{ "comment": { "author": "@strontic20", "website": "strontic.com", "github": "github.com/strontic/xcyclopedia", "synopsis": "Gather metadata of executables", "license": "MIT License; Copyright (c) 2020 strontic", "rundate": "2021-01-11" }, "aitstatic.exe-B7738FF18A19DD34AAE380CE1B2EC495": { "file_name": "aitstatic.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\aitstatic.exe", "hash_md5": "B7738FF18A19DD34AAE380CE1B2EC495", "hash_sha1": "5652A7769E12ED1919CA0AA675EEEB4F0C9EF2B6", "hash_sha256": "9668475A74FD17695929D2882C35C0C29DFEAC4BDBE09B264BE69931BC2F1216", "hash_sha384": "4735B09E0444327186A968A081B15D9144C8FA88703CC055ED02FCF087DDAA29F22A45256312BE6488418DC0FD53DA65", "hash_sha512": "D0AC5518BAB1BFAFE385CF8A233AEE6AFAE09EDF93995DAD6FF8DED9145201BB2DE9827EC59502298515C05037CEC9FDD91096A6A6250239BA1EC1E63EC30C7D", "hash_ssdeep": "49152:HGU3EStENWqei+pSYryLTQ4ullYF5svlRlZPAoTMZmhJv3eEkF/L:HlIAwvAImAoTMgJvuL", "hash_imp": "EDDF29389FA2B9CA07B8B79CE911A8D9", "hash_pesha1": "9520115C83B36475E7E03C311F9CFDAC8DDC3413", "hash_pe256": "9E7D4013F750DDFE5F8C5D41FDFB6863BE6560F5B0376D8B17407E4651A67369", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Application Impact Telemetry Static Analyzer", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/9668475a74fd17695929d2882c35c0c29dfeac4bdbe09b264be69931bc2f1216/detection", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\aitstatic.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "appcert.exe-CA526E704DDFEF1E3E24276FBBF0B4CF": { "file_name": "appcert.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe", "hash_md5": "CA526E704DDFEF1E3E24276FBBF0B4CF", "hash_sha1": "BBBAADC01B079A171462A6FEC4D125EAA5CD9653", "hash_sha256": "1C94217ACD0B918409170B3764BC3B5771C1C2DE2DAFCB09B5E7D9BFF9C226B4", "hash_sha384": "3DCBA5113C39808B8655F9B13EF41F48766C74EA1914D5B41D3EEF6EAD59EA259E31B2D4CF91A2B887180E6670835B30", "hash_sha512": "7E2D6893FDB5410DE9ECC5DE0AE15164BEA7B1C528A90F224F7ADF55200870E5C0385557682A883AF59C53096FC0AD6208CC2A60316DF8A396589EE9FB6CD12F", "hash_ssdeep": "768:n7bDiVME6tBz5s3NHhBX+ZpK76k7Q4+Sz8i75:HDiV2tBzyZhBEY1YSZ5", "hash_imp": "n/a", "hash_pesha1": "6ECA061CE73ACE39C07AD61AD0C21174A867ACD1", "hash_pe256": "B51F0F8B04672E1E1E1BE7FAF8B563E858248A610055056405EB238DC5A7B242", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command Line Interface", "meta_original_filename": "Logotest.exe", "meta_product_name": "Windows App Certification Kit", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/1c94217acd0b918409170b3764bc3b5771c1c2de2dafcb09b5e7d9bff9c226b4/detection", "output": "Windows App Certification Kit\r\n(C) Microsoft Corporation. All rights reserved.\r\n\r\nWelcome to Windows App Certification Kit.\r\n\r\nThis kit will help validate application compliance with Windows App Certification Kit requirements.\r\nFor best results please run this kit on a clean install of Windows. Also make sure all tests are run in the same session - reboots and/or log off will be recorded as failures.\r\nPlease ensure that you have run your application(s) at least once and dismissed license agreements and first-time prompts to avoid unnecessary failures while testing.\r\nPlease run 'appcert reset' before start of a new validation.\r\n\r\nUSAGE:\r\n\r\nappcert.exe [ test | finalizereport | reset | querytestids] [options]\r\n\r\nVerbs:\r\n\r\ntest Executes the testing session.\r\nfinalizereport In case of any waiver instructions, you will need to exercise this option. The output of \"test\" will indicate if report finalization is required.\r\nreset Resets the testing process.\r\nquerytestids Prints list of test names and corresponding test ids for Microsoft Store Certification.\r\n\r\nOptions (test)\r\n-packagefullname Specifies the installed package full name (Microsoft Store Apps only).\r\n-appxpackagepath Specifies the full path to the app package that will be tested (Microsoft Store Apps only).\r\n-apptype Specifies the application type. Can be either desktop or desktopdevice. Not needed for Store app.\r\n-setuppath Specifies the (required) setup executable or MSI full path.\r\n-setupcommandline Specifies the (optional) setup command line.\r\n-waittimeout Specifies the (optional) install or uninstall wait timeout in seconds.\r\n-appusage Specifies the (optional) application usage type. Can be either peruser | permachine. Default value is permachine.\r\n-reportoutputpath Specifies the (required) report output full path and file name.\r\n-testid [testid1,testid2,testid3, ...] Specifies the (optional) list of comma separated test ids to execute during the test.\r\n\r\nOptions (finalizereport)\r\n-reportfilepath Specifies the full path (including file name) of the report that has to be finalized.\r\n\r\nExamples:\r\nappcert test -packagefullname microsoft.devx.appx.helloworld_1.0.0.0_neutral_NorthAmerica_ac4zc6fex2zjp -reportoutputpath c:\\Output\\MyReport.xml\r\nappcert test -appxpackagepath C:\\Input\\myapp_helloworld.msix -reportoutputpath C:\\Output\\MyReport.xml\r\nappcert test -appxpackagepath C:\\Input\\myapp_helloworld.appx -reportoutputpath C:\\Output\\MyReport.xml\r\nappcert test -testid [21,47,31] -packagefullname microsoft.devx.appx.helloworld_1.0.0.0_neutral_NorthAmerica_ac4zc6fex2zjp -reportoutputpath c:\\Output\\MyReport.xml\r\nappcert test -apptype desktop -setuppath d:\\cdrom\\setup.exe -setupcommandline \"-install -quiet\" -waittimeout 900 -appusage permachine -reportoutputpath c:\\Output\\MyReport.xml\r\nappcert test -apptype desktop -setuppath d:\\cdrom\\setup.exe -appusage peruser -reportoutputpath c:\\Output\\MyReport.xml\r\nappcert test -apptype desktopdevice -setuppath d:\\cdrom\\setup.exe -setupcommandline \"-install -quiet\" -waittimeout 900 -reportoutputpath c:\\Output\\MyReport.xml\r\nappcert querytestids\r\nappcert finalizereport -reportfilepath c:\\Output\\MyReport.xml\r\nappcert reset\r\n\r\nReturn codes:\r\n 0 = The verb executed successfully.\r\n 1 = The verb executed successfully but needs report finalization.\r\n -1 = Invalid command line error occurred.\r\n -2 = Infrastructure error occurred.\r\n -3 = User initiated error occurred.\r\n -4 = App installation error occurred.\r\n -5 = App unpackaging error occurred.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "appcertui.exe-7D8AE72EFA1EA28946A79F7E6B21B06D": { "file_name": "appcertui.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcertui.exe", "hash_md5": "7D8AE72EFA1EA28946A79F7E6B21B06D", "hash_sha1": "8381E5087CC79A11091F2D575DAF2ED791806B67", "hash_sha256": "E10DBCECA3299AFB2DDE5B22063B26E84C7311A7D002ADD4FF0D22E41D4AC4D0", "hash_sha384": "8717982077E2599DEB8D63C038AE660711F20E3E4D08941921DDA1BDF96535C5C043BA89370C0E337CEF9652CF84A96F", "hash_sha512": "A7AFEA3CA6E620831D2B93A9945BD8D6870E5A7FC5D18471032778F2FA3A5CE2E2CB04D91E4342A5646935265397CD26B1BBD0432454E219525C6D5681110263", "hash_ssdeep": "3072:p+2KJ2ufJo8YI8ROB/WD0vWFYeW8qURpqHzz/gZ7nIVOAw085X6hFDZDWPlOavC:p+DJJoRK/2C+6sjIVOAw0XZWEwC", "hash_imp": "n/a", "hash_pesha1": "21B58CF7D67BC3014C85057C883DDAC516DC3117", "hash_pe256": "E528B993D75605413DE440F833878E4C76FA89A3103A1A2491675876E9B4FB3A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows App Certification Kit", "meta_original_filename": "appcertui.exe", "meta_product_name": "Windows App Certification Kit", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/e10dbceca3299afb2dde5b22063b26e84c7311a7d002add4ff0d22e41d4ac4d0/detection", "children": [ "csrss.exe", "wininit.exe" ], "runtime_window_title": "Windows App Certification Kit 10.0.19041.1", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_9704": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\Microsoft.AE.Windows.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\microsoft.windows.softwarelogo.shared.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\Microsoft.Diagnostics.Tracing.EventSource.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\microsoft.ae.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\microsoft.windows.softwarelogo.userinterface.workflows.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\microsoft.windows.softwarelogo.userinterface.common.dll": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\en\\appcertui.resources.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcertui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "makeappx.exe-83302F9D356F002DA51F0AAC29ACD317": { "file_name": "makeappx.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\makeappx.exe", "hash_md5": "83302F9D356F002DA51F0AAC29ACD317", "hash_sha1": "5FB001A0EE122158D57DDF54B5BD59237B9BA138", "hash_sha256": "8B832306AAA7D09EB594DF9B1D4B1E73E1ACC59ACCC9FE60226C490A61B64212", "hash_sha384": "5CC7F0475E65F86D1748C4A2425C74942D5CAD80DFAC8326D1DE92C1B7C50A15E3AE17D0015CD37A84BA0DE64ED845D2", "hash_sha512": "8254FDA472F1240487B587D9553D3C192862C7DDAC746A1A2E09C9B551A2CD33A904E96608A1A03846A927734553B955FB0961CE0E6257742C05EF1327C52C76", "hash_ssdeep": "6144:dkmesnB7+XS5eBS61ww0JsF423uCEHOQk+ZhGpmjF/EGPLi+txvmcj/5NbAzawfv:247+XS8BLiCFnEkiu6FDTtx15NeaD5AL", "hash_imp": "C031FA4774700754D25FB610D9D04D26", "hash_pesha1": "2B2B0774394815685E817662F77A5123F8EC6A9B", "hash_pe256": "76AA1BA3794F97391391390A3950C6FE65AC0CBAECA8B00CCB90506CE340023D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command line tool for creating Appx packages", "meta_original_filename": "MakeAppx.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8b832306aaa7d09eb594df9b1d4b1e73e1acc59accc9fe60226c490a61b64212/detection", "output": "Microsoft (R) MakeAppx Tool\r\r\nCopyright (C) 2013 Microsoft. All rights reserved.\r\r\n\r\r\nUsage:\r\r\n------\r\r\n MakeAppx [options]\r\r\n\r\r\nValid commands:\r\r\n---------------\r\r\n pack -- Create a new app package from files on disk\r\r\n unpack -- Extract an existing app package to files on disk\r\r\n bundle -- Create a new app bundle from files on disk\r\r\n unbundle -- Extract an existing app bundle to files on disk\r\r\n encrypt -- Encrypt an existing app package or bundle\r\r\n decrypt -- Decrypt an existing app package or bundle\r\r\n convertCGM -- Convert a source content group map (CGM) to the final content group map\r\r\n build -- Build packages using a packaging layout file\r\r\n\r\r\nFor help with a specific command, enter \"MakeAppx /?\"\r\r\n\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\makeappx.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "microsoft.windows.softwarelogo.appxlauncher.exe-F51098720B2E024FDAAD1CD562C31256": { "file_name": "microsoft.windows.softwarelogo.appxlauncher.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\microsoft.windows.softwarelogo.appxlauncher.exe", "hash_md5": "F51098720B2E024FDAAD1CD562C31256", "hash_sha1": "F281AAB2CBB29714CF140988D01A03486598B425", "hash_sha256": "6E5FC1403441B0275B19B1D0FBD66187B4473CC7781456F4F6F3B7F7C0F821FC", "hash_sha384": "46D096FDBC87B93259778A2CC165DB3A45A6578EC8B9FCBA612894A97DEDF1C9DCC05262740F5D292CC86A0C8F290E07", "hash_sha512": "AD16C36B06D4EDA2221336E612F6427275A8CE6253F5AE126CCE000345A9577BC99FB60D1F03ED38D8DFE894B0C43860CEA07B0C567AFADDF0466E6E884D06F1", "hash_ssdeep": "192:fGnMNDIBh2/44McS2XxIjfwtLWGuFGm1kDWeN:fGkki+Z2hIjfeLWN1kDWeN", "hash_imp": "542A1432CC189E04D435F14FBE1A952F", "hash_pesha1": "FC05B75DE625220E60D288A88FFC8D0162459113", "hash_pe256": "5B82DF5EC6E5FEBB234C0C3082B2537009ED967D9DA79103565567A3419E10E9", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\microsoft.windows.softwarelogo.appxlauncher.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Appx Launcher", "meta_original_filename": "Microsoft.Windows.SoftwareLogo.AppxLauncher.exe", "meta_product_name": "Windows App Certification Kit", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/6e5fc1403441b0275b19b1d0fbd66187b4473cc7781456f4f6f3b7f7c0f821fc/detection", "output": "\r\n[0x80070057] Failed to ActivateApplication\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\microsoft.windows.softwarelogo.appxlauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "microsoft.windows.softwarelogo.taskengine.exe-040F6C712C2570D128A007ACC9ABB579": { "file_name": "microsoft.windows.softwarelogo.taskengine.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\microsoft.windows.softwarelogo.taskengine.exe", "hash_md5": "040F6C712C2570D128A007ACC9ABB579", "hash_sha1": "84B05C47A1631A430DC2229E19C3D6A484BF76D2", "hash_sha256": "DB3EFD0A3679772911DFBFB65A23AEB58D83691C7F4A6E060886AE121427BE92", "hash_sha384": "F1263736F0A83795444321BA8017CB34ED502DEAAF7502E199E79E7A7D5B830661B17E6096D88CE822542D2178C47CA4", "hash_sha512": "C251104878960A1CF96C9668602726A7C892279458CF13A603D032DAF72161F2D6FE809008C3303AD1F0919B12D4F14398A2912368447F5280A2A60EB127CBA7", "hash_ssdeep": "96:6Wpd1MpZF0QE1bC7BfU2GzcjGY13qHckdD3yEWUtlEDJZWPNJ+l:zy0Qsl20h26lVWUtlPA", "hash_imp": "n/a", "hash_pesha1": "78816C2291D0C316121CD7AA003434FBFD13550B", "hash_pe256": "A6D1D61C9ABA96303A38938F472AD3E2FF9290E34B51A5DF2B66C68C79F102BB", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\microsoft.windows.softwarelogo.taskengine.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Task Engine", "meta_original_filename": "Microsoft.Windows.SoftwareLogo.TaskEngine.exe", "meta_product_name": "Windows App Certification Kit", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/db3efd0a3679772911dfbfb65a23aeb58d83691c7f4a6e060886ae121427be92/detection", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\microsoft.windows.softwarelogo.taskengine.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "rmlogotest.exe-11D239B223E84FF4D188BF7E9BCCCA6F": { "file_name": "rmlogotest.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\rmlogotest.exe", "hash_md5": "11D239B223E84FF4D188BF7E9BCCCA6F", "hash_sha1": "BEC8BFED05A7F2EC2D876EFD96CBEB427E03E890", "hash_sha256": "74DB544266BF166140DC94970BDAFB2498C96DEF4E813816D2F91B8F9F291003", "hash_sha384": "74A5A2E3E7CB834F9011CEC500AA2EBE222CB7CB689B52DA1C1F7D81484D0638125831B77BE68997C055B131D42BACA5", "hash_sha512": "A0AAB7A8F1DE2415143CB169F3CD330DB2FF86D59D080DCE7804B4D0247CB2456DBB68EEFE72E6A193268F915956583A4C0BE4B7F2BF7C3A10BC9AC4CF9EA0D0", "hash_ssdeep": "384:ilBbuNdYtqBdqGGNC102sYj4b6EW/GnnW:ilUN6twqAj4b6w", "hash_imp": "0479C1FB938390E75A965C94CF2594FB", "hash_pesha1": "40F2D0D472B82B38ABE644D2803D2D44B400A235", "hash_pe256": "5BB7AEA85DD2E45814290231166DF2DC3B4D5EC896AC079EEB56AC20CCF572AE", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\rmlogotest.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Microsoft Windows Restart Manager Logo Test Tool", "meta_original_filename": "RmLogoTest.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/74db544266bf166140dc94970bdafb2498c96def4e813816d2f91b8f9f291003/detection", "output": "Usage: RmLogoTest.exe \r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\rmlogotest.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "signtool.exe-4F4B0832E56C9550494D869A8369B5F4": { "file_name": "signtool.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\signtool.exe", "hash_md5": "4F4B0832E56C9550494D869A8369B5F4", "hash_sha1": "02DF5D79E9926C9BD5C0DA6AFBDD7EEA35B470F6", "hash_sha256": "649E30AD3451F8F32E5B18A829E28DC326FE944D37C896048240819E37614C9E", "hash_sha384": "ECD1B47C5799E7813D0DAF98C2CA376293BD8D78C397A4FEB87CFC728E23B7E7A3411B4E2346BCCC8B451CF1BB6B08AD", "hash_sha512": "AA37E325488584EDCF48B6F22975C663EE2ECA12AAB209E62CECB22A706A861AEF1E24A5695EF61553B30241CD27D83D22CD9A519098C67501657F3C0337DACA", "hash_ssdeep": "6144:vbbCbwJnuoPVeqVs82NIZ8x4xjKEv0/P6ut4dx3eaeUe0U:frE4VG81Y4xjb4tzp", "hash_imp": "DF3F418443D8095A5F121467E2031EEC", "hash_pesha1": "F8256ADC7B2CB61AEEAB85B2B0C80D360A5FDD37", "hash_pe256": "E3A418FA667676B819B96C4EFC6A1A8E06CE83050C82DA65A3A5979190F2344B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Authenticode(R) - signing and verifying tool", "meta_original_filename": "SIGNTOOL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/649e30ad3451f8f32e5b18a829e28dc326fe944d37c896048240819e37614c9e/detection", "error": "SignTool Error: Invalid command: --help\r\r\nUsage: signtool [options]\r\n\r\n Valid commands:\r\n sign -- Sign files using an embedded signature.\r\n timestamp -- Timestamp previously-signed files.\r\n verify -- Verify embedded or catalog signatures.\r\n catdb -- Modify a catalog database.\r\n remove -- Remove embedded signature(s) or reduce the size of an\r\n embedded signed file.\r\n\r\nFor help on a specific command, enter \"signtool /?\"\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\signtool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "accevent.exe-2B304EE7CC72B92167541E1359435DA9": { "file_name": "accevent.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\accevent.exe", "hash_md5": "2B304EE7CC72B92167541E1359435DA9", "hash_sha1": "9F322E14380F08EFE062580CD296881BAC72C7E9", "hash_sha256": "0A5C6C4127C9C55420089FE465DAB810F068768C0AB278410BBE4F633664BC00", "hash_sha384": "50714E760537B3332F22E21898572BD79BCA30ACE3BE702CE7682171B3DC83AFBCE5D6B4B3A6D2B0A617AF23EDB3B602", "hash_sha512": "B1967285F9C9344D74F267FE1F145440A27E05F43E3EAE45E7BF843AF708F843CC9B943E7E3FF01A91FE25341922D161325355FD52A55C48BA8CA132306C31B1", "hash_ssdeep": "3072:yXhiTM8mP4PnQY0FfH3kMKYMKx6QmwahQWlWSELvB8eyr1rjP7:ahiTM8mP4PnQYg3kMKYMKx1xSELp8emD", "hash_imp": "24F2D16DC5A71AE6355FBCE0CF548988", "hash_pesha1": "0BEFDAAC8B84A820DADC1C09C8B6DB3B6B44B461", "hash_pe256": "1E2E2D92D9A2D8F9F6F1B6826864E0DACEC5B660116D10C3DE932AF103333BC1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Accessible Event Watcher (32-bit UNICODE Release)", "meta_original_filename": "ACCEVENT.EXE", "meta_product_name": "Microsoft Active Accessibility", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.0.0", "meta_product_version": "7.2.0.0", "meta_language": "English (United States)", "meta_legal_copyright": " 2012 Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "computerhardwareids.exe-913A240EE9B85A36DF2842AC056D4473": { "file_name": "computerhardwareids.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\computerhardwareids.exe", "hash_md5": "913A240EE9B85A36DF2842AC056D4473", "hash_sha1": "8F33AB1977A5276353A7B08833257390930250D4", "hash_sha256": "64DEDA13A9EAF331BA1FA37771BBE9FE86FFB71ABB16716E745D55848891FCC6", "hash_sha384": "09AA389F32EC1355032CDA944253772E5945190BA22B0C1F1E765D7BB17BC27391E47F7CB7D0B4EC7E0F291D2DEFA1F7", "hash_sha512": "15FE1D77C0970541CFF751711CECEDF492E12E8AD4AE14FFBF9F488F8AF4F16AEEE726EE60F966784930B48F11CA48BBFDAE9E8C75AB2DF4E3A25FB49DA81EFD", "hash_ssdeep": "768:33UUCVwlmXoHglxCRVEtF8OA8G8yzK+84:nUUV5HKCvEoGGNzKP4", "hash_imp": "9C84734A5ED8B4B890DD394EDCEF6670", "hash_pesha1": "C484C31AD6503F1A4253ECF42CD772C266487E8C", "hash_pe256": "34D179DBADB0C712D0C8911C51A2E92B7D204BA1809515EE0CDBD7851E336D0F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ComputerHardwareIds is a tool to derive the computer hardware ids from SMBIOS information.", "meta_original_filename": "ComputerHardwareIds.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "cppwinrt.exe-2F521E2D6A53E267A924D463B45EA9AA": { "file_name": "cppwinrt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\cppwinrt.exe", "hash_md5": "2F521E2D6A53E267A924D463B45EA9AA", "hash_sha1": "2C7B160BE1C4E3834FACCBF0A6558435D7AF8620", "hash_sha256": "174AD164306E1F6AAA6BAEC3A8BEF778A13041E28982C564D3BAF868EB1D14BB", "hash_sha384": "7BF341F93FA0F8C0480E726F28CC1A4F8C68DA82CB437AC4A4EEB168B79000CD3C16F0FD5738BA08F31137CAEE9A3551", "hash_sha512": "1DBD90496996B5BE89C7162B871BD5B4FBE4477E04BD5315AFF565B2C891FC43868005665EF85D1939C6AEB7C9608BD7C0B10F5F5A5EFDC2A097F4831F52D506", "hash_ssdeep": "24576:RM99jN+doLjdE7gUKFQI9lfHpyNsHujT4R1NtNh4AMgpDeLfPcY5kTl1qS4PQvGa:C0cll11z74bQkdF9HSkpDjeiR/j573Ta", "hash_imp": "6752EDA56876B8755B7CF239CF9ACD46", "hash_pesha1": "A97A2F757C6066F2A1ED5E322891AA7F5CFF22AE", "hash_pe256": "AE6C0AF4E7FADF19C694B5EB98B1DF3D9A524A25CB9D063638A920C8BFF59638", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "C++/WinRT", "meta_original_filename": "cppwinrt.exe", "meta_product_name": "C++/WinRT", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2.0.0.0", "meta_product_version": "2.0.190620.2", "meta_language": "English (United States)", "meta_legal_copyright": "Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nC++/WinRT v2.0.190620.2\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\n cppwinrt.exe [options...]\r\n\r\nOptions:\r\n\r\n -input Windows metadata to include in projection\r\n -reference Windows metadata to reference from projection\r\n -output Location of generated projection and component templates\r\n -component [] Generate component templates, and optional implementation\r\n -name Specify explicit name for component files\r\n -verbose Show detailed progress information\r\n -overwrite Overwrite generated component files\r\n -prefix Use dotted namespace convention for component files (defaults to folders)\r\n -pch Specify name of precompiled header file (defaults to pch.h)\r\n -include One or more prefixes to include in input\r\n -exclude One or more prefixes to exclude from input\r\n -base Generate base.h unconditionally\r\n -optimize Generate component projection with unified construction support\r\n -help Show detailed help with examples\r\n -library Specify library prefix (defaults to winrt)\r\n @ Response file containing command line options\r\n\r\nWhere is one or more of:\r\n\r\n path Path to winmd file or recursively scanned folder\r\n local Local %WinDir%\\System32\\WinMetadata folder\r\n sdk[+] Current version of Windows SDK [with extensions]\r\n 10.0.12345.0[+] Specific version of Windows SDK [with extensions]\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\cppwinrt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "DeployUtil.exe-A7BBA9DE4D71A2C641E33C64DB6E4DB4": { "file_name": "DeployUtil.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\DeployUtil.exe", "hash_md5": "A7BBA9DE4D71A2C641E33C64DB6E4DB4", "hash_sha1": "0A4692829EE34549A24EAFE49F854C5530391EAF", "hash_sha256": "27830C256D42AB96CF21AAF48C083EF3E62FE13FC4E9B03222568AAC055ADD61", "hash_sha384": "26F75C9E845C4181D628A81D0ABE1C6D0D1F4E2B9213F2C5EFB258EB33B121EF27705436A2D172D3AAF5A7E36E5DADA3", "hash_sha512": "507142D3630230553C7E782E9642430B2453F8989A6CA5CB1254776DEE7AD235405E814C04B722024A2C78E33481857C7CDB79EB0DCEC6F235ABF8EB980BB8D5", "hash_ssdeep": "768:mXErbXyDbd2Zc50O0Un762plUVfgg/JoCYtUPZ:mX3zq+6fg/UPZ", "hash_imp": "48D484B7C73D3233122902E38F247334", "hash_pesha1": "2A45E22AED3A49F877A22109B3BEC8E53E9083FD", "hash_pe256": "18436940CDEA0EB09EFA5829801DB0B4C2FE072C2104AB4F35FABC029DC2BACC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000052C8FAF5B90BB753AC000000000052", "signature_thumbprint": "8438EA0A58759BEA28DA7CF658413939F2AD5BFF", "signature_issuer": "CN=Microsoft Windows Phone Production PCA 2012, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Windows Phone, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "452", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/27830c256d42ab96cf21aaf48c083ef3e62fe13fc4e9b03222568aac055add61/detection" }, "dxcapsviewer.exe-30505DF0367892CFB06157B6888C9B5B": { "file_name": "dxcapsviewer.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\dxcapsviewer.exe", "hash_md5": "30505DF0367892CFB06157B6888C9B5B", "hash_sha1": "61EE086A7FC9CAA34232251974F70AFEE6C29B0D", "hash_sha256": "60F4465DF8233C00A67CCDA0F05974ECA21B8606972B1A3014C48AF287FE25B3", "hash_sha384": "2D10AB37EC653DDF58D2B46726CDA0BB750A21351C1A88C810BF22F245071B99FFA493E812DC7AD2852FDEBDA5CDDD02", "hash_sha512": "744469E827A82D20CC19A5BA70240F89C8A06C6BA09942EB28722E2581997E55F597ACF77CC8E55823A4B93A6B4538C271AB78B48C01743AB5B322DDFA88C1A6", "hash_ssdeep": "3072:2BvNiRHAkQjhE6kNRl7UN7FLWUXjVKjV+1qdW2PZspvV:2VNwAk2XSl7UjT8NPqV", "hash_imp": "21B38805569DB4566961A13EEDBD74D3", "hash_pesha1": "373E3A2C6F42A6091E65F4EE5E141F65498E40BB", "hash_pe256": "18DE31E58CEC8EF75CBEF9051866EE50B8E46B74CF2CF72228C13256DF831FD0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) DirectX Caps Viewer", "meta_original_filename": "dxcapsviewer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "filetypeverifier.exe-E9A9F4A70F9AD9DD7E6DD6F133EC8077": { "file_name": "filetypeverifier.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\filetypeverifier.exe", "hash_md5": "E9A9F4A70F9AD9DD7E6DD6F133EC8077", "hash_sha1": "DC78F25EC9386F585C7FC0EED79F78B80E8D9A1B", "hash_sha256": "3BA8818DDE13278F6357F735B0203B27FA465B8562630FEEC3F3A2AC03878284", "hash_sha384": "F37FB13160B6FDEA68A32CFAA39976CB829100A90A8038C5F9AA2AD615A10DB4851C6E51433F15CC987C3F7BB0C7B6FC", "hash_sha512": "774F4C463FDEAD6BF187AB40F06A6F51C431A6817395CA4ADC5AC30118F30FE3AE9724082FE932D421A18AC12923C6AD7A715A8F629126697EA32A0A70CE2C61", "hash_ssdeep": "3072:ONAX1JEsjcljw/CiOnLV6LmMcORqSQns4F31GZq+NvXkRHo3T7tQEghBcYr1APKh:kWjp2kq+N8+uhtx0AmcPdYmdpoBIUa", "hash_imp": "527599EED2AB6CC31C0CA140AD874E37", "hash_pesha1": "159FE571E9B1085A04B8AB93D49152E03A04749C", "hash_pe256": "EFDE62EB378D776B2BEA9EA7311FA12E4BC323951245A072D671352E2C7DD49C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Type Verifier", "meta_original_filename": "FileTypeVerifier.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "filtdump.exe-77C4885494CAF373A60D0E4E1DE6F506": { "file_name": "filtdump.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\filtdump.exe", "hash_md5": "77C4885494CAF373A60D0E4E1DE6F506", "hash_sha1": "215444D0353426253E74EE4EAFDD0EAA6D8A8870", "hash_sha256": "41DE078DE728B1D59AFC389DC34CE7B0267991960B5B4C2F8BC30A5C9987D31C", "hash_sha384": "527118A9F430D98FFA61DA89CC5B029DC3164272E41AF1C9678387FCA1DE4822E0BA50A84643BEBB0094819B90BFA3E7", "hash_sha512": "6DD10505047B61B8897C52B2956342BFBE9CA220C94D27F3A9E004AFDDAF7DD699F7D5F152B9D77AF259F18520F9160EAAD51AA6C32979CEF43C817FD9173CB0", "hash_ssdeep": "1536:xa/BM3q5E8QYOFs5CK6ZPIyGDNVRUCoXkt:XIPuXkt", "hash_imp": "584C3A00FD1CBDE80A4A8953411E9A0C", "hash_pesha1": "5457A91C138B1FEF616A97600E5B7E70053C8542", "hash_pe256": "37EBFC5106A875415FF4E19C98734525A2FEF650F748EDF76624F2C3156EB0B5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Filter dump utility", "meta_original_filename": "filtdump.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "filtreg.exe-FCAF6FC73F93A8C62A9F4C62676520EC": { "file_name": "filtreg.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\filtreg.exe", "hash_md5": "FCAF6FC73F93A8C62A9F4C62676520EC", "hash_sha1": "C05C6AC18F34E38359E0CE0F113AAC97E5DA4EC1", "hash_sha256": "480EB9ED6175F4F02CB53395FC044BCFFC342C46855C145E441DC7674C911DA8", "hash_sha384": "7353958FC6AC1700709397D6344B51D590D0AB3008EF4177C90372345127FB03335C551FF750B6E9507FF3860B0F0240", "hash_sha512": "25316F0E35177E6F9AE388CF6C8AEBC8E0D616B91891F7C71977AB53BEFBFFDF99D341D5175601B528C144C01A2C61FFBA0BD15EE650ABC94F058EDC4A2E757A", "hash_ssdeep": "384:Z7XDXZFGrBxcfuSR2VWWwyWDaD4JeRlFsyJ:5XDp8Bxc9UIBw", "hash_imp": "0DD5BDFF1EDAE5680E13CEEBB64BD9B3", "hash_pesha1": "9BBBACDE8FB092344CCFA9034CCFE34C1090F0BE", "hash_pe256": "94A085062FED4D17769F05A361AF2134FA9E912C23A5A11C831CBA1200357C70", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Filter registration dump utility", "meta_original_filename": "filtreg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "ftquery.exe-B26762BBC07B0338A7F5357A22EECBA7": { "file_name": "ftquery.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\ftquery.exe", "hash_md5": "B26762BBC07B0338A7F5357A22EECBA7", "hash_sha1": "48907590E95DC5030BF7076F0601FF6857A187C0", "hash_sha256": "5AFC405BD0EF6ACE476989E465E10476C57AE306769D18DD85A2E9CBDA776988", "hash_sha384": "81D7EC294A8F3464E4A316ACEF06E5B005CA845E73071477ADF622AFB968C96680CF4D5AD7D240679FDA3880DBC01BDB", "hash_sha512": "14C72603E41B48BE2C59F3EC4988499D6F0441687F1A26EED9030D716F658498E512751870B16A186696A733DBEDB6BFD391541B296CDEC6E4E22F48B9289ADA", "hash_ssdeep": "768:m2Aq/znu2gyGKFcwF+WEaVhfZsgZoF5ZwM6rs4KZYVV:zAcqaFcwFuaBnoF5ZwhrsrZOV", "hash_imp": "n/a", "hash_pesha1": "ADDDF1F743FB7B02DC948983A56AE15DDA63988E", "hash_pe256": "7E9B7C97530C0DC9B8366F3E7808879BE0674225D07A082982B363DA138266E3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "ftquery.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "ifilttst.exe-95147BFF2ACFF57F171CBDE7165F74E6": { "file_name": "ifilttst.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\ifilttst.exe", "hash_md5": "95147BFF2ACFF57F171CBDE7165F74E6", "hash_sha1": "E89DEA0C44019CA4A76DD543E8CBC9D30260FE42", "hash_sha256": "CB63812E777D6957C2C438A796FB796FE185B7E37B4E0F4BC87989591F4DB073", "hash_sha384": "6ECB39110DB5EA71EA6FFBC33F34A5B3E7A3C1F5CF5A74AF726023E0CF7B5C108FF0F0A0931D8048D76AC390738D2F80", "hash_sha512": "45BBB44E0DE7498FF19CC53648C4D947CA79C2CA68BBB018D6EE7D042E347ECF54F3570A6E1B13EC0AB9CDEBF002CAEFAB9CC47C592F526846808C0A49C47E12", "hash_ssdeep": "1536:6awyeGI+Jbaba9609r3Xv1vgZu7vYOEmH4BZw4Fkd4nhmPIEXz+ASKu0:PPXTvxEmH4BOH4QfLSn0", "hash_imp": "EC67CE8D47F4A31338B0577C1BBF7794", "hash_pesha1": "0195C298F7B3F8997B32076D63B89569C9D999D4", "hash_pe256": "CB6A246078D9089DA7518AE2BEA6A02C789A7F6A2FC176EA7FBD33DD13497FBE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IFilter command line test tool", "meta_original_filename": "iFiltTst.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "inspect.exe-B804026AF7C771E19D70EA0358340BF9": { "file_name": "inspect.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\inspect.exe", "hash_md5": "B804026AF7C771E19D70EA0358340BF9", "hash_sha1": "E553C5BA1DCB55001C3B0542D981ECB23C131317", "hash_sha256": "A678C604BE37EB2BFF3B88C59B7BF2928C223932BB04AE45E477833DBB27BBC2", "hash_sha384": "A88232F95D294D2033CE112A598B0D06B4DC92586A70768259DB08A36EA83DBA2EBC4E32EF9B714BBD86CEE328CA5247", "hash_sha512": "B2379175B90461E9D0EC89BF3D5794B54BF9CC8003DD89C761E418930F99A09C82FC72332E3EBAAF60CA4AD236B00607D8A213ACD1AA6F97306B59166EA86361", "hash_ssdeep": "6144:5GrMU3kMKYMKYqOyVSfzptFge6b9TTUW8Tp:mMU3vmjy4zpx6bFup", "hash_imp": "09619BB57B671BC1DACCF1B9547AEB88", "hash_pesha1": "E0E7BF852B2FAC8F00D230BEDBE24D1C43895020", "hash_pe256": "93C8300FD3DEF61CF2D43B80E5856FEB8FE91A8476A9EEDCB9B791998C5EEF2D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Inspect Object (32-bit UNICODE Release)", "meta_original_filename": "INSPECT.EXE", "meta_product_name": "Microsoft Active Accessibility", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.0.0", "meta_product_version": "7.2.0.0", "meta_language": "English (United States)", "meta_legal_copyright": " 2012 Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "mbidgenerator.exe-5B1C33C9BE2742B19983BC29A736D4DA": { "file_name": "mbidgenerator.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\mbidgenerator.exe", "hash_md5": "5B1C33C9BE2742B19983BC29A736D4DA", "hash_sha1": "E2946E7F49574FE6D31FD9D9814CDE50D32C6FAC", "hash_sha256": "A08077560537B358E48200067298D5FB026C835CEB40A44E2E3E827FBF2A484C", "hash_sha384": "2784B8A5F0585270D48882ACF2403F960E38603060B4EBD6D757AD08FA35694C9D5592A23030B9D9802414BB00DE1CDE", "hash_sha512": "52388477970B2DC7B6FB1A55907E71C94E532C4E4ABBDFFECAC725650903BAA435DD7FF84AC4E375472A83E1177AC7C391E8D03060EEAAA6D18C46F65108221D", "hash_ssdeep": "384:R0M+FW1VT7TqF/sk+Unppy/ye7BKy9lUEliyCM8r2aVANW1WWHQJsl9n7g:7vaTrpp4PKmUElGMaNg", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "0E027847B8FE43669AE12A6D495718993D0F271C", "hash_pe256": "540E95BB8B0C6620D4862C5E45DA8CEA5E9170D9E7E7C237A74B42E448EB260F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "MBIDGenerator.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Unknown command option: --help\r\n\r\nUsage: MBIDGenerator [/test] input_file [output_file]\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\mbidgenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mftrace.exe-4A18EDD320539231C508F88BA080C178": { "file_name": "mftrace.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\mftrace.exe", "hash_md5": "4A18EDD320539231C508F88BA080C178", "hash_sha1": "06C009634386B7154140558E31D908C1EF9B7523", "hash_sha256": "4508DFEAFD3D70C7BC5DE59775A67936F993D55FAFDFE81647FDFE061984F7AA", "hash_sha384": "316E183316B5BFFC7EE5184E4F8A7461D0F98663EB10F693D627C046DD0FB9A4EA5FE11AAE71B06DDFD45AF5A68E1324", "hash_sha512": "24D6A3542AE56B41C066982F479F8BB05BA2152370FE6D1FE3B04E975E9CAA0861EF9FE45BEB98224F2FEECA7F1C251B42E26FFC72C7DF3F8085902707AD2683", "hash_ssdeep": "6144:KsWcdeYPCkXZ/6EKADl8Pg+TjRxpZJ5pZN4Zx:ZWeeaCkXZ/6Edl8Pg+nRxpZJ5pZNEx", "hash_imp": "4EE03BCF465A67C28598DDD7E66E309B", "hash_pesha1": "81B15D4CD8D242110EA5B54EF9F6503E4CB550FC", "hash_pe256": "AA5C352A58ED5A3A78F3501E3741016ADF17B52D053CC24A194734F8FAE93C23", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Media Foundation Tracing Application", "meta_original_filename": "mftrace.exe", "meta_product_name": "Media Foundation Tracing Application", "meta_company_name": "Microsoft", "meta_file_version": "1.1.0.1", "meta_product_version": "1.1.0.1", "meta_language": "Language Neutral", "meta_legal_copyright": "(c) Microsoft. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "MsiCert.exe-CE61CE64C9AE15A7F2FC6681F51F203E": { "file_name": "MsiCert.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\MsiCert.exe", "hash_md5": "CE61CE64C9AE15A7F2FC6681F51F203E", "hash_sha1": "50821E7ED27935C9B5350F0FD7845E6F16C67616", "hash_sha256": "1E6D01A9D26D04899BE306962567A91A0E6A3DC8171C2DDF40AB7EA5C9ED123C", "hash_sha384": "0D7FF8060F351B50608F72B41457FC41410D6B74A101CD4B9896E426DC74D52680A813036532D9E155FC138AF740AFB1", "hash_sha512": "B0CC6339083E587E0CFEBC024F2230298FEE18045AD40B906C4E7B9B5E32E299CD9CDB8AD2FCF52C311D278ECDE102FFA41E18D42262AE19584AE78BCD1A18B5", "hash_ssdeep": "768:JMUWEUSXnxXWmSZNhM1ZG6xyvNYQPXv3/44aEk3tL7eiVlTQo1EOWEFb:VZUWghudgh33APL3QgJ1vtFb", "hash_imp": "7E4FEC04EF3E0744F1DDD7A67563A78E", "hash_pesha1": "AF9EBFD4432CE8C1C0EE1A4A8FAE9EF2BE3D5CA3", "hash_pe256": "B472CC857E3D754DA4C86B2B11C20C4862D85989A4083E08467A4517AB6D66B9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MSI Database DigitalSignature table update", "meta_original_filename": "msicert.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "MsiDb.exe-4A21D0F8A054564AED061B01DF002903": { "file_name": "MsiDb.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\MsiDb.exe", "hash_md5": "4A21D0F8A054564AED061B01DF002903", "hash_sha1": "A8F1E92FA6D0FEBF932AAFF53E3FA732E600BF52", "hash_sha256": "45F961231439AB96488E302504D8F926533DEB86C671E04611BCB57AABF9377A", "hash_sha384": "09A96D6A8BDE86F5A08E82628939F198B0A9BCD7CB241C8DDE99F2E6ABAEB2B3AD22C1599FC0052F1C782238F058119A", "hash_sha512": "466F046F64D6011A5191BC9166479C6BCC2D761FEA7FB211B0F3A576FFBF1367C50F1C2CF490B6C985F7641BD93035FA79604A9A16522F4D7ABEB5689A4BD1B2", "hash_ssdeep": "1536:IHIfv5WPfpenYmCfBA3mPx88EqzvBq/XWHlgQ/XG2B:IHIfvYy+fBVJ88eXkyV2B", "hash_imp": "E59C781E7983F5291F92727084E40794", "hash_pesha1": "2EA58ED7BADDA066B05B859E993748C6547F8713", "hash_pe256": "BF237D386D4A1831433D882AC0EEE60E36F5C0E40F1870C48AE0B65E521B2E1A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Installer Table Creator", "meta_original_filename": "msidb.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "MsiFiler.exe-39A68DBB6534A7350239D5403B15FE4F": { "file_name": "MsiFiler.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\MsiFiler.exe", "hash_md5": "39A68DBB6534A7350239D5403B15FE4F", "hash_sha1": "CB41D12B7BF365268B8F951A7A50C60EDFA94CA8", "hash_sha256": "BF512D440C3E9BF2CA13BC43F66A0394A9CB154D699FC13DDCF497FCABF88ECE", "hash_sha384": "7E58D9A9F4DD9E4B431C4244A4C2576E5E509CF8BC70317D8F11E57501EBF352E51844D550A156D81DDC03F5CC3E3668", "hash_sha512": "0AAB04CBB022E6ED5E6617360C07E18DF49F5D2DC6A50BCB1D715BDC740E04946BE8B0751CFB5D44D73480E4FEB907F9B76BDD4A8F17762E228A0FE0755E3C50", "hash_ssdeep": "768:66UW/QQ3X2HivCdf0yeAIv+7bPrb3W1B7tLkC3RH2sU4Xxlp51i5UVv5:m4QQWXfU/v6n3WfZIC3RU4Xv1WUv5", "hash_imp": "1A4BD79F12E451BBAD611E9BF74FABFD", "hash_pesha1": "E60F36F281A6800ADCA074F17553FD92B4281E07", "hash_pe256": "22D0E63D05C6410C6694C7D1EFAC3ACEACDFB0A5296F784B59364106ECF5DA8E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Msi Database File Table Update", "meta_original_filename": "msifiler.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "MsiInfo.exe-A338D1A8BC5083A9FE7FA6CF13D4A1D7": { "file_name": "MsiInfo.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\MsiInfo.exe", "hash_md5": "A338D1A8BC5083A9FE7FA6CF13D4A1D7", "hash_sha1": "6582BC3631EE5AE055B31E77C1E5E4B13042F9C1", "hash_sha256": "9390D64480BDF8D328AADCDB2051EBD5DF82518B3C58FFA874C9F703C2664105", "hash_sha384": "36C6BCEEFE08FBDCD06909C1C0B2FE1AA42A850A58BE4ADFCECDAE540A6E1995761EE75E7B31E6DD5375431C7082A666", "hash_sha512": "4C541D53FBD4496718F8A2FF1F546BF40C13EB74FDCAB88675423928936EB2297D0ED6EA0E6701DE3E80862BA6876FB69579711B8FE44E0C9CB4E34BCEDC3F56", "hash_ssdeep": "1536:5qg3cCABkdBfzRSqw6V9AGn3OzjwuubVuMB8AEi6Is1j1XP:5qg3cCAKB7RbYG+IPJuMBG1j1XP", "hash_imp": "1B4F8940D66BF31979F7F49A7FBFD374", "hash_pesha1": "0C8E7C71F2F10F79F33B6E8F39179909C4E83522", "hash_pe256": "DFFEE805E17F52AB1E4AD6A4DD0714B8AD64349D8B1453B174CE74451C0494B0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MSI SummaryInformation Display and Update", "meta_original_filename": "msiinfo.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "Msimerg.exe-BAC4403744CD93166387188E3A251017": { "file_name": "Msimerg.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\Msimerg.exe", "hash_md5": "BAC4403744CD93166387188E3A251017", "hash_sha1": "C9DA6D491FDEDB8135AEB6EB7F51B9B731112466", "hash_sha256": "12DEA7637207886FE76D5C215F57FE73568F09CDAF84556F2A6D3A1B728609DA", "hash_sha384": "AD6C02EC55D0A305729F5CA8F9C2B597CC54F90E34D611CA98E4133B14ADE93FE46BB4588515E5CD974C3CBEF60E1235", "hash_sha512": "92D0633DA6139FD44C01F1C580A044D24029B0C9BA9AF971C94EC95D3441223057F3F70AA1C7570AF6201905F00B84F6F294323663E778D04B0DAA71B4226FCB", "hash_ssdeep": "768:ayAWKHNXVJI4OD/TYQQPbe3Vfy3UDksjQQhxhRHxBNi4K1Klitij7:OLHNItjTYQQK3FubsjPhRH78L1yMij7", "hash_imp": "7D527569E60236959FFD3B912523094E", "hash_pesha1": "C9232D9521C5639CFDCAC6506DFB51FE7F959A79", "hash_pe256": "79361AAE24AACB458E1EB45E7E354720C33E77CC6E49E1471B05599AAAF815D9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MSI database merge tool", "meta_original_filename": "msimerg.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "MsiMsp.exe-58AF078C924934A884C8BEE33870DD1C": { "file_name": "MsiMsp.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\MsiMsp.exe", "hash_md5": "58AF078C924934A884C8BEE33870DD1C", "hash_sha1": "14500E84633476F8A2E92D928DCD91642197C865", "hash_sha256": "9DBF3E76F0BCB5F977BF9FA7F7E3F8ADA289A558DC5CDDC1AD33D9B83CB2C990", "hash_sha384": "C81195E7E3987EC8FA70ECC15E9A7E7CE00F8907829DD58EFA42C57102155B66B52853067A4E83848EA9D7114208CC4A", "hash_sha512": "077C15E38F34B041D237AFE22E17241B6FEFF67D8935DD9E5E3FD0F16352F0AD5998B125A44AB54F436E004C00AC96F9BE0148B3282E7C4074B420C287B7AB2A", "hash_ssdeep": "768:DtnUWdXH7C1yaH9eb7ZQph3zPIo3/zD9L6w3VVk6sB7y4MOwxwaK1Ldhlq7vB5C:DiqC1ydJqz93LBWYurE4MA1BH2vS", "hash_imp": "40A6C02E402732528C9FE383386AAA7B", "hash_pesha1": "941CA23251AE75C55FBA08D9249BEAE05C8C7DB8", "hash_pe256": "598207B566357A04805EBFEEE499E921993FB6B511F2FA1FE94058E3329560B0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Installer Patch generation command-line tool", "meta_original_filename": "msimsp.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "MsiTran.exe-1701B9E57400C32B72A99E3886FE6E06": { "file_name": "MsiTran.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\MsiTran.exe", "hash_md5": "1701B9E57400C32B72A99E3886FE6E06", "hash_sha1": "A49686DD9BF130A4518067F5BCB68D13CE439DE5", "hash_sha256": "A8F2096DA8994EB1071780A9F38417ABC685D936905AB5ADC64C4618223AB1B8", "hash_sha384": "5B88887A1A473E1907DA615F249EDE432C5C8BDD1C2E63F367C6F86ECA6CA988528A929271BCB87CB946F0473972B83D", "hash_sha512": "BDE980DE174A11F1977E2E84AEAD15BF1FD9212EF98DF2DFE9F9E808D7C29EDF740F70F33CC88B105F2AB95E6301ED188C1AA436634733A7B75BDBF756FA457A", "hash_ssdeep": "768:/wAWbHt5X3oLDY/YA/5IPe13ncyDkhxqM8scUtbDgt1LWrNPjd:X2HtdovYAo5Ie3cXhE4cP1qxrd", "hash_imp": "63AC37FC4DAA877911EB0C2C0F3E4363", "hash_pesha1": "A1589F21966557F88CAD061982295FD6691DF003", "hash_pe256": "8234298B2C4C8A75619EFA063376EF00B3172664FF95BF4C172B4099AAA39FDA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MSI database transform tool", "meta_original_filename": "msitran.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "signtool.exe-E354FB94F286C0220C6C731F16521437": { "file_name": "signtool.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\signtool.exe", "hash_md5": "E354FB94F286C0220C6C731F16521437", "hash_sha1": "EB224C40CE6CD3BE7417CE4516B00DFEA73223E4", "hash_sha256": "B52B90EDDFD72F6E011283C81B3A355D2D718B68B37120AB32432DC659FB338F", "hash_sha384": "227F8115BD372B9D46BF01BA8486B357C9B4A98DD136332C8B208757E3EA6A3CC6A2ABBD9BD57EE40DF0507CDED4BB56", "hash_sha512": "9160ED9C6679BE8DD5D971F00CEEE6124BA2F4DF7171A3EB381A9F31D0403FBA397EFD03458D78F105760DFD939DA4D8C93B63958DE51118D8CE91B9C339AA86", "hash_ssdeep": "6144:iHtWageM0C8fYbi8RUPG3+QT5GNftEUpeUe0NQ:iHtWaxMz8XG3+QlGNftEB", "hash_imp": "78002088CA8E1E6C274C0ED4942773CE", "hash_pesha1": "998D1A9C24244544464B9D1420E98FFEE1C4F452", "hash_pe256": "4BBDD9B9D6C895DE140C1A1CFA1CB019DACDCB42413A3E27306DBA6B41057379", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Authenticode(R) - signing and verifying tool", "meta_original_filename": "SIGNTOOL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "topoedit.exe-2292BBD97B4A4D65344A81FCEF794BB5": { "file_name": "topoedit.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\topoedit.exe", "hash_md5": "2292BBD97B4A4D65344A81FCEF794BB5", "hash_sha1": "A84BBBAA5AE54BFB6798C8156A621FE38A0D758F", "hash_sha256": "165AE012BA72550B791E0722CAD21B6A7AE7154A7B63A4468933229F96560373", "hash_sha384": "8ED86F8BB68CBB33973D6F51407610CE709C7DEDA05E5CFEC588B128AD8AA610D50DC9F201930F80749EB5A2221DBAD6", "hash_sha512": "1D1711BD3B15023FED884AC1BFEAD2D3D44AB266CD4C898A294788B60C93DCBC2964E92AC963D980149DF3C5CD96DAF270B23841CD64B84E29327A7231B7A9A6", "hash_ssdeep": "1536:TYK5Ak5EO42qybrCPLk40MOjlNwzT6h9++swlvlFL7aFdy3af9AHB1uNEHQfbVSB:etO42lbrCzrYhETU9PPHaqkSz3BJoox", "hash_imp": "39ADEFDBEB72AAB6126A466283F864A3", "hash_pesha1": "E1B8B702963733E722224334589ACE77587EBED4", "hash_pe256": "B296BE9E4BF4A8BB8355722264A4DE43A202EB4D35816DCE3C160DFCCDAA931A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Topology Editor", "meta_original_filename": "topoedit.exe", "meta_product_name": "Media Foundation Topology Editor", "meta_company_name": "Microsoft", "meta_file_version": "1.0.0.1", "meta_product_version": "1.0.0.1", "meta_language": "English (United States)", "meta_legal_copyright": "(c) Microsoft. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/165ae012ba72550b791e0722cad21b6a7ae7154a7b63a4468933229f96560373/detection" }, "tracelog.exe-A40D4D4E355DECDCDC00D42A72481FF9": { "file_name": "tracelog.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\tracelog.exe", "hash_md5": "A40D4D4E355DECDCDC00D42A72481FF9", "hash_sha1": "D4E93D72CC3FF6B0C3F77C38FA354F1F93EC9622", "hash_sha256": "063D45EF6DE997FE87D614ECFAAEF2E93DD3D856BB5EA07A590CE086776679B1", "hash_sha384": "B3785B0328888AFB10D941D79FA2F43A31C1466C29947F0A321972838BB725B838C0975B2017DA5F08C603CC8FAA7972", "hash_sha512": "6699DCCA13986CC04B20D722B5EB7B8D95E68CE54D53F0DCCA7FA7FF2BB8C524723E6AE639DD9C68C0BA3F7EDE14F213475441F2E6B3ADD4C077E32AD2126FB7", "hash_ssdeep": "1536:ToXmsO3/efPsuNWT57a80DfaDg1ciwYWrnOaNc5lv3gwIfPVkNx+X/JLo:ToFO3/efPsEWT9RJDg1GOYVcxQ/JLo", "hash_imp": "87052C6C3E6B7596C08C165E8FF08BB3", "hash_pesha1": "FB5C150F13D86157A091C73246EF3BF7BE674F80", "hash_pe256": "5DA08AC8A7520775C60D9BA1188E17516B8518CF3AFC0FE38721432EF106ED37", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Trace control utility", "meta_original_filename": "tracelog.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "WiLogUtl.exe-86682CEF1FB0E0702447EBFF7DC643CB": { "file_name": "WiLogUtl.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\WiLogUtl.exe", "hash_md5": "86682CEF1FB0E0702447EBFF7DC643CB", "hash_sha1": "04834FBA323ACD9CA9236C94933073947DEDF03D", "hash_sha256": "1C4920BCA1754BFACBC4EDCAC73D247F5FD45877191391D657A60C426EB673F3", "hash_sha384": "8E3C2447B56C5A1A6F62C3F88C84F153DC8077A0937707884C4A76847C0093E928C016C5B3862E51ADD5DE96773F3865", "hash_sha512": "8DDD1941267E673CAD0ECAA60834D3526E01912C474AE0B88AA10A05AD918816BFA0BD072D7023EC8DD2E97B86202FFBFB619D1C3DA50332AC3E15AB06D2B5F2", "hash_ssdeep": "3072:gBAcM71VZHpGagCoezIrOAt9WadAHVUfn6yLcDFEy13brvkVbFokvkN:g8pECoe4OaYFEy56u", "hash_imp": "5CACAA9C1D48B9312E5A1B4612FFD9D4", "hash_pesha1": "60574F58F5B6737031238B9108A631093335281F", "hash_pe256": "118E4C830BCE63BF3EF0A1C2EB667011902C9F0589BB8E822244EBFE122925E2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Installer Verbose Setup Log Analyzer", "meta_original_filename": "wilogutl.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "wstraceutil.exe-EDDCA5E3D6C652B50CA2D6A64E2F9341": { "file_name": "wstraceutil.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\wstraceutil.exe", "hash_md5": "EDDCA5E3D6C652B50CA2D6A64E2F9341", "hash_sha1": "26862EB53585568A5821135A7639D00D11E9EF8C", "hash_sha256": "BF66D70D50987584D84749FEEC01A3D3F8E7D6589D6DD3828CEAEFDF9E014254", "hash_sha384": "FA5657E3F43AC17282FA42470AC9CC473A9A6E731627AF788D412AE1E02097CC92F726EC46C2DF2400FCD7B1F5E29422", "hash_sha512": "B95F9B5BA24DB6B85161B9A722DB6112DBDB2B15B3912CBD603CCDFC7B93420A6F796382E9A8AD44E91B597FAB855567AA5516194436589933FEBA4C0F9E8A12", "hash_ssdeep": "1536:3cq4qi1m5QItB0EQCoc1hFf3y5JmQtnACt1aI5ygnGbBCgkXW:3cq6iqM756/JHjauLGbBCgkXW", "hash_imp": "39C29C368DFCED1DB8143576B37EFFD7", "hash_pesha1": "62F5B257D5B43EE1F828E17311C8E4BF715809B2", "hash_pe256": "A45C9994D2BD17D025705801A9E2D24667A4B0B2F40DB1D21D1B7A4E6A76AD10", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Web Services API Trace Utility Tool", "meta_original_filename": "WsTraceUtil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "AccCheckConsole.exe-D5777B6C068E726AF25C21FB0F9608BF": { "file_name": "AccCheckConsole.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\AccChecker\\AccCheckConsole.exe", "hash_md5": "D5777B6C068E726AF25C21FB0F9608BF", "hash_sha1": "C2688C6600F7BA712D7B5987C46F526F6049C3AF", "hash_sha256": "D70D8281EF0F03342F3C0D4E680907B98A86292709FEC0B23FDAB34AA84D43C2", "hash_sha384": "F484762A946E57EC8B30CA42CAB16BD4E4FA43CC5D9E4EA64B1E4D36CC9654F1371E97C0DD727FB11985BC1518FFA8D6", "hash_sha512": "93773A96298D6EB6993FA06E1080779924A0DEDB316C9625019B45253C516A1E54CADEBC877C33E81749DC61BE2B41D7BA3F38A21077616D5501D08000926C95", "hash_ssdeep": "384:+LwCj6aYZS0reG41oCvYf6kQFTFemhjITi3K+dwJugM6gQW2VQwWZE4JeRlFO:ABkC5hnjHK+dwJuugoVQ3H", "hash_imp": "n/a", "hash_pesha1": "1C0230A9362C27FF3FFDBC717228D4141D649D19", "hash_pe256": "65EC0E5CA89E67EE2CACD69F9C9A02ABAE4091F275E2B3C32EA4245B2A56A358", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "AccCheckConsole.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "acccheckui.exe-52BD0FEE326B0CED8BAC30D96F44C663": { "file_name": "acccheckui.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\AccChecker\\acccheckui.exe", "hash_md5": "52BD0FEE326B0CED8BAC30D96F44C663", "hash_sha1": "95359373F16FD9C123E4A4752A35CD79D8B85459", "hash_sha256": "84DEAAA820CF84A83175C774BE9AF516D92A165948285FE81D0758DEFFF5DF75", "hash_sha384": "D08F61767EB33AC80E01C0BA9B81FC20A799981AD9FAB21FE0C92A049687F9D9B789F4B0A798A7C63C0088B614AB38E2", "hash_sha512": "3977C831CC45887E7BDA313DAF0F0B5442D9625C1366B0F977D4455265C5937DC52C4BA61076D20C360C7968131DEA235FB662080E0A6C8CD95B3EF659321CA2", "hash_ssdeep": "3072:coG0eEey3LrG/kWyIEWJYetCSZaPh6uEPl4iGo+XTDhPzpicK/QUK:co5933ObEWJYetyqk", "hash_imp": "n/a", "hash_pesha1": "3F4D52AB1CBFD916BE56FC0E4CB62D43149F2036", "hash_pe256": "039D7331BEF23CC1745E24965767B4AD335B7B3C53DA98D6B916A4AD8D674ED2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UI Accessibility Checker", "meta_original_filename": "AccCheckUI.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "VisualUIAVerifyNative.exe-D5CED91E6E73682D5F80419AAC43725E": { "file_name": "VisualUIAVerifyNative.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm\\UIAVerify\\VisualUIAVerifyNative.exe", "hash_md5": "D5CED91E6E73682D5F80419AAC43725E", "hash_sha1": "7B5839D8B5ACE3A7E0CD653327EB241C2A5AFA05", "hash_sha256": "795434107117BA9D0D75D6502DA003D4765F978460E83746DBB7121BCB622CFB", "hash_sha384": "5D560CBB1A26DD181FC0F26E9EF1A77E8069187E2BF9F735B05F644B13C349DE6ECD7F3E4C12A8AF240DBFBE65516DFC", "hash_sha512": "6409486645CC24F0E261EFEF46EBAB73340CCDAFE20B7A7FB8EE75E27156858161ACD7B1C125AD8B9204DAFAB5BA98A84D538A53A56EB1F75AF00EA8397AA43B", "hash_ssdeep": "6144:yOqyheCdi1s8GbW5eCxWmuPfOBVODnom8gjJOv3AaNWGIAX4c6UdpDl4:yLGHCQmm", "hash_imp": "n/a", "hash_pesha1": "255F4B55CD6BC15A5EEA38A2B560B0EA8C3EDDA2", "hash_pe256": "30527B1C8512DAB5FC8C93A622CC0187EF935FB8441C271AAE48A2F67F732CF8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Visual UIA Verify", "meta_original_filename": "VisualUIAVerifyNative.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "accevent.exe-EE4E6F4157D2F4A00810ECF85D685644": { "file_name": "accevent.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\accevent.exe", "hash_md5": "EE4E6F4157D2F4A00810ECF85D685644", "hash_sha1": "AA8D66E3FDFA1C6C879CC6D482C5BAAF6F4D764B", "hash_sha256": "939F3B8F2AE50D2A619C4EA6BEEEC3E41CB002C3FC83D97CE189F764930F2C91", "hash_sha384": "EF6BAFD324E16F17B97D39A5D27404551FDA76BDC4D46BB5E85FE5CD7A8EA72A8033B00CC8D8894C7D5690D13BCC5417", "hash_sha512": "404AC7375CD529B2A538BD739699AE1C9F72075C12EB97628C730F08342D09FDE09C6D584529ED6CAAF78B4D95CC14CA10097D74625427B281D092D6C0F78497", "hash_ssdeep": "3072:h6BsgbckQLm0/DGaocJcXhijscGP4Pmg53UMKYMKhCfntTr1v4R3Ok:hn2cPLPGNcJEhijscGP4Pmg53UMKYMK1", "hash_imp": "7B793F8F7229B0D099119D454953C350", "hash_pesha1": "424CA79A6FDA1A23583FAB6FD1914304FE8BDE82", "hash_pe256": "C2A8663F1B1A61C794A78FDFEE441F2C69499A27A040C7FCD42865832117C31F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Accessible Event Watcher (64-bit UNICODE Release)", "meta_original_filename": "ACCEVENT.EXE", "meta_product_name": "Microsoft Active Accessibility", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.0.0", "meta_product_version": "7.2.0.0", "meta_language": "English (United States)", "meta_legal_copyright": " 2012 Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "betest.exe-E719594B4DDE3D25952F24BB0D7F1138": { "file_name": "betest.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\betest.exe", "hash_md5": "E719594B4DDE3D25952F24BB0D7F1138", "hash_sha1": "42986F5E730C931359B8E57472FD58F001547243", "hash_sha256": "329FE912E14CD49AF4AB2EB63927DE5C7B820E54A3CFE679EEAF820F4117AF4C", "hash_sha384": "60D70A5EC146C19BBDF41D9F5D4EEA1B19EF0AF63398112AE83BD09CE5CAA762D10861BBCA5F62F7941F134F916658F5", "hash_sha512": "A2254E85AAC91B1E9248915A69B6B550181B17E38E58136C85AFBEDAE7005ED780ACF5CB23CE5AB9553E28C87803B434DF877BF75FCA2A9B5A7ECA516CAF1240", "hash_ssdeep": "6144:PSZbcJuMfMM9HUevaTzYLrU74QaPU/rvJBqM:WQcIHvvG4mvP", "hash_imp": "ACBCD41857C0CBCEDF3267CDD5711D84", "hash_pesha1": "6478397897202D57460CFDD5F84E04BEFC3F17E1", "hash_pe256": "5DC6D7CE8BFFB1D23A85D1041D67FCAFAF422429EC86937D94422F487CD2DA6F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BETest, Volume Shadow Copy Service (VSS) Backup/Restore Test Tool", "meta_original_filename": "BETEST.EXE", "meta_product_name": "BETest", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/329fe912e14cd49af4ab2eb63927de5c7b820e54a3cfe679eeaf820f4117af4c/detection" }, "cameraprofiletool.exe-2CD46186D44C278325B6B00E5D46822C": { "file_name": "cameraprofiletool.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\cameraprofiletool.exe", "hash_md5": "2CD46186D44C278325B6B00E5D46822C", "hash_sha1": "1D370903CA1A1C605214DD51F4BCA083A212F0E2", "hash_sha256": "06EFB53A8E913084F7C4E5C8F47B2D8EC157DAF5339A0BA65C9E48D7147BA27D", "hash_sha384": "8874B6D13ADE3833175F7CEA2C02DF57363143871A69079B186295FB95E3690CAC7B6C32AD706ED528AC9736EE520E04", "hash_sha512": "FF1250CE93A860BD84821E56019A2C066A380C6FDD83D9B5446826943FD0F4ECBC8774D53D0BCCB7D25A41B40ACB2B456AE990A08A5EB7E3AE98943D8FCC3807", "hash_ssdeep": "1536:qbJdCCDadyUXD7BR80GdrsEATrWy4NQvSkmd+3ahYW3NitrXIXHgxIZ:OCd80wrsEAfWBNQ+d+3ahYW9YXCgxIZ", "hash_imp": "31107972DFE8ACD3947D4ED3DFA4E92D", "hash_pesha1": "BCA4FF14B250E9DD7572E70E7D19E8E57E7ED456", "hash_pe256": "FAB830C9A8937B22794B1E9EE43CDFA652B4DCDA71D5635474FBEA48AF02DC95", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Camera Profile Tool Test App", "meta_original_filename": "CameraProfileTool.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/06efb53a8e913084f7c4e5c8f47b2d8ec157daf5339a0ba65c9e48d7147ba27d/detection" }, "cert2spc.exe-A725321361AAE077A560502C1E30BCD5": { "file_name": "cert2spc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\cert2spc.exe", "hash_md5": "A725321361AAE077A560502C1E30BCD5", "hash_sha1": "5D56BD6FDD5966244BA8925D609EA3BA6927952A", "hash_sha256": "382CDB682060ADD0EEE2179AFB4C3F59A8716C6ACC49395DE3E9FD5214A1052F", "hash_sha384": "FC37A40487FD6814CEC4DCD80983BC45C1AB4BFE8F1323A3F349E4F3B966C1F55A53B5748BA13FB0BBB77CA6FDEE0FA7", "hash_sha512": "644FBFACCA35266D9E76F4C283447DEB429EFA66F9DB4F884BF3C8E19393E6399F9753A4F7F7273FB31EAA168002AE4C886D9D0E9AA77F6C7B4EF0BE9356C69B", "hash_ssdeep": "192:Az1a6qaZb4k6F+Fzo/5FsCFuQLft9gRWCa/WnemiqMW8bpVWQ4eWpilGCNxXeRq1:Az1eaZWUzpuv9gRWn/WnemSq4JeRlFQt", "hash_imp": "0BF12D39CF42BF3594FE8ADFCC17DE5E", "hash_pesha1": "63D19E133FEAE8FA6F41E9590B07CA1E9DC82589", "hash_pe256": "BF256575080CE2ADFB0D1E4D77299312A8747ED47EB1B8DC23886355F2034D5E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ECM Cert2Spc", "meta_original_filename": "CERT2SPC.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/382cdb682060add0eee2179afb4c3f59a8716c6acc49395de3e9fd5214a1052f/detection" }, "certmgr.exe-B18C3F2FD9A7E9C7FC8C91BA0BE5FD89": { "file_name": "certmgr.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\certmgr.exe", "hash_md5": "B18C3F2FD9A7E9C7FC8C91BA0BE5FD89", "hash_sha1": "D0B7077AA84C888D86B75D1EEFE006E0D81115BF", "hash_sha256": "800AB3A602177A4DE32310C0A1D260D96C610BC69E0AE3EA2192D891F38744F6", "hash_sha384": "8E4D84BDA7807981EE08DFAC615888049E0806C0AF4B00214777511E302FE846E80F8CE4DF943DA05E1645C308B4B9BD", "hash_sha512": "578E521C14EBA6B732384F234B2945F12E3AC6E801B22DA904D8D6EF5C19F7235656BC5E759DB0807BFDE4811AA23777E9DFD9DCF4D945F20CB5BBA318F1BFFD", "hash_ssdeep": "1536:T+VLohsoNqVWAN9Y4KFa5Qgmq8UBYw+WXsA9i9vYd:MuqVWv/E5QXUBt+WXsN+", "hash_imp": "E49BAEF8540FDB04EDBDE6ACF06A5124", "hash_pesha1": "18825675570FBC97F447CA6E746EED8124FBB190", "hash_pe256": "007289363E8FF081C5D997C1DC46BA9A0A6765ACBE59B82CE2725A30F74D31B1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ECM Certificate Manager", "meta_original_filename": "CERTMGR.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "computerhardwareids.exe-D057B7E43C654976FEDECDB091C4432C": { "file_name": "computerhardwareids.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\computerhardwareids.exe", "hash_md5": "D057B7E43C654976FEDECDB091C4432C", "hash_sha1": "4D94C88D5E792544E5DCE5E11976F7F22BC84A43", "hash_sha256": "DA559FB7B8D258ABE3854AE9BD4D879A99A3E8312CD683DA9E1F36A2C3C3A932", "hash_sha384": "3A044FD75BE41406D20289E0B676247DE9914DEFB455C9A7FA2FEA36E3FB444B110663A412C35FBB7AF85D3485C4780D", "hash_sha512": "CCCB4A3FFAD9E3AB35C8E6D6740255A5B2E4C8ADA5508929BF8136A4169B3390997917269A8116C69BB258424E4D50C142584C1DC30AB1A25B3F10FC9DF1CC83", "hash_ssdeep": "768:7K+BoM1vxBtzm8JY//CVQVKLG5i7odOqB:7KA51JfPo/FAGUoQA", "hash_imp": "660AE429139CE46EF294C187BEEF1BF1", "hash_pesha1": "B5A48D8C5C65309626008E75BFD24EDA6143DBE0", "hash_pe256": "A123DC759E2D21FBCD0B390C022AA9DEF068B16F2CDC1FADDBEF1258063BEFA7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ComputerHardwareIds is a tool to derive the computer hardware ids from SMBIOS information.", "meta_original_filename": "ComputerHardwareIds.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "convert-moftoprovider.exe-DBE1C15194A8D7AFCC53A664226AF243": { "file_name": "convert-moftoprovider.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\convert-moftoprovider.exe", "hash_md5": "DBE1C15194A8D7AFCC53A664226AF243", "hash_sha1": "0EE431B71287197BE04A7780151DFC4629DF4A2C", "hash_sha256": "30BBA3573CC732ACFF0A625B572977C9168758692DC42331B0E710C37438B09A", "hash_sha384": "44B5D49F9EC0F0685DDC8FF6B118F8AE6335683159F4E529C9559E4F05779CA250734C2F31ED4D78A4E631D963C1F2A6", "hash_sha512": "0325FB263C264FF4A1F60FE5CC8F7291B9B5675C90C0B3A774C386065BA10FD0E7562E5ED92507F5581B9D79F5F2651E20C65F62F56F3AE2576D1D2165D12F2E", "hash_ssdeep": "3072:OB3r9Mxp/DrrFP0va7eyzGX/dEo1aJ6Xo:Otc7F0a7eyzGX5sr", "hash_imp": "AEF5331831ECC2815A48D7703AB4F4FB", "hash_pesha1": "8B2D14AC81ADF207D04C7C67348E70F175733A05", "hash_pe256": "34C2D1B82F6FD882A58C85157F56CFB60E252A75F6857D1EB11F9B05CA0EF571", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI V2 provider code generation tool", "meta_original_filename": "convert-moftoprovider.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/30bba3573cc732acff0a625b572977c9168758692dc42331b0e710c37438b09a/detection" }, "cppwinrt.exe-DFE9EA9992099AD626262DF1AAEDAB6F": { "file_name": "cppwinrt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\cppwinrt.exe", "hash_md5": "DFE9EA9992099AD626262DF1AAEDAB6F", "hash_sha1": "E8D4D4B02EB7FE93E959109A9164053BEE593630", "hash_sha256": "063B644F5D103ACF551BFDE052441D11D5816E4E981A2714A3F720BDD9787ACF", "hash_sha384": "4BD28992F393D175E6EEB9B8D8221B555059B72EF992984C46B2050B12BA7740AA1858D75DE2F8C55F9B91339E8096F8", "hash_sha512": "FC1B46DE597521F170E79D11FCEC4F86A65C0E2DDC2300C6C9FE181DA5C70EECC3E8BDDF75E7A9DD55A67FA755C49F877B40E4C476C2513B3A046EBA9E969C2C", "hash_ssdeep": "24576:uM99jN+doLjdE7gUKFQI9lfHpyNsHujT4R1NtNh4AMgpDeLfPcY5kTl1qS4PQvGD:10cll11z74bQkdF9HSkpDjeiR/j573TD", "hash_imp": "6752EDA56876B8755B7CF239CF9ACD46", "hash_pesha1": "A97A2F757C6066F2A1ED5E322891AA7F5CFF22AE", "hash_pe256": "AE6C0AF4E7FADF19C694B5EB98B1DF3D9A524A25CB9D063638A920C8BFF59638", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "C++/WinRT", "meta_original_filename": "cppwinrt.exe", "meta_product_name": "C++/WinRT", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2.0.0.0", "meta_product_version": "2.0.190620.2", "meta_language": "English (United States)", "meta_legal_copyright": "Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nC++/WinRT v2.0.190620.2\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\n cppwinrt.exe [options...]\r\n\r\nOptions:\r\n\r\n -input Windows metadata to include in projection\r\n -reference Windows metadata to reference from projection\r\n -output Location of generated projection and component templates\r\n -component [] Generate component templates, and optional implementation\r\n -name Specify explicit name for component files\r\n -verbose Show detailed progress information\r\n -overwrite Overwrite generated component files\r\n -prefix Use dotted namespace convention for component files (defaults to folders)\r\n -pch Specify name of precompiled header file (defaults to pch.h)\r\n -include One or more prefixes to include in input\r\n -exclude One or more prefixes to exclude from input\r\n -base Generate base.h unconditionally\r\n -optimize Generate component projection with unified construction support\r\n -help Show detailed help with examples\r\n -library Specify library prefix (defaults to winrt)\r\n @ Response file containing command line options\r\n\r\nWhere is one or more of:\r\n\r\n path Path to winmd file or recursively scanned folder\r\n local Local %WinDir%\\System32\\WinMetadata folder\r\n sdk[+] Current version of Windows SDK [with extensions]\r\n 10.0.12345.0[+] Specific version of Windows SDK [with extensions]\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\cppwinrt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ctrpp.exe-B91DF6677FD546F0726637ED4ADC0F86": { "file_name": "ctrpp.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\ctrpp.exe", "hash_md5": "B91DF6677FD546F0726637ED4ADC0F86", "hash_sha1": "9E227AC1378E3EFBD5E1A8CCD7CCBCD88D51F326", "hash_sha256": "B2CEF2C44EB525971ECCB15850F9A144CDA90AEB9A3FB3E9830EDA9107EB00C1", "hash_sha384": "F1A48A95AC4B54B5895BBA23578ACDF48A320415958F6284E56254EADE064DED626495C2192B614AEA17BB417B5B1F4D", "hash_sha512": "12C805F275D89F59AF0C067D8C686E672602F624AAEDC9FCDA66B803A9ABE9AA1EBEAEDF3E0ED1120A409F69A7382B1496CAD3443A4525FA1ABA88FB1A1E6D3F", "hash_ssdeep": "3072:lLvnUtKOYrdJpDIrvYkP0ktBAvog0LGc8nnT1bZBmCK+ntnQnhLofjFdF3vGXu9S:ljSHIJNBtKH0j1GX3WhU", "hash_imp": "335B65F46E68600694D941A16B8B4A92", "hash_pesha1": "B93FBB0D20CE4A9D5C9454161ACFEBA5E180D307", "hash_pe256": "11EB4C284783346B3466BCB3CBE09EB011106A50559C6BDAC288E11778989546", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "parse/validate performance counter manifest and generate helper source files", "meta_original_filename": "CTRPP.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/b2cef2c44eb525971eccb15850f9a144cda90aeb9a3fb3e9830eda9107eb00c1/detection" }, "DeployUtil.exe-564EE245C89CF4890F3987DA2017A902": { "file_name": "DeployUtil.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\DeployUtil.exe", "hash_md5": "564EE245C89CF4890F3987DA2017A902", "hash_sha1": "DFB0E8FB339C2CF8399471C57C3AF0D95BFD8417", "hash_sha256": "5989030095450AC23D425372E448516F67F14525B244FBA2C09AB693C1CD9488", "hash_sha384": "F8AA77FC348DC6C4502F7DBCCEA4C502EA47D8D056CC26D7B76F8C7F5B1556A90A4E408FC0E9CA4FF034E0337C518179", "hash_sha512": "EE0DB6BA826C8CF4424057CB55F90CD6E91A5647A017B50E4D599B6AE98FAD77A1AF00295EE3BB09DE90F23E99AFEA32812CE649D24AC28792DABE6DDF0F2B6F", "hash_ssdeep": "768:p3HjhShdBoCmG71hQHWlcDkH4Y2TuxB9nJoCYdRcPT:FHSB9RhQjkH47Y9uOL", "hash_imp": "579C68BE44458A8BCEFAA4BA411569B6", "hash_pesha1": "3F9168F578EF390D8EB21390FDA0F9221B795E39", "hash_pe256": "C414FE6944B2B326DBA7855619B65E08081F854FFA9B955DBF4C7C7FC779288E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000052C8FAF5B90BB753AC000000000052", "signature_thumbprint": "8438EA0A58759BEA28DA7CF658413939F2AD5BFF", "signature_issuer": "CN=Microsoft Windows Phone Production PCA 2012, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Windows Phone, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5989030095450ac23d425372e448516f67f14525b244fba2c09ab693c1cd9488/detection" }, "dxc.exe-C0D576515CB38D7788DC8B95DD3128CF": { "file_name": "dxc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\dxc.exe", "hash_md5": "C0D576515CB38D7788DC8B95DD3128CF", "hash_sha1": "A0F3AE106A6A8C1C9B62096712B6FAF32E900BA4", "hash_sha256": "D1350600A09F18C78A8E35AA87EF8EE9B774D4D4E7660528456C8219C2C05A45", "hash_sha384": "5940D1B20D1DFAD86E41CF649C4C5F4A901D9F5348A924D574FE5222D87C48EB89264D1CA159871D094625E005950882", "hash_sha512": "B5B2AF8523DF2DAB5BC20E8436EBA3F4DCFF1521990BEB465D8EBB8A69D061968D47A65E07F9CAE1A55F10B8FC46C3E1D75BD3F6A52A6719D5B5A5F3C4EEDEAF", "hash_ssdeep": "3072:2tmDlxWNnppKUlgGJPxaZU1IMX6Jm4r9xYuqr:HD7W3pKigGJPxatk7", "hash_imp": "11FF4520BF8D8095097938C61FECF13A", "hash_pesha1": "3ACFFEC8A0298C8C06B52C2E690EF58E65EEF1A0", "hash_pe256": "EF4F6ABFCEF9E5D45B8CB4AECFB5066D572441844244960F029478A75E4136EA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DX Compiler", "meta_original_filename": "dxc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dxcapsviewer.exe-320BC6EAFCA5CB9F7F031B34E522DC04": { "file_name": "dxcapsviewer.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\dxcapsviewer.exe", "hash_md5": "320BC6EAFCA5CB9F7F031B34E522DC04", "hash_sha1": "DFF7D3CDDD2FF60DDE44FC66408950A6D5AC4B1C", "hash_sha256": "180202EDB1CEDB47F912C464F806D24C6F99FD7B2D37B92E71043268C16CDAB1", "hash_sha384": "47CC9E285D490EF2C87F2F6622F519A4B44D89E88E6F269E5A3CCF9ED88D4589A553ED97B10F90C2EF5984C9A280D308", "hash_sha512": "0CC4477E5502886279DD86AC24E386D5A639016E6B3E930659CDCA79FEA199DB62543E50D4080056B686AA3B4A6FB6C04D209D0F83639BD06DB6F72DC74EDC0E", "hash_ssdeep": "3072:2QKycQBswVrRRDnqiY+MEGx/oonsD1fsW2PIG4WRiuXmC:8yzBsEvDGEQ1skPSC", "hash_imp": "4E8E4279F4DD93D82ED3BFC4C0F94DC2", "hash_pesha1": "BDBF0C3ACA4AD69E673477EFBA25B0E785121316", "hash_pe256": "34CA635EA72767FA09D230D9E9FC2117AFA4F5CEC0BEDC1AE55AB07360169F48", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) DirectX Caps Viewer", "meta_original_filename": "dxcapsviewer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "espexe.exe-FEB6F852EC537B25295350B62F7374B1": { "file_name": "espexe.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\espexe.exe", "hash_md5": "FEB6F852EC537B25295350B62F7374B1", "hash_sha1": "4F3AC4EE1C6AF5CF91A59E2698B76EE0CF3EFE08", "hash_sha256": "F33EA8A14CB1A5D44ECE0289CAA291D21AC77BF3342E24594E7E73BA7953987A", "hash_sha384": "FA31980A8A1C2FF171B565EA031288408E341172B83DF3800C2EF6D4705CF4DC4C2E6E241C5ABE94CD1553DD544E5530", "hash_sha512": "247E0A689C2F10A253C8195FEE62DFA15555CE9C65901E3BF3598B8087418F2B7E1E8614B6C6F6F661D99B1BC402E872F7FCAAB5A2E2868ECCE1D3ED6151F4AF", "hash_ssdeep": "768:lwyyBB/IVwW9KSFIKwpcLE1PafDUYhzCynXWM5U:FyBB/IVpjE1PaYSzCynGMS", "hash_imp": "539C5EEA4AB4A28B793575D4BA844523", "hash_pesha1": "01F883BF010A7625F8A23A6B43C7822A21CE6E61", "hash_pe256": "E22726C9BC2A00930529AAA83E3B33A364A2A46DD13B1263F6D36E5A07EF9F3D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) Economical Service Provider Application", "meta_original_filename": "ESPEXE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright Microsoft Corporation 1995. All Rights Reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/f33ea8a14cb1a5d44ece0289caa291d21ac77bf3342e24594e7e73ba7953987a/detection" }, "extidgen.exe-4E0D942782FA4F2948CDAF99BF0B72D5": { "file_name": "extidgen.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\extidgen.exe", "hash_md5": "4E0D942782FA4F2948CDAF99BF0B72D5", "hash_sha1": "60FAA80DDA39CB59D9E566BDFA5C645486E5AE31", "hash_sha256": "DBC69342C75DD6A641D62303C72002C474B2699DCD88417573744A930E07726B", "hash_sha384": "67ACFAD946F9506F42A7FC09096161DDC317BB5C708182C199F71B8FDFBA78D598D000E308DFE4E2D1A9767E7AE58888", "hash_sha512": "958F63158EB5BE56DFC612DF566F3688323EEE98681AEA071D86B15C5EF239311BCCBB01CDB145747C284D0F4C5E3E815194FD59DCD641FE6A403D0345B146B1", "hash_ssdeep": "192:83DSgjZYM8M+u915rBclCrmdcuQLhWOW8bpVWQ4eWKyitnkwqnaj0LF:wHjZ0U3B2C6dcfWwJyiFlIZ", "hash_imp": "7E0E18E97784B86A90E2C6D70CD1CBD7", "hash_pesha1": "9A2B478EB0958DB316193C4781EBD7213C4439AF", "hash_pe256": "CCDE806EBAA80CEC9908BEC062AFFCB192248F8526FB141B8645B4920A84DB94", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extension ID Generator", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All Rights Reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "filetypeverifier.exe-4C5631352E8E3488D1502C76AE00E806": { "file_name": "filetypeverifier.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\filetypeverifier.exe", "hash_md5": "4C5631352E8E3488D1502C76AE00E806", "hash_sha1": "06147BABF0983BDB46CCEB87546AD97AC4FD5D8B", "hash_sha256": "A0492921C9AD492DB870325508659A8B9312E8750E9BD1DA901CC12CE1C02876", "hash_sha384": "92AEDFC96E8AA609B30F3AD3480C43922E711769642A7BB0B6CE5069A4CA3FF3A68E3736E27A82A19000E31C02A81476", "hash_sha512": "8AF8B1B84F8442B6BB81F95B8327558F653AF04B0C7789A43EFCFB5D6A7B6EA8F4C6FE659F56EE6D1A0B446159A9D9E3BBDCCE98F8910C2FFAB29483B22020B2", "hash_ssdeep": "3072:Kr6vDDxOIf/7BjZ59Fg4en7aJj3YeMeQFNAX15MMz8lDw/SSuH7laLmM8OR6iQ3n:k6vD1ON4JC2DTWx0AmcPdYmdpoBIURe", "hash_imp": "0A29D3688DC627D9C34B2F2855796027", "hash_pesha1": "3F19EDFF730824388B110B1ABD176CABEC8958C3", "hash_pe256": "D76AD1AA58BEBC2779AF3D4B36CBE2A36B4E467EFFA0401D6D0B79C7A0F30903", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Type Verifier", "meta_original_filename": "FileTypeVerifier.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/a0492921c9ad492db870325508659a8b9312e8750e9bd1da901cc12ce1c02876/detection" }, "filtdump.exe-458EBB99A16A062E71D3C285BC648086": { "file_name": "filtdump.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\filtdump.exe", "hash_md5": "458EBB99A16A062E71D3C285BC648086", "hash_sha1": "BE7A0A4134EA434E40152A67F4231F0E385ED3E2", "hash_sha256": "9128513E5C1E6D0AC976D391DF5C29EB271E81E48E95EE3A22F1935045FE4787", "hash_sha384": "760CBAE810AFCD3F9CB6195280D698594126D70538BAA3F59A52C134B4F1A26F45EDCD2224CE0B2F72B99A32CFE1A1BC", "hash_sha512": "2C7CF57B47DED42EAD17E7B4C29B070803848C2262F1D870D5B7D945BE431A35BF7772E8625B23FEF8F933A5DEAD973BB4D2E046711C351DA161169413258B8A", "hash_ssdeep": "768:kQKWi6k/Aa/BM3q508QYeFc5SKKZFbvz0u46:4WC/Aa/BM3q508QYeFc5SKKZOu46", "hash_imp": "BC1DB23559EE79044A24318DC014E563", "hash_pesha1": "BF33FFC80D506EE0336C6189038770BD3EADA7A1", "hash_pe256": "F1233C93DAAF13DA8A97F86EBEC2737E29C51F524C2E7DAC53524DB516368BB1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Filter dump utility", "meta_original_filename": "filtdump.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/9128513e5c1e6d0ac976d391df5c29eb271e81e48e95ee3a22f1935045fe4787/detection" }, "filtreg.exe-D4391002ED47B07D1C97BA56C28A0DCA": { "file_name": "filtreg.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\filtreg.exe", "hash_md5": "D4391002ED47B07D1C97BA56C28A0DCA", "hash_sha1": "BD24A1B42BD7BB7DCC3E1414F48EE872367512FF", "hash_sha256": "61C5E6772FAA7CC47991D32A53D4EB16AD1B7564DD3B432D6296279ED3F2159C", "hash_sha384": "70AB87E68726E0BE6444877A008AE5878A240420A0B2675E140787B41B4B2D14C78BE68030FDB5F27AA0C74961A46BF3", "hash_sha512": "D9A8130CA873E43433B68715E3B512F5D4A874C2A671D46D311D8FCA03F0FF49751EE18673E2985B136A76FE6CCD65908394B35348D211134DCB754CD364399C", "hash_ssdeep": "192:cPr6Z3kqIHX+5wvvEAUpF8h+NlRVga+Q4VYKuyikWwyW9W8bpVWQ4eWGl5qAAqnX:Y6ZxIowvvEAUpCYZGWKDWwyW/JSlDeB", "hash_imp": "D6C999058D1C0C6CA941F7BDA4455C83", "hash_pesha1": "F0C5A7972362D1FB71752046F91E21582946E4C1", "hash_pe256": "CDA60CE446C2D4EBF2DD439D367761B26F5C664742A58CEDFB7F1DEED651BD84", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Filter registration dump utility", "meta_original_filename": "filtreg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/61c5e6772faa7cc47991d32a53d4eb16ad1b7564dd3b432d6296279ed3f2159c/detection" }, "ftquery.exe-4B8ED05C745F1D07B6AD05D2D49F9ED9": { "file_name": "ftquery.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\ftquery.exe", "hash_md5": "4B8ED05C745F1D07B6AD05D2D49F9ED9", "hash_sha1": "11A2F9612C79E1F8091FFD9188CCC5B52649A481", "hash_sha256": "AF1153F0C38A37CBD268D8133A7257ED9F9D7665359B5433F2E36BA1EF360996", "hash_sha384": "74386DB4EEA5EEC4073582B32533A28EB3E806F7C8CF7368370F16201A322D3F474EBFD2A264B1BBF1E53D914A6469DF", "hash_sha512": "3D853FADBD53229CF283579A6A3439F9F317D3EABE2E7D2B54E46C7B57CC0D800A9CB9D4C39F02D867434F721732CCB0A350A180A92EF4347B1D735E389B8CDC", "hash_ssdeep": "768:v2Aq/znu2gyGKFc0F+QaVhfZsgZoF5ZwM6rs4KZGNWs:uAcqaFc0FZaBnoF5ZwhrsrZ0z", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "E50FAF5EF323C592F2E8024E4FA56FCD4337EBCA", "hash_pe256": "D94626DCCB4D5948FF04D864D020E337901B8E71B8ABF935AAD05E7AF520F3C4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "ftquery.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/af1153f0c38a37cbd268d8133a7257ed9f9d7665359b5433f2e36ba1ef360996/detection", "error": "\nUnhandled Exception: System.BadImageFormatException: Could not load file or assembly 'Microsoft.Win32.Search.Query, Version=10.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35' or one of its dependencies. An attempt was made to load a program with an incorrect format.\r\n at Microsoft.WSearch.Tools.Query.Program.Main(String[] args)\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\ftquery.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "fxc.exe-38E4CBFAECF88274F501C6ECD0832AEC": { "file_name": "fxc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\fxc.exe", "hash_md5": "38E4CBFAECF88274F501C6ECD0832AEC", "hash_sha1": "61845A61C290FC766DFFCF9122E2D40925DE814B", "hash_sha256": "A2DCE4F55115BAE715631A9B19FE869723642061FB2F36EE6CA6D87A5353B026", "hash_sha384": "A47A32E77C0C8987C42CFE45711277383D5728CCA260D1969B919345A3400F33BC41342FF3396D80C3A55ABDA23A5BF0", "hash_sha512": "04F02C4EA801233505E073A524CCFC8F9B787302714072B11466EC7298FBD1D74D8AA45AAA571839141112F25867E06357FA00BFD8B0B6EE2EF0057586512B82", "hash_ssdeep": "1536:77lnH9pb2jTtQxCF+ZBmmIoztVYBHF4IqOroV0EKEV0YywBu3PjjG:k3tQxlBmmIozD64DOUaYV52Pj6", "hash_imp": "181F7552BA1EEF643BEC0F0CAAD8663B", "hash_pesha1": "EA5715F086F41C9984677C77E161B254055CEA79", "hash_pe256": "B6374123D1FD816041718C05A9AAAD431B50ADD9E9B5D7ACA26D7B22F460B8DB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "fxc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "graphedt.exe-5E1D46ED8BCB2348380B221AB9952267": { "file_name": "graphedt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\graphedt.exe", "hash_md5": "5E1D46ED8BCB2348380B221AB9952267", "hash_sha1": "DDE0563C32748ABC14193836245E1DA820EF9C3C", "hash_sha256": "684F457E78C61AA41ED915CDA89A5453E232E03EBA5E986C9DDFC97AABF5172D", "hash_sha384": "79C4AB5857538051E9443A916FC163D4F9DC2850737DE122EA0F0D226CA15A76ACA3CCB63543551619435BD8C9811C68", "hash_sha512": "ED1B06A97365373F9EF6FDBE6B62FFE3BEB0C69A05097F1485C22C08121C7B07A4F3675F93F36BA7B7BA4546891005BEAC2217D5494933D3557FBF5A56C54788", "hash_ssdeep": "3072:J3gJLPmdlxuNMhItoTs/TaD7g3pooolQv6289L6lqr/DgI6/wxHJplIcoz:J3gJLOdlxSMOV/Ta/g5Q3T9L6lqjX6/h", "hash_imp": "22072E30666A517289DB44F76BFA340F", "hash_pesha1": "CE9323FAADBC0E407069AB63171B43C71439FF9B", "hash_pe256": "A2D81B39CC03B92264A0CF2C38108B8CBDD95E8C52EE796F91059E3E4B996F63", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DirectShow SDK Filter Graph Editor", "meta_original_filename": "GraphEdt.exe", "meta_product_name": "DirectShow", "meta_comments": "DirectShow Graph Editor tool for software developers", "meta_company_name": "Microsoft Corporation", "meta_file_version": "DirectX 10.0", "meta_product_version": "DirectX 10.0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 1992-2006 Microsoft Corporation", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/684f457e78c61aa41ed915cda89a5453e232e03eba5e986c9ddfc97aabf5172d/detection" }, "ifilttst.exe-3FDB649AFB0FFDC2C1E63AAB02B7F766": { "file_name": "ifilttst.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\ifilttst.exe", "hash_md5": "3FDB649AFB0FFDC2C1E63AAB02B7F766", "hash_sha1": "DB1D8B8C6B6A2B1DD1BC4FC9EA160722900EF079", "hash_sha256": "97A73BC965DB9C2920153C1C1C0EB3BD738E1DA62F1F253611BC534E5716F6E3", "hash_sha384": "6311A80CF48CC6303D4EDC1F333FCB252813B71F03A59BC3C2AC1FB68B39BE9A0599650A2FFF9F74862A3A24712BA187", "hash_sha512": "79EE21362B842DB1731A67D2658E94A03C7D628DD27C0E195336C113FB8F399C25515FECD91261D0607978E5434D3E0013E2D61303C6D2E904DA88D9E4FD37C9", "hash_ssdeep": "1536:efw2J8xX9wMnvRLgddfqDhyaQy+Go+Jb6ba9a3L3XfVvgpTvezujzZLBj2S:Gw2JU6MvRLC+AXMJBj2S", "hash_imp": "45B8E63D1CDFE28B88D67E35A05EC273", "hash_pesha1": "3FF897B527068CE3950C1C0248C5A8549F124FBC", "hash_pe256": "4BAAA3E49641E79A304292B1C241C48BD72C1B29C8333E06CB581C296FBF8F06", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IFilter command line test tool", "meta_original_filename": "iFiltTst.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/97a73bc965db9c2920153c1c1c0eb3bd738e1da62f1f253611bc534e5716f6e3/detection" }, "inspect.exe-C2BE3E8768023C282F359DDC71B9D2C0": { "file_name": "inspect.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\inspect.exe", "hash_md5": "C2BE3E8768023C282F359DDC71B9D2C0", "hash_sha1": "8B9C1D4335B04E9E7D8C54CDEADFC0500C1465EB", "hash_sha256": "7C4D3080E314819D13D0A4F704068357D22DB5C447A2462980766065F5C40D84", "hash_sha384": "17F37A44EA994A22FCE9E73648925C46E2D0A506E09F52F6AAE113ABAB6593808B120DFBD71CF06C6323D69F4989FB6A", "hash_sha512": "E1031DF66D58391DD19C6811474A7E397B055C3E6AF4E1D0A1A1EB9A932FCABBEF6350C25E0F311E305F6F5B74255A409791826A939BF7E0FE57D54F9285DAA0", "hash_ssdeep": "3072:BRc2D3oPXT/9K9IjWOOOozLWFOCx4qjt9sF3UMKYMKI6Cf+sk8BTbNryc78DL+:nT3cXT/9KejWtPWl9sF3UMKYMKI6u0t+", "hash_imp": "FD9BA3997C843970551017713D9FCB16", "hash_pesha1": "6F4A24B915A3A7F5C473C8566C1CCDBB19A18EBA", "hash_pe256": "59FA897464BCC59AA3229AE7274E9183D7A3E4A2E3F1109F517C94921CF835CC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Inspect Object (64-bit UNICODE Release)", "meta_original_filename": "INSPECT.EXE", "meta_product_name": "Microsoft Active Accessibility", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.0.0", "meta_product_version": "7.2.0.0", "meta_language": "English (United States)", "meta_legal_copyright": " 2012 Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "jsconstraintdebug.exe-EEC55393BECC4919BF368574CD3A0A60": { "file_name": "jsconstraintdebug.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\jsconstraintdebug.exe", "hash_md5": "EEC55393BECC4919BF368574CD3A0A60", "hash_sha1": "6E77C31F4A26120EBC5CCD65A0151A3FB960BF0B", "hash_sha256": "1C5E4CF9DCA7786E42B7AC7A002EC4F253E566558E7FAD9A1382E0E14585C1C5", "hash_sha384": "70039237FDB0E973CD5E653BD24B565C06144FCB177B7AC5940F290E749263DD2638D7A6E415F51A9B6CF2A4E8EB1B55", "hash_sha512": "D04649E034745E22236551E1008C799E23AD164784EA1DDEBABE3F0D7CCA5A304798F87AE3A1EB403A4EE1955DB157D2DBE5B0F88F8BD64E94E7E6E3FB618FD8", "hash_ssdeep": "1536:CKlSLCyrObv/n/UF87U0euVOz2bA5aGXqAFc:25rnFuU0eu075aGXqAFc", "hash_imp": "DC25195F0432B41638177233FA7627AF", "hash_pesha1": "7C5355FC2B6EAFB34CBF8B8B2D6013D8C9182590", "hash_pe256": "99CE61FCE10BF6AC81B58A48D4290B73429F782CEFCF4A9D206345DB8BA2086E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "JS Print Constraint Debug Tool", "meta_original_filename": "JSPrintConstraintDebug.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/1c5e4cf9dca7786e42b7ac7a002ec4f253e566558e7fad9a1382e0e14585c1c5/detection" }, "makecat.exe-22641DE744FFB7DD1A9370B3734D6486": { "file_name": "makecat.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\makecat.exe", "hash_md5": "22641DE744FFB7DD1A9370B3734D6486", "hash_sha1": "95AB066B92BBD4E521FDB93D0DF06B407EC9724E", "hash_sha256": "35049D0E21F810D69059A54711C58E954B3C671AB15C54D482019E4411D4CDC0", "hash_sha384": "AE786172E77AC9D3F012701713344445826B0B927AE5AE976F858A5C6CEE440D4051533182B04F94494A53E92BF87A67", "hash_sha512": "C94F101791F94A2315082563ED91A2618CC6359C6001B69D36E4FA93CF1285CEC73F67D4FEF61CAC5B98852C2F38575AB2497C228FC1E455EAAB411FA54E7C68", "hash_ssdeep": "384:rCz93FIf5oUpzJeQk5oxj14SuJaZ2tXWD1ZW3+fzuFNlIewT:uZ3uf5oCzAuAST+GW+VT", "hash_imp": "97A430E897EC5B8A05DA7640A2E8DC18", "hash_pesha1": "A35C8342698854003410AF184FA83ED66D1448AF", "hash_pe256": "763CD08A0073131E70B35A4BCC8EA4B3A71685A2197748426F0988AB11A04692", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Trust Make Catalog utility", "meta_original_filename": "MAKECAT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/35049d0e21f810d69059a54711c58e954b3c671ab15c54d482019e4411d4cdc0/detection" }, "makecert.exe-1618A3DB4F98DF42A0FC19403B9088FA": { "file_name": "makecert.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\makecert.exe", "hash_md5": "1618A3DB4F98DF42A0FC19403B9088FA", "hash_sha1": "27BD3473BD3E0FC92F06DA938A0B45D530FDD65C", "hash_sha256": "0BD928FC54556118C6ED2E83DEAC9B220AF29AF604ACFB5DB7A37202A48045EF", "hash_sha384": "3FA98DC82904333E2CA520794DE507B4925F8AD0AA609B0785CEA5BCD0237F25635139E0F2F30AFE299E8799DE26C0B6", "hash_sha512": "076996ADB04ADFE6291B616DE4AA4AB70FB806B62A63866BAA6D0E22728FB5B357EB2E9DD0573DFC14FF6187BCA9C6D3DA5E2977179ED8D1249E5FBDF4F8235D", "hash_ssdeep": "768:+S+ef787l2Igb9ZgREqFirzFlDWxzh+ScgtmGebTJayaarFdID:/78z9PEzCSvg6bTJayaarFdID", "hash_imp": "BA9D7CB1A0DE45A91B66C4A2BF67AA72", "hash_pesha1": "29C9674F775E73891F1DE6EA1F7815DCF0085A2F", "hash_pe256": "627E0B9208C09BB9A03148837F368E94C9A14714C24DD4F17EDAA7A1CE9B8C60", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ECM MakeCert", "meta_original_filename": "MAKECERT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "makepri.exe-560D87764FE84E3BA6DF40AC94ACEB1F": { "file_name": "makepri.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\makepri.exe", "hash_md5": "560D87764FE84E3BA6DF40AC94ACEB1F", "hash_sha1": "4A8741646AD739DCCC44F6A0F3C0693F8BE6FC93", "hash_sha256": "8C394E08E246FD0810BE900C4FDD06E5D1F53FAFB26C95A61A10CCC96E2AFD85", "hash_sha384": "F53B2B488191A6418C8BFC106FD1CC7589D49C02EC7E63EEFDF40A3DF7729381BB187269140AB46099414ADCCF817C10", "hash_sha512": "A8A0A9BA2AB077BEFC119685BC75FC5F87E0F778BEF1468B224DB2F1E535A68BF3A004DA81B38DD3FE5BD404E39792D2033CB50759EFABEE41E400625838CC74", "hash_ssdeep": "24576:7qn41QevG63sUir2zERbgPg/6V9+TtqTvwShbzHZf94QIIvQdnxdPsksY:Gr9UebgPgi7+TtqTvwStzHZf94QIIvQX", "hash_imp": "670C0CBC1D6FF8E9DB76639058DD13D5", "hash_pesha1": "FF13ACF863ADEBE7A3B274FBC489AB96E854D2FA", "hash_pe256": "9622C665BD0B73185CB434D6DD35A54DF9A48C17718FFC92E94C22A6C4512157", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command line tool for creating PRI files", "meta_original_filename": "Makepri.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "mbidgenerator.exe-7AE4C973F2EA6EF0517A06BB5907E047": { "file_name": "mbidgenerator.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\mbidgenerator.exe", "hash_md5": "7AE4C973F2EA6EF0517A06BB5907E047", "hash_sha1": "2DB7DB9065ECBF7B49BAEFF8579BD99C7A10913F", "hash_sha256": "A173370BEC1D46272313E1815F7858AD7EC4A71200C29E1AEB8001148DC97F67", "hash_sha384": "3B7D087201EF4FE84C1C036B62449F13B9900DBAAF7BAB660C293F40A921869FD8CE34C9E3EFFF030794F1293F486958", "hash_sha512": "D59407640189031AE51FF59770CEC6F83EDB1FC71DB6BA3EAFE77F52EB8E0A65845C50A2CB4BC3C6DA1B4C5B47FA99986A84FF3D77078B52B1A1B9066FFB1FE1", "hash_ssdeep": "384:l0M+FW1VT/3qF/sk+Unppy/ye7PKyXlUEliyCM8r2aVAskW1WWhWxuOMlAA:vvyTrpp4FKwUElGM0spi", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "0B5B3C63E43E64D5870F699C96EA96ABE88B1A73", "hash_pe256": "907ECDBE84FCFD73504274F088ADC71F19673FAA666006C2D2E29D0D0AE8E47D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "MBIDGenerator.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Unknown command option: --help\r\n\r\nUsage: MBIDGenerator [/test] input_file [output_file]\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\mbidgenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mc.exe-C0822352CCD949789C57255C3DF323B4": { "file_name": "mc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\mc.exe", "hash_md5": "C0822352CCD949789C57255C3DF323B4", "hash_sha1": "E3E983EF3273E5B1E633BAAF1E2DABC9D4B90CC9", "hash_sha256": "1A0793BFB8F0F8E14592591CE61369432AEDE5731564550246B33FB9821B4025", "hash_sha384": "A88DB46E8AC158407BE8CD5B29873C56646120E012499FF912FF198FC8539AA30EF0E692E9E169CBF4A213D4CD2E7749", "hash_sha512": "3884424B9A80C382192F6FC40D938D4AE36541CFDA3E0AAAC2B22DE144298E98E03CFD3760A5EBBD1C22AB69D7720E04AFC54E3D39709332F89D16D868133191", "hash_ssdeep": "6144:yBS3aH99xN1pdIa3Gisek01OkKSjXYBSRp1QcGdQmdzWLk/wPqaL2JjsAbjsi3yQ:yQqd9Fph3U521O+mEk/zjsAljvFUY1", "hash_imp": "3D8DA6D9101AE2AEA81154824B6E3760", "hash_pesha1": "7EA95587B2F9121D20AC3BB33CC6C03879EBD3E6", "hash_pe256": "ECEA5A87A6B9A7FE510DDEB1C02973D084E9ECD042DD03D5B5774328A8D8D0FE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Message Compiler", "meta_original_filename": "mc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "mftrace.exe-2C9976CBDC204DF40F06DD7354E08834": { "file_name": "mftrace.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\mftrace.exe", "hash_md5": "2C9976CBDC204DF40F06DD7354E08834", "hash_sha1": "2B3485F16FE3CF00E0A428D28DA3A5511114AF02", "hash_sha256": "89BF81932290CB2DD2B0B4E3E027902B9A17349AE4CB36A086BF5CA02945D233", "hash_sha384": "CF860BA584A7BFF794F84DE765D6458B5A7C04C3816C931ACCF504625C6368DD918CEC5DFE8A31367F1ED6243528C9DE", "hash_sha512": "08361333FCBE4DE77BD20B21748D3CE668BDF9E6B80EF8B062F3E551F8A9B84693A25AF2F583A8B551D214634CED5FBA5466B3868AE3A13F1B3AF6DF4A7B7F47", "hash_ssdeep": "6144:aSxybZCCpiw7M03f6hiLQKJsSaCqsmMNQ7xBO/C0nJP6EnAFmP6T:UMem+JC0nJP6E2K6T", "hash_imp": "4CAC2F45048FBC8CDC66187BD04306FC", "hash_pesha1": "E8509948B4EFF08598680C70F030F96BA896AAD7", "hash_pe256": "7A4FCD595359C3DF8FC8AF0F7E306325C2BE6B6EF0C669E0DB2AE32217E353AE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Media Foundation Tracing Application", "meta_original_filename": "mftrace.exe", "meta_product_name": "Media Foundation Tracing Application", "meta_company_name": "Microsoft", "meta_file_version": "1.1.0.1", "meta_product_version": "1.1.0.1", "meta_language": "Language Neutral", "meta_legal_copyright": "(c) Microsoft. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "midl.exe-C91E698C847466BBE55A92A0FE3D4633": { "file_name": "midl.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\midl.exe", "hash_md5": "C91E698C847466BBE55A92A0FE3D4633", "hash_sha1": "4566F70ACD81ED1FF9E2550DE693590E661B265F", "hash_sha256": "AE95B66821DB89B69AF9266824796E3EF70F7BB60F06E8025FA4AE26812F1B12", "hash_sha384": "BFDA49573955D9FD4CF67421CFB8207938A3BBA58BDC2F7AC3F50C4DBCA207F18EDB34D5DA0842842C80B3AEB8BF596D", "hash_sha512": "D12DD4DBA793B4616F880ADC7C52C78ECAA6C6EE85602A70BC4F65331856D59DB6F15CBF229202E96E9F2C20A84C6F095C7AEBA837B543B32DCDB2DA79F06702", "hash_ssdeep": "3072:ZTG74zxngbOBLyyOHZQJGZpMkY7yQsoz0gj5bzV1P2a:ZrqbqxHNj5/PD", "hash_imp": "E263DCED608A2DD3722B0FF1C9E44A3C", "hash_pesha1": "20312D0D928CD9CB9814677A6154B7E93450CE8B", "hash_pe256": "89501B6470466948F66392F3CDD3B59EB4C3FCC0D4F9D14299ECB960E6313F99", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IDL Compiler Driver", "meta_original_filename": "midl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "midlc.exe-537E65D483302A337EC2441A6A758E53": { "file_name": "midlc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\midlc.exe", "hash_md5": "537E65D483302A337EC2441A6A758E53", "hash_sha1": "6B6CB7FE088ECDACAA0E31DF854F4D9BEDA31000", "hash_sha256": "5F5973119BCC0FAF3BBB8BCD039ACB979B831B490415EFCF8E98FB5141B50231", "hash_sha384": "10950F9BFCA1058CE8CE6E6D59D6997B96BA451FE31C795AC9731F3BB4ADB2CA044B6630728ED54D01F6AD1CC63915F3", "hash_sha512": "59C07DAB026B7CF50585EF755B7543B90D8DB77935E56828ED2FC31DDF81DD36D0FFC46BABCAFA7764B2D79AC8B6FE1754C256381FC37191D072845E73A81F0C", "hash_ssdeep": "12288:SHntcVcWOWDbEOgymOzVPtqtO3hTYuxBohpLH4H7wVh5j24hTj5aIGuB2ix:8NYDXmOzVthLxBohF4udKXix", "hash_imp": "D11719D53C528A91BDAA34A7A0FF427E", "hash_pesha1": "7039C75D8EA3CDEB78054F7A0CDB189720F9657E", "hash_pe256": "4B56548B4E41A53EF427DED21887013E40361946FAB480F3FF6AEEAD7252B902", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IDL Compiler", "meta_original_filename": "midlc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "mt.exe-2E7D7994DA38A2D65817532AC4F9B044": { "file_name": "mt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\mt.exe", "hash_md5": "2E7D7994DA38A2D65817532AC4F9B044", "hash_sha1": "BF2693F58ABAFAE82B5B399CF7488CD4DB52CE62", "hash_sha256": "E185B79A3CCCB46D1269DE7060247E9CAC52D2660A8A076033A216CBA9A0D820", "hash_sha384": "B18AC5F1D6C3E1EC103D561F142A3E4D80AD0B8BFA927B0BA31A92B86BF16654B602A5176DC419A71F5D772FE6840ECE", "hash_sha512": "61279DEE28A6C62379F82DE2B293D1FAB8E5E1B4B33CEE5457FC40CBC55030B694E769FE350D34567AC6BC409ACEBB4091E491558B36C212A1DC95DD4A89F0D8", "hash_ssdeep": "24576:bFY5sC47fcPJ5nyPkYDYDNBAIQuumGyoiIONw8ZoNiSRvDQdCmBV:buUcLnyPk7NBAIjaONw8ZoNiSRvDHc", "hash_imp": "7C083BE80FD04B2C4D4591FB01B3B511", "hash_pesha1": "A581711FF1E84DBB6C15BDCAE9AA24346E1305C2", "hash_pe256": "ADC02484E25FBD339640B64F113061BB4C6266E149D66EAB957B6F196EA55E32", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "mt2.exe", "meta_original_filename": "mt2.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "muirct.exe-2F2D176CAD74B44FEAF70083ECC3392E": { "file_name": "muirct.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\muirct.exe", "hash_md5": "2F2D176CAD74B44FEAF70083ECC3392E", "hash_sha1": "0248048A8AB302D9A6C31EE89B42DC78C637A7CB", "hash_sha256": "844EC22B5BE58442748C2B24D0FC2FA451633C418063AD938BB72C9D8D7E300D", "hash_sha384": "D676510A37DCA7A5905FC022D4BBDFDF677E2C93EA5ED8FA1D59203F1FB6B43F610F302E00E981F44D8AE5F416536CE9", "hash_sha512": "F7208F1E4950616C238B31729ED0F3291F264417416B11C60BA292E51AEC1ED829EEBDBE3C49CA5FCC1A53BA4D13B858ECD877E11637886C1BE334C2F6307B27", "hash_ssdeep": "3072:1APPJd423+bKVfVN4HoPultFrhYOc5z/YOPY0AsYY8Mennkzij6Xr2Y5:1A3JdHLJ4HoPuaF", "hash_imp": "870209685E9CDEABE0512DABA3744DF2", "hash_pesha1": "2ECB9E8748CF564856C37ED663FACE5E41E7903E", "hash_pe256": "839EC65D01F3595FFED74E736EE0843DC0B56AE6DAB3E18B267BC7ACCCE4291A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Muirct.exe MUI build tool", "meta_original_filename": "muirct.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/844ec22b5be58442748c2b24d0fc2fa451633c418063ad938bb72c9d8d7e300d/detection" }, "oleview.exe-BA92550275477C68D1A9E1B4CD3D7E8C": { "file_name": "oleview.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\oleview.exe", "hash_md5": "BA92550275477C68D1A9E1B4CD3D7E8C", "hash_sha1": "7B7BAB9220968991E76CDEE3FD7FE83183839A2D", "hash_sha256": "1BDD5C86AD166EA5A61DCB79E57622AA11AD33B95F3CE50D0BE296D94296CB76", "hash_sha384": "BE1CE4D55CA849F3987CFB9F71489B512C945C5584F6F1426053B5B12C9D652418DA5B06A2BBED01FDF92AFB694D1EA6", "hash_sha512": "581728C5E54DCDA6C3DC23C6C43F5B47541547C7D9007DD154860E15505F19B098E7D323F8D93AE045649F63DF32CFE1D3743D3EF3C8A6C823E99F555077537D", "hash_ssdeep": "6144:1mMxWycohkdPZVpfIl3CTonpVGOcWuAsZBm9j/dPwr:QMxW3PZVb0bSWhABwjFP2", "hash_imp": "F273BD9841C5DF5D6DC8CA7FBB14165E", "hash_pesha1": "0138D9E5F46F0C3EA1500976F4099FEDC84369ED", "hash_pe256": "A5322915E240D59472B0994E65D859A042B4C1683A95D23DAEED4E753C3B2C2C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "OLE/COM Object Viewer", "meta_original_filename": "OLEVIEW.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/1bdd5c86ad166ea5a61dcb79e57622aa11ad33b95f3ce50d0be296d94296cb76/detection" }, "pktextract.exe-2E43B9A19C65CD8E7BAE265628DD80FE": { "file_name": "pktextract.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\pktextract.exe", "hash_md5": "2E43B9A19C65CD8E7BAE265628DD80FE", "hash_sha1": "8DBB72E9D9B9E2C61528484E8BD957377FDE3AA5", "hash_sha256": "20696DF2A0FD94BE372D4A2952AAE02D6BCC79C4BE5F7C5243FD84F39F3A40C7", "hash_sha384": "3D5B0F4F1CDE2D3E37C68D47BB67309202D7EEFED72B0ECE2C132ED040B2A1F0FCC68F106EB6F2F537ABF02A6BFD69A8", "hash_sha512": "585032CA32C4B65C183F2876394647515F169304EFC48E5D53C79F7BD80A8FEADB1B81769C15C86A26104BBDF63AD387B4899FD281A3FA839BEF7A8BE9B5BED2", "hash_ssdeep": "384:yw6wxITBhivAz5wZZe6eeWvf/WJ5I+olz85:OwxITBheAz5aeH8I/u", "hash_imp": "39C98256004F7803BA6839EB105A9A54", "hash_pesha1": "4F890E67D13EBE8DC3D83B9667E852A314244D80", "hash_pe256": "D94ACE0F48BC9749C150F6F40E60EEA1F13AE74E85C12BB2657673C7EBAE1A2F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Side-By-Side Public Key Token Extractor", "meta_original_filename": "pktextract.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/20696df2a0fd94be372d4a2952aae02d6bcc79c4be5f7c5243fd84f39f3a40c7/detection" }, "pvk2pfx.exe-C0002840F47F992AFA351FD697491929": { "file_name": "pvk2pfx.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\pvk2pfx.exe", "hash_md5": "C0002840F47F992AFA351FD697491929", "hash_sha1": "2CF275C5C53E10056C1AD1D9F58D8EFAC63E6E01", "hash_sha256": "5E3BD87491F0D29F04BE39F04C35FE67667C6BD99D2AC05FFD5A70BF69878BF2", "hash_sha384": "0584E36469CCE71E11280A330897DF79365D8274902D3C0539E6CF3BC68BED3065C2515D01BD741B85A357DD097D99C6", "hash_sha512": "F238E6EF856CE7BA94F15AA45BA6F6B5E74B47A3BEF50F32FC587351DEA970F03C131D92F840527A6D1181F78F1EB4C40C1FC2C12C6E45F946CF36E97D474F93", "hash_ssdeep": "384:32+JM0v0AwBg+mC2LWDoR7oZdaWLkWkKOXQUGlgvCf:60v0A5+FXAGd3qKOPg", "hash_imp": "C8B3AB6B9F1265CA50AE6F8E7EDFA0C5", "hash_pesha1": "6B1DA5B24A3627763C037607413341F8D33D7D7F", "hash_pe256": "DF6DBB2BCF97E2C39C3C6D8EF92D4D5374B814AF2937ECB68702090E9ED0766A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PVK/SPC to PFX file converter", "meta_original_filename": "pvk2pfx.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/5e3bd87491f0d29f04be39f04c35fe67667c6bd99d2ac05ffd5a70bf69878bf2/detection" }, "rc.exe-BB813951B9CEE9021A8654583BD64B42": { "file_name": "rc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\rc.exe", "hash_md5": "BB813951B9CEE9021A8654583BD64B42", "hash_sha1": "CC3FBC5FEA48C9AA2450E4F392B2B639CEEBAC87", "hash_sha256": "A7861CDC34B610E8DBE141370A234DC76165D46CD706D140F89A4956D3AEC9AE", "hash_sha384": "E76B7B863255A43F65B7F4B489F54F33D0625E13EFD494055EE42FF4BB27C12766B86394C89DE569937AC679F5FF88DE", "hash_sha512": "2C6AE1D5BB4049097372FA01678D1CFB2EC581AB611D049E7F1D6105C29B33C8529638F42887EE3B6231A29FC66A758646BC1934063EC58FC23EDD578E1AC6CE", "hash_ssdeep": "768:M0oBDC90adoUVD0ZCrC5vMOMC+7VoPv6yss5eDZ5XFmHSU6rkxkipWVXphok2:t90ajYXlDv6ysj6SlM2ok2", "hash_imp": "887702E888C5EE55D78938EF62E42B0E", "hash_pesha1": "7B225F95ADEF71002ADA1E671510DE97410545D6", "hash_pe256": "FF4D9955BBE3A166DD4DB78F60389A6405488B7E5637C7C922C5189FE1F91B51", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Resource Compiler", "meta_original_filename": "rc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "signtool.exe-E389DCFDCAC694A0025BC55A710598EE": { "file_name": "signtool.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\signtool.exe", "hash_md5": "E389DCFDCAC694A0025BC55A710598EE", "hash_sha1": "66D177F9F625D24FA126DCC92C2310BADA7B6FF2", "hash_sha256": "28664E3AA3B584F93B5DC2A16CCC3B11A3415C5EF89DB125470C1E1CEE08DBA9", "hash_sha384": "A66DFB88249E448671B58F5DED2107B9D76ECEBE343113EF6204EE35EF436A52A3640BA9448D897087E7A2982B861D96", "hash_sha512": "027696780536FCD1D1490D13B2146A7C3F85B3E58CB7DE3A2EB0CECE32B05AE50C5B0B0CB83B15684E66F0222B4B743C903F26DEC637A97A5A99714C278BE5A6", "hash_ssdeep": "6144:fLNq4nPcOKtxI6Pbp8LVMU9MXP4L5t3hL/eUe0K:zNjPWIoeLmUAQNt0", "hash_imp": "AEEDC9A4EF9345625D248B0E4C81540E", "hash_pesha1": "95B1D62552705557B4C0028C267DDD3A0E0E9743", "hash_pe256": "8E61CD6286473F9989B07F1032389F73943B78DA78AA1073D924272BB1DC856D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Authenticode(R) - signing and verifying tool", "meta_original_filename": "SIGNTOOL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/28664e3aa3b584f93b5dc2a16ccc3b11a3415c5ef89db125470c1e1cee08dba9/detection" }, "TB3x.exe-1AD59D460167B2726A8439C95DC67205": { "file_name": "TB3x.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\TB3x.exe", "hash_md5": "1AD59D460167B2726A8439C95DC67205", "hash_sha1": "007816BE76DD63781CEA97955141417820A0806C", "hash_sha256": "8023C14ABED3C8A6CE33FEB810A18447456D12FB307B24065AA9D5BC8A89D549", "hash_sha384": "A63DDDC397C3191C7141EE098B9AF79E320022F9C151EC1DB029DFF33E86F75FAD3B111A0356ECAF8BDE0E66F7ECE16E", "hash_sha512": "9632430585866FFD27B6AC4270061EBA71CBA720CA109BCEAB075BC2F8E65B10C5723387556E89A8978F1B293734C2C213CDB0401DA1598D40711AF524348433", "hash_ssdeep": "3072:8ZSIQcOsNdoDf/5UTa2HkA5PV65dY8jE9aoQzJa4CcISQv5HwGHvTSah:8FU7mTag965KWwio7Hx", "hash_imp": "FD3B40AFCA927DC5487FEA0E499644D9", "hash_pesha1": "8016903B3C98C193D081606FE719E2D3CA4F323F", "hash_pe256": "34724D34B6373BD348A8F23FDEEC25553F65A60B33C7A84AA3D1301C5A4D532E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TAPIBrowser MFC Application", "meta_original_filename": "TAPIBrowser.EXE", "meta_product_name": "TAPIBrowser Application", "meta_file_version": "1, 0, 0, 1", "meta_product_version": "1, 0, 0, 1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 2000", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/8023c14abed3c8a6ce33feb810a18447456d12fb307b24065aa9d5bc8a89d549/detection" }, "topoedit.exe-59333974714F3E6EAE7CC7B546C64671": { "file_name": "topoedit.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\topoedit.exe", "hash_md5": "59333974714F3E6EAE7CC7B546C64671", "hash_sha1": "3A0B0D8C9C097128456A8CE97852F32F0F751C9F", "hash_sha256": "E5808F33994EC65502DC82048F312F39E92E1681FC8054E081F20332993898FF", "hash_sha384": "35D5197145B12F5DE11357732EB1E02A421713636E46234BEE8946ADBD7F38225FE15D3AC8A55A25C1703F5DC8FA968C", "hash_sha512": "6207764E3190BD948BF70F7DE18154E0806ECC7F3B9547C451A9DDAD4DB98159A95D16046935D38AABCB5E1DA56AE6592906CA4D8F631FB625C710C6675A1B84", "hash_ssdeep": "3072:oDDvnh79H0v1hFC642klDOSrRojNeiCVaoHDJtbNNoXc3BJiY:op79H0v1hFC642iDOYRojjIDJtbkAh", "hash_imp": "C7C9953C42FFF46946919CFD0378D5F0", "hash_pesha1": "34119013E547CA535FF575479EAA489D40E24575", "hash_pe256": "2D30E8E63FA534EF853389EBF73DC6F0884CF296FE4F0D0BDB70AA50976C4FB1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Topology Editor", "meta_original_filename": "topoedit.exe", "meta_product_name": "Media Foundation Topology Editor", "meta_company_name": "Microsoft", "meta_file_version": "1.0.0.1", "meta_product_version": "1.0.0.1", "meta_language": "English (United States)", "meta_legal_copyright": "(c) Microsoft. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e5808f33994ec65502dc82048f312f39e92e1681fc8054e081f20332993898ff/detection" }, "tracefmt.exe-1A132D3C750C4F6E6A49DD0B15037A01": { "file_name": "tracefmt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\tracefmt.exe", "hash_md5": "1A132D3C750C4F6E6A49DD0B15037A01", "hash_sha1": "80C3184AE374DC697A074C26E31C288C1DA069C0", "hash_sha256": "0D94799CCBA906B3732A15358272563FFBE8D7FD63BD9A7DF5D86C66AEAB1AD4", "hash_sha384": "7942A48CB0133B7F5C9EDE46DD3406AFF6EC473A675EF762FB6F8D88483E234B59FBEFCA7CC2BC459BA9C0180C841DAE", "hash_sha512": "0587B7D6898C7E44DE971A80ADB58D5AC48DAED54C70A070D11A67478093AF9344DD265A2905709D94FE7A9254D9ADD51CCFA8965A412EF562B18958415ED109", "hash_ssdeep": "6144:ZuVGXM37BSEObG00/HkLlxjpOMUoikXVcA9gIQ/yDJF5vVzyfKJb0XCKLAR3tx:k7rB/B00/HkLlxjpEz/25tyfGbJUA1", "hash_imp": "4B2B1881CACBFA7A24DD9CBC2777EDB6", "hash_pesha1": "7F87F243BF67788F9D159ECB464B9D66E195DAD4", "hash_pe256": "596833EBE66C2B3B2329923CA772CEDFC5D084B22A905C377DF990A494983D30", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Format Message traces to text", "meta_original_filename": "TraceFmt.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/0d94799ccba906b3732a15358272563ffbe8d7fd63bd9a7df5d86c66aeab1ad4/detection" }, "tracelog.exe-BE0CA960F8A13A473505821D2493A3DC": { "file_name": "tracelog.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\tracelog.exe", "hash_md5": "BE0CA960F8A13A473505821D2493A3DC", "hash_sha1": "A126F34CBA4A0C5E7A32E676C5706ECF0789C536", "hash_sha256": "4263CFF642430ED63A1F98270A5277F7134AD114BCC582747812EA37D9227FE9", "hash_sha384": "E432DFB48307BF1F2BC8283D0BD52161C690C6CAE6B193700D17C55039888945E9304E3B1F1BA2E76AC29E239668D0CD", "hash_sha512": "CB881FE6B0255B94095919132DA9FC450D0FC7C21150F549429C273FAA2CE80EE6D4F6C522E3F1FDCB0D363881D4818A3BCF38EFF83E502E359C61456B161652", "hash_ssdeep": "1536:qNeOY5c3GtFE7AsXbHrAvQG/FNla71P5q5ooHGMOXfefPMONGRZg6VgxXIfX88:qUNli1R2ooFOXfefPMkGR+6VgxXOn", "hash_imp": "EAF6825E97236AB20323BF3D08888CD8", "hash_pesha1": "0283BC411F6C24F9D106E05643E449C11005C61A", "hash_pe256": "AACA4D20A6991C3E402EFF24F065765DE070403566B98E2A12F55C58680CDEC1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Trace control utility", "meta_original_filename": "tracelog.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "tracepdb.exe-89C9AC9D3AA57314B9A4347322EDD348": { "file_name": "tracepdb.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\tracepdb.exe", "hash_md5": "89C9AC9D3AA57314B9A4347322EDD348", "hash_sha1": "8D1C12B0714665E0AD6E923C437B966F141F56CE", "hash_sha256": "65C50174F9FDEAA69D716C82ADD9746F548C4717DC438BB28DA46F7553E94133", "hash_sha384": "804253B1CAA9D465926C22D98F10FED5DE9D567416BEB88AC58F55D36E5DA91E45ECC048E8E995EBA7EA87B9B3031CD7", "hash_sha512": "E0CCDED26571EB386C5B8F44D883DFFDC174E0F929B52E4A876BE1D4CA6B1E6AFB3A942C9B3A0BC06531EB3983DEBF7818F75B29AE338B1F4ACC7089757A516D", "hash_ssdeep": "768:3VagVLfpvMGcG5kyPYy1n+hpoG5Cl3HcM/ZyuZc1XrWxGXxoTw2d:AeNtc4mf5Cl3HcM/ZyuZCrDxoTwk", "hash_imp": "DB88FC89C005ECF530F95464EA259FD9", "hash_pesha1": "A821EDD17F90E44EEC046C1262131054CFE16E19", "hash_pe256": "B02101AA09F2FD9BD90428FB0ADB2DD9ECA70528BE3C37BD199E538AA796D272", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Get Trace Format info from PDB", "meta_original_filename": "TracePDB.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/65c50174f9fdeaa69d716c82add9746f548c4717dc438bb28da46f7553e94133/detection" }, "traceview.exe-B896BE2FC8C793A61CC10C4EE432C40F": { "file_name": "traceview.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\traceview.exe", "hash_md5": "B896BE2FC8C793A61CC10C4EE432C40F", "hash_sha1": "5BFB1EE197BBEA02A0BD726B35658B0E7B0099B8", "hash_sha256": "CD865FECAE9F4955C8B52EDC6075B843D5FBEC320EC0BF83F3418A9A393947E6", "hash_sha384": "BE49076BD329716269208BE634C8AC880E1A0CFCCEA7037752B151846E1AADFE2F4E7DD04EF3501FF87423B5B80E5D36", "hash_sha512": "9726696203E3904C3BE80926C5BC0FE6CE183E876887F7805C7E67ED3E65E000E57BB89885AB6628C5217D441786036CA85D930872C8458062F94805DCB020C1", "hash_ssdeep": "12288:wXw2p1TGjvlPDCNY6lNYQQqfG8qoOwdpMqADAnybD4TVsIwXzqbJYHJA:d27yjZKG8ehDAnybD4ThwjSYHK", "hash_imp": "FE20FC6016F1B6CF11C496BCA06A6B57", "hash_pesha1": "BA848A2F7B65363B332E94E706DE9D1ABCB0DEC0", "hash_pe256": "5447EA99C42467E11B6144A4554DC5CA54D7025FF8218077CF559C4153516116", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TraceView Application", "meta_original_filename": "TraceView.exe", "meta_comments": "V2.1.1", "meta_company_name": "Microsoft Corporation", "meta_file_version": "V2.1.1", "meta_product_version": "2, 1, 1, 0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 2002-2005, Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/cd865fecae9f4955c8b52edc6075b843d5fbec320ec0bf83f3418a9a393947e6/detection" }, "tracewpp.exe-8216C3E1CF4954338DB9EDB140A20A1C": { "file_name": "tracewpp.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\tracewpp.exe", "hash_md5": "8216C3E1CF4954338DB9EDB140A20A1C", "hash_sha1": "55E6C29A44EA80983F05DF8F79A32F3E0302F711", "hash_sha256": "D4281A5ACDDE6C34BA2A4FE872B1A69EA16582BE749A27A41F989D99619A6019", "hash_sha384": "DB6B8CBCCE43367698E3C0DB9557CD24BF4FC048585BD4BD7C9158337F52CB004EA3DDF8F197D45874E380CBCA2A3CD7", "hash_sha512": "76EA605ABF1FEC910DFD95CFB975341F9ABF4B3744C4AE9B6EC58532431D4D2FFE24C337EB5AD0D1C663DA03DDC069205750B7EA655CD75F9B0D743B15675C76", "hash_ssdeep": "3072:0OqSY36VnknM0ZaHTntnMgxY4nJP/SGrlJg4xqhhnznCEune6pxcVbOKGyQTnHvQ:tnYWJjvrDgRQBQXjLBw3ort+UFXHnuw7", "hash_imp": "11F44EF402295976ABEAB7DE753FCD3C", "hash_pesha1": "8EFEE1E139746D413A3F1C040D679AFA6A9CC0F4", "hash_pe256": "75B0C1A0C28C201B7E61EFBB5F06A508EDFCC5C5D2D6B858C26C3E5B71489781", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Tracing C/C++ preprocessor", "meta_original_filename": "tracewpp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/d4281a5acdde6c34ba2a4fe872b1a69ea16582be749a27a41f989d99619a6019/detection" }, "uuidgen.exe-120EEAB7C2283E19ECF9B98FE1A31A12": { "file_name": "uuidgen.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\uuidgen.exe", "hash_md5": "120EEAB7C2283E19ECF9B98FE1A31A12", "hash_sha1": "D2F1043A48E291B0E85EB4FC15DA1064B7F1075E", "hash_sha256": "CD3D08834A834FB20D09E2CC8784406C62F9F88A3AB85C265D9C95FC8315969E", "hash_sha384": "3F63E79BB7DD7D769A44EFF5ED5DA02AA9C9F34AEF3BCFC71406BE2DF517D360EBB1BE8EEBFE6FE66557E69BE8BF4E66", "hash_sha512": "34CB315EB84C236B1F05415BD21463C4A492A274058086C446A92CEAA1B9048B1EFCCE3A778F4601631BADFD22DB97C2869C919D9E26DC53E8BEE087987200BB", "hash_ssdeep": "384:pWYJ72xQa9YWlza9nIpTo0uQZW4UWoOt2lxnortn:pWs70QaHlzMIpMt4rBn", "hash_imp": "16B4E95DECBE2C2EAC6F1D0E7F3E9E38", "hash_pesha1": "7F5E71094288DE2BC0E2022045FBE21345221397", "hash_pe256": "53FED54265703DC54417D1E6ED6247D53EF5A26DF72B9DC222414E1002F1E03C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UUID Generator Executable", "meta_original_filename": "uuidgen.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "vsdiagview.exe-5922F42724F44A94E36C749125321674": { "file_name": "vsdiagview.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\vsdiagview.exe", "hash_md5": "5922F42724F44A94E36C749125321674", "hash_sha1": "509A46FC0785B3110BACC4DE6569944B7DF6A2E8", "hash_sha256": "B12982AE14BD6B88BDB1C503C87FF46B45ABDE3CCA47D8F57C33DD2F5D5C2D9E", "hash_sha384": "0EB0FE6A8A67134C2768B12270269B23EC09DBE0BFBAB2B8FB152F10820DBAD9179A583C77EC99AA15A037C22289F792", "hash_sha512": "67C66A6A57E6ABC37A330F9B0615FF29EA1B37E9EF46010B8AD96E5A52B6AD652F72CBBB4F5FA34142F6B5C9D96BD74E73E7AEB3571091C230F131997AF53547", "hash_ssdeep": "768:RqXzBgHsUieX9a2GnT2GefO2GUlFfDlEXc6Lh:oBgHB8ifZ6Lh", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "9B5EC42E05DA8C046844841B3857030E0D1BDB98", "hash_pe256": "20AAD07EEDDD8851C566C67DEF66190EEF782E1F44FAFBD70B06A33B8AAE75BC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "vsdiagview.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/b12982ae14bd6b88bdb1c503c87ff46b45abde3cca47d8f57c33dd2f5d5c2d9e/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_7036": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\vsdiagview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ], "runtime_window_title": "VSS Diag Viewer" }, "vshadow.exe-5E7E66E3290CB3412BECB08147C69C78": { "file_name": "vshadow.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\vshadow.exe", "hash_md5": "5E7E66E3290CB3412BECB08147C69C78", "hash_sha1": "57C5F949E67E99D9C726349A069DE4E10A14F702", "hash_sha256": "6546E380EA44C1E2966A2C27C2AFCD6CB549ABCB56CCFA9B0DB15DDF075A7F13", "hash_sha384": "0E0165B3C8657E9419503CF5872F4F374AA507F71C5649D279D649A678DCFDC7792FFFA07AF59182E9A0C0443EC38760", "hash_sha512": "2058F593D3F964A5E5FB87C3DC099F5EAF97B9B7E8F1718AB679BE8F5C868F1A08D2E2CCD493C7C47EBFB42837C6A02C0B619B4041711ACE93B14A865312265F", "hash_ssdeep": "6144:6bIbOFjma4n92hxunrWUMwWoeIp/cZilZON7q:mpa92hxunrWUplp/cZiSNe", "hash_imp": "1CA4EE7CE4FFAF1F599F39FDB4899D95", "hash_pesha1": "82474564547016FED1CB605BCE8547D53AB39D43", "hash_pe256": "4F7BDFE41854E2B32252C724FC963DC1138DBEB53F57DD9097155B0EC299F362", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "VShadow, Volume Shadow Copy Service (VSS) Sample Requestor", "meta_original_filename": "vshadow.exe", "meta_product_name": "VShadow", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/6546e380ea44c1e2966a2c27c2afcd6cb549abcb56ccfa9b0db15ddf075a7f13/detection" }, "vssagent.exe-EF94F97A372BE37FC2CA68A6785ACCC9": { "file_name": "vssagent.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\vssagent.exe", "hash_md5": "EF94F97A372BE37FC2CA68A6785ACCC9", "hash_sha1": "93D9F0923B15964C1A0CD90126409B41926B7B94", "hash_sha256": "0EEDEE8BAABB58C11FB22119D3261AD1E549CDCDE3276A1AB638270AF245F5B3", "hash_sha384": "4616DC06FF0AFC824F829CB441438B1FB93CE58CB6B6B759E7361D2A3BF410480C9E186CAC9E259214F866040D7DBB9B", "hash_sha512": "16F7DEB2934DC3305EF1892B45024891AF190C0BFBC15E6C4FD41F958E73F738DE37DE23DADE8163415436B6ABBED4A3CE937FA3EF464D14D6D5B3B4D1FB6173", "hash_ssdeep": "6144:lrysd+shDw9zYURMTngAjlJONA4gAS0682N/ZyikjYjT97xCoEjn/5jGS55MvnXZ:+UjlJZ/W2N/ZyiIYjx4CS558XB5R", "hash_imp": "307B325BD6A8FB1C7ACE76FC79907826", "hash_pesha1": "3CD9A42E1DA810AE96592166103FFDAF6F40DC0F", "hash_pe256": "C71CD4BA77684229443C6CB2463A692E250D45BB619BE841BAE7B509FF927A07", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "VssAgent, Volume Shadow Copy Service (VSS) support tool", "meta_original_filename": "vssagent.exe", "meta_product_name": "VssAgent", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/0eedee8baabb58c11fb22119d3261ad1e549cdcde3276a1ab638270af245f5b3/detection" }, "vsstrace.exe-FC11597906504CF378148542923793CC": { "file_name": "vsstrace.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\vsstrace.exe", "hash_md5": "FC11597906504CF378148542923793CC", "hash_sha1": "64FF51DC8D8241E9A773F4AB2AE90398548526FD", "hash_sha256": "671D41DF57D62C2EFD56D91DEEA027CE896C157CA7F17DECA7F0E4A3FA0C138D", "hash_sha384": "A09FC462EA4D7D5D666F9F9E6B13E25B4A27B55A57694FE06A9DF603796FCF1E1D10A7C2A851B249DCBD3107B5514928", "hash_sha512": "9267E071614E7036CE2756C5D085C1ED3E97E17E14DB4E65C28DDD02AF97BEA9451890D3931341BA454F75F74EECF49755AE1AA43473225E5317212F911CC6AD", "hash_ssdeep": "768:OsJCTF4rHfhFGXyUEEbgE5byTmLOpCzsBIEhFAjf+eknxz2tHQ:bJCh4rHfiX7DbgvmLOpCzsBDFASXt2FQ", "hash_imp": "E0A612B7BD4B3C1E34C53FB84E5610B9", "hash_pesha1": "A16FB42379C35BD99748BEB30FF5CFDA71F8AC7E", "hash_pe256": "0B036AB577B8E3CEBC6BF895F540CE04B96FA12378F7599B969EC2ADC9D573AB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "vsstrace, Volume Shadow Copy Service (VSS) trace formatting tool", "meta_original_filename": "vsstrace.exe", "meta_product_name": "vsstrace", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/671d41df57d62c2efd56d91deea027ce896c157ca7f17deca7f0e4a3fa0c138d/detection" }, "vstorcontrol.exe-7EC6B4682FF525E43FFB58650980FE82": { "file_name": "vstorcontrol.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\vstorcontrol.exe", "hash_md5": "7EC6B4682FF525E43FFB58650980FE82", "hash_sha1": "1B33B66DDBFBFF4E75CB5B36BE19BB11C0B4D39C", "hash_sha256": "F914CD4995C76CF80D094EE2F5BC6A7E2C182B3B6A37AB622A7527219B12C267", "hash_sha384": "4FECC0874B6CA9A47B5A1DF05A4BFA05672DA41A8EE7B5A6BE1149BC0F9CC8FC16DD4A31297026EAF4583DF47A906EA3", "hash_sha512": "C91DA99176338F9B683B79F379BB416F8EE3FB0781A0E23E50881B33C3435D81D1D0E0C2F23401285637CC95C5FD8CD53BE43DD53750D92F6C387B2C5CB25329", "hash_ssdeep": "3072:aqKKRuVwr8oz7SRUu/4AV7Bb1qA6nM09RTd2Wsf2aJE+AaL4cLGqB:aqVawYoCVXqA6nJd2VfJAab1", "hash_imp": "F0095BD2D7171A41611394E5E9C8A840", "hash_pesha1": "5D0418077F08FCFBA182E3F37850DDC389E87BFD", "hash_pe256": "FBB80BF4C59CEE172BC0D9736EC85C1DA50DA0C14BBE029143E4B853E43C315E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Virtual Storage Command Line Control Tool", "meta_original_filename": "vstorcontrol.exe", "meta_product_name": "Virtual Storage Command Line Control Tool", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/f914cd4995c76cf80d094ee2f5bc6a7e2c182b3b6a37ab622a7527219b12c267/detection" }, "vswriter.exe-751B925A39C1BB29EB7A1107ECD5708F": { "file_name": "vswriter.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\vswriter.exe", "hash_md5": "751B925A39C1BB29EB7A1107ECD5708F", "hash_sha1": "404FC40734DAC4538D1DF59ACD0AC1C3C099A1B6", "hash_sha256": "182D25C84A5DEC922C5C860260F2FF8C792837292F840E065FD15BBC9205821E", "hash_sha384": "52098ED13B0A09518D6CF7C6E856819592E126CB25E2D79B4D38BA5EA70C7F32DEF931BFEBACFF295BCCCD5B303C3E87", "hash_sha512": "03FC662BABC724E8F6CA7C303F8D73BD2C2CEDCF8BBCE02C80F79C81F0B9351B23610F6F9705978D9227DB8D6210CF1403307B44D7586F5BACF608A92DAAA07E", "hash_ssdeep": "6144:T5UiLZrm3FVxhIaxCtK+9M2a97A3zvFNm7jJmEs4dSrEMTiPwNFYX7MlfX1yEhPb:9UiLZrmPLR7+zvLm7jLwsXkQg", "hash_imp": "4A2A93E0E49D601590BA609FA49DBC1D", "hash_pesha1": "AA393917EC08FE7876400CB113BD6B8D774B59C2", "hash_pe256": "7DA88349E936AF6100700880C4D501062C7C72D3CD2221E99C95B8765EB73FDD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Volume Shadow Copy Service (VSS) Test Writer", "meta_original_filename": "vswriter.exe", "meta_product_name": "Vswriter", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/182d25c84a5dec922c5c860260f2ff8c792837292f840e065fd15bbc9205821e/detection" }, "wstracedump.exe-74ACEF076F93BD8D2A95962DBAFA6FCB": { "file_name": "wstracedump.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\wstracedump.exe", "hash_md5": "74ACEF076F93BD8D2A95962DBAFA6FCB", "hash_sha1": "2E7CDD9EE638D8BA093362DB2A54E4BC4E836017", "hash_sha256": "0F685AE292FA073D8A31D1C51AE29B20F09911D7970DCCBEEF30719C4EBFB8DA", "hash_sha384": "1241C83D200F96CE899B1CF8D28D6540F548B5F879D74C8D5EFB40C2D8D840CEB0781E133ADE4AD4D3AE73EB7CAF9A06", "hash_sha512": "26E40B09C147524EFE7C30CD011276EA94EFF14D241EEFA7CBC34EA35B34706E96826B17CA44741555C2FB80A409EED42CA4E9600B54096B820F6FF2FD3619B6", "hash_ssdeep": "768:jge/IpTg1exn/DiChSMyGAIoePByO3P8rXPj0wwjV2X/WJ0J1ebvNhOoG3:p0Tgg/O5MyGAWP4OsnYCpWvmp3", "hash_imp": "B1389E521499DF84FE67FE5714FC46CA", "hash_pesha1": "731AD5822D1970932EDC668A7E7F167ED4E24C92", "hash_pe256": "820A56BE024BE4DBADA35FA22FE2A812B42919259068B32F6A770758613A6B79", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Web Services API Trace Viewer Tool", "meta_original_filename": "WsTraceDump.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "wstraceutil.exe-995BA449A62B2D632E18ADFBF3431729": { "file_name": "wstraceutil.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\wstraceutil.exe", "hash_md5": "995BA449A62B2D632E18ADFBF3431729", "hash_sha1": "21F9836E448E44F40DA30FE35C280A00EC82AE08", "hash_sha256": "14332FD721C1915CBE915C1E2885A9B9E933FCD9205FAFB9B19FE11ED70AA5A6", "hash_sha384": "189657B7B94949C30B644C5049E153AB374A0B983AC721963BEA299C993523689CB58B1BF5004332FB2CAF69DBFA297F", "hash_sha512": "E21BDB6C0805EEA836561FDAB9C3E834FCD302D4B57E03B7D84CFAB98E65F06676C685FF493807625F9F652C6186229756D0FFC8FE5831D85720AE7C889132EE", "hash_ssdeep": "1536:gB3ocGCoz/SoKMSqk6wux/hmodj+6rvGa1rzwwZxqSnbhEU:7cGp1OqkHqmsNZxqSb6U", "hash_imp": "D31775B35C261D1BE1264F7B4C9DF8E5", "hash_pesha1": "9E8C5FCD543B04AE35FB3ADDCC2931E89544A7EF", "hash_pe256": "322AA06142B261E7FC8397EFF1424A0731B37419694DC4308848326B95498800", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Web Services API Trace Utility Tool", "meta_original_filename": "WsTraceUtil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "wsutil.exe-57E41D42D54A36B010A1AE2CF021B200": { "file_name": "wsutil.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\wsutil.exe", "hash_md5": "57E41D42D54A36B010A1AE2CF021B200", "hash_sha1": "47EACC7C662466396E01B91B11CAA226CB9CEC40", "hash_sha256": "80D68454B2997358EA5924404B7D41E9A7EAD0242311DB9069163FBCF242A8E8", "hash_sha384": "EC9474C9983DE064A4F08F3423C16AA133249F8A776969B53A10742857FB03A891875511857B02A86DEC566D69A2DD28", "hash_sha512": "30DE259819DE99ADD6C6A72D811398C0978BE3CCAF674E8A1BDC9A39F27777EC77BBC64322802CA8CE3A52BCBD9E4D93CB799C75CE999F2B0C9557D27AC72375", "hash_ssdeep": "3072:NCSc98vbXX6mwkYQM78cVf/czVgr0g8AStl+lJ2FRQgSboDzETZJlnoO8VQ9vCUe:3vukYQ5cVfU+ezDAqOzPvMnFfLPL", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "A61237BEF3B56BA856EC9C887827A51FA5831716", "hash_pe256": "7EEF628F207BE67A7158A8A8217EDA53A49130DA7200FF7E0C5E30B210DA4664", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Web Services Tool", "meta_original_filename": "Wsutil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Microsoft (R) Windows Web Services Tool, version 1.0098 \r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nWsutil Compiler Options\r\n\r\nSyntax: wsutil.exe [@resfile] [metadataDocument]* [option]*\r\n\r\n--- RESPONSE FILE ---\r\n@resfile Specify the response file that contains all \r\n the arguments.\r\n\r\n--- metadataDocument ---\r\nfileName Specify input fileName. Metadata document type is \r\n determined according to the file content. \r\n Standard command-line wildcards can be used.\r\n/wsdl:fileName[:url] Specify input file as WSDL file; optional url specify\r\n the location that the metadata was retrieved from.\r\n/xsd:fileName Specify input file as XSD Schema file\r\n/wsp:fileName[:url] Specify input file as policy file; optional url specify\r\n the location that the metadata was retrieved from.\r\n\r\n\r\n--- output options ---\r\n/out:directory Specify output directory for generated file\r\n/noclient Do not generate client stub\r\n/noservice Do not generate service stub\r\n/nopolicy Do not generate policy related metadata\r\n\r\n--- misc options ---\r\n/?, /help Display this message.\r\n/W:{0|1|2|3|4} Specify warning level 0-4 (default = 1)\r\n/fullName Prepend fileName to generated identifiers.\r\n/prefix:name Prepend specified name to generated identifiers.\r\n/nologo Do not generate compiler specific information on \r\n console output\r\n/nostamp Do not generate compiler specific information on \r\n generated file\r\n/nosummary Do not produce summary after processing. When combined\r\n with /nologo, the tool is silent on success.\r\n/string:WS_STRING|WCHAR* Specify the string type. By default WCHAR* \r\n string is used.\r\n/ignoreTrailingContent Specify the trailing content for generated \r\n structures to be ignored during deserialization.\r\n/ignoreUnhandledAttributes Specify the unhandled attributes for generated\r\n structures to be ignored during deserialization.\r\n\r\n\r\n", "error": "error WSUTIL0013 Failed to open specified input file 'help'. Error Message:\r\nCould not find file 'C:\\Users\\user\\help'.\r\nwarning WSUTIL0075 Error during compilation. No file was generated.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\wsutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "xpsanalyzer.exe-F6D26A6077FE507CE598F5FFAD9672B1": { "file_name": "xpsanalyzer.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\xpsanalyzer.exe", "hash_md5": "F6D26A6077FE507CE598F5FFAD9672B1", "hash_sha1": "F9A23EC69850CE9B046521F6AF9DCE3277B9989E", "hash_sha256": "BE2E1521FC43756B69B56E0D5C08A871D5810DD45E3F2F5B6B80BE259EAF1298", "hash_sha384": "54EA56A951E1A35BD974C76963E5447831EC3A66C0567187855ED7E3250AA89AD884500E0596F08A6AD3602526F213A4", "hash_sha512": "C8CB247525BE0A6015F8FAFC08294C36432F628696763F6AA2316883C3075ED2E3221391DC172D8FD28ABB5491B5FDADF654F5E86A7E2E9519F7687BBECDF751", "hash_ssdeep": "6144:1p4/b7SFHsgnj64gH+jiGe8pqOZvnwRdXzFTLkf8P+fJ:0KSc6feo8pqOZvngdal", "hash_imp": "5A155E5B1F858928FFB58FD79252EC96", "hash_pesha1": "FA7D9074DC84EB031AA5960005F50E99E5F745AA", "hash_pe256": "15BB9DA4E870FE143501E9A3C9F140B15661216BB2E4EA5C955EEF545873FE36", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "XPS Analysis Tool", "meta_original_filename": "XpsAnalyzer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "AccCheckConsole.exe-4B0134C4D55EE109CE2AF245A295DA69": { "file_name": "AccCheckConsole.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\AccChecker\\AccCheckConsole.exe", "hash_md5": "4B0134C4D55EE109CE2AF245A295DA69", "hash_sha1": "C0F29AEBBA4194BE223BAE74CB7A62E5A19694E1", "hash_sha256": "60FFBECB6301A6EA0CC380D558DBA4CA07E8360A3A838EA317061B6BE6DA6F4F", "hash_sha384": "832D2026F3888171175AA1404CB221B4CB1A0C233096128EA095DB81ADF05E8E6661911FF6776EEDFE49C8E6EB33B6BF", "hash_sha512": "E545646DC265D253FE3FE114526B4A91F603BF629643E64CCE1AC18141A9C591BB8A8B2477A0B53D2802D07D5319284B67BF3CD1BB327FAE6133092D8A8CBF8D", "hash_ssdeep": "384:j6XLwCj6aYZScLeG41oCvYf6kQFTFemhjITi3K+dwJMgMuiXW2VQwWng4JeRlF6:ypkC5hnjHK+dwJMqivVQpz", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "F2C1ED684583ADE3691B81A988DB357C3A837721", "hash_pe256": "52A1DEC3DA7965CDD0A10779B2ED60D79096CDB0AB7312EEF899F97432676B86", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "AccCheckConsole.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "[Information] Command line argument\r\n\tText: -help\r\n\r\nThe syntax of this command is:\n\n\tAccCheckConsole [options] (-hwnd | -process ) []\n\n\tOptions:\n\t\t-hwnd Validates the given hwnd. Can be hex or dec.\n\t\t-window Validates the window with the title given.\n\t\t-process <name> Validates the main window of the process with that name.\n\t\t-list Lists all the verification routines available.\n\t\t-enable <name> Runs the given routine. Can be specified more than once\n\t\t-disable <name> Runs all but the given routine. Can be specified more than once\n\t\t-log (info|warn|err) The lowest event rating that will be logged.\n\t\t-logfile <file> Outputs the log to file. Can be used multiple times.\n\t\t-suppress <file> Uses the XML file <file> to suppress errors.\n\t\t-quiet No logging to stdout.\n\t\t-help Quick Help.\n\n\tError codes returned from AccCheckConsole when using \"echo %errorlevel%\"\n\t\t0 - No errors and no warnings.\n\t\t1 - Usages statement was requested.\n\t\t2 - Errors and no warnings.\n\t\t3 - Errors and warnings.\n\t\t4 - No errors but Warnings.\n\t\t5 - Invalid command line.\n\nExamples:\n\n1) Run all verifications on a window with a specified name.\n\tAccCheckConsole -window \"Untitled - Notepad\"\n\n2) Run a subset of the verifications against an HWND, specifying a suppression file.\n\tAccCheckConsole -hwnd 0x00382f00 -enable CheckTabbing -enable CheckName -suppress suppress.xml\n\n3) Run all verifications from a new verification DLL.\n\tAccCheckConsole -window \"Untitled - Notepad\" VerificationRoutine1.dll\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\AccChecker\\AccCheckConsole.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "acccheckui.exe-118085840E9A257811635E7C0DBEF478": { "file_name": "acccheckui.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\AccChecker\\acccheckui.exe", "hash_md5": "118085840E9A257811635E7C0DBEF478", "hash_sha1": "913EAD514E314E17C539BDFF3786BA6B80E2B073", "hash_sha256": "92EEB71E9C9B789E6D55D8CFB08F22294AC8890F382AF1C0DE34F3EAA8BC21E0", "hash_sha384": "4C766AACA85F0CE5F9155FFD0DA866EB772196A555ED68D95A1E27EAF8EB60277406111228B97BEB9211355FA66BBA86", "hash_sha512": "DF2D895E0C96845C81F20B047172D7B240959C9941792A7153C6F4DE9BE6EEF557D40C8DB624813737CDA5F8CCF1029CFD07405FA51DEB9E85027054E9E388E8", "hash_ssdeep": "3072:YoG0eEey3LrG/HhLyIEWJYetCSZaPh6uEPl4iGo+XZDhPzpiXK/Q9:Yo5933UBbEWJYetgq7", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "D231E1C55805712B88E53234C9C51996AAC73691", "hash_pe256": "A934E0A3C5E767F9552F985386C8CD526FAA29A9026A07DB2C26196D2D267553", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UI Accessibility Checker", "meta_original_filename": "AccCheckUI.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\AccChecker\\Microsoft.Diagnostics.Tracing.EventSource.dll": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_9360": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\AccChecker\\acccheck.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\AccChecker\\UIAVerifications.dll": "File", "(RW-) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\AccChecker": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\AccChecker\\VerificationRoutines.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\AccChecker\\acccheckui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "VisualUIAVerifyNative.exe-39FE85BBC302BB412761FD6DDF323FA0": { "file_name": "VisualUIAVerifyNative.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\UIAVerify\\VisualUIAVerifyNative.exe", "hash_md5": "39FE85BBC302BB412761FD6DDF323FA0", "hash_sha1": "88B4C08BB50C4C7ED867EAD8D6BB0B0CB204C9FB", "hash_sha256": "A3F0A0F01D200A855D9E3C1685FED0FD938A1FA43F005B3F33C071A449EAD11E", "hash_sha384": "C88580AE9D0ECE43A0214CA439408FF5ACC2C6952A7DCFE9771EBC44EC7EE83E6368123E0D92C5FBBE9395571F4AC88C", "hash_sha512": "D3DF56C20E31D0ED75E1E85E300E520FBFD02A7F4DEFA2A120B2A88FBD70572479EB067C753E3A243F474B168806929BF1656E005CBD7042FC27E00F1E2FC1EA", "hash_ssdeep": "6144:ROqyheCdi1s8GbWim3xWmuEfOBVODnom8gjJOv3AaNWGIAX4c6UdpDlF:RLG83QmQ", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "0B3FB9BE44728EF3B415F3EFD3E923077CEB91A1", "hash_pe256": "D952CBF51BF1B4402B0D655AF7EBDFE73C601BF10A867B414EF539D7FA899139", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Visual UIA Verify", "meta_original_filename": "VisualUIAVerifyNative.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_8236": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\UIAVerify\\UIAComWrapper.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\UIAVerify\\WUIATestLibrary.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\System32": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\UIAVerify\\Interop.UIAutomationClient.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\ieframe.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\202cHWNDInterface:c064c": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_ie_global_counters": "Section", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\UIAVerify\\WUIALogging.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\UIAutomationCore.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\arm64\\UIAVerify\\VisualUIAVerifyNative.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll" ], "runtime_window_title": "Visual UI Automation Verify : Client Side Provider" }, "accevent.exe-499CAE98F79635D60CC333400963554E": { "file_name": "accevent.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\accevent.exe", "hash_md5": "499CAE98F79635D60CC333400963554E", "hash_sha1": "8CE29B08A90A7475323703341C1FACC9DF459C72", "hash_sha256": "6917FB723925188A1C1B9A88BA279FD9FC9EF374B8895AAC7BCE00E0D1F05E7B", "hash_sha384": "4E318FE67EC110CFFE82932982FC1077BD0F408C52A8E4D798CF57CDD1F37F7F48C4C679A5F5FDB8A1C1F430DF50CD3F", "hash_sha512": "9BB0971669FA0B0C46DCF927E71BC073B0AB06D4ED15F6518C809E7344A1C09126F0D5F3268C9605FD2E104DDE22378CC401FE89C1452A446D1D07479F432C53", "hash_ssdeep": "3072:yc4gVryv9MLzq9VTuF63OBTd9XXhijscGP4PPgz3UMKYMKhCfNIHlr1JryPeXXOq:f4gVmczqJ3whijscGP4PPgz3UMKYMKhv", "hash_imp": "6ACE1C3BCA2847724E06F3A9E6815C0A", "hash_pesha1": "2179AE8D65091F8C6AFDA43BE9432F5C7D5F9343", "hash_pe256": "7FA5FC5616C155423768882B9A871B9FAC03136FC1EAA40C7B8E90C01FCC9F35", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Accessible Event Watcher (64-bit UNICODE Release)", "meta_original_filename": "ACCEVENT.EXE", "meta_product_name": "Microsoft Active Accessibility", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.0.0", "meta_product_version": "7.2.0.0", "meta_language": "English (United States)", "meta_legal_copyright": " 2012 Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\System32": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\accevent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll" ], "runtime_window_title": "AccEvent - UIAutomation Events [Stopped]" }, "adpcmencode3.exe-12FFEE959BBC29D544DD6387E63981D4": { "file_name": "adpcmencode3.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\adpcmencode3.exe", "hash_md5": "12FFEE959BBC29D544DD6387E63981D4", "hash_sha1": "A43EC313DA7B09AB9F4CFF757FE6A43162FE9487", "hash_sha256": "CFC7FC6B150839C6E4591CAB1E4E518492FCDE547B5D41ACAEBC541251AD397D", "hash_sha384": "BC28D210D52BEA9F2AA44E82B9C655A23C0C242F38FE97BF8C19AB7DD903BA8906D45FFBF469667CD93BB7F781B83687", "hash_sha512": "32B8128CAD269895623A359840A8957616D3D6B4604940E671B4D927FF7406CBBDFE1CEED4C56FF7F57D7E99D153535E12DCC87ED8921C14DA53084646785541", "hash_ssdeep": "6144:eE/K3CrvjZ72vj5bU8d5SfKJ1xBFa3D2Au7qbUxG3M1:eE/K3Crv9yJ15sW/azNQQM1", "hash_imp": "0E2AE90C14F52662C701EB6CA9C81166", "hash_pesha1": "D7FD0DA81DAC7FA28EFCEC1048706D2D13C31CEE", "hash_pe256": "CA33CD590FCC8BF7BB4FD5761F7353EDACC9943F32657EE979AEC2E36A1D8B8D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ADPCM encoding and decoding utility", "meta_original_filename": "AdpcmEncode.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Copyright (C) 2012 Microsoft Corporation. All rights reserved.\r\n\r\nUsage: ADPCMENCODE [-b <N>] [-f <N>] <INPUTFILE>.wav <OUTPUTFILE>.wav\r\n\r\nIf the input file is PCM, it is encoded to an ADPCM file;\r\nif the input file is ADPCM, it is decoded to a PCM file.\r\n\r\nInput PCM files must be int8, int16 or float32, mono or stereo,\r\nwith at least 128 samples of audio and no loop regions shorter\r\nthan 128 samples.\r\n\r\nOptions:\r\n\t-b <32|64|128|256|512>: Number of samples per encoded ADPCM block (default 128)\r\n\t-f <N>: Bits per sample in decoded PCM file (8, 16, or 32; default 16)\r\n\r\nUnrecognized flag \"--\"\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\adpcmencode3.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "betest.exe-FC117B7C64C32995942807907C21936B": { "file_name": "betest.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\betest.exe", "hash_md5": "FC117B7C64C32995942807907C21936B", "hash_sha1": "EC005794C7C828D83D9D2E6348C8DA2036A67B99", "hash_sha256": "A46046DA397B9ECDFFE72540638D4A25EBC1AC0AE4376697CBB564B85339165D", "hash_sha384": "E677EEA094920DCB4077C0BAD4A4C491D93AECD7EA71F8518A204B0D23056FE898E2E49E7F0381223367514B7F01810E", "hash_sha512": "BDBE6D64BB0967B6A6CF1AB38B230A3FFC444EA57BC7D8664BA5455D7B6AC39051F189215D7485FD5A212FF53B5634A2FEB700E193AC89F5A3EBC302EC6BAC08", "hash_ssdeep": "6144:BaMhpGNWA7XxnI2+07Nvb7Ojixqf7ZY74LJPUozIL+I:BaMTGNV5N+0Zzi+kf1y4XvI", "hash_imp": "49274E2FFECC277B0E990D7C1E7CE73F", "hash_pesha1": "62E057CAE31160CBAC677558D522B20F286D6DCA", "hash_pe256": "FCA0D739060F342A9C82C4DF6F76799E79A2593CAE458E49BECB164B791EA330", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BETest, Volume Shadow Copy Service (VSS) Backup/Restore Test Tool", "meta_original_filename": "BETEST.EXE", "meta_product_name": "BETest", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "This version of BETest only runs on Windows 8 and Windows Server 2012 or above.", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\betest.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "cameraprofiletool.exe-7B64FE5C9FBB01E84119BA93E046F1E5": { "file_name": "cameraprofiletool.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\cameraprofiletool.exe", "hash_md5": "7B64FE5C9FBB01E84119BA93E046F1E5", "hash_sha1": "199A9C31DCC96B0A68A72EF6B0046F97FD98C5AE", "hash_sha256": "7BE731BF3ABE4B6C2F2FBAB650F27C545D5F8072CD277B92645618329552EE14", "hash_sha384": "138E134876ACB4D86E9456AED544C5A6D590E0AC87880EECF80A0C13AF17A06B4AE3B0B91A706D19BC473BFF41F43FD5", "hash_sha512": "AF19C1A63456C73F381CAA847600FF3776730DEFAE0EBEFDAF6EBF2F120110BAA61CF9FFEBC719DD13CCF56B8152037F5F3117BB602D9138A6EF04E2B029B4F4", "hash_ssdeep": "1536:LdmwgUH62ruraVOT0ynAqQKhZ2qsT3WETbu++CD7Fr9F4IxxIx:QqauuuVOQyneAoGEZ+SZ9FvxxIx", "hash_imp": "F87C43C58944D8BAA2227A6078AFE456", "hash_pesha1": "9675DDECE9E8B14E4E463E83818EC9F0DB86594B", "hash_pe256": "0A958F843EB1B6A6E902ADCE1604676A3ABDDB0C9FD6109A97F4A256084491BE", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\cameraprofiletool.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Camera Profile Tool Test App", "meta_original_filename": "CameraProfileTool.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7be731bf3abe4b6c2f2fbab650f27c545d5f8072cd277b92645618329552ee14/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\cameraprofiletool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\setupapi.dll" ], "runtime_window_title": "ProfileTool" }, "cert2spc.exe-6D51AC10558A4EE25025F80B72105CA6": { "file_name": "cert2spc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\cert2spc.exe", "hash_md5": "6D51AC10558A4EE25025F80B72105CA6", "hash_sha1": "74C587A396D3B39DF563F88D068DE15D6D5257C4", "hash_sha256": "675D3488D840B6BA6DB21E16CE5FA470CEDD9BCCF554912B667A215FD3EB52F7", "hash_sha384": "C5CAFCAFA8B73BE18485B4BA0D96EF21692F4073772AB624E2EFA828F02B39E3FF7263A69B089E3AAC9FDA1A24C3A42B", "hash_sha512": "5B0F042287D9D659E3881B587FE0FFF6687D809B297F4019B5BADEE15B184B25453EE1B991D70F9F919B1DF09D39037F72E5A3774344A3F1F748CAF06E008D24", "hash_ssdeep": "384:DFwecljZ2jWN5xT5MwCRWn/Wne3wGyOk9flx6v:DaeOZjK/uH3wo", "hash_imp": "6FBAB9A22C6679E90186F2C71B342D49", "hash_pesha1": "CED578E3AFF49E793B841D9532EB68B3E1B592F4", "hash_pe256": "B9CB743CAC3ACBBDDDCE4DE45DA055E371EE0C784428840C07C39F35A04857CC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ECM Cert2Spc", "meta_original_filename": "CERT2SPC.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/675d3488d840b6ba6db21e16ce5fa470cedd9bccf554912b667a215fd3eb52f7/detection", "output": "Usage: Cert2Spc {cert1.cer|crl1.crl ... certN.cer|crlN.crl} output.spc\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\cert2spc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "certmgr.exe-564D9F5DBD12AA4123156ED32A78F409": { "file_name": "certmgr.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\certmgr.exe", "hash_md5": "564D9F5DBD12AA4123156ED32A78F409", "hash_sha1": "944971D62DB020E0D0FD180348F973F49A8623F0", "hash_sha256": "4CE851375F7A0CD135A3148EFEA34CFDB8A9E584E9D179653A142F3640701EDD", "hash_sha384": "4791F33BBD92FECD5306AE124041C8BB4ECB2B8E58AF8E75800F112DB923874EDC077A7C66DA14E3AD49C1C765E2DACA", "hash_sha512": "2FCD31877141C4AEC436DE46CF24B9C4EADB8272260981A077152B1F81E3C03E4072D01DE3B0A51D3EC5910391C0DF93FEE8F6AA8C7DCD6F5AB53891BB397F50", "hash_ssdeep": "1536:VrgQs8OivXyUtiB8JFtY/OT5oNuRGx8UBYw+WXsA9i9vY4u2:3FfvXyUto0qeyHKUBt+WXsNI2", "hash_imp": "288C77221EE9A27F869B542320D273EF", "hash_pesha1": "B77D7F16DFD77FBDAB303A3EC7E491E9509D8BC0", "hash_pe256": "D461B1DE52943920018DBACB46209ADE2F651F1ED5D0D89F568F1C5CF7E7D3AC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ECM Certificate Manager", "meta_original_filename": "CERTMGR.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Usage: CertMgr [options][-s [-r <location>][SourceStoreName]\r\n [-s [-r <location>][DestinationStoreName]\r\nOptions: \r\n -add Add certificates/CRLs/CTLs to a storeFile or a system store\r\n -del Delete certificates/CRLs/CTLs from a storeFile or \r\n a system store\r\n -put Put an encoded certificate/CRL/CTL from a storeFile or\r\n a system store to a file. The file will be saved in X.509\r\n format. -7 can be used to save the file in PKCS #7 format\r\n -s Indicate the store is a system store \r\n -r <location> The system store location \r\n <currentUser|localMachine> Default to 'currentUser' \r\n -c Certificates in the store\r\n -crl Certificates revocation lists(CRLs) in the store\r\n -ctl Certificates trust lists(CTLs) in the store\r\n -v Verbose display of the certificates/CRLs/CTLs \r\n -all All certificates/CRLs/CTLs in the store\r\n -n <name> Common name of the certificate \r\n -sha1 <thumbPrint> The sha1 hash of the certificate/CRLs/CTLs \r\n -7 Save the destination store in PKCS #7 format\r\n -e <encode> Certificate/CRL/CTL encoding type. \r\n Default to X509_ASN_ENCODING\r\n -f <flag> CertStore open flags. Meaningful only if -y is set\r\n -y <provider> CertStore provider name\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\certmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ComparePackage.exe-3851B4FDACA45C3636F0E4EC916A2ACA": { "file_name": "ComparePackage.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\ComparePackage.exe", "hash_md5": "3851B4FDACA45C3636F0E4EC916A2ACA", "hash_sha1": "5D13FD81746FA50EB04B6E60845B9FC26A4C1E56", "hash_sha256": "4F6558FE6BE1AE6A06A8366D7B478BA92791EA7635089D774D1A768AE2E3FAC5", "hash_sha384": "D989AC2B2DD8E478744849469EC6203F0DE8DEAF68B47F3020BC4E2CE63DFB169C2C13C05D9E4AA764A8C347E8C56C42", "hash_sha512": "30029DE606B395B6B241841EEF1CD919F6F55F75CE0B61246B1F1E3C26D275E075F4065FCE9631BC5B784D57F6B6AFE26199C67D37DAECEA5C51E336BFFACA7A", "hash_ssdeep": "768:pTF5BzCz6SHsrZEtOUHDrRyXnbT/23VRfN8l2Hg:LCeKsrKtOUj9y//AVRfN8lqg", "hash_imp": "n/a", "hash_pesha1": "DFA349D71F56D36E361B21652D04725DEE4F0944", "hash_pe256": "ACF96E9F3887E0C62CD8EBEC68A0EB1E588E7DEA331E601310ADFDB90B17C523", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\ComparePackage.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": " ", "meta_original_filename": "ComparePackage.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4f6558fe6be1ae6a06a8366d7b478ba92791ea7635089d774d1a768ae2e3fac5/detection", "output": "Microsoft (R) ComparePackage Tool\r\nCopyright (C) 2018 Microsoft. All rights reserved.\r\nLog file is located under: C:\\Users\\user\\AppData\\Local\\Temp\\ComparePackage\\Logs_1\\Log.txt\r\n\r\nCompare Package started!\r\nVersion 10.0.0.0\r\n\r\nCompare Package started!\nComparePackage analyzes the differences between two versions of your package and helps you understand how the changes can impact users' updates.\r\n\r\nUsage: ComparePackage.exe [arguments] [options]\r\n\r\nArguments:\r\n <original package path> File system path to the original package or the original package's blockmap for comparison\r\n <new package path> File system path to the new package or the original package's blockmap for comparison\r\n\r\nOptions:\r\n -h Shown the usage\r\n -version Show the tool's version\r\n -v Enables verbose output to the console\r\n -o Overrides output XML if exists\r\n -XML Saves XML version of the output to the path specified in addition to the console output\r\n\r\nExamples:\r\nComparePackage <original package path> <new package path> [-XML <XML path>] [-o] [-v]\r\nComparePackage mypackage_1.04_x64.msix mypackage_1.05_x64.msix -XML \"C:\\diffoutputs\\mypackage_1.04_1.05_diff.xml\"\r\nComparePackage mypackage_1.04_x64.appx mypackage_1.05_x64.appx -XML \"C:\\diffoutputs\\mypackage_1.04_1.05_diff.xml\"\n\r\nSupported input types:\r\n .appx/.msix\r\n .appxbundle/.msixbundle\r\n .appxbundle/.msixbundle to .appxbundle/.msixbundle\r\n .eappx/.emsix to .eappx/.emsix\r\n .eappxbundle/.emsixbundle to .eappxbundle/.emsixbundle\r\n .xml to .xml (blockmaps only comparison)\r\n *Only packages encrypted with the test key /kt option in MakeAppx.exe are supported.\r\nDefinitions:\r\n Impact\r\n - The amount that a particular file impacts the users' update in bytes\r\n Net Update Impact Size\r\n - The sum of impact of all changed and added files, can be used to approximate users' update download size as a result of the new version\r\n Size Difference\r\n - Difference in file size in bytes between new and original version\r\n Size\r\n - File size in bytes of added or deleted files\r\n Duplicate Files\r\n - File sets that are exactly the same in the new package(does not consider original package)\r\n\r\n", "error": "Path error: help not found\r\nCheck the paths in your arguments. We couldn't find the files at the paths specified.\r\nError: The argument <original package path> should be a valid file.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\ComparePackage.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "computerhardwareids.exe-F72CADFA334092C45E6B1DD408C79E29": { "file_name": "computerhardwareids.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\computerhardwareids.exe", "hash_md5": "F72CADFA334092C45E6B1DD408C79E29", "hash_sha1": "FF57BDEAD4448A2A0E1DAB35F5576670928FA27D", "hash_sha256": "0EA5B7DCB056B288EA365E0EAC2FBC6F9C5B2DAB6CA722B4FCE747A78249D4E6", "hash_sha384": "78FFE307127CA319DDFDC9DB898E263959C31C74B3065223262D3E0974121242DBEA015C705803A9989633C6592952A6", "hash_sha512": "6BA7E0558D9C8F09D916636432D9F2DC14644D5701C3D2125639C98E134448B439D59144388BA41827DD17AFA9B7ACD8647CCA8F046F802B6C7DEF1A6B638480", "hash_ssdeep": "768:ZC+rrlxPGT1iFYBllWxWC1FFECVQVdu/dGCp1X:dLPYe4jsW+FFEFduFGCL", "hash_imp": "26284274DD19BD6814E0A94AE4E6B717", "hash_pesha1": "AF0018163EF984C70837E6EB7E5C7E242C2BA530", "hash_pe256": "922615BA740ADA8BE8D3F13C97FC8493E1A0619F636ABC5748FA0C382F4D1C49", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ComputerHardwareIds is a tool to derive the computer hardware ids from SMBIOS information.", "meta_original_filename": "ComputerHardwareIds.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "NAME\r\n ComputerHardwareIds - Outputs the HardwareIds for the computer\r\n\r\nSYNOPSIS\r\n ComputerHardwareIds.exe [/mfg] [/product] [/family] [/ven] [/ver] [/major]\r\n [/minor] [/sku] [/enclosure] [/bb_mfg] [/bb_product] [/verbose] [/?]\r\n\r\nDESCRIPTION\r\n Outputs the HardwareIds for the computer. When executed without any command\r\n line arguments the HardwareIds are generated using data in the system\r\n BIOS. Optional arguments allow the generation of HardwareIds based on\r\n strings specified on the command line. When optional arguments are specified\r\n the BIOS values on the local computer are not used when generating the\r\n HardwareID values.\r\n\r\nOPTIONS\r\n\r\n Argument BIOS Field Meaning\r\n -----------------------------------------------------------------------------\r\n /ven \"BIOS vendor string\" Specifies the BIOS vendor string for\r\n a given system. If not specified the\r\n value is assumed to be NULL.\r\n\r\n /ver \"BIOS version string\" Specifies the BIOS version string for\r\n a given system. If not specified the\r\n value is assumed to be NULL.\r\n\r\n /major \"System BIOS Major Release\" Specifies the BIOS major release\r\n as a string representation of\r\n an int. If not specified the value is\r\n assumed to be '0'.\r\n\r\n /minor \"System BIOS Minor Release\" Specifies the BIOS minor release\r\n as a string representation of\r\n an int. If not specified the value is\r\n assumed to be '0'.\r\n\r\n /mfg \"System Manufacturer string\" Specifies the System Manufacturer\r\n string for a given system. If not\r\n specified the value is assumed to be\r\n NULL.\r\n\r\n /family \"System Family string\" Specifies the System Family string\r\n for a given system. If not specified\r\n the value is assumed to be NULL.\r\n\r\n /product \"System ProductName string\" Specifies the ProductName string for\r\n a given system. If not specified the\r\n value is assumed to be NULL.\r\n\r\n /enclosure \"Enclosure type number\" Specifies the number for the\r\n Enclosure type for the system. This\r\n number is the Byte value from the\r\n Sytem Enclosure or Chassis Type list\r\n in the SMBIOS specification. This\r\n value cannot be 0.\r\n\r\n /bb_mfg \"Baseboard Manufacturer string\" Specifies the Baseboard Manufacturer\r\n string for a given system. If not\r\n specified the value is assumed to be\r\n NULL.\r\n\r\n /bb_product \"Baseboard Product string\" Specifies the ProductName string for\r\n a given baseboard. If not specified the\r\n value is assumed to be NULL.\r\n\r\n /sku \"SKU Number string\" Specifies the SKU Number string\r\n for the system. If not specified\r\n the value is assumed to be NULL.\r\n\r\n /verbose \"true or false\" Specifies whether to print more\r\n information than just the GUIDs. If\r\n not specified verbose output is\r\n assumed.\r\n\r\n /? List of the command line options and\r\n usage.\r\n -----------------------------------------------------------------------------\r\n\r\n Up to fifteen HardwareIds will be generated depending on the following:\r\n * The BIOS fields available on the local system when no arguments are\r\n specified.\r\n * The command line arguments specified.\r\n\r\n Each of the following HardwareIds will be generated if the indicated BIOS\r\n fields or arguments are available:\r\n\r\n HardwareId 1 : Manufacturer + Family + Product Name + SKU Number + BIOS Vendor\r\n + BIOS Version + BIOS Major Release + BIOS Minor Release\r\n [required] /ven, /ver, /mfg, /product and /sku\r\n [optional] /major, /minor, and /family\r\n\r\n HardwareId 2 : Manufacturer + Family + Product Name + BIOS Vendor\r\n + BIOS Version + BIOS Major Release + BIOS Minor Release\r\n [required] /ven, /ver, /mfg, and /product\r\n [optional] /major, /minor, and /family\r\n\r\n HardwareId 3 : Manufacturer + Product Name + BIOS Vendor\r\n + BIOS Version + BIOS Major Release + BIOS Minor Release\r\n [required] /ven, /ver, /mfg, and /product\r\n [optional] /major and /minor\r\n\r\n HardwareId 4 : Manufacturer + Family + ProductName + SKU Number + Baseboard Manufacturer + Baseboard Product\r\n [required] /mfg, /product, /sku, /bb_mfg, and /bb_product\r\n [optional] /family\r\n\r\n HardwareId 5 : Manufacturer + Family + ProductName + SKU Number\r\n [required] /mfg, /product, and /sku\r\n [optional] /family\r\n\r\n HardwareId 6 : Manufacturer + Family + ProductName\r\n [required] /mfg, and /product\r\n [optional] /family\r\n\r\n HardwareId 7 : Manufacturer + SKU Number + Baseboard Manufacturer + Baseboard Product\r\n [required] /mfg, /sku, /bb_mfg, and /bb_product\r\n\r\n HardwareId 8 : Manufacturer + SKU Number\r\n [required] /mfg and /sku\r\n\r\n HardwareId 9 : Manufacturer + ProductName + Baseboard Manufacturer + Baseboard Product\r\n [required] /mfg, /product, /bb_mfg, and /bb_product\r\n\r\n HardwareId 10 : Manufacturer + ProductName\r\n [required] /mfg and /product\r\n\r\n HardwareId 11 : Manufacturer + Family + Baseboard Manufacturer + Baseboard Product\r\n [required] /mfg, /family, /bb_mfg, and /bb_product\r\n\r\n HardwareId 12 : Manufacturer + Family\r\n [required] /mfg and /family\r\n\r\n HardwareId 13 : Manufacturer + Enclosure Type\r\n [required] /mfg and /enclosure\r\n\r\n HardwareId 14: Manufacturer + Baseboard Manufacturer + Baseboard Product\r\n [required] /mfg, /bb_mfg, and /bb_product\r\n\r\n HardwareId 15: Manufacturer\r\n [required] /mfg\r\n\r\n Refer to the System Management (SMBIOS) Specification for additional\r\n details on these BIOS fields.\r\n\r\n BIOS Field Name Structure Name (Type) Offset\r\n -----------------------------------------------------------------------------\r\n Baseboard Manufacturer Baseboard Information (Type 2) 04h\r\n\r\n Baseboard Product Baseboard Information (Type 2) 05h\r\n\r\n System Manufacturer System Information (Type 1) 04h\r\n\r\n System Family System Information (Type 1) 1Ah\r\n\r\n System Product Name System Information (Type 1) 05h\r\n\r\n SKU Number System Information (Type 1) 19h\r\n\r\n BIOS Vendor BIOS Information (Type 0) 04h\r\n\r\n BIOS Version BIOS Information (Type 0) 05h\r\n\r\n System BIOS Major Release BIOS Information (Type 0) 14h\r\n\r\n System BIOS Minor Release BIOS Information (Type 0) 15h\r\n\r\n Enclosure type System Enclosure (Type 3) 05h\r\n -----------------------------------------------------------------------------\r\n\r\nEXAMPLES\r\n\r\n Generating HardwareIds from the BIOS:\r\n\r\n ComputerHardwareIds.exe\r\n\r\n Generating HardwareIds from command line arguments:\r\n\r\n ComputerHardwareIds.exe /ven \"Contoso Ltd.\" /ver \"0.158\" /major \"12\"\r\n /minor \"9\" /mfg \"Contoso\" /family \"Q Workstation\" /product \"3C273\"\r\n /enclosure \"6\"\r\n\r\nC:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\computerhardwareids.exe version\r\n 10.0.19041.1\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\computerhardwareids.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "convert-moftoprovider.exe-18B980FAB33DEFADAF55F11C74FB690D": { "file_name": "convert-moftoprovider.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\convert-moftoprovider.exe", "hash_md5": "18B980FAB33DEFADAF55F11C74FB690D", "hash_sha1": "9FB990AE17161C56C1C6EDCE838D384CB62603F4", "hash_sha256": "0C14A5E99C861E3A393A78E23D85DA1AACD43AB29FE017EB56BABD3BF447DBFA", "hash_sha384": "3FE2700108FE5349FB20E9F0184530BA47DD89FCB597328D5744589F096CD291C2ADEFE91C95FA7300A313A4B4EB6B9A", "hash_sha512": "0ADDBE51166592F45F8B68BC0F54F565CC1085A7A0F728680C66DD0EF5607603EB5CE9ECA280A1D88B84D846830796FEAED27479B56B8DB0F0F2C0A35B07F122", "hash_ssdeep": "3072:31gykd5LwSBRwqXiLYra7NNhUtaXkgnUPfoE2vo1aXPcv5:31gykdJYqXUYO7+ta0g0fXXsXO", "hash_imp": "9A3EFF2603CA54C52CD05DC491263F6F", "hash_pesha1": "841A9CD4BE54DDF5379F32714BDE2C5963E9E496", "hash_pe256": "E2DC0FD29995F8D6D8B950AACA247C3007D0CAF8D0B7A6BA8EFF6CB38D79479B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI V2 provider code generation tool", "meta_original_filename": "convert-moftoprovider.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "\r\nGenerates provider source code (C) from MOF class definitions.\r\n\r\nUsage: Convert-MofToProvider.exe\r\n\t\t-MofFile <Mof files>\r\n\t\t-ClassList <Class list>\r\n\t\t-IncludePath <Path list>\r\n\t\t-InputParameterSet <Parameter Filename>\r\n\t\t[Other options]\r\n\r\n-MofFile <Mof files>\r\n\tSpecifies list of mof files that contains the MOF definitions\r\n\t(or includes them), which are seperated by space.\r\n\tIt must include any dependent MOF defintions as well (such as\r\n\tthe CIM schema).\r\n\r\n-ClassList <Class list>\r\n\tSpecifies list of the names of the MOF classes to be generated.\r\n\tIf no class specified, it will generate all classes.\r\n\r\n-IncludePath <Path list>\r\n\tSpecifies list of the directories, from which to search for included\r\n\tMOF files. If no include path specified, it will search current\r\n\tdirectory by default.\r\n\r\n-InputParameterSet <Parameter Filename>\r\n\tSpecifies the parameter filename, which defines the input parameters.\r\n\tThis option cannot be used with other options.\r\n\tExample: Convert-MofToProvider.exe -InputParameterSet param.txt\r\n\tExample of content for the parameter file,\r\n\t\t-MofFile a.mof\r\n\t\t-ClassList MSFT_A MSFT_B\r\n\t\t-IncludePath C:\\stdmof\r\n\r\n[Other options]\r\n\r\n-Help\r\n\tShows the syntax and the version of the code generation tool.\r\n\r\n-NoDescriptionQualifier\r\n\tDoes not generate the description qualifiers in the schema.c.\r\n\tDefault generate.\r\n\r\n-NoBooleanQualifier\r\n\tDoes not generate boolean qualifiers in the schema.c.\r\n\tDefault generate.\r\n\r\n-NoValuemapQualifier\r\n\tDoes not generate values or valuemap qualifiers in the schema.c.\r\n\tDefault generate.\r\n\r\n-NoStandardQualifier\r\n\tDoes not generate standard qualifiers in the schema.c.\r\n\tDefault generate.\r\n\r\n-NoSAL\r\n\tDoes not generate SAL annotation. Default generate.\r\n\r\n-SkipQualifiers\r\n\tGenerates no qualifiers in the schema.c.\r\n\tDefault does not generate. Cannot be used with any *qualifier options.\r\n\r\n-SupportFilter\r\n\tSet MI_MODULE_FLAG_FILTER_SUPPORT bit of MI_Module.\r\n\tDefault does not set.\r\n\r\n-MappingString\r\n\tGenerates mapping strings in the schema.c.\r\n\tDefault does not generate.\r\n\r\n-Quiet\r\n\tDoes not output detail information.\r\n\r\n-SkipLocalize\r\n\tDoes not generate strings.rc file for localizable qualifiers.\r\n\tResource file is always generated by default.\r\n\r\n-OutPath\r\n\tSpecifies output directory of generated files.\r\n\tCreates directory if it does not exist.\r\n\r\n-ExtraClass\r\n\tGenerates class files but not providers for classes listed.\r\n\r\n-OldRcPath\r\n\tGive the path to old rc file to reuse the string ids from.\r\n\r\nEXAMPLES:\r\n\tThe following example generates a 'MSFT_ComputerSystem' class,\r\n\twhich is defined in schema.mof.\r\n\r\n\tConvert-MofToProvider -MofFile schema.mof -ClassList MSFT_ComputerSystem\r\n\r\n\tConvert-MofToProvider -MofFile schema.mof -ClassList MSFT_ComputerSystem\r\n\t-IncludePath C:\\mof\\cim222\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\convert-moftoprovider.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "cppwinrt.exe-47538C456C2A12B90371E541D53933BF": { "file_name": "cppwinrt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\cppwinrt.exe", "hash_md5": "47538C456C2A12B90371E541D53933BF", "hash_sha1": "B8E05A6CBE73342BDCAC40CD37599F6BEF0A4F01", "hash_sha256": "84C8B7417A544B09DEFCFF025524645E2CA7CD1F01B644B22F6B34420EF0D718", "hash_sha384": "4E31B39C0B0537EF7564909FB2C152FD8C00D02BCAE5B3576E414912F59B1CAAFCF265A4A8218F83846B3529661E1351", "hash_sha512": "F461E6656A6D5CC1DA340870DE814B85DC3A11A803B383C53149DECBB1F768E9B8F20B7580D9603DDE06FE69A8A7F646AF803A0DBD6EE748FA9B7F67F352B0FE", "hash_ssdeep": "24576:wM99jN+doLjdE7gUKFQI9lfHpyNsHujT4R1NtNh4AMgpDeLfPcY5kTl1qS4PQvG8:z0cll11z74bQkdF9HSkpDjeiR/j573T8", "hash_imp": "6752EDA56876B8755B7CF239CF9ACD46", "hash_pesha1": "A97A2F757C6066F2A1ED5E322891AA7F5CFF22AE", "hash_pe256": "AE6C0AF4E7FADF19C694B5EB98B1DF3D9A524A25CB9D063638A920C8BFF59638", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\cppwinrt.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "C++/WinRT", "meta_original_filename": "cppwinrt.exe", "meta_product_name": "C++/WinRT", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2.0.0.0", "meta_product_version": "2.0.190620.2", "meta_language": "English (United States)", "meta_legal_copyright": "Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "1/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/84c8b7417a544b09defcff025524645e2ca7cd1f01b644b22f6b34420ef0d718/detection", "output": "\r\nC++/WinRT v2.0.190620.2\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\n cppwinrt.exe [options...]\r\n\r\nOptions:\r\n\r\n -input <spec> Windows metadata to include in projection\r\n -reference <spec> Windows metadata to reference from projection\r\n -output <path> Location of generated projection and component templates\r\n -component [<path>] Generate component templates, and optional implementation\r\n -name <name> Specify explicit name for component files\r\n -verbose Show detailed progress information\r\n -overwrite Overwrite generated component files\r\n -prefix Use dotted namespace convention for component files (defaults to folders)\r\n -pch <name> Specify name of precompiled header file (defaults to pch.h)\r\n -include <prefix> One or more prefixes to include in input\r\n -exclude <prefix> One or more prefixes to exclude from input\r\n -base Generate base.h unconditionally\r\n -optimize Generate component projection with unified construction support\r\n -help Show detailed help with examples\r\n -library <prefix> Specify library prefix (defaults to winrt)\r\n @<path> Response file containing command line options\r\n\r\nWhere <spec> is one or more of:\r\n\r\n path Path to winmd file or recursively scanned folder\r\n local Local %WinDir%\\System32\\WinMetadata folder\r\n sdk[+] Current version of Windows SDK [with extensions]\r\n 10.0.12345.0[+] Specific version of Windows SDK [with extensions]\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\cppwinrt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ctrpp.exe-5DC2ABBECE32570B242E698F633F5EDB": { "file_name": "ctrpp.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\ctrpp.exe", "hash_md5": "5DC2ABBECE32570B242E698F633F5EDB", "hash_sha1": "5ACA6D7C4E9361CAE24DC630008F19D664FD13FF", "hash_sha256": "0FD458FDA1E397CFCBACE36FBFD83AB337D4203CBE3B6880CB00664D6734744A", "hash_sha384": "59EF796040892402C8B70CDB81331F52903397EB8C5832880CB915D73ADF0C49C31B9E86EE616C27860233A1D09A6FCA", "hash_sha512": "6537E3C904963B98F4531278CC1A64BDD83139CD44F6DA6EC0D21B40CB4C750A67A70CD6153B01422EEA4E1A9D7F9D1C1E4E227B6D7382277764D5434C55C857", "hash_ssdeep": "3072:Epr1jLGDbMtRM6Im/bQZU8oQNaK3vGbu9lMcIgeVw70reqnl1PWyHSb7Bt1c2iec:Epr5I6RM6IubQZU8oQkgGbZyb7Y", "hash_imp": "4A5023F965CE7575753F80A44E96FAD5", "hash_pesha1": "DB93779DC17AC4C79BEA7F330A7868E52414BD49", "hash_pe256": "1AA8A9D493F5533ECCE19B8A8796B7962DAE4C283E42EC402EE452CE09FD497E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "parse/validate performance counter manifest and generate helper source files", "meta_original_filename": "CTRPP.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nUsage: ctrpp [-NotificationCallback] [-MemoryRoutines] [-o <filename>]\r\n [-rc <filename>] [-migrate <filename>] [-prefix <prefix>] <manifest>\r\n\r\n -NotificationCallback - Generate customized notification callback template.\r\n Similar to \"callback\" attribute in <provider> element.\r\n -MemoryRoutines - Generate memory allocation/free routine templates.\r\n -Legacy - Revert to previous ctrpp file-output behavior (see below).\r\n -o <filename> - Generate header file for provider.\r\n -ch <filename> - Generate header file for containing counter names and ids.\r\n -rc <filename> - Generate resource source file.\r\n -migrate <filename> - Generate manifest file conforming to the latest schema version.\r\n This switch cannot be used with other switches.\r\n -prefix <prefix> - Prefix to be added to functions and variables generated.\r\n -backcompat - Generates code that is binary compatible with OSs prior\r\n to Windows 7.\r\n -summary <path> - generate binary counter file per provider\r\n generate summary global file GenSumResource.BIN\r\n -sumPath <path> - Path to generate binary counter files\r\n default .\r\n\r\n <manifest> - counter manifest to be processed\r\n\r\nExamples: ctrpp -o header.h -rc resource.rc component.man\r\n ctrpp -legacy component.man\r\n ctrpp -migrate new.man old.man\r\n\r\nLegacy Mode:\r\nThe -legacy switch causes ctrpp to generate four output files: two header files, a resource file, and a source code file. This mimics the behavior found in previous versions of ctrpp. The -o, -ch, -rc and -prefix options cannot be used in conjunction with -legacy.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\ctrpp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DeployUtil.exe-499C75C9FAC5B5FA56A6E1AB712F849C": { "file_name": "DeployUtil.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\DeployUtil.exe", "hash_md5": "499C75C9FAC5B5FA56A6E1AB712F849C", "hash_sha1": "E8B1438E7B1FABD199FBA3D6953E16F427118661", "hash_sha256": "3C2888F1BDBE75A9DF1B9B3BC6578705D1FD5EFB9F5AE36D2CE369859474886A", "hash_sha384": "1B4AA3DD2D09DA2865213E1E77ABAC2DC863B9A3D951A02BA7DCE6DACE28DC1AEBDD6C983659DBA75080A3DD1C5A8336", "hash_sha512": "8905F748409E193BB89FA4E619DF3D4E3C3B4F6D32EEBDA4299064740ED23DF9E359341993BA921420A98AF73F5DF222AB490D4E60669CB66A4097B66BD4D723", "hash_ssdeep": "768:Oe09Yj8R1IGSjHRcJJW/LGBlteZSghZgzkJ1KiJoCYeCRcPj:2JChGQGHteZbEkJ1sOr", "hash_imp": "1E817911DCB445A2174BD8E69B2FD02A", "hash_pesha1": "E37B0D10034625E7D8371304AEBF1274EE602657", "hash_pe256": "8D7D4BB3D3EA1F0F6AEF3918EE93F3F76C00005AEAAE7AD1690AECD74383865E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000052C8FAF5B90BB753AC000000000052", "signature_thumbprint": "8438EA0A58759BEA28DA7CF658413939F2AD5BFF", "signature_issuer": "CN=Microsoft Windows Phone Production PCA 2012, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Windows Phone, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3c2888f1bdbe75a9df1b9b3bc6578705d1fd5efb9f5ae36d2ce369859474886a/detection", "output": "Arguments:\r\r\n\t/install <file-path> (/cert <cert-path>) (/dependency <dep-path>...)\r\r\n\t/update <file-path> (/dependency <dep-path>...)\r\r\n\t/uninstall <package-full-name>\r\r\n\t/list\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\DeployUtil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dxc.exe-ED15CA31310E9F54287C636B2554480E": { "file_name": "dxc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\dxc.exe", "hash_md5": "ED15CA31310E9F54287C636B2554480E", "hash_sha1": "A631498E24572965897C7AEB841BC20B787120B3", "hash_sha256": "0FFF44C2F61C2C61423F08C74ABA325049A1E14EDED5B491EFECB7839CCD9737", "hash_sha384": "1DDCB60E2E6F53CCA11CBE3069AA82B325B7DC586CC11D8ADF4C6B805958CB5AFB643DAD87979D599D41BA8ADC2BAA09", "hash_sha512": "5A50BBB364D130AB0D6F6C171B074480549914537F47CC502FBE18ED92E18C6B69956401A4D6E6ECDDB63D757D8A8A60586E6B0EC981A4FF5E20AD8AF12C721C", "hash_ssdeep": "1536:N+MtxZCPfnfsHZ4jweYJA2hjhlT4oFKuxbr41b8ULcGJPxaMusWUpIMY22HREE2j:rlDhjrKHyxGJPxaZUpIMKEE2+4iTHu", "hash_imp": "A00314C6AABC1FFCB1C05166CB2A3943", "hash_pesha1": "6D2EDB4BDE69A0798F15CBADC807C0B1AC68A470", "hash_pe256": "E0747A9D6A94427C2D5E226746C0A4E1B36039B5D842C09E56397A95B83CD3E1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DX Compiler", "meta_original_filename": "dxc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "OVERVIEW: HLSL Compiler\r\n\r\nVersion: dxcompiler.dll: 1.5 - 10.0.19041.1; dxil.dll: 1.5(10.0.19041.1)\r\n\r\nUSAGE: dxc.exe [options] <inputs>\r\n\r\nCommon Options:\r\n -help Display available options\r\n -nologo Suppress copyright message\r\n -Qunused-arguments Don't emit warning for unused driver arguments\r\n\r\nCompilation Options:\r\n -all_resources_bound Enables agressive flattening\r\n -auto-binding-space <value>\r\n Set auto binding space - enables auto resource binding in libraries\r\n -Cc Output color coded assembly listings\r\n -default-linkage <value>\r\n Set default linkage for non-shader functions when compiling or linking to a library target (internal, external)\r\n -denorm <value> select denormal value options (any, preserve, ftz). any is the default.\r\n -D <value> Define macro\r\n -enable-16bit-types Enable 16bit types and disable min precision types. Available in HLSL 2018 and shader model 6.2\r\n -export-shaders-only Only export shaders when compiling a library\r\n -exports <value> Specify exports when compiling a library: export1[[,export1_clone,...]=internal_name][;...]\r\n -E <value> Entry point name\r\n -Fc <file> Output assembly code listing file\r\n -Fd <file> Write debug information to the given file, or automatically named file in directory when ending in '\\'\r\n -Fe <file> Output warnings and errors to the given file\r\n -Fh <file> Output header file containing object code\r\n -flegacy-macro-expansion\r\n Expand the operands before performing token-pasting operation (fxc behavior)\r\n -flegacy-resource-reservation\r\n Reserve unused explicit register assignments for compatibility with shader model 5.0 and below\r\n -force_rootsig_ver <profile>\r\n force root signature version (rootsig_1_1 if omitted)\r\n -Fo <file> Output object file\r\n -Gec Enable backward compatibility mode\r\n -Ges Enable strict mode\r\n -Gfa Avoid flow control constructs\r\n -Gfp Prefer flow control constructs\r\n -Gis Force IEEE strictness\r\n -HV <value> HLSL version (2016, 2017, 2018). Default is 2018\r\n -H Show header includes and nesting depth\r\n -ignore-line-directives Ignore line directives\r\n -I <value> Add directory to include search path\r\n -Lx Output hexadecimal literals\r\n -Ni Output instruction numbers in assembly listings\r\n -no-warnings Suppress warnings\r\n -not_use_legacy_cbuf_load\r\n Do not use legacy cbuffer load\r\n -No Output instruction byte offsets in assembly listings\r\n -Odump Print the optimizer commands.\r\n -Od Disable optimizations\r\n -pack_optimized Optimize signature packing assuming identical signature provided for each connecting stage\r\n -pack_prefix_stable (default) Pack signatures preserving prefix-stable property - appended elements will not disturb placement of prior elements\r\n -recompile recompile from DXIL container with Debug Info or Debug Info bitcode file\r\n -res_may_alias Assume that UAVs/SRVs may alias\r\n -rootsig-define <value> Read root signature from a #define\r\n -T <profile> Set target profile. \r\n\t<profile>: ps_6_0, ps_6_1, ps_6_2, ps_6_3, ps_6_4, ps_6_5, \r\n\t\t vs_6_0, vs_6_1, vs_6_2, vs_6_3, vs_6_4, vs_6_5, \r\n\t\t cs_6_0, cs_6_1, cs_6_2, cs_6_3, cs_6_4, cs_6_5, \r\n\t\t gs_6_0, gs_6_1, gs_6_2, gs_6_3, gs_6_4, gs_6_5, \r\n\t\t ds_6_0, ds_6_1, ds_6_2, ds_6_3, ds_6_4, ds_6_5, \r\n\t\t hs_6_0, hs_6_1, hs_6_2, hs_6_3, hs_6_4, hs_6_5, \r\n\t\t lib_6_3, lib_6_4, lib_6_5, ms_6_5, as_6_5\r\n -Vd Disable validation\r\n -Vi Display details about the include process.\r\n -Vn <name> Use <name> as variable name in header file\r\n -WX Treat warnings as errors\r\n -Zi Enable debug information\r\n -Zpc Pack matrices in column-major order\r\n -Zpr Pack matrices in row-major order\r\n -Zsb Build debug name considering only output binary\r\n -Zss Build debug name considering source information\r\n\r\nOptimization Options:\r\n -O0 Optimization Level 0\r\n -O1 Optimization Level 1\r\n -O2 Optimization Level 2\r\n -O3 Optimization Level 3 (Default)\r\n\r\nSPIR-V CodeGen Options:\r\n -fspv-debug=<value> Specify whitelist of debug info category (file -> source -> line, tool)\r\n -fspv-extension=<value> Specify SPIR-V extension permitted to use\r\n -fspv-flatten-resource-arrays\r\n Flatten arrays of resources so each array element takes one binding number\r\n -fspv-reflect Emit additional SPIR-V instructions to aid reflection\r\n -fspv-target-env=<value>\r\n Specify the target environment: vulkan1.0 (default) or vulkan1.1\r\n -fvk-b-shift <shift> <space>\r\n Specify Vulkan binding number shift for b-type register\r\n -fvk-bind-globals <binding> <set>\r\n Specify Vulkan binding number and set number for the $Globals cbuffer\r\n -fvk-bind-register <type-number> <space> <binding> <set>\r\n Specify Vulkan descriptor set and binding for a specific register\r\n -fvk-invert-y Negate SV_Position.y before writing to stage output in VS/DS/GS to accommodate Vulkan's coordinate system\r\n -fvk-s-shift <shift> <space>\r\n Specify Vulkan binding number shift for s-type register\r\n -fvk-t-shift <shift> <space>\r\n Specify Vulkan binding number shift for t-type register\r\n -fvk-u-shift <shift> <space>\r\n Specify Vulkan binding number shift for u-type register\r\n -fvk-use-dx-layout Use DirectX memory layout for Vulkan resources\r\n -fvk-use-dx-position-w Reciprocate SV_Position.w after reading from stage input in PS to accommodate the difference between Vulkan and DirectX\r\n -fvk-use-gl-layout Use strict OpenGL std140/std430 memory layout for Vulkan resources\r\n -fvk-use-scalar-layout Use scalar memory layout for Vulkan resources\r\n -Oconfig=<value> Specify a comma-separated list of SPIRV-Tools passes to customize optimization configuration (see http://khr.io/hlsl2spirv#optimization)\r\n -spirv Generate SPIR-V code\r\n\r\nUtility Options:\r\n -dumpbin Load a binary file rather than compiling\r\n -extractrootsignature Extract root signature from shader bytecode (must be used with /Fo <file>)\r\n -getprivate <file> Save private data from shader blob\r\n -P <value> Preprocess to file (must be used alone)\r\n -Qembed_debug Embed PDB in shader container (must be used with /Zi)\r\n -Qstrip_debug Strip debug information from 4_0+ shader bytecode (must be used with /Fo <file>)\r\n -Qstrip_priv Strip private data from shader bytecode (must be used with /Fo <file>)\r\n -Qstrip_reflect Strip reflection data from shader bytecode (must be used with /Fo <file>)\r\n -Qstrip_rootsignature Strip root signature data from shader bytecode (must be used with /Fo <file>)\r\n -setprivate <file> Private data to add to compiled shader blob\r\n -setrootsignature <file>\r\n Attach root signature to shader bytecode\r\n -verifyrootsignature <file>\r\n Verify shader bytecode with root signature\r\n\r\n", "error": "dxc failed : Target profile argument is missing\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\dxc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dxcapsviewer.exe-93CC3C02D2F5B3F104E3C86DD39FC694": { "file_name": "dxcapsviewer.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\dxcapsviewer.exe", "hash_md5": "93CC3C02D2F5B3F104E3C86DD39FC694", "hash_sha1": "7E06C5B6DC6A0A03BF9F843883146EDB5CF65E75", "hash_sha256": "BFD898CD44361C174B5BC05D73B90D2E61594CD1662782AE001D8D31400848FE", "hash_sha384": "26F0BC16C0D0E5771F69359CDB23F84F267F96792FB3379A65EA1951360A4B024B3B00D4B8524E12D8499268874B0E9B", "hash_sha512": "4FFC5C3F1D3FD626C8585C1311507F99D311954818E76DC30413E4791B04A97CDC88C8E3352F6443B16C11212E5DF5A2074DE7FFD7D4EBE3B752110E6ADEAE59", "hash_ssdeep": "3072:tjDKGH0QNGdQcD7hu569/oonG1DDsW2P6GIGRyeHx:tj9H0T+cGi1BPf", "hash_imp": "1A6139BCA24492EE5163FFE299AAA6F6", "hash_pesha1": "3A549BD91364F0F349DB66E8BCD0330A26B531CD", "hash_pe256": "2FAD4CB16581D0ECD6AF9CB5977162DE4657195B3DC8D197850E9A2CE1CB6630", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) DirectX Caps Viewer", "meta_original_filename": "dxcapsviewer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/bfd898cd44361c174b5bc05d73b90d2e61594cd1662782ae001d8d31400848fe/detection", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\dxcapsviewer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\SYSTEM32\\DDRAW.dll", "C:\\Windows\\SYSTEM32\\d3d9.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\dxgi.dll", "C:\\Windows\\SYSTEM32\\dwmapi.dll", "C:\\Windows\\SYSTEM32\\DCIMAN32.dll", "C:\\Windows\\SYSTEM32\\windows.storage.dll" ] }, "espexe.exe-E12EF8D3AA1DC8E8286C5CB67EC11B3C": { "file_name": "espexe.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\espexe.exe", "hash_md5": "E12EF8D3AA1DC8E8286C5CB67EC11B3C", "hash_sha1": "3EBB3CCA9BD51AB8D62F25CCD4DD2A79E2C85702", "hash_sha256": "8927C3D8D6E8C6CB3A0B3361BBE10E0C321432B12A71BBB3B349217CE3A464C8", "hash_sha384": "E03CED53DEFE42961A9ED9FA1B553EC834F4BF8F1981A5B3B9EFF1FC4C5E22FC2941FDF58E75A658347BA9859AC030C4", "hash_sha512": "B8C039B0FD51EF68AF13C4E82041C224B5974C74F8C4BAA5AAC66F7778DB69F3BCCC4375509806A85FD2C2A2E7C5492C4F07906B8876EA2A6CA6D6EEE3EF0ADB", "hash_ssdeep": "768:TnGs2mWJqrwFBaCJTnfBX3Zp/NojQriyzjHLCjE2WM2/nsG:TnGsvWJOIaCDppF8eLCgnMUsG", "hash_imp": "B91D743C6E376F713B4FAA57CF04F85D", "hash_pesha1": "ADFE4BF29143E267CC4DEA4D16E00615CD9DFEE3", "hash_pe256": "25553397C07FCF87C3E3DA2D2A8DD9A99A86651080299C6EA20DB35157EC51E1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) Economical Service Provider Application", "meta_original_filename": "ESPEXE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright Microsoft Corporation 1995. All Rights Reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\espexe.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "runtime_window_title": "ESP: The Economical Service Provider" }, "extidgen.exe-B25B6ADF3A8F3BC2D749269C8DBF8147": { "file_name": "extidgen.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\extidgen.exe", "hash_md5": "B25B6ADF3A8F3BC2D749269C8DBF8147", "hash_sha1": "4F544238CDF617DF366C2C69B7AD952EF6CF0D89", "hash_sha256": "01875C17F96C18A027B83A914034B2D8A2A1EF91A700C21C7D4CADF883EA9D4D", "hash_sha384": "05D8F0F4C3FBDF6361B0B64EB8EC3426CB4AA4AC90C24DB3B89E9129668D8B32FD68A51D0A260660C5D1DBE20C6B7A1B", "hash_sha512": "BF60D722B6EE53452C4ACBA51C754C0A006A259E176DC6FA84533B67E53F714451704692781F627607CA4F1AE47BDA995DDDDAEC2F421567F0FAA3026DC461A7", "hash_ssdeep": "192:V//mVPyosTffU6SBTLJZlzGdzUP+K4G5FvWKWSawTyihVWQ4eWq3YAkwqnaj0jkW:F/mwX3I3Dlzr74OWXwGy6qlIl", "hash_imp": "A3E58D235BA367E17876D5F8ED0F3B4F", "hash_pesha1": "3C7EADE47D42BCD08503CE8AC78983ADE4FDF287", "hash_pe256": "957B60729A1A8E8C2B502C58FC57E3FF1AEB8B5010B2A16F28466BAB4B1F16DC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extension ID Generator", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All Rights Reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nMicrosoft Extension ID Generator v1.1\r\nCopyright 1993-2004 Microsoft Corporation. All Rights Reserved.\r\nA component of the Windows Telephony Software Development Kit.\r\n\r\nUsage: EXTIDGEN\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\extidgen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "filetypeverifier.exe-FD12E08F0ADD76B52C3ED4FEAA51619A": { "file_name": "filetypeverifier.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\filetypeverifier.exe", "hash_md5": "FD12E08F0ADD76B52C3ED4FEAA51619A", "hash_sha1": "E5F132C67768E51D4A05EA538B30EC24BCA837B3", "hash_sha256": "336D00C06C7418D4706E10FDB848CBA07C72C43B31D72603876E87DE7013EBB2", "hash_sha384": "3228D7AC58646F66D44DC4A168210C129FA346F21A9CEB93A4CAC3274BFE1B0E8FD4BF3EB239A929159BB72BFFFA1F05", "hash_sha512": "62890751ED1069B1FC4C22719704A4D1317975BFF026B2BD9E40E274CC4C6B7CA69E348F85A1B0847875776E151D36703B50AFB37484968B807438503AE9B866", "hash_ssdeep": "6144:WEqLZN1jhT2p2Di6uVLx0AmcPdYmdpoBIUj:MtN1jUJt0AmV", "hash_imp": "8008F2B23EAC3D47913A3B99D84AC902", "hash_pesha1": "17C2FD0831D80E866C594F4DF130BB1C9C9BDE96", "hash_pe256": "E41933172408A306C2001BB1E06A6AB0671642E11AF4A8822A05DF8C546234D8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Type Verifier", "meta_original_filename": "FileTypeVerifier.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\filetypeverifier.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ], "runtime_window_title": "File Type Verifier" }, "filtdump.exe-FFDB05023013C4EA4D9AD30F45DB03A9": { "file_name": "filtdump.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\filtdump.exe", "hash_md5": "FFDB05023013C4EA4D9AD30F45DB03A9", "hash_sha1": "0C87855CC725EB682C67BF64C2D1BFDEB4B7FDDF", "hash_sha256": "4C2ECDE2C1B156F90DDA0C3E0790B9F8E878DDE5C9B12201B60F875266C91395", "hash_sha384": "3F0066DCDF1BE12CFAE92AB2F63A12E446266ED05F967095729656ACDCB17C33B6D74A08B9244B4734FF3722F5BEA6A6", "hash_sha512": "7619171DC020CB587A87EFC1392852F6BD7112CC5B13CAE3477CDCB3D77D8E559AC007FFBEA5ADBDD4CABC12893BDA28564C3C1CCC0A0C6769ED5193F846BB00", "hash_ssdeep": "768:1+Ky6A4MM/vHH3a0pa/BM3q508QYeFc5SKKZFVk87WP:/MQ3aYa/BM3q508QYeFc5SKKZl7W", "hash_imp": "2DE5CBD9B510C5463B0B62EE2B2CA206", "hash_pesha1": "BB2E62B98478F1A68A173E9A35EADE6BFDFF5491", "hash_pe256": "ED36091F14A909989A84F3278A24BAA3F8FCD1FB39972B7C14B9A789B4D4E324", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Filter dump utility", "meta_original_filename": "filtdump.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "FILE: help\nIFILTER: LoadIFilter failed, hr == 0x80070006\nIFILTER: SHCreateStreamOnFileEx failed, hr == 0x80070006\nLoadIFilterWrapper failed, hr == 0x80070006\nFILTDUMP failed, hr == 0x80070006\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\filtdump.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "filtreg.exe-BF946D79EEEBC25025F6D820D2B4E647": { "file_name": "filtreg.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\filtreg.exe", "hash_md5": "BF946D79EEEBC25025F6D820D2B4E647", "hash_sha1": "298677A9657B2E875239B0050BC50B3B836938D5", "hash_sha256": "F0F9DDD62DC5059F7D276F7D6C53A3C4C95B58F739AC6220CE9A4796B89718FF", "hash_sha384": "BCC42A539D352FAD3F23F5A7129D96A5E7C17E3AED187E165C2240DC336EFA1568507990AB7C32666ABA208EF9B6391E", "hash_sha512": "FBAED74F851AAA4706B7F5D65A5A7468B96D71C152420590AC1670837A3B1FF364B178559B0CB55D32C8776D25323D02EF3832DAB2F2AAC4A3C8BDEF4B008614", "hash_ssdeep": "192:2gDxWvMeqftib1RkJn1M7EtZDSqyBz/a6S13Gy5LIWwyW:jKqfti5RKnLZuqrh13+WwyW", "hash_imp": "EBA37C722604402F437253AB7EB9B9AC", "hash_pesha1": "5CC7CE743113C463C741B6435A0610DFCD118ADE", "hash_pe256": "6B09D7587A93B9061B0F4022D2E8493B96BB2251914334017D222A5C2753F743", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\filtreg.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Filter registration dump utility", "meta_original_filename": "filtreg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f0f9ddd62dc5059f7d276f7d6c53a3c4c95b58f739ac6220ce9a4796b89718ff/detection", "output": "Usage: filtreg [dstExt] [srcExt]\r\n Displays IFilter registrations. If [dstExt] and [srcExt]\r\n are specified then [dstExt] is registered to act like [srcExt].\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\filtreg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ftquery.exe-273E8ED979456C62A201CCF5DBED7281": { "file_name": "ftquery.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\ftquery.exe", "hash_md5": "273E8ED979456C62A201CCF5DBED7281", "hash_sha1": "310CA403AAE7B577363E618C003D0141045F83AA", "hash_sha256": "0413E0463C98C67A7E59A71A84EAF7BCBAF00DDB316008E8680D130CAB0F4311", "hash_sha384": "77962204C04DE790CF921EA1AF8E9FD7DD85DC622142032CB8A88432BF09F20C2761707BA9621BE6784D83D771B1003E", "hash_sha512": "FDC1950B0664B325EC15AD10C7D57D473F104910EAE690BDC9C81F099F562060E491B035509DE9BED29BBEEF2D3618B4DEF44F4A581D25A13094325DB95A12CD", "hash_ssdeep": "768:D2Aq/znu2gyGKFc0F+WEaVhfZsgZoF5ZwM6rs4KZWOUJ4x:SAcqaFc0FuaBnoF5ZwhrsrZ4", "hash_imp": "n/a", "hash_pesha1": "6A59830AFBA22CA3061B4225C8D694BA700F9DD3", "hash_pe256": "8720D391FB60A7B8F0C6ACC8192108C7684648BB95348662136F41A8119B23FC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "ftquery.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "ftquery.exe <SQL query> | <Query file> [Options]\r\n\n<SQL query> \r\n Example1: \"SELECT path from systemindex\"\r\n Example2: \"SELECT path from mymachine.systemindex where scope='file://mymachine/mysard/foo'\"\r\n Example3: \"SELECT path from mymachine.systemindex where scope='@PATH@'\"\n\t\t(where %PATH% is an environment variable.\n\t\t Note the @'s surrounding the environment variable name.)\r\n\n<Query File> Format per query (repeat for each query):\r\n --TSQLQuery=<Query description> [Any options]\r\n <SQL>\r\n\nAll options can either be on the command line or per query unless otherwise noted.\r\n\n/Bare\r\n Suppress all output except the actual query results.\r\n\n/Binary:<path>\r\n The remote binary path for accessing ftquery.exe on a remote machine when doing /purge for a remote query.\r\n By default this is just ftquery.exe so if it is on a local path of the remote machine it will work.\r\n\n/Busy\r\n Wait for indexer to be busy before executing query and measuring performance.\r\n Normally /Perf will wait for idle.\r\n\n/Cold\r\n Restart the indexer for a cold query if you are an administrator.\r\n On the command line will reset once before all queries.\r\n On an individual query in a file will reset the query. (Not compatible with /thread.)\r\n This will also work on remote machines if you are an administrator on the remote machine and ftquery.exe is available on the remote machine.\r\n\n/Close:<label>[,<label>]\r\n Before executing this query, previous queries with the label will be closed.\r\n Cannot be specified on the command line.\r\n\n/Delay:<miliseconds>\r\n Delay before each query execution. Default value is 0\r\n\n/Depth:<number>\r\n Recursion depth when expanding hierarchical rowsets for GROUP ON queries.\r\n 0 = stop at first top level rowset, 1 = stop at second level, etc.\r\n By default all results are expanded.\r\n\n/Excel:<file>\r\n Dump out an excel friendly summary at end or into file if present.\r\n\n/Expensive\r\n By default expensive properties are not computed.\r\n This sets DBPROP_DONOTCOMPUTEEXPENSIVEPROPERTIES=false and adds these rowset properties:\r\n ResultsFound -- the total number of items that match the where clause.\r\n MaxRank -- the maximum rank of any item that matches the where clause.\r\n\n/FirstPage:<n>\r\n The time to get the first page of results is measured. Default is 60.\r\n\n/Impersonate:{domain\\}user!password\r\n This will impersonate the user for the duration of the query. Domain defaults to redmond.\r\n\n/Iterations:<number>\r\n Number of iterations for <SQL query> | <Query file> execution. Cannot be specified per query in a query file.\r\n Default value is one iteration.\r\n\n/Open:<label>\r\n Keep rowset open after query so the query can be reused by putting ReuseWhere($<label>) into the query.\r\n Cannot be specified on the command line.\r\n\n/Output:<filename>\r\n Direct output to filename.\r\n\n/Page:<n>\r\n Maximum number of rows to fetch at a time. Default is 60.\r\n\n/Perf\r\n Measure query performance. No query results are displayed. Implies /Stats.\r\n\n/Purge\r\n Purge standby lists on the machine being queried.\r\n This is automatically called when using /cold with a remote query.\r\n\n/Rows:<n>\r\n Only fetch this many rows from the top rowset. By default all rows will be fetched.\r\n\n/Share:<\\\\machine\\share{\\path..}>\r\n This will take any query for the local machine and transform it to be over the remote share.\r\n FROM SystemIndex -> FROM \"<machine>\".SystemIndex and the WHERE clause adds a restriction for the share.\r\n\n/Stats\r\n Display all of the stats generated by /Perf together with results.\r\n\n/Thread:<id>\r\n All queries with the same ID will be executed sequentially, but different ID's will be executed in parallel.\r\n Each iteration will wait until all threads are finished.\r\n\n/Timeout:<number>\r\n Timeout for the query in seconds. Default is 0 which means no timeout.\r\n\nPer-Query Output. Sections in {} are only present if /Stats or /Perf\r\n Description=<description if any>\r\n WhereID Label=<label if any>\r\n Query=\r\n <actual query>\r\n <Non-default parameter settings>\r\n {<Perf counters>\r\n Items = Number of URLS in history\r\n Terms = Number of unique terms in inverted index\r\n Inverted Index = Size of inverted index\r\n In-memory Worlists = number of word lists\r\n Persistent Indices = total L1/L2/L3/L4\r\n Flushes = number of currently executing flushes if non-zero\r\n Merges = MasterMerges L1/L2/L3/L4 ongoing merges if non-zero\r\n Crawls in progress = number of crawls in progress if non-zero\r\n Documents in progress = number of documents in word lists if non-zero\r\n Iterating History\r\n Recovery in progress\r\n }\r\n <Column names if not /Perf>\r\n <Rows if not /Perf>\r\n Expanded Rows=<number of expanded rows>[, Children=<total number of children rows>]\r\n {<Server Version Information>\r\n Server=<server version>\r\n WinVer=<server windows major>.<server windows minor>\r\n NLS=<NLS version>.<NLS Defined Version>\r\n WhereID=<where ID for query>\r\n }\r\n {<Timing information>\r\n Execute=<time to parse query and send to server>\r\n Properties=<time to get rowset properties>\r\n Avg Rows/Page=[average number of rows retrieved per page for top-level rowset]\r\n 1st Row=[time from execute to very first row]\r\n <FirstPage>th Row=[time from execute to <FirstPage> rows]\r\n All Rows=[time from execute to get all rows]\r\n }\r\n\nSummary Output for Iterations > 1:\r\n Execute [min avg max] -- stats for execution time\r\n Properties [min avg max] -- stats for property retrieval time\r\n 1st Row [min avg max] -- stats for 1st row time\r\n <FirstPage>th Row [min avg max] -- stats for first page of rows time\r\n All Rows [min avg max] -- stats for getting all rows\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\ftquery.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "fxc.exe-1AC5E88D6C1E4A9E40CC4915244E44F5": { "file_name": "fxc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\fxc.exe", "hash_md5": "1AC5E88D6C1E4A9E40CC4915244E44F5", "hash_sha1": "372FC943325FED85B6FEE180BE5C51B3C65EC51D", "hash_sha256": "8CAECB6664EB715387CAD72FD1571419A44F596FE7DDEE0D9B1173AE947074AC", "hash_sha384": "87441F25B28A6791FDB2DAEE32FDB5042808B6C67DB3C01D0E65F6226F22CF92863EF5D72650EF484B821E5C8035560A", "hash_sha512": "D1C6479B33D7C54D8EE96A8F98DF6C63FF86E006540BE4CBB349E5B8A869035154DD452892FBDA4E3745A898F9050BDF753A48EC0D9175E5C270FDBEF98A7600", "hash_ssdeep": "3072:bhWqqWn2yhdrNuNVcyI2raTgJH4PppxqUrOUa+iR2PjXr:bhWqqWn2UdrNuNVcyaTgJapt6dxMPf", "hash_imp": "286B7A74BCE52FC2963DE05C923E40B1", "hash_pesha1": "48B612FA8C7A3B8D2C141B73CD32144B914D1A96", "hash_pe256": "61AA908863F9A14205F5FA7439D9BF79399F5450971C089354461982B01BCD11", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "fxc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8caecb6664eb715387cad72fd1571419a44f596fe7ddee0d9b1173ae947074ac/detection", "output": "Microsoft (R) Direct3D Shader Compiler 10.1\r\nCopyright (C) 2013 Microsoft. All rights reserved.\r\n\r\nUsage: fxc <options> <files>\r\n\r\n /?, /help print this message\r\n\r\n /T <profile> target profile\r\n /E <name> entrypoint name\r\n /I <include> additional include path\r\n /Vi display details about the include process\r\n\r\n /Od disable optimizations\r\n /Op disable preshaders\r\n /O{0,1,2,3} optimization level 0..3. 1 is default\r\n /WX treat warnings as errors\r\n /Vd disable validation\r\n /Zi enable debugging information\r\n /Zss debug name with source information\r\n /Zsb debug name with only binary information\r\n /Zpr pack matrices in row-major order\r\n /Zpc pack matrices in column-major order\r\n\r\n /Gpp force partial precision\r\n /Gfa avoid flow control constructs\r\n /Gfp prefer flow control constructs\r\n /Gdp disable effect performance mode\r\n /Ges enable strict mode\r\n /Gec enable backwards compatibility mode\r\n /Gis force IEEE strictness\r\n /Gch compile as a child effect for FX 4.x targets\r\n\r\n /Fo <file> output object file\r\n /Fl <file> output a library\r\n /Fc <file> output assembly code listing file\r\n /Fx <file> output assembly code and hex listing file\r\n /Fh <file> output header file containing object code\r\n /Fe <file> output warnings and errors to a specific file\r\n /Fd <file> extract shader PDB and write to given file\r\n /Vn <name> use <name> as variable name in header file\r\n /Cc output color coded assembly listings\r\n /Ni output instruction numbers in assembly listings\r\n /No output instruction byte offset in assembly listings\r\n /Lx output hexadecimal literals\r\n\r\n /P <file> preprocess to file (must be used alone)\r\n\r\n @<file> options response file\r\n /dumpbin load a binary file rather than compiling\r\n /Qstrip_reflect strip reflection data from 4_0+ shader bytecode\r\n /Qstrip_debug strip debug information from 4_0+ shader bytecode\r\n /Qstrip_priv strip private data from 4_0+ shader bytecode\r\n /Qstrip_rootsignature strip root signature from shader bytecode\r\n\r\n /setrootsignature <file> attach root signature to shader bytecode\r\n /extractrootsignature <file> extract root signature from shader bytecode\r\n /verifyrootsignature <file> verify shader bytecode against root signature\r\n\r\n /compress compress DX10 shader bytecode from files\r\n /decompress decompress bytecode from first file, output files should\r\n be listed in the order they were in during compression\r\n \r\n /shtemplate <file> template shader file for merging/matching resources\r\n /mergeUAVs merge UAV slots of template shader and current shader\r\n /matchUAVs match template shader UAV slots in current shader\r\n /res_may_alias assume that UAVs/SRVs may alias for cs_5_0+\r\n /enable_unbounded_descriptor_tables enables unbounded descriptor tables\r\n /all_resources_bound enable aggressive flattening in SM5.1+\r\n\r\n /setprivate <file> private data to add to compiled shader blob\r\n /getprivate <file> save private data from shader blob\r\n /force_rootsig_ver <profile> force root signature version (rootsig_1_1 if omitted)\r\n\r\n /D <id>=<text> define macro\r\n /nologo suppress copyright message\r\n\r\n <profile>: cs_4_0 cs_4_1 cs_5_0 cs_5_1 ds_5_0 ds_5_1 gs_4_0 gs_4_1 gs_5_0 \r\n gs_5_1 hs_5_0 hs_5_1 lib_4_0 lib_4_1 lib_4_0_level_9_1 \r\n lib_4_0_level_9_1_vs_only lib_4_0_level_9_1_ps_only lib_4_0_level_9_3 \r\n lib_4_0_level_9_3_vs_only lib_4_0_level_9_3_ps_only lib_5_0 ps_2_0 \r\n ps_2_a ps_2_b ps_2_sw ps_3_0 ps_3_sw ps_4_0 ps_4_0_level_9_1 \r\n ps_4_0_level_9_3 ps_4_0_level_9_0 ps_4_1 ps_5_0 ps_5_1 rootsig_1_0 \r\n rootsig_1_1 tx_1_0 vs_1_1 vs_2_0 vs_2_a vs_2_sw vs_3_0 vs_3_sw vs_4_0 \r\n vs_4_0_level_9_1 vs_4_0_level_9_3 vs_4_0_level_9_0 vs_4_1 vs_5_0 vs_5_1 \r\n", "error": "C:\\Users\\user\\help(1,1-4): error X3000: unrecognized identifier 'DXGI'\r\n\r\ncompilation failed; no code produced\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\fxc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "gamesaveutil.exe-74F4E779A52A9E9E59B6F85CDC86418C": { "file_name": "gamesaveutil.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\gamesaveutil.exe", "hash_md5": "74F4E779A52A9E9E59B6F85CDC86418C", "hash_sha1": "B5984AD4733B9AAC50884F9EA8077D181FD222C2", "hash_sha256": "F0FFAEA7CCC293FE9A6CB9C298E0B0BE1893EA20DEF32FF511161BDF2727E902", "hash_sha384": "6E214465D879E47FC0F920A16313BB750BA3A15A7CAA0D3A408D6977436993E0BF641E0B0E8794E5E61CDD2CC0C818B3", "hash_sha512": "2F04AC3C96326465F113DAF2595CE057F45F18522B1B6AFDC7D6DA8987178C00F8501919055DD878FB88D52D6C3D56CF4BCFA2FF1296A4F50E02BFC62A8D38BF", "hash_ssdeep": "6144:fmGzTG6KUgH8Ipx4dl49WcQ6ld1egDpysmdpWlzfGlMewQEiIqBYaXEf83V7Kw4B:+GzTG6IHr4kQgpj6w3xqV1NDG7", "hash_imp": "E3AF3D69733A79B41C2A91E430BF90F2", "hash_pesha1": "4F25F33D9437D0959BE4B55BEFAA144E658E655B", "hash_pe256": "94BC26505108948FFE0D45B3EF7B0765B4914BB3714C097302AF1901648177D9", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\gamesaveutil.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "gamesaveutil", "meta_original_filename": "gamesaveutil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f0ffaea7ccc293fe9a6cb9c298e0b0be1893ea20def32ff511161bdf2727e902/detection", "output": "\r\ngamesaveutil - Manage Xbox Live game save storage on a device.\r\n\r\nBuild 10.0.10011.16384\r\n\r\nThe general format of the command line is:\r\n gamesaveutil [command-independent-options] <command> [options]\r\n\r\nFor more detailed help on specific topics, try the following:\r\n gamesaveutil help commands for a list of all commands\r\n gamesaveutil help <command> for help on a specific command\r\n gamesaveutil help options for help on command independent options\r\n\r\n\r\nE102: No command specified.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\gamesaveutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "genmanifest.exe-1AFEA5981AB823E22E0ADF877DE333F1": { "file_name": "genmanifest.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\genmanifest.exe", "hash_md5": "1AFEA5981AB823E22E0ADF877DE333F1", "hash_sha1": "9F37DCEEB7AC4E02A8BE175C7C313DA7D56F980E", "hash_sha256": "9AE9B695F90DCFE9B395F2E0FBC68774786C6BC9DCFD104D0D1C0C3684D5EF61", "hash_sha384": "26BFB9ABD1F4F4EA955E3AA899A010D1E368761FC6A9F699B76D92EB4FAE43EF7BAE407F33A32BAEAAE2CBA685AED7D3", "hash_sha512": "1AF3EB105593F640958F0426B02D963D602BEEAFBE9AA8E533DA6F062B3C121A225CDB5E69CEA70C964E6322911D5F8998ABD65D1CF0C1FC1F6C9ECD57EFD85C", "hash_ssdeep": "3072:QvKY2jfYDS7uFZ6ILkXuvI38bQ8/Mc8gcjnBLk70HcLvJeU:QvKY2jWOuFZ88reeBB", "hash_imp": "AA7E0AB1E3BAA97E27095C92346FC7D4", "hash_pesha1": "1F2F136E83863016FD2853F73C84967D04344E15", "hash_pe256": "450F3F534F3B69428C614CB0426E406DB3BA5A8EDE0F8E8869FF37371713B86B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Managment manifest generator", "meta_original_filename": "genmanifest.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Usage:\r\n genmanifest [-chain <source chain path>] <source MCF path> <destination XML path>\r\n\nExample: genmanifest manifestconfig.mcf c:\\manifest.xml\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\genmanifest.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "graphedt.exe-6A0185B6588A3807C0D3A369DDDF1394": { "file_name": "graphedt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\graphedt.exe", "hash_md5": "6A0185B6588A3807C0D3A369DDDF1394", "hash_sha1": "336F8B3EBA26B5234B06B850E355A9F562A10647", "hash_sha256": "24723610623787DC56CE1D12C1645FFE8488DBDE62DB47E4570790DBE57AFD1B", "hash_sha384": "E28C030646269361CE51081BFC7863C8B71CEA7E4C01447FAA8901E0854604D4C03D63BFDE092308571DAF784B22DFF8", "hash_sha512": "7343F56F0485C381070A98D8A59738D1569D74995C142F124200DEC109ED022038F4EA5EC69B8D541629B18CCA738BC8CBD96907F34EAF150016FED834878ED6", "hash_ssdeep": "6144:HM5A+zz34yiFHQJOqyFPPqyq/18CFAq+Zd:Hx+/ops3tX", "hash_imp": "4B8848F5857917CDF7A7D1F20D5049AC", "hash_pesha1": "CC9B32D4BB7C19228C1E392541666A517D539EE4", "hash_pe256": "BEC2D7EA886465ED395E7923EF6F77AE606847E859C826C56ADA9EBC903415B6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DirectShow SDK Filter Graph Editor", "meta_original_filename": "GraphEdt.exe", "meta_product_name": "DirectShow", "meta_comments": "DirectShow Graph Editor tool for software developers", "meta_company_name": "Microsoft Corporation", "meta_file_version": "DirectX 10.0", "meta_product_version": "DirectX 10.0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 1992-2006 Microsoft Corporation", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42.dll.mui": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\19a0HWNDInterface:5806c2": "Section", "\\Sessions\\1\\BaseNamedObjects\\AMResourceMapping3-0x09-0x000780": "Section", "(R-D) C:\\Windows\\System32\\en-US\\quartz.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\graphedt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "ifilttst.exe-55966155C02033E554E8634996173D76": { "file_name": "ifilttst.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\ifilttst.exe", "hash_md5": "55966155C02033E554E8634996173D76", "hash_sha1": "EE2A16D29C7F6B0C1390825C091A8C64AC4CC11F", "hash_sha256": "C42A1986082967157F511F5CC56818D83CF4F1E19F731D2E0C67A8003A9053DE", "hash_sha384": "AFA41206A430C59302F2CC49B08DBD5079D20A2A9DD0A699371D68CC03869FEC0468992DA262843E9B9B8661ECE42B96", "hash_sha512": "8A40445EF5A2665682E127141AA2EB414F156B0092B46F1F295FFFCFEC92E5C69D18C04A7B62A252B93073DA8038E3E316E9F4BAC1EB757F8AB6DC9FFE192D0E", "hash_ssdeep": "1536:RjjcibSuAtD30ntPT3IzU6cysInYhAiGCzaQy+Go+Jb6ba9aeL3XnVvAZeVqwiO/:Fchuc0ntPT3IzU6cj2tVXXlpPX", "hash_imp": "BF1D07799190ADC65BC0DE67CB6C0FD0", "hash_pesha1": "B74A57C3A36CB2E4A04A733A79CF9F6E4C889E04", "hash_pe256": "C71FBA6AFB75B3FC8FB5E549477A0E679575AA766EF1264849EC92A6AB5E2E3D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IFilter command line test tool", "meta_original_filename": "iFiltTst.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\r\nUSAGE:\r\r\nC:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\ifilttst.exe /i <input file>[...] [/ini <ini file>] [/l [<log file>]] [/d] [/-l] [/-d] [/legit] [/stress] [/v <verbosity>] [/t <threads>] [/r [<depth>]] [/c <loops>]\r\r\n\r\r\n\t<input file> is the file/directory/pattern to which to bind.\r\r\n\t\tWildcards are OK. More than one input file is OK.\r\r\n\t<ini file> is the initialization file to use. If none is\r\r\n\t\tspecified, it defaults to ifilttst.ini.\r\r\n\t[/l] enables logging to a file. By default, the log filename\r\r\n\t\tis the input file name with a .log extension. If you\r\r\n\t\tspecify a log file name, all the log messages will be sent\r\r\n\t\tto a single file.\r\r\n\t[/d] enables dumping to a file. The dump filename is the\r\r\n\t\tinput file name with a .dmp extension.\r\r\n\t[/-l] disables logging. This flag overrides /l.\r\r\n\t[/-d] disables dumping. This flag overrides /d.\r\r\n\t[/legit] forces the test to run only the Validation Test.\r\r\n\t\tThe Consistency and Invalid Input Tests are skipped.\r\r\n\t[/stress] forces the test to run in stress mode. This is the\r\r\n\t\t same as specifying /-l /-d /legit /v 0 /c 0\r\r\n\t<verbosity> is an integer representing the verbosity level\r\r\n\t\tAcceptable values are from 0 through 3, with 3 being the\r\r\n\t\tmost verbose. (default is 3)\r\r\n\t<threads> is an integer representing the number of threads\r\r\n\t\tto launch. Only useful if filtering multiple files.\r\r\n\t\t(default is 1)\r\r\n\t<depth> is an integer representing the depth to recurse.\r\r\n\t\tNo value or a value of 0 indicates full recursion. (default is 1)\r\r\n\t<loops> is an integer representing the number of times to\r\r\n\t\tloop. A value of 0 means loop infinetly. (default is 1)\r\r\nERROR: An input file must be specified\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\ifilttst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "inspect.exe-6F5AEEA6E52F989AB14616FE0BC9D668": { "file_name": "inspect.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\inspect.exe", "hash_md5": "6F5AEEA6E52F989AB14616FE0BC9D668", "hash_sha1": "638792706FCF3C2E57340EAAD63CF2FD94D5930F", "hash_sha256": "ED318C1025044DF2DF14CD15C74C881B7298AE7A35C8F3750560C0BC6BA6C91B", "hash_sha384": "A820F1893C204A4795BB30D34DBAD7D512307B2B6A835B0D95D082FCE37D44A7092AE4949C79CDB552A46D8295ABAA5A", "hash_sha512": "6BD7C50416CA5E7611AD75DA814EC9562C4584DAB726FD3AF4EA07267B81DBE83A92916C975FEF5508CBFEE3B21392E0B8DBCF81170ECF40A77A6D5E29D72A36", "hash_ssdeep": "6144:jMnMskCWLUt2JyPe0/YRsO3UMKYMKI6UFj94:onMskCWjJyPe0/KsO3/m5Z94", "hash_imp": "23D8604B0919BB8B4C1AB9B1DD29F0AB", "hash_pesha1": "906CF9963B091312CFBF92919AD71523C92BDFED", "hash_pe256": "8844199F8235AC305E018405E90C485F351105584982F3B7692974FBD554E986", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Inspect Object (64-bit UNICODE Release)", "meta_original_filename": "INSPECT.EXE", "meta_product_name": "Microsoft Active Accessibility", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.0.0", "meta_product_version": "7.2.0.0", "meta_language": "English (United States)", "meta_legal_copyright": " 2012 Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\System32": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\UIAutomationCore.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\inspect.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll" ], "runtime_window_title": "Inspect (HWND: 0x003B0858)" }, "isxps.exe-48B4F83B356B12C2FCA2EEB394B4B1AC": { "file_name": "isxps.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\isxps.exe", "hash_md5": "48B4F83B356B12C2FCA2EEB394B4B1AC", "hash_sha1": "58A792C0DF74F7C5C8CDDCCA9F691A10D20DC826", "hash_sha256": "23A4C90D11048C5C8B11A980DF7DB44B5A3B62377E97650B045ACA7E8E57D3CA", "hash_sha384": "4F52862EF923D3245CFD9C8167A45BA436C74D1514D2D2DAE3CF4155B2BBB168AA83A52FBCA83A641C0C899251E4A43F", "hash_sha512": "ED4BA91C2F99B16AB23EC4FAD379AFEFE9A89DFB94CC5AE403DC196174F7E83290C82D309B5705CA82288C6669E9EF070CEB15043792A70B22D4F3EC310B34FF", "hash_ssdeep": "3072:xYhy2j14ml3I2LDZm1bRxH2gVMnayzmXtMqRnf1UEDiMvTCfrqUoIg04YUf/oK0t:ey4ScLZIxH2gGanTf1", "hash_imp": "n/a", "hash_pesha1": "EC260A0D7DA6108BE981F0124EFFAEB4953B6E0A", "hash_pe256": "BF3A7C9F36D5FF633BE144C6222895DE442C9E18D4D2A58B715D6CEE0DACF243", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "IsXps.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Filename is required, but was not specified\r\nisXPS v2.0\r\nCopyright (c) 2009 Microsoft Corporation. All rights reserved.\n\r\nUsage---------------------------------------------\r\nisXPS.exe -t=<XPS | OXPS> -f=<FilePattern> [OptionalSwitches]\r\ne.g. isXPS.exe -t=XPS -f=SomeFile.xps -logger:File\r\ne.g. isXPS.exe -t=OXPS -f=*.oxps /s -logger:File\r\nMost Used Switches:\r\n -t=<XPS | OXPS>\n\t\t: Validate against XPS or OpenXPS. The default value is XPS.\r\n -f=<FilePath>\t: The file to perform the validation on.\r\n /s\t\t: Apply pattern to all subdirectories\r\n -logger:<LoggerType>\n\t\t: The logger to use (File, Console, WTT).\r\n \t\t the default logger is \"CONSOLE\".\r\n -logfile:<LogFile>\n\t\t: The log file to write to when using the File logger.\r\n \t\t the default log file is \"isXPSLog.txt\".\r\n /?\t\t: Display this help\r\nXsd Switches (optional for custom XSDs):\r\n -x:<S0Xsd>\t: The path to the S0 xsd\r\n -r:<RSCXsd>\t: The path to the Resource dictionary key xsd\r\n -doc:<DOCXsd>\t: The path to the Document Structure xsd\r\nAdvanced Switches:\r\n -logprefix:<Prefix>\n\t\t: specifies the prefix to append to log files from this run.\r\n \t\t Setting this will enable log file splitting output (for large runs)\r\n \t\t With log file splitting (File logger only), the setup will be output\r\n \t\t to the specified log file while the actual test results will be stored\r\n \t\t in the log file \"prefix_#to#.log files\"\r\n -logsplit:<Number>\n\t\t: How often should isXPS split the log file (Default: 0)\r\n \t\t Setting this will enable log file splitting output (for large runs)\r\n -BadDir=<Quarantine path>\t: Copy invalid packages to this directory.\r\n /DelBad\t: Delete invalid packages.\r\n /OnlyLogFailures\t: Log failures only to create small log files.\r\n /OnlyOPC\t: Only validate against the OPC specification. This will only work with ZIP-based OPC packages\r\n /SkipResParts\t: Don't validate resource parts content.\r\n /NoInterleave\t: Turn off interleaving validation.\r\n /NoPTConform\t: Turn off PTConform (Advanced PrintTicket validation).\r\n /DisallowForeignParts\t: Generate an error on non-XPS parts.\r\n -device:<DeviceString>\n\t\t: The device string to use with the WTT logger.\r\n \t\t: the default device is \"$LogFile:file=isXPSLog.wtl,WriteMode=append\".\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\isxps.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "jsconstraintdebug.exe-3F6DF9194FA2180B5548FA598F1A24F9": { "file_name": "jsconstraintdebug.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\jsconstraintdebug.exe", "hash_md5": "3F6DF9194FA2180B5548FA598F1A24F9", "hash_sha1": "DEF3B3D30C82031CBA2736A9C0348D7C96174571", "hash_sha256": "015D28A5FF13F1C55A8906E962524F41F38BABC27B00D35C42120157A4AE235A", "hash_sha384": "0450590FA47881D5D713A0598D512055ACC4CCE45A7B1EA2AA9FAFA92A356C3EACF1DD59F75F2E9D44532F66304FC62E", "hash_sha512": "A342BFFEFD944D69CACF1437E38D1E1F5BDE169ADFF4C3FD29637AD0BE9AC6F3B0FC492092360422085FCB3C5D2BDE702369720F64E33980693483C5266FCEE6", "hash_ssdeep": "1536:HHuul8o9iz2jwFAoh5NXlU9yF5LVCT0/dKgwj8:58Y3jwFAoh31YyF5Lq0/ojj8", "hash_imp": "2605D1053D66F712DCFAD974C3BD94F7", "hash_pesha1": "A026A5CD23A93D47523139AD814B8F5A92D6516E", "hash_pe256": "D654EC4D972E40B07B85744FC52988D7D812DA2339FE0CA5B6E0E2553337A2A2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "JS Print Constraint Debug Tool", "meta_original_filename": "JSPrintConstraintDebug.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\n\r\n Usage: JSPrintContstraintDebug.exe <PrinterName> <PrintTicket1.xml>[<PrintTicket2.xml>][<JsFile.js>]\r\n\r\n PrinterName : Printer name which contains driver JS files to be debugged.\r\n\r\n PrintTicket1.xml : Path to Print Ticket XML file which will be passed to\r\n JavaScript Print Ticket APIs.\r\n\r\n PrintTicket2.xml : Path to optional second Print Ticket XML file which will\r\n be passed to Merge and Validate API.\r\n\r\n If PrintTicket2.xml is not set the default DevMode will\r\n be converted to a Print Ticket and will be passed to\r\n the Merge and Validate API.\r\n\r\n JsFile.js : Path to optional replacement JavaScript constraints\r\n source file\r\n\r\n If the optional JsFile.js parameter is set, the passed\r\n file replaces the JS file in the target print driver\r\n before debugging.\r\n\r\n NOTE : This tool assumes that user has installed the printer previously, and the\r\n machine has Visual Studio debugger installed.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\jsconstraintdebug.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "makeappx.exe-3EBB0D98BC449501E774EA8D6DE17DC9": { "file_name": "makeappx.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\makeappx.exe", "hash_md5": "3EBB0D98BC449501E774EA8D6DE17DC9", "hash_sha1": "EB8BE2EB534A40E8CFED421182CF58ABBCF788F0", "hash_sha256": "75C36E3B3A7D9AC28779CA74FA182BFDAB7BACF9FA6D2772CD83F568F62DBF29", "hash_sha384": "4B94B575DADD9E964431B9C7937AC50C539B5DD1B437CD8551A7879D1F93E9D061BDAFE236EB4248F873CED90FCAE5FD", "hash_sha512": "EC5E6ED880EC2181F622BB6A43EE09C2B17F290EE205E67B4BBD55A400AAC10FD90F9FEF62C48B9AF4B93FB4B9524B61D606E8CBE7BE2121D87ACF02CEE87B48", "hash_ssdeep": "6144:ZkmesnB7+XS5eBS61ww0JsF423uCEHOQk+ZhGpmjF/EGPLi+txvmcj/5NbAzawfe:S47+XS8BLiCFnEkiu6FDTtx15NeaD5Aq", "hash_imp": "C031FA4774700754D25FB610D9D04D26", "hash_pesha1": "2B2B0774394815685E817662F77A5123F8EC6A9B", "hash_pe256": "76AA1BA3794F97391391390A3950C6FE65AC0CBAECA8B00CCB90506CE340023D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command line tool for creating Appx packages", "meta_original_filename": "MakeAppx.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/75c36e3b3a7d9ac28779ca74fa182bfdab7bacf9fa6d2772cd83f568f62dbf29/detection", "output": "Microsoft (R) MakeAppx Tool\r\r\nCopyright (C) 2013 Microsoft. All rights reserved.\r\r\n\r\r\nUsage:\r\r\n------\r\r\n MakeAppx <command> [options]\r\r\n\r\r\nValid commands:\r\r\n---------------\r\r\n pack -- Create a new app package from files on disk\r\r\n unpack -- Extract an existing app package to files on disk\r\r\n bundle -- Create a new app bundle from files on disk\r\r\n unbundle -- Extract an existing app bundle to files on disk\r\r\n encrypt -- Encrypt an existing app package or bundle\r\r\n decrypt -- Decrypt an existing app package or bundle\r\r\n convertCGM -- Convert a source content group map (CGM) to the final content group map\r\r\n build -- Build packages using a packaging layout file\r\r\n\r\r\nFor help with a specific command, enter \"MakeAppx <command> /?\"\r\r\n\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\makeappx.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "makecat.exe-33694E77EA12069253E7C97277045B5C": { "file_name": "makecat.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\makecat.exe", "hash_md5": "33694E77EA12069253E7C97277045B5C", "hash_sha1": "DB536B92DA00A70ADD8E4400D33C9EA374B93632", "hash_sha256": "5C682E270A395AAFB8BD9FD3B3366E7FB599002AA0358466D53ED6BE0B7DB843", "hash_sha384": "50FCD43B7559EC1E08F99E25116AF8E3FD533BF38CD033C0498E477965A4AAD5FD34710F74E02527840880CD3B124AAB", "hash_sha512": "9E01A182AB0A9020723E24B8AE2E2AF1950A1578A37EB19995D4542CD1EDD7B095307853EA37FCD9821DCF44678CEB47FD1BE5A2D07062A179181D7263091418", "hash_ssdeep": "768:qG8rcvSEQn8nRpJBDzj6OkaoSinCrWvz+VtW++1dCy:orcvlQn8ndhhHoSinWqgW+2dCy", "hash_imp": "1CE446910EE2B7D49D037197B9432688", "hash_pesha1": "96E734BCDAD842207ED83014CDFEAC2B1E639A1E", "hash_pe256": "622FCD211F0E0A75F85B4AE3FDCEFB79FB4983A4B8DB0C5A6C4C3485059F97EC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Trust Make Catalog utility", "meta_original_filename": "MAKECAT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5c682e270a395aafb8bd9fd3b3366e7fb599002aa0358466d53ed6be0b7db843/detection", "output": "usage: makecat.exe [options] [@commandfile] CDF_filename\r\r\n -?: this screen\r\r\n -v: verbose output\r\r\n -r: return fail even on recoverable errors\r\r\n -n: don't stop on error\r\r\n -s <param>: fail if any files are smaller than (param) bytes\r\r\n -o <param>: output filename/hash pairs to specified file\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\makecat.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "makecert.exe-B643D954F3731DC049458F9FA235B493": { "file_name": "makecert.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\makecert.exe", "hash_md5": "B643D954F3731DC049458F9FA235B493", "hash_sha1": "C96DE03D7CDE8098649627AA5EA5909FC4D3EE45", "hash_sha256": "2A3FCA2FDD446417C877479210E6A3095C2F996669A0DF86C2A865E1EE6E0B51", "hash_sha384": "77CEDAA58F1A6B147464144DC5BD11385F4592081D4B8AB56261F57AB1C98E81D31AE0CD32E0603AFD5900A1730BDB0D", "hash_sha512": "7326EAD57C72EAE9DB8F368F01FCF20DC47682A03306EADF527A455F0D6AC64D97C7DFCB285F3C215266AA1BB515B149A6A4DE15754545C4B687578534C8A7E5", "hash_ssdeep": "1536:ZsfdschFlHWPl13B3BOc6qwUEwPvbTJayaarFdq:8XFlHqjOchTESTJayaeq", "hash_imp": "9F00F41A6B62080B1DEFB3B42F19F265", "hash_pesha1": "5440B72B8F5D99EE9EC128C6D96870F47807A07A", "hash_pe256": "DC05AD13736D569E9013D4543B344A82374C5FE9B8161549945CD913651324FE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ECM MakeCert", "meta_original_filename": "MAKECERT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Usage: MakeCert [ basic|extended options] [outputCertificateFile]\r\nBasic Options\r\n -sk <keyName> Subject's key container name; To be created if not present\r\n -pe Mark generated private key as exportable\r\n -ss <store> Subject's certificate store name that stores the output \r\n certificate\r\n -sr <location> Subject's certificate store location.\r\n <CurrentUser|LocalMachine>. Default to 'CurrentUser'\r\n -# <number> Serial Number from 1 to 2^31-1. Default to be unique\r\n -$ <authority> The signing authority of the certificate\r\n <individual|commercial>\r\n -n <X509name> Certificate subject X500 name (eg: CN=Fred Dews)\r\n -? Return a list of basic options\r\n -! Return a list of extended options\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\makecert.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "makepri.exe-EDB9A599FE4DE49FB5D70A805FEDD63D": { "file_name": "makepri.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\makepri.exe", "hash_md5": "EDB9A599FE4DE49FB5D70A805FEDD63D", "hash_sha1": "17DA68AF745BF8B5E6A4B2C5C73BFB5B9D4FFA51", "hash_sha256": "1B2A8914D473C652C8CA0A6C870B25035B6ACA5BF44290CFA53374C23F1929B2", "hash_sha384": "F49800623EB3FA2604FFF96CF4B6347003433756C54F088801FB27601F56ACC837E67C5DF005139F47E027384399ED5C", "hash_sha512": "83B5A82B67A48D670769314CB9062CE634C2755894D431A2DFB042C0A6B070AA58993E69A511C8616B2EE850A8AC7EE29F8EB0E92151312D74F70A5F46EB6856", "hash_ssdeep": "12288:s/qIT5H9ZLGXZZJMcrrjYApf/OeIkW6JO5+wcjxZoFHl4WgnHRIul8Y5NU+:HIFeZJMGHYzkW/502FFT6/lfN", "hash_imp": "7E43F6BBEA9D1E7AAB6DB0933316A62B", "hash_pesha1": "B9BF70F036B7FD183929F4A3BD797EA172CACCA8", "hash_pe256": "6D667CD124214083E3BAE77D4197F3E0E7FFF35F251CD82458B4E32B07681ADD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command line tool for creating PRI files", "meta_original_filename": "Makepri.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1b2a8914d473c652c8ca0a6c870b25035b6aca5bf44290cfa53374c23f1929b2/detection", "output": "Microsoft (R) MakePRI Tool\r\nCopyright (C) 2013 Microsoft. All rights reserved.\r\n\r\n\r\nUsage:\r\r\n------\r\n MakePri.exe <Command> [options]\r\n\r\nExample:\r\r\n--------\r\n MakePri.exe new /pr C:\\MyApp\\src\\ /cf C:\\MyApp\\priconfig.xml /in PackageName\r\n\r\nDescription:\r\r\n------------\r\n MakePri.exe creates, dumps and does utility functions on a PRI file.\r\n A PRI file is an index of application resources (i.e. strings, files, etc).\r\n\r\nCommand Options:\r\r\n----------------\r\n MakePri.exe createconfig Creates a PRI Config file for use with other\r\n commands\r\n MakePri.exe new Creates a new PRI file from scratch\r\n MakePri.exe versioned Creates a PRI file based off a previous version\r\n MakePri.exe resourcepack Creates a PRI file that contains additional\r\n resource variants for a base PRI\r\n MakePri.exe dump Dumps the contents of a PRI file\r\n MakePri.exe help Show this help page\r\n\r\nHelp:\r\n Specify a command with help for more detailed help\r\n MakePri.exe new /?\r\n\r\n", "error": "ERROR: PRI104: 0x80070057 - Unknown option specified - '-help'\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\makepri.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mbidgenerator.exe-5D000EB74B50340117B94DB8E2A6BA4C": { "file_name": "mbidgenerator.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\mbidgenerator.exe", "hash_md5": "5D000EB74B50340117B94DB8E2A6BA4C", "hash_sha1": "A82086C52A6AB23F8252A56A82D26DA050F7E915", "hash_sha256": "6101A9B82A79DC9C3293E6423A87740E4AC6907BA9AA7ADEF0ED954CDABDE4AE", "hash_sha384": "88BA5736A5E0ECC2E9756E15DE18802BAA4D3BDDC387416AE69E4CC62B752249F5A07BEC472FA2E93474DA638AC278A2", "hash_sha512": "256D92648968BE19727D5D2D09EA41FF0ECB397BAB38B850B0602FB217A0010D522A1F816E8A9F4FA86AA74117D45AE9514E344F7BD8EFA9F7E484B024C392EE", "hash_ssdeep": "384:+0M+FW1VT/3qF/sk+Unppy/ye7tKyLlUEliyCM8r2aVA2W1WWTwGyxklN:ovyTrpp4rKkUElGMbr6", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "27718A1E57979C509549D30ABE9D4D560F88ACCA", "hash_pe256": "BE4E06DA0696DB93C1CEEA62AC6A0134DC984BC7D3F0C25ED3B2F739D35869AB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "MBIDGenerator.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Unknown command option: --help\r\n\r\nUsage: MBIDGenerator [/test] input_file [output_file]\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\mbidgenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mc.exe-EAF73DD86A665A60B95A0619D69DE605": { "file_name": "mc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\mc.exe", "hash_md5": "EAF73DD86A665A60B95A0619D69DE605", "hash_sha1": "37581A614CDFE051746FAA7812E05FE5B3D6BCD9", "hash_sha256": "7EA8BD997394C33FB04F1466F667A28AE5DF62B8457B43ABF6BE106682D842D5", "hash_sha384": "40A2EBF5ECAB3EBA5927C75560A1D254FBCB01C1CD12BC264533E59C93B50254797E796D4AF1DD910D12F8314F5AA184", "hash_sha512": "F3DCDEC8F85E6D69C35E6C40737E95BF11F35128292609FEFD40B13EAA69F088FB2BB788DBB857B5195E68496061D9F7429F69DABA79BBB572DCCD36A3DD1DA7", "hash_ssdeep": "6144:xc+sURibGRGhgTD+B3KWGcf3FVR91mQ7Ee4Pkn8aQ1V2LQDK9gIc3Pbj2JjsAWn4:i+sibiZrGi3191GzhPDDIRjsAEdW", "hash_imp": "BC25F59ED7CBA8818E85D7E8CA742AEF", "hash_pesha1": "B0CACEDFF7ACE004225DC4B7887543D9F192B624", "hash_pe256": "63675B3C3477365D9086871DEBD62AEA5511078528847A5531BEA60C9D528C49", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Message Compiler", "meta_original_filename": "mc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/7ea8bd997394c33fb04f1466f667a28ae5df62b8457b43abf6be106682d842d5/detection", "error": "mc : error : Invalid switch: -.\r\nmc : error : Missing argument for -h switch.\r\nmc : error : Missing argument for -e switch.\r\nmc : error : Invalid switch: l.\r\nmc : error : Missing argument for -p switch.\r\nMicrosoft (R) Message Compiler Version 10.0.19041\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUsage:\r\n\r\nMC [-?aAbcdnouUv] [-m <length>] [-h <path>] [-e <extension>] [-r <path>]\r\n [-x <path>] [-w <file>] [-W <file>] [-z <basename> ] [-cp <encoding>]\r\n [-km | -um | -generateProjections | -cs <namespace>]\r\n [-mof] [-p <prefix>] [-P <prefix>]\r\n [<filename.man>] [<filename.mc>]\r\n\r\n -? - Displays this message.\r\n -a - Indicates that the input .mc file is CP_ACP (default).\r\n Ignored if the .mc file has a UTF-8 or UTF-16LE BOM.\r\n -A - DEPRECATED. Encode .BIN messages using CP_ACP (ANSI).\r\n -b - .BIN filename should have .mc filename included for\r\n uniqueness.\r\n -c - Sets the Customer bit in all of the message IDs.\r\n -d - FACILITY and SEVERITY values should be printed as decimal\r\n in header file (default is hexadecimal).\r\n -e <extension> - The extension for the C include file (1-3 chars).\r\n -h <path> - The path for the C include file. Default is: \".\\\"\r\n -m <length> - Warn if any message exceeds <length> characters.\r\n -n - NUL-terminate all message table strings.\r\n -o - Generate OLE2 header file (use HRESULT definition instead\r\n of status code definition).\r\n -r <path> - The directory for the RC include file and the binary\r\n message resource files it includes. Default is: \".\\\"\r\n -s <path> - Generate a separate binary resource per provider.\r\n Generate summary global resource MCGenResource.BIN.\r\n -t <path> - Validate against baseline resource.\r\n -u - Indicates that the input .mc file is UTF-16LE. This flag\r\n is required when the .mc file is UTF-16LE without a BOM.\r\n Ignored if the .mc file has a UTF-8 or UTF-16LE BOM.\r\n -U - Encode .BIN messages using UTF-16LE (default).\r\n -U8 - Encode .BIN messages using UTF8. Resulting message table\r\n will only be usable on Windows 20h1 or later.\r\n -v - Enables verbose output.\r\n -W <file> - The path to a custom winmeta.xml file (rarely needed).\r\n -w <file> - The path to a custom eventman.xsd file (rarely needed).\r\n -x <path> - The path for the .dbg C include file that maps message\r\n IDs to their symbolic names. This option can only be used\r\n with a message text file.\r\n -z <basename> - The base name of the generated files. Default is the base\r\n name of the input file.\r\n <filename.man> - The name of the manifest file to compile.\r\n <filename.mc> - The name of a message file to compile.\r\n\r\n Code Generation Options\r\n ----------------------- \r\n -cp <encoding> - Generated text files will use the specified\r\n character encoding. Valid encoding names include\r\n \"ansi\" (default), \"utf-8\", and \"utf-16\".\r\n The UTF encodings will add a byte order mark (BOM).\r\n -km - Generate Kernel Mode logging macros.\r\n -um - Generate User Mode logging macros.\r\n Note: unless the -mof parameter is specified, the\r\n only difference between -km and -um is that the\r\n EventWrite macros generated with -km accept an\r\n Activity ID parameter.\r\n -generateProjections - Generate logging interfaces projectable to\r\n JavaScript.\r\n -generateTemplateProjections\r\n - Generate logging interfaces projectable to\r\n JavaScript that reduce projection cost.\r\n -generateTemplateStubs <file>\r\n - Override the default template wrapping stubs file\r\n from WinRTTemplateProviderStubs.js to <file>.js.\r\n -cs <namespace> - Generate C# (managed) logging class based on the\r\n .NET 3.5 Eventing class.\r\n -css <namespace> - Generate static C# (managed) logging class based on\r\n the .NET 3.5 Eventing class.\r\n\r\n -co - Generate EventWrite macros that invoke an\r\n MCGEN_CALLOUT macro. Not supported (ignored) for C#.\r\n -mof - DEPRECATED. Generate downlevel (XP-compatible)\r\n functions and macros for ETW. Generate a MOF file\r\n describing the ETW events. The MOF file will be\r\n generated in the location specified by the \"-h\"\r\n switch.\r\n -p <prefix> - Defines the macro name prefix applied to each\r\n generated logging macro. Default is: \"EventWrite\"\r\n -P <prefix> - Specifies text at the start of each event symbol name\r\n to remove before forming the macro names.\r\n\r\nNotes:\r\n\r\n- The 'A' and 'mof' switches are deprecated and will be removed in the future.\r\n- At most one .mc and one .man file can be processed per invocation of mc.exe.\r\n- Generated files have the Archive bit cleared.\r\n- The mofcomp and rc tools do not currently support UTF-8 input. If a UTF-8\r\n encoding is requested, the MOF and RC files will be generated as UTF-16LE.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\mc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mdmerge.exe-B5B0BC14A5A675C143898BD2C67888C7": { "file_name": "mdmerge.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\mdmerge.exe", "hash_md5": "B5B0BC14A5A675C143898BD2C67888C7", "hash_sha1": "45A9C70881965A074FCC9E6E62673C350F436DA7", "hash_sha256": "146EDCF2F69417071178E97ECA594C394130BFEBB9707843DAAF88F90B8CA521", "hash_sha384": "755B6BDB944440DD0E7E30D74C78EE8659ADE4AB19F9E6F215CB8E8B08A4B248F22B30C4E86BEA34E52950C44DA00033", "hash_sha512": "7310359756F894E10941A45AAB6F9FF7F8D88A88BA22FEFE0A67881DD025206F39568CBF418FF168F4C1F5173EA580FCA8A9157F0244FAC0594D54DF682DE061", "hash_ssdeep": "12288:4B7B6/Ovc1wkXq7sgUjrl8xDz2EGwiH13vwzoimBiP+wi:Q0/fwkXq7sgUjrcDzawiH13vwzlSiP7i", "hash_imp": "22B40D760520C08196FEA684FCB40352", "hash_pesha1": "36FB051D21F4F0A5E0D36C78977EBE196D25BA0A", "hash_pe256": "F2D7C1CF0871B04D2BC24693E5D5A1713CB399126D1600C93ED25DE435C89104", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft MDMERGE Utility", "meta_original_filename": "mdmerge.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Microsoft(R) Metadata Merge Utility Version 10.0.49.\r\r\n\r\nUsage: C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\mdmerge.exe [-/][Switch][:][Value]\r\n\r\nWhere Switch is one of the following: \r\n -?: Print this help\r\n -h: Print this help\r\n -v: Validate - Validate metadata type references\r\n -i: Input directory - compose metadata files in this directory\r\n -metadata_dir: Metadata Directory - Directory which contains the master copy of Windows Metadata files\r\n -partial: Partial - resolve unresolved types against metadata files specified in the -metadata_dir switch\r\n -platform_filter: Platform filter - specifies a platform filter XML file\r\n -additional_platform_path: Additional platform path - specifies additional path to look for <platform>.xml file. Optional.\r\n -o: Output directory - put composed metadata files in this directory\r\n -n: Composition Depth - compose to this level of input\r\n -contracts: Sort metadata into contracts\r\n -platform: Target Platform - compose metadata for this platform\r\n -mdv: Metadata format version\r\n -contractMap: Specifies the filename to place the API contract maps\r\n -removeInternal: Removes types that are marked internal\r\n -resFile: A compiled resource file to embed in metadata files\r\n -keepOnlyInternal: Removes types that are not marked internal\r\n -createPublicMetadata: Creates metadata for public release\r\n -transformExperimental: Transform the experimental attribute\r\n -keepOnlyPrivate: Removes types that are not marked private\r\n -verbose: Prints verbose information to the console\r\n", "error": "MDMERGE : error MDM5003: Unrecognized command line switch: --help.\r\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\mdmerge.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mftrace.exe-E95DF4CB73BE53ABB111BEE9F166D716": { "file_name": "mftrace.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\mftrace.exe", "hash_md5": "E95DF4CB73BE53ABB111BEE9F166D716", "hash_sha1": "A2980132E440392D20E36B0DF1EFA23A2D0B3D7F", "hash_sha256": "737B3264A2C58FC6721ACBAB1EB33A905928B59524BC6B96F29DA7527E7FA2CE", "hash_sha384": "3214FAE3686DED13AC843996C40BF7B8293AEE01FBE454EF3066D33C5141D3768FDD0B89B86F100B36BA080FFC0F24D7", "hash_sha512": "2B8A3326CFF74B951AF89C9C15800BD360F2FB6E2CD0FF9B6FC67A5BDF5FE21CC3FC8EA5B8F787ACDED1A27266BDF7F43E78CCB3B09F0329085193B5922C7A52", "hash_ssdeep": "6144:1EyiBAjmdPD0Yq3smMN1h6ftv/C0nJPAEtAz2Ki:1jwPPq8m+mxC0nJPAEU2Ki", "hash_imp": "42443E9A79C89F639C2DEEF11B71ECC4", "hash_pesha1": "C2E8DB26695C4FBD25A4BFD57113CDBD41F3FFCA", "hash_pe256": "5AA67A6838A8E99A4495618EA64076D5FF4E75ABFAD8BCB28376D5CC3AB31E86", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Media Foundation Tracing Application", "meta_original_filename": "mftrace.exe", "meta_product_name": "Media Foundation Tracing Application", "meta_company_name": "Microsoft", "meta_file_version": "1.1.0.1", "meta_product_version": "1.1.0.1", "meta_language": "Language Neutral", "meta_legal_copyright": "(c) Microsoft. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Failed with hr=0x80070057 (ERROR_INVALID_PARAMETER)\r\nUse the '-v' option to get further details\r\n", "output": "For more information on a specific command, type HELP command-name\r\nASSOC Displays or modifies file extension associations.\r\nATTRIB Displays or changes file attributes.\r\nBREAK Sets or clears extended CTRL+C checking.\r\nBCDEDIT Sets properties in boot database to control boot loading.\r\nCACLS Displays or modifies access control lists (ACLs) of files.\r\nCALL Calls one batch program from another.\r\nCD Displays the name of or changes the current directory.\r\nCHCP Displays or sets the active code page number.\r\nCHDIR Displays the name of or changes the current directory.\r\nCHKDSK Checks a disk and displays a status report.\r\nCHKNTFS Displays or modifies the checking of disk at boot time.\r\nCLS Clears the screen.\r\nCMD Starts a new instance of the Windows command interpreter.\r\nCOLOR Sets the default console foreground and background colors.\r\nCOMP Compares the contents of two files or sets of files.\r\nCOMPACT Displays or alters the compression of files on NTFS partitions.\r\nCONVERT Converts FAT volumes to NTFS. You cannot convert the\r\n current drive.\r\nCOPY Copies one or more files to another location.\r\nDATE Displays or sets the date.\r\nDEL Deletes one or more files.\r\nDIR Displays a list of files and subdirectories in a directory.\r\nDISKPART Displays or configures Disk Partition properties.\r\nDOSKEY Edits command lines, recalls Windows commands, and \r\n creates macros.\r\nDRIVERQUERY Displays current device driver status and properties.\r\nECHO Displays messages, or turns command echoing on or off.\r\nENDLOCAL Ends localization of environment changes in a batch file.\r\nERASE Deletes one or more files.\r\nEXIT Quits the CMD.EXE program (command interpreter).\r\nFC Compares two files or sets of files, and displays the \r\n differences between them.\r\nFIND Searches for a text string in a file or files.\r\nFINDSTR Searches for strings in files.\r\nFOR Runs a specified command for each file in a set of files.\r\nFORMAT Formats a disk for use with Windows.\r\nFSUTIL Displays or configures the file system properties.\r\nFTYPE Displays or modifies file types used in file extension \r\n associations.\r\nGOTO Directs the Windows command interpreter to a labeled line in \r\n a batch program.\r\nGPRESULT Displays Group Policy information for machine or user.\r\nGRAFTABL Enables Windows to display an extended character set in \r\n graphics mode.\r\nHELP Provides Help information for Windows commands.\r\nICACLS Display, modify, backup, or restore ACLs for files and \r\n directories.\r\nIF Performs conditional processing in batch programs.\r\nLABEL Creates, changes, or deletes the volume label of a disk.\r\nMD Creates a directory.\r\nMKDIR Creates a directory.\r\nMKLINK Creates Symbolic Links and Hard Links\r\nMODE Configures a system device.\r\nMORE Displays output one screen at a time.\r\nMOVE Moves one or more files from one directory to another \r\n directory.\r\nOPENFILES Displays files opened by remote users for a file share.\r\nPATH Displays or sets a search path for executable files.\r\nPAUSE Suspends processing of a batch file and displays a message.\r\nPOPD Restores the previous value of the current directory saved by \r\n PUSHD.\r\nPRINT Prints a text file.\r\nPROMPT Changes the Windows command prompt.\r\nPUSHD Saves the current directory then changes it.\r\nRD Removes a directory.\r\nRECOVER Recovers readable information from a bad or defective disk.\r\nREM Records comments (remarks) in batch files or CONFIG.SYS.\r\nREN Renames a file or files.\r\nRENAME Renames a file or files.\r\nREPLACE Replaces files.\r\nRMDIR Removes a directory.\r\nROBOCOPY Advanced utility to copy files and directory trees\r\nSET Displays, sets, or removes Windows environment variables.\r\nSETLOCAL Begins localization of environment changes in a batch file.\r\nSC Displays or configures services (background processes).\r\nSCHTASKS Schedules commands and programs to run on a computer.\r\nSHIFT Shifts the position of replaceable parameters in batch files.\r\nSHUTDOWN Allows proper local or remote shutdown of machine.\r\nSORT Sorts input.\r\nSTART Starts a separate window to run a specified program or command.\r\nSUBST Associates a path with a drive letter.\r\nSYSTEMINFO Displays machine specific properties and configuration.\r\nTASKLIST Displays all currently running tasks including services.\r\nTASKKILL Kill or stop a running process or application.\r\nTIME Displays or sets the system time.\r\nTITLE Sets the window title for a CMD.EXE session.\r\nTREE Graphically displays the directory structure of a drive or \r\n path.\r\nTYPE Displays the contents of a text file.\r\nVER Displays the Windows version.\r\nVERIFY Tells Windows whether to verify that your files are written\r\n correctly to a disk.\r\nVOL Displays a disk volume label and serial number.\r\nXCOPY Copies files and directory trees.\r\nWMIC Displays WMI information inside interactive command shell.\r\n\r\nFor more information on tools see the command-line reference in the online help.\r\nListening to ETW events (CTRL+C to end)\r\n __M_F_T_R_A_C_E___LOG__\r\n\r\nPID, TID Time (UTC) TraceMessage\r\n--------- -------------- ------------\r\n8208,CC8 21:40:07.35592 TraceOSVersion @ OS version (BuildLabEx): 19041.1.amd64fre.vb_release.191206-1406\r\n8208,CC8 21:40:07.35593 TraceMFDetoursVersion @ MFDetours version 1.1.0.1\r\n8208,CC8 21:40:07.35595 TraceEnabledKeywords @ Keywords and levels: Default 4, Detours 4, MFDebugHlp 4, Kernel32Export 4, MFExport 4, MFPlatExport 4, MFPlayExport 4, MFReadWriteExport 4, Ole32Export 4, wmvCoreExport 4, MFPublic 4, IMFActivate 4, IMFAsyncCallback 4, IMFAttributes 4, IMFClock 4, IMFClockStateSink 4, IMFMediaEventGenerator 4, IMFMediaSession 4, IMFMediaSink 4, IMFMediaSource 4, IMFMediaStream 4, IMFPMediaPlayer 4, IMFPMediaItem 4\r\n8208,CC8 21:40:07.35600 TraceEnabledKeywords @ Keywords and levels: IMFPMediaPlayerCallback 4, IMFPresentationClock 4, IMFQualityAdvise 4, IMFQualityAdvise2 4, IMFQualityManager 4, IMFRateControl 4, IMFSample 4, IMFSinkWriter 4, IMFSourceReader 4, IMFSourceReaderCallback 4, IMFSourceResolver 4, IMFStreamSink 4, IMFTopology 4, IMFTopologyNode 4, IMFTopoLoader 4, IMFTransform 4, IMediaObject 4, IMFSchemeHandler 4, IMFByteStream 4, IMFByteStreamHandler 4\r\n8208,CC8 21:40:07.35600 TraceEnabledKeywords @ Keywords and levels: IMFReadWriteClassFactory 4, IFilterGraph 4, IGraphBuilder 4, IMediaControl 4, IMemInputPin 4, IWMReader 4, IWMReaderCallback 4\r\n8208,CC8 21:40:07.35690 CMFMediaSessionDetours::Attach @000001B321C189C0 Presentation clock @000001B321C1EB00\r\n8208,CC8 21:40:07.35708 CMFMediaSessionDetours::Attach @000001B321C189C0 Rate control @000001B321C189D0\r\n __M_F_T_R_A_C_E___LOG__\r\nTotal events received: 7 \r\n", "children": "conhost.exe", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\mftrace.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "midl.exe-E8B505903CDE08998EDF0816379EBE61": { "file_name": "midl.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\midl.exe", "hash_md5": "E8B505903CDE08998EDF0816379EBE61", "hash_sha1": "5E6D641B6E1CCA66012EA0131BB52A4212084A95", "hash_sha256": "32589A45054267E6D53CABFBDE27A0C50110EECD0B34E209857607B3E65DFF07", "hash_sha384": "32B4B00EBE2C669159C07BBFB5929203090E462E1057ECD35E6AA634CD9FDC00A5FA55D23008304BB731A0E8137F9A10", "hash_sha512": "A97F2A726395DED52940B487BC1717F3F8A7FCE692EB89A7C7069078B7C81AE5D8068797833753821D942F895ACF24C1055F54D78644A7A21E35A57A90C0AB2E", "hash_ssdeep": "3072:oLATrd1O/60Dg7gYBLyyOHZQJGZpMkY7yQsoz0gj5bzVo4qFYV2p3:/TR1UXXYxHNj5XVo", "hash_imp": "32314B0749D6E242A4D9B55C6738DAD5", "hash_pesha1": "7F9A2142A5BCAB6AB1D10393632486B5ED196B09", "hash_pe256": "6533EB1A5D3096CB04E7B6100C815EF862F11EC41947045AC7D8EAE80677A87F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IDL Compiler Driver", "meta_original_filename": "midl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/32589a45054267e6d53cabfbde27a0c50110eecd0b34e209857607b3e65dff07/detection", "output": " -MIDL COMPILER OPTIONS-\r\n -MODE-\r\n/ms_ext Microsoft extensions to the IDL language (default)\r\n/c_ext Allow Microsoft C extensions in the IDL file (default)\r\n/osf OSF mode - disables /ms_ext and /c_ext options\r\n/app_config Allow selected ACF attributes in the IDL file\r\n/mktyplib203 MKTYPLIB Version 2.03 compatiblity mode\r\n\r\n -INPUT-\r\n/acf filename Specify the attribute configuration file\r\n/I directory-list Specify one or more directories for include path\r\n/no_def_idir Ignore the current and the INCLUDE directories\r\n\r\n -OUTPUT FILE GENERATION-\r\n/client none Do not generate client files\r\n/client stub Generate client stub file only\r\n/out directory Specify destination directory for output files\r\n/server none Generate no server files\r\n/server stub Generate server stub file only\r\n/syntax_check Check syntax only; do not generate output files\r\n/Zs Check syntax only; do not generate output files\r\n/oldtlb Generate old format type libraries\r\n/newtlb Generate new format type libraries (default)\r\n/notlb Don't generate the tlb file\r\n/define_guids Define COM guids in the stub header as well as in dlldata\r\n\r\n -OUTPUT FILE NAMES-\r\n/cstub filename Specify client stub file name\r\n/dlldata filename Specify dlldata file name\r\n/h filename Specify header file name\r\n/header filename Specify header file name\r\n/iid filename Specify interface UUID file name\r\n/proxy filename Specify proxy file name\r\n/sstub filename Specify server stub file name\r\n/tlb filename Specify type library file name\r\n\r\n -C COMPILER AND PREPROCESSOR OPTIONS-\r\n/cpp_cmd cmd_line Specify name of C preprocessor (default: cl.exe)\r\n/cpp_opt options Specify additional C preprocessor options\r\n/D name[=def] Pass #define name, optional value to C preprocessor\r\n/no_cpp Turn off the C preprocessing option\r\n/nocpp Turn off the C preprocessing option\r\n/U name Remove any previous definition (undefine)\r\n/msc_ver <nnnn> Microsoft C/C++ compiler version\r\n/savePP Save the preprocessed temporary file(s)\r\n\r\n -ENVIRONMENT-\r\n/char signed C compiler default char type is signed\r\n/char unsigned C compiler default char type is unsigned\r\n/char ascii7 Char values limited to 0-127\r\n/env win32 Target environment is Microsoft Windows 32-bit (NT)\r\n/env ia64 Target environment is Microsoft Windows 64-bit (NT) for IA64\r\n/env x64 Target environment is Microsoft Windows for 64-Bit \r\n Extended Systems\r\n/env arm32 Target environment is Microsoft Windows for 32-bit ARM\r\n Systems\r\n/env arm64 Target environment is Microsoft Windows for 64-bit ARM\r\n Systems\r\n/lcid Locale id for international locales\r\n/ms_union Use Midl 1.0 non-DCE wire layout for non-encapsulated unions\r\n/oldnames Do not mangle version number into names\r\n/rpcss Automatically activate rpc_sm_enable_allocate\r\n/use_epv Generate server side application calls via entry-pt vector\r\n/no_default_epv Do not generate a default entry-point vector\r\n/prefix client str Add \"str\" prefix to client-side entry points\r\n/prefix server str Add \"str\" prefix to server-side manager routines\r\n/prefix switch str Add \"str\" prefix to switch routine prototypes\r\n/prefix all str Add \"str\" prefix to all routines\r\n/win32 Target environment is Microsoft Windows 32-bit (NT)\r\n/ia64 Target environment is Microsoft Windows 64-bit (NT) for IA64\r\n/x64 Target environment is Microsoft Windows for 64-Bit \r\n Extended Systems\r\n/arm32 Target environment is Microsoft Windows for 32-bit ARM\r\n Systems\r\n/arm64 Target environment is Microsoft Windows for 64-bit ARM\r\n Systems\r\n/protocol dce Use DCE NDR transfer syntax (default for 32-bit)\r\n/protocol all Use all supported transfer syntaxes\r\n/protocol ndr64 Use Microsoft extension NDR64 transfer syntax\r\n/target {system} Set the minimum target system\r\n\r\n -RUNTIME ERROR CHECKING BY STUBS-\r\n/error all Turn on all the error checking options, the best flavor\r\n/error none Turn off all the error checking options\r\n/error allocation Check for out of memory errors\r\n/error bounds_check Check size vs transmission length specification\r\n/error enum Check enum values to be in allowable range\r\n/error ref Check ref pointers to be non-null\r\n/error stub_data Emit additional check for server side stub data validity\r\n All the /error checking above are replaced by /robust\r\n/robust Generate additonal information to validate parameters. \r\n Requires Windows 2000 and after (default)\r\n/no_robust turn off /robust feature. not applicable for 64-bit Windows\r\n\r\n -OPTIMIZATION-\r\n/align {N} Designate packing level of structures\r\n/pack {N} Designate packing level of structures\r\n/Zp {N} Designate packing level of structures\r\n/no_format_opt Skip format string reusage optimization\r\n/Oi Generate fully interpreted stubs, old style\r\n -Oicf is usually better\r\n/Oic Generate fully interpreted stubs for standard interfaces and\r\n stubless proxies for object interfaces as of NT 3.51 release\r\n using -Oicf instead is usually better\r\n/Oicf Generate fully interpreted stubs with extensions and stubless\r\n proxies for object interfaces as of NT 4.0 release (default)\r\n/Oif Same as -Oicf\r\n/Os Generate inline stubs\r\n\r\n -MISCELLANEOUS-\r\n@response_file Accept input from a response file\r\n/? Display a list of MIDL compiler switches\r\n/confirm Display options without compiling MIDL source\r\n/help Display a list of MIDL compiler switches\r\n/nologo Supress displaying of the banner lines\r\n/o filename Redirects output from screen to a file\r\n/W{0|1|2|3|4} Specify warning level 0-4 (default = 1)\r\n/WX Report warnings at specified /W level as errors\r\n/no_warn Suppress compiler warning messages\r\n", "error": "Microsoft (R) 32b/64b MIDL Compiler Version 8.01.0622 \r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\midl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "midlc.exe-A61D3DFFF26964A5F1328D0734D6F32B": { "file_name": "midlc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\midlc.exe", "hash_md5": "A61D3DFFF26964A5F1328D0734D6F32B", "hash_sha1": "DD4F5B5F0DD09D21E2168617282A492F8B777004", "hash_sha256": "0F24504D86BC5EA1DC8B6297B13627BFAC1B9326B254DF7936A04427E7FDCC8B", "hash_sha384": "1C519065E19FB5B416A86FE8A739368CF5A78B7BAFD2172FEC4432D2E25862B5D5BF280ADFC374AD6B12E536B7D916E8", "hash_sha512": "4FA90DDAD072C4D03E4D2F20DC794E2D4BCD0B33D9A09C166D096E31A212B62CED648462395E60DEC2623DBAA10244D9B202E2A5333A86E7C98E87BC2253B21A", "hash_ssdeep": "24576:ZU5I1DWxqgks9ZLXMhhoo6Cmh/tyQoDQRABu:ZDNAqgk4ZDOhqhsDQRl", "hash_imp": "690D5702409567FC8F463EE4ABE543DB", "hash_pesha1": "459DD76F34C3C73D4DCD4999F5137C72348CA882", "hash_pe256": "31EE5FFBBFAFC8E1B693CD2AEB84B32A799247034C7F14763A4E93B6D10BF6AD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IDL Compiler", "meta_original_filename": "midlc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0f24504d86bc5ea1dc8b6297b13627bfac1b9326b254df7936a04427e7fdcc8b/detection", "output": "midl : error MIDL2399 : invalid or corrupt intermediate compiler file : help\r\n00: 30 ffffff82 02 43 30 ffffff82 01 fffffff1 ffffffa0 03 02 01 02 02 10 6b 0.C0.......k\r\n10: 58 ffffffd2 fffffffc 7b 53 ffffffb4 ffffffab 41 6d ffffffd1 3a ffffffd7 ffffffce 6c 39 30 X{SAm:l90\r\n20: 09 06 05 2b 0e 03 02 1d 05 00 30 16 31 14 30 12 ...+......0.1.0.\r\n30: 06 03 55 04 03 13 0b 52 6f 6f 74 20 41 67 65 6e ..U....Root Agen\r\n40: 63 79 30 1e 17 0d 32 31 30 31 31 31 32 31 34 30 cy0...2101112140\r\n50: 30 31 5a 17 0d 33 39 31 32 33 31 32 33 35 39 35 01Z..39123123595\r\n60: 39 5a 30 22 31 20 30 1e 06 03 55 04 03 13 17 4a 9Z0\"1 0...U....J\r\n70: 6f 65 27 73 2d 53 6f 66 74 77 61 72 65 2d 45 6d oe's-Software-Em\r\n80: 70 6f 72 69 75 6d 30 ffffff82 01 22 30 0d 06 09 2a ffffff86 porium0.\"0...*\r\n90: 48 ffffff86 fffffff7 0d 01 01 01 05 00 03 ffffff82 01 0f 00 30 ffffff82 H..........0\r\na0: 01 0a 02 ffffff82 01 01 00 ffffffbc ffffffc0 ffffffb9 03 33 ffffff80 10 5c 77 .......3.\\w\r\nb0: 5c ffffffbf ffffffaa 71 ffffffbd ffffff80 ffffffc1 ffffffdb 66 ffffffc1 ffffffa5 ffffffc4 3f ffffffcd 78 fffffff2 \\qf?x\r\nc0: ffffffe5 63 39 53 69 25 ffffffbf 5b 00 1f ffffffac 5e ffffff95 73 ffffffee 5f c9Si%[..^s_\r\nd0: 11 1f ffffffdf ffffff82 ffffffb4 fffffff3 58 ffffff8e 3f ffffff8f 76 0c 55 07 fffffff3 ffffffc0 ..X?v.U.\r\ne0: ffffffbb ffffffc2 ffffffa5 16 36 ffffffd9 fffffff5 fffffff5 ffffff9c 7f fffffff8 ffffffd8 ffffffbe 04 ffffffa7 ffffff92 .6..\r\nf0: 0a 0b ffffffcd 60 08 19 ffffffb7 ffffff90 79 48 61 ffffff9e 13 0f fffffffe ffffffc0 ..`..yHa..\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\midlc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "midlrt.exe-0537005A34D54CD5401374D36EF14D2F": { "file_name": "midlrt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\midlrt.exe", "hash_md5": "0537005A34D54CD5401374D36EF14D2F", "hash_sha1": "7345E6D979B7C8C5D1945C9B9012903790868B31", "hash_sha256": "2AE7E2C93B06C1B80F2C47EEA8BFD27AA722B4F7ED7C0CA5EA91F1609CB7C17A", "hash_sha384": "5D420539121F3393EB07348F581BBD9D3902BA20B0CFEE4D21136F8F01CB2E83A93E60C56E40BE1321E4F2B0B1AA236A", "hash_sha512": "CBBAD503CD602B1FB3DB32C06F9CA66756D4B898FDBAE7FEB634313EBE2A90C1036A07575C393EA6BFD495B842B72851ACF6EB7A6330F0C4856D66B891F43135", "hash_ssdeep": "24576:Cf0xJAdVAihTardfXX2QhIXohFCcZDMzvxejXsMqqK7tPrqvHqOxcS0eUK9Vyx4f:Cf4Fistao+cZDM0XpqqtnVyx8wY", "hash_imp": "08C39DAF4985A0BFDCECF8E6D1D6C69E", "hash_pesha1": "E283BF0DDA72A4DFD53417CB93EAE6AF6FF204D1", "hash_pe256": "69FB755DE5D386CD1C613AF981EA7C3B3AC1FE37524DA312A9E6BF3140EACC4D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IDL Compiler", "meta_original_filename": "midlrt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": " -MIDL COMPILER OPTIONS-\r\n -MODE-\r\n/ms_ext Microsoft extensions to the IDL language (default)\r\n/c_ext Allow Microsoft C extensions in the IDL file (default)\r\n/osf OSF mode - disables /ms_ext and /c_ext options\r\n/app_config Allow selected ACF attributes in the IDL file\r\n/mktyplib203 MKTYPLIB Version 2.03 compatiblity mode\r\n\r\n -INPUT-\r\n/acf filename Specify the attribute configuration file\r\n/I directory-list Specify one or more directories for include path\r\n/no_def_idir Ignore the current and the INCLUDE directories\r\n/metadata_dir Specify one or more directories containing platform metadata files\r\n/reference Specify one or more WinMD files to import\r\n\r\n -OUTPUT FILE GENERATION-\r\n/client none Do not generate client files\r\n/client stub Generate client stub file only\r\n/out directory Specify destination directory for output files\r\n/server none Generate no server files\r\n/server stub Generate server stub file only\r\n/syntax_check Check syntax only; do not generate output files\r\n/Zs Check syntax only; do not generate output files\r\n/oldtlb Generate old format type libraries\r\n/newtlb Generate new format type libraries (default)\r\n/notlb Don't generate the tlb file\r\n/nomd Suppress generation of metadata file\r\n\r\n -OUTPUT FILE NAMES-\r\n/cstub filename Specify client stub file name\r\n/dlldata filename Specify dlldata file name\r\n/h filename Specify header file name\r\n/header filename Specify header file name\r\n/iid filename Specify interface UUID file name\r\n/proxy filename Specify proxy file name\r\n/sstub filename Specify server stub file name\r\n/tlb filename Specify type library file name\r\n/winmd Specify output metadata file name \r\n\r\n -WINDOWS RUNTIME OPTIONS-\r\n/winrt Enable Windows Runtime semantics\r\n/ns_prefix Prepend the 'ABI' namespace to all types\r\n/enum_class Enable use of the C++ enum class construct\r\n/nomidl Suppress running MIDL.EXE after processing windows runtime IDL file\r\n/nomd Suppress generation of metadata while processing windows runtime IDL file\r\n/enable_true_async <true|false> Enable true async feature by default\r\n\r\n -C COMPILER AND PREPROCESSOR OPTIONS-\r\n/cpp_cmd cmd_line Specify name of C preprocessor (default: cl.exe)\r\n/cpp_opt options Specify additional C preprocessor options\r\n/cpp_level level Specify additional C preprocessor options\r\n/D name[=def] Pass #define name, optional value to C preprocessor\r\n/no_cpp Turn off the C preprocessing option\r\n/nocpp Turn off the C preprocessing option\r\n/U name Remove any previous definition (undefine)\r\n/msc_ver <nnnn> Microsoft C/C++ compiler version\r\n/savePP Save the preprocessed temporary file(s)\r\n\r\n -ENVIRONMENT-\r\n/char signed C compiler default char type is signed\r\n/char unsigned C compiler default char type is unsigned\r\n/char ascii7 Char values limited to 0-127\r\n/env win32 Target environment is Microsoft Windows 32-bit (NT)\r\n/env ia64 Target environment is Microsoft Windows 64-bit (NT) for IA64\r\n/env x64 Target environment is Microsoft Windows for 64-Bit \r\n Extended Systems\r\n/lcid Locale id for international locales\r\n/ms_union Use Midl 1.0 non-DCE wire layout for non-encapsulated unions\r\n/oldnames Do not mangle version number into names\r\n/rpcss Automatically activate rpc_sm_enable_allocate\r\n/use_epv Generate server side application calls via entry-pt vector\r\n/no_default_epv Do not generate a default entry-point vector\r\n/prefix client str Add \"str\" prefix to client-side entry points\r\n/prefix server str Add \"str\" prefix to server-side manager routines\r\n/prefix switch str Add \"str\" prefix to switch routine prototypes\r\n/prefix all str Add \"str\" prefix to all routines\r\n/win32 Target environment is Microsoft Windows 32-bit (NT)\r\n/ia64 Target environment is Microsoft Windows 64-bit (NT) for IA64\r\n/x64 Target environment is Microsoft Windows for 64-Bit \r\n Extended Systems\r\n/protocol dce Use DCE NDR transfer syntax (default for 32b)\r\n/protocol all Use all supported transfer syntaxes\r\n/protocol ndr64 Use Microsoft extension NDR64 transfer syntax\r\n/target {system} Set the minimum target system\r\n\r\n -RUNTIME ERROR CHECKING BY STUBS-\r\n/error all Turn on all the error checking options, the best flavor\r\n/error none Turn off all the error checking options\r\n/error allocation Check for out of memory errors\r\n/error bounds_check Check size vs transmission length specification\r\n/error enum Check enum values to be in allowable range\r\n/error ref Check ref pointers to be non-null\r\n/error stub_data Emit additional check for server side stub data validity\r\n All the /error checking above are replaced by /robust\r\n/robust Generate additonal information to validate parameters. \r\n Requires Windows 2000 and after (default)\r\n/no_robust turn off /robust feature. not applicable for 64-bit Windows\r\n\r\n -OPTIMIZATION-\r\n/align {N} Designate packing level of structures\r\n/pack {N} Designate packing level of structures\r\n/Zp {N} Designate packing level of structures\r\n/no_format_opt Skip format string reusage optimization\r\n/Oi Generate fully interpreted stubs, old style\r\n -Oicf is usually better\r\n/Oic Generate fully interpreted stubs for standard interfaces and\r\n stubless proxies for object interfaces as of NT 3.51 release\r\n using -Oicf instead is usually better\r\n/Oicf Generate fully interpreted stubs with extensions and stubless\r\n proxies for object interfaces as of NT 4.0 release (default)\r\n/Oif Same as -Oicf\r\n/Os Generate inline stubs\r\n\r\n -MISCELLANEOUS-\r\n@response_file Accept input from a response file\r\n/? Display a list of MIDL compiler switches\r\n/confirm Display options without compiling MIDL source\r\n/help Display a list of MIDL compiler switches\r\n/nologo Supress displaying of the banner lines\r\n/o filename Redirects output from screen to a file\r\n/W{0|1|2|3|4} Specify warning level 0-4 (default = 1)\r\n/WX Report warnings at specified /W level as errors\r\n/no_warn Suppress compiler warning messages\r\n", "error": "Microsoft (R) 32b/64b MIDLRT Compiler Engine Version 10.00.0229 \r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\nmidlrt : error MIDL1011 : [msg]argument(s) missing for switch [context]/h\r\nmidlrt : error MIDL1000 : [msg]missing source-file name \r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\midlrt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mt.exe-D955F5778F8107C12788C7BEEC60E67A": { "file_name": "mt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\mt.exe", "hash_md5": "D955F5778F8107C12788C7BEEC60E67A", "hash_sha1": "518718157FF4095CAB3D17F48AFF416A8206D0BA", "hash_sha256": "CF52CB67B516B938DE9B968240537F570626CCF3FBA6BF82D3A71FA3259CAE70", "hash_sha384": "E28A844338BAFE417C94BB278EEB68B80123FE09E1DCE595F3C8CEF8FBC9D9715FB6081606920C926956D33A7E24F4A5", "hash_sha512": "3453B7D225D70D132685CBA1467704BA655F3912B863568FA7EFC7806C307AA05AB56077FDBFCD217E11724BE0A99DACDDC6EA2C72E48C7187E504C1DD56D2F1", "hash_ssdeep": "49152:B5MIeRzLDHwxnm/pgsXKo63wsn8pJVtekw8Zo0iSRvDoI:QdgroV1", "hash_imp": "EC0E7AA6ECB803CE5B956D6DE2F52F04", "hash_pesha1": "5487969BC8498EB3BDBFA91C18F06387A29B3BF8", "hash_pe256": "A616167D9187172911B3A706711F5DEEB42F40AFC327BEEBE61D5725A0B108CA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "mt2.exe", "meta_original_filename": "mt2.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/cf52cb67b516b938de9b968240537f570626ccf3fba6bf82d3a71fa3259cae70/detection", "output": "Microsoft (R) Manifest Tool\r\r\nCopyright (c) Microsoft Corporation. \r\r\nAll rights reserved.\r\r\n\r\r\nUsage:\r\r\n-----\r\r\nmt.exe \r\r\n [ -manifest <manifest1 name> <manifest2 name> ... ]\r\r\n [ -identity:<identity string> ]\r\r\n [ < <[-rgs:<.rgs filename>] [-tlb:<.tlb filename>] [-winmd:<.winmd filename>]> -dll:<filename> > [ -replacements:<XML filename> ] ] \r\r\n [ -managedassemblyname:<managed assembly> [ -nodependency ] ]\r\r\n [ -out:<output manifest name> ]\r\r\n [ -inputresource:<file>[;[#]<resource_id>] ]\r\r\n [ -outputresource:<file>[;[#]<resource_id>] ]\r\r\n [ -updateresource:<file>[;[#]<resource_id>] ]\r\r\n [ -hashupdate[:<path to the files>] ]\r\r\n [ -makecdfs ]\r\r\n [ -validate_manifest ]\r\r\n [ -validate_file_hashes:<path to the files> ]\r\r\n [ -canonicalize ]\r\r\n [ -check_for_duplicates ]\r\r\n [ -nologo ]\r\r\n\r\r\nOptions:\r\r\n-------\r\r\n-manifest Used to specify manifests that need to be processed.\r\r\n At least one manifest name should follow this option.\r\r\n NOTE: There is no colon(:) after -manifest.\r\r\n \r\r\n<manifest1 name> <manifest2 name> ... \r\r\n Names of manifests to be processed and/or merged.\r\r\n Required if the -manifest option is used.\r\r\n NOTE: More than one manifest automatically indicates\r\r\n a manifest \"merge\" operation. In that case, an\r\r\n output specified by one of -out / -outputresource /\r\r\n -updateresource is mandatory.\r\r\n \r\r\n-identity:<identity string>\r\r\n The identity string contains the attributes of the\r\r\n assemblyIdentity element. The identity string is a\r\r\n set of comma separated name=value pairs starting\r\r\n with the \"name\" attribute's value. e.g.:\r\r\n \"Microsoft.Windows.Common-Controls,\r\r\n processorArchitecture=x86, version=6.0.0.0,\r\r\n type=win32, publicKeyToken=6595b64144ccf1df\".\r\r\n NOTE: Only the \"name\" attribute is not of the form\r\r\n \"name=value\" and it should be the first attribute in\r\r\n the identity string.\r\r\n\r\r\n-rgs: Takes the name of the .RGS (Registrar script).\r\r\n\r\r\n-tlb: Takes the name of the .TLB (Typelib file).\r\r\n\r\r\n-winmd: Takes the name of the .WINMD (Windows Runtime metadata file).\r\r\n\r\r\n-dll: Takes the name of the DLL: this represents the DLL\r\r\n that is eventually built from the .RGS, .TLB, and .WINMD\r\r\n files. Required if -rgs, -tlb, or -winmd is specified.\r\r\n\r\r\n-replacements:<.XML filename> \r\r\n Specifies the file that contains values for\r\r\n replaceable strings in the RGS file.\r\r\n\r\r\n-managedassemblyname:<managed assembly> [ -nodependency ] \r\r\n Generates a manifest from a managed assembly.\r\r\n -nodependency suppresses the generation\r\r\n of dependency elements in the final manifest.\r\r\n \r\r\n-out:<Output manifest name> \r\r\n Name of the output manifest. If this is skipped\r\r\n and only one manifest is being operated upon by the\r\r\n tool, that manifest is modified in place.\r\r\n\r\r\n-inputresource:<file>[;[#]<resource_id>]\r\r\n Input the manifest from a resource of type\r\r\n RT_MANIFEST with the specified id.\r\r\n resource_id is restricted to be a non-negative,\r\r\n 16 bit number.\r\r\n resource_id is optional and defaults to\r\r\n CREATEPROCESS_MANIFEST_RESOURCE_ID (winuser.h).\r\r\n\r\r\n-outputresource:<file>[;[#]<resource_id>]\r\r\n Output the manifest to a resource of type\r\r\n RT_MANIFEST with the specified id.\r\r\n resource_id is restricted to be a non-negative,\r\r\n 16 bit number.\r\r\n resource_id is optional and defaults to\r\r\n CREATEPROCESS_MANIFEST_RESOURCE_ID (winuser.h).\r\r\n\r\r\n-updateresource:<file>[;[#]<resource_id>]\r\r\n Equivalent to specifying both -inputresource and\r\r\n -ouputresource with identical parameters.\r\r\n resource_id is restricted to be a non-negative,\r\r\n 16 bit number.\r\r\n\r\r\n-hashupdate:<path to the files> \r\r\n Computes the hash of files specified in the file\r\r\n elements and updates the hash attribute with this\r\r\n value. The searchpath for the actual files\r\r\n specified in the file elements is specified\r\r\n explicitly. If <path to the files> is not\r\r\n specified, the searchpath defaults to the location\r\r\n of the output manifest.\r\r\n\r\r\n-makecdfs Generates Catalog Definition Files (.cdf) - used to\r\r\n make catalogs.\r\r\n \r\r\n-validate_manifest Validates to check syntactic correctness of a\r\r\n manifest and its conformance to the manifest schema.\r\r\n\r\r\n-validate_file_hashes:<path to the files> \r\r\n Validates the hash values of all the file elements.\r\r\n \r\r\n-canonicalize Does a C14N canonicalization of the output manifest\r\r\n contents.\r\r\n\r\r\n-check_for_duplicates Performs a check to see if the final manifest\r\r\n contains duplicate elements.\r\r\n\r\r\n-nologo Runs without displaying standard Microsoft copyright\r\r\n data. This may be used to suppress unwanted output\r\r\n in log files when running mt.exe as part of a build\r\r\n process or from a build environment.\r\r\n\r\r\nSamples:\r\r\n-------\r\r\n\r\r\n> To update the hash of an XML manifest:\r\r\nmt.exe -manifest 1.manifest -hashupdate -out:updated.manifest\r\r\n\r\r\n> To update the hash of an XML manifest while simultaneously producing the .cdf file:\r\r\nmt.exe -manifest 1.manifest -hashupdate -makecdfs -out:updated.manifest\r\r\n\r\r\n> To merge two manifests:\r\r\nmt.exe -manifest 1.manifest 2.manifest -out:merged.manifest\r\r\n\r\r\n> To merge two manifests and finally update the hash to produce the final merged manifest. \r\r\n> Note: The searchpath for the actual files specified in the file elements is specified explicitly.\r\r\nmt.exe -manifest 1.manifest 2.manifest -hashupdate:d:\\filerepository -out:merged.manifest\r\r\n\r\r\n> To generate a manifest from an RGS and/or TLB file:\r\r\nmt.exe -rgs:MSClus.rgs -tlb:MSClus.tlb -dll:foo.dll -replacements:replacements.manifest -identity:\"type=win32, name=Microsoft.Tools.SampleAssembly, version=6.0.0.0, processorArchitecture=x86, publicKeyToken=6595b64144ccf1df\" -out:rgstlb.manifest\r\r\n\r\r\n> To generate an XML manifest from a managed assembly:\r\r\nmt.exe -managedassemblyname:managed.dll -out:out.manifest\r\r\n> To suppress dependencies:\r\r\nmt.exe -managedassemblyname:managed.dll -nodependency -out:out.manifest\r\r\n\r\r\n> To extract manifest out of a dll:\r\r\nmt.exe -inputresource:dll_with_manifest.dll;#1 -out:extracted.manifest\r\r\n\r\r\n> To merge two manifests, one of them embedded in a dll, and embedding final merged manifest into another dll's resource:\r\r\nmt.exe -inputresource:dll_with_manifest.dll;#1 -manifest 2.manifest -outputresource:dll_with_merged_manifest.dll;#3\r\r\n\r\r\n> To update the manifest in a PE's resource (by updating the hashes of the file elements): \r\r\nmt.exe -updateresource:dll_with_manifest.dll;#1 -hashupdate:f:\\files\r\r\n\r\r\n> To validate the hash values of all the file elements:\r\r\nmt.exe -manifest 1.manifest -validate_file_hashes:\"c:\\files\"\r\r\n\r\r\n> To validate a manifest (i.e., to see if it conforms to the manifest schema):\r\r\nmt.exe -manifest 1.manifest -validate_manifest\r\r\n\r\r\n> To do a C14N canonicalization of a manifest (in order to get rid of spurious namespace prefixes (like \"dsig\")):\r\r\nmt.exe -manifest 1.manifest -canonicalize\r\r\n\r\r\n> To check for duplicate elements in a manifest:\r\r\nmt.exe -manifest 1.manifest -check_for_duplicates\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\mt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "muirct.exe-4F3F1AFF6DDC71C845062DFFE90EB018": { "file_name": "muirct.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\muirct.exe", "hash_md5": "4F3F1AFF6DDC71C845062DFFE90EB018", "hash_sha1": "2585964F7339C9DE463826AC5A9DAB97492E7608", "hash_sha256": "EE14DBE175CA3E12ABFAD038FCBFAD0E372B7AA90BFFF2D15F817E62CF0E9C12", "hash_sha384": "225FEB4AA651EEBAE8F32D2EBCE94C81BB202F15F0E6767EA9B767CADA3382754C27BEFE164D5AA879468644B7D1C500", "hash_sha512": "74D585F0BD019E17F96435A73A8B0869C9D7373EA714CDCEA65487626201F27B153CFC4DB970AF6802EFB632AE5160BAFDC7EA0CB716813FF567007FCCD89F75", "hash_ssdeep": "3072:QNgTElazX/Js5U2BE+mIgusP4wlppU6c5z/YOPD0AsYY8sennkzi00Xjc:KliX/OxlVgui44Twj", "hash_imp": "3064221FC9208288E0016821C0F93774", "hash_pesha1": "F6F682860A73B2E66E126CD2B096C56F84100AD0", "hash_pe256": "5E4C93EB2EDD878BAEBB3A8CE5D1DAB8B0138166778E4C3F13AB79F2E97BF543", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Muirct.exe MUI build tool", "meta_original_filename": "muirct.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Description\r\n\r\nMUIRCT (Muirct.exe) is a command-line utility for splitting a standard Win32\r\nportable executable file into a language-neutral (LN) file and a language\r\nspecific .mui file based on a resource configuration file (rc_config file).\r\nIn addition to this main functionality, MUIRCT provides options to extract or\r\ncalculate resource checksum information from one binary file and copy it to\r\nanother and to display the contents of the resource configuration data\r\ncontained in a given binary.\r\n\r\nMUIRCT usages\r\n\r\n1. Split binary into main binary and mui file based on rc_config file\r\n Muirct -q rc_config [-c checksum_file [-b LangID]] [-x LangID] [-g LangId]\r\n [-f] [-m] [-v level] source_file [output_LN_file] [output_MUI_file]\r\n\r\n2. Extract checksum from checksum_file and insert it in output_file\r\n Muirct -c checksum_file [-b LangID] -e output_file\r\n\r\n3. Calculate checksum based on checksum_file and insert it in output_file\r\n Muirct -c checksum_file [-b LangID] -q rc_config -z output_file\r\n\r\n4. Dump resource configuration data contents from input_file.\r\n Muirct -d input_file\r\n\r\nSwitches and arguments\r\n\r\n-b Specifies the language to be used when the checksum_file specified with\r\n -c contains resources in multiple languages. This switch can only be\r\n used in conjunction with the -c switch. The language identifier can be in\r\n decimal or hexadecimal format. MUIRCT fails if the checksum_file contains\r\n resources in multiple language and the -b is not specified or if the\r\n language specified by the -b switch cannot be found in the checksum_file.\r\n\r\n-c Specifies the input checksum_file from which to extract or calculate the\r\n resource checksum. Checksum_file must be a Win32 binary file containing\r\n localizable resources. If checksum_file contains resources for more than\r\n one language, the -b switch must be used to specify which of these\r\n should be used otherwise MUIRCT fails.\r\n\r\n-d Locates and displays embedded resource configuration data in the source\r\n file. When -d is specified, MUIRCT ignores all other switches.\r\n\r\n-e Extracts the resource checksum contained in the checksum_file provided\r\n with the -c switch and inserts it in the specified output_file. When -e\r\n is specified, MUIRCT ignores all switches other than the -c switch.\r\n In this case the checksum_file must be a Win32 binary file that contains a\r\n resource configuration data section with a checksum value.\r\n The output_file must be an existing LN file or .mui file.\r\n\r\n-f Enables creating a .mui file with the version resource being the only\r\n localizable resource. By default, MUIRCT does not allow this.\r\n\r\n-g Specifies the language ID to be included as the ultimate fallback language\r\n in the resource configuration data section of the LN file. If the resource\r\n loader fails to load a requested .mui file from the thread preferred UI\r\n languages, it uses the ultimate fallback language as its last attempt.\r\n The LangID value can be specified in decimal or hexadecimal format.\r\n For example English (United States) can be specified by -g 0x409 or\r\n -g 1033.\r\n\r\n-h | -? Shows the help screen.\r\n\r\n-m Specifies the version number to use when calculating the checksum for\r\n associating the output_LN_file and output_MUI_file.\r\n\r\n-q Specifies that the source_file is to be split into the output_LN_file and\r\n the output_MUI_file according to the rc_config file layout. The rc_config\r\n file is an XML formatted file that specifies which resources will be\r\n extracted to the .mui file and which will be left in the LN file. The\r\n rc_config can specify the distribution of resource types and individual\r\n named items between the output_LN_file and output_MUI_file.\r\n source_file must be a Win32 binary that contains resources in a\r\n single language otherwise MUIRCT fails. MUIRCT does not split the file\r\n if it is language neutral which is indicated by having only language ID\r\n value 0 in the file.output_LN_file and output_mui_file are the names of\r\n the language neutral and .mui file into which the source_file is split.\r\n These file names are optional. If they are not specified, MUIRCT\r\n appends the extensions .ln and .mui to source_file.\r\n Typically you should remove the \".ln\" extension before\r\n deploying the file. MUIRCT associates the output_LN_file and\r\n output_MUI_file by calculating a checksum based on the source_file\r\n name and file version and inserting the result into the resource\r\n configuration section of each output file. When used in conjunction\r\n with the -c switch, the -q switch takes precedence.\r\n If the rc_config file supplied with the -q switch contains a checksum\r\n MUIRCT ignores the -c switch and inserts the checksum value from the\r\n value, rc_config file into the LN and.mui files. If no checksum value is\r\n found in the rc_config, MUIRCT calculates the resource checksum based on\r\n the behavior of the -c switch.\r\n\r\n-v Specifies the level of verboseness for logging. Specify 1 to print all\r\n basic error messages and operation results. Specify 2 to also include the\r\n resource information (type, name, language identifier) included in the\r\n .mui file and LN file. The default is -v 1\r\n\r\n-x Specifies the language ID with which MUIRCT marks all resource types added\r\n to the resource section of the .mui file. The LangID value can be specified\r\n in decimal or hexadecimal format.\r\n For example English (United States) can be specified by -x 0x409 or\r\n -x 1033.\r\n-z Calculates the resource checksum based on the checksum_file specified\r\n with the -c switch (and optionally -b switch) and inserts it in the\r\n specified output_file. The output_file must be an existing LN file or .mui\r\n file.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\muirct.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "oleview.exe-29E1A12E2FC60FBA5FB91D4063108403": { "file_name": "oleview.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\oleview.exe", "hash_md5": "29E1A12E2FC60FBA5FB91D4063108403", "hash_sha1": "5EDC3DE0ADE3770460981EA9330159272EB7B66B", "hash_sha256": "2AD8F23459416A2C1EFA5E333C5FE90D26A3F67A37CE9986CC7A9384B8888BA5", "hash_sha384": "83F11A9722A422CD45D891BAD462D62E022A0475E44C88464D7A7D777E731A11E664E5764FF0D0EB9E613EA321724E3B", "hash_sha512": "BB0ABD5A2A42E5E18882CD6F9AE5E9DEFA6F54548136F0483036554992565D9989A6B6A20E256AAA59FFF67F699BE87FF812EC541FE376045A10ADC094C8BE8D", "hash_ssdeep": "3072:mF6DZ33CnS4/QMfz06qeAvd0D1vPD/Hb7f548Km9jDWa+1gQPQ9S8:mF6DmS4/zr0uaUFPDPXfv9jDcbPwp", "hash_imp": "4048276EA1E1519152D9F28F2E9E23FC", "hash_pesha1": "4236ECDD86426F88892699090DDC505327A87BE4", "hash_pe256": "93C489F6AE064E4BFB025794D063A32765458055971EE54DAE1D775879C4C702", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "OLE/COM Object Viewer", "meta_original_filename": "OLEVIEW.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2ad8f23459416a2c1efa5e333c5fe90d26a3f67a37ce9986cc7a9384b8888ba5/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\aclui.dll.mui": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\24b4HWNDInterface:5006f8": "Section", "\\BaseNamedObjects\\RotHintTable": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\oleview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\SYSTEM32\\MFC42u.dll", "C:\\Windows\\System32\\combase.dll" ], "runtime_window_title": "OLE/COM Object Viewer" }, "PackageEditor.exe-0FF1FE44A592150E689460B7D6A4E9BE": { "file_name": "PackageEditor.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\PackageEditor.exe", "hash_md5": "0FF1FE44A592150E689460B7D6A4E9BE", "hash_sha1": "DA1470BA906262CF1818EDD02FCEC0DD007E46FE", "hash_sha256": "36E83BA30DF4D43E6BAA73DBF2728349662CB40C7E7BB4A104C32C6677D3A967", "hash_sha384": "E4D2864FF3E913A65C620399FFF396E48A2EED868E5A7FDC5C2AA43A071EA72B4A4D8C270CDE5B4993A65DE20DF85BFB", "hash_sha512": "4F0D577805E2212C90D0F79DB84209B897E4BF33D306483A3DF9966EBFF69B9BB506D94FE8F1758E85384F6BD216EAAC4E94962C8600730EAA98C32A2B4C782B", "hash_ssdeep": "384:QO8n8mWa19kkrF8Q5jAH26xN6yAdYQKF0/dLCl+jRdgRFWHsWD:QdGl0FhUzQj/dLClyd1", "hash_imp": "n/a", "hash_pesha1": "454DA625EF606218A8ACBF3E5729873ED776674C", "hash_pe256": "18287FFC7EEE1B376D69CBDD9B530D7A0C5151442F7535A33755A563E22EAD52", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\PackageEditor.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": " ", "meta_original_filename": "PackageEditor.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/36e83ba30df4d43e6baa73dbf2728349662cb40c7e7bb4a104c32c6677d3a967/detection", "output": "Microsoft (R) PackageEditor Tool\r\nCopyright (C) 2018 Microsoft. All rights reserved.\r\nLog file is located under: C:\\Users\\user\\AppData\\Local\\Temp\\PackageEditor\\Logs_2\\Log.txt\r\n\r\nVersion 10.0.0.0\r\n\r\nPackageEditor\r\n\r\nUsage: PackageEditor.exe [options] [command]\r\n\r\nOptions:\r\n -h|-? For help with a specific command.\r\n -version Show the tool's version\r\n\r\nCommands:\r\n createDelta -- Create a delta package from two package versions.\nUsage: \n PackageEditor createDelta -bp <baseline package> -up <updated package> -dp <delta package>\n PackageEditor createDelta -bb <baseline blockmap file> -bn <baseline package full name> -up <updated package> -dp <delta package>\n\r\n update -- Update a baseline package with a delta package.\nUsage: \n PackageEditor update -appendDelta -bp <baseline package> -dp <delta package>\n\r\n updateEncrypted -- Update an encrypted baseline package with an updated package.\nUsage:\n PackageEditor updateEncrypted -appendDelta -bep <baseline package> -dap <delta appended package>\n\r\n updateManifest -- Update the manifest within a package\nUsage:\n PackageEditor updateManifest -p <unencrypted package> -m <updated manifest>\n PackageEditor updateManifest -ep <encrypted package> -m <updated manifest>\n\r\n\r\nExamples:\r\n PackageEditor createDelta -bp <baseline package> -up <updated package> -dp <delta package>\r\n PackageEditor update -appendDelta -bp <baseline package> -dp <delta package>\r\n PackageEditor updateEncrypted -appendDelta -bep <baseline package> -dap <delta appended package>\r\n PackageEditor updateManifest -p <unencrypted package> -m <updated manifest>\r\n\nNote:\r\nFor help with a specific command, provide the -? or -h option, ex.:\r\n PackageEditor.exe createDelta -?\r\n\r\n", "error": "Unrecognized command or argument 'help'\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\PackageEditor.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "pktextract.exe-D0612515780ADE991F2E30429083642C": { "file_name": "pktextract.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\pktextract.exe", "hash_md5": "D0612515780ADE991F2E30429083642C", "hash_sha1": "850BD37F693A2AFFDD7AE51B45B3FE5D7FAD8736", "hash_sha256": "CDE9A01633B67494D37B9BD50472A72E87BB68E63C8007209E98EDF4C5CD1EA8", "hash_sha384": "DF01CA68EFFC2FA5CF334977EE0BAA6262FAF55717D4945C14E0C9F738E49D9577EB509AB0BEEDD068BF39FE738272CE", "hash_sha512": "251ABE1A055B9C804FECE0C60E677D9C22C70AA3150D6AED5A1C6F56A20E06FF886BACEF375DD0294171AD85E5A562DAFD12DFF61F21D10B537B6EE57C530366", "hash_ssdeep": "384:rsmdmFdlKPw1dTW1wDYAz5wxmQUUFWvf/WDwGy1cd4JeRlF:rso8D3VWLAz5FUKmK/", "hash_imp": "3717DCE56024B195AEC6B75312C68675", "hash_pesha1": "795711202CE454F3FC5786D4FC1345A26C4BA005", "hash_pe256": "971E9EF2AE6A4AFC63DDF9C8C9AD6D23F73520A47564D007D461E8FE145DC514", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Side-By-Side Public Key Token Extractor", "meta_original_filename": "pktextract.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Microsoft (R) Side-By-Side Public Key Token Extractor\r\nCopyright (C) Microsoft Corporation. All Rights Reserved\r\n\r\nExtracts public key tokens from certificate files, in a format\r\nusable in Side-By-Side assembly identities.\r\n\r\nUsage:\r\n\r\nC:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\pktextract.exe <filename.cer> [-quiet] [-nologo]\r\n", "error": "Unrecognized parameter --help\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\pktextract.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "pvk2pfx.exe-6E300F27AA19FCD62D309F6622107B68": { "file_name": "pvk2pfx.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\pvk2pfx.exe", "hash_md5": "6E300F27AA19FCD62D309F6622107B68", "hash_sha1": "DC2C2AF0251EF2A071CA9998774BB417F538A1D5", "hash_sha256": "8BE7F023BA93DF9E2BD2D210577C82BE3B619267F3F643AC0349B596E89F7035", "hash_sha384": "6E3D55B6E379D82E5096D07978970397466B7715D94792B876D1B80C3A68284ED3228A44512B42172E27019A3A98AB0D", "hash_sha512": "F55E55FBFD640599809E835EF5DD30D733DF18C0A35E8BE6D9D06F3801CED182463F88E70EB4638DAB55FEBBA1C022A4C029833080913CFFE126F4DE1390D992", "hash_ssdeep": "384:FKfOX7OXf+twNkWuPhMpzntKKTUzjf36cMD+ptjvraWLkWkKOXkwGyq4JeRlFP:AfOXyv+5BSnKUUqLGvr3qKOUC", "hash_imp": "DAF4A77F27D21C03E5490E485C8C787A", "hash_pesha1": "E8AA8A25BFB83883C88A406F449F7012B500ACA4", "hash_pe256": "41BD13834C7CB1B67EC54C1E55D36CCA5F87E8023EADA1EBFAD1A39D84A065B9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PVK/SPC to PFX file converter", "meta_original_filename": "pvk2pfx.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "\r\nUsage:\r\n pvk2pfx -pvk <pvk-file> [-pi <pvk-pswd>] -spc <spc-file>\r\n [-pfx <pfx-file> [-po <pfx-pswd>] [-f]]\r\n\r\n -pvk <pvk-file> - input PVK file name.\r\n -spc <spc-file> - input SPC file name.\r\n -pfx <pfx-file> - output PFX file name.\r\n -pi <pvk-pswd> - PVK password.\r\n -po <pfx-pswd> - PFX password; same as -pi if not given.\r\n -f - force overwrite existing PFX file.\r\n\r\n if -pfx option is not given, an export wizard will pop up. in\r\n this case, options -po and -f are ignored.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\pvk2pfx.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "rc.exe-E5396AF565EB6DC475336F55ABBD0DAB": { "file_name": "rc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\rc.exe", "hash_md5": "E5396AF565EB6DC475336F55ABBD0DAB", "hash_sha1": "D9369DB8E4A0582B750A0E513E25F25E849AA05C", "hash_sha256": "D48522470FA7DCCA448C79781B8E7091CE16521DCEB2AB97BF0F62E7DFD137BC", "hash_sha384": "BF487AFD7B1F09C6759EE7C78FD48A91E76617790991B2C346E6787E0FC9AAEE17AF192B61B429FCD2408B3BE933DA1B", "hash_sha512": "9F13426F7BB31E05E79BEB3657F73FEB5BC270569D30426508A949542BF7A2B54BF9766EDFAA97B126D95627DE238CEDEE91719292715CFB810036E3B2B1F59A", "hash_ssdeep": "1536:vbj2+DH2P19sKLfI67+rNlhK7BI3Shv6FUXui:f2+DH2JbFgfK7BI32v6FU+i", "hash_imp": "14364FD8F9FE355C6DC3AB49D1F37AB6", "hash_pesha1": "6351A3B0586B7C2E5A6F901019D8D7D4E2A88BDA", "hash_pe256": "B0F15BF5F23170E50755C4446A1F6158E4D82350FADDECF1F58118CD84169465", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Resource Compiler", "meta_original_filename": "rc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d48522470fa7dcca448c79781b8e7091ce16521dceb2ab97bf0f62e7dfd137bc/detection", "output": "\r\nMicrosoft (R) Windows (R) Resource Compiler Version 10.0.10011.16384\r\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\r\n\r\r\nUsage: rc [options] .RC input file\r\r\nSwitches:\r\r\n /r Emit .RES file (optional)\r\r\n /v Verbose (print progress messages)\r\r\n /d Define a symbol\r\r\n /u Undefine a symbol\r\r\n /fo Rename .RES file\r\r\n /l Specify default language using language identifier\r\r\n /ln Specify default language using language name\r\r\n /i Add a path for INCLUDE searches\r\r\n /x Ignore INCLUDE environment variable\r\r\n /c Define a code page used by NLS conversion\r\r\n /w Warn on Invalid codepage in .rc (default is an error)\r\r\n /y Don't warn if there are duplicate control ID's\r\r\n /n Append null's to all strings in the string tables\r\r\n /fm Localizable resource only dll file name\r\r\n /q RC Configuration file for the resource only DLL\r\r\n /g Specify the ultimate fallback language using language identifier\r\r\n /gn Specify the ultimate fallback language using language name\r\r\n /g1 Specify if version only MUI file can be created\r\r\n /g2 Specify the custom file version for checksum in MUI creation\r\r\n /nologo Suppress startup logo\r\r\n /sl Specify the resource string length limit in percentage\r\r\nFlags may be either upper or lower case\r\r\n\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\rc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "regwinmd.exe-4F0223C0E2506493005660D462AD515E": { "file_name": "regwinmd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\regwinmd.exe", "hash_md5": "4F0223C0E2506493005660D462AD515E", "hash_sha1": "4C36553740CCC4FACA71A1905B11810BD57B6EAA", "hash_sha256": "88DFB31A2F8141701E8177890ABC79F03E0F9FD50E50CD83070BE56356CCC019", "hash_sha384": "B28D1444EFA86B15E176FFC5CD482BD742C3317B377F92540496D059FB322A9E8336D3F69A8B2E23444C56D609EB47AA", "hash_sha512": "4C9806AD9F3B13C0C7DCC39ADF63C427BE9CFC2E96AE1588E567452BD7BFE7F325AB78E2B8974AE3926115FCB73278DCA97DCA335445ED7AF11E5BCF13437EBC", "hash_ssdeep": "3072:Rk7CaM0aI8oajRqXO03KHcYwfB4z6iRoFEPBpaYiAqXX99jG2+lNGNvBfE94hWuF:Rk4I8ov4zTR3aeuXHi2+lKeqS+", "hash_imp": "0B45FAD381CB684B6564C6C3384A9401", "hash_pesha1": "E8DF9553EF97DBA3B79C7BC65E6785C85E72FDA6", "hash_pe256": "8717047E857151C34792D9A51E8CEEE73E36E3B1523EF538431293C8051812A8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft REGWINMD Utility", "meta_original_filename": "regwinmd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Microsoft(R) RegWinMD Utility Version 10.0.0.\r\r\n\r\nUsage: C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\regwinmd.exe [-/][Switch][:][Value]\r\n\r\nWhere Switch is one of the following: \r\n -?: Print this help\r\n -h: Print this help\r\n -i: Input filename (or directory) - process this metadata file (or files)\r\n -metadata_dir: Metadata Directory - Directory which contains the system directory for Windows Metadata files\r\n -o: Output file name - put manifest fragment in this file\r\n -osmanifest: Generate a windows component manifest fragment instead of an appx manifest fragment \r\n", "error": "REGWINMD : error RMD5003: Unrecognized command line switch: --help.\r\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\regwinmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "signtool.exe-402225631FAD87125901B9A1E67625AF": { "file_name": "signtool.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\signtool.exe", "hash_md5": "402225631FAD87125901B9A1E67625AF", "hash_sha1": "58F8EC5FFD1173ED42A430C0B20DA2E0CE1073B2", "hash_sha256": "2AC86024B1FE60EDC32F43AC6C21FC94999A023F8A1076E43C0806AC55EC7E1E", "hash_sha384": "5459C9E0D7FBE896FB2E0A4B06758D7DAF0EDAC5CCFE06855121BAA238A37C66BCB5D46F5BE74F7EAF76DB251C1DFADA", "hash_sha512": "DD729EA193841E3774F86B533B0E006855C8E23E46BD64B2D71A7F2A60CF27F2C5460E341560CB21C289B350CA1273595642C1F0A8DAFA54F0DBC1E4ED3621E6", "hash_ssdeep": "6144:xbbCbwJnuoPVeqVs82NIZ8x4xjKEv0/P6ut4dx3eaeUe0:FrE4VG81Y4xjb4tz", "hash_imp": "DF3F418443D8095A5F121467E2031EEC", "hash_pesha1": "F8256ADC7B2CB61AEEAB85B2B0C80D360A5FDD37", "hash_pe256": "E3A418FA667676B819B96C4EFC6A1A8E06CE83050C82DA65A3A5979190F2344B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Authenticode(R) - signing and verifying tool", "meta_original_filename": "SIGNTOOL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/2ac86024b1fe60edc32f43ac6c21fc94999a023f8a1076e43c0806ac55ec7e1e/detection", "error": "SignTool Error: Invalid command: --help\r\r\nUsage: signtool <command> [options]\r\n\r\n Valid commands:\r\n sign -- Sign files using an embedded signature.\r\n timestamp -- Timestamp previously-signed files.\r\n verify -- Verify embedded or catalog signatures.\r\n catdb -- Modify a catalog database.\r\n remove -- Remove embedded signature(s) or reduce the size of an\r\n embedded signed file.\r\n\r\nFor help on a specific command, enter \"signtool <command> /?\"\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\signtool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "StoreUploader.exe-E40460FB29D0454B06C959EE030289E2": { "file_name": "StoreUploader.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\StoreUploader.exe", "hash_md5": "E40460FB29D0454B06C959EE030289E2", "hash_sha1": "7C9FEA76DAA83EF6777A5A620DAE58A9CF35FC54", "hash_sha256": "1D8FBB29BB811FA0719A57D2F5EA74780737BCE0C37988A3EBE59E32FE15BDD1", "hash_sha384": "D3D226CA4CA6562C7F2AB69CDB7EFE29BF34E0CF8AACE66663B9D73BB2C5EF239EC7B29AB0472264C2C8D47D1EB7559A", "hash_sha512": "64344A5BE081D358DF6B5787719A7E170D7B2DBC4A76988FB79BAFE529E1D87A7410CF1CEBE346C250210F466CE9531DAB8011E05FAC983B561DB426CC9FAAFB", "hash_ssdeep": "384:mdSyoWQcWl3h0iAJUkwEADVTc2y9yWPUWf:mg1jl3WKBT+x", "hash_imp": "n/a", "hash_pesha1": "DD171185495DAE919F826F156976FF26BF4C54A5", "hash_pe256": "75FFD5666AEE71D643152A768CE689542CE5643AECF32BB28088FB8EB657A2AE", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\StoreUploader.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": " ", "meta_original_filename": "StoreUploader.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1d8fbb29bb811fa0719a57d2f5ea74780737bce0c37988a3ebe59e32fe15bdd1/detection", "output": "Microsoft (R) StoreUploader Tool\r\nCopyright (C) 2018 Microsoft. All rights reserved.\r\nVersion 10.0.0.0\r\n\r\nStoreUploader is a tool to submit packages to the store efficiently.\n\r\n\r\nUsage: StoreUploader.exe [options]\r\n\r\nOptions:\r\n -h Shown the usage\r\n -version Show the tool's version\r\n -i Runs the tool in interactive mode.\r\n -cd Specifies that the tool should attempt to upload the full package if the delta extraction step fails.\r\n -np Runs the tool in serial mode (no parallelism).\r\n -v Enables verbose output of messages.\r\n -c Path to the config file containing Store parameters and information about the packages to upload.\r\n -td Directory where MakeAppx.exe, ComparePackage.exe, and PackageEditor.exe reside.\r\n -l Directory under which the tool should save the logs.\r\n\r\nExamples:\r\nStoreUploader.exe -c <path to config file> [-i] [-cd] [-np] [-td <sdk tools directory>] [-l <output logs directory>] [-v]\r\nStoreUploader.exe -c C:\\StoreUploader\\UploadJob.config -l C:\\StoreUploaderLogs\r\n\r\n", "error": "Unrecognized command or argument 'help'\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\StoreUploader.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "TB3x.exe-ABE2CE6E0609B472A3693C143B65D729": { "file_name": "TB3x.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\TB3x.exe", "hash_md5": "ABE2CE6E0609B472A3693C143B65D729", "hash_sha1": "30916C17483635406628E045CF96D28623823975", "hash_sha256": "002310FBD6E1C459164DC8A9C4169F639D35E4FA0901179DF891D7443A311D21", "hash_sha384": "0DB0D8EBD0DA371288E7CDF40D0F4B385EAB3B87BE2DB5C832AD3A3838B49EE76901D2646475198D58F0AD4A1FFCCAF4", "hash_sha512": "65C0581AAB43D6833A17A273E689E25D10202E5949DFD371968B1F3D84DE052F33247AD54F5514BC908362B61DC046311549572692104FB29910E4F7CF22BC15", "hash_ssdeep": "3072:bPhOf+7daDzoduWcGBfDhUQLJoHIKnhm7oaLJ0Mmfa:DhOEdaDzo3cgfDhWXM", "hash_imp": "ADA44F727467671751E405C611F7D044", "hash_pesha1": "B28629A419B2A67E3BFC803CE15321E105B1977E", "hash_pe256": "FAF3FFFA9E80CDD96AFA77AA15234E6D426EAE594ABEFAF01F413EB752527ABB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TAPIBrowser MFC Application", "meta_original_filename": "TAPIBrowser.EXE", "meta_product_name": "TAPIBrowser Application", "meta_file_version": "1, 0, 0, 1", "meta_product_version": "1, 0, 0, 1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 2000", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(RWD) C:\\Windows\\System32\\tapi3.dll": "File", "(R-D) C:\\Windows\\System32\\stdole2.tlb": "File", "(RWD) C:\\Windows\\System32\\quartz.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\TB3x.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll" ], "runtime_window_title": "TAPI3xBrowser" }, "topoedit.exe-6B3CB99193E072B66142F90749BD4124": { "file_name": "topoedit.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\topoedit.exe", "hash_md5": "6B3CB99193E072B66142F90749BD4124", "hash_sha1": "05F8F3F7ABA0F1CDA3E7DBFA2F89DB7AD9D67BF1", "hash_sha256": "39A140248097D6B8025D99CE6561ADE63EA0AED409CF92778B417F631CB51C83", "hash_sha384": "F489237246C618512D67C568ACA1EE4D7CC0FAC3D4C4442696C56265F05645C4EBEBBBA5B39642238A9874ED95757199", "hash_sha512": "DE1AAB94C926C5E7610E7280A4D157CE9ECE1EDEC13BDC2990D6BB8AFB63596705A1984986B8F6631B43C18E5782322A69E96A83A2A52394DE20081915E8EE07", "hash_ssdeep": "3072:dZjjKN/b8jW1XWSkc7UzCkEw2gYf+3BJik:3j+l8gHPUzVB2gYfSZ", "hash_imp": "1D52E60E68CA8B61DB2A34C1FCD5C6FC", "hash_pesha1": "F574CE100ABFD9BF4914DAFF838924DEFD5BB3A0", "hash_pe256": "CEF8DE712EB810029D09217A0E7BDD072D31DDE81AF5A86169467F6CC722E54F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Topology Editor", "meta_original_filename": "topoedit.exe", "meta_product_name": "Media Foundation Topology Editor", "meta_company_name": "Microsoft", "meta_file_version": "1.0.0.1", "meta_product_version": "1.0.0.1", "meta_language": "English (United States)", "meta_legal_copyright": "(c) Microsoft. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/39a140248097d6b8025d99ce6561ade63ea0aed409cf92778b417f631cb51c83/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\mferror.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\msxml6r.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netmsg.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\topoedit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\tedutil.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\MFPlat.DLL", "C:\\Windows\\SYSTEM32\\MF.dll" ] }, "tracefmt.exe-A02AC40EA76F0B6AFE2C9FF49BB15692": { "file_name": "tracefmt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\tracefmt.exe", "hash_md5": "A02AC40EA76F0B6AFE2C9FF49BB15692", "hash_sha1": "8492C2DBB8DE5E2C9F41C80DBAB597FF4BABF5BA", "hash_sha256": "6C84033B6A0DF638BB5B37A66B6B4597A140CB0778DD4781EEDD3752DE8E92AB", "hash_sha384": "92AD6697AB354337A12369CE2093F93BCA6FCC13A8E4FE4E3DD1AA1CFFA4074796328A0F384B8ABBCA9A45DB6BDE1DD3", "hash_sha512": "DAD103D76C9E7544D8F679634C2E636BB6B3C5CEC2C12D2632CDF7F95D8B6A06E90F1BE4D8C44A8A1DD4DC0F93513D8221E92CB91BAE53A94F9D4142F9676ABF", "hash_ssdeep": "6144:3acUUG1ZxzFFsPaA7VnbqJ0/HELlxjpOMUoikXVcA9gIQ/yDsGX03EcROpyVKQ3x:qr5JvsyA7VnOJ0/HELlxjpEz/2DOP", "hash_imp": "5983ECEE2610945955CBB48DB42E1DDD", "hash_pesha1": "9F0DBAEB105B7C56C207BBD66B4EA8186BA774E3", "hash_pe256": "873AAD758144EC92EFDB35221DF79C8EC1A12395D9288C969E18368C8B044ED5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Format Message traces to text", "meta_original_filename": "TraceFmt.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nMicrosoft (R) TraceFmt.Exe (10.0.19041.1)\r\n Microsoft Corporation. All rights reserved.\r\n\r\nTracefmt formats the messages in trace logs (.etl files) and creates a text\r\nfile of the formatted trace messages. You can specify a TMF file with the\r\nformatting instructions for WPP events, or you can specify an image file and\r\nTracefmt finds the private PDB file for that image and reads the formatting\r\ninstructions from the PDB file.\r\n\r\nUsage:\r\n\r\ntracefmt [<EtlFiles...>] | -rt [<SessionName>]\r\n\r\nParameters:\r\n\r\n<EtlFiles...> - Format a ETW trace file (.etl). Can specify multiple files\r\n separated by spaces.\r\n-rt <SessionName> - Format messages from the named real-time trace session.\r\n Default session name=\"NT Kernel Logger\".\r\n-tmf <TMFFiles> - Trace message format file. Default=\"Default.tmf\".\r\n-i <ImageFiles> - Finds PDBs for the images and creates TMFs.\r\n Separate images with ';'.\r\n-r <SymbolPath> - Path to private PDB symbol files. Default is\r\n \"%_NT_SYMBOL_PATH%\" (if defined) or\r\n srv*\\\\symbols\\symbols otherwise.\r\n-p <TmfPath> - TMF file directory. Without -i, it's an existing directory.\r\n With -i, it's the path for the TMF that tracefmt creates.\r\n-pdb <PdbPath> - Path to one more more PDB files. Multiple files should be\r\n seperated by ';'.\r\n-manpath <Path> - Path to one or more manifest repository folders. Manifests\r\n will be automatically loaded from these folders as needed.\r\n Multiple folders should be separated by ';'. The files in\r\n the folder must be named GUID.man, using the provider's\r\n decode GUID with no '{', '}', or '-' characters. (Use the\r\n traceman tool to import manifests into the repository.)\r\n-man ManFile - Path to an XML manifest from which to load decoding data\r\n for manifest-based ETW events (TdhLoadManifest).\r\n-bin DllFile - Path to a DLL file from which to load decoding data for\r\n manifest-based ETW events (TdhLoadManifestFromBinary).\r\n-h | /? - Displays help.\r\n\r\nOptions:\r\n\r\n-o - Output file name, e.g. \"FormattedData.txt\".\r\n-csv - Output in CSV format.\r\n-csvheader - Adds columns headings to CSV file.\r\n-hires - High resolution timestamp.\r\n-utc | -gmt - Do not convert UTC timestamps to local time.\r\n (Affects timestamps in event header and event content.)\r\n-timeZoneSuffix - Include a suffix on timestamps with a known time zone.\r\n-sortableTime - Use \"yyyy-mm-ddThh:mm:ss\" format for time stamps.\r\n-noFileTimeUtc - Treat event content FILETIME values as having an unknown\r\n time zone. (Default assumes FILETIME is always UTC.)\r\n-display - Print formatted traces messages to console and output file.\r\n-displayonly - Print formatted traces messages only to console (no output\r\n file).\r\n-nosummary - Suppress summary file.\r\n-summaryonly - Suppress output file.\r\n-noprefix - Omit the trace message prefix.\r\n-ods - Send trace messages to the OutputDebugString.\r\n-trace - Print tracefmt actions to the console as they occur.\r\n-v - Verbose console output.\r\n-cp <codepage> - Generated text files should use the specified encoding.\r\n Valid codepage names include \"utf8\", \"utf16\", \"ansi\".\r\n Default is the current ANSI code page.\r\n-skipNoFormat - Filter out events without format strings.\r\n-skipTmfWpp - Filter out TMF-based WPP events.\r\n-preferJson - When possible, decode events as JSON.\r\n TMF-based WPP will still decode as text.\r\n-jsonMeta <flags> - Control which values to include in the JSON \"meta\" suffix.\r\n Default is 0xff3f. Set to 0 to disable the \"meta\" suffix.\r\n Values will often be omitted from suffix if zero or null.\r\n Flags (in hex): provider=1, event=2, time=4, cpu=8,\r\n pid=10, tid=20, id=40, version=80, channel=100, level=200,\r\n opcode=400, task=800, keywords=1000, tags=2000,\r\n activity=4000, relatedActivity=8000, ktime=10000,\r\n utime=20000, ptime=40000, attribs=80000.\r\n\r\nDefault values:\r\n\r\n <EtlFile> C:\\Logfile.Etl\r\n <SessionName> \"NT Kernel Logger\"\r\n <OutputFile> FmtFile.txt (local directory)\r\n <Summary file> FmtFile.sum (local directory)\r\n <TMFFile> default.tmf (local directory)\r\n <Prefix> \"[%9!d!]%8!04X!.%3!04X!::%4!s! [%1!s!]\"\r\n <SymbolPath> %_NT_SYMBOL_PATH% or srv*\\\\symbols\\symbols\r\n\r\nChange Prefix by setting the TRACE_FORMAT_PREFIX environment variable.\r\n\r\nIf neither -tmf nor -p are specified, tracefmt uses the value of the\r\n%TRACE_FORMAT_SEARCH_PATH% environment variable.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\tracefmt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "tracelog.exe-7759D9CA6337F1CD61747BC06E339097": { "file_name": "tracelog.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\tracelog.exe", "hash_md5": "7759D9CA6337F1CD61747BC06E339097", "hash_sha1": "23242F5A39ED211FD31D7F63135FF7E6A2FB98BE", "hash_sha256": "E74D328C9F8472BB64678E045B1FCDAF8EB42D088FB5BC5D84755DE82910C3CF", "hash_sha384": "88C668B0343129A20FD889039DC9A759660A196993F55BF31720E2A4C04A742654795202F35838CCC44D8245224DD440", "hash_sha512": "2928B3B739706C90C27AF85B8A6270704A87CD2C2A8B4B85F4D7799680DC607CFD069494D0B1AF6D9AD3156005F2DD5E1A23859D6315A9FC2F79947A9F1882BD", "hash_ssdeep": "3072:6kHpo4DmTmpFxxoFOXfefPMkGzkVSxhibS:6M24DmTmfefkkLVO", "hash_imp": "5B8DB86FFD8BA51B7D897FD5A9118F0E", "hash_pesha1": "243BBCD8386BDAE2D455CC3BF13CE4C10169BC3C", "hash_pe256": "9B4DC7CB9E96E24DB7F19F723A36787585ACBD89EAED20D0363973D097FB4CD0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Trace control utility", "meta_original_filename": "tracelog.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "ERROR: no action specified\r\n\r\nMicrosoft (R) tracelog.exe (10.0.19041.1)\r\n Microsoft Corporation. All rights reserved.\r\n\r\nUsage: tracelog [actions] [options] | [-h | -help | -?]\r\n\r\nActions can be specified as \"-action LoggerName\" or \"-action=LoggerName\".\r\n\r\nActions:\r\n\r\n-start <LoggerName> Starts the <LoggerName> trace session.\r\n-stop <LoggerName> Stops the <LoggerName> trace session.\r\n-update <LoggerName> Updates the <LoggerName> trace session.\r\n-enable <LoggerName> Enables providers to the <LoggerName> session.\r\n-enableex <LoggerName> Enables providers to the <LoggerName> session.\r\n-timeout <n> Forces enable to be synchronous (timeout value\r\n specified in milliseconds).\r\n-capturestate <LoggerName> Request provider to log state information to the\r\n <LoggerName> session.\r\n-incrementfile <LoggerName> Increment to the next file for the <LoggerName> trace\r\n session (EVENT_TRACE_FILE_MODE_NEWFILE should be enabled)\r\n-systemrundown <LoggerName> Request SystemTraceProvider to log rundown\r\n information to the <LoggerName> session.\r\n-disable <LoggerName> Disables providers for the <LoggerName> session.\r\n-flush <LoggerName> Flushes the <LoggerName> active buffers.\r\n-addautologger <LoggerName> Creates the registry keys for the <LoggerName>\r\n autologger session. Provide the session GUID using\r\n the -sessionguid parameter.\r\n-remove GlobalLogger Removes the registry keys that activate the\r\n GlobalLogger.\r\n-enumguid Enumerate registered trace guids.\r\n-enumguidex [#<guid>] Enumerate registered trace guids.\r\n-q <LoggerName> [-lp]\r\n Query status of <LoggerName> trace session.\r\n Use -lp to list providers enabled to the session.\r\n-l [-lp] List all trace sessions.\r\n Use -lp to list providers enabled to each session.\r\n-h, -?, -help Display usage information.\r\n\r\nOptions:\r\n\r\n-b <n> Sets buffer size to <n> kilobytes.\r\n-min <n> Sets minimum buffers.\r\n-max <n> Sets maximum buffers.\r\n-f <name> Log to file <name>.\r\n-kb Use kilobytes for log file size.\r\n-append Append to file.\r\n-prealloc Pre-allocate.\r\n-seq <n> Sequential logfile of up to n megabytes.\r\n-cir <n> Circular logfile of n Mbytes.\r\n-newfile <n> Log to a new file after every n megabytes.\r\n File name must contain %d.\r\n-UseSystemTime Use System Time clock.\r\n-UsePerfCounter Use Performance Counter clock.\r\n-UseCPUCycle Use CPU Cycle Count clock.\r\n-ft <n> Set flush timer to n seconds.\r\n-QpcDelta Turn on QPC Delta tracking between Container and Host.\r\n Only supported on Start calls on some OS versions.\r\n-bt <n> Specify that n buffers should be filled before the\r\n system begins flushing them.\r\n-paged Use pageable memory for buffers.\r\n-addtotriagedump Write out buffers for triage memory dumps.\r\n-noprocess Disable Process Start/End tracing.\r\n-nothread Disable Thread Start/End tracing.\r\n-nodisk Disable Disk I/O tracing.\r\n-nonet Disable Network TCP/IP tracing.\r\n-fio Enable file I/O tracing.\r\n-pf Enable page faults tracing.\r\n-hf Enable hard faults tracing.\r\n-img Enable image load tracing.\r\n-cm Enable registry calls tracing.\r\n-um Enable Process Private tracing.\r\n-guid <file> Enable tracing for providers specified in <file>.\r\n The file must be formatted as:\r\n ; comment line\r\n guid1;matchanykeyword;level\r\n guid2;matchanykeyword;level\r\n #<guid> Enable tracing for a provider by guid.\r\n *<name> Enable tracing for a provider by guid from hashed\r\n name.\r\n-rt Enable tracing in real time mode.\r\n-kd Enable tracing in kernel debugger.\r\n-level <n> Enable providers with specified level.\r\n-matchanykw <n> Enable providers with specified MatchAnyKeyword.\r\n-matchallkw <n> Enable providers with specified MatchAllKeyword.\r\n-enableproperty <flags> Enable providers with specified EnableProperty\r\n flags.\r\n-sourceguid #<guid> Pass <guid> to the enabled providers' callbacks\r\n as the SourceId.\r\n-flag <n> Enable Flags passed to the providers.\r\n Note: Flags have been replaced by MatchAnyKeyword.\r\n-eflag <Name+Name+...> Enable kernel events by name.\r\n <n> <eflag...> Enable kernel events using <n> extended flags.\r\n Help Print the list of named kernel events that can be\r\n enabled.\r\n-dpcisr Enable kernel events for DPC/ISR analysis.\r\n-ls Generate Local Sequence Numbers.\r\n-gs Generate Global Squence Numbers.\r\n-heap Use this for Heap Guid.\r\n-critsec Use this for CritSec Guid.\r\n-pids <n> <pid1 pid2 ... > Tracing for Heap and CritSec for <n> processes.\r\n-buffering Enable tracing in buffering mode.\r\n-secure Enable tracing in secure mode.\r\n-sessionguid Autologger session GUID Registry value.\r\n-lowcapacity Don't create buffers per processor.\r\n-stackwalk <Events> Enable stack walking for specified events.\r\n-hybridshutdown [stop|persist]\r\n Control hybrid shutdown logger behavior.\r\n-systemlogger Logger can receive SystemTraceProvider events.\r\n-ProfileSource <src>|Help Configure profiling source to use.\r\n Use Help to see the list of available sources.\r\n-SetProfInt <n> <src> Configure profiling interval for specified\r\n source.\r\n-Pmc <Ctr1,Ctr2,...>:<Name+Name+...>\r\n Configure PMC counter sampling on kernel events.\r\n Use -ProfileSource Help for a list of counters.\r\n Use -eflag Help for a list of kernel events.\r\n-independent Enable independent mode on the trace session.\r\n-ExeFilter <Executable names>\r\n Specify an Executable name filter with names\r\n separated by semi-colon.\r\n-PkgIdFilter <Package Full Name>\r\n Specify Package id filter(s) separated by\r\n semi-colon.\r\n-PkgAppIdFilter <PRAID> Specify Package Relative App Id filter(s)\r\n separated by semi-colon.\r\n-PidFilter <n> <pid1 pid2 ... >\r\n Specify Pid filter with <n> Pids (maximum of 8\r\n allowed).\r\n-EventIdFilter -<in|out> <n> <id1 id2 ...>\r\n Specify an event id filter with <n> event ids\r\n (maximum 64 event ids allowed).\r\n-StackWalkFilter -<in|out> <n> <id1 id2 ...>\r\n Specify an event id filter with <n> event ids\r\n (maximum 64 event ids allowed).\r\n-Lbr <EventName+EventName+...>:<Filter1,Filter2>\r\n Configure LBR tracing on kernel events.\r\n-Ipt <EventName+EventName+...>:<BufferSize=size,CodeMode=mode>\r\n Configure IPT tracing on kernel events.\r\n size is a positive integer <= 32 (default) in the unit\r\n of KB, and will be rounded up to the next power of 2 (minimal 4)\r\n mode can be User (default), Kernel and UserKernel.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\tracelog.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "tracepdb.exe-FF54CBB94DCF3C62FC72651F7021AEE3": { "file_name": "tracepdb.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\tracepdb.exe", "hash_md5": "FF54CBB94DCF3C62FC72651F7021AEE3", "hash_sha1": "E56DEEFEB2BCF3D5A928E609564C4B852BF0AD49", "hash_sha256": "18FBB31F3B4FD3076BDE7EA32256B3C3960A629C601C36EBABD3D236318101EC", "hash_sha384": "84C1E118C2D95B55318D40ECBBB23957210D5C6940FB16C0672BC3C72C2C3D7FA8A5B0CE5B376FD18B8FBD59BB11481E", "hash_sha512": "33B555250314F45727CCFC86F616CA607C2CA7176C8C0F45EB298E8EB3E1F01EC01E3FAFA4F2DA4D1F7372DB775497A2EAEF32CAAD3D8E25A0FC6519019411CD", "hash_ssdeep": "768:m4t0NPM/GAtW4hF6gWIlhoNkdlKOlybc1Xreo09x4vw/d:BsPGtWVVWCWlybCre5xcw1", "hash_imp": "C563AF5DA2261C5F1E2DB0D3649C84F3", "hash_pesha1": "5956170EB751DD355D42973A39AEF47F751C0540", "hash_pe256": "A8A8D944D21D2F657108C3CEC806F29D5EDAFFDE3CC14BCA3BFC212A61C3DCDC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Get Trace Format info from PDB", "meta_original_filename": "TracePDB.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nMicrosoft (R) TracePDB.Exe (10.0.19041.1)\r\n Microsoft Corporation. All rights reserved.\r\n\r\nTracePDB creates TMF files from the specified PDB file. If you specify an image\r\nfile, TracePDB finds the PDB file for the image and then creates a TMF file.\r\n\r\nUsage:\r\n\r\nTracePDB.exe [-f <PDBFiles>] [-s] [-p <TMFDirectory>] [-v] [-c]\r\nTracePDB.exe -i <ImageFiles> [-r <SymbolPaths>] [-p <TMFDirectory>] [-v] [-c]\r\n\r\nParameters:\r\n\r\n-f <PDBFiles> - Source of trace formatting instructions. \r\n Default=<LocalDirectory>\\*.pdb.\r\n Valid wildcards are ? and *.\r\n\r\n-s - Recursive. Creates TMF files for all PDB files\r\n that match -f in all subdirectories of the -f path.\r\n\r\n-p <TMFDirectory> - Output file location (directory only).\r\n Default=Local directory.\r\n Do not specify a file name; the file name is generated\r\n automatically based on the message GUID.\r\n\r\n-i ImageFiles - Image Files for which to find PDBs and creates TMFs.\r\n Valid wildcards are ? and *.\r\n\r\n-r <SymbolPaths> - Path to private PDB symbol files. Default \r\n is %_NT_SYMBOL_PATH% or srv*\\\\symbols\\symbols.\r\n\r\n-o <TmfFile> - Name of single tmf file output.\r\n Will generate a single TMF file\r\n\r\n-c - Generate TMC files.\r\n\r\n-v - Verbose.\r\n\r\nDefault values:\r\n\r\n <PDBFiles> <LocalDirectory>\\*.pdb.\r\n <TMFDirectory> Local directory.\r\n <SymbolPath> %_NT_SYMBOL_PATH% or srv*\\\\symbols\\symbols\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\tracepdb.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "traceview.exe-7146787B4DB258701F34829456E1F87D": { "file_name": "traceview.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\traceview.exe", "hash_md5": "7146787B4DB258701F34829456E1F87D", "hash_sha1": "A1516640CCD2C16E5C06E71E453B521056B141D9", "hash_sha256": "38CE6885C30D7B201A4E8E45BE90A5553F62B948CEB7D7C44EDE004E826C83B9", "hash_sha384": "604B5E6635C3DF31EA2E381C34800ED267AADC0EE08398A724D069F4AD74C783C77FA25D25B01D5142734F60E1B8A292", "hash_sha512": "FEECAB13461042F2C2421FC0764C1716AAA9FAB525EA433573CE552E8828A546440B79ECA0CF8168231B1471A684E3890795ABB579974E45CC72625D9FBFB320", "hash_ssdeep": "24576:FBjM3qbw8zYNvWM/CQnYiHAS0bD4ThwD:Fjw8gvWM/CQh10bD4Tk", "hash_imp": "10B5FAA274A46853AC2947FD82C3B002", "hash_pesha1": "9D07E36A8682E166910BB9B531865C922055DB32", "hash_pe256": "D2C8804F716F5EA1ED6C2B461433CDC9DC002EEA2DB8E8474C3A3A3798056C28", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TraceView Application", "meta_original_filename": "TraceView.exe", "meta_comments": "V2.1.1", "meta_company_name": "Microsoft Corporation", "meta_file_version": "V2.1.1", "meta_product_version": "2, 1, 1, 0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 2002-2005, Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(RW-) C:\\Users\\user\\CONERR$": "File" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\traceview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll" ], "runtime_window_title": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\traceview.exe" }, "tracewpp.exe-126DA3375E644F1DD098722D5C823417": { "file_name": "tracewpp.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\tracewpp.exe", "hash_md5": "126DA3375E644F1DD098722D5C823417", "hash_sha1": "3B28FF545C0A50129F321A8EACF66BF935388DE5", "hash_sha256": "2709F23A14AF7E9318959F1B5375DE9D910E55D5D9316C598E4243E698658894", "hash_sha384": "F202E9418D2F91A36CCBA2002C50617FC2B9C756FAAB4FBC6B43B3D7C216160D436079F3860CEBE0D7C5FD83C56A3517", "hash_sha512": "36385C0C9DB830A30EA53ABBF468DDE9556CB5AE579FC24DFF70E34B79DD22CBF8A062CF47231C5BD212C9DFB802ECDE80EF9ED20130DA40BD3E5D869253D459", "hash_ssdeep": "6144:yLR1I4kkz3Pu9wx/T+Otc9vELYfxt+UFtVU:y9VPf/bDtcZxA0", "hash_imp": "C029016959B11FF1147E9F7E2164AC03", "hash_pesha1": "4AFCF5F82ABE524121924FF19B297B32AC254380", "hash_pe256": "24F51EAA9DEA210B31412507F9C920DACBA32516467B7918AED45D92747F9032", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Tracing C/C++ preprocessor", "meta_original_filename": "tracewpp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "tracewpp(0) : error wpp : Unknown cmdline option: --help\r\n\r\nMicrosoft (R) TraceWPP.exe (10.0.19041)\r\n(C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: tracewpp [switches] source-file-names...\r\n\r\nGeneral behavior:\r\n\r\n- Gather configuration settings from the command-line, the WPP_FLAGS\r\n environment variable, the INI file(s), and any files specified via -Scan.\r\n- Parse source code files (C or C++) to find calls to trace functions.\r\n- Generate output files by processing templates using values from the\r\n configuration settings and the source code files.\r\n\r\nThe relationship between source code files, templates, and output files is\r\ncontrolled by the -gen option. If no -gen option is set, a default -gen option\r\nis used. The default -gen option is \"{km-default.tpl}*.tmh\" if the -km switch\r\nhas been set and \"{um-default.tpl}*.tmh\" otherwise. The default -gen option\r\nmeans that one .tmh file will be generated for each source file, and that the\r\n.tmh file will be generated using the \"um-default.tpl\" template (or the\r\n\"km-default.tpl\" template if the -km switch is used).\r\n\r\nInput files that start with a UTF-8 or UTF-16 byte order mark will be parsed\r\nas Unicode. Otherwise, input files will be parsed using the current Windows\r\ncode page (the code page returned by GetACP).\r\n\r\nBy default, output files will be written using the current Windows code page.\r\nThe -cp option can configure tracewpp to generate UTF-8 or UTF-16LE output.\r\nNote that a template can override the output encoding, e.g. the manifest.tpl\r\ntemplate always generates UTF-8 output.\r\n\r\nNote that the output generated by this tool depends on configuration (INI) and\r\ntemplate (TPL) files. The following documentation describes the behavior of\r\nthe tracewpp tool itself (e.g. how a command-line option affects a macro) and\r\nalso describes behavior of the Microsoft-provided configuration files and\r\ntemplates (e.g. how a command-line option will affect the behavior of the\r\nMicrosoft-provided templates). The behavior may be different when this tool is\r\nused with other configuration files or templates.\r\n\r\nRefer to the defaultwpp.ini file for more information about the available\r\nconfiguration options and the settings that are enabled by default.\r\n\r\nGeneral options:\r\n\r\n-man:ManifestFile.man[,HeaderFile.h,Prefix]\r\n\r\n ****************************************************************\r\n PREVIEW: Behavior of the -man option and the associated\r\n configuration options may change in future versions of tracewpp.\r\n ****************************************************************\r\n\r\n Configures tracewpp to use manifest-based WPP instead of the\r\n traditional TMF-based WPP. Options after ManifestFile.man are\r\n optional. If HeaderFile is omitted, it defaults to\r\n \"ManifestFile.h\". If Prefix is omitted, it defaults to\r\n \"EventWrite\". This switch is equivalent to the following WPP\r\n configuration commands:\r\n\r\n MANIFEST_CONFIGURATION(ManifestFile.man[,HeaderFile.h,Prefix]);\r\n SEPARATE_TRACE_GUID_PER_FILE(0);\r\n WPP_FLAGS(gen:{manifest.tpl}ManifestFile.man);\r\n WPP_FLAGS(gen:{provider.tpl}*.tmh);\r\n\r\n For the manifest to be useful, you may need to provide an INI or\r\n scanned header file to specify additional configuration options\r\n such as: MANIFEST_RESOURCES, DEFINE_CONTROL_GUID, and DEFINE_BIT.\r\n\r\n-ctl:GUID Defines the WPP_DEFAULT_CONTROL_GUID macro with the specified\r\n control GUID. This the same as -DWPP_DEFAULT_CONTROL_GUID=GUID\r\n and is an alternative to defining the macro in the source file.\r\n When this macro is defined, the default template will generate a\r\n WPP_CONTROL_GUIDS definition with WPP_DEFINE_BIT entries named\r\n \"Error\", \"Unusual\", and \"Noise\". (Not for use with -man.)\r\n Example: -ctl:195b5884-edd3-400c-bcc8-cceb8c344c04\r\n\r\n-DMacroName Adds \"#define MacroName\" to the output file.\r\n\r\n-DMacroName=Value Adds \"#define MacroName Value\" to the output file.\r\n\r\n-km Defines the WPP_KERNEL_MODE macro. This also changes the default\r\n template. If -km is used, the default template will be\r\n \"km-default.tpl\" instead of \"um-default.tpl\".\r\n\r\n-um Defines the WPP_USER_MODE macro.\r\n\r\n-p:ModuleName Overrides the value of the `CurrentDir` template variable. The\r\n default value of `CurrentDir` is based on the current working\r\n directory when tracewpp is launched. The default templates use\r\n CurrentDir as the event's module name.\r\n\r\nSearch and formatting options:\r\n\r\n-ArgBase:Number\r\n Establishes a numeric base for numbering of format strings, such\r\n as \"%1!d!, %2!s!.\" The default is 1.\r\n\r\n-func:FunctionName(ARG1,ARG2,ARG3,...)\r\n Specifies the name and arguments for a trace function that\r\n tracewpp should process. This is an alternative to specifying the\r\n trace functions in an INI file or a scanned header. Any number of\r\n functions can be defined. The default INI file defines the\r\n following trace functions:\r\n\r\n DoTraceMessage(LEVEL,MSG,...)\r\n DoDebugTrace(TRACELEVEL,MSG,...)\r\n\r\n-LookFor:SpecialSymbol\r\n Directs WPP to search source files for the specified symbol. A\r\n template can determine whether the symbol was found using the\r\n FOUND operator in an IF statement. The default INI settings\r\n direct tracewpp to look for the WPP_INIT_TRACING symbol. If the\r\n WPP_INIT_TRACING symbol is found, the default templates will add\r\n module initialization code to the generated TMH file.\r\n\r\n-NoShrieks Directs WPP to try to parse multi-character type names from\r\n format strings even when no exclamation marks are present.\r\n By default, \"%HRESULT\" will parse as item of type \"H\" followed\r\n by text \"RESULT\". With -NoShrieks, \"%HRESULT\" will parse as an\r\n item of type \"HRESULT\".\r\n\r\nFile options:\r\n\r\n@ResponseFile Specifies the name of an options response file. Tokens in the\r\n file will be treated as if they were specified on the tracewpp\r\n command line, i.e. they can be switches or source file names.\r\n\r\n-IPath1[;Path2]\r\n Specifies the location of configuration and template files. Path1\r\n and Path2 represent the fully qualified path to a directory. If\r\n no paths are specified via -I or -CfgDir, tracewpp uses the\r\n current directory.\r\n\r\n-CfgDir:Path1[;Path2...]\r\n Same as -IPath1;Path2. (Deprecated. Use -I instead of -CfgDir.)\r\n\r\n-DefWpp:Path Specifies an alternate primary configuration file. If -DefWpp is\r\n not specified, tracewpp uses \"defaultwpp.ini\".\r\n\r\n-ext:.ext1[.ext2.ext3...]\r\n Specifies the file types that WPP recognizes as source files. The\r\n default is \".c.cxx.cpp.c++\". The tracewpp tool ignores files with\r\n extensions not on this list. This behavior allows you to provide\r\n an unfiltered list of files to tracewpp, and tracewpp will ignore\r\n files it doesn't recognize such as .mc or .rc files.\r\n\r\n-gen:{TemplateName}*.ext\r\n Specifies that for each source file, tracewpp should read that\r\n file and then invoke the specified template to generate an output\r\n file. The output file will have the same name as the source file,\r\n but will have the given file extension. For example,\r\n -gen:{um-default.tpl}*.tmh means that for each source file,\r\n tracewpp should use the um-default.tpl template to generate a\r\n .tmh file with the definitions needed for that source file.\r\n\r\n-gen:{TemplateName}OutputName\r\n Specifies that tracewpp should process all of the source files as\r\n a group and then invoke the specified template to generate the\r\n specified output file. This can be used to generate one TMH file\r\n per project.\r\n\r\n-ini:File.ini Specifies an additional configuration file. WPP uses this file in\r\n addition to \"defaultwpp.ini\". More than one -ini file may be\r\n specified. If no -ini option is provided, \"localwpp.ini\" will be\r\n used as a configuration file if it exists.\r\n\r\n-oDir:Path Specifies the directory for the output files.\r\n\r\n-cp:Encoding Specifies the text encoding for output files. By default, output\r\n files are generated using the code page returned by the Windows\r\n GetACP() function. Use -cp:UTF-8 or -cp:UTF-16 to generate\r\n output files encoded as UTF-8 (with BOM) or UTF-16LE (with BOM).\r\n Note that a template can override the output encoding, e.g. the\r\n manifest.tpl template always generates UTF-8 output.\r\n\r\n-PreserveExt:.ext1[.ext2.ext3...]\r\n Preserves the specified file name extensions when creating TMH\r\n files. By default, the TMH file for <filename>.<ext> will be\r\n named <filename>.tmh. This can cause conflicts when you have more\r\n than one source file with the same name but different extensions,\r\n e.g. myfile.h and myfile.cpp. By using -PreserveExt:.h, the TMH\r\n files would be named \"myfile.h.tmh\" and \"myfile.tmh\".\r\n\r\n-Scan:File.h Instructs tracewpp to scan the specified file for\r\n \"begin_wpp config\" blocks containing WPP configuration options,\r\n or \"begin_wpp enum\" blocks containing enum definitions. Each\r\n \"begin_wpp\" should be paired with an \"end_wpp\". This is typically\r\n used to scan .h files so that configuration options can be\r\n edited in source code.\r\n\r\n-UnicodeIgnore If this switch is provided, tracewpp will ignore source code\r\n files that start with a UTF-16 byte order mark (i.e. will treat\r\n them as containing no trace function calls). This switch exists\r\n because older versions of tracewpp were unable to parse UTF-16\r\n text. In older versions of tracewpp, this switch simply\r\n suppressed the error message that would have been raised for an\r\n unparseable UTF-16 file. The current version of tracewpp can\r\n parse UTF-8 (with BOM) and UTF-16 (with BOM), but retains this\r\n flag for compatibility with the behavior of older versions.\r\n\r\nOther options:\r\n\r\n-ManifestFormats, -NoManifestFormats\r\n Before Windows 10 19H1, TDH.dll was unable to load manifests\r\n containing complex formatting (i.e. %1!X!). For compatibility,\r\n tracewpp defaults to using only simple formatting in manifests\r\n (i.e. %1!S!). Set -ManifestFormats to enable better formatting\r\n (manifests will only load correctly on Windows 10 19H1 or later).\r\n Set -NoManifestFormats (currently the default) to generate\r\n manifests that use only simple formatting (manifests will be more\r\n compatible with earlier versions of Windows).\r\n\r\n-dll Defines the WPP_DLL macro. This is the same as -DWPP_DLL, and is\r\n an alternative to defining the macro in the source file. In the\r\n default templates, this macro is significant only for user-mode\r\n WPP when WPP_MOF_RESOURCENAME is enabled: if WPP_DLL is set,\r\n WPP_INIT_TRACING uses the AppName parameter as the DLL name to\r\n use when locating MOF resources; without this macro set,\r\n WPP_INIT_TRACING will look in the current process's EXE file to\r\n locate MOF resources. In all other cases, the WPP_DLL macro has\r\n no effect.\r\n\r\n-IgnoreDupTypes Do not raise an error if configuration settings define the same\r\n type more than once. The first definition will be used.\r\n\r\n-v Write additional status information during processing (verbose).\r\n\r\n-q By default, tracewpp returns 0 only on success. Use -q to always\r\n return 0, even if tracewpp encountered an error.\r\n\r\n-NoWppVersion Sets template variable `Compiler.Version` to a static value so\r\n that output files do not change based on the specific version of\r\n the tracewpp tool.\r\n\r\n-NoDateTime Sets template variables `System.Date` and `System.Time` to static\r\n values so that output files do not change based on time.\r\n\r\n-NoEnvironment Disables tracewpp's use of environment variables. If this flag\r\n is set, the WPP_FLAGS environment variable will be ignored. In\r\n addition, any environment variables referenced by templates (e.g.\r\n MAJORCOMP and MINORCOMP) will be treated as unset.\r\n\r\n-PerfReport Prints tracewpp timing information.\r\n\r\n-ArgLimit:n By default, tracewpp allows 32 arguments per trace statement. Use\r\n the -arglimit option to change this limit.\r\n\r\n-Reorder, -NoReorder\r\n By default, tracewpp writes message arguments in the order they\r\n appear in the source code. If -Reorder is set, tracewpp will sort\r\n the arguments based on type priority and then type name. This can\r\n reduce code size by minimizing the number of unique helper\r\n functions required.\r\n\r\n-DoNothing Stop processing arguments and exit immediately.\r\n\r\n-MD5, -NoMD5 By default, tracewpp will generate trace GUIDs by hashing the\r\n message data. This means that the trace GUIDs will not change\r\n unless the message data changes, so you can use the same TMF\r\n files to decode your logs as long as the source files are\r\n unchanged. If -NoMD5 is set, tracewpp will use UuidGen instead,\r\n so it will generate new GUIDs each time it runs.\r\n\r\n-TimeChk Set -TimeChk to exit immediately if all output files already\r\n exist and are newer than all source files. Note that this check\r\n is very simple and might skip regenerating the output files even\r\n if environment variables, INI files, or template files have\r\n changed. In most cases, the default behavior (-NoTimeChk) should\r\n be preferred since the hash check is much more accurate.\r\n\r\n-NoHashChk By default, tracewpp will not overwrite an output file if the\r\n existing file's checksum is the same as the new file's checksum.\r\n This behavior helps optimize a build because tracewpp will not\r\n update the timestamp of an already-up-to-date TMH output file.\r\n Set -NoHashChk to skip this check (always overwrite the output).\r\n Note that this checksum is comprehensive and will regenerate the\r\n output if the new output file is different from the existing file\r\n in any way. In particular, if the template references the Date or\r\n Time macros, or if the -NoMD5 option is used, the new output will\r\n always be different from the old output and the existing output\r\n file will always be overwritten.\r\n Implementation note: tracewpp expects to find \"Checksum='...'\"\r\n at the start of the existing file. The checksum is computed as\r\n the MD5 hash that the output file would have if all instances of\r\n the checksum were removed.\r\n\r\n-Public:Func Marks the named function as public. Public functions will omit\r\n certain metadata from the TMF such as filename and line number.\r\n\r\n-PublicFilter:(Func,Flag)\r\n Marks the named function as conditionally public. The function\r\n will be public if the WPP_PUBLIC_<Flag> macro is defined when the\r\n file is compiled. This is the same as the\r\n PUBLIC_FILTER(Func,Flag) configuration option.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\tracewpp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "uuidgen.exe-A1982C1431E768CDFC1BE2368892496F": { "file_name": "uuidgen.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\uuidgen.exe", "hash_md5": "A1982C1431E768CDFC1BE2368892496F", "hash_sha1": "7D36ADEDCDA441991DE3601A3052D02BA3271556", "hash_sha256": "6D42973272F9C3738D5B21EEA394C13573DE55419036FB67AB8DA7870E48EF7F", "hash_sha384": "95C3C77FC50F9F621C1E180B14050B8683CBD2DDC009CA4CEAF7CCE830488464F0082E6B7E84EC47C08A0012A4A13B87", "hash_sha512": "50094CE02C14693ED9DFC9982C71FDCCD0D740923A2B9DB802C72B4115E7D75E248B26870A5723DB07296A5D9E462005FA5A59422456F5502DA35A7F7AFBF9BF", "hash_ssdeep": "384:WNt9O3aSNp6niO6Ktuqza9nIpTaFyHW4UWmwGyLgZalxYS5gJ:WNt9Y1GibqzMIpG8bQ2b5gJ", "hash_imp": "6439F5ADA50EEF06046775B1BB27E0ED", "hash_pesha1": "B1C90E6E27B7F18E8A2A837BBC27E64BC278F17E", "hash_pe256": "393894A7018990ADD18797C6318F787F95DB68E34A68B56719D582BFE4A70D46", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UUID Generator Executable", "meta_original_filename": "uuidgen.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Microsoft UUID Generator v1.01 Copyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nusage: uuidgen [-xisconvh?]\r\n\tx - Generate sequential (V1) UUIDs\r\n\ti - Output UUID in an IDL interface template\r\n\ts - Output UUID as an initialized C struct\r\n\tc - Output UUID in upper case\r\n\to<filename> - redirect output to a file, specified immediately after o\r\n\tn<number> - Number of UUIDs to generate, specified immediately after n\r\n\tv - display version information about uuidgen\r\n\th,? - Display command option summary\r\n", "error": "Invalid Switch Usage: --help\r\n\r\nMicrosoft UUID Generator v1.01 Copyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nusage: uuidgen [-xisconvh?]\r\n\tx - Generate sequential (V1) UUIDs\r\n\ti - Output UUID in an IDL interface template\r\n\ts - Output UUID as an initialized C struct\r\n\tc - Output UUID in upper case\r\n\to<filename> - redirect output to a file, specified immediately after o\r\n\tn<number> - Number of UUIDs to generate, specified immediately after n\r\n\tv - display version information about uuidgen\r\n\th,? - Display command option summary\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\uuidgen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "vsdiagview.exe-6ECF9487B5302CBC1C33A04D4D994AC5": { "file_name": "vsdiagview.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\vsdiagview.exe", "hash_md5": "6ECF9487B5302CBC1C33A04D4D994AC5", "hash_sha1": "19CFC015BE484A9CC652BCC11CF3E13C5DA167D6", "hash_sha256": "03DA07A128235ECAEE0D8DB18139AA28973CA7C2B4463F8A79CA90E8E2B4C8BF", "hash_sha384": "793F4A2D379686D125C027FC99EED6D831285575890DA9620FC5CB8A3EBB85C12BC2063262EE56180E6EB38178FD83BC", "hash_sha512": "FB3DFB736E8DD7C7DC0564328D6B62EAD1823E4DF0B3ADDFB565B36401909F519E8385635D86770B392A210D34405895ED99EEC1EA91F582582A56DC6EE0EA8D", "hash_ssdeep": "768:pqXzBgHsUieX8a2GnT2GefO2GUlFfDlEycO929:QBgHBPifQK", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "579C31926E4EEA5972B2E75E78854FA2740FD133", "hash_pe256": "A498E07FF711936357DA875E088852932CD597B37BF9C9E6E24B9F3481AF19CD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "vsdiagview.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_7660": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R--) C:\\Users\\user\\--help": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\vsdiagview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ], "runtime_window_title": "File Format Error" }, "vshadow.exe-91170F962E63A7065E39564DC5428EE3": { "file_name": "vshadow.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\vshadow.exe", "hash_md5": "91170F962E63A7065E39564DC5428EE3", "hash_sha1": "27AAB9E8FE9D0547794FA86B808563BA22FB4F86", "hash_sha256": "436EFB1D6574FA0DAB562C938C074BA38FF0FF938884690CFD0293182BC395B5", "hash_sha384": "73B1AF32FD059754E7B1F92DFFBE8D09B6B19BF9402166C421839FC3A7D8263A1F74AB3D872F0BA5516AE5244F02A4F8", "hash_sha512": "7151D7D9CE1988DF0236B70702E7699FC035F46E853C444F8F841970244E979946351E89496C5ED87FFA26689589259D8603BE5E3086AEFC638110F497E9A99F", "hash_ssdeep": "6144:cMwdaYBYgBsKv5DzqELJ2J55ULdqSPovikkvzd/+:0a8YPW1+EsVULdq9Mvp+", "hash_imp": "702A07FF266ECFBCEEAC19B4BDB17820", "hash_pesha1": "764ECEF5AB2E6B435100868D6B503CFE60B0B23F", "hash_pe256": "BE6165E991C4F791C60A28E1CEEE77522CA944AFCD2C4C6911AE7F92E7E20DAF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "VShadow, Volume Shadow Copy Service (VSS) Sample Requestor", "meta_original_filename": "vshadow.exe", "meta_product_name": "VShadow", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nVSHADOW.EXE 3.0 - Volume Shadow Copy sample client.\r\nCopyright (C) 2005 Microsoft Corporation. All rights reserved.\r\n\r\n\r\n\r\nERROR: invalid parameter '--help'\r\n\r\nUsage:\r\n VSHADOW [optional flags] [commands]\r\n\r\nList of optional flags:\r\n -? - Displays the usage screen\r\n -p - Manages persistent shadow copies\r\n -nw - Manages no-writer shadow copies\r\n -nar - Creates shadow copies with no auto-recovery\r\n -tr - Creates TxF-recovered shadow copies\r\n -ad - Creates differential HW shadow copies\r\n -ap - Creates plex HW shadow copies\r\n -scsf - Creates Shadow Copies for Shared Folders (Client Accessible)\r\n -t={file.xml} - Transportable shadow set. Generates also the backup components doc.\r\n -bc={file.xml} - Generates the backup components doc for non-transportable shadow set.\r\n -wi={Writer Name} - Verify that a writer/component is included\r\n -wx={Writer Name} - Exclude a writer/component from set creation or restore\r\n -mask - BreakSnapshotSetEx flag: Mask shadow copy luns from system on break.\r\n -rw - BreakSnapshotSetEx flag: Make shadow copy luns read-write on break.\r\n -forcerevert - BreakSnapshotSetEx flag: Complete operation only if all disk signatures revertable.\r\n -norevert - BreakSnapshotSetEx flag: Do not revert disk signatures.\r\n -revertsig - Revert to the original disk's signature during resync.\r\n -novolcheck - Ignore volume check during resync. Unselected volumes will be overwritten.\r\n -script={file.cmd} - SETVAR script creation\r\n -exec={command} - Custom command executed after shadow creation, import or between break and make-it-write\r\n -wait - Wait before program termination or between shadow set break and make-it-write\r\n -tracing - Runs VSHADOW.EXE with enhanced diagnostics\r\n\r\n\r\nList of commands:\r\n {volume list} - Creates a shadow set on these volumes\r\n -ws - List writer status\r\n -wm - List writer summary metadata\r\n -wm2 - List writer detailed metadata\r\n -wm3 - List writer detailed metadata in raw XML format\r\n -q - List all shadow copies in the system\r\n -qx={SnapSetID} - List all shadow copies in this set\r\n -s={SnapID} - List the shadow copy with the given ID\r\n -da - Deletes all shadow copies in the system\r\n -do={volume} - Deletes the oldest shadow of the specified volume\r\n -dx={SnapSetID} - Deletes all shadow copies in this set\r\n -ds={SnapID} - Deletes this shadow copy\r\n -i={file.xml} - Transportable shadow copy import\r\n -b={SnapSetID} - Break the given shadow set into read-only volumes\r\n -bw={SnapSetID} - Break the shadow set into writable volumes\r\n -bex={SnapSetID} - Break using BreakSnapshotSetEx and flags, see options for available flags\r\n -el={SnapID},dir - Expose the shadow copy as a mount point\r\n -el={SnapID},drive - Expose the shadow copy as a drive letter\r\n -er={SnapID},share - Expose the shadow copy as a network share\r\n -er={SnapID},share,path - Expose a child directory from the shadow copy as a share\r\n -r={file.xml} - Restore based on a previously-generated Backup Components document\r\n -rs={file.xml} - Simulated restore based on a previously-generated Backup Components doc\r\n -revert={SnapID} - Revert a volume to the specified shadow copy\r\n -addresync={SnapID},drive - Resync the given shadow copy to the specified volume\r\n -addresync={SnapID} - Resync the given shadow copy to it's original volume\r\n -resync=bcd.xml - Perform Resync using the specified BCD\r\n\r\n\r\nExamples:\r\n\r\n - Non-persistent shadow copy creation on C: and E:\r\n VSHADOW C: E:\r\n\r\n - Non-persistent shadow copy creation on a CSV named Volume1\r\n VSHADOW C:\\ClusterStorage\\Volume1\r\n\r\n - Persistent shadow copy creation on C: (with no writers)\r\n VSHADOW -p -nw C:\r\n\r\n - Transportable shadow copy creation on X:\r\n VSHADOW -t=file1.xml X:\r\n\r\n - Transportable shadow copy import\r\n VSHADOW -i=file1.xml\r\n\r\n - List all shadow copies in the system:\r\n VSHADOW -q\r\n\r\nPlease see the README.DOC file for more details.\r\n\r\n\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\vshadow.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "vssagent.exe-D7C2815B92C3D38673558BDBE0F40164": { "file_name": "vssagent.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\vssagent.exe", "hash_md5": "D7C2815B92C3D38673558BDBE0F40164", "hash_sha1": "DB7FE0CFA64C5D7F0DF35886C17CC4668AE5A653", "hash_sha256": "A25C2879F596110967C11DB1CB433271BC2F342BCB16A884AFBFC784A2416F51", "hash_sha384": "8677571ED31B61885FA989A97B02154E9A856D459133112A459D350A44BBE2DC8509645C24A7144554A372E856C1DA93", "hash_sha512": "B65B8483E7C14302A7FAD2EC5F20621C4A7109CD11206E6922C0A5DEFA751DA79F49B9213A72BA25DADB4FC499C472F663DE6AB109A4239168D7FC07526CCED1", "hash_ssdeep": "6144:36PWPW/OmPr+NJoBjDd7SdnCCJyq/74pcLFrOe5iKzWk955MtH73BNW99Wn4:KeuPyN8NSdn14pmr55N955Obw", "hash_imp": "A534F8D8F5661B16D014BE792F84B051", "hash_pesha1": "00E5DF2D341C85D503DE30B1BD9BE33FFEF75FA9", "hash_pe256": "9F3CBAEC7EF2B48CE362725C9632FF5E992B24CE20393D489C5553F2DF0AE6C3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "VssAgent, Volume Shadow Copy Service (VSS) support tool", "meta_original_filename": "vssagent.exe", "meta_product_name": "VssAgent", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nVSSAGENT application, version 10.0.19041.1 (WinBuild.160101.0800)\r\n\r\n\r\n--------------- Print supported commands ------------\r\n\r\n\r\nUsage:\r\n * Monitor the given HW provider\r\n VSSAGENT -monitor <provider_id> <xml_file>\r\n\r\n * Monitor the disk/volume PNP messages\r\n VSSAGENT -pnpmonitor <xml_file>\r\n\r\n * Gather diagnose data\r\n VSSAGENT -gather <xml_file>\r\n\r\n * Enable lightweight VSS diagnose mode\r\n VSSAGENT -enablediag\r\n\r\n * Disable lightweight VSS diagnose mode\r\n VSSAGENT -disablediag\r\n\r\n * Stop VSSAGENT\r\n VSSAGENT -stop\r\n\r\n * Cleanup if VSSAGENT abnormally terminates\r\n VSSAGENT -cleanup <provider_id>\r\n\r\n * Make an analysis summary while monitoring\r\n VSSAGENT -makesummary\r\n\r\n * Set parameters for VSS diagnose\r\n VSSAGENT -setparam <param_name> <param_value>\r\n\r\n * List all vss diagnose parameters\r\n VSSAGENT -listparams\r\n\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\vssagent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "vsstrace.exe-0692B32463768C1E240027A828AB3851": { "file_name": "vsstrace.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\vsstrace.exe", "hash_md5": "0692B32463768C1E240027A828AB3851", "hash_sha1": "0ECB82690472BBDF9A27DBFBABD1FA7D8ED47168", "hash_sha256": "39DE95ABC33F911FFE40B0804EE68ABBCD9D3B6C4C2A25005AD7ADE59B5C5BA9", "hash_sha384": "97E4834CF33A58B4808F6E4CD8A2B4B8C8DF70BBF25C519849C35BDC189711D45F4E959883C53CED16BBE2439C058FF5", "hash_sha512": "3C6F233A686E37D4912DACD9802FAC5B77D368E3C27B531F30021F5E1EF5D4C39EAB24FFFCF246E49A219E951499915A72F3FFB8B93401F047A0FAA8FC2E5128", "hash_ssdeep": "768:+TGyLZpAdkSttfK+KbRxwyaOi3GoURasUD9km3n/onhFAq5ncB4WcYWNx:MLvAdk0KbRxwy2+asVGnCFACcGgq", "hash_imp": "B353E2B19ADEFC9DA0B20DF10DA63461", "hash_pesha1": "B94665D4ED8D7335657E7FE66C7A3825C9101CD1", "hash_pe256": "FD641DAF665DE0C1BCEA3AE68D84FF8C89162BF7ABC150443744C8CC81DCE286", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "vsstrace, Volume Shadow Copy Service (VSS) trace formatting tool", "meta_original_filename": "vsstrace.exe", "meta_product_name": "vsstrace", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nUsage: vsstrace [-help <modules | levels | all>] [-l <level>] [-f <flags>]\r\n [-+<module>] [-+ident] [-+pid <process id>] [-+tid <thread id>]\r\n [-etl <input ETL file>] [-o <output TXT File>]\r\n\r\n -f and -+<module>: both effect which modules will be traced;\r\n the order in which they are specified will effect which modules are masked;\r\n you can mask all (-f 0) and then add specific modules by name (+coord +xml)\r\n\r\n -tid/-pid: by default all process IDs (pid) and thread IDs (tid) are enabled;\r\n asterisk (*) can be used as a wildcard for \"any\" process or thread;\r\n the order in which they are provided will effect which traces are included;\r\n you can mask all (-pid *) and then enable specific ones (+pid 0xe8c)\r\n\r\n -o: provides alternate output stream. If you want to exclude console\r\n output and just write to a file, redirect output to a file using > sign\r\n\r\n\r\n Examples:\r\n vsstrace -f 0 +coord +swprv\r\n vsstrace -f 0x6\r\n vsstrace -GEN\r\n vsstrace -etl vss.etl -o vss.log\r\n vsstrace -f 0xffff -pid * +pid 0xe8c -tid * +tid 0x31a\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\vsstrace.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "vstorcontrol.exe-A3E9CC7C462786C4D8D6915FA49F634B": { "file_name": "vstorcontrol.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\vstorcontrol.exe", "hash_md5": "A3E9CC7C462786C4D8D6915FA49F634B", "hash_sha1": "933A5193E7548C8A4B38A8E595013CC1D97A57B2", "hash_sha256": "64A69D471B2DAA2E4E0FE71DD390AF223E48579C122313F3E120640F5D0CE11C", "hash_sha384": "18A28744EB2514AF92E273A68B68DB5F10A86FFDAEE2DC045CA71DDC4E9B53DA0B5B8ED52ADEC1F77F133E409CB8D953", "hash_sha512": "372B68183909D387A3167FEA99F02F4892C95C20F8727963B96DE99C104D36E42AA8F9D7BBD16E75D72352DEB556691997DF221A74B52698A50286B9588E95F5", "hash_ssdeep": "3072:G45Ur+Pl7NGlxA+5qhfKpBpmzEl+4U0HFxNY+ilthgo9aJsExs:G4rnhfV4ULP9gN2E", "hash_imp": "AA30D00FD395B4BE9EE8CFCFE3DF8674", "hash_pesha1": "39262D9B8B0F7242D27CC56848A3BACC1C4F589A", "hash_pe256": "951E26B361922302E88BFFC078FEAF9CAF57DE60B2C73B88F1DA0F9F90C51462", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Virtual Storage Command Line Control Tool", "meta_original_filename": "vstorcontrol.exe", "meta_product_name": "Virtual Storage Command Line Control Tool", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": " Commands:\r\n\t install - Installs the Virtual Storage Driver\r\n\t uninstall - Uninstalls Virtual Storage\r\n\t create - Creates a drive\r\n\t remove - Removes a drive\r\n\t resize - Resizes a disk in the drive\r\n\t query - Displays information about the drive\r\n\t list - Lists all drives created on virtual storage\r\n\t help - Displays detailed help for commands\r\n vstorcontrol help <command> displays detailed help\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\vstorcontrol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "vswriter.exe-2377E4868E5ACB4DC4E337BFB7F594CD": { "file_name": "vswriter.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\vswriter.exe", "hash_md5": "2377E4868E5ACB4DC4E337BFB7F594CD", "hash_sha1": "EEE29675E5504B8D875EFDDADE89DA261FFA69F0", "hash_sha256": "792E8D2A00A60473F465DA0F539129D9BF348BBF7E35F2FA7B79977885B079E1", "hash_sha384": "ADC4AA791D882FFA6400FA099F10A76EC3507AE71CB9C87141CF2FB5CC0141C96F9F53D8D78930C6E7E23F40DDD083D0", "hash_sha512": "6924874091A0DECAA131DF55C50C07DEF6D7C62C8ADB60AB39E1D3BF53C30A8C263572965522BA355A6D9EEE0338723532B1C782A6E013F13FCC96F9DEE085A6", "hash_ssdeep": "6144:ovDuzQJaZNTH3Npt/sqtrEa9pCeVWM+EVN+6C40Z8EhcLGYe0/e1:4DDYDyMka/fm8A", "hash_imp": "FB4110EFD56783E6F0A5AC96B304DB0F", "hash_pesha1": "AE818F9BFC377DEE699193582656EB73E4978D42", "hash_pe256": "684117A0FBB8CBBC087F04A58CBA309234C76F650F5B499CE8AF1736848135DC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Volume Shadow Copy Service (VSS) Test Writer", "meta_original_filename": "vswriter.exe", "meta_product_name": "Vswriter", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Failed to load configuration file:\r\n Reason: Whitespace is not allowed at this location.\r\r\n\r\n Source Text:\r\n Hull & Domain Shaders Yes\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\vswriter.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "winmdidl.exe-595F588304AF6B2A1F004EC71D31F247": { "file_name": "winmdidl.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\winmdidl.exe", "hash_md5": "595F588304AF6B2A1F004EC71D31F247", "hash_sha1": "2B252E725445272AC66DE06FFB18C85313BEEBF3", "hash_sha256": "3E29C74DAB4E28AB289A31E1FC52672C218E85F486B2D7734663CF000F736C07", "hash_sha384": "2E91BFD48FE2E2725E0464E9D6B78EF5719FA19CB47EACA7C88B17558051293C97DE2A41B0360478BE03A8282606385B", "hash_sha512": "F2D778BD4464306BDE21CAA7F94AF3F71B6389CA373215EBBAAEB0872065FF1D169BAF4CC799F93937DD658EF4E698A297949D71FA933DC23597C832C6B80ABB", "hash_ssdeep": "3072:o2svKkp2cQrlBG19605eTRxSBQJSIRt+F76CrK+bVXa+qLc2mDm74TFafxpiaIt9:o2n0/6lBmbeXpRgbmSa82my8E5pp", "hash_imp": "8C809DA55EB0024791F2CF839759BE1B", "hash_pesha1": "64F35F2B06530370A9F4ECA25EF1EC9F75E90838", "hash_pe256": "71180168D11A88529B52488B41ED9342F41E44B427DB0550063F6ECB9B61F656", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft WinMDIDL Utility", "meta_original_filename": "WinMDIDL.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Microsoft(R) Metadata IDL Generation Utility Version 8.00.0021\r\nerror W1001: Usage: Winmdidl.exe [/nologo] [/supressversioncheck] [/time] [/nosystemdeclares] [/outdir:dir] [/metadata_dir:dir] [/reservedTypes:file] [/emptyNamespaceFile:file] [/banner:file] [/utf8] Winmdfile\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\winmdidl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wsdcodegen.exe-E0C608F112BD3ADBFABF3C415D65D23F": { "file_name": "wsdcodegen.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\wsdcodegen.exe", "hash_md5": "E0C608F112BD3ADBFABF3C415D65D23F", "hash_sha1": "28C42C611CDFEFE7A104A8AAC4E6301AC7F691C0", "hash_sha256": "E8FF75147176B7C2055ACCB8AE03871EC1CB485DC76D4C934201D4753010A56B", "hash_sha384": "4AD224E13676B77D44AEA1F01FB3A20C38C73158CC98B95CAA572C0D773D775158489C9943F4F686D1DDB2D8B22E516F", "hash_sha512": "FC63A17AA2FA35CF0348E248870B93C33F5A62833E5AF0A78FC5EDC5A7EAE5C8A35B1907F7025E49F602A732B05A5AB5CA94BC7A549FA003EBF289742412B897", "hash_ssdeep": "3072:BYr/PHkl/UDAjQFRBMsoy4gfs5xw6R63gDWBxFbG+NX:GPEjjuB8y4bO3gD", "hash_imp": "n/a", "hash_pesha1": "40DF2773C6E2FFA9729F23D86BFF57E10195E51F", "hash_pe256": "9D69AAE928FB75F91E890A63C4F2BB098AEC13F621189D12BC2DE6EC303BA129", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "WsdCodeGen.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "children": "Fondue.exe", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\wsdcodegen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wsddebug_client.exe-92782BDA509932C9AE7B22D17CE6D308": { "file_name": "wsddebug_client.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\wsddebug_client.exe", "hash_md5": "92782BDA509932C9AE7B22D17CE6D308", "hash_sha1": "5ADE59AC964D1E2C86F2EEF9229D40FC57293C46", "hash_sha256": "C93BF3EBC89E51F9457FEE863360D9AC1C8BF60992F1EA21DAB0DEC79C21EB16", "hash_sha384": "05AA6EA75336107189D7BE54964C8C479B02D180A5A2E6AB429B885F8A7FA839013685D3864930519CFA694308162F72", "hash_sha512": "62CF4BBD73C2BA1ECE6EAFAE0B966EDC21E81F310D4899B5C929C0719013983234B9D2C15F1A5247AAE0F4AA45EF94866F666D58E643DBB68128077E40753169", "hash_ssdeep": "1536:OOnFTxptZVjo7jKyvr5oECrYDbI1M1DN6HKw6j2p+Su:PF/tZVjo7jKyvr5fvI1MT6Hq2wSu", "hash_imp": "7E504D153E5D3BB56BC6272A12E1D763", "hash_pesha1": "1E60D3B4966BEA1C7B90778248F48DC57FCE1C12", "hash_pe256": "F0361F0C7BEE38631CFA3EB5E70CBC4E96AF6359F557FCF2E05CCFD5B5FEB9E6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WSDAPI Debug Client", "meta_original_filename": "WSDDebug_client.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "WSDAPI Debug Client\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\wsddebug_client.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wsddebug_host.exe-B912BBD3BA1940FF5F1BFA05C5FEBE27": { "file_name": "wsddebug_host.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\wsddebug_host.exe", "hash_md5": "B912BBD3BA1940FF5F1BFA05C5FEBE27", "hash_sha1": "C08A6BE74108987CBD1ABAD398BAF346D656BA09", "hash_sha256": "4105FB520B21458AEB2AAE412A7BA5AFF3A88CF16229394312A350A7E3CD1E2F", "hash_sha384": "C4348F2ECDBCADA29B8DBE7D57572BE934AA37D7A5E372672AE04FF1BCA7B1703C52729C7AE97899979CBF2EF7CAC029", "hash_sha512": "E14B07F9693A8B34F70A87A289157A6FC2AF8FF9640C33172A3C812D5D7D655EB9C9C530C6B8AB1FE0642C1455B61992E8DF7ECF991AA5306DCE3346A0804F85", "hash_ssdeep": "1536:jakXLsBp5VAj2WoMOeYxPlppUmliP3BcH2Fto2P:pe5SqWnYxPWmlCqH2xP", "hash_imp": "7C4E62D5DEE8947A7717DE46C75C978A", "hash_pesha1": "ECCF8B6D869B5B9F3B5D78BDBE3B8C7FEE08EDED", "hash_pe256": "7C73BFD42CFA5428F4E1EC1DD181D2FF8AF58E7D6633174973B12BF5AC9D0C05", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WSDAPI Debug Host", "meta_original_filename": "WSDDebug_host.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "WSDAPI Debug Host\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\wsddebug_host.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wstracedump.exe-2CF8C7C5291EFD6719E9A35D8EF51A76": { "file_name": "wstracedump.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\wstracedump.exe", "hash_md5": "2CF8C7C5291EFD6719E9A35D8EF51A76", "hash_sha1": "069AF7D45E973790F90F6645D326B86637796C7B", "hash_sha256": "55A2484FFFE228BC1F567EBCB1B30F70884AB3F5819B6EEA7C4F65A03B98D24F", "hash_sha384": "EC1391DF82E8C22D277DC445580D2E20DE850E7ED1127AE1D4C9D2B38B9A457C30D8864C048457616C83FF3B01A738A6", "hash_sha512": "4836DF64FEF5C6C0731F6DF265A605CC80D966FF77193202C00F1ABBF4482C5481F1C92234020D4DD71C227389C9522D01CD11CEEA605ED521AF8EE8FD1549C8", "hash_ssdeep": "768:SAYPm1KofwELb1blfXOuEyT9mBm6ChBX3Pnyk7rkb9QwDq4Wjqf7yNrD7Oow:xKSZdwGmE6EZPyk7rkb9Qw10HNrGJ", "hash_imp": "F608678AC29C3EFCF33101E9D4A5792F", "hash_pesha1": "20F61900A2943EE749A2CBAC0758A07CDD0D78C5", "hash_pe256": "6DC29E87DE769AAFBE8B54B32C1FC3A9DD1144434C255B31CE203C568C6F98BA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Web Services API Trace Viewer Tool", "meta_original_filename": "WsTraceDump.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Cannot start WsTraceUtil.exe. Make sure it is in the same directory as WsTraceDump.exe.\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\wstracedump.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wstraceutil.exe-DDB1305AA759C380480B8FB84C4D97F2": { "file_name": "wstraceutil.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\wstraceutil.exe", "hash_md5": "DDB1305AA759C380480B8FB84C4D97F2", "hash_sha1": "E9656D1E0228ED7C48D77324296788BD952827E5", "hash_sha256": "AAE274556FD2C0454F1A2E0C8796AD4F2F4DCECA82423BB71E257A87A502A743", "hash_sha384": "4FF89B623F85B0771A17C3D9D2938A98CAA572CD5F6D84DEEC0C3C97AA69AD5475C4E803BED7AF0D0AF8B6A6BA97BE00", "hash_sha512": "5AAB8CE2898CB5C6A63D2A8F3395FC2B32ED236ACF29656A854B27C2AEEC067E0CA90B7CE00865E168855AC88502CD096756F24DD97BE862918B33593512E190", "hash_ssdeep": "3072:fwG0AN0jB1ZM9oHL/y7/V6BOMwaoRNCd:oiSBjMiHG7/V0O", "hash_imp": "D58E380036B627D7FACF45BE65458415", "hash_pesha1": "C0FF791957C13E90952FE2E64923688E26C20490", "hash_pe256": "1A8E595F713529C72BDE80FEB9004740AA24C2432EDABB89816879F6BA11813F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Web Services API Trace Utility Tool", "meta_original_filename": "WsTraceUtil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Connection-specific - Microsoft (R) Windows Web Services API Trace Viewer Tool version 1.0\r\nCopyright (c) Microsoft Corporation 2009.\r\r\nAll rights reserved.\r\r\n\r\r\nUsage : WsTraceUtil.exe \r\n-create [all|verbose|message|info|warning|error] - start trace session with specified verbosity level. The default is info. \r\n-update [all|verbose|message|info|warning|error] - updates trace verbosity level to specified value. The defaul is info. \r\n-on - turns the trace session on. \r\n-off - turns the session off. \r\n-delete - deletes the session. \r\n-session name - specifies session name. If the parameter is not used, session name is WsTrace. \r\n-output [filename] - dumps trace. If filename is provided, the trace are written to the file. Otherwise to the console screen. To stop the tool use Crtl-C. \r\n-convert filename - reads trace (*.etl) file.\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\wstraceutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wsutil.exe-174A4C5A388A2344A2A6A8DC7F57B99F": { "file_name": "wsutil.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\wsutil.exe", "hash_md5": "174A4C5A388A2344A2A6A8DC7F57B99F", "hash_sha1": "BC88E50EC7B45A146ED73D4474C63D7D425CCA6E", "hash_sha256": "F905D7FEE591625A24D6391C84A734BE0B119D43C01F05988A20C3E310668037", "hash_sha384": "227F85FC70C782A632EFDACCD3E9A6FA9BC7E3D53DBBE3FEB9A8685FF65A9ED086A47CA5A0FEF67408ADE15B7A192FF0", "hash_sha512": "376ABC1A6197F880DA31112C8F3C929DFD09EAF497484CEB6A14A54CFD064BCDD3159B3765A0EF0A1E2CE29AF669E82CCCBF0B17EFB0F27A4EE2DC370C70DD6A", "hash_ssdeep": "3072:7LX7dISJAlmQwlR0nf2IgiDnK9Cpcztjb2K15Pt7Zy7/LO/YQrGNgtif5KAvT/pn:lCVcLVmhjn+382ElnLOzvvMHFz", "hash_imp": "n/a", "hash_pesha1": "35E106CCD8F4D3B8E0B2C8A1AE5347CF5B04270C", "hash_pe256": "E508144F9CCB6E1C5D46BF87C73113B61435DFC8769962D2E6D3BE153B45C682", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Web Services Tool", "meta_original_filename": "Wsutil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Microsoft (R) Windows Web Services Tool, version 1.0098 \r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nWsutil Compiler Options\r\n\r\nSyntax: wsutil.exe [@resfile] [metadataDocument]* [option]*\r\n\r\n--- RESPONSE FILE ---\r\n@resfile Specify the response file that contains all \r\n the arguments.\r\n\r\n--- metadataDocument ---\r\nfileName Specify input fileName. Metadata document type is \r\n determined according to the file content. \r\n Standard command-line wildcards can be used.\r\n/wsdl:fileName[:url] Specify input file as WSDL file; optional url specify\r\n the location that the metadata was retrieved from.\r\n/xsd:fileName Specify input file as XSD Schema file\r\n/wsp:fileName[:url] Specify input file as policy file; optional url specify\r\n the location that the metadata was retrieved from.\r\n\r\n\r\n--- output options ---\r\n/out:directory Specify output directory for generated file\r\n/noclient Do not generate client stub\r\n/noservice Do not generate service stub\r\n/nopolicy Do not generate policy related metadata\r\n\r\n--- misc options ---\r\n/?, /help Display this message.\r\n/W:{0|1|2|3|4} Specify warning level 0-4 (default = 1)\r\n/fullName Prepend fileName to generated identifiers.\r\n/prefix:name Prepend specified name to generated identifiers.\r\n/nologo Do not generate compiler specific information on \r\n console output\r\n/nostamp Do not generate compiler specific information on \r\n generated file\r\n/nosummary Do not produce summary after processing. When combined\r\n with /nologo, the tool is silent on success.\r\n/string:WS_STRING|WCHAR* Specify the string type. By default WCHAR* \r\n string is used.\r\n/ignoreTrailingContent Specify the trailing content for generated \r\n structures to be ignored during deserialization.\r\n/ignoreUnhandledAttributes Specify the unhandled attributes for generated\r\n structures to be ignored during deserialization.\r\n\r\n\r\n", "error": "error WSUTIL0034 error WSUTIL0014 Failed to open specified input file 'help'. Error Message:\r\nValue cannot be null.\r\nParameter name: format\r\n If you have passed in an url, Wsutil does not support downloading metadata from running services. Please check the documentation for detailed instructions on how to retrieve metadata from running webservices.\r\nwarning WSUTIL0075 Error during compilation. No file was generated.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\wsutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "xpsanalyzer.exe-B5D5CB10DC7B87E44568FCD47F4B8564": { "file_name": "xpsanalyzer.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\xpsanalyzer.exe", "hash_md5": "B5D5CB10DC7B87E44568FCD47F4B8564", "hash_sha1": "10113AF7254D38978BACBDEC3A4D5BB829151918", "hash_sha256": "F39856F66B87A7D06FB56F2E641C6D02D5E4B7FFED8F9C530A229A3A2A5EF2CB", "hash_sha384": "DAEF2F287455EB69CA1C2D780FD89101F1A76C83D5FF8FFE1E6A94BC28065D967F39D35EA402D339F10935257C6A39AD", "hash_sha512": "A211AE0C7D39F719262F395ECC001DFDA2C3EFD1864DA8D92F52A3AAAECB20BC48753874649B9144F3EF4CDEC5FF71FB155CC416E8543AF0B5504549AA6F36EA", "hash_ssdeep": "3072:aWDSzgy3b24HzYeVjnpdCE1A6rXCtMYQ8C5vXSvSaW91olE40zFTDHQ8sGWSnrGW:aWDrq2agFQStDN2AL0zFTzqG7yAF", "hash_imp": "1A963B7BAA888669E4231C8D9A574FA3", "hash_pesha1": "0F1EDF384B7FE9CFE08795C4E293A528E8F81954", "hash_pe256": "9B1E6C0DC752D4B3EEAA23F74C0BEE0FB46C5DD25B406A4E5A20B75A4E5F87B4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "XPS Analysis Tool", "meta_original_filename": "XpsAnalyzer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Error: Either /Directory or /XpsFile is required\r\n\r\nXpsAnalyzer\r\nCopyright (c) 2009 Microsoft Corporation. All rights reserved.\r\n\r\nUsage: XpsAnalyzer /Directory:<directory that contains Xps files>\r\n\r\n /XpsFile:<an Xps file>\r\n /FlushSql:<desired format> Flag to output the analysis report in SQL format\r\n Possible SQL formats are \"SqlServer\",\"MySql\" and \"Oracle\"\r\n\r\nSample Usage:\r\n\r\n XpsAnalyzer /Directory:c:\\test\r\n XpsAnalyzer /XpsFile:c:\\test\\sample.xps\r\n XpsAnalyzer /Directory:c:\\test /FlushSql:SqlServer\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\xpsanalyzer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "xpsconverter.exe-60069FF023259C7E9EE32871CF7D4D3E": { "file_name": "xpsconverter.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\xpsconverter.exe", "hash_md5": "60069FF023259C7E9EE32871CF7D4D3E", "hash_sha1": "E7FF81F55246E6B96C54F53DFE69AB93E5BACDF8", "hash_sha256": "A58154AAE284695006237A713654C5B9A40AAF707821AD81C17453669B92951E", "hash_sha384": "877AAF2980D14B07137ACB47A10AD7A07FAE236E1FB7DCA5A4DBC5F9B7B546B66E36D5D4D5AE5289D31DAA2C33052912", "hash_sha512": "85F93EE8CA8E98F80B978EEA60AF7FBB0127444FA8438807793C26DA4FDCF564A046E9FB9BA42AA6025FBBCECBFE5D14BD4C7D235ADB5E9875223BEBE51211F9", "hash_ssdeep": "768:MGo1Z4e3p1I2j8yiD9Ivd8sTzDPz8aVa9XWVPjpB+CxElhoP:MG8bI2j8yiKvdXQaVIXWsh", "hash_imp": "n/a", "hash_pesha1": "E991EC4A9FE9CA32256B9FF5D6A4975E509D886E", "hash_pe256": "6EAE569FFB2EC4B235CE19F17A8EF594C461748C596BA9776F738CF9C2252A31", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "XpsConverter.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Invalid conversion option. Expected /OpenXPS or /XPS\r\n\r\nXpsConverter\r\nCopyright (c) 2010 Microsoft Corporation. All rights reserved.\r\n\r\nUsage:\r\n XpsConverter /OpenXPS | /XPS\r\n [/InputFile=<input file name> /OutputFile=<output file name>]\r\n [/InputFolder=<input folder name> /OutputFolder=<output folder name>]\r\n [OptionalSwitches]\r\n\r\n /OpenXPS - convert to OpenXPS format.\r\n /XPS - convert to XPS format.\r\n\r\n [/InputFile=<input file> /OutputFile=<output file>]\r\n - convert a single file.\r\n\r\n [/InputFolder=<input folder> /OutputFolder=<output folder>]\r\n Convert all the files in <input folder> and save them to <output folder>\r\n Files in <input folder> must have .xps or .oxps extensions.\r\n Converting a folder is a recursive operation.\r\n\r\n -logger:<LoggerType>\n\t: The logger to use (File, Console, WTT).\r\n\t the default logger is \"CONSOLE\".\r\n -logfile:<LogFile>\n\t: The log file to write to when using the File logger.\r\n\t the default log file is \"XpsConverter.txt\".\r\n -device:<DeviceString>\n\t: The device string to use with the WTT logger.\r\n\t the default device is \"$LogFile:file=XpsConverter.wtl,WriteMode=append\".\r\n /?\t: Display this help\r\n\r\nSample Usage:\r\n\r\n XpsConverter /OpenXPS /InputFile=Test.xps /OutputFile=Test.oxps\r\n XpsConverter /XPS /InputFolder=c:\\OpenXps /OutputFolder=c:\\MSXPS\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\xpsconverter.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AccCheckConsole.exe-661E08B8B343F1AFE4E1DDCC9180D2D9": { "file_name": "AccCheckConsole.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\AccChecker\\AccCheckConsole.exe", "hash_md5": "661E08B8B343F1AFE4E1DDCC9180D2D9", "hash_sha1": "EF237756BE56DB310996B9F16FA6D15DBF31A9CE", "hash_sha256": "9EC5D88096C84D9BF533433D38DAA31EE61E34BD8FE9C5ED7ECD60FDDEFB6792", "hash_sha384": "69B38CEDF7FD7D4DCEAE20FF270647531767C7129E77A713D081700C72444095BF7033D0F091D46B89B113A70180E14C", "hash_sha512": "7A9E368FC172910092846AEB06127EE3003786449591FFC492DBA6A7D48369075BE30B5114393AE43925EDDC382EF3B5D9898B2C4674C867ACC6FEA48463EFEC", "hash_ssdeep": "384:aLwCj6aYZS0reG41oCvYf6kQFTFemhjITi3K+dwJ0gM+KyW2VQwWqwGyeVZalxYI:0BkC5hnjHK+dwJ0qKKVQA65gA", "hash_imp": "n/a", "hash_pesha1": "44B637B4DBE16D74CFB8CC25E4315EB57FD845D4", "hash_pe256": "963022C2F151959D3B86C2D1CFAC2160E6CF97D2B1FF7C13C89CF4DF4BBA5376", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "AccCheckConsole.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "[Information] Command line argument\r\n\tText: -help\r\n\r\nThe syntax of this command is:\n\n\tAccCheckConsole [options] (-hwnd <hwnd> | -process <name>) [<dlls>]\n\n\tOptions:\n\t\t-hwnd <hwnd> Validates the given hwnd. Can be hex or dec.\n\t\t-window <title> Validates the window with the title given.\n\t\t-process <name> Validates the main window of the process with that name.\n\t\t-list Lists all the verification routines available.\n\t\t-enable <name> Runs the given routine. Can be specified more than once\n\t\t-disable <name> Runs all but the given routine. Can be specified more than once\n\t\t-log (info|warn|err) The lowest event rating that will be logged.\n\t\t-logfile <file> Outputs the log to file. Can be used multiple times.\n\t\t-suppress <file> Uses the XML file <file> to suppress errors.\n\t\t-quiet No logging to stdout.\n\t\t-help Quick Help.\n\n\tError codes returned from AccCheckConsole when using \"echo %errorlevel%\"\n\t\t0 - No errors and no warnings.\n\t\t1 - Usages statement was requested.\n\t\t2 - Errors and no warnings.\n\t\t3 - Errors and warnings.\n\t\t4 - No errors but Warnings.\n\t\t5 - Invalid command line.\n\nExamples:\n\n1) Run all verifications on a window with a specified name.\n\tAccCheckConsole -window \"Untitled - Notepad\"\n\n2) Run a subset of the verifications against an HWND, specifying a suppression file.\n\tAccCheckConsole -hwnd 0x00382f00 -enable CheckTabbing -enable CheckName -suppress suppress.xml\n\n3) Run all verifications from a new verification DLL.\n\tAccCheckConsole -window \"Untitled - Notepad\" VerificationRoutine1.dll\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\AccChecker\\AccCheckConsole.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "acccheckui.exe-939DB97EAF802AA6E0910B71327B6461": { "file_name": "acccheckui.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\AccChecker\\acccheckui.exe", "hash_md5": "939DB97EAF802AA6E0910B71327B6461", "hash_sha1": "776E2F720B197E3628938B8A753973ADF2AC8E54", "hash_sha256": "BF8AA9057ED39062A9730C4A60A56E6CAE58871D746ED5857FF5CEDBE8C039E7", "hash_sha384": "F0719BB890E51837FCCE157509A2F5DBFE50F2BEF691FD69D33850E776E3E55A2B0DB9E48562E2D7097114B5A5690915", "hash_sha512": "78C36348DB0308FD225D20EB56F36C6377D11A70A4B887887DF53C8716EF182821C541CE1E465614DC1CBD11A53042F3CE24A237E02BCAB26A4E6C9A8C13D1A5", "hash_ssdeep": "3072:roG0eEey3LrG/kWyIEWJYetCSZaPh6uEPl4iGo+XqDhPzpi+K/QFt:ro5933ObEWJYetXqi", "hash_imp": "n/a", "hash_pesha1": "6C8FD4E8A81F0F58CFF0559D9AECC027A63015A8", "hash_pe256": "13FB3BA02AFFFA72EB78BE0E7C385CF981853C6BBC9FA6B570B53F3A1F66037E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UI Accessibility Checker", "meta_original_filename": "AccCheckUI.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\AccChecker\\Microsoft.Diagnostics.Tracing.EventSource.dll": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_5080": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\AccChecker\\AccCheck.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\AccChecker\\UIAVerifications.dll": "File", "(RW-) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\AccChecker": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\AccChecker\\VerificationRoutines.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\AccChecker\\acccheckui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "VisualUIAVerifyNative.exe-171FFBF75F1A7597CEB1579F6000817E": { "file_name": "VisualUIAVerifyNative.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\UIAVerify\\VisualUIAVerifyNative.exe", "hash_md5": "171FFBF75F1A7597CEB1579F6000817E", "hash_sha1": "F5A0F0425178ED742190D304B49368368A91CC8A", "hash_sha256": "B2F5B2CB9474DC3C7AD50002A34DFC16F8BD82120C86FA3BDD7DB8C73B19441F", "hash_sha384": "DEE0D2DFA9D8693FADD6CEBEFBD68CDD8F13DD300EE8278BE9C2B299B54F4E9B2057F2BE209F88C6FB10A5661CE7014E", "hash_sha512": "418AE81D96DCABCBB5E303F0F65D2C93BF9A987C018A2AA76C689EFABEE79D2370070AC31F0C0D661C78885C4A52CADE5403761B9A112F4CE34FA5E937F05E2A", "hash_ssdeep": "6144:FOqyheCdi1s8GbW5eCxWmuNfOBVODnom8gjJOv3AaNWGIAX4c6UdpDlm:FLGHCQm", "hash_imp": "n/a", "hash_pesha1": "5FB8DE8DA1C7AAC9C03B0FB23E7D4D0329F6F028", "hash_pe256": "E752C3FA3D2AA64A00CE24C135B913627701CCFB30CEFD772F01FBAA55BE9538", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Visual UIA Verify", "meta_original_filename": "VisualUIAVerifyNative.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4396": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\UIAVerify\\UIAComWrapper.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\UIAVerify\\WUIATestLibrary.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\System32": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\UIAVerify\\Interop.UIAutomationClient.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\ieframe.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\112cHWNDInterface:5a05e0": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_ie_global_counters": "Section", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\UIAVerify\\WUIALogging.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\UIAutomationCore.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x64\\UIAVerify\\VisualUIAVerifyNative.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\SYSTEM32\\VCRUNTIME140_CLR0400.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\SYSTEM32\\ucrtbase_clr0400.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "runtime_window_title": "Visual UI Automation Verify : Client Side Provider" }, "accevent.exe-F84263097B3C4DE7D584C1E6E2B778D8": { "file_name": "accevent.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\accevent.exe", "hash_md5": "F84263097B3C4DE7D584C1E6E2B778D8", "hash_sha1": "04895DFD3F5A385E2B51D64E7082165BC6F4E475", "hash_sha256": "1369E8F96E54732F45FFAC11C713892F2CDF7AB688BED4B70209DC964928314B", "hash_sha384": "37BDC1BCEEB3BBBF9D2800F392DB2FE6B52CDB5A101D0C4F5E29CAC06DA479558DF757323624DB63F51E2F9044FCC082", "hash_sha512": "FAD76E4C298751CE36F6A6ADBD1C1629E8467B7849B47C2F2ECFB3629CD3E58E006525A0B8BD505D81C4A860A0DEA6675DCC820FF8FFBA782DF6479EB16F4A25", "hash_ssdeep": "3072:zXhiTM8mP4P6QO3kMKYMKByf1aC6Z4GcQ7DpUfmKwCAq1lOKjU9N7r1tjky/XTg:jhiTM8mP4P6QO3kMKYMKBxhVcQ7+fxwY", "hash_imp": "ED1F8E0A43D91499C5EB87827CA878FF", "hash_pesha1": "57135771CF26209386528186E1420EB702E076FE", "hash_pe256": "7840721B4771817407ADF467DC02CC7E36206F26413ADE4F64F1D0BB95DA5CBC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Accessible Event Watcher (32-bit UNICODE Release)", "meta_original_filename": "ACCEVENT.EXE", "meta_product_name": "Microsoft Active Accessibility", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.0.0", "meta_product_version": "7.2.0.0", "meta_language": "English (United States)", "meta_legal_copyright": " 2012 Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\SysWOW64": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\accevent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "AccEvent - UIAutomation Events [Stopped]" }, "adpcmencode3.exe-1390AAF9893E6224845F89C45EC874F4": { "file_name": "adpcmencode3.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\adpcmencode3.exe", "hash_md5": "1390AAF9893E6224845F89C45EC874F4", "hash_sha1": "5F072BFD5BFA3C77B4C6A2EA9B253665BC55CE9F", "hash_sha256": "E848E0A5384E2A0B0FF8B871598132D7A04BB809A35A9ED274F3F0FBF2ADAD3D", "hash_sha384": "60D023BFB1ED66FFFC6569EA5DC42BAA03C960487D02E53FE045B46EB60DC968DADD1EFCBC9DDF853B2B34E637F30BF8", "hash_sha512": "28C6882A5ADF0995409F81C6145DFF913BDC7973458C138969094EB68FF1B03C89932D7ADACA5C8513A6194F74206EC074EA5EA9E3B6A5E02DE3183A35D09334", "hash_ssdeep": "6144:lp5ZU8d5SfqJ1xBFa3D2Au7qbUx3+XbKtpCxCBMD8BeEjqkkd6mCOv:lJ15s2/azNQdSKtW3v", "hash_imp": "AD4D2D13AF2C3FD9E81859ADC25AD651", "hash_pesha1": "15C3AF7A8C6C0A89B671BFE35D6A76C754965330", "hash_pe256": "073165442A80619129AA5AE56577A130D08697E90E4CB60B27FEC7F53A0E6355", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ADPCM encoding and decoding utility", "meta_original_filename": "AdpcmEncode.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Copyright (C) 2012 Microsoft Corporation. All rights reserved.\r\n\r\nUsage: ADPCMENCODE [-b <N>] [-f <N>] <INPUTFILE>.wav <OUTPUTFILE>.wav\r\n\r\nIf the input file is PCM, it is encoded to an ADPCM file;\r\nif the input file is ADPCM, it is decoded to a PCM file.\r\n\r\nInput PCM files must be int8, int16 or float32, mono or stereo,\r\nwith at least 128 samples of audio and no loop regions shorter\r\nthan 128 samples.\r\n\r\nOptions:\r\n\t-b <32|64|128|256|512>: Number of samples per encoded ADPCM block (default 128)\r\n\t-f <N>: Bits per sample in decoded PCM file (8, 16, or 32; default 16)\r\n\r\nUnrecognized flag \"--\"\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\adpcmencode3.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "betest.exe-14376B986664CE9359FBA80D5730CC0A": { "file_name": "betest.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\betest.exe", "hash_md5": "14376B986664CE9359FBA80D5730CC0A", "hash_sha1": "07C62523C062E179AC11DBF5EB9A1B7CAF7B8432", "hash_sha256": "713F78C71F178EF3F79868A1977DEB033A65C72E08AD06D6C1D4780801292E79", "hash_sha384": "6AEAB45A4C60AA9ECC6DB2D652751209A5C8E0777245D20A6B5D586F6DE04B5C61AD258ECA0EE628972DEE3AF7EEB4FB", "hash_sha512": "BEE790E110988015469EF33DAA02C31EF8288BE15715ED8EFEF706E8D8D34EF47F65465171883F5C0822A5FB8582A6A8D2A182A0DB3B964EA53555C45B96FF67", "hash_ssdeep": "3072:YPqvmbB3loT632v0uOUTBbDv7kAZh2XkoTFbNLj81Exh0LrKnnSBeoKvmf3vh4v:CLoTVv0u7Bb72Nn81Exh0LrKg9SEfhi", "hash_imp": "486F924107195F6D293D7541B56FFF5A", "hash_pesha1": "F7BA21E333D6A2807230B80945681FB0BB8BDEEE", "hash_pe256": "8072CFC44BFB8C8FE528CAC510493DB312501AA7BA1B5B7AE00EC815994895D9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BETest, Volume Shadow Copy Service (VSS) Backup/Restore Test Tool", "meta_original_filename": "BETEST.EXE", "meta_product_name": "BETest", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "This version of BETest only runs on Windows 8 and Windows Server 2012 or above.", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\betest.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cameraprofiletool.exe-6A51DE13662E8ECE9DD8C8A70CFCB89D": { "file_name": "cameraprofiletool.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\cameraprofiletool.exe", "hash_md5": "6A51DE13662E8ECE9DD8C8A70CFCB89D", "hash_sha1": "4092E206755A6F1B31CBDC1A324D66E85C8D07F2", "hash_sha256": "598A150E1EACE7B97A9991CE6EF3FF16D1378F19DBFE67EBEEDA28E5B57E00F1", "hash_sha384": "F77A350CF6B39206FCE7EC6CE061C937301F0D0BC714239B37210CD86673E42732F0FE9E5FF947F44B184AE51373F78C", "hash_sha512": "A5EFC52842C8A533429C9DAD29A88D04B7A4BFD11E2423A187E90B87DEC0406B99E541C25604AA52F696B2B9EC18F11ED12A47070FD5AF92E46A121A68C1817C", "hash_ssdeep": "1536:y+IN/w8SQ6XcCiAXEjlNSLzhy+0hnOVcrZxI49:y+Aw8S9JiA0jWLVSnOVCZxI", "hash_imp": "B338910BDD45DBCCC162AE5DDB0F31D5", "hash_pesha1": "96EF7A89A642A944FDB1749AA664D15EFA50438E", "hash_pe256": "2A45DBAA2D259542DF26E3487A405377D049E9AE68F8A215D90DB303E0059396", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\cameraprofiletool.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Camera Profile Tool Test App", "meta_original_filename": "CameraProfileTool.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/598a150e1eace7b97a9991ce6ef3ff16d1378f19dbfe67ebeeda28e5b57e00f1/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\cameraprofiletool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "ProfileTool" }, "cert2spc.exe-6DD17EAB6CB9DB115AF13F5D9F9A7776": { "file_name": "cert2spc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\cert2spc.exe", "hash_md5": "6DD17EAB6CB9DB115AF13F5D9F9A7776", "hash_sha1": "3D3A9391BBBEE0FE8F101E06D1659069E00295E1", "hash_sha256": "0229305598E51975F0BCE0C073C9B1D5410CD884B7760FC3F1D9A2F731F138A6", "hash_sha384": "EE3141F5F70935B633C4BDE91132D89473FC31FBC9F8E5321DC74A5F4AD68FABD9F6B95F79E253753639667471CA24FC", "hash_sha512": "06877DFCCE5860523325B06116FED0C53DD8D386F61CB7A4C4F3ABF23CA4B37F193E7980A7F77B8C72E91A86FF208FCA0326667E3A9D9FBABCCEFBCCBF472BA4", "hash_ssdeep": "384:sntUvtGHO6G3MOBWn/Wne7wGyu2lZ4lrvKZ:lx6uv+H7Ul", "hash_imp": "7148B4312B50933480A1552D0F4E5817", "hash_pesha1": "A1D7C1EB45974B7E98D02A3E90BB1A9009E347C6", "hash_pe256": "595F92F78D129AAB4C39BCEC3FB28CB18FDC5E849D3F81FCA9D91911FEB42A38", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ECM Cert2Spc", "meta_original_filename": "CERT2SPC.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0229305598e51975f0bce0c073c9b1d5410cd884b7760fc3f1d9a2f731f138a6/detection", "output": "Usage: Cert2Spc {cert1.cer|crl1.crl ... certN.cer|crlN.crl} output.spc\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\cert2spc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "certmgr.exe-AFC75CA9510A5A5221222EDC66342935": { "file_name": "certmgr.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\certmgr.exe", "hash_md5": "AFC75CA9510A5A5221222EDC66342935", "hash_sha1": "C7ED5066BCB574529F7E1F8D32CC55B223E3E509", "hash_sha256": "AEB5C24499FAFAEACE3C8F93E6936730BC5AB17512E38E4F74164AF6868769D2", "hash_sha384": "DACB9201DD4068C1C051519677DEC165B04CDB007EFFE252DC7635B22C76372832818CFF68D8F0FC7F9CFD663EE823B4", "hash_sha512": "AAB3002CBB3E40820B1125D972F251C5EB7E6D12FB32CD1741D94BA78E72B925B18A8C5A71A3198BF76055B7ECA6034F2355B65F0C95BAAB1B740FC76FF0B5FD", "hash_ssdeep": "1536:0SVBbOaDDcxFXdf9qAhyMUBYw+WXsA9i9vYRf:0SnCdkAvUBt+WXsNYf", "hash_imp": "0FC82C88FCC1CB6AB4E7AB78D4291CF0", "hash_pesha1": "30AD7D540D96F24446745E54305BE9F80D9F149C", "hash_pe256": "638621EA61E591535C213FF68C4D22E54784E7A968CDE78C30CBF02FF6E4FB40", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ECM Certificate Manager", "meta_original_filename": "CERTMGR.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/aeb5c24499fafaeace3c8f93e6936730bc5ab17512e38e4f74164af6868769d2/detection", "output": "Usage: CertMgr [options][-s [-r <location>][SourceStoreName]\r\n [-s [-r <location>][DestinationStoreName]\r\nOptions: \r\n -add Add certificates/CRLs/CTLs to a storeFile or a system store\r\n -del Delete certificates/CRLs/CTLs from a storeFile or \r\n a system store\r\n -put Put an encoded certificate/CRL/CTL from a storeFile or\r\n a system store to a file. The file will be saved in X.509\r\n format. -7 can be used to save the file in PKCS #7 format\r\n -s Indicate the store is a system store \r\n -r <location> The system store location \r\n <currentUser|localMachine> Default to 'currentUser' \r\n -c Certificates in the store\r\n -crl Certificates revocation lists(CRLs) in the store\r\n -ctl Certificates trust lists(CTLs) in the store\r\n -v Verbose display of the certificates/CRLs/CTLs \r\n -all All certificates/CRLs/CTLs in the store\r\n -n <name> Common name of the certificate \r\n -sha1 <thumbPrint> The sha1 hash of the certificate/CRLs/CTLs \r\n -7 Save the destination store in PKCS #7 format\r\n -e <encode> Certificate/CRL/CTL encoding type. \r\n Default to X509_ASN_ENCODING\r\n -f <flag> CertStore open flags. Meaningful only if -y is set\r\n -y <provider> CertStore provider name\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\certmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ComparePackage.exe-D8816D5E19E91A30AA09CC036ECB1F32": { "file_name": "ComparePackage.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\ComparePackage.exe", "hash_md5": "D8816D5E19E91A30AA09CC036ECB1F32", "hash_sha1": "50B971B2742CBBF13A753B041D4314B826FE25C8", "hash_sha256": "A54360F1AD4414D343365FCC029944C3D8C9A7BD45D7A7BFD6DFF1EF6E31ADCA", "hash_sha384": "9C3909AF8E26F2E2333EEF2CD62C2C753663A18A2E1C44675A9DDD40562576B39D3FE97037EA5A64A72270B090C07562", "hash_sha512": "3492709243E86051B0E28DC0D1AE175EC0FBB9CC817B88B79878360A84546CC7E387509664641E26C5D399FDB0D30D1CAFB50D8501B346AD9684B0D14D0229FC", "hash_ssdeep": "768:FTF5BzCz6ArZEtOUHDrRyXnbT/23VRfNHl2Ag:fCeArKtOUj9y//AVRfNHlxg", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "1D0B395820C635DED9AFA61757E7288A77BB0684", "hash_pe256": "9F2C7ADC1F97EB1D5CB0BC06ABD072D89E56D8C4AD09B8C5BAC24A059F48E9E3", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\ComparePackage.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": " ", "meta_original_filename": "ComparePackage.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a54360f1ad4414d343365fcc029944c3d8c9a7bd45d7a7bfd6dff1ef6e31adca/detection", "error": "Path error: /? not found\r\nCheck the paths in your arguments. We couldn't find the files at the paths specified.\r\nError: The argument <original package path> should be a valid file.\r\n", "output": "Microsoft (R) ComparePackage Tool\r\nCopyright (C) 2018 Microsoft. All rights reserved.\r\nLog file is located under: C:\\Users\\user\\AppData\\Local\\Temp\\ComparePackage\\Logs_10\\Log.txt\r\n\r\nCompare Package started!\r\nVersion 10.0.0.0\r\n\r\nCompare Package started!\nComparePackage analyzes the differences between two versions of your package and helps you understand how the changes can impact users' updates.\r\n\r\nUsage: ComparePackage.exe [arguments] [options]\r\n\r\nArguments:\r\n <original package path> File system path to the original package or the original package's blockmap for comparison\r\n <new package path> File system path to the new package or the original package's blockmap for comparison\r\n\r\nOptions:\r\n -h Shown the usage\r\n -version Show the tool's version\r\n -v Enables verbose output to the console\r\n -o Overrides output XML if exists\r\n -XML Saves XML version of the output to the path specified in addition to the console output\r\n\r\nExamples:\r\nComparePackage <original package path> <new package path> [-XML <XML path>] [-o] [-v]\r\nComparePackage mypackage_1.04_x64.msix mypackage_1.05_x64.msix -XML \"C:\\diffoutputs\\mypackage_1.04_1.05_diff.xml\"\r\nComparePackage mypackage_1.04_x64.appx mypackage_1.05_x64.appx -XML \"C:\\diffoutputs\\mypackage_1.04_1.05_diff.xml\"\n\r\nSupported input types:\r\n .appx/.msix\r\n .appxbundle/.msixbundle\r\n .appxbundle/.msixbundle to .appxbundle/.msixbundle\r\n .eappx/.emsix to .eappx/.emsix\r\n .eappxbundle/.emsixbundle to .eappxbundle/.emsixbundle\r\n .xml to .xml (blockmaps only comparison)\r\n *Only packages encrypted with the test key /kt option in MakeAppx.exe are supported.\r\nDefinitions:\r\n Impact\r\n - The amount that a particular file impacts the users' update in bytes\r\n Net Update Impact Size\r\n - The sum of impact of all changed and added files, can be used to approximate users' update download size as a result of the new version\r\n Size Difference\r\n - Difference in file size in bytes between new and original version\r\n Size\r\n - File size in bytes of added or deleted files\r\n Duplicate Files\r\n - File sets that are exactly the same in the new package(does not consider original package)\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\ComparePackage.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "computerhardwareids.exe-9362D8B14B3D164D3D4673C7216399C4": { "file_name": "computerhardwareids.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\computerhardwareids.exe", "hash_md5": "9362D8B14B3D164D3D4673C7216399C4", "hash_sha1": "52B65D14048EAC6DBC35D515E92AF6CA0F62FF33", "hash_sha256": "074AD56D58183D7704E488A740C2B0EB9635283D601A7BE0A460C0792E07BF26", "hash_sha384": "FA8254F02B6B52AD81FBEE0A81906DE64D01C3CF551E1F39A553B45ED1802A1D3026B92E302DC11238CA822013C1F887", "hash_sha512": "5CDEB69686F4DA5EBCF6AD8A1FB52A8BFD5610CCC8F786148B5C314919260A57EE5A422FF2BBEDF69611A515954180FA536401C328DBE1630A3E8162AA0D77C9", "hash_ssdeep": "384:a/4QrL+TQqY+h87W/8Y95JRK7hOcGqsph1PTy7Y6zl61CTGqGTWESW34iwGy7OCc:aCVwlzNsLRG86NTGqaEi0OCc", "hash_imp": "C2011ED41B616413F5CB608C958D76CD", "hash_pesha1": "507E4D62B49E70F829B05A2EB834D2E9483741AB", "hash_pe256": "276FE03D5D4D3F2A8CE4438203787D82B41EFDE98383C2A83BFD2D9E3B08CE78", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ComputerHardwareIds is a tool to derive the computer hardware ids from SMBIOS information.", "meta_original_filename": "ComputerHardwareIds.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "NAME\r\n ComputerHardwareIds - Outputs the HardwareIds for the computer\r\n\r\nSYNOPSIS\r\n ComputerHardwareIds.exe [/mfg] [/product] [/family] [/ven] [/ver] [/major]\r\n [/minor] [/sku] [/enclosure] [/bb_mfg] [/bb_product] [/verbose] [/?]\r\n\r\nDESCRIPTION\r\n Outputs the HardwareIds for the computer. When executed without any command\r\n line arguments the HardwareIds are generated using data in the system\r\n BIOS. Optional arguments allow the generation of HardwareIds based on\r\n strings specified on the command line. When optional arguments are specified\r\n the BIOS values on the local computer are not used when generating the\r\n HardwareID values.\r\n\r\nOPTIONS\r\n\r\n Argument BIOS Field Meaning\r\n -----------------------------------------------------------------------------\r\n /ven \"BIOS vendor string\" Specifies the BIOS vendor string for\r\n a given system. If not specified the\r\n value is assumed to be NULL.\r\n\r\n /ver \"BIOS version string\" Specifies the BIOS version string for\r\n a given system. If not specified the\r\n value is assumed to be NULL.\r\n\r\n /major \"System BIOS Major Release\" Specifies the BIOS major release\r\n as a string representation of\r\n an int. If not specified the value is\r\n assumed to be '0'.\r\n\r\n /minor \"System BIOS Minor Release\" Specifies the BIOS minor release\r\n as a string representation of\r\n an int. If not specified the value is\r\n assumed to be '0'.\r\n\r\n /mfg \"System Manufacturer string\" Specifies the System Manufacturer\r\n string for a given system. If not\r\n specified the value is assumed to be\r\n NULL.\r\n\r\n /family \"System Family string\" Specifies the System Family string\r\n for a given system. If not specified\r\n the value is assumed to be NULL.\r\n\r\n /product \"System ProductName string\" Specifies the ProductName string for\r\n a given system. If not specified the\r\n value is assumed to be NULL.\r\n\r\n /enclosure \"Enclosure type number\" Specifies the number for the\r\n Enclosure type for the system. This\r\n number is the Byte value from the\r\n Sytem Enclosure or Chassis Type list\r\n in the SMBIOS specification. This\r\n value cannot be 0.\r\n\r\n /bb_mfg \"Baseboard Manufacturer string\" Specifies the Baseboard Manufacturer\r\n string for a given system. If not\r\n specified the value is assumed to be\r\n NULL.\r\n\r\n /bb_product \"Baseboard Product string\" Specifies the ProductName string for\r\n a given baseboard. If not specified the\r\n value is assumed to be NULL.\r\n\r\n /sku \"SKU Number string\" Specifies the SKU Number string\r\n for the system. If not specified\r\n the value is assumed to be NULL.\r\n\r\n /verbose \"true or false\" Specifies whether to print more\r\n information than just the GUIDs. If\r\n not specified verbose output is\r\n assumed.\r\n\r\n /? List of the command line options and\r\n usage.\r\n -----------------------------------------------------------------------------\r\n\r\n Up to fifteen HardwareIds will be generated depending on the following:\r\n * The BIOS fields available on the local system when no arguments are\r\n specified.\r\n * The command line arguments specified.\r\n\r\n Each of the following HardwareIds will be generated if the indicated BIOS\r\n fields or arguments are available:\r\n\r\n HardwareId 1 : Manufacturer + Family + Product Name + SKU Number + BIOS Vendor\r\n + BIOS Version + BIOS Major Release + BIOS Minor Release\r\n [required] /ven, /ver, /mfg, /product and /sku\r\n [optional] /major, /minor, and /family\r\n\r\n HardwareId 2 : Manufacturer + Family + Product Name + BIOS Vendor\r\n + BIOS Version + BIOS Major Release + BIOS Minor Release\r\n [required] /ven, /ver, /mfg, and /product\r\n [optional] /major, /minor, and /family\r\n\r\n HardwareId 3 : Manufacturer + Product Name + BIOS Vendor\r\n + BIOS Version + BIOS Major Release + BIOS Minor Release\r\n [required] /ven, /ver, /mfg, and /product\r\n [optional] /major and /minor\r\n\r\n HardwareId 4 : Manufacturer + Family + ProductName + SKU Number + Baseboard Manufacturer + Baseboard Product\r\n [required] /mfg, /product, /sku, /bb_mfg, and /bb_product\r\n [optional] /family\r\n\r\n HardwareId 5 : Manufacturer + Family + ProductName + SKU Number\r\n [required] /mfg, /product, and /sku\r\n [optional] /family\r\n\r\n HardwareId 6 : Manufacturer + Family + ProductName\r\n [required] /mfg, and /product\r\n [optional] /family\r\n\r\n HardwareId 7 : Manufacturer + SKU Number + Baseboard Manufacturer + Baseboard Product\r\n [required] /mfg, /sku, /bb_mfg, and /bb_product\r\n\r\n HardwareId 8 : Manufacturer + SKU Number\r\n [required] /mfg and /sku\r\n\r\n HardwareId 9 : Manufacturer + ProductName + Baseboard Manufacturer + Baseboard Product\r\n [required] /mfg, /product, /bb_mfg, and /bb_product\r\n\r\n HardwareId 10 : Manufacturer + ProductName\r\n [required] /mfg and /product\r\n\r\n HardwareId 11 : Manufacturer + Family + Baseboard Manufacturer + Baseboard Product\r\n [required] /mfg, /family, /bb_mfg, and /bb_product\r\n\r\n HardwareId 12 : Manufacturer + Family\r\n [required] /mfg and /family\r\n\r\n HardwareId 13 : Manufacturer + Enclosure Type\r\n [required] /mfg and /enclosure\r\n\r\n HardwareId 14: Manufacturer + Baseboard Manufacturer + Baseboard Product\r\n [required] /mfg, /bb_mfg, and /bb_product\r\n\r\n HardwareId 15: Manufacturer\r\n [required] /mfg\r\n\r\n Refer to the System Management (SMBIOS) Specification for additional\r\n details on these BIOS fields.\r\n\r\n BIOS Field Name Structure Name (Type) Offset\r\n -----------------------------------------------------------------------------\r\n Baseboard Manufacturer Baseboard Information (Type 2) 04h\r\n\r\n Baseboard Product Baseboard Information (Type 2) 05h\r\n\r\n System Manufacturer System Information (Type 1) 04h\r\n\r\n System Family System Information (Type 1) 1Ah\r\n\r\n System Product Name System Information (Type 1) 05h\r\n\r\n SKU Number System Information (Type 1) 19h\r\n\r\n BIOS Vendor BIOS Information (Type 0) 04h\r\n\r\n BIOS Version BIOS Information (Type 0) 05h\r\n\r\n System BIOS Major Release BIOS Information (Type 0) 14h\r\n\r\n System BIOS Minor Release BIOS Information (Type 0) 15h\r\n\r\n Enclosure type System Enclosure (Type 3) 05h\r\n -----------------------------------------------------------------------------\r\n\r\nEXAMPLES\r\n\r\n Generating HardwareIds from the BIOS:\r\n\r\n ComputerHardwareIds.exe\r\n\r\n Generating HardwareIds from command line arguments:\r\n\r\n ComputerHardwareIds.exe /ven \"Contoso Ltd.\" /ver \"0.158\" /major \"12\"\r\n /minor \"9\" /mfg \"Contoso\" /family \"Q Workstation\" /product \"3C273\"\r\n /enclosure \"6\"\r\n\r\nC:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\computerhardwareids.exe version\r\n 10.0.19041.1\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\computerhardwareids.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "convert-moftoprovider.exe-81BCF6AAD30486AAF250CAFB1AB864A1": { "file_name": "convert-moftoprovider.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\convert-moftoprovider.exe", "hash_md5": "81BCF6AAD30486AAF250CAFB1AB864A1", "hash_sha1": "54DD9FA84CC30C8C36365644280EF4AA86381F4E", "hash_sha256": "EC764A419FA1D1CFFC69AD4DBB3AE25BEB34E3F60CC04309C3FB7E3F3161CC98", "hash_sha384": "BE827A41178036D1461AF95C27BDFEF0E45BDDA8BDC7E69640E0AD179EB78E65E996D9492C67D7AEBDC0D350CB5FA043", "hash_sha512": "BBBF58B1962DC39CA3D95F7F31ECE45FB1FD9B6B1B4254895FEF07771002F4148A711FC838D08DCD019AF9BE6300373B17CD7022407570AB1E46B84F445323D7", "hash_ssdeep": "3072:Aw5I16fqebG3fyeJyjOfRZCxNokAXXQ8K0ei5yO:AHsftavJ3fRgxikAXh5", "hash_imp": "AB322AF5B64648824E2758D4959889BD", "hash_pesha1": "232CF476854073542DE79EFBCFB9400D869E8295", "hash_pe256": "BB08ECDC459E63D0679E3D07FDE9F71BEDEA17703649935AFD0FD7130AFA4F81", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI V2 provider code generation tool", "meta_original_filename": "convert-moftoprovider.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "\r\nGenerates provider source code (C) from MOF class definitions.\r\n\r\nUsage: Convert-MofToProvider.exe\r\n\t\t-MofFile <Mof files>\r\n\t\t-ClassList <Class list>\r\n\t\t-IncludePath <Path list>\r\n\t\t-InputParameterSet <Parameter Filename>\r\n\t\t[Other options]\r\n\r\n-MofFile <Mof files>\r\n\tSpecifies list of mof files that contains the MOF definitions\r\n\t(or includes them), which are seperated by space.\r\n\tIt must include any dependent MOF defintions as well (such as\r\n\tthe CIM schema).\r\n\r\n-ClassList <Class list>\r\n\tSpecifies list of the names of the MOF classes to be generated.\r\n\tIf no class specified, it will generate all classes.\r\n\r\n-IncludePath <Path list>\r\n\tSpecifies list of the directories, from which to search for included\r\n\tMOF files. If no include path specified, it will search current\r\n\tdirectory by default.\r\n\r\n-InputParameterSet <Parameter Filename>\r\n\tSpecifies the parameter filename, which defines the input parameters.\r\n\tThis option cannot be used with other options.\r\n\tExample: Convert-MofToProvider.exe -InputParameterSet param.txt\r\n\tExample of content for the parameter file,\r\n\t\t-MofFile a.mof\r\n\t\t-ClassList MSFT_A MSFT_B\r\n\t\t-IncludePath C:\\stdmof\r\n\r\n[Other options]\r\n\r\n-Help\r\n\tShows the syntax and the version of the code generation tool.\r\n\r\n-NoDescriptionQualifier\r\n\tDoes not generate the description qualifiers in the schema.c.\r\n\tDefault generate.\r\n\r\n-NoBooleanQualifier\r\n\tDoes not generate boolean qualifiers in the schema.c.\r\n\tDefault generate.\r\n\r\n-NoValuemapQualifier\r\n\tDoes not generate values or valuemap qualifiers in the schema.c.\r\n\tDefault generate.\r\n\r\n-NoStandardQualifier\r\n\tDoes not generate standard qualifiers in the schema.c.\r\n\tDefault generate.\r\n\r\n-NoSAL\r\n\tDoes not generate SAL annotation. Default generate.\r\n\r\n-SkipQualifiers\r\n\tGenerates no qualifiers in the schema.c.\r\n\tDefault does not generate. Cannot be used with any *qualifier options.\r\n\r\n-SupportFilter\r\n\tSet MI_MODULE_FLAG_FILTER_SUPPORT bit of MI_Module.\r\n\tDefault does not set.\r\n\r\n-MappingString\r\n\tGenerates mapping strings in the schema.c.\r\n\tDefault does not generate.\r\n\r\n-Quiet\r\n\tDoes not output detail information.\r\n\r\n-SkipLocalize\r\n\tDoes not generate strings.rc file for localizable qualifiers.\r\n\tResource file is always generated by default.\r\n\r\n-OutPath\r\n\tSpecifies output directory of generated files.\r\n\tCreates directory if it does not exist.\r\n\r\n-ExtraClass\r\n\tGenerates class files but not providers for classes listed.\r\n\r\n-OldRcPath\r\n\tGive the path to old rc file to reuse the string ids from.\r\n\r\nEXAMPLES:\r\n\tThe following example generates a 'MSFT_ComputerSystem' class,\r\n\twhich is defined in schema.mof.\r\n\r\n\tConvert-MofToProvider -MofFile schema.mof -ClassList MSFT_ComputerSystem\r\n\r\n\tConvert-MofToProvider -MofFile schema.mof -ClassList MSFT_ComputerSystem\r\n\t-IncludePath C:\\mof\\cim222\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\convert-moftoprovider.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ctrpp.exe-252B7132D2D8C35CDDE5EA5885DFA671": { "file_name": "ctrpp.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\ctrpp.exe", "hash_md5": "252B7132D2D8C35CDDE5EA5885DFA671", "hash_sha1": "60B34539D81C512A6085CA040A0F14A75CB8DA37", "hash_sha256": "C0F782DEFF229A8D80B7EA3EE1FD623DB4D0B02DAFADD0CE474E2A7BD56ED07D", "hash_sha384": "7C21FC85862766208B0CE72B6EE589CE274CBA4933F57AEA086683C8116CB2097E24BFF1C9C37266DA0E50CC4F9ECA5D", "hash_sha512": "B4A2B4F7F7748C47D9145F2ADD6376C3A519C42CBDAEB417E0D4B6C392CDBDF0EA3471EA863AD931BDB4FFF4303E221BCD327B2849505283DBFCF170B8B7E148", "hash_ssdeep": "3072:X3PWrg5dlM8IgeVw70reqnl1PWiQ/B3lngY9MCKM48u44VnfaS+Kt1c2ieDF1dtW:PWrA305X44VfaS/tW", "hash_imp": "5D9B62E065F43FC3F962709B0D79F60C", "hash_pesha1": "F08C7A5C6421A5586AD5A442FAA00493A9041E26", "hash_pe256": "0F82C1B91FBE5EF8D9A9DA84492E5802A5579D822DB7678B28FB1A94BBA2AF2D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "parse/validate performance counter manifest and generate helper source files", "meta_original_filename": "CTRPP.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nUsage: ctrpp [-NotificationCallback] [-MemoryRoutines] [-o <filename>]\r\n [-rc <filename>] [-migrate <filename>] [-prefix <prefix>] <manifest>\r\n\r\n -NotificationCallback - Generate customized notification callback template.\r\n Similar to \"callback\" attribute in <provider> element.\r\n -MemoryRoutines - Generate memory allocation/free routine templates.\r\n -Legacy - Revert to previous ctrpp file-output behavior (see below).\r\n -o <filename> - Generate header file for provider.\r\n -ch <filename> - Generate header file for containing counter names and ids.\r\n -rc <filename> - Generate resource source file.\r\n -migrate <filename> - Generate manifest file conforming to the latest schema version.\r\n This switch cannot be used with other switches.\r\n -prefix <prefix> - Prefix to be added to functions and variables generated.\r\n -backcompat - Generates code that is binary compatible with OSs prior\r\n to Windows 7.\r\n -summary <path> - generate binary counter file per provider\r\n generate summary global file GenSumResource.BIN\r\n -sumPath <path> - Path to generate binary counter files\r\n default .\r\n\r\n <manifest> - counter manifest to be processed\r\n\r\nExamples: ctrpp -o header.h -rc resource.rc component.man\r\n ctrpp -legacy component.man\r\n ctrpp -migrate new.man old.man\r\n\r\nLegacy Mode:\r\nThe -legacy switch causes ctrpp to generate four output files: two header files, a resource file, and a source code file. This mimics the behavior found in previous versions of ctrpp. The -o, -ch, -rc and -prefix options cannot be used in conjunction with -legacy.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\ctrpp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "DeployUtil.exe-1017233FC4816492D8B96614AB212DAA": { "file_name": "DeployUtil.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\DeployUtil.exe", "hash_md5": "1017233FC4816492D8B96614AB212DAA", "hash_sha1": "82EAA798E8A90BA44E44932DE3A4A6D82A3B7F3F", "hash_sha256": "0FB36938FEE6711D0B729F44DF4EF1292706F856C47AE5D2B301EE1B5A844DCE", "hash_sha384": "8297DB8391461D1409E22188A2F66AD78AABF6E78A917EE98488382BB870D9033F5096DCEF421F16876B1656251E5BF9", "hash_sha512": "428D7552C1B90D224FC9197F71DAAC85B3D1F29A894263BE7B2C652C2A7C2867290743EAD15626BFB5F004BAF8B0F4490D9A8471F7F020EA2ADDD69640A79A9B", "hash_ssdeep": "768:kCHGtkPE/Awpskxlsv5mqR64ATcJEBzsJoCYYC:kCHGtkY/lsv5T69cJEBzsC", "hash_imp": "CF613155CA9926133F8ACB2BDA2A73D2", "hash_pesha1": "33B5D846E1CB20C420F4BCA18D307CADCFE81E6E", "hash_pe256": "62EC2565EA3F8A7C9F3DC47ABE2B5075E655E650DEA6A13A4977DBC8817304C7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000052C8FAF5B90BB753AC000000000052", "signature_thumbprint": "8438EA0A58759BEA28DA7CF658413939F2AD5BFF", "signature_issuer": "CN=Microsoft Windows Phone Production PCA 2012, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Windows Phone, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0fb36938fee6711d0b729f44df4ef1292706f856c47ae5d2b301ee1b5a844dce/detection", "output": "Arguments:\r\r\n\t/install <file-path> (/cert <cert-path>) (/dependency <dep-path>...)\r\r\n\t/update <file-path> (/dependency <dep-path>...)\r\r\n\t/uninstall <package-full-name>\r\r\n\t/list\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\DeployUtil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dxc.exe-0C1709D4E1787E3EB3E6A35C85714824": { "file_name": "dxc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\dxc.exe", "hash_md5": "0C1709D4E1787E3EB3E6A35C85714824", "hash_sha1": "0C3EC93D2CD9145159D6E01CCDA419AD6B8E12E5", "hash_sha256": "2149F8C9967B3C09E8B34E0E8F7FC6FE7D35DEC9E0C499DAD69BFA31E6FBF16B", "hash_sha384": "5C69263180BEC5B7E14886C3CF02CBFCF3D87280C69C9C5A385952E3FD88605D5F267D149455BB0E691303BD6F118E3F", "hash_sha512": "121A2FE5EFB030A7CBC226721CC726CCE7CDCDE195190454C41A39BD1EC2321A0BC764D01BFC54782415AB0EECFB67C0AA25A6C7C0892332CC61A80A1B8921CE", "hash_ssdeep": "3072:9EGJPRap0JIMBqGzpfIEwTYNI80ciUJzgi7V8TKH+7cbfO8L3jwEH:qGJPRa5eiMN/0ciUJkrQ+7c7LLp", "hash_imp": "D3420C3C9D1EE443C8706CE9DDF85614", "hash_pesha1": "662463F1E43BA0D999EBB9EDF00301A44C37B7CA", "hash_pe256": "7D3148F7A9B893C533C39D2D70298C1A8BF01A87E3C4C18522281B6C3CF2F4DE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DX Compiler", "meta_original_filename": "dxc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2149f8c9967b3c09e8b34e0e8f7fc6fe7d35dec9e0c499dad69bfa31e6fbf16b/detection", "output": "OVERVIEW: HLSL Compiler\r\n\r\nVersion: dxcompiler.dll: 1.5 - 10.0.19041.1; dxil.dll: 1.5(10.0.19041.1)\r\n\r\nUSAGE: dxc.exe [options] <inputs>\r\n\r\nCommon Options:\r\n -help Display available options\r\n -nologo Suppress copyright message\r\n -Qunused-arguments Don't emit warning for unused driver arguments\r\n\r\nCompilation Options:\r\n -all_resources_bound Enables agressive flattening\r\n -auto-binding-space <value>\r\n Set auto binding space - enables auto resource binding in libraries\r\n -Cc Output color coded assembly listings\r\n -default-linkage <value>\r\n Set default linkage for non-shader functions when compiling or linking to a library target (internal, external)\r\n -denorm <value> select denormal value options (any, preserve, ftz). any is the default.\r\n -D <value> Define macro\r\n -enable-16bit-types Enable 16bit types and disable min precision types. Available in HLSL 2018 and shader model 6.2\r\n -export-shaders-only Only export shaders when compiling a library\r\n -exports <value> Specify exports when compiling a library: export1[[,export1_clone,...]=internal_name][;...]\r\n -E <value> Entry point name\r\n -Fc <file> Output assembly code listing file\r\n -Fd <file> Write debug information to the given file, or automatically named file in directory when ending in '\\'\r\n -Fe <file> Output warnings and errors to the given file\r\n -Fh <file> Output header file containing object code\r\n -flegacy-macro-expansion\r\n Expand the operands before performing token-pasting operation (fxc behavior)\r\n -flegacy-resource-reservation\r\n Reserve unused explicit register assignments for compatibility with shader model 5.0 and below\r\n -force_rootsig_ver <profile>\r\n force root signature version (rootsig_1_1 if omitted)\r\n -Fo <file> Output object file\r\n -Gec Enable backward compatibility mode\r\n -Ges Enable strict mode\r\n -Gfa Avoid flow control constructs\r\n -Gfp Prefer flow control constructs\r\n -Gis Force IEEE strictness\r\n -HV <value> HLSL version (2016, 2017, 2018). Default is 2018\r\n -H Show header includes and nesting depth\r\n -ignore-line-directives Ignore line directives\r\n -I <value> Add directory to include search path\r\n -Lx Output hexadecimal literals\r\n -Ni Output instruction numbers in assembly listings\r\n -no-warnings Suppress warnings\r\n -not_use_legacy_cbuf_load\r\n Do not use legacy cbuffer load\r\n -No Output instruction byte offsets in assembly listings\r\n -Odump Print the optimizer commands.\r\n -Od Disable optimizations\r\n -pack_optimized Optimize signature packing assuming identical signature provided for each connecting stage\r\n -pack_prefix_stable (default) Pack signatures preserving prefix-stable property - appended elements will not disturb placement of prior elements\r\n -recompile recompile from DXIL container with Debug Info or Debug Info bitcode file\r\n -res_may_alias Assume that UAVs/SRVs may alias\r\n -rootsig-define <value> Read root signature from a #define\r\n -T <profile> Set target profile. \r\n\t<profile>: ps_6_0, ps_6_1, ps_6_2, ps_6_3, ps_6_4, ps_6_5, \r\n\t\t vs_6_0, vs_6_1, vs_6_2, vs_6_3, vs_6_4, vs_6_5, \r\n\t\t cs_6_0, cs_6_1, cs_6_2, cs_6_3, cs_6_4, cs_6_5, \r\n\t\t gs_6_0, gs_6_1, gs_6_2, gs_6_3, gs_6_4, gs_6_5, \r\n\t\t ds_6_0, ds_6_1, ds_6_2, ds_6_3, ds_6_4, ds_6_5, \r\n\t\t hs_6_0, hs_6_1, hs_6_2, hs_6_3, hs_6_4, hs_6_5, \r\n\t\t lib_6_3, lib_6_4, lib_6_5, ms_6_5, as_6_5\r\n -Vd Disable validation\r\n -Vi Display details about the include process.\r\n -Vn <name> Use <name> as variable name in header file\r\n -WX Treat warnings as errors\r\n -Zi Enable debug information\r\n -Zpc Pack matrices in column-major order\r\n -Zpr Pack matrices in row-major order\r\n -Zsb Build debug name considering only output binary\r\n -Zss Build debug name considering source information\r\n\r\nOptimization Options:\r\n -O0 Optimization Level 0\r\n -O1 Optimization Level 1\r\n -O2 Optimization Level 2\r\n -O3 Optimization Level 3 (Default)\r\n\r\nSPIR-V CodeGen Options:\r\n -fspv-debug=<value> Specify whitelist of debug info category (file -> source -> line, tool)\r\n -fspv-extension=<value> Specify SPIR-V extension permitted to use\r\n -fspv-flatten-resource-arrays\r\n Flatten arrays of resources so each array element takes one binding number\r\n -fspv-reflect Emit additional SPIR-V instructions to aid reflection\r\n -fspv-target-env=<value>\r\n Specify the target environment: vulkan1.0 (default) or vulkan1.1\r\n -fvk-b-shift <shift> <space>\r\n Specify Vulkan binding number shift for b-type register\r\n -fvk-bind-globals <binding> <set>\r\n Specify Vulkan binding number and set number for the $Globals cbuffer\r\n -fvk-bind-register <type-number> <space> <binding> <set>\r\n Specify Vulkan descriptor set and binding for a specific register\r\n -fvk-invert-y Negate SV_Position.y before writing to stage output in VS/DS/GS to accommodate Vulkan's coordinate system\r\n -fvk-s-shift <shift> <space>\r\n Specify Vulkan binding number shift for s-type register\r\n -fvk-t-shift <shift> <space>\r\n Specify Vulkan binding number shift for t-type register\r\n -fvk-u-shift <shift> <space>\r\n Specify Vulkan binding number shift for u-type register\r\n -fvk-use-dx-layout Use DirectX memory layout for Vulkan resources\r\n -fvk-use-dx-position-w Reciprocate SV_Position.w after reading from stage input in PS to accommodate the difference between Vulkan and DirectX\r\n -fvk-use-gl-layout Use strict OpenGL std140/std430 memory layout for Vulkan resources\r\n -fvk-use-scalar-layout Use scalar memory layout for Vulkan resources\r\n -Oconfig=<value> Specify a comma-separated list of SPIRV-Tools passes to customize optimization configuration (see http://khr.io/hlsl2spirv#optimization)\r\n -spirv Generate SPIR-V code\r\n\r\nUtility Options:\r\n -dumpbin Load a binary file rather than compiling\r\n -extractrootsignature Extract root signature from shader bytecode (must be used with /Fo <file>)\r\n -getprivate <file> Save private data from shader blob\r\n -P <value> Preprocess to file (must be used alone)\r\n -Qembed_debug Embed PDB in shader container (must be used with /Zi)\r\n -Qstrip_debug Strip debug information from 4_0+ shader bytecode (must be used with /Fo <file>)\r\n -Qstrip_priv Strip private data from shader bytecode (must be used with /Fo <file>)\r\n -Qstrip_reflect Strip reflection data from shader bytecode (must be used with /Fo <file>)\r\n -Qstrip_rootsignature Strip root signature data from shader bytecode (must be used with /Fo <file>)\r\n -setprivate <file> Private data to add to compiled shader blob\r\n -setrootsignature <file>\r\n Attach root signature to shader bytecode\r\n -verifyrootsignature <file>\r\n Verify shader bytecode with root signature\r\n\r\n", "error": "dxc failed : Target profile argument is missing\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\dxc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dxcapsviewer.exe-61CD366558971420E0238C19CAD462F0": { "file_name": "dxcapsviewer.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\dxcapsviewer.exe", "hash_md5": "61CD366558971420E0238C19CAD462F0", "hash_sha1": "9508239ABDD72AC612B49B0679EF7198A8A89918", "hash_sha256": "59EA75181D0120BA94974BBCAC189A4E9386BB2B03232C01B72B3A436620B056", "hash_sha384": "DFE9F94642E561CF937E6A83C03709E69ED1C8093341694DE21834911BC0841617C56D7070EA9C937FA2A4F98FAECB4F", "hash_sha512": "5AD94185446E24F5288E9EAD609AAE9509A0BD775D1C9D3D5531583A91268FA04A023A7A21C28DDE7377CD4273FD8B2569EEC5973D2C8A7D26857AEC9E1EAD2E", "hash_ssdeep": "3072:FBvNiYH0//SOeCUQKYKEHDN5Nr1VNW2PdvM0:FVNXq/SDN3lEH9BPdt", "hash_imp": "AF0FEA4B3241EC32150F78CDAD863062", "hash_pesha1": "743A7A46F2DCEEC9B62B558F56550BA8B9CAD85C", "hash_pe256": "43E2BF1095193F6F2B5A515C0BE9165FDEACFCDCB1A35C441E208985003C2B40", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) DirectX Caps Viewer", "meta_original_filename": "dxcapsviewer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\dxcapsviewer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "espexe.exe-88E35AB456A7EDDD041185DFA528C389": { "file_name": "espexe.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\espexe.exe", "hash_md5": "88E35AB456A7EDDD041185DFA528C389", "hash_sha1": "6B0F43C8BF933E12415901E92DCBA9FD0BB1C8B0", "hash_sha256": "42CD2B1844818BF66796048BFC0FB3CA6B59E410DA87FFC294C04E7368A1594D", "hash_sha384": "0FFE6841F10509179D999F869C0B158B8A7AD883985E34C8152803B50C70249E4CB8BD7CD3FE0062AA0EA995F5070B92", "hash_sha512": "31CB2CC2B3C9A2158751988DE495ACB314B0EF67E410A3724D82F946AA8AF83608413257B594913D1EDF40CD986E749C58A1555DF2944435EEE930A3E38BEE22", "hash_ssdeep": "768:JP/oOjx7qgi7hMLXRXvTBjkuCCe8RLIWM+giTGicL:Z/YL7hIFbBjdCd8RhM+giKj", "hash_imp": "08F8F762932C1554A5E68AB3209F7544", "hash_pesha1": "C0FE64EFD94D768734B7E044AC114290C11CBD07", "hash_pe256": "14E1933CA9DB69C371CE0FA60728D3EB2A2CEB6917A3D07CFD495DA2323E4E46", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) Economical Service Provider Application", "meta_original_filename": "ESPEXE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright Microsoft Corporation 1995. All Rights Reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\espexe.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "ESP: The Economical Service Provider" }, "extidgen.exe-9792D5CEDA67197DF7890BCEBE8E4B51": { "file_name": "extidgen.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\extidgen.exe", "hash_md5": "9792D5CEDA67197DF7890BCEBE8E4B51", "hash_sha1": "0CCB43855DDE978DC40A11A92F2AA189883E5726", "hash_sha256": "98389C5AF3740A6F517537306995F0E8DB26960C2ED33441C5D5FD3DD150A563", "hash_sha384": "4CD8A3D5C167C761D6D48561B5AC76CC2A8D315DEA53E17912BBFE343038888F6F858CE8EDA59C4DB18F68ECD9F5FD7C", "hash_sha512": "6B794D8F92011213140296CC38FB7002695709B2BBD92CA65EE960AB035A90CD107E0CC77E2CB7F38070D0A052DF66A8420170C17F27C0C95A5B1BF138362F31", "hash_ssdeep": "192:zPjs8GzUqSFplZwDLt71qWRWWSawTyihVWQ4eWLCeIpeLirKqnaj/W4:zLGYqSblAJ4WRLwGyFe9LIKlzP", "hash_imp": "6CE389B087B7BC0CDD9A2FB3DE49102B", "hash_pesha1": "1DE18A9EF8C6E1B9FAC4FC4C8FA523D54A55F16C", "hash_pe256": "5B0ACFE1CF3CC846EC77747C89B276DC22737CC572145EAD0F120984C027BEC1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extension ID Generator", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All Rights Reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nMicrosoft Extension ID Generator v1.1\r\nCopyright 1993-2004 Microsoft Corporation. All Rights Reserved.\r\nA component of the Windows Telephony Software Development Kit.\r\n\r\nUsage: EXTIDGEN\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\extidgen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "filetypeverifier.exe-F440C0F23CF3ED7E047D5A6F6E6F504D": { "file_name": "filetypeverifier.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\filetypeverifier.exe", "hash_md5": "F440C0F23CF3ED7E047D5A6F6E6F504D", "hash_sha1": "885F620A6A528199C8EE0D7F1C7CC3BBA521DC5F", "hash_sha256": "73ED614DA288390E05026CE3A4CE9BA3B09F542D9E6E9181AB1D4531EB57DEC9", "hash_sha384": "36F6266D1E1C1D0889F21DD475695D78E4585306B8D312EB694B2ACE386421EEE745F19BAE164EED2862D0A144011021", "hash_sha512": "DCBBCD67E26A9C1AB387C10CD1AA5727162A230B109FC2CB4C12758556AE727DAEF3B7E3E0EF01E2C6F0AF19014DB1093DEA05298A9514422930C763E507732A", "hash_ssdeep": "6144:PlWjDyBORuFF2cbx0AmcPdYmdpoBIU2P:PWyBO8z0Amm", "hash_imp": "A0DBF2F4F4AB884440E2ABF3D7763781", "hash_pesha1": "E54B3FD3F08A70D6600C7D3E8E00D489493AC159", "hash_pe256": "CCAB52F3C13A1237C2A68CAA31D50595CC0E3AA9526395198C25D5D16703F618", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Type Verifier", "meta_original_filename": "FileTypeVerifier.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\filetypeverifier.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "File Type Verifier" }, "filtdump.exe-AE916637051E6E5D87ED4312F38CA665": { "file_name": "filtdump.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\filtdump.exe", "hash_md5": "AE916637051E6E5D87ED4312F38CA665", "hash_sha1": "3E2C35E6AD6D7F5FDD4CF3869D3FB53673BC007B", "hash_sha256": "7ECA7100EA2168AAF635DDD6C12C2D00FE11B0858FAD26A876679187E93BF000", "hash_sha384": "FA92549F22D8A66FBF5459C017F997DCCBAC25C4A3A8885FE011DDE1C5C97516DAA1BEDD4C5327544B4BACC44B752E7D", "hash_sha512": "384221B256CB7AB66D3C65B4BC2B139305D61AD436AB9E9EC057CE10E63DA613D742C3A55901716365E07B92D5B55B3F4AD2360F2BE8896D8A504E265EBDCD16", "hash_ssdeep": "768:db4a/BM3q5E8QYOFs5CK6ZFhxGyX8t1zmm+KfQS3NdO:t4a/BM3q5E8QYOFs5CK6ZEyimNKfVNQ", "hash_imp": "7750F28F6AF10CBD1B8505A76B910309", "hash_pesha1": "33F3EF475036D5D7F99455D487D46679BF68730F", "hash_pe256": "18595D7235A34D399E9B4C99ABE7EB724299AAAC86553D223C791C5C433D5021", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Filter dump utility", "meta_original_filename": "filtdump.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "FILE: help\nIFILTER: LoadIFilter failed, hr == 0x80070006\nIFILTER: SHCreateStreamOnFileEx failed, hr == 0x80070006\nLoadIFilterWrapper failed, hr == 0x80070006\nFILTDUMP failed, hr == 0x80070006\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\filtdump.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "filtreg.exe-CC9F4DAD357A182D9CCD63065BD5A5F7": { "file_name": "filtreg.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\filtreg.exe", "hash_md5": "CC9F4DAD357A182D9CCD63065BD5A5F7", "hash_sha1": "B1DB3421813E3A242D0495D601726944D2A3E3C5", "hash_sha256": "F106A0F6F264EC6EB99FF6BEBB50EDF6A57FD2741C256199842EBF2237F9DD90", "hash_sha384": "82019426DE6696EEE141D0014D73207DD9A8251BCE175CA4DB63D865B38147FB9AF1EDED67BC617E6569CED477190DE8", "hash_sha512": "59A39BCCB2DA6AA252913F96B94180C611DCA865127312E0A3B9F2BE923FC5425876136EF5821A850E95DFB9B1B3C67CD0B1AEF2631F01E51BF6A42AD38FD970", "hash_ssdeep": "192:3UJFeD7vkuExHHm5mWxwtmiNIdx0LMmet/WwyWbSm7Ks:9mobiN+0gb/WwyWbSmK", "hash_imp": "918D18EA5B5619563D5DB9E6909BCF8C", "hash_pesha1": "094B6084C7499174031A4008C4366647ECDA6AD3", "hash_pe256": "3DFB29E635873F8D41274004FDD7793AC679AA6D05D604C7844DB926CC5A6455", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\filtreg.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Filter registration dump utility", "meta_original_filename": "filtreg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f106a0f6f264ec6eb99ff6bebb50edf6a57fd2741c256199842ebf2237f9dd90/detection", "output": "Usage: filtreg [dstExt] [srcExt]\r\n Displays IFilter registrations. If [dstExt] and [srcExt]\r\n are specified then [dstExt] is registered to act like [srcExt].\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\filtreg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ftquery.exe-C5C7F52D2761F1B75B21D105A4E6BA74": { "file_name": "ftquery.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\ftquery.exe", "hash_md5": "C5C7F52D2761F1B75B21D105A4E6BA74", "hash_sha1": "B9ECA5819286471D6492EB1322C7885A592EC36C", "hash_sha256": "23BAC7E35C0A53D925D4605F3C74A6296E60685638E30FA7C6B9C8084477D866", "hash_sha384": "CF3E6EB74F05345D1074306D1BAD26E2F98CC6E8CEB2C0488AF55055D3F58DD7422DF5BDE5AB874C6D765F7C67AECF3B", "hash_sha512": "DCAE13DD385D053A5874CB16AD43F1EC59B792BD5CAB382A0CBDE91060D5683FD819A6748713F85D1B34AF78004445DCD98B71FB6A900D0F06D3EB279FC21162", "hash_ssdeep": "768:a2Aq/znu2gyGKFcwF+QaVhfZsgZoF5ZwM6rs4KZZ25FCo:XAcqaFcwFZaBnoF5ZwhrsrZID", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "136F73B3E5C37C3925C7ECF28DAD0B9CBDF15ED8", "hash_pe256": "CCC001E3BE990AB2F3A0DEC97406F182C10D762434E98BC8536BA71BFC5BD875", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "ftquery.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "ftquery.exe <SQL query> | <Query file> [Options]\r\n\n<SQL query> \r\n Example1: \"SELECT path from systemindex\"\r\n Example2: \"SELECT path from mymachine.systemindex where scope='file://mymachine/mysard/foo'\"\r\n Example3: \"SELECT path from mymachine.systemindex where scope='@PATH@'\"\n\t\t(where %PATH% is an environment variable.\n\t\t Note the @'s surrounding the environment variable name.)\r\n\n<Query File> Format per query (repeat for each query):\r\n --TSQLQuery=<Query description> [Any options]\r\n <SQL>\r\n\nAll options can either be on the command line or per query unless otherwise noted.\r\n\n/Bare\r\n Suppress all output except the actual query results.\r\n\n/Binary:<path>\r\n The remote binary path for accessing ftquery.exe on a remote machine when doing /purge for a remote query.\r\n By default this is just ftquery.exe so if it is on a local path of the remote machine it will work.\r\n\n/Busy\r\n Wait for indexer to be busy before executing query and measuring performance.\r\n Normally /Perf will wait for idle.\r\n\n/Cold\r\n Restart the indexer for a cold query if you are an administrator.\r\n On the command line will reset once before all queries.\r\n On an individual query in a file will reset the query. (Not compatible with /thread.)\r\n This will also work on remote machines if you are an administrator on the remote machine and ftquery.exe is available on the remote machine.\r\n\n/Close:<label>[,<label>]\r\n Before executing this query, previous queries with the label will be closed.\r\n Cannot be specified on the command line.\r\n\n/Delay:<miliseconds>\r\n Delay before each query execution. Default value is 0\r\n\n/Depth:<number>\r\n Recursion depth when expanding hierarchical rowsets for GROUP ON queries.\r\n 0 = stop at first top level rowset, 1 = stop at second level, etc.\r\n By default all results are expanded.\r\n\n/Excel:<file>\r\n Dump out an excel friendly summary at end or into file if present.\r\n\n/Expensive\r\n By default expensive properties are not computed.\r\n This sets DBPROP_DONOTCOMPUTEEXPENSIVEPROPERTIES=false and adds these rowset properties:\r\n ResultsFound -- the total number of items that match the where clause.\r\n MaxRank -- the maximum rank of any item that matches the where clause.\r\n\n/FirstPage:<n>\r\n The time to get the first page of results is measured. Default is 60.\r\n\n/Impersonate:{domain\\}user!password\r\n This will impersonate the user for the duration of the query. Domain defaults to redmond.\r\n\n/Iterations:<number>\r\n Number of iterations for <SQL query> | <Query file> execution. Cannot be specified per query in a query file.\r\n Default value is one iteration.\r\n\n/Open:<label>\r\n Keep rowset open after query so the query can be reused by putting ReuseWhere($<label>) into the query.\r\n Cannot be specified on the command line.\r\n\n/Output:<filename>\r\n Direct output to filename.\r\n\n/Page:<n>\r\n Maximum number of rows to fetch at a time. Default is 60.\r\n\n/Perf\r\n Measure query performance. No query results are displayed. Implies /Stats.\r\n\n/Purge\r\n Purge standby lists on the machine being queried.\r\n This is automatically called when using /cold with a remote query.\r\n\n/Rows:<n>\r\n Only fetch this many rows from the top rowset. By default all rows will be fetched.\r\n\n/Share:<\\\\machine\\share{\\path..}>\r\n This will take any query for the local machine and transform it to be over the remote share.\r\n FROM SystemIndex -> FROM \"<machine>\".SystemIndex and the WHERE clause adds a restriction for the share.\r\n\n/Stats\r\n Display all of the stats generated by /Perf together with results.\r\n\n/Thread:<id>\r\n All queries with the same ID will be executed sequentially, but different ID's will be executed in parallel.\r\n Each iteration will wait until all threads are finished.\r\n\n/Timeout:<number>\r\n Timeout for the query in seconds. Default is 0 which means no timeout.\r\n\nPer-Query Output. Sections in {} are only present if /Stats or /Perf\r\n Description=<description if any>\r\n WhereID Label=<label if any>\r\n Query=\r\n <actual query>\r\n <Non-default parameter settings>\r\n {<Perf counters>\r\n Items = Number of URLS in history\r\n Terms = Number of unique terms in inverted index\r\n Inverted Index = Size of inverted index\r\n In-memory Worlists = number of word lists\r\n Persistent Indices = total L1/L2/L3/L4\r\n Flushes = number of currently executing flushes if non-zero\r\n Merges = MasterMerges L1/L2/L3/L4 ongoing merges if non-zero\r\n Crawls in progress = number of crawls in progress if non-zero\r\n Documents in progress = number of documents in word lists if non-zero\r\n Iterating History\r\n Recovery in progress\r\n }\r\n <Column names if not /Perf>\r\n <Rows if not /Perf>\r\n Expanded Rows=<number of expanded rows>[, Children=<total number of children rows>]\r\n {<Server Version Information>\r\n Server=<server version>\r\n WinVer=<server windows major>.<server windows minor>\r\n NLS=<NLS version>.<NLS Defined Version>\r\n WhereID=<where ID for query>\r\n }\r\n {<Timing information>\r\n Execute=<time to parse query and send to server>\r\n Properties=<time to get rowset properties>\r\n Avg Rows/Page=[average number of rows retrieved per page for top-level rowset]\r\n 1st Row=[time from execute to very first row]\r\n <FirstPage>th Row=[time from execute to <FirstPage> rows]\r\n All Rows=[time from execute to get all rows]\r\n }\r\n\nSummary Output for Iterations > 1:\r\n Execute [min avg max] -- stats for execution time\r\n Properties [min avg max] -- stats for property retrieval time\r\n 1st Row [min avg max] -- stats for 1st row time\r\n <FirstPage>th Row [min avg max] -- stats for first page of rows time\r\n All Rows [min avg max] -- stats for getting all rows\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\ftquery.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "fxc.exe-9DB376CC62713F65E9AF94C294F20177": { "file_name": "fxc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\fxc.exe", "hash_md5": "9DB376CC62713F65E9AF94C294F20177", "hash_sha1": "37D27830EB922E9E4C245D1DEAE9FF230777F351", "hash_sha256": "CA1954EC33FC845502928744E642AA01FB205067248BECB1018CF6FD68B998FE", "hash_sha384": "87A56122A2E4D23D0192429447667097EA1C2CFF7C6C8DE1AD3E09F9C7653D6932D576618BA35749F651C1DE5161C0F3", "hash_sha512": "D108F7E22461F916B6FCFDD8AA6E39A45250124EFF0B38958FC9240666B1CBCA01B95F1FB43388594CA14CB87A0EB265FA43E4594D9B09510485031B7C40FA33", "hash_ssdeep": "1536:EKObo10rG30FqPvYu2KfBGhU+XgtC57L/toKFG6xR4IgmX+fHY0f8SDCYywBu3PP:XOk6h4cV1oKFZxQfHDR32PjT", "hash_imp": "26CDFD3C494168E05B79F230451C2097", "hash_pesha1": "7A2C6DEC193E5971BE13FA4F59D8ADE6FC028302", "hash_pe256": "9A7659394743240C47F10B336FCE20A601E0EB3E1C8039C9015AE4E0FEA4BA38", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "fxc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Microsoft (R) Direct3D Shader Compiler 10.1\r\nCopyright (C) 2013 Microsoft. All rights reserved.\r\n\r\nUsage: fxc <options> <files>\r\n\r\n /?, /help print this message\r\n\r\n /T <profile> target profile\r\n /E <name> entrypoint name\r\n /I <include> additional include path\r\n /Vi display details about the include process\r\n\r\n /Od disable optimizations\r\n /Op disable preshaders\r\n /O{0,1,2,3} optimization level 0..3. 1 is default\r\n /WX treat warnings as errors\r\n /Vd disable validation\r\n /Zi enable debugging information\r\n /Zss debug name with source information\r\n /Zsb debug name with only binary information\r\n /Zpr pack matrices in row-major order\r\n /Zpc pack matrices in column-major order\r\n\r\n /Gpp force partial precision\r\n /Gfa avoid flow control constructs\r\n /Gfp prefer flow control constructs\r\n /Gdp disable effect performance mode\r\n /Ges enable strict mode\r\n /Gec enable backwards compatibility mode\r\n /Gis force IEEE strictness\r\n /Gch compile as a child effect for FX 4.x targets\r\n\r\n /Fo <file> output object file\r\n /Fl <file> output a library\r\n /Fc <file> output assembly code listing file\r\n /Fx <file> output assembly code and hex listing file\r\n /Fh <file> output header file containing object code\r\n /Fe <file> output warnings and errors to a specific file\r\n /Fd <file> extract shader PDB and write to given file\r\n /Vn <name> use <name> as variable name in header file\r\n /Cc output color coded assembly listings\r\n /Ni output instruction numbers in assembly listings\r\n /No output instruction byte offset in assembly listings\r\n /Lx output hexadecimal literals\r\n\r\n /P <file> preprocess to file (must be used alone)\r\n\r\n @<file> options response file\r\n /dumpbin load a binary file rather than compiling\r\n /Qstrip_reflect strip reflection data from 4_0+ shader bytecode\r\n /Qstrip_debug strip debug information from 4_0+ shader bytecode\r\n /Qstrip_priv strip private data from 4_0+ shader bytecode\r\n /Qstrip_rootsignature strip root signature from shader bytecode\r\n\r\n /setrootsignature <file> attach root signature to shader bytecode\r\n /extractrootsignature <file> extract root signature from shader bytecode\r\n /verifyrootsignature <file> verify shader bytecode against root signature\r\n\r\n /compress compress DX10 shader bytecode from files\r\n /decompress decompress bytecode from first file, output files should\r\n be listed in the order they were in during compression\r\n \r\n /shtemplate <file> template shader file for merging/matching resources\r\n /mergeUAVs merge UAV slots of template shader and current shader\r\n /matchUAVs match template shader UAV slots in current shader\r\n /res_may_alias assume that UAVs/SRVs may alias for cs_5_0+\r\n /enable_unbounded_descriptor_tables enables unbounded descriptor tables\r\n /all_resources_bound enable aggressive flattening in SM5.1+\r\n\r\n /setprivate <file> private data to add to compiled shader blob\r\n /getprivate <file> save private data from shader blob\r\n /force_rootsig_ver <profile> force root signature version (rootsig_1_1 if omitted)\r\n\r\n /D <id>=<text> define macro\r\n /nologo suppress copyright message\r\n\r\n <profile>: cs_4_0 cs_4_1 cs_5_0 cs_5_1 ds_5_0 ds_5_1 gs_4_0 gs_4_1 gs_5_0 \r\n gs_5_1 hs_5_0 hs_5_1 lib_4_0 lib_4_1 lib_4_0_level_9_1 \r\n lib_4_0_level_9_1_vs_only lib_4_0_level_9_1_ps_only lib_4_0_level_9_3 \r\n lib_4_0_level_9_3_vs_only lib_4_0_level_9_3_ps_only lib_5_0 ps_2_0 \r\n ps_2_a ps_2_b ps_2_sw ps_3_0 ps_3_sw ps_4_0 ps_4_0_level_9_1 \r\n ps_4_0_level_9_3 ps_4_0_level_9_0 ps_4_1 ps_5_0 ps_5_1 rootsig_1_0 \r\n rootsig_1_1 tx_1_0 vs_1_1 vs_2_0 vs_2_a vs_2_sw vs_3_0 vs_3_sw vs_4_0 \r\n vs_4_0_level_9_1 vs_4_0_level_9_3 vs_4_0_level_9_0 vs_4_1 vs_5_0 vs_5_1 \r\n", "error": "C:\\Users\\user\\help(1,1-4): error X3000: unrecognized identifier 'DXGI'\r\n\r\ncompilation failed; no code produced\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\fxc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "gc.exe-DED3A694B3196DD19BF867DA4CC48D33": { "file_name": "gc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\gc.exe", "hash_md5": "DED3A694B3196DD19BF867DA4CC48D33", "hash_sha1": "21AF756A8EA1D8093A7BB9743C9D2C6898530D00", "hash_sha256": "4FE21A8C875440A0D05EC9DF69D21DFEC4AD48BC0249143F3E91ABAE24E7D592", "hash_sha384": "D565A2BA35EAE4FA9525710C48E02FDB5A80A1576C28114D9DB3F46286225BD017526EA6B5FDCD6ECD78C73BF4B396BD", "hash_sha512": "745156D7BA84A684202766768CD8C06B8B6C01E0683D4129BE2E2BE108C9D2B55BFBCBC4040C8BE40B6AD01A815CD9A822801C6CE29B61EF3A040469987576AC", "hash_ssdeep": "1536:aVVMpwelnBx18ohqW6nO9KuUcIZ4czkcAs1jeWVvtr:aVW9bxNuO9nUxWcA1WV5", "hash_imp": "95D2DFE642977AFF1F788536FD527824", "hash_pesha1": "FC79A2C3D0FDE8DD15B1D85D6D17D12899391925", "hash_pe256": "29BA243C7C2A8734C58FA3B9A7520A6031353527EDA7C2560CD52688C82219FD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "GC - Console grammar compiler", "meta_original_filename": "GC.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.3.24006.00 (WinBuild.160101.0800)", "meta_product_version": "5.3.24006.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "gc.exe [/o output_filename] [/h header_filename] [/s | /w] input_filename\r\n\t/s\tCompile SAPI XML grammars only\r\n\t/w\tCompile W3C XML grammars only\r\n", "error": "[SAPI XML] help(641) : XML parsing error: Whitespace is not allowed at this location.\r\n[SAPI XML] Compilation Failed!\r\n[W3C XML] help(1) : [0xC00CE556] - Invalid at the top level of the document.\r\r\n\r\n[W3C XML] Compilation Failed!\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\gc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "genmanifest.exe-627BE6296CC28A00F2B109E233B4BEF9": { "file_name": "genmanifest.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\genmanifest.exe", "hash_md5": "627BE6296CC28A00F2B109E233B4BEF9", "hash_sha1": "D8A0DD65C68A1EBAF69E6FB28D53E378E0E1A5DE", "hash_sha256": "F846ADE2BD0C354402B89EAB0421128390B2635D85C13706952D63F1860CFCA9", "hash_sha384": "86123CA187B34EE2F0A2F4D769CA20BFE2162E6C6FB6EF360EE2C67DA248E585996A8201B699367B7C7E71CBE695DE38", "hash_sha512": "D1D2CDA10664D9F3C679D37806AFC899D16A31EEDAAA9797A862F7F4CA52592EF7C2360975CB7154890B99EDBDDF0C395A255976B6112CB0B47B0F9B2E9E2418", "hash_ssdeep": "3072:TLkrE38O3mkVg1b60LSPDYYcbMKdWSQLGCA92ywN0igdkSQtpA93TgyquZSx+RpA:0EmkVg9CPngdWSQLGCA92ywN0igdkSQ1", "hash_imp": "F7DD8CA48DE6EB74A3F4726D3A67048A", "hash_pesha1": "58D8381DD0139E7E0E2CAC7CF9C6CCAD9AE8A9A7", "hash_pe256": "1E74F970D3535FBE75FA39A7DC862D59164E50AB3D16381F92709748BDDF8007", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Managment manifest generator", "meta_original_filename": "genmanifest.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Usage:\r\n genmanifest [-chain <source chain path>] <source MCF path> <destination XML path>\r\n\nExample: genmanifest manifestconfig.mcf c:\\manifest.xml\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\genmanifest.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "graphedt.exe-8585B82DA7C04F121D2CCEB6E6E81B40": { "file_name": "graphedt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\graphedt.exe", "hash_md5": "8585B82DA7C04F121D2CCEB6E6E81B40", "hash_sha1": "64CC71E93566AB13911E00C64654A12CEB8177DA", "hash_sha256": "998682A99AAC5D679A736055B50DCDE8DED92A0A9C4FAEE6BE276D710567D632", "hash_sha384": "D14C2FACC7305AD37F9BB11817195F1F4528EDD87278E9759F855E16CFCF31F0E06CE69275BA4E5790B00D929DADEE76", "hash_sha512": "C15546B0307796B80CF7C48B163AD7991362C029AA808D8E72182C30C5949A570B3B55F36C8EA4F1BD30972C9A7C7F570725E40967F6A1164BD5F5126089EBB6", "hash_ssdeep": "6144:uPHWIEJ8nXoLhIDA73BY/Oee5kX/ntHDFRextgDiTebp0kb:MWWKf5kXl5rDiTmb", "hash_imp": "2CEAB251FFFEA7911527BA2B3A62F088", "hash_pesha1": "4F5E898A5D18A0172B0ECB75C3F1FDF6B1672FA6", "hash_pe256": "08A0235019373F6750BD53D1EE56AD46FDE5BA1641D989BEB719279F61660476", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DirectShow SDK Filter Graph Editor", "meta_original_filename": "GraphEdt.exe", "meta_product_name": "DirectShow", "meta_comments": "DirectShow Graph Editor tool for software developers", "meta_company_name": "Microsoft Corporation", "meta_file_version": "DirectX 10.0", "meta_product_version": "DirectX 10.0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 1992-2006 Microsoft Corporation", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\1b9cHWNDInterface:8907e6": "Section", "(R-D) C:\\Windows\\System32\\en-US\\quartz.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\AMResourceMapping3-0000-0x000780": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\graphedt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ifilttst.exe-AB5820BC5A51830590259DE174F9C9E2": { "file_name": "ifilttst.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\ifilttst.exe", "hash_md5": "AB5820BC5A51830590259DE174F9C9E2", "hash_sha1": "0B9CDE65E9FF44E2F70AD97F2C504CC8F30F6879", "hash_sha256": "2225A37A21C190FED2A4BBCCBCE2D64A715B2A11F28A4AAD462A1E651FB1AC33", "hash_sha384": "833AD4ACCF7C6F77B38676D73F372033C9EF0B32D18D00322C301465272175246FE9DEE121851AE2134E0C9DC228A747", "hash_sha512": "A6975246449BEDE77C6CAEF7C7D6317432CE60251970538933280B1AC74648BA029578BB3E24E658E03B8B063581714991C9E0AB241286C2C02043998FCD251A", "hash_ssdeep": "1536:JSawyeGI+Jbaba9609r3Xv1vgZuPiih4Qce2IvUQm+5YBvylKOqB0gIqqWuxV3JV:BPX3n4+5I0gIvWSVZQhUSm", "hash_imp": "4A7FC3B8540EE2F0DF50E5D69D0EF689", "hash_pesha1": "CA9420B06DB898CD5A3283DB97E6121B8396000F", "hash_pe256": "10F6CB9517D8AF5D2AAD51E227FC3880A55735C85815B9CAE125EE79F9DF1578", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IFilter command line test tool", "meta_original_filename": "iFiltTst.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\r\nUSAGE:\r\r\nC:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\ifilttst.exe /i <input file>[...] [/ini <ini file>] [/l [<log file>]] [/d] [/-l] [/-d] [/legit] [/stress] [/v <verbosity>] [/t <threads>] [/r [<depth>]] [/c <loops>]\r\r\n\r\r\n\t<input file> is the file/directory/pattern to which to bind.\r\r\n\t\tWildcards are OK. More than one input file is OK.\r\r\n\t<ini file> is the initialization file to use. If none is\r\r\n\t\tspecified, it defaults to ifilttst.ini.\r\r\n\t[/l] enables logging to a file. By default, the log filename\r\r\n\t\tis the input file name with a .log extension. If you\r\r\n\t\tspecify a log file name, all the log messages will be sent\r\r\n\t\tto a single file.\r\r\n\t[/d] enables dumping to a file. The dump filename is the\r\r\n\t\tinput file name with a .dmp extension.\r\r\n\t[/-l] disables logging. This flag overrides /l.\r\r\n\t[/-d] disables dumping. This flag overrides /d.\r\r\n\t[/legit] forces the test to run only the Validation Test.\r\r\n\t\tThe Consistency and Invalid Input Tests are skipped.\r\r\n\t[/stress] forces the test to run in stress mode. This is the\r\r\n\t\t same as specifying /-l /-d /legit /v 0 /c 0\r\r\n\t<verbosity> is an integer representing the verbosity level\r\r\n\t\tAcceptable values are from 0 through 3, with 3 being the\r\r\n\t\tmost verbose. (default is 3)\r\r\n\t<threads> is an integer representing the number of threads\r\r\n\t\tto launch. Only useful if filtering multiple files.\r\r\n\t\t(default is 1)\r\r\n\t<depth> is an integer representing the depth to recurse.\r\r\n\t\tNo value or a value of 0 indicates full recursion. (default is 1)\r\r\n\t<loops> is an integer representing the number of times to\r\r\n\t\tloop. A value of 0 means loop infinetly. (default is 1)\r\r\nERROR: An input file must be specified\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\ifilttst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "inspect.exe-EB644BD85DC3E7120AE8459C75A70460": { "file_name": "inspect.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\inspect.exe", "hash_md5": "EB644BD85DC3E7120AE8459C75A70460", "hash_sha1": "D41FB03778D84A8BFC7CAB53D603357B906ED478", "hash_sha256": "FC527011F17B3DCBA93D914AB7322C1F3BC6FE3872C361082307A80984E660F5", "hash_sha384": "6FC345B5F69DEC632EE9AC06B58272348600D1E9E2B8DD9E20C981ED1CEF4DC291766A7D76047CB470E32B09F51C6EB1", "hash_sha512": "1992B65C5C935C1E7ECDE33C8BD30B52D293EE7277C633DC9BCF0539AD46D49DA7A9CE8248453FED80C96F396A4BFAB032F3A809EA47945D7A72308B79302B34", "hash_ssdeep": "6144:xqM63kMKYMKoqCHYVi94HrGS8zq1QJaRXwfuh:xqM63vm/4894LH1QKU", "hash_imp": "21F5E91FC9921974FA172D5259F5DC4D", "hash_pesha1": "9771BF9BDFFE68F9EE704C8EF7D41C1DAA880241", "hash_pe256": "F1E79A17116A531BBE3F64DFEC32F34F0EB0D04B520D8598B2E55BCD763E6865", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Inspect Object (32-bit UNICODE Release)", "meta_original_filename": "INSPECT.EXE", "meta_product_name": "Microsoft Active Accessibility", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.0.0", "meta_product_version": "7.2.0.0", "meta_language": "English (United States)", "meta_legal_copyright": " 2012 Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/fc527011f17b3dcba93d914ab7322c1f3bc6fe3872c361082307a80984e660f5/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\SysWOW64": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\UIAutomationCore.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\inspect.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Inspect (HWND: 0x00BA0858)" }, "isxps.exe-AF89FFAABC747CEF26946917F10E3A3C": { "file_name": "isxps.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\isxps.exe", "hash_md5": "AF89FFAABC747CEF26946917F10E3A3C", "hash_sha1": "BB8C726C147803BD8B88697ADD2B642B342A81BC", "hash_sha256": "1F9A84854DCF8C73D6BD3DB89F08451E0C09767CF602F837CBF8E97072E5CD25", "hash_sha384": "0EF09C18D4A075EB8E6DE9A6F8564610F3F2A82778FA7C886F7F9689EB79AF4E9BA0E9549ACD8731B71C1FA19A489279", "hash_sha512": "0BAF8E45705E8E9B2723242A53E4B3B7CD1EAEEAD6338245C7BDA565CFF27507B9F8E5B23B267994A439245309F4A1347130B12A4622933AD1641049F079AE9B", "hash_ssdeep": "3072:FYhy2j14ml3I2LC7bRbH2gVMnayzmXtMqRNf1UuDiMvTCfrqUoIg04YUf/oK0PJT:ay4ScaZbH2gGanxf1", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "C74F6773BD91994515889F2A9C91B69C7D7897DE", "hash_pe256": "9006F7EF17E145F466306593C01A4A16646D555E42DC17A2EC0F0AC31A97B152", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "IsXps.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Filename is required, but was not specified\r\nisXPS v2.0\r\nCopyright (c) 2009 Microsoft Corporation. All rights reserved.\n\r\nUsage---------------------------------------------\r\nisXPS.exe -t=<XPS | OXPS> -f=<FilePattern> [OptionalSwitches]\r\ne.g. isXPS.exe -t=XPS -f=SomeFile.xps -logger:File\r\ne.g. isXPS.exe -t=OXPS -f=*.oxps /s -logger:File\r\nMost Used Switches:\r\n -t=<XPS | OXPS>\n\t\t: Validate against XPS or OpenXPS. The default value is XPS.\r\n -f=<FilePath>\t: The file to perform the validation on.\r\n /s\t\t: Apply pattern to all subdirectories\r\n -logger:<LoggerType>\n\t\t: The logger to use (File, Console, WTT).\r\n \t\t the default logger is \"CONSOLE\".\r\n -logfile:<LogFile>\n\t\t: The log file to write to when using the File logger.\r\n \t\t the default log file is \"isXPSLog.txt\".\r\n /?\t\t: Display this help\r\nXsd Switches (optional for custom XSDs):\r\n -x:<S0Xsd>\t: The path to the S0 xsd\r\n -r:<RSCXsd>\t: The path to the Resource dictionary key xsd\r\n -doc:<DOCXsd>\t: The path to the Document Structure xsd\r\nAdvanced Switches:\r\n -logprefix:<Prefix>\n\t\t: specifies the prefix to append to log files from this run.\r\n \t\t Setting this will enable log file splitting output (for large runs)\r\n \t\t With log file splitting (File logger only), the setup will be output\r\n \t\t to the specified log file while the actual test results will be stored\r\n \t\t in the log file \"prefix_#to#.log files\"\r\n -logsplit:<Number>\n\t\t: How often should isXPS split the log file (Default: 0)\r\n \t\t Setting this will enable log file splitting output (for large runs)\r\n -BadDir=<Quarantine path>\t: Copy invalid packages to this directory.\r\n /DelBad\t: Delete invalid packages.\r\n /OnlyLogFailures\t: Log failures only to create small log files.\r\n /OnlyOPC\t: Only validate against the OPC specification. This will only work with ZIP-based OPC packages\r\n /SkipResParts\t: Don't validate resource parts content.\r\n /NoInterleave\t: Turn off interleaving validation.\r\n /NoPTConform\t: Turn off PTConform (Advanced PrintTicket validation).\r\n /DisallowForeignParts\t: Generate an error on non-XPS parts.\r\n -device:<DeviceString>\n\t\t: The device string to use with the WTT logger.\r\n \t\t: the default device is \"$LogFile:file=isXPSLog.wtl,WriteMode=append\".\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\isxps.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "jsconstraintdebug.exe-295E87A47895FD05365319B38264D231": { "file_name": "jsconstraintdebug.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\jsconstraintdebug.exe", "hash_md5": "295E87A47895FD05365319B38264D231", "hash_sha1": "7F42ED8DC654CFE99C86E9C61E9C9CA19FC8A050", "hash_sha256": "9141732724610F808418A26E704E8F2BA09BBEF1B22F48CD544E2A53EE71259F", "hash_sha384": "426FD78E6C4958E81C74A891987FAC6110B8DC9D442CBD421C83D7DD32A9AF639D5A996D7B00AC939A3FAD0B42694518", "hash_sha512": "D13E5DC2CCC839CAE9E39B263AAC2187FB4D28C7BBADEA63FBE04A7695AE7AE1680D1E63F68AFB66B144B57FBCD43F21D82FE2C268B95C913D652494D60B7018", "hash_ssdeep": "768:jAHFCO/Ve02kAr981SVD4T0CCH+9D7ee8YBNggzipOa22:Exk02km98YV0fl9D7p/Be7pO", "hash_imp": "5ECB0D77F67F8C06DEFED00F7F2E8EF8", "hash_pesha1": "C16EDFE47D7CEFE2A8275AAEDD910F4C81B7842B", "hash_pe256": "192A9F70517B407BBC8FA682C0B5778E8AD0E953008A785797CD9334AB2D5A6C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "JS Print Constraint Debug Tool", "meta_original_filename": "JSPrintConstraintDebug.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\n\r\n Usage: JSPrintContstraintDebug.exe <PrinterName> <PrintTicket1.xml>[<PrintTicket2.xml>][<JsFile.js>]\r\n\r\n PrinterName : Printer name which contains driver JS files to be debugged.\r\n\r\n PrintTicket1.xml : Path to Print Ticket XML file which will be passed to\r\n JavaScript Print Ticket APIs.\r\n\r\n PrintTicket2.xml : Path to optional second Print Ticket XML file which will\r\n be passed to Merge and Validate API.\r\n\r\n If PrintTicket2.xml is not set the default DevMode will\r\n be converted to a Print Ticket and will be passed to\r\n the Merge and Validate API.\r\n\r\n JsFile.js : Path to optional replacement JavaScript constraints\r\n source file\r\n\r\n If the optional JsFile.js parameter is set, the passed\r\n file replaces the JS file in the target print driver\r\n before debugging.\r\n\r\n NOTE : This tool assumes that user has installed the printer previously, and the\r\n machine has Visual Studio debugger installed.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\jsconstraintdebug.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "makeappx.exe-8C87116F9274AD213FE846A6D9E90BA9": { "file_name": "makeappx.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\makeappx.exe", "hash_md5": "8C87116F9274AD213FE846A6D9E90BA9", "hash_sha1": "373FDA1C4178E4646DCE80793E7536CE02C984C4", "hash_sha256": "51D95B9D90A2E606C5D798F18F8FBA3BEBEDE07160F7F790D91166227F5DDB1E", "hash_sha384": "3907961333EFF62A050BF9B35952DD7160246DACE653FE3E5F8CA6617B2964715A4B83E970797768387E76AF3DD97083", "hash_sha512": "F5CDE9A2240AC6BB6AA771CEF00CF4BEC972752E437EE00FC2A2863FD028BA53BBD40158CC7E5642E94BBC012B3394A588B070CF82E1B1832C4C271ADAC2438A", "hash_ssdeep": "6144:8COdbfGMp/5NbAzaAfR7CF3eeJ6cmomnH3FR6rwn+7rwC/Bssr+eFXFutsLsBF6w:wdbH5N+azJ6PomnH3FRE1FuBEeL9p", "hash_imp": "148BF7DE0341D5BEA83060A7529D6815", "hash_pesha1": "FE6CC6CC26F5D41939F1271A4553061C8CB6E5C4", "hash_pe256": "4CD06AA6BE0248B26CF5D822E2B06900341DA43A5ABC35A759B45CCCE44ACF0A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command line tool for creating Appx packages", "meta_original_filename": "MakeAppx.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/51d95b9d90a2e606c5d798f18f8fba3bebede07160f7f790d91166227f5ddb1e/detection", "output": "Microsoft (R) MakeAppx Tool\r\r\nCopyright (C) 2013 Microsoft. All rights reserved.\r\r\n\r\r\nUsage:\r\r\n------\r\r\n MakeAppx <command> [options]\r\r\n\r\r\nValid commands:\r\r\n---------------\r\r\n pack -- Create a new app package from files on disk\r\r\n unpack -- Extract an existing app package to files on disk\r\r\n bundle -- Create a new app bundle from files on disk\r\r\n unbundle -- Extract an existing app bundle to files on disk\r\r\n encrypt -- Encrypt an existing app package or bundle\r\r\n decrypt -- Decrypt an existing app package or bundle\r\r\n convertCGM -- Convert a source content group map (CGM) to the final content group map\r\r\n build -- Build packages using a packaging layout file\r\r\n\r\r\nFor help with a specific command, enter \"MakeAppx <command> /?\"\r\r\n\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\makeappx.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "makecat.exe-2F6F5D2DA0655171CE8AABA33DDA5905": { "file_name": "makecat.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\makecat.exe", "hash_md5": "2F6F5D2DA0655171CE8AABA33DDA5905", "hash_sha1": "BD0FBB03D9C7767C850BF58AEFC96766DF343521", "hash_sha256": "3BAD3D4DE456A36A03F283D66B1A3B4CF292127DD8214315D73833D8F6B0DF9E", "hash_sha384": "86CE193AA0CE84BBBC419A8C13978B85A5BB11026EE98A50FA2C5F9CC3677282709010127CE78C314DBBB0A8C9944958", "hash_sha512": "64952A833043230123051FCB7673B35AA2CA89958F85C94F4CC81AF13B06C7E902F439C0D514C7DF726EE470F5BE8001793E68C88E82C62E66D86CFEC55D7785", "hash_ssdeep": "384:6C0pcjU0i8IErkxdoykhvD5sLoCfcadvo0WD1ZW3+fzuWdwGyz5fk9flx64:RiHIofHkhvDGfX0W+9dVb", "hash_imp": "4980A8BA4C4142E955444BAD65CFC7FF", "hash_pesha1": "2CBA2F854416C06B9649AA83BEE9FD38FB29037A", "hash_pe256": "E3A1374EBF18FBA25377D86A9F70ABBB29E163D956F8336630E7936AA4CBB277", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Trust Make Catalog utility", "meta_original_filename": "MAKECAT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3bad3d4de456a36a03f283d66b1a3b4cf292127dd8214315d73833d8f6b0df9e/detection", "output": "usage: makecat.exe [options] [@commandfile] CDF_filename\r\r\n -?: this screen\r\r\n -v: verbose output\r\r\n -r: return fail even on recoverable errors\r\r\n -n: don't stop on error\r\r\n -s <param>: fail if any files are smaller than (param) bytes\r\r\n -o <param>: output filename/hash pairs to specified file\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\makecat.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "makecert.exe-EDF551E8A4C3CFD532EF07D82D1AE585": { "file_name": "makecert.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\makecert.exe", "hash_md5": "EDF551E8A4C3CFD532EF07D82D1AE585", "hash_sha1": "80BD88B98EAF8A812202F2DDB4CBFF2ACA49AF38", "hash_sha256": "808E43AC6BF1A5C21C6DD3CBDCF32B8C9CAAE2C078D57080CD11BF564ED16242", "hash_sha384": "FECEDD480548E06AB8816675CED121FF1FFA84D432B056D9ED87902C987534F5CDFDAA0FD050BE2DCDDE36FB35F905D3", "hash_sha512": "EB8D252B0ACAE2B932F242E813884D16B2572C4F6A1DAACE49963CAC24AC67BB14704C90FA05E7CF47BD4037F6E080CEC728A16028CB5308B2A31773F40FF97D", "hash_ssdeep": "768:ZQIAghcfXUQaWHze4FIvh1DxkKpQYGLTJayaarFdTeORUXMdZQ:ZQkhUzTRehZx78LTJayaarFdCOlQ", "hash_imp": "2D1E4981855D954BA7C83771BDED9BC2", "hash_pesha1": "039C0E93F760D5B7691C725B31B2980CCF9EACD0", "hash_pe256": "4453AC55F7B33F653A84D37EB03CEB5AC6775FD55BDDE44AE187FFB4DC2F93DA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ECM MakeCert", "meta_original_filename": "MAKECERT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/808e43ac6bf1a5c21c6dd3cbdcf32b8c9caae2c078d57080cd11bf564ed16242/detection", "output": "Usage: MakeCert [ basic|extended options] [outputCertificateFile]\r\nBasic Options\r\n -sk <keyName> Subject's key container name; To be created if not present\r\n -pe Mark generated private key as exportable\r\n -ss <store> Subject's certificate store name that stores the output \r\n certificate\r\n -sr <location> Subject's certificate store location.\r\n <CurrentUser|LocalMachine>. Default to 'CurrentUser'\r\n -# <number> Serial Number from 1 to 2^31-1. Default to be unique\r\n -$ <authority> The signing authority of the certificate\r\n <individual|commercial>\r\n -n <X509name> Certificate subject X500 name (eg: CN=Fred Dews)\r\n -? Return a list of basic options\r\n -! Return a list of extended options\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\makecert.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "makepri.exe-7FFCBDE91373EF0786611CA95F0E3B2B": { "file_name": "makepri.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\makepri.exe", "hash_md5": "7FFCBDE91373EF0786611CA95F0E3B2B", "hash_sha1": "C541C3D6DD0C9539D53C19E08775DDFFAC4E2A7E", "hash_sha256": "D497C9ED1AC550CDA0CE18A5C94AD0F70A306B5E579019554EB2B2979495E316", "hash_sha384": "34FFD65E5681DBC68FB3FDB8AC791A850D446E1EE2D811CCFFF4DC0E72ABDA66DB574EE7C46FDDAA98FF4B0A07472D1F", "hash_sha512": "186ED93734D006A0DC01C876312D18847037964F555CFBE243F578CA01371EF2D9A2192B307C879D8D4623C1A74D1309A547AECCBDCC30F24966CA94E76570CD", "hash_ssdeep": "12288:JikF735N03e6BbWb+BFlLNqo1vk5YTdFrkugItWlOmE5yujmuC5yh4ZTyj:8kFLU9RNTLr9gItWlSC0KZTyj", "hash_imp": "E2CC7C2E396C44A413B2BAACEE086045", "hash_pesha1": "A80157C6998EDCB16644D29339EEC8E68BAB82F3", "hash_pe256": "5ACA3AF986ECE5C0376987F8E9D21C3D8C246A56021131651483B53030ABEDBC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command line tool for creating PRI files", "meta_original_filename": "Makepri.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d497c9ed1ac550cda0ce18a5c94ad0f70a306b5e579019554eb2b2979495e316/detection", "output": "Microsoft (R) MakePRI Tool\r\nCopyright (C) 2013 Microsoft. All rights reserved.\r\n\r\n\r\nUsage:\r\r\n------\r\n MakePri.exe <Command> [options]\r\n\r\nExample:\r\r\n--------\r\n MakePri.exe new /pr C:\\MyApp\\src\\ /cf C:\\MyApp\\priconfig.xml /in PackageName\r\n\r\nDescription:\r\r\n------------\r\n MakePri.exe creates, dumps and does utility functions on a PRI file.\r\n A PRI file is an index of application resources (i.e. strings, files, etc).\r\n\r\nCommand Options:\r\r\n----------------\r\n MakePri.exe createconfig Creates a PRI Config file for use with other\r\n commands\r\n MakePri.exe new Creates a new PRI file from scratch\r\n MakePri.exe versioned Creates a PRI file based off a previous version\r\n MakePri.exe resourcepack Creates a PRI file that contains additional\r\n resource variants for a base PRI\r\n MakePri.exe dump Dumps the contents of a PRI file\r\n MakePri.exe help Show this help page\r\n\r\nHelp:\r\n Specify a command with help for more detailed help\r\n MakePri.exe new /?\r\n\r\n", "error": "ERROR: PRI104: 0x80070057 - Unknown option specified - '-help'\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\makepri.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mbidgenerator.exe-9727C0520B503CC034E079ED338FE3DC": { "file_name": "mbidgenerator.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\mbidgenerator.exe", "hash_md5": "9727C0520B503CC034E079ED338FE3DC", "hash_sha1": "A78CD0B815C24338D90033F067F2C395D6C27F6E", "hash_sha256": "2A28657C9A3A8B2BE40FCC13A3BA6E016763890D9A27449E8529FE9C9880D7CF", "hash_sha384": "853B2491C022C2AF46CB2B8E289B10453CF01E377FC5B860193E1063FDC9A32956ABCCA89BBBCE26F9F163EC5ADEAD77", "hash_sha512": "EA095F2EC76018A97DAC13831F1CC5A74E44ACE72835E0547EE53B648CF5D853CA862D80885EFF144E912C3C317FA15AA65313A3F9209EE9643A1CEC56DD1757", "hash_ssdeep": "384:L+0M+FW1VT7TqF/sk+Unppy/ye7eKyRlUEliyCM8r2aVAXlW1WWgwGy9rzIwS+k3:UvaTrpp4EKOUElGMmIMHdO", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "871D375106ED97651E2DD7098BBD8B07176CC697", "hash_pe256": "A294354475D14B15F6DF6EF6CAC34F66CEC8C01B42402F5A3150EB2457E1D002", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "MBIDGenerator.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Unknown command option: --help\r\n\r\nUsage: MBIDGenerator [/test] input_file [output_file]\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\mbidgenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mc.exe-DD82CFCFDCA336971FB5EB6ECF6FFAA6": { "file_name": "mc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\mc.exe", "hash_md5": "DD82CFCFDCA336971FB5EB6ECF6FFAA6", "hash_sha1": "37E9D0CE60FF94243C7A62A57FF1FBD059CED735", "hash_sha256": "8F6403F5C28E71D9DB6B0A20EC73048D8642E71C4D13FDF39CDE10C5A6BEA863", "hash_sha384": "F683603A8C83F748C4413B9ADA12D5D6C2D023C5A447C249192197C1644D93915EF1C4E1A049A907FB348D6019C2F084", "hash_sha512": "5604D1983C15D1039D17AAFE968F9038DBD306D4987908765873B4936E0CF225FAB4E3F40FDE7059F216908A98E0266302ABA014678D30F24C0439A893F90BE6", "hash_ssdeep": "6144:kWJTsALlsv3YXvfWKc7Iyq8B9xS2IVy9RL3LWPt2wetWmtt6egDM:5TsAPoIyq8B9xS2ay9RLbGvetQegY", "hash_imp": "92F3573E061FE0EC3B22C9D8DC0080E1", "hash_pesha1": "39E75EB29655DF13B9829657BB092C4E56294B02", "hash_pe256": "3F9DEB7830E0FE3DA0EF6D4BBF9EF5BA4C64293AE8A85622C0FC94C496F68E71", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Message Compiler", "meta_original_filename": "mc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8f6403f5c28e71d9db6b0a20ec73048d8642e71c4d13fdf39cde10c5a6bea863/detection", "error": "mc : error : Invalid switch: -.\r\nmc : error : Missing argument for -h switch.\r\nmc : error : Missing argument for -e switch.\r\nmc : error : Invalid switch: l.\r\nmc : error : Missing argument for -p switch.\r\nMicrosoft (R) Message Compiler Version 10.0.19041\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUsage:\r\n\r\nMC [-?aAbcdnouUv] [-m <length>] [-h <path>] [-e <extension>] [-r <path>]\r\n [-x <path>] [-w <file>] [-W <file>] [-z <basename> ] [-cp <encoding>]\r\n [-km | -um | -generateProjections | -cs <namespace>]\r\n [-mof] [-p <prefix>] [-P <prefix>]\r\n [<filename.man>] [<filename.mc>]\r\n\r\n -? - Displays this message.\r\n -a - Indicates that the input .mc file is CP_ACP (default).\r\n Ignored if the .mc file has a UTF-8 or UTF-16LE BOM.\r\n -A - DEPRECATED. Encode .BIN messages using CP_ACP (ANSI).\r\n -b - .BIN filename should have .mc filename included for\r\n uniqueness.\r\n -c - Sets the Customer bit in all of the message IDs.\r\n -d - FACILITY and SEVERITY values should be printed as decimal\r\n in header file (default is hexadecimal).\r\n -e <extension> - The extension for the C include file (1-3 chars).\r\n -h <path> - The path for the C include file. Default is: \".\\\"\r\n -m <length> - Warn if any message exceeds <length> characters.\r\n -n - NUL-terminate all message table strings.\r\n -o - Generate OLE2 header file (use HRESULT definition instead\r\n of status code definition).\r\n -r <path> - The directory for the RC include file and the binary\r\n message resource files it includes. Default is: \".\\\"\r\n -s <path> - Generate a separate binary resource per provider.\r\n Generate summary global resource MCGenResource.BIN.\r\n -t <path> - Validate against baseline resource.\r\n -u - Indicates that the input .mc file is UTF-16LE. This flag\r\n is required when the .mc file is UTF-16LE without a BOM.\r\n Ignored if the .mc file has a UTF-8 or UTF-16LE BOM.\r\n -U - Encode .BIN messages using UTF-16LE (default).\r\n -U8 - Encode .BIN messages using UTF8. Resulting message table\r\n will only be usable on Windows 20h1 or later.\r\n -v - Enables verbose output.\r\n -W <file> - The path to a custom winmeta.xml file (rarely needed).\r\n -w <file> - The path to a custom eventman.xsd file (rarely needed).\r\n -x <path> - The path for the .dbg C include file that maps message\r\n IDs to their symbolic names. This option can only be used\r\n with a message text file.\r\n -z <basename> - The base name of the generated files. Default is the base\r\n name of the input file.\r\n <filename.man> - The name of the manifest file to compile.\r\n <filename.mc> - The name of a message file to compile.\r\n\r\n Code Generation Options\r\n ----------------------- \r\n -cp <encoding> - Generated text files will use the specified\r\n character encoding. Valid encoding names include\r\n \"ansi\" (default), \"utf-8\", and \"utf-16\".\r\n The UTF encodings will add a byte order mark (BOM).\r\n -km - Generate Kernel Mode logging macros.\r\n -um - Generate User Mode logging macros.\r\n Note: unless the -mof parameter is specified, the\r\n only difference between -km and -um is that the\r\n EventWrite macros generated with -km accept an\r\n Activity ID parameter.\r\n -generateProjections - Generate logging interfaces projectable to\r\n JavaScript.\r\n -generateTemplateProjections\r\n - Generate logging interfaces projectable to\r\n JavaScript that reduce projection cost.\r\n -generateTemplateStubs <file>\r\n - Override the default template wrapping stubs file\r\n from WinRTTemplateProviderStubs.js to <file>.js.\r\n -cs <namespace> - Generate C# (managed) logging class based on the\r\n .NET 3.5 Eventing class.\r\n -css <namespace> - Generate static C# (managed) logging class based on\r\n the .NET 3.5 Eventing class.\r\n\r\n -co - Generate EventWrite macros that invoke an\r\n MCGEN_CALLOUT macro. Not supported (ignored) for C#.\r\n -mof - DEPRECATED. Generate downlevel (XP-compatible)\r\n functions and macros for ETW. Generate a MOF file\r\n describing the ETW events. The MOF file will be\r\n generated in the location specified by the \"-h\"\r\n switch.\r\n -p <prefix> - Defines the macro name prefix applied to each\r\n generated logging macro. Default is: \"EventWrite\"\r\n -P <prefix> - Specifies text at the start of each event symbol name\r\n to remove before forming the macro names.\r\n\r\nNotes:\r\n\r\n- The 'A' and 'mof' switches are deprecated and will be removed in the future.\r\n- At most one .mc and one .man file can be processed per invocation of mc.exe.\r\n- Generated files have the Archive bit cleared.\r\n- The mofcomp and rc tools do not currently support UTF-8 input. If a UTF-8\r\n encoding is requested, the MOF and RC files will be generated as UTF-16LE.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\mc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mdmerge.exe-A0C13D0141B208183451035B00137D05": { "file_name": "mdmerge.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\mdmerge.exe", "hash_md5": "A0C13D0141B208183451035B00137D05", "hash_sha1": "1638FD613CBE9050272F1B773E3AD5626F460255", "hash_sha256": "62506E8997DCD544DAB6EC7F792DAB643B1B25EEFF74A21A8C56AFBBA3A76CCD", "hash_sha384": "50D90F3E83469F7805D25B28907B2519AE99B54617D0CC04D2AB520F1805F01ABE71C755D8318AA5818C75155A8F7E00", "hash_sha512": "DC5A3A1517AEA67AD6355997249FA993CC6E6F24021507F5E473EE3F042ECEAA08DAFCFD108F03ACD654C88E0302872319028AAFB38F21321AEEC98764637CF7", "hash_ssdeep": "6144:ak/UoSAOf3bHRGyW3hVv0WbQpCh0V5ZsVxnnYvk8tswxzX2g+uhY3GG/5TN3BJ4y:qoSZgVTfU5+Vavk8tswxzX2fJtl4y", "hash_imp": "D35F09FFA2C37327CAF4D3C5A751464C", "hash_pesha1": "88D6C50FA17BEA1D3C0104934E6FF9351F2B32E5", "hash_pe256": "893B41C44B742BD84EAEE834A104DED5CE9BEAF1E3DC0A3337B4E53F87FBC670", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft MDMERGE Utility", "meta_original_filename": "mdmerge.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Microsoft(R) Metadata Merge Utility Version 10.0.49.\r\r\n\r\nUsage: C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\mdmerge.exe [-/][Switch][:][Value]\r\n\r\nWhere Switch is one of the following: \r\n -?: Print this help\r\n -h: Print this help\r\n -v: Validate - Validate metadata type references\r\n -i: Input directory - compose metadata files in this directory\r\n -metadata_dir: Metadata Directory - Directory which contains the master copy of Windows Metadata files\r\n -partial: Partial - resolve unresolved types against metadata files specified in the -metadata_dir switch\r\n -platform_filter: Platform filter - specifies a platform filter XML file\r\n -additional_platform_path: Additional platform path - specifies additional path to look for <platform>.xml file. Optional.\r\n -o: Output directory - put composed metadata files in this directory\r\n -n: Composition Depth - compose to this level of input\r\n -contracts: Sort metadata into contracts\r\n -platform: Target Platform - compose metadata for this platform\r\n -mdv: Metadata format version\r\n -contractMap: Specifies the filename to place the API contract maps\r\n -removeInternal: Removes types that are marked internal\r\n -resFile: A compiled resource file to embed in metadata files\r\n -keepOnlyInternal: Removes types that are not marked internal\r\n -createPublicMetadata: Creates metadata for public release\r\n -transformExperimental: Transform the experimental attribute\r\n -keepOnlyPrivate: Removes types that are not marked private\r\n -verbose: Prints verbose information to the console\r\n", "error": "MDMERGE : error MDM5003: Unrecognized command line switch: --help.\r\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\mdmerge.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mftrace.exe-C4E8F0C917D4AD90670DB8684FF0AC41": { "file_name": "mftrace.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\mftrace.exe", "hash_md5": "C4E8F0C917D4AD90670DB8684FF0AC41", "hash_sha1": "5A7D5CC81B2662C69D80D580E9F13C49D6595F5F", "hash_sha256": "C8450299DBA10DAF152B3568517C6DF5935DEF941FAB4067AE39E829152FF3B1", "hash_sha384": "C12F361DD20DD6CB90C32A3F5C5CFA59C63BB3C58FADFA98E0B758690962EB8963C740FEEAC84E304A4AB913A6FA2CA1", "hash_sha512": "0E543E79BC3A89F2C972DEAA717782A2EE26B4D2ADD10F81019F173B1D714E1411BB4336357156DC311205564A3D47BBC77724AA5156155D3B021B896AC16F62", "hash_ssdeep": "6144:KsWcdSeCwA4JufPCkXZ/6EVAMgzjcW48ibHMT5pZJ5pZxEOx:ZWeSezAnXCkXZ/6EWI0T5pZJ5pZxd", "hash_imp": "5CAF5F64A6BFCA4E3879DCC7700176A3", "hash_pesha1": "A7F37F3D75D8622E1CF02A9BD8D0086036F99464", "hash_pe256": "088846088C70ACF2B5D9130A0AD817811AC02DEA22BA52B226F2EB4875FD8BFC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Media Foundation Tracing Application", "meta_original_filename": "mftrace.exe", "meta_product_name": "Media Foundation Tracing Application", "meta_company_name": "Microsoft", "meta_file_version": "1.1.0.1", "meta_product_version": "1.1.0.1", "meta_language": "Language Neutral", "meta_legal_copyright": "(c) Microsoft. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Failed with hr=0x80070057 (ERROR_INVALID_PARAMETER)\r\nUse the '-v' option to get further details\r\n", "output": "For more information on a specific command, type HELP command-name\r\nASSOC Displays or modifies file extension associations.\r\nATTRIB Displays or changes file attributes.\r\nBREAK Sets or clears extended CTRL+C checking.\r\nBCDEDIT Sets properties in boot database to control boot loading.\r\nCACLS Displays or modifies access control lists (ACLs) of files.\r\nCALL Calls one batch program from another.\r\nCD Displays the name of or changes the current directory.\r\nCHCP Displays or sets the active code page number.\r\nCHDIR Displays the name of or changes the current directory.\r\nCHKDSK Checks a disk and displays a status report.\r\nCHKNTFS Displays or modifies the checking of disk at boot time.\r\nCLS Clears the screen.\r\nCMD Starts a new instance of the Windows command interpreter.\r\nCOLOR Sets the default console foreground and background colors.\r\nCOMP Compares the contents of two files or sets of files.\r\nCOMPACT Displays or alters the compression of files on NTFS partitions.\r\nCONVERT Converts FAT volumes to NTFS. You cannot convert the\r\n current drive.\r\nCOPY Copies one or more files to another location.\r\nDATE Displays or sets the date.\r\nDEL Deletes one or more files.\r\nDIR Displays a list of files and subdirectories in a directory.\r\nDISKPART Displays or configures Disk Partition properties.\r\nDOSKEY Edits command lines, recalls Windows commands, and \r\n creates macros.\r\nDRIVERQUERY Displays current device driver status and properties.\r\nECHO Displays messages, or turns command echoing on or off.\r\nENDLOCAL Ends localization of environment changes in a batch file.\r\nERASE Deletes one or more files.\r\nEXIT Quits the CMD.EXE program (command interpreter).\r\nFC Compares two files or sets of files, and displays the \r\n differences between them.\r\nFIND Searches for a text string in a file or files.\r\nFINDSTR Searches for strings in files.\r\nFOR Runs a specified command for each file in a set of files.\r\nFORMAT Formats a disk for use with Windows.\r\nFSUTIL Displays or configures the file system properties.\r\nFTYPE Displays or modifies file types used in file extension \r\n associations.\r\nGOTO Directs the Windows command interpreter to a labeled line in \r\n a batch program.\r\nGPRESULT Displays Group Policy information for machine or user.\r\nGRAFTABL Enables Windows to display an extended character set in \r\n graphics mode.\r\nHELP Provides Help information for Windows commands.\r\nICACLS Display, modify, backup, or restore ACLs for files and \r\n directories.\r\nIF Performs conditional processing in batch programs.\r\nLABEL Creates, changes, or deletes the volume label of a disk.\r\nMD Creates a directory.\r\nMKDIR Creates a directory.\r\nMKLINK Creates Symbolic Links and Hard Links\r\nMODE Configures a system device.\r\nMORE Displays output one screen at a time.\r\nMOVE Moves one or more files from one directory to another \r\n directory.\r\nOPENFILES Displays files opened by remote users for a file share.\r\nPATH Displays or sets a search path for executable files.\r\nPAUSE Suspends processing of a batch file and displays a message.\r\nPOPD Restores the previous value of the current directory saved by \r\n PUSHD.\r\nPRINT Prints a text file.\r\nPROMPT Changes the Windows command prompt.\r\nPUSHD Saves the current directory then changes it.\r\nRD Removes a directory.\r\nRECOVER Recovers readable information from a bad or defective disk.\r\nREM Records comments (remarks) in batch files or CONFIG.SYS.\r\nREN Renames a file or files.\r\nRENAME Renames a file or files.\r\nREPLACE Replaces files.\r\nRMDIR Removes a directory.\r\nROBOCOPY Advanced utility to copy files and directory trees\r\nSET Displays, sets, or removes Windows environment variables.\r\nSETLOCAL Begins localization of environment changes in a batch file.\r\nSC Displays or configures services (background processes).\r\nSCHTASKS Schedules commands and programs to run on a computer.\r\nSHIFT Shifts the position of replaceable parameters in batch files.\r\nSHUTDOWN Allows proper local or remote shutdown of machine.\r\nSORT Sorts input.\r\nSTART Starts a separate window to run a specified program or command.\r\nSUBST Associates a path with a drive letter.\r\nSYSTEMINFO Displays machine specific properties and configuration.\r\nTASKLIST Displays all currently running tasks including services.\r\nTASKKILL Kill or stop a running process or application.\r\nTIME Displays or sets the system time.\r\nTITLE Sets the window title for a CMD.EXE session.\r\nTREE Graphically displays the directory structure of a drive or \r\n path.\r\nTYPE Displays the contents of a text file.\r\nVER Displays the Windows version.\r\nVERIFY Tells Windows whether to verify that your files are written\r\n correctly to a disk.\r\nVOL Displays a disk volume label and serial number.\r\nXCOPY Copies files and directory trees.\r\nWMIC Displays WMI information inside interactive command shell.\r\n\r\nFor more information on tools see the command-line reference in the online help.\r\nListening to ETW events (CTRL+C to end)\r\n __M_F_T_R_A_C_E___LOG__\r\n\r\nPID, TID Time (UTC) TraceMessage\r\n--------- -------------- ------------\r\n4036,1084 21:44:50.50525 TraceOSVersion @ OS version (BuildLabEx): 19041.1.x86fre.vb_release.191206-1406\r\n4036,1084 21:44:50.50525 TraceMFDetoursVersion @ MFDetours version 1.1.0.1\r\n4036,1084 21:44:50.50547 TraceEnabledKeywords @ Keywords and levels: Default 4, Detours 4, MFDebugHlp 4, Kernel32Export 4, MFExport 4, MFPlatExport 4, MFPlayExport 4, MFReadWriteExport 4, Ole32Export 4, wmvCoreExport 4, MFPublic 4, IMFActivate 4, IMFAsyncCallback 4, IMFAttributes 4, IMFClock 4, IMFClockStateSink 4, IMFMediaEventGenerator 4, IMFMediaSession 4, IMFMediaSink 4, IMFMediaSource 4, IMFMediaStream 4, IMFPMediaPlayer 4, IMFPMediaItem 4\r\n4036,1084 21:44:50.50553 TraceEnabledKeywords @ Keywords and levels: IMFPMediaPlayerCallback 4, IMFPresentationClock 4, IMFQualityAdvise 4, IMFQualityAdvise2 4, IMFQualityManager 4, IMFRateControl 4, IMFSample 4, IMFSinkWriter 4, IMFSourceReader 4, IMFSourceReaderCallback 4, IMFSourceResolver 4, IMFStreamSink 4, IMFTopology 4, IMFTopologyNode 4, IMFTopoLoader 4, IMFTransform 4, IMediaObject 4, IMFSchemeHandler 4, IMFByteStream 4, IMFByteStreamHandler 4\r\n4036,1084 21:44:50.50554 TraceEnabledKeywords @ Keywords and levels: IMFReadWriteClassFactory 4, IFilterGraph 4, IGraphBuilder 4, IMediaControl 4, IMemInputPin 4, IWMReader 4, IWMReaderCallback 4\r\n4036,1084 21:44:50.50645 CMFMediaSessionDetours::Attach @02A64350 Presentation clock @02A69ED0\r\n4036,1084 21:44:50.50646 CMFMediaSessionDetours::Attach @02A64350 Rate control @02A64358\r\n __M_F_T_R_A_C_E___LOG__\r\nTotal events received: 7 \r\n", "children": "conhost.exe", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\mftrace.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "midl.exe-705993E9F015AC9C51DC5821A51041F3": { "file_name": "midl.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\midl.exe", "hash_md5": "705993E9F015AC9C51DC5821A51041F3", "hash_sha1": "29067B5318881279F7F2701FA286284EBA6C56DB", "hash_sha256": "601D72F3791343038C51EC45587984D85C811DE9929A2AB3D05483AD54AEB443", "hash_sha384": "7197D042A6A22A4373F00F74BBC6DAAAB6A50CDF8C41063D9C2994954303C7C4915DB937E72329918F88CD93E7A08CA2", "hash_sha512": "D73D8936B1009558B2A33056A2E34A552DF131CE66CDCDA99A2398A1FB06FF0ABF0D8D3773B4EF8C5FEE2158B8A962614054032FD3BB5249CDF8C56EB178DBF5", "hash_ssdeep": "3072:2daK7g+hLiiOnpA5GZpckobSAsoDUgj57zVK4zaVH7iQ1OCMR+a28:2F8ah3dj5w4maQaB", "hash_imp": "F7758C78C7848B809E98FAB3C95D1C39", "hash_pesha1": "0A146E8E67388B8CEEEFC56575826048F347CBF1", "hash_pe256": "16B2B26EC28B89B9156962B1D342F28689228BD9F94C12443E20A6F37D3D23E8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IDL Compiler Driver", "meta_original_filename": "midl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/601d72f3791343038c51ec45587984d85c811de9929a2ab3d05483ad54aeb443/detection", "output": " -MIDL COMPILER OPTIONS-\r\n -MODE-\r\n/ms_ext Microsoft extensions to the IDL language (default)\r\n/c_ext Allow Microsoft C extensions in the IDL file (default)\r\n/osf OSF mode - disables /ms_ext and /c_ext options\r\n/app_config Allow selected ACF attributes in the IDL file\r\n/mktyplib203 MKTYPLIB Version 2.03 compatiblity mode\r\n\r\n -INPUT-\r\n/acf filename Specify the attribute configuration file\r\n/I directory-list Specify one or more directories for include path\r\n/no_def_idir Ignore the current and the INCLUDE directories\r\n\r\n -OUTPUT FILE GENERATION-\r\n/client none Do not generate client files\r\n/client stub Generate client stub file only\r\n/out directory Specify destination directory for output files\r\n/server none Generate no server files\r\n/server stub Generate server stub file only\r\n/syntax_check Check syntax only; do not generate output files\r\n/Zs Check syntax only; do not generate output files\r\n/oldtlb Generate old format type libraries\r\n/newtlb Generate new format type libraries (default)\r\n/notlb Don't generate the tlb file\r\n/define_guids Define COM guids in the stub header as well as in dlldata\r\n\r\n -OUTPUT FILE NAMES-\r\n/cstub filename Specify client stub file name\r\n/dlldata filename Specify dlldata file name\r\n/h filename Specify header file name\r\n/header filename Specify header file name\r\n/iid filename Specify interface UUID file name\r\n/proxy filename Specify proxy file name\r\n/sstub filename Specify server stub file name\r\n/tlb filename Specify type library file name\r\n\r\n -C COMPILER AND PREPROCESSOR OPTIONS-\r\n/cpp_cmd cmd_line Specify name of C preprocessor (default: cl.exe)\r\n/cpp_opt options Specify additional C preprocessor options\r\n/D name[=def] Pass #define name, optional value to C preprocessor\r\n/no_cpp Turn off the C preprocessing option\r\n/nocpp Turn off the C preprocessing option\r\n/U name Remove any previous definition (undefine)\r\n/msc_ver <nnnn> Microsoft C/C++ compiler version\r\n/savePP Save the preprocessed temporary file(s)\r\n\r\n -ENVIRONMENT-\r\n/char signed C compiler default char type is signed\r\n/char unsigned C compiler default char type is unsigned\r\n/char ascii7 Char values limited to 0-127\r\n/env win32 Target environment is Microsoft Windows 32-bit (NT)\r\n/env ia64 Target environment is Microsoft Windows 64-bit (NT) for IA64\r\n/env x64 Target environment is Microsoft Windows for 64-Bit \r\n Extended Systems\r\n/env arm32 Target environment is Microsoft Windows for 32-bit ARM\r\n Systems\r\n/env arm64 Target environment is Microsoft Windows for 64-bit ARM\r\n Systems\r\n/lcid Locale id for international locales\r\n/ms_union Use Midl 1.0 non-DCE wire layout for non-encapsulated unions\r\n/oldnames Do not mangle version number into names\r\n/rpcss Automatically activate rpc_sm_enable_allocate\r\n/use_epv Generate server side application calls via entry-pt vector\r\n/no_default_epv Do not generate a default entry-point vector\r\n/prefix client str Add \"str\" prefix to client-side entry points\r\n/prefix server str Add \"str\" prefix to server-side manager routines\r\n/prefix switch str Add \"str\" prefix to switch routine prototypes\r\n/prefix all str Add \"str\" prefix to all routines\r\n/win32 Target environment is Microsoft Windows 32-bit (NT)\r\n/ia64 Target environment is Microsoft Windows 64-bit (NT) for IA64\r\n/x64 Target environment is Microsoft Windows for 64-Bit \r\n Extended Systems\r\n/arm32 Target environment is Microsoft Windows for 32-bit ARM\r\n Systems\r\n/arm64 Target environment is Microsoft Windows for 64-bit ARM\r\n Systems\r\n/protocol dce Use DCE NDR transfer syntax (default for 32-bit)\r\n/protocol all Use all supported transfer syntaxes\r\n/protocol ndr64 Use Microsoft extension NDR64 transfer syntax\r\n/target {system} Set the minimum target system\r\n\r\n -RUNTIME ERROR CHECKING BY STUBS-\r\n/error all Turn on all the error checking options, the best flavor\r\n/error none Turn off all the error checking options\r\n/error allocation Check for out of memory errors\r\n/error bounds_check Check size vs transmission length specification\r\n/error enum Check enum values to be in allowable range\r\n/error ref Check ref pointers to be non-null\r\n/error stub_data Emit additional check for server side stub data validity\r\n All the /error checking above are replaced by /robust\r\n/robust Generate additonal information to validate parameters. \r\n Requires Windows 2000 and after (default)\r\n/no_robust turn off /robust feature. not applicable for 64-bit Windows\r\n\r\n -OPTIMIZATION-\r\n/align {N} Designate packing level of structures\r\n/pack {N} Designate packing level of structures\r\n/Zp {N} Designate packing level of structures\r\n/no_format_opt Skip format string reusage optimization\r\n/Oi Generate fully interpreted stubs, old style\r\n -Oicf is usually better\r\n/Oic Generate fully interpreted stubs for standard interfaces and\r\n stubless proxies for object interfaces as of NT 3.51 release\r\n using -Oicf instead is usually better\r\n/Oicf Generate fully interpreted stubs with extensions and stubless\r\n proxies for object interfaces as of NT 4.0 release (default)\r\n/Oif Same as -Oicf\r\n/Os Generate inline stubs\r\n\r\n -MISCELLANEOUS-\r\n@response_file Accept input from a response file\r\n/? Display a list of MIDL compiler switches\r\n/confirm Display options without compiling MIDL source\r\n/help Display a list of MIDL compiler switches\r\n/nologo Supress displaying of the banner lines\r\n/o filename Redirects output from screen to a file\r\n/W{0|1|2|3|4} Specify warning level 0-4 (default = 1)\r\n/WX Report warnings at specified /W level as errors\r\n/no_warn Suppress compiler warning messages\r\n", "error": "Microsoft (R) 32b/64b MIDL Compiler Version 8.01.0622 \r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\midl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "midlc.exe-275D8C11A944629E9DB9B1A26C186624": { "file_name": "midlc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\midlc.exe", "hash_md5": "275D8C11A944629E9DB9B1A26C186624", "hash_sha1": "A63F881D302540D9EC31F96CE496E9FC83056323", "hash_sha256": "2DAC377ECE0C1BF4F793D4741894E356FE9EAA7D1F54C9CC0FDF7E50B3E46E6C", "hash_sha384": "C6916D7631E7C8B6190DA5E5480BA1F3729A5A046FD0BBCC858DB0AFAC500F18FC42422497F8F80ABDCFDF0B846F7B7E", "hash_sha512": "49A1125A1C5C8D4382FFD6D5CFF6701B30223C5170E40C8425FCFFF97FFB4ED413953B6407889F4D682B026A7D1529BA125B2F32C7C59C324E629AD9899F40AB", "hash_ssdeep": "12288:DgSFxPODhDj5fLFyouBZc/Y9JRq15M6gLVzt70jk7939cjI4sRZCqCG:DYJLFXAnVq1qRRskJ39EsRZCqj", "hash_imp": "B5A2763B8FB2C6E0F0443F5E9C8F872F", "hash_pesha1": "24CFEBB47F3D021E533F002D5BB57C30DEE96D59", "hash_pe256": "88197C4506CFA0F12416C93A4D49BCA5284D0F1F930480178B338E4C3EB7D9EC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IDL Compiler", "meta_original_filename": "midlc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2dac377ece0c1bf4f793d4741894e356fe9eaa7d1f54c9cc0fdf7e50b3e46e6c/detection", "output": "midl : error MIDL2399 : invalid or corrupt intermediate compiler file : help\r\n00: 30 ffffff82 02 43 30 ffffff82 01 fffffff1 ffffffa0 03 02 01 02 02 10 6d 0.C0.......m\r\n10: ffffffdf ffffffcc ffffff8e ffffffa8 50 ffffff89 ffffffae 41 ffffffb7 65 fffffff1 0a 5e 14 fffffffe 30 PAe.^.0\r\n20: 09 06 05 2b 0e 03 02 1d 05 00 30 16 31 14 30 12 ...+......0.1.0.\r\n30: 06 03 55 04 03 13 0b 52 6f 6f 74 20 41 67 65 6e ..U....Root Agen\r\n40: 63 79 30 1e 17 0d 32 31 30 31 31 31 32 31 34 34 cy0...2101112144\r\n50: 34 33 5a 17 0d 33 39 31 32 33 31 32 33 35 39 35 43Z..39123123595\r\n60: 39 5a 30 22 31 20 30 1e 06 03 55 04 03 13 17 4a 9Z0\"1 0...U....J\r\n70: 6f 65 27 73 2d 53 6f 66 74 77 61 72 65 2d 45 6d oe's-Software-Em\r\n80: 70 6f 72 69 75 6d 30 ffffff82 01 22 30 0d 06 09 2a ffffff86 porium0.\"0...*\r\n90: 48 ffffff86 fffffff7 0d 01 01 01 05 00 03 ffffff82 01 0f 00 30 ffffff82 H..........0\r\na0: 01 0a 02 ffffff82 01 01 00 ffffffbc ffffffc0 ffffffb9 03 33 ffffff80 10 5c 77 .......3.\\w\r\nb0: 5c ffffffbf ffffffaa 71 ffffffbd ffffff80 ffffffc1 ffffffdb 66 ffffffc1 ffffffa5 ffffffc4 3f ffffffcd 78 fffffff2 \\qf?x\r\nc0: ffffffe5 63 39 53 69 25 ffffffbf 5b 00 1f ffffffac 5e ffffff95 73 ffffffee 5f c9Si%[..^s_\r\nd0: 11 1f ffffffdf ffffff82 ffffffb4 fffffff3 58 ffffff8e 3f ffffff8f 76 0c 55 07 fffffff3 ffffffc0 ..X?v.U.\r\ne0: ffffffbb ffffffc2 ffffffa5 16 36 ffffffd9 fffffff5 fffffff5 ffffff9c 7f fffffff8 ffffffd8 ffffffbe 04 ffffffa7 ffffff92 .6..\r\nf0: 0a 0b ffffffcd 60 08 19 ffffffb7 ffffff90 79 48 61 ffffff9e 13 0f fffffffe ffffffc0 ..`..yHa..\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\midlc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "midlrt.exe-49EF1FFAF4A83B881485F0C5CB9E112B": { "file_name": "midlrt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\midlrt.exe", "hash_md5": "49EF1FFAF4A83B881485F0C5CB9E112B", "hash_sha1": "43A0FBC884CB2B08060C565B11AAA49015AC7C15", "hash_sha256": "AF38902606532E2BBD37F6FAA3BCB77EC525F96A51EB1A9C3B6584A105F671E5", "hash_sha384": "4A687994D19EC32E3E6553CE65737BE84C9F23AD6DBD31740E57B4FB110A2C7BED0B240D7CA7EF1FC9CC7F5F6E52CC50", "hash_sha512": "234106B643014104FD2FD8A3B62714ACC8ABFBB6B4F194E20DF51E443A0BE274E7847284E597EE2C43CD1EA13C8B31EBC31F8218A823CA4DD0AF74BE23F24768", "hash_ssdeep": "24576:Fh6NhfaJiDqpCz/qxbMulmOqOxcS0eUqDtQXPH6pJwskcDSTmoc8Dhc53EcbrJIJ:D5tQfHewaSTmoc8Dhc53TK27JmeKJTnP", "hash_imp": "222BB63698D5E056823213878B2E8268", "hash_pesha1": "9AB6EE31B803C46E6CEDBEAE27613FFF8786DA93", "hash_pe256": "E574FB86CDE28064AF118ED9A7C0C4C5688322DA1CDC463EED085058E47074D1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IDL Compiler", "meta_original_filename": "midlrt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": " -MIDL COMPILER OPTIONS-\r\n -MODE-\r\n/ms_ext Microsoft extensions to the IDL language (default)\r\n/c_ext Allow Microsoft C extensions in the IDL file (default)\r\n/osf OSF mode - disables /ms_ext and /c_ext options\r\n/app_config Allow selected ACF attributes in the IDL file\r\n/mktyplib203 MKTYPLIB Version 2.03 compatiblity mode\r\n\r\n -INPUT-\r\n/acf filename Specify the attribute configuration file\r\n/I directory-list Specify one or more directories for include path\r\n/no_def_idir Ignore the current and the INCLUDE directories\r\n/metadata_dir Specify one or more directories containing platform metadata files\r\n/reference Specify one or more WinMD files to import\r\n\r\n -OUTPUT FILE GENERATION-\r\n/client none Do not generate client files\r\n/client stub Generate client stub file only\r\n/out directory Specify destination directory for output files\r\n/server none Generate no server files\r\n/server stub Generate server stub file only\r\n/syntax_check Check syntax only; do not generate output files\r\n/Zs Check syntax only; do not generate output files\r\n/oldtlb Generate old format type libraries\r\n/newtlb Generate new format type libraries (default)\r\n/notlb Don't generate the tlb file\r\n/nomd Suppress generation of metadata file\r\n\r\n -OUTPUT FILE NAMES-\r\n/cstub filename Specify client stub file name\r\n/dlldata filename Specify dlldata file name\r\n/h filename Specify header file name\r\n/header filename Specify header file name\r\n/iid filename Specify interface UUID file name\r\n/proxy filename Specify proxy file name\r\n/sstub filename Specify server stub file name\r\n/tlb filename Specify type library file name\r\n/winmd Specify output metadata file name \r\n\r\n -WINDOWS RUNTIME OPTIONS-\r\n/winrt Enable Windows Runtime semantics\r\n/ns_prefix Prepend the 'ABI' namespace to all types\r\n/enum_class Enable use of the C++ enum class construct\r\n/nomidl Suppress running MIDL.EXE after processing windows runtime IDL file\r\n/nomd Suppress generation of metadata while processing windows runtime IDL file\r\n/enable_true_async <true|false> Enable true async feature by default\r\n\r\n -C COMPILER AND PREPROCESSOR OPTIONS-\r\n/cpp_cmd cmd_line Specify name of C preprocessor (default: cl.exe)\r\n/cpp_opt options Specify additional C preprocessor options\r\n/cpp_level level Specify additional C preprocessor options\r\n/D name[=def] Pass #define name, optional value to C preprocessor\r\n/no_cpp Turn off the C preprocessing option\r\n/nocpp Turn off the C preprocessing option\r\n/U name Remove any previous definition (undefine)\r\n/msc_ver <nnnn> Microsoft C/C++ compiler version\r\n/savePP Save the preprocessed temporary file(s)\r\n\r\n -ENVIRONMENT-\r\n/char signed C compiler default char type is signed\r\n/char unsigned C compiler default char type is unsigned\r\n/char ascii7 Char values limited to 0-127\r\n/env win32 Target environment is Microsoft Windows 32-bit (NT)\r\n/env ia64 Target environment is Microsoft Windows 64-bit (NT) for IA64\r\n/env x64 Target environment is Microsoft Windows for 64-Bit \r\n Extended Systems\r\n/lcid Locale id for international locales\r\n/ms_union Use Midl 1.0 non-DCE wire layout for non-encapsulated unions\r\n/oldnames Do not mangle version number into names\r\n/rpcss Automatically activate rpc_sm_enable_allocate\r\n/use_epv Generate server side application calls via entry-pt vector\r\n/no_default_epv Do not generate a default entry-point vector\r\n/prefix client str Add \"str\" prefix to client-side entry points\r\n/prefix server str Add \"str\" prefix to server-side manager routines\r\n/prefix switch str Add \"str\" prefix to switch routine prototypes\r\n/prefix all str Add \"str\" prefix to all routines\r\n/win32 Target environment is Microsoft Windows 32-bit (NT)\r\n/ia64 Target environment is Microsoft Windows 64-bit (NT) for IA64\r\n/x64 Target environment is Microsoft Windows for 64-Bit \r\n Extended Systems\r\n/protocol dce Use DCE NDR transfer syntax (default for 32b)\r\n/protocol all Use all supported transfer syntaxes\r\n/protocol ndr64 Use Microsoft extension NDR64 transfer syntax\r\n/target {system} Set the minimum target system\r\n\r\n -RUNTIME ERROR CHECKING BY STUBS-\r\n/error all Turn on all the error checking options, the best flavor\r\n/error none Turn off all the error checking options\r\n/error allocation Check for out of memory errors\r\n/error bounds_check Check size vs transmission length specification\r\n/error enum Check enum values to be in allowable range\r\n/error ref Check ref pointers to be non-null\r\n/error stub_data Emit additional check for server side stub data validity\r\n All the /error checking above are replaced by /robust\r\n/robust Generate additonal information to validate parameters. \r\n Requires Windows 2000 and after (default)\r\n/no_robust turn off /robust feature. not applicable for 64-bit Windows\r\n\r\n -OPTIMIZATION-\r\n/align {N} Designate packing level of structures\r\n/pack {N} Designate packing level of structures\r\n/Zp {N} Designate packing level of structures\r\n/no_format_opt Skip format string reusage optimization\r\n/Oi Generate fully interpreted stubs, old style\r\n -Oicf is usually better\r\n/Oic Generate fully interpreted stubs for standard interfaces and\r\n stubless proxies for object interfaces as of NT 3.51 release\r\n using -Oicf instead is usually better\r\n/Oicf Generate fully interpreted stubs with extensions and stubless\r\n proxies for object interfaces as of NT 4.0 release (default)\r\n/Oif Same as -Oicf\r\n/Os Generate inline stubs\r\n\r\n -MISCELLANEOUS-\r\n@response_file Accept input from a response file\r\n/? Display a list of MIDL compiler switches\r\n/confirm Display options without compiling MIDL source\r\n/help Display a list of MIDL compiler switches\r\n/nologo Supress displaying of the banner lines\r\n/o filename Redirects output from screen to a file\r\n/W{0|1|2|3|4} Specify warning level 0-4 (default = 1)\r\n/WX Report warnings at specified /W level as errors\r\n/no_warn Suppress compiler warning messages\r\n", "error": "Microsoft (R) 32b/64b MIDLRT Compiler Engine Version 10.00.0229 \r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\nmidlrt : error MIDL1011 : [msg]argument(s) missing for switch [context]/h\r\nmidlrt : error MIDL1000 : [msg]missing source-file name \r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\midlrt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MsiCert.exe-98A65625F8151F65DEADF60A58DE2831": { "file_name": "MsiCert.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\MsiCert.exe", "hash_md5": "98A65625F8151F65DEADF60A58DE2831", "hash_sha1": "DAC6F7301C596BBD4DBEBFCAA57FF7B17E31FF5D", "hash_sha256": "340D0E79D9C18D2445965A32DD9C18C611A03EACA104C7FB6335421F18A3CEE9", "hash_sha384": "C21F43010D87F4B3317208D2CE6B487DCA8E9C7260BC1A2F00A793C9BE61E14C53895D6757E58E4ABFE8964A9192AE93", "hash_sha512": "7259E41DF37670647852E6FD821FA596F94FCE913E1A796532E4179CDE317F418B06BF34C9A6F49D8DDDF6CD45ED79EF602CA6D471A284601B1FFBB03B799302", "hash_ssdeep": "1536:GxUmWLpC/u04jTsYh51ioJ9VF1lT45ikrCBo1cqITCcgH+l:GxDMq40iXJ9f1iWW1cqITRvl", "hash_imp": "2A9E8EF4B4A8386BA6D1261855062BD7", "hash_pesha1": "1F09CB8BA47E5F2FB4713177E16BA9DD08053BC9", "hash_pe256": "4D8849C79F1EC5B934C1A778C8A9A0CDADAF177179EBACD7141AE63D4D0AAFC7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MSI Database DigitalSignature table update", "meta_original_filename": "msicert.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "MsiCert V 5.0\r\nCopyright (c) Microsoft Corporation. All Rights Reserved\r\n\r\nMsiCert will populate the MsiDigitalSignature and MsiDigitalCertificate tables\r\nfor a given Media entry and cabinet\r\n\r\n\r\nSyntax: msicert -d {database} -m {media entry} -c {cabinet} [-h]\r\n\t -d: the database to update\r\n\t -m: the media entry in the Media table representing the cabinet\r\n\t -c: the digitally signed cabinet\r\n\t -h: (optional) include the hash of the digital signature\r\n\t -?: display this help message\r\n\t -nologo: do not display the logo message\r\n\r\nThe default behavior is to populate the MsiDigitalSignature\r\nand MsiDigitalCertificate tables with the signer certificate\r\ninformation from the digitally signed cabinet. The MsiDigitalSignature\r\nand MsiDigitalCertificate tables will be created if necessary.\r\n", "children": [ "csrss.exe", "wininit.exe" ], "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\MsiCert.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MsiDb.exe-A8F07B6C9038A150566C3086F48AA79A": { "file_name": "MsiDb.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\MsiDb.exe", "hash_md5": "A8F07B6C9038A150566C3086F48AA79A", "hash_sha1": "59102B8A1EBEB66A016CBE54E4D18D62B5ACFE7B", "hash_sha256": "A4DF033D52A74020EB742A88138D312B0C3FB2770468FE8B6A9C5CFA5D2256B8", "hash_sha384": "67479A9E293195556476B010725A7A25DAF5F4E7D17C8323ED9C57E599E9DD72E8830B7E76F96291FE307FF4BDA846E3", "hash_sha512": "E761E81BBCE892CF5D1D1942E990B7073ED4646C739AC6F3029822F1347929584C20E55F5DB618F74BB640A40339EC42A153C7D77926F61098DC30790315BCCF", "hash_ssdeep": "1536:kBIfJYeBqWCuVyW9zQYuJWoaw2TQ6xlgppbIkM6CTfxD+tWHlgQ/X3y:kBIfeeBBt9SdZ2TFx2NC+tkyi", "hash_imp": "2DF29D0736B8A2A1FCCE9F4F1B61F32A", "hash_pesha1": "1AFF2367A3B4FF0298793112C76CD36D95F0AE55", "hash_pe256": "D822C6F9246A2C5540537943CE8D37D256F727E24554D7CD196EE0C23214D85E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Installer Table Creator", "meta_original_filename": "msidb.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_window_title": "MsiDb(d) - Database Modifier", "output": "No mode option specified: (-e, -i, -c, -m, -a, -r, -t)\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\MsiDb.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MsiFiler.exe-D3AF97BC8B2B6E545FB9EE60E10BE581": { "file_name": "MsiFiler.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\MsiFiler.exe", "hash_md5": "D3AF97BC8B2B6E545FB9EE60E10BE581", "hash_sha1": "A96634A12B4C498BBDF36506580CAFCECD8D5F4F", "hash_sha256": "19AB565871CC26E427AE9F5DAA7A3A1D8438839C74F093E725D202EC97CE7CF0", "hash_sha384": "26E3E87D51F7E359B1A9DF9042BB517773BE63329FF912759F4777393EDB334CEB48A1543AA325EDC7CF222202CF8115", "hash_sha512": "F9B3F254CBF7A7AB602B327E0475F3123D11F520D7266CF4C3D3A8A326C9DF675732BB75F75A3411225ACF6B4EBFA4E49FEB511D3AF5123FD8B9D1B4E4E223DC", "hash_ssdeep": "1536:fwQQ7cIPlJaVcSNAIp1kSoxX9SMUJoOmkLcvnT18cBV:fwQQ1UZSyUl9x4ST18cBV", "hash_imp": "1E4973D83298D4F758B718CDB9A58676", "hash_pesha1": "5D67B6B23196AEF70D7B2382F9A4DD73E8CF3CCF", "hash_pe256": "A6C8374ECE48A36ECEEB66EE57CE54BABCED949F4DA897DC163FCEAB503DD4F5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Msi Database File Table Update", "meta_original_filename": "msifiler.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "MsiFiler V 5.0\r\nCopyright (c) Microsoft Corporation. All Rights Reserved\r\n\r\nSyntax: msifiler.exe -d database.msi [-v] [-h] [-s SOURCEDIR]\r\n\t-d: the database to update.\r\n\t-v: verbose mode.\r\n\t-h: populate MsiFileHash table (and create table if it doesn't exist).\r\n\t[-s SOURCEDIR]: specifies an alternative directory to find files.\r\n\t-nologo: do not dispay the logo message.\r\n\t-?: dispay this help message.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\MsiFiler.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MsiInfo.exe-EA60F898ACA9B4FF98C0F159F997DC1D": { "file_name": "MsiInfo.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\MsiInfo.exe", "hash_md5": "EA60F898ACA9B4FF98C0F159F997DC1D", "hash_sha1": "57734765370619E43015DBB4E49ED34F9A2278ED", "hash_sha256": "408557251932F5727024F1A23DFF722B97392134D01393C2187A138401BBB15D", "hash_sha384": "52693DFD29CB076D00D1C1482F32379A4077D7DC30AA59D8EEE777081BD70B54C29BE9E9CA93A863883FFBF81703FC73", "hash_sha512": "3037BEA25B3D0BAA6CE376778B273522934BF8DB28000C58044884FA597B353C45AD284859990FE34E84DD9A8138CBEB78B4F58419503BDD3C4123DADA3FD0D1", "hash_ssdeep": "1536:UVSg3cCAyv+wtZzZJmm81Hwp+KqImZoqzcoRTBzE7utI3kHYmrpfXDSiBwnkfX8E:UVSg3cCAyv+azZJd8WYcP2vRTFEghrBL", "hash_imp": "D873CE2F5EC1F9C637B60736185D765F", "hash_pesha1": "EE2B6D387D5E7555AE8C43904EB7C5C199E35CFA", "hash_pe256": "E551285B09B988836030E3C5A87384D800FC82DF67B3AAEBBEF4E8B8A525079C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MSI SummaryInformation Display and Update", "meta_original_filename": "msiinfo.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "++MsiInfo.exe Command Line Syntax++\nMsiInfo.exe {database} --> To Display Summary Info Properties\nMsiInfo.exe {database} Options.... --> To Set Summary Info Properties\n++MsiInfo.exe Options++\nPID_DICTIONARY - /I {value}\nPID_CODEPAGE - /C {value}\nPID_TITLE - /T {value}\nPID_SUBJECT - /J {value}\nPID_AUTHOR - /A {value}\nPID_KEYWORDS - /K {value}\nPID_COMMENTS - /O {value}\nPID_TEMPLATE - /P {value}\nPID_LASTAUTHOR - /L {value}\nPID_REVNUMBER - /V {value}\nPID_EDITTIME - /E {value}\nPID_LASTPRINTED - /S {value}\nPID_CREATE_DTM - /R {value}\nPID_LASTSAVE_DTM - /Q {value}\nPID_PAGECOUNT - /G {value}\nPID_WORDCOUNT - /W {value}\nPID_CHARCOUNT - /H {value}\nPID_THUMBNAIL - NOT SUPPORTED\nPID_APPNAME - /N {value}\nPID_SECURITY - /U {value}\nValidate String Pool - [/B] /D (use /B to display the string pool)\n/? - Displays this help message\n/nologo - Do not display the logo message\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\MsiInfo.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Msimerg.exe-A8F362C7A9854553BB33BF73436E783D": { "file_name": "Msimerg.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\Msimerg.exe", "hash_md5": "A8F362C7A9854553BB33BF73436E783D", "hash_sha1": "4A19608D2348FF66ABF4CA8EAA55C6D7E86D7717", "hash_sha256": "4B5C3F0FA2C0E74DBD15A068F8DE0DC3D16057E2BC32542804E71DB7D1A56447", "hash_sha384": "5E5562F9EE52479A3BFB99EF6CE7A8615AE8DFD27FBF25E08594492F1D48D6337DFAA62648036F3417DFE63074A45577", "hash_sha512": "B586DF35CBA7299B5B216CF83531EFF23B49B96081000310045AF64693AC8B8A953B9953A3B27F62D3DA9E6C4EDA3AF7978BE04BE8A6E379D1C15A3CB4577CFF", "hash_ssdeep": "1536:k1Ht0ZBhf8htGcHndVEoQ4/pb/DpWjotEkdQiMU10gJ1azG:k1HGv1yBnpQ4/pTl/110gJ8zG", "hash_imp": "1F66958841082F299A00160C1B625075", "hash_pesha1": "C63D484899C3B69448F26119B599CDE847C6DBC6", "hash_pe256": "65F098CD24293E150819D3694EF3A0A24FB8B1C009E6F8A03E25977D37B0E799", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MSI database merge tool", "meta_original_filename": "msimerg.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Error 1. \nMsi Merge Tool --- Merge Two Databases\n\n\t MsiMerg(d).exe {base db} {ref db}\n\t /? Displays this help message\n\t /nologo Do not display the logo message. This should be the last option.\n\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\Msimerg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MsiMsp.exe-F7CC0F2944004DA4DCDEA8DEDFD36206": { "file_name": "MsiMsp.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\MsiMsp.exe", "hash_md5": "F7CC0F2944004DA4DCDEA8DEDFD36206", "hash_sha1": "7CE9B098FEB8417C49ED5BFEE2D33763579ED419", "hash_sha256": "8488380CCF6BAEA8786418A516823BD356491239EA456DE78A14C3DA29B92586", "hash_sha384": "31166CC94634D227B62CDDC46AC6013FD8810E1C4EC8BBB708ADED54371FBD84E592CB24FFD2F4CB2997F8FEE8E75DA3", "hash_sha512": "84765857D4424D3E5B51C1629DDEBA6864964A849280B08CA80282135E805055A98F8012FF9DA9816EA9E100A6CA84B3FE6C3E183B9C0775212D2AE9E62C0AA7", "hash_ssdeep": "1536:8t0VtEwk8jv1IGGoFGSfjOtJX/4nS6KkDhHx2ls13g5iC3Q:b9tpTBfStJvw7oC13g5if", "hash_imp": "8838B0111C675FE252DC16B3ABB4A1AC", "hash_pesha1": "80725CE1A5D2203C9C464E293E64794AE037AA88", "hash_pe256": "20B5167CC3F7450FFB7762D8F232A48E75FC6BA79815953D11D8E827A8856CE6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Installer Patch generation command-line tool", "meta_original_filename": "msimsp.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "MsiMsp: Windows Installer patch creation tool.\r\n\r\nSee msi.chm for help on setting up the Patch Creation Properties (pcp) file.\r\n\r\nOptions:\r\n\r\n -s {pcp}\t\tPath to Patch Creation Properties file.\r\n -p {msp}\t\tPath to patch package to create.\r\n [-l[p] {log}]\t\tOptional. Path to log file.\r\n [-f {temp folder}]\tOptional. Path to temp folder.\r\n [-k]\t\tOptional. Fail if temp folder already exists.\r\n [-d]\t\tOptional. Display dialog when patch created successfully.\r\n [-?]\t\tOptional. Display this help message.: --help\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\MsiMsp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MsiTran.exe-6ACFFD6C96B748F7F38063FEC43A24D1": { "file_name": "MsiTran.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\MsiTran.exe", "hash_md5": "6ACFFD6C96B748F7F38063FEC43A24D1", "hash_sha1": "2C16234BDC25D7A08B7F6B02138FF6C8550858E9", "hash_sha256": "A3E13515F279FD84C09F335E34D8EE2D15140007ACC4C377A9E7E9E7C02765AA", "hash_sha384": "4002AE6C5078B6892FC4CB2D90DAE5A469A05216F50B52F1A68A2B456D62D43133B7B0A457BE987607C8E8C58D5FD861", "hash_sha512": "1A2BE60DD6119A311A1D43ABFD6E9B479F7CC4C462DD4F92F8D119A7726BC5BAD071890DF409D8353D7645315ECD3EFC28592D8415B5BFEC04D4EFDBB662817C", "hash_ssdeep": "1536:sEHtCZ9BkpkUp7y2lMZo5WiGuCYPzksrDV1iaAG5a:sEHtuEdNL5WfS751iaAma", "hash_imp": "2966C47977779404E0D6EB3117DD103A", "hash_pesha1": "DE3D95E080697F5A9D10A71839BDBA40C4E6D2D0", "hash_pe256": "BF8904931281DDF88219CAF18AF908A6098B7703C7C0397F96B85FF36B2F3044", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MSI database transform tool", "meta_original_filename": "msitran.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Error 1. Msi Transform Tool --- Generate and Apply Transform Files\n\nOptions for MsiTran.exe:\n-g {base db} {new db} {transform} [{error/validation conditions}] -->Generate\n-a {transform} {database} [{error conditions}] -->Apply\n\nError Conditions:\nThe following errors may be suppressed when applying a transform.\nTo suppress an error, include the appropriate character in\n{error conditions}. Conditions specified with -g are placed in\nthe summary information of the transform, but are not used when\napplying a transform with -a.\n\n'a': Add existing row.\n'b': Delete non-existing row.\n'c': Add existing table.\n'd': Delete non-existing table.\n'e': Modify existing row.\n'f': Change codepage.\n\nValidation Conditions:\nThe following validation conditions may be used to indicate when a\ntransform may be applied to a package. These conditions may be\nspecified with -g but not -a.\n\n'g': Check upgrade code.\n'l': Check language.\n'p': Check platform.\n'r': Check product.\n's': Check major version only.\n't': Check major and minor versions only.\n'u': Check major, minor, and update versions.\n'v': Applied database version < base database version.\n'w': Applied database version <= base database version.\n'x': Applied database version = base database version.\n'y': Applied database version >= base database version.\n'z': Applied database version > base database version.\n\nGenerate transform without summary info stream (conditions ignored):\n'@': Suppress summary information stream generation.\n-? Displays this help message.\n-nologo Do not display the logo message.\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\MsiTran.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mt.exe-3BAE2987E79A60E1C1EBB05A6D58C026": { "file_name": "mt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\mt.exe", "hash_md5": "3BAE2987E79A60E1C1EBB05A6D58C026", "hash_sha1": "2AA062C2853C1BD8392E24B1B81926A113505D98", "hash_sha256": "FB81BEA04D38D5585DE7DDD8EFEE7FF402589F9845D634A4B491DC1BDEA812AF", "hash_sha384": "A5305703CA046A3897B397DF495E75FBE1730FED70AC1D1CA63411226453B4BEB99CFBBD07E679C54F4BE02F42851E39", "hash_sha512": "F79C37CA637503BDB82D0EA78FE02C5CD1FADEDEB1F96BAE561E83BCA0F173CFC46EC12EB111810F47A0ABC991AD6504E798EF05862A36A552BE613608847348", "hash_ssdeep": "24576:BOpO8ZojCyBvTiSDU7wqBO9koe3dX7jG4/gEYqEF723jALQ4yAzxk2g/GVABm4aP:BOpO8ZojCyBvTiObqQQ7jmWSZQszK2gk", "hash_imp": "0F6052A937D9D41FF8F9D7772A13248B", "hash_pesha1": "B584BFE43BE38911956D76B5C6F9A241C7B83312", "hash_pe256": "1AA0C2CCFCFB16C50A4314EE47CF30B7716E516C5579EE72FD6F6B81B347C7E3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "mt2.exe", "meta_original_filename": "mt2.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/fb81bea04d38d5585de7ddd8efee7ff402589f9845d634a4b491dc1bdea812af/detection", "output": "Microsoft (R) Manifest Tool\r\r\nCopyright (c) Microsoft Corporation. \r\r\nAll rights reserved.\r\r\n\r\r\nUsage:\r\r\n-----\r\r\nmt.exe \r\r\n [ -manifest <manifest1 name> <manifest2 name> ... ]\r\r\n [ -identity:<identity string> ]\r\r\n [ < <[-rgs:<.rgs filename>] [-tlb:<.tlb filename>] [-winmd:<.winmd filename>]> -dll:<filename> > [ -replacements:<XML filename> ] ] \r\r\n [ -managedassemblyname:<managed assembly> [ -nodependency ] ]\r\r\n [ -out:<output manifest name> ]\r\r\n [ -inputresource:<file>[;[#]<resource_id>] ]\r\r\n [ -outputresource:<file>[;[#]<resource_id>] ]\r\r\n [ -updateresource:<file>[;[#]<resource_id>] ]\r\r\n [ -hashupdate[:<path to the files>] ]\r\r\n [ -makecdfs ]\r\r\n [ -validate_manifest ]\r\r\n [ -validate_file_hashes:<path to the files> ]\r\r\n [ -canonicalize ]\r\r\n [ -check_for_duplicates ]\r\r\n [ -nologo ]\r\r\n\r\r\nOptions:\r\r\n-------\r\r\n-manifest Used to specify manifests that need to be processed.\r\r\n At least one manifest name should follow this option.\r\r\n NOTE: There is no colon(:) after -manifest.\r\r\n \r\r\n<manifest1 name> <manifest2 name> ... \r\r\n Names of manifests to be processed and/or merged.\r\r\n Required if the -manifest option is used.\r\r\n NOTE: More than one manifest automatically indicates\r\r\n a manifest \"merge\" operation. In that case, an\r\r\n output specified by one of -out / -outputresource /\r\r\n -updateresource is mandatory.\r\r\n \r\r\n-identity:<identity string>\r\r\n The identity string contains the attributes of the\r\r\n assemblyIdentity element. The identity string is a\r\r\n set of comma separated name=value pairs starting\r\r\n with the \"name\" attribute's value. e.g.:\r\r\n \"Microsoft.Windows.Common-Controls,\r\r\n processorArchitecture=x86, version=6.0.0.0,\r\r\n type=win32, publicKeyToken=6595b64144ccf1df\".\r\r\n NOTE: Only the \"name\" attribute is not of the form\r\r\n \"name=value\" and it should be the first attribute in\r\r\n the identity string.\r\r\n\r\r\n-rgs: Takes the name of the .RGS (Registrar script).\r\r\n\r\r\n-tlb: Takes the name of the .TLB (Typelib file).\r\r\n\r\r\n-winmd: Takes the name of the .WINMD (Windows Runtime metadata file).\r\r\n\r\r\n-dll: Takes the name of the DLL: this represents the DLL\r\r\n that is eventually built from the .RGS, .TLB, and .WINMD\r\r\n files. Required if -rgs, -tlb, or -winmd is specified.\r\r\n\r\r\n-replacements:<.XML filename> \r\r\n Specifies the file that contains values for\r\r\n replaceable strings in the RGS file.\r\r\n\r\r\n-managedassemblyname:<managed assembly> [ -nodependency ] \r\r\n Generates a manifest from a managed assembly.\r\r\n -nodependency suppresses the generation\r\r\n of dependency elements in the final manifest.\r\r\n \r\r\n-out:<Output manifest name> \r\r\n Name of the output manifest. If this is skipped\r\r\n and only one manifest is being operated upon by the\r\r\n tool, that manifest is modified in place.\r\r\n\r\r\n-inputresource:<file>[;[#]<resource_id>]\r\r\n Input the manifest from a resource of type\r\r\n RT_MANIFEST with the specified id.\r\r\n resource_id is restricted to be a non-negative,\r\r\n 16 bit number.\r\r\n resource_id is optional and defaults to\r\r\n CREATEPROCESS_MANIFEST_RESOURCE_ID (winuser.h).\r\r\n\r\r\n-outputresource:<file>[;[#]<resource_id>]\r\r\n Output the manifest to a resource of type\r\r\n RT_MANIFEST with the specified id.\r\r\n resource_id is restricted to be a non-negative,\r\r\n 16 bit number.\r\r\n resource_id is optional and defaults to\r\r\n CREATEPROCESS_MANIFEST_RESOURCE_ID (winuser.h).\r\r\n\r\r\n-updateresource:<file>[;[#]<resource_id>]\r\r\n Equivalent to specifying both -inputresource and\r\r\n -ouputresource with identical parameters.\r\r\n resource_id is restricted to be a non-negative,\r\r\n 16 bit number.\r\r\n\r\r\n-hashupdate:<path to the files> \r\r\n Computes the hash of files specified in the file\r\r\n elements and updates the hash attribute with this\r\r\n value. The searchpath for the actual files\r\r\n specified in the file elements is specified\r\r\n explicitly. If <path to the files> is not\r\r\n specified, the searchpath defaults to the location\r\r\n of the output manifest.\r\r\n\r\r\n-makecdfs Generates Catalog Definition Files (.cdf) - used to\r\r\n make catalogs.\r\r\n \r\r\n-validate_manifest Validates to check syntactic correctness of a\r\r\n manifest and its conformance to the manifest schema.\r\r\n\r\r\n-validate_file_hashes:<path to the files> \r\r\n Validates the hash values of all the file elements.\r\r\n \r\r\n-canonicalize Does a C14N canonicalization of the output manifest\r\r\n contents.\r\r\n\r\r\n-check_for_duplicates Performs a check to see if the final manifest\r\r\n contains duplicate elements.\r\r\n\r\r\n-nologo Runs without displaying standard Microsoft copyright\r\r\n data. This may be used to suppress unwanted output\r\r\n in log files when running mt.exe as part of a build\r\r\n process or from a build environment.\r\r\n\r\r\nSamples:\r\r\n-------\r\r\n\r\r\n> To update the hash of an XML manifest:\r\r\nmt.exe -manifest 1.manifest -hashupdate -out:updated.manifest\r\r\n\r\r\n> To update the hash of an XML manifest while simultaneously producing the .cdf file:\r\r\nmt.exe -manifest 1.manifest -hashupdate -makecdfs -out:updated.manifest\r\r\n\r\r\n> To merge two manifests:\r\r\nmt.exe -manifest 1.manifest 2.manifest -out:merged.manifest\r\r\n\r\r\n> To merge two manifests and finally update the hash to produce the final merged manifest. \r\r\n> Note: The searchpath for the actual files specified in the file elements is specified explicitly.\r\r\nmt.exe -manifest 1.manifest 2.manifest -hashupdate:d:\\filerepository -out:merged.manifest\r\r\n\r\r\n> To generate a manifest from an RGS and/or TLB file:\r\r\nmt.exe -rgs:MSClus.rgs -tlb:MSClus.tlb -dll:foo.dll -replacements:replacements.manifest -identity:\"type=win32, name=Microsoft.Tools.SampleAssembly, version=6.0.0.0, processorArchitecture=x86, publicKeyToken=6595b64144ccf1df\" -out:rgstlb.manifest\r\r\n\r\r\n> To generate an XML manifest from a managed assembly:\r\r\nmt.exe -managedassemblyname:managed.dll -out:out.manifest\r\r\n> To suppress dependencies:\r\r\nmt.exe -managedassemblyname:managed.dll -nodependency -out:out.manifest\r\r\n\r\r\n> To extract manifest out of a dll:\r\r\nmt.exe -inputresource:dll_with_manifest.dll;#1 -out:extracted.manifest\r\r\n\r\r\n> To merge two manifests, one of them embedded in a dll, and embedding final merged manifest into another dll's resource:\r\r\nmt.exe -inputresource:dll_with_manifest.dll;#1 -manifest 2.manifest -outputresource:dll_with_merged_manifest.dll;#3\r\r\n\r\r\n> To update the manifest in a PE's resource (by updating the hashes of the file elements): \r\r\nmt.exe -updateresource:dll_with_manifest.dll;#1 -hashupdate:f:\\files\r\r\n\r\r\n> To validate the hash values of all the file elements:\r\r\nmt.exe -manifest 1.manifest -validate_file_hashes:\"c:\\files\"\r\r\n\r\r\n> To validate a manifest (i.e., to see if it conforms to the manifest schema):\r\r\nmt.exe -manifest 1.manifest -validate_manifest\r\r\n\r\r\n> To do a C14N canonicalization of a manifest (in order to get rid of spurious namespace prefixes (like \"dsig\")):\r\r\nmt.exe -manifest 1.manifest -canonicalize\r\r\n\r\r\n> To check for duplicate elements in a manifest:\r\r\nmt.exe -manifest 1.manifest -check_for_duplicates\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\mt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "muirct.exe-7553D72095C0AA7C67BF2058BD93F99F": { "file_name": "muirct.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\muirct.exe", "hash_md5": "7553D72095C0AA7C67BF2058BD93F99F", "hash_sha1": "1038B1282FD8A70CEBD44E69DCBCDE7AC9791B3A", "hash_sha256": "2CCE7EA27A46FDF03148DFC3E1CD6EC52A37D1CFDB8EB0CC7F4C8B0C2F16F194", "hash_sha384": "C1C40327FDDD4A1E3187F51A8F5F2B12CA83F3B896A1DADFC312C60AC071E70E08A77DFCECE90EBB394708F694515EFB", "hash_sha512": "50071B633A9F0F659955CDD01F7EDE6939EB8D976A9CE7AA2DB816AE0636E348B66A8D0B68FB055EB4A536F9475735AEAF1B1B2D9C857DA964E3C4B9A3E3ADC3", "hash_ssdeep": "3072:6spzPYuPTgAsI4s8OnnkzCUBYgUtHG4JGbgkXtWoeFQPEA+KPPXnIzw4bVH:lVmcGbVtbeFmETKnYzbd", "hash_imp": "BD4B220AE7A320EA5953B0A038419700", "hash_pesha1": "BFF381BA01AEE1C2FDF6B354210B27D9EDDE7B66", "hash_pe256": "69DDD69E60463049A078C1FCF56EA22E29499BE7E77070D46E21651B96AE54B2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Muirct.exe MUI build tool", "meta_original_filename": "muirct.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Description\r\n\r\nMUIRCT (Muirct.exe) is a command-line utility for splitting a standard Win32\r\nportable executable file into a language-neutral (LN) file and a language\r\nspecific .mui file based on a resource configuration file (rc_config file).\r\nIn addition to this main functionality, MUIRCT provides options to extract or\r\ncalculate resource checksum information from one binary file and copy it to\r\nanother and to display the contents of the resource configuration data\r\ncontained in a given binary.\r\n\r\nMUIRCT usages\r\n\r\n1. Split binary into main binary and mui file based on rc_config file\r\n Muirct -q rc_config [-c checksum_file [-b LangID]] [-x LangID] [-g LangId]\r\n [-f] [-m] [-v level] source_file [output_LN_file] [output_MUI_file]\r\n\r\n2. Extract checksum from checksum_file and insert it in output_file\r\n Muirct -c checksum_file [-b LangID] -e output_file\r\n\r\n3. Calculate checksum based on checksum_file and insert it in output_file\r\n Muirct -c checksum_file [-b LangID] -q rc_config -z output_file\r\n\r\n4. Dump resource configuration data contents from input_file.\r\n Muirct -d input_file\r\n\r\nSwitches and arguments\r\n\r\n-b Specifies the language to be used when the checksum_file specified with\r\n -c contains resources in multiple languages. This switch can only be\r\n used in conjunction with the -c switch. The language identifier can be in\r\n decimal or hexadecimal format. MUIRCT fails if the checksum_file contains\r\n resources in multiple language and the -b is not specified or if the\r\n language specified by the -b switch cannot be found in the checksum_file.\r\n\r\n-c Specifies the input checksum_file from which to extract or calculate the\r\n resource checksum. Checksum_file must be a Win32 binary file containing\r\n localizable resources. If checksum_file contains resources for more than\r\n one language, the -b switch must be used to specify which of these\r\n should be used otherwise MUIRCT fails.\r\n\r\n-d Locates and displays embedded resource configuration data in the source\r\n file. When -d is specified, MUIRCT ignores all other switches.\r\n\r\n-e Extracts the resource checksum contained in the checksum_file provided\r\n with the -c switch and inserts it in the specified output_file. When -e\r\n is specified, MUIRCT ignores all switches other than the -c switch.\r\n In this case the checksum_file must be a Win32 binary file that contains a\r\n resource configuration data section with a checksum value.\r\n The output_file must be an existing LN file or .mui file.\r\n\r\n-f Enables creating a .mui file with the version resource being the only\r\n localizable resource. By default, MUIRCT does not allow this.\r\n\r\n-g Specifies the language ID to be included as the ultimate fallback language\r\n in the resource configuration data section of the LN file. If the resource\r\n loader fails to load a requested .mui file from the thread preferred UI\r\n languages, it uses the ultimate fallback language as its last attempt.\r\n The LangID value can be specified in decimal or hexadecimal format.\r\n For example English (United States) can be specified by -g 0x409 or\r\n -g 1033.\r\n\r\n-h | -? Shows the help screen.\r\n\r\n-m Specifies the version number to use when calculating the checksum for\r\n associating the output_LN_file and output_MUI_file.\r\n\r\n-q Specifies that the source_file is to be split into the output_LN_file and\r\n the output_MUI_file according to the rc_config file layout. The rc_config\r\n file is an XML formatted file that specifies which resources will be\r\n extracted to the .mui file and which will be left in the LN file. The\r\n rc_config can specify the distribution of resource types and individual\r\n named items between the output_LN_file and output_MUI_file.\r\n source_file must be a Win32 binary that contains resources in a\r\n single language otherwise MUIRCT fails. MUIRCT does not split the file\r\n if it is language neutral which is indicated by having only language ID\r\n value 0 in the file.output_LN_file and output_mui_file are the names of\r\n the language neutral and .mui file into which the source_file is split.\r\n These file names are optional. If they are not specified, MUIRCT\r\n appends the extensions .ln and .mui to source_file.\r\n Typically you should remove the \".ln\" extension before\r\n deploying the file. MUIRCT associates the output_LN_file and\r\n output_MUI_file by calculating a checksum based on the source_file\r\n name and file version and inserting the result into the resource\r\n configuration section of each output file. When used in conjunction\r\n with the -c switch, the -q switch takes precedence.\r\n If the rc_config file supplied with the -q switch contains a checksum\r\n MUIRCT ignores the -c switch and inserts the checksum value from the\r\n value, rc_config file into the LN and.mui files. If no checksum value is\r\n found in the rc_config, MUIRCT calculates the resource checksum based on\r\n the behavior of the -c switch.\r\n\r\n-v Specifies the level of verboseness for logging. Specify 1 to print all\r\n basic error messages and operation results. Specify 2 to also include the\r\n resource information (type, name, language identifier) included in the\r\n .mui file and LN file. The default is -v 1\r\n\r\n-x Specifies the language ID with which MUIRCT marks all resource types added\r\n to the resource section of the .mui file. The LangID value can be specified\r\n in decimal or hexadecimal format.\r\n For example English (United States) can be specified by -x 0x409 or\r\n -x 1033.\r\n-z Calculates the resource checksum based on the checksum_file specified\r\n with the -c switch (and optionally -b switch) and inserts it in the\r\n specified output_file. The output_file must be an existing LN file or .mui\r\n file.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\muirct.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "oleview.exe-A5BBC4727B92D18A472C8DFB566CAB1E": { "file_name": "oleview.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\oleview.exe", "hash_md5": "A5BBC4727B92D18A472C8DFB566CAB1E", "hash_sha1": "12E3095AF25E991FA1E5B981AE38A4817F0521F8", "hash_sha256": "FCD9002C8CB103B8E28A399075068B7713A3696350C0C2AAF8DD7642711A1481", "hash_sha384": "759B4FFE9EA550EBC9F0B5B9FC96A1A2AF9D2CA33BAF2EEF9219FF41FE0592C95151E0BCEDAE98B9D1F39BC25DDBB427", "hash_sha512": "3F3B2C60B929A0FC1C19BB3E9A57D6D378F4B01FA24C5BBD74B2175EF433EB48CA17041FE5088CD5352DB185CCC1017C1924C5E6FD2B8E6C77BAE50E92B66863", "hash_ssdeep": "3072:NyoSSX7XA5RwkP10/Cg+ufLLobyT9S9jDeQPQ9S0bGA:EaXjA5yBF+ma9jDNPwTG", "hash_imp": "7F02DF18D2B4D893FC5BFAF1D6EB2AB6", "hash_pesha1": "DAD88D52033321971FCBD8FA42FCABBC7EA63E2E", "hash_pe256": "21C6C3591D1711D48BDDCD3B416BEDBB8696668B496D02740C35870929220655", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "OLE/COM Object Viewer", "meta_original_filename": "OLEVIEW.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/fcd9002c8cb103b8e28a399075068b7713a3696350c0c2aaf8dd7642711a1481/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\aclui.dll.mui": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\1b80HWNDInterface:a90726": "Section", "\\BaseNamedObjects\\RotHintTable": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\oleview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "OLE/COM Object Viewer" }, "PackageEditor.exe-1E75B766475DB754B3555783A7677C03": { "file_name": "PackageEditor.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\PackageEditor.exe", "hash_md5": "1E75B766475DB754B3555783A7677C03", "hash_sha1": "C044DEDA31963AB4E158F350F1BCA69DA37C5C93", "hash_sha256": "ED466077A085490970841F1C982664F6E1B75EE1F21338A045A4983C8F6E22AE", "hash_sha384": "30F88CB226A7FBBA7B2DFD83AC792C674E107E6429F200D0BE6D2BC57307F5190D33C2285B1071D0A46C5836DB56C228", "hash_sha512": "54788269D8AC9BA61BE5ECA84CF681F67E793EB52CC95E0EEDFC8D89A16B98EE1FB104E2A943D606A00445B5DAEDD54DC5C2BBBFB6BC862CFE0A1836455099CB", "hash_ssdeep": "384:sO8n8mWa19kkrF8Q5SAH26xN6yAdYQKF0/dLCl+jRzgRCWHsWD:sdGl0FhjzQj/dLClym1", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "021F4D7EC490C035FF62BC17130DC587C4162635", "hash_pe256": "82E9C005B49B4E0EE1C1EBD4D415F642A11E028B1815F6CC46D7D0D1D2A7FFB3", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\PackageEditor.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": " ", "meta_original_filename": "PackageEditor.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ed466077a085490970841f1c982664f6e1b75ee1f21338a045a4983c8f6e22ae/detection", "output": "Microsoft (R) PackageEditor Tool\r\nCopyright (C) 2018 Microsoft. All rights reserved.\r\nLog file is located under: C:\\Users\\user\\AppData\\Local\\Temp\\PackageEditor\\Logs_8\\Log.txt\r\n\r\nVersion 10.0.0.0\r\n\r\nPackageEditor\r\n\r\nUsage: PackageEditor.exe [options] [command]\r\n\r\nOptions:\r\n -h|-? For help with a specific command.\r\n -version Show the tool's version\r\n\r\nCommands:\r\n createDelta -- Create a delta package from two package versions.\nUsage: \n PackageEditor createDelta -bp <baseline package> -up <updated package> -dp <delta package>\n PackageEditor createDelta -bb <baseline blockmap file> -bn <baseline package full name> -up <updated package> -dp <delta package>\n\r\n update -- Update a baseline package with a delta package.\nUsage: \n PackageEditor update -appendDelta -bp <baseline package> -dp <delta package>\n\r\n updateEncrypted -- Update an encrypted baseline package with an updated package.\nUsage:\n PackageEditor updateEncrypted -appendDelta -bep <baseline package> -dap <delta appended package>\n\r\n updateManifest -- Update the manifest within a package\nUsage:\n PackageEditor updateManifest -p <unencrypted package> -m <updated manifest>\n PackageEditor updateManifest -ep <encrypted package> -m <updated manifest>\n\r\n\r\nExamples:\r\n PackageEditor createDelta -bp <baseline package> -up <updated package> -dp <delta package>\r\n PackageEditor update -appendDelta -bp <baseline package> -dp <delta package>\r\n PackageEditor updateEncrypted -appendDelta -bep <baseline package> -dap <delta appended package>\r\n PackageEditor updateManifest -p <unencrypted package> -m <updated manifest>\r\n\nNote:\r\nFor help with a specific command, provide the -? or -h option, ex.:\r\n PackageEditor.exe createDelta -?\r\n\r\n", "error": "Unrecognized command or argument 'help'\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\PackageEditor.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "pktextract.exe-C8060EF62C1AE4467AFE9E03A4775AAD": { "file_name": "pktextract.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\pktextract.exe", "hash_md5": "C8060EF62C1AE4467AFE9E03A4775AAD", "hash_sha1": "9350CDC4A650FDF6DBC3DB2FB3C720C9840F38D7", "hash_sha256": "DE7E8D40697BEE642D8D5E97276DFA9086E224947C21C37782C7BACD53432FB4", "hash_sha384": "ADBE35D6EB76D209CC53266762941C2CDBE947FDAFEDC07086ED619D6CCD391004FBC9DA43CC61620C507409E29F85DA", "hash_sha512": "5CD01BB5161A6A015C0591112D8913377A9A12B4F4D525F3232B207DCA335379AAE4E95D943FD0A383146ACBD09C7137BD41BDE2F6446874207D242B97FE5D84", "hash_ssdeep": "384:4gzpwOZ9nma81mlSLMc+pWvf/WZjcwGyA5CTlum5g:4gzpjFm34TcF+jcT5C9", "hash_imp": "E8E9B1DA9993D19120D1DDC493FBC127", "hash_pesha1": "AB4ACFAEE6EF83C840BD566B0DAE8C483805D91C", "hash_pe256": "75809C8591B094903AA8261A09100EF562156CE6E082094F6774A40D20884F6B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Side-By-Side Public Key Token Extractor", "meta_original_filename": "pktextract.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Microsoft (R) Side-By-Side Public Key Token Extractor\r\nCopyright (C) Microsoft Corporation. All Rights Reserved\r\n\r\nExtracts public key tokens from certificate files, in a format\r\nusable in Side-By-Side assembly identities.\r\n\r\nUsage:\r\n\r\nC:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\pktextract.exe <filename.cer> [-quiet] [-nologo]\r\n", "error": "Unrecognized parameter --help\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\pktextract.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "pvk2pfx.exe-5E4F866AD2609C77862F6D1504D39180": { "file_name": "pvk2pfx.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\pvk2pfx.exe", "hash_md5": "5E4F866AD2609C77862F6D1504D39180", "hash_sha1": "B3B1962AD521595E14DC40E4EAE43D6E93971713", "hash_sha256": "518A17B39FFE3C205D9FDD68A3A1E27C14177708A85551F58042FA4EC915BA15", "hash_sha384": "DDDAF269B257542A3A892314BAC41C6AC0D1C489866360C5D765257ABDF172B99B76E140CD25C1A6686246C6CF77D7AD", "hash_sha512": "C7B0820205FB73D05BA94191A8F9C82C8CB1B7861CA0CA4F005F966D4401B3CFDDF70B550C83BCEB77588F5A613740F79D33608AD41DDA80F4FCA8437EF78183", "hash_ssdeep": "384:9YWI5dnWO6vbhe0NQQd/hqWKvlH19d9g7riWLkWkKOXciwGynTTzIwS+klTxi:OXJXEe0NQM5BK91/Wr/qKOf8vdO", "hash_imp": "CBED8978BD13D078156B76651A089815", "hash_pesha1": "D386471110F00D262042C375D56E5725CAF9A943", "hash_pe256": "5ECBA5C40960EE367C4A9C30905AC641B8EB1A72008056C759815691C68629EA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PVK/SPC to PFX file converter", "meta_original_filename": "pvk2pfx.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/518a17b39ffe3c205d9fdd68a3a1e27c14177708a85551f58042fa4ec915ba15/detection", "error": "\r\nUsage:\r\n pvk2pfx -pvk <pvk-file> [-pi <pvk-pswd>] -spc <spc-file>\r\n [-pfx <pfx-file> [-po <pfx-pswd>] [-f]]\r\n\r\n -pvk <pvk-file> - input PVK file name.\r\n -spc <spc-file> - input SPC file name.\r\n -pfx <pfx-file> - output PFX file name.\r\n -pi <pvk-pswd> - PVK password.\r\n -po <pfx-pswd> - PFX password; same as -pi if not given.\r\n -f - force overwrite existing PFX file.\r\n\r\n if -pfx option is not given, an export wizard will pop up. in\r\n this case, options -po and -f are ignored.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\pvk2pfx.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "rc.exe-960A2BB300F4F1058ADBD41B223D88FE": { "file_name": "rc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\rc.exe", "hash_md5": "960A2BB300F4F1058ADBD41B223D88FE", "hash_sha1": "47A19B64AE62C15697448D5302462AE75E0EE1EC", "hash_sha256": "CE6079CE8557C4DBE1F611B19919D70BB6FA9317C426801CC4A1E3B72646F532", "hash_sha384": "21EBE1E5ED618D7F56036A3E83B05670B3584191CEBCFDC40EA3741C3D6061CD549FA99BB377457F55AD5487285633E0", "hash_sha512": "57406A22A276DC8796CDB26A9FDF8E73647DBD9341E8625BAD74234CB571E49713E844473C6CD39948392C7BB5E2F5AEC879A0467884C189F30DD8AF37D2758E", "hash_ssdeep": "1536:Gk1QQKuZTIclwZ/dojlSNV36keeSkbMizJa:GaXKoXj4rqijJa", "hash_imp": "16E69F537C702FCF7AAA8D93096C0710", "hash_pesha1": "1697AA5BA4A17261157B186C2AF940B00C32D1C9", "hash_pe256": "8600C7B62E73ECE9DB5B7E4C122399F89E9FB8F792C724E01D77D841452B6B81", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Resource Compiler", "meta_original_filename": "rc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ce6079ce8557c4dbe1f611b19919d70bb6fa9317c426801cc4a1e3b72646f532/detection", "output": "\r\nMicrosoft (R) Windows (R) Resource Compiler Version 10.0.10011.16384\r\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\r\n\r\r\nUsage: rc [options] .RC input file\r\r\nSwitches:\r\r\n /r Emit .RES file (optional)\r\r\n /v Verbose (print progress messages)\r\r\n /d Define a symbol\r\r\n /u Undefine a symbol\r\r\n /fo Rename .RES file\r\r\n /l Specify default language using language identifier\r\r\n /ln Specify default language using language name\r\r\n /i Add a path for INCLUDE searches\r\r\n /x Ignore INCLUDE environment variable\r\r\n /c Define a code page used by NLS conversion\r\r\n /w Warn on Invalid codepage in .rc (default is an error)\r\r\n /y Don't warn if there are duplicate control ID's\r\r\n /n Append null's to all strings in the string tables\r\r\n /fm Localizable resource only dll file name\r\r\n /q RC Configuration file for the resource only DLL\r\r\n /g Specify the ultimate fallback language using language identifier\r\r\n /gn Specify the ultimate fallback language using language name\r\r\n /g1 Specify if version only MUI file can be created\r\r\n /g2 Specify the custom file version for checksum in MUI creation\r\r\n /nologo Suppress startup logo\r\r\n /sl Specify the resource string length limit in percentage\r\r\nFlags may be either upper or lower case\r\r\n\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\rc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "regwinmd.exe-4F0F88904E92558988BDE0BE8FB5EA20": { "file_name": "regwinmd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\regwinmd.exe", "hash_md5": "4F0F88904E92558988BDE0BE8FB5EA20", "hash_sha1": "911789274B7519AC6B420FC3FADF71DF0595957E", "hash_sha256": "06C8D45779AEA761FB66F10EC5D172EF8B9149C9F7087DA565645BA7DAD90E3B", "hash_sha384": "1AAAD1C05EA0C03E2619ACA887F830DA17EC2E406C356C09AC8D82B01E17418F5C52997A7CEF4D43C741336C17A2598D", "hash_sha512": "1CE06252FDC0B9DC0495322E0E3D55C60F78AE61E58784ADBABED5E0009200A57284743A6AB05DD3BB73959219F1F38E99137D079D3E9B2E652E0B88406BDF79", "hash_ssdeep": "3072:/Y+6f2K+KUyN97xuxXr+8s0wisUL8Afl9enyByIb0Cf1ZDKz95JPf7TeBLTYfGW:/Y+6f2dKUyrs+8s0wis68EQBC7DKpjjL", "hash_imp": "26FB363DF5A7B48FAEFF9F7D4ED4609B", "hash_pesha1": "E75A50EC25176BCD8C6099FE7AED504DA36F37E6", "hash_pe256": "FAEC6209E946ECD9AB81AFFCC70DDA6A898FD0FD4359D75D8F59242F5103648B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft REGWINMD Utility", "meta_original_filename": "regwinmd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Microsoft(R) RegWinMD Utility Version 10.0.0.\r\r\n\r\nUsage: C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\regwinmd.exe [-/][Switch][:][Value]\r\n\r\nWhere Switch is one of the following: \r\n -?: Print this help\r\n -h: Print this help\r\n -i: Input filename (or directory) - process this metadata file (or files)\r\n -metadata_dir: Metadata Directory - Directory which contains the system directory for Windows Metadata files\r\n -o: Output file name - put manifest fragment in this file\r\n -osmanifest: Generate a windows component manifest fragment instead of an appx manifest fragment \r\n", "error": "REGWINMD : error RMD5003: Unrecognized command line switch: --help.\r\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\regwinmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "signtool.exe-73197FAEE70ABF0CA034D6E6A4AB62D6": { "file_name": "signtool.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\signtool.exe", "hash_md5": "73197FAEE70ABF0CA034D6E6A4AB62D6", "hash_sha1": "0F75DA0BEAF9FC99DCD62CC71B4B8D9477F9385F", "hash_sha256": "86139DA7E7E99A1DFDE885A36D2052921DA6258CDD5227896E610A040200C4E2", "hash_sha384": "660F3CDD29F54A34DF10C01DB1C97E96A2957B94097ED5530DDDFDA969FB08A6758533CE7F323D300162FB85F5A5F376", "hash_sha512": "B94C89EE5ABD238884CBE502E602E958A0549EA2A79C37C4AAF3445840616F808971BDF3216220701B6C4BD00F5E6307E65F5ECF5264D621C969761BCD68CAC4", "hash_ssdeep": "6144:9Qt6r+yBsp+BtQlZqMVniIpSMA6+l/6KQs2By+5RWjy4NabPeUe0Z0:9Qt6r+wsMBtwgMgLZpaI+jm9gt0", "hash_imp": "2527EB3EFEC0A4ABC6BC7559BA53A56D", "hash_pesha1": "D84BE6B7B0AB830FB99A4CB3FD812F3F4A73CEA6", "hash_pe256": "07D99A0DC61E7BD369AA7C7039F50D7887AF28637150906673AAF291D74D4597", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Authenticode(R) - signing and verifying tool", "meta_original_filename": "SIGNTOOL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/86139da7e7e99a1dfde885a36d2052921da6258cdd5227896e610a040200c4e2/detection", "error": "SignTool Error: Invalid command: --help\r\r\nUsage: signtool <command> [options]\r\n\r\n Valid commands:\r\n sign -- Sign files using an embedded signature.\r\n timestamp -- Timestamp previously-signed files.\r\n verify -- Verify embedded or catalog signatures.\r\n catdb -- Modify a catalog database.\r\n remove -- Remove embedded signature(s) or reduce the size of an\r\n embedded signed file.\r\n\r\nFor help on a specific command, enter \"signtool <command> /?\"\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\signtool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "StoreUploader.exe-1FDD786455589ABC77B9ED957A0E0490": { "file_name": "StoreUploader.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\StoreUploader.exe", "hash_md5": "1FDD786455589ABC77B9ED957A0E0490", "hash_sha1": "590C4FC371399683FE58AB69AFB61444347F0FAF", "hash_sha256": "3D6205A3A7ED3DC6C5BB7B3CE7BCFE579632BFD2694E8E16064123FF06DC61AF", "hash_sha384": "C1707631B687EA0EBC572E282E9A2D9D8268392FCB317ACB32E1D32BB9D1421B2910D2CA8A7ABA5D5C5CB17DFF78C870", "hash_sha512": "678BD66FA7F55AC2B6FD53C79E0406761DD585F1E0DBF9124F1ADA66FA57C7D244DEFC37DFEC08F53FC0DE13B60A064A0EEAFA4CCA66EBA4B42A38C540CF0A82", "hash_ssdeep": "384:CdSyoWQcYcl3h0iAJUkwEADVTc2yOWPUWf:Cg1ml3WKBTYx", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "D1686DCD6F455AB098E3058E042AEAB40CF7CF26", "hash_pe256": "955B2B4A0C00A59C4711F79A9935CBE318A83D895079E4F1E4AF5EB8889BC9D7", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\StoreUploader.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": " ", "meta_original_filename": "StoreUploader.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3d6205a3a7ed3dc6c5bb7b3ce7bcfe579632bfd2694e8e16064123ff06dc61af/detection", "output": "Microsoft (R) StoreUploader Tool\r\nCopyright (C) 2018 Microsoft. All rights reserved.\r\nVersion 10.0.0.0\r\n\r\nStoreUploader is a tool to submit packages to the store efficiently.\n\r\n\r\nUsage: StoreUploader.exe [options]\r\n\r\nOptions:\r\n -h Shown the usage\r\n -version Show the tool's version\r\n -i Runs the tool in interactive mode.\r\n -cd Specifies that the tool should attempt to upload the full package if the delta extraction step fails.\r\n -np Runs the tool in serial mode (no parallelism).\r\n -v Enables verbose output of messages.\r\n -c Path to the config file containing Store parameters and information about the packages to upload.\r\n -td Directory where MakeAppx.exe, ComparePackage.exe, and PackageEditor.exe reside.\r\n -l Directory under which the tool should save the logs.\r\n\r\nExamples:\r\nStoreUploader.exe -c <path to config file> [-i] [-cd] [-np] [-td <sdk tools directory>] [-l <output logs directory>] [-v]\r\nStoreUploader.exe -c C:\\StoreUploader\\UploadJob.config -l C:\\StoreUploaderLogs\r\n\r\n", "error": "Unrecognized command or argument 'help'\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\StoreUploader.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "TB3x.exe-1CC898763E363F5E53FCB95FF6BE8E45": { "file_name": "TB3x.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\TB3x.exe", "hash_md5": "1CC898763E363F5E53FCB95FF6BE8E45", "hash_sha1": "27288845032190602AD693FB0EDC6FCBF377653E", "hash_sha256": "588626321A498869EADEA00180373B38A4FC3A2AD578919B33E995095FC64F91", "hash_sha384": "43A9FB9BA77F7A1152C3DFF23B7D439E5BABC0A6D92AF6CAA382485EB310520EC38C0435FA96F983FE333EA45F04342A", "hash_sha512": "D6DE3CA801CC6394E72AE121BAA082B64A0D6DA8CF73C1DBD6A63DFFBF13EDC9AB00738491F0BBC637A72D31BB9E521119C19A64636F5930E33D0E47E7878E4E", "hash_ssdeep": "3072:wu7qdCHWSQGSxrElBjjlo8X8NFZ2pFCuvmMhHnNnyqewh2/wezGcBBwB7zmG2rF/:L7qdCHkGSk6jak/DT6mXzi18r", "hash_imp": "E7FFAAA1C092B59D66BE61955205F8BD", "hash_pesha1": "E9517E89C6C4ED1AADC587F62746DC372614AF49", "hash_pe256": "BCC001D99272388784489A3525845B1A9B4319C1CB6D4D3741BFC1AC884E9BD8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TAPIBrowser MFC Application", "meta_original_filename": "TAPIBrowser.EXE", "meta_product_name": "TAPIBrowser Application", "meta_file_version": "1, 0, 0, 1", "meta_product_version": "1, 0, 0, 1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 2000", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(RWD) C:\\Windows\\SysWOW64\\tapi3.dll": "File", "(R-D) C:\\Windows\\SysWOW64\\stdole2.tlb": "File", "(RWD) C:\\Windows\\SysWOW64\\quartz.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\TB3x.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "TAPI3xBrowser" }, "topoedit.exe-48CA72F0593A41066205BA140A64EA9F": { "file_name": "topoedit.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\topoedit.exe", "hash_md5": "48CA72F0593A41066205BA140A64EA9F", "hash_sha1": "6D64613652CF68A00CAD91E0C85CCDD97FB531C4", "hash_sha256": "EE21036C25E08685C89CB9ED9D1BF6F79E9979215E1A826E0217B2EF3D15E40A", "hash_sha384": "D8BD658B3E29AAB796319AEC895C80341040D1D2F948B69D8E69CC78C42522CBAA670C3636D8737C6860B027BED2333E", "hash_sha512": "EA6DB434B6397C6135155D283D69398AB38FBB6F8FF394705457A74154F940580D2481E284EA62E61A9BF8BA149EFA4B22DFFF9D7BEAA7D571D1921F719A2B17", "hash_ssdeep": "1536:dx+4randgmnEhkCIG8Wu7yKZEahHZpKr5REFWiHF5A+wnQpLGjCy53BJELyi0Qe:ZSSSWu7yKZnNZkRyU+wn8Gz53BJ5i1e", "hash_imp": "40BFE466BBF7E50AB2AA99CBF6FFC575", "hash_pesha1": "908F9AB7DF94D0B339B7F6B9739E15D777E5F60D", "hash_pe256": "46B1DB961571C88DB11324ACB9EDC484143D45285C904EDA335F2F5BD453045E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Topology Editor", "meta_original_filename": "topoedit.exe", "meta_product_name": "Media Foundation Topology Editor", "meta_company_name": "Microsoft", "meta_file_version": "1.0.0.1", "meta_product_version": "1.0.0.1", "meta_language": "English (United States)", "meta_legal_copyright": "(c) Microsoft. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ee21036c25e08685c89cb9ed9d1bf6f79e9979215e1a826e0217b2ef3d15e40a/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\mferror.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\msxml6r.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netmsg.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\topoedit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "tracefmt.exe-1C6138DA32D8934605648BAEAB531E7F": { "file_name": "tracefmt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\tracefmt.exe", "hash_md5": "1C6138DA32D8934605648BAEAB531E7F", "hash_sha1": "F0590E286F96B5B0896DC046D4B2E3AB28118A3A", "hash_sha256": "879575B33789469A92D9A12301B9014CA3FA3152B9715CBBCFEA1AE2BF6D379D", "hash_sha384": "25911758EE0E813453051C0CF06851B5651681D6E457A53C30723688DA398C0336D77DF0A195B06EB7FA066B941D9ADE", "hash_sha512": "AE668FF2FE6A886E8F45F35D4703342D36A40217C378197D8AA697981B6D5390E17F55CF703B10016CEDCB9292576A48B2C42CC82A261AB288344B95E7A386EB", "hash_ssdeep": "12288:hSU/XE7VRTJEz/ZTWTkn0rBkr9RDrbL7rnD7SCyiSCyiSC+oQ:AU/XE7VRTi/ZTpn0rWRDrbL7rnD7SCyH", "hash_imp": "6EE784C71AEDA59373E4E5FA13E1CAEB", "hash_pesha1": "137D2F1920CB6023BB4D04D6845D85D56388E87B", "hash_pe256": "FB864350E6B517BF7E3D117C2B8828CB3209D92F4A74E8A665BC3C5DFB701000", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Format Message traces to text", "meta_original_filename": "TraceFmt.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nMicrosoft (R) TraceFmt.Exe (10.0.19041.1)\r\n Microsoft Corporation. All rights reserved.\r\n\r\nTracefmt formats the messages in trace logs (.etl files) and creates a text\r\nfile of the formatted trace messages. You can specify a TMF file with the\r\nformatting instructions for WPP events, or you can specify an image file and\r\nTracefmt finds the private PDB file for that image and reads the formatting\r\ninstructions from the PDB file.\r\n\r\nUsage:\r\n\r\ntracefmt [<EtlFiles...>] | -rt [<SessionName>]\r\n\r\nParameters:\r\n\r\n<EtlFiles...> - Format a ETW trace file (.etl). Can specify multiple files\r\n separated by spaces.\r\n-rt <SessionName> - Format messages from the named real-time trace session.\r\n Default session name=\"NT Kernel Logger\".\r\n-tmf <TMFFiles> - Trace message format file. Default=\"Default.tmf\".\r\n-i <ImageFiles> - Finds PDBs for the images and creates TMFs.\r\n Separate images with ';'.\r\n-r <SymbolPath> - Path to private PDB symbol files. Default is\r\n \"%_NT_SYMBOL_PATH%\" (if defined) or\r\n srv*\\\\symbols\\symbols otherwise.\r\n-p <TmfPath> - TMF file directory. Without -i, it's an existing directory.\r\n With -i, it's the path for the TMF that tracefmt creates.\r\n-pdb <PdbPath> - Path to one more more PDB files. Multiple files should be\r\n seperated by ';'.\r\n-manpath <Path> - Path to one or more manifest repository folders. Manifests\r\n will be automatically loaded from these folders as needed.\r\n Multiple folders should be separated by ';'. The files in\r\n the folder must be named GUID.man, using the provider's\r\n decode GUID with no '{', '}', or '-' characters. (Use the\r\n traceman tool to import manifests into the repository.)\r\n-man ManFile - Path to an XML manifest from which to load decoding data\r\n for manifest-based ETW events (TdhLoadManifest).\r\n-bin DllFile - Path to a DLL file from which to load decoding data for\r\n manifest-based ETW events (TdhLoadManifestFromBinary).\r\n-h | /? - Displays help.\r\n\r\nOptions:\r\n\r\n-o - Output file name, e.g. \"FormattedData.txt\".\r\n-csv - Output in CSV format.\r\n-csvheader - Adds columns headings to CSV file.\r\n-hires - High resolution timestamp.\r\n-utc | -gmt - Do not convert UTC timestamps to local time.\r\n (Affects timestamps in event header and event content.)\r\n-timeZoneSuffix - Include a suffix on timestamps with a known time zone.\r\n-sortableTime - Use \"yyyy-mm-ddThh:mm:ss\" format for time stamps.\r\n-noFileTimeUtc - Treat event content FILETIME values as having an unknown\r\n time zone. (Default assumes FILETIME is always UTC.)\r\n-display - Print formatted traces messages to console and output file.\r\n-displayonly - Print formatted traces messages only to console (no output\r\n file).\r\n-nosummary - Suppress summary file.\r\n-summaryonly - Suppress output file.\r\n-noprefix - Omit the trace message prefix.\r\n-ods - Send trace messages to the OutputDebugString.\r\n-trace - Print tracefmt actions to the console as they occur.\r\n-v - Verbose console output.\r\n-cp <codepage> - Generated text files should use the specified encoding.\r\n Valid codepage names include \"utf8\", \"utf16\", \"ansi\".\r\n Default is the current ANSI code page.\r\n-skipNoFormat - Filter out events without format strings.\r\n-skipTmfWpp - Filter out TMF-based WPP events.\r\n-preferJson - When possible, decode events as JSON.\r\n TMF-based WPP will still decode as text.\r\n-jsonMeta <flags> - Control which values to include in the JSON \"meta\" suffix.\r\n Default is 0xff3f. Set to 0 to disable the \"meta\" suffix.\r\n Values will often be omitted from suffix if zero or null.\r\n Flags (in hex): provider=1, event=2, time=4, cpu=8,\r\n pid=10, tid=20, id=40, version=80, channel=100, level=200,\r\n opcode=400, task=800, keywords=1000, tags=2000,\r\n activity=4000, relatedActivity=8000, ktime=10000,\r\n utime=20000, ptime=40000, attribs=80000.\r\n\r\nDefault values:\r\n\r\n <EtlFile> C:\\Logfile.Etl\r\n <SessionName> \"NT Kernel Logger\"\r\n <OutputFile> FmtFile.txt (local directory)\r\n <Summary file> FmtFile.sum (local directory)\r\n <TMFFile> default.tmf (local directory)\r\n <Prefix> \"[%9!d!]%8!04X!.%3!04X!::%4!s! [%1!s!]\"\r\n <SymbolPath> %_NT_SYMBOL_PATH% or srv*\\\\symbols\\symbols\r\n\r\nChange Prefix by setting the TRACE_FORMAT_PREFIX environment variable.\r\n\r\nIf neither -tmf nor -p are specified, tracefmt uses the value of the\r\n%TRACE_FORMAT_SEARCH_PATH% environment variable.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\tracefmt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "tracelog.exe-B67AA5C2AF632B34596BE02FDD274B28": { "file_name": "tracelog.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\tracelog.exe", "hash_md5": "B67AA5C2AF632B34596BE02FDD274B28", "hash_sha1": "99751335A71AE276472232366D69F3893EA29785", "hash_sha256": "5722900ED58968A5A536F04A4BFEC375D381810DC5C03E60F68FAD73726B3180", "hash_sha384": "556B8E4A1AE37BA6B9EF83801AF73B5D9EC326E3292B0375A69F2CCE48955974E149AE9E3FA907E893827B943676D8EA", "hash_sha512": "CC70694E58B112DB4450709AD57CCCDB684292A51A98390122B1EAAE1B05C393E7CCDB8E985877A49B15CBE0167D4611CC2186FAB1FEF72B2025D9AC9B70F39E", "hash_ssdeep": "3072:RoFO3/efPsEWTdVUwcqZanlSxPO5VYxMX/9LL:lefEEMUtSxsvFv", "hash_imp": "EA8A061571DAD052D4FE8984F532674C", "hash_pesha1": "4F278EB4571DF0DC0D024A772BC6861B207CF26D", "hash_pe256": "AE17786F7AC321E0999C6DC50F31AB2E79138D1CACB3C9EAF966BAA54B51B562", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Trace control utility", "meta_original_filename": "tracelog.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "ERROR: no action specified\r\n\r\nMicrosoft (R) tracelog.exe (10.0.19041.1)\r\n Microsoft Corporation. All rights reserved.\r\n\r\nUsage: tracelog [actions] [options] | [-h | -help | -?]\r\n\r\nActions can be specified as \"-action LoggerName\" or \"-action=LoggerName\".\r\n\r\nActions:\r\n\r\n-start <LoggerName> Starts the <LoggerName> trace session.\r\n-stop <LoggerName> Stops the <LoggerName> trace session.\r\n-update <LoggerName> Updates the <LoggerName> trace session.\r\n-enable <LoggerName> Enables providers to the <LoggerName> session.\r\n-enableex <LoggerName> Enables providers to the <LoggerName> session.\r\n-timeout <n> Forces enable to be synchronous (timeout value\r\n specified in milliseconds).\r\n-capturestate <LoggerName> Request provider to log state information to the\r\n <LoggerName> session.\r\n-incrementfile <LoggerName> Increment to the next file for the <LoggerName> trace\r\n session (EVENT_TRACE_FILE_MODE_NEWFILE should be enabled)\r\n-systemrundown <LoggerName> Request SystemTraceProvider to log rundown\r\n information to the <LoggerName> session.\r\n-disable <LoggerName> Disables providers for the <LoggerName> session.\r\n-flush <LoggerName> Flushes the <LoggerName> active buffers.\r\n-addautologger <LoggerName> Creates the registry keys for the <LoggerName>\r\n autologger session. Provide the session GUID using\r\n the -sessionguid parameter.\r\n-remove GlobalLogger Removes the registry keys that activate the\r\n GlobalLogger.\r\n-enumguid Enumerate registered trace guids.\r\n-enumguidex [#<guid>] Enumerate registered trace guids.\r\n-q <LoggerName> [-lp]\r\n Query status of <LoggerName> trace session.\r\n Use -lp to list providers enabled to the session.\r\n-l [-lp] List all trace sessions.\r\n Use -lp to list providers enabled to each session.\r\n-h, -?, -help Display usage information.\r\n\r\nOptions:\r\n\r\n-b <n> Sets buffer size to <n> kilobytes.\r\n-min <n> Sets minimum buffers.\r\n-max <n> Sets maximum buffers.\r\n-f <name> Log to file <name>.\r\n-kb Use kilobytes for log file size.\r\n-append Append to file.\r\n-prealloc Pre-allocate.\r\n-seq <n> Sequential logfile of up to n megabytes.\r\n-cir <n> Circular logfile of n Mbytes.\r\n-newfile <n> Log to a new file after every n megabytes.\r\n File name must contain %d.\r\n-UseSystemTime Use System Time clock.\r\n-UsePerfCounter Use Performance Counter clock.\r\n-UseCPUCycle Use CPU Cycle Count clock.\r\n-ft <n> Set flush timer to n seconds.\r\n-QpcDelta Turn on QPC Delta tracking between Container and Host.\r\n Only supported on Start calls on some OS versions.\r\n-bt <n> Specify that n buffers should be filled before the\r\n system begins flushing them.\r\n-paged Use pageable memory for buffers.\r\n-addtotriagedump Write out buffers for triage memory dumps.\r\n-noprocess Disable Process Start/End tracing.\r\n-nothread Disable Thread Start/End tracing.\r\n-nodisk Disable Disk I/O tracing.\r\n-nonet Disable Network TCP/IP tracing.\r\n-fio Enable file I/O tracing.\r\n-pf Enable page faults tracing.\r\n-hf Enable hard faults tracing.\r\n-img Enable image load tracing.\r\n-cm Enable registry calls tracing.\r\n-um Enable Process Private tracing.\r\n-guid <file> Enable tracing for providers specified in <file>.\r\n The file must be formatted as:\r\n ; comment line\r\n guid1;matchanykeyword;level\r\n guid2;matchanykeyword;level\r\n #<guid> Enable tracing for a provider by guid.\r\n *<name> Enable tracing for a provider by guid from hashed\r\n name.\r\n-rt Enable tracing in real time mode.\r\n-kd Enable tracing in kernel debugger.\r\n-level <n> Enable providers with specified level.\r\n-matchanykw <n> Enable providers with specified MatchAnyKeyword.\r\n-matchallkw <n> Enable providers with specified MatchAllKeyword.\r\n-enableproperty <flags> Enable providers with specified EnableProperty\r\n flags.\r\n-sourceguid #<guid> Pass <guid> to the enabled providers' callbacks\r\n as the SourceId.\r\n-flag <n> Enable Flags passed to the providers.\r\n Note: Flags have been replaced by MatchAnyKeyword.\r\n-eflag <Name+Name+...> Enable kernel events by name.\r\n <n> <eflag...> Enable kernel events using <n> extended flags.\r\n Help Print the list of named kernel events that can be\r\n enabled.\r\n-dpcisr Enable kernel events for DPC/ISR analysis.\r\n-ls Generate Local Sequence Numbers.\r\n-gs Generate Global Squence Numbers.\r\n-heap Use this for Heap Guid.\r\n-critsec Use this for CritSec Guid.\r\n-pids <n> <pid1 pid2 ... > Tracing for Heap and CritSec for <n> processes.\r\n-buffering Enable tracing in buffering mode.\r\n-secure Enable tracing in secure mode.\r\n-sessionguid Autologger session GUID Registry value.\r\n-lowcapacity Don't create buffers per processor.\r\n-stackwalk <Events> Enable stack walking for specified events.\r\n-hybridshutdown [stop|persist]\r\n Control hybrid shutdown logger behavior.\r\n-systemlogger Logger can receive SystemTraceProvider events.\r\n-ProfileSource <src>|Help Configure profiling source to use.\r\n Use Help to see the list of available sources.\r\n-SetProfInt <n> <src> Configure profiling interval for specified\r\n source.\r\n-Pmc <Ctr1,Ctr2,...>:<Name+Name+...>\r\n Configure PMC counter sampling on kernel events.\r\n Use -ProfileSource Help for a list of counters.\r\n Use -eflag Help for a list of kernel events.\r\n-independent Enable independent mode on the trace session.\r\n-ExeFilter <Executable names>\r\n Specify an Executable name filter with names\r\n separated by semi-colon.\r\n-PkgIdFilter <Package Full Name>\r\n Specify Package id filter(s) separated by\r\n semi-colon.\r\n-PkgAppIdFilter <PRAID> Specify Package Relative App Id filter(s)\r\n separated by semi-colon.\r\n-PidFilter <n> <pid1 pid2 ... >\r\n Specify Pid filter with <n> Pids (maximum of 8\r\n allowed).\r\n-EventIdFilter -<in|out> <n> <id1 id2 ...>\r\n Specify an event id filter with <n> event ids\r\n (maximum 64 event ids allowed).\r\n-StackWalkFilter -<in|out> <n> <id1 id2 ...>\r\n Specify an event id filter with <n> event ids\r\n (maximum 64 event ids allowed).\r\n-Lbr <EventName+EventName+...>:<Filter1,Filter2>\r\n Configure LBR tracing on kernel events.\r\n-Ipt <EventName+EventName+...>:<BufferSize=size,CodeMode=mode>\r\n Configure IPT tracing on kernel events.\r\n size is a positive integer <= 32 (default) in the unit\r\n of KB, and will be rounded up to the next power of 2 (minimal 4)\r\n mode can be User (default), Kernel and UserKernel.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\tracelog.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "tracepdb.exe-8CD553E9DB0224C745E84D456B4E21C8": { "file_name": "tracepdb.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\tracepdb.exe", "hash_md5": "8CD553E9DB0224C745E84D456B4E21C8", "hash_sha1": "4A79415CB75C7F160FB735F22D53C92D17918643", "hash_sha256": "BB5C60D1D3BB2351544B08B5D5862BA283CDEACA04946F6AAC74CEBCB896A0AC", "hash_sha384": "8B6F54D290C822C18030337308639B7AF15A5528CA6AB0D9EAA2644ED6284A90E411BFF5923CBCAEE3BBC75FE20E579D", "hash_sha512": "EC8D7E956A5A1F5B8C3F384C87CB219FF83A4095E81DBA8B444FC179714AC0F0923D371656D91A206D62AB6AF25D315AB8956535814743F21DC63ECB68E533BF", "hash_ssdeep": "768:unc1XrwsG4bS+5BE06AArxSz6odxNYr5rvtP:unCrwSWEBd6h+xNYFrp", "hash_imp": "277FD7663C88CA65910CB9EBBB6589D7", "hash_pesha1": "07FFCA4EAACE8F154D6DD0765910EC5B9197993B", "hash_pe256": "420D8E3CD645F46666FDEAFF70D15C5953525DEE1A4CF5530CCB97341DDA69A1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Get Trace Format info from PDB", "meta_original_filename": "TracePDB.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nMicrosoft (R) TracePDB.Exe (10.0.19041.1)\r\n Microsoft Corporation. All rights reserved.\r\n\r\nTracePDB creates TMF files from the specified PDB file. If you specify an image\r\nfile, TracePDB finds the PDB file for the image and then creates a TMF file.\r\n\r\nUsage:\r\n\r\nTracePDB.exe [-f <PDBFiles>] [-s] [-p <TMFDirectory>] [-v] [-c]\r\nTracePDB.exe -i <ImageFiles> [-r <SymbolPaths>] [-p <TMFDirectory>] [-v] [-c]\r\n\r\nParameters:\r\n\r\n-f <PDBFiles> - Source of trace formatting instructions. \r\n Default=<LocalDirectory>\\*.pdb.\r\n Valid wildcards are ? and *.\r\n\r\n-s - Recursive. Creates TMF files for all PDB files\r\n that match -f in all subdirectories of the -f path.\r\n\r\n-p <TMFDirectory> - Output file location (directory only).\r\n Default=Local directory.\r\n Do not specify a file name; the file name is generated\r\n automatically based on the message GUID.\r\n\r\n-i ImageFiles - Image Files for which to find PDBs and creates TMFs.\r\n Valid wildcards are ? and *.\r\n\r\n-r <SymbolPaths> - Path to private PDB symbol files. Default \r\n is %_NT_SYMBOL_PATH% or srv*\\\\symbols\\symbols.\r\n\r\n-o <TmfFile> - Name of single tmf file output.\r\n Will generate a single TMF file\r\n\r\n-c - Generate TMC files.\r\n\r\n-v - Verbose.\r\n\r\nDefault values:\r\n\r\n <PDBFiles> <LocalDirectory>\\*.pdb.\r\n <TMFDirectory> Local directory.\r\n <SymbolPath> %_NT_SYMBOL_PATH% or srv*\\\\symbols\\symbols\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\tracepdb.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "traceview.exe-2A319762C2B8BF0D564032AE6A591925": { "file_name": "traceview.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\traceview.exe", "hash_md5": "2A319762C2B8BF0D564032AE6A591925", "hash_sha1": "397E30B86899E11F811B218CE63033941CE9504F", "hash_sha256": "E0D595B9B46CDC6166F9493918D78FE7643873E3C97B36AC6D3EC4E609B19DB7", "hash_sha384": "FB0B99E82BA64CB3DA28EFC7504F6E4E8F91F7725E4CE49C611EA93EDC1DA6FFA1AD9B01D8A6185D2DB3EAF328CC748E", "hash_sha512": "13FAE3D5680AB53F06620E5FC450D1DFEA4C94BB7F2F04F5C23E1A08B7DEB148245277D60A2B745572515C48A238AB314C0345BEB7A34315CDA6567147F701FD", "hash_ssdeep": "24576:X+L7tged1e9g5YCLVx0wUa7wGok0b+HPmgE+iTaAOWG2CWG2mWG2mWGVF1lZ7bO:Xatged1rM2PmXTaAOWG2CWG2mWG2mWGU", "hash_imp": "D6283301022C5593FE614C3B8F321A03", "hash_pesha1": "5F9D86370A35238F615A1E3A4F71E88D6D89386B", "hash_pe256": "4FDB90B7178C3B79822F9D8044BB5A7DF6A3EF6FDDD0FDBCC23E0B3795C613CB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TraceView Application", "meta_original_filename": "TraceView.exe", "meta_comments": "V2.1.1", "meta_company_name": "Microsoft Corporation", "meta_file_version": "V2.1.1", "meta_product_version": "2, 1, 1, 0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 2002-2005, Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Users\\user\\CONERR$": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\traceview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\traceview.exe" }, "tracewpp.exe-840EE517DAF89B880CE1BBD1E18E482E": { "file_name": "tracewpp.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\tracewpp.exe", "hash_md5": "840EE517DAF89B880CE1BBD1E18E482E", "hash_sha1": "D6B79E8DC463E1D729CE078F9A07E4774601D45E", "hash_sha256": "057B0FE2CE5212830E24993914C83FCF1301A0ADCF3337F40C554AE32DE1497A", "hash_sha384": "FBE8F3FCFF52827A23AB8ADFAFB8BAE3160A3B27414658BCC10CC69477E196A0ABBE3AC91246A3483692BB3D0CB67EDA", "hash_sha512": "7FAF4D75A52BB9477864CF48E7F8B2CDE4AB1E5BACCF29FCDADDBEBA29A90FEE6CCEB1DEBEBC29D3DC1058F32DE81E4F0A66FDE5D2C64F0848F20321CBA45062", "hash_ssdeep": "3072:d9biOOSiyrFefrr0pzgeDfO3lXF8MeIxoBy7mboUMJlb7xauUdYSFvRvYyM3cpsG:d9btOUFj0iTICOe3MJl5UdYUvYL+p", "hash_imp": "81AFA33A54B2CCD15E170BD5A533B768", "hash_pesha1": "B02D75C6F961422F86EEB9FBF48DFE9B6152649A", "hash_pe256": "136723285F252B956DBEC9402083BA1E8669D5F4A8A22DD71EDC092A7BB55F7B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Tracing C/C++ preprocessor", "meta_original_filename": "tracewpp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "tracewpp(0) : error wpp : Unknown cmdline option: --help\r\n\r\nMicrosoft (R) TraceWPP.exe (10.0.19041)\r\n(C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: tracewpp [switches] source-file-names...\r\n\r\nGeneral behavior:\r\n\r\n- Gather configuration settings from the command-line, the WPP_FLAGS\r\n environment variable, the INI file(s), and any files specified via -Scan.\r\n- Parse source code files (C or C++) to find calls to trace functions.\r\n- Generate output files by processing templates using values from the\r\n configuration settings and the source code files.\r\n\r\nThe relationship between source code files, templates, and output files is\r\ncontrolled by the -gen option. If no -gen option is set, a default -gen option\r\nis used. The default -gen option is \"{km-default.tpl}*.tmh\" if the -km switch\r\nhas been set and \"{um-default.tpl}*.tmh\" otherwise. The default -gen option\r\nmeans that one .tmh file will be generated for each source file, and that the\r\n.tmh file will be generated using the \"um-default.tpl\" template (or the\r\n\"km-default.tpl\" template if the -km switch is used).\r\n\r\nInput files that start with a UTF-8 or UTF-16 byte order mark will be parsed\r\nas Unicode. Otherwise, input files will be parsed using the current Windows\r\ncode page (the code page returned by GetACP).\r\n\r\nBy default, output files will be written using the current Windows code page.\r\nThe -cp option can configure tracewpp to generate UTF-8 or UTF-16LE output.\r\nNote that a template can override the output encoding, e.g. the manifest.tpl\r\ntemplate always generates UTF-8 output.\r\n\r\nNote that the output generated by this tool depends on configuration (INI) and\r\ntemplate (TPL) files. The following documentation describes the behavior of\r\nthe tracewpp tool itself (e.g. how a command-line option affects a macro) and\r\nalso describes behavior of the Microsoft-provided configuration files and\r\ntemplates (e.g. how a command-line option will affect the behavior of the\r\nMicrosoft-provided templates). The behavior may be different when this tool is\r\nused with other configuration files or templates.\r\n\r\nRefer to the defaultwpp.ini file for more information about the available\r\nconfiguration options and the settings that are enabled by default.\r\n\r\nGeneral options:\r\n\r\n-man:ManifestFile.man[,HeaderFile.h,Prefix]\r\n\r\n ****************************************************************\r\n PREVIEW: Behavior of the -man option and the associated\r\n configuration options may change in future versions of tracewpp.\r\n ****************************************************************\r\n\r\n Configures tracewpp to use manifest-based WPP instead of the\r\n traditional TMF-based WPP. Options after ManifestFile.man are\r\n optional. If HeaderFile is omitted, it defaults to\r\n \"ManifestFile.h\". If Prefix is omitted, it defaults to\r\n \"EventWrite\". This switch is equivalent to the following WPP\r\n configuration commands:\r\n\r\n MANIFEST_CONFIGURATION(ManifestFile.man[,HeaderFile.h,Prefix]);\r\n SEPARATE_TRACE_GUID_PER_FILE(0);\r\n WPP_FLAGS(gen:{manifest.tpl}ManifestFile.man);\r\n WPP_FLAGS(gen:{provider.tpl}*.tmh);\r\n\r\n For the manifest to be useful, you may need to provide an INI or\r\n scanned header file to specify additional configuration options\r\n such as: MANIFEST_RESOURCES, DEFINE_CONTROL_GUID, and DEFINE_BIT.\r\n\r\n-ctl:GUID Defines the WPP_DEFAULT_CONTROL_GUID macro with the specified\r\n control GUID. This the same as -DWPP_DEFAULT_CONTROL_GUID=GUID\r\n and is an alternative to defining the macro in the source file.\r\n When this macro is defined, the default template will generate a\r\n WPP_CONTROL_GUIDS definition with WPP_DEFINE_BIT entries named\r\n \"Error\", \"Unusual\", and \"Noise\". (Not for use with -man.)\r\n Example: -ctl:195b5884-edd3-400c-bcc8-cceb8c344c04\r\n\r\n-DMacroName Adds \"#define MacroName\" to the output file.\r\n\r\n-DMacroName=Value Adds \"#define MacroName Value\" to the output file.\r\n\r\n-km Defines the WPP_KERNEL_MODE macro. This also changes the default\r\n template. If -km is used, the default template will be\r\n \"km-default.tpl\" instead of \"um-default.tpl\".\r\n\r\n-um Defines the WPP_USER_MODE macro.\r\n\r\n-p:ModuleName Overrides the value of the `CurrentDir` template variable. The\r\n default value of `CurrentDir` is based on the current working\r\n directory when tracewpp is launched. The default templates use\r\n CurrentDir as the event's module name.\r\n\r\nSearch and formatting options:\r\n\r\n-ArgBase:Number\r\n Establishes a numeric base for numbering of format strings, such\r\n as \"%1!d!, %2!s!.\" The default is 1.\r\n\r\n-func:FunctionName(ARG1,ARG2,ARG3,...)\r\n Specifies the name and arguments for a trace function that\r\n tracewpp should process. This is an alternative to specifying the\r\n trace functions in an INI file or a scanned header. Any number of\r\n functions can be defined. The default INI file defines the\r\n following trace functions:\r\n\r\n DoTraceMessage(LEVEL,MSG,...)\r\n DoDebugTrace(TRACELEVEL,MSG,...)\r\n\r\n-LookFor:SpecialSymbol\r\n Directs WPP to search source files for the specified symbol. A\r\n template can determine whether the symbol was found using the\r\n FOUND operator in an IF statement. The default INI settings\r\n direct tracewpp to look for the WPP_INIT_TRACING symbol. If the\r\n WPP_INIT_TRACING symbol is found, the default templates will add\r\n module initialization code to the generated TMH file.\r\n\r\n-NoShrieks Directs WPP to try to parse multi-character type names from\r\n format strings even when no exclamation marks are present.\r\n By default, \"%HRESULT\" will parse as item of type \"H\" followed\r\n by text \"RESULT\". With -NoShrieks, \"%HRESULT\" will parse as an\r\n item of type \"HRESULT\".\r\n\r\nFile options:\r\n\r\n@ResponseFile Specifies the name of an options response file. Tokens in the\r\n file will be treated as if they were specified on the tracewpp\r\n command line, i.e. they can be switches or source file names.\r\n\r\n-IPath1[;Path2]\r\n Specifies the location of configuration and template files. Path1\r\n and Path2 represent the fully qualified path to a directory. If\r\n no paths are specified via -I or -CfgDir, tracewpp uses the\r\n current directory.\r\n\r\n-CfgDir:Path1[;Path2...]\r\n Same as -IPath1;Path2. (Deprecated. Use -I instead of -CfgDir.)\r\n\r\n-DefWpp:Path Specifies an alternate primary configuration file. If -DefWpp is\r\n not specified, tracewpp uses \"defaultwpp.ini\".\r\n\r\n-ext:.ext1[.ext2.ext3...]\r\n Specifies the file types that WPP recognizes as source files. The\r\n default is \".c.cxx.cpp.c++\". The tracewpp tool ignores files with\r\n extensions not on this list. This behavior allows you to provide\r\n an unfiltered list of files to tracewpp, and tracewpp will ignore\r\n files it doesn't recognize such as .mc or .rc files.\r\n\r\n-gen:{TemplateName}*.ext\r\n Specifies that for each source file, tracewpp should read that\r\n file and then invoke the specified template to generate an output\r\n file. The output file will have the same name as the source file,\r\n but will have the given file extension. For example,\r\n -gen:{um-default.tpl}*.tmh means that for each source file,\r\n tracewpp should use the um-default.tpl template to generate a\r\n .tmh file with the definitions needed for that source file.\r\n\r\n-gen:{TemplateName}OutputName\r\n Specifies that tracewpp should process all of the source files as\r\n a group and then invoke the specified template to generate the\r\n specified output file. This can be used to generate one TMH file\r\n per project.\r\n\r\n-ini:File.ini Specifies an additional configuration file. WPP uses this file in\r\n addition to \"defaultwpp.ini\". More than one -ini file may be\r\n specified. If no -ini option is provided, \"localwpp.ini\" will be\r\n used as a configuration file if it exists.\r\n\r\n-oDir:Path Specifies the directory for the output files.\r\n\r\n-cp:Encoding Specifies the text encoding for output files. By default, output\r\n files are generated using the code page returned by the Windows\r\n GetACP() function. Use -cp:UTF-8 or -cp:UTF-16 to generate\r\n output files encoded as UTF-8 (with BOM) or UTF-16LE (with BOM).\r\n Note that a template can override the output encoding, e.g. the\r\n manifest.tpl template always generates UTF-8 output.\r\n\r\n-PreserveExt:.ext1[.ext2.ext3...]\r\n Preserves the specified file name extensions when creating TMH\r\n files. By default, the TMH file for <filename>.<ext> will be\r\n named <filename>.tmh. This can cause conflicts when you have more\r\n than one source file with the same name but different extensions,\r\n e.g. myfile.h and myfile.cpp. By using -PreserveExt:.h, the TMH\r\n files would be named \"myfile.h.tmh\" and \"myfile.tmh\".\r\n\r\n-Scan:File.h Instructs tracewpp to scan the specified file for\r\n \"begin_wpp config\" blocks containing WPP configuration options,\r\n or \"begin_wpp enum\" blocks containing enum definitions. Each\r\n \"begin_wpp\" should be paired with an \"end_wpp\". This is typically\r\n used to scan .h files so that configuration options can be\r\n edited in source code.\r\n\r\n-UnicodeIgnore If this switch is provided, tracewpp will ignore source code\r\n files that start with a UTF-16 byte order mark (i.e. will treat\r\n them as containing no trace function calls). This switch exists\r\n because older versions of tracewpp were unable to parse UTF-16\r\n text. In older versions of tracewpp, this switch simply\r\n suppressed the error message that would have been raised for an\r\n unparseable UTF-16 file. The current version of tracewpp can\r\n parse UTF-8 (with BOM) and UTF-16 (with BOM), but retains this\r\n flag for compatibility with the behavior of older versions.\r\n\r\nOther options:\r\n\r\n-ManifestFormats, -NoManifestFormats\r\n Before Windows 10 19H1, TDH.dll was unable to load manifests\r\n containing complex formatting (i.e. %1!X!). For compatibility,\r\n tracewpp defaults to using only simple formatting in manifests\r\n (i.e. %1!S!). Set -ManifestFormats to enable better formatting\r\n (manifests will only load correctly on Windows 10 19H1 or later).\r\n Set -NoManifestFormats (currently the default) to generate\r\n manifests that use only simple formatting (manifests will be more\r\n compatible with earlier versions of Windows).\r\n\r\n-dll Defines the WPP_DLL macro. This is the same as -DWPP_DLL, and is\r\n an alternative to defining the macro in the source file. In the\r\n default templates, this macro is significant only for user-mode\r\n WPP when WPP_MOF_RESOURCENAME is enabled: if WPP_DLL is set,\r\n WPP_INIT_TRACING uses the AppName parameter as the DLL name to\r\n use when locating MOF resources; without this macro set,\r\n WPP_INIT_TRACING will look in the current process's EXE file to\r\n locate MOF resources. In all other cases, the WPP_DLL macro has\r\n no effect.\r\n\r\n-IgnoreDupTypes Do not raise an error if configuration settings define the same\r\n type more than once. The first definition will be used.\r\n\r\n-v Write additional status information during processing (verbose).\r\n\r\n-q By default, tracewpp returns 0 only on success. Use -q to always\r\n return 0, even if tracewpp encountered an error.\r\n\r\n-NoWppVersion Sets template variable `Compiler.Version` to a static value so\r\n that output files do not change based on the specific version of\r\n the tracewpp tool.\r\n\r\n-NoDateTime Sets template variables `System.Date` and `System.Time` to static\r\n values so that output files do not change based on time.\r\n\r\n-NoEnvironment Disables tracewpp's use of environment variables. If this flag\r\n is set, the WPP_FLAGS environment variable will be ignored. In\r\n addition, any environment variables referenced by templates (e.g.\r\n MAJORCOMP and MINORCOMP) will be treated as unset.\r\n\r\n-PerfReport Prints tracewpp timing information.\r\n\r\n-ArgLimit:n By default, tracewpp allows 32 arguments per trace statement. Use\r\n the -arglimit option to change this limit.\r\n\r\n-Reorder, -NoReorder\r\n By default, tracewpp writes message arguments in the order they\r\n appear in the source code. If -Reorder is set, tracewpp will sort\r\n the arguments based on type priority and then type name. This can\r\n reduce code size by minimizing the number of unique helper\r\n functions required.\r\n\r\n-DoNothing Stop processing arguments and exit immediately.\r\n\r\n-MD5, -NoMD5 By default, tracewpp will generate trace GUIDs by hashing the\r\n message data. This means that the trace GUIDs will not change\r\n unless the message data changes, so you can use the same TMF\r\n files to decode your logs as long as the source files are\r\n unchanged. If -NoMD5 is set, tracewpp will use UuidGen instead,\r\n so it will generate new GUIDs each time it runs.\r\n\r\n-TimeChk Set -TimeChk to exit immediately if all output files already\r\n exist and are newer than all source files. Note that this check\r\n is very simple and might skip regenerating the output files even\r\n if environment variables, INI files, or template files have\r\n changed. In most cases, the default behavior (-NoTimeChk) should\r\n be preferred since the hash check is much more accurate.\r\n\r\n-NoHashChk By default, tracewpp will not overwrite an output file if the\r\n existing file's checksum is the same as the new file's checksum.\r\n This behavior helps optimize a build because tracewpp will not\r\n update the timestamp of an already-up-to-date TMH output file.\r\n Set -NoHashChk to skip this check (always overwrite the output).\r\n Note that this checksum is comprehensive and will regenerate the\r\n output if the new output file is different from the existing file\r\n in any way. In particular, if the template references the Date or\r\n Time macros, or if the -NoMD5 option is used, the new output will\r\n always be different from the old output and the existing output\r\n file will always be overwritten.\r\n Implementation note: tracewpp expects to find \"Checksum='...'\"\r\n at the start of the existing file. The checksum is computed as\r\n the MD5 hash that the output file would have if all instances of\r\n the checksum were removed.\r\n\r\n-Public:Func Marks the named function as public. Public functions will omit\r\n certain metadata from the TMF such as filename and line number.\r\n\r\n-PublicFilter:(Func,Flag)\r\n Marks the named function as conditionally public. The function\r\n will be public if the WPP_PUBLIC_<Flag> macro is defined when the\r\n file is compiled. This is the same as the\r\n PUBLIC_FILTER(Func,Flag) configuration option.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\tracewpp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "uicc.exe-1F40FD10914BB0ED4CAD079B454BE0F6": { "file_name": "uicc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\uicc.exe", "hash_md5": "1F40FD10914BB0ED4CAD079B454BE0F6", "hash_sha1": "FE1CC92FFD09A299C5D3808B73D85F51D33D7EF3", "hash_sha256": "BFA2C4C8156E4F7C8400E8A85AEB868C8D8D6D786A460A54BDA43FD658A1EBB9", "hash_sha384": "AA23709D8F2150119234D48753202C18365A82A912C3166ED278A716E50D87A3857BBCE51BA083995E33438A74282284", "hash_sha512": "EC4E291EBDDE6C3B0DDC198849429715F9DE693EE88618315BCA30C94331625C9603729D8A86E5AB13898FE7E03A9A0482A3DE3C7DEBDD1F824977902CC31322", "hash_ssdeep": "3072:fneYYaS3Hw5xGMEcysJfYmU3mCSZ1B2svEG4klXeeeehrOqm7zPU4:mYYZ3Q50fXsdTKSZb2sGkm/", "hash_imp": "D7FACF6ED354DDC6B15DD1CE30C2B508", "hash_pesha1": "DA7ED666117AE4EE3519F1697645E50B77D98115", "hash_pe256": "36F2090972279D829D12E65283E359661C6B298DD8215754D360E1B468C8CC55", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Ribbon Markup Compiler", "meta_original_filename": "UICC.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "UICC.exe : warning : Ignored unknown command line switch: -help\r\nMicrosoft (R) Ribbon Markup Compiler Version 10.0.19041.1 for x86, Retail Build\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: UICC <ribbonFile> <binaryFile> [options]\r\n\r\n - OPTIONS -\r\n\r\n /header:<headerFile>\r\n Emit header file named <headerFile>. If omitted, a header file will not be\r\n generated.\r\n\r\n /res:<resourceFile>\r\n Emit resource file named <resourceFile>.\r\n\r\n /name:<ribbonName>\r\n Resource name for the ribbon binary. The default is APPLICATION_RIBBON.\r\n\r\n /W{0|1|2}\r\n Specify warning level 0-2. The default is 2.\r\n\r\n - EXAMPLE -\r\n\r\n UICC.exe MyApp.ribbon MyApp.bin /header:MyRibbon.h /res:MyRibbon.rc\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\uicc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "uuidgen.exe-984A2526C95CB9FCD4571AB4415D85D1": { "file_name": "uuidgen.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\uuidgen.exe", "hash_md5": "984A2526C95CB9FCD4571AB4415D85D1", "hash_sha1": "DC4A026953D257A2CC73247BE280B7CAC17E4B42", "hash_sha256": "F0392F6FB2631D361C4375B8FD9B10662E9584E2A5CAF9D093326F859A0FBC21", "hash_sha384": "3063CDC46EA9D2DCD7C949BD02E066715E8FF14E0577B8F93B27153EC9847D08615A4CA21E9192BDD83B69F0F2F11A11", "hash_sha512": "8D62DA2C55ED3C0FFEDA85E6A18BD8674DA9BFEF0943E85754F81CA6A131C4D9B882A029510C3792FFE652F3580363584984F31BE0BBD68111B46E49E6BA61D9", "hash_ssdeep": "384:fzqNHIpTNqcUlvGwWR3uW4UWfcwGyBDFPlD:fzcoppqcUlvKhoOm", "hash_imp": "299D39B9D943EB2028B75348F605FC5D", "hash_pesha1": "3323B4E9EB7961CECC7052BE2E116EC2AD26BB7C", "hash_pe256": "1F06E05801E86BAA033F5A18B2A76A62E492B6141B2A938F67C81DAFABEA74A0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UUID Generator Executable", "meta_original_filename": "uuidgen.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Microsoft UUID Generator v1.01 Copyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nusage: uuidgen [-xisconvh?]\r\n\tx - Generate sequential (V1) UUIDs\r\n\ti - Output UUID in an IDL interface template\r\n\ts - Output UUID as an initialized C struct\r\n\tc - Output UUID in upper case\r\n\to<filename> - redirect output to a file, specified immediately after o\r\n\tn<number> - Number of UUIDs to generate, specified immediately after n\r\n\tv - display version information about uuidgen\r\n\th,? - Display command option summary\r\n", "error": "Invalid Switch Usage: --help\r\n\r\nMicrosoft UUID Generator v1.01 Copyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nusage: uuidgen [-xisconvh?]\r\n\tx - Generate sequential (V1) UUIDs\r\n\ti - Output UUID in an IDL interface template\r\n\ts - Output UUID as an initialized C struct\r\n\tc - Output UUID in upper case\r\n\to<filename> - redirect output to a file, specified immediately after o\r\n\tn<number> - Number of UUIDs to generate, specified immediately after n\r\n\tv - display version information about uuidgen\r\n\th,? - Display command option summary\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\uuidgen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "vsdiagview.exe-97FCA419DE9869C6616AD37B6A6CA283": { "file_name": "vsdiagview.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\vsdiagview.exe", "hash_md5": "97FCA419DE9869C6616AD37B6A6CA283", "hash_sha1": "CE6DC0EF95327322CA790304F5FBAE44EF7B101D", "hash_sha256": "349FF7AD9A3B00FF87307CE39911504D3C1085202144AC39AB73504140DC7431", "hash_sha384": "6EDCC776FAE94E5E1297684C89F003A0D5A39A815911209E26D47DC0841E79E0109B9FED2D28F0F5A8583A4DC17053DF", "hash_sha512": "1CCA14BEA9FF4972E9472C1DB9BACEE2030E2B268DFFB15DC2C1E389CE763183AF161ACFF4D762AD856CAE5CEFA1FB72895EDF81F47F42DBAFF709E2DCA96C78", "hash_ssdeep": "768:uqXzBgzsWieX+a2GnT2GefO2GUlFfDlEJcgG:9Bgzv5ifL", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "1F1FE3EC068F7C36E07242711C6F51DF0A517C8E", "hash_pe256": "C5092E573D73EB62EE4B04DE4EC770EC5814E444ADE3D6D46F52FDCD7F0BB784", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "vsdiagview.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4636": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R--) C:\\Users\\user\\--help": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\vsdiagview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ], "runtime_window_title": "File Format Error" }, "vshadow.exe-1330827FD544610FDE7B51418862A03D": { "file_name": "vshadow.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\vshadow.exe", "hash_md5": "1330827FD544610FDE7B51418862A03D", "hash_sha1": "EA7780FCFE6E723B8ABCAF33CD19AA02631AE1F1", "hash_sha256": "CA6DA10CEBF8FB80BEC9D501EAED55860FB7DAD7E3E4079D7BED8E6523C87142", "hash_sha384": "894BF2E143DB11A0BBE0A248B2421D326E2C7E1528009577525D00D7EFF36F1D64642EEA1D3B49F5E9FC953CD5AF627B", "hash_sha512": "50DC69850D16AF2EBFCB37890E43C3D98FD171F2B4F254005C82A91AA61559C07E11E4C03809F800654DD025A91310398D3573BBF2622F08AC4948E6FA3B06CF", "hash_ssdeep": "3072:z+HBczyRUIRK4MR5vuyvmCSsxPGpeQ++x2OHoDkX6P6K9tnrwdTaJfDRFAyk:z+/BCSC+peQ+Y2OhXK/nsdgfrAy", "hash_imp": "9558560CBFDB419535F9680927A961EB", "hash_pesha1": "0B54713236A46DC9339A9D98D1B731781C68B506", "hash_pe256": "2B66B55DA479649F6BAE40BCED607E3FB6BC772F3958E60E2ACAA09D3BBAEB66", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "VShadow, Volume Shadow Copy Service (VSS) Sample Requestor", "meta_original_filename": "vshadow.exe", "meta_product_name": "VShadow", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nVSHADOW.EXE 3.0 - Volume Shadow Copy sample client.\r\nCopyright (C) 2005 Microsoft Corporation. All rights reserved.\r\n\r\n\r\n\r\nERROR: invalid parameter '--help'\r\n\r\nUsage:\r\n VSHADOW [optional flags] [commands]\r\n\r\nList of optional flags:\r\n -? - Displays the usage screen\r\n -p - Manages persistent shadow copies\r\n -nw - Manages no-writer shadow copies\r\n -nar - Creates shadow copies with no auto-recovery\r\n -tr - Creates TxF-recovered shadow copies\r\n -ad - Creates differential HW shadow copies\r\n -ap - Creates plex HW shadow copies\r\n -scsf - Creates Shadow Copies for Shared Folders (Client Accessible)\r\n -t={file.xml} - Transportable shadow set. Generates also the backup components doc.\r\n -bc={file.xml} - Generates the backup components doc for non-transportable shadow set.\r\n -wi={Writer Name} - Verify that a writer/component is included\r\n -wx={Writer Name} - Exclude a writer/component from set creation or restore\r\n -mask - BreakSnapshotSetEx flag: Mask shadow copy luns from system on break.\r\n -rw - BreakSnapshotSetEx flag: Make shadow copy luns read-write on break.\r\n -forcerevert - BreakSnapshotSetEx flag: Complete operation only if all disk signatures revertable.\r\n -norevert - BreakSnapshotSetEx flag: Do not revert disk signatures.\r\n -revertsig - Revert to the original disk's signature during resync.\r\n -novolcheck - Ignore volume check during resync. Unselected volumes will be overwritten.\r\n -script={file.cmd} - SETVAR script creation\r\n -exec={command} - Custom command executed after shadow creation, import or between break and make-it-write\r\n -wait - Wait before program termination or between shadow set break and make-it-write\r\n -tracing - Runs VSHADOW.EXE with enhanced diagnostics\r\n\r\n\r\nList of commands:\r\n {volume list} - Creates a shadow set on these volumes\r\n -ws - List writer status\r\n -wm - List writer summary metadata\r\n -wm2 - List writer detailed metadata\r\n -wm3 - List writer detailed metadata in raw XML format\r\n -q - List all shadow copies in the system\r\n -qx={SnapSetID} - List all shadow copies in this set\r\n -s={SnapID} - List the shadow copy with the given ID\r\n -da - Deletes all shadow copies in the system\r\n -do={volume} - Deletes the oldest shadow of the specified volume\r\n -dx={SnapSetID} - Deletes all shadow copies in this set\r\n -ds={SnapID} - Deletes this shadow copy\r\n -i={file.xml} - Transportable shadow copy import\r\n -b={SnapSetID} - Break the given shadow set into read-only volumes\r\n -bw={SnapSetID} - Break the shadow set into writable volumes\r\n -bex={SnapSetID} - Break using BreakSnapshotSetEx and flags, see options for available flags\r\n -el={SnapID},dir - Expose the shadow copy as a mount point\r\n -el={SnapID},drive - Expose the shadow copy as a drive letter\r\n -er={SnapID},share - Expose the shadow copy as a network share\r\n -er={SnapID},share,path - Expose a child directory from the shadow copy as a share\r\n -r={file.xml} - Restore based on a previously-generated Backup Components document\r\n -rs={file.xml} - Simulated restore based on a previously-generated Backup Components doc\r\n -revert={SnapID} - Revert a volume to the specified shadow copy\r\n -addresync={SnapID},drive - Resync the given shadow copy to the specified volume\r\n -addresync={SnapID} - Resync the given shadow copy to it's original volume\r\n -resync=bcd.xml - Perform Resync using the specified BCD\r\n\r\n\r\nExamples:\r\n\r\n - Non-persistent shadow copy creation on C: and E:\r\n VSHADOW C: E:\r\n\r\n - Non-persistent shadow copy creation on a CSV named Volume1\r\n VSHADOW C:\\ClusterStorage\\Volume1\r\n\r\n - Persistent shadow copy creation on C: (with no writers)\r\n VSHADOW -p -nw C:\r\n\r\n - Transportable shadow copy creation on X:\r\n VSHADOW -t=file1.xml X:\r\n\r\n - Transportable shadow copy import\r\n VSHADOW -i=file1.xml\r\n\r\n - List all shadow copies in the system:\r\n VSHADOW -q\r\n\r\nPlease see the README.DOC file for more details.\r\n\r\n\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\vshadow.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "vssagent.exe-71619CD0C2AEB53DC5C2F06C2CD3513D": { "file_name": "vssagent.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\vssagent.exe", "hash_md5": "71619CD0C2AEB53DC5C2F06C2CD3513D", "hash_sha1": "3AD30E869C14B722BACF721F2014EE73B19A71B3", "hash_sha256": "523B81599DDF819C5B89BC08C1E73F8ADA702C07A05D97AEB86C9353ECF9DF23", "hash_sha384": "09F3989083447E0B826D6E360244F628245969CBBFABB48B1997385EFC35F2D0016F137BAA25EEEBDEA44332218444CF", "hash_sha512": "05F26D15A6AD7CD096F41951B9DFE70276E6CD077C5283A1E554EA27815FD128C9F11BF938F31319892A9DCC59AC675B932C053C31B7B6E9D85611B306494B4D", "hash_ssdeep": "6144:v/y55MNVM8GLWk4Isi//qbFDKCVweIXsdU/sD5:v/y55eK8GJvqhKKlss9", "hash_imp": "C7DB862FDC42DCDF0D9E319687995651", "hash_pesha1": "74582BF05056BA03B0A5CBCCBDE2899B0370504F", "hash_pe256": "8F54C66C039BFFA66AF57220086C86939A20A084DB1259469B07631EEE34FCD4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "VssAgent, Volume Shadow Copy Service (VSS) support tool", "meta_original_filename": "vssagent.exe", "meta_product_name": "VssAgent", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nVSSAGENT application, version 10.0.19041.1 (WinBuild.160101.0800)\r\n\r\n\r\n--------------- Print supported commands ------------\r\n\r\n\r\nUsage:\r\n * Monitor the given HW provider\r\n VSSAGENT -monitor <provider_id> <xml_file>\r\n\r\n * Monitor the disk/volume PNP messages\r\n VSSAGENT -pnpmonitor <xml_file>\r\n\r\n * Gather diagnose data\r\n VSSAGENT -gather <xml_file>\r\n\r\n * Enable lightweight VSS diagnose mode\r\n VSSAGENT -enablediag\r\n\r\n * Disable lightweight VSS diagnose mode\r\n VSSAGENT -disablediag\r\n\r\n * Stop VSSAGENT\r\n VSSAGENT -stop\r\n\r\n * Cleanup if VSSAGENT abnormally terminates\r\n VSSAGENT -cleanup <provider_id>\r\n\r\n * Make an analysis summary while monitoring\r\n VSSAGENT -makesummary\r\n\r\n * Set parameters for VSS diagnose\r\n VSSAGENT -setparam <param_name> <param_value>\r\n\r\n * List all vss diagnose parameters\r\n VSSAGENT -listparams\r\n\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\vssagent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "vsstrace.exe-8BDDEF365647B8C84651581AA066E2B6": { "file_name": "vsstrace.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\vsstrace.exe", "hash_md5": "8BDDEF365647B8C84651581AA066E2B6", "hash_sha1": "E2438C6046AF6F38C8F5B646996FE4EC9D7EC5CB", "hash_sha256": "72619984FCFE978792AC77A0A4DCA39109B55F2024B82CE672210958FABA5F3E", "hash_sha384": "38BB000B06749FF5473EFD81A2885EF8A9FAC20BB0E6BC7F28EF1AC49461826C19C5DF1E4F0E0096921AF30D9B231285", "hash_sha512": "9B60A2BB76E05D0703C5F305038C0C720721188F25DF7ACFC10A48F9205D0F68282AA0F83EA8F9B2966C57DC582F2A17AE9EBFCE303C9ADBD5801AA5002F6D73", "hash_ssdeep": "768:JhFAMDMnTP2DQjm9uBX3zs8OduA4/b/d:/FAFTnm9uBnzxeuAQb", "hash_imp": "C825F7F8F7A497A89F39CE337ADAF682", "hash_pesha1": "609A6A428192C4C00A0E1EEE8D72FCBC8712B905", "hash_pe256": "B8CDFD007C23668C7EF6D4DE0D3EB8988FB058D0A8C268C20E0D7771FF39BB9F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "vsstrace, Volume Shadow Copy Service (VSS) trace formatting tool", "meta_original_filename": "vsstrace.exe", "meta_product_name": "vsstrace", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nUsage: vsstrace [-help <modules | levels | all>] [-l <level>] [-f <flags>]\r\n [-+<module>] [-+ident] [-+pid <process id>] [-+tid <thread id>]\r\n [-etl <input ETL file>] [-o <output TXT File>]\r\n\r\n -f and -+<module>: both effect which modules will be traced;\r\n the order in which they are specified will effect which modules are masked;\r\n you can mask all (-f 0) and then add specific modules by name (+coord +xml)\r\n\r\n -tid/-pid: by default all process IDs (pid) and thread IDs (tid) are enabled;\r\n asterisk (*) can be used as a wildcard for \"any\" process or thread;\r\n the order in which they are provided will effect which traces are included;\r\n you can mask all (-pid *) and then enable specific ones (+pid 0xe8c)\r\n\r\n -o: provides alternate output stream. If you want to exclude console\r\n output and just write to a file, redirect output to a file using > sign\r\n\r\n\r\n Examples:\r\n vsstrace -f 0 +coord +swprv\r\n vsstrace -f 0x6\r\n vsstrace -GEN\r\n vsstrace -etl vss.etl -o vss.log\r\n vsstrace -f 0xffff -pid * +pid 0xe8c -tid * +tid 0x31a\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\vsstrace.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "vstorcontrol.exe-56574C3E7EF76003431747FEDFFEB2F6": { "file_name": "vstorcontrol.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\vstorcontrol.exe", "hash_md5": "56574C3E7EF76003431747FEDFFEB2F6", "hash_sha1": "58C96E29B39043F90A75C080F236798BCC9E4249", "hash_sha256": "DEB1B70FC3D200E887457096134424555B2B386DE8852E99FEAF009D0C1FC2B3", "hash_sha384": "47AA302E1369E539975EEF8218C3FAA94DDE184E3B87E134FE88668E7DDA37EA4A5161EFBDC119A83A93314956B58624", "hash_sha512": "5CEF18F9E92FE732600B35436EEDF275AA6C4C503A4D75B4CD60439CE3C1BEAA2231F16F0752E3385D9977FF1F879DA956177A5BFCA9EAA0F9EBB0ACE57ED215", "hash_ssdeep": "3072:H+S6DWcrFVjQ5qg4fFPPOJL9MBxRPwoFZ01lgH:Hv/crFZQ5qgfF9MBLwwKU", "hash_imp": "CBC322CE5A171FBF6DCF14D38255B59D", "hash_pesha1": "6132A16F8BEDB6B9B9E93805DD58F8CE608069FA", "hash_pe256": "3370ACFA8F1BAD1FFFF543CC8465E6744E4DFD7A4F5BCA34502A6769D72B2C86", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Virtual Storage Command Line Control Tool", "meta_original_filename": "vstorcontrol.exe", "meta_product_name": "Virtual Storage Command Line Control Tool", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": " Commands:\r\n\t install - Installs the Virtual Storage Driver\r\n\t uninstall - Uninstalls Virtual Storage\r\n\t create - Creates a drive\r\n\t remove - Removes a drive\r\n\t resize - Resizes a disk in the drive\r\n\t query - Displays information about the drive\r\n\t list - Lists all drives created on virtual storage\r\n\t help - Displays detailed help for commands\r\n vstorcontrol help <command> displays detailed help\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\vstorcontrol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "vswriter.exe-9B415F2DE4AE688AEEDC50D91A8E3767": { "file_name": "vswriter.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\vswriter.exe", "hash_md5": "9B415F2DE4AE688AEEDC50D91A8E3767", "hash_sha1": "184FA447626F84EF2A429F2E043B99D1251F7553", "hash_sha256": "42242487DFBC75422B79888E21C53CC980C66174650584E148EF269CA4B62216", "hash_sha384": "C5EB16392C9D615B887B103888C1EF079F309293C862060EDFE94A68AFEBEAE8CA6976B72F882B4B51840AE79290EEEF", "hash_sha512": "89C0A58E8CB487DD3F24756020F7596F0F43AD0276A08A59DABC4E0C60A30359D917C131745AE9D70DF980652152E8DAD6D553F5FE6268F15E16BE90ED607875", "hash_ssdeep": "6144:HMckB7Wt3K/354F4GHJ6vrPzus1bcpK+Hugf/3LsjAX:HMcdXF4oKcpKIuiwjw", "hash_imp": "F769684CA47C350EEA891AD5839DFF5D", "hash_pesha1": "D5C1163B7DF67B5FE56BA7DDB032BADE3F455AC8", "hash_pe256": "8AEA033429D5FB69C9247DFA629628C3190C7E56B3F78F37CF11FDFE9D1498E6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Volume Shadow Copy Service (VSS) Test Writer", "meta_original_filename": "vswriter.exe", "meta_product_name": "Vswriter", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Failed to load configuration file:\r\n Reason: Whitespace is not allowed at this location.\r\r\n\r\n Source Text:\r\n Hull & Domain Shaders Yes\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\vswriter.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WiLogUtl.exe-33355395C57720FFCDAF3503E257E6FA": { "file_name": "WiLogUtl.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\WiLogUtl.exe", "hash_md5": "33355395C57720FFCDAF3503E257E6FA", "hash_sha1": "AEF502A0F0236B3F03642E7B09CFA85535B46382", "hash_sha256": "32AC543AAF725A47ED41D1A34DA32EA75D35F17279A959224E7EB981D3CA3713", "hash_sha384": "7CDA850DAEDA48B638E87FCB77C13678BFAEDD677253B11013A7909D7EA6265BCFD671BFC9C55A41659EBFC39610D4AA", "hash_sha512": "58EFAE5AC31BCF3B349B0641177F455B703BB7E83F7E9A5F98EB7742FBD73490229F0B6085BAF1436F8ECED5A8F1C6F90BC9EDB01DD939AE1EB3EE8F2F68EEA8", "hash_ssdeep": "3072:BdGczu8FvAhrUlf8xepbAt9WadAHVUfn6yLcDFEy13brvkVbFokmdDn:6czu8FvAC2xepbaYFEy56+", "hash_imp": "A01FA69A52F0027A6ECD4D28BF1B8094", "hash_pesha1": "7D83FDECB367B99DAE3774BBF6EE58277A2CC532", "hash_pe256": "EE4AB9B074D9329BF6FA9FD34F58B172A83335A7ACE4CE403ED8788738ADAF44", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Installer Verbose Setup Log Analyzer", "meta_original_filename": "wilogutl.exe", "meta_product_name": "Windows Installer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\WiLogUtl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Installer Verbose Log Analyzer" }, "WinAppDeployCmd.exe-14C06D1D7800B6C28FC3AA8EB56DED99": { "file_name": "WinAppDeployCmd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\WinAppDeployCmd.exe", "hash_md5": "14C06D1D7800B6C28FC3AA8EB56DED99", "hash_sha1": "1442B3002DAF5675D72041A2FB1303DBD9E136EE", "hash_sha256": "F9CE7F1128015060E41C73BD78EBCB07161F069934D98E0D2743C8018CE8C9B8", "hash_sha384": "77EA1CE1A9ECFF8E4BB4D609E5DE20BB2F1F3A94D178FA4E6D4F7BF43C8209CE2DBD04C4932B6E540F20792423740831", "hash_sha512": "4B072E387FA7D615AFFF9857DB55F38A6DBF1BC474CA539ACD3200D8CD37BFE858FC04AB1E831D8FCBE1CD3DA16D0C11ADACDE32BD87A0509974E9ACE4B090AD", "hash_ssdeep": "768:afYY+d53psClc4iggeXM4wseoxRm5+XRuvjggKR1:ot+d5SClc4iggh4wsXxRm5+ovsgq1", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "6F39CDF55A0C3C86619887C3E1102CB851C1970B", "hash_pe256": "FE0B13F5DFB42326DE70306B4FC2A0F8B748D4CBD9492BB8E6B5A87DB6BD2199", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\WinAppDeployCmd.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": " ", "meta_original_filename": "WinAppDeployCmd.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Windows App Deployment Tool\r\nVersion 10.0.0.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUtility for deploying applications to remote Windows devices.\r\n\r\nWinAppDeployCmd [command] [-ip address|-guid address] [-pin pin]\r\n [-option <argument>] ...\r\n\r\nCommands:\r\n\r\nDiscovery:\r\n devices Show the list of available network devices.\r\n WinAppDeployCmd devices [timeoutSecs]\r\n\r\nLoose file applications:\r\n deployfiles Deploy/Copy loose package files.\r\n Required Options: \r\n -file Full path to the appx manifest .xml file for the app to be installed, updated, or\r\n uninstalled.\r\n -remotedeploydir Relative directory path/name to copy files over on remote device;\r\n This will be relative to a well-known, automatically determined remote deployment folder.\r\n Optional:\r\n -deleteextrafiles Causes the tool to delete extra files from \r\n the remote target path if they are not found in the source layout\r\n -pin The paired pin generated as a result of Developer Unlocking \r\n and enabling Device Discovery on the remote device.\r\n -preserveAppData Preserves app data when uninstalling an app.\r\n WinAppDeployCmd deployfiles -file localmanifestpath -remotedeploydir remoterelativepath \r\n -ip TargetIPAddress [-deleteextrafiles]\r\n \r\n registerfiles Register loose package files from local app layout folder.\r\n Required Options:\r\n -remotedeploydir Relative directory path/name specified in the previous corresponding\r\n deployfiles command.\r\n WinAppDeployCmd registerfiles -remotedeploydir RemoteRelativePath -ip TargetIPAddress\r\n \r\nPackaged Appx applications:\r\n install Install a Windows app to the target device.\r\n Required Options: \r\n -file Full path to the .appx or .appx bundle for the app to be installed.\r\n Optional:\r\n -dependency Optional path to appx dependency packages\r\n -requiredContentGroupOnly Only install the required content groups\r\n WinAppDeployCmd install -file appxpath [-dependency dep1 [dep2] [dep3] ...]\r\n \r\n update Update a Windows app installed on the target device.\r\n Required Options: \r\n -file Full path to the .appx or .appx bundle for the app to be updated.\r\n Optional: \r\n -requiredContentGroupOnly Only install the required content groups\r\n WinAppDeployCmd update -file appxpath\r\n \r\nOther application utilities:\r\n list Show the list of app packages installed on the target\r\n device. Handy to retrieve package name assigned when registering loose files\r\n to use in the subsequent uninstall command.\r\n WinAppDeployCmd list \r\n \r\n uninstall Uninstall the specified appx package from the target\r\n device.\r\n Required Options:\r\n -package Name of the appx\r\n Optional:\r\n -preserveAppData Preserves app data when uninstalling an app.\r\n WinAppDeployCmd uninstall -package pkgname [-preserveAppData]\r\n \r\nCommands to help with deploying/registering applications from a remote network share:\r\n addcreds Add network credentials for the target to use when running\r\n an application from a network share.\r\n Required Options:\r\n -credserver hostname of the remote share or server\r\n -credusername username associated with the remote share/server\r\n -credpassword password associated witht the remote share/server credentials\r\n WinAppDeployCmd addcreds -credserver server -credusername username -credpassword password \r\n \r\n getcreds Get network credentials for the target uses when running\r\n an application from a network share.\r\n Required Options:\r\n -credserver hostname of the remote share or server\r\n WinAppDeployCmd getcreds -credserver server\r\n \r\n deletecreds Delete network credentials the target uses when running an\r\n application from a network share.\r\n Required Options:\r\n -credserver hostname of the remote share or server\r\n WinAppDeployCmd deletecreds -credserver server\r\n\r\nOptions: (Details)\r\n -h -help Show this screen.\r\n -ip IP address of the target device\r\n -g -guid Unique identifier of the target device\r\n -d -dependency Optional to specify the dependency path for each of the\r\n package dependencies. If none are specified, by default,\r\n this tool will search for dependencies in the app root and\r\n SDK directories.\r\n -f -file File path for the app package to be installed, updated, or\r\n uninstalled.\r\n -p -package The Package Full Name for the app package to be\r\n uninstalled. You can use the list command to find the\r\n names for packages already installed on the device.\r\n -pin A pin may be required to establish connection with the\r\n target device. You will be prompted to retry with -pin\r\n option if authentication is required.\r\n -credserver The server name of the network credentials for use by the\r\n target.\r\n -credusername The user name of the network credentials for use by the\r\n target.\r\n -credpassword The password of the network credentials for use by the\r\n target.\r\n -connecttimeout The timeout in seconds that should be used for sync Connect() calls to \r\n the remote device.\r\n -remotedeploydir Relative directory path/name to copy files over on remote device; This will be\r\n relative to a well-known, automatically determined remote deployment folder.\r\n -deleteextrafile Switch to indicate whether existing files in the remote directory should be purged to match the source directory\r\n \r\nExamples:\r\n WinAppDeployCmd devices 10\r\n WinAppDeployCmd deployfiles -file c:\\apps\\App1\\AppxManifest.xml -remotedeploydir app1_F5 -ip 192.168.0.1 [-pin userpin]\r\n WinAppDeployCmd registerfiles -remotedeploydir app1_F5 -ip 192.168.0.1\r\n WinAppDeployCmd install -file \"Downloads\\SampleApp.appx\" -ip 192.168.0.1 [-dependency c:\\temp\\dep\\x86\\*.appx]\r\n WinAppDeployCmd update -file \"Downloads\\SampleApp.appx\" -ip 192.168.0.1\r\n WinAppDeployCmd list -ip 192.168.0.1\r\n WinAppDeployCmd uninstall -package Company.SampleApp_1.0.0.1_x64__qwertyuiop -ip 192.168.0.1\r\n WinAppDeployCmd addcreds -credserver myserver -credusername myname -credpassword mypassword -ip 192.168.0.1\r\n WinAppDeployCmd getcreds -credserver myserver -ip 192.168.0.1\r\n WinAppDeployCmd deletecreds -credserver myserver -ip 192.168.0.1\r\n \r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\WinAppDeployCmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "winmdidl.exe-9A73D7703CEE4678349F58CA1C35D567": { "file_name": "winmdidl.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\winmdidl.exe", "hash_md5": "9A73D7703CEE4678349F58CA1C35D567", "hash_sha1": "DA715CBAB340296A098CDA0F9D01F504D3D1F7A1", "hash_sha256": "BBFCBE817696C857810E41172092F46856BA1F41EEFA160E6A47AD10E398BCFE", "hash_sha384": "85212EDDFD1C86D3F0FC117A6B3A9D0D5536AB32FA38871A5CF14329A88FC97C3F2ACD0B387E6B5D2EF3287B6BF61434", "hash_sha512": "66E821344FC7265007064857C1C3D4C80E13F871421FB0B3D0722C6A06621D7B71F0E2BDE22C445C84FB550D244E5EE8817F9FCF104D2F36AA92E00CFA674930", "hash_ssdeep": "3072:qqLcGmLnINI0MOSnpd9ua65vXjni98Ip3TRSouAEufo/xWiEDViVzz9qsRCjrB:4GmTSI0MOSnpd9ua65vXji98gVuAxcxm", "hash_imp": "026E6A515BB093BA954FD08082ECE617", "hash_pesha1": "4CE75870AE35B72963B49FFF79D8137A5F679AAA", "hash_pe256": "9C7A3F42636502FCC9C986FF6E1D768B574AABB2329CFC701CE9E3EC998FC191", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft WinMDIDL Utility", "meta_original_filename": "WinMDIDL.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Microsoft(R) Metadata IDL Generation Utility Version 8.00.0021\r\nerror W1001: Usage: Winmdidl.exe [/nologo] [/supressversioncheck] [/time] [/nosystemdeclares] [/outdir:dir] [/metadata_dir:dir] [/reservedTypes:file] [/emptyNamespaceFile:file] [/banner:file] [/utf8] Winmdfile\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\winmdidl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wsdcodegen.exe-44ED618606A3BFBED6615A66E11A5612": { "file_name": "wsdcodegen.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\wsdcodegen.exe", "hash_md5": "44ED618606A3BFBED6615A66E11A5612", "hash_sha1": "5CB727F64351B3AE7D74D29CD1F8AEFFB4B4278A", "hash_sha256": "B95A1BA10B69B1D125BEC135E468A4E9A92779EDC3EF57961A1CAB08665C8474", "hash_sha384": "0C67821FA8AD7BFBAAE7E1639D793863ADFBC5E4AF4D33366FC131B5A7366B0C96490B35DC25E63ACA6F25E0C232E899", "hash_sha512": "D64D52D651A3ADF0BC4D30849009B785190AB69A06ECCB648EBD2952E7FF67D31539CFDCDFEB5545DE64592D1E4D91D3761B037F571646EF6585E9FC50BE59C9", "hash_ssdeep": "3072:gYr/PHkl/UDAjQFRBMsoy4gfs5xw6R6DgDtBxFmG+v:TPEjjuB8y4bODgD", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "5843EFB3F07526B57A21370903EE8B434F39721E", "hash_pe256": "0294526D20898BC5CF947E2B9DC1FDA002546561894EF0399B43333867F8DCB9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "WsdCodeGen.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "children": "Fondue.exe", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\wsdcodegen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wsddebug_client.exe-4344773107BD871393E1E653FA634542": { "file_name": "wsddebug_client.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\wsddebug_client.exe", "hash_md5": "4344773107BD871393E1E653FA634542", "hash_sha1": "80F2FD6230EC0C8120BBED7A0357BB0D665F3609", "hash_sha256": "BF741610FDE46B60F94B04F539EB057036F5DA1048134E5535A3A1FFEE89C5F9", "hash_sha384": "5B2FCC643AA409B86F8AB27F92ABC4B40CEAE21EC9F76693E160C0C2408C55C9315890C908B402BBC99297EB7E300D33", "hash_sha512": "7A1ABE8A45C16CA5983E5854F6CD6476592EF9BECD971D3F12531CE565E26D90E689239D838D8A0EFABD077257D86A27E52C00637751D438CE093A6A0E567812", "hash_ssdeep": "768:hQtaTLnlw6ys2EUVV7ZicUrBn3+0HbILmxQHlgpAOnhSpblzwtR+MSLV:QaHlw6r2tRicAgmxEg/nhSpleILV", "hash_imp": "7010D89ACB3DB0DE5137F0699803FF46", "hash_pesha1": "8EB907F145F375CB7556C820E1D6035C9EEABA5B", "hash_pe256": "F1FFF6CBFD3544A572479A5E0BA5AAE80A188F13775167721557B4DDAFBD17B6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WSDAPI Debug Client", "meta_original_filename": "WSDDebug_client.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "WSDAPI Debug Client\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\wsddebug_client.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wsddebug_host.exe-650609F8600500D97FE9CE66311D0DD9": { "file_name": "wsddebug_host.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\wsddebug_host.exe", "hash_md5": "650609F8600500D97FE9CE66311D0DD9", "hash_sha1": "277F5922C036D59BD417C56C43888988E5DB524C", "hash_sha256": "819B5EFD0E219C0CD7D33DEF7E5A5C1C01FB15AD2C1D4301263B8BE2BCE43963", "hash_sha384": "4205EAB3ADBB5263D756B584B88E6AC4D6FA7692D984B1A0AF5B191DE08C194738057F8AA524345716D4879063A1433D", "hash_sha512": "BEE14B02ED02952F4E843ACD5470303861B20D79BEDE1B80FC4C678705750FA824E08982378E9E29ECC07E9BF67778F1AA2D26E62919B197AF02A252533E58AD", "hash_ssdeep": "768:PzIOeBbKLay2IY8A0fPynCq+Cz7GVvlfpsexN3zBqBjojwk6dO:ZL2IYF0HOCpyG1ceDz8dooQ", "hash_imp": "AFCC3D55E5005F3BB0229DE46C8DDB3E", "hash_pesha1": "A2F4E777AD96F34BAE879989F72D02E5F1D2F84F", "hash_pe256": "480920E78321BAC19AD75EDB086AF233D8970F3205AB6019E7A45B482A28A4D8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WSDAPI Debug Host", "meta_original_filename": "WSDDebug_host.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "WSDAPI Debug Host\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\wsddebug_host.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wstracedump.exe-F3B9A8E87A622231E02D8E0DD5116D80": { "file_name": "wstracedump.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\wstracedump.exe", "hash_md5": "F3B9A8E87A622231E02D8E0DD5116D80", "hash_sha1": "933D02D74059A45CCFBCAB6EE46D8EE605170720", "hash_sha256": "A75C80FCCE04BB5F4A504E21FE685E85D9CF4F7BF0115E0C804ACC3907C873AB", "hash_sha384": "6503A63B5615B267C99C5D6FA7AA52717EBE08AF84A6E1C4A484A862F7E2EAD0A61BC27A75B41301E88F88863CEBEF2B", "hash_sha512": "66CD24428BE96DC57D4F964C81F752306441227DAFBDFFC99545E1DA35CBF59D3FEC0BF87D9F8C55AC68042B0D231AFDC995BC383DB25FF606FE8017AC6A6676", "hash_ssdeep": "1536:7f+1BFF7K/0KqVWgoT8KPNF7oWFumkCOI36DY6tQi:7in+MUT8mAWFADY6tQi", "hash_imp": "CD874222F46E236D732F163F4C1FA706", "hash_pesha1": "3CE3E3B80CF6418066CFD51FCA7E564A74C910AA", "hash_pe256": "18427EF4AB6F76F53DBB75081488EEA040E492FE4CECAF8C9F178F220D14323F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Web Services API Trace Viewer Tool", "meta_original_filename": "WsTraceDump.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Cannot start WsTraceUtil.exe. Make sure it is in the same directory as WsTraceDump.exe.\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\wstracedump.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wstraceutil.exe-D528C7DC20E6E67B3E940A8E9EEB759C": { "file_name": "wstraceutil.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\wstraceutil.exe", "hash_md5": "D528C7DC20E6E67B3E940A8E9EEB759C", "hash_sha1": "8D3BFBB27EEED59B639253AF03467D2D677CA4C5", "hash_sha256": "59472E068E7846264A66C02BBF074369A480CFE0B9FB4739906FE57232C021E6", "hash_sha384": "9D5F6D4591529A7B4609FAB6F6558ADA928C1D4631F3C5E65C572855F6006413D3D37DD2E44B538FE6B087D88786065F", "hash_sha512": "65A0BCE943AEFF3AEFBB9F4F9A213F6965FFD79655652A14B950BE70FF8D9BCB878CEFF6305663B7BEF5B6FD8EDFCA0B74C774E49EBCB2014B7095247E90A5AF", "hash_ssdeep": "1536:mLDCIWCI2XA2WtvIqVskGUggkUzWFoK9nC93sd21r1QLOFL1dqL67EYlCEHB:UCGEAxwgr4K9nQ3sdU/qL67EYlFB", "hash_imp": "7CB8195185AE4E01AB936993DD32787C", "hash_pesha1": "F0F1E453472E2D22D2B6A964B0E44DD804BDE944", "hash_pe256": "5909DC13548A37829D173831A67A8257D84F679AF39E25BF4448958A9DCB641E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Web Services API Trace Utility Tool", "meta_original_filename": "WsTraceUtil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Connection-specific - Microsoft (R) Windows Web Services API Trace Viewer Tool version 1.0\r\nCopyright (c) Microsoft Corporation 2009.\r\r\nAll rights reserved.\r\r\n\r\r\nUsage : WsTraceUtil.exe \r\n-create [all|verbose|message|info|warning|error] - start trace session with specified verbosity level. The default is info. \r\n-update [all|verbose|message|info|warning|error] - updates trace verbosity level to specified value. The defaul is info. \r\n-on - turns the trace session on. \r\n-off - turns the session off. \r\n-delete - deletes the session. \r\n-session name - specifies session name. If the parameter is not used, session name is WsTrace. \r\n-output [filename] - dumps trace. If filename is provided, the trace are written to the file. Otherwise to the console screen. To stop the tool use Crtl-C. \r\n-convert filename - reads trace (*.etl) file.\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\wstraceutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wsutil.exe-D6D86B6E0BB097235CDD7E64B7C7A72F": { "file_name": "wsutil.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\wsutil.exe", "hash_md5": "D6D86B6E0BB097235CDD7E64B7C7A72F", "hash_sha1": "BA8A9EBF0C9610D044F2766064171017B634E7C4", "hash_sha256": "9084EB5B12A6657C37E0A0C13F346293E35F36BC1639406F8BFDF28032A06280", "hash_sha384": "C426B88A67BA15358E1FA72E9A00FE77C87F2DAD8215EE86AF6E8E03E9BB06AA56595F59A0636BCB64A3B8361886B3A9", "hash_sha512": "072D962642FDE5097F2440F8D50D727CB6A15B0D7E9D9031FCE3DBBC65C0EB0547F47E59E5A90C4FB0A1CBDC1F0F3A19E6534A31B0D08755E5C9298598B9E04B", "hash_ssdeep": "3072:SLX7dISJAlmQwlR0nf2IgiDnK9Cpcztjb2K15Pt7Zy7/LO/YQrGNgtif5KAvT/p7:CCVcLVmhjn+3862QQnGOzvvMHFN", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "554AC0C84EB602BABFD41AD282683231D16257EC", "hash_pe256": "D310F804F5F83595B251FF73BDDEB48C7CB5049D67D0BB6FD7C3989F1737707B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Web Services Tool", "meta_original_filename": "Wsutil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Microsoft (R) Windows Web Services Tool, version 1.0098 \r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nWsutil Compiler Options\r\n\r\nSyntax: wsutil.exe [@resfile] [metadataDocument]* [option]*\r\n\r\n--- RESPONSE FILE ---\r\n@resfile Specify the response file that contains all \r\n the arguments.\r\n\r\n--- metadataDocument ---\r\nfileName Specify input fileName. Metadata document type is \r\n determined according to the file content. \r\n Standard command-line wildcards can be used.\r\n/wsdl:fileName[:url] Specify input file as WSDL file; optional url specify\r\n the location that the metadata was retrieved from.\r\n/xsd:fileName Specify input file as XSD Schema file\r\n/wsp:fileName[:url] Specify input file as policy file; optional url specify\r\n the location that the metadata was retrieved from.\r\n\r\n\r\n--- output options ---\r\n/out:directory Specify output directory for generated file\r\n/noclient Do not generate client stub\r\n/noservice Do not generate service stub\r\n/nopolicy Do not generate policy related metadata\r\n\r\n--- misc options ---\r\n/?, /help Display this message.\r\n/W:{0|1|2|3|4} Specify warning level 0-4 (default = 1)\r\n/fullName Prepend fileName to generated identifiers.\r\n/prefix:name Prepend specified name to generated identifiers.\r\n/nologo Do not generate compiler specific information on \r\n console output\r\n/nostamp Do not generate compiler specific information on \r\n generated file\r\n/nosummary Do not produce summary after processing. When combined\r\n with /nologo, the tool is silent on success.\r\n/string:WS_STRING|WCHAR* Specify the string type. By default WCHAR* \r\n string is used.\r\n/ignoreTrailingContent Specify the trailing content for generated \r\n structures to be ignored during deserialization.\r\n/ignoreUnhandledAttributes Specify the unhandled attributes for generated\r\n structures to be ignored during deserialization.\r\n\r\n\r\n", "error": "error WSUTIL0034 error WSUTIL0014 Failed to open specified input file 'help'. Error Message:\r\nValue cannot be null.\r\nParameter name: format\r\n If you have passed in an url, Wsutil does not support downloading metadata from running services. Please check the documentation for detailed instructions on how to retrieve metadata from running webservices.\r\nwarning WSUTIL0075 Error during compilation. No file was generated.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\wsutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "xpsanalyzer.exe-F08364D89FFC0005FF6C11B1C368541C": { "file_name": "xpsanalyzer.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\xpsanalyzer.exe", "hash_md5": "F08364D89FFC0005FF6C11B1C368541C", "hash_sha1": "9669E5DE4312A498187B54C6721FECC3084659E9", "hash_sha256": "11274342039A04C1C945E77CE4D55151E8FE984FED166B363CBB76AB75428AEB", "hash_sha384": "BFADD188F73A0E1F1B8E5C42B3415965ACBB1E561290789A49110E26DBF19A8F23A398B7194FCD5799DE4DBFCBFCA2FD", "hash_sha512": "7A30AD7FD9038BC592E4CBB2C156BF3ED99B145BF405C57D582F3E988B74A211F00D704E3A680005286B965B0A752CF7C87FA339771E7595E5AAC48DD341F7F1", "hash_ssdeep": "3072:S36TFzLZirIOYzRVeBIvr1B/IELq7yfjW2L0sT3tPsgGi5x3JUn540:S36TFzhXzREBIvZB/Icq70zQnO3J2/", "hash_imp": "4D3D9E3816B934C1C708FDBDB8B3A190", "hash_pesha1": "05B3B9987E6B46E79D46F1B7680FC6B64D499AD8", "hash_pe256": "5FD5492E92AD54EAA6FFBCB937609181C91A8B61D16508D3029ED36B2BA1D06A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "XPS Analysis Tool", "meta_original_filename": "XpsAnalyzer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Error: Either /Directory or /XpsFile is required\r\n\r\nXpsAnalyzer\r\nCopyright (c) 2009 Microsoft Corporation. All rights reserved.\r\n\r\nUsage: XpsAnalyzer /Directory:<directory that contains Xps files>\r\n\r\n /XpsFile:<an Xps file>\r\n /FlushSql:<desired format> Flag to output the analysis report in SQL format\r\n Possible SQL formats are \"SqlServer\",\"MySql\" and \"Oracle\"\r\n\r\nSample Usage:\r\n\r\n XpsAnalyzer /Directory:c:\\test\r\n XpsAnalyzer /XpsFile:c:\\test\\sample.xps\r\n XpsAnalyzer /Directory:c:\\test /FlushSql:SqlServer\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\xpsanalyzer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "xpsconverter.exe-0440AB91F1E98F58A9711BF480191A5E": { "file_name": "xpsconverter.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\xpsconverter.exe", "hash_md5": "0440AB91F1E98F58A9711BF480191A5E", "hash_sha1": "A8DD9436E13809008DE004425AA69A7D00CF76CD", "hash_sha256": "07D7B85E7805E2E1A22B15861C233F2771B763D0E9261AD6A825424F72BAC7A9", "hash_sha384": "42A1E2445FE97451C8EAA75AFEDFAF7FD0B6541126A19490D97D83A21E95CF7C6F29B13FD0AB93D5BA7AE93070BC473C", "hash_sha512": "E575DCFD4F24619EE72F87E9FBA408270C9403C3B26B3A4878F340E04310E6BF767BF8BB7B79FA0134E1E4DA5FEF1921FC30EBEF3BB831EB24AE9B1FA136D662", "hash_ssdeep": "768:bGo1Z4e3p1I2j8yiD9svd8sTzIT8aVa9XWVPjpB+CxEOuFF:bG8bI2j8yiuvdjFaVIXWzu/", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "5E1D1DB515E4FCF48EE1B45F2053DEE2E46A4B31", "hash_pe256": "8BC5BB03228C32D43E135A41C3F88DC3BC0B5AEA583EA81EB8616DE04FB646D1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "XpsConverter.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Invalid conversion option. Expected /OpenXPS or /XPS\r\n\r\nXpsConverter\r\nCopyright (c) 2010 Microsoft Corporation. All rights reserved.\r\n\r\nUsage:\r\n XpsConverter /OpenXPS | /XPS\r\n [/InputFile=<input file name> /OutputFile=<output file name>]\r\n [/InputFolder=<input folder name> /OutputFolder=<output folder name>]\r\n [OptionalSwitches]\r\n\r\n /OpenXPS - convert to OpenXPS format.\r\n /XPS - convert to XPS format.\r\n\r\n [/InputFile=<input file> /OutputFile=<output file>]\r\n - convert a single file.\r\n\r\n [/InputFolder=<input folder> /OutputFolder=<output folder>]\r\n Convert all the files in <input folder> and save them to <output folder>\r\n Files in <input folder> must have .xps or .oxps extensions.\r\n Converting a folder is a recursive operation.\r\n\r\n -logger:<LoggerType>\n\t: The logger to use (File, Console, WTT).\r\n\t the default logger is \"CONSOLE\".\r\n -logfile:<LogFile>\n\t: The log file to write to when using the File logger.\r\n\t the default log file is \"XpsConverter.txt\".\r\n -device:<DeviceString>\n\t: The device string to use with the WTT logger.\r\n\t the default device is \"$LogFile:file=XpsConverter.wtl,WriteMode=append\".\r\n /?\t: Display this help\r\n\r\nSample Usage:\r\n\r\n XpsConverter /OpenXPS /InputFile=Test.xps /OutputFile=Test.oxps\r\n XpsConverter /XPS /InputFolder=c:\\OpenXps /OutputFolder=c:\\MSXPS\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\xpsconverter.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "AccCheckConsole.exe-7FD40FEAFC038D02E510142B20F4AC8F": { "file_name": "AccCheckConsole.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\AccChecker\\AccCheckConsole.exe", "hash_md5": "7FD40FEAFC038D02E510142B20F4AC8F", "hash_sha1": "18F3AE31D33B30A5FC49C048080BEBB2B355159F", "hash_sha256": "B7AEB85CE2B87D3DBB46D6BF86DD304E13C96AE6DB98059BDCD94AFA0EBE2809", "hash_sha384": "9C564E272821E0EC516F374364F0B7FD23136FF26817AF0A62AEF4389721CEB1327D99ED6CED29BF8A2EC79DBCDCE77D", "hash_sha512": "65A3611E05DA5654CD0BC796CF6659E8FD0B8C83D269CA229007FE215FEAE3A7FA4571AC358433B74C486139F9701C247C18F6A4CE764E66E2915CC8636B6B59", "hash_ssdeep": "384:hLwCj6aYZScLeG41oCvYf6kQFTFemhjITi3K+dwJwgMDoVW2VQwWUwGytZalxb7v:7pkC5hnjHK+dwJwHotVQC3v", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "BF97B26844B4D3193BAEA926DD5B99C6D1BF190E", "hash_pe256": "BCCB9991113DAB6DF65C84B4540589E5CEE107369F8CBEEBABE3B6057AE78C7F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "AccCheckConsole.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "[Information] Command line argument\r\n\tText: -help\r\n\r\nThe syntax of this command is:\n\n\tAccCheckConsole [options] (-hwnd <hwnd> | -process <name>) [<dlls>]\n\n\tOptions:\n\t\t-hwnd <hwnd> Validates the given hwnd. Can be hex or dec.\n\t\t-window <title> Validates the window with the title given.\n\t\t-process <name> Validates the main window of the process with that name.\n\t\t-list Lists all the verification routines available.\n\t\t-enable <name> Runs the given routine. Can be specified more than once\n\t\t-disable <name> Runs all but the given routine. Can be specified more than once\n\t\t-log (info|warn|err) The lowest event rating that will be logged.\n\t\t-logfile <file> Outputs the log to file. Can be used multiple times.\n\t\t-suppress <file> Uses the XML file <file> to suppress errors.\n\t\t-quiet No logging to stdout.\n\t\t-help Quick Help.\n\n\tError codes returned from AccCheckConsole when using \"echo %errorlevel%\"\n\t\t0 - No errors and no warnings.\n\t\t1 - Usages statement was requested.\n\t\t2 - Errors and no warnings.\n\t\t3 - Errors and warnings.\n\t\t4 - No errors but Warnings.\n\t\t5 - Invalid command line.\n\nExamples:\n\n1) Run all verifications on a window with a specified name.\n\tAccCheckConsole -window \"Untitled - Notepad\"\n\n2) Run a subset of the verifications against an HWND, specifying a suppression file.\n\tAccCheckConsole -hwnd 0x00382f00 -enable CheckTabbing -enable CheckName -suppress suppress.xml\n\n3) Run all verifications from a new verification DLL.\n\tAccCheckConsole -window \"Untitled - Notepad\" VerificationRoutine1.dll\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\AccChecker\\AccCheckConsole.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "acccheckui.exe-6F76505258D5A526B9E57C762BC9B5C9": { "file_name": "acccheckui.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\AccChecker\\acccheckui.exe", "hash_md5": "6F76505258D5A526B9E57C762BC9B5C9", "hash_sha1": "2DDA90F87959971CC2C53A8F7F074672C1E8D8DC", "hash_sha256": "CB1352EF00F31D64F3A8FD2E0510E75911E8136C5BC2FB8512505B47F7ED3D50", "hash_sha384": "BF1E66B2D5CC019A2F4726D105C08C190FC3C64DE1A0480811F6EA963F5D1DDCF524AA0953AC2C34FF71D598991E6BF5", "hash_sha512": "A92379F3880D9EF5D5869CD7A960EB221D4502003346B8361B3AEC2E3B6DB2AEAD7E4515E36B42510DFA4DE63EA929E02B74D48DD0DFBAE008BC90029AAC8E31", "hash_ssdeep": "3072:uoG0eEey3LrG/HhLyIEWJYetCSZaPh6uEPl4iGo+XzDhPzpi4K/Q5:uo5933UBbEWJYetCqC", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "4396F192B66F3101B105D85B620981EE05C06BAA", "hash_pe256": "337CEDE7832E570973C8F145B27C20B47D38A8BDF894FFA00EA191E9344DB862", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UI Accessibility Checker", "meta_original_filename": "AccCheckUI.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "children": "Fondue.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\AccChecker\\Microsoft.Diagnostics.Tracing.EventSource.dll": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_8752": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_32\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\AccChecker\\AccCheck.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_4299dbb28a92ae3e": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(RW-) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\AccChecker": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\AccChecker\\VerificationRoutines.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\AccChecker\\UIAVerifications.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\AccChecker\\acccheckui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "VisualUIAVerifyNative.exe-D2539765673A5E87B8800AC42F197EAA": { "file_name": "VisualUIAVerifyNative.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\UIAVerify\\VisualUIAVerifyNative.exe", "hash_md5": "D2539765673A5E87B8800AC42F197EAA", "hash_sha1": "6F1C3B0AD5F57643AAB2F39141B1392B841712F3", "hash_sha256": "BC5C3EDE178FF6CBC7D8474DC4FA330B8A334DC29D7128E919077A40FFAD3E75", "hash_sha384": "4437BDC09212D685B275DF23F29C80A26EAAA7DE9BE99A9E73F1B3F41B12D765119CCF280162C35437CACCCC75BBDDB0", "hash_sha512": "AFE1552297BD0B4774EF4F1E011457D23F7034DF9840EC48B363888CE5C08D423645FE4658DD35435C9033B0E306B0AF3B44DCEEC9E6D0E4ECD00F0D1AB6622E", "hash_ssdeep": "6144:1OqyheCdi1s8GbWim3xWmumfOBVODnom8gjJOv3AaNWGIAX4c6UdpDlCu:1LG83Qm4", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "636D7ECCB9E373AB9D98547DE95310C47453C1EE", "hash_pe256": "6B22CE7C87AD1F7AFFBA81E1D53548318DAEB7FEE5985FD917C9F0A14AAE623D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Visual UIA Verify", "meta_original_filename": "VisualUIAVerifyNative.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_7720": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_32\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\UIAVerify\\UIAComWrapper.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\UIAVerify\\WUIATestLibrary.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\SysWOW64": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\UIAVerify\\Interop.UIAutomationClient.dll": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_4299dbb28a92ae3e": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\SysWOW64\\ieframe.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\1e28HWNDInterface:b06d8": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_ie_global_counters": "Section", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\UIAVerify\\WUIALogging.dll": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\UIAutomationCore.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.19041.0\\x86\\UIAVerify\\VisualUIAVerifyNative.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Visual UI Automation Verify : Client Side Provider" }, "adplus.exe-7E75934D86C4E2EBF641395762BFEA01": { "file_name": "adplus.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\adplus.exe", "hash_md5": "7E75934D86C4E2EBF641395762BFEA01", "hash_sha1": "4B36443EC71078E9FE920F6483295C1416E2B985", "hash_sha256": "AE72DE3D3F8F22AA8AF047A83BAF0F2D5BC745FCE882BFEFEC2597CCE9D30D25", "hash_sha384": "2F90D252AE40D51F934DD31E547D93B6EBBD242E4CDC64BF50DF8B02DFA39F98B9D32DB96ED4BE872E5544C540A33A09", "hash_sha512": "F09DB802CA8B59239EA7B3481C0D6AA922BC4AF68C52F46EC7FD4FC639C942BB9682B91AECC7EBAB6B8A4D407EB2F1CCB164F5D9AFD8CB3F020E5AE20092E25B", "hash_ssdeep": "1536:v8Kjkp0ynhPotyboYSQs1ieSs3YCTbqmC2zPCPXNwcZp3CWVq++FUUPPg:Er0yR/EoaX3YCTb42zPCPXNRxwBPg", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "FF1D0E51995C25CCF23D681CB42CBEBD6BABB2F9", "hash_pe256": "CBD1A5D0FFA8FB774F7469A282AEDCABEE369749A7A4D6CE7451BFD31B9DB024", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "Adplus.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Starting ADPlus\r\n********************************************************\r\n* *\r\n* ADPLus Flash V 7.01.007 08/11/2011 *\r\n* *\r\n* For ADPlus documentation see ADPlus.doc *\r\n* New command line options: *\r\n* -pmn <procname> - process monitor *\r\n* waits for a process to start *\r\n* -po <procname> - optional process *\r\n* won't fail if this process isn't running *\r\n* -mss <LocalCachePath> *\r\n* Sets Microsoft's symbol server *\r\n* -r <quantity> <interval in seconds> *\r\n* Runs -hang multiple times *\r\n* *\r\n* ADPlusManager - an additional tool to facilitate *\r\n* the use of ADPlus in distributed environments like *\r\n* computer clusters. *\r\n* Learn about ADPlusManager in ADPlus.doc *\r\n* *\r\n********************************************************\r\n\r\n\r\nADPlus Version 7.01.007 08/11/2011\r\n\r\n====================\r\n| ADPlus Usage |\r\n====================\r\n Command line syntax options\r\n\tADPlus -? or 'ADPlus -help\r\n\t Displays this information.\r\n\r\n\tADPlus -HelpConfig\r\n\t Displays the built-in key-words and the\r\ndefault behavior settings\r\n\r\n\tADPlus <runmode> -o <OutputDirectory> [options]\r\n\tRun Modes:\r\n\t -Crash Runs ADPlus in Crash mode\r\n\t -Hang Runs ADPlus in Hang mode\r\n\r\nSelecting processes to attach\r\n\t-p <PID> Defines a Process ID to be attached\r\n\t-pn <ProcessName> Defines a process name to be attached\r\n\t-po <ProcessName> Defines an optional process name to be attached\r\n\t-pmn <ProcessName> Defines a process name to be monitored\r\n\t\tADPlus will keep monitoring if a process with this name starts\r\n\t\tand attach\r\n\t-sc <spawning command> Defines the application and parameters to be\r\n\t\t started in the debugger\r\n\t\t The -sc switch, if used, must be the last one\r\n\t-iis All iis related processes will be attached\r\n\t\t like inetinfo, dllhost,mtx, etc.\r\n\r\nSymbol Path Options\r\n-y <symbol path> Defines the symbol path to be used\r\n-yp <symbol path to add> Defines an additional symbol path\r\n-mss <local cache> Adds Microsoft Symbol Server to the symbol path\r\n\r\nMemory Dump Options\r\n-FullOnFirst Sets ADPlus to create full dumps on first chance exceptions\r\n-MiniOnSecond Sets ADPlus to create mini dumps on second chance exceptions\r\n-NoDumpOnFirst Sets ADPlus to not create any dumps on first chance exceptions\r\n-NoDumpOnSecond Sets ADPlus to not create any dumps on second chance exceptions\r\n-do Dump Only - changes default behavior to not include additional info, just a dump\r\n\r\nMiscellaneous Options\r\n-c <config file name> Defines a configuration file to be used\r\n-o <output directory> Defines the directory where logs and dumps are\r\n to be placed.\r\n-r <quantity> <interval in seconds> for multiple attachments in hang mode\r\n-dbg <debugger> Allows you to select the debugger to be used\r\n cdb, windbg or ntsd (default is cdb)\r\n-dp Debuggers path\r\n-gs only generates the script file\r\n\r\n-ce <custom exception code> Defines a custom exception to be monitored\r\n -ce 0x80501001\r\n\r\n-bp <breakpoint parameters> Sets a breakpoint\r\n Syntax: -bp address;optional_additional_parameters\r\n -bp MyModule!MyClass::MyMethod\r\n -bp MyModule!MyClass::MyMethod;MiniDump\r\n\r\n-CTCF Creates a full dump on CTL+C, and quits\r\n-CTCFB Creates a full dump on CTL+C, and breaks into the debugger\r\n-CTCV No special action on CTL+C, just breaks in for user interaction\r\n-lcq sets the last script command to Q (quit)\r\n-lcg sets the last script command to G (go)\r\n-lcgn sets the last script command to GN (go not handled)\r\n-lcqd sets the last script command to QD (quit and detach)\r\n-lcv sets the last script command to void (no command; waits for user input)\r\n-q2 sets the return action for second chance exceptions to Q (quit)\r\n-g2 sets the return action for second chance exceptions to GN (go not handled)\r\n\r\n\r\n-quiet No dialog boxes will be displayed (no more required)\r\n-notify <destination> Will send a message to the destination\r\n\r\n\r\nExamples:\r\n ADPlus -hang -iis -o c:\\dumps\r\n Produces memory dumps of IIS and all \r\n MTS/COM+ packages currently running.\r\n\r\n ADPlus -crash -p 1896 -o c:\\dumps -mss c:\\symbols\r\n Attaches the debugger to process with PID 1896\r\n and monitors it for 1st and 2nd chance access violations and uses\r\n Microsoft's public symbol server with c:\\symbols as a local cache\r\n\r\n-------------------------------------------------------------------------------\r\n\r\n HELP and Documentation\r\n\r\n For more detailed information on how to use and config ADPlus please see\r\n the debugger's help file (debugger.chm) under Extra Tools\r\n However, be aware that this is a new version of ADPlus and debugger.chm\r\n may take some time to be updated\r\n Check for ADPlus.doc in the debuggers' folder\r\n-------------------------------------------------------------------------------\r\nCurrent log content\r\n\r\nADPlus Engine Version: 7.01.007 08/11/2011\r\nCommand line arguments used were: \r\n-help \r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\adplus.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "adplusmanager.exe-2AC2D4DD8DECA751E2E2374CF85752E1": { "file_name": "adplusmanager.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\adplusmanager.exe", "hash_md5": "2AC2D4DD8DECA751E2E2374CF85752E1", "hash_sha1": "0F5BC17912BBD957063663C6411119F8DBFF82D9", "hash_sha256": "99DCDCD4BC0A47F376AF6956785236B199A23182876D5B0256251E539B6ECF55", "hash_sha384": "2020025F8E5F06B5B0A73FF27865AD3EDFCEDEB05FCE998AF0D892E677A5A212259BCCD8E7FD23E8C99F81703F22FC18", "hash_sha512": "B1652A4B4A54F6C13C32CA006588FA5E38A6468C5AB820FA337F008231313229336CE5F77BA174E7C97807A4D6AE578FD73F601D1B5B7FAB29D0EB3BB543F13A", "hash_ssdeep": "768:HZsFKlZ8Kc41WjT4TNegAuDk+rGbG/+B+OzUaGNUXh7mCq:RluaWgpRDkPbr+68OXh7U", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "C878A659AD27D0CD4C2AB4EEE7C05BEBE98BCF7E", "hash_pe256": "90765E0C9F550CC5CDA5825751674A3EB6E9B30554F0653FF24375C45A0352B6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "AdplusManager.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "children": "Fondue.exe", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\adplusmanager.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "agestore.exe-E04D7BB216C5BB4A8B0323AE61030558": { "file_name": "agestore.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\agestore.exe", "hash_md5": "E04D7BB216C5BB4A8B0323AE61030558", "hash_sha1": "F8651D8EDDE497E85A919FB5A222B63EE1E75336", "hash_sha256": "3FE485979444FF025B55786D75750198BB9A39D8402AD1B82B17C66094853F87", "hash_sha384": "7E6CB1A4AE44AA7A0996BDBD8FE39BA23BC15CAFE120372E5A7165252079FC09D818274A24FCE4033D68C0F90D168A48", "hash_sha512": "119940D77E15B9C36A4821B4F35A72563BA1941FF7F4D8EE49D7814F6F4FCD4D57606330EF4DFDF7298AC7E792D10DAA532FB2FF4C3CCC2A16CC43541E4B9287", "hash_ssdeep": "384:l5YXR8WW0q0ywe028Suv0ikmXwueWSU6ZWk5Hl44JeRlFL:nYXfe028QqAugHPW", "hash_imp": "F94CE9C4C4ECD85651AEAEF00699B897", "hash_pesha1": "752B07C022FCE493D87FC28725FBE4ACCF897B02", "hash_pe256": "0938129CF504F698B4CB8B52E4F81C578495EF7E47A92A27D3250087D33C149B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft AgeStore", "meta_original_filename": "agestore.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "breakin.exe-3B73FAC114D9A2BA9758A7E36D90CA8E": { "file_name": "breakin.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\breakin.exe", "hash_md5": "3B73FAC114D9A2BA9758A7E36D90CA8E", "hash_sha1": "6CEB1DB5AC552034C94BB369F7E29C6D38D21023", "hash_sha256": "93256E6D43C5BCFE332F31B571EC044B3B3553F894747E9F77B987D0767FBC90", "hash_sha384": "07DE4647A4E4523EBB80EDB566C34101A91A204E2E62B87387CC85F6C773AFECFAAF7CEA04CECF27531C06913A67D0E3", "hash_sha512": "07653AA41BC09F8D23E8C6099CFAC798E3C757207DEFAE1EE35E19A207943CA8B83E4BBFC60CADA7F4AD9E642E19116317C900BA9DFCABB52381E8357A43ADA5", "hash_ssdeep": "384:SDIXAFE2QO/ZPpxIw0GWYGNWWGJ6olz8I:SkXMEe/xnIw0f2L", "hash_imp": "03667462961B049BAEBEF0B9C8B0F94A", "hash_pesha1": "A27D8FB29A43E0097FD7CC3E24A571F54C77E497", "hash_pe256": "65149C550B4B9DEE81AA74C694CCD20CE0D9837630F06EDFB000AFE9BC8F7864", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Breakpoint forcer", "meta_original_filename": "breakin.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "cdb.exe-5017F8EFBE98513AEB75EAC57C1EA351": { "file_name": "cdb.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\cdb.exe", "hash_md5": "5017F8EFBE98513AEB75EAC57C1EA351", "hash_sha1": "78E71D72E6DDE526B5BAA6C848559C2BADF7F471", "hash_sha256": "264BBA62780E62AF8A1245FD2345AAE5CFBFFEDDDA68E84F5561E3192473A821", "hash_sha384": "FC4762846469ACD0E9EA430B364083E16965845777D461A338FC01FEA4FA5365132477A12FBC1D209E4BAB3F2C7159A6", "hash_sha512": "129A8B2C9F042D9195B2217F11015047448183AA1612DE911DFFD9EE4831A44C7300BCFEAD8EB72B13CEBDAD4AAC01A41DDB3F87982FD7B28A0B63D10B577A71", "hash_ssdeep": "3072:Cmmyc+k5FnbMomoWATuaT0zByCZSUj/VPp59RdJg:lcQ9ZSgp59rJg", "hash_imp": "01717BB155F546CAE097D15EB7D5763C", "hash_pesha1": "9087739A71D8BC6E8635BCA5DAAEAE3E258C5079", "hash_pe256": "B60FE185A81F01D1AD26E190B7BE7074132D64F1E2A17E756F3C9C36818DEAE6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbolic Debugger for Windows", "meta_original_filename": "CDB.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "convertstore.exe-479E52822B84BCC4A67BA8E360F24782": { "file_name": "convertstore.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\convertstore.exe", "hash_md5": "479E52822B84BCC4A67BA8E360F24782", "hash_sha1": "41BCBEB32BC87779F3F71736E182F731705046AC", "hash_sha256": "E7CB8BEBBD009C3E5413C225D1796DABE9BBD1FFE0AB4476C5CDE60657CE4D26", "hash_sha384": "F517649F085E043D3CBA065FE68E940C5D35F936D1B652A3FF49504D6505941350809D46D5C90D4A7C8E969A879F6C1B", "hash_sha512": "26C54A7DF44AFD32857831CD715CD93C50A641D143C141BD0D3FE45A111ED83E8C23026FFB7D3B6610045CA3AEE625D4F22093916B4D6EC0C0C77F4ADDD591E1", "hash_ssdeep": "384:pesZXx776fd/ghH5poakb/f8RuhVPiae8Z7yFWA9WjvtilNH:pesZX4W5yPbgSxiaTmZw1Y", "hash_imp": "F25003FA1F2FCF963A0F33D88748D0F9", "hash_pesha1": "6EA3D859C85FB8245C6D43067A6FF8EF25A7BD2E", "hash_pe256": "A31992AFC84B723E124B50A9FF52C99BA4E6AB064FF69AFAEB768CD4CD1C1B77", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbol Store Conversion Utility", "meta_original_filename": "ConvertStore.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dbengprx.exe-19635FE581E85E6D5A006C2B96C0AA83": { "file_name": "dbengprx.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\dbengprx.exe", "hash_md5": "19635FE581E85E6D5A006C2B96C0AA83", "hash_sha1": "CEDC22175F397902E48BCAD813F55F56CA46A526", "hash_sha256": "F151EF9CA24C44BA9A666E5D626CFCA5051FD594296DFD622FFFA93C9C366411", "hash_sha384": "A0DCC71847AA3DD0E6DE15CBC1C22226B149ADD303F2C20A22B26999566C3B3C9312ABD7945CB14941FCC40C7EFA664F", "hash_sha512": "586A135443E62075728D3608BFEBB82F1E797F4EA3790CEE98F86A89C646D99E0B7BA24B39B228CDCC438CDBBDFCC98D803F7A9D7ED83B2AB4BFD3DD11D85F96", "hash_ssdeep": "1536:+xbOmoWWTuaTSMeDU1POIGYtlzguJnx52f85oCWlzsVDDbovi/itAfxY1tY2h6a:+gmoWWTuaTLeY0Y/5rg3FWfy1y2h6a", "hash_imp": "9CA5D11706BACB79EAECF3E23D2A86F4", "hash_pesha1": "CA8FF3C0F648E73AFCA46FF0C80F637B1BF8C45E", "hash_pe256": "05F6604DDC17DC8FEB06E415910FB7ECDD18D0E5AD2D01F060DFC2FDB4085508", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Debugger Transport Proxy Server", "meta_original_filename": "dbengprx.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dbgrpc.exe-0983936E7B7F9A045001D535988D60A1": { "file_name": "dbgrpc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\dbgrpc.exe", "hash_md5": "0983936E7B7F9A045001D535988D60A1", "hash_sha1": "5CC4EB491A931117A22ECAC2D29D3A05B1B148A9", "hash_sha256": "4AF7C3622D41916344C42A776BE46AE8AE424795DE4BD9D6576067F2D1CF5176", "hash_sha384": "AB226BB5FDB4AAA874A3F9E0B25B8370936F06F97ABF495ABF31008F366B57F5C8DAC7390D4C749F0BD9A428FBFD7DFB", "hash_sha512": "463FFABFC22BBB64C53B56FD8010E1B4DDFD29BEAD08E857BA0DB2FF9D462A1472A706611D97B99BB88BD75B08711C9F4620150ADEFC2387392A0FD395A2FD7F", "hash_ssdeep": "384:yCGUKPIXzQPLpn9tIqL3N/yDokgkv+AZRqQIt6IQCWIdWMztfsl9ng:PrKQXsD9IQ17kgkrRqQ35sZj", "hash_imp": "E706FE44F536F4EB0C897D1DC3E739B3", "hash_pesha1": "C9D468C04469C7C16B4E964762F4589C231ED8FE", "hash_pe256": "90D24CC0F794FD22BE4DFF97DAB1FACCCC682279F389DADA8426143189BB5762", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RPC Extended Debugging Utility", "meta_original_filename": "RpcDbg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dbgsrv.exe-5343914AF3737258C825B5F3BBD943A3": { "file_name": "dbgsrv.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\dbgsrv.exe", "hash_md5": "5343914AF3737258C825B5F3BBD943A3", "hash_sha1": "5449C6F66A8AAA9E81EDB82155D1417611603571", "hash_sha256": "F90B52C72D64100D2112B88EC0AE74516624C374C32A8F9FB1EAF92EDA593C16", "hash_sha384": "8FB34C8DF3555F80416A377CE9C2FB85E06EE67444AF080AE08EBC00D3C29032AE0B2DA31F292DD4A9BBC4643CBB8FE2", "hash_sha512": "005D3997A3E36D5282243DD6E46CE78D4237E477974E0B4D0CB07ABF3F5B3318DDA9039C859BB0002594D6953A0E8B5A4BAF31B5201E08727FA4BE40394A1FF6", "hash_ssdeep": "768:/moW4gP2TuasXSusFy8GcjCbOW7n8B+R9IsbkO5zUDV:/moWATua77Fy8RjaOKM+PkOxUDV", "hash_imp": "785E1D29F0FDDA0B35F0F9B271E30393", "hash_pesha1": "70EA635FBDFBB8D089D42A2E6083E14CC4AC9627", "hash_pe256": "9D0E13020F38BF5C8A7AADBC64C2CFBBE0B995EFA47EFA4A891B34B5700C3644", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft User-Mode Debugger Process Server", "meta_original_filename": "dbgsrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dbh.exe-4AEEF0F666168340E15B252ECA837FD7": { "file_name": "dbh.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\dbh.exe", "hash_md5": "4AEEF0F666168340E15B252ECA837FD7", "hash_sha1": "6AAB25C97805211AB49D5586B18C9820496F19A0", "hash_sha256": "648158A4A04233B7B5B913024848354C13251159EB04651A01CAE23DBE0B6BAC", "hash_sha384": "75890DA52B7FF7A6F4522A214B8B69753F8E05C8EA9F38B1478E8377150B95298C37527756AB19C643F9916B4EAABFD4", "hash_sha512": "893AD207F0EFC31C8542F65740D9302F33A50776989F9D8C55377BFDBDAB8BDD633AB1A5F7BB72C221C611A3F12E2B54225309B9E7362A5731784098CE33B783", "hash_ssdeep": "3072:al+G3awLETEZX+b1l9iFLpzGfbcbeN42Fgl/3sV:afuJl9ihpVbz2kf+", "hash_imp": "AAC70AB87C053524EBA4E6FA3D11CE75", "hash_pesha1": "A21A9CE166A34CF0BED20B4F0112789FAD9FE720", "hash_pe256": "B58FB265AA407A10646FD6A1867B833D4F2E8D28E5E3946FD57048BDCC013FAC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Dbghelp API Example", "meta_original_filename": "dbh.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dumpchk.exe-0A89D9498D40E9E342061A3ECAA9C9D4": { "file_name": "dumpchk.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\dumpchk.exe", "hash_md5": "0A89D9498D40E9E342061A3ECAA9C9D4", "hash_sha1": "3C0A74A0B35B5199FDA4790C2F06EF7E88069B28", "hash_sha256": "41A308AA33C55A8A8492BE3B09938BA60DDE5983D9BA2FC57FD0D9B84BB8A510", "hash_sha384": "106FA237BB6F09BC59170C9DD4E7830D2001613631E24AB84D1751BFAB1A850CD513E032299333A56FC0E771ED5B8CE0", "hash_sha512": "BD3036AB040F0124C008272163C8AB85A7D6942030A575DF08FF0CA9E5929F8006C7A994A7D6E73D6A9E4317F099A91E0A9EF9EEAF72FEBB62306DC6A6C1B2F5", "hash_ssdeep": "192:eDO1XJXmbJQEpo7iE9EIKKHC4kfZVRE0lGWfxWeaW8bpVWQ4WWIwFAOT2XNfqnal:eDOh66t7E27qZXGWfxWecrwFk9flx6E", "hash_imp": "28A2F281EC52EC36C7E9ADC65B3D96BC", "hash_pesha1": "CA0AAE89BEAC0CB1A566CB1FF5F20E951E312DA3", "hash_pe256": "ECF0CD87C601D822C4EBBCA2FAE1807024D4231FACEA00977F2D77B2B858CEE7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Dump File Verifier", "meta_original_filename": "dumpchk.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dumpexam.exe-344C449999D8D2F6A9CA38A6ACB24645": { "file_name": "dumpexam.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\dumpexam.exe", "hash_md5": "344C449999D8D2F6A9CA38A6ACB24645", "hash_sha1": "5396652D131D645C1C03212284E5BF97197CBBAF", "hash_sha256": "05A984386C04DEE06872C06908A8DF2215A31F0E366BDD1065B038A3F07D78D4", "hash_sha384": "95996F6DA627C0D6CBF9A478C813F61403155B4D9824C9D95511B72ED30AF0D0A02BABC02CB0DEDC4A4177AEBD5CCA56", "hash_sha512": "A6824613151F4FD80AEB0C61F0C319F86FCE00D9128A6479291BA7EE26E20975F5422372AAB8918B01F5ACB497B5E31792C4C83BA59665EFA825D952524DB3C8", "hash_ssdeep": "192:SJuJbopEyEkaDDtvVR5Rk8OWH4WBW8bpVWQ4eWAFCNxXeRqnajRqv5:SI2fEjhM8OWH4WjVF4JeRlFe", "hash_imp": "482E9E8B74141A2A2BC1B549F8E6E480", "hash_pesha1": "8580BFD3003FDFA6FAB40A8E922576BC4DCE9F0E", "hash_pe256": "1BD45D158C22F2EE22833AF91F3323ABFCC0DAE5AA065B6A30B4593660578B91", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Dump File Examiner", "meta_original_filename": "dumpexam.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "gflags.exe-256EEDC52F3FFF7020F3286D5BA635A8": { "file_name": "gflags.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\gflags.exe", "hash_md5": "256EEDC52F3FFF7020F3286D5BA635A8", "hash_sha1": "B04D9E1E6F458E9EAC955FCFEB2A2C0123A5DF5D", "hash_sha256": "451E75D8FA831240B208001D3E23B1DC26AB9152A24701604E289CE0A444E956", "hash_sha384": "74D117B3ED948AD7482C5B8E0E461E92F49FA64712B28492ACACE95644566B95F02648F326E5B7F2CC98D9350A5B1B53", "hash_sha512": "67BBB865AFEC13E4F3A881ED3CAFDBCD544CCA5AC66AF95BB6798A377770D8C359ED40965FA66E50608BFDF8F0949865EABA52DC49883C8B7B13BEF6A6ADFB4F", "hash_ssdeep": "768:EKg0lUMWZi2meQwBPXoyPegU6x6ODSKL5b8p6zVTgs0qgWCmuVTvZ:EM+QehA764qdt8m90qDC3VTvZ", "hash_imp": "7E0A5BBAA33183B687A994F22C63644E", "hash_pesha1": "1CC12A9F59C5170483C4B4FACECCFB852FB8FA4D", "hash_pe256": "A61C03B2CC42684A707D4FD09283B3500C52BF0A5406BFEBEE554F5BF25A9A14", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft NT Global Flags Manipulator", "meta_original_filename": "GFLAGS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/451e75d8fa831240b208001d3e23b1dc26ab9152a24701604e289ce0a444e956/detection" }, "kd.exe-F6B9E69A6C0563D9338B4B73EBAAC34C": { "file_name": "kd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\kd.exe", "hash_md5": "F6B9E69A6C0563D9338B4B73EBAAC34C", "hash_sha1": "B5945BEDF6668DF73397745D150C828A928FEDB5", "hash_sha256": "23150CEB2FF1CA823095F297ACA32BC1B1EA3993E030C8CF0B48DA92094C7113", "hash_sha384": "493E1F93A1F71722169000A7C9192B94959069A256260BF2084120355345E69EFBAA0B07B32BBC8FB9CE195429B97836", "hash_sha512": "1B9C93FCFB38D4D165B367395BD0AD11D196F8A30D7CF40CAAD2F2F177EC0E15FEE84173A04038F97FADE7D00D7198CCF38A03AEB15F18173B1407736D97D70C", "hash_ssdeep": "3072:JQ+DfFnbMwmoWATuajAmobD8TiD7y3WKHp55AOxo3GIBNJ:JQpmCD7sHp5SOu3LZ", "hash_imp": "B4EBCFC93EB23586062A42954008DC26", "hash_pesha1": "093C91F0654D5FD16DEF24393BBB7EE2D322D98E", "hash_pe256": "D5F18391480115627BCBA65A94E4DE6257A1DD90CEE7CD3081DA16FC3FCA1F9F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Kernel Debugger", "meta_original_filename": "kd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "kdbgctrl.exe-8B7FABEC2F39E2B008AF214729E02B03": { "file_name": "kdbgctrl.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\kdbgctrl.exe", "hash_md5": "8B7FABEC2F39E2B008AF214729E02B03", "hash_sha1": "C2798EB0C3EDC165BC8851EE1DA9D28C876EBBFC", "hash_sha256": "BBC4CDDE93875BA3E498A82D1A915D2AC4D6FBE5AA6F18D2877D64B01DBA191D", "hash_sha384": "92C9C6D60EC650D4EA26E6C9AE9EB78BEE9460642A21AC20453C6EFC4BC0A76D71D284C373A5AC1EFAC816E68524BD22", "hash_sha512": "2804766DF40702EF4E5C077062D456E05B57C870ECAC5F9F4B2283303708C0574EEB48759DF38E299468DF6B3E8789CFA28B7B9C5FF43CC62B284E4CF9599E57", "hash_ssdeep": "768:QAmoWOgP2TuaPXlQjluE0CaW68y/e9+i5dBoK5WAW1p:dmoWWTuaNQjlR+v8y/e9j5WD1p", "hash_imp": "64C74A80E1427DB7DA03CBA46A74CF13", "hash_pesha1": "E339EDCA5DB52E6E2A3917E247BEC2D98E910326", "hash_pe256": "DCC3DEBAFE87D03596CA308EEC3FBD50C26C3D0A6E28E9DDADC6E97D7B62435F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows kernel debugger configuration utility", "meta_original_filename": "kdbgctrl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "kdnet.exe-F9E59E981819F1F0418B143C19B1AC42": { "file_name": "kdnet.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\kdnet.exe", "hash_md5": "F9E59E981819F1F0418B143C19B1AC42", "hash_sha1": "A094B989ECC02E563ED0D0DBFF11A5085C4BCEEE", "hash_sha256": "A4801D4D945662B5596AB88042EE8DF0D5AE5F0F7F600592D3D1E932C53B1AF0", "hash_sha384": "E1C523E67931A8C246F91FD0BC26D7979C1B389EC5F743A12B57FC60A249369CD997AD9A2F8CB393CC0FC340E13F6DA3", "hash_sha512": "A9E2A6A518C68EBBED388F5009A59882FEB545A032CB2EDD9CC02898F3232485AEFC60EDF89CA90562B44A1E3A73456DA15B78524F998530B324C17992F3BF4E", "hash_ssdeep": "768:Rqh5ZfIKJRYDXILrs5uyR7IG6u7ggg4ocQWp4vj+3Flihkr:RsZ3YgyJR7I3uggg4oMSvj+3FlqM", "hash_imp": "68A47D2835A07A212D86316C9D61B341", "hash_pesha1": "C1C8D6C46DADCB33782CD7DAFA4258F2EAEE32C8", "hash_pe256": "FA37DA7D61AEB6B6F3426CDD5917CE2E0D7268753F984CB3A9C6D89CFEC00239", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Net debugging configuration tool", "meta_original_filename": "kdnet.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "kdsrv.exe-F3DE7A8CF47EA326CA0FDB114288A42F": { "file_name": "kdsrv.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\kdsrv.exe", "hash_md5": "F3DE7A8CF47EA326CA0FDB114288A42F", "hash_sha1": "F8739128F150B05C7B15007C253021E1F9DAA16A", "hash_sha256": "D6F534CAED9032CAB3E000A65C276039AFE096575FB166BBB657999A8A06BB23", "hash_sha384": "9BF04A7CB351D81A3534D64AF4875D6F147A915F9C50A74970380041274D4880E68D13803A4CF02B3E3CE303B890DF39", "hash_sha512": "17863B1D4412946E03C868776C370028C15CEBA8890E53D6FE199D9DE5CEE30489460D1FAD7989B7963F821794DE4CC8907154FADA15BEB82E8B237BDB6B0F9C", "hash_ssdeep": "3072:mYmoWWTuaShi3/oOMqqDE3WbqhPrKRpzrJ7eSOioU48Dg0VFhZl42PW:tolqqDEJzKRNrxeSOioU48s0hkh", "hash_imp": "59E6FE297D27F8961A71FB0AB87C3C66", "hash_pesha1": "AF4A1D019428AD2D4668F0D58A244A1318143932", "hash_pe256": "331A3B5872A89A1B61F320AE43CC582984255E6FD3CE10F97ED8D86CF09C8FC2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Kernel Debugger Connection Server", "meta_original_filename": "kdsrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "KernelDumpDecrypt.exe-3422BB95745E969F3306EA0B70C58A0E": { "file_name": "KernelDumpDecrypt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\KernelDumpDecrypt.exe", "hash_md5": "3422BB95745E969F3306EA0B70C58A0E", "hash_sha1": "1E4E9CED0D5EC9F690946CCF2D7E6D61814D6514", "hash_sha256": "EDA7271A238227DCA5AD5A77187424F4F0CF0B9608C5F396424046FA4B632C35", "hash_sha384": "95E02E9B75CC25D5BDE646D6FC37AD59BF1E16A3B0550DC5FF60A8B8D472C45D35E682F272F305B06ACE2782D8CDAFB8", "hash_sha512": "99A8CA173739F259AC73B3100618C8C793E21B3E37F3DD5C0235EF4002887EF58071D60D52A4F36A2C3686DE63401C2B3DFB3EB8CD6C266C539F6999D6F701BA", "hash_ssdeep": "384:o28MCX9nbZhsLWUtAuL0q7S1Y4WlETpYrN6aWoXWhvwMsl9ni:LfCXRbZhsP3L0Xu4JerUUqJ", "hash_imp": "50C04B023899A8A29CF00DC8CDB570C8", "hash_pesha1": "91EE4C092428D8D1EE02D4D429702EA2FB67C868", "hash_pe256": "2632D169CA03B45AE6563354434DB98DC54E245480D54044B6D3EA099ADD5189", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Kernel Dump File Decryptor", "meta_original_filename": "KernelDumpDecrypt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "kill.exe-2AF1CF6800FAC43DD0CCAEE30A76D994": { "file_name": "kill.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\kill.exe", "hash_md5": "2AF1CF6800FAC43DD0CCAEE30A76D994", "hash_sha1": "3508647ED67058D34AAFBF3467FB6A5510292ED8", "hash_sha256": "D1E263299752B18A056F5EE360B58A066A02C611DA2316DDB1D02327F28BF7D6", "hash_sha384": "F484341EBF5A123E7EC376C261ED778B7519C6462EF93831EA1A0580250C1B91FEEAB8FF39136C415E84C514C442AD52", "hash_sha512": "592E95454A2F96374B4F6AC02FF59E032BFB2DCC78E7E2C9E6459095F482F105F95A2F18B6113A3A3E9D5586E66B3361C72A018762E7BA4023DA28BA559B8BC3", "hash_ssdeep": "384:YayRLeXBk1abEH+2RgQlENo9w7XW2kIx6P6WciqvWGnYBlgpGn:YazXBfolE5/uPs1HA", "hash_imp": "D22DBA2658844B0ECFF9C2D3ECF0FAF3", "hash_pesha1": "7A423B5FCF7348A63085770D091D4B0FA7463373", "hash_pe256": "E7702427415A90E50556AA6917AE8DBBF1A007C97A11D2C2A695B78CD784D428", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Process Kill Utility", "meta_original_filename": "kill.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "list.exe-91CA916C919E3679D02A44978E164481": { "file_name": "list.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\list.exe", "hash_md5": "91CA916C919E3679D02A44978E164481", "hash_sha1": "D951034139E07B73418E4F2FF43C951F495ED8BF", "hash_sha256": "A7DC325D7203A7E9BC1511BD71231821E17C865E96F3D4311165C4E2002A59D4", "hash_sha384": "CC7515DD42F3E5747198547F62F4FC8CEA4C6575E08246706DC050504430EB74A20B5F1C58DB55325A2EE2E1536C888C", "hash_sha512": "032E81262CF5D12C28F7C5E14656C9FFA180C99B74823B8F56A95D3386E87EB7872F172C8B3CC8547629C1FAF9D515DEB2662C6263D1A04968B2C33A37D0885B", "hash_ssdeep": "768:RUs7zXS5I4k1smdfQjAZotwx7pYT1iyLQWIzMvleUoWN+j1q:RUsCufdfQjAC+72L/gMvlesN+g", "hash_imp": "FDA135ACC15B98BE89058AE7680DEB3F", "hash_pesha1": "E5C542CFFA88E3C3CF4F5996230D94A60F22DF0D", "hash_pe256": "2AC75E01D10627EDA4423E4939AF0B1657BA10931763ACF2BEC2AE098555B7B6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft File Lister", "meta_original_filename": "list.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "ntkd.exe-F468EEBF04739821C2B5C322754FA720": { "file_name": "ntkd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\ntkd.exe", "hash_md5": "F468EEBF04739821C2B5C322754FA720", "hash_sha1": "C0EE553F309CD58F57BAB1D6EB3FAF712E89252C", "hash_sha256": "482CA0A7CD1BDAF795458B9CD679093CB452FCAACC6C39C2FC9C0C5E96436A0D", "hash_sha384": "064AD9BECA77BFDDBD0B9C889CFCA6C13D6A289521819D70208D9D818370E8DDBD00884AF9DAAAEE4995B254E6E1ECCE", "hash_sha512": "95C31D06A3C51A56382E29CB4F92F60A6D872FC05CA5A63FA3E94A66E674C984050C198BECB7A494F2073F89706D76846B9C845B851B0F56405B674AC59D110C", "hash_ssdeep": "3072:2FL+W5FnbMBmoWATua6x6UdsL+E5Ar3bjfFJp5XLoXI:2FLaUdfE5ATdJp5XCI", "hash_imp": "4D6BE4ADCC3CB3D94424E05C6905099E", "hash_pesha1": "3363468B0E717B65D0B9AFE281D324E469B30EFD", "hash_pe256": "618B4519D8E68C5F6A2B8302E9E14C67F003AFEA1541A4AD32E8243023D834B4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Kernel Debugger", "meta_original_filename": "ntkd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "ntsd.exe-629EA12D527237B9CD945AC44C2DE80D": { "file_name": "ntsd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\ntsd.exe", "hash_md5": "629EA12D527237B9CD945AC44C2DE80D", "hash_sha1": "DABB109A73FCBCAD223B1B745E470689811BDABE", "hash_sha256": "A989E057B11D4B4DD3737CD0091C8060552959E98C8B4958A58A3E68EB5D9BE1", "hash_sha384": "7049A36AE2C131E7D99DAB6B5CBB6EEC3E719225CD5915AE3D183268C3CB7838EF9397904134B295DD18FE734AD59B87", "hash_sha512": "812529E1FD4F8AC7A5EBC88B548F32103F1A6A5BA9E6DFB62E6F7F028881B917E537E7136313C6E0618E11DE91F0A4783578BBE7C7E0F66C3CA2096BEDAD3C64", "hash_ssdeep": "3072:oH+JhFnbMpmoWATuaRFOarqdu4Eyj4c9pkp5/BHhR9x:oHjMamdu4Ew9pkp5/3d", "hash_imp": "F63FEB3A70D730CEF82DBC8F5675167C", "hash_pesha1": "1F02DECBDE9FF7085E7E6807E1B9B824AC4DC630", "hash_pe256": "459D91763A8D1D70C54FE0541598B6D7436EBA725B220FE4C127A8D94F4CA75B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbolic Debugger for Windows", "meta_original_filename": "NTSD.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "pdbcopy.exe-ED3F58F699454CA7823A341257CC4981": { "file_name": "pdbcopy.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\pdbcopy.exe", "hash_md5": "ED3F58F699454CA7823A341257CC4981", "hash_sha1": "56DE487CC57544CA4F4E2BFE97A81FC460A76E55", "hash_sha256": "AE306791065F68C365BB876AB51201CC8A3646B9B1F9B1278AFB083CF1F99392", "hash_sha384": "F9F0CA8C9673A82AB1A9E418D09F59FABC1DAE16B7D41B97AC4CAF9672B5E121BD59CBAB30D67E286FF0F89C34751FAC", "hash_sha512": "843707F12096ED7317460F97A4F36C9A11AC0C4B4478AE0904D06E3BF1B7F2E64AB1FD4FD73C285CAC5C72BDC928CA2541DB21BAF7BAB968CD090BD50AB786A7", "hash_ssdeep": "6144:N0BXwDKd6Z1WO5jme2d+/Q1hmAPMri/EbKUoHqicq5UElWn2/I05pPHAm6Se6+CV:2Bg2O5jmo2fPfMYUgpPC6J2G", "hash_imp": "0B79FAB60C277E438DB2EA0E7BA6133A", "hash_pesha1": "DE71041B59388A7F6EC02A8082B0015BBE255FA8", "hash_pe256": "7A49B19DBD38CBAA6A987F26E24115060F358EFC321AE9B426F497A9A8DA9B0C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft PDB Copy Utility", "meta_original_filename": "PDBCOPY.EXE", "meta_product_name": "Microsoft Visual Studio 2015", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.00.23615.0 built by: VCTOOLSREL", "meta_product_version": "14.00.23615.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "plmdebug.exe-427C680D862B2DE7F60620A35BC2934B": { "file_name": "plmdebug.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\plmdebug.exe", "hash_md5": "427C680D862B2DE7F60620A35BC2934B", "hash_sha1": "814C4C29C39F7BD9D7E22139B858EFF3C96BFEDC", "hash_sha256": "7A563B3013E8447D00FDEC632C70B707D3C8514AB1116612A8EDC5C85605B130", "hash_sha384": "130F4DE50D060702F0AF31B354361D72748617017432FCFE2E19FE95F8B345E7A43EADBDEC29DA8767EF5C134C252261", "hash_sha512": "D7242412FFDEF1D1D67E4F7B2D297CAD1593BAD5DEA75A295C9886BC80304FAD0741CA1FFA6A0940C7E63A56CCA3AB7854B34A8E7EDB5A811D41023156B62201", "hash_ssdeep": "3072:TdrvMlfJ8c5VOvWJa40qlklbvNnGaf5WID:lA5ovWJaVRlbvNGaf0ID", "hash_imp": "280D3ADF04FABFA39E5E694DC3E3C636", "hash_pesha1": "2CDE68F27DA2DBC0744A452A0B6D6AEEB9A6E6F9", "hash_pe256": "6D013707D9DC0B42E39BBEC7587D3992BAD897FDF94B700BBE2C324DDC83C71D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft PLMDebug", "meta_original_filename": "plmdebug.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "remote.exe-2BE212369D0D0127374037024B1565E0": { "file_name": "remote.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\remote.exe", "hash_md5": "2BE212369D0D0127374037024B1565E0", "hash_sha1": "BD17FEF245628DB9970BF1545940A2DEBC70E296", "hash_sha256": "CF9C06154235FAB5D6B67F742B2D2DF0304411763E8C8C8530C524B6D13975E2", "hash_sha384": "ABB264B7EFF34E50A16AE548360983C48AB87876F8D4F99018AF30DE38C7D0C87332D848E82B732143553AC73E9096F7", "hash_sha512": "A067A837D6B2BDC86E259A93F22F52347234C78F66B358631A0354F329968374091015FBC5EDDF8663B81B327A6CABE65CEDEF4D4DB0466B48C05ADAED8550EF", "hash_ssdeep": "1536:vydgE+vfhT2fL1amiBueD2e55gTHBpbm28nY:adJ6fhifLu95yTHHbmw", "hash_imp": "89B4E9D5BB54E7477EC7759183DCB824", "hash_pesha1": "10942F9E00AB7F8441D6806CE300247FE0657996", "hash_pe256": "9E27FDA09CD75DF42370BF92C99E081366CFF8DD2191220CBD650256DDA85BE2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Remote Std I/O Shell", "meta_original_filename": "remote.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "rtlist.exe-7A8026E127BFD0F4F0CA8AF4D287FE52": { "file_name": "rtlist.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\rtlist.exe", "hash_md5": "7A8026E127BFD0F4F0CA8AF4D287FE52", "hash_sha1": "3DB8B1FB931CDC3DA0C8E18606BAC63622A9C550", "hash_sha256": "19E6ED728B308B9416957ADB9447F873B37E71AE34592B79C62E22B85B784AEA", "hash_sha384": "475C4031E259C29DDCD85F33D6FAD0FEB5B1BC79E94EADB2C054FA2DB06A483DA3E72CB650F704FD94BD2692EE791805", "hash_sha512": "6B35204529B10A61DDE08A93220D95876440EAC5F143E6D3CC64AC945B93B25E58038DB20D04D42F86F3B011CBFC80338419B7078C2FAC4895597096E8791DCA", "hash_ssdeep": "384:V/cXgcd298SvTnCf2eqBWO73ZWPVKfOlD7u:VUXgD98jrqNt", "hash_imp": "0E80492650FF4643EC6CA22942691A16", "hash_pesha1": "F0E031906CF63065ADC733E221D57D2CDF8FD1A0", "hash_pe256": "02643CBB92E25FE96B8B14CB79B7B871D576B39889075BDF17F9259EB35737DC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft User-Mode Process Server Query Tool", "meta_original_filename": "rtlist.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "symchk.exe-DF8295AEE5CCD3C96F293FCE780E4DFC": { "file_name": "symchk.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\symchk.exe", "hash_md5": "DF8295AEE5CCD3C96F293FCE780E4DFC", "hash_sha1": "44FC9FF79433EE0624E3111A6B682BA5614F74BE", "hash_sha256": "502C1837ABFC43F2BCDE6C9E3B596D005A91FD557F642D32FC3F4DFE83B5F5CD", "hash_sha384": "59CE937393AD5F428BC204D7347DD1942F7653F0260C6C7BD16265B070B0A394902224E74DC55A518586680376E184A7", "hash_sha512": "84EB57685CFEBCBEEA7BBBB98E3321C3E2180255EAE5988509DA3276CBE825F7227516DDFCDE1E22CC45C13FC71F8B253B4A0F013FA7213AEC9888DFE6816436", "hash_ssdeep": "768:eaOWfB1oeniNFOR+8XAhngrE+RRftADbtNxFT7uLNkFD7vC4yzsaVVGgTxEZqHx4:eahCN0E+H1AHby0ZqswV7xEZqHxNy", "hash_imp": "7407B08FF96D4F35255C184A57427D26", "hash_pesha1": "5CB8340E37A53D176680AF76EE5650E5AA006444", "hash_pe256": "757C7A2BD7E33DF23F07C93D77A768DBBCCB61B5DCDC35720E4CBC60B252DCB2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbol Checker", "meta_original_filename": "SYMCHK.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "symstore.exe-D1A7C8364D67263E4073EBFDA615C613": { "file_name": "symstore.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\symstore.exe", "hash_md5": "D1A7C8364D67263E4073EBFDA615C613", "hash_sha1": "85758971894DE9822BBD0C26D55EC486E31BA6E6", "hash_sha256": "CADAF22923895212447B25090F567B1F0CF3C10173DB9FA202CE060B57C1E1E8", "hash_sha384": "005D7AF0EB1DAA3E68CC6627890891341C5A4DC828645DF12E7036EA4FA52166D171C6CDBD17A4E2EC7B1AFF2DEB691D", "hash_sha512": "2E26935585C39AE89C1ACA610A9E05606361D71171FA1DBD00688F4C474EE9A723CC604A5B1297E52FB0622FF11CCA814A423FF1768B25C1A33403B591284C92", "hash_ssdeep": "1536:5n+u06nXoZMGxek0Q8+/IixbnZH2FEyE+0iv0apOyvJP:h+L6nXoZKhsX2aAv", "hash_imp": "B05FEFEA8606145D35FC046767BAD15A", "hash_pesha1": "F689BCC26AFA871B8D1CD2C1D3CF6782E720E1A7", "hash_pe256": "E27DD5D5B338187125FD78F074FF73016F3D8123DD490D70E6A5BD98B89E4826", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbol Server Builder", "meta_original_filename": "SYMSTORE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "tlist.exe-22C95ACCEBD8353AEE131E750D900E76": { "file_name": "tlist.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\tlist.exe", "hash_md5": "22C95ACCEBD8353AEE131E750D900E76", "hash_sha1": "EDD1452EABE1598CE154EF35ABF26E410B05AD3A", "hash_sha256": "34C1EFCBABE5CE93C9DF5CB1E8387B72A7B33894515C936555E09286D2C8E5D3", "hash_sha384": "E78C9DF5C6AAB9ED6B0412143503A5FC59E12405421C9FDDBDF79381EBD3ED9D28FE0D59236426F1C7A092688BE3473E", "hash_sha512": "4D60BAF33574B126A4F700067BAFFDC30DB798E731B4418656CD647894D2D896E3337F793608D4393CE18882B5C16E425BD328657DB33F77CB94556D0C15FA55", "hash_ssdeep": "768:Uj16MsXEecs4SlUcxKaTdD18T0yzM8of1w5O5:+tcoydR8Y0M71w5a", "hash_imp": "12F33D6F4C1780A158BB1F3C997CECAA", "hash_pesha1": "3D8AF6BA07EEEBD22040B2592D082937FF053FDD", "hash_pe256": "7C1AD91ABD287DB2F3F2ED726C1A969C77C3B7317D0B21597630523A5A0D9DD2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Process List Utility", "meta_original_filename": "tlist.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "umdh.exe-A9DCB69069F701102ABAF0C24062BCD7": { "file_name": "umdh.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\umdh.exe", "hash_md5": "A9DCB69069F701102ABAF0C24062BCD7", "hash_sha1": "98F277DCA30A5DD3130A6326DB38DD40B2944052", "hash_sha256": "8EC79D95E659C0B532FF8FCA9908A6F3207AF195E65B6215A2B2ED75A2B52CE5", "hash_sha384": "CF47A58192F9C1FC5DD8FBED3D38B36C8AC398140D232C2972E37C48532B54CE29DA031CCBF1143659165ED9ADFDF6AD", "hash_sha512": "EC4141C7E9762BA758E085FE3FF6CD27380BBADE516F1CAFB5B8BD22F5C5CBB4965887E7794C9619C88472BE79A46DE6F5B06E400D97B4CAAD70EFA83C045C60", "hash_ssdeep": "1536:BzNZwxFeHJ/q/apUpyb/TTrVUvUbKTsJI6o7:BzNGLKJ/qhMqsJ1y", "hash_imp": "8F9ACC3CD3B8CF4FBA8DA549D450C30A", "hash_pesha1": "ED217F1C2FEE9D4DE2E18849EF98BE35E5CAD084", "hash_pe256": "864B72C079132FDCC81B518022538C2F119DBFA5828203BB8063ACC3C572CFED", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NT Security Test: UMDH", "meta_original_filename": "UMDH.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "usbview.exe-011CBA2853E8D47161D536C7A9D35D31": { "file_name": "usbview.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\usbview.exe", "hash_md5": "011CBA2853E8D47161D536C7A9D35D31", "hash_sha1": "779F6E55A7535FC8AD6B3CED558AB3DA353C48FB", "hash_sha256": "1269AB6473EEB011FE099CD41E945D4510291B8071D5881F8EC3187A7714236F", "hash_sha384": "001EA5CB67C6AB40FA249E05530186849051E1570CFA77616E8FBD49273DAB2E72AE704239B50C47AEA517A12A72CBDD", "hash_sha512": "E6B90AA8D2C212C94405EB4659CE18B1B6C9CC24E7167D8715AE61BF3C5EB570D6647D748C5146B9254405094646729EF585CF2E866A3E8D2DC4E03F04E9C683", "hash_ssdeep": "12288:5NIWApVpqTA5TMOECaa7UzHkUcUw0NIyc62sO+gbp2seeKx4H9rbL7rbL7rbL7rU:51ApV3TMOEyiE4NIyc6HVgbpUe3H9rbP", "hash_imp": "F777B39DC51FDC0FEFDC5A1AF521C113", "hash_pesha1": "5E36F45F3A63F7932486AAD3DD48559FEC318857", "hash_pe256": "E4B1AC6C139D05339E03FA7238374727D5947027EEA3D957CEB4BFDBA767DEE7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) USB device viewer", "meta_original_filename": "USBView", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright Microsoft Corporation 1996-2011 All Rights Reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_2948": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_32\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\usbview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\usbview.exe" }, "windbg.exe-DA8D9E0797323466972BAF573BA7C02D": { "file_name": "windbg.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\windbg.exe", "hash_md5": "DA8D9E0797323466972BAF573BA7C02D", "hash_sha1": "D30AED1C1A36DCCC8EA450BDCDA91B6618421C14", "hash_sha256": "8B53689B92EE1492A61DBA5476496A807A7954E0171C1B35C906C3EAB1C37465", "hash_sha384": "C66BE4204D8812FD73C0EBC6577EC85B72FEC1486B1CAE2B7C47A6EA5F7CD897678CC0ECEA3D9B26DD191B69C43DD88F", "hash_sha512": "6923DE22E95D9D318FC12F0DA11624158FAC8B70936F4BCD2481A9379BE10868FC5803DB8593198C379B916D3AF4A4C7BE9C55798D4D9C345743A19C94B779DF", "hash_ssdeep": "6144:TQzBThs0lDuWZWwxGFZ+f1wvxKjQjhDnrEw/rl1kwJzF1MfsUZu3Gyg7nZ4GwKrk:TQzlhdc+f1yF9boC1kwJz8wOusrte4Y", "hash_imp": "F97D651BFA105F22F8A9A2474779DAE8", "hash_pesha1": "E6B74D05771CCD639B898C2B43A6CE6F938E04BC", "hash_pe256": "0648918A493C82086E9D586EDDDBE37FCE782CD06788BF0C63A945DC25858002", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows GUI symbolic debugger", "meta_original_filename": "windbg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8b53689b92ee1492a61dba5476496a807a7954e0171c1b35c906c3eab1c37465/detection" }, "pdbstr.exe-8AB79D7879F498AD4A027BE8EC33DCBD": { "file_name": "pdbstr.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\srcsrv\\pdbstr.exe", "hash_md5": "8AB79D7879F498AD4A027BE8EC33DCBD", "hash_sha1": "BD644C481C3167D7AC6FE25A31DA8576AACA3644", "hash_sha256": "2D595E44AA9CA658E49A90C8494AD79136C1D8BB118DB2F34F956B222B1D03D3", "hash_sha384": "09C82E1ECB77AA76CC00CD35FE3AA00FAADB78F89E429B53FD1C9B59285CE954E01D0118DF604D5A340618E98F5C7EB0", "hash_sha512": "B04330539FB61CF545E3938B25C963EABF42C99ED46EF94A1A7AFEE39BD96331A4710101DDFD4578CFC6651D8FC96AB4BC64C9EB7FC461E9AAC2E658469E72CD", "hash_ssdeep": "12288:oIJb55deM8IIRIefvRcc9+hDmUjTXn3AXFzeAAKw5FRryeqMeluYPAkt87BRWeAi:/XaODmIiMelFoO6Vecbz", "hash_imp": "04131A25763DF221991D4ECFF21341A1", "hash_pesha1": "69474984E1A0B170D0FAC565C429947D03CE8FA5", "hash_pe256": "242A3D425F4EC35B37F668926BB982B822A332B4D228C8468750AED44FA76AB4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Stream Utility", "meta_original_filename": "pdbstr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "srctool.exe-3107FF2A8633F4BFD7E69B4444D71B24": { "file_name": "srctool.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\srcsrv\\srctool.exe", "hash_md5": "3107FF2A8633F4BFD7E69B4444D71B24", "hash_sha1": "DC8CCF2D9227DF3307425A8FACCD863096D61737", "hash_sha256": "E99DFD4C8C96CC1E263FB9D21E0F3E485B2760BA59C3937EDA89CEEA31EA61BB", "hash_sha384": "D7946CF9997F7ECA90CEDF2218D0D54A1DFA78EDDFC8B69158940A3A6A2CA68D02B4FA63157E9C496D485E3CAE3129E4", "hash_sha512": "2465376054B0D6A02619D650BE3B656C57C1ABFBD9DE9CFA4852308A01FC7812EC3BCC147541E400B3E0C38595EC209E0EEBDA92687CC755BE71FC12BD029D4B", "hash_ssdeep": "384:Wv/MC9yqK8X6ZHO3SoTqbt3Bk0lX5OVmViWnAHWCrvAE0polz8C:LC9yqK8XOO3SoTqbDkcX2mV0V4lGB", "hash_imp": "8107C25B53617B7E5FE1759D5149EA06", "hash_pesha1": "4B0A148197D3D94FA54E5A03140B11E45ED9FDD5", "hash_pe256": "6CE57341EF3DCDB40FEBAF0E86154C7087969961289BAAE3F56DB17EB8928933", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Stream Utility", "meta_original_filename": "srctool.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "452", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "adplus.exe-FBE03AA8E0CB7E1469F9A12EA10ECCFC": { "file_name": "adplus.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\adplus.exe", "hash_md5": "FBE03AA8E0CB7E1469F9A12EA10ECCFC", "hash_sha1": "45A57B9F45CDF3D80E68522BFFB57E4614A78FCB", "hash_sha256": "9DAEE0BDE6608EFE2A6E564EBDC716013ED79AEFA65C8266597D5BB989FE683E", "hash_sha384": "C9A8ED853A9D3EF074AF47AD4EC07B5FD40924B9C52000B8EDF2C06C2D37E793F897475E30CA7FB003B3108BDB36E28A", "hash_sha512": "5AF17485E7F5DC9D02FB612B76298BD1205EDCA21B4FFBE1225D07F3711D15DB23C733AC4EB300E3C0831572B3E0AF74F47FC5F6BC3FE2B0F2539763053BB893", "hash_ssdeep": "1536:F8Kjkp0ynhPotyboYSQs12eSsBYCTbqmC2zPCPXNwcZp3CWVq++FUALPYo:yr0yR/EoabBYCTb42zPCPXNRxwBPYo", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "2EF3E1B74509010CBAD61957280D1190E3BEE231", "hash_pe256": "FE0C2EFD75BE09631CC6475ABA8F421DBD5CFB4C276CF4FDA78F97F58338E4B1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "Adplus.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Starting ADPlus\r\n********************************************************\r\n* *\r\n* ADPLus Flash V 7.01.007 08/11/2011 *\r\n* *\r\n* For ADPlus documentation see ADPlus.doc *\r\n* New command line options: *\r\n* -pmn <procname> - process monitor *\r\n* waits for a process to start *\r\n* -po <procname> - optional process *\r\n* won't fail if this process isn't running *\r\n* -mss <LocalCachePath> *\r\n* Sets Microsoft's symbol server *\r\n* -r <quantity> <interval in seconds> *\r\n* Runs -hang multiple times *\r\n* *\r\n* ADPlusManager - an additional tool to facilitate *\r\n* the use of ADPlus in distributed environments like *\r\n* computer clusters. *\r\n* Learn about ADPlusManager in ADPlus.doc *\r\n* *\r\n********************************************************\r\n\r\n\r\nADPlus Version 7.01.007 08/11/2011\r\n\r\n====================\r\n| ADPlus Usage |\r\n====================\r\n Command line syntax options\r\n\tADPlus -? or 'ADPlus -help\r\n\t Displays this information.\r\n\r\n\tADPlus -HelpConfig\r\n\t Displays the built-in key-words and the\r\ndefault behavior settings\r\n\r\n\tADPlus <runmode> -o <OutputDirectory> [options]\r\n\tRun Modes:\r\n\t -Crash Runs ADPlus in Crash mode\r\n\t -Hang Runs ADPlus in Hang mode\r\n\r\nSelecting processes to attach\r\n\t-p <PID> Defines a Process ID to be attached\r\n\t-pn <ProcessName> Defines a process name to be attached\r\n\t-po <ProcessName> Defines an optional process name to be attached\r\n\t-pmn <ProcessName> Defines a process name to be monitored\r\n\t\tADPlus will keep monitoring if a process with this name starts\r\n\t\tand attach\r\n\t-sc <spawning command> Defines the application and parameters to be\r\n\t\t started in the debugger\r\n\t\t The -sc switch, if used, must be the last one\r\n\t-iis All iis related processes will be attached\r\n\t\t like inetinfo, dllhost,mtx, etc.\r\n\r\nSymbol Path Options\r\n-y <symbol path> Defines the symbol path to be used\r\n-yp <symbol path to add> Defines an additional symbol path\r\n-mss <local cache> Adds Microsoft Symbol Server to the symbol path\r\n\r\nMemory Dump Options\r\n-FullOnFirst Sets ADPlus to create full dumps on first chance exceptions\r\n-MiniOnSecond Sets ADPlus to create mini dumps on second chance exceptions\r\n-NoDumpOnFirst Sets ADPlus to not create any dumps on first chance exceptions\r\n-NoDumpOnSecond Sets ADPlus to not create any dumps on second chance exceptions\r\n-do Dump Only - changes default behavior to not include additional info, just a dump\r\n\r\nMiscellaneous Options\r\n-c <config file name> Defines a configuration file to be used\r\n-o <output directory> Defines the directory where logs and dumps are\r\n to be placed.\r\n-r <quantity> <interval in seconds> for multiple attachments in hang mode\r\n-dbg <debugger> Allows you to select the debugger to be used\r\n cdb, windbg or ntsd (default is cdb)\r\n-dp Debuggers path\r\n-gs only generates the script file\r\n\r\n-ce <custom exception code> Defines a custom exception to be monitored\r\n -ce 0x80501001\r\n\r\n-bp <breakpoint parameters> Sets a breakpoint\r\n Syntax: -bp address;optional_additional_parameters\r\n -bp MyModule!MyClass::MyMethod\r\n -bp MyModule!MyClass::MyMethod;MiniDump\r\n\r\n-CTCF Creates a full dump on CTL+C, and quits\r\n-CTCFB Creates a full dump on CTL+C, and breaks into the debugger\r\n-CTCV No special action on CTL+C, just breaks in for user interaction\r\n-lcq sets the last script command to Q (quit)\r\n-lcg sets the last script command to G (go)\r\n-lcgn sets the last script command to GN (go not handled)\r\n-lcqd sets the last script command to QD (quit and detach)\r\n-lcv sets the last script command to void (no command; waits for user input)\r\n-q2 sets the return action for second chance exceptions to Q (quit)\r\n-g2 sets the return action for second chance exceptions to GN (go not handled)\r\n\r\n\r\n-quiet No dialog boxes will be displayed (no more required)\r\n-notify <destination> Will send a message to the destination\r\n\r\n\r\nExamples:\r\n ADPlus -hang -iis -o c:\\dumps\r\n Produces memory dumps of IIS and all \r\n MTS/COM+ packages currently running.\r\n\r\n ADPlus -crash -p 1896 -o c:\\dumps -mss c:\\symbols\r\n Attaches the debugger to process with PID 1896\r\n and monitors it for 1st and 2nd chance access violations and uses\r\n Microsoft's public symbol server with c:\\symbols as a local cache\r\n\r\n-------------------------------------------------------------------------------\r\n\r\n HELP and Documentation\r\n\r\n For more detailed information on how to use and config ADPlus please see\r\n the debugger's help file (debugger.chm) under Extra Tools\r\n However, be aware that this is a new version of ADPlus and debugger.chm\r\n may take some time to be updated\r\n Check for ADPlus.doc in the debuggers' folder\r\n-------------------------------------------------------------------------------\r\nCurrent log content\r\n\r\nADPlus Engine Version: 7.01.007 08/11/2011\r\nCommand line arguments used were: \r\n-help \r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\adplus.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "adplusmanager.exe-3147E568D456990D0E222FDC2B89C9E2": { "file_name": "adplusmanager.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\adplusmanager.exe", "hash_md5": "3147E568D456990D0E222FDC2B89C9E2", "hash_sha1": "EC841784005092201EE757FFB2C81027BD29437C", "hash_sha256": "0587DDC1B050F16FD0EB91353E933076CD2FC285A6E1B389A0A9422006346A21", "hash_sha384": "9CD8CB14CD4EDDFB63BB8EC087CCC062DDE6D90C3F17BCC7B68726D255E9581468FD8759B402078ADEDC5020314BF387", "hash_sha512": "4FD4E6A02B70F3BC37DEBAFC5DE84B4B94ED02F1F4CD8EFEE0158C4BEB0A88A66639596A89AB91123018C6D3CD6D8892E93F2B378507E33CE9F330B008F39FE2", "hash_ssdeep": "768:mZsFKlZ8Kc41WjT4TNegAuDk+6KGbG/+B+OzUaGNUXzwRlrgeJ:yluaWgpRDkfbr+68OXzwRxt", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "D23F0E80EE6E539B3191E338355C77DA254FCF89", "hash_pe256": "242FA945B9D59605B84331E3D07C32252E130F58FF213397A1DD98CB812A7A65", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "AdplusManager.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "ADPlusManager usage: <RunMode> [Command [Arguments]]\r\nRunModes:\r\n Master - starts this instance as a master\r\n Server - starts this instance as a server; will subscribe to a master\r\n Client - Runs as a client; sends the Command to a master\r\n GUI - Starts this instance as a client with a GUI\r\n Help - Displays this help\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\adplusmanager.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "agestore.exe-794ECE80B607AD6A630D876BA29EADD8": { "file_name": "agestore.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\agestore.exe", "hash_md5": "794ECE80B607AD6A630D876BA29EADD8", "hash_sha1": "5A9FBD61A4890103B6F9AECEE57220689ED705C6", "hash_sha256": "054FC9C05698A7B93CFF82F78DBA4FC03C6EEA03CFBD8BFC59F68520E0850B70", "hash_sha384": "3644A04D880CA9CF2E272E903CD6721B9F1242EB456BB631361613759C6AE5643EA23BDD5759D0790F55CD1EC13ACBE1", "hash_sha512": "C646ADCD0418E969BB32D845033852DCE449321F6E06E4AB61371A93BB971876CEFDAF85A890750B974E9219EC93365BD652089E4287D419FDF54C3CFABAB52A", "hash_ssdeep": "384:VtDF+WRKXOjQmyEWQm3ZyJmel9+6q2WSU6ZWaNPH4JeRlF64:VpR/jQmP7adc9+6qIac", "hash_imp": "A3E84BCD8DD0D31753AFE6D2C6B36524", "hash_pesha1": "500634A69C1134B9CD28DFB1D809514BC8912197", "hash_pe256": "F6225E96379616A304438C869EC45A510C7B114D53CDF28025F18D26D4F9F21C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft AgeStore", "meta_original_filename": "agestore.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "breakin.exe-3A457F977B3D6BC2A36B645608AAB8CD": { "file_name": "breakin.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\breakin.exe", "hash_md5": "3A457F977B3D6BC2A36B645608AAB8CD", "hash_sha1": "1144707E7FB5A9C1CF7F6ADD83A335A263899BCD", "hash_sha256": "93A92739DA0CF9E08CF15391A9CF3B4D3AA57DAC34A701F11A34DB36EE5A158F", "hash_sha384": "C5E62DE84D0EC0733876D1990E7043D546D03394381287D0AAE81567D95CEF96943492EAE1C35ED67891DBA22AFCF7D0", "hash_sha512": "75FC205AFFF2DB619EDFA1D29336CD8F8D859FCB1D54170F676C2D98D904870C99D9A4C5C88385C8A866B0CE4A86310E0EE719D437DF1C7CCCE9A7F9CAA0DF92", "hash_ssdeep": "192:JgOjF014v+qhBMh0rsMHujxs+oFVEOWYGNW8W8bpVWQ4eWKwkwqnaj0aezCP:JD9V0hi7MxIVEOWYGNWSJ6lITGP", "hash_imp": "03667462961B049BAEBEF0B9C8B0F94A", "hash_pesha1": "CF52B731191ED07F552361589A30C6BF87C996D6", "hash_pe256": "D7FD68D3F015B9D914CBCA8F9FD8F358D32EEF9229897FE69F98EDCC5990DB84", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Breakpoint forcer", "meta_original_filename": "breakin.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "cdb.exe-DD8CDDBA7687534208EBE43DD88E5347": { "file_name": "cdb.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\cdb.exe", "hash_md5": "DD8CDDBA7687534208EBE43DD88E5347", "hash_sha1": "82641BCC048F687D4CFBBB02DE6B22FA1958F814", "hash_sha256": "1EB127E7F0983BA09FC6559FF72ADF11FFCF7116F94B5FDB18F5A728FE8545D7", "hash_sha384": "2CE97CC562F367B2DFC6BCA5388E6079529379BCB7962DE9049A723E62D228A3D6F718080DBD8D800A0280A4D25387B1", "hash_sha512": "2510B89CA7E78852C8CA66F4DACC438F629EF9561FD0EC5B3C0953F7B906CACB1695729998022CAFE4468CF88E5882F584BDA417360CBF8B280A5512ABF621BD", "hash_ssdeep": "3072:U2bOoZisWyRcOYZ4P31R4pVX7MImpATeKt7bFyZh6:Z62isWyRcOY23ozbFy2", "hash_imp": "C64EB6694DCC19EE7E65F4F6C8BFECF0", "hash_pesha1": "8462DAB8C5B236570E94644F17197F1EA4F8C46B", "hash_pe256": "AE1CF1A6EF3DB69A1152B2C5935EA39539CA1A91CE9BFB36D7CB7CA8A2BA5750", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbolic Debugger for Windows", "meta_original_filename": "CDB.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "convertstore.exe-78175AB6BC4235378953F46A1CE3A273": { "file_name": "convertstore.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\convertstore.exe", "hash_md5": "78175AB6BC4235378953F46A1CE3A273", "hash_sha1": "DDE6F8FF367F07394A739D97AF4F227818952A81", "hash_sha256": "5ABF3F6CFE2FB48EF34B3E39C7D7E0CD572CB4D17EE8BD976A9984F882F93CF8", "hash_sha384": "A8ECF47C5DFE30C4A5BC3B6EE59B318A4BA8CCF0B6E29EDD56E6F66A0BD7736A371945471BC5F7DA5DA2505A68D7FE3E", "hash_sha512": "DE264FAD93DA7B25A3B40E8967C79DCFC749E2A4B25612827D32EB07923AC303208D4C2CD2DB86B6875C44CE1095343BE35FBC801C65251D51A8FAD71089A2D0", "hash_ssdeep": "384:X48Z36CVfM8yabNe3hbKvuiRnaL8Z76NWA9WoErk9flx6314:XLVT/yUNe3svuiRaUmBmQi14", "hash_imp": "0FCC79CE9DA46E495D297970140ECFA3", "hash_pesha1": "ADEF0EAA7F40878F6C01420BA63FFFFB73B87D29", "hash_pe256": "1FA57F807CB0CAD24B5A65436A30D67FAEB589B3EE73DE39A0BA55C0F955797A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbol Store Conversion Utility", "meta_original_filename": "ConvertStore.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dbengprx.exe-2A0907E84A30B8E319AB5D285B14A59F": { "file_name": "dbengprx.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\dbengprx.exe", "hash_md5": "2A0907E84A30B8E319AB5D285B14A59F", "hash_sha1": "A735363876DC5FF8E67F68F6A53EAA09DFE9A422", "hash_sha256": "00242A3473E703158206D562D5147BADB883DE15A1B4311D47D6247542677E38", "hash_sha384": "7F3ECB9F440EABB7E2C6794CD83252CC0FA39758F675DCD5539B75AAD21C369DC3323D80FAA0B74B8479623731DF3012", "hash_sha512": "F74528F9541527BE375937064A065C1E3FD4C02226B927DF88CDF7E14172F554F18F385136FB186E328D18D0129614BE5682550AE00AD7C64FE31F882B0405A5", "hash_ssdeep": "3072:a3CKGXRKXDJK8oeFqL7/BMmpmTeKlDxVZ7ANbs:iCK4RKT7DFqLzB8VZ8C", "hash_imp": "7E7E6EAF603AD16D6CF9409D2139B03F", "hash_pesha1": "2DAA0141651AC6BE52753099DAE6BD707769D6FF", "hash_pe256": "546A9D9D0ECAF87504D39B3A7CBF29BCC298AD1929E1D4B5E505C1563D47026E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Debugger Transport Proxy Server", "meta_original_filename": "dbengprx.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dbgrpc.exe-2D7F8F17DD34732C4C3595D3C8F03C08": { "file_name": "dbgrpc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\dbgrpc.exe", "hash_md5": "2D7F8F17DD34732C4C3595D3C8F03C08", "hash_sha1": "69BCC04D022BA000997E315B1BC7DDC93DFE91F7", "hash_sha256": "7BADC05743F6A1AE9121D8F80176428E586EAEA3A3CDC37A36E442EBA914822F", "hash_sha384": "1BC89A9FA59541CC17F250910FE258753004578400CD906C8E30F9B595C6BCC4DFD99B7F4C06E861D8E854C8D182858E", "hash_sha512": "56540AAC670DECE0483FA9B6C141E7C1DCAEB6C816EE24CDFCBBBA21153202DF5EDECA268A7E65EB4B9848F0E907F68975ED2BAFF2855F311B1A759E451A90DB", "hash_ssdeep": "768:9IcuGKgZcNK3skzx+jPZGqvL45YbWm4No8lmD41AY0jc7:9IxG+8+jPZHvL45YbWm4No8lmD46Y0jo", "hash_imp": "16D237713988C1B33CA9FB45731CB64E", "hash_pesha1": "372657EAF3EE1526B65E72331FCD4B9BED7519B1", "hash_pe256": "BCB77A15E05359E4357FCB4E0B08A108966D6A27B20A6C8CA0513169A46E07E6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RPC Extended Debugging Utility", "meta_original_filename": "RpcDbg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dbgsrv.exe-06F490C967134305A0532C135ACE5BD0": { "file_name": "dbgsrv.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\dbgsrv.exe", "hash_md5": "06F490C967134305A0532C135ACE5BD0", "hash_sha1": "7DC335C3BFF73DEDBD1951E761CC2B9F266E4253", "hash_sha256": "19A65F0410B9B2CB0D4F7692B7E6F8ECA5F4522BAB21FD29E66EF5758D3F79A4", "hash_sha384": "72D0C7440EB21F07D78AF82781E869B0B29BE7EF2E08652370C4B947DB040F9F4ED38DF917BF87F1A2BEDAA388926C58", "hash_sha512": "AC97F57EC04EFF173C4CCE5F0CF4850AE22A3DAD12193F9C75529BB85F2855B13D1AC84B0C4BD5E99E207B764838C205534F466D698F63BDBBE180A2A4B5A934", "hash_ssdeep": "768:OLoERUP8eKYAmpYQfWTeK2iVOWrDzPOm8a2m5gm:OLoERUPYvmpATeK2EOqDzPOm8ahgm", "hash_imp": "E6C5135B2A79908A7006A54407BE4A19", "hash_pesha1": "BA072C5C63D12D791B451295569DD02CDA766AB3", "hash_pe256": "CE89D726DF566E9DFF4138DEC68CB2123E818B25DD7DB1FF173CCAFD906795EE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft User-Mode Debugger Process Server", "meta_original_filename": "dbgsrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dbh.exe-32312E5171CEE57FE59E611BF0D0D5E6": { "file_name": "dbh.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\dbh.exe", "hash_md5": "32312E5171CEE57FE59E611BF0D0D5E6", "hash_sha1": "EA73BCB420D90B782BC2B49165AB76E01643D4F5", "hash_sha256": "4A82832BFCAF73F61754E035182BBA2752FD54C31B3A6600CF4314103604E587", "hash_sha384": "D83FC69E24DB7C6D07FBCDE4EE4CEDB2D85A462BDC89F36EAAF80EF6309872D6015BB0EDE92E1D3EE308D42E76D08FAC", "hash_sha512": "52150AAE43EB3E044923B78AB44E761A6D004917FE2653717431D8105EA6E204ECE0DF9E34BF7F42F903D8DB9B305E390D4D1BE4CE85A3369217179E6D0DCF6D", "hash_ssdeep": "3072:7kys89/WHIeWzO0+kXByyuG3KgbED0ZXLAu8n7o:oyjSKzO0+kxFbw7o", "hash_imp": "43A9C10756F301892F8A2596E4284DFD", "hash_pesha1": "79E0F3959BC67EFD7A1124FEDEF666E2EB22EFB9", "hash_pe256": "FAC423A80EA5EDCFD978C4071E9D72480A70CAEA0BF47550FB9B781EE3D26544", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Dbghelp API Example", "meta_original_filename": "dbh.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dumpchk.exe-B2F31A7083876454B49B9D70F8530DF8": { "file_name": "dumpchk.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\dumpchk.exe", "hash_md5": "B2F31A7083876454B49B9D70F8530DF8", "hash_sha1": "B0C1BE7FA7E793D947D857F55755E94EFCD223C7", "hash_sha256": "3579BC8BFB1556057D8DE8C38C9871EEF2708D66320347F92B0B8AFAD672E078", "hash_sha384": "EA6F34D447E2BF8EBC1E425FD458016DABEA723951EA9AEA085EA02D1EEC8D816118DCE40FDF84680F6A8938CD200BC9", "hash_sha512": "5F9595FDB1847099580FD8C473C7E4D2EF0688C6582CCE320E752DA53B3D7AA9E7E807A1CF4566A63E997D1B83A71271C2C932A13CDFB1349723A50BAEF990D6", "hash_ssdeep": "384:P5vx2eun5KVY8EOnoaK79D+lvyQOWfxW8yjGw6lx2+tV:Rvx2eun5KVY8t29DqvHvDptV", "hash_imp": "28A2F281EC52EC36C7E9ADC65B3D96BC", "hash_pesha1": "4C4CF73AFB67BBAC41794D2A7B7AE467592BC979", "hash_pe256": "40B204D30E5780462046E83DDDB73C69CE0C0CC8CCBF745E76EC558B4634EAF4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Dump File Verifier", "meta_original_filename": "dumpchk.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dumpexam.exe-E1A688B2268B55EF70F09306A71ED42B": { "file_name": "dumpexam.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\dumpexam.exe", "hash_md5": "E1A688B2268B55EF70F09306A71ED42B", "hash_sha1": "61B204924E030282E2E11D10EC5B826705576C1A", "hash_sha256": "42CF132E19A15672663427AF2819E5BE4FA8702F3D9A7FB3E47E1E46157C163D", "hash_sha384": "B547D11C57A0149B5B01AC9A1C5157A2C8EE55BA8C2F9D51421E27C82881805875A91A08FA0F7C73BFAD493EF93DEA9E", "hash_sha512": "3F40C5C62179453CDB715FD2ACDB15E26871EEF9348B58ABE4DA0FB2A49EED7878005E1E35849DE0F26045E0C856BED7AE7E4647CC1E2D6748E0E607EB36A5A1", "hash_ssdeep": "384:K6C0enDxg008LbIMGWH4WU07kZalxYS5gKAW:KJxvbIMftT5gKZ", "hash_imp": "482E9E8B74141A2A2BC1B549F8E6E480", "hash_pesha1": "F92D93957B64A4074F5B7CCADB426F0F590130FA", "hash_pe256": "FEF745C38F62C3F24D3C3A4EB9DFB8FBA6D2E26C92411E2D8C228975C5F8E1AE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Dump File Examiner", "meta_original_filename": "dumpexam.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "gflags.exe-2812F8CB93873242F6A76058A8EF67DB": { "file_name": "gflags.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\gflags.exe", "hash_md5": "2812F8CB93873242F6A76058A8EF67DB", "hash_sha1": "6AEB207485B19A491A96044EA14D5FAA88D205F1", "hash_sha256": "444EC25F2326C8E0B4111FDC7068115E2ACC397CBB7353C933E9AC13302CF9D6", "hash_sha384": "70D5361C4608CF523B4D90AB2C144757DDC2BC78AD03074FB49F9126B7E6ED54EF62F7D243D38129440C4F70C002BB55", "hash_sha512": "486CFADCF3EBA5130D4A679F96C3E5CA7BABA8AF25CD63215C886DEE89B860A34BBF9251A95EB6CC6356CEE170616D48AE907C58BF8B389EFFE84B32A044AFE9", "hash_ssdeep": "1536:0PK4gkN5DBivIbZUzY7x443ySndRfD4eRC5GCAXVcg0ycJ:9BSndRfD4eRovAFcg0ycJ", "hash_imp": "981942E76E9072C66057E1B72D92A0BF", "hash_pesha1": "CC2EAE1964D32C8AA430B26D20B099C8A6B84966", "hash_pe256": "8D861C36F9F8D305A6F3BB13E9CEC98CE01C2292E2BAE845546216876B4EE8D6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft NT Global Flags Manipulator", "meta_original_filename": "GFLAGS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "1/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/444ec25f2326c8e0b4111fdc7068115e2acc397cbb7353c933e9ac13302cf9d6/detection" }, "kd.exe-91434D9701F623AAA6110EF731A10C19": { "file_name": "kd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\kd.exe", "hash_md5": "91434D9701F623AAA6110EF731A10C19", "hash_sha1": "32A96293E07F27B565C745F528F6BED4B42C9777", "hash_sha256": "CE3A7F8A083B1290B524C79614C86D9E1DEB22E4ECC94123259CFEE18AE2B90F", "hash_sha384": "E6635FF18651E0A35EC407312CD5AF76DF8A58E2DCCC1E4769B8E3CF622419F4A780D26EF5CAB6E6B8066F99E456C60D", "hash_sha512": "640FCFC14ABC84E92B1545E5FDA9FA048B65462CA21F91C87426B39898ECDCB65FB9E09518F113B68701D64FA4F328B7316CEF44BFF5E57341D81CC4BDD454FF", "hash_ssdeep": "3072:NSC4vKfb4Sxcu4UHJjLF7VVX7MwmpATeK61PbF9lJ/5RkjGn:F4v44Sxcu4CjcPbF9lJ/rPn", "hash_imp": "7FCECA637C138DC381C7952B2CA1EE25", "hash_pesha1": "03A6A782892BF94547C68D4B8B8C55B87F0B5598", "hash_pe256": "2D0EB97265DD667FFFA421C17D6D9BC8C2E0A20979887D792416C90D896FC8A3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Kernel Debugger", "meta_original_filename": "kd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "kdbgctrl.exe-64A5BC3910F3DCFC542D818F91C4B082": { "file_name": "kdbgctrl.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\kdbgctrl.exe", "hash_md5": "64A5BC3910F3DCFC542D818F91C4B082", "hash_sha1": "1F8ED294D852ECDD0ACE6689E959E90ECB85E6D4", "hash_sha256": "D0567180649D535CEB06A460BB71B70C9081D18206F3D849B316777279BA0B44", "hash_sha384": "084F43B510046B1B46207DCDB76DC64501C58005709BFBAC93716557FCAB53293EE5F53458280CB7369D0A5F10CE8FB3", "hash_sha512": "747B60FEB95992584C2684EEB9151689A0973372A45C55C08B237D1151242842998BD3B146FB724F4C005E8C43BC8DAC2EFAAA48FC0DDAA2CE0CE21D7DE00A92", "hash_ssdeep": "768:IGk4j1JLkLNLct89FazS+mpeQfWTeKhUaW6HFCoBm+oy:I6j49r+mpGTeK/vHE/+P", "hash_imp": "68116DABE6AFDE17D271F75E7DD3FF43", "hash_pesha1": "A8AE78D2D477CA0AAE123F8AAA2FB54F4DF44FA7", "hash_pe256": "3E7A8E1B2B4FA4281B1308E981B8426645CF8FB0D402695540B70FB1DEB316D7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows kernel debugger configuration utility", "meta_original_filename": "kdbgctrl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "kdnet.exe-A693DD7E3518578728198EA756748AC9": { "file_name": "kdnet.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\kdnet.exe", "hash_md5": "A693DD7E3518578728198EA756748AC9", "hash_sha1": "4896E0A942D5E1BA8829E58AEFAB88D19EDB77A4", "hash_sha256": "2CA0FB2E06CDB803031125F592A6AC40DAE16C2584BD4CC9CBEBF98F42A16A65", "hash_sha384": "BEFE093A39E1A481749438BD6584A6366275EB1E1F9BAB0641219F01EBB9968FB074ABA1A0E447F673EEFCD38A750031", "hash_sha512": "480886587385BD878863FE91B7E0A89D2CDB947E7F7B043F61B0DADC84F9B9A2D1C4BD8A53947BC7D1A5F6A52AABC58AFCB58A480BECC8D24C82D3658D3652CC", "hash_ssdeep": "768:6E5n5gpmFwrLkMkjrSLERTlf+dRnmbJ5BrFtG4vy+3k5de:6Jp2wfBEllGdJ25BrP9vy+3k5de", "hash_imp": "1C69AB70CF920C4AF68016651235CB05", "hash_pesha1": "81E6B059A0228BFB7BE87014AF9795924544B8B8", "hash_pe256": "4E7124CB5B2CA6482803A2C122A9094D45D207088828646F971F4BBD7EDF8F50", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Net debugging configuration tool", "meta_original_filename": "kdnet.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "kdsrv.exe-E25897210B9758B1EB4DCAE8B4EE3F41": { "file_name": "kdsrv.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\kdsrv.exe", "hash_md5": "E25897210B9758B1EB4DCAE8B4EE3F41", "hash_sha1": "D346C936C6FDA132B2D6D3F012E30D53C648EF2D", "hash_sha256": "E5EEDDE27B19BE9AE493F688AF944513840023B100D55FB42823C8B8DD9CFDEA", "hash_sha384": "7CD38467ABC7B6C78838C4C239E3C7C0A75CF429E3B94A33CE122CFAED8D9B267A6808B6DBF5473B8FEEA6000A3D0803", "hash_sha512": "AB1A882947087546886B7C2EC78B3D53668B1314B8EBB8A6392EC159345D44E0CC4DEBCF55F39D43AEE38FC15CB1D87565F090C3DF7141E62D5AD93022192A19", "hash_ssdeep": "6144:rQsBZpZSoyRY4xIh6OF7hxOmpUsolqqD7X0nXq:fLhoIqfXgq", "hash_imp": "41F024C962032DE261BC365184556A46", "hash_pesha1": "C5B40F84051B9166D0D553A5357B9E8D3E87AD5D", "hash_pe256": "B287443473BA0F25000A2CC85835473714A20B18A388CA02C878A23199D85D1A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Kernel Debugger Connection Server", "meta_original_filename": "kdsrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "KernelDumpDecrypt.exe-C8A3B58BAD61DDC4515766A1E0C5BCAD": { "file_name": "KernelDumpDecrypt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\KernelDumpDecrypt.exe", "hash_md5": "C8A3B58BAD61DDC4515766A1E0C5BCAD", "hash_sha1": "972EA895BF8C1A8676033FC8671E261B2C4A1DB6", "hash_sha256": "8F700AAFC0571ABF32B1B60A2477EAF9101246352AD526B7353B1920B49C8D3C", "hash_sha384": "4615E019137E46E25600308299741223198E1AE355134F25B01CD9EFF5D3A093E87AEDA9786942447A33A2391C2C456C", "hash_sha512": "ABBD90D8FBC0675085F9284D4F82B821E5AC7A03E86DBF177DD27C8FC1A2BEB964608BC570B1854B35531ACC91537523269DD92DEB21B87E72706DFE657FE735", "hash_ssdeep": "384:4F8s5X4khUry/kWtnv32aQXmom2f0cte91YrNmjSWoXW59JlvCz8rgQ:aYy/jn+aQXmuzAiricqrgQ", "hash_imp": "5CB5F28410D9C191B1BB6D8B343687CB", "hash_pesha1": "9E581455C830876A81A62AB64CB30664C3540339", "hash_pe256": "0795CBD744826323532CAE428212735C0A95ECBCCB7D12B4E19DA9196FF61E15", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Kernel Dump File Decryptor", "meta_original_filename": "KernelDumpDecrypt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "kill.exe-6B7A4A283E698A71976BD6E77D01D3F6": { "file_name": "kill.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\kill.exe", "hash_md5": "6B7A4A283E698A71976BD6E77D01D3F6", "hash_sha1": "730E201CF224C2AA100E66637B6F05C3C909ED85", "hash_sha256": "FC4C9E435686B3216BA1DB06445B10C8AF2CA176C5170A0624BC126E952E9326", "hash_sha384": "988FBFACD2AEB612CDFBF5217C026B50CB6844C1677C04E108EB4C72EEA1373BCCDC57017E187242DB90461AEEAFAE89", "hash_sha512": "F248E8C1D423C793A82F084AB2A194360919CB00FDE47B124B776140F14001B46CECB6DD8E89410F84AC660B5F3C32CF394745644E6CFC35F2A2BD1299D20EF9", "hash_ssdeep": "384:QO3tfE/7KF/K8qD7CXF2rt6q6fAiWciqvWQe4JeRlFW:QO3VEmF/K8GvZMfAk5X", "hash_imp": "DEEED6845FE44126D73726EB056698B2", "hash_pesha1": "EC1E0287C3613CCF5F2D99507A1860E3A6A22C3C", "hash_pe256": "E402E0B37BE05D456C18417AF9AD5CEFB7A523BC373E41F32A0C3A4658273728", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Process Kill Utility", "meta_original_filename": "kill.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "ntkd.exe-E0FCB6D2E3B5785392E8BDE334C44620": { "file_name": "ntkd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\ntkd.exe", "hash_md5": "E0FCB6D2E3B5785392E8BDE334C44620", "hash_sha1": "77D883408CBE24D9ED9C8C6A8AD97DB0A2B89C52", "hash_sha256": "9BD4EED254F301301F4FBBA8B99AB9F1C732C0349E44C601B27D4FC450307174", "hash_sha384": "918BBEB1B812C5E870C9FAE2F724123665D383A209F8CA2A7E54C7E708265CD01492D97A9123C7395C03B3780CD2C6E3", "hash_sha512": "88FEF96D3186CE3714276D65019F6337F658FB8214DB4F7197C96B4C20C6E474E475D2CA6B4059CAB0599681D879AC2918FD2D69D723D4A12EF5E7EB8FE78AB2", "hash_ssdeep": "3072:euJBk8FYUANSxcu4fO1+6LF+1VX7MhmpATeKsc5BbF47TK/0:ZBk83ANSxcu4963BbFKb", "hash_imp": "7218B05DF5E0408E242D18C32647D2FC", "hash_pesha1": "9B914DE38527AA9E6DE6CDDAD7739CA2AF120833", "hash_pe256": "683648EA6EB2B943BC844425ABB61DFB79FAF351EFA156552EBF7C59F8CDBB14", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Kernel Debugger", "meta_original_filename": "ntkd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "ntsd.exe-10CA7814A78DFC8207BFA64240580478": { "file_name": "ntsd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\ntsd.exe", "hash_md5": "10CA7814A78DFC8207BFA64240580478", "hash_sha1": "0AE0DB47527EEF74AB88C56760F59C6AF0ACE938", "hash_sha256": "BB00E51E6E6611E03464E640D31ABB3DED6ED9FEF6C65756B2341B4F39AD9776", "hash_sha384": "FCB50398E0BC6FD2BB1981D544445C74E24C4446FE2E0EA157BB74872DC74388AEEEA431CCEA1F4C0BD61C693E2F8362", "hash_sha512": "B74B6E3158B88D0BC91C0CE09C34404703FC491C6F56A7D807BEA1D02B29DD749BE48925B59EB7097053669D26FC3E645A506AF766FD2A8B9956F16E463BE4CD", "hash_ssdeep": "3072:0rVzuP+Sxcu4YSr/31prVX7MJmpATeKT1zxbFgJX:wVzuP+Sxcu4lvy1bFgx", "hash_imp": "104A4B4F037EE805C8AB64205777A309", "hash_pesha1": "16C37D233A6C70C4F6A1A0B06C19225676CCFC79", "hash_pe256": "892A31A14D0B983EF54F8CB4550CB05A488DC179C300DB2278B9523FB8E28953", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbolic Debugger for Windows", "meta_original_filename": "NTSD.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "pdbcopy.exe-2591567A6A2EFA663C94D6EB48ECEBD0": { "file_name": "pdbcopy.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\pdbcopy.exe", "hash_md5": "2591567A6A2EFA663C94D6EB48ECEBD0", "hash_sha1": "3E468A66F6C6275A4E25836296DFB2ABB3E935AF", "hash_sha256": "9A1492AA8F2942F467116DAE96F97DFB7BEA9750099257C1604AF53A1209A48A", "hash_sha384": "76E4AC5BFD50D87F88F2381476C461B01CB58FB4FD79442E25B09E39B0778565F65DAF8EC361C6A19C528DB5064024E7", "hash_sha512": "F31BB02DE85D3230C76D7A6EB0097B8214915DECBDAFEEF371ED2FC600C63328C5040E461847D8C7270B0B3528CB2CA66BCA1969E15D4B3FD3251F2CADC2CCC7", "hash_ssdeep": "12288:+EoPQcgT6pFMIShsgs4dwzJGR8xpHbcBTLu4PsJoAfwcSa:+pGT60kgd2JDIza", "hash_imp": "88BBA1D76A37C386AA0A310D3A5F28F4", "hash_pesha1": "8F8EFAB8B7F2E413686B941F8F29172C7B9A8C77", "hash_pe256": "33C4C888C37B93CC9CC9C85FF096B53FC607329476E353EBE672B44BB5FA6C2F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft PDB Copy Utility", "meta_original_filename": "PDBCOPY.EXE", "meta_product_name": "Microsoft Visual Studio 2015", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.00.23615.0 built by: VCTOOLSREL", "meta_product_version": "14.00.23615.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "plmdebug.exe-E2C61D673FFBEAF43ACB287AFEFEB5B9": { "file_name": "plmdebug.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\plmdebug.exe", "hash_md5": "E2C61D673FFBEAF43ACB287AFEFEB5B9", "hash_sha1": "5BE0083665458164BF2EAC5238D620CE045115FB", "hash_sha256": "84B9BA7F61846146A4E0ABC9816A61CD9A36E8EE389A88C595266E0010C93866", "hash_sha384": "19FF5AEB7400B51099844DACEB53D5F517E9C16239231A658E2E5B65E213991C4036FBA75EE61C7D11B4A4C7AF843C90", "hash_sha512": "50FBBCFAF3DC3E2DB1D2A9DD872AE5303AD518252F8164FC9AF47624B61797B9091B4483F556872FAAFCFC7608040DAC25066B96315C4D5D2E709DC519BE4488", "hash_ssdeep": "3072:DaDe4SFGxjrezJTWjOiSxt1QggiFeEfkTuafdx1WLB:DBXQxjaA0t1QghL5afdxQB", "hash_imp": "6FA33C61A60709031E382EA594E0207C", "hash_pesha1": "FB1A0BE6EBA5513A48FDCDAB4ABB8EF89D87612C", "hash_pe256": "440EE6246C3320FDA62F92842BD7558556BC1BD97012450392E3A9F9874A79C1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft PLMDebug", "meta_original_filename": "plmdebug.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "rtlist.exe-76D12076EE703D65617C5519B5BC42C9": { "file_name": "rtlist.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\rtlist.exe", "hash_md5": "76D12076EE703D65617C5519B5BC42C9", "hash_sha1": "BF579DF8C30D50910E729801390BC8B90F3D861D", "hash_sha256": "ECEFAE02B1D9FCF8618C91B4A949C719C55D414E581CD5E6F50B29A21AC836DE", "hash_sha384": "820A3BE09E81694F7375AABD45ED71B703F39352BC60753110337BE8BC598488198084891F341F2938C6A3443F6D0A36", "hash_sha512": "D9663502D4E864C2DA50559386DEDC8F968132BD276F5ED627C9C713C8AC444AD50CD75990AA60C9857C72C6025A8486E2155CE11D98044157CF4F9300FBD8E8", "hash_ssdeep": "384:2cQCcIYMeMC2teApWO73ZWj8fGw6lx2+t3a:NYMTeAllept3a", "hash_imp": "925D3A2AF095E9FFC054A76D8AAB9887", "hash_pesha1": "DC1CB83F2EA53C3704DB2F660B9E70C69E308C33", "hash_pe256": "4A115F24B29341D6942EA188E113D22C9A349B62A16BDA24E7C53DC881BB0B79", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft User-Mode Process Server Query Tool", "meta_original_filename": "rtlist.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "symchk.exe-924F34304C1BBE4F9BAA29B53C37387A": { "file_name": "symchk.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\symchk.exe", "hash_md5": "924F34304C1BBE4F9BAA29B53C37387A", "hash_sha1": "2AB7E67F06CC0866B7A054D8722CE03CAAF40DC1", "hash_sha256": "5CE69A3FBE74E8C2A45FBE8BEB77D53EDAEBFD1A2DBB66898310976AE44DA698", "hash_sha384": "085EA19409D72865B9A088C0C7FD55E7AD4DDF9062D8673BA1B9296B8386E778B3FC929C4E9C5770119C6C14840B1E70", "hash_sha512": "7814DE1C3103BE32C5C674131CA6C6E865529E3C897EAC187063BDCD891A2363A9D2EA7374F242C62116007E2C3BEDB588BB601E531C481AC2F394EBD00F7D90", "hash_ssdeep": "1536:znp16RpAGr0AtfFao/7HbT0PuqtaGHeKBCZrpCHnX:jXipRrjfFao/v0ujGHeKklCHnX", "hash_imp": "DFF58BF411A804D7482FE38817D9B39C", "hash_pesha1": "01996C416D8C66E65F43255626FF087135D7F100", "hash_pe256": "31ACE5050CD67CB2D552B21B3366CAFF7B69170FE7EE935016D2F2BAC81EB6F2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbol Checker", "meta_original_filename": "SYMCHK.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "symstore.exe-A70FD71933222D829C679585B4D96002": { "file_name": "symstore.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\symstore.exe", "hash_md5": "A70FD71933222D829C679585B4D96002", "hash_sha1": "A641C2573E689194092629F68F2F6FEBACA4B399", "hash_sha256": "EB642F9A78C736132C0D193C5A1E4BC0800DFBCD01D0C57D8542E80F169CDD6F", "hash_sha384": "7A2998571C911159189E811B7967D663F8658B00ABFD463C52A47B5708473228201549F705031AAFD073C11189986F87", "hash_sha512": "B3507155734A9B4001BDC4109AA7ED1C6F546223381903653F5650524C6350B69F098B22D56820FA0EECD38393B6CAE9348E68A0F6CAF4DF55FF90034A6FC804", "hash_ssdeep": "1536:yI0GXoiKh+JnVjBSGdK05ICe0DqP5d159/yk1Jwf3ex+06nNdJw93n:AG4izxCMICeNRd159/ykyexb6nNW3n", "hash_imp": "2524291D401D2B6FA6CDB57204907640", "hash_pesha1": "14571B8E651AB0A9DFD9949E18BE0D49978E197B", "hash_pe256": "E786B7966D756D27928A17BBC2B33F7AEF7355C1AB98A4EE0AC8ECF8E3EE1D74", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbol Server Builder", "meta_original_filename": "SYMSTORE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "umdh.exe-707218AF5E1A6726D1C6E4B885973FA1": { "file_name": "umdh.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\umdh.exe", "hash_md5": "707218AF5E1A6726D1C6E4B885973FA1", "hash_sha1": "192E20A1F6737D928752FEE020E25D789AF0B30A", "hash_sha256": "DAF4F60059FE774B3377E946002849655DD6122B707347A2BFD9B63D1217ECF5", "hash_sha384": "4496459E0F0E636371007565F42593BCF88D3BAADED6F5E69D03944744B84D6B4BB499C50E0E287B0024BFF0429FDF30", "hash_sha512": "698E39829E5D24A4A4BBD00D590B48E7BF5ABD1A7DD085AA6D193CB73DFA5A478FB7BD4D66B98118045B7F50F6E9C06B3039982425E96D21622389A31E3002AB", "hash_ssdeep": "768:UrLLgXi04lrKwH1QQRoFpFTqvNdovRisVHYch5ug/AJqoszG5UtnC:c6KKdXlqNdovRrph5N5cUE", "hash_imp": "92D26216DA73CC8247AC5ED757DF74AA", "hash_pesha1": "7B5DF2A04EECCD13AD306F34D4A93C8589728F0A", "hash_pe256": "238B3D061CD4E69CF36BD5E7C34AD10EAA2D06046455B53CB11A64363CF480F2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NT Security Test: UMDH", "meta_original_filename": "UMDH.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "usbview.exe-79080FFC24C9CA1F42797E993CD85262": { "file_name": "usbview.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\usbview.exe", "hash_md5": "79080FFC24C9CA1F42797E993CD85262", "hash_sha1": "E40BE43750981E7E74F2DFF91284CAA2866095F8", "hash_sha256": "DF27CF370ED330851796238FB07F48882B25B0AB3E9EEC91151188D2590C22FA", "hash_sha384": "3EE0551EF7C421C6A579DD536527CCC2DC0F21D88A700D93ED12D59E87B2000E3BC616C932C7F1C58466B8088AC7403A", "hash_sha512": "E1EFEBBC88877F06DF9632A454AC2E845EB4E60C7067C18406B058DAF7DBE2822DBB992F051EF15FCC29425E4FC049465B1B92E690A801CCA809A6AB86EC75CB", "hash_ssdeep": "12288:TNIWApVpqTA5TMOECaa7UzHkUcUw0NIyc62sO+gbp2seeKx4H9rbL7rbL7rbL7rU:T1ApV3TMOEyiE4NIyc6HVgbpUe3H9rbP", "hash_imp": "F777B39DC51FDC0FEFDC5A1AF521C113", "hash_pesha1": "5E36F45F3A63F7932486AAD3DD48559FEC318857", "hash_pe256": "E4B1AC6C139D05339E03FA7238374727D5947027EEA3D957CEB4BFDBA767DEE7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) USB device viewer", "meta_original_filename": "USBView", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright Microsoft Corporation 1996-2011 All Rights Reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_2792": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_32\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\usbview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\usbview.exe" }, "windbg.exe-7B9C6CAB38F6270C7324DCB375501522": { "file_name": "windbg.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\windbg.exe", "hash_md5": "7B9C6CAB38F6270C7324DCB375501522", "hash_sha1": "6F76ABE530B3B6F946CE0F3CD149FFDB821D7EB1", "hash_sha256": "E864C79EBAF473CD7DD5859DE079635FA09DDA67725E81C1D1907BA9E406C290", "hash_sha384": "D4E2BFC871685530F7D10BB12F32DAC3B0AA48B18758D6431E0B4D5D4F30BBF35CAF4CB5A9039AB9D38E5358108E8E4E", "hash_sha512": "867DE687517E881CC59725995D9AF6E07608C96CE74AC47DDDDC69FE5DF54D39CD310C8C030536DE31C8D44A928632F7CD6A5E0E269F70778D206639883FC451", "hash_ssdeep": "6144:RZdtMZJQwAAHsrZBJkbngc0ORL7fomCThLwQwM0yg7nZ4GwKrte4A3c:TU/HscgQ/Ct6Jusrte4Gc", "hash_imp": "58EACDD61DFF9F4A855CF087FAC2BEF8", "hash_pesha1": "266A04EE5D86B6590824D9147AFEF2F1EB7B604A", "hash_pe256": "AD582815107B816232B649A95777EA0225A20A3515D2386705360BC946FC09F4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows GUI symbolic debugger", "meta_original_filename": "windbg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e864c79ebaf473cd7dd5859de079635fa09dda67725e81c1d1907ba9e406c290/detection" }, "pdbstr.exe-2A4F20100A69195607E9EDB445700339": { "file_name": "pdbstr.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\srcsrv\\pdbstr.exe", "hash_md5": "2A4F20100A69195607E9EDB445700339", "hash_sha1": "873E76F1B40435F2CA871C266262C52483AC4069", "hash_sha256": "C80BAD496CBED90FC70D8BC0BBFE3A0F203A21CDD5BF19D0CD9B6DA63F827C21", "hash_sha384": "313A9389017B959E62389B192A92A1B27DCD84A41244628BDF7D17D016DE731E288F9A68DA5CC3A1FC06C392FA52B885", "hash_sha512": "1ACC01D66D3A0AB1AD3E98CFE6DCA81AFC08454E0508B4A9F173DDB891CFE4CAE99DBE5580A8FA1EB52B9C3FF8F24A34C674F211DFE9A33B5C010791B83CA272", "hash_ssdeep": "12288:tdq/wtkIKIcjtcUGMU5VwoKP4RVUGe9T/sz3hWTlSGpVQR/pj9+WF/nYZMDCo9z:O/1i6ZavWwz", "hash_imp": "E4D92C3BC944CCF3B3D4602E63E4B04F", "hash_pesha1": "E45F50252CD37C194A0B30BA361F8BE69269126D", "hash_pe256": "8097F66BD8D813C5DED3408042E764920E0B4A64BF1E844C72B2B5E257D07751", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Stream Utility", "meta_original_filename": "pdbstr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "srctool.exe-E7973CE7BB9DC189514E66D761468304": { "file_name": "srctool.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\srcsrv\\srctool.exe", "hash_md5": "E7973CE7BB9DC189514E66D761468304", "hash_sha1": "C69A2A3B575C44BDBCB493524F58A5B6040A0910", "hash_sha256": "3FD881F46B7AAE31FED33552249E11D70095C05632E7BF66E0361CA5581FAE0B", "hash_sha384": "506C87341431AF436F56A3C12033A378DFB6AF4DB60D876522122A48215B89DBB093D38868BD3F07848972DAE69D4F37", "hash_sha512": "5790F4D8A770903753F6324091CEF41A1FAA6935209592F126D09615F7B36FD732D59333CF4AA02C68B0C2781BAB385BE1208C09B8275A77BA426962E56EB8FB", "hash_ssdeep": "384:SxMEOYYPRu5qEqUN+j8/mjEyc1gFql3H4gncti2R7/8yNSqKBmm17adK7AeOJ46T:WSu5VwjJc1TZn4i0oyNSqKBmyJ7NlMrr", "hash_imp": "F2FA53139D794D1A4BF7D03A2C3DB03B", "hash_pesha1": "BFB40E481230654A0335B52F09705CE490F0D6AF", "hash_pe256": "765AD46D99418D67DDDBDC7B1ECAE1B13AC09EFEA92DA73BFFF63A3347A1AD93", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002B7E8E007A82AEF13150000000002B7", "signature_thumbprint": "5A68625F1A516670A744F7EF919500A479D32A5B", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Stream Utility", "meta_original_filename": "srctool.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit ARM", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "adplus.exe-8FC2163FC15F2EC5491ED58B1C54287F": { "file_name": "adplus.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe", "hash_md5": "8FC2163FC15F2EC5491ED58B1C54287F", "hash_sha1": "D5F257ABC4499FC3648D7585D80030A3EB686FF5", "hash_sha256": "6262054992658CA2DD8E5A8ADB0B207B630BAA75F930AE82A88835728DB4B7C1", "hash_sha384": "34AE43669FF90A31A1D364DAD8713FE3EBB548815847AF80C8436853FF0B1333C0A50A32B28E4B1002A4853E9E23532F", "hash_sha512": "FCDBBCE53DBF003F302A7B16E98E8CE3454A21D1C9F23B855E23A54DC2F0A5ED5BDA68FA7D815AA4674815303C6B07B6DF19F711D23BD47323288D414DC51273", "hash_ssdeep": "1536:28Kjkp0ynhPotyboYSQs12eSsBYCTbqmC2zPCPXNwcZp3CWVq++FUdIP:Zr0yR/EoabBYCTb42zPCPXNRxwdP", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "248A11517A4FA63D5456E82500B083B9B54E484F", "hash_pe256": "9A5FF8FE135B09D244978779F8BE119214A72E23EC61FC0F5D5B8DB47A254DE6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "Adplus.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/6262054992658ca2dd8e5a8adb0b207b630baa75f930ae82a88835728db4b7c1/detection", "output": "Starting ADPlus\r\n********************************************************\r\n* *\r\n* ADPLus Flash V 7.01.007 08/11/2011 *\r\n* *\r\n* For ADPlus documentation see ADPlus.doc *\r\n* New command line options: *\r\n* -pmn <procname> - process monitor *\r\n* waits for a process to start *\r\n* -po <procname> - optional process *\r\n* won't fail if this process isn't running *\r\n* -mss <LocalCachePath> *\r\n* Sets Microsoft's symbol server *\r\n* -r <quantity> <interval in seconds> *\r\n* Runs -hang multiple times *\r\n* *\r\n* ADPlusManager - an additional tool to facilitate *\r\n* the use of ADPlus in distributed environments like *\r\n* computer clusters. *\r\n* Learn about ADPlusManager in ADPlus.doc *\r\n* *\r\n********************************************************\r\n\r\n\r\nADPlus Version 7.01.007 08/11/2011\r\n\r\n====================\r\n| ADPlus Usage |\r\n====================\r\n Command line syntax options\r\n\tADPlus -? or 'ADPlus -help\r\n\t Displays this information.\r\n\r\n\tADPlus -HelpConfig\r\n\t Displays the built-in key-words and the\r\ndefault behavior settings\r\n\r\n\tADPlus <runmode> -o <OutputDirectory> [options]\r\n\tRun Modes:\r\n\t -Crash Runs ADPlus in Crash mode\r\n\t -Hang Runs ADPlus in Hang mode\r\n\r\nSelecting processes to attach\r\n\t-p <PID> Defines a Process ID to be attached\r\n\t-pn <ProcessName> Defines a process name to be attached\r\n\t-po <ProcessName> Defines an optional process name to be attached\r\n\t-pmn <ProcessName> Defines a process name to be monitored\r\n\t\tADPlus will keep monitoring if a process with this name starts\r\n\t\tand attach\r\n\t-sc <spawning command> Defines the application and parameters to be\r\n\t\t started in the debugger\r\n\t\t The -sc switch, if used, must be the last one\r\n\t-iis All iis related processes will be attached\r\n\t\t like inetinfo, dllhost,mtx, etc.\r\n\r\nSymbol Path Options\r\n-y <symbol path> Defines the symbol path to be used\r\n-yp <symbol path to add> Defines an additional symbol path\r\n-mss <local cache> Adds Microsoft Symbol Server to the symbol path\r\n\r\nMemory Dump Options\r\n-FullOnFirst Sets ADPlus to create full dumps on first chance exceptions\r\n-MiniOnSecond Sets ADPlus to create mini dumps on second chance exceptions\r\n-NoDumpOnFirst Sets ADPlus to not create any dumps on first chance exceptions\r\n-NoDumpOnSecond Sets ADPlus to not create any dumps on second chance exceptions\r\n-do Dump Only - changes default behavior to not include additional info, just a dump\r\n\r\nMiscellaneous Options\r\n-c <config file name> Defines a configuration file to be used\r\n-o <output directory> Defines the directory where logs and dumps are\r\n to be placed.\r\n-r <quantity> <interval in seconds> for multiple attachments in hang mode\r\n-dbg <debugger> Allows you to select the debugger to be used\r\n cdb, windbg or ntsd (default is cdb)\r\n-dp Debuggers path\r\n-gs only generates the script file\r\n\r\n-ce <custom exception code> Defines a custom exception to be monitored\r\n -ce 0x80501001\r\n\r\n-bp <breakpoint parameters> Sets a breakpoint\r\n Syntax: -bp address;optional_additional_parameters\r\n -bp MyModule!MyClass::MyMethod\r\n -bp MyModule!MyClass::MyMethod;MiniDump\r\n\r\n-CTCF Creates a full dump on CTL+C, and quits\r\n-CTCFB Creates a full dump on CTL+C, and breaks into the debugger\r\n-CTCV No special action on CTL+C, just breaks in for user interaction\r\n-lcq sets the last script command to Q (quit)\r\n-lcg sets the last script command to G (go)\r\n-lcgn sets the last script command to GN (go not handled)\r\n-lcqd sets the last script command to QD (quit and detach)\r\n-lcv sets the last script command to void (no command; waits for user input)\r\n-q2 sets the return action for second chance exceptions to Q (quit)\r\n-g2 sets the return action for second chance exceptions to GN (go not handled)\r\n\r\n\r\n-quiet No dialog boxes will be displayed (no more required)\r\n-notify <destination> Will send a message to the destination\r\n\r\n\r\nExamples:\r\n ADPlus -hang -iis -o c:\\dumps\r\n Produces memory dumps of IIS and all \r\n MTS/COM+ packages currently running.\r\n\r\n ADPlus -crash -p 1896 -o c:\\dumps -mss c:\\symbols\r\n Attaches the debugger to process with PID 1896\r\n and monitors it for 1st and 2nd chance access violations and uses\r\n Microsoft's public symbol server with c:\\symbols as a local cache\r\n\r\n-------------------------------------------------------------------------------\r\n\r\n HELP and Documentation\r\n\r\n For more detailed information on how to use and config ADPlus please see\r\n the debugger's help file (debugger.chm) under Extra Tools\r\n However, be aware that this is a new version of ADPlus and debugger.chm\r\n may take some time to be updated\r\n Check for ADPlus.doc in the debuggers' folder\r\n-------------------------------------------------------------------------------\r\nCurrent log content\r\n\r\nADPlus Engine Version: 7.01.007 08/11/2011\r\nCommand line arguments used were: \r\n-help \r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "adplusmanager.exe-2C5B77BC052B279CBD3098544D4E1C9E": { "file_name": "adplusmanager.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplusmanager.exe", "hash_md5": "2C5B77BC052B279CBD3098544D4E1C9E", "hash_sha1": "C9A4B5B94C61D446378683E3E15656E4A27117BF", "hash_sha256": "9B47AE6D148F9EA309FAB5005DB8BD1FBC0B2440875621ABA5A6CC17492996B6", "hash_sha384": "92B985B245BE765A101082058E0229484EE2AFC83157D183A62B2E0DF0C715E3C2D673F55EF06B87BB65EABFA4AF07BE", "hash_sha512": "15943F9A73102603411A4F0BC8428CFCEEF6B77C9BBAD193C97C7831EDD58018E581FDF1E13F20DEC041CEC831230D45384B0F98CA82C3F1261F35C995825511", "hash_ssdeep": "768:KZsFKlZ8Kc41WjT4TNegAuDk+6KGbG/+B+OzUaGNUXpu:2luaWgpRDkfbr+68OXp", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "5F3EBCFD5ED553BD1C9F7E2349B5BE64CC4CD793", "hash_pe256": "04AE348D60C9BF5E060AD89389B3FF17BD96A6631CED4060ED01B376C65B4C00", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "AdplusManager.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/9b47ae6d148f9ea309fab5005db8bd1fbc0b2440875621aba5a6cc17492996b6/detection", "children": "Fondue.exe", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplusmanager.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "agestore.exe-88617F3531491CAE5FEB1A2E459D0AF9": { "file_name": "agestore.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\agestore.exe", "hash_md5": "88617F3531491CAE5FEB1A2E459D0AF9", "hash_sha1": "B50180CDB8814718CA10968AFAD14F4D89EFB03C", "hash_sha256": "3B9D6DF43E8A03106DBA49297B8E49D19515A9F2378AAD4D2AB3D4F88E8AF36A", "hash_sha384": "6376A55E1F0CE9A9D698998EBAE8B93944F24D11725AF9AC13A5CF313AB53E785FFF96A113819F6B61C1061DF9D7FE52", "hash_sha512": "5DEA7B479F98A9D2665406A7268D92C08ADE0AA2A9713A6CD67E611EA883B69955C0306A7CBB40C6D7195A5C7CDDE4D8598B8BACC10800E1E90976A7DEFF90FB", "hash_ssdeep": "384:cwnm2NSDomVlUXt5ZbCJuLOR2WSU6ZW+wGyVThf4JeRlFI:c6m2uomVszGiCIt4w", "hash_imp": "CB99E29B685C706E58643B7AF4AE6715", "hash_pesha1": "7638ACF60EC4DD0964DDC33E526B9E813EEAC776", "hash_pe256": "19AC3A4D1131F646BF2EC483ED5071553F28930BA1EA978D0AFDC1E59A6F34DD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft AgeStore", "meta_original_filename": "agestore.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3b9d6df43e8a03106dba49297b8e49d19515a9f2378aad4d2ab3d4f88e8af36a/detection", "output": "Last-Access-Time support is disabled on this computer.\r\nPlease read the documentation for more details.\r\nAgestore will use the file creation time as the last access time.\r\nplease select either -date, -days, or -size\r\n\r\nagestore [pathspec]\r\n\r\nDeletes all files from a directory based on the last access time of the files.\r\n[pathspec] defines the root path and file specification.\r\nThe default is all files in the current working directory\r\n\r\nIt runs in one of these modes...\r\n\r\n-date=mm-dd-yy - deletes all files that were last accessed before the specified date.\r\n-days=xx - deletes all files that were last accessed before today minus the\r\n amount of days specified by 'xx'. \r\n-size=xx - deletes files in order of last access time (oldest first), until all the\r\n files in the directory total to the amount of bytes specified by 'xx'.\r\n-size - lists the amount of bytes in the directory.\r\n-lat=<on/off> - toggles filesytem support for last-access-time.\r\n\r\nThese other command line switches alter the behavior of the program.\r\n\r\n-l - list files only, don't delete\r\n-s - include subdirectories.\r\n-k - keep empty subdirectories - normally they are removed.\r\n-q - quiet mode stops listing of files as they are deleted.\r\n-y - eliminates the (y/n) prompt.\r\n-r - deletes RO files\r\n\r\nThis program deletes files. You should run agestore with the -l switch\r\nto see what it will delete, before actual usage.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\agestore.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "breakin.exe-723BE264E0CCFD1E4EF1DA8C307AEC7D": { "file_name": "breakin.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\breakin.exe", "hash_md5": "723BE264E0CCFD1E4EF1DA8C307AEC7D", "hash_sha1": "0523C3721589228EB42DA555D0A31F74F616AF69", "hash_sha256": "C9566AAEC773FBB5D0DCF12C2AAB85963979DFF085F8A13F03AEE95A5B6C0335", "hash_sha384": "D107CBFB62B5E218D98A9C299C68DFB1A6AE7CA46BCB976D69B95D5E5202352917686F8F5AD70F74A1A8499640A5E005", "hash_sha512": "7C41EBD8D69F9A6BB6D8A46E50973655904913EEDF5F0C04905645DD9AF20271A4BB96C995B42D9FB13CC4DB1684421F10EE079CBA1A77F276911EFF3EF4E000", "hash_ssdeep": "384:G3b+fZmLoWBrvfaxaMS0EOWYGNWtwGy2HS4JeRlFTWV:QMZOvfKxS0EXql58A", "hash_imp": "C77ABE483E27C8CC9A2B2DC69A1EC27E", "hash_pesha1": "C3565A8E41B91308A8261C26D92807828048F019", "hash_pe256": "4502F2EA94E5325A26BDDB763B1936954AA9BEAFE8D2F2612BB549FC9B845698", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Breakpoint forcer", "meta_original_filename": "breakin.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/c9566aaec773fbb5d0dcf12c2aab85963979dff085f8a13f03aee95a5b6c0335/detection", "error": "usage: breakin <pid>\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\breakin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "cdb.exe-708BDF975C762991A5972224D1F0144D": { "file_name": "cdb.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe", "hash_md5": "708BDF975C762991A5972224D1F0144D", "hash_sha1": "973B208F49E32FF629DDDBA9C88C3348E2DE0A4E", "hash_sha256": "D7FC9FB671D2E92ECD3D7A6BCC80A889EB52B067FD33B1B524547BFA5C303225", "hash_sha384": "1B04BF0784B2DA9F8E8A9DD9F6EA266F0A246DD4A9DF52B3114CBF540AD3251BAEB57A0E97328D44FE53AF4BB9E9B4A1", "hash_sha512": "2A26D04DC7E4FBB5789C792FA17BE6051AF81DF769D13F7EBBCD93C4867C2CFA006DC22D41B374D69D9203BDD2E54E2497F3E741B528026AF3DF719049C81E65", "hash_ssdeep": "3072:YLZfkEI88l6uRyQ+05VX7MompATeKiV0QbAaboZZ:YLZcE4l6a7A0Q8abo", "hash_imp": "FBEA2ABE7A7FBB2047D931990F3C712E", "hash_pesha1": "C5647B3E82B20C2D8B5AFEFDFDE1DF143BF56A2A", "hash_pe256": "2F5BB3469230906D5606BAE5CF97EB22683D3570A67756B3D6120321F99A58F2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbolic Debugger for Windows", "meta_original_filename": "CDB.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d7fc9fb671d2e92ecd3d7a6bcc80a889eb52b067fd33b1b524547bfa5c303225/detection", "output": "cdb: Invalid switch 'h'\ncdb version 10.0.19041.1\nusage: cdb [options]\n\nOptions:\n\n <command-line> command to run under the debugger\n -? displays command line help text\n -- equivalent to -G -g -o -p -1 -d -pd\n -2 creates a separate console window for debuggee\n -a<DllName> adds a default extension DLL\n -bonc request break in after session started\n -c \"<command>\" executes the given debugger command at the first debugger\n prompt\n -cf <file> specifies a script file to be processed at the first debugger\n prompt\n -cfr <file> specifies a script file to be processed at the beginning of a\n session (including after .restart)\n -cimp uses implicit create command line from a process server\n -clines <#> number of lines of output history retrieved by a remote client\n -d sends all debugger output to kernel debugger via DbgPrint\n input is requested from the kernel debugger via DbgPrompt\n -d cannot be used with debugger remoting\n -d can only be used when the kernel debugger is enabled\n -ddefer sends all debugger output to kernel debugger via DbgPrint\n input is requested from the kernel debugger via DbgPrompt unless\n there are remote clients that can provide input\n -ddefer can only be used when the kernel debugger is enabled\n -ddefer should be used with -server\n -ee <name> set default expression evaluator\n <name> can be MASM or C++\n -failinc causes incomplete symbol and module loads to fail\n -g ignores initial breakpoint in debuggee\n -G ignores final breakpoint at process termination\n -hd specifies that the debug heap should not be used for created processes. \n This only works on Windows XP and later\n -i <ImagePath> specifies the location of the executables that generated the\n fault (see _NT_EXECUTABLE_IMAGE_PATH)\n -iae install as AeDebug debugger\n -iaec <Command> install as AeDebug debugger with given command tail\n -isd sets the CREATE_IGNORE_SYSTEM_DEFAULT flag in STARTUPINFO.dwFlags\n during CreateProcess\n -iu install dbgeng URL protocols\n -kqm turns on kd quiet mode (equivalent to KDQUIET)\n -lines requests that line number information be used if present\n -loga <logfile> appends to a log file\n -logau <logfile> appends to an Unicode log file\n -logo <logfile> opens a new log file\n -logou <logfile> opens a new Unicode log file\n -myob ignores version mismatches in DBGHELP.DLL\n -n enables verbose output from symbol handler\n -netsym:yes|no allow or disallow loading symbols from a network path\n -noinh disables handle inheritance for created processes\n -noio disables all I/O\n -noshell disables the .shell (!!) command\n -nosqm disables SQM data collection/upload.\n -o debugs all processes launched by debuggee\n -openPrivateDumpByHandle <HANDLE> \n specifies the handle of a crash dump file to debug\n -p <pid> specifies the decimal process ID to attach to\n -pb specifies that the debugger should not break in at attach\n -pd specifies that the debugger should automatically detach\n -pe specifies that any attach should be to an existing debug port\n -pn <name> specifies the name of the process to attach to\n -pr specifies that the debugger should resume on attach\n -psn <name> specifies the process to attach to by service name\n -premote <transport>:server=<name>,<params> \n specifies the process server to connect to\n transport arguments are given as with remoting\n -pt <#> specifies the interrupt timeout\n -pv specifies that any attach should be noninvasive\n -pvr specifies that any attach should be noninvasive and nonsuspending\n -QR \\\\<machine> queries for remote servers\n -r <BreakErrorLevel> specifies the (0-3) error level to break on (see\n SetErrorLevel)\n -remote <transport>:server=<name>,<params> \n lets you connect to a debugger session started with -server\n must be the first argument if present\n transport: tcp | npipe | ssl | spipe | 1394 | com\n name: machine name on which the debug server was created\n params: parameters the debugger server was created with\n for tcp use: port=<socket port #>\n for npipe use: pipe=<name of pipe>\n for 1394 use: channel=<channel #>\n for com use: port=<COM port>,baud=<baud rate>,\n channel=<channel #>\n for ssl and spipe see the documentation\n example: ... -remote npipe:server=yourmachine,pipe=foobar\n -robp allows breakpoints to be set in read-only memory\n -s disables lazy symbol loading\n -sdce pops up dialogs for critical errors\n -server <transport>:<params> \n creates a debugger session other people can connect to\n must be the first argument if present\n transport: tcp | npipe | ssl | spipe | 1394 | com\n params: connection parameterization\n for tcp use: port=<socket port #>\n for npipe use: pipe=<name of pipe>\n for 1394 use: channel=<channel #>\n for com use: port=<COM port>,baud=<baud rate>,\n channel=<channel #>\n for ssl and spipe see the documentation\n example: ... -server npipe:pipe=foobar\n -ses enables strict symbol loading\n -sflags <flags> sets symbol flags from a numeric argument\n -sicv ignores the CV record when symbol loading\n -sins ignores the symbol path environment variables\n -snc converts :: to __ in symbol names\n -snul disables automatic symbol loading for unqualified names\n -srcpath <SourcePath> specifies the source search path\n -sup enables full public symbol searches\n -t <PrintErrorLevel> specifies the (0-3) error level to display (see\n SetErrorLevel)\n -v enables verbose output from debugger\n -version shows the build version\n -vf enables default ApplicationVerifier settings\n -vf:<opts> enables given ApplicationVerifier settings\n -w specifies to debug 16 bit applications in a separate VDM\n -wake <pid> wakes up a sleeping debugger and exits\n -x sets second-chance break on AV exceptions\n -x{e|d|n|i} <event> sets the break status for the specified event\n -y <SymbolsPath> specifies the symbol search path (see _NT_SYMBOL_PATH)\n -z <CrashDmpFile> specifies the name of a crash dump file to debug\n -zd <CrashDmpFile> specifies the name of a crash dump file to debugand\n deletes that crash dump after the debugger has finished\n using it\n -zp <CrashPageFile> specifies the name of a page.dmp file to use with a\n crash dump\n -plmPackage <PlmPackageFullName> \n specifies the UWP package to be started. Needs '-plmApp' or '-plmPackage'\n option, but not both.\n -plmApp <PlmApplicationName> \n specifies the UWP application to be started. Needs '-plmPackage' option. \n -plmBgTaskId <PlmBackgroundTaskId> \n specifies the UWP background task to be activated. Needs '-plmPackage'\n option. \n\nEnvironment Variables:\n\n _NT_SYMBOL_PATH=[Drive:][Path]\n Specify symbol image path.\n\n _NT_ALT_SYMBOL_PATH=[Drive:][Path]\n Specify an alternate symbol image path.\n\n _NT_DEBUGGER_EXTENSION_PATH=[Drive:][Path]\n Specify a path which should be searched first for extensions dlls\n\n _NT_EXECUTABLE_IMAGE_PATH=[Drive:][Path]\n Specify executable image path.\n\n _NT_SOURCE_PATH=[Drive:][Path]\n Specify source file path.\n\n _NT_DEBUG_LOG_FILE_OPEN=filename\n If specified, all output will be written to this file from offset 0.\n\n _NT_DEBUG_LOG_FILE_APPEND=filename\n If specified, all output will be APPENDed to this file.\n\n _NT_DEBUG_HISTORY_SIZE=size\n Specifies the size of a server's output history in kilobytes\n\nControl Keys:\n\n <Ctrl-B><Enter> Quit debugger\n <Ctrl-C> Break into Target\n <Ctrl-F><Enter> Force a break into debuggee (same as Ctrl-C)\n <Ctrl-\\><Enter> Debug Current debugger\n <Ctrl-V><Enter> Toggle Verbose mode\n <Ctrl-W><Enter> Print version information\n", "children": [ "conhost.exe", "help.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RWD) C:\\Windows\\System32\\ntdll.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_webcache_counters_{9B6AB5B3-91BC-4097-835C-EA2DEC95E9CC}_S-1-5-21-2047949552-857980807-821054962-504": "Section", "\\BaseNamedObjects\\F932B6C7-3A20-46A0-B8A0-8894AA421973": "Section", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\sym\\ntdll.pdb\\1EB9FACB04C73C5DEA7160764CD333D01\\ntdll.pdb": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R-D) C:\\Windows\\System32\\en-US\\mswsock.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "convertstore.exe-C4F08E3B76A0472005D391741BCBB9CA": { "file_name": "convertstore.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\convertstore.exe", "hash_md5": "C4F08E3B76A0472005D391741BCBB9CA", "hash_sha1": "193DA32C5DDBCBAC3B2CD288CB94AD327AA4B16F", "hash_sha256": "3E7A8F01780176213898049D670A61BC4BA086A287C90D33B4329EC9C2E72EEA", "hash_sha384": "F97CBAC8C4ACEBFDEAA993E6102634F882702BD6E4330B86CB458DF088296DCC390FA19612198441FE99E526467E278E", "hash_sha512": "85D1ACF4CAF0D2EA5DB5A80EC5107FCB3C74E98A2D6BF2ED87130834AE46E50DCE9E6EB8AF24C2534CA29981F040E2B7957A8A7415EAEAE67489663F375654ED", "hash_ssdeep": "384:3XzN0IyjxeS7PeaQiOH95bNmWXm6V8u17UTnfRqvNWA9WbwGyEEglIi:Hp03QSjeaQiOnpzN8uVUb6BYPE", "hash_imp": "F093B9C92DA0564D9DFF7D3A02D59506", "hash_pesha1": "2FE606A53E3128B9772C5495DCCF73767D3D9F53", "hash_pe256": "E0AC0708D0FAEB100F12CE01A6AB4486502B7E7AEDA1C601CF8D97DE94743D72", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbol Store Conversion Utility", "meta_original_filename": "ConvertStore.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/3e7a8f01780176213898049d670a61bc4ba086a287c90d33b4329ec9c2e72eea/detection", "output": "convertstore.exe -s <StoreToConvert>\r\n Converts <StoreToConvert> from a 2-tiered symbol store\r\n to a 3-tiered symbol store.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\convertstore.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dbengprx.exe-CDB45C99D88514AEF61951A476E90FA8": { "file_name": "dbengprx.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbengprx.exe", "hash_md5": "CDB45C99D88514AEF61951A476E90FA8", "hash_sha1": "8909E36F7DF4D607CEF27D68D113DE3C537DC3B0", "hash_sha256": "0D535A4065BA70EF55D2C996F1AE1D7EC07FF90FF955067EEA9D8F6D411C44E7", "hash_sha384": "A47CB873EDDF46CD09FB314D9D7D9DCD9131CF1AB8CB2BCF9AC335E39B5231E166478DE8DB5EF617658E6523E449CD94", "hash_sha512": "A3863994FCF0770C8A9B48C78A356B6706FA65B989D4439579DD19A035602A2F93F14B08FF5DA874A0420764F85534502DE7779EF3F068CAF3067E2D6BF49CD2", "hash_ssdeep": "3072:sNrYdnUBMOXYR1UjJLbzmpmTeKNtKWoSJlIqarNl:sNrDM8UUVXamlIqar", "hash_imp": "FFD1762CC41F187D04C2E43B1563CE2F", "hash_pesha1": "F3654EB9615975E0D4E1E470A0EA57952AE42070", "hash_pe256": "56AA7BA628AF65B80D901997D46136A684EDE59EA2B1A9E3B4CB4347913928C8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Debugger Transport Proxy Server", "meta_original_filename": "dbengprx.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0d535a4065ba70ef55d2c996f1ae1d7ec07ff90ff955067eea9d8f6d411c44e7/detection", "output": "Invalid Command Line: Usage: dbengprx [-p] -c <transport> -s <transport>\r\n transport: tcp | npipe\r\n for tcp use: port=<socket port #>\r\n for npipe use: pipe=<name of pipe>\r\n\r\nExample: machine A = server, B = proxy, C = client\r\n A: start cdb -server tcp:port=1234 <...>\r\n B: start dbengprx -c tcp:port=1234,server=A -s tcp:port=1235\r\n C: start cdb -remote tcp:port=1235,server=B\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbengprx.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ADVAPI32.dll" ] }, "dbgrpc.exe-7B1170DF9EC45B45FD8B3CC3276FD805": { "file_name": "dbgrpc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbgrpc.exe", "hash_md5": "7B1170DF9EC45B45FD8B3CC3276FD805", "hash_sha1": "8EDDDB617A53663B72629C04A70C266F3AB1B55A", "hash_sha256": "60BAE2D1F4244411FF0E1ED4224EE54BC78C10BCA84407DEBF28C35B9A110C52", "hash_sha384": "C9CE68548C6EA11F7BD2F5487FFA4862A35F2B198121ADE309F7E360C408FC7910703A0FBC048D4069CD0888F1E3D41C", "hash_sha512": "EDD7AA08A7653235189F55A68C0858AA41A02AED0E5C6022206A1C4D22BAA8F8CF871FC8CB8543004680C618F4DD9BD9B973A2BD4084E9AF12DCB8B0071E2C57", "hash_ssdeep": "384:6ZakfbPGxN4BrVsY3knZM6PR5VkSSuv25vXZ4lrOo6MSzGUGjOmrYR/6XiaWIdWD:67fqxN4fV3u1jVaxRX+jMLK7y6Xi0Ex", "hash_imp": "9BE6C040F9ECFCF8EBDA4E75601DE412", "hash_pesha1": "182D013CF697FC1C725DF04EAF3F30281232A06A", "hash_pe256": "ECA3199B2313888629C1E9DC2BD3765E635946E8ECF3AEDDC3CAE69456363D8D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RPC Extended Debugging Utility", "meta_original_filename": "RpcDbg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/60bae2d1f4244411ff0e1ed4224ee54bc78c10bca84407debf28c35b9a110c52/detection", "output": "Usage: C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbgrpc.exe: -s <server> -p <protseq> -C <CallID> -I <IfStart>\r\n-N <ProcNum> -P <ProcessID> -L <CellID1.CellID2>\r\n-E <EndpointName> -T <ThreadID> -r <radix> -c -l -e -t -a\r\nExactly one of -c, -l, -e, -t, or -a have to be specified.\r\nThe valid combinations are:\r\n-c [-C <CallID>] [-I <IfStart>] [-N <ProcNum>] [-P <ProcessID>]\r\n-l -P <ProcessID> -L <CellID1.CellID2>\r\n-e [-E <EndpointName>]\r\n-t -P <ProcessID> [-T <ThreadID>]\r\n-a [-C <CallID>] [-I <IfStart>] [-N <ProcNum>] [-P <ProcessID>]\r\n-s, -p and -r are independent to the other options. -r affects\r\nonly options after it on the command line. Default is 16 (hex)\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbgrpc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dbgsrv.exe-2D7B08246EE468ECE6B155E9D45277E7": { "file_name": "dbgsrv.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbgsrv.exe", "hash_md5": "2D7B08246EE468ECE6B155E9D45277E7", "hash_sha1": "11E071B8C75A4E5F0D4509F690292DDE74713873", "hash_sha256": "2F6D63D7AD166230CFB4565EFAC54275D263BF0DEE504BAD412DA6013DE1A0EE", "hash_sha384": "68FAF13B9F74CE25153519C655200A7C0B3D4847BC17E20D63496BA45AB48ECFF86917F154F9490AF90704B1CDC0CB49", "hash_sha512": "B143785981C9399B0852867F209EC2EAE416C06268B751B2CD4C3F5B7A80E81377BB6798CBA3BBFDEAC5EDB0649B533807650A09AD9CECE1EB1042C3653FC750", "hash_ssdeep": "768:AKwPwV3VS4EmpYQfWTeKsFHh/YOWP5DUdLy+y8Z:nwPuVSrmpATeKihwOS5QwZ8", "hash_imp": "4EA6300403930A924A2CE2F955CE6984", "hash_pesha1": "8F1DB10518C1D6BFC59E05E40EB37F82ED9E55FD", "hash_pe256": "F7A3E092419F601AD27E93548EB458D2CE21836145800D45B15DB3F16EF2C382", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft User-Mode Debugger Process Server", "meta_original_filename": "dbgsrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2f6d63d7ad166230cfb4565efac54275d263bf0dee504bad412da6013de1a0ee/detection", "output": "Invalid Command Line: Usage: dbgsrv -t <transport> [-sifeo <image.ext>] [-x] [-c[s] <args...>] [-pc <args...>]\r\n transport: tcp | npipe | ssl | spipe | 1394 | com | hyperv \r\n for tcp use: port=<socket port #>\r\n for npipe use: pipe=<name of pipe>\r\n for 1394 use: channel=<channel #>\r\n for com use: port=<COM port>,baud=<baud rate>,\r\n channel=<channel #>\r\n for hyperv use: vmid=<vm id GUID>,serviceid=<service id GUID>\r\n for ssl and spipe see the documentation\r\n\r\nExample: dbgsrv -t npipe:pipe=foobar\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbgsrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbgeng.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbgmodel.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbghelp.dll", "C:\\Windows\\SYSTEM32\\XmlLite.dll", "C:\\Windows\\System32\\combase.dll" ] }, "dbh.exe-D127BA7DE7EA853CC0FB3AAF13CA9971": { "file_name": "dbh.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbh.exe", "hash_md5": "D127BA7DE7EA853CC0FB3AAF13CA9971", "hash_sha1": "91976A6B81BFA594E493A40200F937407745C622", "hash_sha256": "DC5ABBEE12193A7172A2660082456C184C5B41AAEB6AB4A11B32EFBC13603628", "hash_sha384": "CB441A5C2157514AB8309F7A89D4905EC24B213EFD995E059804E36FAD3D4479615D3022D06A8A717AC8E1AFBA953073", "hash_sha512": "1721590655B7418B70342D62A4068B6782E054C70CA78FBCA158CE509C587BB43DE9E6114CF4F561B912449EB7EADC877F5BE21181A23ED626B7A5C95FE2968A", "hash_ssdeep": "3072:Ivoi9MRxo+pHpvFWUblrbe15Nlca71UmSMfuCDyRwG3KgbED0ZXWelzUMnj:Ko0MRxo+pHpvPb5bKPp71hS0xedD1j", "hash_imp": "D807241920AE683668495947DA3CEC29", "hash_pesha1": "557B61BE8633CCAFAFA2F69D26B3A5FB246AF516", "hash_pe256": "B758D04D907E1FCB8EEAE6E7587248A3472B1B59E3E7119E866FC9B9BE797055", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Dbghelp API Example", "meta_original_filename": "dbh.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/dc5abbee12193a7172a2660082456c184c5b41aaeb6ab4a11b32efbc13603628/detection", "output": "\r\n dbh commands :\r\n? help : prints this message\r\nq quit : quits this program\r\nv verbose <on/off> : controls debug spew\r\n load <modname> : loads the requested module\r\nu unload : unloads the current module\r\nx enum <mask> : enumerates all matching symbols\r\nn name <symname> : finds a symbol by it's name\r\na addr <addr> : finds a symbol by it's hex address\r\nm enumaddr <addr> : lists all symbols with a certain hex address\r\nb base <address> : sets the new default base address\r\ns next <add/nam> : finds the symbol after the passed sym\r\np prev <add/nam> : finds the symbol before the passed sym\r\nl line <file#num> : finds the matching line number\r\n laddr <address> : finds a source line by it's corresponding hex address\r\nj linenext : goes to the next line after the current\r\nk lineprev : goes to the line previous to the current\r\nsrchtree <path> <file> : finds file in path\r\n ffpath <file> : finds file in symbol path\r\nr src <mask> : lists source files\r\n+ add <name addr> <sz> : adds symbols with passed name, address, & size\r\n- del <name/addr> : deletes symbols with passed name or address\r\nz locals <func> <mask> : finds all locals a function\r\n multi <name> : loads the requested module 1000 times\r\nt type <name> : lists the type information for the symbol\r\ni info : displays information about the loaded module\r\no obj <mask> : displays object files in the loaded module\r\ne elines <src> <obj>: enumerates lines with optional src mask and obj mask\r\n srch <parameters> : enumerates all symbols - use 'srch ?' for help\r\n dtag : displays all the symtag values\r\n undec <name> : undecorates a given symbol name\r\n findexe <name> <path> : locates an image in the symbol path\r\n finddbg <name> <path> : locates an dbg file in the symbol path\r\n sympath <path> : sets or displays the symbol search path\r\n dir <fname> <path> : calls EnumDirTree to find filename on path\r\n index <val> : finds symbol with matching index value\r\n scope <add/nam> : finds the parent of a symbol\r\n etypes : enumerates all types\r\n enummod : enumerates all modules\r\n sup <pth> <fil> <fil> : finds the symbol server supplement to store\r\n srvind <file> : finds the symbol server index for store\r\n srvpath <path> : tests if path is to a symbol store\r\nstoreadd <fil> <store> : adds a file to a symbol store\r\n getsym <img> <sym> : finds the matching symbol for and image\r\n getfile <name> <idx>> : finds a file based on the symbol server index\r\nsrclines <file> <line> : finds matching source lines\r\n mod <base> : changes default module\r\n refresh : refreshes the module list\r\n home <path> : sets the home directory\r\n omap : dumps the module omaps\r\n setret : toggle the return value of enum procs\r\n symopt <+/-><opt> : sets or displays the current symbol options\r\n epmod <process id> : enumerate the modules loaded for a given process\r\n dump : dumps all function symbols\r\n uw <address> : gets the unwind info for a function\r\n fii <file> : dumps the symsrv indexes for a binary and assciated files\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbh.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dumpchk.exe-63F2C7B079B12F9F44CD202644CD6AFF": { "file_name": "dumpchk.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dumpchk.exe", "hash_md5": "63F2C7B079B12F9F44CD202644CD6AFF", "hash_sha1": "49D2D932BD32F4B8FC4EEE41C1993C83F51DA242", "hash_sha256": "975087A447B166280112C8843AB3C68A21D5DD5AEB955D05E37510316B22CBEF", "hash_sha384": "CF2AF9DF1C0C4D7B8D483BB67C3D891E8A0645841B9FA64AAD9C1580115A8F95849F0EF14F18D0BE6101AD174748ABDB", "hash_sha512": "E62709FEC98904816CEA130E0902D4BDEA013C022D3C91605F5982B2D4FAEBFC8D124CA3CE6F426FD111BF3072D928D0A15E906E6DADB3B229EF9FFF35B25D49", "hash_ssdeep": "192:FfaNdEx9EweKjOTIbD+1mc5da2tGyVhKEOWfxW+WSawTyihVWQ4eWo0kwqnaj0:FiNygBKi8D+9dJmEOWfxWjwGyulI", "hash_imp": "1AC199C5E411E0B295927A9A9124DFE6", "hash_pesha1": "788F4A3CEC2C5D2CA02CC7B41B94DCBE41A34996", "hash_pe256": "3EB0D4B358DB64B23F6E7BEB368558C9AEA683BB574DAC8C342FFB93BE07D02B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Dump File Verifier", "meta_original_filename": "dumpchk.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/975087a447b166280112c8843ab3c68a21d5dd5aeb955d05e37510316b22cbef/detection", "error": "Usage: C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dumpchk.exe [-y <sympath>] <dumpfile>\r\n", "output": "\r\nMicrosoft (R) Windows Debugger Version 10.0.19041.1 AMD64\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\n\r\nLoading Dump File [C:\\Users\\user\\help]\r\nCould not match Dump File signature - invalid file format\r\nCould not open dump file [help], Win32 error 0n87\r\n \"The parameter is incorrect.\"\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dumpchk.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dumpexam.exe-9F3B915F04E4F1C060C5EE87C25C74DB": { "file_name": "dumpexam.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dumpexam.exe", "hash_md5": "9F3B915F04E4F1C060C5EE87C25C74DB", "hash_sha1": "82D72556D5BE0030F1426FD9304D92D6D2A6AF5F", "hash_sha256": "D034C7E7E5A18C42E26AE7914D0049C3C4CF1A7016586CDDD136D99DC810E733", "hash_sha384": "6EF85D7DF1B84F7E79A5481E88D8D08452449A231BCA6A2C18DDE1A6A67A0DFF8BF58524559A658DBA0A95A29B4F51A9", "hash_sha512": "D3E16214A0CD3BECF458E286C3DD8F175D076D5E0287325101D06C39F4767A35E550A37E8496D35722725B2AF7801E67BA4C7DADD50740A572F0DA1AD1D90CC0", "hash_ssdeep": "192:GcF+TrXEp+IWKsHfsB2n0O6DuxwL/GUFmsGWH4W2WSawTyihVWQ4eWFCikwqnaj0:GchAPa200xWusGWH4WrwGyslI", "hash_imp": "EBF7711815AEA5FEF6E675E749C32D0F", "hash_pesha1": "8040C162BF99969AE7AEF88A35BE459723A09B26", "hash_pe256": "435199F7289617C6625ADCD3A368E48A5EFD11FE047D477DDF86A87C152F48EB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Dump File Examiner", "meta_original_filename": "dumpexam.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/d034c7e7e5a18c42e26ae7914d0049c3c4cf1a7016586cddd136d99dc810e733/detection", "error": "\r\n\r\n\r\n\r\n***************************************************************************\r\n***************************************************************************\r\n** **\r\n** This tool is no longer supported. It's functionality has been **\r\n** merged into the kernel debugger. You can examine a dump file by **\r\n** loading it in the kernel debugger **\r\n** **\r\n** kd -z <dump_file_name> -y <symbol_path> [-i <image_path>] **\r\n** **\r\n** and running commands such as !vm, !process, !locks, etc... **\r\n** **\r\n** Please refer to the debugger documentation for more information **\r\n** on analyzing system failures. **\r\n** **\r\n***************************************************************************\r\n***************************************************************************\r\n\r\n\r\n\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dumpexam.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "gflags.exe-2687AF1BBEF4BB00CE45541A6D6F2FE1": { "file_name": "gflags.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\gflags.exe", "hash_md5": "2687AF1BBEF4BB00CE45541A6D6F2FE1", "hash_sha1": "A6BAB85D956788720CBA5F5465260C251A1999E5", "hash_sha256": "1604B95CF7D9CF278D619C0F73902790CE925C1E5C3A3F542E92293754160F64", "hash_sha384": "612DAC1469287DC4C2B033CE885A6D57ACDAD3E3BE86FA741F8192F7CD5E16E4C36AB5987F682AAAA4EDD627723ADA5A", "hash_sha512": "8C1B22D822466D45096819310B09E1A8310AD5D95F5DCE9D6A7EADCEB708E5A2712A816F707CFD494B51437B45328007EE3C75D70E8B71BCAEE65CACDC8C3B51", "hash_ssdeep": "1536:ou9HiFGPMBcno64xGtCZ5UfMt7HcmcAKxjouKT3K2jXBR+geRtk/VXfW9065:onfjxrKxjouG3jX+geRtk9X+9065", "hash_imp": "B8B3384C59DB7CB2D5236D97D33B7D3F", "hash_pesha1": "1C0E38E0B16941A3C612F636712B43268AD72128", "hash_pe256": "BE6C68FF24FF786EE3F863B85D847A3B12AA50015DF3B5F69A1E6E823CBDA5F6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft NT Global Flags Manipulator", "meta_original_filename": "GFLAGS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1604b95cf7d9cf278d619c0f73902790ce925c1e5c3a3f542e92293754160f64/detection", "error": "GFLAGS: Unexpected argument - '-help'\r\n \r\nusage: GFLAGS [-r [<Flags>]] | \r\n [-r +spp TAG | -r +spp SIZE | -r -spp | \r\n [-k [<Flags>]] | \r\n [-k +spp TAG | -k +spp SIZE | -k -spp] |\r\n [-ro [-d | { -i <ImageFileName> | -t <PoolTag>[;<PoolTag>...] } [-p] ] | \r\n [-ko [-d | { -i <ImageFileName> | -t <PoolTag>[;<PoolTag>...] } [-p] ] | \r\n [-i <ImageFileName> [<Flags>]] | \r\n [-i <ImageFileName> -tracedb <SizeInMb>] |\r\n [-p <PageHeapOptions>] (use `-p ?' for help) | \r\n \r\nwhere: <Flags> is a 32 bit hex number (0x12345678) that specifies \r\n one or more global flags to set. \r\n -r operates on system registry settings. \r\n -r +spp TAG - Set Special Pool tag value. \r\n TAG can have up to four characters. \r\n -r +spp SIZE - Set Special Pool block size value. \r\n SIZE must be in hex format, starting with characters 0x. \r\n -r -spp - Disable Special Pool tag or block size. \r\n -k operates on kernel settings of the running system. \r\n -k +spp TAG - Set Special Pool tag value at run time.\r\n TAG can have up to four characters.\r\n -k +spp SIZE - Set Special Pool block size value at run time.\r\n SIZE must be in hex format, starting with characters 0x.\r\n -k -spp - Disable Special Pool tag or block size at run time.\r\n -ro operates on object reference tracing at boot time. \r\n -ko operates on object reference tracing at run time. \r\n -d disables object reference tracing. Do not specify any \r\n other tracing options. \r\n -i <ImageFileName> specifies the image name for which \r\n to capture traces. All processes started up with this \r\n image file will be traced. \r\n -t <PoolTag>[;<PoolTag>...] specifies the pool tags for which \r\n to capture traces. Pool tags should be 4 letters each, \r\n separated by ';'. This value is case sensitive. \r\n -p maintains traces after the objects are destroyed(permanent).\r\n By default traces are temporary. \r\n Unless you are using -d you must specify at least one of the \r\n -i or the -p options. You may specify both in which case \r\n objects with a pool tag that is among the list of pool tags \r\n you specify, created by processes with the image filename \r\n you specify will be traced. -ko settings override -ro settings.\r\n Also, if you specify a new set of -ko settings the previous \r\n -ko settings, if any, are lost (same for -ro). \r\n -i operates on settings for a specific image file. \r\n [ignored when not suported in the current OS versions] \r\n \r\n If only the switch is specified, then current settings \r\n are displayed, not modified. If flags specified for -i \r\n option are FFFFFFFF, then registry entry for that image \r\n is deleted \r\n \r\nThe `-tracedb' option is used to set the size of the stack trace \r\ndatabase used to store runtime stack traces. The actual database \r\nwill be created if the `+ust' flag is set in a previous command. \r\n`-tracedb 0' will revert to the default size for the database. \r\n \r\nIf no arguments are specified to GFLAGS then it displays \r\na dialog box that allows the user to modify the global \r\nflag settings. \r\nNote: The dialog box is only displayed if the GflagsUI dll is available. \r\n \r\nFlags may either be a single hex number that specifies all \r\n32-bits of the GlobalFlags value, or it can be one or more \r\narguments, each beginning with a + or -, where the + means \r\nto set the corresponding bit(s) in the GlobalFlags and a - \r\nmeans to clear the corresponding bit(s). After the + or - \r\nmay be either a hex number or a three letter abbreviation \r\nfor a GlobalFlag. Valid abbreviations are: \r\n \r\n soe - Stop On Exception\r\n sls - Show Loader Snaps\r\n dic - Debug Initial Command\r\n shg - Stop on Hung GUI\r\n htc - Enable heap tail checking\r\n hfc - Enable heap free checking\r\n hpc - Enable heap parameter checking\r\n hvc - Enable heap validation on call\r\n vrf - Enable application verifier\r\n ptg - Enable pool tagging\r\n htg - Enable heap tagging\r\n ust - Create user mode stack trace database\r\n kst - Create kernel mode stack trace database\r\n otl - Maintain a list of objects for each type\r\n htd - Enable heap tagging by DLL\r\n dse - Disable stack extensions\r\n d32 - Enable debugging of Win32 Subsystem\r\n ksl - Enable loading of kernel debugger symbols\r\n dps - Disable paging of kernel stacks\r\n scb - Enable system critical breaks\r\n dhc - Disable Heap Coalesce on Free\r\n ece - Enable close exception\r\n eel - Enable exception logging\r\n eot - Enable object handle type tagging\r\n hpa - Enable page heap\r\n dwl - Debug WINLOGON\r\n ddp - Disable kernel mode DbgPrint output\r\n cse - Early critical section event creation\r\n sue - Stop on Unhandled Exception\r\n bhd - Enable bad handles detection\r\n dpd - Disable protected DLL verification\r\n lpg - Load image using large pages if possible\r\n\r\nAll images with ust enabled can be accessed in the\r\nUSTEnabled key under 'Image File Options'.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\gflags.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "kd.exe-041F14351DD7DEC476C2F2462F941712": { "file_name": "kd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\kd.exe", "hash_md5": "041F14351DD7DEC476C2F2462F941712", "hash_sha1": "0115B3FD2472187137C91176CC6EE62B8B8D9E5F", "hash_sha256": "09314C1C537D8A31458AA08CC308449EB10C0FEC5AF3F9022419C4816F822EF2", "hash_sha384": "551FA70E4A5320313EC12399E32BBB8A258B42DAE7BA9872B9677DB6ACDD913762B07D892AA036520DF74FBFB15539A6", "hash_sha512": "74E36920069238DA5A766D9EF62401765C5FB3372BEBA87F69CC0ED21280AF165A3C0E6321288C1AFDC86E9AF0FD986B7C7FC61295FF31C3EB24FECA84C15DE0", "hash_ssdeep": "3072:WXC0iTEjWsHD7DWErXLbDh/+DPVX7MQmpATeKlwW0QHgT+rdP98N0K:WXCejWsHLW+h/nW0QHS+rdqL", "hash_imp": "A02C20CEEB14CDC45B9CB6B449313073", "hash_pesha1": "ABD9F5AFFF4A20388A840383532F31929BD86256", "hash_pe256": "C2E061962B4065B3ECCECB4A91435284ECC88F3DB190C50797D1A366942EB632", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Kernel Debugger", "meta_original_filename": "kd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/09314c1c537d8a31458aa08cc308449eb10c0fec5af3f9022419c4816f822ef2/detection", "output": "kd: Invalid switch 'h'\nkd version 10.0.19041.1\nusage: kd [options]\n\nOptions:\n\n -? displays command line help text\n -a<DllName> adds a default extension DLL\n -b break into kernel when connection is established\n -bonc request break in after session started\n -c \"<command>\" executes the given debugger command at the first debugger\n prompt\n -cf <file> specifies a script file to be processed at the first debugger\n prompt\n -cfr <file> specifies a script file to be processed at the beginning of a\n session (including after .restart)\n -clines <#> number of lines of output history retrieved by a remote client\n -d breaks into kernel on first module load\n -ee <name> set default expression evaluator\n <name> can be MASM or C++\n -failinc causes incomplete symbol and module loads to fail\n -i <ImagePath> specifies the location of the executables that generated the\n fault (see _NT_EXECUTABLE_IMAGE_PATH)\n -iu install dbgeng URL protocols\n -k <options> tells the debugger how to connect to the target\n net:port=n,key=w.x.y.z[,target=name] connects over the network\n n: network port number, must match port assigned to target\n w.x.y.z: key assigned to target machine\n name: optional VM host machine name, used if debugging VMs\n usb:targetname=name connects over USB\n name: USB target name assigned to target machine\n 1394:channel=chan connects over 1394\n chan: 1394 channel number, must match channel used at boot\n com:modem connects through a modem\n com:port=id,baud=rate connects through a COM port\n id: com port name, of the form com2 or \\\\.\\com12\n rate: valid baudrate value, such as 57600\n -kl tells the debugger to connect to the local machine\n -kqm turns on kd quiet mode (equivalent to KDQUIET)\n -kx <options> tells the debugger to connect to an eXDI driver\n -lines requests that line number information be used if present\n -loga <logfile> appends to a log file\n -logau <logfile> appends to an Unicode log file\n -logo <logfile> opens a new log file\n -logou <logfile> opens a new Unicode log file\n -m serial port is a modem, watch for carrier detect\n -myob ignores version mismatches in DBGHELP.DLL\n -n enables verbose output from symbol handler\n -noio disables all I/O\n -noshell disables the .shell (!!) command\n -nosqm disables SQM data collection/upload.\n -QR \\\\<machine> queries for remote servers\n -r display registers\n -remote <transport>:server=<name>,<params> \n lets you connect to a debugger session started with -server\n must be the first argument if present\n transport: tcp | npipe | ssl | spipe | 1394 | com\n name: machine name on which the debug server was created\n params: parameters the debugger server was created with\n for tcp use: port=<socket port #>\n for npipe use: pipe=<name of pipe>\n for 1394 use: channel=<channel #>\n for com use: port=<COM port>,baud=<baud rate>,\n channel=<channel #>\n for ssl and spipe see the documentation\n example: ... -remote npipe:server=yourmachine,pipe=foobar\n -s disables lazy symbol loading\n -sdce pops up dialogs for critical errors\n -secure disallows operations dangerous for the host\n -server <transport>:<params> \n creates a debugger session other people can connect to\n must be the first argument if present\n transport: tcp | npipe | ssl | spipe | 1394 | com\n params: connection parameterization\n for tcp use: port=<socket port #>\n for npipe use: pipe=<name of pipe>\n for 1394 use: channel=<channel #>\n for com use: port=<COM port>,baud=<baud rate>,\n channel=<channel #>\n for ssl and spipe see the documentation\n example: ... -server npipe:pipe=foobar\n -ses enables strict symbol loading\n -sflags <flags> sets symbol flags from a numeric argument\n -sicv ignores the CV record when symbol loading\n -sins ignores the symbol path environment variables\n -snc converts :: to __ in symbol names\n -snul disables automatic symbol loading for unqualified names\n -srcpath <SourcePath> specifies the source search path\n -sup enables full public symbol searches\n -t Enable KD transport related output (CTRL+D output) by default.\n -v enables verbose output from debugger\n -version shows the build version\n -wake <pid> wakes up a sleeping debugger and exits\n -x same as -b, except uses an initial command of eb NtGlobalFlag 9;g\n -y <SymbolsPath> specifies the symbol search path (see _NT_SYMBOL_PATH)\n -z <CrashDmpFile> specifies the name of a crash dump file to debug\n -zd <CrashDmpFile> specifies the name of a crash dump file to debugand\n deletes that crash dump after the debugger has finished\n using it\n -zp <CrashPageFile> specifies the name of a page.dmp file to use with a\n crash dump\n\nEnvironment Variables:\n\n _NT_SYMBOL_PATH=[Drive:][Path]\n Specify symbol image path.\n\n _NT_ALT_SYMBOL_PATH=[Drive:][Path]\n Specify an alternate symbol image path.\n\n _NT_DEBUGGER_EXTENSION_PATH=[Drive:][Path]\n Specify a path which should be searched first for extensions dlls\n\n _NT_EXECUTABLE_IMAGE_PATH=[Drive:][Path]\n Specify executable image path.\n\n _NT_SOURCE_PATH=[Drive:][Path]\n Specify source file path.\n\n _NT_DEBUG_LOG_FILE_OPEN=filename\n If specified, all output will be written to this file from offset 0.\n\n _NT_DEBUG_LOG_FILE_APPEND=filename\n If specified, all output will be APPENDed to this file.\n\n _NT_DEBUG_HISTORY_SIZE=size\n Specifies the size of a server's output history in kilobytes\n _NT_DEBUG_BUS=1394\n Specifies the type of BUS the kernel debugger will use to communicate with the target\n\n _NT_DEBUG_1394_CHANNEL=number\n Specifies the channel to be used over the 1394 bus\n\n _NT_DEBUG_PORT=com[1|2|...]\n Specify which com port to use. (Default = com1)\n\n _NT_DEBUG_BAUD_RATE=baud rate\n Specify the baud rate used by debugging serial port. (Default = 19200)\n\n _NT_DEBUG_CACHE_SIZE=x\n If specified, gives the number of bytes cached on debugger side\n of kernel debugger serial connection (default is 102400).\n\n KDQUIET=anything\n If defined, disables obnoxious warning message displayed when user\n presses Ctrl-C\n\n\nControl Keys:\n\n <Ctrl-A><Enter> Toggle BaudRate\n <Ctrl-B><Enter> Quit debugger\n <Ctrl-C> Break into Target\n <Ctrl-D><Enter> Display debugger debugging information\n <Ctrl-F><Enter> Force a break into the kernel (same as Ctrl-C)\n <Ctrl-K><Enter> Toggle Initial Breakpoint\n <Ctrl-\\><Enter> Debug Current debugger\n <Ctrl-R><Enter> Resynchronize target and host\n <Ctrl-V><Enter> Toggle Verbose mode\n <Ctrl-W><Enter> Print version information\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\kd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "kdbgctrl.exe-1FAB8BF1AA6954B89DE2490BC6345A91": { "file_name": "kdbgctrl.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\kdbgctrl.exe", "hash_md5": "1FAB8BF1AA6954B89DE2490BC6345A91", "hash_sha1": "46C5E6002DF74F9724539F99EF40C02B5EEC6E39", "hash_sha256": "FD5C21D94F7342E5F4080B9424FEC378DF62D827579DFDB534B38FDC8C8ACFBE", "hash_sha384": "D8F74AAFE84EF5BBED2783F92C193E2AD875F4E90CA866E8ECA81691A7769E7C84EDFBE0242BDAC3304704B260ADBE8A", "hash_sha512": "51FF5235643B729548BD88814F317806C004F2F26536E5CBD46CE8A94A4A7E2B87F286F2B940C951A10EFE66F8CC584C28E1B22EEA0C4376725EE1B06837D840", "hash_ssdeep": "768:LGpiXKk4PuNAhq/esZmpeQfWTeK8AUaW/8hXRG+Hg:tX3zAhq/BmpGTeK8IW8hXRG+A", "hash_imp": "697390BDE2745169AF6142896A42ADEA", "hash_pesha1": "566AED31E2599F6A7BBB5169B28F30E0C507DDCC", "hash_pe256": "8E4F2301F783FFD44DF00F042C458CE46E27BF5E0B297C9081675F510D8DB56D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows kernel debugger configuration utility", "meta_original_filename": "kdbgctrl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/fd5c21d94f7342e5f4080b9424fec378df62d827579dfdb534b38fdc8c8acfbe/detection", "output": "Usage: C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\kdbgctrl.exe <options>\r\nOptions:\r\n -c - Check kernel debugger\r\n -ca - Check kernel debugger auto-enable\r\n -cb - Check kernel debugger block-enable\r\n -cdb - Check kernel DbgPrint buffer size\r\n -cu - Check kernel debugger user exception handling\r\n -cx - Check kernel debugger enable and exit with status\r\n -d - Disable kernel debugger\r\n -da - Disable kernel debugger auto-enable\r\n -db - Disable kernel debugger block-enable\r\n -du - Disable kernel debugger user exception handling\r\n -e - Enable kernel debugger\r\n -ea - Enable kernel debugger auto-enable\r\n -eb - Enable kernel debugger block-enable\r\n -eu - Enable kernel debugger user exception handling\r\n -sdb <size> - Set kernel DbgPrint buffer size\r\n -td <pid> <file> - Get a kernel triage dump\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\kdbgctrl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "kdnet.exe-06906FBC21BFC19615A182CCB356794E": { "file_name": "kdnet.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\kdnet.exe", "hash_md5": "06906FBC21BFC19615A182CCB356794E", "hash_sha1": "5ADCE7DE29CB8560450176FC8D7DCDC1F10BD82B", "hash_sha256": "0DB5A4DCB3BE5ABE889B94A976C203B303CBB189C4DED0C97BE7B81BD1569EBC", "hash_sha384": "72527D479C8AB0C26998840DC2B77F1E5683ED3140211CCBFA081DF10F1130CD95F9E1FEF9D0A3AB56575B2AA24A145C", "hash_sha512": "D22D6961AA457C7E90F7063F9CBF0E3862F7F29F4ECFD7C5FB95C6686BCD37EFF23759FF21012DBE2A1858B4753DC7BE80705406C166BD430D73B31C28A53E55", "hash_ssdeep": "768:49ghuT6KCEY0rPY10TQ7wc1CPJYJlrdXpGbJ5S+mQKar7UvI+3o4tAKGdV5:ggoCEY0rQyRs35W5IQKAIvI+3ZVGd", "hash_imp": "5697E1DEEEC21ACCCAA8B1AE2CBE0EC6", "hash_pesha1": "AD9C25A847BE2E8CCC4E5F3CBCF127C24A2C2CB8", "hash_pe256": "AD57848D21FF448B8314055700F3FF6ED108EF7393086B0A541C03259D7E4940", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Net debugging configuration tool", "meta_original_filename": "kdnet.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0db5a4dcb3be5abe889b94a976c203b303cbb189c4ded0c97be7b81bd1569ebc/detection", "output": "\r\nkdnet.exe [debug_host] [debug_port]\r\n [debug_host] is the name of the host machine running the debugger.\r\n [debug_port] is the network port to use for debugging this machine.\r\n\r\nkdnet.exe /xml\r\n\r\nkdnet.exe /busparams [debug_device] [debug_host] [debug_port]\r\n [debug_device] is the busparams of the debug Device to configure.\r\n [debug_host] is the name of the host machine running the debugger.\r\n [debug_port] is the network port to use for debugging this machine.\r\n\r\nWhen run without parameters, kdnet.exe identifies the NICs and USB3\r\ncontrollers which support network debugging. When run with parameters\r\nkdnet.exe enables network debugging using the specified information.\r\nIf [debug_port] is not specified then it will be set to a default\r\nvalue of 5364.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\kdnet.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "kdsrv.exe-2FD3B6C74E48584FCFB66D64F6994747": { "file_name": "kdsrv.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\kdsrv.exe", "hash_md5": "2FD3B6C74E48584FCFB66D64F6994747", "hash_sha1": "92A26C448E87E874FF7796B1C3B4F1AB63F5CAC8", "hash_sha256": "6D2807F32A87DE9B0167136721B9F8332C1A58F33FC4792155D880052FC5B7F7", "hash_sha384": "245659F4A182177FC0F72E862879B8058DFBE684739E1D23933429F31920383DFE4761ECF27FDBE5D8AB3021BD1C1EA9", "hash_sha512": "C45AB7D2614C8A7ED6885DB58722869DA2178C556ABA905198105C0EBB97A9DBC1B9CDBF8BF8687DE442BA30C6F8ADA6205C04DD915DEBB57F13E9B3C49BBDA4", "hash_ssdeep": "3072:jcdLM8Omj79t4N27dH7SReekIdt1sompmTeKJhCK/oOMqqD8XK3MH0a80ChXk:jcRM4bHH7uHsSolqqDFaYJ", "hash_imp": "EDEF8B0D306E305E62CB5B7C16E66E21", "hash_pesha1": "6DEE18626B98D34E2C0F439F3C4D774F127FC728", "hash_pe256": "1B419FEC40B25577294B0DFD4DC170FDC54B837A430D180763C29C05CA5EB057", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Kernel Debugger Connection Server", "meta_original_filename": "kdsrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6d2807f32a87de9b0167136721b9f8332c1a58f33fc4792155d880052fc5b7f7/detection", "output": "Error 0x80070057: Server initialization\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\kdsrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\WS2_32.dll" ] }, "KernelDumpDecrypt.exe-7236DD7BB0053E540A396C483755E7FC": { "file_name": "KernelDumpDecrypt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\KernelDumpDecrypt.exe", "hash_md5": "7236DD7BB0053E540A396C483755E7FC", "hash_sha1": "8B80C883F0B16C4F5FABE30971303A7B240711F3", "hash_sha256": "A629705EBC2205EE0C565E397E93814A46BA40A35E981FBC8B8F0EBF8D8E2E95", "hash_sha384": "76E9F094144EEE54506B065CFE9849224A0ACE1C1F138ECFD3AEFD02008F2F2D16BA96CAF95E59B92CF0E886C91BC6AB", "hash_sha512": "B05D970C87654E10954D498046636A0BCE97884A547ECC18BD2FF7A5BA424CE6D4DB3E011B82AB4356DCF23F748B0E52DDDD23D7956CC90CEFB5AC6259C6D3E1", "hash_ssdeep": "384:LtSsmphK0Wvpv81zpqv2f0x8FYaHeaq/SWoXWEYwGyAlITvb:Jjcwe1F1yCeFcOov", "hash_imp": "4831C665BDBFB7166F68E6FB09509318", "hash_pesha1": "B2BFDDBC2767DE31FE60CEBDF5DDA8E2898652CC", "hash_pe256": "8B169AE37C89B2C0E61B2AEC836896071AE8F2D3B62A5D48ACAE727B6E0B4031", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Kernel Dump File Decryptor", "meta_original_filename": "KernelDumpDecrypt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a629705ebc2205ee0c565e397e93814a46ba40a35e981fbc8b8f0ebf8d8e2e95/detection", "output": "Usage: KernelDumpDecrypt [args] <input.dmp> <output.dmp>\r\nWhere args is a sequence of the following:\r\n\t/user - Use user certificate store/key store.\r\n\t/machine - Use machine certificate store/key store.\r\n\t/keystore <name> - Name of the key store provider.\r\n\t/keyname <name> - Name of the key to lookup in the KSP.\r\n\t/keyfile <path> - Path to the file containing a raw private key\r\n\t or a full key pair (starts with 'RSA2' magic).\r\n\t/enumproviders - List key store providers.\r\n\t/enumkeys - List keys in the key store.\r\n\r\nIf no key parameters are specified, the tool looks up the certificate\r\nmatching the thumbprint contained in the encrypted dump file.\r\nIf only the keyname is specified, the key will be retrieved from the\r\ndefault key store for the current user.\r\n\r\nExamples:\r\n\r\nKernelDumpDecrypt memory.dmp memory_decr.dmp\r\n\tDecrypts memory.dmp using the private key obtained from the\r\n\tcurrent user's certificate store. Writes memory_decr.dmp.\r\n\r\nKernelDumpDecrypt /machine memory.dmp memory_decr.dmp\r\n\tDecrypts the dump using a key obtained from the local\r\n\tmachine's certificate store.\r\n\r\nKernelDumpDecrypt /user /keyname \"My app key\" memory.dmp memory_decr.dmp\r\n\tDecrypts the dump using named key in the\r\n\tuser store of the default key storage provider\r\n\r\n\r\nExit status: SUCCEEDED: 00000000: The operation completed successfully.\r\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\KernelDumpDecrypt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "kill.exe-1068294A19FE12065DE0A97BA0ABB627": { "file_name": "kill.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\kill.exe", "hash_md5": "1068294A19FE12065DE0A97BA0ABB627", "hash_sha1": "FF523C049584554159A586E58A02351C6C4CA775", "hash_sha256": "02B7A8389602DA429607650F15E20250ACB1DF754C5DB3118E0F3542E1D5A316", "hash_sha384": "3350EFAE3490B29F0EE1B6C44205A2A8156D745FC8B98B41C72186D908BF481A8115DC92D8117BCEB823507B0E9A6180", "hash_sha512": "B21603B08D75DD4EE97F7F6AEFE83F430FADE022720A5D115DEDA85ABC926568024BC250D44DC69BA5C3F980512F544830BFA5FECA104EE39489D7F203A9526C", "hash_ssdeep": "384:T+n+EwU6KhfPRQiXdr3g019+UN1Cjyq45RJRi6IiWciqvWLwGyy4ulI:T++EH6wPR/wORz1xbJ3Ik+i", "hash_imp": "DA6D5C1049DA679AB196D41CA3A57EE3", "hash_pesha1": "6AC1EF2D70F0C837C688E2247E323EA23F3F2753", "hash_pe256": "B3312AC61D1CC4F907198B60DDB3DBC71BAB82D1919D19976F07DA5E6738621E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Process Kill Utility", "meta_original_filename": "kill.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/02b7a8389602da429607650f15e20250acb1df754c5db3118e0f3542e1d5a316/detection", "error": "Microsoft (R) Windows NT (TM) Version 3.5 KILL\r\nCopyright (C) 1994-1998 Microsoft Corp. All rights reserved\r\n\r\nusage: KILL [options] <<pid> | <pattern>>*\r\n\r\n [options]:\r\n -f Force process kill\r\n\r\n <pid>\r\n This is the process id for the task\r\n to be killed. Use TLIST to get a\r\n valid pid\r\n\r\n <pattern>\r\n The pattern can be a complete task\r\n name or a regular expression pattern\r\n to use as a match. Kill matches the\r\n supplied pattern against the task names\r\n and the window titles.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\kill.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "list.exe-02FABE339B0F5DBCC7E5C88243B46B7C": { "file_name": "list.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\list.exe", "hash_md5": "02FABE339B0F5DBCC7E5C88243B46B7C", "hash_sha1": "57571BB40351D3791E284730739F0C29DAF4DA45", "hash_sha256": "AC1A48B17543A37655B1BEFDE747BFDD99360A86F41E6E84C1F828C5DB6BBF2D", "hash_sha384": "796D6D25151698A8C42CAEBF3C3C95220025DDD86EE044FF046A3FC3443FD37F203392E8B67E8A420636509B65510EF7", "hash_sha512": "087E102AF816D521AA9765A925857F05D9494C2266E0FD0FD21660290444432DF4D6F6062DF5C1EDCDD89A9757762711FE2A063AEE700CE98DB4398642E214F6", "hash_ssdeep": "1536:Xn5EUQTUKXs8LnPhia1W9G8bh4A9ip4W9OXxsXQ58OPT8sFo:Xn5QwQ6bh4A9q4jCyZFo", "hash_imp": "D176963A2A09326A75676A6B302B30D3", "hash_pesha1": "5E38434B0AA6D630EB2F83B62E4251A4EB40348A", "hash_pe256": "4670E1AD7DF3C2352BC730F0951DDD9C4F0722C950FE36AB39A8F5352ACC79B5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft File Lister", "meta_original_filename": "list.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/ac1a48b17543a37655b1befde747bfdd99360a86f41e6e84c1f828c5db6bbf2d/detection", "output": "list [-s:string] [-g:line#] filename, ...\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\list.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "logger.exe-5292EA7480417BDFD072BDBDF3E6A0AD": { "file_name": "logger.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe", "hash_md5": "5292EA7480417BDFD072BDBDF3E6A0AD", "hash_sha1": "56178670CE5C14F59A9AEB24B5BE0209615513B7", "hash_sha256": "388767F42AE5FCF196C152C351DF814CE14A85B4AF1EA63ADB10622DE0FF989C", "hash_sha384": "EAC30476AD4BE29F8D8930614002C05C798DA20D8E899921CB1194FA31B21D42513FDB8D75DD697315911527FEF3D13A", "hash_sha512": "BB277AD59B9CB1CD1124023AA6F09BB72645F86BE0059FF76E9777AD2B56059D082DCD06CF1F810775A4D02D657CB94D4D3BCFC313344BD8651A2534B06AFA06", "hash_ssdeep": "6144:oyKgLwznzYqesLqpk7wpMLRh71aO1X1zZ/uvlzQI+7kk:sTcqeve5lQlcP", "hash_imp": "53806EF788FB600B613567AA1B57D6F0", "hash_pesha1": "593C1278FD2886DAC7ABC8BD74D3C692B7D2B9A3", "hash_pe256": "B0DB2826AC8C64459420A35D1B2A9D231D13DE6CC98FC9E475BDDBB5502230F6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/388767f42ae5fcf196c152c351df814ce14a85b4af1ea63adb10622de0ff989c/detection", "children": "conhost.exe", "runtime_window_title": "Error", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "logviewer.exe-D8E92CA6D3E59FEA8D8B5F536A2EB6FC": { "file_name": "logviewer.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logviewer.exe", "hash_md5": "D8E92CA6D3E59FEA8D8B5F536A2EB6FC", "hash_sha1": "7ABC180282F0CD5B0317675B5D318D222C4A07C4", "hash_sha256": "634935E2C023E287ED583E45804E89EE8D5F8F095E442B2083CD1E9B49F7060C", "hash_sha384": "2458FA884AEA7343DCA9E1E8B2AEF24494D95DB345FE10AA220F8A0B51B19BD601ABABF7725B2DC63AC49CF1CE15FBF2", "hash_sha512": "00AE3BA2626DB1FFDAF15CD9B6B3C5DC9B7065DD1AD8990E54B88E689B9E30028A68E739EDA2BABC10D744A1541B2685F8C245F211D414928E8B4B19C8547FE5", "hash_ssdeep": "6144:U6TnX0VBdZse9IfQpvQjbu107B/JbtP3ewn5M:U6TnX07dStP3V", "hash_imp": "646B87ED040ECFDC099239FEC5763255", "hash_pesha1": "040008402BA6B7A0C341216F9DF7D5A64FBB9E17", "hash_pe256": "3F4FD21389A18222B310E5C8E142497ECE4307EAF7678FB9C2E318868EA61D98", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logviewer.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Win32 API Log Viewer", "meta_original_filename": "LogViewer.exe", "meta_product_name": "Logging/Debugging Tools for Windows(R)", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.02 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/634935e2c023e287ed583e45804e89ee8d5f8f095e442b2083cd1e9b49f7060c/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Users\\user\\--help": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logviewer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\msvcrt.dll" ], "runtime_window_title": "Error" }, "ntkd.exe-518942A9C2EEBC5A824BCE51F2536AB3": { "file_name": "ntkd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntkd.exe", "hash_md5": "518942A9C2EEBC5A824BCE51F2536AB3", "hash_sha1": "0281B22D8DB3DAEEC86FE134291E882042B6ADB7", "hash_sha256": "BEDE8DE4FCF51B74E14AB2970861503CEB91C251B81E3CDB97CE2EE4FB8B6688", "hash_sha384": "863A11142D271C774A433C20D810CA9BA20223A0EA4BB73258D00A774B23338032092A824562DE8C0A49A0B06272C7AB", "hash_sha512": "01E4A9AB3B101688FBF19140159BEFB7731FCB59029C8789FC9577C68CD82093682E748B0E7ACB37DB31086D3FA9A7EBEDB1FFEA88B273E016B2B8105945DD23", "hash_ssdeep": "3072:5YEIF3Ce2SqsnM+GZVX7MBmpATeK9Wc0QyJEAYT:5YE+CeF7M9c0QsEAY", "hash_imp": "ED48E803B3F981E212CC99B18B589295", "hash_pesha1": "6C78239C974400A52AA6391051B26FB53628981C", "hash_pe256": "2E5DE400BBCAB7294A88E6D66CBFC07292D31FA0C6AD970966AAC5CD425BE499", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Kernel Debugger", "meta_original_filename": "ntkd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/bede8de4fcf51b74e14ab2970861503ceb91c251b81e3cdb97ce2ee4fb8b6688/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntkd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbgeng.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcrypt.dll" ], "runtime_window_title": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntkd.exe" }, "ntsd.exe-B5BC3A27E60D60EEA47608C3E2B35FD1": { "file_name": "ntsd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntsd.exe", "hash_md5": "B5BC3A27E60D60EEA47608C3E2B35FD1", "hash_sha1": "C6E9F65CE2CBC4D6AAD748F82407FA2631D4F049", "hash_sha256": "15730D0FB2B857972371FA03910474E0971D0F2DA7999C1D606C74C475DD2899", "hash_sha384": "702D2804663FF96D5BC9373B940CBE89C4F05CB0B8232E2114BBD835881674DB379F972FCD18ED10DAE993F1B9C1FDF8", "hash_sha512": "24A923E1FB822F20312FF231E4C5D9A1D231B451D9C7990553B8671E27C41220196C0C363A816F1D01DFEBB109509FE2C5E7DB8E85E8D7EB33490F9E55C7B7D3", "hash_ssdeep": "3072:P8906DXGgoIokGcz7+JBVX7MpmpATeKzA0QKMg83J:P89tDXGUokGC7q0QKMg83", "hash_imp": "81BC91DB7CF89B0EDDA000530F72E4FA", "hash_pesha1": "3A139ACDDEB84D467C668DBBC1DE7903F5D709FC", "hash_pe256": "90120AEA4F03002EC7C5E26D45B4720E82209EDD1D87D094FA9C2C688DB9F115", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbolic Debugger for Windows", "meta_original_filename": "NTSD.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/15730d0fb2b857972371fa03910474e0971d0f2da7999c1d606c74c475dd2899/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RWD) C:\\Windows\\System32\\ntdll.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\sym\\ntdll.pdb\\1EB9FACB04C73C5DEA7160764CD333D01\\ntdll.pdb": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_window_title": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntsd.exe", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntsd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbgeng.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcrypt.dll" ] }, "OffDumpTool.exe-E88793B02D14AD912D4421D90098E166": { "file_name": "OffDumpTool.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\OffDumpTool.exe", "hash_md5": "E88793B02D14AD912D4421D90098E166", "hash_sha1": "1DE208B9FD82545454E08A790373AE81A53EF423", "hash_sha256": "5C2F19D77A8064E34D1711D13A377882A36B4C2F63FD2683F76F3172F2704801", "hash_sha384": "B29EA453A8685EB8C2908629E5758BB299FAD0DAC2ADD270129C631B5D445F929033773E42CB79B39DBB091D3D6C15DC", "hash_sha512": "99FFF64AB576CA514A0AD51E6DB242D4DAB178470284DDCA128F23335F946251DD2F1268E86B33363A9F985767972299EB30116E9E40FCDC63546BCBCCAF5834", "hash_ssdeep": "3072:VzhaACBMODsYnzyysiCWgqZBnWkCdtiRO10xhGJHsVysVTVhOMsMtE:VzhaznDsYnzy1/WgkxnlyV", "hash_imp": "619C42374CE64AE6BCF4F4F04F4AEFF9", "hash_pesha1": "5F55630E3EFD5A9292FBBDD46E40D6D340E4F1DB", "hash_pe256": "8E36281E315FF24CDA38510A096498570999C003C625071C1C3D321018746920", "signature_status": 1, "signature_status_message": "A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider", "signature_serial": "33000003A2973D2E4F88A4ECA10000000003A2", "signature_thumbprint": "59A344D03FA3079B29AF4EA80C6E37C7102848D9", "signature_issuer": "CN=Microsoft Testing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "OfflineDump Tool EXECUTABLE", "meta_original_filename": "offdumptool.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5c2f19d77a8064e34d1711d13a377882a36b4c2f63fd2683f76f3172f2704801/detection", "output": "Device string in use: $localpub:qsize=0($LogFile:file=OfflineDumpTool.wtl,encoding=UNICODE,writemode=overwrite;$Console;$Debugger)\r\r\nWTTLogger_CPP_GitEnlistment(winpbld); Version: 2.7.3483.0\r\r\n\r\n====Offline Dump Tool Version = 10.0.19041.1 (WinBuild.160101.0800)====\r\n\r\r\nMachine: Build=19041.00 \r\r\n\tPlatform=AMD64 \r\r\n\tOS=Windows 10 Enterprise \r\r\n\tServicePack=\"\" \r\r\n\tVersion=6.3 \r\r\n\tBuildLab=\"vb_release\" \r\r\n\tBuildDate=191206-1406 \r\r\n\tLanguage=English (US) (REDMOND) \r\r\n\tConfig=n/a \r\r\n\r\r\nofflinedump test tool.\r\nBackground and Assumptions:\r\n This utility:\r\n - Takes input that conforms to the Microsoft Offline Dump Specification\r\n - Must be run as an administrator\r\n - Denotes System under Test (SUT) as the System that crashed\r\n - Denotes Debug System (DS) as system running the Windows debugger\r\n \r\n The System Under Test (SUT):\r\n - Has a disk partition suitable for storing an offline crash\r\n - May be distinct from the Debug System (DS)\r\n - May be a different system architecture from the Debug System\r\n \r\n To expedite debugging, two distinct systems are recommended\r\n This is based on assumption, relative to SUT:\r\n - The Debug System has greater stability\r\n - The Debug System has higher performance\r\n \r\n The file extension has the following conventions:\r\n .RAW (Raw Partition saved as a File)\r\n [Output or Input to Tool]\r\n .DMP (Windows Dump File loadable by Windows Debugger)\r\n [Output from Tool]\r\n Windows Phone: [Input to Tool]\r\n .BIN (Silicon Vendor Specific BIN File)\r\n [Output from Tool]\r\n .DDR (DDR memory sections File)\r\n [Input to Tool]\r\n \r\n \r\nBASIC Usage Commands:\r\n /help\r\n This help text\r\n \r\n /parsepart\r\n This will Parse the Raw_Dump Partition and create:\r\n .DMP = Windows Dump file \r\n .BIN = Silicon vendor specific bins\r\n Example: offlinedumptool /parsepart\r\n Note: Must run command on System under Test (SUT)\r\n Output file: raw_dump.DMP, <possibly others>\r\n Exact output filenames encoded in headers of Offline Specification\r\n \r\n /zeropart\r\n Wipes the contents of dedicated raw dump partition by filling it with zeros.\r\n \r\n /wipedump\r\n Wipes the raw dump header in the dedicated partition.\r\n \r\n /dumprawpart <DUMPFILE.RAW>\r\n This will dump the raw dump partition to a file. \r\n Example: offlinedumptool /dumprawpart dumpfile.raw\r\n Note: Must run command on System under Test (SUT)\r\n Output .RAW file is further processed using the /parsedump option\r\n \r\n /parsedump <DUMPFILE.RAW> \r\n This will open the Raw_Dump Partition file as raw dump and parse the headers. \r\n Example: offlinedumptool /parsedump DUMPFILE.RAW \r\n Note: .BIN file can be processed using this utility on Debug System\r\n Exact output filenames encoded in headers of Offline Specification\r\n Output file: raw_dump.DMP\r\n option /noapreg will not attempt to process APREG section\r\n \r\n /parsewpdump <WP_DUMPFILE.DMP>\r\n It will extract WP silicon vendor sections from WP dump secondary data and save as .bins \r\n Example: offlinedumptool /parsewpdump memory.dmp\r\n Note: Windows Phone Specific Option, all other options are supported exclusively for Windows\r\n Must run command on .DMP file from Windows Phone System under Test (SUT)\r\n The input .DMP file is generated from another Windows Phone tool\r\n Output file(s): <section>.BIN ...\r\n Exact output filenames encoded in headers of Offline Specification\r\n \r\n OPTIONAL ADD ON COMMANDS :-\r\n /noapreg \r\n Does not attempt to find APREG in the DDR sections\r\n \r\n /apreg64 <address in Hex> \r\n Assumes the APREG format to of 64 bit and attempts to find the MSM_DUMP_TABLE \r\n at that location.\r\n \r\n /supplementalbugcheckdata <path_to_hloscrashdmp.bin>\r\n Bugcheck data from supplied hloscrashdmp.bin is used to replace default FATAL_ABNORMAL_RESET_ERROR (0x14c)\r\n information in generated .dmp file if no such information is found in SV specific section.\r\n \r\nRECOMMENDED Usage Commands:\r\n For example on Windows Systems Under Test (SUT), option A or B:\r\n A) Raw Partition -- > Raw File -- > .DMP, .BIN(s)\r\n -----------------------------------------------------------\r\n /dumprawpart (on SUT) /parsedump, windbg (on DS)\r\n \r\n 1) 'offlinedumptool /dumprawpart dump.raw' (on SUT)\r\n output is user specified 'dump.raw' file\r\n 2) 'offlinedumptool /parsedump dump.raw' (on DS)\r\n output is .DMP file (windbg loadable)\r\n output is .BIN file(s) (as specified in .RAW file)\r\n 3) 'windbg -z crash.dmp' (on DS)\r\n \r\n B) Raw Partition ----- > .DMP, .BIN(s)\r\n --------------------------------------------------\r\n /parsepart (on SUT) windbg (on DS)\r\n \r\n 1) 'offlinedumptool /parsepart' (on SUT)\r\n output is .DMP file (windbg loadable)\r\n output is .BIN file(s) (as specified in .RAW file)\r\n 2) 'windbg -z crash.dmp' (on DS)\r\n \r\n For Windows Phone Systems Under Test (SUT):\r\n A) .DMP File (generated on SUT) -- > .BIN(s)\r\n -----------------------------------------------\r\n /parsewpdump wp_dumpfile.dmp, windbg (on DS)\r\n \r\n 1) 'offlinedumptool /parsewpdump wp_dumpfile.DMP' (on DS)\r\n output is .BIN file(s) (as specified in .DMP file)\r\n 2) 'windbg -z wp_dumpfile.dmp' (on DS)\r\n \r\nSummary: Total=0, Passed=0, Failed=0, Blocked=0, Warned=0, Skipped=0\r\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\OffDumpTool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "pdbcopy.exe-21B8B76D018340BA5DDAAF024361B2BA": { "file_name": "pdbcopy.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\pdbcopy.exe", "hash_md5": "21B8B76D018340BA5DDAAF024361B2BA", "hash_sha1": "CD1EC1EB9897FEE7FD87E9C3291B4096F4F10F57", "hash_sha256": "F10D2233C4B65088E30242041B95FC7D839BFF1EF239AA722916A497CE45AA5B", "hash_sha384": "C0EB7683B3BC8CB052B31CC04D24E9BD3BF2750422490982B7506D6A00FECEF02887A5DD5AF0D3D4C5CFABC42AFE71A5", "hash_sha512": "7BEA5C1F2CA56909B3E9CAD41AFBA46D7A8FDD2D0E2F401CEF6433A11FF747F51B906F2F48F089C20C274CAE907EF30D2DA2BE23DA18BA057A16EE670C1A24DF", "hash_ssdeep": "12288:n/XXw1ntyMLTAh0SnaNrJ6XWN306e5sMgcCP81GTxep:/HwJtyHh0ekrgWNhhcCPXxep", "hash_imp": "B5C9417805C124C8AA9C035426ABEF87", "hash_pesha1": "4A8A98A910550863937654D95F9698BD1FA1C671", "hash_pe256": "9BD4796B43EE73117ADC30944D9F1BD7EB543330F2BCEE9A1B9A886DDF44842B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000010A2C79AED7797BA6AC00010000010A", "signature_thumbprint": "3BDA323E552DB1FDE5F4FBEE75D6D5B2B187EEDC", "signature_issuer": "CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft PDB Copy Utility", "meta_original_filename": "PDBCOPY.EXE", "meta_product_name": "Microsoft Visual Studio 2015", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.00.23615.0 built by: VCTOOLSREL", "meta_product_version": "14.00.23615.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f10d2233c4b65088e30242041b95fc7d839bff1ef239aa722916a497ce45aa5b/detection", "error": "\r\nPDBCopy v14.00.23615\r\nusage: PDBCopy <source_pdb> <destination_pdb> [-p] [-s] [-f] [-F] [-a] [-A] [-?]\r\n\t[-p] remove private debug information\r\n\t[-s] create new signature\r\n\t[-f:{@file|symbol}] filter specific public symbols out of stripped pdb\r\n\t[-F:{@file|symbol}] leave only specific public symbols in stripped pdb\r\n\t[-a] leave all annotation symbols in stripped pdb\r\n\t[-a:{@file|symbol}] filter specific annotation symbols out of stripped pdb\r\n\t[-A:{@file|symbol}] leave only specific annotation symbols in stripped pdb\r\n\t[-?] display this message\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\pdbcopy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "plmdebug.exe-71BDC992A05A47245D6C7B70DD13476C": { "file_name": "plmdebug.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\plmdebug.exe", "hash_md5": "71BDC992A05A47245D6C7B70DD13476C", "hash_sha1": "2B5325047C61FC84EC35B21CE3F159016E47A09E", "hash_sha256": "114B63624E7B8BACCBCFA73295BBFBEA8613BC95DCC9FF1A3E2D0DE87C044B62", "hash_sha384": "4C3E7D9CA47D585B5B16FFF96DDF9AF421AF79D63762CB9080490556C43E3376A4F6585CD17C670D76CFFB7F7249C5E0", "hash_sha512": "5A8B5F11A9C10B845EA6E35638FAD5B07005059BEC03F6920A546A673D78B71700CA4BB28A3F64895DF85F10D56772356E6EDB7F35299F7E36E3C24BA99E6701", "hash_ssdeep": "3072:irntWIUgTjM60EtNUSdsBYa52vXOKeN72ee+44xfUom4gQ:Kh0M5hi8eKYxfUomt", "hash_imp": "2D9614E9DF4F5F1A07E899F19700EBD9", "hash_pesha1": "E8F70690E17FBB4CD723A3A4FDB4E669317BB25B", "hash_pe256": "299BE82A836CAAF8D4092B290F34D8D6F7142E6A93BA95877E3274F423F88011", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft PLMDebug", "meta_original_filename": "plmdebug.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/114b63624e7b8baccbcfa73295bbfbea8613bc95dcc9ff1a3e2d0de87c044b62/detection", "output": "plmdebug.exe /query [pkgname]\r\nplmdebug.exe /enableDebug pkgname [\"debugger\"] [\"environment str1\" ...]\r\nplmdebug.exe /terminate|/forceterminate|/cleanterminate pkgname\r\nplmdebug.exe /suspend|/resume|/disableDebug pkgname\r\nplmdebug.exe /enumerateBgTasks pkgname\r\nplmdebug.exe /activateBgTask taskid\r\n\r\n pkgname can be package full name or a process ID for one of the processes running for the package.\r\n\r\n/query: List running states for all installed packages or a specified package.\r\n/enableDebug: Call the PLM debug API to increment debug ref count on a package. PLM\r\nDoes not suspend a package if it has non zero debug ref count.\r\n debugger: Optional string to start debugger.\r\n Eg: \"C:\\Program Files\\Windows Kits\\8.0\\Debuggers\\x64\\windbg.exe\" -server npipe:pipe=test\"\r\n environment strings: Optional list of environment strings for debug session.\r\n Eg: \"var1=val1\" \"var2=val2\"\r\n/terminate|/forceterminate: Call the PLM debug API to terminate all processes running for the package.\r\n/cleanterminate: Call the PLM debug API to suspend and then terminate all processes running for the package.\r\n/suspend: Call the PLM debug API to asynchronously suspend all processes running for the package.\r\n/resume: Call the PLM debug API to resume a package.\r\n/disableDebug: Call the PLM debug API to decrement debug ref count on a package.\r\n/enumerateBgTasks: Enumerate background task ids for a package\r\n/activateBgTask: Activates a background task\r\n ** NOTE: Not all background tasks can be activated using plmdebug **\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\plmdebug.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "remote.exe-5FD194FF895E0D2F5263B355A6A0D3AA": { "file_name": "remote.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe", "hash_md5": "5FD194FF895E0D2F5263B355A6A0D3AA", "hash_sha1": "49696D8C48ED53471FCC044067B4368076517795", "hash_sha256": "74F00DA9E4128282F502CF3AE67A139B723F2C3C00E5141B7B60E8EED1F3BF6A", "hash_sha384": "EB3BDDE4826FF6C1A2B4BBFAA10E7746E58D281E771B55B3C98DC830CFE0222AC64689124814357F069CE4B0EEA390A6", "hash_sha512": "F03C95918548B912A98278D1C928E87E1CE5CE210DC1D5E6F2FEA006E17B7D1ADCC1DF66F5B34DEFC34DE1051C4D25DD5EA03FF03B839D16C061DB4CD7377680", "hash_ssdeep": "768:6BGHGjXkc0Sol53IecahldJ0P5680gXcy1hgdEhI17s5fmTe1z+Djtg:6BG1SoP3r1zWXcy1hgls5+Te5+DjG", "hash_imp": "3968B0B7E2A026A09218F3B3A9ECC650", "hash_pesha1": "9D8F20CA340248EFDCD038567E166CB4770122DC", "hash_pe256": "F8350391200019EBB3F0F7342F98FAAF2179FA5984173F698A0A21A601FE6D4E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Remote Std I/O Shell", "meta_original_filename": "remote.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/74f00da9e4128282f502cf3ae67a139b723f2c3c00e5141b7b60e8eed1f3bf6a/detection", "output": "\r\n To Start the SERVER end of REMOTE\r\n ---------------------------------\r\n Syntax : REMOTE /S <\"Cmd\"> <Unique Id> [Param]\r\n Example1: REMOTE /S \"i386kd -v\" imbroglio\r\n To interact with this \"Cmd\" from some other machine,\r\n start the client end using: REMOTE /C A0D5F083-3197-4 imbroglio\r\n\r\n Example2: REMOTE /S \"i386kd -v\" \"name with spaces\"\r\n start the client end using: REMOTE /C A0D5F083-3197-4 \"name with spaces\"\r\n\r\n To Exit: @K \r\n [Param]: /F <Foreground color eg yellow, black..>\r\n [Param]: /B <Background color eg lblue, white..>\r\n [Param]: /U username or groupname\r\n specifies which users or groups may connect\r\n may be specified more than once, e.g\r\n /U user1 /U group2 /U user2\r\n [Param]: /UD username or groupname\r\n specifically denies access to that user or group\r\n [Param]: /UL [filename]\r\n Filename of string format security descriptor.\r\n If no filename, then the REMOTE_SDDL_FILE environment\r\n variable is used.\r\n [Param]: /V Makes this session visible to remote /Q\r\n [Param]: /-V Hides this session from remote /q (invisible)\r\n By default, if \"Cmd\" looks like a debugger,\r\n the session is visible, otherwise not\r\n\r\n\r\n To Start the CLIENT end of REMOTE\r\n ---------------------------------\r\n Syntax : REMOTE /C <ServerName> \"<Unique Id>\" [Param]\r\n Example1: REMOTE /C A0D5F083-3197-4 imbroglio\r\n This would connect to a server session on A0D5F083-3197-4 with Id\r\n \"imbroglio\" if there is a REMOTE /S <\"Cmd\"> imbroglio\r\n running on A0D5F083-3197-4.\r\n\r\n Example2: REMOTE /C A0D5F083-3197-4 \"name with spaces\"\r\n This would connect to a server session on A0D5F083-3197-4 with Id\r\n \"name with spaces\" if there is a REMOTE /S <\"Cmd\"> \"name with spaces\"\r\n running on A0D5F083-3197-4.\r\n\r\n To Exit: @Q (Leaves the Remote Server Running)\r\n [Param]: /L <# of Lines to Get>\r\n [Param]: /F <Foreground color eg blue, lred..>\r\n [Param]: /K <Set keywords and colors from file>\r\n [Param]: /B <Background color eg cyan, lwhite..>\r\n\r\n Keywords And Colors File Format\r\n -------------------------------\r\n <KEYWORDs - CASE INSENSITIVE>\r\n <FOREGROUND>[, <BACKGROUND>]\r\n ...\r\n EX:\r\n ERROR\r\n black, lred\r\n WARNING\r\n lblue\r\n COLOR THIS LINE\r\n lgreen\r\n\r\n To Query the visible sessions on a server\r\n -----------------------------------------\r\n Syntax: REMOTE /Q A0D5F083-3197-4\r\n This would retrieve the available <Unique Id>s\r\n visible connections on the computer named A0D5F083-3197-4.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "rtlist.exe-ECF37672B054815EE7CD520B6E4C69C7": { "file_name": "rtlist.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\rtlist.exe", "hash_md5": "ECF37672B054815EE7CD520B6E4C69C7", "hash_sha1": "3543E954B41E82033DE2A669760F3435E7ABAEC2", "hash_sha256": "18011587CEB54A206EDB1BE97BEF4583F37C50CD712F3538610DB330E932F38F", "hash_sha384": "5348FBB0AAF66294F928AD11D4E4DCF7F1229C63CEB79F9F61AA2CE26ED3690F72C782E20F492522579420BE33BC05CD", "hash_sha512": "4A6C53EA8152EE590EF6C82458099EDD59CEC7DD2EF2DD2807690318C16275CEAD149AC9E6A7F1DAC8704FAC89BD623C26286F975DCE517D2CBE4E86922AA765", "hash_ssdeep": "384:akRLlbfoLc1I+npPbopWO73ZW3wGyqlN9:aebZ5Pbolk", "hash_imp": "48D13898BAEA959F965C45DEFAC97048", "hash_pesha1": "D49F5E4D4D7E20487260E0541F88C25A64C3DB09", "hash_pe256": "8C8DA67363D1423A088A4510A81CC71F4E058B01DA83D2E72AC48772EC2CC403", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft User-Mode Process Server Query Tool", "meta_original_filename": "rtlist.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/18011587ceb54a206edb1be97bef4583f37c50cd712f3538610db330e932f38f/detection", "output": "Usage: rtlist <Options>\r\nOptions are:\r\n -premote <Options> - Connect to process server\r\n -pn <Name> - Look for process name\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\rtlist.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "symchk.exe-D08AEA07938DF399409D5B57AAAC448F": { "file_name": "symchk.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\symchk.exe", "hash_md5": "D08AEA07938DF399409D5B57AAAC448F", "hash_sha1": "CF003AF2C5C40B2E9D49C508E99E8031C441A4E0", "hash_sha256": "D3C551B0D36884346702436AEAF57644767D97B3071D082DB3211EDCA59CFFC0", "hash_sha384": "CA6AC609B6301AD086B3E31B3F0E54B5A776880D1FBF6BAD74E2B999AFA6A4B7C9FEA740A929FD410C3FB643A65025CD", "hash_sha512": "9253E7A6D3A0B72373A61C2B44BC4541C9FF3DC55B84ACF535EC517DDD600D2C111BD4CC5ED12F8963A5756B38B0287704BC300BD0E0C66F40769256B7E652CE", "hash_ssdeep": "1536:SalYrAStQVLEz5azdd8VP3VPcRSK7C6iE2CH:/l8x5azd2VfVPcAKSE2CH", "hash_imp": "81952936A5D3F19F7216EDE4DC21BEAF", "hash_pesha1": "2526FB605104BA372253433307A4BF91B0E5F809", "hash_pe256": "33BBE824912B77B80A0FB2E435EF54F0F98DD9087D291C00A33C937FC8CB2BBB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbol Checker", "meta_original_filename": "SYMCHK.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/d3c551b0d36884346702436aeaf57644767d97b3071d082db3211edca59cffc0/detection", "output": "\r\nsymchk [/r] [/q] [Input options] <Filename> [/s <SymbolPath>] [options]\r\n\r\n<Filename> Name of the file or directory that contains the executables\r\n to perform symbol checking on.\r\n\r\n/s <SymbolPath> Semi-colon separated list of symbol paths. Symbol server\r\n paths are allowed. To retrieve symbols to a downstream\r\n store, use \"SRV*<downstream store>*<symbol server>\" for\r\n the symbol path. See the debugger documentation for more\r\n details.\r\n\r\n/r Perform recursive operations on the <Filename> specified. The\r\n wildcard * can be used in filenames.\r\n\r\n/q Turn off all output options by default. Only output turned on\r\n with a output flag (see below) will be printed\r\n\r\n--------------------------------------------------------------------------------\r\n* Input options (choose only one):\r\n/if <Filename> Input is a file name. Wildcards can be used to specify\r\n the file name. Default if nothing is specified.\r\n/id <DumpFile> Input is a dump file.\r\n/ih <HotFix> Input is a self-extracting Hotfix cab.\r\n/ie <ExeName> Input is an application name that is currently running.\r\n If the provided ExeName is '*', all currently running\r\n processes will be checked.\r\n/im <ManifestList> Input is a manifest previously created using the /om <file>\r\n option.\r\n/ip <ProcessId> Input is a process id. If the provided ProcessID is '*',\r\n all currently running processes will be checked.\r\n/it <TextFileList> Input is a list of files, one per line, inside of a text\r\n file.\r\n\r\n--------------------------------------------------------------------------------\r\n* Action options (choose only one):\r\n/av For each binary, Verify symbols exist and match. Default.\r\n\r\n--------------------------------------------------------------------------------\r\n* Symbol checking options:\r\n/cc when symbol checking a hotfix cab, don't look for symbols inside the cab.\r\n By default, symchk will look for symbols in the cab as well as in the\r\n provided symbol path.\r\n/cn When symbol checking a running process, don't suspend that process. User\r\n must ensure the process doesn't exit before symbol checking finishes.\r\n/cs Skip verifying that there is CodeView data. Symchk will verify that there\r\n IS codeview data by default.\r\n\r\n- Symbol checking options for DBG information (choose one):\r\n/ds If image was built so that there is information that belongs in a DBG\r\n file, then this option verifies that the DBG information is stripped\r\n from the image and that the image points to a DBG file. Default.\r\n/de If image was built so that there is information that belongs in a DBG\r\n file, then this option verifies that the DBG information is STILL in the\r\n image and that the image does not point to a DBG file.\r\n/dn Verify that the image does not point to a DBG file and that DBG\r\n information is not in the image.\r\n\r\n- Symbol checking options for PDB files:\r\n/pa Allow both public and private PDBs. Default.\r\n/pf Verify that PDB files contain full source information.\r\n/ps Verify that PDB files are stripped and do not contain full source\r\n (private) information.\r\n/pt Verify that PDB files are stripped, but do have type information. Some\r\n PDB files may be stripped but have type information added back in.\r\n\r\n--------------------------------------------------------------------------------\r\n* Symbol checking exclude options:\r\n/ea <Filename> Don't perform symbol checking for the binaries listed in the\r\n file specified. <Filename> is a text file that contains the\r\n name of each binary, one per line.\r\n/ee <Filename> Perform symbol checking and report files that pass or are\r\n ignored, but don't report errors for binaries listed in the\r\n file specified. <Filename> is a text file that contains the\r\n name of each binary, one per line.\r\n\r\n--------------------------------------------------------------------------------\r\n* Symbol path options:\r\n/s[eprsu] <SymbolPath> Use <SymbolPath> as the search path.\r\n\r\n NOTE: If the '/s' option is not used, SymChk defaults to using the value\r\n in %_NT_SYMBOL_PATH%. If %_NT_SYMBOL_PATH% is not defined, then SymChk\r\n will default to:\r\n SRV*%SYSTEMROOT%\\SYMBOLS*https://msdl.microsoft.com/download/symbols\r\n\r\n* Modifiers (choose all that apply):\r\n e - check each path individually instead of checking all paths at once.\r\n p - force checking for private symbols. Public symbols will be treated as\r\n not matching. (Implies the 'e' and 'u' modifiers.)\r\n r - Expand all non-symbol server elements in the specified path in order to do\r\n a deep search of the path. NOTE: This option may produce matches that will\r\n not occur inside the debugger since it modifies the symbol path specified.\r\n s - force checking for public (split) symbols. Private symbols will be\r\n treated as not matching. (Implies the 'e' and 'u' modifiers.)\r\n u - force updating of downstream stores. If the symbol path includes a\r\n downstream store, always re-check the server for the symbol. Only\r\n stores that are checked against will be updated.\r\n NOTE: The 's' and 'p' options are mutually exclusive. Only the last one\r\n present will be used.\r\n\r\n--------------------------------------------------------------------------------\r\n* Output options (choose all that apply):\r\n/ob Give the full path for binaries in the output messages for symbol\r\n checking.\r\n/oc[x[a]] <Directory> Create a flat symbols tree in <Directory> which\r\n contains all matching symbols. If 'x' is also used, copy the matching\r\n binaries into <Directory> as well. If 'a' is also present, the binary\r\n will always be copied to the flat symbol tree even if symbol checking\r\n failed.\r\n/od List all details. Same as /oe /op /oi\r\n/oe List individual errors. Errors will be sent to the output by default.\r\n This option is only needed when using /q\r\n/oi List each file that is ignored.\r\n/op List each file that passes.\r\n/os Give the full path for symbols in the output messages for symbol\r\n checking.\r\n/ot Send totals to the output. Totals are sent to the output by default.\r\n This option is only needed when using /q\r\n/ov Print version information for checked binaries as well.\r\n\r\n- Extended output options:\r\n/ol <File> In addition to the messages sent to standard out, write a\r\n file that contains a comma separated list of all the\r\n binaries and their symbols that pass symbol checking.\r\n/om <Manifest> Print out a manifest file for later use with the '/im' option.\r\n/v Turn on verbose output mode.\r\n--------------------------------------------------------------------------------\r\n* Module filtering options when checking processes or dump files (choose one):\r\n /fm <Module> Filter results to only include the named module.\r\n\r\n--------------------------------------------------------------------------------\r\n* Misc options\r\n /port Old usage to new usage quick porting table\r\n--------------------------------------------------------------------------------\r\n\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\symchk.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "symstore.exe-1903CF11FA6A75A375DEF2972A62B0E4": { "file_name": "symstore.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\symstore.exe", "hash_md5": "1903CF11FA6A75A375DEF2972A62B0E4", "hash_sha1": "086FE1303ADD5EE2BEE80A54B035F0F28029C769", "hash_sha256": "ED986351C69C556416A950744C2209C136812F3CBB376A1FBF15FE11607C39C4", "hash_sha384": "A26DB11597031580658379806B92F46C211EC9A67ADD9201CA6E1C4BE724F2EFA5B1378FDB13C05775940D7597900C1B", "hash_sha512": "438B4CFDE559697ED9C2DEF809E11BFF8FE899755992050429833297AC72282A8B974BE152985CC1C8AF69560F5C42A5CA4C558B733F218167C7E667C753D750", "hash_ssdeep": "1536:lsJtYgBwZX/Eu6tZsbLFxDB9PL6DhL2b5c3exo06nOv8i37:latYg6Z0jsVh3tbyexZ6ni53", "hash_imp": "A93EF732C8E3E2DEB456943D297AEADA", "hash_pesha1": "74D33C8CF04E65C5EC9384615D2A711C10EC2CDA", "hash_pe256": "93A1A5E448C715F363611E72DCEE56473C17E826748B98E4A270E1BD0609CA34", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbol Server Builder", "meta_original_filename": "SYMSTORE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/ed986351c69c556416a950744c2209c136812f3cbb376a1fbf15fe11607c39c4/detection", "output": "Usage:\r\nsymstore add [/r] [/p] [/l] /f File /s Store /t Product [/v Version]\r\n [/c Comment] [/d LogFile] [/compress]\r\nsymstore add [/r] [/p] [/l] [/q] /g Share /f File /x IndexFile [/a] [/d LogFile]\r\nsymstore add /y IndexFile /g Share /s Store [/p] /t Product [/v Version]\r\n [/c Comment] [/d LogFile] [/compress]\r\nsymstore del /i ID /s Store [/d LogFile]\r\nsymstore query [/r] [/o] /f File /s Store\r\n\r\n add Add files to server or create an index file.\r\n del Delete a transaction from the server.\r\n query Check if file(s) are indexed on the server.\r\n\r\n /3 Create index2.txt when populating a new symbol server.\r\n /f File Network path of files or directories to add.\r\n If the named file begins with an '@' symbol, it is treated\r\n as a response file which is expected to contain a list of\r\n files (path and filename, 1 entry per line) to be stored.\r\n /g Share This is the server and share where the symbol files were\r\n originally stored. When used with /f, Share should be\r\n identical to the beginning of the File specifier. When\r\n used with the /y, Share should be the location of the\r\n original symbol files, not the index file. This allows\r\n you to later change this portion of the file path in case\r\n you move the symbol files to a different server and share.\r\n /i ID Transaction ID string.\r\n /l Allows the file to be in a local directory rather than a\r\n network path.(This option is only used with the /p option.)\r\n /p Causes SymStore to store a pointer to the file, rather than\r\n the file itself.\r\n /q Don't quote fields in the index file.\r\n /r Add files or directories recursively.\r\n /s Store Root directory for the symbol store.\r\n /t Product Name of the product.\r\n /v Version Version of the product.\r\n /c Comment Comment for the transaction.\r\n /d LogFile Send output to LogFile instead of standard output.\r\n /x IndexFile Causes SymStore not to store the actual symbol files in the\r\n symbol store. Instead, information is stored which will\r\n allow the files to be added later.\r\n /y IndexFile This reads the data from a file created with /x.\r\n /yi IndexFile Append a comment with the transaction ID to the end of the\r\n index file.\r\n /z pub | pri Pub option will only index symbols that have had the full\r\n source information stripped. Pri will only index symbols\r\n that contain the full source information. Both options\r\n will index binaries.\r\n /m <prefix> Give preference to files which have <prefix> at the beginning\r\n of their path when storing/updating pointers.\r\n /h pub | pri Give priority to pub or pri.\r\n /a Causes SymStore to append new indexing information\r\n to an existing index file. (This option is only used with\r\n /x option.)\r\n /o Give verbose output.\r\n -:MSG [msg] When storing pointers, also add the provided message to the\r\n file.ptr\r\n -:REL Allow file.ptr paths to be relative. Implies '/l' also.\r\n -:NOREFS Only valid during intial store creation or when used on a\r\n store previously created with the -:NOREFS option. Omits the\r\n creation of refs.ptr files for files and pointers stored.\r\n Use of a store without refs.ptr precludes the ability to do\r\n prioritization and the ability to delete transactions from the\r\n store.\r\n -:NOFORCECOPY\r\n /compress When storing files, store compressed files on the server. Ignored\r\n when storing pointers.\r\n\r\n", "children": [ "csrss.exe", "wininit.exe" ], "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\symstore.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "tlist.exe-133DCA03D53C59A0E155366F89F77737": { "file_name": "tlist.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\tlist.exe", "hash_md5": "133DCA03D53C59A0E155366F89F77737", "hash_sha1": "3203F776455CD75276035576C1C27426A091DA08", "hash_sha256": "E9972E8DCEE65A5D851EED887716B8CE535BC9D439E5976958965C449E5F5750", "hash_sha384": "C94C54EA8A90D25A421036D6168BB3F1D761FE646557871D1CF2DEC4CBFE4A12111BB0306E300FE5C9E16583BCE29AFB", "hash_sha512": "CF904A593C6B9A87D035877F2D3BE2FF67A6B416D3566703B7235C6446C64DE16DEC6D3790953AF4705BA8D082AA462EEE56E1B741F135ECCD5559E9484FCA86", "hash_ssdeep": "768:kzeJADjZEWDItB97gZPq0v4Vj16MSVYmklaC8opnIhx:kcA3SNgZPq0vUKMACNnIL", "hash_imp": "995C499033953B28F84B5F09778C487A", "hash_pesha1": "61A441AFA6A7459B014ECB5B00FDE8DEFC3B1766", "hash_pe256": "F880A2FB4FF77B922BF5D50E3140838FD5D6E6BCE801087C98BCB79D86C08FD9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Process List Utility", "meta_original_filename": "tlist.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/e9972e8dcee65a5d851eed887716b8ce535bc9d439e5976958965c449e5f5750/detection", "error": "Microsoft (R) Windows NT (TM) Version 5.1 TLIST\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nusage: TLIST <<-m <pattern>> | <-t> | <pid> | <pattern> | <-p <processname>>> | <-k> | <-s>\r\n [options]:\r\n -t\r\n Print Task Tree\r\n\r\n <pid>\r\n List module information for this task.\r\n\r\n <pattern>\r\n The pattern can be a complete task\r\n name or a regular expression pattern\r\n to use as a match. Tlist matches the\r\n supplied pattern against the task names\r\n and the window titles.\r\n\r\n -c\r\n Show command lines for each process\r\n\r\n -e\r\n Show session IDs for each process\r\n\r\n -g\r\n Show group affinity for each process (Win7+)\r\n\r\n -k\r\n Show MTS packages active in each process.\r\n\r\n -m <pattern>\r\n Lists all tasks that have DLL modules loaded\r\n in them that match the given pattern name\r\n\r\n -s\r\n Show services active in each process.\r\n\r\n -p <processname>\r\n Returns the PID of the process specified or -1\r\n if the specified process doesn't exist. If there\r\n are multiple instances of the process running only\r\n the instance with the first PID value is returned.\r\n\r\n -v\r\n Show all process information\r\n\r\n -w\r\n Show Wow64 process information\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\tlist.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "umdh.exe-A9B13D96A16154B1E7B82F823B6A5182": { "file_name": "umdh.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\umdh.exe", "hash_md5": "A9B13D96A16154B1E7B82F823B6A5182", "hash_sha1": "DE5B3BDE4D0E134B9AB9AB1462D71BDA6B0A6EEC", "hash_sha256": "B608A4FFBF5E68F47992F22F69DDFC07E18E8858DC3C56A8E77A1577DAEFAE78", "hash_sha384": "052B947F1FF8908D673F91DE1B25164A7BF3F7A12AF02B0F795A137DB6C15AD05157A0B2991F6E597CCC3DF143FB1F9B", "hash_sha512": "0F4FEB10F917311AFD1906274D2640400972D3F659D4E4069317099ED5938DF13C00BD39517688A1088683A82F849465F8476F2F48BC1ABA4D5D4FD3844F2879", "hash_ssdeep": "1536:gH7vJgA+biyjpOTJ8hMXBzIWv0XxdEgU:iJgA0jpOTkWBIk0rEgU", "hash_imp": "5936EEEFB448F0EE7ABF50CCDA83543E", "hash_pesha1": "A5CE2C91C7E212A212AEB5C61DADD0FB1E69A1F6", "hash_pe256": "70547A9C01EFF36C409DD51E878EDED8CB3AB5F59C6543B4233B648AFEDF1379", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NT Security Test: UMDH", "meta_original_filename": "UMDH.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b608a4ffbf5e68f47992f22f69ddfc07e18e8858dc3c56a8e77a1577daefae78/detection", "error": " \r\n UMDH \r\n \r\nMODE 1 \r\n \r\n umdh {-p:Process-id|-pn:ProcessName} [-f:Filename] [-g] \r\n \r\n Creates a dump of the heap allocations. \r\n \r\n -p Indicates the Process-ID to examine. \r\n -pn Indicates the Process name to examine. \r\n -f Indicates output file. \r\n -g Dumps the heap blocks which have no references in the process. \r\n \r\nMODE 2 \r\n \r\n umdh [-d] {File1} [File2] [-f:Filename] \r\n \r\n Compares two dumps and resolves the symbols. \r\n \r\n -d Output in decimal (default is hexadecimal) \r\n -f Indicates output file. \r\n \r\nEXAMPLE: \r\n \r\n -1- umdh.exe -pn:application_name.exe -f:FirstDump.txt \r\n -2- ... exercise the application \r\n -3- umdh.exe -pn:application_name.exe -f:SecondDump.txt \r\n -4- umdh.exe FirstDump.txt SecondDump.txt -f:Result.txt \r\n Compares allocations from the two dumps. \r\n \r\n umdh.exe Dump.txt \r\n Investigate a single dump. \r\n \r\nNOTES: \r\n \r\n Uses the dbghelp library to resolve symbols \r\n therefore _NT_SYMBOL_PATH must be set appropriately. \r\n \r\n \r\n", "output": "// _NT_SYMBOL_PATH set by default to C:\\Windows\\symbols\r\n// Debug library initialized ...\r\n// \r\n// Each log entry has the following syntax: \r\n// \r\n// + BYTES_DELTA (NEW_BYTES - OLD_BYTES) NEW_COUNT allocs BackTrace TRACEID \r\n// + COUNT_DELTA (NEW_COUNT - OLD_COUNT) BackTrace TRACEID allocations \r\n// ... stack trace ... \r\n// \r\n// where: \r\n// \r\n// BYTES_DELTA - increase in bytes between before and after log \r\n// NEW_BYTES - bytes in after log \r\n// OLD_BYTES - bytes in before log \r\n// COUNT_DELTA - increase in allocations between before and after log \r\n// NEW_COUNT - number of allocations in after log \r\n// OLD_COUNT - number of allocations in before log \r\n// TRACEID - decimal index of the stack trace in the trace database \r\n// (can be used to search for allocation instances in the original \r\n// UMDH logs). \r\n// \r\n\r\n\r\n\r\nTotal decrease == 0 requested + 0 overhead = 0\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\umdh.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "usbview.exe-1B770404A886BFDCF3FB6CBB9E3117E2": { "file_name": "usbview.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\usbview.exe", "hash_md5": "1B770404A886BFDCF3FB6CBB9E3117E2", "hash_sha1": "87BA53876C455BB7463F41059FFB23515B0A8F5A", "hash_sha256": "4EB5DADFA86CCFFE209A050E20A526BEEB7C3A116229CF0465DE4278B3875080", "hash_sha384": "8F63CBBB4993DE33990C7C39F8E739F114842C59977080FE77BBC0B2C1D2AB8129DCA506D340F966B33DB9AF38CBE711", "hash_sha512": "3BFC56AAFBD3F11792D1EA41D6115189F2870A998A5015CCF0689209293BE38F491B6A7CF9CD8E8AAE69B3DF86F897AE8DEFDA2477F6986EE1EB96C9C70CFE64", "hash_ssdeep": "12288:16EXeAZVBYCCdVQ5VJ6TEzseESK6DPkTHGwKlfInd9ohJ7nS:8aRunVQ5VHzseESCmwmInd9ohJrS", "hash_imp": "99933A1B95E7F1C3452501E96962FF4C", "hash_pesha1": "979B8AE6437C7C389A5E1887F6B4E8102FE2EFE5", "hash_pe256": "99CC2BA4A76711B44D8E4085FF00DCA95761036FAD9439AA52120735471823E8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) USB device viewer", "meta_original_filename": "USBView", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright Microsoft Corporation 1996-2011 All Rights Reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4eb5dadfa86ccffe209a050e20a526beeb7c3a116229cf0465de4278b3875080/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_8936": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\usbview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\ole32.dll" ], "runtime_window_title": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\usbview.exe" }, "vmdemux.exe-E403383D7F38F00E18C76CFAC226069B": { "file_name": "vmdemux.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\vmdemux.exe", "hash_md5": "E403383D7F38F00E18C76CFAC226069B", "hash_sha1": "DC37A92A8A14FD0C6BF7BBBC64BFF66BB58AD2CA", "hash_sha256": "76340B2A29DC794CD254A0CBAA28F62890E51D187E64E09D072BC243B9E1D510", "hash_sha384": "302EBF69A55B882EF6C6094A8E9762D75DAE27DC99DBEE996208E5A46AD8EF762902D0BD03DFA449BF261AC62BC75159", "hash_sha512": "DAA8A86F4F375274680762BC3FB2058C3655BA51F69828D2D11F00516B14E3019F3F964D897E26E36223FF8A3B82AB4E64CF21149F1F730C3E7684C37584CBCE", "hash_ssdeep": "1536:xsTe9974t5uZbYU+DkkiqhxwSZ+iWHBB8avvQZpEZHHTg:xsTe99Q5uZb1+Dkdq40+dDZHU", "hash_imp": "BF67041AAF4608B178DB55990DAA8297", "hash_pesha1": "97B4380A5910415E97EAEF46D11D9AD1CD835FBA", "hash_pe256": "EB20588DE054CFCE8F634A4357B510F2D1BC8A6F628E7685D8C6F54C022BAD65", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hyper-V Unified Debugging Session Demuxer", "meta_original_filename": "vmdemux.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/76340b2a29dc794cd254a0cbaa28f62890e51d187e64e09d072bc243b9e1d510/detection", "children": "Fondue.exe", "error": "bad command line option '--help'. For usage try 'vmdemux -?'", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\vmdemux.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "windbg.exe-8CC7AB7DC9C670809113929568FB3F31": { "file_name": "windbg.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\windbg.exe", "hash_md5": "8CC7AB7DC9C670809113929568FB3F31", "hash_sha1": "A5B6A107B4D5318D6B666E3CC831E967E999C039", "hash_sha256": "179730146A9A47DF359128F3A49BF09DE932F6F9EECF5BDC96918C5647598BC5", "hash_sha384": "4FDEFF919DD1B1B1F3CFB7618D40F8842611D4AF0101C3EBF4579C1126AA3D72465BDE020DD6A601D061AC79E131C250", "hash_sha512": "6B0D0715BBC2703076E07A55EDF378D3B9AB8FC2737947D1A7D23C1621F9D6CC323FD909C6A8366DB60166D4B28079ECBFBD9929BA974CD19429B76BCEBFC217", "hash_ssdeep": "12288:fZcJofqA3te2VZds33/VgI1y4erFR/32Ousrte4:BcGfqA3te2Si+y4enmOuge", "hash_imp": "0D94733CE3020EDCCF4DFF51CEA82E82", "hash_pesha1": "FF4A5553212033E6FC3DC28B04413CFE9520B3D0", "hash_pe256": "9B6D625987984B9386D112A93AF03E1AEB03981E6DC471FD55F78D9BDEB17131", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows GUI symbolic debugger", "meta_original_filename": "windbg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/179730146a9a47df359128f3a49bf09de932f6f9eecf5bdc96918c5647598bc5/detection", "children": "help.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\1dbcHWNDInterface:5802de": "Section", "(RWD) C:\\Windows\\System32\\ntdll.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\sym\\ntdll.pdb\\1EB9FACB04C73C5DEA7160764CD333D01\\ntdll.pdb": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_window_title": "help - WinDbg:10.0.19041.1 AMD64 ", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\windbg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\dbghelp.dll" ] }, "pdbstr.exe-AFAACEBAF5A13FF4666461FBADDC663F": { "file_name": "pdbstr.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\srcsrv\\pdbstr.exe", "hash_md5": "AFAACEBAF5A13FF4666461FBADDC663F", "hash_sha1": "22F59A42328F0158FE8D93CE72BCA1AA67A6C7F9", "hash_sha256": "A2248F4E0A242B059409FCBFD73E1320025B9B802B7FC8A1A9D29AC05716CF01", "hash_sha384": "995DD1255A51DC0C46D4CF75EA8A7BB3ED3ECCCA366F616B191E690EAA63163134144122426B4F34062EB2066A132462", "hash_sha512": "9CFA0BF1BE414644584CB053CA99B37D88E331FC1E76A4A4C5CA037D19D301F3A739666CEAF915FCE515ED6A094B0706D198E8A86C42B536553A29F1BD93BB33", "hash_ssdeep": "12288:5K7hO/Tr86OxnOhpKX756rIGbuTaxJnculUNAQZNu14LbG9Y/:5K7hO/f3OcmXgrhzU/ZNu2aC", "hash_imp": "2F90C4FAE177BBAEB611B5545CE91D6C", "hash_pesha1": "05EB54088A7AA494AB1E04698E5F4F980A0F6957", "hash_pe256": "E8F67B28ADE68A9E2C95DACE6EAAEB470E43A0EC24242ECBE9A3B223FE7D86BF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Stream Utility", "meta_original_filename": "pdbstr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a2248f4e0a242b059409fcbfd73e1320025b9b802b7fc8a1a9d29ac05716cf01/detection", "output": "pdbstr -r/w -p:PdbFileName -i:StreamFileName -s:StreamName\r\n -r/w indicates whether to read or write the stream\r\n -p name of PDB\r\n -s name of stream in the PDB\r\n -i input text file containing stream to write to PDB (in write mode)\r\n -i output text file for writing contents of PDB stream (in read mode)\r\n", "error": "Error while parsing arguments. Usage:\r\npdbstr -r/w -p:PdbFileName -i:StreamFileName -s:StreamName\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\srcsrv\\pdbstr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "srctool.exe-CC3DD5C588F411FA1E8A8488E1890A3A": { "file_name": "srctool.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\srcsrv\\srctool.exe", "hash_md5": "CC3DD5C588F411FA1E8A8488E1890A3A", "hash_sha1": "B876383D85097D3353379F1C76AB8DEBD044D8A7", "hash_sha256": "B910A86B3AE4A14030CC5A0EEB16241624C8F0B3C37D8E3E3114673C2978B6B0", "hash_sha384": "96DA222CBFF93BF382AF295A5B560DC9A5FE527F4BFA2243273D6372B2EB10EB5182E6CC255845E06634249B7D50B844", "hash_sha512": "B250C2E2586B85BF10DEE16ABCE3674287AB8ED5E6930F05F8F6A2160C9A8D2D11A2EA4D11D909792587D5B33FC4C560279B1852595BBA412DA9AD434A04D177", "hash_ssdeep": "768:A+nNFrLsApsLztiL2Kvl0kyNSqKYX9Zo2jMLc+y:A8rXsLztLKv+pNSqKYNZo0Mfy", "hash_imp": "4EA0CBA5DDF2B598E44CBA0FB1FE5764", "hash_pesha1": "F5FE3AACF89EC2A131D5A8CB4B3311D85C66F9F9", "hash_pe256": "0B447F838D8E3D4FEA02958E7789140E66A7EE4363D4AC4FA919E2918202AA2A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Stream Utility", "meta_original_filename": "srctool.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b910a86b3ae4a14030cc5a0eeb16241624c8f0b3c37d8e3e3114673c2978b6b0/detection", "output": "srctool:\r\n Dumps source information from a pdb or srcsrv stream file.\r\n You must specify a pdb, executable, or srcsrv stream file on the\r\n command line.\r\nOptional Parameters:\r\n -u Displays only source files that are not indexed.\r\n -r Dumps raw source data from the pdb.\r\n -s Recurses subdirectories.\r\n -h Dumps the hash/checksum of the source file.\r\n It is valid only when the -r or -u option is selected.\r\n -l:<mask> Limits output to only source files that match this wildcard\r\n expression.\r\n -lf:<mask> Same as -l except that the mask is applied only to the filename.\r\n Directory paths are ignored and all are matched.\r\n -x Extracts the files, instead of simply listing them.\r\n -f Extracts files to a flat directory.\r\n -n shows version control commands and output while extracting.\r\n -d:<dir> Specifies the directory to extract to.\r\n -c Displays only the count of indexed files - no detail.\r\n -z Returns zero on success or nonzero on failure.\r\n -o Displays the full original version control extraction commands,\r\n disabling any VCS-specific output formatting heuristics.\r\n -a Applies all available VCS-specific heuristics to parse the commands\r\n and output their contents in some user-friendly way.\r\n Without this flag, only the Source Depot (Microsoft internal) heuristic\r\n is applied.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\srcsrv\\srctool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "adplus.exe-1285EB619EEBCBB8DC91B8D5389EDB29": { "file_name": "adplus.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe", "hash_md5": "1285EB619EEBCBB8DC91B8D5389EDB29", "hash_sha1": "E3DEA0839D26E2D127E485BC8A96994B8892C6E7", "hash_sha256": "67D387D2C9C4D701958D28851664DC9E93A193BA29DA0173DB2891F4D1CF1D7A", "hash_sha384": "A1095FF9DFB2BD43D02F490DB184A19108E04A198A9D69768B2CBAF722503B2D71B00BE42BE04F8C51E16F3A5C01C3C7", "hash_sha512": "C7520D2D24DF6B5942FE46BE5C3C53F7707A003EF37DE5E138A5021F79F5BB371F039617D0E936F67E0C9BF690ADEB10F7E1D9F6CB9AAA81BEEF3BF9792724C6", "hash_ssdeep": "1536:d8Kjkp0ynhPotyboYSQs1ieSs3YCTbqmC2zPCPXNwcZp3CWVq++FUnZP:qr0yR/EoaX3YCTb42zPCPXNRxweP", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "513726D4542858B406A7FA8A7ADE4C72A1150500", "hash_pe256": "CF4DB7D3AD88566F2DBA25C18AF6B06EC34D5FDFFE4A7A26D5D21822DD4816F2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "Adplus.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Starting ADPlus\r\n********************************************************\r\n* *\r\n* ADPLus Flash V 7.01.007 08/11/2011 *\r\n* *\r\n* For ADPlus documentation see ADPlus.doc *\r\n* New command line options: *\r\n* -pmn <procname> - process monitor *\r\n* waits for a process to start *\r\n* -po <procname> - optional process *\r\n* won't fail if this process isn't running *\r\n* -mss <LocalCachePath> *\r\n* Sets Microsoft's symbol server *\r\n* -r <quantity> <interval in seconds> *\r\n* Runs -hang multiple times *\r\n* *\r\n* ADPlusManager - an additional tool to facilitate *\r\n* the use of ADPlus in distributed environments like *\r\n* computer clusters. *\r\n* Learn about ADPlusManager in ADPlus.doc *\r\n* *\r\n********************************************************\r\n\r\n\r\nADPlus Version 7.01.007 08/11/2011\r\n\r\n====================\r\n| ADPlus Usage |\r\n====================\r\n Command line syntax options\r\n\tADPlus -? or 'ADPlus -help\r\n\t Displays this information.\r\n\r\n\tADPlus -HelpConfig\r\n\t Displays the built-in key-words and the\r\ndefault behavior settings\r\n\r\n\tADPlus <runmode> -o <OutputDirectory> [options]\r\n\tRun Modes:\r\n\t -Crash Runs ADPlus in Crash mode\r\n\t -Hang Runs ADPlus in Hang mode\r\n\r\nSelecting processes to attach\r\n\t-p <PID> Defines a Process ID to be attached\r\n\t-pn <ProcessName> Defines a process name to be attached\r\n\t-po <ProcessName> Defines an optional process name to be attached\r\n\t-pmn <ProcessName> Defines a process name to be monitored\r\n\t\tADPlus will keep monitoring if a process with this name starts\r\n\t\tand attach\r\n\t-sc <spawning command> Defines the application and parameters to be\r\n\t\t started in the debugger\r\n\t\t The -sc switch, if used, must be the last one\r\n\t-iis All iis related processes will be attached\r\n\t\t like inetinfo, dllhost,mtx, etc.\r\n\r\nSymbol Path Options\r\n-y <symbol path> Defines the symbol path to be used\r\n-yp <symbol path to add> Defines an additional symbol path\r\n-mss <local cache> Adds Microsoft Symbol Server to the symbol path\r\n\r\nMemory Dump Options\r\n-FullOnFirst Sets ADPlus to create full dumps on first chance exceptions\r\n-MiniOnSecond Sets ADPlus to create mini dumps on second chance exceptions\r\n-NoDumpOnFirst Sets ADPlus to not create any dumps on first chance exceptions\r\n-NoDumpOnSecond Sets ADPlus to not create any dumps on second chance exceptions\r\n-do Dump Only - changes default behavior to not include additional info, just a dump\r\n\r\nMiscellaneous Options\r\n-c <config file name> Defines a configuration file to be used\r\n-o <output directory> Defines the directory where logs and dumps are\r\n to be placed.\r\n-r <quantity> <interval in seconds> for multiple attachments in hang mode\r\n-dbg <debugger> Allows you to select the debugger to be used\r\n cdb, windbg or ntsd (default is cdb)\r\n-dp Debuggers path\r\n-gs only generates the script file\r\n\r\n-ce <custom exception code> Defines a custom exception to be monitored\r\n -ce 0x80501001\r\n\r\n-bp <breakpoint parameters> Sets a breakpoint\r\n Syntax: -bp address;optional_additional_parameters\r\n -bp MyModule!MyClass::MyMethod\r\n -bp MyModule!MyClass::MyMethod;MiniDump\r\n\r\n-CTCF Creates a full dump on CTL+C, and quits\r\n-CTCFB Creates a full dump on CTL+C, and breaks into the debugger\r\n-CTCV No special action on CTL+C, just breaks in for user interaction\r\n-lcq sets the last script command to Q (quit)\r\n-lcg sets the last script command to G (go)\r\n-lcgn sets the last script command to GN (go not handled)\r\n-lcqd sets the last script command to QD (quit and detach)\r\n-lcv sets the last script command to void (no command; waits for user input)\r\n-q2 sets the return action for second chance exceptions to Q (quit)\r\n-g2 sets the return action for second chance exceptions to GN (go not handled)\r\n\r\n\r\n-quiet No dialog boxes will be displayed (no more required)\r\n-notify <destination> Will send a message to the destination\r\n\r\n\r\nExamples:\r\n ADPlus -hang -iis -o c:\\dumps\r\n Produces memory dumps of IIS and all \r\n MTS/COM+ packages currently running.\r\n\r\n ADPlus -crash -p 1896 -o c:\\dumps -mss c:\\symbols\r\n Attaches the debugger to process with PID 1896\r\n and monitors it for 1st and 2nd chance access violations and uses\r\n Microsoft's public symbol server with c:\\symbols as a local cache\r\n\r\n-------------------------------------------------------------------------------\r\n\r\n HELP and Documentation\r\n\r\n For more detailed information on how to use and config ADPlus please see\r\n the debugger's help file (debugger.chm) under Extra Tools\r\n However, be aware that this is a new version of ADPlus and debugger.chm\r\n may take some time to be updated\r\n Check for ADPlus.doc in the debuggers' folder\r\n-------------------------------------------------------------------------------\r\nCurrent log content\r\n\r\nADPlus Engine Version: 7.01.007 08/11/2011\r\nCommand line arguments used were: \r\n-help \r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "adplusmanager.exe-3A6F1EE12C9A6189B127DC7BC314C002": { "file_name": "adplusmanager.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplusmanager.exe", "hash_md5": "3A6F1EE12C9A6189B127DC7BC314C002", "hash_sha1": "8AD6352A2D93E7AF4833C3F225AF9559AA0DF376", "hash_sha256": "41B4ABB46D95A5D85F64D99E4D86B9785EEA0144F905B133795D227354871717", "hash_sha384": "3B5326862C927371B3B342098EC5A339CAD8171549491DE212AC425E35F2970B547F9DEA7D0A190316E6D8BE81530908", "hash_sha512": "9D6A9CD303AFF4796EFD188F5A7D83CDA321A0CE6E328E8AA259E0A6CB398B40D1F9944B040E820DA319D636288A9B7AC64AED5793C76730DEDB8289EB375264", "hash_ssdeep": "768:tZsFKlZ8Kc41WjT4TNegAuDk+rGbG/+B+OzUaGNUXXpidOD:7luaWgpRDkPbr+68OXXYQ", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "36E69E1645A97F8E5F8DBAF6E3484F15F2FAD66C", "hash_pe256": "053B3AEC10557775F59DE8C7BA3C72430C3F486754AA9C3AC262B903E5A8BDDF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "AdplusManager.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "children": "Fondue.exe", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplusmanager.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "agestore.exe-989AFAFCFA9169B748F83D5D26056767": { "file_name": "agestore.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\agestore.exe", "hash_md5": "989AFAFCFA9169B748F83D5D26056767", "hash_sha1": "1111BD760FD5DACD23DA58AD0E9B41131B0A1E7D", "hash_sha256": "66E7E3434376EBF4CD942D9D942317187E1841F295ABC74A5C5B71166E18DECC", "hash_sha384": "DC917E25FBF6A884B88C2B0A44202B674AA2D958A46B04A08A98D7096F163C74676DE498E6B3C96A1F59BEEC7679133F", "hash_sha512": "2185DB81C23D67993E1724588B8D6A523613C26ED43CDAB79A4DCB656A5F81792B27AEF2C21CBF58784B662CC5E371589F7949A06E75FFC5F4B834448D54452B", "hash_ssdeep": "384:H5WEH1ZKMloTObvK8X7DaOePKteWSU6ZWvh+uwGy6ifl/zde:ZbHN7DQytg8+ui", "hash_imp": "8377D170587C399850EDF9713DDCA88D", "hash_pesha1": "F3C95B657B28EDE9C4421A1091A56C1C9EA1D560", "hash_pe256": "420DA9187B47133532C0E9F379F0B84BEE31D70AEC0386BA91CB480A9993233D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft AgeStore", "meta_original_filename": "agestore.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Last-Access-Time support is disabled on this computer.\r\nPlease read the documentation for more details.\r\nAgestore will use the file creation time as the last access time.\r\nplease select either -date, -days, or -size\r\n\r\nagestore [pathspec]\r\n\r\nDeletes all files from a directory based on the last access time of the files.\r\n[pathspec] defines the root path and file specification.\r\nThe default is all files in the current working directory\r\n\r\nIt runs in one of these modes...\r\n\r\n-date=mm-dd-yy - deletes all files that were last accessed before the specified date.\r\n-days=xx - deletes all files that were last accessed before today minus the\r\n amount of days specified by 'xx'. \r\n-size=xx - deletes files in order of last access time (oldest first), until all the\r\n files in the directory total to the amount of bytes specified by 'xx'.\r\n-size - lists the amount of bytes in the directory.\r\n-lat=<on/off> - toggles filesytem support for last-access-time.\r\n\r\nThese other command line switches alter the behavior of the program.\r\n\r\n-l - list files only, don't delete\r\n-s - include subdirectories.\r\n-k - keep empty subdirectories - normally they are removed.\r\n-q - quiet mode stops listing of files as they are deleted.\r\n-y - eliminates the (y/n) prompt.\r\n-r - deletes RO files\r\n\r\nThis program deletes files. You should run agestore with the -l switch\r\nto see what it will delete, before actual usage.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\agestore.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "breakin.exe-C497DAE11153EE3DE357D5E375E17E60": { "file_name": "breakin.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\breakin.exe", "hash_md5": "C497DAE11153EE3DE357D5E375E17E60", "hash_sha1": "8A7285FBEE44F45A2578D0A9909BF0B6FCC84D26", "hash_sha256": "D78FB281572D505D72A337152EFDF32B2E10F2A004DB4F86AE81C1FC747E0667", "hash_sha384": "28CE2E1C6D4D33BE295C2E4BC9C8FD03FB3EDC15C4C063A98279E79581B53DCEA2FA477FA75F01EE6D7AC4E136D44887", "hash_sha512": "4519A12743DF59FA27C1F933FBC17642A60E4F6120AE2D26F52971F688EC8DC8B7E7B76CB79680CE37614FE82D8D55E3F2E59BC0F18218B374E3E30F02CF3A60", "hash_ssdeep": "384:8aeTF6/zWKEO0xaWSkcGWYGNW6LwGyJE7olz8F:J3/P7QrSkcf1zI", "hash_imp": "E8F5B6B7002A3987061C7F6ED8FB24A5", "hash_pesha1": "36515488610775E9450BBB57ED23DE7E6342334B", "hash_pe256": "2AC93D564DA7B639A895A4B6E5284132027C5D9CC4445C1E3798B09022BF37B6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Breakpoint forcer", "meta_original_filename": "breakin.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "usage: breakin <pid>\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\breakin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cdb.exe-6E953EFEB12896AC0EC17D198902FAE1": { "file_name": "cdb.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe", "hash_md5": "6E953EFEB12896AC0EC17D198902FAE1", "hash_sha1": "8FAF07B823ECE7885A4AFA7834364B8D931C0976", "hash_sha256": "F63FE4CB27BB604707AB4E5A96BBF74D9940A278F488740DC72F6788B2CD422E", "hash_sha384": "D8F0784655359F9777408731AE8C7ACB27F62A2630FB779D68C03CB6114F292111BCE11C52B3A23066313C42B4CE928F", "hash_sha512": "2DA8C6FD8DD34E5673BB8AA266E2F45DF5DE5D71A14534720B33A495B1CAD34C196859F9FF02D7758D722035F954156ED6B9EA0A79523E084811C013C3849040", "hash_ssdeep": "3072:IW+k5FnbMomoWATua+Ah7aBvOu6eIgJ0xi+RB7M:IWoWvgJ0x1f7M", "hash_imp": "016D37B1E2EF9A623D81C30DB609F838", "hash_pesha1": "3D1385F5614C5C71A707035FAED442AF1FEE0911", "hash_pe256": "A60BAD5A4E4138A303E58DED15ECDA10E7ED522F24538E80D9B14D53F203A71F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbolic Debugger for Windows", "meta_original_filename": "CDB.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "cdb: Invalid switch 'h'\ncdb version 10.0.19041.1\nusage: cdb [options]\n\nOptions:\n\n <command-line> command to run under the debugger\n -? displays command line help text\n -- equivalent to -G -g -o -p -1 -d -pd\n -2 creates a separate console window for debuggee\n -a<DllName> adds a default extension DLL\n -bonc request break in after session started\n -c \"<command>\" executes the given debugger command at the first debugger\n prompt\n -cf <file> specifies a script file to be processed at the first debugger\n prompt\n -cfr <file> specifies a script file to be processed at the beginning of a\n session (including after .restart)\n -cimp uses implicit create command line from a process server\n -clines <#> number of lines of output history retrieved by a remote client\n -d sends all debugger output to kernel debugger via DbgPrint\n input is requested from the kernel debugger via DbgPrompt\n -d cannot be used with debugger remoting\n -d can only be used when the kernel debugger is enabled\n -ddefer sends all debugger output to kernel debugger via DbgPrint\n input is requested from the kernel debugger via DbgPrompt unless\n there are remote clients that can provide input\n -ddefer can only be used when the kernel debugger is enabled\n -ddefer should be used with -server\n -ee <name> set default expression evaluator\n <name> can be MASM or C++\n -failinc causes incomplete symbol and module loads to fail\n -g ignores initial breakpoint in debuggee\n -G ignores final breakpoint at process termination\n -hd specifies that the debug heap should not be used for created processes. \n This only works on Windows XP and later\n -i <ImagePath> specifies the location of the executables that generated the\n fault (see _NT_EXECUTABLE_IMAGE_PATH)\n -iae install as AeDebug debugger\n -iaec <Command> install as AeDebug debugger with given command tail\n -isd sets the CREATE_IGNORE_SYSTEM_DEFAULT flag in STARTUPINFO.dwFlags\n during CreateProcess\n -iu install dbgeng URL protocols\n -kqm turns on kd quiet mode (equivalent to KDQUIET)\n -lines requests that line number information be used if present\n -loga <logfile> appends to a log file\n -logau <logfile> appends to an Unicode log file\n -logo <logfile> opens a new log file\n -logou <logfile> opens a new Unicode log file\n -myob ignores version mismatches in DBGHELP.DLL\n -n enables verbose output from symbol handler\n -netsym:yes|no allow or disallow loading symbols from a network path\n -noinh disables handle inheritance for created processes\n -noio disables all I/O\n -noshell disables the .shell (!!) command\n -nosqm disables SQM data collection/upload.\n -o debugs all processes launched by debuggee\n -openPrivateDumpByHandle <HANDLE> \n specifies the handle of a crash dump file to debug\n -p <pid> specifies the decimal process ID to attach to\n -pb specifies that the debugger should not break in at attach\n -pd specifies that the debugger should automatically detach\n -pe specifies that any attach should be to an existing debug port\n -pn <name> specifies the name of the process to attach to\n -pr specifies that the debugger should resume on attach\n -psn <name> specifies the process to attach to by service name\n -premote <transport>:server=<name>,<params> \n specifies the process server to connect to\n transport arguments are given as with remoting\n -pt <#> specifies the interrupt timeout\n -pv specifies that any attach should be noninvasive\n -pvr specifies that any attach should be noninvasive and nonsuspending\n -QR \\\\<machine> queries for remote servers\n -r <BreakErrorLevel> specifies the (0-3) error level to break on (see\n SetErrorLevel)\n -remote <transport>:server=<name>,<params> \n lets you connect to a debugger session started with -server\n must be the first argument if present\n transport: tcp | npipe | ssl | spipe | 1394 | com\n name: machine name on which the debug server was created\n params: parameters the debugger server was created with\n for tcp use: port=<socket port #>\n for npipe use: pipe=<name of pipe>\n for 1394 use: channel=<channel #>\n for com use: port=<COM port>,baud=<baud rate>,\n channel=<channel #>\n for ssl and spipe see the documentation\n example: ... -remote npipe:server=yourmachine,pipe=foobar\n -robp allows breakpoints to be set in read-only memory\n -s disables lazy symbol loading\n -sdce pops up dialogs for critical errors\n -server <transport>:<params> \n creates a debugger session other people can connect to\n must be the first argument if present\n transport: tcp | npipe | ssl | spipe | 1394 | com\n params: connection parameterization\n for tcp use: port=<socket port #>\n for npipe use: pipe=<name of pipe>\n for 1394 use: channel=<channel #>\n for com use: port=<COM port>,baud=<baud rate>,\n channel=<channel #>\n for ssl and spipe see the documentation\n example: ... -server npipe:pipe=foobar\n -ses enables strict symbol loading\n -sflags <flags> sets symbol flags from a numeric argument\n -sicv ignores the CV record when symbol loading\n -sins ignores the symbol path environment variables\n -snc converts :: to __ in symbol names\n -snul disables automatic symbol loading for unqualified names\n -srcpath <SourcePath> specifies the source search path\n -sup enables full public symbol searches\n -t <PrintErrorLevel> specifies the (0-3) error level to display (see\n SetErrorLevel)\n -v enables verbose output from debugger\n -version shows the build version\n -vf enables default ApplicationVerifier settings\n -vf:<opts> enables given ApplicationVerifier settings\n -w specifies to debug 16 bit applications in a separate VDM\n -wake <pid> wakes up a sleeping debugger and exits\n -x sets second-chance break on AV exceptions\n -x{e|d|n|i} <event> sets the break status for the specified event\n -y <SymbolsPath> specifies the symbol search path (see _NT_SYMBOL_PATH)\n -z <CrashDmpFile> specifies the name of a crash dump file to debug\n -zd <CrashDmpFile> specifies the name of a crash dump file to debugand\n deletes that crash dump after the debugger has finished\n using it\n -zp <CrashPageFile> specifies the name of a page.dmp file to use with a\n crash dump\n -plmPackage <PlmPackageFullName> \n specifies the UWP package to be started. Needs '-plmApp' or '-plmPackage'\n option, but not both.\n -plmApp <PlmApplicationName> \n specifies the UWP application to be started. Needs '-plmPackage' option. \n -plmBgTaskId <PlmBackgroundTaskId> \n specifies the UWP background task to be activated. Needs '-plmPackage'\n option. \n\nEnvironment Variables:\n\n _NT_SYMBOL_PATH=[Drive:][Path]\n Specify symbol image path.\n\n _NT_ALT_SYMBOL_PATH=[Drive:][Path]\n Specify an alternate symbol image path.\n\n _NT_DEBUGGER_EXTENSION_PATH=[Drive:][Path]\n Specify a path which should be searched first for extensions dlls\n\n _NT_EXECUTABLE_IMAGE_PATH=[Drive:][Path]\n Specify executable image path.\n\n _NT_SOURCE_PATH=[Drive:][Path]\n Specify source file path.\n\n _NT_DEBUG_LOG_FILE_OPEN=filename\n If specified, all output will be written to this file from offset 0.\n\n _NT_DEBUG_LOG_FILE_APPEND=filename\n If specified, all output will be APPENDed to this file.\n\n _NT_DEBUG_HISTORY_SIZE=size\n Specifies the size of a server's output history in kilobytes\n\nControl Keys:\n\n <Ctrl-B><Enter> Quit debugger\n <Ctrl-C> Break into Target\n <Ctrl-F><Enter> Force a break into debuggee (same as Ctrl-C)\n <Ctrl-\\><Enter> Debug Current debugger\n <Ctrl-V><Enter> Toggle Verbose mode\n <Ctrl-W><Enter> Print version information\n", "children": [ "conhost.exe", "help.exe" ], "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RWD) C:\\Windows\\SysWOW64\\ntdll.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_webcache_counters_{9B6AB5B3-91BC-4097-835C-EA2DEC95E9CC}_S-1-5-21-2047949552-857980807-821054962-504": "Section", "\\BaseNamedObjects\\F932B6C7-3A20-46A0-B8A0-8894AA421973": "Section", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\sym\\wntdll.pdb\\3CCC2398F623C3D0915D0E0ADC5714A71\\wntdll.pdb": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R-D) C:\\Windows\\System32\\en-US\\mswsock.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "convertstore.exe-47A94D2F58F4C4E6D08A74B0FEDC89A5": { "file_name": "convertstore.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\convertstore.exe", "hash_md5": "47A94D2F58F4C4E6D08A74B0FEDC89A5", "hash_sha1": "F62136A19985E7C221C33CF94066EC6844307AE9", "hash_sha256": "0F72BA15E5B4D2165442A2E5067112CA39DBC662D6AACD39DEF798C0B611A79B", "hash_sha384": "5CCED5772EB87A84CF21BCB8641EEF89DC2A6B77ABB9C5005E84775763D15382DD343F31022CF85BF622993FB642459B", "hash_sha512": "DAC463B25F11B156E8333FC8D9152FF91B1398A8B1A79527EFC7C91DBCE03FCB73E8917AE47433237A639FCB5A4D9A66BFF21A45C42BC7B45FE33AAE973E3A7A", "hash_ssdeep": "384:VedjTrRcEAkitxblnH//rJQMeMo8EQL/ehZm2FWA9W0wGywvGzIwS+klTxs:VeNrOvPH6MeMv/Um2Zv9vgdOs", "hash_imp": "6E4B288FAC76E6107FB6FC0F6D9BA9D6", "hash_pesha1": "0EF6221F6EB8C591A309630B7C22B5518F46213E", "hash_pe256": "F5167BBC1E049327D6BFACC823EB6BBBF1F16903064AF777896BBCE5B95131B6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbol Store Conversion Utility", "meta_original_filename": "ConvertStore.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "convertstore.exe -s <StoreToConvert>\r\n Converts <StoreToConvert> from a 2-tiered symbol store\r\n to a 3-tiered symbol store.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\convertstore.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dbengprx.exe-90E3A624B75BB6DFE21185A444F0E68C": { "file_name": "dbengprx.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dbengprx.exe", "hash_md5": "90E3A624B75BB6DFE21185A444F0E68C", "hash_sha1": "3D13D9BD1362B64E55AF53D155D4A35DFA668DAD", "hash_sha256": "7B20AA2BAFA06805C8B827CDC80A680FC7E6D2A56C539EB95F684FE131564115", "hash_sha384": "F5219328BC9F4FD633FB23F89203D99CC0291D9BC586DC4715F1DF63A1F2570227D662EE9CB7624D8FBF480C3083C6F3", "hash_sha512": "7D65210F3011E2FB2FB3012C74205A6E9965AB63C0DF89BBF5578754185675E4D23566F1DCC879F0E42F3976459544A07B7FBB588D5E6C7390E20A643EAC7685", "hash_ssdeep": "1536:vOmoWWTuaPhD2GWmLbOhCl9Hg7AxUApY/0WkrtIyoG6Kin/1rcdv:WmoWWTuaPvxVHMYGkrEGbin/1rc", "hash_imp": "7388D969348BFF044602F6C4C8F478D9", "hash_pesha1": "001742D9CABE3A2DBEBA14E1CBAB7E582B97657E", "hash_pe256": "602A6E9CE78F6C4542C964BE18C3A21BD8A23815C9AC9F6C0193272DFA0A2ACE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Debugger Transport Proxy Server", "meta_original_filename": "dbengprx.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Invalid Command Line: Usage: dbengprx [-p] -c <transport> -s <transport>\r\n transport: tcp | npipe\r\n for tcp use: port=<socket port #>\r\n for npipe use: pipe=<name of pipe>\r\n\r\nExample: machine A = server, B = proxy, C = client\r\n A: start cdb -server tcp:port=1234 <...>\r\n B: start dbengprx -c tcp:port=1234,server=A -s tcp:port=1235\r\n C: start cdb -remote tcp:port=1235,server=B\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dbengprx.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dbgrpc.exe-A69AFA400FF6F3CFD96BEB8F997EC2A1": { "file_name": "dbgrpc.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dbgrpc.exe", "hash_md5": "A69AFA400FF6F3CFD96BEB8F997EC2A1", "hash_sha1": "1BB268EB9353BE4A7F7C344E34B6A17527216FF3", "hash_sha256": "C532C4AFFA1F444472FF6E837FE5419FED36ECA57541E4015CAA21ADDBA69C05", "hash_sha384": "67343D94ABC9AEF3408764FB5A261063CD786AB6773ACC4FC098A9C48A7F7EC87AC9EEEFCC407B31068CFC600B9AC0B5", "hash_sha512": "2D5FF90C58966C0D8116BBBA752EB9938B7D6A3EF43C0F118CD89E5C0799CACA2E1096A9F899118F4DE40142AE9DE100F2722B468FEF386F6E74C9D7546F061C", "hash_ssdeep": "384:RGUbHD9q4bzeWOVc/c14Xdv+/d6t51Q2sDjxts/CWIdWJIwGyvCCTluN:RrbTbiLyUpaKj0/sqIECCy", "hash_imp": "DC32ED141E304EB5A540B8285C4296B0", "hash_pesha1": "519125F42C19C046965346E09A16DA9296DE7FE3", "hash_pe256": "F9D3358E2A27D89E4493F160C2F36A3A8BF4BCBF5126E35FDB1CF627245ADC50", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RPC Extended Debugging Utility", "meta_original_filename": "RpcDbg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Usage: C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dbgrpc.exe: -s <server> -p <protseq> -C <CallID> -I <IfStart>\r\n-N <ProcNum> -P <ProcessID> -L <CellID1.CellID2>\r\n-E <EndpointName> -T <ThreadID> -r <radix> -c -l -e -t -a\r\nExactly one of -c, -l, -e, -t, or -a have to be specified.\r\nThe valid combinations are:\r\n-c [-C <CallID>] [-I <IfStart>] [-N <ProcNum>] [-P <ProcessID>]\r\n-l -P <ProcessID> -L <CellID1.CellID2>\r\n-e [-E <EndpointName>]\r\n-t -P <ProcessID> [-T <ThreadID>]\r\n-a [-C <CallID>] [-I <IfStart>] [-N <ProcNum>] [-P <ProcessID>]\r\n-s, -p and -r are independent to the other options. -r affects\r\nonly options after it on the command line. Default is 16 (hex)\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dbgrpc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dbgsrv.exe-A51A101856B837AD3EFFDD1A79575165": { "file_name": "dbgsrv.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dbgsrv.exe", "hash_md5": "A51A101856B837AD3EFFDD1A79575165", "hash_sha1": "FA3823ACDC8ADBADEF06B4D4A906F75CD1347899", "hash_sha256": "AFB9FBCF0EBB2789BC0B59CFDFAB144B5DF8FF1FCED15D472A9C4DC506146E38", "hash_sha384": "D53E96D869596E3FD6F1D3592522E0DC47E4BCB1655014FF637E845090C8F4BC922006DB75D9D07B94B5CE4CD00DF3CF", "hash_sha512": "4A147A01725E0C82076A88DB8F34068A2B4E87F580815F9F840F306C2D67BBFED2050CFEA6B65EA59F00C784B0349CA347E18ECD394A202FEBCCFDE9D11C0846", "hash_ssdeep": "768:ymoW4gP2TuaMgthdufu7EdEpSOWP5Wwt6Xc85qkQ+Ejd0Cc:ymoWATuajvv7EdEoOS5WwttkQdm", "hash_imp": "97692A2CA1616DD5AF6732FB35BA7360", "hash_pesha1": "22E50190347B37A1B287932DB7FA55547E994D97", "hash_pe256": "972699F2911147842012310FB5DB0C6004ADE960749CE37C86EFE97A74BF8AEF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft User-Mode Debugger Process Server", "meta_original_filename": "dbgsrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Invalid Command Line: Usage: dbgsrv -t <transport> [-sifeo <image.ext>] [-x] [-c[s] <args...>] [-pc <args...>]\r\n transport: tcp | npipe | ssl | spipe | 1394 | com | hyperv \r\n for tcp use: port=<socket port #>\r\n for npipe use: pipe=<name of pipe>\r\n for 1394 use: channel=<channel #>\r\n for com use: port=<COM port>,baud=<baud rate>,\r\n channel=<channel #>\r\n for hyperv use: vmid=<vm id GUID>,serviceid=<service id GUID>\r\n for ssl and spipe see the documentation\r\n\r\nExample: dbgsrv -t npipe:pipe=foobar\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dbgsrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dbh.exe-906FDD0B925293C493F59B8DDF1A47B7": { "file_name": "dbh.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dbh.exe", "hash_md5": "906FDD0B925293C493F59B8DDF1A47B7", "hash_sha1": "7C8920348924F328A0584A8DE41A87BB9808607F", "hash_sha256": "F18B39801BABDAE4C7508AE2303AACD44AF1DB36F11F4C0B719953B25C26CB83", "hash_sha384": "E4A9FB4D206CBE74D7E8A666C2564B187024514A2F78E405ACB5F8AB688F51D2DD63192D3CE7A05269652FCAE5C3B07A", "hash_sha512": "1DC317E7DBD59AA4116DCDE52EB9C05090514005D96F4ECBF98D71BA272F7C387312331BDF1C88C64768543276411182484CBE473AB9F2480636951A300140FE", "hash_ssdeep": "3072:VGG3awLETEZXFei81Qa3pIsg/1eiQGg8toYKsa9qeZFdXsF9XXG0/OVuwD:XsTb3pg9ltrKsqquFdXIxdmVx", "hash_imp": "E75B4391949C151C9B49088F94EF90E6", "hash_pesha1": "FA0F859233D821A64AFDD0C2B27D779C843A7846", "hash_pe256": "7AC200CD5E91459FC14D3F4C8CFBC76DECF317B016F28525570C59A5FC071B31", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Dbghelp API Example", "meta_original_filename": "dbh.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\n dbh commands :\r\n? help : prints this message\r\nq quit : quits this program\r\nv verbose <on/off> : controls debug spew\r\n load <modname> : loads the requested module\r\nu unload : unloads the current module\r\nx enum <mask> : enumerates all matching symbols\r\nn name <symname> : finds a symbol by it's name\r\na addr <addr> : finds a symbol by it's hex address\r\nm enumaddr <addr> : lists all symbols with a certain hex address\r\nb base <address> : sets the new default base address\r\ns next <add/nam> : finds the symbol after the passed sym\r\np prev <add/nam> : finds the symbol before the passed sym\r\nl line <file#num> : finds the matching line number\r\n laddr <address> : finds a source line by it's corresponding hex address\r\nj linenext : goes to the next line after the current\r\nk lineprev : goes to the line previous to the current\r\nsrchtree <path> <file> : finds file in path\r\n ffpath <file> : finds file in symbol path\r\nr src <mask> : lists source files\r\n+ add <name addr> <sz> : adds symbols with passed name, address, & size\r\n- del <name/addr> : deletes symbols with passed name or address\r\nz locals <func> <mask> : finds all locals a function\r\n multi <name> : loads the requested module 1000 times\r\nt type <name> : lists the type information for the symbol\r\ni info : displays information about the loaded module\r\no obj <mask> : displays object files in the loaded module\r\ne elines <src> <obj>: enumerates lines with optional src mask and obj mask\r\n srch <parameters> : enumerates all symbols - use 'srch ?' for help\r\n dtag : displays all the symtag values\r\n undec <name> : undecorates a given symbol name\r\n findexe <name> <path> : locates an image in the symbol path\r\n finddbg <name> <path> : locates an dbg file in the symbol path\r\n sympath <path> : sets or displays the symbol search path\r\n dir <fname> <path> : calls EnumDirTree to find filename on path\r\n index <val> : finds symbol with matching index value\r\n scope <add/nam> : finds the parent of a symbol\r\n etypes : enumerates all types\r\n enummod : enumerates all modules\r\n sup <pth> <fil> <fil> : finds the symbol server supplement to store\r\n srvind <file> : finds the symbol server index for store\r\n srvpath <path> : tests if path is to a symbol store\r\nstoreadd <fil> <store> : adds a file to a symbol store\r\n getsym <img> <sym> : finds the matching symbol for and image\r\n getfile <name> <idx>> : finds a file based on the symbol server index\r\nsrclines <file> <line> : finds matching source lines\r\n mod <base> : changes default module\r\n refresh : refreshes the module list\r\n home <path> : sets the home directory\r\n omap : dumps the module omaps\r\n setret : toggle the return value of enum procs\r\n symopt <+/-><opt> : sets or displays the current symbol options\r\n epmod <process id> : enumerate the modules loaded for a given process\r\n dump : dumps all function symbols\r\n uw <address> : gets the unwind info for a function\r\n fii <file> : dumps the symsrv indexes for a binary and assciated files\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dbh.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dumpchk.exe-AC21502E9E462CD40F1822EDE9BADE53": { "file_name": "dumpchk.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dumpchk.exe", "hash_md5": "AC21502E9E462CD40F1822EDE9BADE53", "hash_sha1": "BE6D8ED00FDAEF61AA7AD4D9B5A6EFE9A3F254EA", "hash_sha256": "1D06680E23D1FDCC8DB41D2A7C2AFFA427D61962F88FA65AD49E07755C49C3C9", "hash_sha384": "CD11648D1279B32BF0F2E711D4C369B67EDE30BA2C36ADC9DCED234E469C4138D377AD4B233D9E450E4E711C26FAF780", "hash_sha512": "D376EF88C29FE7C3BB1A713D4249AAD0A7262988A507FEB5B92CE776A9EDE14A5E066CE382E96980FB5A862033428AB83E0E2CA69E9899462500324A38F241B8", "hash_ssdeep": "192:lNDO1/R3ofAf9NW/fxOatP1mcGWfxWkuuWSawTyihVWQ4eWLmX0884LfqnajJNej:lNDOvFf9NWw2YcGWfxWTzwGy3bJllNJ", "hash_imp": "991782CA704A3D06F1879642A25290AC", "hash_pesha1": "930DD8EAA02D613F9A2EEB91658395CB34813753", "hash_pe256": "C5F85D9961B219EE6ED64C6A6297B96C730F8081E0D81BD1044F3F229732413D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Dump File Verifier", "meta_original_filename": "dumpchk.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1d06680e23d1fdcc8db41d2a7c2affa427d61962f88fa65ad49e07755c49c3c9/detection", "error": "Usage: C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dumpchk.exe [-y <sympath>] <dumpfile>\r\n", "output": "\r\nMicrosoft (R) Windows Debugger Version 10.0.19041.1 X86\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\n\r\nLoading Dump File [C:\\Users\\user\\help]\r\nCould not match Dump File signature - invalid file format\r\nCould not open dump file [help], Win32 error 0n87\r\n \"The parameter is incorrect.\"\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dumpchk.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dumpexam.exe-BB5B5EF474C3B2C1AFCF9337712B3293": { "file_name": "dumpexam.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dumpexam.exe", "hash_md5": "BB5B5EF474C3B2C1AFCF9337712B3293", "hash_sha1": "9E07CFA496FD19E43BB8684C4966DBE873DD6474", "hash_sha256": "A2D4658B878F6B822D3473FCF4382997A661CB85DA8739B59276FCAF94F76E6D", "hash_sha384": "196045AF258B25106C235041DC218C636DF46FF0F5F9ED0C8B6101C8BDD0E98EF0E78994086664C32715778321A11CA7", "hash_sha512": "E66348FF7708D8B9DB51884E32763BCFB0DE288B71E9B0EF91AD17E6FFC9ACC00ACCACD063BE8A804CB92CE6DFA8969E9B2DDAB1C3F2FCC44391CC1F10A4F758", "hash_ssdeep": "192:bL3qdtLY69qZDNHtH1M0OWH4W5ijSWSawTyihVWQ4eWuoa5M8xOSqnaj3yS:bbGLl9q9+0OWH4WYrwGyaCTlu", "hash_imp": "3452BF5D29DD034D1C1679E9C024FCB5", "hash_pesha1": "235588E47866BE1F13EE435B4BDC748012A189F0", "hash_pe256": "75F6CA728EB5E37C8839A1718E9BF4B8064164C8680815565BBB9BA7364C6D0F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Dump File Examiner", "meta_original_filename": "dumpexam.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "\r\n\r\n\r\n\r\n***************************************************************************\r\n***************************************************************************\r\n** **\r\n** This tool is no longer supported. It's functionality has been **\r\n** merged into the kernel debugger. You can examine a dump file by **\r\n** loading it in the kernel debugger **\r\n** **\r\n** kd -z <dump_file_name> -y <symbol_path> [-i <image_path>] **\r\n** **\r\n** and running commands such as !vm, !process, !locks, etc... **\r\n** **\r\n** Please refer to the debugger documentation for more information **\r\n** on analyzing system failures. **\r\n** **\r\n***************************************************************************\r\n***************************************************************************\r\n\r\n\r\n\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\dumpexam.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "gflags.exe-8B6FDD8FEF0CABD5CC556E1BC81D0B7C": { "file_name": "gflags.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\gflags.exe", "hash_md5": "8B6FDD8FEF0CABD5CC556E1BC81D0B7C", "hash_sha1": "19B5B811B6B72EB3747D46F6906FC216B9FBDFDD", "hash_sha256": "FA1B9EA024C6C7FABE70063DBF5AF5C63A11C57E1B305BDB61A42596CC032E9A", "hash_sha384": "8E1E2D47ED8DAB9A40A9BBC45D6551FC3C7804977D61506E46F741B9915F0D70CAA1F9D116F182D3DBF25800F38F3068", "hash_sha512": "5C9E856A688EEF3A2322CD92EECDBC7D333E393C01B3A5FAF234A15A8369F38D53026153937B0A0DC45DE2E825A9A2A60320440E83A4903FA824EFEBA72D3362", "hash_ssdeep": "768:7PnlUMWZi2meQwB7kb9ijEbhI+ZZ3E1CgNk6zVTgs0tMMTmiVz04+u:Ln+QehYI4bhI+ZwCg390/T/Vzd", "hash_imp": "75F1792141528D908A41983417EE84F2", "hash_pesha1": "D07590DB0425B6832BC8828B7D7FF6670C186A3F", "hash_pe256": "347750733BD21C8C42A738714194E6E12AA5F7DFE276789DE77AA80DC68A0ACF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft NT Global Flags Manipulator", "meta_original_filename": "GFLAGS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/fa1b9ea024c6c7fabe70063dbf5af5c63a11c57e1b305bdb61a42596cc032e9a/detection", "error": "GFLAGS: Unexpected argument - '-help'\r\n \r\nusage: GFLAGS [-r [<Flags>]] | \r\n [-r +spp TAG | -r +spp SIZE | -r -spp | \r\n [-k [<Flags>]] | \r\n [-k +spp TAG | -k +spp SIZE | -k -spp] |\r\n [-ro [-d | { -i <ImageFileName> | -t <PoolTag>[;<PoolTag>...] } [-p] ] | \r\n [-ko [-d | { -i <ImageFileName> | -t <PoolTag>[;<PoolTag>...] } [-p] ] | \r\n [-i <ImageFileName> [<Flags>]] | \r\n [-i <ImageFileName> -tracedb <SizeInMb>] |\r\n [-p <PageHeapOptions>] (use `-p ?' for help) | \r\n \r\nwhere: <Flags> is a 32 bit hex number (0x12345678) that specifies \r\n one or more global flags to set. \r\n -r operates on system registry settings. \r\n -r +spp TAG - Set Special Pool tag value. \r\n TAG can have up to four characters. \r\n -r +spp SIZE - Set Special Pool block size value. \r\n SIZE must be in hex format, starting with characters 0x. \r\n -r -spp - Disable Special Pool tag or block size. \r\n -k operates on kernel settings of the running system. \r\n -k +spp TAG - Set Special Pool tag value at run time.\r\n TAG can have up to four characters.\r\n -k +spp SIZE - Set Special Pool block size value at run time.\r\n SIZE must be in hex format, starting with characters 0x.\r\n -k -spp - Disable Special Pool tag or block size at run time.\r\n -ro operates on object reference tracing at boot time. \r\n -ko operates on object reference tracing at run time. \r\n -d disables object reference tracing. Do not specify any \r\n other tracing options. \r\n -i <ImageFileName> specifies the image name for which \r\n to capture traces. All processes started up with this \r\n image file will be traced. \r\n -t <PoolTag>[;<PoolTag>...] specifies the pool tags for which \r\n to capture traces. Pool tags should be 4 letters each, \r\n separated by ';'. This value is case sensitive. \r\n -p maintains traces after the objects are destroyed(permanent).\r\n By default traces are temporary. \r\n Unless you are using -d you must specify at least one of the \r\n -i or the -p options. You may specify both in which case \r\n objects with a pool tag that is among the list of pool tags \r\n you specify, created by processes with the image filename \r\n you specify will be traced. -ko settings override -ro settings.\r\n Also, if you specify a new set of -ko settings the previous \r\n -ko settings, if any, are lost (same for -ro). \r\n -i operates on settings for a specific image file. \r\n [ignored when not suported in the current OS versions] \r\n \r\n If only the switch is specified, then current settings \r\n are displayed, not modified. If flags specified for -i \r\n option are FFFFFFFF, then registry entry for that image \r\n is deleted \r\n \r\nThe `-tracedb' option is used to set the size of the stack trace \r\ndatabase used to store runtime stack traces. The actual database \r\nwill be created if the `+ust' flag is set in a previous command. \r\n`-tracedb 0' will revert to the default size for the database. \r\n \r\nIf no arguments are specified to GFLAGS then it displays \r\na dialog box that allows the user to modify the global \r\nflag settings. \r\nNote: The dialog box is only displayed if the GflagsUI dll is available. \r\n \r\nFlags may either be a single hex number that specifies all \r\n32-bits of the GlobalFlags value, or it can be one or more \r\narguments, each beginning with a + or -, where the + means \r\nto set the corresponding bit(s) in the GlobalFlags and a - \r\nmeans to clear the corresponding bit(s). After the + or - \r\nmay be either a hex number or a three letter abbreviation \r\nfor a GlobalFlag. Valid abbreviations are: \r\n \r\n soe - Stop On Exception\r\n sls - Show Loader Snaps\r\n dic - Debug Initial Command\r\n shg - Stop on Hung GUI\r\n htc - Enable heap tail checking\r\n hfc - Enable heap free checking\r\n hpc - Enable heap parameter checking\r\n hvc - Enable heap validation on call\r\n vrf - Enable application verifier\r\n ptg - Enable pool tagging\r\n htg - Enable heap tagging\r\n ust - Create user mode stack trace database\r\n kst - Create kernel mode stack trace database\r\n otl - Maintain a list of objects for each type\r\n htd - Enable heap tagging by DLL\r\n dse - Disable stack extensions\r\n d32 - Enable debugging of Win32 Subsystem\r\n ksl - Enable loading of kernel debugger symbols\r\n dps - Disable paging of kernel stacks\r\n scb - Enable system critical breaks\r\n dhc - Disable Heap Coalesce on Free\r\n ece - Enable close exception\r\n eel - Enable exception logging\r\n eot - Enable object handle type tagging\r\n hpa - Enable page heap\r\n dwl - Debug WINLOGON\r\n ddp - Disable kernel mode DbgPrint output\r\n cse - Early critical section event creation\r\n sue - Stop on Unhandled Exception\r\n bhd - Enable bad handles detection\r\n dpd - Disable protected DLL verification\r\n lpg - Load image using large pages if possible\r\n\r\nAll images with ust enabled can be accessed in the\r\nUSTEnabled key under 'Image File Options'.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\gflags.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "kd.exe-E61F51C4CF00EFABF19CC6E80A128846": { "file_name": "kd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\kd.exe", "hash_md5": "E61F51C4CF00EFABF19CC6E80A128846", "hash_sha1": "3FA35574F770704A0C4BE2FFCE290B49AEBCC76D", "hash_sha256": "BD240F684F9E6D1BF03A88C75FA9C6D84BF84F823A9F0E6EBB7DA14B46748B16", "hash_sha384": "0B039736A01D9605F5D41E7A1BDDD41CCF728A1DC99EB8D23587714F6FFBE20DB0A041DA3EC5D1BFB950932D7BE391F3", "hash_sha512": "44742540622CAF25462EF990E0098F0C2589F21E8162A969C8C9D06DD8022121CE729D1BB58E4D7AF520AA8A4A49AD252CAC7ABCD50BC5B8452238A1DB923F7D", "hash_ssdeep": "3072:JO+DfFnbMwmoWATuajmhHmcLslY+20xcKM+8ForOvex:JO5slY+20xceGC", "hash_imp": "35AC0844A3992124484E6597B292EA5D", "hash_pesha1": "AE345C63B49EF181A6B26C351C3EBD80B5B580FA", "hash_pe256": "CDA05CD498D2BC403D26C394A393264B4DBA74ECC7F22FD251B01911A1E472D7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Kernel Debugger", "meta_original_filename": "kd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "kd: Invalid switch 'h'\nkd version 10.0.19041.1\nusage: kd [options]\n\nOptions:\n\n -? displays command line help text\n -a<DllName> adds a default extension DLL\n -b break into kernel when connection is established\n -bonc request break in after session started\n -c \"<command>\" executes the given debugger command at the first debugger\n prompt\n -cf <file> specifies a script file to be processed at the first debugger\n prompt\n -cfr <file> specifies a script file to be processed at the beginning of a\n session (including after .restart)\n -clines <#> number of lines of output history retrieved by a remote client\n -d breaks into kernel on first module load\n -ee <name> set default expression evaluator\n <name> can be MASM or C++\n -failinc causes incomplete symbol and module loads to fail\n -i <ImagePath> specifies the location of the executables that generated the\n fault (see _NT_EXECUTABLE_IMAGE_PATH)\n -iu install dbgeng URL protocols\n -k <options> tells the debugger how to connect to the target\n net:port=n,key=w.x.y.z[,target=name] connects over the network\n n: network port number, must match port assigned to target\n w.x.y.z: key assigned to target machine\n name: optional VM host machine name, used if debugging VMs\n usb:targetname=name connects over USB\n name: USB target name assigned to target machine\n 1394:channel=chan connects over 1394\n chan: 1394 channel number, must match channel used at boot\n com:modem connects through a modem\n com:port=id,baud=rate connects through a COM port\n id: com port name, of the form com2 or \\\\.\\com12\n rate: valid baudrate value, such as 57600\n -kl tells the debugger to connect to the local machine\n -kqm turns on kd quiet mode (equivalent to KDQUIET)\n -kx <options> tells the debugger to connect to an eXDI driver\n -lines requests that line number information be used if present\n -loga <logfile> appends to a log file\n -logau <logfile> appends to an Unicode log file\n -logo <logfile> opens a new log file\n -logou <logfile> opens a new Unicode log file\n -m serial port is a modem, watch for carrier detect\n -myob ignores version mismatches in DBGHELP.DLL\n -n enables verbose output from symbol handler\n -noio disables all I/O\n -noshell disables the .shell (!!) command\n -nosqm disables SQM data collection/upload.\n -QR \\\\<machine> queries for remote servers\n -r display registers\n -remote <transport>:server=<name>,<params> \n lets you connect to a debugger session started with -server\n must be the first argument if present\n transport: tcp | npipe | ssl | spipe | 1394 | com\n name: machine name on which the debug server was created\n params: parameters the debugger server was created with\n for tcp use: port=<socket port #>\n for npipe use: pipe=<name of pipe>\n for 1394 use: channel=<channel #>\n for com use: port=<COM port>,baud=<baud rate>,\n channel=<channel #>\n for ssl and spipe see the documentation\n example: ... -remote npipe:server=yourmachine,pipe=foobar\n -s disables lazy symbol loading\n -sdce pops up dialogs for critical errors\n -secure disallows operations dangerous for the host\n -server <transport>:<params> \n creates a debugger session other people can connect to\n must be the first argument if present\n transport: tcp | npipe | ssl | spipe | 1394 | com\n params: connection parameterization\n for tcp use: port=<socket port #>\n for npipe use: pipe=<name of pipe>\n for 1394 use: channel=<channel #>\n for com use: port=<COM port>,baud=<baud rate>,\n channel=<channel #>\n for ssl and spipe see the documentation\n example: ... -server npipe:pipe=foobar\n -ses enables strict symbol loading\n -sflags <flags> sets symbol flags from a numeric argument\n -sicv ignores the CV record when symbol loading\n -sins ignores the symbol path environment variables\n -snc converts :: to __ in symbol names\n -snul disables automatic symbol loading for unqualified names\n -srcpath <SourcePath> specifies the source search path\n -sup enables full public symbol searches\n -t Enable KD transport related output (CTRL+D output) by default.\n -v enables verbose output from debugger\n -version shows the build version\n -wake <pid> wakes up a sleeping debugger and exits\n -x same as -b, except uses an initial command of eb NtGlobalFlag 9;g\n -y <SymbolsPath> specifies the symbol search path (see _NT_SYMBOL_PATH)\n -z <CrashDmpFile> specifies the name of a crash dump file to debug\n -zd <CrashDmpFile> specifies the name of a crash dump file to debugand\n deletes that crash dump after the debugger has finished\n using it\n -zp <CrashPageFile> specifies the name of a page.dmp file to use with a\n crash dump\n\nEnvironment Variables:\n\n _NT_SYMBOL_PATH=[Drive:][Path]\n Specify symbol image path.\n\n _NT_ALT_SYMBOL_PATH=[Drive:][Path]\n Specify an alternate symbol image path.\n\n _NT_DEBUGGER_EXTENSION_PATH=[Drive:][Path]\n Specify a path which should be searched first for extensions dlls\n\n _NT_EXECUTABLE_IMAGE_PATH=[Drive:][Path]\n Specify executable image path.\n\n _NT_SOURCE_PATH=[Drive:][Path]\n Specify source file path.\n\n _NT_DEBUG_LOG_FILE_OPEN=filename\n If specified, all output will be written to this file from offset 0.\n\n _NT_DEBUG_LOG_FILE_APPEND=filename\n If specified, all output will be APPENDed to this file.\n\n _NT_DEBUG_HISTORY_SIZE=size\n Specifies the size of a server's output history in kilobytes\n _NT_DEBUG_BUS=1394\n Specifies the type of BUS the kernel debugger will use to communicate with the target\n\n _NT_DEBUG_1394_CHANNEL=number\n Specifies the channel to be used over the 1394 bus\n\n _NT_DEBUG_PORT=com[1|2|...]\n Specify which com port to use. (Default = com1)\n\n _NT_DEBUG_BAUD_RATE=baud rate\n Specify the baud rate used by debugging serial port. (Default = 19200)\n\n _NT_DEBUG_CACHE_SIZE=x\n If specified, gives the number of bytes cached on debugger side\n of kernel debugger serial connection (default is 102400).\n\n KDQUIET=anything\n If defined, disables obnoxious warning message displayed when user\n presses Ctrl-C\n\n\nControl Keys:\n\n <Ctrl-A><Enter> Toggle BaudRate\n <Ctrl-B><Enter> Quit debugger\n <Ctrl-C> Break into Target\n <Ctrl-D><Enter> Display debugger debugging information\n <Ctrl-F><Enter> Force a break into the kernel (same as Ctrl-C)\n <Ctrl-K><Enter> Toggle Initial Breakpoint\n <Ctrl-\\><Enter> Debug Current debugger\n <Ctrl-R><Enter> Resynchronize target and host\n <Ctrl-V><Enter> Toggle Verbose mode\n <Ctrl-W><Enter> Print version information\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\kd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "kdbgctrl.exe-30B54B17E08EC8E07B8AF7E4B73AF74A": { "file_name": "kdbgctrl.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\kdbgctrl.exe", "hash_md5": "30B54B17E08EC8E07B8AF7E4B73AF74A", "hash_sha1": "81084FB644EAFD980EFD04582518E0FD56A32C88", "hash_sha256": "F885AF4010A30AC4EC2987938C58AB736621F313D432BD7F8F17B527D2E7A7CB", "hash_sha384": "B1636FEFCB3CCD2594B1C5AFBB5BCFF0E5B527763D6C66AC7A91BFDE5305C5BD72F016B914F77AAD182F87EDBB4BB470", "hash_sha512": "94C9AA738097CCCEDBBFC96B1283CF666A13A8E9BC1D1E5B070E9FBCCDF789CB045D4C90ACA28DB485710997ED868F6163874895B3BAFAA07777BE6286F15B6C", "hash_ssdeep": "768:ZmoWOgP2TuaJXfX5cGfWcX7+aW/88fmz5dBoK3WDkd4:ZmoWWTuaZPfXvW88fQ3W4", "hash_imp": "A14AC62D28479CECD22E3DEDAE51D9FA", "hash_pesha1": "241AFE9167922CDC8C9F204B53C1F2A7F8DADDCE", "hash_pe256": "14D02E7AD3364E44A531FF6DED2F563FF44F0531A95463172EDFEDE723C202DE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows kernel debugger configuration utility", "meta_original_filename": "kdbgctrl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Usage: C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\kdbgctrl.exe <options>\r\nOptions:\r\n -c - Check kernel debugger\r\n -ca - Check kernel debugger auto-enable\r\n -cb - Check kernel debugger block-enable\r\n -cdb - Check kernel DbgPrint buffer size\r\n -cu - Check kernel debugger user exception handling\r\n -cx - Check kernel debugger enable and exit with status\r\n -d - Disable kernel debugger\r\n -da - Disable kernel debugger auto-enable\r\n -db - Disable kernel debugger block-enable\r\n -du - Disable kernel debugger user exception handling\r\n -e - Enable kernel debugger\r\n -ea - Enable kernel debugger auto-enable\r\n -eb - Enable kernel debugger block-enable\r\n -eu - Enable kernel debugger user exception handling\r\n -sdb <size> - Set kernel DbgPrint buffer size\r\n -td <pid> <file> - Get a kernel triage dump\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\kdbgctrl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "kdnet.exe-BA2F9DB032F5CE7341625A810A115474": { "file_name": "kdnet.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\kdnet.exe", "hash_md5": "BA2F9DB032F5CE7341625A810A115474", "hash_sha1": "02244155ED4C367F3513A6117117900EC0395433", "hash_sha256": "CF70EC7740426FA7DBA91C505C9F8A510BE65180451278B64A94970B93ABEBA4", "hash_sha384": "A628491D77459B6672D9FC63395D97E988A20136F190D8D6262BA6A2B889F8BB753143D44DC05F17C6C0D6114A0C4CCD", "hash_sha512": "6BF758DDB093A290670D9FB6FD01549DCB27577C8F909D7026A4A49A50C1F6E3CE34EE77DFF9E2701C239D2E1BC481A89053505A0B5BF6F9EAE40E35847B251C", "hash_ssdeep": "768:fmb5ZFGtbawzNjFITc0YkMY6vw+3Vl86aEr:f2ZmDzN70YJRvw+3Vl82r", "hash_imp": "A222286A15F27F406532CE0FEDEFB706", "hash_pesha1": "E7B9C9A737A03E1F900AAB1FEDEB2DE4424FD4DB", "hash_pe256": "4C94BD80B29E640EF30FC1171C8B04385EBC9A79C4D4F2CD125F4A76F785A238", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Net debugging configuration tool", "meta_original_filename": "kdnet.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/cf70ec7740426fa7dba91c505c9f8a510be65180451278b64a94970b93abeba4/detection", "output": "\r\nkdnet.exe [debug_host] [debug_port]\r\n [debug_host] is the name of the host machine running the debugger.\r\n [debug_port] is the network port to use for debugging this machine.\r\n\r\nkdnet.exe /xml\r\n\r\nkdnet.exe /busparams [debug_device] [debug_host] [debug_port]\r\n [debug_device] is the busparams of the debug Device to configure.\r\n [debug_host] is the name of the host machine running the debugger.\r\n [debug_port] is the network port to use for debugging this machine.\r\n\r\nWhen run without parameters, kdnet.exe identifies the NICs and USB3\r\ncontrollers which support network debugging. When run with parameters\r\nkdnet.exe enables network debugging using the specified information.\r\nIf [debug_port] is not specified then it will be set to a default\r\nvalue of 5364.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\kdnet.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "kdsrv.exe-583B05D3B0756D346D0EE95D64105FB1": { "file_name": "kdsrv.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\kdsrv.exe", "hash_md5": "583B05D3B0756D346D0EE95D64105FB1", "hash_sha1": "5CFC21DF2B7315B78EA8D5DA13FEBAAA04B593CE", "hash_sha256": "462463DC74ECD9C39C2631E7B2F068E65A6DEA82442E31E19A80DDFF62026F16", "hash_sha384": "6C187835394585F679256E64FB1C72B6D006B9523C624453C5091D0A4520E425C482FDF9BD988351ACD530F5E189A415", "hash_sha512": "5750BE10104FFD411B642D226C33CEDED5EC953B77CD3B3EDEFA902B0DF0C3DD640E6E759708A7857059056B76DE61A61AEF323B3056D7B3B66283BAC9E3EB7C", "hash_ssdeep": "3072:MYmoWWTuaVhiA/oOMqqDj1mkCb5Po9lRDdIK2ysyLh6+K9w3GO3WNZpz:MAolqqDZ4bKDdV7sqh6L5O0b", "hash_imp": "464BBECEE2AB49F204966C99159E12A5", "hash_pesha1": "5D3FEC9652F47821547E5C870261F04F1D85FEA2", "hash_pe256": "E92A7BAF8DB763E5EC7D9878B19FF872E804959BE836EED3CADD25012430DE7A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Kernel Debugger Connection Server", "meta_original_filename": "kdsrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Error 0x80070057: Server initialization\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\kdsrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "KernelDumpDecrypt.exe-8990D55CD7DBA7B9A0FE25B448D2FBBF": { "file_name": "KernelDumpDecrypt.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\KernelDumpDecrypt.exe", "hash_md5": "8990D55CD7DBA7B9A0FE25B448D2FBBF", "hash_sha1": "FF12864C1F6943F97CAE31F3CDA98EDEEEC24920", "hash_sha256": "7B422910859C6D7C46F309CE857904B06FBE867E77C552786D23376804E73806", "hash_sha384": "2DC947E64F437824DB9E1086A804812A756E2A83ABB0668490E5FE14822F95D7AC2F50CC45624243815251E9228D9872", "hash_sha512": "785D35A9F934261E8150056F6F177CE74F8B176221397C7EE4169B443C213420C0EAE47F5271D1B6A0F29A120F31B1AEDA8871CA9CA312C8462AB8C520D2D653", "hash_ssdeep": "384:52815cuxAUXQTEWaWc1IvNK/Yadeh2iaWoXWorywwGyzTzIwS+klTxXH:ko53QvPc1IvsAYe/Unryw8vdO3", "hash_imp": "1E442598CB7E6DB7CAAD1C1E6392857C", "hash_pesha1": "007172FF9059F93B0D6F362270EBD6AA9A31B485", "hash_pe256": "7E75E8284C0EBD5AF4BB0FB3392C8BF4849BD0DDCC0EBFD1AF1765E447DD2E1D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Kernel Dump File Decryptor", "meta_original_filename": "KernelDumpDecrypt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7b422910859c6d7c46f309ce857904b06fbe867e77c552786d23376804e73806/detection", "output": "Usage: KernelDumpDecrypt [args] <input.dmp> <output.dmp>\r\nWhere args is a sequence of the following:\r\n\t/user - Use user certificate store/key store.\r\n\t/machine - Use machine certificate store/key store.\r\n\t/keystore <name> - Name of the key store provider.\r\n\t/keyname <name> - Name of the key to lookup in the KSP.\r\n\t/keyfile <path> - Path to the file containing a raw private key\r\n\t or a full key pair (starts with 'RSA2' magic).\r\n\t/enumproviders - List key store providers.\r\n\t/enumkeys - List keys in the key store.\r\n\r\nIf no key parameters are specified, the tool looks up the certificate\r\nmatching the thumbprint contained in the encrypted dump file.\r\nIf only the keyname is specified, the key will be retrieved from the\r\ndefault key store for the current user.\r\n\r\nExamples:\r\n\r\nKernelDumpDecrypt memory.dmp memory_decr.dmp\r\n\tDecrypts memory.dmp using the private key obtained from the\r\n\tcurrent user's certificate store. Writes memory_decr.dmp.\r\n\r\nKernelDumpDecrypt /machine memory.dmp memory_decr.dmp\r\n\tDecrypts the dump using a key obtained from the local\r\n\tmachine's certificate store.\r\n\r\nKernelDumpDecrypt /user /keyname \"My app key\" memory.dmp memory_decr.dmp\r\n\tDecrypts the dump using named key in the\r\n\tuser store of the default key storage provider\r\n\r\n\r\nExit status: SUCCEEDED: 00000000: The operation completed successfully.\r\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\KernelDumpDecrypt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "kill.exe-95990D34832DAF395901F64C58EBEA0F": { "file_name": "kill.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\kill.exe", "hash_md5": "95990D34832DAF395901F64C58EBEA0F", "hash_sha1": "AFF2F3DA3F322E2E57B073DE6079630B10C2FD0E", "hash_sha256": "6CF5144826E09AF4D9D3E41C717ED61D780E58383F62E635CDFF30EBD6B752FA", "hash_sha384": "27FBEAD5AFCDD98C0C70D1706F5852899062827CA17452E1F62F36E8EABCD360BFEBAD312FB3D6B9F4A00494A4D7E0B3", "hash_sha512": "D018CB8931618D3060A755A4CDC843D3FFEF5A2BCEB92AF00DCD9816DC18FDF6B909929ABFF6D791003C1F6CC0BC626E40AF92857C466D0D06DDD4551813203D", "hash_ssdeep": "384:Ql1RyR0nKGqTWyy3DKkaA3SN9arPA/kWl616WciqvWgWHwGyA4JeRlF:Ql1R3KFTWpmRA3SNiwkV1s9yg", "hash_imp": "E1C30333E11B84451371A3F4C6D114EE", "hash_pesha1": "51AC0D2246A7C0FADD46FD30B9B74DA521193586", "hash_pe256": "987A53F0C2EF94369BBF608A5AC97A43EEAFE5CC27DB8A052EF0B2D5EC48695D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Process Kill Utility", "meta_original_filename": "kill.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Microsoft (R) Windows NT (TM) Version 3.5 KILL\r\nCopyright (C) 1994-1998 Microsoft Corp. All rights reserved\r\n\r\nusage: KILL [options] <<pid> | <pattern>>*\r\n\r\n [options]:\r\n -f Force process kill\r\n\r\n <pid>\r\n This is the process id for the task\r\n to be killed. Use TLIST to get a\r\n valid pid\r\n\r\n <pattern>\r\n The pattern can be a complete task\r\n name or a regular expression pattern\r\n to use as a match. Kill matches the\r\n supplied pattern against the task names\r\n and the window titles.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\kill.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "list.exe-665859FA4FEFC54D70AFF96A27B2479F": { "file_name": "list.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\list.exe", "hash_md5": "665859FA4FEFC54D70AFF96A27B2479F", "hash_sha1": "2E9288755A0437A0262E8E19A8546777AC7A97FD", "hash_sha256": "DFA26FB6AC35987EF743EF64A3BC849E7DCC1C6F5B954368F6A3B03A928424AC", "hash_sha384": "42A47A020E6EBD5B9BE2D4644ACD27FA65FD153687B8DFF44DBD281CA69B91806FA9084CEF820FE611E25732A09916A8", "hash_sha512": "398D114251F117930DDA8720F0E5FCB75AF4B3CB4E8C77EA463C81573A547F36AF1DB1725EBD8A8CF6CB0E7C196A5FE054C512651B886CEA9D8C6E1B1F392E3F", "hash_ssdeep": "1536:9UcXs6RbVBxpdD52v5iI99sKlBWRWE279iNugNiAeDpLh:NXxxpdD5E56UByp2TgNiHpl", "hash_imp": "AA9DED3E543513E55C99238C77B036BD", "hash_pesha1": "BFE4063FD38D93BF2BB256E3A07D99871C0031C4", "hash_pe256": "7D8CC6F2C7216735D671498C597D352F5044399EBC6A38AC8DF9DA7ED89DA793", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft File Lister", "meta_original_filename": "list.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "list [-s:string] [-g:line#] filename, ...\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\list.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "logger.exe-58EB12FE266036FEB408528FFBA028D0": { "file_name": "logger.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe", "hash_md5": "58EB12FE266036FEB408528FFBA028D0", "hash_sha1": "FB752AF191BF5E8C7FE9FC053368133BE36FA444", "hash_sha256": "E5AA8D65747EFD4862E74FD223566E3B9D044B0C2D662BD23B53A93D12237D3A", "hash_sha384": "EEE43F50E1A50614F3F3A2C3CEEECE4E39F3A159E02CD3B7C8BA94CB27FE82C0F0C93AD8C8943C7E13A338963897DB21", "hash_sha512": "C6115F412BBE63CE6029B8A81B0DD1FEFE25AD6E49A259AAFACAC53A124EB47AD0F6335C289795D68BBE6C5D5984E968013065CB46E4638A825F6FA42B8013AE", "hash_ssdeep": "6144:Ce2kVAhw/Uu+y/Tb05LmKBz8xh5KzsW5CB:Ce5Khib05SKBIxfKzNCB", "hash_imp": "29B00655AF7D4A72C238F06EF87FB647", "hash_pesha1": "553657E44AE6B4573404D199EF00346092B6E165", "hash_pe256": "4DD37B1E2D92689CC26C3C88E402B8796740DAB6E6FCD032450408C97D9DA1A0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "children": "conhost.exe", "output": "For more information on a specific command, type HELP command-name\r\nASSOC Displays or modifies file extension associations.\r\nATTRIB Displays or changes file attributes.\r\nBREAK Sets or clears extended CTRL+C checking.\r\nBCDEDIT Sets properties in boot database to control boot loading.\r\nCACLS Displays or modifies access control lists (ACLs) of files.\r\nCALL Calls one batch program from another.\r\nCD Displays the name of or changes the current directory.\r\nCHCP Displays or sets the active code page number.\r\nCHDIR Displays the name of or changes the current directory.\r\nCHKDSK Checks a disk and displays a status report.\r\nCHKNTFS Displays or modifies the checking of disk at boot time.\r\nCLS Clears the screen.\r\nCMD Starts a new instance of the Windows command interpreter.\r\nCOLOR Sets the default console foreground and background colors.\r\nCOMP Compares the contents of two files or sets of files.\r\nCOMPACT Displays or alters the compression of files on NTFS partitions.\r\nCONVERT Converts FAT volumes to NTFS. You cannot convert the\r\n current drive.\r\nCOPY Copies one or more files to another location.\r\nDATE Displays or sets the date.\r\nDEL Deletes one or more files.\r\nDIR Displays a list of files and subdirectories in a directory.\r\nDISKPART Displays or configures Disk Partition properties.\r\nDOSKEY Edits command lines, recalls Windows commands, and \r\n creates macros.\r\nDRIVERQUERY Displays current device driver status and properties.\r\nECHO Displays messages, or turns command echoing on or off.\r\nENDLOCAL Ends localization of environment changes in a batch file.\r\nERASE Deletes one or more files.\r\nEXIT Quits the CMD.EXE program (command interpreter).\r\nFC Compares two files or sets of files, and displays the \r\n differences between them.\r\nFIND Searches for a text string in a file or files.\r\nFINDSTR Searches for strings in files.\r\nFOR Runs a specified command for each file in a set of files.\r\nFORMAT Formats a disk for use with Windows.\r\nFSUTIL Displays or configures the file system properties.\r\nFTYPE Displays or modifies file types used in file extension \r\n associations.\r\nGOTO Directs the Windows command interpreter to a labeled line in \r\n a batch program.\r\nGPRESULT Displays Group Policy information for machine or user.\r\nGRAFTABL Enables Windows to display an extended character set in \r\n graphics mode.\r\nHELP Provides Help information for Windows commands.\r\nICACLS Display, modify, backup, or restore ACLs for files and \r\n directories.\r\nIF Performs conditional processing in batch programs.\r\nLABEL Creates, changes, or deletes the volume label of a disk.\r\nMD Creates a directory.\r\nMKDIR Creates a directory.\r\nMKLINK Creates Symbolic Links and Hard Links\r\nMODE Configures a system device.\r\nMORE Displays output one screen at a time.\r\nMOVE Moves one or more files from one directory to another \r\n directory.\r\nOPENFILES Displays files opened by remote users for a file share.\r\nPATH Displays or sets a search path for executable files.\r\nPAUSE Suspends processing of a batch file and displays a message.\r\nPOPD Restores the previous value of the current directory saved by \r\n PUSHD.\r\nPRINT Prints a text file.\r\nPROMPT Changes the Windows command prompt.\r\nPUSHD Saves the current directory then changes it.\r\nRD Removes a directory.\r\nRECOVER Recovers readable information from a bad or defective disk.\r\nREM Records comments (remarks) in batch files or CONFIG.SYS.\r\nREN Renames a file or files.\r\nRENAME Renames a file or files.\r\nREPLACE Replaces files.\r\nRMDIR Removes a directory.\r\nROBOCOPY Advanced utility to copy files and directory trees\r\nSET Displays, sets, or removes Windows environment variables.\r\nSETLOCAL Begins localization of environment changes in a batch file.\r\nSC Displays or configures services (background processes).\r\nSCHTASKS Schedules commands and programs to run on a computer.\r\nSHIFT Shifts the position of replaceable parameters in batch files.\r\nSHUTDOWN Allows proper local or remote shutdown of machine.\r\nSORT Sorts input.\r\nSTART Starts a separate window to run a specified program or command.\r\nSUBST Associates a path with a drive letter.\r\nSYSTEMINFO Displays machine specific properties and configuration.\r\nTASKLIST Displays all currently running tasks including services.\r\nTASKKILL Kill or stop a running process or application.\r\nTIME Displays or sets the system time.\r\nTITLE Sets the window title for a CMD.EXE session.\r\nTREE Graphically displays the directory structure of a drive or \r\n path.\r\nTYPE Displays the contents of a text file.\r\nVER Displays the Windows version.\r\nVERIFY Tells Windows whether to verify that your files are written\r\n correctly to a disk.\r\nVOL Displays a disk volume label and serial number.\r\nXCOPY Copies files and directory trees.\r\nWMIC Displays WMI information inside interactive command shell.\r\n\r\nFor more information on tools see the command-line reference in the online help.\r\n", "runtime_window_title": "Logger (debugger) 4.02", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "logviewer.exe-91C40004502F4663585680165766E1D4": { "file_name": "logviewer.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logviewer.exe", "hash_md5": "91C40004502F4663585680165766E1D4", "hash_sha1": "09DFC9EA557CEAAD4DC9E0A8827203B105C906FA", "hash_sha256": "CAE4E16B99E45ED28EE96E5749B0D279FD754B559BE91B6EC238FD7B7186327D", "hash_sha384": "D4F25B0208E3E4B98058EC68AD9F615B664B5A525D41BB4D1DA3DFF3151C180B893F516CAEA5D22EC87BE830AE352961", "hash_sha512": "7F2BB20ED12B91C31D80DEBD8BFD40055C1896984339421CE2404E1FBA7EEF2EC693466CE2336A8C7FB9B9C359AD199DE59BF502E20DB94173E105CD3BF02960", "hash_ssdeep": "6144:qvr/WG7aCyftsLaXr+SW3PR6ytIFAd2F/s/UsEK:qvB+jW3syKFAdSUMK", "hash_imp": "331C84F694AC087D09B8950C3FA0ABB2", "hash_pesha1": "9183D15A1B33A98759760A27CED7FADB64BF2A85", "hash_pe256": "67EDBE20D5FB181F241BE223AE6FF95C6A2A3604E3E27831F651A029E08640AC", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logviewer.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Win32 API Log Viewer", "meta_original_filename": "LogViewer.exe", "meta_product_name": "Logging/Debugging Tools for Windows(R)", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.02 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/cae4e16b99e45ed28ee96e5749b0d279fd754b559be91b6ec238fd7b7186327d/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Users\\user\\--help": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logviewer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Error" }, "ntkd.exe-BCABCBB87A2D6CF497D3FBF60BDD2543": { "file_name": "ntkd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntkd.exe", "hash_md5": "BCABCBB87A2D6CF497D3FBF60BDD2543", "hash_sha1": "36ECC16F0CD6BE01EFD67C86CA9902730AFCD11A", "hash_sha256": "F39933A516E9398C243609406FD44EA7B01AFB14E89603D60CFF680F961C840B", "hash_sha384": "46B0814460C8DCA56850F338CBE634248E8F1DDFA579CF4E31A01A6290D158D7371E43E97C5A31D53D98B34E1C1309F3", "hash_sha512": "8D4C31A4A83A921745E0EC4FDC9C05D1CFF99E0A225AFF86E787080A49E894BB35A40FDB8529099B5015A45F106D7BE97C51C66C6977EB867EF46F0C0B6EF0CC", "hash_ssdeep": "3072:n6+W5FnbMBmoWATua7yhmh09zAUr80xQgLFp2x:n6jzAUr80xQgTy", "hash_imp": "1841134A666FABEF4DF27B40BC5DCC26", "hash_pesha1": "D24F6333D907F32AEDE0B218851A96FA0D495D3A", "hash_pe256": "487A2370615E52736972A9E22021065775D95E29F5D684CB2307EB5AAB0E22BC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Kernel Debugger", "meta_original_filename": "ntkd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntkd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntkd.exe" }, "ntsd.exe-329FBD3549A7D0FB1BF3A250ED8BDFB7": { "file_name": "ntsd.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntsd.exe", "hash_md5": "329FBD3549A7D0FB1BF3A250ED8BDFB7", "hash_sha1": "6222D8D40CBC2674453CF3836BAA3D019F27C3D8", "hash_sha256": "71227C3FE96B7582111BDC4FC4C098228CA6C6C4F97CDEC9AFF4FC52C352E5D9", "hash_sha384": "62AB31AEA6DB71C07DDFB265166849E4C70064C838935451A5510BDB19383BA063479429752A25F872CBA02065D9C26F", "hash_sha512": "B4B84F807DCFC8243B3E42DFF2C44A6FA18AEA463AC804A842C024F7F28B6CDE6BB6A309BE3A7A985EBB820CA5ABCDFBFDBF26B16596C98DF2759BA91868D331", "hash_ssdeep": "3072:W4+JhFnbMpmoWATuaMGhIwQ2gyq+0xovBnlYl:W4IMq+0x41lYl", "hash_imp": "391B93A5B608F9F327CC4452AD7F11FF", "hash_pesha1": "D717A276C6FAF7308D25075120050B7473554CCE", "hash_pe256": "C9F5CA18763138981F234B759ABF9FA1B9197B87CA5B24065E3040477AFA9FE8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbolic Debugger for Windows", "meta_original_filename": "NTSD.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "1/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/71227c3fe96b7582111bdc4fc4c098228ca6c6c4f97cdec9aff4fc52c352e5d9/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RWD) C:\\Windows\\SysWOW64\\ntdll.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\sym\\wntdll.pdb\\3CCC2398F623C3D0915D0E0ADC5714A71\\wntdll.pdb": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_window_title": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntsd.exe", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntsd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "pdbcopy.exe-249595DA8848A92A5BD72B752439D439": { "file_name": "pdbcopy.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\pdbcopy.exe", "hash_md5": "249595DA8848A92A5BD72B752439D439", "hash_sha1": "FBE07C3CEB1FE7F276B9900ABC82218D36547859", "hash_sha256": "D97E952B341CD01161D879F77B8F88C7CAA95F5562E018CE9A7828D8AEBAC1B7", "hash_sha384": "D9E10E18EDDF097E917EF087A5C6ECD3F810E7560CD36026C1E3A6513D96B800CEA7EA1FEA8F04AFF6EDFEB1CB8A5C19", "hash_sha512": "FFF6453BECE2C5ED30D985CBC9847FDCB7EC366B41CA09FB69CA7C8BF39975AF2D70A29E499868CBBDEED310AB1EFAE803CB316DA6AECC114D1B64E3E9684461", "hash_ssdeep": "12288:GfkovZE6AIAYGzCMFoDfnYwSUFrLV3ivMcynaw7/PG0L+fyZFZjyx6c:GMovlDGzCx2U/ivMcypG0LJFZjiJ", "hash_imp": "AFDFB82BB48F6962E8E445C30E966BD0", "hash_pesha1": "6E8B28C36622FBAA8130924E25192F586ABF41BE", "hash_pe256": "35E873301E3E03C220D04289D97F6250D6DBC9B2BDC84BBED39742038441F095", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000010A2C79AED7797BA6AC00010000010A", "signature_thumbprint": "3BDA323E552DB1FDE5F4FBEE75D6D5B2B187EEDC", "signature_issuer": "CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft PDB Copy Utility", "meta_original_filename": "PDBCOPY.EXE", "meta_product_name": "Microsoft Visual Studio 2015", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.00.23615.0 built by: VCTOOLSREL", "meta_product_version": "14.00.23615.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d97e952b341cd01161d879f77b8f88c7caa95f5562e018ce9a7828d8aebac1b7/detection", "error": "\r\nPDBCopy v14.00.23615\r\nusage: PDBCopy <source_pdb> <destination_pdb> [-p] [-s] [-f] [-F] [-a] [-A] [-?]\r\n\t[-p] remove private debug information\r\n\t[-s] create new signature\r\n\t[-f:{@file|symbol}] filter specific public symbols out of stripped pdb\r\n\t[-F:{@file|symbol}] leave only specific public symbols in stripped pdb\r\n\t[-a] leave all annotation symbols in stripped pdb\r\n\t[-a:{@file|symbol}] filter specific annotation symbols out of stripped pdb\r\n\t[-A:{@file|symbol}] leave only specific annotation symbols in stripped pdb\r\n\t[-?] display this message\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\pdbcopy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "plmdebug.exe-922A5881058A7DAA6D956E819647A1D9": { "file_name": "plmdebug.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\plmdebug.exe", "hash_md5": "922A5881058A7DAA6D956E819647A1D9", "hash_sha1": "F3A73FA7D8C3360884B2A7FC67011AD7379BB4F0", "hash_sha256": "37B375473839139DFB7291DEF96368C56979F7CEFE66971EC6ECDF439E2D05C2", "hash_sha384": "E5705872F17181E09C28C3E6DBB029914DF4D87CC4654125EBC3665BB630FD6DE8B0777B0D2F16AE26B199AD964D745B", "hash_sha512": "6F022685DABB9C280D8E9F12438DDDB6D9E8F85A337B095E6590305069CE94CC102169CC1A6990EC17248C74A35892E1086763B29930454B105E7A73F41C9DEC", "hash_ssdeep": "3072:/drXR16LPEO/IudqcSvP03MtB8RXjoN5Nqh+UaS1jw2fkWwSY:wLX/NdqFvc3MKjoN5Nqh+UH1E2fTxY", "hash_imp": "42C899D013217E2C12090934DFA2E285", "hash_pesha1": "370B20683F614073D023644934EBC15AE56CE220", "hash_pe256": "CD97FD24A19F354F4D7D86B67C3576EE4AA3EC3D5D6F7ABB25D69DBE11251036", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft PLMDebug", "meta_original_filename": "plmdebug.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "plmdebug.exe /query [pkgname]\r\nplmdebug.exe /enableDebug pkgname [\"debugger\"] [\"environment str1\" ...]\r\nplmdebug.exe /terminate|/forceterminate|/cleanterminate pkgname\r\nplmdebug.exe /suspend|/resume|/disableDebug pkgname\r\nplmdebug.exe /enumerateBgTasks pkgname\r\nplmdebug.exe /activateBgTask taskid\r\n\r\n pkgname can be package full name or a process ID for one of the processes running for the package.\r\n\r\n/query: List running states for all installed packages or a specified package.\r\n/enableDebug: Call the PLM debug API to increment debug ref count on a package. PLM\r\nDoes not suspend a package if it has non zero debug ref count.\r\n debugger: Optional string to start debugger.\r\n Eg: \"C:\\Program Files\\Windows Kits\\8.0\\Debuggers\\x64\\windbg.exe\" -server npipe:pipe=test\"\r\n environment strings: Optional list of environment strings for debug session.\r\n Eg: \"var1=val1\" \"var2=val2\"\r\n/terminate|/forceterminate: Call the PLM debug API to terminate all processes running for the package.\r\n/cleanterminate: Call the PLM debug API to suspend and then terminate all processes running for the package.\r\n/suspend: Call the PLM debug API to asynchronously suspend all processes running for the package.\r\n/resume: Call the PLM debug API to resume a package.\r\n/disableDebug: Call the PLM debug API to decrement debug ref count on a package.\r\n/enumerateBgTasks: Enumerate background task ids for a package\r\n/activateBgTask: Activates a background task\r\n ** NOTE: Not all background tasks can be activated using plmdebug **\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\plmdebug.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "remote.exe-C51957E9AFD84515C5F65A14B36FF144": { "file_name": "remote.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe", "hash_md5": "C51957E9AFD84515C5F65A14B36FF144", "hash_sha1": "6E81E8590B3DAE0C085F0A4181C48E58A9E16127", "hash_sha256": "D3E433D4595EB2240EDC914C67AB85D9308BCFC903B185302FE3BC52215C5E6B", "hash_sha384": "577EFE93EBDE49B182A2EEA02A6070AF982A92CC44A18E8F88CF56B8180153DEBD4C7D706D24F9B6FCBC91EBE4888035", "hash_sha512": "4D01E521683A68BD7FAEBDC354296667BAA7F7E2281C770D5C56CB8F00AE041AA11C012D80E97DD8E61A0D06011C2C80EA3FBA54A42318761239C1ACC1C2832F", "hash_ssdeep": "768:Gt04y4dccel+YuNyPA6WBRI+M3UjrLw7Wov5YgTuyMpbAuSUlS5C:GactnC1Unkh5PTuZbAtU", "hash_imp": "5C1E1DA49D61DC05F5D31D7C4F52EECB", "hash_pesha1": "CF98407A8D3E3897B7DBB10169F2449A80C808D1", "hash_pe256": "D0CF21A9D1F6EC3DCCAB63EE4D80F30265BEB41E9104E98ABA7EF658DE098CB2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Remote Std I/O Shell", "meta_original_filename": "remote.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\n To Start the SERVER end of REMOTE\r\n ---------------------------------\r\n Syntax : REMOTE /S <\"Cmd\"> <Unique Id> [Param]\r\n Example1: REMOTE /S \"i386kd -v\" imbroglio\r\n To interact with this \"Cmd\" from some other machine,\r\n start the client end using: REMOTE /C A0D5F083-3197-4 imbroglio\r\n\r\n Example2: REMOTE /S \"i386kd -v\" \"name with spaces\"\r\n start the client end using: REMOTE /C A0D5F083-3197-4 \"name with spaces\"\r\n\r\n To Exit: @K \r\n [Param]: /F <Foreground color eg yellow, black..>\r\n [Param]: /B <Background color eg lblue, white..>\r\n [Param]: /U username or groupname\r\n specifies which users or groups may connect\r\n may be specified more than once, e.g\r\n /U user1 /U group2 /U user2\r\n [Param]: /UD username or groupname\r\n specifically denies access to that user or group\r\n [Param]: /UL [filename]\r\n Filename of string format security descriptor.\r\n If no filename, then the REMOTE_SDDL_FILE environment\r\n variable is used.\r\n [Param]: /V Makes this session visible to remote /Q\r\n [Param]: /-V Hides this session from remote /q (invisible)\r\n By default, if \"Cmd\" looks like a debugger,\r\n the session is visible, otherwise not\r\n\r\n\r\n To Start the CLIENT end of REMOTE\r\n ---------------------------------\r\n Syntax : REMOTE /C <ServerName> \"<Unique Id>\" [Param]\r\n Example1: REMOTE /C A0D5F083-3197-4 imbroglio\r\n This would connect to a server session on A0D5F083-3197-4 with Id\r\n \"imbroglio\" if there is a REMOTE /S <\"Cmd\"> imbroglio\r\n running on A0D5F083-3197-4.\r\n\r\n Example2: REMOTE /C A0D5F083-3197-4 \"name with spaces\"\r\n This would connect to a server session on A0D5F083-3197-4 with Id\r\n \"name with spaces\" if there is a REMOTE /S <\"Cmd\"> \"name with spaces\"\r\n running on A0D5F083-3197-4.\r\n\r\n To Exit: @Q (Leaves the Remote Server Running)\r\n [Param]: /L <# of Lines to Get>\r\n [Param]: /F <Foreground color eg blue, lred..>\r\n [Param]: /K <Set keywords and colors from file>\r\n [Param]: /B <Background color eg cyan, lwhite..>\r\n\r\n Keywords And Colors File Format\r\n -------------------------------\r\n <KEYWORDs - CASE INSENSITIVE>\r\n <FOREGROUND>[, <BACKGROUND>]\r\n ...\r\n EX:\r\n ERROR\r\n black, lred\r\n WARNING\r\n lblue\r\n COLOR THIS LINE\r\n lgreen\r\n\r\n To Query the visible sessions on a server\r\n -----------------------------------------\r\n Syntax: REMOTE /Q A0D5F083-3197-4\r\n This would retrieve the available <Unique Id>s\r\n visible connections on the computer named A0D5F083-3197-4.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "rtlist.exe-7507ED8EAC18BC6B4B360549E5F94787": { "file_name": "rtlist.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\rtlist.exe", "hash_md5": "7507ED8EAC18BC6B4B360549E5F94787", "hash_sha1": "60BFBC463B89FC917726D8EDF9D1A704109BB7EB", "hash_sha256": "6640E4E7E9C2C0F0EAC82134D6600E2F5ED550D4716EF8D12C79D91FED1EA813", "hash_sha384": "2A2036E77D36D11FD8679231B6AD2763F87071CF019927F594BD39B20C4B0DB5C36AF806465BCFFEA31EF4B23180CE3C", "hash_sha512": "821D5E4037E08A3F571B36DBFD7171E1CD9BAD1C7B56F1D18DF7C1A7584D05157B44CE0EAFDBED4FB299B6FD465205CD7EB27CC17F58B3D00B9850369619BDC2", "hash_ssdeep": "384:Ur7nvIJf+n3Ly2D259gBWO73ZW3qwGyjlD:0Tn3HE9gNh", "hash_imp": "7691408898FCC0FDFE9278339D36DA6F", "hash_pesha1": "1E099C755249ADC7B85074395F5AE18E84BD656B", "hash_pe256": "F6B496E461E587B3846AD425BFE5107CA04B993F81DF9CA4440942FF12314EFD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft User-Mode Process Server Query Tool", "meta_original_filename": "rtlist.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Usage: rtlist <Options>\r\nOptions are:\r\n -premote <Options> - Connect to process server\r\n -pn <Name> - Look for process name\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\rtlist.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "symchk.exe-727D672CDAA552D32CED03E0FEC83ABF": { "file_name": "symchk.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\symchk.exe", "hash_md5": "727D672CDAA552D32CED03E0FEC83ABF", "hash_sha1": "328781A60C82BA5396B939097C19DD5D26307F41", "hash_sha256": "D5436169513098F45E53E9B67FCD9BCE47E6FFD40EF208272C34787BDA901F58", "hash_sha384": "974D618E57D258F5511B2A3505C142472A2DAE864378B5106B43237966367ACB3F03341A83FF97E626D7225067F63002", "hash_sha512": "719AB350CDCE9BE04FED2634AA17CE2A8346E2F9F361D2BB5AE0CD76FA86FC799B7996A9B4A8AD421856D03988E1F7F5BFB11CEE57419C93BBD4C188E83E451C", "hash_ssdeep": "768:PaOWfB1oeniNFEzjmZGkkgiS0FTmjVqUBnJfHIt/erxsm8X3YZLXFqH1KuX:PahC0mZGkhCqhHIt53WXFqH1n", "hash_imp": "6B2BED98B1905067E31143851D959636", "hash_pesha1": "8E96204BD2B5819E1C2F52468BF1180E00368E53", "hash_pe256": "617B285B7913A52EECDD1ECE42D2440AB52A4551CEB2423F41399BDF8FE4678B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbol Checker", "meta_original_filename": "SYMCHK.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nsymchk [/r] [/q] [Input options] <Filename> [/s <SymbolPath>] [options]\r\n\r\n<Filename> Name of the file or directory that contains the executables\r\n to perform symbol checking on.\r\n\r\n/s <SymbolPath> Semi-colon separated list of symbol paths. Symbol server\r\n paths are allowed. To retrieve symbols to a downstream\r\n store, use \"SRV*<downstream store>*<symbol server>\" for\r\n the symbol path. See the debugger documentation for more\r\n details.\r\n\r\n/r Perform recursive operations on the <Filename> specified. The\r\n wildcard * can be used in filenames.\r\n\r\n/q Turn off all output options by default. Only output turned on\r\n with a output flag (see below) will be printed\r\n\r\n--------------------------------------------------------------------------------\r\n* Input options (choose only one):\r\n/if <Filename> Input is a file name. Wildcards can be used to specify\r\n the file name. Default if nothing is specified.\r\n/id <DumpFile> Input is a dump file.\r\n/ih <HotFix> Input is a self-extracting Hotfix cab.\r\n/ie <ExeName> Input is an application name that is currently running.\r\n If the provided ExeName is '*', all currently running\r\n processes will be checked.\r\n/im <ManifestList> Input is a manifest previously created using the /om <file>\r\n option.\r\n/ip <ProcessId> Input is a process id. If the provided ProcessID is '*',\r\n all currently running processes will be checked.\r\n/it <TextFileList> Input is a list of files, one per line, inside of a text\r\n file.\r\n\r\n--------------------------------------------------------------------------------\r\n* Action options (choose only one):\r\n/av For each binary, Verify symbols exist and match. Default.\r\n\r\n--------------------------------------------------------------------------------\r\n* Symbol checking options:\r\n/cc when symbol checking a hotfix cab, don't look for symbols inside the cab.\r\n By default, symchk will look for symbols in the cab as well as in the\r\n provided symbol path.\r\n/cn When symbol checking a running process, don't suspend that process. User\r\n must ensure the process doesn't exit before symbol checking finishes.\r\n/cs Skip verifying that there is CodeView data. Symchk will verify that there\r\n IS codeview data by default.\r\n\r\n- Symbol checking options for DBG information (choose one):\r\n/ds If image was built so that there is information that belongs in a DBG\r\n file, then this option verifies that the DBG information is stripped\r\n from the image and that the image points to a DBG file. Default.\r\n/de If image was built so that there is information that belongs in a DBG\r\n file, then this option verifies that the DBG information is STILL in the\r\n image and that the image does not point to a DBG file.\r\n/dn Verify that the image does not point to a DBG file and that DBG\r\n information is not in the image.\r\n\r\n- Symbol checking options for PDB files:\r\n/pa Allow both public and private PDBs. Default.\r\n/pf Verify that PDB files contain full source information.\r\n/ps Verify that PDB files are stripped and do not contain full source\r\n (private) information.\r\n/pt Verify that PDB files are stripped, but do have type information. Some\r\n PDB files may be stripped but have type information added back in.\r\n\r\n--------------------------------------------------------------------------------\r\n* Symbol checking exclude options:\r\n/ea <Filename> Don't perform symbol checking for the binaries listed in the\r\n file specified. <Filename> is a text file that contains the\r\n name of each binary, one per line.\r\n/ee <Filename> Perform symbol checking and report files that pass or are\r\n ignored, but don't report errors for binaries listed in the\r\n file specified. <Filename> is a text file that contains the\r\n name of each binary, one per line.\r\n\r\n--------------------------------------------------------------------------------\r\n* Symbol path options:\r\n/s[eprsu] <SymbolPath> Use <SymbolPath> as the search path.\r\n\r\n NOTE: If the '/s' option is not used, SymChk defaults to using the value\r\n in %_NT_SYMBOL_PATH%. If %_NT_SYMBOL_PATH% is not defined, then SymChk\r\n will default to:\r\n SRV*%SYSTEMROOT%\\SYMBOLS*https://msdl.microsoft.com/download/symbols\r\n\r\n* Modifiers (choose all that apply):\r\n e - check each path individually instead of checking all paths at once.\r\n p - force checking for private symbols. Public symbols will be treated as\r\n not matching. (Implies the 'e' and 'u' modifiers.)\r\n r - Expand all non-symbol server elements in the specified path in order to do\r\n a deep search of the path. NOTE: This option may produce matches that will\r\n not occur inside the debugger since it modifies the symbol path specified.\r\n s - force checking for public (split) symbols. Private symbols will be\r\n treated as not matching. (Implies the 'e' and 'u' modifiers.)\r\n u - force updating of downstream stores. If the symbol path includes a\r\n downstream store, always re-check the server for the symbol. Only\r\n stores that are checked against will be updated.\r\n NOTE: The 's' and 'p' options are mutually exclusive. Only the last one\r\n present will be used.\r\n\r\n--------------------------------------------------------------------------------\r\n* Output options (choose all that apply):\r\n/ob Give the full path for binaries in the output messages for symbol\r\n checking.\r\n/oc[x[a]] <Directory> Create a flat symbols tree in <Directory> which\r\n contains all matching symbols. If 'x' is also used, copy the matching\r\n binaries into <Directory> as well. If 'a' is also present, the binary\r\n will always be copied to the flat symbol tree even if symbol checking\r\n failed.\r\n/od List all details. Same as /oe /op /oi\r\n/oe List individual errors. Errors will be sent to the output by default.\r\n This option is only needed when using /q\r\n/oi List each file that is ignored.\r\n/op List each file that passes.\r\n/os Give the full path for symbols in the output messages for symbol\r\n checking.\r\n/ot Send totals to the output. Totals are sent to the output by default.\r\n This option is only needed when using /q\r\n/ov Print version information for checked binaries as well.\r\n\r\n- Extended output options:\r\n/ol <File> In addition to the messages sent to standard out, write a\r\n file that contains a comma separated list of all the\r\n binaries and their symbols that pass symbol checking.\r\n/om <Manifest> Print out a manifest file for later use with the '/im' option.\r\n/v Turn on verbose output mode.\r\n--------------------------------------------------------------------------------\r\n* Module filtering options when checking processes or dump files (choose one):\r\n /fm <Module> Filter results to only include the named module.\r\n\r\n--------------------------------------------------------------------------------\r\n* Misc options\r\n /port Old usage to new usage quick porting table\r\n--------------------------------------------------------------------------------\r\n\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\symchk.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "symstore.exe-EF349A1CB00E2541785C762A3AFD6714": { "file_name": "symstore.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\symstore.exe", "hash_md5": "EF349A1CB00E2541785C762A3AFD6714", "hash_sha1": "F8A445AD634D161AEDA98EC80048C2D02F03CE24", "hash_sha256": "F08332D60604F0020682BC613072E9628FA4BF21BC61A73EFF9ECFB5AD683A7E", "hash_sha384": "386336B0D75AC8833FEF42E3422658A3CEED488BB28A0BF17EBAB8F6A9EB161630684D2F39803A1A26BE31B3FE888906", "hash_sha512": "DCADF11D293491A890A5320D21A3D95429793535E9978309AFDC3840F7F426F7FA5090820022C85C0CCE6E5E91AD93BBC7F4AE829FAECD34DEA28CA76AD5D2BE", "hash_ssdeep": "1536:wn+u06nuB4+OlSIETjE7bpepwtqNkIK6+bVLI6fvGd65vAtv:k+L6nuBWMjE7bpe1NkIubVLrfO85vAR", "hash_imp": "872FAEF6567331FE9C59F136B91B548C", "hash_pesha1": "DAFD833EF9A0CD77B084FF6FF3202A001EB013EB", "hash_pe256": "624F0A8DADA356D7536288BAD032C7417B9D2972A14803D712A8624F5FE77EDF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Symbol Server Builder", "meta_original_filename": "SYMSTORE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Usage:\r\nsymstore add [/r] [/p] [/l] /f File /s Store /t Product [/v Version]\r\n [/c Comment] [/d LogFile] [/compress]\r\nsymstore add [/r] [/p] [/l] [/q] /g Share /f File /x IndexFile [/a] [/d LogFile]\r\nsymstore add /y IndexFile /g Share /s Store [/p] /t Product [/v Version]\r\n [/c Comment] [/d LogFile] [/compress]\r\nsymstore del /i ID /s Store [/d LogFile]\r\nsymstore query [/r] [/o] /f File /s Store\r\n\r\n add Add files to server or create an index file.\r\n del Delete a transaction from the server.\r\n query Check if file(s) are indexed on the server.\r\n\r\n /3 Create index2.txt when populating a new symbol server.\r\n /f File Network path of files or directories to add.\r\n If the named file begins with an '@' symbol, it is treated\r\n as a response file which is expected to contain a list of\r\n files (path and filename, 1 entry per line) to be stored.\r\n /g Share This is the server and share where the symbol files were\r\n originally stored. When used with /f, Share should be\r\n identical to the beginning of the File specifier. When\r\n used with the /y, Share should be the location of the\r\n original symbol files, not the index file. This allows\r\n you to later change this portion of the file path in case\r\n you move the symbol files to a different server and share.\r\n /i ID Transaction ID string.\r\n /l Allows the file to be in a local directory rather than a\r\n network path.(This option is only used with the /p option.)\r\n /p Causes SymStore to store a pointer to the file, rather than\r\n the file itself.\r\n /q Don't quote fields in the index file.\r\n /r Add files or directories recursively.\r\n /s Store Root directory for the symbol store.\r\n /t Product Name of the product.\r\n /v Version Version of the product.\r\n /c Comment Comment for the transaction.\r\n /d LogFile Send output to LogFile instead of standard output.\r\n /x IndexFile Causes SymStore not to store the actual symbol files in the\r\n symbol store. Instead, information is stored which will\r\n allow the files to be added later.\r\n /y IndexFile This reads the data from a file created with /x.\r\n /yi IndexFile Append a comment with the transaction ID to the end of the\r\n index file.\r\n /z pub | pri Pub option will only index symbols that have had the full\r\n source information stripped. Pri will only index symbols\r\n that contain the full source information. Both options\r\n will index binaries.\r\n /m <prefix> Give preference to files which have <prefix> at the beginning\r\n of their path when storing/updating pointers.\r\n /h pub | pri Give priority to pub or pri.\r\n /a Causes SymStore to append new indexing information\r\n to an existing index file. (This option is only used with\r\n /x option.)\r\n /o Give verbose output.\r\n -:MSG [msg] When storing pointers, also add the provided message to the\r\n file.ptr\r\n -:REL Allow file.ptr paths to be relative. Implies '/l' also.\r\n -:NOREFS Only valid during intial store creation or when used on a\r\n store previously created with the -:NOREFS option. Omits the\r\n creation of refs.ptr files for files and pointers stored.\r\n Use of a store without refs.ptr precludes the ability to do\r\n prioritization and the ability to delete transactions from the\r\n store.\r\n -:NOFORCECOPY\r\n /compress When storing files, store compressed files on the server. Ignored\r\n when storing pointers.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\symstore.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "tlist.exe-4301EE791540B7AC5D85C4B7A383B8CB": { "file_name": "tlist.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\tlist.exe", "hash_md5": "4301EE791540B7AC5D85C4B7A383B8CB", "hash_sha1": "3F6610D07373C7B8C29DC97D47D2A4ACB2AB810A", "hash_sha256": "FAD6CD51C18466760C84D2235F8A514E318AF52D60C3F288A234F5B2BE987691", "hash_sha384": "CFD55D89ED49ED3E48139F93BCC4B6837C2201E32B22C404E028EF0B233AB397A353EDC49194C6E4A87794C3000522B9", "hash_sha512": "50D8FF92F3F05C74DA928A675AB909D532AC52E633A478D6E13CAA199558B31E10CF0EA9C207F4346091A65EC7D188950C37F46230A8C766350E42FB37F6C3B7", "hash_ssdeep": "768:/j16MPBSHAWL99/nDE8GT/pDmkt6tqTaLOyse8o+VwX7Z:77BSgWLju3eDi7eiVw", "hash_imp": "DBEC6EB5DF480CCCC407090C46E85A27", "hash_pesha1": "E18DEA803717C3C17130E44D46ECDD74B31A0CE9", "hash_pe256": "923AFE97DD117D2CC6ECDA6E8BA5B68B7F5B372EBCF2885DA5DC458AAB4E3C86", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Process List Utility", "meta_original_filename": "tlist.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Microsoft (R) Windows NT (TM) Version 5.1 TLIST\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nusage: TLIST <<-m <pattern>> | <-t> | <pid> | <pattern> | <-p <processname>>> | <-k> | <-s>\r\n [options]:\r\n -t\r\n Print Task Tree\r\n\r\n <pid>\r\n List module information for this task.\r\n\r\n <pattern>\r\n The pattern can be a complete task\r\n name or a regular expression pattern\r\n to use as a match. Tlist matches the\r\n supplied pattern against the task names\r\n and the window titles.\r\n\r\n -c\r\n Show command lines for each process\r\n\r\n -e\r\n Show session IDs for each process\r\n\r\n -g\r\n Show group affinity for each process (Win7+)\r\n\r\n -k\r\n Show MTS packages active in each process.\r\n\r\n -m <pattern>\r\n Lists all tasks that have DLL modules loaded\r\n in them that match the given pattern name\r\n\r\n -s\r\n Show services active in each process.\r\n\r\n -p <processname>\r\n Returns the PID of the process specified or -1\r\n if the specified process doesn't exist. If there\r\n are multiple instances of the process running only\r\n the instance with the first PID value is returned.\r\n\r\n -v\r\n Show all process information\r\n\r\n -w\r\n Show Wow64 process information\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\tlist.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "umdh.exe-FA2FECB97CE3961E36892AFAB98DA840": { "file_name": "umdh.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\umdh.exe", "hash_md5": "FA2FECB97CE3961E36892AFAB98DA840", "hash_sha1": "AB8B34F91F87D384C350EC23EAA04F5938E34E03", "hash_sha256": "62C0B8DA8F4F8632D48F8E4D8774F931CF86BB5F9D049969643A7824F37BF897", "hash_sha384": "DEB0810BCEA83D5F9F99EC60D18D555D73F8305C215F7BD0C1E93DE520D58BFC5118404A1E1CE0ED0CB619D5178149BE", "hash_sha512": "78D7F812B60F52803D85217919DC2BFD380B5CFFF0A157C3BA1198F3E24237D9726E1CCF39E25DE316FDAE7C145FEA979B37FB015224FDC7A581FC7259829517", "hash_ssdeep": "768:AfjX7tCfxz3hO4klCQbvvUEern2SMORpz/ZF8tFNhEQoExX6edAscX/4myGl:Arrsz3hOL1sTr2SMO3z/ZFMhFxdAsXE", "hash_imp": "B90E0F9B87800BC3438B2977A6C23A91", "hash_pesha1": "4DBAA243DB5E3F704A864278A603592D4B454A54", "hash_pe256": "48725FF4BD6153027DAD82DAFAD7CA6696D21452CEF65371850DB4D8E386B6BB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NT Security Test: UMDH", "meta_original_filename": "UMDH.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": " \r\n UMDH \r\n \r\nMODE 1 \r\n \r\n umdh {-p:Process-id|-pn:ProcessName} [-f:Filename] [-g] \r\n \r\n Creates a dump of the heap allocations. \r\n \r\n -p Indicates the Process-ID to examine. \r\n -pn Indicates the Process name to examine. \r\n -f Indicates output file. \r\n -g Dumps the heap blocks which have no references in the process. \r\n \r\nMODE 2 \r\n \r\n umdh [-d] {File1} [File2] [-f:Filename] \r\n \r\n Compares two dumps and resolves the symbols. \r\n \r\n -d Output in decimal (default is hexadecimal) \r\n -f Indicates output file. \r\n \r\nEXAMPLE: \r\n \r\n -1- umdh.exe -pn:application_name.exe -f:FirstDump.txt \r\n -2- ... exercise the application \r\n -3- umdh.exe -pn:application_name.exe -f:SecondDump.txt \r\n -4- umdh.exe FirstDump.txt SecondDump.txt -f:Result.txt \r\n Compares allocations from the two dumps. \r\n \r\n umdh.exe Dump.txt \r\n Investigate a single dump. \r\n \r\nNOTES: \r\n \r\n Uses the dbghelp library to resolve symbols \r\n therefore _NT_SYMBOL_PATH must be set appropriately. \r\n \r\n \r\n", "output": "// _NT_SYMBOL_PATH set by default to C:\\Windows\\symbols\r\n// Debug library initialized ...\r\n// \r\n// Each log entry has the following syntax: \r\n// \r\n// + BYTES_DELTA (NEW_BYTES - OLD_BYTES) NEW_COUNT allocs BackTrace TRACEID \r\n// + COUNT_DELTA (NEW_COUNT - OLD_COUNT) BackTrace TRACEID allocations \r\n// ... stack trace ... \r\n// \r\n// where: \r\n// \r\n// BYTES_DELTA - increase in bytes between before and after log \r\n// NEW_BYTES - bytes in after log \r\n// OLD_BYTES - bytes in before log \r\n// COUNT_DELTA - increase in allocations between before and after log \r\n// NEW_COUNT - number of allocations in after log \r\n// OLD_COUNT - number of allocations in before log \r\n// TRACEID - decimal index of the stack trace in the trace database \r\n// (can be used to search for allocation instances in the original \r\n// UMDH logs). \r\n// \r\n\r\n\r\n\r\nTotal decrease == 0 requested + 0 overhead = 0\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\umdh.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "usbview.exe-F57E935A24CF7C76948F7D221BD1EDE9": { "file_name": "usbview.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\usbview.exe", "hash_md5": "F57E935A24CF7C76948F7D221BD1EDE9", "hash_sha1": "18BC11B740D967C3C0112DD2EB31712F06CF49BC", "hash_sha256": "5240369DE615B076F7DE548523CDDA51D720078D130985B177E00F3C05C4EB96", "hash_sha384": "2278507B6B392006001E9D9969355E1E4220E0E66862A51930E1EB8501C4966EB084896AEF4512EDA8251E3FB39BEB87", "hash_sha512": "E5A7BFA7E97F59649F7F2BBB141E5619E0E28C413A6F371142AE3678DCE9903FBE45DB8AD93C38E73AEDAA5EF7C6143702396A29D8832417CFF9E6DA97CD6EA0", "hash_ssdeep": "12288:/NIWApVpqTA5TMOECaa7UzHkUcUw0NIyc62sO+gbp2seeKx4H9rbL7rbL7rbL7rE:/1ApV3TMOEyiE4NIyc6HVgbpUe3H9rbw", "hash_imp": "F777B39DC51FDC0FEFDC5A1AF521C113", "hash_pesha1": "5E36F45F3A63F7932486AAD3DD48559FEC318857", "hash_pe256": "E4B1AC6C139D05339E03FA7238374727D5947027EEA3D957CEB4BFDBA767DEE7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) USB device viewer", "meta_original_filename": "USBView", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright Microsoft Corporation 1996-2011 All Rights Reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5240369de615b076f7de548523cdda51d720078d130985b177e00f3c05c4eb96/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_5380": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_32\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\usbview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\usbview.exe" }, "vmdemux.exe-A993A1F5991289CAD9F48EC48298C680": { "file_name": "vmdemux.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\vmdemux.exe", "hash_md5": "A993A1F5991289CAD9F48EC48298C680", "hash_sha1": "FBE585EF75EF13DAE7C15D5F3C0798036648FC9D", "hash_sha256": "89D60F636A1A95DB4D560639DED6B117963875407EFDF9DEC66DF7E87111B004", "hash_sha384": "F6573C4DA7222D3C28BBF70465CC851D8B7AC59668E4EDE362C36746D8094F197C95D34ED0A835D35EA0ABB7768CAEB0", "hash_sha512": "5364713B0B78C0CC73CBC931425E0F2A171974E92FDF70510005B50E03BCD956D93888EB78947FAEDFC431FA58C5642F7ADA3BA9A8672B9F771B4012427DB27F", "hash_ssdeep": "1536:M1++23RB86vvwZfz98SOMCVV4KFFMSsjFtY9sWxgx:M1+5A5OS2Xgx", "hash_imp": "1BA7996BCCC78780DB114C829B429CBA", "hash_pesha1": "6D6174AD73A9A62873C09CC574727DA3461E83D4", "hash_pe256": "A391689EC2920BA503AC23289BC3A8A6BF6E8FB85D279C186749AD64DB2C0E1B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hyper-V Unified Debugging Session Demuxer", "meta_original_filename": "vmdemux.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "bad command line option '--help'. For usage try 'vmdemux -?'", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\vmdemux.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "windbg.exe-703B2F8C342FEB9FC8782F48B47BA698": { "file_name": "windbg.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\windbg.exe", "hash_md5": "703B2F8C342FEB9FC8782F48B47BA698", "hash_sha1": "2CFAE4B5F01E36B937E7AB2BAB4DEF4563330062", "hash_sha256": "B1CE9D33E94CFB98989147AD1A9CC190FF2EDB97BA24F47A80C5ADAAB01EE80C", "hash_sha384": "FCB1F8A7686EF7681FA0B75988B41E38A77222F98EBC5CBCCAD111F262FE6A3E1B59E6F057E5CFAF1164BF96D2A92A2B", "hash_sha512": "81CBC23BA64CFF21B89D5773A269516C44F91F4BAFD60E9E58EF8ABA654070A5573E8035F10A498EE5719C54C91E027E1D3E7D78285FC72C0E95D864A6BA0C2C", "hash_ssdeep": "12288:ziaAINi0BQjAHXrzYWZci2+Tousrte4XL:D9/L7zYWZT2+Touge", "hash_imp": "CE2DF536539DE0880E2AEF4A9EE567FE", "hash_pesha1": "FF6C1246D69A9A92F08DD9C9F74CDD38752478A9", "hash_pe256": "5B2D3184EF2BEB5F69E50B95D0671B338F5ED4E4A263DA11C2DA66510F78A91B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows GUI symbolic debugger", "meta_original_filename": "windbg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b1ce9d33e94cfb98989147ad1a9cc190ff2edb97ba24f47a80c5adaab01ee80c/detection", "children": "help.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\1f50HWNDInterface:40030c": "Section", "(RWD) C:\\Windows\\SysWOW64\\ntdll.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\sym\\wntdll.pdb\\3CCC2398F623C3D0915D0E0ADC5714A71\\wntdll.pdb": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_window_title": "help - WinDbg:10.0.19041.1 X86 ", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\windbg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "pdbstr.exe-25C823A77EE3183330CFF8D2CF381C9F": { "file_name": "pdbstr.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\srcsrv\\pdbstr.exe", "hash_md5": "25C823A77EE3183330CFF8D2CF381C9F", "hash_sha1": "5AC3BCAF9140C1D374F91DE3C1658FD0E4D7D445", "hash_sha256": "B7CF928B4C48CAA6B39097AE8A27AEC9565C99EE8BC9190C3D97C7AF107E88CC", "hash_sha384": "DC521F3C3A7531AEDCB1262896CFBB3163C2E5289D689B6BA82D6B09FF90394957ECE68CA8C2B39035C26773EC3688E2", "hash_sha512": "C100DE1607958468B16EBEC377832E244EAE40664B0BC6701760D432F817EB5CA7F44681F08B602AF22B822CB3B1C532C98080212342F07C882A8809CCD7F474", "hash_ssdeep": "12288:CNjFhNL1uWDlVtIk3w5UeOTIjV/omLa3CepeF0RMIMq8qujfQpXt+H1DWbQmeKR:OhYWRIk3wjZgpeF0Rlz+HFWbQmeKR", "hash_imp": "146F88594791252355248F736B945F0C", "hash_pesha1": "D223265652834A091209AB2906CDCD14DFF04FAD", "hash_pe256": "085CF89CC710BE5DE270835FCABE5653856F003137864E4BD99106AF4819FA61", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Stream Utility", "meta_original_filename": "pdbstr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "pdbstr -r/w -p:PdbFileName -i:StreamFileName -s:StreamName\r\n -r/w indicates whether to read or write the stream\r\n -p name of PDB\r\n -s name of stream in the PDB\r\n -i input text file containing stream to write to PDB (in write mode)\r\n -i output text file for writing contents of PDB stream (in read mode)\r\n", "error": "Error while parsing arguments. Usage:\r\npdbstr -r/w -p:PdbFileName -i:StreamFileName -s:StreamName\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\srcsrv\\pdbstr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "srctool.exe-EEA8C0C3F61C62609C8B3302C42B9151": { "file_name": "srctool.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\srcsrv\\srctool.exe", "hash_md5": "EEA8C0C3F61C62609C8B3302C42B9151", "hash_sha1": "549DA686DB806F357D515C5EA1A4B406220D36C7", "hash_sha256": "00EDAA35802553A531E934A819BDA1EBF47A1D4C7C710245923D66884F8F85AF", "hash_sha384": "84EF2F2CF938106BCB27D7AA4B8796847AFD1B735340C0FA4DDD413F58A9B8DA29CFD7A063BCCA963BDF18ADD2DDA5DE", "hash_sha512": "F19CED2FC8A7DFFC27A2856F613250939DF7A6FB7326475B8A90807C0AA68BB9D9F64D42A357F43FA1C6C0F82F247220A67F32437232C0FBBB1FD413F5346827", "hash_ssdeep": "768:d/8VlU0C9yqKy2BF/CLqmrU2zVo0Fdhh6qASX:du+Z9yqKy/2mr7zVo0FcDSX", "hash_imp": "EB5E6B0512D3A3012D57AC991444B74A", "hash_pesha1": "04F8248490A758ED485E0F794A95690707E85871", "hash_pe256": "1FC7EB84E5FAD3D041663E4EF25719FE263BD97F2B8492A0AE4A61C3C5C519F3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Stream Utility", "meta_original_filename": "srctool.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "srctool:\r\n Dumps source information from a pdb or srcsrv stream file.\r\n You must specify a pdb, executable, or srcsrv stream file on the\r\n command line.\r\nOptional Parameters:\r\n -u Displays only source files that are not indexed.\r\n -r Dumps raw source data from the pdb.\r\n -s Recurses subdirectories.\r\n -h Dumps the hash/checksum of the source file.\r\n It is valid only when the -r or -u option is selected.\r\n -l:<mask> Limits output to only source files that match this wildcard\r\n expression.\r\n -lf:<mask> Same as -l except that the mask is applied only to the filename.\r\n Directory paths are ignored and all are matched.\r\n -x Extracts the files, instead of simply listing them.\r\n -f Extracts files to a flat directory.\r\n -n shows version control commands and output while extracting.\r\n -d:<dir> Specifies the directory to extract to.\r\n -c Displays only the count of indexed files - no detail.\r\n -z Returns zero on success or nonzero on failure.\r\n -o Displays the full original version control extraction commands,\r\n disabling any VCS-specific output formatting heuristics.\r\n -a Applies all available VCS-specific heuristics to parse the commands\r\n and output their contents in some user-friendly way.\r\n Without this flag, only the Source Depot (Microsoft internal) heuristic\r\n is applied.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\srcsrv\\srctool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "vssdump.exe-B1AE989F01C157A59172437781B5983A": { "file_name": "vssdump.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\srcsrv\\vssdump.exe", "hash_md5": "B1AE989F01C157A59172437781B5983A", "hash_sha1": "6226634D60D6F2C93B08C2736492BF01B0BF81BA", "hash_sha256": "E9CF573BEFBF4366665139CE2D36A419EFEFB9CCBEC3745D8800626233D6866E", "hash_sha384": "120F4CB95CB52AD78144D9B3B048E6AE6659D4D2B7F3E722727E472EC28CE9CD4C2A6045B5675D89020858226BD91475", "hash_sha512": "36D1A041908370718D3FD250C692DAFEC80D239D61E168F80CFA381AA1B04C1046E1D2FC5BE41EBD4EB7E8F801ACDE98F22BDD5DAA5B01BC79C86945C5DFFA94", "hash_ssdeep": "384:ggHUK1WTPgzpAS1xnYfHV7RvIzlArUTB9ffIGWYRzWiOJv1NwGyAAJllN42:RvWTPgzCo9fQEpEXNi4", "hash_imp": "443B9BDBA2773E6E1A824E19FD3967A0", "hash_pesha1": "AD8D194D0E47F23E8F4E5D715ED870AC66DD4CE5", "hash_pe256": "359E9A2502E4B35C68DFA569A67A4E61B685C3965FA63318C8A8C7E663D01BB3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft VSS Folder Dumper", "meta_original_filename": "vssdump.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "vssdump: enumerates files in the current VSS project.\r\n -a ignores the current project and lists all projects.\r\n -p:<projectname> specifies a VSS project to use.\r\n not to be used -with '-a'\r\n -d:<directory> specifies a root directory\r\n otherwise the current directory is used.\r\n -l:<label> specifies a version label\r\n -t don't test version to match a passed label\r\n -v:<sharepath> specifies location of the VSS database - overrides SSDIR\r\n -r recurse subdirectories\r\n -f don't list files - just directories\r\n -i ignore current directory and list entire project\r\n not to be used with '-r'\r\n -s format output for scripting\r\n -c display only the VSS configuration info\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\srcsrv\\vssdump.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Conduit.Broker.Host.exe-47421D88C71B87B1FD21B6FB6ED6E624": { "file_name": "Conduit.Broker.Host.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\Conduit.Broker.Host.exe", "hash_md5": "47421D88C71B87B1FD21B6FB6ED6E624", "hash_sha1": "ADE3A6D0F4A8AEDDE4890176A4C35CF74693A655", "hash_sha256": "1E921B204A1A10CDDF498A8564740EDC9E9895E1CC65333B688443D24CF365B1", "hash_sha384": "FF8E8050ADF60F7FC38E0C1D7A8E5963A5DE06A319FE21C1E4AD0D99C932E5E68F39D74393F8C5EEC48ABAA73A2EE750", "hash_sha512": "7733D76BC4D78B2FC72B015CA19BE86CEF990DE0DBA4BFB43BC82218136B89F4252E8CC3E1473AEB7BF1933AB3BE1B1EC2D8631D3DE86CFEF7FCBD50E6742860", "hash_ssdeep": "3072:1w9jvtYazbE5l2kuANCNkADDf1B6jBoG8NSJP6lq8qRhOt:1w9byaIuANYkOaVPf1/Ot", "hash_imp": "B88724465E5300AB482945B2E7BA1C34", "hash_pesha1": "4EE7C239954F397E632FEC40C887994A28D598AE", "hash_pe256": "56A1C67160FC3B1BE0C6669D8A9F5D40C931DEF3644AFCE740CD85D352AF56D3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Conduit.Broker.Host [v10.43]", "meta_original_filename": "Conduit.Broker.Host.exe", "meta_product_name": "Test Authoring and Execution Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.43.1909.04003", "meta_product_version": "10.43.190904003-develop", "meta_language": "English (United States)", "meta_legal_copyright": "Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "[HRESULT 0x80004004] Failed to initialize the broker process. (Expected to see ' ' in \"--help\".)\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\Conduit.Broker.Host.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "TE.exe-2767D54B6449D3CB17B69B7C9BE7B601": { "file_name": "TE.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\TE.exe", "hash_md5": "2767D54B6449D3CB17B69B7C9BE7B601", "hash_sha1": "300DB2586498E561B5E040F3DFF35E7132D64638", "hash_sha256": "538981E1D87081F1E6F2E1D6296AF604072DBFC65638540326DC537BA5F6263C", "hash_sha384": "A6100DF47FA1FDA592A7B73DD5137988090F7D1A084439F97B6386AA675CFAD2733FD50C72DAEDDBE3160D178150DF3B", "hash_sha512": "9E59F0EE8F3797432F8814D321BB8ECCB293DEDD5761807B8B2EA061728A2F9EDF75E6D14F7D9FEB8720A5C8B51E44606F3444234BE0FE29F5BB0EAD5EBA8167", "hash_ssdeep": "6144:lptbp+xB8m+6rvUs/wp/MSl+neMWmiPOuoareRk5l/:lptbp+xB8J6IXhMSl7MWLOLa5V", "hash_imp": "8268621D19CF595B5F33A4C3F8E3E0DD", "hash_pesha1": "4CBC29BB5B74F0ADBFF45DC5DA5BCAC0CAC9C282", "hash_pe256": "6B959BC160D32B4B218C2918630A6C0EED55EE558E2BD470BF56897E388C614D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Test Authoring and Execution Framework [v10.43k]", "meta_original_filename": "TE.exe", "meta_product_name": "Test Authoring and Execution Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.43.1909.04003", "meta_product_version": "10.43.190904003-develop", "meta_language": "English (United States)", "meta_legal_copyright": "Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/538981e1d87081f1e6f2e1d6296af604072dbfc65638540326dc537ba5f6263c/detection", "output": "Test Authoring and Execution Framework v10.43k for x64\r\n\r\n[TE.exe] Executes one or more test binaries\r\n\r\nUsage: TE <test_binaries> [/select:<query>] [/inproc] \r\n\t [/enablewttlogging] [/list] [/listProperties] \r\n\t [/!]\r\n\r\n\ttest_binaries Specify one or more test files to execute\r\n\t\t\t (separated by spaces). Wild card selection is\r\n\t\t\t supported.\r\n\r\n\t/select:<query> The selection criteria to be used when selecting\r\n\t\t\t tests from each test binary. Selection criteria\r\n\t\t\t is composed of one or more of the following:\r\n\r\n\t\t\t @[property name] = [value as string]\r\n\t\t\t @[property name] >= [value as float or integer]\r\n\t\t\t @[property name] > [value as float or integer]\r\n\t\t\t @[property name] <= [value as float or integer]\r\n\t\t\t @[property name] < [value as float or integer]\r\n\r\n\t\t\t - Property values as strings must be within single\r\n\t\t\t quotes.\r\n\r\n\t\t\t - You can specify a composite selection criteria\r\n\t\t\t using \"and\", \"or\" and \"not\" (case insensitive).\r\n\r\n\t\t\t - Property string values support wildcard searches\r\n\t\t\t via \"*\" and \"?\" characters.\r\n\r\n\t\t\t - For float and integer values, the \"*\" character\r\n\t\t\t may also be used as 'exists', but may not be\r\n\t\t\t used for partial matching.\r\n\r\n\t\t\t For example: /select:\"@Priority=*\" is valid, but\r\n\t\t\t /select:\"@Priority=4*\" is not.\r\n\r\n\t\t\t - For detailed /select examples, run TE /!\r\n\r\n\t/name:<testname> Alternative to \"/select:@Name='<testname>'\". The\r\n\t\t\t <testname> can still contain wildcard characters, \r\n\t\t\t i.e. \"*\" and \"?\", but should not be contained \r\n\t\t\t within single quotes. \r\n\r\n\t/inproc\t\t Execute all tests within the TE.exe process itself\r\n\t\t\t rather than within TE.ProcessHost.exe.\r\n\r\n\t/enablewttlogging Enables WTT logging; Wttlog.dll must be available\r\n\t\t\t in your path.\r\n\r\n\t/list\t\t Lists the names of all the test_binaries and the\r\n\t\t\t classes and methods in them. If selection criteria\r\n\t\t\t is specified, lists only the names of those which \r\n\t\t\t meet the criteria.\r\n\r\n\t/listproperties\t Lists the names and properties of all the \r\n\t\t\t test_binaries and the classes and methods in them\r\n\t\t\t along with Setup and Teardown function names, if \r\n\t\t\t available. If selection criteria is specified, \r\n\t\t\t lists only the names of those which meet the \r\n\t\t\t criteria.\r\n\r\n\t/!\t\t Display detailed help and additional options in a \r\n\t\t\t browser window.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\TE.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "TE.ManagedHost.exe-E921386A75C00B784323E6469244318F": { "file_name": "TE.ManagedHost.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\TE.ManagedHost.exe", "hash_md5": "E921386A75C00B784323E6469244318F", "hash_sha1": "6F439BC5473F0DCB0D255350E76FB7704E0C2CC6", "hash_sha256": "7C80C920C3EE5F84410B133C5AB14DD9C7DD0C8430EA7B9302BE6B87C33C9109", "hash_sha384": "B1DAFC2C8670C60EDA42F95873F6E92FFC142CFA082636E2F820198F4379AA1BB1D10BDA9B14A3E4BA826AAFF4B73D54", "hash_sha512": "A6EEC364EAB5353EE75CFEA09939F1BC3B23521F4BE81B6019EC2D5DEEFA6890D486147A4BE1D53416206CA40B2F30D13B076FB24A731B5FFD8D8984DFA90090", "hash_ssdeep": "384:tGJXcom20HbphN/nFi7wyLeMvbgR2RK+nsWWS31:tGxcomJbphts7NG2RK+s2", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "B98059C436E5143F54156C89E7B4C6E037A9F355", "hash_pe256": "19D20FFCBD8521F1F8A13B24D3FF54BD1C0A0EF691088FAF9B4184BBDD385559", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\TE.ManagedHost.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "TE.ManagedHost.exe", "meta_original_filename": "TE.ManagedHost.exe", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.43.1909.04003", "meta_product_version": "10.43.190904003-develop", "meta_language": "English (United States)", "meta_legal_copyright": "Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7c80c920c3ee5f84410b133c5ab14dd9c7dd0c8430ea7b9302be6b87c33c9109/detection", "output": "Specified operation is not supported.\r\nTE.ManagedHost\r\n\tUsage: TE.ManagedHost.exe /Operation=OperationName /ErrorLogPath=\"Path\" [parameters].\r\n\r\n\tSupported operations: \r\n\r\n\t\tGenerateAxeJob - Generates AXE job from AXE manifest.\r\n\t\tGenerateAxeJob usage:\r\n\t\t\tTe.ManagedHost.exe /Operation=GenerateAxeJob /AssessmentManifestPath=\"Path\" /AssessmentJobPath=\"Path\" [/AxeParameter1Name=AxeParameter1Value /AxeParameter1Name=AxeParameter1Value ...]\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\TE.ManagedHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "TE.ProcessHost.exe-B64ABB46EEE0EBEAD56AE658ACCF02CF": { "file_name": "TE.ProcessHost.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\TE.ProcessHost.exe", "hash_md5": "B64ABB46EEE0EBEAD56AE658ACCF02CF", "hash_sha1": "2487B1E13B7C1074F412B48835AEF3E1CABE38AC", "hash_sha256": "4BDD7E68D8A4560D55549600A76F8A1998AFE01654D3130D6BDE2A720921C255", "hash_sha384": "14A0FF3B602261C29376ABEAD1C3715BAB21EE68E69025F2E37F2B7276C37BCA676AA15F245C2C1A5290968AC9B682C5", "hash_sha512": "4B9874A58C6781B0087E46915BF4ECAA42138899FC9112006E34583BFE69B15444792DFBD7073920604838D6840A259D4C343B19648FB2EB54B7CA9B18BB1B5F", "hash_ssdeep": "384:qOV7aZsn9FOHHJMoqXfQetGe3KorVZW9gyovQHRN7PUulWwm:rFaZsAHIvQw3Kq0a8D", "hash_imp": "DAD4DF10E3FEA7B5837633391A70E31C", "hash_pesha1": "1F026E527547A442F69F9DFC0BB779F2E4829C7A", "hash_pe256": "40FB78C852886CB95309C9A48C0401C10076AB3506C8F32F377E17B504BE59AC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Test Authoring and Execution Framework [v10.43]", "meta_original_filename": "TE.ProcessHost.exe", "meta_product_name": "Test Authoring and Execution Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.43.1909.04003", "meta_product_version": "10.43.190904003-develop", "meta_language": "English (United States)", "meta_legal_copyright": "Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4bdd7e68d8a4560d55549600a76f8a1998afe01654d3130d6bde2a720921c255/detection", "output": "TE.ProcessHost.exe cannot be executed independently. Please use TE.exe to launch TAEF.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\TE.ProcessHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "TE.ProcessHost.UAP.exe-68A404C3C06CA1200DDBE130C3D6311A": { "file_name": "TE.ProcessHost.UAP.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\TE.ProcessHost.UAP.exe", "hash_md5": "68A404C3C06CA1200DDBE130C3D6311A", "hash_sha1": "EE94AE06182EAC6AA69F79DC2C98C8BC1CDA1EBF", "hash_sha256": "2284ACF5E7089103A1E76BADA3262823A2B0F39FB2BF1FE320919D75961DEC42", "hash_sha384": "EE6F134F2B0A9D2D6040C90D07E695DE09728C9D7CD4628C8209094CF6ED7997A23240A28D86915917E2B4E8EDEF1FF6", "hash_sha512": "1AF2CA3D27EB65042A15E4462864F9B0E571C4B4BC728393A9AF7D1504CBD44BF39D45713438A7F7E97ACDB74EF5CB8DBB8908E692C2DE9845EF0A2E3AB2E4B7", "hash_ssdeep": "384:Y2qCilgsnR+oBnJMBMXf0letGe6aJspW24orcyHRN7WEtXhlMgGt:Y2Algstjv0lw6aWSkg", "hash_imp": "230BC52C63ED654A1BE17FF078C53781", "hash_pesha1": "834A0F0E549C74DFBA41880F57829FE0E309CBAC", "hash_pe256": "955B01CD41BD25F2E1E0AEC64B1F578E409276B2BD4B4B59EF01EDF9FBC410E5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001529B409F5056997588000000000152", "signature_thumbprint": "711AF71DC4C4952C8ED65BB4BA06826ED3922A32", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Test Authoring and Execution Framework [v10.43]", "meta_original_filename": "TE.ProcessHost.UAP.exe", "meta_product_name": "Test Authoring and Execution Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.43.1909.04003", "meta_product_version": "10.43.190904003-develop", "meta_language": "English (United States)", "meta_legal_copyright": "Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\TE.ProcessHost.UAP.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\TE.Host.dll" ] }, "Wex.Services.exe-03B28C029FA5895D2391B4308CAB54FE": { "file_name": "Wex.Services.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\x64\\Wex.Services.exe", "hash_md5": "03B28C029FA5895D2391B4308CAB54FE", "hash_sha1": "6647094E3C6DBF71C9D3DE471D8C7A36A0AB1D28", "hash_sha256": "AB50B0EEB9B42DD6D3785C05829F3D84DA589C48E3E8F969DF17D3C6ACB067CF", "hash_sha384": "B724BB0D36184F638E879E2B61EFEA5B245E546A761DC58D9BFA04CADF704F9912F2A20C5B80003FCCED1CF9505D0EA0", "hash_sha512": "ED21AA62D25AD835B5A07E98E6CBD605A997315CE0C8C282B59C06393AAC09CE87FEAF1903A6A6BE7B523F606C0B21DBE8E4C12B002E32253093C986947BA72B", "hash_ssdeep": "3072:fxazRnvaontvdlC/AngmWU4AsQ/6+xBD5BSpzqWZAxQNJ1vl/xOAYgIrQBZVhB:fUdnvHvdlCIn8U4e99OcqAUl/8rQBZvB", "hash_imp": "A95834891C8CA2E5398E162B8C6AAE96", "hash_pesha1": "4DA4C4B0CDF22BE03CFE5E7B9953A923791A5C7B", "hash_pe256": "33D943245940BBC92F9C2178FFC0BC99C1DA6C7A325FABAE9050375BE4398182", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Wex.Services [v10.43k]", "meta_original_filename": "Wex.Services.exe", "meta_product_name": "Test Authoring and Execution Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.43.1909.04003", "meta_product_version": "10.43.190904003-develop", "meta_language": "English (United States)", "meta_legal_copyright": "Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\n[Wex.Services.exe] Runs, installs, or removes Test Authoring and Execution Framework services\r\n\r\nUsage: Wex.Services [/install:<service name>\r\n [/remove:<service name>]\r\n [/run:<service name>]\r\n [/list]\r\n [/?]\r\n [/help]\r\n\r\n Service installation or removal requires running \r\n Wex.Services.exe from an elevated command prompt.\r\n\r\n /install:<name> Specify a service name name to install \r\n\r\n /remove:<name> Specify a service name name to remove\r\n\r\n /run:<name> Runs the specified service in the context of the current user\r\n\r\n /list Lists the names and descriptions of all available services\r\n \r\n /? or /help Prints this help message\r\n \r\nExamples:\r\n\r\n Wex.Services.exe /install:Te.Service\r\n\r\n Interpretation: \"Install 'Te.Service' service\"\r\n\r\n Wex.Services.exe /remove:Te.Service\r\n\r\n Interpretation: \"Remove 'Te.Service' service\"\r\n\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\x64\\Wex.Services.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wpa.exe-F7BF05BE5FD192120CF8390AF1A84EED": { "file_name": "wpa.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\wpa.exe", "hash_md5": "F7BF05BE5FD192120CF8390AF1A84EED", "hash_sha1": "C4E3C253312B66B4C83DD7C6EACFC16054E7651A", "hash_sha256": "BFB94B0A159E36D4B1D2D93785FEAA15532E70B0A0C7B3CA43A709D6478C53B8", "hash_sha384": "102F3AA413BE0861A74842B71609EBF6272DAD9F9B788FBB458031E260F0E94DC4AE1A16D37D09DADE752F78D5C2CEEE", "hash_sha512": "F74C9E5BDC4F8914875F5C6687E68D099BCC80753FDBA710A887C1FD6140431988D7092B094FA69A25C1ECEFF334E499EC1A1A08AF3DB8FA22C22AFCBA1EA434", "hash_ssdeep": "1536:l6FmtMYB9LrMofxvKojFBPNMC4FKN/vwz7NZ3IaZBOn42Syu:mm7DfMof9ZPqlKN/vwvIabOn5Syu", "hash_imp": "n/a", "hash_pesha1": "CCCAD25D45FEE73EDB3B91D04798DB25ABB9D460", "hash_pe256": "967292239A758731AE76937C8B88F7A681083B84BFF7305399558A65B2FDDD84", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Performance Analyzer", "meta_original_filename": "wpa.exe", "meta_product_name": "Microsoft Windows Performance Analyzer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " 2019 Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/bfb94b0a159e36d4b1d2d93785feaa15532e70b0a0c7b3ca43a709d6478c53b8/detection", "output": "\r\nMicrosoft (R) Windows Performance Analyzer Version 10.0.19041.1 (WinBuild.160101.0800)\r\nCopyright (C) 2021 Microsoft Corporation. All rights reserved.\r\n\r\nUsage:\r\n\r\n wpa.exe <<[-i] <file path>> [trace specific options]> ... [general options]\r\n\r\n -INPUT FILE OPTIONS-\r\n\r\n [-i] <input file path> Specifies a file to open for input. This option\r\n may appear multiple times. Input file path can\r\n take one of the following forms:\r\n\r\n [-i] <ETL file> [trace specific options]\r\n\r\n [-i] wpa://<ETL file>[?profile=<profile path>]\r\n profile path The path to a *.wpaprofile file specifying the\r\n UI profile to apply.\r\n\r\n [-i] <assessment xml file>\r\n\r\n [-i] wpa://<assessment xml file>[?issue=<issue id>][?profile=<profile path>]\r\n issue id The issue ID\r\n profile path The path to a *.wpaprofile file specifying the\r\n UI profile to apply.\r\n\r\n -TRACE SPECIFIC OPTIONS-\r\n\r\n -slot <m> Assigns the trace to profile slot m, where m is an\r\n integer.\r\n -range <T1 T2> Zoom to time range [T1,T2]. If units are not specified,\r\n then the units are assumed to be nanoseconds.\r\n Example: -range 10s 20s\r\n Example: -range 5 15\r\n\r\n -region <name> Zoom to the time range defined by a region.\r\n -marks <name1> <name2> Zoom to the time range which starts at the first\r\n mark and ends at the second mark.\r\n\r\n -UNIFIED TRACE SPECIFIC OPTIONS-\r\n\r\n -range <T1 T2> Zoom to time range [T1,T2]. If units are not specified,\r\n then the units are assumed to be nanoseconds.\r\n Example: -range 10s 20s\r\n Example: -range 5 15\r\n\r\n -region <name> Zoom to the time range defined by a region.\r\n\r\n -GENERAL OPTIONS-\r\n\r\n -profile <profile path> Applies the specified *.wpaprofile profile in\r\n the UI.\r\n -symbols Enable symbol decoding as the trace is loaded.\r\n -symcacheonly Symbol loading uses only existing symcache files.\r\n -cliprundown Do not display the rundown region of the trace.\r\n -tti Process the trace even in the presence of time inversions.\r\n\r\n -help, -h, /? Displays this help screen.\r\n\r\n", "error": "Windows Performance Analyzer 10.0.19041.1 (WinBuild.160101.0800)\r\nCommand line: help\r\nCreating WPA Files directory: C:\\Users\\user\\Documents\\WPA Files\r\n", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_8180": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\microsoft.performance.shell.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\microsoft.performance.base.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\Microsoft.Diagnostics.Tracing.EventSource.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\PresentationFramework\\v4.0_4.0.0.0__31bf3856ad364e35\\PresentationFramework.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\WindowsBase\\v4.0_4.0.0.0__31bf3856ad364e35\\WindowsBase.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xaml\\v4.0_4.0.0.0__b77a5c561934e089\\System.Xaml.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Core\\v4.0_4.0.0.0__b77a5c561934e089\\System.Core.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\microsoft.performance.ui.dataengine.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\microsoft.performance.dataengine.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\microsoft.performance.windows.dll": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\PresentationCore\\v4.0_4.0.0.0__31bf3856ad364e35\\PresentationCore.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\microsoft.performance.ui.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\microsoft.performance.core4.interop.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\ecosystem.core.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\UIAutomationTypes\\v4.0_4.0.0.0__31bf3856ad364e35\\UIAutomationTypes.dll": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\microsoft.assessments.administration.presentation.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\ecosystem.windows.dll": "File", "(R-D) C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\microsoft.performance.data.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\PresentationFramework.Aero2\\v4.0_4.0.0.0__31bf3856ad364e35\\PresentationFramework.Aero2.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\wpa.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "wpaexporter.exe-53DE1C9E113BEFB76CFBB87C39482701": { "file_name": "wpaexporter.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\wpaexporter.exe", "hash_md5": "53DE1C9E113BEFB76CFBB87C39482701", "hash_sha1": "68CF10102FC6283F4E5571DA82C003C7BB034173", "hash_sha256": "ADACD487B34A2F6BA9B5994ADC745D64B84717FE478A85DB9BFB1A61E6653C8A", "hash_sha384": "2D952AFFBA9251CE8805F0966D8E4216AEAEE37ED1B531ADA980ECC0445775608B5FBF11016D42E7C6ACCFD9D39016E2", "hash_sha512": "F51731DE1B14A4F1C36A863F1E885D49A56185EA9DF664B28A357A4772065676FA388FDBE65D1083027672C604CA988B8684F81DC78D3701A276CD2936061818", "hash_ssdeep": "3072:1TerEHkU0SiT7gGAs1PqlKN/vwvIazOv5eTg:JHkU0Z1Pqw6vh+yg", "hash_imp": "n/a", "hash_pesha1": "8319EE8741872FF437AE77280A26C6C3399AC4F8", "hash_pe256": "B29E8DB1360AA401CD17C4EE0E7BFF4D096DDB7F6F37DA87C05C9005EF9B1D57", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Performance Analyzer", "meta_original_filename": "wpaexporter.exe", "meta_product_name": "Microsoft Windows Performance Analyzer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " 2019 Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/adacd487b34a2f6ba9b5994adc745d64b84717fe478a85db9bfb1a61e6653c8a/detection", "output": "Microsoft (R) Windows Performance Analyzer Version 10.0.19041.1 (WinBuild.160101.0800)\r\nCopyright (C) 2021 Microsoft Corporation. All rights reserved.\r\n\r\nUsage:\r\n\r\n wpaexporter.exe <<[-i] <trace.etl> [trace specific options]> -profile profile.wpaProfile> ... [general options] \r\n wpaexporter.exe -exporterconfig <config_file> [general options] \r\n\r\n -INPUT FILE OPTIONS-\r\n\r\n -profile <profile.wpaprofile> WPA profile containing the tables to export,\r\n as well as any optional regions XML or stack\r\n tags files.\r\n -exporterconfig <config_file> A configuration file describing the traces\r\n and profiles to export\r\n\r\n -TRACE SPECIFIC OPTIONS-\r\n\r\n -slot <m> Assigns the trace to profile slot m, where m is an\r\n integer.\r\n -range <T1 T2> Zoom to time range [T1,T2]. If units are not specified,\r\n then the units are assumed to be nanoseconds.\r\n Example: -range 10s 20s\r\n Example: -range 5 15\r\n\r\n -marks <name1> <name2> Zoom to the time range which starts at the first\r\n mark and ends at the second mark.\r\n -region <name> Zoom to the time range defined by a region.\r\n\r\n -GENERAL OPTIONS-\r\n\r\n -delimeter <char> Character to use as a separator between values in the\r\n CSV. Defaults to , (comma)\r\n -prefix <prefix> String to prepend to all the output filenames.\r\n -outputfolder <folder> Folder to which to output the exported tables.\r\n -symbols Enable symbol loading.\r\n -symcacheonly Symbol loading only uses existing symcache files.\r\n -sysconfig <table>,... Export System Configuration tables\r\n -h, /? Display help screen.\r\n\r\n", "error": "No data to export was specified\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\wpaexporter.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wpr.exe-3836F328B1E6F7C642B35115D9A2E774": { "file_name": "wpr.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\wpr.exe", "hash_md5": "3836F328B1E6F7C642B35115D9A2E774", "hash_sha1": "E584719FE68C2482E2B0F4042148442F53BB5757", "hash_sha256": "A368454E020E720987DED3D604D654F6314803397153D64D0D2744401B3FF11F", "hash_sha384": "BA2F75DA6D628627B25BD29A8B8F77B9608116FDAE52DF630D3276E47612520EE86F3DBDAF8348C54B3C1F9755E23030", "hash_sha512": "E165855D0B56FE250C3D2FEC53C997D94B9A86B5F1A8D41E7218438EEF06A26B76866B0F447AB14AA995E8B7EC989605E37B8518CA25C6494CCBE98FFE935910", "hash_ssdeep": "6144:FgtvJfDldaBXZd0PaHw/kDeuiEKvK5cnbhbYk06S0Rj:2ZJfreXZd0pseuiISX/X1", "hash_imp": "E61CD2AA90474CA9DFFAD3043C7DA49E", "hash_pesha1": "C6A075712C6F0CF95E9919965A77B476EF335455", "hash_pe256": "CC1558826C64A2A8C0C10BD9C9031A827DA7D9D781A1CDDA3302F3859A223B59", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Performance Recorder", "meta_original_filename": "WPR.exe", "meta_product_name": "Microsoft Windows Performance Recorder", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " 2019 Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a368454e020e720987ded3d604d654f6314803397153d64d0d2744401b3ff11f/detection", "output": "\r\nMicrosoft Windows Performance Recorder Version 10.0.19041 (CoreSystem)\r\nCopyright (c) 2019 Microsoft Corporation. All rights reserved.\r\n\r\n\tUsage: wpr options ...\r\n\r\n\t-help\t\t\t - Provide command line help information\r\n\t-profiles\t\t - Enumerates the profile names and descriptions from a profile file\r\n\t-purgecache\t\t - Purges the dynamic symbols cache\r\n\t-start\t\t\t - Starts one or more profiles\r\n\t-marker\t\t\t - Fires an event marker\r\n\t-markerflush\t\t - Fires an event marker and flushes the working set\r\n\t-status\t\t\t - Displays status on active recording (if any)\r\n\t-profiledetails\t\t - Displays the detailed information about a set of profiles\r\n\t-providers\t\t - Displays detailed information about providers\r\n\t-cancel\t\t\t - Cancels recording initiated via WPR (if any)\r\n\t-stop\t\t\t - Stops recording initiated via WPR (if any) and saves\r\n\t-flush\t\t\t - Flushes logging sessions initiated through WPR (if any)\r\n\t-log\t\t\t - Configure debug logging to the event log\r\n\t-disablepagingexecutive\t - Change the Disable Paging Executive settings\r\n\t-heaptracingconfig\t - Change heap tracing settings for a process\r\n\t-snapshotconfig\t\t - Change snapshot settings for a process\r\n\t-capturestateondemand\t - Capture states for the configured providers in the current recording\r\n\t-pmcsources\t\t - Query the list of hardware counters available on the system\r\n\t-setprofint\t\t - Set sampled profile interval\r\n\t-profint\t\t - Query the current profile interval\r\n\t-resetprofint\t\t - Restores the default profile interval values\r\n\t-boottrace\t\t - Configures the registry entries for autologger/globallogger sessions\r\n\t-enableperiodicsnapshot\t - Enable Periodic Snapshot for the specified interval and given process id\r\n\t-disableperiodicsnapshot - Disable Periodic Snapshot for all process\r\n\t-singlesnapshot\t\t - On demand Snapshot for the specified process\r\n\t-instancename\t\t - Specifies a name to uniquely identify the tracing instance. \r\n\t\t\t\t Useful when managing multiple concurrent wpr sessions. Must be last parameter.\r\n", "error": "\r\n\tInvalid command syntax.\r\r\n\r\n\tError code: 0xc5600602\r\n\tInvalid option: --help\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\wpr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "WPRUI.exe-876DBF8520EAD410CBCFDD31B307E15E": { "file_name": "WPRUI.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\WPRUI.exe", "hash_md5": "876DBF8520EAD410CBCFDD31B307E15E", "hash_sha1": "F8C48B2111DACD126DD745562080B666E825B6D6", "hash_sha256": "7A45E9B06F3D6C8A71C3232D570834CCC37139E7FC1EEA00D4E9CCBA6853B167", "hash_sha384": "BC772B49B87007065619BFCE1EA5D5E74953E74690FD6D13BFEA4951A1066D1268215CE1CE3EA8C92B5D27B663083899", "hash_sha512": "9EBF3928E5A042666C93630F3648E8416BF644CB802C470573DAFFC31D7590A13682C008C203243ACC7571F6362C8B5D198A16BA3C59F9815B5C541B5C01ADDC", "hash_ssdeep": "384:iKSDkhC3Sb6/Izw5pq42Wj3/PfkrFt+iHZSkzY0H3UBgb9E8jT5WFNiW8TvXiKiQ:FS733IzMBiFU0kmbVjT2ESa0R", "hash_imp": "9267B84236E2E06A83272DF013B3B950", "hash_pesha1": "240966AD78DBC735F8CEE5D06247ED756303852A", "hash_pe256": "AA9D67C07F273A06F9E29A5A9E8191061862530A2CC8471F45E6CE2F5FBD9AF5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Performance Recorder", "meta_original_filename": "WPRUI.exe", "meta_product_name": "Microsoft Windows Performance Recorder", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " 2019 Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/7a45e9b06f3d6c8a71c3232d570834ccc37139e7fc1eea00d4e9ccba6853b167/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\WPRUI.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\WindowsPerformanceRecorderUI.dll" ], "runtime_window_title": "Windows Performance Recorder" }, "xbootmgr.exe-DA8725BAF21A0AD86C07DF1539BE8898": { "file_name": "xbootmgr.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe", "hash_md5": "DA8725BAF21A0AD86C07DF1539BE8898", "hash_sha1": "F3CBC38B4BECA6007216C239DE037F6D27AA1A27", "hash_sha256": "8F4B6FE4BEBB2451FA346F56021619CB856AA94EFA9D50C059EFE9F52BE033CF", "hash_sha384": "61A5D91FBEC45BF3853ECBE519D8796CEA97B2BE95FEFB2BECBC11D1A272225326755D703C2F82E8F598E2EF9DD4440D", "hash_sha512": "7DD9C1D3ECD1EE990E6D1906E9225C0B2056D83A903BB82067F589C434297E7768D8CC0526DDE5D4BEA0D81092E68167C353CF23023E66945B9FCA3341664418", "hash_ssdeep": "3072:SLpKgQLC98diQwGvyfcFg/G+K9g/Ovr+KexkXaFXGw:SLpnX98diQwGHqKsh", "hash_imp": "5633E87346C49426A8A8D27B88683523", "hash_pesha1": "6C3E743EB1443AB745907D20469355FABD609AA6", "hash_pe256": "DAE95761C9CD93CCB49588F0A8397319D6A7B0E5F0FD8A5A008E7BC177710147", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Performance Analyzer Power Transition Performance Testing Utility", "meta_original_filename": "xbootmgr.exe", "meta_product_name": "Microsoft Windows Performance Analyzer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " 2019 Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8f4b6fe4bebb2451fa346f56021619cb856aa94efa9d50c059efe9f52be033cf/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ], "runtime_window_title": "Microsoft Windows Performance Analyzer" }, "xbootmgrsleep.exe-6F9935DBC3C306D547F755FF0316C2C6": { "file_name": "xbootmgrsleep.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe", "hash_md5": "6F9935DBC3C306D547F755FF0316C2C6", "hash_sha1": "08AB33C7819EB9A97D91E5A124B5FCE170E7D242", "hash_sha256": "4C384D9306AD151E56F55BA41220C4D709F61A589EE19C322D91A17A2632B218", "hash_sha384": "41FAE1B049E77524ED3F2B83362C60BFCB8438E005C381AC1F9FA075D0418C04FBE121A39CBFF64D39CD7ECF5110D7B2", "hash_sha512": "DD2F23E4CEF2B34E5B9B8A0C8BC00527906B91349679758B896CD99FF696683B540491D90E00EE54BFDF45A3B7BD2D14B8BB2C0EFAD8258E50D292ACC08C54D3", "hash_ssdeep": "384:TeyCc139V4iV+BYRuEf+iL7+7jluzK7bwlJgJiehWbSXmWDsgWvwGyD4ElNA8:BCc1tjVIYRuEn7+/YXgJcbcLs99E", "hash_imp": "DE24CDF4C213B780DF02B3249F17314B", "hash_pesha1": "C6E45806B7F7048704140F3C9D6F089E1EB9D164", "hash_pe256": "148F84E8F5792C0EF51F56AA370FB0701D8BADC32C11FFE234862C8F09F01C82", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Performance Analyzer Power Transition Performance Testing Utility Helper", "meta_original_filename": "xbootmgrSleep.exe", "meta_product_name": "Microsoft Windows Performance Analyzer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " 2019 Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4c384d9306ad151e56f55ba41220c4d709f61a589ee19c322d91a17a2632b218/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHELL32.dll" ], "runtime_window_title": "XBootMgrSleep" }, "xperf.exe-FB0EF601FC6C1DB43AFA8DCBA365CA52": { "file_name": "xperf.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xperf.exe", "hash_md5": "FB0EF601FC6C1DB43AFA8DCBA365CA52", "hash_sha1": "CA0851B39B4F592CB114E463F2B37E6ED1C6F290", "hash_sha256": "56DCEA57BBE52BA5155C282D91AC287779A547C641F31756EF2B2ABD5DA0DDE4", "hash_sha384": "D86874D46118F389C9D71911974843022E1497643884EDFA2E1FD21FD0F594B34AC399BB467498B4FAB853F389B69B5A", "hash_sha512": "0F89415689658F42CBEF20B9147B655BB285FD8FDAE1001BAE2A22C6D1B82911B3648A2F4BB85FB6B6907B98CF2F9121E21412CCC90F6222425EE5D7F8E2BD2D", "hash_ssdeep": "6144:qQPXika9sPh0JzSfbHWEO2dNnSnTFlS+j0pZr:qQPyk3h0JzQ5OOQn/", "hash_imp": "93678734E2455F0CE95AF69EB0EF6082", "hash_pesha1": "FB92332EF71D8C7DCE842597A9E8855557DEF26D", "hash_pe256": "ACD66B0FB5255BB1EEDC4C3D7A312DE45363D45553DE075E3F8030003E38617A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Performance Analyzer Command Line", "meta_original_filename": "xperf.exe", "meta_product_name": "Microsoft Windows Performance Analyzer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " 2019 Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/56dcea57bbe52ba5155c282d91ac287779a547c641f31756ef2b2abd5da0dde4/detection", "error": "xperf: error: --help: The parameter is incorrect. (0x80070057).\r\n\r\n Microsoft (R) Windows (R) Performance Analyzer Version 10.0.19041\r\n Performance Analyzer Command Line\r\n Copyright (c) 2019 Microsoft Corporation. All rights reserved.\r\n\r\n Usage: xperf options ... \r\n\r\n\txperf -help start for logger start options\r\n\txperf -help providers for known tracing flags\r\n\txperf -help stackwalk for stack walking options\r\n\txperf -help stop for logger stop options\r\n\txperf -help merge for merge multiple trace files\r\n\txperf -help processing for trace processing options\r\n\txperf -help symbols for symbol decoding configuration\r\n\txperf -help query for query options\r\n\txperf -help mark for mark and mark-flush\r\n\txperf -help format for time and timespan formats on the command line\r\n\txperf -help profiles for profile options\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xperf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "GPUView.exe-9D77FC089BCC8BF6E86F0777C2C51EBE": { "file_name": "GPUView.exe", "file_path": "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\gpuview\\GPUView.exe", "hash_md5": "9D77FC089BCC8BF6E86F0777C2C51EBE", "hash_sha1": "550BB7384FAA098645DC4E884AFEF6D3DD07F170", "hash_sha256": "5E670B068595EA184306C827CF99D1A100207516BF8BCFE465ED90D88EADBE25", "hash_sha384": "90A483B0D1F43A56F859F09D04E4FC8787C45F82EAFF71DCD6C0AB29973B6507E66CB3C0CBF47C3144CEE02BD28C8CB8", "hash_sha512": "DABF979F189BC3567B00E214A3FAF10FAA408CCEB41E7AED08BCB34CD3DB7B341BE8D1B6DD0B6ACC2242B394905DE8FFC1EDEEC671FE3C56CC9C924BAB6EC413", "hash_ssdeep": "6144:RhasssapJMVo2Rqr5bObUrOGNwWu0OJly8xxSHalScVx5YjUhcxhuS0lu+0EutvA:RhasNoqqMaOGRCxecVmUS4u+hof0R", "hash_imp": "6C45A4068266C98F0ABEFC78FE74A087", "hash_pesha1": "3DE9D4C6A0DC4B66EEA47B3414265579D634F83A", "hash_pe256": "563BD48A5090164ABA9B589A5F97425D1EB25242FF8C60DCF83555820A0D52DE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002CF6D2CC57CAA65A6D80000000002CF", "signature_thumbprint": "1A221B3B4FEF088B17BA6704FD088DF192D9E0EF", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "GPU ETW Event Viewer", "meta_original_filename": "GPUView.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5e670b068595ea184306c827cf99d1a100207516bf8bcfe465ed90d88eadbe25/detection", "children": "hh.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Users\\user\\Log.txt": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\gpuview\\GPUView.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "al.exe-79C91DEF06DC6908C678D7A65456A94E": { "file_name": "al.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\al.exe", "hash_md5": "79C91DEF06DC6908C678D7A65456A94E", "hash_sha1": "B73531EDFBD2579A05469DA99FC9F3C11D3BF42A", "hash_sha256": "90FB42A601E445AC485F30CCED18D3B162B69D7EA1992E26ACC143DDFEF705BE", "hash_sha384": "0405127C3215FBA51E60731C601C6484B39BF0E76969B7309583BDC6E2AC8D6EC4FE26D60A3C151777F8F7B25BF99C22", "hash_sha512": "8E23AE3238E970FE09F99A01AE3081BEE572389BB29756C5EF30C91D5D1A065F7E750C342651A85A472228B8B7AAF144E7FE14794B70F861DDF086004BF3CD84", "hash_ssdeep": "3072:UmafYbYu+88ka0V+m3HF45wwM5oRs8GMMBiimvUWYdWeVHZ9rmlVScOgNghUcfkE:omHsm3leoTxBiiXWJ85lmlscO4gduzif", "hash_imp": "C440C2B7D05FF946D2A4C8F8B6C0DCAE", "hash_pesha1": "64C5632E7E7C088E787030DD411FC3963C23DCB3", "hash_pe256": "DDBD8503A753D6E55248E350A7B5A749FCF9EE9E820A480D3A8632D0CA16DEAD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Assembly Linker command line tool", "meta_original_filename": "al.exe", "meta_product_name": "Microsoft .NET Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.8.4084.0 built by: NET48REL1", "meta_product_version": "14.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/90fb42a601e445ac485f30cced18d3b162b69d7ea1992e26acc143ddfef705be/detection", "output": "Microsoft (R) Assembly Linker version 14.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: al [options] [sources]\r\nOptions: ('/out' must be specified)\r\n\r\n /? or /help Display this usage message\r\n @<filename> Read response file for more options\r\n /algid:<id> Algorithm used to hash files (in hexadecimal)\r\n /base[address]:<addr> Base address for the library\r\n /bugreport:<filename> Create a 'Bug Report' file\r\n /comp[any]:<text> Company name\r\n /config[uration]:<text> Configuration string\r\n /copy[right]:<text> Copyright message\r\n /c[ulture]:<text> Supported culture\r\n /delay[sign][+|-] Delay sign this assembly\r\n /descr[iption]:<text> Description\r\n /e[vidence]:<filename> Security evidence file to embed\r\n /fileversion:<version> Optional Win32 version (overrides assembly version)\r\n /flags:<flags> Assembly flags (in hexadecimal)\r\n /fullpaths Display files using fully-qualified filenames\r\n /keyf[ile]:<filename> File containing key to sign the assembly\r\n /keyn[ame]:<text> Key container name of key to sign assembly\r\n /main:<method> Specifies the method name of the entry point\r\n /nologo Suppress the startup banner and copyright message\r\n /out:<filename> Output file name for the assembly manifest\r\n /platform:<text> Limit which platforms this code can run on; must be\r\n one of x86, Itanium, x64, arm, anycpu32bitpreferred,\r\n or anycpu (the default)\r\n /prod[uct]:<text> Product name\r\n /productv[ersion]:<text> Product version\r\n /subsystemversion:<version>\r\n Specifies the subsystem version for the assembly\r\n /t[arget]:lib[rary] Create a library\r\n /t[arget]:exe Create a console executable\r\n /t[arget]:win[exe] Create a Windows executable\r\n /t[arget]:appcontainerexe Create a Windows executable that runs on AppContainer\r\n /template:<filename> Specifies an assembly to get default options from\r\n /title:<text> Title\r\n /trade[mark]:<text> Trademark message\r\n /v[ersion]:<version> Version (use * to auto-generate remaining numbers)\r\n /win32icon:<filename> Use this icon for the output\r\n /win32res:<filename> Specifies the Win32 resource file\r\n\r\nSources: (at least one source input is required)\r\n <filename>[,<targetfile>] add file to assembly\r\n /embed[resource]:<filename>[,<name>[,Private]]\r\n embed the file as a resource in the assembly\r\n /link[resource]:<filename>[,<name>[,<targetfile>[,Private]]]\r\n link the file as a resource to the assembly\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\al.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "aspnet_intern.exe-2F639BC466E10AC0CF7260AAA82EFB70": { "file_name": "aspnet_intern.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\aspnet_intern.exe", "hash_md5": "2F639BC466E10AC0CF7260AAA82EFB70", "hash_sha1": "14D3F01A0425C8AAB3E2A187558C000ACBC3F376", "hash_sha256": "AA251111C007308805F3FE888298D52CA80DBE2D0C622C8FF5AD4B32BF38D573", "hash_sha384": "D3162EA04F355305959F80148CE07A85DD00380C583983B76A85E833C4E1A7527E54D4C5F2ECAA0A104ADB31B31CC141", "hash_sha512": "619F82ABBC3B12E6912AEEEEBDA4685EA315090971F95504631357E6E9ACD698A0379C309E5014CF3A335FF330E84159F905FD32238DFD84F5E8651679CF539E", "hash_ssdeep": "1536:oSVxegzJEgTb6MISFdrpgbAcoT1twP5kmr:oqMgz2gH6UFdr6bAcoTHwPpr", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "02F1A56AD7DD1F83FC3B2E61E54A7179AD9DDF02", "hash_pe256": "503EC558D8A28A5B875AD32A5CE113182DD97BAC84DAEB3EF338D9838A1FECC1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "aspnet_intern.exe", "meta_original_filename": "aspnet_intern.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "aspnet_intern.exe", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0", "meta_product_version": "4.8.4084.0", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/aa251111c007308805f3fe888298d52ca80dbe2d0c622c8ff5ad4b32bf38d573/detection", "output": "Microsoft (R) ASP.NET Intern version 4.8.4084.0\r\nUtility to analyze ASP.NET web applications and intern common .NET assemblies found in the Temporary ASP.NET Files directory.\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\naspnet_intern [-mode analyze|exec|clean|query] [-sourcedir <input source path>] [-interndir <output target interned path>] \r\n\r\n-? Display this help text.\r\n-mode analyze Analyze source directory for managed assemblies that can be\r\n interned for cross application sharing (default)\r\n-mode exec Perform interning of managed assemblies for cross\r\n application sharing\r\n-mode query Display information about shared assemblies in the intern\r\n directory\r\n-mode clean Deletes the intern directory and all symbolic links in the\r\n source directory pointing at files in the intern directory\r\n-sourcedir Source directory to scan for potential assembly interning\r\n candidates. Use either the Temporary ASP.NET Files\r\n directory location, or the location defined in the\r\n system.web/compilation/tempDirectory web.config attribute.\r\n-interndir The location where interned assemblies are stored for\r\n sharing across ASP.NET applications.\r\n-v Verbose output\r\n-bpc Bypass platform checks\r\n-minrefcount The minimum number of times an assembly was found in\r\n different locations for the assembly to be considered an\r\n interning candidate. (Default: 3)\r\n-whitelist Only allows interning of managed assemblies that are\r\n contained in this file. Value should be the full file path\r\n to a line delimited list of patterns which may contain a\r\n trailing asterisk which will turn the pattern into a prefix\r\n match. i.e. MyAssembly-1.*\r\n\r\nExamples:\r\n\r\n aspnet_intern -mode analyze -sourcedir \"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Temporary ASP.NET Files\"\r\n aspnet_intern -mode exec -sourcedir \"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Temporary ASP.NET Files\" -interndir C:\\ASPNETCommonAssemblies\r\n aspnet_intern -mode clean -sourcedir \"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Temporary ASP.NET Files\" -interndir C:\\ASPNETCommonAssemblies\r\n aspnet_intern -mode query -interndir C:\\ASPNETCommonAssemblies\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\aspnet_intern.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "aspnet_merge.exe-80365B1BCA6859C13EDDC66D6E323597": { "file_name": "aspnet_merge.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\aspnet_merge.exe", "hash_md5": "80365B1BCA6859C13EDDC66D6E323597", "hash_sha1": "2000C24EF20B90E09EB6BBFA1324CA1CC98D7C4E", "hash_sha256": "261FE302BE15AD77E6CAD8C15BF7DB7D326D493B1C790F234E2F652B58F362D1", "hash_sha384": "EBB78FB40E5C5719EECEA3420BB59A55F0880DF02EA0C4B3FC4BF4793EE6A7877B22855DBB165E336F5E74CE19E66BA0", "hash_sha512": "2577E21AB9E21D5691B81DF41697A90F3ADA9F05B74E27E7AE321F3BEAF111AA672B958FB8157F52C19F2CE426E8F17384E80AFE54F4F46D622A64A48B67069B", "hash_ssdeep": "12288:p346MW/wmJ47iF0H+zzPxF3dv2E/5RTw3xjI3Zh3UnfNKWK:i6Mavb/5RTc6Zh3Un1xK", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "8FD1395ED31174BC1FAE6B1740AB26FF7AA167B9", "hash_pe256": "A0A446836AADC46E80603FBD6F6C6B16638CC416FC0C0AC2F115772F644023A4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "aspnet_merge.exe", "meta_original_filename": "aspnet_merge.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "aspnet_merge.exe", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0", "meta_product_version": "4.8.4084.0", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/261fe302be15ad77e6cad8c15bf7db7d326d493b1c790f234e2f652b58f362d1/detection", "output": "Microsoft (R) ASP.NET Merge Tool version 4.8.4084.0.\nPlease note, new versions of the ASP.NET Merge Tool will no longer be included in the .NET SDK. Instead, new versions are now exclusively available via NuGet. For details, go to http://go.microsoft.com/fwlink/?LinkId=528812\r\nUtility to merge precompiled ASP.NET assemblies.\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: \r\naspnet_merge [-?] applicationPath [-keyfile filename [-delaysign]]\r\n [-o assemblyname | -w assemblyname | -prefix prefix]\r\n [-copyattrs [assemblyfile]] [-debug] [-nologo]\r\n [-errorstack] [-r] [-xmldocs] [-a] [-log logfile]\r\n [-allowattrs filename]\r\n\r\n-? Display this help text.\r\napplicationPath The physical path of the precompiled application.\r\n-keyfile The physical path to the strong name keyfile.\r\n-delaysign Delay sign the merged assemblies.\r\n-o Merge the entire application into a single assembly with\r\n the given name. This option cannot be combined with the\r\n -prefix or -w options.\r\n-w Merge the application Web files into a single assembly with\r\n the given name. This option cannot be combined with the -o\r\n or -prefix options.\r\n-prefix Prefix the merged assembly names with a specified string.\r\n This option cannot be combined with the -o or -w options.\r\n-copyattrs Copy the assembly level attributes from the input assembly.\r\n If input assembly is not specified, the main App_Code\r\n assembly will be used instead.\r\n-debug Preserve debug information in the merged assembly. The\r\n default is to remove debug information.\r\n-nologo Suppress the copyright message.\r\n-errorstack Show additional information that can help debug certain\r\n conditions.\r\n-r Remove the .compiled files for main code assembly. This\r\n option should not be used if your application contains any\r\n explicit type references to the main code assembly.\r\n-xmldocs Merge the xml documentation files associated with the input\r\n assemblies.\r\n-a Force merge the assemblies.\r\n-log Log messages to the specified file.\r\n-allowattrs Use the specified text file which contains attributes to\r\n exclude when checking consistency of attributes in merged\r\n assemblies. Each line of the file can either be a fully\r\n qualified name of an attribute, or a namespace. If a\r\n namespace is specified, all attributes found in the\r\n namespace will be excluded.\r\n\r\nExamples:\r\n\r\nThe following command merges the assemblies in the precompiled application\r\nunder C:\\MyTarget:\r\n aspnet_merge c:\\MyTarget\r\n\r\nThe following command merges the assemblies in C:\\MyTarget and signs the merged\r\nassemblies using the Keyfile.snk file:\r\n aspnet_merge -keyfile keyfile.snk c:\\MyTarget\r\n\r\nThe following command merges all Web application assemblies into a single\r\nassembly and names the resulting assembly MyApp.dll:\r\n aspnet_merge -o MyApp.dll c:\\MyTarget\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\aspnet_merge.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "AxImp.exe-5675F2BA7A604C31FDA0BD75488BEC85": { "file_name": "AxImp.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\AxImp.exe", "hash_md5": "5675F2BA7A604C31FDA0BD75488BEC85", "hash_sha1": "2E083C1E5306C18C8C24FE85B86E1EF43175F9B1", "hash_sha256": "B9B5F16CD710DC3EF4A2DA440AD5B5AC06385E1E7187F27C6CC1EFA631A18E4E", "hash_sha384": "B6EFAAAA57997752B0388A0022E0BFE52DD291038D4A3940C6492D14DD639A1BF1B0AF68B47966B22D6E2C25CB269429", "hash_sha512": "EF669C8B5874EFCAF9F4D55135D5B4E56459086C13A35539A86D3E78D9C6A429198B48BC940BB2B563DAFBEAEEC3BCD06380034596DFFF4519A2F860CBC5B01A", "hash_ssdeep": "768:R3IqpkgaFC9l/3SXwXdv5/Iyd6Iq8zf7bwG/5OEWtJqWA/bV8Aeuko:R/p2glPSX6dB/90aAG/5OEWtnSWAeul", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "9EB7540BAA96D2DE4E51E2C16C9AD6D79A61E7ED", "hash_pe256": "EE3F287F7DE0AD942523B7A4A37A90D8BF8D4D8B7BEEFC279D50AADC2F5B4336", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Framework Windows forms ActiveX conversion utility", "meta_original_filename": "AxImp.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/b9b5f16cd710dc3ef4a2da440ad5b5ac06385e1e7187f27c6cc1efa631a18e4e/detection", "output": "Microsoft (R) .NET ActiveX Control to Windows Forms Assembly Generator \n[Microsoft .Net Framework, Version 4.8.4084.0]\nCopyright (C) Microsoft Corporation. All rights reserved.\n\n\r\nGenerates a Windows Forms Control that wraps ActiveX controls defined in the given OcxName.\n\nUsage:\n AxImp OcxName [Options]\r\nOptions:\r\n /out:FileName File name of assembly to be produced\r\n /publickey:FileName File containing strong name public key\r\n /keyfile:FileName File containing strong name key pair\r\n /keycontainer:FileName Key container holding strong name key pair\r\n /delaysign Force strong name delay signing\r\n Used with /keyfile, /keycontainer or /publickey\r\n /source Generate C# source code for Windows Forms wrapper\r\n /rcw:FileName Assembly to use for Runtime Callable Wrapper rather than generating new one.\r\n Multiple instances of this option may be specified. Current directory is used\r\n as a root for relative paths\r\n /ignoreregisteredocx version of 'OcxName' library supplied on the command line is used to generate\r\n the Windows Forms wrapper, if this type library is registered on the machine,\r\n then the registered version is ignored\r\n /nologo Prevents AxImp from displaying logo\r\n /silent Prevents AxImp from displaying success message\r\n /verbose Displays extra information\r\n /? or /help Display this usage message\r\n", "error": "AxImp Error: Unknown option: /-help\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\AxImp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "clrver.exe-313292CC69013E2480ADB00CD7A5A083": { "file_name": "clrver.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\clrver.exe", "hash_md5": "313292CC69013E2480ADB00CD7A5A083", "hash_sha1": "7D28C3DA3E6F7D846D6E8DE433193780125FA984", "hash_sha256": "A27915C77B0EA675A15897D4A3DC49F7F08714275443BBC19A4718A96A648304", "hash_sha384": "660AD505DC112B6835554D8FD8B386BD22FC2CF7200D55FCFBE11B5F0786690E790AB083C0B9D642586539C3CD0147D9", "hash_sha512": "25F127FEA8ABA923F5C154ED318371559C7BAB134A9A16E019CCE8AA045C2BDB9CAE3B239592C5D18A500005E5F590E29EE3F6EF0B12F6FDDF34D6BD206D5691", "hash_ssdeep": "3072:/2BqqJxrivCQmt5uBny4vi0dWaUrfYlJL8:Qxrlt+Pj/N8", "hash_imp": "6FFF4A5E297C498BFD661630755C9748", "hash_pesha1": "0173AD84114BC09EE9CEE79FF9B013D5E7623FB4", "hash_pe256": "7E1A669B6CC42A42961CFA5903C32BDFF138020F2141CB4929F68C36239B4018", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays CLR Versions", "meta_original_filename": "clrver.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/a27915c77b0ea675a15897d4a3dc49f7f08714275443bbc19a4718a96a648304/detection", "output": "\r\nMicrosoft (R) .NET CLR Version Tool Version 4.8.4084.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUnknown option \"--help\".\r\nDisplays CLR versions\r\nUsage: clrver [-?|-all|<PID>]\r\n\r\n\t-all - Displays all processes on the machine using the CLR.\r\n\t<PID> - Displays the version of the CLR used by the specified process.\r\n\t-? - Displays this help screen.\r\n\r\nIf called with no options, clrver will display all installed CLR versions.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\clrver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "CorFlags.exe-01CC4822FE50180CC5D459A8B21E96D0": { "file_name": "CorFlags.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\CorFlags.exe", "hash_md5": "01CC4822FE50180CC5D459A8B21E96D0", "hash_sha1": "248A3172661ED65BD57F6D54EAC1F4FE6CFD2B7D", "hash_sha256": "98AF83697D51AD5E529AD3AACFEA5717851371D45A48EAA6BA2BAB013B142A02", "hash_sha384": "D5B0BF4B53BC886A1A2E73F14A096C058725441EABBDC15B3314AF9E45C7DD2E71E1D3D286D971B8CD357230ECFADAB7", "hash_sha512": "04AAEA187F540498F1C721236FB12B23C50DA1CD8F97B84C9D3E0FEF2AA5A4B4198A8C24FEF4D299C51CC869509B0F950A17F05C2423F0F4235FE83E1C5CF146", "hash_ssdeep": "3072:3ym0jmY04me/zHPcaV1E/IN0i8xzvXTBjpt/c8ptVLUrkh425s+HK2E:rK/E/e0i8xDJpJc8Zow4Ws+HKl", "hash_imp": "84EDC1DB7D6233B2DC3A9D515E266A8B", "hash_pesha1": "855413E51A5C6FC6CFFF42D2722C5A30C1C92AAC", "hash_pe256": "F48EC3B5F12E4F04819E400BFD4E54F7393DFC67B9268DBE322E01C7261067D2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Common Language Runtime Agnostic Assembly Conversion Tool", "meta_original_filename": "CorFlags.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/98af83697d51ad5e529ad3aacfea5717851371d45a48eaa6ba2bab013b142a02/detection", "output": "corflags : error CF000 : Invalid option (--help)\r\n\r\nMicrosoft (R) .NET Framework CorFlags Conversion Tool. Version 4.8.4084.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: Corflags.exe Assembly [options]\r\n\r\nIf no options are specified, the flags for the given image are displayed.\r\n\r\nOptions:\r\n/ILONLY+ /ILONLY- Sets/clears the ILONLY flag\r\n/32BITREQ+ /32BITREQ- Sets/clears the bits indicating 32-bit x86 only\r\n/32BITPREF+ /32BITPREF- Sets/clears the bits indicating 32-bit preferred\r\n/UpgradeCLRHeader Upgrade the CLR Header to version 2.5\r\n/RevertCLRHeader Revert the CLR Header to version 2.0\r\n/Force Force an assembly update even if the image is\r\n strong name signed.\r\n WARNING: Updating a strong name signed assembly\r\n will require the assembly to be resigned before\r\n it will execute properly.\r\n/nologo Prevents corflags from displaying logo\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\CorFlags.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "disco.exe-D4185B3B4A99F18237168473F3AA8AAA": { "file_name": "disco.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\disco.exe", "hash_md5": "D4185B3B4A99F18237168473F3AA8AAA", "hash_sha1": "E589ABC1C3EE4E96590B93848F24D30524176496", "hash_sha256": "3912EF15D9D554C05E129ADDC0810ED0BCC66FB8458EBF49A1185EB2B347BD98", "hash_sha384": "D42AF0964835D35F9BE06A314A6AA93F836F883D06C9E14932DAFF88174883478562D14E55CF5340B050F7F2F9853A64", "hash_sha512": "698DB53BFFF88C8730B16F62974E0214DD2BB387F1B93CA180AA240AEF057463F6DA0AC8DEA2409A4E17B6BBD024D7570BDD24B41B784FEF7309459F719C7B31", "hash_ssdeep": "1536:v36g84qP7Oi8hK8RgdJlb60Fnhh1BkVpKm97L:v36gKP7OiUWdrFTkVpK0L", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "16BD5364256D988B4B314F9E349F8B6BDAA75764", "hash_pe256": "DB0291B3DBC4FB3726ABC22AA4CF9196C632334D97F02A374613744D934F4243", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Frameworks Web Service Discovery Tool", "meta_original_filename": "disco.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/3912ef15d9d554c05e129addc0810ed0bcc66fb8458ebf49a1185eb2b347bd98/detection", "output": "Microsoft (R) Web Services Discovery Utility\r\n[Microsoft (R) .NET Framework, Version 4.8.4084.0]\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\ndisco.exe -\r\n Utility to discover the URLs of xml web services located on a web server\r\n and to save documents related to that xml web service on the local disk.\r\n The results.discomap, .wsdl and .xsd files produced by this tool can be\r\n used with wsdl.exe to produce web service clients and abstract web service\r\n servers using ASP.NET.\r\n\r\ndisco.exe <options> <url to discover>\r\n\r\n - OPTIONS -\r\n\r\n/nologo\r\n Suppresses the banner.\r\n\r\n/nosave\r\n Do not save the discovered documents or results to disk (for example\r\n wsdl, xsd and disco files). The default is to save the documents.\r\n\r\n/out:<directoryName>\r\n The output directory to save the discovered documents in. The default\r\n is the current directory. Short form is '/o:'.\r\n\r\n/username:<username>\r\n/password:<password>\r\n/domain:<domain>\r\n The credentials to use when the connecting to a server that\r\n requires authentication. Short forms are '/u:', '/p:' and '/d:'.\r\n\r\n/proxy:<url>\r\n The url of the proxy server to use for http requests.\r\n The default is to use the system proxy setting.\r\n\r\n/proxyusername:<username>\r\n/proxypassword:<password>\r\n/proxydomain:<domain>\r\n The credentials to use when the connecting to a proxy server that\r\n requires authentication. Short forms are '/pu:', '/pp:' and '/pd:'.\r\n", "error": "ERROR: help\r\n - Invalid URI: The format of the URI could not be determined.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\disco.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "FUSLOGVW.exe-2F24AA6680B6A754EAE611C6D6B464F2": { "file_name": "FUSLOGVW.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\FUSLOGVW.exe", "hash_md5": "2F24AA6680B6A754EAE611C6D6B464F2", "hash_sha1": "3E2F807F1D8CBF48110CA9E288DEEB784BB2C0B1", "hash_sha256": "2D9D36AC3355ACBBE17A3AFABC2889054ED69B7B1D688B195DB923BFBBA172B0", "hash_sha384": "AF3ADF550564EA09F1BAAD2E143972EEA4C90C1A12D92B8DF6830929259FA3F7E10D78D1B58C30E0139BFFD019459CB1", "hash_sha512": "DDA189AFC68D1518847EDE5A068B8ECE51A168E98834BFD57434DD2F795C3CFCBDBC63A391CEF791BC4298326C8EBC22A8D1A6D493B5413F84A751C5D0F946BB", "hash_ssdeep": "3072:HqRwMOWbOeA1wvRn/sA6K26Oj8H8v6TQR22ZkpN+9dS12B3ngk:N5cRn/fOj8HJUo2M+O2B3gk", "hash_imp": "F81BCB87D492797FA09BA236BB186BB6", "hash_pesha1": "5080B054874C3AB25F9CDB2DA13E0BB373DCB16C", "hash_pe256": "F104073C547806F6A58DB9D6E4551DAB10E0AD792E5CB5B9E918A4ADEFBFE07C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .Net Framework Assembly Binding Log Viewer", "meta_original_filename": "fuslogvw.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/2d9d36ac3355acbbe17a3afabc2889054ed69b7b1d688b195db923bfbba172b0/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_webcache_counters_{9B6AB5B3-91BC-4097-835C-EA2DEC95E9CC}_S-1-5-21-2047949552-857980807-821054962-504": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\FUSLOGVW.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Assembly Binding Log Viewer" }, "gacutil.exe-F2FE4DF74BD214EDDC1A658043828089": { "file_name": "gacutil.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\gacutil.exe", "hash_md5": "F2FE4DF74BD214EDDC1A658043828089", "hash_sha1": "1777FD3BBB4584ED820682659C495E0696CB6E91", "hash_sha256": "974226C200F8EDAD7F4F7444DF62D9E87D09DC631803A0EDB3723DC99C484920", "hash_sha384": "D5F3AC6E1CC32729AA113DAD3477E27FCEF35C576A929ADE82C6146A7327933CB2E7CE5E5FA2414F9529167BA2D8F714", "hash_sha512": "FD14428D59DDFBC9DAD7033BD4A654B0D73CE783DD88F493019489669CD994863C1D6319E509C075E80DD41D37BD3FA805A9FC950E2F4EFC69EDA46912DF0B9F", "hash_ssdeep": "3072:UzYgOrGCg5a3ADbR0d4/dA9lq/M8MjHIqfKqxFqNL9pf:VICg5AYR0SmnDRdFFaN", "hash_imp": "37EA4407B538D703D6E995D8E0E0DDE7", "hash_pesha1": "54C9861FD298BF7510D8F2A643DB49DC00E01142", "hash_pe256": "37FA9A94A5E6D6CB2352046B13558E17E07E4DA05529B42C74B251370A72B25B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) .NET Framework Global Assembly Cache Utility", "meta_original_filename": "gacutil.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/974226c200f8edad7f4f7444df62d9e87d09dc631803a0edb3723dc99c484920/detection", "output": "Microsoft (R) .NET Global Assembly Cache Utility. Version 4.0.30319.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: Gacutil <command> [ <options> ]\r\nCommands:\r\n /i <assembly_path> [ /r <...> ] [ /f ]\r\n Installs an assembly to the global assembly cache. <assembly_path> is the\r\n name of the file that contains the assembly manifest.\r\n Example: /i myDll.dll /r FILEPATH c:\\projects\\myapp.exe \"My App\"\r\n\r\n /il <assembly_path_list_file> [ /r <...> ] [ /f ]\r\n Installs one or more assemblies to the global assembly cache. \r\n <assembly_list_file> is the path to a text file that contains a list of \r\n assembly manifest file paths. Individual paths in the text file must be \r\n separated by CR/LF.\r\n Example: /il MyAssemblyList.txt /r FILEPATH c:\\projects\\myapp.exe \"My App\"\r\n myAssemblyList.txt content:\r\n myAsm1.dll\r\n myAsm2.dll\r\n\r\n /u <assembly_display_name> [ /r <...> ]\r\n Uninstalls an assembly. <assembly_name> is the name of the assembly\r\n (partial or fully qualified) to remove from the Global Assembly Cache.\r\n If a partial name is specified all matching assemblies will be uninstalled.\r\n Example:\r\n /u myDll,Version=1.1.0.0,Culture=en,PublicKeyToken=874e23ab874e23ab\r\n /r FILEPATH c:\\projects\\myapp.exe \"My App\"\r\n\r\n /uf <assembly_name>\r\n Forces uninstall of an assembly by removing all traced references.\r\n <assembly_name> is the full name of the assembly to remove.\r\n Assembly will be removed unless referenced by Windows Installer.\r\n !! Warning: use the /uf command with care as applications may fail to run !!\r\n Example: /uf myDll,Version=1.1.0.0,Culture=en,PublicKeyToken=874e23ab874e23ab\r\n\r\n /ul <assembly_display_name_list_file> [ /r <...> ]\r\n Uninstalls one or more assemblies from the global assembly cache. \r\n <assembly_list_file> is the path to a text file that contains a list of \r\n assembly names. Individual names in the text file must be \r\n separated by CR/LF.\r\n Example: /ul myAssemblyList.txt/r FILEPATH c:\\projects\\myapp.exe \"My App\"\r\n myAssemblyList.txt content:\r\n myDll,Version=1.1.0.0,Culture=en,PublicKeyToken=874e23ab874e23ab\r\n myDll2,Version=1.1.0.0,Culture=en,PublicKeyToken=874e23ab874e23ab\r\n\r\n /l [ <assembly_name> ]\r\n Lists the contents of the global assembly cache. When the optional \r\n <assembly_name> parameter is specified only matching assemblies are listed.\r\n\r\n /lr [ <assembly_name> ]\r\n Lists the contents of the global assembly cache including traced reference \r\n information. When the optional <assembly_name> parameter is specified only \r\n matching assemblies are listed.\r\n\r\n /cdl\r\n Deletes the contents of the download cache\r\n\r\n /ldl\r\n Lists the contents of the download cache\r\n\r\n /? \r\n Displays a detailed help screen\r\n\r\nOld command syntax:\r\n /if <assembly_path>\r\n equivalent to /i <assembly_path> /f\r\n\r\n /ir <assembly_path> <reference_scheme> <reference_id> <description>\r\n equivalent to /i <assembly_path> /r <...>\r\n\r\n /ur <assembly_name> <reference_scheme> <reference_id> <description>\r\n equivalent to /u <assembly_path> /r <...>\r\n\r\nOptions:\r\n /r <reference_scheme> <reference_id> <description>\r\n Specifies a traced reference to install (/i, /il) or uninstall (/u, /ul).\r\n <reference_scheme> is the type of the reference being added \r\n (UNINSTALL_KEY, FILEPATH or OPAQUE). \r\n <reference_id> is the identifier of the referencing application, \r\n depending on the <reference_scheme>\r\n <description> is a friendly description of the referencing application.\r\n Example: /r FILEPATH c:\\projects\\myapp.exe \"My App\"\r\n\r\n /f \r\n Forces reinstall of an assembly regardless of any existing assembly with \r\n the same assembly name.\r\n\r\n /nologo\r\n Suppresses display of the logo banner\r\n\r\n /silent\r\n Suppresses display of all output\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\gacutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ildasm.exe-6C579A66AE0B5BAA15C651E617977648": { "file_name": "ildasm.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\ildasm.exe", "hash_md5": "6C579A66AE0B5BAA15C651E617977648", "hash_sha1": "711334A1A639249CB178BE961FB4F49390650AF5", "hash_sha256": "B40202B260210EEB597773CD14EF0FCB0E8E03597700C76E2D4130BE898BF26A", "hash_sha384": "89CB570A151E65038854564E686F30F337231C1396923C3385F1970D9969FFCAED9184FE97BFC38442533A026BFBACD9", "hash_sha512": "710678188A31EAA5638850F3FFF3D901AF1A2EDCDFC7E33B308C7925F4EEEBCB6483E6EE71EF170734EEED39BCEA6C653E239B4FD0425A4B8B0043151DE67043", "hash_ssdeep": "12288:P5EERjTVCej+lvCu2Ko22K3ugPGXPNhUHuE:P5nVCejyAKpdPOXUHl", "hash_imp": "B0FED2BCFEB483968154D53F991D8343", "hash_pesha1": "B2BD704B0F3E22F18BB28627231DA762DC4F78BB", "hash_pe256": "D7DBCC936EA6F7C8F7E5030FC0E6FED307DDE596F980274727D50751DF02489C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework IL disassembler", "meta_original_filename": "ildasm.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/b40202b260210eeb597773cd14ef0fcb0e8e03597700c76e2d4130be898bf26a/detection", "children": "ildasm.exe", "output": "Microsoft (R) .NET Framework IL Disassembler. Version 4.8.4084.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nINVALID COMMAND LINE OPTION: --help\r\n\r\nUsage: ildasm [options] <file_name> [options]\r\n\r\nOptions for output redirection:\r\n /OUT=<file name> Direct output to file rather than to GUI.\r\n /TEXT Direct output to console window rather than to GUI.\r\n\r\n /HTML Output in HTML format (valid with /OUT option only).\r\n /RTF Output in rich text format (invalid with /TEXT option).\r\nOptions for GUI or file/console output (EXE and DLL files only):\r\n /BYTES Show actual bytes (in hex) as instruction comments.\r\n /RAWEH Show exception handling clauses in raw form.\r\n /TOKENS Show metadata tokens of classes and members.\r\n /SOURCE Show original source lines as comments.\r\n /LINENUM Include references to original source lines.\r\n /VISIBILITY=<vis>[+<vis>...] Only disassemble the items with specified\r\n visibility. (<vis> = PUB | PRI | FAM | ASM | FAA | FOA | PSC)\r\n /PUBONLY Only disassemble the public items (same as /VIS=PUB).\r\n /QUOTEALLNAMES Include all names into single quotes.\r\n /NOCA Suppress output of custom attributes.\r\n /CAVERBAL Output CA blobs in verbal form (default - in binary form).\r\n /NOBAR Suppress disassembly progress bar window pop-up.\r\n\r\nThe following options are valid for file/console output only:\r\nOptions for EXE and DLL files:\r\n /UTF8 Use UTF-8 encoding for output (default - ANSI).\r\n /UNICODE Use UNICODE encoding for output.\r\n /NOIL Suppress IL assembler code output.\r\n /FORWARD Use forward class declaration.\r\n /TYPELIST Output full list of types (to preserve type ordering in round-trip).\r\n /PROJECT Display .NET projection view if input is a .winmd file.\r\n /HEADERS Include file headers information in the output.\r\n /ITEM=<class>[::<method>[(<sig>)] Disassemble the specified item only\r\n\r\n /STATS Include statistics on the image.\r\n /CLASSLIST Include list of classes defined in the module.\r\n /ALL Combination of /HEADER,/BYTES,/STATS,/CLASSLIST,/TOKENS\r\n\r\nOptions for EXE,DLL,OBJ and LIB files:\r\n /METADATA[=<specifier>] Show MetaData, where <specifier> is:\r\n MDHEADER Show MetaData header information and sizes.\r\n HEX Show more things in hex as well as words.\r\n CSV Show the record counts and heap sizes.\r\n UNREX Show unresolved externals.\r\n SCHEMA Show the MetaData header and schema information.\r\n RAW Show the raw MetaData tables.\r\n HEAPS Show the raw heaps.\r\n VALIDATE Validate the consistency of the metadata.\r\nOptions for LIB files only:\r\n /OBJECTFILE=<obj_file_name> Show MetaData of a single object file in library\r\n\r\nOption key is '-' or '/', options are recognized by first 3 characters\r\n\r\nExample: ildasm /tok /byt myfile.exe /out=myfile.il\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\ildasm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll" ] }, "lc.exe-FD35B38452CEA103B00BDB059C20B3CC": { "file_name": "lc.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\lc.exe", "hash_md5": "FD35B38452CEA103B00BDB059C20B3CC", "hash_sha1": "B78FA57AF5168B4C22B5591EB4CAC926FFB89CDE", "hash_sha256": "F4FBF9BA0CA747ABC06E1334EF10735E47C0CE2D4A114115E4032F6D4A1C4EF0", "hash_sha384": "92A12CE5D700C1BFDBA505823FFA636F08A8ACE1B3FDE86438B2ED07CF2AE8347985D1D312C537DECCC1E78D64995A9D", "hash_sha512": "DBD6F9B03EB4607A42677E0AFF89A4E76793479706EB9650EFF18FA9D81E1FEE38AEA2A984FFE41829FF30DD0E25807CE8DF814C152413F05A5E54EC163C739C", "hash_ssdeep": "768:1vOvK7zwAUmudqda5W4E96Iq8clWdgtXqWMh8R5D1rO:1vcAE1LEdaQ4EUzKgHRPo", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "EB66081DE8219EFAE106F02C7CD1C2B14137919A", "hash_pe256": "0882DEF193396E2428DB14AD4B513342398FD6BD845431AC4FC4683A0FA7898B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Framework license compiler", "meta_original_filename": "lc.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f4fbf9ba0ca747abc06e1334ef10735e47c0ce2d4a114115e4032f6d4a1c4ef0/detection", "output": "Microsoft (R) .NET License Compiler \n[Microsoft .Net Framework, Version 4.8.4084.0]\nCopyright (C) Microsoft Corporation. All rights reserved.\n\n\r\nGenerates a .NET Licenses file and adds it to the manifest of the given assembly\nUsage:\n lc /target:TargetAssembly /complist:filename [/outdir:path] [/i:modules] [/v] [/nologo]\n\nOptions:\n /target:<str> Target assembly for the generated licenses file\n /complist:<str> Licensed component list file\n /outdir:<str> Output directory for the generated licenses file\n /i:<str> Specify modules to load\n /v Verbose output\n /nologo Suppress the display of the startup banner\n @<file> Accept options from a response file\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\lc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mage.exe-EF155322DF77221F060095F7D8B0C512": { "file_name": "mage.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\mage.exe", "hash_md5": "EF155322DF77221F060095F7D8B0C512", "hash_sha1": "5F03012A92C217DDD19E13739A93DABB91899F74", "hash_sha256": "80E6D3B3CAC3C35027845B222C31B10D57BABE7AF43FAF2358343C531348427D", "hash_sha384": "78521F0958675D9A71FF61158E2678A415F8B2F4E8A352F42B816B11504B0CCED13A365241C678461ADD1A8494EA001D", "hash_sha512": "70AAFE40A1F655D186D974C273DA577262760113D6551770B7FCC0AB6CA5CEAF3A5A97F7C8EFBD9C7ABADC184E24D4044FD31D47A3314192F4CAE8FE1994B7B7", "hash_ssdeep": "3072:uF4JUXgz5if9KWZ1tu6DEaYjeWIbiYjeWIbXXg2u2:uFzXgz5hq1XTYjeW7YjeWOQ/2", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "CA9B1C39D3D959F40831938B6DDF6A84CD080A94", "hash_pe256": "E2821DF1797F24D3EC2BB7D5C28CDE92D9D3022CB33100C1C54CAFB262ECA191", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Manifest Generation And Editing Tool", "meta_original_filename": "mage.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/80e6d3b3cac3c35027845b222c31b10d57babe7af43faf2358343c531348427d/detection", "output": "Commands\r\n -New <file_type>\t -n\r\n -Update <file_name>\t -u\r\n -Sign <file_name>\t -s\r\n -ClearApplicationCache\t -cc\r\n -Verify <manifest_file_name> -ver\r\n -Help [verbose]\t\t -h -?\r\n\r\n\r\n\r\nOptions\r\n -Algorithm <sha256RSA|sha1RSA> -a\r\n -AppCodeBase <path>\t -appc\r\n -AppManifest <path>\t -appm\r\n -CertFile <file_name>\t -cf\r\n -CertHash <hash> -ch\r\n -CryptoProvider <name> -csp\r\n -FromDirectory <path>\t -fd\r\n -IconFile <file_path> -if\r\n -IncludeProviderURL <true|false> -ip\r\n -Install <true|false> -i \r\n -KeyContainer <name> -kc\r\n -MinVersion <version #|none> -mv\r\n -Name <name>\t\t -n\r\n -Password <password>\t -pwd\r\n -Processor <processor>\t -p\r\n -ProviderURL <url> \t -pu\r\n -Publisher <publisher_name> -pub\r\n -SupportURL <support_url> -s\r\n -TimeStampUri <uri> -ti\r\n -ToFile\t<file_name>\t -t\r\n -TrustLevel <level>\t -tr\r\n -UseManifestForTrust <true|false> -um\r\n -Version <version>\t -v\r\n -WPFBrowserApp <true|false> -wpf\r\n\r\nUse \"mage -help verbose\" for more detailed help\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\mage.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mageui.exe-CE546105C7E0B3099CD1F885A89883A1": { "file_name": "mageui.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\mageui.exe", "hash_md5": "CE546105C7E0B3099CD1F885A89883A1", "hash_sha1": "A2FDBCAECE2E817B1A001D8BD5396C30A8A8B71D", "hash_sha256": "030E5D51199BD0E4A00F7C67DF4D00F1DF2CDA6E819D67192F07DBB3A524C77B", "hash_sha384": "4DF6C11070C1C3257C992F200494D854A70AB59E553D04D528574D140E49F4693BBF9AB872C0DC2EAAE7A7AB8F3B303F", "hash_sha512": "BD717EBB15DBF675A36084C3E4D7429A801EC9B9A971B47665C16B16B1A787A4F4E6B817057AA9C9D32E206EC7884EB1B1C7203CF66089B0CBB365C7D0A872CC", "hash_ssdeep": "6144:8hK1u0Q3gKw7iPvY5VPYd7xCd0b4raCIkfQOfyAZKi7xCd0b4raCIkfQOfyAZKB+:2Iu2T3QlW0sra+lW0sraN6R", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "28951BA5BA5077B924730374A232CC2A94761915", "hash_pe256": "704FAF47DD50AE04461922FF363421206F9BF0927F252546EAA4E84EB2A0F9E0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Manifest Generation And Editing Tool", "meta_original_filename": "mageui.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/030e5d51199bd0e4a00f7c67df4d00f1df2cda6e819d67192f07dbb3a524c77b/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_968": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Windows\\Theme2042523233": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Security\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Security.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.Build.Tasks.v4.0\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Microsoft.Build.Tasks.v4.0.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\3c8HWNDInterface:600534": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\mageui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "mgmtclassgen.exe-96A69600D8C9E9AB0AD3EB15CBD1DF1B": { "file_name": "mgmtclassgen.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\mgmtclassgen.exe", "hash_md5": "96A69600D8C9E9AB0AD3EB15CBD1DF1B", "hash_sha1": "4715989CEBDE3ED1FA554605DF33F1E5C7B216D9", "hash_sha256": "4E0E621EB4CDE9981097480F888FFDB215F82757440F3B0D4BA43E8600FE3813", "hash_sha384": "4A9CA776FBABF05B4E045A04AE1713D5F33AF9A5C2616F922C0636FA6BB91135494F42143CF72EEBA1FCD55EF18AA9D3", "hash_sha512": "F8D7397901C3164ED3E65176790311F68459FD0FB444C78F07A6E45DA8BA9B6D27EE46A3C40AA5950FDCF463D4031D9134AD2F045513369938274E2307EA71B0", "hash_ssdeep": "768:2WilFoFfbikdGL6Iq8GVfiagqWrQ8J5D1yK:XilFabJdGC7ia61Xb", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "2B56F0BA8B9FABBFE0C19025C5EFD7309B547560", "hash_pe256": "BB941CBE7F5A14750BEC3D2C815E25EF8EA3FB9578A0EB8C392C2DC9039B7A39", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Framework", "meta_original_filename": "MgmtClassGen.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/4e0e621eb4cde9981097480f888ffdb215f82757440f3b0d4ba43e8600fe3813/detection", "output": "Microsoft (R) .NET Framework Version 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\nMgmtClassGen <WMIClass> [options]\n\r\n\t /N <WMINamespace> \t \t WMI namespace containing the class. Defaults to root\\cimv2\r\n\t /O <ClassNamespace> \t \t .NET namespace in which the class is generated\r\n\t /L <Generated Language> \t One of the following. Defaulted to CS\r\n\t\t\t\t\t\t CS - CSharp(C#)\r\n\t\t\t\t\t\t VB - Visual Basic\r\n\t\t\t\t\t\t JS - JScript\r\n\t\t\t\t\t\t VJ - JSharp(J#)\r\n\t\t\t\t\t\t MC - Managed C++\n\r\n\t /P <FilePath> \t \t \t Output file path\r\n\t /M <Machine> \t \t \t Remote computer to connect. Defaults to the local machine\r\n\t /U <User> \t \t \t User name\r\n\t /PW <Password> \t \t Password\r\n\t /?\t\t \t \t Displays this help screen\n\r\nExample :\r\n\tMgmtclassGen Win32_Logicaldisk /L VB /N root\\cimv2 /P c:\\temp\\logicaldisk.vb\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\mgmtclassgen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mpgo.exe-8A0EA0E822DCC215A7FA453AE679327A": { "file_name": "mpgo.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\mpgo.exe", "hash_md5": "8A0EA0E822DCC215A7FA453AE679327A", "hash_sha1": "CEF3996139FABC132C62587CB27304B466FBE4D8", "hash_sha256": "33C11F4BA35CD4F04012134A4EECC730CD37D26163C3B84E7E76D0DC8FAE6EA0", "hash_sha384": "8A762C6739C113848C99D2F38EB60F0A0D136201BB5161B6992419DCC62C861ED69A261DAA375CDF7635B17892E49480", "hash_sha512": "5462F4329DA1CFEA6A9DB69E335B2DD9BFE9AEC4805126E99ED91B68B77D5DD4A202E7909FBBF0BE27EB387F88D0C527E2D0217C355AE696CB02691FDAE49FF7", "hash_ssdeep": "3072:BWZC6Kxje1uPOGpPBwrp1pIb1OGn3socs4kEsRne/FujeMm5pnWT+HJ1kz8V3b4b:Zzje1uPOGpPBC1asocs4k7n/mrbk", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "5E5C6DDAADC4A972B76D5C61492BDC518480D67D", "hash_pe256": "8C297F482FF60F6731F57D6850F1974380A091BD067EEC12A43587D8412470BB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "mpgo.exe", "meta_original_filename": "mpgo.exe", "meta_product_name": "Microsoft Visual Studio 12 CTP", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.8.4084.0 built by: NET48REL1", "meta_product_version": "14.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/33c11f4ba35cd4f04012134a4eecc730cd37d26163c3b84e7e76d0dc8fae6ea0/detection", "output": "Unknown command line argument '--help'\r\n\r\nMPGO {arguments}\r\nRequired arguments:\r\n-Scenario {scen}\r\n{scen}: The program, with arguments, to run to generate profile information.\r\n Include double-quotes around this to properly specify arguments. If\r\n there are spaces in individual arguments, 2 double-quotes are needed:\r\n -Scenario \"\"\"My App.exe\"\" \"\"Argument #1\"\" Arg#2\"\r\n OR\r\n-Scenario {package_name} -AppID {appid} -Timeout {seconds}\r\n{package_name}: The package name for the Windows Store app to run to generate\r\n profile information. If the package family name or package name is\r\n specified instead of the full package name MPGO will attempt to \r\n disambiguate by either prompting the user for a choice or by \r\n selecting the only package that satisfies the name provided.\r\n{appid}: The application ID of the application in the package specified by\r\n {package_name}. If * is specified MPGO will attempt to enumerate\r\n AppIDs in the package and fallback to {package_family_name}!App\r\n if it fails. If a string prefixed by ! is specified MPGO will\r\n concatenate the package family name with the argument provided.\r\n{seconds} The amount of time to allow the Windows Store app to run before\r\n termination. MUST be specified.\r\n OR\r\n-Import {dir}\r\n Migrate previously collected profile data from assemblies specified\r\n by either -AssemblyList or -AssemblyListFile found in {dir} into the \r\n location specified in -OutDir\r\n-OutDir {dir}\r\n{dir}: The directory to put optimized assemblies in. It is not recommended\r\n to be the location of the unoptimized assemblies, as the output files\r\n will be renamed with numeric suffixes.\r\n-AssemblyList {asmlist} OR -AssemblyListFile {file}\r\n{asmlist}:A list of assemblies (including .exe's & .dll's) to collect profile\r\n information about while running the scenario. It cannot include\r\n any assemblies that begin with a '-' character. Use an\r\n AssemblyListFile to specify that assembly (or rename your assembly).\r\n{file}: A text file containing the list of assemblies to collect profile\r\n information about, one assembly per line.\r\nBoth -AssemblyList and -AssemblyListFile can be used multiple times to build\r\nup the list of assemblies to profile.\r\n\r\nOptional arguments:\r\n-ExeConfig {file}\r\n{file}: The config file which your scenario uses to specify version and\r\n loader information. Check MSDN for more details.\r\n-64bit\r\n Instrument the assemblies for 64 bit. You MUST specify this, even\r\n if your assembly declares itself to be explicitly 64 bit.\r\n-Reset\r\n Reset the environment to make certain that an aborted profiling\r\n session has no impact to your assemblies, and then quit.\r\n This is done by default before & after a profiling session.\r\n-LeaveNativeImages\r\n Do not remove the instrumented native images after the scenario has\r\n been run. This is useful primarily when you're getting your scenario\r\n up & working. It will prevent the recreation of native images for\r\n subsequent runs of MPGO. When you are done, if you have passed this\r\n option, there may be orphaned native images in the cache, run MPGO\r\n with the same assembly list & scenario to remove them up.\r\n-RemoveNativeImages\r\n Cleanup from a run where -LeaveNativeImages was specified.\r\n This will ignore any arguments except -64bit, -AssemblyList[File] and\r\n exit after cleaning up all instrumented native images.\r\n-TimeOut {seconds}\r\n Collect profile data after {seconds} has elapsed. This will not\r\n terminate the scenario, just collect the profile at the timeout point.\r\n-f\r\n Force the inclusion of the profile data in a binary, even if it's\r\n signed. Please note that this will require that the binary be \r\n re-signed to work properly. If this is not done, the binary will\r\n fail to load & run.\r\n\r\nWARNING: Assemblies in the GAC cannot be updated with profile information. \r\n Please un-GAC assemblies before collecting profile data.\r\n Assemblies which are signed will not be updated with profile data,\r\n unless the -f option is specified. If -f is specified, binaries must\r\n be re-signed before they can be used.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\mpgo.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MSBuildTaskHost.exe-7FD0CCFF46ADD1EE51750C63A2D31EA6": { "file_name": "MSBuildTaskHost.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\MSBuildTaskHost.exe", "hash_md5": "7FD0CCFF46ADD1EE51750C63A2D31EA6", "hash_sha1": "C877C91A77EEC5582F5910C498359BCB75453C77", "hash_sha256": "02D0600983BF4EC6D1C48A1D5D80B4C3B63FBE9ECF11D236C2FC76E8D1F952F1", "hash_sha384": "DEE820D71D377A9A790562A1F8E6911685B3823E5D1B5544BCE34E1AD0DC89F60F2A99063E9325AD7F2C77A894BDA04E", "hash_sha512": "5E5265A45432B75E544562EAB461D5FB61313DE70AE9A282EA20FD4810731568E65D44498C12CBE5A323391153946B8B4E6843212B2248F3ADB56C1A7877E462", "hash_ssdeep": "3072:uPtaGqMdqIgVyu9FrJFYqGWAavcWO0MtN5UYLfZAIgKoPtUQRFi4aVii:uPtaGqfpFrJezBVtXCD5tUQbi59", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "761F63BC71C2B4A282AD8FFAED140981A3BA70F8", "hash_pe256": "071FEEEB983AF4F95D222B001F1B488B65FED0AC5E516D3F8F0943834F4B29B3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MSBuildTaskHost.exe", "meta_original_filename": "MSBuildTaskHost.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "MSBuildTaskHost.exe", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0", "meta_product_version": "4.8.4084.0", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/02d0600983bf4ec6d1c48a1d5d80b4c3b63fbe9ecf11d236c2fc76e8d1f952f1/detection", "children": "Fondue.exe", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\MSBuildTaskHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "PEVerify.exe-1478B8851D3CFDFADF062F5039689D55": { "file_name": "PEVerify.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\PEVerify.exe", "hash_md5": "1478B8851D3CFDFADF062F5039689D55", "hash_sha1": "0D82E2AAB97ECBC8AFE1F6B59A19EF1CAD1DCF9F", "hash_sha256": "3590509830F027E2AEC29CF6AD5264546ABE7EC680C79B812F31244C3CE3B700", "hash_sha384": "874A45C358CD8F126B4C3FDECD23931D232B1A117ADDB2D4524DC9111BA7051CD0F054DE3C27478745F8968570718B5D", "hash_sha512": "1601A1DCEEAA379DAE0D22D79531C336559A7859A6124A15C48E4C458084DAA7814782EB5131ED1394FCC141C7A862681983FF65929F38660C140E315E78F555", "hash_ssdeep": "6144:5Vv4KEAupAITg7dOk20LANia2WjohLklfFrG4vho:c+EAN7dQiA8a+LkltrxZo", "hash_imp": "0030A2B878F02AB35902EA691F76DE68", "hash_pesha1": "F0FDEC3F0A1918A8CD0FC61A61D2B78902ED90C3", "hash_pe256": "D6FF5E3501D4EEEE5E7919AD509BBC4A71998461EB8F7BF978BA50F4A0C7A64F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework PE, Metadata and IL Verification Tool", "meta_original_filename": "peverify.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/3590509830f027e2aec29cf6ad5264546abe7ec680c79b812f31244c3ce3b700/detection", "output": "Invalid option: --help \r\n\r\n\r\nMicrosoft (R) .NET Framework PE Verifier. Version 4.0.30319.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: PEverify <image file> [Options]\r\n\r\n\r\nOptions:\r\n/IL Verify only the PE structure and IL\r\n/MD Verify only the PE structure and MetaData\r\n/TRANSPARENT Verify only transparent methods\r\n/UNIQUE Disregard repeating error codes\r\n/HRESULT Display error codes in hex format\r\n/CLOCK Measure and report verification times\r\n/IGNORE=<hex.code>[,<hex.code>...] Ignore specified error codes\r\n/IGNORE=@<file name> Ignore error codes specified in <file name>\r\n/QUIET Display only file and Status. Do not display all errors.\r\n/VERBOSE Display additional info in IL verification error messages.\r\n/NOLOGO Don't display product version and copyright info.\r\n\r\nNote: By default, MD is verified and then if there were no errors, IL is\r\n verified. If /MD /IL options are specified, IL is verified even if\r\n there were MD verification errors.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\PEVerify.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ResGen.exe-2CE714E5B060916C5906D89652B1950A": { "file_name": "ResGen.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\ResGen.exe", "hash_md5": "2CE714E5B060916C5906D89652B1950A", "hash_sha1": "2C5CFD46A12CE04C6FE221E81FF18B49AEA39386", "hash_sha256": "2A6F7E904A822302C7D659EC976E897DFF8BCC7F3643DE877C6F87CA9B0A5DF9", "hash_sha384": "DBF38279D1EB8AC43DC969B36421BB128DE4A1C5AC1D1E99D3CF5A912DE39E90967404569A3B86DEC053CEABD560298E", "hash_sha512": "2296DBE9C10DC63CC55801A0FFDC22BA9E6514EE78FD447FB6E31A4E58FBBDDAA01A4F4AC064853482F888DF7915B10D82A45E4C3C388410F3053034ED1DF166", "hash_ssdeep": "1536:AKR6BqOrMJ0OjEirbeMlGQddeXHsYendvLHdjJXu6HV/EgLsqmXitf8TLCnffbe8:e+DEglG+deX2ndD1JeqtEg4qmXitf8TJ", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "845A7B3D5CC651723B548FBEE64AA4FC84D1D0EC", "hash_pe256": "6C75F0215DDF05C2334AAF7E2C501180FA6E0190D463F3227F15D4C748E4065C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework Resource Generator", "meta_original_filename": "ResGen.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/2a6f7e904a822302c7d659ec976e897dff8bcc7f3643de877c6f87ca9b0a5df9/detection", "output": "Microsoft (R) .NET Resource Generator \r\n[Microsoft .Net Framework, Version 4.8.4084.0]\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage:\r\n ResGen inputFile.ext [outputFile.ext] [/str:lang[,namespace[,class[,file]]]]\r\n ResGen [options] /compile inputFile1.ext[,outputFile1.resources] [...]\r\n ResGen inputFile.ext2 [outputDirectory]\r\nWhere .ext is .resX, .restext, .txt or .resources\r\nand .ext2 is .resources.dll, .dll or .exe. outputDirectory must already exist.\r\nResources will be extracted under outputDirectory in resW format.\r\n\r\nConverts files from one resource format to another. If the output\r\nfilename is not specified, inputFile.resources will be used.\r\nOptions:\r\n/compile Converts a list of resource files from one format to another\r\n in one bulk operation. By default, it converts into .resources\r\n files, using inputFile[i].resources for the output file name.\r\n/str:<language>[,<namespace>[,<class name>[,<file name>]]]] \r\n Creates a strongly-typed resource class in the specified\r\n programming language using CodeDOM. In order for the strongly\r\n typed resource class to work properly, the name of your output \r\n file without the .resources must match the\r\n [namespace.]classname of your strongly typed resource class.\r\n You may need to rename your output file before using it or\r\n embedding it into an assembly. \r\n/useSourcePath Use each source file's directory as the current directory\r\n for resolving relative file paths.\r\n/publicClass Create the strongly typed resource class as a public class.\r\n This option is ignored if the /str: option is not used.\r\n/r:<assembly> Load types from these assemblies. A ResX file with a previous\r\n version of a type will use the one in this assembly, when set.\r\n/define:A[,B] For #ifdef support in .ResText files, pass a comma-separated\r\n list of symbols. ResText files can use \"#ifdef A\" or \"#if !B\".\r\n/allowUntrustedFiles\r\n Process files that are in the Internet or Restricted zone or\r\n have the mark of the web on the file.\r\n\r\nMiscellaneous:\r\n@<file> Read response file for more options. At most one response file\r\n may be specified, and its entries must be line-separated.\r\n\r\n.restext & .txt files have this format:\r\n\r\n # Use # at the beginning of a line for a comment character.\r\n name=value\r\n more elaborate name=value\r\n\r\nExample response file contents: \r\n\r\n # Use # at the beginning of a line for a comment character.\r\n /useSourcePath\r\n /compile\r\n file1.resx,file1.resources\r\n file2.resx,file2.resources\r\n\r\n\r\nLanguage names valid for the /str:<language> option are:\r\nc#, cs, csharp, vb, vbs, visualbasic, vbscript, js, jscript, javascript, c++, mc, cpp\r\n", "children": [ "csrss.exe", "wininit.exe" ], "error": "ResGen : error RG0000: The file named \"help\" does not have a known extension. Managed resource files must end in .ResX, .restext, .txt, .resources, .resources.dll, .dll or .exe. Response files must end in .rsp and be specified as @respFile.rsp.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\ResGen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SecAnnotate.exe-FF00925E17A6F1F22349D064D70E720E": { "file_name": "SecAnnotate.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\SecAnnotate.exe", "hash_md5": "FF00925E17A6F1F22349D064D70E720E", "hash_sha1": "E83F4F4057EE2B6B4E48D126A014AA3575A8C9BA", "hash_sha256": "7E2E24188B61B19F872BA72DBF30D6D2324EE9E67F1AD95280DC873BC0E49F5B", "hash_sha384": "CEB32EBD24A137A1C1F829524FDC2A07D81481251F22A0CE5EFB85317D7F125FDE7743C214A72FED2DAB7702009B6281", "hash_sha512": "AB67473A71609D09D3D238590B53AE0AAFB38E5FECD38B4187AB182353E5B53FCF55000863CAC2A2581E8B1376F27BCFA07E5EEB64CD1F5BEC7C71563634536D", "hash_ssdeep": "12288:GArvHQvWXXAiY5+jJw3rrP18TZJwU4oEKDPbn7v8AqIsy7Fmx88hK+DLZ:GArOAhY59cLBLghIs/x88hK+DLZ", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "6175488458E724DA98D0250A17B65804EE3911E7", "hash_pe256": "B0C20B7EF2B896B21A9F8713BFC074AE382C60D14FD67E5C3AB9E973030302A1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework Security Transparency Annotator", "meta_original_filename": "SecAnnotate.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/7e2e24188b61b19f872ba72dbf30d6d2324ee9e67f1ad95280dc873bc0e49f5b/detection", "output": "Microsoft (R) .NET Framework Security Transparency Annotator 4.8.4084.0 \r\nCopyright (C) Microsoft Corporation. All rights reserved. \r\n \r\nUsage: SecAnnotate.exe [arguments] assemblies \r\n \r\nArguments: \r\n /a or /showstatistics \r\n Show statistics about the use of transparency in assemblies being analyzed. \r\n \r\n /d:directory or /referencedir:directory \r\n Include the specified directory when searching for dependent assemblies during annotation. \r\n \r\n /i or /includesignatures \r\n Include extended signature information in the annotation report file. \r\n \r\n /n or /nogac \r\n Suppress searching for referenced assemblies in the Global Assembly Cache. \r\n \r\n /o:output.xml or /out:output.xml \r\n Specifies the output annotation file. \r\n \r\n /p:maxpasses or /maximumpasses:maxpasses \r\n Specify the maximum number of annotation passes to make on assemblies before stopping the generation of new annotations. \r\n \r\n /q or /quiet \r\n Quiet mode: annotator will only output error information and no status messages. \r\n \r\n /r:assembly or /referenceassembly:assembly \r\n Include the specified assembly when resolving dependent assemblies during annotation. Reference assemblies are given priority over assemblies found in the reference path. \r\n \r\n /s:rulename or /suppressrule:rulename \r\n Suppress running a transparency rule on the input assemblies. \r\n \r\n /t or /forcetransparent \r\n Forces Annotator to treat all assemblies without any transparency annotations as if they were entirely transparent. \r\n \r\n /t:assembly or /forcetransparent:assembly \r\n Force the given assembly to be transparent, regardless of its current assembly level annotations. \r\n \r\n /v or /verify \r\n Verify that an assembly's annotations are correct only, do not attempt to make multiple passes to find all required annotations if the assembly does not verify. \r\n \r\n /x or /verbose \r\n Verbose output while annotating \r\n \r\n /y:directory or /symbolpath:directory \r\n Include the specified directory when searching for symbol files during annotation. \r\n \r\nArguments and assemblies may also be provided in a response file provided on the command line prefixed with an @. Each line in the response file should contain a single argument or assembly name. \r\n \r\n", "error": "Error running annotator: Assembly 'C:\\Users\\user\\help' could not be loaded. Check to ensure the file exists, and is a valid assembly. \r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\SecAnnotate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "sgen.exe-B29B877FAF928A9C74E8173CE7A5BD6F": { "file_name": "sgen.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\sgen.exe", "hash_md5": "B29B877FAF928A9C74E8173CE7A5BD6F", "hash_sha1": "2974CDCC3A2B5CFC4E4FFD42CE70AFC8E64CBA57", "hash_sha256": "609ACC482C1712F6AF8F7B1314CB7896BABBD1B1D65BD2A181951975FD76551B", "hash_sha384": "B87618CB9458E35EDC108A391ADEBF5CD518C2463B24D3CCB74A939E7BE16F877630C46E15301136A03C31054114F1AF", "hash_sha512": "5D9943B1EDD90A12F09C203C2DC71D1229BBF1C89C98D5F5B5AF2583DC362282A40554C4AC0F7B22E1EAF06D97962953A09BEC6465F325EB7B3A6CED02A7DF83", "hash_ssdeep": "768:rQC5IzfNUYPWpZbFdlHDqCZh6Iq8zNGO2QIIIIzGJaqWFnr8U/Tbf:95IzfumWpZxd52CZoKEOEJ4Kof", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "3A585E05E4F2898587EA14DDD62B8FE07B7858B3", "hash_pe256": "A44AC420A9B461118312B8453CC701EB2F4DD2FDB79A79324D7CA7555EF21268", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Frameworks Xml serialization assembly generation Tool", "meta_original_filename": "sgen.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/609acc482c1712f6af8f7b1314cb7896babbd1b1d65bd2a181951975fd76551b/detection", "output": "Microsoft (R) Xml Serialization support utility\r\n[Microsoft (R) .NET Framework, Version 4.8.4084.0]\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nGenerates serialization assemblies for use with XmlSerializer.\r\nThe utility allows developers to pre-generate assemblies for serialization\r\nand deploying the assemblies with the application.\r\n\r\nUsage: sgen.exe [[/assembly:<assembly name>] | [<assembly file location>]]\r\n [/type:] [/reference:] [/compiler:] [/debug] [/keep] [/nologo]\r\n [/silent] [/verbose]\r\n\r\n\r\n Developer options:\r\n /assembly: Assembly location or display name. Short form is '/a:'.\r\n /type: Generate code for serialization/deserialization of the\r\n specified type from the input assembly. Short form is '/t:'.\r\n /reference: Reference metadata from the specified assembly files.\r\n Short form is '/r:'.\r\n /compiler: Visual C# compiler options to use while compiling generated\r\n code. Short form is '/c'.\r\n For complete list of available options see c# compiler help.\r\n /proxytypes Generate serialization code only for proxy classes and web\r\n method parameters. Short form is '/p'.\r\n /debug Generate image which can be used under a debugger.\r\n Short form is '/d'.\r\n /keep Keep source code and compiler temp files. Short form is '/k'.\r\n /force Forces overwrite of a previously generated assembly.\r\n Short form is '/f'.\r\n /out: Output directory name (default: target assembly location).\r\n Short form is '/o:'.\r\n /parsableerrors\r\n Print errors in a format similar to those reported by\r\n compilers.\r\n\r\n Miscellaneous options:\r\n /? or /help Show this message\r\n /nologo Prevents displaying of logo. Short form is '/n'.\r\n /silent Prevents displaying of success messages. Short form is '/s'.\r\n /verbose Displays verbose output for debugging. Short form is '/v'.\r\n List types from the target assembly that cannot be serialized\r\n with XmlSerializer.\r\n", "error": "Warning: Ignoring invalid command line argument: '--help'.\r\nMissing required command-line argument: The name of the source assembly.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\sgen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "sn.exe-10FB62758B7366034D099D86CEB76895": { "file_name": "sn.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\sn.exe", "hash_md5": "10FB62758B7366034D099D86CEB76895", "hash_sha1": "30120DEE36C457522640A8673D3E5DF9883E4A11", "hash_sha256": "0B0BFB2EE32A2A58D0D7723EDBABF635145B349830110F0D696881CC35EF143F", "hash_sha384": "2268C10A32EE8FB771BA8E3E3565DAB3533663B8AF54685665A7ECC7158EC01C0D4777D81999FC1EE0876CB9DE497BE2", "hash_sha512": "674D20138560AF2ABAAA4A449BABF1FD2E57B9A48FE75B60B7B0CF371AE56AF11CE1DF112A031440C0A19A2B47FBCB6B66BA8645A1D55DF4C25250E72896EC1A", "hash_ssdeep": "3072:pK07uWd23HeYpMmOMu2h60YpnhTwQ/YmPwkZ093cvW9T+DYWbvsVk9XocssuTyhQ:NAOMg1fYYwgHDYWEkWyuCXhP+PMS", "hash_imp": "BA5D103CD67C13A261C3D965ED8D6252", "hash_pesha1": "ECBF28BB7F0B20F4C51E1D5181E8EAF74D35B95D", "hash_pe256": "E912BD107C3D7D225B44BEFE6AD748F0E303D3D4117E00A62E5B4AE9E5E9C5BC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Strong Name Utility", "meta_original_filename": "sn.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/0b0bfb2ee32a2a58d0d7723edbabf635145b349830110f0d696881cc35ef143f/detection", "output": "\r\nMicrosoft (R) .NET Framework Strong Name Utility Version 4.0.30319.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: sn [-q|-quiet] <option> [<parameters>]\r\n Options:\r\n -a identityPublicKeyFile identityKeyPairFile signaturePublicKeyFile\r\n Generate AssemblySignatureKeyAttribute data to migrate the identity key to the signature key from a file.\r\n -ac identityPublicKeyFile identityKeyPairContainer signaturePublicKeyFile\r\n Generate AssemblySignatureKeyAttribute data to migrate the identity key to the signature key from a key container.\r\n -c [<csp> [<provtype>] ] \r\n Set/reset the name of the CSP to use for MSCORSN operations.\r\n -d <container>\r\n Delete key container named <container>.\r\n -dg <assembly> <digest file> [-rehash]\r\n Compute the digest of an assembly, generating a digest file for signing by\r\n the -ds or -dsc commands.\r\n If -rehash is specified, modules are re-hashed before digest calulation\r\n -ds <digest file> <keyfile> [-ecma]\r\n Sign a digest file generated by the -dg command using the full key pair\r\n from the given key file.\r\n If -ecma is used, keyfile is treated as the real key for ECMA signing.\r\n -dsc <digest file> <container> [-ecma]\r\n Sign a digest filegenerated by the -dg command using the key in the\r\n specified key container.\r\n If -ecma is used, container is treated as the real key for ECMA signing.\r\n -di <digest file> <assembly>\r\n Insert the signature from the digest file signed by the -ds or -dsc\r\n commands into the assembly.\r\n -dh <digest file> <hash file>\r\n Extract the base64 encoded hash value from the digest file\r\n -du <signature file> <digest file>\r\n Update the signature in the digest file with a base64 encoded signature\r\n in a signature file. WARNING: using this operation may result in a digest\r\n file that contains an invalid signature for its corresponding assembly.\r\n -dd <digest file>\r\n Dump the digest file to the console\r\n -D <assembly1> <assembly2>\r\n Verify <assembly1> and <assembly2> differ only by signature.\r\n -e <assembly> <outfile>\r\n Extract public key from <assembly> into <outfile>.\r\n -i <infile> <container>\r\n Install key pair from <infile> into a key container named <container>.\r\n -k [<keysize>] <outfile>\r\n Generate a new key pair of the specified size and write it into <outfile>.\r\n -m [y|n]\r\n Enable (y), disable (n) or check (no parameter) whether key containers\r\n are machine specific (rather than user specific).\r\n -o <infile> [<outfile>]\r\n Convert public key in <infile> to text file <outfile> with comma separated\r\n list of decimal byte values.\r\n If <outfile> is omitted, text is copied to clipboard instead.\r\n -p <infile> <outfile> [<hashalg>]\r\n Extract public key from key pair in <infile> and export to <outfile>,\r\n embedding the specified hash algorithm (sha1|sha256|sha384|sha512).\r\n -pc <container> <outfile> [<hashalg>]\r\n Extract public key from key pair in <container> and export to <outfile>,\r\n embedding the specified hash algorithm (sha1|sha256|sha384|sha512).\r\n -Pb [y|n]\r\n Enable (y), disable (n) or check (no parameters) the CLR policy allowing\r\n trusted applications to bypass strong name signature verification on their\r\n assemblies.\r\n -q\r\n Quiet mode. This option must be first on the command line and will suppress\r\n any output other than error messages.\r\n -R[a] <assembly> <infile> [-ecma]\r\n Re-sign signed or partially signed assembly with the key pair in <infile>.\r\n If -Ra is used, hashes are recomputed for all files in the assembly.\r\n If -ecma is used, infile is treated as the real key for ECMA signing.\r\n -Rc[a] <assembly> <container> [-ecma]\r\n Re-sign signed or partially signed assembly with the key pair in the key\r\n container named <container>.\r\n If -Rca is used, hashes are recomputed for all files in the assembly.\r\n If -ecma is used, container is treated as the real key for ECMA signing.\r\n -Rh <assembly>\r\n Re-compute hashes for all files in the assembly.\r\n -t[p] <infile>\r\n Display token for public key in <infile> (together with the public key\r\n itself if -tp is used).\r\n -T[p] <assembly>\r\n Display token for public key of <assembly> (together with the public key\r\n itself if -Tp is used).\r\n -TS <assembly> <infile>\r\n Test-sign signed or partially signed assembly with the key pair in \r\n <infile>.\r\n -TSc <assembly> <container>\r\n Test-sign signed or partially signed assembly with the key pair in the key\r\n container named <container>.\r\n -v[f] <assembly> [{-ecmakey <keyfile> | -ecmacontainer <container>}]\r\n Verify <assembly> for strong name signature self consistency. If -vf is\r\n specified, force verification even if disabled in the registry.\r\n If -ecmakey is specified, keyfile is treated as the real ECMA key.\r\n If -ecmacontainer is specified, container is treated as the real ECMA key.\r\n -Vk <regfile> <assembly> [<userlist>] [<testkey>]\r\n Generate a registry script in <regfile> to register <assembly> for\r\n verification skipping (with an optional, comma separated list of usernames\r\n for which this will take effect and an optional test public key in\r\n <testkey>). <assembly> can be specified as * to indicate all assemblies or\r\n *,<public key token> to indicate that all assemblies with the given public\r\n key token. Public key tokens should be specified as a string of hex digits.\r\n -Vl\r\n List current settings for strong name verification on this machine.\r\n -Vr <assembly> [<userlist>] [<infile>]\r\n Register <assembly> for verification skipping (with an optional, comma\r\n separated list of usernames for which this will take effect and an\r\n optional test public key in <infile>).\r\n <assembly> can be specified as * to indicate all assemblies or *,<public key token> to\r\n indicate that all assemblies with the given public key token. Public key\r\n tokens should be specified as a string of hex digits.\r\n -Vu <assembly>\r\n Unregister <assembly> for verification skipping. The same rules for\r\n <assembly> naming are followed as for -Vr.\r\n -Vx\r\n Remove all verification skipping entries.\r\n -?\r\n -h\r\n Displays this help text.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\sn.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SqlMetal.exe-D7E0F02D6643944C773D1A6D94D77BF8": { "file_name": "SqlMetal.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\SqlMetal.exe", "hash_md5": "D7E0F02D6643944C773D1A6D94D77BF8", "hash_sha1": "136B3C28372B312BEF2072AD2C6E4F4BF5E66668", "hash_sha256": "B0974E15DED88CA5A0342CC1E2E3D97FCCC596B75A39C6D31F8D9BFAAD10F8B5", "hash_sha384": "FEB70C75E82A12D3A1107F9E6D96C2B7986F85CA687F8E80E6C323A269DA6C4B88FAE33A048012581B3989B8765DA19E", "hash_sha512": "354708C6FE28BD516F85CAC4175A17874C7C8241C6526743875201B17ABC41AE38FF647F3DE6BA4E50F497E0EA657E2003B75555AA5CF0B004C1F4F22E06D420", "hash_ssdeep": "6144:ByuefGT5rk1z/Q0BQMUQY28b30A7ur0WpG:OfG9rECZQY70AGY", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "2F236548A13548A7E7963B3EECF7C187347B930B", "hash_pe256": "2383839B3C5DC94E2EF482F25EDE2405613E26E0A1A139BEE92539F76E843578", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SqlMetal.exe", "meta_original_filename": "SqlMetal.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "SqlMetal.exe", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0", "meta_product_version": "4.8.4084.0", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/b0974e15ded88ca5a0342cc1e2e3d97fccc596b75a39c6d31f8d9bfaad10f8b5/detection", "output": "Microsoft (R) Database Mapping Generator version 4.8.4084.0\nfor Microsoft (R) .NET Framework version 4.8\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nSqlMetal [options] [<input file>]\r\n\r\n Generates code and mapping for the LINQ to SQL component of the .NET framework. SqlMetal can:\r\n - Generate source code and mapping attributes or a mapping file from a database.\r\n - Generate an intermediate dbml file for customization from the database.\r\n - Generate code and mapping attributes or mapping file from a dbml file.\r\n\r\nOptions:\r\n /server:<name> Database server name.\r\n /database:<name> Database catalog on server.\r\n /user:<name> Login user ID (default: use Windows Authentication).\r\n /password:<password> Login password (default: use Windows Authentication).\r\n /conn:<connection string> Database connection string. Cannot be used with /server, /database, /user or /password options.\r\n /timeout:<seconds> Timeout value to use when SqlMetal accesses the database (default: 0 which means infinite).\r\n\r\n /views Extract database views.\r\n /functions Extract database functions.\r\n /sprocs Extract stored procedures.\r\n\r\n /dbml[:file] Output as dbml. Cannot be used with /map option.\r\n /code[:file] Output as source code. Cannot be used with /dbml option.\r\n /map[:file] Generate mapping file, not attributes. Cannot be used with /dbml option.\r\n\r\n /language:<language> Language for source code: VB or C# (default: derived from extension on code file name).\r\n /namespace:<name> Namespace of generated code (default: no namespace).\r\n /context:<type> Name of data context class (default: derived from database name).\r\n /entitybase:<type> Base class of entity classes in the generated code (default: entities have no base class).\r\n /pluralize Automatically pluralize or singularize class and member names using English language rules.\r\n /serialization:<option> Generate serializable classes: None or Unidirectional (default: None).\r\n /provider:<type> Provider type: SQLCompact, SQL2000, SQL2005, or SQL2008. (default: provider is determined at run time).\r\n\r\n <input file> May be a SqlExpress mdf file, a SqlCE sdf file, or a dbml intermediate file.\r\n\r\nCreate code from SqlServer:\r\n SqlMetal /server:myserver /database:northwind /code:nwind.cs /namespace:nwind \r\n\r\nGenerate intermediate dbml file from SqlServer:\r\n SqlMetal /server:myserver /database:northwind /dbml:northwind.dbml /namespace:nwind\r\n\r\nGenerate code with external mapping from dbml:\r\n SqlMetal /code:nwind.cs /map:nwind.map northwind.dbml\r\n\r\nGenerate dbml from a SqlCE sdf file:\r\n SqlMetal /dbml:northwind.dbml northwind.sdf\r\n\r\nGenerate dbml from SqlExpress local server:\r\n SqlMetal /server:.\\sqlexpress /database:northwind /dbml:northwind.dbml\r\n\r\nGenerate dbml by using a connection string in the command line:\r\n SqlMetal /conn:\"server='myserver'; database='northwind'\" /dbml:northwind.dbml\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\SqlMetal.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "StoreAdm.exe-85B13A98346827385E170C43C6210B3C": { "file_name": "StoreAdm.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\StoreAdm.exe", "hash_md5": "85B13A98346827385E170C43C6210B3C", "hash_sha1": "61C1A887413783704156BFFEBA52417351031D31", "hash_sha256": "246561721BBDAA384EB618093785B56138348D89D42BEC3C44D2DC58A4E4A40F", "hash_sha384": "4EBA056FFB76536FB10E3D79DD87EB8831DADF62035AF49E7AF981131C66448038AD3141B5C979166D9EF55E48FB80A3", "hash_sha512": "3B3B8A3169A0D2A09CDF2BC5C2B8BB04FD70B705255687779064D930FFA5F0ADD56D2AF9065C764D844132F6194A5AA358890FBF36CCFCE5FA7FC726C57D3A9D", "hash_ssdeep": "384:iwPAmUthIeIvBwHK4dfFxvvIKKJ9Yl6dnPU3SERztmbqCJstdMardz/JikPZ+tPl:IgKHK4dnYp6Iq89+jCuIWqW6S9xQ8va", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "16430CFB21E5ECC1482773709E6FE5567237F37C", "hash_pe256": "41E77088C5A46F9D9EFF0A166D9EE6072C8C5FF64A7732C9CF952855D1E68258", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework Store Admin", "meta_original_filename": "storeadm.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/246561721bbdaa384eb618093785b56138348d89d42bec3c44d2dc58a4e4a40f/detection", "output": "Microsoft (R) .NET Framework Store Admin 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nUnknown Option --help\r\n\r\nUsage : StoreAdm [options]\r\noptions : [/LIST] [/REMOVE] [/ROAMING | /MACHINE] [/QUIET]\r\n/LIST : Displays the existing isolated storage for the current user.\r\n/REMOVE : Removes all existing isolated storage for the current user.\r\n/ROAMING : Select the roaming store.\r\n/QUIET : Only error messages will be output.\r\n/MACHINE : Select the machine store.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\StoreAdm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SvcConfigEditor.exe-F3F98CD1524F4C835C264CA3494F657A": { "file_name": "SvcConfigEditor.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\SvcConfigEditor.exe", "hash_md5": "F3F98CD1524F4C835C264CA3494F657A", "hash_sha1": "7D755ED8B37C4B3EEF50FEBEBD9D02A9A1B81AF0", "hash_sha256": "5C0B2BF4AD320EC0FA48C12BC546B04701C5A5DD196D953DF310402190EB853C", "hash_sha384": "4C49614538BE55B2EF46032087DC5FD6B01D2E53DEF2193223D37516D9E365D7803B2AA1BB266E8A8D83855D3FD2A913", "hash_sha512": "DE0A1E22E14E49BE97246377293B207B3823603208DEA753E2D855C6A2BF38344EA59A2A0540867BD9595F3C0B1A99328791F5F6D52B25C963AF96F0CCE0BDE0", "hash_ssdeep": "24576:YcMKecTmJMBo9Dob1pk6K8Vv0ne6xwTY22IOZMMauGDwoDTZvvRFJyWWt8Kki4ey:sU/BU0Q6K8Vv0ne6xwTY2MGDwqFgWkRU", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "B0D61783FD380AA5D035A14C28BBADBE133B7361", "hash_pe256": "4EA8F5CCA022D1C7F282DF2516255F299E397DDF8FE3B47DD0B810BC4B2A8CA3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SvcConfigEditor.exe", "meta_original_filename": "SvcConfigEditor.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/5c0b2bf4ad320ec0fa48c12bc546b04701c5a5dd196d953df310402190eb853c/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4756": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.ServiceModel\\v4.0_4.0.0.0__b77a5c561934e089\\System.ServiceModel.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.ServiceModel.Activities\\v4.0_4.0.0.0__31bf3856ad364e35\\System.ServiceModel.Activities.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.ServiceModel.Channels\\v4.0_4.0.0.0__31bf3856ad364e35\\System.ServiceModel.Channels.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.ServiceModel.Discovery\\v4.0_4.0.0.0__31bf3856ad364e35\\System.ServiceModel.Discovery.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.ServiceModel.Routing\\v4.0_4.0.0.0__31bf3856ad364e35\\System.ServiceModel.Routing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.WorkflowServices\\v4.0_4.0.0.0__31bf3856ad364e35\\System.WorkflowServices.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.IdentityModel\\v4.0_4.0.0.0__b77a5c561934e089\\System.IdentityModel.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.ServiceModel.Web\\v4.0_4.0.0.0__31bf3856ad364e35\\System.ServiceModel.Web.dll": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\1294HWNDInterface:230672": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\SvcConfigEditor.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ], "runtime_window_title": "Microsoft Service Configuration Editor" }, "SvcTraceViewer.exe-271F9F6A59595EF6625EA8B827EE21A2": { "file_name": "SvcTraceViewer.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\SvcTraceViewer.exe", "hash_md5": "271F9F6A59595EF6625EA8B827EE21A2", "hash_sha1": "E64584BFEBFF0BC69BADF447828E8FDDB89B9D02", "hash_sha256": "51D92A37E799E471F9E7F8D51C2854C59C7D2B2311DBA50517EB80D0C73B7215", "hash_sha384": "1306BCF009D3A06A31376B240254FD36EACBC9511FCDA98E4AA24CF97D7B2EFAC0C11ED913C9125783E8275C080F7FED", "hash_sha512": "0872B387613C033D72977FACF9DAF9222ECACFA20446399365C6E6FA0EE90D538C7BDB211AFCBFB5C87EE1536D47FEE75A51DE20CA6E6AB3A9FEB27F923A5712", "hash_ssdeep": "6144:NcPXzoiYYCO7HWz7qXkBGkDynzUZm8hWQuh+1ctPhEFTSYfS4ZnHzIYBWAAPY2cn:23S7qYDxmSvuhQohEFm/cu5xisC", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "7A4C2F3206152DD1F59366A16D89E92FCC860B8E", "hash_pe256": "48FF17C6516CB70FB69DB72651C26F081D4580A99BBC75854680B203AD641E4B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SvcTraceViewer.exe", "meta_original_filename": "SvcTraceViewer.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/51d92a37e799e471f9e7f8d51c2854c59c7d2b2311dba50517eb80d0c73b7215/detection", "runtime_window_title": "Microsoft Service Trace Viewer", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_6012": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\177cHWNDInterface:605f2": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\SvcTraceViewer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "SvcUtil.exe-0F32F1595A0169D195D9B2D85F6F9E7B": { "file_name": "SvcUtil.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\SvcUtil.exe", "hash_md5": "0F32F1595A0169D195D9B2D85F6F9E7B", "hash_sha1": "6C609906ABD4CF9230481C2AF4885CCBAA444563", "hash_sha256": "DA75BB271D3F0E6B15ABFF5D90AAC4EC93440733A68B69CA94A226F7276F168A", "hash_sha384": "EBBB4EAF50D1F59FBFD33B8E3A16E43F76B7F01AB320681DA8887CE7657A0B0F7A635F615F2DEC56E21467AB12E4811C", "hash_sha512": "9C78E4500A2CDB6224483C64AB097B174744E16EFA11EBCBCAF7FBC16C7AFD53BD37F518875212DF00415BE811BFC73DCA97444B3630B025FC5836CF2E16CABE", "hash_ssdeep": "3072:2ysdQTmv0xhhFwz/cHYePxMdU0xgQ8gJh2y64vlli7/qUH+Pz/tY/j2Ln:QCTJLwz/c4ePxInO2r", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "DDCCD46A1448D88872575209D4ECECDB71CDE167", "hash_pe256": "790A95D3CB3FD511D4897D1D6A0229025F1E195D6B90FA678AEB90F8330F8E1C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "svcutil.exe", "meta_original_filename": "svcutil.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/da75bb271d3f0e6b15abff5d90aac4ec93440733a68b69ca94a226f7276f168a/detection", "output": "Microsoft (R) Service Model Metadata Tool\r\n[Microsoft (R) Windows (R) Communication Foundation, Version 4.8.4084.0]\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUSES:\r\n\r\n - Generate code from running services or static metadata documents. \r\n - Export metadata documents from compiled code.\r\n - Validate compiled service code.\r\n - Download metadata documents from running services.\r\n - Pre-generate serialization code.\r\n\r\n\r\n -= COMMON OPTIONS =-\r\n\r\nOptions:\r\n\r\n /target:<output type> - The target output for the tool: code, metadata or xmlSerializer.\r\n /directory:<directory> - Directory to create files in (default: current directory) (Short Form: /d)\r\n\r\n /svcutilConfig:<configFile> - Custom configuration file to use in place of the app config file. This can be used to register system.serviceModel extensions without altering the tool's config file.\r\n /noLogo - Suppress the copyright and banner message.\r\n /help - Display command syntax and options for the tool. (Short Form: /?)\r\n\r\n\r\n\r\n -= CODE GENERATION =-\r\n\r\nDescription: svcutil.exe can generate code for service contracts, clients and data types from metadata documents. These metadata documents can be on disk or retrieved online. Online retrieval follows either the WS-Metadata Exchange protocol or the DISCO protocol.\r\n\r\nSyntax: svcutil.exe [/t:code] <metadataDocumentPath>* | <url>* | <epr>\r\n\r\n <metadataDocumentPath> - The path to a metadata document (wsdl or xsd). Standard command-line wildcards can be used in the file path.\r\n <url> - The URL to a service endpoint that provides metadata or to a metadata document hosted online. For more information on how these documents are retrieved see the Metadata Download section.\r\n <epr> - The path to an XML file that contains a WS-Addressing EndpointReference for a service endpoint that supports WS-Metadata Exchange. For more information see the Metadata Download section.\r\n\r\nOptions:\r\n\r\n /out:<file> - The filename for the generated code. Default: derived from the WSDL definition name, WSDL service name or targetNamespace of one of the schemas. (Short Form: /o)\r\n /config:<configFile> - The filename for the generated config file. Default: output.config\r\n /mergeConfig - Merge the generated config into an existing file instead of overwriting the existing file.\t\r\n /noConfig - Do not generate config\r\n /dataContractOnly - Generate code for Data Contract types only. Service Contract types will not be generated. (Short Form: /dconly)\r\n\r\n /language:<language> - The programming language to use for generating code. Provide either a language name registered in the machine.config file or provide the fully-qualified name of a class that inherits from System.CodeDom.Compiler.CodeDomProvider. Examples of language names to use are CS and VB. Default: C#. (Short Form: /l)\r\n /namespace:<string,string> - A mapping from a WSDL or XML Schema targetNamespace to a CLR namespace. Using the '*' for the targetNamespace maps all targetNamespaces without an explicit mapping to that CLR namespace. Default: derived from the target namespace of the schema document for Data Contracts. The default namespace is used for all other generated types. (Short Form: /n)\r\n\r\n /messageContract - Generate Message Contract types. (Short Form: /mc)\r\n /enableDataBinding - Implement the System.ComponentModel.INotifyPropertyChanged interface on all Data Contract types to enable data binding. (Short Form: /edb)\r\n /serializable - Generate classes marked with the Serializable Attribute. (Short Form: /s)\r\n /async - Generate both synchronous and begin/end asynchronous method signatures. Default: generate synchronous and task-based asynchronous method signatures. (Short Form: /a)\r\n /internal - Generate classes that are marked as internal. Default: generate public classes. (Short Form: /i)\r\n\r\n /reference:<file path> - Reference types in the specified assembly. When generating clients, use this option to specify assemblies that might contain types representing the metadata being imported. (Short Form: /r)\r\n /collectionType:<type> - A fully-qualified or assembly-qualified name of the type to use as a collection data type when code is generated from schemas. (Short Form: /ct)\r\n /excludeType:<type> - A fully-qualified or assembly-qualified type name to exclude from referenced contract types. (Short Form: /et)\r\n /noStdLib - Do not reference standard libraries. By default mscorlib.dll and system.servicemodel.dll are referenced.\r\n\r\n /serializer:Auto - Automatically select the serializer. This tries to use the Data Contract serializer and uses the XmlSerializer if that fails. (Short Form: /ser)\r\n /serializer:DataContractSerializer - Generate data types that use the Data Contract Serializer for serialization and deserialization\r\n /serializer:XmlSerializer - Generate data types that use the XmlSerializer for serialization and deserialization\r\n /importXmlTypes - Configure the Data Contract serializer to import non-Data Contract types as IXmlSerializable types.\r\n /useSerializerForFaults - This option specifies whether the serializer specified in the 'serializer' switch is used for fault contract types. DataContractSerializer is used for faults if this switch is not specified. (Short Form: /fault)\r\n\r\n /targetClientVersion:Version30 - Generate code that references functionality in .NET Framework assemblies 3.0 and before. Use this switch if you are generating code for clients that use .NET Framework version 3.0.(Short Form: /tcv)\r\n /targetClientVersion:Version35 - Generate code that references functionality in .NET Framework assemblies 3.5 and before. Use this switch if you are generating code for clients that use .NET Framework version 3.5.(Short Form: /tcv)\r\n /wrapped - Generated code will not unwrap \"parameters\" member of document-wrapped-literal messages.\r\n /serviceContract - Generate code for Service Contracts. Client class and configuration will not be generated. (Short Form: /sc)\r\n /syncOnly - Generate only synchronous method signature. Default: generate synchronous and task-based asynchronous method signatures.\r\n\r\n\r\n\r\n -= METADATA EXPORT =-\r\n\r\nDescription: svcutil.exe can export metadata for services, contracts and data types in compiled assemblies. To export metadata for a service, you must use the /serviceName option to indicate the service you would like to export. To export all Data Contract types within an assembly use the /dataContractOnly option. By default metadata is exported for all Service Contracts in the input assemblies.\r\n\r\nSyntax: svcutil.exe [/t:metadata] [/serviceName:<serviceConfigName>] [/dataContractOnly] <assemblyPath>*\r\n\r\n <assemblyPath> - The path to an assembly that contains services, contracts or Data Contract types to be exported. Standard command-line wildcards can be used to provide multiple files as input.\r\n\r\nOptions:\r\n\r\n /serviceName:<serviceConfigName> - The config name of a service to export. If this option is used, an executable assembly with an associated config file must be passed as input. Svcutil will search through all associated config files for the service configuration. If the config files contain any extension types, the assemblies containing these types must either be in the GAC or explicitly provided using the /r option.\r\n /reference:<file path> - Add the specified assembly to the set of assemblies used for resolving type references. If you are exporting or validating a service that uses 3rd-party extensions (Behaviors, Bindings and BindingElements) registered in config use this option to locate extension assemblies that are not in the GAC. (Short Form: /r)\r\n /dataContractOnly - Operate on Data Contract types only. Service Contracts will not be processed. (Short Form: /dconly)\r\n /excludeType:<type> - The fully-qualified or assembly-qualified name of a type to exclude from export. This option can be used when exporting metadata for a service or a set of service contracts to exclude types from being exported. This option cannot be used with the /dconly option. (Short Form: /et)\r\n\r\n\r\n\r\n -= SERVICE VALIDATION =-\r\n\r\nDescription: Validation is useful to detect errors in service implementations without hosting the service. You must use the /serviceName option to indicate the service you would like to validate.\r\n\r\nSyntax: svcutil.exe /validate /serviceName:<serviceConfigName> <assemblyPath>*\r\n\r\n <assemblyPath> - The path to an assembly containing service types to be validated. The assembly must have an associated config file to provide service configuration. Standard command-line wildcards can be used to provide multiple assemblies.\r\n\r\nOptions:\r\n\r\n /validate - Validate a service implementation. To validate a service, you must use the /serviceName option to indicate the service you would like to validate. If this option is used, an executable assembly with an associated config file must be passed as input. (Short Form: /v)\r\n /serviceName:<serviceConfigName> - The config name of a service to validate. To validate a service this option must be provided. Svcutil will search through the associated config files of all input assemblies for the service configuration. If the associated configuration file contain any extension types, the assemblies containing these types must either be in the GAC or explicitly provided using the /r option.\r\n /reference:<file path> - Add the specified assembly to the set of assemblies used for resolving type references. If you are exporting or validating a service that uses 3rd-party extensions (Behaviors, Bindings and BindingElements) registered in config use this option to locate extension assemblies that are not in the GAC. (Short Form: /r)\r\n /dataContractOnly - Operate on Data Contract types only. Service Contracts will not be processed. (Short Form: /dconly)\r\n /excludeType:<type> - The fully-qualified or assembly-qualified name of a service type to exclude from validation. (Short Form: /et)\r\n\r\n\r\n\r\n -= METADATA DOWNLOAD =-\r\n\r\nDescription: svcutil.exe can be used to download metadata from running services and save the metadata to local files. To download metadata, you must explicitly specify the /t:metadata option. Otherwise, client code will be generated. For http and https URL schemes svcutil.exe will try to retrieve metadata using WS-Metadata Exchange and DISCO. For all other URL schemes svcutil.exe will only try WS-Metadata Exchange. By default, svcutil.exe uses the bindings defined in the System.ServiceModel.Description.MetadataExchangeBindings class. To configure the binding used for WS-Metadata Exchange you must define a client endpoint in config that uses the IMetadataExchange contract. This can be defined either in svcutil.exe's config file or in another config file specified using the /svcutilConfig option.\r\n\r\nSyntax: svcutil.exe /t:metadata <url>* | <epr>\r\n\r\n <url> - The URL to a service endpoint that provides metadata or an URL that points to a metadata document hosted online. \r\n <epr> - The path to an XML file that contains a WS-Addressing EndpointReference for a service endpoint that supports WS-Metadata Exchange.\r\n\r\n\r\n\r\n -= XMLSERIALIZER TYPE GENERATION =-\r\n\r\nDescription: svcutil.exe can pre-generate C# serialization code that is required for types that can be serialized using the XmlSerializer. svcutil.exe will only generate code for types used by Service Contracts found in the input assemblies.\r\n\r\nSyntax: svcutil.exe /t:xmlSerializer <assemblyPath>*\r\n\r\n <assemblyPath> - The path to an assembly containing Service Contract types. Serialization types will be generated for all Xml Serializable types in each contract\r\n\r\nOptions:\r\n\r\n /reference:<file path> - Add the specified assembly to the set of assemblies used for resolving type references. (Short Form: /r)\r\n /excludeType:<type> - Fully-qualified or assembly-qualified type name to exclude from export or validation. This option can be used when exporting metadata for a service or a set of service contracts to exclude types from being exported. This option cannot be used with the /dataContractOnly option. (Short Form: /et)\r\n /out:<file> - Filename for the generated code. This option will be ignored when multiple assemblies are passed as input to the tool. Default: derived from the assembly name. (Short Form: /o)\r\n\r\n\r\n\r\n -= EXAMPLES =-\r\n\r\n svcutil http://service/metadataEndpoint\r\n - Generate client code from a running service or online metadata documents.\r\n\r\n svcutil *.wsdl *.xsd /language:C#\r\n - Generate client code from local metadata documents.\r\n\r\n svcutil /dconly *.xsd /language:VB\r\n - Generate Data Contract types in VisualBasic from local schema documents.\r\n\r\n svcutil /t:metadata http://service/metadataEndpoint\r\n - Download metadata documents from running services\r\n\r\n svcutil myAssembly.dll\r\n - Generate metadata documents for Service Contracts and associated types in an assembly\r\n\r\n svcutil myServiceHost.exe /serviceName:myServiceName \r\n - Generate metadata documents for a service, and all associated Service Contracts and data types in an assembly\r\n\r\n svcutil myServiceHost.exe /dconly \r\n - Generate metadata documents for data types in an assembly\r\n\r\n svcutil /validate /serviceName:myServiceName myServiceHost.exe\r\n - Verify service hosting\r\n\r\n svcutil /t:xmlserializer myContractLibrary.exe\r\n - Generate serialization types for XmlSerializer types used by any Service Contracts in the assembly\r\n\r\n\r\n\r\n", "error": "Error: Cannot read help.\r\n\r\n Cannot load file C:\\Users\\user\\help as an Assembly. Check the FusionLogs for more Information.\r\n\r\n Could not load file or assembly 'file:///C:\\Users\\user\\help' or one of its dependencies. The module was expected to contain an assembly manifest.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\SvcUtil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "TlbExp.exe-3E5110E620F7742CBBE7DB9852D3483E": { "file_name": "TlbExp.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\TlbExp.exe", "hash_md5": "3E5110E620F7742CBBE7DB9852D3483E", "hash_sha1": "4C6B88D7F3E1050839E3E70CCA3E07F08C1ADC07", "hash_sha256": "F1947472576EDE7BD8C1CBF2C047BACD0974697DCCB8E9FD257670D0C16F1307", "hash_sha384": "D430A7FA0929E4BBBF1BC803F014CB7870F8A0BD3C7CFA72A290DC990F309C95B6B175A62B5D9502C6B28D8844F7903A", "hash_sha512": "91CD3655CC35C8384E6B00E619FCAFFE4B16AE9227D272E065E78CDEA8EE24F195322A7B48FE0347AACA4AA24AC496E4AAE9934BF8EBA102323EEEA8FE4FF807", "hash_ssdeep": "1536:Fc2wX1cQKRNBx6IqvdG5xb2Bf0VDSqgD2LJ6lXyAqjZH:NwyjRNBgIqvdG5xb2BfUDSFD2LJ6lXyD", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "CAD386F0BF542CCFC2FF44A2CCDFF245C43E1156", "hash_pe256": "A74FE04AB214E52ECE4C2782EF394156C0C00DC13E8DC183979FA45327E21845", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Assembly to Type Library Converter", "meta_original_filename": "TlbExp.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/f1947472576ede7bd8c1cbf2c047bacd0974697dccb8e9fd257670d0c16f1307/detection", "output": "Microsoft (R) .NET Framework Assembly to Type Library Converter 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nSyntax: TlbExp AssemblyName [Options]\r\nOptions:\r\n /out:FileName File name of type library to be produced\r\n /tlbreference:TypeLibrary Type library used to resolve references\r\n /tlbrefpath:Path Path used to resolve referenced type libraries\r\n /asmpath:Directory Look for assembly references here\r\n /win32 Create a 32-bit type library\r\n /win64 Create a 64-bit type library\r\n /oldnames Do not ignore COM invisible types when\r\n decorating names (old-rules)\r\n /nologo Prevents TlbExp from displaying logo\r\n /silent Suppresses all output except for errors\r\n /silence:WarningNumber Suppresses output for the given warning \r\n (Can not be used with /silent)\r\n /verbose Displays extra information\r\n /names:FileName A file in which each line specifies the\r\n capitalization of a name in the type library.\r\n /? or /help Display this usage message\r\n", "error": "TlbExp : error TX0000 : Could not load file or assembly 'file:///C:\\Users\\user\\help' or one of its dependencies. The module was expected to contain an assembly manifest.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\TlbExp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "TlbImp.exe-8520418C8256FC21ECAE460653B00454": { "file_name": "TlbImp.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\TlbImp.exe", "hash_md5": "8520418C8256FC21ECAE460653B00454", "hash_sha1": "B85B4E5D3D2DBBAAB28FC83BECA9CCA4ACB77A81", "hash_sha256": "75E2A025F5B20BA324AB0DBCF877F3FB3A9467D4736CB2BFBA9B79EFC68AFB04", "hash_sha384": "D995C1287870C612250AE4B14218FCCFC7A9A9CF4D0C592D69813735A4BA74C04BC25CA8635B5A92D4A1643C3671E80B", "hash_sha512": "9004C8490F20A54421F9BC477BE6C8272981E7E46B8281DABA9D59A60932A7CD14AEA2B399B72A8921B6E7B50AFC88EE9E1A0F3E8DD48B8CE8776A36115296C0", "hash_ssdeep": "3072:KGz3mZJiOWFd83yPdQ2l5E5nuQs3upGCFFHqdFdJ4U8hWFUy1zVwKwDr61pV+5:KGz3fOW/dr5knEaJ/QVwt6J6", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "016FE853D519F4D910C06D46D9B95159E0FAA320", "hash_pe256": "A18BD5FEEBDD35217907207A073F1EC3F97C5A1C2BD5F88A7D29F31DC4AE768A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Assembly to Type Library Converter", "meta_original_filename": "TlbImp.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/75e2a025f5b20ba324ab0dbcf877f3fb3a9467d4736cb2bfba9b79efc68afb04/detection", "output": "Microsoft (R) .NET Framework Type Library to Assembly Converter 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nSyntax: TlbImp TypeLibName [Options]\r\nOptions:\r\n /out:FileName File name of assembly to be produced\r\n /namespace:Namespace Namespace of the assembly to be produced\r\n /asmversion:Version Version number of the assembly to be produced\r\n /reference:FileName File name of assembly to use to resolve references\r\n /tlbreference:FileName File name of typelib to use to resolve references\r\n /publickey:FileName File containing strong name public key\r\n /keyfile:FileName File containing strong name key pair\r\n /keycontainer:FileName Key container holding strong name key pair\r\n /delaysign Force strong name delay signing\r\n /product:Product The name of the product with which this assembly\r\n is distributed\r\n /productversion:Version The version of the product with which this\r\n assembly is distributed\r\n /company:Company The name of the company that produced this\r\n assembly\r\n /copyright:Copyright Describes all copyright notices, trademarks, and\r\n registered trademarks that apply to this assembly\r\n /trademark:Trademark Describes all trademarks and registered trademarks\r\n that apply to this assembly\r\n /unsafe Produce interfaces without runtime security checks\r\n /noclassmembers Prevents TlbImp from adding members to classes\r\n /nologo Prevents TlbImp from displaying logo\r\n /silent Suppresses all output except for errors\r\n /silence:WarningNumber Suppresses output for the given warning (Can not \r\n be used with /silent)\r\n /verbose Displays extra information\r\n /primary Produce a primary interop assembly\r\n /sysarray Import SAFEARRAY as System.Array\r\n /machine:MachineType Create an assembly for the specified machine type\r\n /transform:TransformName Perform the specified transformation\r\n /strictref Only use assemblies specified using /reference and\r\n registered PIAs\r\n /strictref:nopia Only use assemblies specified using /reference and\r\n ignore PIAs\r\n /VariantBoolFieldToBool Convert VARIANT_BOOL field in structures to bool.\r\n /Legacy35 Use legacy TlbImp 3.5 behavior.\r\n /? or /help Display this usage message\r\n\r\nThe assembly version must be specified as: Major.Minor.Build.Revision.\r\n\r\nMultiple reference assemblies can be specified by using the /reference option\r\nmultiple times.\r\n\r\nSupported machine types:\r\n X86\r\n X64\r\n Itanium\r\n ARM\r\n Agnostic\r\n\r\nSupported transforms:\r\n SerializableValueClasses Mark all value classes as serializable\r\n DispRet Apply the [out, retval] parameter transformation\r\n to methods of disp only interfaces\r\n\r\nA resource ID can optionally be appended to the TypeLibName when importing a\r\ntype library from a module containing multiple type libraries.\r\n example: TlbImp MyModule.dll\\1\r\n", "error": "TlbImp : error TI1002 : The input file 'C:\\Users\\user\\help' is not a valid type library.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\TlbImp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Tracker.exe-566303DFC036D3B99B62B158CE5636C5": { "file_name": "Tracker.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\Tracker.exe", "hash_md5": "566303DFC036D3B99B62B158CE5636C5", "hash_sha1": "5105E7EB421521C139F15D9E4175B7BAFDC253AE", "hash_sha256": "5B97761C5C93FC7205EEED95BDA09CC48BD5511E3ECE91F107DC175B89BE8975", "hash_sha384": "45FB9C85BC9597D5CC186F05260F194C2F22BBCE35FF2AA3DAFA9355CD18CB0DB6E4CCA52ADFECAD175ADEACD3DBC245", "hash_sha512": "BE99E1D8A38256DF6D803DB6BF9000FFE932FE8A4BEAD1639AC0D4C20ADD66E4A7C0D258D54C4506DAA5B7CDFDE0221DC1F70D1072C182A9EB79013AE904D541", "hash_ssdeep": "3072:3IKUy2ssbzT385i0wrv2eJwJX/aqIvjusqfaU7t0WxpM1f2i4w:0T/85i0wKMuX1IPqVrU1um", "hash_imp": "C680C48710AC898A7A6D38020952E20D", "hash_pesha1": "94FB4A22C3F0E4C85BBBC8EC5916E1D46EBE1B40", "hash_pe256": "4AAD9F492C5216285331D723848DF6762B03B7ADA267D56EA2A7DD5042D3A08D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Tracker", "meta_original_filename": "Tracker.exe", "meta_product_name": "Microsoft .NET Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.8.4084.0 built by: NET48REL1", "meta_product_version": "14.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/5b97761c5c93fc7205eeed95bda09cc48bd5511e3ece91f107dc175b89be8975/detection", "error": "TRACKER : error TRK0000: Bad argument: --help\r\nMicrosoft (R) Build (MSBuild) File Tracker Version 4.0.30319\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\nSyntax:\r\n Tracker.exe [options] [@tracker-response-file] /c [command-line]\r\n\r\nSwitches:\r\n\r\n /d file.dll : Start the process with the tracking dll file.dll.\r\n (default: FileTracker.dll from the PATH)\r\n\r\n /i[f] <path> : Intermediate directory for tracking log output.\r\n (using /if will expand the path to full immediately)\r\n (default: current directory in tracked process)\r\n\r\n /o : Track operations performed on each file\r\n\r\n /m : Include missing files in tracking logs\r\n i.e. those that are deleted before process closes\r\n\r\n /u : Do not remove duplicate file operations from the\r\n tracking log.\r\n\r\n /t : Track command lines (will expand response files\r\n specified with the '@filename' syntax)\r\n\r\n /a : Enable extended tracking: GetFileAttributes,\r\n GetFileAttributesEx\r\n\r\n /e : Enable extended tracking: GetFileAttributes,\r\n GetFileAttributesEx, RemoveDirectory, CreateDirectory\r\n\r\n /k : Keep the full tool chain in tlog filenames.\r\n\r\n /r file1;file2;..;filen : Root primary input file(s) being tracked\r\n (default: none)\r\n\r\n /c [command-line] : Command to be tracked (must be the last argument).\r\n\r\n /? : This help text.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\Tracker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WCA.exe-0D49D0C3B0554836FEC4A71BBE4A0BA4": { "file_name": "WCA.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\WCA.exe", "hash_md5": "0D49D0C3B0554836FEC4A71BBE4A0BA4", "hash_sha1": "750BB9F953052CB768A0D5547A0DD4B3D150CF8C", "hash_sha256": "3C8AA7ADE8FD2DC0EE12E92274449520CFA36317C365F7C4B7235B50CF766B40", "hash_sha384": "F80F00C45C1AAA4E0E827F9EF92D76D759A8A833C9D7E2EC9EC14DEDC08C5DBF269F5D6A462D830C5AF7DE49C219012E", "hash_sha512": "FCFF2F05BB5DA97996D538332FE6A1BE5DA6807F8697FDF39FA0E519DB0254963E4515C29153AF014B64FF5CFDE3EFDBD32A10DCFC019F5E2E412BF8D845048A", "hash_ssdeep": "1536:26Eq5DMvEun/BcW21f6QQ3sXHd5honeHZo8P+:26Eq5DMvEunph1Cd5rZ2", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "CD3DA6D55B7F07A4B32A6DDB6E86C77301030477", "hash_pe256": "5ADEA1D3DCFEEDBD01B26B7273C47FF0F36A7A1F94F544EA3D87A111D108A9A9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "wca.exe", "meta_original_filename": "wca.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/3c8aa7ade8fd2dc0ee12e92274449520cfa36317c365f7c4b7235b50cf766b40/detection", "output": "Microsoft (R) Workflow Communications Activity generator utility\r\n[Microsoft(R) .NET Framework, Version 4.8.4084.0]\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nwca.exe -\r\n Utility to generate activities from a valid workflow communication\r\n interface\r\n\r\nwca.exe <assembly>.dll|.exe [/c] [/i] [/l:] [/o:]\r\n\r\n - OPTIONS -\r\n\r\n/collapseArgs\r\n Collapse HandleExternalEventActivity EventArg properties into a single\r\n variable E. Default is to create a public property on the\r\n HandleExternalEventActivity for each public property and public field in\r\n the EventArgs. Short form is '/c'.\r\n\r\n/includeSender\r\n Include the object Sender as a property of the HandleExternalEventActivity.\r\n Default is not to include the sender property. Short form is '/i'.\r\n\r\n/language:<language>\r\n The language to use for the generated code. Choose from 'CS' or 'VB'.\r\n Default is 'CS'. Short form is '/l:'.\r\n\r\n/out:<directoryName>\r\n The output directory in which to create the files. Default is the current\r\n directory. Short form is '/o:'.\r\n\r\n/namespace:<namespace>\r\n The namespace to which the activity classes will belong. Default is the\r\n namespace of the corresponding interface. Short form is '/n:'.\r\n\r\n - ARGUMENTS -\r\n\r\n<assembly>.dll|.exe\r\n Name of an assembly containing interfaces to generate activities for.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\WCA.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "WFC.exe-00CD451BA395EB6AE066C5DB7136C79C": { "file_name": "WFC.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\WFC.exe", "hash_md5": "00CD451BA395EB6AE066C5DB7136C79C", "hash_sha1": "34AAE15BCF61D46A7170F3700015BD3DF01E53A2", "hash_sha256": "8B66EF24A75AEFD4392210B3F340FDE5D3506EBC4BA1484E4E91E44570B85BFC", "hash_sha384": "FE743C3E66C1B250043C0147FEFFAB930D5FAA0A26BA40396F7377678BE733F7F99C246DA057524297621887FE9DD13A", "hash_sha512": "9C20B269663A3114EA5249AB455ADF77288A2142E937969E7B79B49AECDAA62496BB1461ED311EC501BD2CB8A02C8FAEB7D510CAC963ED73DD3B8845AC8B19E0", "hash_ssdeep": "1536:JFnVMMEogd8/Iz12L1LMDukPx6y0+uumbmqmKZ4N:JFnVbEbd8/Iz12xLMDukcy0+uu6m4Z4N", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "58E5F334FB46F7B0E0864ED1F2D5C9E24847F6C5", "hash_pe256": "D78D6B51C9C9A8BFF00056C0DCBDB3EE4B62BCE96733D2BF2851FC6E63E1233C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Workflow Foundation Compiler", "meta_original_filename": "wfc.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/8b66ef24a75aefd4392210b3f340fde5d3506ebc4ba1484e4e91e44570b85bfc/detection", "output": "Microsoft (R) Windows Workflow Compiler version 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n\r\n Windows Workflow Compiler Options\r\n\r\nwfc.exe <Xoml file list> /target:assembly [<vb/cs file list>] [/language:...]\r\n [/out:...] [/reference:...] [/library:...] [/debug...] [/nocode...]\r\n [/checktypes...] [/resource:<resource info>]\r\n\r\n - OUTPUT FILE -\r\n/out:<file> Output file name\r\n/target:assembly Build a Windows Workflow assembly (default).\r\n Short form: /t:assembly\r\n/target:exe\t\t Build a Windows Workflow application.\r\n Short form: /t:exe\r\n/delaysign[+|-] Delay-sign the assembly using only the public portion\r\n of the strong name key.\r\n/keyfile:<file> Specifies a strong name key file.\r\n/keycontainer:<string> Specifies a strong name key container.\r\n\r\n - INPUT FILES -\r\n<Xoml file list> Xoml source file name(s).\r\n<vb/cs file list> Code-beside file name(s).\r\n/reference:<file list> Reference metadata from the specified assembly file(s).\r\n Short form is '/r:'.\r\n/library:<path list> Set of directories where to lookup for the references.\r\n Short form is '/lib:'.\r\n/resource:<resinfo> Embed the specified resource. Short form is '/res:'.\r\n resinfo format is <file>[,<name>[,public|private]].\r\n\r\nRules and freeform layout files must be embedded as assembly resources.\r\nThe resource name is constructed by using the namespace and type name\r\nof the activity. For example, an activity named \"MyActivity\" in namespace\r\n\"WFProject\" would require resource names \"WFProject.MyActivity.rules\"\r\nand/or \"WFProject.MyActivity.layout\".\r\n\r\n - CODE GENERATION -\r\n/debug[+|-] Emit full debugging information. The default is '+'.\r\n/nocode[+|-] Disallow code-beside model.\r\n The default is '-'. Short form is '/nc:'.\r\n/checktypes[+|-] Check for permitted types in wfc.exe.config file.\r\n The default is '-'. Short form is '/ct:'.\r\n\r\n - LANGUAGE -\r\n/language:[cs|vb] The language to use for the generated class.\r\n The default is 'CS' (C#). Short form is '/l:'.\r\n/rootnamespace:<string> Specifies the root Namespace for all type declarations.\r\n Valid only for 'VB' (Visual Basic) language.\r\n Short form is '/rns:'.\r\n\r\n - MISCELLANEOUS -\r\n/help Display this usage message. Short form is '/?'.\r\n/nologo Suppress compiler copyright message. Short form is '/n'.\r\n/nowarn Ignore compiler warnings. Short form is '/w'.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\WFC.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "WinMDExp.exe-FD3EDAFFA3865DF5D5B25E6F493539CE": { "file_name": "WinMDExp.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\WinMDExp.exe", "hash_md5": "FD3EDAFFA3865DF5D5B25E6F493539CE", "hash_sha1": "EF6F720470F4421D4928BF1F6698930D7E79226C", "hash_sha256": "7C45E0E0996978D6A54C44DF159A45850E01A30DAA94FD80149641CB310183D6", "hash_sha384": "B3EBC6C14ABB5E155B86F75433A138BBF384AA375AF038589321BD14D190282EAB3F688A929BD315CF51118C87951CC7", "hash_sha512": "D5DEAACBA461C855660F43BD434D8E77774886C6F045E4B26BA98A75ECC03D5F11D4A8F2C0ECFAD3E261BDB99F3C6A144B04E5F0B3D8305136DAA223BBB746E1", "hash_ssdeep": "24576:CcjdWgRJLUfPi/HxRYZO3mWW8Y9d+19VAtwzLb7yPWmTw9+4BuqoNlB518ZtE:CeFR5vc3+rVSwzsqKt518Z+", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "87E70073E71571599754F128AA1B70B399CEBCCA", "hash_pe256": "71E474EA35E67E51BCB477404ED6955CF0C3B48D8664D199788E0E85C65D3D5F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework Windows Metadata Exporter", "meta_original_filename": "WinMDExp.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/7c45e0e0996978d6a54c44df159a45850e01a30daa94fd80149641cb310183d6/detection", "output": "Microsoft (R) .NET Framework Windows Metadata Exporter 4.8.4084.0 \r\nCopyright (C) Microsoft Corporation. All rights reserved. \r\n \r\nError parsing the command line: Argument '--help' is unknown.. \r\n \r\nUsage: WinMDExp.exe [arguments] <winmdmodule> \r\n \r\nArguments: \r\n /d:<docfile> or /doc:<docfile> \r\n Specify the name of the output XML documentation file \r\n \r\n /md:<docfile> or /moduledoc:<docfile> \r\n Specify the name of the XML documentation file for the winmdmodule being exported \r\n \r\n /mp:<symbolfile> or /modulepdb:<symbolfile> \r\n Specify the name of the PDB file containing symbols for the winmdmodule being exported \r\n \r\n /nowarn:<warning> \r\n Suppress the given warning number \r\n \r\n /o:<file> or /out:<file> \r\n Specify the name of the output Windows Metadata file \r\n \r\n /p:<symbolfile> or /pdb:<symbolfile> \r\n Specify the name of the PDB file to contain the symbols for the exported Windows Metadata file \r\n \r\n /r:<winmd> or /reference:<winmd> \r\n Adds a winmd file to reference during export \r\n \r\n /warnaserror+ \r\n Treat all warnings as errors. \r\n \r\n /utf8output \r\n Output messages in UTF-8 encoding. \r\n \r\n \r\n /assemblyunificationpolicy:<policy> or /up:<policy> \r\n Set the assembly unification policy, choices are: \r\n \r\n HighestVersion - Unify assemblies to the highest referenced version. Unification will only succeed if the unified assembly version is greater than or equal to the referenced assembly version. Unification applies to assemblies with identical names, public key tokens, and cultures. [default] \r\n \r\n ExactMatch - Do not unify assemblies, instead require exact version matching \r\n \r\n/windowsRuntimeVersion:<version> \r\n The Windows Runtime Version to target(1.2, 1.3, etc). The default is to use the highest version from the referenced winmd files. \r\n \r\nArguments and assemblies can also be provided in a response file provided on the command line prefixed with an @. Each line in the response file should contain a single argument or assembly name. \r\n \r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\WinMDExp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WinRes.exe-F8AA83A4AEE120EEB97C729D8886DAF3": { "file_name": "WinRes.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\WinRes.exe", "hash_md5": "F8AA83A4AEE120EEB97C729D8886DAF3", "hash_sha1": "EE23A9D588FACE97482C34F6A2932AFA1E18B72A", "hash_sha256": "00F6542A4909E9E872D6CB9B827D3AB4E7E54EA6E1C0F85421477DA7A666DC17", "hash_sha384": "6A8534201E6BFB05CC07BBB479F5629213056A99BA2FF3665ECB2C16D0A0077CAFF976D69A05CE315469BB64122CA311", "hash_sha512": "29B84445C1DA6D6B73792B7068CC3476038BE71C7CCF35D461991F0473F4E6182B4DDF808BD782AC335DA249F5965C34FB1ED53E701E8A4B179F045DCEE46DBA", "hash_ssdeep": "3072:JkgCSWbgfX7wuLMDBfUFIYE29GI8ldg+UPQBLgFppmylTtK5:JbCgfX7wuLMDBsFiyfPIOppmylTI5", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "CE25FFF736D48A1CB5B0994C6560174F812DEE0B", "hash_pe256": "A923C1A8CDDCE425C189FC59B8207E878FA046EC48C6FD2A7FB74D1EE7A452C5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Framework sample Windows forms designer", "meta_original_filename": "WinRes.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/00f6542a4909e9e872d6cb9b827d3ab4e7e54ea6e1c0f85421477da7a666dc17/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_6240": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Design\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Design.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\WinRes.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ], "runtime_window_title": "Windows Resource Localization Editor" }, "wsdl.exe-C53785CE6D43450E46EAC1BC84E591B8": { "file_name": "wsdl.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\wsdl.exe", "hash_md5": "C53785CE6D43450E46EAC1BC84E591B8", "hash_sha1": "72377BA6738D4EC400B8A7BA32FDAABAC63B1FAC", "hash_sha256": "BE565845988853858F285F3B007F9E1F1D3DA75E0F4C095371FA032D45389F83", "hash_sha384": "EC68BEA84E0A41963F42B200BFF63712745E52870D4DC3AE4062119E106F0E55530153F63523661E6F4F1DBFF872FE52", "hash_sha512": "F8290843577AF8AA0A33CCFE63B8E745766289593865E123223D03AFA8DFE45276DC36E57EFC777D5A94D3DAC5B025EB0C03866749421B8A8567530428B5012B", "hash_ssdeep": "1536:Au190NfjB1B+DRBz0B2lU/DWZiSwWN/lPhlMw8MTIBvdu0PfYcVOuj243yzB:eNfjB1B+DRBoB2pxlMo6dnxl2JB", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "B0F3175E5CEA51A8027DEAAF441AB51A4F0E9492", "hash_pe256": "03C7F01F99C8F327A3746BDBA098A7E96F178B41B08BF28765D427F83ABD9673", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Frameworks WebService install and administration tool", "meta_original_filename": "wsdl.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/be565845988853858f285f3b007f9e1f1d3da75e0f4c095371fa032d45389f83/detection", "output": "Microsoft (R) Web Services Description Language Utility\r\n[Microsoft (R) .NET Framework, Version 4.8.4084.0]\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nwsdl.exe -\r\n Utility to generate code for xml web service clients and xml web services\r\n using ASP.NET from WSDL contract files, XSD schemas and .discomap\r\n discovery documents. This tool can be used in conjunction with disco.exe.\r\n\r\nwsdl.exe <options> <url or path> <url or path> ...\r\n\r\n - OPTIONS -\r\n\r\n<url or path> -\r\n A url or path to a WSDL contract, an XSD schema or .discomap document.\r\n\r\n/nologo\r\n Suppresses the banner.\r\n\r\n/language:<language>\r\n The language to use for the generated proxy class. Choose from 'CS',\r\n 'VB', 'JS', 'VJS', 'CPP' or provide a fully-qualified name for a class\r\n implementing System.CodeDom.Compiler.CodeDomProvider. The default\r\n language is 'CS' (CSharp). Short form is '/l:'.\r\n\r\n/sharetypes\r\n Turns on type sharing feature. This feature creates one code file with\r\n a single type definition for identical types shared between different\r\n services (namespace, name and wire signature must be identical).\r\n Reference the services with http:// URLs as command-line parameters\r\n or create a discomap document for local files.\r\n\r\n/verbose\r\n Displays extra information when the /sharetypes switch is specified.\r\n Short form is '/v'.\r\n\r\n/fields\r\n Generate fields instead of properties. Short form is '/f'.\r\n\r\n/order\r\n Generate explicit order identifiers on particle members.\r\n\r\n/enableDataBinding\r\n Implement INotifyPropertyChanged interface on all generated types\r\n to enable data binding. Short form is '/edb'.\r\n\r\n/namespace:<namespace>\r\n The namespace for the generated proxy or template. The default namespace\r\n is the global namespace. Short form is '/n:'.\r\n\r\n/out:<fileName|directoryPath>\r\n The filename or directory path for the generated proxy code. The default\r\n filename is derived from the service name. Short form is '/o:'.\r\n\r\n/protocol:<protocol>\r\n Override the default protocol to implement. Choose from 'SOAP',\r\n 'SOAP12', 'HttpGet', 'HttpPost'.\r\n\r\n/username:<username>\r\n/password:<password>\r\n/domain:<domain>\r\n The credentials to use when connecting to a server that\r\n requires authentication. Short forms are '/u:', '/p:' and '/d:'.\r\n\r\n/proxy:<url>\r\n The url of the proxy server to use for http requests.\r\n The default is to use the system proxy setting.\r\n\r\n/proxyusername:<username>\r\n/proxypassword:<password>\r\n/proxydomain:<domain>\r\n The credentials to use when the connecting to a proxy server that\r\n requires authentication. Short forms are '/pu:', '/pp:' and '/pd:'.\r\n\r\n/appsettingurlkey:<key>\r\n The configuration key to use in the code generation to read the default\r\n value for the Url property. The default is to not read from the config\r\n file. Short form is '/urlkey:'.\r\n\r\n/appsettingbaseurl:<baseurl>\r\n The base url to use when calculating the url fragment. The\r\n appsettingurlkey option must also be specified. The url fragment is\r\n the result of calculating the relative url from the appsettingbaseurl\r\n to the url in the WSDL document. Short form is '/baseurl:'.\r\n\r\n/parsableerrors\r\n Print errors in a format similar to those reported by compilers.\r\n\r\n - ADVANCED -\r\n\r\n/server\r\n Server switch has been deprecated. Please use /serverInterface instead.\r\n Generate an abstract class for an xml web service implementation using\r\n ASP.NET based on the contracts. The default is to generate client proxy\r\n classes.\r\n\r\n/serverInterface\r\n Generates interfaces for server-side implementation of an ASP.Net \r\n Web Service. An interface is generated for each binding in the wsdl \r\n document(s). The wsdl alone implements the wsdl contract (classes \r\n that implement the interface should not include either of the following\r\n on the class methods: Web Service attributes or Serialization \r\n attributes that change the wsdl contract). Short form is '/si'.\r\n\r\n/parameters:<file>\r\n Read command-line options from the specified xml file. This allows you\r\n to specify options not available from command line such as choosing\r\n which type of asynchronous programming model is generated. For details,\r\n please see the tool documentation. Short form is '/par:'.\r\n", "error": "Error: File 'help' missing a file extension.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\wsdl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "xsd.exe-513E71569647CB7729DBE8A87CB667FF": { "file_name": "xsd.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\xsd.exe", "hash_md5": "513E71569647CB7729DBE8A87CB667FF", "hash_sha1": "5E8ABAAB5195EE7072370000BBEFB2148E3F1873", "hash_sha256": "A0B8CC794ECD4AA173B651DE77F7D559CD66F66598AC33C42A65561F1E6ECA5A", "hash_sha384": "06B3D7D00BA05F86EB37FB66D14E85631F8B145855E1B019A006A360CF4841D0BF4B7E9C6A10160F51FB7AA966F4D7EC", "hash_sha512": "94402708CB928B1E07C2AEEFDE81C43940752BD735A33E58823B0F8A0CF62EE62C9ABB887223C17085058CE8D5808F3A26107C4A2C15D048826BFEC1CEEDB4F0", "hash_ssdeep": "1536:VQipoylcELO4r4MyPYvTFdryM2YCrNHBV9O8sTS:YI4tQvZd7AB9iTS", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "D7A2304FF08C0AF1FBD0D8EC17E5E347CADAD860", "hash_pe256": "85B4F6AF15C852E8E62A35017E43FA83BB33D29339E8C1D8F21DA788196E8D4A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Frameworks Xml Schema Tool", "meta_original_filename": "xsd.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/a0b8cc794ecd4aa173b651de77f7d559cd66f66598ac33c42a65561f1e6eca5a/detection", "output": "Microsoft (R) Xml Schemas/DataTypes support utility\r\n[Microsoft (R) .NET Framework, Version 4.8.4084.0]\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nxsd.exe -\r\n Utility to generate schema or class files from given source.\r\n\r\nxsd.exe <schema>.xsd /classes|dataset [/e:] [/l:] [/n:] [/o:] [/s] [/uri:]\r\nxsd.exe <assembly>.dll|.exe [/outputdir:] [/type: [...]]\r\nxsd.exe <instance>.xml [/outputdir:]\r\nxsd.exe <schema>.xdr [/outputdir:]\r\n\r\n - OPTIONS -\r\n\r\n/classes\r\n Generate classes for this schema. Short form is '/c'.\r\n\r\n/dataset\r\n Generate sub-classed DataSet for this schema. Short form is '/d'.\r\n\r\n/enableLinqDataSet\r\n Generate LINQ-enabled sub-classed Dataset for the schemas provided. Short form is '/eld'.\r\n\r\n/element:<element>\r\n Element from schema to process. Short form is '/e:'.\r\n\r\n/fields\r\n Generate fields instead of properties. Short form is '/f'.\r\n\r\n/order\r\n Generate explicit order identifiers on all particle members.\r\n\r\n/enableDataBinding\r\n Implement INotifyPropertyChanged interface on all generated types\r\n to enable data binding. Short form is '/edb'.\r\n\r\n/language:<language>\r\n The language to use for the generated code. Choose from 'CS', 'VB', 'JS',\r\n 'VJS', 'CPP' or provide a fully-qualified name for a class implementing\r\n System.CodeDom.Compiler.CodeDomProvider. The default language\r\n is 'CS' (CSharp). Short form is '/l:'.\r\n\r\n/namespace:<namespace>\r\n The namespace for generated class files. The default namespace\r\n is the global namespace. Short form is '/n:'.\r\n\r\n/nologo\r\n Suppresses the banner.\r\n\r\n/out:<directoryName>\r\n The output directory to create files in. The default\r\n is the current directory. Short form is '/o:'.\r\n\r\n/type:<type>\r\n Type from assembly to generate schema for. Multiple types may be provided.\r\n If no types are provided, then schemas for all types in an assembly\r\n are generated. Short form is '/t:'.\r\n\r\n/uri:<uri>\r\n Uri of elements from schema to process. Short form is '/u:'.\r\n\r\n - ADVANCED -\r\n\r\n/parameters:<file>\r\n Read command-line options from the specified xml file. Short form is '/p:'.\r\n\r\n - ARGUMENTS -\r\n<schema>.xsd Name of a schema containing elements to import.\r\n<assembly>.dll|exe Name of an assembly containing types to generate schema for.\r\n<instance>.xml Name of an xml file to infer xsd schema from.\r\n<schema>.xdr Name of an xdr schema to convert to xsd.\r\nMultiple file arguments of the same type may be provided.\r\n", "error": "Error: invalid command line argument: '--help'.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\xsd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "xsltc.exe-8EAA7099776CFA8B96D7EF3592281DF6": { "file_name": "xsltc.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\xsltc.exe", "hash_md5": "8EAA7099776CFA8B96D7EF3592281DF6", "hash_sha1": "667F9FDF7143EFEDA7C8EB7FD13ED47FD09464A5", "hash_sha256": "005CF08BAB825948F28FEE8EDD110453CFAEEBF42FF8EFA700B5A8656847EE11", "hash_sha384": "78F6816E4C05587F4C1F23805B6E6C7A4746712CD754C5FD4125196A0BB77BF2084B19947451378B9A0E00229625B715", "hash_sha512": "825E35E0E6BB01BAF48A759B737BC9EE932066676D4D29E3EE727A253F49AA180682D42BE91A2BE2CF504E122A6D94D0F4A7DE935037E3228A7D508526B124C9", "hash_ssdeep": "768:9bUWXHRo5QM3r7MP0mG0/zdxSruPy3aG66Iq83jygVg8JS9NNTzkhqWSq8p0:9bZXHR8QMrB90Ld9a/JDUgdNNXkfSHp0", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "486A2AF89CE325D084DD3410B8A988AA35D88C43", "hash_pe256": "A4A7BE350899624F25A57E6C3FCD525A132CF4822369189EDA80522DCF98A4DA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework XSLT Compiler", "meta_original_filename": "xsltc.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/005cf08bab825948f28fee8edd110453cfaeebf42ff8efa700b5a8656847ee11/detection", "output": "Microsoft (R) XSLT Compiler version 4.8.4084.0\r\n[Microsoft (R) .NET Framework version 4.8.4300]\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nxsltc [options] [/class:<name>] <source file> [[/class:<name>] <source file>...]\r\n\r\n XSLT Compiler Options\r\n\r\n - OUTPUT FILES -\r\n/out:<file> Specify name of binary output file (default: name of the first source file)\r\n/version:<version> Specify an assembly version\r\n/delaysign[+|-] Delay-sign the assembly using only the public portion of the strong name key\r\n/keyfile:<file> Specify a strong name key file\r\n/keycontainer:<string> Specify a strong name key container\r\n/platform:<string> Limit which platforms this code can run on: x86, Itanium, x64, or anycpu, which is the default\r\n\r\n - RESOURCES -\r\n/win32res:<file> Specify a Win32 resource file (.res)\r\n\r\n - CODE GENERATION -\r\n/class:<name> Specify name of the class for compiled stylesheet (short form: /c)\r\n/debug[+|-] Emit debugging information\r\n/debug:{full|pdbonly} Specify debugging type ('full' is default and enables attaching a debugger)\r\n/settings:<list> Specify security settings in the format (dtd|document|script)[+|-],...\r\n Dtd enables DTDs in stylesheets, document enables document() function, script enables <msxsl:script> element\r\n\r\n - MISCELLANEOUS -\r\n@<file> Insert command-line settings from a text file\r\n/help Display this usage message (short form: /?)\r\n/nologo Suppress compiler copyright message\r\n", "error": "\nUnhandled Exception: System.IO.FileNotFoundException: Could not load file or assembly 'System.Data.SqlXml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089' or one of its dependencies. The system cannot find the file specified.\r\n at Microsoft.Xslt.Compiler.ImproveErrorText(String errorText)\r\n at Microsoft.Xslt.Compiler.PrintError(ErrorKind errorKind, String errorNumber, String errorText)\r\n at Microsoft.Xslt.Compiler.Run(String[] args)\r\n at Microsoft.Xslt.Compiler.Main(String[] args)\n", "children": [ "conhost.exe", "xsltc.exe", "WerFault.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_6092": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\xsltc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "al.exe-29043C744D89D17AEEE28BB2E367107F": { "file_name": "al.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\al.exe", "hash_md5": "29043C744D89D17AEEE28BB2E367107F", "hash_sha1": "95914A19F65AFA13E19FD31BE2EED9D02795489D", "hash_sha256": "950EA4E4DBB2EC5AB6D95102F2F1F4740569CFB773E5FFE4A7CA8B03CE79C9FB", "hash_sha384": "86659C7A73967D1D2A9FA72C8FF828BF26AC650D6FC31ED3D8132029613E4ADED41A02BA2F3B1A71BAFDF11374EEBFA5", "hash_sha512": "CDC679E0A538C9B3CC0207D05D9BE7EB223330C0934740AA46B62F7B9DE99D3E5057D83CFE2E082466DFEDBB22A7BD46BB71A69FA9C3232DB4B108DE19C5DD23", "hash_ssdeep": "6144:jW7p5LbqYsK+i5pPDWoQ8WFeJtBmF5Ym4iKS3OJqV:jWFQK+i5pPioVE8S+JqV", "hash_imp": "EBACDBB94C2E9279569CC7B90953FEA2", "hash_pesha1": "A0AFE4D4599B7373BC687D6F0C81599AB5EA49BE", "hash_pe256": "3345A94657F7BD6A3DE1A86C5E87C4FFB18816C9129F46F67398D988BE0BB4CB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Assembly Linker command line tool", "meta_original_filename": "al.exe", "meta_product_name": "Microsoft .NET Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.8.4084.0 built by: NET48REL1", "meta_product_version": "14.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/950ea4e4dbb2ec5ab6d95102f2f1f4740569cfb773e5ffe4a7ca8b03ce79c9fb/detection", "output": "Microsoft (R) Assembly Linker version 14.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: al [options] [sources]\r\nOptions: ('/out' must be specified)\r\n\r\n /? or /help Display this usage message\r\n @<filename> Read response file for more options\r\n /algid:<id> Algorithm used to hash files (in hexadecimal)\r\n /base[address]:<addr> Base address for the library\r\n /bugreport:<filename> Create a 'Bug Report' file\r\n /comp[any]:<text> Company name\r\n /config[uration]:<text> Configuration string\r\n /copy[right]:<text> Copyright message\r\n /c[ulture]:<text> Supported culture\r\n /delay[sign][+|-] Delay sign this assembly\r\n /descr[iption]:<text> Description\r\n /e[vidence]:<filename> Security evidence file to embed\r\n /fileversion:<version> Optional Win32 version (overrides assembly version)\r\n /flags:<flags> Assembly flags (in hexadecimal)\r\n /fullpaths Display files using fully-qualified filenames\r\n /keyf[ile]:<filename> File containing key to sign the assembly\r\n /keyn[ame]:<text> Key container name of key to sign assembly\r\n /main:<method> Specifies the method name of the entry point\r\n /nologo Suppress the startup banner and copyright message\r\n /out:<filename> Output file name for the assembly manifest\r\n /platform:<text> Limit which platforms this code can run on; must be\r\n one of x86, Itanium, x64, arm, anycpu32bitpreferred,\r\n or anycpu (the default)\r\n /prod[uct]:<text> Product name\r\n /productv[ersion]:<text> Product version\r\n /subsystemversion:<version>\r\n Specifies the subsystem version for the assembly\r\n /t[arget]:lib[rary] Create a library\r\n /t[arget]:exe Create a console executable\r\n /t[arget]:win[exe] Create a Windows executable\r\n /t[arget]:appcontainerexe Create a Windows executable that runs on AppContainer\r\n /template:<filename> Specifies an assembly to get default options from\r\n /title:<text> Title\r\n /trade[mark]:<text> Trademark message\r\n /v[ersion]:<version> Version (use * to auto-generate remaining numbers)\r\n /win32icon:<filename> Use this icon for the output\r\n /win32res:<filename> Specifies the Win32 resource file\r\n\r\nSources: (at least one source input is required)\r\n <filename>[,<targetfile>] add file to assembly\r\n /embed[resource]:<filename>[,<name>[,Private]]\r\n embed the file as a resource in the assembly\r\n /link[resource]:<filename>[,<name>[,<targetfile>[,Private]]]\r\n link the file as a resource to the assembly\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\al.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AxImp.exe-8F1DC3A76AE04FD73E84D5936BACFDB9": { "file_name": "AxImp.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\AxImp.exe", "hash_md5": "8F1DC3A76AE04FD73E84D5936BACFDB9", "hash_sha1": "80F75DC9E3937F71D47CC6A064021BAEFA33BCA4", "hash_sha256": "23701485B9493F9C1BAEABD7E4F3D80D4DD5D6FA9BB0D3A9050690977E07312B", "hash_sha384": "491A0EF773EF5F0447B8C8F1A4069D55D1E5F2D5565E06F9F470F059813CC72E9337E1633BEAC6047749C056E95F3BAE", "hash_sha512": "37E0584E0FBE7A89260F3159B262292EDE3458BEEB065AC5BB31040864171811CC82034019F0F7C4E3BEDBA4CC65AD6A2B028E35D5AABA30F87A970C2DCB2914", "hash_ssdeep": "768:X3Iqp37aFC9l/3SXwXdv5yIyd6Iq8zf7bwG/5OECQ2qWqx8v4D:X/p8glPSX6dBy90aAG/5OECbqaAD", "hash_imp": "n/a", "hash_pesha1": "2CBFB4FCE1FDC4CA32FE6BFE838CDA614D5095AA", "hash_pe256": "121C937ACCDCA0CF6BC296E00E941562D3E295C44EC91927BD0742A177F8865B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Framework Windows forms ActiveX conversion utility", "meta_original_filename": "AxImp.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/23701485b9493f9c1baeabd7e4f3d80d4dd5d6fa9bb0d3a9050690977e07312b/detection", "output": "Microsoft (R) .NET ActiveX Control to Windows Forms Assembly Generator \n[Microsoft .Net Framework, Version 4.8.4084.0]\nCopyright (C) Microsoft Corporation. All rights reserved.\n\n\r\nGenerates a Windows Forms Control that wraps ActiveX controls defined in the given OcxName.\n\nUsage:\n AxImp OcxName [Options]\r\nOptions:\r\n /out:FileName File name of assembly to be produced\r\n /publickey:FileName File containing strong name public key\r\n /keyfile:FileName File containing strong name key pair\r\n /keycontainer:FileName Key container holding strong name key pair\r\n /delaysign Force strong name delay signing\r\n Used with /keyfile, /keycontainer or /publickey\r\n /source Generate C# source code for Windows Forms wrapper\r\n /rcw:FileName Assembly to use for Runtime Callable Wrapper rather than generating new one.\r\n Multiple instances of this option may be specified. Current directory is used\r\n as a root for relative paths\r\n /ignoreregisteredocx version of 'OcxName' library supplied on the command line is used to generate\r\n the Windows Forms wrapper, if this type library is registered on the machine,\r\n then the registered version is ignored\r\n /nologo Prevents AxImp from displaying logo\r\n /silent Prevents AxImp from displaying success message\r\n /verbose Displays extra information\r\n /? or /help Display this usage message\r\n", "error": "AxImp Error: Unknown option: /-help\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\AxImp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "clrver.exe-C2915E5A90FEF1FBD138A57DA64F331C": { "file_name": "clrver.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\clrver.exe", "hash_md5": "C2915E5A90FEF1FBD138A57DA64F331C", "hash_sha1": "1CF7E2F27AFA5BB88AE96DA1E66584F701E1791C", "hash_sha256": "50FBE4A2A190FDBF15FDC7DF00180D5C08726A7F89A1252ED9F556EE2DE1061F", "hash_sha384": "70127619CBFE99D3CC70FE70FF937EE3DB03465475D766E34893909C7404BF44A7EC4AF628779D486AD249769FE54637", "hash_sha512": "D595B1CA98ED151CF6216D2BF34217AC307DF21B2B12699BC2F78B5DD4D573CBC3C7EB74BBE566EA09F520970FD3BF70C71D3FC747B4D66956857C492C7AB424", "hash_ssdeep": "3072:tVsNBuwPmVx0rxQdDDhJAFCUgSzGc6txvg1VxZSz:tVdw+f0SD1JZUdiZ8k", "hash_imp": "DD8FC794E50A831220028F4281C4E156", "hash_pesha1": "F19940E010FC32E929187C1EF19CBEA46AE07CB7", "hash_pe256": "90322F98378689C1B68D71C2AC4B2E69FF441AD0AA069935AD4ED7A941852117", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays CLR Versions", "meta_original_filename": "clrver.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/50fbe4a2a190fdbf15fdc7df00180d5c08726a7f89a1252ed9f556ee2de1061f/detection", "children": "Fondue.exe", "output": "\r\nMicrosoft (R) .NET CLR Version Tool Version 4.8.4084.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUnknown option \"--help\".\r\nDisplays CLR versions\r\nUsage: clrver [-?|-all|<PID>]\r\n\r\n\t-all - Displays all processes on the machine using the CLR.\r\n\t<PID> - Displays the version of the CLR used by the specified process.\r\n\t-? - Displays this help screen.\r\n\r\nIf called with no options, clrver will display all installed CLR versions.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\clrver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "CorFlags.exe-EA46F177C0C1E89B3EF37A415384562A": { "file_name": "CorFlags.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\CorFlags.exe", "hash_md5": "EA46F177C0C1E89B3EF37A415384562A", "hash_sha1": "120A4571808296FDD151D74600EA2E39C75167A1", "hash_sha256": "6B4301904632B25D8E1638BF3F274251D9FF1A175B525F8E1E4B93C38BDE42E0", "hash_sha384": "6562F2FC1F55474B2117009BA956D327DE58EE1DF063ECEE7C986437642F87F3DFE3C25D34BF7F6AAFEFF8F2BE4CC4F7", "hash_sha512": "97A19B2912165BD10295A4DE9D341E45423C6174092A0531F21F9A61B8228796CE21CCD2D52388704B8B7B4476940468C643012C29A3E32B55B16D80D71D88DC", "hash_ssdeep": "6144:exlU0xp1BhhTnIrxmc7b3rdEq5tpNl0JKFh1ME8:6a0nrhhTnIrxBb32wsE8", "hash_imp": "2BE01F61EFE0EC9BD26A9DB134AE42E3", "hash_pesha1": "A260404198C2A8273ECE7DE07C97F28250CA858A", "hash_pe256": "E78A1696BC7343BE281F290CFAC66BB8D54FE7A7C8DCB996A00E7F063389BD8E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Common Language Runtime Agnostic Assembly Conversion Tool", "meta_original_filename": "CorFlags.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/6b4301904632b25d8e1638bf3f274251d9ff1a175b525f8e1e4b93c38bde42e0/detection", "output": "corflags : error CF000 : Invalid option (--help)\r\n\r\nMicrosoft (R) .NET Framework CorFlags Conversion Tool. Version 4.8.4084.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: Corflags.exe Assembly [options]\r\n\r\nIf no options are specified, the flags for the given image are displayed.\r\n\r\nOptions:\r\n/ILONLY+ /ILONLY- Sets/clears the ILONLY flag\r\n/32BITREQ+ /32BITREQ- Sets/clears the bits indicating 32-bit x86 only\r\n/32BITPREF+ /32BITPREF- Sets/clears the bits indicating 32-bit preferred\r\n/UpgradeCLRHeader Upgrade the CLR Header to version 2.5\r\n/RevertCLRHeader Revert the CLR Header to version 2.0\r\n/Force Force an assembly update even if the image is\r\n strong name signed.\r\n WARNING: Updating a strong name signed assembly\r\n will require the assembly to be resigned before\r\n it will execute properly.\r\n/nologo Prevents corflags from displaying logo\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\CorFlags.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "disco.exe-20DC8790BF695D7F3A429D7E16159D27": { "file_name": "disco.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\disco.exe", "hash_md5": "20DC8790BF695D7F3A429D7E16159D27", "hash_sha1": "3B59261752810566975F7008691EC83BD03C779F", "hash_sha256": "1013BA5F76D06C88C89A286570B3F691F290180F1D8F60E4182F2824DF14A9F9", "hash_sha384": "A338EB5DADB5F85634D4BD399883D7771E3D8FE9508EA40BCF83DDEC6115B4CFD7D13099F7CF9727E1C219A2BC68B9AB", "hash_sha512": "B1398BF59874A8FF16FED40CBD2A2B51F6D86527974FBED3DF014D39044D0106C43BD7D2208470CC3771A7999A5C1AAAA7DE121DEDA5BBD47E040D34A741FC4B", "hash_ssdeep": "1536:U36g84qP7OibhK8RgdJlbb0Fnhh1BkVgWf66F:U36gKP7OiFWd8FTkVgWt", "hash_imp": "n/a", "hash_pesha1": "7A463A35DCAECCB8CC1C6EA8DC887E3FDC9A4759", "hash_pe256": "DE5B448CD65F3038CA3118ACA80D659DD108A044DDD1AB900F3437570C6D5811", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Frameworks Web Service Discovery Tool", "meta_original_filename": "disco.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/1013ba5f76d06c88c89a286570b3f691f290180f1d8f60e4182f2824df14a9f9/detection", "output": "Microsoft (R) Web Services Discovery Utility\r\n[Microsoft (R) .NET Framework, Version 4.8.4084.0]\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\ndisco.exe -\r\n Utility to discover the URLs of xml web services located on a web server\r\n and to save documents related to that xml web service on the local disk.\r\n The results.discomap, .wsdl and .xsd files produced by this tool can be\r\n used with wsdl.exe to produce web service clients and abstract web service\r\n servers using ASP.NET.\r\n\r\ndisco.exe <options> <url to discover>\r\n\r\n - OPTIONS -\r\n\r\n/nologo\r\n Suppresses the banner.\r\n\r\n/nosave\r\n Do not save the discovered documents or results to disk (for example\r\n wsdl, xsd and disco files). The default is to save the documents.\r\n\r\n/out:<directoryName>\r\n The output directory to save the discovered documents in. The default\r\n is the current directory. Short form is '/o:'.\r\n\r\n/username:<username>\r\n/password:<password>\r\n/domain:<domain>\r\n The credentials to use when the connecting to a server that\r\n requires authentication. Short forms are '/u:', '/p:' and '/d:'.\r\n\r\n/proxy:<url>\r\n The url of the proxy server to use for http requests.\r\n The default is to use the system proxy setting.\r\n\r\n/proxyusername:<username>\r\n/proxypassword:<password>\r\n/proxydomain:<domain>\r\n The credentials to use when the connecting to a proxy server that\r\n requires authentication. Short forms are '/pu:', '/pp:' and '/pd:'.\r\n", "error": "ERROR: help\r\n - Invalid URI: The format of the URI could not be determined.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\disco.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "FUSLOGVW.exe-FD4D60958411F59DDE08C4457171F339": { "file_name": "FUSLOGVW.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\FUSLOGVW.exe", "hash_md5": "FD4D60958411F59DDE08C4457171F339", "hash_sha1": "DF5653FE66B8A4895C373C56A204B4882A711655", "hash_sha256": "5787C302E38CBBC067EAA81BB0E6B13478873D9AD69D1AB570E8319B6169077A", "hash_sha384": "CBC60ACC5BD237B6183AB87EB2ED8F0F4DD449445433E12A618EB25B8D3CB60628414683D05D29A7C9AA9E9DFBC8E11F", "hash_sha512": "C36C166841D7DB180A0CFE2E4C90BE8CBF34B2AD61761A1DEC7DDE3410F3E866E9DC00E872BE0C54C6468CB3EF45130204B32505F7F26C5104D770F9C0D8E677", "hash_ssdeep": "3072:WeuDBAaOPKfdiCFrRZCTnIrcu3EbzXHnyBKeMRt7x+KKALqMl1TbGUg2OpS5hPZY:dxKJ3ZCTnIrv3EH3nqGl+0b/WuMkFM", "hash_imp": "72CDDE1D32512CC3230FA6C81DBAC223", "hash_pesha1": "F334AE8D44587A897EC2484BA28FD1AA206D3CF1", "hash_pe256": "20192BD42618B84CE0CB17635BE8180AC5E0307827BAD7CB67E038173279A90D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .Net Framework Assembly Binding Log Viewer", "meta_original_filename": "fuslogvw.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/5787c302e38cbbc067eaa81bb0e6b13478873d9ad69d1ab570e8319b6169077a/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme2042523233": "Section", "\\Sessions\\1\\Windows\\Theme1383959086": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_webcache_counters_{9B6AB5B3-91BC-4097-835C-EA2DEC95E9CC}_S-1-5-21-2047949552-857980807-821054962-504": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\FUSLOGVW.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\mscoree.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll" ], "runtime_window_title": "Assembly Binding Log Viewer" }, "gacutil.exe-B832833BB3D6DE53EE50DA48667A5AC2": { "file_name": "gacutil.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\gacutil.exe", "hash_md5": "B832833BB3D6DE53EE50DA48667A5AC2", "hash_sha1": "ECA3E57F47B220392FD883EE112C95F51793609C", "hash_sha256": "C4884B1CD4BF6726056382DA620BDD7C16BFEC4D2E6FB8AA450E9AAAFDFC7DA0", "hash_sha384": "60E1FD1F9923C3D259CD3C28B0859A0E7F651FC96638887C94C0C7CDA48BCBF523DE1F98609175B2BB3E6D3C354FB0C5", "hash_sha512": "994A53478DF9FB5BC1C5F0E929D5584AD0523FDE74A4ADF3873EDD613FD82F4CB525E32DE30F0FA316D6295A2AFFAC25163DDA2AF3927B7877DBF9B201577E5C", "hash_ssdeep": "3072:KQKlsv+7uScu58rRTFtE/ZLO63uIIzc1VofMJvaj9YfTOJpYb:K3I+Wu58rlCH1IzcTpNTO/C", "hash_imp": "AD8FD1BD9FF6D25B8E1A4F2AB0155FF4", "hash_pesha1": "DB1E6919D19CE64406592D18C7061FD73DEA6AF6", "hash_pe256": "4A586317F2895A08EC34F124D5DD953E121118C0E1FEE353DCDDFD8C2AC30E44", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) .NET Framework Global Assembly Cache Utility", "meta_original_filename": "gacutil.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/c4884b1cd4bf6726056382da620bdd7c16bfec4d2e6fb8aa450e9aaafdfc7da0/detection", "output": "Microsoft (R) .NET Global Assembly Cache Utility. Version 4.0.30319.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: Gacutil <command> [ <options> ]\r\nCommands:\r\n /i <assembly_path> [ /r <...> ] [ /f ]\r\n Installs an assembly to the global assembly cache. <assembly_path> is the\r\n name of the file that contains the assembly manifest.\r\n Example: /i myDll.dll /r FILEPATH c:\\projects\\myapp.exe \"My App\"\r\n\r\n /il <assembly_path_list_file> [ /r <...> ] [ /f ]\r\n Installs one or more assemblies to the global assembly cache. \r\n <assembly_list_file> is the path to a text file that contains a list of \r\n assembly manifest file paths. Individual paths in the text file must be \r\n separated by CR/LF.\r\n Example: /il MyAssemblyList.txt /r FILEPATH c:\\projects\\myapp.exe \"My App\"\r\n myAssemblyList.txt content:\r\n myAsm1.dll\r\n myAsm2.dll\r\n\r\n /u <assembly_display_name> [ /r <...> ]\r\n Uninstalls an assembly. <assembly_name> is the name of the assembly\r\n (partial or fully qualified) to remove from the Global Assembly Cache.\r\n If a partial name is specified all matching assemblies will be uninstalled.\r\n Example:\r\n /u myDll,Version=1.1.0.0,Culture=en,PublicKeyToken=874e23ab874e23ab\r\n /r FILEPATH c:\\projects\\myapp.exe \"My App\"\r\n\r\n /uf <assembly_name>\r\n Forces uninstall of an assembly by removing all traced references.\r\n <assembly_name> is the full name of the assembly to remove.\r\n Assembly will be removed unless referenced by Windows Installer.\r\n !! Warning: use the /uf command with care as applications may fail to run !!\r\n Example: /uf myDll,Version=1.1.0.0,Culture=en,PublicKeyToken=874e23ab874e23ab\r\n\r\n /ul <assembly_display_name_list_file> [ /r <...> ]\r\n Uninstalls one or more assemblies from the global assembly cache. \r\n <assembly_list_file> is the path to a text file that contains a list of \r\n assembly names. Individual names in the text file must be \r\n separated by CR/LF.\r\n Example: /ul myAssemblyList.txt/r FILEPATH c:\\projects\\myapp.exe \"My App\"\r\n myAssemblyList.txt content:\r\n myDll,Version=1.1.0.0,Culture=en,PublicKeyToken=874e23ab874e23ab\r\n myDll2,Version=1.1.0.0,Culture=en,PublicKeyToken=874e23ab874e23ab\r\n\r\n /l [ <assembly_name> ]\r\n Lists the contents of the global assembly cache. When the optional \r\n <assembly_name> parameter is specified only matching assemblies are listed.\r\n\r\n /lr [ <assembly_name> ]\r\n Lists the contents of the global assembly cache including traced reference \r\n information. When the optional <assembly_name> parameter is specified only \r\n matching assemblies are listed.\r\n\r\n /cdl\r\n Deletes the contents of the download cache\r\n\r\n /ldl\r\n Lists the contents of the download cache\r\n\r\n /? \r\n Displays a detailed help screen\r\n\r\nOld command syntax:\r\n /if <assembly_path>\r\n equivalent to /i <assembly_path> /f\r\n\r\n /ir <assembly_path> <reference_scheme> <reference_id> <description>\r\n equivalent to /i <assembly_path> /r <...>\r\n\r\n /ur <assembly_name> <reference_scheme> <reference_id> <description>\r\n equivalent to /u <assembly_path> /r <...>\r\n\r\nOptions:\r\n /r <reference_scheme> <reference_id> <description>\r\n Specifies a traced reference to install (/i, /il) or uninstall (/u, /ul).\r\n <reference_scheme> is the type of the reference being added \r\n (UNINSTALL_KEY, FILEPATH or OPAQUE). \r\n <reference_id> is the identifier of the referencing application, \r\n depending on the <reference_scheme>\r\n <description> is a friendly description of the referencing application.\r\n Example: /r FILEPATH c:\\projects\\myapp.exe \"My App\"\r\n\r\n /f \r\n Forces reinstall of an assembly regardless of any existing assembly with \r\n the same assembly name.\r\n\r\n /nologo\r\n Suppresses display of the logo banner\r\n\r\n /silent\r\n Suppresses display of all output\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\gacutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ildasm.exe-1EDEF2D2C5BE98582F8CBA566F3603F0": { "file_name": "ildasm.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\ildasm.exe", "hash_md5": "1EDEF2D2C5BE98582F8CBA566F3603F0", "hash_sha1": "FA4B04167B54E727898CA0326FF08FEDAADD5428", "hash_sha256": "16B83C1E88BF45EF528DA4FDA4CD0D174571D7597A6379492A12B26AB69DABA6", "hash_sha384": "694D63472776602E8CAF2D65F8939C53CF6B8B7F2E2FEEC3FA1E8C20D5C02F42E3CC7011CE8BE4A3D8194D2FE4470932", "hash_sha512": "6BB1CC8C7B6961AFA93A885EE03D42570132BC3008C4490EAFC44254F93631F654D4C0A1979FAAF986DE9AEA34389DDA08CB043E6E9B8647833A1BD13CAAE437", "hash_ssdeep": "12288:cArMxakG4g2X9/3L68Vzk4SMO7ky0VX2DIa6E4TDrVRe+JcbZTB6Xq3jmugHG5aO:pr1Z4g2X9/3L6YeMO7ky0VmDqNi+Jcbd", "hash_imp": "420AF2FBD6F4480F1FB6C114A447BB80", "hash_pesha1": "559344F8246649B32C12356F366C232395E25F7E", "hash_pe256": "33077C8C2412A76924EB7561471589C6422C6D818C448B6E90119C8AA747202E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework IL disassembler", "meta_original_filename": "ildasm.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/16b83c1e88bf45ef528da4fda4cd0d174571d7597a6379492a12b26ab69daba6/detection", "children": "ildasm.exe", "output": "Microsoft (R) .NET Framework IL Disassembler. Version 4.8.4084.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nINVALID COMMAND LINE OPTION: --help\r\n\r\nUsage: ildasm [options] <file_name> [options]\r\n\r\nOptions for output redirection:\r\n /OUT=<file name> Direct output to file rather than to GUI.\r\n /TEXT Direct output to console window rather than to GUI.\r\n\r\n /HTML Output in HTML format (valid with /OUT option only).\r\n /RTF Output in rich text format (invalid with /TEXT option).\r\nOptions for GUI or file/console output (EXE and DLL files only):\r\n /BYTES Show actual bytes (in hex) as instruction comments.\r\n /RAWEH Show exception handling clauses in raw form.\r\n /TOKENS Show metadata tokens of classes and members.\r\n /SOURCE Show original source lines as comments.\r\n /LINENUM Include references to original source lines.\r\n /VISIBILITY=<vis>[+<vis>...] Only disassemble the items with specified\r\n visibility. (<vis> = PUB | PRI | FAM | ASM | FAA | FOA | PSC)\r\n /PUBONLY Only disassemble the public items (same as /VIS=PUB).\r\n /QUOTEALLNAMES Include all names into single quotes.\r\n /NOCA Suppress output of custom attributes.\r\n /CAVERBAL Output CA blobs in verbal form (default - in binary form).\r\n /NOBAR Suppress disassembly progress bar window pop-up.\r\n\r\nThe following options are valid for file/console output only:\r\nOptions for EXE and DLL files:\r\n /UTF8 Use UTF-8 encoding for output (default - ANSI).\r\n /UNICODE Use UNICODE encoding for output.\r\n /NOIL Suppress IL assembler code output.\r\n /FORWARD Use forward class declaration.\r\n /TYPELIST Output full list of types (to preserve type ordering in round-trip).\r\n /PROJECT Display .NET projection view if input is a .winmd file.\r\n /HEADERS Include file headers information in the output.\r\n /ITEM=<class>[::<method>[(<sig>)] Disassemble the specified item only\r\n\r\n /STATS Include statistics on the image.\r\n /CLASSLIST Include list of classes defined in the module.\r\n /ALL Combination of /HEADER,/BYTES,/STATS,/CLASSLIST,/TOKENS\r\n\r\nOptions for EXE,DLL,OBJ and LIB files:\r\n /METADATA[=<specifier>] Show MetaData, where <specifier> is:\r\n MDHEADER Show MetaData header information and sizes.\r\n HEX Show more things in hex as well as words.\r\n CSV Show the record counts and heap sizes.\r\n UNREX Show unresolved externals.\r\n SCHEMA Show the MetaData header and schema information.\r\n RAW Show the raw MetaData tables.\r\n HEAPS Show the raw heaps.\r\n VALIDATE Validate the consistency of the metadata.\r\nOptions for LIB files only:\r\n /OBJECTFILE=<obj_file_name> Show MetaData of a single object file in library\r\n\r\nOption key is '-' or '/', options are recognized by first 3 characters\r\n\r\nExample: ildasm /tok /byt myfile.exe /out=myfile.il\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\ildasm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "lc.exe-D08897BE2EC64B1BE4DF4F8430DBC535": { "file_name": "lc.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\lc.exe", "hash_md5": "D08897BE2EC64B1BE4DF4F8430DBC535", "hash_sha1": "B1B446E5B629505F6C8C3FC7D0A4213D8AA8F0D4", "hash_sha256": "B2469E3F6B40BA631C4CE36FFE5EDED4AD65FC5BAA560ADACD186C4D0E6B9862", "hash_sha384": "B535AC63DF44AB0B1B405728E9AC1E9520CF25CC27FD86366ADEF77854686DCFA10D6FFC033DD10AFF346C1F98601F42", "hash_sha512": "04203E933594D812A60DDDF47A2B8E26CB5B40996B7B44CFE4B044AF845C217453180E62CB58B7780BEA4F6733C153A727DFE25350852A2E6E88DD5E6881E7AF", "hash_ssdeep": "768:RvOvK7zwpgiSUmudqda59E96Iq8clW+J8Vu2qWls8K5D1V3:RvcAEpgibLEdanEUzJ8VJ/yf", "hash_imp": "n/a", "hash_pesha1": "9DE3B2DE9A6EC246FA49B59D86C6D4A690A6D6A3", "hash_pe256": "5DC7281742F090C0FB351EAC2D94A4B58A2B3365F8DBB844C57941389D65C3D2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Framework license compiler", "meta_original_filename": "lc.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/b2469e3f6b40ba631c4ce36ffe5eded4ad65fc5baa560adacd186c4d0e6b9862/detection", "output": "Microsoft (R) .NET License Compiler \n[Microsoft .Net Framework, Version 4.8.4084.0]\nCopyright (C) Microsoft Corporation. All rights reserved.\n\n\r\nGenerates a .NET Licenses file and adds it to the manifest of the given assembly\nUsage:\n lc /target:TargetAssembly /complist:filename [/outdir:path] [/i:modules] [/v] [/nologo]\n\nOptions:\n /target:<str> Target assembly for the generated licenses file\n /complist:<str> Licensed component list file\n /outdir:<str> Output directory for the generated licenses file\n /i:<str> Specify modules to load\n /v Verbose output\n /nologo Suppress the display of the startup banner\n @<file> Accept options from a response file\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\lc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "MSBuildTaskHost.exe-AAF1A565E5923FCF6F171B4C154AAC39": { "file_name": "MSBuildTaskHost.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\MSBuildTaskHost.exe", "hash_md5": "AAF1A565E5923FCF6F171B4C154AAC39", "hash_sha1": "DA76BBBB831072F67BE3E6AAFF2D2B2B927A84F9", "hash_sha256": "9080F70EAE53A7FB4CC13933802F96EA26219E0CE531FCF691C2D48E1B1AB4AD", "hash_sha384": "A412596A1EAA4830309D46640E0C1F4330CEF001857E47CBB1C0754AF4CCCF0D53276F19B25C1177B91DE698484DAF0A", "hash_sha512": "BA52D876E46E9355D7449E2AB4CB46A5980166036454D4B9FA41E67A725E472C726C3386EBCF04284D48391828F59668222894314DF045B101A23444C43DE495", "hash_ssdeep": "3072:aPtaGqMdqIgVyu9FrJFXVmH0IAavcWu0MtN5UYLFZAIgKoPtUQRFiQae:aPtaGqfpFrJ3g01hVttCD5tUQbixe", "hash_imp": "n/a", "hash_pesha1": "5E6D7EE994A1E45339656796230F05EC858F64FE", "hash_pe256": "56B1E8044D3685EE4AB80F25814CB11E56F86F0BE808325A986D5F58236A7150", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MSBuildTaskHost.exe", "meta_original_filename": "MSBuildTaskHost.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "MSBuildTaskHost.exe", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0", "meta_product_version": "4.8.4084.0", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/9080f70eae53a7fb4cc13933802f96ea26219e0ce531fcf691c2d48e1b1ab4ad/detection", "children": "Fondue.exe", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\MSBuildTaskHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "PEVerify.exe-1B735EB9E463BE009BC52F28A86F7D5D": { "file_name": "PEVerify.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\PEVerify.exe", "hash_md5": "1B735EB9E463BE009BC52F28A86F7D5D", "hash_sha1": "29C167CA8FB0257003EC0A2E426CDF3AFE3F692B", "hash_sha256": "6C89FC6FA70130DFF015271BFBB580BF100EAA3FC168B5BBD4B762E9CBEFD251", "hash_sha384": "6E5B0EAD2269CC94FBFBD886CCEDDF2B109F6F4445B3FE56C2C36A83D5AC51506853AEA87448BA98E5EC595CDE968F82", "hash_sha512": "2E33F2F02A1D1B811DF111182A26EDD13BCEBA6AC4694138890F5BB3347AF9FD5CF18C1850337220CC2026A522E26F483A3E65FD645B812C5F920C5C8532110A", "hash_ssdeep": "6144:xySBYI5nomXZC0kOxFnkXdr0I8sUodCZc2hx+ut6EJH2Qg:xygYWomXA0kOxFnkB0IrUod6+Qg", "hash_imp": "FCE4B3FCE7172B533D57FCDAA56D92DC", "hash_pesha1": "C1BFD5249132400A2D93BCD924BE5A87B0F081D7", "hash_pe256": "67C084218E958144070384F101D15DA2C6A411D1778CFD679D205213F911AC2E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework PE, Metadata and IL Verification Tool", "meta_original_filename": "peverify.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/6c89fc6fa70130dff015271bfbb580bf100eaa3fc168b5bbd4b762e9cbefd251/detection", "output": "Invalid option: --help \r\n\r\n\r\nMicrosoft (R) .NET Framework PE Verifier. Version 4.0.30319.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: PEverify <image file> [Options]\r\n\r\n\r\nOptions:\r\n/IL Verify only the PE structure and IL\r\n/MD Verify only the PE structure and MetaData\r\n/TRANSPARENT Verify only transparent methods\r\n/UNIQUE Disregard repeating error codes\r\n/HRESULT Display error codes in hex format\r\n/CLOCK Measure and report verification times\r\n/IGNORE=<hex.code>[,<hex.code>...] Ignore specified error codes\r\n/IGNORE=@<file name> Ignore error codes specified in <file name>\r\n/QUIET Display only file and Status. Do not display all errors.\r\n/VERBOSE Display additional info in IL verification error messages.\r\n/NOLOGO Don't display product version and copyright info.\r\n\r\nNote: By default, MD is verified and then if there were no errors, IL is\r\n verified. If /MD /IL options are specified, IL is verified even if\r\n there were MD verification errors.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\PEVerify.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "sgen.exe-2B3AA895D991740E5F04B2DE825A41A4": { "file_name": "sgen.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\sgen.exe", "hash_md5": "2B3AA895D991740E5F04B2DE825A41A4", "hash_sha1": "7E464CB8DBE13FB89EDCF3FB9FAF979810A2611F", "hash_sha256": "1418BB188E22F5EE1210EDEEA96387A4FB3C37D1FB089CBC9CE2E016DFF0C096", "hash_sha384": "146CC92FEC773FE38DCF782242AC3BB2E25B405762C17CF370CE09928CF5864602FB7F2D20AB3FEBEB2F834CDB5D1C3D", "hash_sha512": "60CAFE735684C434707510015B1C1D19BDC2632F836618B4CA2592520E4434A4D0B95E13C5CFAD2C3EC8B49DABEF3E41F9C7A775279772FEAFE09C03EBB1B4AB", "hash_ssdeep": "768:yQC5IzfNcYPWpZbFdlHDqCUh6Iq8zNGOxyQIIIIvGdjpqW1m8eHCL0:w5IzfGmWpZxd52CUoKEO+drd+", "hash_imp": "n/a", "hash_pesha1": "5347D603057E208A0127755E51DBB1C754D0F7E2", "hash_pe256": "D3A0652045A4ACB7F5DF122ED231A0551A26F81A3D37C14D09D1D128BC1DDE07", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Frameworks Xml serialization assembly generation Tool", "meta_original_filename": "sgen.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/1418bb188e22f5ee1210edeea96387a4fb3c37d1fb089cbc9ce2e016dff0c096/detection", "output": "Microsoft (R) Xml Serialization support utility\r\n[Microsoft (R) .NET Framework, Version 4.8.4084.0]\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nGenerates serialization assemblies for use with XmlSerializer.\r\nThe utility allows developers to pre-generate assemblies for serialization\r\nand deploying the assemblies with the application.\r\n\r\nUsage: sgen.exe [[/assembly:<assembly name>] | [<assembly file location>]]\r\n [/type:] [/reference:] [/compiler:] [/debug] [/keep] [/nologo]\r\n [/silent] [/verbose]\r\n\r\n\r\n Developer options:\r\n /assembly: Assembly location or display name. Short form is '/a:'.\r\n /type: Generate code for serialization/deserialization of the\r\n specified type from the input assembly. Short form is '/t:'.\r\n /reference: Reference metadata from the specified assembly files.\r\n Short form is '/r:'.\r\n /compiler: Visual C# compiler options to use while compiling generated\r\n code. Short form is '/c'.\r\n For complete list of available options see c# compiler help.\r\n /proxytypes Generate serialization code only for proxy classes and web\r\n method parameters. Short form is '/p'.\r\n /debug Generate image which can be used under a debugger.\r\n Short form is '/d'.\r\n /keep Keep source code and compiler temp files. Short form is '/k'.\r\n /force Forces overwrite of a previously generated assembly.\r\n Short form is '/f'.\r\n /out: Output directory name (default: target assembly location).\r\n Short form is '/o:'.\r\n /parsableerrors\r\n Print errors in a format similar to those reported by\r\n compilers.\r\n\r\n Miscellaneous options:\r\n /? or /help Show this message\r\n /nologo Prevents displaying of logo. Short form is '/n'.\r\n /silent Prevents displaying of success messages. Short form is '/s'.\r\n /verbose Displays verbose output for debugging. Short form is '/v'.\r\n List types from the target assembly that cannot be serialized\r\n with XmlSerializer.\r\n", "error": "Warning: Ignoring invalid command line argument: '--help'.\r\nMissing required command-line argument: The name of the source assembly.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\sgen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "sn.exe-FDC3ABAA5F2D644FE4AC1D8FA8AB7A91": { "file_name": "sn.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\sn.exe", "hash_md5": "FDC3ABAA5F2D644FE4AC1D8FA8AB7A91", "hash_sha1": "E08E276311CA6FC3E1D694E64860998D8E2A57AC", "hash_sha256": "6ADC7DA3C691C8834A68BBF03EB06D15B586997BBCE3C83B5AA4BDF063BC1F37", "hash_sha384": "440ECC37EA2B581DEF4843511365D7B1BD6B103E1970D4EA97D5B8C0BE62B3F60B1C0357B6083BAB4530315D320626BA", "hash_sha512": "F78E50F70D433DD8FCC9D6361E2CD02DD18D6B9E155A4BB43466BAA9F5A0215FF4C72BAB08122ED6E7B445CF579109796680F9889F2F928544C377C21D6A9892", "hash_ssdeep": "6144:mHmQxK0/49qukbQNbW6rGXqqocVdmw1a9/x7fHh0ek3c:mG70/4Y7bQNbW6qXWTt5tks", "hash_imp": "4D928D7489AFD656BEE49BE7D560585F", "hash_pesha1": "C545E03E8D3D4E771C3CFAD84CB290A691449F45", "hash_pe256": "CB7B580FF6DBA89A9FEB31CE08886702B51120948956A00318C046A67F540328", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Strong Name Utility", "meta_original_filename": "sn.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/6adc7da3c691c8834a68bbf03eb06d15b586997bbce3c83b5aa4bdf063bc1f37/detection", "output": "\r\nMicrosoft (R) .NET Framework Strong Name Utility Version 4.0.30319.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: sn [-q|-quiet] <option> [<parameters>]\r\n Options:\r\n -a identityPublicKeyFile identityKeyPairFile signaturePublicKeyFile\r\n Generate AssemblySignatureKeyAttribute data to migrate the identity key to the signature key from a file.\r\n -ac identityPublicKeyFile identityKeyPairContainer signaturePublicKeyFile\r\n Generate AssemblySignatureKeyAttribute data to migrate the identity key to the signature key from a key container.\r\n -c [<csp> [<provtype>] ] \r\n Set/reset the name of the CSP to use for MSCORSN operations.\r\n -d <container>\r\n Delete key container named <container>.\r\n -dg <assembly> <digest file> [-rehash]\r\n Compute the digest of an assembly, generating a digest file for signing by\r\n the -ds or -dsc commands.\r\n If -rehash is specified, modules are re-hashed before digest calulation\r\n -ds <digest file> <keyfile> [-ecma]\r\n Sign a digest file generated by the -dg command using the full key pair\r\n from the given key file.\r\n If -ecma is used, keyfile is treated as the real key for ECMA signing.\r\n -dsc <digest file> <container> [-ecma]\r\n Sign a digest filegenerated by the -dg command using the key in the\r\n specified key container.\r\n If -ecma is used, container is treated as the real key for ECMA signing.\r\n -di <digest file> <assembly>\r\n Insert the signature from the digest file signed by the -ds or -dsc\r\n commands into the assembly.\r\n -dh <digest file> <hash file>\r\n Extract the base64 encoded hash value from the digest file\r\n -du <signature file> <digest file>\r\n Update the signature in the digest file with a base64 encoded signature\r\n in a signature file. WARNING: using this operation may result in a digest\r\n file that contains an invalid signature for its corresponding assembly.\r\n -dd <digest file>\r\n Dump the digest file to the console\r\n -D <assembly1> <assembly2>\r\n Verify <assembly1> and <assembly2> differ only by signature.\r\n -e <assembly> <outfile>\r\n Extract public key from <assembly> into <outfile>.\r\n -i <infile> <container>\r\n Install key pair from <infile> into a key container named <container>.\r\n -k [<keysize>] <outfile>\r\n Generate a new key pair of the specified size and write it into <outfile>.\r\n -m [y|n]\r\n Enable (y), disable (n) or check (no parameter) whether key containers\r\n are machine specific (rather than user specific).\r\n -o <infile> [<outfile>]\r\n Convert public key in <infile> to text file <outfile> with comma separated\r\n list of decimal byte values.\r\n If <outfile> is omitted, text is copied to clipboard instead.\r\n -p <infile> <outfile> [<hashalg>]\r\n Extract public key from key pair in <infile> and export to <outfile>,\r\n embedding the specified hash algorithm (sha1|sha256|sha384|sha512).\r\n -pc <container> <outfile> [<hashalg>]\r\n Extract public key from key pair in <container> and export to <outfile>,\r\n embedding the specified hash algorithm (sha1|sha256|sha384|sha512).\r\n -Pb [y|n]\r\n Enable (y), disable (n) or check (no parameters) the CLR policy allowing\r\n trusted applications to bypass strong name signature verification on their\r\n assemblies.\r\n -q\r\n Quiet mode. This option must be first on the command line and will suppress\r\n any output other than error messages.\r\n -R[a] <assembly> <infile> [-ecma]\r\n Re-sign signed or partially signed assembly with the key pair in <infile>.\r\n If -Ra is used, hashes are recomputed for all files in the assembly.\r\n If -ecma is used, infile is treated as the real key for ECMA signing.\r\n -Rc[a] <assembly> <container> [-ecma]\r\n Re-sign signed or partially signed assembly with the key pair in the key\r\n container named <container>.\r\n If -Rca is used, hashes are recomputed for all files in the assembly.\r\n If -ecma is used, container is treated as the real key for ECMA signing.\r\n -Rh <assembly>\r\n Re-compute hashes for all files in the assembly.\r\n -t[p] <infile>\r\n Display token for public key in <infile> (together with the public key\r\n itself if -tp is used).\r\n -T[p] <assembly>\r\n Display token for public key of <assembly> (together with the public key\r\n itself if -Tp is used).\r\n -TS <assembly> <infile>\r\n Test-sign signed or partially signed assembly with the key pair in \r\n <infile>.\r\n -TSc <assembly> <container>\r\n Test-sign signed or partially signed assembly with the key pair in the key\r\n container named <container>.\r\n -v[f] <assembly> [{-ecmakey <keyfile> | -ecmacontainer <container>}]\r\n Verify <assembly> for strong name signature self consistency. If -vf is\r\n specified, force verification even if disabled in the registry.\r\n If -ecmakey is specified, keyfile is treated as the real ECMA key.\r\n If -ecmacontainer is specified, container is treated as the real ECMA key.\r\n -Vk <regfile> <assembly> [<userlist>] [<testkey>]\r\n Generate a registry script in <regfile> to register <assembly> for\r\n verification skipping (with an optional, comma separated list of usernames\r\n for which this will take effect and an optional test public key in\r\n <testkey>). <assembly> can be specified as * to indicate all assemblies or\r\n *,<public key token> to indicate that all assemblies with the given public\r\n key token. Public key tokens should be specified as a string of hex digits.\r\n -Vl\r\n List current settings for strong name verification on this machine.\r\n -Vr <assembly> [<userlist>] [<infile>]\r\n Register <assembly> for verification skipping (with an optional, comma\r\n separated list of usernames for which this will take effect and an\r\n optional test public key in <infile>).\r\n <assembly> can be specified as * to indicate all assemblies or *,<public key token> to\r\n indicate that all assemblies with the given public key token. Public key\r\n tokens should be specified as a string of hex digits.\r\n -Vu <assembly>\r\n Unregister <assembly> for verification skipping. The same rules for\r\n <assembly> naming are followed as for -Vr.\r\n -Vx\r\n Remove all verification skipping entries.\r\n -?\r\n -h\r\n Displays this help text.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\sn.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "SvcUtil.exe-A4453C2ED9B130AAC6860E8410799F1F": { "file_name": "SvcUtil.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\SvcUtil.exe", "hash_md5": "A4453C2ED9B130AAC6860E8410799F1F", "hash_sha1": "50208B407ECB23A4EC2D7418A471E59BB06AD114", "hash_sha256": "6793C7139163A02A67EB0380A462025DC10748837AAA25AB5DE16ADADFA13927", "hash_sha384": "AD32E4C66A97C5609C352AF22BB875923C1B99064BA41386AAF9C1A7AFB92A261D70EFF6603217A325CF823C207C9115", "hash_sha512": "1E0EF91CF9C4A7C7F20856A68DC3E4D5DF7A9635861C04B47E46CEA9FC25FDC0901DD6EC5B07B8CFD81F5A34DA67F9B3094DDAAB19CB8CCF9AACF64B06492AF1", "hash_ssdeep": "3072:CysdQTmv0xhnwz/cHYePxMdU0xgN8gJh2y64vlli7/qUH+Pz/tYWvyH:UCTJLwz/c4ePxhnLy", "hash_imp": "n/a", "hash_pesha1": "A2B96FAF4DBEB62E21120ADF7740731CB8E8ABB5", "hash_pe256": "E879F68885015AC0B96134894B3932C19AE4292AA45E74E0D5972DB8E402BD6B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "svcutil.exe", "meta_original_filename": "svcutil.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/6793c7139163a02a67eb0380a462025dc10748837aaa25ab5de16adadfa13927/detection", "output": "Microsoft (R) Service Model Metadata Tool\r\n[Microsoft (R) Windows (R) Communication Foundation, Version 4.8.4084.0]\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUSES:\r\n\r\n - Generate code from running services or static metadata documents. \r\n - Export metadata documents from compiled code.\r\n - Validate compiled service code.\r\n - Download metadata documents from running services.\r\n - Pre-generate serialization code.\r\n\r\n\r\n -= COMMON OPTIONS =-\r\n\r\nOptions:\r\n\r\n /target:<output type> - The target output for the tool: code, metadata or xmlSerializer.\r\n /directory:<directory> - Directory to create files in (default: current directory) (Short Form: /d)\r\n\r\n /svcutilConfig:<configFile> - Custom configuration file to use in place of the app config file. This can be used to register system.serviceModel extensions without altering the tool's config file.\r\n /noLogo - Suppress the copyright and banner message.\r\n /help - Display command syntax and options for the tool. (Short Form: /?)\r\n\r\n\r\n\r\n -= CODE GENERATION =-\r\n\r\nDescription: svcutil.exe can generate code for service contracts, clients and data types from metadata documents. These metadata documents can be on disk or retrieved online. Online retrieval follows either the WS-Metadata Exchange protocol or the DISCO protocol.\r\n\r\nSyntax: svcutil.exe [/t:code] <metadataDocumentPath>* | <url>* | <epr>\r\n\r\n <metadataDocumentPath> - The path to a metadata document (wsdl or xsd). Standard command-line wildcards can be used in the file path.\r\n <url> - The URL to a service endpoint that provides metadata or to a metadata document hosted online. For more information on how these documents are retrieved see the Metadata Download section.\r\n <epr> - The path to an XML file that contains a WS-Addressing EndpointReference for a service endpoint that supports WS-Metadata Exchange. For more information see the Metadata Download section.\r\n\r\nOptions:\r\n\r\n /out:<file> - The filename for the generated code. Default: derived from the WSDL definition name, WSDL service name or targetNamespace of one of the schemas. (Short Form: /o)\r\n /config:<configFile> - The filename for the generated config file. Default: output.config\r\n /mergeConfig - Merge the generated config into an existing file instead of overwriting the existing file.\t\r\n /noConfig - Do not generate config\r\n /dataContractOnly - Generate code for Data Contract types only. Service Contract types will not be generated. (Short Form: /dconly)\r\n\r\n /language:<language> - The programming language to use for generating code. Provide either a language name registered in the machine.config file or provide the fully-qualified name of a class that inherits from System.CodeDom.Compiler.CodeDomProvider. Examples of language names to use are CS and VB. Default: C#. (Short Form: /l)\r\n /namespace:<string,string> - A mapping from a WSDL or XML Schema targetNamespace to a CLR namespace. Using the '*' for the targetNamespace maps all targetNamespaces without an explicit mapping to that CLR namespace. Default: derived from the target namespace of the schema document for Data Contracts. The default namespace is used for all other generated types. (Short Form: /n)\r\n\r\n /messageContract - Generate Message Contract types. (Short Form: /mc)\r\n /enableDataBinding - Implement the System.ComponentModel.INotifyPropertyChanged interface on all Data Contract types to enable data binding. (Short Form: /edb)\r\n /serializable - Generate classes marked with the Serializable Attribute. (Short Form: /s)\r\n /async - Generate both synchronous and begin/end asynchronous method signatures. Default: generate synchronous and task-based asynchronous method signatures. (Short Form: /a)\r\n /internal - Generate classes that are marked as internal. Default: generate public classes. (Short Form: /i)\r\n\r\n /reference:<file path> - Reference types in the specified assembly. When generating clients, use this option to specify assemblies that might contain types representing the metadata being imported. (Short Form: /r)\r\n /collectionType:<type> - A fully-qualified or assembly-qualified name of the type to use as a collection data type when code is generated from schemas. (Short Form: /ct)\r\n /excludeType:<type> - A fully-qualified or assembly-qualified type name to exclude from referenced contract types. (Short Form: /et)\r\n /noStdLib - Do not reference standard libraries. By default mscorlib.dll and system.servicemodel.dll are referenced.\r\n\r\n /serializer:Auto - Automatically select the serializer. This tries to use the Data Contract serializer and uses the XmlSerializer if that fails. (Short Form: /ser)\r\n /serializer:DataContractSerializer - Generate data types that use the Data Contract Serializer for serialization and deserialization\r\n /serializer:XmlSerializer - Generate data types that use the XmlSerializer for serialization and deserialization\r\n /importXmlTypes - Configure the Data Contract serializer to import non-Data Contract types as IXmlSerializable types.\r\n /useSerializerForFaults - This option specifies whether the serializer specified in the 'serializer' switch is used for fault contract types. DataContractSerializer is used for faults if this switch is not specified. (Short Form: /fault)\r\n\r\n /targetClientVersion:Version30 - Generate code that references functionality in .NET Framework assemblies 3.0 and before. Use this switch if you are generating code for clients that use .NET Framework version 3.0.(Short Form: /tcv)\r\n /targetClientVersion:Version35 - Generate code that references functionality in .NET Framework assemblies 3.5 and before. Use this switch if you are generating code for clients that use .NET Framework version 3.5.(Short Form: /tcv)\r\n /wrapped - Generated code will not unwrap \"parameters\" member of document-wrapped-literal messages.\r\n /serviceContract - Generate code for Service Contracts. Client class and configuration will not be generated. (Short Form: /sc)\r\n /syncOnly - Generate only synchronous method signature. Default: generate synchronous and task-based asynchronous method signatures.\r\n\r\n\r\n\r\n -= METADATA EXPORT =-\r\n\r\nDescription: svcutil.exe can export metadata for services, contracts and data types in compiled assemblies. To export metadata for a service, you must use the /serviceName option to indicate the service you would like to export. To export all Data Contract types within an assembly use the /dataContractOnly option. By default metadata is exported for all Service Contracts in the input assemblies.\r\n\r\nSyntax: svcutil.exe [/t:metadata] [/serviceName:<serviceConfigName>] [/dataContractOnly] <assemblyPath>*\r\n\r\n <assemblyPath> - The path to an assembly that contains services, contracts or Data Contract types to be exported. Standard command-line wildcards can be used to provide multiple files as input.\r\n\r\nOptions:\r\n\r\n /serviceName:<serviceConfigName> - The config name of a service to export. If this option is used, an executable assembly with an associated config file must be passed as input. Svcutil will search through all associated config files for the service configuration. If the config files contain any extension types, the assemblies containing these types must either be in the GAC or explicitly provided using the /r option.\r\n /reference:<file path> - Add the specified assembly to the set of assemblies used for resolving type references. If you are exporting or validating a service that uses 3rd-party extensions (Behaviors, Bindings and BindingElements) registered in config use this option to locate extension assemblies that are not in the GAC. (Short Form: /r)\r\n /dataContractOnly - Operate on Data Contract types only. Service Contracts will not be processed. (Short Form: /dconly)\r\n /excludeType:<type> - The fully-qualified or assembly-qualified name of a type to exclude from export. This option can be used when exporting metadata for a service or a set of service contracts to exclude types from being exported. This option cannot be used with the /dconly option. (Short Form: /et)\r\n\r\n\r\n\r\n -= SERVICE VALIDATION =-\r\n\r\nDescription: Validation is useful to detect errors in service implementations without hosting the service. You must use the /serviceName option to indicate the service you would like to validate.\r\n\r\nSyntax: svcutil.exe /validate /serviceName:<serviceConfigName> <assemblyPath>*\r\n\r\n <assemblyPath> - The path to an assembly containing service types to be validated. The assembly must have an associated config file to provide service configuration. Standard command-line wildcards can be used to provide multiple assemblies.\r\n\r\nOptions:\r\n\r\n /validate - Validate a service implementation. To validate a service, you must use the /serviceName option to indicate the service you would like to validate. If this option is used, an executable assembly with an associated config file must be passed as input. (Short Form: /v)\r\n /serviceName:<serviceConfigName> - The config name of a service to validate. To validate a service this option must be provided. Svcutil will search through the associated config files of all input assemblies for the service configuration. If the associated configuration file contain any extension types, the assemblies containing these types must either be in the GAC or explicitly provided using the /r option.\r\n /reference:<file path> - Add the specified assembly to the set of assemblies used for resolving type references. If you are exporting or validating a service that uses 3rd-party extensions (Behaviors, Bindings and BindingElements) registered in config use this option to locate extension assemblies that are not in the GAC. (Short Form: /r)\r\n /dataContractOnly - Operate on Data Contract types only. Service Contracts will not be processed. (Short Form: /dconly)\r\n /excludeType:<type> - The fully-qualified or assembly-qualified name of a service type to exclude from validation. (Short Form: /et)\r\n\r\n\r\n\r\n -= METADATA DOWNLOAD =-\r\n\r\nDescription: svcutil.exe can be used to download metadata from running services and save the metadata to local files. To download metadata, you must explicitly specify the /t:metadata option. Otherwise, client code will be generated. For http and https URL schemes svcutil.exe will try to retrieve metadata using WS-Metadata Exchange and DISCO. For all other URL schemes svcutil.exe will only try WS-Metadata Exchange. By default, svcutil.exe uses the bindings defined in the System.ServiceModel.Description.MetadataExchangeBindings class. To configure the binding used for WS-Metadata Exchange you must define a client endpoint in config that uses the IMetadataExchange contract. This can be defined either in svcutil.exe's config file or in another config file specified using the /svcutilConfig option.\r\n\r\nSyntax: svcutil.exe /t:metadata <url>* | <epr>\r\n\r\n <url> - The URL to a service endpoint that provides metadata or an URL that points to a metadata document hosted online. \r\n <epr> - The path to an XML file that contains a WS-Addressing EndpointReference for a service endpoint that supports WS-Metadata Exchange.\r\n\r\n\r\n\r\n -= XMLSERIALIZER TYPE GENERATION =-\r\n\r\nDescription: svcutil.exe can pre-generate C# serialization code that is required for types that can be serialized using the XmlSerializer. svcutil.exe will only generate code for types used by Service Contracts found in the input assemblies.\r\n\r\nSyntax: svcutil.exe /t:xmlSerializer <assemblyPath>*\r\n\r\n <assemblyPath> - The path to an assembly containing Service Contract types. Serialization types will be generated for all Xml Serializable types in each contract\r\n\r\nOptions:\r\n\r\n /reference:<file path> - Add the specified assembly to the set of assemblies used for resolving type references. (Short Form: /r)\r\n /excludeType:<type> - Fully-qualified or assembly-qualified type name to exclude from export or validation. This option can be used when exporting metadata for a service or a set of service contracts to exclude types from being exported. This option cannot be used with the /dataContractOnly option. (Short Form: /et)\r\n /out:<file> - Filename for the generated code. This option will be ignored when multiple assemblies are passed as input to the tool. Default: derived from the assembly name. (Short Form: /o)\r\n\r\n\r\n\r\n -= EXAMPLES =-\r\n\r\n svcutil http://service/metadataEndpoint\r\n - Generate client code from a running service or online metadata documents.\r\n\r\n svcutil *.wsdl *.xsd /language:C#\r\n - Generate client code from local metadata documents.\r\n\r\n svcutil /dconly *.xsd /language:VB\r\n - Generate Data Contract types in VisualBasic from local schema documents.\r\n\r\n svcutil /t:metadata http://service/metadataEndpoint\r\n - Download metadata documents from running services\r\n\r\n svcutil myAssembly.dll\r\n - Generate metadata documents for Service Contracts and associated types in an assembly\r\n\r\n svcutil myServiceHost.exe /serviceName:myServiceName \r\n - Generate metadata documents for a service, and all associated Service Contracts and data types in an assembly\r\n\r\n svcutil myServiceHost.exe /dconly \r\n - Generate metadata documents for data types in an assembly\r\n\r\n svcutil /validate /serviceName:myServiceName myServiceHost.exe\r\n - Verify service hosting\r\n\r\n svcutil /t:xmlserializer myContractLibrary.exe\r\n - Generate serialization types for XmlSerializer types used by any Service Contracts in the assembly\r\n\r\n\r\n\r\n", "error": "Error: Cannot read help.\r\n\r\n Cannot load file C:\\Users\\user\\help as an Assembly. Check the FusionLogs for more Information.\r\n\r\n Could not load file or assembly 'file:///C:\\Users\\user\\help' or one of its dependencies. The module was expected to contain an assembly manifest.\r\n\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\SvcUtil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "TlbExp.exe-6B0D1377AB15A4F9B408E3DC1098036C": { "file_name": "TlbExp.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\TlbExp.exe", "hash_md5": "6B0D1377AB15A4F9B408E3DC1098036C", "hash_sha1": "DD456F55EBCF42C3843A8F718A6820B0D18CEE4B", "hash_sha256": "60A2BDE6B8EEA903DD00660B9F9500BB9664004A13F62C9272B5ADB28F008BDD", "hash_sha384": "127B1E2C7BA2852AB975CD2F5510BBCC7B5CC1386A58DD2120C333DE377ACF9D6D57AA22A684057FFE599CB209FB6DE0", "hash_sha512": "3E7CECD0B434179111A4DF2664E9EAF55664F88AAA2C57EADFBDAD90A9DA5E9496FD7C16208D27A19C26FEC47330CC46229B7580BD6F8E678B72A9BA396FB72F", "hash_ssdeep": "1536:sN2wX1c9RNBx6IqvdG5xb2Hf0VDSqgD2LJ6lXz8kZal+:Xwy9RNBgIqvdG5xb2HfUDSFD2LJ6lXzt", "hash_imp": "n/a", "hash_pesha1": "47611A1AF4ECD45CF0581C5F69AC9196E0A72CD7", "hash_pe256": "1E363CB7C1627123DE2839FA9D0029BBE341A269020023387A1B28A9DAD9BA19", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Assembly to Type Library Converter", "meta_original_filename": "TlbExp.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/60a2bde6b8eea903dd00660b9f9500bb9664004a13f62c9272b5adb28f008bdd/detection", "output": "Microsoft (R) .NET Framework Assembly to Type Library Converter 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nSyntax: TlbExp AssemblyName [Options]\r\nOptions:\r\n /out:FileName File name of type library to be produced\r\n /tlbreference:TypeLibrary Type library used to resolve references\r\n /tlbrefpath:Path Path used to resolve referenced type libraries\r\n /asmpath:Directory Look for assembly references here\r\n /win32 Create a 32-bit type library\r\n /win64 Create a 64-bit type library\r\n /oldnames Do not ignore COM invisible types when\r\n decorating names (old-rules)\r\n /nologo Prevents TlbExp from displaying logo\r\n /silent Suppresses all output except for errors\r\n /silence:WarningNumber Suppresses output for the given warning \r\n (Can not be used with /silent)\r\n /verbose Displays extra information\r\n /names:FileName A file in which each line specifies the\r\n capitalization of a name in the type library.\r\n /? or /help Display this usage message\r\n", "error": "TlbExp : error TX0000 : Could not load file or assembly 'file:///C:\\Users\\user\\help' or one of its dependencies. The module was expected to contain an assembly manifest.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\TlbExp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "TlbImp.exe-51E5E1DD5D979152AB92DFF0B0EA292B": { "file_name": "TlbImp.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\TlbImp.exe", "hash_md5": "51E5E1DD5D979152AB92DFF0B0EA292B", "hash_sha1": "0B289B921EA567921138B069E76B5AC9AAF4B819", "hash_sha256": "B03269A241B248F8703D0EEF439B5318A3F53B2D26BDB2DDB9B771ABC5074407", "hash_sha384": "0549108EBDC23277BF977B3289ED6B6E7B526323321F2C4A079259FF9C821CE27718381D6A2EE74CDB3414C37CCF3917", "hash_sha512": "95FB5942BC9AFF6BFAB5514080F47F24C845B4C36E2E7358B8D665D55D9A21E53B890646CAEAE8007FD34D0099E3CBF1859B4734B3947AB449756C2E53DCC6A4", "hash_ssdeep": "3072:/0z3mZJiOWFd83yPdQ2l5EmsFFIZupGCFFHqdFdJ4U8hWFUy1vVwKwDr61jREyIA:/0z3fOW/dr5/sFlJ/4Vwt6v1IA", "hash_imp": "n/a", "hash_pesha1": "ACEF56EA4827AEA3C97911D9B54D325CC952427D", "hash_pe256": "D743E0B9418E0A1B0E882D065561D1F3C3B4157FE6EFDA84A74A1D1478A1BF7E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Assembly to Type Library Converter", "meta_original_filename": "TlbImp.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/b03269a241b248f8703d0eef439b5318a3f53b2d26bdb2ddb9b771abc5074407/detection", "output": "Microsoft (R) .NET Framework Type Library to Assembly Converter 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nSyntax: TlbImp TypeLibName [Options]\r\nOptions:\r\n /out:FileName File name of assembly to be produced\r\n /namespace:Namespace Namespace of the assembly to be produced\r\n /asmversion:Version Version number of the assembly to be produced\r\n /reference:FileName File name of assembly to use to resolve references\r\n /tlbreference:FileName File name of typelib to use to resolve references\r\n /publickey:FileName File containing strong name public key\r\n /keyfile:FileName File containing strong name key pair\r\n /keycontainer:FileName Key container holding strong name key pair\r\n /delaysign Force strong name delay signing\r\n /product:Product The name of the product with which this assembly\r\n is distributed\r\n /productversion:Version The version of the product with which this\r\n assembly is distributed\r\n /company:Company The name of the company that produced this\r\n assembly\r\n /copyright:Copyright Describes all copyright notices, trademarks, and\r\n registered trademarks that apply to this assembly\r\n /trademark:Trademark Describes all trademarks and registered trademarks\r\n that apply to this assembly\r\n /unsafe Produce interfaces without runtime security checks\r\n /noclassmembers Prevents TlbImp from adding members to classes\r\n /nologo Prevents TlbImp from displaying logo\r\n /silent Suppresses all output except for errors\r\n /silence:WarningNumber Suppresses output for the given warning (Can not \r\n be used with /silent)\r\n /verbose Displays extra information\r\n /primary Produce a primary interop assembly\r\n /sysarray Import SAFEARRAY as System.Array\r\n /machine:MachineType Create an assembly for the specified machine type\r\n /transform:TransformName Perform the specified transformation\r\n /strictref Only use assemblies specified using /reference and\r\n registered PIAs\r\n /strictref:nopia Only use assemblies specified using /reference and\r\n ignore PIAs\r\n /VariantBoolFieldToBool Convert VARIANT_BOOL field in structures to bool.\r\n /Legacy35 Use legacy TlbImp 3.5 behavior.\r\n /? or /help Display this usage message\r\n\r\nThe assembly version must be specified as: Major.Minor.Build.Revision.\r\n\r\nMultiple reference assemblies can be specified by using the /reference option\r\nmultiple times.\r\n\r\nSupported machine types:\r\n X86\r\n X64\r\n Itanium\r\n ARM\r\n Agnostic\r\n\r\nSupported transforms:\r\n SerializableValueClasses Mark all value classes as serializable\r\n DispRet Apply the [out, retval] parameter transformation\r\n to methods of disp only interfaces\r\n\r\nA resource ID can optionally be appended to the TypeLibName when importing a\r\ntype library from a module containing multiple type libraries.\r\n example: TlbImp MyModule.dll\\1\r\n", "error": "TlbImp : error TI1002 : The input file 'C:\\Users\\user\\help' is not a valid type library.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\TlbImp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "Tracker.exe-19426C1DF6876C3DBF0331953C8FACA2": { "file_name": "Tracker.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\Tracker.exe", "hash_md5": "19426C1DF6876C3DBF0331953C8FACA2", "hash_sha1": "721DA7021D3F837CD9154F34614C324DB75935EC", "hash_sha256": "63BB4ECF8C913B79473CC9AFB38FD77B63FBFDE3750EC1E937315631FB6E0D80", "hash_sha384": "4884D828B4DC33A557422B59BC45D6674827CEDE95FD27BBAB679DD0DEC52A27F95DCE82180E634A023503A16A114873", "hash_sha512": "52F724DCCE76BCDCE37030F71130CA5B65A57BF719A896047532344300E21187917762E2877ED85D9B8EF187B4464F185DE972098274DD82571BC8F69CB287BB", "hash_ssdeep": "3072:YQpnY7lL/+uDb38Bns1C4vAzE402o3ng5bHqrTu+dor/9ZWBiZK:YQpeL/+2T8BgZvAdLo3nD8/9kBis", "hash_imp": "05F2874F08228C142185ADBDAA336B88", "hash_pesha1": "16458E16F10A14BE068FF5B7B465C4C7D44F55A4", "hash_pe256": "83C77820D44E6A5F2898AD579C5D0A73489E2462B40A2BCC286C9ACB9622C76B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Tracker", "meta_original_filename": "Tracker.exe", "meta_product_name": "Microsoft .NET Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.8.4084.0 built by: NET48REL1", "meta_product_version": "14.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/63bb4ecf8c913b79473cc9afb38fd77b63fbfde3750ec1e937315631fb6e0d80/detection", "error": "TRACKER : error TRK0000: Bad argument: --help\r\nMicrosoft (R) Build (MSBuild) File Tracker Version 4.0.30319\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\nSyntax:\r\n Tracker.exe [options] [@tracker-response-file] /c [command-line]\r\n\r\nSwitches:\r\n\r\n /d file.dll : Start the process with the tracking dll file.dll.\r\n (default: FileTracker.dll from the PATH)\r\n\r\n /i[f] <path> : Intermediate directory for tracking log output.\r\n (using /if will expand the path to full immediately)\r\n (default: current directory in tracked process)\r\n\r\n /o : Track operations performed on each file\r\n\r\n /m : Include missing files in tracking logs\r\n i.e. those that are deleted before process closes\r\n\r\n /u : Do not remove duplicate file operations from the\r\n tracking log.\r\n\r\n /t : Track command lines (will expand response files\r\n specified with the '@filename' syntax)\r\n\r\n /a : Enable extended tracking: GetFileAttributes,\r\n GetFileAttributesEx\r\n\r\n /e : Enable extended tracking: GetFileAttributes,\r\n GetFileAttributesEx, RemoveDirectory, CreateDirectory\r\n\r\n /k : Keep the full tool chain in tlog filenames.\r\n\r\n /r file1;file2;..;filen : Root primary input file(s) being tracked\r\n (default: none)\r\n\r\n /c [command-line] : Command to be tracked (must be the last argument).\r\n\r\n /? : This help text.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\Tracker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wsdl.exe-C4E29F9BC7CBDE52C072F9C0D3B81799": { "file_name": "wsdl.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\wsdl.exe", "hash_md5": "C4E29F9BC7CBDE52C072F9C0D3B81799", "hash_sha1": "8F52AC40C93CE89C0DA39E363D3A9D90854EE87D", "hash_sha256": "E3E72E69D3EB165F873C5DC55CC1D35AA8CECF1B7ACBD2663B2BB529B8E61BA9", "hash_sha384": "37E9B555B40D4349CB6AC014D72FA97A6000F2A43E6E765E41673E0D35D04C63A01F921BB5E925F10FB18ADFE84A7B4E", "hash_sha512": "081C14333DF92371992DAFF1F37B36183029B1AE1E9B40B7FC4326534808D78C9ADD46D1AED9F55E89217A5D37DE14C23D7B5230DC36C7B88DFE032628AB1C92", "hash_ssdeep": "1536:Nu190NfjB1B+DRBz0B2lU/DWZiSwWN/lPqlMw8MTIBvdu0HfYcVOuPaJ3j:nNfjB1B+DRBoB2palMo6dPxJah", "hash_imp": "n/a", "hash_pesha1": "516E3FC881E296583E9D734D282E8152A218050D", "hash_pe256": "F38CC75B926CF99B83F48A9FEF2567ED0FBECCAE1AA9380787770333CC087020", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Frameworks WebService install and administration tool", "meta_original_filename": "wsdl.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/e3e72e69d3eb165f873c5dc55cc1d35aa8cecf1b7acbd2663b2bb529b8e61ba9/detection", "output": "Microsoft (R) Web Services Description Language Utility\r\n[Microsoft (R) .NET Framework, Version 4.8.4084.0]\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nwsdl.exe -\r\n Utility to generate code for xml web service clients and xml web services\r\n using ASP.NET from WSDL contract files, XSD schemas and .discomap\r\n discovery documents. This tool can be used in conjunction with disco.exe.\r\n\r\nwsdl.exe <options> <url or path> <url or path> ...\r\n\r\n - OPTIONS -\r\n\r\n<url or path> -\r\n A url or path to a WSDL contract, an XSD schema or .discomap document.\r\n\r\n/nologo\r\n Suppresses the banner.\r\n\r\n/language:<language>\r\n The language to use for the generated proxy class. Choose from 'CS',\r\n 'VB', 'JS', 'VJS', 'CPP' or provide a fully-qualified name for a class\r\n implementing System.CodeDom.Compiler.CodeDomProvider. The default\r\n language is 'CS' (CSharp). Short form is '/l:'.\r\n\r\n/sharetypes\r\n Turns on type sharing feature. This feature creates one code file with\r\n a single type definition for identical types shared between different\r\n services (namespace, name and wire signature must be identical).\r\n Reference the services with http:// URLs as command-line parameters\r\n or create a discomap document for local files.\r\n\r\n/verbose\r\n Displays extra information when the /sharetypes switch is specified.\r\n Short form is '/v'.\r\n\r\n/fields\r\n Generate fields instead of properties. Short form is '/f'.\r\n\r\n/order\r\n Generate explicit order identifiers on particle members.\r\n\r\n/enableDataBinding\r\n Implement INotifyPropertyChanged interface on all generated types\r\n to enable data binding. Short form is '/edb'.\r\n\r\n/namespace:<namespace>\r\n The namespace for the generated proxy or template. The default namespace\r\n is the global namespace. Short form is '/n:'.\r\n\r\n/out:<fileName|directoryPath>\r\n The filename or directory path for the generated proxy code. The default\r\n filename is derived from the service name. Short form is '/o:'.\r\n\r\n/protocol:<protocol>\r\n Override the default protocol to implement. Choose from 'SOAP',\r\n 'SOAP12', 'HttpGet', 'HttpPost'.\r\n\r\n/username:<username>\r\n/password:<password>\r\n/domain:<domain>\r\n The credentials to use when connecting to a server that\r\n requires authentication. Short forms are '/u:', '/p:' and '/d:'.\r\n\r\n/proxy:<url>\r\n The url of the proxy server to use for http requests.\r\n The default is to use the system proxy setting.\r\n\r\n/proxyusername:<username>\r\n/proxypassword:<password>\r\n/proxydomain:<domain>\r\n The credentials to use when the connecting to a proxy server that\r\n requires authentication. Short forms are '/pu:', '/pp:' and '/pd:'.\r\n\r\n/appsettingurlkey:<key>\r\n The configuration key to use in the code generation to read the default\r\n value for the Url property. The default is to not read from the config\r\n file. Short form is '/urlkey:'.\r\n\r\n/appsettingbaseurl:<baseurl>\r\n The base url to use when calculating the url fragment. The\r\n appsettingurlkey option must also be specified. The url fragment is\r\n the result of calculating the relative url from the appsettingbaseurl\r\n to the url in the WSDL document. Short form is '/baseurl:'.\r\n\r\n/parsableerrors\r\n Print errors in a format similar to those reported by compilers.\r\n\r\n - ADVANCED -\r\n\r\n/server\r\n Server switch has been deprecated. Please use /serverInterface instead.\r\n Generate an abstract class for an xml web service implementation using\r\n ASP.NET based on the contracts. The default is to generate client proxy\r\n classes.\r\n\r\n/serverInterface\r\n Generates interfaces for server-side implementation of an ASP.Net \r\n Web Service. An interface is generated for each binding in the wsdl \r\n document(s). The wsdl alone implements the wsdl contract (classes \r\n that implement the interface should not include either of the following\r\n on the class methods: Web Service attributes or Serialization \r\n attributes that change the wsdl contract). Short form is '/si'.\r\n\r\n/parameters:<file>\r\n Read command-line options from the specified xml file. This allows you\r\n to specify options not available from command line such as choosing\r\n which type of asynchronous programming model is generated. For details,\r\n please see the tool documentation. Short form is '/par:'.\r\n", "error": "Error: File 'help' missing a file extension.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\wsdl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "xsd.exe-0265FFFC84FCD1C9585A1F1E2F78BFCC": { "file_name": "xsd.exe", "file_path": "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\xsd.exe", "hash_md5": "0265FFFC84FCD1C9585A1F1E2F78BFCC", "hash_sha1": "D10F74394E40F87256B1BCB28FCE05A36A9C44B6", "hash_sha256": "212B8FBFF65F4B911FF30A07F5600698825822FF935B5C3BCA474B16D7FDF1C7", "hash_sha384": "4C70CCCD8102C4008263A2FF67F8C8ABD69F88A21B33423551C9471D3B182E5D282B81F90B466D178141A78788C773EA", "hash_sha512": "328B0E4FE768CEA06A06110A4B051F8A6713AD972DE69240374432C496A850EDF84FC5A7D712AE5CD6A1414F2108BD5B499D2912ACA4CC802DF00D374E644FB9", "hash_ssdeep": "1536:RQipoylcELO4r4MyoYvTFdryG2YCrNHuhb5YGB:UI4tHvZdFAchb", "hash_imp": "n/a", "hash_pesha1": "440466790E31EDCDDE61A78E296A5A8ACE9DA3E7", "hash_pe256": "E38FC1E512FA9A0BF461863688B5C0FAF239305A7D510E57604A75616819DF7A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001519E8D8F4071A30E41000000000151", "signature_thumbprint": "62009AAABDAE749FD47D19150958329BF6FF4B34", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Frameworks Xml Schema Tool", "meta_original_filename": "xsd.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/212b8fbff65f4b911ff30a07f5600698825822ff935b5c3bca474b16d7fdf1c7/detection", "output": "Microsoft (R) Xml Schemas/DataTypes support utility\r\n[Microsoft (R) .NET Framework, Version 4.8.4084.0]\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nxsd.exe -\r\n Utility to generate schema or class files from given source.\r\n\r\nxsd.exe <schema>.xsd /classes|dataset [/e:] [/l:] [/n:] [/o:] [/s] [/uri:]\r\nxsd.exe <assembly>.dll|.exe [/outputdir:] [/type: [...]]\r\nxsd.exe <instance>.xml [/outputdir:]\r\nxsd.exe <schema>.xdr [/outputdir:]\r\n\r\n - OPTIONS -\r\n\r\n/classes\r\n Generate classes for this schema. Short form is '/c'.\r\n\r\n/dataset\r\n Generate sub-classed DataSet for this schema. Short form is '/d'.\r\n\r\n/enableLinqDataSet\r\n Generate LINQ-enabled sub-classed Dataset for the schemas provided. Short form is '/eld'.\r\n\r\n/element:<element>\r\n Element from schema to process. Short form is '/e:'.\r\n\r\n/fields\r\n Generate fields instead of properties. Short form is '/f'.\r\n\r\n/order\r\n Generate explicit order identifiers on all particle members.\r\n\r\n/enableDataBinding\r\n Implement INotifyPropertyChanged interface on all generated types\r\n to enable data binding. Short form is '/edb'.\r\n\r\n/language:<language>\r\n The language to use for the generated code. Choose from 'CS', 'VB', 'JS',\r\n 'VJS', 'CPP' or provide a fully-qualified name for a class implementing\r\n System.CodeDom.Compiler.CodeDomProvider. The default language\r\n is 'CS' (CSharp). Short form is '/l:'.\r\n\r\n/namespace:<namespace>\r\n The namespace for generated class files. The default namespace\r\n is the global namespace. Short form is '/n:'.\r\n\r\n/nologo\r\n Suppresses the banner.\r\n\r\n/out:<directoryName>\r\n The output directory to create files in. The default\r\n is the current directory. Short form is '/o:'.\r\n\r\n/type:<type>\r\n Type from assembly to generate schema for. Multiple types may be provided.\r\n If no types are provided, then schemas for all types in an assembly\r\n are generated. Short form is '/t:'.\r\n\r\n/uri:<uri>\r\n Uri of elements from schema to process. Short form is '/u:'.\r\n\r\n - ADVANCED -\r\n\r\n/parameters:<file>\r\n Read command-line options from the specified xml file. Short form is '/p:'.\r\n\r\n - ARGUMENTS -\r\n<schema>.xsd Name of a schema containing elements to import.\r\n<assembly>.dll|exe Name of an assembly containing types to generate schema for.\r\n<instance>.xml Name of an xml file to infer xsd schema from.\r\n<schema>.xdr Name of an xdr schema to convert to xsd.\r\nMultiple file arguments of the same type may be provided.\r\n", "children": "Fondue.exe", "error": "Error: invalid command line argument: '--help'.\r\n", "runtime_modules": [ "C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\x64\\xsd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "bcp.exe-7AA08BDEF40632D26C957C0D02441C6A": { "file_name": "bcp.exe", "file_path": "C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe", "hash_md5": "7AA08BDEF40632D26C957C0D02441C6A", "hash_sha1": "1173D94349566014D7443E30A6A74E6C0C7BFB9C", "hash_sha256": "06DF5C21A32B41279361F1E8E2809894DEC403B3168E11959EFEED734605AFDD", "hash_sha384": "0CBA60361AFD1FF5FF252C1CEF203E31E9990E51BE90B93F126ED7442565FEE336CAE2E942DB7785645B78FF7090A2A9", "hash_sha512": "405BC3C11279578BD4B4EAE8BAAE1054EB0180B2C8D1D95D88BD5557C95365262B8EFA9287CBA0998F2B5711482100D3299BEBC2C067EA1DE6EDDB0FBD66EC2F", "hash_ssdeep": "3072:91BLMuh57yd6bGXC6joQ5XBjJDpYzo2eI0eyiEe:aG2joeXBjJDp33e", "hash_imp": "3FA895B748E2AF8D3260E15F88A1C167", "hash_pesha1": "E3FD82A7A59CE77FE11F64D5625523E8DF2D89AD", "hash_pe256": "DAFEF88663942F39863016AA39896ACEEF8DE7563283FBE22E128FDC51784BB4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001E47CFC029560FF84FB0002000001E4", "signature_thumbprint": "E942D27A35DCBBE072872AD9E9E0AC4C948A7864", "signature_issuer": "CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BCP - SQL bulk copy tool", "meta_original_filename": "BCP.exe", "meta_product_name": "Microsoft SQL Server", "meta_comments": "SQL", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2019.0150.2000.05 ((SQLServer).190924-2033)", "meta_product_version": "15.0.2000.5", "meta_language": "English (United States)", "meta_legal_copyright": "Microsoft. All rights reserved.", "meta_legal_trademarks": "Microsoft SQL Server is a registered trademark of Microsoft Corporation.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/06df5c21a32b41279361f1e8e2809894dec403b3168e11959efeed734605afdd/detection", "output": "usage: C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe {dbtable | query} {in | out | queryout | format} datafile\r\n [-m maxerrors] [-f formatfile] [-e errfile]\r\n [-F firstrow] [-L lastrow] [-b batchsize]\r\n [-n native type] [-c character type] [-w wide character type]\r\n [-N keep non-text native] [-V file format version] [-q quoted identifier]\r\n [-C code page specifier] [-t field terminator] [-r row terminator]\r\n [-i inputfile] [-o outfile] [-a packetsize]\r\n [-S server name] [-U username] [-P password]\r\n [-T trusted connection] [-v version] [-R regional enable]\r\n [-k keep null values] [-E keep identity values][-G Azure Active Directory Authentication]\r\n [-h \"load hints\"] [-x generate xml format file]\r\n [-d database name] [-K application intent] [-l login timeout]\r\n", "runtime_modules": [ "C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "SQLCMD.EXE-341B3C6F5A1BFB7EC6FC47878BDBAB80": { "file_name": "SQLCMD.EXE", "file_path": "C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\SQLCMD.EXE", "hash_md5": "341B3C6F5A1BFB7EC6FC47878BDBAB80", "hash_sha1": "8423D5A8E47430A29D0E91A066E3B429CE7BE9A0", "hash_sha256": "5803521CD1A53B4DE33E7BB782651548C22D1D81C0C1C6B26B1EB9CF773BB724", "hash_sha384": "BFE021A7592499D905D70E2D456CF78BB73D232B9DF2D6AAF37E837BD00A11C61163653C88EABDBB6CAC44BEA3293F51", "hash_sha512": "31AC3DAFFCD052E027D7FE2A320720E9482D05FCB90B2690F2BDD8A29893500FD5C1FF9353DE44C802C0EF099CC15E991895260A26897DA8615DFB01466F3010", "hash_ssdeep": "3072:QPkOTjjmDpuQtR8NMtmjcrM4NCjKtirp5DqNUseGvMNTcyqnqFmCQiEd:4/edtvBoxjUir7DqNU7GkNTMqFcd", "hash_imp": "3D3B6D9E8906FC45B35D79B6B2BFDC28", "hash_pesha1": "84EB0C9C0EE1F3D5DEA419522D26FA23310DAFE1", "hash_pe256": "9FDE8E7801064FBA173C73992EE617FF02C6A59979AC2D947DBB42A2AD897ACA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001E47CFC029560FF84FB0002000001E4", "signature_thumbprint": "E942D27A35DCBBE072872AD9E9E0AC4C948A7864", "signature_issuer": "CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "T-SQL execution command line utility", "meta_original_filename": "SQLCMD.exe", "meta_product_name": "Microsoft SQL Server", "meta_comments": "SQL", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2019.0150.2000.05 ((SQLServer).190924-2033)", "meta_product_version": "15.0.2000.5", "meta_language": "English (United States)", "meta_legal_copyright": "Microsoft. All rights reserved.", "meta_legal_trademarks": "Microsoft SQL Server is a registered trademark of Microsoft Corporation.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5803521cd1a53b4de33e7bb782651548c22d1d81c0c1c6b26b1eb9cf773bb724/detection", "output": "Microsoft (R) SQL Server Command Line Tool\r\nVersion 15.0.2000.5 NT\r\nCopyright (C) 2019 Microsoft Corporation. All rights reserved.\r\n\r\nusage: Sqlcmd [-U login id] [-P password]\r\n [-S server] [-H hostname] [-E trusted connection]\r\n [-N Encrypt Connection][-C Trust Server Certificate]\r\n [-d use database name] [-l login timeout] [-t query timeout]\r\n [-h headers] [-s colseparator] [-w screen width]\r\n [-a packetsize] [-e echo input] [-I Enable Quoted Identifiers]\r\n [-c cmdend] [-L[c] list servers[clean output]]\r\n [-q \"cmdline query\"] [-Q \"cmdline query\" and exit]\r\n [-m errorlevel] [-V severitylevel] [-W remove trailing spaces]\r\n [-u unicode output] [-r[0|1] msgs to stderr]\r\n [-i inputfile] [-o outputfile] [-z new password]\r\n [-f <codepage> | i:<codepage>[,o:<codepage>]] [-Z new password and exit]\r\n [-k[1|2] remove[replace] control characters]\r\n [-y variable length type display width]\r\n [-Y fixed length type display width]\r\n [-p[1] print statistics[colon format]]\r\n [-R use client regional setting]\r\n [-K application intent]\r\n [-M multisubnet failover]\r\n [-b On error batch abort]\r\n [-v var = \"value\"...] [-A dedicated admin connection]\r\n [-X[1] disable commands, startup script, environment variables [and exit]]\r\n [-x disable variable substitution]\r\n [-j Print raw error messages]\r\n [-g enable column encryption]\r\n [-G use Azure Active Directory for authentication]\r\n [-? show syntax summary]\r\n", "error": "Sqlcmd: '-h elp': header value must be either -1 or a value between -1 and 2147483647\r\n", "runtime_modules": [ "C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\SQLCMD.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "agentactivationruntimestarter.exe-4C47A88676A64840686E8628AAB36B82": { "file_name": "agentactivationruntimestarter.exe", "file_path": "C:\\Windows\\system32\\agentactivationruntimestarter.exe", "hash_md5": "4C47A88676A64840686E8628AAB36B82", "hash_sha1": "D92C7C8D7C549D6AD6D827B5B679C794FDEFCBDA", "hash_sha256": "682C197AE9F493827B8E53FCD0C8A54F2AD504FC2E8AA466FD4E268139CEBF40", "hash_sha384": "DF53936AA09FF96888F5B9DE8B2B438908236BD17EF07F2252EE201A29EF9C9BB78A509F09E51B14C4A40EBAE2DB650A", "hash_sha512": "76AAB5919843529D1287A035C57A0919B6CBDFF72F2C8597F05C0BFEFEAA66CB6AE8278166C38C107DDD614577E93B61ED0F286F3372959897E1ABB2D95A0BD6", "hash_ssdeep": "192:wJcdVHZqzn/3dbd3380z/hDU48AoAvclD2WFZpLsBJGTZ6lE96Uc7EN:FdVH8Tdbx8ExPvt0lDlqHlUc7", "hash_imp": "9FF2CEFB944FB06F3C5F295C519519AE", "hash_pesha1": "3A6E881DE52B5DDD2F32E02D220ACECDE57C8918", "hash_pe256": "56FC669D96DACF48CDDB28EEB46F45D519566B3F1285F40AB841A039D72B5A66", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/682c197ae9f493827b8e53fcd0c8a54f2ad504fc2e8aa466fd4e268139cebf40/detection", "runtime_modules": [ "C:\\Windows\\system32\\agentactivationruntimestarter.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AgentService.exe-5E87EEF78E014C98E5C7D137A8E25DCA": { "file_name": "AgentService.exe", "file_path": "C:\\Windows\\system32\\AgentService.exe", "hash_md5": "5E87EEF78E014C98E5C7D137A8E25DCA", "hash_sha1": "F06C5CE3E801C30DCEFA0B23B7380049CBFE0C20", "hash_sha256": "308F7F09CD5D71F29E800F969DE053ECB134544CAE1393098B9A7126EE0BC5A9", "hash_sha384": "A26765F9F4908FEB341831AA198CE809EE2EB3FAA0B70632DECB59D077E1CA782695357642BB137C26145746AD988148", "hash_sha512": "47CB08043543001B57FDD288FBAE567EF6D9D4B7264E82CEE2FDE76FD6CDEFE24807A5D66A2199C0FB3E3E8ABEF881CED0AEC391629A24F4D60D5EA6E82620A9", "hash_ssdeep": "24576:Iq0xOyGFzRew1HSmQHHZRBC5udon/h42suQa7r/8BDw5Ht5Hc/4TyUeG6TpQ:3COyG3ewdSVHlE7Hc/4TyUeG+p", "hash_imp": "3EE48866035CFD9316411B9261573247", "hash_pesha1": "3F1ABC025F037221552816FCCCA295EF83938DD0", "hash_pe256": "5129B44A8C524F54DA89FA98C18559D85109C246CADC9F5856D1D99CC683BE37", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AgentService EXE", "meta_original_filename": "AgentService.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/308f7f09cd5d71f29e800f969de053ecb134544cae1393098b9a7126ee0bc5a9/detection", "runtime_modules": [ "C:\\Windows\\system32\\AgentService.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll" ] }, "aitstatic.exe-E944049D4EC7F93576A1CA5039658CFA": { "file_name": "aitstatic.exe", "file_path": "C:\\Windows\\system32\\aitstatic.exe", "hash_md5": "E944049D4EC7F93576A1CA5039658CFA", "hash_sha1": "F9F84AB4703AF0C38691A7447C1EB98277FE5920", "hash_sha256": "FA0F83DCA7A4EE0B2AAB762EE381FA1A259E552BDAC1E302F53CC7F50EE44C13", "hash_sha384": "32A6748B5EBF4806FD6965662C97880030D7BF3EB3C454A03642A914AD01D7A2419096B6EED8EB19815D4BA1F836B615", "hash_sha512": "7A4AAE75C67C8C9DDB74AA759B3FEBCEBBBB27061D76EEB91A47DB693434C8AB442D8F30FC9586F97FFED0FEB4A28E3674BF4E11253AF634957F8D0C1EC31520", "hash_ssdeep": "49152:ljt1+tENWqA/+pSYryLTQ4ullYF5svlRlZPAoTMZmhJv3eEkF/Le:lveAwvAImAoTMgJvuLe", "hash_imp": "F72ACD5834B43927998E9B0707B7AE4B", "hash_pesha1": "CFC33455CBE24E7CADCB92FAD4AF8E034E5A1B6D", "hash_pe256": "DEEE0C488309C70CF1F5B6B79B7B6A4FCD3A8DF20E3EBF9D9E0E19C655A9134C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Application Impact Telemetry Static Analyzer", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19645.1016 (WinBuild.160101.0800)", "meta_product_version": "10.0.19645.1016", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/fa0f83dca7a4ee0b2aab762ee381fa1a259e552bdac1e302f53cc7f50ee44c13/detection", "runtime_modules": [ "C:\\Windows\\system32\\aitstatic.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "alg.exe-EE6E3DCACA515C8E507236E4FAC225DE": { "file_name": "alg.exe", "file_path": "C:\\Windows\\system32\\alg.exe", "hash_md5": "EE6E3DCACA515C8E507236E4FAC225DE", "hash_sha1": "70A182F68431763A533BCD695B2E01CD29FE4FF1", "hash_sha256": "AC42E63AB0DF0D5329506900D4CBE188BB3A24AEBEE368F9FF413A2C464AD656", "hash_sha384": "2F7EE41BCFB206994D325E3D9ECE905006B60DB3D5A73E11732FC733AAB6CB62F6E44BE838C98F67EA39784C3ACE8DE9", "hash_sha512": "1D7CD334F174198AA8C13FA98B0FB723F5BE9A0E9FF06AD084173857FCDEB60CC2B29056EA91BCE6A3DBB728C5F1E8DCCBB1C118329CC14C1FD5F0E06A6E3115", "hash_ssdeep": "1536:OOK5IBp+EyHoMo3XhhVBmB96cuFUGwtlavc/V3TLQh7VrGH3:jKcp+EysxhVgLpuskaVDM5x", "hash_imp": "F718D257CB3A4BBBE8310FA60E7D1DED", "hash_pesha1": "0432916B82FD57E60FA4C45BABBD1456CF38844A", "hash_pe256": "B4B4D369E6F2B472305E6F828FEBFA9610130F5962DB1BB5D57B5E687AAD0F60", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Application Layer Gateway Service", "meta_original_filename": "ALG.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ac42e63ab0df0d5329506900d4cbe188bb3a24aebee368f9ff413a2c464ad656/detection", "runtime_modules": [ "C:\\Windows\\system32\\alg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\CRYPTBASE.dll", "C:\\Windows\\system32\\MSWSOCK.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "AppHostRegistrationVerifier.exe-F0B221519D1419F1CCEBEFCA4E8219BD": { "file_name": "AppHostRegistrationVerifier.exe", "file_path": "C:\\Windows\\system32\\AppHostRegistrationVerifier.exe", "hash_md5": "F0B221519D1419F1CCEBEFCA4E8219BD", "hash_sha1": "1230DC27C534FE6A1C185B8776869472A008A2B8", "hash_sha256": "B50C8BD4935D56F398ECA98339A038F68362392F679514753F3F986B8E345186", "hash_sha384": "2D37EA1CF0DEE3311D6294BC7101871D3F538E59D2CE82B78427505474EC8A4DAC46D1E3B26FC6B108E27B90BA33BFBD", "hash_sha512": "BE024B8FC73651C6FD11EB2A6109C16B814F3D5CCE9AB81E2CE27929BBE0346D99FF74728A95BDC6C5CBA9D1E5F24AD29FDDBC216800765D5C0063353AE275A2", "hash_ssdeep": "3072:kyBB6kEY2Sn8x7djJ3P/cp3WpOvm/r+jBm+ydrqJAq2a0x:kyBBFc5bKGxSBb0rRQ", "hash_imp": "BC98DE83C852774D36E8A23873E33A68", "hash_pesha1": "3F1B10ACCDF3562023F6850464BCF2EEEAC87B58", "hash_pe256": "F712E0ABD329C1F39CA774986DFA9CE505D89FCCA18E3814760951DACD01AB0F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "App Uri Handlers Registration Verifier", "meta_original_filename": "AppHostNameRegistrationVerifier.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b50c8bd4935d56f398eca98339a038f68362392f679514753f3f986b8e345186/detection", "runtime_modules": [ "C:\\Windows\\system32\\AppHostRegistrationVerifier.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll" ] }, "appidcertstorecheck.exe-ADE6B1F9E5A36ADA6F1483E331746AA5": { "file_name": "appidcertstorecheck.exe", "file_path": "C:\\Windows\\system32\\appidcertstorecheck.exe", "hash_md5": "ADE6B1F9E5A36ADA6F1483E331746AA5", "hash_sha1": "5AF9F3B251A2B25F67C1B1D00AEB8441DE96036F", "hash_sha256": "5AFDC8AE3AAC555A3DDC317D8AA05EAB3A7A24AC5641C3A7162AAC96F511F6D3", "hash_sha384": "E2C6DBD4C9CB9752225A69641B2D0D444AEF9518D6257D1F3AFAAC5D6306967BC011D6DBF1C94C4CA557A133BBD4D4B1", "hash_sha512": "1D5AAE5B1D69B2989F0C5FB6480F21BA4D75FA47AA6F2510D716063B10ABB74621129DDD09ECEDA5029B9B514C7DCB89CFFCE469F147C303D1B0820B577D2761", "hash_ssdeep": "384:jNVuI9B+QoLq04scLVGQ8swLRQw522lK6x3lBe9JomWBaK1W:RVuHxkBLVEswuk2t6NlBKS5aK", "hash_imp": "0CCBBA73193E73A96FCFB925C3CA3B3C", "hash_pesha1": "65150FA0D2C436F190F706ADE7A12DF8415ED7DB", "hash_pe256": "0AA5A448A5BCEDB6FA56AA90C14C73DFC65D48C7C023A0C0CEE196576AEB44C2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AppID Certificate Store Verification Task", "meta_original_filename": "AppIDCertstoreCheck.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5afdc8ae3aac555a3ddc317d8aa05eab3a7a24ac5641c3a7162aac96f511f6d3/detection", "runtime_modules": [ "C:\\Windows\\system32\\appidcertstorecheck.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "appidpolicyconverter.exe-D8B33FB1A36E7AE7699A875791A50FF9": { "file_name": "appidpolicyconverter.exe", "file_path": "C:\\Windows\\system32\\appidpolicyconverter.exe", "hash_md5": "D8B33FB1A36E7AE7699A875791A50FF9", "hash_sha1": "CFD01A7DF6E88199B9B31B1CF941EF30939E1FD5", "hash_sha256": "024E4E2E61AE722BE8F66267B989B6819028C6B4552B9E8238A5BB7CEE1CA4DC", "hash_sha384": "DD68B92A1E12B61A031CC931E6C2C7B8AF7A57ADD4103E6A43FB340E476AECB628271F9C513F7254253D2A860335F315", "hash_sha512": "C913935B3AB16786AD45A1C4A18A50C359EB9437400ECE2C74AC88892BEECC3217D8BBD4369802348449AE6198A4A26382263092BAEB0C103CDBAAC68B033140", "hash_ssdeep": "3072:3WZXanrPkihwG/CgPQFsUgWNSXtsJM8v5iS6XY:3WlanrPhhwyPQFsUz4CMI5iS6X", "hash_imp": "BEA539CDA9D232EDE3328D63369DA2F9", "hash_pesha1": "8950EE81C2A591BC13C2422A73F8A314B2E53883", "hash_pe256": "EBF3892BB3231E1A9B3EF5E9F67ED5176CF3C01C9401F5DFF6772AC4050DC258", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AppID Policy Converter Task", "meta_original_filename": "AppIDPolicyConverter.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/024e4e2e61ae722be8f66267b989b6819028c6b4552b9e8238a5bb7cee1ca4dc/detection", "runtime_modules": [ "C:\\Windows\\system32\\appidpolicyconverter.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "appidtel.exe-A54179DCCD31B6F6D23DF8DA147F4748": { "file_name": "appidtel.exe", "file_path": "C:\\Windows\\system32\\appidtel.exe", "hash_md5": "A54179DCCD31B6F6D23DF8DA147F4748", "hash_sha1": "69CDD81FE5EE8EE25A90C2455CD7879D8660A668", "hash_sha256": "902F327BFF5A5F4B2333F5AE28F843A1AC705BC0E04B4B37CEE3D9158F8F017C", "hash_sha384": "C186C1FD3248AED67F885A2B8E61B94A9BEB9432FCEE46DA2AC5CB65AC933041320C9634DC07A35D8BD523D36AFF521E", "hash_sha512": "C4FF89C249CD96BF80814076E240FAB76E2F067FA5AC440FB6E781FC02D3DACABA59D799B7BEAE87D36674D0038E15D299A80D52134817144C74ECB0D155B5B8", "hash_ssdeep": "384:6f+WpdRobF3A8wjfe6W813lOdo1IO4el2R5WjOQV8HpJZsWsdsWdv:6Hd63A8b/GOdoPhl05Wis8H/A", "hash_imp": "85042296267FAC79E897C8302E744A31", "hash_pesha1": "9FE65F9FE2CE1C2D6707455B8CCE38667BF3BB68", "hash_pe256": "8B59140CA6B7D5A8A51CB5A6EDD3FF6FFDC71F46879FB5C1A4ADB7DBDEA86A52", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Initializes Appid ManagedInstaller and Smartscreen Telemetry", "meta_original_filename": "APPIDTEL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/902f327bff5a5f4b2333f5ae28f843a1ac705bc0e04b4b37cee3d9158f8f017c/detection", "runtime_modules": [ "C:\\Windows\\system32\\appidtel.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ApplicationFrameHost.exe-25760B755195D2DD44074CD47EE7969B": { "file_name": "ApplicationFrameHost.exe", "file_path": "C:\\Windows\\system32\\ApplicationFrameHost.exe", "hash_md5": "25760B755195D2DD44074CD47EE7969B", "hash_sha1": "1A32ABA054084C253487DB2318A0995963145A31", "hash_sha256": "5DA7A338FA478C96E83A27DB481E39C1F2689E9016CF9AA7FF5CD2BFF32F33F2", "hash_sha384": "07E6581B4EE506218527ED00168F5B1A8598B90B200EBA34A25A2D7D3BD99CA769E10C2AFC36CC2E7EEA53B9AC8DEBBB", "hash_sha512": "FE8012E597AE7188EF8DF43EF2090ADD16204E790FA8A9976DB213831AB1C4CE7C11F361F09F85DC22C3CCA38D347E438AE8BA50E22B171F0E105BD9706697CB", "hash_ssdeep": "1536:MX+MHodV6ZMI6ZLaWDp3sXf+WhSbJfR+PcBP:MXrHCVbI5WDqXf+MSbvYcB", "hash_imp": "09ACF1642E301359F90E7DA59EE838C6", "hash_pesha1": "E99A935F6FFA1A4127997A1D865DDE6FD6C63732", "hash_pe256": "E2493F17C554F4105FEAF5AD4659CC6DD1F044C776148359D90138FA56CBC2BC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Application Frame Host", "meta_original_filename": "ApplicationFrameHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5da7a338fa478c96e83a27db481e39c1f2689e9016cf9aa7ff5cd2bff32f33f2/detection", "runtime_modules": [ "C:\\Windows\\system32\\ApplicationFrameHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\System32\\win32u.dll" ] }, "ApplySettingsTemplateCatalog.exe-FA7CF1D689F41663B0BB03EFC19A8247": { "file_name": "ApplySettingsTemplateCatalog.exe", "file_path": "C:\\Windows\\system32\\ApplySettingsTemplateCatalog.exe", "hash_md5": "FA7CF1D689F41663B0BB03EFC19A8247", "hash_sha1": "154F7BE464CA5DA8D92C9A913A8B410D4768FAF2", "hash_sha256": "76002759EFE9430FF557D6A6AD309336E2BE8CB650DD05EF71FEC80F26FB135C", "hash_sha384": "115D0B7E58444BEA1438422B36D0F22EC42E62C624F651C1A34EAD901D9F7A0E49EF8DB6886E51466BFA7949D44EB9AA", "hash_sha512": "645AE7986F6FB82F709DAF225C88E1D511DA5C8405BF0EBF69525A38E93B339D8A9281796DC41DBF3A56EF62EFC6EB3A44727BBF13A3F842295FF88F47A27538", "hash_ssdeep": "24576:D1nmmXE3sakiTWsUM/dMS1DEu1dIYtIS1TsHp/mDgfNDBEkvwBBI:DxmAE3VTRZJl+3wBB", "hash_imp": "FF62C8E308A6E4A03970891F06512C69", "hash_pesha1": "B8BBB111F1E13119E708FE74A2BE3CA1498FE2B4", "hash_pe256": "999777248074E5880F0ABC8F0309ECD2F30116C230A84E65C34DE38E1DB5EBD7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ApplySettingsTemplateCatalog EXE", "meta_original_filename": "ApplySettingsTemplateCatalog.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/76002759efe9430ff557d6a6ad309336e2be8cb650dd05ef71fec80f26fb135c/detection", "runtime_modules": [ "C:\\Windows\\system32\\ApplySettingsTemplateCatalog.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll" ] }, "ApplyTrustOffline.exe-9107DB590E57C64746779D28DAB71C10": { "file_name": "ApplyTrustOffline.exe", "file_path": "C:\\Windows\\system32\\ApplyTrustOffline.exe", "hash_md5": "9107DB590E57C64746779D28DAB71C10", "hash_sha1": "89520B6CAB7A1E5AE16F2E0A2425D15362384708", "hash_sha256": "A9D9C18F27DACB14580D13F5D12DD3A02B4385F86CADFE975F6A47124C7B6C3A", "hash_sha384": "BEB24316B3AC666AF9157531065E9009BDD1BB9F33E8EC23690BFEA7690EE725882214DEF048F24927EBA7F2E0A8BEEE", "hash_sha512": "83A9703BE424E1F2AFAFCF37C5A2918F52E741AC558F38275B0F2E032C0ACE6186B52383FE2798DA64371E7DB30C003A1F6C983BBB941E0D2F5873449088E02C", "hash_ssdeep": "12288:g5ht6VzvhJqWUkg3rSD/wW6IcSXkir0d6PVKAMq8dXijwl7:gPqLciw2cSXp0U0AMrIwp", "hash_imp": "D51B3217AE37F361FC8DC92018E1B2E2", "hash_pesha1": "6C47ED8DFFCCDADBDF212E404BC47BFDEC5CECEA", "hash_pe256": "4E192812D6A405527A7C1D2337B8BDDB19A1CD5D62FE96D4F1F36AB8EC78A19F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "\"ApplyTrustOffline.PROGRAM\"", "meta_original_filename": "\"ApplyTrustOffline.PROGRAM\"", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a9d9c18f27dacb14580d13f5d12dd3a02b4385f86cadfe975f6a47124c7b6c3a/detection", "runtime_modules": [ "C:\\Windows\\system32\\ApplyTrustOffline.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ApproveChildRequest.exe-0774A755163023FFA8A42AC2851C9CC1": { "file_name": "ApproveChildRequest.exe", "file_path": "C:\\Windows\\system32\\ApproveChildRequest.exe", "hash_md5": "0774A755163023FFA8A42AC2851C9CC1", "hash_sha1": "3B219547DD0C753B999AFF9D1A5BF533366F9B20", "hash_sha256": "9590CDD23C89D2ED07A2F185673CA2CA4325BCA3B24D37AA39EA897DEDABF1F6", "hash_sha384": "A211932DBBDD454995B36340A9273CFEA22B421F6B95CC84FB9331B10665D0F47884F1C2CD754FFFFFAB9A2903F46002", "hash_sha512": "87EC75BF06CE52692A6BFABDB1D97897C3411F6DEEC15BD4D9A9953F97D860541B156AA0E6B0FFD791BE7661A86FDB71E4ADBC4D7AF2A58A657E8809CAD0BE78", "hash_ssdeep": "6144:oBjN5zr+Czch7Hqlbs2z8aHpGZaa2nfRGKdDPDvV:Ix5/bz/bbzVpGtcnjDt", "hash_imp": "1C4DF20AAD5350BA911F079171B0F617", "hash_pesha1": "485F94B230314466B37BAC98961797E07A925596", "hash_pe256": "9C9EA96D521B89E12C630DE7B545A7C4EE3D5976C4E32F5361DE60473390DE9B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Grant more screen time", "meta_original_filename": "ApproveChildRequest.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/9590cdd23c89d2ed07a2f185673ca2ca4325bca3b24d37aa39ea897dedabf1f6/detection", "runtime_modules": [ "C:\\Windows\\system32\\ApproveChildRequest.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll" ] }, "AppVClient.exe-DC06815F02B8E4F5BFDD44D29DE33047": { "file_name": "AppVClient.exe", "file_path": "C:\\Windows\\system32\\AppVClient.exe", "hash_md5": "DC06815F02B8E4F5BFDD44D29DE33047", "hash_sha1": "6303B330F72D0E2DDF0A8561ED9133850C750C8E", "hash_sha256": "03BC40C526BA6C67474DF13A61D724F7E01C39342D66C5F4BE7FC3F8A0F5A662", "hash_sha384": "564D2BD90F9DEF1F8320EC9306249C01140598728F587A69B4BCD643C67ACC0D0D87C8339546B66280A83172C028B758", "hash_sha512": "61A84E54EB5B2D65B400BF67E2CAE5687139EE5B2B25B6BE3758D973F6CA56CBA2DFAA54CE3192CE69393B128249A6D13FD2048C0E7FF7FEE43A33DC4CF71F37", "hash_ssdeep": "12288:5ph5FaYjJB0ZFLyFrwGZxW6jSYwdFBqJGNUbTpqGCICumH83M2X:f7F5f0ZJyFrwGvW6jSNdFBqTqGCICumK", "hash_imp": "A4529EE3A1660DAF1F914304A5C7333E", "hash_pesha1": "BD652FA52F06ACFB80623C7D514F21B41BF55B18", "hash_pe256": "DBE422333C1C6097085B993829AA24919B01AD3CBF4CABC085C778DD0D896B6B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Application Virtualization Client Service", "meta_original_filename": "AppVClient.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.84 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.84", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/03bc40c526ba6c67474df13a61d724f7e01c39342d66c5f4be7fc3f8a0f5a662/detection", "runtime_modules": [ "C:\\Windows\\system32\\AppVClient.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AppVDllSurrogate.exe-FE1414362471F8F2603A41BDA2B81526": { "file_name": "AppVDllSurrogate.exe", "file_path": "C:\\Windows\\system32\\AppVDllSurrogate.exe", "hash_md5": "FE1414362471F8F2603A41BDA2B81526", "hash_sha1": "6ADEC76090CCD309B8C24CAA14F48E960705D6E6", "hash_sha256": "5BD041CB98925247E539C1B59CC5E4469ECB619B2B9ACE99719D2991D64B7290", "hash_sha384": "AA0C0D797B7BFDA1877A374AA4FFAF936D90CAD09FB66E47B5594D2BC59E1C9DA9CFFD6C3A74BAF52FF9A3550FA4048C", "hash_sha512": "43770AD082FDCBD40819029E51D3D6973A5C054BC75624248FE54CE6D2D215D856C6EC5C64E0304FAEB14883BC09AC6E7DCA192C9E548CCE4E7D4704E2819AA9", "hash_ssdeep": "1536:1EeJUjrWIuWuAqS3Iu2EARWafKYbkkbsFDfSIT0nJ2QC7pf7Gl8gRLPkCY:1EeS+IsAqS3RARWGNU6ITLjil8gRLcCY", "hash_imp": "0587FCF2E1F1E03C45813A57DC9CF623", "hash_pesha1": "9D5D276980E16934D2DADF3BA8606D71C82FA825", "hash_pe256": "13D431116FDA78EF4BA88370DD8157AB394BDCD0ABF4A0098631ED1A6D362B11", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Client DLL Surrogate Host", "meta_original_filename": "AppVDllSurrogate.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/5bd041cb98925247e539c1b59cc5e4469ecb619b2b9ace99719d2991d64b7290/detection", "runtime_modules": [ "C:\\Windows\\system32\\AppVDllSurrogate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AppVNice.exe-8F6A8E7CEF9833166DE4A29920B48F42": { "file_name": "AppVNice.exe", "file_path": "C:\\Windows\\system32\\AppVNice.exe", "hash_md5": "8F6A8E7CEF9833166DE4A29920B48F42", "hash_sha1": "ADF1A5E6618C4AA599F6EABF52AFD15E9CD5F63F", "hash_sha256": "504C21604870116A0EF5C1581020DD90E2AE21FD9E3B464C271DAF51A255DE95", "hash_sha384": "1BDD2B978729128E1D8E5254B8C990D4574622B8F5456285C888F9D9441E7BC1C09EEEB4E20B8EB3F90C8BC6972E0CD1", "hash_sha512": "9F4485BEA51031035D4FCB9C33BBB2D30B785DD597228EA3066B97863E16B0108A13A75C9AD05DA38BE7F6F6E4134FBD3CD56AFBAA7F9C1ED7E89ECA46B77780", "hash_ssdeep": "3072:Nh4kTFwXWmvV+vJa0WGNU6ITLAY0dehOFLwV:N/beV+vXWGNU6ITLAv5wV", "hash_imp": "614837F49DD2BFC301DBFDA8BA526AEF", "hash_pesha1": "B8A850BC57235B3F45E6566CE5F871885E4E7438", "hash_pe256": "7C12F3CF3561CFDA11B818A24BF19AEEF74DDF88317BFD3A19F623AA52F92862", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Application Virtualization appvnice", "meta_original_filename": "appvnice.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/504c21604870116a0ef5c1581020dd90e2ae21fd9e3b464c271daf51a255de95/detection", "runtime_modules": [ "C:\\Windows\\system32\\AppVNice.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AppVShNotify.exe-F4E5D8D8C06466305663EC35C617D458": { "file_name": "AppVShNotify.exe", "file_path": "C:\\Windows\\system32\\AppVShNotify.exe", "hash_md5": "F4E5D8D8C06466305663EC35C617D458", "hash_sha1": "0012064E9E494CFBCFF0D7E3FED2C50F364BA288", "hash_sha256": "ECEEE47CD852E7A867FFC81F998A0702BB04C2D98247DBF98662BBE924748B44", "hash_sha384": "3CB6A5133D298EB06F3C7107A365BBE7A990EC62075604E4713F92ABD475CCD32CEB587CB3E1E041F62E385C9320F037", "hash_sha512": "C0C1980F9EDFC8AB9E90F49219ADBC1FDBDAD73935FCD569366B6B2E33FB4B897FD8FBF7C1017B8AE5741EFA5FC8B54463FC39C3079FFDBDB2BA1D9C76080AC5", "hash_ssdeep": "3072:c8Ngvq78iajNsFhehRsPi5o57WGNU6ITLTI23mKXDsbs3:c8Ngvq7XQYshRui5MWGNU6ITLTRWKTsE", "hash_imp": "D8F1AB20D443B8D34709DFC6C048D003", "hash_pesha1": "F18036E6FBFA13B9B78CFF5836BF13160368C25E", "hash_pe256": "BB23FD4EB393D7B63C9109684A09A436E0D8EA5D698B7B5A2AE698D2D6399C51", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Application Virtualization Client Shell Notifier", "meta_original_filename": "AppVShNotify.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/eceee47cd852e7a867ffc81f998a0702bb04c2d98247dbf98662bbe924748b44/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\AppVShNotify.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll" ] }, "ARP.EXE-2AF1B2C042B83437A4BE82B19749FA98": { "file_name": "ARP.EXE", "file_path": "C:\\Windows\\system32\\ARP.EXE", "hash_md5": "2AF1B2C042B83437A4BE82B19749FA98", "hash_sha1": "9BB265D4582DE87EBA4E34081BD122C3395A232E", "hash_sha256": "7B79171410482F410B7572C58EDB7FD39326F7150C7C6882249B1CF9D7C970F0", "hash_sha384": "64ABFCE7C0C6C03B4C896111BF3F1DC6FA086016E8761843ECDB7A5745AC127C46FE4E03452D6599481672CDC0F4F1B4", "hash_sha512": "B03A5C26331BEABFBAEDFDF31AC6D25C76C04B5AAB3C5B669F06C7404FABBCB41D2720EA907F860BDF3DF27AC16BC7363BEC02093DDF203C308B2156C838E731", "hash_ssdeep": "384:3iA8SVIMqzTvuNMA9polh/tOeILdKWgPs2ZR0bCBURc737HjGx5RdWS9mW:yJSGMqzTCM9odTG+bjRc3Hj45R7", "hash_imp": "48A4D83E58F21E6758C9F94526FBB940", "hash_pesha1": "37D8F23F9FB3FDAB0DD3E5233BB94415FDE597F2", "hash_pe256": "2CB97DA6630FB6E1A94FDF7DE307D5DD8E99C0F08A9C550FB3F8330A80D93647", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Arp Command", "meta_original_filename": "arp.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7b79171410482f410b7572c58edb7fd39326f7150c7c6882249b1cf9d7c970f0/detection", "output": "\r\nDisplays and modifies the IP-to-Physical address translation tables used by\r\naddress resolution protocol (ARP).\r\n\r\nARP -s inet_addr eth_addr [if_addr]\r\nARP -d inet_addr [if_addr]\r\nARP -a [inet_addr] [-N if_addr] [-v]\r\n\r\n -a Displays current ARP entries by interrogating the current\r\n protocol data. If inet_addr is specified, the IP and Physical\r\n addresses for only the specified computer are displayed. If\r\n more than one network interface uses ARP, entries for each ARP\r\n table are displayed.\r\n -g Same as -a.\r\n -v Displays current ARP entries in verbose mode. All invalid \r\n entries and entries on the loop-back interface will be shown.\r\n inet_addr Specifies an internet address.\r\n -N if_addr Displays the ARP entries for the network interface specified\r\n by if_addr.\r\n -d Deletes the host specified by inet_addr. inet_addr may be \r\n wildcarded with * to delete all hosts.\r\n -s Adds the host and associates the Internet address inet_addr\r\n with the Physical address eth_addr. The Physical address is\r\n given as 6 hexadecimal bytes separated by hyphens. The entry\r\n is permanent.\r\n eth_addr Specifies a physical address.\r\n if_addr If present, this specifies the Internet address of the\r\n interface whose address translation table should be modified.\r\n If not present, the first applicable interface will be used.\r\nExample:\r\n > arp -s 157.55.85.212 00-aa-00-62-c6-09 .... Adds a static entry.\r\n > arp -a .... Displays the arp table.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\ARP.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "at.exe-15FE2283B40819234C9909E841EBCA0A": { "file_name": "at.exe", "file_path": "C:\\Windows\\system32\\at.exe", "hash_md5": "15FE2283B40819234C9909E841EBCA0A", "hash_sha1": "B376962AB87262A0C2FE5231688B49BDB080583A", "hash_sha256": "5B97C39D87AD627C53023BFEBB0EA1B5227C3F4E86E3BF06B23F3E4B0D6726E2", "hash_sha384": "9DFA89D110BCF3E3209BC87A6ABEF0D5591DDAE2EEC89F4845272B359ECC136E20CA3104EFF6EBB9CFD83BA83F574E32", "hash_sha512": "5DCD2E486239F626F4E2AC9AD63675BE5B3E4F47CF4BB836CBAFF420724ECB32E70E51D14FC0C7ED7E81D6A9C209F9C2D4C57919926D4B5666591AC00D2B877D", "hash_ssdeep": "768:e0+CAGU0QOBk7EUXPHbSGYH2rZ/kmJvjjOr:PKWkYKPi2RkmJ7jOr", "hash_imp": "CBFC405CA679EDA11C11371ED3CE65EB", "hash_pesha1": "A5D92C4A7BB010E5B4A1AF4276EFF8DA45961885", "hash_pe256": "E2CEF1375D0E645C7C537D4E1F5B6EC9F097D3846E20E0513EDEA7C940266950", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Schedule service command line interface", "meta_original_filename": "AT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5b97c39d87ad627c53023bfebb0ea1b5227c3f4e86e3bf06b23f3e4b0d6726e2/detection", "output": "The AT command has been deprecated. Please use schtasks.exe instead.\r\n\r\nInvalid command.\r\n\r\nThe AT command schedules commands and programs to run on a computer at \r\na specified time and date. The Schedule service must be running to use \r\nthe AT command.\r\n \r\nAT [\\\\computername] [ [id] [/DELETE] | /DELETE [/YES]] \r\nAT [\\\\computername] time [/INTERACTIVE]\r\n [ /EVERY:date[,...] | /NEXT:date[,...]] \"command\"\r\n\r\n\\\\computername Specifies a remote computer. Commands are scheduled on the\r\n local computer if this parameter is omitted. \r\nid Is an identification number assigned to a scheduled \r\n command. \r\n/delete Cancels a scheduled command. If id is omitted, all the\r\n scheduled commands on the computer are canceled.\r\n/yes Used with cancel all jobs command when no further\r\n confirmation is desired.\r\ntime Specifies the time when command is to run.\r\n/interactive Allows the job to interact with the desktop of the user \r\n who is logged on at the time the job runs.\r\n/every:date[,...] Runs the command on each specified day(s) of the week or\r\n month. If date is omitted, the current day of the month\r\n is assumed. \r\n/next:date[,...] Runs the specified command on the next occurrence of the\r\n day (for example, next Thursday). If date is omitted, the\r\n current day of the month is assumed.\r\n\"command\" Is the Windows NT command, or batch program to be run.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\at.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AtBroker.exe-22FB65036D7A01D15710A14CD70A903C": { "file_name": "AtBroker.exe", "file_path": "C:\\Windows\\system32\\AtBroker.exe", "hash_md5": "22FB65036D7A01D15710A14CD70A903C", "hash_sha1": "45A1BEEE176F092CDAD1384D82EFDBDD4589C41E", "hash_sha256": "4D75D895625DCF95E06DB50816CEC9EF125B25FF916AF3F9CEA68CDBD2630799", "hash_sha384": "014B98364A545972CCCD53619F5DBCB592F03DBF576BD35D0A5B7C28F37ADBD67E971A70853BCA89662471C1F57FBF59", "hash_sha512": "C501B8B473F2C5614263B5C27F5A721B070FEEF5001A4BF1E29A8ACE54FA9FDF7755A5D52066619C3BC74CD7F0484AED38A5D1513034547348E6504F71F03515", "hash_ssdeep": "1536:nXtIN3Ow1nvQUfNvOI3d3M8oth+Gms2AVC3Yfx9BiXeL5Zcz5kWXFMx:ndQJBlPdc8/AVCkx/aeL5ZY5kWX6", "hash_imp": "EB4EAB2F36ED8FB4978A50489F965F43", "hash_pesha1": "A0F462A07AE194F61A2A68F1BA2F23B7EEF1D867", "hash_pe256": "0BBCFC32BDF75E80F1242A1E9DEB7270023DE0108C2F7E3A5DD4BD03C342F3D4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Assistive Technology Manager", "meta_original_filename": "ATBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/4d75d895625dcf95e06db50816cec9ef125b25ff916af3f9cea68cdbd2630799/detection", "runtime_modules": [ "C:\\Windows\\system32\\AtBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ] }, "attrib.exe-5037D8E6670EF1D89FB6AD435F12A9FD": { "file_name": "attrib.exe", "file_path": "C:\\Windows\\system32\\attrib.exe", "hash_md5": "5037D8E6670EF1D89FB6AD435F12A9FD", "hash_sha1": "B8337FA20077A2C6DB7D01CCC18E328A91255745", "hash_sha256": "1043111FF07814B0D3439561B4CEE5D7EC1799A7A0A419949FEE707666F6DDED", "hash_sha384": "EB296F04B98E4ADE3517DDCB6B6EFA60BD2B4D2B636A62383E25922C470BE823CA67B876223D9B1532CB0BE227AABED2", "hash_sha512": "5BF517A500D25BFA57445E51750A51CEBFC3C325BBCDC5D7EE0E9C3109F5F0DC6259FDE8417A24AFC1C608C44D090BE3630663E0B1536E6FB30E5EAFD4621F4F", "hash_ssdeep": "384:/Nm/jtao5pbmww2j3B0UEdsGDv9CBP54OLw6tGfvXWjtW:/Nsjiww2eUAsWCh51tGfvw", "hash_imp": "2CB38FE7D8F223D9DA50B7CBA9B95A6D", "hash_pesha1": "2BB3502AFE4CFD81386AA37E07C59F887BD74985", "hash_pe256": "D4B156B92D125EA57B4BB7C1E72C8E06FD8602F85A77EE9AD91E67F77DDDE671", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Attribute Utility", "meta_original_filename": "ATTRIB.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1043111ff07814b0d3439561b4cee5d7ec1799a7a0a419949fee707666f6dded/detection", "output": "Displays or changes file attributes.\r\n\r\nATTRIB [+R | -R] [+A | -A] [+S | -S] [+H | -H] [+O | -O] [+I | -I] [+X | -X] [+P | -P] [+U | -U]\r\n [drive:][path][filename] [/S [/D]] [/L]\r\n\r\n + Sets an attribute.\r\n - Clears an attribute.\r\n R Read-only file attribute.\r\n A Archive file attribute.\r\n S System file attribute.\r\n H Hidden file attribute.\r\n O Offline attribute.\r\n I Not content indexed file attribute.\r\n X No scrub file attribute.\r\n V Integrity attribute.\r\n P Pinned attribute.\r\n U Unpinned attribute.\r\n B SMR Blob attribute.\r\n [drive:][path][filename]\r\n Specifies a file or files for attrib to process.\r\n /S Processes matching files in the current folder\r\n and all subfolders.\r\n /D Processes folders as well.\r\n /L Work on the attributes of the Symbolic Link versus\r\n the target of the Symbolic Link\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\attrib.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "audiodg.exe-CBF4F868E857AB7E4817B7E3D70D2C88": { "file_name": "audiodg.exe", "file_path": "C:\\Windows\\system32\\audiodg.exe", "hash_md5": "CBF4F868E857AB7E4817B7E3D70D2C88", "hash_sha1": "CAD26985D73070C6CFC05ED79CDA22E1DAC4B5C3", "hash_sha256": "55B144D3BDD0C14FF810FA295CA79E08A1E418EE3BB46EAB78982EEB0BB7816F", "hash_sha384": "39979B65CAB17BDCF1F14686B6B498006B3D4F4C67FEA936FC01ACF67D926E2EAF88A4684747C9E3CA3D9C7C8A2EE064", "hash_sha512": "AF3FF9ACCED9A52C18E2560D278651E1F266D101D674EEFC91EF50FCC293052A4C82BDB69A1CBF9344DC6872A1461A0716BFF22690D183E86EF5859352207D60", "hash_ssdeep": "12288:EShVuOWudUdWi6MiVA/NNxssBUDOo5DaHZFU:5hViuKdWMwA/j6AUyo5DaU", "hash_imp": "356C5FB039EB7424A518F132A23D3232", "hash_pesha1": "014706757B58F7CC9E2D82EBAAC8E7C3E46B66C4", "hash_pe256": "6210CB17011D8F6DC5A4DE022918B08CBD37091B378E86877FD634B431118DFF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Audio Device Graph Isolation ", "meta_original_filename": "audioadg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/55b144d3bdd0c14ff810fa295ca79e08a1e418ee3bb46eab78982eeb0bb7816f/detection", "runtime_modules": [ "C:\\Windows\\system32\\audiodg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\MMDevAPI.DLL", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\DEVOBJ.dll" ] }, "auditpol.exe-0CBBB1FFE1AF93272D498FB8FBBFFCC6": { "file_name": "auditpol.exe", "file_path": "C:\\Windows\\system32\\auditpol.exe", "hash_md5": "0CBBB1FFE1AF93272D498FB8FBBFFCC6", "hash_sha1": "E6A50645A361D5C763802FFA6E3C749FB81E96D7", "hash_sha256": "D1C6EC7F394B59D067DFD47A6A65978E4C2CC73437457A4B78209E5F516471CC", "hash_sha384": "B0AC794ADC7B01CB5D0889986FAB9CA8E3CAF948158B993830BD158926ACB71D147C2E2762CC5CBF5467A8CCCB5E7E58", "hash_sha512": "A979571B537C0C00A102721B1790E5ADC78E0FD4CF120785A12FF810592C878F2C0E20B079D9AD0E213B9B3E517DE2E989FA59DD9433AB047E916B98A9DE2AB6", "hash_ssdeep": "768:nPAYR3/NExmZz69/3BTpcfoxAETN67y1FGl0QZ04y13NhUIz+jIIzC+nMumpU0:PAYR3/NExmZzwpu3ETN6l+W9y13NhUIX", "hash_imp": "90AC86A122E388FC7E7952289389E5B0", "hash_pesha1": "147A1F6DDE57FB477AFD1B485BE29D3FAE2036DE", "hash_pe256": "CAE44241AF9F6A1B2E8FCD894DC6F5DE1163FEEA99BD1E0EE323180D6F4741D9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Audit Policy Program", "meta_original_filename": "AUDITPOL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/d1c6ec7f394b59d067dfd47a6a65978e4c2cc73437457a4b78209e5f516471cc/detection", "output": "Usage: AuditPol command [<sub-command><options>]\r\r\n\r\r\n\r\r\nCommands (only one command permitted per execution)\r\r\n /? Help (context-sensitive)\r\r\n /get Displays the current audit policy.\r\r\n /set Sets the audit policy.\r\r\n /list Displays selectable policy elements.\r\r\n /backup Saves the audit policy to a file.\r\r\n /restore Restores the audit policy from a file.\r\r\n /clear Clears the audit policy.\r\r\n /remove Removes the per-user audit policy for a user account.\r\r\n /resourceSACL Configure global resource SACLs\r\r\n\r\r\n\r\r\nUse AuditPol <command> /? for details on each command\r\r\n", "error": "Error 0x00000057 occurred:\r\r\nThe parameter is incorrect.\r\r\n\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\auditpol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AuthHost.exe-199E71236CF51D5330DBB343EBD2CBC3": { "file_name": "AuthHost.exe", "file_path": "C:\\Windows\\system32\\AuthHost.exe", "hash_md5": "199E71236CF51D5330DBB343EBD2CBC3", "hash_sha1": "1254BDE46B089E4930AC650B2F4DBE5B43E20EBC", "hash_sha256": "7B24C56BD854742A55CCB2210846B71A48EE821B1DFA1EF70918B63DA0005A1A", "hash_sha384": "44369CBE8F495BA95B8FDCD38BC9FDBF7B967DBCB38FCDEA74AB0AFCAC132DEEEFEA5CDB9196913A877C1C6338A11424", "hash_sha512": "987FCA42A0511176D44B6BF3DDF4D7669405AA3DE40573EEBC920FCCF29CB24A60371E1E6AEB58D46460A159BA65DDCAB036911BAD006E841107398C2E0731FC", "hash_ssdeep": "1536:nDhJD9M8e3o0q1kWEBYq535SLWsfBbyvXl73+jql7gE5rN5DoVURpgy7uVfTxPc:m80e1kpmcgLFJa17Q8N5kVUbh7u5TxU", "hash_imp": "B807969F17FB21F4B481EED4AD78CB4C", "hash_pesha1": "22EE69C1AA35A4F27C300A552EDD46D03D83C9DB", "hash_pe256": "CBDAF126B4036A61F22EE6A05B05F001E22B3E15971D48AA0926514CD3C3284E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft AuthHost", "meta_original_filename": "AuthHost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7b24c56bd854742a55ccb2210846b71a48ee821b1dfa1ef70918b63da0005a1a/detection", "runtime_modules": [ "C:\\Windows\\system32\\AuthHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\wintypes.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ] }, "autochk.exe-40897D187D663CF88A7778CA3C4E4843": { "file_name": "autochk.exe", "file_path": "C:\\Windows\\system32\\autochk.exe", "hash_md5": "40897D187D663CF88A7778CA3C4E4843", "hash_sha1": "BED555241C1CC102F91AADB28E2C87CFE1F739A6", "hash_sha256": "467C3CCA2C7DA9CC8E3A43F80A28D18EAD9F2B85197DB4FC5FE208174015F1B3", "hash_sha384": "0D491E62C281450B2F8A71896BCA9876751B45B11B733567153721BF9EEA343BB485137FDDF9CE60BCB747C3E1047CCE", "hash_sha512": "27E7D2F3E45CF02893AC538752B1055D1D304547644D5516C9A868B7B9D973FD5FD21D3B3AF83E599C8F2E4CEB08E0AC940DB73F53336B892B1122F67E45FB54", "hash_ssdeep": "12288:PQ/3ozogB6xwnmLaNlyUkHYg7bm7Gq6FxPBV0xVDdtUyb6AlM8ta5Hv3r:PEXFKmLmUUkHYg7LqgfVaVDsFPb", "hash_imp": "531155DD27B3D44E358C27BFBEE9CAC1", "hash_pesha1": "A5FA5DC6579DBF9611EA50B2D6CF78CAEF2D5D80", "hash_pe256": "F5B83AA5D07AA090EFFB6402595EA55817CFB97075298B92567651DFFE2A547A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto Check Utility", "meta_original_filename": "AutoChk.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/467c3cca2c7da9cc8e3a43f80a28d18ead9f2b85197db4fc5fe208174015f1b3/detection" }, "autoconv.exe-AB104321E37B57448F40F87E8E0BCC61": { "file_name": "autoconv.exe", "file_path": "C:\\Windows\\system32\\autoconv.exe", "hash_md5": "AB104321E37B57448F40F87E8E0BCC61", "hash_sha1": "25519383AF4B8026245576BA08A60E184374B268", "hash_sha256": "A3172D37531665F5528E5B6831CC00644694B95CE3CCEDCB32F1F0997DE22465", "hash_sha384": "BA734B979EC72458B599BFADB0D8C9930AB1AEB6B9386DBB9A3DE7329CB5408459E8968C28674F310A4011E0E873E57F", "hash_sha512": "B0305C5F9E0454A7F3ACA12141179BADA0D3E40ADDDA5AFBB8943705E0B303043C62E3BC6FB243A9A0828A1C93F38EE59E74FF62E2677AA285A1F6EE5B0BE675", "hash_ssdeep": "12288:f1IOvjjGQg42skB3hI6CWbbLNCcDQfHeCJ0fXYxoIOJ21g3r:f1RWf42ss3FdbbLwcDQf+Cifwgb", "hash_imp": "918C8F06B30D99678E0281D170345BB8", "hash_pesha1": "EFDC541EF8B2F83D126109DD081C4E6E26F0B60C", "hash_pe256": "B1A484D2CF5332D0A58398C4ADDF39EB8FF28E569F064C768DDEF2028EEF3341", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto File System Conversion Utility", "meta_original_filename": "AUTOCONV.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a3172d37531665f5528e5b6831cc00644694b95ce3ccedcb32f1f0997de22465/detection" }, "autofmt.exe-197AC6AEBD721D3BE4D9C7754B329FD5": { "file_name": "autofmt.exe", "file_path": "C:\\Windows\\system32\\autofmt.exe", "hash_md5": "197AC6AEBD721D3BE4D9C7754B329FD5", "hash_sha1": "4FA84EA6426F54F24BADF0C32D2872EA40D21B74", "hash_sha256": "561576E824768797D8B484EDC365D232E2F6532D22D748FC2BFE04E85635E6F6", "hash_sha384": "DBC7CC4F6479055E7407FD45C39276CD4671DE37F6604B7F8EA68900D92E6F341E42488E8D0F0B5A8A7B41BCC691B197", "hash_sha512": "807FE703C17A4D692A9E24D98685070F8CC83656B8D9F787EFC6F0D6B5B7BA561DC9A0595041633C9275DCE3DF7DEE8E90DF20D595F24C39C8DE57011A312F19", "hash_ssdeep": "12288:a61y/5KBFwc58Bj+1boSXkGYagSzgoZwG5rJWA4QdKVXrD0Y3r:j1e8wc585+JoSUGoloagrz41b", "hash_imp": "B4244F6B664A22C5280A208C8E07501A", "hash_pesha1": "2B2B505289B070C3030B118A81E1D000E977B216", "hash_pe256": "BB511B0767EAC8714550A8A2B343FC86E405D640884B3218E3D3A51EFFC392D3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto File System Format Utility", "meta_original_filename": "AUTOFMT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/561576e824768797d8b484edc365d232e2f6532d22d748fc2bfe04e85635e6f6/detection" }, "AxInstUI.exe-CEC05AD8BEA148A6FCA3854CB5243C3D": { "file_name": "AxInstUI.exe", "file_path": "C:\\Windows\\system32\\AxInstUI.exe", "hash_md5": "CEC05AD8BEA148A6FCA3854CB5243C3D", "hash_sha1": "F1B01909A9DD82787D96494DCEEF4387B90DC453", "hash_sha256": "3FA0691CBDC871981560B8DCE54491682CD7B574C5416DEFC889D90830FE63F8", "hash_sha384": "FD0ABCED0FA0B25BE0D488249946D7D79009D867D81088E1F8036F58E082A19C7A5D9B4DB2B36B66EF57476E6F99D8A9", "hash_sha512": "280D5B72B03BAEDA85034F27AC6F6FD28AEA64A4A64DEB3EA264FDF286BB672A2A44A481D9C3260AAE307CB039DF5E685D63A4701609B2262539C1ABDCD9719A", "hash_ssdeep": "384:2j00uSxMVdckL061itZdOTw+1xq3UZU9a1xq3UZU9GW5IW:2j0h9pL0ntZdOTw8ZU9QZU9h", "hash_imp": "7D8DEE85A40FC5307CB205608512D381", "hash_pesha1": "13B6DE7AA71FBBE7FDB9E1D8C469DDBA9C7A230C", "hash_pe256": "C406003AE4F7131825E4DADE1246BF8F9130EAAFEDD3C46C26415B0768628E6F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ActiveX Installer Service", "meta_original_filename": "AxInstUI.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.388 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.388", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3fa0691cbdc871981560b8dce54491682cd7b574c5416defc889d90830fe63f8/detection", "runtime_modules": [ "C:\\Windows\\system32\\AxInstUI.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\WINTRUST.dll" ] }, "baaupdate.exe-A5BCC0E852AC6B17F3D0E6C9F95E95D4": { "file_name": "baaupdate.exe", "file_path": "C:\\Windows\\system32\\baaupdate.exe", "hash_md5": "A5BCC0E852AC6B17F3D0E6C9F95E95D4", "hash_sha1": "8591856DBAF1D2EE1604CE7698471531B6DAF91A", "hash_sha256": "9F2251424D855579C2E2CA78486FF4DD1DF807E6F02FD5E513065225E44AD4C6", "hash_sha384": "7ED2C3D01C8EFB95F8B6605826B1C0FCD927FA6A952387ED0D3555FB9A5025ABE8A1EFAC96D720E6BD6EA0A401FCCA0D", "hash_sha512": "E0C6837FB84B4D0757FDA0022F9F6B21026D6F0E505DEBE7BFCD2F7BAD50B02A3829BD5920774A7B6DCAC6EFBE51855C6F907E778CBCE7A4B908F3F314BB7EE2", "hash_ssdeep": "3072:u4/Tt39wnVS570M9kdatGCO+xmBc+hMPhPsx:TteVs7nyatGt+SYF", "hash_imp": "EEDA0083C7D468FE0C97DE8B9FCD7FF8", "hash_pesha1": "839E7E00D7F3243016B69AC231B84807C63D1700", "hash_pe256": "4E3A0473B80BC1AFF01BA4DAA1144110971F67E572887DCD636AD1E0286E0783", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BitLocker Access Agent Update Utility", "meta_original_filename": "BAAUPDATE.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9f2251424d855579c2e2ca78486ff4dd1df807e6f02fd5e513065225e44ad4c6/detection", "runtime_modules": [ "C:\\Windows\\system32\\baaupdate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\BDEUI.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\bcrypt.dll" ] }, "backgroundTaskHost.exe-DA7063B17DBB8BBB3015351016868006": { "file_name": "backgroundTaskHost.exe", "file_path": "C:\\Windows\\system32\\backgroundTaskHost.exe", "hash_md5": "DA7063B17DBB8BBB3015351016868006", "hash_sha1": "C6E63C7AAE9C4E07E15C1717872C0C73F3D4FB09", "hash_sha256": "20330D3CA71D58F4AEB432676CB6A3D5B97005954E45132FB083E90782EFDD50", "hash_sha384": "EAB5CEFD65A29D80B5CB330DD2F6B22AD678A10984FF13F20ADCD3187DEAA1C6114CC5BA8A78534FC40620C66214853C", "hash_sha512": "16A8E5AAD8900CB2DA6D2E06258563EFF56B4022092A750C16DA50496EC490D1B761D630135CDF313C0EF96D6F30CCE09DF9EBCA0DE96E854F2F901B34FD9D1F", "hash_ssdeep": "384:s5daovOa6xo3rHy7WqGWl8hDBRJykqQ3klGs6mJJc9:semHbHypmh1PJGDc9", "hash_imp": "D2ACF1CBC4A6DB14A34C687B9362D66B", "hash_pesha1": "47F5FDA44A6E0307FC3B9BBA945BA4F113B19811", "hash_pe256": "FF3236DB2671E3E544CB5E38638D678AE771E2BB75B9673F75F5D89D2120DA16", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Background Task Host", "meta_original_filename": "backgroundTaskHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/20330d3ca71d58f4aeb432676cb6a3d5b97005954e45132fb083e90782efdd50/detection", "runtime_modules": [ "C:\\Windows\\system32\\backgroundTaskHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "BackgroundTransferHost.exe-A6FCD059386BE8DB866BF1339A8BE345": { "file_name": "BackgroundTransferHost.exe", "file_path": "C:\\Windows\\system32\\BackgroundTransferHost.exe", "hash_md5": "A6FCD059386BE8DB866BF1339A8BE345", "hash_sha1": "FBB767272862A50AC2F3F804A454BBD6729B94F9", "hash_sha256": "62B52F9594BDD96E73B2A21944977229786D4F4C421EB0F353C310B71A56C9AA", "hash_sha384": "62C1474DC62756C6BCFC9CA2FEAA832A4E90D56C123D8F9A4E9862423EEB33C9227B75B7D87A50DB5F46F19DC411ABB2", "hash_sha512": "E2C122CC16B3B675EC533FB780D09F10058163D33D1B90770E34A9121DE0DDD12F503AD8130CE7DD18675D1875ACB83EE13776E7EA7343789016944939B72835", "hash_ssdeep": "384:of2V54xSVFSkVXWDUcHbImbsp2Ywe6j5W0ggWbQE0g7qW2RPT/8rFeZmJhk:o0ykVXWRje6j0T2a", "hash_imp": "43BA7C14F952D3784267C6946F79BD81", "hash_pesha1": "DFD56445663D30D831043453703290436CA792CA", "hash_pe256": "C4EE30E19B51F2BA47BC2B6CA88D81ED3320DE0FDBCCD3F62BF7023F590CBD9A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Download/Upload Host", "meta_original_filename": "BackgroundTransferHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/62b52f9594bdd96e73b2a21944977229786d4f4c421eb0f353c310b71a56c9aa/detection", "runtime_modules": [ "C:\\Windows\\system32\\BackgroundTransferHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ] }, "bcdboot.exe-A0DD46060463930D05A55D739F0B1961": { "file_name": "bcdboot.exe", "file_path": "C:\\Windows\\system32\\bcdboot.exe", "hash_md5": "A0DD46060463930D05A55D739F0B1961", "hash_sha1": "B71F09BBB4004620FFDBF225AAE6F399CFE6CD92", "hash_sha256": "04A7284AD746597DDA60589B07CF133C3A1CADF556E555AFF4967CF5EC76A097", "hash_sha384": "6D8A50CB2024C08BA3D64295C575689E66DC90B98AA4D666342E4CB16FD8DB27C3994AF9AD7AFF9D968B87600CA947BF", "hash_sha512": "9D2A41EF7889A486D5B79DA1F36C0C67AE56DE3A278F0F1CABA4F2144A8B6D0EE6E4696EF366D2D9607EC67CD3F9124D0F3F60ED7D023FACA89D3ECFB0D68590", "hash_ssdeep": "3072:iBAqaCxGjFhQ5ny02WDNHGR5aK2QAP9wqb83OD+eOT3Rz4DUVQkx:iCqagV5nyNW+aK2vP9d83ODSUUV3", "hash_imp": "AF86C47D5C1FD207A4F0077D8879A7AB", "hash_pesha1": "5E4BE138CFDB20F9F06534089C40449F270B5182", "hash_pe256": "D0BDFD724A6E14FE6BB5ACB490B2C28E58E5762089DD8A2CD5EF04CE111396FF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Bcdboot utility", "meta_original_filename": "bcdboot.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/04a7284ad746597dda60589b07cf133c3a1cadf556e555aff4967cf5ec76a097/detection", "output": "\r\nBcdboot - Bcd boot file creation and repair tool.\r\n\r\nThe bcdboot.exe command-line tool is used to copy critical boot files to the\r\nsystem partition and to create a new system BCD store.\r\n\r\nbcdboot <source> [/l <locale>] [/s <volume-letter> [/f <firmware>]] [/v]\r\n [/vbcd] [/m [{OS Loader ID}]] [/addlast] [/p] [/c]\r\n\r\n source Specifies the location of the windows system root.\r\n\r\n /l Specifies an optional locale parameter to use when\r\n initializing the BCD store. The default is US English.\r\n\r\n /s Specifies an optional volume letter parameter to designate\r\n the target system partition where boot environment files are\r\n copied. The default is the system partition identified by\r\n the firmware.\r\n\r\n /v Enables verbose mode.\r\n\r\n /vbcd Enables BCD logging.\r\n\r\n /m If an OS loader GUID is provided, this option merges the\r\n given loader object with the system template to produce a\r\n bootable entry. Otherwise, only global objects are merged.\r\n\r\n /d Specifies that the existing default windows boot entry\r\n should be preserved.\r\n\r\n /f Used with the /s command, specifies the firmware type of the\r\n target system partition. Options for <firmware> are 'UEFI',\r\n 'BIOS', or 'ALL'.\r\n\r\n /addlast Specifies that the windows boot manager firmware entry\r\n should be added last. The default behavior is to add it\r\n first.\r\n\r\n /bcdclean Clean the BCD Store. By default, simply removes any duplicate\r\n entries in the BCD. Can be followed by 'full'. In this case,\r\n each entry is scanned. If the corresponding device for that entry\r\n does not exist, the entry is deleted.\r\n\r\n /p Specifies that the windows boot manager firmware entry\r\n position should be preserved. If entry does not exist,\r\n new entry will be added in the first position.\r\n\r\n /c Specifies that any existing objects described by the template\r\n should not be migrated.\r\n\r\nExamples: bcdboot c:\\windows /l en-us\r\n bcdboot c:\\windows /s h:\r\n bcdboot c:\\windows /s h: /f UEFI\r\n bcdboot c:\\windows /m {d58d10c6-df53-11dc-878f-00064f4f4e08}\r\n bcdboot c:\\windows /d /addlast\r\n bcdboot c:\\windows /p\r\n", "runtime_modules": [ "C:\\Windows\\system32\\bcdboot.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "bcdedit.exe-628DC41BC80918EBCABA972B911267B7": { "file_name": "bcdedit.exe", "file_path": "C:\\Windows\\system32\\bcdedit.exe", "hash_md5": "628DC41BC80918EBCABA972B911267B7", "hash_sha1": "B1A125DEACB9B549545C0BB77097DD2A00AA8DD9", "hash_sha256": "8DE81171C19749E77DBF7317316EB8D0FE3BD1D2A52413E5D997E9248A325D37", "hash_sha384": "9E19B787C80F4140916A7E77119E0201ED3CBB16ACAEF1AD8E364EA19842457270C0FD97308C3A5960A142B996AB26E8", "hash_sha512": "1EE359673724822653612E61845593210782B9BC9FE45D57DED9C2CA61A4E6B68F61FBE1F3C9C36E9919D0AFAA423D1BBBFD61F70BCECDF1EAFABBB57746AAF6", "hash_ssdeep": "6144:Jah5m2sLddo16eYXrnWTKB0GgEKkGh7qA:J45m2I7oMWT8BJKkK7", "hash_imp": "ED47BFF4333B75903582989F6C229A64", "hash_pesha1": "CA4AFC6A21A48C385F25D9FAC1F5ADC944121102", "hash_pe256": "A67024B12B994B13EC6DDE69E0DCF1D73A248F19C054857638CA8D9CCB9E0A88", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Boot Configuration Data Editor", "meta_original_filename": "bcdedit.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8de81171c19749e77dbf7317316eb8d0fe3bd1d2a52413e5d997e9248a325d37/detection", "output": "\r\nBCDEDIT - Boot Configuration Data Store Editor\r\n\r\nThe Bcdedit.exe command-line tool modifies the boot configuration data store.\r\nThe boot configuration data store contains boot configuration parameters and\r\ncontrols how the operating system is booted. These parameters were previously\r\nin the Boot.ini file (in BIOS-based operating systems) or in the nonvolatile\r\nRAM entries (in Extensible Firmware Interface-based operating systems). You can\r\nuse Bcdedit.exe to add, delete, edit, and append entries in the boot\r\nconfiguration data store.\r\n\r\nFor detailed command and option information, type bcdedit.exe /? <command>. For\r\nexample, to display detailed information about the /createstore command, type:\r\n\r\n bcdedit.exe /? /createstore\r\n\r\nFor an alphabetical list of topics in this help file, run \"bcdedit /? TOPICS\".\r\n\r\nCommands that operate on a store\r\n================================\r\n/store Used to specify a BCD store other than the current system default.\r\n/createstore Creates a new and empty boot configuration data store.\r\n/export Exports the contents of the system store to a file. This file\r\n can be used later to restore the state of the system store.\r\n/import Restores the state of the system store using a backup file\r\n created with the /export command.\r\n/sysstore Sets the system store device (only affects EFI systems, does\r\n not persist across reboots, and is only used in cases where\r\n the system store device is ambiguous).\r\n\r\nCommands that operate on entries in a store\r\n===========================================\r\n/copy Makes copies of entries in the store.\r\n/create Creates new entries in the store.\r\n/delete Deletes entries from the store.\r\n/mirror Creates mirror of entries in the store.\r\n\r\nRun bcdedit /? ID for information about identifiers used by these commands.\r\n\r\nCommands that operate on entry options\r\n======================================\r\n/deletevalue Deletes entry options from the store.\r\n/set Sets entry option values in the store.\r\n\r\nRun bcdedit /? TYPES for a list of datatypes used by these commands.\r\nRun bcdedit /? FORMATS for a list of valid data formats.\r\n\r\nCommands that control output\r\n============================\r\n/enum Lists entries in the store.\r\n/v Command-line option that displays entry identifiers in full,\r\n rather than using names for well-known identifiers.\r\n Use /v by itself as a command to display entry identifiers\r\n in full for the ACTIVE type.\r\n\r\nRunning \"bcdedit\" by itself is equivalent to running \"bcdedit /enum ACTIVE\".\r\n\r\nCommands that control the boot manager\r\n======================================\r\n/bootsequence Sets the one-time boot sequence for the boot manager.\r\n/default Sets the default entry that the boot manager will use.\r\n/displayorder Sets the order in which the boot manager displays the\r\n multiboot menu.\r\n/timeout Sets the boot manager time-out value.\r\n/toolsdisplayorder Sets the order in which the boot manager displays\r\n the tools menu.\r\n\r\nCommands that control Emergency Management Services for a boot application\r\n==========================================================================\r\n/bootems Enables or disables Emergency Management Services\r\n for a boot application.\r\n/ems Enables or disables Emergency Management Services for an\r\n operating system entry.\r\n/emssettings Sets the global Emergency Management Services parameters.\r\n\r\nCommand that control debugging\r\n==============================\r\n/bootdebug Enables or disables boot debugging for a boot application.\r\n/dbgsettings Sets the global debugger parameters.\r\n/debug Enables or disables kernel debugging for an operating system\r\n entry.\r\n/hypervisorsettings Sets the hypervisor parameters.\r\n\r\nCommand that control remote event logging\r\n=========================================\r\n/eventsettings Sets the global remote event logging parameters.\r\n/event Enables or disables remote event logging for an operating \r\n system entry.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\bcdedit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "bdechangepin.exe-5A7DB303C82FB9AC72483ABB58B5CF8C": { "file_name": "bdechangepin.exe", "file_path": "C:\\Windows\\system32\\bdechangepin.exe", "hash_md5": "5A7DB303C82FB9AC72483ABB58B5CF8C", "hash_sha1": "2C8084670A72E17A4435A2C6DA661DDE8A5FB42B", "hash_sha256": "7205E5645C6CAE8CDFD337638B55532260BD0CD6FECE68EF62C26312B69A7D3F", "hash_sha384": "ECF69C322C1A008489628E5D30903AEDAE49540E1154D74D73A2639C5C72F7CA2C515BB243EE916210A4E48A8EDC96EF", "hash_sha512": "55954CD12505D8E6E4CF94A5CB0FA6881EEA0FB7800845230737F0C3B950CCDFB882BC6B8C58CEB9D25B38F09275F0C417278B854CAC542945C3F06CD4FB8A06", "hash_ssdeep": "6144:nq6X4aHVxHEVHHHQVb1kHVqHVqHQQ9T8TXT5ThT2HVfAXTWT6TITQTMVyW176eIi:qQTH+S+", "hash_imp": "4495500841C44942B029618F7907A5D9", "hash_pesha1": "B59CD5AF984F7C046DD7C7DAD6D89CE95209B612", "hash_pe256": "FDFF63ECCA5B3E790CEC8A7960C14782BBC95C47DD7FA4C66B6BA972E968FCB8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BitLocker Drive Encryption: PIN Change Tool", "meta_original_filename": "bdechangepin.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7205e5645c6cae8cdfd337638b55532260bd0cd6fece68ef62c26312b69a7d3f/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\bdechangepin.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\bdechangepin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\BDEUI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\FVEAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "runtime_window_title": "BitLocker Drive Encryption" }, "BdeHdCfg.exe-89D0572C9B53F34230C8514F6B11BD56": { "file_name": "BdeHdCfg.exe", "file_path": "C:\\Windows\\system32\\BdeHdCfg.exe", "hash_md5": "89D0572C9B53F34230C8514F6B11BD56", "hash_sha1": "C8111FA4BB979386BD9C7923EB5E8BA3CB2947FB", "hash_sha256": "A6797C873AF8F7FEFE1352876113CD912E329759E838CF2F49ECD7BDF4BF4F26", "hash_sha384": "EAE382250DEAEE0F6A1ABA0D4B1AAC80D50048E043B51742D06DD19984A47BF456C928C6D751317163370E5751C4E344", "hash_sha512": "EC6199DF2DACA0DE2BC279E891D5996BA4AFC6EE1892AA878FB17C438F7C2EBC4E7678A582151ACC56D7FB74E8787E3EC8D5AA0C370DF0B5D0DEA0DEDFC30EA0", "hash_ssdeep": "3072:pq93U6JRZxaPUKHVZzwnVS570M9kdatGCO+xmBc+hMPhPsx:pqzXKHVZ8Vs7nyatGt+SYF", "hash_imp": "BED35470582631F338EFA043107C9B11", "hash_pesha1": "D1A8D815A510A7D9E4EC21989D4B1748A7C2C202", "hash_pe256": "85C2E37B81F2E69FDE96A4B39D473E49E1C0B327FD8F26B04F5634EA2D824BB7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BitLocker Drive Encryption: Drive Preparation Tool", "meta_original_filename": "BdeHdCfg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a6797c873af8f7fefe1352876113cd912e329759e838cf2f49ecd7bdf4bf4f26/detection", "output": "BitLocker Drive Preparation Tool version 10.0.19041\r\r\nCopyright (C) 2013 Microsoft Corporation. All rights reserved.\r\r\n\r\r\nUsage:\r\r\n\r\r\nBdeHdCfg[.exe] \r\r\n [-driveinfo]\r\r\n [-target {default | unallocated | \r\r\n TargetDriveLetter {shrink | merge}}]\r\r\n [-newdriveletter DriveLetter]\r\r\n [-size SizeInMegabytes]\r\r\n [-quiet] [-restart] [{-? | /?}]\r\r\n\r\r\nDescription:\r\r\n This command prepares your hard drive for BitLocker Drive Encryption.\r\r\n\r\r\n Command line parameters are not case-sensitive.\r\r\n\r\r\nParameters:\r\r\n -driveinfo\r\r\n Displays information about valid target drives.\r\r\n\r\r\n -target\r\r\n Specifies the target and operation.\r\r\n\r\r\n Specify 'shrink' to create a new active partition.\r\r\n Specify 'merge' to make an existing partition active.\r\r\n Specify 'unallocated' to use unformatted space on disk.\r\r\n Specify 'default' for the target to be chosen automatically.\r\r\n\r\r\n Examples: -target D: merge\r\r\n -target C: shrink\r\r\n -target unallocated\r\r\n -target default\r\r\n\r\r\n -newdriveletter\r\r\n Specifies the desired drive letter for the new drive. This option is\r\r\n only valid when a new drive is created.\r\r\n\r\r\n Example: -newdriveletter S:\r\r\n\r\r\n -size\r\r\n Specifies the desired size of the new drive. This option is only valid\r\r\n when a new drive is created.\r\r\n\r\r\n If not specified, the Drive Preparation Tool assumes the required\r\r\n minimum size of 550 megabytes.\r\r\n\r\r\n Example: -size 700\r\r\n \r\r\n -quiet\r\r\n Specifies operation in quiet mode. No output from the drive preparation\r\r\n tool is displayed.\r\r\n\r\r\n -restart\r\r\n Enables an automatic restart after drive preparation.\r\r\n\r\r\n You must restart your computer before enabling BitLocker.\r\r\n\r\r\n -? or /?\r\r\n Displays help for this command.\r\r\n\r\r\nExamples:\r\r\n BdeHdCfg -target c: shrink -newdriveletter x: -size 550 -quiet -restart\r\r\n BdeHdCfg -target d: merge -quiet -restart\r\r\n BdeHdCfg -target unallocated -newdriveletter s:\r\r\n BdeHdCfg -target default\r\r\n\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\BdeHdCfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "BdeUISrv.exe-E0ABA1CF3AC2F198D1F3B78331E6AD46": { "file_name": "BdeUISrv.exe", "file_path": "C:\\Windows\\system32\\BdeUISrv.exe", "hash_md5": "E0ABA1CF3AC2F198D1F3B78331E6AD46", "hash_sha1": "81A67C8FF145E32391E2680104AF86695F202215", "hash_sha256": "37E9A578A9802A02C5A78BD3466127A21E555422E3D7847B63471AA9DFEF04C4", "hash_sha384": "4308A1BE244035CB9AB46EF659337B8A5CA7CC304C568E96994068922E453B9BDEC8562D1290D0E213BA2046278504BC", "hash_sha512": "9891D95B837807D23354647813500898DA7648448A1E6517C2F06E418B5981FD1A91F63E5CE9C5E65D88376F65562E8665D81A7CB55AECB6E6BCF08C1CA32F02", "hash_ssdeep": "1536:viwyXsYLR3FrzDn0YVEYW3bcZd84ImNqtae:donV3Fr3Yrcbotae", "hash_imp": "282735D0D5831BB1C7033BF08F93ACE8", "hash_pesha1": "723F42514E9B5C57453753C72EE793D63BA68DAB", "hash_pe256": "3631C1042B77F6BC148D9F0F23E93C5359FDCEF2EAB36BC06D9E8999D26E27A0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BDE UI Launcher", "meta_original_filename": "BDEUISRV.DLL", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.329 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.329", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/37e9a578a9802a02c5a78bd3466127a21e555422e3d7847b63471aa9dfef04c4/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\BdeUISrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\system32\\USERENV.dll" ] }, "bdeunlock.exe-6DF8548ED3BA2DF3C682A5E342DA7BE4": { "file_name": "bdeunlock.exe", "file_path": "C:\\Windows\\system32\\bdeunlock.exe", "hash_md5": "6DF8548ED3BA2DF3C682A5E342DA7BE4", "hash_sha1": "0DA1B1ADF286C318E3AB950C4C4D0C778177C8E3", "hash_sha256": "387911A1AC9D717420B0BD6E4C8055EF2EC75C66C64FFA2447B12D49E95AC4B4", "hash_sha384": "68945F14D385A7F8C3F9C1F4C3533630CB4181DF72646509F121F6B22D75126C8948AC6F66DC723794D3D01095B14B8B", "hash_sha512": "A151B05BD05C986A7B4B358D18ABBAD7F56CFD723FFAD36D7CD7B8B515A21DD1F67650271B9EE9269BD8BF6B474CA579849273EBC9378E070960617FBD4E7F37", "hash_ssdeep": "6144:8v4KaSwBeBLnDXjosNiGkPHgmqEwo4ndpjVs7nyatGt+SYFSW2:8v1aS6eBzDXjosNiGkvgmqEwTd1H+S+", "hash_imp": "62596CD98BFD22A43D0FBC85C9A00B6F", "hash_pesha1": "67EEED5D03FB25862A9FF9EBE5185913C02066A1", "hash_pe256": "DEB1475870A373DF000D64FC6E441DB1B581722319E24D6E52EB382E760D0455", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BitLocker Unlock", "meta_original_filename": "BDEUNLOCK.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "1/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/387911a1ac9d717420b0bd6e4c8055ef2ec75c66c64ffa2447b12d49e95ac4b4/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\bdeunlock.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SystemResources\\Windows.UI.Immersive.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\Windows.UI.Immersive.dll.mui": "File", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RWD) C:\\Windows\\Fonts\\segoeuisl.ttf": "File", "(RWD) C:\\Windows\\Fonts\\seguisym.ttf": "File", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\bdeunlock.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\BDEUI.dll", "C:\\Windows\\system32\\FVEAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\cfgmgr32.dll" ] }, "BioIso.exe-CA90DB02AAF23C6D9E81896B63913B85": { "file_name": "BioIso.exe", "file_path": "C:\\Windows\\system32\\BioIso.exe", "hash_md5": "CA90DB02AAF23C6D9E81896B63913B85", "hash_sha1": "78B9F2B975670B9BD185CBC9D9408DBBBA1ECF61", "hash_sha256": "9BD80E2859E159D0B70A7FEB6EE112CC3FAD31A9B4A1D861D139E33C92C6FFFF", "hash_sha384": "67F81C4B932193A81E58E17F1BC0E6652B5220B875D885427ED9463DCA56E691240C3868630ABDACF54FCD179AD04DB2", "hash_sha512": "3038D852FE8DEDBD174A33BBD6046F848C3452DC6550528F3B295922E20E78C34E5CB6CD7409E05E7C40270897B110CBA7A73BC662961BB29ECAEEFC3A3C4B29", "hash_ssdeep": "12288:KZXrd7K9Aa4p8dAxPmJ2Jby170h0z4A/zWKBIj3bIwUCbKbe+QNAl3h:aQdOPmJLWKBIDbIwUCbKbe+QNI", "hash_imp": "3F5B796077B309628770294C7B57EC57", "hash_pesha1": "3B2872076F2DB4693C5A4308E06013A94865829C", "hash_pe256": "42B5DC67ED8259EDE00316F09A1AE32A6F0854C038B465A7D19FD9E1B80F3730", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Secure Biometrics", "meta_original_filename": "BioIso.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/9bd80e2859e159d0b70a7feb6ee112cc3fad31a9b4a1d861d139e33c92c6ffff/detection", "runtime_modules": [ "C:\\Windows\\system32\\BioIso.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\IumSdk.dll", "C:\\Windows\\system32\\iumbase.DLL", "C:\\Windows\\SYSTEM32\\IUMDLL.dll" ] }, "BitLockerDeviceEncryption.exe-F7B836FF5CB5A7913DF883B565C36473": { "file_name": "BitLockerDeviceEncryption.exe", "file_path": "C:\\Windows\\system32\\BitLockerDeviceEncryption.exe", "hash_md5": "F7B836FF5CB5A7913DF883B565C36473", "hash_sha1": "7F6EA24AC3B81BF0C7624E26751411C84514BBCA", "hash_sha256": "777C576288E43A1332D7F0B985BB788A6DCC9369102579C604711CAE1B12EA27", "hash_sha384": "76796B3A75F487416567F7D037A73E7E7C530F748A8EFCC864B083B389FED577A0EB60978EA4CFB3F8BB51DC79F00D22", "hash_sha512": "E420E2BFE4C25FB8C29B0055004D19959267035C51D57D73B7F781847579AEFB27765B8CA29337F93EEE3E053DA1D124365DA0AAE1AB6EC44328D262210EB86F", "hash_ssdeep": "3072:mIpJVc85ucB0w4LORAFqyORJPBa+W/vkh8ZsViOo:mqVc7zL8AF1ORPaTGViO", "hash_imp": "1ABE7D6A7284BF03930A349D9B175DED", "hash_pesha1": "320412CE63ABF0FD07947662A4E909690B9D1985", "hash_pe256": "229B107F0E56B9B4D8D36C4945183210B0100E226911DBDC62920F3141E09E06", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BitLocker Device Encryption Tool", "meta_original_filename": "BitLockerDeviceEncryption.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/777c576288e43a1332d7f0b985bb788a6dcc9369102579c604711cae1b12ea27/detection", "runtime_modules": [ "C:\\Windows\\system32\\BitLockerDeviceEncryption.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\FVESKYBACKUP.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\FVEAPI.dll", "C:\\Windows\\system32\\WINHTTP.dll", "C:\\Windows\\system32\\dsreg.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll" ] }, "BitLockerWizard.exe-A9C78F189E2111734F7E961EBE38188A": { "file_name": "BitLockerWizard.exe", "file_path": "C:\\Windows\\system32\\BitLockerWizard.exe", "hash_md5": "A9C78F189E2111734F7E961EBE38188A", "hash_sha1": "F4C13F46048B4B536083D4627A1C0E2C22753385", "hash_sha256": "13302146579B36397D4B5E602F98B8474A65BDCC125E499FD0FF2EEFD811C44B", "hash_sha384": "9D54C7149FCC8E3FA00752419C78B6D1F5DF988907D5549DA2BEAB8B823DE19E2587F67F6DA999BE4D41BDDDA007CF81", "hash_sha512": "7389E29B83E6ECFD061C7668A1B4841D0359E40DF34460E8FAA2A616A6F3F46B2F1405630E32F6ABB311FF2C527966DAB13ADD386F6F685FE9FDE7C8C3864F90", "hash_ssdeep": "3072:NZoyKwnVS570M9kdatGCO+xmBc+hMPhPsx:ceVs7nyatGt+SYF", "hash_imp": "1438673C4B1B5696C777658AD76B5D13", "hash_pesha1": "D4F285E06AE87D808F75688D470822451E9B3C42", "hash_pe256": "8B8002DC5034BED43A7814A1BEB3B7AED27BC2014D7B879C62F686825C308335", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BitLocker Drive Encryption Wizard", "meta_original_filename": "BitLockerWizard.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/13302146579b36397d4b5e602f98b8474a65bdcc125e499fd0ff2eefd811c44b/detection", "error": "Bitlocker Wizard Launcher\r\n \tUsage: BitlockerWizard X: <P|R|S|T>\r\n \t P is mapped to FVEUI_AFTER_TPM_PPI_NO_REBOOT\r\n \t R is mapped to FVEUI_AFTER_TPM_PPI_REBOOT\r\n \t S is mapped to FVEUI_MODE_CREATE_NO_REBOOT\r\n \t T is mapped to FVEUI_MODE_CREATE_AFTER_REBOOT\r\n \t U is mapped to FVEUI_MODE_DUPLICATEKEY\r\n \t V is mapped to FVEUI_MODE_RESUME\r\n \t W is mapped to FVEUI_AFTER_REPARTITION\r\n \t X is mapped to FVEUI_PARAM_AFTER_REPARTITION_TPM_PPI\r\n \t Y is mapped to FVEUI_PARAM_SAVE_RECOVERY\r\n \t Z is mapped to FVEUI_PARAM_PASSPHRASE\r\n \t K is mapped to FVEUI_PARAM_STARTUPKEY\r\n \t J is mapped to FVEUI_PARAM_CHANGE_PIN\r\n \t I is mapped to FVEUI_PARAM_STARTUP_UNLOCK\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\BitLockerWizard.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\FVEWIZ.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\system32\\BDEUI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\COMDLG32.dll" ] }, "BitLockerWizardElev.exe-68A4D7474F142060F46C37BCE45FABFE": { "file_name": "BitLockerWizardElev.exe", "file_path": "C:\\Windows\\system32\\BitLockerWizardElev.exe", "hash_md5": "68A4D7474F142060F46C37BCE45FABFE", "hash_sha1": "2949BBE6968EE2CBF4F7F86A29035FE5EB604D6E", "hash_sha256": "15820C45B1686910877FFACED9A9E9AE02334B967475FDE566E60CE8D4BD182B", "hash_sha384": "CDD861A80A42366471385A4DE92FD73D1B35A36BED3CC55D16FE8BCB45025F6C5E9EDD4626AA405004763DB544CBDCC8", "hash_sha512": "D4A2953577B7F549BD1BB77DF3C5219F05FEB553A7480E0FAB54F02448C79E63480863DDBD39CFADCA00F3DF1BD12D5D70E855E5150B032E171DEA84B81E0676", "hash_ssdeep": "3072:wZEDf0wnVS570M9kdatGCO+xmBc+hMPhPsx:XDdVs7nyatGt+SYF", "hash_imp": "1438673C4B1B5696C777658AD76B5D13", "hash_pesha1": "87D80066BFE91AB2444D785EF4DEE53A168DA5A7", "hash_pe256": "A2816E86745F9865B475A80F48E37AC346E502707E208B6EE841ACC7D9AA8AA9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BitLocker Drive Encryption Wizard", "meta_original_filename": "BitLockerWizardElev.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/15820c45b1686910877ffaced9a9e9ae02334b967475fde566e60ce8d4bd182b/detection", "error": "Bitlocker Wizard Launcher\r\n \tUsage: BitlockerWizard X: <P|R|S|T>\r\n \t P is mapped to FVEUI_AFTER_TPM_PPI_NO_REBOOT\r\n \t R is mapped to FVEUI_AFTER_TPM_PPI_REBOOT\r\n \t S is mapped to FVEUI_MODE_CREATE_NO_REBOOT\r\n \t T is mapped to FVEUI_MODE_CREATE_AFTER_REBOOT\r\n \t U is mapped to FVEUI_MODE_DUPLICATEKEY\r\n \t V is mapped to FVEUI_MODE_RESUME\r\n \t W is mapped to FVEUI_AFTER_REPARTITION\r\n \t X is mapped to FVEUI_PARAM_AFTER_REPARTITION_TPM_PPI\r\n \t Y is mapped to FVEUI_PARAM_SAVE_RECOVERY\r\n \t Z is mapped to FVEUI_PARAM_PASSPHRASE\r\n \t K is mapped to FVEUI_PARAM_STARTUPKEY\r\n \t J is mapped to FVEUI_PARAM_CHANGE_PIN\r\n \t I is mapped to FVEUI_PARAM_STARTUP_UNLOCK\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\BitLockerWizardElev.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\FVEWIZ.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\system32\\BDEUI.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\FVEAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\FVEUI.dll", "C:\\Windows\\system32\\NETAPI32.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\BDEHDCFGLIB.dll", "C:\\Windows\\system32\\FVECERTS.dll", "C:\\Windows\\system32\\FVESKYBACKUP.dll", "C:\\Windows\\system32\\VSSAPI.DLL", "C:\\Windows\\system32\\profapi.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\system32\\dsreg.dll", "C:\\Windows\\system32\\ReAgent.dll", "C:\\Windows\\system32\\credui.dll", "C:\\Windows\\system32\\WINHTTP.dll", "C:\\Windows\\system32\\VssTrace.DLL", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\system32\\WKSCLI.DLL", "C:\\Windows\\system32\\NETUTILS.DLL" ] }, "bitsadmin.exe-01AAB62D5799F75B0D69EB29C1CA6855": { "file_name": "bitsadmin.exe", "file_path": "C:\\Windows\\system32\\bitsadmin.exe", "hash_md5": "01AAB62D5799F75B0D69EB29C1CA6855", "hash_sha1": "3FD6EB9A72446F34F309ADFAA6B8695EECD5B4B6", "hash_sha256": "739B2DD012EA183895CC01116906F339C9AA1C0BAABF6F22C8E59E25A0C12917", "hash_sha384": "2AA55A915BA0A19F31DBDD940B95D627254A8A679695CFC2A1CAD852B8D8AB55418B8F990D1B31F93DDC10FC54B1981D", "hash_sha512": "5AF578B6DCD86CF97D3DC68E882336B48930CEF5CA70C29FA755792A20A2FF9B2EAD486213BF35DB4A2490B663D4FF63DB8235DD4D5E278D763ED17A353D11F1", "hash_ssdeep": "3072:fnFedmxU5z8iwzLX/5kXm2wIvi53+Yvsd0etQSmX0jhwTKm3:fnFrymr/5kXmxS/h7", "hash_imp": "774033454EB79213B09F788FC004A02D", "hash_pesha1": "DA4ABE55AF4381E59156E41783F9919B8F85669F", "hash_pe256": "190C485A5C054B8ADBB7EF8D413CD6455416FCAE79FD0B66E596B116DF16F0F9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BITS administration utility", "meta_original_filename": "bitsadmin.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.8.19041.1 (WinBuild.160101.0800)", "meta_product_version": "7.8.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/739b2dd012ea183895cc01116906f339c9aa1c0baabf6f22c8e59e25a0c12917/detection", "output": "\r\nBITSADMIN version 3.0\r\nBITS administration utility.\r\n(C) Copyright Microsoft Corp.\r\n\r\nInvalid command\r\nUSAGE: BITSADMIN [/RAWRETURN] [/WRAP | /NOWRAP] command\r\nThe following commands are available:\r\n\r\n/HELP Prints this help \r\n/? Prints this help \r\n/UTIL /? Prints the list of utilities commands \r\n/PEERCACHING /? Prints the list of commands to manage Peercaching\r\n/CACHE /? Prints the list of cache management commands \r\n/PEERS /? Prints the list of peer management commands\r\n\r\n/LIST [/ALLUSERS] [/VERBOSE] List the jobs\r\n/MONITOR [/ALLUSERS] [/REFRESH sec] Monitors the copy manager\r\n/RESET [/ALLUSERS] Deletes all jobs in the manager\r\n\r\n/TRANSFER <job name> [type] [/PRIORITY priority] [/ACLFLAGS flags] [/DYNAMIC] \r\n remote_url local_name\r\n Transfers one of more files.\r\n [type] may be /DOWNLOAD or /UPLOAD; default is download\r\n Multiple URL/file pairs may be specified.\r\n Unlike most commands, <job name> may only be a name and not a GUID.\r\n /DYNAMIC configures the job with BITS_JOB_PROPERTY_DYNAMIC_CONTENT, which relaxes the server-side requirements.\r\n\r\n/CREATE [type] <job name> Creates a job\r\n [type] may be /DOWNLOAD, /UPLOAD, or /UPLOAD-REPLY; default is download\r\n Unlike most commands, <job name> may only be a name and not a GUID.\r\n\r\n/INFO <job> [/VERBOSE] Displays information about the job\r\n/ADDFILE <job> <remote_url> <local_name> Adds a file to the job\r\n/ADDFILESET <job> <textfile> Adds multiple files to the job\r\n Each line of <textfile> lists a file's remote name and local name, separated\r\n by spaces. A line beginning with '#' is treated as a comment.\r\n Once the file set is read into memory, the contents are added to the job.\r\n\r\n/ADDFILEWITHRANGES <job> <remote_url> <local_name range_list>\r\n Like /ADDFILE, but BITS will read only selected byte ranges of the URL.\r\n range_list is a comma-delimited series of offset and length pairs.\r\n For example,\r\n\r\n 0:100,2000:100,5000:eof\r\n\r\n instructs BITS to read 100 bytes starting at offset zero, 100 bytes starting\r\n at offset 2000, and the remainder of the URL starting at offset 5000.\r\n\r\n/REPLACEREMOTEPREFIX <job> <old_prefix> <new_prefix>\r\n All files whose URL begins with <old_prefix> are changed to use <new_prefix>\r\n\r\nNote that BITS currently supports HTTP/HTTPS downloads and uploads.\r\nIt also supports UNC paths and file:// paths as URLS\r\n\r\n/LISTFILES <job> Lists the files in the job\r\n/SUSPEND <job> Suspends the job\r\n/RESUME <job> Resumes the job\r\n/CANCEL <job> Cancels the job\r\n/COMPLETE <job> Completes the job\r\n\r\n/GETTYPE <job> Retrieves the job type\r\n/GETACLFLAGS <job> Retrieves the ACL propagation flags\r\n\r\n/SETACLFLAGS <job> <ACL_flags> Sets the ACL propagation flags for the job\r\n O - OWNER G - GROUP \r\n D - DACL S - SACL \r\n\r\n Examples:\r\n bitsadmin /setaclflags MyJob OGDS\r\n bitsadmin /setaclflags MyJob OGD\r\n\r\n/GETBYTESTOTAL <job> Retrieves the size of the job\r\n/GETBYTESTRANSFERRED <job> Retrieves the number of bytes transferred\r\n/GETFILESTOTAL <job> Retrieves the number of files in the job\r\n/GETFILESTRANSFERRED <job> Retrieves the number of files transferred\r\n/GETCREATIONTIME <job> Retrieves the job creation time\r\n/GETMODIFICATIONTIME <job> Retrieves the job modification time\r\n/GETCOMPLETIONTIME <job> Retrieves the job completion time\r\n/GETSTATE <job> Retrieves the job state\r\n/GETERROR <job> Retrieves detailed error information\r\n/GETOWNER <job> Retrieves the job owner\r\n/GETDISPLAYNAME <job> Retrieves the job display name\r\n/SETDISPLAYNAME <job> <display_name> Sets the job display name\r\n/GETDESCRIPTION <job> Retrieves the job description\r\n/SETDESCRIPTION <job> <description> Sets the job description\r\n/GETPRIORITY <job> Retrieves the job priority\r\n/SETPRIORITY <job> <priority> Sets the job priority\r\n Priority usage choices:\r\n FOREGROUND \r\n HIGH\r\n NORMAL\r\n LOW\r\n/GETNOTIFYFLAGS <job> Retrieves the notify flags\r\n/SETNOTIFYFLAGS <job> <notify_flags> Sets the notify flags\r\n For more help on this option, please refer to the MSDN help page for SetNotifyFlags/GETNOTIFYINTERFACE <job> Determines if notify interface is registered\r\n/GETMINRETRYDELAY <job> Retrieves the retry delay in seconds\r\n/SETMINRETRYDELAY <job> <retry_delay> Sets the retry delay in seconds\r\n/GETNOPROGRESSTIMEOUT <job> Retrieves the no progress timeout in seconds\r\n/SETNOPROGRESSTIMEOUT <job> <timeout> Sets the no progress timeout in seconds\r\n/GETMAXDOWNLOADTIME <job> Retrieves the download timeout in seconds\r\n/SETMAXDOWNLOADTIME <job> <timeout> Sets the download timeout in seconds\r\n/GETERRORCOUNT <job> Retrieves an error count for the job\r\n\r\n/SETPROXYSETTINGS <job> <usage> Sets the proxy usage\r\n usage choices:\r\n PRECONFIG - Use the owner's default Internet settings.\r\n AUTODETECT - Force autodetection of proxy.\r\n NO_PROXY - Do not use a proxy server.\r\n OVERRIDE - Use an explicit proxy list and bypass list. \r\n Must be followed by a proxy list and a proxy bypass list.\r\n NULL or \"\" may be used for an empty proxy bypass list.\r\n Examples:\r\n bitsadmin /setproxysettings MyJob PRECONFIG\r\n bitsadmin /setproxysettings MyJob AUTODETECT\r\n bitsadmin /setproxysettings MyJob NO_PROXY\r\n bitsadmin /setproxysettings MyJob OVERRIDE proxy1:80 \"<local>\" \r\n bitsadmin /setproxysettings MyJob OVERRIDE proxy1,proxy2,proxy3 NULL \r\n\r\n/GETPROXYUSAGE <job> Retrieves the proxy usage setting\r\n/GETPROXYLIST <job> Retrieves the proxy list\r\n/GETPROXYBYPASSLIST <job> Retrieves the proxy bypass list\r\n\r\n/TAKEOWNERSHIP <job> Take ownership of the job\r\n\r\n/SETNOTIFYCMDLINE <job> <program_name> [program_parameters] \r\n Sets a program to execute for notification, and optionally parameters.\r\n The program name and parameters can be NULL.\r\n IMPORTANT: if parameters are non-NULL, then the program name should be the\r\n first parameter.\r\n\r\n Examples:\r\n bitsadmin /SetNotifyCmdLine MyJob c:\\winnt\\system32\\notepad.exe NULL\r\n bitsadmin /SetNotifyCmdLine MyJob c:\\callback.exe \"c:\\callback.exe parm1 parm2\" \r\n bitsadmin /SetNotifyCmdLine MyJob NULL NULL\r\n\r\n/GETNOTIFYCMDLINE <job> Returns the job's notification command line\r\n\r\n/SETCREDENTIALS <job> <target> <scheme> <username> <password>\r\n Adds credentials to a job.\r\n <target> may be either SERVER or PROXY\r\n <scheme> may be BASIC, DIGEST, NTLM, NEGOTIATE, or PASSPORT. \r\n\r\n/REMOVECREDENTIALS <job> <target> <scheme> \r\n Removes credentials from a job.\r\n/GETCUSTOMHEADERS <job> Gets the Custom HTTP Headers\r\n/SETCUSTOMHEADERS <job> <header1> <header2> <...> Sets the Custom HTTP Headers\r\n/MAKECUSTOMHEADERSWRITEONLY <job> Make a job's Custom HTTP Headers write-only (cannot be undone).\r\n\r\n/GETHTTPMETHOD <job> Gets the HTTP verb to use.\r\n/SETHTTPMETHOD <job> <HTTPMethod> Sets the HTTP verb to use.\r\n\r\n/GETCLIENTCERTIFICATE <job> Gets the job's Client Certificate Information\r\n/SETCLIENTCERTIFICATEBYID <job> <store_location> <store_name> <hexa-decimal_cert_id>\r\n Sets a client authentication certificate to a job.\r\n <store_location> may be \r\n\t1(CURRENT_USER), 2(LOCAL_MACHINE), 3(CURRENT_SERVICE),\r\n\t4(SERVICES), 5(USERS), 6(CURRENT_USER_GROUP_POLICY),\r\n\t7(LOCAL_MACHINE_GROUP_POLICY) or 8(LOCAL_MACHINE_ENTERPRISE). \r\n\r\n/SETCLIENTCERTIFICATEBYNAME <job> <store_location> <store_name> <subject_name>\r\n Sets a client authentication certificate to a job.\r\n <store_location> may be \r\n\t1(CURRENT_USER), 2(LOCAL_MACHINE), 3(CURRENT_SERVICE),\r\n\t4(SERVICES), 5(USERS), 6(CURRENT_USER_GROUP_POLICY),\r\n\t7(LOCAL_MACHINE_GROUP_POLICY) or 8(LOCAL_MACHINE_ENTERPRISE). \r\n\r\n/REMOVECLIENTCERTIFICATE <job> Removes the Client Certificate Information from the job\r\n\r\n/SETSECURITYFLAGS <job> <value> \r\n Sets the HTTP security flags for URL redirection and checks performed on the server certificate during the transfer.\r\n The value is an unsigned integer with the following interpretation for the bits in the binary representation.\r\n Enable CRL Check : Set the least significant bit\r\n Ignore invalid common name in server certificate : Set the 2nd bit from right\r\n Ignore invalid date in server certificate : Set the 3rd bit from right\r\n Ignore invalid certificate authority in server\r\n certificate : Set the 4th bit from right\r\n Ignore invalid usage of certificate : Set the 5th bit from right\r\n Redirection policy : Controlled by the 9th-11th bits from right\r\n 0,0,0 - Redirects will be automatically allowed.\r\n 0,0,1 - Remote name in the IBackgroundCopyFile interface will be updated if a redirect occurs.\r\n 0,1,0 - BITS will fail the job if a redirect occurs.\r\n\r\n Allow redirection from HTTPS to HTTP : Set the 12th bit from right\r\n\r\n/GETSECURITYFLAGS <job> \r\n Reports the HTTP security flags for URL redirection and checks performed on the server certificate during the transfer.\r\n\r\n/SETVALIDATIONSTATE <job> <file-index> <true|false>\r\n <file-index> starts from 0 \r\n Sets the content-validation state of the given file within the job.\r\n\r\n/GETVALIDATIONSTATE <job> <file-index> \r\n <file-index> starts from 0 \r\n Reports the content-validation state of the given file within the job.\r\n\r\n/GETTEMPORARYNAME <job> <file-index> \r\n <file-index> starts from 0 \r\n Reports the temporary filename of the given file within the job.\r\n\r\nThe following options control peercaching of a particular job:\r\n\r\n/SETPEERCACHINGFLAGS <job> <value> \r\n Sets the flags for the job's peercaching behavior.\r\n The value is an unsigned integer with the following interpretation for the bits in the binary representation.\r\n Allow the job's data to be downloaded from a peer : Set the least significant bit\r\n Allow the job's data to be served to peers : Set the 2nd bit from right\r\n\r\n/GETPEERCACHINGFLAGS <job> \r\n Reports the flags for the job's peercaching behavior.\r\n\r\nThe following options are valid for UPLOAD-REPLY jobs only:\r\n\r\n/GETREPLYFILENAME <job> Gets the path of the file containing the server reply\r\n/SETREPLYFILENAME <job> <path> Sets the path of the file containing the server reply\r\n/GETREPLYPROGRESS <job> Gets the size and progress of the server reply\r\n/GETREPLYDATA <job> Dumps the server's reply data in hex format\r\n\r\n/SETHELPERTOKEN <job> Sets the current command prompt's primary token as a job's helper token\r\n/GETHELPERTOKENSID <job> Reports the user account SID of a job's helper token, if one is set\r\n\r\n/SETHELPERTOKENFLAGS <job> <flags> \r\n Sets the helper token usage flags for a job. Possible values are:\r\n 1 - The helper token is used when accessing the local filesystem.\r\n 2 - The helper token is used when accessing the network.\r\n 3 - The helper token is used when accessing both the local filesystem and the network.\r\n\r\n/GETHELPERTOKENFLAGS <job> \r\n Reports a job's helper token usage flags.\r\n\r\n/GETPEERSTATS <job> <file-index> \r\n <file-index> starts from 0 \r\n Reports statistics about the amount of data downloaded from peers and origin servers for a specific file within a job.\r\n\r\nThe following options can be placed before the command:\r\n/RAWRETURN Return data more suitable for parsing\r\n/WRAP Wrap output around console (default)\r\n/NOWRAP Don't wrap output around console\r\n\r\nThe /RAWRETURN option strips new line characters and formatting.\r\nIt is recognized by the /CREATE and /GET* commands.\r\n\r\nCommands that take a <job> parameter will accept either a job name or a job ID\r\nGUID inside braces. BITSADMIN reports an error if a name is ambiguous.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\bitsadmin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "bootcfg.exe-EC92EDA497062006DCFC1D200DFD8C97": { "file_name": "bootcfg.exe", "file_path": "C:\\Windows\\system32\\bootcfg.exe", "hash_md5": "EC92EDA497062006DCFC1D200DFD8C97", "hash_sha1": "1DDFD9E8224E4CCF18C6F6DAE69DD7D8655D6716", "hash_sha256": "3AE4009D8722649281C1F352CFD65186198FC6EE8FD62B436869789F8D06D348", "hash_sha384": "897545988520D78C56B5392E232E650A47795C5DFE8C14573BE0E2B6A86B010AD6A40306E0F6589505125C61E139D14E", "hash_sha512": "82E9A336BC5ADEF11914C04FB94589BF24AB0123757F502F854CEC3578BF242E149714F0EB74961B9BFBC7A83D37A701546DB4D4EB029694AA64CE9E70F0533B", "hash_ssdeep": "1536:XKHR/57Ggj0+HPJwQWifFLAAHV1eH1OCUUjgnO18JQy+u5sFa+I38s:MpNDB/JRAt1OCUUxe+UsFa+Ix", "hash_imp": "F3ADCD04B0BF69589B2B3643D6CF3803", "hash_pesha1": "A618F84CAA76485739F31FF1B6CB0AD01836110C", "hash_pe256": "55984350FCD1FBB7B659DB5874542C28962C188F2E2BD99F63918584D852856D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BootCfg - Lists or changes the boot settings.", "meta_original_filename": "bootcfg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/3ae4009d8722649281c1f352cfd65186198fc6ee8fd62b436869789f8d06d348/detection", "output": "\r\nBOOTCFG /parameter [arguments]\r\n\r\nDescription:\r\n This command line tool can be used to configure, query, change or \r\n delete the boot entry settings in the BOOT.INI file.\r\n\r\nParameter List:\r\n /Copy Makes a copy of an existing boot entry.\r\n\r\n /Delete Deletes an existing boot entry from the BOOT.INI file.\r\n\r\n /Query Displays the current boot entries and their settings.\r\n\r\n /Raw Allows the user to specify any switch to be added.\r\n\r\n /Timeout Allows the user to change the Timeout value.\r\n\r\n /Default Allows the user to change the Default boot entry.\r\n\r\n /EMS Allows the user to configure the /redirect switch\r\n for headless support.\r\n\r\n /Debug Allows the user to specify the port and baudrate for \r\n remote debugging.\r\n\r\n /Addsw Allows the user to add predefined switches.\r\n\r\n /Rmsw Allows the user to remove predefined switches.\r\n\r\n /Dbg1394 Allows the user to configure 1394 port for debugging.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n BOOTCFG /Copy /?\r\n BOOTCFG /Delete /?\r\n BOOTCFG /Query /?\r\n BOOTCFG /Raw /?\r\n BOOTCFG /Timeout /?\r\n BOOTCFG /EMS /?\r\n BOOTCFG /Debug /?\r\n BOOTCFG /Addsw /?\r\n BOOTCFG /Rmsw /?\r\n BOOTCFG /Dbg1394 /?\r\n BOOTCFG /Default /?\r\n BOOTCFG /?\r\n\r\nWARNING: BOOT.INI is used for boot options on Windows XP and earlier\r\n operating systems. Use the BCDEDIT command line tool to modify\r\n Windows Vista boot options.\r\n", "error": "ERROR: Invalid syntax.\r\nType \"BOOTCFG /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\bootcfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "bootim.exe-9E65F3BF408CC580BED4ECB0D91AC58D": { "file_name": "bootim.exe", "file_path": "C:\\Windows\\system32\\bootim.exe", "hash_md5": "9E65F3BF408CC580BED4ECB0D91AC58D", "hash_sha1": "1D0ECFF74BBC4F1A56583773492198A84546F105", "hash_sha256": "99660E380163AFBF4D66341364909F904E9695BA2872B5DC1DF575498D2BD344", "hash_sha384": "2DCB7B9788BE0AAB594D5089A8EBDB3D72972C80C8E7A1AD4506D8896E20E910029FF12C261C8BEE0A0824F0D04CE445", "hash_sha512": "DACC80FF162DE5F818334C9ED6ED988459FB11CAAB99BC27A1B03251D2E582A425E6D93A94AC21B68B58FA7B18BFE2B75C92C1497439073A2632907B5768B719", "hash_ssdeep": "768:pq9FtEU+i2u88EoO7nwF2IDec322GBwQB:8pUuBqwFLec5GBwQB", "hash_imp": "518DDF1B5D2EAA775607E0D8B554C455", "hash_pesha1": "C79026C78DCECD923EFE271B8F64A0A4DA7E5577", "hash_pe256": "C2AD234474A4FB6BF4271026BE28D96E0A55AC49969577494FB4A5B2E1AB9CF2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "boot immersive menus", "meta_original_filename": "bootim.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.508 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.508", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/99660e380163afbf4d66341364909f904e9695ba2872b5dc1df575498d2bd344/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\bootux.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(RWD) C:\\Windows\\Fonts\\segoeuisl.ttf": "File", "(RWD) C:\\Windows\\Fonts\\segoeuil.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\bootim.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\BOOTUX.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\UIAutomationCore.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "runtime_window_title": "Boot App" }, "bootsect.exe-4A59BDA770A1683A7BC5A913EA1D74AB": { "file_name": "bootsect.exe", "file_path": "C:\\Windows\\system32\\bootsect.exe", "hash_md5": "4A59BDA770A1683A7BC5A913EA1D74AB", "hash_sha1": "C65466640BD627F40C67C7BA07814BCAE4B69E2F", "hash_sha256": "2D7CE2DD4A9CE5FBED2C150720280CF50808B0CD5D7D988CDAAF5BD1E9E292F3", "hash_sha384": "F9CCB58F7BDCBB2D2491728FE48F8C4333EBB379519FC9BBDC9617459F05CBD993201EBE7A7849A9EA80795C094C4E66", "hash_sha512": "846DDC20123C8F47F2E9205D17DCF5FF53CA962891B309E7AEBB0098ED6EB10EE56C53AC81C89745AC43B6FF8C4868A8144CAC8C35B090A38C4D70FD9ECD6D24", "hash_ssdeep": "768:rt9O59BuIAee9VkuIvsdzsyCY5eNildVUt7/8tK4ZcvNoXxrkWqVsiawjprT3lxU:RTB5egI78tKKc7XHui2IH5vgY83JDPxb", "hash_imp": "A26CB263B9DC97B5627F1E68CAAC6231", "hash_pesha1": "E350A271E03024A8D6D0E8B22818A2DCA28D229B", "hash_pe256": "9710607BA10DD6978DE04E13D7BE3223B72190F3D526D4E8F817B53F4C3956C6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Boot Sector Manipulation Tool", "meta_original_filename": "bootsect.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2d7ce2dd4a9ce5fbed2c150720280cf50808b0cd5d7d988cdaaf5bd1e9e292f3/detection", "output": "\r\nbootsect {/help|/nt60|/nt52} {SYS|ALL|<DriveLetter>:} [/force] [/mbr]\r\n\r\nBoot sector restoration tool\r\n\r\nBootsect.exe updates the master boot code for hard disk partitions in order to\r\nswitch between BOOTMGR and NTLDR. You can use this tool to restore the boot\r\nsector on your computer.\r\n\r\n/help Displays these usage instructions.\r\n\r\n/nt52 Applies the master boot code that is compatible with NTLDR to SYS,\r\n ALL, or <DriveLetter>. The operating system installed on SYS, ALL, or\r\n <DriveLetter> must be older than Windows Vista.\r\n\r\n/nt60 Applies the master boot code that is compatible with BOOTMGR to SYS,\r\n ALL, or <DriveLetter>. The operating system installed on SYS, ALL, or\r\n <DriveLetter> must be Windows Vista, Windows Server 2008 or later.\r\n\r\nSYS Updates the master boot code on the system partition used to boot\r\n Windows.\r\n\r\nALL Updates the master boot code on all partitions. ALL does not\r\n necessarily update the boot code for each volume. Instead, this\r\n option updates the boot code on volumes that could be used as Windows\r\n boot volumes, which excludes any dynamic volumes that are not\r\n connected with an underlying disk partition. This restriction is\r\n present because boot code must be located at the beginning of a disk\r\n partition.\r\n\r\n<DriveLetter> Updates the master boot code on the volume associated with this\r\n drive letter. Boot code will not be updated if either 1)\r\n <DriveLetter> is not associated with a volume or 2) <DriveLetter> is\r\n associated with a volume not connected to an underlying disk\r\n partition.\r\n\r\n/force Forcibly dismounts the volume(s) during the boot code update. You\r\n should use this option with caution.\r\n\r\n If Bootsect.exe cannot gain exclusive volume access then the file\r\n system may overwrite the boot code before the next reboot.\r\n Bootsect.exe always attempts to lock and dismount the volume before\r\n each update. When /force is specified, a forced dismount is attempted\r\n if the initial lock attempt fails. A lock can fail, for example, if\r\n files on the target volume are currently opened by other programs.\r\n\r\n When successful, a forced dismount allows exclusive volume access and\r\n a reliable boot code update even though the initial lock failed. At\r\n the same time, a forced dismount invalidates all open handles to files\r\n on the target volume. This could result in unexpected behavior from\r\n the programs that opened these files. Therefore, you should use this\r\n option with caution.\r\n\r\n/mbr Updates the Master Boot Record without changing the partition table on\r\n sector 0 of the disk that contains the partition specified by SYS, ALL,\r\n or drive letter. When used with /nt52 option, the master boot record\r\n is compatible with operating systems older than Windows Vista. When\r\n used with the /nt60 option, the master boot record is compatible with\r\n Windows Vista, Windows Server 2008 or later.\r\n\r\nExample:\r\n\r\nTo apply the master boot code that is compatible with NTLDR to the volume\r\nlabeled E:, use the following command:\r\n\r\nbootsect /nt52 E:\r\n", "runtime_modules": [ "C:\\Windows\\system32\\bootsect.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "bridgeunattend.exe-AA9147FAAEE0724C637931246F0E52F9": { "file_name": "bridgeunattend.exe", "file_path": "C:\\Windows\\system32\\bridgeunattend.exe", "hash_md5": "AA9147FAAEE0724C637931246F0E52F9", "hash_sha1": "BAE8A9B25262D11202C0D1F955149027246CFA73", "hash_sha256": "0DAB54A90BF52EB64F8EB50D94298F2C55D04682369C93107315AD91A3C6D642", "hash_sha384": "8158C30A754CF5602EDD43FA47BF19A0F6839EEC4A5DB208F118BCCB12B4850669027213754B8664864C11D5FF5C6BE3", "hash_sha512": "2AD39D894246C73A25D2CF0EB914560A6AC9FBB1A467E5C6D3DA0E1DBD37B63E2588100F94E717434B4A4C34464A7F3C305E216331A543DD81280276C62A2F48", "hash_ssdeep": "384:fhDPLVoZt21ZaGYYZHHO6nOO+gkX7E8o5OO5AIHvi3WjfW:At8JOiOv65tHaA", "hash_imp": "43414F81FC52CAF520B560A4956A39CC", "hash_pesha1": "DE2EF940643BC966A2C1BF47A1E72E7FF9ED9788", "hash_pe256": "DB88F39B54F26F3FDEFDBEE90F8F129505790CFDF6E345A7517D2035BBDA4C29", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Bridge Unattend Utility", "meta_original_filename": "bridgeunattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/0dab54a90bf52eb64f8eb50d94298f2c55d04682369c93107315ad91a3c6d642/detection", "runtime_modules": [ "C:\\Windows\\system32\\bridgeunattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "browserexport.exe-8F62856617BFB752B7C4746D9A384659": { "file_name": "browserexport.exe", "file_path": "C:\\Windows\\system32\\browserexport.exe", "hash_md5": "8F62856617BFB752B7C4746D9A384659", "hash_sha1": "85F5814D9DB8F280C1732710D8BA9CA4B5A612D5", "hash_sha256": "983502C17475814CCCC6D8B41A87B62B28DED6DCE680A67DD6EE44B367E20A1A", "hash_sha384": "80C3979630489B6AA04350F9B4D10A67D038AFECCBA0D0A9BB0A0DBA38A1C0653B9FD0823DD9B8ABF71BB2DF0F982B91", "hash_sha512": "6B181A691939A4B9ED655D2E1C7B88B5E990BE83AD4CCA45811D1BCD8A6CCA612FB5B396ACAC96E1CB2B1127F3FEC1295B4CB250A0ABBBDD28E909B20CE3AAC6", "hash_ssdeep": "3072:A6sR5hdaQoi36UnM/EA1Pozcrx2SpDatdgKmUw1NbPbMssjpt4S2+GcykX:YR5hdPoi36EM/1xvpDatdvUbPbMsDcz", "hash_imp": "40AAF38944F0933C0EB6654302549F58", "hash_pesha1": "A9A82BD3D16D3A151F7376EF42F4FF0B3573C9ED", "hash_pe256": "1D55892F74E411F318E6FB4B99991CC66AA9C1F80DCACEC343025427BFABCA6F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Edge Browser Exporter", "meta_original_filename": "browserexport.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/983502c17475814cccc6d8b41a87b62b28ded6dce680a67dd6ee44b367e20a1a/detection", "runtime_modules": [ "C:\\Windows\\system32\\browserexport.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\WININET.dll", "C:\\Windows\\system32\\winsqlite3.dll", "C:\\Windows\\SYSTEM32\\windows.storage.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\msIso.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll" ] }, "browser_broker.exe-7CB13E73E3530F172E26CFE146EA20B0": { "file_name": "browser_broker.exe", "file_path": "C:\\Windows\\system32\\browser_broker.exe", "hash_md5": "7CB13E73E3530F172E26CFE146EA20B0", "hash_sha1": "98137E27BD1B0ED92B3ABF4C16EDFF9FEDA14C2C", "hash_sha256": "0698E50FC9E661A29476F737375753576D321EA6F15D19579F8FB8746DB59E50", "hash_sha384": "CC6EA7CAAE0C13AA545718AB9E714DC7BF1691D4AC95054043869DBD5441AC4079DC4A18A2A4972CD5097281895B5F66", "hash_sha512": "51C9112BDF6433532967022035190E19930A00E3F948C1C27FBBB6DEAAB01D006EA605E046939631B0FF398F6ADD2C9AE744D997420A71DC97ED2C5624CEC238", "hash_ssdeep": "768:5tXC6qdiPEI9kxIEBIiv219NWMqSaKmbwtiCmKI1Pnr3l:XOiPhaxX2OMqSRmbwcCmLPn5", "hash_imp": "0F55A2F5C27203431AB9FD8C11D1FE1E", "hash_pesha1": "0F3D477228F8D86274E965FC73CE5622688050D3", "hash_pe256": "DB395D38876E2B170570B33B4B79209C2802C400BE503278046187F21A30197B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Browser_Broker", "meta_original_filename": "browser_broker.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/0698e50fc9e661a29476f737375753576d321ea6f15d19579f8fb8746db59e50/detection", "runtime_modules": [ "C:\\Windows\\system32\\browser_broker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "bthudtask.exe-4DCD6FCABF20FBC8BFB11A9F6E4B77F0": { "file_name": "bthudtask.exe", "file_path": "C:\\Windows\\system32\\bthudtask.exe", "hash_md5": "4DCD6FCABF20FBC8BFB11A9F6E4B77F0", "hash_sha1": "233EAC2BED59B8FE167C1501AC3FDA48B32A1B0C", "hash_sha256": "CF5AE95C9FDAFE5F0CC9D7010412E84502FE66AD60F57DFDF68735B9315FF444", "hash_sha384": "A861FDC89E162AF7AA8ADA1DF84640316F5F2719DB26B1C092329E4A6F8147B969FBFFE3B0F1F433EF273A3462E6E124", "hash_sha512": "B4293A438BA9D41E446BFB1BCA3A4DF4AB009882B7DF2EDA61607CFEF77A397F6AE3C3532DC1ADDAA9553A0BC9F3E756D3AC377A69CF1AE537638F618E666EA3", "hash_ssdeep": "384:9xPCdanLUfz+Kr+fUOzDfINIDaqJkb9J3WWLHWpKJajXDO1/EagS817l:rjLUL+KAfosa59J7kzDO", "hash_imp": "9ABEB2B37A47478C60D77A46A439A38B", "hash_pesha1": "1E7DFC093D378E382CAC47BACEFE666F49F180C2", "hash_pe256": "314B2C477633AC026E09C025EFA91B77190959F2874939E8E67F1ED144886D44", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Bluetooth Uninstall Device Task", "meta_original_filename": "BthUdTask.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/cf5ae95c9fdafe5f0cc9d7010412e84502fe66ad60f57dfdf68735b9315ff444/detection", "runtime_modules": [ "C:\\Windows\\system32\\bthudtask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ByteCodeGenerator.exe-C791146EE46E8AC93DFAC7F6B91040EC": { "file_name": "ByteCodeGenerator.exe", "file_path": "C:\\Windows\\system32\\ByteCodeGenerator.exe", "hash_md5": "C791146EE46E8AC93DFAC7F6B91040EC", "hash_sha1": "D979A1ABFFD7329C03FA4F93D13883616989D8B7", "hash_sha256": "2A3445CCEBDE3CFF3D78F7FD8B02155CBCBABFA3EAFC7304BF99B6748F1969B0", "hash_sha384": "4CA9DA56CFB45C44AE813EE562C516DEA529EFFAF3534DB945217FFA05BF52F5E3A9C22B961F8B546794132B4CF2EE84", "hash_sha512": "E2D4FD42E674337B6A5CD5A65921AF000B236A697948BE1B7D854A84A0D728D8B1C7A39A16E948E0100862A66B43043F877BAE55A4A2D291196C6AEC2173C761", "hash_ssdeep": "1536:Ub36kzTz/7W3nErc2o09ie5e/LMPBdUU9JYNdWBFfkayZx:UF/7knEo2o09ieFDUU9SmkayL", "hash_imp": "5B44D7BB96AF203A37FE84D57E8F2254", "hash_pesha1": "6A9D1AD4B0669EB4089E6C422B3B4A86C046E871", "hash_pe256": "0673CA44DFFE711BCECA6C8A793E8DE4F6E389B7A15B864B3706E5E4A2C36CD9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AppX Deployment Bytecode Generator EXE", "meta_original_filename": "BytecodeGenerator.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2a3445ccebde3cff3d78f7fd8b02155cbcbabfa3eafc7304bf99b6748f1969b0/detection", "runtime_modules": [ "C:\\Windows\\system32\\ByteCodeGenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "cacls.exe-A353590E06C976809F14906746109758": { "file_name": "cacls.exe", "file_path": "C:\\Windows\\system32\\cacls.exe", "hash_md5": "A353590E06C976809F14906746109758", "hash_sha1": "3E38480E52434F1E193D9C84B8BDC133C4BD10C2", "hash_sha256": "D6E40B4ED7C0BC8AC18B15D265ED2EDAB9EFC260332EF0A98623F943BE3A43FA", "hash_sha384": "75A1879BF22E076C12BC6EDB4EBF40604B78EC6C8D347CD1DE957B327187E61D9943BC18C2D9E36CA6D938D387DA3A5C", "hash_sha512": "54A884652032040ACDA5C3A78D258BBE50362F77F2A3A364A8819CF8263282FCB21E35D7293EB62202EA82E96B5994FD072356D310DF3037BEC6A61C221796A6", "hash_ssdeep": "768:gOkLr2hyZByocltC8L90CoWbR+B9/d9gWh4i/6rWaDbGXlF:gBLr2hOkzL90CoK+BRd95hmDbGXlF", "hash_imp": "30254A514CD61AB9D483307AA5A195E8", "hash_pesha1": "FE772B355E1733B1F8E1954C44BDBCC10DAC6621", "hash_pe256": "A6EC74EDD825EC6EE28F6A74A8CBFCA102A994AABF560EA2F4D578E04A251641", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Control ACLs Program", "meta_original_filename": "CACLS.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d6e40b4ed7c0bc8ac18b15d265ed2edab9efc260332ef0a98623f943be3a43fa/detection", "output": "\r\r\n NOTE: Cacls is now deprecated, please use Icacls.\r\r\n\r\r\n Displays or modifies access control lists (ACLs) of files\r\r\n\r\r\n CACLS filename [/T] [/M] [/L] [/S[:SDDL]] [/E] [/C] [/G user:perm]\r\r\n [/R user [...]] [/P user:perm [...]] [/D user [...]]\r\r\n filename Displays ACLs.\r\r\n /T Changes ACLs of specified files in\r\r\n the current directory and all subdirectories.\r\r\n /L Work on the Symbolic Link itself versus the target\r\r\n /M Changes ACLs of volumes mounted to a directory\r\r\n /S Displays the SDDL string for the DACL.\r\r\n /S:SDDL Replaces the ACLs with those specified in the SDDL string\r\r\n (not valid with /E, /G, /R, /P, or /D).\r\r\n /E Edit ACL instead of replacing it.\r\r\n /C Continue on access denied errors.\r\r\n /G user:perm Grant specified user access rights.\r\r\n Perm can be: R Read\r\r\n W Write\r\r\n C Change (write)\r\r\n F Full control\r\r\n /R user Revoke specified user's access rights (only valid with /E).\r\r\n /P user:perm Replace specified user's access rights.\r\r\n Perm can be: N None\r\r\n R Read\r\r\n W Write\r\r\n C Change (write)\r\r\n F Full control\r\r\n /D user Deny specified user access.\r\r\n Wildcards can be used to specify more than one file in a command.\r\r\n You can specify more than one user in a command.\r\r\n\r\r\n Abbreviations:\r\r\n CI - Container Inherit.\r\r\n The ACE will be inherited by directories.\r\r\n OI - Object Inherit.\r\r\n The ACE will be inherited by files.\r\r\n IO - Inherit Only.\r\r\n The ACE does not apply to the current file/directory.\r\r\n ID - Inherited.\r\r\n The ACE was inherited from the parent directory's ACL.\r\r\n", "error": "The system cannot find the file specified.\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\cacls.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "calc.exe-5DA8C98136D98DFEC4716EDD79C7145F": { "file_name": "calc.exe", "file_path": "C:\\Windows\\system32\\calc.exe", "hash_md5": "5DA8C98136D98DFEC4716EDD79C7145F", "hash_sha1": "ED13AF4A0A754B8DAEE4929134D2FF15EBE053CD", "hash_sha256": "58189CBD4E6DC0C7D8E66B6A6F75652FC9F4AFC7CE0EBA7D67D8C3FEB0D5381F", "hash_sha384": "871A9643E947BEF44AA5E52E828F7245EE427CE14133778048F769FDD04F75119EE5453A90EC581A29B6A0722477B4E2", "hash_sha512": "6E2B067760EC178CDCC4DF04C541CE6940FC2A0CDD36F57F4D6332E38119DBC5E24EB67C11D2C8C8FFEED43533C2DD8B642D2C7C997C392928091B5CCCE7582A", "hash_ssdeep": "384:Otj8FKzuRxmeWCJxhd2WS/YWyiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiLiiiB:QXif4CbPQ7", "hash_imp": "8EEAA9499666119D13B3F44ECD77A729", "hash_pesha1": "68555FB55B4D974628D429EDA7F5E282D647B426", "hash_pe256": "6C669C3BB2E7F23798AFD237461979E232F08D0B834F8097EE2B84E6D8ED56A7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Calculator", "meta_original_filename": "CALC.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/58189cbd4e6dc0c7d8e66b6a6f75652fc9f4afc7ce0eba7d67d8c3feb0d5381f/detection", "runtime_modules": [ "C:\\Windows\\system32\\calc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "CameraSettingsUIHost.exe-614FF954708C6FB0376F210E76CC97D5": { "file_name": "CameraSettingsUIHost.exe", "file_path": "C:\\Windows\\system32\\CameraSettingsUIHost.exe", "hash_md5": "614FF954708C6FB0376F210E76CC97D5", "hash_sha1": "39862526EE428058CEE1740C46564A7B32304E58", "hash_sha256": "81376383CB5285501006766DF674500B19E27D736BC627C6078BC41E0D6FF9B5", "hash_sha384": "25D003042FF0280AD48C5D153A3BD2FCEDECD24C47C356B02DB0422E5B612F536655A06CA4D6CB7A4297A69BCC0BEA2D", "hash_sha512": "F28686EBE650C8D65B9B1C6473339A6E485526F1752EFE6944CEE160968B97645E1FB4DDAC14CD80908293B77EC700D7E54964B4B10A2A9FA0BD318665380704", "hash_ssdeep": "768:v4dTniroyUNLn4gXuGpcTHOLFYE7I1Pz0LL:2Ti7e4VQLFYEMP4LL", "hash_imp": "CC9B41F8A3BF3F245934B3D3A32E9E74", "hash_pesha1": "F78CCB179685715FD8FDF8B9747C275ABA5996A6", "hash_pe256": "66FBD92EED24AB24A069A612A8CB3C861CBF166484FC43BEE2B8E9A26B52F4AE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Camera Settings UI Host", "meta_original_filename": "CameraSettingsUIHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/81376383cb5285501006766df674500b19e27d736bc627c6078bc41e0d6ff9b5/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\CameraSettingsUIHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\system32\\DUI70.dll" ] }, "CastSrv.exe-015AD1456E4D952C6C115511FEA0D4D8": { "file_name": "CastSrv.exe", "file_path": "C:\\Windows\\system32\\CastSrv.exe", "hash_md5": "015AD1456E4D952C6C115511FEA0D4D8", "hash_sha1": "03E400366041BACBC101A1B3DFBE8834931FE298", "hash_sha256": "A0DC0EFF268756B16541DD36AB8ACAF3979A240C474D9CD19CCBA1ECFD263998", "hash_sha384": "0C015EE2EEF805B0646B759F2423565AE10D0792AD09EFB81AB526DEEF0F3F4FAC91F05241C950D3568570918D72CED2", "hash_sha512": "49141D4B466765FAC7F5B2645762F5DEE37E94EEF6771523EF3034B638E2D476E24AAFB3B7D6EC0F2D0CF1D0A6AE23BB8E82C2BFE87167047E86F2935EA12CA3", "hash_ssdeep": "768:+1s/AeBg/HSiP8a94IdfQ7MaNwTBjXQlOTLsAGRjTNBJlwCOI1PV:+03G5E/YxQMcnJBJlwIP", "hash_imp": "9903CD922A38DEE760918B0D80CEB7B0", "hash_pesha1": "1D8B97E0CE8F2F12051DAB1803F655BC0BF1D582", "hash_pe256": "917AA7A9D138ACACC46F445966D3EB35EA0E8E978CF6B372397B5C51E43A1A88", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Casting protocol connection listener", "meta_original_filename": "CastSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a0dc0eff268756b16541dd36ab8acaf3979a240c474d9cd19ccba1ecfd263998/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\CastSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "CertEnrollCtrl.exe-A5258406C3C926A651A0A9DB93B4E8E3": { "file_name": "CertEnrollCtrl.exe", "file_path": "C:\\Windows\\system32\\CertEnrollCtrl.exe", "hash_md5": "A5258406C3C926A651A0A9DB93B4E8E3", "hash_sha1": "3E5A407DFA4ED557D4E88830504B00A8A3EE0020", "hash_sha256": "C180F87DD7F7BD58AD85BE08B0C59F95FA4A5D3EC748931FF4A89D1AFCFE8449", "hash_sha384": "1E92C9D7AC14E6337F3942F2D58ACA9CE163594E6054AE713D2DAD7BA42F2C17D4BBC9D99B0E252A7388011CC469E140", "hash_sha512": "880B50786528D503348FE156124FFCC0F7922428EA2A1C4BB543CBBFB1FDA2672A434C40AB8F7F8ABBA24A52B40BA97ACD84119A9D8876267837FAAE1F3DBF71", "hash_ssdeep": "1536:WM1+cvmDLbfr4xgEGhxuOSaNx6Y4Vrr+BvHuiHgZCCys:23QgEGhVxav+BWnjys", "hash_imp": "90691EED0033FC894F22AFCD8DC3AA79", "hash_pesha1": "C6C1B27DD97AE5CF001A0C545D705C14BEB976FD", "hash_pe256": "11F44846E4E07161ED1423538BFF3EDE991362E99E7320812718C28822BB8F18", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Certificate Enrollment Control", "meta_original_filename": "EnrollComServer.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c180f87dd7f7bd58ad85be08b0c59f95fa4a5d3ec748931ff4a89d1afcfe8449/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\CertEnrollCtrl.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\CertEnrollCtrl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\certenroll.dll", "C:\\Windows\\system32\\certca.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\system32\\DSPARSE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\DPAPI.DLL", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "certreq.exe-9649D64AD61B3BD3696BB82721242088": { "file_name": "certreq.exe", "file_path": "C:\\Windows\\system32\\certreq.exe", "hash_md5": "9649D64AD61B3BD3696BB82721242088", "hash_sha1": "5EF73B793B262E3F6E824F56620363129C2C7923", "hash_sha256": "AC46A263AC5A21F55FF092D43FB865EDBBAB6AF8BCBE1372AE004FD0B12A8E46", "hash_sha384": "AD9C316B678C0A557C7BBA7BF7530D856C3207D9642E200CDCC21B17C734F3326E7DB1631FA11957DA0A6E8B77EE8065", "hash_sha512": "07001E5080C0F35C508E31F6781A81A8F2DED92A32C7B7B72EF777A921737EB1BFC98679E995BBEAA503A41FB826FBC68DD41F285A634FA8078B91C3E5A657B8", "hash_ssdeep": "6144:w0CPCy08ZMcEvpjujaIKk76o4HnxUHQygQakKwHvVHLu5fRpNjy3NoYb1X9tE:w0MspjLpk+NHCTnKyldrK", "hash_imp": "E4057C8BDE1B79AA1724B455F9E7C2BB", "hash_pesha1": "034362EABB5290613FF8376A1C4B4B398C71CB55", "hash_pe256": "A2C2D19BC07C904C4BA1570D4FDDB1E24463B6776B42186BF4D8794828E755C1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CertReq.exe", "meta_original_filename": "CertReq.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ac46a263ac5a21f55ff092d43fb865edbbab6af8bcbe1372ae004fd0b12a8e46/detection", "children": "conhost.exe", "output": "Usage:\r\r\n CertReq -?\r\r\n CertReq [-v] -?\r\r\n CertReq [-Command] -?\r\r\n\r\n CertReq [-Submit] [Options] [RequestFileIn [CertFileOut [CertChainFileOut [FullResponseFileOut]]]]\r\r\n Submit a request to a Certification Authority.\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -binary\r\r\n -PolicyServer PolicyServer\r\r\n -config ConfigString\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -crl\r\r\n -rpc\r\r\n -AdminForceMachine\r\r\n -RenewOnBehalfOf\r\r\n -NoChallenge\r\r\n\r\n CertReq -Retrieve [Options] RequestId [CertFileOut [CertChainFileOut [FullResponseFileOut]]]\r\r\n Retrieve a response to a previous request from a Certification Authority.\r\r\n\r\n Options:\r\r\n -binary\r\r\n -PolicyServer PolicyServer\r\r\n -config ConfigString\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -crl\r\r\n -rpc\r\r\n -AdminForceMachine\r\r\n\r\n CertReq -New [Options] [PolicyFileIn [RequestFileOut]]\r\r\n Create a new request as directed by PolicyFileIn\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -binary\r\r\n -cert CertId\r\r\n -PolicyServer PolicyServer\r\r\n -config ConfigString\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -pin Pin\r\r\n -user\r\r\n -machine\r\r\n -xchg ExchangeCertFile\r\r\n\r\n CertReq -Accept [Options] [CertChainFileIn | FullResponseFileIn | CertFileIn]\r\r\n Accept and install a response to a previous new request.\r\r\n\r\n Options:\r\r\n -user \r\r\n -machine \r\r\n -pin Pin\r\r\n\r\n CertReq -Policy [Options] [RequestFileIn [PolicyFileIn [RequestFileOut [PKCS10FileOut]]]]\r\r\n Construct a cross certification or qualified subordination request\r\r\n from an existing CA certificate or from an existing request.\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -binary\r\r\n -cert CertId\r\r\n -PolicyServer PolicyServer\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -pin Pin\r\r\n -noEKU\r\r\n -AlternateSignatureAlgorithm\r\r\n -HashAlgorithm HashAlgorithm\r\r\n\r\n CertReq -Sign [Options] [RequestFileIn [RequestFileOut]]\r\r\n Sign a certificate request with an enrollment agent or qualified\r\r\n subordination signing certificate.\r\r\n\r\n Options:\r\r\n -binary\r\r\n -cert CertId\r\r\n -PolicyServer PolicyServer\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -pin Pin\r\r\n -crl\r\r\n -noEKU\r\r\n -HashAlgorithm HashAlgorithm\r\r\n\r\n CertReq -Enroll [Options] TemplateName\r\r\n CertReq -Enroll -cert CertId [Options] Renew [ReuseKeys]\r\r\n Enroll for or renew a certificate.\r\r\n\r\n Options:\r\r\n -PolicyServer PolicyServer\r\r\n -user \r\r\n -machine \r\r\n -pin Pin\r\r\n\r\n CertReq -EnrollAIK [Options] [KeyContainerName]\r\r\n Enroll for AIK certificate.\r\r\n\r\n Options:\r\r\n -config\r\r\n\r\n CertReq -EnrollCredGuardCert [Options] TemplateName [ExtensionInfFile]\r\r\n Enroll for machine account Credential Guard certificate.\r\r\n\r\n Options:\r\r\n -config\r\r\n\r\n CertReq -EnrollLogon [Options]\r\r\n Enroll for Hello for Business Logon certificate via ADFS.\r\r\n\r\n Options:\r\r\n -q\r\r\n\r\n CertReq -Post [Options]\r\r\n POST an http request.\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -config URL\r\r\n\r\nUnknown argument: --help\r\n", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\certreq.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\certreq.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "runtime_window_title": "Certificate Request Processor" }, "certutil.exe-BD8D9943A9B1DEF98EB83E0FA48796C2": { "file_name": "certutil.exe", "file_path": "C:\\Windows\\system32\\certutil.exe", "hash_md5": "BD8D9943A9B1DEF98EB83E0FA48796C2", "hash_sha1": "70E89852F023AB7CDE0173EDA1208DBB580F1E4F", "hash_sha256": "8DE7B4EB1301D6CBE4EA2C8D13B83280453EB64E3B3C80756BBD1560D65CA4D2", "hash_sha384": "5028F527AC152266E655F8027D3C888659EC4641E26550FBFA77A39BC13528FCF7CB8ED963C9EA77092A8CF11E4E43DC", "hash_sha512": "95630FDDDAD5DB60CC97EC76EE1CA02DBB00EE3DE7D6957ECDA8968570E067AB2A9DF1CC07A3CE61161A994ACBE8417C83661320B54D04609818009A82552F7B", "hash_ssdeep": "24576:aCaND6ankkViMCsJf0JhY+3hvwUJDP+t3HvDGKK1V3FuNM2GRUY/ejsSvVo2:aCiDLnPipbJ5vwES3CKGVVuNM20UXa2", "hash_imp": "7B7F7ED372C027216AE5100589C424EA", "hash_pesha1": "10D312BD6E1670DD935BDBA351E828CE96F73BD4", "hash_pe256": "0E84C340A1C065641A19DD794F773BD60CC8223E285068AEF19C204804469FDD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CertUtil.exe", "meta_original_filename": "CertUtil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8de7b4eb1301d6cbe4ea2c8d13b83280453eb64e3b3c80756bbd1560d65ca4d2/detection", "output": "\r\nVerbs:\r\n -dump -- Dump configuration information or file\r\n -dumpPFX -- Dump PFX structure\r\n -asn -- Parse ASN.1 file\r\n\r\n -decodehex -- Decode hexadecimal-encoded file\r\n -decode -- Decode Base64-encoded file\r\n -encode -- Encode file to Base64\r\n\r\n -deny -- Deny pending request\r\n -resubmit -- Resubmit pending request\r\n -setattributes -- Set attributes for pending request\r\n -setextension -- Set extension for pending request\r\n -revoke -- Revoke Certificate\r\n -isvalid -- Display current certificate disposition\r\n\r\n -getconfig -- Get default configuration string\r\n -ping -- Ping Active Directory Certificate Services Request interface\r\n -pingadmin -- Ping Active Directory Certificate Services Admin interface\r\n -CAInfo -- Display CA Information\r\n -ca.cert -- Retrieve the CA's certificate\r\n -ca.chain -- Retrieve the CA's certificate chain\r\n -GetCRL -- Get CRL\r\n -CRL -- Publish new CRLs [or delta CRLs only]\r\n -shutdown -- Shutdown Active Directory Certificate Services\r\n\r\n -installCert -- Install Certification Authority certificate\r\n -renewCert -- Renew Certification Authority certificate\r\n\r\n -schema -- Dump Certificate Schema\r\n -view -- Dump Certificate View\r\n -db -- Dump Raw Database\r\n -deleterow -- Delete server database row\r\n\r\n -backup -- Backup Active Directory Certificate Services\r\n -backupDB -- Backup Active Directory Certificate Services database\r\n -backupKey -- Backup Active Directory Certificate Services certificate and private key\r\n -restore -- Restore Active Directory Certificate Services\r\n -restoreDB -- Restore Active Directory Certificate Services database\r\n -restoreKey -- Restore Active Directory Certificate Services certificate and private key\r\n -importPFX -- Import certificate and private key\r\n -dynamicfilelist -- Display dynamic file List\r\n -databaselocations -- Display database locations\r\n -hashfile -- Generate and display cryptographic hash over a file\r\n\r\n -store -- Dump certificate store\r\n -enumstore -- Enumerate certificate stores\r\n -addstore -- Add certificate to store\r\n -delstore -- Delete certificate from store\r\n -verifystore -- Verify certificate in store\r\n -repairstore -- Repair key association or update certificate properties or key security descriptor\r\n -viewstore -- Dump certificate store\r\n -viewdelstore -- Delete certificate from store\r\n -UI -- invoke CryptUI\r\n -attest -- Verify Key Attestation Request\r\n\r\n -dsPublish -- Publish certificate or CRL to Active Directory\r\n\r\n -ADTemplate -- Display AD templates\r\n -Template -- Display Enrollment Policy templates\r\n -TemplateCAs -- Display CAs for template\r\n -CATemplates -- Display templates for CA\r\n -SetCASites -- Manage Site Names for CAs\r\n -enrollmentServerURL -- Display, add or delete enrollment server URLs associated with a CA\r\n -ADCA -- Display AD CAs\r\n -CA -- Display Enrollment Policy CAs\r\n -Policy -- Display Enrollment Policy\r\n -PolicyCache -- Display or delete Enrollment Policy Cache entries\r\n -CredStore -- Display, add or delete Credential Store entries\r\n -InstallDefaultTemplates -- Install default certificate templates\r\n -URLCache -- Display or delete URL cache entries\r\n -pulse -- Pulse autoenrollment event or NGC task\r\n -MachineInfo -- Display Active Directory machine object information\r\n -DCInfo -- Display domain controller information\r\n -EntInfo -- Display enterprise information\r\n -TCAInfo -- Display CA information\r\n -SCInfo -- Display smart card information\r\n\r\n -SCRoots -- Manage smart card root certificates\r\n\r\n -DeleteHelloContainer -- Delete Hello Logon container. \r\n ** Users need to sign out after using this option for it to complete. **\r\n -verifykeys -- Verify public/private key set\r\n -verify -- Verify certificate, CRL or chain\r\n -verifyCTL -- Verify AuthRoot or Disallowed Certificates CTL\r\n -syncWithWU -- Sync with Windows Update\r\n -generateSSTFromWU -- Generate SST from Windows Update\r\n -generatePinRulesCTL -- Generate Pin Rules CTL\r\n -downloadOcsp -- Download OCSP Responses and Write to Directory\r\n -generateHpkpHeader -- Generate HPKP header using certificates in specified file or directory\r\n -flushCache -- Flush specified caches in selected process, such as, lsass.exe\r\n -addEccCurve -- Add ECC Curve\r\n -deleteEccCurve -- Delete ECC Curve\r\n -displayEccCurve -- Display ECC Curve\r\n -sign -- Re-sign CRL or certificate\r\n\r\n -vroot -- Create/delete web virtual roots and file shares\r\n -vocsproot -- Create/delete web virtual roots for OCSP web proxy\r\n -addEnrollmentServer -- Add an Enrollment Server application\r\n -deleteEnrollmentServer -- Delete an Enrollment Server application\r\n -addPolicyServer -- Add a Policy Server application\r\n -deletePolicyServer -- Delete a Policy Server application\r\n -oid -- Display ObjectId or set display name\r\n -error -- Display error code message text\r\n -getreg -- Display registry value\r\n -setreg -- Set registry value\r\n -delreg -- Delete registry value\r\n\r\n -ImportKMS -- Import user keys and certificates into server database for key archival\r\n -ImportCert -- Import a certificate file into the database\r\n -GetKey -- Retrieve archived private key recovery blob, generate a recovery script,\r\n or recover archived keys\r\n -RecoverKey -- Recover archived private key\r\n -MergePFX -- Merge PFX files\r\n -ConvertEPF -- Convert PFX files to EPF file\r\n\r\n -add-chain -- (-AddChain) Add certificate chain\r\n -add-pre-chain -- (-AddPrechain) Add pre-certificate chain\r\n -get-sth -- (-GetSTH) Get signed tree head\r\n -get-sth-consistency -- (-GetSTHConsistency) Get signed tree head changes\r\n -get-proof-by-hash -- (-GetProofByHash) Get proof by hash\r\n -get-entries -- (-GetEntries) Get entries\r\n -get-roots -- (-GetRoots) Get roots\r\n -get-entry-and-proof -- (-GetEntryAndProof) Get entry and proof\r\n -VerifyCT -- Verify certificate SCT\r\n -? -- Display this usage message\r\n\r\n\r\nCertUtil -? -- Display a verb list (command list)\r\nCertUtil -dump -? -- Display help text for the \"dump\" verb\r\nCertUtil -v -? -- Display all help text for all verbs\r\n\r\nCertUtil: -? command completed successfully.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\certutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "CExecSvc.exe-B574BC02064F4000A127F208722CD2BE": { "file_name": "CExecSvc.exe", "file_path": "C:\\Windows\\system32\\CExecSvc.exe", "hash_md5": "B574BC02064F4000A127F208722CD2BE", "hash_sha1": "46C1D63EA0EFBBFA6F33EAF20E8684469C79E0A4", "hash_sha256": "666992BC336C0BDA92A7731C77F04B28E7EB22C72421676F32AA13B443372FC3", "hash_sha384": "0E9139B8103D050DB90875810E690EE34A4DD6F3C8F5AD3EF5F88E66D810FDF1D05B3FCD2CD004B178D9A24E561E7E79", "hash_sha512": "095BAAD2126D2EE8011728185E4498D95E370E8C0DC7CA67629ACBBDCEE2CC240E02F6F001CCB8C164095EAD2366AF826F665E4AC31AE3FDE922129EAC25CAC7", "hash_ssdeep": "3072:Hv/1bjf9G6QqSPVjK8Bxibhx64oaW5iMhNYg9R8R+sU5sr30RZaG:HH1/86rSvDs0laW5hXz8R+5D", "hash_imp": "E76E5D60866630BC836B4F20FAD51C5C", "hash_pesha1": "C4B25B858484EFF7497A0EC01A1D5963A711B904", "hash_pe256": "861CEE15860E6FA526F09FF1536094A149E9701A5E751F7D18F4B048DACFC7CF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Container Execution Agent", "meta_original_filename": "CExecSvc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/666992bc336c0bda92a7731c77f04b28e7eb22c72421676f32aa13b443372fc3/detection", "runtime_modules": [ "C:\\Windows\\system32\\CExecSvc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "change.exe-B5A2475E90B9970F16C50D392B9A16BB": { "file_name": "change.exe", "file_path": "C:\\Windows\\system32\\change.exe", "hash_md5": "B5A2475E90B9970F16C50D392B9A16BB", "hash_sha1": "0FC5EAAFBB93C2D1816F0FED0E1D5B2A3AE57373", "hash_sha256": "D2DF044B73E57CB2FFAB4BEAE33355301B124B7CA45861C683B97D376019D717", "hash_sha384": "9D521667F05AA8D2E975441A3B1FA7E0560A0F2C82116D68A58EE38433D69AD0DB43C2C709C347EF3994562E7C8D7324", "hash_sha512": "C2AFC2FF49A578C67921290D598BFF0E5AA0149731B4732D6ECDB3A44E71C3AA20C734E6E63E4ECAEB668F49C168BB1CF2A72D6F711332457B05B7D1FC65B9BE", "hash_ssdeep": "192:/YOS4SwveEAMuDzEAk3ZsThGdgo8jJIbO4kvByIhwxxth2GcDK71gmfWOLW:/YOQ1M/Kg7y2bzGlOxth20hFfWOLW", "hash_imp": "CCC9DA4A55E90DFE34CBCDB066D6A6B3", "hash_pesha1": "2FDB2069AD91D71D2C54D9F31D0727A0C67BB3CC", "hash_pe256": "B016F29FDB4D388B233A121EB106BEBD6F1BAAD823727F4F3E7CFB578E25F619", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Services Change Utility", "meta_original_filename": "change.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d2df044b73e57cb2ffab4beae33355301b124b7ca45861c683b97d376019d717/detection", "output": "CHANGE { LOGON | PORT | USER }\r\n", "error": "Invalid parameter(s)\r\nCHANGE { LOGON | PORT | USER }\r\n", "runtime_modules": [ "C:\\Windows\\system32\\change.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "changepk.exe-E1CF89FC48F0C246C7FFDAC3727CFFCB": { "file_name": "changepk.exe", "file_path": "C:\\Windows\\system32\\changepk.exe", "hash_md5": "E1CF89FC48F0C246C7FFDAC3727CFFCB", "hash_sha1": "15C30A19D1661E5DECF643BE09FFA358EC83A6CA", "hash_sha256": "69644AB12ECC3A89BC2DB5DC8198A506647D14F5B44745BCED02EAFAC362E8CF", "hash_sha384": "54AA3E9793223853216E400F1126FA25EAD5ECA9B2EE11B269AD6CC64B302BBB1C026C918CE75EF430F6DEDDB12732E5", "hash_sha512": "F904C301C09937C8C7F246CFFB3CB2792C61D3679B3EE60D8CD6B3D9D46EB0488692803E7DD3ABAA113C1C808539F7491069249FDDF1ACCE850A6E4FED771B01", "hash_ssdeep": "1536:17F+2BGymzag4U8AIvd1scT05vzj07j5UfE9AIP:ejyzg4U3Ivd1sU0lK5UfEqI", "hash_imp": "E3EFA1B5D57BA8D5B087542C1D3F58F7", "hash_pesha1": "2519A33EAE53413E71D91AB7A893FA89E9A6087A", "hash_pe256": "1CE9E6C4811EF1160C4C0DFED1F7619DF0B21D054A0DFDD245B2994B56703726", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Activation", "meta_original_filename": "changepk.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/69644ab12ecc3a89bc2db5dc8198a506647d14f5b44745bced02eafac362e8cf/detection", "runtime_modules": [ "C:\\Windows\\system32\\changepk.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "charmap.exe-56007E9A525980A3F904798CF2A65DF6": { "file_name": "charmap.exe", "file_path": "C:\\Windows\\system32\\charmap.exe", "hash_md5": "56007E9A525980A3F904798CF2A65DF6", "hash_sha1": "23EDCAC222205D0FFB221F85A814B6A88DE5CEDF", "hash_sha256": "FBEABC298ECDEA381161A1DA6881923B29FD7B1861A7B1779CE8011E401F8F81", "hash_sha384": "48A9713E1929ACDF5AF8E286CFFBC56A9C9069940D6290F5890AFBD0F8F6619D16959759EDC8550DE674DA9D304523E0", "hash_sha512": "86B29B83591019EF68F1D2825F09AA2EA604396C226F5D2A5443162219663EC10B498FFD8691FC7B7B91FB657453BA61B5EE6DA1985D33AEDFFD6FC8C290B5A4", "hash_ssdeep": "3072:hJ+GTwdjp/8x3biW6TABtJXSHDClbNvHttEEjfGbrLF5NUdrSO9K/tagbdDu5nB:h9wAxuW6TABtJ3dKbgqt5g", "hash_imp": "191F093436BAEDDF9464CCBEDFB49DA3", "hash_pesha1": "C7B73E41A73C9940F710032B939C1052E96066AE", "hash_pe256": "C2961BCFAA93FAC74079BABC5C07C96F27D7081944AD1121015C8051533AAE17", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Character Map", "meta_original_filename": "charmap.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/fbeabc298ecdea381161a1da6881923b29fd7b1861a7b1779ce8011e401f8f81/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\charmap.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme601709542": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Sessions\\1\\BaseNamedObjects\\1738HWNDInterface:704e4": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\getuname.dll.mui": "File", "(R--) C:\\Windows\\System32\\bopomofo.uce": "File", "(R--) C:\\Windows\\System32\\gb2312.uce": "File", "(R--) C:\\Windows\\System32\\ideograf.uce": "File", "(R--) C:\\Windows\\System32\\kanji_1.uce": "File", "(R--) C:\\Windows\\System32\\kanji_2.uce": "File", "(R--) C:\\Windows\\System32\\korean.uce": "File", "(R--) C:\\Windows\\System32\\ShiftJIS.uce": "File", "(R--) C:\\Windows\\System32\\SubRange.uce": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\charmap.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\GetUName.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll" ], "runtime_window_title": "Character Map" }, "CheckNetIsolation.exe-67564F60C9A857B065B8494817624A2C": { "file_name": "CheckNetIsolation.exe", "file_path": "C:\\Windows\\system32\\CheckNetIsolation.exe", "hash_md5": "67564F60C9A857B065B8494817624A2C", "hash_sha1": "9E1BAF758584F62F18FF45D4BCF01BB170B292B9", "hash_sha256": "9CB971F87C46B7F96B83CF601C49AF9629D0B688A6A8B5C68192AA96ADEF6C45", "hash_sha384": "589A4B35A072108A6382E40DF37DDAE36B002329666AFAE37EBD058F9DC3B6CF4FD6700412A5D8D8CF6FA97FA787E580", "hash_sha512": "31A23222951C590059D09FC5E7F83A5A37CF0B42F89794102B675BB3899DDD8FC423680967C9A1E211482B5D5F1FC7B841AA994366E0D5DAE327A0682FFA2117", "hash_ssdeep": "768:ClwlBleXgP6qbheMK2x0OKafaFnctky7pt:CalPeXgrh1x0OFfaqtky7p", "hash_imp": "E437A3A0162600CE23B282A0DFA53D7B", "hash_pesha1": "5E3759CA1391989EF4403839A1EC26398AC0B4DC", "hash_pe256": "7131C89F49F64968A9B70E82C9A6568AC86322B9AEE51C1A7929B791F806618D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AppContainer Network Isolation Diagnostic Tool", "meta_original_filename": "CheckNetIsolation.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9cb971f87c46b7f96b83cf601c49af9629d0b688a6a8b5c68192aa96adef6c45/detection", "output": "Error: Invalid Parameters\r\n\r\nUsage:\r\n CheckNetIsolation [Module]\r\n List Of Modules: \r\n LoopbackExempt - controls the loopback exemption of AppContainers\r\n and Package Families to ease application\r\n development.\r\n Debug - Starts a network traffic troubleshooting session\r\n of an AppContainer or Package Family. Generates a\r\n report of network capabilities that are used, not\r\n used or missing, together with the network traffic\r\n generated by the application.\r\n -? - Displays this help message.\r\n \r\n", "runtime_modules": [ "C:\\Windows\\system32\\CheckNetIsolation.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "chglogon.exe-96C637283D92573C121B34513C267987": { "file_name": "chglogon.exe", "file_path": "C:\\Windows\\system32\\chglogon.exe", "hash_md5": "96C637283D92573C121B34513C267987", "hash_sha1": "1556FDC9EE7E3F8C8729932E0D5E660DFD69CC53", "hash_sha256": "A9CC2B03783896C6596D8F4E4CC3DB555A9096264BC8253478D1F0F0FBB2B74B", "hash_sha384": "F4A07779DB4957DC86365F6165385B0056D5CA01099BC5BE32070DA905A00C4AFD3B5918E21AA4E5B07A9559071424BC", "hash_sha512": "A7AA96670C2B1A2CF8511C4BEF0F2742FA3E2BBE8B797D380652B8BC8D57182FC97FE1FB41B6DE3279FEBDFEC9AF280C7C9DF9641BE0685FFB90219CAF68DFF2", "hash_ssdeep": "384:aoE7WrAWCBk4MAQhI/CtoeT5nj1Z8YuB+rtNsN7uEGVEkGuRVHIhjkKWiEW:aoSPW2k4MAQhI/n2h1Z8Ye+tiuD/0km", "hash_imp": "39CDC867B4449192C880F526495B2B10", "hash_pesha1": "283D9110925B5F6064A65759EA0B5AF7BFFFE805", "hash_pe256": "FB40002BF1019B9BD699FDB1B60910A1E269E91251578360A1E523D135D4C51B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Logon Utility", "meta_original_filename": "chglogon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a9cc2b03783896c6596d8f4e4cc3db555a9096264bc8253478d1f0f0fbb2b74b/detection", "error": "Invalid parameter(s)\r\nEnable, disable, or drain session logins.\r\n\r\nCHANGE LOGON {/QUERY | /ENABLE | /DISABLE | /DRAIN | /DRAINUNTILRESTART}\r\n\r\n /QUERY Query current session login mode.\r\n /ENABLE Enable user login from sessions.\r\n /DISABLE Disable user login from sessions.\r\n /DRAIN Disable new user logons, but allow reconnections to existing sessions.\r\n /DRAINUNTILRESTART Disable new user logons until the server is restarted, but allow reconnections to existing sessions.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\chglogon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "chgport.exe-C00B03DE19767654C9D9F69FE825EDEB": { "file_name": "chgport.exe", "file_path": "C:\\Windows\\system32\\chgport.exe", "hash_md5": "C00B03DE19767654C9D9F69FE825EDEB", "hash_sha1": "FBD6B69654D9B75A6F828AD56BE8C28BDEF747CE", "hash_sha256": "E68AA9ECD4ECF58618EF794A9B493B5D070CCD5B435B7B850C95A3302C39FA59", "hash_sha384": "BF1819DA432B9B75FA3C59EFD0A475F87182761CF396EA48AC2C5CD3A67E66C3B4A6E911296C6E96B735BE3161FE52AD", "hash_sha512": "F64EAB534B02DDCCB8A6929ED5AE14630609FEB262D425BE72F9C1EDD05E26041FF9C02D2F5E92E3676111AEC9AFDD55F91BD86A607DC22D5D542E3534DCA716", "hash_ssdeep": "768:Yh6BjS7hWc2xg4mHdutBxBxjZ8eiOuRF:YUBj2hRUnxpinF", "hash_imp": "312892FBBDB240DC5E0852F245418146", "hash_pesha1": "563F229232B498267177264D19840B1C322D27A8", "hash_pe256": "A8F1802EE9E6C55205A228C807F10214947EC14CC9A5E1DE289AC1C5CE78AB0C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change port Utility", "meta_original_filename": "chgport.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e68aa9ecd4ecf58618ef794a9b493b5d070ccd5b435b7b850c95a3302c39fa59/detection", "error": "Invalid parameter(s)\r\nList or change COM port mappings for DOS application compatibility.\r\n\r\nCHANGE PORT [portx=porty | /D portx | /QUERY]\r\n\r\n portx=porty Map port x to port y.\r\n /D portx Delete mapping for port x.\r\n /QUERY Display current mapping ports.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\chgport.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "chgusr.exe-D686812456A76D1FD64334B1967E5051": { "file_name": "chgusr.exe", "file_path": "C:\\Windows\\system32\\chgusr.exe", "hash_md5": "D686812456A76D1FD64334B1967E5051", "hash_sha1": "4D3D670B1DF78A805A9601EC861F0B3B874F344C", "hash_sha256": "074B4A36E0CC697E4146EA3873BFD25EBB067F2A937930E4D8393340F84F0D32", "hash_sha384": "2AB5FCB6FA4CCEF294229A5C077F58EF8C1FBBAB27AF2497C326E0EDD8EFFCCE8CA65A83860E48BD15EB58E69B677587", "hash_sha512": "D53FB3510C1A0F5411D1F8EF04456672D547BFABE02063B114B516162CAF99A59C06C8B1EFD721E0B4BE0E924038845FA55F28260C254AC67682CE97A5F3296F", "hash_ssdeep": "384:cGcZkm+OYbUHJjtm3tJT52DZZ8sSv6u2i89xP95ElC1H0aAKWDVW:cGcZkbJUHJjtmvkZZ8DfanPk/", "hash_imp": "EA17270B67FAE16B05714FD14BE68EA3", "hash_pesha1": "EF6EAB602B0D4D930148026180156F37BCC03E8D", "hash_pe256": "E393174C4D5921D8C641985689C2DD361E959792AB0585FB35040FEE37A7D517", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change INI File Mapping Utility", "meta_original_filename": "chgusr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/074b4a36e0cc697e4146ea3873bfd25ebb067f2a937930e4d8393340f84f0d32/detection", "output": "Change Install Mode.\r\n\r\nCHANGE USER {/EXECUTE | /INSTALL | /QUERY}\r\n\r\n /EXECUTE Enable execute mode (default).\r\n /INSTALL Enable install mode.\r\n /QUERY Display current settings.\r\n\r\n", "error": "Invalid parameter(s)\r\nChange Install Mode.\r\n\r\nCHANGE USER {/EXECUTE | /INSTALL | /QUERY}\r\n\r\n /EXECUTE Enable execute mode (default).\r\n /INSTALL Enable install mode.\r\n /QUERY Display current settings.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\chgusr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "chkdsk.exe-7A5061E14CD532A38C926AA7002DD205": { "file_name": "chkdsk.exe", "file_path": "C:\\Windows\\system32\\chkdsk.exe", "hash_md5": "7A5061E14CD532A38C926AA7002DD205", "hash_sha1": "F3A199547855FA4C35B1906DBFB66E2565DAB460", "hash_sha256": "F3F0645ED6CF3421520787846A8D0F66367522B4EC2C34021A1A11373D229712", "hash_sha384": "D1C1EA481E48A4E4A640EFD01518B6192E8735C504F11DE867A9FEB0E8AB516487EDA7E090D2D6D3871DAB4FC081A4CF", "hash_sha512": "FDAC2E99F72AB855C2FF03D7ECDC416DAC6DABB5115C82F31DCCE3378024D175792884EA8AF32350C02879BB17CC69111F9739304BB7793065C1D13EEEE00084", "hash_ssdeep": "384:0fiAp0JsN1ujvfSOrGjQ7egAVluOfRvH0fabr05SqeNqWSFKhW:0fiApuMujfQPuMVHfv0kVCK", "hash_imp": "B76F08B214F8792B9B5AAFBC94FB4F07", "hash_pesha1": "B5E6EEFBD3942E5A8FE86653679B78E7FA8123E5", "hash_pe256": "0C6EACAAC2C81D146C441FEF36491880EECF2F90169C728615BFE84BF081B897", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Check Disk Utility", "meta_original_filename": "CHKDSK.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f3f0645ed6cf3421520787846a8d0f66367522b4ec2c34021a1a11373d229712/detection", "output": "Checks a disk and displays a status report.\r\n\r\n\r\nCHKDSK [volume[[path]filename]]] [/F] [/V] [/R] [/X] [/I] [/C] [/L[:size]] [/B] [/scan] [/spotfix]\r\n\r\n\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name.\r\n filename FAT/FAT32 only: Specifies the files to check for\r\n fragmentation.\r\n /F Fixes errors on the disk.\r\n /V On FAT/FAT32: Displays the full path and name of every\r\n file on the disk.\r\n On NTFS: Displays cleanup messages if any.\r\n /R Locates bad sectors and recovers readable information\r\n (implies /F, when /scan not specified).\r\n /L:size NTFS only: Changes the log file size to the specified\r\n number of kilobytes. If size is not specified, displays\r\n current size.\r\n /X Forces the volume to dismount first if necessary.\r\n All opened handles to the volume would then be invalid\r\n (implies /F).\r\n /I NTFS only: Performs a less vigorous check of index\r\n entries.\r\n /C NTFS only: Skips checking of cycles within the folder\r\n structure.\r\n /B NTFS only: Re-evaluates bad clusters on the volume\r\n (implies /R)\r\n /scan NTFS only: Runs an online scan on the volume\r\n /forceofflinefix NTFS only: (Must be used with \"/scan\")\r\n Bypass all online repair; all defects found\r\n are queued for offline repair (i.e. \"chkdsk /spotfix\").\r\n /perf NTFS only: (Must be used with \"/scan\")\r\n Uses more system resources to complete a scan as fast as\r\n possible. This may have a negative performance impact on\r\n other tasks running on the system.\r\n /spotfix NTFS only: Runs spot fixing on the volume\r\n /sdcleanup NTFS only: Garbage collect unneeded security descriptor\r\n data (implies /F).\r\n /offlinescanandfix Runs an offline scan and fix on the volume.\r\n /freeorphanedchains FAT/FAT32/exFAT only: Frees any orphaned cluster chains\r\n instead of recovering their contents.\r\n /markclean FAT/FAT32/exFAT only: Marks the volume clean if no\r\n corruption was detected, even if /F was not specified.\r\n\r\nThe /I or /C switch reduces the amount of time required to run Chkdsk by\r\nskipping certain checks of the volume.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\chkdsk.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "chkntfs.exe-899CA96BF3EF67BF03808CCD7FC8F8F4": { "file_name": "chkntfs.exe", "file_path": "C:\\Windows\\system32\\chkntfs.exe", "hash_md5": "899CA96BF3EF67BF03808CCD7FC8F8F4", "hash_sha1": "B23B32225CEDB14AA43524EA9E00BDFDD61C6080", "hash_sha256": "B11778898A18C8A6A24AF153743060E1569F443AD73943BC4292EDA844C80E2E", "hash_sha384": "328A3D0FF0294CAF8267BBF09FBDAE403BD043874E7A0522541378B46029DE126869B5D1D1FE85040C564825B5EC1A54", "hash_sha512": "B3E5323DE6233833F6116795CB5AA59554EB06390982DB06DBBFF18A4D4A02A5092A7F34200D659B75CDD0ABFA674D9B4BF263A0BA7EC462DE3BF9C781D7C96F", "hash_ssdeep": "384:rOtQXGfBVa0gum5UTpr2QX0iBkNmqmBr0mqzrXm+TO0h2NUWi6W:ytQ4a0nmSTh2Pyqmbqzr3Cta", "hash_imp": "D41BF2F313E9EE8CBB20EF9AD2025250", "hash_pesha1": "A3CFB32DCA3043A4904B2701B9B4F199E824CDFC", "hash_pe256": "6A8CE9F5038F8AF4A6C927E99ADA63972A877AF81741FE44EE5C6FBA7DC437A1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NTFS Volume Maintenance Utility", "meta_original_filename": "CHKNTFS.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/b11778898a18c8a6a24af153743060e1569f443ad73943bc4292eda844c80e2e/detection", "output": "Displays or modifies the checking of disk at boot time.\r\n\r\nCHKNTFS volume [...]\r\nCHKNTFS /D\r\nCHKNTFS /T[:time]\r\nCHKNTFS /X volume [...]\r\nCHKNTFS /C volume [...]\r\n\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name.\r\n /D Restores the machine to the default behavior; all drives are\r\n checked at boot time and chkdsk is run on those that are\r\n dirty.\r\n /T:time Changes the AUTOCHK initiation countdown time to the\r\n specified amount of time in seconds. If time is not\r\n specified, displays the current setting.\r\n /X Excludes a drive from the default boot-time check. Excluded\r\n drives are not accumulated between command invocations.\r\n /C Schedules a drive to be checked at boot time; chkdsk will run\r\n if the drive is dirty.\r\n\r\nIf no switches are specified, CHKNTFS will display if the specified drive is\r\ndirty or scheduled to be checked on next reboot.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\chkntfs.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "choice.exe-1A9804F0C374283B094E9E55DC5EE128": { "file_name": "choice.exe", "file_path": "C:\\Windows\\system32\\choice.exe", "hash_md5": "1A9804F0C374283B094E9E55DC5EE128", "hash_sha1": "145F6745C02F5EFA23A411B5F87FCC995A4D3856", "hash_sha256": "B2191C32538842D3FDEFF972E5A77527FA35D69FA400AAD2AA2798B86FC6CF2A", "hash_sha384": "6B3CEFC5C85C090D77BD00D8900C7233A53CAC450111DA1E9634AC2ACD220B73AD0EC7B92DBA2CE0F3035E40E96B9559", "hash_sha512": "8CE31A84D01204F8360F75904500C9AE26218BF4E0A1A6F97108EDB65B20FE857FE597438BE5068AE0C7CB6F8A0F417039B19709BF8CC8D441FCB4DBFCA7CC62", "hash_ssdeep": "768:PZPyoiiumgQlRXh66ANl3HrGq9dyCq41Ar/27V1ZUxGt3P:VPbu/3HTdyCq41Ar/61qxS3P", "hash_imp": "F181EBCAA9D1344F02A766BAC8E1CFAA", "hash_pesha1": "E15010F6983433ED1593BA30845CF89C015836D9", "hash_pe256": "932254E5306B492C65D6F138F66BA31AD94955E7989DD060F76F6959D5E976A1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Offers the user a choice", "meta_original_filename": "choice.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b2191c32538842d3fdeff972e5a77527fa35d69fa400aad2aa2798b86fc6cf2a/detection", "output": "\r\nCHOICE [/C choices] [/N] [/CS] [/T timeout /D choice] [/M text]\r\n\r\nDescription:\r\n This tool allows users to select one item from a list \r\n of choices and returns the index of the selected choice.\r\n\r\nParameter List:\r\n /C choices Specifies the list of choices to be created.\r\n Default list is \"YN\".\r\n\r\n /N Hides the list of choices in the prompt.\r\n The message before the prompt is displayed\r\n and the choices are still enabled.\r\n\r\n /CS Enables case-sensitive choices to be selected.\r\n By default, the utility is case-insensitive.\r\n\r\n /T timeout The number of seconds to pause before a default \r\n choice is made. Acceptable values are from 0 to \r\n 9999. If 0 is specified, there will be no pause \r\n and the default choice is selected.\r\n\r\n /D choice Specifies the default choice after nnnn seconds.\r\n Character must be in the set of choices specified\r\n by /C option and must also specify nnnn with /T.\r\n\r\n /M text Specifies the message to be displayed before \r\n the prompt. If not specified, the utility \r\n displays only a prompt.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE:\r\n The ERRORLEVEL environment variable is set to the index of the\r\n key that was selected from the set of choices. The first choice\r\n listed returns a value of 1, the second a value of 2, and so on.\r\n If the user presses a key that is not a valid choice, the tool \r\n sounds a warning beep. If tool detects an error condition,\r\n it returns an ERRORLEVEL value of 255. If the user presses \r\n CTRL+BREAK or CTRL+C, the tool returns an ERRORLEVEL value\r\n of 0. When you use ERRORLEVEL parameters in a batch program, list\r\n them in decreasing order.\r\n\r\nExamples:\r\n CHOICE /?\r\n CHOICE /C YNC /M \"Press Y for Yes, N for No or C for Cancel.\"\r\n CHOICE /T 10 /C ync /CS /D y \r\n CHOICE /C ab /M \"Select a for option 1 and b for option 2.\"\r\n CHOICE /C ab /N /M \"Select a for option 1 and b for option 2.\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"CHOICE /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\choice.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "CIDiag.exe-64DE2494A5F31E732F3ADDB029841441": { "file_name": "CIDiag.exe", "file_path": "C:\\Windows\\system32\\CIDiag.exe", "hash_md5": "64DE2494A5F31E732F3ADDB029841441", "hash_sha1": "BC0AC2AF60ECA874BD44ECAE885E9F539D46F8EB", "hash_sha256": "5837847870A5ACEB61E8AA826875495E73AD05E8CC544424A431A2B4CCC48252", "hash_sha384": "4B45A040618ACCE964C07F627F0809CA6B5A5D0F2C62514CDB387B81410C9887B640AE544A012376A2C6060C47355033", "hash_sha512": "7693C082ECA3D001CE68461B8124469D1992DF78C24D2B86FF176687459B2857FD08CD3F27F079A67B6C2DB1A8F768E70D783DBAE406857E224F8FEDE8970417", "hash_ssdeep": "768:ZXNZZo0h/uuk9rIyeZrc35mvI++uP9w7l03VXQdr+gT8RdU:ZdZZo0h/uuk9rIycQMvI++F7++pVT8Re", "hash_imp": "792497AF5DD0DF4A915F2F6B0FE22F3D", "hash_pesha1": "A8D9232C6136B6BFB283F3F23FB15D424DDA957D", "hash_pe256": "C012BEFCE1587D625E3B44AA85A0A66F5F4BE912585A764F0932DC36A53C9C7F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CodeIntegrity Diagnostic Tool", "meta_original_filename": "CIDiag.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.329 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.329", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/5837847870a5aceb61e8aa826875495e73ad05e8cc544424a431a2b4ccc48252/detection", "output": "Usage: \"CIDiag.exe /start\", \"CIDiag.exe /stop <outputpath>\", or \"CIDiag.exe /stop /nologs <outputpath>\"\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\CIDiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "cipher.exe-F3471DDB5AE8E057F1B908A50E4AAD7C": { "file_name": "cipher.exe", "file_path": "C:\\Windows\\system32\\cipher.exe", "hash_md5": "F3471DDB5AE8E057F1B908A50E4AAD7C", "hash_sha1": "12B08C7A6A36D5624C2D7F40784C26A3607FA89B", "hash_sha256": "A6B2CFDE3E3DE872D9EDD6A16710ED6C8EE32A0DFCF57322B27B3DA8D18AE71A", "hash_sha384": "EB632BF7AE1DAC972F8085B154917E08FF45CFD819E0F715828A790C03F9A70E4630C3A2EF3B6C825FC591D4ADCE7F57", "hash_sha512": "9BEA40D52E4C36FDAD0E4FF02D6534737A0729E3BEE34DA0AA2BD5B74C966BE0868B638AE28CC8168127E59CC35368D508BF5CA379BE1E5C49824F05DBC85DF5", "hash_ssdeep": "768:/fwPMuMlMhvgfgiWLm7x62QfDrm+egQuLFL7BLmCfU0GWKwhj1QJGAfopGxnzZ5I:nwdKMhgfwS6ffDrm+egf+iDgJfQKI", "hash_imp": "E83B4C457AFD5EEA31874B00E8A3A956", "hash_pesha1": "10F31C3EE1D6409D7C3FEAA821C43597EC43CEC8", "hash_pe256": "8394875442C88988781381272B5642CCEE4B696F71D40A97951E2A05E741A278", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Encryption Utility", "meta_original_filename": "CIPHER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a6b2cfde3e3de872d9edd6a16710ed6c8ee32a0dfcf57322b27b3da8d18ae71a/detection", "output": "Displays or alters the encryption of directories [files] on NTFS partitions.\r\n\r\n CIPHER [/E | /D | /C]\r\n [/S:directory] [/B] [/H] [pathname [...]]\r\n\r\n CIPHER /K [/ECC:256|384|521]\r\n\r\n CIPHER /R:filename [/SMARTCARD] [/ECC:256|384|521]\r\n\r\n CIPHER /P:filename.cer\r\n\r\n CIPHER /U [/N]\r\n\r\n CIPHER /W:directory\r\n\r\n CIPHER /X[:efsfile] [filename]\r\n\r\n CIPHER /Y\r\n\r\n CIPHER /ADDUSER [/CERTHASH:hash | /CERTFILE:filename | /USER:username]\r\n [/S:directory] [/B] [/H] [pathname [...]]\r\n\r\n CIPHER /FLUSHCACHE [/SERVER:servername]\r\n\r\n CIPHER /REMOVEUSER /CERTHASH:hash\r\n [/S:directory] [/B] [/H] [pathname [...]]\r\n\r\n CIPHER /REKEY [pathname [...]]\r\n\r\n /B Abort if an error is encountered. By default, CIPHER continues\r\n executing even if errors are encountered.\r\n /C Displays information on the encrypted file.\r\n /D Decrypts the specified files or directories.\r\n /E Encrypts the specified files or directories. Directories will be\r\n marked so that files added afterward will be encrypted. The\r\n encrypted file could become decrypted when it is modified if the\r\n parent directory is not encrypted. It is recommended that you\r\n encrypt the file and the parent directory.\r\n /H Displays files with the hidden or system attributes. These files\r\n are omitted by default.\r\n /K Creates a new certificate and key for use with EFS. If this\r\n option is chosen, all the other options will be ignored.\r\n\r\n Note: By default, /K creates a certificate and key that conform\r\n to current group policy. If ECC is specified, a self-signed\r\n certificate will be created with the supplied key size.\r\n\r\n /N This option only works with /U. This will prevent keys being\r\n updated. This is used to find all the encrypted files on the\r\n local drives.\r\n /R Generates an EFS recovery key and certificate, then writes them\r\n to a .PFX file (containing certificate and private key) and a\r\n .CER file (containing only the certificate). An administrator may\r\n add the contents of the .CER to the EFS recovery policy to create\r\n the recovery key for users, and import the .PFX to recover\r\n individual files. If SMARTCARD is specified, then writes the\r\n recovery key and certificate to a smart card. A .CER file is\r\n generated (containing only the certificate). No .PFX file is\r\n generated.\r\n\r\n Note: By default, /R creates an 2048-bit RSA recovery key and\r\n certificate. If ECC is specified, it must be followed by a\r\n key size of 256, 384, or 521.\r\n\r\n /P Creates a base64-encoded recovery-policy blob from the passed-in\r\n certificate. This blob can be used to set DRA policy for\r\n MDM deployments.\r\n /S Performs the specified operation on the given directory and all\r\n files and subdirectories within it.\r\n /U Tries to touch all the encrypted files on local drives. This will\r\n update user's file encryption key or recovery keys to the current\r\n ones if they are changed. This option does not work with other\r\n options except /N.\r\n /W Removes data from available unused disk space on the entire\r\n volume. If this option is chosen, all other options are ignored.\r\n The directory specified can be anywhere in a local volume. If it\r\n is a mount point or points to a directory in another volume, the\r\n data on that volume will be removed.\r\n /X Backup EFS certificate and keys into file filename. If efsfile is\r\n provided, the current user's certificate(s) used to encrypt the\r\n file will be backed up. Otherwise, the user's current EFS\r\n certificate and keys will be backed up.\r\n /Y Displays your current EFS certificate thumbprint on the local PC.\r\n /ADDUSER Adds a user to the specified encrypted file(s). If CERTHASH is\r\n provided, cipher will search for a certificate with this SHA1\r\n hash. If CERTFILE is provided, cipher will extract the\r\n certificate from the file. If USER is provided, cipher will\r\n try to locate the user's certificate in Active Directory Domain\r\n Services.\r\n /FLUSHCACHE\r\n Clears the calling user's EFS key cache on the specified server.\r\n If servername is not provided, cipher clears the user's key cache\r\n on the local machine.\r\n /REKEY Updates the specified encrypted file(s) to use the configured\r\n EFS current key.\r\n /REMOVEUSER\r\n Removes a user from the specified file(s). CERTHASH must be the\r\n SHA1 hash of the certificate to remove.\r\n\r\n directory A directory path.\r\n filename A filename without extensions.\r\n pathname Specifies a pattern, file or directory.\r\n efsfile An encrypted file path.\r\n\r\n Used without parameters, CIPHER displays the encryption state of the\r\n current directory and any files it contains. You may use multiple directory\r\n names and wildcards. You must put spaces between multiple parameters.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\cipher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "cleanmgr.exe-D17E532DB343357FC9EBF5E559820BD4": { "file_name": "cleanmgr.exe", "file_path": "C:\\Windows\\system32\\cleanmgr.exe", "hash_md5": "D17E532DB343357FC9EBF5E559820BD4", "hash_sha1": "6EDC7C835D5C3410909999690D0ECF3D3EDB480A", "hash_sha256": "A43C79ECAE0D4726157FBB2E9E2E314D3622201678B56DB514AAE50EA84A09F9", "hash_sha384": "A6664786AEB39A5C0170F8BC80A592F0D85C95C267ABB9456DCA980BB0ED4DC548B220357767025C2D878E2D3DE43D80", "hash_sha512": "225E4959335DEFFF69D91358DDE1DF86CF54A19325F0589A316F57923101BE6A5244F6E845A18CBBD9A017870F5BC150F3D2C8ABC007BD0EE1F125623F0C4778", "hash_ssdeep": "3072:bQVx/3xmYvearjjPFC2bbymKByAEPGRvQhRkKqUa9antF5hvvJkuXpZ:a57XgtmKBFE+ohSKq99UF5hvv/", "hash_imp": "05A7686561BB995BEAD3C54DB2591AD1", "hash_pesha1": "F03F295A9CE64F4891A49DC00A4BB4941894CC67", "hash_pe256": "007BBD0E071911888E111FCC487927AA67A2892703541D724A77216F67799AAF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Space Cleanup Manager for Windows", "meta_original_filename": "CLEANMGR.DLL.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a43c79ecae0d4726157fbb2e9e2e314d3622201678b56db514aae50ea84a09f9/detection", "children": "DismHost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\cleanmgr.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\cleanmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\VSSAPI.DLL", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\VssTrace.DLL" ], "runtime_window_title": "USAGE" }, "cliconfg.exe-E06C0D21FFE629D45E3F0067B86D2CEA": { "file_name": "cliconfg.exe", "file_path": "C:\\Windows\\system32\\cliconfg.exe", "hash_md5": "E06C0D21FFE629D45E3F0067B86D2CEA", "hash_sha1": "05EEA2A01A7B63B43D8F465D190D206A890F3F30", "hash_sha256": "5B223B5BD106FF17C7817858CB6C371A055B54486E4C351CA952D6CD83A2DA88", "hash_sha384": "80D46CF053546942C5428B762DFD67B5148C4215F8E22C71980D66049F37BC14FC5887A8930EDA887854586205DBBA86", "hash_sha512": "9409D6D1C7BA6F069A551A37A20AF278EDE5DB452974FD7B853722A96FE24B5C1A1D3BF251D52846067CA479B0697F92E16DF236E6FEB297331AAE8DB3C419F0", "hash_ssdeep": "384:+TO+UvOyKBxv9CtYUJW0wWFPXuNvBQAMYJQ2JQSkdowyo:+TO+UvOBxtU5ruI30lJBkvT", "hash_imp": "E0A4A433A88E43CFE20831B905227E5B", "hash_pesha1": "6DCB70EB815E35D6D62E1F0A3B2B79DA4F34D426", "hash_pe256": "EA2DFE75AC0C30183B7726DACBD43901F86291DB464044217804673A47B59286", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SQL Client Configuration Utility EXE", "meta_original_filename": "cliconfg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5b223b5bd106ff17c7817858cb6c371a055b54486e4c351ca952d6cd83a2da88/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "(R-D) C:\\Windows\\System32\\en-US\\cliconfg.rll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.19041.1_en-us_6144a36069349598": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.19041.1_en-us_6144a36069349598\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\cliconfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll" ], "runtime_window_title": "SQL Server Client Network Utility" }, "clip.exe-50F2CF199F2EB26D37403C9D7268D81F": { "file_name": "clip.exe", "file_path": "C:\\Windows\\system32\\clip.exe", "hash_md5": "50F2CF199F2EB26D37403C9D7268D81F", "hash_sha1": "1DEAA1CDDCC528D30749DCA3CC410EBFE9ADE6C8", "hash_sha256": "5AD606BCBBBDB95DDA19C955E4129B436295CAC249E2370FEE3D0285D387CF55", "hash_sha384": "C42EF2CE3E5BBF6C4BF5262DD7CAFBB2085A9E39A1AD08F556507AF9DD3C7781A76334D83898AC748C41624D7205BCD4", "hash_sha512": "594F89523886B2451222067D196F1A62CAC9EF784B633DF638DDDC0F0E53042FF94C4D0C69751BD352DE3A9D502C5E38115E7CAE32C5772310D2FA3C4906AE2C", "hash_ssdeep": "768:RKq1nys0lSb7jg4jY5yi+i359SMY1yGiaLefVv0r0x+gNcgs:RKq1BNLdi3scGiaLef+Ixfcg", "hash_imp": "D4F9D4B3E58F3C49F0B3042F0B20C802", "hash_pesha1": "C7CD388D1908DD1812B7F3104D529FF8313838F5", "hash_pe256": "3D992025F26A7D8A1BB3E2AB15982D2D4E4169DD1CE924666776BFB3DB26A8F8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Clip - copies the data into clipboard", "meta_original_filename": "clip.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/5ad606bcbbbdb95dda19c955e4129b436295cac249e2370fee3d0285d387cf55/detection", "output": "\r\nCLIP\r\n\r\nDescription:\r\n Redirects output of command line tools to the Windows clipboard.\r\n This text output can then be pasted into other programs.\r\n\r\nParameter List:\r\n /? Displays this help message.\r\n\r\nExamples:\r\n DIR | CLIP Places a copy of the current directory\r\n listing into the Windows clipboard.\r\n\r\n CLIP < README.TXT Places a copy of the text from readme.txt\r\n on to the Windows clipboard.\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"CLIP /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\clip.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ClipRenew.exe-F9C43C85CB2068DF7DEB1C9D58046400": { "file_name": "ClipRenew.exe", "file_path": "C:\\Windows\\system32\\ClipRenew.exe", "hash_md5": "F9C43C85CB2068DF7DEB1C9D58046400", "hash_sha1": "F4EE9279F964E7349CDE354B91E2440CCC226C7F", "hash_sha256": "F6E6F9043A1DDB2028D7960E9269E174ACBB54242099B0F6160E081DFBF564CE", "hash_sha384": "D2036FA4789C03070620BE7D920F0825F5E551548B28251F3B0554EA2C1FF0AFC4C659C236726E1F6D86FAE9550BCBDC", "hash_sha512": "70EBA74FB0236AD30AC12984142D07C2398676F6948C22EA1A1467587F55BB00ADD7B17F37B0686622D4840DD469FEE49F8BAAEBC6FB740FC8CD65D85E58809A", "hash_ssdeep": "3072:Uy/X5H/pZurO8GZgqcIruYzpXOIAEaR5O:U8pHBZcUZLcIruYzJOb", "hash_imp": "0E7E6B5C5220A319F4AF2426CF1F807D", "hash_pesha1": "57308F039F4B47B83B629352EF8035DB4C10B4C1", "hash_pe256": "60EBCF43B1117E11D7AA7F0B0423DD7CAFFCD56168F465AA0EBB583D0B43833D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Acquire License From Store", "meta_original_filename": "ClipRenew.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/f6e6f9043a1ddb2028d7960e9269e174acbb54242099b0f6160e081dfbf564ce/detection", "runtime_modules": [ "C:\\Windows\\system32\\ClipRenew.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\dsreg.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\CRYPT32.dll" ] }, "ClipUp.exe-0BE391A5D9C5FB4DE0CD1A4B1440FF69": { "file_name": "ClipUp.exe", "file_path": "C:\\Windows\\system32\\ClipUp.exe", "hash_md5": "0BE391A5D9C5FB4DE0CD1A4B1440FF69", "hash_sha1": "CA6025A1B991A367DBB790C03F86CBB46646509B", "hash_sha256": "A8FD7DBF296BFD7117ACBF844ED84B0DB896524825D8A172C4D4C1272C8F4087", "hash_sha384": "3D952B7D56FD2D81750655C6E494E30CD6F8160D4BF6C6383E570E2CCFCFB3C2FE45ED8B11ADE8C52A5BAED9B7AB2783", "hash_sha512": "2293CF50F48265562D1F7B170DAEBF0BA66E8E7DB5027163305AF2E4176181FD8EB91AA1AA2636D04C20ABCED4D158A3F563A6626CE30F494C5BC73DC43ACB48", "hash_ssdeep": "24576:g22rikDzqNUGWO+JlEE1Rp2G55JwrygkeI0Q+p+z60:gzVDeU5O+kiYrseVx0", "hash_imp": "5DD332D22060CEB44D5347FCE1989751", "hash_pesha1": "C2EDF5AFBC4E7BC893699B42B24FD01580521F06", "hash_pe256": "40989C3DA8E6215DDFCA6D85646C9CED7FBC5E9C3A529C2415D145BA96C29452", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Client License Platform migration tool", "meta_original_filename": "ClipUp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a8fd7dbf296bfd7117acbf844ed84b0db896524825d8a172c4d4c1272c8f4087/detection", "error": "Failed! Error 0x80070057.\r\n", "output": "Done.\r\nC:\\Windows\\system32\\ClipUp.exe Usage: \r\n-?/-h\tThis help menu\r\n-p \tAttempts to migrate data from the legacy Windows Phone database\r\n-o \tAttempts to migrate data from Windows Genuine Authorization blob\r\n-altto \t[path] Optional alternative Windows Genuine Authorization blob folder location\r\n-d \tGenerate a genuine ticket for the BIOS key\r\n-k \t[5X5 product key] Windows product key\r\n-pfm \t[package family name] Optional package family name to look for a migratable license\r\n-l \t[path] Optional folder of legacy Windows Store licenses\r\n-v \tEnables optional verbose logging\r\n-previd \tDevice ID prior to hardware-related changes\r\n[path]\tOptional alternative output location for migrated data\r\nDone.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\ClipUp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "CloudExperienceHostBroker.exe-A1A471DD1A8B5D479866661E54320832": { "file_name": "CloudExperienceHostBroker.exe", "file_path": "C:\\Windows\\system32\\CloudExperienceHostBroker.exe", "hash_md5": "A1A471DD1A8B5D479866661E54320832", "hash_sha1": "8B4A3F4FCE4179400039964BCE73B427C5C054E9", "hash_sha256": "8A9A207A88BFE90889F783EF4FCE2383A6955AB5C5AFA13F49826D6B88360FE8", "hash_sha384": "A91E8ABB293830D61D9F5D6D61DA6676A72D72571B20545B5E185810CAD67CEC43BEE327DBE9E80603FB864BD161A5E4", "hash_sha512": "DE8BE203F7372244787F0372D08533C812DA8B37B198AC8784EBA4BBD15D54BCD51CBCB547238D78422A6197D5DF1D44ED4889DA02061383273527D38B5E9CF3", "hash_ssdeep": "1536:r9bmvT0o8Di6ZRgv5SYle/XzBH2UO+CxB7XTYHnOJPXPapzrR:Ur0Di06Sue/XNHDO+chTyOJPXQ5", "hash_imp": "F44EF1AC01AF15CA9A6E9DBF699063B9", "hash_pesha1": "29F0EA3738D270E62C3BEEA70EF06D1BF940188B", "hash_pe256": "87EDBBA144885BAF239E422A4A7E331BBE8FB307BB0919D05C188ED0FF616D5B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CloudExperienceHost Broker", "meta_original_filename": "CloudExperienceHostBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.508 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.508", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8a9a207a88bfe90889f783ef4fce2383a6955ab5c5afa13f49826d6b88360fe8/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\CloudExperienceHostBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll" ] }, "CloudNotifications.exe-2F98D2E07B3B3557A28583BA47D8A3C4": { "file_name": "CloudNotifications.exe", "file_path": "C:\\Windows\\system32\\CloudNotifications.exe", "hash_md5": "2F98D2E07B3B3557A28583BA47D8A3C4", "hash_sha1": "CCCCAC749E74426D34E66243818E540D89B700FA", "hash_sha256": "F14079B36F180AB59F02827222CDCC4948FAC197C223EC3B732667ABF99D7F91", "hash_sha384": "75CFDF331CE6BEFA6773701A97120182FDA985EB2B70B67C855F4D0C736A34B795AB401C8679E1E35DD0AE07795C6F06", "hash_sha512": "0303E2AF3F1E40D753D48A7EAF27944368DC19C7534ED039AF9A76FCEDB3E73ABEAADE5CFF6A13BB047919E528F16933988E82BBF80F4DF5306DF7423DE5684C", "hash_ssdeep": "1536:UAdhHhV1rUZt8r/4botKhM+hDXDLd9tWyj3I7CFPEf:Vib8rbtKa+JTLdPDj3IuFsf", "hash_imp": "76AC3B575CAD11297CDCC1151A77E563", "hash_pesha1": "28869430B4CB7429504B7170BB1CF4474734E957", "hash_pe256": "ACF0297FF1F90A5235551A39DAEEEF75F7C27F5358E203B09FEE1D8000FA586C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Cloud notifications", "meta_original_filename": "CloudNotifications.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f14079b36f180ab59f02827222cdcc4948fac197c223ec3b732667abf99d7f91/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\CloudNotifications.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\SystemResources\\Windows.UI.Immersive.dll.mun": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\Windows.UI.Immersive.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(RWD) C:\\Windows\\Fonts\\seguisym.ttf": "File", "(RWD) C:\\Windows\\Fonts\\segoeuisl.ttf": "File", "(RWD) C:\\Windows\\Fonts\\seguisb.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\CloudNotifications.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ], "runtime_window_title": "Low disk space" }, "cmd.exe-321A50053155122E6ACE9691197A8E3F": { "file_name": "cmd.exe", "file_path": "C:\\Windows\\system32\\cmd.exe", "hash_md5": "321A50053155122E6ACE9691197A8E3F", "hash_sha1": "77BB1893182667D4B3614A55592C9DC42FBB831D", "hash_sha256": "100348552B388AB5D0095BB09EBF0EBC22668092FB8E0F92AC7ED5909492B4F6", "hash_sha384": "4DE379D932CF6CFFDE9582842D5E5DDBE6B0B5F62943D9109E66C22F26162EE4A4B650D0962D87FAD815DF23AA972328", "hash_sha512": "1839F33E89B1EEDD6126D1AA3AC0CB4A46125535BDD168F6124D3C347A28BE79EFB80F14A9D91702E9ADEBACC3E8514ED2C9C0055137B71AF443E275A29D3E30", "hash_ssdeep": "6144:sotX7CuMWEnynN5WgsTd1g3SfOWlWE5vIfzmmbt2Tjm:t7CakgLmd1g3eRWkvmiYcTj", "hash_imp": "272245E2988E1E430500B852C4FB5E18", "hash_pesha1": "68BB2ABB85BEC52A20EC9FB4066A350371A361AC", "hash_pe256": "3044C88F0520B591B6858B13EF6FDF3E9F65FE0B0F63F5FBA3B567291331CBE9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Command Processor", "meta_original_filename": "Cmd.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/100348552b388ab5d0095bb09ebf0ebc22668092fb8e0f92ac7ed5909492b4f6/detection", "output": "Starts a new instance of the Windows command interpreter\r\n\r\nCMD [/A | /U] [/Q] [/D] [/E:ON | /E:OFF] [/F:ON | /F:OFF] [/V:ON | /V:OFF]\r\n [[/S] [/C | /K] string]\r\n\r\n/C Carries out the command specified by string and then terminates\r\n/K Carries out the command specified by string but remains\r\n/S Modifies the treatment of string after /C or /K (see below)\r\n/Q Turns echo off\r\n/D Disable execution of AutoRun commands from registry (see below)\r\n/A Causes the output of internal commands to a pipe or file to be ANSI\r\n/U Causes the output of internal commands to a pipe or file to be\r\n Unicode\r\n/T:fg Sets the foreground/background colors (see COLOR /? for more info)\r\n/E:ON Enable command extensions (see below)\r\n/E:OFF Disable command extensions (see below)\r\n/F:ON Enable file and directory name completion characters (see below)\r\n/F:OFF Disable file and directory name completion characters (see below)\r\n/V:ON Enable delayed environment variable expansion using ! as the\r\n delimiter. For example, /V:ON would allow !var! to expand the\r\n variable var at execution time. The var syntax expands variables\r\n at input time, which is quite a different thing when inside of a FOR\r\n loop.\r\n/V:OFF Disable delayed environment expansion.\r\n\r\nNote that multiple commands separated by the command separator '&&'\r\nare accepted for string if surrounded by quotes. Also, for compatibility\r\nreasons, /X is the same as /E:ON, /Y is the same as /E:OFF and /R is the\r\nsame as /C. Any other switches are ignored.\r\n\r\nIf /C or /K is specified, then the remainder of the command line after\r\nthe switch is processed as a command line, where the following logic is\r\nused to process quote (\") characters:\r\n\r\n 1. If all of the following conditions are met, then quote characters\r\n on the command line are preserved:\r\n\r\n - no /S switch\r\n - exactly two quote characters\r\n - no special characters between the two quote characters,\r\n where special is one of: &<>()@^|\r\n - there are one or more whitespace characters between the\r\n two quote characters\r\n - the string between the two quote characters is the name\r\n of an executable file.\r\n\r\n 2. Otherwise, old behavior is to see if the first character is\r\n a quote character and if so, strip the leading character and\r\n remove the last quote character on the command line, preserving\r\n any text after the last quote character.\r\n\r\nIf /D was NOT specified on the command line, then when CMD.EXE starts, it\r\nlooks for the following REG_SZ/REG_EXPAND_SZ registry variables, and if\r\neither or both are present, they are executed first.\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\AutoRun\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\AutoRun\r\n\r\nCommand Extensions are enabled by default. You may also disable\r\nextensions for a particular invocation by using the /E:OFF switch. You\r\ncan enable or disable extensions for all invocations of CMD.EXE on a\r\nmachine and/or user logon session by setting either or both of the\r\nfollowing REG_DWORD values in the registry using REGEDIT.EXE:\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\EnableExtensions\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\EnableExtensions\r\n\r\nto either 0x1 or 0x0. The user specific setting takes precedence over\r\nthe machine setting. The command line switches take precedence over the\r\nregistry settings.\r\n\r\nIn a batch file, the SETLOCAL ENABLEEXTENSIONS or DISABLEEXTENSIONS arguments\r\ntakes precedence over the /E:ON or /E:OFF switch. See SETLOCAL /? for details.\r\n\r\nThe command extensions involve changes and/or additions to the following\r\ncommands:\r\n\r\n DEL or ERASE\r\n COLOR\r\n CD or CHDIR\r\n MD or MKDIR\r\n PROMPT\r\n PUSHD\r\n POPD\r\n SET\r\n SETLOCAL\r\n ENDLOCAL\r\n IF\r\n FOR\r\n CALL\r\n SHIFT\r\n GOTO\r\n START (also includes changes to external command invocation)\r\n ASSOC\r\n FTYPE\r\n\r\nTo get specific details, type commandname /? to view the specifics.\r\n\r\nDelayed environment variable expansion is NOT enabled by default. You\r\ncan enable or disable delayed environment variable expansion for a\r\nparticular invocation of CMD.EXE with the /V:ON or /V:OFF switch. You\r\ncan enable or disable delayed expansion for all invocations of CMD.EXE on a\r\nmachine and/or user logon session by setting either or both of the\r\nfollowing REG_DWORD values in the registry using REGEDIT.EXE:\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\DelayedExpansion\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DelayedExpansion\r\n\r\nto either 0x1 or 0x0. The user specific setting takes precedence over\r\nthe machine setting. The command line switches take precedence over the\r\nregistry settings.\r\n\r\nIn a batch file the SETLOCAL ENABLEDELAYEDEXPANSION or DISABLEDELAYEDEXPANSION\r\narguments takes precedence over the /V:ON or /V:OFF switch. See SETLOCAL /?\r\nfor details.\r\n\r\nIf delayed environment variable expansion is enabled, then the exclamation\r\ncharacter can be used to substitute the value of an environment variable\r\nat execution time.\r\n\r\nYou can enable or disable file name completion for a particular\r\ninvocation of CMD.EXE with the /F:ON or /F:OFF switch. You can enable\r\nor disable completion for all invocations of CMD.EXE on a machine and/or\r\nuser logon session by setting either or both of the following REG_DWORD\r\nvalues in the registry using REGEDIT.EXE:\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\CompletionChar\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\PathCompletionChar\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\CompletionChar\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\PathCompletionChar\r\n\r\nwith the hex value of a control character to use for a particular\r\nfunction (e.g. 0x4 is Ctrl-D and 0x6 is Ctrl-F). The user specific\r\nsettings take precedence over the machine settings. The command line\r\nswitches take precedence over the registry settings.\r\n\r\nIf completion is enabled with the /F:ON switch, the two control\r\ncharacters used are Ctrl-D for directory name completion and Ctrl-F for\r\nfile name completion. To disable a particular completion character in\r\nthe registry, use the value for space (0x20) as it is not a valid\r\ncontrol character.\r\n\r\nCompletion is invoked when you type either of the two control\r\ncharacters. The completion function takes the path string to the left\r\nof the cursor appends a wild card character to it if none is already\r\npresent and builds up a list of paths that match. It then displays the\r\nfirst matching path. If no paths match, it just beeps and leaves the\r\ndisplay alone. Thereafter, repeated pressing of the same control\r\ncharacter will cycle through the list of matching paths. Pressing the\r\nShift key with the control character will move through the list\r\nbackwards. If you edit the line in any way and press the control\r\ncharacter again, the saved list of matching paths is discarded and a new\r\none generated. The same occurs if you switch between file and directory\r\nname completion. The only difference between the two control characters\r\nis the file completion character matches both file and directory names,\r\nwhile the directory completion character only matches directory names.\r\nIf file completion is used on any of the built in directory commands\r\n(CD, MD or RD) then directory completion is assumed.\r\n\r\nThe completion code deals correctly with file names that contain spaces\r\nor other special characters by placing quotes around the matching path.\r\nAlso, if you back up, then invoke completion from within a line, the\r\ntext to the right of the cursor at the point completion was invoked is\r\ndiscarded.\r\n\r\nThe special characters that require quotes are:\r\n <space>\r\n &()[]{}^=;!'+,`~\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\cmd.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\cmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "cmdkey.exe-F9C20642B4CFCE4517F4F26B6305607C": { "file_name": "cmdkey.exe", "file_path": "C:\\Windows\\system32\\cmdkey.exe", "hash_md5": "F9C20642B4CFCE4517F4F26B6305607C", "hash_sha1": "B0DE4D5F0E178002E02C66DAF064DFD3FF1DBDE6", "hash_sha256": "14BCC1901C5CCA8E91A6400050308752916AC861BDD52CF3A44DC7EF46830282", "hash_sha384": "45F38A585851501FAA095A9374AEC160DB3800B9AC9196D0D64AA1DF74E449D97A1C542737072B169DEAA2493F3C2862", "hash_sha512": "8EB98B07E17EF8B0891F79C5248F3A59EEBA41F190746C4407AC401329225A17051401A82807CBACDB265784EEA4D38BD8BF89E3080C30FAFFE4C3F5691D1A13", "hash_ssdeep": "384:MXKDF3y+4BMfcDv2ZtqjXR/1RvOiDVwJxCGsVW3wW:5Jd4qShzTDSCGsK", "hash_imp": "03AD7A1AF78BF7A500FB199CABE4C34A", "hash_pesha1": "F98AF9D1CC63F9DFED9EC2FF7AD8A5C407B7808C", "hash_pe256": "06D8A0BCD59D55E87AF90D582B9FE43A45AA00FFE121B469E2139AFD8DEDC6F1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Manager Command Line Utility", "meta_original_filename": "cmdkey.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/14bcc1901c5cca8e91a6400050308752916ac861bdd52cf3a44dc7ef46830282/detection", "output": "\r\nCreates, displays, and deletes stored user names and passwords.\r\n\r\nThe syntax of this command is:\r\n\r\nCMDKEY [{/add | /generic}:targetname {/smartcard | /user:username {/pass{:password}}} | /delete{:targetname | /ras} | /list{:targetname}]\r\n\r\nExamples:\r\n\r\n To list available credentials:\r\n cmdkey /list\r\n cmdkey /list:targetname\r\n\r\n To create domain credentials:\r\n cmdkey /add:targetname /user:username /pass:password\r\n cmdkey /add:targetname /user:username /pass\r\n cmdkey /add:targetname /user:username\r\n cmdkey /add:targetname /smartcard\r\n \r\n To create generic credentials:\r\n The /add switch may be replaced by /generic to create generic credentials\r\n\r\n To delete existing credentials:\r\n cmdkey /delete:targetname\r\n\r\n To delete RAS credentials:\r\n cmdkey /delete /ras\r\n \r\n", "runtime_modules": [ "C:\\Windows\\system32\\cmdkey.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "cmdl32.exe-77B22CEA6688A005473FC4896910924F": { "file_name": "cmdl32.exe", "file_path": "C:\\Windows\\system32\\cmdl32.exe", "hash_md5": "77B22CEA6688A005473FC4896910924F", "hash_sha1": "5CCF7BFEF1E003644E7DF2C226D76B1B31C4DDCD", "hash_sha256": "28A7FF1AE045EB1FE7ED6A7DCD9B2212411C449A8AFE0E652071AF48BEAC610D", "hash_sha384": "624032478818B9044B32962532F599A79248708E0FD064ED5AC8085FFD5C327CED7D91EB3328D33DAF4DD3BA7E59C2A4", "hash_sha512": "B16CB5A2D44F01EEB70012A5B34540BC44839F2F610EB84A63A6ABCCCA7ADFEB26CB725213DEA5F68700BBF464615558E0796005450F1F1016D64DEFF316964D", "hash_ssdeep": "1536:qHYI8+yFRfADp+o03NC4uKlyDQoD3swgz9szevkp8KdjQ352xiI:cYFvo+YGNJq8KdjQ3JI", "hash_imp": "AD55713E249A605BD30190ACBD0F9776", "hash_pesha1": "526929185B0FEFE49BB168116732F67A967EF16A", "hash_pe256": "85E3E5F69BCB0F1F4DA4349EE0F3533D46DEF7FA919984DAC3E5F8D59FFDD73A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Connection Manager Auto-Download", "meta_original_filename": "CMDL32.EXE.MUI", "meta_product_name": "Microsoft(R) Connection Manager", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.19041.1 (WinBuild.160101.0800)", "meta_product_version": "7.2.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/28a7ff1ae045eb1fe7ed6a7dcd9b2212411c449a8afe0e652071af48beac610d/detection", "runtime_modules": [ "C:\\Windows\\system32\\cmdl32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\cmpbk32.dll", "C:\\Windows\\system32\\cmutil.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28\\COMCTL32.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\system32\\RASAPI32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\system32\\WINHTTP.dll" ] }, "cmmon32.exe-BAFEC2E2CA3D475942E001907B9597BC": { "file_name": "cmmon32.exe", "file_path": "C:\\Windows\\system32\\cmmon32.exe", "hash_md5": "BAFEC2E2CA3D475942E001907B9597BC", "hash_sha1": "149A762FDAD6E688823754413D50FBD69BC55FE4", "hash_sha256": "542D796DB8372C7BD3F9861E0071FFADFAB3E9B5CF49A9CDC975C5CB003F3D5F", "hash_sha384": "C8B0C9185ED9C134D3AEAA5767F763C6DDBFB53F2489CB4515D99FA68F6C076AC30880DD5AF42EBA87D1548C7CEACE14", "hash_sha512": "4B2C8238029848EE7000AE36F8B4EA247849ECF1898E7D7EF5A6987E7C004D9FA2698091B7BD70161C1CC11050F302AD57D211FB7518CAEF711335DB02AE1000", "hash_ssdeep": "768:gM1x20HxMOlnNsJEqWx6LkXaHDnOHh9UASndImNDJWe:Dx20RP2Ep6LkXaHDq9CnNDJWe", "hash_imp": "99EE87FB928DFE3DEA854430CDA54850", "hash_pesha1": "37DBE7861E0FD00542AC853E762DDBF53023FC49", "hash_pe256": "3FCBE7B0E80EB02F56BD64281C8334E151806D042E4EC1EE79EFE21AC0D0B703", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Connection Manager Monitor", "meta_original_filename": "CMMON32.exe.mui", "meta_product_name": "Microsoft(R) Connection Manager", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.19041.1 (WinBuild.160101.0800)", "meta_product_version": "7.2.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/542d796db8372c7bd3f9861e0071ffadfab3e9b5cf49a9cdc975c5cb003f3d5f/detection", "runtime_modules": [ "C:\\Windows\\system32\\cmmon32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\cmutil.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\VERSION.dll" ] }, "cmstp.exe-4CC43FE4D397FF79FA69F397E016DF52": { "file_name": "cmstp.exe", "file_path": "C:\\Windows\\system32\\cmstp.exe", "hash_md5": "4CC43FE4D397FF79FA69F397E016DF52", "hash_sha1": "8FD6CF81AD40C9B123CD75611860A8B95C72869C", "hash_sha256": "F2D3905EE38B2B5C0B724D582F14EB1DB7621FFB8F3826DF686A20784341614C", "hash_sha384": "07E1DF4F8D73864CD8A3919C0F6806DCFD133BFD98B4A746F43075C106B1235D23A64186A5D9D476732093F7B2C82522", "hash_sha512": "851EF9FA5A03EC8B9FEA0094C6E4BFA0B9E71CEE3412EE86B2DFC34682AA5FB6455FEFE7FC0092B711956D7C880CF8A5761B63EE990AA8E72F3473086AC0F157", "hash_ssdeep": "1536:IuDT8WaTCxyBRTzVDnqeQCLGAtkHJDygsyux+bFrQe3tAljHZjlLKR8M187BM5jp:I2RJcRtnACkp5QGtA15Bi27BM5j9O1JE", "hash_imp": "109BA8ED3C458360A74EA1216207CA09", "hash_pesha1": "2A456ED6F5D8E5EA5A5277BEF57FA817C9DC4E29", "hash_pe256": "3D4086A6B3D6C72E6CA59AF808E8DC2F937517C680D1B4742636090FBA594F07", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Connection Manager Profile Installer", "meta_original_filename": "CMSTP.EXE.MUI", "meta_product_name": "Microsoft(R) Connection Manager", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.19041.1 (WinBuild.160101.0800)", "meta_product_version": "7.2.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/f2d3905ee38b2b5c0b724d582f14eb1db7621ffb8f3826df686a20784341614c/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\cmstp.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\cmstp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ], "runtime_window_title": "Connection Manager Profile Installer" }, "cofire.exe-585A383A2D2F6C9466367A50CAA1AFF2": { "file_name": "cofire.exe", "file_path": "C:\\Windows\\system32\\cofire.exe", "hash_md5": "585A383A2D2F6C9466367A50CAA1AFF2", "hash_sha1": "2C34288B7DF5F1AEFCAF6E23602193413A8862B4", "hash_sha256": "BB4B7C9197803404DB85684A5DB5528A87E1E0A9D1D6906A608F7FD6DD1659A8", "hash_sha384": "199C7F7C0356DD355C91D32B5970FEC23E61BC41F757CF6C8B9D4105E11123E8C3B9EB1B01D9EC0B2AF13F043942CB2D", "hash_sha512": "1EDC2E15870F252B1B84DC7FE7A462A9B5DBE6F8FC0DA0DA0881229CA3124CE99C7058212F2373BF18AB33DCD075CC2C46A6841B6842A5C97ADEB3E8A2E35BA5", "hash_ssdeep": "384:Hrs2LDWkGGaZ5pZ21SauUohaueuLf95/704/fOePFNAmkseW0JW:LlCHGCw1qleeDjTF6mD0", "hash_imp": "49C319693A3F09328AFCB91C7F2E2CBE", "hash_pesha1": "1003E9D75DBE6B924E2EC75F15C0684058F0782F", "hash_pe256": "2E3192A1DA136DED8DD3324CBD6F75BD77F88B1FAA528313C4C38A3D58D66E12", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Corrupted File Recovery Client", "meta_original_filename": "cofire.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/bb4b7c9197803404db85684a5db5528a87e1e0a9d1d6906a608f7fd6dd1659a8/detection", "runtime_modules": [ "C:\\Windows\\system32\\cofire.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "colorcpl.exe-7009947CFC65EA513ED9EBD37EC63C62": { "file_name": "colorcpl.exe", "file_path": "C:\\Windows\\system32\\colorcpl.exe", "hash_md5": "7009947CFC65EA513ED9EBD37EC63C62", "hash_sha1": "62B0273CD43E21DC9E55A100BE1F7C52D6C5F249", "hash_sha256": "86C19BC9523FB84EEF1A18AF66ACED909C32FEDBAD9988397A8367A836BBB2E0", "hash_sha384": "B71E7970CD5AA3C28E8909F4DABAF3F889BD9D12D2D233BB4E0EB1BEBF62902B671B51891B49F092B319E1BD2B1F408F", "hash_sha512": "514DFB6B4CFAC6BCB7B70B810A1FDBBFF6E21EBDBD0DE3929045E53520B9045D9CCCD9897996800875184415693AE1D4A7E0DA1C9F5307D12CE49FD480C7E7A3", "hash_ssdeep": "1536:wf7sbIPfSbS9vMBN7rQOJ7CFToTCzhcRguhwxTyPCb3lZpdym4dy7p:a4EXlvq7jSP1cR2prbpdCY9", "hash_imp": "BF699192BC903253BE75CBD63776138C", "hash_pesha1": "3CB5DE3671DE72DB42C1A002BEAFC680FD6E2157", "hash_pe256": "C711DCD79F719F80C5438AFC58B255D35F5E08333FBCDE7B903FAA95FF473EE8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Color Control Panel", "meta_original_filename": "colorcpl.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/86c19bc9523fb84eef1a18af66aced909c32fedbad9988397a8367a836bbb2e0/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\colorcpl.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\colorui.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\colorcpl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\colorui.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\WINSPOOL.DRV", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ], "runtime_window_title": "Color Management" }, "comp.exe-18F8A8D83533AE93382E6E4C236405D8": { "file_name": "comp.exe", "file_path": "C:\\Windows\\system32\\comp.exe", "hash_md5": "18F8A8D83533AE93382E6E4C236405D8", "hash_sha1": "CD6BBE67E0B1675ED6CB93AF2A9A14E09C233480", "hash_sha256": "C2729CBCB6A723939CA111C7EE82BAB30856EC8D728CA234459112B975B9F306", "hash_sha384": "07EB14BDA1518C1DEC418D674B0B333DC7974AD3ABEBF6F08A7B4C3381A813D31D431E9A53015BB64F9753C4EF01CEA8", "hash_sha512": "DCAB01D741D9DDF0D6E1063C395B47EF1B4E8DC85A838964E80668571E8406EB61994BDCC084E8A0DBBC1ACE5AFC3478549F3F418FA4E64B6D11E4E1059F30B9", "hash_ssdeep": "384:xlqkwafU/pK5j53eh7MG3nEaZG6uftggJiDwC+m4vNDWccW:L85Ad53ehzEaHctggkx4vh", "hash_imp": "02B63B93BB0FF42FF5BEB4C6E62D06B7", "hash_pesha1": "CA080272F02C67D9882D2298398E9AA4CC1B7ED7", "hash_pe256": "B85989AAA74E81D22126A124C32B44918F8E509B290398A4173DD8972E4DFDD1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Compare Utility", "meta_original_filename": "Comp.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c2729cbcb6a723939ca111c7ee82bab30856ec8d728ca234459112b975b9f306/detection", "output": "Compares the contents of two files or sets of files.\r\n\r\nCOMP [data1] [data2] [/D] [/A] [/L] [/N=number] [/C] [/OFF[LINE]] [/M]\r\n\r\n data1 Specifies location and name(s) of first file(s) to compare.\r\n data2 Specifies location and name(s) of second files to compare.\r\n /D Displays differences in decimal format.\r\n /A Displays differences in ASCII characters.\r\n /L Displays line numbers for differences.\r\n /N=number Compares only the first specified number of lines in each file.\r\n /C Disregards case of ASCII letters when comparing files.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n /M Do not prompt for compare more files.\r\n\r\nTo compare sets of files, use wildcards in data1 and data2 parameters.\r\n", "error": "Name of second file to compare: ", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\ulib.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\comp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "compact.exe-278549BBD0CE09F011C1B8481576CA0C": { "file_name": "compact.exe", "file_path": "C:\\Windows\\system32\\compact.exe", "hash_md5": "278549BBD0CE09F011C1B8481576CA0C", "hash_sha1": "8AD4FF0884AD295489495EDCCEECAF2595D96FF3", "hash_sha256": "6245640E75E1E55AF426F8D9A779B8478F8034479AD5CA7D49E5BEBEB823B76A", "hash_sha384": "4DD1DCDD1E49D0D078A0908383C1AEBA29E723C5844103E9E7443D24751357BDB1A0A2D3E4D2AF0A4FBECF10B55DB9DB", "hash_sha512": "AB07478DDF1A38B1E39D1EA31FCB47CB4B3B24D68B2091109D303216F8490CAE94EE9BD468B53B6B15CBBE50E513160FDED583BABFEC575B10A8F39A4E34C26B", "hash_ssdeep": "768:pq9T3sJh6bx2X1YMDgvILb107Y7fKHvApyMuuoJQcTlpHpoaqEzsztq5uIVTZ:whXt0YcgvIP14t493oJQcTlpHp1qzzts", "hash_imp": "928C9114035A0164EB94B966F4A358C8", "hash_pesha1": "E914796C6714E0B6BA3024A07635E4A33BFD4363", "hash_pe256": "2EB1147B3CAF5FA01B4F1D76DA9420CAA6949B4B1E09D46A3981F63634996CA2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Compress Utility", "meta_original_filename": "COMPACT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6245640e75e1e55af426f8d9a779b8478f8034479ad5ca7d49e5bebeb823b76a/detection", "output": "Displays or alters the compression of files on NTFS partitions.\r\n\r\nCOMPACT [/C | /U] [/S[:dir]] [/A] [/I] [/F] [/Q] [/EXE[:algorithm]]\r\n [/CompactOs[:option] [/WinDir:dir]] [filename [...]]\r\n\r\n /C Compresses the specified files. Directories will be marked\r\n so that files added afterward will be compressed unless /EXE\r\n is specified.\r\n /U Uncompresses the specified files. Directories will be marked\r\n so that files added afterward will not be compressed. If\r\n /EXE is specified, only files compressed as executables will\r\n be uncompressed; if this is omitted, only NTFS compressed\r\n files will be uncompressed.\r\n /S Performs the specified operation on files in the given\r\n directory and all subdirectories. Default \"dir\" is the\r\n current directory.\r\n /A Displays files with the hidden or system attributes. These\r\n files are omitted by default.\r\n /I Continues performing the specified operation even after errors\r\n have occurred. By default, COMPACT stops when an error is\r\n encountered.\r\n /F Forces the compress operation on all specified files, even\r\n those which are already compressed. Already-compressed files\r\n are skipped by default.\r\n /Q Reports only the most essential information.\r\n /EXE Use compression optimized for executable files which are read\r\n frequently and not modified. Supported algorithms are:\r\n XPRESS4K (fastest) (default)\r\n XPRESS8K\r\n XPRESS16K\r\n LZX (most compact)\r\n /CompactOs Set or query the system's compression state. Supported options are:\r\n query - Query the system's Compact state.\r\n always - Compress all OS binaries and set the system state to Compact\r\n which remains unless administrator changes it.\r\n never - Uncompress all OS binaries and set the system state to non\r\n Compact which remains unless administrator changes it.\r\n /WinDir Used with /CompactOs:query, when querying the offline OS. Specifies\r\n the directory where Windows is installed.\r\n filename Specifies a pattern, file, or directory.\r\n\r\n Used without parameters, COMPACT displays the compression state of\r\n the current directory and any files it contains. You may use multiple\r\n filenames and wildcards. You must put spaces between multiple\r\n parameters.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\compact.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "CompatTelRunner.exe-CB6CA75C8DE515340514D54DD2EB0E64": { "file_name": "CompatTelRunner.exe", "file_path": "C:\\Windows\\system32\\CompatTelRunner.exe", "hash_md5": "CB6CA75C8DE515340514D54DD2EB0E64", "hash_sha1": "D562D36F3F1AB5F1C96D6532DFDBEEDC12491CE1", "hash_sha256": "2967699A953D5690222655124FBB79ACCDBBE7714F7698FCADC1815B1684E81B", "hash_sha384": "5CBE00C1EE68C812EE1FAE702603AAC932788623D9E3C805D9A2ADB890A7655EF37650A26C2D7F3E8E3FC696A25E8762", "hash_sha512": "28470B803778FF7B8D4D8F9CE7BD971352B5881E21E7283EFDA5223A2ECD8F8BBF8DAF45088EA7D825F155ECC95809E246A6099FD073BC0BAF07046E295AC863", "hash_ssdeep": "3072:qm18wDYYRZVaVWELsqeW+arDGi9UkIHLLeDDAtwJ2H2NXd:q88wn3VaVMqeWY1k4WDDA6N", "hash_imp": "5E4D55883A5FB7A7D7CAB55A34B42708", "hash_pesha1": "F45336CFC6E2AFD609643AA2AE285DA231D93870", "hash_pe256": "F35C42CD3A7F2F5468C8F61857766FF55738A88B03A2F9455A2760F9F012A32E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Compatibility Telemetry", "meta_original_filename": "CompatTelRunner.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19645.1016 (WinBuild.160101.0800)", "meta_product_version": "10.0.19645.1016", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2967699a953d5690222655124fbb79accdbbe7714f7698fcadc1815b1684e81b/detection", "runtime_modules": [ "C:\\Windows\\system32\\CompatTelRunner.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "CompMgmtLauncher.exe-FF9690925244473ECC4C2E5B535B8599": { "file_name": "CompMgmtLauncher.exe", "file_path": "C:\\Windows\\system32\\CompMgmtLauncher.exe", "hash_md5": "FF9690925244473ECC4C2E5B535B8599", "hash_sha1": "14B1887A1979904AE2AEFB582BCBDBB33DF66A5A", "hash_sha256": "764AD199D40BFD87C0906470A816422ECDAA7CAFF7DF97592922B068FA9C5F40", "hash_sha384": "91B06E9726F88D28645FA864D692B72D7E02D585925B97D56ADBA97085846A7C7A26C5AA7C508FE5A36C027FD43E16F2", "hash_sha512": "096DEF64516A9268E388EB06CEAA34E0772D9AD041A5368F5F68036DBA3DC5F756E226A00BD6A8B5710B9A075ADD2849E180E68603430873685330A95D7802A1", "hash_ssdeep": "1536:PHsdhnqKTs6GHQm7cMvn3MuD4ptcD2e9lOo+vi6Uf:PMnnq25Gwm7cMv3p4ptcCe9co+Q", "hash_imp": "5C07F48325D782CDDABE04AA4F7F5B0B", "hash_pesha1": "B3ABD82ABA30E9678C03893E75B2AA432BB1C420", "hash_pe256": "A4AF3E4F731BF33178E2B415552770CE9BD16F6EDBB48F14E30262A22DD2EAA1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Computer Management Snapin Launcher", "meta_original_filename": "CompMgmtLauncher.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/764ad199d40bfd87c0906470a816422ecdaa7caff7df97592922b068fa9c5f40/detection", "children": "mmc.exe", "runtime_modules": [ "C:\\Windows\\system32\\CompMgmtLauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "CompPkgSrv.exe-35897B203D4E63EB8B94A7B969D6EF26": { "file_name": "CompPkgSrv.exe", "file_path": "C:\\Windows\\system32\\CompPkgSrv.exe", "hash_md5": "35897B203D4E63EB8B94A7B969D6EF26", "hash_sha1": "51E5CC550F4556D223DE4D0AA60DF0F93D1BFBFF", "hash_sha256": "EED9A14316D718146735FD2B3885992698113DB19F2048185B1DCC794640ACA3", "hash_sha384": "0EA7472B98FFEA24F475B6C66916FF4CE01F4296DC49FF1BDAD49B09EC87C379E3FE6E31FE032FD1E16145971F425978", "hash_sha512": "7A53F7336B1485A886F0A69782D7D0E5D86518308F57AEA9C1662C4DC0A4F62E0CD9F6AF1A3DB23F9E73479EEC88BE13BE895DCBD3F78653ADEBE34E157093D9", "hash_ssdeep": "3072:gfba3KVdg2migJueg2mnve3n+he6DyAY446aIUDk44koxRwc7MDMRyyP:gfO3IdLrEueGYn+Q6WAjGIwcAIRyy", "hash_imp": "A806C273820A599A220B6B95DB94A6ED", "hash_pesha1": "42350A0B2EDD53357E2E6328EE908999659252F1", "hash_pe256": "9A8F9C03E52A90EC2C554C65AC31B3393094956475395F42707FA6721B648F10", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Component Package Support Server", "meta_original_filename": "CompPkgSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/eed9a14316d718146735fd2b3885992698113db19f2048185b1dcc794640aca3/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\CompPkgSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "ComputerDefaults.exe-D25A9E160E3B74EF2242023726F15416": { "file_name": "ComputerDefaults.exe", "file_path": "C:\\Windows\\system32\\ComputerDefaults.exe", "hash_md5": "D25A9E160E3B74EF2242023726F15416", "hash_sha1": "27A9BB9D7628D442F9B5CF47711C906E3315755B", "hash_sha256": "7B0334C329E40A542681BCAFF610AE58ADA8B1F77FF6477734C1B8B9A951EF4C", "hash_sha384": "3C7A69579ECD5A4953FEE1EBEC0C9C752D268153093A0008BDA114225B93A9F1C6651D8997E8D84CD38F895525D14C87", "hash_sha512": "BAFAEE786C90C96A2F76D4BBCDDBBF397A1AFD82D55999081727900F3C2DE8D2EBA6B77D25C622DE0C1E91C54259116BC37BC9F29471D1B387F78AAA4D276910", "hash_ssdeep": "1536:DayE7ffgaxRF71ry9vmt486MypQKURDoq4OZZZLlCIibz:Y3ganFp4NpqRD68wbz", "hash_imp": "00B74CCF8A4820BD574431AE64ECF0C5", "hash_pesha1": "9028D08B690C437B26F6124EE97FBA31C01FF907", "hash_pe256": "11D8AC4CD8675361BE1C8A17A15F345C62C98C1C173D13EDC2396A6B3696BB57", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Set Program Access and Computer Defaults Control Panel", "meta_original_filename": "ComputerDefaults.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7b0334c329e40a542681bcaff610ae58ada8b1f77ff6477734c1b8b9a951ef4c/detection", "runtime_modules": [ "C:\\Windows\\system32\\ComputerDefaults.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "conhost.exe-B577C5F724544F0C677F9C51D9B7B481": { "file_name": "conhost.exe", "file_path": "C:\\Windows\\system32\\conhost.exe", "hash_md5": "B577C5F724544F0C677F9C51D9B7B481", "hash_sha1": "2976D388F210AFC42B5F7AEAFA58805BA7589B8F", "hash_sha256": "A9B3185119953859889B462FAF68D75DF365FF569EE1B9A5C5CE1C26CB443CB9", "hash_sha384": "A4281EB08A0B1D9F9867AD1BD4587D8A77ADAE147DE49D83E99815BADBC60BC0DF3F3C7ECAC0F9A537398F588A1B1BCB", "hash_sha512": "2BB6D97B3CDB0B9EF940F09CB23477A67FED2F7D6B0753CCDD6B7CA7DC55F23B9E25F89E9A674B946E47789BD0264DEB3780AB58F499D08D912D7BE7B73B7EB7", "hash_ssdeep": "12288:fS3UrwBJ7TR1WASnE6dQuiAfE9khVlnc3TsPLT4fscR:a3UcJ7TR1hx6W/94lc3TsPAfs0", "hash_imp": "AFFE8C3BE3BBE4F0AC2EF124256F372D", "hash_pesha1": "C39E665513ABD46298A54F16E4A22EDD1A74EB0D", "hash_pe256": "829DA05F36F82B32960DFFCA200DCB99D61305D643D08D724255783B0C85AF14", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Console Window Host", "meta_original_filename": "CONHOST.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a9b3185119953859889b462faf68d75df365ff569ee1b9a5c5ce1c26cb443cb9/detection", "output": "\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\nFINDSTR Searches for strings in files.\r\nFOR Runs a specified command for each file in a set of files.\r\nFORMAT Formats a disk for use with Windows.\r\nFSUTIL Displays or configures the file system properties.\r\nFTYPE Displays or modifies file types used in file extension\r\n associations.\r\nGOTO Directs the Windows command interpreter to a labeled line in\r\n a batch program.\r\nGPRESULT Displays Group Policy information for machine or user.\r\nGRAFTABL Enables Windows to display an extended character set in\r\n graphics mode.\r\nHELP Provides Help information for Windows commands.\r\nICACLS Display, modify, backup, or restore ACLs for files and\r\n directories.\r\nIF Performs conditional processing in batch programs.\r\nLABEL Creates, changes, or deletes the volume label of a disk.\r\nMD Creates a directory.\r\nMKDIR Creates a directory.\r\nMKLINK Creates Symbolic Links and Hard Links\r\nMODE Configures a system device.\r\nMORE Displays output one screen at a time.\r\nMOVE Moves one or more files from one directory to another\r\n directory.\r\nOPENFILES Displays files opened by remote users for a file share.\r\nPATH Displays or sets a search path for executable files.\r\nPAUSE Suspends processing of a batch file and displays a message.\r\nPOPD Restores the previous value of the current directory saved by\r\n PUSHD.\r\nPRINT Prints a text file.\r\n]0;C:\\Windows\\system32\\conhost.exe[?25h\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\nRENAME Renames a file or files.\r\nREPLACE Replaces files.\r\nRMDIR Removes a directory.\r\nROBOCOPY Advanced utility to copy files and directory trees\r\nSET Displays, sets, or removes Windows environment variables.\r\nSETLOCAL Begins localization of environment changes in a batch file.\r\nSC Displays or configures services (background processes).\r\nSCHTASKS Schedules commands and programs to run on a computer.\r\nSHIFT Shifts the position of replaceable parameters in batch files.\r\nSHUTDOWN Allows proper local or remote shutdown of machine.\r\nSORT Sorts input.\r\nSTART Starts a separate window to run a specified program or command.\r\nSUBST Associates a path with a drive letter.\r\nSYSTEMINFO Displays machine specific properties and configuration.\r\nTASKLIST Displays all currently running tasks including services.\r\nTASKKILL Kill or stop a running process or application.\r\nTIME Displays or sets the system time.\r\nTITLE Sets the window title for a CMD.EXE session.\r\nTREE Graphically displays the directory structure of a drive or\r\n path.\r\nTYPE Displays the contents of a text file.\r\nVER Displays the Windows version.\r\nVERIFY Tells Windows whether to verify that your files are written\r\n correctly to a disk.\r\nVOL Displays a disk volume label and serial number.\r\nXCOPY Copies files and directory trees.\r\nWMIC Displays WMI information inside interactive command shell.\r\n\r\nFor more information on tools see the command-line reference in the online help.\r\n[?25h", "runtime_modules": [ "C:\\Windows\\system32\\conhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "consent.exe-E3D1802FA8697E9E761F6D501E45BF0A": { "file_name": "consent.exe", "file_path": "C:\\Windows\\system32\\consent.exe", "hash_md5": "E3D1802FA8697E9E761F6D501E45BF0A", "hash_sha1": "C8B5B30FFEE0EFC22A2B6F8E81A9CC9C97A1ED43", "hash_sha256": "BAF527D2F09EC003BB3E399347056A3EE2AD60F4E07E4010CE858ECCE697EC75", "hash_sha384": "45DE5763DEA25181F69A5CE51BA300EA7D1E24A18DD02F1234D1DE0DB51C552CAF0677341864A31D34082476D5F53E6C", "hash_sha512": "B96A0B98226E47F322A62922952A6DACD821D19E8DB070B14E238032C351B2656CC494054C35477428955F6D52E88F62CF8555EE4CAE70EB651FBF3DC51373AD", "hash_ssdeep": "3072:C8m2NJJZ3SiT6P6Yfdj+6ir9ORhsjz+gE:C8mAFrTrYfdj+6nROjz6", "hash_imp": "ACAFC223D6C3FCAE537D9630A0021EFD", "hash_pesha1": "25EDAA786E00B3316CA4CF31F8E21A583E41A986", "hash_pe256": "F7D7C6D2226A17282149496B21EB29F9125BDC2B7B112C25D0A8F9B505DF1477", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Consent UI for administrative applications", "meta_original_filename": "consent.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/baf527d2f09ec003bb3e399347056a3ee2ad60f4e07e4010ce858ecce697ec75/detection", "runtime_modules": [ "C:\\Windows\\system32\\consent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\SYSTEM32\\samcli.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\SYSTEM32\\netutils.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\SYSTEM32\\Amsi.dll", "C:\\Windows\\SYSTEM32\\WMsgAPI.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\MsCtfMonitor.DLL", "C:\\Windows\\SYSTEM32\\MSIMG32.dll", "C:\\Windows\\SYSTEM32\\WINSTA.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\SYSTEM32\\WTSAPI32.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "control.exe-3011923664DA91ED45B0FA6AE852DD1A": { "file_name": "control.exe", "file_path": "C:\\Windows\\system32\\control.exe", "hash_md5": "3011923664DA91ED45B0FA6AE852DD1A", "hash_sha1": "DA28F05F804E2E02EF2594B899B51976E745455A", "hash_sha256": "54D9F98F36BC5511D281318B8022002F74AD30B6383696E861220E15EE68E5A3", "hash_sha384": "98AE8CC78B1E74D2F0A6CD6B5F32567B80B3C2092E0682E81E4418BD2407EAE3C13E8681B9B577B522C5E5E9EDECBA6A", "hash_sha512": "F09F07F6285A7ED8AB6066F95EC4C770378D40282D41ED65D3CC7DE701EC73506053BADE2AF0D34C98DF8E6CEF4CFBB77A22B6C63B1C179E27FF53D2BC0A6AF3", "hash_ssdeep": "3072:tCPVV7dL01mNUug7Sp5+1k12b/Af885RK:tCtVZi7+5+1kf15", "hash_imp": "ED7ECF5DCE55D515F7FE036FCAEBFF1A", "hash_pesha1": "191F24AF6F8B7D227ACD9944247824BBA5A334E4", "hash_pe256": "9DD0AB521FF0F56FDEAD107709DB7A598F63AB9C0F9FC09205561FC95011FFE9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Control Panel", "meta_original_filename": "CONTROL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/54d9f98f36bc5511d281318b8022002f74ad30b6383696e861220e15ee68e5a3/detection", "runtime_modules": [ "C:\\Windows\\system32\\control.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll" ] }, "convert.exe-7428F525CBC2AB967913609B11125506": { "file_name": "convert.exe", "file_path": "C:\\Windows\\system32\\convert.exe", "hash_md5": "7428F525CBC2AB967913609B11125506", "hash_sha1": "1C5D5E33612B2983FAD12B516DF5CD7EE192C16B", "hash_sha256": "9678122ABE2FFEDA75912DA16B188C755B7517EA1DA8E51BBA38934F2A5D3252", "hash_sha384": "0F9E555EA227314A863CB9F3AF987EB01B889D844B820819DB08D5DA939E3E75986452BA711AC1C269CDB2A1FFF27458", "hash_sha512": "1B812A859CEEA40988BBD62FEF899AA1CD17F5CFD7A6FF034F1484EF0D654D324C4C89EEACBFAAC966148372D38F24A1DC19967B5C7AF80C800982D96EE73C44", "hash_ssdeep": "384:bOR9OuS0dzglLXebaxQSyE8mtP1wx2Ck8dRwKRSnBPNjWCqW:bOyN0dMl7eWxVyETm2SSBPz", "hash_imp": "D950A0891AA3651B49F0BAFE5E2CEF68", "hash_pesha1": "DD0F83388645B68947904DD0A143A5BF87515C3A", "hash_pe256": "A536DFA4FFBAC26CC9862FC2F5BE6EF3DFEEE0C7F4C8862037A49930FE7EDDAC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File System Conversion Utility", "meta_original_filename": "CONVERT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/9678122abe2ffeda75912da16b188c755b7517ea1da8e51bba38934f2a5d3252/detection", "output": "Converts a FAT volume to NTFS.\r\n\r\nCONVERT volume /FS:NTFS [/V] [/CvtArea:filename] [/NoSecurity] [/X]\r\n\r\n\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name.\r\n /FS:NTFS Specifies that the volume will be converted to NTFS.\r\n /V Specifies that Convert will be run in verbose mode.\r\n /CvtArea:filename\r\n Specifies a contiguous file in the root directory\r\n that will be the place holder for NTFS system files.\r\n /NoSecurity Specifies that the security settings on the converted\r\n files and directories allow access by all users.\r\n /X Forces the volume to dismount first if necessary.\r\n All open handles to the volume will not be valid.\r\n", "error": "Invalid drive specification.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\convert.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "convertvhd.exe-20C01F0B5F37FC672746A201F339CAAD": { "file_name": "convertvhd.exe", "file_path": "C:\\Windows\\system32\\convertvhd.exe", "hash_md5": "20C01F0B5F37FC672746A201F339CAAD", "hash_sha1": "4B2627479BDC9A74C51904F5CF9B77F50B05B0AB", "hash_sha256": "BA2BDCA7835C6CD58700F2C50E8B2054A916C194BC2A4807C53A6D7B5D8B625F", "hash_sha384": "F59420320E5187A94B7EE105083714EA92CCC5B0442FF8B99C46D75610AE81EB3040C537859FAA37B42918CF75E8DBD9", "hash_sha512": "33D65BC2862AA375E0F5BD7B79FF4AE3F088DB320829E02356C057F884A24CA41E85A6CA3F54C00352EFF8BC3EFB028670493672D62692CC9A44104B3D7B1329", "hash_ssdeep": "3072:stUQk+kk1k62oPeH0VbBe9EaA/Y1CRlAe1nczSKLc2ohZd6:stjkVk1YIQlA/vIe1nczSac25", "hash_imp": "8EC57BBA22E989550ED815A52461CEDD", "hash_pesha1": "A6F720F0F52942F027DBC677FD49FD445162404E", "hash_pe256": "2280046A72586F4E08F7AAE8ADA7FBFE95419D81CD0E3916BC5AC7C581765A68", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "VHD Conversion Tool", "meta_original_filename": "ConvertVhd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ba2bdca7835c6cd58700f2c50e8b2054a916c194bc2a4807c53a6d7b5d8b625f/detection", "output": "VHD Conversion Tool [Version 1.00]\r\nCopyright (C) 2017 Microsoft Corporation. All rights reserved.\r\n", "error": "onecore\\vm\\dv\\storage\\vhd\\btt\\tools\\convertvhdmodule.cpp(112)\\convertvhd.exe!00007FF7BBD38732: (caller: 00007FF7BBD3928A) Exception(1) tid(1250) 80070057 The parameter is incorrect.\r\r\n Msg:[\r\n\r\nUSAGE:\r\nconvertvhd.exe -source <filepath> -destination <filepath> [-btt] [-toPMem]\r\nconvertvhd.exe -sourceToken <file handle> -destinationToken <file handle> [-btt] [-toPMem]\r\n\r\n] \r\nonecore\\vm\\common\\vml\\VmModules.h(1492)\\convertvhd.exe!00007FF7BBD534E6: (caller: 00007FF7BBD51CAC) LogHr(1) tid(1250) 80070057 The parameter is incorrect.\r\r\n Msg:[onecore\\vm\\dv\\storage\\vhd\\btt\\tools\\convertvhdmodule.cpp(112)\\convertvhd.exe!00007FF7BBD38732: (caller: 00007FF7BBD3928A) Exception(1) tid(1250) 80070057 The parameter is incorrect.\r\r\n Msg:[\r\n\r\nUSAGE:\r\nconvertvhd.exe -source <filepath> -destination <filepath> [-btt] [-toPMem]\r\nconvertvhd.exe -sourceToken <file handle> -destinationToken <file handle> [-btt] [-toPMem]\r\n\r\n] \r\n] \r\n", "runtime_modules": [ "C:\\Windows\\system32\\convertvhd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "coredpussvr.exe-701AF7D884B07E69D1FCB75E193C3FB4": { "file_name": "coredpussvr.exe", "file_path": "C:\\Windows\\system32\\coredpussvr.exe", "hash_md5": "701AF7D884B07E69D1FCB75E193C3FB4", "hash_sha1": "D0A2B7E929AB3CD93E8712EC81F4CF724312908C", "hash_sha256": "3478AD525FE16EF4D7742F547C45D4FCD9046378B19ECCE963606E0392308209", "hash_sha384": "3900662B457133CE0A689BBE674D17268517D905053AE99E23FDEDCE1A98206451BC7D57F8153346D155198901176494", "hash_sha512": "BB77A8579C1AF1605157B9471892980FD7F709EB38F3BB087E3992BB9D68A05AD919772ED5362DD1E7FA9470A899EE8F4F28543DE0BFB0CD4D80E627664A1CCA", "hash_ssdeep": "1536:QsPD9VTdjy5KbrwHDGj8r37lQU35o942LQm0o+2Q:QsblmKbrNYr37Oiz2LTj+l", "hash_imp": "16F602B525E407B740EE990577004CF7", "hash_pesha1": "BF7FE4747CD426C8604A7C92EBA0D9185773BFCA", "hash_pe256": "D9EA9D1446657D0987D9490FCBCA7A91E0EA5417C0D9FC8D00771DA9E30EEEFD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "coredpussvr.exe", "meta_original_filename": "coredpussvr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3478ad525fe16ef4d7742f547c45d4fcd9046378b19ecce963606e0392308209/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\coredpussvr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "CredentialEnrollmentManager.exe-54798227D5409CB924DFD28EB740A1D4": { "file_name": "CredentialEnrollmentManager.exe", "file_path": "C:\\Windows\\system32\\CredentialEnrollmentManager.exe", "hash_md5": "54798227D5409CB924DFD28EB740A1D4", "hash_sha1": "4C76A5FC4EB2C281413A0FBDA7A48F7CE1BE420A", "hash_sha256": "F3896F6F5F51061AC47687AF886D3E8170CEF75D221FA2E4FAC2368DF51990DE", "hash_sha384": "CBFEE836B5E98E5532DBC0A748002A58559E2E9C6B2600716C374C0F1E012D4D2FEE84C6CFC507965CD9A6062F7D7DA3", "hash_sha512": "24CDC2B9C69487B83281119794A646CAD1FD06A1B0F9F97D81E8FA483E9076ADFF73B5C30B258A0F27EA39E63D512E0773D87D6A02766F23EB89A26E9E912DAE", "hash_ssdeep": "6144:bNKYFwqpNUuRNF86Ti1AaSDfH/7U0hN4tH:MY2qDRvK1AvTTDP", "hash_imp": "B2FF13828E34C14FED8546A032241FA2", "hash_pesha1": "813D931DF883ADB5924B9D3C951CA2FC440A215C", "hash_pe256": "96109A8DD8D7AF36879D12887E97F258364D1974CBE0B4450A2469AC2914E9FB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Enrollment Manager", "meta_original_filename": "CredentialEnrollmentManager.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f3896f6f5f51061ac47687af886d3e8170cef75d221fa2e4fac2368df51990de/detection", "runtime_modules": [ "C:\\Windows\\system32\\CredentialEnrollmentManager.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\SspiCli.dll" ] }, "CredentialUIBroker.exe-A2FEFF4D52130BB5701BBDE8EAE85235": { "file_name": "CredentialUIBroker.exe", "file_path": "C:\\Windows\\system32\\CredentialUIBroker.exe", "hash_md5": "A2FEFF4D52130BB5701BBDE8EAE85235", "hash_sha1": "EE6B7F33042A2A6AA6FEC6FFFC4392737E1E8CD2", "hash_sha256": "13B403048599690A2C7D261E9CA44033F214F2A92A8C45E07750E32CA4038735", "hash_sha384": "FE61D0FC18FD524E8CC9F04FD64FF6E5A514C31196096C73C602601EC56B61385F812AD7BCBEC7912815DB228D11E265", "hash_sha512": "FD42631729335A219F6786E077B199F1994802D0A1AAC533D53401F3C4EFBEE6856C1BABD40D73C6BC8B3A6B5A3CC7C049010C938A19CF6175458BA808C9CBBF", "hash_ssdeep": "3072:Z36iH1TNc9R52M2dOqusS/eX4oRSIeWRLTF9oA1:16iHRNes1X4A/d", "hash_imp": "E0CC4D4881448DD8FF9B5686D594DF7A", "hash_pesha1": "83522850AB579BA0573C08FBC0598AE273B44791", "hash_pe256": "9D7A0D71744A98FB4A30C855C33ED15E50A5C62FFC76DFD39B08917314DAA5AF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Manager UI Host", "meta_original_filename": "CredentialUIBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/13b403048599690a2c7d261e9ca44033f214f2a92a8c45e07750e32ca4038735/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\CredentialUIBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ] }, "credwiz.exe-19FFB4C1B2042DEF14EC20365CBE0E7F": { "file_name": "credwiz.exe", "file_path": "C:\\Windows\\system32\\credwiz.exe", "hash_md5": "19FFB4C1B2042DEF14EC20365CBE0E7F", "hash_sha1": "3C0E69D8EC422545438FC335CFA26CF18579264B", "hash_sha256": "DD73D0ADBEDF9C251C055081279CF152E3E84197F91024474EFD4D23FAB3C6C3", "hash_sha384": "68C612F85B358BA7805EB378EEB8B39F2BE0CDB90A8F03EEB0E36AC4CC81AD9643BB3D4C85FA95749B72C39BA6BE6A1D", "hash_sha512": "F973C5C4FC586CC6C5919FBF0DA4F136F6B70CE42A02871FA5D50E883B6E5113B5835508CBAC05CAE47E6778806D2EE6C54DC2553A471C00562D593E23F6C119", "hash_ssdeep": "768:Ten/md0ztQCEzuAngPhAcgXc8lgEflVcTA9T9xZF+5:4/mdWez9cunlg8lVcTAbxZF+", "hash_imp": "1DD00699999764F96356FE23CCDE82BD", "hash_pesha1": "ED4B10B38695C943312932483F1AC180176DE385", "hash_pe256": "52C2C38D722745A251DB52A15D7272E035B5E31B6A69A24D1FA916A05508E9DD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Backup and Restore Wizard", "meta_original_filename": "credwiz.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/dd73d0adbedf9c251c055081279cf152e3e84197f91024474efd4d23fab3c6c3/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\credwiz.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\credwiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\netutils.dll" ], "runtime_window_title": "Stored User Names and Passwords" }, "cscript.exe-B8454647EFC71192BF7B1572D18F7BD8": { "file_name": "cscript.exe", "file_path": "C:\\Windows\\system32\\cscript.exe", "hash_md5": "B8454647EFC71192BF7B1572D18F7BD8", "hash_sha1": "C3D511D4CF77C50D00A5264C6BB3AE44E5008831", "hash_sha256": "C69648B049E35FF96523C911737A0481D52DD06508A561094A4FA895A30A6535", "hash_sha384": "DB3D26C62456D1EA44E1B6C959539630F99F6B94BF8A0C567CDB1B4069554FE1E1C9C3BB1A8B1E1C78ECF1622B5A572A", "hash_sha512": "14FBAA714126804AF732ADA044D2B69BFBD1514BFA553D732D70025A6B3AB5CAC0CF05F5B1F0F2758418EFACDFE405E534C81C1145110B5E5401911379B8719E", "hash_ssdeep": "3072:M4j8J582MJlfBNezPd2002mm0R/EOhjULtqqM6IZxtt:Nj8olPfBNeT40DmmcUqqMfZh", "hash_imp": "2B44D2206B9865383429E9C1524F1CAC", "hash_pesha1": "4E424D3592615E730F73EDE98879B1A3B4914FEC", "hash_pe256": "B345760307FB0443F1CA9F07E81BBCD393094897BEF6F2C2B67F59B252065610", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Console Based Script Host", "meta_original_filename": "cscript.exe.mui", "meta_product_name": "Microsoft Windows Script Host", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.812.10240.16384", "meta_product_version": "5.812.10240.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c69648b049e35ff96523c911737a0481d52dd06508a561094a4fa895a30a6535/detection", "output": "Microsoft (R) Windows Script Host Version 5.812\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: CScript scriptname.extension [option...] [arguments...]\r\n\r\nOptions:\r\n //B Batch mode: Suppresses script errors and prompts from displaying\r\n //D Enable Active Debugging\r\n //E:engine Use engine for executing script\r\n //H:CScript Changes the default script host to CScript.exe\r\n //H:WScript Changes the default script host to WScript.exe (default)\r\n //I Interactive mode (default, opposite of //B)\r\n //Job:xxxx Execute a WSF job\r\n //Logo Display logo (default)\r\n //Nologo Prevent logo display: No banner will be shown at execution time\r\n //S Save current command line options for this user\r\n //T:nn Time out in seconds: Maximum time a script is permitted to run\r\n //X Execute script in debugger\r\n //U Use Unicode for redirected I/O from the console\r\n", "runtime_modules": [ "C:\\Windows\\system32\\cscript.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "csrss.exe-72565E7A0145E0657E586F6CF7696DC7": { "file_name": "csrss.exe", "file_path": "C:\\Windows\\system32\\csrss.exe", "hash_md5": "72565E7A0145E0657E586F6CF7696DC7", "hash_sha1": "11EBA7B1E26CC7D492A2C161AC48370811D0B01E", "hash_sha256": "6F1C9B4C187669BC0371260D121CAF48D65F829A9104C483BEFBD8FC0BED24F5", "hash_sha384": "F712FBA0FFF93FEC038D0AE8ED05C0C15BA26DAAABEF590F26793BB106947C261675DCE039A4DBD82731C20141E7BB2A", "hash_sha512": "E099AC9C0E6ED1FF8C3307F17CCB13A0306178679A3F7F5AB4B23699FAD859B3101243E2782771CA2B9B8FA2785437FBE71A7F04633F45732EB3E0C998603D20", "hash_ssdeep": "384:yXrUnRpvW5cnWeA0lqMDBRJsYoiFWSlGsxoA:gUfpK0ld1PsHPe", "hash_imp": "A96FA9912E09E361274AD77F1A4B252C", "hash_pesha1": "ACA5D490C63032FD7085EA14450BBA96B54FF230", "hash_pe256": "9B83649A6A0DA465D35C294C1BC23B7B488494233DF5E36CB79B4B4537999FA9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Client Server Runtime Process", "meta_original_filename": "CSRSS.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/6f1c9b4c187669bc0371260d121caf48d65f829a9104c483befbd8fc0bed24f5/detection" }, "ctfmon.exe-B625C18E177D5BEB5A6F6432CCF46FB3": { "file_name": "ctfmon.exe", "file_path": "C:\\Windows\\system32\\ctfmon.exe", "hash_md5": "B625C18E177D5BEB5A6F6432CCF46FB3", "hash_sha1": "ABB864E1911C59F785B0E1822701B9A5AB31BA1E", "hash_sha256": "484FED5F039F429ED933931BA607B7EFDA7D1A343D79CFAB60910E1843147012", "hash_sha384": "837300F82D6F1419643D369B7350C16D08BA4768D3875DA3D6BA3970C6A43DB01F9F18F70E20B7191454DF352D9D15C9", "hash_sha512": "D908BBDC26504B7BF6527C6F436D1BA0EDFD9D2D09981ECE411551BB3C5E1CFD046675A09A98438C5C59A2A4D9BA689FB0F1DD017190DF6705EA088F11CC0C7F", "hash_ssdeep": "96:09AOfIKFb3nPWsv+5g3U2QD6S1EswBm5R00hTTpTq6mmyJfLODJVpRKLsLEWhgWq:AX3DPWsD7DS1EswEnp5q6mmy1CMWhgW", "hash_imp": "6FD43544FB51C12382CAD7C88F550240", "hash_pesha1": "ADFB83DD927ED15B5AE5696F0A88D0422F86D373", "hash_pe256": "BF1AFF435CA010D8BF927C22E891E16682BF2148CF17D037FDA0DD75DE325671", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CTF Loader", "meta_original_filename": "CTFMON.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/484fed5f039f429ed933931ba607b7efda7d1a343d79cfab60910e1843147012/detection", "runtime_modules": [ "C:\\Windows\\system32\\ctfmon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\MsCtfMonitor.DLL", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\system32\\MSUTB.dll", "C:\\Windows\\system32\\WINSTA.dll" ] }, "cttune.exe-FA924465A33833F41C1A39F6221BA460": { "file_name": "cttune.exe", "file_path": "C:\\Windows\\system32\\cttune.exe", "hash_md5": "FA924465A33833F41C1A39F6221BA460", "hash_sha1": "801D505D81E49D2B4FFA316245CA69FF58C523C3", "hash_sha256": "DE2D871AFE2C071CF305FC488875563B778E7279E57030BA1A1C9F7E360748DA", "hash_sha384": "A2EE156DC6E3575D9754D3EBEA377B971D2B3ECE0D830D37BD50707F6F92ACCD0AE0DB77D39AF37B702A3BD9C047B48C", "hash_sha512": "EEF91316E1A679CC2183D4FE9F8F40B5EFA6D06F7D1246FD399292E14952053309B6891059DA88134A184D9BD0298A45A1BF4BC9F27140B1A31B9523ACBF3757", "hash_ssdeep": "1536:CRdy54O22tc9pXvadM5ZePHMtFiGVhaROQc9QHgA1OEpWpUEQIARmXPackKrAbZX:JVwpIM53iMKHgtRdPkkIX", "hash_imp": "A8201FB74C93028C6784684AEC5E29DB", "hash_pesha1": "373EC5011C80CCC9343E34569C7659E07D85B064", "hash_pe256": "E0B13E5D0ACA2606B2B0295B7BFE2ABDA211AAAC9E21BAF9F5C3E51B19221DD5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ClearType Tuner", "meta_original_filename": "CTTUNE.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/de2d871afe2c071cf305fc488875563b778e7279e57030ba1a1c9f7e360748da/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\cttune.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\cttune.exe.mun": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\cttune.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ], "runtime_window_title": "ClearType Text Tuner" }, "cttunesvr.exe-BB3C2749AAA5000BFD1612D81D910E14": { "file_name": "cttunesvr.exe", "file_path": "C:\\Windows\\system32\\cttunesvr.exe", "hash_md5": "BB3C2749AAA5000BFD1612D81D910E14", "hash_sha1": "C5846C4BE4F76AE8B62642EBA32F6D801D7613B3", "hash_sha256": "73FFE2D9F2E0083D61D62479C1292060FF16C584B6A2EE009B99177A163132CE", "hash_sha384": "5661AF37A66F9392C5F519AA4C8FE3073B28D3A3CCD5F06315970A222994DA9A61777A4D22502DDBDAD5C9D6C80F7D6B", "hash_sha512": "27C1952284D283EA873C46C7932196F08B84FC6D27BDA0DA71CE6587F0F2669E18EC8383D22903986CB0E3F8DC326EBE2E0D385CF24ABED48155D93C8D6E9478", "hash_ssdeep": "768:k7MYvnRpTPQSCNYbAyWjKIU/JODjci0XK3vGLn9rt8BscrF91Ftl1tdsI7okkJYi:Qx7mNYbAelGjci0XKuLn9jAF91Ftl1ts", "hash_imp": "B4869B44437954AFF623E907CAA503F1", "hash_pesha1": "777E74E3302432E8089B08507B4E37D2D8390D62", "hash_pe256": "AA7AC44635D39DB516FB6332CBF8785EA9C1C93E0FA2FD51C84C3FAAC93FF512", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ClearType Tuner", "meta_original_filename": "CTTUNESVR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/73ffe2d9f2e0083d61d62479c1292060ff16c584b6a2ee009b99177a163132ce/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\cttunesvr.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\cttunesvr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "curl.exe-1C3645EBDDBE2DA6A32A5F9FB43A3C23": { "file_name": "curl.exe", "file_path": "C:\\Windows\\system32\\curl.exe", "hash_md5": "1C3645EBDDBE2DA6A32A5F9FB43A3C23", "hash_sha1": "086F74A35D5AFED78AE50CF5586FAFFFB7845464", "hash_sha256": "0BA1C44D0EE5B34B45B449074CDA51624150DC16B3B3C38251DF6C052ADBA205", "hash_sha384": "CD03A66219C32C68588DB3DF8967461781692565778C303D14FCFD822BCA782408DEA0D7129D08119140355B280D5D2B", "hash_sha512": "CCC9534A454971DB0014BA0996D837A36CDA0B91DB32A93D73F17097825B1AB7C973601586D06C953BC79D2863C52C7DB0FB4D04E37F83581A27E1CF7284224B", "hash_ssdeep": "6144:2L6+FAKWJAdpfK92cy8u9I2enqjUifLfPxH7IzPyerjgvsA6E1P/qRSp:mVGUQ92PJjfzky0dE1P/qRSp", "hash_imp": "2447B641444AC52A5B600C8801CE3532", "hash_pesha1": "87CE7102A887A87E1D532DB20B295D0FBD5140D5", "hash_pe256": "AD9CB041995F0618F77FA6394EF4BC760D6F17DC74ED410CF97D34B7B7FCFCA3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "The curl executable", "meta_original_filename": "curl.exe", "meta_product_name": "The curl executable", "meta_company_name": "curl, https://curl.haxx.se/", "meta_file_version": "7.55.1", "meta_product_version": "7.55.1", "meta_language": "English (United States)", "meta_legal_copyright": " 1996 - 2017 Daniel Stenberg, <daniel@haxx.se>.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0ba1c44d0ee5b34b45b449074cda51624150dc16b3b3c38251df6c052adba205/detection", "output": "Usage: curl [options...] <url>\r\n --abstract-unix-socket <path> Connect via abstract Unix domain socket\r\n --anyauth Pick any authentication method\r\n -a, --append Append to target file when uploading\r\n --basic Use HTTP Basic Authentication\r\n --cacert <CA certificate> CA certificate to verify peer against\r\n --capath <dir> CA directory to verify peer against\r\n -E, --cert <certificate[:password]> Client certificate file and password\r\n --cert-status Verify the status of the server certificate\r\n --cert-type <type> Certificate file type (DER/PEM/ENG)\r\n --ciphers <list of ciphers> SSL ciphers to use\r\n --compressed Request compressed response\r\n -K, --config <file> Read config from a file\r\n --connect-timeout <seconds> Maximum time allowed for connection\r\n --connect-to <HOST1:PORT1:HOST2:PORT2> Connect to host\r\n -C, --continue-at <offset> Resumed transfer offset\r\n -b, --cookie <data> Send cookies from string/file\r\n -c, --cookie-jar <filename> Write cookies to <filename> after operation\r\n --create-dirs Create necessary local directory hierarchy\r\n --crlf Convert LF to CRLF in upload\r\n --crlfile <file> Get a CRL list in PEM format from the given file\r\n -d, --data <data> HTTP POST data\r\n --data-ascii <data> HTTP POST ASCII data\r\n --data-binary <data> HTTP POST binary data\r\n --data-raw <data> HTTP POST data, '@' allowed\r\n --data-urlencode <data> HTTP POST data url encoded\r\n --delegation <LEVEL> GSS-API delegation permission\r\n --digest Use HTTP Digest Authentication\r\n -q, --disable Disable .curlrc\r\n --disable-eprt Inhibit using EPRT or LPRT\r\n --disable-epsv Inhibit using EPSV\r\n --dns-interface <interface> Interface to use for DNS requests\r\n --dns-ipv4-addr <address> IPv4 address to use for DNS requests\r\n --dns-ipv6-addr <address> IPv6 address to use for DNS requests\r\n --dns-servers <addresses> DNS server addrs to use\r\n -D, --dump-header <filename> Write the received headers to <filename>\r\n --egd-file <file> EGD socket path for random data\r\n --engine <name> Crypto engine to use\r\n --expect100-timeout <seconds> How long to wait for 100-continue\r\n -f, --fail Fail silently (no output at all) on HTTP errors\r\n --fail-early Fail on first transfer error, do not continue\r\n --false-start Enable TLS False Start\r\n -F, --form <name=content> Specify HTTP multipart POST data\r\n --form-string <name=string> Specify HTTP multipart POST data\r\n --ftp-account <data> Account data string\r\n --ftp-alternative-to-user <command> String to replace USER [name]\r\n --ftp-create-dirs Create the remote dirs if not present\r\n --ftp-method <method> Control CWD usage\r\n --ftp-pasv Use PASV/EPSV instead of PORT\r\n -P, --ftp-port <address> Use PORT instead of PASV\r\n --ftp-pret Send PRET before PASV\r\n --ftp-skip-pasv-ip Skip the IP address for PASV\r\n --ftp-ssl-ccc Send CCC after authenticating\r\n --ftp-ssl-ccc-mode <active/passive> Set CCC mode\r\n --ftp-ssl-control Require SSL/TLS for FTP login, clear for transfer\r\n -G, --get Put the post data in the URL and use GET\r\n -g, --globoff Disable URL sequences and ranges using {} and []\r\n -I, --head Show document info only\r\n -H, --header <header/@file> Pass custom header(s) to server\r\n -h, --help This help text\r\n --hostpubmd5 <md5> Acceptable MD5 hash of the host public key\r\n -0, --http1.0 Use HTTP 1.0\r\n --http1.1 Use HTTP 1.1\r\n --http2 Use HTTP 2\r\n --http2-prior-knowledge Use HTTP 2 without HTTP/1.1 Upgrade\r\n --ignore-content-length Ignore the size of the remote resource\r\n -i, --include Include protocol response headers in the output\r\n -k, --insecure Allow insecure server connections when using SSL\r\n --interface <name> Use network INTERFACE (or address)\r\n -4, --ipv4 Resolve names to IPv4 addresses\r\n -6, --ipv6 Resolve names to IPv6 addresses\r\n -j, --junk-session-cookies Ignore session cookies read from file\r\n --keepalive-time <seconds> Interval time for keepalive probes\r\n --key <key> Private key file name\r\n --key-type <type> Private key file type (DER/PEM/ENG)\r\n --krb <level> Enable Kerberos with security <level>\r\n --libcurl <file> Dump libcurl equivalent code of this command line\r\n --limit-rate <speed> Limit transfer speed to RATE\r\n -l, --list-only List only mode\r\n --local-port <num/range> Force use of RANGE for local port numbers\r\n -L, --location Follow redirects\r\n --location-trusted Like --location, and send auth to other hosts\r\n --login-options <options> Server login options\r\n --mail-auth <address> Originator address of the original email\r\n --mail-from <address> Mail from this address\r\n --mail-rcpt <address> Mail from this address\r\n -M, --manual Display the full manual\r\n --max-filesize <bytes> Maximum file size to download\r\n --max-redirs <num> Maximum number of redirects allowed\r\n -m, --max-time <time> Maximum time allowed for the transfer\r\n --metalink Process given URLs as metalink XML file\r\n --negotiate Use HTTP Negotiate (SPNEGO) authentication\r\n -n, --netrc Must read .netrc for user name and password\r\n --netrc-file <filename> Specify FILE for netrc\r\n --netrc-optional Use either .netrc or URL\r\n -:, --next Make next URL use its separate set of options\r\n --no-alpn Disable the ALPN TLS extension\r\n -N, --no-buffer Disable buffering of the output stream\r\n --no-keepalive Disable TCP keepalive on the connection\r\n --no-npn Disable the NPN TLS extension\r\n --no-sessionid Disable SSL session-ID reusing\r\n --noproxy <no-proxy-list> List of hosts which do not use proxy\r\n --ntlm Use HTTP NTLM authentication\r\n --ntlm-wb Use HTTP NTLM authentication with winbind\r\n --oauth2-bearer <token> OAuth 2 Bearer Token\r\n -o, --output <file> Write to file instead of stdout\r\n --pass <phrase> Pass phrase for the private key\r\n --path-as-is Do not squash .. sequences in URL path\r\n --pinnedpubkey <hashes> FILE/HASHES Public key to verify peer against\r\n --post301 Do not switch to GET after following a 301\r\n --post302 Do not switch to GET after following a 302\r\n --post303 Do not switch to GET after following a 303\r\n --preproxy [protocol://]host[:port] Use this proxy first\r\n -#, --progress-bar Display transfer progress as a bar\r\n --proto <protocols> Enable/disable PROTOCOLS\r\n --proto-default <protocol> Use PROTOCOL for any URL missing a scheme\r\n --proto-redir <protocols> Enable/disable PROTOCOLS on redirect\r\n -x, --proxy [protocol://]host[:port] Use this proxy\r\n --proxy-anyauth Pick any proxy authentication method\r\n --proxy-basic Use Basic authentication on the proxy\r\n --proxy-cacert <file> CA certificate to verify peer against for proxy\r\n --proxy-capath <dir> CA directory to verify peer against for proxy\r\n --proxy-cert <cert[:passwd]> Set client certificate for proxy\r\n --proxy-cert-type <type> Client certificate type for HTTS proxy\r\n --proxy-ciphers <list> SSL ciphers to use for proxy\r\n --proxy-crlfile <file> Set a CRL list for proxy\r\n --proxy-digest Use Digest authentication on the proxy\r\n --proxy-header <header/@file> Pass custom header(s) to proxy\r\n --proxy-insecure Do HTTPS proxy connections without verifying the proxy\r\n --proxy-key <key> Private key for HTTPS proxy\r\n --proxy-key-type <type> Private key file type for proxy\r\n --proxy-negotiate Use HTTP Negotiate (SPNEGO) authentication on the proxy\r\n --proxy-ntlm Use NTLM authentication on the proxy\r\n --proxy-pass <phrase> Pass phrase for the private key for HTTPS proxy\r\n --proxy-service-name <name> SPNEGO proxy service name\r\n --proxy-ssl-allow-beast Allow security flaw for interop for HTTPS proxy\r\n --proxy-tlsauthtype <type> TLS authentication type for HTTPS proxy\r\n --proxy-tlspassword <string> TLS password for HTTPS proxy\r\n --proxy-tlsuser <name> TLS username for HTTPS proxy\r\n --proxy-tlsv1 Use TLSv1 for HTTPS proxy\r\n -U, --proxy-user <user:password> Proxy user and password\r\n --proxy1.0 <host[:port]> Use HTTP/1.0 proxy on given port\r\n -p, --proxytunnel Operate through a HTTP proxy tunnel (using CONNECT)\r\n --pubkey <key> SSH Public key file name\r\n -Q, --quote Send command(s) to server before transfer\r\n --random-file <file> File for reading random data from\r\n -r, --range <range> Retrieve only the bytes within RANGE\r\n --raw Do HTTP \"raw\"; no transfer decoding\r\n -e, --referer <URL> Referrer URL\r\n -J, --remote-header-name Use the header-provided filename\r\n -O, --remote-name Write output to a file named as the remote file\r\n --remote-name-all Use the remote file name for all URLs\r\n -R, --remote-time Set the remote file's time on the local output\r\n -X, --request <command> Specify request command to use\r\n --request-target Specify the target for this request\r\n --resolve <host:port:address> Resolve the host+port to this address\r\n --retry <num> Retry request if transient problems occur\r\n --retry-connrefused Retry on connection refused (use with --retry)\r\n --retry-delay <seconds> Wait time between retries\r\n --retry-max-time <seconds> Retry only within this period\r\n --sasl-ir Enable initial response in SASL authentication\r\n --service-name <name> SPNEGO service name\r\n -S, --show-error Show error even when -s is used\r\n -s, --silent Silent mode\r\n --socks4 <host[:port]> SOCKS4 proxy on given host + port\r\n --socks4a <host[:port]> SOCKS4a proxy on given host + port\r\n --socks5 <host[:port]> SOCKS5 proxy on given host + port\r\n --socks5-basic Enable username/password auth for SOCKS5 proxies\r\n --socks5-gssapi Enable GSS-API auth for SOCKS5 proxies\r\n --socks5-gssapi-nec Compatibility with NEC SOCKS5 server\r\n --socks5-gssapi-service <name> SOCKS5 proxy service name for GSS-API\r\n --socks5-hostname <host[:port]> SOCKS5 proxy, pass host name to proxy\r\n -Y, --speed-limit <speed> Stop transfers slower than this\r\n -y, --speed-time <seconds> Trigger 'speed-limit' abort after this time\r\n --ssl Try SSL/TLS\r\n --ssl-allow-beast Allow security flaw to improve interop\r\n --ssl-no-revoke Disable cert revocation checks (WinSSL)\r\n --ssl-reqd Require SSL/TLS\r\n -2, --sslv2 Use SSLv2\r\n -3, --sslv3 Use SSLv3\r\n --stderr Where to redirect stderr\r\n --suppress-connect-headers Suppress proxy CONNECT response headers\r\n --tcp-fastopen Use TCP Fast Open\r\n --tcp-nodelay Use the TCP_NODELAY option\r\n -t, --telnet-option <opt=val> Set telnet option\r\n --tftp-blksize <value> Set TFTP BLKSIZE option\r\n --tftp-no-options Do not send any TFTP options\r\n -z, --time-cond <time> Transfer based on a time condition\r\n --tls-max <VERSION> Use TLSv1.0 or greater\r\n --tlsauthtype <type> TLS authentication type\r\n --tlspassword TLS password\r\n --tlsuser <name> TLS user name\r\n -1, --tlsv1 Use TLSv1.0 or greater\r\n --tlsv1.0 Use TLSv1.0\r\n --tlsv1.1 Use TLSv1.1\r\n --tlsv1.2 Use TLSv1.2\r\n --tlsv1.3 Use TLSv1.3\r\n --tr-encoding Request compressed transfer encoding\r\n --trace <file> Write a debug trace to FILE\r\n --trace-ascii <file> Like --trace, but without hex output\r\n --trace-time Add time stamps to trace/verbose output\r\n --unix-socket <path> Connect through this Unix domain socket\r\n -T, --upload-file <file> Transfer local FILE to destination\r\n --url <url> URL to work with\r\n -B, --use-ascii Use ASCII/text transfer\r\n -u, --user <user:password> Server user and password\r\n -A, --user-agent <name> Send User-Agent <name> to server\r\n -v, --verbose Make the operation more talkative\r\n -V, --version Show version number and quit\r\n -w, --write-out <format> Use output FORMAT after completion\r\n --xattr Store metadata in extended file attributes\r\n", "error": " % Total % Received % Xferd Average Speed Time Time Time Current\r\n Dload Upload Total Spent Left Speed\r\n\r 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0\r 0 0 0 0 0 0 0 0 --:--:-- 0:00:01 --:--:-- 0", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\curl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "CustomInstallExec.exe-811DC50EA55C6DB8A04AE00754E16A0A": { "file_name": "CustomInstallExec.exe", "file_path": "C:\\Windows\\system32\\CustomInstallExec.exe", "hash_md5": "811DC50EA55C6DB8A04AE00754E16A0A", "hash_sha1": "4F06C78D47C6358FEF8DFA08F15B9C85C151483F", "hash_sha256": "4E3E318ED1C9A469C600E5C409FEE07D6E2751ED252019AEF3F280328D12ACF8", "hash_sha384": "FAD65623C41D26A14BCC4FF8D41F37337AD0C848F7913A6F320539491A9B19320EEF42F407429837134CFA56D3FC7240", "hash_sha512": "493CC31561C81D2A8A1DA0C5A217DD8EE272C4D0B55E7A1F9500B6CE7E86573FE25B93E87FED292CB1DE8F885DB6F282096E431CA8726E55A5118F79D437EF57", "hash_ssdeep": "1536:jojGI8jwL9/ApyiEcgPhpP5ysQ/d1+d1ttf2FGsp/IbGJGNVmnlc7DR/S33N:g0wLWPENpxysq1+d9fwlQGJGH0ODR/", "hash_imp": "932FD25545AE94A1CE9C7E00FD2ABDFC", "hash_pesha1": "D7C2B0DC61827869298D30C6CA8A9D55FFD1E64D", "hash_pe256": "FEAECBE0C7C38209C6BA73F1F03CBB0206E59376F3A2A221AB9506BEC7776BE7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Store Package Dependency Installer", "meta_original_filename": "CUSTOMINSTALLEXEC.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4e3e318ed1c9a469c600e5c409fee07d6e2751ed252019aef3f280328d12acf8/detection", "runtime_modules": [ "C:\\Windows\\system32\\CustomInstallExec.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll" ] }, "dasHost.exe-B3EEF1835548CEB20C282AAC9AA8E387": { "file_name": "dasHost.exe", "file_path": "C:\\Windows\\system32\\dasHost.exe", "hash_md5": "B3EEF1835548CEB20C282AAC9AA8E387", "hash_sha1": "A2AABF0B8AB7BA5BE9516B07DD79EBD2F67BC8F2", "hash_sha256": "88FD7E7E15D4C8B22C355ED56EDD45734F05A55A5BDC18EC1917583194ECD981", "hash_sha384": "F9F7B01914D2F82736316D97922AA5C73F5832A549365A198F71CCAACAEF3D1790B70880B9044202A2FEDAE25FDE5A15", "hash_sha512": "4D9BBFD1AB07C3D3042A793FE32C5832688FE63F8D1C79C59400FA3A54F53707A589EA8302B14FE481BD4171050D7B1F5A951EA0B58181FC34A32635AD21FB28", "hash_ssdeep": "1536:l3CuQWbPqWewIqfKVdpjrmN5qY2cLEj8zai1nrMJS2Co:IlqfKdpjrhY3LXzairaS1o", "hash_imp": "2FA3D006E774952B3F9DFF2DC941A2ED", "hash_pesha1": "CEC2983CE82AA8AF317C284C535CCAF60E652C52", "hash_pe256": "AFAA4963A7EC0834A4AE8DEAF8C384120677AACD8A67D3B5664F37108946EA7D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Association Framework Provider Host", "meta_original_filename": "dasHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/88fd7e7e15d4c8b22c355ed56edd45734f05a55a5bdc18ec1917583194ecd981/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\dasHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DataExchangeHost.exe-A672C1495A75898F0FF454CC082DCAA7": { "file_name": "DataExchangeHost.exe", "file_path": "C:\\Windows\\system32\\DataExchangeHost.exe", "hash_md5": "A672C1495A75898F0FF454CC082DCAA7", "hash_sha1": "DF1C3DFFA215B02505E78A06FB4BCC3B73823654", "hash_sha256": "839173A5B2A980EEA9D306D71F09876CECFE6B68EFBF4735182924BCDC275646", "hash_sha384": "EB6B6B28E24AF815757F0339CA1CF2ED13614747AF319018E473853EEC674CD8359FA352C8E390C4FFB0CC8CE650884C", "hash_sha512": "F98E089F837D49D2C6480DF9DF2AD798F78DB252C966FBAADE0CD1EBDDF962609913A0317801FD79702E4543373CB115035AC2487864D3FF2C7A5F6D35E91EC5", "hash_ssdeep": "3072:y7wCsV5mrZt+o6MJwW47PoVTgHYs+aQymHW7HJP2Ue/kXP3WmToiSHPIXG2aaawM:yo5mr56M2MczDqWXvjToiUK3bloZhiYx", "hash_imp": "B30B5DDD9DE2B3AD7DF270F23ADF7D33", "hash_pesha1": "70B597B1A791915F57F8F200A9D06D0954A86ECD", "hash_pe256": "266C7B830C4B2B0673256DA2DCFFC2A0E422790FF2A4434D17A33C70695F107D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Data Exchange Host", "meta_original_filename": "DataExchangeHost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/839173a5b2a980eea9d306d71f09876cecfe6b68efbf4735182924bcdc275646/detection", "runtime_modules": [ "C:\\Windows\\system32\\DataExchangeHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\system32\\DWrite.dll", "C:\\Windows\\system32\\TWINAPI.dll", "C:\\Windows\\system32\\dcomp.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\d2d1.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\system32\\dxgi.dll" ] }, "DataStoreCacheDumpTool.exe-3A9E15EFCA3C3292016DAB2E2DA1BA2F": { "file_name": "DataStoreCacheDumpTool.exe", "file_path": "C:\\Windows\\system32\\DataStoreCacheDumpTool.exe", "hash_md5": "3A9E15EFCA3C3292016DAB2E2DA1BA2F", "hash_sha1": "14AEA85AE97213E1AF0A83F24583E207E26D9A61", "hash_sha256": "49B08DCC3302B5E01C24FE3088BA30062C9790C2BFE0E020F5B288301C9F0521", "hash_sha384": "21A9E8B491775F03F3282C681AA51B73955EF0E74EC2D2E72FD621B0FDF66082332279A9A19EFE31A685A368C70C1851", "hash_sha512": "049560EF21A57C4F27597D78EC42ACCA26AA4EEF5A671EA5D36E1D98C089143F43F623BA7B6FBD254A4A0931FD6BA45F2CB618B9FB89D0F88BF310D029E4ACDA", "hash_ssdeep": "3072:flDDz46SxZtnoXIaDqU1pB2Sab5/pv9bRoHBLpFRyegyaol+nKn:fl3fqZUj1pB2Sab5/+jrmKn", "hash_imp": "C491B3BD905877FC1C844F4EF62647C9", "hash_pesha1": "1402A6B59AB0F9E93182228B61F55336961B76B9", "hash_pe256": "C5D895945208876B0EB050398C932BBE7D8ED33A7A728F15504879055A6BFC0D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/49b08dcc3302b5e01c24fe3088ba30062c9790c2bfe0e020f5b288301c9f0521/detection", "runtime_modules": [ "C:\\Windows\\system32\\DataStoreCacheDumpTool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DataUsageLiveTileTask.exe-E83264790C844DDBA19AD3B2E1FB4F80": { "file_name": "DataUsageLiveTileTask.exe", "file_path": "C:\\Windows\\system32\\DataUsageLiveTileTask.exe", "hash_md5": "E83264790C844DDBA19AD3B2E1FB4F80", "hash_sha1": "2F41BC4A75C246036C78FEF79450310D7F21E217", "hash_sha256": "058DAE5514918715F4C493601CCA3DC66A82F403E4DD9B6BC645F2379CDEEA3B", "hash_sha384": "136852894CB49FF9FC2DAE3FFEE845F2F755FBF8801E526A8E28A28ACC0E2D585BC405D7CD0CD2C0E66108AB28D2BECF", "hash_sha512": "FCFCF39E536C42CE0DDAFC613D9B612F9EA7304FC87037D296B811C0CDB1A95AFDD4D1A76AFD727348E9E8313DD0E58DD7700C6DA8790FAB87FB05AC7B1D02E4", "hash_ssdeep": "3072:fA/+5QQBFBhWVFpe/KqPyjVdEGNDo6HM5FMb5nluparY1aOcF695/0Q0TgyL:fIJwLovr0Oo66FMbFr+V+Tg", "hash_imp": "E0092B01A31FC3F70AD06E657DFDD32D", "hash_pesha1": "CB8EBD52A8C94E1F9E7770682880B97A957F07C3", "hash_pe256": "63DEFBC24122FC9DDC803F3547A3D9F402EEF19172EDC9DE579907FD1EB67F22", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Data Sense Live Tile Task", "meta_original_filename": "DataSenseLiveTileTask.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.84 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.84", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/058dae5514918715f4c493601cca3dc66a82f403e4dd9b6bc645f2379cdeea3b/detection", "children": [ "csrss.exe", "winlogon.exe" ], "runtime_modules": [ "C:\\Windows\\system32\\DataUsageLiveTileTask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\wwapi.dll", "C:\\Windows\\system32\\dusmapi.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\SYSTEM32\\wlanapi.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\profapi.dll" ] }, "dccw.exe-CB9374911BF5237179785C739A322C0F": { "file_name": "dccw.exe", "file_path": "C:\\Windows\\system32\\dccw.exe", "hash_md5": "CB9374911BF5237179785C739A322C0F", "hash_sha1": "3F4D3DD3D58C9F19DFBB414DED16969EBD9F74B9", "hash_sha256": "F7F3300B78148A34F6A35796C777A832B638B6D3193E11F4A37F45D4C6DFA845", "hash_sha384": "6250A1A04D4F201DC8DCB90F7E68330829236BA433F93A8D63A07196BEFEFF327069CEED0100F58382C5EA307CF04943", "hash_sha512": "9D47521538148B1823C0A17BAA86DDF932F06F46D5D8B63FA87B2CC220FB98CE3F933E32D771222937BB8E41C88030839D489D1CD78B062BFFEB2980DC6864BE", "hash_ssdeep": "1536:KCuqiEgeGHVfsbusCrUEGC4NffprtWSDPJJGGJpezQZkr/kbPftwiapzsf:KFqCeCCvcpkxfrHYt2twzpzsf", "hash_imp": "F9BC8BD9A4625C4E4D51D3742B03CA20", "hash_pesha1": "EDA4DD06EE0B269536D215A62324D723DB5824D1", "hash_pe256": "73F293C2D99D328F83FF1B74805A6E4A2075D3180F81D7CF36DE9EB325B79706", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Display Color Calibration", "meta_original_filename": "dccw.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/f7f3300b78148a34f6a35796c777a832b638b6d3193e11f4a37f45d4c6dfa845/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\dccw.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\dccw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\system32\\mscms.dll", "C:\\Windows\\system32\\dxva2.dll", "C:\\Windows\\System32\\combase.dll" ], "runtime_window_title": "Display Color Calibration" }, "dcomcnfg.exe-43BA7E3425A24539DC6A2D63F0ED5C22": { "file_name": "dcomcnfg.exe", "file_path": "C:\\Windows\\system32\\dcomcnfg.exe", "hash_md5": "43BA7E3425A24539DC6A2D63F0ED5C22", "hash_sha1": "E29601FF41DF796D996A4A5D32E5E654B24D1E95", "hash_sha256": "2300CC68C414B779D20899F2ACFBADA8A5D9E7D01A291DD0DF9898DD2CABB6BC", "hash_sha384": "5F75D913BEC394950CBDBC4097622FD2DDF43450CBE055F1EA1F6A108F942B67D31E75E2311EDEA6329CDA63E89FF0A3", "hash_sha512": "3E984204CD1D8AEFE5EC50E5106346CF85A138E6A74EAC146ECF0EF11F89F9267728249134CD4745DDD4682487733F89F00A01A188917DF8499F34BCA37426F2", "hash_ssdeep": "192:8wdkIEF+J7L4e2CeYWi4e7DJYvhT10XGK6lPf+W0EW:8wtEwJHpZ1WiJ71YN10XLW0EW", "hash_imp": "4C7F165DA8DA80935D61C0512A3469C1", "hash_pesha1": "B0A89E91B1AAB29200C8295098AC4A633644AEE5", "hash_pe256": "391B1165148792D26389D0EB80912E5AEE3E6024F74ED2ABE3FA13A4647EC8DC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+", "meta_original_filename": "DCOMCNFG.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2300cc68c414b779d20899f2acfbada8a5d9e7d01a291dd0df9898dd2cabb6bc/detection", "children": "mmc.exe", "runtime_modules": [ "C:\\Windows\\system32\\dcomcnfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "ddodiag.exe-85FEEE634A6AEE90F0108E26D3D9BC1F": { "file_name": "ddodiag.exe", "file_path": "C:\\Windows\\system32\\ddodiag.exe", "hash_md5": "85FEEE634A6AEE90F0108E26D3D9BC1F", "hash_sha1": "A7B1FA32FE7ED67BD51DEA438F2F767E3FEF0CA2", "hash_sha256": "99C63175504781E9278824D487DA082DA7C014E99F1024227AF164986D3A27C6", "hash_sha384": "F6820000F1373CF0201AAA3681062729AF08DB49D6E351C00BA53E7A769864086438B29D09F1FD8DD423D506E77DD8DB", "hash_sha512": "B81A3E1723A5180C5168CD7BB5181C631F4F57C59780BB82A502160B7874777F3EEF1EBE1B14F66C97F9F1A4721AF13B6FBCDFF2045C8563C18B5D12540953FF", "hash_ssdeep": "768:C+UDtsXkIdh/W7TNL5TGK/hc3aZkLmMgMaouZl6iAK5vjQf:904JINL5TGK/hc3aZkLmMgMaouZl6iPc", "hash_imp": "64A12EF7F6C9BB0EDB1C912884F52AB1", "hash_pesha1": "03DDC852BADA2ACD1A1734A88F3356EF8D4EFE34", "hash_pe256": "A7506CD3B33E9D6B349C791E350A36C9CCCAD2124D5C4395C99F1BE030490642", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DDODiag is a tool that collects Device Display Object (DDO) information from the system and logs it", "meta_original_filename": "DDODiag.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/99c63175504781e9278824d487da082da7c014e99f1024227af164986d3a27c6/detection", "runtime_modules": [ "C:\\Windows\\system32\\ddodiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\system32\\XmlLite.dll" ] }, "Defrag.exe-F7AC2F29879A0789A74F87012861A956": { "file_name": "Defrag.exe", "file_path": "C:\\Windows\\system32\\Defrag.exe", "hash_md5": "F7AC2F29879A0789A74F87012861A956", "hash_sha1": "7F690ED5DEED179A5B0834783A39C0035E9AFE5E", "hash_sha256": "D90DF37806E6F4A59D51B2D6FEDFDAF129436C4A0BC27DC271650B53B4848053", "hash_sha384": "D797295A1DCA8C8883E8D0B9A2483F4C5A5F2FDD6E438CE5090640D4E53220350B646FBBE90AD517E3F2EA79D20FEF5F", "hash_sha512": "93981E904171CAC7F050E277DF270B93984F7F85C5B64802112EE00668811EC61D4431FA9258999FBFB6AC104879751322ED51BA6CDDAF01DD800083D647798E", "hash_ssdeep": "3072:EswPgZs/8fsIlnK0tRrDrTkJKk/V5W86uvsb4C6c5Q3eSjlR+8qxLijgJyfFOG8l:P02o8PK+q+uJ3lRGOUZGKc4YFnwjCpW", "hash_imp": "9233D07CE8B477A0DE3511C3B6B4B24D", "hash_pesha1": "8FEF5F428B441A89487AD10189C8354F6769E4D2", "hash_pe256": "B270B551385887434E5B0D73E35213D49777F8B76E5A1E943F2CCCEF041C55E8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Defragmenter Module", "meta_original_filename": "Defrag.EXE.MUI", "meta_product_name": "Windows Drive Optimizer", "meta_company_name": "Microsoft Corp.", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corp.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d90df37806e6f4a59d51b2d6fedfdaf129436c4a0bc27dc271650b53b4848053/detection", "output": "\r\nPlease specify a volume to perform the operation on. (0x89000007)\r\n\r\nDefrag <Volumes> <Operations> [<Options>]\r\n\r\nVolumes:\r\n /C | /AllVolumes On each volume run only the preferred operations from\r\n the given list of operations.\r\n /E | /VolumesExcept <volume paths>\r\n Perform all the given operations on each volume except.\r\n those specified. If the exception list is empty, this\r\n behaves as /AllVolumes.\r\n volume paths Specifies the drive letter followed by a colon, mount point\r\n or volume name. More than one volume can be specified. Run\r\n all the given operations on each specified volume..\r\n\r\nOperations:\r\n /A | /Analyze Perform analysis.\r\n /B | /BootOptimize Perform boot optimization to increase boot performance.\r\n /D | /Defrag Perform traditional defrag (this is the default). On a tiered\r\n volume, traditional defrag is performed only on the Capacity\r\n tier.\r\n /G | /TierOptimize On tiered volumes, optimize files to reside on the appropriate\r\n storage tier.\r\n /K | /SlabConsolidate On thinly provisioned volumes, perform slab consolidation to\r\n increase slab usage efficiency.\r\n /L | /Retrim On thinly provisioned volumes, perform retrim to release free\r\n slabs. On SSDs perform retrim to improve write performance.\r\n /O | /Optimize Perform the proper optimization for each media type.\r\n /T | /TrackProgress Track progress of a running operation for a given volume. An\r\n instance can show progress only for a single volume. To see\r\n progress for another volume launch another instance.\r\n /U | /PrintProgress Print the progress of the operation on the screen.\r\n /V | /Verbose Print verbose output containing the fragmentation statistics.\r\n /X | /FreespaceConsolidate\r\n Perform free space consolidation, moves free space towards\r\n the end of the volume (even on thin provisioned volumes). On\r\n tiered volumes consolidation is performed only on the Capacity\r\n tier.\r\n\r\nOptions:\r\n /H | /NormalPriority Run the operation at normal priority (default is low).\r\n /I | /MaxRuntime n Available only with TierOptimize. Tier optimization would\r\n run for at most n seconds on each volume.\r\n /LayoutFile <file path>\r\n Available only with BootOptimize. This file contains the list\r\n of files to be optimized. The default location is\r\n %windir%\\Prefetch\\layout.ini.\r\n /M | /MultiThread [n] Run the operation on each volume in parallel in the background.\r\n For TierOptimize, at most n threads optimize the storage tiers\r\n in parallel. Default value of n is 8. All other optimizations\r\n ignore n.\r\n /OnlyPreferred When volumes are specified explicitly, defrag performs all\r\n the given operations on each specified volume. This switch\r\n lets defrag run only the preferred operations, from the\r\n given list of operations, on each specified volume.\r\n\r\nExamples:\r\n Defrag C: /U /V\r\n Defrag C: D: /TierOptimize /MultiThread\r\n Defrag C:\\mountpoint /Analysis /U\r\n Defrag /C /H /V\r\n", "runtime_modules": [ "C:\\Windows\\system32\\Defrag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "deploymentcsphelper.exe-B924F1A7DE5ED8331B3375A778B3FE38": { "file_name": "deploymentcsphelper.exe", "file_path": "C:\\Windows\\system32\\deploymentcsphelper.exe", "hash_md5": "B924F1A7DE5ED8331B3375A778B3FE38", "hash_sha1": "E62CE42735C05D2BB792AF2648DAEFC04DEA144C", "hash_sha256": "90E6DBDB4EB72ED9BCB4DCDC53F9A3CE3108297F84CE346B9AF04790A641CCCE", "hash_sha384": "59AC0C7A4F32AE5C1EE16B6DE21A8043D397486CC0DFD341692563436DD440BEC4033308EECFCF869E846BCB05C22F6E", "hash_sha512": "0002AC854E72866F10B4779C3F12CCA97554654463341E05632198C31F98833E176D12D11E665AC2684E32BAEC8B08EAD04FD05345D60D73839BDAF0ED311810", "hash_ssdeep": "768:P3a3ZvbIV9503ncUOf6VxDpl038yk5Akzaqd:P3aJDIL5GcUTt+omUH", "hash_imp": "677AB69463CC55E2E7CFC2A39BB04B46", "hash_pesha1": "88FB94B3E4FCF3E828DC682F884016458A3271A8", "hash_pe256": "81BC5B4D0F6CECDF15D2C8FAD23714A1E35063B8E6F9214EA98FA1BD75D9D5AA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/90e6dbdb4eb72ed9bcb4dcdc53f9a3ce3108297f84ce346b9af04790a641ccce/detection", "runtime_modules": [ "C:\\Windows\\system32\\deploymentcsphelper.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\WDSCORE.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\system32\\DismApi.DLL" ] }, "desktopimgdownldr.exe-AECDFE9512F9ABF601B5B439FAA2B64A": { "file_name": "desktopimgdownldr.exe", "file_path": "C:\\Windows\\system32\\desktopimgdownldr.exe", "hash_md5": "AECDFE9512F9ABF601B5B439FAA2B64A", "hash_sha1": "DD4E992C75E791094449FD52F646233C9AD06654", "hash_sha256": "1F336FA7255266CA76D26928DA7A2E0D4446F4CAE7F2041218BB2B166A97504D", "hash_sha384": "0607C22104D22394E41CCE21C6720AC85C5174926866B62FA4FF73FBD06704628BDF9EF52D71DDE6A44DE5A1C1931C49", "hash_sha512": "8DB2B94D74817B4B2B59B95CC7FEB9963CDCA372A8144634DFBB9258261B5AD6024B4BF37B48C73C51CEA417585FEFC1F45ED5080F4292AADEB7B6FC5878BCFB", "hash_ssdeep": "1536:OarCi80YW9i3P9fS+4mh1yUUt1Thu3SkJXDuMOI14uDLRS4Xe6KXQXQX+:nmYQhIt183SkJTuxuDdSkKAXb", "hash_imp": "4497ED51F6847EDEE6F31E6DE69B6378", "hash_pesha1": "0A683F53F11ED02115F415709AA60D2387EF9B0E", "hash_pe256": "3E3017729AE251D02AEE1DE4F0571C297BD06231A74A9CB4EFD45AA6EC62F1EF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "desktopimgdownldr.exe", "meta_original_filename": "desktopimgdownldr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/1f336fa7255266ca76d26928da7a2e0d4446f4cae7f2041218bb2b166a97504d/detection", "runtime_modules": [ "C:\\Windows\\system32\\desktopimgdownldr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DeviceCensus.exe-D1B722A188C84E5059765FA87E8C5F32": { "file_name": "DeviceCensus.exe", "file_path": "C:\\Windows\\system32\\DeviceCensus.exe", "hash_md5": "D1B722A188C84E5059765FA87E8C5F32", "hash_sha1": "05D74408A9899054FF5CEA5DAC98858062E3250E", "hash_sha256": "1041623963E1A109B80312CBFE4DC4544CBAC478C2EB2597CA040E1C78585A3E", "hash_sha384": "D6D2D21403EE174CAE34EA0ACD3F96C29E7E5B0251B4634F86E65D42922295499C1AF35F3C8E89B5B43FA816C74D0440", "hash_sha512": "4EB2B33C511A6623706D3A5A87394A25D80FBDA3AB82D7C49ABB4AD4D46A495B98D7A0EFAAE8F08E11984183F02E292A7922AA5E42BCDA7CC8AA2B71F908E730", "hash_ssdeep": "384:3hbaEPVaYmPw5gyLjuCrHGOl2R3qj37nec/gWJXn7fRUWbgWPc3228hDBRJwzJXj:RmEsxwGPcrl08Cc/giXn7nSih1PwVEI", "hash_imp": "69755EB5A4F06F0B816F7B23B33E44E8", "hash_pesha1": "6522AD1A8757A9F38761C7E46AFCE10B8A2FF8F2", "hash_pe256": "FAE15D42944FDAE6A68B1E5A83CCB5055F781C909009C3F44CAA668D4BA36E23", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Census", "meta_original_filename": "DeviceCensus.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19645.1016 (WinBuild.160101.0800)", "meta_product_version": "10.0.19645.1016", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1041623963e1a109b80312cbfe4dc4544cbac478c2eb2597ca040e1c78585a3e/detection", "runtime_modules": [ "C:\\Windows\\system32\\DeviceCensus.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\dcntel.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\system32\\logoncli.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\WINHTTP.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\UMPDC.dll" ] }, "DeviceCredentialDeployment.exe-F54BAB04869A6E4E6F0CB4D9DDC8C151": { "file_name": "DeviceCredentialDeployment.exe", "file_path": "C:\\Windows\\system32\\DeviceCredentialDeployment.exe", "hash_md5": "F54BAB04869A6E4E6F0CB4D9DDC8C151", "hash_sha1": "106919705D048981C710A22CA24267EB8B488FE0", "hash_sha256": "774B570C43254D32B769489270E6ADE3F39CCEB19985675339AEE06AFAF230CD", "hash_sha384": "3FEBFB2B6B7C055D429C41B35AAFB59E8344A3376CEEB8491146B56DA1E2D0216EBC155567A5DF8A0C2C7AA21CD4F844", "hash_sha512": "F6161861EE8AB963689378E13ED45082FD3FAF6F2D8C86683D5A30F79359E81A01637780E3C0CD35E47E73849DD748F08C33BA1D723E64BAB4BB174F0F60443D", "hash_ssdeep": "1536:LiYK2URh11/JU6bS3/NIQB2/21eCmRWqlGfT/AIAgg4fi2n:OxvRBb+NvB2/21e36f7AjggJ2n", "hash_imp": "DAA572DA142CF75B7362D0A1665A9C11", "hash_pesha1": "D47A0F0419EA7B89702CCF0B70997BC1A29C3223", "hash_pe256": "05F75FCE4F8B925AC0A17D7E1F62488A1EC585701DFB637D7A584C8775743BE6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "\"DeviceCredentialDeployment.exe\"", "meta_original_filename": "\"DeviceCredentialDeployment.exe\"", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/774b570c43254d32b769489270e6ade3f39cceb19985675339aee06afaf230cd/detection", "runtime_modules": [ "C:\\Windows\\system32\\DeviceCredentialDeployment.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DeviceEject.exe-ABCCD41E21586BB8A669E9B2F04CB65E": { "file_name": "DeviceEject.exe", "file_path": "C:\\Windows\\system32\\DeviceEject.exe", "hash_md5": "ABCCD41E21586BB8A669E9B2F04CB65E", "hash_sha1": "A7EB7AA8F2D2AC46CD942043853A84B95655C002", "hash_sha256": "14A69B5E05A8496EBCA246B356AB318A32DF3B563E4F375C6BBAE07E87B8DE51", "hash_sha384": "8605FE51AB2CC1AF442D743A4BDA674DD4D748D0F822C76313016EFF5A0039EAE0CA9B567F44E5A02C4B3A043A6BBD18", "hash_sha512": "80FA4154442E16A75338BD40FDCC3D39ED717153F7985A84D349BC117DCF359712DAFAEC2306ECC4CB1FA91BEE146F8664D53164AAE718D201F4CC7C0E61DD95", "hash_ssdeep": "384:bBtZ6SEFik4imsCqHJEPH6cHsOz8q0np8EMUWD5ir0TYWywWpJY0ehA/9gnl0:bBtZ6VQQEPUS8VuEMX5/M7JYQ/9gnl0", "hash_imp": "2E7F5CD72D55290932813BE557479C8F", "hash_pesha1": "857CF762DE5A06527EF04C58A2AE6F13D1D00677", "hash_pe256": "FB024B32BD2F3FF25E5D76BB2EE2334FD5ADE2864978BFE09787DDA398117A46", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Eject Device", "meta_original_filename": "DeviceEject.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/14a69b5e05a8496ebca246b356ab318a32df3b563e4f375c6bbae07e87b8de51/detection", "runtime_modules": [ "C:\\Windows\\system32\\DeviceEject.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "DeviceEnroller.exe-D9056CA8B40C5BE905683BD83165DBEF": { "file_name": "DeviceEnroller.exe", "file_path": "C:\\Windows\\system32\\DeviceEnroller.exe", "hash_md5": "D9056CA8B40C5BE905683BD83165DBEF", "hash_sha1": "8D5010F45C8C112A6261B5C8B9393DC903CE42ED", "hash_sha256": "37791F628DF0DA25B5D3CCB45B150888A7C1B00635F91CB73C6B7184D8F888BE", "hash_sha384": "41DAFDA48772788F034C10ECA080D1DED1257CE22BF1C942EEDD5B15CF9ECCF96F322CF10B7CE197497CBBC492A1D84C", "hash_sha512": "6905D3E7673A7192E51CD4DE811A4155FBDCB0B8033DF8628AF1C72E9CAB5D924E8DDA48BC781B67358E086C53F14B90B4356C13BA8E3F3A5517652E788A05C0", "hash_ssdeep": "6144:kbpsCsMoncdv372Fhbg2Jjlz3Y4GUDs6k/r0L7HZUzZCkX1Ek4:esCsy3yLbTJjBY4GUo5rA5UhX1Ek", "hash_imp": "4C5FF3E49D0CFA853B183D09EA0613F4", "hash_pesha1": "4343ED629CC692913108B36DDDF853CA2849CDED", "hash_pe256": "70071534E6E1952062C99C6632E877620D9869FF547C5516BAEFFAFC27DD2AB2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "API for MDM Enrollment", "meta_original_filename": "deviceenroller.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/37791f628df0da25b5d3ccb45b150888a7c1b00635f91cb73c6b7184d8f888be/detection", "runtime_modules": [ "C:\\Windows\\system32\\DeviceEnroller.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\dmEnrollEngine.DLL", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\system32\\CRYPTSP.dll", "C:\\Windows\\system32\\iri.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\system32\\UMPDC.dll", "C:\\Windows\\system32\\dmenterprisediagnostics.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\cfgmgr32.dll" ] }, "DevicePairingWizard.exe-D0E40A5A0C7DAD2D6E5040D7FBC37533": { "file_name": "DevicePairingWizard.exe", "file_path": "C:\\Windows\\system32\\DevicePairingWizard.exe", "hash_md5": "D0E40A5A0C7DAD2D6E5040D7FBC37533", "hash_sha1": "B0EABBD37A97A1ABCD90BD56394F5C45585699EB", "hash_sha256": "2ADAF3A5D3FDE149626E3FEF0E943C7029A135C04688ACF357B2D8D04C81981B", "hash_sha384": "ADFFB34CE2A740CCA7F88B6A8CE98F58294739B398065474DD87580EAA2EB2CDA384EE307F1361548809EC188804140B", "hash_sha512": "1191C2EFCADD53B74D085612025C44B6CD54DD69493632950E30ADA650D5ED79E3468C138F389CD3BC21EA103059A63EB38D9D919A62D932A38830C93F57731F", "hash_ssdeep": "1536:UgTdAN6wPYZucq7WPXTsQ5xSjBxrzSj11nhy0ohqZ3qOTU:v26wwZuX+X4USjBxfSj11o0oRoU", "hash_imp": "048D96A843A6DF20276E268A873746A7", "hash_pesha1": "032BA3D5A498B3B4B66D44DA59A55F562BCEEFCB", "hash_pe256": "069FAF50AC58DEFDA1ECDCFE2CA585259BB0907FD574E033D0BBE5BBDCC28379", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Pairing Application", "meta_original_filename": "DevicePairing.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2adaf3a5d3fde149626e3fef0e943c7029a135c04688acf357b2d8d04c81981b/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\DevicePairing.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\DevicePairing.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\DevicePairingWizard.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\OLE32.dll" ], "runtime_window_title": "Add a device" }, "DeviceProperties.exe-02C5A4C5A452E248F805186B8BF41BF7": { "file_name": "DeviceProperties.exe", "file_path": "C:\\Windows\\system32\\DeviceProperties.exe", "hash_md5": "02C5A4C5A452E248F805186B8BF41BF7", "hash_sha1": "6D7E61D837A2E96A7168649D749AECF393CA7788", "hash_sha256": "15522B3B263D5F4A88A61162033DAD8286D601985FD13EDF04FE8E7F5E54AC14", "hash_sha384": "4BE2DBAD283E78EE957742E9956FB6BF3EE1BE4001D92E4AFEA7F50AC844BBACA0564A642185D77B7499328DBBCB0D93", "hash_sha512": "8E2DE7A454209E1BFDC8CF1FFE6A822EDD00608E0D1CF68C378BDE7FE5502A7F3DFAB02A8A29FDE8007BC59E1F57AB513D9DA92150676DFECBC173DA66CBD57F", "hash_ssdeep": "1536:ZALNf/2y5nNWLJpBpTybQ74i6u0dw9Wegi85mChdlzwCxi65H:ZAJ/55NOFpTyIcuz9WzF4Chdlzri69", "hash_imp": "987DCEE8E6AD88968255DA46F110A7CB", "hash_pesha1": "60832493F98B9F8446F35354515A723EF8E8639C", "hash_pe256": "256A93803CC1F3A8F7804C50E7CC1A7A5B6C226734C510D1AE106824A46DA8ED", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Properties", "meta_original_filename": "DeviceProperties.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/15522b3b263d5f4a88a61162033dad8286d601985fd13edf04fe8e7f5e54ac14/detection", "runtime_modules": [ "C:\\Windows\\system32\\DeviceProperties.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "DFDWiz.exe-41ABE514F48858221260F689DC214B3A": { "file_name": "DFDWiz.exe", "file_path": "C:\\Windows\\system32\\DFDWiz.exe", "hash_md5": "41ABE514F48858221260F689DC214B3A", "hash_sha1": "9A9942C909075C9530E568BE74E904F0C3A40298", "hash_sha256": "548A3C7EC9AD1BB63F6CC21F4AE2A3B2317EFAD5B02031F542A18E3132022972", "hash_sha384": "35543E3A132FB2762702D447C23B39A16AF11BD220E04E5CAE19948A9575F86C44C514484BF4BF29BE51E226203F9347", "hash_sha512": "5C3A25796EAA63ACCD6439F8EC80CDC26ABA9528D39AA1525D74672006FA8DF8725B97E3EA492E380C9096644DB8AD49F298C2B7FF17FC9216EE6878FA1134F5", "hash_ssdeep": "768:hP28j6PltChSOgjp//K50or70wrIOgdUFwLoVhoTWMpVIjaCb6wJUjO2wth1R:0nPBB5C5r70wc1GwURMjsb6mxT", "hash_imp": "E513C960F7D5AA8D43E2A5AA898DD995", "hash_pesha1": "EDB5C04B3798BD270DFB14F4EAFCD0FBB979BB08", "hash_pe256": "86DD5F9D6CCDED169F797B722D61D433BFADEC947969208453CC212C50DAF22B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Disk Diagnostic User Resolver", "meta_original_filename": "DFDWiz.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/548a3c7ec9ad1bb63f6cc21f4ae2a3b2317efad5b02031f542a18e3132022972/detection", "runtime_modules": [ "C:\\Windows\\system32\\DFDWiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "dfrgui.exe-4EF0749EA944BE2383D4CC82645E6942": { "file_name": "dfrgui.exe", "file_path": "C:\\Windows\\system32\\dfrgui.exe", "hash_md5": "4EF0749EA944BE2383D4CC82645E6942", "hash_sha1": "92647B442C4307E8A3FFDD7CD0F3A1207109CA96", "hash_sha256": "F45129D7F036DE281FDCD47A10E590DCF208021901EEE0E60B7207408854DCD6", "hash_sha384": "C25397B14BF2B7192BEB153FDC54877CB4C475142A17ADEBD7CA825C6374214B6B0659A2986F7FA222DC726C7FFE66FA", "hash_sha512": "A14C66EFCC33C2CA9F02184E7ED98478AA688B835E1FD9FD1F1B9338A1275994A45EFBCAB1E6BF0FB1FE6156FABA7725A1BE95EE0384426D0C261DEF2B039128", "hash_ssdeep": "3072:7Aad0bZhQ7EGVNXb26F/63nzwBf4SmkJKk/I+GJZKPy:caKbZhQ71fXhFyzQiYP", "hash_imp": "BA22F719CDE8DA4204EB7FFA324CF53D", "hash_pesha1": "D40BC975B2444953830A30A8B05794C1FDCCD371", "hash_pe256": "7456EB383D34C4ACCB71123C42E2139377757E2A39119CA8F59212ADB539ED76", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Drive Optimizer", "meta_original_filename": "lhdfrgui.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f45129d7f036de281fdcd47a10e590dcf208021901eee0e60b7207408854dcd6/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\DfrgUI.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SystemResources\\dfrgui.exe.mun": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_16.db": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\dfrgui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll" ], "runtime_window_title": "Optimize Drives" }, "dialer.exe-B2626BDCF079C6516FC016AC5646DF93": { "file_name": "dialer.exe", "file_path": "C:\\Windows\\system32\\dialer.exe", "hash_md5": "B2626BDCF079C6516FC016AC5646DF93", "hash_sha1": "838268205BD97D62A31094D53643C356EA7848A6", "hash_sha256": "E3AC5E6196F3A98C1946D85C653866C318BB2A86DD865DEFFA7B52F665D699BB", "hash_sha384": "6F7C42535766887AFB1990722700D6A110E77F69ACFAC9D345691BB722EA0B55B0C25139BF368DFE3025A3ADAA14974E", "hash_sha512": "615CFE1F91B895513C687906BF3439CA352AFCADD3B73F950AF0A3B5FB1B358168A7A25A6796407B212FDE5F803DD880BCDC350D8BAC7E7594090D37CE259971", "hash_ssdeep": "768:4KWEPeDS5mp3dg9fNBqOKfFz5VJp49Kbg9aQHsWo0meKRCd:335G3dg5NkOwLpOAbQHrmXCd", "hash_imp": "EA84F2A49408D51D324DE27B0D115B5E", "hash_pesha1": "8B7203D9098FC6ACB648E4BA74AFE29C812FC96A", "hash_pe256": "5D31DCC36B5B9B2D66ACD7F3A40800255EC1A169487C372E23DC2E380323F3FD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Phone Dialer", "meta_original_filename": "DIALER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e3ac5e6196f3a98c1946d85c653866c318bb2a86dd865deffa7b52f665d699bb/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\dialer.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\dialer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHELL32.dll" ], "runtime_window_title": "Phone Dialer" }, "directxdatabaseupdater.exe-453C9F2193E6C48326BCFC9937C6405D": { "file_name": "directxdatabaseupdater.exe", "file_path": "C:\\Windows\\system32\\directxdatabaseupdater.exe", "hash_md5": "453C9F2193E6C48326BCFC9937C6405D", "hash_sha1": "12B8BCC78798E2A47891F2D13878977BBE24A129", "hash_sha256": "1C51BC8FD77CC446ED42680D5342991D774594A22B98BD4C6D9A6B2CB018FE72", "hash_sha384": "9219202906456084A8BD3383F9336071D12BC9721B93E455758B9EA5AAD1D52C1966F0D1EA687A0A0AC94104FA82326A", "hash_sha512": "E1D64CF37321F673D19467A8B5B39D7EE3B71BB2164639ACD3F2615DA336D3FA3443E8E007C52776ECB9CBCAF64F2B4C9A264E219CEEF8C29828F93C6B530878", "hash_ssdeep": "6144:g8XJ4a44x4cfgug7gFMJXbkk3n+qpt52l:TZ4ahBjMJX1n+qf5o", "hash_imp": "A750073A3FBE89E2E49291BE00808091", "hash_pesha1": "D3ED5B26BB982DBD27DF1C6A6F5937011CA2B676", "hash_pe256": "E3921D30776A89BBDDAA6B0A07EFC1B64F35F0B9F3734EB4514C88A51DAA0E3F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DirectX Database Updater", "meta_original_filename": "DirectXDatabaseUpdater.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1c51bc8fd77cc446ed42680d5342991d774594a22b98bd4c6d9a6b2cb018fe72/detection", "runtime_modules": [ "C:\\Windows\\system32\\directxdatabaseupdater.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\DismApi.DLL", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll" ] }, "diskpart.exe-B8BC7D9AEBD54FF1E7CD61A185CC05FF": { "file_name": "diskpart.exe", "file_path": "C:\\Windows\\system32\\diskpart.exe", "hash_md5": "B8BC7D9AEBD54FF1E7CD61A185CC05FF", "hash_sha1": "7654183139B9DB5505A74B58E7F0DEC6F17FCE8B", "hash_sha256": "B9AA0F0F7C8924BD38734B8DE08D435FB2E73EEB16B89D4EA5BFE6F2AC06B54E", "hash_sha384": "7D49A0F80E9A7CEFC465B24A59C1A38EB494B7CEDA2A2778DA72082609F58BF87C5EE2E1E8EF19F136E1AF78B2F28D64", "hash_sha512": "28118CBC70489D2E1813BCE1BF7FC1FAEEDCC4CD46F9C1E1E2142A3DE6A4488760ABDD6097B8AC484A6A559F7F81AECD953392124562011C1EEC227BA9D6CFEF", "hash_ssdeep": "3072:BW48cN69DcPeNUEUXG2O87UATXX7CrtFtt5WTLfV5FfxEwV:H8cN69I2uESGibXChd56Ltrm", "hash_imp": "F82C2F5655093594CEAD2DBD23248DE9", "hash_pesha1": "963E524794EB9BEEAC6D36D93F47971E64BD74BC", "hash_pe256": "259DBE480B1352E380B2E2826F472D43958200B194F8AD7CFD8F900AE5841AFB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DiskPart", "meta_original_filename": "diskpart.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b9aa0f0f7c8924bd38734b8de08d435fb2e73eeb16b89d4ea5bfe6f2ac06b54e/detection", "output": "\r\nMicrosoft DiskPart version 10.0.19041.610\r\n\r\nCopyright (C) Microsoft Corporation.\r\nOn computer: 18CE68CB-4304-4\r\n\r\nMicrosoft DiskPart syntax:\r\n\tdiskpart [/s <script>] [/?]\r\n\r\n\t/s <script> - Use a DiskPart script.\r\n\t/? - Show this help screen.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\diskpart.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "diskperf.exe-7FACE5A6C4FA7913A7051BB8C8F9E7ED": { "file_name": "diskperf.exe", "file_path": "C:\\Windows\\system32\\diskperf.exe", "hash_md5": "7FACE5A6C4FA7913A7051BB8C8F9E7ED", "hash_sha1": "9E184F02EE2FC57E03A00F3A62A1126EA7657451", "hash_sha256": "293044B6001452F9855CE34BBF26F8A5C9D44A5CD2FBE9D8AC0651398C0F5FCB", "hash_sha384": "2514CD4B80CA0BCAAF6B6546CD608752802A028D1EB16A1D4B7B3A2A994C4280863249833DFF1A96E33519A930C3AE4D", "hash_sha512": "3730FD41AFF94C140CAD7F97C7935962527FEDF4C0784A99986D739E60ACE884EDEADEA4CEDC53EA6BA758DF12E87D2549531610BAF1564C05B158CDCFC57B18", "hash_ssdeep": "384:W1Y8+hriGBKOuP5X5ol44lDHtiPSmLkyT8QYRiOMRAt1z3VweQZ6KS9WDJW:WAhrtQol44lDASG8VRiOMReVwzZRSu", "hash_imp": "8C30315F0059261E5778F328A7850B04", "hash_pesha1": "23DD3AC030134282020C0E480BA3EA60D260FE85", "hash_pe256": "8F10E0D2887584C039628249D83E1F79F7114C6727C089711A4430FB91C6223A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Performance Configuration Utility", "meta_original_filename": "DISKPERF.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/293044b6001452f9855ce34bbf26f8a5c9d44a5cd2fbe9d8ac0651398c0f5fcb/detection", "output": "\r\n\r\nDISKPERF=====================\r\n\r\nStarts and stops system disk performance counters.\r\n\r\nUsed without the command switches, DISKPERF reports what disk\r\nperformance counters are enabled on the specified Windows 2000 computer.\r\n\r\nDisk performance counters can be specified to report the\r\nperformance of the individual physical drives, or the individual\r\nlogical drives or storage volumes. Note that these two sets of\r\nperformance counters are measured independently. The user\r\nhas the option of enabling and disabling them independently\r\nusing the command line switches.\r\nNOTE: This command can only be used to control remote\r\nWindows 2000 systems. In newer systems, these performance counters\r\nare automatically enabled.\r\n\r\nDISKPERF [-Y[D|V] | -N[D|V]] [\\\\computername]\r\n\r\n -Y Sets the system to start all disk performance counters\r\n when the system is restarted.\r\n\r\n -YD Enables the disk performance counters for physical drives.\r\n when the system is restarted.\r\n -YV Enables the disk performance counters for logical drives\r\n or storage volumes when the system is restarted.\r\n -N Sets the system to disable all disk performance counters\r\n when the system is restarted.\r\n\r\n -ND Disables the disk performance counters for physical drives.\r\n -NV Disables the disk performance counters for logical drives.\r\n \\\\computername Is the name of the computer you want to\r\n see or set disk performance counter use.\r\n The computer must be a Windows 2000 system.\r\n NOTE: Disk performance counters are permanently enabled on\r\n systems beyond Windows 2000.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\diskperf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "diskraid.exe-9D2870D8EB59514E6D481252BB987B48": { "file_name": "diskraid.exe", "file_path": "C:\\Windows\\system32\\diskraid.exe", "hash_md5": "9D2870D8EB59514E6D481252BB987B48", "hash_sha1": "63F45DA3308E130FB6A0C9B89C34182551DC6D71", "hash_sha256": "6F572BD4C5A0D9CDCAA2E63FF1B0E36982F4D35FA9FB9D360B2D8CC57FE4EE54", "hash_sha384": "FC53ECF53C50B4C988049E426565BEF032FF60F8AE3EC3DBC5BC612FE25CEC462A457CF1BAAD262259A0D65FAA02329C", "hash_sha512": "56278FE5DA369B7CC9D6C9A8DF94E1333FEB407907C945716EAB52958EF07FCF66AB64803501C27E4C5BC4B060EA1BD851978D7E1D5061EA3E1AC2E4DCBC1EEC", "hash_ssdeep": "6144:ADX91oG3blPe1hUZuintPiDWOc1zDuIrI6zo4SPvU:ADN1jlw6PiDA1zyms", "hash_imp": "701F69CB7F69911A0C2E0D44935719EB", "hash_pesha1": "8E5699D7A4263F8D4B92E9580A352F2C38B83F5A", "hash_pe256": "F572C50ACCE476B0B1D8A1FFCCA3C8BC0243DD12546C49D85700CBAAFB38B99B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DiskRAID", "meta_original_filename": "diskraid.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/6f572bd4c5a0d9cdcaa2e63ff1b0e36982f4d35fa9fb9d360b2d8cc57fe4ee54/detection", "output": "\r\nMicrosoft DiskRAID version 10.0.19041.1\r\n\r\nCopyright (C) 2003-2013 Microsoft Corporation.\r\nOn computer: 18CE68CB-4304-4\r\n\r\nUsage: DISKRAID [/? | [/s <script>] [/v]]\r\n\r\n Launches the DiskRAID application.\r\n\r\n /? specifies that DiskRAID should display this usage text.\r\n\r\n /s <script> specifies that DiskRAID should execute commands from the script\r\n file at the location specified.\r\n\r\n /v specifies that DiskRAID should run in verbose mode, printing\r\n out additional information about each command being executed.\r\n\r\nExamples:\r\n\r\n DISKRAID\r\n DISKRAID /v\r\n", "runtime_modules": [ "C:\\Windows\\system32\\diskraid.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DiskSnapshot.exe-FD450157FCC92C0A80EC3CF22AB5E4B3": { "file_name": "DiskSnapshot.exe", "file_path": "C:\\Windows\\system32\\DiskSnapshot.exe", "hash_md5": "FD450157FCC92C0A80EC3CF22AB5E4B3", "hash_sha1": "394166FE3140A310371DF5D58E95C0AD86706876", "hash_sha256": "2AF7212A150B721D0105928864DF0049A4D959AD7B5B997DF47BA69B434404B3", "hash_sha384": "49C56BE0112CCB6E7442D1C14B161592170FCE082887CBF0FB47893E71FC3120A2A6815873C89B941DC2B2FBD73FB281", "hash_sha512": "E25482CE70709855C9D08278A9020850E993E9F95845C8C51EAB181BC6B234C5CD9B7B53A2BAC1779E2447E95FD42E280E4F0DBA78E4FB8C82462717397A159B", "hash_ssdeep": "1536:b+tuvEu02o2kZfjY1VYL8g4VXx+9qauZZ+I+:bPvzYWVJ5x+9qaIZ+v", "hash_imp": "FB86A93BD88DA4F1C0C0CBC30C6E1C3B", "hash_pesha1": "0F04DB196758B1314B7CF3DC4FB75E4E08F387D8", "hash_pe256": "17CDBE1D47FFBFC8B5EA3EC3A7ED44582E3B3FCF1127704A486C5D5D70DF5EC7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DiskSnapshot.exe", "meta_original_filename": "DiskSnapshot.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2af7212a150b721d0105928864df0049a4d959ad7b5b997df47ba69b434404b3/detection", "error": "DiskSnapshot: illegal option: --\r\nDiskSnapshot.exe [options]\r\n\t-c write detail data to console\r\n\t-i write detail data to console (same as -c)\r\n\t-s (deprecated) summary data to console\r\n\t-u process large volumes (no limit)\r\n\t-j [config] specifies an alternate config file\r\n\t-v [volume][path] specifies volume(+path) to process, e.g. \"d:\" or \"d:\\foo\" \r\n\t-d [input-file] print encoded versions of the strings in the input file, for decoding purposes\r\n\t-e prints out escalation keywords\r\n\t-k calculate checksums for files, used to investigate duplicated on-disk content (c arg required).\r\n\t-o [output-file] write detail data to a file\r\n", "runtime_modules": [ "C:\\Windows\\system32\\DiskSnapshot.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "Dism.exe-34E5C4F6C39482EAA98A952DEF864735": { "file_name": "Dism.exe", "file_path": "C:\\Windows\\system32\\Dism.exe", "hash_md5": "34E5C4F6C39482EAA98A952DEF864735", "hash_sha1": "18FF045B29EDE2374790D4D1E32AC4B59197D0A7", "hash_sha256": "769FE00942EB716EC99A7947CAB6B4C8B0647936C01AA27BC249BBEC61DE82B5", "hash_sha384": "EBC7202C00957C47F6EC540A584DCA3D87E3FA42270C98E2D54C6EE1A8AEF367DB7EA4816F0F5B463C63AD76E4667805", "hash_sha512": "BA8A04F0D161C08C94AFCC11DD55A643689F87E5DD6EEDA1918478A4F8AC1486111EA15FF7D7DF653A8A614A0EF03966D4BA41BFB570611BB6344FA3D3178FA5", "hash_ssdeep": "3072:CC2XHiiwoxmlb9nKVOx87DDYAsn0qI6r7RW0JjIEoY68C2pM/7WJVrbXu:4H5wXsTOI+lW0uY68C2CAri", "hash_imp": "7BDAA6809ABE1512EF489728EEBD5989", "hash_pesha1": "509D93DAA9FEBF7189FC97EC92B85C6098964E09", "hash_pe256": "FC1D1594EDBB85A5212AB10FDA5122E5B92D373E076303D94161841AF5B5FCC1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Dism Image Servicing Utility", "meta_original_filename": "DISM.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/769fe00942eb716ec99a7947cab6b4c8b0647936c01aa27bc249bbec61de82b5/detection", "output": "\r\nDeployment Image Servicing and Management tool\r\nVersion: 10.0.19041.572\r\n\r\n\r\nDISM.exe [dism_options] {Imaging_command} [<Imaging_arguments>]\r\nDISM.exe {/Image:<path_to_offline_image> | /Online} [dism_options] \r\n {servicing_command} [<servicing_arguments>]\r\n\r\nDESCRIPTION:\r\n\r\n DISM enumerates, installs, uninstalls, configures, and updates features\r\n and packages in Windows images. The commands that are available depend \r\n on the image being serviced and whether the image is offline or running.\r\n\r\n\r\nGENERIC IMAGING COMMANDS:\r\n\r\n /Split-Image - Splits an existing .wim file into multiple \r\n read-only split WIM (SWM) files.\r\n /Apply-Image - Applies an image.\r\n /Get-MountedImageInfo - Displays information about mounted WIM and VHD\r\n images.\r\n /Get-ImageInfo - Displays information about images in a WIM, a VHD\r\n or a FFU file.\r\n /Commit-Image - Saves changes to a mounted WIM or VHD image.\r\n /Unmount-Image - Unmounts a mounted WIM or VHD image.\r\n /Mount-Image - Mounts an image from a WIM or VHD file.\r\n /Remount-Image - Recovers an orphaned image mount directory.\r\n /Cleanup-Mountpoints - Deletes resources associated with corrupted\r\n mounted images.\r\n\r\nWIM COMMANDS:\r\n\r\n /Apply-CustomDataImage - Dehydrates files contained in the custom data image.\r\n /Capture-CustomImage - Captures customizations into a delta WIM file on a \r\n WIMBoot system. Captured directories include all \r\n subfolders and data.\r\n /Get-WIMBootEntry - Displays WIMBoot configuration entries for the \r\n specified disk volume.\r\n /Update-WIMBootEntry - Updates WIMBoot configuration entry for the \r\n specified disk volume.\r\n /List-Image - Displays a list of the files and folders in a \r\n specified image.\r\n /Delete-Image - Deletes the specified volume image from a WIM file\r\n that has multiple volume images.\r\n /Export-Image - Exports a copy of the specified image to another\r\n file.\r\n /Append-Image - Adds another image to a WIM file.\r\n /Capture-Image - Captures an image of a drive into a new WIM file.\r\n Captured directories include all subfolders and \r\n data.\r\n /Get-MountedWimInfo - Displays information about mounted WIM images.\r\n /Get-WimInfo - Displays information about images in a WIM file.\r\n /Commit-Wim - Saves changes to a mounted WIM image.\r\n /Unmount-Wim - Unmounts a mounted WIM image.\r\n /Mount-Wim - Mounts an image from a WIM file.\r\n /Remount-Wim - Recovers an orphaned WIM mount directory.\r\n /Cleanup-Wim - Deletes resources associated with mounted WIM \r\n images that are corrupted.\r\n\r\nFFU COMMANDS:\r\n\r\n /Capture-Ffu - Captures a physical disk image into a new FFU file.\r\n /Apply-Ffu - Applies an .ffu image.\r\n /Split-Ffu - Splits an existing .ffu file into multiple read-only\r\n split FFU files.\r\n /Optimize-Ffu - Optimizes a FFU file so that it can be applied to storage \r\n of a different size.\r\n\r\nIMAGE SPECIFICATIONS:\r\n\r\n /Online - Targets the running operating system.\r\n /Image - Specifies the path to the root directory of an\r\n offline Windows image.\r\n\r\nDISM OPTIONS:\r\n\r\n /English - Displays command line output in English.\r\n /Format - Specifies the report output format.\r\n /WinDir - Specifies the path to the Windows directory.\r\n /SysDriveDir - Specifies the path to the system-loader file named\r\n BootMgr.\r\n /LogPath - Specifies the logfile path.\r\n /LogLevel - Specifies the output level shown in the log (1-4).\r\n /NoRestart - Suppresses automatic reboots and reboot prompts.\r\n /Quiet - Suppresses all output except for error messages.\r\n /ScratchDir - Specifies the path to a scratch directory.\r\n\r\nFor more information about these DISM options and their arguments, specify an\r\noption immediately before /?.\r\n\r\n Examples: \r\n DISM.exe /Mount-Wim /?\r\n DISM.exe /ScratchDir /?\r\n DISM.exe /Image:C:\\test\\offline /?\r\n DISM.exe /Online /?\r\n\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\Dism.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dispdiag.exe-D6087E386F3D6AF9474EFFFA6C586CEC": { "file_name": "dispdiag.exe", "file_path": "C:\\Windows\\system32\\dispdiag.exe", "hash_md5": "D6087E386F3D6AF9474EFFFA6C586CEC", "hash_sha1": "FAF1350A70457B82F5826FDB7B42A5B61252C41D", "hash_sha256": "89808FECDA2B63D1A16C42748C4905324983F66AA20EAA704F39F251CCCE7B7A", "hash_sha384": "65EFA232F7207134644610146FF508C938880BC199657303B5305A9B0FA2B2C0C7EE2760E8474AFB11F67A9E57107B04", "hash_sha512": "8F966A8AEBA3D7EB615815CE94FC57BC6F68B05F723802A86BABB6B0DBA4767F50EA8B8C646C4A16566C58CB97A1D034700A35A1AB25362361CA378A06D349BC", "hash_ssdeep": "3072:/ZMS3Ww0Zx6o6s/W/MCv6KuGzSSOE219p+IjPiy1yk:ROw0ZQoPK9YfptjPiy1y", "hash_imp": "9ACE3E42278A3D9F47810466AD00D927", "hash_pesha1": "5DDE05DFCBD4873ED8BFBBDD8CFE566E99794487", "hash_pe256": "A156B6983F0D2D3B23DEB8314A3AF26BB0292603363AAF137B015DDDAE26FBBC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Display Diagnostics", "meta_original_filename": "dispdiag.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/89808fecda2b63d1a16c42748c4905324983f66aa20eaa704f39f251ccce7b7a/detection", "output": "Logs display information to a file in the current directory.\r\n\r\nUsage: dispdiag [-testacpi] [-d] [-delay <seconds>] [-brightnesslogging] [-out <FilePath>]\r\n\t-testacpi runs hotkey diagnostics test\r\n\t-d generates a dmp file as well with additional data.\r\n\t-delay delays the collection of data by specified time in seconds.\r\n\t-out <FilePath> path where the dispdiag file should be saved, including filename. This must be the last parameter\r\n\t-DumpIdDiag force Indirect DIsplay framework to dump diag info via WPP\r\n\t-brightnesslogging toggle verbose brightness logging.\r\n\t-ccddatabaselogging <on|off> toggle Ccd database access logging.\r\n\t-dxgautologger <on|off> toggle DxgDiagnostics autologger. Requires admin and a reboot.\r\n\t-DodFullscreenupdates <on|off> toggle if all active display only drivers should process each present\r\n\t as full screen dirty.\r\n\t-Msg <Message to log> Inserts the specified message into the diagnostic buffers\r\nOutput:\r\n\tName of the saved file.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\dispdiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DisplaySwitch.exe-A1780867BAB912A4DA7105D54C7BFD39": { "file_name": "DisplaySwitch.exe", "file_path": "C:\\Windows\\system32\\DisplaySwitch.exe", "hash_md5": "A1780867BAB912A4DA7105D54C7BFD39", "hash_sha1": "CDD54DC89F9E064C0C5E8FA4E9F30735FA4DDB95", "hash_sha256": "A5F3500875F4C482BD821B251B6A79E144C021A40E7054D10085619932FF4FF9", "hash_sha384": "145543BCE6897085BF05D9F8C9F1696170486E2CF855FE3FF3F2B58544A4A3436400246FB6A889F922AB28BA42DA5983", "hash_sha512": "C1C010228441726624C820FBBB2EF43762353D7D75F440D424672C45FAB2BEBCDAFF17F83BCC319B1B38C08FD6C1832DDEEDB7B047092E498934DEED917DB8FA", "hash_ssdeep": "3072:QsdJNVZUwfBEjFSJu20qc7sPv+W1jOGy2XvkY0rPRLTWyDSBloU:QwZU+2ThsPv+W1jOGy2/3yJjY", "hash_imp": "3DBF1C80950DFBF8F40A0705EDFD00AD", "hash_pesha1": "2CB69F8960F607FFAEC66F85A36530480C83EF41", "hash_pe256": "B1866B98E5E31F46C7C4A9E098A0C8C16BCA8A55438C4920B2CC285FF49A8BE3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Display Switch", "meta_original_filename": "DisplaySwitch.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a5f3500875f4c482bd821b251b6a79e144c021a40e7054d10085619932ff4ff9/detection", "runtime_modules": [ "C:\\Windows\\system32\\DisplaySwitch.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\policymanager.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll" ] }, "djoin.exe-1BC9245D12077F2E422C84541D62BED9": { "file_name": "djoin.exe", "file_path": "C:\\Windows\\system32\\djoin.exe", "hash_md5": "1BC9245D12077F2E422C84541D62BED9", "hash_sha1": "01C877005E353A5202B2250B0277BB900D71753F", "hash_sha256": "F5EE00BF7CFD7BF7504597D0106D1FA2C8CEBFC7B693DC18E6E10F2864FAD690", "hash_sha384": "BBD52D571A209D42DEA28C24E7DBFE4BD5FC0647EFE2101D50F8FCD43DB5E230D87F2C28EF19355ABA9922B75EC60BB4", "hash_sha512": "23D6D5217D2113909D69C769A41A39BF824101EBF4424F52F8ADF19E807D9FF392B5B2E29607D3659E22C513A024EB6D46E85DC73E89B443BBA74E497626E987", "hash_ssdeep": "1536:uzk0GRwMJ2Ut668+tFI2GwKEQeXsOmQJ:uA0GQUt668+U2GrEjL", "hash_imp": "A97339DE0E1A0EBC1C5F5B0FA9A1EF2E", "hash_pesha1": "E4EFB9A52B09140ED04075752DB7E0E4FED12E07", "hash_pe256": "C1B118BC2F06892D825C160C782723CA7239832CDC3784AEBEDBE8D87721A978", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Unattended Setup Generic Command For Domain Join", "meta_original_filename": "djoin.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f5ee00bf7cfd7bf7504597d0106d1fa2c8cebfc7b693dc18e6e10f2864fad690/detection", "output": "Usage: djoin.exe [/OPTIONS]\r\r\n\r\r\n /PROVISION - Provision a computer account in the domain\r\r\n /DOMAIN <Name> - <Name> of the domain to join\r\r\n /MACHINE <Name> - Host <Name> of the computer joining the domain\r\r\n /MACHINEOU <OU> - Optional <OU> where the account is created\r\r\n /DCNAME <DC> - Optional <DC> to target for account creation\r\r\n /REUSE - Reuse any existing account (password will be reset)\r\r\n /SAVEFILE <FilePath> - Save provisioning data to a file at <FilePath>\r\r\n /NOSEARCH - Skip account conflict detection, requires DCNAME (faster)\r\r\n /DOWNLEVEL - Support using a Windows Server 2008 DC or earlier\r\r\n /PRINTBLOB - Return base64 encoded metadata blob for an answer file\r\r\n /DEFPWD - Use default machine account password (not recommended)\r\r\n /ROOTCACERTS - Opt. include root Certificate Authority certificates.\r\r\n /CERTTEMPLATE <Name> - Optional <Name> of machine certificate template.\r\r\n Includes root Certificate Authority certificates.\r\r\n /POLICYNAMES <Name(s)> - Opt. semicolon-separated list of policy names.\r\r\n Each name is the displayName of the GPO in AD.\r\r\n /POLICYPATHS <Path(s)> - Opt. semicolon-separated list of policy paths.\r\r\n Each path is a path to a registry policy file.\r\r\n /NETBIOS <Name> - Opt. Netbios <Name> of the computer joining the domain.\r\r\n /PSITE <Name> - Opt. <Name> of persistent site to put the computer joining\r\r\n the domain in.\r\r\n /DSITE <Name> - Opt. <Name> of dynamic site to initially put the computer \r\r\n joining the domain in.\r\r\n /PRIMARYDNS <Name> - Opt. <Name> of primary DNS domain of the computer\r\r\n joining the domain.\r\r\n\r\r\n /REQUESTODJ - Request offline domain join at next boot\r\r\n /LOADFILE <FilePath> - <FilePath> specified previously via /SAVEFILE\r\r\n /WINDOWSPATH <Path> - <Path> to the Windows directory in an offline image\r\r\n /LOCALOS - Allows /WINDOWSPATH to specify the locally running OS.\r\r\n This command must be run as a local Administrator.\r\r\n This option requires a reboot for changes to be applied.\r\r\n \r\r\nExamples:\r\r\n\r\r\nTo provision a computer account in the domain:\r\r\ndjoin.exe /PROVISION /DOMAIN <DomainName> /MACHINE <MachineName>\r\r\n /SAVEFILE <FilePath>\r\r\n Note: Other parameters are optional\r\r\n \r\r\nTo request the local machine to perform an offline domain join:\r\r\ndjoin.exe /REQUESTODJ /LOADFILE <FilePath> /WINDOWSPATH <Path>\r\r\n Note: Other parameters are optional\r\r\nThe parameter is incorrect.\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\djoin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dllhost.exe-08EB78E5BE019DF044C26B14703BD1FA": { "file_name": "dllhost.exe", "file_path": "C:\\Windows\\system32\\dllhost.exe", "hash_md5": "08EB78E5BE019DF044C26B14703BD1FA", "hash_sha1": "2CE12A317BEBF8293F3544433A55D972A5967996", "hash_sha256": "E7FC40B41AA8B83841A0B96D169EAF0800AA784733E636935374D56536253F10", "hash_sha384": "FE56817F7F5B8534AA8E57A7FFC546DF18B9B74A0765CA590D3015AAC4B8A4FE79BC1B7DD6B837747F9FB51230C3CDB8", "hash_sha512": "A2BC4EB15048C182AF80192C19147D8871396B1463A8CB9257C80B142698B71A8093C65206847D9E07FCC2FBED0829390908597F617E26AC6523577927836562", "hash_ssdeep": "384:lJRXcksOiPxc+rWw5Ww78hDBRJXP+CcWlGsaX:lJR7cxcEKh1PfwL", "hash_imp": "CF79FCE90FCED31836373F3E48251A5D", "hash_pesha1": "24BBAE507219C32594364D9ED39EA16AFB892032", "hash_pe256": "07F72EC5C39A54A33C0E9238E42E517168682029210AA9CDAC647116B9D1B954", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM Surrogate", "meta_original_filename": "dllhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e7fc40b41aa8b83841a0b96d169eaf0800aa784733e636935374d56536253f10/detection", "runtime_modules": [ "C:\\Windows\\system32\\dllhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "dllhst3g.exe-E4208ACA399EC8C0AD48B05960F7FA9D": { "file_name": "dllhst3g.exe", "file_path": "C:\\Windows\\system32\\dllhst3g.exe", "hash_md5": "E4208ACA399EC8C0AD48B05960F7FA9D", "hash_sha1": "BC85DBAD1A7BEF476AA5D41BC9884515506C53A6", "hash_sha256": "360E11757029F102BF9DEFAF60B24F96A8C4B6726C0B9EC9ECE4BBAE89F3AF7B", "hash_sha384": "9F0E74A3FC5ED5621A2C9DEA600C459D4D415FF4F9C5083C68B31D9693435E573E4C5D11386E7B48A925F765FA1D9ECD", "hash_sha512": "4796606D6D61A93894E033BBE23FA9F6C05D72F433B4522F3E10A0D71A7AE7BEEBFB8CB00F78DAA9A6F6881BE58EE82B5336B82C98DD6A3C11BDBC90CFE3B019", "hash_ssdeep": "192:f1CJDNbj7tYacksOgasl96c/xPhu9ai5uTEDcw8AW5yW:wJRXcksOqHMcFAW5yW", "hash_imp": "CF79FCE90FCED31836373F3E48251A5D", "hash_pesha1": "7E2DA07D0CDB540428FDEC0A26080B108A4820DF", "hash_pe256": "08EC9AF7DF4FEF3477FDAF42B7DBB1072849938D7404BA4B9BC9F85A090CED82", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM Surrogate", "meta_original_filename": "dllhst3g.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/360e11757029f102bf9defaf60b24f96a8c4b6726c0b9ec9ece4bbae89f3af7b/detection", "runtime_modules": [ "C:\\Windows\\system32\\dllhst3g.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "dmcertinst.exe-F4C5288EACB20BEC86982B71BF3AFC38": { "file_name": "dmcertinst.exe", "file_path": "C:\\Windows\\system32\\dmcertinst.exe", "hash_md5": "F4C5288EACB20BEC86982B71BF3AFC38", "hash_sha1": "BA924CE9E019995065FC73274AEFE0C1C9DCFC46", "hash_sha256": "BC91D1EC93E1EBF081B8C76666433ED82CC1360B5E478AFBE5FD7DD1F4E80831", "hash_sha384": "50D678F4B0E07C6D7C7F7C28C998CD64E63002C263C74208FAECC614EC8D0378F743700B5A599E6EAB28C7396428C9C6", "hash_sha512": "14DD59C4338DC75D51FA0ED74CF8F86EB6E2481D38E8A71782A51EB2EDAACE6EEDCFE32D8148761C0C026D5A3E7EEBAEBC16788288B24687166FBB8630985FA7", "hash_ssdeep": "3072:uuSMxutLfC1YnUkfdCD9mzDb9NgTk9yUILpi8L0puz4COLzIYayq+ArNMJg:uvMxutLfaY+9m35Ngw9ALpfQS+Lxayq+", "hash_imp": "1F4D4D9DCBB6A3291F7252C0C91A0649", "hash_pesha1": "0C2A3D64D50A8593638DE49D4DF2B6879B67A361", "hash_pe256": "535A846E80966662406D9F338245533CE9DACDBC0710A5F9D7C8413676733955", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DM Certificate Installer", "meta_original_filename": "dmcertinst.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/bc91d1ec93e1ebf081b8c76666433ed82cc1360b5e478afbe5fd7dd1f4e80831/detection", "runtime_modules": [ "C:\\Windows\\system32\\dmcertinst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\system32\\certenroll.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\UMPDC.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\certca.dll", "C:\\Windows\\system32\\ncrypt.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\system32\\CRYPTSP.dll", "C:\\Windows\\system32\\iri.dll" ] }, "dmcfghost.exe-A245EE3F5E935B53D6CFE3491FDAC745": { "file_name": "dmcfghost.exe", "file_path": "C:\\Windows\\system32\\dmcfghost.exe", "hash_md5": "A245EE3F5E935B53D6CFE3491FDAC745", "hash_sha1": "C9307AD21E9901D7A9C24EDFCDC34BEA83C09BEB", "hash_sha256": "460D46FD4F0196D3483D5C3831017C931B8E34837CC873FB68C1D3239907F455", "hash_sha384": "C5804A326D07CBAE3ADE6E75CE84E7525B32B606F611E5370238DD440587CFB063383CDAB4ADA01C1CDEDAD2800B34D4", "hash_sha512": "55647E67E5E1AE9C5CFD232C6286DB87267FD28812842A583BBD43639C31DE73AA031F4AF138FC4A544DA306343041BC9FE6EBEB3F9B09DA33D6259BBFE7A245", "hash_ssdeep": "768:b55BaJh8bJtYVO0Y2BIybL9mg4KorWhl0vqyMmAF8ZfQ:bBOAf0Y2KWh+SyMmK8ZfQ", "hash_imp": "6FCA673968906FA1EB9C396AD8DFDF7E", "hash_pesha1": "C18228A9DA9184C4DDDAC970FB35A04E0E5CBB1A", "hash_pe256": "1D05C65CA92DB1AB52B91800FAC5BE86012213C0416173B6FA652FC6DA0F36D0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Push Router Client of OMA-CP", "meta_original_filename": "dmcfghost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/460d46fd4f0196d3483d5c3831017c931b8e34837cc873fb68c1d3239907f455/detection", "runtime_modules": [ "C:\\Windows\\system32\\dmcfghost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\dsclient.dll", "C:\\Windows\\system32\\DMPushProxy.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\system32\\dmxmlhelputils.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\system32\\iri.dll", "C:\\Windows\\system32\\XmlLite.dll" ] }, "dmclient.exe-CF2AFC5BE537F8DB1C2D76B8E9933A37": { "file_name": "dmclient.exe", "file_path": "C:\\Windows\\system32\\dmclient.exe", "hash_md5": "CF2AFC5BE537F8DB1C2D76B8E9933A37", "hash_sha1": "A8081FE5FB2487E5DD1C0DD8847C0ED14B2ED86B", "hash_sha256": "4E12F924847C1C9F3E30C27184E3DAB8F608FD4C414B04C6D0032EA57F9C89B4", "hash_sha384": "93FF0E9F22E29556A12AD3237B03EFCE154D73571BF988C535ABCFB7BB043A793CD19BF767A17755C00CA262015E0A3F", "hash_sha512": "ED952EC482703C9F3E59E501F7C830B4C8FAA3A90311105F7B729AEC7B17D40561C6E01D21455867D1C63C702B22437E83D3347A3222CAD120DA4124C6347C98", "hash_ssdeep": "3072:tAgr76ZO37h8lvkOyhUJbWEHq5Is2Evuh1mr+QoIxTfgvtj:tAgr7X7h8JxyhURHHq5IsUhoG4gl", "hash_imp": "7D6AD21AC6C2B8DEC545547ABF80FE44", "hash_pesha1": "18713AE182201040B36A1622CE6720065AE0628A", "hash_pe256": "3BFA88CB184E99A705A14876F4A2CBE9AE582193BEF547606050C2AB953AFBDD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Feedback SIUF Deployment Manager Client", "meta_original_filename": "dmclient.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4e12f924847c1c9f3e30c27184e3dab8f608fd4c414b04c6d0032ea57f9c89b4/detection", "runtime_modules": [ "C:\\Windows\\system32\\dmclient.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DmNotificationBroker.exe-545FE8495AAFFCEC31A407368E7C498C": { "file_name": "DmNotificationBroker.exe", "file_path": "C:\\Windows\\system32\\DmNotificationBroker.exe", "hash_md5": "545FE8495AAFFCEC31A407368E7C498C", "hash_sha1": "5066BE3365CE91BD6DC8A0642F84C01ABEF34062", "hash_sha256": "9E5F3D2A0D483D36CC69B958C6BAC7DB679F9B9083D9443E0920634493DC15CF", "hash_sha384": "A0A9B124F5610C9F4233D03605CDC8527FF61E1A4644483CC29CDFE6EB7576DFF64C366F5EADDDE89DF7C411B136E257", "hash_sha512": "303195572095B150E69C93939424A46060E651805914BDEC8A06C19501890E4F7F477FC8116393DCA74ADC07522750812402A8AB810A9845E96FACDA06BDBB7A", "hash_ssdeep": "384:mHmlyfSLvL4jzt245j6/VG7laAeSsiFMeONwsiOAuJAnYl2R/KHZgUJVjeYeITWQ:mHmXLvL4g4SwdRJpQZl0/QtLjy2", "hash_imp": "289708B41323FCB3D276BCFB9F56B2E7", "hash_pesha1": "D7DB6EFCFD4A16072613D7E1682A29CBC1E5C961", "hash_pe256": "DCC717B088AF7212C212D32C46A93F199F934C38F51B19B6D1BD15790648D0AE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DmNotificationBroker", "meta_original_filename": "DmNotificationBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/9e5f3d2a0d483d36cc69b958c6bac7db679f9b9083d9443e0920634493dc15cf/detection", "runtime_modules": [ "C:\\Windows\\system32\\DmNotificationBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\Windows.UI.Immersive.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\system32\\msvcp110_win.dll" ] }, "DmOmaCpMo.exe-0591261A0070E218264C5B129C33AEF1": { "file_name": "DmOmaCpMo.exe", "file_path": "C:\\Windows\\system32\\DmOmaCpMo.exe", "hash_md5": "0591261A0070E218264C5B129C33AEF1", "hash_sha1": "DA782EC434914B8B60AED37272C822740D7F4A01", "hash_sha256": "C9FDA4B2B4851DB71D73E568B5D10BE577D525A2F2F68B83B2110862E3491B16", "hash_sha384": "B2DEEEE3AF18415564CA26DEF2D2F7F10665F0B5A5F6BCC007B369C27560A0C952992350CC8BD0B36E36A8F78D7A2F1D", "hash_sha512": "A1EFF9BF327E0FF2B9E959851FF1D5537CD097E70C9BB292A04BECE8EB6BBFACD5078B792BF093C0743F09EA81564F6BA31259B622E38A2A74BB8BCABF8FC263", "hash_ssdeep": "768:SdT+WduLUspgE/FxwFqy5/LklXXbxRBn1EHd8d3G80DdbyAyy1bnKiOkPOq:SdTUgE9ZQLkpxRBniHdoa2AyanK/q", "hash_imp": "CF308790E494EF6E2671CD289C4EA3D2", "hash_pesha1": "718C4A3B71AB4ACE7985F28B08D6474ADFA6702D", "hash_pe256": "0A4D881B33A0E6266FC80D5D31D24DFC49E58886B5444A465432A9ACE3BB07AA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for OMA-CP Client", "meta_original_filename": "DmOmaCpMo.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c9fda4b2b4851db71d73e568b5d10be577d525a2f2f68b83b2110862e3491b16/detection", "runtime_modules": [ "C:\\Windows\\system32\\DmOmaCpMo.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\system32\\DMProcessXMLFiltered.dll", "C:\\Windows\\system32\\dsclient.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\dmEnrollEngine.DLL", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\system32\\iri.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\cfgmgr32.dll" ] }, "dnscacheugc.exe-0EA805915C512B7A68601CE5D796E63E": { "file_name": "dnscacheugc.exe", "file_path": "C:\\Windows\\system32\\dnscacheugc.exe", "hash_md5": "0EA805915C512B7A68601CE5D796E63E", "hash_sha1": "B59B36B676885E720C5E4F7F850B31146F21E807", "hash_sha256": "2A993865F4EB6849A2E9A16B1ACFD6E942B63338EA1699FBE785A6BA4B75C39E", "hash_sha384": "1FB179882F638571A660937C7DDB0DB775DB679CD1B814E14C3CC4F1F00D276EE903FDB3CF312EC87AA7B93D0AF5AB60", "hash_sha512": "E210FB084F14BFD073C648CFAD5AA71193A9CA60E783E28DB32784A960971D4CBA5CB7BF4FCB9A94690E2752940300C16ED9D945C34D22EB9ADF512DB01C2EB1", "hash_ssdeep": "384:be7JA0ShZ6VpoQ6q9rY5Inf/x0LL+5AxbDveQUodkSZDPryc1ObH9uoskSPElSH7:gJdL6qP3EOzQ2AZRElUUItfLz7U", "hash_imp": "B6CEB2D01553AAEFF2915051C0E45345", "hash_pesha1": "E3E03FDF81AA162728589FC9EBEC9479A14FDF3F", "hash_pe256": "237E648454AE46F16791C3CA7D56BB6DDEE3BE06E797AEBDA895A28058FC9E95", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DNSCache Unattend Generic Command", "meta_original_filename": "dnscacheugc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2a993865f4eb6849a2e9a16b1acfd6e942b63338ea1699fbe785a6ba4b75c39e/detection", "runtime_modules": [ "C:\\Windows\\system32\\dnscacheugc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "doskey.exe-B830840C8EF48C927ABFF897022274C4": { "file_name": "doskey.exe", "file_path": "C:\\Windows\\system32\\doskey.exe", "hash_md5": "B830840C8EF48C927ABFF897022274C4", "hash_sha1": "B5A2A09C4E663E188D455FE2670E8739EDB8A707", "hash_sha256": "543819E74FD619EA3D45D1AD1640907B16B576813F0F8DF9EA0C63B48DC4E323", "hash_sha384": "45553CCA466CC87EA08E9299FB577A0D2C171A100E0BB1983D2C652A873D262A110D4793367CE2E1D0A308F5C1AE9342", "hash_sha512": "301E160E00BA95EBDB2E9AA33DE90DDE08EBE66D957C44C387395CAC49C7D4072CF73A12DA05892912C7EAD8AFC97075B5FE92A72EACF6B51BD65413B0071421", "hash_ssdeep": "384:FvTRedyHrlmMnmgb2Bi6Pe8p/s5qHfiGv3n0dw70Aj3W4iW:FvTReQrYMnmZBi2p0IiGmE0AjL", "hash_imp": "A1EA9D934205151494B8180E6C772F08", "hash_pesha1": "29392F3F06FE8D1873734CD48FAFBF7CA6F0E05E", "hash_pe256": "3667371FDB28187381B74B5C3C1ACFE6C7887318FC9D26AC5E93B9F95C62404F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Keyboard History Utility", "meta_original_filename": "DOSKEY.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/543819e74fd619ea3d45d1ad1640907b16b576813f0f8df9ea0c63b48dc4e323/detection", "output": "Edits command lines, recalls Windows commands, and creates macros.\r\n\r\nDOSKEY [/REINSTALL] [/LISTSIZE=size] [/MACROS[:ALL | :exename]]\r\n [/HISTORY] [/INSERT | /OVERSTRIKE] [/EXENAME=exename] [/MACROFILE=filename]\r\n [macroname=[text]]\r\n\r\n /REINSTALL Installs a new copy of Doskey.\r\n /LISTSIZE=size Sets size of command history buffer.\r\n /MACROS Displays all Doskey macros.\r\n /MACROS:ALL Displays all Doskey macros for all executables which have\r\n Doskey macros.\r\n /MACROS:exename Displays all Doskey macros for the given executable.\r\n /HISTORY Displays all commands stored in memory.\r\n /INSERT Specifies that new text you type is inserted in old text.\r\n /OVERSTRIKE Specifies that new text overwrites old text.\r\n /EXENAME=exename Specifies the executable.\r\n /MACROFILE=filename Specifies a file of macros to install.\r\n macroname Specifies a name for a macro you create.\r\n text Specifies commands you want to record.\r\n\r\nUP and DOWN ARROWS recall commands; ESC clears command line; F7 displays\r\ncommand history; ALT+F7 clears command history; F8 searches command\r\nhistory; F9 selects a command by number; ALT+F10 clears macro definitions.\r\n\r\nThe following are some special codes in Doskey macro definitions:\r\n$T Command separator. Allows multiple commands in a macro.\r\n$1-$9 Batch parameters. Equivalent to %1-%9 in batch programs.\r\n$* Symbol replaced by everything following macro name on command line.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\doskey.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dpapimig.exe-B6D6477A0C90A81624C6A8548026B4D0": { "file_name": "dpapimig.exe", "file_path": "C:\\Windows\\system32\\dpapimig.exe", "hash_md5": "B6D6477A0C90A81624C6A8548026B4D0", "hash_sha1": "E6EAC6941D27F76BBD306C2938C0A962DBF1CED1", "hash_sha256": "A8147D08B82609C72D588A0A604CD3C1F2076BEFCC719D282C7CBD6525AE89EB", "hash_sha384": "3F22EFDBE5A6311BA4D359DE0A7B757BC101E686CABCF870CB2B3CDB06DECCABB4920F2B063244BC9E5100D28552D8E1", "hash_sha512": "72EC8B79E3438F0F981129A323AD39DB84DF7DD14A796A820BDBC74EA8FA13EEE843D1EA030A0C1CAEDA2E2D69952F14A821A73825B38DD9415047ACA597B1FE", "hash_ssdeep": "1536:5Thpc5GR/Zhp00l3uU1HIED1fCbWpygzU:VhaKh+SJj16bE", "hash_imp": "5BACEA135D7122680523ECF81DEF2D51", "hash_pesha1": "75FCCC39073029797B96CE61994E31EF9194E814", "hash_pe256": "FF196069C71C5C0E8775405433F65416DFB7EBFD81FAF4004EAE4D6AB33DB861", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DPAPI Key Migration Wizard", "meta_original_filename": "dpapimig.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a8147d08b82609c72d588a0a604cd3c1f2076befcc719d282c7cbd6525ae89eb/detection", "runtime_modules": [ "C:\\Windows\\system32\\dpapimig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\SHELL32.dll" ] }, "DpiScaling.exe-109D8299C806BD19A3E9F34A0B5C0DB0": { "file_name": "DpiScaling.exe", "file_path": "C:\\Windows\\system32\\DpiScaling.exe", "hash_md5": "109D8299C806BD19A3E9F34A0B5C0DB0", "hash_sha1": "20C1A66E2EA39F7C83E9A1541CDF20531D838D08", "hash_sha256": "1192F380B190AA0C6B531BA59B14A12C6346B642C3553EC9F014B68AAC992950", "hash_sha384": "A73A6A049A8EE80D8B88197A98CAE5F66D375A9654E8372BD4D2F02B479104A55FA893A8EF7A9415BBFFBA9B82A773A2", "hash_sha512": "A2E449E7BDA46B7A19577E18E22808538991D606096199CA9788B3C663D59445C96EC17F7FD9D0C8B030D845AEF4A35E36A15A10373454245BFFA9DF4C564532", "hash_ssdeep": "1536:AVZd91OwxgwYfPSqlGv+BNXNvuZS36EDtAZ7jz6dTdMQiMtYwJj8:S1OwNMSqoKXNvuZAFDqXzlzQQ", "hash_imp": "79AF10FA7C10573B0B9B52F39C28B0F2", "hash_pesha1": "AD268B019C68CA4E180EBDA826DFD636D1B23D82", "hash_pe256": "3718ACC683877FC0C5815C2DDB1342D3A2282CE3EA572604EA05866674FEF99A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Display Control Panel", "meta_original_filename": "DPISCALING.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/1192f380b190aa0c6b531ba59b14a12c6346b642c3553ec9f014b68aac992950/detection", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\system32\\DpiScaling.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll" ] }, "dpnsvr.exe-BA32BB24B7DA23BD7EE7AE4B576338CD": { "file_name": "dpnsvr.exe", "file_path": "C:\\Windows\\system32\\dpnsvr.exe", "hash_md5": "BA32BB24B7DA23BD7EE7AE4B576338CD", "hash_sha1": "17731367250361C6B1AAF24F988B8DD1150B1E92", "hash_sha256": "7CF4535E85EC02365C54BF460992344FE1E319381E794E51A7CE0F9CB0438929", "hash_sha384": "89AECA4B70DFE9C64219EB8AD7D83B50E8E3E32B16A4FAB14DE95F4C95DA9F37E49CB27594165D9638B474EFB23FFC58", "hash_sha512": "4317C083C491E74EF7E1AD30D79164B3D6BA360F3B83A88D220B21385837049A33C3023C5F9D10C42980C45FECC747D271263242976435ABAB7612C26E486BE4", "hash_ssdeep": "96:FjxR3HUNj9fs2Qz6IDyBTFdesMH3aLbJ0lq5/sEWRuWwl:FtmzzyyBJdQH3aXSlSWRuW", "hash_imp": "5C317B4785C1C3CE395F95788FB0F892", "hash_pesha1": "45119AD3D8FFD5310574245E9C38234BFAEB18AA", "hash_pe256": "2CB668642ECDAEAAFECBE04E10D93FED47CFCC73996B1D4CB3566F31AC9C3BAD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DirectPlay Stub", "meta_original_filename": "wcodstub.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7cf4535e85ec02365c54bf460992344fe1e319381e794e51a7ce0f9cb0438929/detection" }, "driverquery.exe-E9AAEFB8346D15994D056DBDDCCBEA15": { "file_name": "driverquery.exe", "file_path": "C:\\Windows\\system32\\driverquery.exe", "hash_md5": "E9AAEFB8346D15994D056DBDDCCBEA15", "hash_sha1": "A498528978CB4755A648957EC72DDA8C5ADB289B", "hash_sha256": "6696BF1B9D15F90031DCDBF5F227C137CE9A85F5459BDC2D9B906D93B216E055", "hash_sha384": "466C9D745850925423CD9940CE57FAAA22AE5920811057893C7EAC924343B8BCB1852B1F06F7FED9B495DD20D0376C94", "hash_sha512": "0F891C80C5D1C644DCA91099485C9DC5612A79D3981993CA403CC69DCEC6B17B8B78009520C645EEF34F9EE28D97927565CACC83EED36D4B67B6E8CB61F52E33", "hash_ssdeep": "1536:75Z6gasNisfWv1kBDvPxKcKLcc3CjSJZjDWIl6ngSmjIOxhe:79Li2zx6LcnGKIlWMEOxc", "hash_imp": "48FDE118F6EA9360334916CF78D8BD4C", "hash_pesha1": "E2AFDD227CA5B1E165F23E16178513CFE19A3E2B", "hash_pe256": "965F9AA3B81BB3F6D6107146FBC007D036F486C8AED5B5850F39828B70454A8D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Queries the drivers on a system", "meta_original_filename": "drvqry.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/6696bf1b9d15f90031dcdbf5f227c137ce9a85f5459bdc2d9b906d93b216e055/detection", "output": "\r\nDRIVERQUERY [/S system [/U username [/P [password]]]]\r\n [/FO format] [/NH] [/SI] [/V] \r\nDescription:\r\n Enables an administrator to display a list of \r\n installed device drivers.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context \r\n under which the command should execute.\r\n\r\n /P [password] Specify the password for the given \r\n user context.\r\n\r\n /FO format Specifies the type of output to display.\r\n Valid values to be passed with the\r\n switch are \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" \r\n should not be displayed. Valid for \r\n \"TABLE\" and \"CSV\" format only.\r\n\r\n /SI Provides information about signed drivers.\r\n\r\n /V Displays verbose output. Not valid \r\n for signed drivers.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n DRIVERQUERY\r\n DRIVERQUERY /FO CSV /SI\r\n DRIVERQUERY /NH\r\n DRIVERQUERY /S ipaddress /U user /V \r\n DRIVERQUERY /S system /U domain\\user /P password /FO LIST\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"DRIVERQUERY /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\driverquery.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "drvinst.exe-14ABEDA67965D38555E35B1A09315CFD": { "file_name": "drvinst.exe", "file_path": "C:\\Windows\\system32\\drvinst.exe", "hash_md5": "14ABEDA67965D38555E35B1A09315CFD", "hash_sha1": "37F857F6A6CCDBEC61A1420F86874B1F1320F960", "hash_sha256": "E14F9DD7D33F19F7ECE9BD23B239043CCC41CFF0BD2CA0CC5B15EF66DD82C7D8", "hash_sha384": "13E9C4DEE55C34610E22DA03E722F915F09FDA9998C0DA3613BF8F51D5256E4D2BE4AEB13B77B32EA5CFD4A04D77ECA0", "hash_sha512": "F663F7A78E6155059B454EB955AE672EEFF5B3B83FEDF13AA03F1AEA6EA3834202B25037997F0F0549ED5ADAFD3605B3302A7C9BD199AB6BEF361472D7B3201A", "hash_ssdeep": "6144:DS0KCMjkeQhgYXnjtx/YyqR8ovhVgBD3+XFQsGfTl3JJ:WFRQdnjXAyqWovhySFnGfJZ", "hash_imp": "A731DE6D9DA28E5FE6670C4FA7835CE5", "hash_pesha1": "9FC7F105E2A5DCF461AF3C566F87D045AE1C7949", "hash_pe256": "AB85D8544CE976C94877A0E080124FE447B5A57867F21FC0E54374116BEF2F8F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Driver Installation Module", "meta_original_filename": "DrvInst.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e14f9dd7d33f19f7ece9bd23b239043ccc41cff0bd2ca0cc5b15ef66dd82c7d8/detection", "runtime_modules": [ "C:\\Windows\\system32\\drvinst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DsmUserTask.exe-410C2E8839611762EC62385B8E947657": { "file_name": "DsmUserTask.exe", "file_path": "C:\\Windows\\system32\\DsmUserTask.exe", "hash_md5": "410C2E8839611762EC62385B8E947657", "hash_sha1": "9CD7EBBDC724A8552B6090E68BB52ADB931979E6", "hash_sha256": "88352FB0B4550A4A8C24CFC2E23F6DB551BB60C41B2FE3DB0797A3B7B10E6064", "hash_sha384": "37BA9BC4C0FB51F1FC12EB5076BA48A15E67218ABC023B0BB5859C5B922E8BC10E7EFCC922B15348B57092C98646D519", "hash_sha512": "4AD58BC5D5E6806603DDE43FA4B594878980A61E4C9E4663FA2000B0FEDC3929499FAC0BE00D330179A8A00717A2E86F92F8A5EA1B56E87DB67A5312D0111A2F", "hash_ssdeep": "384:9FXqQSy4rsB0KSzp7FU+Ih661dx+3kpyHujQWizW:9AZy4rsbSzVFUNs3k8H7", "hash_imp": "FA06392965404FA424A5FED87A4FD79F", "hash_pesha1": "A309E0372B381A1018432D2AAA626C8CA6596ED8", "hash_pe256": "B6BA5A32DAFFA96C27B935E9AF2DCE24975B826B9A72F99F0526C1DBBE927689", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Setup Manager User Task Handler", "meta_original_filename": "DsmUserTask.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/88352fb0b4550a4a8c24cfc2e23f6db551bb60c41b2fe3db0797a3b7b10e6064/detection", "runtime_modules": [ "C:\\Windows\\system32\\DsmUserTask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\cfgmgr32.dll" ] }, "dsregcmd.exe-275D60543ED4E6CA39FB78DA0A101645": { "file_name": "dsregcmd.exe", "file_path": "C:\\Windows\\system32\\dsregcmd.exe", "hash_md5": "275D60543ED4E6CA39FB78DA0A101645", "hash_sha1": "DE5A012F4CECC38B9031E10F7834FA8B5AA05D8C", "hash_sha256": "3AB0BD7713BFEFD5B8C3C9614EE62F7D6C66D57D6408D20D54CD994E38C29C83", "hash_sha384": "245293B1A5BE6F648EE1DF904617463CCA2985289CFA1BA80FA4CB6165375E5FA618A83494971DCEEDC5A8E0CC2849E6", "hash_sha512": "CB71DAB4A3AA3ED650E8B550DBD5846753A3FE3523713B6ABE92C06D9B18E683D03E0ABB61B6216CD48661F1EE7E67276377A967AAEE3EC67728117DE83C0B26", "hash_ssdeep": "6144:/bo3h/Ww1LMBsQ7vyp4A96qdfOQvLwvtl7jxXZ9D5OzNkRMPpZlJcG+X:EMw2BsVpx96qdfXEvtRpkuSxk", "hash_imp": "C2D1A2C9FFEA6DDBC11DE8E37CF589D3", "hash_pesha1": "560F1BC18C431D35F51E74C22F2D748911D42BAE", "hash_pe256": "A87A76C163EF3A4F1DBFB9A7B33AB72F6E4CAE0D517045F96A8ED48A4489531C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DSREG commandline tool", "meta_original_filename": "dsregcmd.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3ab0bd7713bfefd5b8c3c9614ee62f7d6c66d57d6408d20d54cd994e38c29c83/detection", "output": "DSREGCMD switches\r\n /? : Displays the help message for DSREGCMD\r\n /status : Displays the device join status\r\n /status_old : Displays the device join status in old format\r\n /join : Schedules and monitors the Autojoin task to Hybrid Join the device\r\n /leave : Performs Hybrid Unjoin\r\n /debug : Displays debug messages\r\n", "runtime_modules": [ "C:\\Windows\\system32\\dsregcmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dstokenclean.exe-79546C85EE91F2AEC0B1BC79B07AB154": { "file_name": "dstokenclean.exe", "file_path": "C:\\Windows\\system32\\dstokenclean.exe", "hash_md5": "79546C85EE91F2AEC0B1BC79B07AB154", "hash_sha1": "494F1D9531606C7F7DF71A95B8963D15B4376AEB", "hash_sha256": "CD3BD705613B8CD0F25159B32ADF38F73FD0B5BB9F384C08BDE8214509E0D716", "hash_sha384": "FA3D26AF66DDB3A5C3AEAA020D4D570ABE6F7B92B9018ABA1FC853195DBB51C462E95C80FFD21F288E298948557EF7E7", "hash_sha512": "EAC0DC9DE9CDB24FAB3477586C1E1415294398A7977940AD4FDDC9ECC5D4B59F48EC3027B31E98B395A483358D38B559320D7AC1DCCEE848FBF24B6B508E2B4E", "hash_ssdeep": "192:kLQTJkVb81LGCtZOBuvdrryIzv9WrGt7Wd2elV2AZVAlWuEW:P10uDOAlrZbgrq7WTV0WuEW", "hash_imp": "F1D06B8C52F369E9C51A17B21E2BD700", "hash_pesha1": "668AD2BF0B48CE543B3429770F99779D244A1602", "hash_pe256": "2C9265BEF4EB15425B8B73DC8F1E822C3EEBE864AED8323C76B12C203B43B274", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Data Sharing Service Maintenance Driver", "meta_original_filename": "dstokenclean.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.84 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.84", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/cd3bd705613b8cd0f25159b32adf38f73fd0b5bb9f384c08bde8214509e0d716/detection", "runtime_modules": [ "C:\\Windows\\system32\\dstokenclean.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DTUHandler.exe-8C39A00C7D56DDA973430424EF88C09C": { "file_name": "DTUHandler.exe", "file_path": "C:\\Windows\\system32\\DTUHandler.exe", "hash_md5": "8C39A00C7D56DDA973430424EF88C09C", "hash_sha1": "9DF0BC17D34C84F8F2AF91E963EBB55B5320C702", "hash_sha256": "72B7B45DCAB185602D127CE4E70CBAEE63F83D7C9F16A0B82B559888481CD39E", "hash_sha384": "72D61BC78FE47D0F0980A8698E5C2096D5017F0DF706DFA1E9B20EBDA29BACECCF8C7937BC3A616611E7009A2FBDD617", "hash_sha512": "655D48772EA793A6C3E3381BA30BBACAFC1EA2EDF12B2059D22034CE47C0E1ED0B45B4E009D5FEEBDF6EBF7FD18EA5382A481C35E81476D28D46A152C445C7FD", "hash_ssdeep": "3072:/5rWLgiea7x1erD5Lh4v53l7x9OLzh4bJurJ/pJyeoHpMLCDtamBZg11PD3wsoXm:/FWLgNaN1C5Lha53UCDtamBZgXoXCR", "hash_imp": "D6A23E2DBCECC3A6B227BCA1AC686B59", "hash_pesha1": "EFC4A3C59E466A52C1DA56D154E0CB2A66443633", "hash_pe256": "84EDDF36D8C38F74EAF263F5907F1A29C074E86BAAF1DD10E5840A0EA5704E9A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DTUHandler", "meta_original_filename": "DTUHandler.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.153 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.153", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/72b7b45dcab185602d127ce4e70cbaee63f83d7c9f16a0b82b559888481cd39e/detection", "runtime_modules": [ "C:\\Windows\\system32\\DTUHandler.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\OLE32.dll" ] }, "dusmtask.exe-A9BE64A9C8EA10E9C6864D1694244F98": { "file_name": "dusmtask.exe", "file_path": "C:\\Windows\\system32\\dusmtask.exe", "hash_md5": "A9BE64A9C8EA10E9C6864D1694244F98", "hash_sha1": "DA546D4C11674C8EF1A98915B0C60A0F664B3343", "hash_sha256": "C604F3C971220C04DB7ACEBE9585C49AA55718C16D042E6B67F76485EBE65477", "hash_sha384": "7CBF1503FF7648E744CB1A8578D5B8CD9E0A062927DD3C33BB524E0BE6DBF98A1129194FE450F62FC212F4AB0B03C1E1", "hash_sha512": "A416F57FCFBE74240EE4F49C5FD7DD4F2E4D789A426BC603851417F26CA6C0C6ABBD1E53FD9354F215F2B0FFBF9900532FB368476E39FC725B91348754A60EBB", "hash_ssdeep": "768:i+RfQscyF+z3eCT1iZXEOJothC50/ASGUJlvVrnIrztl3RU/zZ+ylgsSK:iaA3eCT1iDJ/SGGCH3RCJzSK", "hash_imp": "0117BC2CEE4D5D2EDC11E21FB6247FD7", "hash_pesha1": "B45E8FDD4EAFD9ACA642570A5785896E4BC47748", "hash_pe256": "C01FC39EDFE97490E2676EDFCB06A324671EBF91A73F4ED49627E8A28A82C726", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DUSM Task", "meta_original_filename": "dusmtask.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c604f3c971220c04db7acebe9585c49aa55718c16d042e6b67f76485ebe65477/detection", "runtime_modules": [ "C:\\Windows\\system32\\dusmtask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "dvdplay.exe-B7FF9DEE35818D7C2780D3897963D787": { "file_name": "dvdplay.exe", "file_path": "C:\\Windows\\system32\\dvdplay.exe", "hash_md5": "B7FF9DEE35818D7C2780D3897963D787", "hash_sha1": "E92DA782D0B1B03E6484604D5A1518027E58CEA2", "hash_sha256": "59576775D8A06038BD9975903418AEBF003F075D82F1F109FEADDAB8877E3C20", "hash_sha384": "B7552C9FE5F52BDF12659027F53B61B65589FCFBBF3F92DDEE760B577018A6996FFF270E317B83CC1AAEBCBD32E356CC", "hash_sha512": "BE1EEA964C35EB4716E286696E6F559C6BA9459CAC27073299EC5634FFC628F2F88F5DC44284673D057EC5C1DE9F4DED53546640C1394528C155A93EFC6ACC9D", "hash_ssdeep": "192:O0Lw0ZGSOrYHMVEkx2dPZ3rHIQ1qgxZMCPEq6lFsAmQPjhFioWSZW:O0BJgkLS2dh3Utqjl8hWSZW", "hash_imp": "9D517BD4783BA5BC3C67F3120C6BA649", "hash_pesha1": "4E9C14E4FDA05E1268C9943A9880EC220835065D", "hash_pe256": "3E310D1CFFE01E87D5351952180692D452B48C4C78BDD37C68EF3A80EE7B5A88", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "dvdplay placeholder Application", "meta_original_filename": "dvdplay", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/59576775d8a06038bd9975903418aebf003f075d82f1f109feaddab8877e3c20/detection", "children": "wmplayer.exe", "runtime_modules": [ "C:\\Windows\\system32\\dvdplay.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "dwm.exe-7260B06613BC480862F379FF5CCD58B6": { "file_name": "dwm.exe", "file_path": "C:\\Windows\\system32\\dwm.exe", "hash_md5": "7260B06613BC480862F379FF5CCD58B6", "hash_sha1": "90BFD3DCAB257A3B16EB46E8135B3621B6A7BCBE", "hash_sha256": "18B84DF6110F4A23660A256E558BCE4F5FC0D47678E4D1F9F8188DD490E5B293", "hash_sha384": "0291169F028867034811641137BEB5E436B7FD10CDCB8490640C810EC1B31C01523E4EA0A6628530B30DE6F27C3AD777", "hash_sha512": "AE1C1EC018A2AE4995B0A1F9B45FCDCF15F4D8488BD7717A432D84B92E35337F22E8032D5B280E25869449FEC392F977ECF86C28D9C16E4222BA4E8BB5C463B4", "hash_ssdeep": "1536:/czc/VgKoRvi74qJbCVRilfB/od7lE58ohypJpbVHYGQfAmrERRrg33ALvar:cvi740pB/4lEgpbVHYfACEjQ3ALar", "hash_imp": "154ED7B525A399CB7070EB8FD0DFC4DE", "hash_pesha1": "7524DBAB7F0D5861BCC3277E8CDBE9611EC130AD", "hash_pe256": "4CB2AD8AFEAF0C9677E2A5B8D627BACE2239FE49E3558BB4324C8C0A336A1079", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Desktop Window Manager", "meta_original_filename": "dwm.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/18b84df6110f4a23660a256e558bce4f5fc0d47678e4d1f9f8188dd490e5b293/detection", "runtime_modules": [ "C:\\Windows\\system32\\dwm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\gdi32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "DWWIN.EXE-F4F5AF932AB98E8953A288DD8B03AFBF": { "file_name": "DWWIN.EXE", "file_path": "C:\\Windows\\system32\\DWWIN.EXE", "hash_md5": "F4F5AF932AB98E8953A288DD8B03AFBF", "hash_sha1": "32BB1611BCCD7E1D6DE437A33681216C1CBB78BF", "hash_sha256": "32BE8352E1E158BF893E9A9E49D91178DEA7FB16025D669FAF4E2BC9FAD988E6", "hash_sha384": "D8C8E02B383EA0E314E7225FE91394E27E990DBBFA7AC2BB0D648EE1F4527D4DFF228ACCAA0BF41994DC50723723146D", "hash_sha512": "A23E9659074FE3FA8DED21660D3ED3634D38B39BE91F6FDE319F9FE619943306734C30DFDBCACFBC156383E0C216FDFE1078DBFAC7726FEC05F0A37CA1CC406C", "hash_ssdeep": "3072:Lf+lhn9C/wBbG6/nvUjMlfbpyClJdvtLySs5lM0RbT2VXVaMwA74s7iTxf1zHcz:Mhn9SwZnUjYpPBtLi5lM8OVXlp7it1z", "hash_imp": "FE9551C19FFA0B0B4EC670BA900DCB7F", "hash_pesha1": "5A91C9B79EB8B831E25E221BECB2774C9D23451D", "hash_pe256": "B9CFF34735B2DCCBE7784F2A2C0138BA8DBBE1E57671F255461A6E5512340F6F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Error Reporting", "meta_original_filename": "DWWIN", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/32be8352e1e158bf893e9a9e49d91178dea7fb16025d669faf4e2bc9fad988e6/detection", "runtime_modules": [ "C:\\Windows\\system32\\DWWIN.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\system32\\wer.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "dxdiag.exe-19AB5AD061BF013EBD012D0682DF37E5": { "file_name": "dxdiag.exe", "file_path": "C:\\Windows\\system32\\dxdiag.exe", "hash_md5": "19AB5AD061BF013EBD012D0682DF37E5", "hash_sha1": "12D398377984569695F4882C5734D5A7CFD727DE", "hash_sha256": "B3C1048DF7A2292798EFCAD66B3400C5C3C5747E8F09993621FD0DE7B33A159C", "hash_sha384": "3C224B1C8AE1847A1908936760FC76F48948F3ABAFA77A3FA738DE651CE421C4ACB6BCB33FCEBBB9F067ED1318040482", "hash_sha512": "2142C9F06A87FF8901705C022CA5BA0C768BA4484A32DB596361D04C149B390191BBE05392BCB724FC9F2B172C2817F7B9F9FECD130A4A894FEA5D72ECF10647", "hash_ssdeep": "6144:kVzfxC1imqncQXy9194csa8iy9JBl6glJVJ3UkvhZ3P:t1iJckY6hDUUP", "hash_imp": "6B783B76A766357333E369590AB75C80", "hash_pesha1": "B1C1DBBE0476C8DD46E89332F094E5D0C49AD2A5", "hash_pe256": "34FA29C4BA811485B176351EFD1E93A1681C824A2E1371E75FB4E33E62E7535C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft DirectX Diagnostic Tool", "meta_original_filename": "dxdiag.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b3c1048df7a2292798efcad66b3400c5c3c5747e8f09993621fd0de7b33a159c/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\dxdiag.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\dxdiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll" ], "runtime_window_title": "DirectX Diagnostic Tool" }, "dxgiadaptercache.exe-885AFAE1B0904558BD658598358F2A33": { "file_name": "dxgiadaptercache.exe", "file_path": "C:\\Windows\\system32\\dxgiadaptercache.exe", "hash_md5": "885AFAE1B0904558BD658598358F2A33", "hash_sha1": "5CB5D0D0376AF92156187C1316ECB6D38BDA4A22", "hash_sha256": "7EE345476D996E05E7D7519E0639ABBC6D23011B5C38BFDCC63AD89D1352270A", "hash_sha384": "F874FEB7D3E7D34BD0689162AD8792BC5D8FE65078B6FBF766A24EA08807CEDFD426452D17BC6FB6A032A502194ED5DE", "hash_sha512": "5B000AA628B74DF182D9FE205D58F28152CF9CEBCBF355762574E3E5A3EA4343F96B0460E5FC06380C29D3126C63C48181280CB960CF5C58438F3298814C2FC1", "hash_ssdeep": "3072:lO9kc/ycfe6PVl3F4MTHNdDsajAOccfVchonwy42e8GwIlp6+ISzsdPhpg63Evem:lO9ndRP7F4UXD+cfJnwy42coMGtRJ", "hash_imp": "FFB8C8134BBB1572B7BDBEA1214AE140", "hash_pesha1": "B493B45B5BFB537275A9A0C7FBB085726AE0629B", "hash_pe256": "08A2A5C8AFA7D19EE1275495357C5BE829E6DA3D5158CDAF6BD98D551BA779A9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DXGI Adapter Cache", "meta_original_filename": "DXGIAdapterCache.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7ee345476d996e05e7d7519e0639abbc6d23011b5c38bfdcc63ad89d1352270a/detection", "children": "setup_wm.exe", "runtime_modules": [ "C:\\Windows\\system32\\dxgiadaptercache.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\gdi32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\d3d12.dll", "C:\\Windows\\system32\\d3d11.dll" ] }, "Dxpserver.exe-9E93A82FF36FF36303D66B581913A06A": { "file_name": "Dxpserver.exe", "file_path": "C:\\Windows\\system32\\Dxpserver.exe", "hash_md5": "9E93A82FF36FF36303D66B581913A06A", "hash_sha1": "47435B950803E3FAC5E6459F7DAD861CCE86F6E4", "hash_sha256": "AED8102FDB7970D607F0A8B525F9240E26D106B6B2B0DCF2B529A1D8D8E3F2AF", "hash_sha384": "A1B8E6A7DD97491987CA84DD21FE84A7682F3F456B9805B56233403C1AC5A48BE901E1B9465D9D2D9DD8E8CCD2BE256C", "hash_sha512": "8F2C31DBCD072E825C23FD1DD9030F9CCDB53650C4368D2DACFBDC168747CBDEE6BCF3957B29F6A9A36D1EA8A067E8E591C831E52CA332AAC5E3CD9A48015394", "hash_ssdeep": "6144:k8ENbqHxsWQWikMMiJBYnT24EbFHdYLY:k8ENbwsfVdJBYnTCY8", "hash_imp": "F42C8BCF261DFCA473236A3B0B22F25E", "hash_pesha1": "ED04D4A5089EDE010D3F051F3264DA2E93B3502B", "hash_pe256": "6D0689F5E32A61729C95A4E6B1D177AD6744899A20D2CC555F901529914115D6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Stage Platform Server", "meta_original_filename": "DXPServer.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/aed8102fdb7970d607f0a8b525f9240e26d106b6b2b0dcf2b529a1d8d8e3f2af/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\System32\\en-US\\dxpserver.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Dxpserver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ] }, "Eap3Host.exe-F41A134FE68E9A86510BF931D4366DD7": { "file_name": "Eap3Host.exe", "file_path": "C:\\Windows\\system32\\Eap3Host.exe", "hash_md5": "F41A134FE68E9A86510BF931D4366DD7", "hash_sha1": "D8836537F091BDBC3C3F4AF3BC8B93EFE0463CD5", "hash_sha256": "11794657DDA144B9A8D07BA5AE0868D2ED7AC47CD7559B68A49A51050E229780", "hash_sha384": "2112F9E08B02B7C2FA8D93C2D021B93F44A905BD059156A1B708A5CAA91E913BEB01D083A4242CB15EC8E1AEE7E3F202", "hash_sha512": "7ADAA97186B729D09E6DE3023CD5D5E6343CA52701C07C5CCAEA2706877D0BE4C54DB472D3A5CC1FBEBC3071E06063563BBD5CC3F0EBF9E2252AF20AAEE61A3D", "hash_ssdeep": "384:lEVw7Sg5b9iHk2/317pOnqKWU6znNO84ga5WuaW:l/OoYHk2/3GnPWR5O84gaP", "hash_imp": "39A0A62D4EC9FCB9DC7B3B19151FB19A", "hash_pesha1": "52107B2B56A68858B091A34DDA5EEFF4C5890948", "hash_pe256": "F8BDE6D0C4228DA5457A4F5DCAE24AA0320D57A811A3BBFDE89F3AE7A30DB789", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Eap Third Party Surrogate Host", "meta_original_filename": "Eap3Host.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/11794657dda144b9a8d07ba5ae0868d2ed7ac47cd7559b68a49a51050e229780/detection", "runtime_modules": [ "C:\\Windows\\system32\\Eap3Host.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "EaseOfAccessDialog.exe-12C2E7BF90782B6E9D36D9DD59FECB84": { "file_name": "EaseOfAccessDialog.exe", "file_path": "C:\\Windows\\system32\\EaseOfAccessDialog.exe", "hash_md5": "12C2E7BF90782B6E9D36D9DD59FECB84", "hash_sha1": "7531542AAEB12F0DDA9A258FA2514E1DA15FCB73", "hash_sha256": "B15BBF698EEEABCFA91B7BD5A42BA7C1AB8C801BCC1C5A971A7E81D8C97989F6", "hash_sha384": "62929207BFF737ACF7A0898C9D6C9D333789FB1226529B52824CAC9C6E131578AA2C05BF15115FDBA7E46A632CFC38CA", "hash_sha512": "57380C5105228C477A9027BCC5DAFF718E05ADC4131574E3C3974ACDF771B62B942770C4A524953FC122F7101C84AEBFAA2748923D5C44666CF7359309A4646B", "hash_ssdeep": "1536:g2obuXQTUeVFNcE5NPpGo33ZFH7m6vMjFlxSL28ByA239RccNldG3AnF/R2E3tEk:auuU4DKTRP5h3TcOR2+Hj/ZlsxY", "hash_imp": "7F4F4EC9CB00CFFCCC3EAF21600E3F37", "hash_pesha1": "A94E3B1388BDCD211CFBC94F102BF27C4F966732", "hash_pe256": "C169E99432DCAB0EE892C9586EA1841DFDBA8E01C0022F2FA1AD33EFE9A58084", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Ease of Access Dialog Host", "meta_original_filename": "EaseOfAccessDialog.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/b15bbf698eeeabcfa91b7bd5a42ba7c1ab8c801bcc1c5a971a7e81d8c97989f6/detection", "runtime_modules": [ "C:\\Windows\\system32\\EaseOfAccessDialog.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\OLEACC.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\SHCORE.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\DUI70.dll" ] }, "easinvoker.exe-82EF69ECABF12160625A6BA15D2A2671": { "file_name": "easinvoker.exe", "file_path": "C:\\Windows\\system32\\easinvoker.exe", "hash_md5": "82EF69ECABF12160625A6BA15D2A2671", "hash_sha1": "5E590F68D63BA7DDF86C822498FAA944A4E0990A", "hash_sha256": "4AB78DC788CEAD8F20227C9E2ABFBEFD5E74C64C85677C505AE7E694B7D41565", "hash_sha384": "08992F7E6D2E042F3F712D297CA555DCFE2BB07CED0EF474AD0B2414E8B9D336AE78313FED9E7C8274E303DD2A79DB0E", "hash_sha512": "1881A5F8AAFFAE5B4E549F0C905C36B3736911A426D024E11ED9541333BD9C5B02E1CEA7309C906B575FA2C8EF98B84ABFB3D087D55DE7C0E0A00445F0C40FFB", "hash_ssdeep": "1536:FvMYKUtUZn/0q9+DaVu2xXibswbTYWXUZf8y8vPF:FNd+cc+D2u2xXibswbzXUR8TvN", "hash_imp": "A80CEE60EFFA9529BAF16EE52FF52B18", "hash_pesha1": "3558E552C88A80A88533B6B4EE7E416021E108D3", "hash_pe256": "2607AAAACA8C2893444BCF79E37AFC7556C6F8A2215F40A75B3B443074185702", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Exchange ActiveSync Invoker", "meta_original_filename": "easinvoker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/4ab78dc788cead8f20227c9e2abfbefd5e74c64c85677c505ae7e694b7d41565/detection", "runtime_modules": [ "C:\\Windows\\system32\\easinvoker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\system32\\AUTHZ.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\system32\\SAMLIB.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "EASPolicyManagerBrokerHost.exe-0C029B03C81C2FBEBE29AEDEE4A82F98": { "file_name": "EASPolicyManagerBrokerHost.exe", "file_path": "C:\\Windows\\system32\\EASPolicyManagerBrokerHost.exe", "hash_md5": "0C029B03C81C2FBEBE29AEDEE4A82F98", "hash_sha1": "2267E137BD97FE8D90036973D1A110D34BFDB403", "hash_sha256": "01A3961335775580390CEE8906DE0B73C9BF38C908737618038F0B8CC59CAC8D", "hash_sha384": "1B6787361C89C0279455C19E173CF7127935B13A9FB1782AE49A3BDBFAB2F04AD9238E9D88AD82B84B9F9295E844E14D", "hash_sha512": "A45C51DC2C3B0FE36D941AC66E6E2687C3FB8DD61642586241C4FF8432BD88A5B759D2CD1D9E149648E10BE4FD13080C2AC9B9B0F9A4DAF8EF4A6DC62F362723", "hash_ssdeep": "1536:Zc+mEZ2tVhXMDHcz+HsniO6WCp+Hgaax:HEScz+MnTo+AaK", "hash_imp": "247A62F930C6646E6F2E8EE408142FFB", "hash_pesha1": "A2D1B44CF623994FA15AB678E9A97CD16471F49B", "hash_pe256": "8FE8A38FB16D4E25DC9F82303D8CB863797F3E7847E51ACB6B4D8F075394FFC4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Exchange Active Sync Policy Manager Broker", "meta_original_filename": "EASPolicyManagerBrokerHost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/01a3961335775580390cee8906de0b73c9bf38c908737618038f0b8cc59cac8d/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\EASPolicyManagerBrokerHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\policymanager.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\msvcp110_win.dll" ] }, "EDPCleanup.exe-A5E505DFC3ED5180353F6C448B390AE9": { "file_name": "EDPCleanup.exe", "file_path": "C:\\Windows\\system32\\EDPCleanup.exe", "hash_md5": "A5E505DFC3ED5180353F6C448B390AE9", "hash_sha1": "AA73B338F393954DF2643A4A59175C90A7578948", "hash_sha256": "CCE74369B704CE5768D8057BC54D2A429871BE0D42FDF7BD49F5C127FF5D9696", "hash_sha384": "9F97358FFB02C36D67033FFEFB8582E46EE00F9F4A437F95EA19966C0B1FFAF0B2AF96EDD358393D87670449BF744966", "hash_sha512": "09742699F35C2EE5E4C76106E9F83167D597A63E4E38B7AE8F780B019C0C3ABEF31FC550ADFF5113362CE2BEA27D4B9748F39AC4D0715FA711BF0D6D2BB99E93", "hash_ssdeep": "3072:xim8X+Pr7pPoi7ZetwzLiqR5UbMESkSYFw4pBFZHu:Ym8Xo3Joi7ZeeiqR5YSoxpBF", "hash_imp": "D9E5BDC7004B886C9D93408EEE1DAA54", "hash_pesha1": "759F3CABED0073AB561B1468F60914CB016A54AC", "hash_pe256": "A97554C16A723149864C5151365A6F444116143175B8D3F4ED2E10C5B91B2F33", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EDP Cleanup", "meta_original_filename": "EDPCleanup.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/cce74369b704ce5768d8057bc54d2a429871be0d42fdf7bd49f5c127ff5d9696/detection", "runtime_modules": [ "C:\\Windows\\system32\\EDPCleanup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\policymanager.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\FirewallAPI.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\profapi.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\system32\\DNSAPI.dll" ] }, "edpnotify.exe-6EECA58E87BB27973F645DB12C275A17": { "file_name": "edpnotify.exe", "file_path": "C:\\Windows\\system32\\edpnotify.exe", "hash_md5": "6EECA58E87BB27973F645DB12C275A17", "hash_sha1": "3A4FE2D1AE2152285F826D50F802EABB8FFE5857", "hash_sha256": "CD83E0891F6A928C05127E264B5D46E6808A77CFB369B51BEBFE390102CD861C", "hash_sha384": "905D76CCCD9DC594C5DDDDB63E4ACEC9494619084E20FCF6DA9B463DB25B2D444572CC2AE83653CE350A2159D3001B9F", "hash_sha512": "5741D7B46D1736494449F0D582240A07409853CEF40D3DBF8D10DF61F842EB9ABA4BD8A78A0BC11F7216D908F4266BF0B803485D817BF5A2DD5839017EF1EE54", "hash_ssdeep": "1536:pCGwA9ply3kgZO5qcMaXR1yFPh3iIDEtMa1Um7g:pCUs/JpaXR1yFPp94tMUUf", "hash_imp": "11D90D317ACD2AF99D552F6987B426E7", "hash_pesha1": "FE1C15F435057887A349D606213D71A3A8C43A32", "hash_pe256": "2BAA5E7DE24A7F65C8A1E282B876EF868129B9519FA2510494BFD7A3356366D7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Enterpise Data Protection", "meta_original_filename": "EdpNotify.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/cd83e0891f6a928c05127e264b5d46e6808a77cfb369b51bebfe390102cd861c/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\edpnotify.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "EduPrintProv.exe-F934BBA57ED7661BC892763F023EB54C": { "file_name": "EduPrintProv.exe", "file_path": "C:\\Windows\\system32\\EduPrintProv.exe", "hash_md5": "F934BBA57ED7661BC892763F023EB54C", "hash_sha1": "EA2B14A27DF8AA4F02B541FB1D426866D358B4FA", "hash_sha256": "1D3595FC64E37533FBBFC26EA27E6F66420759BD9341321435A5872ECFC13D8C", "hash_sha384": "831857BCCC57A303FE9F2C40C2E97D205E1B2CBD504125CAC30C2D4AFBD6CCC901CABD7CF8B54B0879F592214FF5B358", "hash_sha512": "CD25310DA12D7F4CC5C19F116E620B1A01F63D95BD69CA3D777AD5770723FDF70CE9B810EF35F34FA9A5F4BE2B1D266EC463AC9D99FF03FB9B1569B3F86C7859", "hash_ssdeep": "1536:MfHhAeoQeNhu3qg7P8i9pKaHiQVFmLfb6RemPLmRAewRXvnXXJj/4kigzpd8Xs+0:qZS0qg7kirNOeLLmRAecnXCktliXsJ", "hash_imp": "B1EFDB0538ABA103E3EA07F7B26BF021", "hash_pesha1": "5ACD7210FDE47588B6C8DB724747933EE3A82612", "hash_pe256": "F14198023366D149CC4836AFABF58439A5E58DBC6B750D340CD3CF24811074B2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Printer Provision Utility for EDU", "meta_original_filename": "eduprintprov.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1d3595fc64e37533fbbfc26ea27e6f66420759bd9341321435a5872ecfc13d8c/detection", "runtime_modules": [ "C:\\Windows\\system32\\EduPrintProv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\policymanager.dll", "C:\\Windows\\system32\\deviceassociation.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "efsui.exe-64F5611CC62E65748D140E6F288CE1EA": { "file_name": "efsui.exe", "file_path": "C:\\Windows\\system32\\efsui.exe", "hash_md5": "64F5611CC62E65748D140E6F288CE1EA", "hash_sha1": "D337D3576AE4B7495F1D58926868AF8BF296CF87", "hash_sha256": "EC1DC1A2EE200DA0C787328DF4FB91A2B978FD09CA1F83F3E55994C0F9BA1D11", "hash_sha384": "8F94558DEC914E27A6363AF27F2AEE1D63D9F649879B6FDA3F9320C828A42D94AEA9B7CE8BA02FE8F1767B6881A3A26F", "hash_sha512": "FC6B6B635066A1F9CCB17F149CAD54AE4688C98B7611BA00DBF024B97AD9353B03D5B92D6E675F9EC2362810A63B85220D0DDFD9C8C043768DB4A9DABB44839B", "hash_ssdeep": "384:cMmmp5Wrd9uJuBE/otMLItH0f/Z4TxWSDRW:cWLA9guBEd0HA/Z4Tx", "hash_imp": "79780253655B3282FD06EA62FCA2F32F", "hash_pesha1": "E4DA76CC399A4B35FEDB4079747558AB71368971", "hash_pe256": "7F0B6B8C2099BC07D87FE6352E045787075A7552C2033ED56D2055C1AB1E1404", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EFS UI Application", "meta_original_filename": "efsui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ec1dc1a2ee200da0c787328df4fb91a2b978fd09ca1f83f3e55994c0f9ba1d11/detection", "runtime_modules": [ "C:\\Windows\\system32\\efsui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\system32\\EFSADU.dll", "C:\\Windows\\system32\\EFSUTIL.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\system32\\ncrypt.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\system32\\DSROLE.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\System32\\OLE32.dll" ] }, "EhStorAuthn.exe-D45618E58303EDB4268A6CCA5EC99ECC": { "file_name": "EhStorAuthn.exe", "file_path": "C:\\Windows\\system32\\EhStorAuthn.exe", "hash_md5": "D45618E58303EDB4268A6CCA5EC99ECC", "hash_sha1": "1F8049FC5EA8B57BB68E19FB55CB9DC1E18E9513", "hash_sha256": "D527323643BE9DF4D174C3169C6F2C7854A59B781654BCAEBD154CB51FB4219C", "hash_sha384": "57DFE94E79211C3FC6D2D076729B70AC9CE0449CBDA3D7D2076C78A96104CA3F19714EE8DDBEA7B573BCBAB10FC516C0", "hash_sha512": "5D7AE663DCFEDFAF00836DC018131851E5A40778BD582B417B9F0BBD4BB6D1B2EB8F37F7F5A01CD2BEED78B6037EF6EB2A3290248D5E901173B1407990A202BD", "hash_ssdeep": "3072:Vf8h0Gfm1y0Mx3JOlaEHPxPxQZDFcZIZ:Vfu0i17OlaEJPxQZDFZ", "hash_imp": "781D28469BB74D268EAF05BBBB5DA822", "hash_pesha1": "9B4C98D9F3B8493396E42CDC5B906FC99F3903B4", "hash_pe256": "14F4524AF26B09287AE096568356021C79062D833774BD292A19D5A28B54A512", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Enhanced Storage Authentication Program", "meta_original_filename": "EhStorAuthn.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/d527323643be9df4d174c3169c6f2c7854a59b781654bcaebd154cb51fb4219c/detection", "runtime_modules": [ "C:\\Windows\\system32\\EhStorAuthn.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "EoAExperiences.exe-606FCD6F83436A5F7244F7199673BCF6": { "file_name": "EoAExperiences.exe", "file_path": "C:\\Windows\\system32\\EoAExperiences.exe", "hash_md5": "606FCD6F83436A5F7244F7199673BCF6", "hash_sha1": "4C82B58198734839AE2EA4A922A92AB26E18A4E4", "hash_sha256": "35139D3F51350165B3FDF50F2FE7229D516C2DEC1339B5D31B152CD85B4FCC78", "hash_sha384": "DCDD472ABF3EB58A577DFE4A303062935FA00D1B1F8A7EB633167F63B3BE9D29CF79C90529F8F89260D03BC5BB854D89", "hash_sha512": "DE406900095D5C58A264EEDCBFA90A39B46B10B0CD0FA1FB06F928088689C2B2E0EAFE3978DC9CB2CCE5060EF60070BE503BEA66EC21928C186CCF67ED4DCC9E", "hash_ssdeep": "3072:lRrEX85TtwQ+MaLOzJGObzLG6GsD3Rg/Qqf:fr9twIDbnG74q", "hash_imp": "D46678B9B998F5730B05D75E27442FE5", "hash_pesha1": "8561CB37BA53063A7C4B74A9C0D6E6B01480E6D1", "hash_pe256": "D4DFABD9AA09BE0D4DF8F8EDF2474E5EBC678CD9BDB96B34909ABB09BD696A8E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/35139d3f51350165b3fdf50f2fe7229d516c2dec1339b5d31b152cd85b4fcc78/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\System32": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\EoAExperiences.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\uiautomationcore.dll" ] }, "esentutl.exe-E2098B56CF093E165D030E27591CE498": { "file_name": "esentutl.exe", "file_path": "C:\\Windows\\system32\\esentutl.exe", "hash_md5": "E2098B56CF093E165D030E27591CE498", "hash_sha1": "C1C23E7EF3E0C428AD776A25FA556C776078997D", "hash_sha256": "753FEB8E2BC07B6ED0E3BA836A33EC3C6F097A237FB9D48C23938892C8A16F4A", "hash_sha384": "36892754D28AA22B5322627092E05168745AB02C1882D7B0488437E2E9CDD3D9468B62F6D2941B8A9248C77815386B52", "hash_sha512": "497521AC2F1F5AE4B1A264950C693FCADB8EAC9B421E33FDE2BD69368F1CFC813D8EB24C280BF03550DB552E9CFC0B9751DEA0C9DDB67BE9B95EFD9A0C90914A", "hash_ssdeep": "12288:8Rk6AXIHw5djFUHsHSdsm89sWqiG0UXd1jU:5IHMdRUOSdsm8eWnG0UXXjU", "hash_imp": "46B1EC0A16C340EBA5EDDD8E6BE9B4F6", "hash_pesha1": "55323829765AE01806D605C43FC7826D9F3B60E4", "hash_pe256": "CEC36A128CB8ACCEE1FCCED7431DC28F0B4C1766BE82794ACFFDC66EE7E9CB23", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extensible Storage Engine Utilities for Microsoft(R) Windows(R)", "meta_original_filename": "esentutl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/753feb8e2bc07b6ed0e3ba836a33ec3c6f097a237fb9d48c23938892c8a16f4a/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\esentutl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "eudcedit.exe-A9DE6557179D371938FBE52511B551CE": { "file_name": "eudcedit.exe", "file_path": "C:\\Windows\\system32\\eudcedit.exe", "hash_md5": "A9DE6557179D371938FBE52511B551CE", "hash_sha1": "DEF460B4028788DED82DC55C36CB0DF28599FD5F", "hash_sha256": "83C8D1A7582B24B4BBC0D453C813487185C2B05C483BD1759EF647A7E7E92DFE", "hash_sha384": "5042D3A49882F14942C79749E8195BBE6F34923E903A9A4E9B5307D88E25E764F4EAA3424D31FD4173C9B4E90C53660C", "hash_sha512": "5790CAC8DAE16A785B48F790E6645B137F211C1587FB64EA88E743B846FF3A886324AFCFEF4BEBC61F869023B9A22BA925C461DFB2E12497B70F501E6B79153C", "hash_ssdeep": "6144:K+bClLWeHMY88wTC673qqG/JAbxfZcQJ1PZSqtYVd:MZMvXtGBAbVl13tY7", "hash_imp": "131F5E7B11F72770453B90271E4FE286", "hash_pesha1": "B5E7243EB6C4CCA19CF39CC8E45866D1E9C35ECD", "hash_pe256": "4F17AD06FF6F10A790CBA04C1CEBD24CBC2071ACDF5B2D662AABAB3D1AFC06A5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Private Character Editor", "meta_original_filename": "EUDCEDIT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/83c8d1a7582b24b4bbc0d453c813487185c2b05c483bd1759ef647a7e7e92dfe/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\eudcedit.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\eudcedit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ], "runtime_window_title": "Private Character Editor " }, "eventcreate.exe-091FFA3893661C5597CA719F28EE03EA": { "file_name": "eventcreate.exe", "file_path": "C:\\Windows\\system32\\eventcreate.exe", "hash_md5": "091FFA3893661C5597CA719F28EE03EA", "hash_sha1": "C80D0792ECFCA2113958C0A8805D3D99FDF58A76", "hash_sha256": "7CC501292377DC849A34214F017F62A7331F44F96BC6FE3E566253A9918BF811", "hash_sha384": "114A305B52470D8FD3E517B45A3B1341FA61E3A780BF628C7F005EBEE42B230EC5B952A608EBDE2DAA451E03D70D2092", "hash_sha512": "8503AD99472B223B4F10DE64A09E8B06A52FB785F102E10803FDB16AC675251C26FF1E4723B9E938B9DA24C10B71B4375906D86DC31AA154514C9D76A69023BC", "hash_ssdeep": "768:eEfda6X3VaOqeBHY9+NCmzr8lpyRX+lTHnXYQXFdZ6luOoaJamI/:jfd9OeBHY9RawznXYQX96luvacmI/", "hash_imp": "AFD01C6C03BABAB564D0A0CDA1CD4649", "hash_pesha1": "53151AAAD1F3D72C4B49DF82EB382AB514894612", "hash_pe256": "CAC761941BD0B6DAC5730357AC7372D7C11CB487C33086267E5FEB3FCBB9E3A1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Create - Creates a custom event in an event log", "meta_original_filename": "evcreate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/7cc501292377dc849a34214f017f62a7331f44f96bc6fe3e566253a9918bf811/detection", "output": "\r\nEVENTCREATE [/S system [/U username [/P [password]]]] /ID eventid\r\n [/L logname] [/SO srcname] /T type /D description\r\n\r\nDescription:\r\n This command line tool enables an administrator to create\r\n a custom event ID and message in a specified event log.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /L logname Specifies the event log to create\r\n an event in.\r\n\r\n /T type Specifies the type of event to create.\r\n Valid types: SUCCESS, ERROR, WARNING, INFORMATION.\r\n\r\n /SO source Specifies the source to use for the\r\n event (if not specified, source will default\r\n to 'eventcreate'). A valid source can be any\r\n string and should represent the application\r\n or component that is generating the event.\r\n\r\n /ID id Specifies the event ID for the event. A\r\n valid custom message ID is in the range\r\n of 1 - 1000.\r\n\r\n /D description Specifies the description text for the new event.\r\n\r\n /? Displays this help message.\r\n\r\n\r\nExamples:\r\n EVENTCREATE /T ERROR /ID 1000\r\n /L APPLICATION /D \"My custom error event for the application log\"\r\n\r\n EVENTCREATE /T ERROR /ID 999 /L APPLICATION\r\n /SO WinWord /D \"Winword event 999 happened due to low diskspace\"\r\n\r\n EVENTCREATE /S system /T ERROR /ID 100\r\n /L APPLICATION /D \"Custom job failed to install\"\r\n\r\n EVENTCREATE /S system /U user /P password /ID 1 /T ERROR\r\n /L APPLICATION /D \"User access failed due to invalid user credentials\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"EVENTCREATE /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\eventcreate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "eventvwr.exe-3A8EBEB41000296D44EDDF39A505F7E0": { "file_name": "eventvwr.exe", "file_path": "C:\\Windows\\system32\\eventvwr.exe", "hash_md5": "3A8EBEB41000296D44EDDF39A505F7E0", "hash_sha1": "C426A1490E469025F20F51939F157DC15E4D6AC3", "hash_sha256": "BE0D401C8B42024B0918394FAA0AA6B494EA537B3C6C2C62C3D9064929F6245B", "hash_sha384": "939F81DF42B460070915BFCE960E1179A80E1661E2221E5D7F50801B8E4B7D20EFB2D5FE162D13D7F889AC42554B14D6", "hash_sha512": "8275CFC0E9ED492429F3A604A65F611FA85BBF833994C659592F92077C3125F29E21F18E772AA6EFB2A9D0F5770EAD39BB5460FBC9D1BC07F825795BEBD96856", "hash_ssdeep": "1536:/gfEFLkT5IMfoJUhSU6nPlTggJ2oj71BgR/Vp8dY1/:/BFAF3lhzslTZJ9j7Heb8C1/", "hash_imp": "5843AE9886BB500E05E07EE59BB5AD42", "hash_pesha1": "1603FD5A3562DC20309A74C790CAE0478FEDE80B", "hash_pe256": "66750366EC45D12BFC50B249FD5D55C28062BB06A7ADFEC6C526F3F886F1AFED", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Viewer Snapin Launcher", "meta_original_filename": "eventvwr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/be0d401c8b42024b0918394faa0aa6b494ea537b3c6c2c62c3d9064929f6245b/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\eventvwr.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "Event Viewer", "children": "mmc.exe", "runtime_modules": [ "C:\\Windows\\system32\\eventvwr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "expand.exe-3080AD9250254478269B486EC15C25FF": { "file_name": "expand.exe", "file_path": "C:\\Windows\\system32\\expand.exe", "hash_md5": "3080AD9250254478269B486EC15C25FF", "hash_sha1": "56F145B564EEE207A542C142FF9C2FE56A131985", "hash_sha256": "210A43646B58A60035CEDC30281F3414DD6A551A62255AAC7EF828C5D7EA46CE", "hash_sha384": "C3706377DFB3C528786D70D75C9D90C828DD9D1A15AAA50DD0B2507C6F233C66381F8370D68F4600A9DD38ED0E1AB69A", "hash_sha512": "662F57AA91202AAA48282F099ED5DDCB9F7151E2E7733983F312823D4D5DDAE4506F3DB0F6BE7FE7D7DA49415197D3B982A0FB76777470A9A0B0E7EC004F4B9F", "hash_ssdeep": "1536:1HUJ90Qr1hzF2F5Tbmb+KEUlqHuikyMUn:qHh2fTSLfan", "hash_imp": "8BB8291E08A891E3DCA4B595B2F1D718", "hash_pesha1": "1076B64C749875C6166A3C18EF122DB42472BACD", "hash_pe256": "24AFE74B2B157088844DBF2D034578D09EC1760F99197E68068569F4B2AC6E14", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "LZ Expansion Utility", "meta_original_filename": "expand", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.00 (WinBuild.160101.0800)", "meta_product_version": "5.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/210a43646b58a60035cedc30281f3414dd6a551a62255aac7ef828c5d7ea46ce/detection", "output": "Microsoft (R) File Expansion Utility\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nExpands one or more compressed files.\r\n\r\nEXPAND [-R] Source Destination\r\nEXPAND -R Source [Destination]\r\nEXPAND -I Source [Destination]\r\nEXPAND -D Source.cab [-F:Files]\r\nEXPAND Source.cab -F:Files Destination\r\n\r\n -R\t\tRename expanded files.\r\n -I\t\tRename expanded files but ignore directory structure.\r\n -D\t\tDisplay list of files in source.\r\n Source\tSource file specification. Wildcards may be used.\r\n -F:Files\tName of files to expand from a .CAB.\r\n Destination\tDestination file | path specification.\r\n\t\tDestination may be a directory.\r\n\t\tIf Source is multiple files and -r is not specified,\r\n\t\tDestination must be a directory.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\expand.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "extrac32.exe-41330D97BF17D07CD4308264F3032547": { "file_name": "extrac32.exe", "file_path": "C:\\Windows\\system32\\extrac32.exe", "hash_md5": "41330D97BF17D07CD4308264F3032547", "hash_sha1": "0FCD5A3233316939129E6FCF4323E925E8406E5D", "hash_sha256": "A224559FD6621066347A5BA8F4AEECEEA8A0A7A881A71BD36DE69ACEB52E9DF7", "hash_sha384": "E2F07921D9BC80EF4120891A96B2B4A9DE86F8A8512BB3EE261B6320429E5B1964D5B0776084C6A67A18B31834B7C23D", "hash_sha512": "AE29E41C01EE6620FE822F9FEB3DD851617314CEC4D8EF750D2EBD2C61BD24FB54012146123F1FDF9B893F26E83CE5A17DBC5D3AAE42BB04DAAB6D42E82F2A04", "hash_ssdeep": "768:ovwYnkEtzFtV6F/+oPaGYVAVIoDxeaPbS2s6Hl4yA:cRfa+YaGYVAVIexeqbSIpA", "hash_imp": "9E8A016B1763601647B4DFBEF00DAC86", "hash_pesha1": "157E49FF299D661B1B09B667A9CAD327B8C4A5C2", "hash_pe256": "249AE9FCD78556E94F9A37F388890D5D48A583EA5895B7BC01EA0987D2454EAF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft CAB File Extract Utility", "meta_original_filename": "extrac32.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.00 (WinBuild.160101.0800)", "meta_product_version": "5.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a224559fd6621066347a5ba8f4aeeceea8a0a7a881a71bd36de69aceb52e9df7/detection", "output": "Microsoft (R) Cabinet Extraction Tool\r\nCopyright (c) Microsoft Corporation. All rights reserved..\r\n\r\nEXTRACT [/Y] [/A] [/D | /E] [/L dir] cabinet [filename ...]\r\nEXTRACT [/Y] source [newname]\r\nEXTRACT [/Y] /C source destination\r\n\r\n cabinet - Cabinet file (contains two or more files).\r\n filename - Name of the file to extract from the cabinet.\r\n Wild cards and multiple filenames (separated by\r\n blanks) may be used.\r\n\r\n source - Compressed file (a cabinet with only one file).\r\n newname - New filename to give the extracted file.\r\n If not supplied, the original name is used.\r\n\r\n /A Process ALL cabinets. Follows cabinet chain\r\n starting in first cabinet mentioned.\r\n /C Copy source file to destination (to copy from DMF disks).\r\n /D Display cabinet directory (use with filename to avoid extract).\r\n /E Extract (use instead of *.* to extract all files).\r\n /L dir Location to place extracted files (default is current directory).\r\n /Y Do not prompt before overwriting an existing file.", "runtime_modules": [ "C:\\Windows\\system32\\extrac32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\system32\\Cabinet.dll" ] }, "fc.exe-1C20087F983D01465FEA3A33EAB19370": { "file_name": "fc.exe", "file_path": "C:\\Windows\\system32\\fc.exe", "hash_md5": "1C20087F983D01465FEA3A33EAB19370", "hash_sha1": "6E2061E02EF3C747046D269C55C2E78C4CBCBDC2", "hash_sha256": "C5B2FFF1230C5CB4B7E62DF2ABDF65DF25822E70D68D27A9A390016A3C3D5C04", "hash_sha384": "09976B7353BAF59FB84817A3734CF4596D50DE74733DD0F77034D17521639ED636993BD8641F34C452E5D7F58F5982A0", "hash_sha512": "B5C4FA6D821863EA04DFF43D49DF6554458F6F0C7D9196894040AB2D5B2AF1E551CA6E2ADE2307C164D21F08F23CDE0EEE07E3FB2967F9E5B749D9E3ABE95C64", "hash_ssdeep": "384:2G8ro6z17MBP1U2ID4kyqkXamW3TFPtX/tkYFYH6WpuWFYW:MrX7MwDiQF1XWE4V", "hash_imp": "89BAD98DE0A45ABD45AFD0C86A8F82A6", "hash_pesha1": "2CB4D933DF14D14DDE7F6A74AE4739197FCFA9A8", "hash_pe256": "2EF6C5C8F42D96264F6F9E15AE1523BECB97258FD2880647287C7EACDE842BF3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DOS 5 File Compare Utility", "meta_original_filename": "FC.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/c5b2fff1230c5cb4b7e62df2abdf65df25822e70d68d27a9a390016a3c3d5c04/detection", "output": "Compares two files or sets of files and displays the differences between\r\nthem\r\n\r\n\r\nFC [/A] [/C] [/L] [/LBn] [/N] [/OFF[LINE]] [/T] [/U] [/W] [/nnnn]\r\n [drive1:][path1]filename1 [drive2:][path2]filename2\r\nFC /B [drive1:][path1]filename1 [drive2:][path2]filename2\r\n\r\n /A Displays only first and last lines for each set of differences.\r\n /B Performs a binary comparison.\r\n /C Disregards the case of letters.\r\n /L Compares files as ASCII text.\r\n /LBn Sets the maximum consecutive mismatches to the specified\r\n number of lines.\r\n /N Displays the line numbers on an ASCII comparison.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n /T Does not expand tabs to spaces.\r\n /U Compare files as UNICODE text files.\r\n /W Compresses white space (tabs and spaces) for comparison.\r\n /nnnn Specifies the number of consecutive lines that must match\r\n after a mismatch.\r\n [drive1:][path1]filename1\r\n Specifies the first file or set of files to compare.\r\n [drive2:][path2]filename2\r\n Specifies the second file or set of files to compare.\r\n\r\n", "error": "FC: Insufficient number of file specifications\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\fc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "fhmanagew.exe-22604BBB1760AC54911FD2B568D39775": { "file_name": "fhmanagew.exe", "file_path": "C:\\Windows\\system32\\fhmanagew.exe", "hash_md5": "22604BBB1760AC54911FD2B568D39775", "hash_sha1": "6B75E2824725BAA4010D40FD8CA9DA4143EF2B20", "hash_sha256": "D637BC5FEA9A49F354326C754A947449E3AA08E6C2E0BDC5C882D354FB7B8755", "hash_sha384": "B18BBE37B37178012F41FCDC825F315A694355B023AC59B7F6EF0B608D6B3B00877033538683B07F0125BBA656CCABBD", "hash_sha512": "ABD8FCD4A8D10DD8F1DAA5C3D60CFCA42E295C854B490A4C1395971E7CB09282B2ABD443092F66AF5BB028C24D42A8FB0C2D946BB575AD38F5819D7A4A0608E1", "hash_ssdeep": "3072:Rz97nOD7tyckm7t50MHjNRzpkVTFJcMuneHI:Rz97nOD7tyckm7cMHts7Z", "hash_imp": "BF399B752EB90CB1F04EC6DB7DE82609", "hash_pesha1": "7F61ACCE47A0B7FA5CD1581D7E067816F3B0A600", "hash_pe256": "4291C529FE73442EDD33DCAA5BB9CE72545AD7D3DDCAB0D40A6DCF480226C7F8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File History Management Tool", "meta_original_filename": "fhmanagew.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d637bc5fea9a49f354326c754a947449e3aa08e6c2e0bdc5c882d354fb7b8755/detection", "runtime_modules": [ "C:\\Windows\\system32\\fhmanagew.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\system32\\fhsvcctl.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll" ] }, "FileHistory.exe-11FCDD6D3B8F0381AC9E90F9B4EC0865": { "file_name": "FileHistory.exe", "file_path": "C:\\Windows\\system32\\FileHistory.exe", "hash_md5": "11FCDD6D3B8F0381AC9E90F9B4EC0865", "hash_sha1": "EB1E8F4AC804DD8D92B328841FEC1E1D64548946", "hash_sha256": "A495F0059E9A68C99BE88FCA44B2C5E75E6345374C44F58DC3218839A1CBF05A", "hash_sha384": "B6E74F7F3A88DD16038402E7B790DC96A534411F651FA36EFD98231A5A8E97E7024B57C40BC8947C217A3485984F79B8", "hash_sha512": "3FE1F51134D7C513E8CE2C5117C065E5D44D78100554375637B06244D243A14C05687A2E6BCF3234694698E3FB8A8B8BE26E1675939B2C1D4F654A9018F75032", "hash_ssdeep": "3072:Yc6avDu8+NorasBZOsdC6VD7xvxzYuVD8C+cxICGQWcMh4N6obdmyTVulAyXbwN:Yc6XvIvxzYuVD8CnxICGJcTIobd", "hash_imp": "0C153A28F0F3D65D93238BD2C448D417", "hash_pesha1": "79412F37972DF575071403A105E419B92B66B57B", "hash_pe256": "E2C2F13FB184F3C9A86368387B8DB553D459AEE72F86CA4A469B3F7AF0C271CF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File History", "meta_original_filename": "FileHistory.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/a495f0059e9a68c99be88fca44b2c5e75e6345374c44f58dc3218839a1cbf05a/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\System32\\en-US\\FileHistory.exe.mui": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_2540": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\fhuxpresentation.dll": "File", "(R-D) C:\\Windows\\System32\\fhuxcommon.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Core\\v4.0_4.0.0.0__b77a5c561934e089\\System.Core.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\System32\\fhuxapi.dll": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\System32": "File", "(R-D) C:\\Windows\\System32\\en-US\\explorerframe.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\ExplorerFrame.dll.mun": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\fhuxgraphics.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\fhuxadapter.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\FileHistory.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\system32\\UxTheme.dll" ], "runtime_window_title": "--help - File History" }, "find.exe-AE3F3DC3ED900F2A582BAD86A764508C": { "file_name": "find.exe", "file_path": "C:\\Windows\\system32\\find.exe", "hash_md5": "AE3F3DC3ED900F2A582BAD86A764508C", "hash_sha1": "1E44EE63BDB2CF3A6E48B521844204218A001344", "hash_sha256": "1A1876C5EED2B8CD9E14EBFF3F4EEB7E21552A4C6AAB4BF392A55F8DF3612DAB", "hash_sha384": "79CD234F9166F15122D8DAC377DE28940139E7E68636BBAB93C4BD89BC4A450C9DF4D0E72212AE4DF2FE63B3D07BB904", "hash_sha512": "059C0A371AADA5F36E72196109C06208B68475ED0FBEFB950BEB0CBEA2C29595151D65B087C5113AF41DF926596C4FE4E01102DAF4B75E999CF6D6517D26FF63", "hash_ssdeep": "384:Ahvo3AARFAaVDVxRshn92Jwpvwp0VJZyTWOIW:oV2DVM9Cuvu0VLyt", "hash_imp": "EF85879194FF4D8C5632D025B0B0AFDE", "hash_pesha1": "EB3B8D1DE22CE44B52DE7B3A370A13F374F493C5", "hash_pe256": "1E5FD45808E7977FB54272C3B9280D4CC5CE265C2A5097F66F289C6B2F4243C2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Find String (grep) Utility", "meta_original_filename": "FIND.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1a1876c5eed2b8cd9e14ebff3f4eeb7e21552a4c6aab4bf392a55f8df3612dab/detection", "output": "Searches for a text string in a file or files.\r\n\r\nFIND [/V] [/C] [/N] [/I] [/OFF[LINE]] \"string\" [[drive:][path]filename[ ...]]\r\n\r\n /V Displays all lines NOT containing the specified string.\r\n /C Displays only the count of lines containing the string.\r\n /N Displays line numbers with the displayed lines.\r\n /I Ignores the case of characters when searching for the string.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n \"string\" Specifies the text string to find.\r\n [drive:][path]filename\r\n Specifies a file or files to search.\r\n\r\nIf a path is not specified, FIND searches the text typed at the prompt\r\nor piped from another command.\r\n", "error": "FIND: Parameter format not correct\r\n", "runtime_modules": [ "C:\\Windows\\system32\\find.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "findstr.exe-804A6AE28E88689E0CF1946A6CB3FEE5": { "file_name": "findstr.exe", "file_path": "C:\\Windows\\system32\\findstr.exe", "hash_md5": "804A6AE28E88689E0CF1946A6CB3FEE5", "hash_sha1": "FDC776E1297D6E6FB31F8EB0E85771D886A18DC2", "hash_sha256": "B29BE6DA54121F5D9350C545ECECCE26F30A7F209CE0D9AAEA8E00C27DDA27A2", "hash_sha384": "6A92AC5593C379768770E1C679DACEB13A53AC1012AAA6E0019CAD2691485FD481164840D728C27D38885A348F38A3F5", "hash_sha512": "A9DA237EA51B08352C407E1CC125ADA83C04D651ABC9915167DD12701757AD18D82FBB41DE295087CEABE53A0E75070D66C8891044945F9C247056B9D74A4883", "hash_ssdeep": "768:TI6zJ0yVxDvpndn3b9byoORdLcLlhL+KwEKZJehZENBC34sNGS9Dm08cCy:M6zbVxNnrbbOMlhLzbaYhuNBC3ZNGSFB", "hash_imp": "A27641A39DA5A6B0717E06BA00E56B7F", "hash_pesha1": "2501D62DB6FD772FD4D6B06F8DACDD9448BE8B20", "hash_pe256": "E2EC1E1845BB5FA62C7E7796E75796B28F62F786E1CFA27F06CE917CFCEFF618", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Find String (QGREP) Utility", "meta_original_filename": "FINDSTR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "1/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b29be6da54121f5d9350c545ececce26f30a7f209ce0d9aaea8e00c27dda27a2/detection", "output": "Searches for strings in files.\r\n\r\nFINDSTR [/B] [/E] [/L] [/R] [/S] [/I] [/X] [/V] [/N] [/M] [/O] [/P] [/F:file]\r\n [/C:string] [/G:file] [/D:dir list] [/A:color attributes] [/OFF[LINE]]\r\n strings [[drive:][path]filename[ ...]]\r\n\r\n /B Matches pattern if at the beginning of a line.\r\n /E Matches pattern if at the end of a line.\r\n /L Uses search strings literally.\r\n /R Uses search strings as regular expressions.\r\n /S Searches for matching files in the current directory and all\r\n subdirectories.\r\n /I Specifies that the search is not to be case-sensitive.\r\n /X Prints lines that match exactly.\r\n /V Prints only lines that do not contain a match.\r\n /N Prints the line number before each line that matches.\r\n /M Prints only the filename if a file contains a match.\r\n /O Prints character offset before each matching line.\r\n /P Skip files with non-printable characters.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n /A:attr Specifies color attribute with two hex digits. See \"color /?\"\r\n /F:file Reads file list from the specified file(/ stands for console).\r\n /C:string Uses specified string as a literal search string.\r\n /G:file Gets search strings from the specified file(/ stands for console).\r\n /D:dir Search a semicolon delimited list of directories\r\n strings Text to be searched for.\r\n [drive:][path]filename\r\n Specifies a file or files to search.\r\n\r\nUse spaces to separate multiple search strings unless the argument is prefixed\r\nwith /C. For example, 'FINDSTR \"hello there\" x.y' searches for \"hello\" or\r\n\"there\" in file x.y. 'FINDSTR /C:\"hello there\" x.y' searches for\r\n\"hello there\" in file x.y.\r\n\r\nRegular expression quick reference:\r\n . Wildcard: any character\r\n * Repeat: zero or more occurrences of previous character or class\r\n ^ Line position: beginning of line\r\n $ Line position: end of line\r\n [class] Character class: any one character in set\r\n [^class] Inverse class: any one character not in set\r\n [x-y] Range: any characters within the specified range\r\n \\x Escape: literal use of metacharacter x\r\n \\<xyz Word position: beginning of word\r\n xyz\\> Word position: end of word\r\n\r\nFor full information on FINDSTR regular expressions refer to the online Command\r\nReference.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\findstr.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "error": "FINDSTR: /- ignored\r\nFINDSTR: /h ignored\r\nFINDSTR: Bad command line\r\n", "runtime_modules": [ "C:\\Windows\\system32\\findstr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "finger.exe-C9085755F831F1345CF2B0A309095522": { "file_name": "finger.exe", "file_path": "C:\\Windows\\system32\\finger.exe", "hash_md5": "C9085755F831F1345CF2B0A309095522", "hash_sha1": "4C7D686DE444BB2101934350A9357BF95260F4B4", "hash_sha256": "D6C52EA560D6009505545E53C481F1D75579E11DADE120CF164EBD196824BA91", "hash_sha384": "E6E76C1B0F724AEEA555243155F05623A582B4837D3AE365781A39EC360DD6831608DC07BDBD62C705F9B19AC376D71D", "hash_sha512": "69FCF92EBE2E86EC0160B785740979E48FE87E79DDE225ABBA27CCC7028DF071416532F5B310FF0051F4949E91B509C1A7A04771B91FABB1724583F8FF5C0622", "hash_ssdeep": "384:LgY+HjG7lsZSy9x6R58lSGQ7O7+VjNbKfWl0W:ETWUmVjAq", "hash_imp": "E15D0366B0329E559CFF2A7B0126BA16", "hash_pesha1": "A442D917D4FE5EBA502EE4B5736D1EAEC2290834", "hash_pe256": "DBE5062B44BFBD35D2839FAFF89618CE59472C452AE391777F1DB6B6B6C71DC8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCPIP Finger Command", "meta_original_filename": "finger.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d6c52ea560d6009505545e53c481f1d75579e11dade120cf164ebd196824ba91/detection", "error": "\r\nDisplays information about a user on a specified system running the\r\nFinger service. Output varies based on the remote system.\r\n\r\nFINGER [-l] [user]@host [...]\r\n\r\n -l Displays information in long list format.\r\n user Specifies the user you want information about. Omit the user\r\n parameter to display information about all users on the\r\n specifed host.\r\n @host Specifies the server on the remote system whose users you\r\n want information about.\r\n\r\n", "output": "\r\n[18ce68cb-4304-4445-a952-d165bf86113f]\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\finger.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\finger.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "fixmapi.exe-1B64E8442ADB0741AD1469EB33209B36": { "file_name": "fixmapi.exe", "file_path": "C:\\Windows\\system32\\fixmapi.exe", "hash_md5": "1B64E8442ADB0741AD1469EB33209B36", "hash_sha1": "3230B1A4B592C3B711AB9C2F51AE4307596A1E5C", "hash_sha256": "E77C39972273CE22AF4FB971FD08108FB6F6C02F97C92260F4EB9D31CDBE39C0", "hash_sha384": "C491ECB7E67140DE399362D3100A921AC5B6A8B99798A16027A71CBA9A3A2BDE6A49467B0FB099A185FD13F6949165DD", "hash_sha512": "76CF6D6C15AB52FF4DB4011B6EC88560BB1D2F20A7242B454D60C6521B294197798CDB8A9F92F8920404264D030C9D91D3E22B5C8375683A7D45264649CE7E1E", "hash_ssdeep": "384:qwKMEQb8/xjDHLBNl3MyzTOeS2fy9LDE/LDEdTnRkT/erue/4WbnWqw:3TirBNlzzTO9lYeVd", "hash_imp": "671476B97F9417A9DD566A255C7365DD", "hash_pesha1": "46DD6BB53884FE4F32B1BAA41EA2F342817073DA", "hash_pe256": "50054C0FCD3B8B24A8EE106B535EB94BBCC416C512E129E06CD267A8E7216D47", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "FIXMAPI 1.0 MAPI Repair Tool", "meta_original_filename": "FIXMAPI.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e77c39972273ce22af4fb971fd08108fb6f6c02f97c92260f4eb9d31cdbe39c0/detection", "runtime_modules": [ "C:\\Windows\\system32\\fixmapi.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "fltMC.exe-6AB08CADCE7DF971A043DCD1257D7374": { "file_name": "fltMC.exe", "file_path": "C:\\Windows\\system32\\fltMC.exe", "hash_md5": "6AB08CADCE7DF971A043DCD1257D7374", "hash_sha1": "27BF9EB6969D40910AAF6C1B9E4A424F2D8ED88D", "hash_sha256": "D127CC48C864A84DF91C3132314EC9698855DFBB6E9AFF97AB13023E9EAFF8B4", "hash_sha384": "FE3ABEE003D9B1CA6427CA142B909E9F51A2322B19B3291741DFF808D091225AFD4EE1B94E5388671BCC94C51DEEE2B5", "hash_sha512": "6905AF58DA34B02A28C174BD8F5464B32614AF0A6D8E83CCD75110B56DADD2FC40F0E116B1139EC871082A955698F6BD451FC1473C766E8DF85B67E2FFEB8EFF", "hash_ssdeep": "768:ovTzG/rqYhvazMpo8VUIzRAjzQ6cRsG1zJ:MYr9Le8HAvQ6cRsGpJ", "hash_imp": "D9C40185EFB3517F3A8819033083C33B", "hash_pesha1": "5426D7B257FBC50A7801FEF89F1C6A768BC0FDFF", "hash_pe256": "79603696C604367217EFBE973A7510316DFF0A1836B2B48AD4F781E36F238874", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Filter Manager Control Program", "meta_original_filename": "fltMC.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d127cc48c864a84df91c3132314ec9698855dfbb6e9aff97ab13023e9eaff8b4/detection", "output": "\r\n** Invalid command\r\nValid commands:\r\n load Loads a Filter driver\r\n unload Unloads a Filter driver\r\n filters Lists the Filters currently registered in the system\r\n instances Lists the Instances for a Filter or Volume currently\r\n registered in the system\r\n volumes Lists all volumes/RDRs in the system\r\n attach Creates a Filter Instance to a Volume\r\n detach Removes a Filter Instance from a Volume\r\n\r\n Use fltmc help [ command ] for help on a specific command\r\n", "runtime_modules": [ "C:\\Windows\\system32\\fltMC.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "fodhelper.exe-85018BE1FD913656BC9FF541F017EACD": { "file_name": "fodhelper.exe", "file_path": "C:\\Windows\\system32\\fodhelper.exe", "hash_md5": "85018BE1FD913656BC9FF541F017EACD", "hash_sha1": "26D7407931B713E0F0FA8B872FEECDB3CF49065A", "hash_sha256": "C546E05D705FFDD5E1E18D40E2E7397F186A7C47FA5FC21F234222D057227CF5", "hash_sha384": "DE9AE28B35A9F9ED3D41D222ABCE0C39B8C0E5DBED6FCBC5F6F0001124D28D789C004727044CA12AE09746C5CD19DC37", "hash_sha512": "3E5903CF18386951C015AE23DD68A112B2F4B0968212323218C49F8413B6D508283CC6AAA929DBEAD853BD100ADC18BF497479963DAD42DFAFBEB081C9035459", "hash_ssdeep": "768:WwU7bDT2KLt6oPjQQ5fxGIjN44MgZkD9TpiPogpUORaNpohsySZlv7:WtfT2KwoPBxjN4zDbgpUOoo1SZ17", "hash_imp": "2BD851C90720C3E5FEE7E3FF3ACFA3D5", "hash_pesha1": "21687605F7285AB4815D1FD6E43A4015B3E2A995", "hash_pe256": "3D103B9B4E19548A0B63A8607E28E54F164BE13B2D5FEAF1AC046EBCB90DFEE4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Features On Demand Helper", "meta_original_filename": "FodHelper.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c546e05d705ffdd5e1e18d40e2e7397f186a7c47fa5fc21f234222d057227cf5/detection", "runtime_modules": [ "C:\\Windows\\system32\\fodhelper.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "Fondue.exe-237E1F3944532E26BB1EB945798DB582": { "file_name": "Fondue.exe", "file_path": "C:\\Windows\\system32\\Fondue.exe", "hash_md5": "237E1F3944532E26BB1EB945798DB582", "hash_sha1": "D0F203A9692CAF03AA92F77A63058221191999EE", "hash_sha256": "52319D1A4C727BAC0A328383F4A571DEC7B7B72EF6D50913E9212834983C5547", "hash_sha384": "629E9539E2B1F9333168434461502E5692231B0C3724B2EF0168756127E2EC80357D905F6B909E9E48A1CD7C97BA5585", "hash_sha512": "F7DEA6AB00E89B871E7580FDF3F790E27BE8E6F4D265106C7311F51FA16E9E907881B8D672FF418D000597058392E2EF32BE3CD10CE74A0CE9389D3C7A99E376", "hash_ssdeep": "3072:rexYNbibEaznWfH22ZsuX2xKwMPTnaSrIrvDJ:6Eb0znWjZnXeKwMLnaqY", "hash_imp": "E8309E14FD0CD5D0959FCC7F5E47D546", "hash_pesha1": "5AC03405715EE1CD71A30F2E00BFE7AF6EABC9D5", "hash_pe256": "AF0E79174AC1F061BA2B64BBDE2DA8C12316F8A42C4970DA80F7505882BCEEF1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Features on Demand UX", "meta_original_filename": "Fondue.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/52319d1a4c727bac0a328383f4a571dec7b7b72ef6d50913e9212834983c5547/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\Fondue.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\appwiz.cpl.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Fondue.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "runtime_window_title": "Windows Features" }, "fontdrvhost.exe-DADAB3E5A3A2BFB177A177CEE3C4CAFD": { "file_name": "fontdrvhost.exe", "file_path": "C:\\Windows\\system32\\fontdrvhost.exe", "hash_md5": "DADAB3E5A3A2BFB177A177CEE3C4CAFD", "hash_sha1": "DBBD24F6C17AC1FE49B1FE3B22D33DD4F4863E0E", "hash_sha256": "4F5D509ED0813495684A0A5CED614F234E3F595B7A83B25C0AA2940C76D327AA", "hash_sha384": "0EDC3C1C7023DF41D9F2E6F0EFA4B1FD87A6168A6B1A73F687CAA5DBA3DBC8C9B3845EA7E23A81CD7D7D8E49F73E30ED", "hash_sha512": "809744F92ECFAC5CA8C7D4F4E19C2362C8C90AE9E9202F9CB69C4E718C71F8C7EEB010F64B7F90774E5F7E90B8B511503DA187E0D68813FA54272B38990D8F58", "hash_ssdeep": "12288:novL51mcx24UuNz0SmjlkZnHucZPTUl7A2n7V8dPPyMG4j+T3dSAVNoPOB/AVWW9:oD51mL4NzakZHu0PaXep70dSMGW/AV3", "hash_imp": "6F99B3F14EB64D3801C2C98B4B171BF8", "hash_pesha1": "7A1DDEA320AF906DF29146AFAFAB30EC2CBFEE40", "hash_pe256": "A6E99E1F7BB984301ADDA5E3CA4B86E29E63D1EE31794CD81C1DEA9F419F03D5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Usermode Font Driver Host", "meta_original_filename": "fontdrvhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4f5d509ed0813495684a0a5ced614f234e3f595b7a83b25c0aa2940c76d327aa/detection", "runtime_modules": [ "C:\\Windows\\system32\\fontdrvhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "fontview.exe-C07C4F59EA1A3795CEC526582A5DD7C2": { "file_name": "fontview.exe", "file_path": "C:\\Windows\\system32\\fontview.exe", "hash_md5": "C07C4F59EA1A3795CEC526582A5DD7C2", "hash_sha1": "6D2EF5FED901AF5761A92E1359461B975A1399DD", "hash_sha256": "551D7D1047AB302EDF713DEB2AC82AFA9CA89AAA41A6557721D23721C873BC55", "hash_sha384": "6AC94AB44E0A86663636E644D410BB7CFB4A4211178C4118531149560BBED2395E2D2EBAD32703E319162779F5C9A512", "hash_sha512": "0C6125204D9DE0346307C80E11B9917D9A548A998CD0E426C0BC553E23542605ACDBA70951ECD4CD147A5D7972834FAD545131DE1DFD15C8005C0A00E609F95D", "hash_ssdeep": "3072:hs1CPVisdNbtJNu2HNJjWRkOtHxtt3EOL2QvIsitSYVe:hiMVisdNE27WRRZzqGY", "hash_imp": "CE80D2BBAE2A3F37CA3BC062CBCF1F8C", "hash_pesha1": "A6F56E21EDAAB7BED6BBE81E7D3AC1EB95AD7DEF", "hash_pe256": "17CCAEF92AFA10546A1653810FA7AF7B798B9504D472020FEA2EEEEB4F8245A4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Font Viewer", "meta_original_filename": "FONTVIEW.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/551d7d1047ab302edf713deb2ac82afa9ca89aaa41a6557721d23721c873bc55/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\fontview.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\fontview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ], "runtime_window_title": "Windows Font Viewer " }, "forfiles.exe-9BB67AEA5E26CB136F23F29CC48D6B9E": { "file_name": "forfiles.exe", "file_path": "C:\\Windows\\system32\\forfiles.exe", "hash_md5": "9BB67AEA5E26CB136F23F29CC48D6B9E", "hash_sha1": "CABEE28F7368AAE1AC23F0713E2C330F96AF2062", "hash_sha256": "9B4886F187489A190BB2C412772C1998539F086C63A4CFD72FF3B107CBC21907", "hash_sha384": "52831636AFEC50A2F6FC4CBF7766F1831D513707653896695036CCCF5F51E3ED4C8CF9FE299DEA60634175D92C9BFB7C", "hash_sha512": "AC1EA7BE97CADCE0ABF3B581A97B32CCEECDC5E7015704EF6A08E33D47F928AAB4758DF61EFB9856057C09D31629EA080F9525B199DAEBAA4B945338086411BB", "hash_ssdeep": "1536:3vFQXxbEZhhnGU3Yk8aoBgkRfnt6xCxggRL:3exAZhhnGU3Yk7kRyCxgU", "hash_imp": "BB3BC1A3FEF88F916302D61DDC886F80", "hash_pesha1": "62B4D108996AEAD71664BEABD9CF05764594BB4F", "hash_pe256": "1693C3F0D4CA2B5206F11A406A2A3B17B8B8077534DAD2631454FFA4A115804F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ForFiles - Executes a command on selected files", "meta_original_filename": "forfiles.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9b4886f187489a190bb2c412772c1998539f086c63a4cfd72ff3b107cbc21907/detection", "output": "\r\nFORFILES [/P pathname] [/M searchmask] [/S]\r\n [/C command] [/D [+ | -] {MM/dd/yyyy | dd}]\r\n\r\nDescription:\r\n Selects a file (or set of files) and executes a \r\n command on that file. This is helpful for batch jobs.\r\n\r\nParameter List:\r\n /P pathname Indicates the path to start searching.\r\n The default folder is the current working\r\n directory (.).\r\n\r\n /M searchmask Searches files according to a searchmask.\r\n The default searchmask is '*' .\r\n\r\n /S Instructs forfiles to recurse into\r\n subdirectories. Like \"DIR /S\".\r\n\r\n /C command Indicates the command to execute for each file.\r\n Command strings should be wrapped in double\r\n quotes. \r\n\r\n The default command is \"cmd /c echo @file\".\r\n\r\n The following variables can be used in the\r\n command string:\r\n @file - returns the name of the file.\r\n @fname - returns the file name without\r\n extension.\r\n @ext - returns only the extension of the\r\n file.\r\n @path - returns the full path of the file.\r\n @relpath - returns the relative path of the\r\n file.\r\n @isdir - returns \"TRUE\" if a file type is\r\n a directory, and \"FALSE\" for files.\r\n @fsize - returns the size of the file in\r\n bytes.\r\n @fdate - returns the last modified date of the\r\n file.\r\n @ftime - returns the last modified time of the\r\n file.\r\n\r\n To include special characters in the command \r\n line, use the hexadecimal code for the character\r\n in 0xHH format (ex. 0x09 for tab). Internal\r\n CMD.exe commands should be preceded with\r\n \"cmd /c\".\r\n\r\n /D date Selects files with a last modified date greater\r\n than or equal to (+), or less than or equal to\r\n (-), the specified date using the\r\n \"MM/dd/yyyy\" format; or selects files with a\r\n last modified date greater than or equal to (+)\r\n the current date plus \"dd\" days, or less than or\r\n equal to (-) the current date minus \"dd\" days. A\r\n valid \"dd\" number of days can be any number in\r\n the range of 0 - 32768.\r\n \"+\" is taken as default sign if not specified.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n FORFILES /?\r\n FORFILES \r\n FORFILES /P C:\\WINDOWS /S /M DNS*.* \r\n FORFILES /S /M *.txt /C \"cmd /c type @file | more\"\r\n FORFILES /P C:\\ /S /M *.bat\r\n FORFILES /D -30 /M *.exe\r\n /C \"cmd /c echo @path 0x09 was changed 30 days ago\"\r\n FORFILES /D 01/01/2001\r\n /C \"cmd /c echo @fname is new since Jan 1st 2001\"\r\n FORFILES /D +12/12/2020 /C \"cmd /c echo @fname is new today\"\r\n FORFILES /M *.exe /D +1\r\n FORFILES /S /M *.doc /C \"cmd /c echo @fsize\" \r\n FORFILES /M *.txt /C \"cmd /c if @isdir==FALSE notepad.exe @file\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"FORFILES /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\forfiles.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "fsavailux.exe-9BF3B32A357FC15EB03DF5F58752C393": { "file_name": "fsavailux.exe", "file_path": "C:\\Windows\\system32\\fsavailux.exe", "hash_md5": "9BF3B32A357FC15EB03DF5F58752C393", "hash_sha1": "A5355EF7DDC3912C5630F56DABA667E3B81519D6", "hash_sha256": "B6F49FBE12F91BEC54CF7EC214F808DB0DCA04F99B71FAE2F47A75EBAE16521E", "hash_sha384": "D808CB02BE9B1120D61F3D9182A29522B4440FDD593BFBBFB216A44B3D78B4C8E90554D3BDDCF0C8CC25C2E4FAB82B03", "hash_sha512": "A12B0DEE1AA58458CE0EA5067AC8AA580498A8F1957DCC79865FFE5E73DDA62FC6B157F10B1A19FEC5FA801FFA8DC4E68099900B2D7B3189B96CF5668E2E8121", "hash_ssdeep": "384:YvcJm6/P7HHt8Bp6PVCK1ub9Sj1RWgmWW:hJ3/P7ntgp6tOm1G", "hash_imp": "7906A2680F0C0553216922F1E3808813", "hash_pesha1": "EDEFD163F9E2862770DCC3D612DDC41FF2A5E31E", "hash_pe256": "B85DF509CDAAE909F6D56C4FCF0DC59AE8C1C1D3564B5C538ECC9FA64D58C78A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft\\fsavailux", "meta_original_filename": "fsavailux.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b6f49fbe12f91bec54cf7ec214f808db0dca04f99b71fae2f47a75ebae16521e/detection", "runtime_modules": [ "C:\\Windows\\system32\\fsavailux.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\IfsUtil.dll", "C:\\Windows\\system32\\ulib.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\system32\\DEVOBJ.dll" ] }, "FsIso.exe-5906E37F13CC8BD54AE55717A1D9208C": { "file_name": "FsIso.exe", "file_path": "C:\\Windows\\system32\\FsIso.exe", "hash_md5": "5906E37F13CC8BD54AE55717A1D9208C", "hash_sha1": "6D33FC270F53A6587166EB5ECB9AFE91E0EF4C15", "hash_sha256": "A20162CDCBDEF6198F706ACED860ECC93096AECCEA1ACC959E3FF51132BF62E7", "hash_sha384": "61059FFB083FE25D79861049215D5773B77A36C9B7C488D86C360F73BE16D805C1982EBF6E83623A60C4A54A4239E9C3", "hash_sha512": "92132E374BA0B160A02CBB7AE5E7B8B51CD9283F149F3FB4D4AB888C0B14FF7D782CAF38EF7883185AC941A31CACEEA9D9B0B366193EDD93763EBD61DEEB62D0", "hash_ssdeep": "1536:FOpprVd4sYWZau3+p9kxXqZzNiLyC0gsLo3u9DBLxTONr4PBJ4:FOjAHWZau3ckxa9Mh0gsEe9DnyUc", "hash_imp": "54FDA49E38FC53ED5FD39A6AE34568E0", "hash_pesha1": "1160767992DBDD01832D1ADD0A1210C14446184F", "hash_pe256": "4E443CFE27BFE8AFB7AAB3D63CC2CE809EAD0C7C6A5D4582BD88FA39FC6B9204", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Secure Frame Server Helper", "meta_original_filename": "FsIso.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a20162cdcbdef6198f706aced860ecc93096aeccea1acc959e3ff51132bf62e7/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\FsIso.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "fsquirt.exe-32903A64F68464B1570A62E45CB93B26": { "file_name": "fsquirt.exe", "file_path": "C:\\Windows\\system32\\fsquirt.exe", "hash_md5": "32903A64F68464B1570A62E45CB93B26", "hash_sha1": "F9D3C58628CA6DD01B5C5C47C7CAF5356DFD2892", "hash_sha256": "B088A402467D54206254050A5D754F8B6313A670B350DE8F28CAB416095C894F", "hash_sha384": "EF117D4597D080F5DF89620E29BC791C542F86633C700E889935F3F8A5692D69F114AE2C9A6CF12C2767B75BA08E2828", "hash_sha512": "87F17931C007035546C558253E88B034F1FB75936ADB0988F88F60BFA3C63171E39906546EFA47C3E0D92E5A55A4CBBF661C6E25AC9E425BEEAFA9B5EB9C4374", "hash_ssdeep": "1536:PY20pdhld78gDTbJ0iu06GH9pfOPIVpOYa++wUr6vRklnPP7f1pUi4elRh8xwpp0:qz64fy8P+wunnD1pz46RhE8jDh", "hash_imp": "2445A8B6BDC13970785EE16F13E5A569", "hash_pesha1": "EA2E691AF8FA4356BDA6594F295635EEFE34214F", "hash_pe256": "3483DFA16D4C5033256ECD5E06EDF159DC3B6FBAADBAF7C45B60A28BEED96041", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "fsquirt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/b088a402467d54206254050a5d754f8b6313a670b350de8f28cab416095c894f/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\fsquirt.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\fsquirt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHELL32.dll" ], "runtime_window_title": "Bluetooth File Transfer" }, "fsutil.exe-DE00EDA7134D3365E6074700E3008CAD": { "file_name": "fsutil.exe", "file_path": "C:\\Windows\\system32\\fsutil.exe", "hash_md5": "DE00EDA7134D3365E6074700E3008CAD", "hash_sha1": "B1E5B19E3828886FD4A3A8F827A41232514ED71B", "hash_sha256": "8767BC230A6928DF40B66A1D127C7DBAEDF70BD18D5C20C094FFC7F23902A7CF", "hash_sha384": "537B8646163E1090A1405B9C9ACD7DFDEFD0467C49DFBDD1E53024EC55244F37E39C62C03685FDE7E1398FAB9F697C68", "hash_sha512": "1EDFE25FD2067AC3D3E15A4BF3FD1A621B0EDADEBB2530F35667F6800995827EEEFDAFE42CE64BE72814F7F04973BFE02AD4E1A2297A7A3CF5D87289A48077D8", "hash_ssdeep": "6144:O4AA5pY72zEUIK0wSA4SjabSrlbEbTNOjM:lAwbJv0wLvjabZ/so", "hash_imp": "15904A5517C1B1501E6213EDD591C487", "hash_pesha1": "95AD9C913720C1F309AA6BE70C06895CDBAC0556", "hash_pe256": "8E8E46423CAC7C8F4AF56B358CE66D0E5102863C5EB303048F18364D6EE19DB4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "fsutil.exe", "meta_original_filename": "fsutil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8767bc230a6928df40b66a1d127c7dbaedf70bd18d5c20c094ffc7f23902a7cf/detection", "output": "--help is an invalid parameter.\r\n---- Commands Supported ----\r\n\r\n8dot3name 8dot3name management\r\nbehavior Control file system behavior\r\ndax Dax volume management\r\ndirty Manage volume dirty bit\r\nfile File specific commands\r\nfsInfo File system information\r\nhardlink Hardlink management\r\nobjectID Object ID management\r\nquota Quota management\r\nrepair Self healing management\r\nreparsePoint Reparse point management\r\nstorageReserve Storage Reserve management\r\nresource Transactional Resource Manager management\r\nsparse Sparse file control\r\ntiering Storage tiering property management\r\ntransaction Transaction management\r\nusn USN management\r\nvolume Volume management\r\nwim Transparent wim hosting management\r\n", "runtime_modules": [ "C:\\Windows\\system32\\fsutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ftp.exe-7DB5A93B4113369B03D1F18D8325FEF6": { "file_name": "ftp.exe", "file_path": "C:\\Windows\\system32\\ftp.exe", "hash_md5": "7DB5A93B4113369B03D1F18D8325FEF6", "hash_sha1": "5082B57359A9EF6D440D5D1520A45E201442F146", "hash_sha256": "9728A3B5755A67A4EBE91A04730EFCC2CABEBACBB41FFCA75A71B42502E3D7D5", "hash_sha384": "3E6E1F226CDF6A347A0B4E6108A278CF75B25FD893D4FCD393DB9EEEEDA960FA922F283F66210791D939C159E2BE9C5F", "hash_sha512": "BB35CD7B526B0E819E8C83CF84769F2DD1EBF0C62094D4756881612B22892B3F964489DA64BF5CE8BD758F3B2AC8C06D035F048675BDB64DB98F437666A30444", "hash_ssdeep": "1536:PDri+Kto7tsFr0VHYHtenn8hhuMhMMXi:PyEOFwhYHteOdS", "hash_imp": "77FB959251723204D9A218FADEE0AF08", "hash_pesha1": "407FFEA54A73ACEF271DD5FD02B5EAFEEA6C411E", "hash_pe256": "94848C77C242DC87990F7EDD4961549FE4E935E5671BBC0360120D7A903F383F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Transfer Program", "meta_original_filename": "ftp.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9728a3b5755a67a4ebe91a04730efcc2cabebacbb41ffca75a71b42502e3d7d5/detection", "error": "\r\nTransfers files to and from a computer running an FTP server service\r\n(sometimes called a daemon). Ftp can be used interactively.\r\n\r\nFTP [-v] [-d] [-i] [-n] [-g] [-s:filename] [-a] [-A] [-x:sendbuffer] [-r:recvbuffer] [-b:asyncbuffers] [-w:windowsize] [host]\r\n\r\n -v Suppresses display of remote server responses.\r\n -n Suppresses auto-login upon initial connection.\r\n -i Turns off interactive prompting during multiple file\r\n transfers.\r\n -d Enables debugging.\r\n -g Disables filename globbing (see GLOB command).\r\n -s:filename Specifies a text file containing FTP commands; the\r\n commands will automatically run after FTP starts.\r\n -a Use any local interface when binding data connection.\r\n -A login as anonymous.\r\n -x:send sockbuf Overrides the default SO_SNDBUF size of 8192.\r\n -r:recv sockbuf Overrides the default SO_RCVBUF size of 8192.\r\n -b:async count Overrides the default async count of 3\r\n -w:windowsize Overrides the default transfer buffer size of 65535.\r\n host Specifies the host name or IP address of the remote\r\n host to connect to.\r\n\r\nNotes:\r\n - mget and mput commands take y/n/q for yes/no/quit.\r\n - Use Control-C to abort commands.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\ftp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "fvenotify.exe-1DDE0327CAF5309EC597B21726028153": { "file_name": "fvenotify.exe", "file_path": "C:\\Windows\\system32\\fvenotify.exe", "hash_md5": "1DDE0327CAF5309EC597B21726028153", "hash_sha1": "D8325D665F482377A0622B6C70C25911F81E1A95", "hash_sha256": "B7FD898228EFFC5C80349B74175337486E43F327782B3CF37CC6C81FF5F934C5", "hash_sha384": "EB0305AC930B321B98DB1D8D63D085C6CCF42F740EC81CD8F6D0077A4E5D296FB34F203252927C2B7BE54B7624FEC30E", "hash_sha512": "BE51BFB66DFB2CC0FD21BC17DE1A36A59E290E3C249A3D1EFBC11A9F5E436C39A4CEEBC3AE4D510900BE26572E7C27635F57054472C320299FF890A5239F8DFB", "hash_ssdeep": "3072:8P4awiEsVHmEZj0SkK4avkuIwnVS570M9kdatGCO+xmBc+hMPhPsx:HKqEZ0SkKbDVs7nyatGt+SYF", "hash_imp": "D3D42414DD4F1C65256B4DAFBE1F9151", "hash_pesha1": "62FD23AE5D598C60BD2416B10E08753F937F5E83", "hash_pe256": "03DB5224544C197E47FCA3938FD15C0549364088E89A7C00C7752D89D40B0777", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BitLocker Drive Encryption Notification Utility", "meta_original_filename": "FVENOTIFY.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b7fd898228effc5c80349b74175337486e43f327782b3cf37cc6c81ff5f934c5/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\fvenotify.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "BitLocker Drive Encryption", "runtime_modules": [ "C:\\Windows\\system32\\fvenotify.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "fveprompt.exe-1FDC5C40B2DE4167895EFFCAB0854C0C": { "file_name": "fveprompt.exe", "file_path": "C:\\Windows\\system32\\fveprompt.exe", "hash_md5": "1FDC5C40B2DE4167895EFFCAB0854C0C", "hash_sha1": "B89B0EE4A98768353D9B889CF133373DF1B79DD3", "hash_sha256": "FE5098923F27EF6055E3343A26AF9BED62EAA9EDDFCB77AB06D2328D8497B112", "hash_sha384": "81E0DC75CA7E397712F1EF807A775A43A60D3AB4B18E90DEAE46D9B21CEC3F25723B353B9225813D6FCC2DEA468E6F03", "hash_sha512": "B871F2D8E2C2E2F614D0EFE6E31445140CD2783DDAFEC4C8A859C2B0EC2F9BF77C00A34AA1727BD393DC9F7580B59BBB3B894356370A4200B8D3B8537F44EAD7", "hash_ssdeep": "3072:mCV4NknUZFc/R/e91WOyvkfQbwnVS570M9kdatGCO+xmBc+hMPhPsx:zFIFm/6MYPVs7nyatGt+SYF", "hash_imp": "F4EEE32A76D9E4FEE247653CA992EDC4", "hash_pesha1": "95DD19CD0DB784F84012CFA1C6914407F7A31BC8", "hash_pe256": "09F8D0EA706C281DA16FBF46D598BB71DC68A96FA4BC6E9F4642FF9349FF6B9E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BitLocker Drive Encryption", "meta_original_filename": "FVEPROMPT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/fe5098923f27ef6055e3343a26af9bed62eaa9eddfcb77ab06d2328d8497b112/detection", "runtime_modules": [ "C:\\Windows\\system32\\fveprompt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll" ] }, "FXSCOVER.exe-CC45C7238FC4238C8A5A8D270AFB7F40": { "file_name": "FXSCOVER.exe", "file_path": "C:\\Windows\\system32\\FXSCOVER.exe", "hash_md5": "CC45C7238FC4238C8A5A8D270AFB7F40", "hash_sha1": "A53004F5A8D4E25D3A2B9735645B4A7A8476AA80", "hash_sha256": "2C4A4B206E941E938E2FA93B2D034432DD4C040293F933BC1EEC9DC539E83EC9", "hash_sha384": "3F695F656D6B9877A8AA249601AF557A82BF9F8A9957FA047653585EAF9F62B12DEE1C09FA88AFCAB6ECAA81F784D3D9", "hash_sha512": "9B0380B9583C4E3E7A9A0B6DF8FFA130A25461A45834105E1F71E4F9E7D750AE6B3D99BF2E48F3F7C4BDE55B2C203CC0173ED08631917178C208D1F132E880F7", "hash_ssdeep": "6144:7UsVXQny/Zwvg2xe/xHq3PnIrUTHleDb6OB4/:Wy/ZwI2xSJGFtK4/", "hash_imp": "27CE374153A8DD50DDF6F59B17C8348A", "hash_pesha1": "5DEF3A042DDE181ED2AA4DC4A1BC750873660938", "hash_pe256": "A7602AB0BD092548AD7FAFB35CEC9BACD1BF00DAA42F4CECDF388521906683E9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Fax Cover Page Editor", "meta_original_filename": "FXSCOVER.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.508 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.508", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/2c4a4b206e941e938e2fa93b2d034432dd4c040293f933bc1eec9dc539e83ec9/detection", "runtime_handles": { "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Users\\user\\Documents\\Fax\\Personal CoverPages": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "(R-D) C:\\Windows\\System32\\en-US\\FXSRESM.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\FXSCOVER.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll" ], "runtime_window_title": "Cover Page - Fax Cover Page Editor" }, "FXSSVC.exe-448D27130A927F933E9B283A165300A3": { "file_name": "FXSSVC.exe", "file_path": "C:\\Windows\\system32\\FXSSVC.exe", "hash_md5": "448D27130A927F933E9B283A165300A3", "hash_sha1": "EFC95DA195E18AE1F9852C2F693266F296E31867", "hash_sha256": "D70CB3598AF18E75DB858ACCB6D3E7B4D6F6D8F68E50673BF28A45CEA1658701", "hash_sha384": "CA2F30F3A85DC42BE9AADE1DA2906A165F50295C6C3AAE6B0178CA1105BA5107DA46C05C9B109AC6BAE123E7CBC6A52C", "hash_sha512": "F4188CE6DAFA48775819EC6387F781357C39BFBCA1D733FDBFA6E5D880DE2E8C7D8F78046076CA5D5CBDEE6FAEB9B705FC297EF3A08DBFDDD9C03B1E184C3707", "hash_ssdeep": "12288:+uFG/3iJDrhVn43HRo4vRWQQkXBphGBnghhNBeELURZT7A/:91JDrhpexobkXrhGBg9gRZg/", "hash_imp": "6F91BAF876B8AA66CF43576F7BE1E85F", "hash_pesha1": "09FA73DA0A6C4F20D95E8C0262CE788978D6494E", "hash_pe256": "874BB9D70AE583D9FC12867EA94A08E9069865329F6197C472D24E6AF57C7639", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Fax Service", "meta_original_filename": "FXSSVC.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d70cb3598af18e75db858accb6d3e7b4d6f6d8f68e50673bf28a45cea1658701/detection", "runtime_modules": [ "C:\\Windows\\system32\\FXSSVC.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "FXSUNATD.exe-2D93B27FC9B9523714AF89FDA7BB26FB": { "file_name": "FXSUNATD.exe", "file_path": "C:\\Windows\\system32\\FXSUNATD.exe", "hash_md5": "2D93B27FC9B9523714AF89FDA7BB26FB", "hash_sha1": "2DE66986F91D3953DFD690671F5D67BCA36DF357", "hash_sha256": "C665E8D130A01FEA91B8A38A9DEAEBD57F0FC71A4E6709225A408D02F47ADEF4", "hash_sha384": "FB28BA453454E209697D0E49D48F201BBEE331D18749928275066E153DE3082FF183DF8A4EE6884A9EF4651301483E94", "hash_sha512": "7FB3265AC04698B0D130085306CAE9FC139A1DC0B6AE7BDB89C804C19F90DE714EA645555D3E3600C7D936C9A3D01CC189AA1E2DC525396578DA7D0C061F74F4", "hash_ssdeep": "384:oVK5U+eRaYQ4i6dHfm6fTJm9uSGv0oyVDJmx1h/j3zzOeIRofpkZ+up93RgW2QiW:oVKneRaYLdlf89Noy0Xj3zdIL4uplRN", "hash_imp": "3A1FF52D192D0C383E6737050E3BC9DB", "hash_pesha1": "8EDAD0F4E07BECEB1FF3E6829565BA8C9578D062", "hash_pe256": "06C59F419384E10CE5369190025E9A3C5FA16D2A1B430FB81D577937EF9841C1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Fax Unattend Setup Program", "meta_original_filename": "FXSUNATD.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c665e8d130a01fea91b8a38a9deaebd57f0fc71a4e6709225a408d02f47adef4/detection", "runtime_modules": [ "C:\\Windows\\system32\\FXSUNATD.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "GameBarPresenceWriter.exe-0A96F076F6A9550386C83D71CC913A53": { "file_name": "GameBarPresenceWriter.exe", "file_path": "C:\\Windows\\system32\\GameBarPresenceWriter.exe", "hash_md5": "0A96F076F6A9550386C83D71CC913A53", "hash_sha1": "3FC914BD6D7FDBB05F0D777DD9C5D24BB53B9580", "hash_sha256": "D5816718026274F5BFD67EE85F6EC008C81C7069AA0E883CAA3B01953C855D30", "hash_sha384": "86E51444ADC45B98177FD18711DCB42CC233D4CE8B306B1F1E64401DCEAFDEE2CBD6F1FEB7CEB05765C4CE3CE4FE37CF", "hash_sha512": "792D59B4DCB281E9AC9B9F6E65B504EB0850648598273DD16BAAAD19F4E9139210EC3CF734147DDC44029699DE02D3BF4F55F3B5B9C53A97F64BC9C909092FB7", "hash_ssdeep": "6144:M2oF0JZRDBx42459/sgKYVNd5kfJ5sp7tdV0/:hoF0rRDBrgzztdV", "hash_imp": "552E34DC4CB0C0D42A2EB9FD261B5174", "hash_pesha1": "BFD56B595A54DF24297830F8648813B58F1D67AB", "hash_pe256": "5818738CBB3AE6934C6A04A991D2FE82FC34B0A1118AC1EE8ABCF93849752B09", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Gamebar Presence Writer", "meta_original_filename": "GamebarPresenceWriter.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d5816718026274f5bfd67ee85f6ec008c81c7069aa0e883caa3b01953c855d30/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\GameBarPresenceWriter.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll" ] }, "GamePanel.exe-E2E1DFEB766F358715DAE39E0CDEE7E0": { "file_name": "GamePanel.exe", "file_path": "C:\\Windows\\system32\\GamePanel.exe", "hash_md5": "E2E1DFEB766F358715DAE39E0CDEE7E0", "hash_sha1": "2CD7CF21E328FA20101CB21ED900D19C90B39F99", "hash_sha256": "97C6FCFA760A17DD8A2A27CA85B66E2559EB52C563DC2E40788FA2C91623B159", "hash_sha384": "A9EEA460743943AB9C5F4058F490529DD2E2C571C3C832988DAF884EC29F106B6185D96B32CC7E1521A177650CFC3DDD", "hash_sha512": "1E3897BB95F0E91459DED346B532ADD0721E65BA0F4C8787F290ECC2641B4CC00B356DF92256A68EFB243E21FD6A9D715D7D1F98363F84482CC6AA9CFEC3D71D", "hash_ssdeep": "24576:eqe5Y2WPhFW940AKBqVaaHVGZQ8MRE7hYR1OT32Sy5sVnA+j08FTB+IGoT6jYQSa:eqeYLhFWCbKBquwGhYR1OTaldMQ", "hash_imp": "28A171FB66EF92BEB7178A780526D50F", "hash_pesha1": "B3A173B8F3BC7198B51E93F0287275E7344DCAB8", "hash_pe256": "BB4493FC56C224CD217A00954794DEA28CEECBCAF0682328E74DA71299DD047A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Game Bar", "meta_original_filename": "gamepanel.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/97c6fcfa760a17dd8a2a27ca85b66e2559eb52c563dc2e40788fa2c91623b159/detection", "runtime_modules": [ "C:\\Windows\\system32\\GamePanel.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\system32\\d2d1.dll", "C:\\Windows\\system32\\DWrite.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ] }, "GenValObj.exe-F64A684E29E8E117C8B3B1087594A673": { "file_name": "GenValObj.exe", "file_path": "C:\\Windows\\system32\\GenValObj.exe", "hash_md5": "F64A684E29E8E117C8B3B1087594A673", "hash_sha1": "B5FABC9D29C542DA40B351347A3226CB1E65BB5D", "hash_sha256": "126AB3B346252BE7227FBDC67F9FDC5F66D698DF771DEB1A1FDA6F6B1AFE810A", "hash_sha384": "494A3BB09AB494B8BC8DF2E790A56350D868966B9B48FE7812121EE5485A8A48A0750F732D683DA72CF3E63397727653", "hash_sha512": "0024DB52AA46D5698A9848A09EDCAAB5CF34A9442A4DD79595A46BC3692321E3CF9B7D8225C9FF905F5A760BB1D9455501B2FE6BCFD688E7F96176287EC6C405", "hash_ssdeep": "12288:r+Sn6Ky36tBwfyE5ljj/JtJm7NA7xBou/ChDEG9nGds2VaFhS5h0KuP:5g36Lwa6J11ahDEG9nGds2aFhT3", "hash_imp": "46AA772C99E3ABAFE91346DF0960F328", "hash_pesha1": "77646A4CA1452BC745C316E7710D143C712064D2", "hash_pe256": "E58CE8FAF7FAD0F1934D528366D348F0C795406EE3B410D385A81586659E0E03", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Software Protection Platform Admin Object", "meta_original_filename": "GenValObj.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/126ab3b346252be7227fbdc67f9fdc5f66d698df771deb1a1fda6f6b1afe810a/detection" }, "getmac.exe-7D4B72DFF5B8E98DD1351A401E402C33": { "file_name": "getmac.exe", "file_path": "C:\\Windows\\system32\\getmac.exe", "hash_md5": "7D4B72DFF5B8E98DD1351A401E402C33", "hash_sha1": "40810FB6EEE8856B1884ECB528C88B97E447C5D8", "hash_sha256": "467CE33B5145C6E71499F32139F14D81B47C38F11DCA26B330367ADD263DBA12", "hash_sha384": "BAB432F0E2300ED98BAC9B8918D9FFFF322250C40254FA0706761E889C1CBB1E47FF2484CA495EF208CE4B5C03E8A08C", "hash_sha512": "5A26E5E22AD1005E67F6B66187DF4E6F75F1B611B2C8D615AF34BD61E94FD48FC64B606E7C43D608D112096C7BBAA8FDDFC8A9ACB603AB137E71D85783B98FD5", "hash_ssdeep": "1536:8sn3fTNgYCr7wkLNlU2IyB5Xgf3uDjEPJAMP4BY6z5gTs2Ob1FlUaxFwC:8ehi7Rpwf+DjqeMKgTbSjlUaxh", "hash_imp": "7799FC1B52F754F1DCF814E10FD9693D", "hash_pesha1": "9C0598A4AD8BF683D32F7D9B3613A5C5D41CDE34", "hash_pe256": "D75910F530A90631985A27AFD8FA2E005CB1449F99DB66840F0182AA6E4DEA9C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays NIC MAC information", "meta_original_filename": "GetMac.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/467ce33b5145c6e71499f32139f14d81b47c38f11dca26b330367add263dba12/detection", "output": "\r\nGETMAC [/S system [/U username [/P [password]]]] [/FO format] [/NH] [/V]\r\n\r\nDescription:\r\n This tool enables an administrator to display the MAC address\r\n for network adapters on a system.\r\n\r\nParameter List: \r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under \r\n which the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /FO format Specifies the format in which the output\r\n is to be displayed.\r\n Valid values: \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" should\r\n not be displayed in the output.\r\n Valid only for TABLE and CSV formats.\r\n\r\n /V Specifies that verbose output is displayed.\r\n\r\n /? Displays this help message.\r\n\r\nExamples: \r\n GETMAC /? \r\n GETMAC /FO csv \r\n GETMAC /S system /NH /V\r\n GETMAC /S system /U user\r\n GETMAC /S system /U domain\\user /P password /FO list /V\r\n GETMAC /S system /U domain\\user /P password /FO table /NH\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"GETMAC /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\getmac.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "gpresult.exe-C4C27B789A69C94569599DE9911C4680": { "file_name": "gpresult.exe", "file_path": "C:\\Windows\\system32\\gpresult.exe", "hash_md5": "C4C27B789A69C94569599DE9911C4680", "hash_sha1": "7FCE8A9ECD2127EBF9F81C3C7C4BC43AF1E8D157", "hash_sha256": "CBE6468F73F39F84915EB810D23DCC6539F348FE82456567297F9F1CF7DE5423", "hash_sha384": "40A3536DC90976005F8DF7CF9C4C162C914A85126FE81E8F26E0DFBC2EAA7A9986B3434595B93179BE7C2B4B7B1E4789", "hash_sha512": "9573721FE53EFA56475A2B15C528359A72A18A2919B926F4B1AAB2B2695E60E949C6A5ABFB2EAF492CAAFFF594212222B3D0653BC57D4A7ADC4B4BEA82A7DF9C", "hash_ssdeep": "6144:6rXb50kBdpTutMbucJmLaPcpHtWJpNBnee50IyKMnF:6zV0kBjUMb1JHPPFTRMn", "hash_imp": "56EB6715BADB6555CE5481DB32071823", "hash_pesha1": "62CB480DACFE8CB7F5C97A1BD84E7D48FCAAC6EE", "hash_pe256": "56BC01D642CA712E723CC9FCEFD4664E455C5997519281944F7B7DEC7BE29F34", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query Group Policy RSOP Data", "meta_original_filename": "gprslt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.117 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.117", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/cbe6468f73f39f84915eb810d23dcc6539f348fe82456567297f9f1cf7de5423/detection", "output": "\r\nGPRESULT [/S system [/U username [/P [password]]]] [/SCOPE scope]\r\n [/USER targetusername] [/R | /V | /Z] [(/X | /H) <filename> [/F]]\r\n\r\nDescription:\r\n This command line tool displays the Resultant Set of Policy (RSoP)\r\n information for a target user and computer.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which the\r\n command should run.\r\n Can not be used with /X, /H.\r\n\r\n /P [password] Specifies the password for the given user\r\n context. Prompts for input if omitted.\r\n Cannot be used with /X, /H.\r\n\r\n /SCOPE scope Specifies whether the user or the\r\n computer settings need to be displayed.\r\n Valid values: \"USER\", \"COMPUTER\".\r\n\r\n /USER [domain\\]user Specifies the user name for which the\r\n RSoP data is to be displayed.\r\n\r\n /X <filename> Saves the report in XML format at the\r\n location and with the file name specified\r\n by the <filename> parameter. (valid in Windows\r\n Vista SP1 and later and Windows Server 2008 and later)\r\n\r\n /H <filename> Saves the report in HTML format at the\r\n location and with the file name specified by\r\n the <filename> parameter. (valid in Windows\r\n at least Vista SP1 and at least Windows Server 2008)\r\n\r\n /F Forces Gpresult to overwrite the file name\r\n specified in the /X or /H command.\r\n\r\n /R Displays RSoP summary data.\r\n\r\n /V Specifies that verbose information should\r\n be displayed. Verbose information provides\r\n additional detailed settings that have\r\n been applied with a precedence of 1.\r\n\r\n /Z Specifies that the super-verbose\r\n information should be displayed. Super-\r\n verbose information provides additional\r\n detailed settings that have been applied\r\n with a precedence of 1 and higher. This\r\n allows you to see if a setting was set in\r\n multiple places. See the Group Policy\r\n online help topic for more information.\r\n\r\n /? Displays this help message.\r\n\r\n\r\nExamples:\r\n GPRESULT /R\r\n GPRESULT /H GPReport.html\r\n GPRESULT /USER targetusername /V\r\n GPRESULT /S system /USER targetusername /SCOPE COMPUTER /Z\r\n GPRESULT /S system /U username /P password /SCOPE USER /V\r\n", "error": "ERROR: Invalid syntax. Value expected for '/h'.\r\nType \"GPRESULT /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\gpresult.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "gpscript.exe-94FC20DD55459F467A22817CC3B089E5": { "file_name": "gpscript.exe", "file_path": "C:\\Windows\\system32\\gpscript.exe", "hash_md5": "94FC20DD55459F467A22817CC3B089E5", "hash_sha1": "56BE5829772F8E6F9A8C83B213145B183B5FCCD0", "hash_sha256": "BB008DEED1241EAD9F245661D2CD629D02031433B614CDC2CD7B1291A753A6A7", "hash_sha384": "6B2D69615863A441CE43414B101D4E96C8259F8B3C2A36652528004E6433FCCB482F8959BC63A6970AF27E51FB6FFFAA", "hash_sha512": "816F681C923949E091252EBB34E95647BB27AEB6722E2B90D7DF80423AAE0B957163F12C0963710A1C62AFC57F0074B3A4AD4DF7D8B3BB24D7F574EBB1E62B4E", "hash_ssdeep": "768:y6eYCR0d5ylfuPJ3CFOQfs+aVdl0ex0HXdBTdTlYwGqk:7e1u5ylmB3CFOsDaVd+ex0HXdBTdTiw0", "hash_imp": "74C28449EAF72F02E22F89C962FB3F40", "hash_pesha1": "70576F401A7E05F3D6762D8FD756963BA887954C", "hash_pe256": "054FFB20952D28AD5453C0C1E0A85D9FD5634CA5B93790DA612FAED86BF974F1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Group Policy Script Application", "meta_original_filename": "GPSCRIPT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/bb008deed1241ead9f245661d2cd629d02031433b614cdc2cd7b1291a753a6a7/detection", "runtime_modules": [ "C:\\Windows\\system32\\gpscript.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "gpupdate.exe-118729DD62B9422D21AFE5CEBD564F8A": { "file_name": "gpupdate.exe", "file_path": "C:\\Windows\\system32\\gpupdate.exe", "hash_md5": "118729DD62B9422D21AFE5CEBD564F8A", "hash_sha1": "0638FC81AC1545D9A324460DE4CA6AE234C2A005", "hash_sha256": "B76CE2BBA63BD2949FA6E36FBA963379B9D682F7642CD3782D9818FCD30A3E00", "hash_sha384": "992097EDD8AC6F4224F2176A17CC7DF6093627A9E8191DF87885D091A664E039B61682E3C7939B2B44D293E55B925B36", "hash_sha512": "7CA53ECDAF4F72948370E74224544DB5C3106B829B329C912B77D41E0969B521276135D13A652DA8FED326DBB8B6238207BC66B764C03C11B9BB46B5C30DADEE", "hash_ssdeep": "384:c4ce5DsF6pQMT5TLSUK9EJ8r/eOdqClM+RCTXOPlU3JF26XI/N6rMSnl2R/WoD4T:cJdET5TL5zOrePQCTXqhSnl0QC4CGer", "hash_imp": "D2466CD4C38ECEF8AAB0EE78B79FC8B8", "hash_pesha1": "3355447AA2D6C929D3168CFCC4939A15C2F9AB12", "hash_pe256": "F9853A7A8AA26B1B84FAE4E97D4FEDBD2BE0CAA2717C4A8C31C1C80E9600DB0F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Group Policy Update Utility", "meta_original_filename": "GPUpdate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.117 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.117", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b76ce2bba63bd2949fa6e36fba963379b9d682f7642cd3782d9818fcd30a3e00/detection", "output": "Description: Updates multiple Group Policy settings.\r\r\n\r\r\nSyntax: Gpupdate [/Target:{Computer | User}] [/Force] [/Wait:<value>]\r\r\n [/Logoff] [/Boot] [/Sync] \r\r\n\r\r\nParameters:\r\r\n\r\r\nValue Description\r\r\n/Target:{Computer | User} Specifies that only User or only Computer\r\r\n policy settings are updated. By default,\r\r\n both User and Computer policy settings are\r\r\n updated.\r\r\n\r\r\n/Force Reapplies all policy settings. By default,\r\r\n only policy settings that have changed are\r\r\n applied.\r\r\n\r\r\n/Wait:{value} Sets the number of seconds to wait for policy\r\r\n processing to finish. The default is 600\r\r\n seconds. The value '0' means not to wait.\r\r\n The value '-1' means to wait indefinitely.\r\r\n When the time limit is exceeded, the command\r\r\n prompt returns, but policy processing\r\r\n continues.\r\r\n\r\r\n/Logoff Causes a logoff after the Group Policy settings\r\r\n have been updated. This is required for\r\r\n those Group Policy client-side extensions\r\r\n that do not process policy on a background\r\r\n update cycle but do process policy when a\r\r\n user logs on. Examples include user-targeted\r\r\n Software Installation and Folder Redirection.\r\r\n This option has no effect if there are no\r\r\n extensions called that require a logoff.\r\r\n\r\r\n/Boot Causes a computer restart after the Group Policy settings\r\r\n are applied. This is required for those\r\r\n Group Policy client-side extensions that do\r\r\n not process policy on a background update cycle\r\r\n but do process policy at computer startup.\r\r\n Examples include computer-targeted Software\r\r\n Installation. This option has no effect if\r\r\n there are no extensions called that require\r\r\n a restart.\r\r\n\r\r\n/Sync Causes the next foreground policy application to\r\r\n be done synchronously. Foreground policy\r\r\n applications occur at computer start up and user\r\r\n logon. You can specify this for the user,\r\r\n computer or both using the /Target parameter.\r\r\n The /Force and /Wait parameters will be ignored\r\r\n if specified.\r\r\n\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\gpupdate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "grpconv.exe-8531882ACC33CB4BDC11B305A01581CE": { "file_name": "grpconv.exe", "file_path": "C:\\Windows\\system32\\grpconv.exe", "hash_md5": "8531882ACC33CB4BDC11B305A01581CE", "hash_sha1": "1B8AFC2C821709143F4B95AC0709B6BC572E67F3", "hash_sha256": "A248E327B89F8574CB7DF9F34CD7120C0508CA1541C5520BD72F0830F85A0CEC", "hash_sha384": "CFB7F1E23EAD839688547DD80A0757B7D079E57BA928924DE5E8A0104723364ED1A1E93771DAE6037624A1AE7D992013", "hash_sha512": "C5318BC367CD192211F1CD5DCBC63025780F4262DFAC1E80BA4FCD94A907723B8DE23A3B7E112B731A4AF8415B4B1375D1688C50C27D12406F87C247C492FB6B", "hash_ssdeep": "1536:RbWdz0bCMCUzmHmVTRufNBjtlCVR0wmU05khyrE:RKd8lOBzCuUKR4", "hash_imp": "671EAFCFCFA86F159D56B51A22BF5C87", "hash_pesha1": "D9FD0A3F365DFAB280D5A9AAE37195C91506CAE1", "hash_pe256": "35FE60F5E21AA510D9236C62CD159B70EB65CFA548089637480BE0EC0E4C2F82", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Progman Group Converter", "meta_original_filename": "GRPCONV.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/a248e327b89f8574cb7df9f34cd7120c0508ca1541c5520bd72f0830f85a0cec/detection", "runtime_modules": [ "C:\\Windows\\system32\\grpconv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll" ] }, "hdwwiz.exe-F56E9258DA93E144BF62C4E0BADB349A": { "file_name": "hdwwiz.exe", "file_path": "C:\\Windows\\system32\\hdwwiz.exe", "hash_md5": "F56E9258DA93E144BF62C4E0BADB349A", "hash_sha1": "4BD81A3DD101B33C786D0EA4615CF583146F73C3", "hash_sha256": "5C77FE684533FC41685A2BDF757DEB2B428CA342D74697D06A2C9B5AA0DE2FF3", "hash_sha384": "9F786DA84EC3ED5B07380CBACF2E9485102372862849133371501755D60E314DBB6F936F3E5E241FE4D242C3BA160536", "hash_sha512": "A2DD1D7D0A967A381B06DEF1A52B7560A790929CB0EB69E25200190A8D8BE87CB7B7F3C229BC3CC4729F859BE8B9E39D7E318B373CB49D9AC4BA498A692BE8AC", "hash_ssdeep": "768:COjpj1p4QBJITzz0f4G0In3BhzhWM1GOVz17:fJ1p4ig/0zZ3qOT", "hash_imp": "C5D02BC3CD327FBB8CA4DDF2ED1F5119", "hash_pesha1": "BC57603CF75D62F7B32EC05267376C8DE959461F", "hash_pe256": "11F24A748034F88C268BC5269331C17548D5834AB2808BA27CE5DEBF3431E126", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Add Hardware Wizard", "meta_original_filename": "HdwWiz.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5c77fe684533fc41685a2bdf757deb2b428ca342d74697d06a2c9b5aa0de2ff3/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\hdwwiz.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\newdev.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\devmgr.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\hdwwiz.cpl.mui": "File", "(R-D) C:\\Windows\\SystemResources\\shell32.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\setupapi.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\hdwwiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\hdwwiz.cpl", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll" ], "runtime_window_title": "Add Hardware" }, "help.exe-980741ACD376F0049FFE81DF19187201": { "file_name": "help.exe", "file_path": "C:\\Windows\\system32\\help.exe", "hash_md5": "980741ACD376F0049FFE81DF19187201", "hash_sha1": "B07BDA5BC58EB4F1721280709F838BD21C501D90", "hash_sha256": "CDCC70D77775A9FADC1D6D70D8C8F0C83D7C9ABDB3507254AF5CBE64C86A3AA1", "hash_sha384": "9FC8A59DD2F7616BA733F636A8652404FF235F74CE7C92A4BAB506CFE24CCE34271A27FC17F89475A12F035B2C2380AE", "hash_sha512": "1CFCCB42BD15446B5305E9F3801542E48E74966CB2B007D2447E3766F1C45913BDCFCC3D7EC5EAAB73408C89609B16C12477A846222817BEC75A62CB0503D7A2", "hash_ssdeep": "192:eFN/8LSwljr+GTbpxtPOyYyUdouWib+LGc+31moWMcW:ef/8LS6jC6VWy4d5WhNoWMcW", "hash_imp": "AC4BF9C2AE25ADA7A4716EBEAF3CC839", "hash_pesha1": "7B67A560484AE548F7339E0DBA051BC996654DCB", "hash_pe256": "543536622AFB1663020F04A75F34CD9BC4B62C1C6EAA8C81B4D97E7C6E41F934", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command Line Help Utility", "meta_original_filename": "Help.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/cdcc70d77775a9fadc1d6d70d8c8f0c83d7c9abdb3507254af5cbe64c86a3aa1/detection", "output": "Provides help information for Windows commands.\r\n\r\nHELP [command]\r\n\r\n command - displays help information on that command.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\help.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "HOSTNAME.EXE-33AFAA43B84BDEAB12E02F9DBD2B2EE0": { "file_name": "HOSTNAME.EXE", "file_path": "C:\\Windows\\system32\\HOSTNAME.EXE", "hash_md5": "33AFAA43B84BDEAB12E02F9DBD2B2EE0", "hash_sha1": "A57959CB3D0CEA955ACAA5DBA3D1197CD4C7E1A8", "hash_sha256": "A90C3FB350A11C6F6A6EFA9607987D924D1DE65E09CA9FAF2E0E0E00531EE335", "hash_sha384": "1E7F4D1DF1F887898A8AEA476AB836455B97CC21D8A9B217AFABFF5CD675CD5825FAB7B378C8F3BF2668D2EE3BF7CA16", "hash_sha512": "9783343CD311B12860FBA232AFCE9651B6D528C97C532A9E5AD76BB813AFFB923224DC90E7F16D183DFC6990A93C337C584ED3F0BE9927DB293A0B1502110EC5", "hash_ssdeep": "384:+8ShT761G2Weh3rjhVwVab27enbtKWV6W:+8SqG27rfZK7sb3", "hash_imp": "5CD891320C666621E9783444DB8CBA78", "hash_pesha1": "4724AFE177D3A0107C5FC9DA28C7BFD310EE2AD9", "hash_pe256": "8B856AF12D2CB9DD13BBCDF9BBF3D0A40AE6E6F36628203573B8DAD9F30C16C1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hostname APP", "meta_original_filename": "hostname.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a90c3fb350a11c6f6a6efa9607987d924d1de65e09ca9faf2e0e0e00531ee335/detection", "output": "\r\nPrints the name of the current host.\r\n\r\nhostname\r\n\r\n", "error": "sethostname: Use the Network Control Panel Applet to set hostname.\r\nhostname -s is not supported.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\HOSTNAME.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "hvax64.exe-BAA1F433CC42C55E5260922537D52F10": { "file_name": "hvax64.exe", "file_path": "C:\\Windows\\system32\\hvax64.exe", "hash_md5": "BAA1F433CC42C55E5260922537D52F10", "hash_sha1": "1B8A6AE9A86E0804FF2869A36A707DD04948D4CD", "hash_sha256": "3AC77574BBA4D7EB76BF44E831BC6A67A2AD4DAD29861C8696E8E0D4FCA23F50", "hash_sha384": "531A3582C7223F974E85CD484497875BD3C786C365D618F94A75FCE851D44AD34739EBF1A2B94DD81D14A34B2EF59463", "hash_sha512": "47AAC93D59E4883C0AAE34FFFEA049321CC78736B5DF470102B4653FB4444F32B9B8F98327AAF01878F6770ADFB0F0AF929DA56E64E5E7EDE8D2DA8A9F4BF0BE", "hash_ssdeep": "24576:Xqr1CAOeVcDWe7PyP51hkjepiQ5trjQpVkBoI5K3V9j:/eVcKyyP5M0rGk+nr", "hash_imp": "D5AEC1C1F764856CFB4155CEE3321234", "hash_pesha1": "5D5C0547D7E4D282B4F32141C02E09395830D7FB", "hash_pe256": "E33E3FF41FCE150E522988E6E2D37413333C1CA2042D96D37CDCEBF0003208B6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hypervisor V2.0", "meta_original_filename": "hvax64.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.685 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.685", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3ac77574bba4d7eb76bf44e831bc6a67a2ad4dad29861c8696e8e0d4fca23f50/detection", "runtime_modules": [ "C:\\Windows\\system32\\hvax64.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "hvix64.exe-48D042CD58915FE62BBC56AEA8BCD32F": { "file_name": "hvix64.exe", "file_path": "C:\\Windows\\system32\\hvix64.exe", "hash_md5": "48D042CD58915FE62BBC56AEA8BCD32F", "hash_sha1": "9418C170B552252C32984CA11DC219CB62734298", "hash_sha256": "1EF52EED2A89E290D5264F86DC03FD6869791DFD8B2FA8A0EA2535850EAA79E4", "hash_sha384": "EBE579EA924500964868560E0125D7CF38D1822DDE998931EAD4A6FCC44502411D4B7C9E603518C1D77E06832D1BD8A0", "hash_sha512": "2CE8CE25DE83805554071C5AFD1AACECCCCFF75D4F9D5778114FA7A88664EA718B588234FA59BDB02CC6C0F4D7A61DE811B3DFE2A7D34E6934B8CFB195072B03", "hash_ssdeep": "24576:vZXYwbEKo/nXYdYzd7GPg8cDc7yOzlLopu+guqAPjOYg6+KjjcVFs3N0Dy69ikrq:vZc/IgDIg8JAPasHcVFs3iWEikMb", "hash_imp": "D5AEC1C1F764856CFB4155CEE3321234", "hash_pesha1": "1AE05647D0E392F04554BEBFE899A1900C34008D", "hash_pe256": "C8A2F6334A493646437BD4AD313C8220B93248CE2D6C83B137F2259D95868F88", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hypervisor V2.0", "meta_original_filename": "hvix64.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.685 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.685", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1ef52eed2a89e290d5264f86dc03fd6869791dfd8b2fa8a0ea2535850eaa79e4/detection", "runtime_modules": [ "C:\\Windows\\system32\\hvix64.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "hvsievaluator.exe-A26ECA1B3E8AABE2F1D44641333D35EA": { "file_name": "hvsievaluator.exe", "file_path": "C:\\Windows\\system32\\hvsievaluator.exe", "hash_md5": "A26ECA1B3E8AABE2F1D44641333D35EA", "hash_sha1": "6A60E2ECC1730E5AF0563B6373E2E05D4AC9B657", "hash_sha256": "BFFDA0FC8DA8F4307847FADB38770885E6A2E25B6DDDEC5474D68D8DEBDAE823", "hash_sha384": "DAA964B099574B89DC8F5304ECE8C74296738C124BF298F11F91599217F9FE65730F8DC2140E3F58F4EEA3A3BB3715B8", "hash_sha512": "25C96923E36510931F47FDBCE47862A7EF73756B1EBF87AC8276E01C8B37D73BC1A3A7FDB43C3D4CEAA8D7EBFBBD00F13E3B4859CEF4A312ECE67B0EC4443C31", "hash_ssdeep": "3072:oC7MPsDfE62taO/3USL4qCt2fUN9una4UvkNBOiOlk4FHj:j4wCdfUSLZCt2fUKlAUOlkK", "hash_imp": "A04C5AF08B405A6490A1C28DFA7E95B1", "hash_pesha1": "B54EF9B2DF603612A59D110FE735A228233C7943", "hash_pe256": "0EADF858A064DEB9B48F1A7C5E0BCC3BBD6CB710BF204ADCB81011C0F8287AC4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Defender Application Guard Policy Evaluator", "meta_original_filename": "HvsiEvaluator.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/bffda0fc8da8f4307847fadb38770885e6a2e25b6dddec5474d68d8debdae823/detection", "runtime_modules": [ "C:\\Windows\\system32\\hvsievaluator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "icacls.exe-48C87E3B3003A2413D6399EA77707F5D": { "file_name": "icacls.exe", "file_path": "C:\\Windows\\system32\\icacls.exe", "hash_md5": "48C87E3B3003A2413D6399EA77707F5D", "hash_sha1": "2B52B53FAB6C50F3852F55B786FF16D7FE25BCB8", "hash_sha256": "222EA0E9D8ED1D337DBAEDD75A13B8F28FA5C3711DCDF4307E75CEDE5B5F6B9A", "hash_sha384": "E590F892766ECBEAD37867C99C63366BFB74DB4EB82BA66F674C03E6129A8CC50E97A9225B6F94FCDD020932D0708244", "hash_sha512": "503D567172D532040B9EF0CBBD9B7D8BAD1F2AFA41ACB68B19AB91775B69AD327BFBD907102FA9A8E0C99E9B7E9B1E3C20D720839DADC7B94AC819C6A4D5D9E3", "hash_ssdeep": "768:KTvUPwbiVBlFnF+Js3hj/+eHI3ajMEsaqSKp1K+LXtjIAHwtMzP:KLn+BlBF+Js3ceKSKp1KqXtjIcwtMzP", "hash_imp": "446163A548337B5BCF2727BCD1CFB399", "hash_pesha1": "51963D2AF8585FC28911E271B75475EB6046457C", "hash_pe256": "65C449B6BACC88F545F1C7446D5E78AFCDA9EBF4932E8A2D794D180BC0B3F064", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "iCACLS.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/222ea0e9d8ed1d337dbaedd75a13b8f28fa5c3711dcdf4307e75cede5b5f6b9a/detection", "output": "\r\nICACLS name /save aclfile [/T] [/C] [/L] [/Q]\r\n stores the DACLs for the files and folders that match the name\r\n into aclfile for later use with /restore. Note that SACLs,\r\n owner, or integrity labels are not saved.\r\n\r\nICACLS directory [/substitute SidOld SidNew [...]] /restore aclfile\r\n [/C] [/L] [/Q]\r\n applies the stored DACLs to files in directory.\r\n\r\nICACLS name /setowner user [/T] [/C] [/L] [/Q]\r\n changes the owner of all matching names. This option does not\r\n force a change of ownership; use the takeown.exe utility for\r\n that purpose.\r\n\r\nICACLS name /findsid Sid [/T] [/C] [/L] [/Q]\r\n finds all matching names that contain an ACL\r\n explicitly mentioning Sid.\r\n\r\nICACLS name /verify [/T] [/C] [/L] [/Q]\r\n finds all files whose ACL is not in canonical form or whose\r\n lengths are inconsistent with ACE counts.\r\n\r\nICACLS name /reset [/T] [/C] [/L] [/Q]\r\n replaces ACLs with default inherited ACLs for all matching files.\r\n\r\nICACLS name [/grant[:r] Sid:perm[...]]\r\n [/deny Sid:perm [...]]\r\n [/remove[:g|:d]] Sid[...]] [/T] [/C] [/L] [/Q]\r\n [/setintegritylevel Level:policy[...]]\r\n\r\n /grant[:r] Sid:perm grants the specified user access rights. With :r,\r\n the permissions replace any previously granted explicit permissions.\r\n Without :r, the permissions are added to any previously granted\r\n explicit permissions.\r\n\r\n /deny Sid:perm explicitly denies the specified user access rights.\r\n An explicit deny ACE is added for the stated permissions and\r\n the same permissions in any explicit grant are removed.\r\n\r\n /remove[:[g|d]] Sid removes all occurrences of Sid in the ACL. With\r\n :g, it removes all occurrences of granted rights to that Sid. With\r\n :d, it removes all occurrences of denied rights to that Sid.\r\n\r\n /setintegritylevel [(CI)(OI)]Level explicitly adds an integrity\r\n ACE to all matching files. The level is to be specified as one\r\n of:\r\n L[ow]\r\n M[edium]\r\n H[igh]\r\n Inheritance options for the integrity ACE may precede the level\r\n and are applied only to directories.\r\n\r\n /inheritance:e|d|r\r\n e - enables inheritance\r\n d - disables inheritance and copy the ACEs\r\n r - remove all inherited ACEs\r\n\r\n\r\nNote:\r\n Sids may be in either numerical or friendly name form. If a numerical\r\n form is given, affix a * to the start of the SID.\r\n\r\n /T indicates that this operation is performed on all matching\r\n files/directories below the directories specified in the name.\r\n\r\n /C indicates that this operation will continue on all file errors.\r\n Error messages will still be displayed.\r\n\r\n /L indicates that this operation is performed on a symbolic link\r\n itself versus its target.\r\n\r\n /Q indicates that icacls should suppress success messages.\r\n\r\n ICACLS preserves the canonical ordering of ACE entries:\r\n Explicit denials\r\n Explicit grants\r\n Inherited denials\r\n Inherited grants\r\n\r\n perm is a permission mask and can be specified in one of two forms:\r\n a sequence of simple rights:\r\n N - no access\r\n F - full access\r\n M - modify access\r\n RX - read and execute access\r\n R - read-only access\r\n W - write-only access\r\n D - delete access\r\n a comma-separated list in parentheses of specific rights:\r\n DE - delete\r\n RC - read control\r\n WDAC - write DAC\r\n WO - write owner\r\n S - synchronize\r\n AS - access system security\r\n MA - maximum allowed\r\n GR - generic read\r\n GW - generic write\r\n GE - generic execute\r\n GA - generic all\r\n RD - read data/list directory\r\n WD - write data/add file\r\n AD - append data/add subdirectory\r\n REA - read extended attributes\r\n WEA - write extended attributes\r\n X - execute/traverse\r\n DC - delete child\r\n RA - read attributes\r\n WA - write attributes\r\n inheritance rights may precede either form and are applied\r\n only to directories:\r\n (OI) - object inherit\r\n (CI) - container inherit\r\n (IO) - inherit only\r\n (NP) - don't propagate inherit\r\n (I) - permission inherited from parent container\r\n\r\nExamples:\r\n\r\n icacls c:\\windows\\* /save AclFile /T\r\n - Will save the ACLs for all files under c:\\windows\r\n and its subdirectories to AclFile.\r\n\r\n icacls c:\\windows\\ /restore AclFile\r\n - Will restore the Acls for every file within\r\n AclFile that exists in c:\\windows and its subdirectories.\r\n\r\n icacls file /grant Administrator:(D,WDAC)\r\n - Will grant the user Administrator Delete and Write DAC\r\n permissions to file.\r\n\r\n icacls file /grant *S-1-1-0:(D,WDAC)\r\n - Will grant the user defined by sid S-1-1-0 Delete and\r\n Write DAC permissions to file.\r\n", "error": "First parameter must be a file name pattern or \"/?\"\r\n", "runtime_modules": [ "C:\\Windows\\system32\\icacls.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "IcsEntitlementHost.exe-09909A92211BC70A40AB2C1B2FDCAFF5": { "file_name": "IcsEntitlementHost.exe", "file_path": "C:\\Windows\\system32\\IcsEntitlementHost.exe", "hash_md5": "09909A92211BC70A40AB2C1B2FDCAFF5", "hash_sha1": "2DB15648C7A334ADC5ACB1FD4FD22E4ABDB65DE0", "hash_sha256": "E7619637635A78F1F16A4A40C962FCCF207D1EDD4F64579EF192DA7791B4CFDC", "hash_sha384": "90C28AD55BA21D14EBEADBAF0D297F7EA9573D1C65427C2768B7D6C92737E79EAAA67864DC41CDE8B9E92107B9CCF9F4", "hash_sha512": "3032E88649A12980BCB26C41D1A003B17E6A484F758CDB692E49E661BA025FAB27DD3E3F44A06FB1C1FC7CDC659231BC1BECD365B136421D483CE60332DF8E9C", "hash_ssdeep": "768:qrL4uqycqJmx/wwzI2DHVvc3bHUyYDl0EM0oe42BI4+20EW:91qYx/wwzxV03jUL+EM0746P+2O", "hash_imp": "4F5540E6872E1985ABF6F28DE3CD8DBF", "hash_pesha1": "2C96155D77B2FD72E16A71B00020B9EF9A93F8C9", "hash_pe256": "3C69AB452FD979D3FBBD91779411105E9926672094AFB145CA15281DF32E39D9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ICS Entitlement Host", "meta_original_filename": "IcsEntitlementHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e7619637635a78f1f16a4a40c962fccf207d1edd4f64579ef192da7791b4cfdc/detection", "runtime_modules": [ "C:\\Windows\\system32\\IcsEntitlementHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "icsunattend.exe-A0B03F4D4EB564122BC9FFC4A7F7969F": { "file_name": "icsunattend.exe", "file_path": "C:\\Windows\\system32\\icsunattend.exe", "hash_md5": "A0B03F4D4EB564122BC9FFC4A7F7969F", "hash_sha1": "ACDB15CF72FC53BB4F2B2632801ED783C5CC8579", "hash_sha256": "0FAA0037A7D81EFF82E067CCEB34DA2A71ED5B24C9D009F1BF431D47619D4765", "hash_sha384": "DAD38F8E1C1E30FE3511730E574287D79D0070FC17AACE0F98D5F18853C1575E600813DC67B1609DADF35EFEF254FA11", "hash_sha512": "ED62B772011E10E8769A868E69592679DF678463132B2E6183C073C29F1F57548EE40AF663F848AACBC9F3422323EF0451875793F7AB4F91D17A4C2D77C5C4F9", "hash_ssdeep": "384:TnjWX0wDRyAkHdLxWeThVnXTn3Ma+BIzvW8RW:TqX04y/xWSjnJ+BIzH", "hash_imp": "000A1AB01B6FC837AF5A26B5A9854A1C", "hash_pesha1": "1AF17AEB5A2B41F13DA20927E00F07EAEF656CB0", "hash_pe256": "FCF1E6FE7926C009BCC62C9EB6D673EF5C28D751FFEE340D8F5E74B6477AF354", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ICS Unattend Utility", "meta_original_filename": "icsunattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.207 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.207", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0faa0037a7d81eff82e067cceb34da2a71ed5b24c9d009f1bf431d47619d4765/detection", "runtime_modules": [ "C:\\Windows\\system32\\icsunattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ie4uinit.exe-7B68D605B51474457D1CAFE437205213": { "file_name": "ie4uinit.exe", "file_path": "C:\\Windows\\system32\\ie4uinit.exe", "hash_md5": "7B68D605B51474457D1CAFE437205213", "hash_sha1": "2DAA37A12BA96B6990418460F1D30869E432F125", "hash_sha256": "6F83621ED34B61CA0BBAFF5A5FD158FEECA364DE52EEC38E1CC2295A82A7BD5C", "hash_sha384": "96D0EEAD8C04662AD3CB5DF188C881292FA28AED20491B039B7C269D05FA5DCAA9898988381AD63ADB74935635E06F02", "hash_sha512": "616873A3BCC7A1E78441A9040FD37DFA5F6648347685C1B4198841B64F8E553F82CC28288215B6016602071F5C854D43EFFE0898C552F3A1B6D183479612264F", "hash_ssdeep": "6144:U3scA4efnKKCR/o6e8cnz/eXTsrqAxWl/s5ZMyQ:U8cAjKd7I7UAx+", "hash_imp": "AE9B039EFA096B7A0B1FD63D51F43863", "hash_pesha1": "95216B359B62BFC5972BC4967FB989AC6D5B172D", "hash_pe256": "94DD39CB8A2DC823DBC592AE400F054C433EEC28D084076F5642C0483C17A457", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IE Per-User Initialization Utility", "meta_original_filename": "IE4UINIT.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6f83621ed34b61ca0bbaff5a5fd158feeca364de52eec38e1cc2295a82a7bd5c/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "(R-D) C:\\Windows\\System32\\en-US\\ie4uinit.exe.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\ie4uinit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll" ] }, "ie4ushowIE.exe-9DE952F476ABAB0CD62BFD81E20A3DEB": { "file_name": "ie4ushowIE.exe", "file_path": "C:\\Windows\\system32\\ie4ushowIE.exe", "hash_md5": "9DE952F476ABAB0CD62BFD81E20A3DEB", "hash_sha1": "109CC4467B78DAD4B12A3225020EA590BCCEE3E6", "hash_sha256": "E9CB6336359AC6F71AC75AF2836EFB28DAA3BAFD10A1F0B775DCDC2EC8850A6B", "hash_sha384": "2BF2449167B6A6131E2447DAA745650794A018679E4712914F45D092B18A3889B490AB7E883E3D85FFBFDD03CCFB27A6", "hash_sha512": "3CBE50A146CA50B0657A78A2D89A34630C69823005668906785B2D2015CC6139C8DBBF7AEFA5FE55957EF55AE06E758933B3B41EAF822E49DBA3B7700582E2C9", "hash_ssdeep": "1536:df2qw3wJAUtJwJ7ckngGaiwo9Q1w2GTkJpQDICWJHHyx4Ov:dOqw3KAD7rUPLQD7WJHHyx4Ov", "hash_imp": "4B2165F00D6BF1B6AFA6327B04028BFB", "hash_pesha1": "EC7246C063939276EADD46835C1825507E98267E", "hash_pe256": "2E17A70E290F4948DE1F83B91B9041A4ECF15F4B98570EDE283C9DA3329FC38B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IE Per-User Show IE Icon Utility", "meta_original_filename": "IE4USHOWIE.EXE", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e9cb6336359ac6f71ac75af2836efb28daa3bafd10a1f0b775dcdc2ec8850a6b/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\ie4ushowIE.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ole32.dll" ] }, "IESettingSync.exe-1BD7D7F2F049656C7355532C4C645BF6": { "file_name": "IESettingSync.exe", "file_path": "C:\\Windows\\system32\\IESettingSync.exe", "hash_md5": "1BD7D7F2F049656C7355532C4C645BF6", "hash_sha1": "76C672C6188BC149A0CE207039D12F44E47E2DBD", "hash_sha256": "11F2B82BC9E075C120422477E114A53DC46E1A5058027E36E8ED81A4C55CAFA5", "hash_sha384": "D2D6C36E096032CF6E1EBC5231B130C786040BCDA57A7F137C04BA332CD59C58CDE2ABF88EE50B5964AB8F5F712AC8D7", "hash_sha512": "29BD6953D6DEFC62EF8511BDAA987C038ABC72294BDB77105AE3A0678E53B1ABE163609D939D830D89E2A846887A21A803DC5F06F18F76180F00C8EC6D568BAB", "hash_ssdeep": "12288:SGPkkQzOKz9RgeuSeGrXBhA291eKLIX/KfuUgEpe:SGPbAOKz9RgiVrXBhASwKzflgM", "hash_imp": "4F00D504881D899D006AA39F1A427096", "hash_pesha1": "74B8FCE7719F77C0F4F628F7B141C88BFA71E98A", "hash_pe256": "5A825FD56F61B2890EDCEE68D9263CA96E60CC17A2B7728673D09C9DDBD68959", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IE Setting Sync Background Application", "meta_original_filename": "IESettingSync.exe", "meta_product_name": "IESettingSync", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.662 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/11f2b82bc9e075c120422477e114a53dc46e1a5058027e36e8ed81a4c55cafa5/detection", "runtime_modules": [ "C:\\Windows\\system32\\IESettingSync.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\system32\\UMPDC.dll", "C:\\Windows\\system32\\iertutil.dll" ] }, "ieUnatt.exe-9FCC4EE3E149D58408DCF67D416EFE79": { "file_name": "ieUnatt.exe", "file_path": "C:\\Windows\\system32\\ieUnatt.exe", "hash_md5": "9FCC4EE3E149D58408DCF67D416EFE79", "hash_sha1": "76DC802D8B64B2B6C4921A90D0E255912C53134D", "hash_sha256": "FA9E71CB9718935131C5136D8D98BDDDDC1917EA4BFA9E36F4116AB7AF46C275", "hash_sha384": "9E29DE8F1CF746A97E369C5E563945B82E770806E2DD684E5672D48DBED5090B3212CD6F77AA13372E008E8D73ADF0A4", "hash_sha512": "E67E8E4E5ED35587D7CE5E9E99B52DED74B88E3A24941135BCA32E46FA0E377011AC87ACA204941B20C7DCFFA585500F53FC0020086F5CDDE98285CC1AFBC34A", "hash_ssdeep": "1536:ISl2Cbv4Vn77uV6bhZm3+9mTXEwUse+1SjB1H6f9DNV4IkbgRLzzUmKp/6bASGtI:1lR49792Ewbj9DiMQ5SOGlOUU98", "hash_imp": "1609C54D12D93039FAAED355B7E7063D", "hash_pesha1": "334F76DED93DC8BD80A055632C949011B0DCC750", "hash_pe256": "E25F489AEA446F381BD8A31D815E5EFE93209163A6C98651E3995794691FBE31", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IE 7.0 Unattended Install Utility", "meta_original_filename": "IEUNATT.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/fa9e71cb9718935131c5136d8d98bddddc1917ea4bfa9e36f4116ab7af46c275/detection", "runtime_modules": [ "C:\\Windows\\system32\\ieUnatt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "iexpress.exe-17B93A43E25D821D01AF40BA6BABCC8C": { "file_name": "iexpress.exe", "file_path": "C:\\Windows\\system32\\iexpress.exe", "hash_md5": "17B93A43E25D821D01AF40BA6BABCC8C", "hash_sha1": "97C978D78056D995F751DFEF1388D7CCE4CC404A", "hash_sha256": "D070B79FA254C528BABB73D607A7A8FD53DB89795D751F42FC0A283B61A76FD3", "hash_sha384": "EFBC94B257E3925846AB253748F8D6281C302A2393CA8CF332635D929222CD0C8299FA94E28E274F703E5DFF56FF4D78", "hash_sha512": "6B5743B37A3BE8AE9EE2AB84E0749C32C60544298A7CCE396470AA40BBD13F2E838D5D98159F21D500D20817C51EBCE4B1D2F554E3E05F6C7FC97BC9D70EA391", "hash_ssdeep": "3072:d7g3ODTHYAlYzLXB08Pfd0Zu/Rh1hNDnGOb+ahXNqJohePnq45L843:dECNYzLXB0KfdvR1NDGOb+asEwv5L", "hash_imp": "EB7245009D5161BC32C51EA9DCB81D49", "hash_pesha1": "F17688CD41C31E67DEFF5D7B797DF1F12FD4AF43", "hash_pe256": "0F683FE1F00F8300214997FCE3290306E875E56DC91657328F5921989B7F88A2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Wizard", "meta_original_filename": "IEXPRESS.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d070b79fa254c528babb73d607a7a8fd53db89795d751f42fc0a283b61a76fd3/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "(R-D) C:\\Windows\\System32\\en-US\\iexpress.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.19041.1_en-us_6144a36069349598": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.19041.1_en-us_6144a36069349598\\comctl32.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\iexpress.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28\\COMCTL32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ], "runtime_window_title": "IExpress Wizard" }, "immersivetpmvscmgrsvr.exe-EF47C7172F61D13830DE98749247E789": { "file_name": "immersivetpmvscmgrsvr.exe", "file_path": "C:\\Windows\\system32\\immersivetpmvscmgrsvr.exe", "hash_md5": "EF47C7172F61D13830DE98749247E789", "hash_sha1": "FE4F98326DF1B7AA3D0EC8C6368AB14269DA3815", "hash_sha256": "B1395245E76BE0EDB9B0C9C7D59660314893AB5C6609E794131789EA79E72841", "hash_sha384": "8AEA943341F4F44ADF3A184CD7E0AE601C965F5E9769240D8F79CB50C61954881C5472A485D3BFC5FBD46F02ED3F227A", "hash_sha512": "5ED62F5B14F87D5BF537F51D9F3AFA2366B5A2502A5D018954E1699957E5984A89F94B79564D4B1502B034BE5F5B44C7B4CEADD2F84742B785D088B01FC57326", "hash_ssdeep": "3072:TUaba/d/VYCcMcML0KPAapOeyO/njDmsFuV:TxmF/mC/0KYQOrGGs", "hash_imp": "EF430A49CAEE55F9924945FCB05ACA33", "hash_pesha1": "2D024BE173F252E8D7F74250B2E861B7F5DDA2D7", "hash_pe256": "69D34501A954247691AC007347588CCB804F1DE4E778ECFFFEF6CB750E772705", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Immersive TPM Virtual Smart Card Manager COM Server", "meta_original_filename": "ImmersiveTpmVscMgrSvr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/b1395245e76be0edb9b0c9c7d59660314893ab5c6609e794131789ea79e72841/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\immersivetpmvscmgrsvr.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\immersivetpmvscmgrsvr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\profapi.dll", "C:\\Windows\\system32\\WinSCard.dll", "C:\\Windows\\system32\\DEVOBJ.dll" ] }, "InfDefaultInstall.exe-EE18876C1E5DE583DE7547075975120E": { "file_name": "InfDefaultInstall.exe", "file_path": "C:\\Windows\\system32\\InfDefaultInstall.exe", "hash_md5": "EE18876C1E5DE583DE7547075975120E", "hash_sha1": "F7FCB3D77DA74DEEE25DE9296A7C7335916504E3", "hash_sha256": "E59127B5FE82714956C7A1F10392A8673086A8E1F609E059935C7DA1FA015A5D", "hash_sha384": "0877DD43A5106BFFC866D40BA29656CA8E8D44BE66E8ADDB7FCBC64052972C8ABE895DF1D6C37E5FCF0C65C552975605", "hash_sha512": "08BC4D28B8F528582C58175A74871DD33AC97955C3709C991779FC34B5BA4B2BA6FF40476D9F59345B61B0153FD932B0EA539431A67FF5012CB2AC8AB392F73C", "hash_ssdeep": "192:GvRYnSvsizWLyiXELlX4NtbEHyuCjL0gEL4Ji6yNqhs3AOs9aW/GW:GvenSvPwEhatOfCP0T4JiLwOcaW/GW", "hash_imp": "3E175C26441FF14C3E974BD9038CB8CB", "hash_pesha1": "B05E6D48FD253069F7810ABEB20CB21397FFB437", "hash_pe256": "1EBB6DC47E46B1442B09818D26F77234D03BFA359287869012ECB11A598540E8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "INF Default Install", "meta_original_filename": "InfDefaultInstall.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e59127b5fe82714956c7a1f10392a8673086a8e1f609e059935c7da1fa015a5d/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\InfDefaultInstall.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\newdev.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\InfDefaultInstall.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\system32\\newdev.dll", "C:\\Windows\\system32\\drvstore.dll" ], "runtime_window_title": "Install Error" }, "InputSwitchToastHandler.exe-B7B0FCB7932E5C90F30ABD807D810616": { "file_name": "InputSwitchToastHandler.exe", "file_path": "C:\\Windows\\system32\\InputSwitchToastHandler.exe", "hash_md5": "B7B0FCB7932E5C90F30ABD807D810616", "hash_sha1": "1DABF4374D44E531042EDFF4652BF1220D537C1F", "hash_sha256": "2BF6B3E12E08EE322A6C3FD6437E36D2DC8CF3A2C16BBB5A1A30A61626B24123", "hash_sha384": "D7E2F429929747AC881AC100F2725027ABD479F3397641F4C0F69A773DEBE86A8118171FCA76AC5DDAE1C619EE845751", "hash_sha512": "3DAA20EAFF8CD5B7F3A4E1EA99C2ACBD0DF4B627FBA66EF4442524904F59DC962731D6C2272E271B39D29C79D9FED07E3D00D8B2EA9F2052E779DC068BB54582", "hash_ssdeep": "1536:KWEXl+E9vPzlUPhJ7j1+3HmzKrHWVoPhoJLi:nEXPkPjj+WQHA++", "hash_imp": "E1D88F4B1D4C6DAE79ADFCF44DF28C32", "hash_pesha1": "AED58C204E42E593D83BF9BA54511DD31B99E54D", "hash_pe256": "44504B25156C408A75D8581B0543139BC9A67097714E15EDA44AD82F78C7FABA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Input Switch Toast Handler", "meta_original_filename": "InputSwitchToastHandler.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2bf6b3e12e08ee322a6c3fd6437e36d2dc8cf3a2c16bbb5a1a30a61626b24123/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\InputSwitchToastHandler.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "iotstartup.exe-3CDBF5BEDE229EAEC307F6AA547E5239": { "file_name": "iotstartup.exe", "file_path": "C:\\Windows\\system32\\iotstartup.exe", "hash_md5": "3CDBF5BEDE229EAEC307F6AA547E5239", "hash_sha1": "7D9A89234D5DEA57576BD378D392B1471CCDC7A0", "hash_sha256": "1726E468963A71BE4445369BA4822EBB4E058154EFB887D33F3D0939E322F8AD", "hash_sha384": "22C7FE45B0DD6C1616C38F4DFDABA563E077FEA6B9411A788EA084AACFFF303F438A2E242237A064B04F668851336271", "hash_sha512": "0A9A6E3EFBBFC8348CCFD3BC3CFE365FDA70BE7245BFFF739E09DD45CD2610FB6FC8EF16B4488C87FFDD40F1A089FFF28801AC3E3EC1C2A989B768BB9379245C", "hash_ssdeep": "3072:1apgtemxd/Jc4Yx3WJ781aY1b/0EVCug8cEexFQG33UUt:UpgxxdB3Q3WJ78gC0EVDcXxFb9t", "hash_imp": "00D32FE90872607F30106DCFDCE1114F", "hash_pesha1": "74497166DA53562534C88E7285730947D3EE0849", "hash_pe256": "96BBE4861FEF28FF4AB0E082DDAE5A525EBD4D053373453AD6E06CCAAEC442E4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IotStartup", "meta_original_filename": "iotstartup.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1726e468963a71be4445369ba4822ebb4e058154efb887d33f3d0939e322f8ad/detection", "output": "Usage:\r\n IotStartup [list|add|remove|startup] ([headed|headless]) (suppress) (std::regex regular expression with implied ^ prepended)\r\n IotStartup [run|stop] (std::regex regular expression with implied ^ prepended)\r\n IotStartup [help|-?|-h|--help]\r\n\r\nExamples:\r\n IotStartup list // list installed applications\r\n IotStartup list headed // list installed headed applications\r\n IotStartup list headless // list installed headless applications\r\n IotStartup list MyApp // list installed applications that match pattern MyApp\r\n\r\n IotStartup add headed MyApp // add headed application that matches pattern MyApp. Pattern must match only one application.\r\n IotStartup add headless Task1 // add headless applications that match pattern Task1\r\n\r\n IotStartup remove headless Task1 // remove headless applications that match pattern Task1\r\n IotStartup remove headless suppress Task1 // remove headless applications that match pattern Task1 and suppress WNF notification\r\n\r\n IotStartup startup // list headed and headless applications registered for startup\r\n IotStartup startup MyApp // list headed and headless applications registered for startup that match pattern MyApp\r\n IotStartup startup headed MyApp // list headed applications registered for startup that match MyApp\r\n IotStartup startup headless Task1 // list headless applications registered for startup that match Task1\r\n\r\n IotStartup run MyApp // Start app identified by MyApp (see 'iotstartup list')\r\n IotStartup stop MyApp // Stop app identified by MyApp (see 'iotstartup list')\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\iotstartup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ipconfig.exe-62F170FB07FDBB79CEB7147101406EB8": { "file_name": "ipconfig.exe", "file_path": "C:\\Windows\\system32\\ipconfig.exe", "hash_md5": "62F170FB07FDBB79CEB7147101406EB8", "hash_sha1": "D9BBB4E4900FF03B0486FAC32768170249DAD82D", "hash_sha256": "53E000F5AA9B3A00934319DB8080BB99CB323BF48FC628A64F75D7847C265606", "hash_sha384": "AE3015ED164E0BD9AA70C8989EA032D2371F71DEE2938B0C07284B551FC0E40842F0170BB77306EB03FA8B0767631069", "hash_sha512": "81BD918EC7617ACEA3D8B5659AC518E5BC19E585F49BDD601FFF6FADEA95F2FD57450EE41D181280089B92C949289249A350AA5428E2E31B53FDFF2F47C46265", "hash_ssdeep": "768:PlrmW/PE2IjDjU6O5UvNW5zCfhbxmXYlM76Ubni:PlSW3JII5m1WYfhbx7MGQni", "hash_imp": "1002D523645A81BC52877D82D9E88417", "hash_pesha1": "FBB341C72B2625373555F7B07F1899F603F01EDA", "hash_pe256": "EFAE044BF7D3E32EFDFD6CAA094B738C567B69E68AFCDC40E5849DCC8653AD1B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IP Configuration Utility", "meta_original_filename": "ipconfig.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/53e000f5aa9b3a00934319db8080bb99cb323bf48fc628a64f75d7847c265606/detection", "output": "\r\nError: unrecognized or incomplete command line.\r\n\r\nUSAGE:\r\n ipconfig [/allcompartments] [/? | /all | \r\n /renew [adapter] | /release [adapter] |\r\n /renew6 [adapter] | /release6 [adapter] |\r\n /flushdns | /displaydns | /registerdns |\r\n /showclassid adapter |\r\n /setclassid adapter [classid] |\r\n /showclassid6 adapter |\r\n /setclassid6 adapter [classid] ]\r\n\r\nwhere\r\n adapter Connection name \r\n (wildcard characters * and ? allowed, see examples)\r\n\r\n Options:\r\n /? Display this help message\r\n /all Display full configuration information.\r\n /release Release the IPv4 address for the specified adapter.\r\n /release6 Release the IPv6 address for the specified adapter.\r\n /renew Renew the IPv4 address for the specified adapter.\r\n /renew6 Renew the IPv6 address for the specified adapter.\r\n /flushdns Purges the DNS Resolver cache.\r\n /registerdns Refreshes all DHCP leases and re-registers DNS names\r\n /displaydns Display the contents of the DNS Resolver Cache.\r\n /showclassid Displays all the dhcp class IDs allowed for adapter.\r\n /setclassid Modifies the dhcp class id. \r\n /showclassid6 Displays all the IPv6 DHCP class IDs allowed for adapter.\r\n /setclassid6 Modifies the IPv6 DHCP class id.\r\n\r\n\r\nThe default is to display only the IP address, subnet mask and\r\ndefault gateway for each adapter bound to TCP/IP.\r\n\r\nFor Release and Renew, if no adapter name is specified, then the IP address\r\nleases for all adapters bound to TCP/IP will be released or renewed.\r\n\r\nFor Setclassid and Setclassid6, if no ClassId is specified, then the ClassId is removed.\r\n\r\nExamples:\r\n > ipconfig ... Show information\r\n > ipconfig /all ... Show detailed information\r\n > ipconfig /renew ... renew all adapters\r\n > ipconfig /renew EL* ... renew any connection that has its \r\n name starting with EL\r\n > ipconfig /release *Con* ... release all matching connections,\r\n eg. \"Wired Ethernet Connection 1\" or\r\n \"Wired Ethernet Connection 2\"\r\n > ipconfig /allcompartments ... Show information about all \r\n compartments\r\n > ipconfig /allcompartments /all ... Show detailed information about all\r\n compartments\r\n", "runtime_modules": [ "C:\\Windows\\system32\\ipconfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "iscsicli.exe-87EA97EDF96EEFE4DB352CB584E6AC07": { "file_name": "iscsicli.exe", "file_path": "C:\\Windows\\system32\\iscsicli.exe", "hash_md5": "87EA97EDF96EEFE4DB352CB584E6AC07", "hash_sha1": "3EF9C8EF289C38BB8BD6011A67691A54CBCB2405", "hash_sha256": "BDCECA674699354DD54A9C3C2481FF9C1B947132C348DE135CC7EDEEA452B524", "hash_sha384": "FE1458237F9BA8E0FEAA064B9EA38582E8EC249490954C5184607567495BD4C8159A88B1F7C02B7233D4896E2DEFE705", "hash_sha512": "93DB8CB3F0C49FCB90CD39B1CAF4D4F8BA1F9D22F24E5C3100889258EFC2E20B81969A52944CC52285A87D1822C72EF7A9FA0BCEEA9BB12C746B304425E64B7C", "hash_ssdeep": "1536:QJHREH44NN63rS+PYbX7XDB9F3KyqacVubBkks2NztFxUJr23NrJn:lHHN67SlrWalbBx3PoaNJn", "hash_imp": "028C14ACF014C0D70B45E3DF78F2A400", "hash_pesha1": "3845245FA3154707290B7AE634B2AFB1915FD4BF", "hash_pe256": "79450F263AE26B8F8740239DD0AEC4F44DBFDA178FDB1D537F9F00DE2262C35D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "iSCSI Discovery tool", "meta_original_filename": "iscsicli.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/bdceca674699354dd54a9c3c2481ff9c1b947132c348de135cc7edeea452b524/detection", "output": "Microsoft iSCSI Initiator Version 10.0 Build 19041\n\niscsicli\n\niscsicli AddTarget <TargetName> <TargetAlias> <TargetPortalAddress>\n <TargetPortalSocket> <Target flags>\n <Persist> <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType>\n <Mapping Count> <Target Lun> <OS Bus> <Os Target> \n <OS Lun> ...\n\niscsicli RemoveTarget <TargetName> \n\niscsicli AddTargetPortal <TargetPortalAddress> <TargetPortalSocket> \n [HBA Name] [Port Number]\n <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType>\n\niscsicli RemoveTargetPortal <TargetPortalAddress> <TargetPortalSocket> [HBA Name] [Port Number]\n\niscsicli RefreshTargetPortal <TargetPortalAddress> <TargetPortalSocket> [HBA Name] [Port Number]\n\niscsicli ListTargets [ForceUpdate]\n\niscsicli ListTargetPortals\n\niscsicli TargetInfo <TargetName> [Discovery Mechanism]\n\niscsicli LoginTarget <TargetName> <ReportToPNP>\n <TargetPortalAddress> <TargetPortalSocket>\n <InitiatorInstance> <Port number> <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType> <Key>\n <Mapping Count> <Target Lun> <OS Bus> <Os Target> \n <OS Lun> ...\n\niscsicli LogoutTarget <SessionId>\n\niscsicli PersistentLoginTarget <TargetName> <ReportToPNP>\n <TargetPortalAddress> <TargetPortalSocket>\n <InitiatorInstance> <Port number> <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType> <Key>\n <Mapping Count> <Target Lun> <OS Bus> <Os Target> \n <OS Lun> ...\n\niscsicli ListPersistentTargets\n\niscsicli RemovePersistentTarget <Initiator Name> <TargetName> \n <Port Number> \n <Target Portal Address> \n <Target Portal Socket> \n\niscsicli AddConnection <SessionId> <Initiator Instance>\n <Port Number> <Target Portal Address>\n <Target Portal Socket> <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType> <Key>\n\niscsicli RemoveConnection <SessionId> <ConnectionId> \niscsicli ScsiInquiry <SessionId> <LUN> <EvpdCmddt> <PageCode>\n\niscsicli ReadCapacity <SessionId> <LUN>\n\niscsicli ReportLUNs <SessionId>\n\niscsicli ReportTargetMappings\n\niscsicli ListInitiators\n\niscsicli AddiSNSServer <iSNS Server Address>\n\niscsicli RemoveiSNSServer <iSNS Server Address>\n\niscsicli RefreshiSNSServer <iSNS Server Address>\n\niscsicli ListiSNSServers\n\niscsicli FirewallExemptiSNSServer\n\niscsicli NodeName <node name>\n\niscsicli SessionList <Show Session Info>\n\niscsicli CHAPSecret <chap secret>\n\niscsicli TunnelAddr <Initiator Name> <InitiatorPort> <Destination Address> <Tunnel Address> <Persist>\n\niscsicli GroupKey <Key> <Persist>\n\niscsicli BindPersistentVolumes\n\niscsicli BindPersistentDevices\n\niscsicli ReportPersistentDevices\n\niscsicli AddPersistentDevice <Volume or Device Path>\n\niscsicli RemovePersistentDevice <Volume or Device Path>\n\niscsicli ClearPersistentDevices\n\niscsicli Ping <Initiator Name> <Address> [Request Count] [Request Size] [Request Timeout]\n\niscsicli GetPSKey <Initiator Name> <initiator Port> <Id Type> <Id>\n\niscsicli PSKey <Initiator Name> <initiator Port> <Security Flags> <Id Type> <Id> <Key> <persist>\nQuick Commands\n\niscsicli QLoginTarget <TargetName> [CHAP Username] [CHAP Password]\n\niscsicli QAddTarget <TargetName> <TargetPortalAddress>\n\niscsicli QAddTargetPortal <TargetPortalAddress>\n [CHAP Username] [CHAP Password]\n\niscsicli QAddConnection <SessionId> <Initiator Instance>\n <Target Portal Address>\n [CHAP Username] [CHAP Password]\n\nTarget Mappings:\n <Target Lun> is the LUN value the target uses to expose the LUN.\n It must be in the form 0x0123456789abcdef\n <OS Bus> is the bus number the OS should use to surface the LUN\n <OS Target> is the target number the OS should use to surface the LUN\n <OS LUN> is the LUN number the OS should use to surface the LUN\n\nPayload Id Type:\n ID_IPV4_ADDR is 1 - Id format is 1.2.3.4\n ID_FQDN is 2 - Id format is ComputerName\n ID_IPV6_ADDR is 5 - Id form is IPv6 Address\nSecurity Flags:\n TunnelMode is 0x00000040\n TransportMode is 0x00000020\n PFS Enabled is 0x00000010\n Aggressive Mode is 0x00000008\n Main mode is 0x00000004\n IPSEC/IKE Enabled is 0x00000002\n Valid Flags is 0x00000001\n\nLogin Flags:\n ISCSI_LOGIN_FLAG_REQUIRE_IPSEC 0x00000001\n IPsec is required for the operation\n\n ISCSI_LOGIN_FLAG_MULTIPATH_ENABLED 0x00000002\n Multipathing is enabled for the target on this initiator\n\nAuthType:\n ISCSI_NO_AUTH_TYPE = 0,\n No iSCSI in-band authentication is used\n\n ISCSI_CHAP_AUTH_TYPE = 1,\n One way CHAP (Target authenticates initiator is used)\n\n ISCSI_MUTUAL_CHAP_AUTH_TYPE = 2\n Mutual CHAP (Target and Initiator authenticate each other is used)\n\nTarget Flags:\n ISCSI_TARGET_FLAG_HIDE_STATIC_TARGET 0x00000002\n If this flag is set then the target will never be reported unless it\n is also discovered dynamically.\n\n ISCSI_TARGET_FLAG_MERGE_TARGET_INFORMATION 0x00000004\n If this flag is set then the target information passed will be\n merged with any target information already statically configured for\n the target\n\nCHAP secrets, CHAP passwords and IPSEC preshared keys can be specified as\na text string or as a sequence of hexadecimal values. The value specified on\nthe command line is always considered a string unless the first two characters\n0x in which case it is considered a hexadecimal value.\n\nFor example 0x12345678 specifies a 4 byte secret\n\nAll numerical values are assumed decimal unless preceeded by 0x. If\npreceeded by 0x then value is assumed to be hex\n\niscsicli can also be run in command line mode where iscsicli commands\ncan be entered directly from the console. To enter command line\nmode, just run iscsicli without any parameters\n\nThe operation completed successfully. \n", "runtime_modules": [ "C:\\Windows\\system32\\iscsicli.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "iscsicpl.exe-50930FF50D66E5F3B90CCA7F09DED1C6": { "file_name": "iscsicpl.exe", "file_path": "C:\\Windows\\system32\\iscsicpl.exe", "hash_md5": "50930FF50D66E5F3B90CCA7F09DED1C6", "hash_sha1": "4D884BCAF78308F6D91C2A5D50633E6537C28DE1", "hash_sha256": "E5E2F1673D1DA42B134C35D74655CBEB7272686D52F65B5FB3C1FE2B2F75586E", "hash_sha384": "EF3C4C79D0B3F31EFE486CDA9F022E6925B5C23C4C01CDA633F7FF9AB5EB252EBA3729F9B394301B8C0E7E6BF51E48E2", "hash_sha512": "D445F6176CABB1F73C421A5FAF6E690767F60615F6F2B89A85B7336AC5007F52E19A72546D6D9F123C565421734253E627212DE73EEEA92CB6F2211A3D093C73", "hash_ssdeep": "192:CVMpF8FIY/SHoIafKIph607zumzBPJzF2Z9d643okmr2W7gRWl:gMpF+SIIaKyV7Zr52or2W7gRW", "hash_imp": "23B7709C37B2C36EA9464F15DEA83D64", "hash_pesha1": "DFD14ADA53BFF9F941B421C361B6D5D619A8F9E4", "hash_pe256": "68586C3A0F90FFC93A117426CF256036D106FA156939BC81A3558E8557233ADB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft iSCSI Initiator Configuration Tool", "meta_original_filename": "iscsicpl.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/e5e2f1673d1da42b134c35d74655cbeb7272686d52f65b5fb3c1fe2b2f75586e/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\iscsicpl.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\iscsicpl.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\SystemResources\\iscsicpl.dll.mun": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\iscsicpl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ] }, "isoburn.exe-2853B9F80D6B8309759CC20D5540BF87": { "file_name": "isoburn.exe", "file_path": "C:\\Windows\\system32\\isoburn.exe", "hash_md5": "2853B9F80D6B8309759CC20D5540BF87", "hash_sha1": "D5D7689E1862474F73E1A2259C0FB4762705E979", "hash_sha256": "CF44CE08F8FB81D23AA960D47701AC0312681D2F4E8E5A601707DB46BF840BF9", "hash_sha384": "6F98A844BF96FF6D8CA18FBD01612C91D047FC53AF38AA1B3B5BEE9781EB7602F75F69B8BFA719FE4AEB046211A04722", "hash_sha512": "46D66B1BB3702841EA5E348ACA821AF36A0919437C8A69B697B6990110FFECD59E8510763AFDC5A7F1AC1018AC64079312E53E7908CF95A236AB58A5A6503A9C", "hash_ssdeep": "1536:MUfw0C2PhvRxw7mK7FIG4FfhRRGxbR4M/ybB/6EK8sYuyLiFAbeHZrQqf:Bhvs7Zch7qbRQ28tbeSeHd3", "hash_imp": "1742AC388B6BB3F558A56D5CBF60F3D3", "hash_pesha1": "058B9D864D15A59CC1A2C869D1CF6ECECA6675F8", "hash_pe256": "6819EACBFC8EAE800EF42EAC663F742C9CE1FF4361527BDFB8A413355D20FDFE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Disc Image Burning Tool", "meta_original_filename": "ISOBURN.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/cf44ce08f8fb81d23aa960d47701ac0312681d2f4e8e5a601707db46bf840bf9/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\isoburn.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\isoburn.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ], "runtime_window_title": "Windows Disc Image Burner" }, "klist.exe-8ADE30AD79FDC8BFC227D35C73C640F3": { "file_name": "klist.exe", "file_path": "C:\\Windows\\system32\\klist.exe", "hash_md5": "8ADE30AD79FDC8BFC227D35C73C640F3", "hash_sha1": "5CE270AA93B6AA7AD851DC50EE1EABA3F2B950BF", "hash_sha256": "F5AB529EF4B76FF81F363F600202EB82925CE624C60F7AD3A4AEF3C8FCBECA41", "hash_sha384": "E0F7F464930A028A528471A3F252CAA77C7C9B1EBC5FC64E2C779FB02ADE7E801B3703F6E60CC194D2E0555AD4D01496", "hash_sha512": "57FF8FA6AF0CD9AF1925488EBF2845ECDF3CCEA5CBF7B8E035895D8E9468BDAE024257C8E3A3D1EE771731E7B29367B873C24A2F045D236D54A1CAE3D34B8E28", "hash_ssdeep": "768:zGsdjbk6Bk9tUd8gDXhGwKqs+AXhWkPlFE0eRt/vQ8Fci4n8D1ckyDj/eo3F9tN3:zGmU6K9MpDKf+AXMkYBRt+jd3F9tC0", "hash_imp": "85207CDD890ACE87BF7EF7906D90318B", "hash_pesha1": "707DB74244FA8805FB5BB21EAE692813B6D327E2", "hash_pe256": "320BF938C62919B2FF76D63D6E030FC22F597F844F7282985B553B24C0DF2FCC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Tool for managing the Kerberos ticket cache", "meta_original_filename": "klist.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f5ab529ef4b76ff81f363f600202eb82925ce624c60f7ad3a4aef3c8fcbeca41/detection", "output": "\r\nUsage: klist.exe [command]\r\n\r\nCommand list:\r\n [tickets] [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n tgt [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n purge [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n sessions [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n kcd_cache [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n get <SPN> [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n [-kdcoptions <options>] [-cacheoptions <options>]\r\n add_bind <DOMAIN> <DC>\r\n query_bind\r\n purge_bind\r\n", "runtime_modules": [ "C:\\Windows\\system32\\klist.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ksetup.exe-A2D2EBDC4529455F734EB079E75EE3CD": { "file_name": "ksetup.exe", "file_path": "C:\\Windows\\system32\\ksetup.exe", "hash_md5": "A2D2EBDC4529455F734EB079E75EE3CD", "hash_sha1": "D8BD77D83B112ED8CA462C0E848E8DD94234D73D", "hash_sha256": "8DE772DC39DE39E6D156529E9130E61079E400A14116B42A7E8614D509B68C30", "hash_sha384": "60D1802492E6E42F33B85338359A20E56BC39F56645B78512C13B1770F3FD6F35B0098EA92D72C7254C7D42D1B5FFEFD", "hash_sha512": "1C59A1DDF244DAE13FE0860B149669F809C64642B6ADF9E0CFEB6A17B7DD801BDD54221146A76F3CDCB2DC600B1BB69C6297F929167CA35327FB030105098BE7", "hash_ssdeep": "768:WZqFgWdpyXUkJtKJ5dLdTgSPkzCOEIn3jOd+rowm1s0MO+z00PiIS15VNbog9b0x:z/yXJYvRup3SsrO1onqIS15VNbog9b0x", "hash_imp": "1F57ADDB730D5E4437682FEAF1F27C0D", "hash_pesha1": "D7162604F373925803376EA5E95424DD9D28E59B", "hash_pe256": "AE987B2F31D8F0F609A6C46AB341F37D2B87061EF92139768FD7A105A2CC6E0C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Kerberos Setup tool", "meta_original_filename": "ksetup.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8de772dc39de39e6d156529e9130e61079e400a14116b42a7e8614d509b68c30/detection", "output": "\r\nUSAGE:\r\n/SetRealm <DnsDomainName>\r\n\tMakes this computer a member of an RFC1510 Kerberos Realm\r\n/MapUser <Principal> [Account]\r\n\tMaps a Kerberos Principal ('*' = any principal)\r\r\n\tto an account ('*' = an account by same name);\r\r\n\tIf account name is omitted, mapping is deleted \r\r\n\tfor the specified principal\r\n/AddKdc <RealmName> [KdcName]\r\n\tDefines a KDC entry for the given realm.\r\r\n\tIf KdcName omitted, DNS may be used to locate KDCs.\r\n/DelKdc <RealmName> [KdcName]\r\n\tdeletes a KDC entry for the realm.\r\r\n\tIf KdcName omitted, the realm entry itself is deleted.\r\n/AddKpasswd <Realmname> <KpasswdName>\r\n\tAdd Kpasswd server address for a realm\r\n/DelKpasswd <Realmname> <KpasswdName>\r\n\tDelete Kpasswd server address for a realm\r\n/Server <Servername>\r\n\tspecify name of a Windows machine to target the changes.\r\n/SetComputerPassword <Password>\r\n\tSets the password for the computer's domain account\r\r\n\t(or host principal)\r\n/RemoveRealm <RealmName>\r\n\tdelete all information for this realm from the registry.\r\n/Domain [DomainName]\r\n\tuse this domain (if DomainName is unspecified, detect it)\r\n/ChangePassword <OldPasswd> <NewPasswd>\r\n\tUse Kpasswd to change the logged-on user's password.\r\r\n\tUse '*' to be prompted for passwords.\r\n/ListRealmFlags (no args)\r\n\tLists the available Realm flags that ksetup knows\r\n/SetRealmFlags <realm> <flag> [flag] [flag] [...]\r\n\tSets RealmFlags for a specific realm\r\n/AddRealmFlags <realm> <flag> [flag] [flag] [...]\r\n\tAdds additional RealmFlags to a realm\r\n/DelRealmFlags <realm> <flag> [flag] [flag] [...]\r\n\tDeletes RealmFlags from a realm.\r\n/DumpState (no args)\r\n\tAnalyze the kerberos configuration on the given machine.\r\n/AddHostToRealmMap <host> <realm>\r\n\tAdds a mapping for <host> to <realm> to the registry.\r\n/DelHostToRealmMap <host> <realm>\r\n\tDeletes existing mapping for <host> to <realm> from the registry.\r\n/SetEncTypeAttr <domainname> <enctypes>\r\n\tSets the encryption types trust attribute for <domain> to <enctypes> (multiple types should be separated by spaces).\r\r\n\tSupported encryption types are:\r\r\n\t DES-CBC-CRC, DES-CBC-MD5, RC4-HMAC-MD5, \r\r\n\t AES128-CTS-HMAC-SHA1-96, AES256-CTS-HMAC-SHA1-96\r\n/GetEncTypeAttr <domainname>\r\n\tGets the encryption types trust attribute for <domain>.\r\n/AddEncTypeAttr <domainname> <enctypes>\r\n\tAdds <enctypes> to the encryption types trust attribute for <domain> (multiple types should be separated by spaces).\r\n/DelEncTypeAttr <domainname>\r\n\tDeletes the encryption types trust attribute for <domain>.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\ksetup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ktmutil.exe-C9D776B6A4BC22B5B9A0985AB9CD6101": { "file_name": "ktmutil.exe", "file_path": "C:\\Windows\\system32\\ktmutil.exe", "hash_md5": "C9D776B6A4BC22B5B9A0985AB9CD6101", "hash_sha1": "FC72D96DF9D0E61A0458280290B27165258D735C", "hash_sha256": "81765113B2DF32F13EF09FC96645C183F6064B27FCF4F3A3575088F016BBB5A5", "hash_sha384": "056E17A1962F58322DFE61CDF94A7882A2397E981BDEDDD1C84A40BD94F97A1FC9DBE704FC8D49B497C2D86C2D50B9ED", "hash_sha512": "E5080ECEEAB1C3A430A93F3B42CC09A295A02F3D3EFA538965AEA19EAE77F870A9191104D92BC373F7E806A2245B507D1D231BFF71CDE5684DD634CA82D75141", "hash_ssdeep": "384:Pqsz66pGvFTnOVsFkxaHtywf+DgY2+WjjW:Pc68F6hx1VUBD", "hash_imp": "B3B2528C3A2C9CC109BE296FC38F31BF", "hash_pesha1": "9D83BCF6B461E170BB04F930E3A7A145CD190487", "hash_pe256": "7FF68DF310DC5ED82F9BDD62C2B2B67C4B6F49B3D64088EAF14AD1C31398FEDD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Kernel Transaction Management Utility", "meta_original_filename": "ktmutil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/81765113b2df32f13ef09fc96645c183f6064b27fcf4f3a3575088f016bbb5a5/detection", "output": "--help is an invalid parameter.\r\n---- Commands Supported ----\r\n\r\ntx Commands related to transactions\r\ntm Commands related to transaction managers\r\n", "runtime_modules": [ "C:\\Windows\\system32\\ktmutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "label.exe-C62801F2FD980D444EC12455F83CF536": { "file_name": "label.exe", "file_path": "C:\\Windows\\system32\\label.exe", "hash_md5": "C62801F2FD980D444EC12455F83CF536", "hash_sha1": "82F508B9CAAF23F766935D03D43C28C787AE1B2B", "hash_sha256": "5B63CDAA6B386340186D48FCA6687B51D666F4457C1D1228C4915BDD2917A315", "hash_sha384": "1268DCD2DF01398F462C736D3C7E0615E8331C014B0D9599FB17508E7811EFD630DF953C9D1B442E5F7542C483FCE684", "hash_sha512": "CD193F836EAE332A6C5F6BF47D4B8ACC8C8E469DDCC3AA068CC9E8EF209AB77AFB73E9122728B3CD0788D4D8753785CBCD4877BF72022E29FAF2D70994CA728A", "hash_ssdeep": "384:9IKr+PAtNL+TlYeRycSXIl6Xsh/QWSCjW:9Iw+ItNqTKeAXIoXsh//", "hash_imp": "9D31AD7E7AE990941EB6693E119F8284", "hash_pesha1": "5985A9808DBBDBCDBC92A36B5ECCBD6CBE4E4095", "hash_pe256": "A47BD6707627BC976DC9B9C754154FDD6321385369C38AA85033F03753CB6118", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Label Utility", "meta_original_filename": "Label.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/5b63cdaa6b386340186d48fca6687b51d666f4457c1d1228c4915bdd2917a315/detection", "output": "Creates, changes, or deletes the volume label of a disk.\r\n\r\nLABEL [drive:][label]\r\nLABEL [/MP] [volume] [label]\r\n\r\n drive: Specifies the drive letter of a drive.\r\n label Specifies the label of the volume.\r\n /MP Specifies that the volume should be treated as a\r\n mount point or volume name.\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name. If volume name is specified,\r\n the /MP flag is unnecessary.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\label.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "LanguageComponentsInstallerComHandler.exe-CC0C8499EA3FB0FF84A4F58C3F8920A2": { "file_name": "LanguageComponentsInstallerComHandler.exe", "file_path": "C:\\Windows\\system32\\LanguageComponentsInstallerComHandler.exe", "hash_md5": "CC0C8499EA3FB0FF84A4F58C3F8920A2", "hash_sha1": "D7744AB6B72F54BBF26BD832FF1CBA162B816A47", "hash_sha256": "EC47F7C125C7412B2C0D3F8C776EC281FAEBCF82DDE7A98D25602CD1864E44B7", "hash_sha384": "7841EDCEF9E98CA65467EF2BA0C23C70279E5B8B9489E98388CF6799802B1CC0D2B75EDCE09FCEFE0A406A5EDDEC0BF7", "hash_sha512": "3580EAEDFC3EA83AD93E96F7AFC3152AE85E58D89BBA522E11AC77EC31F6DC34AAF4EE19AE743D2E85A0FF85EA6EEE010E814400E2B92FB9EBC269136F440005", "hash_ssdeep": "1536:v7kVOPRMzTIP01zyWuYZp/ytbWiw+Y3N2HKtaM2:jk8GoP01mol+HKQM2", "hash_imp": "471DBD49E64A7A69D4CE26244906F660", "hash_pesha1": "3FE485FFBBBEA566AC8739A330D37B968D0A9233", "hash_pe256": "B90B5D9B74BC1726A36E714DB3EEBAFFE428D9EE439F44C7B39541E06C969EA8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "LanguageComponentsInstaller COM Handler", "meta_original_filename": "LanguageComponentsInstallerComHandler.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/ec47f7c125c7412b2c0d3f8c776ec281faebcf82dde7a98d25602cd1864e44b7/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\LanguageComponentsInstallerComHandler.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ] }, "LaunchTM.exe-2A00EED654DD3A437922F96F7DF3AF92": { "file_name": "LaunchTM.exe", "file_path": "C:\\Windows\\system32\\LaunchTM.exe", "hash_md5": "2A00EED654DD3A437922F96F7DF3AF92", "hash_sha1": "E64AF88B2D4AE82D82EBBE118F9D19B465615D12", "hash_sha256": "F8F394A721883D69F845859DB1B02C167B6EFAB121632F1265912B94CE007C39", "hash_sha384": "0F454553A1205712784BDEF33A97477BF10A67C82B2E8442504BB381ABB8F6736AF7A98B4BD64A6E953304997BB49B62", "hash_sha512": "311A2BDDE2F499931F5D85D6472BA1A9F492B0B03B9C63AF364419DBD28AF8CD512DCA84D8E13EFAAC6EEF5777617775FF41A9D70C616AFD228068C42EFBD038", "hash_ssdeep": "192:zgvRQ0/cEyT/uufqR1a71pd1fsTvB0mWvqayW:iRsxT2lLQp/qBRWvqayW", "hash_imp": "AD4CEE994BCE4BEC755FC55C249B5C5F", "hash_pesha1": "2CD861F024C605BA8C1BE8CED5B163811814B50E", "hash_pe256": "64A7D3CE4AFFE780BF9F139F35445298D2F027677796578638ADADADA5D82B67", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Manager Launcher", "meta_original_filename": "LaunchTM.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f8f394a721883d69f845859db1b02c167b6efab121632f1265912b94ce007c39/detection", "children": "Taskmgr.exe", "runtime_modules": [ "C:\\Windows\\system32\\LaunchTM.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\uxtheme.dll" ] }, "LaunchWinApp.exe-9B5936D6FA3FDC46CB3D5195A8969380": { "file_name": "LaunchWinApp.exe", "file_path": "C:\\Windows\\system32\\LaunchWinApp.exe", "hash_md5": "9B5936D6FA3FDC46CB3D5195A8969380", "hash_sha1": "B7C65019FDFECBA36AA6EE8F66BE2CC7A6FF4343", "hash_sha256": "8D6F4DAB60B4449A2E66E840DF672156A2875C57B0A98240EC90CAD177BA87E1", "hash_sha384": "A51BF5AE360164EBAC1CB115784C8E37457660DACE95E24A50FA5A7BB28CE7B463388FC8D7BFA11A388BF13FDA394FFC", "hash_sha512": "9DA56FDA77D8C7EAC2D12C4CD47B207C1E76CA97F252654C8080BC640632AEB86E3F10AA836926A7477840F8FC8B49CD389810DEB2660DB2B44C8EDA5ABF802A", "hash_ssdeep": "768:1fbrskjaHYAdIx4a8g6DhNhuIlNg1WH1PQV5RFl0KzrLLs/gVOyWZq/:ZbqYAWq9g6DfhVlgWHZARF+Kz3bVOyWW", "hash_imp": "C4CA68CBE89618BC436A1B8B645F9E29", "hash_pesha1": "607038F96EF2D4EE4880D1F5397179732F2E7CF4", "hash_pe256": "A8B3FE7C8DDF79424DE795248980BE5D66E4CB9C964893D0A7057D84E5DE1B0A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Launch Windows App", "meta_original_filename": "LaunchWinApp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8d6f4dab60b4449a2e66e840df672156a2875c57b0a98240ec90cad177ba87e1/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\LaunchWinApp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\shcore.dll" ], "runtime_window_title": "--help" }, "LegacyNetUXHost.exe-85DC8E98C045A943DEDAE779308F06DD": { "file_name": "LegacyNetUXHost.exe", "file_path": "C:\\Windows\\system32\\LegacyNetUXHost.exe", "hash_md5": "85DC8E98C045A943DEDAE779308F06DD", "hash_sha1": "21AE751EF48D59CDE25F77B6780CE7BEC57FC866", "hash_sha256": "1F9685A107E5F4A832B923AEBB9D427146492392C39F691C393EB5A2B399DE12", "hash_sha384": "37F885194B662EFFFCB3E133760D7375331766C061BD64F72D6BEF850B5CE86BCE2B1BAE0865020CD25BC3417A5F5495", "hash_sha512": "DDCB8BEBA25C9A74396F633FB9999CFADB774FCB524BFDC004472A30CECB647A92525351523FBA8AD3FD7A76E0DC80F5BC9BDB063FCD254B749F0550F8530125", "hash_ssdeep": "3072:xoVtYneJqHctNkdp7oOj54lBLEzpgsUZz00O+9JjZR6cYlHqXo6p:xoVtYn2q8tO7olpEKsgz00O81uEXo", "hash_imp": "E50991F6BCA375B78BC40BC117F3BF7A", "hash_pesha1": "7DBE6B07521136602C47353E47CC7710C2A0C2D3", "hash_pe256": "33331F94AC3DDEDA70F4285075BA553BEBAF6FDB0AB917BE2B6AE187D9F4CE6B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Legacy Net UX Host", "meta_original_filename": "LegacyNetUXHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/1f9685a107e5f4a832b923aebb9d427146492392c39f691c393eb5a2b399de12/detection", "runtime_modules": [ "C:\\Windows\\system32\\LegacyNetUXHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\system32\\wlanapi.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "LicenseManagerShellext.exe-760FAE2CDBB9F789D307F41124F3852E": { "file_name": "LicenseManagerShellext.exe", "file_path": "C:\\Windows\\system32\\LicenseManagerShellext.exe", "hash_md5": "760FAE2CDBB9F789D307F41124F3852E", "hash_sha1": "F76659E7090505B37C95D3BE813E4DE3218A3C8E", "hash_sha256": "5F938CF1B5272FD6BCBDBA557C9D110A3624E56066464F25C99E68026798D8B5", "hash_sha384": "DE02F9FFE6A6FD75F9F436C988A047E895A6785D1B731635C27A084EE28E1D4723370D1128D0C553CEE5924F57525DE7", "hash_sha512": "86F8C96F19205456D0A73501E19B1767D03EEB5067D60A93DBA1E40B04A1448D1C1083ADBE9EEB3C3E7EDA2B65B8C36C758F89E5986DDCC4325AD95C4D8E8E4E", "hash_ssdeep": "768:U004d0m+MgrKxaNWWPhfISuVfGsWruqnj+0ngYlSzwBzbKf4RaWy2eCf:UZDrK0NWWPh7u5G/ruqjBJlSqHI4Hy2X", "hash_imp": "ACE1872AFF01E0DB43043614F1A39B6D", "hash_pesha1": "9A83EA7217582E34C016CC3C768EFF9FCE224B52", "hash_pe256": "03761CE5FA4B6A3FD6388141306598C3EF19DE7D4E357999168DEA9832A0CC72", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "LicenseManagerShellExt", "meta_original_filename": "LicenseManagerShellExt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/5f938cf1b5272fd6bcbdba557c9d110a3624e56066464f25c99e68026798d8b5/detection", "runtime_modules": [ "C:\\Windows\\system32\\LicenseManagerShellext.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "licensingdiag.exe-73ECA0B9B3777563106041218ACDA4C9": { "file_name": "licensingdiag.exe", "file_path": "C:\\Windows\\system32\\licensingdiag.exe", "hash_md5": "73ECA0B9B3777563106041218ACDA4C9", "hash_sha1": "FCD6EF0A559401A9C3EC1F2F681B63BE5FA050A7", "hash_sha256": "EFC01E7C6E0F807895C385C5B6D2510A20A47275C9FFCE76A75B976567B44E58", "hash_sha384": "81FC4988882ACB928D532215241C2A9174F990B9993F369249AC6AFF628694FEA2E07E194BE5AB87DD0FFDB035651772", "hash_sha512": "9E70BE77FCB3A2326066C85796DE1DD9F3D4161E5F76277834FD5C0FB089CBEFE00FFE61C787D11DB1C9D6CE018C173CE2130ABFB7D93F6C1B3A662C4A88BC43", "hash_ssdeep": "6144:UnFs3rO9QxJh027vdUKEDY8topthYakSY5kGMnLdCCxwtQbize+VZmjNu2Xqm7YF:UArO9QzDB8mk8Y5kZnxvwtQbiz3oYwS", "hash_imp": "A751FC7E8269F06C95E6B324DDA13568", "hash_pesha1": "51AA4A2F3EC79274DB3EBFE4AA36DEC81569DD23", "hash_pe256": "8DCF957A086F36654440D43AB71C22E9488E1A7C02CBF910367E68217146D1D3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Licensing Diagnostic Tool", "meta_original_filename": "LicensingDiag.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/efc01e7c6e0f807895c385c5b6d2510a20a47275c9ffce76a75b976567b44e58/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\licensingdiag.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\licensingdiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "runtime_window_title": "Microsoft Licensing Diagnostic Tool" }, "LicensingUI.exe-D1FBF1E85C785C7E0DFE3C2AC860A115": { "file_name": "LicensingUI.exe", "file_path": "C:\\Windows\\system32\\LicensingUI.exe", "hash_md5": "D1FBF1E85C785C7E0DFE3C2AC860A115", "hash_sha1": "8351E3F6B3829F0B6D0D3E9C61F1B895457FCB65", "hash_sha256": "BCB44BD5F1738FD10A2150EB59AA4C70DD3DAC09085427B1B9CA427B45F26685", "hash_sha384": "45E6D1DFCF84AF3991FFB146146095E830260C8E861B998153C8DB8D5A5FF8D7FAD2F6373C3321DB472FCD03671DDAB5", "hash_sha512": "1D515EBD6A6D30C09B33113298B2A21F47CDE77C264DCD30DF07FABB2883C9529B914C2E0F4D860E355B3CACA90321D35C0D131451F7F4E980D8AC63F539ACA7", "hash_ssdeep": "3072:Jf95vgmYcsVD88d89a1aanLqzL1wssFWZY9i9Co/vkTpm4Etk:JV557PTa1Vn2VwssFWZY9i9Co1O", "hash_imp": "F20BBD4E6426B2E3E1A9FE792E75A421", "hash_pesha1": "08889A922EE83708117D40B03CA55AEEA1A1687E", "hash_pe256": "E50C1DE86B4EFA1B6E3F8511DA95D4929C2B321F40F391DC5887C4D30B7EB2F9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Licensing UI", "meta_original_filename": "LicensingUI.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/bcb44bd5f1738fd10a2150eb59aa4c70dd3dac09085427b1b9ca427b45f26685/detection", "runtime_modules": [ "C:\\Windows\\system32\\LicensingUI.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\DUI70.dll" ] }, "LocationNotificationWindows.exe-9BAD04696E81E4420A99660C8D1388A1": { "file_name": "LocationNotificationWindows.exe", "file_path": "C:\\Windows\\system32\\LocationNotificationWindows.exe", "hash_md5": "9BAD04696E81E4420A99660C8D1388A1", "hash_sha1": "39A7906F585C5DF2E5105DA07DEC0669C46174F9", "hash_sha256": "A9024C4C0ED03730085FB529828A917F701E3DCA30D3286AE0D41E9FFF33F445", "hash_sha384": "C95FDCCF27B395B62EEAADB17ACB7346DB06F6340996BC8147BFA158A63D6B43B3FEDDFF70A1094E087D2A636B518BCB", "hash_sha512": "9626EFC5A8C89A0F761DE07EADA67596A9AAD3C4895DF408611B0996C92CBE1EED795CB51A821C281A3649FB107282D15565178912688F70FDA49F9B96304777", "hash_ssdeep": "1536:VVrqPCW4YrmTpVF5ETTJXeIPsi7oTIMvNyDJb2zL:VVnamTpVF5qJEeyIMvoEzL", "hash_imp": "43770938065E918EAD8F8E36EA492A75", "hash_pesha1": "9C984DC20A27E0F1FFFCCE79386C59483B6D016E", "hash_pe256": "92DE8A8EBCED271B6DEA5AAE6F30C36E13250369DEB1A0FC253EF9396FB34A4B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Location Notification", "meta_original_filename": "LocationNotificationWindows.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a9024c4c0ed03730085fb529828a917f701e3dca30d3286ae0d41e9fff33f445/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\LocationNotificationWindows.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\LocationNotificationWindows.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "Locator.exe-D45676C47616B9ABBFAEC97DD3B240A8": { "file_name": "Locator.exe", "file_path": "C:\\Windows\\system32\\Locator.exe", "hash_md5": "D45676C47616B9ABBFAEC97DD3B240A8", "hash_sha1": "DEFE4561F0A6B279CACC18E8B92728046709110C", "hash_sha256": "E13985D667F66B7A0082356F23270F61A57B8C2DD211B1E09D66D7970D7B4D6A", "hash_sha384": "2868B875D0A9A8A5D3DCDB4832D79BC268F7204486A5640043EF671393F9E02AF928E1102E64957BC8BF978A7A6EBD21", "hash_sha512": "227BFC40E7553A061B5E09C630897797C53DDD5E582D9D2D264AE28407D4320EC89EAF0E18680AC7D17699CFB327366BF9AACBB56CC743D72258B82B0D0FE0CD", "hash_ssdeep": "192:uOMwhqSgiDsX8xMxbPurbzEjd9/cGmSrsa1q18oDD9Ge8r1mDqW0lW:OwASH/qbGrbOc+rpo1ZDdtDqW0lW", "hash_imp": "CBECBDF0E16268273DCA4CB132D15D23", "hash_pesha1": "25123A0F52177618E52128C2F505AFE6E2463742", "hash_pe256": "28660B13BBC8C844CAA61992E330AE95F4E535299B73BA0FA419E9B73E9A15FE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Rpc Locator", "meta_original_filename": "locator.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e13985d667f66b7a0082356f23270f61a57b8c2dd211b1e09d66d7970d7b4d6a/detection", "runtime_modules": [ "C:\\Windows\\system32\\Locator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "LockAppHost.exe-669B039303627B2FFD771B4B74C78BF7": { "file_name": "LockAppHost.exe", "file_path": "C:\\Windows\\system32\\LockAppHost.exe", "hash_md5": "669B039303627B2FFD771B4B74C78BF7", "hash_sha1": "8A3DFB8984DE014F426767DA937BE66F4AA40797", "hash_sha256": "A0E3ABEE637656C2AD5033D89F364F1C98E508CEFA5F9E069BCF7430EDFFA662", "hash_sha384": "FAC0F095C23D394FC3AF24B6216A43B09AEA483D7C6152BFC037F3B968E1AC08C3A18CA21280EDD266EC373F8CB4E568", "hash_sha512": "9079497DEC9A3A7DDC7EB99EE419A7CBC60E018F7CF25F2065BDC6C59197D8BCAD15F17EBCA6B546411E656DAD3D44B8249FB98F658ACDF5BF8DD0647BEBADBE", "hash_ssdeep": "1536:PpvUmznA2BzHXf6b3v3WJeBxoMwiYAie+SKOPGJYgkq5vlldPPV:FxnA2BHPFJ4u1e+7QGJY7qRllV9", "hash_imp": "290C858C8D54632F9419C04010DF2751", "hash_pesha1": "46E46EF62B21EED852088FF4EA372B9ED7686D98", "hash_pe256": "E6B1D1E6C7867F46B9C5B08323A773D5C8FF6A7A91C4966F65C2AF5F7EADC79E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "LockAppHost", "meta_original_filename": "LockAppHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a0e3abee637656c2ad5033d89f364f1c98e508cefa5f9e069bcf7430edffa662/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\LockAppHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\system32\\LockHostingFramework.dll", "C:\\Windows\\System32\\SHCORE.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll" ] }, "LockScreenContentServer.exe-6AF14D7B0F21773BEE920435E36395C3": { "file_name": "LockScreenContentServer.exe", "file_path": "C:\\Windows\\system32\\LockScreenContentServer.exe", "hash_md5": "6AF14D7B0F21773BEE920435E36395C3", "hash_sha1": "7B05192630F0C555A3C4945E550A48EF20E47A99", "hash_sha256": "217A41AB21095D289867AD177DE71241A970EE8FA7F569C4751F6190F8FDAFFF", "hash_sha384": "7D86A0D2AB1F99AF65504BADFAC153F9A5DB28CCCC4C9423158411322DF2F171405B46C2C8730606EA707DD17F6149C4", "hash_sha512": "8585A2B7C4C2F6507461B62FB406B6320F28B50F59B1B629E7EB4259301AC8CEAFC3082D470C8785208B2C7F4094CC1F6661A222A65A58B09D8D60579CD203B9", "hash_ssdeep": "768:i9vZAVIGUb4KO1K/3Hujsf/XJUQ4oZmW6CHI1Pti:gvIIlUKFfP4oZmW6CwPQ", "hash_imp": "E441628266F72396B90DBB4176D0A3BD", "hash_pesha1": "CB1861A18D91FA95468A235D1C30CA44DDC8E194", "hash_pe256": "F8A2C9A70B0CA0590B6B8E78DA1B23ECCE3A4C4EBEE035BA217F03E0BE968E28", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "LockScreenContent Server", "meta_original_filename": "LockScreenContentServer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/217a41ab21095d289867ad177de71241a970ee8fa7f569c4751f6190f8fdafff/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\LockScreenContentServer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\system32\\DUser.dll" ] }, "lodctr.exe-38983AF776238A60E94DEEF341353378": { "file_name": "lodctr.exe", "file_path": "C:\\Windows\\system32\\lodctr.exe", "hash_md5": "38983AF776238A60E94DEEF341353378", "hash_sha1": "C67BD43CD017E9285CA9BCBA41AC3B922B163F26", "hash_sha256": "A68DC00716E93540692CE686922B1CF6D3F216FC9E0396C6D6B7291778DBA6ED", "hash_sha384": "F855A0F93B27B0ABB1070D6F042B8AA04B961E272B45FC1F5AD1124530B9E2CBC78DA6F67EB0CBA3A9831B89D90D988B", "hash_sha512": "F65BBC41151E5EE063815A4D6EBBB128286D5CBD63D3A562143865FBA0BD8ACF085F897F4C1B3FCDC0108D704A5944100A43580E403591819D369893DCCF4D1F", "hash_ssdeep": "768:iHUfeo733JISlfCczwkT/AEzQOGByniogtI0gq9J8wHplMcJ0/JECwmS2k:6U33LlJzdGByi9t/J5lMc+ECwmS2k", "hash_imp": "161F3C69B9F275480C338BBAB3DA4D6E", "hash_pesha1": "3BA6400DC7595E91F49C30AA7A82D0F0CF21EE2A", "hash_pe256": "9D18CE526328DD917ABB9D0A8BD77E81BCC0BCDE4599C36A82B9163E3AC6CC17", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Load PerfMon Counters", "meta_original_filename": "LODCTR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a68dc00716e93540692ce686922b1cf6d3f216fc9e0396c6d6b7291778dba6ed/detection", "output": "\r\n \r\nLODCTR \r\n Updates registry values related to performance counters. \r\nUsage: \r\n LODCTR <INI-filename> \r\n Installs counter text strings. INI-filename is the name of the \r\n initialization file that contains the counter name definitions \r\n and explain text for an extensible counter DLL.\r\n\r\n LODCTR /C:<filename> \r\n Upgrades counter text strings using <filename>\r\n\r\n LODCTR /H:<filename> \r\n Upgrades help text strings using <filename>\r\n\r\n LODCTR /L:<LangID> \r\n Specifies the language for the /C and /H commands\r\n\r\n LODCTR /S:<Backup-filename> \r\n Saves the current perf registry strings and info to \r\n <Backup-filename>\r\n\r\n LODCTR /R \r\n Rebuilds perf registry from scratch based on current registry \r\n settings and backup INI files.\r\n\r\n LODCTR /R:<filename> \r\n Restores perf registry strings & info using <filename>\r\n\r\n LODCTR /T:<service-name> \r\n Sets the specified performance counter provider as trusted.\r\n\r\n LODCTR /Q \r\n Displays performance counter provider information.\r\n\r\n LODCTR /Q:<service-name> \r\n Displays performance counter provider information for a \r\n specific provider.\r\n\r\n LODCTR /E:<service-name> \r\n Enables the performance counter provider.\r\n\r\n LODCTR /D:<service-name> \r\n Disables the performance counter provider.\r\n\r\n LODCTR /M:<Counter-Manifest> [<Installation-Path>]\r\n Installs a v2.0 performance counter provider using the specified \r\n XML manifest. \r\n\r\n The installation requires a full path to the DLL containing the \r\n performance counter resources (localized strings). The path \r\n to the DLL will be determined as follows:\r\n\r\n If the applicationIdentity attribute in the manifest is a full \r\n path, that will be used.\r\n\r\n Otherwise, if <Installation-Path> is provided and is a full \r\n path, that will be used.\r\n\r\n Otherwise, if <Counter-Manifest> is a full path, the directory \r\n from <Counter-Manifest> will be combined with the DLL name from \r\n the applicationIdentity attribute in the manifest.\r\n\r\n Otherwise, the current directory will be combined with the DLL \r\n name from the applicationIdentity attribute in the manifest.\r\n\r\nNote: Any arguments with spaces in the names must be enclosed within double \r\nquotation marks.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\lodctr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "logagent.exe-0C2EBDB69ECEF0BBAFDECA08775C4333": { "file_name": "logagent.exe", "file_path": "C:\\Windows\\system32\\logagent.exe", "hash_md5": "0C2EBDB69ECEF0BBAFDECA08775C4333", "hash_sha1": "283FCABFFBD74412F1CF4C15D226A2C1BF93E479", "hash_sha256": "4F77AFEC77AB4C42F274BFB3F1FD5FCF58F6FCF73C93CDA0F50721AF34BD94C1", "hash_sha384": "0DFA8106B9C7AAB08D54FBCFD5EE87602CFDA4E9C2557BBFB5205CF5B277B0788321AD3E887FCFBDA75CB5C96976BA96", "hash_sha512": "2B0779C00E9E793D8A659A740EE90B7C78F28D19D68495018B3F2E2AFFCC84E16C59936698060E8407F8067C46153A941F11C9E4F8BFD715E1A743AC316DDBC2", "hash_ssdeep": "3072:LSg2ZjAX1eZYFFRrMJkDnRKOi92+e2mNCKfH:O8leZUvrWkDnRK0SmNCK", "hash_imp": "D41074F30A9619E57B1244FFD6A35B53", "hash_pesha1": "B66F5DF5DF3F408C923623530CEC75191F3F6B2D", "hash_pe256": "524E06999E09AE91C21AC0FE6799D24496832B6E16490D1EBDF37118E7E8B457", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Logagent", "meta_original_filename": "logagent.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.19041.1", "meta_product_version": "12.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4f77afec77ab4c42f274bfb3f1fd5fcf58f6fcf73c93cda0f50721af34bd94c1/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\logagent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\WININET.dll", "C:\\Windows\\system32\\WSOCK32.dll", "C:\\Windows\\System32\\WS2_32.dll" ] }, "logman.exe-CA042C9A80D01C409C740D0437942B4E": { "file_name": "logman.exe", "file_path": "C:\\Windows\\system32\\logman.exe", "hash_md5": "CA042C9A80D01C409C740D0437942B4E", "hash_sha1": "715146CAA48D94A6AE2F6F0B2D5268296D51773E", "hash_sha256": "CDAA7D2FD4328877FCAB873CFA85B6B46B0A1AFA6CC39017CED21DCFB139BBA7", "hash_sha384": "8D4D8529419B2AEFB158A8A1FBAE46150754ACA9AD51DC1F86BFCC0C8DAE30ECEE2C7A7B81CDA7BA48919FBA909FD24E", "hash_sha512": "32C0EF8AB6A938DFC0BB00F41B4A2937EA9370D80104A4D1F6CC5782D1F97D4C8823F413A02A6F911DC06F4B1EECF4BAFAB08DB56CDF678E0E0B37CBA7C96A63", "hash_ssdeep": "3072:jk3dNq/ZpEoxPeFpT0NMrUs0Kj6aWkGTy:jk3/q/PEoxP6pT0NY0Kja", "hash_imp": "468AE0E85185C7B62E8740F0B95D8D25", "hash_pesha1": "6F11D3C4FEBB3416F852DAA6AFB9A43BDB808637", "hash_pe256": "9CB93F65237DC1FB2CDC424B051BD6AC48190C429329C86D6FB3393C82360B47", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Performance Log Utility", "meta_original_filename": "Logman.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/cdaa7d2fd4328877fcab873cfa85b6b46b0a1afa6cc39017ced21dcfb139bba7/detection", "output": "\r\nMicrosoft r Logman.exe (10.0.19041.546)\r\n\r\nUsage:\r\n C:\\Windows\\system32\\logman.exe [create|query|start|stop|delete|update|import|export] [options]\r\n\r\nVerbs:\r\n create Create a new data collector.\r\n query Query data collector properties. If no name\n is given all data collectors are listed.\r\n start Start an existing data collector and set the\n begin time to manual.\r\n stop Stop an existing data collector and set the\n end time to manual.\r\n delete Delete an existing data collector.\r\n update Update an existing data collector's properties.\r\n import Import a data collector set from an XML file.\r\n export Export a data collector set to an XML file.\r\n\r\nAdverbs:\r\n counter Create a counter data collector.\r\n trace Create a trace data collector.\r\n alert Create an alert data collector.\r\n cfg Create a configuration data collector.\r\n providers Show registered providers.\r\n\r\nOptions (counter):\r\n -c <path [path [...]]> Performance counters to collect.\r\n -cf <filename> File listing performance counters to collect,\n one per line.\r\n -f <bin|bincirc|csv|tsv|sql> Specifies the log format for the data\n collector. For SQL database format, you must\n use the -o option in the command line with\n the DNS!log option. The defaults is binary.\r\n -sc <value> Maximum number of samples to collect with a\n performance counter data collector.\r\n -si <[[hh:]mm:]ss> Sample interval for performance counter data\n collectors.\r\n\r\nOptions (trace):\r\n -f <bin|bincirc|csv|tsv|sql> Specifies the log format for the data\n collector. For SQL database format, you must\n use the -o option in the command line with\n the DNS!log option. The defaults is binary.\r\n -mode <trace_mode> Event Trace Session logger mode. For more\n information visit -\n https://go.microsoft.com/fwlink/?LinkID=136464\r\n -ct <perf|system|cycle> Specifies the clock resolution to use when\n logging the time stamp for each event. You\n can use query performance counter, system\n time, or CPU cycle.\r\n -ln <logger_name> Logger name for Event Trace Sessions.\r\n -ft <[[hh:]mm:]ss> Event Trace Session flush timer.\r\n -[-]p <provider [flags [level]]> A single Event Trace provider to enable.\n The terms 'Flags' and 'Keywords' are\n synonymous in this context.\r\n -pf <filename> File listing multiple Event Trace providers\n to enable.\r\n -[-]rt Run the Event Trace Session in real-time mode.\r\n -[-]ul Run the Event Trace Session in user mode.\r\n -bs <value> Event Trace Session buffer size in kb.\r\n -nb <min max> Number of Event Trace Session buffers.\r\n\r\nOptions (alert):\r\n -[-]el Enable/Disable event log reporting.\r\n -th <threshold [threshold [...]]> Specify counters and their threshold\n values for and alert.\r\n -[-]rdcs <name> Data collector set to start when alert fires.\r\n -[-]tn <task> Task to run when alert fires.\r\n -[-]targ <argument> Task arguments.\r\n -si <[[hh:]mm:]ss> Sample interval for performance counter data\n collectors.\r\n\r\nOptions (cfg):\r\n -[-]ni Enable/Disable network interface query.\r\n -reg <path [path [...]]> Registry values to collect.\r\n -mgt <query [query [...]]> WMI objects to collect.\r\n -ftc <path [path [...]]> Full path to the files to collect.\r\n\r\nOptions:\r\n -? Displays context sensitive help.\r\n -s <computer> Perform the command on specified remote system.\r\n -config <filename> Settings file containing command options.\r\n [-n] <name> Name of the target object.\r\n -pid <pid> Process identifier.\r\n -xml <filename> Name of the XML file to import or export.\r\n -as Perform the requested operation asynchronously.\r\n -[-]u <user [password]> User to Run As. Entering a * for the password\n produces a prompt for the password. The\n password is not displayed when you type it at\n the password prompt.\r\n -m <[start] [stop]> Change to manual start or stop instead of a\n scheduled begin or end time.\r\n -rf <[[hh:]mm:]ss> Run the data collector for the specified\n period of time.\r\n -b <M/d/yyyy h:mm:ss[AM|PM]> Begin the data collector at specified time.\r\n -e <M/d/yyyy h:mm:ss[AM|PM]> End the data collector at specified time.\r\n -o <path|dsn!log> Path of the output log file or the DSN and\n log set name in a SQL database. The default\n path is '%systemdrive%\\PerfLogs\\Admin'.\r\n -[-]r Repeat the data collector daily at the\n specified begin and end times.\r\n -[-]a Append to an existing log file.\r\n -[-]ow Overwrite an existing log file.\r\n -[-]v <nnnnnn|mmddhhmm> Attach file versioning information to the end\n of the log name.\r\n -[-]rc <task> Run the command specified each time the log\n is closed.\r\n -[-]max <value> Maximum log file size in MB or number of\n records for SQL logs.\r\n -[-]cnf <[[hh:]mm:]ss> Create a new file when the specified time has\n elapsed or when the max size is exceeded.\r\n -y Answer yes to all questions without prompting.\r\n -fd Flushes all the active buffers of an existing\n Event Trace Session to disk.\r\n -ets Send commands to Event Trace Sessions\n directly without saving or scheduling.\r\n\r\nNote:\r\n Where [-] is listed, an extra - negates the option.\r\n For example --u turns off the -u option.\r\n\r\nMore Information:\r\n Microsoft TechNet - https://go.microsoft.com/fwlink/?LinkID=136332\n\r\nExamples:\r\n logman start perf_log\n logman update perf_log -si 10 -f csv -v mmddhhmm\n logman create counter perf_log -c \"\\Processor(_Total)\\% Processor Time\"\n logman create counter perf_log -c \"\\Processor(_Total)\\% Processor Time\" -max 10 -rf 01:00\n logman create trace trace_log -nb 16 256 -bs 64 -o c:\\logfile\n logman create alert new_alert -th \"\\Processor(_Total)\\% Processor Time>50\"\n logman create cfg cfg_log -reg \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\\\\"\n logman create cfg cfg_log -mgt \"root\\cimv2:SELECT * FROM Win32_OperatingSystem\"\n logman query providers\n logman query providers Microsoft-Windows-Diagnostics-Networking\n logman start process_trace -p Microsoft-Windows-Kernel-Process 0x10 win:Informational -ets\n logman start usermode_trace -p \"Service Control Manager Trace\" -ul -ets\n logman query usermode_trace -p \"Service Control Manager Trace\" -ul -ets\n logman stop usermode_trace -p \"Service Control Manager Trace\" -ul -ets\n logman start process_trace -p Microsoft-Windows-Kernel-Process -mode newfile -max 1 -o output%d.etl -ets\n logman start \"NT Kernel Logger\" -o log.etl -ets\n logman start \"NT Kernel Logger\" -p \"Windows Kernel Trace\" (process,thread) -ets\n", "runtime_modules": [ "C:\\Windows\\system32\\logman.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "logoff.exe-DDB4F5DC12EC364DD325A2C63AB5F0DE": { "file_name": "logoff.exe", "file_path": "C:\\Windows\\system32\\logoff.exe", "hash_md5": "DDB4F5DC12EC364DD325A2C63AB5F0DE", "hash_sha1": "CF3C725036A7442DE1D94F9AA70CFD524DA258DA", "hash_sha256": "4B5DF4CE25BCD9CF635CDED7333F5F53D23F57B2ADACA1DDF987C4B717F7FFB4", "hash_sha384": "2774812033F757100F644342494D5CCFD8A3427C0478413FEB8404E2304AD4E6886B90C7A7BFE5278951D9CA30086E4A", "hash_sha512": "C526B3DBF8DD03F03E0C2453F5E95ED0E9F5A54C00445D21234FBFBFFB24D8D4C864D2D45BBE4CC9CC55585586AB13978579A4F2482A86AC5E0C516C6E722A04", "hash_ssdeep": "384:OZYareI5jx+cnKJlcXeet3T5t1pZ8PoBZv5Tx8YRA8oYMhVMcrLoiW3kuW:O+aaI5UcnKvcXecVpZ8wBhRzT0voA", "hash_imp": "5DEE48EC7C50D677FA5BFE4D23399111", "hash_pesha1": "30D8575B561C179C44316E1949DF2D16471A506A", "hash_pe256": "70FA0B5703EDD0003045006AA507506D6EE5E45385BF96CA0E607E1EC3F5F039", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Session Logoff Utility", "meta_original_filename": "logoff.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/4b5df4ce25bcd9cf635cded7333f5f53d23f57b2adaca1ddf987c4b717f7ffb4/detection", "error": "Invalid parameter(s)\r\nTerminates a session.\r\n\r\nLOGOFF [sessionname | sessionid] [/SERVER:servername] [/V] [/VM]\r\n\r\n sessionname The name of the session.\r\n sessionid The ID of the session.\r\n /SERVER:servername Specifies the Remote Desktop server containing the user\r\n session to log off (default is current).\r\n /V Displays information about the actions performed.\r\n /VM Logs off a session on server or within virtual machine. The unique ID of the session needs to be specified.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\logoff.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "LogonUI.exe-893144FE49AA16124B5BD3034E79BBC6": { "file_name": "LogonUI.exe", "file_path": "C:\\Windows\\system32\\LogonUI.exe", "hash_md5": "893144FE49AA16124B5BD3034E79BBC6", "hash_sha1": "FBF39A288FC46CBF0620CFD297395A8FB4FBCDAD", "hash_sha256": "CF01E46C146699F6C0E3DD447043F59BC9438DBBCB9563AF6C60EBC6D82727F2", "hash_sha384": "AD04C11ECD7D65D4C50FDCFF26BBA66F60D0F929C624FC85A706456C142036EBB4E3E40AD75EE9CA407E614EEE741517", "hash_sha512": "C921EE3786717AC1F9E1981E35494F33D26D153AFB335C52219830261F84155383D5AC9FF0EA1D7F3F6913B28C878CE6B5EA350F60ED9A9BF1AC006596FD4C68", "hash_ssdeep": "192:yecuhBM44rbhVsO3XKtK3NyeiKQ2pxeILJJQYSlid3slZiU4ltWIUW:HVhq4Ih6U3NRXpxLLJGYWi2ZcnWIUW", "hash_imp": "B9B0B64B08B38276711093CA94348D39", "hash_pesha1": "7C621A783BF7A358486DAC4DF3DEFD1185E56D26", "hash_pe256": "7A2DB86800DDCE2F818724012C945E54834BA2C8D9644F43372FED150A5EA592", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Logon User Interface Host", "meta_original_filename": "logonui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/cf01e46c146699f6c0e3dd447043f59bc9438dbbcb9563af6c60ebc6d82727f2/detection", "runtime_modules": [ "C:\\Windows\\system32\\LogonUI.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "lpkinstall.exe-908D30340700A528C4958EEE6051FD8E": { "file_name": "lpkinstall.exe", "file_path": "C:\\Windows\\system32\\lpkinstall.exe", "hash_md5": "908D30340700A528C4958EEE6051FD8E", "hash_sha1": "FDBD3AB4F5D75DD86F3DF89085E5645B3D7D19A8", "hash_sha256": "80D0FF5397B1270888CD4D63266AE31D86EDC682E36A69B83CABE605E5616636", "hash_sha384": "9EB03FAE5FB8A003ABBFF43F1929B7B6300335B7304EDE8D6B6465601374571A584D0D5C54EC4048696C21565BE0A545", "hash_sha512": "6ACE3E7D1E2C027F4406852B6C5C9B3CC88F9790128466F3BE9F3D48B6271059E36F56CEC382643B9A7B76E39D0F06B6A8589ACC4E46DDB6840966EE799D1E9D", "hash_ssdeep": "768:3j6Rghp/0enynqLmx5ZB6ulx68SY/gWdPYaal07c8wvn6f9k:3j6Rg7xyqLmnZ4cxV4hL+7c8wP6f9k", "hash_imp": "3AA27B5B1AB823F07D4032A9BA4767F6", "hash_pesha1": "ACAA9AF9FA951B62FEA5D05B1D40FEC2E3B5DD35", "hash_pe256": "C06E7D5887CB5DE9692DE22CC837599A79DD8375B9080350BE8BBC8EC61B6AEF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Language Pack Installer", "meta_original_filename": "lpkinstall.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/80d0ff5397b1270888cd4d63266ae31d86edc682e36a69b83cabe605e5616636/detection", "runtime_modules": [ "C:\\Windows\\system32\\lpkinstall.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "lpksetup.exe-77BA86BC95DD19D9C6B0BD4E5E94E823": { "file_name": "lpksetup.exe", "file_path": "C:\\Windows\\system32\\lpksetup.exe", "hash_md5": "77BA86BC95DD19D9C6B0BD4E5E94E823", "hash_sha1": "2FF069945D9AC3DAA4DA310927B4109EC52B3687", "hash_sha256": "0FEFBD2235C5EB2BABCEDECAA3F798CF632A580AA4D73D023D3D24D8365DA562", "hash_sha384": "C6F7C40A29C6CAA602348B55363AEE4A755F60633C5D0E93A338CCF036363B4436C85F76DD6472B98E068E45E41AA6C2", "hash_sha512": "84D40F7DCC0116B84712C9EEB1A126E591C386675390C65AC059BDC6834AE6B1477039336A8206FD22BCFFACF53BD3E6A0BAC9B454D9E62F0D5F2A8BFFBEDAD5", "hash_ssdeep": "12288:yL+oTc8GaWeMrq8foczY1teOcu6A5yxmGCphr8fVv67ZluKAyfndmLh:K+Nxhqm8AON5y9Cphr8fVi7ZluKAemd", "hash_imp": "8D09DF56DB65CA2428CB8BEFB9C1F83A", "hash_pesha1": "A304084C43C16BFCAE3EB0A451AAAECB1A112BBA", "hash_pe256": "FC7EE3A86527EC4294631710090CEDAE8B45B2BFE44E3FE60BA66795E6D68DBF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Language Pack Installer", "meta_original_filename": "lpksetup.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0fefbd2235c5eb2babcedecaa3f798cf632a580aa4d73d023d3d24d8365da562/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\lpksetup.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\RotHintTable": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\lpksetup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll" ] }, "lpremove.exe-272B5EA7309039A904D254EDCC9796AB": { "file_name": "lpremove.exe", "file_path": "C:\\Windows\\system32\\lpremove.exe", "hash_md5": "272B5EA7309039A904D254EDCC9796AB", "hash_sha1": "5296CB00CBF63FC0443D9BFDC1FE203D596CC497", "hash_sha256": "6220BA55D96DDAFB6B573B2405DB412F7420C77D09B5C1A1637D558EA5480057", "hash_sha384": "00272A16AAF69D93A271747B2653BABE82988E5EA806002EF61A6952FC73205D66F23B70EF656E629086B2943B408ADA", "hash_sha512": "018ED63A1FE4D233849D700F967243AE44A33172FE63CE1BC30A3028656DEFAAD41CAFDBDD6A1B6C7741B875DC9490CDFFAD6BDC2BB4570671A52364994F449E", "hash_ssdeep": "1536:K83joPP2VSiGrslo0QcOxizNpe02ZKljwa99xvbuMQnf5wTz5z3:7ujTrs2RFr02ZKdj6nfqz5T", "hash_imp": "2CE3B69EDF64B3D3627C181D0422215F", "hash_pesha1": "2EF4CF6429342007A5375D2A17F8751F82722A74", "hash_pe256": "187477CF485FFB64AD8B6D3AEC3793976E167D1CD7A108706D3B60E5430354BD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MUI Language pack cleanup", "meta_original_filename": "lpremove.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/6220ba55d96ddafb6b573b2405db412f7420c77d09b5c1a1637d558ea5480057/detection", "runtime_modules": [ "C:\\Windows\\system32\\lpremove.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "LsaIso.exe-D9BF2CA0262F8F71556BAB579A871C34": { "file_name": "LsaIso.exe", "file_path": "C:\\Windows\\system32\\LsaIso.exe", "hash_md5": "D9BF2CA0262F8F71556BAB579A871C34", "hash_sha1": "857CA4B4235889ABA721671A1699FDBA0DB88C52", "hash_sha256": "9610808D82A12F4227DF7CEAB1DD5172B120E0FB19F660B394185D1C17F297CC", "hash_sha384": "5272D2A80ACC86A1B661842D84EAD7B455978EEA543453DF1AEF908224E5CC6C763C0B8178AD7C5080C271E539145A66", "hash_sha512": "9492C4E95CBD65D8FA108AAD87363F689D85323584E85D9A1347671C8718F40AC28220161B724A3DD1F68797948C5BB2CE034843852998116207985FA9F240EC", "hash_ssdeep": "3072:HNn1cDVeN6CSi1rusmUQwPlZGtYsMpubpA9PeRRQEUN/nLnS+yhmwg4gzIeV8k:HNn1cDVepxKwv2MApEmRRINznSbpsPL", "hash_imp": "E20271694660EB17470CEE91AE53E0B4", "hash_pesha1": "6602158D351196F59D471DD81434DF995C0E1A7B", "hash_pe256": "DAC519D5C4F5135AF8882F7750557C38BEF78D93D90889DD90DD84E65B263F1F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Guard & Key Guard", "meta_original_filename": "LsaIso.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9610808d82a12f4227df7ceab1dd5172b120e0fb19f660b394185d1c17f297cc/detection" }, "lsass.exe-0467D648EF6191ADC4DF8FD7F42F3DD0": { "file_name": "lsass.exe", "file_path": "C:\\Windows\\system32\\lsass.exe", "hash_md5": "0467D648EF6191ADC4DF8FD7F42F3DD0", "hash_sha1": "D642FB1660DA8E3508225810EB04C246E7DACD90", "hash_sha256": "7FE327AE2DD924E2318796508B6CFF5FD6B70A3DEB30A2B7C7403ABDBD805462", "hash_sha384": "244DA646BFF6738E068C205C284C5CBEB76DA5A97A1AFB6C53F7D3B2D7726CFDDA8C4A497A1F13927BBF3258D3649B26", "hash_sha512": "9350C9E29C8359102DEF2452A5705D78BB7BC47026CE463E8DEFD4242B3790D4D0269A39FC319136C19EB76C3BF4D7BDC92D75F602FD0008B440810840572584", "hash_ssdeep": "1536:I5JpE9iBd8GwcGa+SxZJkuNbcqeLxniMJ6gyP42qogPr5:QO9iBd8GwcpBuZLVkA2qX9", "hash_imp": "09FDE88C65E2BC5F1F90E96B673C52B1", "hash_pesha1": "6253E671D134D09AC3B6BF3661F6F81F4688CCA0", "hash_pe256": "A13EC92B8DDCB669ADF6D7A5ECF7E9B67CFE7D65E4ACE02718E78ACB3F70C8F0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Local Security Authority Process", "meta_original_filename": "lsass.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7fe327ae2dd924e2318796508b6cff5fd6b70a3deb30a2b7c7403abdbd805462/detection" }, "Magnify.exe-7572108D37E05044E30E8E9B201DC0F8": { "file_name": "Magnify.exe", "file_path": "C:\\Windows\\system32\\Magnify.exe", "hash_md5": "7572108D37E05044E30E8E9B201DC0F8", "hash_sha1": "73659C57E3A09104BCBCA0648CD0662EFE6E5CC0", "hash_sha256": "66B87EFBF56E20FBFB0667C3D3CDA098B9ECA7472C597F381958524D6EDE0BAC", "hash_sha384": "5D49B5667CFF2351DF847A19CB1C4257E57CB62DF2A1C8ACC9010A43F5D7C925A260C1EBBF4C86A588C4FD2DEC92D2CC", "hash_sha512": "B6E7614E46537A2465D883C72B99002DA2E93ED74502B55B04628A78C05463180A6670FC67A6A48F5A87549ED2B516069424168D3D36A3DECCCF02C2644EF210", "hash_ssdeep": "12288:LheWIHrGx/CSMz9VuO+WTo6USPsfhqfQFhlt:LhpIHr8a9XXT4SPQofmbt", "hash_imp": "295E3CC64E17760377EB198BCFE0B288", "hash_pesha1": "35BE5E6147FD4C1F7DFC5961DC24AEC99E80F2E1", "hash_pe256": "6B68E8CE1959502CF83B38C0FEC38498A41C26E55ED4304288D75DA20750EC70", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Screen Magnifier", "meta_original_filename": "ScreenMagnifier.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/66b87efbf56e20fbfb0667c3d3cda098b9eca7472c597f381958524d6ede0bac/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\Magnify.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\System32": "File", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\17ccHWNDInterface:7006c": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "\\Sessions\\1\\BaseNamedObjects\\{03316E24-3669-48AE-B0D0-4E9CD608CE6E}-Map-GLOBAL": "Section", "(R--) C:\\Windows\\Speech_OneCore\\Engines\\TTS\\en-US\\NUSData\\M1033David.keyboard.WVE": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\{A78B032C-F564-4E8E-9995-0661714401C9}-Map-S-1-16-12288": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\SRH.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\Magnify.exe.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\combase.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\windows.ui.xaml.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\17ccHWNDInterface:70058": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Magnify.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\OLEACC.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538\\gdiplus.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\system32\\MAGNIFICATION.dll", "C:\\Windows\\system32\\UIAutomationCore.DLL", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\system32\\WTSAPI32.dll", "C:\\Windows\\system32\\d3d9.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll" ], "runtime_window_title": "Magnifier" }, "makecab.exe-FF47E32B1B45D1DE2ECC39107B365563": { "file_name": "makecab.exe", "file_path": "C:\\Windows\\system32\\makecab.exe", "hash_md5": "FF47E32B1B45D1DE2ECC39107B365563", "hash_sha1": "A8B93562ABC7F0D7252EE9A01E335A3FCECDD30B", "hash_sha256": "BA31AD8ECA19C5FE03F6A5C64C8E0ADFC7BD8D04B1F4E1C11D167467FD5261E9", "hash_sha384": "4B0CAD899127F7B28E81B4B0A45A0361A67E4DE60FD1B6DD493ABDC893C69F5CF0218A6832F879DEAF11609583D74C09", "hash_sha512": "0E0778306A37B4178B570DFFCEB00C5AC7C0110FC35FD81DBE105D759AADEDDD9006DC8CFD654F948FD42A2D5BF12453AA629F637C3FCD94718122580AE12DE8", "hash_ssdeep": "1536:E1O9GAeEoohuq5r20STMoXQVhuKGlMykUR021AmN3EDKtx0vRu:v9GAmqx52TTMoXQLFGlMykl21vEDKtxl", "hash_imp": "A9326A6F3C34256D97D8CD7972ACC242", "hash_pesha1": "B742443BCD0F291D7BB2BD953BE5906C30AFF317", "hash_pe256": "2D8A7CC311E52167DA99BB22B2819E82FBEDCC670ABE1B3DF85BF80E393F0F03", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Cabinet Maker", "meta_original_filename": "makecab.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.00 (WinBuild.160101.0800)", "meta_product_version": "5.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ba31ad8eca19c5fe03f6a5c64c8e0adfc7bd8d04b1f4e1c11d167467fd5261e9/detection", "output": "Cabinet Maker - Lossless Data Compression Tool\r\n\r\nMAKECAB [/V[n]] [/D var=value ...] [/L dir] source [destination]\r\nMAKECAB [/V[n]] [/D var=value ...] /F directive_file [...]\r\n\r\n source File to compress.\r\n destination File name to give compressed file. If omitted, the\r\n last character of the source file name is replaced\r\n with an underscore (_) and used as the destination.\r\n /F directives A file with MakeCAB directives (may be repeated). Refer to\r\n Microsoft Cabinet SDK for information on directive_file.\r\n /D var=value Defines variable with specified value.\r\n /L dir Location to place destination (default is current directory).\r\n /V[n] Verbosity level (1..3).\r\n", "children": [ "csrss.exe", "winlogon.exe" ], "runtime_modules": [ "C:\\Windows\\system32\\makecab.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "manage-bde.exe-84021D418863A3E530D2E3F65F5D154C": { "file_name": "manage-bde.exe", "file_path": "C:\\Windows\\system32\\manage-bde.exe", "hash_md5": "84021D418863A3E530D2E3F65F5D154C", "hash_sha1": "4EEE495D9121CB6BB510A1298E209B175454B1AD", "hash_sha256": "38F20A75E04BB9A53C563152A90A5B29AB689AFF58D6ABD3E005D156EE4E4C73", "hash_sha384": "E82F9D96B62FBB7494F9329F3C8F288270A517D0268BBAE8AC6EE4B1B134A35EBBA20EBB86898B9C9EAF9781CEEE7F5F", "hash_sha512": "AEDCC746BF543DB4BB7529F5C2FF678DFC386AC53A7A0D1E51A3B46FBD62BB7455A0630E1EAAA73CD73CB1D340DF65677CF3CACB261619C636CDD073842B4B75", "hash_ssdeep": "6144:9sZ+OW0m5L6kLZc87GF1lqq1Bmt5Vs7nyatGt+SYF:9snWBhPS8lH+S+", "hash_imp": "817DDC8CC4FA183F801D96706E452A3B", "hash_pesha1": "28814B26EC2F640FC2F9B5E26C562169730D57CA", "hash_pe256": "030975587F4448F60B3B9BCE4F92EBFCE17F8ED1DE0BFEB4A34EA27AC01CE5E2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BitLocker Drive Encryption: Configuration Tool", "meta_original_filename": "manage-bde.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/38f20a75e04bb9a53c563152a90a5b29ab689aff58d6abd3e005d156ee4e4c73/detection", "output": "BitLocker Drive Encryption: Configuration Tool version 10.0.19041\r\nCopyright (C) 2013 Microsoft Corporation. All rights reserved.\r\n\r\nmanage-bde[.exe] -parameter [arguments]\r\n\r\nDescription:\r\n Configures BitLocker Drive Encryption on disk volumes.\r\n\r\nParameter List:\r\n -status Provides information about BitLocker-capable volumes.\r\n -on Encrypts the volume and turns BitLocker protection on.\r\n -off Decrypts the volume and turns BitLocker protection off.\r\n -pause Pauses encryption, decryption, or free space wipe.\r\n -resume Resumes encryption, decryption, or free space wipe.\r\n -lock Prevents access to BitLocker-encrypted data.\r\n -unlock Allows access to BitLocker-encrypted data.\r\n -autounlock Manages automatic unlocking of data volumes.\r\n -protectors Manages protection methods for the encryption key.\r\n -SetIdentifier or -si\r\n Configures the identification field for a volume.\r\n -ForceRecovery or -fr\r\n Forces a BitLocker-protected OS to recover on restarts.\r\n -changepassword\r\n Modifies password for a data volume.\r\n -changepin Modifies PIN for a volume.\r\n -changekey Modifies startup key for a volume.\r\n -KeyPackage or -kp\r\n Generates a key package for a volume.\r\n -upgrade Upgrades the BitLocker version.\r\n -WipeFreeSpace or -w\r\n Wipes the free space on the volume.\r\n -ComputerName or -cn\r\n Runs on another computer. Examples: \"ComputerX\", \"127.0.0.1\"\r\n -? or /? Displays brief help. Example: \"-ParameterSet -?\"\r\n -Help or -h Displays complete help. Example: \"-ParameterSet -h\"\r\n\r\nExamples:\r\n manage-bde -status\r\n manage-bde -on C: -RecoveryPassword -RecoveryKey F:\\\r\n manage-bde -unlock E: -RecoveryKey F:\\84E151C1...7A62067A512.bek\r\n", "runtime_modules": [ "C:\\Windows\\system32\\manage-bde.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mavinject.exe-E354F3D93A7639FCE4D649874766D624": { "file_name": "mavinject.exe", "file_path": "C:\\Windows\\system32\\mavinject.exe", "hash_md5": "E354F3D93A7639FCE4D649874766D624", "hash_sha1": "93B00ADC9B3871635ABC9C6AFE483E83782582CD", "hash_sha256": "930272DA382ACCB872CD2F4BE045BEAAC493CD1A896786E4FB4B42F30E1D9A32", "hash_sha384": "EEE0E4350BFF277013FC6224109C0388642E15F3F42D2BB3715A15FEA370A0B55FE32D6B53E2AC19F0CED08FDB01A73F", "hash_sha512": "C7CA5EF25972A31243DE688B8C599B3B77DC9E34A84F466B8C9CC0828DF9436780E091FD45CAF8122BCD247C48902D606C00CFD5375CC6A2A489B80912FFA3A4", "hash_ssdeep": "3072:5V9WX1D4iekQ5fG0SltWQWGNU6ITL2VprwXhw:X9tiXAItTWGNU6ITL2/Ww", "hash_imp": "429058796B83BC005DB1F177F77554BC", "hash_pesha1": "D1FC943C8F25039E7936C287DB5C0F5C6D073536", "hash_pe256": "C025C2E9369E8CD13151CE20F58C7C24BE05F1F28FCA97DEE8285E06060F74E2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Application Virtualization Injector", "meta_original_filename": "mavinject64.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/930272da382accb872cd2f4be045beaac493cd1a896786e4fb4b42f30e1d9a32/detection", "runtime_modules": [ "C:\\Windows\\system32\\mavinject.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "MbaeParserTask.exe-D8728CC5E5D3CB8A04972D2E0C21EE3A": { "file_name": "MbaeParserTask.exe", "file_path": "C:\\Windows\\system32\\MbaeParserTask.exe", "hash_md5": "D8728CC5E5D3CB8A04972D2E0C21EE3A", "hash_sha1": "45986FAC70A9A20FE8798C042DF325F1631E8DD8", "hash_sha256": "E7EC0402B1FB18E41A6AE0F88464D0E07F314FBB418C93771CA94EB0EC60D4EC", "hash_sha384": "529989FA5FB65281BA8E13CF80ED6A08334C60C567F18FFFE68F300E27C9321B4E328C0944A06474D7945CBC987763E8", "hash_sha512": "92E5B5B97F78AC4F65F9C34669FF39A5198D8FEC51B00BC4E20B7A207761A2187CB84BCC83FBCD17D9A3341BE7D00ECE4C687428905F4FDB0929372F266656B7", "hash_ssdeep": "3072:bvedGi1Cmn8lDj0CUuE2u9RkPhE85H13dTGR:bve42CNDIfF2ub0Fld", "hash_imp": "6AAF7C4D7CA95CB440F06CE700C9C270", "hash_pesha1": "2B3559CE3013118675A48E548F9C298DE73C9A9A", "hash_pe256": "C9C78B297B86B4D70DE6BE1E2E7BE05A823CF689B69B206D335E9BD90492F2C9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Mobile Broadband Account Experience Parser Task", "meta_original_filename": "MbaeParserTask.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e7ec0402b1fb18e41a6ae0f88464d0e07f314fbb418c93771ca94eb0ec60d4ec/detection", "runtime_modules": [ "C:\\Windows\\system32\\MbaeParserTask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mblctr.exe-D3DB14EABB2679E08020BCD0C96FA9F6": { "file_name": "mblctr.exe", "file_path": "C:\\Windows\\system32\\mblctr.exe", "hash_md5": "D3DB14EABB2679E08020BCD0C96FA9F6", "hash_sha1": "578DCA7AAD29409634064579D269E61E1F07D9DD", "hash_sha256": "3BAA1DC0756EBB0C2C70A31BE7147863D8D8BA056C1AA7F979307F8790D1FF69", "hash_sha384": "DE36EEA28157AF7CF0FD68BD9FC7209E4380E5CDF536B1CAD610D63CF815B9F259947136146BA4F2982060BAA0E9FB53", "hash_sha512": "14DC895AE458FF0CA13D9C27AA5B4CFC906D338603D43389BB5F4429BE593A587818855D1FE938F9EBEBF46467FB0C1AB28247E8F9F5357098E8B822ECD8FFFE", "hash_ssdeep": "12288:H9lIZoE0OrRvgBRWasky51qviizQBODAKylkm5ZUxXrc5Zh5ZG5Ze:Hsf0GaR3y5kRzAKcjY8poA", "hash_imp": "1A740E3BCF1A45F07A6AE843AF8719BA", "hash_pesha1": "A9D4B43D871BFD060F7D0DDC45B707D4AB9E4EA5", "hash_pe256": "CA5BA35DC6E5AEB7786E3DC677348623FEB3DAF27F6474F4373F946D34E71474", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Mobility Center", "meta_original_filename": "MBLCTR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) Microsoft. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3baa1dc0756ebb0c2c70a31be7147863d8d8ba056c1aa7f979307f8790d1ff69/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\System32\\en-US\\mblctr.exe.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\mblctr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ], "runtime_window_title": "Windows Mobility Center" }, "MBR2GPT.EXE-FFA7448C64B359D176256F313E8A4C44": { "file_name": "MBR2GPT.EXE", "file_path": "C:\\Windows\\system32\\MBR2GPT.EXE", "hash_md5": "FFA7448C64B359D176256F313E8A4C44", "hash_sha1": "B1C94DC0E8493DF6690BD79CF1338F9143A2F599", "hash_sha256": "AEC30F1A41779734895A54503D3151C727D584454BA320E1C0A7270375A4832A", "hash_sha384": "0EA359B22FBC410665AB574DE6F88B9015D091C90922968A596525AC112FE82ED6BF746A2547379C6A95546D11E67367", "hash_sha512": "1E0453EF2DA4FEC878C0AB5056FB064A05DD46996BB761CAF2EC6D1F82B2239E247E2E0B817DFCFBB7A964F4101342F09668AE1F8E40DAEF5E82C2746182E7AC", "hash_ssdeep": "12288:rohI+WFpFLQ8AqGZAGGYGaZvtgbQ9bAXfL+7oqM5PYhrv+gVcuq4tWZiT0cgfD7a:EhIf1SqyAnnhS7oqMlSygGuq4t+1D7a", "hash_imp": "D9311FE666B004EAC7209E9F97EC1B5A", "hash_pesha1": "837C8E77231B469C7F3E8CEF88D8776AE7CFA576", "hash_pe256": "910ED325E6F21271FB328FB5A48F00C19E142631B358E7BFE2689A5D1D612017", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/aec30f1a41779734895a54503d3151c727d584454ba320e1c0a7270375a4832a/detection", "output": "\r\nConverts a disk from MBR to GPT partitioning without modifying or deleting data on the disk.\r\n\r\nMBR2GPT.exe /validate|convert [/disk:<diskNumber>] [/logs:<logDirectory>] [/map:<source>=<destination>] [/allowFullOS]\r\n\r\nWhere:\r\n\r\n /validate\r\n - Validates that the selected disk can be converted\r\n without performing the actual conversion.\r\n\r\n /convert\r\n - Validates that the selected disk can be converted\r\n and performs the actual conversion.\r\n\r\n /disk:<diskNumber>\r\n - Specifies the disk number of the disk to be processed.\r\n If not specified, the system disk is processed.\r\n\r\n /logs:<logDirectory>\r\n - Specifies the directory for logging. By default logs\r\n are created in the %windir% directory.\r\n\r\n /map:<source>=<destination>\r\n - Specifies the GPT partition type to be used for a\r\n given MBR partition type not recognized by Windows.\r\n Multiple /map switches are allowed.\r\n\r\n /allowFullOS\r\n - Allows the tool to be used from the full Windows\r\n environment. By default, this tool can only be used\r\n from the Windows Preinstallation Environment.\r\n\r\n", "error": "Invalid argument: --help\r\n\r\nInvalid arguments\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\MBR2GPT.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mcbuilder.exe-9EE06F45CF8D8154FA53BC0B0397E2D2": { "file_name": "mcbuilder.exe", "file_path": "C:\\Windows\\system32\\mcbuilder.exe", "hash_md5": "9EE06F45CF8D8154FA53BC0B0397E2D2", "hash_sha1": "2CD73F065F259027610BF59B4DD6448E90C5104A", "hash_sha256": "B139D09D95E5A1DE02A00324054FD3DB7D7E874E881C2420441F2576496F8695", "hash_sha384": "07531404C064C0BAFA86E63ACF2D69632B9E3D29C4B450646CD1246FBAD7EE92DBDA8C9CB54A4E7D48E3034CC4568990", "hash_sha512": "49666EF990D4A31B268FA7C7DE8AC12CF0F8F00199FE982EECB92B190A55B8C0F33F1C6F806A1DBC8F167C5E5877A0C7ADF2143006EB4C83CFDF71758F7E1820", "hash_ssdeep": "1536:ucNRbdJlpmUyxs1fweEVIMANxZ09B2ssW4d09dldIGxWJ1jMXT:uwpdJlgUkseLVIMANxKBmMDIGxWf0", "hash_imp": "B48FB62848AB5BA140995A62D9ACEF1A", "hash_pesha1": "8177BF1CF09EFE12665154D0132487F98AEA73E6", "hash_pe256": "7252BF91DCBAB8E17F3481B548C6AF1F2B56DAA5359381135E53C084F260842B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resource cache builder tool", "meta_original_filename": "mcbuilder.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b139d09d95e5a1de02a00324054fd3db7d7e874e881c2420441f2576496f8695/detection", "runtime_modules": [ "C:\\Windows\\system32\\mcbuilder.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "MDEServer.exe-30D6C6D0B3D2DDC16D2BB4A76317F688": { "file_name": "MDEServer.exe", "file_path": "C:\\Windows\\system32\\MDEServer.exe", "hash_md5": "30D6C6D0B3D2DDC16D2BB4A76317F688", "hash_sha1": "40A4E17F790B231FFEFAC5EEE4BA1AB71E9A38EB", "hash_sha256": "47C664B20C6818B29397298F941CE64807D82D80EC96D1E874A9D70F11ACD8D2", "hash_sha384": "6FDF669529797365130039989F64EDDEB8BB26E2CCFF841BF0251C232C38FD74E659B3075E6C118D51CC6CD7E3A9B78F", "hash_sha512": "04569DAC3506F5D0E2461F018B1925F90DDE453DEDB71E734CD4C97D7E19AD04DE5F01EA5B1CDBEFEE492BA5C756F5862EC33DCC3CD7FAE42CE9DE30847CAF69", "hash_ssdeep": "6144:+PBx4Cu9HJ1UKeg0FO8OMxXkDFNxXwDeVeribHIrmAg9hqkAdWSIAtaI:+PBzAJ1mg0FO8fNzGbHI69hqkAd5Lt", "hash_imp": "07880D9EACC62B2F96EDEB42BA6D9055", "hash_pesha1": "60DFA05DD0FF2A27393F198BDC6655647E4D7B24", "hash_pe256": "188C3FE0D658641D09E6ED38496212265F780F5D93223FD831CA688F42017C52", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Cast to Device Server", "meta_original_filename": "MDEServer.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/47c664b20c6818b29397298f941ce64807d82d80ec96d1e874a9d70f11acd8d2/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MDEServer.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\MDEServer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\winmde.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll" ] }, "MDMAgent.exe-75C2003F3D269C07A5D52E3AA8225D05": { "file_name": "MDMAgent.exe", "file_path": "C:\\Windows\\system32\\MDMAgent.exe", "hash_md5": "75C2003F3D269C07A5D52E3AA8225D05", "hash_sha1": "9B114E77531B106A6970C5528E211BB796521CC9", "hash_sha256": "9840565E700311386876D2843B33E9A680F3D64AC821674B259573E441198E13", "hash_sha384": "0CA0815E205A1B82E63F3A0B7AF92497D9F83C56FC1BDC7B725871F6634A49F11CED55315BA71307D08C10AEB020F3CE", "hash_sha512": "A835061FAFE7B7B4EBE0345010377B46B71745FE4BD8D602CE3648BBF6097B87BD6E66CB1567D7A040D2253367C2609135F3CC3B2FA1257D720DBDCA0C2A7484", "hash_ssdeep": "3072:pupEb89riFezeeTK1X6EYzdMkbe0rHjnZnk1Fe/oOfRM:pupEb89r/2E9KJMQMR", "hash_imp": "345FA8112EDD1BE2A4082E99B3F7711B", "hash_pesha1": "6AA1C9A540C636992AA14D6244B9F184AED399B4", "hash_pe256": "50068988BFEA981F91D37488FC0D2B1E1E58F1C1D374A31BE9B1EC683226A945", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MDMAgent", "meta_original_filename": "MDMAgent", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/9840565e700311386876d2843b33e9a680f3d64ac821674b259573e441198e13/detection", "runtime_modules": [ "C:\\Windows\\system32\\MDMAgent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\system32\\dmEnrollEngine.DLL", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\system32\\iri.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\cfgmgr32.dll" ] }, "MDMAppInstaller.exe-4403D9A9D8E92E7695DAC02E7A0E20CE": { "file_name": "MDMAppInstaller.exe", "file_path": "C:\\Windows\\system32\\MDMAppInstaller.exe", "hash_md5": "4403D9A9D8E92E7695DAC02E7A0E20CE", "hash_sha1": "6FC07663DCFB17D649B7FA800978C1D261031717", "hash_sha256": "79B9D43AACD693EBDF53E6F90B3C6EEF5EE4EE2E80D229518AAB98AC48C1C65E", "hash_sha384": "9A74BF7E701E312E629B67126C009351AE9B5684807BEB5318309F04533248AE06C967D55B43B549E4B23B4C709C1BE6", "hash_sha512": "C1D31884534CAD2F8A0D0B6CF13FDB23F0B9F677F83D3E71DE6A269D37EC469128E22DFE39BF7F59466949AAC56A15EC3C700FD76BB3851463D34E05A28F4F11", "hash_ssdeep": "3072:YseL7LkO2Hqj1QVnkwZRzksjVehxoqgo+CsKwt5:YseL7LkO2Hq1QVnkEQoeb9go+Cat", "hash_imp": "BA2321FB33BEFB0EA756FD274337B07A", "hash_pesha1": "3B7891CF734F1F1A5A8A29F5A613B0AE8BDBF42A", "hash_pe256": "FB2CD7B6285C8990A3849E3FC1B4D330D23596EE32C5CCDB4305668B8671DCAB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MDM App Installer", "meta_original_filename": "MDMAppInstaller.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/79b9d43aacd693ebdf53e6f90b3c6eef5ee4ee2e80d229518aab98ac48c1c65e/detection", "runtime_modules": [ "C:\\Windows\\system32\\MDMAppInstaller.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\dmEnrollEngine.DLL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\WTSAPI32.dll" ] }, "MdmDiagnosticsTool.exe-F20ECB94071A09A82E77D6C6EC812EE2": { "file_name": "MdmDiagnosticsTool.exe", "file_path": "C:\\Windows\\system32\\MdmDiagnosticsTool.exe", "hash_md5": "F20ECB94071A09A82E77D6C6EC812EE2", "hash_sha1": "17456B841F099D2CAFCA796AAB5A1A282B72C93E", "hash_sha256": "AAFAD4DB7AAB9E9A140DF4E6B0A53DC7067E22C65CAD1616E3B79CCC3252EC71", "hash_sha384": "54DB7A6AA16494461F9A49E10304DAE5C9EFAB59021B415463A619269505C9059E7295F6ECECA192A05F2560730BB7B5", "hash_sha512": "0DD696DFD4AF5F88A9C42B1FCF04A2AFF0E05B2C3552CB3AB1D1786977193A895E7A1823580BDE4F2237E4AFBF8924B213E1176E05A28147757DB00F3FF323EE", "hash_ssdeep": "1536:N7L5ewNt3W0wWBPt+KWmfVev4+6PdHvpuebu:lYuW0wqt+LyVo4+GdHBDbu", "hash_imp": "B3D13A58F56A15A7D8EC28905ABAC621", "hash_pesha1": "FC13B31CCB614D84B131F095B33F2E4C20D3D4FC", "hash_pe256": "16D287F66313D7BB6FA4F1A620D1F520ADBC1B3B7D79568D0948FB8D74F999FC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MdmDiagnosticsTool", "meta_original_filename": "MdmDiagnosticsTool.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.329 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.329", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/aafad4db7aab9e9a140df4e6b0a53dc7067e22c65cad1616e3b79ccc3252ec71/detection", "output": "\r\n Usage1: C:\\Windows\\system32\\MdmDiagnosticsTool.exe -out <output folder path>\r\n * Output MDM diagnostics info only to given folder path specified in -out parameter.\r\n eg: C:\\Windows\\system32\\MdmDiagnosticsTool.exe -out c:\\temp\\outputfolder\r\n\r\n Usage2: C:\\Windows\\system32\\MdmDiagnosticsTool.exe -area <area name(s)> -cab <output cab file path>\r\n * Collect predefined area logs and create a log cab to given cab file.\r\n * Supported area name example:\r\n Autopilot\r\n DeviceProvisioning\r\n Tpm\r\n * It also supports multiple areas, separated by ';', example:\r\n Autopilot;DeviceEnrollment;Tpm\r\n * Please find all possible areas in registry under:\r\n HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\MdmDiagnostics\\Area\r\n eg: C:\\Windows\\system32\\MdmDiagnosticsTool.exe -area Autopilot;Tpm -cab c:\\temp\\AutopilotDiag.cab\r\n Usage3: C:\\Windows\\system32\\MdmDiagnosticsTool.exe -area <area name(s)> -zip <output zip file path>\r\n * Collect predefined area logs and create a log zip to given zip file. Areas supported are the same as Usage2 for creating cab\r\n Usage4: C:\\Windows\\system32\\MdmDiagnosticsTool.exe -xml <xml file of information to gather> -zip <output zip file path> -server <MDM Server to alert>\r\n * Collect information specified in the xml and create a log zip to given zip file. \r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\MdmDiagnosticsTool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "MdRes.exe-0C523F617F069E18124660A1486D6B6F": { "file_name": "MdRes.exe", "file_path": "C:\\Windows\\system32\\MdRes.exe", "hash_md5": "0C523F617F069E18124660A1486D6B6F", "hash_sha1": "3753404A31A30F60B5E246579DEEB7BD8A3B3F29", "hash_sha256": "017F58759130EB04830148C5F71D866D9D9C0A231CA67440D335B8790C19AFE0", "hash_sha384": "EB1ABDA55BFA9EE171763013A58748236ED58C57209F3C53644862F7FACA5C2F451805CE5E40CA3525DBAFD773E37F27", "hash_sha512": "B40FEA55BBBC473207F3046DC42CE495C047E57C42624EF6B0A74A78CB961FCE8D494DC463A2507E6A507DC663D053E8B36A029B7D3779914BC4FCE594937E24", "hash_ssdeep": "1536:bKH1/nfGLm+65tFI720+VpmDOzc4JNWxwB1MjVJmRc:uteLe/FO+VQDUcUNWs+jm6", "hash_imp": "3D553FEF2350214DF4679F35FF59A173", "hash_pesha1": "0FF8C4B9198275AB696FBFEC70BD635BB5879284", "hash_pe256": "B5EC96063D421CF6127DE49E64F7C9DE244998582E3C8678B99C6ACC006C7401", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Memory Diagnostic", "meta_original_filename": "MdRes.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/017f58759130eb04830148c5f71d866d9d9c0a231ca67440d335b8790c19afe0/detection", "runtime_modules": [ "C:\\Windows\\system32\\MdRes.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "MdSched.exe-4FF2CCEEDC45B573012B35E6DCA467AA": { "file_name": "MdSched.exe", "file_path": "C:\\Windows\\system32\\MdSched.exe", "hash_md5": "4FF2CCEEDC45B573012B35E6DCA467AA", "hash_sha1": "409D14B3AEB39D8480EAF5B981D3E009276EE5B3", "hash_sha256": "043CF5DA5A37A30ECC4BF526A811E7C474843FD25E45C691B82C1458318686E8", "hash_sha384": "397AB51878D65A6FB7424CDF90EDF340CBADF9D0F0E1CBD48C9B2DC1342225AAB273BD7742598ECD0915F75CB3D9785A", "hash_sha512": "3EBA3F25115950BD98AAC4D9112D716E965ED0D08F86DB35BD48525EDDDD781A24A2FFDAAA03D7B38DB5F55B782EDED6FEAF241A46D2677AC736810167298F2E", "hash_ssdeep": "1536:j60HWG8IvGm+65tFI720+VpmDOzc4JNWxwB1MjVJmRc:tHfvGe/FO+VQDUcUNWs+jm6", "hash_imp": "AAA5D23775A803F6978426A3C7A1F259", "hash_pesha1": "306B935F9F03B0FB0ABB90204A94537FCFAC461B", "hash_pe256": "A1D7A2D6A43ECE27E189889353475EC2F15D41608F2E61066AC18568F75E27B0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Memory Diagnostics Tool", "meta_original_filename": "MdSched.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/043cf5da5a37a30ecc4bf526a811e7c474843fd25e45c691b82c1458318686e8/detection", "runtime_modules": [ "C:\\Windows\\system32\\MdSched.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\system32\\bcd.dll" ] }, "mfpmp.exe-8F8FD1988973BAC0C5244431473B96A5": { "file_name": "mfpmp.exe", "file_path": "C:\\Windows\\system32\\mfpmp.exe", "hash_md5": "8F8FD1988973BAC0C5244431473B96A5", "hash_sha1": "CE81EA37260D7CAFE27612606CF044921AD1304C", "hash_sha256": "27287AC874CEF86BE03AEE7B6D34FDC3BD208070ED20E44621A305865FB7579E", "hash_sha384": "A4380BA6C1E3D565C07AFCA79CF0076AD1499576A3112585420409A5702F91056840418D2723735E1BD0C57AAE80E4A7", "hash_sha512": "A91179E1561168B3B58F5CA893BCE425D35F4A02AEC20AC3D6FB944F5EB3C06B0A1B9D9F3FB9EA87869D65671D2B89B4AE19ACF794372BDBD27F5E9756C5A8AB", "hash_ssdeep": "768:T9djkePa3/Yk6CPq0dv23xdLEED1txmjajEI1PWCi:T9dji3/Yp0dv23xdEEZnmjatPY", "hash_imp": "FD15D01D16137A6440E7161E903FCC93", "hash_pesha1": "6FC7D3573EF2182E55AAD652BBD9719D4F7E3399", "hash_pe256": "57D03B762B7E6A2F34BF13698BE55065C9C53602C7388240FC36BA52329E75DC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Media Foundation Protected Pipeline EXE", "meta_original_filename": "mf.dll.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/27287ac874cef86be03aee7b6d34fdc3bd208070ed20e44621a305865fb7579e/detection", "runtime_modules": [ "C:\\Windows\\system32\\mfpmp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\system32\\MFCORE.dll", "C:\\Windows\\system32\\MFPlat.DLL", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\system32\\ksuser.dll", "C:\\Windows\\system32\\CRYPTBASE.DLL" ] }, "Microsoft.Uev.CscUnpinTool.exe-DBAD2253C9B3154DEE72F431A6FD5D91": { "file_name": "Microsoft.Uev.CscUnpinTool.exe", "file_path": "C:\\Windows\\system32\\Microsoft.Uev.CscUnpinTool.exe", "hash_md5": "DBAD2253C9B3154DEE72F431A6FD5D91", "hash_sha1": "1AFCFD06ED73B5FB9951D7FD799CFD2E945AEC61", "hash_sha256": "A5EFB6AB80C76D5EC238BB952A8EE241ED13077F27FBECBF43F9780125034ABF", "hash_sha384": "8A7CCEA442E6BB17D768418E04768C4FB8E0BDB65577137ACC0C61113FCB967315ADC1E9C96E0831F4004ECA306D4F86", "hash_sha512": "EAE2234C112AD3B291A6F507B9DF670CE41A5E8359DD7BAC2DACF5BE7248DA2E336933357CB355BA2F53B7042DAC0C3D503946988C4EDFA800FFBE853FF5CE27", "hash_ssdeep": "6144:2LHkw505P//M5tV0lo1wSPAdQoICRqbS78xft2iGX+YfQliXu52/wWUL:sM/+Uo18rRAS7wfBIXoliXur", "hash_imp": "D126B605E4BA44992675F5E6815BE754", "hash_pesha1": "0C01A7C66D45875282E845385B34CE8A36DB368E", "hash_pe256": "604948C3CCC2CF92204F2CEF5F27305DEB91A73E29815F16701B0701D1EB7A99", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft.Uev.CscUnpinTool EXE", "meta_original_filename": "Microsoft.Uev.CscUnpinTool.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a5efb6ab80c76d5ec238bb952a8ee241ed13077f27fbecbf43f9780125034abf/detection", "runtime_modules": [ "C:\\Windows\\system32\\Microsoft.Uev.CscUnpinTool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\CSCAPI.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "Microsoft.Uev.SyncController.exe-B9D4C0EA77E598B45015E36624D8FBE4": { "file_name": "Microsoft.Uev.SyncController.exe", "file_path": "C:\\Windows\\system32\\Microsoft.Uev.SyncController.exe", "hash_md5": "B9D4C0EA77E598B45015E36624D8FBE4", "hash_sha1": "FB69E81B5D252152630D3F1B6426FEF4DE3FC2EE", "hash_sha256": "D0B753FC637891AAE7FB08AD4B4EFDC693689EE8E6A9B7145E15E495493972F3", "hash_sha384": "0C1268B968488C21F6A2846EF4BB9959790FAC2958F7BC9E3FAA94ACC2C0C3420F652B8643380E4FEC2AE37DE86BE011", "hash_sha512": "3A61E16E4B6870C97EF4F5628444EFC6D7D46E7F9072124D4C37DA4CB19FBF06553108BAB45AA8D0542B6DA3987C88035C5176B7573783EA930194B47D47805C", "hash_ssdeep": "1536:2hCtaUCKV/Q2vd1sTNe+6NwiKE10DHlu:FCKV/Q2vd1sTNGBl10Y", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "935A4BD1227F8DAFE22031A81A64635D4998C3A3", "hash_pe256": "D6D3D9C65068198B89F8E3A992C1BF6460B3479F4365E15FD6389D44022A1CC0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "Microsoft.Uev.SyncController.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/d0b753fc637891aae7fb08ad4b4efdc693689ee8e6a9b7145e15e495493972f3/detection", "runtime_modules": [ "C:\\Windows\\system32\\Microsoft.Uev.SyncController.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "MicrosoftEdgeBCHost.exe-1472361DB9BC28F6C4CB327FE5E35393": { "file_name": "MicrosoftEdgeBCHost.exe", "file_path": "C:\\Windows\\system32\\MicrosoftEdgeBCHost.exe", "hash_md5": "1472361DB9BC28F6C4CB327FE5E35393", "hash_sha1": "5675BF13004943DEBD19A6B1CAD3707076CD2A2B", "hash_sha256": "91A954FECD74F20B4A25708D7323E64FB4DD4E03997BCF234E7B810F9EB03A95", "hash_sha384": "2BB29A5C674127BF2AEE4091240E22B889B90C4A4B50E9C7D5915B88E6DA08D0FB9DB592D8964C81A894809FBABD657A", "hash_sha512": "B3675480F4B234098B485A7F63799BD95877C879E85456D4FCF9EAC3CC2FD6C7383AF7419E0BE8297289B3C577839E046B343E18B655EADD184501117D1C13AB", "hash_ssdeep": "1536:pIYH0romDAy7+O0eNz2sRZjDM0Q1/UqjbB877rnjrd1nP8RX:pI7omcy17kf0Qy7/jpVP8RX", "hash_imp": "CCC8877CD76F451BC5955A4881A228DF", "hash_pesha1": "A25347CEA622305D99259E6E26FDE44DEA31ED1A", "hash_pe256": "4D2C6A7DDA1533B6995EBFD587717D298BB0E7C5EB5734D7FD97352E074B1C63", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Edge Content Process", "meta_original_filename": "MicrosoftEdgeCP.exe", "meta_product_name": "Microsoft Edge Web Platform", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/91a954fecd74f20b4a25708d7323e64fb4dd4e03997bcf234e7b810f9eb03a95/detection", "runtime_modules": [ "C:\\Windows\\system32\\MicrosoftEdgeBCHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll" ] }, "MicrosoftEdgeCP.exe-1472361DB9BC28F6C4CB327FE5E35393": { "file_name": "MicrosoftEdgeCP.exe", "file_path": "C:\\Windows\\system32\\MicrosoftEdgeCP.exe", "hash_md5": "1472361DB9BC28F6C4CB327FE5E35393", "hash_sha1": "5675BF13004943DEBD19A6B1CAD3707076CD2A2B", "hash_sha256": "91A954FECD74F20B4A25708D7323E64FB4DD4E03997BCF234E7B810F9EB03A95", "hash_sha384": "2BB29A5C674127BF2AEE4091240E22B889B90C4A4B50E9C7D5915B88E6DA08D0FB9DB592D8964C81A894809FBABD657A", "hash_sha512": "B3675480F4B234098B485A7F63799BD95877C879E85456D4FCF9EAC3CC2FD6C7383AF7419E0BE8297289B3C577839E046B343E18B655EADD184501117D1C13AB", "hash_ssdeep": "1536:pIYH0romDAy7+O0eNz2sRZjDM0Q1/UqjbB877rnjrd1nP8RX:pI7omcy17kf0Qy7/jpVP8RX", "hash_imp": "CCC8877CD76F451BC5955A4881A228DF", "hash_pesha1": "A25347CEA622305D99259E6E26FDE44DEA31ED1A", "hash_pe256": "4D2C6A7DDA1533B6995EBFD587717D298BB0E7C5EB5734D7FD97352E074B1C63", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Edge Content Process", "meta_original_filename": "MicrosoftEdgeCP.exe", "meta_product_name": "Microsoft Edge Web Platform", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/91a954fecd74f20b4a25708d7323e64fb4dd4e03997bcf234e7b810f9eb03a95/detection", "runtime_modules": [ "C:\\Windows\\system32\\MicrosoftEdgeCP.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "MicrosoftEdgeDevTools.exe-1472361DB9BC28F6C4CB327FE5E35393": { "file_name": "MicrosoftEdgeDevTools.exe", "file_path": "C:\\Windows\\system32\\MicrosoftEdgeDevTools.exe", "hash_md5": "1472361DB9BC28F6C4CB327FE5E35393", "hash_sha1": "5675BF13004943DEBD19A6B1CAD3707076CD2A2B", "hash_sha256": "91A954FECD74F20B4A25708D7323E64FB4DD4E03997BCF234E7B810F9EB03A95", "hash_sha384": "2BB29A5C674127BF2AEE4091240E22B889B90C4A4B50E9C7D5915B88E6DA08D0FB9DB592D8964C81A894809FBABD657A", "hash_sha512": "B3675480F4B234098B485A7F63799BD95877C879E85456D4FCF9EAC3CC2FD6C7383AF7419E0BE8297289B3C577839E046B343E18B655EADD184501117D1C13AB", "hash_ssdeep": "1536:pIYH0romDAy7+O0eNz2sRZjDM0Q1/UqjbB877rnjrd1nP8RX:pI7omcy17kf0Qy7/jpVP8RX", "hash_imp": "CCC8877CD76F451BC5955A4881A228DF", "hash_pesha1": "A25347CEA622305D99259E6E26FDE44DEA31ED1A", "hash_pe256": "4D2C6A7DDA1533B6995EBFD587717D298BB0E7C5EB5734D7FD97352E074B1C63", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Edge Content Process", "meta_original_filename": "MicrosoftEdgeCP.exe", "meta_product_name": "Microsoft Edge Web Platform", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/91a954fecd74f20b4a25708d7323e64fb4dd4e03997bcf234e7b810f9eb03a95/detection", "runtime_modules": [ "C:\\Windows\\system32\\MicrosoftEdgeDevTools.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll" ] }, "MicrosoftEdgeSH.exe-C2599AACDB852A0E1BCB2BA6E2CA348E": { "file_name": "MicrosoftEdgeSH.exe", "file_path": "C:\\Windows\\system32\\MicrosoftEdgeSH.exe", "hash_md5": "C2599AACDB852A0E1BCB2BA6E2CA348E", "hash_sha1": "2FD233F65D589BF6C4994818C3336BC8679D7CE1", "hash_sha256": "E5D93718F0905B341D6FC68399257D88C56479B2A7FFB253FD88A405E6ED6E74", "hash_sha384": "AB8A4059E1B3188E637C3D52642F0C71DB63799F9B13465DA9F87B1BCE03C90C5FEC6C9D4836ED981D9319AAFAE73938", "hash_sha512": "ADB69E63122CD69240FB577016C77EB58A18D35528D173E31AE3E6820327606A9B83312AA308D808A635103080E6B7A00D2842F6334A7D0E6A63079ECBAC97F6", "hash_ssdeep": "768:el/wBBBMcf1XIOOBTn9DAvt8DQgfMycTEYL67rNFPWk+iVgkV:el/wzfhFOBThDUygL67xpr+iVgu", "hash_imp": "9A60907A4B7698D20A0EE05C0A0E3F5D", "hash_pesha1": "C990FC5D35AD1655D602D3EE5EB5F6932F10DA84", "hash_pe256": "59853FBB1C2878738F034532E03DEF17AB7100FAFDB8936D5E16301D50A703C7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Edge Web Platform", "meta_original_filename": "MicrosoftEdgeSH.exe", "meta_product_name": "Microsoft Edge Web Platform", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e5d93718f0905b341d6fc68399257d88c56479b2a7ffb253fd88a405e6ed6e74/detection", "runtime_modules": [ "C:\\Windows\\system32\\MicrosoftEdgeSH.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\system32\\edgeIso.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll" ] }, "mmc.exe-C51BACB9B93CA44254BE462516C6BEE0": { "file_name": "mmc.exe", "file_path": "C:\\Windows\\system32\\mmc.exe", "hash_md5": "C51BACB9B93CA44254BE462516C6BEE0", "hash_sha1": "4862BFF38B774FC8329756B0773CF53D46B2DC37", "hash_sha256": "35791F1DBD343A5A46A3A18100E2E85C1DF83085053E07DEAE56D46132F982AF", "hash_sha384": "50D70D08EBF9863D422DF3FC7978BCA58BE603643C000F59A571AC5EAA4D0915C9F14155CF9B95731D00B470CAF01596", "hash_sha512": "36A110DCFF0E10B2C45A9C4F0850D114100F59525EAAC3E2FA95A8E9925A108AFC1AD05B800226FF5EB2D5B628D4C63BED2E4FC47EDCB440C975477EF0FF8AE8", "hash_ssdeep": "24576:bj9vu0hWh5OephGCeKIvnOtAaOMo7wMo7DH:J45OeThmnOG97e7DH", "hash_imp": "6D8477830CFE8D50B7224D91F4DD7CB9", "hash_pesha1": "EE7B77DD16EA8A5BE66229AF761889F696488B67", "hash_pe256": "D9CC805400983D89137ADC292D243C87964137A8AC39AB9B5686084D285400D9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Management Console", "meta_original_filename": "mmc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/35791f1dbd343a5a46a3a18100e2e85c1df83085053e07deae56d46132f982af/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\mmc.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\mmcbase.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\SystemResources\\mmcbase.dll.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Sessions\\1\\BaseNamedObjects\\42cHWNDInterface:1003e6": "Section", "\\Sessions\\1\\BaseNamedObjects\\42cHWNDInterface:1303e4": "Section", "(R-D) C:\\Windows\\System32\\en-US\\mmcndmgr.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\mmcndmgr.dll.mun": "File", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\mmc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\SYSTEM32\\AcGenral.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ADVAPI32.dll" ], "runtime_window_title": "Console1 - [Console Root]" }, "mmgaserver.exe-84646E6A86FEB9C096D354B011D23F05": { "file_name": "mmgaserver.exe", "file_path": "C:\\Windows\\system32\\mmgaserver.exe", "hash_md5": "84646E6A86FEB9C096D354B011D23F05", "hash_sha1": "40800D4988E7C4A4F94E59C5ACA4C887905DE422", "hash_sha256": "9143D7977DBB84661AB4C5050CC69E7784BCDCE26FFBC036B108C09A81318CB3", "hash_sha384": "20D8EA6BD33B5818C7FF74FBDF0F57DC53A6B1B5BF8A66EBC0A9F7DD7CED75CD76D2C8B0A68728C0975F47D0E7ACC1DD", "hash_sha512": "E257A1897301F12973DA2F9B85DE89F721A37D2FF8D642A5185F89D074ED6DA2BE3BD3D770C18F8392E25A1A3058388214C95097CDBAF1AF99263DA5C1D1077E", "hash_ssdeep": "24576:0DQv2TXwDO4++8cXwnLcbZV6GTS2AR/P93:0DT9c/VfS2s93", "hash_imp": "27B4DB1C625181771F64CF4B5A6A8E44", "hash_pesha1": "94FE6F768421F68833D4DE45B6C6F7B6A9754CD2", "hash_pe256": "37FDF5952AA85A42648E1486AE169BF4EEF9E7CFCCB6C16795EED941B9BC205D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MMGA Server", "meta_original_filename": "mmgaserver.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9143d7977dbb84661ab4c5050cc69e7784bcdce26ffbc036b108c09a81318cb3/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\mmgaserver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "mobsync.exe-5990B373978022822C91C1B997B859AA": { "file_name": "mobsync.exe", "file_path": "C:\\Windows\\system32\\mobsync.exe", "hash_md5": "5990B373978022822C91C1B997B859AA", "hash_sha1": "E65D0219E0E0C7B564D7CC71A11F145A1EE7E358", "hash_sha256": "6E83030A6A3E447ACB1D38CC07035C1FD5BD2C9E136A57CE99F3AC1BE45A7D3D", "hash_sha384": "6F1DCFAED0C588571D74D420B33902F4230109E8F703D03229C5EFAD6D06106FC398DF0CA5EE9C489908679DE8E989E6", "hash_sha512": "0FF669AA63D510A57EE834D0C9FBA99FAF2609A02765A8CF29BEFD29004AC7095FFB2A7B190E7723347941DEE12BE546ED55EC7558CA0C1C10F182B0B070A568", "hash_ssdeep": "1536:Egi6A/6n66FHGYzkZup0ZBN2GPoCGVjGWmt8CXZ+63x+w4JD+0NL+fK:ni6Bn66NYj2GPo9St8WHxSD+09+S", "hash_imp": "F247D587E13B170D2246BD033539DBFB", "hash_pesha1": "1CB8FE914AEFB0FD1807D331C48E530E3D785773", "hash_pe256": "717ACAC9C17DD66D4D375C5F3F3516B9F943E960CEF9711262F16C60025D4CDD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Sync Center", "meta_original_filename": "mobsync.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/6e83030a6a3e447acb1d38cc07035c1fd5bd2c9e136a57ce99f3ac1be45a7d3d/detection", "runtime_modules": [ "C:\\Windows\\system32\\mobsync.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll" ] }, "mountvol.exe-F3EDFF85DE5FD002692D54A04BCB1C09": { "file_name": "mountvol.exe", "file_path": "C:\\Windows\\system32\\mountvol.exe", "hash_md5": "F3EDFF85DE5FD002692D54A04BCB1C09", "hash_sha1": "4C844C5B0EE7CB230C9C28290D079143E00CB216", "hash_sha256": "CAF29650446DB3842E1C1E8E5E1BAFADAF90FC82C5C37B9E2C75A089B7476131", "hash_sha384": "6E5D0127C6BD7E1FF21B05674565031608275C42238A7C70CD794E5711AC76453525FF3201793E0B040585152E78BB40", "hash_sha512": "531D920E2567F58E8169AFC786637C1A0F7B9B5C27B27B5F0EDDBFC3E00CECD7BEA597E34061D836647C5F8C7757F2FE02952A9793344E21B39DDD4BF7985F9D", "hash_ssdeep": "384:abquDyuX3PMD1A77ciNqC/Elsrl+0+/QlDIINvB0WLFW:gquuuHPMDinDY9al+0WQFNvBZ", "hash_imp": "72D2CD1301A2466A3D1834DC3B95BE3F", "hash_pesha1": "B30703EA6D8390223B61552D3FBAE3C7BFE791D8", "hash_pe256": "F130F3E4BBE0957960CC3442E09364645E73ABDB5B085DF9E34CBD4D20E567D9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Mount Volume Utility", "meta_original_filename": "MOUNTVOL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/caf29650446db3842e1c1e8e5e1bafadaf90fc82c5c37b9e2c75a089b7476131/detection", "output": "Creates, deletes, or lists a volume mount point.\r\n\r\nMOUNTVOL [drive:]path VolumeName\r\nMOUNTVOL [drive:]path /D\r\nMOUNTVOL [drive:]path /L\r\nMOUNTVOL [drive:]path /P\r\nMOUNTVOL /R\r\nMOUNTVOL /N\r\nMOUNTVOL /E\r\nMOUNTVOL drive: /S\r\n\r\n path Specifies the existing NTFS directory where the mount\r\n point will reside.\r\n VolumeName Specifies the volume name that is the target of the mount\r\n point.\r\n /D Removes the volume mount point from the specified directory.\r\n /L Lists the mounted volume name for the specified directory.\r\n /P Removes the volume mount point from the specified directory,\r\n dismounts the volume, and makes the volume not mountable.\r\n You can make the volume mountable again by creating a volume\r\n mount point.\r\n /R Removes volume mount point directories and registry settings\r\n for volumes that are no longer in the system.\r\n /N Disables automatic mounting of new volumes.\r\n /E Re-enables automatic mounting of new volumes.\r\n /S Mount the EFI System Partition on the given drive.\r\n\r\nPossible values for VolumeName along with current mount points are:\r\n\r\n \\\\?\\Volume{38184124-336f-4bf7-bb7f-9d8459dba1b2}\\\r\n C:\\\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\mountvol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "MoUsoCoreWorker.exe-66D5E472CAC7AD32561F891AACDC71D9": { "file_name": "MoUsoCoreWorker.exe", "file_path": "C:\\Windows\\system32\\MoUsoCoreWorker.exe", "hash_md5": "66D5E472CAC7AD32561F891AACDC71D9", "hash_sha1": "F3DA6968A419685023BB46D00B47ED343047FE5A", "hash_sha256": "22AFA24D1A010B9465897BD8657FF34F27EFEC9EF0AA919EB3F211F1C1026948", "hash_sha384": "6525625D72DFB029FC4C327048D28C35CDFFD1C227C592230E127F76E1F7E485455A1364FC2E598C04ED9DF9843969F0", "hash_sha512": "FC6153E8BA6C5DBEBE2EC90903803B1D32E1EE08AE26DBA5FE285E92DE7AB157C07DC73107C7F3E630A6FCE29C84C6DC00791E337C5EC4764E9A0FA05FB13E2D", "hash_ssdeep": "24576:aZJvYqhVusESiktB0KL0PcQFGH0pyPGgLipKQsG3WTs:EgqazJB00MPGdpDtW", "hash_imp": "39233DDAE71CD9D2B0CA5AA6FDD61054", "hash_pesha1": "4EF7DFA80D44EBC484A6939678465571E027AEE6", "hash_pe256": "A008E3448A4196FE5F5D0763C639A422EF36F607D0AB719169E80236BBC96100", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MoUSO Core Worker Process", "meta_original_filename": "MoUSOCoreWorker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/22afa24d1a010b9465897bd8657ff34f27efec9ef0aa919eb3f211f1c1026948/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\MoUsoCoreWorker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\dmiso8601utils.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\cfgmgr32.dll" ] }, "mpnotify.exe-8F9739E266623499391CBAC652A01036": { "file_name": "mpnotify.exe", "file_path": "C:\\Windows\\system32\\mpnotify.exe", "hash_md5": "8F9739E266623499391CBAC652A01036", "hash_sha1": "DA16142D698DBBD243930E5058D7756F2204296D", "hash_sha256": "33F636F222A3AF0BBBE429CC87B25B21B6C56182936C81C9453C4BDFB61A3C5E", "hash_sha384": "21C480B71FE15FA1B1EFD9402220532AAAF9B111E4CD6BF4544EC87D44A78E473B1BDF7E44F85E8775734A4816B264A6", "hash_sha512": "D5E562332B4BCD77C7C4C426491E37D3501388656E51F600FB6F007A59675D3AD5669487E730A38AF705E94E2746F1BD9238190FE1C6152229096A5180AA3797", "hash_ssdeep": "384:kTXEOdSMTDFZygxQ6HNO+4j7W9zAdTZVRqHWijW:aXEODFZyg9N4j2z+TZW1", "hash_imp": "CD22AC47106D5026EA3B26DED33E58CD", "hash_pesha1": "707F057ADB8E80AC734598B1BEF3B2321583ED31", "hash_pe256": "E85D49BCC22851EC9AE5A8EEFAFB850A1FF478FAC2E4236A73C1F99C524BD024", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows NT Multiple Provider Notification Application", "meta_original_filename": "mpnotify.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/33f636f222a3af0bbbe429cc87b25b21b6c56182936c81c9453c4bdfb61a3c5e/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\mpnotify.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "MRINFO.EXE-8880DA143C3911C2ED71AE4C3E534531": { "file_name": "MRINFO.EXE", "file_path": "C:\\Windows\\system32\\MRINFO.EXE", "hash_md5": "8880DA143C3911C2ED71AE4C3E534531", "hash_sha1": "5FCE5C7D3F1F077141889E407348DA4706D85C31", "hash_sha256": "59EEA6E8904771A620559EC4F55AED2CA0F5BCF9B14C6D030301F165AA59EB2C", "hash_sha384": "94BE9F7996021FC719F1CF81093395B42DDAA793149827C0ED57F289CE74950209273B0A23E9C2DAD6C923350CD638A7", "hash_sha512": "00A0318225F59DDE6E1489655B81B609A53034C32E197F96B60C25D731847ACF363E6E82302C0FA2ACAF8581A318ECACF4FAE9CAD6DDAAF374EFCA30A815A073", "hash_ssdeep": "384:YFt53LJeMkQ6QknlMFwoDomCCmNKMfyPEHsWe8W:YrBrkT8huCmNKMfjH4", "hash_imp": "293E4CA0CECE9CF71F0DB8AA9DCA02F6", "hash_pesha1": "FC22C045AF29EAA62E62CF92A0ABB21DF702EC3E", "hash_pe256": "7112895823DFA9518BDBCD62173904100AFE11324A47299BBEA8979193B2A5A5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Multicast Information", "meta_original_filename": "mrinfo.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/59eea6e8904771a620559ec4f55aed2ca0f5bcf9b14c6d030301f165aa59eb2c/detection", "output": "\r\nUsage: mrinfo [-n?] [-i address] [-t secs] [-r retries] destination\r\n \r\n -n Display IP addresses in numeric format\r\n -i address Address of local interface to send query out\r\n -t seconds Timeout in seconds for IGMP queries (default = 3 seconds) \r\n -r retries Number of extra times to send the SNMP queries (default = 0) \r\n -? Print Usage\r\n destination Address or name of destination\r\n\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\MRINFO.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "MSchedExe.exe-89E7C865C8D862C55404B8B9A5F4B371": { "file_name": "MSchedExe.exe", "file_path": "C:\\Windows\\system32\\MSchedExe.exe", "hash_md5": "89E7C865C8D862C55404B8B9A5F4B371", "hash_sha1": "54F5E4C43388C958A1ED947E2BB9E0E5D8A43277", "hash_sha256": "B48D5B58D9BBF92FBFFBA06D98E695218676D3BA1D4A060C08E3B9EF1650110C", "hash_sha384": "9800D46BF83318819EBFB157CD514922DF7901892901EA79C5B002023F6F2C98D39A971AC3AFE9EFE13DAA07F1860FE8", "hash_sha512": "15EE9D59BD528D3E5897C7574552A8AFE68E592E5064D03B1BC9F7B5F3F9BE308A9A2E39BEE7B8A190C4DEC5EB36FCFB347D488187B93E352AC03B2DD6E4DFCD", "hash_ssdeep": "1536:piDtREC/rMcgEPJV+G57ThjEC0kzJP+V5Jx:EzECTMpuDhjRVJGb", "hash_imp": "9BB805D1418F5443C74B46538E23AA97", "hash_pesha1": "08AAC218ED9B5BAF3B12ABEC552BC2B7952DEF66", "hash_pe256": "7B513F50F4B58F978065DA8B65436D52716E4049A1D7A981B107F6FA137252B8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Automatic Maintenance", "meta_original_filename": "MSchedExe.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/b48d5b58d9bbf92fbffba06d98e695218676d3ba1d4a060c08e3b9ef1650110c/detection", "runtime_modules": [ "C:\\Windows\\system32\\MSchedExe.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\MaintenanceUI.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\System32\\SHCORE.DLL" ] }, "msconfig.exe-C39148DD0D650E2C49095237998218F2": { "file_name": "msconfig.exe", "file_path": "C:\\Windows\\system32\\msconfig.exe", "hash_md5": "C39148DD0D650E2C49095237998218F2", "hash_sha1": "950228195DC712E9E94F176518E4182F0F2911AF", "hash_sha256": "D651FD59887B01833F6434C3E7540CA0E3768E070DC986439355E981E92A110E", "hash_sha384": "DA12254A44BC702EB98C77CF2AD63C9E3E542274771BB926E2A21B6EE65F6CD5D01232779FF3612EE9FBF673351672DD", "hash_sha512": "6195341CD8115984AEDD4DFB853DA1BF1738DCD2E44CFF382F8135727AABB97BD4F7F0F2D3A88455956E1CA33E3D5F5A165670A03EDD21A39692C8E70FEFEA7B", "hash_ssdeep": "3072:LBxoaLVCKd0quj5hOl5MGIIC09CS0IIb6V+rpTfUd0/HlGJRA1f:/oow8xuj5hOkp0U6VELUdSGJRW", "hash_imp": "48D24FD6767DEDAF3D3F9B0CAA18321E", "hash_pesha1": "552F375AADBE1EF84AA2D31AF1E01F22AD1A6587", "hash_pe256": "9BA3F4822B31B5D60C99781EC34BA18270ED51235CDEAA31A0A868756D65E971", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Configuration Utility", "meta_original_filename": "msconfig.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d651fd59887b01833f6434c3e7540ca0e3768e070dc986439355e981e92a110e/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\msconfig.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\msconfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ], "runtime_window_title": "System Configuration" }, "msdt.exe-992C3F0CC8180F2F51156671E027AE75": { "file_name": "msdt.exe", "file_path": "C:\\Windows\\system32\\msdt.exe", "hash_md5": "992C3F0CC8180F2F51156671E027AE75", "hash_sha1": "942EC8C2CCFCACD75A1CD86CBE8873AEE5115E29", "hash_sha256": "6859D1B5D1BEAA2985B298F3FCEE67F0AAC747687A9DEC2B4376585E99E9756F", "hash_sha384": "9883706170D4AE0B7588859790F2743B1744BB601D31EE6055953777251D96F5FBC2BDA47B2F76F500783D955AA915D1", "hash_sha512": "1F1B8D39E29274CFC87A9EF1510ADB9C530086A421C121523376731C8933C6E234E9146310D3767CE888A8DCE7A5713221F4D25E5B7B6398D06AE2BE2B99EADF", "hash_ssdeep": "6144:DyDdIBWtP3soBExEjFsH/72/KRRYmKwsJ0ONA3lZf+/BrfMpBXqL/+7jGpys3Z/L:DmoLoexFz2CRlxbfgfOti4svB", "hash_imp": "3A1E8B78C984CDC6E669D871794AD160", "hash_pesha1": "6251DFF361951BFCBF348841AADD86C2D5663665", "hash_pe256": "624E67C8898E4D692DAF39272F68B60E0C233D997B08A1096285002A0DE2DF20", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Diagnostics Troubleshooting Wizard", "meta_original_filename": "msdt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/6859d1b5d1beaa2985b298f3fcee67f0aac747687a9dec2b4376585e99e9756f/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\msdt.exe.mui": "File", "(---) C:\\Users\\user\\AppData\\Local\\Temp\\msdtadmin\\_F25172B4-11C9-468B-BDF5-74913D94B483_\\inuse": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\msdt.exe.mun": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\msdt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll" ], "runtime_window_title": "An error occurred" }, "msdtc.exe-2EF846AC66E181BE820B513DBC15B5D2": { "file_name": "msdtc.exe", "file_path": "C:\\Windows\\system32\\msdtc.exe", "hash_md5": "2EF846AC66E181BE820B513DBC15B5D2", "hash_sha1": "8B4786EB9D864FC78BD99432AE0C78F887049461", "hash_sha256": "EDFE71025C352D0DABEC7B9506C5945BB0EC11F8DB540DB8CB1116C2EA1648A8", "hash_sha384": "BA601A97F69630626939298014FFCD764B0CF4D936A02814145BA18EE4A5EFCD55F699EDD2ECFDD5BC551C4548F65BE3", "hash_sha512": "2587ACD723F515EB8FA1DD7016647079FD7AF2A1C32F92FF344766803D524D9820BEBAF21DAA3B3D3556D2DB8AB956A8A1682EAA46ABB9B04A4C8E1E21321BDC", "hash_ssdeep": "1536:vOKf3ewElEA4yattFzRFZzi1A0a4qDLZAQcEzok3E8vroH3S7NtiXE/Lc:GNlOxzvv7fcmEAkyXiqc", "hash_imp": "51BA43624008AF885335F88516CA2AD3", "hash_pesha1": "A8A8101BC18379F31B40513A68B4834E7AC3D5EC", "hash_pe256": "22EA120BB10C430E58DB1EBC6BD51710705C1180C0E0182082FA90088662F410", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Distributed Transaction Coordinator Service", "meta_original_filename": "MSDTC.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/edfe71025c352d0dabec7b9506c5945bb0ec11f8db540db8cb1116c2ea1648a8/detection", "runtime_modules": [ "C:\\Windows\\system32\\msdtc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\MSDTCTM.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\system32\\MSDTCLOG.dll", "C:\\Windows\\system32\\MSDTCPRX.dll", "C:\\Windows\\system32\\MTXCLU.DLL", "C:\\Windows\\system32\\WINMM.dll", "C:\\Windows\\system32\\CLUSAPI.dll", "C:\\Windows\\system32\\XOLEHLP.dll", "C:\\Windows\\system32\\MSWSOCK.dll", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\system32\\CRYPTSP.dll", "C:\\Windows\\system32\\RESUTILS.dll" ] }, "msfeedssync.exe-C80939122EEC4C9583A521F673ED8DCC": { "file_name": "msfeedssync.exe", "file_path": "C:\\Windows\\system32\\msfeedssync.exe", "hash_md5": "C80939122EEC4C9583A521F673ED8DCC", "hash_sha1": "B9006DAF6092C3788C0BEF9568A66DD93AE54AD5", "hash_sha256": "D842C0AA333567D6B14A5F7429282652917A10B449BBAB8A79D7F4C4821A5D9F", "hash_sha384": "8CF439B72E2D5AE237C3221CEAEFB9505978EA7E7E37E0C3AA8D2B858EA23CAE895B55AE0DE9B7BAC91F366BAE9CB5AE", "hash_sha512": "76D6D8ADAAAAC72244A4116698A652027FF910FAF570A0BBBD79CE560EE01B615E6691B941605062A29B5FCD6B1017FEDFBF1750E3CCF9FE200736673D73A051", "hash_ssdeep": "192:aTRvrbsW2+9r8ZoT2U9NhZGFxAGGGZIW8XmMjQ+adCeeQtShWcs0:Otr2U8ZoLhQ2GNd82iaCQ0hWcs0", "hash_imp": "E4C2A510E7541CF3FA9C8202F4B88D97", "hash_pesha1": "8B435DD5617A264106533B26DBCCE6D9D306B80F", "hash_pe256": "08307ED0C28E8AA15ACDC9A7D90ED47F9AB233D8C383B38BED07008F97356762", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Feeds Synchronization", "meta_original_filename": "msfeedssync.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d842c0aa333567d6b14a5f7429282652917a10b449bbab8a79d7f4c4821a5d9f/detection", "runtime_modules": [ "C:\\Windows\\system32\\msfeedssync.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "msg.exe-B42553599E40029366A0FD8F81079BED": { "file_name": "msg.exe", "file_path": "C:\\Windows\\system32\\msg.exe", "hash_md5": "B42553599E40029366A0FD8F81079BED", "hash_sha1": "81EE73E59C1D612700761CAC931CD3013215DFB2", "hash_sha256": "2BDAB404DF6E4990BC1FD8F7464DBA325FB993C67E592BA1C5DC4F07C02A8E85", "hash_sha384": "D1BFDA7690FC0A289275DAA13EDEC0B75B3097B5E03F583F92ECD7269E582637189FE5D0828A72C2A08394FE26860B43", "hash_sha512": "379226EDD56B5BF109102BE5FB3B340DB92AE9E1B0DB9BAA2A21EBEBC4E5A15C8E37E79E04167A4CDCC9F875F34F22C8D74FF7AE2BFBFEFFD8D47697EB3C2B4C", "hash_ssdeep": "768:S8Wp08SpWHZNwhOvCB5fHP14PoxZ8qtLwGP:S8Wp08FHZ8nCstDP", "hash_imp": "CD3B5466F111A79E4AC06248B98E0B04", "hash_pesha1": "554191C216D0B4978BDD00B70A5DBDCB7601958C", "hash_pe256": "F421C05B5CBE096EBF4B940BE6F518FB5B5D40B381D455381BAD48E369429EDF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Message Utility", "meta_original_filename": "msg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2bdab404df6e4990bc1fd8f7464dba325fb993c67e592ba1c5dc4f07c02a8e85/detection", "output": "Send a message to a user.\r\n\r\nMSG {username | sessionname | sessionid | @filename | *}\r\n [/SERVER:servername] [/TIME:seconds] [/V] [/W] [message]\r\n\r\n username Identifies the specified username.\r\n sessionname The name of the session.\r\n sessionid The ID of the session.\r\n @filename Identifies a file containing a list of usernames,\r\n sessionnames, and sessionids to send the message to.\r\n * Send message to all sessions on specified server.\r\n /SERVER:servername server to contact (default is current).\r\n /TIME:seconds Time delay to wait for receiver to acknowledge msg.\r\n /V Display information about actions being performed.\r\n /W Wait for response from user, useful with /V.\r\n message Message to send. If none specified, prompts for it\r\n or reads from stdin.\r\n\r\n", "error": "Invalid parameter(s)\r\nSend a message to a user.\r\n\r\nMSG {username | sessionname | sessionid | @filename | *}\r\n [/SERVER:servername] [/TIME:seconds] [/V] [/W] [message]\r\n\r\n username Identifies the specified username.\r\n sessionname The name of the session.\r\n sessionid The ID of the session.\r\n @filename Identifies a file containing a list of usernames,\r\n sessionnames, and sessionids to send the message to.\r\n * Send message to all sessions on specified server.\r\n /SERVER:servername server to contact (default is current).\r\n /TIME:seconds Time delay to wait for receiver to acknowledge msg.\r\n /V Display information about actions being performed.\r\n /W Wait for response from user, useful with /V.\r\n message Message to send. If none specified, prompts for it\r\n or reads from stdin.\r\n\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\msg.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\msg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mshta.exe-0B4340ED812DC82CE636C00FA5C9BEF2": { "file_name": "mshta.exe", "file_path": "C:\\Windows\\system32\\mshta.exe", "hash_md5": "0B4340ED812DC82CE636C00FA5C9BEF2", "hash_sha1": "51C97EBE601EF079B16BCD87AF827B0BE5283D96", "hash_sha256": "DBA3137811C686FD35E418D76184070E031F207002649DA95385DFD05A8BB895", "hash_sha384": "3EE1B87540C45A9A7ADFEB7EAFD58345ECFB825B234A4D4F972B6C58672A4E7E0B6F45631C70271CD77FD173186236BE", "hash_sha512": "D9DF8C1F093EA0F7BDE9C356349B2BA43E3CA04B4C87C0F33AB89DDA5AFE9966313A09B60720AA22A1A25D43D7C71A060AF93FB8F6488201A0E301C83FA18045", "hash_ssdeep": "192:Mp2bLg8CB95kCfjmRXKbpkSprJ6AdgxYsPvWw5aIR:MpMLgdrkCjm9KZJAXWw5", "hash_imp": "DCDEE2FF2311B9AE7C4D768FA56524DD", "hash_pesha1": "239C222ED917E52236AC5433C2B79BE27541CA72", "hash_pe256": "7133CC2C07DFF02BAD91564682EDDF92DDE7BDCE42650581772B5B134A6A93A2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) HTML Application host", "meta_original_filename": "MSHTA.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/dba3137811c686fd35e418d76184070e031f207002649da95385dfd05a8bb895/detection", "runtime_modules": [ "C:\\Windows\\system32\\mshta.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "msiexec.exe-E5DA170027542E25EDE42FC54C929077": { "file_name": "msiexec.exe", "file_path": "C:\\Windows\\system32\\msiexec.exe", "hash_md5": "E5DA170027542E25EDE42FC54C929077", "hash_sha1": "5D6102F5A170E982C7735BFC2B9C1A0A0D435FD1", "hash_sha256": "0A8797D088023A7F17BB00B22FF7C91036070CCA561BFF5337C472313C0CB4AD", "hash_sha384": "D62B95D86AEB0095E4C25EADB801441D4359112E98BE94BCCF3A943C425DBDD5FDEEE80156CADFBC0F92982C28900F90", "hash_sha512": "C7595C3770D743229CEA4E56D0191535B92F280F98BDAD9C21606AACB7F4DCBEFEAB9BF8C22836059B56A4ABDB839ED7AAD2F855E34EFFBF508E392E9B4029A4", "hash_ssdeep": "1536:lxhjgDHJealHb0zdTC3wuzZ28Tx4rUbu60:la475TC37HTx4rd60", "hash_imp": "7B0965996CADE227105A63F975958C0D", "hash_pesha1": "1F0F81BC08DC6C3841B93041DF2BA6E54EA62E9A", "hash_pe256": "1A9CD80D9A3B739E908811ADE896002550377093D2451F17BFD6CF5E3813BAE6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows installer", "meta_original_filename": "msiexec.exe.mui", "meta_product_name": "Windows Installer - Unicode", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0a8797d088023a7f17bb00b22ff7c91036070cca561bff5337c472313c0cb4ad/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\msiexec.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\msimsg.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\msiexec.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll" ], "runtime_window_title": "Windows Installer" }, "msinfo32.exe-238137CD0CD9CC74F361BEBD0178F0E6": { "file_name": "msinfo32.exe", "file_path": "C:\\Windows\\system32\\msinfo32.exe", "hash_md5": "238137CD0CD9CC74F361BEBD0178F0E6", "hash_sha1": "54FDE7B6CC2F3A4E9B00916448172B92AB68FF3D", "hash_sha256": "68390551BC3BBC372AE64B5860DCBAC3E74866595F05577A7C19365384B5D6CB", "hash_sha384": "3698B4AF2BA5AB8E8122079D045322C952A03F3D1BFD48D8BF862CACE07BD15FF093F7BBFDC20A1C15C42FC71F65E1AC", "hash_sha512": "A7793C8B82AF66D9DBA1B4562B15E8E0ACC4E576547B509AB908C5AACBDC591D1C1046DA86AA625E8FB459A827AB81A6DC65C82A95C85D1BA5E8C7337448F3D9", "hash_ssdeep": "6144:oVzQSvqnSt7I+4DS3yrvJcwb+JgPkZEOHHrpm1XUZLxEZEOHHrpm1XUZLx:oVzQ1r+4VrhcwNPMtLpm1EwtLpm1E", "hash_imp": "6E6A036BD2DEF1FB34D19979D5B23ECB", "hash_pesha1": "571651568DDA05ADBBC78B5BEC20A88DD7436F6D", "hash_pe256": "33C04C087B17BBC72A1DBF3D0062F3739E6D82852055FD3574EA08320922161F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Information", "meta_original_filename": "msinfo.dll.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/68390551bc3bbc372ae64b5860dcbac3e74866595f05577a7c19365384b5d6cb/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\msinfo32.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\msinfo32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\ATL.DLL", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll" ], "runtime_window_title": "System Information" }, "mspaint.exe-4C99142651ABA7300AD7FFBB5BE2E81A": { "file_name": "mspaint.exe", "file_path": "C:\\Windows\\system32\\mspaint.exe", "hash_md5": "4C99142651ABA7300AD7FFBB5BE2E81A", "hash_sha1": "E6353CCD671ED8EEFFBB012D744A7E3B0C56BD81", "hash_sha256": "FDB5A84BF619CFDB6BBF6C88D657724574EC67393AFAD56443F0C173BF1AFEF5", "hash_sha384": "255FD4B958A5CF7F6C48A074E9AB53F9674E30C9D196A279346788D20C21A93B9CBF5269B746A2C577190007817661AF", "hash_sha512": "06B50F8BDB25E60DD7624DFAF7D89DB1404B30998C6AE3E77893BB1DE7948DF355FB2C8E42ED3F71D21A0AB781511C9C4B6EAE2362A4D92F7277B4720FCA9282", "hash_ssdeep": "24576:uxD4o8zPsAdQnDdEJ+OknWfYgoSlSoUM:/DGdERuq1lSoz", "hash_imp": "D90E4D192F94E7240C400DA8FC2154D7", "hash_pesha1": "F3EA4A503A35ECE39789B06A267CCFDB94978B2C", "hash_pe256": "68E78B6FD4E035C56278254B9F5B2132810D6FF19738A4CB0CA8AEE59AC422CC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Paint", "meta_original_filename": "MSPAINT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/fdb5a84bf619cfdb6bbf6c88d657724574ec67393afad56443f0c173bf1afef5/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\mspaint.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\debug\\WIA\\wiatrace.log": "File", "(R-D) C:\\Windows\\SystemResources\\mspaint.exe.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\UIRibbon.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\RotHintTable": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\mspaint.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\SYSTEM32\\AcGenral.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ], "runtime_window_title": "Paint" }, "msra.exe-F3D6337795EAC77A2834332A57DD0A24": { "file_name": "msra.exe", "file_path": "C:\\Windows\\system32\\msra.exe", "hash_md5": "F3D6337795EAC77A2834332A57DD0A24", "hash_sha1": "7D5F0D9F37EEC668415135CB11E32E01C497B351", "hash_sha256": "B2A4D4C2F7AF63557426E2AAE5CE287311CA1AD229398A095224C9F1A9A6999C", "hash_sha384": "5F73B7EAA1A4AEF538E4FE9A280E6F5D96C7FB107399EBD39317E4183EE764696414750FC5336391FB3E9AD0F5F33EDB", "hash_sha512": "17FA682E9B58653210BB531FB731874F22264F05033B2AD1D7AE4746B98EE26E447EECD530B43308FFB456347E0492FE88BCFEC0B7B6B91D8073B500EDEFC001", "hash_ssdeep": "6144:rPllwqmzOAOmNd50E5Bd+9AAtzK22jjNbCG53rBEeeOTdQQY9m78KO:rPMxC9AAtzGF1593iv", "hash_imp": "EC1A78EE235BD1B3D48A3A4A27ABA978", "hash_pesha1": "8ABD64D7F32FAC35C10EA46327262F04236BB5A0", "hash_pe256": "0E3DA5C9DEC34209B492E30F3586888A7B29285CC04C7F525B240F1455869AA1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Remote Assistance", "meta_original_filename": "msra.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b2a4d4c2f7af63557426e2aae5ce287311ca1ad229398a095224c9f1a9a6999c/detection", "runtime_window_title": "Windows Remote Assistance Help", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\msra.exe.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\msra.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\shcore.dll" ] }, "MsSpellCheckingHost.exe-4BFA84F46101446F6CD7516CE04C37B3": { "file_name": "MsSpellCheckingHost.exe", "file_path": "C:\\Windows\\system32\\MsSpellCheckingHost.exe", "hash_md5": "4BFA84F46101446F6CD7516CE04C37B3", "hash_sha1": "5A238AED7477BCD07A42831B7B8AA62F06F06411", "hash_sha256": "C3BC4B8C3E4BC49C6AE5F28DE4891FA946D0566160E2C47E3927DF4C9BAD0E41", "hash_sha384": "72281EE7930B27E98BF4083C710E1E1FC4F6C30B212010A4C670276A35CC96E3178333E064F43670B100738E061DF063", "hash_sha512": "90B5F54FA68E3D0CC10A64A720B2FF461A7A2F12C6227C8DCEB78C17B99279137BE5ED585E4816534D3F3DA70F426FF06F48C50A690E8441F708CF3872C22886", "hash_ssdeep": "1536:516b9VLrXr/+qbpDLhPD4k3RJRfmY53iDMj+V1sI/ZkbIEK6WApaly:Ej/qgpDxBJRfzd5+YI/ZJEK6WApal", "hash_imp": "98F31E1804CC8A05A90626F7AA65FBED", "hash_pesha1": "CD9A5F8AF231CA446E3D900900BF1886DA5FB2F6", "hash_pe256": "1A119833036894B47F5B229E75B548F92463CC1D6A4E3612B8BEE34DCE46B331", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Spell Checking Host", "meta_original_filename": "MsSpellCheckingHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c3bc4b8c3e4bc49c6ae5f28de4891fa946d0566160e2c47e3927df4c9bad0e41/detection", "runtime_modules": [ "C:\\Windows\\system32\\MsSpellCheckingHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "mstsc.exe-7F7D1971CFF5E9D15F33E8582E7E84FE": { "file_name": "mstsc.exe", "file_path": "C:\\Windows\\system32\\mstsc.exe", "hash_md5": "7F7D1971CFF5E9D15F33E8582E7E84FE", "hash_sha1": "19E960506C281EAEC4CB2986C07DC4B9812CDDC6", "hash_sha256": "5CE2BE81382FE4D759F0C4389972FBF508F5E9C8F06AAFA7333244006F5F2CBA", "hash_sha384": "4BAD8C76028ACC6A32124C49C1B657E670FA70284F3276494C6F72B2062DF5E1879A7FFE501140CA00E9E25F44D4CD01", "hash_sha512": "4A7CC87CB36E806DCAFAD72FF13C36B3F4538EB24B510C4545A310EA191637062007936332239E56963338AC94C70FF5F30CC25A8F9C20FA69EB1911824F77F0", "hash_ssdeep": "24576:aaynVLSkeJ7Et1vk61L873eor9GLiP8jGQhNhaDigqKSdxClrell1r3MJ6W2LVrM:DsVLSkeJ7Et1vk61LO3e+9HP8jGQhNhA", "hash_imp": "8ED9FD7812149E8C5396DE875FB2685E", "hash_pesha1": "110337C7D4D9C4897E33CF3BF21E80B7EE3C2117", "hash_pe256": "163E4111903887A5B7A53696605C79FDC3129B78D09F690755279337BDE176BD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Connection", "meta_original_filename": "mstsc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5ce2be81382fe4d759f0c4389972fbf508f5e9c8f06aafa7333244006f5f2cba/detection" }, "mtstocom.exe-963D599F73FE512DCAE1887C9FEDD346": { "file_name": "mtstocom.exe", "file_path": "C:\\Windows\\system32\\mtstocom.exe", "hash_md5": "963D599F73FE512DCAE1887C9FEDD346", "hash_sha1": "B3A3C22CE3B3560403407CF3F59D64368B457296", "hash_sha256": "66479FCA0DC380ECBD62BC55A75C2AB5B33FBF3D2119C47748FBF3A3DD3A0954", "hash_sha384": "C64E940B1C7518AB582A6FDCFF75316E88F32EFF5717253629E6AB63DFCACFCBF4DB00A86D3A9ADCA825214A0D339AC0", "hash_sha512": "47379A52E2844C3E76811234483FA5E1CC72005D18E8DF28907A56F0A312C8B3D4919DCE86E35D7EA734DF64F29B4266EF2CCF25CF956D681CB6FEEE41B158E0", "hash_ssdeep": "3072:JZ7Bi7yKamDD9ZDp+tvRUiR2yPCVExfa3uG0:vBcaOLp+tZtVqKxf6u", "hash_imp": "630A3A9AA7982CFD7A78DDCB919E831E", "hash_pesha1": "DD125583222AEEC6B6A914CF303CEEF03AA11740", "hash_pe256": "50A0406CC7EA7921EB833964C54A23861CDA695F69089CA800D76B5FB0325555", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+", "meta_original_filename": "MTSTOCOM.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/66479fca0dc380ecbd62bc55a75c2ab5b33fbf3d2119c47748fbf3a3dd3a0954/detection", "runtime_modules": [ "C:\\Windows\\system32\\mtstocom.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "MuiUnattend.exe-17647290E0458149D4AB206F6C77073F": { "file_name": "MuiUnattend.exe", "file_path": "C:\\Windows\\system32\\MuiUnattend.exe", "hash_md5": "17647290E0458149D4AB206F6C77073F", "hash_sha1": "59BA6F2E3B274A181393E3E134D70F07688529B6", "hash_sha256": "4D27F41FFDA9FBCC4347568CF184EF2065C77CB091CB14EEDCDDDCB575EAE343", "hash_sha384": "5E8747E3548563FB8EF1A7DE1984A9EC7EEBF5744D16D07A6A920FEF0786D1DCE1F6E9AD51209A10762D54C2EFF3F252", "hash_sha512": "4990F4F4F3FEC15BABB2A135FEAE00AFF7329E090092E2A1A7107C974E35CF8BDF9217E45947C97A1D5D6C135B939B15CE33ACD15C830040D240AF25ED73D3D4", "hash_ssdeep": "3072:qBANdz2bpENv4bT34dr+TztaP+KWhs0D5TsM:qmNdybpE14bT34dr+Tz0+7Ts", "hash_imp": "EAE9E5ED8E5388A1D64299459DF8B3CC", "hash_pesha1": "97C5E46AA1DFAE17FD2C7D78D78D91EB2DA4F0F5", "hash_pe256": "31714DEBB07F867366BD140B56D34E0439C890B51BB12B3BB9A45D59C0FCBCE7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MUI unattend action", "meta_original_filename": "MuiUnattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4d27f41ffda9fbcc4347568cf184ef2065c77cb091cb14eedcdddcb575eae343/detection", "runtime_modules": [ "C:\\Windows\\system32\\MuiUnattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "MultiDigiMon.exe-DF6AA1B1C7732809E42EC4B28738B813": { "file_name": "MultiDigiMon.exe", "file_path": "C:\\Windows\\system32\\MultiDigiMon.exe", "hash_md5": "DF6AA1B1C7732809E42EC4B28738B813", "hash_sha1": "498766636CEAB6C91326D2FB666F40FDB4A7D335", "hash_sha256": "AC37148D091BC02D24E40A1215AEB9A750EC10C48F7D709E4E1483E665677AB5", "hash_sha384": "19FF080B08F36FF50441C88150A3D476720397D0C179B1060AA0BC11FDF1984039E27BE86FC75DA53FE22904F7B18D8F", "hash_sha512": "94BDC1B0F2BF55ADDA532E6042FB34C91399A285184B5A0CE8BB80758BBBE23B400C5F56946545954BF1CC9F0BFCA0F4C9F381F906DD4B8EE1CFDF97A67080C2", "hash_ssdeep": "768:WtH7bnhiFP1vOKUJdkk9Ks+cJS2KVrrI16mi8kU18uqdfdh22C+BH7sFpCKcKP:I3M9XUs1ygrBU18ldfW2jbJK", "hash_imp": "E2B29DA5A898E5378D53FC923C78C72E", "hash_pesha1": "74A8DBFC0960350E85477B108348618612B6B85A", "hash_pe256": "D8353C4C7CD2430198DDBF1810F82B84B8003B1F4673D72C493837A68C171087", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Digitizer to Monitor Mapping Tool", "meta_original_filename": "MultiDigiMon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ac37148d091bc02d24e40a1215aeb9a750ec10c48f7d709e4e1483e665677ab5/detection", "runtime_modules": [ "C:\\Windows\\system32\\MultiDigiMon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "MusNotification.exe-BEA88BA2814FE7ADB1DE2DE6D4F0C997": { "file_name": "MusNotification.exe", "file_path": "C:\\Windows\\system32\\MusNotification.exe", "hash_md5": "BEA88BA2814FE7ADB1DE2DE6D4F0C997", "hash_sha1": "6D80F8D7B3BC3B15CDD0AF880410AA89C9D1B100", "hash_sha256": "E7E463B3F6C4EB898C1068B1D8BAF23CEA586115FB70846978CD513C017ECF64", "hash_sha384": "198A9795084C84905C57C19FBB1C4B74AFD478489E691E5D2BE482E59E06AD823BAF05BD4E19CDB0BC649D0163DA578E", "hash_sha512": "791F17307A91CBB719732D4B7BDC6BDD6A006100AFA81347EB648398E0DE56690A6A3A98BE6B6A6E0140B354408037F0DD7809D3990A28BC45B2D8A1AC2572CA", "hash_ssdeep": "12288:1EwGGYc7j9smGHutZI+U/7JQq5o0faq7T1QlsCXJ++bl:1JTY4j9smFtZNUD5oI/7xQl9J+", "hash_imp": "84FBBB6DBD1F54E54A52A927B24E8AC3", "hash_pesha1": "603576DCC654A8F4E9DB7E7D9ABA9B4316FDDA9A", "hash_pe256": "C1393891A820D5D9823F23C8AEA0C7BD8023167910FA07978D4BE0962B41C807", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MusNotificationBroker", "meta_original_filename": "MusNotification.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e7e463b3f6c4eb898c1068b1d8baf23cea586115fb70846978cd513c017ecf64/detection", "runtime_modules": [ "C:\\Windows\\system32\\MusNotification.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\UMPDC.dll", "C:\\Windows\\system32\\UpdatePolicy.dll", "C:\\Windows\\system32\\UPShared.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\profapi.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\system32\\WINHTTP.dll" ] }, "MusNotificationUx.exe-35C22877DAE5A3C90D2DEBCCD5C52454": { "file_name": "MusNotificationUx.exe", "file_path": "C:\\Windows\\system32\\MusNotificationUx.exe", "hash_md5": "35C22877DAE5A3C90D2DEBCCD5C52454", "hash_sha1": "45EAC6950901BC33407C4558619ECF5FE20B77AE", "hash_sha256": "EC8CF187BF1849F81FCE8C00DDA08FBB0C20FF75C8B7BE3D9DC07FDBC461C7CF", "hash_sha384": "68A178237777DC2EA01D38F69FDFEB26849E64D473C8AD5E1AA63FEF3715801FCE4A265664A3A6518FE71460B4D2CE39", "hash_sha512": "4667D724096CB3598653A2EDCBE7A904D36D5B0F254AEA2A061EE51BCBB9A143A38DCDEC94813E19F83BF2267D5555B17F24B34E8179B0FDC8C5E7E19CCB6563", "hash_ssdeep": "12288:eZIJt0cS5UrZYPS0Uqtk1IdQ7e/2W/fep:eZS0cj+y8k1O/26fe", "hash_imp": "11BB33ADB1CD8A9E92015368682D42D5", "hash_pesha1": "8EACC526C50574268DAF106C473D87FE208E2D0B", "hash_pe256": "319E47FB2DD20CBB9F3C5EFC41132C2C50ACB2D66937EE80FCE3F7F3C5826980", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MusNotificationUx.exe", "meta_original_filename": "MusNotificationUx.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ec8cf187bf1849f81fce8c00dda08fbb0c20ff75c8b7be3d9dc07fdbc461c7cf/detection", "runtime_modules": [ "C:\\Windows\\system32\\MusNotificationUx.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\advapi32.dll" ] }, "MusNotifyIcon.exe-543E22DE96FD5CD3713D68D7E4FCB7DB": { "file_name": "MusNotifyIcon.exe", "file_path": "C:\\Windows\\system32\\MusNotifyIcon.exe", "hash_md5": "543E22DE96FD5CD3713D68D7E4FCB7DB", "hash_sha1": "AA7246FAA81850DD29F7DEFD57317BCC0CF878A0", "hash_sha256": "3DD0A60A4E858AE1E71EF87F2797A7567E06150DFFDC841A0CD3ADE71802348D", "hash_sha384": "5CDE4B7C99F349926F30068DB8C6ECBD60FB87BAFACAFD39546AE00678F51C0AC6BDB8D4F976F4CCC07E738A16C5321E", "hash_sha512": "3B3BC439970D2F7C430F0F2989394366C44C813E6DFF14FF3A023976D3EEA0B825247346CCC6477CFF917A08DFD7FC562EF4C18713D129DDF14EF14EC78D7CBA", "hash_ssdeep": "6144:Zmdoh1Lkqc6YszTcq0q4UQ88mxnvSg1XD/QfCn/+IbpDK21g:MdiRcRszTT0kQvsn31XnpT", "hash_imp": "FA70CBC2965951C33EFC0CE42A40E4B5", "hash_pesha1": "AFB42ECE739B5997310AFEE1359BF8BA62CA4832", "hash_pe256": "55C7A10DC3268B5A5FBBD436DCBFE68172F3BF598AE6BAC6C1CFA9FDD00A5785", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MusNotifyIcon.exe", "meta_original_filename": "MusNotifyIcon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3dd0a60a4e858ae1e71ef87f2797a7567e06150dffdc841a0cd3ade71802348d/detection", "runtime_modules": [ "C:\\Windows\\system32\\MusNotifyIcon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\UPShared.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\WINHTTP.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\system32\\DPAPI.DLL" ] }, "Narrator.exe-DFE8232D6C8D204A74D8B6B174CA6002": { "file_name": "Narrator.exe", "file_path": "C:\\Windows\\system32\\Narrator.exe", "hash_md5": "DFE8232D6C8D204A74D8B6B174CA6002", "hash_sha1": "E74A83DB3C70292C899DBED934D8326862983D83", "hash_sha256": "5012F2AC4CA5A6F8D49F97015C1E6CAD6581979C386EC947BAB64E193C82E877", "hash_sha384": "C1BBC3F011C3EF1D14C6134A18DC2480A40A7A0671285F625522535A215F0F7EDD78997DBB401CEA49F0255047DC40CA", "hash_sha512": "3AE913B709ECD302F546ECE75CDED57FFFF9546FE9784FD4F1DBFEFE1C1A1F4D4EDFE80FAF769BF2AACB54FDF323F83722779FDF9E851055FBC821A3355C0F4A", "hash_ssdeep": "6144:Cta6N54lJ8jU6MP3O6OFPKVPoI1EYIaCIyX:2NkSw+6AKVPo/Y/CIy", "hash_imp": "9EFBF4DCAF4AA6EC250BEACF7D448D6E", "hash_pesha1": "C48022AA4689D7FAFE66E01203C2FC92A5E1D33A", "hash_pe256": "002F67457584DBBADE61A7DA78F76FB2BCB86B1E7A31C205F25DC9C1195D79A8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Screen Reader", "meta_original_filename": "SR.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5012f2ac4ca5a6f8d49f97015c1e6cad6581979c386ec947bab64e193c82e877/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\Narrator.exe.mui": "File", "(RW-) C:\\Windows\\System32": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\{8116BAA4-A182-4333-A165-6468E0517C6C}-Map-GLOBAL": "Section", "(R--) C:\\Windows\\Speech_OneCore\\Engines\\TTS\\en-US\\NUSData\\M1033David.keyboard.WVE": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\BaseNamedObjects\\{A78B032C-F564-4E8E-9995-0661714401C9}-Map-S-1-16-12288": "Section", "(R-D) C:\\Windows\\System32\\en-US\\SRH.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\System32\\en-US\\UIAutomationCore.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\iertutil.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Narrator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\UIAutomationCore.DLL", "C:\\Windows\\system32\\OLEACC.dll", "C:\\Windows\\System32\\SHELL32.dll" ] }, "nbtstat.exe-004091B8024936FF322C11CF370F2184": { "file_name": "nbtstat.exe", "file_path": "C:\\Windows\\system32\\nbtstat.exe", "hash_md5": "004091B8024936FF322C11CF370F2184", "hash_sha1": "8208FEE26D92E661A8F65A721B272AE931BC7692", "hash_sha256": "6210FA6ADE115DD07409CFAE21683B1772D6D3FDB6B438814CACBD3588DAD9E3", "hash_sha384": "0399A8DCA87CE46F532FD8986E0E3F606BCC4CB6C4C47DA3DCE7A8C41B35B28F0C2C481B25EF2F987BFD01AEC28783EA", "hash_sha512": "769D4B80F458E9CABD2EC016DF37C27D5CFF01AB21803D5193917DAFD95C90AC7044356D2745C6E19E9F4F86CBDEA052AE3025C73DF7D593DE8D43525F092DB6", "hash_ssdeep": "384:6snJtifh+JZdy1T0Lxh9/gZ3/2RtiJ5C2EGnArzJDmZWVrW:6uJtiUTcuxPNMzEGn3Y", "hash_imp": "207F3D1F113DEB58D9E4C6ACA8E0FA3F", "hash_pesha1": "54855AF5157C373C1A546177E9CAE748FB161D29", "hash_pe256": "F18B6B3D3D77B69A551C8EE40AF6C40A876C1E72D5C4B4FF487E53AA04F2EBF3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP NetBios Information", "meta_original_filename": "nbtinfo.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6210fa6ade115dd07409cfae21683b1772d6d3fdb6b438814cacbd3588dad9e3/detection", "error": "\r\nDisplays protocol statistics and current TCP/IP connections using NBT\r\n(NetBIOS over TCP/IP).\r\n\r\nNBTSTAT [ [-a RemoteName] [-A IP address] [-c] [-n]\r\n [-r] [-R] [-RR] [-s] [-S] [interval] ]\r\n\r\n -a (adapter status) Lists the remote machine's name table given its name\r\n -A (Adapter status) Lists the remote machine's name table given its\r\n IP address.\r\n -c (cache) Lists NBT's cache of remote [machine] names and their IP addresses\r\n -n (names) Lists local NetBIOS names.\r\n -r (resolved) Lists names resolved by broadcast and via WINS\r\n -R (Reload) Purges and reloads the remote cache name table\r\n -S (Sessions) Lists sessions table with the destination IP addresses\r\n -s (sessions) Lists sessions table converting destination IP\r\n addresses to computer NETBIOS names.\r\n -RR (ReleaseRefresh) Sends Name Release packets to WINS and then, starts Refresh\r\n\r\n RemoteName Remote host machine name.\r\n IP address Dotted decimal representation of the IP address.\r\n interval Redisplays selected statistics, pausing interval seconds\r\n between each display. Press Ctrl+C to stop redisplaying\r\n statistics.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\nbtstat.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ndadmin.exe-DFCF5A55C907ACED69415F871335DD3B": { "file_name": "ndadmin.exe", "file_path": "C:\\Windows\\system32\\ndadmin.exe", "hash_md5": "DFCF5A55C907ACED69415F871335DD3B", "hash_sha1": "6BC2FBD73C5A89CCD621CFC130735EA9274EEC1A", "hash_sha256": "E31A51CDC7CFD3924C2C259B78A5D5165E1EB708F20BE9806B5D400F76470EE9", "hash_sha384": "66D718EF43C3A3197CC28D71FE1C917B8CF9CF2DFAF526F3052607D681519262B461C576BFABF3FB340565DC2882DBEA", "hash_sha512": "943B5AF342467B2657010A8D34FFF57BA3AEE8F5FCC927A1F9250AB8D44D311AEDEF9DF39F05C2A6661F2634B160A018547BB136612352A05C18E2E528ED5FD9", "hash_ssdeep": "768:EEnF9lObTuBYzMbjrjQAhtqIrn8+1hrpFIUUUUUUUUUUUUqRcxM:d9lObT+YAPrjfFrGUUUUUUUUUUUU3+", "hash_imp": "3AED82C66B004C977279044836A79845", "hash_pesha1": "0B72792C053CB0502B594C1A247F4B17A9BBBB63", "hash_pe256": "BD187803B958BC22957CA730B4F735134CE6AFC89B17133B88F0C1676EB82180", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device driver software installation", "meta_original_filename": "NDAdmin.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e31a51cdc7cfd3924c2c259b78a5d5165e1eb708f20be9806b5d400f76470ee9/detection", "runtime_modules": [ "C:\\Windows\\system32\\ndadmin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "NDKPing.exe-5FC26E00B9012CC0188F65BB999174E9": { "file_name": "NDKPing.exe", "file_path": "C:\\Windows\\system32\\NDKPing.exe", "hash_md5": "5FC26E00B9012CC0188F65BB999174E9", "hash_sha1": "84B873DA341D53FBA671C10869F02AC8B8507E13", "hash_sha256": "E2E6EA04DB42F5ABD29C767681798B070A25B0768106689E36613B2E3A810170", "hash_sha384": "08298EF487B0BC404F1146D427947BD08D2FD5668A17A9FDA0284E4F3BFDD024CF466145849289AFFEDAAD09FD780295", "hash_sha512": "BE5EBF8E75808048357303DCDB6B908E8C8E64B15E3225256957B49E45E42E3216E693A43AAC9B6432E711F657366D6C091F86790D719A276E8D2AB445AE087F", "hash_ssdeep": "384:AuO3duY0GpGl3/gqnjpXi9iAK8HZeiKoWtl4t82foWYWWDD1IDBRJJuhKtklxt:TO3W02njIPei0tlg82fK9I1PG", "hash_imp": "74808FDE4CC6FD1DD43D82595ADDE0C9", "hash_pesha1": "635C66F3E314A0E8A0E4884666369B22223D6C93", "hash_pe256": "F04FC4ACD139370546AC8E8A80298CB994B39CFACCBF7874D45B6AA89FEE08CB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDMA Ping Cmd", "meta_original_filename": "RdmaPing.sys", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e2e6ea04db42f5abd29c767681798b070a25b0768106689e36613b2e3a810170/detection", "output": "NDKPing can run on a system as Server or Client.\r\nRun as a Server:\r\n\t -S -- Specify that the system will be a Server.\r\n\t -ServerAddr <ServerIPAddress>:<ServerPort> -- Specify ip address of the server and the port on which to listen in format of ipServer:portServer.\r\n\t -ServerIf <ServerInterfaceIndex> -- Specify the interface index for the server.\r\n\t -TestType <TestType> -- Specify the type of test to run.\r\n\t -W <Timeout> -- Specify the timeout of Server Listen socket, in seconds. If this parameter is not specified, will wait infinitely.\r\n\r\nRun as a Client:\r\n\t -C -- Specify that the system will be a Client.\r\n\t -ServerAddr <ServerIPAddress>:<ServerPort> -- Specify ip address of the server and the port on which to listen in format of ipServer:portServer.\r\n\t -ClientAddr <ClientIPAddress> -- Specify the ip address of the Client.\r\n\t -ClientIf <ClientInterfaceIndex> -- Specify the interface index for the Client.\r\n\t -LogFilename <LogFileName> -- Specify NDKPing test results log file name, relative path or full path.\r\n\t (Default: [systemdrive]\\NDKPingResults.log). On client side only.\r\n\t -A -- Specify that at client side NDKPing test results should be appended to the log file if it already exists.\r\n\t -V -- Specify that at client side NDKPing test results should be printed out on screen except being stored in a log file.\r\n\t -TestType <TestType> -- Specify the type of test to run.\r\n\r\nTestType Options: (Server and Client must be with same TestType)\r\n\t rping -- Tests RDMA connectivity with Send/Receive transfers and logs the status of each of them.\r\n\r\n\t Read/Write tests will be in future version!!! \r\n\r\nUsage Sample:\r\n\t As a Server:\r\n\t NDKPing -S -ServerAddr 10.10.10.10:55555 -ServerIf 3 -TestType rping -W 60 \r\n\t As a Client:\r\n\t NDKPing -C -ServerAddr 10.10.10.10:55555 -ClientAddr 10.10.10.11 -ClientIf 4 -TestType rping -LogFilename .\\NDKPingResults.log -V \r\n", "runtime_modules": [ "C:\\Windows\\system32\\NDKPing.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "net.exe-0BD94A338EEA5A4E1F2830AE326E6D19": { "file_name": "net.exe", "file_path": "C:\\Windows\\system32\\net.exe", "hash_md5": "0BD94A338EEA5A4E1F2830AE326E6D19", "hash_sha1": "88B101598CC6726B7A57D02B1FA95BE1B272A821", "hash_sha256": "9F376759BCBCD705F726460FC4A7E2B07F310F52BAA73CAAAAA124FDDBDF993E", "hash_sha384": "3A51B04C537B2B3BF3B123271E8C92AF250371F2EF83183A0B9839C59B02CCEECCFBBD18D30695F94849253A227E8C92", "hash_sha512": "2253820EE1E72340BB74D2BE721AC5064953E85527F3C396C763032D6C22248C623EB7D0CA2D33D8C866B628D19E2B4D2C45BD2966F55B9584DB97E56ED014B3", "hash_ssdeep": "1536:+CgeNgIVR1beQxaUa+tQFJuzY6z69q5ef3Rk1kDCtvGwgtZVmKtW:0egy1aQxaUa+tQTZq7kDCtvGwgtvmf", "hash_imp": "57F0C47AE2A1A2C06C8B987372AB0B07", "hash_pesha1": "E45D02C43E374DC208A150341893B87B3DA2EB8C", "hash_pe256": "F3DD2F47E8C2E85910263826C02E986ADCCD8AE78C0CABBDC7969913ED1E3E13", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Net Command", "meta_original_filename": "net.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/9f376759bcbcd705f726460fc4a7e2b07f310f52baa73caaaaa124fddbdf993e/detection", "error": "The syntax of this command is:\r\n\r\nNET\r\n [ ACCOUNTS | COMPUTER | CONFIG | CONTINUE | FILE | GROUP | HELP |\r\n HELPMSG | LOCALGROUP | PAUSE | SESSION | SHARE | START |\r\n STATISTICS | STOP | TIME | USE | USER | VIEW ]\r\n", "output": "The syntax of this command is:\r\n\r\nNET HELP\r\ncommand\r\n -or-\r\nNET command /HELP\r\n\r\n Commands available are:\r\n\r\n NET ACCOUNTS NET HELPMSG NET STATISTICS\r\n NET COMPUTER NET LOCALGROUP NET STOP\r\n NET CONFIG NET PAUSE NET TIME\r\n NET CONTINUE NET SESSION NET USE\r\n NET FILE NET SHARE NET USER\r\n NET GROUP NET START NET VIEW\r\n NET HELP\r\n\r\n NET HELP NAMES explains different types of names in NET HELP syntax lines.\r\n NET HELP SERVICES lists some of the services you can start.\r\n NET HELP SYNTAX explains how to read NET HELP syntax lines.\r\n NET HELP command | MORE displays Help one screen at a time.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\net.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "net1.exe-21C0AFE3CF5DE008014C7D6130A80C3D": { "file_name": "net1.exe", "file_path": "C:\\Windows\\system32\\net1.exe", "hash_md5": "21C0AFE3CF5DE008014C7D6130A80C3D", "hash_sha1": "20728995F03FA8FDCF66A2A848AB5405932A66C2", "hash_sha256": "F4CBB5284B2D0334A1F65060CBFFF1E382CA7A0C35E6BD4031710F301FF9816B", "hash_sha384": "AF3B74254053AB2F5CAB6C174D72D156E4F2E06DAC35CDE58DABC64C84265CA585848AECC0B86D7ACD2B569CE3944AC2", "hash_sha512": "EFC977889999C827BA17F23F39A8389ED675F5D5A45BF860DE002BBB82F638E1C37D66F96440CC9EA80F98B17BE93D55A0E051F21F75FE6151424FEBE341EE7F", "hash_ssdeep": "3072:V/25MVfzyevWl2irm+q4y/SVfoFTOoa3js/RJjnPr9WBWj+Yvvf4PMKzHq1VHRz:JOEiy+q4y/SVfyTpa3js/RJjnP56Wj+m", "hash_imp": "D115CDECBD7EB553182EAD3D45F5816C", "hash_pesha1": "D5FECFB007E6A5D945718CC17E197B2F6C7BB1C6", "hash_pe256": "45E8065BB6B9A4D2DDC0FB87EE4096E3A457C9109FD3CAD6C019C124F5105649", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Net Command", "meta_original_filename": "net1.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f4cbb5284b2d0334a1f65060cbfff1e382ca7a0c35e6bd4031710f301ff9816b/detection", "error": "The syntax of this command is:\r\n\r\nNET\r\n [ ACCOUNTS | COMPUTER | CONFIG | CONTINUE | FILE | GROUP | HELP |\r\n HELPMSG | LOCALGROUP | PAUSE | SESSION | SHARE | START |\r\n STATISTICS | STOP | TIME | USE | USER | VIEW ]\r\n", "output": "The syntax of this command is:\r\n\r\nNET HELP\r\ncommand\r\n -or-\r\nNET command /HELP\r\n\r\n Commands available are:\r\n\r\n NET ACCOUNTS NET HELPMSG NET STATISTICS\r\n NET COMPUTER NET LOCALGROUP NET STOP\r\n NET CONFIG NET PAUSE NET TIME\r\n NET CONTINUE NET SESSION NET USE\r\n NET FILE NET SHARE NET USER\r\n NET GROUP NET START NET VIEW\r\n NET HELP\r\n\r\n NET HELP NAMES explains different types of names in NET HELP syntax lines.\r\n NET HELP SERVICES lists some of the services you can start.\r\n NET HELP SYNTAX explains how to read NET HELP syntax lines.\r\n NET HELP command | MORE displays Help one screen at a time.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\net1.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "netbtugc.exe-FDB4E1CAB952959AF7CB2DE2D587FA0E": { "file_name": "netbtugc.exe", "file_path": "C:\\Windows\\system32\\netbtugc.exe", "hash_md5": "FDB4E1CAB952959AF7CB2DE2D587FA0E", "hash_sha1": "61E807277EEB87545259A00C1B5DAB487110AA77", "hash_sha256": "8C04F0F006F4B441B288CB1735DEC8A2396294FA75B4B027FFBD6A3256DE1DE1", "hash_sha384": "F328B1C4AF826050A166F305C7F3CFD389872F68701896B7C82D34FFF4BA7CD5E0FD5BDA832ACB06C440261E54C3C04E", "hash_sha512": "B157985ED0B2BEE58C12D8626DE1B0345A5702973959FB2B192B4EAAD9BAE88553A6E25E33C80EF5544B84FE8149C7D43A21EBF5CB7B5B5ED0FD00C0DA97C598", "hash_ssdeep": "384:8eCCnwITNe7QCY6dQ5Mebta4eOz7W8G0jWoskCzjDtmYmpivIpLSRXW/PFW:8NHIT6fbdIiO+Dtm78vI6k", "hash_imp": "ADD0F2FFF93DAD23E7A057CD8C646094", "hash_pesha1": "A8542BF192F6107137446D80EA01FA4E4B9B38C0", "hash_pe256": "2E495C5B822CED4E0C716E5836FC178A41DE2DC1CFC9CE7F63439C25182CCBC8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NetBT Unattend Generic Command", "meta_original_filename": "netbtugc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8c04f0f006f4b441b288cb1735dec8a2396294fa75b4b027ffbd6a3256de1de1/detection", "runtime_modules": [ "C:\\Windows\\system32\\netbtugc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "netcfg.exe-01504F3B8B252F5619C94FD65DC52842": { "file_name": "netcfg.exe", "file_path": "C:\\Windows\\system32\\netcfg.exe", "hash_md5": "01504F3B8B252F5619C94FD65DC52842", "hash_sha1": "864612BAA46728B9605A38262486AB4F4D36E1B0", "hash_sha256": "EAD06F5F5EB67FDF1CCB25511D6D7CA38DDD307B4499274886E04BEC53F1C76D", "hash_sha384": "8750352134C9820DC6BBD3E70175513D56BC83904BD80C937BA7134A28D8DBC9A43304DBDC7A91F3EB6EB0691009B2CC", "hash_sha512": "64CD48923524108C8E490C9EA5E6D629777E2BA3369841676148BF4844B22820311C82C9A0CCAFED3BFEA2921920572FBAD1C003272E20AE611B507E34F62DAE", "hash_ssdeep": "768:HDxQg9VbHv2PPCHM4OTJ0G/N1oUd8ONn3/UpgyQV2N5DyQzDM0cwft:HDKg/L2OMpZN1ocnPggy/DyyD9Tt", "hash_imp": "8A37733FD8C84A4AE8E86BE773288EE1", "hash_pesha1": "E5E884DF0FC5E02CA916A81EC478EF33D2C73A07", "hash_pe256": "5072A33F2C570F9A00E4B1FC46890DE69D7FF4C9108C10EB5311757201AABC14", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WinPE network installer", "meta_original_filename": "netcfg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ead06f5f5eb67fdf1ccb25511d6d7ca38ddd307b4499274886e04bec53f1c76d/detection", "output": "netcfg [-v] [-winpe] [-l <full-path-to-component-INF>] -c <p|s|c> \r\r\n -i <comp-id>\r\r\n \r\r\n -winpe installs TCP/IP, NetBIOS and Microsoft Client for Windows \r\r\n preinstallation environment\r\r\n -l\t provides the location of INF\r\r\n -c\t provides the class of the component to be installed (p == Protocol, \r\r\n s == Service, c == Client)\r\r\n -i\t provides the component ID\r\r\n\r\r\n The arguments must be passed in the order shown.\r\r\n\r\r\n Examples:\r\r\n \r\r\n netcfg -l c:\\oemdir\\myprot.inf -c p -i myprot\r\r\n \r\r\n Installs protocol 'myprot' using c:\\oemdir\\myprot.inf\r\r\n\r\r\n netcfg -c s -i MS_Server\r\r\n \r\r\n Installs service 'MS_Server'\r\r\n \r\r\nOR\r\r\n\r\r\nnetcfg [-v] -winpe\r\r\n\r\r\n Example:\r\r\n \r\r\n netcfg -v -winpe\r\r\n\r\r\n Installs TCP/IP, NetBIOS, and Microsoft Client for Windows \r\r\n preinstallation environment\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg [-v] -q <comp-id>\r\r\n\r\r\n Example:\r\r\n \r\r\n netcfg -q MS_IPX\r\r\n \r\r\n Displays if component 'MS_IPX' is installed\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg [-v] -u <comp-id>\r\r\n\r\r\n Example:\r\r\n\r\r\n netcfg -u MS_IPX\r\r\n\r\r\n Uninstalls component 'MS_IPX'\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg [-v] -s <a|n>\r\r\n\r\r\n -s provides the type of components to show (a == adapters, \r\r\n n == net components)\r\r\n\r\r\n Example:\r\r\n \r\r\n netcfg -s n\r\r\n\r\r\n Shows all installed net components\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg [-v] -b <comp-id>\r\r\n\r\r\n Example:\r\r\n\r\r\n netcfg -b ms_tcpip\r\r\n\r\r\n Shows binding paths containing 'MS_TCPIP'\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg [-v] -m\r\r\n\r\r\n Example:\r\r\n\r\r\n netcfg -m \r\r\n\r\r\n Outputs the binding map to NetworkBindingMap.txt in the current directory.\r\r\n -v will also display the binding map to the console.\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg -d\r\r\n\r\r\n Example:\r\r\n\r\r\n netcfg -d\r\r\n\r\r\n Performs a cleanup on all networking devices.\r\r\n\t\tThis will require a reboot.\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg -x\r\r\n\r\r\n Example:\r\r\n\r\r\n netcfg -x\r\r\n\r\r\n Performs a cleanup on networking devices, skipping those without physical\r\r\n object names.\r\r\n\t\tThis will require a reboot.\r\r\n\r\r\nGeneral Notes:\r\r\n -v\tRun in verbose (detailed) mode\r\r\n -?\tDisplays this help information\r\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\netcfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "NetCfgNotifyObjectHost.exe-8C417DD7B9DA72A182F24565BDBF3B3D": { "file_name": "NetCfgNotifyObjectHost.exe", "file_path": "C:\\Windows\\system32\\NetCfgNotifyObjectHost.exe", "hash_md5": "8C417DD7B9DA72A182F24565BDBF3B3D", "hash_sha1": "A477DB3E8BD9AEC6E778AF38CCE271C62EF3E67B", "hash_sha256": "87C9F1299BC80CF310F42F5639236101A42E2892C542AD43E86BB8C93A4B27B6", "hash_sha384": "5E705588D5B4EE1713A9E9595AE51A64D2CE68AC63BA57508551008071860E77FFB594DA5739FB56AD9EC1C4F215B46E", "hash_sha512": "05CCB5C2B74E82C5623AC4D059BF2E28FD75F456B2814423A39524D5C87D5A39977CA47E9A6468909B564A2FF49FC79481E9734BBAE2F830DD620579B11EC079", "hash_ssdeep": "1536:oC9MEZu7BzeMV3n79v5rE6sDtnr/euSxZceFt0PsUyTbJ/LF:BwzWpn7QceFt0Pszp/x", "hash_imp": "A1804A366C11F465BE3AF20494FA3303", "hash_pesha1": "11E1D9EBF7BB2B1AF663DADB5D2BF67BD6B9CD56", "hash_pe256": "48EB6339585266F724CF5FEF6FE9E3AA8E2D988A89E33C300E9580E346D729D8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Network Driver Configuration Plugins", "meta_original_filename": "NetCfgNotifyObjectHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/87c9f1299bc80cf310f42f5639236101a42e2892c542ad43e86bb8c93a4b27b6/detection", "runtime_modules": [ "C:\\Windows\\system32\\NetCfgNotifyObjectHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "NetEvtFwdr.exe-BC8AFFBBBB2B7235B206E948373B7D80": { "file_name": "NetEvtFwdr.exe", "file_path": "C:\\Windows\\system32\\NetEvtFwdr.exe", "hash_md5": "BC8AFFBBBB2B7235B206E948373B7D80", "hash_sha1": "72B2DB0543D7CC10B38C45286AA8D143C32E216D", "hash_sha256": "D0A85D5D71C08149325E4A2D34C5C42DE5505B2790A96880BF839B39F3CAC717", "hash_sha384": "DCBF84D79B40888732960E31F666DABA09BD16BDB456723118079BC0B8D5CDC684E30CB25CE4681C32834EF738692082", "hash_sha512": "C96D7AD2FC21A9D5799E9DC8D7642C54F1138673656932024DDD59CD2A9BF906920031293D76E9679EE4FDA412EAE6FAE8F9E7E2208238D2E58F99CC74D7BEEB", "hash_ssdeep": "384:2aaKgf1JAxnVAx4OQTDXzPX+YKP7RM4dzt3O6yeY0Hc1/FOIqscW//7F5kNYX7Uk:2TKeAwIP+rzAFd0an/Blobn0h/cx5", "hash_imp": "06F9D15B3947279143A7D5F4DC25306E", "hash_pesha1": "768CA63299566B819DA9BD364611E90974AB5198", "hash_pe256": "37F666CF9856FA975530A08C1F5B22D0388B3B4902E024E04BF824F7108F2221", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Forwarder", "meta_original_filename": "NetEvtFwdr.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/d0a85d5d71c08149325e4a2d34c5c42de5505b2790a96880bf839b39f3cac717/detection", "runtime_modules": [ "C:\\Windows\\system32\\NetEvtFwdr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "NetHost.exe-0C8BEC1C52FFA65CB36D21404E8F54DE": { "file_name": "NetHost.exe", "file_path": "C:\\Windows\\system32\\NetHost.exe", "hash_md5": "0C8BEC1C52FFA65CB36D21404E8F54DE", "hash_sha1": "2D97F07676F85C6D1A24B84164268C9AE9EB3DB9", "hash_sha256": "BA3426F2B9C5B657F38721BDF7AC3229804597544FF5F4096D9F858AD00C8A3D", "hash_sha384": "D653A5CE59C713314D8BE7D1D1860A3654BBE970BCFAB6D189FCDF2B2D89BC99D09CF93AE0C088DC4C9EA2C82B292C18", "hash_sha512": "B94AD801DB8F9BF9BDDFEE02DA4CBDE2587E0BA4C951C0DC9AF45CEDAAD7EDB3888B81C9A8E17438BEAF6502DD277EA4DE5847CA367B820F4479750E521850F2", "hash_ssdeep": "192:MG9pCGrh+bHyLDZV4/iZoypDrGysekf7WdEqW:7vCGd0HyXZuu5p3if7WdEqW", "hash_imp": "68873B7B30277427484800907F68E033", "hash_pesha1": "245DC263041E4AEB7C175684DC5BA06052E84D33", "hash_pe256": "65BDDF34BD83447FDDCB14EE8843921DBC97ECA2DD6CEE2B55FC0638B3F9F86F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EXE for configuring VPN proxy", "meta_original_filename": "nethost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ba3426f2b9c5b657f38721bdf7ac3229804597544ff5f4096d9f858ad00c8a3d/detection", "runtime_modules": [ "C:\\Windows\\system32\\NetHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "netiougc.exe-E57E5770F7FD571160F587C125D0A508": { "file_name": "netiougc.exe", "file_path": "C:\\Windows\\system32\\netiougc.exe", "hash_md5": "E57E5770F7FD571160F587C125D0A508", "hash_sha1": "EAD7D539E39CC732DC7968ECF9801AD1B854BF48", "hash_sha256": "62094BC03D7E5C88E06DF229CED53E8233E090225CB7401B7F548F5F60F3312E", "hash_sha384": "23BD0A9E6341AC7AAF3510B9C5082B90DB06B02FD3072ACCC0BA0BEC355257FAFB3FB623A23396A25F93B72C91E6EE1C", "hash_sha512": "ABC1E77094C09CA1AC0B2DD0B441D41194F5D3983CDE7634A95DF3491B8E0AE1BEB0E30A13B0CBD166D854CD25665A5E30542D74E9EED9052B582BE9DA2AAB53", "hash_ssdeep": "768:kMUoj7X652kyvkNyCrRpHvf1ZZWZRj/3hUpq:1dYPycNyYLtKX/ypq", "hash_imp": "DA6561132324AC4114296507CE0C85DB", "hash_pesha1": "74C69ED24095792D355A61B20660302DEE6A6C66", "hash_pe256": "36736B2F52A3B9CBB138BC69FD47A9C5915B69840E4B0B0AF3620D51A3144E42", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Netio Unattend Generic Command", "meta_original_filename": "netiougc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/62094bc03d7e5c88e06df229ced53e8233e090225cb7401b7f548f5f60f3312e/detection", "runtime_modules": [ "C:\\Windows\\system32\\netiougc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "Netplwiz.exe-520A7B7065DCB406D7ECA847B81FD4EC": { "file_name": "Netplwiz.exe", "file_path": "C:\\Windows\\system32\\Netplwiz.exe", "hash_md5": "520A7B7065DCB406D7ECA847B81FD4EC", "hash_sha1": "D1B3B046A456630F65D482FF856C71DFD2F335C8", "hash_sha256": "8323B44B6E69F02356A5AB0D03A4FC87B953EDCBD85C2B6281BF92BC0A3B224D", "hash_sha384": "041669B47B10ACBE04B2B5031073908022A2DF60DE0A0F10437D20E24DC298DA9C7BE2CBF5D959AB81C06C651E2317DE", "hash_sha512": "7AEA2810F38D1640D4AA87EFBBE20783FE7B8E7F588864A3A384A37C91108D906ABD89B235672608C98C46ED76DB2B0039462098A1064EBE4108EC37B6087914", "hash_ssdeep": "768:HCG9UkEMqenGsEzZZh8L2rdZTyflT0vKcMyK1AqfUrh6WeENiJDBPrxZt4p:i6nq3vp8cdlypa5MybNeWSDBPrxZap", "hash_imp": "33207161F1F01D54E759E316F16998D2", "hash_pesha1": "0DA11AAB39F54683F1BF8F4050A7B5E515D62116", "hash_pe256": "B9D92AD256970330A02864F767B26FB2714B02AF70ED7A33E5D0416475C8B6C4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Advanced User Accounts Control Panel", "meta_original_filename": "NETPLWIZ.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/8323b44b6e69f02356a5ab0d03a4fc87b953edcbd85c2b6281bf92bc0a3b224d/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\Netplwiz.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\netplwiz.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Netplwiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\NETPLWIZ.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "netsh.exe-6F1E6DD688818BC3D1391D0CC7D597EB": { "file_name": "netsh.exe", "file_path": "C:\\Windows\\system32\\netsh.exe", "hash_md5": "6F1E6DD688818BC3D1391D0CC7D597EB", "hash_sha1": "9184E64C36629A1DCEF084E19CC3E3BEF78F2D7B", "hash_sha256": "6B691B06FA865F52C9484EF4F10E2E02ED6D7C3A3F474B8B138A33AF7258B2A9", "hash_sha384": "74019373E67C55140F8E420FACCDC47311D23CB4A77DD47293E6999A6721B79EC9D0D4C0A16D6DA112299DBF5D49AB39", "hash_sha512": "92BB25170B96980CA688DE629220D0321BA3601F6396456BE462E432C5CE958D29DD52F728A7FA992B16F82D456F017809A9E9138E3C2608832469D0F007AF24", "hash_ssdeep": "1536:VwF6OfZyb85Gj8fgKoc43C3RagjPpr0HJ6HpfbFqgu9:VszRBGj8gKou38gjPp0p6HpTQge", "hash_imp": "90B4317BE51850B8EF9F14EB56FB7DDC", "hash_pesha1": "9E5648571DDF8849C0F2C51E7D756306088D00EE", "hash_pe256": "B91D3DA216D32ABA80D9B1F826E6B063E9A039033C3AB2485D117F77B616159A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Network Command Shell", "meta_original_filename": "netsh.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/6b691b06fa865f52c9484ef4f10e2e02ed6d7c3a3f474b8b138a33af7258b2a9/detection", "output": "\r\nUsage: C:\\Windows\\system32\\netsh.exe [-a AliasFile] [-c Context] [-r RemoteMachine] [-u [DomainName\\]UserName] [-p Password | *]\r\n [Command | -f ScriptFile]\r\n\r\nThe following commands are available:\r\n\r\nCommands in this context:\r\n? - Displays a list of commands.\r\nadd - Adds a configuration entry to a list of entries.\r\nadvfirewall - Changes to the `netsh advfirewall' context.\r\nbranchcache - Changes to the `netsh branchcache' context.\r\nbridge - Changes to the `netsh bridge' context.\r\ndelete - Deletes a configuration entry from a list of entries.\r\ndhcpclient - Changes to the `netsh dhcpclient' context.\r\ndnsclient - Changes to the `netsh dnsclient' context.\r\ndump - Displays a configuration script.\r\nexec - Runs a script file.\r\nfirewall - Changes to the `netsh firewall' context.\r\nhelp - Displays a list of commands.\r\nhttp - Changes to the `netsh http' context.\r\ninterface - Changes to the `netsh interface' context.\r\nipsec - Changes to the `netsh ipsec' context.\r\nlan - Changes to the `netsh lan' context.\r\nmbn - Changes to the `netsh mbn' context.\r\nnamespace - Changes to the `netsh namespace' context.\r\nnetio - Changes to the `netsh netio' context.\r\np2p - Changes to the `netsh p2p' context.\r\nras - Changes to the `netsh ras' context.\r\nrpc - Changes to the `netsh rpc' context.\r\nset - Updates configuration settings.\r\nshow - Displays information.\r\ntrace - Changes to the `netsh trace' context.\r\nwcn - Changes to the `netsh wcn' context.\r\nwfp - Changes to the `netsh wfp' context.\r\nwinhttp - Changes to the `netsh winhttp' context.\r\nwinsock - Changes to the `netsh winsock' context.\r\nwlan - Changes to the `netsh wlan' context.\r\n\r\nThe following sub-contexts are available:\r\n advfirewall branchcache bridge dhcpclient dnsclient firewall http interface ipsec lan mbn namespace netio p2p ras rpc trace wcn wfp winhttp winsock wlan\r\n\r\nTo view help for a command, type the command, followed by a space, and then\r\n type ?.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\netsh.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "NETSTAT.EXE-7FDDD6681EA81CE26E64452336F479E6": { "file_name": "NETSTAT.EXE", "file_path": "C:\\Windows\\system32\\NETSTAT.EXE", "hash_md5": "7FDDD6681EA81CE26E64452336F479E6", "hash_sha1": "C038069021CEA437AE40B421929E9D4D1A3440B3", "hash_sha256": "B094E827AF70241D71BED9767EC1A254FDC4164A646B2BA4C7105CD783ADBA0D", "hash_sha384": "FF4EE704245143A96F73EFD8E3D075BDDA71FA140302F66ADBEFC68E2BCE5A44C6685956F2A76903C8C2EC13E80A34B7", "hash_sha512": "9A7C50E83CA4575A46D574A2E148190CCEBDB6EEC1F6FB21A1F31418B3BE475B344F0D64E0F2EFE54184BBD4EFAC21BDF86E7EAA462D89DBB57342E25BEAE4E9", "hash_ssdeep": "768:TCLi37IWjyj54W/zRgU4lNE7FdM0XyPBSRFQiyAx:YWj3W/zRgU4C00XyPB4+iyY", "hash_imp": "F495C58FFEE3A623AD7AAA6BE78756D5", "hash_pesha1": "700D4C138948E43955E15F0E3BFD3EA7AE0F8C0B", "hash_pe256": "96E06301185D8F023657E57B8631F81C595718247109F02A3D56F63305382BD6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Netstat Command", "meta_original_filename": "netstat.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b094e827af70241d71bed9767ec1a254fdc4164a646b2ba4c7105cd783adba0d/detection", "error": "\r\nDisplays protocol statistics and current TCP/IP network connections.\r\n\r\nNETSTAT [-a] [-b] [-e] [-f] [-n] [-o] [-p proto] [-r] [-s] [-t] [-x] [-y] [interval]\r\n\r\n -a Displays all connections and listening ports.\r\n -b Displays the executable involved in creating each connection or\r\n listening port. In some cases well-known executables host\r\n multiple independent components, and in these cases the\r\n sequence of components involved in creating the connection\r\n or listening port is displayed. In this case the executable\r\n name is in [] at the bottom, on top is the component it called,\r\n and so forth until TCP/IP was reached. Note that this option\r\n can be time-consuming and will fail unless you have sufficient\r\n permissions.\r\n -e Displays Ethernet statistics. This may be combined with the -s\r\n option.\r\n -f Displays Fully Qualified Domain Names (FQDN) for foreign\r\n addresses.\r\n -n Displays addresses and port numbers in numerical form.\r\n -o Displays the owning process ID associated with each connection.\r\n -p proto Shows connections for the protocol specified by proto; proto\r\n may be any of: TCP, UDP, TCPv6, or UDPv6. If used with the -s\r\n option to display per-protocol statistics, proto may be any of:\r\n IP, IPv6, ICMP, ICMPv6, TCP, TCPv6, UDP, or UDPv6.\r\n -q Displays all connections, listening ports, and bound\r\n nonlistening TCP ports. Bound nonlistening ports may or may not\r\n be associated with an active connection.\r\n -r Displays the routing table.\r\n -s Displays per-protocol statistics. By default, statistics are\r\n shown for IP, IPv6, ICMP, ICMPv6, TCP, TCPv6, UDP, and UDPv6;\r\n the -p option may be used to specify a subset of the default.\r\n -t Displays the current connection offload state.\r\n -x Displays NetworkDirect connections, listeners, and shared\r\n endpoints.\r\n -y Displays the TCP connection template for all connections.\r\n Cannot be combined with the other options.\r\n interval Redisplays selected statistics, pausing interval seconds\r\n between each display. Press CTRL+C to stop redisplaying\r\n statistics. If omitted, netstat will print the current\r\n configuration information once.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\NETSTAT.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "newdev.exe-167BCF4327B033D2B9A4FAD661C12DD4": { "file_name": "newdev.exe", "file_path": "C:\\Windows\\system32\\newdev.exe", "hash_md5": "167BCF4327B033D2B9A4FAD661C12DD4", "hash_sha1": "2D14C11BA415CCEC0DCA30DCD8B3853C47B0245D", "hash_sha256": "DE9849562A31642DCE4C12683E7769D52C58B11C45B92186989DC5672C77BCCB", "hash_sha384": "4E68593A36358D81AFCD0021952C558EBDC39B49F27189086663DADDB5CD60095D38FAA72EF5485B7D1183146529485B", "hash_sha512": "75F97A317D1BB60E989B2E581E832D28146FAFB23AB39FEB90C5766A632F73CE4A8E02EA3F8F2FB24FC50E21D462B3DC1AF8884C80AB4948DCBE02B87EA1251D", "hash_ssdeep": "1536:uxXicfJw+ay02+G3CJfFrGUUUUUUUUUUUU3+:tcSz6+fJh", "hash_imp": "C601175EC89061A8970A843D93305533", "hash_pesha1": "F4162B6860EF1CB097CBE8CA02ACDEEE5476F7BA", "hash_pe256": "20C95C3134C19D40E839A4954AC644B9964464513856FA6FDD7D1C475C534D0B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device driver software installation", "meta_original_filename": "NewDev.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/de9849562a31642dce4c12683e7769d52c58b11c45b92186989dc5672c77bccb/detection", "runtime_modules": [ "C:\\Windows\\system32\\newdev.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll" ] }, "NgcIso.exe-353EAB0594FDC93348280EDCDA8E0495": { "file_name": "NgcIso.exe", "file_path": "C:\\Windows\\system32\\NgcIso.exe", "hash_md5": "353EAB0594FDC93348280EDCDA8E0495", "hash_sha1": "2682A00E2C1E238A7B5E20E2D77F9C20445557BC", "hash_sha256": "BEBC95D47863245293261DDD67D273665CD485AEE4DF8562FE35E421925EBC4E", "hash_sha384": "E8D4D9463F06F927EDAD8514F7D37B580AB577C811B9AD53EA6E2F6104A684FCBCEA4C9C94D77F2ACB7C369529114187", "hash_sha512": "4FD0993F97DE10DD4CEAF50D975CFA87D74742D4B5A1081ABB8B3ABC5DC3ABBA05A46AD6441E2658FF5F994C165049D01A41FEB4BF8910A66928BC948F276AC9", "hash_ssdeep": "6144:UwW5mHtL2ut479u4ADYDK2AwiA/+wGWclDQ8L3vmf+IYf:hW5OC79PZAwEbQgvd7f", "hash_imp": "52E843A0E7736840CDCE9B4887B92406", "hash_pesha1": "272C20403A37798BA62156AB6E2802761BE82209", "hash_pe256": "84BB7A48FD6EFA1D8C4485962D0AA79CDD5DDB2869ABA4F5326B837C41C1062F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Hello Security Process", "meta_original_filename": "NgcIso.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/bebc95d47863245293261ddd67d273665cd485aee4df8562fe35e421925ebc4e/detection", "runtime_modules": [ "C:\\Windows\\system32\\NgcIso.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\IumSdk.dll" ] }, "nltest.exe-0C96FBA0F1ABEEF164B077D34F5B6F6A": { "file_name": "nltest.exe", "file_path": "C:\\Windows\\system32\\nltest.exe", "hash_md5": "0C96FBA0F1ABEEF164B077D34F5B6F6A", "hash_sha1": "B76FA1640538A8B423750C9E2AD5BA286019DCB4", "hash_sha256": "171202183676B30C00B4D25438E64C565978B7DCF0DFC17A2F1990A237E7C11B", "hash_sha384": "E84CF415709D27EB6F0D3D7AF58D3F8621552116ADB2E5C1A39D1DE100B009903D20357C6689AB8378B6256165EF3DC7", "hash_sha512": "F441D563F55802E82EA4478F1D817F9CC838E861C236ACFEAC75D005F41042480B4DD55A05F7037C900AC8300C23C09DF0DBD1B92FB0021EB98D571C110E337B", "hash_ssdeep": "6144:rHaZvA73e4yxjpOMUoikXVVCvLKEWguyy6e8yAv:jdvyxjpEdX2jA", "hash_imp": "3C2F1E1F36E78E5E52A39C29EECFBF10", "hash_pesha1": "57E3B48435590C6F1EF837F951F3C9AF6858A758", "hash_pe256": "91288D25DE94B73AA2C832BD7DF36312A5407EC7979BBCF07750321C4CA9F350", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Logon Server Test Utility", "meta_original_filename": "nltestrk.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/171202183676b30c00b4d25438e64c565978b7dcf0dfc17a2f1990a237e7c11b/detection", "error": "Usage: nltest [/OPTIONS]\r\n\r\n\r\n /SERVER:<ServerName> - Specify <ServerName>\r\n\r\n /QUERY - Query <ServerName> netlogon service\r\n /REPL - Force partial sync on <ServerName> BDC\r\n /SYNC - Force full sync on <ServerName> BDC\r\n /PDC_REPL - Force UAS change message from <ServerName> PDC\r\n\r\n /SC_QUERY:<DomainName> - Query secure channel for <Domain> on <ServerName>\r\n /SC_RESET:<DomainName>[\\<DcName>] - Reset secure channel for <Domain> on <ServerName> to <DcName>\r\n /SC_VERIFY:<DomainName> - Verify secure channel for <Domain> on <ServerName>\r\n /SC_CHANGE_PWD:<DomainName> - Change a secure channel password for <Domain> on <ServerName>\r\n /DCLIST:<DomainName> - Get list of DC's for <DomainName>\r\n /DCNAME:<DomainName> - Get the PDC name for <DomainName>\r\n /DSGETDC:<DomainName> - Call DsGetDcName /PDC /DS /DSP /GC /KDC\r\n /TIMESERV /GTIMESERV /WS /NETBIOS /DNS /IP /FORCE /WRITABLE /AVOIDSELF /LDAPONLY /BACKG /DS_6 /DS_8 /DS_9 /DS_10\r\n /KEYLIST /TRY_NEXT_CLOSEST_SITE /SITE:<SiteName> /ACCOUNT:<AccountName> /RET_DNS /RET_NETBIOS\r\n /DNSGETDC:<DomainName> - Call DsGetDcOpen/Next/Close /PDC /GC\r\n /KDC /WRITABLE /LDAPONLY /FORCE /SITESPEC\r\n /DSGETFTI:<DomainName> - Call DsGetForestTrustInformation\r\n /UPDATE_TDO\r\n /DSGETSITE - Call DsGetSiteName\r\n /DSGETSITECOV - Call DsGetDcSiteCoverage\r\n /DSADDRESSTOSITE:[MachineName] - Call DsAddressToSiteNamesEx\r\n /ADDRESSES:<Address1,Address2,...>\r\n /PARENTDOMAIN - Get the name of the parent domain of this machine\r\n /WHOWILL:<Domain>* <User> [<Iteration>] - See if <Domain> will log on <User>\r\n /FINDUSER:<User> - See which trusted domain will log on <User>\r\n /TRANSPORT_NOTIFY - Notify netlogon of new transport\r\n\r\n /DBFLAG:<HexFlags> - New debug flag\r\n\r\n /USER:<UserName> - Query User info on <ServerName>\r\n\r\n /TIME:<Hex LSL> <Hex MSL> - Convert NT GMT time to ascii\r\n /LOGON_QUERY - Query number of cumulative logon attempts\r\n /DOMAIN_TRUSTS - Query domain trusts on <ServerName>\r\n /PRIMARY /FOREST /DIRECT_OUT /DIRECT_IN /ALL_TRUSTS /V\r\n /DSREGDNS - Force registration of all DC-specific DNS records\r\n /DSDEREGDNS:<DnsHostName> - Deregister DC-specific DNS records for specified DC\r\n /DOM:<DnsDomainName> /DOMGUID:<DomainGuid> /DSAGUID:<DsaGuid>\r\n /DSQUERYDNS - Query the status of the last update for all DC-specific DNS records\r\n\r\n /BDC_QUERY:<DomainName> - Query replication status of BDCs for <DomainName>\r\n\r\n /LIST_DELTAS:<FileName> - display the content of given change log file \r\n\r\n /CDIGEST:<Message> /DOMAIN:<DomainName> - Get client digest\r\n /SDIGEST:<Message> /RID:<RID in hex> - Get server digest\r\n\r\n /SHUTDOWN:<Reason> [<Seconds>] - Shutdown <ServerName> for <Reason>\r\n /SHUTDOWN_ABORT - Abort a system shutdown\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\nltest.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "notepad.exe-054F6E4419404C94F35888CEA6B4DE32": { "file_name": "notepad.exe", "file_path": "C:\\Windows\\system32\\notepad.exe", "hash_md5": "054F6E4419404C94F35888CEA6B4DE32", "hash_sha1": "FE48F836ED5264320F4C28E01A4225DC01329D11", "hash_sha256": "CA2837031952C32BC1639A416F5C2ADCEEBF33507D216E554A3B47B17C52E9B1", "hash_sha384": "5FC86291D631CC82FC2F03B9CEB6CF9C7004A180445BD8ACDA31A594376B3FB7325AD1BA448F41832BA683640F75E700", "hash_sha512": "F7B941B8351F1A8203AEE6D7794295AA2B111E0F609A0D07DED4CEC6651A7AD751F7623DF2B90862E4A47E1AD0D873E8D363A91954A78DEB181CFD62362B232A", "hash_ssdeep": "6144:vFbZ7SPu5J0DQ/zaQg56AOhB7ZrgeI5tT/fUWIzh:BZ75J0DQ/rg56Ae7ZMeI5C3t", "hash_imp": "4089A6EA56504C3C66D7744AC0A8131A", "hash_pesha1": "4E5100BFA9D55EF9B19982FD7C7B821ADFA549C9", "hash_pe256": "B5D7BBAA1245FF0507504B565B2C4ED4BBE3225A407705D2A20CD6598A15A4AB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Notepad", "meta_original_filename": "NOTEPAD.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ca2837031952c32bc1639a416f5c2adceebf33507d216e554a3b47b17c52e9b1/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\notepad.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\SystemResources\\notepad.exe.mun": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\notepad.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ], "runtime_window_title": "Untitled - Notepad" }, "nslookup.exe-F2E3950C1023ACF80765C918791999C0": { "file_name": "nslookup.exe", "file_path": "C:\\Windows\\system32\\nslookup.exe", "hash_md5": "F2E3950C1023ACF80765C918791999C0", "hash_sha1": "953726ECD156848921609201C97C51A50C0CF36C", "hash_sha256": "55AB032D256ADBE3FDE40CF90FE83BA5EAB591E04AD720161ED8E6EF059CA747", "hash_sha384": "4C9045F57205E36144FE02170E342186F7C66AF313F755179A138950248F8F9870A63D01EF561EAF26CFB01B95855FF3", "hash_sha512": "BAA7FB2385BD82D9A6A0A92FC41E2D26122154AA47199FE3AA9030FCAB1BF12D6B926AA27957B1F6E33A3FAF41B2B9F6B655104CB337928FF95BBF45D1A93E6E", "hash_ssdeep": "1536:Ono+AIqFL2Gl26Uk+n4vAyl4Ds6blmRbxOcxm:OnnAI3GJ+A5Kg6Re7m", "hash_imp": "2C6AC0BEC4117681BA25EAD3FABF0BA1", "hash_pesha1": "2B8DB26C180254210563F4AE5C79961A37DD8C86", "hash_pe256": "1C608BC89EA4B3DE01527027A7308662F99A1694FB66AD73C0B4F7C78F30EFFC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "nslookup", "meta_original_filename": "nslookup.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/55ab032d256adbe3fde40cf90fe83ba5eab591e04ad720161ed8e6ef059ca747/detection", "error": "Usage:\r\r\n nslookup [-opt ...] # interactive mode using default server\r\r\n nslookup [-opt ...] - server # interactive mode using 'server'\r\r\n nslookup [-opt ...] host # just look up 'host' using default server\r\r\n nslookup [-opt ...] host server # just look up 'host' using 'server'\r\r\n", "output": "Default Server: DESKTOP-IOOJLI7.mshome.net\r\nAddress: 172.26.224.1\r\n\r\n> ", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\nslookup.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\nslookup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ntoskrnl.exe-128034B59B7011ED13035550B6A88562": { "file_name": "ntoskrnl.exe", "file_path": "C:\\Windows\\system32\\ntoskrnl.exe", "hash_md5": "128034B59B7011ED13035550B6A88562", "hash_sha1": "FB9961E163E09B431C9FC347DEE28D26A5E50FC3", "hash_sha256": "ACEC36B1C1A3665CA16349A928B36F2F90335E4D1D385F7239AF2474D7AC25B9", "hash_sha384": "42E852EB15C8B44D97521D838D4BF44A032F3A8CC800AE65EB9F0B865EC48958245996D154E2AF0CC9EC893AF011BB40", "hash_sha512": "66EB8FAB35CF40C0EE65CA268F4E04716499421710218DE0D26CCD12C93567A8F1C1AD06718075E180198DCA687564DBBEDD1295D2E80CEA81588383FE7A7E56", "hash_ssdeep": "196608:6uFi6ixIuYIfjHjtPeZ6aiYmd++lWanDRkMMjN:6uU7xsmjHjtPew/Ymd+NO/Q", "hash_imp": "E0E869BBD92F59B58E146BA81EEE3F6D", "hash_pesha1": "8D4187A23AAE6D3B3364DDD532820305A6222EA2", "hash_pe256": "907C9422577F7A948F9B14C6A5F4261CA41AFFAF2CF784C1CEF371700F226D25", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NT Kernel & System", "meta_original_filename": "ntkrnlmp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.685 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.685", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/acec36b1c1a3665ca16349a928b36f2f90335e4d1d385f7239af2474d7ac25b9/detection" }, "ntprint.exe-6376E0AC71E2795B8924308C69641D31": { "file_name": "ntprint.exe", "file_path": "C:\\Windows\\system32\\ntprint.exe", "hash_md5": "6376E0AC71E2795B8924308C69641D31", "hash_sha1": "5755CD65CD7B79A97220A69BDA79801884DE7E56", "hash_sha256": "DA9C3C6745F1A186C3F2938F98EC5F8432058139607ACB6D684A4879881B6DF0", "hash_sha384": "085BE66C5CC74F5AB041343AE41E96C29D7D1B358F30DA15514AB2963A4FFC1A6C446E0837125ED458AF5394DF1EDE9B", "hash_sha512": "58FCF42D2F3398C82BC8C80D77962860B22EB7A894FA1ECC8F6A9EAE8259F4BF7A38F433E627C5BF3F1BBFFE8B19D2C68936530D5226EADF56ABACC14AF1C5B8", "hash_ssdeep": "768:BykF8JkZnr95vI1iQfCIWVM9G4qW4ne+S/ly+PKAoXRZX6fbX57UWkCRPPA7/Qn+:ByiWkJxVIPd4n+lbeRZIbSQPPA73", "hash_imp": "598CA250C4CE0ED92CFA650D081AD874", "hash_pesha1": "46E9B83684536A94D6A39316132FA532EA9E7B23", "hash_pe256": "C22429606BF3C98459EEF1A196733D1D5209FA3698F17E18275A0A20A0C4D248", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Printer driver software installation", "meta_original_filename": "ntprint.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/da9c3c6745f1a186c3f2938f98ec5f8432058139607acb6d684a4879881b6df0/detection", "runtime_modules": [ "C:\\Windows\\system32\\ntprint.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "odbcad32.exe-5A39C66F76F4629666BADC65370744FD": { "file_name": "odbcad32.exe", "file_path": "C:\\Windows\\system32\\odbcad32.exe", "hash_md5": "5A39C66F76F4629666BADC65370744FD", "hash_sha1": "6045F8797503004294FCE6E449C7D6FEDC24F2B4", "hash_sha256": "A7DE309D8A5A68FB4623D41914AB5F03D6FF7BB2E0B5927AFB402DA137BE6CA9", "hash_sha384": "DA830D48C35E245FC059341FB772D61B75ADA3C0B331226FF3F60A439DF1B55E93F29821285783CE528EEF564435FE4A", "hash_sha512": "6E61B6544C734875511C0B97391D96E4CAC638D5BC6136E995D6401119C66198E8C1BD44C3FFDB2BC1542ADD3E07580139C0FF1D21F489B870160FF63FBDC2F7", "hash_ssdeep": "1536:zm5ULWuR7Dytv3Jrz6q9EyYt9FlUIlbvBjIloW:1r7UUKI9jo", "hash_imp": "69FEEBD40FEB17DCC302C7A64D65BD53", "hash_pesha1": "A0EEF4621591D2A8D6DC15A99874CD10C87CA288", "hash_pe256": "DE584C88F3560D82189EEC445BDAE0D04AFE95BFE116E14D5F9E54658BB74871", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ODBC Administrator", "meta_original_filename": "odbcad32.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a7de309d8a5a68fb4623d41914ab5f03d6ff7bb2e0b5927afb402da137be6ca9/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\odbcad32.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\odbcint.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\odbcad32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll" ], "runtime_window_title": "Microsoft ODBC Administrator" }, "odbcconf.exe-7D7B705E462B7EAE1C4728064E5EFF1C": { "file_name": "odbcconf.exe", "file_path": "C:\\Windows\\system32\\odbcconf.exe", "hash_md5": "7D7B705E462B7EAE1C4728064E5EFF1C", "hash_sha1": "50D0ABDA40FC878682723BDAECC12D3974419429", "hash_sha256": "476346234300504CCCF360EF8172B4E07CCA59B43B7F09818B11B71210DF3481", "hash_sha384": "5876AB1D3FD483E7BB6565EC668FADF0D7FCA52BB935C066682508647E0C103469D2664082DA7600600D87E0674F6265", "hash_sha512": "745036FA0BDDE18E2302580C4EE0E95969D1C27F6F0741A95581A0C45F4946ED926D9F30D9D018308A4A3734A074C959DF51275C5A81FBE253D7F93BFC4A2779", "hash_ssdeep": "768:O3PYdy60y+LCmASNmMexDlqxCSl9NBid:9yry+LCmASNoxlqjlMd", "hash_imp": "09AE8655C843B33D7FA4CDD4F87AD0BF", "hash_pesha1": "4B4449F11177B18DA4FB9ACD258458A97AF61A92", "hash_pe256": "76AECFF9B1075695955082677F4F392D838627B8A6335E4160C9D5778EBF1035", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ODBC Driver Configuration Program", "meta_original_filename": "odbcconf.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/476346234300504cccf360ef8172b4e07cca59b43b7f09818b11b71210df3481/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\odbcconf.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\odbcconf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ], "runtime_window_title": "Invalid Parameter" }, "ofdeploy.exe-F09C49AD23CECE014B1244ED86CF5E3B": { "file_name": "ofdeploy.exe", "file_path": "C:\\Windows\\system32\\ofdeploy.exe", "hash_md5": "F09C49AD23CECE014B1244ED86CF5E3B", "hash_sha1": "D07C4CB8260E9D6EE2868F51D390A540A928DE73", "hash_sha256": "C82577866C274EAF4BC5B4876F0140ABE0E47A82DC49E9342416440497F0A045", "hash_sha384": "EFBE591FBFB537ED937EEB3BB269FD55C52576F8C719D9958D9732EA3EB0602C0896C284F14EC9F8DA3946C1FBADDB31", "hash_sha512": "243BB1A356D1D37ED12F63985E0BF777C00600374E60BD405D541E25EF866A1E85A2B8F6EB07179BA749E2E9A6607489189979974E36653BDF7F1C521C58C07A", "hash_ssdeep": "1536:iQNEPip/J7QlsI9gRO2pDh0DRgy3+sFssssv3WT+LdaWfwNc8:rEPC/tRO2pDWRdR33LdtwNc8", "hash_imp": "59D8EDDB0EFA26A12F88FAD57CBED731", "hash_pesha1": "199A8A44490C187F234FBBE33879F8B3282CB861", "hash_pe256": "D6D28449ABBA8BBA84A543BF1F2BEF4AB6B8405648E579E65FDCB78A671013C5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Office Deployment", "meta_original_filename": "OFDEPLOY.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/c82577866c274eaf4bc5b4876f0140abe0e47a82dc49e9342416440497f0a045/detection", "runtime_modules": [ "C:\\Windows\\system32\\ofdeploy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "omadmclient.exe-391AC654E003DA3F4916C2D9290732B6": { "file_name": "omadmclient.exe", "file_path": "C:\\Windows\\system32\\omadmclient.exe", "hash_md5": "391AC654E003DA3F4916C2D9290732B6", "hash_sha1": "D5C8847FA21B193581096F6DAAFBC4837F8A0ABD", "hash_sha256": "C81C43CD22F5985933FB5B4A734C0329C0134A740947C91C9F2199FA52B68784", "hash_sha384": "67CA0029EBCD262F560B78631CF16442DA4962F05279B59161E5D66DD224B1664B43B83E2A5C1AD2E9D1AB1E3D01FC34", "hash_sha512": "5FB13A1B194B9D658A8C351AEAE7F86109998A0A39BB2CDD5E8B203A7B75914D1809D3C07D9E7B11840F5F6BDECD5B584D60A3AE37567DCB9ED2A436D3C42292", "hash_ssdeep": "6144:5asSCK+In2MgTnAwSxI8i1dV7yRTqxAam71bGotz/fHcgKahq20n9ocUi+:59g+ieDL1dV2RGxIKoBP+R9ocn", "hash_imp": "90E14BC25835954BD4557FFA70888E60", "hash_pesha1": "271D6EC2D033348F8FA4273FCAB109494211294A", "hash_pe256": "28D947050061FC7D5992CF97DC4AA119C5287E743E4DF2E1590C12CBB235D455", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for OMA-DM Client", "meta_original_filename": "omadmclient.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c81c43cd22f5985933fb5b4a734c0329c0134a740947c91c9f2199fa52b68784/detection", "runtime_modules": [ "C:\\Windows\\system32\\omadmclient.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\coredpus.dll", "C:\\Windows\\system32\\CRYPTSP.dll" ] }, "omadmprc.exe-0C2094F5317EB0D8D5D1759F8C0D43EC": { "file_name": "omadmprc.exe", "file_path": "C:\\Windows\\system32\\omadmprc.exe", "hash_md5": "0C2094F5317EB0D8D5D1759F8C0D43EC", "hash_sha1": "238C97AF3A75A9A48DB4CB72326DEA29FC5E0984", "hash_sha256": "16DC4D82C9F77E82378226BA4DD9314F2A49FDBB6B0456FCDABA9182AA8C4AB0", "hash_sha384": "4569A00EBDB64D9C61B66C472D5969ADF2A2841783C8F9337D8DD902B032777AAA625035419CB46A4218F9A137995A2D", "hash_sha512": "F314470BA9CE51F2399E6165E4AB94717A171F7B9765B5D0D22C665D60CD02011438B84FD68F73F56E374B9FE1F73C575FA9EB820B9B4AEC73B0617840C38323", "hash_ssdeep": "1536:fuWEbAR0mVztOE/RTZSGFFJBmFIwRdH7y/+iTdTnia1Gomz5j1W7Nij0BTs:fGoBsQ9S8eFvdH7w+cdTniqjON1SiCTs", "hash_imp": "33B843B0DAF2BCAFE24F6EF6B08855DD", "hash_pesha1": "F8F491475F55930428B1A2CD167FC61BECB55A0A", "hash_pe256": "2521782150243CC50F68CEB3365B8F1C341F23435F4AC0F6DFA148A395386780", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Push Router Client of OMA-DM", "meta_original_filename": "omadmprc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/16dc4d82c9f77e82378226ba4dd9314f2a49fdbb6b0456fcdaba9182aa8c4ab0/detection", "runtime_modules": [ "C:\\Windows\\system32\\omadmprc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\system32\\DMPushProxy.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\system32\\iri.dll" ] }, "openfiles.exe-E9B42270F9D7C5F8F11C1FCCACDDA2B8": { "file_name": "openfiles.exe", "file_path": "C:\\Windows\\system32\\openfiles.exe", "hash_md5": "E9B42270F9D7C5F8F11C1FCCACDDA2B8", "hash_sha1": "03837335A68E92E907FD46CA3BB59094ABAE0081", "hash_sha256": "F559EB1DE240CC388D2D1B612D45B8AD962822783FCF36EC8C541ED0F29C9D48", "hash_sha384": "8E2C6043D94B324AC03C95F656B4F3CB84BC7485FE26A99B4DC9528E3794B61CEC8A2E1CEA400B7D7E92F88CB094A59D", "hash_sha512": "E47B20B7B71DB151FF0785194F5B68874E986E749A7CD294D4EC943D38961A29731163DFE0636906C108DE8CA08F634678BA6D1FDB0F5CEED6021237EA25DD6A", "hash_ssdeep": "1536:ZophSZFo1G6cxXw2Z01utNJCL3vwVy4GvJ482E69vP+f0Pz9nEPx4zF:ZoYh5ZUX3vyyZiC0zhEPxc", "hash_imp": "A7F4C437854AA08D24A43D35AF38A943", "hash_pesha1": "57EF9896CDAA266A6AF722175D496EA2E5451132", "hash_pe256": "890719FE4AF9C2D6537FECBCF9F9DEF5343DC720C3E7CCA1823DA903A00FC683", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays the current open files list", "meta_original_filename": "opnfiles.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/f559eb1de240cc388d2d1b612d45b8ad962822783fcf36ec8c541ed0f29c9d48/detection", "output": "\r\nOPENFILES /parameter [arguments]\r\n\r\nDescription:\r\n Enables an administrator to list or disconnect files and folders\r\n that have been opened on a system.\r\n\r\nParameter List:\r\n /Disconnect Disconnects one or more open files.\r\n\r\n /Query Displays files opened locally or from shared\r\n folders.\r\n\r\n /Local Enables / Disables the display of local open files.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n OPENFILES /Disconnect /?\r\n OPENFILES /Query /?\r\n OPENFILES /Local /?\r\n", "error": "ERROR: Invalid syntax.\r\nType \"OPENFILES /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\openfiles.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "OpenWith.exe-0234BF822C4D6070819403F1BEF37F14": { "file_name": "OpenWith.exe", "file_path": "C:\\Windows\\system32\\OpenWith.exe", "hash_md5": "0234BF822C4D6070819403F1BEF37F14", "hash_sha1": "09C4E44A4474C575F8478558064ABF72A39CC369", "hash_sha256": "E108BAC5A0D02952EA6B2EF4EAFDCB38017934525175E85BE70012D406476D22", "hash_sha384": "2F3A228959818E21A11496999AC34F5FD3A10E910EFA2080DE2B22294099DF236E80225A2D558E8E94E056926F3FA5BC", "hash_sha512": "064F643BDA82851ED95CDCF975DA3FEDA83392A00EE288C8CB87F3AFD88EFE4F92FF10C2117489561580D4160CFF89089EFC0F3D22F24300027DB87C3A4525F7", "hash_ssdeep": "1536:r6YmJompoZOQ76froDbm4g63Sj0QoBeAjEyPzumfKQTzBNer+CE+Ge+1PQM:796MDbuVoBeAhC6rer+CE+GHIM", "hash_imp": "4CDC00ED05B5E2753EAAEC1DEEF7901B", "hash_pesha1": "CEF635D927CFE05466C9038E388D1BB9CC9AE392", "hash_pe256": "EF8B572CEBA69062BA2A2732BC6CE10F35A62A21ED66B4D697B33AF7EC557D61", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Pick an app", "meta_original_filename": "OpenWith.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e108bac5a0d02952ea6b2ef4eafdcb38017934525175e85be70012d406476d22/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\OpenWith.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\SystemResources\\Windows.UI.Immersive.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\Windows.UI.Immersive.dll.mui": "File", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Windows\\SystemResources\\twinui.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\twinui.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "(RW-) C:\\Windows\\System32": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_32.db": "File", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(RWD) C:\\Windows\\Fonts\\seguisb.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\OpenWith.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHCORE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ] }, "OptionalFeatures.exe-D6CD8BEF71458804DBC33B88ACE56372": { "file_name": "OptionalFeatures.exe", "file_path": "C:\\Windows\\system32\\OptionalFeatures.exe", "hash_md5": "D6CD8BEF71458804DBC33B88ACE56372", "hash_sha1": "A18B58445BE2492C5D37ABAD69B5AA0D29416A60", "hash_sha256": "FA2E741416994F2C1BF9EF7A16B9C4DBF20C84267E3DA91AE6F1AD75EE9F49B8", "hash_sha384": "E9847725B7A6B7AD2B5D1715BC784A8005E79E658814ADB5B7F8DA15812D87732840041C22C50C27657F638FE25C3029", "hash_sha512": "1BED8AF2CF99A7F3BB36A34F4A71C34787904BD072ECDC731FB7498290DCF4024B956FB8B6912AD050B74AA861F0B0349081B77088F72732BDA5075413B1F83D", "hash_ssdeep": "3072:7EObbEaznWfH22ZsuX2xKwMPTnaSrIrvDx:75jznWjZnXeKwMLnaqY", "hash_imp": "B1DA23E5BF146552E38FA70DEE47601E", "hash_pesha1": "EDF63A3AC4A8CBEEC043AC071A2246730DE925C8", "hash_pe256": "F9CBD945413EBD7D5688FD3F9C48008F2CE9B871D952AB3C4D674BD340C7BCBC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Features", "meta_original_filename": "OptionalFeatures.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/fa2e741416994f2c1bf9ef7a16b9c4dbf20c84267e3da91ae6f1ad75ee9f49b8/detection", "runtime_modules": [ "C:\\Windows\\system32\\OptionalFeatures.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\appwiz.cpl", "C:\\Windows\\System32\\SHCORE.dll" ] }, "osk.exe-745F2DF5BEED97B8C751DF83938CB418": { "file_name": "osk.exe", "file_path": "C:\\Windows\\system32\\osk.exe", "hash_md5": "745F2DF5BEED97B8C751DF83938CB418", "hash_sha1": "2F9FC33B1BF28E0F14FD75646A7B427DDBE14D25", "hash_sha256": "F67EF6E31FA0EAED44BFBAB5B908BE06B56CBC7D5A16AB2A72334D91F2BB6A51", "hash_sha384": "E8BD7ADCEB80C997212654D1EE47EE169B353E76C7B9ACA08ED61D367CB7E183C18C6E961F50EC640CB8613108D4BDFB", "hash_sha512": "2125D021E6F45A81BD75C9129F4B098AD9AA15C25D270051F4DA42458A9737BFF44D6ADF17AA1F2547715D159FB621829F7CD3B9D42F1521C919549CC7DEB228", "hash_ssdeep": "6144:vjEuy1vvndibBecaV3ORc1OcvH3AdKy9HGeofJgDEvr6slnCUGw/xIRLtxIRLuoR:vHCv/dmBeV3OrjmNwzaoo", "hash_imp": "6AEB800FEEB9D418D3E47935AE3AB427", "hash_pesha1": "34FD6C75A406A40527A00EF99637D0C884123AB4", "hash_pe256": "8D30B06ACAB340243D6265EDFB352153B962584F720947A93C6CEB33E31EE870", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Accessibility On-Screen Keyboard", "meta_original_filename": "osk.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f67ef6e31fa0eaed44bfbab5b908be06b56cbc7d5a16ab2a72334d91f2bb6a51/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\System32\\en-US\\osk.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "(R-D) C:\\Windows\\System32\\en-US\\wdmaud.drv.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R--) C:\\Windows\\SKB\\LanguageModels\\lm.en.dat": "File", "(R--) C:\\Windows\\SKB\\LanguageModels\\lm.en-US.dat": "File", "(R--) C:\\Windows\\SKB\\LanguageModels\\lm.en-grammar.dat": "File", "(RW-) C:\\Windows\\System32": "File", "(R-D) C:\\Program Files\\Common Files\\microsoft shared\\ink\\en-US\\tipresx.dll.mui": "File", "(R-D) C:\\Program Files\\Common Files\\microsoft shared\\ink\\en-US\\tabskb.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\osk.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll" ], "runtime_window_title": "On-Screen Keyboard" }, "pacjsworker.exe-BE887110C3A171FD52CAF989976BD42E": { "file_name": "pacjsworker.exe", "file_path": "C:\\Windows\\system32\\pacjsworker.exe", "hash_md5": "BE887110C3A171FD52CAF989976BD42E", "hash_sha1": "140BB0FBA4361618064B3CE9E71C4ED3BE2A2733", "hash_sha256": "B706DF579959E10B50990643507D0B4DC241DAE5B3DB9EF844242AE74D16B4EF", "hash_sha384": "81212F7941D7118B0C5D2885352186BBAAD8BC4BB7BDBD4159CE790D9AFAC40CD4CC1C1DE34EB28F2122DA7DAC2B3562", "hash_sha512": "BBC4A12A025D2B5E7C6BAD63B70DBAC231DD8EE9EC423549E4ED0751B0770D8275124726C95E00447F4CC9C328AB20F506C1A9556E9F6E57A81233FBF9237EDC", "hash_ssdeep": "192:rydEJy/AuJgXEAVbDWt054vEQEWcLWaZAW:rlogXE0bCSOcLWaZAW", "hash_imp": "687E476BFD1F30A3D4393039D490BFCC", "hash_pesha1": "8B1645705DAF4E3D2015051C6D4D81FC6EC2935F", "hash_pe256": "21EA55F7430FC9B842F8B3E2DB112DE2C93A61F2284B0384D18F4870079BEA9B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "HTTP Auto Proxy Detection Worker Process", "meta_original_filename": "pacjsworker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/b706df579959e10b50990643507d0b4dc241dae5b3db9ef844242ae74d16b4ef/detection", "runtime_modules": [ "C:\\Windows\\system32\\pacjsworker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\WINHTTP.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "PackagedCWALauncher.exe-6D39751E14AF8E2FC2F87A31B7CA82F9": { "file_name": "PackagedCWALauncher.exe", "file_path": "C:\\Windows\\system32\\PackagedCWALauncher.exe", "hash_md5": "6D39751E14AF8E2FC2F87A31B7CA82F9", "hash_sha1": "86A2016F670F2FA0225136939EA7A80A631137F8", "hash_sha256": "C81F1F7A9FC42B2996B963FCC3D1F63ADEC73EC55B25E63FE351D43AA1D37DC6", "hash_sha384": "F86481929C57B3ABF8D4D74A8925B199C61196134B311F32B5919D071CC5C785077705424F2CFCA726450615815B54E9", "hash_sha512": "B4544435DDB84EB90EA24BEF2B2345C661220DC1219BFD48B9B3057426364E2F80DE321C41C156296469A6DEE8250056E24C2B6C08F7F55B579BA0116F8E1476", "hash_ssdeep": "768:rsg8AAfcjLNNme4VI0tTNxlRfz/CSbBxn7H5vZT8C9DlrbZSUu:NUqP4Vxt3lR+SNxn7H7T8C9Dx9SUu", "hash_imp": "85200C522AEECEDFF4551238547F8E74", "hash_pesha1": "1FBBB1A1291DB90A79EEC61201F2956A9A72EE45", "hash_pe256": "FB16A18241D805803AEA596529D3265F6254814142A748E7C0DF68DD4B293BC9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Packaged CWA Launcher", "meta_original_filename": "PackagedCWALauncher.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/c81f1f7a9fc42b2996b963fcc3d1f63adec73ec55b25e63fe351d43aa1d37dc6/detection", "runtime_modules": [ "C:\\Windows\\system32\\PackagedCWALauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "PackageInspector.exe-A128A0B6961768391516E71DB936E4E4": { "file_name": "PackageInspector.exe", "file_path": "C:\\Windows\\system32\\PackageInspector.exe", "hash_md5": "A128A0B6961768391516E71DB936E4E4", "hash_sha1": "148CC949EDD24D9227736C75A831DF2BE746A7C5", "hash_sha256": "ADF1880A66C7FFAB61F60DBB27145A0DCCBC7B7726AC750896FF2B7E79A31064", "hash_sha384": "2AA127F0872B36C818D38D2BFBDB436C53D56C8C7946FB5AA00F59FEA0104520BA61763D3987B9A288DEB6F62B06D4FF", "hash_sha512": "B60C0A5779D8A9FE69E124DA62EF8647940DF2BB916C5E644178290A1387040C5C017E33A4388A9677958253E2FD6A5E2132A77D322CBB3D3F3AB80FCD3A2502", "hash_ssdeep": "1536:fjzMGv33k2Ty2QepOaVc+wnZYeOfhAt6mhdFA+K7gAwS+EwAPJP9HUcn:fMI3U4Q7l+GZYe8AAm7y+K7gI+EwAPJb", "hash_imp": "4E095ADEBA5B01D1D9BE8EA1CB75A8BA", "hash_pesha1": "9CAAD71DAF7467E5752757D15AA261695CCE2E85", "hash_pe256": "8C508A38F06B3EEF4A2A665C60A855DC11D3B1B36C8AF2CCFD90714F3F4A01C4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PackageInspector allows creation of a catalog containing all executable files laid down by an installer", "meta_original_filename": "PACKAGEINSPECTOR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/adf1880a66c7ffab61f60dbb27145a0dccbc7b7726ac750896ff2b7e79a31064/detection", "output": "Usage:\r\r\nPackageInspector.exe <command> <DriveLetter or Path> [options]\r\r\nPackageInspector.exe start <DriveLetter>: [-path <pathToInstaller>]\r\r\nPackageInspector.exe stop <DriveLetter>: -out cdf|cat|list [-cdfPath <outputCdfPath>] [-name <nameOfCat>] [-resdir <directoryForCat>] [-ph true | false] [-en <encoding type>] [-ca1 <CATATTR1>] [-ca2 <CATATTR2>] [-listPath <pathToOutputList.txt>]\r\r\nPackageInspector.exe scan <PathToScan> -out cdf|cat|list [-cdfPath <outputCdfPath>] [-name <nameOfCat>] [-resdir <directoryForCat>] [-ph true | false] [-en <encoding type>] [-ca1 <CATATTR1>] [-ca2 <CATATTR2>] [-listPath <pathToOutputList.txt>]\r\r\n\r\r\nValid Commands : \r\r\n\tstart \t--\tSpecifies that a user will start a scan\r\r\n\tstop \t--\tSpecifies that a scan is complete and one of the supported outputs it to be produced\r\r\n\tscan \t--\tSpecifies that PackageInspector is to directly scan the given path rather than monitor created files. Takes same options as stop\r\r\n\r\r\nStart Options : \r\r\n\tpath \t--\tFile path to the package being inspected\r\r\n\r\r\nStop/Scan Options : \r\r\n\tout \t--\tSpecifies what the tool should output from the scan (CAT, CDF, or List)\r\r\n\tcdfPath \t--\tSpecifies the full path for output of CDF including filename\r\r\n\tname \t--\tSpecifies the name of the catalog to produce\r\r\n\tresdir \t--\tSpecifies the result directory of the catalog\r\r\n\tph \t--\tSpecifies whether page hashes should be included in the catalog\r\r\n\ten \t--\tSpecifies the encoding type of the catalog\r\r\n\tca1 \t--\tSpecifies CATATTR1 in the CDF or CAT\r\r\n\tca2 \t--\tSpecifies CATATTR2 in the CDF or CAT\r\r\n\tlistPath\t--\tSpecifies location to output list of files laid down by installer (for -out list)\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\PackageInspector.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "PasswordOnWakeSettingFlyout.exe-1A60CFC12F4501F7F63A4AE8224F1369": { "file_name": "PasswordOnWakeSettingFlyout.exe", "file_path": "C:\\Windows\\system32\\PasswordOnWakeSettingFlyout.exe", "hash_md5": "1A60CFC12F4501F7F63A4AE8224F1369", "hash_sha1": "E1267E08DD2DB8834B577FBAE50561FAAFFBC3CE", "hash_sha256": "B99A8DEFA04137A51AB4DA1A1C97F4209914BF0522827FA6CBDE18B0D4E3A406", "hash_sha384": "13AAB9C18493429D63386B0C2906732E29D46EEC60ECD2B618C376EB489F1AE7A5FD25F160465C0AAF4DC9F3C5F30D8A", "hash_sha512": "E1D04A9C6E44B0F5DDCACF065454301B755ED9888A8B5DA2C058F1D9003B1203A8FEE5B73F69B8FE5A5AD28E4375E3E18780EA923AED11CC3233713F66434A9E", "hash_ssdeep": "768:FZpQg3C4Vvp9ilGPYHJR4mKw5RczMKONXpCgCWax9QMPRCPPJMZWxXI1PSsB:fC4RilGiJR4mt0OhssSDPRCPGZeAPS+", "hash_imp": "EFBB2AE327C24AC043BA293919F6DEDD", "hash_pesha1": "243AF7AFD35053FFE0746469CDA55C87703A3CAD", "hash_pe256": "8F8E38F6B6F5A9C7A42C20F2FEE6142FAA92A2A8D75847B1E6BC2B1429065825", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "User CPL Password on wake setting flyout", "meta_original_filename": "PasswordOnWakeSettingFlyout.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b99a8defa04137a51ab4da1a1c97f4209914bf0522827fa6cbde18b0d4e3a406/detection", "runtime_modules": [ "C:\\Windows\\system32\\PasswordOnWakeSettingFlyout.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\DUI70.dll" ] }, "PATHPING.EXE-30A75901664FF9EB870B68D9364CEB8A": { "file_name": "PATHPING.EXE", "file_path": "C:\\Windows\\system32\\PATHPING.EXE", "hash_md5": "30A75901664FF9EB870B68D9364CEB8A", "hash_sha1": "83389DDDD22045B608F542BA075E46F16CFCA7C7", "hash_sha256": "348FB606016A1D9D7A1791A2FD561CF58B2B22165CF3C204FF9C541911078F59", "hash_sha384": "D39E3A660C51A6D8115A181013FCDEC24EB08BCE0CAC074BA5A189FE76B3BD20C18683BA6EE7F07523BD274C87E649C7", "hash_sha512": "2EF1DE3037B5EF64657CF08B93447FDCD33EAF699963C50C053E56698C952F4740F9AECD7C9B9D16149C41F4AFFB4952B146DB83A765A944B3823C596B6676F1", "hash_ssdeep": "384:3oRw9uj+d7UNlmEl8ZKrgdIhjSD30o+n/69m4L8SCv/WVAW:YRwgbBlDfSD30/6I4L84", "hash_imp": "527F94868035A5EFB9B24DFA6322F29D", "hash_pesha1": "C5723D35F785B603B280A3ECF8D40C65CBE4B6EF", "hash_pe256": "1EFD0ED7785CDCF04B54AAEC9537466115BB2616274836E3E51C0F8EC2203340", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP PathPing Command", "meta_original_filename": "pathping.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/348fb606016a1d9d7a1791a2fd561cf58b2b22165cf3c204ff9c541911078f59/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "output": "--help is not a valid command option.\r\n\r\nUsage: pathping [-g host-list] [-h maximum_hops] [-i address] [-n] \r\n [-p period] [-q num_queries] [-w timeout] \r\n [-4] [-6] target_name\r\n\r\nOptions:\r\n -g host-list Loose source route along host-list.\r\n -h maximum_hops Maximum number of hops to search for target.\r\n -i address Use the specified source address. \r\n -n Do not resolve addresses to hostnames.\r\n -p period Wait period milliseconds between pings.\r\n -q num_queries Number of queries per hop.\r\n -w timeout Wait timeout milliseconds for each reply.\r\n -4 Force using IPv4.\r\n -6 Force using IPv6.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\PATHPING.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "pcalua.exe-FDA12B6075B344B04FBD1B35B8D8B1E1": { "file_name": "pcalua.exe", "file_path": "C:\\Windows\\system32\\pcalua.exe", "hash_md5": "FDA12B6075B344B04FBD1B35B8D8B1E1", "hash_sha1": "F6FE1855DA595291593E2C68ECD889E68F2CE309", "hash_sha256": "E7049E16DBA743600F33A8DC5255507C7E212B119569DF5354605FE14A75E61B", "hash_sha384": "2AC32541C8BBD821FE3A18BD55D8C7713876DEB705F4F173C0D39EC3C26E0C10E5B442E1D26A977A04FF92FE777A9D09", "hash_sha512": "1E64057DE5B6328A366C8213F6619957E897A27E3E07C833EBF7397F2DF0D8985574730E13A71293F50BFB1265227C79C03E104BC5EF4F8239481773D46BA37B", "hash_ssdeep": "768:DGCafzyeq4PnN621EKlFMRU5LfMdcGap1k1acETfpkW9/2MWgKDogJ/5YTWZVjoJ:Oq416mbyo0CfnlTLKDR/5pV0J", "hash_imp": "5AD5C9412DDBD3C076272C60FA1FDD4C", "hash_pesha1": "FC1306978F6B3155A4C2B5E267AA326A07201A7E", "hash_pe256": "5FB6608DF5D4B0BD2D3C8FA3929481E152A85B6818E97A45138FBBCE0D86CF8A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Program Compatibility Assistant", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/e7049e16dba743600f33a8dc5255507c7e212b119569df5354605fe14a75e61b/detection", "runtime_modules": [ "C:\\Windows\\system32\\pcalua.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\pcaui.dll", "C:\\Windows\\system32\\apphelp.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ] }, "pcaui.exe-23487289A03FA0CB78C67FDD6D957D15": { "file_name": "pcaui.exe", "file_path": "C:\\Windows\\system32\\pcaui.exe", "hash_md5": "23487289A03FA0CB78C67FDD6D957D15", "hash_sha1": "EFC354E9509A9B726A322363C17BDBED180DC0C2", "hash_sha256": "3B853261A2B8353A0E985F5DD57667E0999AF659FA27D25E308EE9D2667EE607", "hash_sha384": "E4D9FCF43714A77A27D9E6666C2269B75859EC7B9F58B02DDEBC2073E35FD58E82CA7F80C136C8F6FA006E04AE6D3EAB", "hash_sha512": "0B885C3BFBCC5EAA2A81F71E5E236FE61E368A8FB017FFDB539AE6508E5930E1D23312672850FBC34B8527962A96E15A9654382F83DA7BB72DB9A54E88999437", "hash_ssdeep": "3072:YJ5vsVJfLOxVXo+i3IaXYoUlyZvC49gDpP0GerSq:YEfL8Xmj3UlyZvRr", "hash_imp": "73320C49F6F9013BE0C1814683FEDD50", "hash_pesha1": "7DC788E5B798E21C0B9433FB2ABE57C7FE8D2F31", "hash_pe256": "A3C016C0E366113B1DE1E4E608611C1B09C91E33FF6751CDAB592B43865E14AB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Program Compatibility Assistant User Interface", "meta_original_filename": "pcaui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3b853261a2b8353a0e985f5dd57667e0999af659fa27d25e308ee9d2667ee607/detection", "runtime_modules": [ "C:\\Windows\\system32\\pcaui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\apphelp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538\\gdiplus.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\system32\\pcaui.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "pcwrun.exe-5304FC0B26B34335369EAEDD7BB30E97": { "file_name": "pcwrun.exe", "file_path": "C:\\Windows\\system32\\pcwrun.exe", "hash_md5": "5304FC0B26B34335369EAEDD7BB30E97", "hash_sha1": "A194040DD88C66A6C61033A8BA8727E07C8200BC", "hash_sha256": "E3D136C667662A2198DA3D45A4637DF1EFE1F61B2B948F421FC0F8EEE6D83C3A", "hash_sha384": "A6417550886393FC9A9052BC5DF6F3447F1F28B9AED55116F3B21D83EBF5F00EDEE0BE1FAC2075E22E070FEDF8832100", "hash_sha512": "DE582402580A4D87E51AD992625024AC9E6E0E5CD9E4C88C2BFB5608F9DE99FB8BE037E055670BAEB71E2698E3E06CB017882FEF9D9963ED873E386FB39E8C8B", "hash_ssdeep": "384:9uqm53yj33csvrp6rThI/NfiiJoJ4fA+cWMgW:9+ij33cGrMrwNfiiJcOA+C", "hash_imp": "B78658A8BFA515AFA2CD46E53317253F", "hash_pesha1": "CAC074C20335A643C190F2E08B8B2E30C12DDC76", "hash_pe256": "792309C4B1874121DD841D2EA0400289FD40FE47DD84B23E4C464C51B4659B95", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Program Compatibility Troubleshooter Invoker", "meta_original_filename": "pcwrun.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/e3d136c667662a2198da3d45a4637df1efe1f61b2b948f421fc0f8eee6d83c3a/detection", "children": "msdt.exe", "runtime_modules": [ "C:\\Windows\\system32\\pcwrun.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ] }, "perfmon.exe-D38AA59C3BEA5456BD6F95C73AD3C964": { "file_name": "perfmon.exe", "file_path": "C:\\Windows\\system32\\perfmon.exe", "hash_md5": "D38AA59C3BEA5456BD6F95C73AD3C964", "hash_sha1": "40170EAB389A6BA35E949F9C92962646A302D9EF", "hash_sha256": "5F041CFF346FB37E5C5C9DAB3C1272C76F8B5F579205170E97D2248D04A4EA0C", "hash_sha384": "59C1DB08828A483F26E7A71A2019619DB9078603916195EC940611FFA0E6809A9F2F31BFE7EE9E926A204DE144EAECE0", "hash_sha512": "59FA552A46E5D6237C7244B03D09D60E9489217B4319A212E822C73FE1F31A81837CB906AE7DA92072BD3D9263FE0B967E073110BA81DA3A90126F25115FFF68", "hash_ssdeep": "3072:Y0fcuMXJEzBG8IPFThJRoGghtYIo9piswTogiqQKy349:hWZEzBG8SFNJWhqIo9s37iTK24", "hash_imp": "1B5EB71BEAEE7EFF37B32AE9FCEA653A", "hash_pesha1": "1B74F88D9CA76720ADE32799A162C9554ED2C301", "hash_pe256": "502976B205D5C385826BAE2034F577AE72F67B1F50F5B496BF4B1B3D3E2107F5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resource and Performance Monitor", "meta_original_filename": "perfmon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.00", "meta_product_version": "10.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/5f041cff346fb37e5c5c9dab3c1272c76f8b5f579205170e97d2248d04a4ea0c/detection", "output": "Argument '-help' is unknown.\r\n", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\perfmon.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\perfmon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ], "runtime_window_title": "Resource and Performance Monitor" }, "phoneactivate.exe-6E220F994F09387091CD1BCFA94F7B89": { "file_name": "phoneactivate.exe", "file_path": "C:\\Windows\\system32\\phoneactivate.exe", "hash_md5": "6E220F994F09387091CD1BCFA94F7B89", "hash_sha1": "E50F7FE14C7676378B7F3E23B03E29E94BFC51DD", "hash_sha256": "4325652E762C5BA53C48752373AA2ECA1CA0F91C19E826160FC9B195E1D5E70A", "hash_sha384": "99005B730A495752C35D05EB4D966E0D7106C8812A7C9D356093D64686EE9E444FDD2B61E2A63CEC31E3106DBDA79456", "hash_sha512": "2BD7EC2881063DDADE77A62F6AC0A046DA902F1615722EEE9F7C1324E3F7EB0881B121319D7E78A393A4832E041F25AD49ADFD7149BC741F18B1B935EA3FE637", "hash_ssdeep": "1536:/sZvXjZKYkNj0aiqlm/2WB/dT7j5vpEdkrE3vrWUg6niZA2tjyJVWPCl:UhFLCXtg/dSkrN6niW2Cgql", "hash_imp": "DA01ABA632042A34353C786F41878181", "hash_pesha1": "BC774D896B095DF4322EECFE204DE49393953169", "hash_pe256": "49922CCBD9BD33B3D3AF815B156AAAEFE554EED841D70185BCBE726D72C95B67", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Phone Activation UI", "meta_original_filename": "phoneactivate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4325652e762c5ba53c48752373aa2eca1ca0f91c19e826160fc9b195e1d5e70a/detection", "runtime_modules": [ "C:\\Windows\\system32\\phoneactivate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\Windows.UI.Immersive.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll" ] }, "PickerHost.exe-433A4A6A2205559EA3433FEF3F1DC9BB": { "file_name": "PickerHost.exe", "file_path": "C:\\Windows\\system32\\PickerHost.exe", "hash_md5": "433A4A6A2205559EA3433FEF3F1DC9BB", "hash_sha1": "C129B562FF29EAB4E79DE2EB29E149E858D32859", "hash_sha256": "2FE89DF706C2B56461D988C1E9B57C1C4FEF94353D4E2BF267A99A7EB63846BF", "hash_sha384": "F3C35FBAD5D296CE1027A1B23162020F0931AF508348F0660A3A223403012BEAF983F3326FD4C0E3A48F64F6697CF490", "hash_sha512": "69020852E40E0CB045818BD1EA6DB99E05EDFE9893D5F2471ED777A7C856CCA7581442A5B5245AE8FDF66EDB33903AE51BCC451E52006745FD8719A7C50A3106", "hash_ssdeep": "3072:uYcgSb1dwE5/GuOlHA+4Y4H3i+KHfasRcVwEEovx9L:unfwZg+4pH3iMsRswE/5d", "hash_imp": "C3DE8313F45360F43B3BF562DCAAF09E", "hash_pesha1": "7C39C38F7A29F76A36A4C8BD1C664939C615DAB6", "hash_pe256": "1B08518C43F546AB01BAE7B0A4A236601DE8C0102DD0A01882A70FFF99FE1E06", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Picker UI Host", "meta_original_filename": "PickerHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2fe89df706c2b56461d988c1e9b57c1c4fef94353d4e2bf267a99a7eb63846bf/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\PickerHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "PinEnrollmentBroker.exe-79C1AD1982EA7C57217FE2F691CDB619": { "file_name": "PinEnrollmentBroker.exe", "file_path": "C:\\Windows\\system32\\PinEnrollmentBroker.exe", "hash_md5": "79C1AD1982EA7C57217FE2F691CDB619", "hash_sha1": "F5F679ED4195971CE2E6B3B9BF40247824E794A2", "hash_sha256": "0031642ED03CA783BE44A6AB62702BC1F4AFE78C245B5B42DDC41D65155468A0", "hash_sha384": "413161A5BA74A6A798A9DCD8A91230FFFA19F155A25DB027C5A68A5A9ABA38B3B5D36ECC5AD2C61E6349AE1FE070B77C", "hash_sha512": "354A1D9346B3F67113DB6AB73DC4302545E4D6DC21AFBD21FECBA1E4C26724E3DDD0AD1D632438EAAA2600785F4595A9B25A7EA0401277ACE5C1D6F191011F9A", "hash_ssdeep": "3072:DFWpQoKnAF/nkFPGyuWOiUOvUfbEu+nBq+:D1tfAyuW30+nBq", "hash_imp": "036EFC6028ABEF34B1893EDD34FE70E9", "hash_pesha1": "64BEF05333F02444F2483CB5CF564556E5C45555", "hash_pe256": "27C279DCCE15C4B285B5FC38245E7A5EC5E85ED032A47CCEF8B7DDD473EE416A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PinEnrollmentBroker", "meta_original_filename": "PinEnrollmentBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/0031642ed03ca783be44a6ab62702bc1f4afe78c245b5b42ddc41d65155468a0/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\PinEnrollmentBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\PROPSYS.dll" ] }, "PING.EXE-2F46799D79D22AC72C241EC0322B011D": { "file_name": "PING.EXE", "file_path": "C:\\Windows\\system32\\PING.EXE", "hash_md5": "2F46799D79D22AC72C241EC0322B011D", "hash_sha1": "9C13C854A4EF98879D0CAB80EF679B4C4ECCF518", "hash_sha256": "7AF50FA112932EA3284F7821B2EEA2B7582F558DBA897231BB82182003C29F8B", "hash_sha384": "1016DCB1ADB5FD3CAD17D1B5B9DFF8758CB25452F8D599B15D429B8ADACE13FBAA4BCEC914965289438DCFC1EBA791FF", "hash_sha512": "D0274C6047A788F87ADEF7E125F65D80D0DFCDD54A00C0EF5AF22466E807802F2126C5DB2F61A419D71C8A323095116FB72A648413C38E17BA82F2C4394DEFF2", "hash_ssdeep": "384:Js9qZDngKcZhS6JLFULEg9PhayhN9dsv/45rJLQhW79WBlW:JsgZbgZZGa49snUrJLQ5", "hash_imp": "8C3BE1286CDAD6AC1136D0BB6C83FF41", "hash_pesha1": "CBE24B531CF9305D42D0A12A29124A4A319F2F21", "hash_pe256": "A59994BBF30A4C071F20F8E6AEED8AB606EC18CE87BD048FFAB98B43CC2B4F39", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Ping Command", "meta_original_filename": "ping.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7af50fa112932ea3284f7821b2eea2b7582f558dba897231bb82182003c29f8b/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "output": "Bad option --help.\r\n\r\nUsage: ping [-t] [-a] [-n count] [-l size] [-f] [-i TTL] [-v TOS]\r\n [-r count] [-s count] [[-j host-list] | [-k host-list]]\r\n [-w timeout] [-R] [-S srcaddr] [-c compartment] [-p]\r\n [-4] [-6] target_name\r\n\r\nOptions:\r\n -t Ping the specified host until stopped.\r\n To see statistics and continue - type Control-Break;\r\n To stop - type Control-C.\r\n -a Resolve addresses to hostnames.\r\n -n count Number of echo requests to send.\r\n -l size Send buffer size.\r\n -f Set Don't Fragment flag in packet (IPv4-only).\r\n -i TTL Time To Live.\r\n -v TOS Type Of Service (IPv4-only. This setting has been deprecated\r\n and has no effect on the type of service field in the IP\r\n Header).\r\n -r count Record route for count hops (IPv4-only).\r\n -s count Timestamp for count hops (IPv4-only).\r\n -j host-list Loose source route along host-list (IPv4-only).\r\n -k host-list Strict source route along host-list (IPv4-only).\r\n -w timeout Timeout in milliseconds to wait for each reply.\r\n -R Use routing header to test reverse route also (IPv6-only).\r\n Per RFC 5095 the use of this routing header has been\r\n deprecated. Some systems may drop echo requests if\r\n this header is used.\r\n -S srcaddr Source address to use.\r\n -c compartment Routing compartment identifier.\r\n -p Ping a Hyper-V Network Virtualization provider address.\r\n -4 Force using IPv4.\r\n -6 Force using IPv6.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\PING.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "PkgMgr.exe-9934CEF23769FA6D63A4330C45B13157": { "file_name": "PkgMgr.exe", "file_path": "C:\\Windows\\system32\\PkgMgr.exe", "hash_md5": "9934CEF23769FA6D63A4330C45B13157", "hash_sha1": "1132F9CECF5CE80B55CAB84D7DA3527EC354B503", "hash_sha256": "ADD78C9574CA3C5913BDE91097A2C9130125C7E09657E54E456C450117945C4A", "hash_sha384": "2353FE1774C597A76C68D61BEE5CE4921AA809FAF39EAB91CED096EF3CFD0407EA1A4078D81DB71B5775134E5C4C1A73", "hash_sha512": "E43D39A42B086442B4FD8C7276B4B65C22978909519D1AB9DD3FF25A6E0B93048CEAB55CC4D4E042F5EE1FD430C5664DE5542E2431FA4438DB9AFDFB17A36A2B", "hash_ssdeep": "6144:leHLzmyhGNXJl1hJ1ILeIi75S+MHxM8cG28x:lmLzmyhGNXJl1X1meI0NMHxM6n", "hash_imp": "F8D5056C8491474AE1BF8CC7382B98B0", "hash_pesha1": "CE25AC82860C737443C0300F2672A6A6D80BBD5A", "hash_pe256": "DEFD105B09EA0472979B649777F6214D2FCC5B0CE21555F99C22F25FA6EDDD52", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Package Manager", "meta_original_filename": "PkgMgr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/add78c9574ca3c5913bde91097a2c9130125c7e09657e54e456c450117945c4a/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\PkgMgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ], "runtime_window_title": "Windows Package Manager" }, "PktMon.exe-61EF1CC9374141C9FDD6A1C6C2A5CFD5": { "file_name": "PktMon.exe", "file_path": "C:\\Windows\\system32\\PktMon.exe", "hash_md5": "61EF1CC9374141C9FDD6A1C6C2A5CFD5", "hash_sha1": "A6588ACF9CE1FD85E37619C4E5B0003EF8AC19B4", "hash_sha256": "4714B03FFA5C666572A4AB6B04310A6CA654C3C1C68EDD3696088C238628BBB6", "hash_sha384": "E1A6907A1CAADEAF37D018209641C17A06ADBED8854548DF74AB19D41D73379537B3326078FC8BFA048F4952323C7041", "hash_sha512": "C64A8770AECE1D48B2D8FEAFCF8B4C2571769DE230BDADD99E5932D556896479021872B754BA37DFF5A985E7811D1542352F22DE06E752E2391C2CFFEAD4DBBB", "hash_ssdeep": "6144:479vuP6FiiJ33RyDqE2Hhpm5HVOFis83FKjQ0Auk//cYHJRF5JAiIN:Gc64iJnEDqE2HhpAHEis83sQ0AuuccJG", "hash_imp": "11E8AE0C5BCFD0E994EC39E1738B8D1B", "hash_pesha1": "30454E0D37CC435CF63EE94B140F5AC263FF2783", "hash_pe256": "B445FAC4CC816AC4F8A51A8E3E1F12C99AA4A89E209EE5E3347F5AA40C4BBE72", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Packet Monitor", "meta_original_filename": "PktMon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4714b03ffa5c666572a4ab6b04310a6ca654c3c1c68edd3696088c238628bbb6/detection", "output": "pktmon { filter | comp | reset | start | stop } [OPTIONS | help]\r\n Monitor internal packet propagation and packet drop reports.\r\n\r\nCommands\r\n filter Manage packet filters.\r\n comp Manage registered components.\r\n\r\n reset Reset counters to zero.\r\n start Start packet monitoring.\r\n stop Stop monitoring.\r\n format Convert log file to text.\r\n pcapng Convert log file to pcapng format.\r\n unload Unload PktMon driver.\r\n\r\nhelp\r\n Show help text for a command.\r\n\r\n", "error": "Unknown command '--help'. See pktmon \b help.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\PktMon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "plasrv.exe-9C338B7DD0916E2E282E15B385ED0716": { "file_name": "plasrv.exe", "file_path": "C:\\Windows\\system32\\plasrv.exe", "hash_md5": "9C338B7DD0916E2E282E15B385ED0716", "hash_sha1": "92B157CD2EF81C4649C491C4FC76C2422DCE45C6", "hash_sha256": "2D1C235DDC76D427C48C39C22E6DC50141F09734270EAF01778713F987E99CC4", "hash_sha384": "292A1C7F2736C5F2CD22FFF6B04ED1DD9EC06D1198C0CF2C778E410C1414288A654CC12488A2B76FB5C2DB39751167B8", "hash_sha512": "B34F659A85F9621FE75D087B8A9D502ECD600AD182863B134A071DC7877900CFBAD6A2C17FEC7DAF0B25891E9F66EDB8596B74860F2D745DC1046A72ACC71399", "hash_ssdeep": "192:F4tGfanJwH7XLc8B+Ps9nCuYgLrgdRFn5OW+XW:F4tLJwbXYq+U1YgPgNgW+XW", "hash_imp": "71297308FDB1BE310422F78B8E23F73C", "hash_pesha1": "98074B41AAD64CC5B31633D886377CD5E8717B7D", "hash_pe256": "AF4E7D29CD9FF88DAE11F1D17E29ACCDD872D502E36809419199A5F03893D736", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Performance Logs and Alerts DCOM Server", "meta_original_filename": "plasrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2d1c235ddc76d427c48c39c22e6dc50141f09734270eaf01778713f987e99cc4/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\plasrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\pla.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\USER32.dll" ] }, "PnPUnattend.exe-036FADF41AAD27390DC0C7C141F09F0C": { "file_name": "PnPUnattend.exe", "file_path": "C:\\Windows\\system32\\PnPUnattend.exe", "hash_md5": "036FADF41AAD27390DC0C7C141F09F0C", "hash_sha1": "833CD4B5934B41EE815DD4486386564C1294BE71", "hash_sha256": "DAAA6F8DFAFFDA95DCD17C30BEBD41A9C6F1B913EC37B34E0F137E35D5BA33A6", "hash_sha384": "E3C8B1E40B11FE4267062EE81EDC28669C5DA5B965D6F8D9F8C169A0C10A4040050526C86A8DBB829127E7ADD4A27562", "hash_sha512": "C9FF688BCD4CA21E3E577781CF21BF50201B5F0C455F9EFDF6413AB1B9788A956EB99DE8B44EBD5479315D20806D8600B31ED7A34B55EB5E054F9F853A908EBA", "hash_ssdeep": "1536:IrZgZdA+8KYh+uMeJVSPiDYd3Qk94nA5lA:9dq/h+PeJlkdp9E/", "hash_imp": "C932EE34DAB949E336FC1EEE748E7A12", "hash_pesha1": "99C87C3F89A1B4EAB15FA509BBE8D0F0880A31D7", "hash_pe256": "926B080B05F204B72372580F95E5A03C7CC37CEA0A4FC3DE27ADAEA3950A7F43", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PnP unattend action", "meta_original_filename": "PnPUnattend.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/daaa6f8dfaffda95dcd17c30bebd41a9c6f1b913ec37b34e0f137e35d5ba33a6/detection", "output": "DESCRIPTION:\r\r\nAuditSystem, Unattend online driver install \r\r\n\r\nUSAGE:\r\r\n PnPUnattend.exe [auditSystem | /help /? /h] [/s] [/L]\r\r\n auditSystem Online driver install.\r\r\n /help /? /h This help.\r\r\n /s Search without installing.\r\r\n /L Print Logging information to the command line.\r\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\PnPUnattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "pnputil.exe-A143EA998B2011E397CFE603F9D2C125": { "file_name": "pnputil.exe", "file_path": "C:\\Windows\\system32\\pnputil.exe", "hash_md5": "A143EA998B2011E397CFE603F9D2C125", "hash_sha1": "0E83DD7B28B049F9F7AF9242CE1C13DCE12E90E6", "hash_sha256": "008E3EF11D666D456902B267C192AAA57ADC69CA9B6680C6136043695BE5644B", "hash_sha384": "41910514FCC924E1196C5ACBC56CEF94407C2A7C704CA22B132AA6FA44F2373929A30AB4073E3EDCAC50CF791473A2AA", "hash_sha512": "DFE5DFED947C927C133F57A57A6615C9B2D38CB629CA9DC3D690A16B6A69D5641BA6888DE63F6E6372DA65A8BF0ED8091CA387BB4971321E0BF0D8D7FF82117B", "hash_ssdeep": "3072:Ybgw6wspDHtZN01HaJ3i71XnlU/PfAEKJYqjSYCjPHHUAuSGdY5BbAXaH/Px:Ybf6wADHd09aJ3UXnlbVSjPHpt9A+", "hash_imp": "16667493AA19EF905772DBF54729674D", "hash_pesha1": "E1A8ED19547D764660501D4B97FEE283B7998454", "hash_pe256": "366CA08F58262270978D3C0BE25DEA2EC5FF9EA15259DC2A9C8C8970815E155D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft PnP Utility - Tool to add, delete, export, and enumerate driver packages.", "meta_original_filename": "pnputil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/008e3ef11d666d456902b267c192aaa57adc69ca9b6680c6136043695be5644b/detection", "output": "Microsoft PnP Utility\r\n\r\nPNPUTIL [/add-driver <...> | /delete-driver <...> |\r\n /export-driver <...> | /enum-drivers |\r\n /enum-devices [<...>] | /enum-interfaces [<...>] |\r\n /disable-device <...> | /enable-device <...> |\r\n /restart-device <...> | /remove-device <...> |\r\n /scan-devices [<...>] | /?]\r\n\r\nCommands:\r\n\r\n /add-driver <filename.inf | *.inf> [/subdirs] [/install] [/reboot]\r\n\r\n Add driver package(s) into the driver store.\r\n /subdirs - traverse sub directories for driver packages.\r\n /install - install/update drivers on any matching devices.\r\n /reboot - reboot system if needed to complete the operation.\r\n\r\n Examples:\r\n Add driver package:\r\n pnputil /add-driver x:\\driver.inf\r\n Add multiple driver packages:\r\n pnputil /add-driver c:\\oem\\*.inf\r\n Add and install driver package:\r\n pnputil /add-driver device.inf /install\r\n\r\n /delete-driver <oem#.inf> [/uninstall] [/force] [/reboot]\r\n\r\n Delete driver package from the driver store.\r\n /uninstall - uninstall driver package from any devices using it.\r\n /force - delete driver package even when it is in use by devices.\r\n /reboot - reboot system if needed to complete the operation.\r\n\r\n Examples:\r\n Delete driver package:\r\n pnputil /delete-driver oem0.inf\r\n Force delete driver package:\r\n pnputil /delete-driver oem1.inf /force\r\n\r\n /export-driver <oem#.inf | *> <target directory>\r\n\r\n Export driver package(s) from the driver store into a target directory.\r\n\r\n Examples:\r\n Export driver package:\r\n pnputil /export-driver oem6.inf .\r\n Export all driver packages:\r\n pnputil /export-driver * c:\\backup\r\n\r\n /enum-drivers\r\n\r\n Enumerate all 3rd party driver packages in the driver store.\r\n\r\n Examples:\r\n Enumerate all OEM driver packages:\r\n pnputil /enum-drivers\r\n\r\n /disable-device <instance ID> [/reboot]\r\n\r\n Disable devices on the system.\r\n /reboot - reboot system if needed to complete the operation.\r\n\r\n Examples:\r\n Disable device:\r\n pnputil /disable-device \"USB\\VID_045E&PID_00DB\\6&870CE29&0&1\"\r\n\r\n /enable-device <instance ID> [/reboot]\r\n\r\n Enable devices on the system.\r\n /reboot - reboot system if needed to complete the operation.\r\n\r\n Examples:\r\n Enable device:\r\n pnputil /enable-device \"USB\\VID_045E&PID_00DB\\6&870CE29&0&1\"\r\n\r\n /restart-device <instance ID> [/reboot]\r\n\r\n Restart devices on the system.\r\n /reboot - reboot system if needed to complete the operation.\r\n\r\n Examples:\r\n Restart device:\r\n pnputil /restart-device \"USB\\VID_045E&PID_00DB\\6&870CE29&0&1\"\r\n\r\n /remove-device <instance ID> [/subtree] [/reboot]\r\n\r\n Attempt to remove a device from the system.\r\n /subtree - remove entire device subtree, including any child devices.\r\n /reboot - reboot system if needed to complete the operation.\r\n\r\n Examples:\r\n Remove device:\r\n pnputil /remove-device \"USB\\VID_045E&PID_00DB\\6&870CE29&0&1\"\r\n\r\n /scan-devices [/instanceid <instance ID>] [/async]\r\n\r\n Scan the system for any device hardware changes.\r\n /instanceid <instance ID> - scan device subtree for changes.\r\n /async - scan for changes asynchronously.\r\n\r\n Examples:\r\n Scan devices:\r\n pnputil /scan-devices\r\n\r\n /enum-devices [/connected | /disconnected] [/instanceid <instance ID>]\r\n [/class <name | GUID>] [/problem [<code>]] [/ids] [/relations]\r\n [/drivers]\r\n\r\n Enumerate all devices on the system.\r\n /connected | /disconnected - filter by connected devices or\r\n filter by disconnected devices.\r\n /instanceid <instance ID> - filter by device instance ID.\r\n /class <name | GUID> - filter by device class name or GUID.\r\n /problem [<code>] - filter by devices with problems or\r\n filter by specific problem code.\r\n /ids - display hardware IDs and compatible IDs.\r\n /relations - display parent and child device relations.\r\n /drivers - display matching and installed drivers.\r\n\r\n Examples:\r\n Enumerate only connected devices on the system:\r\n pnputil /enum-devices /connected\r\n Enumerate device with specific instance ID:\r\n pnputil /enum-devices /instanceid \"ACPI\\PNP0A08\\1\"\r\n Enumerate all devices with specific class:\r\n pnputil /enum-devices /class Display\r\n pnputil /enum-devices /class {4d36e97d-e325-11ce-bfc1-08002be10318}\r\n Enumerate all devices with specific problem code:\r\n pnputil /enum-devices /problem 28\r\n pnputil /enum-devices /problem 0xA\r\n Enumerate all devices with problems and display hardware/compatible IDs:\r\n pnputil /enum-devices /problem /ids\r\n\r\n /enum-interfaces [/enabled | /disabled] [/class <GUID>]\r\n\r\n Enumerate all device interfaces on the system.\r\n /enabled | /disabled - filter by enabled interfaces or\r\n filter by disabled interfaces.\r\n /class <GUID> - filter by interface class GUID.\r\n\r\n Examples:\r\n Enumerate only enabled interfaces on the system:\r\n pnputil /enum-interfaces /enabled\r\n Enumerate all interfaces with specific interface class GUID:\r\n pnputil /enum-interfaces /class {884b96c3-56ef-11d1-bc8c-00a0c91405dd}\r\n\r\n /?\r\n\r\n Show usage screen.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\pnputil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "poqexec.exe-78AE381E38249513E5AA3A9976DD16BE": { "file_name": "poqexec.exe", "file_path": "C:\\Windows\\system32\\poqexec.exe", "hash_md5": "78AE381E38249513E5AA3A9976DD16BE", "hash_sha1": "8CAE565DCA0AAEBED77D22B18ECD0857B81A8AB6", "hash_sha256": "B47E181B9ACA9EDE316CAE1CA6C50CE0ABD623994E4EB0DEECADC7C044F7E6A3", "hash_sha384": "C9F5F10AC46B127D70B09599689F3A464FB86E860D3BD6DD277C94788D9DC1302F1804E0BE0F68C64118CBD23F6F2143", "hash_sha512": "F1EBB350621F521B585BD817C01705546B731421A89CD763F1AC51312263F4BD77DA6CBD3E56F0E4D19189B7028414CD74F0F75A545276B5281179E44C3910D3", "hash_ssdeep": "12288:sa08Hr0ycItJ3KEoz8XQ1C+1TEpt9MpkFoxrInyH5fKl:w8HrPj3oymC4TGMGmxrL5S", "hash_imp": "BD47FF03174DF83245815823DFE013EC", "hash_pesha1": "E2A5AFBB073ECECAF262C8CD2F1F78DECA5E6E90", "hash_pe256": "548DC694F01C3B2FA9C4EFE49943E8A69B2A2DA0942ED311FFBC2B20B11EA27A", "signature_status": 2, "signature_status_message": "The file C:\\Windows\\system32\\poqexec.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Primitive Operations Queue Executor", "meta_original_filename": "poqexec.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b47e181b9aca9ede316cae1ca6c50ce0abd623994e4eb0deecadc7c044f7e6a3/detection" }, "pospaymentsworker.exe-7700A1F5ECACFB07A92C5960448AFAB8": { "file_name": "pospaymentsworker.exe", "file_path": "C:\\Windows\\system32\\pospaymentsworker.exe", "hash_md5": "7700A1F5ECACFB07A92C5960448AFAB8", "hash_sha1": "2547845243FF409F8FBC56474AE1D796B558F010", "hash_sha256": "43E3FCB7A777C62D02CB359452C488E114D8DA9F9FFA7854ECFB5CD236B9377F", "hash_sha384": "9448A49193C8E5CBDC6B52BB70853EDD0857E1357E309894B799E8D8AA07871ACC09012A7E46BB60D6387E1951F7B53D", "hash_sha512": "B8832E18B99065CB5BF251BC93E944033FF5BC50EA68120383EA51075A47C0D65C3506E2BFCEAABCECCD8F0D7E407EEE8327311D9A3534A85B422E4354754549", "hash_ssdeep": "768:QENcs7AUREojUerIG9HPLR4chodK5bYL6qEcloLgsP8VwcQJn97w9sGFeor:9nREojUerIG9xh75u6+TVwznF6TFeo", "hash_imp": "C06E0C121412B612B774C1FB7D21710A", "hash_pesha1": "481720CB23486C75590B80E06F4C2B7DA08ED122", "hash_pe256": "9350C55D53355F9438A50D9625E5DE7210A7D9277907D5D8548655D6B515422C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/43e3fcb7a777c62d02cb359452c488e114d8da9f9ffa7854ecfb5cd236b9377f/detection", "runtime_modules": [ "C:\\Windows\\system32\\pospaymentsworker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "powercfg.exe-9CA38BE255FFF57A92BD6FBF8052B705": { "file_name": "powercfg.exe", "file_path": "C:\\Windows\\system32\\powercfg.exe", "hash_md5": "9CA38BE255FFF57A92BD6FBF8052B705", "hash_sha1": "9ADB16A18ED1650F5F5A7E6BD83DBD3DFD1963E1", "hash_sha256": "CB2459971A56CEE45A30346281FF3B0ECCEA0C2BEE1AE6B8477712404D2E6AE1", "hash_sha384": "1CF1AB7D192FBF96726C5AC655A57E308AC2A4B27D18EB47795BB01417EBE7939053284E7FA42F0861E0F5A7ED55D4ED", "hash_sha512": "7746A3232C82C1C0850A7FC3507B872CB73E86E4C90E45F6B80855CB2509D9C0F824995E7DB0534816A424FC7D4DC414E98196BA664870E6B6741F1E2E268E68", "hash_ssdeep": "1536:IP++GkfoF8OF3R9Jz1+GidH27gYqXwkNUFmhBwU9LLVHhdeTdDze4yx34QvZj:I50b3R9JBZGuVqRN/wUhhB0Nzejv", "hash_imp": "158B4F23EB328627448C1E3FBBBD4079", "hash_pesha1": "B8BDD30CF29AB7BD354CA1BE2D5F3171943690B5", "hash_pe256": "71DA978AA49642D9D629193A3E6D2A3B426A12642838D6384D5F1D3FCDEBFE86", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Power Settings Command-Line Tool", "meta_original_filename": "PowerCfg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/cb2459971a56cee45a30346281ff3b0eccea0c2bee1ae6b8477712404d2e6ae1/detection", "output": "\r\nPOWERCFG /COMMAND [ARGUMENTS]\r\n\r\nDescription:\r\n Enables users to control power settings on a local system.\r\n\r\n For detailed command and option information, run \"POWERCFG /? <COMMAND>\"\r\n\r\nCommand List:\r\n /LIST, /L Lists all power schemes.\r\n\r\n /QUERY, /Q Displays the contents of a power scheme.\r\n\r\n /CHANGE, /X Modifies a setting value in the current power scheme.\r\n\r\n /CHANGENAME Modifies the name and description of a power scheme.\r\n\r\n /DUPLICATESCHEME Duplicates a power scheme.\r\n\r\n /DELETE, /D Deletes a power scheme.\r\n\r\n /DELETESETTING Deletes a power setting.\r\n\r\n /SETACTIVE, /S Makes a power scheme active on the system.\r\n\r\n /GETACTIVESCHEME Retrieves the currently active power scheme.\r\n\r\n /SETACVALUEINDEX Sets the value associated with a power setting\r\n while the system is powered by AC power.\r\n\r\n /SETDCVALUEINDEX Sets the value associated with a power setting\r\n while the system is powered by DC power.\r\n\r\n /IMPORT Imports all power settings from a file.\r\n\r\n /EXPORT Exports a power scheme to a file.\r\n\r\n /ALIASES Displays all aliases and their corresponding GUIDs.\r\n\r\n /GETSECURITYDESCRIPTOR\r\n Gets a security descriptor associated with a specified\r\n power setting, power scheme, or action.\r\n\r\n /SETSECURITYDESCRIPTOR\r\n Sets a security descriptor associated with a\r\n power setting, power scheme, or action.\r\n\r\n /HIBERNATE, /H Enables and disables the hibernate feature.\r\n\r\n /AVAILABLESLEEPSTATES, /A\r\n Reports the sleep states available on the system.\r\n\r\n /DEVICEQUERY Returns a list of devices that meet specified criteria.\r\n\r\n /DEVICEENABLEWAKE Enables a device to wake the system from a sleep state.\r\n\r\n /DEVICEDISABLEWAKE Disables a device from waking the system from a sleep\r\n state.\r\n\r\n /LASTWAKE Reports information about what woke the system from the\r\n last sleep transition.\r\n\r\n /WAKETIMERS Enumerates active wake timers.\r\n\r\n /REQUESTS Enumerates application and driver Power Requests.\r\n\r\n /REQUESTSOVERRIDE Sets a Power Request override for a particular Process,\r\n Service, or Driver.\r\n\r\n /ENERGY Analyzes the system for common energy-efficiency and\r\n battery life problems.\r\n\r\n /BATTERYREPORT Generates a report of battery usage.\r\n\r\n /SLEEPSTUDY Generates a diagnostic system power transition report.\r\n\r\n /SRUMUTIL Dumps Energy Estimation data from System Resource Usage\r\n Monitor (SRUM).\r\n\r\n /SYSTEMSLEEPDIAGNOSTICS\r\n Generates a diagnostic report of system sleep transitions.\r\n\r\n /SYSTEMPOWERREPORT Generates a diagnostic system power transition report.\r\n\r\n /POWERTHROTTLING Control power throttling for an application.\r\n\r\n\r\n", "error": "Invalid Parameters -- try \"/?\" for help\r\n", "runtime_modules": [ "C:\\Windows\\system32\\powercfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "PresentationHost.exe-EF27D65B92D89E8175E6751A57ED9D93": { "file_name": "PresentationHost.exe", "file_path": "C:\\Windows\\system32\\PresentationHost.exe", "hash_md5": "EF27D65B92D89E8175E6751A57ED9D93", "hash_sha1": "7279B58E711B459434F047E9098F9131391C3778", "hash_sha256": "17D6DCFACED6873A4AC0361FF14F48313F270AC9C465E9F02B5C12B5A5274C48", "hash_sha384": "9779F95F87B421BFDE816FA47AE7ED4EC520B3D3A28899B66893A2EDD4084D5B040B83E152704D3318F2D5DB821990B0", "hash_sha512": "40F46C3A131BB0388B8A3F7AEE422936F6E2AA8D2CDA547C43C4E7979C163D06C5AA20033A5156D3EEEE5D455EEB929CBCE89BCC8BB1766CBB65D7F03DD23E2E", "hash_ssdeep": "6144:nKzlwEJfWd1o8UmCz1Jf5KNXwy3Odjp19k5KNXf:nclwEyymCR3KVwy3OdLaKV", "hash_imp": "0F05A612CA776F9A937ECDE00BDB9592", "hash_pesha1": "8D88D1300FA7F6900B4BB6CBF6BAA54AB5AB9C0E", "hash_pe256": "B437E2F8A7406A36DB15FFFC00BFD6795341DC1ADBCCD2BE53C79849C19D5DA5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Presentation Foundation Host", "meta_original_filename": "PresentationHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/17d6dcfaced6873a4ac0361ff14f48313f270ac9c465e9f02b5c12b5a5274c48/detection", "children": "iexplore.exe", "runtime_modules": [ "C:\\Windows\\system32\\PresentationHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "PresentationSettings.exe-790799A168C41689849310F6C15F98FA": { "file_name": "PresentationSettings.exe", "file_path": "C:\\Windows\\system32\\PresentationSettings.exe", "hash_md5": "790799A168C41689849310F6C15F98FA", "hash_sha1": "A5D213FC1C71A56DE9441B2E35411D83770C01EC", "hash_sha256": "6E59AB1A0B4AC177DC3397A54AFCF68FCEA3C1EE72C33BD08C89F04A6DAC64B8", "hash_sha384": "11044442BFBC7F3488A51ACD5A99FE5748D66C1998072B584EF29F60C9FFDA60EBFF1ED281A8FE9D2EB988D4C657948E", "hash_sha512": "8153B79D4681F21ADE7AFE995841C386BFF8E491AD347F8E7C287DF5F9053CAE7458E273339146D9A920CEAA2BA0F41CC793D7B2C0FA80EFBB41477D39470866", "hash_ssdeep": "6144:rt0iOUEDwHulF8VC+LM6Ce9U7its2xmhfGKraEH:rtgUoUulW/Cr7p2Gfn", "hash_imp": "7B89FBC2ECACD3670D706A9372A38F83", "hash_pesha1": "865549BFF9397EBF4B3B1B38A903F75C8C74B5F9", "hash_pe256": "4E14878339BA87C39180326A8FBC81D3E4632CF51490B10B93FE6B8092FA2C30", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Mobile PC Presentation Adaptability Client", "meta_original_filename": "PresentationSettings.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) Microsoft. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/6e59ab1a0b4ac177dc3397a54afcf68fcea3c1ee72c33bd08c89f04a6dac64b8/detection", "children": [ "csrss.exe", "winlogon.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\PresentationSettings.exe.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\PresentationSettings.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll" ], "runtime_window_title": "Presentation Settings" }, "prevhost.exe-3F4A1B67F58ED77745EDA2D57BD47458": { "file_name": "prevhost.exe", "file_path": "C:\\Windows\\system32\\prevhost.exe", "hash_md5": "3F4A1B67F58ED77745EDA2D57BD47458", "hash_sha1": "A2C3E5B4EE3B422376A5DCF77D24C9D7B4DB6C09", "hash_sha256": "A5E77D6C2D343DA645ACC660D45B15ACAAFEFBD091A2F18A0C5137655D848026", "hash_sha384": "852F421C1B5EAE97AA2E4875EEBFDF9C339C5165C059D670993A1FD7ED6B2FF8FCCD1125EE82FC5EDF5301C84386A61A", "hash_sha512": "195E486776FE94499412803B08370CE0850CB9D1AB10033371E5DAD62B18A44EDE703C62B1B61113FFEC78C03DE1116BEADA6331496F8D5D7ACAB49FF81EC759", "hash_ssdeep": "768:dQTeTembVs9iswcQXD6VUPko7K24l4rjgTGQnPevyJSNtP:CTkhs9+c3OPKrl4vg6mmvywtP", "hash_imp": "14E7A56CE14DAD875047D7EC617BC003", "hash_pesha1": "4D71F6BA61D36C2104582BEA1FEB18903AD059C4", "hash_pe256": "8C37E053AC242E750B8281B10BE9A029FCBAE23403B2719B1370E6EC74D757A3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Preview Handler Surrogate Host", "meta_original_filename": "PREVHOST.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a5e77d6c2d343da645acc660d45b15acaafefbd091a2f18a0c5137655d848026/detection", "runtime_modules": [ "C:\\Windows\\system32\\prevhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll" ] }, "print.exe-63E11431499B9603D21BA075543CD415": { "file_name": "print.exe", "file_path": "C:\\Windows\\system32\\print.exe", "hash_md5": "63E11431499B9603D21BA075543CD415", "hash_sha1": "38FC357A66EF90D84FA07509DFD9071B54EB345D", "hash_sha256": "388D6761E678C66EEDA7085A05E10B13ABF88F855B753300C0F9B0D94DDB4DB0", "hash_sha384": "48540D170C7BB0ACEA8A706705AC77492886CAA3391D09545E585ECFA3E7A0491DBDA215778C9F9C2F6FE43B6C13BE42", "hash_sha512": "997F4CD774102FC867A7BD4C5851C13E6C160323937A31EF7678234F47EFA19E9AF492D13A37E294DF20144F8DAE6A7A7D62E0134CF0E2536FADFCCC5A4453A6", "hash_ssdeep": "192:Ks0CHkYa05foZiaDsqBNCh7MtKd+46Pv+DxlzezB/HQYjkGpnX4dhiJmVWzUW:vXbjaNNtkdU6xBezB/UQnXCVWzUW", "hash_imp": "D67C73847BD1DC0D9109BA544AD6C11D", "hash_pesha1": "50A77BD35AC84ECAC14CC2E25B7735F9BB89A11D", "hash_pe256": "98FD7307A07AD66A5718C153284BEF7A46CED530C146EEE728D61402540AE49C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Print Utility", "meta_original_filename": "Print.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/388d6761e678c66eeda7085a05e10b13abf88f855b753300c0f9b0d94ddb4db0/detection", "output": "Prints a text file.\r\n\r\nPRINT [/D:device] [[drive:][path]filename[...]]\r\n\r\n /D:device Specifies a print device.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\print.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "PrintBrmUi.exe-F51A4CE1A45BF7AB2FA7C7BB9B22335D": { "file_name": "PrintBrmUi.exe", "file_path": "C:\\Windows\\system32\\PrintBrmUi.exe", "hash_md5": "F51A4CE1A45BF7AB2FA7C7BB9B22335D", "hash_sha1": "644B654FB2DB5204FD9518EEF30E40D7110E061C", "hash_sha256": "4D2E80582318FCDE61028FBC1A232D1CA604D9478CFAE3982AE62501C3267228", "hash_sha384": "9872E323D2C79627F1EAF37D29724AD3DF14FC6D8687832998DB2AC98BD9D03E595EF0E84B81518BC46A75709C47AD00", "hash_sha512": "A363585F73A5855C61E357DBA257917D9CD7931EC1BE84739FEC11497050BA119C379AC8FC2CB4422C785964BD7B8BAE604653F6A60738C37D73ADC206002090", "hash_ssdeep": "1536:MnMQCWE1SzuGoWh0Gtl2FKr6pk0fei8vvKayD9:MtCWEHGoWh0GtlWKryLfei8nDY", "hash_imp": "D2225A1D5CB618A27802604174449643", "hash_pesha1": "1AF26E48FA715E0831D4CA47EB806D3FC08DCE30", "hash_pe256": "EC21693816471E57F8631DCD305ACC89529A75031CD821764324376FCBAC05BD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PrintBrm Application", "meta_original_filename": "PrintBrmUi.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4d2e80582318fcde61028fbc1a232d1ca604d9478cfae3982ae62501c3267228/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\PrintBrmUi.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\PrintBrmUi.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ], "runtime_window_title": "Printer Migration" }, "printfilterpipelinesvc.exe-1F863541DB3B70D31F1951E0930244F8": { "file_name": "printfilterpipelinesvc.exe", "file_path": "C:\\Windows\\system32\\printfilterpipelinesvc.exe", "hash_md5": "1F863541DB3B70D31F1951E0930244F8", "hash_sha1": "240E5DA7ED919845052D66B3853D111023618B7A", "hash_sha256": "3771726D6FF435265391CDD36B2F102EA7E1A157682EC55FE2910D390711E813", "hash_sha384": "4137DAB99B4BAF0806B625435959845A9362E49347F3CC26ECE12A6F05CCE4D0D132854068DA59BCDF4ACD3E4D633231", "hash_sha512": "A0F7F68E3E3432F036E6022314A079FB06B39CF078433ACC7447C033986D48368C585FEF146F6D8364EB2AEEBF6CC2492F191A9BD6557BE01C2BF14842B45F78", "hash_ssdeep": "12288:OpOCQekD+wV4zSGa9G8lCBsGaBYe2cUEZp/cJ:MED+XSzJAsUEZp/8", "hash_imp": "6D541090B3382AC315CB40B2EBBA1AEC", "hash_pesha1": "655E8F5ACFE98CFC4B44DBC5A1350AC02E563DD1", "hash_pe256": "25F8099381EDF7C7BAEFC80020F2D794B90519700195B81F79DD940749A453B2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Print Filter Pipeline Host", "meta_original_filename": "PrintFilterPipelineSvc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.264 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.264", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3771726d6ff435265391cdd36b2f102ea7e1a157682ec55fe2910d390711e813/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\printfilterpipelinesvc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "PrintIsolationHost.exe-95E50C824C9C9B4362AA3522B8449E29": { "file_name": "PrintIsolationHost.exe", "file_path": "C:\\Windows\\system32\\PrintIsolationHost.exe", "hash_md5": "95E50C824C9C9B4362AA3522B8449E29", "hash_sha1": "DEC6BEB4E2E15689EB4C924E1EFF84C0DB2C0DFA", "hash_sha256": "EB0AC5D09D1CB7830FEB6FD002F07BF26DAB139546C48FA03AAA5383190DB1AD", "hash_sha384": "14E70426B14359F9F171273E528323F954D487BCFF8C8C130E365874A55D7CE9A83D5E24BD7DB81D4601D797C07BEC0D", "hash_sha512": "147F390584737EF4A389DCB84263712A22F3DB4B8D6DE1EF95088832D3ED56F919B1F88935FBBA7F9EE482048E56BAA8F4FB48858E6C0056A4EFBD97ECFCC8F1", "hash_ssdeep": "1536:Dwr4rk/B5oU5Vt3A7HPd4n+lbeRZIbSQPT:M9p5N5HQbPRyZ2pPT", "hash_imp": "C3D07A510071A15D061A6D4301509DBC", "hash_pesha1": "083AD3F9E34BE2449D2B1D9C9F23AF18F4498B23", "hash_pe256": "7732F5C24FF68D2CA537B8AEBBEA626551035BF4DDC7D5ABE5526996F10E9889", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PrintIsolationHost", "meta_original_filename": "PrintIsolationHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/eb0ac5d09d1cb7830feb6fd002f07bf26dab139546c48fa03aaa5383190db1ad/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\PrintIsolationHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "printui.exe-89682E5353569213F4F9AA8B8AEFD69C": { "file_name": "printui.exe", "file_path": "C:\\Windows\\system32\\printui.exe", "hash_md5": "89682E5353569213F4F9AA8B8AEFD69C", "hash_sha1": "2A2926B68B140D48D041C3070CBE7E788EA2B8FB", "hash_sha256": "30BA375125E87D88106EC1B952AF157CAF9940DFC2CC382C56087DB9F15A4FA6", "hash_sha384": "0C35DDB6C8C143D7C5F2EF423AD87EB0C192BD1BD38C5034A897E3B46370ECF68B0F8912B4675A46BB1BE29F822F9B51", "hash_sha512": "EAD85A958F37C20EEA3881A4952A9BD930ABD5E34805A5C3183C84BD830968ED5A9C5B829E46551AB32B25C4AB0CBAAEDAF2F5ED1ABA9C4E0248F625591A072F", "hash_ssdeep": "768:a4PHmXrHTZCm5vI1iQfCIWVM9G4qW4ne+S/ly+PKAoXRZX6fbX57UWkCRPPA7/Qp:Jc9lVIPd4n+lbeRZIbSQPPA7s", "hash_imp": "DE8C59512CA98FB3E224769147985370", "hash_pesha1": "38F78D38EF16FB296A49E1A4C2E0302EE6FFB7F3", "hash_pe256": "7F5B48C966EDDD6AAA8EFC0725571E34C57C905BBC1804A716C9C2051FD94833", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Printing Settings", "meta_original_filename": "printui.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/30ba375125e87d88106ec1b952af157caf9940dfc2cc382c56087db9f15a4fa6/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\printui.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\printui.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\printui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll" ], "runtime_window_title": "Printers" }, "proquota.exe-4D60B00A13EAB7734CA1CF92B124B1DA": { "file_name": "proquota.exe", "file_path": "C:\\Windows\\system32\\proquota.exe", "hash_md5": "4D60B00A13EAB7734CA1CF92B124B1DA", "hash_sha1": "B7E1AF128EB6FE1BB6C3DEA2B3E9E6E06CAA8788", "hash_sha256": "817ED06C7BEC832CD3B574491D149CEC61D3D33F86AF93607893F76D349BC38F", "hash_sha384": "8621502D9AA1905D912B46D367C81A26E32B6C7C6AC704AF1915F2A87F04D1AFDB892231E07DA3ABD56BFBD98E414F94", "hash_sha512": "939D3A598000CE1D8FDFF625A3E8477933B779EF2920BF99EF1A8A8376426CAA4D25A8CAEB6B3D6D5C4E199FEFB6B5F96373A9DAE1530E0D681D55D7028B56C6", "hash_ssdeep": "1536:/dR90jjOyqIFvu77b+pJhHBHB3Q/4qvTs/dV:/7xyqazhhHB3QVsr", "hash_imp": "ABC8E22DBBEBF60ED7A7AEEE0144B820", "hash_pesha1": "37C256710B2E3BC2F867190BCF40BC063B78FD2F", "hash_pe256": "9F4F4D25972D1E16D42EDA33255FB693063A893F64CAD6AE0867B3DA5D816D48", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ProQuota", "meta_original_filename": "proquota.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/817ed06c7bec832cd3b574491d149cec61d3d33f86af93607893f76d349bc38f/detection", "runtime_modules": [ "C:\\Windows\\system32\\proquota.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28\\COMCTL32.dll", "C:\\Windows\\System32\\combase.dll" ] }, "provlaunch.exe-7BB8F781477C0870B70EB33262D28FCE": { "file_name": "provlaunch.exe", "file_path": "C:\\Windows\\system32\\provlaunch.exe", "hash_md5": "7BB8F781477C0870B70EB33262D28FCE", "hash_sha1": "27E3853E6F4E30B7563F4E2067179BD243B62E54", "hash_sha256": "337569C120A3F113A4DFD907427D939A44D60DA2E6D300C85C8A286048BFD851", "hash_sha384": "37C078A4F7C66D8B377F45C32F5AAF1A5DB1DCDA6B46061288F572D71A44084E89E0C9E308BCDE9957B495811C9207D9", "hash_sha512": "784E05F8E9061FAAF2564E78A3807B53E710CEE505A411A3C9EB4187E3F8ED1009579457D136572EC4A8063308A337705A44630E57A1E9C7CCE9A630BE480185", "hash_ssdeep": "1536:sNNugGdLPLu975SqHG1TQIolWLzmuuQKrXzbB3QzO7Os:sDMulsqIQblWF98jb1QS7Os", "hash_imp": "3E0DDAB92FCD1DD5AB2C7083DBECEB31", "hash_pesha1": "6FEF29B1A515D864D591F6982DFD029E5FFA4ED1", "hash_pe256": "E12C39AC61EC2D8D4B34681DBE53578591C292224A3697A5201BF74E494CDCEA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Provisioning package runtime command launching tool", "meta_original_filename": "provlaunch", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/337569c120a3f113a4dfd907427d939a44d60da2e6d300c85c8a286048bfd851/detection", "runtime_modules": [ "C:\\Windows\\system32\\provlaunch.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "provtool.exe-B62067B26775BDF072C328246E25AA89": { "file_name": "provtool.exe", "file_path": "C:\\Windows\\system32\\provtool.exe", "hash_md5": "B62067B26775BDF072C328246E25AA89", "hash_sha1": "4D7895566E3DC4E5600C225FBDA558DF9F37B2E1", "hash_sha256": "F643689F807C0666EC44E9D9B3BD583F1254049DDDAD0758235EE5C027352CFE", "hash_sha384": "3CBB49B685B57504D582E15271BAC465A89BE4577D95E39307F8C72521198E641BA85CE05B77F666E8DC6C19C716B758", "hash_sha512": "FBEE96CFB888B1E45A572DCFBD4E471A4FD848495D62CEA0A371E3F7077A3F9476FB8E03485DF5397FA66CDF74952CEAA40D33C63818E32359AB1E168FAAD982", "hash_ssdeep": "3072:+ippC67yMMiFWCi7rvzMtfTtu/OTh22veh7MVi:+rYyMMiFWCi7rvItfTxlZehAV", "hash_imp": "6768183691759CB6C8852BF74C7E52F3", "hash_pesha1": "BABDD2BEFA65E93926B858AB770C4DF2004E4ADA", "hash_pe256": "944A34F08A135C94A0FFD6B6BD76B3A10C7C167DD30C48EB42945B6B54E356B9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Provisioning package runtime processing tool", "meta_original_filename": "provtool", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.508 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.508", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f643689f807c0666ec44e9d9b3bd583f1254049dddad0758235ee5c027352cfe/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\provplatformdesktop.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\SystemResources\\Windows.UI.Immersive.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\Windows.UI.Immersive.dll.mui": "File", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(RWD) C:\\Windows\\Fonts\\seguisym.ttf": "File", "(RWD) C:\\Windows\\Fonts\\segoeuisl.ttf": "File", "(RWD) C:\\Windows\\Fonts\\seguisb.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\provtool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\profapi.dll", "C:\\Windows\\system32\\dmcommandlineutils.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll" ] }, "ProximityUxHost.exe-7041EE260AEF8A29E53596C5D07D9179": { "file_name": "ProximityUxHost.exe", "file_path": "C:\\Windows\\system32\\ProximityUxHost.exe", "hash_md5": "7041EE260AEF8A29E53596C5D07D9179", "hash_sha1": "50202D094347976BE09EB1C6C521E919C3209F88", "hash_sha256": "5286DFD70DBC92127B1F335AFC557EBD6322317971C62B8897BDC7095BD4485F", "hash_sha384": "4D5E1BABDAAB9EBAA86172F4721D6A7511F57DD830904113DC0D6CAC7C2840F82E0453D3E5E1E31F74383999BF178054", "hash_sha512": "8C5C144493EA982B88EB7F438CB4DE53ECA072B246589D7974EECE2A6AE515803FFC19206D8FED51034763E013054D079FF747A40247E7A30AFA2FDB84FA3942", "hash_ssdeep": "6144:RE9Mf3yyewNFkMX4NQYYw2i3g1xC+XKft+OMyviBBq1n:RE9g3yNGFkDQYA1xC+XKfmki/En", "hash_imp": "71F008D4A2B2412178B7977523CA2D5D", "hash_pesha1": "11BA7247376D76908E0AF71D8D7191400B93D3A7", "hash_pe256": "072D82D7237322F7AF46789A3743B3E27E9F591E78678769ED52CF8063FCA32B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Proximity UX Host", "meta_original_filename": "ProximityUxHost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5286dfd70dbc92127b1f335afc557ebd6322317971c62b8897bdc7095bd4485f/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\ProximityUxHost.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\ProximityUxHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\system32\\ProximityServicePAL.dll", "C:\\Windows\\system32\\ProximityCommon.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\System32\\cfgmgr32.dll" ] }, "prproc.exe-912400A90CA88E80ABC6CB8F30C1BB41": { "file_name": "prproc.exe", "file_path": "C:\\Windows\\system32\\prproc.exe", "hash_md5": "912400A90CA88E80ABC6CB8F30C1BB41", "hash_sha1": "BF32F1DD03D9DFEA828109824928C7F13B23CA99", "hash_sha256": "A174DE17639A2C544D8124895F878ABAAA634FDC63BF49979B407FD7A20C28BF", "hash_sha384": "35B6141F7407006AD02A5253B0B33A66E7F5DBF3F092551655DD789BC24A321D7F3461B3EA42D10C5F3ECFAB71BF589D", "hash_sha512": "2B858C8025F6B4FC63F72DC1A2259D79B0E4F06BEEDE4C2FC79C1D6D997D064C77EBFA68AB66F5F1CEF85F996E7C35CE86939D7AB0C8B2B83A3C9C2354539ACB", "hash_ssdeep": "384:m8s6nIBV0X5VtUWm6DYgWsUD1IDBRJtIlIX:mCe0X5VLgI1P3", "hash_imp": "92966D1E1404073AA1D43B25D8FD8907", "hash_pesha1": "EF19A06A6C9BDB6C56D72C4E24677E321A368221", "hash_pe256": "F912B31497003A70AD059E47F8EC9C90E16293978781540A33E7BFA3060D6426", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PlayReady Process EXE", "meta_original_filename": "PlayReady Process EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a174de17639a2c544d8124895f878abaaa634fdc63bf49979b407fd7a20c28bf/detection", "runtime_modules": [ "C:\\Windows\\system32\\prproc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "psr.exe-080E4F8ABAEA2DFE03DB802FC842E60A": { "file_name": "psr.exe", "file_path": "C:\\Windows\\system32\\psr.exe", "hash_md5": "080E4F8ABAEA2DFE03DB802FC842E60A", "hash_sha1": "DBD7D7E8A9AEBD5AA615F5FDC970F9C231A34F0C", "hash_sha256": "88160871721148021A86D945BCB04FCD483776FF3F1480DE33EA8FD56BF4EA87", "hash_sha384": "6A84E3CF50BCF8141D0821EC07634CF43AA7BC599213AE05A5BB4218AAE64535CC41A17F87FE66DF1E751C9A98546E3C", "hash_sha512": "404D9746956325B1B4F1BED2D7E73CF182C6A47D5066961677DF08BC005EB45B60AD20D5545DAAD010CA806480CB83723B96BBB7FA37BC6370BF6CDE1C85E8C3", "hash_ssdeep": "6144:KnH4+bmsLdjcwQjk/g3SvUnOwi0Lpi8Qgm:KnH4mu95ivqOwiECg", "hash_imp": "03EDC1179F035D69376C75EFF57B51D0", "hash_pesha1": "5DAB4BB28A360494086DA57FD2A2508A46800703", "hash_pe256": "4CF7C0D4F1BF9B89F310CD8E15DEC7EA393DC0C084AD6A05DE46C9B394A39B5D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Steps Recorder", "meta_original_filename": "psr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/88160871721148021a86d945bcb04fcd483776ff3f1480de33ea8fd56bf4ea87/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\psr.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\psr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll" ], "runtime_window_title": "Steps Recorder Error" }, "pwlauncher.exe-0B80CF2D0B14393D604E1B3F45B533D3": { "file_name": "pwlauncher.exe", "file_path": "C:\\Windows\\system32\\pwlauncher.exe", "hash_md5": "0B80CF2D0B14393D604E1B3F45B533D3", "hash_sha1": "5989C4F77687AB0D412C3B732E018E6B72D4EF94", "hash_sha256": "20BD575E31804C52D7EDC3A6298ABA504878D31DF549D3FC82FE7A99EE9A966E", "hash_sha384": "F540532EE9BD6E0377C2DFB6AF60441F890D2CCBDB62FB8AE25FD658D58A7FFBDA8D093A1C8721CEA695F8AE6913FF7F", "hash_sha512": "DA277637BDE52D14B6E37BD3B2C9C9B90C774CA7F9D08561249B3F1651CB670446759111015BF9D8AEA5D41B013D2B440C703AC83F309888AB7DE1BE3634A0A7", "hash_ssdeep": "768:3tosHsyociq2KK0Mqqvgz1QoL7JTHcs7z9JGBphb7idM8UOa5:dosHr3f7g+QoHx8s7z94Bzb7yNUO6", "hash_imp": "10E2E3C83FAD470F2219B3E8C8A1881E", "hash_pesha1": "4107D3F04AD8247594DC1696582A19DE23D283C4", "hash_pe256": "7B5823CCE9EDE541ADA4A1881153D454CF6A0D45BD56C62F212B51CB88E53DCD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows To Go Startup Options Command Line Tool", "meta_original_filename": "pwlauncher.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/20bd575e31804c52d7edc3a6298aba504878d31df549d3fc82fe7a99ee9a966e/detection", "output": "pwlauncher.exe - Windows To Go startup options command-line tool.\r\r\n\r\r\nThe pwlauncher.exe command-line tool is used to query or change your Windows To\r\r\nGo startup options.\r\r\n\r\r\npwlauncher [/enable | /disable]\r\r\n\r\r\n <<no parameter>> Display the current state.\r\r\n\r\r\n /enable Enable the startup option.\r\r\n\r\r\n /disable Disable the startup option.\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\pwlauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "qappsrv.exe-663EEF6513881B3AB42DB330B7C7068A": { "file_name": "qappsrv.exe", "file_path": "C:\\Windows\\system32\\qappsrv.exe", "hash_md5": "663EEF6513881B3AB42DB330B7C7068A", "hash_sha1": "2D98697ADD27C7F0233E4B4DEC38C98F74BB99FD", "hash_sha256": "7854BECE46ECA8917904D60666A856DE11CA4896C6452D5AF1A1B20F1626C971", "hash_sha384": "F82DB34F12D90A88E8251DF4B71FD82E1797C328D67F02D79F398CF560788344741395AE19A73A50FA317FD8F276FB58", "hash_sha512": "E724B8956E423B63DEC7A3487CA788A9E16E67E4413932E86909F920710E240E324398E00042FA32B9B16AEA2DF4A7EBB347CA14ECF7A068C3C6691CBA3823FF", "hash_ssdeep": "384:DQTcgWLsYGvRO+UxtRT5dseZ87BvFtSZa6KuRX390pkINWgaWF:DQoMYGvRO+UtYeZ8Nr6ckIx", "hash_imp": "868BFA1AAB4C99A8643F150421706BD1", "hash_pesha1": "017914B13A0075C38D0D0C88561A7AE18D27D834", "hash_pe256": "CE21F7D9C92B79D0FEE6BD70B832D6C13A91A04531BB19A27511F2855F979AA9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query Remote Desktop Session Host Server Utility", "meta_original_filename": "qappsrv.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/7854bece46eca8917904d60666a856de11ca4896c6452d5af1a1b20f1626c971/detection", "output": "Displays the available Remote Desktop Session Host servers on the network.\r\n\r\nQUERY TERMSERVER [servername] [/DOMAIN:domain] [/ADDRESS] [/CONTINUE]\r\n\r\n servername Identifies a Remote Desktop Session Host server.\r\n /DOMAIN:domain Displays information for the specified domain (defaults \r\n to the current domain).\r\n /ADDRESS Displays network and node addresses.\r\n /CONTINUE Does not pause after each screen of information.\r\n\r\n", "error": "Invalid parameter(s)\r\nDisplays the available Remote Desktop Session Host servers on the network.\r\n\r\nQUERY TERMSERVER [servername] [/DOMAIN:domain] [/ADDRESS] [/CONTINUE]\r\n\r\n servername Identifies a Remote Desktop Session Host server.\r\n /DOMAIN:domain Displays information for the specified domain (defaults \r\n to the current domain).\r\n /ADDRESS Displays network and node addresses.\r\n /CONTINUE Does not pause after each screen of information.\r\n\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\qappsrv.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\qappsrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "qprocess.exe-33305BA7125D811F716148C421553F79": { "file_name": "qprocess.exe", "file_path": "C:\\Windows\\system32\\qprocess.exe", "hash_md5": "33305BA7125D811F716148C421553F79", "hash_sha1": "A90B92D3F21FE22BD7C896A0CAE8663AD7514273", "hash_sha256": "F71965F45A393E95B8C10B6D8947903BD0F035FC8CA3982D0F1A7D42B23FA315", "hash_sha384": "F82B7FB20FD43C00AA287C59DBC998B1D2F2D053A68453582B33A15492555205A7AAAD14D25823CDDA0F0517ECF787F2", "hash_sha512": "C28347F4C719317B847C333C393B316DDFBD290FB56F7B286269E3850C05BF717F12E81FEB95D2F07D5A18F22DE0C9FE9D0329322726117B6342E2D62E46992D", "hash_ssdeep": "768:z0wxzFYy7HF93OARwQs3Zzg2yHMpZ8iLLBVu3:z0wFjPxOZdgnsLL23", "hash_imp": "2C6064FDDA8E2B58540E4729A999BB69", "hash_pesha1": "CC735AB6CC79E2D4DB8762B08D84100C54C681FC", "hash_pe256": "9B27E73546CD423EEB33922B53C6545B71A349C670A48C04E37AE13295D7AB48", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query Process Utility", "meta_original_filename": "qprocess.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/f71965f45a393e95b8c10b6d8947903bd0f035fc8ca3982d0f1a7d42b23fa315/detection", "output": "Displays information about processes.\r\n\r\nQUERY PROCESS [* | processid | username | sessionname | /ID:nn | programname]\r\n [/SERVER:servername]\r\n\r\n * Display all visible processes.\r\n processid Display process specified by processid.\r\n username Display all processes belonging to username.\r\n sessionname Display all processes running at sessionname.\r\n /ID:nn Display all processes running at session nn.\r\n programname Display all processes associated with programname.\r\n /SERVER:servername The Remote Desktop Session Host server to be queried.\r\n", "error": "Invalid parameter(s)\r\nDisplays information about processes.\r\n\r\nQUERY PROCESS [* | processid | username | sessionname | /ID:nn | programname]\r\n [/SERVER:servername]\r\n\r\n * Display all visible processes.\r\n processid Display process specified by processid.\r\n username Display all processes belonging to username.\r\n sessionname Display all processes running at sessionname.\r\n /ID:nn Display all processes running at session nn.\r\n programname Display all processes associated with programname.\r\n /SERVER:servername The Remote Desktop Session Host server to be queried.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\qprocess.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "query.exe-29043BC0B0F99EAFF36CAD35CBEE8D45": { "file_name": "query.exe", "file_path": "C:\\Windows\\system32\\query.exe", "hash_md5": "29043BC0B0F99EAFF36CAD35CBEE8D45", "hash_sha1": "BFF9633D301818EB5DEB684E758A04BC204FECC9", "hash_sha256": "58D1132B636C6D33C2B8B3659F310F6DE370A00F837226129657B2B82184A307", "hash_sha384": "403C0D1AF974C954FF028F47AA1728507B5BDBD9037D8ACD3D7C94E5AD408323B5AE0E6C044FC4D0A6F569BB0B82CE30", "hash_sha512": "A3FF3FB40A11C98C64AE7EE9B052BC00EB10401BAAB665BC9EFCBC0F3B0B9616761776F5942E614E40CF1C088575040024ED046A0E90BF72C7269A40A9DF91CD", "hash_ssdeep": "192:/+OSUSw8eEAMuDzEAk3ZsThGdgo8jJIbO4klbhwxxth2GcDK71QmPgWh3W:/+OV1M/Kg7y2bzgOxth20hVPgWh3W", "hash_imp": "CCC9DA4A55E90DFE34CBCDB066D6A6B3", "hash_pesha1": "B5FB29D06214C4D66E96B996F5C29D924A3624F7", "hash_pe256": "7D91E2F35D978905E9465421329699E02C0353C9B88B3DC8687AB892F5DE9C69", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MultiUser Query Utility", "meta_original_filename": "query.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/58d1132b636c6d33c2b8b3659f310f6de370a00f837226129657b2b82184a307/detection", "output": "QUERY { PROCESS | SESSION | TERMSERVER | USER }\r\n", "error": "Invalid parameter(s)\r\nQUERY { PROCESS | SESSION | TERMSERVER | USER }\r\n", "runtime_modules": [ "C:\\Windows\\system32\\query.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "quickassist.exe-39AB5ED601B0C39DCE3B7D269847C944": { "file_name": "quickassist.exe", "file_path": "C:\\Windows\\system32\\quickassist.exe", "hash_md5": "39AB5ED601B0C39DCE3B7D269847C944", "hash_sha1": "B13914A7207F2ED60F229FD2FDECDA9AD3F2EC78", "hash_sha256": "F3FF9DB4C29E460735FFA8E9B0882A27BA5AC67351CD2ADEA759E496D8BA918A", "hash_sha384": "3E0B54D31F45FA314BFC25823B72358D98AB5190B1B8383569EA90F66AD850BA911DBC540A8D851050C173437A42069B", "hash_sha512": "C95644E0C5255E36FFF2A67641DBD2235EFE2268ACC8F3BC6DFBE81A7A4FFC90FD99D2003C27D809FA0516CDE63D68F2DD2EC94DEB52870E82660D768F9A3DE0", "hash_ssdeep": "12288:CKyWgF3B0YvjxtdsTR8ZgOoqR+GizpAG:CKyWgfjxjsKZCq4/", "hash_imp": "E2E46D7CC60155253B0BA0DAE9B6394F", "hash_pesha1": "F2704BD4B3DFE13CDA77DD38AB9D31FBBF529EE9", "hash_pe256": "F7BF2D20A7D836D5EA9140A0DAB0AA3AE1AF468A06E8F49DF67C1B22A1D56D56", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Quick Assist", "meta_original_filename": "QuickAssist.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f3ff9db4c29e460735ffa8e9b0882a27ba5ac67351cd2adea759e496d8ba918a/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\System32\\en-US\\quickassist.exe.mui": "File", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Windows\\Theme601709542": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\jscript9.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\1e60HWNDInterface:1b0636": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_ie_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\ieframe.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_webcache_counters_{9B6AB5B3-91BC-4097-835C-EA2DEC95E9CC}_S-1-5-21-2047949552-857980807-821054962-504": "Section", "\\BaseNamedObjects\\F932B6C7-3A20-46A0-B8A0-8894AA421973": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\Sessions\\1\\BaseNamedObjects\\1e60HWNDInterface:2c0460": "Section", "(R-D) C:\\Windows\\System32\\en-US\\mswsock.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "(RW-) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\INetCache\\IE\\3X3M6V65\\RDT5YZRU.htm": "File", "(R-D) C:\\Windows\\System32\\en-US\\mshtml.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\urlmon.dll.mui": "File", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "(RWD) C:\\Windows\\Fonts": "File", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(RW-) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\INetCache\\IE\\3X3M6V65\\DevCMDL2.1.62[1].eot": "File", "(RW-) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\INetCache\\IE\\AU189C9G\\StrgMDL2.1.58[1].eot": "File", "(RW-) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\INetCache\\IE\\X4THQAJB\\MemMDL2.1.62[1].eot": "File", "(RW-) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\INetCache\\IE\\EFGLGQ51\\RemtMDL2[1].eot": "File", "\\Sessions\\1\\BaseNamedObjects\\MSIMGSIZECacheMap": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\quickassist.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\ATL.DLL", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\UxTheme.dll" ], "runtime_window_title": "Quick Assist" }, "quser.exe-480868AEBA9C04CA04D641D5ED29937B": { "file_name": "quser.exe", "file_path": "C:\\Windows\\system32\\quser.exe", "hash_md5": "480868AEBA9C04CA04D641D5ED29937B", "hash_sha1": "D675361B748CAF22A3C1C275CCFF2D472245099C", "hash_sha256": "766C791EDFA6EEEBA0F99D6481BFE23BF59E6ACB81A930B71F3AA33EFBAFE544", "hash_sha384": "58DC5D3A0B332F42D0CEFE7344C5272C06D6A1A35B997D38E8E43870FE9AF2C9F194FA138D01514CF1B1D7A0043A906A", "hash_sha512": "8E5BF5D46ECBECF552295A9AE938BECD82F18ACC643256C203F8DD5538292198D10F6C3CA1571B5110AD279280CAF4778E64B937BE86D5A9B87F30A126893FF8", "hash_ssdeep": "768:KpDszzRss58elGTDZznkOh6Z8QBc6ij5vYMo:KpDszJWlkDm6iRYMo", "hash_imp": "B72F14292FAC033099AD1A08D6867486", "hash_pesha1": "022E2528554367E4EAC67795FD9C133F3E8F67CF", "hash_pe256": "57DF4F4BE576D2D4AEF25CD37FF6D0797302EADCCCF65FC2145E235CE6A3DA07", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query User Utility", "meta_original_filename": "quser.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/766c791edfa6eeeba0f99d6481bfe23bf59e6acb81a930b71f3aa33efbafe544/detection", "output": "Display information about users logged on to the system.\r\n\r\nQUERY USER [username | sessionname | sessionid] [/SERVER:servername]\r\n\r\n username Identifies the username.\r\n sessionname Identifies the session named sessionname.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server to be queried (default is current).\r\n\r\n", "error": "Invalid parameter(s)\r\nDisplay information about users logged on to the system.\r\n\r\nQUERY USER [username | sessionname | sessionid] [/SERVER:servername]\r\n\r\n username Identifies the username.\r\n sessionname Identifies the session named sessionname.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server to be queried (default is current).\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\quser.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "qwinsta.exe-3ED9CCC06AF18EF822E1794FEAEC6183": { "file_name": "qwinsta.exe", "file_path": "C:\\Windows\\system32\\qwinsta.exe", "hash_md5": "3ED9CCC06AF18EF822E1794FEAEC6183", "hash_sha1": "61BB46E5D659EFE16E5C019EABCA1AA1D5CD8F8F", "hash_sha256": "08AC265F1888731D6FF54D762FA08B06B172A9424B66CE113AFCEFEF9759C37B", "hash_sha384": "7C29FFCF61B450043333A8E3505BFFDA7741F81120377AB6D5E54BF8E71E0038AE51EDE32750BC2467104EE360D19241", "hash_sha512": "C07F8FB0CB5FB1C6E81AB7495653373F6D8F6AC4CE49CC04A337155EE22C9987E950F2676BE7B9BBDA94A72B3621BF32E607FBDC96D85ED416820A16B7D003E6", "hash_ssdeep": "768:HcqOE52Je/1ejPYAtXYpW3yMzXCki7aBzRIHZ8DjO9Dt:HcqOE52J6szYAtX0PZApj+t", "hash_imp": "D1DB32AE474C00FB7315E2D610E6A740", "hash_pesha1": "E59D31CA1B8F0DBC41846330C5184EABFFDC7186", "hash_pe256": "E42513910BDE8D325A5B0C96194882D1889A1C76DA4EF7E52DA6800EC55187A3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query Session Utility", "meta_original_filename": "qwinsta.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/08ac265f1888731d6ff54d762fa08b06b172a9424b66ce113afcefef9759c37b/detection", "output": "Display information about Remote Desktop Services sessions.\r\n\r\nQUERY SESSION [sessionname | username | sessionid]\r\n [/SERVER:servername] [/MODE] [/FLOW] [/CONNECT] [/COUNTER] [/VM]\r\n\r\n sessionname Identifies the session named sessionname.\r\n username Identifies the session with user username.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server to be queried (default is current).\r\n /MODE Display current line settings.\r\n /FLOW Display current flow control settings.\r\n /CONNECT Display current connect settings.\r\n /COUNTER Display current Remote Desktop Services counters information.\r\n /VM Display information about sessions within virtual machines.\r\n\r\n", "error": "Invalid parameter(s)\r\nDisplay information about Remote Desktop Services sessions.\r\n\r\nQUERY SESSION [sessionname | username | sessionid]\r\n [/SERVER:servername] [/MODE] [/FLOW] [/CONNECT] [/COUNTER] [/VM]\r\n\r\n sessionname Identifies the session named sessionname.\r\n username Identifies the session with user username.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server to be queried (default is current).\r\n /MODE Display current line settings.\r\n /FLOW Display current flow control settings.\r\n /CONNECT Display current connect settings.\r\n /COUNTER Display current Remote Desktop Services counters information.\r\n /VM Display information about sessions within virtual machines.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\qwinsta.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "rasautou.exe-1CE09827C1778F8AB4F09C9541542479": { "file_name": "rasautou.exe", "file_path": "C:\\Windows\\system32\\rasautou.exe", "hash_md5": "1CE09827C1778F8AB4F09C9541542479", "hash_sha1": "275DF18EE0F0B482708390B3A62C870CE303A9A8", "hash_sha256": "EEC5DBDF411A89F65247679840DC7A902180C1D23C94B0D92C283B4130664263", "hash_sha384": "23AF6F5C9B610B49095DB6AD1DB3BAF2A7992B1B5C622E80D78E261DC4BCC27C842696FD23BF9E40555FD22A8D606D9C", "hash_sha512": "F414C423C1CF770A9DFA036CE98AA7B527A9B8C3CE476EA09C64FD74B8EDB7DC45D0250BA2C7062CD74008A07D8E5FC9E5A65027A17066BE11A17E04B3629573", "hash_ssdeep": "384:lMzAORLrDeL9wSi37rT8Oy11BTwt4hxPsWHBW:ls/D5SwT8OZ2xPt", "hash_imp": "0B915B3D21B94438146557937D698E77", "hash_pesha1": "ECC4B7B29DD08BFDF2B00ED205C8FF952507EBE7", "hash_pe256": "81F3401A4463D218504CA4FF634FC30F5ACE05AD6C0ED7ED3F6B4D98E9DF1B22", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Access Dialer", "meta_original_filename": "rasdlui.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/eec5dbdf411a89f65247679840dc7a902180c1d23c94b0d92c283b4130664263/detection", "output": "Usage: rasautou [-f phonebook] [-a address] [-e entry] [-s]\r\n", "runtime_modules": [ "C:\\Windows\\system32\\rasautou.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "rasdial.exe-6AEB82B4CA13B5FBD316F3247049DB0F": { "file_name": "rasdial.exe", "file_path": "C:\\Windows\\system32\\rasdial.exe", "hash_md5": "6AEB82B4CA13B5FBD316F3247049DB0F", "hash_sha1": "E88733C2ED3E96C7DE001909D29D97E2F1E99B0F", "hash_sha256": "31016AE60A8AEF2DBF1C399F7709BC4FF69BE1E2EBAE5699FA55CFCA606C397A", "hash_sha384": "AAFF2BAB4CD9816D24FD1B1F393B97FC7DBC3717D017F1C4DE36B384FF1A2484045E90C30B36C315997D474500FCB14E", "hash_sha512": "A4F11DC7DD73F46718DFDD7F2D589E2A14E8CF41BBF15E5C857BD23AC8D4D65948937B13EA37EC6C50AAB1234A1E021732B2A9A199E1248733C19365D6E80FE2", "hash_ssdeep": "384:mYoqPypTRhuYONke1rk9I45HFO+0+DKOFNXrEmg6WrVW:mYXyuDNke1o9Iush507M3", "hash_imp": "D893FB6DD140FF7107D0E41FFBAAAEC9", "hash_pesha1": "AF08A96DA94DFB34623C0A2975EDBDCD10FE5C52", "hash_pe256": "AF20FD0A04E2E66374781C2AEDAAAD51C8CE1F4B28E96DAABD426CC78BF8BE8B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Access Command Line Dial UI", "meta_original_filename": "RASDIAL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/31016ae60a8aef2dbf1c399f7709bc4ff69be1e2ebae5699fa55cfca606c397a/detection", "output": "USAGE:\n\tC:\\Windows\\system32\\rasdial.exe entryname [username [password|*]] [/DOMAIN:domain]\n\t\t[/PHONE:phonenumber] [/CALLBACK:callbacknumber]\n\t\t[/PHONEBOOK:phonebookfile] [/PREFIXSUFFIX]\n\n\tC:\\Windows\\system32\\rasdial.exe [entryname] /DISCONNECT\n\n\tC:\\Windows\\system32\\rasdial.exe\n\n\tPlease refer to our privacy statement at \n\t'https://go.microsoft.com/fwlink/?LinkId=521839'\n\n", "runtime_modules": [ "C:\\Windows\\system32\\rasdial.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "raserver.exe-8587293293333A174606EA3E640A4A64": { "file_name": "raserver.exe", "file_path": "C:\\Windows\\system32\\raserver.exe", "hash_md5": "8587293293333A174606EA3E640A4A64", "hash_sha1": "5738EFDBCE78DC71C4D7236293843C0A06B7939B", "hash_sha256": "448E69DB2624789E2927AAA2C7B5271ACC10F6DE949D89A427FF856E4117CAFE", "hash_sha384": "FBE0056B446BD921F04174140FD4EAFE21747CBCBDDC7A8E8BAE8837CDF6CE8C440DD680508D8D5A6465040417B5A766", "hash_sha512": "20CFD4385E0A3C57D217EBF0E997212F275C7105EED0CE3A45D268E0BEE542C6AE3FDC82A90CB1EBA72538F7699F8E6081531996C33C45354168B4DA24453311", "hash_ssdeep": "3072:GX+C/MoIvAIJeTFnvOi5BXxLqEWJ+pD7jNoYgnEU/GkzH:1C/OvAIJehn2i59xLqEWJAVoYgnDH", "hash_imp": "514AC84C0F18361321BD8060B1318F9D", "hash_pesha1": "44C28BA0BAC207B67428F9797AA4EE4CC536E34C", "hash_pe256": "0E7DCD1BE720658422517CEAC7A95C9F0EF3940D1EC5C2B5E33F93B448A84E10", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Remote Assistance COM Server", "meta_original_filename": "raserver.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/448e69db2624789e2927aaa2c7b5271acc10f6de949d89a427ff856e4117cafe/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\raserver.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\raserver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "rasphone.exe-95356A41F7C4372F45FCBE4D32BB2003": { "file_name": "rasphone.exe", "file_path": "C:\\Windows\\system32\\rasphone.exe", "hash_md5": "95356A41F7C4372F45FCBE4D32BB2003", "hash_sha1": "B1D877340C4DD4B4FA03F87F13B9D2EEF976F34D", "hash_sha256": "F0B3457EEFB179AF919F3EF4014655E17A6CE49065504F0B4E48D9EC0CDF6E64", "hash_sha384": "198C890EC2C2BB35893D06D6EE1D79B5073A1669C4BF6D9CFF8AD42BE915FF9EBBC5B98A189CA4894364AF5D1EB47459", "hash_sha512": "210A1A93A32E31BC22D6D5F729EF56DF77471DB0007F04BDE97A95E0844F67769B6B6CB211AE0DE14EE674FB4B547A209CBB7888110E9EB3BA8906BD3A6A5159", "hash_ssdeep": "768:ItnJV3OHJIm0QuWUcO+/HpiFL2EKMmkORUOiFq11od:I1JzWUShEKMmFsd", "hash_imp": "C940443312A7232B26BCFD8DB2823083", "hash_pesha1": "40DB8CED2D8914069C5F48345F442F6E6B1D77EC", "hash_pe256": "9D0B8E191BE5FA627858D8430AD2BC29F4FAAA22C3998B1ACEA8CFE046B69F7B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Access Phonebook", "meta_original_filename": "rasphone.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f0b3457eefb179af919f3ef4014655e17a6ce49065504f0b4e48d9ec0cdf6e64/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\rasphone.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\rasphone.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\system32\\rtutils.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "runtime_window_title": "Dial-Up Networking Command Line" }, "rdpclip.exe-D3348A5042E6613D2DF07CBF3D2257D4": { "file_name": "rdpclip.exe", "file_path": "C:\\Windows\\system32\\rdpclip.exe", "hash_md5": "D3348A5042E6613D2DF07CBF3D2257D4", "hash_sha1": "9BF306B58F5DDA6B0EEFF5DF0EE8CE45907E84DB", "hash_sha256": "8AB6E280B961D73082C5F6C67E843CB2F8B666DFFA4104995DAFC454432847D6", "hash_sha384": "7B5CE312D9DA04C81AB0B85D12C84B6C6569919D9ADC2B5E83EA817AFE4CD14E74E9353637938AD5F843FD2063A1818E", "hash_sha512": "543DBFF7BA26F6D4B9F26AC9AC64CC7455BA08981DB4356544ABDD5AEB4AA9BBB922A7D34349D681C929639B818B86806310171BF60EE06AA3E30C0A08FC6F0D", "hash_ssdeep": "12288:A34oYkqYnFYTuW8Pq4C4bhObjoSpPwevZu2oxuXet9qviLboBcquUwQtBpDlJ5y8:3oYkqYFYTuW8Pq49bhOb6nRDbyFb1", "hash_imp": "810E64B8DF587DC8C95D4C20115A7F58", "hash_pesha1": "287C693231871C2C3AE4269F07128E795C74DF51", "hash_pe256": "B6DCFA67E90042BBB38E16D379A5E4DD9E80C693F981256716FAA36F6C814F12", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Clipboard Monitor", "meta_original_filename": "rdpclip.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8ab6e280b961d73082c5f6c67e843cb2f8b666dffa4104995dafc454432847d6/detection", "runtime_modules": [ "C:\\Windows\\system32\\rdpclip.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "rdpinit.exe-FAC33E98F2C94753F0FFF10DC018C0FB": { "file_name": "rdpinit.exe", "file_path": "C:\\Windows\\system32\\rdpinit.exe", "hash_md5": "FAC33E98F2C94753F0FFF10DC018C0FB", "hash_sha1": "D541DC5D4572197ACFE166359F0D6B3C86154B6A", "hash_sha256": "A4BBE8274D83B75BFD6A2DEE159A46C7221BB33E092677CDC2E1CB704EFF7DDE", "hash_sha384": "4DEAE76E76FB878ED2E0455059AFF2FBFD82D5ED8830AECEB0F03A6B98342FD686EF76DE8563E3247EF67CD2986B7A1B", "hash_sha512": "F7DC49FF0C4DDD07EC078DC650A89A15E61864716B61666BA1EF1B994E0E6C216D0288EA58A2232E99D42FB248E740F2AB852869D365C19824AE0DF719AF0068", "hash_ssdeep": "6144:nc5PN5jeRy+lqcPS94LYY79XzMSIICfV9Ad0LfqDTNBD8:nc5POo+YcPS94dz9IIcnw0re5J", "hash_imp": "1FA6F273F528994178532729010B47C1", "hash_pesha1": "A22AF4DAF323873F63181C8DC8E908B81E8491A1", "hash_pe256": "4859884C635531EF4CCF6835AF283779FE8BA1E4268DF402A5D5F0EA3AAFB6AC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RemoteApp Logon Application", "meta_original_filename": "rdpinit.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a4bbe8274d83b75bfd6a2dee159a46c7221bb33e092677cdc2e1cb704eff7dde/detection" }, "rdpinput.exe-BD99EECA92869F9A3084D689F335C734": { "file_name": "rdpinput.exe", "file_path": "C:\\Windows\\system32\\rdpinput.exe", "hash_md5": "BD99EECA92869F9A3084D689F335C734", "hash_sha1": "A2839F6038EA50A4456CD5C2A3EA003E7B77688C", "hash_sha256": "39BFB2214EFEED47F4F5E50E6DFF05541E29CAEB27966520BDADD52C3D5E7143", "hash_sha384": "BE89BA1C83A0D91A3C3497F0CC0641EDDDFC39EE8E3C3786232CE7ABFFB4E58BA1D8CD0E4E1489ACBB6726D64FA57BF8", "hash_sha512": "355433C3BBBAA3BCB849633D45713D8A7AC6F87A025732FBE83E259EC3A0CB4EABB18239DF26609453F9FC6764C7276C5D0472F11CF12D15EF806AA7594D090E", "hash_ssdeep": "3072:y8R002SD4r1d9aP2bu5I709ooTumjZu9g3IY2z8wFVC6f2:yYyFrz9apI7JoL9u9g3wTD", "hash_imp": "977236F816067A2F2F469ED5AEF2E6AF", "hash_pesha1": "945BDA2701AFAB130BE1C33607D1AAA86E25E142", "hash_pe256": "DA695EBB68699B4B6782890E0550F5D9E82F2E43C09CDE3C512DA0B576E9BBC8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Input Handler", "meta_original_filename": "rdpinput.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/39bfb2214efeed47f4f5e50e6dff05541e29caeb27966520bdadd52c3d5e7143/detection" }, "RdpSa.exe-5992F5B5D0B296B83877DA15B54DD1B4": { "file_name": "RdpSa.exe", "file_path": "C:\\Windows\\system32\\RdpSa.exe", "hash_md5": "5992F5B5D0B296B83877DA15B54DD1B4", "hash_sha1": "0D87BE8D4B7AEADA4B55D1D05C0539DF892F8F82", "hash_sha256": "32F60EABE54C4D0CD0F0EC29F48F55CA1AD097BF35097247B186FD70426F847C", "hash_sha384": "31109A4B018DA163230978D94984DE0B651D392AB016470288B1DE3697D200FBCCEE36C19A1A83B6E7BA7D18C2CEA08C", "hash_sha512": "4F6DA913AF530301DA1D0638AA2635ADA446EBEE6E27B5059DB5C2B7FE439162AC3B1A595ECF4163A093890DF9AC94D9085A53D8C991E48703F9D2691326E7E6", "hash_ssdeep": "1536:hUI4Ok4rdTa5rbcdkhvaaaaaaaaaaaaaaaaaaaaaaaaaaaPTS+FnnlVZuh71o:lotbo0vaaaaaaaaaaaaaaaaaaaaaaaah", "hash_imp": "9CAB97FF944F0ADB015AB80E6D39F8FD", "hash_pesha1": "1FCAD27E72AC0E8B1AEA89F6B633F55C4C2A55F9", "hash_pe256": "131B991736E82DDADC003CE5B3F45FB1BFCB0662EF8DF5742DF1B9F374CDE77C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Agent", "meta_original_filename": "RdpSa.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/32f60eabe54c4d0cd0f0ec29f48f55ca1ad097bf35097247b186fd70426f847c/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\RdpSa.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\RdpSa.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll" ] }, "RdpSaProxy.exe-B891622CC2BD3A590F341DD4A3B5EA0F": { "file_name": "RdpSaProxy.exe", "file_path": "C:\\Windows\\system32\\RdpSaProxy.exe", "hash_md5": "B891622CC2BD3A590F341DD4A3B5EA0F", "hash_sha1": "50DBA46499F21C856E7677C3B769AFA38CFC48EB", "hash_sha256": "D263AA2DBFD48F580594630C9AC3D72E64620B8EA67B9123332DD52467311095", "hash_sha384": "44A1E9D0B7C2BBAED7F305D31152DB01F8D7B7F61B55231563AF92A3548675A412F7BA97BC44E61629EED859E3239D08", "hash_sha512": "D290A9B103AB963B55FC3F9C7E693665D0E3D829B9F0A0CA83A8184C4610E51ADBEE26164D3158B34BAB560EEB9D83FF0F605B0E4878AB40D005E1DB04C78D69", "hash_ssdeep": "768:VTDECjSJWyyz/nIP+yzlHua+OVAl0Vd2kZv4gd9B+nMuMA//c:RECWot/olOB+VLZv4gd9Ac", "hash_imp": "CAB3BAC1D31F8145D8F4244A95674FA1", "hash_pesha1": "82988A9CB6B4937BCB9855F28D0B9B80CA161450", "hash_pe256": "78A5BEF4C0CF94D66F409736EC83E3FE750A138AE4D7D535B7EC628A04DA10F2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Agent Proxy", "meta_original_filename": "RdpSaProxy.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/d263aa2dbfd48f580594630c9ac3d72e64620b8ea67b9123332dd52467311095/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\RdpSaProxy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll" ] }, "RdpSaUacHelper.exe-0D5B016AC7E7B6257C069E8BB40845DE": { "file_name": "RdpSaUacHelper.exe", "file_path": "C:\\Windows\\system32\\RdpSaUacHelper.exe", "hash_md5": "0D5B016AC7E7B6257C069E8BB40845DE", "hash_sha1": "5282F30E90CBD1BE8DA95B73BC1B6A7D041E43C2", "hash_sha256": "6A6FDD834AF9C79C5FFC5E6B51700030259AEAE535F8626DF84B07B7D2CEE067", "hash_sha384": "18F7DD05DD9D528F2244DE0DD749683C5EB973BD55103D7F6D331D52798AF966B02375545FE6D7341AF2935A7B2C6A26", "hash_sha512": "CD44D8B70FC67C692E6966B4AD86A7DE9C96DF0BADE1B3A80CB4767BE159D64F3CC04DC5934F7D843B15101865089E43B8AECABDDC370B22CAF0C48B56B3430E", "hash_ssdeep": "384:xoC91ywhP4h30pA2G1krpzQ+KjduVx11HbGH9Zegxt/BIAJ5Zah3n4WBgW61:X90whP4lQGidXgkVxnY3NB3J5Za1Xg", "hash_imp": "8AF12EDD150A1168DC2B3C264D8F5383", "hash_pesha1": "3E1C22CCDDEEF4E61F54BA53CA84A23FFDD93B64", "hash_pe256": "5FE7E12EA11BDA2C9C05DD7A0B983B90A7038E6FF326BD233D6A25FBA160A1F4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Agent UAC Helper", "meta_original_filename": "RdpSaUacHelper.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6a6fdd834af9c79c5ffc5e6b51700030259aeae535f8626df84b07b7d2cee067/detection", "runtime_modules": [ "C:\\Windows\\system32\\RdpSaUacHelper.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\system32\\WINSTA.dll" ] }, "rdpshell.exe-763361A7F4774E17110986C2CD7A47C8": { "file_name": "rdpshell.exe", "file_path": "C:\\Windows\\system32\\rdpshell.exe", "hash_md5": "763361A7F4774E17110986C2CD7A47C8", "hash_sha1": "8945494E43722447469171F0CA093F12F83921CD", "hash_sha256": "407A7DCA4722725826F0D2BBEA6D5C774B9D21930D96E66BFDB100D49174816E", "hash_sha384": "63F6B15E38E78AE7A339D4BCC45B47970A01CA03256718483FEE420FFDFF71DA8CE18C40A6EC70203549F69ED98AB536", "hash_sha512": "C3A12B499FE4B1235F1865E71FEEB1466B2B645C35C4129551CDAD08720BA60DB6DBB536AE88B047F58C86F46B5641743CC005D78216C2C3B4A053EB1DC04A23", "hash_ssdeep": "12288:P7+h2vbzl0GjSQ7pAPFPs41dIdvqxUXs/:P7+h2jzWARKPd9dIdir/", "hash_imp": "64E9F3A61B367A03199B12902099FBE6", "hash_pesha1": "2C1DB653C7641C55F9BE21E10A9AC3F7B403FA29", "hash_pe256": "450981243CD35BA115AA294469F17A167BB75E0597E81AE57EDACA562D541CCA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RemoteApp Shell", "meta_original_filename": "rdpshell.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/407a7dca4722725826f0d2bbea6d5c774b9d21930d96e66bfdb100d49174816e/detection", "runtime_modules": [ "C:\\Windows\\system32\\rdpshell.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll" ] }, "rdpsign.exe-16F2AC16783A45C41218418C92BBE8EC": { "file_name": "rdpsign.exe", "file_path": "C:\\Windows\\system32\\rdpsign.exe", "hash_md5": "16F2AC16783A45C41218418C92BBE8EC", "hash_sha1": "3A8E4D421AC783C9A51B4A61014C2543F73E011A", "hash_sha256": "2DA5D38A23C4FCA4C44957F392256E3A761F90C1C4F5789513A265023B837117", "hash_sha384": "26E0DC65D207C76260D03D2EB78F1B3299E515566DAE19E247DE5A328B89C4F93A716076F033BB10D29316A137210C7B", "hash_sha512": "8DA1FC06C2439813DD69313126F77B87E63981930F6E469696FC3D004108194A9C3A403A2E67DE382EA3011288319E9129E0CE4981CC1DDFF55CBAE042805912", "hash_ssdeep": "3072:vKkr49g3mQi7Esiz1S89RkHRvQYlNJ+d28mHRlRr:Prqg3mj7EsQS89Kxx3M2dlR", "hash_imp": "E3919B702EC45B7A5C0DE4EED6F36CF0", "hash_pesha1": "3AD1C9C38361D3297101F037C2E2ACF5913EA911", "hash_pe256": "10D5B40BA92C77E086C619615DDF7E2565AB4CDDBE56F8E64D8330E938B7B649", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Session Host Server Sign Tool", "meta_original_filename": "TSSignTool.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/2da5d38a23c4fca4c44957f392256e3a761f90c1c4f5789513a265023b837117/detection", "output": "All rdp file(s) have been succesfully signed.\r\n", "error": "NAME\r\n\r\nrdpsign [options] [items to sign]\r\n\r\nOPTIONS\r\n\r\n /sha256 HASH\r\n Specified the SHA256 hash of the signing certificate.\r\n /q\r\n Quiet mode: No output when success, minimal output when failed.\r\n /v\r\n Verbose mode: Display all warnings, messages, and status.\r\n /l\r\n Test signing and output results without actually replacing any of the inputs. Ignores when input files are on stdin.\r\n\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\rdpsign.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "rdrleakdiag.exe-C04F4FB2C7B44E19E85908459D3F0085": { "file_name": "rdrleakdiag.exe", "file_path": "C:\\Windows\\system32\\rdrleakdiag.exe", "hash_md5": "C04F4FB2C7B44E19E85908459D3F0085", "hash_sha1": "5352E3C56E4AB1C017CC4571423B3EC9C2629B39", "hash_sha256": "D66E1EE7970598A5F34FD4B468B5B7705219E80A8A2784E7B18564831FCA797C", "hash_sha384": "35BFF04CEFC1F1A07B78EA3C829935F5FC81A4FDEE92B8C3BDE84E80A07F52D37F2F27E286EC59724D7DBEA5706E29E5", "hash_sha512": "81298F03B5D8EF919A4BE90C978A89B19F0945669BE682BF6FEFD35FCC4A7B121AB9F44BB55F81CCD69E079C5F6B67E441915BE58D1C5B0ED60697729AF9526F", "hash_ssdeep": "768:e9c+P7qBxdbY2rZuv/lOmhqabv28XZACDJMwxKiHHd3nyBQgpHBe/pIP6kFNco2j:GIdVuv/lOmLRdvHpt5A6kFNx5W", "hash_imp": "5D87ACDE58B6E042FB38FE42B86E9C25", "hash_pesha1": "78D441F82CBF5B4BD50AA8E4DFD1261805AFD539", "hash_pe256": "4D03657D4914B50993DAB38B70720E77F7E6A1CF1C8298070D041498E3B4DC9B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Resource Leak Diagnostic", "meta_original_filename": "RdrLeakDiag.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d66e1ee7970598a5f34fd4b468b5b7705219e80a8a2784e7b18564831fca797c/detection", "runtime_modules": [ "C:\\Windows\\system32\\rdrleakdiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll" ] }, "RDVGHelper.exe-97E71398617B6C27F39BE66C596BC4C5": { "file_name": "RDVGHelper.exe", "file_path": "C:\\Windows\\system32\\RDVGHelper.exe", "hash_md5": "97E71398617B6C27F39BE66C596BC4C5", "hash_sha1": "5DB49A1CBE7C462393FC868D82F78D5DF45CB79F", "hash_sha256": "8B578E0DC5BAC0D60B946A41C69138E30E5EB6C43B05EA706EE6D48BB3DF317A", "hash_sha384": "C113AA915D26F5EA3AF9B8BBA077D435C8EC0CDEED24C64A2BB86B780B1A297503B17E4E469423BC2AED5F85EEF59B03", "hash_sha512": "B8A9CF6929937840A36440D105D19C4C7887837D51C6F5EB77FC7B6F0CC6880523F3F83795F4B388185EB336F4FCBE9EB53B00A1878522F538801C8DD844CECE", "hash_ssdeep": "3072:aHzCxUcl66okaTi//SB7h/GrKicaXzI9ub0Ns:aTCqcRt/6irKkM9ubM", "hash_imp": "559CD49233407E243C5DA072697BEDA4", "hash_pesha1": "15688C1BAE86B579145E6F068BD93D069AE88958", "hash_pe256": "956B8BCFD0C3B70BB6B040B01C4490F6F97B4C5B5CC9DCD222596DFB6DDCAF93", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RemoteFX Helper", "meta_original_filename": "RDVGHelper.exe", "meta_product_name": "RemoteFX Helper", "meta_file_version": "1, 1, 0, 0", "meta_product_version": "0, 0, 0, 1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 2009", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8b578e0dc5bac0d60b946a41c69138e30e5eb6c43b05ea706ee6d48bb3df317a/detection", "children": "RdpSa.exe", "runtime_modules": [ "C:\\Windows\\system32\\RDVGHelper.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\WTSAPI32.dll", "C:\\Windows\\system32\\dwmapi.dll" ] }, "ReAgentc.exe-A109CC3B919C7D40E4114966340F39E5": { "file_name": "ReAgentc.exe", "file_path": "C:\\Windows\\system32\\ReAgentc.exe", "hash_md5": "A109CC3B919C7D40E4114966340F39E5", "hash_sha1": "56063A8458A9C2396D7E0C50877AA633548ADE72", "hash_sha256": "125EE07FC9D013AA89A80B742326318E30EAEF40C5EDFF283C5FFDF41F93616B", "hash_sha384": "315A0D46F51254E92CA9A61D130C19213689D861E4798B0D011347456D0A96ABEA9E36EBEC879D921CA9FA7D33E44C5A", "hash_sha512": "D045AC6C83FCCF2F3E2D7F987443691D8300F3B688E4D148DD1E8BEFD0BA3259892B6DBC9D0E0E4F6813867482FC8585D7756EFA0846C0EAA34107D83E9D83C3", "hash_ssdeep": "768:dEf6TOIasJMBVsMHKlen6VR5E71x7RJINqk4vPFk/lmyVJMx5WzC1fH:dQ6TOIasJMte8jvINqkr/lmyjg5WEfH", "hash_imp": "9A64FB4189BC3B4D80589BCA6F1350F7", "hash_pesha1": "BAC4D7E3DB56BA7D45AA33B28AF49ADFDD53C89A", "hash_pe256": "AD476DA7A6125961BE75C8998CCFCC12F19BFA6613D0836FB3006E42CF22B59F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Recovery Agent", "meta_original_filename": "reagentc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/125ee07fc9d013aa89a80b742326318e30eaef40c5edff283c5ffdf41f93616b/detection", "output": "\r\nConfigures the Windows Recovery Environment (Windows RE) and system reset.\r\n\r\nREAGENTC.EXE <command> <arguments>\r\n\r\nThe following commands can be specified:\r\n\r\n /info - Displays Windows RE and system reset configuration\r\n information.\r\n /setreimage - Sets the location of the custom Windows RE image.\r\n /enable - Enables Windows RE.\r\n /disable - Disables Windows RE.\r\n /boottore - Configures the system to start Windows RE next time the\r\n system starts up.\r\n /setbootshelllink - Adds an entry to the Reset and Restore page in the boot\r\n menu.\r\n\r\nFor more information about these commands and their arguments, type\r\nREAGENTC.EXE <command> /?.\r\n\r\n Examples:\r\n REAGENTC.EXE /setreimage /?\r\n REAGENTC.EXE /disable /?\r\n\r\nREAGENTC.EXE: Operation Successful.\r\n \r\n", "error": "\r\nConfigures the Windows Recovery Environment (Windows RE) and system reset.\r\n\r\nREAGENTC.EXE <command> <arguments>\r\n\r\nThe following commands can be specified:\r\n\r\n /info - Displays Windows RE and system reset configuration\r\n information.\r\n /setreimage - Sets the location of the custom Windows RE image.\r\n /enable - Enables Windows RE.\r\n /disable - Disables Windows RE.\r\n /boottore - Configures the system to start Windows RE next time the\r\n system starts up.\r\n /setbootshelllink - Adds an entry to the Reset and Restore page in the boot\r\n menu.\r\n\r\nFor more information about these commands and their arguments, type\r\nREAGENTC.EXE <command> /?.\r\n\r\n Examples:\r\n REAGENTC.EXE /setreimage /?\r\n REAGENTC.EXE /disable /?\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\ReAgentc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "recdisc.exe-8EF7D941809838D9672680F72F060DEC": { "file_name": "recdisc.exe", "file_path": "C:\\Windows\\system32\\recdisc.exe", "hash_md5": "8EF7D941809838D9672680F72F060DEC", "hash_sha1": "B1BDDAAC8338B1DF3754049F1E4255154F86B2D5", "hash_sha256": "B8E7C3191B077FCAF5768D8D995DD71098E1BD078719FB20D954BB19076435E7", "hash_sha384": "499F6744948A7976DC8899CD91C77A5E5F3EAB6CB6EC56E8DEC1DCCEE20C39A5964B4F02DE489307F73567E617604D4E", "hash_sha512": "1ABD487B6E280378486FF2E61E53CD8DC0D411822A2A8238612997B9F3A2BFF5131E9CDFBAEAD31DC6917F6A8A68C3C89B8C5523CC72994904092CFAF8196FB4", "hash_ssdeep": "3072:fhP2ErzTESY0QeKpy/z/wyCTBQSZAuegPO8evTq2Vq:flQSdQw/rCTBlFegEv+2V", "hash_imp": "CF2D2E3F19F6703E26A61C456DB6C3F9", "hash_pesha1": "C850B9EEFAD4BF5CFE52FBA5DD75EB7207AAC251", "hash_pe256": "6FF04338E18CBD6C4902322ACF062CB552F7E0F4B24F793603D9AC54180CC8DE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Repair Disc", "meta_original_filename": "recdisc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b8e7c3191b077fcaf5768d8d995dd71098e1bd078719fb20d954bb19076435e7/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\recdisc.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\ntdll.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\recdisc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\SHELL32.dll" ], "runtime_window_title": "Create a system repair disc" }, "recover.exe-FB2C06116CA9506829F08B8CAAE56561": { "file_name": "recover.exe", "file_path": "C:\\Windows\\system32\\recover.exe", "hash_md5": "FB2C06116CA9506829F08B8CAAE56561", "hash_sha1": "BB6745BDDE365BCF26FCA0727FF0541C3D173BDD", "hash_sha256": "DD8BC56FFB5B471B94F101C385439159B289BB9255A48EDD1F0C247F5101FDD7", "hash_sha384": "BC88FEF37801C34E43C59C8030068B4D947EDC790D2780451BD6FD46656B7A056ACF81A2422AF2F2C2C0F75B863BF11E", "hash_sha512": "430F9B8CD1B89C50DC77CA137368B391534312A278881D297E201C72F96D7BB6DFF51D84CBFE783A2F000EDBF0A049279180B66136551119B1242AC7DD2F4A4D", "hash_ssdeep": "192:EMp1/zPqoxJg1VD87N9EKVar3qy08VchbWSGS5Ajum2jWEnWy:BTRM7879UuyBVoVB62jWEnW", "hash_imp": "15EC0ACE85D3228ADCC66943670EF7D8", "hash_pesha1": "7755FF29ED30AE5989DD476939C43064DAC24309", "hash_pe256": "F1AB60DD90A424DC9ADA815829F250267CABEEB2A094C3D0877122917A92000F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Recover Files Utility", "meta_original_filename": "Recover.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/dd8bc56ffb5b471b94f101c385439159b289bb9255a48edd1f0c247f5101fdd7/detection", "output": "Recovers readable information from a bad or defective disk.\r\n\r\nRECOVER [drive:][path]filename\r\nConsult the online Command Reference in Windows Help\r\nbefore using the RECOVER command.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\recover.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "RecoveryDrive.exe-C24F3A647E1ADF08F3DE680A57BCF4FB": { "file_name": "RecoveryDrive.exe", "file_path": "C:\\Windows\\system32\\RecoveryDrive.exe", "hash_md5": "C24F3A647E1ADF08F3DE680A57BCF4FB", "hash_sha1": "74EA9E8E972F5BC73F2E5E85ED8AC112C1913FAC", "hash_sha256": "8F7FC1BFD0EEAD026F70EEEE716C150B9D128ECF89ADFDC8D01718CA0262CD88", "hash_sha384": "E999E70D0E84964B21539237A261C5865D35F0B03D2209C6471BED7309BE3D0BD2D61081DAFEDD43D9077E40B98EBE30", "hash_sha512": "86504EE37B4FBED982A492508CD7AC7F27676D596683783C640449D6BA7763E7AD6E62A77B1D16933D7D45695B5F3EC57386F26BFC2ACDBE3779A2E108B3D96E", "hash_ssdeep": "12288:g1yCMjcMrVR7KfAgiC6znSfrolOgjTlRt84lpJsmOjmmoJtl+c8lwewKrsnyVZWg:g11MrWol5FvrSjUJtdKrV47H", "hash_imp": "1100C74449370D6AC44C44BE1F34713D", "hash_pesha1": "3D61D538E230EE4FBEECA6EB408AAF8D3E6FE753", "hash_pe256": "47EF140A7721AA3D926949CC2ABC539CE9AE852DB83D7500665A8D089591827C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Recovery Media Creator", "meta_original_filename": "RECOVERYDRIVE.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8f7fc1bfd0eead026f70eeee716c150b9d128ecf89adfdc8d01718ca0262cd88/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\RecoveryDrive.exe.mui": "File", "(RW-) C:\\Windows\\Logs\\RecoveryDrive\\setupact.log": "File", "\\BaseNamedObjects\\SetupLogSection": "Section", "(RW-) C:\\Windows\\Logs\\RecoveryDrive\\setuperr.log": "File", "(RW-) C:\\Windows\\Logs\\RecoveryDrive\\diagerr.xml": "File", "(RW-) C:\\Windows\\Logs\\RecoveryDrive\\diagwrn.xml": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\RecoveryDrive.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll" ], "runtime_window_title": "Recovery Drive" }, "refsutil.exe-2004935AAA03817B27C9A2ACE8C7B854": { "file_name": "refsutil.exe", "file_path": "C:\\Windows\\system32\\refsutil.exe", "hash_md5": "2004935AAA03817B27C9A2ACE8C7B854", "hash_sha1": "93E92C9BDA5240566A5663114EC6FE9E8C7B5B8F", "hash_sha256": "7E740610DB81F36D96DDC05CA9FE15FBB0C09BFC7168E80E1FB93586C6970CFD", "hash_sha384": "A8018A572B893B22620F7F8BCD5DFC232ACB6E76DD2A5F3DCCC3DDA6F6BD87775C7EDAF1354B88930E6C9DD7A719D75D", "hash_sha512": "AABD419C591C5900856E149826DC6A6821893BBB1A9F8FF53BE064A03095F468D15ABB8277066FD4C67DF215999B84F6072DD08A1F4B6A3D292215332EF4B15A", "hash_ssdeep": "24576:VyjRzvYLnvlag4to4VtcrcDXd1d85vwL+dmSXDxGwhR:Vk7YLnvlag4to4VtcrYXd1d85v0GXzY4", "hash_imp": "140B57FE70F5016718431D3C313D32BE", "hash_pesha1": "00C6C1C5F206F0721BC87CBD12669ADAB6D20D9E", "hash_pe256": "7435FC864585D2C4AD1A3085A80A785F2403068AE1D562DBB5F35D0ECCC00CB5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "refsutil.exe", "meta_original_filename": "refsutil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7e740610db81f36d96ddc05ca9fe15fbb0c09bfc7168e80e1fb93586c6970cfd/detection", "output": "---- Commands Supported ----\r\nfixboot Repair boot sectors\r\nleak Leak Detection and Fixing\r\nsalvage Salvage operations for corrupt volume\r\ntriage Handle corruptions\r\n", "runtime_modules": [ "C:\\Windows\\system32\\refsutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "reg.exe-227F63E1D9008B36BDBCC4B397780BE4": { "file_name": "reg.exe", "file_path": "C:\\Windows\\system32\\reg.exe", "hash_md5": "227F63E1D9008B36BDBCC4B397780BE4", "hash_sha1": "C0DB341DEFA8EF40C03ED769A9001D600E0F4DAE", "hash_sha256": "C0E25B1F9B22DE445298C1E96DDFCEAD265CA030FA6626F61A4A4786CC4A3B7D", "hash_sha384": "293A81EC3B67A98E87A02B2EDEBCF5571DCB452138AF829E5440ACA29F0B2212A3F139B53DECD4107DCD007C84E4D5DD", "hash_sha512": "101907B994D828C83587C483B4984F36CAF728B766CB7A417B549852A6207E2A3FE9EDC8EFF5EEAB13E32C4CF1417A3ADCCC089023114EA81974C5E6B355FED9", "hash_ssdeep": "1536:/ZsKjopjN/cYXsuMdCAOznsA5q+oxxhRO+sAg9RyTVZiJXpnvo/vrK:FW5nspdCbzpq+iLcqjWXpvo/vm", "hash_imp": "BE482BE427FE212CFEF2CDA0E61F19AC", "hash_pesha1": "17B18DA9AC00F6F4711154E04D226E74E1FBC800", "hash_pe256": "4D4D884EC8F5B600B2D2F31A941FFD7E6F40168ACFDBD590AAE14826C5CEC509", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Console Tool", "meta_original_filename": "reg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c0e25b1f9b22de445298c1e96ddfcead265ca030fa6626f61a4a4786cc4a3b7d/detection", "output": "\r\nREG Operation [Parameter List]\r\r\n\r\r\n Operation [ QUERY | ADD | DELETE | COPY |\r\r\n SAVE | LOAD | UNLOAD | RESTORE |\r\r\n COMPARE | EXPORT | IMPORT | FLAGS ]\r\r\n\r\r\nReturn Code: (Except for REG COMPARE)\r\r\n\r\r\n 0 - Successful\r\r\n 1 - Failed\r\r\n\r\r\nFor help on a specific operation type:\r\r\n\r\r\n REG Operation /?\r\r\n\r\r\nExamples:\r\r\n\r\r\n REG QUERY /?\r\r\n REG ADD /?\r\r\n REG DELETE /?\r\r\n REG COPY /?\r\r\n REG SAVE /?\r\r\n REG RESTORE /?\r\r\n REG LOAD /?\r\r\n REG UNLOAD /?\r\r\n REG COMPARE /?\r\r\n REG EXPORT /?\r\r\n REG IMPORT /?\r\r\n REG FLAGS /?\r\r\n", "error": "ERROR: Invalid Argument/Option - '--help'.\r\nType \"REG /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\reg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "regedt32.exe-C6B24486DE73A457D582F6BEEAABC983": { "file_name": "regedt32.exe", "file_path": "C:\\Windows\\system32\\regedt32.exe", "hash_md5": "C6B24486DE73A457D582F6BEEAABC983", "hash_sha1": "B876B5C799226F6D6DBC4348B161DE8F457EA968", "hash_sha256": "A83D55C6F3FD0E634D4CD570CED654A8BDC1776027680BC3F003476E764CC499", "hash_sha384": "4ACE1A903F35E55CC5EB69BA1062426CB47956DE6D4FE2AA5C8EE60532CC2A53460C8F6979C01D2ACD3308B8FFA8B84C", "hash_sha512": "59D38AE1A915C73D565BDECB9FF10C3074B021DC2D2B144DD6636FB59BF15085C76A306F09403617065FE21A3DEC91B4F744FE63EA79004DF0DC730E14E6557C", "hash_ssdeep": "192:9cIya1bGZuqvFJscKonxSWR8ji6ZPl6cMWbxW:KIyQbQuOfx5nEXiENMWbxW", "hash_imp": "A3060EC916831020104FAE5BC9414975", "hash_pesha1": "B37CE6AFB3F6D6F557B1F7825E143635379F33C6", "hash_pe256": "855057B96229B2831E5F9FC2506043D5DDA0B7CC0E04F6F6EDA09785F52AFCCC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Editor Utility", "meta_original_filename": "regedt32.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a83d55c6f3fd0e634d4cd570ced654a8bdc1776027680bc3f003476e764cc499/detection", "children": "regedit.exe", "runtime_modules": [ "C:\\Windows\\system32\\regedt32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "regini.exe-3C91C37CE39EF6C3E6776B286EF7C295": { "file_name": "regini.exe", "file_path": "C:\\Windows\\system32\\regini.exe", "hash_md5": "3C91C37CE39EF6C3E6776B286EF7C295", "hash_sha1": "2179C42587A2C140EFF254D9C18131783C7ACD34", "hash_sha256": "C2EE2FFE2FAE173188C3568C47C8090347E6CB09085C249936DF2D52C0521DBB", "hash_sha384": "F129281A54A234F0CC7B8BE4E9E5C6CD321B02C3CDCB00E86EEF3C5897B11E2D3CC49D39D63651F13C2644F8B8E6D0E5", "hash_sha512": "953AEC7AFAD4BADBA32903736F07CE5EC4649B3A8D1BC71206DD0039A427B3D6854BD8F0BD9F5F17F7C6F9C2171639C943F49F35DAD4E67BFCB3EDB768A1AA1C", "hash_ssdeep": "768:EQwpWanLtqpGjQmwcWD5ZrOjA3dtTKvworOu+fOuuvygWLDPGlVogExyyl+/LccT:EQwBLtqpGjQmwce5ZMOZqLOL7XgWvpUR", "hash_imp": "59EADF2E64B87E9C2B8F545B5E2B4A03", "hash_pesha1": "89FC0BAA2EFBDE92F174E0548445A90EF62D3E33", "hash_pe256": "9360ABAE69DB1C6E28DBEEF080F7AF20D119CDE170F03AECB052AC1D63187E9F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Initializer", "meta_original_filename": "REGINI.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/c2ee2ffe2fae173188c3568c47c8090347e6cb09085c249936df2d52c0521dbb/detection", "error": "usage: REGINI [-m \\\\machinename | -h hivefile hiveroot]\r\n [-i n] [-o outputWidth]\r\n [-b] textFiles...\r\n\r\nwhere: -m specifies a remote Windows NT machine whose registry is to be manipulated.\r\n -h specifies a specify local hive to manipulate.\r\n -i n specifies the display indentation multiple. Default is 4\r\n -o outputWidth specifies how wide the output is to be. By default the\r\n outputWidth is set to the width of the console window if standard\r\n output has not been redirected to a file. In the latter case, an\r\n outputWidth of 240 is used.\r\n\r\n -b specifies that REGINI should be backward compatible with older\r\n versions of REGINI that did not strictly enforce line continuations\r\n and quoted strings Specifically, REG_BINARY, REG_RESOURCE_LIST and\r\n REG_RESOURCE_REQUIREMENTS_LIST data types did not need line\r\n continuations after the first number that gave the size of the data.\r\n It just kept looking on following lines until it found enough data\r\n values to equal the data length or hit invalid input. Quoted\r\n strings were only allowed in REG_MULTI_SZ. They could not be\r\n specified around key or value names, or around values for REG_SZ or\r\n REG_EXPAND_SZ Finally, the old REGINI did not support the semicolon\r\n as an end of line comment character.\r\n \r\n textFiles is one or more ANSI or Unicode text files with registry data.\r\n \r\n Some general rules are:\r\n Semicolon character is an end-of-line comment character, provided it\r\n is the first non-blank character on a line\r\n \r\n Backslash character is a line continuation character. All\r\n characters from the backslash up to but not including the first\r\n non-blank character of the next line are ignored. If there is more\r\n than one space before the line continuation character, it is\r\n replaced by a single space.\r\n \r\n Indentation is used to indicate the tree structure of registry keys\r\n The REGDMP program uses indentation in multiples of 4. You may use\r\n hard tab characters for indentation, but embedded hard tab\r\n characters are converted to a single space regardless of their\r\n position\r\n \r\n Values should come before child keys, as they are associated with\r\n the previous key at or above the value's indentation level.\r\n \r\n For key names, leading and trailing space characters are ignored and\r\n not included in the key name, unless the key name is surrounded by\r\n quotes. Imbedded spaces are part of a key name.\r\n \r\n Key names can be followed by an Access Control List (ACL) which is a\r\n series of decimal numbers, separated by spaces, bracketed by a\r\n square brackets (e.g. [8 4 17]). The valid numbers and their\r\n meanings are:\r\n \r\n 1 - Administrators Full Access\r\n 2 - Administrators Read Access\r\n 3 - Administrators Read and Write Access\r\n 4 - Administrators Read, Write and Delete Access\r\n 5 - Creator Full Access\r\n 6 - Creator Read and Write Access\r\n 7 - World Full Access\r\n 8 - World Read Access\r\n 9 - World Read and Write Access\r\n 10 - World Read, Write and Delete Access\r\n 11 - Power Users Full Access\r\n 12 - Power Users Read and Write Access\r\n 13 - Power Users Read, Write and Delete Access\r\n 14 - System Operators Full Access\r\n 15 - System Operators Read and Write Access\r\n 16 - System Operators Read, Write and Delete Access\r\n 17 - System Full Access\r\n 18 - System Read and Write Access\r\n 19 - System Read Access\r\n 20 - Administrators Read, Write and Execute Access\r\n 21 - Interactive User Full Access\r\n 22 - Interactive User Read and Write Access\r\n 23 - Interactive User Read, Write and Delete Access\r\n \r\n If there is an equal sign on the same line as a left square bracket\r\n then the equal sign takes precedence, and the line is treated as a\r\n registry value. If the text between the square brackets is the\r\n string DELETE with no spaces, then REGINI will delete the key and\r\n any values and keys under it.\r\n \r\n For registry values, the syntax is:\r\n \r\n value Name = type data\r\n \r\n Leading spaces, spaces on either side of the equal sign and spaces\r\n between the type keyword and data are ignored, unless the value name\r\n is surrounded by quotes. If the text to the right of the equal sign\r\n is the string DELETE, then REGINI will delete the value.\r\n \r\n The value name may be left off or be specified by an at-sign\r\n character which is the same thing, namely the empty value name. So\r\n the following two lines are identical:\r\n \r\n = type data\r\n @ = type data\r\n \r\n This syntax means that you can't create a value with leading or\r\n trailing spaces, an equal sign or an at-sign in the value name,\r\n unless you put the name in quotes.\r\n \r\n Valid value types and format of data that follows are:\r\n \r\n REG_SZ text\r\n REG_EXPAND_SZ text\r\n REG_MULTI_SZ \"string1\" \"str\"\"ing2\" ...\r\n REG_DATE mm/dd/yyyy HH:MM DayOfWeek\r\n REG_DWORD numberDWORD\r\n REG_BINARY numberOfBytes numberDWORD(s)...\r\n REG_NONE (same format as REG_BINARY)\r\n REG_RESOURCE_LIST (same format as REG_BINARY)\r\n REG_RESOURCE_REQUIREMENTS (same format as REG_BINARY)\r\n REG_RESOURCE_REQUIREMENTS_LIST (same format as REG_BINARY)\r\n REG_FULL_RESOURCE_DESCRIPTOR (same format as REG_BINARY)\r\n REG_QWORD numberQWORD\r\n REG_MULTISZ_FILE fileName\r\n REG_BINARYFILE fileName\r\n \r\n If no value type is specified, default is REG_SZ\r\n \r\n For REG_SZ and REG_EXPAND_SZ, if you want leading or trailing spaces\r\n in the value text, surround the text with quotes. The value text\r\n can contain any number of imbedded quotes, and REGINI will ignore\r\n them, as it only looks at the first and last character for quote\r\n characters.\r\n \r\n For REG_MULTI_SZ, each component string is surrounded by quotes. If\r\n you want an imbedded quote character, then double quote it, as in\r\n string2 above.\r\n \r\n For REG_BINARY, the value data consists of one or more numbers The\r\n default base for numbers is decimal. Hexidecimal may be specified\r\n by using 0x prefix. The first number is the number of data bytes,\r\n excluding the first number. After the first number must come enough\r\n numbers to fill the value. Each number represents one DWORD or 4\r\n bytes. So if the first number was 0x5 you would need two more\r\n numbers after that to fill the 5 bytes. The high order 3 bytes\r\n of the second DWORD would be ignored.\r\n \r\n Whenever specifying a registry path, either on the command line\r\n or in an input file, the following prefix strings can be used:\r\n \r\n HKEY_LOCAL_MACHINE\r\n HKEY_USERS\r\n HKEY_CURRENT_USER\r\n USER:\r\n \r\n Each of these strings can stand alone as the key name or be followed\r\n a backslash and a subkey path.\r\n\r\n\r\nREGINI: Missing parameter(s) for -h switch\r\n", "runtime_modules": [ "C:\\Windows\\system32\\regini.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "Register-CimProvider.exe-F9F77EB472F58EDEBCFEA7B51FFC6EEA": { "file_name": "Register-CimProvider.exe", "file_path": "C:\\Windows\\system32\\Register-CimProvider.exe", "hash_md5": "F9F77EB472F58EDEBCFEA7B51FFC6EEA", "hash_sha1": "087B259400C4E523144A4A829610BF589BDE125B", "hash_sha256": "5311C4B92BDA7852580C8DF50922F8328EB5A238012F10DED7B38DC3B9D00D8E", "hash_sha384": "E3BBE473967D2EE8387AA90656F9AB4554AAE5BF8AD9A3C81652C4C8015D2A96DCA6E6FF3F25580051B0AEBA0FA5DEA2", "hash_sha512": "0C6D1BDCEEA5FD5E7DE2B47B4961E596E45FCB9237EE8B42CC9BBD93AB8F627CA919F3FCA744B701BAFB269E45C7BF4955268CA408926F10AD3DF200495F7BFA", "hash_ssdeep": "384:VNV1h6Bch1F9FajPameTrsv4LfDnexElF4dkEZfp1NJZ7ysl2RZPGPWrHo34Wxwq:/96BcEoYdx44FXlJl0gsHo34WxA", "hash_imp": "657445DD05A7049E92510D26B786C072", "hash_pesha1": "91802BF3383560B9892C7CFD77F60AE5BEF79DE8", "hash_pe256": "D8C41016DF1B7860E483981419B13DECCE7F62FED3FBB9A18CB07E2F13BDAB51", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI", "meta_original_filename": "Register-CimProvider2.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5311c4b92bda7852580c8df50922f8328eb5a238012f10ded7b38dc3b9d00d8e/detection", "output": "\r\nRegisters CIM Provider into system\r\n\r\nUsage: Register-CimProvider.exe\r\n\t\t-Namespace <NamespaceName>\r\n\t\t-ProviderName <ProviderName>\r\n\t\t-Path <ProviderDllPath>\r\n\t\t[-ClassList <Space delimited list of white-listed classes>]\r\n\t\t[-Impersonation <True or False>]\r\n\t\t[-Decoupled <SDDL>]\r\n\t\t[-HostingModel <HostingModel>]\r\n\t\t[-Localize <locale>]\r\n\t\t[-NoAutorecover]\r\n\t\t[-SupportWQL]\r\n\t\t[-GenerateUnregistration]\r\n\t\t[-ForceUpdate]\r\n\t\t[-Verbose]\r\n\r\n-Namespace <NamespaceName>\r\n\tSpecifies the target namespace of the provider.\r\n\r\n-ProviderName <ProviderName>\r\n\tSpecifies the provider name.\r\n\r\n-Path <ProviderDllPath>\r\n\tSpecifies the provider binary path.\r\n\r\n-Impersonation <True or False>\r\n\tSpecifies foldidentity of decoupled provider, by default is True.\r\n\r\n-Decoupled <SDDL>\r\n\tRegisters provider as decoupled and specifies the security descriptor\r\n\tthat determines the set of users that can successfully register\r\n\tthe provider.\r\n\r\n-HostingModel <HostingModel>\r\n\tSpecifies the HostingModel of coupled provider.\r\n\r\n-Localize <locale>\r\n\tLocalizes the provider with resource of specified locale.\r\n\r\n-NoAutorecover\r\n\tDoesn't autorecover the provider.\r\n\r\n-SupportWQL\r\n\tPasses the query expression to the filter.\r\n\r\n-GenerateUnregistration\r\n\tGenerate the uninstall mof for the registration,\r\n\twhich is disabled by default.\r\n\r\n-ForceUpdate\r\n\tForce update the class if it exists in the system.\r\n\r\n-ClassList <ProviderDllPath>\r\n\tSpecifies space delimited list of white-listed classes that\r\n\twill be generated in the mof.\r\n\r\n-Verbose\r\n\tOutputs registration log.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\Register-CimProvider.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "regsvr32.exe-B0C2FA35D14A9FAD919E99D9D75E1B9E": { "file_name": "regsvr32.exe", "file_path": "C:\\Windows\\system32\\regsvr32.exe", "hash_md5": "B0C2FA35D14A9FAD919E99D9D75E1B9E", "hash_sha1": "8D7C2FD354363DAEE63E8F591EC52FA5D0E23F6F", "hash_sha256": "022CB167A29A32DAE848BE91AEF721C74F1975AF151807DAFCC5ED832DB246B7", "hash_sha384": "33DD9542ABAB5ADFEE1BF775C51C08DA8FBCDDC5F8E2C9E00EF8BEEB15EE02DD4C8F401309DE702A14C25AB340F2084C", "hash_sha512": "A6155E42B605425914D1BF745D9B2B5ED57976E161384731C6821A1F8FA2BC3207A863AE45D6AD371AC82733B72BB024204498BAA4FB38AD46C6D7BC52E5A022", "hash_ssdeep": "384:n5Y3wBQ8l/m60z+G7XU9I6ExBOMDl16AvcX9dp/Ql7YQCrA2WrcLHW:n5Yg3l/mTRXU9FeGpX9dp/47tCnL", "hash_imp": "0235FF9A007804882636BCCCFB4D1A2F", "hash_pesha1": "3724FC650D475C9C7408B9723D0F65BACD0C3B67", "hash_pe256": "D3E19AB1F4DDF4F88A495E7660CCF47EF9945C4EEFFD5FC2D8D826CA7F932AEF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft(C) Register Server", "meta_original_filename": "REGSVR32.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/022cb167a29a32dae848be91aef721c74f1975af151807dafcc5ed832db246b7/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\regsvr32.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\regsvr32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll" ], "runtime_window_title": "RegSvr32" }, "rekeywiz.exe-332C1F483F179A7C5DDF548CF3259032": { "file_name": "rekeywiz.exe", "file_path": "C:\\Windows\\system32\\rekeywiz.exe", "hash_md5": "332C1F483F179A7C5DDF548CF3259032", "hash_sha1": "D1EDB2425F730BF9F482798DBCB8C194F7321764", "hash_sha256": "A56393270663BF591D0269692536F6BA2E0909A11879201F6EDC7FF2A80F13AB", "hash_sha384": "655DBE06D1CD3F1F8BB7815558350CF46343A6D04B97E4C92EC2209D8673FD702050CE71EE74F6322F08458C8E214450", "hash_sha512": "D0E0DA964A1F085D2DFBF769E0246A29626AC771FC5997BD497F2C47144E5594E9533D2B2EF5DA9919B56527D2B0686562A782A38D32413109447E95E40CEDCC", "hash_ssdeep": "3072:BeD3ukOY+6P0b12kd4U0ph2RQvkyvt7fBdh:BejukOY+6P629U0ph2ahvt7fBd", "hash_imp": "0186B48C4B71FBB2942FA3FE4E920D76", "hash_pesha1": "2031F95549D9F7FB2DDFDC8F4C427C56240E022B", "hash_pe256": "3E9A59D9545A860D32740A02AE209DA92240A6B7EE8D9918F45303ADAFFE6909", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EFS REKEY wizard", "meta_original_filename": "rekeywiz.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/a56393270663bf591d0269692536f6ba2e0909a11879201f6edc7ff2a80f13ab/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\efsadu.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\rekeywiz.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\rekeywiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\EFSADU.dll", "C:\\Windows\\system32\\MPR.dll" ], "runtime_window_title": "Encrypting File System" }, "relog.exe-1178E44A76AF0C15D307B292A734F0E3": { "file_name": "relog.exe", "file_path": "C:\\Windows\\system32\\relog.exe", "hash_md5": "1178E44A76AF0C15D307B292A734F0E3", "hash_sha1": "DF6A9E2EF04F2C4CD46319D475FEDF87148C6EDE", "hash_sha256": "67A91A332E3FE5444AC17489806709E5430A47AAFBCF3AD57EF2A849F599A3CC", "hash_sha384": "5438456579A3223DF538DA7A57646B31184B2BDDF81409B6B7655F05929778E3D732303679656671BE135C583FBAB415", "hash_sha512": "2CF21230EB8E5D1FC7C8C8BB3CF4E2A7514C291B79B2748B2B1BDAAAC6B541584BAA1F3C5DFB4A808A243F1E7E79955B524E54C2CFE5A843309BE0AADAC8AA24", "hash_ssdeep": "1536:rpHBWxPFzEpyAr6tRLBAGbRh45w991G+QY2s/Zp8:+rA8PyAf4AG+v2kZO", "hash_imp": "B09E7B2A179D74583FD66AEE5A7A267B", "hash_pesha1": "AEE7720313A38300B068DCD2EAEFC8FB6BD0AA7A", "hash_pe256": "71D5F99D8E9B4E294B60770EB3F32EA41CC71DE2A83723A212D75D8B69AF9595", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Performance Relogging Utility", "meta_original_filename": "Relog.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/67a91a332e3fe5444ac17489806709e5430a47aafbcf3ad57ef2a849f599a3cc/detection", "output": "\r\nMicrosoft r Relog.exe (10.0.19041.546)\r\n\r\nRelog creates new performance logs from data in existing performance logs by\r\nchanging the sampling rate and/or converting the file format. Supports all\r\nperformance log formats, including Windows NT 4.0 compressed logs.\r\n\r\nUsage:\r\nC:\\Windows\\system32\\relog.exe <filename [filename ...]> \r\n [options]\r\n\r\nParameters:\r\n <filename [filename ...]> Performance file to relog.\r\n\nOptions:\r\n -? Displays context sensitive help.\r\n -a Append output to the existing binary file.\r\n -c <path [path ...]> Counters to filter from the input log.\r\n -cf <filename> File listing performance counters to filter\r\n from the input log. Default is all counters\r\n in the original log file.\r\n -f <CSV|TSV|BIN|SQL> Output file format.\r\n -t <value> Only write every nth record into the output\r\n file. Default is to write every record.\r\n -o Output file path or SQL database.\r\n -b <M/d/yyyy h:mm:ss[AM|PM]> Begin time for the first record to write into\r\n the output file.\r\n -e <M/d/yyyy h:mm:ss[AM|PM]> End time for the last record to write into\r\n the output file.\r\n -config <filename> Settings file containing command options.\r\n -q List performance counters in the input file.\r\n -y Answer yes to all questions without prompting.\r\n\r\nExamples:\r\n relog logfile.csv -c \"\\Processor(_Total)\\% Processor Time\" -o logfile.blg\r\n relog logfile.blg -cf counters.txt -f bin\r\n relog logfile.blg -f csv -o logfile.csv -t 2\r\n relog logfile.blg -q -o counters.txt\r\n", "runtime_modules": [ "C:\\Windows\\system32\\relog.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "RelPost.exe-E351DDC4F470EDEF41D705315CA1F156": { "file_name": "RelPost.exe", "file_path": "C:\\Windows\\system32\\RelPost.exe", "hash_md5": "E351DDC4F470EDEF41D705315CA1F156", "hash_sha1": "E78D010C9F068709F495A31D319568330A1781FC", "hash_sha256": "509A5A06F26E7CD8FED50D39D36D32D617887F04FDD8EDC2546254DF61C1132F", "hash_sha384": "61EE458F783F495843ECF18C03EF3D416D479CB1EB55D59B786C13A05C023389A34EF5A3DBF054E2EE548ADA1A5DC6D8", "hash_sha512": "52574C86E8216E4A2A9D779399E7921EF54DDD7E8EF33CBE528B2A07058615836BDA6E3B5F941BB977CD378EBA20224B1003042C7EF23B374882CDED78AD3127", "hash_ssdeep": "3072:xyFp9kpKealesPggZISSa7Je3xNZopLGnAuegPO8evTq2V:mp9kpKpelINJOtFegEv+2V", "hash_imp": "3A7C5EC633F86929A4C13B843E65A4F9", "hash_pesha1": "15E7229AEAE87920BCBB0A30E9926A986FA46F64", "hash_pe256": "F850D897A897FD49D042AEC94122E45583175328DE9C3C67CBA4EE5C103E898A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Diagnosis and Recovery", "meta_original_filename": "RelPost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/509a5a06f26e7cd8fed50d39d36d32d617887f04fdd8edc2546254df61c1132f/detection", "runtime_modules": [ "C:\\Windows\\system32\\RelPost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "RemoteAppLifetimeManager.exe-86DB277AD39E4F0D78212F44FDF0471F": { "file_name": "RemoteAppLifetimeManager.exe", "file_path": "C:\\Windows\\system32\\RemoteAppLifetimeManager.exe", "hash_md5": "86DB277AD39E4F0D78212F44FDF0471F", "hash_sha1": "D231D8079C4C9715392A29AD6872A8A4C812346D", "hash_sha256": "E4940A4E264098B8BD5C26B4621884C1465025563CF67E0C93AF40BD990A1999", "hash_sha384": "0895E17E765C0EF67152D4AF6E981A4A46F4250649C217664740BEAF036BEF5B1C23ABA009F5191940CFDFCBD4BA009B", "hash_sha512": "CB1C1B6CD9FB3A04FAB961E10DEE63B87DA5493D694960270096C89296B27BA155FE72ECEE581F98930239C234C10DD36114BA249E7D27C2F9D76150131D04B2", "hash_ssdeep": "1536:tk2yS4wz789Xfwx3kG/qsganNZGRgvO9EMl91SccyyyxyyyFfJDg8TBSb/1gk0dv:KS/89vwl7/tpNouvWEMlrzwUBj1Odv", "hash_imp": "AA11F76B1D188438E1F1736A36B77400", "hash_pesha1": "806627676AEB88CEB1182B324DA79D2793874B09", "hash_pe256": "3B087BBD6F5D3643588D2E42244C7D65C3C9AB68590F9C564EAD4B8181C57BE8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RemoteAppLifetimeManager_ServerExe.exe", "meta_original_filename": "RemoteAppLifetimeManager_ServerExe.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e4940a4e264098b8bd5c26b4621884c1465025563cf67e0c93af40bd990a1999/detection", "runtime_modules": [ "C:\\Windows\\system32\\RemoteAppLifetimeManager.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "RemoteFXvGPUDisablement.exe-0718AA4C9BD4A64231A92672B36BCDA9": { "file_name": "RemoteFXvGPUDisablement.exe", "file_path": "C:\\Windows\\system32\\RemoteFXvGPUDisablement.exe", "hash_md5": "0718AA4C9BD4A64231A92672B36BCDA9", "hash_sha1": "EDBC95E7D5A3F93F851950AB75C5EC182757824A", "hash_sha256": "CFCF444DDB908A89DC7C0C279D320F960FAC3BA5D64E631370CD7357D4003880", "hash_sha384": "D2B744813FA5DAF6063306560BA4A2DBA85C91437DCE4F11FB861C0CEB3CD78A5CE2C67BEE1D9F5AF80585C9064334D4", "hash_sha512": "A2664413B5B12090D94F472317764DA9D983359222770C78AE6905CCB45276C4D786FC34A3B12FF8904F1376597CAEE582111B36463771581A7D24ADFE988621", "hash_ssdeep": "192:j2sL84qxeU25tRTOzRDnEtzMPUOYA0svGS0qTYRWlofWi:MeU29TO9Et0UOB3kRWlofW", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "020E641B1E1FD6B0639CEFF3BE973363B29D2DC4", "hash_pe256": "DD0B154805FC7A56587EBF6F067C76F94AC34CEC30255AE0AAFAE3CF6D0F152F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "RemoteFXvGPUDisablement.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.388", "meta_product_version": "10.0.19041.388", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/cfcf444ddb908a89dc7c0c279d320f960fac3ba5d64e631370cd7357d4003880/detection", "runtime_modules": [ "C:\\Windows\\system32\\RemoteFXvGPUDisablement.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "RemotePosWorker.exe-958717B8839C0148B3226CDF343EE8E9": { "file_name": "RemotePosWorker.exe", "file_path": "C:\\Windows\\system32\\RemotePosWorker.exe", "hash_md5": "958717B8839C0148B3226CDF343EE8E9", "hash_sha1": "A7F5A5A01A5D785FECC1EB6679E4B0A8FE72606D", "hash_sha256": "2868B0CC04E8DC5A415DAED0FEFEC08430261FAE6B5707A83A848EDF8BF24DA7", "hash_sha384": "882E19683BD3B76ED95DE9B9746E017EAA471C937D5B30944572501C4C1E6FDCDC66ADAFF9655973EAA8001857213998", "hash_sha512": "BADD5D814077A2417533A473E6AFD5E962B632C962DC46F245A538DCBB55D96817700415FC25373D698E37B3D67401B11C3A6E9806D00AF7CB4AC4B0D59DF961", "hash_ssdeep": "192:PZzjVeQ6z/Q7d5o4tUdSm6DOHysW9Okd4qigseaRluWq7W:PZzjVeQpd59mdZ5WskFWRIWq7W", "hash_imp": "C6E4FB88ABA54E5E339120511BB8F20D", "hash_pesha1": "726279907EC3D3AAC8C7E412DCD27D5B7BF6D41C", "hash_pe256": "43114A7BD2C917E8081BD9F03574A9FB116B9AAD7F6BA43D3D402553C6C85D84", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Pos Driver Worker", "meta_original_filename": "RemotePosWorker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/2868b0cc04e8dc5a415daed0fefec08430261fae6b5707a83a848edf8bf24da7/detection", "runtime_modules": [ "C:\\Windows\\system32\\RemotePosWorker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "repair-bde.exe-9FA5C71841FDE30C7D62CC95E5389E6A": { "file_name": "repair-bde.exe", "file_path": "C:\\Windows\\system32\\repair-bde.exe", "hash_md5": "9FA5C71841FDE30C7D62CC95E5389E6A", "hash_sha1": "B00760877633FB4A34FCE53C1C5142F2FFD43284", "hash_sha256": "13930144928B4C55AC75120678F3C523B6E6E1730B0E5BC972A15FAEAE399259", "hash_sha384": "5B0087441AD8ECDAA326ACE1605B5F71FBA1BD2E0BAB3BFEAEB4648D54D556E9DA336F89335348F07956449E2AB5B877", "hash_sha512": "B37C82EC0F6ECAB0887263BE677B1A1D6CFCABB775D22C4AF62A22AE544D6BDE8B31D2F99CB3BCBCD9A9C160692F69EFDAEEF387596434A3971D2E1E0EBDE412", "hash_ssdeep": "3072:Tv2Xi0hGCIG1PfGWxa637wnVS570M9kdatGCO+xmBc+hMPhPsx:Tv2Xi0hGCZUWaVs7nyatGt+SYF", "hash_imp": "E79D89F81C99F2656B81FFE7397F88D7", "hash_pesha1": "523ABD30F512707F47FCAC99439C0C4481913D15", "hash_pe256": "DB39A2344C3E436899EA9A2295302688E9E2F4FA0A741E0806D091F5D8B4A7BC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BitLocker Drive Encryption: Repair Tool", "meta_original_filename": "repair-bde.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/13930144928b4c55ac75120678f3c523b6e6e1730b0e5bc972a15faeae399259/detection", "output": "BitLocker Drive Encryption: Repair Tool version 10.0.19041\r\r\nCopyright (C) 2013 Microsoft Corporation. All rights reserved.\r\r\n\r\r\nUsage:\r\r\n\r\r\nrepair-bde[.exe] InputVolume\r\r\n { OutputVolumeOrImage }\r\r\n { {-RecoveryPassword|-rp} NumericalPassword |\r\r\n {-RecoveryKey|-rk} PathToExternalKeyFile |\r\r\n {-Password|-pw} }\r\r\n [{-KeyPackage|-kp} PathToKeyPackage]\r\r\n [{-LogFile|-lf} PathToLogFile]\r\r\n [{-?|/?}]\r\r\n\r\r\nDescription:\r\r\n Attempts to repair or decrypt a damaged BitLocker-encrypted volume using the\r\r\n supplied recovery information. If BitLocker was in the process of encryption\r\r\n or decryption or had been suspended prior to volume failure a clear key will\r\r\n be present on the volume. Repair-bde attempts to use this clear key by\r\r\n default if another key is not specified.\r\r\n\r\r\n WARNING! To avoid additional data loss, you should have a spare hard drive\r\r\n available. Use this spare drive to store decrypted output or to back up the\r\r\n contents of the damaged volume. \r\r\n\r\r\nParameters:\r\r\n InputVolume\r\r\n The BitLocker-encrypted volume to repair.\r\r\n Example: \"C:\",\r\r\n \"\\\\?\\Volume{26a21bda-a627-11d7-9931-806e6f6e6963}\".\r\r\n\r\r\n OutputVolumeOrImage\r\r\n The volume to store decrypted contents, or the file\r\r\n location to create an image file of the contents.\r\r\n Examples: \"D:\", \"D:\\imagefile.img\".\r\r\n \r\r\n WARNING! All information on this output volume will be\r\r\n overwritten.\r\r\n\r\r\n -rk or -RecoveryKey\r\r\n Provide an external key to unlock the volume. \r\r\n Example: \"F:\\RecoveryKey.bek\".\r\r\n\r\r\n -rp or -RecoveryPassword\r\r\n Provide a numerical password to unlock the volume.\r\r\n Example: \"111111-222222-333333-...\".\r\r\n\r\r\n -pw or -Password\r\r\n Provide a password to unlock the volume.\r\r\n\r\r\n -kp or -KeyPackage\r\r\n Optional. Provide a key package to unlock the volume.\r\r\n Example: \"F:\\ExportedKeyPackage\"\r\r\n \r\r\n If this option is blank, the tool will look for the key package\r\r\n automatically. This option is needed only if required by the tool.\r\r\n\t\r\r\n -lf or -LogFile\r\r\n Optional. Provide a path to a file that will store progress\r\r\n information. Example: \"F:\\log.txt\".\r\r\n\r\r\n -f or -Force\r\r\n Optional. When used, forces a volume to be dismounted even if\r\r\n it cannot be locked. This option is needed only if required by\r\r\n the tool.\r\r\n\r\r\n -? or /? \r\r\n Shows this screen.\r\r\n\r\r\nExamples:\r\r\n repair-bde C: D: -rk F:\\RecoveryKey.bek -Force\r\r\n repair-bde C: D: -rp 111111-222222-[...] -lf F:\\log.txt\r\r\n repair-bde C: D: -kp F:\\KeyPackage -rp 111111-222222-[...]\r\r\n repair-bde C: D:\\imagefile.img -kp F:\\KeyPackage -rk F:\\RecoveryKey.bek\r\r\n repair-bde C: D: -pw\r\r\n\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\repair-bde.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "replace.exe-38BE568DCB9A7C5FE665DB6EE29B1ECF": { "file_name": "replace.exe", "file_path": "C:\\Windows\\system32\\replace.exe", "hash_md5": "38BE568DCB9A7C5FE665DB6EE29B1ECF", "hash_sha1": "A0A8A7FFDEE19D0620BD21CEB11E6AA92D5B3265", "hash_sha256": "EA3F7FBEC756AC2F7CC26659BE3F70637DDD892BC67127777B2BCD0605B2CCF1", "hash_sha384": "44860B22152E921A5C0A6A278FF58AF85BA51AE04FE9E6F15861CC9A25635CD572A161C384D15C8292620D7EC337B3AC", "hash_sha512": "2FE8B04FF5B4810A2EF03A378832432A291F112640261D070CE5CE15C5D67198468E56B18AECAB26FB104CFC35EF56A2133867B8EE3D3BF8727533F532695798", "hash_ssdeep": "384:rfm4Vaq2i9N6hiXiOnPHxgawFmrU6iD3Bc8s6xXaTjdW2h/W:7nVuHsRrwF593SPAaTjL", "hash_imp": "7F915E73EEE8F7CA67BD9BA9264315DA", "hash_pesha1": "23FB5DFB3935ED63D4464202942EBB2693EDF4B8", "hash_pe256": "2C54E731DA6BCE84A5980C533F9E077E03E412E45ED413549D31046C5A85A7AA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Replace File Utility", "meta_original_filename": "REPLACE.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ea3f7fbec756ac2f7cc26659be3f70637ddd892bc67127777b2bcd0605b2ccf1/detection", "output": "Replaces files.\r\n\r\nREPLACE [drive1:][path1]filename [drive2:][path2] [/A] [/P] [/R] [/W]\r\nREPLACE [drive1:][path1]filename [drive2:][path2] [/P] [/R] [/S] [/W] [/U]\r\n\r\n [drive1:][path1]filename Specifies the source file or files.\r\n [drive2:][path2] Specifies the directory where files are to be\r\n replaced.\r\n /A Adds new files to destination directory. Cannot\r\n use with /S or /U switches.\r\n /P Prompts for confirmation before replacing a file or\r\n adding a source file.\r\n /R Replaces read-only files as well as unprotected\r\n files.\r\n /S Replaces files in all subdirectories of the\r\n destination directory. Cannot use with the /A\r\n switch.\r\n /W Waits for you to insert a disk before beginning.\r\n /U Replaces (updates) only files that are older than\r\n source files. Cannot use with the /A switch.\r\n", "error": "Invalid switch - --help\r\n", "runtime_modules": [ "C:\\Windows\\system32\\replace.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "reset.exe-FE84BB8BBAA4FA1FD3892BE328E78A3F": { "file_name": "reset.exe", "file_path": "C:\\Windows\\system32\\reset.exe", "hash_md5": "FE84BB8BBAA4FA1FD3892BE328E78A3F", "hash_sha1": "C4461ABC06352B344ACBB045E8BDB955A7BCF85E", "hash_sha256": "0F45EE243CDC2AAEC85DC18B686A86B18D3416729751F273FC094DA0A5BCCF07", "hash_sha384": "B6C6C2A02DD2EAD7537B3E7F68415E2C52CAB431DAB33B6EAD84DB6D20DA9B2972863B01A2E3843C356076BCFFC673B5", "hash_sha512": "ABB113470F260496E8E905A9C482EA19636A9B2ED3B08B7D5B5B49823E41259CA30B593A687FA146E185CABD7192EFE74281E48AB84A336F556FAE8A474A2EBB", "hash_ssdeep": "192:/bOsPg02O0EAMuDzEAk3ZsThGdgo8jJIbO4kekhwxxth2GcDKI12m6W7gW:/bO5Z1M/Kg7y2bzyOxth20Cj6W7gW", "hash_imp": "CCC9DA4A55E90DFE34CBCDB066D6A6B3", "hash_pesha1": "9EDC7BAD27E6FAC0CB86D091E1C1143A24A772B6", "hash_pe256": "32D809B75186F9DF9444D05EEC916CADAFD1E87AB46C5763D46570F4C93AF519", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Services Reset Utility", "meta_original_filename": "reset.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/0f45ee243cdc2aaec85dc18b686a86b18d3416729751f273fc094da0a5bccf07/detection", "output": "RESET { SESSION }\r\n", "error": "Invalid parameter(s)\r\nRESET { SESSION }\r\n", "runtime_modules": [ "C:\\Windows\\system32\\reset.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ResetEngine.exe-5D20EF28D0B222CA57F47524F2D3E8C0": { "file_name": "ResetEngine.exe", "file_path": "C:\\Windows\\system32\\ResetEngine.exe", "hash_md5": "5D20EF28D0B222CA57F47524F2D3E8C0", "hash_sha1": "D02A33A2E1BABAE5C7FF753800B5AD1C930A708C", "hash_sha256": "E91DE86C7BE50A588EFFA24707B2EFC4D51A7728C8D1DB281F5334B34284AE67", "hash_sha384": "817C584A1F71CCC73B0ABBE524107F3E617E4F6BAD02ACBB32263E5CCDF3CAF79AB6484B64850ED251F87675B53C3C91", "hash_sha512": "239FBDB12F9E762B1E752418030D0FD972EF0C4342B6A302CBCA91101554F12630418C600329D47A663A65DB91875A85B1414B5BDE9F517C47AF98EC06145622", "hash_ssdeep": "384:d3lfHLUNi4m1mglACsRW3eWsr6wDDBRJ6imfklIc9Q2:TrCvglhsOsr6wD1P7Q2", "hash_imp": "D1CCC9D0A0240603DC3279F82F80F8D3", "hash_pesha1": "35099986A419B5DCDB4F05058CB205AB936FDF0A", "hash_pe256": "9645C0A39EA595FCC1DA453FCD27485EC7BC2DDDB1947D2397C19C5128BF326D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Push-Button Reset Engine", "meta_original_filename": "RESETENGINE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.630 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.630", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e91de86c7be50a588effa24707b2efc4d51a7728c8d1db281f5334b34284ae67/detection", "children": [ "csrss.exe", "winlogon.exe" ], "runtime_modules": [ "C:\\Windows\\system32\\ResetEngine.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "resmon.exe-852ACA89972551B00B110EEE6ADA717A": { "file_name": "resmon.exe", "file_path": "C:\\Windows\\system32\\resmon.exe", "hash_md5": "852ACA89972551B00B110EEE6ADA717A", "hash_sha1": "E1DB406505EC0492825E83D81C9C0274C1ACF1AD", "hash_sha256": "4C0BDF906AF0C1FDBC9FA61BF2AF95C708498F5AFE8E05C65E865E99DEAC8716", "hash_sha384": "3BECAD8F946B4B7A1D2A16ADC98A4EF7BA372A4086A050C50241E333C7C90EDDAA507FD530380DAF8A7BF63BCBF7708A", "hash_sha512": "9E388B1325CFDA2597428D9B44EE48B491D29DBF0840065DEAC7C75F3647757EEFD8AA5D1E8B33AA119C742EB71751FA94B66B47574C9A4F65A5F25025372664", "hash_ssdeep": "1536:5EZgvhlKBqY3KtrtizIo9plJSs9kYuZJnGZLzOcE6Ls7HXG84PK05Z34g/CO+sH:c6KghtYIo9piswTogiqQKy349", "hash_imp": "C489853A1F490DCDAEA1E10E57C136E4", "hash_pesha1": "4A85AF6DCFFFA70C9CCFDD570444F551A5FABB1F", "hash_pe256": "1A945D89A85BBD00490D29DF7A12C400EF02D3F5EE1353C2BF9388598686792F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resource Monitor", "meta_original_filename": "resmon.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/4c0bdf906af0c1fdbc9fa61bf2af95c708498f5afe8e05c65e865e99deac8716/detection", "children": "perfmon.exe", "runtime_modules": [ "C:\\Windows\\system32\\resmon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll" ] }, "RMActivate.exe-7AB107EB402094077ABB814A370DA5D2": { "file_name": "RMActivate.exe", "file_path": "C:\\Windows\\system32\\RMActivate.exe", "hash_md5": "7AB107EB402094077ABB814A370DA5D2", "hash_sha1": "E7C52FB9C3A1DFABA7FA171C378C028764BF3ABB", "hash_sha256": "E5AED34EEA1160D2E0674C3373420CB486E68DFA81C3B32A8174963140AB2A5D", "hash_sha384": "AF1642CF1F42C544028E9F31A8EAC0498AA5C6FBBAAB4F9DC1E76ABB4EEDB56F72EF7DC3A54D40B545A6823F0D54F4EB", "hash_sha512": "E6CE040E37ED72DA14FAC2D1CC82216341A06856C12BEBD170521C0EA89463688A86DF568CEB2BB0013C695CF98D723AF7A8D99FF49B09D358FFBC39F8ACCE69", "hash_ssdeep": "12288:OMQ+mXYIKPPOKfv1sUxVsZbzjSWaT6rLW1Yf2TyIFHCKMt:xmKPl1txmaDT6STJHCKM", "hash_imp": "A64B00149541ECB0FA84FD98B79BF54D", "hash_pesha1": "493B2F611942EB9DF37BC00F37C0CB6412988F27", "hash_pe256": "4BD5A4C8DB3078F8106BB22EDDF149B999E91B3FAAFE98D2477A42B4D21AD0F9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Desktop Security Processor", "meta_original_filename": "rmactivate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e5aed34eea1160d2e0674c3373420cb486e68dfa81c3b32a8174963140ab2a5d/detection", "runtime_modules": [ "C:\\Windows\\system32\\RMActivate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "RMActivate_isv.exe-2B7EEFC12AE63E19DD2D95870312117D": { "file_name": "RMActivate_isv.exe", "file_path": "C:\\Windows\\system32\\RMActivate_isv.exe", "hash_md5": "2B7EEFC12AE63E19DD2D95870312117D", "hash_sha1": "6767A420F1B2899C05CD72A120D6BBCA6DA1921D", "hash_sha256": "29638E099F526F7AC9E85099BD380122A6CB4C656BC24837639B62FF11910254", "hash_sha384": "AB91418E0E2174E31234ED949B13587E17DE28951EE95C8A8A1CF1E868C89E93A742D0B4BE18F02D1316560822BF93FF", "hash_sha512": "2D8E47202C9A0FF64303C01B159E4915D78A75256C7B3E9FF25F11D2D6E170F64E3704A4DC51D33D6D4C876D40AB749722377C2C0F52A24D4F622F26DD3A3A9D", "hash_ssdeep": "12288:64J9caESH90n7HyI5+93eNRUm2pV+9RT4EgXcSu:FTOy+wLV+9RT44Su", "hash_imp": "A64B00149541ECB0FA84FD98B79BF54D", "hash_pesha1": "66E1FEB67E5E593DA496CB2936B216E40CB8C300", "hash_pe256": "14D2089E860B551FD8F31093ED09BC40CF8C21DF41522EEF9FB830B67615CAE1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Desktop Security Processor", "meta_original_filename": "rmactivate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/29638e099f526f7ac9e85099bd380122a6cb4c656bc24837639b62ff11910254/detection", "runtime_modules": [ "C:\\Windows\\system32\\RMActivate_isv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "RMActivate_ssp.exe-877C9B714DB7C264546FF4A9CDE48C77": { "file_name": "RMActivate_ssp.exe", "file_path": "C:\\Windows\\system32\\RMActivate_ssp.exe", "hash_md5": "877C9B714DB7C264546FF4A9CDE48C77", "hash_sha1": "DCC607EF1BE540F58855A8E207BAB539AAB88E0E", "hash_sha256": "04B23C3BB0541D69D6FE30500EB1B22B1E03452B824CE1CE29B7F89EB1C386E0", "hash_sha384": "EA10E17C942BADABF784425BC65BAA5C27750C49AB4805FC1CC7C0F0D75C7D76F3C520AF3C993E03EFDCF08EB70C7663", "hash_sha512": "2E9ACAA30E16A7CC25E3ABF084DFE7C433DE89203FAD3D26D2253DC2E77BCAF256D0DD4B5EE878E654AE0C7FB86ADEBF7A6C9400B69AD7A0E1224FA2BF68BBD9", "hash_ssdeep": "12288:mdtMrm7ZMeb52OkBd7DI/E/4vgXhY5wxWcbfqy:EMrmdMA5ni44XRjmy", "hash_imp": "0A975696C1EBDA2FE57027FB43C0A3BD", "hash_pesha1": "01C50EF95D85B0D19A5C8E8B86A4C36DA745E9AE", "hash_pe256": "05797898F61D34D625B7939AF09EF999E8DAC0B4AC96F939E1BD1FEAC79034D5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Server Security Processor", "meta_original_filename": "rmactivate_ssp.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/04b23c3bb0541d69d6fe30500eb1b22b1e03452b824ce1ce29b7f89eb1c386e0/detection", "runtime_modules": [ "C:\\Windows\\system32\\RMActivate_ssp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "RMActivate_ssp_isv.exe-2652297470C8A89CCACB79AF2F391003": { "file_name": "RMActivate_ssp_isv.exe", "file_path": "C:\\Windows\\system32\\RMActivate_ssp_isv.exe", "hash_md5": "2652297470C8A89CCACB79AF2F391003", "hash_sha1": "E96B643DC0EF6B2429BF35877BD13D182FCE38A3", "hash_sha256": "AEAD49CA461086872D44D6B4C749A961FBFE39A3F6D51A9B46756F854C574356", "hash_sha384": "3A38DE64BF3721D0EE2D7D97A9A5B3E7F42BB73CC6BCC77E616D9E8232291E905F0A4F3AE0C439DC2DC5483D1545F208", "hash_sha512": "C1DEB73587D0D865914B9A89D4C919BAD366DFC77ABAAA88CDDC23E4649E8550D82A0A4DBE42C5FDA3BB0B8210E0122A7C713737B3AB5495F713F169AE6DCB28", "hash_ssdeep": "12288:1S4wx5oml5JFKsCo1kW+Hy8CIsRPHbYUrIjuUzKhJTiIu/ikSQ5:qx5omg8kWQy5vp7YqKMJTiIuZSQ", "hash_imp": "0A975696C1EBDA2FE57027FB43C0A3BD", "hash_pesha1": "B6BFDC2AA229C604E20DA86416463CDF1413649C", "hash_pe256": "612F531DCFC10833CE94ED0503B57C3CF9B89767861DECD15C274CEA49DB5074", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Server Security Processor (Pre-production)", "meta_original_filename": "rmactivate_ssp_isv.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/aead49ca461086872d44d6b4c749a961fbfe39a3f6d51a9b46756f854c574356/detection", "runtime_modules": [ "C:\\Windows\\system32\\RMActivate_ssp_isv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "RmClient.exe-2FBC913D73662559400A314EB1E57EE0": { "file_name": "RmClient.exe", "file_path": "C:\\Windows\\system32\\RmClient.exe", "hash_md5": "2FBC913D73662559400A314EB1E57EE0", "hash_sha1": "7DE1753E8B881F5A7F944F7C19F2180E83823AAD", "hash_sha256": "D0E19F73E1E3343A995D3DA28AAA88BBEBC63B871BDACFED664D4F38CB9C62F9", "hash_sha384": "BD4C5DE1B45F3F5B7AD2EEE2CF84AA9F97B50242E63CB2BD2402E514CCBBBE84D7B1DDD9FA9C8C29F090A59BD9F804CB", "hash_sha512": "03EC7B2B3890D62782D2DEA5427BD96C57895FF8D92F4B6A9FDF383221B76D60B876033FBA899767A7F36732909F19B9A46B29BBF9689A83F3D5933CE2A869CD", "hash_ssdeep": "384:8a5BIuZ+Eje6dQBfMJLTkGRkm6YG50Jed2bovPWozW:8S+oFTdEUJXkIawbEj", "hash_imp": "EB0E8D586B57D8075925424DA3BD6710", "hash_pesha1": "AEB40A05FFD452A4071473CC221CC8CE7108C9EF", "hash_pe256": "BBEF6B47348D9C54D6E4C0D284BB18315662CE3A19439A1052DF798C1DFE2A03", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Restart Manager LUA Restart Client", "meta_original_filename": "RmClient.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d0e19f73e1e3343a995d3da28aaa88bbebc63b871bdacfed664d4f38cb9c62f9/detection", "output": "\r\n RmClient.exe pipename\r\n\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\RmClient.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "rmttpmvscmgrsvr.exe-7FC22E2C851C817698B23379912E737D": { "file_name": "rmttpmvscmgrsvr.exe", "file_path": "C:\\Windows\\system32\\rmttpmvscmgrsvr.exe", "hash_md5": "7FC22E2C851C817698B23379912E737D", "hash_sha1": "3FDE3596A50667F5381954EEE6482C85698F3652", "hash_sha256": "5F5153DD2D8C6B529CCCA08CA73BCE7D55C10199E4FAB32E910B3F4AFEA9A04E", "hash_sha384": "205BDAFA5E2B8C591E06D8A174A9FB67E05F1B4A22F778DCC523A428087664C750B31C85E1DEB98296E5230E0AAB2338", "hash_sha512": "57C561DF86DAEFAE5211279802943539E120288612CABE75513B751E916FE1AB1BBF395A5AF4E4C9910CF5E3D79FEC4A27FF5FC2FB1731D7F1DAB7D2F1494D12", "hash_ssdeep": "3072:87NT0Qkfa/Sc5pdNE0xhQth3R+Nlb47ShHFke:8BdGa/fn6OhQt/+874l", "hash_imp": "54D25617977E08207789223DE4A9C8E4", "hash_pesha1": "8C8B2137EF3BF2B86636F403B5C0B4133501F889", "hash_pe256": "5189DFF9920534D06F52079F824F087E2AD8E392E4C73D042056C48D3D596B2E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TPM Virtual Smart Card Manager DCOM Server", "meta_original_filename": "RmtTpmVscMgrSvr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5f5153dd2d8c6b529ccca08ca73bce7d55c10199e4fab32e910b3f4afea9a04e/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\rmttpmvscmgrsvr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcrypt.dll" ] }, "Robocopy.exe-29D3CAA546AAF7D711E0431210C06E82": { "file_name": "Robocopy.exe", "file_path": "C:\\Windows\\system32\\Robocopy.exe", "hash_md5": "29D3CAA546AAF7D711E0431210C06E82", "hash_sha1": "01FC5C3E5F2A0957F9F4E27AB3349657D0FA324D", "hash_sha256": "AB5FE50644FD7E989C00F6596EC40284FF37A3AD8E44FBCA98DBFBF9B5192A2E", "hash_sha384": "00E66FD4BEDC7E447623837A4FA3AB07611320AC2C0137A0D6A6FCD09AE4D114520D246275B57F459E7820DD7E908126", "hash_sha512": "12347E4891783E94B2135223CD46AEB2FC684AFF402903E7D2D5249842194E64499454B6C70D3380FE79B014AB8C948EDAC62510F448C6E13BA96B4BDA882AD8", "hash_ssdeep": "3072:CIsMV4DXl7fCpw55HgpjfIQQcg/rvzHaI3y9XF9FAAbpTT6mg1avYtvff:CJM+ZfCw5KJQCg/rvzHaI3y9XOypimtE", "hash_imp": "8FEDEBCE77B4BC94A8D29804416DA569", "hash_pesha1": "3197C83BF963AB60FF1A3E64B9F38FD6ED364A07", "hash_pe256": "A0E9E203654FDDEFCEBB248DEB0086973550A9C04807F348E2171DE9101BB451", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Robocopy", "meta_original_filename": "robocopy.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ab5fe50644fd7e989c00f6596ec40284ff37a3ad8e44fbca98dbfbf9b5192a2e/detection", "output": "\r\n-------------------------------------------------------------------------------\r\n ROBOCOPY :: Robust File Copy for Windows \r\n-------------------------------------------------------------------------------\r\n\r\n Started : Saturday, December 12, 2020 10:09:02 PM\r\n Usage :: ROBOCOPY source destination [file [file]...] [options]\r\n\r\n source :: Source Directory (drive:\\path or \\\\server\\share\\path).\r\n destination :: Destination Dir (drive:\\path or \\\\server\\share\\path).\r\n file :: File(s) to copy (names/wildcards: default is \"*.*\").\r\n\r\n::\r\n:: Copy options :\r\n::\r\n /S :: copy Subdirectories, but not empty ones.\r\n /E :: copy subdirectories, including Empty ones.\r\n /LEV:n :: only copy the top n LEVels of the source directory tree.\r\n\r\n /Z :: copy files in restartable mode.\r\n /B :: copy files in Backup mode.\r\n /ZB :: use restartable mode; if access denied use Backup mode.\r\n /J :: copy using unbuffered I/O (recommended for large files).\r\n /EFSRAW :: copy all encrypted files in EFS RAW mode.\r\n\r\n /COPY:copyflag[s] :: what to COPY for files (default is /COPY:DAT).\r\n (copyflags : D=Data, A=Attributes, T=Timestamps, X=Skip alt data streams).\r\n (S=Security=NTFS ACLs, O=Owner info, U=aUditing info).\r\n\r\n \r\n /SEC :: copy files with SECurity (equivalent to /COPY:DATS).\r\n /COPYALL :: COPY ALL file info (equivalent to /COPY:DATSOU).\r\n /NOCOPY :: COPY NO file info (useful with /PURGE).\r\n /SECFIX :: FIX file SECurity on all files, even skipped files.\r\n /TIMFIX :: FIX file TIMes on all files, even skipped files.\r\n\r\n /PURGE :: delete dest files/dirs that no longer exist in source.\r\n /MIR :: MIRror a directory tree (equivalent to /E plus /PURGE).\r\n\r\n /MOV :: MOVe files (delete from source after copying).\r\n /MOVE :: MOVE files AND dirs (delete from source after copying).\r\n\r\n /A+:[RASHCNET] :: add the given Attributes to copied files.\r\n /A-:[RASHCNET] :: remove the given Attributes from copied files.\r\n\r\n /CREATE :: CREATE directory tree and zero-length files only.\r\n /FAT :: create destination files using 8.3 FAT file names only.\r\n /256 :: turn off very long path (> 256 characters) support.\r\n\r\n /MON:n :: MONitor source; run again when more than n changes seen.\r\n /MOT:m :: MOnitor source; run again in m minutes Time, if changed.\r\n\r\n /RH:hhmm-hhmm :: Run Hours - times when new copies may be started.\r\n /PF :: check run hours on a Per File (not per pass) basis.\r\n\r\n /IPG:n :: Inter-Packet Gap (ms), to free bandwidth on slow lines.\r\n\r\n /SJ :: copy Junctions as junctions instead of as the junction targets.\r\n /SL :: copy Symbolic Links as links instead of as the link targets.\r\n\r\n /MT[:n] :: Do multi-threaded copies with n threads (default 8).\r\n n must be at least 1 and not greater than 128.\r\n This option is incompatible with the /IPG and /EFSRAW options.\r\n Redirect output using /LOG option for better performance.\r\n\r\n /DCOPY:copyflag[s] :: what to COPY for directories (default is /DCOPY:DA).\r\n (copyflags : D=Data, A=Attributes, T=Timestamps, E=EAs, X=Skip alt data streams).\r\n\r\n /NODCOPY :: COPY NO directory info (by default /DCOPY:DA is done).\r\n\r\n /NOOFFLOAD :: copy files without using the Windows Copy Offload mechanism.\r\n\r\n /COMPRESS :: Request network compression during file transfer, if applicable.\r\n\r\n::\r\n:: File Selection Options :\r\n::\r\n /A :: copy only files with the Archive attribute set.\r\n /M :: copy only files with the Archive attribute and reset it.\r\n /IA:[RASHCNETO] :: Include only files with any of the given Attributes set.\r\n /XA:[RASHCNETO] :: eXclude files with any of the given Attributes set.\r\n\r\n /XF file [file]... :: eXclude Files matching given names/paths/wildcards.\r\n /XD dirs [dirs]... :: eXclude Directories matching given names/paths.\r\n\r\n /XC :: eXclude Changed files.\r\n /XN :: eXclude Newer files.\r\n /XO :: eXclude Older files.\r\n /XX :: eXclude eXtra files and directories.\r\n /XL :: eXclude Lonely files and directories.\r\n /IS :: Include Same files.\r\n /IT :: Include Tweaked files.\r\n\r\n /MAX:n :: MAXimum file size - exclude files bigger than n bytes.\r\n /MIN:n :: MINimum file size - exclude files smaller than n bytes.\r\n\r\n /MAXAGE:n :: MAXimum file AGE - exclude files older than n days/date.\r\n /MINAGE:n :: MINimum file AGE - exclude files newer than n days/date.\r\n /MAXLAD:n :: MAXimum Last Access Date - exclude files unused since n.\r\n /MINLAD:n :: MINimum Last Access Date - exclude files used since n.\r\n (If n < 1900 then n = n days, else n = YYYYMMDD date).\r\n\r\n /FFT :: assume FAT File Times (2-second granularity).\r\n /DST :: compensate for one-hour DST time differences.\r\n\r\n /XJ :: eXclude symbolic links (for both files and directories) and Junction points.\r\n /XJD :: eXclude symbolic links for Directories and Junction points.\r\n /XJF :: eXclude symbolic links for Files.\r\n\r\n /IM :: Include Modified files (differing change times).\r\n::\r\n:: Retry Options :\r\n::\r\n /R:n :: number of Retries on failed copies: default 1 million.\r\n /W:n :: Wait time between retries: default is 30 seconds.\r\n\r\n /REG :: Save /R:n and /W:n in the Registry as default settings.\r\n\r\n /TBD :: Wait for sharenames To Be Defined (retry error 67).\r\n\r\n /LFSM :: Operate in low free space mode, enabling copy pause and resume (see Remarks).\r\n\r\n /LFSM:n[KMG] :: /LFSM, specifying the floor size in n [K:kilo,M:mega,G:giga] bytes.\r\n\r\n::\r\n:: Logging Options :\r\n::\r\n /L :: List only - don't copy, timestamp or delete any files.\r\n /X :: report all eXtra files, not just those selected.\r\n /V :: produce Verbose output, showing skipped files.\r\n /TS :: include source file Time Stamps in the output.\r\n /FP :: include Full Pathname of files in the output.\r\n /BYTES :: Print sizes as bytes.\r\n\r\n /NS :: No Size - don't log file sizes.\r\n /NC :: No Class - don't log file classes.\r\n /NFL :: No File List - don't log file names.\r\n /NDL :: No Directory List - don't log directory names.\r\n\r\n /NP :: No Progress - don't display percentage copied.\r\n /ETA :: show Estimated Time of Arrival of copied files.\r\n\r\n /LOG:file :: output status to LOG file (overwrite existing log).\r\n /LOG+:file :: output status to LOG file (append to existing log).\r\n\r\n /UNILOG:file :: output status to LOG file as UNICODE (overwrite existing log).\r\n /UNILOG+:file :: output status to LOG file as UNICODE (append to existing log).\r\n\r\n /TEE :: output to console window, as well as the log file.\r\n\r\n /NJH :: No Job Header.\r\n /NJS :: No Job Summary.\r\n\r\n /UNICODE :: output status as UNICODE.\r\n\r\n::\r\n:: Job Options :\r\n::\r\n /JOB:jobname :: take parameters from the named JOB file.\r\n /SAVE:jobname :: SAVE parameters to the named job file\r\n /QUIT :: QUIT after processing command line (to view parameters). \r\n /NOSD :: NO Source Directory is specified.\r\n /NODD :: NO Destination Directory is specified.\r\n /IF :: Include the following Files.\r\n\r\n::\r\n:: Remarks :\r\n::\r\n Using /PURGE or /MIR on the root directory of the volume formerly caused \r\n robocopy to apply the requested operation on files inside the System \r\n Volume Information directory as well. This is no longer the case; if \r\n either is specified, robocopy will skip any files or directories with that \r\n name in the top-level source and destination directories of the copy session.\r\n\r\n The modified files classification applies only when both source \r\n and destination filesystems support change timestamps (e.g., NTFS) \r\n and the source and destination files have different change times but are \r\n otherwise the same. These files are not copied by default; specify /IM \r\n to include them.\r\n\r\n The /DCOPY:E flag requests that extended attribute copying should be \r\n attempted for directories. Note that currently robocopy will continue \r\n if a directory's EAs could not be copied. This flag is also not included \r\n in /COPYALL.\r\n\r\n Using /LFSM requests robocopy to operate in 'low free space mode'. \r\n In that mode, robocopy will pause whenever a file copy would cause the \r\n destination volume's free space to go below a 'floor' value, which \r\n can be explicitly specified by the LFSM:n[KMG] form of the flag. \r\n If /LFSM is specified with no explicit floor value, the floor is set to \r\n ten percent of the destination volume's size. \r\n Low free space mode is incompatible with /MT, /EFSRAW, /B, and /ZB.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\Robocopy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ROUTE.EXE-3C97E63423E527BA8381E81CBA00B8CD": { "file_name": "ROUTE.EXE", "file_path": "C:\\Windows\\system32\\ROUTE.EXE", "hash_md5": "3C97E63423E527BA8381E81CBA00B8CD", "hash_sha1": "DC9ECD7E9FF4A4675C977A418BF1BB562C34C890", "hash_sha256": "B8A28AEB6345CA88B04FF3D9FADF30EACF26958C991BD8E4FB1DF12A68F60EAE", "hash_sha384": "E51897911ED0AA70721420E322563436381118BE0373F5221A994CE281292A1DA23213977193B0FDBD3F29949B7744CC", "hash_sha512": "E202D2202632A40423C339BE2EABD6430B3EA07A744FEF536C555A3C083A678E8E2E03B8CA95E19198CE744C33FBDFBC4DB050C6738C5837A8675BCDF203CFDD", "hash_ssdeep": "384:wlHC4G+lpeWcH385iN5BTP8vtAznh9M+OPH1zryxavKifGwkerFqZ9AZdyWI0W:2+ey385iB8FnHrdYkFqZ9IdM", "hash_imp": "95110DF86CE2E63EB457CE5860C12E57", "hash_pesha1": "138E1FC81C9260B4240FE42FBBAEA75B98AB04F6", "hash_pe256": "D3E1C8B99695BAC527458C2A4800F973605D03B5FD1A7CD6D64A207E1E93D07D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Route Command", "meta_original_filename": "route.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b8a28aeb6345ca88b04ff3d9fadf30eacf26958c991bd8e4fb1df12a68f60eae/detection", "error": "\r\nManipulates network routing tables.\r\n\r\nROUTE [-f] [-p] [-4|-6] command [destination]\r\n [MASK netmask] [gateway] [METRIC metric] [IF interface]\r\n\r\n -f Clears the routing tables of all gateway entries. If this is\r\n used in conjunction with one of the commands, the tables are\r\n cleared prior to running the command.\r\n \r\n -p When used with the ADD command, makes a route persistent across\r\n boots of the system. By default, routes are not preserved\r\n when the system is restarted. Ignored for all other commands, \r\n which always affect the appropriate persistent routes.\r\n \r\n -4\t Force using IPv4.\r\n\r\n -6 Force using IPv6. \r\n \r\n command One of these:\r\n PRINT Prints a route\r\n ADD Adds a route\r\n DELETE Deletes a route\r\n CHANGE Modifies an existing route\t\r\n destination Specifies the host.\r\n MASK Specifies that the next parameter is the 'netmask' value.\r\n netmask Specifies a subnet mask value for this route entry.\r\n If not specified, it defaults to 255.255.255.255.\r\n gateway Specifies gateway.\r\n interface the interface number for the specified route.\r\n METRIC specifies the metric, ie. cost for the destination.\r\n\r\nAll symbolic names used for destination are looked up in the network database\r\nfile NETWORKS. The symbolic names for gateway are looked up in the host name\r\ndatabase file HOSTS.\r\n\r\nIf the command is PRINT or DELETE. Destination or gateway can be a wildcard,\r\n(wildcard is specified as a star '*'), or the gateway argument may be omitted.\r\n\r\nIf Dest contains a * or ?, it is treated as a shell pattern, and only\r\nmatching destination routes are printed. The '*' matches any string,\r\nand '?' matches any one char. Examples: 157.*.1, 157.*, 127.*, *224*.\r\n\r\nPattern match is only allowed in PRINT command.\r\nDiagnostic Notes:\r\n Invalid MASK generates an error, that is when (DEST & MASK) != DEST.\r\n Example> route ADD 157.0.0.0 MASK 155.0.0.0 157.55.80.1 IF 1\r\n The route addition failed: The specified mask parameter is invalid. (Destination & Mask) != Destination.\r\n\r\nExamples:\r\n\r\n > route PRINT\r\n > route PRINT -4\r\n > route PRINT -6\r\n > route PRINT 157* .... Only prints those matching 157*\r\n\t\r\n > route ADD 157.0.0.0 MASK 255.0.0.0 157.55.80.1 METRIC 3 IF 2\r\n destination^ ^mask ^gateway metric^ ^\r\n Interface^\r\n If IF is not given, it tries to find the best interface for a given \r\n gateway.\r\n > route ADD 3ffe::/32 3ffe::1\r\n \r\n > route CHANGE 157.0.0.0 MASK 255.0.0.0 157.55.80.5 METRIC 2 IF 2\r\n \r\n CHANGE is used to modify gateway and/or metric only.\r\n \r\n > route DELETE 157.0.0.0\r\n > route DELETE 3ffe::/32\r\n", "runtime_modules": [ "C:\\Windows\\system32\\ROUTE.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "RpcPing.exe-106B31549A7DCDE1D7A9E52FB73C838C": { "file_name": "RpcPing.exe", "file_path": "C:\\Windows\\system32\\RpcPing.exe", "hash_md5": "106B31549A7DCDE1D7A9E52FB73C838C", "hash_sha1": "B0CBDF0F2375950F87AB346B043F3CE85009E811", "hash_sha256": "B26CA32A7EEE65B90658EACAEB3589E69E9EFB5686CE6CEC7D20C1766DA34F32", "hash_sha384": "24105E4CF81EEE31F6F2620FA9E9E6208D35F47B280D4A5E24A797069B178ABAE1E719B8ABBC051791436F1E7CB5E639", "hash_sha512": "3EF2B4603908C010B1439DF821622D267AB6C1476753458944528E1B1C992915AFF93D4877C44F99B4A99A1790CAF65D3E1170832D46F636FDC2D4E84CA7E2C9", "hash_ssdeep": "768:DN3YTAR6SQ7EW0HuqSJRtVtjovmEO9t8lulQt:B3A63yEF9SJRtLjovdO9ClUQt", "hash_imp": "AA6B2A7321AE60F227BDF8367761D35D", "hash_pesha1": "380346AF9B72A47E30AA2B67F3033E3175B64EA4", "hash_pe256": "355616BBA56C6BA32621A8A2F8A8C9658208DEB9ECEAD0C7B0A0C67B4D760E56", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RPC Ping Utility", "meta_original_filename": "RpcPing.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/b26ca32a7eee65b90658eacaeb3589e69e9efb5686ce6cec7d20c1766da34f32/detection", "output": "Usage: \r\nrpcping [-t <protseq>] [-s <server_addr>] [-e <endpoint> \r\n |-f <interface UUID>[,MajorVer]] [-O <Interface Object UUID]\r\n [-i <#_iterations>] [-u <security_package_id>] [-a <authn_level>] \r\n [-N <server_princ_name>] [-I <auth_identity>] [-C <capabilities>]\r\n [-T <identity_tracking>] [-M <impersonation_type>]\r\n [-S <server_sid>] [-P <proxy_auth_identity>] [-F <RPCHTTP_flags>]\r\n [-H <RPC/HTTP_authn_schemes>] [-o <binding_options>]\r\n [-B <server_certificate_subject>] [-b] [-E] [-q] [-c]\r\n [-A <http_proxy_auth_identity>] [-U <HTTP_proxy_authn_schemes>]\r\n [-r <report_results_interval>] [-v <verbose_level>] \r\n\r\nPings a server using RPC. Options are:\r\n\r\n-t <protseq> - protocol sequence to use. Can be one of the standard\r\n RPC protocol sequences - ncacn_ip_tcp, ncacn_np, ncacn_http, etc.\r\n If not specified, default is ncacn_ip_tcp.\r\n \r\n-s <server_addr> - the server address. If not specified, the local\r\n machine will be pinged. E.g. server, server.com, 157.59.244.141\r\n \r\n-e <endpoint> - the endpoint to ping. If none is specified, the endpoint\r\n mapper on the target machine will be pinged. This option is mutually\r\n exclusive with the interface (-f) option.\r\n\r\n-o <binding_options> - the binding options for the RPC ping. See the\r\n MSDN for more details (RpcStringBindingCompose and RPC over HTTP).\r\n \r\n-f <interface UUID>[,MajorVer] - the interface to ping. This option is\r\n mutually exclusive with the endpoint option. The interface is specified\r\n as a UUID. If the MajorVer is not specified, version 1 of the interface\r\n will be sought. When interface is specified, rpcping will query the\r\n endpoint mapper on the target machine to retrieve the endpoint for the\r\n specified interface. The endpoint mapper will be queried using the\r\n options specified in the command line.\r\n \r\n-O <Object UUID> - Object Uuid if the interface registerd one.\r\n\r\n-i <#_iterations> - number of calls to make. The default is 1. This\r\n option is useful for measuring connection latency if multiple\r\n iterations are specified.\r\n \r\n-u <security_package_id> - the security package (security provider) RPC\r\n will use to make the call. The security package is identified as a\r\n number or a name. If a number is used it is the same number as in the\r\n RpcBindingSetAuthInfoEx API. The table below gives the names and\r\n numbers. Names are not case sensitive:\r\n Negotiate - 9 or one of nego, snego or negotiate\r\n NTLM - 10 or NTLM\r\n SChannel - 14 or SChannel\r\n Kerberos - 16 or Kerberos\r\n Kernel - 20 or Kernel\r\n If you specify this option you must specify authentication level other\r\n than none. There is no default for this option. If it is not specified,\r\n RPC will not use security for the ping.\r\n \r\n-a <authn_level> - the authentication level to use. Possible values are\r\n connect, call, pkt, integrity and privacy. If this option is\r\n specified, the security package id (-u) must also be specified. There\r\n is no default for this option. If this option is not specified, RPC\r\n will not use security for the ping.\r\n\r\n-N <server_princ_name> - specifies a server principal name. Same semantics\r\n as the ServerPrincName argument to RpcBindingSetAuthInfoEx. See the\r\n MSDN for more information on RpcBidningSetAuthInfoEx. This field can be\r\n used only when authentication level and security package are selected.\r\n \r\n-I <auth_identity> - allows you to specify alternative identity to connect\r\n to the server. The identity is in the form user,domain,password where\r\n the three fields have the obvious meaning. If the user name, domain or\r\n password have special characters that can be interpreted by the shell\r\n be sure to enclose the identity in double quotes. You can specify *\r\n instead of the password and RPC will prompt you to enter the password\r\n without echoing it on the screen. If this field is not specified, the\r\n identity of the logged on user will be used. This field can be used\r\n only when authentication level and security package are selected.\r\n \r\n-C <capabilities> - a hex bitmask of flags. It has the same meaning as\r\n the Capabilities field in the RPC_SECURITY_QOS structure described\r\n in the MSDN. This field can be used only when authentication level and\r\n security package are selected.\r\n \r\n-T <identity_tracking> - can be static or dynamic. If not specified,\r\n dynamic is the default. This field can be used only when authentication\r\n level and security package are selected.\r\n\r\n-M <impersonation_type> - can be anonymous, identify, impersonate or\r\n delegate. Default is impersonate. This field can be used only when\r\n authentication level and security package are selected. \r\n\r\n-S <server_sid> - the expected SID of the server. For more information\r\n see the Sid field in the RPC_SECURITY_QOS structure in the MSDN. Using \r\n this option requires Windows .NET Server 2003 or higher. This field can\r\n be used only when authentication level and security package are\r\n selected.\r\n \r\n-Z <effectiveonly> - the EffectiveOnly setting to use. For more information\r\n see the EffectiveOnly field in the RPC_SECURITY_QOS structure in MSDN.\r\n Using this option requires Windows Vista or higher. This field can be\r\n used only when authentication level and security package are selected.\r\n\r\n-D <serversecuritydescriptor> - the security descriptor (in string format)\r\n of the server when using mutual authentication. For more information\r\n see the ServerSecurityDescriptor field in the RPC_SECURITY_QOS structure\r\n in MSDN. Using this option requires Windows 8 or higher. This field can\r\n be used only when authentication level and security package are\r\n selected.\r\n\r\n-P <proxy_auth_identity> - specifies the identity to authenticate with to\r\n the RPC/HTTP proxy. Has the same format as for the -I option. \r\n Also, you must specify security package (-u), authentication level \r\n (-a), and authentication schemes (-H) in order to use this option.\r\n \r\n-F <RPCHTTP_flags> - the flags to pass for RPC/HTTP front end\r\n authentication. The flags may be specified as numbers or names\r\n The currently recognized flags are:\r\n Use SSL - 1 or ssl or use_ssl\r\n Use first auth scheme - 2 or first or use_first\r\n See the Flags field in RPC_HTTP_TRANSPORT_CREDENTIALS for more \r\n information. Also, you must specify security package (-u) and \r\n authentication level (-a) in order to use this option.\r\n \r\n-H <RPC/HTTP_authn_schemes> - the authentication schemes to use for\r\n RPC/HTTP front end authentication. This option is a list of numerical\r\n values or names separated by comma. E.g. Basic,NTLM. Recognized values\r\n are (names are not case sensitive:\r\n Basic - 1 or Basic\r\n NTLM - 2 or NTLM\r\n Certificate - 65536 or Cert\r\n Also, you must specify security package (-u) and authentication level \r\n (-a) in order to use this option.\r\n \r\n-B <server_certificate_subject> - the server certificate subject. For\r\n more information, see the ServerCertificateSubject field in the\r\n RPC_HTTP_TRANSPORT_CREDENTIALS structure in the MSDN. You must use\r\n SSL for this option to work. Also, you must specify security package \r\n (-u) and authentication level (-a) in order to use this option.\r\n \r\n-b - retrieves the server certificate subject from the certificate sent\r\n by the server and prints it to a screen or a log file. Valid only when\r\n the Proxy Echo only option (-E) and the use SSL options are specified.\r\n Also, you must specify security package (-u) and authentication level \r\n (-a) in order to use this option.\r\n \r\n-R - specifies the HTTP proxy. if it's 'none', we will not use HTTP proxy but\r\n directly attempt the RPC proxy. the value 'default' means to use the IE\r\n settings in your client machine. any other value will be treated as the\r\n explicit HTTP proxy. if you don't specify this flag, the default value\r\n is assumed, that is, the IE settings are checked. this flag is valid\r\n only when the -E (Echo Only) flag is enabled.\r\n\r\n-E - restricts the ping to the RPC/HTTP proxy only. The ping does not\r\n reach the server. Useful when trying to establish whether the RPC/HTTP\r\n proxy is reachable. Also, you must specify security package (-u) and \r\n authentication level (-a) in order to use this option. To specify an \r\n HTTP proxy, use the -R flag. If an HTTP proxy is specified in the -o \r\n flag, this option will be ignored.\r\n \r\n-q - quiet mode. Does not issue any prompts except for passwords. Assumes\r\n 'Y' response to all queries. Use this option with care.\r\n \r\n-c - use smart card certificate. RPCPing will prompt user to choose\r\n smart card.\r\n \r\n-A <http_proxy_auth_identity> - specifies the identity to authenticate\r\n with to the HTTP proxy. Has the same format as for the -I option. \r\n Also, you must specify authentication schemes (-U), security package \r\n (-u) and authentication level (-a) in order to use this option.\r\n \r\n-U <HTTP_proxy_authn_schemes> - the authentication schemes to use for\r\n HTTP proxy authentication. This option is a list of numerical\r\n values or names separated by comma. E.g. Basic,NTLM. Recognized values \r\n are (names are not case sensitive:\r\n Basic - 1 or Basic\r\n NTLM - 2 or NTLM\r\n You must specify security package (-u) and authentication level (-a) \r\n in order to use this option.\r\n\r\n-r <report_results_interval> - if multiple iterations are specified, this\r\n option will make rpcping display current execution statistics\r\n periodically instead after the last call. The report interval is given\r\n in seconds. Default is 15.\r\n \r\n-v <verbose_level> - tells rpcping how verbose to make the output. Default\r\n value is 1. 2 and 3 provide more output from rpcping.\r\n \r\nExample: Find out if your Exchange server that you connect through\r\nRPC/HTTP is accessible:\r\n rpcping -t ncacn_http -s exchange_server -o RpcProxy=front_end_proxy\r\n -P \"username,domain,*\" -H Basic -u NTLM -a connect -F 3\r\nWhen prompted for the password, enter it. exchange_server is the name of\r\nyour exchange server, front_end_proxy is the name of your proxy, username\r\nand domain are your user name and domain as you would enter them in the\r\nOutlook prompt. The other parameters will ask rpcping to ping your\r\nExchange server in exactly the same way as Outlook will connect to it for\r\nthe typical profile.\r\n\r\n-p - Prompt for credentials if authentication fails.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\RpcPing.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "rrinstaller.exe-57FD77E8AE7C715E94BF60FD00F26195": { "file_name": "rrinstaller.exe", "file_path": "C:\\Windows\\system32\\rrinstaller.exe", "hash_md5": "57FD77E8AE7C715E94BF60FD00F26195", "hash_sha1": "1BC17655DFF39EADB4060BCE65084D16B7B0CAFB", "hash_sha256": "4FF9A380F55C6B3BB4AA67E6C757B5DCCC5AF9F5C4A433A255D7A6F83C8DCADA", "hash_sha384": "E558A934251E341A94C0C3D3FAD5B0B9B989E7C4B02B7D3C76B1C54C4C2D3151A1F1A738C4F94DBDA97D397451BBDFCB", "hash_sha512": "612FC2F1873BA1212088A8465E8A97A74503E3604C680831D853A3FA1B89E6E3906C0BCBE2FF5D15C2F929F6060F061FBE987AD560FE622EBE9B5DC951554861", "hash_ssdeep": "768:GFCt19SksNdQSG17G/MLiRMp31X38NKIcrYbFeRc8Ld0UbpIj+X1cIA57WyvzfXY:GFClSFNV8iR631X38NDccqc8R0UbSaXb", "hash_imp": "0F7716C51D703DF0FEA1B2EE96B8C0C7", "hash_pesha1": "534A496CE22ED0A863076CAC5BC7D9F1DAAC6CAC", "hash_pe256": "F489C352B7BA17638A8A3D287D2E0EBA482ECD10CD0E5A673B96469C108E160B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "R&R installer", "meta_original_filename": "rrinstaller.exe", "meta_product_name": "Microsoft DRM", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.0.19041.1", "meta_product_version": "11.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4ff9a380f55c6b3bb4aa67e6c757b5dccc5af9f5c4a433a255d7a6f83c8dcada/detection", "runtime_modules": [ "C:\\Windows\\system32\\rrinstaller.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "rstrui.exe-CC4FD2CAEAB42F55A7EB6A29D0F0759B": { "file_name": "rstrui.exe", "file_path": "C:\\Windows\\system32\\rstrui.exe", "hash_md5": "CC4FD2CAEAB42F55A7EB6A29D0F0759B", "hash_sha1": "592FF752BE18D970391E85652629248AF2DA02ED", "hash_sha256": "1726F953B518D611979730EFA87F63D324E20138B3A846468E35B9E67DA2F5D6", "hash_sha384": "4604EF8D747CAF94B38D9D54F31CFF84B4AC70795C46D724FD747C1448F1642F70D5F5E6933D673685340313B872A9F5", "hash_sha512": "2B074CABF5506D37484056C1BDF8CD005682CAFAE3FB4E614D2B2D69F7D34EF3B217575E052F6F0D6A46EE26F5DDA1F49BA003F844F9DD7941A9B0C505A2C0F8", "hash_ssdeep": "6144:zBXgbF45I9ng85AiaKRnWJjbangH2+UvQ/KpmOq:zBXuGOg857H+bKjvQ/Kp", "hash_imp": "9D3877D28342FF71396AB7B327C8F5AE", "hash_pesha1": "E572F353BF1AA0A9425B88845F6A0C18E033D6CF", "hash_pe256": "244690A6704F9C2B04D4DED7234D52017EBF7D1ED6F2E876C5C3CF2EB319BC6A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows System Restore", "meta_original_filename": "rstrui.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1726f953b518d611979730efa87f63d324e20138b3a846468e35b9e67da2f5d6/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\rstrui.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\ntdll.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\rstrui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ole32.dll" ], "runtime_window_title": "System Restore" }, "runas.exe-B37E31C5BEB6D9EB20B4DB8DF4D82960": { "file_name": "runas.exe", "file_path": "C:\\Windows\\system32\\runas.exe", "hash_md5": "B37E31C5BEB6D9EB20B4DB8DF4D82960", "hash_sha1": "29796ACA36A723D625595214E7FDA2735BAE26B2", "hash_sha256": "4FA830B5E1794FF72C691B19174C3CAFC8FB4DAE97455560B75866E19A4FFF1A", "hash_sha384": "565ABABAAA04EBB19EE9985B75013B1BE75B3CC89658139C9F18C5DD959BF8B13DE1D7D297762ED5D5597801D655E4AC", "hash_sha512": "25B8677B9DFCDBCCB127E2FF73E62BA498D8739D1123909CC04BF32F17AA81B6248C547DB2EFB5E0238CE590985ECB842A1DABA7DBDC3D05166A010A40EBB205", "hash_ssdeep": "384:x13usNRQfKgFEcgEABcSGpSW24GYGYorKq9bOOWSLTOBoV82ydWWOW:7esftQEcgEQi724GzYo9Y6Lgoby7", "hash_imp": "5B7B2489AAE1B4C266ABE004F393E61C", "hash_pesha1": "B48904F8884788E4D53F4234EAD9DF1824925FFD", "hash_pe256": "BC4866FC6E935F94517A822D10EAE615B11B3C3C123800F40B9C5972663F738D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Run As Utility", "meta_original_filename": "RUNAS.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4fa830b5e1794ff72c691b19174c3cafc8fb4dae97455560b75866e19a4fff1a/detection", "runtime_modules": [ "C:\\Windows\\system32\\runas.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "rundll32.exe-44B041922105E01BFD0D096123F7D312": { "file_name": "rundll32.exe", "file_path": "C:\\Windows\\system32\\rundll32.exe", "hash_md5": "44B041922105E01BFD0D096123F7D312", "hash_sha1": "84DDB2B3D1158485B2B66867CA9452930A258EDD", "hash_sha256": "F1DC9560D0C381C78304D94F7BA469490017D9728A03C2DD32C3BE957FC9F923", "hash_sha384": "825A5C8D7265D3F77D49E270F1D1A0F564C3FF23DC755B8FF86FDE698BF89B0311E28C51A3CE790284B72A342492722A", "hash_sha512": "F8EC1BAB25EBB3107AAF59CF687E043ABF33A2839B4F5557197472BE18F0AB3788878417E724456BF9D30E237BBA9179AB87803EC410F0F9A5C68631F8F17180", "hash_ssdeep": "1536:OM81xna/qB3NhUNfkze1+yWiYcWUoBmtSWRuln5IUmDjoX:l7/o3NhOfk7y7YsdtpRuln5I", "hash_imp": "4DB27267734D1576D75C991DC70F68AC", "hash_pesha1": "0689A2BEDC094FE12F3C0517C0991DD7F842B2C6", "hash_pe256": "335ED9EB6223407990A540AA4136E7D75CD41E3A50A016CD746A98FAF967F817", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows host process (Rundll32)", "meta_original_filename": "RUNDLL32.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f1dc9560d0c381c78304d94f7ba469490017d9728a03c2dd32c3be957fc9f923/detection", "runtime_modules": [ "C:\\Windows\\system32\\rundll32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\imagehlp.dll" ] }, "runexehelper.exe-928C96503D628409A7D00287B893A7C2": { "file_name": "runexehelper.exe", "file_path": "C:\\Windows\\system32\\runexehelper.exe", "hash_md5": "928C96503D628409A7D00287B893A7C2", "hash_sha1": "9A1E2C5769EE2E605745B4032DFC6D8932A7CA44", "hash_sha256": "D0426AE4BDF1C4910ABA092396BB1D55EABBD8246B2977CF069D1BDE0711CD4B", "hash_sha384": "BB933B617A0DA785BA52A773B8977A7057E985FDD3CD8F34C31CC58DDF52FFBB5495BE21BE87FF3263C4D32690CFCC88", "hash_sha512": "3E7A63D65EC34B1DFA97E98DDE332CF1107CCF300F946049E2A1AC23254105A21EF72A5629AAD534B189B4F4707D55EE3983494D4CE1B8A728043C0C22224E83", "hash_ssdeep": "1536:MnmN+KmLPwX/bSJjITNBZmBNYrjh5uuTxUT:MmEKmybAkTNB40jDuuO", "hash_imp": "E66B94547D97B956C966DB1C1C41DBD6", "hash_pesha1": "1874AAE030E702686DF6B83D7F98DE6F26639D19", "hash_pe256": "CCCEDC0695C2CFF197A14C79C9E83D05F03AB40EFFCBFF51B7BB51C80A4E4B45", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d0426ae4bdf1c4910aba092396bb1d55eabbd8246b2977cf069d1bde0711cd4b/detection", "children": [ "csrss.exe", "winlogon.exe" ], "runtime_modules": [ "C:\\Windows\\system32\\runexehelper.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "RunLegacyCPLElevated.exe-095CDBFC0D53FC186EE6BA4D82E5B811": { "file_name": "RunLegacyCPLElevated.exe", "file_path": "C:\\Windows\\system32\\RunLegacyCPLElevated.exe", "hash_md5": "095CDBFC0D53FC186EE6BA4D82E5B811", "hash_sha1": "9A2C346F90F32D88BF10868B1C62D8288AE2E2DD", "hash_sha256": "56132C62671C38C162DC4712F71213BA818FE369604C29572C95D7BB5C88E800", "hash_sha384": "CFD89FDADF3E266C969EB744BC9388120CF9ADD32F6C921789BF63AED3F5FA9C7B484DD3F2B3E27BC537D8AE65E877EF", "hash_sha512": "5178753FAD890AC3A6393C9EEF0DBF9441C461FBBFDF6C4D73AE8A6E31F7EC122639169D71DAB0BEB3C36E68F11C7C75C32327421A29B96B8A34E692F772819D", "hash_ssdeep": "1536:+q/ZSaYwCOUVI9FyPnL1Sxxakkn6oYY0ewiP8:5JCyOfLYxxaJVYYPwi", "hash_imp": "994147192F9A5486FF1045A684507004", "hash_pesha1": "4FC48AF2E4782F0D0A8266AF466F38BDD14812B2", "hash_pe256": "613CCFEA2202D3CC1A64BFD11E88B692CDC818A43461E04C41FF1EF731938DFD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Run a legacy CPL elevated", "meta_original_filename": "RunLegacyCPLElevated.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/56132c62671c38c162dc4712f71213ba818fe369604c29572c95d7bb5c88e800/detection", "runtime_modules": [ "C:\\Windows\\system32\\RunLegacyCPLElevated.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ] }, "runonce.exe-EC798C94932A86C01742220825073416": { "file_name": "runonce.exe", "file_path": "C:\\Windows\\system32\\runonce.exe", "hash_md5": "EC798C94932A86C01742220825073416", "hash_sha1": "1478DC8635B564C740103C6A8FF5CAF8374DA0A0", "hash_sha256": "5994E053D58DB049F4BAB2117C51CC314D1553BC6793FF000B232B66F709B0D7", "hash_sha384": "C5CCED9623776636F0C0E586AEE2CF3DCCEB5D2BFD1621A3985C6C568609A72E1FBB3FE1643856DB83949F2FAA53D463", "hash_sha512": "6B5CA46B74879732D8A147FBCB950CC7CD846264E05D5D7A27E25BB70CABF8451E68C564BDF02FE2BF33C3C885021252692D1A2ED8376F61022DAD87BCFDE524", "hash_ssdeep": "1536:vhMChceJibHnk/MkccqpyfDqsS92mqN1x7S9a1MvZ5v/G:66OcqpyrSMBN11SAqRJu", "hash_imp": "350A36A0685299C2C1A6E561AE87CE6F", "hash_pesha1": "5B7A9CF10DD182C834FC3B91EE7DA302775D8FE9", "hash_pe256": "0D648EC1214936853BA520F4FBFCCCFEA85EF03E4BC7DB038034EADEEB46743E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Run Once Wrapper", "meta_original_filename": "RUNONCE.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5994e053d58db049f4bab2117c51cc314d1553bc6793ff000b232b66f709b0d7/detection", "runtime_modules": [ "C:\\Windows\\system32\\runonce.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ole32.dll" ] }, "RuntimeBroker.exe-42CB264897445970C7FBE4C60AC74987": { "file_name": "RuntimeBroker.exe", "file_path": "C:\\Windows\\system32\\RuntimeBroker.exe", "hash_md5": "42CB264897445970C7FBE4C60AC74987", "hash_sha1": "3AF6154156D8CC1B695FB6F44993CDF83D092680", "hash_sha256": "70D968B4F65C5CE471474096F8623AECD7D496E4F10C8B94C3577C8362E0ADA1", "hash_sha384": "18DB1853AB7D0F515D242844C4C99D9F5F6343B4DC1C7D2DBB6B097A357F9DA9054CC5E4809225F0F991B2848299F9AA", "hash_sha512": "99D048E8CC77036B021E47E6EDE75E9D4F70D1134DCDF6B010A20AB2A4D379D3E8E3393B4D83A9A5097B9AD1A5F42F4FEECF20E3073BF7E0BDA6D8D6AA30E296", "hash_ssdeep": "1536:hAL8w3ydlf2ggSgbeHLIloWMUlySN+vQyk6x/Q4GE/5K5/Zdxq2VLUc6fraqP2OZ:dP0glgbRlDMQq/QddxqALyOqu", "hash_imp": "D4D98ACF3243E0C97C83C6548571A44E", "hash_pesha1": "49E1D467B4C4305B75AD0133ED1A304A486C6D49", "hash_pe256": "5D28BAF57043D3406097F2EB2B9998C2844258605DC671706A85B1CF441AF79C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Runtime Broker", "meta_original_filename": "RuntimeBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/70d968b4f65c5ce471474096f8623aecd7d496e4f10c8b94c3577c8362e0ada1/detection", "runtime_modules": [ "C:\\Windows\\system32\\RuntimeBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\system32\\RMCLIENT.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "rwinsta.exe-690A9F472F6AAFBA0E90BEDAB91366C2": { "file_name": "rwinsta.exe", "file_path": "C:\\Windows\\system32\\rwinsta.exe", "hash_md5": "690A9F472F6AAFBA0E90BEDAB91366C2", "hash_sha1": "8F4E4A8634D704FD98D6DF491149CDB472BA30AB", "hash_sha256": "44B1C84811495B426EC69A15888D5824A894421DF052CC378FD6ADA5C32A112F", "hash_sha384": "F2620F7A2ABDB4F8007ED0DF4109384601AC2CA2E780CC4F8948D73D9A743F90AD3F2AF7339A5C91578C43761F65862B", "hash_sha512": "764E35D03421B7FE881BCE684FF9754809DDC3A832FDC4B4A3AA7CA5315E4A0BBB62AE40839FB0B39DE117CB8A5A6E584B8B75B3CAB92770CD7E9E4AE30C3C01", "hash_ssdeep": "384:94dVwndNFFgbG3mrNOO0CLtRrT5tTVZ8pJxkkdmiQUWPhVMcrpXzvWSZW:OdVwBFV2rNOO0C7zVZ8LiydBK9Xzt", "hash_imp": "ACE7E1CA440DD0C4C63E4D2682CA6E8B", "hash_pesha1": "78C34B11537C7F3AE08314AC45EA6CBF152E18F5", "hash_pe256": "11C6D2AA4E48A81192F168611912278306CF6D6EB5EF843C8860B0854A990D3D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Reset Session Utility", "meta_original_filename": "rwinsta.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/44b1c84811495b426ec69a15888d5824a894421df052cc378fd6ada5c32a112f/detection", "output": "Reset the session subsytem hardware and software to known initial values.\r\n\r\nRESET SESSION {sessionname | sessionid} [/SERVER:servername] [/V]\r\n\r\n sessionname Identifies the session with name sessionname.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server containing the session (default is current).\r\n /V Display additional information.\r\n\r\n", "error": "Invalid parameter(s)\r\nReset the session subsytem hardware and software to known initial values.\r\n\r\nRESET SESSION {sessionname | sessionid} [/SERVER:servername] [/V]\r\n\r\n sessionname Identifies the session with name sessionname.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server containing the session (default is current).\r\n /V Display additional information.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\rwinsta.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "sc.exe-3FB5CF71F7E7EB49790CB0E663434D80": { "file_name": "sc.exe", "file_path": "C:\\Windows\\system32\\sc.exe", "hash_md5": "3FB5CF71F7E7EB49790CB0E663434D80", "hash_sha1": "B4979A9F970029889713D756C3F123643DDE73DA", "hash_sha256": "41F067C3A11B02FE39947F9EBA68AE5C7CB5BD1872A6009A4CD1506554A9ABA9", "hash_sha384": "5CE16AFC273E549BFDDF679FB54A63BB26B8A5B3B7C3FCE0F5C444208E3956006BFA577269E9B1FFCF04034E8C6B1EF1", "hash_sha512": "2B59A6D0AFEF765C6CA80B5738202622CFE0DFFCEC2092D23AD8149156B0B1DCA479E2E2C8562639C97E9F335429854CAD12461F2FB277207C39D12E3E308EF5", "hash_ssdeep": "1536:zth6CGDJhe/FbtFWQj1vm4LvWjh937ZlzE10:zthtiJhetRhu4DWjh937Z1ES", "hash_imp": "803254E010814E69947095A2725B2AFD", "hash_pesha1": "8960CD81B92738593D290830B7943DBB72C23BC4", "hash_pe256": "75FD106DCEE557FF574F56D7748FCA62BD0A445F660E53747F1F7D77BE7F225B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Service Control Manager Configuration Tool", "meta_original_filename": "sc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/41f067c3a11b02fe39947f9eba68ae5c7cb5bd1872a6009a4cd1506554a9aba9/detection", "output": "\r\nERROR: Unrecognized command\r\n\r\nDESCRIPTION:\r\n SC is a command line program used for communicating with the\r\n Service Control Manager and services.\r\nUSAGE:\r\n sc <server> [command] [service name] <option1> <option2>...\r\n\r\n\r\n The option <server> has the form \"\\\\ServerName\"\r\n Further help on commands can be obtained by typing: \"sc [command]\"\r\n Commands:\r\n query-----------Queries the status for a service, or\r\n enumerates the status for types of services.\r\n queryex---------Queries the extended status for a service, or\r\n enumerates the status for types of services.\r\n start-----------Starts a service.\r\n pause-----------Sends a PAUSE control request to a service.\r\n interrogate-----Sends an INTERROGATE control request to a service.\r\n continue--------Sends a CONTINUE control request to a service.\r\n stop------------Sends a STOP request to a service.\r\n config----------Changes the configuration of a service (persistent).\r\n description-----Changes the description of a service.\r\n failure---------Changes the actions taken by a service upon failure.\r\n failureflag-----Changes the failure actions flag of a service.\r\n sidtype---------Changes the service SID type of a service.\r\n privs-----------Changes the required privileges of a service.\r\n managedaccount--Changes the service to mark the service account \r\n password as managed by LSA.\r\n qc--------------Queries the configuration information for a service.\r\n qdescription----Queries the description for a service.\r\n qfailure--------Queries the actions taken by a service upon failure.\r\n qfailureflag----Queries the failure actions flag of a service.\r\n qsidtype--------Queries the service SID type of a service.\r\n qprivs----------Queries the required privileges of a service.\r\n qtriggerinfo----Queries the trigger parameters of a service.\r\n qpreferrednode--Queries the preferred NUMA node of a service.\r\n qmanagedaccount-Queries whether a services uses an account with a \r\n password managed by LSA.\r\n qprotection-----Queries the process protection level of a service.\r\n quserservice----Queries for a local instance of a user service template.\r\n delete----------Deletes a service (from the registry).\r\n create----------Creates a service. (adds it to the registry).\r\n control---------Sends a control to a service.\r\n sdshow----------Displays a service's security descriptor.\r\n sdset-----------Sets a service's security descriptor.\r\n showsid---------Displays the service SID string corresponding to an arbitrary name.\r\n triggerinfo-----Configures the trigger parameters of a service.\r\n preferrednode---Sets the preferred NUMA node of a service.\r\n GetDisplayName--Gets the DisplayName for a service.\r\n GetKeyName------Gets the ServiceKeyName for a service.\r\n EnumDepend------Enumerates Service Dependencies.\r\n\r\n The following commands don't require a service name:\r\n sc <server> <command> <option>\r\n boot------------(ok | bad) Indicates whether the last boot should\r\n be saved as the last-known-good boot configuration\r\n Lock------------Locks the Service Database\r\n QueryLock-------Queries the LockStatus for the SCManager Database\r\nEXAMPLE:\r\n sc start MyService\r\n\r\n\r\nQUERY and QUERYEX OPTIONS:\r\n If the query command is followed by a service name, the status\r\n for that service is returned. Further options do not apply in\r\n this case. If the query command is followed by nothing or one of\r\n the options listed below, the services are enumerated.\r\n type= Type of services to enumerate (driver, service, userservice, all)\r\n (default = service)\r\n state= State of services to enumerate (inactive, all)\r\n (default = active)\r\n bufsize= The size (in bytes) of the enumeration buffer\r\n (default = 4096)\r\n ri= The resume index number at which to begin the enumeration\r\n (default = 0)\r\n group= Service group to enumerate\r\n (default = all groups)\r\n\r\nSYNTAX EXAMPLES\r\nsc query - Enumerates status for active services & drivers\r\nsc query eventlog - Displays status for the eventlog service\r\nsc queryex eventlog - Displays extended status for the eventlog service\r\nsc query type= driver - Enumerates only active drivers\r\nsc query type= service - Enumerates only Win32 services\r\nsc query state= all - Enumerates all services & drivers\r\nsc query bufsize= 50 - Enumerates with a 50 byte buffer\r\nsc query ri= 14 - Enumerates with resume index = 14\r\nsc queryex group= \"\" - Enumerates active services not in a group\r\nsc query type= interact - Enumerates all interactive services\r\nsc query type= driver group= NDIS - Enumerates all NDIS drivers\r\n\n", "runtime_modules": [ "C:\\Windows\\system32\\sc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "schtasks.exe-4766931AD10E882F25C3FA5C3F01D096": { "file_name": "schtasks.exe", "file_path": "C:\\Windows\\system32\\schtasks.exe", "hash_md5": "4766931AD10E882F25C3FA5C3F01D096", "hash_sha1": "08ECCE170F2AC05FF70788164D2B2EFA5244F508", "hash_sha256": "D94194BAB0128BD8E26C9ABB21DBABB60C4DA9A5C682F4EC1B2A7EA6779E1CE5", "hash_sha384": "9A01C0D22A4B812C6D5A5BCC4744EEAE1B5901BAC10F93AA9621A4EBA5A89B295DE6BB27878C7417DC047DB660700E96", "hash_sha512": "2106DC9E738002BB65E9CC347784B1928C8EACED8C623047F81E589F85D557DA2B4724D034ACFE80B3A1269DC23B1DC7CA30C80A76935E26EC60C1FE8898B567", "hash_ssdeep": "6144:iVcU1WHmSwUQF48qSuz2mZf8rqOElVYVbVKTGGnT:dUUHwU9xLeVbVpQ", "hash_imp": "61106288C4A98856C5CBC97F1256ED80", "hash_pesha1": "5EBB6D31827BFA0B8074D32370728A8D7CB9D51B", "hash_pe256": "76EDBB8F754EFC780A1FD3494AC06EFA8B28C21392FE7BF10197B0B4F741545F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Scheduler Configuration Tool", "meta_original_filename": "schtasks.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d94194bab0128bd8e26c9abb21dbabb60c4da9a5c682f4ec1b2a7ea6779e1ce5/detection", "output": "\r\nSCHTASKS /parameter [arguments]\r\n\r\nDescription:\r\n Enables an administrator to create, delete, query, change, run and\r\n end scheduled tasks on a local or remote system. \r\n\r\nParameter List:\r\n /Create Creates a new scheduled task.\r\n\r\n /Delete Deletes the scheduled task(s).\r\n\r\n /Query Displays all scheduled tasks.\r\n\r\n /Change Changes the properties of scheduled task.\r\n\r\n /Run Runs the scheduled task on demand.\r\n\r\n /End Stops the currently running scheduled task.\r\n\r\n /ShowSid Shows the security identifier corresponding to a scheduled task name.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n SCHTASKS \r\n SCHTASKS /?\r\n SCHTASKS /Run /?\r\n SCHTASKS /End /?\r\n SCHTASKS /Create /?\r\n SCHTASKS /Delete /?\r\n SCHTASKS /Query /?\r\n SCHTASKS /Change /?\r\n SCHTASKS /ShowSid /?\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"SCHTASKS /QUERY /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\schtasks.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ScriptRunner.exe-C64357854C5214AC178B78EF1A17042F": { "file_name": "ScriptRunner.exe", "file_path": "C:\\Windows\\system32\\ScriptRunner.exe", "hash_md5": "C64357854C5214AC178B78EF1A17042F", "hash_sha1": "464B383C00C609B633191FAFC93D72685653C832", "hash_sha256": "267D6422A1AE5E633A04129388FC8BEC82FD751E0130E5998F1168BEFEC38058", "hash_sha384": "A10621E8323F8809AF7015DF8AC8E701C39CFD0BD271D34DB6003A5B644C920A5C263FC7F1413755802BCA12FF5F8B07", "hash_sha512": "2E610EBF219F5B7519B774FFD2029A28EC387E7709C695B7EE66AB261C83606203C44D1F3DA054E0A0727C0E9E8946DB9D7CE0ED60E964FBA672D03595D7B178", "hash_ssdeep": "384:+9z/IFagu/0Ei6yymaWl4wWHer6wDDBRJ5Sifl+Puh+9:yzKG/0TLyRBer6wD1PP69", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "56328C4174DD67123BA5334C96FAE9FBDB20D5F2", "hash_pe256": "BB3E29AB0705957FD7EFE7F15F4587E3618B275582DCDF53000A91BD7518A2B1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "ScriptRunner.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488", "meta_product_version": "10.0.19041.488", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/267d6422a1ae5e633a04129388fc8bec82fd751e0130e5998f1168befec38058/detection", "output": "Invalid argument specified: --help\r\nUsage:\r\nScriptRunner.exe\r\n-appvscript scriptFileName [Arguments] [-appvscriptrunnerparameters [-wait] [-timeout=<TimeInSeconds>] [-rollbackonerror]] \r\n-appvscript scriptFileName [Arguments] [-appvscriptrunnerparameters [-wait] [-timeout=<TimeInSeconds>] [-rollbackonerror]] \r\n...\r\nDefault values for -appvscriptrunnerparameters: No wait, No timeout, No rollback on error\r\nEvery parameter must be separated by a unicode space character (U+0020)\r\nExample:\r\nScriptRunner.exe -appvscript foo.cmd arg1 arg2 -appvscriptrunnerparameters -wait -timeout=30 -rollbackonerror -appvscript foobar.exe arg1 arg2\r\nError: Invalid argument specified\r\n", "runtime_modules": [ "C:\\Windows\\system32\\ScriptRunner.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "sdbinst.exe-111F6F0708DA82681BE2B1B25B25BED3": { "file_name": "sdbinst.exe", "file_path": "C:\\Windows\\system32\\sdbinst.exe", "hash_md5": "111F6F0708DA82681BE2B1B25B25BED3", "hash_sha1": "3D1D4F53EE96F29EDA84E48425FDD60962D24BDB", "hash_sha256": "5C07D2D008652A173B05460570F5B73763CC7E2E094391320E3741C9448AE0F8", "hash_sha384": "EC27F97FE8FFFE81730BC42806338422F2FE6863AAF3F1EF7C705BEE696DDD273417F95AE925A29246BC6525D0BB5E97", "hash_sha512": "6757D98D74A6E60CC09A5FE27E7EB080F9FAD36614ACE2D00BF75BA3F99F974A52F552C45C4662C925FC4DCE6C8B392FCAE9205B186E81CE51FEB2C1F91C892F", "hash_ssdeep": "384:ybwRvEgNKgGXZ/bgtIhaRkZE6SFZKhi/EazdZM9Sy2Bc6zFzWRgW:IwRCJDgtChqmGdZM9Sy2Bc6zFq", "hash_imp": "5D01C40092C3C1075F7A8335CD70663B", "hash_pesha1": "70565E0F6C4D0255D7930E9BF13C18F91705F2BC", "hash_pe256": "4712A7173033ACE575AB9437C6E158AC92111E0C287CD75875A533687AF980FD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Application Compatibility Database Installer", "meta_original_filename": "sdbinst.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5c07d2d008652a173b05460570f5b73763cc7e2e094391320e3741c9448ae0f8/detection", "output": "Error: Invalid switch --help.\nUsage: C:\\Windows\\system32\\sdbinst.exe [-?] [-q] [-u] [-g] [-p] [-n[:WIN32|WIN64]] myfile.sdb | {guid} | \"name\"\r\n\r\n -? - print this help text.\r\n -p - Allow SDBs containing patches.\r\n -q - Quiet mode: prompts are auto-accepted.\r\n -u - Uninstall.\r\n -g {guid} - GUID of file (uninstall only).\r\n -n \"name\" - Internal name of file (uninstall only).\n", "runtime_modules": [ "C:\\Windows\\system32\\sdbinst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "sdchange.exe-7C801E3D4A13B5F1047B6843B76800A8": { "file_name": "sdchange.exe", "file_path": "C:\\Windows\\system32\\sdchange.exe", "hash_md5": "7C801E3D4A13B5F1047B6843B76800A8", "hash_sha1": "5B31F95D088CF2B8ECFE82F30B02C4B8E882C8C6", "hash_sha256": "B5DD0952E1B8DAC257B6AF7E3C0674585E834A4B8EF280D730057252592F9879", "hash_sha384": "D5D1467F731B4C273D11214C8A6AA6A8D12B90860125D9806C7A4EF573FD56E36F0A747AB95B4C1AC1EEE790F30FF079", "hash_sha512": "6DDDF0F3B54F4B02F5919ACCD69A8A1913773818F2A4A7C4A7706F234D875BCA1CD7D185E3D17DA149CAEAF08EA5C430705D67D8EAF90D6803C1B5C4A995D18A", "hash_ssdeep": "1536:0ZayPR1zuZlyF40iNEIHeLSF+Bhkb8X6XwE85di:0NPRxu2O0i2E+BLmwB5di", "hash_imp": "66292039E97668307DE2282308C3E6DF", "hash_pesha1": "0DB3BB037C25F647984D9EC677CB849A9F18F5D7", "hash_pe256": "1339D26C95C74E66E96C5ED45C3879BA74A1A2870942AC3D0075A3B70F82CC9E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Remote Assistance SD Server", "meta_original_filename": "sdchange.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b5dd0952e1b8dac257b6af7e3c0674585e834a4b8ef280d730057252592f9879/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\sdchange.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\sdchange.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll" ] }, "sdclt.exe-34B64D8A4316A9C97E56C0DFCFCEC3C6": { "file_name": "sdclt.exe", "file_path": "C:\\Windows\\system32\\sdclt.exe", "hash_md5": "34B64D8A4316A9C97E56C0DFCFCEC3C6", "hash_sha1": "893E91C7E9437BFB701E3168B2273EBBFF63A0D6", "hash_sha256": "58DD58A15DA129E44CA5116E2DA71A913ABD08C7DE7F3D2F3A843F867108F9A9", "hash_sha384": "AED5E20BF06F172C07E72351B908729A75CDE0E625FB03F51E8D36D3A665E2B9D0CAEAB15650FA3666124367AB766D52", "hash_sha512": "CE88C272CFDF74496E472B43107A62B24809B2E8168B78B3141EDCB417B8748243175610CEB922EB41F5509249F17797D552F10F6E9C034CCB5D0FB7BA095E44", "hash_ssdeep": "24576:sJjr1lDybzUNu/oCexZLIh9yptQHZ7RHegR:o9N2oHZ0aQ5dH9", "hash_imp": "1F4349F0C287A904C0483B5CD434DF28", "hash_pesha1": "DD19610935D3258507BC19AC4019EAA7B900B434", "hash_pe256": "ED4DA34405E051AFE8741B8CD83FE2AEC37A58B240DFCBCBE2C241BE36F335BF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Backup", "meta_original_filename": "sdclt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/58dd58a15da129e44ca5116e2da71a913abd08c7de7f3d2f3a843f867108f9a9/detection", "runtime_modules": [ "C:\\Windows\\system32\\sdclt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\SPP.dll", "C:\\Windows\\system32\\ReAgent.dll" ] }, "sdiagnhost.exe-6A21B1893DDE94CB87BA56111375888A": { "file_name": "sdiagnhost.exe", "file_path": "C:\\Windows\\system32\\sdiagnhost.exe", "hash_md5": "6A21B1893DDE94CB87BA56111375888A", "hash_sha1": "540745F1CE67423A156069218680B9DA873B4778", "hash_sha256": "761815301A00D0B3A7BB4959A5004B623C55009CE701C6E867C96F468DC1323A", "hash_sha384": "4A7C83879CB0A023C98E7908A706B88D4B44C8CA3253884A0A9E030CD5CFEDFA821DF4D2A9A4FB4B79AC2AEFCE08B35C", "hash_sha512": "AB4261F78EABC4EFD9ECA0240C147F69A17DBFFAE0486420AA2396A1C1260F82889D060FC4D3D4959AD84C23E65BD1C0AFA8F3328B4497B14391439ECF5CAC08", "hash_ssdeep": "384:bJwNWEgA6slYA8AGoZesJ1MYEFu8BNtbFTpUHGcMXgvaNS/uoJwJsL4BxKilsWh2:dwNW764o/+b7rHNS/uLs8KiR", "hash_imp": "88C840A970A1633DCA61E1CD2D926E21", "hash_pesha1": "593CC73AEA0ED6AAD288D92C3B6A63BE8A628B19", "hash_pe256": "842636E8014B8043A4FF5BBACB6EB14E142D491AC7B7599B6B6F961AF3B142CD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Scripted Diagnostics Native Host", "meta_original_filename": "sdiagnhost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/761815301a00d0b3a7bb4959a5004b623c55009ce701c6e867c96f468dc1323a/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\sdiagnhost.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\sdiagnhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll" ] }, "SearchFilterHost.exe-1B3706231F1003B03717691C5AFCD361": { "file_name": "SearchFilterHost.exe", "file_path": "C:\\Windows\\system32\\SearchFilterHost.exe", "hash_md5": "1B3706231F1003B03717691C5AFCD361", "hash_sha1": "7CDD324302C3E568CDD1E187E1EC51CEFA2662DF", "hash_sha256": "FFBCF5F709E1E017EAC64AF5C9E232140FCA2D1A02A64C1FFFD965B1E5AB842F", "hash_sha384": "A0144EB7EB9555E9DE39FA8AEE6296D7611B00BC0416F4361729BFD88BC9492774928507E05B579CC1258ED72E699B5F", "hash_sha512": "D3DC86424FF4C047DA73B3A8C04D132582930DFDC2C746961CBDC46E7F1BFDA2294D82719F8DF1003F667C12BCA7805F40F72F3A8809E39BD10DDE42121887B0", "hash_ssdeep": "3072:TsZBSJaS2JnRUk7JlsIXO/aa+l+sg3JCG32sVPQp7d1ihk6kvtfGq0ev3U5WN:SBiaS2V/lxXiaPK2sVWorkR10efUK", "hash_imp": "25975932FE65B44EA2DD939DC008D453", "hash_pesha1": "9E4A389221505BC81BA68A73EDD598AEEBB5A826", "hash_pe256": "79E470C9A9CAC5480D26595E047D79BD7F2D4C1115D73A4B7622A22EFE180069", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Search Filter Host", "meta_original_filename": "SearchFilterHost.exe", "meta_product_name": "Windows Search", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "7.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/ffbcf5f709e1e017eac64af5c9e232140fca2d1a02a64c1fffd965b1e5ab842f/detection", "runtime_modules": [ "C:\\Windows\\system32\\SearchFilterHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "SearchIndexer.exe-2775EAF48F6E1DC05EB8E6FF98FA3A42": { "file_name": "SearchIndexer.exe", "file_path": "C:\\Windows\\system32\\SearchIndexer.exe", "hash_md5": "2775EAF48F6E1DC05EB8E6FF98FA3A42", "hash_sha1": "83E542E5A0C93F181253274C2C127327B007594F", "hash_sha256": "63B92D3657EC7E81AD3A8AD8ECA83C456752EB654715518732DA1ADC9C4241AD", "hash_sha384": "AC76CB3D00EB6CF4134F170D363DF0D7C7D59D0A0679FC0578A43AB975FC34627FD4E8AAFD9A439B0CAD9F3D21922E26", "hash_sha512": "EFD925A538E3CA7F338A648638FBF272BF3D2D0A1E01300CDC913D5752DA3D70C3DB8605D51799AD4C974383A240AA4819A3581C143FDE6E08603506048DC211", "hash_ssdeep": "24576:SCbwO4J2bdDUVXCmovWffrR7h8OYbKh74:SCbh4Z0vQrX8/bKh", "hash_imp": "A1B3FB608C2CC985C3A5D8A82E356A6F", "hash_pesha1": "36F1F9A180BF440051D4E86E404CF8CFC3125036", "hash_pe256": "6714D2212BD29E2D5139286D83EDA1AEB411405D62383159810B64A4DD697FEC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Search Indexer", "meta_original_filename": "SearchIndexer.exe.mui", "meta_product_name": "Windows Search", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "7.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/63b92d3657ec7e81ad3a8ad8eca83c456752eb654715518732da1adc9c4241ad/detection", "runtime_modules": [ "C:\\Windows\\system32\\SearchIndexer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\system32\\TQUERY.DLL", "C:\\Windows\\system32\\MSSRCH.DLL" ] }, "SearchProtocolHost.exe-62FE16D24CC7054FB9DA9EDC410F5D06": { "file_name": "SearchProtocolHost.exe", "file_path": "C:\\Windows\\system32\\SearchProtocolHost.exe", "hash_md5": "62FE16D24CC7054FB9DA9EDC410F5D06", "hash_sha1": "F1036BBC00B26C6020881A23C938DA1B66F3C03A", "hash_sha256": "59CC005C70A7E16BD2E0C8DF3DAF7E6F9FCA5B49A7A377A62775480579A5252F", "hash_sha384": "33105CFBA03CFE38C0CA592D23042326A1DB11C20F0E44B0FBCA49A601CD884829F1B129577C35E78240F79234C3291E", "hash_sha512": "D9E27FFC049B9E7E6E4FB534A69AE8CEAF703D284EB7C07E33CC56AB585B7A0B5C0FF98F9657A2FBE41897D6CF8B05A23B72B20D7141790D5A73C3566FF9063A", "hash_ssdeep": "12288:jegrIapfSxPzbSWfpDpBAGiFfcm+Qztf9:6OS9H5XB2fcfQv", "hash_imp": "8B2A73CF81704F7AED84C67134EC39AC", "hash_pesha1": "2F1BBA396D298D954A3AC92CB2B363B0CF807EFE", "hash_pe256": "21B074477C85A195DE10580D92AD8B5C680A34B817D36E53AB2D26E2A40D0FB2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Search Protocol Host", "meta_original_filename": "SearchProtocolHost.exe", "meta_product_name": "Windows Search", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "7.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/59cc005c70a7e16bd2e0c8df3daf7e6f9fca5b49a7a377a62775480579a5252f/detection", "runtime_modules": [ "C:\\Windows\\system32\\SearchProtocolHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "SecEdit.exe-FE961D8056062E047BCFBD77EBD431B7": { "file_name": "SecEdit.exe", "file_path": "C:\\Windows\\system32\\SecEdit.exe", "hash_md5": "FE961D8056062E047BCFBD77EBD431B7", "hash_sha1": "2CD7718827C793F8CA53C9FE0CC11D09E450EA67", "hash_sha256": "58348E21FB9AE1582E68AA07BF21F87D58DB03FE12123B0DF5BFB3A7E168DB26", "hash_sha384": "FA57EEE9D6F92DCAD9C55C6B62ED419AB2908222C94F94AE7AC058B5F76B479F1A58AB23BC5BD7FA5A185F452E643E31", "hash_sha512": "C4EE99BA9AD4E3B725404E564628196A0F68DE0C46D267C29FB33007C850A9A79875D007AE12C946E4BA34398B29183327438DC63A23D3F97F8D0702C32B142A", "hash_ssdeep": "768:TjqyEE2/b/6zzHDn82pvU14B+uKGWzdJqT7/pXk:NEE2D/6zzjvUmhKGWz6", "hash_imp": "58A66C69176097C9B8C5C9AE4273BD6F", "hash_pesha1": "B71284E44F41E4B89B1754A814E26BEA3E416B87", "hash_pe256": "30CE15333529587515D7A886CAEAB19B4E5EAF379707DB09DF81B7CA372FCE7D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Security Configuration Editor Command Tool", "meta_original_filename": "SeCEdit", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/58348e21fb9ae1582e68aa07bf21f87d58db03fe12123b0df5bfb3a7e168db26/detection", "output": "\r\nThe syntax of this command is:\r\n\r\nsecedit [/configure | /analyze | /import | /export | /validate | /generaterollback]\r\n", "runtime_modules": [ "C:\\Windows\\system32\\SecEdit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "secinit.exe-1CE1954EE68A2C53D8DABBF8783E118A": { "file_name": "secinit.exe", "file_path": "C:\\Windows\\system32\\secinit.exe", "hash_md5": "1CE1954EE68A2C53D8DABBF8783E118A", "hash_sha1": "750C766342D70A17BCD880134F85159DDCE4CF40", "hash_sha256": "2CDD87C41C0865DE240AA3324492C66EDED2EE0ACAC2E0532A92CDC0D664CD23", "hash_sha384": "8F5063F3FB034B7A46E26087949119D1A83199C365CE2F98AA233DF7DEE369EA7318817E04E46109BF70191DD1BEA33A", "hash_sha512": "4A106FA7C8F6B33955DEEADDAB96EAFC4F57A64CB4CBD8EED96F9EC5E8253756F69D1CD5BF96E7DA6CABC6EC61EEB1BAE81F5DFCE2F83BE53B2C2F8225BC2B83", "hash_ssdeep": "192:6AUaMc1cWhuo7KJhxGsWK+5KNf1Tqze+eIG4ahdfSm9W8vbzRiW:bQRWYwK7xvWKOrzeRIc9W8vbzRiW", "hash_imp": "26553A8E11C5CC5CD0F898A06C1EEBEA", "hash_pesha1": "837ADF8FE2E09F28641F4FEE02548BF061922562", "hash_pe256": "85AC42DEC9DBFB4650E27BE73228740F1BE596799EFB21AC9D152A1A2C00728F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Security Init", "meta_original_filename": "secinit", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2cdd87c41c0865de240aa3324492c66eded2ee0acac2e0532a92cdc0d664cd23/detection", "runtime_modules": [ "C:\\Windows\\system32\\secinit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "securekernel.exe-E0AB270381D77BBCE0F318E092A2AA5C": { "file_name": "securekernel.exe", "file_path": "C:\\Windows\\system32\\securekernel.exe", "hash_md5": "E0AB270381D77BBCE0F318E092A2AA5C", "hash_sha1": "B9333E6613EA1808090F4547DB83AFD4A6223D85", "hash_sha256": "76E30B0EE68CD42445AD5CF493CB178C3FB4B6FBA70D62847B03C26B9CC4E43E", "hash_sha384": "378FE169CA71576437EF4111F4A5B2138E70F6F26C54C3BECAC636CAEF7CBF77F4818633C16BF01354211933D0007FEB", "hash_sha512": "66C44528A41446712B9DDA9A5E9D9ADED432D174F002B3338330884F56C74A40F355D0772438A39D6F40E7A6FC740EF1A7DBD1FCC517716B5B89742EA0D53394", "hash_ssdeep": "12288:ISuydwHJmS/d3BvqxvRitgUfAr0MKWjFZVir9OXN/elJYFHaRttttZ3OLzH0Cb7R:Dbg/d3qaMjFTG0XgwFHQttttR4Hd", "hash_imp": "18399EDE6C02958819045C1CB263C0B9", "hash_pesha1": "C6DDBB6DAD20BE0F8AAF743401939F20082F04E6", "hash_pe256": "EDF417887EA2D66B883A177090EA8F441770CFA7564C65A4A56869D69F9ECAD0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NT Secure Kernel", "meta_original_filename": "securekernel.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/76e30b0ee68cd42445ad5cf493cb178c3fb4b6fba70d62847b03c26b9cc4e43e/detection" }, "SecurityHealthHost.exe-4DDD148F1F3D0BD86EB26EF8F05499FF": { "file_name": "SecurityHealthHost.exe", "file_path": "C:\\Windows\\system32\\SecurityHealthHost.exe", "hash_md5": "4DDD148F1F3D0BD86EB26EF8F05499FF", "hash_sha1": "0FC16D0BA6EB0FD14AE18F231ABE70ABFDBA4781", "hash_sha256": "9E51AE18554E6BF48B475BE5CB5D8149691A5E73A97A53CAE00448BF5C86B2B8", "hash_sha384": "6931D95E6850523596151A23AEB6443C3D4DFEC4339449744EB0983BDFF2F7DAEF43080771AB627405F7BB35F44C79C7", "hash_sha512": "07D7DFACA2CFEA6FDD437435B41EEDB86FF6C8A942776CFE7873BC3BF720DF6AC7582BC072B2E4ADA297904A8185FFBC46143BFE29AF4EF610E6A47C35155D15", "hash_ssdeep": "1536:Ii7x3sT6ALT1T3nFr68IVtTLjnQiJuMRYtGAf+J8hgiHboPP/Jc:iNVFhgLDkU3kysoPq", "hash_imp": "4E28FDA241BEFA94F219E0683850258F", "hash_pesha1": "EC1C4C5762FB05C2003E295421F6E6AF0D131B29", "hash_pe256": "D1F783151492185B98FA5417DF1CBA37C3BD608A4E31E8C108ABECC0E5B6646F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Security Health Host", "meta_original_filename": "SecurityHealthHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.1907.16384 (WinBuild.160101.0800)", "meta_product_version": "4.18.1907.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/9e51ae18554e6bf48b475be5cb5d8149691a5e73a97a53cae00448bf5c86b2b8/detection", "runtime_modules": [ "C:\\Windows\\system32\\SecurityHealthHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\CRYPT32.dll" ] }, "SecurityHealthService.exe-96BE970B2CB0BB0A86D8F74C1A3F8596": { "file_name": "SecurityHealthService.exe", "file_path": "C:\\Windows\\system32\\SecurityHealthService.exe", "hash_md5": "96BE970B2CB0BB0A86D8F74C1A3F8596", "hash_sha1": "67C9150529F292FB5A2511CFBBB89E9749ECCDEE", "hash_sha256": "8A33DA8CC05398C29688C5BB4D8643EE055F9E707FDBC80815CCFADAD7824C2C", "hash_sha384": "BC2C824900A80A24232F89FEEB95553AB3343C908CAA95DE782B26E1D81366955DC82D4E7066AF5AD4D79239FF4B0ED2", "hash_sha512": "5CBE9A06179C6BF0C9C2CAA7102982EFBB8403F69C95F9FE5ACA05391081A4364F467FD666E85BEE5215D1C7685D972A0C2E9A1AC35D3E9F4A0A45EEA177F16D", "hash_ssdeep": "24576:nTTDSXwRPhDsw5JJO1y79VSJ8hF1zTuad0:nB5JJO5GL1zTuad0", "hash_imp": "2601842F772C1F9ABA3AAD89180D20E0", "hash_pesha1": "7C28B68B33EACBA8E72EE86385BC2EC51D989845", "hash_pe256": "5578494375FFE903F57D897E6B3A76451D9D24F7BFDB704FA2CD488090B330AC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Security Health Service", "meta_original_filename": "SecurityHealthService.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.1907.16384 (WinBuild.160101.0800)", "meta_product_version": "4.18.1907.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8a33da8cc05398c29688c5bb4d8643ee055f9e707fdbc80815ccfadad7824c2c/detection", "output": "Unknown switch.\r\n" }, "SecurityHealthSystray.exe-783C99AFD4C2AE6950FA5694389D2CFA": { "file_name": "SecurityHealthSystray.exe", "file_path": "C:\\Windows\\system32\\SecurityHealthSystray.exe", "hash_md5": "783C99AFD4C2AE6950FA5694389D2CFA", "hash_sha1": "D79D21F4D6741F83FB98FDCF8D06FE8C5D78A799", "hash_sha256": "570B37A7A3FFDAFCCECCC33CBC1968FEB857B73CA3CB4DFFEDC2E67E9ABD0878", "hash_sha384": "6022A3C0C0D93BE920073A61464D574522C97C44E0D0BAB26654A3343402D12EAA4B43DB39B116244F245637D38BB636", "hash_sha512": "64CF69020713119C0B1633B600435F18342052F9DE0529CE658446E041CC51FBF73AF4C92E41C77417C8ADC35C78A15188CFD8C5A90AFB89CCAF0B440AFE4ACA", "hash_ssdeep": "768:8r/PLGOY9Vl4qvTLC+pIxtFfNKgfP5uYoNIjDx0Nw4BygrPoB90g:yI9Vl4Q2p0gfPviOx0/BygrPoBq", "hash_imp": "E6B44B525767F585EB30F35172497CB0", "hash_pesha1": "0C18123CF9F366D55403C5670E49B43FAE87CD97", "hash_pe256": "9B83EF83482631EB2FFA3CC77BA766EF12B686F5923809E2FFAEE2E405D97444", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Security notification icon", "meta_original_filename": "SecurityHealthSystray.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/570b37a7a3ffdafcceccc33cbc1968feb857b73ca3cb4dffedc2e67e9abd0878/detection", "runtime_modules": [ "C:\\Windows\\system32\\SecurityHealthSystray.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "SensorDataService.exe-38339304CB5D1154A10699A526ABDF4F": { "file_name": "SensorDataService.exe", "file_path": "C:\\Windows\\system32\\SensorDataService.exe", "hash_md5": "38339304CB5D1154A10699A526ABDF4F", "hash_sha1": "D6BAC444089667455F041846C95E849BB3E78480", "hash_sha256": "B7027BFF6DBFC68315CCE2B6E8F4A5854A94C388D7AF71FE4F59B58F43C742C1", "hash_sha384": "A03EC897108B73D36818BB56E248E6C8B87BD12DD97D47364E134B23C33411999F084E0A3CD13702247B207F390A1FF8", "hash_sha512": "B613237E28428860E631A9969078D175C777179153D84955579C11643305E5E155CFFCF2DBE97BA67BCA8C5C706114FF7EDA73282F9F3301F609C600913B5CA6", "hash_ssdeep": "12288:c8y5o/xqUoD0Q1cxH6UaOwVJTVpdBMDyhSyMiVbry81mEhg0GduGd6B:c1CxqUoDRTDVfkyrLny81hZGAGd6", "hash_imp": "3BE3970BBCE80A537BD7C47F27ADE20C", "hash_pesha1": "34A0412BEC1949A01075E64ABAF7A85053315757", "hash_pe256": "CB6F827732E2836A54464C792DE91174668CB3E87DF01A219054DFF38CECA4A0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Sensor Data Service", "meta_original_filename": "SensorDataService.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b7027bff6dbfc68315cce2b6e8f4a5854a94c388d7af71fe4f59b58f43c742c1/detection", "runtime_modules": [ "C:\\Windows\\system32\\SensorDataService.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "services.exe-1B8FD5BCAF4B90950D50AAC16B0DF9A3": { "file_name": "services.exe", "file_path": "C:\\Windows\\system32\\services.exe", "hash_md5": "1B8FD5BCAF4B90950D50AAC16B0DF9A3", "hash_sha1": "FFB38669750CEC946E81F0114AABD1A2555A51E9", "hash_sha256": "F14CBE42E4C29C57ACDF781388D387A01963075F255ABF57D8486D7842257500", "hash_sha384": "41B464052D287E33A8A994C339B60061C7DA591AACDB61AC0A60E7B300BCCA14DB743E90DF1049F5BC4038706E06C4A0", "hash_sha512": "AEDC98B67C590D05C0F103865741B2F502D70B73EB7F6CA519C227B5FCFF28AF702831AC5CE02D78725E483A063CBEC71C4FF869EA18DDF07ABB1F56E9C30AD2", "hash_ssdeep": "12288:n8mrmpMj8jAkkteIKuk91HcFsJOkK1tvX0o50RKEQA:n8m6ej3kweBuwiu4fNX0o50/", "hash_imp": "CDE9FC783A23D72BBCF6C4DDCC10ED87", "hash_pesha1": "CC44E3501489CD9BA145E09D7E2662D06E5513B3", "hash_pe256": "488F11922738FA01284294BDFCC784A50B435AB702F7F96D2D813BA96B1F01A0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Services and Controller app", "meta_original_filename": "services.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f14cbe42e4c29c57acdf781388d387a01963075f255abf57d8486d7842257500/detection" }, "sessionmsg.exe-C07A27BF54DD7A6B892846548CCEDA13": { "file_name": "sessionmsg.exe", "file_path": "C:\\Windows\\system32\\sessionmsg.exe", "hash_md5": "C07A27BF54DD7A6B892846548CCEDA13", "hash_sha1": "AC324C853F71A9C071FA75F19BE55BC93E14D5A8", "hash_sha256": "1FDEB92B01AA906A7FBEC8573C70480EDFCD2A35649CCA7F1EBF2B3755AE0FAE", "hash_sha384": "DD7141AF520C96851C22300A6240098C686831D9A4CD50B7D835998FC744E5948A2433533D10CF5E064655B278AD1BDF", "hash_sha512": "60F4CB583A9A436823896E35109AE7E1390E3227B0474E2C2A68B4089BAB66F77B21D62F2392AF36BD23A9350ECE3A4D5ADF1A00225FA754455EAC225D4EF3DF", "hash_ssdeep": "1536:Co66RLekVSZkdJJdPm/su/p2v6F+WaITVwhIbMFEiJCPW:dnQqdJYZpu6F+STVwhIbMqlu", "hash_imp": "1F9ABC3E0DF808E5F1C188F772C8385D", "hash_pesha1": "81B3B916FC6511F2AB886095CC2BF5544EFF107F", "hash_pe256": "C69A86504A4074BA315EBE1110FD44D39695C25348BD57BEC5A55DF03F406AB7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Remote Desktop Services Session Message Server", "meta_original_filename": "SessionMsg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1fdeb92b01aa906a7fbec8573c70480edfcd2a35649cca7f1ebf2b3755ae0fae/detection", "children": [ "csrss.exe", "winlogon.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\sessionmsg.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\sessionmsg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll" ] }, "sethc.exe-8BA3A9702A3F1799431CAD6A290223A6": { "file_name": "sethc.exe", "file_path": "C:\\Windows\\system32\\sethc.exe", "hash_md5": "8BA3A9702A3F1799431CAD6A290223A6", "hash_sha1": "9C7DC9B6830297C8F759D1F46C8B36664E26C031", "hash_sha256": "615B2F2D7E3FCE340839A9B54BDC3445EB2333D0FAFEE477D6113379E90935B8", "hash_sha384": "E2FB2A230A9F16D836E5993397829B3A705FC078F72016A9ABAA88500511753844A8E1672D5F1ACEAB3E829E3051D290", "hash_sha512": "680C216D54F4FD2A14F0398E4461C8340AC15ACDCA75C36A42083625E1081D5E7D262C4C12296B6F21BA2F593F92816EDF1C9A0CF4CBEE23588E590713B87746", "hash_ssdeep": "3072:1atXdQaL4XqVpGlqWRNp756WGrzH5GNz:eXNsqVklqWRNp75NuY", "hash_imp": "AD694ADFA4060E27C7194543DE6A15FA", "hash_pesha1": "1866101E37FA098C05AC22AD050BB87EE3F69983", "hash_pe256": "0196F87BAD7B869ABE34DF4045CF523EAE10D17B83B934C0F8D4A08F4E6F04E5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Accessibility shortcut keys", "meta_original_filename": "sethc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/615b2f2d7e3fce340839a9b54bdc3445eb2333d0fafee477d6113379e90935b8/detection", "runtime_modules": [ "C:\\Windows\\system32\\sethc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "setspn.exe-9DEC0F79D40FB78BA94E770E2D8D942B": { "file_name": "setspn.exe", "file_path": "C:\\Windows\\system32\\setspn.exe", "hash_md5": "9DEC0F79D40FB78BA94E770E2D8D942B", "hash_sha1": "68A1857D6F40FD5F6CBC05D49896F71DB556B16E", "hash_sha256": "3EE597FA9B3333AB491807F48AEC985C4429F975E0DABCE2AF0CCAA182628884", "hash_sha384": "4521FC148B23BECA34251D704097DDB90AC3C1D5FAEAC00F07A7DE1F67F61172ADEC653FA761C9B8FC9817C4D3FB310D", "hash_sha512": "23871330177E9EF9B33CAE1BE74C9A4BFA57496F879880EF7B8502422D3FF9BE6562659E1ECDBBA984BC8B0355BE10198F9C546D7B904D566CDD828802892AF1", "hash_ssdeep": "768:6tM372OwDBqKg2d8qxQDHpX32A0AQpL4iVI4h0q+YmF:6a372OwdI2OOa123R4iz0RYmF", "hash_imp": "E6B8038038B9ABF6ACB11E0A8BE9BB84", "hash_pesha1": "A9C404CE14B14478355EA450716CE2E4BBF5D9F9", "hash_pe256": "DD16A1DCEC8291FA987A0F9B99CF7CEF3705158602FA7F8F166371A7EB0B8ACD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query or reset the computer's SPN attribute", "meta_original_filename": "setspn.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3ee597fa9b3333ab491807f48aec985c4429f975e0dabce2af0ccaa182628884/detection", "output": "Usage: C:\\Windows\\system32\\setspn.exe [modifiers switch] [accountname] \r\n Where \"accountname\" can be the name or domain\\name\r\n of the target computer or user account\r\n\r\n Edit Mode Switches:\r\n -R = reset HOST ServicePrincipalName\r\n Usage: setspn -R accountname\r\n -S = add arbitrary SPN after verifying no duplicates exist\r\n Usage: setspn -S SPN accountname\r\n -D = delete arbitrary SPN\r\n Usage: setspn -D SPN accountname\r\n -L = list SPNs registered to target account\r\n Usage: setspn [-L] accountname \r\n\r\n Edit Mode Modifiers:\r\n -C = specify that accountname is a computer account\r\n -U = specify that accountname is a user account\r\n \r\n Note: -C and -U are exclusive. If neither is specified, the tool\r\n will interpret accountname as a computer name if such a computer\r\n exists, and a user name if it does not.\r\n\r\n Query Mode Switches:\r\n -Q = query for existence of SPN\r\n Usage: setspn -Q SPN \r\n -X = search for duplicate SPNs\r\n Usage: setspn -X \r\n\r\n Note: searching for duplicates, especially forestwide, can take\r\n a long period of time and a large amount of memory. -Q will execute\r\n on each target domain/forest. -X will return duplicates that exist\r\n across all targets. SPNs are not required to be unique across forests,\r\n but duplicates can cause authentication issues when authenticating\r\n cross-forest.\r\n\r\n Query Mode Modifiers:\r\n -P = suppresses progress to the console and can be used when redirecting\r\n output to a file or when used in an unattended script. There will be no\r\n output until the command is complete.\r\n -F = perform queries at the forest, rather than domain level\r\n -T = perform query on the speicified domain or forest (when -F is also used)\r\n Usage: setspn -T domain (switches and other parameters)\r\n \"\" or * can be used to indicate the current domain or forest.\r\n\r\n Note: these modifiers can be used with the -S switch in order to specify\r\n where the check for duplicates should be performed before adding the SPN.\r\n Note: -T can be specified multiple times.\r\n\r\nExamples: \r\nsetspn -R daserver1 \r\n It will register SPN \"HOST/daserver1\" and \"HOST/{DNS of daserver1}\" \r\nsetspn -S http/daserver daserver1 \r\n It will register SPN \"http/daserver\" for computer \"daserver1\" \r\n if no such SPN exists in the domain\r\nsetspn -D http/daserver daserver1 \r\n It will delete SPN \"http/daserver\" for computer \"daserver1\" \r\nsetspn -F -S http/daserver daserver1 \r\n It will register SPN \"http/daserver\" for computer \"daserver1\"\r\n if no such SPN exists in the forest\r\nsetspn -U -S http/daserver dauser \r\n It will register SPN \"http/daserver\" for user account \"dauser\" \r\n if no such SPN exists in the domain\r\nsetspn -T * -T bar -X\r\n It will report all duplicate registration of SPNs in this domain and bar\r\nsetspn -T bar -F -Q */daserver\r\n It will find all SPNs of the form */daserver registered in the forest to\r\n which bar belongs\r\n", "error": "FindDomainForAccount: Call to DsGetDcNameWithAccountW failed with return value 0x0000054B\r\nCould not find account help\r\n", "runtime_modules": [ "C:\\Windows\\system32\\setspn.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "SettingSyncHost.exe-080B1B825DD5C47B661795FA7AB83C6A": { "file_name": "SettingSyncHost.exe", "file_path": "C:\\Windows\\system32\\SettingSyncHost.exe", "hash_md5": "080B1B825DD5C47B661795FA7AB83C6A", "hash_sha1": "556DA7E1928BF4F32A9C5B550141EFC4309E9F49", "hash_sha256": "73D8F23A1ACF635A39B2DCB8B37304658F6F84D1090AF961EA031EFAB833D916", "hash_sha384": "D4251DA3097702CFA5E62C5130BBA1A0594C6AED273919AC97F590A4530197452885A1445111B833BA8573137233BD23", "hash_sha512": "69A6FA5C93F0729BA54EE6F46E80AF09AEAB355A594EEB3CD7A830553969EADFAEF637042B1ABBD442B22F31A21E2A5F89105A6F447CEEF9BAB09424D0D9C932", "hash_ssdeep": "24576:I8IflK01N/Jsr8YZD73W3Jdm0TzVYf7uA6:sfqD73+JPT5Yf7uf", "hash_imp": "8049F9993FD0B0E41EDE568A3C5646B8", "hash_pesha1": "84948592B65113C2FC2E4AE3B2F26E900B538144", "hash_pe256": "2C1AC310B4B9E42BA347FF11F39E4C93623FB99321D4D0C5E8076BEDDE4840B3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Setting Synchronization", "meta_original_filename": "SettingSyncHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/73d8f23a1acf635a39b2dcb8b37304658f6f84d1090af961ea031efab833d916/detection", "runtime_modules": [ "C:\\Windows\\system32\\SettingSyncHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll" ] }, "setupcl.exe-501D2B053F7EAD583763E758038CE68A": { "file_name": "setupcl.exe", "file_path": "C:\\Windows\\system32\\setupcl.exe", "hash_md5": "501D2B053F7EAD583763E758038CE68A", "hash_sha1": "5DB3C5AEFC28214C73F24EC4D2B416D9E6A0423D", "hash_sha256": "913C6ECFEB0E6B7347682C7CA9E7BF5CF5D875BB52E7A4332D305B10C5F16DB1", "hash_sha384": "84F3C8851ED6FC19791F7D9A4FAE35D1C7704E61F610D79F28457C4B82B15E679140C74D19DCE78A70C46043BA03BB94", "hash_sha512": "1084465DD01E5D959C3A5F1A6A4D0701C185551B079823F87F679A4F22433F45454DC8489773741C5C2CC2CEECC7B216D72B5ADC2E982353D1DBCF26E4F1791F", "hash_ssdeep": "96:ZL22RAp6NAj5gMwV02STdhiUa5NBxtI0E0yMQWmnDJvmMDAASEWTVWw:ZyEa7wV02SFoW0E0rQWmRmsWTVW", "hash_imp": "E6EC033D50C4AA333266D896D32511BD", "hash_pesha1": "B4805B71AF67C14DA82D83E622453A642DB7E279", "hash_pe256": "A578E1CB815F3B7FF1F1E1BC59A4220899FFF6B3A60FCCCC4793765108460DEF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Clone Tool", "meta_original_filename": "Setupcl.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/913c6ecfeb0e6b7347682c7ca9e7bf5cf5d875bb52e7a4332d305b10c5f16db1/detection" }, "setupugc.exe-3E8F0CD57528C0B3E420531E743DD462": { "file_name": "setupugc.exe", "file_path": "C:\\Windows\\system32\\setupugc.exe", "hash_md5": "3E8F0CD57528C0B3E420531E743DD462", "hash_sha1": "22BF14DC941CEF74379206E61905C65BC81A4EFE", "hash_sha256": "6CA35B1605ED1C3BA18181163FB8376FC7C080D2DC4DCE1D726EB41CB92E9754", "hash_sha384": "EFA27E7942BC7481AD91420DD53853E73AC15E671B565FFB74070BABA340AFA130F0DCADD5FCEFB65133A9D1722620E6", "hash_sha512": "3F717703EE4BA87F5763F8F833615AD79C6DA5C06E9220564EC5D0380D31A98F183B1A45690979D4DDC146E0C45770555C9FFD282E316423AC9C284048C6DBF8", "hash_ssdeep": "3072:hOGI0OpMn4cA7Db7XjVACpTCZjbjtpy23aTcxXX:hrI0OpMUfb7zVrdCZTtw23aTG", "hash_imp": "EE1D28548AC1502EBE59FBB75127C02A", "hash_pesha1": "32CAFCFB8C6F69289CF14F6D0E06D4B0342C173D", "hash_pe256": "FB3654C9FFD62DE2965347D1112000CFADFBD0904835DECEBBCF6F8C88A02CE7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Setup Unattend Generic Command Processor", "meta_original_filename": "SETUPUGC.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/6ca35b1605ed1c3ba18181163fb8376fc7c080d2dc4dce1d726eb41cb92e9754/detection", "runtime_modules": [ "C:\\Windows\\system32\\setupugc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\system32\\WDSCORE.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "setx.exe-7D809CCFEC9A92BC2C6B35247473245B": { "file_name": "setx.exe", "file_path": "C:\\Windows\\system32\\setx.exe", "hash_md5": "7D809CCFEC9A92BC2C6B35247473245B", "hash_sha1": "AD79E24BA010465E964941573289408FFC342ED0", "hash_sha256": "F207F3BF4B4D3F2C73DB94BAA69CE81CC0675F7C638B5D747C8C46F4323A2F44", "hash_sha384": "AE791B6656F7219655A8CFF0138FEA117A31979218778DAD8E43A0CE070A94AC0A0333ECBC2C82979E25C79AC35312A6", "hash_sha512": "1DA8F5009437038080526073F99F69D27C96FB3071A78E16EC002026ECAABCA337D16CDFD523CD2EB2A6789228DA987E948E94570352EE770FCBFBFFA1799E1A", "hash_ssdeep": "1536:ggvUfgYx+EORiLLuyi9Lo3lxO/EKM89HANa1252:JYx+no3gJ5ANa12o", "hash_imp": "C557D5D19CCB921CE7CDDF694D378625", "hash_pesha1": "919CCDE6A7B7FAF816FF5D17B51257281E40969F", "hash_pe256": "6B1AAE4603F74F765C27224CB1536DDEB7D781715F0ADE61E2525EB8E07BF1E8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Setx - Sets environment variables", "meta_original_filename": "setx.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/f207f3bf4b4d3f2c73db94baa69ce81cc0675f7c638b5d747c8c46f4323a2f44/detection", "output": "\r\nSetX has three ways of working: \r\n\r\nSyntax 1:\r\n SETX [/S system [/U [domain\\]user [/P [password]]]] var value [/M]\r\n\r\nSyntax 2:\r\n SETX [/S system [/U [domain\\]user [/P [password]]]] var /K regpath [/M]\r\n\r\nSyntax 3:\r\n SETX [/S system [/U [domain\\]user [/P [password]]]]\r\n /F file {var {/A x,y | /R x,y string}[/M] | /X} [/D delimiters]\r\n\r\nDescription:\r\n Creates or modifies environment variables in the user or system\r\n environment. Can set variables based on arguments, regkeys or\r\n file input.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n var Specifies the environment variable to set.\r\n\r\n value Specifies a value to be assigned to the \r\n environment variable.\r\n\r\n /K regpath Specifies that the variable is set based\r\n on information from a registry key.\r\n Path should be specified in the format of\r\n hive\\key\\...\\value. For example,\r\n HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\\r\n Control\\TimeZoneInformation\\StandardName.\r\n\r\n /F file Specifies the filename of the text file\r\n to use.\r\n\r\n /A x,y Specifies absolute file coordinates\r\n (line X, item Y) as parameters to search \r\n within the file.\r\n\r\n /R x,y string Specifies relative file coordinates with\r\n respect to \"string\" as the search parameters.\r\n\r\n /M Specifies that the variable should be set in\r\n the system wide (HKEY_LOCAL_MACHINE)\r\n environment. The default is to set the\r\n variable under the HKEY_CURRENT_USER \r\n environment.\r\n\r\n /X Displays file contents with x,y coordinates.\r\n\r\n /D delimiters Specifies additional delimiters such as \",\"\r\n or \"\\\". The built-in delimiters are space,\r\n tab, carriage return, and linefeed. Any \r\n ASCII character can be used as an additional\r\n delimiter. The maximum number of delimiters,\r\n including the built-in delimiters, is 15.\r\n\r\n /? Displays this help message.\r\n\r\nNOTE: 1) SETX writes variables to the master environment in the registry.\r\n\r\n 2) On a local system, variables created or modified by this tool\r\n will be available in future command windows but not in the\r\n current CMD.exe command window.\r\n\r\n 3) On a remote system, variables created or modified by this tool\r\n will be available at the next logon session.\r\n\r\n 4) The valid Registry Key data types are REG_DWORD, REG_EXPAND_SZ,\r\n REG_SZ, REG_MULTI_SZ.\r\n\r\n 5) Supported hives: HKEY_LOCAL_MACHINE (HKLM),\r\n HKEY_CURRENT_USER (HKCU).\r\n\r\n 6) Delimiters are case sensitive.\r\n\r\n 7) REG_DWORD values are extracted from the registry in decimal \r\n format.\r\n\r\nExamples:\r\n SETX MACHINE COMPAQ \r\n SETX MACHINE \"COMPAQ COMPUTER\" /M\r\n SETX MYPATH \"%PATH%\"\r\n SETX MYPATH ~PATH~\r\n SETX /S system /U user /P password MACHINE COMPAQ \r\n SETX /S system /U user /P password MYPATH ^%PATH^% \r\n SETX TZONE /K HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\\r\n Control\\TimeZoneInformation\\StandardName\r\n SETX BUILD /K \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\r\n NT\\CurrentVersion\\CurrentBuildNumber\" /M\r\n SETX /S system /U user /P password TZONE /K HKEY_LOCAL_MACHINE\\\r\n System\\CurrentControlSet\\Control\\TimeZoneInformation\\\r\n StandardName\r\n SETX /S system /U user /P password BUILD /K \r\n \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\\r\n CurrentVersion\\CurrentBuildNumber\" /M\r\n SETX /F ipconfig.out /X \r\n SETX IPADDR /F ipconfig.out /A 5,11 \r\n SETX OCTET1 /F ipconfig.out /A 5,3 /D \"#$*.\" \r\n SETX IPGATEWAY /F ipconfig.out /R 0,7 Gateway\r\n SETX /S system /U user /P password /F c:\\ipconfig.out /X\r\n", "error": "ERROR: Invalid syntax.\r\nType \"SETX /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\setx.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "sfc.exe-F0600834BCA330548F261FBAADF783F9": { "file_name": "sfc.exe", "file_path": "C:\\Windows\\system32\\sfc.exe", "hash_md5": "F0600834BCA330548F261FBAADF783F9", "hash_sha1": "8D76F73ECBD6837424C1845FF3E3BFA09B16F79D", "hash_sha256": "E7A57BE660B32AEBEC5C59786D9F56DE1DFB9E4BCE2B1AAEFEA94CAAC5C63E42", "hash_sha384": "F0972D3556DC3B1B630799073C796EC76C6332458E757323E598ABAA908EC68FFBF055A48F9BF8D665ECA9B1288A6368", "hash_sha512": "6F701FA28AF5D235A72337120510FC42CCAEE7DF654AC0D4E9DC14AC63DB6322C49A4D6CD2E63D74CE53FA34FDF735A08D15A0EBEE56DC4F9A9766493DA040E1", "hash_ssdeep": "1536:hO1eY5wNp9njw3I8QQ/Q/CZ2ujdQsGyhP:m35J/0j+GsP", "hash_imp": "B189E8379F15898C31342CC9D3ED02C7", "hash_pesha1": "416355E7F3D1A292D9E0480B8D1DB60E5A51A6AE", "hash_pe256": "DBF3FE018639860EF7A8FD0C10887812308047CAF7B5C744D6F9AF9FB7D514DF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Integrity Check and Repair", "meta_original_filename": "sfc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e7a57be660b32aebec5c59786d9f56de1dfb9e4bce2b1aaefea94caac5c63e42/detection", "output": "\r\r\nMicrosoft (R) Windows (R) Resource Checker Version 6.0\r\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\r\n\r\r\nScans the integrity of all protected system files and replaces incorrect versions with \r\r\ncorrect Microsoft versions.\r\r\n\r\r\nSFC [/SCANNOW] [/VERIFYONLY] [/SCANFILE=<file>] [/VERIFYFILE=<file>]\r\r\n [/OFFWINDIR=<offline windows directory> /OFFBOOTDIR=<offline boot directory> [/OFFLOGFILE=<log file path>]]\r\r\n\r\r\n/SCANNOW Scans integrity of all protected system files and repairs files with\r\r\n problems when possible.\r\r\n/VERIFYONLY Scans integrity of all protected system files. No repair operation is\r\r\n performed.\r\r\n/SCANFILE Scans integrity of the referenced file, repairs file if problems are\r\r\n identified. Specify full path <file>\r\r\n/VERIFYFILE Verifies the integrity of the file with full path <file>. No repair\r\r\n operation is performed.\r\r\n/OFFBOOTDIR For offline repair, specify the location of the offline boot directory\r\r\n/OFFWINDIR For offline repair, specify the location of the offline windows directory\r\r\n/OFFLOGFILE For offline repair, optionally enable logging by specifying a log file path\r\r\n\r\r\ne.g.\r\r\n\r\r\n sfc /SCANNOW\r\r\n sfc /VERIFYFILE=c:\\windows\\system32\\kernel32.dll\r\r\n sfc /SCANFILE=d:\\windows\\system32\\kernel32.dll /OFFBOOTDIR=d:\\ /OFFWINDIR=d:\\windows\r\r\n sfc /SCANFILE=d:\\windows\\system32\\kernel32.dll /OFFBOOTDIR=d:\\ /OFFWINDIR=d:\\windows /OFFLOGFILE=c:\\log.txt\r\r\n sfc /VERIFYONLY\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\sfc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "SgrmBroker.exe-3BA1A18A0DC30A0545E7765CB97D8E63": { "file_name": "SgrmBroker.exe", "file_path": "C:\\Windows\\system32\\SgrmBroker.exe", "hash_md5": "3BA1A18A0DC30A0545E7765CB97D8E63", "hash_sha1": "9B39F815CA4416BFF574D01C90D03D2DF2A0BDD7", "hash_sha256": "F9CBF1FF87D6F11920C4B7367EA2178BF13AA276C65D918950683983F268BC1F", "hash_sha384": "67EF4110903E48736CCB61E873BCAEFC432D872212ADEE8A3CBF8C12B0E02A1EF9CBF0D8CBA874DABB9756FACCAF091E", "hash_sha512": "1FE0E69CC5A07E9A8906B4E1D10ADF2229C75C43301D931B9BCE389E2C9B33B3D95DFF0246C569C30457DAF41C5FE9B527131E23258BB8ED4EC1824D83D7C918", "hash_ssdeep": "6144:Fy/t/nnT8bRdOz1ObFFT/++ebo9D1iKE97mazeyLCVL:c/5T+RdOzMbFFTG+eEWNmSL+L", "hash_imp": "A1CEC4880519264E008442D1427A48FB", "hash_pesha1": "13E6C3BE742C4CB7338DFECD779E3874596D8458", "hash_pe256": "7F2570384FA585034F48FD2A365310BED6AF1D876E653C82A481D0268ACD22D1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Guard Runtime Monitor Broker Service", "meta_original_filename": "SgrmBroker.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f9cbf1ff87d6f11920c4b7367ea2178bf13aa276c65d918950683983f268bc1f/detection" }, "SgrmLpac.exe-7E4F5EE531A80E80B2AB7CC2F5621EEC": { "file_name": "SgrmLpac.exe", "file_path": "C:\\Windows\\system32\\SgrmLpac.exe", "hash_md5": "7E4F5EE531A80E80B2AB7CC2F5621EEC", "hash_sha1": "9019DFD840C8AB98469A401F58ED752F42191EA9", "hash_sha256": "249B9A3A875AF413328BC559620FEC131A0DB707CB6B46001C752ADCF3E043DF", "hash_sha384": "6B752E6852D1A1AC1AA52C494A8BF7016417DC4C173F1E5728D573860E6D60FF1A5DE7A6EF8CAE7D4A4D695EE13EC939", "hash_sha512": "B6522FC68B28A35C663C172F03ADF0A6238AD7938CCF9D2E5FBFEAEBDACF5FFC304C6756C8D6EE1DD760A07BEC46FE655B43993E17ECCD90840E0F62292A1241", "hash_ssdeep": "1536:fZHzBtJZAVuHIvlxqWW4ltu8HB/9ktyqPly:RLJZAVuHgwWWwtus7ktyqty", "hash_imp": "78899CFF817AD8547147D8AD92BCABE2", "hash_pesha1": "85E95834E1E586B62806610490D17D38F545003E", "hash_pe256": "60EC1D2978FBD7CF3F761693ACD6088D6228686B69EAC9E9689318CAFE8FA21B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Guard Runtime Monitor LPAC", "meta_original_filename": "SgrmLpac.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/249b9a3a875af413328bc559620fec131a0db707cb6b46001c752adcf3e043df/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SgrmLpac.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\WINHTTP.dll" ] }, "shrpubw.exe-9910D5C62428EC5F92B04ABF9428EEC9": { "file_name": "shrpubw.exe", "file_path": "C:\\Windows\\system32\\shrpubw.exe", "hash_md5": "9910D5C62428EC5F92B04ABF9428EEC9", "hash_sha1": "05F27D7515E8AE1FA3BC974EC65B864EC4C9AC8B", "hash_sha256": "6B84E6E55D8572D7EDF0B6243D00ABB651FCB0CDDDDAC8461DE5F9BB80035A2E", "hash_sha384": "41CD7222C52FF01B0DD3EF808AA4121F482286C5010C45B5AB41EFFEF75DDCE09EF1A2FC29B2E6AFEB2234090AD76C90", "hash_sha512": "01BE043F7FF879A683E53962EEC58456BA200D6787EA66581BB62669AE65D5E58A5577CDF23441165F7A535FCE1DEC933E3AD2465C72172B4A1488B24CE722CB", "hash_ssdeep": "1536:YGanoDUow1Wt446VQFRlrDk7BOrkfRIUUgzwpRc:5nDKWt446VQF/r5k+jAww", "hash_imp": "521C24CDD31AC7EEAE6AE8E5130A93F2", "hash_pesha1": "7F33EAE6682E46CCD339B586DD7C813589DA0B23", "hash_pe256": "7B5A4D025955681FE3E485F0B7167645EE497A4E3499C1FEC2613FD7225CAA6A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Share Creation Wizard", "meta_original_filename": "shrpubw.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/6b84e6e55d8572d7edf0b6243d00abb651fcb0cddddac8461de5f9bb80035a2e/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\shrpubw.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\aclui.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\shrpubw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll" ], "runtime_window_title": "Create A Shared Folder Wizard" }, "shutdown.exe-F2A4E18DA72BB2C5B21076A5DE382A20": { "file_name": "shutdown.exe", "file_path": "C:\\Windows\\system32\\shutdown.exe", "hash_md5": "F2A4E18DA72BB2C5B21076A5DE382A20", "hash_sha1": "DAF6D8AF4E015DD9242998D8288557B253F30143", "hash_sha256": "D4E68CC9CB1965D70134C68BD1A090E0AFAE5B8B3D8018C6B6564852AE7BF396", "hash_sha384": "B9167142A331F456BCE0814845367ACA6E7C78A86C6D05D9AB208A119CEF09E1B53BBE9616A1A85BA4506474F71178FA", "hash_sha512": "F4B20884AEEA2540D8414ABC9DEDA859E8938CDF04A743AB6F151139DEA08BDA4B0EB9208500CD0402A7D1E9046A916405DCBDD9766FA6987C415B0CED387703", "hash_ssdeep": "384:NazzUt9HUx0M51Il9FM3Ey/7mJEclNhTfnz53Ful0fNpIiaQ/W1+SW:Ng89H726M3J6Jbdt1mcNpxa5+", "hash_imp": "7381EF144DB2B1CFEA7EEF9BB9B7A530", "hash_pesha1": "61A1CE3D95FC2C796EBEAB6AE5C7BD0B0FFDE12D", "hash_pe256": "811BEB487FC91CA6FB0156A7B967CE04B4B503857AAABEBBADAFFB4C5F50BE4C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Shutdown and Annotation Tool", "meta_original_filename": "SHUTDOWN.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d4e68cc9cb1965d70134c68bd1a090e0afae5b8b3d8018c6b6564852ae7bf396/detection", "output": "Usage: C:\\Windows\\system32\\shutdown.exe [/i | /l | /s | /sg | /r | /g | /a | /p | /h | /e | /o] [/hybrid] [/soft] [/fw] [/f]\n [/m \\\\computer][/t xxx][/d [p|u:]xx:yy [/c \"comment\"]]\n\n No args Display help. This is the same as typing /?.\n /? Display help. This is the same as not typing any options.\n /i Display the graphical user interface (GUI).\n This must be the first option.\n /l Log off. This cannot be used with /m or /d options.\n /s Shutdown the computer.\n /sg Shutdown the computer. On the next boot, if Automatic Restart Sign-On\n is enabled, automatically sign in and lock last interactive user.\n After sign in, restart any registered applications.\n /r Full shutdown and restart the computer.\n /g Full shutdown and restart the computer. After the system is rebooted,\n if Automatic Restart Sign-On is enabled, automatically sign in and\n lock last interactive user.\n After sign in, restart any registered applications.\n /a Abort a system shutdown.\n This can only be used during the time-out period.\n Combine with /fw to clear any pending boots to firmware.\n /p Turn off the local computer with no time-out or warning.\n Can be used with /d and /f options.\n /h Hibernate the local computer.\n Can be used with the /f option.\n /hybrid Performs a shutdown of the computer and prepares it for fast startup.\n Must be used with /s option.\n /fw Combine with a shutdown option to cause the next boot to go to the\n firmware user interface.\n /e Document the reason for an unexpected shutdown of a computer.\n /o Go to the advanced boot options menu and restart the computer.\n Must be used with /r option.\n /m \\\\computer Specify the target computer.\n /t xxx Set the time-out period before shutdown to xxx seconds.\n The valid range is 0-315360000 (10 years), with a default of 30.\n If the timeout period is greater than 0, the /f parameter is\n implied.\n /c \"comment\" Comment on the reason for the restart or shutdown.\n Maximum of 512 characters allowed.\n /f Force running applications to close without forewarning users.\n The /f parameter is implied when a value greater than 0 is\n specified for the /t parameter.\n /d [p|u:]xx:yy Provide the reason for the restart or shutdown.\n p indicates that the restart or shutdown is planned.\n u indicates that the reason is user defined.\n If neither p nor u is specified the restart or shutdown is\n unplanned.\n xx is the major reason number (positive integer less than 256).\n yy is the minor reason number (positive integer less than 65536).\n\nReasons on this computer:\n(E = Expected U = Unexpected P = planned, C = customer defined)\nType\tMajor\tMinor\tTitle\n\n U \t0\t0\tOther (Unplanned)\nE \t0\t0\tOther (Unplanned)\nE P \t0\t0\tOther (Planned)\n U \t0\t5\tOther Failure: System Unresponsive\nE \t1\t1\tHardware: Maintenance (Unplanned)\nE P \t1\t1\tHardware: Maintenance (Planned)\nE \t1\t2\tHardware: Installation (Unplanned)\nE P \t1\t2\tHardware: Installation (Planned)\nE \t2\t2\tOperating System: Recovery (Unplanned)\nE P \t2\t2\tOperating System: Recovery (Planned)\n P \t2\t3\tOperating System: Upgrade (Planned)\nE \t2\t4\tOperating System: Reconfiguration (Unplanned)\nE P \t2\t4\tOperating System: Reconfiguration (Planned)\n P \t2\t16\tOperating System: Service pack (Planned)\n \t2\t17\tOperating System: Hot fix (Unplanned)\n P \t2\t17\tOperating System: Hot fix (Planned)\n \t2\t18\tOperating System: Security fix (Unplanned)\n P \t2\t18\tOperating System: Security fix (Planned)\nE \t4\t1\tApplication: Maintenance (Unplanned)\nE P \t4\t1\tApplication: Maintenance (Planned)\nE P \t4\t2\tApplication: Installation (Planned)\nE \t4\t5\tApplication: Unresponsive\nE \t4\t6\tApplication: Unstable\n U \t5\t15\tSystem Failure: Stop error\n U \t5\t19\tSecurity issue (Unplanned)\nE \t5\t19\tSecurity issue (Unplanned)\nE P \t5\t19\tSecurity issue (Planned)\nE \t5\t20\tLoss of network connectivity (Unplanned)\n U \t6\t11\tPower Failure: Cord Unplugged\n U \t6\t12\tPower Failure: Environment\n P \t7\t0\tLegacy API shutdown\n", "error": "Hibernation is not enabled on this system. You must enable hibernation in order to use the -h option.(126)\n", "runtime_modules": [ "C:\\Windows\\system32\\shutdown.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "sigverif.exe-2151A535274B53BA8A728E542CBC07A8": { "file_name": "sigverif.exe", "file_path": "C:\\Windows\\system32\\sigverif.exe", "hash_md5": "2151A535274B53BA8A728E542CBC07A8", "hash_sha1": "A2304C0F2616A7D12298540DCE459DD9CCF07443", "hash_sha256": "064DE47877B00DC35886E829A697E4ADB3D3CFDF294DDBA13B6009A0F415B1BD", "hash_sha384": "B6581EE87CDA8E69E23B9466E643E460763AADBA85F66C339B335D656954887328675607E830E203DB27797D106F3B91", "hash_sha512": "E6FD520EE1BD80A5FE8A7C2AE6446DCAABD4E335A602C36356F85305ABEF751B7DFFA7EAAC1EC13C105CCD8C3E9070BD32ED4B14BC8A9E52DC5F47B936D69A9F", "hash_ssdeep": "1536:qDt2ukIUSAzqwNPXkHE8QECOQvPXFz8rNntxzAZT3WuEs:qDt2ukzSAzqwNMHQx8rNnkB7", "hash_imp": "AA4B4E6BDB1A12EF8952DD7EDDDE3EED", "hash_pesha1": "976436FEA858EF1948728D66B21DB67FA17B0EB4", "hash_pe256": "F63E58DCF7A27435B3A6A0EF87292665C3BB9EF16506ED8A1D8B0CE472ACABB6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Signature Verification", "meta_original_filename": "sigverif.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/064de47877b00dc35886e829a697e4adb3d3cfdf294ddba13b6009a0f415b1bd/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\sigverif.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\sigverif.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHELL32.dll" ], "runtime_window_title": "File Signature Verification" }, "SIHClient.exe-F2CC4F2F8B22C6540E557892A2E3A562": { "file_name": "SIHClient.exe", "file_path": "C:\\Windows\\system32\\SIHClient.exe", "hash_md5": "F2CC4F2F8B22C6540E557892A2E3A562", "hash_sha1": "4EDB06BC51EE0EA2050C6087FC8FA164D3C8A63A", "hash_sha256": "A167B3DE2DF58AB035602223DAF33FC807F01FBE901EDC7BD1913B43D5172541", "hash_sha384": "42565CA51F7BF19903565E2BA204BD702A17AD8587A2E0ABE0ADA6F01D3AC93BE63ECB407022F037ADE414B7471194B4", "hash_sha512": "3AD341046431B9439668E6A66C4E8ADDC895E05755D2F082BA2B6E1D958B7EBD9E8ED620ABF4AB4AFFD92753A7210930F53F0601DF446CAA4EBE84DA4B45886D", "hash_ssdeep": "6144:KOCUtmYAGr1TgnkQ+4Vx2f8hOAvj3aWzl49IT90edT+ZQb6fnA6RFFMTi5Ci:VCUvKECNvbaOUaZ+rA6fyTACi", "hash_imp": "69863607D629D2AA5AB89B0D5A4AD9A1", "hash_pesha1": "22E296E8E73CD2FAA2652CF33A9DC6C74C09092C", "hash_pe256": "5D83F8C576143DC88F93D9A896130BF20389F471A6AA0FF80AAE079D36E82E8F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SIH Client", "meta_original_filename": "sihclient.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a167b3de2df58ab035602223daf33fc807f01fbe901edc7bd1913b43d5172541/detection" }, "sihost.exe-B19D63CBAF662531A3B9071372B86595": { "file_name": "sihost.exe", "file_path": "C:\\Windows\\system32\\sihost.exe", "hash_md5": "B19D63CBAF662531A3B9071372B86595", "hash_sha1": "1D1AEDCFB4F5B05490084609B54908901B35BF54", "hash_sha256": "C2194F45C7B614B4520ED551C88C2B32D2E0065EDCF3D7208086A1B0EC07D835", "hash_sha384": "ECC0DA5C9DD4277348214DFFD82ED1E73012B23DD0C92949B70BEEC773856DF5B304736ABA6B277C1D6E22A3542303F2", "hash_sha512": "F89366599D002AA16E59D76B05D43A7E2F15B5D358BD2DC417A2366BEA7554B8C51DA4F5F6001711C374DDB843AB15E9D6D0F02215149E6FA7774141D5BBEE08", "hash_ssdeep": "1536:teWBpMaPLTsVD5HRQdmM0YgNJfgJSSo1CTECC2s7SUyb76AgztlNm:tzBuaHsl5xm30fxTkECC2s7/yX6dlNm", "hash_imp": "9FFE8029F721BD904F419F82A63D59A2", "hash_pesha1": "748D08F31BDB2EADCCD7C3472C45E87414BD492C", "hash_pe256": "6E98752C2566F049601210956055EC12F905EF9CF25A0B201C936DE49E069595", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Shell Infrastructure Host", "meta_original_filename": "sihost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c2194f45c7b614b4520ed551c88c2b32d2e0065edcf3d7208086a1b0ec07d835/detection", "children": "explorer.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\sihost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "SlideToShutDown.exe-FD18CDC89BFD664E85644B460C37D85B": { "file_name": "SlideToShutDown.exe", "file_path": "C:\\Windows\\system32\\SlideToShutDown.exe", "hash_md5": "FD18CDC89BFD664E85644B460C37D85B", "hash_sha1": "C242494ECE2ED744D412FDF77980EE2E18952350", "hash_sha256": "C167F7C83952A95633AD4B65D419D162F85066DEA159CB011E771C7C1E07476F", "hash_sha384": "32175DA33C16BEF10CDE89C364539BB39DBCF23314A7488916D38C69FD56F348F514E29200C73DD9B14E7EF16419FBE0", "hash_sha512": "AEC2D69AF3938AE46551CCBEFC5C72252ADDC49DE1F56D9ECCE505B886BE6478478603BA2E5905DA74FE311D9EFB4DA4EC67B4AFC5EBBBC19898ADD293436BC5", "hash_ssdeep": "384:PIcZxe7HHZu9Ws9GczaAn8ZNjWWWRC6WzZD1IDBRJJssl9ntYT:PbXuu9Ws9Gcza08ZNlWRCXI1PPg", "hash_imp": "BB14032CDADDA2A586E94DCE4AF0AF58", "hash_pesha1": "35FBEB17AEA798A163845471A55417E0AE5A0ECA", "hash_pe256": "27D3CE5094B78CBB4E59510E2C23ACB826FA8DACB583BEAD2CAB5945ECC99BF6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SlideToShutDown", "meta_original_filename": "SlideToShutDown.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/c167f7c83952a95633ad4b65d419d162f85066dea159cb011e771c7c1e07476f/detection" }, "slui.exe-EB725EA35A13DC18EAC46AA81E7F2841": { "file_name": "slui.exe", "file_path": "C:\\Windows\\system32\\slui.exe", "hash_md5": "EB725EA35A13DC18EAC46AA81E7F2841", "hash_sha1": "C0B3304C970324952E18C4A51073E3BDEC73440B", "hash_sha256": "25E7624D469A592934AB8C509D12C153C2799E604C2A4B8A83650A7268577DFF", "hash_sha384": "A18EBA9D31210D73F844EA5BBDC716A212FF92212CF2AA58706BB4EF82CB2F6010FA5E7DCF4505292A479BB297DE5285", "hash_sha512": "39192A1FAD29654B3769F007298EFF049D0688A3CB51390833EC563F44F9931CD3F6F8693DB37B649B061B5AAB379B166C15DADE56D0FC414375243320375B26", "hash_ssdeep": "12288:h0RtNWU//5TEDbZUfBsphGkQhHBcyxlT2Lq3nyR:h07NWu/KUYGk4nXT2m3", "hash_imp": "F2014F5555EEFEC494A169DEEBA0FEE5", "hash_pesha1": "E8A2AD11590A0FCC44EDBE44930C682DF430F6CE", "hash_pe256": "66B804B7E1992404FB4A0E071858207EBB5BB8A3E5B6964521BC245AC9D46873", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Activation Client", "meta_original_filename": "slui.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/25e7624d469a592934ab8c509d12c153c2799e604c2a4b8a83650a7268577dff/detection", "runtime_modules": [ "C:\\Windows\\system32\\slui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\system32\\WINBRAND.dll" ] }, "smartscreen.exe-3FC10273D5BBB7B06A76FD5E78D91469": { "file_name": "smartscreen.exe", "file_path": "C:\\Windows\\system32\\smartscreen.exe", "hash_md5": "3FC10273D5BBB7B06A76FD5E78D91469", "hash_sha1": "D500C5892411CC6DCDAB2EBBAA54FC40E3785B0B", "hash_sha256": "1E35BB9770AE8202BD6D2E5FDA6784A80F67DCF4B547B206A14D82CC17154842", "hash_sha384": "00AB59A1C15536A4583E89B92ABA0A922BA84484B923402AE997B8A9D80C7C5000C73B62CD306DC24374223518382B03", "hash_sha512": "F1B15C780442101F3DFDD19AE6B1A22A70BA5903BCFCC9297A6577A21E17E1DDFCB3D8B5B3D498776AD6ED75968CF16886E270CFD7EBF68F92C7301A10085835", "hash_ssdeep": "49152:GcYVj023jhdZVTL3bBPZziAnrRfOqI/TYhUEgPk/Cx/mNDS8r37Un:qdHvNlr37", "hash_imp": "6DFBF12753AF176E3C203C407493A5B9", "hash_pesha1": "6ABDEBC739E92D45F13C342703494724F516463B", "hash_pe256": "3B310D0ED16B4400FFCED1EA162162E9E0C5342A056C123B90E9D22A3A1B824E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Defender SmartScreen", "meta_original_filename": "smartscreen.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1e35bb9770ae8202bd6d2e5fda6784a80f67dcf4b547b206a14d82cc17154842/detection", "runtime_modules": [ "C:\\Windows\\system32\\smartscreen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "smss.exe-793C887D404F3EE2F9B490C21C38DD80": { "file_name": "smss.exe", "file_path": "C:\\Windows\\system32\\smss.exe", "hash_md5": "793C887D404F3EE2F9B490C21C38DD80", "hash_sha1": "C438640E94CDC3A0037D47B8228A6DA9EA293AF4", "hash_sha256": "E11AE324BA8C7AD66869BC34D16594F053C9447F0B11BF8D147DA259AD19DC92", "hash_sha384": "3F2E621E6A84F35B5B86B514FC1201FBC63CC0CA6D5863883CDF3D2549118FDF1E0E26E58D378F4A04CB34E3FB79FEE1", "hash_sha512": "ED78C1AA8A106E08F36C71CAB204AF7535371499961FC998459DEDFD75DE318229A9494DFF77A8DE6F3657345ACE39D0EBE7CCF9C3A0FEFCEF61C88F0D5DFF18", "hash_ssdeep": "3072:yQePhGRSAkjk9DswG11GIYH23Nh5+cLy4LBNG:yzijkjk9Ir1Gv23Nd+", "hash_imp": "9514316F92E1910DDBCE2EA3735D33A5", "hash_pesha1": "12907A129BD9309F39F866D90ED56B50E1D560F5", "hash_pe256": "6D57331D6A666AD555B009202277F69F3309C95EA8ECB7F6E3EF0F47436F834E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Session Manager", "meta_original_filename": "smss.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e11ae324ba8c7ad66869bc34d16594f053c9447f0b11bf8d147da259ad19dc92/detection" }, "SndVol.exe-9877E28BD78EFAAF4813C84D48CC56C4": { "file_name": "SndVol.exe", "file_path": "C:\\Windows\\system32\\SndVol.exe", "hash_md5": "9877E28BD78EFAAF4813C84D48CC56C4", "hash_sha1": "56F9639C87C4D9E08C92D115F4EF7955697FE77D", "hash_sha256": "5BE12686C75A1F034EAC11031A7440EA40731298DF5F7296B2C5462028793BF3", "hash_sha384": "3498A8467E84A6FA53064C97A79B09E2E5933416AF3DBDDDEF02D37DB1CEF84411BDC979C9289B4EF38423EE8CC2EE00", "hash_sha512": "B6E504BC4E8336D4FD8733594DEB8CE6165DB48E978DB1C1538AE23C5F17AA24DAAABE6F3DF2819BCE950618B59AE0115F6C37F7A9841D1FF38D471B56397AF8", "hash_ssdeep": "6144:M/k6mogoeAAVpq4jpExOd3n3u8Ggu0kr/2rzIBqncyXy10X:r6pTjA7q4jpEcX3upgvXyM", "hash_imp": "C9F852C96B7C3A52C280EB97D52DA386", "hash_pesha1": "520734A2AD986A81109CDA0CFE288BF73669F784", "hash_pe256": "2BE10F4FC1DC3E6202C0F765B848E2DD4AD3A9299AF8A419E52125B31D739E59", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Volume Mixer", "meta_original_filename": "SndVol.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5be12686c75a1f034eac11031a7440ea40731298df5f7296b2c5462028793bf3/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\System32\\en-US\\sndvol.exe.mui": "File", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Windows\\Theme601709542": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\wdmaud.drv.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SndVol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll" ], "runtime_window_title": "Volume Mixer - Remote Audio" }, "SnippingTool.exe-0D42E0492585153117F6ECF250EC8993": { "file_name": "SnippingTool.exe", "file_path": "C:\\Windows\\system32\\SnippingTool.exe", "hash_md5": "0D42E0492585153117F6ECF250EC8993", "hash_sha1": "DB90A82E8131B24432E8C19C1D9689B12D2FA25E", "hash_sha256": "6B7B9973B5C5099626A97CC45B70BA6456EF6615692CDE1149FBD06022AA4856", "hash_sha384": "58F3B3EAA3C641AF442C4FEBA60BBEE298F008932B890E7B7BAEC51CBD189A2C4E576020F7BF45B3A84DDF2B452C26CE", "hash_sha512": "06115F1F73BE64DBF8AEA1AF1EA0716A68584C3C5A02168E37EC960D4520482552D8FB41D57709849FFD11E67DB16CEA7B093DF715EFB30A919AE6849183A424", "hash_ssdeep": "98304:mRTlxL4TsqaA2SRmXUrymuXB2rmaOOaCa2PKCZZNRwtPV3Oy:eTvDqaA2SRmXUrymuXB2rmaOOaCa2PKL", "hash_imp": "1E5B697DA460222A16D80AC56256B657", "hash_pesha1": "EB7A4E986B579BDAE9D2C278BE28C574BCFB53A3", "hash_pe256": "23E94A47139EC19171590F6E0424340C8251109D1D9782E4F44308D8DBD9D7B9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Snipping Tool", "meta_original_filename": "SnippingTool.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/6b7b9973b5c5099626a97cc45b70ba6456ef6615692cde1149fbd06022aa4856/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\SnippingTool.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RWD) C:\\Windows\\Fonts\\seguisym.ttf": "File", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SnippingTool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538\\gdiplus.dll" ], "runtime_window_title": "Snipping Tool" }, "snmptrap.exe-1971BBC71602B928CF9257759E3C05E8": { "file_name": "snmptrap.exe", "file_path": "C:\\Windows\\system32\\snmptrap.exe", "hash_md5": "1971BBC71602B928CF9257759E3C05E8", "hash_sha1": "C4A9C0CC61B0C74043F0C9617EE100A5EE76BAE5", "hash_sha256": "9D665698FF26ED333AD385B4B7A6C0F2B6806371D278E281FA4188002A5317E8", "hash_sha384": "12D4D4E3B93213B69ED2EE8A9A48CD81EAAAF443069CED799E75BBC75E549048B4AE0B9ACBE571C04A9998F554869FE8", "hash_sha512": "9766EEB67BABAD99C45EE6C1E18ED74600C284E6B50DA84D77B485FEFEF1A64595E4D0A74492DE06C75DD14D9EE51C2E2ABD62C41E0D1C9126E364F125570029", "hash_ssdeep": "384:t6asNn8aCT/+jUF2d/zrSsOj5/gfnR8WSWlyW:8asNn8aCT/72dx6FgfRpx", "hash_imp": "C2C94366EB9868AA74167BBE2B51AA0A", "hash_pesha1": "B7498B635AF76F6B018FCCC155345B6D2E35E27B", "hash_pe256": "4FD3CBB7CF34C1ED5821299400DDCB77278C784B8302F90B060B15B745BD9FBF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SNMP Trap", "meta_original_filename": "snmptrap.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/9d665698ff26ed333ad385b4b7a6c0f2b6806371d278e281fa4188002a5317e8/detection", "runtime_modules": [ "C:\\Windows\\system32\\snmptrap.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "sort.exe-28079B69DC7EF8D6DCECD0A6A0750BBA": { "file_name": "sort.exe", "file_path": "C:\\Windows\\system32\\sort.exe", "hash_md5": "28079B69DC7EF8D6DCECD0A6A0750BBA", "hash_sha1": "602A982E7B574870E853C9EA5F7F83C0E76A2BF5", "hash_sha256": "C9D8C048BEEC3AA7D0494A36E77D5692391DFF26BD32B07A3358C010D8C84C79", "hash_sha384": "E278E94ED8A1513774A16BBD0FEDB697BFF1DDCA3EE68FD7583FDB14BCEE0169161991C0556A4AFEBE6AF80FD3BA3007", "hash_sha512": "3343B18197F8D9245466C5260D332E80C5167403E9DE5411B9D926AC01D24892AD1BE26E28A2C28D7E0E37898A6178E9837DD131535D04BAC1A87F96C98E6330", "hash_ssdeep": "768:rc0yzw7kniZU5zTUKGcv9gb+KVahzfN8AWYsp/SNKxxYFE3:Hyzw7kniZU5/nzKGzfCSixv3", "hash_imp": "96BC073D8286B37DFA22A171D067DA0F", "hash_pesha1": "2ADC26AB1B16037F66E658767D41B7E8EF0B262A", "hash_pe256": "8A98C953B36692F4DF17A288D630E9049C75F09D44AE41697DB5092A482488D0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Sort Utility", "meta_original_filename": "Sort.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/c9d8c048beec3aa7d0494a36e77d5692391dff26bd32b07a3358c010d8c84c79/detection", "output": "SORT [/R] [/+n] [/M kilobytes] [/L locale] [/REC recordbytes]\r\r\n [[drive1:][path1]filename1] [/T [drive2:][path2]]\r\r\n [/O [drive3:][path3]filename3]\r\r\n /+n Specifies the character number, n, to\r\r\n begin each comparison. /+3 indicates that\r\r\n each comparison should begin at the 3rd\r\r\n character in each line. Lines with fewer\r\r\n than n characters collate before other lines.\r\r\n By default comparisons start at the first\r\r\n character in each line.\r\r\n /L[OCALE] locale Overrides the system default locale with\r\r\n the specified one. The \"\"C\"\" locale yields\r\r\n the fastest collating sequence and is\r\r\n currently the only alternative. The sort\r\r\n is always case insensitive.\r\r\n /M[EMORY] kilobytes Specifies amount of main memory to use for\r\r\n the sort, in kilobytes. The memory size is\r\r\n always constrained to be a minimum of 160\r\r\n kilobytes. If the memory size is specified\r\r\n the exact amount will be used for the sort,\r\r\n regardless of how much main memory is\r\r\n available.\r\r\n\r\r\n The best performance is usually achieved by\r\r\n not specifying a memory size. By default the\r\r\n sort will be done with one pass (no temporary\r\r\n file) if it fits in the default maximum\r\r\n memory size, otherwise the sort will be done\r\r\n in two passes (with the partially sorted data\r\r\n being stored in a temporary file) such that\r\r\n the amounts of memory used for both the sort\r\r\n and merge passes are equal. The default\r\r\n maximum memory size is 90% of available main\r\r\n memory if both the input and output are\r\r\n files, and 45% of main memory otherwise.\r\r\n /REC[ORD_MAXIMUM] characters Specifies the maximum number of characters\r\r\n in a record (default 4096, maximum 65535).\r\r\n /R[EVERSE] Reverses the sort order; that is,\r\r\n sorts Z to A, then 9 to 0.\r\r\n [drive1:][path1]filename1 Specifies the file to be sorted. If not\r\r\n specified, the standard input is sorted.\r\r\n Specifying the input file is faster than\r\r\n redirecting the same file as standard input.\r\r\n /T[EMPORARY]\r\r\n [drive2:][path2] Specifies the path of the directory to hold\r\r\n the sort's working storage, in case the data\r\r\n does not fit in main memory. The default is\r\r\n to use the system temporary directory.\r\r\n /O[UTPUT]\r\r\n [drive3:][path3]filename3 Specifies the file where the sorted input is\r\r\n to be stored. If not specified, the data is\r\r\n written to the standard output. Specifying\r\r\n the output file is faster than redirecting\r\r\n standard output to the same file.\r\r\n\r\n", "error": "--helpThe system cannot find the file specified.\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\sort.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "SpaceAgent.exe-2542D5C20AC5E8CEB42113529AD0BFDA": { "file_name": "SpaceAgent.exe", "file_path": "C:\\Windows\\system32\\SpaceAgent.exe", "hash_md5": "2542D5C20AC5E8CEB42113529AD0BFDA", "hash_sha1": "31FE2B9A6CE57E855F8CBAF4E3B6F69CBDC9F2C6", "hash_sha256": "0793CD515F80FB8025924418C7E289047BBC15019ACEA868914EA0015FCB6ADA", "hash_sha384": "14E59349D944BB44476CA1D33CF5B3978D668A20AA195E1231C60AF205322496FDEF57CE4921383FA6D452E845039F5F", "hash_sha512": "B18267924772E553E7433A400DE7292F0020C0ED3530198413BB593CACEB5AB3460E08AA70FE456A4DE6720A2B3C2BE7B4748805BBF22382A3B269D1906D584B", "hash_ssdeep": "3072:qo6In9JEX3tC6JdCUsvdvGgFMoejViwurx/ELOU+iGhZBu4+Pb:6In9JEX3tC6JdCUgV4iwex/ELOUPGYF", "hash_imp": "8E2D8565E9944263A362F96D2D8287AB", "hash_pesha1": "78E544271E802C5F973EDD522DBEBA50E3A5CD3D", "hash_pe256": "5A9498A24B702859DDF8B1B8DBB6314F9A4BE7F383312FA3033E7465B3977737", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Storage Spaces Settings", "meta_original_filename": "SpaceAgent.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0793cd515f80fb8025924418c7e289047bbc15019acea868914ea0015fcb6ada/detection", "runtime_modules": [ "C:\\Windows\\system32\\SpaceAgent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll" ] }, "spaceman.exe-BBB29C1B182668D6393D401DCA726BAE": { "file_name": "spaceman.exe", "file_path": "C:\\Windows\\system32\\spaceman.exe", "hash_md5": "BBB29C1B182668D6393D401DCA726BAE", "hash_sha1": "F371029C2391BA02BEA20FCDA0FCB8BB31FD833A", "hash_sha256": "D7C6897B47AC880611B48490C4E74F79A9C52AE9E4E596FED1064A2F97434C0D", "hash_sha384": "03D2BB0D67C6B6EA99217C0EFF1C147BDF5FE1DF69BF8080BE39FF026489E6223ACD7AB68AFBC928AA1CAE4029002855", "hash_sha512": "B3C5E425C800A7D03A609A70299C87DE1E86B9E3EA5119742C5C1823BCE0D7AB4F7CBF6F98909F7EE95989CEACA2FF610D5324EFB9B78ABE92F2387D01AC82F2", "hash_ssdeep": "1536:jZMHPR186z5lBaTcFFpVw3Nt1VTGxq1LpSYCyejoKkY7HMQn8WYD1EsND3PbxYmD:jmPR1mcP3wzKq1LHCyuDsQn8tq4D3P9J", "hash_imp": "0051ED26FAD4A5455AAD4AE48969C316", "hash_pesha1": "C6F1A0B03DBA2352A3A88487FBA59EC9F1531A32", "hash_pe256": "59622E25632D91B765ABE06C553B7C1F9E8FDB62CAA5AEAC4D45FE4393B76D3B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Storage Spaces Manager", "meta_original_filename": "spaceman.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d7c6897b47ac880611b48490c4e74f79a9c52ae9e4e596fed1064a2f97434c0d/detection", "runtime_modules": "C:\\Windows\\system32\\spaceman.exe" }, "SpatialAudioLicenseSrv.exe-FB07974EEE916C9729B6AD675565D135": { "file_name": "SpatialAudioLicenseSrv.exe", "file_path": "C:\\Windows\\system32\\SpatialAudioLicenseSrv.exe", "hash_md5": "FB07974EEE916C9729B6AD675565D135", "hash_sha1": "C3FC5395B7D24C7FD3ED3BD7FFF5CE2DF8F188FD", "hash_sha256": "1A82CB48027A92E0463CCFD7A47AB01CEAC5338A13C1CC74FA6CA718EE42C3F8", "hash_sha384": "72CDDDD3932A849586DCE3B45E19C493BEF82434117F8E3A1A9D8DA6F25880787F8B4837D642B7ECE96DFCA6E9605B36", "hash_sha512": "9F6E5483E5C6443F45DE7AA1E188F46178415D1AB3AA7CA9482415A198696A94BA0FD3C923453F107842F9B983625860BC84F53876099115706C6FA142543941", "hash_ssdeep": "3072:ylyFjABNr9Rrx7hoxPXIC7IckrB/N8Cozx5wWA2savkHJgddWBRvNqV8rxcx:RAp+XIC7FCozxuW5gGGc", "hash_imp": "ABB101FE9A06CD5E31B234938EA2320D", "hash_pesha1": "629A1ACE5186C7C588F06FA44D58A1D2DE485728", "hash_pe256": "E79D9E01BF1AA31B5DC7F8E4243781EEF30DC1759530314426869B1E80F31383", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Spatial License AppService Broker", "meta_original_filename": "SpatialLicenseSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1a82cb48027a92e0463ccfd7a47ab01ceac5338a13c1cc74fa6ca718ee42c3f8/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SpatialAudioLicenseSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "Spectrum.exe-B98C95BFDF2404A12D77AFBA3C8C1A59": { "file_name": "Spectrum.exe", "file_path": "C:\\Windows\\system32\\Spectrum.exe", "hash_md5": "B98C95BFDF2404A12D77AFBA3C8C1A59", "hash_sha1": "267A457FABFE3493B9F93E99A410067BCC0728AA", "hash_sha256": "D79729B2A955AE829D58A9F78EB0610F2E2014F52625A1E214D444FD45EE90DE", "hash_sha384": "9CEE6B33F018FDE4FE2FF2905EBAF652990AD349388E99BC5E49F7A7D1F4DB0A3D45DF63F672894682040635DFF8FB1D", "hash_sha512": "D64B4543B1CA7309C96AE594775D295653C3BA13A0178B882F04F8A77408ADB49538AEF7E2339975195560BEC16E94C995AA65BBE53C4EC29E378C752A34074A", "hash_ssdeep": "6144:nuGk5kSnyukXc+Po+S3VREHZK+WaeWTlaz9dOKhd7MezMvlAhgD8uAra12pr83sA:uGk5kXXcZzt00hM2ggZraMjt7+5M4", "hash_imp": "2D430AF2F5D536907F1205720822457A", "hash_pesha1": "FF90D8C0574F6982B9268D42CC057DD6C069C824", "hash_pe256": "DD69C8710386F562E786C1752D7490487A69D0F4DB1662A228431DD4FED624CF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Perception Service", "meta_original_filename": "Spectrum.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d79729b2a955ae829d58a9f78eb0610f2e2014f52625a1e214d444fd45ee90de/detection", "output": "Unrecognized parameter: --help\r\nParameters:\r\n /debug to run the service executable in debug mode\r\n /safemode to set up the service to run in safe mode\r\n /safemode:off to disable safe mode if enabled\r\n", "runtime_modules": [ "C:\\Windows\\system32\\Spectrum.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "spoolsv.exe-2709938B30A5689918CA7BA7F0F70F6D": { "file_name": "spoolsv.exe", "file_path": "C:\\Windows\\system32\\spoolsv.exe", "hash_md5": "2709938B30A5689918CA7BA7F0F70F6D", "hash_sha1": "325B9C218A88DFB0E8A5CFD66E0C6C901B2D0D98", "hash_sha256": "4CCD2F52F39CC72787BB4CAC73BEFC5D27E2E77B14E70B04CF604159D19313B4", "hash_sha384": "84750483306591D702A5B890CC1A0DC2F8165899D0F9DDEDE7FD981127157E0BA9848C32F3EE5973DCBCAFA62D880DC8", "hash_sha512": "88A29318D6E57F2ED3C7E51A0F622D536A7AA0108C86B84740DBE1FA5E96CB6BE47F80A9226817BC71E2C397F8E7EAC3381AF7C86180677F5C2683112FB50C31", "hash_ssdeep": "24576:5syPDeBJLDzWBYnuesJLK27QDndkYQQZmPRmtFDJGu4K:5s2DSJLDzWBYnuesJLK27QDndkYQQZm0", "hash_imp": "6D527F52CF7772DC1BF45147E1BD0544", "hash_pesha1": "47524655B7904625387BD0557A002CF0ECBA955F", "hash_pe256": "8FDCA2BF9ABD94FB9814A31D586B4DB9A90E7B3022AD5DC7D6544769E158C61D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Spooler SubSystem App", "meta_original_filename": "spoolsv.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4ccd2f52f39cc72787bb4cac73befc5d27e2e77b14e70b04cf604159d19313b4/detection", "runtime_modules": [ "C:\\Windows\\system32\\spoolsv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\DNSAPI.dll" ] }, "SppExtComObj.Exe-21F0EE78CC0D250CEE3DF6F8A0A171FB": { "file_name": "SppExtComObj.Exe", "file_path": "C:\\Windows\\system32\\SppExtComObj.Exe", "hash_md5": "21F0EE78CC0D250CEE3DF6F8A0A171FB", "hash_sha1": "211D8A06B6073FC7404A3D94F1705E54F34C458F", "hash_sha256": "E6AC49BDDBE734097F86E55D1250A29DE1196B0C7A260BC36DC171D33FFBED0D", "hash_sha384": "0D28DB80B6A14537460FDAF94EDBEF8980C13A7369A28455FF1CB57BB3B148F958E129CB72E19B27B3108BE5620E393A", "hash_sha512": "2D250ACB34CFA7569F25F732141DA991F981E83D09CA576902C9E3F5004562F623B3B0B92F64701D46C1400D2DE712A8EED3621080B58F98EC26CF23BE286F6C", "hash_ssdeep": "12288:KDoiXz1aUu47gFeOHgskuzvABNK7PCxIZLx59kIQbw8Ffm:Kp5aU/EFPPxzv2N4PCxZ", "hash_imp": "4C96B0E079D994B8689C66F7872425EB", "hash_pesha1": "25DB9DDF3A3FF3739A7ECDA66540C6A86D80D63F", "hash_pe256": "BFD72E053BDAD625C5473BDBE8B53B6A7F1018AB90601C8C733144649D9F0019", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "KMS Connection Broker", "meta_original_filename": "SppExtComObj.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.685 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.685", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e6ac49bddbe734097f86e55d1250a29de1196b0c7a260bc36dc171d33ffbed0d/detection", "runtime_modules": [ "C:\\Windows\\system32\\SppExtComObj.Exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "sppsvc.exe-BE2DA701099AA7A3DF6FBC9F82B398BF": { "file_name": "sppsvc.exe", "file_path": "C:\\Windows\\system32\\sppsvc.exe", "hash_md5": "BE2DA701099AA7A3DF6FBC9F82B398BF", "hash_sha1": "197A90BB02B1766848CE70FEF3AA7C7F2970A0DB", "hash_sha256": "925F864865AE0F552356DA34008E77B231DA3E525314FFBDBC62E8955CA091EA", "hash_sha384": "D933327C5410C36AA31FAB1757DD7ACF9DAA135CA220C93A7C679C0C29C83893494A888C967DFE3EE42FF30B1F1B7AEE", "hash_sha512": "C056777EB1503881B98A015DFC4803C06D7340CAC089A19DCC4878975B3DF13664AF8E2DD07487A3955D2A5CABA420D2EC3A718A78BE3BA473A78C726132811F", "hash_ssdeep": "98304:wqZqizznD4vJIxGUiKXDwmaZn8qExjolSsDhwQF5:wqDzznD4ROiKXDwmk8qEulScn5", "hash_imp": "865C812E4E3E6E8C398A0757574C8DA3", "hash_pesha1": "AB6977696A47B5F8AC7C73F6D565E38A63B521F2", "hash_pe256": "2DA0957216FC6DFC9E2BCBF1E51030C1D7F085F4206810CCA364A2C31E0BEFBC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Software Protection Platform Service", "meta_original_filename": "sppsvc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/925f864865ae0f552356da34008e77b231da3e525314ffbdbc62e8955ca091ea/detection" }, "srdelayed.exe-B98EDE682551A52911E63EC9648A30CB": { "file_name": "srdelayed.exe", "file_path": "C:\\Windows\\system32\\srdelayed.exe", "hash_md5": "B98EDE682551A52911E63EC9648A30CB", "hash_sha1": "95058A12FF4B51AF54A51F29683D51AE49B2440A", "hash_sha256": "873232BC7DA9A9C6C572CF00E7C95B3D74B863403DE1784BD031BCA1EDED5106", "hash_sha384": "97345D06519FBA47EF82245FDD92A85CC50BD8E9392DEEAA17E0FB6A83F9483A272F7275B320128CD4298BE0DD47521B", "hash_sha512": "A1D9B82C6D8759FE5A52C968D4261329A721CF43F290531DBAC2B64A2DA6F15021B679440C0642463049E34E0484F79E88953F6686F2CBDCD7874FB1FF6B8220", "hash_ssdeep": "384:pD7nl0lEfdyYcJaxOlWWoq1o3qk6Xt8BLNEwW19oW:pV0mfgaxOlWWX66XK25", "hash_imp": "D8EAE8BD2F02F588285BA4821936CD9D", "hash_pesha1": "5F131C1578901F9AF8E9B0B3C60F5133CD16E285", "hash_pe256": "B740A830A9A4F7E53ABAE9CE943A6A757239ACD0BD31B31D482ACEA551D4577C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows System Restore Delayed File Renamer", "meta_original_filename": "srdelayed.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/873232bc7da9a9c6c572cf00e7c95b3d74b863403de1784bd031bca1eded5106/detection" }, "SrTasks.exe-2694D2D28C368B921686FE567BD319EB": { "file_name": "SrTasks.exe", "file_path": "C:\\Windows\\system32\\SrTasks.exe", "hash_md5": "2694D2D28C368B921686FE567BD319EB", "hash_sha1": "ABE2F09702C05FFE19ACCD3F149C0FB1031AEA2A", "hash_sha256": "40E27A9039A2E4A731EA6A74291840FB13C679A1E8AE5B523016AA15727D8A58", "hash_sha384": "B3C982EE3809FD3E42707EC4455B46DF1DC51B1C6DB0BE3BB8FCCC670E3731F3E79269B061A580948E2E5E58509153BF", "hash_sha512": "BBFE17DEFAAEED42FFE12758462550ECD4FD0F31EA1E4B9ED0CB542C3342C5961FA35B54850EC90E277EF93EF1C9271B4121972C0F704AE27FCEB1B890EABA4C", "hash_ssdeep": "768:1Vcks2RjKYdOXvodptBQt9EXAKYuaXwdU27P7NEGsKCM8BcL+rarwpqt6xX/l+SB:nMvodptBQvoAKYuaOSBJracIto+ouUr", "hash_imp": "DA5162FC74286D3065F624C6773BD09D", "hash_pesha1": "094EBF96BA4A038F07B31015181D785D9CDB161F", "hash_pe256": "3DA2F0AD0B03F5D226AEBAF2D82A55D14BD6F05B99FEB357E291F6A502E85C02", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows System Protection background tasks.", "meta_original_filename": "srtasks.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/40e27a9039a2e4a731ea6a74291840fb13c679a1e8ae5b523016aa15727d8a58/detection", "runtime_modules": [ "C:\\Windows\\system32\\SrTasks.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "stordiag.exe-0A486DBEBEEE0BEC3D3E2F20978F53F8": { "file_name": "stordiag.exe", "file_path": "C:\\Windows\\system32\\stordiag.exe", "hash_md5": "0A486DBEBEEE0BEC3D3E2F20978F53F8", "hash_sha1": "7BBC1977DE11EE9324C5A4C3ACF4724882B38279", "hash_sha256": "6A13DAC8BD42767DAD55D4C1ED4640F4E7F01ABB08CA05DDCDC2C348FCD6F8B3", "hash_sha384": "FFBD945C22C16E612BE83BA3EDB2ABB74E69491256F8C0F529AC92A5098F0A430E1B5D6E8108BE7240A732CD3C256CFB", "hash_sha512": "400ACADC345D946EF481C974856C9E3101B59D47E559790D0B161CDF05BC01E0498A45159392223240BF49EE0EA7D68189BDC24D929E7FC6532F24B496326E5B", "hash_ssdeep": "1536:hwYYQyn8M801RXnItvNCl/iB8KwZfbOZE4RS8JRFahdqb9BuN:6Y28M8068xfbOZE4I8JRFEYb9BuN", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "9F1243EDB08EC84BC245EF048FFE441CBEBEC1C1", "hash_pe256": "8D2BF9896D5B7051DB9AB0EA9EC13CA01FBA6700831B651A925785311270F9AB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "stordiag.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/6a13dac8bd42767dad55d4c1ed4640f4e7f01abb08ca05ddcdc2c348fcd6f8b3/detection", "output": "\r\nCollects storage and filesystem diagnostic logs and outputs them to a folder.\r\n\r\nStorDiag [-collectEtw] [-out <PATH>]\r\n-collectEtw Collect a 30-second long ETW trace if run from an elevated session\r\n-collectPerf Collect disk performance counters\r\n-collectStorageBreakdown Collect system volume used space breakdown\r\n-checkFSConsistency Checks for the consistency of the NTFS file system\r\n-diagnostic outputs a storage diagnostic report\r\n-bootdiag output boot sectors of the disk\r\n-driverdiag output avaliable storport and storahci logs\r\n-out <PATH> Specify the output path. If not specified, logs are saved to %TEMP%\\StorDiag\r\n\r\n\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_7832": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Management\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Management.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R--) C:\\Users\\user\\AppData\\Local\\Temp\\StorDiag\\PSLogs.txt": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Core\\v4.0_4.0.0.0__b77a5c561934e089\\System.Core.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.Commands.Diagnostics\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.Commands.Diagnostics.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Management.Automation\\v4.0_3.0.0.0__31bf3856ad364e35\\System.Management.Automation.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration.Install\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.Install.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.ConsoleHost\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.ConsoleHost.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.Commands.Utility\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.Commands.Utility.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.Commands.Management\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.Commands.Management.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.Management.Infrastructure\\v4.0_1.0.0.0__31bf3856ad364e35\\Microsoft.Management.Infrastructure.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.ServiceProcess\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.ServiceProcess.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.Security\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.Security.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.WSMan.Management\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.WSMan.Management.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.WSMan.Runtime\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.WSMan.Runtime.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\System.Data\\v4.0_4.0.0.0__b77a5c561934e089\\System.Data.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.DirectoryServices\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.DirectoryServices.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\stordiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "subst.exe-4399AA03FC3472709E9E1BB68F2A56E4": { "file_name": "subst.exe", "file_path": "C:\\Windows\\system32\\subst.exe", "hash_md5": "4399AA03FC3472709E9E1BB68F2A56E4", "hash_sha1": "2467CD11C3E8672B0509641CCDD4A32792B9B76A", "hash_sha256": "BF91A26C040417656E389188F291C9FCC8C7BEB4F1A00067D3D3623EF8F3C03C", "hash_sha384": "85C5C3FB1B0EE5D186D6E71976446B16187B62014060E01D6FDE7B98668BD8D1AAF8FE9AD9232932FEB3ED6F2CC9A9A5", "hash_sha512": "A761ACBFEB619236DA44C222D59834D531E4778764D03ADB0B46307891D9ACBF9D2514227B942A28E07DD82510C6D7111B0D328E3F298D58A0099805415547E0", "hash_ssdeep": "384:iDqh05jngc5eIJz3owju9M5lsDEJbZWzGW:BS5bgwe8LCmbQERa", "hash_imp": "657724BEF967C549A066ECF72A628438", "hash_pesha1": "22D95BB6A2205E74572BDAC8568A9E6EE366AF33", "hash_pe256": "A297A81A32129D94FCE4D5B50ADCBA870B631D2761C4A9DEA57041A0CDF52705", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Subst Utility", "meta_original_filename": "Subst.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/bf91a26c040417656e389188f291c9fcc8c7beb4f1a00067d3d3623ef8f3c03c/detection", "output": "Associates a path with a drive letter.\r\n\r\nSUBST [drive1: [drive2:]path]\r\nSUBST drive1: /D\r\n\r\n drive1: Specifies a virtual drive to which you want to assign a path.\r\n [drive2:]path Specifies a physical drive and path you want to assign to\r\n a virtual drive.\r\n /D Deletes a substituted (virtual) drive.\r\n\r\nType SUBST with no parameters to display a list of current virtual drives.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\subst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "svchost.exe-F586835082F632DC8D9404D83BC16316": { "file_name": "svchost.exe", "file_path": "C:\\Windows\\system32\\svchost.exe", "hash_md5": "F586835082F632DC8D9404D83BC16316", "hash_sha1": "010DB07461E45B41C886192DF6FD425BA8D42D82", "hash_sha256": "643EC58E82E0272C97C2A59F6020970D881AF19C0AD5029DB9C958C13B6558C7", "hash_sha384": "9BD6CE26EE0F8BC3083F57586C6C52B0AE195695EDC389358759BE81339E0BAA14F72006C1E74925331752E764E75CF2", "hash_sha512": "4A76272011AA2EF210DE6E54CCF2B3D8068DFCE8A741256562F2423048D94381D6F30AB47D88C37175FB3C7F6EFB08BBD8BD8501789CF4E5BB1DFF2455BE2425", "hash_ssdeep": "768:DPLnVeJ+4jnLejsSOQ3DOIKBL4DbNHeDA/YCN8HVvWc9w3Y1P6j3w:DDVeHnLejsT9k1HeGYbVWc9w3gP6jw", "hash_imp": "F9BBD96FAE53B7A31264A703CAFA0666", "hash_pesha1": "F70AEFD2967B93036C894F542E1AB47F122F5E7E", "hash_pe256": "409FDBA4D6704E4AC6D69EE8293E33103A53C40C89B4C95DF20993B41B5A6070", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Windows Services", "meta_original_filename": "svchost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/643ec58e82e0272c97c2a59f6020970d881af19c0ad5029db9c958c13b6558c7/detection", "children": "powershell.exe", "runtime_modules": [ "C:\\Windows\\system32\\svchost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "sxstrace.exe-5BB36C8D050826429ACF840163C1C0ED": { "file_name": "sxstrace.exe", "file_path": "C:\\Windows\\system32\\sxstrace.exe", "hash_md5": "5BB36C8D050826429ACF840163C1C0ED", "hash_sha1": "BE88EC2680991B502A193DE71E0709C6D0D344A2", "hash_sha256": "4C1283E3538BF2299B62D0C18440C242822775658BA0A9ADDDA2133CF2F16CB0", "hash_sha384": "10046C4C585DFED01A4454F6415EA649C106D633EB33C6832DEED0839C193E28AACAB81E05F2661457F71AD092F02E52", "hash_sha512": "4BDF7FF5054CE24E4782B51E9A8E2247D4D5E1C7A7A2BCBC0E925036F8FFF0FAE2D7BE79D5F13AAD7C826F1B9F2A40DCB3C731610E2B6710B2F293E11673B947", "hash_ssdeep": "768:+RhzpU+uAS9PWNBWLVx9n/Q42aXOfDd3EbBUfHICGrxHJ2D40J6+P:+R3W9PLPZEro2P9Gr/kJJ6+P", "hash_imp": "608C121F28B6837B15D6067BE234792E", "hash_pesha1": "1276F2E0DF259A8AD137BE252C9909739E95044E", "hash_pe256": "9ED3FC80DC36D6F41B1CDE0514C43548AA02FB796990EF9FCD1F37A9C710C535", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Sxs Tracing Tool", "meta_original_filename": "sxstrace.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4c1283e3538bf2299b62d0c18440c242822775658ba0a9addda2133cf2f16cb0/detection", "output": "WinSxs Tracing Utility.\r\nUsage: SxsTrace [Options]\r\nOptions:\r\n Trace -logfile:FileName [-nostop]\r\n Enabling tracing for sxs.\r\n Tracing log is saved to FileName.\r\n If -nostop is specified, will not prompt to stop tracing.\r\n Parse -logfile:FileName -outfile:ParsedFile [-filter:AppName]\r\n Translate the raw trace file into a human readable format and save the result to ParsedFile.\r\n Use -filter option to filter the output.\r\n Stoptrace\r\n Stop the trace if it is not stopped before.\r\nExample: SxsTrace Trace -logfile:SxsTrace.etl\r\n SxsTrace Parse -logfile:SxsTrace.etl -outfile:SxsTrace.txt\r\n", "runtime_modules": [ "C:\\Windows\\system32\\sxstrace.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "SyncAppvPublishingServer.exe-104C4F47F750B2C312EF9258C59A86E7": { "file_name": "SyncAppvPublishingServer.exe", "file_path": "C:\\Windows\\system32\\SyncAppvPublishingServer.exe", "hash_md5": "104C4F47F750B2C312EF9258C59A86E7", "hash_sha1": "5511CDC09B3E5AB22F6A73E75028135A5B2499DC", "hash_sha256": "C92228717E28C25E9F8B295BE7849CFCAFED9D76C945BDFB993E683F60AC3586", "hash_sha384": "34DB508B53210BC90CC88E42ED4C69EA0E4BE61089401FB884C127804D6A3C17BCBE9C34FD796D4B6DB5DA9A45BCAEA5", "hash_sha512": "5F5D84ACDB024529A1A6988A93946DD0B96A07E2333359E2ABA9B586C9C35E706825E234276D75417CD6F6A69EBFA9995661EBC64D0B6DEB33AEE8A36F7B6AC7", "hash_ssdeep": "768:W6Fyyphi89jr4jwmp3PwyDdwiBGeSWaZxZEApqiN8fr6wD1PzjR:W6V9jrN8P3DvGCa5Egny3PJ", "hash_imp": "1EC41853BAB928648731DDAB143F3159", "hash_pesha1": "73E58E409080B6FC243CCF28337FF886C0F83542", "hash_pe256": "2B265EE08FE1F5B0CD1F931253996E16A0DFB913D47E7E6D2B99D93C92B573A3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Application Virtualization Sync Utility", "meta_original_filename": "syncappvpublishingserver.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/c92228717e28c25e9f8b295be7849cfcafed9d76c945bdfb993e683f60ac3586/detection", "runtime_modules": [ "C:\\Windows\\system32\\SyncAppvPublishingServer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll" ] }, "SyncHost.exe-4368144247135D07E0A34E958B109751": { "file_name": "SyncHost.exe", "file_path": "C:\\Windows\\system32\\SyncHost.exe", "hash_md5": "4368144247135D07E0A34E958B109751", "hash_sha1": "9FA191B17F13DBB1D408C7E6BA9535DFC4813079", "hash_sha256": "F6F36D637D7F9C69CD7CFB953DB81D16AE5DD1B28EF2EAD799258EC3351CD4AB", "hash_sha384": "8C715170AB4E9262AF2D7168AA6AB00D0BBDF69F18A7E8A30AB84E2A73568386B87850B3D38F2A54BC4E5C9492069EBC", "hash_sha512": "78DF8F1AD6671F14F020C5C0CB27DAC8FA1619C41D7B67EA13E81EE8B0F591F5CABE97875FB4BAE8EB9D85E2D1C191BBD2DC2953EA75EDAB558FA10B6B403275", "hash_ssdeep": "768:vUj+YSrZ+ZVP+nT0rLG3n2K0tXho5cOGXqsPB00W4uJVFw6esGOR:vY5bVP+YLG3njKo5cOBsVW4uFw68", "hash_imp": "49B558CFF6EB0AA461D3A1C0FC9F8220", "hash_pesha1": "BBD60EB0C9A81D34AACBE5CC3B8C014AF23E2A9E", "hash_pe256": "E525BCBDFD1E9CEC212615D0EB5902630943946E0F7528A60BEF9C75D059D966", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Windows Sync", "meta_original_filename": "SyncHost.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f6f36d637d7f9c69cd7cfb953db81d16ae5dd1b28ef2ead799258ec3351cd4ab/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SyncHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "SysResetErr.exe-DA3578862503CF81B6BEED9ED90B8144": { "file_name": "SysResetErr.exe", "file_path": "C:\\Windows\\system32\\SysResetErr.exe", "hash_md5": "DA3578862503CF81B6BEED9ED90B8144", "hash_sha1": "92E3BDAFED9B46D3BCD866581D34F51B81584B29", "hash_sha256": "FC73996315BC9D306917E18A7065CE78E2BB31B5BFB5C164E31679E83E687381", "hash_sha384": "5EC6216F91B7221BD03D2BBA3E6521500F91EF88F05B4F13F72E55FC03B001CBEA8BC558CC2725A47FE8742D77A65CD3", "hash_sha512": "697F7124EF4442290143985700D8FB45F8E1820EBB1B8228C3E128B01840492D88F88883F4D02479381FBA2B26BF086D4D86475C398AFA3530C81592317B4512", "hash_ssdeep": "768:rYdRFkviZJJsE+lIGhruVSX+VuAQjzPVo8z/sr6wD1PaA:rYdRFbsEeFBuYautjzP2C/SPaA", "hash_imp": "94756B15804C0785AB207C72059C788E", "hash_pesha1": "FAE6DB4455EFB1876C2534CA850DCED4E8EEC449", "hash_pe256": "7533FCDBA470F769DDDA01119DCAFC9F73628E38ED05DA4A114A18BC704E03F5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows System Reset", "meta_original_filename": "SysResetErr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/fc73996315bc9d306917e18a7065ce78e2bb31b5bfb5c164e31679e83e687381/detection", "runtime_modules": [ "C:\\Windows\\system32\\SysResetErr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ole32.dll" ] }, "systeminfo.exe-EE309A9C61511E907D87B10EF226FDCD": { "file_name": "systeminfo.exe", "file_path": "C:\\Windows\\system32\\systeminfo.exe", "hash_md5": "EE309A9C61511E907D87B10EF226FDCD", "hash_sha1": "711D6F6394333AE55A06076DEB9189C04846F939", "hash_sha256": "6F87CAA51BDEA802045BB281FC2686A3C76364C26A3FFE6C2CCAC4AF5F9DB37B", "hash_sha384": "5995711121B421CA3D87A8B6D1AD5FA0D4A2EE5C991F0F929C3981D118351F56A39A0F7F8A4C02A349233B612E0F4346", "hash_sha512": "7FA1DB1EBDB7CC8A1ACF724FB910CECA1B8A433E51912B9291EAA153AF29FEC4B9AA60572CC06EF5E5EAF105277081BA5FD32B0F6D1DF8F3CC32FE9E8462C7B4", "hash_ssdeep": "3072:5qY7kUs93xU3RsyInRIQ4+cSvpcr9JLrDxS+Q+JPWIt2GvUxQ:5qY7T23xU3RJaIbdSvpcr9JLrDxS+Q+r", "hash_imp": "C7C3DF13F22D7A13802E6509367A5830", "hash_pesha1": "BA26D2CB277D4C8EB4CAFFE3F6305E04307945A4", "hash_pe256": "C6A316C2FE3A9148FB5DB3822150C11F10A0BC6D15E8AE5EF260D6873A1D8BAC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays system information", "meta_original_filename": "sysinfo.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6f87caa51bdea802045bb281fc2686a3c76364c26a3ffe6c2ccac4af5f9db37b/detection", "output": "\r\nSYSTEMINFO [/S system [/U username [/P [password]]]] [/FO format] [/NH]\r\n\r\nDescription:\r\n This tool displays operating system configuration information for\r\n a local or remote machine, including service pack levels.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /FO format Specifies the format in which the output\r\n is to be displayed.\r\n Valid values: \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" should\r\n not be displayed in the output.\r\n Valid only for \"TABLE\" and \"CSV\" formats.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n SYSTEMINFO\r\n SYSTEMINFO /?\r\n SYSTEMINFO /S system\r\n SYSTEMINFO /S system /U user\r\n SYSTEMINFO /S system /U domain\\user /P password /FO TABLE\r\n SYSTEMINFO /S system /FO LIST\r\n SYSTEMINFO /S system /FO CSV /NH\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"SYSTEMINFO /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\systeminfo.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "SystemPropertiesAdvanced.exe-FA040B18D2D2061AB38CF4E52E753854": { "file_name": "SystemPropertiesAdvanced.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesAdvanced.exe", "hash_md5": "FA040B18D2D2061AB38CF4E52E753854", "hash_sha1": "B1B37124E9AFD6C860189CE4D49CEBBB2E4C57BC", "hash_sha256": "C61FA0F8C5D8D61110ADBCCEAA453A6C1D31255B3244DC7E3B605A4A931C245C", "hash_sha384": "48CC273685B249733E79BFFF61BD986CFAECA9B271E42340E5313CF93595A1C02953381EE5333426AB8892B9C53ED3CE", "hash_sha512": "511F5981BD2C446F1F3039F6674F972651512305630BD688B1EF159AF36A23CB836B43D7010B132A86B5F4D6C46206057ABD31600F1E7DC930CB32ED962298A4", "hash_ssdeep": "1536:9aZhtREC/rMcgEPJV+G57ThjEC0kzJP+V5Ja:GhzECTMpuDhjRVJGk", "hash_imp": "68CA080EE65AE9EA92581804B773ECBD", "hash_pesha1": "D1E6E61CD2BDD4959B9926AD9638FF52B9634E71", "hash_pe256": "75110719C1C0DF60A85129D95B150165B12A659BF239B2F76C7959C1B40568EA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Advanced System Settings", "meta_original_filename": "SystemPropertiesAdvanced.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c61fa0f8c5d8d61110adbcceaa453a6c1d31255b3244dc7e3b605a4a931c245c/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesAdvanced.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\srrstr.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesAdvanced.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\COMDLG32.dll" ] }, "SystemPropertiesComputerName.exe-6711765F323289F5008A6A2A04B6F264": { "file_name": "SystemPropertiesComputerName.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesComputerName.exe", "hash_md5": "6711765F323289F5008A6A2A04B6F264", "hash_sha1": "D8116FDF73608B4B254AD83C74F2232584D24144", "hash_sha256": "BD3A97327326E2245938EC6099F20059B446FF0FE1C10B9317D15D1A1DD5331E", "hash_sha384": "20EA4E4B3E40E1A8A2832509EEAFF280FFF6259A8F264E325CF5B7446EA4BD27A3D56963CB66577D972339AD803AA44E", "hash_sha512": "438ABD282D9D1C0E7E5DB2CE027FF9522C3980278B32B2EAE09C595884A8DCBFD5178BC5926B1D15F03174303382E13F5D5ECAB9A5D8E31FC07EF39E66C012E8", "hash_ssdeep": "1536:ptZ9tREC/rMcgEPJV+G57ThjEC0kzJP+V5Ju:d9zECTMpuDhjRVJGY", "hash_imp": "68CA080EE65AE9EA92581804B773ECBD", "hash_pesha1": "71C8D4F02777D126F23C43903CF16578C5BDB2C1", "hash_pe256": "FC6AA16508BE74692E9D46D8AF3CA4E7CB0D45B04C88D8294B895DE057DE6576", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Computer Settings", "meta_original_filename": "SystemPropertiesComputerName.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/bd3a97327326e2245938ec6099f20059b446ff0fe1c10b9317d15d1a1dd5331e/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesComputerName.exe.mui": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\srrstr.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesComputerName.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "SystemPropertiesDataExecutionPrevention.exe-DE58532954C2704F2B2309FFC320651D": { "file_name": "SystemPropertiesDataExecutionPrevention.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesDataExecutionPrevention.exe", "hash_md5": "DE58532954C2704F2B2309FFC320651D", "hash_sha1": "0A9FC98F4D47DCCB0B231EDF9A63309314F68E3B", "hash_sha256": "1F810658969560F6E7D7A14F71D1196382E53B984CA190FA9B178AC4A32ACFB3", "hash_sha384": "9543DFB1E18A7680FFE38D389D8BE9EF30C7D10DE5B0C1F852057194F2CFB005004317F117ACDF1F7F2CB624BD2EEF37", "hash_sha512": "D4D57CC30D9079F4E9193BA42631E8E53D86B22E9C655D7A8C25E5BE0E5E1D6DFFF4714DDC23E3E392809D623B4F8D43C63893F74C325FC77459AC03C7A451ED", "hash_ssdeep": "1536:SzZ9tREC/rMcgEPJV+G57ThjEC0kzJP+V5Jf:K9zECTMpuDhjRVJGJ", "hash_imp": "68CA080EE65AE9EA92581804B773ECBD", "hash_pesha1": "B1BF70B67116506CC456B92DDC9AE4A286B1C09C", "hash_pe256": "8A2DCE84E87DD3A48B8871BD039C5C389B4B37F05FDFD5FE202ECE2CCF72CC48", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Data Execution Prevention Settings", "meta_original_filename": "SystemPropertiesDataExecutionPrevention.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1f810658969560f6e7d7a14f71d1196382e53b984ca190fa9b178ac4a32acfb3/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesDataExecutionPrevention.exe.mui": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesDataExecutionPrevention.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL" ] }, "SystemPropertiesHardware.exe-BF5BC0D70A936890D38D2510EE07A2CD": { "file_name": "SystemPropertiesHardware.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesHardware.exe", "hash_md5": "BF5BC0D70A936890D38D2510EE07A2CD", "hash_sha1": "69D5971FD264D8128F5633DB9003AFEF5FAD8F10", "hash_sha256": "C8EBD920399EBCF3AB72BD325B71A6B4C6119DFECEA03F25059A920C4D32ACC7", "hash_sha384": "136F8DC5583CC61FC68D4655D3D893D459DBCE6854F8E1AB13AB213C4190644C740268B0B18D6C4797177EF6452DC4FB", "hash_sha512": "0E129044777CBBF5EA995715159C50773C1818FC5E8FAA5C827FD631B44C086B34DFDCBE174B105891CCC3882CC63A8664D189FB6A631D8F589DE4E01A862F51", "hash_ssdeep": "1536:TWZxtREC/rMcgEPJV+G57ThjEC0kzJP+V5JX:8xzECTMpuDhjRVJGB", "hash_imp": "68CA080EE65AE9EA92581804B773ECBD", "hash_pesha1": "8DE5898DE13FE6DC14EA7F4ECB66C28ACDAAEE72", "hash_pe256": "59E1FA081A76EFB6BDCF02C7AE2AE539A1FC2B1AA7FB0933CA4E53CDE485588A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hardware Settings", "meta_original_filename": "SystemPropertiesHardware.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/c8ebd920399ebcf3ab72bd325b71a6b4c6119dfecea03f25059a920c4d32acc7/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesHardware.exe.mui": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\srrstr.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesHardware.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\GDI32.dll" ] }, "SystemPropertiesPerformance.exe-E4FBF7CAB8669C7C9CEF92205D2F2FFC": { "file_name": "SystemPropertiesPerformance.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesPerformance.exe", "hash_md5": "E4FBF7CAB8669C7C9CEF92205D2F2FFC", "hash_sha1": "ADBFA782B7998720FA85678CC85863B961975E28", "hash_sha256": "B266318D45A4245556A2E39B763F2F11ECA780969105F6F103E53DD0A492BB30", "hash_sha384": "C977461A713A9018D6ABA88176D0E18689E96234E52F09DE678000A45F3BCC5A07A0933B4820886318B859DEA8D52074", "hash_sha512": "C5C62578D04133352D6CB7B018DF96A7B55C18D6111AB8BF2BFE232A3315A63B07047FA5B0B88551D152085776C66169B47566242C8C4C5E0333C55ADC64E1B6", "hash_ssdeep": "1536:+2ZPAtREC/rMcgEPJV+G57ThjEC0kzJP+V5JS:DPAzECTMpuDhjRVJGc", "hash_imp": "835402499FB5903791DBBE73881263B5", "hash_pesha1": "BB28E635AEA7AB2E8482812CA311EB90E9256A0C", "hash_pe256": "0A762E3B9C32F19326EFC866E00ED100EEB638868C51A5560CB84153F4522BAD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Computer Performance Settings", "meta_original_filename": "SystemPropertiesPerformance.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b266318d45a4245556a2e39b763f2f11eca780969105f6f103e53dd0a492bb30/detection", "children": "RdpSa.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesPerformance.exe.mui": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\SystemResources\\shell32.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesPerformance.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\GDI32.dll" ] }, "SystemPropertiesProtection.exe-26640D2D4FA912FC9A354EF6CFE500FF": { "file_name": "SystemPropertiesProtection.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesProtection.exe", "hash_md5": "26640D2D4FA912FC9A354EF6CFE500FF", "hash_sha1": "A343FD82659CE2D8DE3BEB587088867CF2AB8857", "hash_sha256": "A8DDF1B17B0CBC96A7EAEDB0003AA7B1631DA09EBFE85B387F8F630222511B37", "hash_sha384": "92A4CF11C9BF8A2B511B7EB9D8B646929B38A35F087E8638653B0A4DDCE0E8794EA9F9AACAD616BB6E2E9AE196DC658C", "hash_sha512": "26162A3D9D4A8E3290DBCF6FE387B5C48AB1D9552AA02A38954649D877F408CB282E57580F81E15128E3A41DA0EB58328D1D6253E1B57232F9A8CECDD99991DC", "hash_ssdeep": "1536:zkZptREC/rMcgEPJV+G57ThjEC0kzJP+V5JP:qpzECTMpuDhjRVJGF", "hash_imp": "68CA080EE65AE9EA92581804B773ECBD", "hash_pesha1": "2E006DBF3B3530A3396AFB49CE2B43E72F9B0698", "hash_pe256": "385E2DC87CD969561B4FE36E819002E2FB0DF4188AD27172A36EC0F35A7AA8ED", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Protection Settings", "meta_original_filename": "SSystemPropertiesProtection.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a8ddf1b17b0cbc96a7eaedb0003aa7b1631da09ebfe85b387f8f630222511b37/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesProtection.exe.mui": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\srrstr.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\vsstrace.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_16.db": "File", "(R-D) C:\\Windows\\System32\\en-US\\windows.storage.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesProtection.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\GDI32.dll" ] }, "SystemPropertiesRemote.exe-CDCE1EE7F316F249A3C20CC7A0197DA9": { "file_name": "SystemPropertiesRemote.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesRemote.exe", "hash_md5": "CDCE1EE7F316F249A3C20CC7A0197DA9", "hash_sha1": "DADB23AF07827758005EC0235AC1573FFCEA0DA6", "hash_sha256": "7984E2BFF295C8DBCBD3CD296D0741E3A6844B8DB9F962ABDBC8D333E9A83932", "hash_sha384": "476242B4A137123FA5400D77564CA0BACEF554D699594FA455060595A15422F6C35162D3F2DF4E6B46F9C076FA8B8A0C", "hash_sha512": "F1DC529EBFED814ADCF3E68041243EE02BA33B56C356A63EBA5EF2CB6EDE1EDA192E03349F6A200D34DFAB67263DF79CF295BE3706F4197B9008CCDC53410C26", "hash_ssdeep": "1536:82ZTtREC/rMcgEPJV+G57ThjEC0kzJP+V5Jx:lTzECTMpuDhjRVJGf", "hash_imp": "68CA080EE65AE9EA92581804B773ECBD", "hash_pesha1": "FAFF7FC273278A8F510FDEBE654560D74009F8ED", "hash_pe256": "F1F0809B2C29F6395BA032947620CC05301C4682C4F14CBE576F8360C2F50EB4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Remote Settings", "meta_original_filename": "SystemPropertiesRemote.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7984e2bff295c8dbcbd3cd296d0741e3a6844b8db9f962abdbc8d333e9a83932/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesRemote.exe.mui": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\srrstr.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesRemote.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "systemreset.exe-2D90A9D5A963524C914B75F3DED81301": { "file_name": "systemreset.exe", "file_path": "C:\\Windows\\system32\\systemreset.exe", "hash_md5": "2D90A9D5A963524C914B75F3DED81301", "hash_sha1": "B08BB69F873E4E7DC535EDFC2877F552C175398F", "hash_sha256": "D2A488D18595BD4C0C324A99BF2746CB934ADC4E4268938F1057933F614F083F", "hash_sha384": "2E54625A79E6B131863855B9D795FA1944492B1778B5112EA23A1266BE9E68718DC667F1A0C5BE95B68C28D709AACF15", "hash_sha512": "E023967F04EB13C3978DBCD48FF0879ECAB287AB70BAEA5D8A977FBE3E73A5808C5ADE7D8C3065D3639DEBC0AB05C2760C17C7FD4D4586D0F53CB607FA5C7AA8", "hash_ssdeep": "6144:NrfopRvRJj0HM4LOS89dMP3eWQvCCTQ4S4M9OWK/sT+1Jtq6VC+LV7KUIQGEEEsf:NgpFRJj0HM469MP3PQaC84S4M9Ox8z5l", "hash_imp": "8B0F5D4A63127835DC3CA54D48C2BA57", "hash_pesha1": "884EB291F18C75A6BA5EA68AE2296BC9ED3121EE", "hash_pe256": "AA1023D6E3D8BF44549A3C0C6107156174BA14F80367269F2B7263C71BD2EC2F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Reset for Windows", "meta_original_filename": "systemreset.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d2a488d18595bd4c0c324a99bf2746cb934adc4e4268938f1057933f614f083f/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\systemreset.exe.mui": "File", "\\BaseNamedObjects\\SetupLogSection": "Section", "(RW-) C:\\$SysReset\\Logs\\setupact.log": "File", "(RW-) C:\\$SysReset\\Logs\\setuperr.log": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\Windows.UI.Immersive.dll.mun": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\Windows.UI.Immersive.dll.mui": "File", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Windows\\System32\\en-US\\bootux.dll.mui": "File", "(RW-) C:\\Windows\\System32": "File", "(RWD) C:\\Windows\\Fonts\\seguisym.ttf": "File", "(RWD) C:\\Windows\\Fonts\\segoeuisl.ttf": "File", "(RWD) C:\\Windows\\Fonts\\seguisb.ttf": "File", "(RWD) C:\\Windows\\Fonts\\segoeuil.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\systemreset.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\WINTRUST.dll" ], "runtime_window_title": "Choose an option" }, "SystemSettingsAdminFlows.exe-DAB5D8C43AD5FC042037E7E62C449EF9": { "file_name": "SystemSettingsAdminFlows.exe", "file_path": "C:\\Windows\\system32\\SystemSettingsAdminFlows.exe", "hash_md5": "DAB5D8C43AD5FC042037E7E62C449EF9", "hash_sha1": "E3FA091A3CE4A4E683A4D63248B842445175FDD4", "hash_sha256": "72D72F950FB618710F91DA59361CF4B8B6BB703610EFB5DA2501987A28FFFC84", "hash_sha384": "CF55E8546D49F566F385879E0B08B43D7E9E500DE54576BB36DBE5A48449ECA3F96B95F0F3CBA65B85D28D429FF03C8C", "hash_sha512": "68F5BF395BCF58F98C49F6D660B3DF14180ACD79A7D59419211329C9CA5AEEB1BC3D3DD2809BE80CBD4C4611EFF2119EC9F85A649A6CFA6DC4B98C0E2ED84045", "hash_ssdeep": "6144:rgiF6uqHtSJ4km5flEsHFlrMeWpUeIW5A2VJov+ZPyq1ywPu8nkiNjtN2:MiF9ItFk6l1H3rMzeeBHZPtwC7jtU", "hash_imp": "C6531DFED34A54D8246E693AE49F54F8", "hash_pesha1": "5A5039D2F3EFE9FA0CE6486ED43FB68DA82F8D33", "hash_pe256": "2F55472D56E92E80407DC30B945AB1161F6EDCDE18EF021C916280912CF25C08", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Settings", "meta_original_filename": "SystemSettingsAdminFlows.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/72d72f950fb618710f91da59361cf4b8b6bb703610efb5da2501987a28fffc84/detection", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\system32\\SystemSettingsAdminFlows.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\system32\\SystemSettingsThresholdAdminFlowUI.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\SHCORE.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\newdev.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\WTSAPI32.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\system32\\AppXDeploymentClient.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\DismApi.DLL", "C:\\Windows\\system32\\WINBRAND.dll", "C:\\Windows\\system32\\wincorlib.DLL", "C:\\Windows\\system32\\DNSAPI.dll" ] }, "SystemSettingsBroker.exe-C9BA3F7DEC88D45F55FF2FB3DC4FDB5C": { "file_name": "SystemSettingsBroker.exe", "file_path": "C:\\Windows\\system32\\SystemSettingsBroker.exe", "hash_md5": "C9BA3F7DEC88D45F55FF2FB3DC4FDB5C", "hash_sha1": "BFB6328E7DF66AFA8E8BC09708DD9DF0293636CC", "hash_sha256": "C57B3CCDED8EFEA55A1CDB794DE2ABF46B3BC1CEE108768BF572388922DC6D7C", "hash_sha384": "454220084C9D15BB293E6112E5E8134014FCD948CFE90DDE8E263B2C43BBD051A584A79531D8907C4BE8727EEC3EC41E", "hash_sha512": "F96E584667F00784D7A57FEE33C303FD1A497EBD251B95B476D586D30B2570447B26AF2733F1CA2A1A7C8AA7A19AC3984E8486A5C3BDC60AB9CE488CA904C5D7", "hash_ssdeep": "3072:jB0/XugribH0k9pDBUpUET+o6jReL+9y4PyxnYYmHx3FCy7wqe9LIctbie:jFpUGN+UW+o6jRenpmHOy7wZjtD", "hash_imp": "3A177E6AFB160C377ED95B1005942B8A", "hash_pesha1": "C59C1A35D3ABEA7E03C9EE4940B85B7BF35B482D", "hash_pe256": "A77789C9D3A4E272ED9F0B2A54119842C4CC000EA98A2DE54BE137B909557265", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Settings Broker", "meta_original_filename": "SystemSettingsBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.329 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.329", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c57b3ccded8efea55a1cdb794de2abf46b3bc1cee108768bf572388922dc6d7c/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemSettingsBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "SystemSettingsRemoveDevice.exe-6DFE20B7A849D60E580D3BE2FA008C04": { "file_name": "SystemSettingsRemoveDevice.exe", "file_path": "C:\\Windows\\system32\\SystemSettingsRemoveDevice.exe", "hash_md5": "6DFE20B7A849D60E580D3BE2FA008C04", "hash_sha1": "F8F68A30518B71AC8D3EFE6D7BBBB8C81E9ED57D", "hash_sha256": "4264902A2BEFCF2A94A3BF5B660837581EB777742AD3BA8D405B67A52EDADFD9", "hash_sha384": "47C1C35BB95A73DEEBD795A8CAB8E4585B97A0738CE32559F9B8A826009C9EB1A2C4CE00688FC19F5E8CE97B785973AA", "hash_sha512": "5665CC7ECB45EC3F77965CCE0BDB34A82BE783B99E6509F7731E5EA52A7336F9F6E1E8A25A0A982E473DC559EA88F3639E3C8CD96F9A11CEB1726B4C754CF79A", "hash_ssdeep": "768:j3batw7cbZaPffKJ1DEjFBfJmsYEby0sOZdrnXETI1PKV5v:DubACXDQPmcbhZdrnbPKV", "hash_imp": "9DC9B6E9378726AD78F12FE890DECC7F", "hash_pesha1": "418269821F8E72C2D51A0D0E8663161799753F45", "hash_pe256": "5D7F6FC36D4CC0B1A21602274F225D4644D927F1BB462C25525FA0D57FBBC3B5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SystemSettingsRemoveDevice", "meta_original_filename": "SystemSettingsRemoveDevice.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4264902a2befcf2a94a3bf5b660837581eb777742ad3ba8d405b67a52edadfd9/detection", "children": "powershell.exe", "runtime_modules": [ "C:\\Windows\\system32\\SystemSettingsRemoveDevice.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll" ] }, "SystemUWPLauncher.exe-91E6F5ED4140101CA3D2F48BF8B149E1": { "file_name": "SystemUWPLauncher.exe", "file_path": "C:\\Windows\\system32\\SystemUWPLauncher.exe", "hash_md5": "91E6F5ED4140101CA3D2F48BF8B149E1", "hash_sha1": "85E348FBC9D183D360FFA5CDCEDDE9698029D4F4", "hash_sha256": "510EDE28028A3BBBAED028804AE5F0D8E5A5864F134021476B0A006A8E69BE2C", "hash_sha384": "90F0B5D52C9D112FB827CC63D0227ECAB21F4579728488C053E7BAEEA55AC3C6547D055F513C70E7239E51F8AC8AC38B", "hash_sha512": "5C34F7D2DAB4871C86241DCABEDE089B36BC106187EB75AD87D445812458D1CA7A676FA7D39FB7B628CC536EC8DA5D3941D0E408F9BDFEEC090D8A5601B2BA95", "hash_ssdeep": "1536:hR9tTsigVdKpRTuZmqZDu6ehbi44voz8kDhvTb:vovdKpFuZmiDu6IG44AzlFvn", "hash_imp": "455635ECDB048BC446820490B3539B1C", "hash_pesha1": "199F6DE09424B91290B876DDABEBC1EFC5BB6FCB", "hash_pe256": "11CCE4D11B1D4C1FDEFE3ACDBD195934A6C8B4669AD10F9E6A59EFB07E1452AB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SystemUWPLauncher", "meta_original_filename": "SystemUWPLauncher.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.388 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.388", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/510ede28028a3bbbaed028804ae5f0d8e5a5864f134021476b0a006a8e69be2c/detection", "runtime_modules": [ "C:\\Windows\\system32\\SystemUWPLauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll" ] }, "systray.exe-E951653F86A2E7BEB23BA5F7FCD22354": { "file_name": "systray.exe", "file_path": "C:\\Windows\\system32\\systray.exe", "hash_md5": "E951653F86A2E7BEB23BA5F7FCD22354", "hash_sha1": "650FC49914018E76292720F3B22F0A052FDFB2B2", "hash_sha256": "853ABA88579DFE2D5A9C4F614BB68983F3989DB621C9181F235CD79103E9B2AB", "hash_sha384": "92DD84415F48FCCA5525EBC46B9F96F51B4884B76EAD244C215A8A4E1B82EFF1312F1D645BF5496C835C8B390780DCCA", "hash_sha512": "3A5EBF3D5507D30B9F52453173588E145AA51C61948C6C037CB561E3E522F12DD4EEBF97EAD8B3C30B53962E0781B161ADAF52DFB3F7FF4904A23AD5B6D810A9", "hash_ssdeep": "192:xntMErK9VZdM3q8zCicMLL08IT6N6UseWZbfuWhyW:xnGeK567OiX73NGZb2WhyW", "hash_imp": "5487E920EA68F003A70EB2B7EC92C4EB", "hash_pesha1": "0FBDCEDFFE59C1A0F82754123A3E0FAB17C66494", "hash_pe256": "EDFF0BD317689CB47E2E35FC482A2538998799C4FDBC0E8CF3F3366ECDD2024D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Systray .exe stub", "meta_original_filename": "systray.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/853aba88579dfe2d5a9c4f614bb68983f3989db621c9181f235cd79103e9b2ab/detection", "runtime_modules": [ "C:\\Windows\\system32\\systray.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "tabcal.exe-40F4014416FF0CBF92A9509F67A69754": { "file_name": "tabcal.exe", "file_path": "C:\\Windows\\system32\\tabcal.exe", "hash_md5": "40F4014416FF0CBF92A9509F67A69754", "hash_sha1": "1798FF7324724A32C810E2075B11C09B41E4FEDE", "hash_sha256": "F31B4C751DBCA276446119BA775787C3EB032DA72EABCD40AD96A55826A3F33C", "hash_sha384": "E84AE1B42DAE9C2A7020E4F81099B0F60F5D60CDFD8DA34D79F279E34D54D9DE3990F03961BD3D9FDA4B2DD6509C6155", "hash_sha512": "646DFE4CFE90D068C3DA4C35F7053BB0F57687875A0F3469C0683E707306E6A42B0BACA3E944D78F9BE5C564BB0600202C32C223A770F89D3E2B07A24673C259", "hash_ssdeep": "1536:XVS+G/Xh6wJ/59qhwfhrJ4L1Y6pEGMne24cdfW2jbJK:XsL6oRFhrJ4G6J2eJcdfZbs", "hash_imp": "AE0F94FDC8914C190BEEBCE401A3F4B2", "hash_pesha1": "15139CB1C91A530FEF5B3C162D1E0B8654ECC750", "hash_pe256": "870798A3E4A6457743FB646256BB153E0ADFDB277B1D2D1323CD5ACE76C59EFB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Digitizer Calibration Tool", "meta_original_filename": "tabcal.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f31b4c751dbca276446119ba775787c3eb032da72eabcd40ad96a55826a3f33c/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\tabcal.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\tabcal.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\system32\\HID.DLL", "C:\\Windows\\system32\\NInput.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ], "runtime_window_title": "Digitizer Calibration Tool" }, "takeown.exe-D258A76AA885CBBCAE8C720CD1C284A5": { "file_name": "takeown.exe", "file_path": "C:\\Windows\\system32\\takeown.exe", "hash_md5": "D258A76AA885CBBCAE8C720CD1C284A5", "hash_sha1": "85A080DA6C5A908C4C5973BF429D63B975B85109", "hash_sha256": "57B3CFA9993E52866A2FB489EDF079BF4F1C78FA7525BDF59AFFA8F9CB4023F8", "hash_sha384": "C3F315A757A2471FF8EF75A6D708104D92AE45F275F91A2AF2885BB2224A1A41CE45C903BB97BF2B169894D0BE0B931A", "hash_sha512": "FFAE4A77862DCFA7AFC358BFA72183A3DE1741215878FBC476C65FB6E4C456B3CEEC957E4D7F7A0CF43B2852D5CFE4AE96CB3739C93D63F73F3B6C153CF22D1E", "hash_ssdeep": "1536:U/7ViVxnApoXoCPWDBmjYiCxnG4hPpWfPZaTqk:U7V1goCPWDBWY//PpOPZaH", "hash_imp": "3BF02FC8FEFDCA08F1DB0D03C18BF179", "hash_pesha1": "A49F56BFAA75952F38E09EC91EF060346B6E56F5", "hash_pe256": "48839B211F1717ADC6858707D7C7C3893B9E7343CE8D45CA2999F7F77DE71A27", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Takes ownership of a file", "meta_original_filename": "takeown.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/57b3cfa9993e52866a2fb489edf079bf4f1c78fa7525bdf59affa8f9cb4023f8/detection", "output": "\r\nTAKEOWN [/S system [/U username [/P [password]]]]\r\n /F filename [/A] [/R [/D prompt]]\r\n\r\nDescription:\r\n This tool allows an administrator to recover access to a file that\r\n was denied by re-assigning file ownership.\r\n\r\nParameter List: \r\n /S system Specifies the remote system to\r\n connect to.\r\n\r\n /U [domain\\]user Specifies the user context under\r\n which the command should execute.\r\n\r\n /P [password] Specifies the password for the\r\n given user context.\r\n Prompts for input if omitted.\r\n\r\n /F filename Specifies the filename or directory\r\n name pattern. Wildcard \"*\" can be used\r\n to specify the pattern. Allows\r\n sharename\\filename.\r\n\r\n /A Gives ownership to the administrators\r\n group instead of the current user.\r\n\r\n /R Recurse: instructs tool to operate on\r\n files in specified directory and all \r\n subdirectories.\r\n\r\n /D prompt Default answer used when the current user\r\n does not have the \"list folder\" permission\r\n on a directory. This occurs while operating\r\n recursively (/R) on sub-directories. Valid \r\n values \"Y\" to take ownership or \"N\" to skip.\r\n\r\n /SKIPSL Do not follow symbolic links.\r\n Only applicable with /R.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE: 1) If /A is not specified, file ownership will be given to the\r\n current logged on user.\r\n\r\n 2) Mixed patterns using \"?\" and \"*\" are not supported.\r\n\r\n 3) /D is used to suppress the confirmation prompt.\r\n\r\nExamples: \r\n TAKEOWN /?\r\n TAKEOWN /F lostfile\r\n TAKEOWN /F \\\\system\\share\\lostfile /A\r\n TAKEOWN /F directory /R /D N\r\n TAKEOWN /F directory /R /A\r\n TAKEOWN /F *\r\n TAKEOWN /F C:\\Windows\\System32\\acme.exe\r\n TAKEOWN /F %windir%\\*.txt\r\n TAKEOWN /S system /F MyShare\\Acme*.doc\r\n TAKEOWN /S system /U user /F MyShare\\MyBinary.dll\r\n TAKEOWN /S system /U domain\\user /P password /F share\\filename\r\n TAKEOWN /S system /U user /P password /F Doc\\Report.doc /A\r\n TAKEOWN /S system /U user /P password /F Myshare\\* \r\n TAKEOWN /S system /U user /P password /F Home\\Logon /R\r\n TAKEOWN /S system /U user /P password /F Myshare\\directory /R /A\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"TAKEOWN /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\takeown.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "TapiUnattend.exe-B574ABF43DCC57A359129D1ADB4CDDA0": { "file_name": "TapiUnattend.exe", "file_path": "C:\\Windows\\system32\\TapiUnattend.exe", "hash_md5": "B574ABF43DCC57A359129D1ADB4CDDA0", "hash_sha1": "6FB0F79D9A7F0108FF817EE418E3436CC51393B5", "hash_sha256": "6A960EDAD235F685E741E0F1A74D1162FD3CF410862192236F962AE289F0886E", "hash_sha384": "FB880E552CCA9D42F53A9DFCB41A21DC452DC0086A93F3F84EA15FB66B6F1C60134BD8265D835E38B2493F379FEE9EC7", "hash_sha512": "A82831945726B02E56A843288039D5770F926615DDE410653EDA33A90BDF00B5C9492DD8483D97F2798009E8F38453C3089853495E1AF2A8276BBA7EBCE51B78", "hash_ssdeep": "384:iDGM25RMVvRfawNrznG1t8DiPvkYvUFRR4Jxj0GW/GUW:iV2ovn+PvkYMyvjT", "hash_imp": "42F88FF1F6019E68C40B1CFD658DDBCE", "hash_pesha1": "BE8AFB7D621C0F00CED7796EF18C1A3803DF0BF8", "hash_pe256": "51CDBE9D4EF3787D4FF17D458613E02EB719DA9E185837DE542CA3BDC8521A2F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) Telephony Unattend Action", "meta_original_filename": "TapiUnattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6a960edad235f685e741e0f1a74d1162fd3cf410862192236f962ae289f0886e/detection", "runtime_modules": [ "C:\\Windows\\system32\\TapiUnattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\WDSCORE.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll" ] }, "tar.exe-4D188B08E9274E1360062B22E88A2F3F": { "file_name": "tar.exe", "file_path": "C:\\Windows\\system32\\tar.exe", "hash_md5": "4D188B08E9274E1360062B22E88A2F3F", "hash_sha1": "F93374196F5F6E19B370CDDD9332AC248937E5EF", "hash_sha256": "0F28C8D166C7A671B0048137232E9CA6973F1EC826104834AE310681C1866E62", "hash_sha384": "FE40A7B2E90581E231295F445F6DB120EA30CB4FA05A42BC0EB120E28A3F269DB1F711EFC87AB89C6DA93348EE90872B", "hash_sha512": "5B0D1D2F0E48FB3B250891163C2F1E935663B6865483180EDD1167B8F3269508977893E3FAF905D0676EF0A5CBFDD3486A66D3D521643D68DDA7E55528337207", "hash_ssdeep": "768:CciB9nbl48DFyNO63/JoH4jEjwlz18rOq5+fQgD77uPhyHijOuPhtflM7J5SpxdG:Fy9nbktRoH4jAOz7CPZpPBMLSp7Kr", "hash_imp": "518D7F2D8793287656651908BECA1B27", "hash_pesha1": "0F4F94501DA0A6D7FDF1917E52B1AF481D9DA394", "hash_pe256": "F363FB85DA8700BB2796DCEC95747B166C639D7A92679ECF43AA07669B983AEC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "bsdtar archive tool", "meta_original_filename": "bsdtar", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "3.3.2 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (c) libarchive authors", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0f28c8d166c7a671b0048137232e9ca6973f1ec826104834ae310681c1866e62/detection", "error": "Usage:\r\n List: tar.exe -tf <archive-filename>\r\n Extract: tar.exe -xf <archive-filename>\r\n Create: tar.exe -cf <archive-filename> [filenames...]\r\n Help: tar.exe --help\r\n", "output": "tar.exe(bsdtar): manipulate archive files\r\nFirst option must be a mode specifier:\r\n -c Create -r Add/Replace -t List -u Update -x Extract\r\nCommon Options:\r\n -b # Use # 512-byte records per I/O block\r\n -f <filename> Location of archive (default \\\\.\\tape0)\r\n -v Verbose\r\n -w Interactive\r\nCreate: tar.exe -c [options] [<file> | <dir> | @<archive> | -C <dir> ]\r\n <file>, <dir> add these items to archive\r\n -z, -j, -J, --lzma Compress archive with gzip/bzip2/xz/lzma\r\n --format {ustar|pax|cpio|shar} Select archive format\r\n --exclude <pattern> Skip files that match pattern\r\n -C <dir> Change to <dir> before processing remaining files\r\n @<archive> Add entries from <archive> to output\r\nList: tar.exe -t [options] [<patterns>]\r\n <patterns> If specified, list only entries that match\r\nExtract: tar.exe -x [options] [<patterns>]\r\n <patterns> If specified, extract only entries that match\r\n -k Keep (don't overwrite) existing files\r\n -m Don't restore modification times\r\n -O Write entries to stdout, don't restore to disk\r\n -p Restore permissions (including ACLs, owner, file flags)\r\nbsdtar 3.3.2 - libarchive 3.3.2 zlib/1.2.5.f-ipp\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tar.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "taskhostw.exe-B2B02A857A2AA316EC17DD3BC73406C3": { "file_name": "taskhostw.exe", "file_path": "C:\\Windows\\system32\\taskhostw.exe", "hash_md5": "B2B02A857A2AA316EC17DD3BC73406C3", "hash_sha1": "B970BFA8A50D49D7DADB4BEAF17BCE0F62A8143C", "hash_sha256": "59C34F131DCEDCC34252D2AB18754481843EFB2A64A92996391330C321154943", "hash_sha384": "FC073DA6769EDADDD0EC4325DCC697F60983DB8CBDA3F8247F68E83AEC2D0231E16D47066ADBF0D57E520866363D6C4C", "hash_sha512": "A9AD7C90656BFE25F7CF1A657D965170EC103A56CBC1FA58DC735D8EF6EDB9D327037E2FAE75F24DD2C9D8DFB63DE0F21027D341FA2460EFB29A07C84A9215FF", "hash_ssdeep": "1536:+1ZCzBzDm9RGtcpHyxlLfE38VsPPh2mBqXh+MGfv6BirgrKdO3yfP9J/:0Ezp1tcJyxlLfE38wP7sXh+HfCogrKdP", "hash_imp": "3A0C6863CDE566AF997DB2DEFFF9D924", "hash_pesha1": "B80FFB5C8474121865F49C6CA4935C53FA08DAF1", "hash_pe256": "614D057889E734F81F915FD6399FAFCDE007BE163917935E7C8EDD0E3F4BBFBF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Windows Tasks", "meta_original_filename": "taskhostw.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/59c34f131dcedcc34252d2ab18754481843efb2a64a92996391330c321154943/detection", "runtime_modules": [ "C:\\Windows\\system32\\taskhostw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "taskkill.exe-A599D3B2FAFBDE4C1A6D7D0F839451C7": { "file_name": "taskkill.exe", "file_path": "C:\\Windows\\system32\\taskkill.exe", "hash_md5": "A599D3B2FAFBDE4C1A6D7D0F839451C7", "hash_sha1": "0225BBEC16CB7B23B189F811065767180EDA9801", "hash_sha256": "56F8CC2C1790C389394733B84C3FB55E10977E9F0FE0C08110AC11F0FE47F05E", "hash_sha384": "94A9CBC5732353B92378FD8BCE2941AEA223991653BFD2FE330FE40C79AFE239E8CEA5FCC16439C82D8320E4094FFD83", "hash_sha512": "ACFD16B245A667C3766D36EA753AA7002A03C206B7C3117CCAC92315401B536F56CEFF606D8112178DD8916A20378AB91818E0E65E6CCFD5D75955F511D6FBFB", "hash_ssdeep": "1536:mr0UyaEu4C1f5FJHLK9eHckIe5VZ67IrujQR4I+9TrxxIzN:y0UBEu4kNysIe5V8MCj5xxIB", "hash_imp": "71212588549FB37A46C8556278F180CD", "hash_pesha1": "D79571C64CF61F2668BEE3A5D1A944BC6D97C8A8", "hash_pe256": "4EA4FAC43EEE4D1B3F7D37B81A7ABE05E880D9A7361A1A190A5014092AE585EC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Terminates Processes", "meta_original_filename": "taskkill.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/56f8cc2c1790c389394733b84c3fb55e10977e9f0fe0c08110ac11f0fe47f05e/detection", "output": "\r\nTASKKILL [/S system [/U username [/P [password]]]]\r\n { [/FI filter] [/PID processid | /IM imagename] } [/T] [/F]\r\n\r\nDescription:\r\n This tool is used to terminate tasks by process id (PID) or image name.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which the\r\n command should execute.\r\n\r\n /P [password] Specifies the password for the given user\r\n context. Prompts for input if omitted.\r\n\r\n /FI filter Applies a filter to select a set of tasks.\r\n Allows \"*\" to be used. ex. imagename eq acme*\r\n\r\n /PID processid Specifies the PID of the process to be terminated.\r\n Use TaskList to get the PID.\r\n\r\n /IM imagename Specifies the image name of the process\r\n to be terminated. Wildcard '*' can be used\r\n to specify all tasks or image names.\r\n\r\n /T Terminates the specified process and any\r\n child processes which were started by it.\r\n\r\n /F Specifies to forcefully terminate the process(es).\r\n\r\n /? Displays this help message.\r\n\r\nFilters:\r\n Filter Name Valid Operators Valid Value(s)\r\n ----------- --------------- -------------------------\r\n STATUS eq, ne RUNNING |\r\n NOT RESPONDING | UNKNOWN\r\n IMAGENAME eq, ne Image name\r\n PID eq, ne, gt, lt, ge, le PID value\r\n SESSION eq, ne, gt, lt, ge, le Session number.\r\n CPUTIME eq, ne, gt, lt, ge, le CPU time in the format\r\n of hh:mm:ss.\r\n hh - hours,\r\n mm - minutes, ss - seconds\r\n MEMUSAGE eq, ne, gt, lt, ge, le Memory usage in KB\r\n USERNAME eq, ne User name in [domain\\]user\r\n format\r\n MODULES eq, ne DLL name\r\n SERVICES eq, ne Service name\r\n WINDOWTITLE eq, ne Window title\r\n\r\n NOTE\r\n ----\r\n 1) Wildcard '*' for /IM switch is accepted only when a filter is applied.\r\n 2) Termination of remote processes will always be done forcefully (/F).\r\n 3) \"WINDOWTITLE\" and \"STATUS\" filters are not considered when a remote\r\n machine is specified.\r\n\r\nExamples:\r\n TASKKILL /IM notepad.exe\r\n TASKKILL /PID 1230 /PID 1241 /PID 1253 /T\r\n TASKKILL /F /IM cmd.exe /T \r\n TASKKILL /F /FI \"PID ge 1000\" /FI \"WINDOWTITLE ne untitle*\"\r\n TASKKILL /F /FI \"USERNAME eq NT AUTHORITY\\SYSTEM\" /IM notepad.exe\r\n TASKKILL /S system /U domain\\username /FI \"USERNAME ne NT*\" /IM *\r\n TASKKILL /S system /U username /P password /FI \"IMAGENAME eq note*\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"TASKKILL /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\taskkill.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "tasklist.exe-D0A49A170E13D7F6AEBBEFED9DF88AAA": { "file_name": "tasklist.exe", "file_path": "C:\\Windows\\system32\\tasklist.exe", "hash_md5": "D0A49A170E13D7F6AEBBEFED9DF88AAA", "hash_sha1": "D61FFD641C2F6D45DADC26C02DAEEA8DABEE8204", "hash_sha256": "BE7241A74FE9A9D30E0631E41533A362B21C8F7AAE3E5B6AD319CC15C024EC3F", "hash_sha384": "04D9F9F58B6A1926D0B22A9B4974895686E23FDDA2FE9ED64D9EBA2AE642FD5642F759B7D79B9F857370A3E79AC83D51", "hash_sha512": "8FAB3A6ED410C44E05F5CF13AD732BE00A1D72DB9A35124D385E1D7E3B081377B98B91715269BD858D3044D413DC7527E103C882A9BED9637F2B46F3247AF9A9", "hash_ssdeep": "1536:yUI3KbhXflnknXNMT8ujZAJfLfkx4thxGU2Izjr5wiQ5PJAuhEaHxZGC:K3G9npXWDfkx4thxGiH5wdEaHxD", "hash_imp": "4C8D21C644C980DB3FF94E27BAD14C18", "hash_pesha1": "09DE88B71138EDA32174528A1DAAB7E3E7412D6E", "hash_pe256": "1B16DCABFA83531F3DDF42AC76FC7876AFF28F023A78D18904AE96EE1BF52A5A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Lists the current running tasks", "meta_original_filename": "tasklist.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/be7241a74fe9a9d30e0631e41533a362b21c8f7aae3e5b6ad319cc15c024ec3f/detection", "output": "\r\nTASKLIST [/S system [/U username [/P [password]]]]\r\n [/M [module] | /SVC | /V] [/FI filter] [/FO format] [/NH]\r\n\r\nDescription:\r\n This tool displays a list of currently running processes on\r\n either a local or remote machine.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /M [module] Lists all tasks currently using the given\r\n exe/dll name. If the module name is not\r\n specified all loaded modules are displayed.\r\n\r\n /SVC Displays services hosted in each process.\r\n\r\n /APPS Displays Store Apps and their associated processes.\r\n\r\n /V Displays verbose task information.\r\n\r\n /FI filter Displays a set of tasks that match a\r\n given criteria specified by the filter.\r\n\r\n /FO format Specifies the output format.\r\n Valid values: \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" should\r\n not be displayed in the output.\r\n Valid only for \"TABLE\" and \"CSV\" formats.\r\n\r\n /? Displays this help message.\r\n\r\nFilters:\r\n Filter Name Valid Operators Valid Value(s)\r\n ----------- --------------- --------------------------\r\n STATUS eq, ne RUNNING | SUSPENDED\r\n NOT RESPONDING | UNKNOWN\r\n IMAGENAME eq, ne Image name\r\n PID eq, ne, gt, lt, ge, le PID value\r\n SESSION eq, ne, gt, lt, ge, le Session number\r\n SESSIONNAME eq, ne Session name\r\n CPUTIME eq, ne, gt, lt, ge, le CPU time in the format\r\n of hh:mm:ss.\r\n hh - hours,\r\n mm - minutes, ss - seconds\r\n MEMUSAGE eq, ne, gt, lt, ge, le Memory usage in KB\r\n USERNAME eq, ne User name in [domain\\]user\r\n format\r\n SERVICES eq, ne Service name\r\n WINDOWTITLE eq, ne Window title\r\n MODULES eq, ne DLL name\r\n\r\nNOTE: \"WINDOWTITLE\" and \"STATUS\" filters are not supported when querying\r\n a remote machine.\r\n\r\nExamples:\r\n TASKLIST\r\n TASKLIST /M\r\n TASKLIST /V /FO CSV\r\n TASKLIST /SVC /FO LIST\r\n TASKLIST /APPS /FI \"STATUS eq RUNNING\"\r\n TASKLIST /M wbem*\r\n TASKLIST /S system /FO LIST\r\n TASKLIST /S system /U domain\\username /FO CSV /NH\r\n TASKLIST /S system /U username /P password /FO TABLE /NH\r\n TASKLIST /FI \"USERNAME ne NT AUTHORITY\\SYSTEM\" /FI \"STATUS eq running\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"TASKLIST /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tasklist.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "Taskmgr.exe-44E41BABF9676B9296D8A5719A9ACECC": { "file_name": "Taskmgr.exe", "file_path": "C:\\Windows\\system32\\Taskmgr.exe", "hash_md5": "44E41BABF9676B9296D8A5719A9ACECC", "hash_sha1": "10D7BAAA772F31B8E3B1F63CD2C8FA71492B5D23", "hash_sha256": "793CA2ED06301D0AE8BB590254380E71A91E0EFDEDCE825FB9367D31D02B1D27", "hash_sha384": "5D1B1CAF2F55D81DA2FAA08F63CF843BFABCC1A14E542BE6286A07E15EA44647479FD10F1D3B591941C1E57105BC15CD", "hash_sha512": "758F3375B300F1D77BEED95A0A3A7120932A089072C28828C39B3C2D44F4DB8192F2173EDEBE321A83E48D580D8A9E4BF10607DDD1E16958826C130C55980730", "hash_ssdeep": "24576:JdUilwcPxRSPydIY+SaYLoitMvIIYxBopASEfGJ8Q21dgb25:owxRS6dIYdLIIIYxBUEfGJB21dg", "hash_imp": "9905CD1DB600EE86C64A86E4F49A7378", "hash_pesha1": "56FFD129EF621E8049052DF788F6D3C60560BDA9", "hash_pe256": "54E2986865F1A3B91882F5A5ABE4B2B8B7332246949956C94657D7D7EA5802DF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Manager", "meta_original_filename": "Taskmgr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/793ca2ed06301d0ae8bb590254380e71a91e0efdedce825fb9367d31d02b1d27/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\Taskmgr.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\Taskmgr.exe.mun": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\Sessions\\1\\BaseNamedObjects\\C:*Users*user*AppData*Local*Microsoft*Windows*Caches*cversions.3.ro": "Section", "\\Sessions\\1\\BaseNamedObjects\\C:*Users*user*AppData*Local*Microsoft*Windows*Caches*{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000009.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_16.db": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Taskmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\NSI.dll" ], "runtime_window_title": "Task Manager" }, "tcblaunch.exe-1856AC6C22261F8A2D704E546BAD352F": { "file_name": "tcblaunch.exe", "file_path": "C:\\Windows\\system32\\tcblaunch.exe", "hash_md5": "1856AC6C22261F8A2D704E546BAD352F", "hash_sha1": "64EF8B608B0EE8A31EEE2DE24D8C0EFEB24F7FD4", "hash_sha256": "BCFC04884FEA9AA7A422373F608F011899AAC19DDC46C1AFBAE5D2CCEA576360", "hash_sha384": "919E8562EFAEAACC629A18C9CF672ACA330D9FBE7F803A26D8EB245662E95CDD3022B5428A4FA0A113656BD20D140E8A", "hash_sha512": "1BB2D7D3F74E35D08D9DEE51E078BC17D2BC5909C831B20EEDE5C1C99AFC34C7AABD2B6649C283C0B687AE0B4CF819F340E5802812F3040ABB261DF9E3A2CAD0", "hash_ssdeep": "12288:5oIqmPNU1SvQAnjkHAc8fnOPmCJnj9rwxEbX0Ghy:5oI7NU1SHnj5cLPm6jnbXm", "hash_imp": "n/a", "hash_pesha1": "C1EEBA9A89969CDD739F56D59FF4725675A211B1", "hash_pe256": "33C107B9F183CE311A9C95E0E55C33E8CF0D8B357D63F93D2FDDC47E90AFC8E1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCB Launcher", "meta_original_filename": "tcblaunch.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.685 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.685", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/bcfc04884fea9aa7a422373f608f011899aac19ddc46c1afbae5d2ccea576360/detection" }, "tcmsetup.exe-58F3B915B9AE7D63431772C2616B0945": { "file_name": "tcmsetup.exe", "file_path": "C:\\Windows\\system32\\tcmsetup.exe", "hash_md5": "58F3B915B9AE7D63431772C2616B0945", "hash_sha1": "6346E837DA3B0F551BECB7CAC6D160E3063696E9", "hash_sha256": "E243501BA2EF7A6F04F51410BB916FAFFE0EC23450A4D030CE6BFE747E544B39", "hash_sha384": "AEBC6FB1B84DD3E429A464135FF2955D78C401C86C22B2BB7ADC80C8CC0E914CDFE08AFC93D0FCED5846B2D8010649E3", "hash_sha512": "7B09192AF460C502D1A94989A0D06191C8C7A058CE3A4541E3F45960A1E12529D0CDAFF9DA3D5BACFDCEED57AEB6DC9A159C6C0A95675C438F99BF7E418C6DC5", "hash_ssdeep": "384:A+W7Hrtkdpm8DwTWeErIiBAEdBTC2WGroW:Af7xapm8Dw6n3/CA", "hash_imp": "AE7E4F06CC6D11D0E730DEFD22D14777", "hash_pesha1": "2C527A464E181F92E9917DF07B9519447E6443B3", "hash_pe256": "16CA9ABCCADD6EBDE93902EBCD3D9DAE96BB7A896EE91BA6DBD4A18AE8D5C061", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) Telephony Administration Setup", "meta_original_filename": "TCMSETUP.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/e243501ba2ef7a6f04f51410bb916faffe0ec23450a4d030ce6bfe747e544b39/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\tcmsetup.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\tcmsetup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ], "runtime_window_title": "Telephony Client Setup Help" }, "TCPSVCS.EXE-1DFC98F2EFA2385A9E1D317F980A5092": { "file_name": "TCPSVCS.EXE", "file_path": "C:\\Windows\\system32\\TCPSVCS.EXE", "hash_md5": "1DFC98F2EFA2385A9E1D317F980A5092", "hash_sha1": "D264115BDCFEAF71A5CB31FE9B83641B59499790", "hash_sha256": "FC2BC4B2B115BDE5341C2D40E371A4F50FEEE14D19AAD12EAF5FD0A052BEA403", "hash_sha384": "694A46915EC6514CFC4606368C17AA3C6E72C428879FB8EA9B8590226F8B8204B2AB25DAA4C61A60C6DC21FA021A321A", "hash_sha512": "A3B6FBF4CD048124C844527457298568458E4126EA5846E1767B4B670FF5E9B899B795A12A028C981E867220F545B573D15E875952B93E59876E6F984FB8E88E", "hash_ssdeep": "192:v/jrdjk/bpQQ6yZf7BZWrY9U+l0o+qpXKXU5Gjbm9SdeL6//1FcwcW+/W:vdIt/lV7XW0l0oh54q9f6//ZcW+/W", "hash_imp": "5FB43D31195A81197A7053C4A202BCED", "hash_pesha1": "558722FE2EF97E21D2165257E872866D6E688074", "hash_pe256": "4BAFEA25F5BE00131216064D838A4961E10FEA21737E2263827E4A1628B41F3A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Services Application", "meta_original_filename": "TCPSVCS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "A device attached to the system is not functioning.", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Windows\\system32\\TCPSVCS.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ThumbnailExtractionHost.exe-C56102522FAE0E84503B731B2F8D6B7F": { "file_name": "ThumbnailExtractionHost.exe", "file_path": "C:\\Windows\\system32\\ThumbnailExtractionHost.exe", "hash_md5": "C56102522FAE0E84503B731B2F8D6B7F", "hash_sha1": "3C1D8005F3AAB05B67127C4A3D3861AE8EBE054B", "hash_sha256": "274E6D2AAFB4E660A1FE3FE4FDB8C8EF79576AF9AD5FC0D64A42ABB9D7AFAF9C", "hash_sha384": "E30D0D640F32E421802C5473824764927859C1710BAB90E7CC583A7049F02F9B972C305976BB3C475BD55935F6C94121", "hash_sha512": "B77CD3F0719C00601236BC3A356BCB534E3AE6D2976C938E76978A7555F27B707B47CAAC046B99DE72BDDB60F68023A1E59F8D4BB1FB6C3EF0CE210E5436E808", "hash_ssdeep": "768:F6TwnuaNcBL2BXnC3l4J6BmlXSq6oO0y4WF:ATwnuaIL2Be+zlXSLey4WF", "hash_imp": "8711951497435C4E20E8335DA3ED1A9D", "hash_pesha1": "4B403DC45B3207A0F21415005BC56B69EDD14FCD", "hash_pe256": "CC4957232BE8604AA0DF370993CC8FD855AA96AB0F4D1D725F01980A416E5C4F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Thumbnail Handler Extraction Host", "meta_original_filename": "ThumbnailExtractionHost.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/274e6d2aafb4e660a1fe3fe4fdb8c8ef79576af9ad5fc0d64a42abb9d7afaf9c/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\ThumbnailExtractionHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll" ] }, "TieringEngineService.exe-7005BF7DC5F068712F4A4A1DDD5C4719": { "file_name": "TieringEngineService.exe", "file_path": "C:\\Windows\\system32\\TieringEngineService.exe", "hash_md5": "7005BF7DC5F068712F4A4A1DDD5C4719", "hash_sha1": "A97762B4DDB7C254F876086DDB72221039808B2D", "hash_sha256": "2B871B446CD18D9F8461E5E7C56C2FD3530F06FDED609B8E5A145348C27CB53F", "hash_sha384": "0E52B0271E210FF0C19550CAB574528C93F04867E5D3CEC20630D057D1E4B8EC334770C1059FA2D85C68327971D17E51", "hash_sha512": "6825497D8D62F3EFFB71F9C915948ED1E55C34158016090639A52EC61EBB7E728E6EEE764059E453C306CC580CDB32BBC4059540DA01F3F2F12E171752B0BAB3", "hash_ssdeep": "6144:a2mI1/6JnJRbDpkTK/Na6v1msqIJARE6cjr:avIMJnJ3Va6v1mJVQr", "hash_imp": "F930AAA62473D878318E36DF44DD3044", "hash_pesha1": "0AFFF6DD540DBDE49E77CB0575626330E0EB3B29", "hash_pe256": "7F9AA02B73E46A4625FFAD3D7B3E8601354C9626912CE3F6A3D4FEEC48564839", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Storage Tiers Management", "meta_original_filename": "TieringEngineService.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2b871b446cd18d9f8461e5e7c56c2fd3530f06fded609b8e5a145348c27cb53f/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\TieringEngineService.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\TieringEngineService.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "timeout.exe-100065E21CFBBDE57CBA2838921F84D6": { "file_name": "timeout.exe", "file_path": "C:\\Windows\\system32\\timeout.exe", "hash_md5": "100065E21CFBBDE57CBA2838921F84D6", "hash_sha1": "CE99C615B38F6FEA5A76E19AE95AE16A734332C0", "hash_sha256": "C8C350FAB1130644536DB6A84F605791367308B995079AD494D46A8C617C21D6", "hash_sha384": "B0AF51E7A9B0070760FD5E25B2AB91DC9F1BE2995199F598BD8906C0923DC931F0441BE476B3609594DE553C0D9EE3DD", "hash_sha512": "C22953AC704F376896F60C89DEE27D939B71F1271CEA566D734792A64D375E51A501EF4B89B5031B8AB8AE0BB20A9970A3EA32B55F8C8AF5A60C93DAC6D811EE", "hash_ssdeep": "768:4C+mstSMSSA245AVpUkk8UfOJHfA17pyxg82d:oRV1UfmHfwMxCd", "hash_imp": "0C91A5CE0FB26F4C5CE39E340F43873B", "hash_pesha1": "BC3790FF74A4827F505B040AB16EFA5A97FC23F3", "hash_pe256": "54BB9B9C6AF220A402DBE7F05C7B01951CE4A7E3415F0441C6B741168E6BA99F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "timeout - pauses command processing", "meta_original_filename": "timeout.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c8c350fab1130644536db6a84f605791367308b995079ad494d46a8c617c21d6/detection", "output": "\r\nTIMEOUT [/T] timeout [/NOBREAK] \r\n\r\nDescription:\r\n This utility accepts a timeout parameter to wait for the specified\r\n time period (in seconds) or until any key is pressed. It also \r\n accepts a parameter to ignore the key press. \r\n\r\nParameter List:\r\n /T timeout Specifies the number of seconds to wait.\r\n Valid range is -1 to 99999 seconds.\r\n\r\n /NOBREAK Ignore key presses and wait specified time.\r\n\r\n /? Displays this help message.\r\n\r\nNOTE: A timeout value of -1 means to wait indefinitely for a key press.\r\n\r\nExamples:\r\n TIMEOUT /?\r\n TIMEOUT /T 10\r\n TIMEOUT /T 300 /NOBREAK\r\n TIMEOUT /T -1\r\n", "error": "ERROR: Invalid value for timeout (/T) specified. Valid range is -1 to 99999.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\timeout.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "TokenBrokerCookies.exe-C7F2C10FAA86764A25A99016DE40FB32": { "file_name": "TokenBrokerCookies.exe", "file_path": "C:\\Windows\\system32\\TokenBrokerCookies.exe", "hash_md5": "C7F2C10FAA86764A25A99016DE40FB32", "hash_sha1": "54B584B5BDC0ADD4266996E4ABF33BCBF55BD69F", "hash_sha256": "48EC4693D70E9EB63A21D7A6C8B04BDE7C886D786650DD43D952FAEDBD357CA3", "hash_sha384": "B02B92F7E47C8C6E851CB28B6BC745E5C2A7B865E0448D135E39DB52EAF8B9B099FE6F1AFD403C57F337480C5E96063C", "hash_sha512": "6DF940C711B4E2D74413D81610D5A8C70D33C7C247BB55152480FD734F231C876DD0C986A681114BD8EE4838DD7BC5380D6ADF3561DFFDE3BE10B0FEE9B97A19", "hash_ssdeep": "768:I+2fYWvjH04nHLMvlip+Te/jVwaN/a6SC4l9zJMihGGRUFZ:I1nHLMAh/jaaNaC4lnMihGGRUFZ", "hash_imp": "702F5476F4C0A7F27F77F6BF3689CBB8", "hash_pesha1": "6F3117745FDF9B05870B39C6F813E9C313354049", "hash_pe256": "3E3699B70205ECF476EC53A726331D673C10B44CCE2958CDAAF4A970F05BE848", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Token Broker Cookie Helper", "meta_original_filename": "TokenBrokerCookies.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/48ec4693d70e9eb63a21d7a6c8b04bde7c886d786650dd43d952faedbd357ca3/detection", "runtime_modules": [ "C:\\Windows\\system32\\TokenBrokerCookies.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\WININET.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "TpmInit.exe-2EF855672A91AA4443E8B4C2E1AE278E": { "file_name": "TpmInit.exe", "file_path": "C:\\Windows\\system32\\TpmInit.exe", "hash_md5": "2EF855672A91AA4443E8B4C2E1AE278E", "hash_sha1": "2AB65EA700C05450A48F3842DBC4E7D65C346317", "hash_sha256": "06210A3296CFAD3AF92253BF998536BA1786A8799BB4CAB80CCDF3DDE30F0E66", "hash_sha384": "A4A8E2CEE94DEAD179C790E308FD697694C4DF8322F48452B4247F0D2BED5799A5D559CC065E990D3066FDAB7117E2E3", "hash_sha512": "E5674153D4B8F82B1944C99B89064FC277171737806D8602BDE243F50012CC8BCBDC47B75F48485CC35008BA702796F88B23DF31C4E020BB28C10754C2E253C8", "hash_ssdeep": "1536:TcI7HDs/dfHDh6XcnkYXFT70JLNuuGiceY0lA3CJHkxUM:T+/dfHQXcnV+JLNNPYfSFkx1", "hash_imp": "CB0FB4D269B59D4F60F985CCD3A90C83", "hash_pesha1": "6CD2F17F074C0135C97BA645AB904CC0AB6644F2", "hash_pe256": "FFCAD6B0E8C9050CFB0B0459E3917DA82E08E41B2412636FF1495F03C824091D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TPM Initialization Wizard", "meta_original_filename": "TpmInit.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/06210a3296cfad3af92253bf998536ba1786a8799bb4cab80ccdf3dde30f0e66/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\TpmInit.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netmsg.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\TpmInit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ], "runtime_window_title": "Manage the TPM security hardware" }, "TpmTool.exe-8F62B9FD83E2B04251560B55760F32E2": { "file_name": "TpmTool.exe", "file_path": "C:\\Windows\\system32\\TpmTool.exe", "hash_md5": "8F62B9FD83E2B04251560B55760F32E2", "hash_sha1": "5FBA4F28E840166DE30B742F78152D2F4C09352A", "hash_sha256": "8B4C6FC6CF8E6F0FDF56BDEBD7601A67336DBBC085D2D8A09893A6DD78DE05CE", "hash_sha384": "705E1A3788DB487DE8FA956A3C83DBD79E86E3959BA7DF65BD6FDD614503D6E41B3B7993854F846892B6B8051363270D", "hash_sha512": "DC4A4F705BBB85423B609B0881DA66767C1370DF1B30382FB3D503806CE4B4898861AB5B795696D42201DA24151A117403C9174039A30953A1044D127193D0EE", "hash_ssdeep": "6144:GsnCbduJJtsDXN2DMc5vP4LmmILq9j4zPJjHf/2BVurHH:GHaADcDKymI+9j47JjV", "hash_imp": "C878BAE10AF943CC8CE7C40FA3C0AA35", "hash_pesha1": "DCBDC07AA5AD99FE03B16B7F782B4FCD1EB129E9", "hash_pe256": "18C6A1C8155C94906E0A71F517D1DE7359F411532E7EA18C2F4BD7651AE8C3BF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8b4c6fc6cf8e6f0fdf56bdebd7601a67336dbbc085d2d8a09893a6dd78de05ce/detection", "output": "Description:\r\n This utility can be used to get information about the Trusted Platform Module (TPM).\r\n For up-to-date documentation, please go to https://aka.ms/tpmtool\r\n\r\nSyntax:\r\n tpmtool [parameter] [<arguments>]\r\n\r\nParameters:\r\n GETDEVICEINFORMATION Displays the basic information of the TPM.\r\n\r\n GATHERLOGS [OUTPUT DIRECTORY PATH] Collects TPM logs and places them in the specified directory.\r\n If path is not specified, will default to current directory.\r\n\r\n DRIVERTRACING [START / STOP] Start / stop collecting driver traces.\r\n\r\n PARSETTCGLOGS [-VALIDATE] Displays the parsed TCG logs, and optionally validates all PCRs.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n tpmtool /?\r\n\r\n tpmtool getdeviceinformation\r\n\r\n tpmtool gatherlogs C:\\Users\\Public\r\n\r\n tpmtool drivertracing start\r\n\r\n tpmtool drivertracing stop\r\n\r\n tpmtool parsetcglogs\r\n\r\n tpmtool parsetcglogs -validate\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\TpmTool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "tpmvscmgr.exe-D922A26D46A2E2194BE6C3AF1548D0E9": { "file_name": "tpmvscmgr.exe", "file_path": "C:\\Windows\\system32\\tpmvscmgr.exe", "hash_md5": "D922A26D46A2E2194BE6C3AF1548D0E9", "hash_sha1": "D0AFD35A719DC0EFC018F2609144297473D711D3", "hash_sha256": "4363B665CB1B4B724716D7E287FE770D8C38C76AA78FA0D1CBCD1C9BC1C2B02C", "hash_sha384": "2E90C554917683CC150985A422381CA830CA4FB6A08B6CB72A8E61A8452C91599061EFBC6101B52569B2822532FC5E7E", "hash_sha512": "582D2892040C7F57DD00E14C9382CFB832CADDA8B7A6DBC5DBF02B6A2AAF2D311CBC47012369020C413F8BDB03EE7DFC7AEBC898278A973BC14D0796A22DE977", "hash_ssdeep": "1536:tgQHoHzuTzBCC72MKRoHV+UfKhMCmi9CHN+0YlcqvaDM8CEnZTzVKUl43CuA8VO:7ICXEC771LLaJvaDM8ZxVt/uA", "hash_imp": "A22C17C1D2409AECD89D89119717EDD9", "hash_pesha1": "72983869C135483D2935B8460BB529FD91C2AA6F", "hash_pe256": "914CD171E89877D4BDF66535C8DF0B276EA7E84B02A1F303498E9B4173DAF39D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TPM Virtual Smartcard Setup Utility", "meta_original_filename": "TpmVscMgr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4363b665cb1b4b724716d7e287fe770d8c38c76aa78fa0d1cbcd1c9bc1c2b02c/detection", "error": "Unknown action: /-help\r\nTpmVscMgr.exe \r\n \r\n Commands: \r\n\tcreate \r\n\t\t[/quiet] \r\n\t\t/name <name> \r\n\t\t/adminkey 'PROMPT'|'DEFAULT'|'RANDOM' \r\n\t\t[/puk 'PROMPT'|'DEFAULT'] \r\n\t\t/pin 'PROMPT'|'DEFAULT' \r\n\t\t[/generate] \r\n\t\t[/machine <machine name>] \r\n\t\t[/pinpolicy [policy options]] \r\n\t\t policy options: \r\n\t\t\tminlen <minimum PIN length> \r\n\t\t\tmaxlen <maximum PIN length> \r\n\t\t\tuppercase 'ALLOWED'|'DISALLOWED'|'REQUIRED' \r\n\t\t\tlowercase 'ALLOWED'|'DISALLOWED'|'REQUIRED' \r\n\t\t\tdigits 'ALLOWED'|'DISALLOWED'|'REQUIRED' \r\n\t\t\tspecialchars 'ALLOWED'|'DISALLOWED'|'REQUIRED' \r\n\t\t[/attestation 'AIK_AND_CERT'|'AIK_ONLY'] \r\n \r\n\tdestroy \r\n\t\t[/quiet] \r\n\t\t/instance <device instance ID> \r\n\t\t[/machine <machine name>] \r\n \r\n Legend: \r\n\t\t'PROMPT' => prompt for parameter \r\n\t\t'DEFAULT' => default value for parameter \r\n\t\t'RANDOM' => generate a random value \r\n\t\t'ALLOWED' => these characters are allowed \r\n\t\t'DISALLOWED' => these characters are not \r\n\t\t allowed \r\n\t\t'REQUIRED' => at least one such character \r\n\t\t is required \r\n\t\t'AIK_AND_CERT' => Creates an AIK and obtains\r\n\t\t an AIK certificate from the cloud CA \r\n\t\t'AIK_ONLY' => Creates an AIK but \r\n\t\t does not obtain an AIK certificate \r\n \r\n Note: \r\n\t\tThe generate command formats the TPM \r\n\t\tvirtual smart card so that it can be used \r\n\t\tto enroll for certificates. If this option \r\n\t\tis not specified, a card management \r\n\t\tsystem/tool will need to be used to format \r\n\t\tthe card before first use. \r\n \r\n Note: \r\n\t\t/pinpolicy may only be used in conjunction \r\n\t\twith /pin prompt. \r\n \r\n Note: \r\n\t\tThe default PIN policy options are as \r\n\t\tfollows: \r\n\t\t minlen 8 \r\n\t\t maxlen 127 \r\n\t\t uppercase allowed \r\n\t\t lowercase allowed \r\n\t\t digits allowed \r\n\t\t specialchars allowed \r\n\r\n\t\tThe lower and upper bounds on PIN length \r\n\t\tare 4 and 127, respectively. When using \r\n\t\t/pinpolicy, PIN characters must be \r\n\t\tprintable ASCII characters. \r\n \r\n Note: \r\n\t\tIf '/attestation AIK_AND_CERT' is specified, it\r\n\t\tis possible that VSC creation will fail if\r\n\t\tthere is no network connectivity. \r\n Examples: \r\n Create a TPM virtual smart card with default value for \r\n PIN and a random admin key with no attestation: \r\n\r\n\tTpmVscMgr create /name MyVSC /pin default /adminkey random /generate \r\n\r\n Create a TPM virtual smart card with default value for \r\n admin key and a specified PIN policy and attestation method: \r\n\r\n\tTpmVscMgr create /name MyVSC /pin prompt /pinpolicy minlen 4 maxlen 8 \r\n\t /adminkey default /attestation AIK_AND_CERT /generate \r\n\r\n Destroy a TPM virtual smart card using the instance ID \r\n that was returned when the card was created: \r\n\r\n\tTpmVscMgr destroy /instance root\\smartcardreader\\0000\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tpmvscmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "tpmvscmgrsvr.exe-80C808F7536CC0F6CEF9FA4446692DE1": { "file_name": "tpmvscmgrsvr.exe", "file_path": "C:\\Windows\\system32\\tpmvscmgrsvr.exe", "hash_md5": "80C808F7536CC0F6CEF9FA4446692DE1", "hash_sha1": "DAFF4E20F4A5702BCFC84CD092F8F7C21C453C35", "hash_sha256": "26F532C646277168A3DECD7E7D60A33276A1CF6A8DCACC35A9A8498923D50DDE", "hash_sha384": "F4F38360E6249A45BDA2B3B264C62029D3F9554120A68E67290AB619EB2A613536B0549D3A14A59CEA0D7F88B81CCAD5", "hash_sha512": "483847CC1762C42A691924BBA45BAD3D9D932D6E2D6504ED1AB3612ACE47E72E97D98FBB12962A4AB9ABA084A628F57F1B91680C6DDFCF3BF0DE56DECDD27D66", "hash_ssdeep": "3072:a1HczjfoP8RqAK2Hs6vblWiOBBlcex48hHm7:a9cPfoP9fIsAARBIeBG", "hash_imp": "D7212F3209BACBAC41D0A96B1EFD8084", "hash_pesha1": "C5BD7D18072A6566E5B604CD7228C28C13A19BC3", "hash_pe256": "FDC58A2D004FD8070091EB80CE56E1FEE5FB4976591A9147D81511C703C40B92", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TPM Virtual Smart Card Manager COM Server", "meta_original_filename": "TpmVscMgrSvr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/26f532c646277168a3decd7e7d60a33276a1cf6a8dcacc35a9a8498923d50dde/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\tpmvscmgrsvr.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\tpmvscmgrsvr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "tracerpt.exe-B28148E4DC7BD3E63DC0162EBC33685C": { "file_name": "tracerpt.exe", "file_path": "C:\\Windows\\system32\\tracerpt.exe", "hash_md5": "B28148E4DC7BD3E63DC0162EBC33685C", "hash_sha1": "FDE2AB2CFBA3D62C79B74D214C4AC9BB31BCD2B6", "hash_sha256": "2ECE870892BB1C19AE933A5411560D1FE4EB51DD6B6B510F82B05F2B1BA49851", "hash_sha384": "6ADEB283DC134165C6786FE590E4422906CCCCE4E5CE2F7B808CDB362BA481206C9B6994DB64AEC1719AEC0F71E2021B", "hash_sha512": "F2375BBECED332E1C9FBDBBD24285FE83DD1CC207CF9BF2F17E378577202D242E8D38772ED260D339B70FAF6A1C8FC2C975C6DB0E06792519ECB7FD94A636746", "hash_ssdeep": "6144:Jwtn9ITcMqHx2kPlatC20/H272230KIR2lpt8fWoF5iyOW/TqxUB:+9ITCHx2k9/UUF54k", "hash_imp": "46E5DA1ED3EC55407D760ABB247DEF1C", "hash_pesha1": "E6BB607BC46334D0783E41DBDBE9580100C3499F", "hash_pe256": "0709D6D02C89AC07E7AA57E3EA8F8FB12921EBFE1048C9165C7479D5BAD9A877", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Trace Report Tool", "meta_original_filename": "TraceRpt.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2ece870892bb1c19ae933a5411560d1fe4eb51dd6b6b510f82b05f2b1ba49851/detection", "output": "\r\nMicrosoft r TraceRpt.Exe (10.0.19041.546)\r\n\r\nUsage:\r\n C:\\Windows\\system32\\tracerpt.exe <[-l] <value [value [...]]>|-rt <session_name [session_name [...]]>> [options]\r\n\r\nOptions:\r\n -? Displays context sensitive help.\r\n -config <filename> Settings file containing command options.\r\n -y Answer yes to all questions without prompting.\r\n -f <XML|HTML> Report format.\r\n -of <CSV|EVTX|XML> Dump format, the default is XML.\r\n -en <ANSI|Unicode> Output file encoding. Only allowed with CSV\n output format.\r\n -df <filename> Microsoft specific counting/reporting schema\n file.\r\n -import <filename [filename [...]]> Event Schema import file.\r\n -int <filename> Dump interpreted event structure into\n specified file.\r\n -rts Report raw timestamp in event trace header. \n Can only be used with -o, not -report or\n -summary.\r\n -tmf <filename> Trace Message Format definition file\r\n -tp <value> TMF file search path. Multiple paths can be\n used, separated with ';'.\r\n -i <value> Specifies the provider image path. The\n matching PDB will be located in the Symbol\n Server. Multiple paths can be used, separated\n with ';'.\r\n -pdb <value> Specifies the symbol server path. Multiple\n paths can be used, separated with ';'.\r\n -gmt Convert WPP payload timestamps to GMT time\r\n -rl <value> System Report Level from 1 to 5, the default\n value is 1.\r\n -summary [filename] Summary report text file. Default is\n summary.txt.\r\n -o [filename] Text output file. Default is dumpfile.xml.\r\n -report [filename] Text output report file. Default is\n workload.xml.\r\n -lr Less restrictive; use best effort for events\n not matching event schema.\r\n -export [filename] Event Schema export file. Default is\n schema.man.\r\n [-l] <value [value [...]]> Event Trace log file to process.\r\n -rt <session_name [session_name [...]]> Real-time Event Trace Session data\n source.\r\n\r\nExamples:\r\n tracerpt logfile1.etl logfile2.etl -o logdump.xml -of XML\n tracerpt logfile.etl -o logdmp.xml -of XML -lr -summary logdmp.txt -report logrpt.xml\n tracerpt logfile1.etl logfile2.etl -o -report\n tracerpt logfile.etl counterfile.blg -report logrpt.xml -df schema.xml\n tracerpt -rt \"NT Kernel Logger\" -o logfile.csv -of CSV\n\n", "runtime_modules": [ "C:\\Windows\\system32\\tracerpt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "TRACERT.EXE-FEDBAC964787AD4898109A744FB6EC02": { "file_name": "TRACERT.EXE", "file_path": "C:\\Windows\\system32\\TRACERT.EXE", "hash_md5": "FEDBAC964787AD4898109A744FB6EC02", "hash_sha1": "1DAEA40E923EE1FD8C5832274CDD478A45685E46", "hash_sha256": "743F8E8A91B2D1E0DB9323109034DE91A1E065242A33A90BB787A63EDB860B35", "hash_sha384": "9E54E476DC22C560595DF071A8511B630C2BF1887FBD1137A8F790D01611D607F68B0E84B3046F3FE92A23CC3B411852", "hash_sha512": "A4B486F99F19914148A2D06433CFE007992096B497BFDE66EAA740308413D3F7D899CE7D75EBC392C4DE482F0B788DD081DB4E010FDE4B636894948415B31F65", "hash_ssdeep": "384:NYFTJuM9IzcKonUb4W1MAYZC7dbcpJplmmL1y9W6aW:NYFtuMMjiIbdEpQmL1i", "hash_imp": "7A80F2FE2DD40125FA241B4F53DF08D1", "hash_pesha1": "475164396A1A4B265AF9311400F15FB02C07B620", "hash_pe256": "6EC690DE44666B3F1FDE55C6A6B56E40263F90BAEE6CD437CDF58BE290F49E34", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Traceroute Command", "meta_original_filename": "tracert.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/743f8e8a91b2d1e0db9323109034de91a1e065242a33a90bb787a63edb860b35/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "output": "--help is not a valid command option.\r\n\r\nUsage: tracert [-d] [-h maximum_hops] [-j host-list] [-w timeout] \r\n [-R] [-S srcaddr] [-4] [-6] target_name\r\n\r\nOptions:\r\n -d Do not resolve addresses to hostnames.\r\n -h maximum_hops Maximum number of hops to search for target.\r\n -j host-list Loose source route along host-list (IPv4-only).\r\n -w timeout Wait timeout milliseconds for each reply.\r\n -R Trace round-trip path (IPv6-only).\r\n -S srcaddr Source address to use (IPv6-only).\r\n -4 Force using IPv4.\r\n -6 Force using IPv6.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\TRACERT.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "tscon.exe-B792676216706673B65D67916460299F": { "file_name": "tscon.exe", "file_path": "C:\\Windows\\system32\\tscon.exe", "hash_md5": "B792676216706673B65D67916460299F", "hash_sha1": "7E7351664DAEA80EFCF57C7A55E413C59BF53BA2", "hash_sha256": "15E3A70FD3F2972CD8D7826DFE4058255B0FBB974969828644D93256F7FB9C12", "hash_sha384": "314CCDEB1C5DEAF6A7338B28B1D7E5F31E3AE556C2D15968C997EC08D19CD8293276692C52B42530C56C947034FCE623", "hash_sha512": "7DF72AC370C7AAF81038C013D3A1BA0EF46A3FF9068EF0F6447B93D736E0EC5219C3F7C211C36CBF9CBACAA165860DF9013B997CD89E603B1DF0459CA4EDB17B", "hash_ssdeep": "384:OqozIUA9aekHHGaNQYlD1eotMT5geGKZ8hYP4No31Rd+3GcJycrceDowLWjdgW:OqoFAweYGaNQ+D1e1yPKZ8PCPo1/DowS", "hash_imp": "24472C36A35ED9C96546FC249317D860", "hash_pesha1": "24812B39A048CCA4458F823848E74FF61ED28AC4", "hash_pe256": "63316C1C79174F80D4D068AEF405FF131F3CDD74AE32CF3654039E27FE0CB450", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Session Connection Utility", "meta_original_filename": "tscon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/15e3a70fd3f2972cd8d7826dfe4058255b0fbb974969828644d93256f7fb9c12/detection", "output": "Attaches a user session to a remote desktop session.\r\n\r\nTSCON {sessionid | sessionname} [/DEST:sessionname]\r\n [/PASSWORD:pw | /PASSWORD:*] [/V]\r\n\r\n sessionid The ID of the session.\r\n sessionname The name of the session.\r\n /DEST:sessionname Connect the session to destination sessionname.\r\n /PASSWORD:pw Password of user owning identified session.\r\n /V Displays information about the actions performed.\r\n\r\n", "error": "Invalid parameter(s)\r\nAttaches a user session to a remote desktop session.\r\n\r\nTSCON {sessionid | sessionname} [/DEST:sessionname]\r\n [/PASSWORD:pw | /PASSWORD:*] [/V]\r\n\r\n sessionid The ID of the session.\r\n sessionname The name of the session.\r\n /DEST:sessionname Connect the session to destination sessionname.\r\n /PASSWORD:pw Password of user owning identified session.\r\n /V Displays information about the actions performed.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tscon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "tsdiscon.exe-09CEE5D093127AA9C9FF4B90F6A90581": { "file_name": "tsdiscon.exe", "file_path": "C:\\Windows\\system32\\tsdiscon.exe", "hash_md5": "09CEE5D093127AA9C9FF4B90F6A90581", "hash_sha1": "B67E776551F3A451F0D5FFBCB6C3A9F096920386", "hash_sha256": "4FA837762A3A76BCEE46F7D34F8D2E3E4EA59A0D8F9094A8CA96144E137370F9", "hash_sha384": "CA379FD997E16A67B6CA556AE019D26849DADF614E5538E20895B1067A0830AB9ABB80854385E7D542315872C3ED26C3", "hash_sha512": "42E1EE5FCFCD638E03F381FADD4E37C9A637D7F42B2156359994A126F1EB428A0BD32BC2977CB8A70865DF915F21E728D1E44DF1F95CF271AFD2ED16D5EE55A0", "hash_ssdeep": "384:n46XIz3PLC0n2q3ifiljIeUtsT5uXRZ8pB+vJIiQa1TzPPhVMcrwXWMVWW:46XYTClq3ifYjIeZURZ8pBqR5nM3", "hash_imp": "3FC6BB9BBEE32550C1847BB966FD1F6C", "hash_pesha1": "6B46C07FBDBE3CD274C7765A03DF4AB9B4C4475C", "hash_pe256": "AF9D03DB22FB767F986B5A53C273360E3DB61F1D07BE7D46B6CD03ED4BC771FB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Session Disconnection Utility", "meta_original_filename": "tsdiscon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/4fa837762a3a76bcee46f7d34f8d2e3e4ea59a0d8f9094a8ca96144e137370f9/detection", "output": "Disconnects a Remote Desktop Services session.\r\n\r\nTSDISCON [sessionid | sessionname] [/SERVER:servername] [/V] [/VM]\r\n\r\n sessionid The ID of the session.\r\n sessionname The name of the session.\r\n /SERVER:servername Specifies the Remote Desktop Session Host server (default is current).\r\n /V Displays information about the actions performed.\r\n /VM Disconnects session on server or within virtual machine. The unique ID of the session needs to be specified.\r\n\r\n", "error": "Invalid parameter(s)\r\nDisconnects a Remote Desktop Services session.\r\n\r\nTSDISCON [sessionid | sessionname] [/SERVER:servername] [/V] [/VM]\r\n\r\n sessionid The ID of the session.\r\n sessionname The name of the session.\r\n /SERVER:servername Specifies the Remote Desktop Session Host server (default is current).\r\n /V Displays information about the actions performed.\r\n /VM Disconnects session on server or within virtual machine. The unique ID of the session needs to be specified.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tsdiscon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "tskill.exe-2393D4F762FB671D92A59388109C24D4": { "file_name": "tskill.exe", "file_path": "C:\\Windows\\system32\\tskill.exe", "hash_md5": "2393D4F762FB671D92A59388109C24D4", "hash_sha1": "2E27346B7CFF97619923C3E3199E68E7B91D142B", "hash_sha256": "8D9373EBD69F42153B0B47DBDA2174811599DB91630651CA01627AC1795F8D56", "hash_sha384": "11EA7C57DEE31D5E8F16B92DECAE49DBF05CD925C6A48E0B3F21E4794541CF48D0E573A72C64AE525A739D2CFA0B3FDC", "hash_sha512": "9EAA9CD2813F8864244547FBC81BA6759F63E32F73ED2394DFA311FF60A9727E47DBDCF42D1AAFB5E6C5A40A43A83AE32F5FA443083319F5B6B1E73457C59758", "hash_ssdeep": "768:+IPzZhZGDotUMCZvNvNZ8LYIPxCHxCH9kG:+IjEVdJ6YIwYGG", "hash_imp": "0568AF4DCDD3B8A976BBBBC1530C6847", "hash_pesha1": "FF78CF970784C966AB172C14A049A81DDB745490", "hash_pe256": "9E3FCE0B4154C5F94855B65FB926B6F19C96339DF235F2F1DC0B5A9A801EC0C4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Services End Process Utility", "meta_original_filename": "tskill.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8d9373ebd69f42153b0b47dbda2174811599db91630651ca01627ac1795f8d56/detection", "error": "Invalid parameter(s)\r\nEnds a process.\r\n\r\nTSKILL processid | processname [/SERVER:servername] [/ID:sessionid | /A] [/V]\r\n\r\n processid Process ID for the process to be terminated.\r\n processname Process name to be terminated.\r\n /SERVER:servername Server containing processID (default is current).\r\n /ID or /A must be specified when using processname\r\n and /SERVER\r\n /ID:sessionid End process running under the specified session.\r\n /A End process running under ALL sessions.\r\n /V Display information about actions being performed.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tskill.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "TSTheme.exe-C0AB057D87EB804E79F3540F0AC1AC37": { "file_name": "TSTheme.exe", "file_path": "C:\\Windows\\system32\\TSTheme.exe", "hash_md5": "C0AB057D87EB804E79F3540F0AC1AC37", "hash_sha1": "1E1EC63ED702B6BB96DE0A99C793103B4CA96129", "hash_sha256": "31114F153F14D9AABD425D75A0F3F87D68A3A4C30E6185D9C040B86AE6470CEE", "hash_sha384": "7174073AF10D2DCEE152459BE41C7274D065F4154273F92E45A305786B8488F11E3443D4E954CD18B5396F3E8C354B91", "hash_sha512": "76C7EAAD1A3F5DDA5F2F037C7AEFCB560BE063A77CD925B61F124D5B4401283FD345F0037A396642CF7D6CAF8BBF2D4D2693A2D9D36EF31D9308268181997F09", "hash_ssdeep": "1536:V6TIIfttRqCLNvA3glLTsRe774HrPU8wIBS0s+rPjundilyq//v2:4sWD36YTUe774HrM8JBA+DjudicI/+", "hash_imp": "C12F529C6B4328A6103FC0A0C6285568", "hash_pesha1": "45080E43D23C13B9202A239E666AA620C8FC03E1", "hash_pe256": "DE422F6B69C692D2075DA996C0510C87BEEA442279AAD3246F5B74120CCA7D29", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TSTheme Server Module", "meta_original_filename": "TSThemeS.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/31114f153f14d9aabd425d75a0f3f87d68a3a4c30e6185d9c040b86ae6470cee/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\TSTheme.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\TSTheme.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "TSWbPrxy.exe-BC37BFB826A35B981AFF6DA51248765D": { "file_name": "TSWbPrxy.exe", "file_path": "C:\\Windows\\system32\\TSWbPrxy.exe", "hash_md5": "BC37BFB826A35B981AFF6DA51248765D", "hash_sha1": "7D63053B1F94248A4FBE905208AA9B83F4883193", "hash_sha256": "A0D6F924564F662D584D3C24C4EB50EA8607B8F8D8816550AAD3ECDD87DBE34D", "hash_sha384": "830B5679898D4D45242C6B864F4ECF52FD46A4252578B411E5FF18320E254179DD1A22111143A77BD6363C384BE710BA", "hash_sha512": "FF56159F87CC1FD3A520111349E6DEDA97803A6EE1987287388773FAF5F30064624DD8A2D48411449AC64B53C4020416D112E20E36D8F409273EA9C45EF49C52", "hash_ssdeep": "1536:vQjKKc/Fd7yXLc8jgey3pWVPoUjN9/1U95hLlNQmjKmqt+kbZhpC36UOnUA7sawr:oWhTyJjgTQVPoUjN9/1U95hLlXjK9+k2", "hash_imp": "632C4BFEAE990ABC068E4E9436B9396B", "hash_pesha1": "75F5A011B61E9E85FE4EE95566B3F7445F6DBAA7", "hash_pe256": "CC6C0C2C8FAB4886735716170E03A1415089401E2F4F03E0B095F05CBCF728D3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Remote Desktop Services Web Proxy", "meta_original_filename": "TSWbPrxy.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a0d6f924564f662d584d3c24c4eb50ea8607b8f8d8816550aad3ecdd87dbe34d/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\TSWbPrxy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "ttdinject.exe-B1116E05A2AEDA8E95F89E74C1525A6C": { "file_name": "ttdinject.exe", "file_path": "C:\\Windows\\system32\\ttdinject.exe", "hash_md5": "B1116E05A2AEDA8E95F89E74C1525A6C", "hash_sha1": "7685045CCD89E21943330C049A84E6F0184104BE", "hash_sha256": "1CDF9D33B2C92A212C8A297802178127F354131D6D05641B6FDB6C52AFF5FDE3", "hash_sha384": "AA77A344AC61C3922C5FDB57468773EA5FFFDED6BA634923BC92535435E02E2AFB07C6EB34828671F5AF21AF49AC19F0", "hash_sha512": "37E875A1E35E89D4D1675C724B29E19BBF4A91E4E512952CE792F6BC040E8806544EC67B413024A9955453B80F76458367D545AA7E910DD99D001151329E6B63", "hash_ssdeep": "3072:r77GakXf+WXf4Zd6/7e2wyctvtOisrGr7xpKQi23rX8LcC/1IrM72tZzPaLArd5n:faHf4ZdMJisrE7XLPiUZzA2dwbDHu", "hash_imp": "B0F85C22544E7D82BA1D1F5B11B27088", "hash_pesha1": "32693F44C6BA3B996182D90B4924DF13336B0527", "hash_pe256": "53D223A5323908F5BCAC0DFB29134778341BF9CD75311491D4BB1438FCF6C9B5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Time Traver Debugging Application Injector", "meta_original_filename": "TTDInject.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/1cdf9d33b2c92a212c8a297802178127f354131d6d05641b6fdb6c52aff5fde3/detection", "output": "Microsoft (R) TTDInject Launcher 1.01.06\r\nRelease: 10.0.19041.1\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n", "error": "\b\b\b!!! Unexpected string 'help' after 'C:\\Windows\\system32\\ttdinject.exe'\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\ttdinject.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "tttracer.exe-61C47B71A25302934A8CFB16E3B4DBD9": { "file_name": "tttracer.exe", "file_path": "C:\\Windows\\system32\\tttracer.exe", "hash_md5": "61C47B71A25302934A8CFB16E3B4DBD9", "hash_sha1": "FCC75A413069B1579868FB0026099FAA5BE358C3", "hash_sha256": "B2A6E526499F552C2C9AE920DD7B6722B0D49B862950B5740033A8764F66E9D2", "hash_sha384": "523DC88B240766DFA2114189737C690FBD6FFF848B628CB1F7455DF886FE2D21764C903A480CA479F317E7B534B00078", "hash_sha512": "13A5B22762D47D08CC76E556AC30C6FC2EFB7744EB94487EC27D7195F3CFAB33A1D0C48DF005236BD7A3B84255B7B379A91B6B3343276ACF4DFB980F9814EB7A", "hash_ssdeep": "1536:GF3vbRpaTi07EMKW4OFgu24sDRccRXP0VOESXthksJczJe8s4TIePPMuJ:EjkR4MKuFgu2Pfh0VtSX7ksJkTNxJ", "hash_imp": "2747C011A492A08D7DAFC885F1D691EA", "hash_pesha1": "3E11C38562F6B373DDF22BE98F2469848DF49627", "hash_pe256": "0D4918D185DF2517DE119A3320DA174566C4218796C515879D836FAD2FC40B8A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Time Travel Debugging Tracer Tool", "meta_original_filename": "TTTracer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b2a6e526499f552c2c9ae920dd7b6722b0d49b862950b5740033a8764f66e9d2/detection", "output": "MICROSOFT TIME TRAVEL DEBUGGING (TTD)\r\r\n\r\r\nTime Travel Debugging (TTD) command line utility is not meant for use in custom software or\r\r\nautomation. TTD is included with this version of Windows to improve diagnostics gathering and is not\r\r\nintended for direct use as a stand-alone solution.\r\r\n\r\r\nDISCLAIMER OF WARRANTY. THE SOFTWARE IS LICENSED \"AS IS.\" YOU BEAR THE RISK OF USING IT. MICROSOFT\r\r\nGIVES NO EXPRESS WARRANTIES, GUARANTEES, OR CONDITIONS. TO THE EXTENT PERMITTED UNDER APPLICABLE LAWS,\r\r\nMICROSOFT EXCLUDES ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE,\r\r\nAND NON-INFRINGEMENT.\r\r\n\r\r\n1. DATA COLLECTION. The software may collect information about you and your use of the software and send\r\r\n that to Microsoft. Microsoft may use this information to provide services and improve Microsoft's\r\r\n products and services. Your opt-out rights, if any, are described in the product documentation. Some\r\r\n features in the software may enable collection of data from users of your applications that access or\r\r\n use the software. If you use these features to enable data collection in your applications, you must\r\r\n comply with applicable law, including getting any required user consent, and maintain a prominent\r\r\n privacy policy that accurately informs users about how you use, collect, and share their data. You can\r\r\n learn more about Microsoft's data collection and use in the product documentation and the Microsoft\r\r\n Privacy Statement at https://go.microsoft.com/fwlink/?LinkId=521839. You agree to comply with all\r\r\n applicable provisions of the Microsoft Privacy Statement.\r\r\n\r\r\n2. SCOPE OF LICENSE. The software is licensed, not sold. Microsoft reserves all other rights. Unless\r\r\n applicable law gives you more rights despite this limitation, you will not (and have no right to):\r\r\n a) work around any technical limitations in the software that only allow you to use it in certain ways;\r\r\n b) reverse engineer, decompile or disassemble the software;\r\r\n c) remove, minimize, block, or modify any notices of Microsoft or its suppliers in the software;\r\r\n d) use the software for commercial, non-profit, or revenue-generating activities;\r\r\n e) use the software in any way that is against the law or to create or propagate malware; or\r\r\n f) share, publish, distribute, or lend the software, provide the software as a stand-alone hosted\r\r\n solution for others to use, or transfer the software or this agreement to any third party.\r\r\n\r\r\n3. SUPPORT SERVICES. Microsoft is not obligated under this agreement to provide any support services\r\r\n for the software. Any support provided is \"as is\", \"with all faults\", and without warranty of any kind.\r\r\n\r\n", "error": "Error: Unrecognized command line option '--help' (Error Code 0x80070057: The parameter is incorrect.)\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tttracer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "typeperf.exe-EDC83F2D9E0F3906EEFF6C5056EBECA6": { "file_name": "typeperf.exe", "file_path": "C:\\Windows\\system32\\typeperf.exe", "hash_md5": "EDC83F2D9E0F3906EEFF6C5056EBECA6", "hash_sha1": "3C3BD1889D01EE717B15AF7100BF1897BEABDA49", "hash_sha256": "D036BCD15FB7054AA1951BD72C776E3BA089C3E6AB5020A850A1B52ED0ED2F08", "hash_sha384": "A68BF9CC6AA7A80AB3DD4DF82D859E9E73E8F9A5BA5EF57E06E4E6755523DA08474AC84FD63D6019FAFE8D0C2FC34162", "hash_sha512": "A09BBCBDEB878077F05599558EBBC3211F35357C28984C2DE6840A51B1B10ECDD1DB97E6BCE29EA79DD00CEB8C92F26214D478FD7D4255531633F635C7171C5B", "hash_ssdeep": "1536:xfBr4KmhY50dwFscTswUGt00vw42wuLmCMa4NwK2:0k0uFLAituLmCMaiY", "hash_imp": "6C6EF5458AE158C242617DDB457DC4C9", "hash_pesha1": "B97A6EA30A92B7244BBD4C8857A0F6494543157B", "hash_pe256": "ED39898A1AC996C58866794132E04CC4FF1388BEC2073B85199ABCBB2924CF44", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command line performance monitor", "meta_original_filename": "TypePerf.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d036bcd15fb7054aa1951bd72c776e3ba089c3e6ab5020a850a1b52ed0ed2f08/detection", "output": "\r\nMicrosoft r TypePerf.exe (10.0.19041.546)\r\n\r\nTypeperf writes performance data to the command window or to a log file. To\r\nstop Typeperf, press CTRL+C.\r\n\r\nUsage:\r\nC:\\Windows\\system32\\typeperf.exe { <counter [counter ...]> \r\n | -cf <filename> \r\n | -q [object] \r\n | -qx [object] \r\n } [options]\r\n\r\nParameters:\r\n <counter [counter ...]> Performance counters to monitor.\r\n\nOptions:\r\n -? Displays context sensitive help.\r\n -f <CSV|TSV|BIN|SQL> Output file format. Default is CSV.\r\n -cf <filename> File containing performance counters to\r\n monitor, one per line.\r\n -si <[[hh:]mm:]ss> Time between samples. Default is 1 second.\r\n -o <filename> Path of output file or SQL database. Default\r\n is STDOUT.\r\n -q [object] List installed counters (no instances). To\r\n list counters for one object, include the\r\n object name, such as Processor.\r\n -qx [object] List installed counters with instances. To\r\n list counters for one object, include the\r\n object name, such as Processor.\r\n -sc <samples> Number of samples to collect. Default is to\r\n sample until CTRL+C.\r\n -config <filename> Settings file containing command options.\r\n -s <computer_name> Server to monitor if no server is specified\r\n in the counter path.\r\n -y Answer yes to all questions without prompting.\r\n\r\nNote:\r\n Counter is the full name of a performance counter in\r\n \"\\\\<Computer>\\<Object>(<Instance>)\\<Counter>\" format,\r\n such as \"\\\\Server1\\Processor(0)\\% User Time\".\r\n\r\nExamples:\r\n typeperf \"\\Processor(_Total)\\% Processor Time\"\r\n typeperf -cf counters.txt -si 5 -sc 50 -f TSV -o domain2.tsv\r\n typeperf -qx PhysicalDisk -o counters.txt\r\n", "runtime_modules": [ "C:\\Windows\\system32\\typeperf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "tzsync.exe-433D943CE267EAA3485137E0D21A7348": { "file_name": "tzsync.exe", "file_path": "C:\\Windows\\system32\\tzsync.exe", "hash_md5": "433D943CE267EAA3485137E0D21A7348", "hash_sha1": "0FFBAE84AFADF220CD379BC823F0BA7E95E50EA5", "hash_sha256": "3C4DE3F013D4611BBDB14EA17207E4D93EB406E14E639B1D87CE217C96747CF2", "hash_sha384": "22131FC7EA40FB5F489E1DBD8BB22D759468CCCF2F80F433145CC31455C9BECFB245343B0797E3ABE41AA9B7D794195B", "hash_sha512": "E91BCC1555EBC0F3866CB81F93D65F1672818940E89972A1B76EBBDC1E5B0976854301244F3C95761C16C986D4B7154A278453F90501D9698030447A971F4450", "hash_ssdeep": "1536:iSofGQ6bS1v1XQEqsGIa0ZuJXwECJlDsS37eX/z7:6YOiuuD+evP", "hash_imp": "n/a", "hash_pesha1": "819D1279226913E5BF6A1F0FDE185AFC53EAEF20", "hash_pe256": "096BAE6271A0237297D43B8795DE6ABD3080E139329D447E82495B44A773843C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TimeZone Sync Task", "meta_original_filename": "tzsync.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3c4de3f013d4611bbdb14ea17207e4d93eb406e14e639b1d87ce217c96747cf2/detection", "runtime_modules": [ "C:\\Windows\\system32\\tzsync.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "tzutil.exe-D707382B7D60EB8830A2DA9D6480062A": { "file_name": "tzutil.exe", "file_path": "C:\\Windows\\system32\\tzutil.exe", "hash_md5": "D707382B7D60EB8830A2DA9D6480062A", "hash_sha1": "4C721616200B2CD92D7716981999D94F549732A8", "hash_sha256": "BF331CDF306FE1D01A5B4B81B898A268D0D1C8461C4AEDA19D5C67F5FAD981B1", "hash_sha384": "416AE7EB5677B7760067892AC4019ADFEC6B26A49FCD57F70667B606A8E2D26DC19F6A28D5EDBC533AF8D54F2510254E", "hash_sha512": "3341C6AE65C4604792ED64900BB4E7E713E60148ECB9AAB88C0108F1E6C21AF2311289137C2D5D6F32A1CDDF3157E8B52FDE55FB607719D0D47F64B1A77F2D51", "hash_ssdeep": "768:r4gjGXBwJDkHlyVm9h8oxpIHskL9sl7R8FNjprT3lxyVO1VTO+Uvxxi8oOWx:kgjG2JDkQYbBpyskLSKBHuiE5oOWx", "hash_imp": "B4940EAAD48DE4C33FFFA56E15249A7A", "hash_pesha1": "C30C6920FD54287234AE20051EF4752F17E0F38F", "hash_pe256": "43F52E3DED69A9053B30359DA961E55A42CFEAB492DDA173D935A800BD7B8FFE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Time Zone Utility", "meta_original_filename": "tzutil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/bf331cdf306fe1d01a5b4b81b898a268d0d1c8461c4aeda19d5c67f5fad981b1/detection", "output": "Windows Time Zone Utility\r\n\r\nUsage:\r\nTZUTIL </? | /g | /s TimeZoneID[_dstoff] | /l>\r\n\r\nParameters:\r\n /? Displays usage information.\r\n\r\n /g Displays the current time zone ID.\r\n\r\n /s TimeZoneID[_dstoff]\r\n Sets the current time zone using the specified time zone ID.\r\n The _dstoff suffix disables Daylight Saving Time adjustments\r\n for the time zone (where applicable).\r\n\r\n /l Lists all valid time zone IDs and display names. The output will\r\n be: \r\n <display name>\r\n <time zone ID>\r\n\r\nExamples:\r\n TZUTIL /g\r\n TZUTIL /s \"Pacific Standard Time\"\r\n TZUTIL /s \"Pacific Standard Time_dstoff\"\r\n\r\nRemarks:\r\n An exit code of 0 indicates the command completed successfully.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tzutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ucsvc.exe-909E5A293A94055D67AF53A7EDF27D27": { "file_name": "ucsvc.exe", "file_path": "C:\\Windows\\system32\\ucsvc.exe", "hash_md5": "909E5A293A94055D67AF53A7EDF27D27", "hash_sha1": "B04D2E846EF7CC1D8D224F07D2F8D7BAE7F2BF6E", "hash_sha256": "2BFAC411F014D87171CF09B110EC44436F4A0850B8B2CC3A4F72E7412F7A9D39", "hash_sha384": "F943A5C14E251CA0FF24530FCFDC6BB7F297746616EDF0A5B66889410452AFC44BC8D4F7E9B18AEF63552776CC2F67BC", "hash_sha512": "33855BEB5BF9A23C2ED2B6C58C6F52E8EC0EB2E5CAC558FD2EA33E5FFE78D021397A055D72739D4374592C15EACAC3E1BBA6DAFDAF36044409CFEB9FCF361455", "hash_ssdeep": "768:UxjRyM/jOSSwjaV7/hgRHMNM07mqEBNhkW8RYBQOL9czpoJI1PQdOY:UBRtOiIpOr07mqAaPR2L+NoePQQY", "hash_imp": "0E0328595A346203B68DE1869CCFF8C2", "hash_pesha1": "B5078D3E8674326EAD5331B9F398D0D579EFE7E8", "hash_pe256": "9BEDFEAD1AA98C577DD9CD1216ACD923FD8E7DA31E690728074B90FC266645E6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Boot File Servicing Utility", "meta_original_filename": "bfsvc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2bfac411f014d87171cf09b110ec44436f4a0850b8b2cc3a4f72e7412f7a9d39/detection", "runtime_modules": [ "C:\\Windows\\system32\\ucsvc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "UevAgentPolicyGenerator.exe-C048906265AB5C4EA7118084A1E316CF": { "file_name": "UevAgentPolicyGenerator.exe", "file_path": "C:\\Windows\\system32\\UevAgentPolicyGenerator.exe", "hash_md5": "C048906265AB5C4EA7118084A1E316CF", "hash_sha1": "73FEB9C5E827548E309DC69A14E833F7F13F2EF1", "hash_sha256": "C43CD630EE07A72181E255EBFF2BD63F7479622D8F895249614DE94A8611B3F8", "hash_sha384": "EA8A396373E6E8BA664ED0A73B1FCA145BFED1D9B4A6FDE493CCD3B493D1791B90C424A25E5B13FB72CA406FC777B975", "hash_sha512": "72A4A2FA3444F4B7A8F02BCC2FCE2D820743A44AB7F2C88AE7F58BAD135A378700514F5F64C8E28482655BF2D7E30A80F471D908721567BFAFD80F719D950A67", "hash_ssdeep": "384:kZm0fhsl8PKzKq06MUt3jt/KJSaI3DDvQS114fOmDH1J/8rfZuKRSfDOya2VFkmB:kkllzqD2ZRP2VFk8vnjHn6tPC9", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "00BDC3C0952893BB6503EB2E6D28D056E8B99A7B", "hash_pe256": "94877114A0EC2DA6A886F0591070809BCD5871BB550EF8D55D985DFBC293024E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "UevAgentPolicyGenerator.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/c43cd630ee07a72181e255ebff2bd63f7479622d8f895249614de94a8611b3f8/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\UevAgentPolicyGenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "UevAgentPolicyGenerator.exe - This application could not be started." }, "UevAppMonitor.exe-B54F6F7A63A0E20DE1A80D1C8AAA2882": { "file_name": "UevAppMonitor.exe", "file_path": "C:\\Windows\\system32\\UevAppMonitor.exe", "hash_md5": "B54F6F7A63A0E20DE1A80D1C8AAA2882", "hash_sha1": "87219685412BD05E56DAE1162108087872DB5357", "hash_sha256": "0BE7F413037A2192E3361954867B09DE0568FF53A938F73DD8BA1BDCE05C7002", "hash_sha384": "41B1DE37E41DF4CDFC3791CE8EFA73A904F98F318A3AA99060AF660F665F32E1C735B3BE220E87A9E3DECDA06A984FC4", "hash_sha512": "908FD0444E43438AD563AED947302A8F3AE4F6AB35B115137D137F27DB932AC2B5F21658C1E04297A5A4347029B23A0645B37B87B8687A4B9D7F92BFF38B34B3", "hash_ssdeep": "768:vN0yKm62+wU+Aa91slxN+u996swwiKEtycTY5lkQ7Vy9ylDX7:LK/A91szN++6NwiKE10DjlP", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "5BF8191ADB1ADAFC20AC427E44D21E17F6F05A97", "hash_pe256": "642C83D2A017868169A67D4E1ABE6EEAABFC1149E0D7CF46FAFC23DAAF13C65C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "UevAppMonitor.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0be7f413037a2192e3361954867b09de0568ff53a938f73dd8ba1bdce05c7002/detection", "children": "powershell.exe", "runtime_modules": [ "C:\\Windows\\system32\\UevAppMonitor.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "UevTemplateBaselineGenerator.exe-C85A5D2C00FF444E9E7D3E31977234AE": { "file_name": "UevTemplateBaselineGenerator.exe", "file_path": "C:\\Windows\\system32\\UevTemplateBaselineGenerator.exe", "hash_md5": "C85A5D2C00FF444E9E7D3E31977234AE", "hash_sha1": "A773267945FB049F756A0133335C454FCE18C380", "hash_sha256": "303BE386109BD9CF507B72F467AE9DDB22AE1B85FD05423DAFC9385624EB1053", "hash_sha384": "B9A381BC32DF7DAEC1C2CB0855D282774100F8052D4D8D8CA937323098D8A75CCE0412B0D482959B911B8D3FF626C4C0", "hash_sha512": "38CCE8A3702C87A99FF21D3176089A642DCC037889AC2C754666AF3BBE3FDA83CB06C4BD4741466D1D4574DF09D9464328D7390E85F42E71345706E578DD53BB", "hash_ssdeep": "384:OwL8CUA6oNTSAkBcYKPdIQX6GIp056PMSK++WTJW9Z:Z4CbTSviBqYe+", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "66EA67C2A5A1AA5A2B48243BE26906B575E5D3E2", "hash_pe256": "215D588F8C290FCE2BB56F2C5980B0D97A2E3C3DEDD35CAB88C910EAAC960F57", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "UevTemplateBaselineGenerator.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/303be386109bd9cf507b72f467ae9ddb22ae1b85fd05423dafc9385624eb1053/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\UevTemplateBaselineGenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "UevTemplateBaselineGenerator.exe - This application could not be started." }, "UevTemplateConfigItemGenerator.exe-57C26AF3682374941B185A50C4DBFA8A": { "file_name": "UevTemplateConfigItemGenerator.exe", "file_path": "C:\\Windows\\system32\\UevTemplateConfigItemGenerator.exe", "hash_md5": "57C26AF3682374941B185A50C4DBFA8A", "hash_sha1": "E033B9E3A1208F72D47331ECA3D2BBB7E3F264AB", "hash_sha256": "ED370E58E64E68C3DBDE73CFAD811D35048452688A7001A202C1C1CD630A5B29", "hash_sha384": "9373C9D64F8AA7A94C533D4E3C7B6569282113450B6AAF9359D99BA88BCBB506DA466B11BABF6B75E9BF2C10FBAAE819", "hash_sha512": "70FE75577F552E69BA69517ADA7E0C7B1C620816DB0A25D3D2D8337239FC9E45666462946E842A12C9B24DEBD1EF2572317A4B110EAE039ACFF63F1DA6D7F5A1", "hash_ssdeep": "192:Lq0JHU41GGkZ1ElGTubagmrCdsa/2pEu0rqWp8eMPOHnQW3FW/zv:20pU4G1MCIbmOdsa/2pPWp8eqW3FW/L", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "AAAA7525B0E9844BE23EF58CBF09D102C34C2E20", "hash_pe256": "33BDCC879FC3CBFD0EE55E56D9BF23119C508AAB60087667445F25674080D488", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "UevTemplateConfigItemGenerator.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ed370e58e64e68c3dbde73cfad811d35048452688a7001a202c1c1cd630a5b29/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\UevTemplateConfigItemGenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "UevTemplateConfigItemGenerator.exe - This application could not be started." }, "UIMgrBroker.exe-E4F4D53813A3EA93431BEC0ABC43F187": { "file_name": "UIMgrBroker.exe", "file_path": "C:\\Windows\\system32\\UIMgrBroker.exe", "hash_md5": "E4F4D53813A3EA93431BEC0ABC43F187", "hash_sha1": "65557469B8412D361BBD74088FD8636C95217160", "hash_sha256": "B8D7A7F2E5A27AF2B36C3E7DB27AC39C378B197FEB2AFD590BC1FD2088BCC241", "hash_sha384": "44802521BDDAD20A9003BA6C0E8BF2E3A75942C3A1D18098F5287FE5D5954FE880A5D72D81B7B50E3BA9AB7A3297040D", "hash_sha512": "13769A75938DE87CDE4BFE7E703B35BED3506C7BAC21F86993B617ABB743127B77FCA356999A97AE7F19A180FA068CA4493AE6210B56804C92B643B3BEC4EDB1", "hash_ssdeep": "768:ps727bWSEAvQyTUfqU3F6yk4kKZB4IWXP1pIllNWk0uAFkQKPhBAE:aqEAvQxqpmj/4Rp6lNWHuA6VPhBAE", "hash_imp": "68B9DCA137FA8179CE80445E610B5C16", "hash_pesha1": "D0C0314908BBD1A981C723726CB6247558CED804", "hash_pe256": "0E21B7EA84796725B7AF72DA9921105A517725E21F690262A19E755F82E12D6E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft UIManager Broker", "meta_original_filename": "UIMgrBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.388 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.388", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b8d7a7f2e5a27af2b36c3e7db27ac39c378b197feb2afd590bc1fd2088bcc241/detection", "runtime_modules": [ "C:\\Windows\\system32\\UIMgrBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\SHELL32.dll" ] }, "unlodctr.exe-789736A4A47609C77DF65E2D0F7BC61B": { "file_name": "unlodctr.exe", "file_path": "C:\\Windows\\system32\\unlodctr.exe", "hash_md5": "789736A4A47609C77DF65E2D0F7BC61B", "hash_sha1": "7879DE7ABFBACE22C691F7C05C21A9518C28DDEF", "hash_sha256": "E8EEAC85A29EB75A4CF41509EA982AE1B6256D0C7CDFF3299ED3DF3CE34356D9", "hash_sha384": "3D7CA89804A9A75FC54F18C362E3426BFC58CE6462CEE8ED7BDAE82BD454991BDEFCE59ED166226289A13204D2A10A2C", "hash_sha512": "35FF07C6038C74399176454416118853B48257BF003646E91C10F4D59DE31D4BB5BC502F5D2701C3E8576CB750530D2825C1688DD3C2B59C80BEDFAB5266758C", "hash_ssdeep": "768:Urp1PX8kHsc3L2CK7JhIlqyTDwI+pXn7M9DdRMTdplMcAujMFwf/wEdk:81PXtHZlqy4IMXn49DdRMTTlMcrCwf4x", "hash_imp": "F1D5D1A81E34EB75E2AF99A4FB939D87", "hash_pesha1": "6A9664A1C14EAD8825F1190C0399D76835956390", "hash_pe256": "C2AD349F097C56B509D21AB502FDD8100CA627ED25A8FBC06F8A0E830243F59C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Unload PerfMon Counters", "meta_original_filename": "UNLODCTR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/e8eeac85a29eb75a4cf41509ea982ae1b6256d0c7cdff3299ed3df3ce34356d9/detection", "output": "\r\n \r\nUNLODCTR \r\n uninstalls a performance counter provider. \r\nUsage: \r\n UNLODCTR <service-name> \r\n uninstalls the v1.0 performance counter provider associated \r\n with the <service-name> service.\r\n UNLODCTR /m:<manifest> \r\n uninstall a v2.0 performance counter provider using the \r\n provider GUID from the specified XML manifest.\r\n UNLODCTR /g:{ProviderGuid} \r\n uninstall a v2.0 performance counter provider using the \r\n specified provider GUID. The GUID should be specified in \r\n registry form, i.e. {nnnnnnnn-nnnn...}\r\n UNLODCTR /p:<ProviderName> \r\n uninstall a v2.0 performance counter provider matching the \r\n specified provider name.\r\n\r\nNote: any arguments with spaces in the names must be enclosed within double \r\nquotation marks.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\unlodctr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "unregmp2.exe-A6FC8CE566DEC7C5873CB9D02D7B874E": { "file_name": "unregmp2.exe", "file_path": "C:\\Windows\\system32\\unregmp2.exe", "hash_md5": "A6FC8CE566DEC7C5873CB9D02D7B874E", "hash_sha1": "A30040967F75DF85A1E3927BDCE159B102011A61", "hash_sha256": "21F41FEA24DDDC8A32F902AF7B0387A53A745013429D8FD3F5FA6916EADC839D", "hash_sha384": "EC1861BD4A4AC734CA4B5146A5D3E9B6BC01C6CA4E199E8AC924AA0CF3DD9D2A7AEB039F4BC7BBA5C8E990CEEDC7CCE0", "hash_sha512": "F83E17DD305EB1BC24CCA1F197E2440F9B501EAFB9C9D44EDE7C88B1520030A87D059BDCB8EADEAC1EAEDABCBC4FE50206821965D73F0F6671E27EDD55C01CBC", "hash_ssdeep": "3072:/m433KYPAtk2IX6T3jSoMR6JpQBvAwk4OBpqkmaHmI:/p3aYFJ6y7RwpdpqEH", "hash_imp": "1DE1DA351E000239456F4F921473BDC8", "hash_pesha1": "9CE4EF41248EBACD3A2A14511B995960178295A8", "hash_pe256": "36C1E12FE484CE7239D8A4B374542F52A10A27E5353D4DD037519EE685391EB7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Media Player Setup Utility", "meta_original_filename": "unregmp2.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/21f41fea24dddc8a32f902af7b0387a53a745013429d8fd3f5fa6916eadc839d/detection", "runtime_modules": [ "C:\\Windows\\system32\\unregmp2.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\VERSION.dll" ] }, "upfc.exe-299EA296575CCB9D2C1A779062535D5C": { "file_name": "upfc.exe", "file_path": "C:\\Windows\\system32\\upfc.exe", "hash_md5": "299EA296575CCB9D2C1A779062535D5C", "hash_sha1": "2497169C13B0BA46A6BE8A1FE493B250094079B7", "hash_sha256": "EE44FE14DF89C4E5EAF8398F8FB4823FD910C5A94D913653D6B9E831254F6CC2", "hash_sha384": "DF31B2090978D9A10C0483902A94F6546BB938D54A3AA10F7D9AAFF7CB4661B669E124FEBE7DA9B3B202FF769C861565", "hash_sha512": "02FC2B25167EBD7DFCC7B8AA74613E7004FDF33DFCCCCBA6C3427434CCA981C2EB50F4A801969B3A40C495A9BB0EAC8176F4F2EC9091916CF3509A7F909B30FA", "hash_ssdeep": "1536:0sV1GX6P47JxjWuNbQiun8PNO2zwI6guA78E8DdassZ7jyjbkVNLP+u66fvc+PPw:/V1GqPWxjWuKiYXdunyvkDzx66fvhP4", "hash_imp": "49394AADDEF3EB66CCAB094EE1702917", "hash_pesha1": "DA90D63E9EEF162627100E9560F62202EEC181A4", "hash_pe256": "9A24F664541C0222E9A49F70D5DB0A16444CCEADA59E30EA1BE96B8D11FFD2B9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Updateability From SCM", "meta_original_filename": "upfc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ee44fe14df89c4e5eaf8398f8fb4823fd910c5a94d913653d6b9e831254f6cc2/detection", "runtime_modules": [ "C:\\Windows\\system32\\upfc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll" ] }, "UpgradeResultsUI.exe-2EA6649DB74775305468181AB2182B31": { "file_name": "UpgradeResultsUI.exe", "file_path": "C:\\Windows\\system32\\UpgradeResultsUI.exe", "hash_md5": "2EA6649DB74775305468181AB2182B31", "hash_sha1": "2C67A23368C53A9FB043FBF399AA777267AF35E9", "hash_sha256": "E0BACF2FE7FF684FA46CA255D4EBA2F25E290AF4837C1652BD315424B50F9A74", "hash_sha384": "7C3DB1D24F6DA1A1BC0DB00CEDB01BBC01AE211EB60212221134B5DE651A0869ACFEC44266F66F62968F4CF73C63809E", "hash_sha512": "C8927828DE5796B7390FF8B059741CFF67A59C34A22BD602D5D191E28BA7B6B546201E30B704C1EAAF89AAB27CE4C25F4F9C02A1B6EA93E9F02194AA04704FD3", "hash_ssdeep": "768:jk6JudvwLDubOqbJcTMkYoKxuKtcF8ewGJHXXbWr4FBURvPNbA7ZEAnTdfvRS:jksBubHsMkHKQKtyIGJHbWrxxAtEUTFI", "hash_imp": "56DE186C5EFDCC074128270182A83C83", "hash_pesha1": "38BDFEFDC9DD488BB0AF828C0F10D35EB17AC4A9", "hash_pe256": "F59F27CC9C7F233B24084879C03994EFFC9536095062CC93684621721F4840A6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Add features to Windows Results", "meta_original_filename": "UpgradeResultsUI.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e0bacf2fe7ff684fa46ca255d4eba2f25e290af4837c1652bd315424b50f9a74/detection", "runtime_modules": [ "C:\\Windows\\system32\\UpgradeResultsUI.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "upnpcont.exe-C88FC34F02CA63F2A927B17E0A14E3A4": { "file_name": "upnpcont.exe", "file_path": "C:\\Windows\\system32\\upnpcont.exe", "hash_md5": "C88FC34F02CA63F2A927B17E0A14E3A4", "hash_sha1": "AB98A880EFFE0FEB52F51AAA2F66169C2609BE76", "hash_sha256": "273C07A18E58228ECEEC37878621407FAEAFCE7310F1E44307B592A386E994F5", "hash_sha384": "48B73AE599895D6160E73BC440344B8CAF5C672B28C4BDDE4BD3E1116FAADDD13DFBAD95E323AE255117307BD3E91A09", "hash_sha512": "1155B9C9F87309C833DAF129611D75FF727226EC60F5D7B4734E52E5F690AF320D3F2B91F37195A0AF98CAD360237CAA8A806B59D300A95C37317D07D1DFE1EE", "hash_ssdeep": "768:JMh/7183E+APyg2DdC65oSZl4Uh6Rp80YITHZkiZXZq7LyUh5:JEJ80+R1C65ZWplRVLXZqvp", "hash_imp": "7B81D592E2E0E57EBD2E87234270AF60", "hash_pesha1": "BCA2B865490B2C808803857F3747F6B0DFB8B58E", "hash_pe256": "EFB2FE1BC085E36DB517E20E800800D476C553DA6E22C13B7362A7B249805A32", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UPnP Device Host Container", "meta_original_filename": "upnpcont.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.508 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.508", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/273c07a18e58228eceec37878621407faeafce7310f1e44307b592a386e994f5/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\upnpcont.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "UserAccountBroker.exe-F76DC927B78D3EEA7B6509D1736177C8": { "file_name": "UserAccountBroker.exe", "file_path": "C:\\Windows\\system32\\UserAccountBroker.exe", "hash_md5": "F76DC927B78D3EEA7B6509D1736177C8", "hash_sha1": "3CA3023193D43C76D70B0A36C522F5D7E5A17118", "hash_sha256": "A632049A11A5CD83688A40C27D3285377F82B41840504B158415BDFBBD90E488", "hash_sha384": "C3FD32D044FFE4E6E6C65D9692E4057ADA9851C419DCE9451DFAE8960372457859AB1F00F9FBF103D9B9CDE161847149", "hash_sha512": "2CC4E15ED134531671369FF8FB664A6AAD4C54CB8B7AB2144CB8AFE6C78A220B10A351E73DFC599554E05418CDC195D2A73BDA87BB042943EE9482E4EA040B50", "hash_ssdeep": "768:b9ERA13psk8q+7zHJHKP667KgvkbMJUZAWPoGsK074O2+51MPZdOjwPI1P7f:GReaTrzHdcswmyWoFxUOXqZMjwIP7", "hash_imp": "DBB7D8A71D753C694BB0AE94F3103E3A", "hash_pesha1": "175315DE71FC421269DA41AD4A742C1163C180B4", "hash_pe256": "81F8FD6C8A1989B4DC0D7BD348D240CD6DF9FD05740F3756FD1978685A62F7D7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "User Account Control Panel Host", "meta_original_filename": "UserAccountBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a632049a11a5cd83688a40c27d3285377f82b41840504b158415bdfbbd90e488/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\UserAccountBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "UserAccountControlSettings.exe-A9E9342FE35671E51E80CC64CC6A5CE5": { "file_name": "UserAccountControlSettings.exe", "file_path": "C:\\Windows\\system32\\UserAccountControlSettings.exe", "hash_md5": "A9E9342FE35671E51E80CC64CC6A5CE5", "hash_sha1": "264B1A7B3BBA509029906E9EBB3AD2C6089025D9", "hash_sha256": "DAA00A8C9F3531100DF87FC5D4226B6E8A476D80E2D109274128CA65701197C5", "hash_sha384": "57BA22DDA6462DA8A823B067A621D0BCE6636041965BB52142F50C80FB9C68BE978B412855610A918859A1DA2EC8C8E2", "hash_sha512": "7BDCE71D6B5B9259E858600BF8DEC02391136AEFB2F235F74672C67265985BE007A98F9B3B6AB04809D8BC7484F393BE272C0B1392439E1004BA7168F85B360D", "hash_ssdeep": "1536:F9Y3005lZEv18V2CW02hCqKd3ruXyzWP751sNz0UCdkV/L7:/uY1gWL271aT5K", "hash_imp": "535666E355558A85F423E8C8D4D12F36", "hash_pesha1": "050B35F5B9C70F636249C20B659DC12B7BB474E9", "hash_pe256": "A0BDC1F5B5D338CB6C40C87A259D37BBCC98C7987EA1F48C0E0970588DB0419D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UserAccountControlSettings", "meta_original_filename": "UserAccountControlSettings.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/daa00a8c9f3531100df87fc5d4226b6e8a476d80e2d109274128ca65701197c5/detection", "runtime_modules": [ "C:\\Windows\\system32\\UserAccountControlSettings.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "userinit.exe-582A919CA5F944AA83895A5C633C122C": { "file_name": "userinit.exe", "file_path": "C:\\Windows\\system32\\userinit.exe", "hash_md5": "582A919CA5F944AA83895A5C633C122C", "hash_sha1": "6D0C6AEA6BCE05166761085B1D612558F81D877A", "hash_sha256": "EDA7EE39D4DB8142A1E0788E205E80AE798035D60273E74981E09E98C8D0E740", "hash_sha384": "AD99932C6C699F11E6993BA44B2D497D6772A114D4435EF1731C49CF70976A9CC91A9319271841ED28F429B5D17345C7", "hash_sha512": "D4A4550D886FF49B4C3E382C1F30D260300CD29EAD7716161A79A489292825E72015871556167E1EF51E47D95C3795DE8108A2177B4A41559965DDE25B2A51CD", "hash_ssdeep": "768:i/J8uwEySKG/sMFii+6vLkkSSZ8q0NJNfKN6onrN:8J8uwEy+/sMFiPkXZZ0NbKN5nrN", "hash_imp": "DE7486657F39757C768DEE3094E10FF8", "hash_pesha1": "4823558B75C97B0638D4041B0F6AAA6874F74BCA", "hash_pe256": "897F76B61FEC1DE7A7CF6DD211FE7F28610BC1E3C7063DE4F8FA4E53F51667F5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Userinit Logon Application", "meta_original_filename": "USERINIT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/eda7ee39d4db8142a1e0788e205e80ae798035d60273e74981e09e98c8d0e740/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\userinit.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\userinit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "UsoClient.exe-0BD9035FB5DC6BB7536D88CE0D3F0F31": { "file_name": "UsoClient.exe", "file_path": "C:\\Windows\\system32\\UsoClient.exe", "hash_md5": "0BD9035FB5DC6BB7536D88CE0D3F0F31", "hash_sha1": "1B6D6F51CE0B7CBAF337E075699F8E5183BC7B2D", "hash_sha256": "FA54E07E1D8DD669E5BDBB0EA918677EA0391AB419EC849FE0F1793165900794", "hash_sha384": "567605246949CCBB5EB47E88ACC8C3B15662B4D1A6142CB1EB95A78E386A48A39833CFF74B03E008B1C16678B58E8A6C", "hash_sha512": "FC25F63BE601C834A5788B0113300282A26E65F2645EFF5BD2F98930FD0F1F0DDA88DEE1A958348AB1F9FDE7295292952172351B19F34D03A50614CE3377FFA1", "hash_ssdeep": "1536:SL/jU0EwxbVDfxZ+SefADimRGQ4e0FeOJaVjiWhVB2fx79I:xUbkZfADimRGQ4e0FPJaVjFg579I", "hash_imp": "208F065ACB93BA3D82E648BAA58D7553", "hash_pesha1": "0E1B38968D7B521F73EA34B2A99D2814E4BD422D", "hash_pe256": "E56542566F479C02346F42DE934FB966123EA7631BA47E560E36EE889482A17A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UsoClient", "meta_original_filename": "UsoClient", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/fa54e07e1d8dd669e5bdbb0ea918677ea0391ab419ec849fe0f1793165900794/detection", "runtime_modules": [ "C:\\Windows\\system32\\UsoClient.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "usocoreworker.exe-D59AB47DD17B9BE6BDEAC599DCC56E77": { "file_name": "usocoreworker.exe", "file_path": "C:\\Windows\\system32\\usocoreworker.exe", "hash_md5": "D59AB47DD17B9BE6BDEAC599DCC56E77", "hash_sha1": "596BCB7075A5D4937696168561DD223242C1E8A0", "hash_sha256": "B27891E718C6842A406C3F1C01DF8FCAB04AD355319DF55025BB7C6F13D88918", "hash_sha384": "76998C6D35E14F584366F196084CAEBDA69FEB6E250FD05CEFBD13365A57403C5488F7AE203BE1E7F1CE2DE8CB6DCDC4", "hash_sha512": "48C85E39BD285DA819A54D6E57E3B197560FACA4F1F8F4FE91A23714EACB37B0E1CBC30C2A8AF8A43E17F001068C15A3BCE4FE3A31598AD0603B835C2C6082A8", "hash_ssdeep": "24576:XCBZM8bzg7Hu9QwOyDwD7xqk3VTQyewDgCQ1SwcWjiLaajLxkGQMgP:WZPhQRmwPpa5EgW1Wjga+xq1", "hash_imp": "5832569D3382CE32D02E5DA0D33C4C13", "hash_pesha1": "26131B1218E2B8B25B35586AEF82373CC7ECF766", "hash_pe256": "65F9FCB8F0241BC53FB37525977AE1596BA1FC4853CFAAE791458A9F88AD249B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "USO Core Worker Process", "meta_original_filename": "USOCoreWorker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/b27891e718c6842a406c3f1c01df8fcab04ad355319df55025bb7c6f13d88918/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\ProgramData\\USOShared\\Logs\\User\\UsoCoreWorker.5b2a8a0a-7624-43a8-b8ad-cc85680f9f5b.1.etl": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\usocoreworker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "UtcDecoderHost.exe-6A66CDB41B75E7C7E339B84C2A51CA1F": { "file_name": "UtcDecoderHost.exe", "file_path": "C:\\Windows\\system32\\UtcDecoderHost.exe", "hash_md5": "6A66CDB41B75E7C7E339B84C2A51CA1F", "hash_sha1": "3613B74FAA7804D13CE4988C444BD355BE3B147F", "hash_sha256": "B285CB12050FA52AE6A41F76E540B8A9A88F2D7B2F52DD3467F66703B7B112B1", "hash_sha384": "F7AEFD28818E0056DF3BBFCF7A0FC9EF7837F816D9010DAFAFD81D1DA41D05D7140D20716F8E3C2670296DABC8A1E7E2", "hash_sha512": "EE6691118C521AEB722DFE1C815C01A6776501CA437F2BA31F4CC71A730C4F6FC7F85A989009A4A0EF02E23D6274FEF17F3602D52517915300EF11BB4940744F", "hash_ssdeep": "3072:wZM2kBuzvOgRTNvg+rXRJ1gpfSNXt8bFUKgMz7rruqLJ7Kgj7j/m2GzVyE+j0OF:4XydR/DqyXz", "hash_imp": "0B25406AFEBFAE2E90EEE1EF452D0457", "hash_pesha1": "266034D059FDBD26CD55D73DE1BCDF3BD42E70AA", "hash_pe256": "0C1F8106D192F5FD0CC760A622419F1D7BB21C523C905DD989AC003741A30948", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Diagnostics Tracking Decoder Host", "meta_original_filename": "UtcDecoderHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b285cb12050fa52ae6a41f76e540b8a9a88f2d7b2f52dd3467f66703b7b112b1/detection", "runtime_modules": [ "C:\\Windows\\system32\\UtcDecoderHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "Utilman.exe-B0CBB83A8E75F61E261B0BCBEB117B61": { "file_name": "Utilman.exe", "file_path": "C:\\Windows\\system32\\Utilman.exe", "hash_md5": "B0CBB83A8E75F61E261B0BCBEB117B61", "hash_sha1": "FF1509E9C0BE765056264B171D047130ABC514F6", "hash_sha256": "FC6DFD41F75BB4640767BE808A2D890AC7654AAF2C505455732D9F6290F9A030", "hash_sha384": "4C2A8E01A879CCDA855835DEE528A682453778D5C7192291EAD029F573FFBEDC8228249840DC7738A127A81D3A4FD24E", "hash_sha512": "25387F37737589711276D92160B8998DB6972DD75EF8F6C387C12514BB380779AE8954301C11278F1E7304F18E7243ADAA3F0DBA1BCE9D18697D07F15EDA5B54", "hash_ssdeep": "1536:OcofAgDrvk1QP8lob2wrlX09Ogx94NkLBijcYnm+CjoSxEfZ59kovpvgX1shlXN6:Wz/Alob3naWEg0jbxEf9vls1ElXNo5o", "hash_imp": "A2FCCA077B02C4BE5588E6BDCA6B76AA", "hash_pesha1": "A697F53CC32EB3AF7DDF7030E66AF3467D008822", "hash_pe256": "4500582113C6B1D63B209DA98AF45A7E4F13B6BD4509AF515E6D180458C4A422", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Utility Manager", "meta_original_filename": "utilman2.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/fc6dfd41f75bb4640767be808a2d890ac7654aaf2c505455732d9f6290f9a030/detection", "runtime_modules": [ "C:\\Windows\\system32\\Utilman.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\OLEACC.dll" ] }, "VaultCmd.exe-5F69F4F8683151A59C5A11265B4A3C96": { "file_name": "VaultCmd.exe", "file_path": "C:\\Windows\\system32\\VaultCmd.exe", "hash_md5": "5F69F4F8683151A59C5A11265B4A3C96", "hash_sha1": "95AE738AB6B2CC92D88E3DEBBAACDD924BC27F5E", "hash_sha256": "EDC1B6A3E4FDE216A323329E35F4192B0F49BC68285EE67036DEFF9E94C4E33A", "hash_sha384": "4FD25542E14EF99158C31B3278F7E209EE09327980393C7555F6386E0EE7D27D0C23D941E0F1E9BA77FC6D1AF0EFCBA6", "hash_sha512": "33FD26E122685C5D9E49930CF4C64237D157443EA43DD82423187C6B71E19539BC3C9582D567736BAC3D8D27B604F32514F85EEFA8E8A5E5B26B9F402B23BEBF", "hash_ssdeep": "768:fs4TjbWSCdB16t4D+GJmiPioMNFzXn7Bv:fTjb7yPioWFzXn7Bv", "hash_imp": "692BBD94F45AD2DFEFD2A3DA11FCCE0F", "hash_pesha1": "8AD190CA516BE4D2011FAB4CCA027EF3C7A9556E", "hash_pe256": "1FAB228260D00955882172B836AA658E48A7A27D1506F3B1B4448A3C95B05490", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Vault cmdline Program", "meta_original_filename": "VAULTCMD.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/edc1b6a3e4fde216a323329e35f4192b0f49bc68285ee67036deff9e94c4e33a/detection", "output": "Creates, displays and deletes stored credentials.\r\nFollowing commands are supported.Use VaultCmd /<command> /? for further help \r\nVaultCmd /list\r\nVaultCmd /listschema\r\nVaultCmd /listcreds\r\nVaultCmd /addcreds\r\nVaultCmd /deletecreds\r\nVaultCmd /listproperties\r\nVaultCmd /sync\r\n", "runtime_modules": [ "C:\\Windows\\system32\\VaultCmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "vds.exe-8845765B4D416FD2835C27C58A15E99E": { "file_name": "vds.exe", "file_path": "C:\\Windows\\system32\\vds.exe", "hash_md5": "8845765B4D416FD2835C27C58A15E99E", "hash_sha1": "50CE4B4441661CBB0617A8D39476F9712FD31B4C", "hash_sha256": "8A0AA93F17FEE2C816D57ADB6B6BE38D195D87A3CDCFBDDB78E0AF0D5452BC5E", "hash_sha384": "7C0A8683387E1F62226AAE6DE5B64ACA50FE42ACEF8C9108D76014230E43962A17D584841D38AABB4F42B5E80F4AC56B", "hash_sha512": "B965C1891027276A5299F854C45AC5A3155821B78C448562126BB9F79C5F6C2DADD1EDDA151653AE434A20D9281D804603892B930C6E36A00D1DB8F88C02E47A", "hash_ssdeep": "6144:TOKzUfSIW1onAtgXx/moIs8hxVR+7F7eYaj4se0LxQdxJ:T0AtgXx7Is8bCtVA4T8M", "hash_imp": "1DED34FA2F4887EC7854C3137A5F180D", "hash_pesha1": "DB3505A17AF47608077CFA3542BF87CF4BB7EF9E", "hash_pe256": "92E371D1EBF466F641C6CC4B220A4438AB6E82499638B2A61172306403764573", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Virtual Disk Service", "meta_original_filename": "vds.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8a0aa93f17fee2c816d57adb6b6be38d195d87a3cdcfbddb78e0af0d5452bc5e/detection", "runtime_modules": [ "C:\\Windows\\system32\\vds.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\system32\\ATL.DLL", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\OSUNINST.dll", "C:\\Windows\\system32\\vdsutil.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll" ] }, "vdsldr.exe-D7C605515077733AC12B22C7B6D4F1BB": { "file_name": "vdsldr.exe", "file_path": "C:\\Windows\\system32\\vdsldr.exe", "hash_md5": "D7C605515077733AC12B22C7B6D4F1BB", "hash_sha1": "98AC15F44A0D35414537E9EC2F6CA58EA3EBC866", "hash_sha256": "C80AA94B7370BCAF14EE105E8208A303957E64F030BFF3D77F98ACE089A575B7", "hash_sha384": "78643ED798D8122C4DCE151C826A964AE13F221412ED47AA5D1033528118EBD93C44588ABA9FA0BDB0E5FBDDB8301758", "hash_sha512": "89023B7E716F88393D9E67C92645BE0BB43867AE443B1BF2161C77CDBD14384B5C954AA0D9A2E963906FAFFD7C5284B3BC2484C317AF701F5DE5C3EB6543FD3B", "hash_ssdeep": "768:PuuEyKsUf6U5N6huY/ZwLRG1LTsRcYmjFh:PhEyKO14QLTsBmjF", "hash_imp": "9603C9CE05A128F079B59510B5F4D75C", "hash_pesha1": "D4076A058B02204B271434C75D800DF38F1C19E2", "hash_pe256": "A7017CFC453830E82D75846DB9EB7317818CCFEBF760A46FCC363575592B6E0C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Virtual Disk Service Loader", "meta_original_filename": "vdsldr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c80aa94b7370bcaf14ee105e8208a303957e64f030bff3d77f98ace089a575b7/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\vdsldr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "verclsid.exe-81D41E225B8B55748FFB0D8747FE8BAC": { "file_name": "verclsid.exe", "file_path": "C:\\Windows\\system32\\verclsid.exe", "hash_md5": "81D41E225B8B55748FFB0D8747FE8BAC", "hash_sha1": "B8359399F1751FF1AFFC4A3A9F90F890CB17C9ED", "hash_sha256": "AC6E1F614CB902C0ABE4297646E21C70590624B652A080BFBB8407B1AB52609D", "hash_sha384": "1A10576F99F7927D3C30D5EC3031BF226BAA3E650BC6C3844DA759D4A40C51F4D7F29AF93128AE29AFDCD01E47BDFDBE", "hash_sha512": "495B57077F2E50247D8CB041405A39B6B8459A794AC3A801DF5CCF6EB1C2A8AFCCA668920A7039A6199B91C8895A2FCB7D70CB1955C69E0D31E4C4CDCD81AC0E", "hash_ssdeep": "192:1S1rPu2/TzyyIDWm8ZdFN2y9qnWJ8VaZGuJG+WfCkXWSNW:1S17uezxm8vL2PWJqOGuUCoWSNW", "hash_imp": "FA65D753209C7382631265744DE49154", "hash_pesha1": "1DE0E12F0D8BEC5CFD749CC24901367A305AD1CB", "hash_pe256": "F37FCB07032841EB2FFE0A88884A4712B1A217E71EAC6B9653834ED58F2D09F4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extension CLSID Verification Host", "meta_original_filename": "verclsid.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ac6e1f614cb902c0abe4297646e21c70590624b652a080bfbb8407b1ab52609d/detection", "runtime_modules": [ "C:\\Windows\\system32\\verclsid.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\GDI32.dll" ] }, "verifier.exe-2116190AE866163ED485C4FD3E13D03B": { "file_name": "verifier.exe", "file_path": "C:\\Windows\\system32\\verifier.exe", "hash_md5": "2116190AE866163ED485C4FD3E13D03B", "hash_sha1": "664654A40696F13DC8E23BD2DF32BA55A6E0DA20", "hash_sha256": "608AF8AEF15BA4F75996D46249A428EBBFF1551DE06F6EB6A053C2C330DA6965", "hash_sha384": "D79CF171A2A811E37FE36E297CB886A63AE79074B7A1AFD90627EE09E2F55454E0DDED9F1BBFD709350315FF535E67E0", "hash_sha512": "D1215853879DE73AA469563C4BA85C40E0B3FB09CC32E56A8EB70FB003BB62625291857FB51B9D9A16DA8B977075AA1C96A154437B06065C672FA04D7F2C48C6", "hash_ssdeep": "3072:0JF8t4lZdHOg4IDGxdHga52NaB44nDIXKGyc5VoJe3+Vcv2JxQQBBEB3Befnj0zD:2F8t4lZdHFDGxdHgXNaBlnDIaGGzMZam", "hash_imp": "B1AD676B2E6F36FC8CB817134AB146B4", "hash_pesha1": "19FE0FEE85D81A0A6EDC3F3D313499C67CABC5F6", "hash_pe256": "31147654D8B30FC49DEF94948CE23B9127797E288E0512393D50545751F04ED2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Verifier Configuration Editor", "meta_original_filename": "verifier.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/608af8aef15ba4f75996d46249a428ebbff1551de06f6eb6a053c2c330da6965/detection", "output": "\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nSYNTAX:\r\n\r\n verifier {/? | /help}\r\n verifier /standard /all\r\n verifier /standard /driver <name> [<name> ...]\r\n verifier {/ruleclasses | /rc} <options> [<ruleclass_1> <ruleclass_2> ...] /all\r\n verifier /flags <options> [<options> ...] /all\r\n verifier /flags <options> [<options> ...] /driver <name> [<name> ...]\r\n verifier /rules {query | reset | default <id> | disable <id>}\r\n verifier /query\r\n verifier /querysettings\r\n verifier /bootmode {persistent | resetonbootfail | oneboot | resetonunusualshutdown}\r\n verifier /persistthroughupgrade\r\n verifier /reset\r\n verifier /faults [probability [pool_tags [applications [delay_minutes]]]]\r\n verifier /faultssystematic [<options> ...]\r\n verifier /log <file_name> [/interval <seconds>]\r\n verifier /volatile /flags <options> [<options> ...]\r\n verifier /volatile /adddriver <name> [<name> ...]\r\n verifier /volatile /removedriver <name> [<name> ...]\r\n verifier /volatile /faults [probability [pool_tags [applications\r\n [delay_minutes]]]]\r\n verifier /domain {wdm | ndis | ks | audio} [rules.all | rules.default ]\r\n /driver ... [/logging | /livedump]\r\n verifier /logging\r\n verifier /livedump\r\n\r\nPARAMETERS:\r\n\r\n /? or /help\r\n Displays this help message.\r\n\r\n /standard\r\n Specifies standard Driver Verifier flags.\r\n\r\n /all\r\n Specifies that all installed drivers will be verified after the next\r\n boot.\r\n\r\n /driver <name> [<name> ...]\r\n Specifies one or more drivers (image names) that will be verified.\r\n Wildcard values (e.g. n*.sys) are not supported.\r\n\r\n /driver.exclude <name> [<name> ...]\r\n Specifies one or more drivers (image names) that will be excluded\r\n from verification. This parameter is applicable only if all drivers\r\n are selected for verification. Wildcard values (e.g. n*.sys) are not\r\n supported.\r\n\r\n /flags <options> [<options> ...]\r\n Specifies one or more options that should be enabled for verification.\r\n Flags are applied to all drivers being checked by Driver Verifier. The\r\n provided options values must be either in decimal, hexadecimal (\"0x\"\r\n prefix), octal (\"0o\" prefix) or binary (\"0b\" prefix) format.\r\n\r\n Standard Flags:\r\n Standard Driver Verifier options can be specified using '/standard'.\r\n WDF verification is included in /standard but is not shown here.\r\n\r\n 0x00000001 (bit 0) - Special pool\r\n 0x00000002 (bit 1) - Force IRQL checking\r\n 0x00000008 (bit 3) - Pool tracking\r\n 0x00000010 (bit 4) - I/O verification\r\n 0x00000020 (bit 5) - Deadlock detection\r\n 0x00000080 (bit 7) - DMA checking\r\n 0x00000100 (bit 8) - Security checks\r\n 0x00000800 (bit 11) - Miscellaneous checks\r\n 0x00020000 (bit 17) - DDI compliance checking\r\n\r\n Additional Flags:\r\n These flags are intended for specific scenario testing. Flags marked\r\n with (*) require I/O Verification (bit 4) that will be automatically\r\n enabled. Flags marked with (**) support disabling of individual\r\n rules.\r\n\r\n 0x00000004 (bit 2) - Randomized low resources simulation\r\n 0x00000200 (bit 9) - Force pending I/O requests (*)\r\n 0x00000400 (bit 10) - IRP logging (*)\r\n 0x00002000 (bit 13) - Invariant MDL checking for stack (*)\r\n 0x00004000 (bit 14) - Invariant MDL checking for driver (*)\r\n 0x00008000 (bit 15) - Power framework delay fuzzing\r\n 0x00010000 (bit 16) - Port/miniport interface checking\r\n 0x00040000 (bit 18) - Systematic low resources simulation\r\n 0x00080000 (bit 19) - DDI compliance checking (additional)\r\n 0x00200000 (bit 21) - NDIS/WIFI verification (**)\r\n 0x00800000 (bit 23) - Kernel synchronization delay fuzzing\r\n 0x01000000 (bit 24) - VM switch verification\r\n 0x02000000 (bit 25) - Code integrity checks\r\n\r\n /ruleclasses or /rc [<ruleclass_1> <ruleclass_2> ... <ruleclass_k>]\r\n This parameter is larger set of '/flags' above. While '/flags' is\r\n limited to 32 bit bitmap expression, this can include more than 32\r\n verification classes. Each positive decimal integer represents a\r\n verification class. Multiple classes can be expressed by separating\r\n each class id with space character. Following rule classes IDs are\r\n available and leading 0's can be omitted.\r\n\r\n Standard Rule Classes:\r\n\r\n 1 - Special pool\r\n 2 - Force IRQL checking\r\n 4 - Pool tracking\r\n 5 - I/O verification\r\n 6 - Deadlock detection\r\n 8 - DMA checking\r\n 9 - Security checks\r\n 12 - Miscellaneous checks\r\n 18 - DDI compliance checking\r\n 34 - WDF Verification\r\n\r\n Additional Rule Classes:\r\n These rule classes are intended for specific scenario testing. Rule\r\n classes are marked with (*) require I/O Verification (5) that will\r\n be automatically enabled. Flags marked with (**) support disabling\r\n of individual rules.\r\n\r\n 3 - Randomized low resources simulation\r\n 10 - Force pending I/O requests (*)\r\n 11 - IRP logging (*)\r\n 14 - Invariant MDL checking for stack (*)\r\n 15 - Invariant MDL checking for driver (*)\r\n 16 - Power framework delay fuzzing\r\n 17 - Port/miniport interface checking\r\n 19 - Systematic low resources simulation\r\n 20 - DDI compliance checking (additional)\r\n 22 - NDIS/WIFI verification (**)\r\n 24 - Kernel synchronization delay fuzzing\r\n 25 - VM switch verification\r\n 26 - Code integrity checks\r\n\r\n /log.code_integrity\r\n This option suppresses Code Integrity violation breaks and collects\r\n only statistics for verified drivers. Statistics could be extracted\r\n via /log option or kernel debugger. This parameter is applicable only\r\n if Code Integrity checks are enabled.\r\n\r\n /rules {query | reset | default <id> | disable <id>}\r\n Specifies rules level control (advanced).\r\n\r\n query Shows current status of controllable rules.\r\n reset Resets all rules to their default state.\r\n default <id> Sets rule ID to its default state.\r\n disable <id> Disables specified rule ID.\r\n\r\n /query\r\n Display runtime Driver Verifier statistics and settings.\r\n\r\n /querysettings\r\n Displays a summary of the options and drivers that are currently\r\n enabled, or options and drivers that will be verified after the\r\n next boot. The display does not include drivers and options added\r\n using /volatile.\r\n\r\n /bootmode\r\n Specifies the Driver Verifier boot mode. This option requires system\r\n reboot to take effect.\r\n\r\n persistent Ensures that Driver Verifier settings are\r\n persistent across reboots. This is the default\r\n value.\r\n resetonbootfail Disables Driver Verifier for subsequent reboots\r\n if the system failed to start.\r\n resetonunusualshutdown\r\n Driver Verifier persists until unusual shutdown\r\n happens. Its abbrevation, 'rous', can be used.\r\n oneboot Enables Driver Verifier only for the next boot.\r\n\r\n /persistthroughupgrade\r\n Makes the Driver Verifier settings persist through upgrade. Driver\r\n Verifier will be active during system upgrade.\r\n\r\n /reset\r\n Clears Driver Verifier flags and driver settings. This option requires\r\n system reboot to take effect.\r\n\r\n /faults [probability [pool_tags [applications [delay_minutes]]]]\r\n Enable the Randomized low resources simulation feature and optionally\r\n control parameters for the Randomized low resources simulation.\r\n\r\n Probability Specifies the probability that Driver Verifier will\r\n fail a given allocation. The value represents the\r\n number of chances in 10,000 that Driver Verifier will\r\n fail the allocation. The default value 600, means\r\n 600/10000 or 6.\r\n Pool Tags: Specifies a space separated list of the pool tags to\r\n be injected with faults. By default, any pool\r\n allocation can be injected with faults.\r\n Applications Specifies a space separated list of image file names\r\n (an executable) that will be injected with faults. By\r\n default, any pool allocation can be injected with\r\n faults.\r\n DelayMinutes Specifies the number of minutes after booting during\r\n which Driver Verifier does not intentionally fail any\r\n allocations. This delay allows the drivers to load\r\n and the system to stabilize before the test begins.\r\n The default value is 8 minutes.\r\n\r\n /faultssystematic [<options> ...]\r\n Controls the Systematic low resources simulation parameters.\r\n\r\n enableboottime Enables fault injections across reboots.\r\n disableboottime Disables fault injections across reboots.\r\n This is the default value.\r\n recordboottime Enables fault injections in 'what if' mode\r\n across reboots.\r\n resetboottime Disables fault injections across reboots and\r\n clears the stack exclusion list.\r\n enableruntime Dynamically enables fault injections.\r\n disableruntime Dynamically disables fault injections.\r\n recordruntime Dynamically enables fault injections in\r\n 'what if' mode.\r\n resetruntime Dynamically disables fault injections and\r\n clears the previously faulted stack list.\r\n querystatistics Shows the current fault injection statistics.\r\n incrementcounter Increments the test pass counter used to\r\n identify when a fault was injected.\r\n getstackid <counter> Retrieves the indicated injected stack id.\r\n excludestack <stack_id> Excludes the stack from fault injection.\r\n\r\n /log <file_name> [/interval <seconds>]\r\n Creates a log file with the specified name and periodically writes the\r\n runtime statistics to this file. The interval between log file updates\r\n is controlled by the '/interval' parameter. The default value is 30\r\n seconds. Use CTRL+C to close the log and return.\r\n\r\n /volatile\r\n Changes Driver Verifier settings without rebooting the computer.\r\n Volatile settings take effect immediately and are in effect until the\r\n next system reboot.\r\n\r\n /volatile /adddriver <name> [<name> ...]\r\n Starts the verification for the specified driver or drivers.\r\n\r\n /volatile /removedriver <name> [<name> ...]\r\n Stops the verification for the specified driver or drivers.\r\n\r\n /domain {wdm | ndis | ks | audio} [rules.all | rules.default] /driver ...\r\n [/logging | /livedump]\r\n Controls the verifier extension settings. The following verifier\r\n extension types are supported:\r\n\r\n wdm Enabled verifier extension for WDM drivers.\r\n ndis Enabled verifier extension for networking drivers.\r\n ks Enabled verifier extension for kernel mode\r\n streaming drivers.\r\n audio Enabled verifier extension for audio drivers.\r\n\r\n The following extension options are supported:\r\n\r\n rules.default Enables default validation rules for the selected\r\n verifier extension.\r\n rules.all Enables all validation rules for the selected\r\n verifier extension.\r\n\r\n /logging\r\n Enables logging for violated rules detected by the selected verifier\r\n extensions.\r\n\r\n /livedump\r\n Enables live memory dump collection for violated rules detected by\r\n the selected verifier extensions.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\verifier.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "verifiergui.exe-03A76A765ABE56C8999A548331F191D9": { "file_name": "verifiergui.exe", "file_path": "C:\\Windows\\system32\\verifiergui.exe", "hash_md5": "03A76A765ABE56C8999A548331F191D9", "hash_sha1": "37D5323CC065638D06C29E8A4239DC0FAE072A5D", "hash_sha256": "19A383A3028816C56AB123962707ADDA9D3F68091C44F9D9E2F69E6CA935F151", "hash_sha384": "9DCEE7EC1A2C3DA7FE1C8EB9D2616813E2DE1CC99FF26F6F2079FF6891F2764496D2E9D276CDAA02D22F34E773B382BF", "hash_sha512": "C741D5B4293F33F3DC1235F381BFE5F6635BA95D73BD719C800EDE6AFEE160E6095B1136779EA1DCC85A2ABC24DCE872B80F897662B33EB9A5C7A299337D86D4", "hash_ssdeep": "3072:chElFUjJ4TITY3ZbKLc/Ul7Fgqhjc5VoJe3+Vcv2JxQQBBEB3Befnj0t+TrjqNnf:0jJ4bZbvnbvhL", "hash_imp": "466780D17BDF0C0DD4493F0E167E7B41", "hash_pesha1": "04292B4FA8DA89B6D09C214A60215FEFA8613876", "hash_pe256": "C2C3630CD8C1B7214DEFE774484607008D791440230EF06B40E37F364E10EEDD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Driver Verifier Manager", "meta_original_filename": "verifiergui.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/19a383a3028816c56ab123962707adda9d3f68091c44f9d9e2f69e6ca935f151/detection", "output": " \r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n \r\nCOMMON USAGE: \r\n verifier /?\r\n verifier /standard /all\r\n verifier /standard /driver NAME [NAME ...]\r\n verifier /flags FLAGS /all\r\n verifier /flags FLAGS /driver NAME [NAME ...]\r\n verifier /rules [OPTION ...]\r\n verifier /query\r\n verifier /querysettings\r\n verifier /bootmode [persistent|resetonbootfail|oneboot]\r\n verifier /reset\r\n verifier /faults [PROB [TAGS [APPS [MINS]]]]\r\n verifier /faultssystematic [OPTION ...]\r\n verifier /log LOG_FILE_NAME [/interval SECONDS]\r\n verifier /volatile /flags FLAGS\r\n verifier /volatile /adddriver NAME [NAME ...]\r\n verifier /volatile /removedriver NAME [NAME ...]\r\n verifier /volatile /faults [PROB [TAGS [APPS [MINS]]]]\r\n \r\n/?\r\n This help.\r\n \r\n/standard\r\n Enable the Driver Verifier standard flags. \r\n This is functionally equivalent to '/flags 0x209BB'\r\n \r\n/all\r\n Enable Driver Verifier on all drivers in a system.\r\n \r\n/driver NAME [NAME ...]\r\n Specify the driver or list of drivers that should be verified.\r\n NAME is the name and extension of the file to verify (example: driver.sys).\r\n To enable Driver Verifier on more than one driver, list all drivers using a\r\n space separated list. Wildcard values (such as n*.sys) are not supported.\r\n \r\n/flags FLAGS \r\n Specify which options are enabled for verification. \r\n FLAGS value must be a number in decimal or hex (with 0x prefix).\r\n Note: Flags are applied to all drivers being checked by Driver Verifier. \r\n \r\n STANDARD FLAGS:\r\n These flags are considered standard options for Driver Verifier and can be \r\n set using '/standard' or by the combination of the options: '/flags 0x209BB'\r\n bit 0 (0x00000001) - Special pool\r\n bit 1 (0x00000002) - Force IRQL checking\r\n bit 3 (0x00000008) - Pool tracking\r\n bit 4 (0x00000010) - I/O verification\r\n bit 5 (0x00000020) - Deadlock detection\r\n bit 7 (0x00000080) - DMA checking\r\n bit 8 (0x00000100) - Security checks\r\n bit 11 (0x00000800) - Miscellaneous checks\r\n bit 17 (0x00020000) - DDI compliance checking\r\n \r\n ADDITIONAL FLAGS:\r\n These flags are designed for specific scenario testing.\r\n Flags marked with a (*) require I/O Verification (bit 4) also be enabled.\r\n Flags marked with a (**) support disabling of individual rules.\r\n bit 2 (0x00000004) - Randomized low resources simulation\r\n bit 9 (0x00000200) - Force pending I/O requests (*)\r\n bit 10 (0x00000400) - IRP logging (*)\r\n bit 13 (0x00002000) - Invariant MDL checking for stack (*)\r\n bit 14 (0x00004000) - Invariant MDL checking for driver (*)\r\n bit 15 (0x00008000) - Power framework delay fuzzing\r\n bit 16 (0x00010000) - Port/miniport interface checking\r\n bit 18 (0x00040000) - Systematic low resources simulation\r\n bit 19 (0x00080000) - DDI compliance checking (additional)\r\n bit 21 (0x00200000) - NDIS/WIFI verification (**)\r\n bit 23 (0x00800000) - Kernel synchronization delay fuzzing\r\n bit 24 (0x01000000) - VM switch verification\r\n bit 25 (0x02000000) - Code integrity checks\r\n \r\n/rules [OPTION ...]\r\n Options for rules that can be disabled (advanced). \r\n query: shows current status of controllable rules.\r\n reset: resets all rules to their default state.\r\n default ID: sets rule ID to its default state.\r\n disable ID: disables specified rule ID.\r\n \r\n/query\r\n Display a summary of Driver Verifier's current activity.\r\n \r\n/querysettings\r\n Display a summary of the options and drivers that are currently enabled, \r\n or options and drivers that will be verified after the next boot. The \r\n display does not include drivers and options added using /volatile.\r\n \r\n/bootmode\r\n Sets the verifier boot mode. Requires reboot to take effect.\r\n persistent: Ensures that DV settings are persistent over many reboots.\r\n This is default.\r\n resetonbootfail: If OS fails to boot, reset verifier for subsequent boots.\r\n oneboot: Only enable verifier for next boot.\r\n \r\n/reset\r\n Clear Driver Verifier flag and driver settings. Does not clear bootmode.\r\n Requires reboot to take effect.\r\n \r\n/faults [PROB [TAGS [APPS [MINS]]]]\r\n Enable the Randomized low resources simulation bit and optionally control\r\n parameters for the Randomized low resources simulation.\r\n PROB: A number between 1 and 10000 specifying the fault injection \r\n probability. If this parameter is not specified, then the default \r\n value of 600 (6%) will be used.\r\n TAGS: A space separated list of the pool tags to be injected with faults.\r\n If this parameter is not specified, then any pool allocation can be\r\n injected with faults.\r\n APPS: A space separated list of the image filename of the applications that\r\n will be injected with faults. If this parameter is not specified then\r\n the Randomized low resources simulation can take place in any\r\n application.\r\n MINS: A positive number indicating the of minutes after rebooting during \r\n which no fault injection will occur. If this parameter is not \r\n specified, then the default length of 8 minutes will be used.\r\n \r\n/faultssystematic [OPTION ...]\r\n Options for controlling the Systematic low resources simulation.\r\n enableboottime: enables fault injections across reboots.\r\n disableboottime: disables fault injections across reboots (default).\r\n recordboottime: enables fault injections in 'what if' mode across\r\n reboots.\r\n resetboottime: disables fault injections across reboots and clears\r\n the stack exclusion list.\r\n enableruntime: dynamically enables fault injections.\r\n disableruntime: dynamically disables fault injections.\r\n recordruntime: dynamically enables fault injections in 'what if'\r\n mode.\r\n resetruntime: dynamically disables fault injections and clears the\r\n previosly faulted stack list.\r\n querystatistics: shows the current fault injection statistics.\r\n incrementcounter: increments the test pass counter used to identify\r\n when a fault was injected.\r\n getstackid COUNTER: retrieves the indicated injected stack id.\r\n excludestack STACKID: excludes the stack from fault injection.\r\n \r\n/log LOG_FILE_NAME [/interval SECONDS]\r\n Create a log file with the name LOG_FILE_NAME. \r\n If '/interval' option is not specified, the default 30 seconds is used. \r\n Note: If a 'verifier /log' command is typed at the command line, the command\r\n prompt does not return. Use CTRL+C to close the log and return.\r\n \r\n/volatile\r\n Change the verifier settings dynamically without rebooting the system.\r\n Volatile settings are in effect until the next system reboot. \r\n \r\n/volatile /adddriver NAME [NAME ...]\r\n Add the specified driver or drivers to the list of drivers that will be \r\n checked with volatile settings. \r\n \r\n/volatile /removedriver NAME [NAME ...]\r\n Remove the specified driver or drivers from the list of drivers that are\r\n being checked with volatile settings. \r\n \r\n", "runtime_modules": [ "C:\\Windows\\system32\\verifiergui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "VmComputeAgent.exe-152CA5099ECD5FBBCA86064A7DBC7B4F": { "file_name": "VmComputeAgent.exe", "file_path": "C:\\Windows\\system32\\VmComputeAgent.exe", "hash_md5": "152CA5099ECD5FBBCA86064A7DBC7B4F", "hash_sha1": "B9354E471078ACF8754B7B1447CFB0A08B7D6BAD", "hash_sha256": "DC9691009F3CBDEE1C5CD8A526A1630D5BFFD70AADE9E6ED9900A5F3E00A2494", "hash_sha384": "79C56CD7B2F59C1FD26C8D23EC679CC8CB2009E8EAC1D9551BF7542215DE6F2AE9A95880B61B1DECB062578B57294B43", "hash_sha512": "97DC271AF7C077ABEA22E74A8A5A06E5A6F8FD1232831F3C948FD030D2BEB239448AC9B3E0E197DD19AEDE32FA340997FDD62F03CBA681B5D10756FF2CC4973E", "hash_ssdeep": "24576:rSfYW+davvAC0jkPlbmVdSR3hqo/ZP0Vx+Cxr9qsO:rSfYW+davvAC0jkPlQdSR39ZcL+g9qH", "hash_imp": "78D6614749B85E892B168EA2E2B6D5ED", "hash_pesha1": "37EB57E44C63DFD0095854A07106BE260CA6B0E8", "hash_pe256": "726E57D31112D60D08DFC8E45B559C2D147C074440EFE18E4FDE9A9B44059AD4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hyper-V Guest Compute Service", "meta_original_filename": "VmComputeAgent.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/dc9691009f3cbdee1c5cd8a526a1630d5bffd70aade9e6ed9900a5f3e00a2494/detection", "runtime_modules": [ "C:\\Windows\\system32\\VmComputeAgent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\container.dll", "C:\\Windows\\system32\\HvSocket.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\wc_storage.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "vssadmin.exe-B58073DB8892B67A672906C9358020EC": { "file_name": "vssadmin.exe", "file_path": "C:\\Windows\\system32\\vssadmin.exe", "hash_md5": "B58073DB8892B67A672906C9358020EC", "hash_sha1": "AAFE91BDC580260E4EF7FABC6B273FF0AE1E703F", "hash_sha256": "8C1FABCC2196E4D096B7D155837C5F699AD7F55EDBF84571E4F8E03500B7A8B0", "hash_sha384": "D05BD691914E58FBAA08F78D1E305782A4ADA5B3435841C3EC958FFB2562CD36C862AB116387B42040A79861944398FF", "hash_sha512": "84C3B17D84FB07F561F9ED53FF4CEF7EA155659F302631971F949999F2EAE87F7087DE2402B512714A0FBF4CCAFBAB2E0D015FAE508E96B783A9D894F6702BFA", "hash_ssdeep": "3072:o3mb3+xAIlxg9FTtLPQ0GGm47pylFHYcXZj5f0g8R:o3mb3+xNlx0T1PPm47pOFZZj5f0g8", "hash_imp": "C1EDC431CD345F0A0F32019895D13FCE", "hash_pesha1": "D871D005C0231F4A849A873805E32F8F48E46631", "hash_pe256": "5186EA897F6A878A05A1C6F4761AFE4AD621B4B522929430289B71B4E0CD4CB8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command Line Interface for Microsoft Volume Shadow Copy Service ", "meta_original_filename": "VSSADMIN.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8c1fabcc2196e4d096b7d155837c5f699ad7f55edbf84571e4f8e03500b7a8b0/detection", "output": "vssadmin 1.1 - Volume Shadow Copy Service administrative command-line tool\r\n(C) Copyright 2001-2013 Microsoft Corp.\r\n\r\nError: Invalid command.\r\n \r\n---- Commands Supported ----\r\n\r\nDelete Shadows - Delete volume shadow copies\r\nList Providers - List registered volume shadow copy providers\r\nList Shadows - List existing volume shadow copies\r\nList ShadowStorage - List volume shadow copy storage associations\r\nList Volumes - List volumes eligible for shadow copies\r\nList Writers - List subscribed volume shadow copy writers\r\nResize ShadowStorage - Resize a volume shadow copy storage association\r\n", "runtime_modules": [ "C:\\Windows\\system32\\vssadmin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "VSSVC.exe-2A6BB06A14D810601F8CA02A98A3E16F": { "file_name": "VSSVC.exe", "file_path": "C:\\Windows\\system32\\VSSVC.exe", "hash_md5": "2A6BB06A14D810601F8CA02A98A3E16F", "hash_sha1": "D2720CDBF4A96A21266FBEEC4D79182D983D979B", "hash_sha256": "0BA31F101507CD279108F7845AA7EF38B7ADC2E595921F6A1C09954A2315409D", "hash_sha384": "0345C6CCCDA1C5C90B4417EC8BCF2B1067811454F1EF4C820D4E0A6B4AE56AEAF959CE6C0896716DAB45451B03AC7785", "hash_sha512": "E541523ABF25744A5A2AB6D9B827AE69A88A1942E1203D7221F118377E99FC67BD48A6775B0244926693B0ACBE8FD207085EF7AF36D743CC5893BC2288B82253", "hash_ssdeep": "24576:h4A9Q+MAmdFWAfPf0irTqAs8ndjGUbXCZvyg3cvVQv0b/:hAAmfXfVrxs8dSYCZvygMNQ8b/", "hash_imp": "DBAF0083B9DB3B427241890602C826A3", "hash_pesha1": "BD5CE9B6276D857BCF92BE0D622E66E1F1BEF5FC", "hash_pe256": "489066B79878A674078F317AB243630BFACD290011323BA9578643AE58F1BEFC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Volume Shadow Copy Service", "meta_original_filename": "VSSVC.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0ba31f101507cd279108f7845aa7ef38b7adc2e595921f6a1c09954a2315409d/detection", "runtime_modules": [ "C:\\Windows\\system32\\VSSVC.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "w32tm.exe-81A82132737224D324A3E8DA993E2FB5": { "file_name": "w32tm.exe", "file_path": "C:\\Windows\\system32\\w32tm.exe", "hash_md5": "81A82132737224D324A3E8DA993E2FB5", "hash_sha1": "EF9F88FE8E2BCD8086860092BFB45BC58E9726EE", "hash_sha256": "88F14176C848ADCE732FE1DB67C2D95CD495AC71CAED5D137E0108332509042F", "hash_sha384": "F5B146B0495133C448088A01138F8929B5D1A8B5188BF58D88133E8188E7413077BC33AD43B8AE3CA12A36BC517028F6", "hash_sha512": "AF918D4343E6E00050092BE047D00F92405A71113E270E780D75500AFE5C077419020C08A6ED4F6EAEE9E771954E1F9A953157EA90FBB384ECA8EA6DE62B9480", "hash_ssdeep": "3072:Ko44whoErXpbSSE1mfgQkinoN6nuiepP3ddcIm7EZZo9lSv:/44wnrIWhnuZpPXmoZZo9lS", "hash_imp": "D825DE3A7A0BA78C5D631CAFDFBE9F2A", "hash_pesha1": "B41D1DAF60271B1EC87EE160781DCD51A2245B80", "hash_pe256": "7508DE292B477A5CF929E1D7E07DBC8F8B09488C64E259E229B693C18819C44D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Time Service Diagnostic Tool", "meta_original_filename": "w32time.dll.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/88f14176c848adce732fe1db67c2d95cd495ac71caed5d137e0108332509042f/detection", "output": "w32tm [/? | /register | /unregister ]\r\n ? - this help screen.\r\n register - register to run as a service and add default\r\n configuration to the registry.\r\n unregister - unregister service and remove all configuration\r\n information from the registry.\r\n\r\nw32tm /monitor [/domain:<domain name>]\r\n [/computers:<name>[,<name>[,<name>...]]]\r\n [/threads:<num>] [/ipprotocol:<4|6>] [/nowarn]\r\n domain - specifies which domain to monitor. If no domain name\r\n is given, or neither the domain nor computers option is\r\n specified, the default domain is used. This option may be\r\n used more than once.\r\n computers - monitors the given list of computers. Computer\r\n names are separated by commas, with no spaces. If a name is\r\n prefixed with a '*', it is treated as an AD PDC. This option\r\n may be used more than once.\r\n threads - how many computers to analyze simultaneously. The\r\n default value is 3. Allowed range is 1-50.\r\n ipprotocol - specify the IP protocol to use. The default is\r\n to use whatever is available.\r\n nowarn - skip warning message.\r\n\r\nw32tm /ntte <NT time epoch>\r\n Convert a NT system time, in (10^-7)s intervals from 0h 1-Jan 1601,\r\n into a readable format.\r\n\r\nw32tm /ntpte <NTP time epoch>\r\n Convert an NTP time, in (2^-32)s intervals from 0h 1-Jan 1900, into\r\n a readable format.\r\n\r\nw32tm /resync [/computer:<computer>] [/nowait] [/rediscover] [/soft]\r\n Tell a computer that it should resynchronize its clock as soon\r\n as possible, throwing out all accumulated error statistics.\r\n computer:<computer> - computer that should resync. If not\r\n specified, the local computer will resync.\r\n nowait - do not wait for the resync to occur;\r\n return immediately. Otherwise, wait for the resync to\r\n complete before returning.\r\n rediscover - redetect the network configuration and rediscover\r\n network sources, then resynchronize.\r\n soft - resync utilizing existing error statistics. Not useful,\r\n provided for compatibility.\r\n\r\nw32tm /stripchart /computer:<target> [/period:<refresh>]\r\n [/dataonly] [/samples:<count>] [/packetinfo] [/ipprotocol:<4|6>] [/rdtsc]\r\n Display a strip chart of the offset between this computer and\r\n another computer.\r\n computer:<target> - the computer to measure the offset against.\r\n period:<refresh> - the time between samples, in seconds. The\r\n default is 2s\r\n dataonly - display only the data, no graphics.\r\n samples:<count> - collect <count> samples, then stop. If not\r\n specified, samples will be collected until Ctrl-C is pressed.\r\n packetinfo - print out NTP packet response message.\r\n ipprotocol - specify the IP protocol to use. The default is \r\n to use whatever is available.\r\n rdtsc - display the TSC values and time offset data in CSV format.\r\n The output displays TSC and FILETIME values captured before the \r\n NTP request is sent, TSC value after an NTP response is received\r\n along with NTP roundtrip and time offset values.\r\n\r\n\r\nw32tm /config [/computer:<target>] [/update]\r\n [/manualpeerlist:<peers>] [/syncfromflags:<source>]\r\n [/LocalClockDispersion:<seconds>]\r\n [/reliable:(YES|NO)]\r\n [/largephaseoffset:<milliseconds>]\r\n computer:<target> - adjusts the configuration of <target>. If not\r\n specified, the default is the local computer.\r\n update - notifies the time service that the configuration has\r\n changed, causing the changes to take effect.\r\n manualpeerlist:<peers> - sets the manual peer list to <peers>,\r\n which is a space-delimited list of DNS and/or IP addresses.\r\n When specifying multiple peers, this switch must be enclosed in\r\n quotes.\r\n syncfromflags:<source> - sets what sources the NTP client should\r\n sync from. <source> should be a comma separated list of\r\n these keywords (not case sensitive):\r\n MANUAL - sync from peers in the manual peer list\r\n DOMHIER - sync from an AD DC in the domain hierarchy\r\n NO - sync from none\r\n ALL - sync from both manual and domain peers \r\n LocalClockDispersion:<seconds> - configures the accuracy of the\r\n internal clock that w32time will assume when it can't acquire \r\n time from its configured sources. \r\n reliable:(YES|NO) - set whether this machine is a reliable time source.\r\n This setting is only meaningful on domain controllers. \r\n YES - this machine is a reliable time service\r\n NO - this machine is not a reliable time service\r\n largephaseoffset:<milliseconds> - sets the time difference between \r\n local and network time which w32time will consider a spike. \r\n\r\nw32tm /tz\r\n Display the current time zone settings.\r\n\r\nw32tm /dumpreg [/subkey:<key>] [/computer:<target>]\r\n Display the values associated with a given registry key.\r\n The default key is HKLM\\System\\CurrentControlSet\\Services\\W32Time\r\n (the root key for the time service).\r\n subkey:<key> - displays the values associated with subkey <key> \r\n of the default key.\r\n computer:<target> - queries registry settings for computer <target>.\r\n\r\nw32tm /query [/computer:<target>] \r\n {/source | /configuration | /peers | /status} \r\n [/verbose]\r\n Display a computer's windows time service information.\r\n computer:<target> - query the information of <target>. If not\r\n specified, the default is the local computer.\r\n source: display the time source.\r\n configuration: display the configuration of run-time and where \r\n the setting comes from. In verbose mode, display the undefined \r\n or unused setting too.\r\n peers: display a list of peers and their status.\r\n status: display windows time service status.\r\n verbose: set the verbose mode to display more information.\r\n\r\nw32tm /debug {/disable | {/enable /file:<name> /size:<bytes> /entries:<value>\r\n [/truncate]}} \r\n Enable or disable local computer windows time service private log.\r\n disable: disable the private log.\r\n enable: enable the private log.\r\n file:<name> - specify the absolute filename.\r\n size:<bytes> - specify the maximum size for circular logging.\r\n entries:<value> - contains a list of flags, specified by number and\r\n separated by commas, that specify the types of information that \r\n should be logged. Valid numbers are 0 to 300. A range of numbers \r\n is valid, in addition to single numbers, such as 0-100,103,106. \r\n Value 0-300 is for logging all information.\r\n truncate: truncate the file if it exists.\r\n\r\nw32tm /leapseconds /getstatus [/verbose]\r\n Display the status of leap seconds on the local machine.\r\n verbose: Set the verbose mode to display more information.\n", "runtime_modules": [ "C:\\Windows\\system32\\w32tm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "WaaSMedicAgent.exe-911D9D803989FA9D6BC44A25312DB06E": { "file_name": "WaaSMedicAgent.exe", "file_path": "C:\\Windows\\system32\\WaaSMedicAgent.exe", "hash_md5": "911D9D803989FA9D6BC44A25312DB06E", "hash_sha1": "B3CB6D9AFACFAE1FC1E3C20A461EAADE72EED4FB", "hash_sha256": "6E43FD39C25B6B216E8ACF72F8EF420B811506DFAF0E6F23E21F4708BE36F048", "hash_sha384": "6543A147D692374B18FBF9056B5449B87D48F756EF2243F43292755923C7694C2C8F15D6D933AAAA1E31D05895505289", "hash_sha512": "8072D76CAC207EBFAFF0BDC38CA7AE951A3049AA7641F1B0519999280DC6787E3576E224E4502DD9A529FAFDD0C42920EC01B5E4635BD8FC0E3006E9008D9F42", "hash_ssdeep": "1536:EZ+BrC19u2QuxXLyTaTa6nFOMIhpz7ifJfTfgTBXSXg55GS1a7jHi977:E0hC1c25JLO6nFkJ2fJrfgTBXEg5Z1aw", "hash_imp": "9DAE31EFDD1938D98CFED21A148FAC3B", "hash_pesha1": "D94C75A1C24BFED5B8FD84F7C7A80EDD298F5B45", "hash_pe256": "DDB24616238179B251B428FB4B7262D52769DB539329BB5CEBF81D5DC2BB1108", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WaasMedic Agent Exe", "meta_original_filename": "WaasMedicAgent.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/6e43fd39c25b6b216e8acf72f8ef420b811506dfaf0e6f23e21f4708be36f048/detection", "runtime_modules": [ "C:\\Windows\\system32\\WaaSMedicAgent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "waitfor.exe-65F95B6F9A894116AF21D19A8CF54C34": { "file_name": "waitfor.exe", "file_path": "C:\\Windows\\system32\\waitfor.exe", "hash_md5": "65F95B6F9A894116AF21D19A8CF54C34", "hash_sha1": "97F016A385FC4D533AE46F7F7C98A91B175934C3", "hash_sha256": "1ED4BDFBBE7E27856D1B3D6D743EFAB72E5727BAE7B6C02492F8890C97AE602F", "hash_sha384": "C34C2EC91CBF91B7F89DF4481D7464B34EFE9DF1385FE27B0CF8B6F6A2BA67C2588A6AB85BEF32C873C04D97290836BE", "hash_sha512": "650DCC22A207FFA42135CF95F3B47ABFCA6CAE63989E81D382A3F191718075927224783FFC2BBF4B54D8ECB801786086CD0B022E07D98FFF09D34BA9742021D5", "hash_ssdeep": "768:xiRUemA7ksCE/cil7ko1YllhHdoggsnf7bdHHKGrbinxPO1:8vZv/cil7LRgznT5HHKMsxW1", "hash_imp": "8275F58C1058DF4BAFF590DA991AC78C", "hash_pesha1": "A3D25E839F2B615E6365E3A33260D1B6CC4BDDD1", "hash_pe256": "DB1532FFA7AD1DC65A5DBF2920FB9656AE8126EA3A41F41E4CB53735958468B1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "waitfor - wait/send a signal over a network", "meta_original_filename": "waitfor.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1ed4bdfbbe7e27856d1b3d6d743efab72e5727bae7b6c02492f8890c97ae602f/detection", "output": "\r\nWaitFor has two ways of working: \r\n\r\nSyntax 1: to send a signal\r\n WAITFOR [/S system [/U user [/P [password]]]] /SI signal\r\n\r\nSyntax 2: to wait for a signal\r\n WAITFOR [/T timeout] signal \r\n\r\nDescription:\r\n This tool sends, or waits for, a signal on a system. When /S is not\r\n specified, the signal will be broadcasted to all the systems in a\r\n domain. If /S is specified, then the signal will be sent only\r\n to the specified system.\r\n\r\nParameter List:\r\n /S system Specifies remote system to send signal to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given user context.\r\n\r\n /SI Sends the signal across the net to waiting machines\r\n\r\n /T timeout Number of seconds to wait for signal. Valid range\r\n is 1 - 99999. Default is to wait forever for signal.\r\n\r\n signal The name of the signal to wait for or to send.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE: A system can wait for multiple unique signal names.\r\n The signal name cannot exceed 225 characters and cannot\r\n contain characters other than a-z, A-Z, 0-9 and ASCII \r\n characters in the range 128-255.\r\n\r\nExamples:\r\n WAITFOR /?\r\n WAITFOR SetupReady \r\n WAITFOR CopyDone /T 100 \r\n WAITFOR /SI SetupReady \r\n WAITFOR /S system /U user /P password /SI CopyDone\r\n", "error": "ERROR: The signal cannot contain characters other than a-z, A-Z, 0-9 \r\nand ASCII characters in the range 128-255.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\waitfor.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\waitfor.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "WallpaperHost.exe-37DFAA45EA5706964A01AF082B831BDA": { "file_name": "WallpaperHost.exe", "file_path": "C:\\Windows\\system32\\WallpaperHost.exe", "hash_md5": "37DFAA45EA5706964A01AF082B831BDA", "hash_sha1": "C14E27C3A8EC356FE239FE0238E0C8B42132EEE2", "hash_sha256": "D3CF86E66420B2DA75B0BE38FA78FD8E41F01AD827F9D5EEBDA59182D394968C", "hash_sha384": "64BA9AD9BFF08FF7EB533AC609C011EFBF76C043F97F7F852F1A063325A246E2E96FFF9D432CA72F5507921FAD4A79AE", "hash_sha512": "40CA4E5014D9FCA3569823C139309CE2D7871054F1A7D875125D6E447A8439DE56BCA801416EE7C1AC2A4579151E5D07842EE52D04DA80EC7D6BAAF3C6406550", "hash_ssdeep": "384:n+Yx9hgLjTEWKIoGtxi5wZkTgEfJ7y7xUietlChvCauuphNvUhytTbWK0FW2:Xx9GLjT7tUAkEEfJ7y7xheDCtCuZvUhV", "hash_imp": "A1F991B4FDC56F63965DBE7640A1BE21", "hash_pesha1": "D642F9E709ADE1206D139287CBA4AC7C13583B8B", "hash_pe256": "D1E980CB4ED1AB895C7484B488D8EAE8D9F3F295F417C44AC6D2A54230C534BB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Wallpaper Host Process", "meta_original_filename": "WallpaperHost.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/d3cf86e66420b2da75b0be38fa78fd8e41f01ad827f9d5eebda59182d394968c/detection", "runtime_modules": [ "C:\\Windows\\system32\\WallpaperHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "wbadmin.exe-14833578D461729CC21CE9AF311EEC1F": { "file_name": "wbadmin.exe", "file_path": "C:\\Windows\\system32\\wbadmin.exe", "hash_md5": "14833578D461729CC21CE9AF311EEC1F", "hash_sha1": "2EED621A1F8D6E99B91D2294C8F3EE7BB60D1573", "hash_sha256": "382B033D559B33D801F77776F4D6ECB180703C14A3CE5B91277A5B589B2F8B18", "hash_sha384": "9AF2F99ADFCA212458EFC51D321BCA5266048990F6505B69ECD7C3E30855DB23EA32949561352B3C9E90E6B0C599261E", "hash_sha512": "DD1854742B76745F150E8C304A9A3DA715FE4C55D8505E1C49FA2C1979A403E79576D178450B43F014C805FBA08F51614127764FD05F2B9AD35C8BEC41F53E80", "hash_ssdeep": "6144:F2qRmqUH1IHdfS08hQ/Cv1Sx4I48OUFfa6/9xkluvAloZNsEI:UqUcdS651ZDZKEI", "hash_imp": "D72A8A096458529EDF54E67F5F212651", "hash_pesha1": "E72EC04F6A3754D2439D66DB7F5B84CB927AE6C1", "hash_pe256": "5CDC83B7A105D1B7B5A0901869A0C166A143A31D9CC6F9106B6B093B36E480D1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command Line Interface for Microsoft BLB Backup", "meta_original_filename": "WBADMIN.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/382b033d559b33d801f77776f4d6ecb180703c14a3ce5b91277a5b589b2f8b18/detection", "output": "wbadmin 1.0 - Backup command-line tool\r\n(C) Copyright Microsoft Corporation. All rights reserved.\r\n\r\n---- Commands Supported ----\r\n\r\nENABLE BACKUP -- Creates or modifies a daily backup schedule.\r\nDISABLE BACKUP -- Disables the scheduled backups.\r\nSTART BACKUP -- Runs a one-time backup.\r\nSTOP JOB -- Stops the currently running backup or recovery \r\n operation.\r\nGET VERSIONS -- Lists details of backups that can be recovered \r\n from a specified location.\r\nGET ITEMS -- Lists items contained in a backup.\r\nGET STATUS -- Reports the status of the currently running \r\n operation.\r\nDELETE BACKUP -- Deletes one or more backups.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\wbadmin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wbengine.exe-9CA1D999F01E0F8AEDDE2CFC187B2C0B": { "file_name": "wbengine.exe", "file_path": "C:\\Windows\\system32\\wbengine.exe", "hash_md5": "9CA1D999F01E0F8AEDDE2CFC187B2C0B", "hash_sha1": "C66192B63E343DF494A5DC2D9EF268FA1126DFC0", "hash_sha256": "5AE95F3F77AAED3067CBA39C5B2CD1790B949027E837B5AF580F2A8D4714FB68", "hash_sha384": "9025F8389C63383683EFC1506D7F3D6ECE763D2623B0E244454669C169DF6C44F127495BC770A51C3D709E1C8A70446D", "hash_sha512": "56AC22606CA58BB32B752DCCE360D68C10E4B27097A3423D6936FF0BD8F94F4537168C9D361F81DABF487EF71E4BF48EE895AAFADC57C77E8D8D8DE87176BED5", "hash_ssdeep": "49152:bjzbr8N77L0toSDJMdZgwaIdzqrDv8Ii:re7yoSFX", "hash_imp": "DCB1AF9EF2E2CA490391D7B29D744188", "hash_pesha1": "6F181B32E130BC69E10DB7A69C498A7218FE705F", "hash_pe256": "3ADEE4854F8FB275C274B61C1D8B60573BDD7D56A73FE6F3103DB443EC37DA79", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Block Level Backup Engine Service EXE", "meta_original_filename": "wbengine.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "The operation timed out", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Windows\\system32\\wbengine.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\VSSAPI.DLL", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\VirtDisk.dll", "C:\\Windows\\System32\\WS2_32.dll" ] }, "wcsetupagent.exe-844A67BE7A242CE50168C2B37C010C7B": { "file_name": "wcsetupagent.exe", "file_path": "C:\\Windows\\system32\\wcsetupagent.exe", "hash_md5": "844A67BE7A242CE50168C2B37C010C7B", "hash_sha1": "5552553879E8354070431FF3CD73FB77493452E8", "hash_sha256": "3749B4F1D866A1552C07E30FDF85BB24A7DF7DC7A4F8E703CF6E23E47CBEA7D2", "hash_sha384": "1906DB4B25CDD17A4E28370FE1668D69A816ED29ABE3CE616B84D0ED88BB018DD2C64210F3179666BFCCE9DFBAD51F4B", "hash_sha512": "DBA63CA5D8E1F3367DABEA911FE334B1B551B6FBBBFEC192EC02DE3D169FAA3832217006281FBFE6CDE6078909EA5594C379948E27B174D9E4DD0B33839CF5F7", "hash_ssdeep": "1536:2M+f49Qox51v/j2ie1vkhPXCesZHW+XUk99P0uf3:9Lv/j2VvMq7vkk99pP", "hash_imp": "0BFC70E7578FC85B8136243B25EA8984", "hash_pesha1": "991AF8BB84FD126B9618A07BE81DD0048FDF4C94", "hash_pe256": "1B8406CE53F41A0E665255648F7C3C2B123C9801D8CB41B0E63FB2995F473104", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Utility VM Setup Agent", "meta_original_filename": "wcsetupagent.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3749b4f1d866a1552c07e30fdf85bb24a7df7dc7a4f8e703cf6e23e47cbea7d2/detection", "runtime_modules": [ "C:\\Windows\\system32\\wcsetupagent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\samcli.dll" ] }, "wecutil.exe-B78753F05E058638CD0A0169D8F69EF7": { "file_name": "wecutil.exe", "file_path": "C:\\Windows\\system32\\wecutil.exe", "hash_md5": "B78753F05E058638CD0A0169D8F69EF7", "hash_sha1": "C6EFF962AD0CB28537009FB8AA025A59EAC70604", "hash_sha256": "8270BB4468B3FC5C2EA6FE92A550DE517992DD2F84E195124CFEF358F1C8EA5A", "hash_sha384": "EC4F353984DF4ADCCD2FE57CB8D15D1A5FE4F0209B5F1374F3EB4D257F3E4DC9F917D9AB38DF7A105C3FCEC4AC60D6EE", "hash_sha512": "D4AE7C00F70DFA9E3AB7847D9A51D7E65652D11D4D80C2808F090F714EC341A31B8106D1412794E390577ED7C38A18CDA4BDAF58FC621C40A22A717BE867FCA8", "hash_ssdeep": "3072:M52dNgyz5GK+mn7TmNbyCfu+h+UV86Ew0yQw8tq:M52d/sZBbfZh1B0yQw8t", "hash_imp": "B72EE51C5FE65846BB96655320BB4A02", "hash_pesha1": "7964F20F2D736F119CBFFC96004E7AB69F2AABFF", "hash_pe256": "96F68AB623784F88188692AFA8C67ABDEB6A1EFD0420E1907FD1A83590DF605D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Collector Command Line Utility", "meta_original_filename": "WECUTIL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8270bb4468b3fc5c2ea6fe92a550de517992dd2f84e195124cfef358f1c8ea5a/detection", "output": "Windows Event Collector Utility\r\n\r\nEnables you to create and manage subscriptions to events forwarded from remote\r\nevent sources that support WS-Management protocol.\r\n\r\nUsage:\r\n\r\nYou can use either the short (i.e. es, /f) or long (i.e. enum-subscription, /format)\r\nversion of the command and option names. Commands, options and option values are\r\ncase-insensitive.\r\n\r\n(ALL UPPER-CASE = VARIABLE)\r\n\r\nwecutil COMMAND [ARGUMENT [ARGUMENT] ...] [/OPTION:VALUE [/OPTION:VALUE] ...]\r\n\r\nCommands:\r\n\r\nes (enum-subscription) List existent subscriptions.\r\ngs (get-subscription) Get subscription configuration.\r\ngr (get-subscriptionruntimestatus) Get subscription runtime status.\r\nss (set-subscription) Set subscription configuration.\r\ncs (create-subscription) Create new subscription.\r\nds (delete-subscription) Delete subscription.\r\nrs (retry-subscription) Retry subscription.\r\nqc (quick-config) Configure Windows Event Collector service.\r\n\r\nCommon options:\r\n\r\n/h|? (help)\r\nGet general help for the wecutil program.\r\n\r\nwecutil { -help | -h | -? }\r\n\r\nFor arguments and options, see usage of specific commands:\r\n\r\nwecutil COMMAND -?\r\n", "error": "Command help is not supported. Error = 0x57.\r\nThe parameter is incorrect.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\wecutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "WerFault.exe-58A5ED5D96E2C671CFC69808E1F7B4FA": { "file_name": "WerFault.exe", "file_path": "C:\\Windows\\system32\\WerFault.exe", "hash_md5": "58A5ED5D96E2C671CFC69808E1F7B4FA", "hash_sha1": "B647E85161505E59B0BE3659A6DA4FED9F7FDED6", "hash_sha256": "5E6540869A48565787573F9E6ED168D3074ADA48ED1B732C1615C980AF711F34", "hash_sha384": "3E98BB8AFBCA22B9D9FDF63BCA64861DD319DA9C36F72A364DBDFCA55C8A5E047FC3499D06D32A9AAF21CE8C14B7DDEE", "hash_sha512": "B470B0F3449BB304BAD04A88C78EB91B5023C246088B5830B013D861C0FF932EDAE57CE1976D61676FE91DD90A058CDB3ED048C6EFFF09964D6ED609F1E057A1", "hash_ssdeep": "12288:J09H9MkWWUV8mKTPKbO1CR/OzvlPzc2Hywa:J06HPV8musOzvlPzcyha", "hash_imp": "A8411DCFB6906C782549D77E5571DC7E", "hash_pesha1": "DC6D34CBE5268633BDE83150D9FA78308380297F", "hash_pe256": "9FFD4126868D24A6F4545E71AF84AB38AF392541A3AE8A67F20953F6A598906E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Problem Reporting", "meta_original_filename": "WerFault.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5e6540869a48565787573f9e6ed168d3074ada48ed1b732c1615c980af711f34/detection", "runtime_modules": [ "C:\\Windows\\system32\\WerFault.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\CRYPTSP.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\wer.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\system32\\faultrep.dll" ] }, "WerFaultSecure.exe-DE56B2A5785ED06A8D1A6EC23F9FDF37": { "file_name": "WerFaultSecure.exe", "file_path": "C:\\Windows\\system32\\WerFaultSecure.exe", "hash_md5": "DE56B2A5785ED06A8D1A6EC23F9FDF37", "hash_sha1": "EEE23BC0F845739688BC36B7A4E0C218F918439F", "hash_sha256": "B3003748290692E15B176BF54DED2220017E412624D3184CFCBB61216534595E", "hash_sha384": "E18B6E764D7ABFF09F0C81ACE94CCE2AB10348866762927CE7B5810A614188F823687AD894289F5D768F81DEC2EEC9E8", "hash_sha512": "46AD3CB5FB7B2C3335034EFCFE0D03C3B0C61FE8C0B043D8F501B522FEF48DC13FA2AD2F5D54F58F630AC4ABAFECEDDBD24669FF84B7BA3E28DA757EEB562C40", "hash_ssdeep": "3072:iUZH/OJkaZUkkKqj7lQWamHFJ+yC3pwRb6JPqB604HHy7hRCd39vjKdR:iE/OJfUkkKY+OCVJyB60OHyLC7vuj", "hash_imp": "238B416AE1929D60DF85CAC4307083D4", "hash_pesha1": "8BEE16A7BD1D6FB1936B59B91CCBFB4AFF373696", "hash_pe256": "03F7150C8B729FD631FDA3E93CF855E710C41D596E88F7DC67F7F5373F8DA725", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Fault Reporting", "meta_original_filename": "WerFaultSecure.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b3003748290692e15b176bf54ded2220017e412624d3184cfcbb61216534595e/detection" }, "wermgr.exe-DF2AD28AC6BEDF07422537CCA6F1E637": { "file_name": "wermgr.exe", "file_path": "C:\\Windows\\system32\\wermgr.exe", "hash_md5": "DF2AD28AC6BEDF07422537CCA6F1E637", "hash_sha1": "519C69EB52AACFF9E2123DD36C7F547EF918A274", "hash_sha256": "EDCE588F879E657B24037DD0AE3233C97CE9B0E4A115C62BBF00C983EF288A85", "hash_sha384": "0A779DD954D3526782F06129F317396CA0D78AA09F93264A32026171542A20085B7E28F8BE550EAA515365EBD8C90FD4", "hash_sha512": "5247220ED707B6BD7C866AE432276B1E5B11B61E444E13ECEC257C709F54F00A24C5DCBB1D23DDE3F061B7DE4913E6EA117D2FD0D26D1F3C3DBA015CAA87CADD", "hash_ssdeep": "3072:CteAK7APRbQ9Dijb4Z0o+AeuQEjusUlOsFJ+yC3pwRb6JPqB604HHy7hRCd39vRG:gemZj8JecusUlO/VJyB60OHyLC7vSj", "hash_imp": "70F5990F8FE8FCFC99DCF4D791F596C8", "hash_pesha1": "F801E7F188A184B71D610EE759BA835AE8800203", "hash_pe256": "69435ABA5326511BF33683175A79F20DCB1A42D72EDDC17E79C43B501F0131FF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Problem Reporting", "meta_original_filename": "WerMgr", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.685 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.685", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/edce588f879e657b24037dd0ae3233c97ce9b0e4a115c62bbf00c983ef288a85/detection", "runtime_modules": [ "C:\\Windows\\system32\\wermgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\wer.dll" ] }, "wevtutil.exe-B7371A463B711C28DEA387E9EFE90855": { "file_name": "wevtutil.exe", "file_path": "C:\\Windows\\system32\\wevtutil.exe", "hash_md5": "B7371A463B711C28DEA387E9EFE90855", "hash_sha1": "552EB2AECB4B52FF6650F94BC949FCE05576C161", "hash_sha256": "4A727688B939E08C26064EA08DCFF29B3D4608D28820874030524F79B4B1CCA8", "hash_sha384": "51D747513F44472D2FC7ABFA119AFEE19E2B62629B8F44A7B71D043B56A28F40D4382488801D62159F3895DC17C4C86B", "hash_sha512": "BA989B608CD7867137B73E9082D5C8E8FD8B85CF83201D2CF87C891460D517CC0BB9CE893237710B6F5C3F4D62B0470832967D1CA47F1B5FDCF6D1B7097ED688", "hash_ssdeep": "6144:3cg4TR2QnhitEh08GdHyo+s38AMd3LitqM:3f4TR2QnUc08od8nut", "hash_imp": "D3310B6271278C48FE7AE9F4AD5259B6", "hash_pesha1": "1083BACDFC1EE2E2C60810150F6DA7D8828F88EB", "hash_pe256": "987890A48276DEFF86256F8BFCCFCFAF63D854CA510C066D0545874EBE40E41D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Eventing Command Line Utility", "meta_original_filename": "wevtutil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4a727688b939e08c26064ea08dcff29b3d4608d28820874030524f79b4b1cca8/detection", "output": "Windows Events Command Line Utility.\r\n\r\nEnables you to retrieve information about event logs and publishers, install\r\nand uninstall event manifests, run queries, and export, archive, and clear logs.\r\n\r\nUsage:\r\n\r\nYou can use either the short (for example, ep /uni) or long (for example, \r\nenum-publishers /unicode) version of the command and option names. Commands, \r\noptions and option values are not case-sensitive.\r\n\r\nVariables are noted in all upper-case.\r\n\r\nwevtutil COMMAND [ARGUMENT [ARGUMENT] ...] [/OPTION:VALUE [/OPTION:VALUE] ...]\r\n\r\nCommands:\r\n\r\nel | enum-logs List log names.\r\ngl | get-log Get log configuration information.\r\nsl | set-log Modify configuration of a log.\r\nep | enum-publishers List event publishers.\r\ngp | get-publisher Get publisher configuration information.\r\nim | install-manifest Install event publishers and logs from manifest.\r\num | uninstall-manifest Uninstall event publishers and logs from manifest.\r\nqe | query-events Query events from a log or log file.\r\ngli | get-log-info Get log status information.\r\nepl | export-log Export a log.\r\nal | archive-log Archive an exported log.\r\ncl | clear-log Clear a log.\r\n\r\nCommon options:\r\n\r\n/{r | remote}:VALUE\r\nIf specified, run the command on a remote computer. VALUE is the remote computer \r\nname. Options /im and /um do not support remote operations.\r\n\r\n/{u | username}:VALUE\r\nSpecify a different user to log on to the remote computer. VALUE is a user name\r\nin the form domain\\user or user. Only applicable when option /r is specified.\r\n\r\n/{p | password}:VALUE\r\nPassword for the specified user. If not specified, or if VALUE is \"*\", the user \r\nwill be prompted to enter a password. Only applicable when the /u option is\r\nspecified.\r\n\r\n/{a | authentication}:[Default|Negotiate|Kerberos|NTLM]\r\nAuthentication type for connecting to remote computer. The default is Negotiate.\r\n\r\n/{uni | unicode}:[true|false]\r\nDisplay output in Unicode. If true, then output is in Unicode. \r\n\r\nTo learn more about a specific command, type the following:\r\n\r\nwevtutil COMMAND /?\r\n", "error": "Command help is not supported.\r\nThe parameter is incorrect.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\wevtutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wextract.exe-56E501E3E49CFDE55EB1CAABE6913E45": { "file_name": "wextract.exe", "file_path": "C:\\Windows\\system32\\wextract.exe", "hash_md5": "56E501E3E49CFDE55EB1CAABE6913E45", "hash_sha1": "AB2399CBF17DBEE7B302BEA49E40D4CEE7CAEA76", "hash_sha256": "FBB6DC62ABEEB222B49A63F43DC6EEA96F3D7E9A8DA55381C15D57A5D099F3E0", "hash_sha384": "DF9295D3849683F921F7B5F124DEDE5DB5C59A9EAEF06EB05FD7406195E0C103642622E0A6B0A0F0E8F6891D7BE61529", "hash_sha512": "2B536E86CBD8AB026529BA2C72C0FDA97E9B6F0BC4FD96777024155852670CB41D17937CDE372A44CDBAD3E53B8CD3EF1A4A3EE9B34DFB3C2069822095F7A172", "hash_ssdeep": "3072:fahKyd2n31jcWp1icKAArDZz4N9GhbkUNEk956:fahOddp0yN90vE", "hash_imp": "4CEA7AE85C87DDC7295D39FF9CDA31D1", "hash_pesha1": "831AAD24C3AB453EED39F9D9A40EF9CED6084F3D", "hash_pe256": "C47886C3131CA780CAB701CCE7010BA09AA8E54FAE482C251FDD79D930414DD9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Win32 Cabinet Self-Extractor ", "meta_original_filename": "WEXTRACT.EXE .MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "1/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/fbb6dc62abeeb222b49a63f43dc6eea96f3d7e9a8da55381c15d57a5d099f3e0/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\wextract.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wextract.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "WFS.exe-7C1E8C5382FF4F55BF242B0377DA3EC5": { "file_name": "WFS.exe", "file_path": "C:\\Windows\\system32\\WFS.exe", "hash_md5": "7C1E8C5382FF4F55BF242B0377DA3EC5", "hash_sha1": "27AEB21948BB14B02B8C9D2A8839E36856B1FB5C", "hash_sha256": "3524B83ACFF7070143DAE54426FCF5B3A83F3BCFB0CBFD1CC96E2F9002E1F4F0", "hash_sha384": "1CDA4576FCB7EF7A8B9FE58348093D255757C58BF92164322AACD92DF6EEC33165DA050608F99E89A3BAA30B8B95F7A6", "hash_sha512": "C995737C458AA771F88A81588F4B6D5E684F239E52A336950DB27CE74E652969A7E0434076E48460698298427B9323493B6E9FE9885C837E50B8E98A0D503F1E", "hash_ssdeep": "12288:W5jgrWR+su5Csep5Cv6x+KTMpbphYc2rP3xg5WAylk/++xt4vFe:O94SsZv6sKTMZ2K5WAd/YvFe", "hash_imp": "0C0F99E9CC374A35F58EA4DFD6D0F32A", "hash_pesha1": "80FE3069E0FAFE0270E8204F726050FF86FF57E6", "hash_pe256": "D7630C462769E44F70B06FD19C60C2521AD9A40F5831C2AEC7CB38F628D5B5A0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Fax and Scan", "meta_original_filename": "ClientConsole.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.508 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.508", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3524b83acff7070143dae54426fcf5b3a83f3bcfb0cbfd1cc96e2f9002e1f4f0/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\WFSR.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Users\\user\\AppData\\Local\\Temp\\FXSAPIDebugLogFile.txt": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\scansetting.dll.mui": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_16.db": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\WFS.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\ole32.dll" ], "runtime_window_title": "Windows Fax and Scan" }, "where.exe-3CF958B0F63FB1D74F7FCFE14B039A58": { "file_name": "where.exe", "file_path": "C:\\Windows\\system32\\where.exe", "hash_md5": "3CF958B0F63FB1D74F7FCFE14B039A58", "hash_sha1": "37DB3A31AE73538B9887F6E537F17CF49BBC3E3C", "hash_sha256": "A19F7B783BC5611095D577F5ECCC12069CA2B5E92BBE37F415429BB72C09792C", "hash_sha384": "AC0875D4E96AB610032EB01C7AE27F5A96FCE83673BF935ACA9C6D20ABF9FF5CB52E1F478F1F63532E242A6FE8D37B57", "hash_sha512": "7DAE44CC54B59A951D1F93E3426B76DD27FE88CFB374D0CD8861AF8D4CDE1116673829A8877DE70F27F4C5A3877DB728D64E9A968EBEA55359B1ADDB9173A6A4", "hash_ssdeep": "768:L/lCZBqFV1UILaTYl+oJD6Fnv0DkxkbRG565ygKWkJ46RQ3/G8QDDxOB6G:RzV1bCYl+oJD6F8wA6uyRJ46RQ3/GJvU", "hash_imp": "1B253A651AEF9DCAAFF94AFE777011D1", "hash_pesha1": "757C78DCF7E1143D9B5F77B6E782E494F5E80B57", "hash_pe256": "862EC1F760452BD9FAA0B03A3036C35F9BC1A0A8B35BE937D708A434662DCA9B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Where - Lists location of files", "meta_original_filename": "where.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a19f7b783bc5611095d577f5eccc12069ca2b5e92bbe37f415429bb72c09792c/detection", "output": "\r\nWHERE [/R dir] [/Q] [/F] [/T] pattern...\r\n\r\nDescription:\r\n Displays the location of files that match the search pattern.\r\n By default, the search is done along the current directory and\r\n in the paths specified by the PATH environment variable.\r\n\r\nParameter List:\r\n /R Recursively searches and displays the files that match the\r\n given pattern starting from the specified directory.\r\n\r\n /Q Returns only the exit code, without displaying the list\r\n of matched files. (Quiet mode)\r\n\r\n /F Displays the matched filename in double quotes.\r\n\r\n /T Displays the file size, last modified date and time for all\r\n matched files.\r\n\r\n pattern Specifies the search pattern for the files to match.\r\n Wildcards * and ? can be used in the pattern. The\r\n \"$env:pattern\" and \"path:pattern\" formats can also be\r\n specified, where \"env\" is an environment variable and\r\n the search is done in the specified paths of the \"env\"\r\n environment variable. These formats should not be used\r\n with /R. The search is also done by appending the\r\n extensions of the PATHEXT variable to the pattern.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE: The tool returns an error level of 0 if the search is\r\n successful, of 1 if the search is unsuccessful and\r\n of 2 for failures or errors.\r\n\r\nExamples:\r\n WHERE /?\r\n WHERE myfilename1 myfile????.*\r\n WHERE $windir:*.* \r\n WHERE /R c:\\windows *.exe *.dll *.bat \r\n WHERE /Q ??.??? \r\n WHERE \"c:\\windows;c:\\windows\\system32:*.dll\"\r\n WHERE /F /T *.dll \r\n", "error": "ERROR: Invalid argument or option - '/h'.\r\nType \"WHERE /?\" for usage help.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\where.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "whoami.exe-A4A6924F3EAF97981323703D38FD99C4": { "file_name": "whoami.exe", "file_path": "C:\\Windows\\system32\\whoami.exe", "hash_md5": "A4A6924F3EAF97981323703D38FD99C4", "hash_sha1": "1915FBFDB73FDD200C47880247ACDDE5442431A9", "hash_sha256": "1D4902A04D99E8CCBFE7085E63155955FEE397449D386453F6C452AE407B8743", "hash_sha384": "3B13C11D92F1081BBABC199F32BBAA506B0C6917C4FBA93841DC32CDCFB8B48DEA2142CD6F5D7964EEEF2FAB25A5C4B9", "hash_sha512": "90A556B98C1FDDBC862E851C560BF57B2166572C1425AD624C7ADE54073012F0CF84FD1E6047015FF2CEEA96806AC8AF2BBA59B1F86F80ADF9C46A95CFD22262", "hash_ssdeep": "1536:DOG7Cm6WrNJNiQZcQsfpkb+xssmUN7h8QdWNjhuL/2IR21oxMnI:qG7X6eJo2Tb+xssmurkpIU1oxZ", "hash_imp": "7FF0758B766F747CE57DFAC70743FB88", "hash_pesha1": "1849ACA53AB1A55D87601CFCFF12BBD1BD464F78", "hash_pe256": "82B7D0D03587EDDDC1D42B365648062793C5DBAEA751184D3C2BAC94219B30E4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "whoami - displays logged on user information", "meta_original_filename": "whoami.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1d4902a04d99e8ccbfe7085e63155955fee397449d386453f6c452ae407b8743/detection", "output": "\r\nWhoAmI has three ways of working: \r\n\r\nSyntax 1:\r\n WHOAMI [/UPN | /FQDN | /LOGONID]\r\n\r\nSyntax 2:\r\n WHOAMI { [/USER] [/GROUPS] [/CLAIMS] [/PRIV] } [/FO format] [/NH]\r\n\r\nSyntax 3:\r\n WHOAMI /ALL [/FO format] [/NH]\r\n\r\nDescription:\r\n This utility can be used to get user name and group information\r\n along with the respective security identifiers (SID), claims,\r\n privileges, logon identifier (logon ID) for the current user\r\n on the local system. I.e. who is the current logged on user?\r\n If no switch is specified, tool displays the user name in NTLM\r\n format (domain\\username).\r\n\r\nParameter List:\r\n /UPN Displays the user name in User Principal \r\n Name (UPN) format.\r\n\r\n /FQDN Displays the user name in Fully Qualified \r\n Distinguished Name (FQDN) format.\r\n\r\n /USER Displays information on the current user\r\n along with the security identifier (SID).\r\n\r\n /GROUPS Displays group membership for current user,\r\n type of account, security identifiers (SID)\r\n and attributes.\r\n\r\n /CLAIMS Displays claims for current user,\r\n including claim name, flags, type and values.\r\n\r\n /PRIV Displays security privileges of the current\r\n user.\r\n\r\n /LOGONID Displays the logon ID of the current user.\r\n\r\n /ALL Displays the current user name, groups \r\n belonged to along with the security \r\n identifiers (SID), claims and privileges for \r\n the current user access token.\r\n\r\n /FO format Specifies the output format to be displayed.\r\n Valid values are TABLE, LIST, CSV.\r\n Column headings are not displayed with CSV\r\n format. Default format is TABLE.\r\n\r\n /NH Specifies that the column header should not\r\n be displayed in the output. This is\r\n valid only for TABLE and CSV formats.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n WHOAMI\r\n WHOAMI /UPN\r\n WHOAMI /FQDN \r\n WHOAMI /LOGONID\r\n WHOAMI /USER\r\n WHOAMI /USER /FO LIST\r\n WHOAMI /USER /FO CSV\r\n WHOAMI /GROUPS\r\n WHOAMI /GROUPS /FO CSV /NH\r\n WHOAMI /CLAIMS\r\n WHOAMI /CLAIMS /FO LIST\r\n WHOAMI /PRIV\r\n WHOAMI /PRIV /FO TABLE\r\n WHOAMI /USER /GROUPS\r\n WHOAMI /USER /GROUPS /CLAIMS /PRIV\r\n WHOAMI /ALL\r\n WHOAMI /ALL /FO LIST\r\n WHOAMI /ALL /FO CSV /NH\r\n WHOAMI /?\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"WHOAMI /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\whoami.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wiaacmgr.exe-DE7B66F105366BF8A0265530EDCB58DA": { "file_name": "wiaacmgr.exe", "file_path": "C:\\Windows\\system32\\wiaacmgr.exe", "hash_md5": "DE7B66F105366BF8A0265530EDCB58DA", "hash_sha1": "617F5FDB9E14A5D92D4316EC120672BE7472DF6C", "hash_sha256": "8E1F055CBC375865D0FE2F97186FA66F916594996720CC4627D8D47E1D86E732", "hash_sha384": "8DADBC3EBB5D6F20FB939BBC43C6E1F0D8EBFC38FF91FE7489D7BA0A17F757464029134A43EE3E180185211BFBC303A8", "hash_sha512": "A629A7131715B9E1C7606577D07DCA228B98C4259BB59693FFA6CAE2CE6E5C38D7F2328283D4A56FB1FEFA4B98070FB2E61BFABC684A56F6D64A8C1FB037855B", "hash_ssdeep": "3072:e6RbL71i19Y6fXJOoEr5sAmHKy9TmmBo6j:FbLQ19Y6fXJOoEr5eHv9BD", "hash_imp": "A33A978964804D79AED85FB0267A592E", "hash_pesha1": "ED50B7E81B51EDED3DFEA7392C2D2ED4DCACC9DF", "hash_pe256": "54CC4FA8E8E683A22EF5038AC0E5F065A2B56599838D428BD1081B6D6F3FFBE8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Picture Acquisition Wizard", "meta_original_filename": "WIAACMGR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/8e1f055cbc375865d0fe2f97186fa66f916594996720cc4627d8d47e1d86e732/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\System32\\en-US\\wiaacmgr.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\scansetting.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wiaacmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll" ] }, "wiawow64.exe-57672B94BF24E8EC8DCD56F28142F60A": { "file_name": "wiawow64.exe", "file_path": "C:\\Windows\\system32\\wiawow64.exe", "hash_md5": "57672B94BF24E8EC8DCD56F28142F60A", "hash_sha1": "0ED9EDF34AE137E3EF5F6A619E1FA12B0EB9D051", "hash_sha256": "5CBB42D37F3FEA5496598A6FE85405047C7E78697E6FA474353CFEDCAE9883EA", "hash_sha384": "BAF3B9C60B91426F5ED101B546DB2DC74BC59C5AA3E0D31315FBC09A715EAF735BD9CE8590D751B8587FEEF2B4F51DBA", "hash_sha512": "C038A89CA60D0A95DE4C5395F49F07134F63B748F331D02001E0D21DDD8F7454D376E9B0DCBB6166314E5F13BF51880CD540F854FC3C1E755C22C90A0C9DD832", "hash_ssdeep": "768:i5Nl801zjSbUd9GXkb609f9n2iqQ1a2Tb+svBJ:yh5SoCMOQ1aoSsH", "hash_imp": "AEE5239EB39B2A68BBB39BB42EAC0312", "hash_pesha1": "0ABE4AA6F1A1F08D5307109EBA0F7EC980432CFD", "hash_pe256": "8739032D929707A7C99EDB74C95FBFBDF24F63723583FEF3354F3C6B1E7BDA3F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Thunking WIA APIS from 32 to 64 Process", "meta_original_filename": "wiawow64.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5cbb42d37f3fea5496598a6fe85405047c7e78697e6fa474353cfedcae9883ea/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\scansetting.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wiawow64.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll" ] }, "wifitask.exe-65DE048F4B3DD6EC21D8D890038038F1": { "file_name": "wifitask.exe", "file_path": "C:\\Windows\\system32\\wifitask.exe", "hash_md5": "65DE048F4B3DD6EC21D8D890038038F1", "hash_sha1": "66F56714A8139FAF7DDD44F5391D18355ADAD96E", "hash_sha256": "C8F9670069B7D3CBA9BA618720926B8B6BE4B96C466CBB0014F75449A8E0989A", "hash_sha384": "3E3B36C7F62B123EAB2F050F1A4BFE2A472D7766CCA2D7B81FC75504A4556B0F28A5EA0CA8DA701CA51933961E0C103B", "hash_sha512": "2C1DB74C9C392290C12AC6F57D131F98CCEA59300D2FED032267A5A3104B4B01191CB4A0060E56AA3DF66CF0FE8CFF6A34CB360B812E0699052FA0DFEE419286", "hash_ssdeep": "1536:yMc99L6OGXo8VYH7/tLXwtV5ARAzCwgKWHsDaDQnjZpgbPHF/w0ZhmecGp0iK68x:yN6zVYbF0tesnVuPxw0ZhmecGGbdtjPX", "hash_imp": "1C88C23A76315B092F23CEA68A636F07", "hash_pesha1": "7324F7A5B5085F2F4B067D94CC7BFA3B7305B788", "hash_pe256": "90583B0D94C5D8C8A9C6F312833838EA1330DC17B84B4AEDE0FF54BC34040B98", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Wireless Background Task", "meta_original_filename": "WiFiTask.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c8f9670069b7d3cba9ba618720926b8b6be4b96c466cbb0014f75449a8e0989a/detection", "runtime_modules": [ "C:\\Windows\\system32\\wifitask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\CRYPT32.dll" ] }, "wimserv.exe-1E310C46056ACE8AE3C3E947B465DB05": { "file_name": "wimserv.exe", "file_path": "C:\\Windows\\system32\\wimserv.exe", "hash_md5": "1E310C46056ACE8AE3C3E947B465DB05", "hash_sha1": "C8A710EF9DD598B802EDB0E342C997E8CF992E3F", "hash_sha256": "39BA7611E151D75D55DB784ADC001EF23BA88474A4FC223ECEA3F21312D15737", "hash_sha384": "23BF41CF6FE97E3C07D3856C6779AF64896839DCAA10D1CAF7BECD419E35B1DCC26A2D8B8AF8DE6D95E668B9CE1302D2", "hash_sha512": "8B4438CB3EB0C1DC9A585CE6D6AFEA260718A4F0E47E307D65D7C62BAA3D2371A373FB25FE1A842E48422DEB0497100CB283C25439FAD77056C3BEC4FBCC082A", "hash_ssdeep": "12288:7RWf4MEyIeF19bnpfE7DqJBimXiUHvNm2:l1xeZ+PqHim5HvNm2", "hash_imp": "D664C5CCBA7A8DE3C26390C871325E60", "hash_pesha1": "3702CF6C39AA4427A7E1E278E4182329E85AC408", "hash_pe256": "2C0297587D2B17D1D52AB7E8754B116B04B987B3173A8E2648347C4C5F218BD0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Wimfltr v2 extractor", "meta_original_filename": "extractr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/39ba7611e151d75d55db784adc001ef23ba88474a4fc223ecea3f21312d15737/detection", "runtime_modules": [ "C:\\Windows\\system32\\wimserv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "WinBioDataModelOOBE.exe-4F5ABD7281B7782086A970390C824698": { "file_name": "WinBioDataModelOOBE.exe", "file_path": "C:\\Windows\\system32\\WinBioDataModelOOBE.exe", "hash_md5": "4F5ABD7281B7782086A970390C824698", "hash_sha1": "C5DA799DD7FD2DA6C829D23CF53D370670D376F0", "hash_sha256": "0F8FF7B4506B083D87A2759D7959CBE8E8F7485D17DC40FA97327473FCAF113D", "hash_sha384": "ABEEF9A60E90BBC6A1C5C2DB0D72E91897B792A40E47AD66FA159DE500E3A2B9B9694A2FC21AE32E6DF9D5A3B0677D07", "hash_sha512": "47B6FBB37908FFABBFF1BCA52A55978325086FA8F12AC8A2EEA748DC882E2DE878BBD4FAF8608DD088B2C92EE30F2DCCA8D7C2342E9CB2058B567A2669223652", "hash_ssdeep": "1536:ZEZyXaYgpfcmho5TYdb16C70ixioQNFo9pQIa4LDyTTfGF9o:qwxmhS0Xxi5joHQIpHyT7Gk", "hash_imp": "B715BA90BF8C6071611DBD2C43347A2A", "hash_pesha1": "4C6D87432106A6FC043837EA9251A5BEB3F2B379", "hash_pe256": "EB301E35FCBCEF2ECBD584A7EA50F620384AE441FCE73F7BA60523F6A19EFAAF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WinBioDataModel OOBE", "meta_original_filename": "WinBioDataModelOOBE.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0f8ff7b4506b083d87a2759d7959cbe8e8f7485d17dc40fa97327473fcaf113d/detection", "runtime_modules": [ "C:\\Windows\\system32\\WinBioDataModelOOBE.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "Windows.Media.BackgroundPlayback.exe-44F6D9B36D00FD48BE6FD0F2F93307A1": { "file_name": "Windows.Media.BackgroundPlayback.exe", "file_path": "C:\\Windows\\system32\\Windows.Media.BackgroundPlayback.exe", "hash_md5": "44F6D9B36D00FD48BE6FD0F2F93307A1", "hash_sha1": "8F79E5111ECDA7A89552770BB1528732AF64CE21", "hash_sha256": "F1675AEC9BE46208FBAFA4D6BB389F61C89B1F6059E15CA1C4390EBA9F7C03AC", "hash_sha384": "484BFB61760F6317F691FDD4B11BCA3A20F5CA7DD61B7274110AB9AA0798015F08E8481BE388327FAB6B2E56EBAF700A", "hash_sha512": "EE72E9EB80B3AD8C8BC02026FD7D8D7307BBD3F4CC0334A326FC3649897227DFAF9A07D16DE84BD3B792B9784B96848B384D6376D66FA463EF8AFC843158213A", "hash_ssdeep": "192:BIVYCOELtatxHyzLfscOLViBYA8OzyMpJgXGSjqOsJD1h7re0Hm1zaDW+5Wk:BISdkctxHsLtiV25bHgXJQtHMGW+5Wk", "hash_imp": "475266A2489617ACC64ABDFCAE452AE0", "hash_pesha1": "3503FBF0AB7F48E02A60A9BBAA820C88BCCFC01C", "hash_pe256": "F6DC238238302CA67D503D5ADC2668E31C6BA73FA45C29484E71478494D6A372", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Playback EXE", "meta_original_filename": "Windows.Media.Playback.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f1675aec9be46208fbafa4d6bb389f61c89b1f6059e15ca1c4390eba9f7c03ac/detection", "runtime_modules": [ "C:\\Windows\\system32\\Windows.Media.BackgroundPlayback.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "Windows.WARP.JITService.exe-25BEB755413479420EA4AFB4775460AA": { "file_name": "Windows.WARP.JITService.exe", "file_path": "C:\\Windows\\system32\\Windows.WARP.JITService.exe", "hash_md5": "25BEB755413479420EA4AFB4775460AA", "hash_sha1": "46F6D23D92E44536608453F28E2EDE3BBD2422DE", "hash_sha256": "0D9B57043BA5ED8FF7955CEB5D590255B03744475347EB1FBD29A9686B98DB0E", "hash_sha384": "51B8183F6CA5CA8D255EFA8F1191439DD7FCAD6F6ABE91BF0C388D9DB7FE6523EF452BC9C1F932C15B589D5A8BE11E1B", "hash_sha512": "CECC70AAC18F5021896C5319D80C9EA07BFD9FA9DFB8BD4F3C2BA2D944156B63DD5369DD4B427060BA3A85370FA8ECF58850F0A72B38EE49B7F737D03E61732B", "hash_ssdeep": "1536:Wy1+ILk0rQcF7Wj5PfvtG5f3T4/ydyD6DJehLO3mEJL:W/c231qf3T4X6DTWE", "hash_imp": "44B86D624A0039683ABD4DA90F8B815D", "hash_pesha1": "159C94B987D18E8EC812E9DAC2B0568610FC5A4E", "hash_pe256": "D4ECEB196C37CD8E03505EB4FB946189C04F0F23F5139C9E625FCB35C3047C3F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/0d9b57043ba5ed8ff7955ceb5d590255b03744475347eb1fbd29a9686b98db0e/detection", "runtime_modules": [ "C:\\Windows\\system32\\Windows.WARP.JITService.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "WindowsActionDialog.exe-592EFCF6AA5DB766461916061B2D4AF9": { "file_name": "WindowsActionDialog.exe", "file_path": "C:\\Windows\\system32\\WindowsActionDialog.exe", "hash_md5": "592EFCF6AA5DB766461916061B2D4AF9", "hash_sha1": "487370B414518FC7A3E6FD06E73A112795D13BAF", "hash_sha256": "60948718AA23398C24BADD7CE9A9FC6F36160DBB578ADC593FF465AE878B9782", "hash_sha384": "BD070C99EA21175C7DDEAD9BBD5FA556E3FCFADDBA2C671F1528689D4E267CB2343CD836A6C402211DDD655B98DBA232", "hash_sha512": "98714CE857F72AF035A9565FEF2C038A75838F1C4246BF48785C2585CEDD180432392F37B667D4D444B8F1103352FAD2052DD8B94B19D0991ADEA61DBBB237AA", "hash_ssdeep": "1536:+BN+Ay4F5ePIrgJuhEhDZAHpwBXhE4chjKmr/eso4s+Ic88v5qsQSyIQ:a+m5ewrQuh8ypwBXh0K+Vnl28xqsQfIQ", "hash_imp": "F42F7A5425CB00E71D7C4716F98BCA8F", "hash_pesha1": "DC77D917CCB60F652ABAE6E9C4B799593007C85A", "hash_pe256": "AB8FA9F6086C95F65974038EB4D0789560BCF59BF9C281E785AD07034B496D6E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Action Dialog Broker", "meta_original_filename": "WindowsActionDialog.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/60948718aa23398c24badd7ce9a9fc6f36160dbb578adc593ff465ae878b9782/detection" }, "WindowsUpdateElevatedInstaller.exe-9BFA72E3F5AEB427A3D7D4D6D3BE1EBD": { "file_name": "WindowsUpdateElevatedInstaller.exe", "file_path": "C:\\Windows\\system32\\WindowsUpdateElevatedInstaller.exe", "hash_md5": "9BFA72E3F5AEB427A3D7D4D6D3BE1EBD", "hash_sha1": "E8AEC40AAEE42FAEC94A747821CC4B7D09147EAC", "hash_sha256": "E387376538F15A27B9548DB7ABBC04CAE62CCE7CBE7BACB1B504F5D082AD83FC", "hash_sha384": "9C50DFC3A90529B21C2B2C0071FEA7FF420042A09B02C739A2A0EF9789629E69209547D3B6CB0265CC01567F9FA99AD9", "hash_sha512": "D00A6E1318C85D7F0516A56840A6D83FB1488D7D11584B7F468E20B3316A552801214075CF886F8389F3099EADC67DF79DF71A056BE85AD597517997A257D0B4", "hash_ssdeep": "768:ZzEjDzLYl6jzw2kJfx+1yBjTJaFbvgNLEJMqeZqTOV:Zoe6jzw2kv+cBIoCZ6qTOV", "hash_imp": "464BECE13E769D1AB0E5D1A6D49AAD1C", "hash_pesha1": "BE1476EC5F90D8E742C1B5FFBC193AA5FA837691", "hash_pe256": "ADFD83A594CD27B6F6D31511A1D97E1D9C5D700769E25A055B495BB61D192D4E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WindowsUpdateElevatedInstaller", "meta_original_filename": "WindowsUpdateElevatedInstaller", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e387376538f15a27b9548db7abbc04cae62cce7cbe7bacb1b504f5d082ad83fc/detection" }, "wininit.exe-9EF51C8AD595C5E2A123C06AD39FCCD7": { "file_name": "wininit.exe", "file_path": "C:\\Windows\\system32\\wininit.exe", "hash_md5": "9EF51C8AD595C5E2A123C06AD39FCCD7", "hash_sha1": "915EA28BDAA9A2230CE52080693D7F7E27620ED5", "hash_sha256": "268CA325C8F12E68B6728FF24D6536030AAB6E05603D0179033B1E51D8476D86", "hash_sha384": "E267C1B8B959EDD16781940503F8ACC7DDD5CAF58C7D759C87834C79ED27CA8A3457B2821A823E08DB372686B3A2CD16", "hash_sha512": "E1D92DD51C840C6A9001B31C40D89DADAA2048ABA6201845C8B5B48A63A46D0E861AB91DB53757A9AEB6CB5CF9A4253CCD47DC4ADF1E9EAC4C48D0282598A486", "hash_ssdeep": "6144:CV7PELsqQmhwqpRxTtkNnWriIEOrDmrMyoYc2SbAdO7pQM1HZRXLCQ+JKTEs:CV7EEmhwqLzKnWriHOrDmoy+X81lKTEs", "hash_imp": "5DD14AFAB46B0C83EA7A6093D7355FA9", "hash_pesha1": "576E660FF4918B7A10E38A8B7F0826B5DC029E81", "hash_pe256": "E6859386D3535C70585958835D6BF02675453DA58D5BEC69B214FA778980B621", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Start-Up Application", "meta_original_filename": "WinInit.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/268ca325c8f12e68b6728ff24d6536030aab6e05603d0179033b1e51d8476d86/detection" }, "winload.exe-5FE7EDEF3632AA57B80C3F0EAAC591E3": { "file_name": "winload.exe", "file_path": "C:\\Windows\\system32\\winload.exe", "hash_md5": "5FE7EDEF3632AA57B80C3F0EAAC591E3", "hash_sha1": "60D9BFF6A349632E6409CF0C9BF308D61B0B429C", "hash_sha256": "0E2DB883E483794631804947D433F29D0D469C9585935E052166076C71BA4495", "hash_sha384": "A867C8F94F53C4A30E864C0F6E92F491A4622BBF65ED95DDD8FAC7963813ED9CFC3D685869E3BB8276CB170ACBFE8651", "hash_sha512": "D553272A1B2AF5070D13928C909BD5AC37AF26ECE458F791F712B40E3CD5D6DE3A6F07DE6CEA88FDE06697DB9095166A80F1AD87CD62ED6E46018E87B19D6C6A", "hash_ssdeep": "24576:bYubtHAB35alfGc7z5tZR8H1ylp9IVmJPmqd7pktYzpM2K7W6J4DOVD:bY30LbD9ZmqxM5WC", "hash_imp": "n/a", "hash_pesha1": "2C61C614D6B7B96BD6CC2FFA73B5AB9C5776B77D", "hash_pe256": "A57E1B5C30A198B26BD3F00A9A0694EFF13C13A411672F11298EEC9BA889DC8F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "OS Loader", "meta_original_filename": "osloader.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0e2db883e483794631804947d433f29d0d469c9585935e052166076c71ba4495/detection" }, "winlogon.exe-BF6EA00C7E364065320924D71D545113": { "file_name": "winlogon.exe", "file_path": "C:\\Windows\\system32\\winlogon.exe", "hash_md5": "BF6EA00C7E364065320924D71D545113", "hash_sha1": "597C5A7D78D4AE6A4CF8A081081D97F9CBB5D18C", "hash_sha256": "1A1FE677953A31886243F5410FA08FBD12F6022CC952F6712542BED02259779C", "hash_sha384": "282786485BDBC0031A997E81453736871DE5F34B97F85C7344908550AE7005C883E92288270FAB228DBA3C1DEA94129A", "hash_sha512": "2D46F683A1B8AA4D2731EC77DF6CE7703FCA22F13D84558997BA06CA6EDE39CDB1677452E798E2D523F77EE96CFDBB1D4D2FFA681D16C859DCF3767544580EDB", "hash_ssdeep": "12288:CHzdZNJyKsGhp8L7EpN0HDGKIKx5CX41FoKuCETLSLo/:CB1yKxCEQjTIWoKuCE4o", "hash_imp": "C399754881779489CBD0F5D180C41465", "hash_pesha1": "D06A2208E7BCDED8A016504F5F26D7CC1F7B8B45", "hash_pe256": "03D387011608F05613295CD6CB71497285E89AFC8FE2906BCC884D28BEA5A226", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Logon Application", "meta_original_filename": "WINLOGON.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1a1fe677953a31886243f5410fa08fbd12f6022cc952f6712542bed02259779c/detection", "runtime_modules": [ "C:\\Windows\\system32\\winlogon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll" ] }, "winresume.exe-E0F836B4773EC86CA67005E0E70D2BCF": { "file_name": "winresume.exe", "file_path": "C:\\Windows\\system32\\winresume.exe", "hash_md5": "E0F836B4773EC86CA67005E0E70D2BCF", "hash_sha1": "D2F061AE0464F905605154EE0D214C4F67B04AED", "hash_sha256": "0F621876EA2FE9CB79503A1852BCD922D9825B579E86296F5D82AB88C0BF942E", "hash_sha384": "5E7269D6E0306668C84D6E809BC91A8877F3B107ADEEF6C20ECD6712FD81FEF435C4DA00B41FCB2A6AD616B59EA872A5", "hash_sha512": "605019A389CE98294DD476109A78A06EC1BD2203EE13ADC1572161E3E1CDFE2788BA7A0316D89AC95753D2A1B3A276A7A745ACF838B1AD2CA9F0B5BF35CDED82", "hash_ssdeep": "24576:Ld+Oy1HK0CcxbR6SK5kIBA5WvfmnvMxLdPmYoIr:Q5C0KPBhvfmvqLhmxI", "hash_imp": "n/a", "hash_pesha1": "087C95A77664F0E5EF73A8142DE99A7F2406A8F8", "hash_pe256": "0437934F2BB0C427211399EBCF568300989A83A514834A0FF507BF15707FA32C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resume From Hibernate boot application", "meta_original_filename": "hiberrsm.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0f621876ea2fe9cb79503a1852bcd922d9825b579e86296f5d82ab88c0bf942e/detection" }, "winrs.exe-D2C250C6B01198BEA08AA355983C0923": { "file_name": "winrs.exe", "file_path": "C:\\Windows\\system32\\winrs.exe", "hash_md5": "D2C250C6B01198BEA08AA355983C0923", "hash_sha1": "87648C3120F9C2CE9C218E183EFCAAEF9F01E34D", "hash_sha256": "00B00F9E2A62550136F2D80428BDCE22C8FE718784B7F8DAFC29C18BFD782BDF", "hash_sha384": "183FBE4C0FDEC2EF772C4180C44AB494ECDE0A142C477D2DFA01600CA26B1A4E7C9BA307D50146FF8C489FB552BB5EEE", "hash_sha512": "673DCA33B1E412510792D84549D04B56912AF9B6D845327593354311AFA6977DDAB87182410DE24DAB27D879FA59E9DB3E7A2E42D91DBD7323947750FFB9519E", "hash_ssdeep": "768:cTnnHx13UF6bVgw7nOrXgsRrMfDEklZx1nKuPUA/2/lDfShXcMmkdhuxVqVaogE:wRSFO7nOzr5kl7s6Uv/lDKhvmkWE", "hash_imp": "2A6F61CB3D8B085F04D934C7B0CC98A1", "hash_pesha1": "09244B1BE9614EFC501FFB0CB906229FADC9187A", "hash_pe256": "4215E29B7975BA06CFAE64C78A95323EAAD5800EE669EFC901D80B6532A5026E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "winrs", "meta_original_filename": "winrs.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/00b00f9e2a62550136f2d80428bdce22c8fe718784b7f8dafc29c18bfd782bdf/detection", "output": "\nUSAGE\n=====\n(ALL UPPER-CASE = value that must be supplied by user.)\n\nwinrs [-/SWITCH[:VALUE]] COMMAND\n\nCOMMAND - Any string that can be executed as a command in the cmd.exe shell.\n\nSWITCHES\n========\n(All switches accept both short form or long form. For example both -r and \n-remote are valid.)\n\n-r[emote]:ENDPOINT - The target endpoint using a NetBIOS name or the standard connection URL: [TRANSPORT://]TARGET[:PORT]. If not specified \n-r:localhost is used.\n\n-un[encrypted] - Specify that the messages to the remote shell will not be encrypted. This is useful for troubleshooting, or when the network traffic is already encrypted using ipsec, or when physical security is enforced. By default the messages are encrypted using Kerberos or NTLM keys. This switch is ignored when HTTPS transport is selected. \n\n-u[sername]:USERNAME - Specify username on command line. If not specified the tool will use Negotiate authentication or prompt for the name. \nIf -username is specified, -password must be as well.\n\n-p[assword]:PASSWORD - Specify password on command line. If -password is not specified but -username is the tool will prompt for the password. If -password is specified, -user must be specified as well.\n\n-t[imeout]:SECONDS - This option is deprecated. \n\n-d[irectory]:PATH - Specifies starting directory for remote shell. If not specified the remote shell will start in the user's home directory defined by the environment variable %USERPROFILE%.\n\n-env[ironment]:STRING=VALUE - Specifies a single environment variable to be set when shell starts, which allows changing default environment for shell. Multiple occurrences of this switch must be used to specify multiple environment variables.\n\n-noe[cho] - Specifies that echo should be disabled. This may be necessary to ensure that user's answers to remote prompts are not displayed locally. By default echo is \"on\".\n\n-nop[rofile] - Specifies that the user's profile should not be loaded. By default the server will attempt to load the user profile. If the remote user is not a local administrator on the target system then this option will be required (the default will result in error).\n\n-a[llow]d[elegate] - Specifies that the user's credentials can be used to access a remote share, for example, found on a different machine than the target endpoint.\n\n-comp[ression] - Turn on compression. Older installations on remote machines may not support compression so it is off by default.\n\n-[use]ssl - Use an SSL connection when using a remote endpoint. Specifying this instead of the transport \"https:\" will use the default WinRM default port. \n\n-? - Help\n\nTo terminate the remote command the user can type Ctrl-C or Ctrl-Break, which will be sent to the remote shell. The second Ctrl-C will force termination of winrs.exe.\n\nTo manage active remote shells or WinRS configuration, use the WinRM tool. The URI alias to manage active shells is shell/cmd. The URI alias for WinRS configuration is winrm/config/winrs. Example usage can be found in the WinRM tool by typing \"WinRM -?\".\n\nExamples:\nwinrs -r:https://myserver.com command\nwinrs -r:myserver.com -usessl command\nwinrs -r:myserver command\nwinrs -r:http://127.0.0.1 command\nwinrs -r:http://169.51.2.101:80 -unencrypted command\nwinrs -r:https://[::FFFF:129.144.52.38] command\nwinrs -r:http://[1080:0:0:0:8:800:200C:417A]:80 command\nwinrs -r:https://myserver.com -t:600 -u:administrator -p:$%fgh7 ipconfig\nwinrs -r:myserver -env:PATH=^%PATH^%;c:\\tools -env:TEMP=d:\\temp config.cmd\nwinrs -r:myserver netdom join myserver /domain:testdomain /userd:johns /passwordd:$%fgh789\nwinrs -r:myserver -ad -u:administrator -p:$%fgh7 dir \\\\anotherserver\\share\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "\\BaseNamedObjects\\F932B6C7-3A20-46A0-B8A0-8894AA421973": "Section", "(R-D) C:\\Windows\\System32\\en-US\\mswsock.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "error": "Winrs.exe: Unrecognized switch \"--help\"\r\nUse \"winrs -?\" to obtain the usage information", "runtime_modules": [ "C:\\Windows\\system32\\winrs.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "winrshost.exe-6790044CEB4BA5BE6AA8161460D990FD": { "file_name": "winrshost.exe", "file_path": "C:\\Windows\\system32\\winrshost.exe", "hash_md5": "6790044CEB4BA5BE6AA8161460D990FD", "hash_sha1": "F8DA634CFF92D525B98D99E91A6551020B3F5C0C", "hash_sha256": "047427E1ECC1D5758A9553F0E819A9536D9D56D279BA81F707FE377FA1433318", "hash_sha384": "CA1DE62A16D55DA5E7CBD99388F413894461DD0CD56CF3A2A0CB36F9D77582C29EA6F2B0404C68476931662661EC43F9", "hash_sha512": "E52F5D34069AE471B41A20B7F71D8EC3219F1BD2848AF1EDC5FC976C55106BBBDEF76A8A2DC26F66087DFFBC3178CCBB53A7FE542BD5F81343E90DA61CA6F4C9", "hash_ssdeep": "768:sb+k5T4Bpg6zDHkIabua14BVkB4x8/07spU:M+k54wSEIaKa14BVkk8/07spU", "hash_imp": "94B88BB1A488481A09FB94AE3B531ED2", "hash_pesha1": "9C4A5996EB1355105B5A316202D1E91C98528033", "hash_pe256": "5721D76D71D34C9D116808654F8C0B13D88E04DA3F68E56B8AF46B40AC09E02A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for WinRM's Remote Shell plugin", "meta_original_filename": "winrshost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/047427e1ecc1d5758a9553f0e819a9536d9d56d279ba81f707fe377fa1433318/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\winrshost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "WinRTNetMUAHostServer.exe-24F075C40FA979B9152A3E643940A387": { "file_name": "WinRTNetMUAHostServer.exe", "file_path": "C:\\Windows\\system32\\WinRTNetMUAHostServer.exe", "hash_md5": "24F075C40FA979B9152A3E643940A387", "hash_sha1": "7C7AEA806017EA6DEC12A5139C87AFDBB3912461", "hash_sha256": "0763B8A990BAB988BDBD3AAB258B587A634FCDADC204A9B36B9ABE10CDAF4A83", "hash_sha384": "378AA71C34334DCC9569693CC94FAFD9664C34AD21FF8C5126761B64510258929D033771FFB18E5B7D01A72D7D4E74E8", "hash_sha512": "4250C85FEB3F014EFC1D7F17BF4C302C28743A4C9FDA95269B3811388C26714085E99311FF60C83C5802DC0B3C65AD8EE084F3B0C5A22E4E5EF6E77647B02869", "hash_ssdeep": "384:o22Qlce5cahaEZV1LMVHKtFMw/slH7RZOPy4uYMFkpWdTJMBnDk2+3YIU8WxoWO:iCvrZMVHwO7P4uYMgj+3Y3", "hash_imp": "469CAFAA823DF7EB902F143AC17B104A", "hash_pesha1": "9434277F8C0A6C075F26F3FB5C4B62F14D717A4D", "hash_pe256": "DCD27BC3359205CFD7A6EBE4ADA4DBE65AFD80E7CF51341ECD2DE64286B06B66", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WinRTNet MUA HostServer EXE", "meta_original_filename": "WinRTNetMUAHostServer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0763b8a990bab988bdbd3aab258b587a634fcdadc204a9b36b9abe10cdaf4a83/detection", "runtime_modules": [ "C:\\Windows\\system32\\WinRTNetMUAHostServer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "WinSAT.exe-715DB53A8064C6DECCF68B7501DF3386": { "file_name": "WinSAT.exe", "file_path": "C:\\Windows\\system32\\WinSAT.exe", "hash_md5": "715DB53A8064C6DECCF68B7501DF3386", "hash_sha1": "99ACD12C3600AD3A7C478E49126DB520BC136304", "hash_sha256": "CC31FDCDCE05144EF750B01233D57614CDA7364A73CA26FF68886EBDC650E367", "hash_sha384": "C069E9F4D7BDF64983C1315CE0FC1378D63AE0489C012CDEC97F519EC8E78107EB0E7AAFBF17D2FE9F035C2BE2104671", "hash_sha512": "9BA9EAEFA1E2E4DA2D14F12B81F2ED0597AB6EB6B32D85851B69BC86D77A6B38810A04AA35FFCBF64484D544F52960F05F4EACA4740CD3674A1D09D8B373CE3C", "hash_ssdeep": "49152:R8sgM4nGU8AlipUY2K7G/hDAHlmWC67HyYmq1dKwdfU2bECbe:gBGUkezg/1DFE/", "hash_imp": "77CCB5C30DFB942E48EBC52E645CF431", "hash_pesha1": "FA83B2D0316B485FDBCE16935B9B05C3C4C71326", "hash_pe256": "188B5F14467E3DCC2F5AE75C6C113C4DA3139E2141B275EA696B939D5A486C1D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows System Assessment Tool", "meta_original_filename": "WinSAT.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/cc31fdcdce05144ef750b01233d57614cda7364a73ca26ff68886ebdc650e367/detection", "output": "\r\nWindows System Assessment Tool\r\n\r\n \r\nCOMMAND LINE USAGE : \r\n WINSAT <assessment_name> [switches]\r\n\r\nIt's necessary to supply an assessment name. In contrast, switches are optional. \r\nValid assessment names already seen in Vista include: \r\n\r\n formal\t\trun the full set of assessments \r\n\r\n dwm\t\tRun the Desktop Windows Manager assessment\r\n - Re-assess the systems graphics capabilities and \r\n restart the Desktop Window Manager.\r\n\r\n cpu\t\tRun the CPU assessment. \r\n mem\t\tRun the system memory assessment. \r\n d3d\t\tRun the d3d assessment \r\n (Note that the d3d assessment no longer runs the workload. \r\n For backward compatibility, pre-determined scores and metrics are reported.)\r\n disk\t\tRun the storage assessment\r\n media\t\tRun the media assessment \t\t\t\r\n mfmedia\t\tRun the Media Foundation based assessment\t\r\n features\tRun just the features assessment \t\t\r\n - Enumerates the system's features. \r\n - It's best used with the -xml <filename> switch \r\n to save the data. \r\n - The 'eef'switch can be used to enumerate extra \r\n features such as optical disks,\tmemory modules, \r\n and other items.\r\n \r\nPRE-POPULATION: \r\nThe new command-line options for pre-populating WinSAT assessment results are : \r\n \r\n Winsat prepop [-datastore <directory>] [ -graphics | -cpu | -mem | -disk | -dwm ]\r\n\r\n\r\nThis generates WinSAT xml files whose filenames contain \"prepop\". For example :\r\n 0008-09-26 14.48.28.542 Cpu.Assessment (Prepop).WinSAT.xml\r\n\r\nThe filename pattern is :\t\r\n %IdentifierDerivedFromDate% %Component%.Assessment(Prepop).WinSAT.xml\r\n\r\nThe datastore directory option specifies an alternative target location for generated xml files. \r\nIf no location is specified, everything is pre-populated to \r\n %WINDIR%\\performance\\winsat\\datastore. \r\n\r\nTo generate a full set of result xml files, use \"winsat prepop\". \r\n\r\nIt is also possible to pre-populate results for a subsystem, such as CPU, \r\nsubject to the following dependencies:\r\n\r\n The CPU assessment has a secondary dependency on the Memory assessment\r\n The Memory assessment has a secondary dependency on the CPU assessment\r\n The Graphics assessment has a secondary dependency on both CPU and Memory assessments\r\n The DWM assessment can run standalone\r\n The Disk assessment can run standalone \r\n\r\nIf the assessment for a secondary dependency is not present, WinSAT will run the \r\nsecondary assessment along with the requested primary assessment. \r\n\r\nFor example, \"winsat prepop -cpu\" will run both the CPU and the Memory test, \r\nif the xml file for the Memory test is not present.\t\r\n\r\n\r\n\r\nOTHER NEW Win7 ASSESSMENT OPTIONS :\r\n\r\n dwmformal\tRun Desktop Windows Manager assessment to generate the WinSAT Graphics score\r\n cpuformal\tRun CPU assessment to generate the WinSAT Processor score\r\n memformal\tRun Memory assessment to generate the WinSAT Memory (RAM) score\r\n graphicsformal\tRun Graphics assessment to generate the WinSAT Gaming Graphics score\r\n diskformal\tRun Disk assessment to generate the WinSAT Primary Hard Disk score\r\n \r\nAll formal assessments will save the data (xml files) in \r\n %WINDIR%\\performance\\winsat\\datastore. \r\n\r\nIf a system has been prepopulated (using files generated by the \"winsat prepop\" option), \r\nit is not necessary to run formal assessments.\r\n\r\n\r\nSUB-ASSESSMENTS:\r\nWhile investigating results, it may be convenient to look at individual assessments. \r\nOptions for running Gaming Graphics sub-assessments include:\r\n\r\n Winsat graphicsformal3d\r\n Winsat graphicsformalmedia\r\n\r\n DX9 Variations: \r\n Winsat d3d -dx9\r\n winsat d3d -batch\r\n winsat d3d -alpha\r\n winsat d3d -tex\r\n winsat d3d -alu\r\n\r\n DWM/DX10 variations: \r\n Winsat d3d -dx10\r\n winsat d3d -dx10 -alpha\r\n winsat d3d -dx10 -tex\r\n winsat d3d -dx10 -alu\r\n winsat d3d -dx10 -batch\r\n winsat d3d -dx10 -geomf4\r\n winsat d3d -dx10 -geomf27\r\n winsat d3d -dx10 -geomv8\r\n winsat d3d -dx10 -gemov32\r\n winsat d3d -dx10 -cbuffer\r\n\r\n\r\n\r\nOPTIONS FOR FORMAL ASSESSMENTS FOR SUBSEQUENT RUNS ON THE SAME MACHINE:\r\n\r\nThe default behavior for \"WinSAT formal\" when a complete set of winsat formal files is present \r\nand a second \"winsat formal\" run is requested is to \r\n 1) Run incrementally if component change implies that an assessment needs to be re-run, \r\n e.g. if a video card were updated \r\n 2) If no component updates were detected, re-run all assessments.\r\n\r\n The restart option enables behavior other than the default. The syntax is : \t\r\n Winsat formal -restart [clean|never]\r\n \r\n Winsat formal -restart\t \tReruns all assessments. \r\n Winsat formal -restart never \tAttempts to run incrementally.\r\n Winsat formal -restart clean \tReruns all assessments and provides the same functionality as \"forgethistory\". \r\n Winsat forgethistory\t\tChoosing to forgethistory will rate a machine as if for the first time.\r\n\r\n\r\nOTHER COMMAND LINE OPTIONS :\r\n -v\t\t\tEnables verbose output\r\n -xml\t\t\tSaves the XML output to 'filename'\r\n\r\n <command> -log <fn>\tGenerates a log file associated with the specified command, such as disk\r\n The -log switch can be used with any WinSAT command.\r\n\r\n viewlog -i <filename> \tDumps the results of a log file . \r\n viewevents \t\tUsed to view relevant winsat events in the event log. \r\n (This launches the event log)\r\n query \t\t\tCan be used to query the current datastore.\r\n", "error": "Error: Unable to run inside of a Virtual Machine. Please try again running directly on the native hardware.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\WinSAT.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "winver.exe-63DC2D604B8A96C9962494D1D957DD77": { "file_name": "winver.exe", "file_path": "C:\\Windows\\system32\\winver.exe", "hash_md5": "63DC2D604B8A96C9962494D1D957DD77", "hash_sha1": "08FBA88D84BB68A64F666F3B4F831DDD3AA89B41", "hash_sha256": "0F588A098AF640A29C1651D17CAFE662814943A4AAD3BF4D043177F8298EDE68", "hash_sha384": "DAD9F36363AC56AF6D47E5D036EB7B81BEF25E804316EA6575878E34BC04E35ABE3E659A3A6212975E57F244950493FD", "hash_sha512": "9523B1BDED45A099CE4A6AF2F9182523DBE163FFEF65FE4A28B65FF9F2DD6E6E29F69335652E305B42C801391DD2BB172EDA02497F3730A4240689CAFD12CE66", "hash_ssdeep": "768:xNXJX+daykoGSkVhWakkbB5eT905WGnUKxHUe7n8jKBFFptX/7wUXI:vXF+Yykoxakkn6oYY0ewiP8J", "hash_imp": "92BE77A081419D46930EEB51BF20D61B", "hash_pesha1": "EC3C4052E8D72B3C0602D771576BA9E7700BFD1B", "hash_pe256": "89654C686A6ECE0EE5DB3A974ED98E59F5A1CD6EC3022BEFC82A7F0B941CA2A4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Version Reporter Applet", "meta_original_filename": "WINVER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/0f588a098af640a29c1651d17cafe662814943a4aad3bf4d043177f8298ede68/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\winver.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\winver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll" ], "runtime_window_title": "About Windows" }, "wkspbroker.exe-D91F6BFB33B0898374B35D36F60A6FC2": { "file_name": "wkspbroker.exe", "file_path": "C:\\Windows\\system32\\wkspbroker.exe", "hash_md5": "D91F6BFB33B0898374B35D36F60A6FC2", "hash_sha1": "FE4FA63405ED48FA3BCFF35B543BA43C2EA86592", "hash_sha256": "82BE5F871B0981113CD84CC4F8E093588E1ABB00DDD199AE0F93D9B2A6C66B3D", "hash_sha384": "BE413D83F32D820E68A402CDC392484DCD10791B85446C16AE74E56EE82A4D0A70E9CA6EEDDEF4F7B56C0AC15E30E370", "hash_sha512": "78E6FD58B67A7CC864508B65649EB83D88C8876BFC8F170763BA7BA53F6C6A8C96492E68857B19CB41E49BFB306D4B216547143118D864BE9115656AFE72240C", "hash_ssdeep": "6144:HaC8Dim7iOEhE4gDkSdNUjSq1rxAvanWTH8Akw5Ped0YB:x8Dim7iOEhEddNUPCvanWTrWyG", "hash_imp": "39669356A1624D7E9B15F2312098BA01", "hash_pesha1": "EA7A51DA157BC4FF0D47C4FDB655343FA7AD3040", "hash_pe256": "4F0C344B18890100E02107C42B51CF2EB3AEEBBDAE23230373A33E5F6511E986", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RemoteApp and Desktop Connection Runtime Broker", "meta_original_filename": "wkspbroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/82be5f871b0981113cd84cc4f8e093588e1abb00ddd199ae0f93d9b2a6c66b3d/detection", "runtime_modules": [ "C:\\Windows\\system32\\wkspbroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\RADCUI.dll", "C:\\Windows\\system32\\WININET.dll" ] }, "wksprt.exe-BA81ED5D41505A2311DB75585620A381": { "file_name": "wksprt.exe", "file_path": "C:\\Windows\\system32\\wksprt.exe", "hash_md5": "BA81ED5D41505A2311DB75585620A381", "hash_sha1": "F02403A281B8D80176C37C24B10E53E1A8CBCCE6", "hash_sha256": "3159D37162E97C34BD7809FA98AAAD1993F2FB72D70806503F808820AD5871D9", "hash_sha384": "4098E1491B17D226013F903F5E5E511A158190FC4BCD3AB58ACD90302D217E75C14BC155D0871E62E02EDA1DE2254C2C", "hash_sha512": "D8BA2082E48F807C7FB2D6643EF3CFA66F69CAA96338C5CA0FEF9562AC68F4664CCD801872194C14F7C9A0961F46F7F25D9297DB98021F1F8CCA82B765D2D647", "hash_ssdeep": "12288:jBu21sy5Y1mg+vG3tKvA2HdiqZtL9XCXIB7GjFMvT3lxR:jBn1ZYy+3tmA2L9SimI", "hash_imp": "88A462E0F580961648CAD58E157C0D43", "hash_pesha1": "C379922F4D659746EB1A152AC172AA114B9A26CF", "hash_pe256": "6F5B6E0072692550F6DBA5D5B7778F168F7D968FAD876D242B0830B5F440D92A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RemoteApp and Desktop Connection Runtime", "meta_original_filename": "wksprt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/3159d37162e97c34bd7809fa98aaad1993f2fb72d70806503f808820ad5871d9/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\wksprt.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wksprt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll" ] }, "wlanext.exe-D178119D8DE4E18B05C3DEFB22B6D3CC": { "file_name": "wlanext.exe", "file_path": "C:\\Windows\\system32\\wlanext.exe", "hash_md5": "D178119D8DE4E18B05C3DEFB22B6D3CC", "hash_sha1": "0CBF3F61C88E7A944294D8E577011F44DD99A9B4", "hash_sha256": "8456099DEB994F309FDE890E4F0E571A0A67F9B7DD079516905175CD1500FA52", "hash_sha384": "89748309A3C9179084972E211638F875820D609D9FA5272370E6FFA937376211EE6685001F73F03161EC6480D374EBC1", "hash_sha512": "EA97A93C3B6E9ADA6ACEB6DBA358C9E4A6EE4EDF1228942378C8879ECA8A60A6B85112D11E0DB387999729203707A0D4292CC80697CBB8CF42B4BE2202762E44", "hash_ssdeep": "1536:Q9XHUkfBwkQ1meRIZN1Y8t93q91YI/JIq7cNn5LfDb5s:QR1fOkby8tyL/JZsnJu", "hash_imp": "93B58E7D480A8A2281EAE5DDF5F178F2", "hash_pesha1": "6954EAC024A4EB84BF40A5C28C124ECA14D49434", "hash_pe256": "0AEBFBC212F66DAE1A8A80CA460C6842FADEB8C8B3471333015F551CBCF21A90", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Wireless LAN 802.11 Extensibility Framework", "meta_original_filename": "wlanext.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8456099deb994f309fde890e4f0e571a0a67f9b7dd079516905175cd1500fa52/detection", "runtime_modules": [ "C:\\Windows\\system32\\wlanext.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wlrmdr.exe-82404475E1FFEEDBFA1758197858C432": { "file_name": "wlrmdr.exe", "file_path": "C:\\Windows\\system32\\wlrmdr.exe", "hash_md5": "82404475E1FFEEDBFA1758197858C432", "hash_sha1": "AB64C7001894B6C5FAB926596D0E2536BB547BE8", "hash_sha256": "876E04F2C6F953C80EDF173DFB2EB950257AABE5603ABC2EA43EAC0229A553A3", "hash_sha384": "12E1E812951521411E63B00A0E4CD2247E4A3FC3097FB8C5A9BF050C2BEAC0E61549302BDE28A9713BD3ADC11ABD97F9", "hash_sha512": "38F55778FDC19397FAB21D4879C8B810586B64508BE64BA4189866AA8B3C663E54824562132862AA88274C89C706B1D27FE57B726830E26C55AC590BD691B18B", "hash_ssdeep": "1536:s4/jyj91lFbMs/ukWlxZyE8svqr9PxDtykPmvX:7jyj9WoWlxgGu9ZDtyk+vX", "hash_imp": "0C029EF03BE0DFE4324558843609A28E", "hash_pesha1": "1E053F812333C35A5BC350198438F15257689F1D", "hash_pe256": "97B81982E5C01B4B94464D482826990A11EC86759DEC0483AF892F6AD5AFF762", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows logon reminder", "meta_original_filename": "WLRMNDR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/876e04f2c6f953c80edf173dfb2eb950257aabe5603abc2ea43eac0229a553a3/detection", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\system32\\wlrmdr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll" ] }, "WMPDMC.exe-209E92EAD1CE8D7ED3F66A33CE3B04F7": { "file_name": "WMPDMC.exe", "file_path": "C:\\Windows\\system32\\WMPDMC.exe", "hash_md5": "209E92EAD1CE8D7ED3F66A33CE3B04F7", "hash_sha1": "E604FA0300F6189DFEA5E0AC26755557DC3EE252", "hash_sha256": "D7581B8C82FAF97B9B2049F031D29AAE593AAEB3DA805F5AF14944C0129622EB", "hash_sha384": "4280E8B3127037C2B1C4D099D363E8F66C71E33F96C258A824D9A564D1420FB8B077B48A2989D5C8C9F0ADA0FC722B83", "hash_sha512": "1A9BEC23F6901BEC2BE0AF5CB9ECAF6159DB16581C1F87BC2827A91FA73EA3E50BEB41104CB04DFFF04569D4C38B8397269A8C9704782D2E7B76DF51A6663636", "hash_ssdeep": "24576:s0kbwKYJXtbr9DcuRxQHABbAizBGuP0nmsWmsnQX+TO0EHVJZh/u:sFbwKidftXQStGDn1WmsnJKHVU", "hash_imp": "4104CF876C2E2570AFB2FF65C56DD170", "hash_pesha1": "363D2F23EF8D43AF7037664226983ED1DF61324E", "hash_pe256": "C5B2A2EB7922EE0228EDC20F65FEE40657E9B2826C8C929BAB6D22A45613F341", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Cast to Device", "meta_original_filename": "WMPDMC.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d7581b8c82faf97b9b2049f031d29aae593aaeb3da805f5af14944c0129622eb/detection", "runtime_modules": [ "C:\\Windows\\system32\\WMPDMC.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ole32.dll" ] }, "WorkFolders.exe-8373D16B14416C0F892DDFECBB4CBFAC": { "file_name": "WorkFolders.exe", "file_path": "C:\\Windows\\system32\\WorkFolders.exe", "hash_md5": "8373D16B14416C0F892DDFECBB4CBFAC", "hash_sha1": "0E3397AE69A35CBDE52719F01097B2930A89C464", "hash_sha256": "CFC058A712B0F1A0932E7FA1F17430EEAA231C41FDD1EAD38639D603A8006ACA", "hash_sha384": "9E2F49CDD221E6F38DE9F5C40974DCCE0E6216631E9CE81FFA86D7D7671C4BA17155B52DB4E81BC929F34D7B30D06A51", "hash_sha512": "9575B2C03492994A4DAECC1920E8B18BE5FD2968DDAA99D4FD1ED7BA2730F2A952669FCD86B653A3FD7E9F45A268D0B9C153FFC80070DD745871E3AA6AA0F9F3", "hash_ssdeep": "1536:wfNflQGO4bUh97+Bq+KvejHDHIm1wisw/8cxEa:oBhAfT+lHDHIm1Uw0cxE", "hash_imp": "7468ED9A85006965C01F519C0D2C8E9F", "hash_pesha1": "28EDC5C9728C1BF1EE2FADB9985B6D1FC2564BF5", "hash_pe256": "731232265E86E45F30872B1D4DC4D44127031BFCF3B1B97EA5C91EA47FE1EA39", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Work Folders", "meta_original_filename": "WorkFolders.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.329 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.329", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/cfc058a712b0f1a0932e7fa1f17430eeaa231c41fdd1ead38639d603a8006aca/detection", "children": "control.exe", "runtime_modules": [ "C:\\Windows\\system32\\WorkFolders.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "wowreg32.exe-A94E8C8C8D5D5F7BCD38C9EE5C1C08BF": { "file_name": "wowreg32.exe", "file_path": "C:\\Windows\\system32\\wowreg32.exe", "hash_md5": "A94E8C8C8D5D5F7BCD38C9EE5C1C08BF", "hash_sha1": "EBE201223C357174549CDEC945D1897B0BFFFCE4", "hash_sha256": "FDC250B842E7744BC51D217941465DF1055C9780966E00A701557CCF1F1A6905", "hash_sha384": "7E1090A676BD7B34812EEFD6F6692ADF0F7FF58175A2136D2297C235BF3C8BC225CD4F1E1E895A1D71DE730C46302288", "hash_sha512": "04AE579F76325DB9BB37D9B81F7147315A6BD92CF3FCACD40884924CEBCA89FE9BE4BD4879602574DC84AB018B39F6D336948E89A9B1C8322A3EE188C9D041B3", "hash_ssdeep": "384:i//v1X5Ns17zhiel+5Ob+DQ0CxN71ej46KLrWgTZjHW:i//v1DslzhhgI0Cz7PtBZj", "hash_imp": "9E395710D74BF587FAC4F5CA37BF2548", "hash_pesha1": "7B88EA3260AA49D69458AD624FCC57A1E7E759C7", "hash_pe256": "92E01394C55F420BAEECC954B439C7ABCCB32C78FAFB28129A87742479B803CD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SetupAPI 64-bit Surrogate", "meta_original_filename": "WOWREG32.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/fdc250b842e7744bc51d217941465df1055c9780966e00a701557ccf1f1a6905/detection", "runtime_modules": [ "C:\\Windows\\system32\\wowreg32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "WpcMon.exe-5DC0427001F8FCA8FC0FE80CC0EABECB": { "file_name": "WpcMon.exe", "file_path": "C:\\Windows\\system32\\WpcMon.exe", "hash_md5": "5DC0427001F8FCA8FC0FE80CC0EABECB", "hash_sha1": "D3FF63482FB615663AFC4E4B140226EFE0F370E8", "hash_sha256": "4F81BCCCA5A891C4EA0205973002AE91A18962B882E02B73D76BD72E1C1F1918", "hash_sha384": "0EB84AD202F507FD09524BF7D0A62464FA6606440B2D97F740940FC0BB57EF242B6C8E91FF040D049CC0B63763551561", "hash_sha512": "21F7CB2FB93ED34AA81CE5171205CC5627D11BFC6F684BC0DC70AA1F9DA2EC1F64A6FA4404000260A0DDFEC12259D0FA3EA189316F1935B8247F702B166D4F9A", "hash_ssdeep": "24576:aTq+0dNyt1SHrwFeADXKlL4VfSboTYjG4coF:a2dsCMgAA8hetF", "hash_imp": "D7BF6777BE67ACBE091F892E19199749", "hash_pesha1": "4F13E99BCAB04A1D8F9A3BE3CA1F26DE65DBD543", "hash_pe256": "0CB1613ECA865807152BCF0880C1D351A9B149496F9BE32785D9B710C2959220", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Family Safety Monitor", "meta_original_filename": "WpcMon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4f81bccca5a891c4ea0205973002ae91a18962b882e02b73d76bd72e1c1f1918/detection", "runtime_modules": [ "C:\\Windows\\system32\\WpcMon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\samcli.dll" ] }, "WpcTok.exe-B50219EF074DD572343FE9232417F4C4": { "file_name": "WpcTok.exe", "file_path": "C:\\Windows\\system32\\WpcTok.exe", "hash_md5": "B50219EF074DD572343FE9232417F4C4", "hash_sha1": "115834803E9BAC33808D16503C3202AD617B595A", "hash_sha256": "1558AB156118AD16F990139AFACEB425E5455A6921821A165F9068EEE655E0E3", "hash_sha384": "75DA082FAA17FBFC1632AAF179103E0560BBD3BA950BF253E793FAD9B7E149342DE5CCEB3FBE4577FD96B874C2700630", "hash_sha512": "23997FCCC1AE6BDB4D6E5A5494F9E4375C52DB4DB61E2F252131150A7DBA74EB7D5B4C881831851961A17257E98C49F415E4AAEEDC23B2317BC153DBD1EC9B18", "hash_ssdeep": "6144:rquiYttTsYLCZVwRGEbx+grPVlqGs/hw:rmYtdLCZVwRGox+gr3qGu", "hash_imp": "52DE82B8B6B24E3AA23CAC4F0B872BF8", "hash_pesha1": "0FD2972EDA0914E140AE9E947CC66590FF4E3015", "hash_pe256": "F81AAAD14B9F98D3F348C059988A42DF60A5B5F6E104B877342111BE7776591E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Family Safety Token Auth", "meta_original_filename": "WpcTok.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1558ab156118ad16f990139afaceb425e5455a6921821a165f9068eee655e0e3/detection", "runtime_modules": [ "C:\\Windows\\system32\\WpcTok.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "WPDShextAutoplay.exe-AEC95CC6133FCB8ADF95F3A141F631A0": { "file_name": "WPDShextAutoplay.exe", "file_path": "C:\\Windows\\system32\\WPDShextAutoplay.exe", "hash_md5": "AEC95CC6133FCB8ADF95F3A141F631A0", "hash_sha1": "09EB1C81EA820D6B104021E85AF5E24A07565BBA", "hash_sha256": "C0F8536C11BE99D0128DD970DE2B592B7C558037F07783DF006B552A9C07F17D", "hash_sha384": "40A7F66E3DFA07E911A25F498C88EC4A2329E2E8B8BACF9B1552F215024C2E9A539CF22BB41BD2E3BA9A473D37DF37E8", "hash_sha512": "FE39F828F804963855D58D1F9E88B225962C154DFF89AD4EAAF926C963D02C765545D69C427771FA850D4911F8612936A68E6B42AC880CD22467396E3ED03313", "hash_ssdeep": "768:BQkcgJLEh0oIof0Wo0NiJoUoyFk4oehcrXM8wr:BPJLEqCcWZilFk4FuFwr", "hash_imp": "D6E136D4A9E27F31C5602B427D3226E9", "hash_pesha1": "EE798F1FA5BF6863D23A07A2E19A933FEE9B2BBB", "hash_pe256": "9839B113DD1C012D39E8FF3B579F615D7C14B2B09E21713560B11D41C5517931", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Portable Device Shell Extension Autoplay Handler", "meta_original_filename": "WpdShExtAutoplay.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c0f8536c11be99d0128dd970de2b592b7c558037f07783df006b552a9c07f17d/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\WPDShextAutoplay.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\WPDShextAutoplay.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "wpnpinst.exe-DDC06114E429A71E731FCA21783D987C": { "file_name": "wpnpinst.exe", "file_path": "C:\\Windows\\system32\\wpnpinst.exe", "hash_md5": "DDC06114E429A71E731FCA21783D987C", "hash_sha1": "9DC4B9B3391B90762B28BF2CD30B075701E4396A", "hash_sha256": "BDBDA99CC9903DC782CE7EC2AFCB7EA9851DC63333449841C2C3F917B4D8D3B8", "hash_sha384": "280E99E29D4A9BB0F891AB2C59DA5D67026046726D69D60E6E5D15E1712DD0CB4C58803CE8E93E8C592099728F6AF649", "hash_sha512": "EE2E7A305BACC218AAF9C255D21AD249B5A302E3EFEA104A00650A4DB405D38CDF2E6985B22F8001219CC8EF2F66FF2A941FA093D07DE962E0338450BA227673", "hash_ssdeep": "384:7My5IVOzIZbJqe+aYM0/BeeaJ9VVz7ldwdNlHsplHWAcW:356WoYeCMQeP+/Hix", "hash_imp": "0BFABAEB4CD73DC65E72416C4EDF1553", "hash_pesha1": "8E0999043E9DBBFF903879F907470986554994E0", "hash_pe256": "E218C0CFD9F3EB52F3095E45F3C4C4F797199A693D6AD04CA3C17DCD4D02DFB3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Support exe for Internet Printing", "meta_original_filename": "wpnpinst.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/bdbda99cc9903dc782ce7ec2afcb7ea9851dc63333449841c2c3f917b4d8d3b8/detection", "runtime_modules": [ "C:\\Windows\\system32\\wpnpinst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "wpr.exe-6E4BF60ABB6F9373D5C795D7CD7EDF68": { "file_name": "wpr.exe", "file_path": "C:\\Windows\\system32\\wpr.exe", "hash_md5": "6E4BF60ABB6F9373D5C795D7CD7EDF68", "hash_sha1": "A78B4AEF2DE0EC9675C92FFAABAFA438B79FE576", "hash_sha256": "30940147D6C68C79C9CB8E56CEDB4DAA4F025EDDF1134274DE90DD39D0D8EAD0", "hash_sha384": "A7E008CC9393C194FD46AA6B762920950A51FC613E0A784A93F93B3AC48128D0F049DC6B37BFA7873830D389F7F4B6B1", "hash_sha512": "0F993938797ADFE1E13457A4777946B65679EBD9AEBC84F64D12170E0948596022CE25A3C57C0ED216AF1A957BE5672AEE57B920B26A2416CA74B9B2AC338247", "hash_ssdeep": "6144:egtvJfDldaBXZd0PaHw/kDeuiEKvK5cnbhbYg06X0R:JZJfreXZd0pseuiIS//E", "hash_imp": "E61CD2AA90474CA9DFFAD3043C7DA49E", "hash_pesha1": "E6E806F059535CDAA2655ADEF8979FCD518309C3", "hash_pe256": "D661C1CB218965082FDF827B3ACB8BF7E966E06B098218E1DB70DFC0284BB6AC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Performance Recorder", "meta_original_filename": "WPR.exe", "meta_product_name": "Microsoft Windows Performance Recorder", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.329 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.329", "meta_language": "English (United States)", "meta_legal_copyright": " 2019 Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/30940147d6c68c79c9cb8e56cedb4daa4f025eddf1134274de90dd39d0d8ead0/detection", "output": "\r\nMicrosoft Windows Performance Recorder Version 10.0.19041 (CoreSystem)\r\nCopyright (c) 2019 Microsoft Corporation. All rights reserved.\r\n\r\n\tUsage: wpr options ...\r\n\r\n\t-help\t\t\t - Provide command line help information\r\n\t-profiles\t\t - Enumerates the profile names and descriptions from a profile file\r\n\t-purgecache\t\t - Purges the dynamic symbols cache\r\n\t-start\t\t\t - Starts one or more profiles\r\n\t-marker\t\t\t - Fires an event marker\r\n\t-markerflush\t\t - Fires an event marker and flushes the working set\r\n\t-status\t\t\t - Displays status on active recording (if any)\r\n\t-profiledetails\t\t - Displays the detailed information about a set of profiles\r\n\t-providers\t\t - Displays detailed information about providers\r\n\t-cancel\t\t\t - Cancels recording initiated via WPR (if any)\r\n\t-stop\t\t\t - Stops recording initiated via WPR (if any) and saves\r\n\t-flush\t\t\t - Flushes logging sessions initiated through WPR (if any)\r\n\t-log\t\t\t - Configure debug logging to the event log\r\n\t-disablepagingexecutive\t - Change the Disable Paging Executive settings\r\n\t-heaptracingconfig\t - Change heap tracing settings for a process\r\n\t-snapshotconfig\t\t - Change snapshot settings for a process\r\n\t-capturestateondemand\t - Capture states for the configured providers in the current recording\r\n\t-pmcsources\t\t - Query the list of hardware counters available on the system\r\n\t-setprofint\t\t - Set sampled profile interval\r\n\t-profint\t\t - Query the current profile interval\r\n\t-resetprofint\t\t - Restores the default profile interval values\r\n\t-boottrace\t\t - Configures the registry entries for autologger/globallogger sessions\r\n\t-enableperiodicsnapshot\t - Enable Periodic Snapshot for the specified interval and given process id\r\n\t-disableperiodicsnapshot - Disable Periodic Snapshot for all process\r\n\t-singlesnapshot\t\t - On demand Snapshot for the specified process\r\n\t-instancename\t\t - Specifies a name to uniquely identify the tracing instance. \r\n\t\t\t\t Useful when managing multiple concurrent wpr sessions. Must be last parameter.\r\n", "error": "\r\n\tInvalid command syntax.\r\r\n\r\n\tError code: 0xc5600602\r\n\tInvalid option: --help\r\n", "runtime_modules": [ "C:\\Windows\\system32\\wpr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "write.exe-B947CCA7F485F6C1156F4D02E8C9874F": { "file_name": "write.exe", "file_path": "C:\\Windows\\system32\\write.exe", "hash_md5": "B947CCA7F485F6C1156F4D02E8C9874F", "hash_sha1": "9F184E48F17F104C6A476687E8E760A65A0326B5", "hash_sha256": "A70D52EDA892EDC073932B462CC367CDBFBACE3F4196857D8D4FA869A13DE792", "hash_sha384": "54333EC10CFCAB874257FA46DCF5E9F30D3F982B194D32C4022D7533AB04356D7093EF6B2552D164126EF9B5D2AB830D", "hash_sha512": "28C6FF32BC94AAD8B201E469F854DDE32CAD9EB2E7A80ED858AC2FF99648312CECCA06918BCE96E8D905D52D5EBEE076BD08D957F7933602C0C79D93EAD20EE3", "hash_ssdeep": "192:ZV89t7hglDCS8O3GbXdYFWihWxu/sWGOW:ZVM7hceSP3IXioxu/sWGOW", "hash_imp": "90A23F469BA0443719430CBA4569B220", "hash_pesha1": "A4F66FA28EB11A219C177052029687C0C3E983CE", "hash_pe256": "C0B77A27E77A38B21724E115C8BF3C8EF59F820DAF3AE4F83084218C730DA403", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Write", "meta_original_filename": "write", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/a70d52eda892edc073932b462cc367cdbfbace3f4196857d8d4fa869a13de792/detection", "children": "wordpad.exe", "runtime_modules": [ "C:\\Windows\\system32\\write.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "wscadminui.exe-99D392604486D81F2F0AC21ED5A13091": { "file_name": "wscadminui.exe", "file_path": "C:\\Windows\\system32\\wscadminui.exe", "hash_md5": "99D392604486D81F2F0AC21ED5A13091", "hash_sha1": "6D392969F15F4D690EFFBF2C4391860C274F951C", "hash_sha256": "9AFA38359D1960A2366522E0658D656DD984A0838AF491EC51E179B444394985", "hash_sha384": "D783F5C8F9F66B386C17B785990EC024DEB7A70F402DF86AC8A6136092B429BB0DCC0792E97FC5B27F731C4786ACA09D", "hash_sha512": "A3AAAD47F9BDA9DBEB4423B99B9E23251D15B358F2B99EFF3262755909A378FE901D32432069352BFFA03F0F946BDD17384D7591045997B867189D6E2A052A8C", "hash_ssdeep": "96:TCfIlqZhGhbHHgP32Qz69cVvbDrahnVZxzX29snVkG1FREWehRWw:TUGKhGCGzqVvvGhdhWG1FSWehRW", "hash_imp": "95DFB21A6AA7374716FD58473502A86F", "hash_pesha1": "60A8B6A142CA7B2DC6737C926C06C5AF6ECBD23F", "hash_pe256": "0F1B15B8371A92F15535DCE98E54DC8E5D52CFCBF7A71DD1FF5F5FCA7100D371", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Security Center Elevated UI App", "meta_original_filename": "wscadminui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9afa38359d1960a2366522e0658d656dd984a0838af491ec51e179b444394985/detection", "runtime_modules": [ "C:\\Windows\\system32\\wscadminui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\WSCAPI.dll" ] }, "WSCollect.exe-1C4F7AB2AD0B867487E42F77A637A3F2": { "file_name": "WSCollect.exe", "file_path": "C:\\Windows\\system32\\WSCollect.exe", "hash_md5": "1C4F7AB2AD0B867487E42F77A637A3F2", "hash_sha1": "41E27983E2D168B28F6702F0AD4DB83A5A24C926", "hash_sha256": "B9FBB27BE73E23A835B4B8803C82775274BE26339BF68F1F7C0499DE3D330533", "hash_sha384": "B7BF141C3EBD28FF94E218AA77F62849030502169893FBE1A69ECBD8E390B28C2A24161396D01E1E9B0BF3E6BAAF521A", "hash_sha512": "79CB56DF25C5849D28D72CBA87B1687F91616DC4B9F97C414C2DCE0BB3D83C0EB5E2412D1CD3868F093AD4E8C48132FA3B6CED9D14EEAB170845D120CC123BEC", "hash_ssdeep": "768:v7FfBiRLtfp5oscQ5vCJfoDNsn4FOBkStBWO:SRhfp5oscQ5vqfoAg0YO", "hash_imp": "9F02A366D38804E1F04B39C5385F776C", "hash_pesha1": "08D30935C4EA3BF7F5536A1286AE72B79C6982DA", "hash_pe256": "51D1594F03092C31639485B0C65A4D7F950EA24CDA964FEE1D11DB446D47E834", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "This tool collects Windows Store log files", "meta_original_filename": "WSCollect.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/b9fbb27be73e23a835b4b8803c82775274be26339bf68f1f7c0499de3d330533/detection", "output": "The operation completed successfully.\r\r\nDone.\r\n", "error": "ERROR: The system was unable to find the specified registry key or value.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\WSCollect.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wscript.exe-0639B0A6F69B3265C1E42227D650B7D1": { "file_name": "wscript.exe", "file_path": "C:\\Windows\\system32\\wscript.exe", "hash_md5": "0639B0A6F69B3265C1E42227D650B7D1", "hash_sha1": "545EC11DEE642DE633EB2C6F6FFC90CCE4DECF8D", "hash_sha256": "CE9F70E104C07D92FC05FBD6000839FD6A87FF010E706396F87DD679244ED97B", "hash_sha384": "BBB058996AD1F6209658DE1DD20258BE8BFABBE897AA223655B364CF4CB99A943FA4DA9E45C5681311BDDE434AD08D06", "hash_sha512": "4504E1F26D83AA4F23AD4DF55034AD6A0292DB33234CAC660A6A617DC7CEBC78B99312933AF83F1633C0A991FFE798C8B7755523569E3CE3966A115DDDD8306A", "hash_ssdeep": "3072:03dUXpcpsc9NrGoRd27i3NJVjU2Qw4+WUZxtt:03cpcpVfjj27i97eb+nZh", "hash_imp": "0F71D5F6F4CBB935CE1B09754102419C", "hash_pesha1": "EE6F4E20F6275BE3700BB7E99E7408ACD8B4CC32", "hash_pe256": "B9AC2057A05D02862AD083976A638D42DA4E4A0B99CC58A5C9E92FA7BDD27D88", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Based Script Host", "meta_original_filename": "wscript.exe.mui", "meta_product_name": "Microsoft Windows Script Host", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.812.10240.16384", "meta_product_version": "5.812.10240.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ce9f70e104c07d92fc05fbd6000839fd6a87ff010e706396f87dd679244ed97b/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\wscript.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wscript.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll" ], "runtime_window_title": "Windows Script Host" }, "WSManHTTPConfig.exe-77CEDB1A7736FD7E25C5C333D1FCE56C": { "file_name": "WSManHTTPConfig.exe", "file_path": "C:\\Windows\\system32\\WSManHTTPConfig.exe", "hash_md5": "77CEDB1A7736FD7E25C5C333D1FCE56C", "hash_sha1": "DAB1ECA6EA2DEB8CE11D91F9E1EDB5FCB68CF573", "hash_sha256": "A152A611D0AB437A194A199FB36B3AE35302124F5935D6991AF9083E2BBAC5CE", "hash_sha384": "14A6E33D4CCBB3F62CE634F34D2ACB55F00BD2E58989F0CAF6E7E40C9560B1CCD134075351637661B87BBB9D1D9D5B38", "hash_sha512": "79A7E704973D325DDE84C0D157410111FFB77155C10422C143EDA02A4B23FF86CDF7831AFA32CC8B9216335FAEA32637A1CFD67BFC5901BE0548809084FEE84E", "hash_ssdeep": "768:/x5XDOb98ZtDFK7l0cxV0eOHfi//2e2csdn:/XOb98Q+AV0hfi/x2cin", "hash_imp": "822DC9AB765EDBCD88EF1608A7BA0BB1", "hash_pesha1": "6EA7C29D3F8BC95B625D7BC065D93576645382DE", "hash_pe256": "B36C21F7D4E42194975B747CE0559E50D7D4ABE7FB7B655560DBB58AE82391C9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WSMan HTTP Configuration File", "meta_original_filename": "WSManHTTPConfig.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a152a611d0ab437a194a199fb36b3ae35302124f5935d6991af9083e2bbac5ce/detection", "error": "WSMan Generic Command ERROR: Unknown switch: --help\r\nWSMan Generic Command ERROR: Error in parsing input\r\n", "runtime_modules": [ "C:\\Windows\\system32\\WSManHTTPConfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wsmprovhost.exe-345926C1D6E692E0054E1B2A61E202EC": { "file_name": "wsmprovhost.exe", "file_path": "C:\\Windows\\system32\\wsmprovhost.exe", "hash_md5": "345926C1D6E692E0054E1B2A61E202EC", "hash_sha1": "B1A32230391B6D87D255053DE0FD262C8329DDB8", "hash_sha256": "0FBB9BE7CA2AAFDE4ED8614A3A9DEF68E5AF1A2CB2E15D6CBCBF7B72F4DCD3B6", "hash_sha384": "00677AA6CE6EB666B2032BC7D8AA8F9D2B5C0ACB69E294F53EE51CACFDAFF19E969B7E5054330D3890FF822CDDB9A759", "hash_sha512": "6F569BA2E9F9E8ECD4162B1D649B29E5AD74466AF2EDE8DCF24EA0E209F66307C962D450EDEC5D1F213A62665624578F0A156106AE86C66D8322F1E046170544", "hash_ssdeep": "384:CBbTa6lzIQJ2bmEl5TpJYxpQU5Rs+U9ixUzeESb9eVKl2RNGLr/PyboQinL7ueW0:CBvyV5H8ZRs+ClSokl0NGLrqbBiLaAj", "hash_imp": "E54118702A5DA1E2A145713FB7D6A53B", "hash_pesha1": "B844888BCF722E0CB82AF20E448B060A40B80891", "hash_pe256": "7EFFEAC7EACF591FB2AF21C40C758FEEC27950BA0E34B0A597F282B3FDD3991A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host process for WinRM plug-ins", "meta_original_filename": "wsmprovhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0fbb9be7ca2aafde4ed8614a3a9def68e5af1a2cb2e15d6cbcbf7b72f4dcd3b6/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wsmprovhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\WsmSvc.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "wsqmcons.exe-78EBE5D865E3618F6275EFC7A54963C9": { "file_name": "wsqmcons.exe", "file_path": "C:\\Windows\\system32\\wsqmcons.exe", "hash_md5": "78EBE5D865E3618F6275EFC7A54963C9", "hash_sha1": "6E01CCE73376DC359E0BB1F20F36E1E3DF3D1793", "hash_sha256": "B78663AF2C7177CBB51A1CB62219D8737ACC5BD76A0D9C037C949406FF5768CB", "hash_sha384": "E4EE6E7E0E2661EB1C22B7D581DF349AF7641935E946F9577989CC5F30575AD2C34E87CEDF6AC5E4F4B59D6A71D40EFD", "hash_sha512": "4AF7170434FEA194925524F3922FC18F25506AED4537FBFA86A0230F111EF6AF8AF8F60315188562673B5DE9392E9896A82163E5B0C4A2792E8D9101BB748963", "hash_ssdeep": "1536:msvpIBM5HxjuPsMpNWxA8FrMqDL5an3YZEW+yyoecNtS3JPVo1GQumre2q61:UM3dxF3D8IZf+zE43JZQuCe2t", "hash_imp": "16504DCDB7B5511E296EEF5ED950DDD2", "hash_pesha1": "AA5C11532A3471A546E17B6EA25844D54F0A6C92", "hash_pe256": "DF65EA7CD1B9A0D59C30B64343369991475F2E4B4077B9D6B25D7EC139E43AD8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows SQM Consolidator", "meta_original_filename": "wsqmcons.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b78663af2c7177cbb51a1cb62219d8737acc5bd76a0d9c037c949406ff5768cb/detection", "runtime_modules": [ "C:\\Windows\\system32\\wsqmcons.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "WSReset.exe-C08D9492A11813196000AF9E4F5EE23F": { "file_name": "WSReset.exe", "file_path": "C:\\Windows\\system32\\WSReset.exe", "hash_md5": "C08D9492A11813196000AF9E4F5EE23F", "hash_sha1": "2404225C00764ADB780FF21C06890CFB3FA327F0", "hash_sha256": "E1E8F9FB5503A7EC9731BC81CDD3F428001C2AFB0528CF99DA451C5220A1580F", "hash_sha384": "39474778BF617D16343F3FCADF197C268EA1B9409B5C6C3DD16061188A75F9AA4E638A9F82182301FD81B9989A7352C6", "hash_sha512": "6F3539EC0F15184F887D2CC8417D5133FBED65666A8FA4459351422F408401B13CCBA3162B9BF8693E5F24858DD72155FF1EB7409ECF6692FDFFD4CA1C53BEBF", "hash_ssdeep": "768:lJKVfVIDwlvjEFLSj1cKSSSzSSoMo9b1Nsn4FOBkStBW/:mbiMjEFLi1tFGg0Y/", "hash_imp": "AB03184F9306BF7E8482C6F987BA1832", "hash_pesha1": "AAE557C6EDB843CB97C908076D2453840BC752D8", "hash_pe256": "A82F5E43E6F796FA94FAABA7CA3FC0252817753CB4B36E916EE57BB457F9255B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "This tool resets the Windows Store without changing account settings or deleting installed apps", "meta_original_filename": "WSReset.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/e1e8f9fb5503a7ec9731bc81cdd3f428001c2afb0528cf99da451c5220a1580f/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\WSReset.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wuapihost.exe-9E41B17E9BE29C963E8AE84D42BCEB45": { "file_name": "wuapihost.exe", "file_path": "C:\\Windows\\system32\\wuapihost.exe", "hash_md5": "9E41B17E9BE29C963E8AE84D42BCEB45", "hash_sha1": "9D37F7356576B1D8697FD790C18F278871ECC164", "hash_sha256": "BA77D5EBACBAD0939B9EE667C59BCB7143A432BE91522F4397D458E62F03EEDD", "hash_sha384": "8B42E35BF366A48569FEBE0C4B197CAFCE0164177079DB2920CDF47A4ECFB6C247A3919F3648D89DEDC9FFCD0F52F96F", "hash_sha512": "AE9DF79A3B98073A39CDEE6866075BB5BC8A7258326068674CDFDEF22A0F01E5601CFDA78CF416CBBD55DB707BC2AA10804B9503C8A9875EA566425D9C2A34DE", "hash_ssdeep": "192:7YY+HRgEnp0aqP5S5d/is2qbhK6vZK4/s2qtdmko8ebet/NRWPfW:kY+aEn5acL/JfhKH/5RH/7WPfW", "hash_imp": "04AC43054DE90C6C2629EAD16AB86780", "hash_pesha1": "ABDC985E335C82059CADA749770AA4F6314EC85F", "hash_pe256": "99553469147BD673369C942448B01D6A799B9EDD1FFAFCEE5015F38A25DBA998", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "wuapihost", "meta_original_filename": "wuapihost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ba77d5ebacbad0939b9ee667c59bcb7143a432be91522f4397d458e62f03eedd/detection", "runtime_modules": [ "C:\\Windows\\system32\\wuapihost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll" ] }, "wuauclt.exe-42B8C692B9A93F2224CA4BA56B99FC37": { "file_name": "wuauclt.exe", "file_path": "C:\\Windows\\system32\\wuauclt.exe", "hash_md5": "42B8C692B9A93F2224CA4BA56B99FC37", "hash_sha1": "1C7C8733DD0CD2F42B498E988F099EC03FC3C012", "hash_sha256": "6390C42F0DD21C9611D2EB9C7929F5213A95438D4FBFE0D4EA2ADF1271F0696F", "hash_sha384": "BCDBA036D6AFB89B9C4C713516048E10B6C037FB29F807F17E80C6AA3E73C406E510F75D66955A4EA0B779E782329AE0", "hash_sha512": "2D69A5769B76F97AC8573BD823C91782C280704E5D1362D125F4C49D599705124FB701D95A16894252B49BB3C34D5893EC04EE135055BCD877CA769D7C72DB89", "hash_ssdeep": "1536:WK0T48tY6HAqCsd56ncytR7TBH5KZYacAPt:WKE48tY6H/FPAHH5AYacAl", "hash_imp": "B90160F88EBACE2E5AC66C36689E0BDA", "hash_pesha1": "E4452CFDB3CA41C1A7B1B96905D4CFDA4E44A03C", "hash_pe256": "F83E184874AF59575F591061B6DC4B23E46F066E3AE66715E80BBFE838105778", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Update", "meta_original_filename": "wuauclt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6390c42f0dd21c9611d2eb9c7929f5213a95438d4fbfe0d4ea2adf1271f0696f/detection", "runtime_modules": [ "C:\\Windows\\system32\\wuauclt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "WUDFCompanionHost.exe-3205CAC02430B308B141390A9F536E7C": { "file_name": "WUDFCompanionHost.exe", "file_path": "C:\\Windows\\system32\\WUDFCompanionHost.exe", "hash_md5": "3205CAC02430B308B141390A9F536E7C", "hash_sha1": "7E13C97C24969004CA0F9D4B0C5903C29A5CD842", "hash_sha256": "493433767C039A105A6FF53305CF0CF34F85A737D94BAFCA4E449284675AE34F", "hash_sha384": "2E99DDF2A3403C8F5116444B89C89E31597DC1556BE2BA793DF7228CAC732EBA7516812596E87127D5136B2E76739F2D", "hash_sha512": "58586D6EB0B4BDB9A4B85847810BA1E5F3F7A66274F559423D927C68B09E73CCD6AD09CF076DCC9A62C2C2C380BCCA292481EEEF69C9903761B9AAE1C470D319", "hash_ssdeep": "3072:9GVLyyv9RNNId5aci25bCTZR5tIPBu0YuAt4QxG55uaDxV:9GVLyyv9jNId7i25bCTZR5tJ09Qxe", "hash_imp": "7B21670FB2AFAC237D5B032D5E6A35FB", "hash_pesha1": "3A737D6D1F828B4708294CE5B42203B1F535A85D", "hash_pe256": "4C2E8144B47EE2E884AABE9449583499EEE2EFFD6D4FF921C4F9CC4BAC5E2C32", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Driver Foundation - User-mode Driver Companion Framework Host Process", "meta_original_filename": "WUDFCompanionHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/493433767c039a105a6ff53305cf0cf34f85a737d94bafca4e449284675ae34f/detection", "runtime_modules": [ "C:\\Windows\\system32\\WUDFCompanionHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "WUDFHost.exe-8E3F4F1D20179DB86CAF4C7E110DFC18": { "file_name": "WUDFHost.exe", "file_path": "C:\\Windows\\system32\\WUDFHost.exe", "hash_md5": "8E3F4F1D20179DB86CAF4C7E110DFC18", "hash_sha1": "2367C318C59A945DC0C07A9C879C81F2F870E08C", "hash_sha256": "E6F5DE8BC3FC572D9A2866024C5AF3A83A4D70F4D38810B9E7679A2E9F89775C", "hash_sha384": "2C4100316B220AE42D4D952FDE5ADC9BBED2820F97D3955585EDFB271C53F08D67A41F7682141A3EDE5F9BF71F5F2EDA", "hash_sha512": "8C550010324504998897139E5AE7DC23D661128EC814010DE52C7FB5459620BE4CE34C9E4FE2275A7C0B28D123B0465501543E77986FD8D2CA6C41A0532FB067", "hash_ssdeep": "6144:2Tm48xdj2eu0c4Q5zEO08mFnGxl9dG2Xdmzopj/qn:2TmXeKc4Uj97/A", "hash_imp": "3FB4FBF226FDE242843AE0A7C907D1D5", "hash_pesha1": "E755599F0196CFB8A5FFEDFF7DAA90139213E789", "hash_pe256": "E1FDD4542FD032CF0ECE159FCD362E7DF94A78489467D469ADD0A6FD19438691", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Driver Foundation - User-mode Driver Framework Host Process", "meta_original_filename": "WUDFHost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e6f5de8bc3fc572d9a2866024c5af3a83a4d70f4d38810b9e7679a2e9f89775c/detection", "runtime_modules": [ "C:\\Windows\\system32\\WUDFHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\DEVOBJ.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\SYSTEM32\\WUDFPlatform.dll" ] }, "wusa.exe-8A0B789F779802881EEAC4F99532A35C": { "file_name": "wusa.exe", "file_path": "C:\\Windows\\system32\\wusa.exe", "hash_md5": "8A0B789F779802881EEAC4F99532A35C", "hash_sha1": "5E01067FDAA7EB84CEDEF00D0D3C238455DB4846", "hash_sha256": "2AF3885AB02E20B64C60AE7D8E2B3E07667529C5A7699CE16AD83D33AB781020", "hash_sha384": "0CEF8CA30B8F007432E455C3842C21E23E8AFBE3516AF440F64D70BCAE0AEDA7D6F056B2EE3E021B81DF7D77550E22D8", "hash_sha512": "0567735C1D47FB0CC54FE76045250B79911A1308112047BE158F32D04347E2BAD6F6A15B1369AA7C8A60BEC347F721924F26F9F1FDC5889FC3241BEF017A32D9", "hash_ssdeep": "6144:3qOUK0HBOfIkdjnI+iczCL4cM0ZggD32bItObtMHxM8cL9hpxyN90vE:3qOaBOfIkdjnI+iGCL4cMkggD32bItO5", "hash_imp": "9565B2082CB4F1BF01973EA3AEE6DC58", "hash_pesha1": "36268FE565B9F49B72B916CA6EF4A0818D548D46", "hash_pe256": "F5CCD290D6D71F707F0C749BEB56674ED7021E22BF36B2C8A5575F150C4EA4C0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Update Standalone Installer", "meta_original_filename": "wusa.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2af3885ab02e20b64c60ae7d8e2b3e07667529c5a7699ce16ad83d33ab781020/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\wusa.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wusa.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ], "runtime_window_title": "Windows Update Standalone Installer" }, "WWAHost.exe-7D9FA478A888364A5F82A8C9C2A45D9C": { "file_name": "WWAHost.exe", "file_path": "C:\\Windows\\system32\\WWAHost.exe", "hash_md5": "7D9FA478A888364A5F82A8C9C2A45D9C", "hash_sha1": "A7E0A33307AC640577F747EB153A2C4DC3FE4F00", "hash_sha256": "1B3069159897DBBB2518C1698A4A62FDE15E5475717CA177A3677B9E9D5FA7F9", "hash_sha384": "3C647765A7E5B9CBF2004CBAC3C6D2F757D4B9566F6E69F55AB7B64D7F643102548F19F83C5166B1EA8CFF1739E66261", "hash_sha512": "EBEC8DC0BD9C3FD31E6BDB051DDF985406F0082F21C47614F672B7468C0E7F6E2E02780A160B4FACA7DBEA437933D4BF44CFA9BC58DAA069FB722028BF42A4C1", "hash_ssdeep": "12288:52sEToothRP1iTbdlQlJm/LtVbSOFOvUhc4C/qB7AaS47CNwfpULpL4LaLvKLSLg:DELzgBlQK3aoPpg7GfjZ89vQ", "hash_imp": "EBA419BF1904E24EBC1D5E420D4E0E2E", "hash_pesha1": "E533D3E1BB8BCE0133BC6A02EF265F1E685A043B", "hash_pe256": "FD6A759CB2081622684477B576806C6565942E222FC01186CC37DB3B7C68E13F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft WWA Host", "meta_original_filename": "WWAHost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1b3069159897dbbb2518c1698a4a62fde15e5475717ca177a3677b9e9d5fa7f9/detection", "children": [ "WWAHost.exe", "WerFault.exe" ], "runtime_modules": [ "C:\\Windows\\system32\\WWAHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "XblGameSaveTask.exe-B3D4334C3207386D47C8B5E0C21210F6": { "file_name": "XblGameSaveTask.exe", "file_path": "C:\\Windows\\system32\\XblGameSaveTask.exe", "hash_md5": "B3D4334C3207386D47C8B5E0C21210F6", "hash_sha1": "B61A35285AE452FD44A8F30720EE1EE0D1DC53DE", "hash_sha256": "A6F8B7E0547ACE0D54485AA79FDC4C7C83EE9E363EB30E8E401CB57B4494619A", "hash_sha384": "3F0A412C02B2A1DC2AB6A230E63DCCC64EED1F5FF5BF4E7FD0DDA45BC953E59B5DF2C657992E47494494D639CD12FD13", "hash_sha512": "9D5D1A808473BDCB36AE15033EE1BE7285D15859AD0F5AF59F63B6E7EAE38E0AE978AC6EB797CD0BB137E87AB7B5863CF1659E4674BF9FD3A08D73C723102FF4", "hash_ssdeep": "768:NUc/ni/OA4AILlAJwsmYYspdoVhuCrQ1UXC:OtOAkLPsmYYspOVhuUUUXC", "hash_imp": "5FE4D2E140ACB326C0C6CD7C4EF83C9F", "hash_pesha1": "08331C9DE89646B60C07B272CB38AF99F210450D", "hash_pe256": "D8FDABF439CB620A80BE88392C07C5F0E4DBB57FAE5AD828FE0A2E803B808811", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "XblGameSave Standby Task", "meta_original_filename": "XblGameSaveTask.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.264 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.264", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a6f8b7e0547ace0d54485aa79fdc4c7c83ee9e363eb30e8e401cb57b4494619a/detection", "runtime_modules": [ "C:\\Windows\\system32\\XblGameSaveTask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "xcopy.exe-39FBFD3AF58238C6F9D4D408C9251FF5": { "file_name": "xcopy.exe", "file_path": "C:\\Windows\\system32\\xcopy.exe", "hash_md5": "39FBFD3AF58238C6F9D4D408C9251FF5", "hash_sha1": "C5BD7815ED18F7E3D1CE93CC47AECF58D908DCA8", "hash_sha256": "269EB0728413654856F4B2EE1FA7838CD69672EBC11BAED4CAA63F58C2DF5823", "hash_sha384": "27409A9A6F56C88F47482C79A5E63C9D28FF87AAF2E77DDF2C6A90111CC90CE24C0447CFB9DB72A79A45C2CAED64F9A7", "hash_sha512": "B1CF7952F4C5D049C6BF076A34ABA5789833EF208C3E8AB1DE300D96C9E7FFCFD13E0B458FF608105395B57CEC7FE0F2DD240C942E9E727E13BF5686C752E336", "hash_ssdeep": "768:MMrZVvJJntoBFNqe9BGJ3t+yzXzDbJX5t30fRynjjZgxMae:M8ZVvLCB/qOBGJ3tnDzDFLE8nax7e", "hash_imp": "1EFFE65A4F251E4AE9FA8551F9FCDABB", "hash_pesha1": "8694FF3A1C3A67F338DB5C391C989BDB76E99DB9", "hash_pe256": "6ADD938B26A573378BEFEB6C5CD9E539476C1378227C0979AA62F45D738C03AF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extended Copy Utility", "meta_original_filename": "XCOPY.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/269eb0728413654856f4b2ee1fa7838cd69672ebc11baed4caa63f58c2df5823/detection", "output": "Copies files and directory trees.\r\n\r\nXCOPY source [destination] [/A | /M] [/D[:date]] [/P] [/S [/E]] [/V] [/W]\r\n [/C] [/I] [/Q] [/F] [/L] [/G] [/H] [/R] [/T] [/U]\r\n [/K] [/N] [/O] [/X] [/Y] [/-Y] [/Z] [/B] [/J]\r\n [/EXCLUDE:file1[+file2][+file3]...] [/COMPRESS]\r\n\r\n source Specifies the file(s) to copy.\r\n destination Specifies the location and/or name of new files.\r\n /A Copies only files with the archive attribute set,\r\n doesn't change the attribute.\r\n /M Copies only files with the archive attribute set,\r\n turns off the archive attribute.\r\n /D:m-d-y Copies files changed on or after the specified date.\r\n If no date is given, copies only those files whose\r\n source time is newer than the destination time.\r\n /EXCLUDE:file1[+file2][+file3]...\r\n Specifies a list of files containing strings. Each string\r\n should be in a separate line in the files. When any of the\r\n strings match any part of the absolute path of the file to be\r\n copied, that file will be excluded from being copied. For\r\n example, specifying a string like \\obj\\ or .obj will exclude\r\n all files underneath the directory obj or all files with the\r\n .obj extension respectively.\r\n /P Prompts you before creating each destination file.\r\n /S Copies directories and subdirectories except empty ones.\r\n /E Copies directories and subdirectories, including empty ones.\r\n Same as /S /E. May be used to modify /T.\r\n /V Verifies the size of each new file.\r\n /W Prompts you to press a key before copying.\r\n /C Continues copying even if errors occur.\r\n /I If destination does not exist and copying more than one file,\r\n assumes that destination must be a directory.\r\n /Q Does not display file names while copying.\r\n /F Displays full source and destination file names while copying.\r\n /L Displays files that would be copied.\r\n /G Allows the copying of encrypted files to destination that does\r\n not support encryption.\r\n /H Copies hidden and system files also.\r\n /R Overwrites read-only files.\r\n /T Creates directory structure, but does not copy files. Does not\r\n include empty directories or subdirectories. /T /E includes\r\n empty directories and subdirectories.\r\n /U Copies only files that already exist in destination.\r\n /K Copies attributes. Normal Xcopy will reset read-only attributes.\r\n /N Copies using the generated short names.\r\n /O Copies file ownership and ACL information.\r\n /X Copies file audit settings (implies /O).\r\n /Y Suppresses prompting to confirm you want to overwrite an\r\n existing destination file.\r\n /-Y Causes prompting to confirm you want to overwrite an\r\n existing destination file.\r\n /Z Copies networked files in restartable mode.\r\n /B Copies the Symbolic Link itself versus the target of the link.\r\n /J Copies using unbuffered I/O. Recommended for very large files.\r\n /COMPRESS Request network compression during file transfer where\r\n applicable.\r\n\r\nThe switch /Y may be preset in the COPYCMD environment variable.\r\nThis may be overridden with /-Y on the command line.\r\n", "error": "File cannot be copied onto itself\r\n", "runtime_modules": [ "C:\\Windows\\system32\\xcopy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "xwizard.exe-30C784340F42DB44A84C7958C240E394": { "file_name": "xwizard.exe", "file_path": "C:\\Windows\\system32\\xwizard.exe", "hash_md5": "30C784340F42DB44A84C7958C240E394", "hash_sha1": "A9611D90310FE54D0F78E7E067B00C9D53C870C3", "hash_sha256": "4359C82A6760D717EC367BC80B1A70E149BF7E197EA45C1188A4826570B96C50", "hash_sha384": "A339A0099D201304612ADBACC84D0E81132C0BB3CC73A7D6A7F8764CCD661AFA04390F98C922E310CAFFB3C0A9CD6CC1", "hash_sha512": "F5F7DA6505DFDE7060EC0FB186915F4390EB1D0A3048EFFC65DF41B9B6201E501BE1AD6CB3DB8F626451FD3FDFAF5EF9D615200B7D039F79E93EF74E4A359D8E", "hash_ssdeep": "1536:Q6/9faJbkDGuJjMVxMckeR1Ea/0z/v7SIiuIJcURDoq4OZZZLlCIib:Q6/9CJbUGuJjYM57CuIJ9RD68wb", "hash_imp": "42465F712C75BD79EB46ECE0D31A4B8D", "hash_pesha1": "8C6D1387B27148E3DD998ED4B79D7A87CDCED1E1", "hash_pe256": "86F45225EDBB0758C7B7ADCDB80F6021DF4761538423387E08A024113240F9CD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extensible Wizards Host Process", "meta_original_filename": "xwizard.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4359c82a6760d717ec367bc80b1a70e149bf7e197ea45c1188a4826570b96c50/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\xwizard.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\xwizard.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "AppVStreamingUX.exe-95FF56D9254F8E3B18CD72AA88E19160": { "file_name": "AppVStreamingUX.exe", "file_path": "C:\\Windows\\system32\\AppV\\AppVStreamingUX.exe", "hash_md5": "95FF56D9254F8E3B18CD72AA88E19160", "hash_sha1": "A496D332EADF60FDFCCFBD31450703A67901C00B", "hash_sha256": "31D93C67E67B38FE607E17D87AFAAF63C1B0D6FCA8586C2001F1BFA1A5564D87", "hash_sha384": "F994AEB22794133620F55C44FAE6FC1998A20EB60EA5E7AEA105DDDF255023EC181223A0F48B5A88F66F78BF584ADDB5", "hash_sha512": "D3600C9AF40D8082D2B41C61C2B896890D6670B0414BC1CD3BFEB0FA0CEE5C620E5B16AE4B63D628BD5CBA49094F6726E64CB2E7D42B4B572D3DC793E48E51AE", "hash_ssdeep": "3072:7yIen7ExTWZLS0dxYkEmIjedpjMqVVdmabWcONiHNp6ei/EzUHMqVVdmabWcONiO:s7ExKZddZCaqg6RcmCaqg6RhP", "hash_imp": "n/a", "hash_pesha1": "84A647EB000AFCDA13AFD5751E1E9085015DACFF", "hash_pe256": "F0304EF000B244E693EEBAC4F7900E29C245785134770ECB147D15FAA4F51DE8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/31d93c67e67b38fe607e17d87afaaf63c1b0d6fca8586c2001f1bfa1a5564d87/detection", "runtime_modules": [ "C:\\Windows\\system32\\AppV\\AppVStreamingUX.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "winresume.exe-D9341DC8E1A66AC40B3CDF5BB6BE151B": { "file_name": "winresume.exe", "file_path": "C:\\Windows\\system32\\Boot\\winresume.exe", "hash_md5": "D9341DC8E1A66AC40B3CDF5BB6BE151B", "hash_sha1": "ED64E0E8583203C5C8A9FB382E377874B9527D18", "hash_sha256": "093A8BBF4407FCB92E6D70CCBEADB7F7489C81C91A5149976F04FA923132407C", "hash_sha384": "E1E6AD79D831AEF8EB35A4A201B4BE58E75C7C7294C50FEFEC6CCA1E6ED617E277DE62C1122D48BD6872C608C72416D8", "hash_sha512": "B02855CB35ACF923F7BFEDCA3F37EF5FF3E8FC1B4CF598CA4AEEBC48CAC2D1955B41F4218B78954B02761B157540CE0AFE68E0567C0B76AE6CB0595D93215826", "hash_ssdeep": "24576:1C1vP37zfr+k0k9VyJ7BAs2cJSidPm7oI0J:Y3ri71BgcQihm8/", "hash_imp": "n/a", "hash_pesha1": "1227014AA7DB24562C208047B3E2CD091159D493", "hash_pe256": "395372FE87F65834C800A995E3DE16802E684811986A18F2F2A0D4A6F6E94177", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resume From Hibernate boot application", "meta_original_filename": "hiberrsm.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/093a8bbf4407fcb92e6d70ccbeadb7f7489c81c91a5149976f04fa923132407c/detection" }, "comrepl.exe-920731B00424E33934AD8BB4A923CFE1": { "file_name": "comrepl.exe", "file_path": "C:\\Windows\\system32\\Com\\comrepl.exe", "hash_md5": "920731B00424E33934AD8BB4A923CFE1", "hash_sha1": "315F6DF5C9059A1FA40C19EECC3E102F41598309", "hash_sha256": "1A9B9B536A195D25F0B97B741CF4E44C22ABEF8B0355BF8ADC8F5C176B74204E", "hash_sha384": "C01D8B548A17383CF00B55AEE6639FBDD3C0895619A8673C9D4C08BE12C23E80503C928E59FEB4292B5E95F6CDC2871C", "hash_sha512": "A9C24CEBC1B7B91FA5EA008FDA50CD5DEED374BC48DEF055318DC1013CDD8107B8246F3EEC561FF9953A697827449E5C8885D4A8550AB6215A9A8453009ACE6B", "hash_ssdeep": "384:oMUCSbVvolvXzd1rrMxtx77QxL4AAZrGW5VuoW:odCSbVyhGxjGL4AAB", "hash_imp": "7361F50FBCDC282E828EFD5A9C317E2B", "hash_pesha1": "664B59580D3DE25BE588D6F1D4FF5BBD7C0AF63E", "hash_pe256": "3EB06F2610F31657F7160F15464622035130FF1EE688B2AFDD4FCC3079B9B8DF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+ Server Replication", "meta_original_filename": "COMREPL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1a9b9b536a195d25f0b97b741cf4e44c22abef8b0355bf8adc8f5c176b74204e/detection", "output": "ERROR: WriteConsole failed = 00000001\r\r\nERROR: WriteConsole failed = 00000001\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\Com\\comrepl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "MigRegDB.exe-86B96422A58603B6419C1B8173241FED": { "file_name": "MigRegDB.exe", "file_path": "C:\\Windows\\system32\\Com\\MigRegDB.exe", "hash_md5": "86B96422A58603B6419C1B8173241FED", "hash_sha1": "591CFEA356D96CCBD7CC94EEFA21D0B2B18B8193", "hash_sha256": "75F6FA1D2BD6CF3D2E3B1389B55EC533EFCF1AD9C3AD5C71799621A6E2A7C0C8", "hash_sha384": "2B85D2E452CDB991A7C6A84F08785ACA0B1B5CC3CAC77B5339B2E6F998F379AD3F35F0579E9EB0D2C4D9A10F72CCA279", "hash_sha512": "BE8805129D03F6DB4C5F9A189FCAD031EBB14EA53E9152A526C842D180DA83C6EB8BC4A212BF6ED6AF004E3E4D2C7608FC43613AD176D9C57FC71D4EBAD20CF1", "hash_ssdeep": "192:KgW6jmFhw9BbREMcnpl0FK3rK9wvx3WTgeo+TEPS5IzHGLFto4rWYwW:KgW6jmnw9x2rL0urPx3+FIr2o4rWYwW", "hash_imp": "3ABC19FA8AADAB98440F63CE4EBA6EE2", "hash_pesha1": "C3F5E8639537C2D9A393E75DF82FAB8E4A1AA75D", "hash_pe256": "027EC38B37E2318DFB7693EC8E7B4A6BF84FBE83B1085D16D00F90C3ED70BDAC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+", "meta_original_filename": "MIGREGDB.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/75f6fa1d2bd6cf3d2e3b1389b55ec533efcf1ad9c3ad5c71799621a6e2a7c0c8/detection", "runtime_modules": [ "C:\\Windows\\system32\\Com\\MigRegDB.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DiagnosticsHub.StandardCollector.Service.exe-917CC8AD990789A111B73284B33EAAF6": { "file_name": "DiagnosticsHub.StandardCollector.Service.exe", "file_path": "C:\\Windows\\system32\\DiagSvcs\\DiagnosticsHub.StandardCollector.Service.exe", "hash_md5": "917CC8AD990789A111B73284B33EAAF6", "hash_sha1": "3E969D0BC4FF3714E140DF04CE02265B0E1BD646", "hash_sha256": "468BA4278B1A99387A91B2652AA0FAC39784AB0460E52B2BD885F74B79A6E5A4", "hash_sha384": "5B8948AEB012912E8459123B2C626BDAB28C1E802038E9E10B8F3A346571272B0DED01993680C69FD4FDED7F25D26559", "hash_sha512": "0FC706CC1F2AEA0DBB2D54AEEAF3E05DAF8EF39ACA2AB7C485833205325CD6D72772E99A906059F0D779D15CC887CAA624346AC884143491AF81011F18748425", "hash_ssdeep": "1536:CJ6uSIgtRftJql6DhU421i/drGQuxfFSkKSXUd5gAnlVcAjQSbEcK47rjPbBUG:uvgtht+i/drGQuxfFZKSzs9jQYEt4HjZ", "hash_imp": "7AD65964CB0B1519889935B01435364E", "hash_pesha1": "88C953B3DA8CA497D2865703F8D3C39572BE23AD", "hash_pe256": "BF83E09AE010C4F99FBF1BFACEB6BB5655F8A25B520EACB7778E9496F56D40A5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) Diagnostics Hub Standard Collector", "meta_original_filename": "DiagnosticsHub.StandardCollector.Service.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.508 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.508", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/468ba4278b1a99387a91b2652aa0fac39784ab0460e52b2bd885f74b79a6e5a4/detection", "output": "Unrecognized option: --help\r\n", "runtime_modules": [ "C:\\Windows\\system32\\DiagSvcs\\DiagnosticsHub.StandardCollector.Service.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "DismHost.exe-80E6C06C378BC7C382C23B1D643CD7D2": { "file_name": "DismHost.exe", "file_path": "C:\\Windows\\system32\\Dism\\DismHost.exe", "hash_md5": "80E6C06C378BC7C382C23B1D643CD7D2", "hash_sha1": "F95ED0E286AA68B4DF779D7E782363EDB5B9FF04", "hash_sha256": "21BAEF2BB5AB2DF3AA4D95C8333AADADDA61DEE65E61AD2DBE5F3DBADDB163C7", "hash_sha384": "052D309828532E7F5996D22932D6E27CBADC90240E3C8D7D19FA800F03EFBB556D794F4EFC9CC81B4FCEDCA90C49D25D", "hash_sha512": "1993564E378A9AC9E66FEFC9E0AEB150B0BF5A88ABA6AB53A0811263823E902B1A2220C06D435CEB52F3151C5BAE5DB0EDC3D4BD23EC45190E6CBE1BE64B98F8", "hash_ssdeep": "1536:EasXwMMHIj1tlkHBoq18dCILuSVFX/U3NdDEIdfvDMY8SeacKMck/T8QgOJMMY8J:Ea5hItlvvJVYNdR1Qgkw2CLNEiYD", "hash_imp": "CA3036FDC2F24315F9C2173721E21693", "hash_pesha1": "DB84D79A86D1A97B63A53B757CFAA5827B3D2987", "hash_pe256": "01493BC4B1DD27B3879C52C037BDA22B1AA957C05DAFE1C992E58682294C9670", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Dism Host Servicing Process", "meta_original_filename": "DismHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/21baef2bb5ab2df3aa4d95c8333aadadda61dee65e61ad2dbe5f3dbaddb163c7/detection", "runtime_modules": [ "C:\\Windows\\system32\\Dism\\DismHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "IEChooser.exe-EA2321EB757F966B2DE90B5F88704F4C": { "file_name": "IEChooser.exe", "file_path": "C:\\Windows\\system32\\F12\\IEChooser.exe", "hash_md5": "EA2321EB757F966B2DE90B5F88704F4C", "hash_sha1": "ACF1AB265FCF92E97880EB3EF51C22B933D790E1", "hash_sha256": "0B822960532DB8B1F75E9233038F74B64532248972B2F8FB701D3692D30F538D", "hash_sha384": "8E49FEF2F76E74CF1C48AABBE337DB792D585968E28C56B6DBD9B10F6D9BAB215F5A70C7799F2AF2C6B9867AAE78E3C3", "hash_sha512": "84E48E990632EAF864AD73CD15686EA72AD77BF36B3E627324FF4A7E0EB875851022D1F6D57539C31623F96E3456ABECD229A7665AE14952DEBF366EFBE0E3C7", "hash_ssdeep": "3072:nkhjbJjgGOxPRebOuCksxTYZvvEIeT3xtRKxAhrSTMk9iVTRv21qaahQr:yjKPR9BMZvvEdTReAtSTMvVY1qa0Q", "hash_imp": "AFE1DBEF4178B090A3FDF69ACC1F9705", "hash_pesha1": "F0E81FAC4CA05C00898EB63CF48D9946362CBF6E", "hash_pe256": "2FCB7F913C1CDAD3B3208555474BA8329B29DE9A9AC6E5EA102516CF4F982BD3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "F12 Attach Chooser executable", "meta_original_filename": "F12Chooser.exe.mui", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0b822960532db8b1f75e9233038f74b64532248972b2f8fb701d3692d30f538d/detection", "runtime_modules": [ "C:\\Windows\\system32\\F12\\IEChooser.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll" ] }, "IMJPDCT.EXE-49414139613D64A97DA848E0DEDB109C": { "file_name": "IMJPDCT.EXE", "file_path": "C:\\Windows\\system32\\IME\\IMEJP\\IMJPDCT.EXE", "hash_md5": "49414139613D64A97DA848E0DEDB109C", "hash_sha1": "79212977A5429F61BC5494CCB96C82F21FFF26EB", "hash_sha256": "2C5C6EB1F0C4FD1E88C5EFE75D714D5EA2803A6C221ADDF217204E6FDF5F825A", "hash_sha384": "20E2CE454853B2B859829687930AED2BC312AC0971FE203C78744622955DD2D560153E6C61A97647C2B818A9123108F4", "hash_sha512": "A9D0921C773F64FAD7A3B4A418BB4A6085EDFB20707EFB56684D4BA9415752778955C282BB466B9ACC698FAC6E3FFDCC0034B9510E924598046865E1D4DE07BF", "hash_ssdeep": "12288:lAPcSqj5MKvpfgzVed00JRT5/FgH1MjnHCTPTuXdAp8qrn:lA+hpjy0O+jiDTuXdAp8q", "hash_imp": "D3B2B10D95D858C06C039D9B31E78785", "hash_pesha1": "D5417DAF22B33CDC02ED0C781DE52FFBCAFE853E", "hash_pe256": "3C84B42866AE41D8EFB3296B41A8F6E7855DB47664B8B378233F76B2C96B4815", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imjpdct.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2c5c6eb1f0c4fd1e88c5efe75d714d5ea2803a6c221addf217204e6fdf5f825a/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Sessions\\1\\BaseNamedObjects\\SatoriKnlDict_MemoryDictionary_IMJP_15__M_S-1-5-21-2047949552-857980807-821054962-504": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\1e8cHWNDInterface:5302f0": "Section", "\\Sessions\\1\\BaseNamedObjects\\1e8cHWNDInterface:8804b4": "Section", "\\Sessions\\1\\BaseNamedObjects\\1e8cHWNDInterface:7804ba": "Section", "\\Sessions\\1\\BaseNamedObjects\\_IMJP_15_UD_FileMapping_{b4f0aa5b-77d3-486f-b999-53049e87159e}_M_S-1-5-21-2047949552-857980807-821054962-504": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\IMEJP\\IMJPDCT.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ], "runtime_window_title": "Add Word" }, "IMJPSET.EXE-0DE3C3E47A5EF0B9170437D0D02422E3": { "file_name": "IMJPSET.EXE", "file_path": "C:\\Windows\\system32\\IME\\IMEJP\\IMJPSET.EXE", "hash_md5": "0DE3C3E47A5EF0B9170437D0D02422E3", "hash_sha1": "75DD2D14DCB7D4F3639EA8792BA1B1DB2F1A7DF6", "hash_sha256": "F270580D875C376E7CA80718623338C09635BB446890676C732C9989D326EE4C", "hash_sha384": "A28B598B92B18C7D3BD53B6EFC7C090999FAAADA8B5A34D365575927C9E0285AFB90EE2A9CDCED881DB841D310B01FDD", "hash_sha512": "3922895D23FF78C9CEA371CB11FAFA039FC42CEC5D3779630F7FE9BD5EC78868AF4FEBC71F6CA069AE84C844A0DC6F37B6836E7C6C2C1E29B51929D09E335EE0", "hash_ssdeep": "3072:S5YBwyROX446PQ4mbMxX+EV+jb2dp/Zpo+E4D9/maFhh0YH67IkK2NLPcV2:S5HToXPQ4mbEXnhpEKD9OwhpmIkC", "hash_imp": "D029DD353E920B362E6A4D2B864A663D", "hash_pesha1": "9F16682D2FAA3CB2FABB6C6C27B3217B7216AFEA", "hash_pe256": "6B26E26E5412493AAD54419E36AB85738ACBBE8826C2CC238560A0E67DA23610", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "IMJPSET.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/f270580d875c376e7ca80718623338c09635bb446890676c732c9989d326ee4c/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\_IMJP_15_UD_FileMapping_{b4f0aa5b-77d3-486f-b999-53049e87159e}_M_S-1-5-21-2047949552-857980807-821054962-504": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\IMEJP\\IMJPSET.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ], "runtime_window_title": "Settings for Microsoft IME" }, "IMJPUEX.EXE-8B2B2098EF493A0A308983B6608E6225": { "file_name": "IMJPUEX.EXE", "file_path": "C:\\Windows\\system32\\IME\\IMEJP\\IMJPUEX.EXE", "hash_md5": "8B2B2098EF493A0A308983B6608E6225", "hash_sha1": "0646880B45E10BCFEFA11E802176CEC7BDBD7EAD", "hash_sha256": "22DC0BB19124A079B440259E17602E26E56A58D468C93ED8482497162F3616D4", "hash_sha384": "2E29A35B05DD4CA36F0A0E918896CD0FB13A7ADCCBE454CE0999AF1E8A137CA063DD6DB3A651A41B54745A3ED14790DD", "hash_sha512": "83B08A546AE920679E6E874E1C33093D5FBF8F29AA4F05F5C88A6D88945ABB966243F23062D724740D512B68F1E072E6FA69A5CE000F3EC2DECE07758856ACA8", "hash_ssdeep": "3072:kSWI0otIjDCSJB+na3Jg5EJYYH67IkK2NLPcr:kSWI0otyCSJB6TGmIk", "hash_imp": "F96602F47608B3339FA2B5E5D2F5C266", "hash_pesha1": "902C69848B9E0EB3CE744D56C52560E501867C5E", "hash_pe256": "381CECB98CA9ACA67B08A925086A3009D742325BE67F82013FA70094253ACFF6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imjpuex.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/22dc0bb19124a079b440259e17602e26e56a58d468c93ed8482497162f3616d4/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\_IMJP_15_UD_FileMapping_{b4f0aa5b-77d3-486f-b999-53049e87159e}_M_S-1-5-21-2047949552-857980807-821054962-504": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\IMEJP\\IMJPUEX.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\SYSTEM32\\MFC42u.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ], "runtime_window_title": "Advanced Settings for Microsoft IME" }, "imjpuexc.exe-5804B10C0BB2B946CBDD8796C43C6F04": { "file_name": "imjpuexc.exe", "file_path": "C:\\Windows\\system32\\IME\\IMEJP\\imjpuexc.exe", "hash_md5": "5804B10C0BB2B946CBDD8796C43C6F04", "hash_sha1": "5FED65BA54F2CC1DA0D658BD70585111F9092754", "hash_sha256": "71F269F30BA467E1AB201035E41BCC0AE16737CB22F5DB66814964C7369E9595", "hash_sha384": "E58A6FC5213488ED73D3F98DC6103FD046DDCAA265E2C26CA745F19CAB0D76191ED43251500E4415A93585BF3B5ECE87", "hash_sha512": "BA8345C6FD678A335678407CFA7AAEA81B7AF4D19BB9DBEC823F51EA35F20176DF23ACAE2AC2ADD9D9AE3577B0E3757F0A96C0C960BF17A395AA5C5DA184B98B", "hash_ssdeep": "6144:yjvgIyHpSphcDRsc7s6NLzBW7+0F3jiGK1Y1iQ3q6oQ:XvHpUh8ZsYLiF3vKqjq", "hash_imp": "12743530832F1784677D7A4D739C3D72", "hash_pesha1": "99F29689A2321225B5EE2755180FCA7B787CDAD5", "hash_pe256": "62BD1A75BA2FDEC8E1A478A19EDF5C334FFA00D2C25B272A25A80F8A8C15E34D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imjpuexc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/71f269f30ba467e1ab201035e41bcc0ae16737cb22f5db66814964c7369e9595/detection", "output": "Microsoft IME Property Command Line Tool (10.0.19041.1)\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nThe Syntax of this command is:\r\n\r\n IMJPUEXC HELP command\r\n\r\n Commands available are:\r\n \r\nIMJPUEXC ADDSYSDICT\t\tIMJPUEXC CHECKSYSDICT \r\nIMJPUEXC REMOVESYSDICT\t\tIMJPUEXC SETKANAINPUT \r\nIMJPUEXC GETKANAINPUT\t\tIMJPUEXC SETCUSTOMDICTPATH \r\nIMJPUEXC GETCUSTOMDICTPATH\tIMJPUEXC FIXCUSTOMDICT \r\nIMJPUEXC CODEAREAFORCONVERT\tIMJPUEXC SETOKURIGANAOPTION \r\nIMJPUEXC GETOKURIGANAOPTION\tIMJPUEXC SETKEYTEMPLATE \r\nIMJPUEXC SETKUTOUTEN\t\tIMJPUEXC RESET \r\nIMJPUEXC LOADAUTOTUNEDATA\tIMJPUEXC SAVEAUTOTUNEDATA \r\nIMJPUEXC REMOVEAUTOTUNEDATA\tIMJPUEXC SETFILTERDICT \r\nIMJPUEXC GETFILTERDICT\t\tIMJPUEXC REMOVEFILTERDICT\r\n", "runtime_modules": [ "C:\\Windows\\system32\\IME\\IMEJP\\imjpuexc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "IMTCLNWZ.EXE-276DC3BD19C1340A5CD15EF59493DBD4": { "file_name": "IMTCLNWZ.EXE", "file_path": "C:\\Windows\\system32\\IME\\IMETC\\IMTCLNWZ.EXE", "hash_md5": "276DC3BD19C1340A5CD15EF59493DBD4", "hash_sha1": "D72B7BC13229D499DBBCA0B48D42CB4D1DD00B85", "hash_sha256": "7E217E293D846D488C1CD3BB633FC1FE1A2D6B5F522D35C872D8E16DE8EBD2B3", "hash_sha384": "20100FC57BD43E922AF7414D35AF79DCE3489E94708BFC5BAF1282E31CB6C6F8363D3E456E23725996C807FCA7CDEB16", "hash_sha512": "F6E962F73780571447563BDB3F74E8E43CEB0CACDA6C344B0DE38F2BB32D11575922F7C89E856289579514A5F3B15A2F2766222D0A634E33F20E77C193F4BC14", "hash_ssdeep": "1536:pYhOSuDldiIpbk7+iNV04MxWwHb7eEJePz+0mCLwrex9rFKf55kEIxjNqcG5yObq:pUOSj7+icPH+hPz+K0Cx9rFKf7ryNqc", "hash_imp": "57B8F0222E3DA258F07382AB54344591", "hash_pesha1": "138E9B998D3714EE08D7E72F029FA05A4FCF9C6A", "hash_pe256": "4E2FEFFC96A35F5E10811DACF4DE3ED2F7FCF1148B8882446EB6EAEACD235349", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IMTCLNWZ.exe", "meta_original_filename": "IMTCLNWZ.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7e217e293d846d488c1cd3bb633fc1fe1a2d6b5f522d35c872d8e16de8ebd2b3/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme601709542": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\IMETC\\IMTCLNWZ.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28\\COMCTL32.dll" ], "runtime_window_title": "ANSI" }, "IMTCPROP.exe-1C555A6D303925921D4C623B107E848F": { "file_name": "IMTCPROP.exe", "file_path": "C:\\Windows\\system32\\IME\\IMETC\\IMTCPROP.exe", "hash_md5": "1C555A6D303925921D4C623B107E848F", "hash_sha1": "7579D448830AD4477BE96A52E91FCF2E1D293FA8", "hash_sha256": "6FA685493CE0BE5900D5648D1F02789AAC403DABDA6FE23D0D82B531547184BF", "hash_sha384": "7911A7A1905D02368CA0CAD0DAF10FF01DBBC3BF5EDBB34D48A91DBA0B64180BB9A666F7D95CF18DCB41F50A2A7DA657", "hash_sha512": "759B7D487A456692B39E860D543959D8E2C6A3C115E2F89E75C6D9E64855F61D84513FE4DBD40FDE85FE7612CBE45D9A99D0C092B024A613632C1FECEB3D6B66", "hash_ssdeep": "6144:4qZRdNTPKcdMHl24Ob74jINmKKRiT7fJ:pR/3+l24ObKw", "hash_imp": "860B268C63F0A6124F9DA48D063DA550", "hash_pesha1": "4E77A33DCCFB31338FDA15E4C2C43D2CD1191A09", "hash_pe256": "D42A43182DCD3FDA99C35A32CD3859E6D18C4291F7A05726CA1DA4439E4595F8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IMTCPROP.exe", "meta_original_filename": "IMTCPROP.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6fa685493ce0be5900d5648d1f02789aac403dabda6fe23d0d82b531547184bf/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\IMETC\\IMTCPROP.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\COMDLG32.dll" ], "runtime_window_title": "Microsoft Bopomofo" }, "IMCCPHR.exe-6E76A76F787ECD24673694BB33371A79": { "file_name": "IMCCPHR.exe", "file_path": "C:\\Windows\\system32\\IME\\SHARED\\IMCCPHR.exe", "hash_md5": "6E76A76F787ECD24673694BB33371A79", "hash_sha1": "57A31ED7CFCE584B0EFDE2517D9C674262B1836F", "hash_sha256": "903E4FA43525D57646F55D9B3B91730F9B3A0527A7044E0340E6A2582EC19FDD", "hash_sha384": "1C65466D129CC2C1A7429E6C2CA955EB32C181345B42F0BBA0F362D1FB1D9FD1487D619115CBEE3A4E952FE22666C130", "hash_sha512": "4A1BECFD0F98118C77C897FD20AA8DBF0B084316308BAB13B83E3CAAE3F0F63234DF6AE15D0B68FC95E6E4F42B3DDD6D5412CEB2F7F0CDC6F2F6BFF9800CB593", "hash_ssdeep": "6144:yp6wO0Ny9Nfq1fEhgCWR5ioOXsOlx8uSXmCPwP6k+kc8DZ5n:a6EyDmAghRO2uSXmH6k+kcuv", "hash_imp": "64F06DCAEA7C73CD8AE821E090F5F5B5", "hash_pesha1": "8488228546A3FEB873D902C6D1E905D3DF8D2CE2", "hash_pe256": "9FC505FABEAEEF7B9CE073CC7D21BC3B17FE9547EE27F51851A0B15FE4724C0B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IMCCPHR.exe", "meta_original_filename": "IMCCPHR.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/903e4fa43525d57646f55d9b3b91730f9b3a0527a7044e0340e6a2582ec19fdd/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\SHARED\\IMCCPHR.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll" ], "runtime_window_title": "User-defined Phrase Tool for Microsoft Pinyin IME" }, "ImeBroker.exe-ECE90ABA65539E284BCFC29913025F09": { "file_name": "ImeBroker.exe", "file_path": "C:\\Windows\\system32\\IME\\SHARED\\ImeBroker.exe", "hash_md5": "ECE90ABA65539E284BCFC29913025F09", "hash_sha1": "97788D7E387AC5A98A24781D7EE56C793555B30F", "hash_sha256": "165B5570C07D102725BCD757006234FBB501BFD47C9A85D4B656866CBA40EAEA", "hash_sha384": "FCDA5C116A85D7DF9297EC54C9F6C0C50E31266598B88EB9E76E3286783E51280F07B6A8B39172EC42BCCADD5419C30A", "hash_sha512": "1265EFF515B53EDD10415F0BCB159DB4663C59FEE984F04B6B0734133E63C5A64E49770F8FD63F96DB6707404FA78FB5E82233ED66340D9E76BDBB8989C8407C", "hash_ssdeep": "12288:Sxb4b5ND0liY29RkWQBipPnrV3RZkY/6KUzhcv:Sx0bnmj29f/0K2hcv", "hash_imp": "6B3AF851CFE39952B016816040D31CC8", "hash_pesha1": "358A7401D35B0BA3ECC4C9F45736E4FAE4A6F5B5", "hash_pe256": "04F28D348AF661F181A563AA5145FA30C241DF0ED02C5B714D727173290303CD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "ImeBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.84 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.84", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/165b5570c07d102725bcd757006234fbb501bfd47c9a85d4b656866cba40eaea/detection", "runtime_modules": [ "C:\\Windows\\system32\\IME\\SHARED\\ImeBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll" ] }, "imecfmui.exe-CA2AFE86E64242CE78A5FC41F8D774CB": { "file_name": "imecfmui.exe", "file_path": "C:\\Windows\\system32\\IME\\SHARED\\imecfmui.exe", "hash_md5": "CA2AFE86E64242CE78A5FC41F8D774CB", "hash_sha1": "070E7DEF19D93CB743D6BC4D85A5F7A4638D92DC", "hash_sha256": "AA0B99D00A342BE0B5BCDD26D6AEAD470301081CEE2E1F8D73A5B86F222AFBF0", "hash_sha384": "D3432E9971003DDBB5BB44D8312CDF85ACD4E32A8DB9249E5317B8A7BE58ECB3E951E03CC4A034FE02575816BB9FC4EE", "hash_sha512": "247CC1C5E5EE3193675B6CB0C56E7A308094A207DEC6D62E3397844619F96379E784CC5129027474F31E15A9297BD1A70077CE2481CBF42047CF0D74C46065BE", "hash_ssdeep": "6144:pWCOJi2sxqy72/b+OsfW6Y6Alm0lHS34D71n4ZgBk8SK1A:pWji2sz856tAlm0I3gS", "hash_imp": "8D93DF9136B1CE35DF052B28A1BF27CD", "hash_pesha1": "36EF95AE983BD435C5386FD467D605D6552F4DFF", "hash_pe256": "DB1AAA6F0D3F0A3734D4D1764AC369A1C34D90D827025A95611427E9C99D374E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imecfmui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/aa0b99d00a342be0b5bcdd26d6aead470301081cee2e1f8d73a5b86f222afbf0/detection", "runtime_modules": [ "C:\\Windows\\system32\\IME\\SHARED\\imecfmui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\wer.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "IMEPADSV.EXE-D4B200C50C5302202F6E73ACE02D16DD": { "file_name": "IMEPADSV.EXE", "file_path": "C:\\Windows\\system32\\IME\\SHARED\\IMEPADSV.EXE", "hash_md5": "D4B200C50C5302202F6E73ACE02D16DD", "hash_sha1": "017FAD6B6A34D224E756A4B50EDADB72DFF6EBC6", "hash_sha256": "00DD85F627E953F114C0AF021B9C203D0A46184ACAED201F07313AF275A6F798", "hash_sha384": "DDB9B6B4838AB8370DA747771D2047B78527DFDD394FCB9E0887401776F9DCA381CC066866B5BB43CAD852075D6A63D9", "hash_sha512": "530F4B70550EAF42FBA3BC911B0F0AF5310C3C1AD05084699A6A9070C92CB150F34DC613172B3D20C846AAB046D8A2183CB24205086DE34503ECBBEC8206F3C5", "hash_ssdeep": "6144:iy6WNt9IssaMOUKbybBDnO9zSpe1R5E1G79KOkCbbUz:PNt9ZuKbybBzO3Uo9r1K", "hash_imp": "3D6DFE1363396D488C5C5821E0922FA2", "hash_pesha1": "DA8DC0E1F7661D60FEEF112920FE0D9B76714B24", "hash_pe256": "EF5CCB2F5E67FAF2AEFB3A4C595E9C9420C3D359221B775AC215E5968B7B27B2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "Microsoft IME", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/00dd85f627e953f114c0af021b9c203d0a46184acaed201f07313af275a6f798/detection", "runtime_modules": [ "C:\\Windows\\system32\\IME\\SHARED\\IMEPADSV.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll" ] }, "IMESEARCH.EXE-C61697BB0A671425CF824AE0B6A4C04E": { "file_name": "IMESEARCH.EXE", "file_path": "C:\\Windows\\system32\\IME\\SHARED\\IMESEARCH.EXE", "hash_md5": "C61697BB0A671425CF824AE0B6A4C04E", "hash_sha1": "B523B78EDCA13A5CA570EFA873BF2EF530D36AE8", "hash_sha256": "0289D2AEF081F8B51C08553E6A886BF63B8FE4FBA62D44EBBEF6B77A83F5C9C0", "hash_sha384": "E07DF499DE81E1864EE098BDFB2CD460ADAB1FCBF292BAE1950D4E3AFDF3CCCE36F7DDA81185481249CF466BF6AB960E", "hash_sha512": "47FD1479D831672C6A288352F02E5D9BC39B51726D46E7A6A6ADA157504111051F1E3E2C4C969E2D84B06392C085F5C44C3D613BEEE90903A8C861B20B0EEA07", "hash_ssdeep": "3072:jISL9KqHOfbJZCjFlMLcHb1L9+vDWfKBJcI+doI+VLn5gzbtyDlG:PL93YbJZGlML01ULWfKBJcI+doIcNgRQ", "hash_imp": "C8018DAFE35C614C5CE6103227B217BB", "hash_pesha1": "8A566970C866E7201F841B752CBFF1E5C041FD86", "hash_pe256": "408FA0057EC2BEB52341D126A7478C64722D25DCC0939C873A5BE355E14E6DB8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IME search module", "meta_original_filename": "imesearch.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0289d2aef081f8b51c08553e6a886bf63b8fe4fba62d44ebbef6b77a83f5c9c0/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\msxml6r.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netmsg.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\SHARED\\IMESEARCH.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll" ], "runtime_window_title": "Microsoft IME Search Provider" }, "IMEWDBLD.EXE-FBEE6DD18640B1575FF98D1EB3B51724": { "file_name": "IMEWDBLD.EXE", "file_path": "C:\\Windows\\system32\\IME\\SHARED\\IMEWDBLD.EXE", "hash_md5": "FBEE6DD18640B1575FF98D1EB3B51724", "hash_sha1": "768565DFF960DAE2C88160A83D6E89EC324871EB", "hash_sha256": "E41B6E1DC3B77040B10FF3DC3BC54AB528DC0CBBBB9841D3AD05FD2136E542A9", "hash_sha384": "0A78CBB200E3F359F79F5CD8CE8E351933A90F9F5FCC4F64A82DE084C9EC74CFEDAC608EE87B886AF424C384DDB87480", "hash_sha512": "FB8E215F86537F905212F9AC98BFD57A55FF4733829F9D6290BBAADB6B9DE38B3E49311D315B26FD98DAF779ABE00CF7607E865F2F0C28B563138E073013CB2D", "hash_ssdeep": "6144:Cgxh/q0ihC+IxjWE9MHvf08pUphjkhmTDsMEU7Gs/UEVTppcX+:XxKE9SvVUphIgzEU7Gs/r", "hash_imp": "9058F8CAF1607207583049235B4FF842", "hash_pesha1": "DCB72798AEE9CCBFDF43137844CBB706F3D0ABC4", "hash_pe256": "E1995150558EFCE8E6B8F21143FC017EE97D2DE97D76ABEDD59AC239BA46F010", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME Open Extended Dictionary Module", "meta_original_filename": "imewdbld.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e41b6e1dc3b77040b10ff3dc3bc54ab528dc0cbbbb9841d3ad05fd2136e542a9/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\SHARED\\IMEWDBLD.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\SYSTEM32\\Cabinet.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\UxTheme.dll", "C:\\Windows\\SYSTEM32\\profapi.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "runtime_window_title": "Microsoft IME Open Extended Dictionary Error" }, "ChsIME.exe-BC1E295CECEBC7BE83562F9BDED0EF4A": { "file_name": "ChsIME.exe", "file_path": "C:\\Windows\\system32\\InputMethod\\CHS\\ChsIME.exe", "hash_md5": "BC1E295CECEBC7BE83562F9BDED0EF4A", "hash_sha1": "46B154D2476226B8C357E2D1C9B035F7169F29F7", "hash_sha256": "07840EE337279E5C39480FF76605A9617E47D28A0B364C940BDDBDA2AD08A79F", "hash_sha384": "E0C56DA0F98EF3519008018ABE5DE3906A82774AB08A01BF510BB04A1928C2E6A00B729B9605A1E76FEB38678DEA08D9", "hash_sha512": "205ECE0B9EAFCF056F4EFF6EE83AC293B5DB4FD0297AA20D00CF0BA310314BE6279B03E3A909725C7CEAC20792CEF26CFA6E5A4ED4CB79B30B3FD8127A5179A6", "hash_ssdeep": "12288:6zDL8Py14NxrKl8VcIquMClleqUc5NhZrnMs:4UPZrKOVcruMClleqUc5Nh5nb", "hash_imp": "F8F04A4EDEEEF9E4C3DAE55CA37C62F5", "hash_pesha1": "E85147E9168D0B10105DCAAD80060479F7D85C14", "hash_pe256": "26F80A401354B79CC3922FBEDDDD3842C28F5A596884A292C40548B91624B239", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "ChsIME.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/07840ee337279e5c39480ff76605a9617e47d28a0b364c940bddbda2ad08a79f/detection", "runtime_modules": [ "C:\\Windows\\system32\\InputMethod\\CHS\\ChsIME.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll" ] }, "ChtIME.exe-8A781EC6ED9D9FA4A13A6C8A2C980482": { "file_name": "ChtIME.exe", "file_path": "C:\\Windows\\system32\\InputMethod\\CHT\\ChtIME.exe", "hash_md5": "8A781EC6ED9D9FA4A13A6C8A2C980482", "hash_sha1": "1F886DC6A4F5A82445124B0F2836ECD4C6FBC071", "hash_sha256": "65F15353E9BC6EBCAED4B24A1451B609BAB5D53DFA83FA3E9D3205ADB61074BF", "hash_sha384": "05522FF71DA8DC49EB85A1545671E5733F3B4BBEE1208665EE4E3A7EDBADEB294161FF501EF544784A3D1E27CF475663", "hash_sha512": "F4D6D19B40A262A38ECC677C8ACB4DC1C65E628E6459675CA3E2690BA270C5FA2423B472BFB264DF14D3843FB6CFC772ED7D025B9A9C20B18A712C3CF8C5D030", "hash_ssdeep": "3072:oR/VBg5J1Pah9JVIdnAoiDvDiTDPvutbaCy+vqx+bcmh1tmMN:C/VBMJVah9JVboiDvDaHutbaCy+v+iVn", "hash_imp": "1C137B847577B8F44F2F823B62D4AD5D", "hash_pesha1": "53F2E05B753CE4F5AF5FCDB9BFFC64A2810F1A3F", "hash_pe256": "C6D58E5CA4808CCEB86DD7B062429F69AEB04017EA0ACA6E1BEC37DB219BDC1E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "ChtIME.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/65f15353e9bc6ebcaed4b24a1451b609bab5d53dfa83fa3e9d3205adb61074bf/detection", "runtime_modules": [ "C:\\Windows\\system32\\InputMethod\\CHT\\ChtIME.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "FlashUtil_ActiveX.exe-995D6CD6AF514FB805537240E7561583": { "file_name": "FlashUtil_ActiveX.exe", "file_path": "C:\\Windows\\system32\\Macromed\\Flash\\FlashUtil_ActiveX.exe", "hash_md5": "995D6CD6AF514FB805537240E7561583", "hash_sha1": "2601A80347D340531124B1A6A06DFE74701EBE98", "hash_sha256": "5F2B3F35184E5145CC3B3483C75D5600698C4D644AB71FB6DE6D0654ECC25419", "hash_sha384": "80DB20ED8B738C55DCBC8C84B9F51A98B0EB3B27C446D26268077D31E3F30C2FA453CDA571EBC381FB46796C92C80A3B", "hash_sha512": "F83640D6CEBE7D6F3A47DA05DAD8EF8E175B74792A3F8652CE6D0E7A41050660DAE4828C43CB8D69B648BF53AFBE165B156DD608F8CD66973B5674BE91142F9F", "hash_ssdeep": "12288:yzAX7n7Y3NxneITvgzCOLmJSAn4PICTKFUAAAAAAAAAAAAAAAXAbAAAAAAAAAAA5:y043NxeITvgzCOLmMAITKtYfLTcfb", "hash_imp": "6C86A081DC92C914E3BFF3992C6E967A", "hash_pesha1": "1DA726CF0D03BF1656FAAC752083B9F250375BC9", "hash_pe256": "1D15E71103CF242756AF12DD5008F7E6E07F47D36367A59E62F412F8555A9AE4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000008D391F9E635AAD4D5000000000008D", "signature_thumbprint": "B8A71534F400FF263831F8FD44D22053A3F6857F", "signature_issuer": "CN=Microsoft Windows Third Party Component CA 2013, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Third Party Application Component, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Adobe Flash Player Utility", "meta_original_filename": "FlashUtil.exe", "meta_product_name": "Adobe Flash Player Utility", "meta_company_name": "Adobe", "meta_file_version": "32,0,0,445", "meta_product_version": "32,0,0,445", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 1996-2020 Adobe", "meta_legal_trademarks": "Adobe Flash Player", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5f2b3f35184e5145cc3b3483c75d5600698c4d644ab71fb6de6d0654ecc25419/detection", "children": [ "FlashUtil_ActiveX.exe", "WerFault.exe" ], "runtime_handles": { "(RW-) C:\\Windows\\System32": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "Uninstall Adobe Flash Player", "runtime_modules": [ "C:\\Windows\\system32\\Macromed\\Flash\\FlashUtil_ActiveX.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll" ] }, "mighost.exe-BAD04F25F7495A2CCB0CE1E8F043D748": { "file_name": "mighost.exe", "file_path": "C:\\Windows\\system32\\migwiz\\mighost.exe", "hash_md5": "BAD04F25F7495A2CCB0CE1E8F043D748", "hash_sha1": "7FC7DA893BA2E15EBFDF5FF2F62BC9ADA736D8BF", "hash_sha256": "BE5BED6CA3FAB9427F54F93DDF82F3B6B9ECE6F59BAD9699316FB724D07509F0", "hash_sha384": "E7075C9519843D8449D4E011217EE5345C56D8BB2AEAE175FB93900D93B9199A8F73A737CBF82B278E0933046DC63B43", "hash_sha512": "4EA8F8D4D12010E41963452A5380E42070F50B4B5A121186707F00CD0D5EA4AF72ED21C4E6F3730D518BEB2E7387F76D99095F2C3DBF7D1D45363F6272143944", "hash_ssdeep": "6144:rofOiYlr1OlojDuUlMtq10Q8m7NNqM9N+hN1UFpfNS5iXjD56Gpovgp2H32nq54x:r+9eDuUlEqatglsLb0", "hash_imp": "1A2E6FBE71CAA18E49B7AEBBC2EAC135", "hash_pesha1": "6916B641FF94340D4BD91A7D352DEBB5D4338DF0", "hash_pe256": "C77A91926289594A7B5789E1A453E5938D859726FE9E22BA2EE57372922FAA95", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Migration Plugins host program", "meta_original_filename": "MigHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.630 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.630", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/be5bed6ca3fab9427f54f93ddf82f3b6b9ece6f59bad9699316fb724d07509f0/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\migwiz\\mighost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "runtime_window_title": "MigHost.exe" }, "audit.exe-B577EAC2A952401CC3E8E12219082324": { "file_name": "audit.exe", "file_path": "C:\\Windows\\system32\\oobe\\audit.exe", "hash_md5": "B577EAC2A952401CC3E8E12219082324", "hash_sha1": "0DD1AE0AF6E363AF73EFACFA35108FE47D5A9693", "hash_sha256": "4BF33E9DE3635D54A163D5371DD1A02F684BECAF8830AF7B0CD0E882405CE48D", "hash_sha384": "7FF7E9C5FF57610A13426192467713A540C7CC5C748A0A3A49A82EF056D72B3527A88A4A3C0FE9BA985EFD0CC47DA1A9", "hash_sha512": "8C30FD771DB478BA6BC7C7C4F69A5324ECF642405B108209D6411AFE4C0D5270DE2E02AC0BD4F04AAC47B9A327E624BA6E17846A9E6AD3703E031412222D83CA", "hash_ssdeep": "1536:Nu/gJt3eXmX5mGrQ/MgZnhn27Y35yCdUJAxsEJIh/s+0YShMBrdC:kGdeXY5v8/MgZZ5y4Tj3YuMT", "hash_imp": "C4966BF6BFF648EC020D2E1F01AA9301", "hash_pesha1": "A2D39EA2914550E7A44C8116B52FD3C157F077BD", "hash_pe256": "E7A0A4DEFE5B0B824D4C4670C286441F0D749404C5A1ED5EFCF47D2CF471563F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Audit", "meta_original_filename": "AUDIT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4bf33e9de3635d54a163d5371dd1a02f684becaf8830af7b0cd0e882405ce48d/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\SetupLogSection": "Section", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setupact.log": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setuperr.log": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagerr.xml": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagwrn.xml": "File", "(R-D) C:\\Windows\\System32\\oobe\\en-US\\audit.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\oobe\\audit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll" ], "runtime_window_title": "Install Windows" }, "AuditShD.exe-35A5400520CB015BF0BDFD7FA9B81085": { "file_name": "AuditShD.exe", "file_path": "C:\\Windows\\system32\\oobe\\AuditShD.exe", "hash_md5": "35A5400520CB015BF0BDFD7FA9B81085", "hash_sha1": "F8B942EFB86BCF8412DD7C19FD5E2873B9D8690E", "hash_sha256": "13B9F0F81E9EF9F77DA064A3DC483D873796BEDA8355520606C3A10B074D66E1", "hash_sha384": "76A149D4EFD3C2738969643A666F083F33973E35A2A3E72687068C96C281E51D2750AF414BBDC0812C79668C951FD459", "hash_sha512": "60FEE57EAB2276DEDD9EECB45589002482FE5E50FFD241BBA9EBF8E459D2244B5B7D25FBE08ED979ED72F26C0336C43ECF143CA0C2D30593D96BC069A1C773DD", "hash_ssdeep": "768:jxYzrcby4T4vRUVK58bo4IVwQiPdrlxUdqPD6Z:ucbApz58ueLPdrlqdq+Z", "hash_imp": "B1A6068BAA73FBE37CC0271811BDCDBC", "hash_pesha1": "961F1582C37F86354B611394519B7CA160872436", "hash_pe256": "C0BBF61577584C3E8691FA04D96E30466C99EAB7C2B7DDB49BBEB40D8269C1CA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Audit Mode Desktop Switch Utility", "meta_original_filename": "AuditShD.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/13b9f0f81e9ef9f77da064a3dc483d873796beda8355520606c3a10b074d66e1/detection", "runtime_modules": [ "C:\\Windows\\system32\\oobe\\AuditShD.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "FirstLogonAnim.exe-EA059E3BA7E07347BDE08EF016E09D50": { "file_name": "FirstLogonAnim.exe", "file_path": "C:\\Windows\\system32\\oobe\\FirstLogonAnim.exe", "hash_md5": "EA059E3BA7E07347BDE08EF016E09D50", "hash_sha1": "B8FD1E038BA40053C35759C901E304F79E00D367", "hash_sha256": "96EC7820603A983285A982FF7D26A688C7DE3184FDD73041655044162B9A35C4", "hash_sha384": "8B8C63E36E5F84728B7B7FF963226A0A465735E1473E8E7EA525B03BDE6A168DF1930065FA718C3BBE34605EC7F96A93", "hash_sha512": "EBA13222E7433B2F6A329D8A4CE1E93FECFF5B30B6DA00C4417E9519AC67FEE75E1026B8D451CAAAF11E5DCFE6978853090ABE5FC1C1A068A0F1D56E5A5E5B41", "hash_ssdeep": "384:RNLLyaWv/5k/oy97ZLOW3xWmD1IDBRJtnl4JeRlF8:RNfERk/77ZLndI1PEj", "hash_imp": "3803F409406CF069F54F47AB8EC15EF4", "hash_pesha1": "D67E35D088BEAE9CC4B368C259CB328D85DFCDE8", "hash_pe256": "F6AA291F01503F25C013D8B43C9E4EC5A12A4F505BF43B229AE667C6E5B34ABE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "First Sign-in Animation", "meta_original_filename": "FirstLogonAnim.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/96ec7820603a983285a982ff7d26a688c7de3184fdd73041655044162b9a35c4/detection" }, "msoobe.exe-23E4CE578D614A517069C1B3DFD0799C": { "file_name": "msoobe.exe", "file_path": "C:\\Windows\\system32\\oobe\\msoobe.exe", "hash_md5": "23E4CE578D614A517069C1B3DFD0799C", "hash_sha1": "6401BAB5E6857347473DED3A06415DC2B5A2B26F", "hash_sha256": "41013C4E65D37D1AF2E95B581A766E99A222F1E4E9D347363DDB7B557703FA73", "hash_sha384": "DEACE43EC55CBCD70E72BB87E4224E7BA1F826E7876B1A9AD23B2DBC9CC4DFC45A7B469FBD84156ED8247597B994D69D", "hash_sha512": "25153A334D82096B4248931207041617C38B7B869226DF7E3830B5CEF0DEE0826A1E8047EC49817818EC70C9FAC9DEAC1C2B879DE457C24E45609227AFB57874", "hash_ssdeep": "3072:s8Io4bOaWrtTd/liZtTrxsocuKnHHQAXz+MdAVOWnOxRZn+:s8Io4CVBTdkv+uAHHbtdIARZn", "hash_imp": "AB801A82AEA92BE7ED425A39E0598BD6", "hash_pesha1": "E35DD6B7CD26AD19AA4DB59A98202E830321DE2C", "hash_pe256": "AE05B3F4F9A1636AC376AEF97CB09F0D430CFD7257E3DDAA9FB209498BC2D7D6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MSOOBE EXE", "meta_original_filename": "msoobe.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/41013c4e65d37d1af2e95b581a766e99a222f1e4e9d347363ddb7b557703fa73/detection", "runtime_modules": [ "C:\\Windows\\system32\\oobe\\msoobe.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll" ] }, "oobeldr.exe-C06CFC85B4F5251137B0A8CCD5B1A159": { "file_name": "oobeldr.exe", "file_path": "C:\\Windows\\system32\\oobe\\oobeldr.exe", "hash_md5": "C06CFC85B4F5251137B0A8CCD5B1A159", "hash_sha1": "20681CABDBD21FAACB824E75F0E79404B0AB46FD", "hash_sha256": "67FE654B8B277DF364E596C2AC7466BD307F28C244425AAC7BC79F1DE3269A5A", "hash_sha384": "4E5E5668D84CB594C125C0ECB72EBE488112FF44ECC05DCEFD97FDC10AA27EF10C75D7443B868DAB155657265E047F09", "hash_sha512": "35BA7A5D8932EB1986DD8BA954837A3AE6D14700E6C59ACBEDCEA3879AB982500DF3F8E998211C90E1F899CF7E91F41D397396E5E1E99F0246BBEE015CECA7EF", "hash_ssdeep": "1536:4LKuETtMeVp1z0Cf6TMuB1k8iobVklp8t2bH3hvHBxXiSK:4udTi4Dz0Cf6TMuB1k8TbVklp8+hZ1+", "hash_imp": "056DD64EBE1622D153F1DA843F487C05", "hash_pesha1": "12F53D888CCCC6B60F4170E52C2B206F53CE9E0C", "hash_pe256": "7AA587A84CB061EBD611F78411D1CF8D112BC5351DF6E03EF10E7F1DB584FCCF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "OOBE Loader", "meta_original_filename": "OOBELDR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/67fe654b8b277df364e596c2ac7466bd307f28c244425aac7bc79f1de3269a5a/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\SetupLogSection": "Section", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setupact.log": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setuperr.log": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagerr.xml": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagwrn.xml": "File", "(R-D) C:\\Windows\\System32\\oobe\\en-US\\oobeldr.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\oobe\\oobeldr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\ActionQueue.dll", "C:\\Windows\\SYSTEM32\\UNATTEND.DLL" ], "runtime_window_title": "Install Windows" }, "Setup.exe-C50F9DE218E09BB839C0D58727D7857D": { "file_name": "Setup.exe", "file_path": "C:\\Windows\\system32\\oobe\\Setup.exe", "hash_md5": "C50F9DE218E09BB839C0D58727D7857D", "hash_sha1": "D54347302CC3FEBF64100ED03D1E7913BDB811FC", "hash_sha256": "FB2CC6A3E02E538714D1634CA7889C5A3F214C32FFAA0EA21FCC90FD64FFCEB4", "hash_sha384": "A3FF6F284DBBDC3308E4B594FFC498910408FB9D51BAEF178B4C3E05BC7DCFDC752E0B3DEA2CA01F4E49252808E12169", "hash_sha512": "64FCAAC9F8D23270445492DAD4C2DC7448D28E8FCAC45F3E1B8BFFB367DACC410FB5C21F5F345915AF3FE54DEFE373828D23649BF87CE07F2EF3591FAE8B33BF", "hash_ssdeep": "6144:B1iE+ZtnXmljTvpMs7aeCxE9h/abzhQXJgzBU4GfjTz:B1iE+qHv/a5agS", "hash_imp": "8200B0AFB7ACC2B5E1B595FFF0378F6E", "hash_pesha1": "AA393F57278BF46BF1EF8B5D2649A23D9ECD3696", "hash_pe256": "8B67834CC585607BD197A1D7102C4D6E09D40863AE7026ACCCD7197A1D6A5DF6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Installation and Setup", "meta_original_filename": "SETUP.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/fb2cc6a3e02e538714d1634ca7889c5a3f214c32ffaa0ea21fcc90fd64ffceb4/detection", "runtime_handles": { "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\oobe\\en-US\\setup.exe.mui": "File", "(RW-) C:\\Windows\\System32\\oobe": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\oobe\\Setup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ], "runtime_window_title": "Install Windows" }, "UserOOBEBroker.exe-80E7F1E70CB79EF61E2D5D710FC22A2A": { "file_name": "UserOOBEBroker.exe", "file_path": "C:\\Windows\\system32\\oobe\\UserOOBEBroker.exe", "hash_md5": "80E7F1E70CB79EF61E2D5D710FC22A2A", "hash_sha1": "228175CF48F79FEE94E153D605D35E286751329A", "hash_sha256": "2A449E3D6A3954FB9765152BE964A29B743665738F78B6B81AE5CB712876B8A4", "hash_sha384": "47150A3E7146A8C8B83222FFE33CB90BACEDD76C6F86EB9EFF34C19A4BFBE6A2AD6EC23E5EDC20F1B3100CBE46C3221A", "hash_sha512": "D5D65798403218F801C0EF344461FE2542F92BD9CAC3CAD522AFE9F5FFBDEA15C6C7CC65B4B4E1F661AD0813018CF57A3A0591A9A81BA35CDE4C36C21ED6A18B", "hash_ssdeep": "1536:IrAf9XxdvZt3Anl5ic86qIHxxGhOkm+C4b0iX3B8FyC9KmV:I05hxAnlb8iHcm+hIa3BpCj", "hash_imp": "3C57A5863091FCD312D336794114E352", "hash_pesha1": "516EF8EB69A930E1BC1B306A704C2CC8AF1E5208", "hash_pe256": "33DFF402DFED45E3BA7108FCCD4BAF17727292A52B6EBB10BD56F237A62C7CDE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "User OOBE Broker", "meta_original_filename": "UserOOBEBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.508 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.508", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2a449e3d6a3954fb9765152be964a29b743665738f78b6b81ae5cb712876b8a4/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\oobe\\UserOOBEBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "windeploy.exe-7B3485CFEDD39B8E52A25155C34E3DB8": { "file_name": "windeploy.exe", "file_path": "C:\\Windows\\system32\\oobe\\windeploy.exe", "hash_md5": "7B3485CFEDD39B8E52A25155C34E3DB8", "hash_sha1": "7AA553F3E4DC0D6D8D488BEF7FA3BEDBC6035EE7", "hash_sha256": "1E4F948548F20D621900678718BF341AB92C637C07DF5EC96FE4879A6B57206A", "hash_sha384": "1725FC6706ED1372DCC70C6BB3A7D5FDD44E6A74AE2567F2E5496FB1BA28ADADD696448476FBD69138471C60C46C42F8", "hash_sha512": "A79F502323ACFB78D9FA6551FF6B0A4463A8B1C7EFD3C4DD1D3992A13D8F68605992584C8848203869CEC6178AA1226947A5BCDDDB3C6CDBD58F3C575A4B94EF", "hash_ssdeep": "3072:7tqPVyki/mUhoNS+81CDPOfwcFa3p047FtPrFrbbuB7KAHKtmpijM0/i7:OVyTASAya3p047FtDF07O9M0/", "hash_imp": "03433EF878B5C5DB4A84F8AD3556A814", "hash_pesha1": "7100497873CEC0484DDDE3B8E74F57A4039EF9F7", "hash_pe256": "CE16FD779A84A0096FEA397553C6E838141F3297E29A24C3B477D1D4B5E36C27", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Deployment Loader", "meta_original_filename": "WinDeploy.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1e4f948548f20d621900678718bf341ab92c637c07df5ec96fe4879a6b57206a/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\oobe\\en-US\\windeploy.exe.mui": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagwrn.xml": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setuperr.log": "File", "\\BaseNamedObjects\\SetupLogSection": "Section", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setupact.log": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagerr.xml": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\oobe\\windeploy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\bcd.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "scp.exe-2B26FED866AE32256A13E518EBD99A5E": { "file_name": "scp.exe", "file_path": "C:\\Windows\\system32\\OpenSSH\\scp.exe", "hash_md5": "2B26FED866AE32256A13E518EBD99A5E", "hash_sha1": "64CD2E217B8C6460983CD3EC6A424C3DE9288276", "hash_sha256": "8860E4273F59CAA71FA585697E291270F94CEE83439E5C94726D918D7C72F362", "hash_sha384": "241330B8FB6905C078C5921ECE61866C5EDDB31FD2A6C2F02665116F07909DFD40A2C8C7A50850229BE38B58C68ED206", "hash_sha512": "F698D8AE1E595830759B30B42E50136E3D3DBD0540DFAF0430E7CF31AF200A3F73A4803C7DA44500E3AB5B8D3768D271B5165608818ADED5FD2EFAC0C8B418E1", "hash_ssdeep": "6144:WThqanTjXv0Xa6CRU+/WFg/jB5B07qnolqLC8Z+a:qqanTDv0q6B+/WGXnolGCQ", "hash_imp": "85D8C9B4FBF728E5F40C3F477EEE0C79", "hash_pesha1": "4CB0246F0F5A62033303C14D7FB801ACC16E08FA", "hash_pe256": "922EA6413B52502F17D6618426FD659872966BDCC9B46D5A39D7AD3426E70C02", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_product_name": "OpenSSH for Windows", "meta_file_version": "7.7.2.1", "meta_product_version": "OpenSSH_7.7p1 for Windows", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/8860e4273f59caa71fa585697e291270f94cee83439e5c94726d918d7c72f362/detection", "error": "unknown option -- h\r\nusage: scp [-346BCpqrv] [-c cipher] [-F ssh_config] [-i identity_file]\r\n [-l limit] [-o ssh_option] [-P port] [-S program] source ... target\r\n", "runtime_modules": [ "C:\\Windows\\system32\\OpenSSH\\scp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "sftp.exe-028093CC65E2E42EFC5AE37F030AA164": { "file_name": "sftp.exe", "file_path": "C:\\Windows\\system32\\OpenSSH\\sftp.exe", "hash_md5": "028093CC65E2E42EFC5AE37F030AA164", "hash_sha1": "A83C9DE27D43CFB56E827F693B05171B858D0256", "hash_sha256": "7651A9E5721C2FCEE4C34A253062914AB93C7B3B415D313658B058AED4F2FDE2", "hash_sha384": "00D63179BAC48B234A018CC9625CF6A5C613BB9C2DA1BD37CD2ED9F8FD1205BF04B61F38A13EF92BF06EADAAC54ED623", "hash_sha512": "1416021F7B0D8E96AC1B581119B79E80E20404884C8FA12272A26181F6FC522B136820EEC79CE96690088EF00DAD2B4E31717CC6BF1B38DD914E0D79D281B679", "hash_ssdeep": "6144:pqTjTw9mPw0bLaPpV+y9h+jdi2qAYE4/GgcKuzxywdrHGlUTONZJVxrgZmlx4Cjh:pqrw9mPw0bLaXb9h+Mh84/Gggx5AVx8o", "hash_imp": "F439E59D3BD1D28D6ABD4CCFCBD7AEB9", "hash_pesha1": "385D96EFFA0CD4556681D8954E4AFF8D5AA2CEE4", "hash_pe256": "78DD7947388404E221A3B52DD54DBAE34172BB25441D480BF13B7AA2CDDCB068", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_product_name": "OpenSSH for Windows", "meta_file_version": "7.7.2.1", "meta_product_version": "OpenSSH_7.7p1 for Windows", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7651a9e5721c2fcee4c34a253062914ab93c7b3b415d313658b058aed4f2fde2/detection", "children": [ "conhost.exe", "ssh.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "error": "unknown option -- -\r\nusage: sftp [-46aCfpqrv] [-B buffer_size] [-b batchfile] [-c cipher]\r\n [-D sftp_server_path] [-F ssh_config] [-i identity_file] [-l limit]\r\n [-o ssh_option] [-P port] [-R num_requests] [-S program]\r\n [-s subsystem | sftp_server] destination\r\n", "runtime_modules": [ "C:\\Windows\\system32\\OpenSSH\\sftp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ssh-add.exe-C808CB063C0B78E92FF7F5A85905218D": { "file_name": "ssh-add.exe", "file_path": "C:\\Windows\\system32\\OpenSSH\\ssh-add.exe", "hash_md5": "C808CB063C0B78E92FF7F5A85905218D", "hash_sha1": "911C6AFE8802F33076A551AD3E6DADEE0E2CCC5C", "hash_sha256": "7E5D13C4B13BE142DA676FA5F533AA92D12F7C66AC04EC26066C271326B789E7", "hash_sha384": "04BE6FBE1AE4FB5F571C9963D032995D7DD74454672D6C3A07EEF11A836FA07831A779F5B22BD7B2C3CA10D5B17F353B", "hash_sha512": "3F7108CA89A7F57FE997F0440F885E5A88B33A2FC87919908E7977E34F179D1C82525EA922504457E1FE560D688270EE8D78E3798E42D84DEEB3646ACBC6B466", "hash_ssdeep": "6144:4NWN/DJLikLPPD4mv/uws3RrDDdgi2yZ8jiRPgaDb2O7fcCnDtS9LU9qDCLlC4F:4NWNrJPLMQ/uwypei2alOU9uCLlCq", "hash_imp": "5CE85084191BE301FA076E5F6FC85F6B", "hash_pesha1": "B7595AA848AE9294EE43BC1EE822BFA8418E539A", "hash_pe256": "A7A76AB098186CDCDA291150D9347A055F2AF14270CAC3A2EB71E31560D758F7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_product_name": "OpenSSH for Windows", "meta_file_version": "7.7.2.1", "meta_product_version": "OpenSSH_7.7p1 for Windows", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/7e5d13c4b13be142da676fa5f533aa92d12f7c66ac04ec26066c271326b789e7/detection", "error": "Error connecting to agent: No such file or directory\r\n", "runtime_modules": [ "C:\\Windows\\system32\\OpenSSH\\ssh-add.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ssh-agent.exe-9FFECD197D09FF33B00D5E5B78A48146": { "file_name": "ssh-agent.exe", "file_path": "C:\\Windows\\system32\\OpenSSH\\ssh-agent.exe", "hash_md5": "9FFECD197D09FF33B00D5E5B78A48146", "hash_sha1": "74F3580EC1374F5A7367E157ACD76AA03EE7F7CB", "hash_sha256": "79C03E83B42E3C0402680B47A2493C3C506E2D212062859BD7C4EBACA46F3AD5", "hash_sha384": "062C92AFE3DDD6CF63F575635036C84FF3311471D928FB2BC731D6023F67B4CE7DBF21754D22272888952966FF3A106B", "hash_sha512": "6C1077035A534C51586CF4ADAF6F7387AB3411F0C0662A3331F238D2C1F4BA007D352324B9B901ECE8838C3C458EE3526A1F88471672F8451EC87B82F7A217D5", "hash_ssdeep": "6144:wE7PBeGGXEkgumpLL5szsz/uyNPgfdaDb2O7fcCnDto/HOvtBCrljcz:J7J1GlvQRSyVammkfCrljcz", "hash_imp": "C3450B747B22F2447BB5C3214451ADA3", "hash_pesha1": "9F39153A279CFDFF7AB7DFAE1A83900ED6EF90B5", "hash_pe256": "FD6D1ECE2E8DAA5ADAD01E4E3CF1589F502A3BA62FEF25896C5FA58889BB9AD4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_product_name": "OpenSSH for Windows", "meta_file_version": "7.7.2.1", "meta_product_version": "OpenSSH_7.7p1 for Windows", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/79c03e83b42e3c0402680b47a2493c3c506e2d212062859bd7c4ebaca46f3ad5/detection", "error": "unable to start ssh-agent service, error :1058\r\n", "runtime_modules": [ "C:\\Windows\\system32\\OpenSSH\\ssh-agent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ssh-keygen.exe-E7F2BA307D3C923709744745C25C9CB5": { "file_name": "ssh-keygen.exe", "file_path": "C:\\Windows\\system32\\OpenSSH\\ssh-keygen.exe", "hash_md5": "E7F2BA307D3C923709744745C25C9CB5", "hash_sha1": "9A58D2AB3681C2DD9DCEB3C497F17966CF8B9B67", "hash_sha256": "F647D15BAC7651FB3FC23779D7568F7C14B139745AFF03201EA5F569A7D84810", "hash_sha384": "BA21430FD59C29B39E185EACDA530F562B5E524103C3FAAA4E2514731A8B78F6C93413AFD8D0B24BAEA0A0F4867A1D37", "hash_sha512": "DB5F7CA98083444D348C7BE8851ECEDA225A06446C4C97323B2A6B3A382CC0867A89CD3EEEEC4A7A1F505B4FC3226D7EB9E002C24785B0E33C936E29CF25D29E", "hash_ssdeep": "6144:1jOlrq2QzsTMhJoEBA/YF9HE0C09/l760j6qTjhqVSxwn1VU1B8zqcNPaDb2O7fB:1CTOJl+EO0CM/M0+Ck8Bixo0lHCd", "hash_imp": "643DF7829C13810977871B7A9E601644", "hash_pesha1": "970DC5D9DEE15124AB266C6FE37D09E8E1879DF0", "hash_pe256": "48DE64377C0CB07CA1AF00987DB65A9A4734F6FD5BCE156D8CDACA2D7039D612", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_product_name": "OpenSSH for Windows", "meta_file_version": "7.7.2.1", "meta_product_version": "OpenSSH_7.7p1 for Windows", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f647d15bac7651fb3fc23779d7568f7c14b139745aff03201ea5f569a7d84810/detection", "error": "Too many arguments.\r\nusage: ssh-keygen [-q] [-b bits] [-t dsa | ecdsa | ed25519 | rsa]\r\n [-N new_passphrase] [-C comment] [-f output_keyfile]\r\n ssh-keygen -p [-P old_passphrase] [-N new_passphrase] [-f keyfile]\r\n ssh-keygen -i [-m key_format] [-f input_keyfile]\r\n ssh-keygen -e [-m key_format] [-f input_keyfile]\r\n ssh-keygen -y [-f input_keyfile]\r\n ssh-keygen -c [-P passphrase] [-C comment] [-f keyfile]\r\n ssh-keygen -l [-v] [-E fingerprint_hash] [-f input_keyfile]\r\n ssh-keygen -B [-f input_keyfile]\r\n ssh-keygen -F hostname [-f known_hosts_file] [-l]\r\n ssh-keygen -H [-f known_hosts_file]\r\n ssh-keygen -R hostname [-f known_hosts_file]\r\n ssh-keygen -r hostname [-f input_keyfile] [-g]\r\n ssh-keygen -G output_file [-v] [-b bits] [-M memory] [-S start_point]\r\n ssh-keygen -T output_file -f input_file [-v] [-a rounds] [-J num_lines]\r\n [-j start_line] [-K checkpt] [-W generator]\r\n ssh-keygen -s ca_key -I certificate_identity [-h] [-U]\r\n [-D pkcs11_provider] [-n principals] [-O option]\r\n [-V validity_interval] [-z serial_number] file ...\r\n ssh-keygen -L [-f input_keyfile]\r\n ssh-keygen -A\r\n ssh-keygen -k -f krl_file [-u] [-s ca_public] [-z version_number]\r\n file ...\r\n ssh-keygen -Q -f krl_file file ...\r\n", "output": "Generating public/private rsa key pair.\r\nEnter file in which to save the key (C:\\Users\\user/.ssh/id_rsa): ", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\OpenSSH\\ssh-keygen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ssh-keyscan.exe-4720A475F697D41705EBEECC9812C718": { "file_name": "ssh-keyscan.exe", "file_path": "C:\\Windows\\system32\\OpenSSH\\ssh-keyscan.exe", "hash_md5": "4720A475F697D41705EBEECC9812C718", "hash_sha1": "DD2F92FB532DFF61E3EEA3C2B9789D10208444E8", "hash_sha256": "965ACD45BD7D44FD374D3E598E88148AFFD8C7C148EA846167FB04F7837A5503", "hash_sha384": "48AE80576BDF525BB854B7D1051F028FBDF0024678F2C0742DD9C7DD5F6AB413D2A20092C122083A85A8BD7BB9C92097", "hash_sha512": "285FEF404DDF66CD5CF77342C43FCF82F0E2E51405590DD0FC1CF558549576F605A9A3787DC694FDEDE5F02A104FE3B9E9E92574CC6AC7E3647E00B9C756DBD9", "hash_ssdeep": "6144:EM8cYMUe6/LztG7NFm7tUp/GXusKK2tiaDb2O7fcCnDtiZgcaGHCSlhoWksAYX:EcIztcexUp/TbXBSa2CSl6WX", "hash_imp": "EB8223A61E876E103713BD9CE4F82C84", "hash_pesha1": "36CB821312445DADD687037FE4986BD11C311ABB", "hash_pe256": "96D692420E594813180440E8F6FE8228160906C7E7566AE5E718D13D77E6AE07", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_product_name": "OpenSSH for Windows", "meta_file_version": "7.7.2.1", "meta_product_version": "OpenSSH_7.7p1 for Windows", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/965acd45bd7d44fd374d3e598e88148affd8c7c148ea846167fb04f7837a5503/detection", "error": "unknown option -- h\r\nusage: ssh-keyscan [-46cDHv] [-f file] [-p port] [-T timeout] [-t type]\r\n\t\t [host | addrlist namelist]\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\OpenSSH\\ssh-keyscan.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ssh.exe-B664CCD9E064BA9542BCC71A5DED6A1A": { "file_name": "ssh.exe", "file_path": "C:\\Windows\\system32\\OpenSSH\\ssh.exe", "hash_md5": "B664CCD9E064BA9542BCC71A5DED6A1A", "hash_sha1": "1B4ED1E4E6D3F8EFFB0F119056D5B06342D80524", "hash_sha256": "0C0E91427A4B0E4CD0B59BDB73054252FB74C0977D13A73AB7423E15528B0485", "hash_sha384": "42EEC84E4B8A61A116E58DF421559EC5E9B639F17B7202634E8501DCC6D1604764446A5F7655F6AB5046CD5CEDF48AE2", "hash_sha512": "7EB6A9ACB61D964C82C46E897F8A5195C7F06BEDF7F1ECD2D64F2783BE996F7A6356E9C991DA4BBE541F4E8A214B7D58DC9AF17652E448CE582BBFA2946690AB", "hash_ssdeep": "24576:QTDSQPwMHspFKajxUAn0/2L50P6DlZC2u:eSMYFKaT70P6DlZC", "hash_imp": "5F959422308AC3D721010D66647E100E", "hash_pesha1": "4AFC80848BB05DEB11715F760913D649151E9C1A", "hash_pe256": "02B0354F69677B654E1DAF5510378501B2D0D6B6534F2AA3011C9F5F1936C2BD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_product_name": "OpenSSH for Windows", "meta_file_version": "7.7.2.1", "meta_product_version": "OpenSSH_7.7p1 for Windows", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0c0e91427a4b0e4cd0b59bdb73054252fb74c0977d13a73ab7423e15528b0485/detection", "error": "unknown option -- h\r\nusage: ssh [-46AaCfGgKkMNnqsTtVvXxYy] [-B bind_interface]\r\n [-b bind_address] [-c cipher_spec] [-D [bind_address:]port]\r\n [-E log_file] [-e escape_char] [-F configfile] [-I pkcs11]\r\n [-i identity_file] [-J [user@]host[:port]] [-L address]\r\n [-l login_name] [-m mac_spec] [-O ctl_cmd] [-o option] [-p port]\r\n [-Q query_option] [-R address] [-S ctl_path] [-W host:port]\r\n [-w local_tun[:remote_tun]] destination [command]\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\OpenSSH\\ssh.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "PerceptionSimulationInput.exe-E9700994FB95782727D038F8750671EA": { "file_name": "PerceptionSimulationInput.exe", "file_path": "C:\\Windows\\system32\\PerceptionSimulation\\PerceptionSimulationInput.exe", "hash_md5": "E9700994FB95782727D038F8750671EA", "hash_sha1": "20943008176E6DD35DB22602595C2EF5FB331C0A", "hash_sha256": "6DAA3C4359DE509E490B6D5FA777C67FFDA5178C4C7D2EC1AAD8EE8C22D3B5BA", "hash_sha384": "3A4E4006FE06EC52EE2C304A935A6ED4E2C1BBDB98521396306815BA60266C8EEC61D75B74873B1D11C1E965CBC45B4C", "hash_sha512": "6AB45F812B00110419474FD8044CC129530B3BA8F526B31FD3F14ED9FB5AC9C4317B4E0F56CCE891D38EB46BD25E198589482F7F43EE32B2F8F0679A225FF657", "hash_ssdeep": "768:QNLbT0zBFpzX5SLsOq/VbDhZeRhh4sVvwEO97dFpMzfe+Ic7Zn9I8Royy51YKX+F:QpH0prYI/VbD3efO9pMj8DAmpfhNokN", "hash_imp": "EB3F6F99C19C67E537908E9D98C57787", "hash_pesha1": "B384F2D2BFDDC7230D60512DFF6127AB9165E365", "hash_pe256": "729B174A375F4176FA3CF7F6C868CBB1E5FFFBEF2A09403DECBA3F132D62A9BD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Mixed Reality Simulation Control", "meta_original_filename": "PerceptionSimulationInput.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6daa3c4359de509e490b6d5fa777c67ffda5178c4c7d2ec1aad8ee8c22d3b5ba/detection", "runtime_modules": [ "C:\\Windows\\system32\\PerceptionSimulation\\PerceptionSimulationInput.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\PerceptionSimulation\\PerceptionSimulationInput.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "PerceptionSimulationService.exe-FC843422E589B5B2400FE528BCF96DD3": { "file_name": "PerceptionSimulationService.exe", "file_path": "C:\\Windows\\system32\\PerceptionSimulation\\PerceptionSimulationService.exe", "hash_md5": "FC843422E589B5B2400FE528BCF96DD3", "hash_sha1": "7FED8242B33343E6ADD2AA112D55991CD3B4E9CD", "hash_sha256": "2FBD09D8C423876B4C47211FD878514DB630DD38A0EE7292B608051CA2CAF137", "hash_sha384": "B39AC9255A5E3F9E8BF26E7BB12FCFEEA50C1F415B7FEF48DC85B983E232C213955411519064FEB081378AC978A4CA49", "hash_sha512": "E942AEFA29431A275931FCCE08976C417A7B5028BAD6E9819FDFD856B94538ACFD6B6C122ED78C40BF6C19A31BEAE67B23A5A59EF12B2E32DEFAEDC70C12FFDC", "hash_ssdeep": "1536:4i5L8OascgCDVIxPT2ym3rp4kmlCrolqJ5VLKgljv3OFbOsJs3Gey9RHOeCUC:4g8FZIxPTXKfUCrUCele+DHOeC1", "hash_imp": "C2DE8C94325285248B02AD116C1FA4BE", "hash_pesha1": "A0A235AE3D1F85C04E12B91F70EFCB856424C2BC", "hash_pe256": "BB354F2A74EA1402F16F95656A9BA8D5E32F2EF7971AD6D9AFA3C32BA2D8917C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Perception Simulation Service", "meta_original_filename": "PerceptionSimulationService.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2fbd09d8c423876b4c47211fd878514db630dd38a0ee7292b608051ca2caf137/detection", "output": "Windows Perception Simulation Service.\r\n\r\nPerceptionSimulation [/I][/U][/?]\r\r\n\r\n /I Installs the \"Windows Perception Simulation Service\" Service.\r\n /U Removes the \"Windows Perception Simulation Service\" Service.\r\n /? Displays this help.\r\n\r\nUnrecognized switch \"--help\"\r\n", "runtime_modules": [ "C:\\Windows\\system32\\PerceptionSimulation\\PerceptionSimulationService.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "SpeechUXWiz.exe-02BCE04D6192EB6BC85A195E0187E707": { "file_name": "SpeechUXWiz.exe", "file_path": "C:\\Windows\\system32\\Speech\\SpeechUX\\SpeechUXWiz.exe", "hash_md5": "02BCE04D6192EB6BC85A195E0187E707", "hash_sha1": "975ECD7E4D51DA13584F8453C9E4959FB94C0545", "hash_sha256": "6FA424DDD31E80D679D987FD94FB2A35D8BBEAD7F5F09404AF531B46DBAE85B6", "hash_sha384": "E0E34C8A25ECA3E596F3611E3AFFA93F609F72D110F8636F1B0ADE6520720399427A9EBB828E0DC891B1DD95D07F119B", "hash_sha512": "F1B82D484867585E206A2D48B64791724ED9AAE57FE55FAE755A786BEE228482CB9CBC03B1E84CFA4D7FD5BBDA0F733FE9500C8303834E3B23FB89580F589733", "hash_ssdeep": "12288:a7lb57GX8YbVe0TIrf8NbywLkRLgLBAgV:ul7Y82VLTIrfMy8oLg", "hash_imp": "831B003F0C669C0AEFF82B001BEDB059", "hash_pesha1": "ED4E92E44B6AEAA4761FC49E87D897E644B07830", "hash_pe256": "54B9DF949C404D67E950F06D1F4CC10A1C3938F559AC27538634A368B5160894", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Speech UX Configuration", "meta_original_filename": "SpeechUXWiz.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6fa424ddd31e80d679d987fd94fb2a35d8bbead7f5f09404af531b46dbae85b6/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_faeca4db76168538": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\Speech\\SpeechUX\\en-US\\SpeechUXWiz.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\shlwapi.dll.mui": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Speech\\SpeechUX\\SpeechUXWiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ], "runtime_window_title": " " }, "SpeechModelDownload.exe-150219C2CCDE1BB1CB0CBB76E8EA94E9": { "file_name": "SpeechModelDownload.exe", "file_path": "C:\\Windows\\system32\\Speech_OneCore\\common\\SpeechModelDownload.exe", "hash_md5": "150219C2CCDE1BB1CB0CBB76E8EA94E9", "hash_sha1": "35276397F86EF8A934515267CFB2223B179A8EF7", "hash_sha256": "CA8768B01D16068F88FB1E6DF7DE9C7D8D46C034AA85F6FC38645131F9670ED4", "hash_sha384": "F7638CFF17F3EAAF1776DA39066649160488447C002678DAE7B89DC0EACDE603C4EB1E3B571BC693BDBBB46BBD0D7A3D", "hash_sha512": "D488817C438497D07828FF3CDD1987D957B686F1BB72D125AC8122ABC1B9C4AFC597BACF5B115FCC2CCD384467470A6DEB6AEF0AA7EB3EAA015E433019CBF28B", "hash_ssdeep": "3072:U+NKOELAaetq/bLeJQ4aTGYPA/kpIEWsaxweImspzFj6551KvNs:U+NKOQjEqzLMQRTzA0JZ2wJRc0N", "hash_imp": "909F26F5A4CB705B5E4FD5A25197A041", "hash_pesha1": "11FC7804C2D9937340FB3A3A3CE9A659A5548CF5", "hash_pe256": "F52523AEBD2CE67290496D66A29852C9E44CDDC1745298C6BC1A87BBEDD2783B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Speech Model Download Executable", "meta_original_filename": "SpeechModelDownload.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/ca8768b01d16068f88fb1e6df7de9c7d8d46c034aa85f6fc38645131f9670ed4/detection", "runtime_modules": [ "C:\\Windows\\system32\\Speech_OneCore\\common\\SpeechModelDownload.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\msvcp110_win.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\policymanager.dll", "C:\\Windows\\SYSTEM32\\WINHTTP.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "SpeechRuntime.exe-7D3B918B0F8B74CDF7990030C2480A49": { "file_name": "SpeechRuntime.exe", "file_path": "C:\\Windows\\system32\\Speech_OneCore\\common\\SpeechRuntime.exe", "hash_md5": "7D3B918B0F8B74CDF7990030C2480A49", "hash_sha1": "E73324E3F6CF9C9C44DF0B2D5BBC9213C77F97CF", "hash_sha256": "BCE8DD332BE145D80C4D32354AAA68590C964D50CE4D2F83F6B775A03011FEEC", "hash_sha384": "1F96A4AA46A58D0074EFD14A49BD919444A6F71BC26202283FA8C3A43D3FD9BCE612E7A2A9906B4D67964DC9717AAB1A", "hash_sha512": "4F317B37C29ADCA80B7D3C9D9494E5EE636A25628AB23623F8B27199DFF1351E0EB6366C9F49D5D48F8FA90F669E3F227887A182ED5C15F18032431606AFE136", "hash_ssdeep": "3072:Pdr828Mc2JGBMlRuVRyIyGzVL83I6H0CeYDtuqx1yY/Ptm9Cskaxa7H/bqoRdhAI:/8AdRurBi3I6H0uDt1/Pq+VDbR+", "hash_imp": "BE5F2589CC9B9F8396B9829ED1BB6BBA", "hash_pesha1": "258FDE5E063B30A73278A0298D59DB5B2C24AE1C", "hash_pe256": "F0FA23D0EFACD30FB11964BF362D3C6C4505E81826F496B018AA94CBAE34FF4C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Speech Runtime Executable", "meta_original_filename": "SpeechRuntime.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.450 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.450", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/bce8dd332be145d80c4d32354aaa68590c964d50ce4d2f83f6b775a03011feec/detection", "runtime_modules": [ "C:\\Windows\\system32\\Speech_OneCore\\common\\SpeechRuntime.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\SYSTEM32\\msvcp110_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\MMDevAPI.DLL", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll" ] }, "PrintBrm.exe-BAE39750EE98F30056CC520ED59C8E88": { "file_name": "PrintBrm.exe", "file_path": "C:\\Windows\\system32\\spool\\tools\\PrintBrm.exe", "hash_md5": "BAE39750EE98F30056CC520ED59C8E88", "hash_sha1": "E97628C7DE13D0F631BFADE8994F6E4445F5ECBA", "hash_sha256": "68DFB48A2A78893FFDCD8D02D24DC8BBF95699857DA95862B034E6EB885B6EF2", "hash_sha384": "8899A738A78120332E366E54A6D751BD31527FEB6E042E0E77EEC1D98D689392DC7D3D0CD0E6227B9B1AF822E4E4D81F", "hash_sha512": "D40F8C33423854C2F6B4181458D12F5AF9AA6B2658FA32D1D2AC8035F8899A97845DC6C62BDDB43DF0E2BFE23AA453B389BCBED3B36B3BF6703903C0748CD769", "hash_ssdeep": "384:VygfGoA3q3S/j6ae3m2vIOfgwi57MdLpdEjGt/Uy6ZbqY2+O5PP9WWhW:PGoA3qC/YX+SdFUzoY2ZPL", "hash_imp": "C41B1537E18BBD1DFB2420E52994CAEF", "hash_pesha1": "63F0EEB7FE292BDE398AD1DFB1EC9D098ABFA0B5", "hash_pe256": "596B82DC1E89CE20C09E1E286D80C23022BC6F3E5E97D1FC78AADC9E26516CDA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Print BRM command line tool", "meta_original_filename": "PrintBrm.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/68dfb48a2a78893ffdcd8d02d24dc8bbf95699857da95862b034e6eb885b6ef2/detection", "output": "Error: A single mode must be selected!\n\nAccess the Backup Recovery Migration tool through a command line interface.\n\nPrintBrm -B|R|Q [-S <server>] -F <file> [-D <directory>] [-O FORCE] [-P ALL|ORIG] [-NOBIN] [-LPR2TCP] [-C <config file>] [-NOACL] [-?]\n-B Backup the server to the specified file\n-R Restore the configuration in the file to the server\n-Q Query the server or the backup file\n-S <server name> Target server\n-F <file name> Target backup File\n-D <directory> Unpack the backup file to (with -R) or repack a backup file from (with -B) the given directory\n-O FORCE Force overwriting of existing objects\n-P ALL|ORIG Publish all printers in directory, or publish printers that were published originally\n-NOBIN Omit the binaries from the backup\n-LPR2TCP Convert LPR ports to Standard TCP/IP ports on restore\n-C <file name> Use the specified configuration file for BRM\n-NOACL Remove ACLs from print queues on restore\n-? Display this help\n", "runtime_modules": [ "C:\\Windows\\system32\\spool\\tools\\PrintBrm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "PrintBrmEngine.exe-B012FFD4218AF49AD09156E918A6757E": { "file_name": "PrintBrmEngine.exe", "file_path": "C:\\Windows\\system32\\spool\\tools\\PrintBrmEngine.exe", "hash_md5": "B012FFD4218AF49AD09156E918A6757E", "hash_sha1": "CE8AE6E76B3C1199A568E06CE9C65E4ACD44F6F3", "hash_sha256": "C3247F0751FFA3167E89B2DA622AA46BBE5605A5D930511B8209303778499A9B", "hash_sha384": "1A59EF1A63B8F3D843402A1B4DA30507844F082C85D281B72A465715FF2D43206FFE8D968D7E98103B0C5CFFEED95171", "hash_sha512": "520420DE0F819FD3631A80ABAE14334A0B5FD9CBB7EF3FD37BF2C183FEA06B9900AA4E6A3650D016A39ED44740E66A8091068C95C46A3F3E29E3A47DA542D2BB", "hash_ssdeep": "3072:/fxkIjwIiz5+x3llyhRCojCckNT7MqOqCbNvb6t2PnOp8j4d0hvH9KGprQArIqpN:eIjb7Y7jCXN0bE0PhxdKGrIpc", "hash_imp": "7B4A0F411CD34A08A69BAB9D0217D8BB", "hash_pesha1": "C124E9057AEFF460449ACDBFB90AE9BA085B3F1F", "hash_pe256": "6305873DA533B81CC33362F37FFF911C679AD43E63B78A85FAD040D2268B9CA4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PrintBrmEngine EXE", "meta_original_filename": "PrintBrmEng.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c3247f0751ffa3167e89b2da622aa46bbe5605a5d930511b8209303778499a9b/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\spool\\tools\\en-US\\PrintBrmEngine.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\spool\\tools\\PrintBrmEngine.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\SYSTEM32\\NETAPI32.dll", "C:\\Windows\\SYSTEM32\\mscms.dll", "C:\\Windows\\SYSTEM32\\WINSPOOL.DRV", "C:\\Windows\\SYSTEM32\\RESUTILS.dll", "C:\\Windows\\SYSTEM32\\CLUSAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\Cabinet.dll" ] }, "sysprep.exe-C5E1B06428599844B7A5F68569BC9B2C": { "file_name": "sysprep.exe", "file_path": "C:\\Windows\\system32\\Sysprep\\sysprep.exe", "hash_md5": "C5E1B06428599844B7A5F68569BC9B2C", "hash_sha1": "77F1251781EA5ADB08D9562EEE4D7F8A7E75464C", "hash_sha256": "13D75313A9C011214F7C62EF659E441ABE4C80D5F85FF559C0ABCFDB36C44F10", "hash_sha384": "9F0A0DEDEF8CC11CF7FB04721D769FBB23B66653E0BF321FB8514605E46AA1122BB0F6AAEFCFBE365B82D9A20CFC99CC", "hash_sha512": "18EE126C254C87F4ACEF5D5ACFFA9AF5329433C7445D9405E48052C869FBEAB53ED2106245B3140D144C1DFDF832FB2140838D8C2528641DDA6029F15EF0E2C8", "hash_ssdeep": "12288:NiwH2arwj4gAiiLSHp4Kh15ogt6ldY1f661Ep:NiUTgAiaSuMl6ea", "hash_imp": "26CECC77A14868FEBC547A3A952471C1", "hash_pesha1": "5826A62D2704F84A344A2309B280A6272EEFEFE4", "hash_pe256": "939B3B9811A5FC7244B296EA1BA2D1CCD9FABC09C6A663B7FD030909B2698FB1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Preparation Tool", "meta_original_filename": "sysprep.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/13d75313a9c011214f7c62ef659e441abe4c80d5f85ff559c0abcfdb36c44f10/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\Sysprep\\en-US\\sysprep.exe.mui": "File", "(RW-) C:\\Windows\\System32\\Sysprep\\Panther\\setupact.log": "File", "\\BaseNamedObjects\\SetupLogSection": "Section", "(RW-) C:\\Windows\\System32\\Sysprep\\Panther\\setuperr.log": "File", "(RW-) C:\\Windows\\System32\\Sysprep\\Panther\\diagerr.xml": "File", "(RW-) C:\\Windows\\System32\\Sysprep\\Panther\\diagwrn.xml": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Sysprep\\sysprep.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll" ], "runtime_window_title": "System Preparation Tool 3.14" }, "SystemResetPlatform.exe-53D5FFBB2B075BB8D1E1D49F2F0FF774": { "file_name": "SystemResetPlatform.exe", "file_path": "C:\\Windows\\system32\\SystemResetPlatform\\SystemResetPlatform.exe", "hash_md5": "53D5FFBB2B075BB8D1E1D49F2F0FF774", "hash_sha1": "F2803F0BD860067DE1AC288E0059C28C81A15AD7", "hash_sha256": "260B6137F1D1977F569EDEF5DF5684FE61F5CC2A5E56F351A6309BD97E8E4F16", "hash_sha384": "2A4876C8FF7CE4E84E1F92A5130F225CA80BDE7CA8719F3BB9F96B4B19EEFCA989EE50CB2797F20A04B03CEBCE6CD935", "hash_sha512": "EE6A056EA87D50CC6F864C02E4753DDD215CA1A3D9B9DE3423BF11CC2CD3ED1875C8BEE73D73C06852E589D832AB42FF780DDC50A9BC6FF62B583933029E94D5", "hash_ssdeep": "192:oX0u1J0pbgNGM9gNaBLLSGBwcgvv1sxu4UGvdhjUWpSW:UpJsgkYC+HIXSQ4UhWpSW", "hash_imp": "E058437B06D0330796EF05165724B390", "hash_pesha1": "E2DA3DAF0137D6FE8E61778F8663EA3C24C7CDF8", "hash_pe256": "0D33EC75F0783F89795BCB15D98689A61E48C6D10442D701E99CC3CF74876633", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows System Reset Platform", "meta_original_filename": "SystemResetPlatform.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/260b6137f1d1977f569edef5df5684fe61f5cc2a5e56f351a6309bd97e8e4f16/detection", "runtime_modules": [ "C:\\Windows\\system32\\SystemResetPlatform\\SystemResetPlatform.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "UNPUXHost.exe-3DE5A57F85767A9CD8352963353A61F1": { "file_name": "UNPUXHost.exe", "file_path": "C:\\Windows\\system32\\UNP\\UNPUXHost.exe", "hash_md5": "3DE5A57F85767A9CD8352963353A61F1", "hash_sha1": "5028CCD48E04299D49D371B5475D945A2B60063D", "hash_sha256": "BF2BB12082DAAB0649D6E9C828102156528CDC656957C9E11B5863117EF60F51", "hash_sha384": "A7CA3E5B9D71779A62A0B814DC3A82755FB4CD78D5F61250F6CFF46D7A6CCFCD045C74253A777671BED34B752DD876F8", "hash_sha512": "D3C748BF8F42F98AFDAC29973D2BDF7E8BF6D3F63481F2D3E1536588A6D2C9184236C5CDE8F01DAEAC196E13E7FB17F5BA83E749B7395BB7214C78572E034F7C", "hash_ssdeep": "1536:fXB9Ug7Ef5YVVRcM9juqM/0eloKd/IpNfKVN2YPw:fxkf5Yv7uJ02epNfmN2Y4", "hash_imp": "F6D1ECC54CD450FBD9FBBEABF11BEB51", "hash_pesha1": "9F40338EE14E6A9C31656A83E6FA752866C69AAA", "hash_pe256": "4F5D7A99E7E9F0B1B591C822E0A401A02E941F25C01D8AE94C15913B85B92764", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UNPUXHost", "meta_original_filename": "UNPUXHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.264 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.264", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/bf2bb12082daab0649d6e9c828102156528cdc656957c9e11b5863117ef60f51/detection", "runtime_modules": [ "C:\\Windows\\system32\\UNP\\UNPUXHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll" ] }, "UNPUXLauncher.exe-6D2213A1354244E88CA019115C84886C": { "file_name": "UNPUXLauncher.exe", "file_path": "C:\\Windows\\system32\\UNP\\UNPUXLauncher.exe", "hash_md5": "6D2213A1354244E88CA019115C84886C", "hash_sha1": "3627932B4C5033A821532F96DB78D2FD5FD9129A", "hash_sha256": "D06A1EC31F16F24D7B027A6997578F1C0055CDDDE09A135D1FFE6497EE93C4A1", "hash_sha384": "F309426204E39705EE7322F416503EFC8AEEA2C72014351F51256B4C046B44F2784759D92D74625334ACF05B053984CE", "hash_sha512": "76B304556E357BF6224C4827DFD89081724D164E9E50C1123612896BBFBED7C4E88CB0EF9AA2834577F80D26F75AB353E18E6CED38462CDBED0CE66329E0D60B", "hash_ssdeep": "6144:EPbSJ3mQdtLgvdp+jOf20thsVH5SyZOxHABAcMShxyH0j19PYrgxMIWbbuoNVJoo:8qdtSKGsLjq8EOrP0WMIywmK3ecq", "hash_imp": "A46F59BA88B91648797F2C614E169048", "hash_pesha1": "8C1104F521E57B9418A5CD83F7C9FFBD3908D501", "hash_pe256": "C4397AC13679E2D7B899D213FB6D772EC7904AB43440E0FCCA51FDCB7F3C8FFE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UNP UXLauncher", "meta_original_filename": "UNPUXLauncher.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.264 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.264", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d06a1ec31f16f24d7b027a6997578f1c0055cddde09a135d1ffe6497ee93c4a1/detection", "runtime_modules": [ "C:\\Windows\\system32\\UNP\\UNPUXLauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\SYSTEM32\\NETAPI32.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\SYSTEM32\\UpdatePolicy.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\SYSTEM32\\profapi.dll", "C:\\Windows\\SYSTEM32\\WKSCLI.DLL", "C:\\Windows\\SYSTEM32\\Cabinet.dll", "C:\\Windows\\SYSTEM32\\DSREG.DLL", "C:\\Windows\\SYSTEM32\\NETUTILS.DLL", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\msvcp110_win.dll" ] }, "UpdateNotificationMgr.exe-77F9C8B70ED9F3E16819D9765D19B0A9": { "file_name": "UpdateNotificationMgr.exe", "file_path": "C:\\Windows\\system32\\UNP\\UpdateNotificationMgr.exe", "hash_md5": "77F9C8B70ED9F3E16819D9765D19B0A9", "hash_sha1": "D787E4C376C9CF8D83D1EBFD161BBC71D61F7D82", "hash_sha256": "5FE4952BCF8AC7EDF0C7C6342F674AFF558D47D7902C8217D73069AE084F3F9B", "hash_sha384": "856FA8054D8BAF5955403BC621F8FEA66F3B664BD58A340B011B06209222D1960A9EBE7FA56F364E5DC1CDE05F0B77CC", "hash_sha512": "997063AA59C9B1FE1EEF0FE8BDA269D429B387914C3EF3450A439439D279E8C916A454A347503F2CD37BCCE4B94C92FF2D96E9ADEED3866BADFC946CA67E28B5", "hash_ssdeep": "6144:f0qkYPw/UC2Vl9KNsrqPWE53VkN9ghWSXeAGagqeM8ywebWxZGi/tHd53HN3qfuC:8nIwKl9nNqooGqVGGAJHVd8AAQUZf", "hash_imp": "E8EAAE034EA45824C464D09034C7E0E3", "hash_pesha1": "0173AFF3C78248FE45B49DA8FA7AB52385B6CFCF", "hash_pe256": "F8F6D3A9E263F1197F555DAFB75F9CF67FCDD63B637C1C8601FEC2F8C07EB941", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Update Notification Pipeline Manager", "meta_original_filename": "UpdateNotificationMgr.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.264 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.264", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/5fe4952bcf8ac7edf0c7c6342f674aff558d47d7902c8217d73069ae084f3f9b/detection", "runtime_modules": [ "C:\\Windows\\system32\\UNP\\UpdateNotificationMgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll" ] }, "mofcomp.exe-E09EEB349A313277FABBC4204360D005": { "file_name": "mofcomp.exe", "file_path": "C:\\Windows\\system32\\wbem\\mofcomp.exe", "hash_md5": "E09EEB349A313277FABBC4204360D005", "hash_sha1": "8A34E39B4969D6F593CBECD662A7A77E9E87A798", "hash_sha256": "C6997C7079F983FAC9A928FA87CA9824CF7BEF3979735AC5C1F690EBDCEBA770", "hash_sha384": "77B5F69AECA4AB899E37C39FB68A81866EB6B5D9BEBEEA4183B592832866C4BBCFEE5C33F1FCDE221C333642E5740F52", "hash_sha512": "AE8E40B4C9E8AE396C40F92E8E50EEFA74D5457164835079AE2EFBA62B05D4F5606040DE107C1F82FF56DDAC5A0ECCC186F93BB5E79E83AF0DF2EFFED4B65AD5", "hash_ssdeep": "768:M0C+hz3bD5Y3fKWIdqjl0cT4i1oa9/TRNV2:vC+DgfKWH+bi2a9/TRb2", "hash_imp": "9A6A5E4D269C5D18366CA5BF7D1981EB", "hash_pesha1": "AA642E5C8658003C052A272244A6B4B8E9A08F01", "hash_pe256": "DE9BED5DB33CADAC09554BAA387E586A72A82A4AF2F92D511B0FEFB5525FD9AD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "The Managed Object Format (MOF) Compiler ", "meta_original_filename": "mofcomp.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c6997c7079f983fac9a928fa87ca9824cf7bef3979735ac5c1f690ebdceba770/detection", "output": "Microsoft (R) MOF Compiler Version 10.0.19041.1\nCopyright (c) Microsoft Corp. 1997-2006. All rights reserved.\n\nusage: mofcomp [-check] [-N:<Path>]\n [-class:updateonly|-class:createonly]\n [-instance:updateonly|-instance:createonly]\n [-B:<filename>] [-P:<Password>] [-U:<UserName>]\n [-A:<Authority>] [-WMI] [-AUTORECOVER]\n [-MOF:<path>] [-MFL:<path>] [-AMENDMENT:<Locale>]\n [-ER:<ResourceName>] [-L:<ResourceLocale>] \n <MOF filename>\n\n -check Syntax check only\n -N:<path> Load into this namespace by default\n -class:updateonly Do not create new classes\n -class:safeupdate Update unless conflicts exist\n -class:forceupdate Update resolving conflicts if possible\n -class:createonly Do not change existing classes\n -instance:updateonly Do not create new instances\n -instance:createonly Do not change existing instances\n -U:<UserName> User Name\n -P:<Password> Login password\n -A:<Authority> Example: NTLMDOMAIN:Domain\n -B:<destination filename> Creates a binary MOF file, does not add to DB\n -WMI Do Windows Driver Model (WDM) checks, requires -B switch\n -AUTORECOVER Adds MOF to list of files compiled during DB recovery\n -Amendment:<LOCALE> splits MOF into language neutral and specific versions\n where locale is of the form \"MS_4??\"\n -MOF:<path> name of the language neutral output\n -MFL:<path> name of the language specific output\n -ER:<ResourceName> extracts binary mof from named resource\n -L:<ResourceLocale> optional specific locale number when using -ER switch\n\n Example c:>mofcomp -N:root\\default yourmof.mof\n", "runtime_modules": [ "C:\\Windows\\system32\\wbem\\mofcomp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "scrcons.exe-FD8C66AD69CCF980E08ADA4EA35FD3FB": { "file_name": "scrcons.exe", "file_path": "C:\\Windows\\system32\\wbem\\scrcons.exe", "hash_md5": "FD8C66AD69CCF980E08ADA4EA35FD3FB", "hash_sha1": "0102A12E468DCC2B40681252E311B6AFA3C6DAB0", "hash_sha256": "F96C187199362265FAC87ADB337DB242D24F9B313407646F89DA62A1ED12B6D9", "hash_sha384": "83F0E50AAFBA9BD059A42EC8680A1DEA22ACB08BF042BF0A608500D73FD22AEE856442586F49470F8958429B78CC84F2", "hash_sha512": "69414794881801B43855A6880159E61B0D412B192F57066D8AE820267F43D5255D2660C69A4B98F7924083DE8FC66920E67EE0AFBF3C3C780147213C876A3177", "hash_ssdeep": "1536:5K7eR5nv5HMyhDuihPLrFj3tkj069tuNdXSnNdGjQBBBfA1bUIzB21+nFFifj:5nnv5HMyVuiHj3tgBfUbUIV21+nFQ", "hash_imp": "33D9F246D162F5E1E1312E28E566A69E", "hash_pesha1": "06B6A53B58BD62CC5FCDFDED693F806C941226A1", "hash_pe256": "8864A7B69CB55FA75466F2A5260277B2088C29498A42DADD6DF95679B96B98DD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Standard Event Consumer - scripting", "meta_original_filename": "ScrCons", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f96c187199362265fac87adb337db242d24f9b313407646f89da62a1ed12b6d9/detection", "output": "Cannot run standalone\r\n", "runtime_modules": [ "C:\\Windows\\system32\\wbem\\scrcons.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "unsecapp.exe-0BA8D3EDBE27B4C5475D569AF411C2A0": { "file_name": "unsecapp.exe", "file_path": "C:\\Windows\\system32\\wbem\\unsecapp.exe", "hash_md5": "0BA8D3EDBE27B4C5475D569AF411C2A0", "hash_sha1": "8E8AF64662B50738D27D835FEDD66A41E5752A0D", "hash_sha256": "5CD0DD3B1454B437362C87C651EE2068AC27CDB725AA1C705CF62FF325A759CC", "hash_sha384": "021884DE1CE9B75AAA3B762B81F6E76D2B83DFF81206E2CAE897D97BFCEF4375FE0F450DB5E164130A95543BDB8A5FF4", "hash_sha512": "D7FF3EBFFEE853A643DE5D10E59C6A6199E24CC9BDFC585ECF8414D26721F50178B96A294E624B68BE532C9EE2EB086E3876B896C8CC25E9C0C50C1F58D7F8C2", "hash_ssdeep": "1536:DzAD+X+1mFQOM16kLDGa3Fz8yntK6b+Bzn1dZSfcP2OZ:DzcT1wkLDGa3Fz1nk6b+Bz1b62", "hash_imp": "87E54E3D04D772F26002D8B564B2426C", "hash_pesha1": "E93D96431BEA31516A2F80132FB67B44B605C2C8", "hash_pe256": "7090CE5A6DD300A85026CAC8D898C33401B8727FB3BE56FC8C70C99E23A4FF00", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Sink to receive asynchronous callbacks for WMI client application", "meta_original_filename": "unsecapp.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5cd0dd3b1454b437362c87c651ee2068ac27cdb725aa1c705cf62ff325a759cc/detection", "output": "Cannot run standalone\r\n", "runtime_modules": [ "C:\\Windows\\system32\\wbem\\unsecapp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll" ] }, "wbemtest.exe-0BE7ED026AA1220DE3C2F099983E35CA": { "file_name": "wbemtest.exe", "file_path": "C:\\Windows\\system32\\wbem\\wbemtest.exe", "hash_md5": "0BE7ED026AA1220DE3C2F099983E35CA", "hash_sha1": "C6218D1101F9BC639E193F98EDC0428D322E11FB", "hash_sha256": "2828D06FE31D1D3A1910DC4F370CA652F10CB0F8C83CD0CCDEC1F72A1469DDB9", "hash_sha384": "8280275DF8F6DE4E05C3B76BB45E645F45AB93E1FD7915820E64865E06FC028065E0001E6D7E6A579C39C90AEB93E474", "hash_sha512": "7AAA3D6897CD0892BAD74F571E4DA7318B8884BC83EE9E66F70876352CBFD185EF1282A8B7097E8FA918111A5D8FF7BD6ED996B96AEA25D86F3F2CA086FE6014", "hash_ssdeep": "3072:+4Nur3ltFr/NTVtC6VYnzvM5RBgDw0B8Y1wfT6UhIPFJRAhP2EAeL:+4NuL1NTVRgTOQiEqmtDeP", "hash_imp": "CDFDFC84E739873776D87479B9819CD0", "hash_pesha1": "942F366EB61513A1B9ACEF186A00D043EBC326EF", "hash_pe256": "E6A81CDAC5DD5DB917D405163869948B5D34458F56F345BDAE059A447BB9BF8A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Test Tool", "meta_original_filename": "wbemtest.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/2828d06fe31d1d3a1910dc4f370ca652f10cb0f8c83cd0ccdec1f72a1469ddb9/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\wbem\\en-US\\wbemtest.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wbem\\wbemtest.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "runtime_window_title": "Windows Management Instrumentation Tester" }, "WinMgmt.exe-16960C591549024DE6400C41917BA082": { "file_name": "WinMgmt.exe", "file_path": "C:\\Windows\\system32\\wbem\\WinMgmt.exe", "hash_md5": "16960C591549024DE6400C41917BA082", "hash_sha1": "A22F02418BD1D8569D4E7E0D95385A5640FE6D21", "hash_sha256": "ACF5CB14318C8CCD2645F9F72A8885EF3631CED88EBF2B832DFA541373B062E3", "hash_sha384": "B7BFCD03F85790705DBF8D5F3BBD667DED194EADDF87548C98811CE62EC3014C89CD6B212B85717AAD80C1549D315F58", "hash_sha512": "F2AE52D1DF101166BF0E61FDCBB9464823AACAA79D4F526D43805DE73F8BCA3E0DAE314B18E9DF4755EA42EEFF146B5D8AAEB1472AF371E5D3FC724EE9CE2B63", "hash_ssdeep": "1536:O6/vNRQsuQivv2vdShIPoANJLlAXuSXv+qSFEAeOFi:tc2vshIPFJRAhP2EAeP", "hash_imp": "798ACA9C42114FEEB9FA9A5FD82CBA43", "hash_pesha1": "A23BF496D4F683B72B1C865B430FB60A7A079D0D", "hash_pe256": "BC6F5E042A8DE63FCACEF093E1FADE8F9CD2236A2F68156BAA7C9B6D38250D3F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Service Control Utility", "meta_original_filename": "winmgmt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/acf5cb14318c8ccd2645f9f72a8885ef3631ced88ebf2b832dfa541373b062e3/detection", "children": "powershell.exe", "output": "Invalid parameter\n\nWindows Management Instrumentation\n\nUsage: winmgmt\t[/backup <filename>] [/restore <filename> <flag>]\n\t\t[/resyncperf] [/standalonehost [<level>]] [/sharedhost]\n\t\t[/verifyrepository [<path>]] [/salvagerepository]\n\t\t[/resetrepository]\n\n/backup <filename>\n\tCauses WMI to back up the repository to the specified file name. The\n\tfilename argument should contain the full path to the file location.\n\tThis process requires a write lock on the repository so that write\n\toperations to the repository are suspended until the backup process is\n\tcompleted.\n\n/restore <filename> <flag>\n\tManually restores the WMI repository from the specified backup file.\n\tThe filename argument should contain the full path to the backup file\n\tlocation. To perform the restore operation, WMI saves the existing\n\trepository to write back if the operation fails. Then the repository is\n\trestored from the backup file that is specified in the filename\n\targument. If exclusive access to the repository cannot be achieved,\n\texisting clients are disconnected from WMI. The flag argument must be a\n\t1 (force - disconnect users and restore) or 0 (default - restore if no\n\tusers connected) and specifies the restore mode.\n\n/resyncperf\n\tRegisters the system performance libraries with WMI.\n\n/standalonehost [<level>]\n\tMoves the Winmgmt service to a standalone Svchost process that has a\n\tfixed DCOM endpoint. The default endpoint is \"ncacn_ip_tcp.0.24158\".\n\tHowever, the endpoint may be changed by running Dcomcnfg.exe. The level\n\targument is the authentication level for the Svchost process. If level\n\tis not specified, the default is 4 (RPC_C_AUTHN_LEVEL_PKT).\n\n/sharedhost\n\tMoves the Winmgmt service into the shared Svchost process.\n\n/verifyrepository [<path>]\n\tPerforms a consistency check on the WMI repository. When you add the\n\t/verifyrepository switch without the <path> argument, then the live\n\trepository currently used by WMI is verified. When you specify the path\n\targument, you can verify any saved copy of the repository. In this\n\tcase, the path argument should contain the full path to the saved\n\trepository copy. The saved repository should be a copy of the entire\n\trepository folder.\n\n/salvagerepository\n\tPerforms a consistency check on the WMI repository, and if an\n\tinconsistency is detected, rebuilds the repository. The content of the\n\tinconsistent repository is merged into the rebuilt repository, if it\n\tcan be read. The salvage operation always works with the repository\n\tthat the WMI service is currently using. MOF files that contain the\n\t#pragma autorecover preprocessor statement are restored to the\n\trepository.\n\n/resetrepository\n\tThe repository is reset to the initial state when the operating system\n\tis first installed. MOF files that contain the #pragma autorecover\n\tpreprocessor statement are restored to the repository.\n\n", "runtime_modules": [ "C:\\Windows\\system32\\wbem\\WinMgmt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "WMIADAP.exe-44FA781649A564AD9DD8453D14758F96": { "file_name": "WMIADAP.exe", "file_path": "C:\\Windows\\system32\\wbem\\WMIADAP.exe", "hash_md5": "44FA781649A564AD9DD8453D14758F96", "hash_sha1": "F3651B5BCAC5CED5174F43DDC98DDF3BE8616CDD", "hash_sha256": "9B1F44ED54A0AB6D1A18D113BA3C946D961F4D652FFBA0C3F1B2AA89A6CC7D0E", "hash_sha384": "4603C8EC84358C290574773638214D59D9C8BB25073DD4582E57D46ACEE235EA1623DE8E72AC9E9615B0E346742E1486", "hash_sha512": "C4E45384451823375D913C5A74D73858A7D0BAFA84825B56472731700192B16E3CA3B60CED7A79E88DA05B828035ED043266336140F25AEDF0BBF706A879C923", "hash_ssdeep": "1536:cg5H2POb7l/WO7bMv+MinfDTeuzP0DxPfrkiD9r+vCtrFtwgVeBLbZ1jh1aANQdo:j1JbMvefDF8DNHD9r+qzK1mwUMOofqq", "hash_imp": "367D299428703C9A9715504BFE071C97", "hash_pesha1": "1756F43A1467F839F5D6951608CA59F0DE99C108", "hash_pe256": "16B0C87AEFF51A43F5FFE4B5B587446903F2410DBA147C4AB4CD9F4E35B8DB1C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Reverse Performance Adapter Maintenance Utility", "meta_original_filename": "wmicookr.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/9b1f44ed54a0ab6d1a18d113ba3c946d961f4d652ffba0c3f1b2aa89a6cc7d0e/detection", "runtime_modules": [ "C:\\Windows\\system32\\wbem\\WMIADAP.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll" ] }, "WmiApSrv.exe-6389D05C6AAE73AD218CDC8153647CBB": { "file_name": "WmiApSrv.exe", "file_path": "C:\\Windows\\system32\\wbem\\WmiApSrv.exe", "hash_md5": "6389D05C6AAE73AD218CDC8153647CBB", "hash_sha1": "E593A6EF16D400B761800BDEE37A4D6364AFCF1D", "hash_sha256": "2A05EA2653CE6EE43E02B1CC26530D3292D314BE8D31A4641DE333FA6B093CCA", "hash_sha384": "AC1A7C23D9E38500609240045443E30DA2833B181AD63380AB0D0AFD9BEB16F5F2CEB283C750FEDBC7C0C852DADE6E14", "hash_sha512": "7109FCB3B640D6B4C8B266FF13D4927CAAA5523155264417404D21DA9A4069E988265F88DBB9A9FB0A696D6B543001AB04923B1BD7DB8D596D39A901927CAF3A", "hash_ssdeep": "3072:lAiSyaIRNc6IQqHNOQpwLs2Z0PpEXcjZl+7aTnbJUORZp2:lwyaIRNcLDtOPo2Z0Ryc1lhn6ORZp", "hash_imp": "E91C5A3E92623E396D79A8A599CF25A9", "hash_pesha1": "5C6B9931F1C020ECB882B820B43E7767192E8D04", "hash_pe256": "1D7A0138D99CDB361C769ACA8FE3067003E8102C85874FB61CA558F43EC54593", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Performance Reverse Adapter", "meta_original_filename": "WmiApSrv.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2a05ea2653ce6ee43e02b1cc26530d3292d314be8d31a4641de333fa6b093cca/detection", "runtime_modules": [ "C:\\Windows\\system32\\wbem\\WmiApSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "WMIC.exe-A2EF3F0AD95FDA9262A5F9533B6DD1BD": { "file_name": "WMIC.exe", "file_path": "C:\\Windows\\system32\\wbem\\WMIC.exe", "hash_md5": "A2EF3F0AD95FDA9262A5F9533B6DD1BD", "hash_sha1": "AA3047921E1821FC2959D0ED40191A7AFF33B6EC", "hash_sha256": "FA78C88DAC91FDF2EAC736E6900AC1EC4AB7A388B8F77A23FFA7E80A4AD29F5A", "hash_sha384": "83FB60616B354E148638A11FEBDB54B2CEDB6D0430138D6DD70B1BFFEBA60FE5B29A82D8D8D78DB9571C5E0E0AA5C9DE", "hash_sha512": "71C9B7F76AE68CA24C2B985D47509C5C5CA262A2A23FDADA63B35343C3482776539B5D958D92F7C53F79A91320555EB569E22D30B8CA83D94D555F7E5665CFC1", "hash_ssdeep": "6144:fSWq+ijIokIRywZYxCzEY5wfY0fvnnok/LFoCs4F/HPcoe/VLSztBKHGH5enh:KWptweFYi1ok6CsV/VLSDKHGH0nh", "hash_imp": "D8770F1C24B7AAD7B5CD1817B3FEB2AA", "hash_pesha1": "063C404BE48F1DFA34E01613FBC64D155580A6D1", "hash_pe256": "C0A0014E734125EA5871831823EE0D2E91B36CF8293F263FCE3D8E8AD62ED3A2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Commandline Utility", "meta_original_filename": "wmic.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/fa78c88dac91fdf2eac736e6900ac1ec4ab7a388b8f77a23ffa7e80a4ad29f5a/detection", "output": "\r\r\nWMIC is deprecated.\r\r\n\r\r\n[global switches] <command>\r\r\n\r\r\nThe following global switches are available:\r\r\n/NAMESPACE Path for the namespace the alias operate against.\r\r\n/ROLE Path for the role containing the alias definitions.\r\r\n/NODE Servers the alias will operate against.\r\r\n/IMPLEVEL Client impersonation level.\r\r\n/AUTHLEVEL Client authentication level.\r\r\n/LOCALE Language id the client should use.\r\r\n/PRIVILEGES Enable or disable all privileges.\r\r\n/TRACE Outputs debugging information to stderr.\r\r\n/RECORD Logs all input commands and output.\r\r\n/INTERACTIVE Sets or resets the interactive mode.\r\r\n/FAILFAST Sets or resets the FailFast mode.\r\r\n/USER User to be used during the session.\r\r\n/PASSWORD Password to be used for session login.\r\r\n/OUTPUT Specifies the mode for output redirection.\r\r\n/APPEND Specifies the mode for output redirection.\r\r\n/AGGREGATE Sets or resets aggregate mode.\r\r\n/AUTHORITY Specifies the <authority type> for the connection.\r\r\n/?[:<BRIEF|FULL>] Usage information.\r\r\n\r\r\nFor more information on a specific global switch, type: switch-name /?\r\r\n\r\r\n\r\r\nThe following alias/es are available in the current role:\r\r\nALIAS - Access to the aliases available on the local system\r\r\nBASEBOARD - Base board (also known as a motherboard or system board) management.\r\r\nBIOS - Basic input/output services (BIOS) management.\r\r\nBOOTCONFIG - Boot configuration management.\r\r\nCDROM - CD-ROM management.\r\r\nCOMPUTERSYSTEM - Computer system management.\r\r\nCPU - CPU management.\r\r\nCSPRODUCT - Computer system product information from SMBIOS. \r\r\nDATAFILE - DataFile Management. \r\r\nDCOMAPP - DCOM Application management.\r\r\nDESKTOP - User's Desktop management.\r\r\nDESKTOPMONITOR - Desktop Monitor management.\r\r\nDEVICEMEMORYADDRESS - Device memory addresses management.\r\r\nDISKDRIVE - Physical disk drive management. \r\r\nDISKQUOTA - Disk space usage for NTFS volumes.\r\r\nDMACHANNEL - Direct memory access (DMA) channel management.\r\r\nENVIRONMENT - System environment settings management.\r\r\nFSDIR - Filesystem directory entry management. \r\r\nGROUP - Group account management. \r\r\nIDECONTROLLER - IDE Controller management. \r\r\nIRQ - Interrupt request line (IRQ) management. \r\r\nJOB - Provides access to the jobs scheduled using the schedule service. \r\r\nLOADORDER - Management of system services that define execution dependencies. \r\r\nLOGICALDISK - Local storage device management.\r\r\nLOGON - LOGON Sessions. \r\r\nMEMCACHE - Cache memory management.\r\r\nMEMORYCHIP - Memory chip information.\r\r\nMEMPHYSICAL - Computer system's physical memory management. \r\r\nNETCLIENT - Network Client management.\r\r\nNETLOGIN - Network login information (of a particular user) management. \r\r\nNETPROTOCOL - Protocols (and their network characteristics) management.\r\r\nNETUSE - Active network connection management.\r\r\nNIC - Network Interface Controller (NIC) management.\r\r\nNICCONFIG - Network adapter management. \r\r\nNTDOMAIN - NT Domain management. \r\r\nNTEVENT - Entries in the NT Event Log. \r\r\nNTEVENTLOG - NT eventlog file management. \r\r\nONBOARDDEVICE - Management of common adapter devices built into the motherboard (system board).\r\r\nOS - Installed Operating System/s management. \r\r\nPAGEFILE - Virtual memory file swapping management. \r\r\nPAGEFILESET - Page file settings management. \r\r\nPARTITION - Management of partitioned areas of a physical disk.\r\r\nPORT - I/O port management.\r\r\nPORTCONNECTOR - Physical connection ports management.\r\r\nPRINTER - Printer device management. \r\r\nPRINTERCONFIG - Printer device configuration management. \r\r\nPRINTJOB - Print job management. \r\r\nPROCESS - Process management. \r\r\nPRODUCT - Installation package task management. \r\r\nQFE - Quick Fix Engineering. \r\r\nQUOTASETTING - Setting information for disk quotas on a volume. \r\r\nRDACCOUNT - Remote Desktop connection permission management.\r\r\nRDNIC - Remote Desktop connection management on a specific network adapter.\r\r\nRDPERMISSIONS - Permissions to a specific Remote Desktop connection.\r\r\nRDTOGGLE - Turning Remote Desktop listener on or off remotely.\r\r\nRECOVEROS - Information that will be gathered from memory when the operating system fails. \r\r\nREGISTRY - Computer system registry management.\r\r\nSCSICONTROLLER - SCSI Controller management. \r\r\nSERVER - Server information management. \r\r\nSERVICE - Service application management. \r\r\nSHADOWCOPY - Shadow copy management.\r\r\nSHADOWSTORAGE - Shadow copy storage area management.\r\r\nSHARE - Shared resource management. \r\r\nSOFTWAREELEMENT - Management of the elements of a software product installed on a system.\r\r\nSOFTWAREFEATURE - Management of software product subsets of SoftwareElement. \r\r\nSOUNDDEV - Sound Device management.\r\r\nSTARTUP - Management of commands that run automatically when users log onto the computer system.\r\r\nSYSACCOUNT - System account management. \r\r\nSYSDRIVER - Management of the system driver for a base service.\r\r\nSYSTEMENCLOSURE - Physical system enclosure management.\r\r\nSYSTEMSLOT - Management of physical connection points including ports, slots and peripherals, and proprietary connections points.\r\r\nTAPEDRIVE - Tape drive management. \r\r\nTEMPERATURE - Data management of a temperature sensor (electronic thermometer).\r\r\nTIMEZONE - Time zone data management. \r\r\nUPS - Uninterruptible power supply (UPS) management. \r\r\nUSERACCOUNT - User account management.\r\r\nVOLTAGE - Voltage sensor (electronic voltmeter) data management.\r\r\nVOLUME - Local storage volume management.\r\r\nVOLUMEQUOTASETTING - Associates the disk quota setting with a specific disk volume. \r\r\nVOLUMEUSERQUOTA - Per user storage volume quota management.\r\r\nWMISET - WMI service operational parameters management. \r\r\n\r\r\nFor more information on a specific alias, type: alias /?\r\r\n\r\r\nCLASS - Escapes to full WMI schema.\r\r\nPATH - Escapes to full WMI object paths.\r\r\nCONTEXT - Displays the state of all the global switches.\r\r\nQUIT/EXIT - Exits the program.\r\r\n\r\r\nFor more information on CLASS/PATH/CONTEXT, type: (CLASS | PATH | CONTEXT) /?\r\r\n\r\r\n", "error": "help - Alias not found.\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\wbem\\WMIC.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "WmiPrvSE.exe-60FF40CFD7FB8FE41EE4FE9AE5FE1C51": { "file_name": "WmiPrvSE.exe", "file_path": "C:\\Windows\\system32\\wbem\\WmiPrvSE.exe", "hash_md5": "60FF40CFD7FB8FE41EE4FE9AE5FE1C51", "hash_sha1": "3EA7CC066317AC45F963C2227C4C7C50AA16EB7C", "hash_sha256": "2198A7B58BCCB758036B969DDAE6CC2ECE07565E2659A7C541A313A0492231A3", "hash_sha384": "2C35968B61058B913E26F050AF04C9DFB05E319C0D081F2A3F9D940D2DF855C915FF351BDC2B04C10496814A0E534659", "hash_sha512": "991E38E2B480FFC58EC5ADE9DCC8747A57B29FBC9B12397A8010E73143C4DFB420E5248A0C3ACF0832812C0E804080ED5A83952B9C05419D93763372ECE775C3", "hash_ssdeep": "12288:ahBzXzR4mnIu0CWQjONc3XmvzjnyBEIl/t8:qumnGDjnyBll/", "hash_imp": "B71CB3AC5C352BEC857C940CBC95F0F3", "hash_pesha1": "27488A4F4D0FB889F5BCDF2D70CB02CA7CF9FA07", "hash_pe256": "415006C376C01C74875D9CFA1ECA0D365A67E186399CDFFA1E7C05A6B2080BDF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Provider Host", "meta_original_filename": "Wmiprvse.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wbem\\WmiPrvSE.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\wbem\\FastProx.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\NCObjAPI.DLL", "C:\\Windows\\SYSTEM32\\wbemcomn.dll" ] }, "FaceFodUninstaller.exe-0B570A6EA529F1D20DDB4C1C216A1AB7": { "file_name": "FaceFodUninstaller.exe", "file_path": "C:\\Windows\\system32\\WinBioPlugIns\\FaceFodUninstaller.exe", "hash_md5": "0B570A6EA529F1D20DDB4C1C216A1AB7", "hash_sha1": "5133E35FB2B8767FBBA0329FD5E8A4F116FEC186", "hash_sha256": "8E49B01AA269866E471090B95ED9C2AA009DF768FF3B9463FF732BCD775D144F", "hash_sha384": "92EEC89454658FA0A5A90CD8264171997395FF586729B212CD34639C641E4644E95DC1A8DA7D581DB3D3D2A96B7C3BC3", "hash_sha512": "FCAF18D6057A9874DA9278709733263884C1F2D8AF39AE0BFFD3A4FD6C363A1B6C4EA1B51E7D72AF4AE757AB74E80047031BE4F10B3297A6C4E35A8C6B469A89", "hash_ssdeep": "6144:JVHh3Y8C9WT9jbM6lRvkkSvzi61+lhFyUH6he5ai5nOSrvCumYI4sws2wWs1B:JHUWhXZFSvzonyUHl5aCOSrv1mt4sQ", "hash_imp": "5552BDFD4F73C12A92B1D77FEFE3BB20", "hash_pesha1": "483ED361A332D5ECBFA2BE3CE83C561356D0AA8C", "hash_pe256": "D62885708AAC32A77F67D8DDEE602E97A213E6694CFBEFA83F20416288524085", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8e49b01aa269866e471090b95ed9c2aa009df768ff3b9463ff732bcd775d144f/detection", "runtime_modules": [ "C:\\Windows\\system32\\WinBioPlugIns\\FaceFodUninstaller.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\WTSAPI32.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "powershell.exe-04029E121A0CFA5991749937DD22A1D9": { "file_name": "powershell.exe", "file_path": "C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\powershell.exe", "hash_md5": "04029E121A0CFA5991749937DD22A1D9", "hash_sha1": "F43D9BB316E30AE1A3494AC5B0624F6BEA1BF054", "hash_sha256": "9F914D42706FE215501044ACD85A32D58AAEF1419D404FDDFA5D3B48F66CCD9F", "hash_sha384": "13BE484F0CBE81E41D98B78ECE5EC7D7434C3AEEFDD37A4094D5D53F4119BF059C758647AC224BF7A7625C00435AFA1A", "hash_sha512": "6A2FB055473033FD8FDB8868823442875B5B60C115031AAEDA688A35A092F6278E8687E2AE2B8DC097F8F3F35D23959757BF0C408274A2EF5F40DDFA4B5C851B", "hash_ssdeep": "6144:r2fdXxswSX0z/YWwO9sV1yZywi/PzNKXzJ7BapCK5d3klRzULOnWyjLsPhAQzqO:qVXqXEgW2KXzJ4pdd3klnnWosPhnzq", "hash_imp": "7C955A0ABC747F57CCC4324480737EF7", "hash_pesha1": "C4D242121640421297003F028AA3B8C6BECAB131", "hash_pe256": "BAC613D793971F156BA846F8B1C1ABF6A635309EA32BD9258CD2AA1E1CD8C51E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows PowerShell", "meta_original_filename": "PowerShell.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/9f914d42706fe215501044acd85a32d58aaef1419d404fddfa5d3b48f66ccd9f/detection", "output": "\r\nPowerShell[.exe] [-PSConsoleFile <file> | -Version <version>]\r\n [-NoLogo] [-NoExit] [-Sta] [-Mta] [-NoProfile] [-NonInteractive]\r\n [-InputFormat {Text | XML}] [-OutputFormat {Text | XML}]\r\n [-WindowStyle <style>] [-EncodedCommand <Base64EncodedCommand>]\r\n [-ConfigurationName <string>]\r\n [-File <filePath> <args>] [-ExecutionPolicy <ExecutionPolicy>]\r\n [-Command { - | <script-block> [-args <arg-array>]\r\n | <string> [<CommandParameters>] } ]\r\n\r\nPowerShell[.exe] -Help | -? | /?\r\n\r\n-PSConsoleFile\r\n Loads the specified Windows PowerShell console file. To create a console\r\n file, use Export-Console in Windows PowerShell.\r\n\r\n-Version\r\n Starts the specified version of Windows PowerShell. \r\n Enter a version number with the parameter, such as \"-version 2.0\".\r\n\r\n-NoLogo\r\n Hides the copyright banner at startup.\r\n\r\n-NoExit\r\n Does not exit after running startup commands.\r\n\r\n-Sta\r\n Starts the shell using a single-threaded apartment.\r\n Single-threaded apartment (STA) is the default.\r\n\r\n-Mta\r\n Start the shell using a multithreaded apartment.\r\n\r\n-NoProfile\r\n Does not load the Windows PowerShell profile.\r\n\r\n-NonInteractive\r\n Does not present an interactive prompt to the user.\r\n\r\n-InputFormat\r\n Describes the format of data sent to Windows PowerShell. Valid values are\r\n \"Text\" (text strings) or \"XML\" (serialized CLIXML format).\r\n\r\n-OutputFormat\r\n Determines how output from Windows PowerShell is formatted. Valid values\r\n are \"Text\" (text strings) or \"XML\" (serialized CLIXML format).\r\n\r\n-WindowStyle\r\n Sets the window style to Normal, Minimized, Maximized or Hidden.\r\n\r\n-EncodedCommand\r\n Accepts a base-64-encoded string version of a command. Use this parameter \r\n to submit commands to Windows PowerShell that require complex quotation \r\n marks or curly braces.\r\n\r\n-ConfigurationName\r\n Specifies a configuration endpoint in which Windows PowerShell is run.\r\n This can be any endpoint registered on the local machine including the\r\n default Windows PowerShell remoting endpoints or a custom endpoint having\r\n specific user role capabilities.\r\n \r\n-File\r\n Runs the specified script in the local scope (\"dot-sourced\"), so that the \r\n functions and variables that the script creates are available in the \r\n current session. Enter the script file path and any parameters. \r\n File must be the last parameter in the command, because all characters \r\n typed after the File parameter name are interpreted \r\n as the script file path followed by the script parameters.\r\n\r\n-ExecutionPolicy\r\n Sets the default execution policy for the current session and saves it \r\n in the $env:PSExecutionPolicyPreference environment variable. \r\n This parameter does not change the Windows PowerShell execution policy \r\n that is set in the registry.\r\n\r\n-Command\r\n Executes the specified commands (and any parameters) as though they were\r\n typed at the Windows PowerShell command prompt, and then exits, unless \r\n NoExit is specified. The value of Command can be \"-\", a string. or a\r\n script block.\r\n\r\n If the value of Command is \"-\", the command text is read from standard\r\n input.\r\n\r\n If the value of Command is a script block, the script block must be enclosed\r\n in braces ({}). You can specify a script block only when running PowerShell.exe\r\n in Windows PowerShell. The results of the script block are returned to the\r\n parent shell as deserialized XML objects, not live objects.\r\n\r\n If the value of Command is a string, Command must be the last parameter\r\n in the command , because any characters typed after the command are \r\n interpreted as the command arguments.\r\n\r\n To write a string that runs a Windows PowerShell command, use the format:\r\n\t\"& {<command>}\"\r\n where the quotation marks indicate a string and the invoke operator (&)\r\n causes the command to be executed.\r\n\r\n-Help, -?, /?\r\n Shows this message. If you are typing a PowerShell.exe command in Windows\r\n PowerShell, prepend the command parameters with a hyphen (-), not a forward\r\n slash (/). You can use either a hyphen or forward slash in Cmd.exe.\r\n\r\nEXAMPLES\r\n PowerShell -PSConsoleFile SqlSnapIn.Psc1\r\n PowerShell -version 2.0 -NoLogo -InputFormat text -OutputFormat XML\r\n PowerShell -ConfigurationName AdminRoles\r\n PowerShell -Command {Get-EventLog -LogName security}\r\n PowerShell -Command \"& {Get-EventLog -LogName security}\"\r\n\r\n # To use the -EncodedCommand parameter:\r\n $command = 'dir \"c:\\program files\" '\r\n $bytes = [System.Text.Encoding]::Unicode.GetBytes($command)\r\n $encodedCommand = [Convert]::ToBase64String($bytes)\r\n powershell.exe -encodedCommand $encodedCommand\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\en-US\\powershell.exe.mui": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4480": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.ConsoleHost\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.ConsoleHost.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Management.Automation\\v4.0_3.0.0.0__31bf3856ad364e35\\System.Management.Automation.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Core\\v4.0_4.0.0.0__b77a5c561934e089\\System.Core.dll": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.Management.Infrastructure\\v4.0_1.0.0.0__31bf3856ad364e35\\Microsoft.Management.Infrastructure.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Numerics\\v4.0_4.0.0.0__b77a5c561934e089\\System.Numerics.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.DirectoryServices\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.DirectoryServices.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Management\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Management.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\System.Data\\v4.0_4.0.0.0__b77a5c561934e089\\System.Data.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.Security\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.Security.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\System.Transactions\\v4.0_4.0.0.0__b77a5c561934e089\\System.Transactions.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "error": "At line:1 char:3\r\n+ --help\r\n+ ~\r\nMissing expression after unary operator '--'.\r\nAt line:1 char:3\r\n+ --help\r\n+ ~~~~\r\nUnexpected token 'help' in expression or statement.\r\n + CategoryInfo : ParserError: (:) [], ParentContainsErrorRecordException\r\n + FullyQualifiedErrorId : MissingExpressionAfterOperator\r\n \r\n", "runtime_modules": [ "C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\powershell.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "powershell_ise.exe-E05920670516CC96822699E5688A79FA": { "file_name": "powershell_ise.exe", "file_path": "C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\powershell_ise.exe", "hash_md5": "E05920670516CC96822699E5688A79FA", "hash_sha1": "5F2596B6C147E13A32C7D73EF1C1365BA0171687", "hash_sha256": "1172951D8B1AA4CF9D0AC9F72AE344C5896CE4286C790A1F0DFF8A6F71A5772E", "hash_sha384": "4760816D7369B8DF66C185EC0FCC3DE3361FFDA65CA0F65767DDD7BD9EC837373FB68E34624399C2023F60F54A7519D6", "hash_sha512": "1C47B24D04104D0E7291D09AB6DAD2C0433CA4FFA947A051A73159A986A0C0E8634B3701153E54E7D96364F80407E9FCC6D5EB8A9C34D8EA35B86780211F9CFD", "hash_ssdeep": "3072:zfkVjGPsw40aLkVjqP4w6U+ToIuWNXmmZTWl/jC7gDooMLdx:zkTuZToIuUXmmZbgDooMb", "hash_imp": "n/a", "hash_pesha1": "6DA0DD4D97E6BB31D3098BEDE5C5F055A87F0A90", "hash_pe256": "30E126A34BB6E9D83642D47C4B21D9154A9CE063C5BD2E8EBD1747B42D3731CE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows PowerShell ISE", "meta_original_filename": "powershell_ise.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1172951d8b1aa4cf9d0ac9f72ae344c5896ce4286c790a1f0dff8a6f71a5772e/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4644": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.ISECommon\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.ISECommon.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Management.Automation\\v4.0_3.0.0.0__31bf3856ad364e35\\System.Management.Automation.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Core\\v4.0_4.0.0.0__b77a5c561934e089\\System.Core.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\powershell_ise.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ], "runtime_window_title": "Windows PowerShell ISE" }, "agentactivationruntimestarter.exe-E556115BD4E751178310F842E457CA22": { "file_name": "agentactivationruntimestarter.exe", "file_path": "C:\\Windows\\SysWOW64\\agentactivationruntimestarter.exe", "hash_md5": "E556115BD4E751178310F842E457CA22", "hash_sha1": "0858A3B566FF22C1A8116220875A3207BA0E0644", "hash_sha256": "012F3E214D405D03AEFA0D407FDAAB35B53A7A8E549AE5AA85E3BFD355AF65F1", "hash_sha384": "70DEFEF4B0507505713DA909CBCBBF2CD3EB45B4CC40C88EA3A68E3C608EE26B8383F0474098FF274284CAAAC07302EF", "hash_sha512": "009726FED7B38E13C3FB7C2D499C97C5D6E6D82DD38B64ADA8A2D25ACD2DF23B19E5DB599F78C6001648519D0BBF52B342CF2E6104F209404982C40762B34637", "hash_ssdeep": "192:XSs00YAq7lyttXwJcPqT/0WlygTMf5ZmlE96UTQj:XStb/7lyMcPqr0AyjGlUT", "hash_imp": "C92464C94895CEE3BD3869E057DA0432", "hash_pesha1": "59C7542A1C85BBFA38ADAC41EFC4C7409000DDF7", "hash_pe256": "EC3B34E47333AA63C795C3BB62C8C804F62A851B59EDBBD62B804D84650358F3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/012f3e214d405d03aefa0d407fdaab35b53a7a8e549ae5aa85e3bfd355af65f1/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\agentactivationruntimestarter.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "appidtel.exe-A5DF3FC61AD6CAE971D58F5C8C0F4D27": { "file_name": "appidtel.exe", "file_path": "C:\\Windows\\SysWOW64\\appidtel.exe", "hash_md5": "A5DF3FC61AD6CAE971D58F5C8C0F4D27", "hash_sha1": "D1F1C9C97959A4CF27565CC6CAB48232518C0B3E", "hash_sha256": "24A53FDB11310D8E797729C90600AE694A49EAD6C4B277110662028A11F946BE", "hash_sha384": "9CC2B9D1ACEE64A55E6BD6E74CA0456740E49AC3C85C038D1C03638AC0CD80A0B0DF44DEDE7FA13CFACB9B9A4BCD39E2", "hash_sha512": "275E43E3BF2AFECED87C3AD9FD022D13C0233A70F1E6F6676573940C4F933422F280226DEB112CCDB0BE9D49A842CC9C8C7B14339CD49988BD293ECF82EC2624", "hash_ssdeep": "384:XlRT3esKmxpIJkkRwZycsNdFy3kEk/sQDTYgr214RwpWsdsW:1JOlUpY0ZmNdFEQDTS146B", "hash_imp": "45B4E0F623405C276E4DA9F4816C57F0", "hash_pesha1": "A4B7B04F18FBCDC1F9D13BB938B06CEC6BEFBA19", "hash_pe256": "80BBB002D7790F42DF1111CFC20963E47036FF9B3F7B6DA2E562DE07419F7DC4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Initializes Appid ManagedInstaller and Smartscreen Telemetry", "meta_original_filename": "APPIDTEL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/24a53fdb11310d8e797729c90600ae694a49ead6c4b277110662028a11f946be/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\appidtel.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ARP.EXE-4D3943EDBC9C7E18DC3469A21B30B3CE": { "file_name": "ARP.EXE", "file_path": "C:\\Windows\\SysWOW64\\ARP.EXE", "hash_md5": "4D3943EDBC9C7E18DC3469A21B30B3CE", "hash_sha1": "534A42A7045ED26D11D00721A9542CACA7F2B4EF", "hash_sha256": "F9C384659E3C66FB0AF5F18D19A16AE11910AEFD3BEAFE2170F937FD521E0391", "hash_sha384": "E58AD4054E6BBF6C22A14A3C548EC5E0E21DCBCF22B776FBF60C86A6B3DCE1794CBE552773CA00CBBF8CF6F676F12B24", "hash_sha512": "5D2BB83308C3D0612DE54451B6852C61774DFC05904FA5F4B1160E044CFC5D63151F5821F6A970DBD399C28F75868B0933B7A60B2016DF68EDC40AF85183EFE2", "hash_ssdeep": "384:wWh7jqKlUDy3Xm0s5bF5r5ymHBISmmGtjPx5IWS9mWM0:wWh7j7LHmJj/ymHCltjZ5c", "hash_imp": "7B5BE93B3EE823A6C20B62AEBA53062F", "hash_pesha1": "54A1F3FE82198EC437BD9B135FF0ED1FA223D2CE", "hash_pe256": "AEE01415E70A49BF64EB532BC782F8D10D9BB48B798D26EC9F8016117FEF95A4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Arp Command", "meta_original_filename": "arp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f9c384659e3c66fb0af5f18d19a16ae11910aefd3beafe2170f937fd521e0391/detection", "output": "\r\nDisplays and modifies the IP-to-Physical address translation tables used by\r\naddress resolution protocol (ARP).\r\n\r\nARP -s inet_addr eth_addr [if_addr]\r\nARP -d inet_addr [if_addr]\r\nARP -a [inet_addr] [-N if_addr] [-v]\r\n\r\n -a Displays current ARP entries by interrogating the current\r\n protocol data. If inet_addr is specified, the IP and Physical\r\n addresses for only the specified computer are displayed. If\r\n more than one network interface uses ARP, entries for each ARP\r\n table are displayed.\r\n -g Same as -a.\r\n -v Displays current ARP entries in verbose mode. All invalid \r\n entries and entries on the loop-back interface will be shown.\r\n inet_addr Specifies an internet address.\r\n -N if_addr Displays the ARP entries for the network interface specified\r\n by if_addr.\r\n -d Deletes the host specified by inet_addr. inet_addr may be \r\n wildcarded with * to delete all hosts.\r\n -s Adds the host and associates the Internet address inet_addr\r\n with the Physical address eth_addr. The Physical address is\r\n given as 6 hexadecimal bytes separated by hyphens. The entry\r\n is permanent.\r\n eth_addr Specifies a physical address.\r\n if_addr If present, this specifies the Internet address of the\r\n interface whose address translation table should be modified.\r\n If not present, the first applicable interface will be used.\r\nExample:\r\n > arp -s 157.55.85.212 00-aa-00-62-c6-09 .... Adds a static entry.\r\n > arp -a .... Displays the arp table.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ARP.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "at.exe-2AE20048111861FA09B709D3CC551AD6": { "file_name": "at.exe", "file_path": "C:\\Windows\\SysWOW64\\at.exe", "hash_md5": "2AE20048111861FA09B709D3CC551AD6", "hash_sha1": "63DB5BEA03C9924DF8EC497DAC03F41AF582565B", "hash_sha256": "C27460533B663278C2C03CD85384AA2560BC4A8FFA6D7160B070F8BE62839145", "hash_sha384": "D72D887DDF6474BE365260AED388C040478EC2CF99235B71F9C00EEFB24D4983AF2F58822A92EC2427D24185AFEF5208", "hash_sha512": "772BB06A670B5A0B7F732D6A4FD38BD9DFCA1E3A705388B3E6D6B37C90C91F907266B7CB10894F0B9798772DA929211D6B688DA30B52EE5F7F14683B260ABE8E", "hash_ssdeep": "384:ROnToZKLrisNpN/mSBJtWh/1yyEatn7lwUcHc/f5wpnJ7vHWwwWl:RymKisNpA0tWhfwV8/BknJ7r", "hash_imp": "D5E405DA642D875E6A1BC0F575104CE1", "hash_pesha1": "0D9F164BB8A23C20EE28A5EF8BF6B06953783804", "hash_pe256": "8EB5E4B7517E84B11FC7DB130552965E0822C13BAE9AE8D111A5665B565DE470", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Schedule service command line interface", "meta_original_filename": "AT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c27460533b663278c2c03cd85384aa2560bc4a8ffa6d7160b070f8be62839145/detection", "children": "explorer.exe", "output": "The AT command has been deprecated. Please use schtasks.exe instead.\r\n\r\nInvalid command.\r\n\r\nThe AT command schedules commands and programs to run on a computer at \r\na specified time and date. The Schedule service must be running to use \r\nthe AT command.\r\n \r\nAT [\\\\computername] [ [id] [/DELETE] | /DELETE [/YES]] \r\nAT [\\\\computername] time [/INTERACTIVE]\r\n [ /EVERY:date[,...] | /NEXT:date[,...]] \"command\"\r\n\r\n\\\\computername Specifies a remote computer. Commands are scheduled on the\r\n local computer if this parameter is omitted. \r\nid Is an identification number assigned to a scheduled \r\n command. \r\n/delete Cancels a scheduled command. If id is omitted, all the\r\n scheduled commands on the computer are canceled.\r\n/yes Used with cancel all jobs command when no further\r\n confirmation is desired.\r\ntime Specifies the time when command is to run.\r\n/interactive Allows the job to interact with the desktop of the user \r\n who is logged on at the time the job runs.\r\n/every:date[,...] Runs the command on each specified day(s) of the week or\r\n month. If date is omitted, the current day of the month\r\n is assumed. \r\n/next:date[,...] Runs the specified command on the next occurrence of the\r\n day (for example, next Thursday). If date is omitted, the\r\n current day of the month is assumed.\r\n\"command\" Is the Windows NT command, or batch program to be run.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\at.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "AtBroker.exe-F3E6149FFBD29CC3FB4B975224AB4FCF": { "file_name": "AtBroker.exe", "file_path": "C:\\Windows\\SysWOW64\\AtBroker.exe", "hash_md5": "F3E6149FFBD29CC3FB4B975224AB4FCF", "hash_sha1": "C7FE62899CB337DCF9CFF0DEA6A3ADF61E2AE222", "hash_sha256": "CDC2B0207769F3F73BBF068EFF68661D145909B410F2C25FBFA5A38D4AAD464C", "hash_sha384": "C2FA89F85BC8F97CB849DF018B3F31BAFBC00858D743EBE70DBA3973558FAA14C37E66BDF468C8C9016976A636FCF272", "hash_sha512": "6D525914332227099ED2ED7AA2B218CCB7FA2EA49CABD1E8334299222A368FD48B609FD5DD5B2C8F4287D3193507433A4DE7B98A0184512B23A3BBB56FC97F98", "hash_ssdeep": "1536:RMa9OziOF0JbOKal+DmJTTc3vL9GSDNhGEiL:x9+iQ+InM8SxhGEiL", "hash_imp": "20DD334D18ED22744B3C9C88AA5E4B64", "hash_pesha1": "1386A9F338AABE60B7BFF2BC4F47924B33B71171", "hash_pe256": "E3B7A03787C199047AF77C94CCD9775E4B5BFA60FCA2F4DEAC9D1FEB1DCB6282", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Assistive Technology Manager", "meta_original_filename": "ATBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/cdc2b0207769f3f73bbf068eff68661d145909b410f2c25fbfa5a38d4aad464c/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\AtBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "attrib.exe-0E938DD280E83B1596EC6AA48729C2B0": { "file_name": "attrib.exe", "file_path": "C:\\Windows\\SysWOW64\\attrib.exe", "hash_md5": "0E938DD280E83B1596EC6AA48729C2B0", "hash_sha1": "831EF11DA10DE2706EF6920D58CB3CC145148B27", "hash_sha256": "1DD136CD5B90C2ABC4F163429A99ED32A7D4B047407DF45D96E20130F8B14920", "hash_sha384": "D88AAE456106BFBA204A09811B5174986EF7B58BB9EAE5A85258D3C6334624B29C1C1A962B7884D1D69AE4137330A220", "hash_sha512": "5DF2F8157AA0EA3C32ECE1041DD4B31A6AE915E17223B7C5A14AF403023945F83AC41A872D0883684735C166150AA65A205344D6163443A5CEDAF4CB546C9D40", "hash_ssdeep": "384:mnfAhEVYUnsthqUHFOQw61Z8EI/5fw3WjtWEBw:mn4hEC1vqUHVO5fwQdK", "hash_imp": "F0A82FEBA5B0EF2BE614622AE3E32C1C", "hash_pesha1": "E7D6EF1C3AEDE4303A8C10728B3CB58400650472", "hash_pe256": "7158B349B67B87161BE1CF5D048DC9863DB8DB974298BB7559EB2F6A289D4FBC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Attribute Utility", "meta_original_filename": "ATTRIB.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1dd136cd5b90c2abc4f163429a99ed32a7d4b047407df45d96e20130f8b14920/detection", "output": "Displays or changes file attributes.\r\n\r\nATTRIB [+R | -R] [+A | -A] [+S | -S] [+H | -H] [+O | -O] [+I | -I] [+X | -X] [+P | -P] [+U | -U]\r\n [drive:][path][filename] [/S [/D]] [/L]\r\n\r\n + Sets an attribute.\r\n - Clears an attribute.\r\n R Read-only file attribute.\r\n A Archive file attribute.\r\n S System file attribute.\r\n H Hidden file attribute.\r\n O Offline attribute.\r\n I Not content indexed file attribute.\r\n X No scrub file attribute.\r\n V Integrity attribute.\r\n P Pinned attribute.\r\n U Unpinned attribute.\r\n B SMR Blob attribute.\r\n [drive:][path][filename]\r\n Specifies a file or files for attrib to process.\r\n /S Processes matching files in the current folder\r\n and all subfolders.\r\n /D Processes folders as well.\r\n /L Work on the attributes of the Symbolic Link versus\r\n the target of the Symbolic Link\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\attrib.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "auditpol.exe-70DF7973F8D4AAA2EE3B28391239397B": { "file_name": "auditpol.exe", "file_path": "C:\\Windows\\SysWOW64\\auditpol.exe", "hash_md5": "70DF7973F8D4AAA2EE3B28391239397B", "hash_sha1": "970FA2222ED1BBDCC9D42D41FCE25DEC09DC9A42", "hash_sha256": "92274459D15DD69E20598F5CE54933635C2BD916CA2B0A039F96BE782FAC1CA6", "hash_sha384": "59588232DB9B802EB18BEA042FD7D544180665F1A11E3870C5714CF4E8D7EA262737EE02D833242A0462710F6CB0A5EC", "hash_sha512": "AA63C38FEE0EF17170E3F242E0E12A9AE5F23A93E375A1FBCFA4C14E886B422DB93B1F689D47ABA289B20CBF0AD62D0F5466EE366AB643E94EB7BC89B353CA28", "hash_ssdeep": "768:YF76lUgEsRF057jvykFalDtqQ4pd5w2NOEa:me+MRi7W+ADtqQ4X5w2NOEa", "hash_imp": "0C4B99BEEA5B3B9367B087A10A48BD92", "hash_pesha1": "45313280692ADEC67D894F207E3DB57A3F23E283", "hash_pe256": "BDCBA7026A7729DFFCA9A7B7A08EF9798F6C4B3A36223D4A62F1EBB858948028", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Audit Policy Program", "meta_original_filename": "AUDITPOL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/92274459d15dd69e20598f5ce54933635c2bd916ca2b0a039f96be782fac1ca6/detection", "output": "Usage: AuditPol command [<sub-command><options>]\r\r\n\r\r\n\r\r\nCommands (only one command permitted per execution)\r\r\n /? Help (context-sensitive)\r\r\n /get Displays the current audit policy.\r\r\n /set Sets the audit policy.\r\r\n /list Displays selectable policy elements.\r\r\n /backup Saves the audit policy to a file.\r\r\n /restore Restores the audit policy from a file.\r\r\n /clear Clears the audit policy.\r\r\n /remove Removes the per-user audit policy for a user account.\r\r\n /resourceSACL Configure global resource SACLs\r\r\n\r\r\n\r\r\nUse AuditPol <command> /? for details on each command\r\r\n", "error": "Error 0x00000057 occurred:\r\r\nThe parameter is incorrect.\r\r\n\r\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\auditpol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "autochk.exe-2B05C1F6DF12F60D409462923279F4CD": { "file_name": "autochk.exe", "file_path": "C:\\Windows\\SysWOW64\\autochk.exe", "hash_md5": "2B05C1F6DF12F60D409462923279F4CD", "hash_sha1": "74A5BCCB37FF7379B5960789BF5C26E9F42B39F0", "hash_sha256": "ACFC3B040A0D403789C702B13A106C1189DF34C5AD1751D0BFECF8CDD8F291C3", "hash_sha384": "2FF7B60C87CF5A68EC64FF444DD173C7868A389347D9203B0111FF2D8745408635A226136E52A5B4F2C5E7DED972A823", "hash_sha512": "7E779F45F5DFA8D4A5940492F93C054A1082EA19D0944F21A3198C743E305F6525B53FB968DF7CE26B4CF55D404E0E0B85B4FB1EC52DC040B4083DC8CBE36195", "hash_ssdeep": "24576:8ZY5AZArjw5mnClqjrDzP0QrxnygjQVb:8OrlClSrDzcqnZsVb", "hash_imp": "93B24440FA49BA3DE72AFDF46CE6E972", "hash_pesha1": "3657A02973FF25FEE9542ECA73C3B94BC271F9F3", "hash_pe256": "524813A5F78E39BFBDE7A469E40A4C77AEF1B0862055CCD583721BD07C31F489", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto Check Utility", "meta_original_filename": "AutoChk.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/acfc3b040a0d403789c702b13a106c1189df34c5ad1751d0bfecf8cdd8f291c3/detection" }, "autoconv.exe-CF7A59C5DB3D8C2267D2CBB1CB3C8C83": { "file_name": "autoconv.exe", "file_path": "C:\\Windows\\SysWOW64\\autoconv.exe", "hash_md5": "CF7A59C5DB3D8C2267D2CBB1CB3C8C83", "hash_sha1": "3CA9E43C1B10A3695E3306DC12896FA5F8FEBA22", "hash_sha256": "86EE7446784D9AFBE3B44EC20825027BAA5D32A45D4EFAF137C360A102BEDC39", "hash_sha384": "115B3BA157FFB627FF847C66164F4326E45C3C19D3CD13D55B0C1678FA6FEE05947710948A7C86380794973F977C4BB6", "hash_sha512": "A250AB210640F685A21FB08B153E6F3F82E8DBAD84A2FB2F65F9E38CFB7991B79D55D5491D96B3AAF9DFD4479C8548BEA8B935E96E9FEA757B73423E9E96B49D", "hash_ssdeep": "24576:UAY+hdi0XCCQ9cFzELM7VOkKNjFUIGQ/Unp4xJbV:UkirnmxELMpOkKhNGQ/Q4xJb", "hash_imp": "5DF399086BF351F35499EE0E042BEE31", "hash_pesha1": "677924614F3857A803C3AE64286228104FA8A269", "hash_pe256": "0C9379D5DFD1F81539DF432A5B195C9374FF574003C747E32E4434E5B91F72FD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto File System Conversion Utility", "meta_original_filename": "AUTOCONV.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/86ee7446784d9afbe3b44ec20825027baa5d32a45d4efaf137c360a102bedc39/detection" }, "autofmt.exe-F011089C22922FA42DF321B4F3EC7591": { "file_name": "autofmt.exe", "file_path": "C:\\Windows\\SysWOW64\\autofmt.exe", "hash_md5": "F011089C22922FA42DF321B4F3EC7591", "hash_sha1": "33C890ED1B2E34D08EEAB56CB5A0FE65800E8F41", "hash_sha256": "06263E020A00AC0AB567C949E0E3B99270A1AB9A819A721BA8EB616D7B852AA2", "hash_sha384": "8D5ADEF549802E432D3BBF6FB0F512F1629CE16A4B11D20F21D88AE411AEAB78BAD341591C96C5DFE5DBB154C1AA3055", "hash_sha512": "373B7189CC41D1C9A5C674800BF8AAC14248650A8F2945EC720E91575BBAD7EA6D18D18A0D28C5F81D405D36392BC15073B4ED20FBCDC4022856D999C8F9BABC", "hash_ssdeep": "24576:ZxeyPLCVIWEj+5cS7RVd7KcyTDjyRfMzi5cb:Z+V0+WeRVd7K1m5M25cb", "hash_imp": "DEA42E92AA39B193CBF108D8F6BB53DA", "hash_pesha1": "47CF3C7B85A98D05EA75DE098F47A5CCB7C756C0", "hash_pe256": "AB2F38E9B6497DC87797B51BCA23CF3742B4B9CB439E2423C15EF8684F607D55", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto File System Format Utility", "meta_original_filename": "AUTOFMT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/06263e020a00ac0ab567c949e0e3b99270a1ab9a819a721ba8eb616d7b852aa2/detection" }, "backgroundTaskHost.exe-F290D12F0351B56708B3DF1EC26CB45B": { "file_name": "backgroundTaskHost.exe", "file_path": "C:\\Windows\\SysWOW64\\backgroundTaskHost.exe", "hash_md5": "F290D12F0351B56708B3DF1EC26CB45B", "hash_sha1": "8992D17CBE7275F69B8CABEE0EE6BCFBDD1B3596", "hash_sha256": "CD2BF90FE5CD57DC49AF50950C8CE3CFC6433CCE7B68FB20DFD78E30A865B134", "hash_sha384": "2AB41422D0E4942EE8227472D42B7E0A3F6BDA9929B240DAF6EE9835A0D7E2115CF7D096B001E1C1BB20CD5F8D1A7FBF", "hash_sha512": "918C3D82CA9E8386EF0BCAD06B5238DF9DC6E5F9C3B58EEFC0A10E90F1A3EEE613503281E31567FD498AFF439AE850CCACC6F0DD5EF23273FBA3AFBC5641EB13", "hash_ssdeep": "384:oLapnnorHWBWqGWhr6wDDBRJLrUJAl3qQBYJ:kknOHWbJr6wD1PLIuS", "hash_imp": "B01956F70C2FC1C81D9AF197F35D4D75", "hash_pesha1": "F2B4B70338939B44D86BC5D578C54DDE3BAF7D6C", "hash_pe256": "979EF31565289D7672F368247B466854F8A89F7432C51DE5F6DCADC69D9BE100", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Background Task Host", "meta_original_filename": "backgroundTaskHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/cd2bf90fe5cd57dc49af50950c8ce3cfc6433cce7b68fb20dfd78e30a865b134/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\backgroundTaskHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "BackgroundTransferHost.exe-1BE6B2C519B9E212265C30CBA6319B88": { "file_name": "BackgroundTransferHost.exe", "file_path": "C:\\Windows\\SysWOW64\\BackgroundTransferHost.exe", "hash_md5": "1BE6B2C519B9E212265C30CBA6319B88", "hash_sha1": "A59AC22F93C5CCBA8B9DD5EF1F0D649B4844AB14", "hash_sha256": "3D395FE2C562D0222CB77D89219685A22FF8ADA9FEC0D2B55D1E8137D864E8B1", "hash_sha384": "9FDD19CB4E429906E55F6781D72567E733E0FF5113112846DB54FEC28D5C401004DCEC9241C2CE1A3AF4AC5A38480A26", "hash_sha512": "EDA24CFD6522B703A68CCF1C6DDED793021674A35EE8E115F5735A4E374D99AFAD2276B5C0236721137EC05F2F906235463D127E6BC2F3FC113B676058EC8B6A", "hash_ssdeep": "384:bF4OfAVPLg4rv13S/nxspKMweBHW0ggWbQE0g7qW2RPT/8rFeZmJhu:hpIV04m1eB2T2a", "hash_imp": "2C84391D64B2AF34A9B9E60431B39091", "hash_pesha1": "E966BD328F228A56714305381E3F214084D162A3", "hash_pe256": "66E2FB49E8F1819B4CB05D54D8CCFF9F1EFBC301BD678C387552C1BBFC77765D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Download/Upload Host", "meta_original_filename": "BackgroundTransferHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3d395fe2c562d0222cb77d89219685a22ff8ada9fec0d2b55d1e8137d864e8b1/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\BackgroundTransferHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "bitsadmin.exe-F57A03FA0E654B393BB078D1C60695F3": { "file_name": "bitsadmin.exe", "file_path": "C:\\Windows\\SysWOW64\\bitsadmin.exe", "hash_md5": "F57A03FA0E654B393BB078D1C60695F3", "hash_sha1": "1CED6636BD2462C0F1B64775E1981D22AE57AF0B", "hash_sha256": "C93B7734470CF96C5170F7B21F361CDF3F74CA819626C83C4B8A68210DEEB35C", "hash_sha384": "1A9F75C72E24A1071B8AF3D09896CA86BF86779081DAC905A7F7F5B7E02FC098EFCCF2FAEC2521C6E22A36C52A1F1C9D", "hash_sha512": "7E84DD9A3E29523D25C0927424261CED908191E3151C9802B61FA3C5FE13D1192D19996CB435BB6D9BE5731B8370E8FFB6AD26A4BA0733E212A103EB0BD75A2A", "hash_ssdeep": "3072:845J3+Yf8tEONgW6YPdVI3f60nAufMGeCEC1Q0jon3YR:FWzPg3f3nNfiCf9cI", "hash_imp": "91F78CCC8BF8197765B0B6389F98B314", "hash_pesha1": "569D20AB8676AD62A5448FC98EC198922A72E7AD", "hash_pe256": "4DF20E37B76C1C69A22684E9B84CEE3F6B9F97CCC65BDDBED8E3F1DE0ADD5FD1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BITS administration utility", "meta_original_filename": "bitsadmin.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.8.19041.1 (WinBuild.160101.0800)", "meta_product_version": "7.8.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/c93b7734470cf96c5170f7b21f361cdf3f74ca819626c83c4b8a68210deeb35c/detection", "output": "\r\nBITSADMIN version 3.0\r\nBITS administration utility.\r\n(C) Copyright Microsoft Corp.\r\n\r\nInvalid command\r\nUSAGE: BITSADMIN [/RAWRETURN] [/WRAP | /NOWRAP] command\r\nThe following commands are available:\r\n\r\n/HELP Prints this help \r\n/? Prints this help \r\n/UTIL /? Prints the list of utilities commands \r\n/PEERCACHING /? Prints the list of commands to manage Peercaching\r\n/CACHE /? Prints the list of cache management commands \r\n/PEERS /? Prints the list of peer management commands\r\n\r\n/LIST [/ALLUSERS] [/VERBOSE] List the jobs\r\n/MONITOR [/ALLUSERS] [/REFRESH sec] Monitors the copy manager\r\n/RESET [/ALLUSERS] Deletes all jobs in the manager\r\n\r\n/TRANSFER <job name> [type] [/PRIORITY priority] [/ACLFLAGS flags] [/DYNAMIC] \r\n remote_url local_name\r\n Transfers one of more files.\r\n [type] may be /DOWNLOAD or /UPLOAD; default is download\r\n Multiple URL/file pairs may be specified.\r\n Unlike most commands, <job name> may only be a name and not a GUID.\r\n /DYNAMIC configures the job with BITS_JOB_PROPERTY_DYNAMIC_CONTENT, which relaxes the server-side requirements.\r\n\r\n/CREATE [type] <job name> Creates a job\r\n [type] may be /DOWNLOAD, /UPLOAD, or /UPLOAD-REPLY; default is download\r\n Unlike most commands, <job name> may only be a name and not a GUID.\r\n\r\n/INFO <job> [/VERBOSE] Displays information about the job\r\n/ADDFILE <job> <remote_url> <local_name> Adds a file to the job\r\n/ADDFILESET <job> <textfile> Adds multiple files to the job\r\n Each line of <textfile> lists a file's remote name and local name, separated\r\n by spaces. A line beginning with '#' is treated as a comment.\r\n Once the file set is read into memory, the contents are added to the job.\r\n\r\n/ADDFILEWITHRANGES <job> <remote_url> <local_name range_list>\r\n Like /ADDFILE, but BITS will read only selected byte ranges of the URL.\r\n range_list is a comma-delimited series of offset and length pairs.\r\n For example,\r\n\r\n 0:100,2000:100,5000:eof\r\n\r\n instructs BITS to read 100 bytes starting at offset zero, 100 bytes starting\r\n at offset 2000, and the remainder of the URL starting at offset 5000.\r\n\r\n/REPLACEREMOTEPREFIX <job> <old_prefix> <new_prefix>\r\n All files whose URL begins with <old_prefix> are changed to use <new_prefix>\r\n\r\nNote that BITS currently supports HTTP/HTTPS downloads and uploads.\r\nIt also supports UNC paths and file:// paths as URLS\r\n\r\n/LISTFILES <job> Lists the files in the job\r\n/SUSPEND <job> Suspends the job\r\n/RESUME <job> Resumes the job\r\n/CANCEL <job> Cancels the job\r\n/COMPLETE <job> Completes the job\r\n\r\n/GETTYPE <job> Retrieves the job type\r\n/GETACLFLAGS <job> Retrieves the ACL propagation flags\r\n\r\n/SETACLFLAGS <job> <ACL_flags> Sets the ACL propagation flags for the job\r\n O - OWNER G - GROUP \r\n D - DACL S - SACL \r\n\r\n Examples:\r\n bitsadmin /setaclflags MyJob OGDS\r\n bitsadmin /setaclflags MyJob OGD\r\n\r\n/GETBYTESTOTAL <job> Retrieves the size of the job\r\n/GETBYTESTRANSFERRED <job> Retrieves the number of bytes transferred\r\n/GETFILESTOTAL <job> Retrieves the number of files in the job\r\n/GETFILESTRANSFERRED <job> Retrieves the number of files transferred\r\n/GETCREATIONTIME <job> Retrieves the job creation time\r\n/GETMODIFICATIONTIME <job> Retrieves the job modification time\r\n/GETCOMPLETIONTIME <job> Retrieves the job completion time\r\n/GETSTATE <job> Retrieves the job state\r\n/GETERROR <job> Retrieves detailed error information\r\n/GETOWNER <job> Retrieves the job owner\r\n/GETDISPLAYNAME <job> Retrieves the job display name\r\n/SETDISPLAYNAME <job> <display_name> Sets the job display name\r\n/GETDESCRIPTION <job> Retrieves the job description\r\n/SETDESCRIPTION <job> <description> Sets the job description\r\n/GETPRIORITY <job> Retrieves the job priority\r\n/SETPRIORITY <job> <priority> Sets the job priority\r\n Priority usage choices:\r\n FOREGROUND \r\n HIGH\r\n NORMAL\r\n LOW\r\n/GETNOTIFYFLAGS <job> Retrieves the notify flags\r\n/SETNOTIFYFLAGS <job> <notify_flags> Sets the notify flags\r\n For more help on this option, please refer to the MSDN help page for SetNotifyFlags/GETNOTIFYINTERFACE <job> Determines if notify interface is registered\r\n/GETMINRETRYDELAY <job> Retrieves the retry delay in seconds\r\n/SETMINRETRYDELAY <job> <retry_delay> Sets the retry delay in seconds\r\n/GETNOPROGRESSTIMEOUT <job> Retrieves the no progress timeout in seconds\r\n/SETNOPROGRESSTIMEOUT <job> <timeout> Sets the no progress timeout in seconds\r\n/GETMAXDOWNLOADTIME <job> Retrieves the download timeout in seconds\r\n/SETMAXDOWNLOADTIME <job> <timeout> Sets the download timeout in seconds\r\n/GETERRORCOUNT <job> Retrieves an error count for the job\r\n\r\n/SETPROXYSETTINGS <job> <usage> Sets the proxy usage\r\n usage choices:\r\n PRECONFIG - Use the owner's default Internet settings.\r\n AUTODETECT - Force autodetection of proxy.\r\n NO_PROXY - Do not use a proxy server.\r\n OVERRIDE - Use an explicit proxy list and bypass list. \r\n Must be followed by a proxy list and a proxy bypass list.\r\n NULL or \"\" may be used for an empty proxy bypass list.\r\n Examples:\r\n bitsadmin /setproxysettings MyJob PRECONFIG\r\n bitsadmin /setproxysettings MyJob AUTODETECT\r\n bitsadmin /setproxysettings MyJob NO_PROXY\r\n bitsadmin /setproxysettings MyJob OVERRIDE proxy1:80 \"<local>\" \r\n bitsadmin /setproxysettings MyJob OVERRIDE proxy1,proxy2,proxy3 NULL \r\n\r\n/GETPROXYUSAGE <job> Retrieves the proxy usage setting\r\n/GETPROXYLIST <job> Retrieves the proxy list\r\n/GETPROXYBYPASSLIST <job> Retrieves the proxy bypass list\r\n\r\n/TAKEOWNERSHIP <job> Take ownership of the job\r\n\r\n/SETNOTIFYCMDLINE <job> <program_name> [program_parameters] \r\n Sets a program to execute for notification, and optionally parameters.\r\n The program name and parameters can be NULL.\r\n IMPORTANT: if parameters are non-NULL, then the program name should be the\r\n first parameter.\r\n\r\n Examples:\r\n bitsadmin /SetNotifyCmdLine MyJob c:\\winnt\\system32\\notepad.exe NULL\r\n bitsadmin /SetNotifyCmdLine MyJob c:\\callback.exe \"c:\\callback.exe parm1 parm2\" \r\n bitsadmin /SetNotifyCmdLine MyJob NULL NULL\r\n\r\n/GETNOTIFYCMDLINE <job> Returns the job's notification command line\r\n\r\n/SETCREDENTIALS <job> <target> <scheme> <username> <password>\r\n Adds credentials to a job.\r\n <target> may be either SERVER or PROXY\r\n <scheme> may be BASIC, DIGEST, NTLM, NEGOTIATE, or PASSPORT. \r\n\r\n/REMOVECREDENTIALS <job> <target> <scheme> \r\n Removes credentials from a job.\r\n/GETCUSTOMHEADERS <job> Gets the Custom HTTP Headers\r\n/SETCUSTOMHEADERS <job> <header1> <header2> <...> Sets the Custom HTTP Headers\r\n/MAKECUSTOMHEADERSWRITEONLY <job> Make a job's Custom HTTP Headers write-only (cannot be undone).\r\n\r\n/GETHTTPMETHOD <job> Gets the HTTP verb to use.\r\n/SETHTTPMETHOD <job> <HTTPMethod> Sets the HTTP verb to use.\r\n\r\n/GETCLIENTCERTIFICATE <job> Gets the job's Client Certificate Information\r\n/SETCLIENTCERTIFICATEBYID <job> <store_location> <store_name> <hexa-decimal_cert_id>\r\n Sets a client authentication certificate to a job.\r\n <store_location> may be \r\n\t1(CURRENT_USER), 2(LOCAL_MACHINE), 3(CURRENT_SERVICE),\r\n\t4(SERVICES), 5(USERS), 6(CURRENT_USER_GROUP_POLICY),\r\n\t7(LOCAL_MACHINE_GROUP_POLICY) or 8(LOCAL_MACHINE_ENTERPRISE). \r\n\r\n/SETCLIENTCERTIFICATEBYNAME <job> <store_location> <store_name> <subject_name>\r\n Sets a client authentication certificate to a job.\r\n <store_location> may be \r\n\t1(CURRENT_USER), 2(LOCAL_MACHINE), 3(CURRENT_SERVICE),\r\n\t4(SERVICES), 5(USERS), 6(CURRENT_USER_GROUP_POLICY),\r\n\t7(LOCAL_MACHINE_GROUP_POLICY) or 8(LOCAL_MACHINE_ENTERPRISE). \r\n\r\n/REMOVECLIENTCERTIFICATE <job> Removes the Client Certificate Information from the job\r\n\r\n/SETSECURITYFLAGS <job> <value> \r\n Sets the HTTP security flags for URL redirection and checks performed on the server certificate during the transfer.\r\n The value is an unsigned integer with the following interpretation for the bits in the binary representation.\r\n Enable CRL Check : Set the least significant bit\r\n Ignore invalid common name in server certificate : Set the 2nd bit from right\r\n Ignore invalid date in server certificate : Set the 3rd bit from right\r\n Ignore invalid certificate authority in server\r\n certificate : Set the 4th bit from right\r\n Ignore invalid usage of certificate : Set the 5th bit from right\r\n Redirection policy : Controlled by the 9th-11th bits from right\r\n 0,0,0 - Redirects will be automatically allowed.\r\n 0,0,1 - Remote name in the IBackgroundCopyFile interface will be updated if a redirect occurs.\r\n 0,1,0 - BITS will fail the job if a redirect occurs.\r\n\r\n Allow redirection from HTTPS to HTTP : Set the 12th bit from right\r\n\r\n/GETSECURITYFLAGS <job> \r\n Reports the HTTP security flags for URL redirection and checks performed on the server certificate during the transfer.\r\n\r\n/SETVALIDATIONSTATE <job> <file-index> <true|false>\r\n <file-index> starts from 0 \r\n Sets the content-validation state of the given file within the job.\r\n\r\n/GETVALIDATIONSTATE <job> <file-index> \r\n <file-index> starts from 0 \r\n Reports the content-validation state of the given file within the job.\r\n\r\n/GETTEMPORARYNAME <job> <file-index> \r\n <file-index> starts from 0 \r\n Reports the temporary filename of the given file within the job.\r\n\r\nThe following options control peercaching of a particular job:\r\n\r\n/SETPEERCACHINGFLAGS <job> <value> \r\n Sets the flags for the job's peercaching behavior.\r\n The value is an unsigned integer with the following interpretation for the bits in the binary representation.\r\n Allow the job's data to be downloaded from a peer : Set the least significant bit\r\n Allow the job's data to be served to peers : Set the 2nd bit from right\r\n\r\n/GETPEERCACHINGFLAGS <job> \r\n Reports the flags for the job's peercaching behavior.\r\n\r\nThe following options are valid for UPLOAD-REPLY jobs only:\r\n\r\n/GETREPLYFILENAME <job> Gets the path of the file containing the server reply\r\n/SETREPLYFILENAME <job> <path> Sets the path of the file containing the server reply\r\n/GETREPLYPROGRESS <job> Gets the size and progress of the server reply\r\n/GETREPLYDATA <job> Dumps the server's reply data in hex format\r\n\r\n/SETHELPERTOKEN <job> Sets the current command prompt's primary token as a job's helper token\r\n/GETHELPERTOKENSID <job> Reports the user account SID of a job's helper token, if one is set\r\n\r\n/SETHELPERTOKENFLAGS <job> <flags> \r\n Sets the helper token usage flags for a job. Possible values are:\r\n 1 - The helper token is used when accessing the local filesystem.\r\n 2 - The helper token is used when accessing the network.\r\n 3 - The helper token is used when accessing both the local filesystem and the network.\r\n\r\n/GETHELPERTOKENFLAGS <job> \r\n Reports a job's helper token usage flags.\r\n\r\n/GETPEERSTATS <job> <file-index> \r\n <file-index> starts from 0 \r\n Reports statistics about the amount of data downloaded from peers and origin servers for a specific file within a job.\r\n\r\nThe following options can be placed before the command:\r\n/RAWRETURN Return data more suitable for parsing\r\n/WRAP Wrap output around console (default)\r\n/NOWRAP Don't wrap output around console\r\n\r\nThe /RAWRETURN option strips new line characters and formatting.\r\nIt is recognized by the /CREATE and /GET* commands.\r\n\r\nCommands that take a <job> parameter will accept either a job name or a job ID\r\nGUID inside braces. BITSADMIN reports an error if a name is ambiguous.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\bitsadmin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "bootcfg.exe-A4F740C1E63ED13E9569D0E3AABA24B3": { "file_name": "bootcfg.exe", "file_path": "C:\\Windows\\SysWOW64\\bootcfg.exe", "hash_md5": "A4F740C1E63ED13E9569D0E3AABA24B3", "hash_sha1": "4720D0A3A64C3E337CDF545C5150DDC20033761A", "hash_sha256": "F45992F7D3602A41CFCBDA622C3E5F9F45AB2A4D19059BC746DA151ABAAAB140", "hash_sha384": "EA6BDCD4FA76B1AC4DB03052893DEA826BA960D60B706460C925379E064F927A7D33B2D58EF7C47D3C81D2955C1A6107", "hash_sha512": "036867916D63DF17F3F0204AEEC3BE8135C01CBBBCDCA0D87BC2464C6B0722D82503C9886A9A9CAEC93F56B8787E9565289AEAECBAA4264F11C1B8AE50186AEF", "hash_ssdeep": "1536:3a5QRGYct9JeOreQD+5c5CU+JjRfZSb+onFuwK72EwEUiFYIxAkUFa+pU76I:1GYct6Oio+5SEfZSb+6wwc8iFYIxLUFm", "hash_imp": "1326F3C4127B0B966C0872341E0A5A17", "hash_pesha1": "4AB37812F8DE6584B525F717A80ADB156597F347", "hash_pe256": "3D026553F75C6F59F470AFF4D99A71BBAE1CCA41C25AAB061F0122B5B45D5620", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BootCfg - Lists or changes the boot settings.", "meta_original_filename": "bootcfg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f45992f7d3602a41cfcbda622c3e5f9f45ab2a4d19059bc746da151abaaab140/detection", "output": "\r\nBOOTCFG /parameter [arguments]\r\n\r\nDescription:\r\n This command line tool can be used to configure, query, change or \r\n delete the boot entry settings in the BOOT.INI file.\r\n\r\nParameter List:\r\n /Copy Makes a copy of an existing boot entry.\r\n\r\n /Delete Deletes an existing boot entry from the BOOT.INI file.\r\n\r\n /Query Displays the current boot entries and their settings.\r\n\r\n /Raw Allows the user to specify any switch to be added.\r\n\r\n /Timeout Allows the user to change the Timeout value.\r\n\r\n /Default Allows the user to change the Default boot entry.\r\n\r\n /EMS Allows the user to configure the /redirect switch\r\n for headless support.\r\n\r\n /Debug Allows the user to specify the port and baudrate for \r\n remote debugging.\r\n\r\n /Addsw Allows the user to add predefined switches.\r\n\r\n /Rmsw Allows the user to remove predefined switches.\r\n\r\n /Dbg1394 Allows the user to configure 1394 port for debugging.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n BOOTCFG /Copy /?\r\n BOOTCFG /Delete /?\r\n BOOTCFG /Query /?\r\n BOOTCFG /Raw /?\r\n BOOTCFG /Timeout /?\r\n BOOTCFG /EMS /?\r\n BOOTCFG /Debug /?\r\n BOOTCFG /Addsw /?\r\n BOOTCFG /Rmsw /?\r\n BOOTCFG /Dbg1394 /?\r\n BOOTCFG /Default /?\r\n BOOTCFG /?\r\n\r\nWARNING: BOOT.INI is used for boot options on Windows XP and earlier\r\n operating systems. Use the BCDEDIT command line tool to modify\r\n Windows Vista boot options.\r\n", "error": "ERROR: Invalid syntax.\r\nType \"BOOTCFG /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\bootcfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "bthudtask.exe-45629A966631FE387396D2546BA58112": { "file_name": "bthudtask.exe", "file_path": "C:\\Windows\\SysWOW64\\bthudtask.exe", "hash_md5": "45629A966631FE387396D2546BA58112", "hash_sha1": "75668F50BD9830FAF3A4975C941CD659DCC504C1", "hash_sha256": "51CCC01F8565F17F1E8676EC3B7389D85753A9774B224F59D247BD349744E455", "hash_sha384": "73CC8F8A3A7778642F48441366C3B2E38E5FEDE28ACEC4F9483481632595C98A05B60093EDEDA48825B7BCB2199AA6D5", "hash_sha512": "22B91EA1E3D9E5C4DB93A430323C7FEEC5DC276221C56BC57B3D6C8DE6DACA329DD16B919A7F26C822EE633D2E1E2547413A0257B73F82A1DE8300FFEC369EE8", "hash_ssdeep": "384:csfYNIs7bDPUeEryOhZWWLHWpKJajXDO1/EagS817lL:csfY5DRtOhVkzDO", "hash_imp": "AB106F86DFB187B013004B44C843D3E8", "hash_pesha1": "BC9B51ED668546667F97B0C49A072BD373ABE78D", "hash_pe256": "FBA920562F64DCCA1004A19DB6CB05B01CFCDE5500CDEDD6E6373870CEBF1311", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Bluetooth Uninstall Device Task", "meta_original_filename": "BthUdTask.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/51ccc01f8565f17f1e8676ec3b7389d85753a9774b224f59d247bd349744e455/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\bthudtask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ByteCodeGenerator.exe-BFC129DE1873C84B5ACAFA85F145AEC6": { "file_name": "ByteCodeGenerator.exe", "file_path": "C:\\Windows\\SysWOW64\\ByteCodeGenerator.exe", "hash_md5": "BFC129DE1873C84B5ACAFA85F145AEC6", "hash_sha1": "78E1A3368F6F690DF2EA33966E68AEB6E9F3367A", "hash_sha256": "83A7DF7C45F6D7F39534DBDACD49EF8B49F9FA789578836D63B01252DDAD7161", "hash_sha384": "5198E4A695DD142F19AF63F10D3C6AA1E62BF10B02031BC0A8D7F820893B2F5A1CB7D8674279C89B326CD1277EE54F77", "hash_sha512": "DDCD64A6D43C9D1A01F0D7ACDE2E1358CF8078461473820D431085E59BB79E968CFA91AFE0146DF380D67F344A74FE344ABE6612ABA48DA9EDC75FC2DB0DF449", "hash_ssdeep": "1536:BCS4SRwzfcm90BILpc06FqibrehvhfMZT:uSRXGO06Ejnw", "hash_imp": "193F44574D84860F297AB441A1777671", "hash_pesha1": "E30E4AF9ABDB9BF5D5DC41AC0586C56A47CA4A21", "hash_pe256": "C368BA4F7E6A14604513D1F88930B12661A7071C3FABB663752D11C8C0067778", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AppX Deployment Bytecode Generator EXE", "meta_original_filename": "BytecodeGenerator.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/83a7df7c45f6d7f39534dbdacd49ef8b49f9fa789578836d63b01252ddad7161/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ByteCodeGenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cacls.exe-00BAAE10C69DAD58F169A3ED638D6C59": { "file_name": "cacls.exe", "file_path": "C:\\Windows\\SysWOW64\\cacls.exe", "hash_md5": "00BAAE10C69DAD58F169A3ED638D6C59", "hash_sha1": "C20D323DA2AC83D69472C316D1528174E2718DCE", "hash_sha256": "092C1FE176EF37703A9BEF4974CCF7DDD7A4D400FA37DCB04B721CCE0657B03A", "hash_sha384": "E120615332BF8982650F832248D77DBE3059D07245340D564AD6C25534D9025BBD6B65893C9E2DF0FF6B0CF745D6CDB3", "hash_sha512": "F669943E289419850F8D6B679734E1E9F2FB1384E5A0A57107CE7DCAB8B21030BE18C4CCB7FFB8A30FAB191B458CEC18B2E9CBB59A219C2940930E9BF2F82CF4", "hash_ssdeep": "384:TSCA340xYxnTHNb+jq3alMs/2XzZRERbTYxBs1rX5BFvZ/mi0DbGwNRNWsDWCAL7:A3402xnaqK2s/27ERTYu3QDbGwVzF", "hash_imp": "29323867CDC9A8BC7E9164C47C4E0B13", "hash_pesha1": "6DDA2773BC7DA7727BEA0645CF329D11B82B853F", "hash_pe256": "C771E5FC31760A953800930BF7E32FF885CCDA098131B614724315995F7323C9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Control ACLs Program", "meta_original_filename": "CACLS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/092c1fe176ef37703a9bef4974ccf7ddd7a4d400fa37dcb04b721cce0657b03a/detection", "output": "\r\r\n NOTE: Cacls is now deprecated, please use Icacls.\r\r\n\r\r\n Displays or modifies access control lists (ACLs) of files\r\r\n\r\r\n CACLS filename [/T] [/M] [/L] [/S[:SDDL]] [/E] [/C] [/G user:perm]\r\r\n [/R user [...]] [/P user:perm [...]] [/D user [...]]\r\r\n filename Displays ACLs.\r\r\n /T Changes ACLs of specified files in\r\r\n the current directory and all subdirectories.\r\r\n /L Work on the Symbolic Link itself versus the target\r\r\n /M Changes ACLs of volumes mounted to a directory\r\r\n /S Displays the SDDL string for the DACL.\r\r\n /S:SDDL Replaces the ACLs with those specified in the SDDL string\r\r\n (not valid with /E, /G, /R, /P, or /D).\r\r\n /E Edit ACL instead of replacing it.\r\r\n /C Continue on access denied errors.\r\r\n /G user:perm Grant specified user access rights.\r\r\n Perm can be: R Read\r\r\n W Write\r\r\n C Change (write)\r\r\n F Full control\r\r\n /R user Revoke specified user's access rights (only valid with /E).\r\r\n /P user:perm Replace specified user's access rights.\r\r\n Perm can be: N None\r\r\n R Read\r\r\n W Write\r\r\n C Change (write)\r\r\n F Full control\r\r\n /D user Deny specified user access.\r\r\n Wildcards can be used to specify more than one file in a command.\r\r\n You can specify more than one user in a command.\r\r\n\r\r\n Abbreviations:\r\r\n CI - Container Inherit.\r\r\n The ACE will be inherited by directories.\r\r\n OI - Object Inherit.\r\r\n The ACE will be inherited by files.\r\r\n IO - Inherit Only.\r\r\n The ACE does not apply to the current file/directory.\r\r\n ID - Inherited.\r\r\n The ACE was inherited from the parent directory's ACL.\r\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\cacls.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "calc.exe-961E093BE1F666FD38602AD90A5F480F": { "file_name": "calc.exe", "file_path": "C:\\Windows\\SysWOW64\\calc.exe", "hash_md5": "961E093BE1F666FD38602AD90A5F480F", "hash_sha1": "3574FC3A80D80146A7067A478DB209E452757950", "hash_sha256": "B183BD6414C5123465075D76D2413C999D569492FB543ACBC29690B4B745BDF2", "hash_sha384": "7757730FA7685622B9BDA9205572D382F121C0940D3D334F6B29C00957E776C9D44B1E19052ACC28D7484413281103A0", "hash_sha512": "BC0C98B3CC8FF9B4E804B09CE833ABCEDFBD14A6B64C2F0F3CC9510E544849582B6D4BFD04FFD1364E89EE2AE98A6BE3A7E16DFB0FA4D4C26343BABB46FBB3CD", "hash_ssdeep": "384:y7cqdIxXkRswWS/YWyiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiLiiiiiriiii9:yk0sS7", "hash_imp": "BA072A972FE6C47C8CF7A0347BB0AF7A", "hash_pesha1": "5869D920028159CA92A0AEBE1DFCCC8AFA963265", "hash_pe256": "239B7480DF14E32CEA8663FEC2E3E18F3B22197BE86D04FA46DAE65BC2A19C5D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Calculator", "meta_original_filename": "CALC.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b183bd6414c5123465075d76d2413c999d569492fb543acbc29690b4b745bdf2/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\calc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "CameraSettingsUIHost.exe-AB2C7BC86F9E1BB245E43C81A01A7380": { "file_name": "CameraSettingsUIHost.exe", "file_path": "C:\\Windows\\SysWOW64\\CameraSettingsUIHost.exe", "hash_md5": "AB2C7BC86F9E1BB245E43C81A01A7380", "hash_sha1": "C20EEDFBB2DDD04AA094F11067E5ED13967E282F", "hash_sha256": "9753C8D7E7B89F707712B24699BBD10CBDA1F09EAC1DD5A2F99D741F15F7897D", "hash_sha384": "56FA1545FF9F9512E43122EEEDDB3F89F8B2F586CF86703B786274673240AD0AF64E0E8DD297D1EBD6AA5F8AB343AA41", "hash_sha512": "265981572F01FFE7C304ADCD525DCACB8EB53CFA4E19752A1972682A885AFC0CD5745A9659778B284B0D2C8B1EC2CA125AAE5DC1655411CB0036E097A59E4DF4", "hash_ssdeep": "384:tDiqhV8/xNeLE9kbMe6hFvR2yoB2dJ+7Qg2qXpdJBbWZdWpex5sD1IDBRJtGICTh:0qhVMxNeKkIdcyRrkJBay8sI1PoIC9", "hash_imp": "098461CCF821A821C7EF74FD392E1DB6", "hash_pesha1": "0366E8AFADB7B04E07CD10F4ECD7D9FD6E22C965", "hash_pe256": "9ACF958ECD1E9B5BFBC5EDCC05156649B3C300E32B9AA56A7C0DBEDAE0E3D32A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Camera Settings UI Host", "meta_original_filename": "CameraSettingsUIHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9753c8d7e7b89f707712b24699bbd10cbda1f09eac1dd5a2f99d741f15f7897d/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\CameraSettingsUIHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "CertEnrollCtrl.exe-8929EBB0CCABE2B6001440E138A7DFB5": { "file_name": "CertEnrollCtrl.exe", "file_path": "C:\\Windows\\SysWOW64\\CertEnrollCtrl.exe", "hash_md5": "8929EBB0CCABE2B6001440E138A7DFB5", "hash_sha1": "C49515EEDE37A81C100378D228F03321FCC485B8", "hash_sha256": "18F25C1F71BFBA5BB2D159228C0563CAA54BEEAF2F732DD2B614E77024A97A6C", "hash_sha384": "D6F82B63829DBACB1CA410D6B5E28C03AC8BE19E1612C0B3C945C740DCB2ED1D21E4596A008CB55156DCAF7CE39EFFBF", "hash_sha512": "AD9D7DE3145FB44DBE8E8670D88DF8930D51DF95CDA3586719F8448BE23F8F7E26456205FB1AC63D7B2C0A7611A6A1148BFBD7C64A200BD014EAC7462E13F697", "hash_ssdeep": "768:VrLB44+MF3lUR5qiavKHjiPqqymtnY5xpI+wLUEvK9uwY+LmGZmR++Ah:V3h3+RfHeSan6xpI+cVvFmZmR++k", "hash_imp": "EABE8C5D3BBE7BB90E7C03DED23530EE", "hash_pesha1": "83C805F6EA1341A0E7C188F7CC36DC3B2733BAF5", "hash_pe256": "FF34206B07C24BB66ACB1F61983FCF8E3F031FA83716EC567A4F1B973641038A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Certificate Enrollment Control", "meta_original_filename": "EnrollComServer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/18f25c1f71bfba5bb2d159228c0563caa54beeaf2f732dd2b614e77024a97a6c/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\CertEnrollCtrl.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\CertEnrollCtrl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "certreq.exe-B2DFFD4A6646AD25A9AA40FA2DF519DC": { "file_name": "certreq.exe", "file_path": "C:\\Windows\\SysWOW64\\certreq.exe", "hash_md5": "B2DFFD4A6646AD25A9AA40FA2DF519DC", "hash_sha1": "DF320B01643259AEDE3D46C09439C41F9D1804E4", "hash_sha256": "BDFD1131BFC746A7A08AF26063FDF9BA148691C2CCD4CDEBB5A73045BFC61B02", "hash_sha384": "B862858B81EA74F8D146B99AF3FCDC8665AAE59F4D186FDFE783F0D85F96B11C2659F60E6F53CAF9FA38B7C1DBE3D044", "hash_sha512": "47A8419C255221909F69E310AE38921B98813786DF75346AF184F30B92B2BA738EAE01E4F243B7226D30C1D09AFAC37858C374B78FB349002109A94F90A65744", "hash_ssdeep": "6144:bE5qa4XEg9GDTo33owUamjeui8AtrPLcYWqNMUYLGQx993taHAdyPHz1:ba0EVOUaWeui8AtrQYFNMUYLr2Hlz1", "hash_imp": "76D5EC94263665D8F75D78ED97C77C03", "hash_pesha1": "A2370CFE8BD95728D0581FCED67DE72740D2D7EE", "hash_pe256": "87E6E1FF5B47E0319A063E398B5032B5340D1384752514A9C4E298CC2085C322", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CertReq.exe", "meta_original_filename": "CertReq.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/bdfd1131bfc746a7a08af26063fdf9ba148691c2ccd4cdebb5a73045bfc61b02/detection", "children": "conhost.exe", "output": "Usage:\r\r\n CertReq -?\r\r\n CertReq [-v] -?\r\r\n CertReq [-Command] -?\r\r\n\r\n CertReq [-Submit] [Options] [RequestFileIn [CertFileOut [CertChainFileOut [FullResponseFileOut]]]]\r\r\n Submit a request to a Certification Authority.\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -binary\r\r\n -PolicyServer PolicyServer\r\r\n -config ConfigString\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -crl\r\r\n -rpc\r\r\n -AdminForceMachine\r\r\n -RenewOnBehalfOf\r\r\n -NoChallenge\r\r\n\r\n CertReq -Retrieve [Options] RequestId [CertFileOut [CertChainFileOut [FullResponseFileOut]]]\r\r\n Retrieve a response to a previous request from a Certification Authority.\r\r\n\r\n Options:\r\r\n -binary\r\r\n -PolicyServer PolicyServer\r\r\n -config ConfigString\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -crl\r\r\n -rpc\r\r\n -AdminForceMachine\r\r\n\r\n CertReq -New [Options] [PolicyFileIn [RequestFileOut]]\r\r\n Create a new request as directed by PolicyFileIn\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -binary\r\r\n -cert CertId\r\r\n -PolicyServer PolicyServer\r\r\n -config ConfigString\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -pin Pin\r\r\n -user\r\r\n -machine\r\r\n -xchg ExchangeCertFile\r\r\n\r\n CertReq -Accept [Options] [CertChainFileIn | FullResponseFileIn | CertFileIn]\r\r\n Accept and install a response to a previous new request.\r\r\n\r\n Options:\r\r\n -user \r\r\n -machine \r\r\n -pin Pin\r\r\n\r\n CertReq -Policy [Options] [RequestFileIn [PolicyFileIn [RequestFileOut [PKCS10FileOut]]]]\r\r\n Construct a cross certification or qualified subordination request\r\r\n from an existing CA certificate or from an existing request.\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -binary\r\r\n -cert CertId\r\r\n -PolicyServer PolicyServer\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -pin Pin\r\r\n -noEKU\r\r\n -AlternateSignatureAlgorithm\r\r\n -HashAlgorithm HashAlgorithm\r\r\n\r\n CertReq -Sign [Options] [RequestFileIn [RequestFileOut]]\r\r\n Sign a certificate request with an enrollment agent or qualified\r\r\n subordination signing certificate.\r\r\n\r\n Options:\r\r\n -binary\r\r\n -cert CertId\r\r\n -PolicyServer PolicyServer\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -pin Pin\r\r\n -crl\r\r\n -noEKU\r\r\n -HashAlgorithm HashAlgorithm\r\r\n\r\n CertReq -Enroll [Options] TemplateName\r\r\n CertReq -Enroll -cert CertId [Options] Renew [ReuseKeys]\r\r\n Enroll for or renew a certificate.\r\r\n\r\n Options:\r\r\n -PolicyServer PolicyServer\r\r\n -user \r\r\n -machine \r\r\n -pin Pin\r\r\n\r\n CertReq -EnrollAIK [Options] [KeyContainerName]\r\r\n Enroll for AIK certificate.\r\r\n\r\n Options:\r\r\n -config\r\r\n\r\n CertReq -EnrollCredGuardCert [Options] TemplateName [ExtensionInfFile]\r\r\n NOTE: Enrolling for machine account Credential Guard certificate is not supported on this platform.\r\r\n\r\n Options:\r\r\n Not supported on this platform\r\r\n\r\n CertReq -EnrollLogon [Options]\r\r\n Enroll for Hello for Business Logon certificate via ADFS.\r\r\n\r\n Options:\r\r\n -q\r\r\n\r\n CertReq -Post [Options]\r\r\n POST an http request.\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -config URL\r\r\n\r\nUnknown argument: --help\r\n", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\certreq.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\certreq.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Certificate Request Processor" }, "certutil.exe-2EE61062AF648FF954408D422CA408F4": { "file_name": "certutil.exe", "file_path": "C:\\Windows\\SysWOW64\\certutil.exe", "hash_md5": "2EE61062AF648FF954408D422CA408F4", "hash_sha1": "2085D81175AEF2537D4B4E8DCD641585951DADEE", "hash_sha256": "1C010BFBF42A6A32EC9BFF5A3A559B51C983D77CE47D30074AA170417FA4CF1D", "hash_sha384": "85A8A8BF42BAAAD8246FC69CB0EC1F303552C9FAFEE7C0EAC3FB7B07690F9DF631F4DC364B10D0212583CB97FE207C80", "hash_sha512": "C6AC6DED5342E674968FCFD5F95334C20A6001FA78D7BE3088BB3D6B2D836F5776332AF40819CC5BB7F5266A5D2A553A9DF984BE53FC3928FC79460799791CDE", "hash_ssdeep": "24576:kl2ZFnvgwPY4Wii0yVAUKxaY1nRKziwHP8dAReFQ3K2pGrgzFqaOO2BN5Dr:k4W0zxaYXNrsAgzcbO2/R", "hash_imp": "92EAFDFBCF8B4ECD46E832973B0649D6", "hash_pesha1": "9EBA176BE99C940DF1F268F60AD3A9B918D00739", "hash_pe256": "C92DDFF5AE62D2DC375A9C2580BE6EBF0A544A79A4FBE551071567F4A59290C6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CertUtil.exe", "meta_original_filename": "CertUtil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1c010bfbf42a6a32ec9bff5a3a559b51c983d77ce47d30074aa170417fa4cf1d/detection", "output": "\r\nVerbs:\r\n -dump -- Dump configuration information or file\r\n -dumpPFX -- Dump PFX structure\r\n -asn -- Parse ASN.1 file\r\n\r\n -decodehex -- Decode hexadecimal-encoded file\r\n -decode -- Decode Base64-encoded file\r\n -encode -- Encode file to Base64\r\n\r\n -deny -- Deny pending request\r\n -resubmit -- Resubmit pending request\r\n -setattributes -- Set attributes for pending request\r\n -setextension -- Set extension for pending request\r\n -revoke -- Revoke Certificate\r\n -isvalid -- Display current certificate disposition\r\n\r\n -getconfig -- Get default configuration string\r\n -ping -- Ping Active Directory Certificate Services Request interface\r\n -pingadmin -- Ping Active Directory Certificate Services Admin interface\r\n -CAInfo -- Display CA Information\r\n -ca.cert -- Retrieve the CA's certificate\r\n -ca.chain -- Retrieve the CA's certificate chain\r\n -GetCRL -- Get CRL\r\n -CRL -- Publish new CRLs [or delta CRLs only]\r\n -shutdown -- Shutdown Active Directory Certificate Services\r\n\r\n -installCert -- Install Certification Authority certificate\r\n -renewCert -- Renew Certification Authority certificate\r\n\r\n -schema -- Dump Certificate Schema\r\n -view -- Dump Certificate View\r\n -db -- Dump Raw Database\r\n -deleterow -- Delete server database row\r\n\r\n -backup -- Backup Active Directory Certificate Services\r\n -backupDB -- Backup Active Directory Certificate Services database\r\n -backupKey -- Backup Active Directory Certificate Services certificate and private key\r\n -restore -- Restore Active Directory Certificate Services\r\n -restoreDB -- Restore Active Directory Certificate Services database\r\n -restoreKey -- Restore Active Directory Certificate Services certificate and private key\r\n -importPFX -- Import certificate and private key\r\n -dynamicfilelist -- Display dynamic file List\r\n -databaselocations -- Display database locations\r\n -hashfile -- Generate and display cryptographic hash over a file\r\n\r\n -store -- Dump certificate store\r\n -enumstore -- Enumerate certificate stores\r\n -addstore -- Add certificate to store\r\n -delstore -- Delete certificate from store\r\n -verifystore -- Verify certificate in store\r\n -repairstore -- Repair key association or update certificate properties or key security descriptor\r\n -viewstore -- Dump certificate store\r\n -viewdelstore -- Delete certificate from store\r\n -UI -- invoke CryptUI\r\n -attest -- Verify Key Attestation Request\r\n\r\n -dsPublish -- Publish certificate or CRL to Active Directory\r\n\r\n -ADTemplate -- Display AD templates\r\n -Template -- Display Enrollment Policy templates\r\n -TemplateCAs -- Display CAs for template\r\n -CATemplates -- Display templates for CA\r\n -SetCASites -- Manage Site Names for CAs\r\n -enrollmentServerURL -- Display, add or delete enrollment server URLs associated with a CA\r\n -ADCA -- Display AD CAs\r\n -CA -- Display Enrollment Policy CAs\r\n -Policy -- Display Enrollment Policy\r\n -PolicyCache -- Display or delete Enrollment Policy Cache entries\r\n -CredStore -- Display, add or delete Credential Store entries\r\n -InstallDefaultTemplates -- Install default certificate templates\r\n -URLCache -- Display or delete URL cache entries\r\n -pulse -- Pulse autoenrollment event or NGC task\r\n -MachineInfo -- Display Active Directory machine object information\r\n -DCInfo -- Display domain controller information\r\n -EntInfo -- Display enterprise information\r\n -TCAInfo -- Display CA information\r\n -SCInfo -- Display smart card information\r\n\r\n -SCRoots -- Manage smart card root certificates\r\n\r\n -DeleteHelloContainer -- Delete Hello Logon container. \r\n ** Users need to sign out after using this option for it to complete. **\r\n -verifykeys -- Verify public/private key set\r\n -verify -- Verify certificate, CRL or chain\r\n -verifyCTL -- Verify AuthRoot or Disallowed Certificates CTL\r\n -syncWithWU -- Sync with Windows Update\r\n -generateSSTFromWU -- Generate SST from Windows Update\r\n -generatePinRulesCTL -- Generate Pin Rules CTL\r\n -downloadOcsp -- Download OCSP Responses and Write to Directory\r\n -generateHpkpHeader -- Generate HPKP header using certificates in specified file or directory\r\n -flushCache -- Flush specified caches in selected process, such as, lsass.exe\r\n -addEccCurve -- Add ECC Curve\r\n -deleteEccCurve -- Delete ECC Curve\r\n -displayEccCurve -- Display ECC Curve\r\n -sign -- Re-sign CRL or certificate\r\n\r\n -vroot -- Create/delete web virtual roots and file shares\r\n -vocsproot -- Create/delete web virtual roots for OCSP web proxy\r\n -addEnrollmentServer -- Add an Enrollment Server application\r\n -deleteEnrollmentServer -- Delete an Enrollment Server application\r\n -addPolicyServer -- Add a Policy Server application\r\n -deletePolicyServer -- Delete a Policy Server application\r\n -oid -- Display ObjectId or set display name\r\n -error -- Display error code message text\r\n -getreg -- Display registry value\r\n -setreg -- Set registry value\r\n -delreg -- Delete registry value\r\n\r\n -ImportKMS -- Import user keys and certificates into server database for key archival\r\n -ImportCert -- Import a certificate file into the database\r\n -GetKey -- Retrieve archived private key recovery blob, generate a recovery script,\r\n or recover archived keys\r\n -RecoverKey -- Recover archived private key\r\n -MergePFX -- Merge PFX files\r\n -ConvertEPF -- Convert PFX files to EPF file\r\n\r\n -add-chain -- (-AddChain) Add certificate chain\r\n -add-pre-chain -- (-AddPrechain) Add pre-certificate chain\r\n -get-sth -- (-GetSTH) Get signed tree head\r\n -get-sth-consistency -- (-GetSTHConsistency) Get signed tree head changes\r\n -get-proof-by-hash -- (-GetProofByHash) Get proof by hash\r\n -get-entries -- (-GetEntries) Get entries\r\n -get-roots -- (-GetRoots) Get roots\r\n -get-entry-and-proof -- (-GetEntryAndProof) Get entry and proof\r\n -VerifyCT -- Verify certificate SCT\r\n -? -- Display this usage message\r\n\r\n\r\nCertUtil -? -- Display a verb list (command list)\r\nCertUtil -dump -? -- Display help text for the \"dump\" verb\r\nCertUtil -v -? -- Display all help text for all verbs\r\n\r\nCertUtil: -? command completed successfully.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\certutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "charmap.exe-436AB8366C52C59543BEB03F4599C01B": { "file_name": "charmap.exe", "file_path": "C:\\Windows\\SysWOW64\\charmap.exe", "hash_md5": "436AB8366C52C59543BEB03F4599C01B", "hash_sha1": "612EF68E300C084C63A6BA27221FD74B724BADBC", "hash_sha256": "9D1955F3A5A98C6BF6886280D3B6736163B6F05DC06A10CB89A152C5B8D43BFC", "hash_sha384": "32944CB014EB5DAFD7D1CEEB50905E1B5CDF64D09A43ACFBDD73FB428F30724EE2BE7367366ABF5E7384DD26146FF2D8", "hash_sha512": "5A7F6C4DFF95564E64E64985F54619A89DAA6BA26A20D998FCF25BAFAF9FF206F0FB1319B1242F6A64B63BCBE5CEC59A0E1402B5F758CD1F27279E07DEC28B12", "hash_ssdeep": "3072:ukP4rthUtI0OUpwFzz4G3PVClnDjlbrLF5NUdrSO9K/tagbdDu5nBf9f:ptI0pUz4G9Cl31bgqt5gZ", "hash_imp": "AA067A9709CF4CC14566F71EE6196E09", "hash_pesha1": "B9C0DC1D23B2DA53C698AEEE70CD5C5EEC1D49EA", "hash_pe256": "86FAFA9D22551500DD1707DAE6105152951C0ED82BCC9BE940B7012D9DB14095", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Character Map", "meta_original_filename": "charmap.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9d1955f3a5a98c6bf6886280d3b6736163b6f05dc06a10cb89a152c5b8d43bfc/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\charmap.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme601709542": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\ca4HWNDInterface:14104fe": "Section", "(R-D) C:\\Windows\\System32\\en-US\\getuname.dll.mui": "File", "(R--) C:\\Windows\\SysWOW64\\bopomofo.uce": "File", "(R--) C:\\Windows\\SysWOW64\\gb2312.uce": "File", "(R--) C:\\Windows\\SysWOW64\\ideograf.uce": "File", "(R--) C:\\Windows\\SysWOW64\\kanji_1.uce": "File", "(R--) C:\\Windows\\SysWOW64\\kanji_2.uce": "File", "(R--) C:\\Windows\\SysWOW64\\korean.uce": "File", "(R--) C:\\Windows\\SysWOW64\\ShiftJIS.uce": "File", "(R--) C:\\Windows\\SysWOW64\\SubRange.uce": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\charmap.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Character Map" }, "CheckNetIsolation.exe-1DBA0805E01C22E064398F357A7A01B1": { "file_name": "CheckNetIsolation.exe", "file_path": "C:\\Windows\\SysWOW64\\CheckNetIsolation.exe", "hash_md5": "1DBA0805E01C22E064398F357A7A01B1", "hash_sha1": "F759238BE45C73342A9C0CECD98773CFB97D0A4A", "hash_sha256": "9243004D116C726F0AD5DCD744D1B2242FC40917D1FDE5396CDC8516369DACF3", "hash_sha384": "6486113EECF1222AB12B5B526DE24D437A8292F37551AC75F0886A8919DCFAE24643B41C859AAD6B072491EEF5B597E3", "hash_sha512": "20094389E0430A3928E3B498696CE7CB22213C04ABC6D09C8D64D1A632F6D14A2DE450B1E4E6705D55F0BADBB87E7C3447468D34420F01DEBF2C95DB7760B86A", "hash_ssdeep": "384:x+/aa0r5d/U9nexsC52KXLEbZ7RCmr43p+2DInx2tHMAWy7pOW931CD5AqjX:M/aYQYbmwsInotHM87pt3M5Aq7", "hash_imp": "8C4B70B06FD4E738845E670CA5E4F39B", "hash_pesha1": "231D2F0C9F49AF03F970546E9DB959EE7ED20F1B", "hash_pe256": "E2C8481D48F070237454440D5E2C68B695BF8C0B66F7F436C3D1204F57D3786B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AppContainer Network Isolation Diagnostic Tool", "meta_original_filename": "CheckNetIsolation.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/9243004d116c726f0ad5dcd744d1b2242fc40917d1fde5396cdc8516369dacf3/detection", "output": "Error: Invalid Parameters\r\n\r\nUsage:\r\n CheckNetIsolation [Module]\r\n List Of Modules: \r\n LoopbackExempt - controls the loopback exemption of AppContainers\r\n and Package Families to ease application\r\n development.\r\n Debug - Starts a network traffic troubleshooting session\r\n of an AppContainer or Package Family. Generates a\r\n report of network capabilities that are used, not\r\n used or missing, together with the network traffic\r\n generated by the application.\r\n -? - Displays this help message.\r\n \r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\CheckNetIsolation.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "chkdsk.exe-B4016BEE9D8F3AD3D02DD21C3CAFB922": { "file_name": "chkdsk.exe", "file_path": "C:\\Windows\\SysWOW64\\chkdsk.exe", "hash_md5": "B4016BEE9D8F3AD3D02DD21C3CAFB922", "hash_sha1": "82256B26A70A38FED9AF0080CD4B07320041C69B", "hash_sha256": "1D5227595AEB4FF3CEEB620E94B5342955667EEACD000E2A4BE748AD94583DAF", "hash_sha384": "79A4D69FE4B06B0B433A91B725DD4341D92B0CAAEDF60F61276F22A50E09F4402B4DFAF10363EA544B5788C24D261DAD", "hash_sha512": "EC9032F1889CBA56E6340A52963BBCB8F83D7B5D60AD11642CC6204836295D46F29192F8B62AE70A2A132AAD473B873BC928B14A4D96F2B0483DD078557EEE4C", "hash_ssdeep": "384:2RNnyRmBn6gPnAQReaUCGOf0jJUlvlGs0trLhpNSWSFKhW:HmBn6gPnAQReaUCG60Xp6K", "hash_imp": "52F0D0726DA8AD61A069466457E67F74", "hash_pesha1": "A73E5E802FDBA5A17E272C60EE991BCF522FE8C3", "hash_pe256": "329FF017C2E73CD6C0CCE694509270AF5A58B09755AD7AA0B7592807B23EC480", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Check Disk Utility", "meta_original_filename": "CHKDSK.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1d5227595aeb4ff3ceeb620e94b5342955667eeacd000e2a4be748ad94583daf/detection", "output": "Checks a disk and displays a status report.\r\n\r\n\r\nCHKDSK [volume[[path]filename]]] [/F] [/V] [/R] [/X] [/I] [/C] [/L[:size]] [/B] [/scan] [/spotfix]\r\n\r\n\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name.\r\n filename FAT/FAT32 only: Specifies the files to check for\r\n fragmentation.\r\n /F Fixes errors on the disk.\r\n /V On FAT/FAT32: Displays the full path and name of every\r\n file on the disk.\r\n On NTFS: Displays cleanup messages if any.\r\n /R Locates bad sectors and recovers readable information\r\n (implies /F, when /scan not specified).\r\n /L:size NTFS only: Changes the log file size to the specified\r\n number of kilobytes. If size is not specified, displays\r\n current size.\r\n /X Forces the volume to dismount first if necessary.\r\n All opened handles to the volume would then be invalid\r\n (implies /F).\r\n /I NTFS only: Performs a less vigorous check of index\r\n entries.\r\n /C NTFS only: Skips checking of cycles within the folder\r\n structure.\r\n /B NTFS only: Re-evaluates bad clusters on the volume\r\n (implies /R)\r\n /scan NTFS only: Runs an online scan on the volume\r\n /forceofflinefix NTFS only: (Must be used with \"/scan\")\r\n Bypass all online repair; all defects found\r\n are queued for offline repair (i.e. \"chkdsk /spotfix\").\r\n /perf NTFS only: (Must be used with \"/scan\")\r\n Uses more system resources to complete a scan as fast as\r\n possible. This may have a negative performance impact on\r\n other tasks running on the system.\r\n /spotfix NTFS only: Runs spot fixing on the volume\r\n /sdcleanup NTFS only: Garbage collect unneeded security descriptor\r\n data (implies /F).\r\n /offlinescanandfix Runs an offline scan and fix on the volume.\r\n /freeorphanedchains FAT/FAT32/exFAT only: Frees any orphaned cluster chains\r\n instead of recovering their contents.\r\n /markclean FAT/FAT32/exFAT only: Marks the volume clean if no\r\n corruption was detected, even if /F was not specified.\r\n\r\nThe /I or /C switch reduces the amount of time required to run Chkdsk by\r\nskipping certain checks of the volume.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\chkdsk.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "chkntfs.exe-A9B42ED1B14BB22EF07CCC8228697408": { "file_name": "chkntfs.exe", "file_path": "C:\\Windows\\SysWOW64\\chkntfs.exe", "hash_md5": "A9B42ED1B14BB22EF07CCC8228697408", "hash_sha1": "DC7CDC53D24CF94D66A77A9AD5AB84551056659A", "hash_sha256": "A7E7965C36A54135BF192AA34ED32065C151691EECC5F5C17FFC1DB2C767478A", "hash_sha384": "F00BC15CB97A506932BA060578D14AA0333FBC70DF116B7E9AD430DFD16A689F0B273116F17AD00A1AF53C0577D55F27", "hash_sha512": "49378910D09003A3A97EAF4B320BFC42C00F2EC87C1D5C3344E96C0B9D2E3D562736EC4DC6F13F830821C9A04CCBF60DE210A9F93A426A75DE31F6D5D6A4EC30", "hash_ssdeep": "192:dlvgZmvQxNwXMTnCzdZDqAWjVcEXKYgQrSKidzdrLROUazLUq7sgkN7nQWJ46WzG:7IKYNwuidowQrS9RBELDo7N8Wi6Wz2j", "hash_imp": "D0F4E345E64F27143A66B4C09C8B88D7", "hash_pesha1": "542624BB008B84F7B17200C87F44E1AD76A1C51B", "hash_pe256": "4B0511952DF051F42B191F02B566D90429529AC6902114FF2173CAC0DB2C5915", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NTFS Volume Maintenance Utility", "meta_original_filename": "CHKNTFS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/a7e7965c36a54135bf192aa34ed32065c151691eecc5f5c17ffc1db2c767478a/detection", "output": "Displays or modifies the checking of disk at boot time.\r\n\r\nCHKNTFS volume [...]\r\nCHKNTFS /D\r\nCHKNTFS /T[:time]\r\nCHKNTFS /X volume [...]\r\nCHKNTFS /C volume [...]\r\n\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name.\r\n /D Restores the machine to the default behavior; all drives are\r\n checked at boot time and chkdsk is run on those that are\r\n dirty.\r\n /T:time Changes the AUTOCHK initiation countdown time to the\r\n specified amount of time in seconds. If time is not\r\n specified, displays the current setting.\r\n /X Excludes a drive from the default boot-time check. Excluded\r\n drives are not accumulated between command invocations.\r\n /C Schedules a drive to be checked at boot time; chkdsk will run\r\n if the drive is dirty.\r\n\r\nIf no switches are specified, CHKNTFS will display if the specified drive is\r\ndirty or scheduled to be checked on next reboot.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\chkntfs.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "choice.exe-FCE0E41C87DC4ABBE976998AD26C27E4": { "file_name": "choice.exe", "file_path": "C:\\Windows\\SysWOW64\\choice.exe", "hash_md5": "FCE0E41C87DC4ABBE976998AD26C27E4", "hash_sha1": "6FA25E0162F4AB0ABF7BCD8368B03722244D81FF", "hash_sha256": "F6E5759793032BB3CE69658D0D4F0049A06E25FDC316D457846BB644212730AF", "hash_sha384": "B9EE098EA6984F9D916A9B6EC8FF5380B2481944F0CE76FD0F327CA288082AA728D6D4D53F6F306AEC6B596EC163F235", "hash_sha512": "EC348B6B0AE65A42021DA7765896A52CD7658295FF93065ECBD11ED7C509DBACF8E0FAEA5B9D2E13291CCE33A813A96D5C3C90A118E3949396B8B0424BAFBFBA", "hash_ssdeep": "768:frftNwW24gksQdc+bIyni4hTNGeLBHXyxnd3PX:frftNwhdP+ztnikMeLBHixd3P", "hash_imp": "A445244C63114214072FAF6C3DCE1438", "hash_pesha1": "6F1BE54FF6978CF5ACDDF933038CF3084EA5E9E9", "hash_pe256": "EAE3CBE520820FEA0CA911D56615C55082D018E095A9980BE80BFAFD9BC4F3D8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Offers the user a choice", "meta_original_filename": "choice.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f6e5759793032bb3ce69658d0d4f0049a06e25fdc316d457846bb644212730af/detection", "output": "\r\nCHOICE [/C choices] [/N] [/CS] [/T timeout /D choice] [/M text]\r\n\r\nDescription:\r\n This tool allows users to select one item from a list \r\n of choices and returns the index of the selected choice.\r\n\r\nParameter List:\r\n /C choices Specifies the list of choices to be created.\r\n Default list is \"YN\".\r\n\r\n /N Hides the list of choices in the prompt.\r\n The message before the prompt is displayed\r\n and the choices are still enabled.\r\n\r\n /CS Enables case-sensitive choices to be selected.\r\n By default, the utility is case-insensitive.\r\n\r\n /T timeout The number of seconds to pause before a default \r\n choice is made. Acceptable values are from 0 to \r\n 9999. If 0 is specified, there will be no pause \r\n and the default choice is selected.\r\n\r\n /D choice Specifies the default choice after nnnn seconds.\r\n Character must be in the set of choices specified\r\n by /C option and must also specify nnnn with /T.\r\n\r\n /M text Specifies the message to be displayed before \r\n the prompt. If not specified, the utility \r\n displays only a prompt.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE:\r\n The ERRORLEVEL environment variable is set to the index of the\r\n key that was selected from the set of choices. The first choice\r\n listed returns a value of 1, the second a value of 2, and so on.\r\n If the user presses a key that is not a valid choice, the tool \r\n sounds a warning beep. If tool detects an error condition,\r\n it returns an ERRORLEVEL value of 255. If the user presses \r\n CTRL+BREAK or CTRL+C, the tool returns an ERRORLEVEL value\r\n of 0. When you use ERRORLEVEL parameters in a batch program, list\r\n them in decreasing order.\r\n\r\nExamples:\r\n CHOICE /?\r\n CHOICE /C YNC /M \"Press Y for Yes, N for No or C for Cancel.\"\r\n CHOICE /T 10 /C ync /CS /D y \r\n CHOICE /C ab /M \"Select a for option 1 and b for option 2.\"\r\n CHOICE /C ab /N /M \"Select a for option 1 and b for option 2.\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"CHOICE /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\choice.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cipher.exe-EC2B2944AB4480E520A8015A0740E684": { "file_name": "cipher.exe", "file_path": "C:\\Windows\\SysWOW64\\cipher.exe", "hash_md5": "EC2B2944AB4480E520A8015A0740E684", "hash_sha1": "A378EC4828DAB685A88B2763DB5DCE96C3AC20E6", "hash_sha256": "0B26B46319CE5332AC61DC2D4767368AF0C5FD0475B0B82304AB3AB621952ECE", "hash_sha384": "1C562F14FEF4FA40E500C3766B26BA6BB16F498BD482DB48000072BF4B14371F2EAFB29A4936712A560FA1584D08B6F4", "hash_sha512": "A5EA6ABCE9B77E27DE2661773BCDD54FDB5730605273D214299BC0CF2DA369FEC52AAA6B4B3D160179BC7CD17634EBB514581BFA4FA09259269766DECBD18174", "hash_ssdeep": "768:3W2atUnmVZln7u0aIORVpIx34pcKmPJoz4joP:3xammR7u3VeOWK5z4j", "hash_imp": "3709556898BEAA4E2B5F857FFA0F54BA", "hash_pesha1": "8C702D8EBB66721193D0903D5D92238DA271DA73", "hash_pe256": "0D6751B3D87C1341AF2AAF67E2241186C03BC10AA0B26983788568F2B0A93D1F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Encryption Utility", "meta_original_filename": "CIPHER.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0b26b46319ce5332ac61dc2d4767368af0c5fd0475b0b82304ab3ab621952ece/detection", "output": "Displays or alters the encryption of directories [files] on NTFS partitions.\r\n\r\n CIPHER [/E | /D | /C]\r\n [/S:directory] [/B] [/H] [pathname [...]]\r\n\r\n CIPHER /K [/ECC:256|384|521]\r\n\r\n CIPHER /R:filename [/SMARTCARD] [/ECC:256|384|521]\r\n\r\n CIPHER /P:filename.cer\r\n\r\n CIPHER /U [/N]\r\n\r\n CIPHER /W:directory\r\n\r\n CIPHER /X[:efsfile] [filename]\r\n\r\n CIPHER /Y\r\n\r\n CIPHER /ADDUSER [/CERTHASH:hash | /CERTFILE:filename | /USER:username]\r\n [/S:directory] [/B] [/H] [pathname [...]]\r\n\r\n CIPHER /FLUSHCACHE [/SERVER:servername]\r\n\r\n CIPHER /REMOVEUSER /CERTHASH:hash\r\n [/S:directory] [/B] [/H] [pathname [...]]\r\n\r\n CIPHER /REKEY [pathname [...]]\r\n\r\n /B Abort if an error is encountered. By default, CIPHER continues\r\n executing even if errors are encountered.\r\n /C Displays information on the encrypted file.\r\n /D Decrypts the specified files or directories.\r\n /E Encrypts the specified files or directories. Directories will be\r\n marked so that files added afterward will be encrypted. The\r\n encrypted file could become decrypted when it is modified if the\r\n parent directory is not encrypted. It is recommended that you\r\n encrypt the file and the parent directory.\r\n /H Displays files with the hidden or system attributes. These files\r\n are omitted by default.\r\n /K Creates a new certificate and key for use with EFS. If this\r\n option is chosen, all the other options will be ignored.\r\n\r\n Note: By default, /K creates a certificate and key that conform\r\n to current group policy. If ECC is specified, a self-signed\r\n certificate will be created with the supplied key size.\r\n\r\n /N This option only works with /U. This will prevent keys being\r\n updated. This is used to find all the encrypted files on the\r\n local drives.\r\n /R Generates an EFS recovery key and certificate, then writes them\r\n to a .PFX file (containing certificate and private key) and a\r\n .CER file (containing only the certificate). An administrator may\r\n add the contents of the .CER to the EFS recovery policy to create\r\n the recovery key for users, and import the .PFX to recover\r\n individual files. If SMARTCARD is specified, then writes the\r\n recovery key and certificate to a smart card. A .CER file is\r\n generated (containing only the certificate). No .PFX file is\r\n generated.\r\n\r\n Note: By default, /R creates an 2048-bit RSA recovery key and\r\n certificate. If ECC is specified, it must be followed by a\r\n key size of 256, 384, or 521.\r\n\r\n /P Creates a base64-encoded recovery-policy blob from the passed-in\r\n certificate. This blob can be used to set DRA policy for\r\n MDM deployments.\r\n /S Performs the specified operation on the given directory and all\r\n files and subdirectories within it.\r\n /U Tries to touch all the encrypted files on local drives. This will\r\n update user's file encryption key or recovery keys to the current\r\n ones if they are changed. This option does not work with other\r\n options except /N.\r\n /W Removes data from available unused disk space on the entire\r\n volume. If this option is chosen, all other options are ignored.\r\n The directory specified can be anywhere in a local volume. If it\r\n is a mount point or points to a directory in another volume, the\r\n data on that volume will be removed.\r\n /X Backup EFS certificate and keys into file filename. If efsfile is\r\n provided, the current user's certificate(s) used to encrypt the\r\n file will be backed up. Otherwise, the user's current EFS\r\n certificate and keys will be backed up.\r\n /Y Displays your current EFS certificate thumbprint on the local PC.\r\n /ADDUSER Adds a user to the specified encrypted file(s). If CERTHASH is\r\n provided, cipher will search for a certificate with this SHA1\r\n hash. If CERTFILE is provided, cipher will extract the\r\n certificate from the file. If USER is provided, cipher will\r\n try to locate the user's certificate in Active Directory Domain\r\n Services.\r\n /FLUSHCACHE\r\n Clears the calling user's EFS key cache on the specified server.\r\n If servername is not provided, cipher clears the user's key cache\r\n on the local machine.\r\n /REKEY Updates the specified encrypted file(s) to use the configured\r\n EFS current key.\r\n /REMOVEUSER\r\n Removes a user from the specified file(s). CERTHASH must be the\r\n SHA1 hash of the certificate to remove.\r\n\r\n directory A directory path.\r\n filename A filename without extensions.\r\n pathname Specifies a pattern, file or directory.\r\n efsfile An encrypted file path.\r\n\r\n Used without parameters, CIPHER displays the encryption state of the\r\n current directory and any files it contains. You may use multiple directory\r\n names and wildcards. You must put spaces between multiple parameters.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\cipher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cleanmgr.exe-5AB8F80E61D780F31585E612B83FFFAD": { "file_name": "cleanmgr.exe", "file_path": "C:\\Windows\\SysWOW64\\cleanmgr.exe", "hash_md5": "5AB8F80E61D780F31585E612B83FFFAD", "hash_sha1": "CC79E333A78DBA85136B9674125E6F48C13B099A", "hash_sha256": "21737F8A48F1A7FB7873DFED26836382613DDC9E1DB860D71250B5067C011D82", "hash_sha384": "0EA3AC9AD762E37B1789F8ED665E0302AF1AF116748B47ABEE7DED71DCECCF14739A5E06460904F77A545456332116E2", "hash_sha512": "B098215E02967963C092161B3A15774886F7276B15D1C297E3ED0FA76CE44068ACF353A44B4891A4574F427848C4D35A1CD229F230FF04B1A6CBAC2073EC0EAB", "hash_ssdeep": "3072:rJ8eh6cvBPXSWRf1nhBYoFcBdyqLAEPGRvQhRkKqUa9antF5hvvJkuXpZJq:LHvhBYoFcBMqsE+ohSKq99UF5hvv/", "hash_imp": "F76A18F264CF5159E816B15A0467A24E", "hash_pesha1": "C8003ECCD65001D3EFBCC02C5A5DE7DE4CF231B3", "hash_pe256": "E8363348996515C388559019C8088D7C33E262FB9B67022231631CD934BECA9E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Space Cleanup Manager for Windows", "meta_original_filename": "CLEANMGR.DLL", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/21737f8a48f1a7fb7873dfed26836382613ddc9e1db860d71250b5067c011d82/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\cleanmgr.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\cleanmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "USAGE" }, "cliconfg.exe-5EE49921CB7AEA9FDF2938F99DB69FFA": { "file_name": "cliconfg.exe", "file_path": "C:\\Windows\\SysWOW64\\cliconfg.exe", "hash_md5": "5EE49921CB7AEA9FDF2938F99DB69FFA", "hash_sha1": "115948FE90CD8D1890F1B59E767409CAF1F95B2B", "hash_sha256": "DDC3AA90B1229F7ED1F3C64BCDEBC527D18FA24C6BCA9A0B0A7A9C0ECD37E89B", "hash_sha384": "F59153D910A52D707F6A20BF3DF50ADF0719731CD85212464678D9DFDD860667F6578DF145FE79BF51CDE457C19776EF", "hash_sha512": "86205ADB8FEFA78B19249000FB11109C42EA12D52455D6606FBFC91087D2395ECAA856CCE4A428A33B1A0E4222A8532C15D7CA6D0AFF9BBA6DDD07CD9A814F38", "hash_ssdeep": "384:EwA9G50JT6pxW0wWFPXuNvBQAMYJQ2JQSkdowyoF:5K6pRruI30lJBkvTF", "hash_imp": "0BDCEE28946450C424EEAF4F97F264EE", "hash_pesha1": "931FED0093A83AC468C70D501D785A75208D871C", "hash_pe256": "A9636383D7855328A63AE5B34C51438419FE19C7FDFB6537A57CF4B52E667A74", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SQL Client Configuration Utility EXE", "meta_original_filename": "cliconfg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ddc3aa90b1229f7ed1f3c64bcdebc527d18fa24c6bca9a0b0a7a9c0ecd37e89b/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "(R-D) C:\\Windows\\System32\\en-US\\cliconfg.rll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.19041.1_en-us_a8f1da377db0be9e": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.19041.1_en-us_a8f1da377db0be9e\\comctl32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\cliconfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "SQL Server Client Network Utility" }, "clip.exe-E40CB198EBCD20CD16739F670D4D7B74": { "file_name": "clip.exe", "file_path": "C:\\Windows\\SysWOW64\\clip.exe", "hash_md5": "E40CB198EBCD20CD16739F670D4D7B74", "hash_sha1": "E898A3B321BD6734C5A676382B5C0DFD42BE377D", "hash_sha256": "6CDC8D3C147DCF7253C0FB7BB552B4AE918ABA4058CC072A2320A7297D4FBED7", "hash_sha384": "EC95F7C7CC1D0F72AC9ABCF24C6BECA45B9B01F3E42945A308302311943064D237159AB647E535BB1BD039640DFCBFFA", "hash_sha512": "1E5A68B2AE30C7D16A0A74807FA069BE2D1B8ADCFCBCDE777217B9420A987196AF13FB05177E476157029A1F7916E6948A1286CDB8957CDD142756DA3C42BEEF", "hash_ssdeep": "384:R7OPm5RmB6C+DlVbrb6IQhH48oOhQ76pXeEYfM3G8HIdkLWXKQAF900kdxLd73NV:R7OPQc+DlVbrvQhYWhQ+BeEYfyRHPcZl", "hash_imp": "2E4F8B6217B6FC3E22F837FF8337F26B", "hash_pesha1": "5FDD96068858E1DFD8414A1B87589B2C0FE15FEC", "hash_pe256": "76A402561ADE86AA7E2C6D1850B8ACD5E779BDBAB2EA3AEA1F3F9DE52C3289AC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Clip - copies the data into clipboard", "meta_original_filename": "clip.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/6cdc8d3c147dcf7253c0fb7bb552b4ae918aba4058cc072a2320a7297d4fbed7/detection", "output": "\r\nCLIP\r\n\r\nDescription:\r\n Redirects output of command line tools to the Windows clipboard.\r\n This text output can then be pasted into other programs.\r\n\r\nParameter List:\r\n /? Displays this help message.\r\n\r\nExamples:\r\n DIR | CLIP Places a copy of the current directory\r\n listing into the Windows clipboard.\r\n\r\n CLIP < README.TXT Places a copy of the text from readme.txt\r\n on to the Windows clipboard.\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"CLIP /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\clip.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "CloudNotifications.exe-CC6E14967CA55471701693EB47C00369": { "file_name": "CloudNotifications.exe", "file_path": "C:\\Windows\\SysWOW64\\CloudNotifications.exe", "hash_md5": "CC6E14967CA55471701693EB47C00369", "hash_sha1": "C3D8FAED4A7E60634F538196506B080454F16349", "hash_sha256": "479ABB3C7EEE7D94A18CA41ACB4429F196CF5668A5D9BC20278A930BE3E8F1FF", "hash_sha384": "772D39AE97F6FF1F47A751E44212B87EF1C54D1BCC1CDE3033955FD3076ECB281EFD5368AAF28F06975206AC578FC8AD", "hash_sha512": "A46108A4B995CDC30E22E4CA2EFA80A84DB6849721B2CAE0FAD37226BC0CE7558D0B823F1D8EDC1273D5264CA3DAEACBEB2785D320F0C21B7A326616A33EAE91", "hash_ssdeep": "768:5RCmPlUYyj3KPY9Ci/aUzAYMDouj8R/cJ6x0ZOOLAq2dLwYryilmsJJH0I1Pv7zJ:5z+Yyj3yMBrVyouj8R/cJ6x0ZOOLAq2H", "hash_imp": "BA9610B04A94F3AB402D164B84007BE4", "hash_pesha1": "A56D15E853833F35C466C4F10136862F08344EAB", "hash_pe256": "94E8F12A112174FC012BEB0B3C91A036018DECB33BD27178E5E5881F6F8D0ACC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Cloud notifications", "meta_original_filename": "CloudNotifications.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/479abb3c7eee7d94a18ca41acb4429f196cf5668a5d9bc20278a930be3e8f1ff/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\CloudNotifications.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\SystemResources\\Windows.UI.Immersive.dll.mun": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\Windows.UI.Immersive.dll.mui": "File", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(RWD) C:\\Windows\\Fonts\\seguisym.ttf": "File", "(RWD) C:\\Windows\\Fonts\\segoeuisl.ttf": "File", "(RWD) C:\\Windows\\Fonts\\seguisb.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\CloudNotifications.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Low disk space" }, "cmd.exe-844DC165B24FE114978CA2C2E8D30453": { "file_name": "cmd.exe", "file_path": "C:\\Windows\\SysWOW64\\cmd.exe", "hash_md5": "844DC165B24FE114978CA2C2E8D30453", "hash_sha1": "1DD63EDD445413719BF9A4494BF7028F9BC097F3", "hash_sha256": "A47311AF139D7CD7C8F4C8C29BC5C6DF4FF8D592F2728F823A4CA96A7AF48723", "hash_sha384": "2F528196D53AB3584B286AA174E613FEF598C915432AA2698E29C8DCD5B5174D4F528F6720ABD6625C244FFBE8CF055F", "hash_sha512": "A419A6EB3DD5E61FAB95A2B551BD03BDDE4A8D0D296CE01B90B418F3369A6421C223C832F6C8C41850C82C1C8F06329CA83DCD625B866E33707246CA3EFEC013", "hash_ssdeep": "6144:ZeW6Mov7R2skwCYsCMAeqk5wUGMsfiKqnqbtfmem:ZpozRSDoNunHkdXm", "hash_imp": "392B4D61B1D1DADC1F06444DF258188A", "hash_pesha1": "B31A64A86B17B3F7DB12AAC294910A48AD3D3EB9", "hash_pe256": "BF5774A6236293E51B89616B8452D3BF5FA02634A14FDD5485BA38CB588E6FFA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Command Processor", "meta_original_filename": "Cmd.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "1/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a47311af139d7cd7c8f4c8c29bc5c6df4ff8d592f2728f823a4ca96a7af48723/detection", "output": "Starts a new instance of the Windows command interpreter\r\n\r\nCMD [/A | /U] [/Q] [/D] [/E:ON | /E:OFF] [/F:ON | /F:OFF] [/V:ON | /V:OFF]\r\n [[/S] [/C | /K] string]\r\n\r\n/C Carries out the command specified by string and then terminates\r\n/K Carries out the command specified by string but remains\r\n/S Modifies the treatment of string after /C or /K (see below)\r\n/Q Turns echo off\r\n/D Disable execution of AutoRun commands from registry (see below)\r\n/A Causes the output of internal commands to a pipe or file to be ANSI\r\n/U Causes the output of internal commands to a pipe or file to be\r\n Unicode\r\n/T:fg Sets the foreground/background colors (see COLOR /? for more info)\r\n/E:ON Enable command extensions (see below)\r\n/E:OFF Disable command extensions (see below)\r\n/F:ON Enable file and directory name completion characters (see below)\r\n/F:OFF Disable file and directory name completion characters (see below)\r\n/V:ON Enable delayed environment variable expansion using ! as the\r\n delimiter. For example, /V:ON would allow !var! to expand the\r\n variable var at execution time. The var syntax expands variables\r\n at input time, which is quite a different thing when inside of a FOR\r\n loop.\r\n/V:OFF Disable delayed environment expansion.\r\n\r\nNote that multiple commands separated by the command separator '&&'\r\nare accepted for string if surrounded by quotes. Also, for compatibility\r\nreasons, /X is the same as /E:ON, /Y is the same as /E:OFF and /R is the\r\nsame as /C. Any other switches are ignored.\r\n\r\nIf /C or /K is specified, then the remainder of the command line after\r\nthe switch is processed as a command line, where the following logic is\r\nused to process quote (\") characters:\r\n\r\n 1. If all of the following conditions are met, then quote characters\r\n on the command line are preserved:\r\n\r\n - no /S switch\r\n - exactly two quote characters\r\n - no special characters between the two quote characters,\r\n where special is one of: &<>()@^|\r\n - there are one or more whitespace characters between the\r\n two quote characters\r\n - the string between the two quote characters is the name\r\n of an executable file.\r\n\r\n 2. Otherwise, old behavior is to see if the first character is\r\n a quote character and if so, strip the leading character and\r\n remove the last quote character on the command line, preserving\r\n any text after the last quote character.\r\n\r\nIf /D was NOT specified on the command line, then when CMD.EXE starts, it\r\nlooks for the following REG_SZ/REG_EXPAND_SZ registry variables, and if\r\neither or both are present, they are executed first.\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\AutoRun\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\AutoRun\r\n\r\nCommand Extensions are enabled by default. You may also disable\r\nextensions for a particular invocation by using the /E:OFF switch. You\r\ncan enable or disable extensions for all invocations of CMD.EXE on a\r\nmachine and/or user logon session by setting either or both of the\r\nfollowing REG_DWORD values in the registry using REGEDIT.EXE:\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\EnableExtensions\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\EnableExtensions\r\n\r\nto either 0x1 or 0x0. The user specific setting takes precedence over\r\nthe machine setting. The command line switches take precedence over the\r\nregistry settings.\r\n\r\nIn a batch file, the SETLOCAL ENABLEEXTENSIONS or DISABLEEXTENSIONS arguments\r\ntakes precedence over the /E:ON or /E:OFF switch. See SETLOCAL /? for details.\r\n\r\nThe command extensions involve changes and/or additions to the following\r\ncommands:\r\n\r\n DEL or ERASE\r\n COLOR\r\n CD or CHDIR\r\n MD or MKDIR\r\n PROMPT\r\n PUSHD\r\n POPD\r\n SET\r\n SETLOCAL\r\n ENDLOCAL\r\n IF\r\n FOR\r\n CALL\r\n SHIFT\r\n GOTO\r\n START (also includes changes to external command invocation)\r\n ASSOC\r\n FTYPE\r\n\r\nTo get specific details, type commandname /? to view the specifics.\r\n\r\nDelayed environment variable expansion is NOT enabled by default. You\r\ncan enable or disable delayed environment variable expansion for a\r\nparticular invocation of CMD.EXE with the /V:ON or /V:OFF switch. You\r\ncan enable or disable delayed expansion for all invocations of CMD.EXE on a\r\nmachine and/or user logon session by setting either or both of the\r\nfollowing REG_DWORD values in the registry using REGEDIT.EXE:\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\DelayedExpansion\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DelayedExpansion\r\n\r\nto either 0x1 or 0x0. The user specific setting takes precedence over\r\nthe machine setting. The command line switches take precedence over the\r\nregistry settings.\r\n\r\nIn a batch file the SETLOCAL ENABLEDELAYEDEXPANSION or DISABLEDELAYEDEXPANSION\r\narguments takes precedence over the /V:ON or /V:OFF switch. See SETLOCAL /?\r\nfor details.\r\n\r\nIf delayed environment variable expansion is enabled, then the exclamation\r\ncharacter can be used to substitute the value of an environment variable\r\nat execution time.\r\n\r\nYou can enable or disable file name completion for a particular\r\ninvocation of CMD.EXE with the /F:ON or /F:OFF switch. You can enable\r\nor disable completion for all invocations of CMD.EXE on a machine and/or\r\nuser logon session by setting either or both of the following REG_DWORD\r\nvalues in the registry using REGEDIT.EXE:\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\CompletionChar\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\PathCompletionChar\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\CompletionChar\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\PathCompletionChar\r\n\r\nwith the hex value of a control character to use for a particular\r\nfunction (e.g. 0x4 is Ctrl-D and 0x6 is Ctrl-F). The user specific\r\nsettings take precedence over the machine settings. The command line\r\nswitches take precedence over the registry settings.\r\n\r\nIf completion is enabled with the /F:ON switch, the two control\r\ncharacters used are Ctrl-D for directory name completion and Ctrl-F for\r\nfile name completion. To disable a particular completion character in\r\nthe registry, use the value for space (0x20) as it is not a valid\r\ncontrol character.\r\n\r\nCompletion is invoked when you type either of the two control\r\ncharacters. The completion function takes the path string to the left\r\nof the cursor appends a wild card character to it if none is already\r\npresent and builds up a list of paths that match. It then displays the\r\nfirst matching path. If no paths match, it just beeps and leaves the\r\ndisplay alone. Thereafter, repeated pressing of the same control\r\ncharacter will cycle through the list of matching paths. Pressing the\r\nShift key with the control character will move through the list\r\nbackwards. If you edit the line in any way and press the control\r\ncharacter again, the saved list of matching paths is discarded and a new\r\none generated. The same occurs if you switch between file and directory\r\nname completion. The only difference between the two control characters\r\nis the file completion character matches both file and directory names,\r\nwhile the directory completion character only matches directory names.\r\nIf file completion is used on any of the built in directory commands\r\n(CD, MD or RD) then directory completion is assumed.\r\n\r\nThe completion code deals correctly with file names that contain spaces\r\nor other special characters by placing quotes around the matching path.\r\nAlso, if you back up, then invoke completion from within a line, the\r\ntext to the right of the cursor at the point completion was invoked is\r\ndiscarded.\r\n\r\nThe special characters that require quotes are:\r\n <space>\r\n &()[]{}^=;!'+,`~\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\cmd.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\cmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cmdkey.exe-6CDC8E5DF04752235D5B4432EACC81A8": { "file_name": "cmdkey.exe", "file_path": "C:\\Windows\\SysWOW64\\cmdkey.exe", "hash_md5": "6CDC8E5DF04752235D5B4432EACC81A8", "hash_sha1": "858A6A5A56C473F3DDD0BC2CC6DFE30856442103", "hash_sha256": "DA8059F55EC94DFCB0E75FA43FA6BBC794070E50DEFC00216FC42710CFA58825", "hash_sha384": "726DB38E17D1538D2AA8CAC43E2E7C295AAE8DDB9CE4DDD05E63B423E72D73CB41B0F48AB467B8A90BEB31810F27B195", "hash_sha512": "85662F9A7E8820DE2CAB4FDACA1DCC9D3503F9A401EB83A4022B2F94090EE73133B453574FEA33117CC247134F0BE24F9D562C4B2F76C18C899D66759DB3C628", "hash_ssdeep": "384:h/HDVrL5yZsXfPPeN5qu7/btczd/xbGV9W3wW:VDCgmHLVchhGVC", "hash_imp": "19CAF11535B9CA1BEB2EF45EB8724422", "hash_pesha1": "3436CC79A0721F888C51F837315862DC33CB57E6", "hash_pe256": "9B0B6BA719A07051820857918A3312313429B7941B9C382B61285FD09C14F16D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Manager Command Line Utility", "meta_original_filename": "cmdkey.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/da8059f55ec94dfcb0e75fa43fa6bbc794070e50defc00216fc42710cfa58825/detection", "output": "\r\nCreates, displays, and deletes stored user names and passwords.\r\n\r\nThe syntax of this command is:\r\n\r\nCMDKEY [{/add | /generic}:targetname {/smartcard | /user:username {/pass{:password}}} | /delete{:targetname | /ras} | /list{:targetname}]\r\n\r\nExamples:\r\n\r\n To list available credentials:\r\n cmdkey /list\r\n cmdkey /list:targetname\r\n\r\n To create domain credentials:\r\n cmdkey /add:targetname /user:username /pass:password\r\n cmdkey /add:targetname /user:username /pass\r\n cmdkey /add:targetname /user:username\r\n cmdkey /add:targetname /smartcard\r\n \r\n To create generic credentials:\r\n The /add switch may be replaced by /generic to create generic credentials\r\n\r\n To delete existing credentials:\r\n cmdkey /delete:targetname\r\n\r\n To delete RAS credentials:\r\n cmdkey /delete /ras\r\n \r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\cmdkey.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cmdl32.exe-BD60DF43E6419AFE39B3FCBFB14077E7": { "file_name": "cmdl32.exe", "file_path": "C:\\Windows\\SysWOW64\\cmdl32.exe", "hash_md5": "BD60DF43E6419AFE39B3FCBFB14077E7", "hash_sha1": "ED73F4A5605FBDE7CA7454D8E851B6EB6F14DA11", "hash_sha256": "85B76DE4B1E44D375DF9D8D668B4BC4B91565A9BC652654C789A5EAD6D5E1AEC", "hash_sha384": "5695D998DF905488A9C5F5605D5D21DFC9989985A258FF4CAE395D10E29729DCA75862DB6DE7E0920DD9CAF96ADA118A", "hash_sha512": "537078C7BBA3F2E28152618F89A78F49B9D018CB9CE7F79DA974E0324D7EACA4D08273BE897616E8C891E182634895294B48B059C2AAA8F7A10F9B8FE6F4BB3C", "hash_ssdeep": "768:OTqHPEiucKttmhpGt7ZnPJ+GO7fRk+gogm4m5LXaqauwwiI/:OT+PEJcKtt+ye//4z0BiI", "hash_imp": "BA2BC70069F6B2E3580725012BA0CDE5", "hash_pesha1": "35727A5A79C3779A925870D6609B24AE85E25051", "hash_pe256": "CBBD67909F480504ACD15C1A8087947E1F1F5FAE1CFD6EEBDF65ED7750E1E852", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Connection Manager Auto-Download", "meta_original_filename": "CMDL32.EXE.MUI", "meta_product_name": "Microsoft(R) Connection Manager", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.19041.1 (WinBuild.160101.0800)", "meta_product_version": "7.2.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/85b76de4b1e44d375df9d8d668b4bc4b91565a9bc652654c789a5ead6d5e1aec/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\cmdl32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cmmon32.exe-DEC326E5B4D23503EA5176878DDDB683": { "file_name": "cmmon32.exe", "file_path": "C:\\Windows\\SysWOW64\\cmmon32.exe", "hash_md5": "DEC326E5B4D23503EA5176878DDDB683", "hash_sha1": "1BE1612863AD7147EA03047D8B934F89055F440E", "hash_sha256": "0032CD8F78472C45C2030441CB3446BAD5A632BB149DA0AC76F3B6FC2647BA33", "hash_sha384": "ECD7FC7E504A94DCE80D8437336569775B7AE8728E5151CB18D9503BD2BE46D1725BF406573A2FF930D100180A03D148", "hash_sha512": "EDA377BB4EF7947BA2E3F208AA6315E4AD697FBEBF770DD7F9B81E78B14B64ADA0C6F98ECD0037EAB6CDAA03D3701A961A41748D25220D0EC4F570E4C6C6CCAA", "hash_ssdeep": "768:THDnOXh9UwynApgeI3PG3nT3m6jgjF2SGFvFiJz5tKA+n3HJ:THD69ieI3PG3jmFadUN5tKA+3p", "hash_imp": "D3E67DC5271176E155375662C3682D3F", "hash_pesha1": "A2989E03285DC6D3CD7582BDEE854426F3679950", "hash_pe256": "E6445EB98FF12154887780AE8B22D9C4849CB2BDB885845CDFEF19293FA389A1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Connection Manager Monitor", "meta_original_filename": "CMMON32.exe.mui", "meta_product_name": "Microsoft(R) Connection Manager", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.19041.1 (WinBuild.160101.0800)", "meta_product_version": "7.2.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0032cd8f78472c45c2030441cb3446bad5a632bb149da0ac76f3b6fc2647ba33/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\cmmon32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cmstp.exe-D7AABFAB5BEFD53BA3A27BD48F3CC675": { "file_name": "cmstp.exe", "file_path": "C:\\Windows\\SysWOW64\\cmstp.exe", "hash_md5": "D7AABFAB5BEFD53BA3A27BD48F3CC675", "hash_sha1": "E1E2758E7427FFEF7D943EF1AE9024AF76A9142F", "hash_sha256": "2EB8278210434CED87711889BA19582B7A104190310D2A06F0855A9CF5772D11", "hash_sha384": "967297C5B85AB7B078D1D9557CFC56AF3C723ABFC7A4A3E100D712515F9DFB4E26AB8C6E2390982B277F9FF8960CFEEE", "hash_sha512": "AA1E9D9614808BBD53182702D1E0E6B13B70B9B42EBC8F7CAFBF4356D2EEAEE10955710503EDFE485E095335959DB92D1F123588A536FC172E2CDB03F37B64FF", "hash_ssdeep": "1536:kvsrU8tbNyQmvDV7zdIpCFo80PA3OBk62FH/IwRw1lqCDo:kErU8tbUQmvDjYndW/IwRw1MC", "hash_imp": "1BFCD0AAD19887A1035BF48D79219292", "hash_pesha1": "E457F5FE425186AB22A3E1AC153AAB2B939DBEFA", "hash_pe256": "32E9407D2543E931B9BCBDD877544C07FAAF40B31400590BB72E55DB819C0F57", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Connection Manager Profile Installer", "meta_original_filename": "CMSTP.EXE.MUI", "meta_product_name": "Microsoft(R) Connection Manager", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.19041.1 (WinBuild.160101.0800)", "meta_product_version": "7.2.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/2eb8278210434ced87711889ba19582b7a104190310d2a06f0855a9cf5772d11/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\cmstp.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "Connection Manager Profile Installer", "runtime_modules": [ "C:\\Windows\\SysWOW64\\cmstp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "colorcpl.exe-DB71E132EBF1FEB6E93E8A2A0F0C903D": { "file_name": "colorcpl.exe", "file_path": "C:\\Windows\\SysWOW64\\colorcpl.exe", "hash_md5": "DB71E132EBF1FEB6E93E8A2A0F0C903D", "hash_sha1": "7E9B267FAEE4593DF44E41B0A5FB900DE62060FB", "hash_sha256": "2E5E0B8FE1C6A6314145E404C46ACC4FF227AD63D0F2765D5458D0C4CB80C110", "hash_sha384": "89E250EDBE6666745DA30938A521C0839709A69935C5AAEA76E7B8825C7650CC937E0320E9F717B0B56770F4754CAEA2", "hash_sha512": "9F3B00A452B5D528AC27EC0D100A938753A70A300E7EADC40A3E4456C6223FD8D61393D3EE6995F2D6D0ADEC4AE48296B4C04ABB89A28FECF82DEC5B0975583E", "hash_ssdeep": "1536:fPbIPfSbS9vMBN7rQOJ7CFToTCzhcRguhwxTyPCb3lZpdym4dy7p:nEXlvq7jSP1cR2prbpdCY9", "hash_imp": "FE642844D8BB41A0A5162838127D9366", "hash_pesha1": "EA38FC2A99AC6B8307C468863F645DD89AD69A1C", "hash_pe256": "9ED1874F0D6813096B80A3E370308A0068F52C2ED0CC1DFFB919D5769995F50B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Color Control Panel", "meta_original_filename": "colorcpl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/2e5e0b8fe1c6a6314145e404c46acc4ff227ad63d0f2765d5458d0c4cb80c110/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\colorcpl.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\colorui.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "Color Management", "runtime_modules": [ "C:\\Windows\\SysWOW64\\colorcpl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "comp.exe-712EF348F7032AA1C80D24600BA5452D": { "file_name": "comp.exe", "file_path": "C:\\Windows\\SysWOW64\\comp.exe", "hash_md5": "712EF348F7032AA1C80D24600BA5452D", "hash_sha1": "CFC9150CA0300B0103DA49CE21D8DCA6DCAE13AC", "hash_sha256": "758A3A677F150ECB7B123848A5F227A1B436D13B61191377E74A456535708908", "hash_sha384": "AAC283AEAB4B1550A01D4D97D0D225C0B242E718E2D44F3EA291173AAFCDAD78293A4F6E7FB0318D422DB0D829364F18", "hash_sha512": "1692E8B47AD67B0326936C949D655DD86E8AB9E19950F94C165E2133586A43C399B7FAEFCF3A20503699778F232D3EBE713B4ED0D0B70624627D72936F07D9E5", "hash_ssdeep": "384:DiLW3NrHPDfwgGvZYsQgKNWiHiNeZPWqZ2guEA68NDWccWFsk:DiLW3NroRQgaWiHiNYbjD8RU", "hash_imp": "FFD97A520B1CE23CD1FC4B5F8E5BCB3C", "hash_pesha1": "4B824386D98960932A72344F486AFA3E5F0AA0DE", "hash_pe256": "4BBFBEBEB24307829D5161B65BDDC3ACD01F0EED12E3A481BE3036426B267D57", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Compare Utility", "meta_original_filename": "Comp.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/758a3a677f150ecb7b123848a5f227a1b436d13b61191377e74a456535708908/detection", "output": "Compares the contents of two files or sets of files.\r\n\r\nCOMP [data1] [data2] [/D] [/A] [/L] [/N=number] [/C] [/OFF[LINE]] [/M]\r\n\r\n data1 Specifies location and name(s) of first file(s) to compare.\r\n data2 Specifies location and name(s) of second files to compare.\r\n /D Displays differences in decimal format.\r\n /A Displays differences in ASCII characters.\r\n /L Displays line numbers for differences.\r\n /N=number Compares only the first specified number of lines in each file.\r\n /C Disregards case of ASCII letters when comparing files.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n /M Do not prompt for compare more files.\r\n\r\nTo compare sets of files, use wildcards in data1 and data2 parameters.\r\n", "error": "Name of second file to compare: ", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\ulib.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\comp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "compact.exe-5CB107F69062D6D387F4F7A14737220E": { "file_name": "compact.exe", "file_path": "C:\\Windows\\SysWOW64\\compact.exe", "hash_md5": "5CB107F69062D6D387F4F7A14737220E", "hash_sha1": "5E38AB6290379794F88655B2D68A361574F07482", "hash_sha256": "E8DDA2E35381B17E9619EA49305B53E8321F56947D19E981012D300428E3B0B1", "hash_sha384": "90BC8C1B44F7CF4C68E47C5DE844A4E7A7B4A28708687ED0BC2E4FFCB9CA25106F74402068A189205B2C8EB368A957A0", "hash_sha512": "95212006110772E675A683DC058F3DC95EF8CB7A9C9D11B77E02DD108E6697A718F618EEE5671B0A512208990EE7A301615229B9BD50A6228B1A37FEFA58EAFA", "hash_ssdeep": "768:RVZQMj1pHpIb5Rtt+BESwRdIdGwTH/cat9fgFrDxZNRjk8G8jHxuMlTK/ktHq5u5:RVZQMj1pHpE5R/oozrDDlHUkTK/ktHqs", "hash_imp": "F62B024CE3F1C2441731CA2486368509", "hash_pesha1": "C10C78BE8A56F0DB36A4900B3FFF6AD4EFB264B9", "hash_pe256": "4333E0CC9129552584B959A47BB78669708AB09DC0A6721D777554EC588AD9C8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Compress Utility", "meta_original_filename": "COMPACT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e8dda2e35381b17e9619ea49305b53e8321f56947d19e981012d300428e3b0b1/detection", "output": "Displays or alters the compression of files on NTFS partitions.\r\n\r\nCOMPACT [/C | /U] [/S[:dir]] [/A] [/I] [/F] [/Q] [/EXE[:algorithm]]\r\n [/CompactOs[:option] [/WinDir:dir]] [filename [...]]\r\n\r\n /C Compresses the specified files. Directories will be marked\r\n so that files added afterward will be compressed unless /EXE\r\n is specified.\r\n /U Uncompresses the specified files. Directories will be marked\r\n so that files added afterward will not be compressed. If\r\n /EXE is specified, only files compressed as executables will\r\n be uncompressed; if this is omitted, only NTFS compressed\r\n files will be uncompressed.\r\n /S Performs the specified operation on files in the given\r\n directory and all subdirectories. Default \"dir\" is the\r\n current directory.\r\n /A Displays files with the hidden or system attributes. These\r\n files are omitted by default.\r\n /I Continues performing the specified operation even after errors\r\n have occurred. By default, COMPACT stops when an error is\r\n encountered.\r\n /F Forces the compress operation on all specified files, even\r\n those which are already compressed. Already-compressed files\r\n are skipped by default.\r\n /Q Reports only the most essential information.\r\n /EXE Use compression optimized for executable files which are read\r\n frequently and not modified. Supported algorithms are:\r\n XPRESS4K (fastest) (default)\r\n XPRESS8K\r\n XPRESS16K\r\n LZX (most compact)\r\n /CompactOs Set or query the system's compression state. Supported options are:\r\n query - Query the system's Compact state.\r\n always - Compress all OS binaries and set the system state to Compact\r\n which remains unless administrator changes it.\r\n never - Uncompress all OS binaries and set the system state to non\r\n Compact which remains unless administrator changes it.\r\n /WinDir Used with /CompactOs:query, when querying the offline OS. Specifies\r\n the directory where Windows is installed.\r\n filename Specifies a pattern, file, or directory.\r\n\r\n Used without parameters, COMPACT displays the compression state of\r\n the current directory and any files it contains. You may use multiple\r\n filenames and wildcards. You must put spaces between multiple\r\n parameters.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\compact.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ComputerDefaults.exe-CFA65B13918526579371C138108A7DDB": { "file_name": "ComputerDefaults.exe", "file_path": "C:\\Windows\\SysWOW64\\ComputerDefaults.exe", "hash_md5": "CFA65B13918526579371C138108A7DDB", "hash_sha1": "28BC560C542C405E08001F95C4EA0511E5211035", "hash_sha256": "4C70FEA1C4F9B78955EB840C11C6C81F1D860485E090526A8E8176D98B1BE3D6", "hash_sha384": "3989AB6092EE411EC1631EE668FDE3013DDF38CC2723D44A84FA1B54C9869855E469D51244D568DFCCF4406E3077B9ED", "hash_sha512": "7AD417E862C38F1032B300735C00050435F0DD1D816E93B9A466ADF3BC092BE770EBF59C1617DB2281C7CF982A75E6C93D927D5784132AA2C6292F3E950ECA88", "hash_ssdeep": "1536:lxNHwdSsszF8tbVBATYqyrURDoq4OZZZLlCIibz2:VHwdSfSfBATYXwRD68wbz2", "hash_imp": "DCF24A295065FCFB6B7F451585917C44", "hash_pesha1": "0B74426EBDF2F11D7BA0FC89E4C04B53B90A26E4", "hash_pe256": "330CA68230D8EFE439E8E6F896C43A8B0891AE1E4FF288959E4922DBDE351C74", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Set Program Access and Computer Defaults Control Panel", "meta_original_filename": "ComputerDefaults.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/4c70fea1c4f9b78955eb840c11c6c81f1d860485e090526a8e8176d98b1be3d6/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ComputerDefaults.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "control.exe-4DBD69D4C9DA5AAAC731F518EF8EBEA0": { "file_name": "control.exe", "file_path": "C:\\Windows\\SysWOW64\\control.exe", "hash_md5": "4DBD69D4C9DA5AAAC731F518EF8EBEA0", "hash_sha1": "912DB82D61915F34E60FDCEB39963E71B9FA0546", "hash_sha256": "D923F812BF0191F3344DE6CD5FCEAF6C7B2F6961F637C74C2AA329FB3F8CA6C5", "hash_sha384": "D43646A184E6C50FC465B345C1F979A12E9A48F33243901B775BD6181265035A4ABB7308BBE5E2327B41D4BDB26EF668", "hash_sha512": "5756AAE6F17009A550F5C1FCF51A16F4B51675B16E2E548C5BBBEA64FBE5CD59BF9173205310D40E0AEF1605BDF44CC4C21577DA529164CC489A94FD0894D0AB", "hash_ssdeep": "3072:GcDa+r2qCGcsfcVd0g7Sp5+1k12b/Af885RK:t++r5crd/7+5+1kf15", "hash_imp": "E429F70455F107F91CC4781D386989F0", "hash_pesha1": "7EF5E339B38917744B80128789AB6234D049FEA6", "hash_pe256": "B87507FDB866B6CA95DB02DFF75AF3B9B747003B4761C579D58FFBA31EE6492F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Control Panel", "meta_original_filename": "CONTROL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "1/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d923f812bf0191f3344de6cd5fceaf6c7b2f6961f637c74c2aa329fb3f8ca6c5/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\control.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "convert.exe-2B1AC34AB72C95793CFE7E936F15389D": { "file_name": "convert.exe", "file_path": "C:\\Windows\\SysWOW64\\convert.exe", "hash_md5": "2B1AC34AB72C95793CFE7E936F15389D", "hash_sha1": "A964322A5C12A99FC7C8CE5EF48F98C3E2CA01CE", "hash_sha256": "2598BE0686DD5BF41F3270483A210A33DFD190A902021ADF2407BED8A9C5C84D", "hash_sha384": "70CDC5758D28ED0768785E595CCA86F9030F031594C27CFDCB1C99EE194037873BA11BC1A083F80B2412EDF83E553208", "hash_sha512": "D14702345862B4DB2E765AEDB312621288A25BA8C45B7FBA74E2FA17A1C91B779806DBCB4CC0482D3611143E7F1B8E17E224EF2CD654F42D5EFC1B01D4B97144", "hash_ssdeep": "384:aJloU9AHup2V7CV5SugYcFl/sX6XvwTaAztbNDWCqW/L:6loPHupWBugYMYFZbjj", "hash_imp": "67458FAEC238A61DD838DD54CA17F2A9", "hash_pesha1": "1EB15318DA53EC1CC9D30B401D3B480C0883A2D1", "hash_pe256": "02D0C7A2752F3461DC382AE1BFD1048B0F22476C58E86196AD7695F192E4287E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File System Conversion Utility", "meta_original_filename": "CONVERT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2598be0686dd5bf41f3270483a210a33dfd190a902021adf2407bed8a9c5c84d/detection", "output": "Converts a FAT volume to NTFS.\r\n\r\nCONVERT volume /FS:NTFS [/V] [/CvtArea:filename] [/NoSecurity] [/X]\r\n\r\n\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name.\r\n /FS:NTFS Specifies that the volume will be converted to NTFS.\r\n /V Specifies that Convert will be run in verbose mode.\r\n /CvtArea:filename\r\n Specifies a contiguous file in the root directory\r\n that will be the place holder for NTFS system files.\r\n /NoSecurity Specifies that the security settings on the converted\r\n files and directories allow access by all users.\r\n /X Forces the volume to dismount first if necessary.\r\n All open handles to the volume will not be valid.\r\n", "error": "Invalid drive specification.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\convert.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "CredentialUIBroker.exe-2445C61870E687B69C3A3238886071DE": { "file_name": "CredentialUIBroker.exe", "file_path": "C:\\Windows\\SysWOW64\\CredentialUIBroker.exe", "hash_md5": "2445C61870E687B69C3A3238886071DE", "hash_sha1": "5C384E36F09F60D54B492344DDA85C77D7D90CA2", "hash_sha256": "88435303FD2A0B7D0B03A017238ABA5C46B1F75DBCD9ECB8B35756BE2B444BCD", "hash_sha384": "34127E4C6BC98CA5F1B4C6F93E82436D961167D979CD247B0F3CBC187F54BA020DD4BB201EF04FBB6E1FB0C4FE84CDFF", "hash_sha512": "2782CC9A3E5E957021D09CED0A985760F2AA7F26D1BD8D56A84D33D8D17FF1F7B9A8F7DCB2D87878C1BFAF3D604721A9D10A5BC762F6993781F27A29566CBD25", "hash_ssdeep": "3072:faCt7OmCepV69VDw2mbL+GKRQVLa9PRuFnUotf7Gtg:BiwtKRsOvuBxf7Gm", "hash_imp": "7892C039093F24D042274218024F00F3", "hash_pesha1": "5C41664B9D8F27E80229E33932B174D7FC158A7F", "hash_pe256": "95C487040C4D0EAEC5EFDF785CCBB4BC4659F429059EC7661DB93CD52778D059", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Manager UI Host", "meta_original_filename": "CredentialUIBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/88435303fd2a0b7d0b03a017238aba5c46b1f75dbcd9ecb8b35756be2b444bcd/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\CredentialUIBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "credwiz.exe-9B726550E4C82BBEB045150E75FEE720": { "file_name": "credwiz.exe", "file_path": "C:\\Windows\\SysWOW64\\credwiz.exe", "hash_md5": "9B726550E4C82BBEB045150E75FEE720", "hash_sha1": "E42D4D119E7ED4104F89E9242439003328320540", "hash_sha256": "2156279EAC34CC622F755766DE61090290FF8B0960EBB46B03038AE321B3566D", "hash_sha384": "C741910F4F9D932244AA155C0B596B59218100B2DDEFFF772EAFDA72FE8D873C186022B3F3565805CBC5A8A29E94D283", "hash_sha512": "BC919B76D0DC34AF5156D170BCDC80D46218810D144FCCEBA7ACDF0AA6069C9B66569750CDD2DEDC4B503A0A823C57CEB169F0441E552161900E6E7601EFB3C9", "hash_ssdeep": "384:yuFGSBYpI5xk2SJUkU3ij/PofixfO/gJ+N+4sV6Vey6Yr9jKmZzPzWN5WrNuimn:v1YbKyj/P4InJBjk6A9j1Zbe5/n", "hash_imp": "7811C1109D45B9069E28DFEE0C0F979D", "hash_pesha1": "36778A1FD289AB857D4C9C85FF0C1C10D2AC5609", "hash_pe256": "C367306613F22705BD7CE15809FC5716829AE1451DAAFC4DE869145329D043DC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Backup and Restore Wizard", "meta_original_filename": "credwiz.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2156279eac34cc622f755766de61090290ff8b0960ebb46b03038ae321b3566d/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\credwiz.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\credwiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Stored User Names and Passwords" }, "cscript.exe-13783FF4A2B614D7FBD58F5EEBDEDEF6": { "file_name": "cscript.exe", "file_path": "C:\\Windows\\SysWOW64\\cscript.exe", "hash_md5": "13783FF4A2B614D7FBD58F5EEBDEDEF6", "hash_sha1": "85CE2BC3E099FC6BD46CDB1DB95FE75E3572E364", "hash_sha256": "A80E2D4B10E53C5F1D1BB41FD117FC5B6C358B87E3B2C197FC9AF484BC44E5C6", "hash_sha384": "1752578D54ED37B1124CCE8EA6752436EAB94B94F695AA19EF9E4BDCF7647322336350863D5BAD0D792D8174721E5F08", "hash_sha512": "1162EA4F7BF5A4A80365A5D40CA1451532E3D267946B5D3A17477B20BAB6F2CF625A85C0C242DD0111745C24EF5FD013F152CFA1E3B69DD9ABC76C8C882AEF1D", "hash_ssdeep": "3072:FIm9CL5YHnh8TYUKqicfAyRG6NFujTxEjUhqkyqTxt/m:h9CKSTfKqicOjIxklT", "hash_imp": "E4D90F9825B64532B46F2C87EC5B0A16", "hash_pesha1": "2245EA13E520F62E5EE9C387CFF445622A6E9AFC", "hash_pe256": "E32B95C6E19F42354CAEC5A7E6F0F6199035D974421E8548517FD17A4AA909CE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Console Based Script Host", "meta_original_filename": "cscript.exe", "meta_product_name": "Microsoft Windows Script Host", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.812.10240.16384", "meta_product_version": "5.812.10240.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a80e2d4b10e53c5f1d1bb41fd117fc5b6c358b87e3b2c197fc9af484bc44e5c6/detection", "output": "Microsoft (R) Windows Script Host Version 5.812\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: CScript scriptname.extension [option...] [arguments...]\r\n\r\nOptions:\r\n //B Batch mode: Suppresses script errors and prompts from displaying\r\n //D Enable Active Debugging\r\n //E:engine Use engine for executing script\r\n //H:CScript Changes the default script host to CScript.exe\r\n //H:WScript Changes the default script host to WScript.exe (default)\r\n //I Interactive mode (default, opposite of //B)\r\n //Job:xxxx Execute a WSF job\r\n //Logo Display logo (default)\r\n //Nologo Prevent logo display: No banner will be shown at execution time\r\n //S Save current command line options for this user\r\n //T:nn Time out in seconds: Maximum time a script is permitted to run\r\n //X Execute script in debugger\r\n //U Use Unicode for redirected I/O from the console\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\cscript.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ctfmon.exe-1B19D302D7FFA3D0901B3D990A4E8E12": { "file_name": "ctfmon.exe", "file_path": "C:\\Windows\\SysWOW64\\ctfmon.exe", "hash_md5": "1B19D302D7FFA3D0901B3D990A4E8E12", "hash_sha1": "1C06DBE26185E2956373118EDC7543EE5FE9B6EB", "hash_sha256": "33AD4738B6342C9CC2DA01402B26A4424C0ADFDDDE9936D8926A86BF8D80D44F", "hash_sha384": "51041DBF8CF4DD7BA2CB445D58DA97125335C848520978BAC6B9A9A7EC3911C945F532207841A3051822A9A2DAD9AB58", "hash_sha512": "348405010F1AF06ADE0F4B9A27144E783C48777E93D0EFD2D2F42C3DBAC34DD9CA54EC7618120384F36B1A34BC0BCC0A38808080B8D6866C010743E327890293", "hash_ssdeep": "96:K6Qq4eRAWEKAp2hJH3DGjoK6HU9osQshDJ7pRKRcLEWhgWwUeq:K6Qq4q2JUU9osQsniWhgW", "hash_imp": "A0DF2CAE30CD48F978A8D80039C738E5", "hash_pesha1": "025E1EB147C4D753E8728EBD862B3B67CE4F10F1", "hash_pe256": "D70A05F4239E96CF7AD31104988A0DE8925AF34F7E5269171CF0276EFE1F205C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CTF Loader", "meta_original_filename": "CTFMON.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/33ad4738b6342c9cc2da01402b26a4424c0adfddde9936d8926a86bf8d80d44f/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ctfmon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cttune.exe-E515AF722F75E1A5708B532FAA483333": { "file_name": "cttune.exe", "file_path": "C:\\Windows\\SysWOW64\\cttune.exe", "hash_md5": "E515AF722F75E1A5708B532FAA483333", "hash_sha1": "6840CC68AE55DC00F07157C35A1EF134C98FFE53", "hash_sha256": "07985748945405D62508F31F933A671B24CAA2D38DA08E12DBB7F6060C26446B", "hash_sha384": "D412B9C7E56B0AC1AD438B491544E38B87DEE3F2D874037A9575FE318C80500AD3ADDE1B3C0C49258270E61EFE273517", "hash_sha512": "4FAC7BF851B983128D71A1F01BA4F5CACFFA8941A63D78A875FEE791131A416A107752E7432527D64DF833267238178623B5333EE44C79FA1623A5E94D529F4C", "hash_ssdeep": "1536:h2fR+sBgVL4nCXjsEsmVC42qhDZZru4Ic:heR+OyLyCXjuyV9urc", "hash_imp": "F0FE6035F966BA8EBBFAF27107E1EAF4", "hash_pesha1": "EB85BCDC7807E34DBB6B41216BE25FB8DB986298", "hash_pe256": "5ACFA664BE4EC8FEA694F8D4174232D05DE15235E3694D000D5AF814566B8D95", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ClearType Tuner", "meta_original_filename": "CTTUNE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/07985748945405d62508f31f933a671b24caa2d38da08e12dbb7f6060c26446b/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\cttune.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\cttune.exe.mun": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\cttune.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "ClearType Text Tuner" }, "cttunesvr.exe-FFC7FCCA38C8248A1EBF8C4D20CA8D33": { "file_name": "cttunesvr.exe", "file_path": "C:\\Windows\\SysWOW64\\cttunesvr.exe", "hash_md5": "FFC7FCCA38C8248A1EBF8C4D20CA8D33", "hash_sha1": "EB6712BF1D216764F0B7AD626B51FB8871BDA0E9", "hash_sha256": "BD23F7BAA3EA5D4303FD11BBF58132C9732DFCFD4EC61ADC0033AB7556B8B8B9", "hash_sha384": "B099FD33F2D1004D660BD88BD655361227DD210AC83CE3FED19973441DB30743D4B063B0B2C920418221DFA82E08F472", "hash_sha512": "6AB73D95BDE4E727875861AB2697BEC43730EDF40C1800D9118513C5B85111DE05DB85D44CB745FCE1A47A8B59762EC85E31C7346B373C33203C38ACACDAB2A5", "hash_ssdeep": "768:iyq+IN5iphUL9jsspsuwqJk1vjsiMzr1avhTku:iyqN5ipisspsuwqJk1vjIEvdku", "hash_imp": "C888235856577B905938185E0F1CDC12", "hash_pesha1": "8F2F356F754E3E32F98BAB89AD0BAD99370A5F9F", "hash_pe256": "B0D7944836BA32D194B104379E232BB5F9E9EC9405734787AE17418191F1547D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ClearType Tuner", "meta_original_filename": "CTTUNESVR.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/bd23f7baa3ea5d4303fd11bbf58132c9732dfcfd4ec61adc0033ab7556b8b8b9/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\cttunesvr.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\cttunesvr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "curl.exe-4329254E74AD91D047E3CEDCC7C138C3": { "file_name": "curl.exe", "file_path": "C:\\Windows\\SysWOW64\\curl.exe", "hash_md5": "4329254E74AD91D047E3CEDCC7C138C3", "hash_sha1": "4D1EF7146365C25A518549811FEADA3A949B2361", "hash_sha256": "126217CB9E37D9CF3B254E13A4E2B257FFFFAE54728892D00E868D56DE726071", "hash_sha384": "611FD29E435BB8744088CE608FAB7DC183F36877A65763B41D141C56FED6BB7E7F588EB088C86BE96BBAB6E9E4598D64", "hash_sha512": "77F25E22536DCC1DDDC0E7D4A309D8535E910D39FF3B5A390BC116E4602DE4D07312EDC4D87A654D8EBF93CCCE5EA5EEDD80E5F758283BD92629686166F9DC55", "hash_ssdeep": "6144:L9a6KNoetW6yge/7hGgY1b2OFpG1PisLzZhKt8/6pSd1bG/e/XZwl6UId0Vv/Rk9:LvetW6yl/7hR8GNisLzLKtA6p7mVU20A", "hash_imp": "1FAE21CBD5A980A07170C74DE0A3B416", "hash_pesha1": "03484C0DEB8E7D033D060B9875E380B3337D37CE", "hash_pe256": "BA6729824B4B3DEC1A26ABD486CB01CB1EBBC188E6E9F092AF93ECB42138DABD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "The curl executable", "meta_original_filename": "curl.exe", "meta_product_name": "The curl executable", "meta_company_name": "curl, https://curl.haxx.se/", "meta_file_version": "7.55.1", "meta_product_version": "7.55.1", "meta_language": "English (United States)", "meta_legal_copyright": " 1996 - 2017 Daniel Stenberg, <daniel@haxx.se>.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/126217cb9e37d9cf3b254e13a4e2b257ffffae54728892d00e868d56de726071/detection", "output": "Usage: curl [options...] <url>\r\n --abstract-unix-socket <path> Connect via abstract Unix domain socket\r\n --anyauth Pick any authentication method\r\n -a, --append Append to target file when uploading\r\n --basic Use HTTP Basic Authentication\r\n --cacert <CA certificate> CA certificate to verify peer against\r\n --capath <dir> CA directory to verify peer against\r\n -E, --cert <certificate[:password]> Client certificate file and password\r\n --cert-status Verify the status of the server certificate\r\n --cert-type <type> Certificate file type (DER/PEM/ENG)\r\n --ciphers <list of ciphers> SSL ciphers to use\r\n --compressed Request compressed response\r\n -K, --config <file> Read config from a file\r\n --connect-timeout <seconds> Maximum time allowed for connection\r\n --connect-to <HOST1:PORT1:HOST2:PORT2> Connect to host\r\n -C, --continue-at <offset> Resumed transfer offset\r\n -b, --cookie <data> Send cookies from string/file\r\n -c, --cookie-jar <filename> Write cookies to <filename> after operation\r\n --create-dirs Create necessary local directory hierarchy\r\n --crlf Convert LF to CRLF in upload\r\n --crlfile <file> Get a CRL list in PEM format from the given file\r\n -d, --data <data> HTTP POST data\r\n --data-ascii <data> HTTP POST ASCII data\r\n --data-binary <data> HTTP POST binary data\r\n --data-raw <data> HTTP POST data, '@' allowed\r\n --data-urlencode <data> HTTP POST data url encoded\r\n --delegation <LEVEL> GSS-API delegation permission\r\n --digest Use HTTP Digest Authentication\r\n -q, --disable Disable .curlrc\r\n --disable-eprt Inhibit using EPRT or LPRT\r\n --disable-epsv Inhibit using EPSV\r\n --dns-interface <interface> Interface to use for DNS requests\r\n --dns-ipv4-addr <address> IPv4 address to use for DNS requests\r\n --dns-ipv6-addr <address> IPv6 address to use for DNS requests\r\n --dns-servers <addresses> DNS server addrs to use\r\n -D, --dump-header <filename> Write the received headers to <filename>\r\n --egd-file <file> EGD socket path for random data\r\n --engine <name> Crypto engine to use\r\n --expect100-timeout <seconds> How long to wait for 100-continue\r\n -f, --fail Fail silently (no output at all) on HTTP errors\r\n --fail-early Fail on first transfer error, do not continue\r\n --false-start Enable TLS False Start\r\n -F, --form <name=content> Specify HTTP multipart POST data\r\n --form-string <name=string> Specify HTTP multipart POST data\r\n --ftp-account <data> Account data string\r\n --ftp-alternative-to-user <command> String to replace USER [name]\r\n --ftp-create-dirs Create the remote dirs if not present\r\n --ftp-method <method> Control CWD usage\r\n --ftp-pasv Use PASV/EPSV instead of PORT\r\n -P, --ftp-port <address> Use PORT instead of PASV\r\n --ftp-pret Send PRET before PASV\r\n --ftp-skip-pasv-ip Skip the IP address for PASV\r\n --ftp-ssl-ccc Send CCC after authenticating\r\n --ftp-ssl-ccc-mode <active/passive> Set CCC mode\r\n --ftp-ssl-control Require SSL/TLS for FTP login, clear for transfer\r\n -G, --get Put the post data in the URL and use GET\r\n -g, --globoff Disable URL sequences and ranges using {} and []\r\n -I, --head Show document info only\r\n -H, --header <header/@file> Pass custom header(s) to server\r\n -h, --help This help text\r\n --hostpubmd5 <md5> Acceptable MD5 hash of the host public key\r\n -0, --http1.0 Use HTTP 1.0\r\n --http1.1 Use HTTP 1.1\r\n --http2 Use HTTP 2\r\n --http2-prior-knowledge Use HTTP 2 without HTTP/1.1 Upgrade\r\n --ignore-content-length Ignore the size of the remote resource\r\n -i, --include Include protocol response headers in the output\r\n -k, --insecure Allow insecure server connections when using SSL\r\n --interface <name> Use network INTERFACE (or address)\r\n -4, --ipv4 Resolve names to IPv4 addresses\r\n -6, --ipv6 Resolve names to IPv6 addresses\r\n -j, --junk-session-cookies Ignore session cookies read from file\r\n --keepalive-time <seconds> Interval time for keepalive probes\r\n --key <key> Private key file name\r\n --key-type <type> Private key file type (DER/PEM/ENG)\r\n --krb <level> Enable Kerberos with security <level>\r\n --libcurl <file> Dump libcurl equivalent code of this command line\r\n --limit-rate <speed> Limit transfer speed to RATE\r\n -l, --list-only List only mode\r\n --local-port <num/range> Force use of RANGE for local port numbers\r\n -L, --location Follow redirects\r\n --location-trusted Like --location, and send auth to other hosts\r\n --login-options <options> Server login options\r\n --mail-auth <address> Originator address of the original email\r\n --mail-from <address> Mail from this address\r\n --mail-rcpt <address> Mail from this address\r\n -M, --manual Display the full manual\r\n --max-filesize <bytes> Maximum file size to download\r\n --max-redirs <num> Maximum number of redirects allowed\r\n -m, --max-time <time> Maximum time allowed for the transfer\r\n --metalink Process given URLs as metalink XML file\r\n --negotiate Use HTTP Negotiate (SPNEGO) authentication\r\n -n, --netrc Must read .netrc for user name and password\r\n --netrc-file <filename> Specify FILE for netrc\r\n --netrc-optional Use either .netrc or URL\r\n -:, --next Make next URL use its separate set of options\r\n --no-alpn Disable the ALPN TLS extension\r\n -N, --no-buffer Disable buffering of the output stream\r\n --no-keepalive Disable TCP keepalive on the connection\r\n --no-npn Disable the NPN TLS extension\r\n --no-sessionid Disable SSL session-ID reusing\r\n --noproxy <no-proxy-list> List of hosts which do not use proxy\r\n --ntlm Use HTTP NTLM authentication\r\n --ntlm-wb Use HTTP NTLM authentication with winbind\r\n --oauth2-bearer <token> OAuth 2 Bearer Token\r\n -o, --output <file> Write to file instead of stdout\r\n --pass <phrase> Pass phrase for the private key\r\n --path-as-is Do not squash .. sequences in URL path\r\n --pinnedpubkey <hashes> FILE/HASHES Public key to verify peer against\r\n --post301 Do not switch to GET after following a 301\r\n --post302 Do not switch to GET after following a 302\r\n --post303 Do not switch to GET after following a 303\r\n --preproxy [protocol://]host[:port] Use this proxy first\r\n -#, --progress-bar Display transfer progress as a bar\r\n --proto <protocols> Enable/disable PROTOCOLS\r\n --proto-default <protocol> Use PROTOCOL for any URL missing a scheme\r\n --proto-redir <protocols> Enable/disable PROTOCOLS on redirect\r\n -x, --proxy [protocol://]host[:port] Use this proxy\r\n --proxy-anyauth Pick any proxy authentication method\r\n --proxy-basic Use Basic authentication on the proxy\r\n --proxy-cacert <file> CA certificate to verify peer against for proxy\r\n --proxy-capath <dir> CA directory to verify peer against for proxy\r\n --proxy-cert <cert[:passwd]> Set client certificate for proxy\r\n --proxy-cert-type <type> Client certificate type for HTTS proxy\r\n --proxy-ciphers <list> SSL ciphers to use for proxy\r\n --proxy-crlfile <file> Set a CRL list for proxy\r\n --proxy-digest Use Digest authentication on the proxy\r\n --proxy-header <header/@file> Pass custom header(s) to proxy\r\n --proxy-insecure Do HTTPS proxy connections without verifying the proxy\r\n --proxy-key <key> Private key for HTTPS proxy\r\n --proxy-key-type <type> Private key file type for proxy\r\n --proxy-negotiate Use HTTP Negotiate (SPNEGO) authentication on the proxy\r\n --proxy-ntlm Use NTLM authentication on the proxy\r\n --proxy-pass <phrase> Pass phrase for the private key for HTTPS proxy\r\n --proxy-service-name <name> SPNEGO proxy service name\r\n --proxy-ssl-allow-beast Allow security flaw for interop for HTTPS proxy\r\n --proxy-tlsauthtype <type> TLS authentication type for HTTPS proxy\r\n --proxy-tlspassword <string> TLS password for HTTPS proxy\r\n --proxy-tlsuser <name> TLS username for HTTPS proxy\r\n --proxy-tlsv1 Use TLSv1 for HTTPS proxy\r\n -U, --proxy-user <user:password> Proxy user and password\r\n --proxy1.0 <host[:port]> Use HTTP/1.0 proxy on given port\r\n -p, --proxytunnel Operate through a HTTP proxy tunnel (using CONNECT)\r\n --pubkey <key> SSH Public key file name\r\n -Q, --quote Send command(s) to server before transfer\r\n --random-file <file> File for reading random data from\r\n -r, --range <range> Retrieve only the bytes within RANGE\r\n --raw Do HTTP \"raw\"; no transfer decoding\r\n -e, --referer <URL> Referrer URL\r\n -J, --remote-header-name Use the header-provided filename\r\n -O, --remote-name Write output to a file named as the remote file\r\n --remote-name-all Use the remote file name for all URLs\r\n -R, --remote-time Set the remote file's time on the local output\r\n -X, --request <command> Specify request command to use\r\n --request-target Specify the target for this request\r\n --resolve <host:port:address> Resolve the host+port to this address\r\n --retry <num> Retry request if transient problems occur\r\n --retry-connrefused Retry on connection refused (use with --retry)\r\n --retry-delay <seconds> Wait time between retries\r\n --retry-max-time <seconds> Retry only within this period\r\n --sasl-ir Enable initial response in SASL authentication\r\n --service-name <name> SPNEGO service name\r\n -S, --show-error Show error even when -s is used\r\n -s, --silent Silent mode\r\n --socks4 <host[:port]> SOCKS4 proxy on given host + port\r\n --socks4a <host[:port]> SOCKS4a proxy on given host + port\r\n --socks5 <host[:port]> SOCKS5 proxy on given host + port\r\n --socks5-basic Enable username/password auth for SOCKS5 proxies\r\n --socks5-gssapi Enable GSS-API auth for SOCKS5 proxies\r\n --socks5-gssapi-nec Compatibility with NEC SOCKS5 server\r\n --socks5-gssapi-service <name> SOCKS5 proxy service name for GSS-API\r\n --socks5-hostname <host[:port]> SOCKS5 proxy, pass host name to proxy\r\n -Y, --speed-limit <speed> Stop transfers slower than this\r\n -y, --speed-time <seconds> Trigger 'speed-limit' abort after this time\r\n --ssl Try SSL/TLS\r\n --ssl-allow-beast Allow security flaw to improve interop\r\n --ssl-no-revoke Disable cert revocation checks (WinSSL)\r\n --ssl-reqd Require SSL/TLS\r\n -2, --sslv2 Use SSLv2\r\n -3, --sslv3 Use SSLv3\r\n --stderr Where to redirect stderr\r\n --suppress-connect-headers Suppress proxy CONNECT response headers\r\n --tcp-fastopen Use TCP Fast Open\r\n --tcp-nodelay Use the TCP_NODELAY option\r\n -t, --telnet-option <opt=val> Set telnet option\r\n --tftp-blksize <value> Set TFTP BLKSIZE option\r\n --tftp-no-options Do not send any TFTP options\r\n -z, --time-cond <time> Transfer based on a time condition\r\n --tls-max <VERSION> Use TLSv1.0 or greater\r\n --tlsauthtype <type> TLS authentication type\r\n --tlspassword TLS password\r\n --tlsuser <name> TLS user name\r\n -1, --tlsv1 Use TLSv1.0 or greater\r\n --tlsv1.0 Use TLSv1.0\r\n --tlsv1.1 Use TLSv1.1\r\n --tlsv1.2 Use TLSv1.2\r\n --tlsv1.3 Use TLSv1.3\r\n --tr-encoding Request compressed transfer encoding\r\n --trace <file> Write a debug trace to FILE\r\n --trace-ascii <file> Like --trace, but without hex output\r\n --trace-time Add time stamps to trace/verbose output\r\n --unix-socket <path> Connect through this Unix domain socket\r\n -T, --upload-file <file> Transfer local FILE to destination\r\n --url <url> URL to work with\r\n -B, --use-ascii Use ASCII/text transfer\r\n -u, --user <user:password> Server user and password\r\n -A, --user-agent <name> Send User-Agent <name> to server\r\n -v, --verbose Make the operation more talkative\r\n -V, --version Show version number and quit\r\n -w, --write-out <format> Use output FORMAT after completion\r\n --xattr Store metadata in extended file attributes\r\n", "error": " % Total % Received % Xferd Average Speed Time Time Time Current\r\n Dload Upload Total Spent Left Speed\r\n\r 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0\r 0 0 0 0 0 0 0 0 --:--:-- 0:00:01 --:--:-- 0", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\curl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dccw.exe-66A082AFD0B7FD0F629FB1DEE4B588D5": { "file_name": "dccw.exe", "file_path": "C:\\Windows\\SysWOW64\\dccw.exe", "hash_md5": "66A082AFD0B7FD0F629FB1DEE4B588D5", "hash_sha1": "171FCEBEF33965D18A836FF1A95BB0C61D4EFBD3", "hash_sha256": "CCA939FE6452C1C5582821986294B6A6A8AAF61E3F5B73C8407E6B520F27001C", "hash_sha384": "4F9BEE36981EB2AD8C10D80C0F7C49CC51113EE6C007B0A865D585D42C31A8CFBC0FA25658B833189983F34BB1A89FFB", "hash_sha512": "7694A45D7479180882C1385DD6829CA804F0EE820C0613C489C1F6F8BFD7DA31D80630B446740E603ECC117726912A048A903D12951CA1FE911BD00EF1D751D4", "hash_ssdeep": "1536:W7o1m69ukhqJ0YnMXWFnVCP3Dm6RbPhHj/5/RCBBskLnrc4xro3Ci+0d/:Fu+YnogVCP3Dm6RbPhHjhpCm4xQCl0d", "hash_imp": "F18BF641045D05FC3844480267D2E273", "hash_pesha1": "CEB7F8E74A2909386E92A6867FEEC53DC10A348B", "hash_pe256": "6CC87C6B6DF15AE3018575FCF477085F54346BE37E0FD6ECF63C2E7E045CE2AC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Display Color Calibration", "meta_original_filename": "dccw.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/cca939fe6452c1c5582821986294b6a6a8aaf61e3f5b73c8407e6b520f27001c/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_4299dbb28a92ae3e": "File", "(R-D) C:\\Windows\\System32\\en-US\\dccw.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\dccw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Display Color Calibration" }, "dcomcnfg.exe-8D282EDE189E69E0EFE0043144EFA236": { "file_name": "dcomcnfg.exe", "file_path": "C:\\Windows\\SysWOW64\\dcomcnfg.exe", "hash_md5": "8D282EDE189E69E0EFE0043144EFA236", "hash_sha1": "1BD6D5F4612DDFD977E37ECC2907BCB058322217", "hash_sha256": "A5AF51728E1EB3E5D4F7FFA9DEB78E3D7986CB308761D5E5D1A130CD02362F55", "hash_sha384": "93C7769E7FED68FD7A0F4E4650FACC1484F670B4F8E0E23E9C08D7396CED4EE71FCF6216B4FA75546BDD7058DB6A303C", "hash_sha512": "9CB1AA80A974E935DB144BF355BA6AD8ADEF255603BC464B1349FC01734A2DC944A66A08EFDF8E31B0BE4737C58F685BD773CE012258D3E431F3AFB914946C6F", "hash_ssdeep": "96:kiav2cf7gE+EyPBEp2CyIRoiyI9ncnrsDGjAWEt68rtzzfDP2LVD7KkBLEW0EWwb:kFvd7WUZRouRQy68rtzzuf+W0EW", "hash_imp": "09DC7C84FC3FF557D19CADF0EA6EB40E", "hash_pesha1": "3AF75087469F5A7F18F2170061EC7F7510C0D2E9", "hash_pe256": "174B7058B7F465010B9D6A999451A94883260D17C389423A6E2C764BE0D2CD4C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+", "meta_original_filename": "DCOMCNFG.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a5af51728e1eb3e5d4f7ffa9deb78e3d7986cb308761d5e5d1a130cd02362f55/detection", "children": "mmc.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\dcomcnfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ddodiag.exe-B99A1EA960AA12EA6A972335999D2B1F": { "file_name": "ddodiag.exe", "file_path": "C:\\Windows\\SysWOW64\\ddodiag.exe", "hash_md5": "B99A1EA960AA12EA6A972335999D2B1F", "hash_sha1": "1E25B7092765A069EEBD3BB2FB9FBF74F0298CF2", "hash_sha256": "1A40075AE8330D3B2AB1C567B4FD183CFDDA20794015DAB8503A406B58DF9D44", "hash_sha384": "52BA63988B760F0F70AD7CF3CC2A8D6BCCA0198123A32623C55F038EA1499B3553A527C52CC34B49CFEA329BD99E733E", "hash_sha512": "D022F018906C896CBDE62FECABE6EDDE07B9CC4C01982FC2EB8ABFAC3289201189C9E3B3086B85F7560021E8CF410E05893AFB377D537BA352B5BECA1197015E", "hash_ssdeep": "768:Jm6fhsXKZkrWcwMa4uZlqivwTuhLuxhIO+5A:Jm6fhsXKZkrWcwMa4uZlqiw2uxh25A", "hash_imp": "C44782044D722D4027BBE52D755A88BB", "hash_pesha1": "6B44FD647760660711A71868E50D9B827477D9E1", "hash_pe256": "C178B15D8FDFF27E23CD5299216DEA7A2ADDB4259BC023EDD5A8428BE9C0AF48", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DDODiag is a tool that collects Device Display Object (DDO) information from the system and logs it", "meta_original_filename": "DDODiag.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1a40075ae8330d3b2ab1c567b4fd183cfdda20794015dab8503a406b58df9d44/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ddodiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "DevicePairingWizard.exe-2A4C038870FD0083037A7B07FEAAEDE5": { "file_name": "DevicePairingWizard.exe", "file_path": "C:\\Windows\\SysWOW64\\DevicePairingWizard.exe", "hash_md5": "2A4C038870FD0083037A7B07FEAAEDE5", "hash_sha1": "7D67612E310AD2EFC424B313AAF067CE10F3EF1C", "hash_sha256": "E681BAF7AFF55B0D22C8AC7034100B532F45F760847A969658159043F930AE78", "hash_sha384": "8A3A6C9F3BBFC683674DDB43D867FD26AB3783A43EBE30DDECC4C73DE802B1808F91A2B6643F6059AD636A306FA76DCF", "hash_sha512": "D1B8B8AE347D7328EDB901DC33B2842FD240EF4314D5C6E222E2327877FBFCBE095A5EAD305A8E88200695A14BD9404D3EE94F43E1144B9C82CB25B3BFC29331", "hash_ssdeep": "1536:w9B9jBpFkkmgXWW4wyYjXAOyb8Z3qOTU:u9jBpFkkW2yYE7loU", "hash_imp": "E22F4F896B9960494DDA33E77FEBFA53", "hash_pesha1": "65D0B88C8493C954CAA67A4697C68488F9FBC439", "hash_pe256": "F0DD25B4DBB3207700D3C240844013772EFC5D5AA8006BF3E2F58F3F0DA1DBA7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Pairing Application", "meta_original_filename": "DevicePairing.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e681baf7aff55b0d22c8ac7034100b532f45f760847a969658159043f930ae78/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\DevicePairing.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\DevicePairing.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\DevicePairingWizard.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Add a device" }, "dfrgui.exe-0945B79FA909727AF1640884AAA1D375": { "file_name": "dfrgui.exe", "file_path": "C:\\Windows\\SysWOW64\\dfrgui.exe", "hash_md5": "0945B79FA909727AF1640884AAA1D375", "hash_sha1": "FBE8157191FBBAC7FA244A90E9B39C281CCFE177", "hash_sha256": "A52DE4CDCA80E744C587166F8DF1AB25790DBA3D9C8B6478187F397791D3D183", "hash_sha384": "64FAC778D837D32AD9F89938FD148A2AF31EC7890A1752B4C7407868A252A819C8CDE2C9FF9E2D8C97A93B95452091FD", "hash_sha512": "36D84BF788C23DD103D1A50025A4789F00D9F6505DECBAFF8E7EC3C413B1962C040E416032FD124A1FDE0392D43DF0F6A3E4431E9E5CA897BCF340373FDC3900", "hash_ssdeep": "1536:HkJKk/odDy7ODjg+kqzzZydHzc8xS+JJlfzbPHHAB5WIY2PinuZ9ncCpCC7zOa+q:HkJKk/o87ODjxzZydTcL+7lfzbvHAB5M", "hash_imp": "B20BC0F9195C807AD51C2444356A716A", "hash_pesha1": "DF6C46CC0F0685981ACFE98B7E74C1E1A4F39F56", "hash_pe256": "C864055E68F3F72E80DE87FCDC2F875DC8F88E22E038C0069A3F97880527CDDA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Drive Optimizer", "meta_original_filename": "lhdfrgui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.84 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.84", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a52de4cdca80e744c587166f8df1ab25790dba3d9c8b6478187f397791d3d183/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\dfrgui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dialer.exe-E4BD77FB64DDE78F1A95ECE09F6A9B85": { "file_name": "dialer.exe", "file_path": "C:\\Windows\\SysWOW64\\dialer.exe", "hash_md5": "E4BD77FB64DDE78F1A95ECE09F6A9B85", "hash_sha1": "F62687DCF8AFE594F414B35076B1EDE419325716", "hash_sha256": "179584E64148751549E5F25A127293FD6E0AC7C2CEAED78E53669397A005BAE7", "hash_sha384": "5E0B1DDADE15930E30A74065356E9780CC4B5071DD1F1E11C4D4033ECD49C47F5AA86AD970A74823D91C582F356D6A73", "hash_sha512": "2B73E358BCA9DA827E2BC99045F93D73E6C23F577380F5FA30422FEDA1F19D2E3DEA28F5A47A60FB94E1B837B2C55395A61A9D6CF14716500B01E68A33B23BDF", "hash_ssdeep": "384:3RUApn/nE6i9nNsxkP7/1E0mMbtszLLC6A72OpZ+HB44zLhFw3dL9vbWtvKW2d7p:3hpUZekP7/rmOtsz5A7zKS59+CdKo2Q", "hash_imp": "76E0D8D65462216E7B0903BC27D606D1", "hash_pesha1": "D609B7232584F57791742F9A8A59E9AC87EF94F5", "hash_pe256": "CAB17443F1C21CA66B17B64136F8B4A09787B391DAA65DE0D4337AC4DDF9B8A2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Phone Dialer", "meta_original_filename": "DIALER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/179584e64148751549e5f25a127293fd6e0ac7c2ceaed78e53669397a005bae7/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\dialer.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\dialer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Phone Dialer" }, "diskpart.exe-D469D2073C8234DF591BDA28CB3A1981": { "file_name": "diskpart.exe", "file_path": "C:\\Windows\\SysWOW64\\diskpart.exe", "hash_md5": "D469D2073C8234DF591BDA28CB3A1981", "hash_sha1": "C89841C0D684685562AD1F81157E08E8EBAE2442", "hash_sha256": "A11172AA1A38F461F20A7AB393797ECA3A93CB6A8126988C174294D449DA67D8", "hash_sha384": "7434487AF4AC71DA2E3A78967A46D418B5FC1F502F298D70BC24B7FC1CB252E266BA3F242A5DEDEC92895BD853410F5B", "hash_sha512": "0E2389455B3E73F9C1874FB6B4ABA20665A524F7B5C332E23D69AAE04EDED99DC300D2D5ABB4246ED27BF8266F8CA7239401816C15BCC6876128474B81567C28", "hash_ssdeep": "3072:0p4nh3LogVEFRbzTGZHjesv0g8Lg+auNfo62KNl/wkyUxU1grr2d6xbTI:0pwLoQEn/06sf8LKkfNekh+b", "hash_imp": "83DF01F6588FB2BE4B753129F4F85645", "hash_pesha1": "F4601D06BCE2CE2CA7E057F11E9915A983F463A0", "hash_pe256": "6AC7C3F71BDD75E22A90A51244FC08D020A7D4F8FDDF33E6ACF303DB22B610BB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DiskPart", "meta_original_filename": "diskpart.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a11172aa1a38f461f20a7ab393797eca3a93cb6a8126988c174294d449da67d8/detection", "output": "\r\nMicrosoft DiskPart version 10.0.19041.610\r\n\r\nCopyright (C) Microsoft Corporation.\r\nOn computer: DESKTOP-F9N3CL1\r\n\r\nDiskPart has encountered an error: No mapping between account names and security IDs was done.\r\nSee the System Event Log for more information.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\diskpart.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "diskperf.exe-F91BF214C9CD4A7E73B68882755905F8": { "file_name": "diskperf.exe", "file_path": "C:\\Windows\\SysWOW64\\diskperf.exe", "hash_md5": "F91BF214C9CD4A7E73B68882755905F8", "hash_sha1": "8C36A1DD40D1F5EEDDC1D55B6FD6A7D1CCDEB980", "hash_sha256": "9175DCDC9D866E0FD09FF4DABF8783A203201809489B1E73486E2183960C6A4D", "hash_sha384": "D6050EE8AD3A331CC4B4502F3C6787303BF5B372EEC21795EF6314ECFBA3CC724A8E29C0CE3C93D2FDE38FB91E5EE873", "hash_sha512": "A46D10A2B4B732CC935842EF0F8718471837B31CDEFA9C02E78EA5A9978F800604C3C5A37F49988401028840AFCC33E1E2652E562E6520DBCEE442664CE935A8", "hash_ssdeep": "384:6COMELFFyNdHwHfybLVnzp6+PQJfjsGeNZ+FWDJWujUS:6COMEryHHwHfEF6+4aGSZ+GC", "hash_imp": "C28394BB096619BE03BC663DF4326B95", "hash_pesha1": "D1A97908BFDF07E503E9F768B26C176E325FD778", "hash_pe256": "A4F5EA762AED9BE1978616CD3FD7BB55FCB74B204B26FC062E0AB52968CDCB02", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Performance Configuration Utility", "meta_original_filename": "DISKPERF.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/9175dcdc9d866e0fd09ff4dabf8783a203201809489b1e73486e2183960c6a4d/detection", "output": "\r\n\r\nDISKPERF=====================\r\n\r\nStarts and stops system disk performance counters.\r\n\r\nUsed without the command switches, DISKPERF reports what disk\r\nperformance counters are enabled on the specified Windows 2000 computer.\r\n\r\nDisk performance counters can be specified to report the\r\nperformance of the individual physical drives, or the individual\r\nlogical drives or storage volumes. Note that these two sets of\r\nperformance counters are measured independently. The user\r\nhas the option of enabling and disabling them independently\r\nusing the command line switches.\r\nNOTE: This command can only be used to control remote\r\nWindows 2000 systems. In newer systems, these performance counters\r\nare automatically enabled.\r\n\r\nDISKPERF [-Y[D|V] | -N[D|V]] [\\\\computername]\r\n\r\n -Y Sets the system to start all disk performance counters\r\n when the system is restarted.\r\n\r\n -YD Enables the disk performance counters for physical drives.\r\n when the system is restarted.\r\n -YV Enables the disk performance counters for logical drives\r\n or storage volumes when the system is restarted.\r\n -N Sets the system to disable all disk performance counters\r\n when the system is restarted.\r\n\r\n -ND Disables the disk performance counters for physical drives.\r\n -NV Disables the disk performance counters for logical drives.\r\n \\\\computername Is the name of the computer you want to\r\n see or set disk performance counter use.\r\n The computer must be a Windows 2000 system.\r\n NOTE: Disk performance counters are permanently enabled on\r\n systems beyond Windows 2000.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\diskperf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Dism.exe-CD1A10887F341BD0F0CC63E5B992FC62": { "file_name": "Dism.exe", "file_path": "C:\\Windows\\SysWOW64\\Dism.exe", "hash_md5": "CD1A10887F341BD0F0CC63E5B992FC62", "hash_sha1": "5603AE71B3F1EFFD4D2F43860FFD5AE267496CFF", "hash_sha256": "CA010C46E1B7B986F282C06DF69F222C358724B35724E313E5C4C64F55D9F2BA", "hash_sha384": "8A081ED7B6E1091BDDBC0D0BDE8852601477C165F59FE26FE05EBD471CB8EE138BC8C8834B875657D1A32DCE759147E9", "hash_sha512": "9842972BE4FD639B4675893CCE346B086CB0843367997ED20FCDB730265749814F3105D14585FCE40B7E5B26A9A60932FC29D6AD90A13A6745271AE1F20BF576", "hash_ssdeep": "3072:LR577RF5w/eZ6ZobOkGrHrDavacZma3ZJ99LFY4zlTer4F/2TCMdJVrclyXII:/lF5P6ZobOt7fEt31XY4zlqcF/2jrb", "hash_imp": "A4DC751C02F601828A098E8DA5850F7D", "hash_pesha1": "4A7BAE346134E8BA51D18EFD4E085A12105BABD2", "hash_pe256": "E22984E7EC34017B4F80C1DCAECE8BA53587862AB12F0EDFC4A0EB8B12C8A367", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Dism Image Servicing Utility", "meta_original_filename": "DISM.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ca010c46e1b7b986f282c06df69f222c358724b35724e313e5c4c64f55d9f2ba/detection", "output": "\r\nDeployment Image Servicing and Management tool\r\nVersion: 10.0.19041.572\r\n\r\n\r\nDISM.exe [dism_options] {Imaging_command} [<Imaging_arguments>]\r\nDISM.exe {/Image:<path_to_offline_image> | /Online} [dism_options] \r\n {servicing_command} [<servicing_arguments>]\r\n\r\nDESCRIPTION:\r\n\r\n DISM enumerates, installs, uninstalls, configures, and updates features\r\n and packages in Windows images. The commands that are available depend \r\n on the image being serviced and whether the image is offline or running.\r\n\r\n\r\nGENERIC IMAGING COMMANDS:\r\n\r\n /Split-Image - Splits an existing .wim file into multiple \r\n read-only split WIM (SWM) files.\r\n /Apply-Image - Applies an image.\r\n /Get-MountedImageInfo - Displays information about mounted WIM and VHD\r\n images.\r\n /Get-ImageInfo - Displays information about images in a WIM, a VHD\r\n or a FFU file.\r\n /Commit-Image - Saves changes to a mounted WIM or VHD image.\r\n /Unmount-Image - Unmounts a mounted WIM or VHD image.\r\n /Mount-Image - Mounts an image from a WIM or VHD file.\r\n /Remount-Image - Recovers an orphaned image mount directory.\r\n /Cleanup-Mountpoints - Deletes resources associated with corrupted\r\n mounted images.\r\n\r\nWIM COMMANDS:\r\n\r\n /Apply-CustomDataImage - Dehydrates files contained in the custom data image.\r\n /Capture-CustomImage - Captures customizations into a delta WIM file on a \r\n WIMBoot system. Captured directories include all \r\n subfolders and data.\r\n /Get-WIMBootEntry - Displays WIMBoot configuration entries for the \r\n specified disk volume.\r\n /Update-WIMBootEntry - Updates WIMBoot configuration entry for the \r\n specified disk volume.\r\n /List-Image - Displays a list of the files and folders in a \r\n specified image.\r\n /Delete-Image - Deletes the specified volume image from a WIM file\r\n that has multiple volume images.\r\n /Export-Image - Exports a copy of the specified image to another\r\n file.\r\n /Append-Image - Adds another image to a WIM file.\r\n /Capture-Image - Captures an image of a drive into a new WIM file.\r\n Captured directories include all subfolders and \r\n data.\r\n /Get-MountedWimInfo - Displays information about mounted WIM images.\r\n /Get-WimInfo - Displays information about images in a WIM file.\r\n /Commit-Wim - Saves changes to a mounted WIM image.\r\n /Unmount-Wim - Unmounts a mounted WIM image.\r\n /Mount-Wim - Mounts an image from a WIM file.\r\n /Remount-Wim - Recovers an orphaned WIM mount directory.\r\n /Cleanup-Wim - Deletes resources associated with mounted WIM \r\n images that are corrupted.\r\n\r\nFFU COMMANDS:\r\n\r\n /Capture-Ffu - Captures a physical disk image into a new FFU file.\r\n /Apply-Ffu - Applies an .ffu image.\r\n /Split-Ffu - Splits an existing .ffu file into multiple read-only\r\n split FFU files.\r\n /Optimize-Ffu - Optimizes a FFU file so that it can be applied to storage \r\n of a different size.\r\n\r\nIMAGE SPECIFICATIONS:\r\n\r\n /Online - Targets the running operating system.\r\n /Image - Specifies the path to the root directory of an\r\n offline Windows image.\r\n\r\nDISM OPTIONS:\r\n\r\n /English - Displays command line output in English.\r\n /Format - Specifies the report output format.\r\n /WinDir - Specifies the path to the Windows directory.\r\n /SysDriveDir - Specifies the path to the system-loader file named\r\n BootMgr.\r\n /LogPath - Specifies the logfile path.\r\n /LogLevel - Specifies the output level shown in the log (1-4).\r\n /NoRestart - Suppresses automatic reboots and reboot prompts.\r\n /Quiet - Suppresses all output except for error messages.\r\n /ScratchDir - Specifies the path to a scratch directory.\r\n\r\nFor more information about these DISM options and their arguments, specify an\r\noption immediately before /?.\r\n\r\n Examples: \r\n DISM.exe /Mount-Wim /?\r\n DISM.exe /ScratchDir /?\r\n DISM.exe /Image:C:\\test\\offline /?\r\n DISM.exe /Online /?\r\n\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Dism.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dllhost.exe-6F3C9485F8F97AC04C8E43EF4463A68C": { "file_name": "dllhost.exe", "file_path": "C:\\Windows\\SysWOW64\\dllhost.exe", "hash_md5": "6F3C9485F8F97AC04C8E43EF4463A68C", "hash_sha1": "497B8CE238DB644B7E1A16B417DBB5BC052A2684", "hash_sha256": "3ED69CAAB035258E008EFBCF40DB305891B40BA02CA2737E20DEFA7C2D4AFAF7", "hash_sha384": "825CC484BCFF8DA9E29239B5401C828729E1ECB784A1C887FC2A18D7B48B09D9F9F774C397753519396046F4680107CE", "hash_sha512": "DBB04F0D2AA4AC2C234B08125564F8F9F790B115E0C5B3F3765ED3C20F3CFD24D6110AF04FEB1837E77DA84524180A85CC9B6802F9ACFBD8809B052221A04EA7", "hash_ssdeep": "384:bWHTVQyztcEUJnPjz2M2ucqWw5WG+GOxr6wDDBRJcoTCTlJSBA:bqKyxcEUR2rucs5Ar6wD1PFC6G", "hash_imp": "B6A6C5247EFBD2610E3DEA44649D7041", "hash_pesha1": "2B27B79FFA64C9305AD074513EE51AEDA9A9FD23", "hash_pe256": "7C06EE399035352594D2C16EBEF24098BAB91577A4DE2D38332A49AC52E6AFB5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM Surrogate", "meta_original_filename": "dllhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3ed69caab035258e008efbcf40db305891b40ba02ca2737e20defa7c2d4afaf7/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\dllhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dllhst3g.exe-98858F3C8EE47AC663BDF08919F38EFE": { "file_name": "dllhst3g.exe", "file_path": "C:\\Windows\\SysWOW64\\dllhst3g.exe", "hash_md5": "98858F3C8EE47AC663BDF08919F38EFE", "hash_sha1": "47DAB9F67544849693D0AF8AAF10CD29AFD69122", "hash_sha256": "9D71A9EDD75017C6EFFD7BC8FCAFF5022D615C83B3DDA2B3073415B697EFE645", "hash_sha384": "041FB7CCDF52DF27FAEB73ED7072BA5C04FE917378996F1DC5B842CB1B19464C1C4E4E6FDD2FF4BC0B3C171D90698C50", "hash_sha512": "847E9A11C4DDBFA15FDD65B23814D02DAF1183ADE3C36CBECEB93AB8471F5E8B1DC0CA70E9A59BD74900A2E37C9CAD7AB12EF6D04DF279D6A6BA69D009F90387", "hash_ssdeep": "192:nOeAHzVsL5B1qztC93UgzJn7DjOA2M25VwOuTEDcSW5yW++GO:nOhTVQyztckUJnPjz2M2lcSW5yW++GO", "hash_imp": "B6A6C5247EFBD2610E3DEA44649D7041", "hash_pesha1": "221D3390DE4385D73661B97847C2CACEA8A51306", "hash_pe256": "14C9218525F06A6836C954DF385E9008384E2A1910504A68BE0D3589BA945E02", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM Surrogate", "meta_original_filename": "dllhst3g.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9d71a9edd75017c6effd7bc8fcaff5022d615c83b3dda2b3073415b697efe645/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\dllhst3g.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "doskey.exe-06B531B4DB79416D0117EDE4DF42567C": { "file_name": "doskey.exe", "file_path": "C:\\Windows\\SysWOW64\\doskey.exe", "hash_md5": "06B531B4DB79416D0117EDE4DF42567C", "hash_sha1": "4077207DA8C513C57F1B628CD3F1708EE3C2D40B", "hash_sha256": "9D9568D16DA949EEDFE608E40F92433A3340A6676FC0D9EBD027D13EF18AC3CF", "hash_sha384": "6CA9228810ABF7A391E81BDC8121A6A608C09A1C93A443787D23E6B24DBEA5325BA1637AB45667F1AEE5B9A134219A95", "hash_sha512": "8413BFD0A59275CF892BB03A0B597F07E529008E627D32663D048A4D16BC322851A534FD2E72427E684DFCB1558AD5EA99C508C8908C9A18C30D7237D3C9CEB1", "hash_ssdeep": "384:AfRzIPevb7bI7rSexFQZwBUhFlFEiXW4iWCy:oR8Pevb7bI7rSexYwqFEirm", "hash_imp": "815CEBC8099878FCFC3EEFE858FAB97B", "hash_pesha1": "C2F2482D96169596715020DB4A5542A1730609BC", "hash_pe256": "2C59A011004E4C6E87D3289D3B6201F9B0E58AA7D13CC43617C3CEECC660AF8E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Keyboard History Utility", "meta_original_filename": "DOSKEY.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9d9568d16da949eedfe608e40f92433a3340a6676fc0d9ebd027d13ef18ac3cf/detection", "output": "Edits command lines, recalls Windows commands, and creates macros.\r\n\r\nDOSKEY [/REINSTALL] [/LISTSIZE=size] [/MACROS[:ALL | :exename]]\r\n [/HISTORY] [/INSERT | /OVERSTRIKE] [/EXENAME=exename] [/MACROFILE=filename]\r\n [macroname=[text]]\r\n\r\n /REINSTALL Installs a new copy of Doskey.\r\n /LISTSIZE=size Sets size of command history buffer.\r\n /MACROS Displays all Doskey macros.\r\n /MACROS:ALL Displays all Doskey macros for all executables which have\r\n Doskey macros.\r\n /MACROS:exename Displays all Doskey macros for the given executable.\r\n /HISTORY Displays all commands stored in memory.\r\n /INSERT Specifies that new text you type is inserted in old text.\r\n /OVERSTRIKE Specifies that new text overwrites old text.\r\n /EXENAME=exename Specifies the executable.\r\n /MACROFILE=filename Specifies a file of macros to install.\r\n macroname Specifies a name for a macro you create.\r\n text Specifies commands you want to record.\r\n\r\nUP and DOWN ARROWS recall commands; ESC clears command line; F7 displays\r\ncommand history; ALT+F7 clears command history; F8 searches command\r\nhistory; F9 selects a command by number; ALT+F10 clears macro definitions.\r\n\r\nThe following are some special codes in Doskey macro definitions:\r\n$T Command separator. Allows multiple commands in a macro.\r\n$1-$9 Batch parameters. Equivalent to %1-%9 in batch programs.\r\n$* Symbol replaced by everything following macro name on command line.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\doskey.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dpapimig.exe-D35833E98209E9267C4FE5C2C3E88AE9": { "file_name": "dpapimig.exe", "file_path": "C:\\Windows\\SysWOW64\\dpapimig.exe", "hash_md5": "D35833E98209E9267C4FE5C2C3E88AE9", "hash_sha1": "2904327B36327B9E40AE4C4216E369D4A26F5191", "hash_sha256": "63DE0E29608BA9702FC0996460271886D1F5C8809788BE035105BC317A47A5CD", "hash_sha384": "43F9E4F104308F8648ECA07BCD3B22E73BAE12C333D8E3407492D25EE0517237A0B14C17AF944C123F261D25E1970E3F", "hash_sha512": "CFDED83278DB13AD7A6D9738097E8743EDB7E2D738F45BF2DDA400588B931304F9D398A20D5239331AF9E8A4E2BE588820E5BFD7094500BC751279876A2DDC75", "hash_ssdeep": "1536:82tDEGcbBM8T2ZKpUZir/QxkvsKp00l3uU1HIED1fCbWpygzU:NeGcbBIKSK+SJj16bE", "hash_imp": "DA3FB0A7EB3F23A19BB11529165AC3DA", "hash_pesha1": "80B34C7F899BC5FCAD40418AC0F51D8AEC7CC4C8", "hash_pe256": "558F820F8EAA1E9986115592F66CB6F6F2E91A66C489EAB6347B801A71D76808", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DPAPI Key Migration Wizard", "meta_original_filename": "dpapimig.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/63de0e29608ba9702fc0996460271886d1f5c8809788be035105bc317a47a5cd/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\dpapimig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "DpiScaling.exe-D44D3A0F5E53F6ECC5C6232930CFCC5E": { "file_name": "DpiScaling.exe", "file_path": "C:\\Windows\\SysWOW64\\DpiScaling.exe", "hash_md5": "D44D3A0F5E53F6ECC5C6232930CFCC5E", "hash_sha1": "D42B4FC663FB0328A2307EC7C8F56F220872D953", "hash_sha256": "FA1DD224289D1C39C49CB5DD2896FA19A3091CE650D6B665626D5D30B65DEE9E", "hash_sha384": "C834E33A780A89415E7AE5DDC2925206D2987B74EF5CA0D022321AACD8D91FEBAC31664F8039062955FCA0D4DBD94531", "hash_sha512": "A4104E8ABB58D17D6565A410A5E4653280827D2291BFEDB59201E368DCE475B43B79FDD3087DCE46C8E0A95CAD78AFB15E0C1FB351BABD7168E39E26EF861AF6", "hash_ssdeep": "1536:8jZI91OwxgwYfPSqlGv+BNXNvuZS36EDtAZ7jz6dTdMQiMtYwJj8:YOOwNMSqoKXNvuZAFDqXzlzQQ", "hash_imp": "91ACA85D178C3B3F6B7A2FAD4CCCBEE7", "hash_pesha1": "D4A32D5BE35B888D8ED1C43182AE8E33F0E92687", "hash_pe256": "DD3E243BD7D25E6239F28D679FD000315F3E2A45B2063D358473F9C26CD47F61", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Display Control Panel", "meta_original_filename": "DPISCALING.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/fa1dd224289d1c39c49cb5dd2896fa19a3091ce650d6b665626d5d30b65dee9e/detection", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\DpiScaling.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dplaysvr.exe-FAEDA9B43E022ACD3B8462B222EEDC72": { "file_name": "dplaysvr.exe", "file_path": "C:\\Windows\\SysWOW64\\dplaysvr.exe", "hash_md5": "FAEDA9B43E022ACD3B8462B222EEDC72", "hash_sha1": "9D81571936C9270600E54F7BCA210026F6ECD830", "hash_sha256": "F0F847A5079F94ADFD5B224C05DDD4A5651C757B920B6C26E629993C7DD36951", "hash_sha384": "A60C88365A45A6E9D6D9EE4F5C01BF421A201D7BB54BA5079ADBEBBDC04E18A133A33A1F340A7673C6CE364082E24D99", "hash_sha512": "5A351F6A59F148E7091B8EFFA5D5E59102AB4FC4BFC1374E19A8ADE57FC68BCE4467F5B9BE34F9A4AAF2DF85721EFBCCDE064803469FEBA2B06EA789681B0D4E", "hash_ssdeep": "96:ixLCTNklk4a+4a9Tcqn2jshq8PjAzIsEWRuWw1QR:ixmT4kJ+4Yu0PrAzKWRuW", "hash_imp": "E0BD3263FD5EA99B1D0C2F6F5194CC24", "hash_pesha1": "5A36F23B87691AB54B966A078386DD14E7BC9EE5", "hash_pe256": "81BE0F9ED5512C9FAF6B7659DEAE7F8E18C015CC10DA87DEEDA4235E67948B4C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DirectPlay Stub", "meta_original_filename": "wcodstub.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f0f847a5079f94adfd5b224c05ddd4a5651c757b920b6c26e629993c7dd36951/detection" }, "dpnsvr.exe-FAEDA9B43E022ACD3B8462B222EEDC72": { "file_name": "dpnsvr.exe", "file_path": "C:\\Windows\\SysWOW64\\dpnsvr.exe", "hash_md5": "FAEDA9B43E022ACD3B8462B222EEDC72", "hash_sha1": "9D81571936C9270600E54F7BCA210026F6ECD830", "hash_sha256": "F0F847A5079F94ADFD5B224C05DDD4A5651C757B920B6C26E629993C7DD36951", "hash_sha384": "A60C88365A45A6E9D6D9EE4F5C01BF421A201D7BB54BA5079ADBEBBDC04E18A133A33A1F340A7673C6CE364082E24D99", "hash_sha512": "5A351F6A59F148E7091B8EFFA5D5E59102AB4FC4BFC1374E19A8ADE57FC68BCE4467F5B9BE34F9A4AAF2DF85721EFBCCDE064803469FEBA2B06EA789681B0D4E", "hash_ssdeep": "96:ixLCTNklk4a+4a9Tcqn2jshq8PjAzIsEWRuWw1QR:ixmT4kJ+4Yu0PrAzKWRuW", "hash_imp": "E0BD3263FD5EA99B1D0C2F6F5194CC24", "hash_pesha1": "5A36F23B87691AB54B966A078386DD14E7BC9EE5", "hash_pe256": "81BE0F9ED5512C9FAF6B7659DEAE7F8E18C015CC10DA87DEEDA4235E67948B4C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DirectPlay Stub", "meta_original_filename": "wcodstub.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f0f847a5079f94adfd5b224c05ddd4a5651c757b920b6c26e629993c7dd36951/detection" }, "driverquery.exe-D14D75148EB7FCCD8D8849F9BFDC4E89": { "file_name": "driverquery.exe", "file_path": "C:\\Windows\\SysWOW64\\driverquery.exe", "hash_md5": "D14D75148EB7FCCD8D8849F9BFDC4E89", "hash_sha1": "2BC4B5F66769C9A7361D86EB3B8B2A82A285E65C", "hash_sha256": "42EC0718E29088EA73BBAC9C96EAF02807BA556A392FA8C830AE9B425B7E0CC0", "hash_sha384": "D9308CE4907507C330C3A3975073361C24AE8FCA7FA2009619C5EC3614C12EAC53C22AD85AFC7CFF90C94DBE68E6B62F", "hash_sha512": "AF16C83D1468AAABCD10A3A4BB13BC753D30770F6496526E561674D36DB0B974A678C7E35A10153059FB26BEB1FBF257F08B5D5744FEAC7E54297E7A711468E2", "hash_ssdeep": "1536:LSJUbCDS01QaavBCGWFxND02cCncUIfP0N5yIKxfm8:/bCF1QaD/DncdUZ1Kxe", "hash_imp": "C118304E7D2CAFD7F39FDA694BE5CE60", "hash_pesha1": "516F7F8F94692A7D2EBF8EC4B11FF2B68C476672", "hash_pe256": "08910C8DB9E4C230452404BEA0651678C0C80AE6C6151FFBF8B6D9D296A7F536", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Queries the drivers on a system", "meta_original_filename": "drvqry.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/42ec0718e29088ea73bbac9c96eaf02807ba556a392fa8c830ae9b425b7e0cc0/detection", "output": "\r\nDRIVERQUERY [/S system [/U username [/P [password]]]]\r\n [/FO format] [/NH] [/SI] [/V] \r\nDescription:\r\n Enables an administrator to display a list of \r\n installed device drivers.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context \r\n under which the command should execute.\r\n\r\n /P [password] Specify the password for the given \r\n user context.\r\n\r\n /FO format Specifies the type of output to display.\r\n Valid values to be passed with the\r\n switch are \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" \r\n should not be displayed. Valid for \r\n \"TABLE\" and \"CSV\" format only.\r\n\r\n /SI Provides information about signed drivers.\r\n\r\n /V Displays verbose output. Not valid \r\n for signed drivers.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n DRIVERQUERY\r\n DRIVERQUERY /FO CSV /SI\r\n DRIVERQUERY /NH\r\n DRIVERQUERY /S ipaddress /U user /V \r\n DRIVERQUERY /S system /U domain\\user /P password /FO LIST\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"DRIVERQUERY /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\driverquery.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dtdump.exe-7A9343CFA9D5F9FBEB611628A1682D96": { "file_name": "dtdump.exe", "file_path": "C:\\Windows\\SysWOW64\\dtdump.exe", "hash_md5": "7A9343CFA9D5F9FBEB611628A1682D96", "hash_sha1": "66AFC2E9989A6A8646C7AAE6D61E749BDCAF4763", "hash_sha256": "C3FD85CCA8B5CA64EEC2205D356BB6A4D007057E9E340B44916E80BE7F327246", "hash_sha384": "9BC014C71BC1D584851F2914E68064B2F359C24A8B05123E579BBFFE3FA552608946AC7B09E2C531A4E36207A09E63D7", "hash_sha512": "27CF57671536C872F3FA889740E61C494AA34F797E3E5F7066C9C87BFC7E5140BAC7DDCB68FE820292A886683588DFBAC5FC2CF75956D9A054DD018AD61720CC", "hash_ssdeep": "1536:NNp9R862jRGDCdFz4jzbaDA9xSfJiobRLK+69hlSj/Mptryg8AfOd4oOyzvQ+aj9:NNp904mdFsjzd8QobRLKL9hukHfHFRZb", "hash_imp": "4A03FD182BD0DDE1234B51ECCE34E598", "hash_pesha1": "82A129ACEDDFEFBAC4ACB38D1C95D37062391373", "hash_pe256": "94154A364E2A8411D99EFF76E6C0287861AF95ACE7F4B13006686AB4D7A3DC8E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DTDUMP.EXE", "meta_original_filename": "DTDUMP.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c3fd85cca8b5ca64eec2205d356bb6a4d007057e9e340b44916e80be7f327246/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\dtdump.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dvdplay.exe-D388610A1DE600E01277AECF3B1280A3": { "file_name": "dvdplay.exe", "file_path": "C:\\Windows\\SysWOW64\\dvdplay.exe", "hash_md5": "D388610A1DE600E01277AECF3B1280A3", "hash_sha1": "57E36BA27CFD74C70567E5CE6305381317D9808C", "hash_sha256": "B740FBBA53980B4C2EEC43D09F3ADA7D7B55431D68A15D83AD77E1DC582AD31E", "hash_sha384": "8719329B46F2D974D3B57A836470DCABBA089FB9A813B3C2CF34A80F32F1509BAF7A77B4C6ACED27ED9EB1BEE9949BA3", "hash_sha512": "6E7073B8EB25129CA12251DC352CF8C3174C9B61A51025005A481B62149BCDA00F831C5A6BE2758DFC5577846BC1F71283F07A754BAFCD6871EC6B92422AB8E6", "hash_ssdeep": "96:bOQ+dun2Ap2hCP/DGjsg5HNI9oE1tDJvkMqf9sPfbhFijEWoBZWw3JpFY:bZp/E9i9oE1XkoPjhFioWSZW6pFY", "hash_imp": "E039C46E30A89ABAF651718C922747B4", "hash_pesha1": "7ACBD7A67F70630119484521DBE2419C7E45E886", "hash_pe256": "B211D71765A19FF4744E39D9E45D0C86B0D6B453DA3E8463031412A899F5A7D5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "dvdplay placeholder Application", "meta_original_filename": "dvdplay", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/b740fbba53980b4c2eec43d09f3ada7d7b55431d68a15d83ad77e1dc582ad31e/detection", "children": "wmplayer.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\dvdplay.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "DWWIN.EXE-349A39BCF32EA165934BEBDCC57189E7": { "file_name": "DWWIN.EXE", "file_path": "C:\\Windows\\SysWOW64\\DWWIN.EXE", "hash_md5": "349A39BCF32EA165934BEBDCC57189E7", "hash_sha1": "951CF35F20128945AEEB974590A77091EF01D738", "hash_sha256": "D96CFE9E5E79D519BD3D88EE9716C145490D93840C858AAD58B9EF1C446C6E8D", "hash_sha384": "10DA157048A6065883356B3228387039D4FA6EF166E1EDD83324BF17075AA648D0AA0740AEE0C7E374914AA409825331", "hash_sha512": "B72CFBDDA8ECC0B6DB75E19D18D63BE9D531C1668BC6841312E5EFF115807A45670E4F592D3A165BEB804D698BA0415F1296C9F0CEBDE2043E325CC77467AD62", "hash_ssdeep": "3072:PDJd43BKKbhcngAwJwICH7Vemmr+Y3XbselNDahIR7IEaGifQF9K7CuJYz+kJ0LZ:Lb43BZb7J5CbEyYnrlah2Mgifu9Pz+kC", "hash_imp": "51824BC71568257DA5A091A60BB84DBE", "hash_pesha1": "9926DF7233BF6AC13B68A334E48B6AB8CEDEA6CC", "hash_pe256": "945D9B27CDCF0DF2D6DE4D49C0551C4A88A0EAEE0BE713E071027974EF512DF1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Error Reporting", "meta_original_filename": "DWWIN", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.630 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.630", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d96cfe9e5e79d519bd3d88ee9716c145490d93840c858aad58b9ef1c446c6e8d/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\DWWIN.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dxdiag.exe-24D3F0DB6CCF0C341EA4F6B206DF2EDF": { "file_name": "dxdiag.exe", "file_path": "C:\\Windows\\SysWOW64\\dxdiag.exe", "hash_md5": "24D3F0DB6CCF0C341EA4F6B206DF2EDF", "hash_sha1": "B65ED4B4B1FB9CC5C128EE48A0B7CD326BA3AC93", "hash_sha256": "C36C36C2945802FEB2195AD271C98F994B22A09F6CF2A1764A190865D1D6CE2B", "hash_sha384": "0B7A23E752E83A37C0E0D42C47B3FA73E93860039F1A75252DC7DF1002EA69D3C02C611D345F4F61CFDAC77B25AE0417", "hash_sha512": "7C4CC31303C59903E74B29B6EC14138611567A09281A4728D2B2A9B170E14344395173C1D97DF34B2F0391BC7365AC856884643C857325C3EA293AEF643C53E7", "hash_ssdeep": "3072:MMlaJEzHyusOl081O6Zdtx7SNchIarfvdNpNXXR2P9K:k0HF/1l9lhIabdNpNMP", "hash_imp": "E0714F696F6DB2113819D17A314D083F", "hash_pesha1": "009B1E0505A2A54960E01C9C6326BB1107A24364", "hash_pe256": "8EF6F6A10D97BD2D3A56D50EE74406275B2886DF67508DCC258D37D37ACF835F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft DirectX Diagnostic Tool", "meta_original_filename": "dxdiag.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c36c36c2945802feb2195ad271c98f994b22a09f6cf2a1764a190865d1d6ce2b/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\dxdiag.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\dxdiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "DirectX Diagnostic Tool" }, "EaseOfAccessDialog.exe-792CA1E7ABC6CED234B0D361093AD0D3": { "file_name": "EaseOfAccessDialog.exe", "file_path": "C:\\Windows\\SysWOW64\\EaseOfAccessDialog.exe", "hash_md5": "792CA1E7ABC6CED234B0D361093AD0D3", "hash_sha1": "8BF7837B2C789531B2D136A041D927D11F64A2FC", "hash_sha256": "80CBCA69617773334A9DC9A082A4FB3979E2D588BCB221F020A391D793E366C5", "hash_sha384": "BA155EEFCFC7706753AA25129DC57FEF816E66947239916760C0FAF7BA7A0B7A8B1C6F702FA3C4B66834619DD8ECADE2", "hash_sha512": "F9D640B2DFAF8B720B4C6131EBBAD981F0C654973FC8E6476E37D886EDDBB66FD262E9FE135B4CBA02C36605F86A44866AF503AE0A6E343F8E4751D071E1CE0E", "hash_ssdeep": "1536:9coh9wplqBI7xWjDgOlWGCbkN0/EjJMk64vHqI3R1qzWO0vmTZB1+hKW/GJzNjgd:99eplqcWQOxO40uJMGfN33D3X1T", "hash_imp": "D0655A5D963411CB2710FE56B09DA6C6", "hash_pesha1": "12A3EC3F5075AE6F708D62A95CC0F577A2D96E49", "hash_pe256": "A8E540C2EB24227A21B5CFE825E6E0AF278EC2B728EA8A642CA611061AE23045", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Ease of Access Dialog Host", "meta_original_filename": "EaseOfAccessDialog.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.388 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.388", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/80cbca69617773334a9dc9a082a4fb3979e2d588bcb221f020a391d793e366c5/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\EaseOfAccessDialog.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "edpnotify.exe-516042566C6228F60F16AB375814D891": { "file_name": "edpnotify.exe", "file_path": "C:\\Windows\\SysWOW64\\edpnotify.exe", "hash_md5": "516042566C6228F60F16AB375814D891", "hash_sha1": "F84627DD29D9AF24A661DA0F24609B07FA194494", "hash_sha256": "589CACEDADF3A399DB2FCAA2508EC4E52DF6FE4CF7AEDABFCADEAF14A31C684B", "hash_sha384": "2A440F42CA44E69D2753104A1107C3D664CBE278DFBC28C60603C7335ED681CFF1B3C1ED94C8FEBC283AD7E9030A9B33", "hash_sha512": "40625510AA43FAB356CFF6EE6800C103E2721ADFA2C79E80C2A2DCB30BCC826181FF57B73FDFD1E81636D73B2B6218863D32A35F20D28275576C19B3F4BD250B", "hash_ssdeep": "768:19Xf7zx1hZyNhgNQ4BAq5dVQkqxz1zxZxQvTa1kSZPO4:19XzXMaG4B3bOkqnzxZxQra1kSZP", "hash_imp": "29BC9B844EA94820F993F536087E7163", "hash_pesha1": "81E2AA16077E75ACF2864C3A114A9FA9645F66AD", "hash_pe256": "450864C73B4F5426D7629D7755AE90D8F2E9DA8F30F7B8CD309921CCAEFBC88D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Enterpise Data Protection", "meta_original_filename": "EdpNotify.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/589cacedadf3a399db2fcaa2508ec4e52df6fe4cf7aedabfcadeaf14a31c684b/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\edpnotify.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "efsui.exe-8FE2A7847AB90E6E150B6B4E4C247927": { "file_name": "efsui.exe", "file_path": "C:\\Windows\\SysWOW64\\efsui.exe", "hash_md5": "8FE2A7847AB90E6E150B6B4E4C247927", "hash_sha1": "8A417B125D22CD6E75EDD8F16C82CB2ADB4EDE3B", "hash_sha256": "15D3D82211FE83FEE501D2EFACD0168301CE73DCB7CC08F1CA7BC2EE94A61FC7", "hash_sha384": "AB31FD5E2472FAC68316A6A94A2632A06087E46DAA8E3C8E11A1FCABBD414141755053168994E4C29DFE7EB7BF6654E3", "hash_sha512": "18FAAA7EED78E6503F90041B65B8C7B9C57A2CA800A9BA4AE59A42B9D5C1F92C13246A34266D18A7FDCD1A646B921163E0E1354815F74455BCC210289E0FCAD1", "hash_ssdeep": "192:Qgeajd/FlC6t7V/TGjJKgDIjoBbqZ2kTBWSDRWqfd:tTZFlC6xp8JKjMgZxTBWSDRWqf", "hash_imp": "FBFCDB62E39168BD77F5A0D82001C66C", "hash_pesha1": "E684172D549E0A133D27F5BAEF0D4A3AA8EF93A9", "hash_pe256": "10CF362FD92E137B1CDDCADA981C0B885398E1B020BCAD64DF1B05AC95BA2F2C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EFS UI Application", "meta_original_filename": "efsui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/15d3d82211fe83fee501d2efacd0168301ce73dcb7cc08f1ca7bc2ee94a61fc7/detection", "children": "setup_wm.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\efsui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "EhStorAuthn.exe-0C9245FDD67B14B9E7FBEBB88C3A5E7F": { "file_name": "EhStorAuthn.exe", "file_path": "C:\\Windows\\SysWOW64\\EhStorAuthn.exe", "hash_md5": "0C9245FDD67B14B9E7FBEBB88C3A5E7F", "hash_sha1": "339AB7C897FC50930B29AFA0E6C11FBD1DED2E69", "hash_sha256": "DE0662EB81790FE9E872A5061BA088DA715D50156AAF1E2B0546E20892E05D8E", "hash_sha384": "602152BFE75F0892ADEBB4B3F664915DD25675215FE97BA443A25E32B4CD6975C693232D1296C95E930ECB99154D56ED", "hash_sha512": "F04F0E0856DEB528DF2DC2D728527297A8499028D962209AFAC1A9B9F502063D3AC9B9A537A9CA7A4C5C63898FABD1E3723CF2E2573F058111BEB55B8A1BB850", "hash_ssdeep": "1536:8qxyjSo/dX/n7HGYbsTfCHPeomgPHA5kG9mQ7N6wMkNaAYG5n8sRWy:QRdXTHFwKHPxPxQZDFcZIZ", "hash_imp": "D8BEA4FEF46578B7424738F766C2A7CC", "hash_pesha1": "E99268FC6182C8300FB771B98F2B70379EAF0281", "hash_pe256": "8070B31DDC33EC038495CBBABD277C11151E78F53431FEC52DE861F57044B46B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Enhanced Storage Authentication Program", "meta_original_filename": "EhStorAuthn.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/de0662eb81790fe9e872a5061ba088da715d50156aaf1e2b0546e20892e05d8e/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\EhStorAuthn.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "esentutl.exe-5F5105050FBE68E930486635C5557F84": { "file_name": "esentutl.exe", "file_path": "C:\\Windows\\SysWOW64\\esentutl.exe", "hash_md5": "5F5105050FBE68E930486635C5557F84", "hash_sha1": "2D07C804E9EFE16DDA41619D9E5F5448E524BBED", "hash_sha256": "26D0A05D6AC8584440B3B771CF8BE4746E5F2BF19FFB118FD7C7DD551F61BA74", "hash_sha384": "2DCAEEF6FCFB20B584FBA8E88B5C938A6B1529C8ED07ADDCAC10E86488CD3FFE7F4C84AD636DD76FD1A25F4423CDB041", "hash_sha512": "80F9CFC5BB514871325B947AA534D4F868B141868E6BFCA9E5255EC758E88371FE4F7FA3CC3899019B79FBD6CA13E61CE7757179BC3FAA34F440AA155DA65CF8", "hash_ssdeep": "6144:fzAG0u8JLzbva/bv7caTZmxvnJwYKlK4KhOxZTfjr4fn:sG0LJLzbvazNToxKZcGZTjrGn", "hash_imp": "F1C6F14D0CE10C71EBBD7A7E5EDDA3EF", "hash_pesha1": "E9142BDE071AE792A26AE52A41B2B0542F445810", "hash_pe256": "2FDEEE9EE5D98439E247E0F09F75874B5C108DC214A9C2FAC9DEFD3496BB61A0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extensible Storage Engine Utilities for Microsoft(R) Windows(R)", "meta_original_filename": "esentutl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/26d0a05d6ac8584440b3b771cf8be4746e5f2bf19ffb118fd7c7dd551f61ba74/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\esentutl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "eudcedit.exe-EA7665A5FFB3B16DE571F6386BD76851": { "file_name": "eudcedit.exe", "file_path": "C:\\Windows\\SysWOW64\\eudcedit.exe", "hash_md5": "EA7665A5FFB3B16DE571F6386BD76851", "hash_sha1": "EF68B45EA5F42CC859BA1C63E96B2CC72CF679D4", "hash_sha256": "9DF01A528A262F4AAB5EB53C9600AC0A2578CFA52B642A7E8A0FEA3EAE3B7F03", "hash_sha384": "6D712783F20DFBC5E14A40A82CB41D813610CF57A9AFB05404784C8A2F53B103A8DC14FE69A0BC5B66541AA809A682E7", "hash_sha512": "CD3B17A9181F44760289ECE8D146BB72B9355D58A99D80104A3C8205BDE4E50FA8B78745682A62AC1EE6002BDFDF6252493539211869DF6C736B5E23A5EDCAF6", "hash_ssdeep": "6144:P+hDFDfhzsV+URf0MkW5VTHMLOKfN6rT6Nc4mE1PZSqtYVqu6:PqVAV+0y6rT6N913tYwu6", "hash_imp": "89CE6E83A7D65B7A667CBEB550CFC769", "hash_pesha1": "7E2FA1256629F635A63C2A9C9285FF187B63C4AC", "hash_pe256": "8BB72E570A0B3A92B9289CCC6792C79B2D430C30DBCDF29D77FF9D4C55A48BA4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Private Character Editor", "meta_original_filename": "EUDCEDIT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9df01a528a262f4aab5eb53c9600ac0a2578cfa52b642a7e8a0fea3eae3b7f03/detection", "children": "powershell.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\eudcedit.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\eudcedit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Private Character Editor " }, "eventcreate.exe-49BB9DE1CFC0CAAB8454453DDB5523DF": { "file_name": "eventcreate.exe", "file_path": "C:\\Windows\\SysWOW64\\eventcreate.exe", "hash_md5": "49BB9DE1CFC0CAAB8454453DDB5523DF", "hash_sha1": "B27C3E379F4B4575F9080E56F33054B6855460C2", "hash_sha256": "AB6D407D07D35AFF98E3F59F8715B1C2A820B2D76E24E4D8CEDC13F00D1ABA31", "hash_sha384": "AFF32AACACAFA46BB96670D83B5692C93A22197799BFF2D420E4C868B2789F4D0F709ECBE2DE4482B3CD1809A47B31D9", "hash_sha512": "B3285677468664F20D169652879DA9BB693C523E57E292051BE95DE8100C01A8631A410B617D5B89F2D73795A321429B9A8015FC9C6DE14A28FDA1C327CE2FF6", "hash_ssdeep": "768:PYgnYOP9WXFQk762tjYgThdzdikWOyRkP5j53nil7Ooa+Q/6z:PYgYOPQ1D/KgdzdimlBRil7va+Q/", "hash_imp": "D9D5E96F73EC284F3BDBECE646CCF1EC", "hash_pesha1": "B79FBCD61AAE8B7903336581DB599A1CD14FF678", "hash_pe256": "99C89C6908AAB4C5D16BAAEC4548AD2C3FC408D1F479C9871E54FDC93ED22CB7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Create - Creates a custom event in an event log", "meta_original_filename": "evcreate.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/ab6d407d07d35aff98e3f59f8715b1c2a820b2d76e24e4d8cedc13f00d1aba31/detection", "output": "\r\nEVENTCREATE [/S system [/U username [/P [password]]]] /ID eventid\r\n [/L logname] [/SO srcname] /T type /D description\r\n\r\nDescription:\r\n This command line tool enables an administrator to create\r\n a custom event ID and message in a specified event log.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /L logname Specifies the event log to create\r\n an event in.\r\n\r\n /T type Specifies the type of event to create.\r\n Valid types: SUCCESS, ERROR, WARNING, INFORMATION.\r\n\r\n /SO source Specifies the source to use for the\r\n event (if not specified, source will default\r\n to 'eventcreate'). A valid source can be any\r\n string and should represent the application\r\n or component that is generating the event.\r\n\r\n /ID id Specifies the event ID for the event. A\r\n valid custom message ID is in the range\r\n of 1 - 1000.\r\n\r\n /D description Specifies the description text for the new event.\r\n\r\n /? Displays this help message.\r\n\r\n\r\nExamples:\r\n EVENTCREATE /T ERROR /ID 1000\r\n /L APPLICATION /D \"My custom error event for the application log\"\r\n\r\n EVENTCREATE /T ERROR /ID 999 /L APPLICATION\r\n /SO WinWord /D \"Winword event 999 happened due to low diskspace\"\r\n\r\n EVENTCREATE /S system /T ERROR /ID 100\r\n /L APPLICATION /D \"Custom job failed to install\"\r\n\r\n EVENTCREATE /S system /U user /P password /ID 1 /T ERROR\r\n /L APPLICATION /D \"User access failed due to invalid user credentials\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"EVENTCREATE /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\eventcreate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "eventvwr.exe-0B6FEE1C98B1290BB4C05596A37B8EE2": { "file_name": "eventvwr.exe", "file_path": "C:\\Windows\\SysWOW64\\eventvwr.exe", "hash_md5": "0B6FEE1C98B1290BB4C05596A37B8EE2", "hash_sha1": "A6B21843720A2BD6B044B5078E7E94DCA8CC6B06", "hash_sha256": "A05F5F53458B25C025D9DACD0864CD07C78D0F1D8496E7D89EACDA3F0005120C", "hash_sha384": "66A83ABE3A58A321A2C1C9184AA0236988D8242D0B1E6404E77F1C6A80BEB2690D7BBACE10DE14324BA233F9FBF00D9C", "hash_sha512": "9DD12BB4F910174951344F7C9FA5982819CC6350944B1BA6960F4954BAEE8DE0BA052FF393CF060012A842EC8ACAD0868676366AA20DCB7765BA6B6BF0D169DF", "hash_ssdeep": "1536:azChIMfoJUhSU6nPlTggJ2oj71BgR/Vp8dY1/:v3lhzslTZJ9j7Heb8C1/", "hash_imp": "6202C13AD7EF6559EA1F41430390B2E0", "hash_pesha1": "457CA6E17AE4D4720368197FFE3CC6D876B48225", "hash_pe256": "036718F286B03C0B308A711B5502AEB67018B411BBE904AFADA17E852D5D7684", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Viewer Snapin Launcher", "meta_original_filename": "eventvwr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/a05f5f53458b25c025d9dacd0864cd07c78d0f1d8496e7d89eacda3f0005120c/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\eventvwr.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "Event Viewer", "children": "mmc.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\eventvwr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "expand.exe-544B0DBFF3F393BCE8BB9D815F532D51": { "file_name": "expand.exe", "file_path": "C:\\Windows\\SysWOW64\\expand.exe", "hash_md5": "544B0DBFF3F393BCE8BB9D815F532D51", "hash_sha1": "5D256016C9095AD9D9D9A33CC310EB810A9D80FE", "hash_sha256": "DFC1709A2988301F7A9D145FB107793E3299ECC85F4B9702523939E35573AB85", "hash_sha384": "F6136DDD88E17C3FC54D5FB58CB578DF93C4DC89C3BAB29A851968239F434011A3D4829E1B5CFC47D0C5FEB69A7B9493", "hash_sha512": "3F9A937967FD748C7B58EC6E40040990EB177173C0B43476F8AE20FD0906E640ECDB8C82828BC1DACD8218325855BAD52D62221222EC5175E732570D4386561A", "hash_ssdeep": "768:ZQPMXOSialKHjiPqqg4VEneL6a74UnAgFeErpPeQjNLUnk:ZQPMKHeSmVdL174UnAyFPhjVUnk", "hash_imp": "69150CCEA4BC1D53D379CE29BCAE7760", "hash_pesha1": "1C025A96A3510508072FBD63D550BE2F4615BD71", "hash_pe256": "526D92818337E34324BB1E8ED0A8FBE26D6C9E4089144F70985BE85A4F1000D1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "LZ Expansion Utility", "meta_original_filename": "expand", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.00 (WinBuild.160101.0800)", "meta_product_version": "5.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/dfc1709a2988301f7a9d145fb107793e3299ecc85f4b9702523939e35573ab85/detection", "output": "Microsoft (R) File Expansion Utility\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nNo destination specified for: help.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\expand.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "explorer.exe-D7F24279DBF00B5E19DD7CA4B71D83FD": { "file_name": "explorer.exe", "file_path": "C:\\Windows\\SysWOW64\\explorer.exe", "hash_md5": "D7F24279DBF00B5E19DD7CA4B71D83FD", "hash_sha1": "87A80DBBF40428C4222E98FF223D8A9145118291", "hash_sha256": "6620395D8DDE0A46C329E16DF15AA02EB63954C4AE0CB9DCA44558D27E3C53D8", "hash_sha384": "D7E13C084555C7C566A16A0174D213A5D24F896C834C994CFCADFB3463FA9D81B29842E4F73714D84097EE0264F4897B", "hash_sha512": "1544D501BF9B58B5A20075C6D5E3D0E46433317FEDF725082A1A7921D8F17DA07ABE04282F604A553D13D3EE1E224C3A5EEDDF236AF0B1B062C3C23C65582266", "hash_ssdeep": "98304:PTFeMQ17fBsRry5gPZjE8fvxPqNUux6w8a0cDoU:PTFeMQ17feRry54ZjhfvxPqNUFwFZL", "hash_imp": "069E9ED908FC6692795780CE08D0EF22", "hash_pesha1": "A46E79B378265531A38E7AF91B43210D3C5F3B64", "hash_pe256": "2B1320FC9F6716D9F39CD424A726D531DFCE570919729ED0A2E56AA947E8384A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Explorer", "meta_original_filename": "EXPLORER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/6620395d8dde0a46c329e16df15aa02eb63954c4ae0cb9dca44558d27e3c53d8/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\explorer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "extrac32.exe-9472AAB6390E4F1431BAA912FCFF9707": { "file_name": "extrac32.exe", "file_path": "C:\\Windows\\SysWOW64\\extrac32.exe", "hash_md5": "9472AAB6390E4F1431BAA912FCFF9707", "hash_sha1": "73EAE67D723328D609E43531E80DB37219ED5E02", "hash_sha256": "A91D32973A1097EB1131FF630B0C082406703C48B8F442955DDA184C43BCE99E", "hash_sha384": "4CC8041CC3F31EED5D5095DE077E0082674E884A6CE72B208641DE469D803796B3E71A9F978A75F27D60401E799C7979", "hash_sha512": "8671662575E3166CB31875CB618FBD7ED4BD80112AD849F05CAE28B725E1DC129A6099D00879006E4F451B64E5B8DF558A4E8C35D274ED003FB572964008E09E", "hash_ssdeep": "768:jYDhe6vo5kwydC3ryl77oOP6emNLZnlOsWLuYksMfdxH:jOheqo5k77oe6eoyBuNsMfd", "hash_imp": "7B1D3FE0DC6AA68A34FB0D96A1457FE6", "hash_pesha1": "052FD384AFA1A7883AFB02A1C1F0E05771D48B57", "hash_pe256": "519EE514572F1CBAD00A931C97BEBF085FB83694044931C66AC5D46BA83888F4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft CAB File Extract Utility", "meta_original_filename": "extrac32.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.00 (WinBuild.160101.0800)", "meta_product_version": "5.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a91d32973a1097eb1131ff630b0c082406703c48b8f442955dda184c43bce99e/detection", "output": "Microsoft (R) Cabinet Extraction Tool\r\nCopyright (c) Microsoft Corporation. All rights reserved..\r\n\r\nEXTRACT [/Y] [/A] [/D | /E] [/L dir] cabinet [filename ...]\r\nEXTRACT [/Y] source [newname]\r\nEXTRACT [/Y] /C source destination\r\n\r\n cabinet - Cabinet file (contains two or more files).\r\n filename - Name of the file to extract from the cabinet.\r\n Wild cards and multiple filenames (separated by\r\n blanks) may be used.\r\n\r\n source - Compressed file (a cabinet with only one file).\r\n newname - New filename to give the extracted file.\r\n If not supplied, the original name is used.\r\n\r\n /A Process ALL cabinets. Follows cabinet chain\r\n starting in first cabinet mentioned.\r\n /C Copy source file to destination (to copy from DMF disks).\r\n /D Display cabinet directory (use with filename to avoid extract).\r\n /E Extract (use instead of *.* to extract all files).\r\n /L dir Location to place extracted files (default is current directory).\r\n /Y Do not prompt before overwriting an existing file.", "runtime_modules": [ "C:\\Windows\\SysWOW64\\extrac32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "fc.exe-4D5F86B337D0D099E18B14F1428AAEFF": { "file_name": "fc.exe", "file_path": "C:\\Windows\\SysWOW64\\fc.exe", "hash_md5": "4D5F86B337D0D099E18B14F1428AAEFF", "hash_sha1": "3122B5A4A51AA9B5435DBEA0E335C3A6405F0267", "hash_sha256": "9C52BFD3C2EFD9DBC031112359F4F8C4B002B4C829D70862BE100D17710DAC01", "hash_sha384": "A94EAE95CBB97E41F6D67ACFA3752980DC6F115678DA72C40E9E95C2577CB4C2C2FB8E14FC6A2EC0A37B9D763B893AE6", "hash_sha512": "8D41AB4A53D275DFC046EC1707D2154025BDC9F19A52E1A9A26D5B5C22333ED3EE29022C10BBEF6907A9EC7D3E004CBA459752E3695669650187E8D97E2E6BE7", "hash_ssdeep": "384:wq9Vyq/AGmYtxQht5IgFeudWVlggjdAPKAa3SNZU7YbWWFYWlr:DVy6AGmExQhtCBuQo6E9X", "hash_imp": "8737B5A2A0AC9AC3783A38A0C047A140", "hash_pesha1": "0F76A656154ECAC90A9DBDACE56120E0562FB02C", "hash_pe256": "E4A8E7FA899CE9B707152609EE0705865DBDF9DCB2E6BD2F3F30D7F4A507F401", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DOS 5 File Compare Utility", "meta_original_filename": "FC.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9c52bfd3c2efd9dbc031112359f4f8c4b002b4c829d70862be100d17710dac01/detection", "output": "Compares two files or sets of files and displays the differences between\r\nthem\r\n\r\n\r\nFC [/A] [/C] [/L] [/LBn] [/N] [/OFF[LINE]] [/T] [/U] [/W] [/nnnn]\r\n [drive1:][path1]filename1 [drive2:][path2]filename2\r\nFC /B [drive1:][path1]filename1 [drive2:][path2]filename2\r\n\r\n /A Displays only first and last lines for each set of differences.\r\n /B Performs a binary comparison.\r\n /C Disregards the case of letters.\r\n /L Compares files as ASCII text.\r\n /LBn Sets the maximum consecutive mismatches to the specified\r\n number of lines.\r\n /N Displays the line numbers on an ASCII comparison.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n /T Does not expand tabs to spaces.\r\n /U Compare files as UNICODE text files.\r\n /W Compresses white space (tabs and spaces) for comparison.\r\n /nnnn Specifies the number of consecutive lines that must match\r\n after a mismatch.\r\n [drive1:][path1]filename1\r\n Specifies the first file or set of files to compare.\r\n [drive2:][path2]filename2\r\n Specifies the second file or set of files to compare.\r\n\r\n", "error": "FC: Insufficient number of file specifications\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\fc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "find.exe-31D06677CD9ACA84EA2E2E8E3BF22D65": { "file_name": "find.exe", "file_path": "C:\\Windows\\SysWOW64\\find.exe", "hash_md5": "31D06677CD9ACA84EA2E2E8E3BF22D65", "hash_sha1": "83780092915B15E5188AD0B2E7A683442566F3BF", "hash_sha256": "63DDBCB0233ED7C8C90748869EC5879309A351FFC6D230AF66CCDE8372F00B34", "hash_sha384": "397D0BE78FF9E7F80E3C1EDFE841CC85F9BC66435DD3BFEE1E4C1077C92B6506F100B10E53430A050BB160B1E8B2CFE5", "hash_sha512": "AEF0356F9D6C9A35189305A507A02E3874F573A693293331971BF46F698A1398C2DEE1D89F742D25109E28DB826DB8932CB1FDEA412FB123BFAF6B6D7FDAAE33", "hash_ssdeep": "384:HIGKTPCCRLMRUXIQmm9Me7sNDT6zjazWOIW7:HIGKjCCRLMRU4bm9Me7sJGzONR", "hash_imp": "F1CCECB8E289C2632DEE607CD74A0CCA", "hash_pesha1": "16E63F62C8A3D27CDDF30E1A69928DE534E05D16", "hash_pe256": "67DC28AD2A6507CE06FCF58F3CF642F44A87DF2A6F5BA85D48C2F757BFB276BF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Find String (grep) Utility", "meta_original_filename": "FIND.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/63ddbcb0233ed7c8c90748869ec5879309a351ffc6d230af66ccde8372f00b34/detection", "output": "Searches for a text string in a file or files.\r\n\r\nFIND [/V] [/C] [/N] [/I] [/OFF[LINE]] \"string\" [[drive:][path]filename[ ...]]\r\n\r\n /V Displays all lines NOT containing the specified string.\r\n /C Displays only the count of lines containing the string.\r\n /N Displays line numbers with the displayed lines.\r\n /I Ignores the case of characters when searching for the string.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n \"string\" Specifies the text string to find.\r\n [drive:][path]filename\r\n Specifies a file or files to search.\r\n\r\nIf a path is not specified, FIND searches the text typed at the prompt\r\nor piped from another command.\r\n", "error": "FIND: Parameter format not correct\r\n", "children": "mmc.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\find.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "findstr.exe-F1D4BE0E99EC734376FDE474A8D4EA3E": { "file_name": "findstr.exe", "file_path": "C:\\Windows\\SysWOW64\\findstr.exe", "hash_md5": "F1D4BE0E99EC734376FDE474A8D4EA3E", "hash_sha1": "D8B69C48D0B67D1825F191984E2032712823E4EC", "hash_sha256": "1900C48FDB1C2DDFA59C37BA86AFFA502D44AF55F313D0D53FAC60D9B96943B6", "hash_sha384": "87D5D38D092A6C7CB8018330844EB26A424E0C254D126AD5D03F005C4D210818C52DCF379D205C7BDC96F4001801CD56", "hash_sha512": "4299D6599C48884A120277CA28B3FFA591B6180AEE8DA891A7AD85DDC316B01B8B67E29280CAB684C1A4E84D964C0F98A58AB2C10779E17BC4A3485C7D56948D", "hash_ssdeep": "384:spHiw5XBWHg7B7FHn74cPQDRdExW4MkRfX0wbHu26BQtP3vMhfGGNYeCPXm0DnfM:Dw5XYAVpkBSREZuMwgYJm0jyqtVm", "hash_imp": "AD72E3C04C1BC40AB74532464B40A96E", "hash_pesha1": "2639F098E94DDD5E05ABF93B353CBC04EF3CB981", "hash_pe256": "43990C57845ACF5157DA5EF40CA1C5A49C0618183A8D40C72DEC63F702DC67AD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Find String (QGREP) Utility", "meta_original_filename": "FINDSTR.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1900c48fdb1c2ddfa59c37ba86affa502d44af55f313d0d53fac60d9b96943b6/detection", "output": "Searches for strings in files.\r\n\r\nFINDSTR [/B] [/E] [/L] [/R] [/S] [/I] [/X] [/V] [/N] [/M] [/O] [/P] [/F:file]\r\n [/C:string] [/G:file] [/D:dir list] [/A:color attributes] [/OFF[LINE]]\r\n strings [[drive:][path]filename[ ...]]\r\n\r\n /B Matches pattern if at the beginning of a line.\r\n /E Matches pattern if at the end of a line.\r\n /L Uses search strings literally.\r\n /R Uses search strings as regular expressions.\r\n /S Searches for matching files in the current directory and all\r\n subdirectories.\r\n /I Specifies that the search is not to be case-sensitive.\r\n /X Prints lines that match exactly.\r\n /V Prints only lines that do not contain a match.\r\n /N Prints the line number before each line that matches.\r\n /M Prints only the filename if a file contains a match.\r\n /O Prints character offset before each matching line.\r\n /P Skip files with non-printable characters.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n /A:attr Specifies color attribute with two hex digits. See \"color /?\"\r\n /F:file Reads file list from the specified file(/ stands for console).\r\n /C:string Uses specified string as a literal search string.\r\n /G:file Gets search strings from the specified file(/ stands for console).\r\n /D:dir Search a semicolon delimited list of directories\r\n strings Text to be searched for.\r\n [drive:][path]filename\r\n Specifies a file or files to search.\r\n\r\nUse spaces to separate multiple search strings unless the argument is prefixed\r\nwith /C. For example, 'FINDSTR \"hello there\" x.y' searches for \"hello\" or\r\n\"there\" in file x.y. 'FINDSTR /C:\"hello there\" x.y' searches for\r\n\"hello there\" in file x.y.\r\n\r\nRegular expression quick reference:\r\n . Wildcard: any character\r\n * Repeat: zero or more occurrences of previous character or class\r\n ^ Line position: beginning of line\r\n $ Line position: end of line\r\n [class] Character class: any one character in set\r\n [^class] Inverse class: any one character not in set\r\n [x-y] Range: any characters within the specified range\r\n \\x Escape: literal use of metacharacter x\r\n \\<xyz Word position: beginning of word\r\n xyz\\> Word position: end of word\r\n\r\nFor full information on FINDSTR regular expressions refer to the online Command\r\nReference.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\findstr.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "error": "FINDSTR: /- ignored\r\nFINDSTR: /h ignored\r\nFINDSTR: Bad command line\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\findstr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "finger.exe-C586D06BF5D5B3E6E9E3289F6AA8225E": { "file_name": "finger.exe", "file_path": "C:\\Windows\\SysWOW64\\finger.exe", "hash_md5": "C586D06BF5D5B3E6E9E3289F6AA8225E", "hash_sha1": "140E4BF6934EEF85C10A96EE45CC6E479AA30992", "hash_sha256": "781F1BB7080EF4DC5BD8B5F6E3D7CD1AE304E0DA6DE135B166EF686326E87C5F", "hash_sha384": "07213C43E06CC71A3513D74B097325BF5A95270D936F89AB60BD9A49919B540F367FEA45C96F0BDF0530A40A6414214C", "hash_sha512": "00A3421557C1E08FA476F78C0A4C615DE57E85AB69E46C9E56BE1E6BE2CED01CEF3988029E07BAB3F9950064B9F8A4B8A4019D329DF89DF2FC5ACE76B50D9548", "hash_ssdeep": "192:k7obhx5K9enOD92DgDmX/mXp6MFE+jJ6wWoWl0W0W:EUhx5MenW2DjXeXRTjJ1pWl0W", "hash_imp": "DD36F61A81704582E5C476E946B3969A", "hash_pesha1": "C9C041E329135864D46954B13137570689AE9898", "hash_pe256": "C58AAC1FADBEC621A61AF1C3CCFABC22721C4E039936180FDB251182B272B9B9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCPIP Finger Command", "meta_original_filename": "finger.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/781f1bb7080ef4dc5bd8b5f6e3d7cd1ae304e0da6de135b166ef686326e87c5f/detection", "error": "\r\nDisplays information about a user on a specified system running the\r\nFinger service. Output varies based on the remote system.\r\n\r\nFINGER [-l] [user]@host [...]\r\n\r\n -l Displays information in long list format.\r\n user Specifies the user you want information about. Omit the user\r\n parameter to display information about all users on the\r\n specifed host.\r\n @host Specifies the server on the remote system whose users you\r\n want information about.\r\n\r\n", "output": "\r\n[DESKTOP-F9N3CL1]\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\finger.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\finger.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "fixmapi.exe-D2EB94CD3D20772989DF0CB0DE56C3ED": { "file_name": "fixmapi.exe", "file_path": "C:\\Windows\\SysWOW64\\fixmapi.exe", "hash_md5": "D2EB94CD3D20772989DF0CB0DE56C3ED", "hash_sha1": "ADD5EB08AFC97693E7F1A48B6AF413D3FF59F113", "hash_sha256": "1AD59AE610D513F1D85E54C2A791D48AE71960F78BB1A214A36718F57C838E85", "hash_sha384": "0C8E59F81BBA1C3EC52E29C07B16353C77DFA86E07045452840A9E3610A07E71420667421EB4D1FE97489F20D8541913", "hash_sha512": "DE5DEF2106751136F9A124BFFECEF3F53410EC32C87D3D99FAF9D8ED49F7D30D04B3FB75754C55309229F10373216679315D2BC1FA9DB7E69E5BADE8656CF911", "hash_ssdeep": "192:WJlZn76w9UikCQ31gKssG5Ag/3+HoeSMNNrm1Fp5kgWbnWq9nMV:W9ELCmgK051/uI4Nr9gWbnWqpMV", "hash_imp": "AA30E33727F4F0E9977929AB0E68947A", "hash_pesha1": "2F3E795DE672F52060BE293E53EA193140BF42FD", "hash_pe256": "3ABD938D22A392D3166697B457FD57963B2DC0B69AAE7929AF1D72E9543DF55C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "FIXMAPI 1.0 MAPI Repair Tool", "meta_original_filename": "FIXMAPI.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/1ad59ae610d513f1d85e54c2a791d48ae71960f78bb1a214a36718f57c838e85/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\fixmapi.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "fltMC.exe-330E111C418797FC2E56F3F7E5FAAB9A": { "file_name": "fltMC.exe", "file_path": "C:\\Windows\\SysWOW64\\fltMC.exe", "hash_md5": "330E111C418797FC2E56F3F7E5FAAB9A", "hash_sha1": "F7405889D043C4A872C1246D16C4D006BD1405CC", "hash_sha256": "7E2A2A6D4ED446503A677A98EDB90CF12838B5764CE863AFDDAFB45F3B631597", "hash_sha384": "C81E702BB831269400A9374EF4B70C55DC41CAC20C2D959BC5E0624019CBDF654307E7CDE85E25C5F2390F49D779DFAD", "hash_sha512": "3B938BBF513BB8265214556BE9C28E2B0C8A66EB2DF3E4CDF90A3B79F113788CF35EC34FBF9F32F406EAAE42976F3B8A7B9CE0535CFDE2D625005E3D781A3B14", "hash_ssdeep": "384:EAMNUGvYUI9LwOnrnq0px6izavkJjjJ5X8cR29WY9WK6:EFI9LwOnrnq2oiOvk3+cR2Z", "hash_imp": "50932E942F8E6C207BD1C02FB974B27C", "hash_pesha1": "F04E8DE6AA584963E36DB68405B48825B60B58B4", "hash_pe256": "53A55D4873B684D01AFA10A957763BB8FB4A7C3621A526F2F59E1148BF0C3968", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Filter Manager Control Program", "meta_original_filename": "fltMC.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7e2a2a6d4ed446503a677a98edb90cf12838b5764ce863afddafb45f3b631597/detection", "output": "\r\n** Invalid command\r\nValid commands:\r\n load Loads a Filter driver\r\n unload Unloads a Filter driver\r\n filters Lists the Filters currently registered in the system\r\n instances Lists the Instances for a Filter or Volume currently\r\n registered in the system\r\n volumes Lists all volumes/RDRs in the system\r\n attach Creates a Filter Instance to a Volume\r\n detach Removes a Filter Instance from a Volume\r\n\r\n Use fltmc help [ command ] for help on a specific command\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\fltMC.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Fondue.exe-69A312336DBCAE207F5D8C04520B9B3C": { "file_name": "Fondue.exe", "file_path": "C:\\Windows\\SysWOW64\\Fondue.exe", "hash_md5": "69A312336DBCAE207F5D8C04520B9B3C", "hash_sha1": "F0B1B23EB18C0818897CB36E2B16E01F2E7C63ED", "hash_sha256": "8F4758F2B671E901CFC743FB7F3BD7B63094D84D55B4D8F7EB0722BA1205A6D2", "hash_sha384": "DF19C94A6C044779BEE023A238A9620004DA04D1673E8DA31E3325ECF0CDE9F18172A4508B477B082F5C7BF6AFF57437", "hash_sha512": "88F4BEBE4973F5F29B640792D21227D99AE234A834FAAB6C0BF07DF0BB0DCAF5D020B244E8CF752E4C1BAD3D0046313455598373A64947B65E690CAD64F600B8", "hash_ssdeep": "3072:2zslQbEaznWfH22ZsuX2xKwMPTnaSrIrvDJ:aQuznWjZnXeKwMLnaqY", "hash_imp": "C90A9B51B5004E7BF81F560D871186E8", "hash_pesha1": "3A85AB9BDB5A6AD857E896F40D2070640F6DE2B9", "hash_pe256": "916C757994B67FC3C554B5D9155846F1680A2D78B8820D58DD15BA74F0E5319C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Features on Demand UX", "meta_original_filename": "Fondue.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/8f4758f2b671e901cfc743fb7f3bd7b63094d84d55b4d8f7eb0722ba1205a6d2/detection", "children": "Fondue.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\Fondue.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\Fondue.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "fontdrvhost.exe-11DB5997A69803AA14FDEE3A16655911": { "file_name": "fontdrvhost.exe", "file_path": "C:\\Windows\\SysWOW64\\fontdrvhost.exe", "hash_md5": "11DB5997A69803AA14FDEE3A16655911", "hash_sha1": "BB223AE1F48ACAF3DC772616D965F40A64BEE93D", "hash_sha256": "605DFC2BDF26A311335F395FC4FDA76A6F7617DFE0A39D740043817BF8687F29", "hash_sha384": "5C2F0F59772857A63F404471425AADBF70F26B5517D287D8CC6D8F279BD689AFFF7DE0B7C745AF6898A30F76E306E990", "hash_sha512": "F6A94BFCA5209FFDE74E1A7B2DC79B0630C85438F03E9399C0765BC1B312AC627F11F2D56AFE8E52F64577C7EB3B16089598DC2323EB9F9EDA8C854D1B060D68", "hash_ssdeep": "12288:WAztbcoocbXmEMP7nJC+bEyO1AKwnC08SAKR06F6wq:WAztbco6EMjg+bEyO1AjCvSRs", "hash_imp": "7C5B72E9C85B4AACD28EB4806FA7623F", "hash_pesha1": "B764BB25344EFCA284DE0B885B77953299975CEB", "hash_pe256": "07BAD1F56AE9CBF14BFA9834CBE364ABAE38FBD2DF08DF5CCE35C228DF7A66AE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Usermode Font Driver Host", "meta_original_filename": "fontdrvhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/605dfc2bdf26a311335f395fc4fda76a6f7617dfe0a39d740043817bf8687f29/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\fontdrvhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "fontview.exe-8324ECE6961ADBE6120CCE9E0BC05F76": { "file_name": "fontview.exe", "file_path": "C:\\Windows\\SysWOW64\\fontview.exe", "hash_md5": "8324ECE6961ADBE6120CCE9E0BC05F76", "hash_sha1": "2047BC42BD465A3F47A2A9EB6823C3C0A68E7405", "hash_sha256": "3D20938ABDFC1BCBDD5FCDE9DC6C813C99C5B20A187BB944EA4FE4B1AC0EECE8", "hash_sha384": "0B828382797A7F2F2D2332511D2B68CE93E5EF4555C5448B0EAF9F90B0697A6DEC2B3BBE524070195B6644B066658E89", "hash_sha512": "A0C71234866020CD5AC84DDA040BAE8586E557398E294C8756C95F63EFAEDE6BA7EC01F59F4FFFAF3E79F799B2AD91E5606E61D8707762E6FE9DC1DB1B66FE5C", "hash_ssdeep": "3072:84y9KY1ReNJjWRkOtHxtt3EOL2QvIsitSYVeUd:Fy9KY1RiWRRZzqGYZd", "hash_imp": "45C6DEC368899AF38B3C2F1BD3E62E67", "hash_pesha1": "D97696452385300BBEC78A021846F43E2B9B7EB4", "hash_pe256": "144F3923AE2BC5CB8270F0A4BA8BC5CD60A46BBE8617CEF0AA874EDA9C8B1DB7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Font Viewer", "meta_original_filename": "FONTVIEW.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/3d20938abdfc1bcbdd5fcde9dc6c813c99c5b20a187bb944ea4fe4b1ac0eece8/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\fontview.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\fontview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Font Viewer " }, "forfiles.exe-D95C443851F70F77427B3183B1619DD3": { "file_name": "forfiles.exe", "file_path": "C:\\Windows\\SysWOW64\\forfiles.exe", "hash_md5": "D95C443851F70F77427B3183B1619DD3", "hash_sha1": "0CF2936B8D074F39FE030FEF6266AF53399B31AF", "hash_sha256": "7074D2A9C3D669A15D5B3A7BA1226DBBA05888CC537CF055FED6371F32F0C1F5", "hash_sha384": "212E167B8738E62237330655E5C0BED77BF5E150796FA2B5F3CAF1C3B9B4FC788EB0BD4678337EC6CAE186EF29815B26", "hash_sha512": "641F5900269341233C32F9CB62B943D116AC719FE6E2337E8B78FE8CDE9CFD5CC1CD5C0217A7D7E1055E24D25860CE2550A75393E6F6A184FCB3E4F77DCC5550", "hash_ssdeep": "768:f96OOt1TmpvqEHZLDarw+Vv9Tm8oIiItPT98u0BZi5MjcPA/Fw2Dx899BLlv/:f96OaTm5HZDarwATNi6KBZi+k7gx8/BF", "hash_imp": "64E68F7B6E212C1F2B12FFE1C1CFE372", "hash_pesha1": "5FA58513EB01CEE5DA4FEC1FFE174B8032C12493", "hash_pe256": "0C5B2181FE6C525D964E08F09856256A458B819B18395D6FAF78EA0B5343AE19", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ForFiles - Executes a command on selected files", "meta_original_filename": "forfiles.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7074d2a9c3d669a15d5b3a7ba1226dbba05888cc537cf055fed6371f32f0c1f5/detection", "output": "\r\nFORFILES [/P pathname] [/M searchmask] [/S]\r\n [/C command] [/D [+ | -] {MM/dd/yyyy | dd}]\r\n\r\nDescription:\r\n Selects a file (or set of files) and executes a \r\n command on that file. This is helpful for batch jobs.\r\n\r\nParameter List:\r\n /P pathname Indicates the path to start searching.\r\n The default folder is the current working\r\n directory (.).\r\n\r\n /M searchmask Searches files according to a searchmask.\r\n The default searchmask is '*' .\r\n\r\n /S Instructs forfiles to recurse into\r\n subdirectories. Like \"DIR /S\".\r\n\r\n /C command Indicates the command to execute for each file.\r\n Command strings should be wrapped in double\r\n quotes. \r\n\r\n The default command is \"cmd /c echo @file\".\r\n\r\n The following variables can be used in the\r\n command string:\r\n @file - returns the name of the file.\r\n @fname - returns the file name without\r\n extension.\r\n @ext - returns only the extension of the\r\n file.\r\n @path - returns the full path of the file.\r\n @relpath - returns the relative path of the\r\n file.\r\n @isdir - returns \"TRUE\" if a file type is\r\n a directory, and \"FALSE\" for files.\r\n @fsize - returns the size of the file in\r\n bytes.\r\n @fdate - returns the last modified date of the\r\n file.\r\n @ftime - returns the last modified time of the\r\n file.\r\n\r\n To include special characters in the command \r\n line, use the hexadecimal code for the character\r\n in 0xHH format (ex. 0x09 for tab). Internal\r\n CMD.exe commands should be preceded with\r\n \"cmd /c\".\r\n\r\n /D date Selects files with a last modified date greater\r\n than or equal to (+), or less than or equal to\r\n (-), the specified date using the\r\n \"MM/dd/yyyy\" format; or selects files with a\r\n last modified date greater than or equal to (+)\r\n the current date plus \"dd\" days, or less than or\r\n equal to (-) the current date minus \"dd\" days. A\r\n valid \"dd\" number of days can be any number in\r\n the range of 0 - 32768.\r\n \"+\" is taken as default sign if not specified.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n FORFILES /?\r\n FORFILES \r\n FORFILES /P C:\\WINDOWS /S /M DNS*.* \r\n FORFILES /S /M *.txt /C \"cmd /c type @file | more\"\r\n FORFILES /P C:\\ /S /M *.bat\r\n FORFILES /D -30 /M *.exe\r\n /C \"cmd /c echo @path 0x09 was changed 30 days ago\"\r\n FORFILES /D 01/01/2001\r\n /C \"cmd /c echo @fname is new since Jan 1st 2001\"\r\n FORFILES /D +12/12/2020 /C \"cmd /c echo @fname is new today\"\r\n FORFILES /M *.exe /D +1\r\n FORFILES /S /M *.doc /C \"cmd /c echo @fsize\" \r\n FORFILES /M *.txt /C \"cmd /c if @isdir==FALSE notepad.exe @file\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"FORFILES /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\forfiles.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "fsquirt.exe-BA54013CAD72CD79D2B7843602835ED3": { "file_name": "fsquirt.exe", "file_path": "C:\\Windows\\SysWOW64\\fsquirt.exe", "hash_md5": "BA54013CAD72CD79D2B7843602835ED3", "hash_sha1": "F89261D8AB16CFECA8A26A9E49DAB0AEEBF1F0DB", "hash_sha256": "323D09A48B982F2E880F4BC529F6756BBE53CB59CED8DEABBF3705CD5DE935E2", "hash_sha384": "95B95F74CA5F87052173EE2037C2A49B99F4FD13840FBA862953B2C812E0B5B3DC34C82602EA5515F31EDD1EFD6C9648", "hash_sha512": "BB8909C633D751282821DE98592FAF6A5E7EC29F8F7426B5874CAD495C2683EFA08897087B8C948200A27B41C16D83220F2D6F1146B775515B89DA6AC24A0397", "hash_ssdeep": "1536:4Cyn7pGs+ZZp4FYwtsv4+LThW3dFMyYvXAlxM3lFJnhIK:Hs+bp43tsAmW3dFMrAlKVDh", "hash_imp": "6314EE5B74F8A2221CEBEC09F5B1A761", "hash_pesha1": "E7DBB12941ED9A0D7564C070003A93E0A561F82D", "hash_pe256": "6B30C4B345F83DE8A2FD22A8458692727A6B0464F57ADB894FD82C1A1A118C1B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "fsquirt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/323d09a48b982f2e880f4bc529f6756bbe53cb59ced8deabbf3705cd5de935e2/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\fsquirt.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\fsquirt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Bluetooth File Transfer" }, "fsutil.exe-452CA7574A1B2550CD9FF83DDBE87463": { "file_name": "fsutil.exe", "file_path": "C:\\Windows\\SysWOW64\\fsutil.exe", "hash_md5": "452CA7574A1B2550CD9FF83DDBE87463", "hash_sha1": "E98B328B51FF18D2042C0A75CF8F5F882FBAC4BB", "hash_sha256": "B732E4E29A2D768417BBCD1B18368B1BA9BFECF0EB4AF320C27B5D800D1F8DA2", "hash_sha384": "9EB4CB7A0A93E5AB0E3A0BEAF73248E4B82AA797F95738DB69B1AF626167739E5A6969622081EACB5E33C0C0DE60D97F", "hash_sha512": "CAE5D6C7271BD6BE2D4D87538E4142330C87CA84032B8222829126C950F13A84E64900DAF1F35EF6AFB26D9FFB3EC1968CFDA6EE88D91EDB14CA91131B56452E", "hash_ssdeep": "3072:Oy90dPKnlGwgbLOAZc7ejIKsvF6oW/GAYbHOeMFNa/zob48OQrq7w:KKn0Pb5qejIKMF6oFAN7FNa/zu48Ouq", "hash_imp": "6B1F6721FD39601739EB215E5FBA7364", "hash_pesha1": "091E4BCB0594DAF1DCBAD1307F665D23F63D3810", "hash_pe256": "027166710C994880B9B86F6D29D34FBFA5C57F32C1B58E59B2476372FAF7229D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "fsutil.exe", "meta_original_filename": "fsutil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b732e4e29a2d768417bbcd1b18368b1ba9bfecf0eb4af320c27b5d800d1f8da2/detection", "output": "--help is an invalid parameter.\r\n---- Commands Supported ----\r\n\r\n8dot3name 8dot3name management\r\nbehavior Control file system behavior\r\ndax Dax volume management\r\ndirty Manage volume dirty bit\r\nfile File specific commands\r\nfsInfo File system information\r\nhardlink Hardlink management\r\nobjectID Object ID management\r\nquota Quota management\r\nrepair Self healing management\r\nreparsePoint Reparse point management\r\nstorageReserve Storage Reserve management\r\nresource Transactional Resource Manager management\r\nsparse Sparse file control\r\ntiering Storage tiering property management\r\ntransaction Transaction management\r\nusn USN management\r\nvolume Volume management\r\nwim Transparent wim hosting management\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\fsutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ftp.exe-8F8733C9166875645438CA7F57E4FEE7": { "file_name": "ftp.exe", "file_path": "C:\\Windows\\SysWOW64\\ftp.exe", "hash_md5": "8F8733C9166875645438CA7F57E4FEE7", "hash_sha1": "D73128F714D07F8149E018AEBF29048576F423C0", "hash_sha256": "43784D61F7ABA93CBD8127251229C66FE37B3AF0759CA07E70CA7FA96B13CFB1", "hash_sha384": "70815C2CFCB646895CB362F4123E8AE509A024BB86580D052D018A5C8A69C9BA6236D33091A7D4142D46E80007516C22", "hash_sha512": "71D6257CA8093D0160CB8DB25117E7300C82C44669395037FBC09CA8AFAEFD6957FBA5B3B32B9FB5C781A7E1D6B41C5272CDFB6445DCD67325F9A1D6B9806C3C", "hash_ssdeep": "768:OCZzp6zKzZSi6mZo0HZedzMbxklDyAFC4xruUaROTU0bq7RBUxtW:bcmZRHZedzzFl8CU0bqBUC", "hash_imp": "F76AC455BB3971C0CB2A43FDCD1FF525", "hash_pesha1": "C0E6AC8C44F002E245DA932197FE50D6C4C23F57", "hash_pe256": "45BEB106D9022DD220B273C7F60850CB54AF50F28E3D921F51EE585401A1A7E8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Transfer Program", "meta_original_filename": "ftp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/43784d61f7aba93cbd8127251229c66fe37b3af0759ca07e70ca7fa96b13cfb1/detection", "error": "\r\nTransfers files to and from a computer running an FTP server service\r\n(sometimes called a daemon). Ftp can be used interactively.\r\n\r\nFTP [-v] [-d] [-i] [-n] [-g] [-s:filename] [-a] [-A] [-x:sendbuffer] [-r:recvbuffer] [-b:asyncbuffers] [-w:windowsize] [host]\r\n\r\n -v Suppresses display of remote server responses.\r\n -n Suppresses auto-login upon initial connection.\r\n -i Turns off interactive prompting during multiple file\r\n transfers.\r\n -d Enables debugging.\r\n -g Disables filename globbing (see GLOB command).\r\n -s:filename Specifies a text file containing FTP commands; the\r\n commands will automatically run after FTP starts.\r\n -a Use any local interface when binding data connection.\r\n -A login as anonymous.\r\n -x:send sockbuf Overrides the default SO_SNDBUF size of 8192.\r\n -r:recv sockbuf Overrides the default SO_RCVBUF size of 8192.\r\n -b:async count Overrides the default async count of 3\r\n -w:windowsize Overrides the default transfer buffer size of 65535.\r\n host Specifies the host name or IP address of the remote\r\n host to connect to.\r\n\r\nNotes:\r\n - mget and mput commands take y/n/q for yes/no/quit.\r\n - Use Control-C to abort commands.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\ftp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "GameBarPresenceWriter.exe-C87A18C292E4A612B9E55C5E037BBAB7": { "file_name": "GameBarPresenceWriter.exe", "file_path": "C:\\Windows\\SysWOW64\\GameBarPresenceWriter.exe", "hash_md5": "C87A18C292E4A612B9E55C5E037BBAB7", "hash_sha1": "EC5654BBA60A0617B3D8379FF33841E173E98BA6", "hash_sha256": "767CC00AF6F9F37E77D3365F2EE50A327166107341B159BF8A7C6B3C5259FD56", "hash_sha384": "514F76B1D6D0FCF9F7F8BE2C4D972A4CDB6D0979CC1C226DDA235B8A761D9D51C040A2D0BA883F823B03673F2804C107", "hash_sha512": "CC4844372818C412A980CD260023E0B543C23EC3BEF3192985A84C22F70C81CE15109EC99599031E162E80CF134A00F47F9B8700B2FE401019F42F65C6E26539", "hash_ssdeep": "3072:R0SoILaKBeNGCnIbwiDksk3Qvy8pom20TRmclWJfzmVE2+v:FL4NGCnqwiDkskgvfpomFTsOWJL9v", "hash_imp": "3588AA305058E008E242A190513344B7", "hash_pesha1": "77D3498C987ED70B3516B4803BFEE12EAC89FF23", "hash_pe256": "08A1AD18E1FA9CB9EC2A58CB540F5DCF5130A58010C7AF301350B8D7AD69715F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Gamebar Presence Writer", "meta_original_filename": "GamebarPresenceWriter.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/767cc00af6f9f37e77d3365f2ee50a327166107341b159bf8a7c6b3c5259fd56/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\GameBarPresenceWriter.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "GamePanel.exe-CDF9C625C91AEF97F0FC745E245E514E": { "file_name": "GamePanel.exe", "file_path": "C:\\Windows\\SysWOW64\\GamePanel.exe", "hash_md5": "CDF9C625C91AEF97F0FC745E245E514E", "hash_sha1": "B5E238D8A14D591EEBE7338326352219777F233C", "hash_sha256": "E6E3B0BC663C60939A2032216167A71AC9334E9BD2E0854CA0B1F40A43D69CB9", "hash_sha384": "98A77C0C808207BFE631ECF9F42C08A79155A807E9437895B7048E65130A8018E0019C2A545C9C54FD666CC13BE016C4", "hash_sha512": "A7231BDDDCFD02DC30BAF18B335167BEA31AA90DFF779871DCC8D9BD424C13632EF8DF3389C325865CF718A812577BED8E574DF20D1C843FCF7047A5508A174C", "hash_ssdeep": "24576:BRROExw8KmFhLtXnXdEB026y8X6iacJtTkD:fRLxwJuH8gx7tTkD", "hash_imp": "4C451E73F90F9DBB2E6DECD130608F82", "hash_pesha1": "4A56AFFD5FF753CEF0EB75772C26DAA1BAA57F73", "hash_pe256": "BBBD56DFE5E0E41C6AB9D5A8C14D7FA6FED229F04E82F58E8A690BC6CD940603", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Game Bar", "meta_original_filename": "gamepanel.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/e6e3b0bc663c60939a2032216167a71ac9334e9bd2e0854ca0b1f40a43d69cb9/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\GamePanel.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "getmac.exe-31874C37626D02373768F72A64E76214": { "file_name": "getmac.exe", "file_path": "C:\\Windows\\SysWOW64\\getmac.exe", "hash_md5": "31874C37626D02373768F72A64E76214", "hash_sha1": "CB788C30FFA61E17327D411B55CE6EE7491062D5", "hash_sha256": "AF862B278038DC2A84DEE82932CFDCFFC837A747C7852DC905DE72300C6FD937", "hash_sha384": "26EF1C4DA9B8CDB8B565E5A8463D8E6F9A0FA6DBE164C13912D132F4661D7E15896024C6FFC3FE1C7902781368AAF7A3", "hash_sha512": "C47E0F5E440C6F00054067510610C5483DD7A5060D1FCEC736231EEA88414D42139F86CACEC56A1EA6CC4288A367D28F1CFBC84471D687562465FE494EDE5264", "hash_ssdeep": "1536:oL4azlGfoseDXCPwF3kFCtk1FYTlgkt4cIqi2pBKMAlUasSGm1a:o6foseTCPc4C2/YTWs4ctiSKXlUaPGm0", "hash_imp": "6CB365C8C4783D7461BD89A2FF705113", "hash_pesha1": "A8355DE57784FFA4AB405287C2485550E1AFF198", "hash_pe256": "810654C1EE19CF7BC71619B16B8C28E724785AF12B88E8BCC4E04B55BA229088", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays NIC MAC information", "meta_original_filename": "GetMac.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/af862b278038dc2a84dee82932cfdcffc837a747c7852dc905de72300c6fd937/detection", "output": "\r\nGETMAC [/S system [/U username [/P [password]]]] [/FO format] [/NH] [/V]\r\n\r\nDescription:\r\n This tool enables an administrator to display the MAC address\r\n for network adapters on a system.\r\n\r\nParameter List: \r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under \r\n which the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /FO format Specifies the format in which the output\r\n is to be displayed.\r\n Valid values: \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" should\r\n not be displayed in the output.\r\n Valid only for TABLE and CSV formats.\r\n\r\n /V Specifies that verbose output is displayed.\r\n\r\n /? Displays this help message.\r\n\r\nExamples: \r\n GETMAC /? \r\n GETMAC /FO csv \r\n GETMAC /S system /NH /V\r\n GETMAC /S system /U user\r\n GETMAC /S system /U domain\\user /P password /FO list /V\r\n GETMAC /S system /U domain\\user /P password /FO table /NH\r\n", "children": "mmc.exe", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"GETMAC /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\getmac.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "gpresult.exe-24091E39D3C98CD0866002B618801C6E": { "file_name": "gpresult.exe", "file_path": "C:\\Windows\\SysWOW64\\gpresult.exe", "hash_md5": "24091E39D3C98CD0866002B618801C6E", "hash_sha1": "66386E3CB2B37BCC6B98D34D0B3FC32EF0BDA6C7", "hash_sha256": "2BAC97558FA6700178EBF89AD80DB4492E21A6C92692F89956FDAB2AA5899D57", "hash_sha384": "0E1BC158F4F8D277C12AB840DC6AB4B76DE6082AB0F69CD823940CB61444835FD720FA20600E2FC8956C30ABE4AE0D53", "hash_sha512": "FB76E01930FB01176016786CDEDF2349720150E2308138FF585E0B98EC1BF96003A8BF95B87018AC9BEDA7CBE0056356FBB3EA42BEA5A19286F94D09398792B3", "hash_ssdeep": "3072:Ja+sOKvkY3L78RtU5eITpgwRO42wtzi8TKnpft9PtgXtmpZmnIMqiNPr5W3qi1Xi:8BHL78R+5ef4O6nv36ayucr2k/MF", "hash_imp": "C2331BA71CEC644A91EA059F8846B40A", "hash_pesha1": "79ED5D211464254315020C72B3957BBF1C86D931", "hash_pe256": "176AB07D2950A0EA16E860BCA5A0129E50BEA5DA3C4ECEBAF82AED7ABD422B29", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query Group Policy RSOP Data", "meta_original_filename": "gprslt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2bac97558fa6700178ebf89ad80db4492e21a6c92692f89956fdab2aa5899d57/detection", "output": "\r\nGPRESULT [/S system [/U username [/P [password]]]] [/SCOPE scope]\r\n [/USER targetusername] [/R | /V | /Z] [(/X | /H) <filename> [/F]]\r\n\r\nDescription:\r\n This command line tool displays the Resultant Set of Policy (RSoP)\r\n information for a target user and computer.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which the\r\n command should run.\r\n Can not be used with /X, /H.\r\n\r\n /P [password] Specifies the password for the given user\r\n context. Prompts for input if omitted.\r\n Cannot be used with /X, /H.\r\n\r\n /SCOPE scope Specifies whether the user or the\r\n computer settings need to be displayed.\r\n Valid values: \"USER\", \"COMPUTER\".\r\n\r\n /USER [domain\\]user Specifies the user name for which the\r\n RSoP data is to be displayed.\r\n\r\n /X <filename> Saves the report in XML format at the\r\n location and with the file name specified\r\n by the <filename> parameter. (valid in Windows\r\n Vista SP1 and later and Windows Server 2008 and later)\r\n\r\n /H <filename> Saves the report in HTML format at the\r\n location and with the file name specified by\r\n the <filename> parameter. (valid in Windows\r\n at least Vista SP1 and at least Windows Server 2008)\r\n\r\n /F Forces Gpresult to overwrite the file name\r\n specified in the /X or /H command.\r\n\r\n /R Displays RSoP summary data.\r\n\r\n /V Specifies that verbose information should\r\n be displayed. Verbose information provides\r\n additional detailed settings that have\r\n been applied with a precedence of 1.\r\n\r\n /Z Specifies that the super-verbose\r\n information should be displayed. Super-\r\n verbose information provides additional\r\n detailed settings that have been applied\r\n with a precedence of 1 and higher. This\r\n allows you to see if a setting was set in\r\n multiple places. See the Group Policy\r\n online help topic for more information.\r\n\r\n /? Displays this help message.\r\n\r\n\r\nExamples:\r\n GPRESULT /R\r\n GPRESULT /H GPReport.html\r\n GPRESULT /USER targetusername /V\r\n GPRESULT /S system /USER targetusername /SCOPE COMPUTER /Z\r\n GPRESULT /S system /U username /P password /SCOPE USER /V\r\n", "error": "ERROR: Invalid syntax. Value expected for '/h'.\r\nType \"GPRESULT /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\gpresult.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "gpscript.exe-4C50A56D35AA7189C3CCBC29BA9ADC24": { "file_name": "gpscript.exe", "file_path": "C:\\Windows\\SysWOW64\\gpscript.exe", "hash_md5": "4C50A56D35AA7189C3CCBC29BA9ADC24", "hash_sha1": "CA1436CC32BAB1A5E9F420280D6391F57DEEB48D", "hash_sha256": "E2434CD5C049DB2976702490C5E34C0134A9F158FA76020C62DE4A6DC4AAA25F", "hash_sha384": "14A4976A8B69586A7990661D043151D2A1AFA298D1C229953DD776F40799043471BFA9276EA8EE10C3B84F77AF9254D6", "hash_sha512": "F5F053925C81E74598CF24B7700FA623FAB3198DD940223FEDE522894D8169BBF3A5AA00F2930E8EF73FFF3887A26DCFF5AACE9E2AD8A1D660DE29EACA597DC4", "hash_ssdeep": "768:poMQyZlU+Bk3f8hor4US+XLC2Ece+b9GZpCTdTR7LIELR/X:pB++Bk3f8hor4t+7C2EXZpCTdTRLIE1f", "hash_imp": "5C9ADBC2A218AEE3FE31C3D2507C5911", "hash_pesha1": "59AD00A4A1AD9EA6BEC615846EADBC0624DEC3BB", "hash_pe256": "0C2A3D0D6A22CAFD8738BB80A1103AF123FB123F67A2615BE8EE15A4C565FBDC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Group Policy Script Application", "meta_original_filename": "GPSCRIPT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e2434cd5c049db2976702490c5e34c0134a9f158fa76020c62de4a6dc4aaa25f/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\gpscript.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "gpupdate.exe-6DC3720EA74B49C8ED64ACA3E0162AC8": { "file_name": "gpupdate.exe", "file_path": "C:\\Windows\\SysWOW64\\gpupdate.exe", "hash_md5": "6DC3720EA74B49C8ED64ACA3E0162AC8", "hash_sha1": "B473D5BC0E9A3A02D26B73770CBEF6AF2CF93B26", "hash_sha256": "9732B6C10D74C01D69BE9D61F2056B4F30FF911045A14126D0C1352D02C276E3", "hash_sha384": "8885039425A75DB9919D340BB162E4B82C9EFA00C35559912DA1BD41E524883DCD045B1EE780E56EC4585BF2A0DE2AD4", "hash_sha512": "8607F320028058363768A95768E2D609CA13C794479B28F2E850C624B7A8E6FBC0CCA9F66DCC5E446EFC371D0B53E0EB631D7FAB8AC3E221DC82CD1A4D984189", "hash_ssdeep": "384:ZI/t0ZEVsKmxTDaLuiYK5jUhL4O1TBRbVnaYaV4T4rZo/qWF9DW4l:mt0ZmlUllzrT4rq/7", "hash_imp": "E28FE91AADCEC39343D96C4659091959", "hash_pesha1": "0B480DFEFF4D2227601EA57CDFF377CD47C12F3D", "hash_pe256": "214E5D87D9FAB14BD14C782AB0C55CF90D4FC6D9C17148523D284E184B5C60BB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Group Policy Update Utility", "meta_original_filename": "GPUpdate.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9732b6c10d74c01d69be9d61f2056b4f30ff911045a14126d0c1352d02c276e3/detection", "output": "Description: Updates multiple Group Policy settings.\r\r\n\r\r\nSyntax: Gpupdate [/Target:{Computer | User}] [/Force] [/Wait:<value>]\r\r\n [/Logoff] [/Boot] [/Sync] \r\r\n\r\r\nParameters:\r\r\n\r\r\nValue Description\r\r\n/Target:{Computer | User} Specifies that only User or only Computer\r\r\n policy settings are updated. By default,\r\r\n both User and Computer policy settings are\r\r\n updated.\r\r\n\r\r\n/Force Reapplies all policy settings. By default,\r\r\n only policy settings that have changed are\r\r\n applied.\r\r\n\r\r\n/Wait:{value} Sets the number of seconds to wait for policy\r\r\n processing to finish. The default is 600\r\r\n seconds. The value '0' means not to wait.\r\r\n The value '-1' means to wait indefinitely.\r\r\n When the time limit is exceeded, the command\r\r\n prompt returns, but policy processing\r\r\n continues.\r\r\n\r\r\n/Logoff Causes a logoff after the Group Policy settings\r\r\n have been updated. This is required for\r\r\n those Group Policy client-side extensions\r\r\n that do not process policy on a background\r\r\n update cycle but do process policy when a\r\r\n user logs on. Examples include user-targeted\r\r\n Software Installation and Folder Redirection.\r\r\n This option has no effect if there are no\r\r\n extensions called that require a logoff.\r\r\n\r\r\n/Boot Causes a computer restart after the Group Policy settings\r\r\n are applied. This is required for those\r\r\n Group Policy client-side extensions that do\r\r\n not process policy on a background update cycle\r\r\n but do process policy at computer startup.\r\r\n Examples include computer-targeted Software\r\r\n Installation. This option has no effect if\r\r\n there are no extensions called that require\r\r\n a restart.\r\r\n\r\r\n/Sync Causes the next foreground policy application to\r\r\n be done synchronously. Foreground policy\r\r\n applications occur at computer start up and user\r\r\n logon. You can specify this for the user,\r\r\n computer or both using the /Target parameter.\r\r\n The /Force and /Wait parameters will be ignored\r\r\n if specified.\r\r\n\r\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\gpupdate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "grpconv.exe-5A13926732E6D349FD060C072BC7FB74": { "file_name": "grpconv.exe", "file_path": "C:\\Windows\\SysWOW64\\grpconv.exe", "hash_md5": "5A13926732E6D349FD060C072BC7FB74", "hash_sha1": "515EA092604E6A3EAD70E702573DE0C54D769620", "hash_sha256": "3B496786568A0A35780B0AF76AC486C24FEFA867C663DD931A86DB6A263E992C", "hash_sha384": "F06FDA096807C1C0682656EA6CDF550CC8B1460A0EF485E6309FE1C633C2D5CFE0EC6D334F22332C09853DDE512EE914", "hash_sha512": "99FA12C4555C2D62C733D42991865DD50A5F59F9443979F776C50ADC661E67F2F99CB9F680E43A9D248925CB9BE944B382D22E164F4BFF70397F0F3A46825C36", "hash_ssdeep": "768:Ayr0h7j4JEoo2BR/6kbdR6zuFZFBVM4NTqyd213k:Ayr0hX4JEo/R/PdRTTBGyd210", "hash_imp": "132C218B1F2E13F78FEE548483028E32", "hash_pesha1": "06822DBBD836E820A6A6D09890F5FA198323704F", "hash_pe256": "986F46CB76AB08801B8D94253EBD662022B4EBD218BE61B49F31D3C44071E5FA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Progman Group Converter", "meta_original_filename": "GRPCONV.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3b496786568a0a35780b0af76ac486c24fefa867c663dd931a86db6a263e992c/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\grpconv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "hdwwiz.exe-AD95D55FFCEA88F38021920924E4C971": { "file_name": "hdwwiz.exe", "file_path": "C:\\Windows\\SysWOW64\\hdwwiz.exe", "hash_md5": "AD95D55FFCEA88F38021920924E4C971", "hash_sha1": "D49793C7F6359EF3519D6972EFA8A6AD8151940D", "hash_sha256": "81D43AD111BD8B8DAD77E0C36E0D420332889FB9B473857DBA779EA0C070442C", "hash_sha384": "A08D253C10CC747D4D9F7D9DC5186D56A0B31C18D0F89BCFD702FE846F6E2A1579A31D13F443362C14BEA7BB4398F5AD", "hash_sha512": "1B7464DBD3DBA7AECBC898211838C28F8A0DCF630E382673A3DAF94583FE9C0F809E143FD10435D3FC8794336C0D83032DBC7B30094E251408D7566D2DF5B7B0", "hash_ssdeep": "768:8bXwlZwI1XBflGf4G0In3BhzhWM1GOVz170Cv:kXw7wIflGzZ3qOTwC", "hash_imp": "613877CB92EF7DF19BF5DEFD1BA60402", "hash_pesha1": "217CC19AB3205CE602AFED88FDF538C10BDB6E9B", "hash_pe256": "BDC3B563F546FA3313E10804FBC26BD5B1BF54FA6785723616021686E6F62FD5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Add Hardware Wizard", "meta_original_filename": "HdwWiz.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/81d43ad111bd8b8dad77e0c36e0d420332889fb9b473857dba779ea0c070442c/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\hdwwiz.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\newdev.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\devmgr.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\hdwwiz.cpl.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SystemResources\\shell32.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\setupapi.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\hdwwiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Add Hardware" }, "help.exe-DD40774E56D4C44B81F2DFA059285E75": { "file_name": "help.exe", "file_path": "C:\\Windows\\SysWOW64\\help.exe", "hash_md5": "DD40774E56D4C44B81F2DFA059285E75", "hash_sha1": "0461D593E5D7E38319DB5B57EF50EB773BAF8EE2", "hash_sha256": "53827A12373901FCA002C3FC012D0BCE0C4AF422A7CF12CAD19C655C903314E3", "hash_sha384": "5708BB7372D36795A99C3896FD2ADDB8887E9B63B223BBC3ED35B604A81552C734A512289C701E3926B16505E74D8E2F", "hash_sha512": "7D10D778F785B12F62449E2B0D7AFF9A417B00074969AE85B7346196FCE67AAD989A6F81D08462EAA01E06551833DE90241A274A317B6B0745E347B96A1875D2", "hash_ssdeep": "96:xc7G/+oRECOajYzsp20jvfnDGjshvQluDbX1QJMfgzGDJvkMhd0cSEWMcWw:xc4nECOajY62ypDblQJMfgzKkgWMcW", "hash_imp": "611805A7C3221EBB521E87BF9182D982", "hash_pesha1": "41A1B410DB36BDD9706AEB34C5A63FBDD7ADE6FE", "hash_pe256": "72AD64057E1388CED1A17E1153761212959F95D60230A98A3D5CCDD610C6E8A6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command Line Help Utility", "meta_original_filename": "Help.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/53827a12373901fca002c3fc012d0bce0c4af422a7cf12cad19c655c903314e3/detection", "output": "Provides help information for Windows commands.\r\n\r\nHELP [command]\r\n\r\n command - displays help information on that command.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\help.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "hh.exe-25DA176935752443FE077C2F0F819B7E": { "file_name": "hh.exe", "file_path": "C:\\Windows\\SysWOW64\\hh.exe", "hash_md5": "25DA176935752443FE077C2F0F819B7E", "hash_sha1": "003BD308D99FF43D8E1881DE337FF3EF9F757960", "hash_sha256": "A83ADD413DF07EFB9A6609F1B2D677521B5060E2D01678B3CDBF6B805592EFD5", "hash_sha384": "59F9279BDB1516A3D95B9005E3B8443339E8AD1D66A5729A861D9EAFC08640EA1A0777348E1CDD82344DA91501CF4F2A", "hash_sha512": "272F4C2228E4F4FF1EEDB127E706C71760499030E1F2F43D73F9B308A0BABBD4A47F500BCFD90A92DA6D5F0E1C12E94181CF21907767E2377B89B110A6BB96F5", "hash_ssdeep": "192:/RqP4aXNtLROydEt8GRyPLoAzDkBGJ1KDJD/QWc7NS:5aT1OOpGRyPURA1KDuWc7U", "hash_imp": "F937A8A0DD0B39468FF87DDE8D9CDB45", "hash_pesha1": "20B9456F69FDFC3A44C4E385AD1B12E2902F5871", "hash_pe256": "2E56C543A89D6873300985E769EEF3FA87F563F5240C74CD06CDC3A353DBE411", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft HTML Help Executable", "meta_original_filename": "HH.exe.mui", "meta_product_name": "HTML Help", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a83add413df07efb9a6609f1b2d677521b5060e2d01678b3cdbf6b805592efd5/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\hh.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\hhctrl.ocx.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "(R--) C:\\Users\\user\\AppData\\Local\\Temp\\~DF1F334D942DCC706E.TMP": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Temp\\~DFB5052DF5EBCEAFFC.TMP": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Sessions\\1\\BaseNamedObjects\\d8cHWNDInterface:23040e": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_ie_global_counters": "Section", "(R-D) C:\\Windows\\SysWOW64\\ieframe.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\ieframe.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_webcache_counters_{9B6AB5B3-91BC-4097-835C-EA2DEC95E9CC}_S-1-5-21-2047949552-857980807-821054962-504": "Section", "(R-D) C:\\Windows\\SystemResources\\ieframe.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\mshtml.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\urlmon.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\Sessions\\1\\BaseNamedObjects\\d8cHWNDInterface:c02de": "Section", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "(RWD) C:\\Users\\user": "File", "\\Sessions\\1\\BaseNamedObjects\\MSIMGSIZECacheMap": "Section", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(RWD) C:\\Windows\\Fonts": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Users\\user\\help": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_32.db": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "File Download", "runtime_modules": [ "C:\\Windows\\SysWOW64\\hh.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "HOSTNAME.EXE-B1C51FED46434CF91E65C7B605F8EF3A": { "file_name": "HOSTNAME.EXE", "file_path": "C:\\Windows\\SysWOW64\\HOSTNAME.EXE", "hash_md5": "B1C51FED46434CF91E65C7B605F8EF3A", "hash_sha1": "AFAD449EA0F14299847B6CE341105F728DBDB311", "hash_sha256": "379CBA8D0A1288E316126AC75A354C03BE76A61EAD6BD5EC6C72ED7DA3DC49D9", "hash_sha384": "475204C5B2452057D07A3562DA6BEE1A43E897A974F128B53A477FC94ABF73CFA544CB37E08FC4570C3A8540D9A1F2AC", "hash_sha512": "32B62D3BAD33C3B13404DF4B4BED5E85F08BAB1D4C45507B414F5484072C62057BDCE9715A174D3F9572CCB89D1672D77A1FF17E4DDE13FB6C0B3F27CBBEB139", "hash_ssdeep": "192:pUTjdxfF4UIuIZf121ZWYgbeabxwurWV6WkZX1B:pGdhF4UIuS121gY+bxHWV6Wkp1", "hash_imp": "2177BAFF198B6BCDCF56F96FB63DD54C", "hash_pesha1": "84225A2D3B1A734372409486ECA03F806752001B", "hash_pe256": "866252298EA97F376B79B9A75FD82A11CABC23AF97ED6924BF536BB03083DB49", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hostname APP", "meta_original_filename": "hostname.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/379cba8d0a1288e316126ac75a354c03be76a61ead6bd5ec6c72ed7da3dc49d9/detection", "output": "\r\nPrints the name of the current host.\r\n\r\nhostname\r\n\r\n", "error": "sethostname: Use the Network Control Panel Applet to set hostname.\r\nhostname -s is not supported.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\HOSTNAME.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "icacls.exe-2E49585E4E08565F52090B144062F97E": { "file_name": "icacls.exe", "file_path": "C:\\Windows\\SysWOW64\\icacls.exe", "hash_md5": "2E49585E4E08565F52090B144062F97E", "hash_sha1": "9F35D4F5C89393A70FF66D985FFAC6F78B8C5DA5", "hash_sha256": "468F69606E8F341B8822D20F6557CC1C2BE1BA61FFBC47988540C8674F46017B", "hash_sha384": "E083EF0518F2129FD715168E78E8495DD805A29A37348C729B6C08E1493A899FDF4BF93BDEDF97F3A01288DE4638BD6D", "hash_sha512": "34C3C3811B9F12349A01D35A063A934688D08D703B613C308230B89A894562CFA6A1DA3DEF59014EAE07E70F71E8D27F480C69F8715E67705BF0ED7E53B4E0FC", "hash_ssdeep": "384:ZwV5B6rEUmhyfibgla7J/SAXDVLsvbaz7q9BtPmGjKy3jS8+sIrZsr5Ao8PpXwtG:ogmhyKEla7J9tIBZmyKFrZsrm1wtMYP", "hash_imp": "019F88299D7F5E77F17221DA15112A43", "hash_pesha1": "3D257DA354D4486D9F1EE6331057CB6DE81D5284", "hash_pe256": "5E2717A4758DF99F50470FB443104F3F83CE488161D81E01A09CECF9E652D380", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "iCACLS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/468f69606e8f341b8822d20f6557cc1c2be1ba61ffbc47988540c8674f46017b/detection", "output": "\r\nICACLS name /save aclfile [/T] [/C] [/L] [/Q]\r\n stores the DACLs for the files and folders that match the name\r\n into aclfile for later use with /restore. Note that SACLs,\r\n owner, or integrity labels are not saved.\r\n\r\nICACLS directory [/substitute SidOld SidNew [...]] /restore aclfile\r\n [/C] [/L] [/Q]\r\n applies the stored DACLs to files in directory.\r\n\r\nICACLS name /setowner user [/T] [/C] [/L] [/Q]\r\n changes the owner of all matching names. This option does not\r\n force a change of ownership; use the takeown.exe utility for\r\n that purpose.\r\n\r\nICACLS name /findsid Sid [/T] [/C] [/L] [/Q]\r\n finds all matching names that contain an ACL\r\n explicitly mentioning Sid.\r\n\r\nICACLS name /verify [/T] [/C] [/L] [/Q]\r\n finds all files whose ACL is not in canonical form or whose\r\n lengths are inconsistent with ACE counts.\r\n\r\nICACLS name /reset [/T] [/C] [/L] [/Q]\r\n replaces ACLs with default inherited ACLs for all matching files.\r\n\r\nICACLS name [/grant[:r] Sid:perm[...]]\r\n [/deny Sid:perm [...]]\r\n [/remove[:g|:d]] Sid[...]] [/T] [/C] [/L] [/Q]\r\n [/setintegritylevel Level:policy[...]]\r\n\r\n /grant[:r] Sid:perm grants the specified user access rights. With :r,\r\n the permissions replace any previously granted explicit permissions.\r\n Without :r, the permissions are added to any previously granted\r\n explicit permissions.\r\n\r\n /deny Sid:perm explicitly denies the specified user access rights.\r\n An explicit deny ACE is added for the stated permissions and\r\n the same permissions in any explicit grant are removed.\r\n\r\n /remove[:[g|d]] Sid removes all occurrences of Sid in the ACL. With\r\n :g, it removes all occurrences of granted rights to that Sid. With\r\n :d, it removes all occurrences of denied rights to that Sid.\r\n\r\n /setintegritylevel [(CI)(OI)]Level explicitly adds an integrity\r\n ACE to all matching files. The level is to be specified as one\r\n of:\r\n L[ow]\r\n M[edium]\r\n H[igh]\r\n Inheritance options for the integrity ACE may precede the level\r\n and are applied only to directories.\r\n\r\n /inheritance:e|d|r\r\n e - enables inheritance\r\n d - disables inheritance and copy the ACEs\r\n r - remove all inherited ACEs\r\n\r\n\r\nNote:\r\n Sids may be in either numerical or friendly name form. If a numerical\r\n form is given, affix a * to the start of the SID.\r\n\r\n /T indicates that this operation is performed on all matching\r\n files/directories below the directories specified in the name.\r\n\r\n /C indicates that this operation will continue on all file errors.\r\n Error messages will still be displayed.\r\n\r\n /L indicates that this operation is performed on a symbolic link\r\n itself versus its target.\r\n\r\n /Q indicates that icacls should suppress success messages.\r\n\r\n ICACLS preserves the canonical ordering of ACE entries:\r\n Explicit denials\r\n Explicit grants\r\n Inherited denials\r\n Inherited grants\r\n\r\n perm is a permission mask and can be specified in one of two forms:\r\n a sequence of simple rights:\r\n N - no access\r\n F - full access\r\n M - modify access\r\n RX - read and execute access\r\n R - read-only access\r\n W - write-only access\r\n D - delete access\r\n a comma-separated list in parentheses of specific rights:\r\n DE - delete\r\n RC - read control\r\n WDAC - write DAC\r\n WO - write owner\r\n S - synchronize\r\n AS - access system security\r\n MA - maximum allowed\r\n GR - generic read\r\n GW - generic write\r\n GE - generic execute\r\n GA - generic all\r\n RD - read data/list directory\r\n WD - write data/add file\r\n AD - append data/add subdirectory\r\n REA - read extended attributes\r\n WEA - write extended attributes\r\n X - execute/traverse\r\n DC - delete child\r\n RA - read attributes\r\n WA - write attributes\r\n inheritance rights may precede either form and are applied\r\n only to directories:\r\n (OI) - object inherit\r\n (CI) - container inherit\r\n (IO) - inherit only\r\n (NP) - don't propagate inherit\r\n (I) - permission inherited from parent container\r\n\r\nExamples:\r\n\r\n icacls c:\\windows\\* /save AclFile /T\r\n - Will save the ACLs for all files under c:\\windows\r\n and its subdirectories to AclFile.\r\n\r\n icacls c:\\windows\\ /restore AclFile\r\n - Will restore the Acls for every file within\r\n AclFile that exists in c:\\windows and its subdirectories.\r\n\r\n icacls file /grant Administrator:(D,WDAC)\r\n - Will grant the user Administrator Delete and Write DAC\r\n permissions to file.\r\n\r\n icacls file /grant *S-1-1-0:(D,WDAC)\r\n - Will grant the user defined by sid S-1-1-0 Delete and\r\n Write DAC permissions to file.\r\n", "error": "First parameter must be a file name pattern or \"/?\"\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\icacls.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "icsunattend.exe-6D01FCE30EF8A2CA0D385593E90879E5": { "file_name": "icsunattend.exe", "file_path": "C:\\Windows\\SysWOW64\\icsunattend.exe", "hash_md5": "6D01FCE30EF8A2CA0D385593E90879E5", "hash_sha1": "5DCD267C7E7A816234E7D7A768EAD12F2353087C", "hash_sha256": "732B8722B6C44DFB9DB2E28C22638150DD64540BC4480DDF585E6E5890DCF72A", "hash_sha384": "CDDCCFA459848EDD679BE65C5C66F30AD002EB3DDC81C071D7322BAAA4B769C274F2D4230AB78919ADA3F913D927CE37", "hash_sha512": "3740A13547DA6353C7F552FC646BA4E990D795D5ACE53827C12F5B6FE0FEB0DE6B7E04FD8F9648DB9E3AA807B7E06F8A6ADD00E29CC9F73A64314A5D05EE6088", "hash_ssdeep": "192:0o4V0XE9mzMw5hUcPkYNU07WVedDnt1MaEbeDBqkz3WiRWo:0hVy5PPkYRuer1MabBdz3WiRWo", "hash_imp": "11531FA26DD040394D31F8396F295974", "hash_pesha1": "7B9EB53A43E9FE971A1B62A4C9F67126F7EC05BB", "hash_pe256": "D2EFAD0B7E45AA1F54D82FECE458015FC585E9F1C711844656783754A3D4C26F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ICS Unattend Utility", "meta_original_filename": "icsunattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/732b8722b6c44dfb9db2e28c22638150dd64540bc4480ddf585e6e5890dcf72a/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\icsunattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ieUnatt.exe-4E9919DF2EF531B389ABAEFD35AD546E": { "file_name": "ieUnatt.exe", "file_path": "C:\\Windows\\SysWOW64\\ieUnatt.exe", "hash_md5": "4E9919DF2EF531B389ABAEFD35AD546E", "hash_sha1": "518263A503D77FDE3D7C5A4C72899EE7951FFF95", "hash_sha256": "D3881AEA8DC3FA20B60EB15FBA561B5AF4DBAECE3CF3B643B755425FEB864263", "hash_sha384": "1FCE1AC2FBCB24580BA02AEFBF1908C438B0080E30043382847E605BBF660D1B99A91781BB0856DB64959BA1A84E2E71", "hash_sha512": "6196A529E17856AE35D7E48C79870DB7AE3719CA74412D73CD8498D9B0DFDBAA683A5BE02D73D716C8F3E840B33954E4EF6A531D2D88C45D806E943882659254", "hash_ssdeep": "3072:lUTeV1GvS/T/DFEISSYX5PFG0qYsXHsgt0TIhX:mSVaS/nmFLpwHv0TwX", "hash_imp": "1E43FF632AA51C8FFFBA8BEF3073E0DD", "hash_pesha1": "7E4288A8363D276F403B6D019A738B0878D1E1A4", "hash_pe256": "6DA2D06D25A7E02620D9C04FFFF0F6BE16923A1CBA822474DA973D5F110FEF26", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IE 7.0 Unattended Install Utility", "meta_original_filename": "IEUNATT.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d3881aea8dc3fa20b60eb15fba561b5af4dbaece3cf3b643b755425feb864263/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ieUnatt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "iexpress.exe-D594B2A33EFAFD0EABF09E3FDC05FCEA": { "file_name": "iexpress.exe", "file_path": "C:\\Windows\\SysWOW64\\iexpress.exe", "hash_md5": "D594B2A33EFAFD0EABF09E3FDC05FCEA", "hash_sha1": "06845890C783ABB305A8C9BBD119DF5DE0A17E6F", "hash_sha256": "DD2C185DEAE89D41F42FB9903AA274AE70B103EA2285184C4565F39B69DF945F", "hash_sha384": "E0AC2315C4E8BBB6DFEB784402F1C35B7DA7B203EF2CBDFFE86AC20843AB5128E74280A6ABDAC0FE4401D0FB24E2EB34", "hash_sha512": "20E26F7CEB672A4B64CF05CA5595611B9FA561B6C141BD0E9FDC777836AF1E343DFFED81B07D8F3636D1E21A1FE42176C0A090DFB711EACD56006F85551E9A43", "hash_ssdeep": "3072:KLys2qzK5RnUri12NDnGOb+ahXNqJohePnq45L843H:lqzKDKXNDGOb+asEwv5LD", "hash_imp": "74C91AAB7B963325BC9BC79D27993FB4", "hash_pesha1": "A4BFE33FBF848C233DA11B8D3E1D322B4D20AE91", "hash_pe256": "C15CD725091D887C0CB9FF709C53592519CA965006E88CEA1B7A09AF48B183A8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Wizard", "meta_original_filename": "IEXPRESS.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/dd2c185deae89d41f42fb9903aa274ae70b103ea2285184c4565f39b69df945f/detection", "children": "explorer.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\iexpress.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.19041.1_en-us_a8f1da377db0be9e": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.19041.1_en-us_a8f1da377db0be9e\\comctl32.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\iexpress.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "IExpress Wizard" }, "InfDefaultInstall.exe-3E9C81A60DEDC5FFFF1D8F1FC5D7908F": { "file_name": "InfDefaultInstall.exe", "file_path": "C:\\Windows\\SysWOW64\\InfDefaultInstall.exe", "hash_md5": "3E9C81A60DEDC5FFFF1D8F1FC5D7908F", "hash_sha1": "D6153796E0B88B6519E538FD8898C72655E1C0FF", "hash_sha256": "63805BF43B07576C68129B305A8D82E7ADCDFC38812A1515E85D45229D94C26B", "hash_sha384": "9527D646C5EF076DFAD7DD6D52A8D5CF6757601526E2EF8BEE2882EFEFFF541A8C2B4F657F09A94885F2750D4F5E466B", "hash_sha512": "089307D18678FC39143596147226E910166FDD6A9FED8D59EE4611A50EED9AB212E2020D1C28D1137E602507EAF4A6AFE25604437EA07E710D980CF833B5FC2B", "hash_ssdeep": "192:x+KMK7x2hOIDjZ+Rots11JSsZKW/GWMI:1n2hOOMatYSoKW/GWM", "hash_imp": "426943BF6D529CB3262EBF3ACCD763CB", "hash_pesha1": "E1CC54F5E5A55461168ABDF8127114B498318AA2", "hash_pe256": "BE920D225AF8726C8B454DFCBE123CE9F75BD487621D03B048413563C43889EE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "INF Default Install", "meta_original_filename": "InfDefaultInstall.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/63805bf43b07576c68129b305a8d82e7adcdfc38812a1515e85d45229d94c26b/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\InfDefaultInstall.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\newdev.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\InfDefaultInstall.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Install Error" }, "InputSwitchToastHandler.exe-BE00D803E4E2B5A19C3E8AECC42C8727": { "file_name": "InputSwitchToastHandler.exe", "file_path": "C:\\Windows\\SysWOW64\\InputSwitchToastHandler.exe", "hash_md5": "BE00D803E4E2B5A19C3E8AECC42C8727", "hash_sha1": "53E26E8B0C7145BD85E37A727A60313BFF7703C8", "hash_sha256": "977E71C9547055DB4A0814971D85C5B0FAAF8A5BE529AF55FA60B4E67417131E", "hash_sha384": "466B9163866CC5737248DDF2D78B35B4D11E395DC25D24B5685FD4E49580121D5615D501B34C777932F6E144A9CFAC2C", "hash_sha512": "6310773396B78B3288707D88D26D6FFE4D4AE3462EC5D84AEF6352AF5B81E087D8CFF79D08DDA1065E6978B84B29EFB26AA150A1F3DE45A42C85ECB6B26C1B32", "hash_ssdeep": "768:Dhk1gAl2Ty7WCKe7O+5QgAK2x1ZuwmCSpIFjBy9RFASViJM0u3stSPeU04Rg:De1gAl2TWhddA7PZ5Sp0CzvViJLi", "hash_imp": "8767FC78CB0E7522A525CB603CC3A06F", "hash_pesha1": "F1685A5E8F01803866532BE2FBCFE51BD2CCB460", "hash_pe256": "B9F128B53FB81E2D645C5AC36D8AD10D24A7D8CDAE2A2E26433B770C03692642", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Input Switch Toast Handler", "meta_original_filename": "InputSwitchToastHandler.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/977e71c9547055db4a0814971d85c5b0faaf8a5be529af55fa60b4e67417131e/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\InputSwitchToastHandler.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "instnm.exe-1B1261560B0D072A4643A48143C6ECD5": { "file_name": "instnm.exe", "file_path": "C:\\Windows\\SysWOW64\\instnm.exe", "hash_md5": "1B1261560B0D072A4643A48143C6ECD5", "hash_sha1": "9F63732ADE74FC269128BB0FDABD302CB4F09F69", "hash_sha256": "87CB70386DAD7504AEBDB37B0E34A0D4E3EB4A946FA4367C3555954F0F65560D", "hash_sha384": "7408C6B8D630A25EA75F80510F18D1F224855A915E1A5E231EA20364AE3D151C8529D10DE2F7EF2F83B87C559D9631A1", "hash_sha512": "66292DB2AC829BCF6022345FFAD901BA6FDD6A68DD239CF3C864BF98CC013E919101FE5D15F21255B5B85B443416DF39F4CE343A0B1DDC39EFF68F338BFF6F89", "hash_ssdeep": "96:Rntlaijhm/uEp2keirJDGj4fDVHOEMsfP18+EW7rIXuWwjBesb:nEiVm/rItS5NM618TWw+WkBeg", "hash_imp": "34EF1D42EB1DA272F024F086EE53F0D2", "hash_pesha1": "4DB00E7DE54C992862B2FD2DB71A641BD54586E6", "hash_pe256": "8B5D39089FB2C3DB4AA114A38D7B281CF3DDCCFFCCF2FB9AB6DEBA31D07D608C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "32-bit NetMeeting Installer for Win64", "meta_original_filename": "instnm.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/87cb70386dad7504aebdb37b0e34a0d4e3eb4a946fa4367c3555954f0f65560d/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\instnm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ipconfig.exe-3A3B9A5E00EF6A3F83BF300E2B6B67BB": { "file_name": "ipconfig.exe", "file_path": "C:\\Windows\\SysWOW64\\ipconfig.exe", "hash_md5": "3A3B9A5E00EF6A3F83BF300E2B6B67BB", "hash_sha1": "261127183DF2987DE2239806DD74FE624C430608", "hash_sha256": "87B036C720FBD5E63355B9920A2864FEAF59B1584EBD8458651936AB8C7C1F81", "hash_sha384": "308F95286C1AEBA9EA9BED79C36F74DF459FF6510D9AAFF97D9035E69F8D35DCA9067F2D167593CEFC4B2A8ECD679306", "hash_sha512": "21DF8867246A9C5834253C0D2C2DE3E620E9F8B4B031B9E53CB6082ECA78B90BDB09B9E8BAF39E05A08B859F81B3AECBC34F3540428CEF0BED746D7E769F2F04", "hash_ssdeep": "384:TX75STbXbI4zeTgPH1H5T2FJzTe959+Ir+1Dc7oL88RbfMoUn2gF97h7YBTsbnk6:rt+Z/1Z2FtA3+Ir+1DF70Nt7YCbn6K", "hash_imp": "14140F48563DAAA2A531D3BAD3FFF909", "hash_pesha1": "A66EAED9A3D852CEBFE8A54293634471A87C9457", "hash_pe256": "1D51A18576963307DFC65EF409EF4581C6497151266499551A4067310BDC318F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IP Configuration Utility", "meta_original_filename": "ipconfig.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/87b036c720fbd5e63355b9920a2864feaf59b1584ebd8458651936ab8c7c1f81/detection", "output": "\r\nError: unrecognized or incomplete command line.\r\n\r\nUSAGE:\r\n ipconfig [/allcompartments] [/? | /all | \r\n /renew [adapter] | /release [adapter] |\r\n /renew6 [adapter] | /release6 [adapter] |\r\n /flushdns | /displaydns | /registerdns |\r\n /showclassid adapter |\r\n /setclassid adapter [classid] |\r\n /showclassid6 adapter |\r\n /setclassid6 adapter [classid] ]\r\n\r\nwhere\r\n adapter Connection name \r\n (wildcard characters * and ? allowed, see examples)\r\n\r\n Options:\r\n /? Display this help message\r\n /all Display full configuration information.\r\n /release Release the IPv4 address for the specified adapter.\r\n /release6 Release the IPv6 address for the specified adapter.\r\n /renew Renew the IPv4 address for the specified adapter.\r\n /renew6 Renew the IPv6 address for the specified adapter.\r\n /flushdns Purges the DNS Resolver cache.\r\n /registerdns Refreshes all DHCP leases and re-registers DNS names\r\n /displaydns Display the contents of the DNS Resolver Cache.\r\n /showclassid Displays all the dhcp class IDs allowed for adapter.\r\n /setclassid Modifies the dhcp class id. \r\n /showclassid6 Displays all the IPv6 DHCP class IDs allowed for adapter.\r\n /setclassid6 Modifies the IPv6 DHCP class id.\r\n\r\n\r\nThe default is to display only the IP address, subnet mask and\r\ndefault gateway for each adapter bound to TCP/IP.\r\n\r\nFor Release and Renew, if no adapter name is specified, then the IP address\r\nleases for all adapters bound to TCP/IP will be released or renewed.\r\n\r\nFor Setclassid and Setclassid6, if no ClassId is specified, then the ClassId is removed.\r\n\r\nExamples:\r\n > ipconfig ... Show information\r\n > ipconfig /all ... Show detailed information\r\n > ipconfig /renew ... renew all adapters\r\n > ipconfig /renew EL* ... renew any connection that has its \r\n name starting with EL\r\n > ipconfig /release *Con* ... release all matching connections,\r\n eg. \"Wired Ethernet Connection 1\" or\r\n \"Wired Ethernet Connection 2\"\r\n > ipconfig /allcompartments ... Show information about all \r\n compartments\r\n > ipconfig /allcompartments /all ... Show detailed information about all\r\n compartments\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ipconfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "iscsicli.exe-C98254F4AC5F825ABC7A09924D95A61D": { "file_name": "iscsicli.exe", "file_path": "C:\\Windows\\SysWOW64\\iscsicli.exe", "hash_md5": "C98254F4AC5F825ABC7A09924D95A61D", "hash_sha1": "FF23DD6299049F4E9FF90976D5A587B3DEFFAABF", "hash_sha256": "436072ADDF870C0ED6B8E21C550CADFAA549264D35A18D4D0E3D3104846BA9E6", "hash_sha384": "C15C15D674C336ACA37E9BB90B307731EF4DE3C07E64F208A6D08F108FC19F7271CFDDC9FB6A1BC07982A33884AD4657", "hash_sha512": "AACB07A1C04E8C693AD82B0A0150F12F717637668E257C674FD402DB58FB326DFCC123D74F028401BC2D10D7766F66BDC36D892170B9B16DE948747B7354F805", "hash_ssdeep": "768:yywiJK3iS9LNZA0yOxev/gETthnJcbTWprR/:tYXLNZAFOsv4ETtuWprR/", "hash_imp": "8CA0AB71D922D32950087F16FDC104A3", "hash_pesha1": "45ADDF995FB4466B1D3BCA2B171066C18FE47479", "hash_pe256": "44126F528912607A2669062FC018279E3A2BCF869BC5DC43C7B6C51DA19B21A9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "iSCSI Discovery tool", "meta_original_filename": "iscsicli.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/436072addf870c0ed6b8e21c550cadfaa549264d35a18d4d0e3d3104846ba9e6/detection", "output": "Microsoft iSCSI Initiator Version 10.0 Build 19041\n\niscsicli\n\niscsicli AddTarget <TargetName> <TargetAlias> <TargetPortalAddress>\n <TargetPortalSocket> <Target flags>\n <Persist> <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType>\n <Mapping Count> <Target Lun> <OS Bus> <Os Target> \n <OS Lun> ...\n\niscsicli RemoveTarget <TargetName> \n\niscsicli AddTargetPortal <TargetPortalAddress> <TargetPortalSocket> \n [HBA Name] [Port Number]\n <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType>\n\niscsicli RemoveTargetPortal <TargetPortalAddress> <TargetPortalSocket> [HBA Name] [Port Number]\n\niscsicli RefreshTargetPortal <TargetPortalAddress> <TargetPortalSocket> [HBA Name] [Port Number]\n\niscsicli ListTargets [ForceUpdate]\n\niscsicli ListTargetPortals\n\niscsicli TargetInfo <TargetName> [Discovery Mechanism]\n\niscsicli LoginTarget <TargetName> <ReportToPNP>\n <TargetPortalAddress> <TargetPortalSocket>\n <InitiatorInstance> <Port number> <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType> <Key>\n <Mapping Count> <Target Lun> <OS Bus> <Os Target> \n <OS Lun> ...\n\niscsicli LogoutTarget <SessionId>\n\niscsicli PersistentLoginTarget <TargetName> <ReportToPNP>\n <TargetPortalAddress> <TargetPortalSocket>\n <InitiatorInstance> <Port number> <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType> <Key>\n <Mapping Count> <Target Lun> <OS Bus> <Os Target> \n <OS Lun> ...\n\niscsicli ListPersistentTargets\n\niscsicli RemovePersistentTarget <Initiator Name> <TargetName> \n <Port Number> \n <Target Portal Address> \n <Target Portal Socket> \n\niscsicli AddConnection <SessionId> <Initiator Instance>\n <Port Number> <Target Portal Address>\n <Target Portal Socket> <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType> <Key>\n\niscsicli RemoveConnection <SessionId> <ConnectionId> \niscsicli ScsiInquiry <SessionId> <LUN> <EvpdCmddt> <PageCode>\n\niscsicli ReadCapacity <SessionId> <LUN>\n\niscsicli ReportLUNs <SessionId>\n\niscsicli ReportTargetMappings\n\niscsicli ListInitiators\n\niscsicli AddiSNSServer <iSNS Server Address>\n\niscsicli RemoveiSNSServer <iSNS Server Address>\n\niscsicli RefreshiSNSServer <iSNS Server Address>\n\niscsicli ListiSNSServers\n\niscsicli FirewallExemptiSNSServer\n\niscsicli NodeName <node name>\n\niscsicli SessionList <Show Session Info>\n\niscsicli CHAPSecret <chap secret>\n\niscsicli TunnelAddr <Initiator Name> <InitiatorPort> <Destination Address> <Tunnel Address> <Persist>\n\niscsicli GroupKey <Key> <Persist>\n\niscsicli BindPersistentVolumes\n\niscsicli BindPersistentDevices\n\niscsicli ReportPersistentDevices\n\niscsicli AddPersistentDevice <Volume or Device Path>\n\niscsicli RemovePersistentDevice <Volume or Device Path>\n\niscsicli ClearPersistentDevices\n\niscsicli Ping <Initiator Name> <Address> [Request Count] [Request Size] [Request Timeout]\n\niscsicli GetPSKey <Initiator Name> <initiator Port> <Id Type> <Id>\n\niscsicli PSKey <Initiator Name> <initiator Port> <Security Flags> <Id Type> <Id> <Key> <persist>\nQuick Commands\n\niscsicli QLoginTarget <TargetName> [CHAP Username] [CHAP Password]\n\niscsicli QAddTarget <TargetName> <TargetPortalAddress>\n\niscsicli QAddTargetPortal <TargetPortalAddress>\n [CHAP Username] [CHAP Password]\n\niscsicli QAddConnection <SessionId> <Initiator Instance>\n <Target Portal Address>\n [CHAP Username] [CHAP Password]\n\nTarget Mappings:\n <Target Lun> is the LUN value the target uses to expose the LUN.\n It must be in the form 0x0123456789abcdef\n <OS Bus> is the bus number the OS should use to surface the LUN\n <OS Target> is the target number the OS should use to surface the LUN\n <OS LUN> is the LUN number the OS should use to surface the LUN\n\nPayload Id Type:\n ID_IPV4_ADDR is 1 - Id format is 1.2.3.4\n ID_FQDN is 2 - Id format is ComputerName\n ID_IPV6_ADDR is 5 - Id form is IPv6 Address\nSecurity Flags:\n TunnelMode is 0x00000040\n TransportMode is 0x00000020\n PFS Enabled is 0x00000010\n Aggressive Mode is 0x00000008\n Main mode is 0x00000004\n IPSEC/IKE Enabled is 0x00000002\n Valid Flags is 0x00000001\n\nLogin Flags:\n ISCSI_LOGIN_FLAG_REQUIRE_IPSEC 0x00000001\n IPsec is required for the operation\n\n ISCSI_LOGIN_FLAG_MULTIPATH_ENABLED 0x00000002\n Multipathing is enabled for the target on this initiator\n\nAuthType:\n ISCSI_NO_AUTH_TYPE = 0,\n No iSCSI in-band authentication is used\n\n ISCSI_CHAP_AUTH_TYPE = 1,\n One way CHAP (Target authenticates initiator is used)\n\n ISCSI_MUTUAL_CHAP_AUTH_TYPE = 2\n Mutual CHAP (Target and Initiator authenticate each other is used)\n\nTarget Flags:\n ISCSI_TARGET_FLAG_HIDE_STATIC_TARGET 0x00000002\n If this flag is set then the target will never be reported unless it\n is also discovered dynamically.\n\n ISCSI_TARGET_FLAG_MERGE_TARGET_INFORMATION 0x00000004\n If this flag is set then the target information passed will be\n merged with any target information already statically configured for\n the target\n\nCHAP secrets, CHAP passwords and IPSEC preshared keys can be specified as\na text string or as a sequence of hexadecimal values. The value specified on\nthe command line is always considered a string unless the first two characters\n0x in which case it is considered a hexadecimal value.\n\nFor example 0x12345678 specifies a 4 byte secret\n\nAll numerical values are assumed decimal unless preceeded by 0x. If\npreceeded by 0x then value is assumed to be hex\n\niscsicli can also be run in command line mode where iscsicli commands\ncan be entered directly from the console. To enter command line\nmode, just run iscsicli without any parameters\n\nThe operation completed successfully. \n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\iscsicli.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "iscsicpl.exe-653F3E22DB3F8589703A9B3677CCA56E": { "file_name": "iscsicpl.exe", "file_path": "C:\\Windows\\SysWOW64\\iscsicpl.exe", "hash_md5": "653F3E22DB3F8589703A9B3677CCA56E", "hash_sha1": "E57F2F600C845EE8C29AD983DAAED413D2D0AD93", "hash_sha256": "4138F8FEE342C54723A38D2F07F56F3E482926F72B078A937492A94D45571F78", "hash_sha384": "3660A3D8326239EE4F13E2CB7BAD3E986E3C3941F3D822567B5D9C05155BBC5D638DC28FF8DE51901A05286E458E6495", "hash_sha512": "F8164D6B27DF0406427A97116A611EFCB359AA2FF3FB9B53EAC81FB74D5736FF85C3CA510F32A7960AE554FF057B8A3BF962C6A6DDF99F40F418BD1AA0E9EAAA", "hash_ssdeep": "96:VZE5zvURNNZNMn9F8p2kvnxDGjoBcHz0yjCyj9uxIly1MXSSDJWRxkMC58kdEWPD:VZwYNOe4DznxZ9loMXSdkruW7gRWl", "hash_imp": "4751D16FE4697EBBF94F37D0EBC833C3", "hash_pesha1": "C0A1BFF366487AA08644B48E2D48FFF36A34CEB1", "hash_pe256": "C9535160B8FCDFABB8AB7E721188B5C045FB9B047D8643668A5CCE49BAF58691", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft iSCSI Initiator Configuration Tool", "meta_original_filename": "iscsicpl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/4138f8fee342c54723a38d2f07f56f3e482926f72b078a937492a94d45571f78/detection", "children": "rundll32.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\iscsicpl.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\iscsicpl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "isoburn.exe-BDC61F9F6F634563BF1DB9C6F92C1DF5": { "file_name": "isoburn.exe", "file_path": "C:\\Windows\\SysWOW64\\isoburn.exe", "hash_md5": "BDC61F9F6F634563BF1DB9C6F92C1DF5", "hash_sha1": "4354F5CD9B4047FD00AF177139B172A907F7B34F", "hash_sha256": "446603B26C0C6C2A4AB6CD40A1DCC0CD3892C40EDE84A5174601D33A080A8EE7", "hash_sha384": "8C89E04B2A20A7C7075CDA9B935D5C0FE87DBE4989D0700F795BD01B33D5238F2EB7582410BFE01B64602BE5554804CD", "hash_sha512": "DC6CFD757FE6D5D10C0760CC290A6AE6B48D0194ABD501C09ECF45BBEF9CFFE3DE2D955AB0C437D84B189CE6B1ABF7627E60CA9C9E73314E4B71A37987A231D0", "hash_ssdeep": "1536:EUknIEpyfA6F1q2nVIPuWkGyo0FAbeHZrQqfsTU:wIEpy/u2nVWul5SeHd3R", "hash_imp": "7F94E9D0CC07E577A42FAADF4CF700A6", "hash_pesha1": "087497A19D4EFD0DE5BF5B1FBCFA0C3E99804DED", "hash_pe256": "9027CF2922611542684AD741ECBC4B644FD2D2D97AEA6BFD86C14BC571782A3A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Disc Image Burning Tool", "meta_original_filename": "ISOBURN.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/446603b26c0c6c2a4ab6cd40a1dcc0cd3892c40ede84a5174601d33a080a8ee7/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\isoburn.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\isoburn.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Disc Image Burner" }, "ktmutil.exe-AC387D5962B2FE2BF4D518DD57BA7230": { "file_name": "ktmutil.exe", "file_path": "C:\\Windows\\SysWOW64\\ktmutil.exe", "hash_md5": "AC387D5962B2FE2BF4D518DD57BA7230", "hash_sha1": "511D913F817DD36995035DFA64FB2D7F171CCDCB", "hash_sha256": "180305260DA3DD77215DCA061C10B869CD69307E9D0CFFFCAFA27CCEC0AF71B3", "hash_sha384": "91CC0961810E5F582A1E8C02E6ADA1ACBCA44378CF2628CAEAE5EE90B2EBEB545D1CBF7144B137CD77CE8B2CB3591402", "hash_sha512": "57F0AD17B3C0B05FD228672CDB72DF0DEDC3AED176CB5D29152A99665C250A72231FCE3631C5FEABB4820B16A27749CC840B4B89091DB5DE38A8503F8DE69263", "hash_ssdeep": "192:yj5P8awg3p4VZycwkCdwGZp/CBzqtQrdxrtWOPZsTkOWjjWTI:Y5P9SZycLSp/C9qtMQOTOWjjW", "hash_imp": "E096B10874B4B45A595EAE17714B7AEE", "hash_pesha1": "84802678357F914DDA80683174C69ADDFDCFD68D", "hash_pe256": "84241E014242C4FEEC696C196D65A783122901280B25101C41A18BDE833E2DB4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Kernel Transaction Management Utility", "meta_original_filename": "ktmutil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/180305260da3dd77215dca061c10b869cd69307e9d0cfffcafa27ccec0af71b3/detection", "output": "--help is an invalid parameter.\r\n---- Commands Supported ----\r\n\r\ntx Commands related to transactions\r\ntm Commands related to transaction managers\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ktmutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "label.exe-89622C68CA73EDE797CBAE9D1BDF0572": { "file_name": "label.exe", "file_path": "C:\\Windows\\SysWOW64\\label.exe", "hash_md5": "89622C68CA73EDE797CBAE9D1BDF0572", "hash_sha1": "CBDF87518AB0437CCAB8F246E9AB6DC01C876FEF", "hash_sha256": "FD11A74C35A7713013474417C89C7DD61E7E3063119FBE655A759BEE0F8731A2", "hash_sha384": "2CD09B575724742A7818633B9CB5016008827E996DFC0E96FF6DD81952840570BA9FC983C3F862F276B71FEBAA4F4A70", "hash_sha512": "C512F17D19B5B52EAE1063CAC925565A474D05F82B2CD91F5EBF774B5E34C54435D56ED6D88ABE3839BC7A6C0226BD0C627E4144053861BBA6AC578EA17EE907", "hash_ssdeep": "192:U+RYVDdE+ijhYIS1eHvr5faRvaH8gY0gxiHDLtRkOc1dkYWSCjWgX:UEWp3ISiapaH8gdgxitRbjYWSCjWg", "hash_imp": "89817B62874F5050E534349B8EB33EB0", "hash_pesha1": "E034EE78AEF920B4E9CA267E6ED35EB5471D52AD", "hash_pe256": "1CF5C784D2903DAA3345F999737F8945C894ECABE30FBF3014684C0CF881F5E7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Label Utility", "meta_original_filename": "Label.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/fd11a74c35a7713013474417c89c7dd61e7e3063119fbe655a759bee0f8731a2/detection", "output": "Creates, changes, or deletes the volume label of a disk.\r\n\r\nLABEL [drive:][label]\r\nLABEL [/MP] [volume] [label]\r\n\r\n drive: Specifies the drive letter of a drive.\r\n label Specifies the label of the volume.\r\n /MP Specifies that the volume should be treated as a\r\n mount point or volume name.\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name. If volume name is specified,\r\n the /MP flag is unnecessary.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\label.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "LaunchTM.exe-CEDC8282CFAF5E2CAD92EF53E0556B3A": { "file_name": "LaunchTM.exe", "file_path": "C:\\Windows\\SysWOW64\\LaunchTM.exe", "hash_md5": "CEDC8282CFAF5E2CAD92EF53E0556B3A", "hash_sha1": "DB77957B99152A889CB768FF3D041AC157E2526C", "hash_sha256": "EF9C0384FB695452851506713577E617C330F5F814E3FF6438088F13C52781AD", "hash_sha384": "36D5ED87149509953182CE9F2588D7813F402AAF8D965330C495A5AC88388D9849A8E3803FCCE4EB125D60FA7A0E930D", "hash_sha512": "1DA12A78322458D60614194F92AC564CB9749147B45AEEE9AED49F525090EB23259EBF0C9F7D6C2787A98132C1F115C59D26C0CDC567CACCBAFB4B8D8A7C4D23", "hash_ssdeep": "96:Sr8q3JNNpDiN0OEusn9ndcp2k3jD02DGjQLRHMizB4MocflJTvcS8DJ+XVpH6b+S:aZNNp7Oru24IMi94MDfbTvB/UWvqayW", "hash_imp": "E28D1A46BA8C0C2DD607DFE0E3A12845", "hash_pesha1": "09F2BCA8EA59A694D830CBE77C33EED6EDF8B578", "hash_pe256": "D195841522E32ADD4D3728FEB36C71E7ACFCBD4B8EC1839AB88B2D9EE6AC2B43", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Manager Launcher", "meta_original_filename": "LaunchTM.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ef9c0384fb695452851506713577e617c330f5f814e3ff6438088f13c52781ad/detection", "children": "Taskmgr.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\LaunchTM.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "LaunchWinApp.exe-6894C31A670287B7866B7A69F5C9F72E": { "file_name": "LaunchWinApp.exe", "file_path": "C:\\Windows\\SysWOW64\\LaunchWinApp.exe", "hash_md5": "6894C31A670287B7866B7A69F5C9F72E", "hash_sha1": "7B4B27F291363185A95FD62332BD7C6FA43D3941", "hash_sha256": "E25D5FC0B84C66C26FEADD5C9AAE34E5FD7E13914F1301D38B6E40AADB13117A", "hash_sha384": "0EDE541D505DCB86BB3229314D9C2A478B16FB69E0463D24CC3C204ABA4F058A24EAA5921438AE0CB7853FCC622A240B", "hash_sha512": "B4CE5EF8BC57341F6BABD3722DE42D7B6E1906C6EE85477E2CB11713AD0B6538C96E74EF27DEE8234AF56743E83F87919A340BA716321E8667D19EE81D8E90EA", "hash_ssdeep": "768:NmllU49YhtUEjM49favBpRPY7yNepQePZryv:NI+49YEonRsY7yNwryv", "hash_imp": "7559541AD6A516CFC5219B151BF29352", "hash_pesha1": "C5D1AA77849FB6C325FCE6D0BC22E0B5CF7AC907", "hash_pe256": "242C93230D27128A3EDEA5CEE9BBD64C77C0913C8CD0589C359D6C3A80ADC6D9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Launch Windows App", "meta_original_filename": "LaunchWinApp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e25d5fc0b84c66c26feadd5c9aae34e5fd7e13914f1301d38b6e40aadb13117a/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\LaunchWinApp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "C:\\Users\\user\\--help" }, "lodctr.exe-351D1E0D384BC1FAEB40131446C74D1A": { "file_name": "lodctr.exe", "file_path": "C:\\Windows\\SysWOW64\\lodctr.exe", "hash_md5": "351D1E0D384BC1FAEB40131446C74D1A", "hash_sha1": "3DEC174F08F22FACFCB53D4BD8993D0AB9DA5EAE", "hash_sha256": "3915BFB4520C2947E3DC9B4BDD4AF56AABDEDA1923B60F17A6E742A2231EA50D", "hash_sha384": "286C2BC641F35AA94809F4F19196C76E94387CF4637D412E5291DCA47D9CE75E809206847BE84269943A8277405F8D2D", "hash_sha512": "B4EDD7D5050491E0A706F2BD9E56C564E599FBC03ED84D24CE4A36261A99D34B87899791E551FE14C17E35E9AD15A3911410318BC9836C8C273BCA831BD78A8B", "hash_ssdeep": "768:qJ3ZlM8ZvQ0RrAs8fkk6IrHYUZgMkuwm8VcMDwFZ/hiKMAZnEOw9i:ulM8FFrANHHYUyMku4VKhJB1EOw9i", "hash_imp": "FDABB1B17742D7066DE0358591144052", "hash_pesha1": "2E22CFA2967A876B932A4FDD287FDB2B35F733F0", "hash_pe256": "4F1377C128E97EC6726D5D2B9C0CCA1DD029D02A26757AC347FD24D3FC58E7DB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Load PerfMon Counters", "meta_original_filename": "LODCTR.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3915bfb4520c2947e3dc9b4bdd4af56aabdeda1923b60f17a6e742a2231ea50d/detection", "output": "\r\n \r\nLODCTR \r\n Updates registry values related to performance counters. \r\nUsage: \r\n LODCTR <INI-filename> \r\n Installs counter text strings. INI-filename is the name of the \r\n initialization file that contains the counter name definitions \r\n and explain text for an extensible counter DLL.\r\n\r\n LODCTR /C:<filename> \r\n Upgrades counter text strings using <filename>\r\n\r\n LODCTR /H:<filename> \r\n Upgrades help text strings using <filename>\r\n\r\n LODCTR /L:<LangID> \r\n Specifies the language for the /C and /H commands\r\n\r\n LODCTR /S:<Backup-filename> \r\n Saves the current perf registry strings and info to \r\n <Backup-filename>\r\n\r\n LODCTR /R \r\n Rebuilds perf registry from scratch based on current registry \r\n settings and backup INI files.\r\n\r\n LODCTR /R:<filename> \r\n Restores perf registry strings & info using <filename>\r\n\r\n LODCTR /T:<service-name> \r\n Sets the specified performance counter provider as trusted.\r\n\r\n LODCTR /Q \r\n Displays performance counter provider information.\r\n\r\n LODCTR /Q:<service-name> \r\n Displays performance counter provider information for a \r\n specific provider.\r\n\r\n LODCTR /E:<service-name> \r\n Enables the performance counter provider.\r\n\r\n LODCTR /D:<service-name> \r\n Disables the performance counter provider.\r\n\r\n LODCTR /M:<Counter-Manifest> [<Installation-Path>]\r\n Installs a v2.0 performance counter provider using the specified \r\n XML manifest. \r\n\r\n The installation requires a full path to the DLL containing the \r\n performance counter resources (localized strings). The path \r\n to the DLL will be determined as follows:\r\n\r\n If the applicationIdentity attribute in the manifest is a full \r\n path, that will be used.\r\n\r\n Otherwise, if <Installation-Path> is provided and is a full \r\n path, that will be used.\r\n\r\n Otherwise, if <Counter-Manifest> is a full path, the directory \r\n from <Counter-Manifest> will be combined with the DLL name from \r\n the applicationIdentity attribute in the manifest.\r\n\r\n Otherwise, the current directory will be combined with the DLL \r\n name from the applicationIdentity attribute in the manifest.\r\n\r\nNote: Any arguments with spaces in the names must be enclosed within double \r\nquotation marks.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\lodctr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "logagent.exe-AA8A67D6FB3A32FCD46078FBE61A5E26": { "file_name": "logagent.exe", "file_path": "C:\\Windows\\SysWOW64\\logagent.exe", "hash_md5": "AA8A67D6FB3A32FCD46078FBE61A5E26", "hash_sha1": "CF9F4A8BC06F3B03385B4FC60EF38075C4BEF109", "hash_sha256": "E8B7A1DBCFBBFC948BEB96F4E716CE243BDDB6A2E643C6C180BA54CE529ADEF4", "hash_sha384": "55823EB48E0D00DC2F34E73122E4809B4266774D7AE1DD2616A44076BB1C3BBCCB7719B399609E6392D05789F494878B", "hash_sha512": "6EE754EF76CCF8DDEBFFCECCC958D332A456488FAFDE2FFE241CBBA441F84829884A0D112D007A23947BAE12E1CF27F202928CA0885024E892631C46AB204649", "hash_ssdeep": "1536:g8EanzTRKTfpChJgUgKaM37iqynweFaf+5pNknbhWduXKvCK7olBoOF:IanzNKTpChgEUFafspA9WduXQCK74Bo", "hash_imp": "B6C7B26AD38A6146C7BB1A6BF5FBAAA8", "hash_pesha1": "44ED9F1B270F880CA7FBCE60BDA5775D011435B0", "hash_pe256": "94F0C5A09FBD0DED19486D7234FCE3F6D52FFE100E9DAA3E73B04D6F4367C119", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Logagent", "meta_original_filename": "logagent.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.19041.1", "meta_product_version": "12.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/e8b7a1dbcfbbfc948beb96f4e716ce243bddb6a2e643c6c180ba54ce529adef4/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\logagent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "logman.exe-6D2B1E2C3199BD27E2E532089C178AEE": { "file_name": "logman.exe", "file_path": "C:\\Windows\\SysWOW64\\logman.exe", "hash_md5": "6D2B1E2C3199BD27E2E532089C178AEE", "hash_sha1": "596C173C369321699ADB8CC038068FA31044CA8B", "hash_sha256": "2F5DD9EA0B39FF630EF53EA778C17BB4480980FC15D09291E7FCD97AFDA80D3D", "hash_sha384": "803BC4BCB94F94427F379A7B3DD7648567A292FAD0B539535FE4420ABC7EDA4248F415CDE4408AB23D6F573BCA48DA77", "hash_sha512": "5B300DCE0A7757785F39BC4AD06177D0D97634C64005B7B4C1493DC49032BF2CDDC60117FA5BAE6D4EFAE66F6481992FC40B2FA448CE129897D88676D465716F", "hash_ssdeep": "1536:q2HfEpSTGHeSunvRkpVwRB9dLHLxsXn+CKhXvatptBPW:qQ4STBlnJkbM9ZHLOKJvahJ", "hash_imp": "0DCA318B38537E36C8CE6E8439F768C4", "hash_pesha1": "E77125FF4D13C4D37CEF4446B09A597CAD40B9C7", "hash_pe256": "15335F1DBA6C85EC9EC380F97364609EB8BA6EFDCFA3C1E13334D83C873958FE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Performance Log Utility", "meta_original_filename": "Logman.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2f5dd9ea0b39ff630ef53ea778c17bb4480980fc15d09291e7fcd97afda80d3d/detection", "output": "\r\nMicrosoft r Logman.exe (10.0.19041.546)\r\n\r\nUsage:\r\n C:\\Windows\\SysWOW64\\logman.exe [create|query|start|stop|delete|update|import|export] [options]\r\n\r\nVerbs:\r\n create Create a new data collector.\r\n query Query data collector properties. If no name\n is given all data collectors are listed.\r\n start Start an existing data collector and set the\n begin time to manual.\r\n stop Stop an existing data collector and set the\n end time to manual.\r\n delete Delete an existing data collector.\r\n update Update an existing data collector's properties.\r\n import Import a data collector set from an XML file.\r\n export Export a data collector set to an XML file.\r\n\r\nAdverbs:\r\n counter Create a counter data collector.\r\n trace Create a trace data collector.\r\n alert Create an alert data collector.\r\n cfg Create a configuration data collector.\r\n providers Show registered providers.\r\n\r\nOptions (counter):\r\n -c <path [path [...]]> Performance counters to collect.\r\n -cf <filename> File listing performance counters to collect,\n one per line.\r\n -f <bin|bincirc|csv|tsv|sql> Specifies the log format for the data\n collector. For SQL database format, you must\n use the -o option in the command line with\n the DNS!log option. The defaults is binary.\r\n -sc <value> Maximum number of samples to collect with a\n performance counter data collector.\r\n -si <[[hh:]mm:]ss> Sample interval for performance counter data\n collectors.\r\n\r\nOptions (trace):\r\n -f <bin|bincirc|csv|tsv|sql> Specifies the log format for the data\n collector. For SQL database format, you must\n use the -o option in the command line with\n the DNS!log option. The defaults is binary.\r\n -mode <trace_mode> Event Trace Session logger mode. For more\n information visit -\n https://go.microsoft.com/fwlink/?LinkID=136464\r\n -ct <perf|system|cycle> Specifies the clock resolution to use when\n logging the time stamp for each event. You\n can use query performance counter, system\n time, or CPU cycle.\r\n -ln <logger_name> Logger name for Event Trace Sessions.\r\n -ft <[[hh:]mm:]ss> Event Trace Session flush timer.\r\n -[-]p <provider [flags [level]]> A single Event Trace provider to enable.\n The terms 'Flags' and 'Keywords' are\n synonymous in this context.\r\n -pf <filename> File listing multiple Event Trace providers\n to enable.\r\n -[-]rt Run the Event Trace Session in real-time mode.\r\n -[-]ul Run the Event Trace Session in user mode.\r\n -bs <value> Event Trace Session buffer size in kb.\r\n -nb <min max> Number of Event Trace Session buffers.\r\n\r\nOptions (alert):\r\n -[-]el Enable/Disable event log reporting.\r\n -th <threshold [threshold [...]]> Specify counters and their threshold\n values for and alert.\r\n -[-]rdcs <name> Data collector set to start when alert fires.\r\n -[-]tn <task> Task to run when alert fires.\r\n -[-]targ <argument> Task arguments.\r\n -si <[[hh:]mm:]ss> Sample interval for performance counter data\n collectors.\r\n\r\nOptions (cfg):\r\n -[-]ni Enable/Disable network interface query.\r\n -reg <path [path [...]]> Registry values to collect.\r\n -mgt <query [query [...]]> WMI objects to collect.\r\n -ftc <path [path [...]]> Full path to the files to collect.\r\n\r\nOptions:\r\n -? Displays context sensitive help.\r\n -s <computer> Perform the command on specified remote system.\r\n -config <filename> Settings file containing command options.\r\n [-n] <name> Name of the target object.\r\n -pid <pid> Process identifier.\r\n -xml <filename> Name of the XML file to import or export.\r\n -as Perform the requested operation asynchronously.\r\n -[-]u <user [password]> User to Run As. Entering a * for the password\n produces a prompt for the password. The\n password is not displayed when you type it at\n the password prompt.\r\n -m <[start] [stop]> Change to manual start or stop instead of a\n scheduled begin or end time.\r\n -rf <[[hh:]mm:]ss> Run the data collector for the specified\n period of time.\r\n -b <M/d/yyyy h:mm:ss[AM|PM]> Begin the data collector at specified time.\r\n -e <M/d/yyyy h:mm:ss[AM|PM]> End the data collector at specified time.\r\n -o <path|dsn!log> Path of the output log file or the DSN and\n log set name in a SQL database. The default\n path is '%systemdrive%\\PerfLogs\\Admin'.\r\n -[-]r Repeat the data collector daily at the\n specified begin and end times.\r\n -[-]a Append to an existing log file.\r\n -[-]ow Overwrite an existing log file.\r\n -[-]v <nnnnnn|mmddhhmm> Attach file versioning information to the end\n of the log name.\r\n -[-]rc <task> Run the command specified each time the log\n is closed.\r\n -[-]max <value> Maximum log file size in MB or number of\n records for SQL logs.\r\n -[-]cnf <[[hh:]mm:]ss> Create a new file when the specified time has\n elapsed or when the max size is exceeded.\r\n -y Answer yes to all questions without prompting.\r\n -fd Flushes all the active buffers of an existing\n Event Trace Session to disk.\r\n -ets Send commands to Event Trace Sessions\n directly without saving or scheduling.\r\n\r\nNote:\r\n Where [-] is listed, an extra - negates the option.\r\n For example --u turns off the -u option.\r\n\r\nMore Information:\r\n Microsoft TechNet - https://go.microsoft.com/fwlink/?LinkID=136332\n\r\nExamples:\r\n logman start perf_log\n logman update perf_log -si 10 -f csv -v mmddhhmm\n logman create counter perf_log -c \"\\Processor(_Total)\\% Processor Time\"\n logman create counter perf_log -c \"\\Processor(_Total)\\% Processor Time\" -max 10 -rf 01:00\n logman create trace trace_log -nb 16 256 -bs 64 -o c:\\logfile\n logman create alert new_alert -th \"\\Processor(_Total)\\% Processor Time>50\"\n logman create cfg cfg_log -reg \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\\\\"\n logman create cfg cfg_log -mgt \"root\\cimv2:SELECT * FROM Win32_OperatingSystem\"\n logman query providers\n logman query providers Microsoft-Windows-Diagnostics-Networking\n logman start process_trace -p Microsoft-Windows-Kernel-Process 0x10 win:Informational -ets\n logman start usermode_trace -p \"Service Control Manager Trace\" -ul -ets\n logman query usermode_trace -p \"Service Control Manager Trace\" -ul -ets\n logman stop usermode_trace -p \"Service Control Manager Trace\" -ul -ets\n logman start process_trace -p Microsoft-Windows-Kernel-Process -mode newfile -max 1 -o output%d.etl -ets\n logman start \"NT Kernel Logger\" -o log.etl -ets\n logman start \"NT Kernel Logger\" -p \"Windows Kernel Trace\" (process,thread) -ets\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\logman.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Magnify.exe-E7C9C8F8B67850410EE0C36DB7743B27": { "file_name": "Magnify.exe", "file_path": "C:\\Windows\\SysWOW64\\Magnify.exe", "hash_md5": "E7C9C8F8B67850410EE0C36DB7743B27", "hash_sha1": "D0B00DC14233A7EC509A3D2393DD64263FB38B3E", "hash_sha256": "72187106E9C57D2655ADB2AB6176A00267878B5C3C698FE321CEF5BAA14346E8", "hash_sha384": "ABF484EE1C9A2F9DED60E64EDAB4F89B05003C567B273B6D0D346CEDF6FA38F07B85601AC77B3D33B6BCB8A7D46F11B3", "hash_sha512": "8EC507502BC44DB80A8CA3745B7FBA625A9B9E61D8519B724A4138DD4877AFCEEFB44F7E2EED0D33FEFABBF721FE2091DC55E7E8F247432C28AD010A81B971A6", "hash_ssdeep": "6144:oEVfyJw2fggMDFXb3uWeA3g6ZKhWYs07/Nts9LbWrzkdY5j4VppD+QFKQ0N4PkeN:oiyJKnDF5e2KhvsQW+5YppDT0NHFC", "hash_imp": "91B1DB750FBA961CBDDD26628A2C9415", "hash_pesha1": "334B03540235D44B010A12ECB3CC777B8FA471C7", "hash_pe256": "C38D20D17A85620B262BBA4538743537D24DF2E389F1E489EED98987702F0352", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Screen Magnifier", "meta_original_filename": "ScreenMagnifier.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/72187106e9c57d2655adb2ab6176a00267878b5c3c698fe321cef5baa14346e8/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_4299dbb28a92ae3e": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\Magnify.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\SysWOW64": "File", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "\\Sessions\\1\\BaseNamedObjects\\c30HWNDInterface:17a04d4": "Section", "(R-D) C:\\Windows\\System32\\en-US\\UIAutomationCore.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(R-D) C:\\Windows\\System32\\en-US\\combase.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\Magnify.exe.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\c30HWNDInterface:8d042c": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\windows.ui.xaml.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\Magnify.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Magnifier" }, "makecab.exe-00824484BE0BCE2A430D7F43CD9BABA5": { "file_name": "makecab.exe", "file_path": "C:\\Windows\\SysWOW64\\makecab.exe", "hash_md5": "00824484BE0BCE2A430D7F43CD9BABA5", "hash_sha1": "85DFD8B30399A207B0CFDE6FCBAE03385DD98642", "hash_sha256": "F3C190724C35D35DA5213DAEB868DADE5556EAEA69A9337DEDD6402CF4C42E48", "hash_sha384": "2564BD4955B5261267AE13B0B4071002A9DD9C97D3CCA9ACC9A1F781886D6CA65814A2A0D19E104BA6A58199AA1545E5", "hash_sha512": "7D2522D9CB3B5E9700753B40BA5B99854CBFA2A100B065808F2C7B1C40A565C0AA849B178A544067D05BBB6176C7D7F8B7D4FADED8B2A94B0DC492E94D9F6203", "hash_ssdeep": "1536:KHETyr/UEt6k01v/wjM/bCsvmhnEAWykSxHEVcjrIcuj+cZv7gJ/V3pnQgJY+F7+:0ETyzUEt6k01v/wjM/bCsvmhnEAWdSxK", "hash_imp": "DB419917F8DBA7D951EB3BCBFC2572AA", "hash_pesha1": "E701D0D4054AE937856F65F6811E47108AA4C2F9", "hash_pe256": "74C9BCE815AF297F5997731EA19F6D689B4803E50C4AB6CA0143680BA218BC5A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Cabinet Maker", "meta_original_filename": "makecab.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.00 (WinBuild.160101.0800)", "meta_product_version": "5.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f3c190724c35d35da5213daeb868dade5556eaea69a9337dedd6402cf4c42e48/detection", "output": "Cabinet Maker - Lossless Data Compression Tool\r\n\r\nMAKECAB [/V[n]] [/D var=value ...] [/L dir] source [destination]\r\nMAKECAB [/V[n]] [/D var=value ...] /F directive_file [...]\r\n\r\n source File to compress.\r\n destination File name to give compressed file. If omitted, the\r\n last character of the source file name is replaced\r\n with an underscore (_) and used as the destination.\r\n /F directives A file with MakeCAB directives (may be repeated). Refer to\r\n Microsoft Cabinet SDK for information on directive_file.\r\n /D var=value Defines variable with specified value.\r\n /L dir Location to place destination (default is current directory).\r\n /V[n] Verbosity level (1..3).\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\makecab.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mavinject.exe-B8B01B6A24B8A2BA242D96DB63298120": { "file_name": "mavinject.exe", "file_path": "C:\\Windows\\SysWOW64\\mavinject.exe", "hash_md5": "B8B01B6A24B8A2BA242D96DB63298120", "hash_sha1": "1A6FFFB7F78E4C3481D1183A7CFB37A92F410BB1", "hash_sha256": "765EE5F458AB9254ADE24CAA3321411F625F959ED380851476FDDB9652EC963F", "hash_sha384": "C03160BACD8810183F4DCF5B426EC69693705E92A93A1FBB277909B5567565153015DB780BEF74BC86499646D7507435", "hash_sha512": "3EB3A29C2B632F0FA3913A55CDF043ECFAFBC0F002718EFCD8E13D0736F7A13B23CB9141ABBA2BE2B8009D28F8728C508C661FDEB794F1D64E0745425808F181", "hash_ssdeep": "3072:7vYvmmt0fSoD7WH7s+PtKkiIoqfKSXgQpm:7vQmmt0fSoD7WHI+PSgBm", "hash_imp": "92734E64BEDF9E93EEC501508D2B049C", "hash_pesha1": "5E11E4BF571DCFAA739B8EF40CF85E7C1C7759D5", "hash_pe256": "8D59FF7FDD69C625CA8E3AB53825C3845E226F5313FF557BF35BA167EA61C01D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Application Virtualization Injector", "meta_original_filename": "mavinject32.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/765ee5f458ab9254ade24caa3321411f625f959ed380851476fddb9652ec963f/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mavinject.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mcbuilder.exe-CAE8E531CD82401A9ECB4C446CBB964B": { "file_name": "mcbuilder.exe", "file_path": "C:\\Windows\\SysWOW64\\mcbuilder.exe", "hash_md5": "CAE8E531CD82401A9ECB4C446CBB964B", "hash_sha1": "60F23D6F5BAEA091C997DC7527C0F2896C801F6F", "hash_sha256": "F5FBD701E0CEEFCAB76839231C23F29EB967AD6107520B8454C40FD8DCDDFDE1", "hash_sha384": "A4DBA9F6CD894551E6B6B3A7386BBDD6BBEDA047A989559F00658BFB63A24918F63264A98E83A6F234AB1C865E0B4A07", "hash_sha512": "0D87C7C6797312286AB141AF5260BA8E6A3DE98A51617AFF9F7D1DC149B239FA04E26F87B72FB7E4BC387566317C8801A62D50E953F0872A8790EB5B9D8F7932", "hash_ssdeep": "1536:U5i0hBmMsWjcdIkpk0551bBuej8LrdHNaAssqeyAiBTd9aFZBrx7WwE45:UhBGIkV71bBuEmrIsqeyAiBTdCBrpWwr", "hash_imp": "195E17EC8E0FA560F3971AAF373C53F7", "hash_pesha1": "6577D29FD94DAB13ADD5A38C6C9D6A14C9CBEA8E", "hash_pe256": "70F2F7071071B099EE404BE265B2FCFDD44DF0AF0351F7EAD7A9D13CD151F85C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resource cache builder tool", "meta_original_filename": "mcbuilder.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f5fbd701e0ceefcab76839231c23f29eb967ad6107520b8454c40fd8dcddfde1/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mcbuilder.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mfpmp.exe-9CD65F38A2B4E53E8180395DE4988D6A": { "file_name": "mfpmp.exe", "file_path": "C:\\Windows\\SysWOW64\\mfpmp.exe", "hash_md5": "9CD65F38A2B4E53E8180395DE4988D6A", "hash_sha1": "204E6274A0AB04ED1596CDCBB41BD92C7F54EA62", "hash_sha256": "FF7E8CCC41BC3A506103BDD719A19318BF711351AC0E61E1F1CF00F5F02251D5", "hash_sha384": "A7AB6C21ED9DE1064832D2862BD20CA9DD8794F5825D7815FD37256C5939651DFDFB8499C1C4876D761F41E5103C7F26", "hash_sha512": "52F059B67B86E75463020858B558214534A81094FD9DA11756B41576F1D2A4A2C7C338422EFBBBD833972931C4F213BDD1CEC215AE65B029E2003BC281A8DF98", "hash_ssdeep": "768:L6SmZOou+ZO5YChjm1gqcfkypd7FAsJE72j3I1Ptptl:L6hNu+w5YChjQ1ypHDE72jgPtvl", "hash_imp": "F1975DE33BCED82CEDA455FBB76EBE51", "hash_pesha1": "122E880F818FB5282794F88AB8A4F817DDCDC5C8", "hash_pe256": "DDCEF2003D5453999863556A65072E78FFDA637FCA51F92C1770745975E50BF1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Media Foundation Protected Pipeline EXE", "meta_original_filename": "mf.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/ff7e8ccc41bc3a506103bdd719a19318bf711351ac0e61e1f1cf00f5f02251d5/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mfpmp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mmc.exe-A40546440A81D2E36FB1F6F18AC376BC": { "file_name": "mmc.exe", "file_path": "C:\\Windows\\SysWOW64\\mmc.exe", "hash_md5": "A40546440A81D2E36FB1F6F18AC376BC", "hash_sha1": "D5F486F60BD4A3230C65EABDF6C6CBC31C7ECF2F", "hash_sha256": "101B06FD8A344D594454BB1C4F9F2BC37680235504436512FB3ABC3F20704547", "hash_sha384": "BC6761DE37FC11AAEB55BF6DC3CDF43D75FA42019AF2340E53DABD22B4FDBE046F493D19DE5B60B7CE41A78629581F34", "hash_sha512": "E583699A9E79C95C6D85C9E0092F5F31C3FE3B6DFC555E6BDC7CC25D3E97941C98BE51B8DB7FDCB8BDC4BD44CCC9EC6C44DF83FE23A45967AFDCCD4A4EA5D7B4", "hash_ssdeep": "24576:T7WbO/1cWKvhKVbPhS8nZ0MbatL+gR+QOxRK9Mo7wMo7DHjexVkj8r:T7WMcZm48ndeT7e7DHjexVkj8r", "hash_imp": "E930A44493D92B845A352867BF590FC8", "hash_pesha1": "860B57C93C85E993FA6350965404D9B9EBA904AE", "hash_pe256": "579D42B9D53A0CFE9E2CB45AC5FAD42731B49ABF96827C938FDBF6D0AF454DF2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Management Console", "meta_original_filename": "mmc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/101b06fd8a344d594454bb1c4f9f2bc37680235504436512fb3abc3f20704547/detection", "children": "mmc.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mmc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mmgaserver.exe-4F8B022F8043FF14E26F7403E00F1857": { "file_name": "mmgaserver.exe", "file_path": "C:\\Windows\\SysWOW64\\mmgaserver.exe", "hash_md5": "4F8B022F8043FF14E26F7403E00F1857", "hash_sha1": "AA6EA19D1B101A790E54E0A54C2FC1D1DFB992C5", "hash_sha256": "C4AF20467472CD76F0D011A2AE9CECD265896D3A04935628298CAB5937B41DAE", "hash_sha384": "EEBFEE1E27574A9289865B911EC9553BBD93AC1517A54C64FC6BC1F71D738C6337AD0897E85BCED4A38404181D6F365D", "hash_sha512": "7FEF6B4A3A4A00A95BC3BF26FCEB313CD290F18075066E348719E58B601D42D4F4C7E19C074ECCA52B4A375B11DDF1D0E2207D8D5BD7CB1D3CEDEB82AEF32A4D", "hash_ssdeep": "6144:FHMTPEHDyQwRLVxYvuRg1uuBdyOcRx10DSWTarStnftqrb1hcQwU7CGjb5WuvFRV:JDGRLVNgZdyQSWGcVemE33", "hash_imp": "48E5252A498A48528212307135C0290D", "hash_pesha1": "3C1E28D69DA4E98BA94ACFC3953931207CEA5166", "hash_pe256": "3791C4FF4A775920720CE2C8544B209BC0B23DEFA274A7AA78BB59F195688C48", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MMGA Server", "meta_original_filename": "mmgaserver.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c4af20467472cd76f0d011a2ae9cecd265896d3a04935628298cab5937b41dae/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\mmgaserver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mobsync.exe-F7114D05B442F103BD2D3E20E78A7AA5": { "file_name": "mobsync.exe", "file_path": "C:\\Windows\\SysWOW64\\mobsync.exe", "hash_md5": "F7114D05B442F103BD2D3E20E78A7AA5", "hash_sha1": "99C6C768C5E1F1EFBA918B9432A108A8515A66CF", "hash_sha256": "244B65DC083F033047F8BDCBFE128D6D118D72C113D1DC21E0D2FD16C09A735A", "hash_sha384": "10EA70333C82848D3B6A05B7395F53E2FFFF2053B7E6E022F430BD25590C69BFB12446ED2C0C776147B87027E665BEA2", "hash_sha512": "A1EB8502429612E1F3A4618E16D6FE27295D31E872E0448D94C974929C408340838D778C485849EC6E4E9D70189475E718583996EF3B57809EF40D091E57C13E", "hash_ssdeep": "1536:XY8psCkXo9ZjH2GPoCGVjGWmt8CXZ+63x+w4JD+0NL+fK:CCkkD2GPo9St8WHxSD+09+S", "hash_imp": "B4668B610D5FA04C01B79CE854744B5B", "hash_pesha1": "52768179A93719AF4D87CC9E3550AA30547CC037", "hash_pe256": "69F61E129C96C739831EE7405E20B28F55B6C19B6EC30499C1ABE5C0C7AE4F13", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Sync Center", "meta_original_filename": "mobsync.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/244b65dc083f033047f8bdcbfe128d6d118d72c113d1dc21e0d2fd16c09a735a/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mobsync.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mountvol.exe-E0B3FFF7584298E77DFFB50796839FED": { "file_name": "mountvol.exe", "file_path": "C:\\Windows\\SysWOW64\\mountvol.exe", "hash_md5": "E0B3FFF7584298E77DFFB50796839FED", "hash_sha1": "4934F95BA483F3626E91C7B16DA609DDF04E8081", "hash_sha256": "F247BE88F22B07A36F4B71707ED7A96BD989BAD37A7500DA03B81709749DED7E", "hash_sha384": "7C2259B742D8C889B8355876EF4E792C9CF54688776CB966FCA94CE7232E27AC245F0FF23AC50868B8AC150529CE41A9", "hash_sha512": "49F56C904C8E8433F13D49D6F2C67BECFB1FC8CA41C28ABBD67687FFBA00095827F2000F39F1DB217A1EF47FF9EF6FCC8B150572F4DD9B779565932EB4C7A709", "hash_ssdeep": "384:Ob5fptnL+WMPDmOK84xVLdI8NuIcWLFWq:ofr+WMPDMx31NuIB", "hash_imp": "30F2C65A9103A7536B77118A741917B8", "hash_pesha1": "75141692C6580AD5F9890E32530BD94BA5E05F8C", "hash_pe256": "809333394E05CB5ABF942D826E545483638655624AD6FF8452EDEB24A9D9C500", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Mount Volume Utility", "meta_original_filename": "MOUNTVOL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f247be88f22b07a36f4b71707ed7a96bd989bad37a7500da03b81709749ded7e/detection", "output": "Creates, deletes, or lists a volume mount point.\r\n\r\nMOUNTVOL [drive:]path VolumeName\r\nMOUNTVOL [drive:]path /D\r\nMOUNTVOL [drive:]path /L\r\nMOUNTVOL [drive:]path /P\r\nMOUNTVOL /R\r\nMOUNTVOL /N\r\nMOUNTVOL /E\r\nMOUNTVOL drive: /S\r\n\r\n path Specifies the existing NTFS directory where the mount\r\n point will reside.\r\n VolumeName Specifies the volume name that is the target of the mount\r\n point.\r\n /D Removes the volume mount point from the specified directory.\r\n /L Lists the mounted volume name for the specified directory.\r\n /P Removes the volume mount point from the specified directory,\r\n dismounts the volume, and makes the volume not mountable.\r\n You can make the volume mountable again by creating a volume\r\n mount point.\r\n /R Removes volume mount point directories and registry settings\r\n for volumes that are no longer in the system.\r\n /N Disables automatic mounting of new volumes.\r\n /E Re-enables automatic mounting of new volumes.\r\n /S Mount the EFI System Partition on the given drive.\r\n\r\nPossible values for VolumeName along with current mount points are:\r\n\r\n \\\\?\\Volume{38184124-336f-4bf7-bb7f-9d8459dba1b2}\\\r\n C:\\\r\n\r\n", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mountvol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MRINFO.EXE-F664A3E4625D86FC6B389AFF416CF67F": { "file_name": "MRINFO.EXE", "file_path": "C:\\Windows\\SysWOW64\\MRINFO.EXE", "hash_md5": "F664A3E4625D86FC6B389AFF416CF67F", "hash_sha1": "1697129DD5541DA901E909D886983AEE01DDAC87", "hash_sha256": "4E02CB071B535096151DEB19675B5544D4DA97584E782BF6993E9FD1E9B2007D", "hash_sha384": "0C19E4E07ED622D274DFA3BA8A513A55C00A851D72C549890E082D028D9FC47999BD8995774A3FDD11B3B5C0E344AA47", "hash_sha512": "3DB758872C66ED7BCF07D98469FFB27DDF5F749750DC4535CD61C0AE4C6D4F0A8D9670F51A8814BD3DF2AC089CD009513A606BF4867F8FE8BA0B32B45F3A0B44", "hash_ssdeep": "384:eDMa5ntCFWvw4aZsJke6UYRMfbP3B0We8W8:eDMIntCFcC8wVRMfLBg", "hash_imp": "190D14EA18A077D297455C1871A8223C", "hash_pesha1": "B4581DF1C7CC32FBF12B7A3E4999F2963795BE3D", "hash_pe256": "03A9EE0C08F08AE4DA7B598D33DDBA4A034C5B33A0517A86D54726FC021F18F8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Multicast Information", "meta_original_filename": "mrinfo.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/4e02cb071b535096151deb19675b5544d4da97584e782bf6993e9fd1e9b2007d/detection", "output": "\r\nUsage: mrinfo [-n?] [-i address] [-t secs] [-r retries] destination\r\n \r\n -n Display IP addresses in numeric format\r\n -i address Address of local interface to send query out\r\n -t seconds Timeout in seconds for IGMP queries (default = 3 seconds) \r\n -r retries Number of extra times to send the SNMP queries (default = 0) \r\n -? Print Usage\r\n destination Address or name of destination\r\n\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\MRINFO.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "msdt.exe-A9AB42610361BF6432259061737EA309": { "file_name": "msdt.exe", "file_path": "C:\\Windows\\SysWOW64\\msdt.exe", "hash_md5": "A9AB42610361BF6432259061737EA309", "hash_sha1": "25FA6252069395C5F923A22D40FCB0EC6D13A109", "hash_sha256": "48103C8EE52D4CEFF0FB8974FFB17E6BFAB773B51F9D187A3A581401D6A7663B", "hash_sha384": "B8002527584DB7D5D1B03A705593AD4F315BC43270E569F8FAA013DEB3A223A798BE2FAA59A71BBD38DE718659C15E9F", "hash_sha512": "FDFA84A297A2492D98BE927E8A797227B2B19AE5EF4326DCA04E19A01D89054AC71330403C6195F056460498315133077FB9559AE054FB14AD36160301A2A2DB", "hash_ssdeep": "6144:vBGci6SDxNV7xLAeijxawdtuGjU8TdLO694gI1sicf7LpPtKXl:vW3V7pX8/XzjUILP94g0cD9Ptm", "hash_imp": "19CB93A7F4980963BA180BBC8785967E", "hash_pesha1": "64FE45A286695B60511EEE06B432CFE7BB3ACD5A", "hash_pe256": "9B3A5113D5886040CDA36EE70893EDDCB818EA2A476CE962DDB7143D46CFBFA4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Diagnostics Troubleshooting Wizard", "meta_original_filename": "msdt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/48103c8ee52d4ceff0fb8974ffb17e6bfab773b51f9d187a3a581401d6a7663b/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\msdt.exe.mui": "File", "(---) C:\\Users\\user\\AppData\\Local\\Temp\\msdtadmin\\_4FEAE4A6-A1F1-4528-B3F3-316545AC1C61_\\inuse": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\msdt.exe.mun": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\msdt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "An error occurred" }, "msfeedssync.exe-E1C1AB8118F67D856FD140FB7175BF13": { "file_name": "msfeedssync.exe", "file_path": "C:\\Windows\\SysWOW64\\msfeedssync.exe", "hash_md5": "E1C1AB8118F67D856FD140FB7175BF13", "hash_sha1": "FC8716EB4A2C5EB980022F8683DFBD4CD9A5B727", "hash_sha256": "73CD7E458475E0A83CDE7FAA3982FCD341A6B6C4AFAB33E4950BCCD15635EADF", "hash_sha384": "CEAFD3226395D7642D1E2E9EF6DCA67EACBA36F6F7FB4E6E76D5FAC04652E3B3CC911C9F924B32718E14A1CE7F2DBB20", "hash_sha512": "1B7278347C8ABD2536A61B017574718FA3B5ADD4A9F0ACD22576C4380F1CF0A2FF9057AE4E405A047B2C4D2539695D1E142E4CD0DC55FC5D3E5AB8B2A6FDFAE5", "hash_ssdeep": "192:DgOt5Km8/ddLDVIg3wHmm4DvXFhRM3s8oRWcs0oj:DBt5A/dFJI02mmyFhCARWcs0I", "hash_imp": "ADEEB2B92A40AAEE5BEF5E8DCE91D76B", "hash_pesha1": "B88E86A93D4D1B6ED0D8E0F508D1EA560E556585", "hash_pe256": "1CB6ECDC9FDAE126E297F40C8559A5CACAC41C3395B598B5F073169ACB6FAB12", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Feeds Synchronization", "meta_original_filename": "msfeedssync.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/73cd7e458475e0a83cde7faa3982fcd341a6b6c4afab33e4950bccd15635eadf/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\msfeedssync.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mshta.exe-06B02D5C097C7DB1F109749C45F3F505": { "file_name": "mshta.exe", "file_path": "C:\\Windows\\SysWOW64\\mshta.exe", "hash_md5": "06B02D5C097C7DB1F109749C45F3F505", "hash_sha1": "089B8363EB686C8D055EC2C4E5899FDD450EF77D", "hash_sha256": "213AB5658E44F2A111C5E4CFFA043660BC49307EBB1B7EEDD21DBDDCA5DA41AC", "hash_sha384": "9F4C5B2814D427DB94275CB4D11D3DD4E25497E71282A45A93245535FFB6B61064111AC3762F3D561F5DBD7ADC7DDCF9", "hash_sha512": "CFE911501CCFCE27F8EEEBA161D545A183AFCF03206DBC2EFA9320947D78D0CFE8AB1398BDEC7CA426EB76AF657704C6567375FD1F2C26EC3B0D281B99D5D654", "hash_ssdeep": "96:+qlXn5BDB1IeuXhOGVl82Ap2N8VDLDGjoJDYwuDy7ovE6759SF2DJ+PjGGYEWw5G:++11pktg/wSODy7o8672FDJWw5aIR9", "hash_imp": "EE4E4A67C3E30B424AA8A1C9C579181F", "hash_pesha1": "B438EE8BF926E33D2AF0AC36A63C5F94D2549BF1", "hash_pe256": "1B8228D6866694ED22E51F9E4F8F98C67419CC6B0884F1735CA7FBF7A8325601", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) HTML Application host", "meta_original_filename": "MSHTA.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "1/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/213ab5658e44f2a111c5e4cffa043660bc49307ebb1b7eedd21dbddca5da41ac/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mshta.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "msiexec.exe-9D09DC1EDA745A5F87553048E57620CF": { "file_name": "msiexec.exe", "file_path": "C:\\Windows\\SysWOW64\\msiexec.exe", "hash_md5": "9D09DC1EDA745A5F87553048E57620CF", "hash_sha1": "1D0C7CFCA8104D06DE1F08B97F28B3520C246CD7", "hash_sha256": "3A90EDE157D40A4DB7859158C826F7B4D0F19A5768F6483C9BE6EE481C6E1AF7", "hash_sha384": "D735C0B7D639C98F2B853D0540F62A7BB2EE7DF377D9B07821062CF3E01B40F94520400B56B014BD8DF8E4884D0AB305", "hash_sha512": "2BE940F0468F77792C6E1B593376900C24FF0B0FAE8DC2E57B05596506789AA76119F8BE780C57252F74CD1F0C2FA7223FE44AE4FA3643C26DF00DD42BD4C016", "hash_ssdeep": "768:uo8HL2TB4LHLbo77Q2d9xSDvYD07BOUp8VKfTKznHVXq6ayYf3:vTB4LG7B8jY4XprIHw62", "hash_imp": "E4E40938E4BF6C66424859ED02171C41", "hash_pesha1": "3631FA02746894561C6151FA554165C21DCF1ED6", "hash_pe256": "81CA9B493C0C48D4D6F966981089A2D6DC86FDEDBD4C7FC5F62D6FCDEEA6839D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows installer", "meta_original_filename": "msiexec.exe", "meta_product_name": "Windows Installer - Unicode", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3a90ede157d40a4db7859158c826f7b4d0f19a5768f6483c9be6ee481c6e1af7/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\msiexec.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\msimsg.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\msiexec.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Installer" }, "msinfo32.exe-E0A7B839C77497E01864479B70ACB5AE": { "file_name": "msinfo32.exe", "file_path": "C:\\Windows\\SysWOW64\\msinfo32.exe", "hash_md5": "E0A7B839C77497E01864479B70ACB5AE", "hash_sha1": "74DBDE5817BBCDCA9DBF81CE24461AC7F6AFFDC0", "hash_sha256": "7C9587BAD9050E03F13AB1F46E4F02F350CDD0A6EA893F70D52436E3849B2985", "hash_sha384": "0A1C265419CEF0C310DB72E768431A4D2C797B1874B072F5C9E44ACD31693FEA0069505AF7779A33F40AFAE1207193C0", "hash_sha512": "6D86476E1F1ADAF493063A4AB52128BCDA6CD0D3EFB4D1BD304D55CC9B3697FAC111D816C8BE3BB0FA872ECEB0356A4B1F415E50D88FFF4B4A187B6FF790DBC4", "hash_ssdeep": "6144:8+Curxrt3aOo/8McrIHxKhph5hphcl1oMtSZEOHHrpm1XUZLxEZEOHHrpm1XUZLp:8HuVgD/LmIHxKhph5hphcl1LOtLpm1E0", "hash_imp": "B82A7325B56EDAACBA365CDE179A07C8", "hash_pesha1": "0F79860591C9CB296F3781D49189669320F3D4DF", "hash_pe256": "EA416041E0D1B4A0F167FCCAC677752C95F1B8869B0845D940D0E7973DFB058C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Information", "meta_original_filename": "msinfo.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7c9587bad9050e03f13ab1f46e4f02f350cdd0a6ea893f70d52436e3849b2985/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\msinfo32.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\msinfo32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "System Information" }, "mspaint.exe-986A191E95952C9E3FE6BE112FB92026": { "file_name": "mspaint.exe", "file_path": "C:\\Windows\\SysWOW64\\mspaint.exe", "hash_md5": "986A191E95952C9E3FE6BE112FB92026", "hash_sha1": "1E2A48F1088CA5AB78617A7EEB8AA5F62ABD4846", "hash_sha256": "8BD3C3D2A3E6285D004AFD50262D80939FA588B39C5ECB404D12D364216E73B2", "hash_sha384": "05DCA8E9021857F4AC731191D0DDEE1972DB016DFDAE6914FF91F783D211ABAB02287C883C054ADFC76E5F88DBE8ADBF", "hash_sha512": "044294049FED0C5165D2C204D4DFEF8DDC65CBC872D499531A2D4F179E3AE2345142510FFC9C12C32E0C316EAC3250D60B0B316A74A3D7D31B0A9699DC8529F7", "hash_ssdeep": "12288:fk4MXNLmDguv3NU+5cqI648Hd+qKoN26/XtqG/OqNj+mJ5Fw9qF6fDKog0+QLkR:6XNLmDguF7/4899KoN2OqG/5j15Fw9qb", "hash_imp": "056D9B704775F8E465E0485902904B4E", "hash_pesha1": "85074F0F9492693754DD9882E6B6D4F7C36AB048", "hash_pe256": "7D7F56CFA17592E07016FA0FD7A6568BB5F3E45709A711C29D910087B56889A9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Paint", "meta_original_filename": "MSPAINT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8bd3c3d2a3e6285d004afd50262d80939fa588b39c5ecb404d12d364216e73b2/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\mspaint.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_4299dbb28a92ae3e": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Windows\\debug\\WIA\\wiatrace.log": "File", "(R-D) C:\\Windows\\SystemResources\\mspaint.exe.mun": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\UIRibbon.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R--) C:\\Users\\user\\--help": "File", "\\BaseNamedObjects\\RotHintTable": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\mspaint.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Paint" }, "msra.exe-C672D655B862EB54B57B678D506F58E4": { "file_name": "msra.exe", "file_path": "C:\\Windows\\SysWOW64\\msra.exe", "hash_md5": "C672D655B862EB54B57B678D506F58E4", "hash_sha1": "C32BB7E5D18A9044F327E8E2FCF23E8F96E5BCCA", "hash_sha256": "A9F3B092C6204F05311174628076E0CF719FE1D3A83AF43EB2FB60144E988965", "hash_sha384": "AC6496C5A2E3DD548DB2435D1F2B60A9C91089BCE3550FCA786AF476FEC2C237C9A5A1DBCA075E78903B529DBA429CB8", "hash_sha512": "E254AA57871AC59E59BC7F015EBF2CCD1ABE3F968202AB36850E38C90F94B82F88669AE5202B0B1C1AC857B0C46191FE9B007DF3A263AFBA96D62C1BB9472BB5", "hash_ssdeep": "1536:HELmsueazinQ+dYxfNJK02oM8kIcnmPkkSTst7vIyR:HdRLSX8jn6KvI", "hash_imp": "3A9CFBE2704D53479014B87DF3DAF578", "hash_pesha1": "A05C14CBE51A73F05737D925B41BD4365E9B5DAD", "hash_pe256": "5D0A15D102DAB4E79E2720237879AD81F3529D44982C2A6BA362319C716F52CC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Remote Assistance", "meta_original_filename": "msra.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a9f3b092c6204f05311174628076e0cf719fe1d3a83af43eb2fb60144e988965/detection", "children": "msra.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\msra.exe.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\msra.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mstsc.exe-035314ECE0D2904CD11B070D3DFF6E7C": { "file_name": "mstsc.exe", "file_path": "C:\\Windows\\SysWOW64\\mstsc.exe", "hash_md5": "035314ECE0D2904CD11B070D3DFF6E7C", "hash_sha1": "C04DADEF7E27983972BC1BD93304DCF8FFA7E28C", "hash_sha256": "08AAB0687C052AFCB0959DD9F5580745336C7B14E1ACD40EBA32E8B326F8BFFC", "hash_sha384": "D9B1F6D4B2BC6E8DD2F683166962ECEF0495CCAA6D8FDAAB0C2FEC9FC7AC450C09D8B70954D68981C6DD234F510BDCCB", "hash_sha512": "4AD8F27F3ADA7AF84509853A4E1490ABFB0EDBCE78420A20AD64C50F168B050275E209CD053AF723081E9C012D374554379D03C50E549DEBB9A5B0B30800EA79", "hash_ssdeep": "24576:mS2n2Y4wHj7ZjE4M5FuG2/07hawMS7tCGmQYOozji/ZbSG9gMmzHtKBnHD8ougt:Vm25wxG63ln8djV", "hash_imp": "3B243D5A3E7930EA33DE363F732B781D", "hash_pesha1": "4D899A965772779396383D88614CDAF952F9C3BA", "hash_pe256": "21CB1073C4EE60F24832CAEB5EB560C0F472C19342D8C1241964E9E4B9689D79", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Connection", "meta_original_filename": "mstsc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/08aab0687c052afcb0959dd9f5580745336c7b14e1acd40eba32e8b326f8bffc/detection" }, "mtstocom.exe-5930C59472F42B5F237500C999727441": { "file_name": "mtstocom.exe", "file_path": "C:\\Windows\\SysWOW64\\mtstocom.exe", "hash_md5": "5930C59472F42B5F237500C999727441", "hash_sha1": "3D41AC230B7FB2A467804D5341A54491D8AF0530", "hash_sha256": "9DB938CB9989A1882DBC0F344E510E76BAFC4358B2AADB5DBB66A11D763A7AE6", "hash_sha384": "B18838650060405D4B1609D469A3FBD414C34DF31338A7AE461B96B1374FDE65FE75FB56F37075931D481DE0FE7846F6", "hash_sha512": "C2E76CC6F64F32BFFBF280C6E89FDE42874CDA4601048A9525C960D659D789199813157948A9661E379B4AC088142921974EEFA20BFC69F79B99B48D7DC6008D", "hash_ssdeep": "3072:W2CFzMuka9O72YrrR97xU60rYPbFOgu3o:W1FQuc2YrjO6TTFOA", "hash_imp": "08B4F5CEB407D118D07C8692BB1C07FF", "hash_pesha1": "AEBF5FAF3E8DE17A38C9087B475B36158E6E077E", "hash_pe256": "17390E04E4A0DE9AD5F90770F9263D529043F497560272A4428AB2E333DAE3AC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+", "meta_original_filename": "MTSTOCOM.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/9db938cb9989a1882dbc0f344e510e76bafc4358b2aadb5dbb66a11d763a7ae6/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mtstocom.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MuiUnattend.exe-AC45586A0B1CCCC8F1CC5276D8DC9893": { "file_name": "MuiUnattend.exe", "file_path": "C:\\Windows\\SysWOW64\\MuiUnattend.exe", "hash_md5": "AC45586A0B1CCCC8F1CC5276D8DC9893", "hash_sha1": "6A5D99C8618367BDC0AF7DA70996AAF373B5D5B3", "hash_sha256": "AC644FF7C0D30E0C0BEA00255CA65CFDCB5972799ACE79FCA41C50BF496E44E9", "hash_sha384": "2913A325B721B775346E4559459E223BE4E8C6E71747B12383352264CC3D1AD94647B313C5A0B5A3E829F73BD2AB271C", "hash_sha512": "2C0D69EE7028272539CE3FE1007C16E5592522D80F236E59EB79A56D49EEB2A99AF87256BBB926BBD5C670F4FFFECDC6BECD4DDCF57C75F0D1E20B9409CFFF51", "hash_ssdeep": "1536:gAAX5T8mHe4nAgKIMz7cfQpi8On5qoanxUglYj4jPFEHSBAboXd3iCQqnC6+:gAPhcAgKIQYfF8On5qD2glk4rFknGCjn", "hash_imp": "077339B2CC4306B9686EBA0AEDF87EAB", "hash_pesha1": "511322F1C8D63CDFDBF2BC939ECC49E7C8750576", "hash_pe256": "B6985751E7A2B94A0BC6FCA66DE6D10F8F113D9BA02022BF8AF3FDC252C8C70E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MUI unattend action", "meta_original_filename": "MuiUnattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ac644ff7c0d30e0c0bea00255ca65cfdcb5972799ace79fca41c50bf496e44e9/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\MuiUnattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ndadmin.exe-1890F13BD17570D36EFE9AA192F6CE6E": { "file_name": "ndadmin.exe", "file_path": "C:\\Windows\\SysWOW64\\ndadmin.exe", "hash_md5": "1890F13BD17570D36EFE9AA192F6CE6E", "hash_sha1": "A718DCF5571EADCBF311322D30077CB95473D929", "hash_sha256": "46E4B4F4E9B7369DBD24D8BF09B092EDB1A0E051F65467562A8A0FE5E5E988CE", "hash_sha384": "8057E54FE9DF1D4FBAF673FE88E7B90F5C5B225F7CDF465EE2E26A9D6C6F411B14DF741F52C34B204B9E6C8B6B95E56F", "hash_sha512": "D5E411C401D341F5F025ACF2EFB011C38C7980C052A9A46D29E4D485A77D286BF1F743039AD586BA72CF3D76DE0DCC4FE265022390452299B887006CF07885E9", "hash_ssdeep": "768:xilh3x8dsPbjQAhtqIrn8+1hrpFIUUUUUUUUUUUUqRcxMm/:xilhh8dCbjfFrGUUUUUUUUUUUU3+m", "hash_imp": "5C2A6BE2FBEA9DDE5E237A67C853D0FA", "hash_pesha1": "85F97516E2742DC7B33F7604343BB030CB6D7061", "hash_pe256": "17FFD2A69A42585CC30CA48B0B014A527385848326F271F9FBDD52A5147A5D8A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device driver software installation", "meta_original_filename": "NDAdmin.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/46e4b4f4e9b7369dbd24d8bf09b092edb1a0e051f65467562a8a0fe5e5e988ce/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ndadmin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "net.exe-31890A7DE89936F922D44D677F681A7F": { "file_name": "net.exe", "file_path": "C:\\Windows\\SysWOW64\\net.exe", "hash_md5": "31890A7DE89936F922D44D677F681A7F", "hash_sha1": "A5BADC2DD4DBAA8ED5F0A3646F7248BF060A2F13", "hash_sha256": "7C4C7725E266F12ABA8C50FD1598D4001201BCA0E7ACA901508307E365AFFF42", "hash_sha384": "A5419FB1E25167553C0726DB58DD58F9CB507AA1CACB819EDBEA840A9F4A0F882A95161054F9E22B6667804E0527F1E0", "hash_sha512": "A921CDF8BD8ED267A96BA7B41F34657BE2C564A2DBF32F5DFED68435E1F2ED24AB9D081498791BD9B811AF4B35652D60014F5C0AAE64F1B69631D84F149DA455", "hash_ssdeep": "768:gD4wg9/D0xoYrEqStXRphjl5Mtt5+m3kZcX5orUZp+1uq3:gD0J068SNRpqr3kZcXuIZp+", "hash_imp": "AC592B83B5CAEB41A6F6DF7DB53F9076", "hash_pesha1": "58E18AABCDB91A3C6AA5BA3BD0CD1CF553596041", "hash_pe256": "7F7FBAFFEE4CDC9F1F0C46BC2FF27D89D43E750E810DA75EE73FC9098FDDA34A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Net Command", "meta_original_filename": "net.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7c4c7725e266f12aba8c50fd1598d4001201bca0e7aca901508307e365afff42/detection", "error": "The syntax of this command is:\r\n\r\nNET\r\n [ ACCOUNTS | COMPUTER | CONFIG | CONTINUE | FILE | GROUP | HELP |\r\n HELPMSG | LOCALGROUP | PAUSE | SESSION | SHARE | START |\r\n STATISTICS | STOP | TIME | USE | USER | VIEW ]\r\n", "output": "The syntax of this command is:\r\n\r\nNET HELP\r\ncommand\r\n -or-\r\nNET command /HELP\r\n\r\n Commands available are:\r\n\r\n NET ACCOUNTS NET HELPMSG NET STATISTICS\r\n NET COMPUTER NET LOCALGROUP NET STOP\r\n NET CONFIG NET PAUSE NET TIME\r\n NET CONTINUE NET SESSION NET USE\r\n NET FILE NET SHARE NET USER\r\n NET GROUP NET START NET VIEW\r\n NET HELP\r\n\r\n NET HELP NAMES explains different types of names in NET HELP syntax lines.\r\n NET HELP SERVICES lists some of the services you can start.\r\n NET HELP SYNTAX explains how to read NET HELP syntax lines.\r\n NET HELP command | MORE displays Help one screen at a time.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\net.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "net1.exe-2D06D33D05E02C11DC5C5B9A671E974C": { "file_name": "net1.exe", "file_path": "C:\\Windows\\SysWOW64\\net1.exe", "hash_md5": "2D06D33D05E02C11DC5C5B9A671E974C", "hash_sha1": "B4A2C1230227500BFA40ABFE6722AB88E97ACF5E", "hash_sha256": "964722D4207CDF6C2419212E101B453A7C6DAFD3B65AC9205AAEA4D38C5514E4", "hash_sha384": "B6FA912B1A0BA0B9CCB9BB7982AC72EB9F1AD5CF0DCF414C51E37537208437910F9A50C7D2B45D1B98697C07130AB983", "hash_sha512": "3F4D3EFBC81DBDB27D5A8E4015B9C5A3847EF26B3525531684F4B8E5F2E959D2CBEF36F26BB429C9130A030986EFBB84AC83246A4133C46375A32C0C20663D2B", "hash_ssdeep": "3072:DKTO7WOip+MUEAWChg4wqPceuZS5/wNlWKiHBVjR:OTSEpGRZjuZS5/wNgKiHBhR", "hash_imp": "1D734F0B53689FA33F2F764B9CDCF8EE", "hash_pesha1": "345B9477403C930FBF6D781034379194DB3F0FD4", "hash_pe256": "34B357E41777AA5DBE2FDBECBE06F51FFEC7EC68E24B6F781C1ECA772DA64E46", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Net Command", "meta_original_filename": "net1.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/964722d4207cdf6c2419212e101b453a7c6dafd3b65ac9205aaea4d38c5514e4/detection", "error": "The syntax of this command is:\r\n\r\nNET\r\n [ ACCOUNTS | COMPUTER | CONFIG | CONTINUE | FILE | GROUP | HELP |\r\n HELPMSG | LOCALGROUP | PAUSE | SESSION | SHARE | START |\r\n STATISTICS | STOP | TIME | USE | USER | VIEW ]\r\n", "output": "The syntax of this command is:\r\n\r\nNET HELP\r\ncommand\r\n -or-\r\nNET command /HELP\r\n\r\n Commands available are:\r\n\r\n NET ACCOUNTS NET HELPMSG NET STATISTICS\r\n NET COMPUTER NET LOCALGROUP NET STOP\r\n NET CONFIG NET PAUSE NET TIME\r\n NET CONTINUE NET SESSION NET USE\r\n NET FILE NET SHARE NET USER\r\n NET GROUP NET START NET VIEW\r\n NET HELP\r\n\r\n NET HELP NAMES explains different types of names in NET HELP syntax lines.\r\n NET HELP SERVICES lists some of the services you can start.\r\n NET HELP SYNTAX explains how to read NET HELP syntax lines.\r\n NET HELP command | MORE displays Help one screen at a time.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\net1.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "netbtugc.exe-B90999280377BD3D3BD041FA5F906BED": { "file_name": "netbtugc.exe", "file_path": "C:\\Windows\\SysWOW64\\netbtugc.exe", "hash_md5": "B90999280377BD3D3BD041FA5F906BED", "hash_sha1": "D8D58E5B915458DB28D9866695800EBA5FC6CC09", "hash_sha256": "90662ED05D2E3F416B9E1482ECFC0D4265918152016354ED882922F660C64FC3", "hash_sha384": "CB938EE2840573199385D1DEE903AEADCDC91693403DA298758375204E075848ED97AA73054152B7521CCDA9E7E8F4C3", "hash_sha512": "2BA1CDAF0193ACAC5AEE9072058C7947447A6E0865D5B018B19FDD6BE6EEBC878E2BB59459829D2C890B6D7C3DB72020A76DF66421B66E93F32558ADF2D555DB", "hash_ssdeep": "384:Uj2osEgJ9UfPPB+aNYFCasNPWI0B4gfmSkiVw+I/PW/uFWAb:6fx+lFCao0iBiVmxJ", "hash_imp": "4466068C0E40CE7D9687DE58566C2743", "hash_pesha1": "9B48053B8CA1E6EF33014880C32266FA48E147F2", "hash_pe256": "198DC6D27D1AD3D6649CF987F9765616BFB8CF52C24E835E2BB1B9686A6DE9D3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NetBT Unattend Generic Command", "meta_original_filename": "netbtugc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/90662ed05d2e3f416b9e1482ecfc0d4265918152016354ed882922f660c64fc3/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\netbtugc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "NetCfgNotifyObjectHost.exe-170BEF4E786C676C3A68163D23B81C5B": { "file_name": "NetCfgNotifyObjectHost.exe", "file_path": "C:\\Windows\\SysWOW64\\NetCfgNotifyObjectHost.exe", "hash_md5": "170BEF4E786C676C3A68163D23B81C5B", "hash_sha1": "C5ACEC8E7C386E01E12186C7C7B9FE619BEB7810", "hash_sha256": "4AA3B4382067841FD02D4778BAD973DD89E43F22B08A0A3A27FF463F01540E85", "hash_sha384": "AD38BA1E13B3CA1897370D8CB4E27B41B7894856EEA82683F4A8A649D0BE6160769FB47EB9DDEDFA64B895E3DB4552E9", "hash_sha512": "E0B13ABF56210F797854A7F5782A35E99E6F9145BB6EEDAA2414B7E89A8D0D2C52D2B36078F727ACEB09539306851F506253216B9FED5D1C415455898C0D30CA", "hash_ssdeep": "1536:fKE9pTyrqNrpeFgOTzB9Ja8Q1ROrsBZe0Mx/iETvC/yuwJE9jE+x:fByrAFeF13JzQ1ROrsBZe0Mx/iYa/yJg", "hash_imp": "A8D7B6412514578972310CDCBECE40DF", "hash_pesha1": "D84845B861980E7237F2203F51DCAEFBCBE18518", "hash_pe256": "2A25BB8C93695F31EC54293630DBD6725C01CC016FF6BB92EAA4AA417138808C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Network Driver Configuration Plugins", "meta_original_filename": "NetCfgNotifyObjectHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4aa3b4382067841fd02d4778bad973dd89e43f22b08a0a3a27ff463f01540e85/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\NetCfgNotifyObjectHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "netiougc.exe-D6F88E1E0D5AF1462FE2586CD13395C1": { "file_name": "netiougc.exe", "file_path": "C:\\Windows\\SysWOW64\\netiougc.exe", "hash_md5": "D6F88E1E0D5AF1462FE2586CD13395C1", "hash_sha1": "29925F4A8D4AF58C96F757A97982CAB5944B8378", "hash_sha256": "8908F41BF5480D047FD3D6B08493D4280B2FAAF530DD245516B06ABF1BF48B87", "hash_sha384": "7030888D5158D2390F76061D98F9B1436E5D50E943B2F95C4A8F89FDBEE01C75333296F8DCBFDC132ECF476912E82049", "hash_sha512": "7DF069A3851C3C992839C37C174006827952BA8FE4C2AF8560B838759D52D0C7B3C0C7DEEA3A015C9F451D638E4661D40C3751C8B815C3DA8064D7304301768A", "hash_ssdeep": "384:Jx59osET80onfa3iLeoW6LOU/dBpWVoh/uETtI5s+0Z6j/3YqE4dWXXNWU:Jx5hHhOUPGLEO5WZ6j/39NCJ", "hash_imp": "39A671FDA98B2B10A7EF471D1DE3BC56", "hash_pesha1": "336A3B678F04A8773FE13E2C4CB9CD548A7EB76A", "hash_pe256": "0914EDF2F7BAFA7904A5A33AC8F7FB4A8E487A67A4FAD3647E21A67EC768DA79", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Netio Unattend Generic Command", "meta_original_filename": "netiougc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8908f41bf5480d047fd3d6b08493d4280b2faaf530dd245516b06abf1bf48b87/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\netiougc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Netplwiz.exe-28DF040CA6E1FF434429485EDB9EF869": { "file_name": "Netplwiz.exe", "file_path": "C:\\Windows\\SysWOW64\\Netplwiz.exe", "hash_md5": "28DF040CA6E1FF434429485EDB9EF869", "hash_sha1": "E94782BE789535B2ED055F9891E4D8F3C266CF73", "hash_sha256": "223ADF0652426B95C10C2081F185AE82FD96BA1DE0AB1569913809922E5765F9", "hash_sha384": "007D30D53D13104171513A9523298E9F307498E771B3A6967C3496C7923A0557773FAFD3943AC207C8DE69E17FD1D63A", "hash_sha512": "CD82160139972B948CE3AB1A3D6797E64A8340FCC1751472819AC57C32FD34D127A0FBBC0E6B13DA23811921B58EEEB90BE98DB33CF49598A805D491FEFE261C", "hash_ssdeep": "768:nryqWemtvUIr9Ty7fUrh6WeENiJDBPrxZt4p:nryTemVryOeWSDBPrxZap", "hash_imp": "983415DF1D541F291D0E1A1B15A0047E", "hash_pesha1": "5A1EC51900361FDA73BA8E6EAEE089D7A3EB22AF", "hash_pe256": "91DDC599CB84485076997237D7D33475DDC4F05339F677FBD12F70553909E4DD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Advanced User Accounts Control Panel", "meta_original_filename": "NETPLWIZ.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/223adf0652426b95c10c2081f185ae82fd96ba1de0ab1569913809922e5765f9/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\Netplwiz.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\netplwiz.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\Netplwiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "netsh.exe-4E89A1A088BE715D6C946E55AB07C7DF": { "file_name": "netsh.exe", "file_path": "C:\\Windows\\SysWOW64\\netsh.exe", "hash_md5": "4E89A1A088BE715D6C946E55AB07C7DF", "hash_sha1": "42A2098CF80EF917B6374715914FFAA36F6B65DF", "hash_sha256": "9EFA9DAFA09AE9BA6390A8F0F6751006C18A98B6692667CA08367CDDB47AC634", "hash_sha384": "12D27C730A8C18A36DFE14F91D01039DCEE1DE83718ADFC2A43B8BCFFA554F355DC9E224FB100FA4043E79320F2F97E7", "hash_sha512": "2FC5AE837676ACD894DD66959C1F030388A5C9D0270033704FE9260767337FB520E6D88DE28C6A456E36D7E7F5D075FC7F68E954017D0674597829A7F26CFFC2", "hash_ssdeep": "768:NvRTXqA4Ns80OePbc+l5TlfGh1paSWzg6ljWbkt3j9ZVM:NvRGb90OetTls1YSdGWbktz9T", "hash_imp": "C8D91522FEEE1152DC40833F6A4717E7", "hash_pesha1": "2A90BB2A4A4387307FAFC14CD159F513330EEA05", "hash_pe256": "07D1F936FAB36E4A6615B0C4A8F81C35EFB8AF3D1CC31519F37D23D493E05CE7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Network Command Shell", "meta_original_filename": "netsh.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/9efa9dafa09ae9ba6390a8f0f6751006c18a98b6692667ca08367cddb47ac634/detection", "output": "\r\nUsage: C:\\Windows\\SysWOW64\\netsh.exe [-a AliasFile] [-c Context] [-r RemoteMachine] [-u [DomainName\\]UserName] [-p Password | *]\r\n [Command | -f ScriptFile]\r\n\r\nThe following commands are available:\r\n\r\nCommands in this context:\r\n? - Displays a list of commands.\r\nadd - Adds a configuration entry to a list of entries.\r\nadvfirewall - Changes to the `netsh advfirewall' context.\r\nbranchcache - Changes to the `netsh branchcache' context.\r\nbridge - Changes to the `netsh bridge' context.\r\ndelete - Deletes a configuration entry from a list of entries.\r\ndhcpclient - Changes to the `netsh dhcpclient' context.\r\ndnsclient - Changes to the `netsh dnsclient' context.\r\ndump - Displays a configuration script.\r\nexec - Runs a script file.\r\nfirewall - Changes to the `netsh firewall' context.\r\nhelp - Displays a list of commands.\r\nhttp - Changes to the `netsh http' context.\r\ninterface - Changes to the `netsh interface' context.\r\nipsec - Changes to the `netsh ipsec' context.\r\nlan - Changes to the `netsh lan' context.\r\nnamespace - Changes to the `netsh namespace' context.\r\nnetio - Changes to the `netsh netio' context.\r\np2p - Changes to the `netsh p2p' context.\r\nras - Changes to the `netsh ras' context.\r\nrpc - Changes to the `netsh rpc' context.\r\nset - Updates configuration settings.\r\nshow - Displays information.\r\nwfp - Changes to the `netsh wfp' context.\r\nwinhttp - Changes to the `netsh winhttp' context.\r\nwinsock - Changes to the `netsh winsock' context.\r\nwlan - Changes to the `netsh wlan' context.\r\n\r\nThe following sub-contexts are available:\r\n advfirewall branchcache bridge dhcpclient dnsclient firewall http interface ipsec lan namespace netio p2p ras rpc wfp winhttp winsock wlan\r\n\r\nTo view help for a command, type the command, followed by a space, and then\r\n type ?.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\netsh.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "NETSTAT.EXE-9DB170ED520A6DD57B5AC92EC537368A": { "file_name": "NETSTAT.EXE", "file_path": "C:\\Windows\\SysWOW64\\NETSTAT.EXE", "hash_md5": "9DB170ED520A6DD57B5AC92EC537368A", "hash_sha1": "58439037BD6BABFA0EB32E2C1F331D8E715A8B62", "hash_sha256": "5B0C639E4B9916D7EE58A75587CF5BB8D6136BDF2DEC95537C1765720C7B7CCC", "hash_sha384": "4D3A4A5A706F0215D50C55617BD4EA8E213040348797DB5B3F03044E1E26C1456FA73E4458260B6D4E83DEFEE1E2199B", "hash_sha512": "3BB75B0438A19507D09E7C0D0BCA703342CC33A3ED04A4B835749BE585B689F0C4A2320FF53253FE4EE98A5B7D3E4B04C7671C822E196E1EA5793D724C23C9D6", "hash_ssdeep": "384:jWBE/Nh40Em/4jC7vARslC/2IiAtLV6tdGVt0bJ6hQTqiwMI3NoCh52Mi99FWKQX:jWWf40ESjzIlc8MJpLwMeHiPnH", "hash_imp": "4A124D4C214DBB24BCE7F0447B727173", "hash_pesha1": "7BBE86223CC2765EC2A96A8A44723F8E9D4372FD", "hash_pe256": "EFA43159298444F5A6B45F8D8908357F140BFF36A372F96B9B5B60042FA58A8C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Netstat Command", "meta_original_filename": "netstat.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5b0c639e4b9916d7ee58a75587cf5bb8d6136bdf2dec95537c1765720c7b7ccc/detection", "error": "\r\nDisplays protocol statistics and current TCP/IP network connections.\r\n\r\nNETSTAT [-a] [-b] [-e] [-f] [-n] [-o] [-p proto] [-r] [-s] [-t] [-x] [-y] [interval]\r\n\r\n -a Displays all connections and listening ports.\r\n -b Displays the executable involved in creating each connection or\r\n listening port. In some cases well-known executables host\r\n multiple independent components, and in these cases the\r\n sequence of components involved in creating the connection\r\n or listening port is displayed. In this case the executable\r\n name is in [] at the bottom, on top is the component it called,\r\n and so forth until TCP/IP was reached. Note that this option\r\n can be time-consuming and will fail unless you have sufficient\r\n permissions.\r\n -e Displays Ethernet statistics. This may be combined with the -s\r\n option.\r\n -f Displays Fully Qualified Domain Names (FQDN) for foreign\r\n addresses.\r\n -n Displays addresses and port numbers in numerical form.\r\n -o Displays the owning process ID associated with each connection.\r\n -p proto Shows connections for the protocol specified by proto; proto\r\n may be any of: TCP, UDP, TCPv6, or UDPv6. If used with the -s\r\n option to display per-protocol statistics, proto may be any of:\r\n IP, IPv6, ICMP, ICMPv6, TCP, TCPv6, UDP, or UDPv6.\r\n -q Displays all connections, listening ports, and bound\r\n nonlistening TCP ports. Bound nonlistening ports may or may not\r\n be associated with an active connection.\r\n -r Displays the routing table.\r\n -s Displays per-protocol statistics. By default, statistics are\r\n shown for IP, IPv6, ICMP, ICMPv6, TCP, TCPv6, UDP, and UDPv6;\r\n the -p option may be used to specify a subset of the default.\r\n -t Displays the current connection offload state.\r\n -x Displays NetworkDirect connections, listeners, and shared\r\n endpoints.\r\n -y Displays the TCP connection template for all connections.\r\n Cannot be combined with the other options.\r\n interval Redisplays selected statistics, pausing interval seconds\r\n between each display. Press CTRL+C to stop redisplaying\r\n statistics. If omitted, netstat will print the current\r\n configuration information once.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\NETSTAT.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "newdev.exe-0059CE2007BE4AC0F00E2007EB327770": { "file_name": "newdev.exe", "file_path": "C:\\Windows\\SysWOW64\\newdev.exe", "hash_md5": "0059CE2007BE4AC0F00E2007EB327770", "hash_sha1": "81A1BAEE23814ED74124EA8CD08BD49E6FC734C5", "hash_sha256": "CE9B35CE076CA17F312A324058925AECF9E389C61F27985A161DABD7B016CF01", "hash_sha384": "2B3E13AF032433110F4F5F2ECF8CD42508F4AAB02A9E77E779E658A1FA3CDE1BFBFADBA5461CF9D057855838C6E78AF2", "hash_sha512": "C21D2F84FFB6146267CED32C2BF40DB56A28AB3B2CE78258A55AA3B9FC7A50332ED8ECC42114690042B2F7F6917C819B1CD666DC9DCC5CFC5BEFC5EA03C80F6C", "hash_ssdeep": "768:1iFs97OzKEH02zaJQAhtqIrn8+1hrpFIUUUUUUUUUUUUqRcxMF:cFsBOzR02zaJfFrGUUUUUUUUUUUU3+F", "hash_imp": "B4DC1C33BAF719825A5B35608B2A72A8", "hash_pesha1": "A3838686F51BBEB93DEE1D82715AFFA30DC264AA", "hash_pe256": "41FE0094E2D33ABA16F793546AABB1F74B35C205F1B5430CF89DBCD10233626C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device driver software installation", "meta_original_filename": "NewDev.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ce9b35ce076ca17f312a324058925aecf9e389c61f27985a161dabd7b016cf01/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\newdev.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "notepad.exe-E92D3A824A0578A50D2DD81B5060145F": { "file_name": "notepad.exe", "file_path": "C:\\Windows\\SysWOW64\\notepad.exe", "hash_md5": "E92D3A824A0578A50D2DD81B5060145F", "hash_sha1": "50EF7C645FD5CBB95D50FBADDF6213800F9296EC", "hash_sha256": "87F53BC444C05230CE439DBB127C03F2E374067D6FB08E91C834371FD9ECF661", "hash_sha384": "94B1A77101BDDDEC053CF61624F984A858F9A284CE2067EC8497A29A23A056D25D16C4C4D658FEAD8FDE04F4D350F091", "hash_sha512": "40D0AC6FA5A424B099923FCDB465E9A2F44569AF1C75CF05323315A8720517316A7E8627BE248CFF3A83382FB6DB1CF026161F627A39BC1908E63F67A34C0FD5", "hash_ssdeep": "3072:GLLvkpY5SnMwbv5RkorwMLuflibzL/cNArhCAEf7ngKpIcXNokJrzOxEPcZA8TJa:E6USNVRkIHXO7RN/1y6PcOwej/Hv", "hash_imp": "291BF41874EDCDB21D447B43EE0E6B1F", "hash_pesha1": "A449A35286CAC895B59970FC543E0E255D62A779", "hash_pe256": "A3D73A766B718A3D19322043E6418EB9657F752543BDAFA9FD8BCBFA3E874625", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Notepad", "meta_original_filename": "NOTEPAD.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/87f53bc444c05230ce439dbb127c03f2e374067d6fb08e91c834371fd9ecf661/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\notepad.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\SystemResources\\notepad.exe.mun": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\notepad.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "--help - Notepad" }, "nslookup.exe-9D2EB13476B126CB61B12CDD03C7DCA6": { "file_name": "nslookup.exe", "file_path": "C:\\Windows\\SysWOW64\\nslookup.exe", "hash_md5": "9D2EB13476B126CB61B12CDD03C7DCA6", "hash_sha1": "94EEF82037135C46AFADD641C58F8D46E2399C2B", "hash_sha256": "531A1B65E4E3869D65D2EAF6B07C92A34DD6FE18ED9A647BD1A257AB3D0C1AEB", "hash_sha384": "651645B8BFF5031268EA485B741D961A13E6BA96EB13BAAD78E2383A1D7C5DAE448F0DDDA879DE66D9FB4D9C306EB8F4", "hash_sha512": "2BC9BB27FEA55ED715F977223EFD36999E22B1D86ACF19A0715DF65E15FD01023D7F12E63E83DB792B5E2BF27B0824DE542E486FBB183D5DF7142B44AB59D089", "hash_ssdeep": "768:IY0qLepllEGlKKQH9YBtmlXs1ggqwNzT3Dk90qFaqIWnrJWsEe6QYMLZmGIJYBRs:cyOuG1UByHrMCaYMLZQ+BRWgTMZmvuh", "hash_imp": "DA56B644408C06CA96A55143F44254E8", "hash_pesha1": "782FB44FD69D3D1B4B84D34C289CB4697686A7E1", "hash_pe256": "F15594A0C3E91D64B25AA87630F11B78EA6B2354F0B00D0CB75CCF2AA646DF08", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "nslookup", "meta_original_filename": "nslookup.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/531a1b65e4e3869d65d2eaf6b07c92a34dd6fe18ed9a647bd1a257ab3d0c1aeb/detection", "error": "Usage:\r\r\n nslookup [-opt ...] # interactive mode using default server\r\r\n nslookup [-opt ...] - server # interactive mode using 'server'\r\r\n nslookup [-opt ...] host # just look up 'host' using default server\r\r\n nslookup [-opt ...] host server # just look up 'host' using 'server'\r\r\n", "output": "Default Server: DESKTOP-IOOJLI7.mshome.net\r\nAddress: 172.26.224.1\r\n\r\n> ", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\nslookup.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\nslookup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ntprint.exe-A54667054FC769A3888C2F1A0853E93D": { "file_name": "ntprint.exe", "file_path": "C:\\Windows\\SysWOW64\\ntprint.exe", "hash_md5": "A54667054FC769A3888C2F1A0853E93D", "hash_sha1": "FB2EE55AA432B3E150C518E378D2CE4C4295A62C", "hash_sha256": "24BE330AC87CDCFFD09F2F6AB8CA17415EC22E8F28B80C9D2B3B0C804D571834", "hash_sha384": "FCFCA08EAD9E7DD23192D627CC876E08A93F25E1F4270A688DFD19CAB146DF338C12C226966633D92ACB72ECB75D8560", "hash_sha512": "64F998EE30D70ADEED408ED94892D9AD8E704501E0D7524A6424C70020B71720D6B65F340BBAD4325D952B86B588B1F0448DB1900A4651877374D624B3DAC657", "hash_ssdeep": "768:9koqI6PbFT5vI1iQfCIWVM9G4qW4ne+S/ly+PKAoXRZX6fbX57UWkCRPPA7/Qn+:WpHVIPd4n+lbeRZIbSQPPA73", "hash_imp": "84E6CE32AD78D98B8E208DD970DC233E", "hash_pesha1": "ABD4F6CC462D63BE92BEC705B01A2CBBA652FC91", "hash_pe256": "341E80C4CC9EA22250FD9CD2DFF490985C56DB2EBF39B3E4BDEA71DCF887740F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Printer driver software installation", "meta_original_filename": "ntprint.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/24be330ac87cdcffd09f2f6ab8ca17415ec22e8f28b80c9d2b3b0c804d571834/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ntprint.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "odbcad32.exe-270A8ECB4852CE263591DBBCEDE32EDA": { "file_name": "odbcad32.exe", "file_path": "C:\\Windows\\SysWOW64\\odbcad32.exe", "hash_md5": "270A8ECB4852CE263591DBBCEDE32EDA", "hash_sha1": "6319C59F5B2591C736B12DDEB2743A9BBEF2A73C", "hash_sha256": "4D08777448E389EF4355918153FC40BBE8861B66D1F4E48CFDB68B9E9838875B", "hash_sha384": "7DD24E9F58E0A12B0A109A6969074036555666CE8801CB8DACB8A83D36C5ADE8452B4FA359623E14528A95331BF866EB", "hash_sha512": "092A375F4E2169681A8E557AAA40FBFBFFB242442304E6BC20D1C1282A001D41B1FD20976D64F2B6627DF0677C8D4ED01181172F956E05D0694246140C00B764", "hash_ssdeep": "1536:E077Dytv3Jrz6q9EyYt9FlUIlbvBjIloW:EI7UUKI9jo", "hash_imp": "5EA6AB8804656F81EFFBB0E2F39649E5", "hash_pesha1": "06FDFA8E551A3DC37EBF4AC45E00443405C67486", "hash_pe256": "B80253828AB4E8E5B8A6250272B1A0E1F09A8CEF66E021A630CAD07786CEE91E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ODBC Administrator", "meta_original_filename": "odbcad32.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/4d08777448e389ef4355918153fc40bbe8861b66d1f4e48cfdb68b9e9838875b/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\odbcad32.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\odbcint.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\odbcad32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Microsoft ODBC Administrator" }, "odbcconf.exe-D567FFF92055255DBE43BF8F989A4B7E": { "file_name": "odbcconf.exe", "file_path": "C:\\Windows\\SysWOW64\\odbcconf.exe", "hash_md5": "D567FFF92055255DBE43BF8F989A4B7E", "hash_sha1": "C5062F8F0AB46D9CED9D23F1E7473338C5F24EFD", "hash_sha256": "5213C43C38D85BA69B406F27FA1A2505173DEA529010BF6DD34049E9CC9DC01A", "hash_sha384": "441A2A630E4BBBC149EC6E93156CAE6C93DBF8D8CE9D309D43F1B65E72ACC0255FFF9C4CF62C4D32B90A5F1436B4EED9", "hash_sha512": "0A774C8D5A86C942B3B6E9E849559DCD09FE94DB8D8DA259C09787F899271A7B1037563BE5DD10941AECE4BFFA73A1DF65C3476DEA088BCED4DA86D3EC39CA82", "hash_ssdeep": "384:hVrAigT9ML8mORIdwWyjk3lxK29CnnnMrpKsOTt/v3xJPbu8dCxS9l1TlYOyvYb/:D8mOsbenq0t/7NgYbHu9Q5", "hash_imp": "0BFFB84095E2F3283A30D28326BDE550", "hash_pesha1": "24B36B78022D48539A6CC0E647160155DE3B78D1", "hash_pe256": "4274C6FC13C3B63811E1BBEF6929F970E01AAA0C19EC9067907581E3F063F0EB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ODBC Driver Configuration Program", "meta_original_filename": "odbcconf.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5213c43c38d85ba69b406f27fa1a2505173dea529010bf6dd34049e9cc9dc01a/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\odbcconf.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\odbcconf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Invalid Parameter" }, "OneDriveSetup.exe-0EA845F896C821E04009C0336D7547EC": { "file_name": "OneDriveSetup.exe", "file_path": "C:\\Windows\\SysWOW64\\OneDriveSetup.exe", "hash_md5": "0EA845F896C821E04009C0336D7547EC", "hash_sha1": "CE8669D8826C8795115D58C62E726AE53943DCE9", "hash_sha256": "94273EC2DAED031ADB6A954E5E49B29E61042D26BFBE074AF534EA743F54460C", "hash_sha384": "2A3709AE460A9158E5379378240FA330A69BFA69E1A015B0D0585BFC78546D48183401111BFD1BF5FE95736521085ADB", "hash_sha512": "EECA5098D10506EB1D6EEE2CBC50FDCEDA7DEA6468CA753A01059F28B407C4123A78230FB312C0DCFBF87B44703A7C2C9D4E04B71D6BFD63323F865E7B977B34", "hash_ssdeep": "786432:bwDzDsBnXydqA+UHdl2ui3WOsk9BKeVVe90A2MAS:bwDzIRQqA1HHFiGo9nVeGS", "hash_imp": "8CAA74ED9190DA79525729FFC9BE511E", "hash_pesha1": "9853ED227CA8BEE8FA51C6CB2C9477B0A985F4F4", "hash_pe256": "B4DEFEF556A4933B7288D146D1FA14AEC35D01C2C5404CED9B7E2BFA69BD48D4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft OneDrive (32 bit) Setup", "meta_original_filename": "OneDriveSetup.exe", "meta_product_name": "Microsoft OneDrive", "meta_company_name": "Microsoft Corporation", "meta_file_version": "19.043.0304.0013", "meta_product_version": "19.043.0304.0013", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/94273ec2daed031adb6a954e5e49b29e61042d26bfbe074af534ea743f54460c/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_4299dbb28a92ae3e": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(RW-) C:\\Users\\user\\AppData\\Local\\Temp\\aria-debug-4152.log": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R--) C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\setup\\logs\\Install-2020-12-13.0406.4152.1.aodl": "File", "(R--) C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\setup\\logs\\Install_2020-12-13_040600_1038-16f4.log": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\OneDriveSetup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "openfiles.exe-50BD10A4C573E609A401114488299D3D": { "file_name": "openfiles.exe", "file_path": "C:\\Windows\\SysWOW64\\openfiles.exe", "hash_md5": "50BD10A4C573E609A401114488299D3D", "hash_sha1": "7240332D975AAF2F26726730CA18113FE37B5563", "hash_sha256": "8C8EAD6B2FFF2BECE455B6B43BE47DDD177B5803F1CE9D0AB7CF5F23AEFC3221", "hash_sha384": "6FA1B656C2C268AE158463DC87FA40F49A796311DE131F535545C6A45F1151885E305F3D38FFD4A80133283C74C3D02F", "hash_sha512": "E44F4C4A23FD6C57B155ED4D531EC83453A64D78D1FD03979F2D7C501156C620D598005B60E8DCBB5A42AD090BA6FB908ADBBAAD09B97A230A63FB663BB5AC90", "hash_ssdeep": "1536:vORfIKvHBDNrNIwv9DVSc+c3YWaq9xddR/:HKvHBDXIs1VSc+cZaq9xzR/", "hash_imp": "F4871A9C2C4D47CC68C3AE460CFDE7D8", "hash_pesha1": "18CE9A6C368A69AB91F20F84EFC6CA198598819F", "hash_pe256": "57A9EE24D97A64A7A77ACC490DA36DD6BCA339A404AE8ED0CF37EAEAE056BB8F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays the current open files list", "meta_original_filename": "opnfiles.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/8c8ead6b2fff2bece455b6b43be47ddd177b5803f1ce9d0ab7cf5f23aefc3221/detection", "error": "ERROR: The target system must be running a 32 bit OS.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\openfiles.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "OpenWith.exe-53E3F9F13C4C20B32CDA36FDEE865890": { "file_name": "OpenWith.exe", "file_path": "C:\\Windows\\SysWOW64\\OpenWith.exe", "hash_md5": "53E3F9F13C4C20B32CDA36FDEE865890", "hash_sha1": "2D00DE8557AC739E93E07B376FAD859AC7E15752", "hash_sha256": "3A796E0D682BD590B4C0AC50C8BCF80FADC6331FE83FBD6F2DE67148B4DA7005", "hash_sha384": "3A2BB748C9E185EE1FAD2959EDCC828FE2169D1D315983629C87A371DB95B4AA047AA1F938836705D46629CDD0DF487F", "hash_sha512": "DDBEC8B6BC4A2A1EA96DE2D5C983702DFA14ECB14ADCB31A2DD55338845DD1B1C9C4076B3FDA8BE9D38876502A50C845EA82BC9A8152AF73E7E15272B20AAC0F", "hash_ssdeep": "1536:gx2TCjRqyegzTJ8VcJQyAO50aimJ1JsaeQyrFumfKQTzBNer+CE+Ge+MgTq2lPxH:rTCjHPJQymaexs6rer+CE+G9lpH", "hash_imp": "753F8F3C01391963EA78BBF3E74B5A84", "hash_pesha1": "21FF10713EACCC10FDDF950D05D23246429639F4", "hash_pe256": "3F9DC14DBA11995D9B1F2F2A36B8B87F5CA7F0C2818AF92AABAB9A6620FE64EC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Pick an app", "meta_original_filename": "OpenWith.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3a796e0d682bd590b4c0ac50c8bcf80fadc6331fe83fbd6f2de67148b4da7005/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\OpenWith.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\SystemResources\\Windows.UI.Immersive.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\Windows.UI.Immersive.dll.mui": "File", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Windows\\SystemResources\\twinui.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\twinui.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "(RW-) C:\\Windows\\SysWOW64": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_32.db": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(RWD) C:\\Windows\\Fonts\\seguisb.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\OpenWith.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "OposHost.exe-6ED3E81C46DF70E54F1389DDF56B96D2": { "file_name": "OposHost.exe", "file_path": "C:\\Windows\\SysWOW64\\OposHost.exe", "hash_md5": "6ED3E81C46DF70E54F1389DDF56B96D2", "hash_sha1": "ABE52E52EEA480B0DBDDC51630793DCE66E7C48E", "hash_sha256": "ED1854856CBA22769623F6242683D493B179802BF9E7F0E931090EE9200C9E19", "hash_sha384": "3FAF9B7FA53EC9194CB6DD49DE39CED4FFA7DC7934FC590D6C642EE6602FB93B25726B31686D67D269D727BBA343BC00", "hash_sha512": "62C72D6447045314D2ED46CC11807D99D703B725F2A86B79D0ACA552E2A03985667322A760903EF98113FB1938DF54D84125E4B0E3A3C5026943CD894E0E0AEB", "hash_ssdeep": "768:761VLzOgculcZOvA+pGRxOJuUWPShVmSNA2nVrEXoQGdJ:76fzOScgvA+NuUlVDGoPd", "hash_imp": "98831A85A3877513610E651A30F984D2", "hash_pesha1": "8717313F6811D6E084D5DB3A661B502A629320AB", "hash_pe256": "DE8432A903E3E76815DCAA8491593ED6C7AABACC4A72027299784208107565D2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "OPOS Service Object Host", "meta_original_filename": "oposhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/ed1854856cba22769623f6242683d493b179802bf9e7f0e931090ee9200c9e19/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\OposHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "PackagedCWALauncher.exe-954A9FB06D2B80FE08D3576446788B42": { "file_name": "PackagedCWALauncher.exe", "file_path": "C:\\Windows\\SysWOW64\\PackagedCWALauncher.exe", "hash_md5": "954A9FB06D2B80FE08D3576446788B42", "hash_sha1": "AACF1098CF9BE6575E73839E7EAA46F62E71C94C", "hash_sha256": "22401DE528F379922A04D7B8ABEB5F4E895AA2064ADB700B28BFB4496C15002D", "hash_sha384": "58228FFBF8FCED0671979F7D6EDEA8EF8155A59CD3DE0D57C1B819BCB51D42E22BF34D8E92D54A26573102DEEA0AB4F6", "hash_sha512": "C502D1FA02DF084CF0AD62CADFA4D11F85B2E23DD50BD39E3B669CB2BEA0EE92F06B502808D284ED5109DC99412A08B45AEEFDCD43CD5B6F4333702E4AFAF23E", "hash_ssdeep": "384:1795j4XQaj/X+ZnwYW7amsHDUz9plbLjDkatf0pf8ALSsZbaa0iRTM+ieDj7BSsy:d9ASZwY9maOzJDJa7PjRTM+ZSnT", "hash_imp": "0D14A9F6A66B170ABCB7FCEBF02B0822", "hash_pesha1": "9677F4E6D7BDFAD4CC2A1180895A5597A661BA6F", "hash_pe256": "E9BC597EA3CC1105AED11054C4B844927C5855156AA54C222FE185C247C1AD2D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Packaged CWA Launcher", "meta_original_filename": "PackagedCWALauncher.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/22401de528f379922a04d7b8abeb5f4e895aa2064adb700b28bfb4496c15002d/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\PackagedCWALauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "PasswordOnWakeSettingFlyout.exe-9E9747DF3D5A7F1C095D23FDF5A874F8": { "file_name": "PasswordOnWakeSettingFlyout.exe", "file_path": "C:\\Windows\\SysWOW64\\PasswordOnWakeSettingFlyout.exe", "hash_md5": "9E9747DF3D5A7F1C095D23FDF5A874F8", "hash_sha1": "30761FDE12B8D7BC7376D2F6DF44EF8AF347E951", "hash_sha256": "23064784E45919E962E9FC7A532696856F061C0FB4A77D8923C50527ABA2E15E", "hash_sha384": "5A88F14741527427F1B63E3F6A1679B2421A55D0C7E991FF4E012FE63E08E3EBB1780AD5222456758DEAF86F40C11C85", "hash_sha512": "63FDA76B017ED595EDE569A47CAE9C28C425E7671205D675BDF2270A90A4ADDD9E8C85879B0397E26FB287B1C3D69FF9BDB6EC8B987353E065E6F8FF307826F0", "hash_ssdeep": "768:KGxhl0jA1Hcp1A16kcmlMZHxl3vbOOLAMogpI1PQ:Xxhl0VRkcZZRl3vbOOLAMo9PQ", "hash_imp": "33D63270D927C05E54560A274D4D4932", "hash_pesha1": "09B98B52D0C95735A9211ED459FF65695F8B1561", "hash_pe256": "2E10D2330FA13DE68755A6B3C130B6A74323599A21518651C440E9DD0765DDB2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "User CPL Password on wake setting flyout", "meta_original_filename": "PasswordOnWakeSettingFlyout.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/23064784e45919e962e9fc7a532696856f061c0fb4a77d8923c50527aba2e15e/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\PasswordOnWakeSettingFlyout.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "PATHPING.EXE-078AD26F906EF2AC1661FCAC84084256": { "file_name": "PATHPING.EXE", "file_path": "C:\\Windows\\SysWOW64\\PATHPING.EXE", "hash_md5": "078AD26F906EF2AC1661FCAC84084256", "hash_sha1": "6C43FC753A74290889C62D432035465D54D6A58E", "hash_sha256": "BB6753327AECDCC1E9C44E75BE44AE94FEDDDABEF038411D510D861A1527E79E", "hash_sha384": "145857C46DBFFD53BEB7D568FBF474CC643281A8B49D4FF85CE2A706017EE9302C16237BFEF4F5246482FBF17C7E9BE1", "hash_sha512": "790522172D90821529D0BDF2ACB5D2C5DE3F39A5299D8469C923709DBAF9A5056186919555C9B208BA5147E46B8E5CEA8B378146BBA803C46B116F442383B849", "hash_ssdeep": "384:P564Qut7wFP4RXWKZCraV/mlL8fzKWVAW:Pk/P4RvV+lL8V", "hash_imp": "ECB4C43808A5E78D58E2DCAEA3958691", "hash_pesha1": "3676F5C1BD9AE779945CD493C80FF96E62EA07EA", "hash_pe256": "F8DD333507B8D196E0DC7A9430324042153656B3DFDEF2DE9EFB14E3C3F420CB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP PathPing Command", "meta_original_filename": "pathping.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/bb6753327aecdcc1e9c44e75be44ae94fedddabef038411d510d861a1527e79e/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "output": "--help is not a valid command option.\r\n\r\nUsage: pathping [-g host-list] [-h maximum_hops] [-i address] [-n] \r\n [-p period] [-q num_queries] [-w timeout] \r\n [-4] [-6] target_name\r\n\r\nOptions:\r\n -g host-list Loose source route along host-list.\r\n -h maximum_hops Maximum number of hops to search for target.\r\n -i address Use the specified source address. \r\n -n Do not resolve addresses to hostnames.\r\n -p period Wait period milliseconds between pings.\r\n -q num_queries Number of queries per hop.\r\n -w timeout Wait timeout milliseconds for each reply.\r\n -4 Force using IPv4.\r\n -6 Force using IPv6.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\PATHPING.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "pcaui.exe-AAB5A69D537E380AC818B0F2A23F07C7": { "file_name": "pcaui.exe", "file_path": "C:\\Windows\\SysWOW64\\pcaui.exe", "hash_md5": "AAB5A69D537E380AC818B0F2A23F07C7", "hash_sha1": "5972B81346E1709BFA787328BC3CDE4BC4549AF9", "hash_sha256": "D05751968C1691E54724CF46BB14F09F904DA98896B4F95F24625F250433C5B7", "hash_sha384": "C6AEE84E7F5C12FC11482E7F69E91297FB2E9BF6667DA0182897BB341B7BEE8C63D7730C4AF4082B89E34F93599D7232", "hash_sha512": "241CCFA9518EB5B0D23CCBE16183C6ED20CD08EE7EB8B06826DC4AAEA419FCED470BB16E587300D251D49AE0E75A2F98B2F047DB9ED73D8EB27E2903C89EFACE", "hash_ssdeep": "3072:W9gTrPEV8wXIzTgYwB2AipiAiG68eXX1ytMbt2LU:A+9wziUG6z1rbELU", "hash_imp": "6A622289532880C5478586E66AF98EEC", "hash_pesha1": "6E716A0E1C072BE9BDCAA8E20AC8226907E2458D", "hash_pe256": "7CA1F11E9D7DEDD321BB9C4922AB74379287305FEB9FC62A74A69AA750F170CA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Program Compatibility Assistant User Interface", "meta_original_filename": "pcaui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d05751968c1691e54724cf46bb14f09f904da98896b4f95f24625f250433c5b7/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\pcaui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "perfhost.exe-2FC7CFCEDBF7E038351C7CEB1036D2E1": { "file_name": "perfhost.exe", "file_path": "C:\\Windows\\SysWOW64\\perfhost.exe", "hash_md5": "2FC7CFCEDBF7E038351C7CEB1036D2E1", "hash_sha1": "E826FDD69BDB47C8B13E4CD19CAD5F2AB0580400", "hash_sha256": "41D7DA706F0CF613DF768B6795CD09C5C1035F9F101051FB58F5042EB4352DB6", "hash_sha384": "16EE1E11FB45BBA1D02CED2604E5696DCAC529B94B537F018909A4BD8F5C89D25FF1FA8F4547BC0561186A394DF8C0EC", "hash_sha512": "1C8B2FD49BAEB1BCD106D1C4306B4A559A607F3CED62DCF814C1CEF218A31254F5112F52CBCA4EFC04265ED9C638D54A5D608F63532D5239AE65457B450BA353", "hash_ssdeep": "384:PabW9bWlzvC3qZKrntZL1Zp+lF6Wv0WV5Ftgh5D:CumWlnpOFj9kD", "hash_imp": "8D5844FD312E4B4DE80E5A985C8DF3AC", "hash_pesha1": "FF575B49C069F6C32F96A4BF40B7A62AEBBCBB09", "hash_pe256": "39F1BB1FD219E3316BE9DDCE53ECE93819CA00F3936730B21B62C6EA75625111", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "x86 Performance Counter Host", "meta_original_filename": "perfhost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/41d7da706f0cf613df768b6795cd09c5c1035f9f101051fb58f5042eb4352db6/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\perfhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "perfmon.exe-6284C86A1AE399794C18FBBC86CC8340": { "file_name": "perfmon.exe", "file_path": "C:\\Windows\\SysWOW64\\perfmon.exe", "hash_md5": "6284C86A1AE399794C18FBBC86CC8340", "hash_sha1": "06D3C338A1C30921DD8544F117F43497AD111E86", "hash_sha256": "3FA716B87491BDC9A01EC636F0010A028552D224EEC64334F7669206C69CFFF2", "hash_sha384": "F362E0489C49CF03F64FAE91156C18D219DF29374A65FC929C27D90816EC8CE4C91B45DA01C7758DB6583441D0EF7E4E", "hash_sha512": "822F9150CFB661897B61D97F15EE2B3B20D6100A5B3976E401176244C1AB63978ECCCEBE313DDBCA99E8F8E66A158026106340BEBA821060C38FA62966977AA1", "hash_ssdeep": "3072:gHuEgHwz/iUZPGghtYIo9piswTogiqQKy349e:gYHcKUZrhqIo9s37iTK24I", "hash_imp": "9E1163D7390EBC6170B5E1D9EE0421D0", "hash_pesha1": "A29B197DFA7D6F3CE7BACC8A7D60A90859552483", "hash_pe256": "0F1BD43D7E561CFFAFD3A41F9083D4EB3F9EE4B8647B20EDBA4D10A9D641F3DD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resource and Performance Monitor", "meta_original_filename": "perfmon.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.00", "meta_product_version": "10.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3fa716b87491bdc9a01ec636f0010a028552d224eec64334f7669206c69cfff2/detection", "output": "Argument '-help' is unknown.\r\n", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\perfmon.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\perfmon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Resource and Performance Monitor" }, "PickerHost.exe-E43A63632C72D52B9C17A0AD85BF2E65": { "file_name": "PickerHost.exe", "file_path": "C:\\Windows\\SysWOW64\\PickerHost.exe", "hash_md5": "E43A63632C72D52B9C17A0AD85BF2E65", "hash_sha1": "E8EA5666C04F3D9AD946CE0D8B19C78ED183F70A", "hash_sha256": "7D8F2DE2869889F41FE94FD9A4CCC1F67B971F9DB8F564E216B99B682E6C7241", "hash_sha384": "4ACB547C35CE08F9EB20DA3ECAB4037334FA088656F1D991FEFF8C278C216A5A8E6D03CDB9D262B3EA00EEFD412AFB3D", "hash_sha512": "D64AD3C2CDDB774F862DFDB093506F81F9409B3320D68B62B1DAFDC343D9F5B2053002205ACFC3D1DFD35E90A4153A0237E52609F3178315796CE4480BDE4FB8", "hash_ssdeep": "1536:O+HsU8OXmSD8h0ys52Vz+OZYO9P9a8d3DzSgrLq/0PR6NNphgoPtE:O+78emyWJs2x9ZYO9P9aYTzSgK/0PRUA", "hash_imp": "89065E850EBCA00D19512DDBB7206E2F", "hash_pesha1": "9B09DB887CA256FBE0B8B67398370DD17EF6FB0D", "hash_pe256": "721872C0E4798ACAAB1638F64B767EB9D817A624C9E2E61F736A1EF9FBB01F74", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Picker UI Host", "meta_original_filename": "PickerHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7d8f2de2869889f41fe94fd9a4ccc1f67b971f9db8f564e216b99b682e6c7241/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\PickerHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "PING.EXE-B3624DD758CCECF93A1226CEF252CA12": { "file_name": "PING.EXE", "file_path": "C:\\Windows\\SysWOW64\\PING.EXE", "hash_md5": "B3624DD758CCECF93A1226CEF252CA12", "hash_sha1": "FCF4DAD8C4AD101504B1BF47CBBDDBAC36B558A7", "hash_sha256": "4AAA74F294C15AEB37ADA8185D0DEAD58BD87276A01A814ABC0C4B40545BF2EF", "hash_sha384": "4A2C6917CB8EB958DED1BE985F2053B76E2A5AF6E4EEF75C577DD9700A7C63F28867743CF2B0CFA979E14C69FE859566", "hash_sha512": "C613D18511B00FA25FC7B1BDDE10D96DEBB42A99B5AAAB9E9826538D0E229085BB371F0197F6B1086C4F9C605F01E71287FFC5442F701A95D67C232A5F031838", "hash_ssdeep": "384:PVhNH/TqNcx+5tTAjtn3bPcPwoeGULZbiWBlWjVw:PVhZXx+5tTetLVohULZJgw", "hash_imp": "6C1FE20B3F9688A9263FFDF9FF417272", "hash_pesha1": "306AC6B860783CC69BF7915472BCB41FC9A08343", "hash_pe256": "18AC70758DE5A85B011FCE39F9D27143DA97F9F6DB94127510BF3417C299669B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Ping Command", "meta_original_filename": "ping.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4aaa74f294c15aeb37ada8185d0dead58bd87276a01a814abc0c4b40545bf2ef/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "output": "Bad option --help.\r\n\r\nUsage: ping [-t] [-a] [-n count] [-l size] [-f] [-i TTL] [-v TOS]\r\n [-r count] [-s count] [[-j host-list] | [-k host-list]]\r\n [-w timeout] [-R] [-S srcaddr] [-c compartment] [-p]\r\n [-4] [-6] target_name\r\n\r\nOptions:\r\n -t Ping the specified host until stopped.\r\n To see statistics and continue - type Control-Break;\r\n To stop - type Control-C.\r\n -a Resolve addresses to hostnames.\r\n -n count Number of echo requests to send.\r\n -l size Send buffer size.\r\n -f Set Don't Fragment flag in packet (IPv4-only).\r\n -i TTL Time To Live.\r\n -v TOS Type Of Service (IPv4-only. This setting has been deprecated\r\n and has no effect on the type of service field in the IP\r\n Header).\r\n -r count Record route for count hops (IPv4-only).\r\n -s count Timestamp for count hops (IPv4-only).\r\n -j host-list Loose source route along host-list (IPv4-only).\r\n -k host-list Strict source route along host-list (IPv4-only).\r\n -w timeout Timeout in milliseconds to wait for each reply.\r\n -R Use routing header to test reverse route also (IPv6-only).\r\n Per RFC 5095 the use of this routing header has been\r\n deprecated. Some systems may drop echo requests if\r\n this header is used.\r\n -S srcaddr Source address to use.\r\n -c compartment Routing compartment identifier.\r\n -p Ping a Hyper-V Network Virtualization provider address.\r\n -4 Force using IPv4.\r\n -6 Force using IPv6.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\PING.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "PkgMgr.exe-2F98A0859C8F75D8EEE78E0C8DB2F59F": { "file_name": "PkgMgr.exe", "file_path": "C:\\Windows\\SysWOW64\\PkgMgr.exe", "hash_md5": "2F98A0859C8F75D8EEE78E0C8DB2F59F", "hash_sha1": "9EA846D34523EDE2F4126C87895F3AE9983633DC", "hash_sha256": "CBF7C8A6F52735CA8C1118D65C1FE96A5345987F3B81726E2F8356E22AC5E088", "hash_sha384": "3804463005E52CAD36C4BA3409F303E030449032CE00219310BF15FECFA34924B1D7094625B0817B7BE6B4ECC37C9712", "hash_sha512": "9FC9EBC4F7E4E4C5CB100D1F82ADC4712FBD2EEF4F912D9BF84CCFF182F7DC625EE0938BE14D1F0BF1C04A45EAA39C8F58253AE8C1C267D5C1DF6FA49918331A", "hash_ssdeep": "3072:aC6RSlENnKKphw6s4RTQcWl444TKJ6eWIC5ou6IQN8QimaBo:aPSl8nRccMT41eWIyobIQN8", "hash_imp": "5DA81DD73892247EA00FA07D46307D16", "hash_pesha1": "5B69323E55431E7CDE63E62E112D505AD760DBB4", "hash_pe256": "E25B3F13635823EBD8BD4969A9B6446C9FB1CED314142EC42CE150860C9FBDCC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Package Manager", "meta_original_filename": "PkgMgr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/cbf7c8a6f52735ca8c1118d65c1fe96a5345987f3b81726e2f8356e22ac5e088/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\PkgMgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Package Manager" }, "poqexec.exe-FDEC1A07993B5A85F18F421963DD301D": { "file_name": "poqexec.exe", "file_path": "C:\\Windows\\SysWOW64\\poqexec.exe", "hash_md5": "FDEC1A07993B5A85F18F421963DD301D", "hash_sha1": "BD1D3E27DDF655F8D126983F221E8B0456CDCC6E", "hash_sha256": "431631601A6646D711632D93CFA768BD522F125320BD8BFADCB2D18B67A61303", "hash_sha384": "0812D00416F9CD9ED859F96C7F6B89100523575D20A25F03471730466078A5695E38C0907C0C3C27EE38A15D47B5D38B", "hash_sha512": "70E74727A49E31CC58347E56BC72F58673C29309A864E260B513DB925216F1DE660F864DC9167D284F5DC20622D280D651F17F38B276747F234D2E213CB08F45", "hash_ssdeep": "6144:0W5uKmK3eyy33PInY24RQHMt/N+MP7ikFvm1a9ZpHBufqnPCOjvCa4aOnUWkQokN:0W5feyy339WsJN+MP7ikc1c3BufqnPCz", "hash_imp": "49D7FAB9D4B1A98A8BD1BC23B4876852", "hash_pesha1": "CFC3003F6E60C56F871D3F768A92A30C92697B7F", "hash_pe256": "37A05C2C3D2BDB636E701AD7E4C6AD014760576C0D39D16D52D8B3133C91B461", "signature_status": 2, "signature_status_message": "The file C:\\Windows\\SysWOW64\\poqexec.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Primitive Operations Queue Executor", "meta_original_filename": "poqexec.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.680 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.680", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/431631601a6646d711632d93cfa768bd522f125320bd8bfadcb2d18b67a61303/detection" }, "powercfg.exe-9D71DBDD3AD017EC69554ACF9CAADD05": { "file_name": "powercfg.exe", "file_path": "C:\\Windows\\SysWOW64\\powercfg.exe", "hash_md5": "9D71DBDD3AD017EC69554ACF9CAADD05", "hash_sha1": "0989525DDA5F937A4895F2A53A4319FF16890B03", "hash_sha256": "7B48D1D9EB8ECC4E59F76CABAC1A9E009E5A39F0524FA8EEA29A3ACBC8CD32C1", "hash_sha384": "F103D13F06DE46E4E5CF64484E16D97EFD609E1F0230C889AA75FDC5F821AF2D8CE9F1123EECFA907DE4A16DF7D2FA06", "hash_sha512": "D145D011D8E344A650D4E60579BD0CE5D8BD33645342CA20F44D62013B6BDC4935F4E2E272D80410E17B3D2464D3C9B1E8FDA2A3657E0606F301CF24B945B1B3", "hash_ssdeep": "1536:shBwU9X3QNgjjy8uAQBc2vkgNszy+yfPildu/iaxczLMYe4/z0ls:wwUp3zOvAK5Ky9iQiaxULMYeCC", "hash_imp": "A4CAEF3F5A6B4DE55898C86E84355E40", "hash_pesha1": "D158196F06A6F9B9E4BDE3A544396E4792ED9F2A", "hash_pe256": "6888BA6E89D221CABD306F93AAE8725E879B6183F07ABA4B21319378175ED913", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Power Settings Command-Line Tool", "meta_original_filename": "PowerCfg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7b48d1d9eb8ecc4e59f76cabac1a9e009e5a39f0524fa8eea29a3acbc8cd32c1/detection", "output": "\r\nPOWERCFG /COMMAND [ARGUMENTS]\r\n\r\nDescription:\r\n Enables users to control power settings on a local system.\r\n\r\n For detailed command and option information, run \"POWERCFG /? <COMMAND>\"\r\n\r\nCommand List:\r\n /LIST, /L Lists all power schemes.\r\n\r\n /QUERY, /Q Displays the contents of a power scheme.\r\n\r\n /CHANGE, /X Modifies a setting value in the current power scheme.\r\n\r\n /CHANGENAME Modifies the name and description of a power scheme.\r\n\r\n /DUPLICATESCHEME Duplicates a power scheme.\r\n\r\n /DELETE, /D Deletes a power scheme.\r\n\r\n /DELETESETTING Deletes a power setting.\r\n\r\n /SETACTIVE, /S Makes a power scheme active on the system.\r\n\r\n /GETACTIVESCHEME Retrieves the currently active power scheme.\r\n\r\n /SETACVALUEINDEX Sets the value associated with a power setting\r\n while the system is powered by AC power.\r\n\r\n /SETDCVALUEINDEX Sets the value associated with a power setting\r\n while the system is powered by DC power.\r\n\r\n /IMPORT Imports all power settings from a file.\r\n\r\n /EXPORT Exports a power scheme to a file.\r\n\r\n /ALIASES Displays all aliases and their corresponding GUIDs.\r\n\r\n /GETSECURITYDESCRIPTOR\r\n Gets a security descriptor associated with a specified\r\n power setting, power scheme, or action.\r\n\r\n /SETSECURITYDESCRIPTOR\r\n Sets a security descriptor associated with a\r\n power setting, power scheme, or action.\r\n\r\n /HIBERNATE, /H Enables and disables the hibernate feature.\r\n\r\n /AVAILABLESLEEPSTATES, /A\r\n Reports the sleep states available on the system.\r\n\r\n /DEVICEQUERY Returns a list of devices that meet specified criteria.\r\n\r\n /DEVICEENABLEWAKE Enables a device to wake the system from a sleep state.\r\n\r\n /DEVICEDISABLEWAKE Disables a device from waking the system from a sleep\r\n state.\r\n\r\n /LASTWAKE Reports information about what woke the system from the\r\n last sleep transition.\r\n\r\n /WAKETIMERS Enumerates active wake timers.\r\n\r\n /REQUESTS Enumerates application and driver Power Requests.\r\n\r\n /REQUESTSOVERRIDE Sets a Power Request override for a particular Process,\r\n Service, or Driver.\r\n\r\n /SYSTEMSLEEPDIAGNOSTICS\r\n Generates a diagnostic report of system sleep transitions.\r\n\r\n /SYSTEMPOWERREPORT Generates a diagnostic system power transition report.\r\n\r\n /POWERTHROTTLING Control power throttling for an application.\r\n\r\n\r\n", "error": "Invalid Parameters -- try \"/?\" for help\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\powercfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "PresentationHost.exe-C6671F8B9F073785FD617661AD1F1C45": { "file_name": "PresentationHost.exe", "file_path": "C:\\Windows\\SysWOW64\\PresentationHost.exe", "hash_md5": "C6671F8B9F073785FD617661AD1F1C45", "hash_sha1": "DA141EC60E3CE6CC8A9CF60D13C4DEB6CB105B4A", "hash_sha256": "D9C533B6109160ABBF139D83C438806563E212D5C877192B64E4304806626C0A", "hash_sha384": "88AE0D8BA707375F80B836041B9E8C6F77AC01E5AAD33ED6DADD60D6259631ABFC7D460AB539DC74150F3EDE879E9469", "hash_sha512": "DC2D3A9E766F46DC5FC3296B2AC17642234BE1CC87EAA83EC7994C68915AF31CD5FE7CA7B561253EDAAE775E669E9D8AF926A0C20F3634037AF7A40257B09DBE", "hash_ssdeep": "6144:A0z2luCY78kez5KNXwy3Odjp19k5KNXf:AC2lu97ZQKVwy3OdLaKV", "hash_imp": "EAABF5736556491C472D1B684E7EB9A1", "hash_pesha1": "C8CE9AA7164D1A765B69E42A23A404BC295FCA21", "hash_pe256": "0BDC09FBCFA4F9A69B9C7575E35B13DAE940D01622186E873ABCDF2C541EBF44", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Presentation Foundation Host", "meta_original_filename": "PresentationHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d9c533b6109160abbf139d83c438806563e212d5c877192b64e4304806626c0a/detection", "children": "iexplore.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\PresentationHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "prevhost.exe-F6510F50CD47A9B324A6A1759265CFF1": { "file_name": "prevhost.exe", "file_path": "C:\\Windows\\SysWOW64\\prevhost.exe", "hash_md5": "F6510F50CD47A9B324A6A1759265CFF1", "hash_sha1": "78533509A2E269201ECAFB1808AB99C6871C0390", "hash_sha256": "BF39153D7EE708F5AAE0746EC64F813F9BD3C345394641D8651ABA8161C9C039", "hash_sha384": "709B58F188CDDCEF1351FA0BBD6282A8EDBDC2324FC43E77A997B85F9C1F1ADF92B6B75DFA96D37E5DBD75E86AB741EF", "hash_sha512": "B2D4F2A832B636997F2E72C0EAF4620D5CBF0C929095305DB4B62918E92E6EF90A5EC72DD7A3A7E4E25D14B1E39F540E1785A975E6D7D97BF5EC855674CDA145", "hash_ssdeep": "384:uZypIAkLlVlp+lfaTb16R//sOrQIwFxjxp6kmqt2J7ya+WFcWEV:cypIAk7pTC1rQIw7tzO7yal8", "hash_imp": "64AD0500B99B03083D39C3F6AFAF2C66", "hash_pesha1": "680E692DEDD316772C4844EBD874196084FFF78D", "hash_pe256": "A6E0EE5D129B7DABC3163896C21A98207CF91EB6376EDE1A1526EF52312C4706", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Preview Handler Surrogate Host", "meta_original_filename": "PREVHOST.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/bf39153d7ee708f5aae0746ec64f813f9bd3c345394641d8651aba8161c9c039/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\prevhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "print.exe-D23A0864F1F867B3098FD93463B62007": { "file_name": "print.exe", "file_path": "C:\\Windows\\SysWOW64\\print.exe", "hash_md5": "D23A0864F1F867B3098FD93463B62007", "hash_sha1": "E8B391A3B9FF13F5D87813706CC0584F027EA1F8", "hash_sha256": "76CD31A70770AF4FF2DB5F84F174D9740D2FE6603628BC07D6689E60EDFF5935", "hash_sha384": "F0C2ECA9646A66B0ED1320DB950E95551465B06906A266653D9DB5F3C7CA4B3DEE9BE43485CEE6DE8FB2DF33726B4BAF", "hash_sha512": "EBBF266B4F3E10C18B10922FCB392484539B40A7BA477CDD0B3A3DEAE2F40BA4FF579C1A7D9512C45964C18852134441C5B5EA05B4B0467606B43F3FB21A27E8", "hash_ssdeep": "192:gt/kI0F5av6J+mi9hRKvtalAbvBhKupoDQlibliQtMbe1AklWzUW:gt/BA5av8BrzKup5lmlnMklWzUW", "hash_imp": "EC8AF21EA60135BB82EBEBEAF1752064", "hash_pesha1": "A14481BB3CBB6916E1BE91EFE9BB883B6005E7C0", "hash_pe256": "A7B83177CF4516532D61145B66643593083C3899DD4F4708899B3795F1854909", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Print Utility", "meta_original_filename": "Print.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/76cd31a70770af4ff2db5f84f174d9740d2fe6603628bc07d6689e60edff5935/detection", "output": "Prints a text file.\r\n\r\nPRINT [/D:device] [[drive:][path]filename[...]]\r\n\r\n /D:device Specifies a print device.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\print.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "printui.exe-E73BC2E6C64861430CEA5D9C784BB6F7": { "file_name": "printui.exe", "file_path": "C:\\Windows\\SysWOW64\\printui.exe", "hash_md5": "E73BC2E6C64861430CEA5D9C784BB6F7", "hash_sha1": "B25AC4DC19EF1A37B0A554923B8ECB8421CB8689", "hash_sha256": "0CCF0351C0E4E9E422D014F349B75F0CF9710E241CDD40FD48C6BAB1E165FE66", "hash_sha384": "E0803D2C25C562DA51FBA4B09C5EDCD88DD4754EC3EB4FBB9E8EF41F56E2BA093671CF97CFEF7513D55FA46A42FB67DB", "hash_sha512": "101B8C3751BE3B22ACB285C75CAF7B8220C56EF8CF325A265E546B5465AA8F831F45DC059261F838694F2A8F037847456289605E1A6E62E1A4F0F6BEB7209B53", "hash_ssdeep": "768:FKgp+/G5vI1iQfCIWVM9G4qW4ne+S/ly+PKAoXRZX6fbX57UWkCRPPA7/Qnp:YVuVIPd4n+lbeRZIbSQPPA7s", "hash_imp": "6F4EF9E489C40856B4C2A7590D1E7B05", "hash_pesha1": "363B0ED78F47CA7B041B03F09B250DA79FD68E4C", "hash_pe256": "28477DE74D5A9A08C9A111D72AF011E621CCD9837F71944317CB495628FD4C74", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Printing Settings", "meta_original_filename": "printui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0ccf0351c0e4e9e422d014f349b75f0cf9710e241cdd40fd48c6bab1e165fe66/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\printui.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\printui.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\printui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Printers" }, "proquota.exe-224AA81092A51AE0080DEE1E454E11AD": { "file_name": "proquota.exe", "file_path": "C:\\Windows\\SysWOW64\\proquota.exe", "hash_md5": "224AA81092A51AE0080DEE1E454E11AD", "hash_sha1": "F66CE33A20A672D16C6ED7652C88E240A6F10231", "hash_sha256": "A5C199413A4800A0D5260AED37F0B923A52C9F1E69A584D153CBE04D58CE5600", "hash_sha384": "D867FBEF545781784BD32FC0F948AD57A87D19F069A5E53F8B9323896B3FBA442A3EC02D48D6BF483FB31A28C1FFB59B", "hash_sha512": "853AA99417D5A11692E5615320BA4EDCEADBA4FC037E2B480264F0BD15D7CF684AB34A282A8B57EAF80C15F33B77B65DFE2342972434A5687BCBB2E7EEFE7D4D", "hash_ssdeep": "768:p/MRrdWqSTk1jGKBLTyQWAWkBPQ3ba2W3TI1Hc6F:JMRrdEAJGQyQxBPt1TI1Hc", "hash_imp": "ECFCBB08CD09732932D8D88FAE38A065", "hash_pesha1": "30B3B7380BB4D355FDFB6F132C142F9EB8F521B3", "hash_pe256": "2BE12CB55A04A33DC1659524C8B4CE613AE6753A2A03445B76242D769A425B6A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ProQuota", "meta_original_filename": "proquota.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a5c199413a4800a0d5260aed37f0b923a52c9f1e69a584d153cbe04d58ce5600/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\proquota.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "provlaunch.exe-4F43F86CB657BCEA8CDFC4E242AD1C39": { "file_name": "provlaunch.exe", "file_path": "C:\\Windows\\SysWOW64\\provlaunch.exe", "hash_md5": "4F43F86CB657BCEA8CDFC4E242AD1C39", "hash_sha1": "C1F6EC1098B6DFB25235CAF2F0721C72B38011CC", "hash_sha256": "B602337A386A68AA4B7D1E3D863A158601CF0891C22ABF8B29427CAE87853F82", "hash_sha384": "3E058D5582995822C003D9D0E65E424F2760784DF3660DFE0D7FB878399A1924F0ABC3F0B942EDEF26B1020CD35B2967", "hash_sha512": "94787531E4D0A9FF5515A8EAB69CDEC0FE0A82733E032C2D73902C779C0D5C16C11CEC9E8902DC81DAF657A14578D224F553B7EF07CEB535D115572446702B5A", "hash_ssdeep": "768:2o1z8M3rpu+Ng2pWyEyu9NV1EfHGKhcJj3iPFpGr7Ri48Y6EoVapsvqM57PVThvE:B1z8KuuzhW9NV1QIJj3iKRi48Qoop81E", "hash_imp": "39FF8560269B45333304DEB510F143F9", "hash_pesha1": "A950AF4520D628B9DB6EDA9D98CF4334895D1152", "hash_pe256": "EEFABFB5B5A8B10BC760639D85807DEB68411B7A452AE2B0E9D7D4B44B02AB1B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Provisioning package runtime command launching tool", "meta_original_filename": "provlaunch", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b602337a386a68aa4b7d1e3d863a158601cf0891c22abf8b29427cae87853f82/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\provlaunch.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "psr.exe-3117B8F9AF28E7E720739A2C13F919C2": { "file_name": "psr.exe", "file_path": "C:\\Windows\\SysWOW64\\psr.exe", "hash_md5": "3117B8F9AF28E7E720739A2C13F919C2", "hash_sha1": "8B5D904B77B061B2100374D6B98DB276459352D3", "hash_sha256": "4092750B7E9792B6D6CC9D3599B2EBE40BC5D797E51A05985C3CDE4CE4095DC4", "hash_sha384": "A40D1D0EAF912DB55DC9E435CFC0EAE29A7C576048F5B49804BD5A4D60A90626C252E81A046B29BC6E8EA81763311541", "hash_sha512": "D85338EB07F7B6A3484EA5A283B3AD68B3B4CDE982054F23036EF832AA3588B7B49B37866B29F65168E5CA32E88D630AB166CF1E449F772A0FCA0715D05A609E", "hash_ssdeep": "3072:FWnjIUy51jrku1O/dUNVNv8NDKt93Bgk/3MlgLnBMO3034A20HvBrg7bsJt2:AnUUy51jr5O/6NVNv8e9zdFMOk34A3PQ", "hash_imp": "A4D09DAF661F529D8CFB9BB71F32E84E", "hash_pesha1": "99F48C90EB246FA10142A20840497C7C79BA2C94", "hash_pe256": "D1AD878987E071B64BFA089D8DB7FC4AAB31682CCFAA768F247680018BEEDDBA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Steps Recorder", "meta_original_filename": "psr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/4092750b7e9792b6d6cc9d3599b2ebe40bc5d797e51a05985c3cde4ce4095dc4/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_4299dbb28a92ae3e": "File", "(R-D) C:\\Windows\\System32\\en-US\\psr.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\psr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Steps Recorder Error" }, "quickassist.exe-F0F3390CF55DB6E7DA129BCE57EEE967": { "file_name": "quickassist.exe", "file_path": "C:\\Windows\\SysWOW64\\quickassist.exe", "hash_md5": "F0F3390CF55DB6E7DA129BCE57EEE967", "hash_sha1": "58E24C9C74FB0CF4C4FFBD20EE124979BFD8D9E9", "hash_sha256": "023155542B86DC9E1DEDAADC2FCA0F5DE90153C529508C25C63A7E3B3FBA958C", "hash_sha384": "D5F2E548ACCD7554D7EA5EB6017AC7A73C03E5497E94FD3BA93C741873BB38B07E42514776272BFCED94D769595D757A", "hash_sha512": "910D3D877B368D375D41A2C1657295D7A792DC6BC0BD3C0568A9BCC66C345D38C8F25B00A0AC13B10E8C23429DA58416567C8AF6CE0249A9E87CD77C686ABDF8", "hash_ssdeep": "6144:Fv8MWXWlPSrhGwtSD+UCytmwa8QprGDYjeB+NYXW:Fv8MWXWlqrRkDqsYrUIeBvX", "hash_imp": "298CE2E246AD0C8FF2AB8F20C2FEB4E0", "hash_pesha1": "11681024C6B9FF9F89F1EDAE2CDC761FAD5F6DE3", "hash_pe256": "54D841834757008C26DD0980E4CDD34CD2D6CFBC0250A4A949AFAB5BA20CD3B5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Quick Assist", "meta_original_filename": "QuickAssist.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/023155542b86dc9e1dedaadc2fca0f5de90153c529508c25c63a7e3b3fba958c/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_4299dbb28a92ae3e": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\quickassist.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\jscript9.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\ae4HWNDInterface:2e0420": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_ie_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\ieframe.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_webcache_counters_{9B6AB5B3-91BC-4097-835C-EA2DEC95E9CC}_S-1-5-21-2047949552-857980807-821054962-504": "Section", "\\BaseNamedObjects\\F932B6C7-3A20-46A0-B8A0-8894AA421973": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\Sessions\\1\\BaseNamedObjects\\ae4HWNDInterface:4902f2": "Section", "(R-D) C:\\Windows\\System32\\en-US\\mswsock.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "(RW-) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\INetCache\\ie\\AU189C9G\\IET0LU2J.htm": "File", "(RW-) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\INetCache\\ie\\AU189C9G\\DevCMDL2.1.62[1].eot": "File", "(R-D) C:\\Windows\\System32\\en-US\\mshtml.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\urlmon.dll.mui": "File", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RWD) C:\\Windows\\Fonts": "File", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(RW-) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\INetCache\\ie\\3X3M6V65\\MemMDL2.1.62[1].eot": "File", "(RW-) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\INetCache\\ie\\X4THQAJB\\StrgMDL2.1.58[1].eot": "File", "(RW-) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\INetCache\\ie\\3X3M6V65\\RemtMDL2[1].eot": "File", "\\Sessions\\1\\BaseNamedObjects\\MSIMGSIZECacheMap": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\quickassist.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Quick Assist" }, "rasautou.exe-DFDBEDC2ED47CBABC13CCC64E97868F3": { "file_name": "rasautou.exe", "file_path": "C:\\Windows\\SysWOW64\\rasautou.exe", "hash_md5": "DFDBEDC2ED47CBABC13CCC64E97868F3", "hash_sha1": "39972920EC8353749ADB37F185E691FD09AB6FDC", "hash_sha256": "51B2F4F5B5CFB55143113B3071BB62FECD4015BAAB59315CFFF5EA8BE4A4B3B4", "hash_sha384": "2CC7DD3E248CB18B9E8657BA584B0E8A124A51BEC2F84CC576C209EB8AC0A4045CB5038A93F002BD40676F375A2DABE6", "hash_sha512": "8063B28D6DF6CA9C58783E2CF65763140954371D1B6155398992DA5F7C44EC0033727BF80C28DFA2C539A7D3B3B8C40EBCF5A42C9F56F61DEFD017EEFE23F08D", "hash_ssdeep": "192:bqNL4VbTTSWOqEpitQ3xFey4zNq3jzoGoDY0FZOGZPWGTp+p43KWHBWn0:uNLfqElBFDPzoGGZOGZuct3KWHBW", "hash_imp": "6FD6CB5E209EBD24A870B74D8EE7F599", "hash_pesha1": "8170E7F325AF70ED3C7BD16BAE6B46563FCEB0B7", "hash_pe256": "3F4185EC0A074D00CF8C0AA70E75F783D48407E9E59F66327ED100C56A5281EC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Access Dialer", "meta_original_filename": "rasdlui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/51b2f4f5b5cfb55143113b3071bb62fecd4015baab59315cfff5ea8be4a4b3b4/detection", "output": "Usage: rasautou [-f phonebook] [-a address] [-e entry] [-s]\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\rasautou.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "rasdial.exe-799A2572818B770C12B9B02B89E38FEB": { "file_name": "rasdial.exe", "file_path": "C:\\Windows\\SysWOW64\\rasdial.exe", "hash_md5": "799A2572818B770C12B9B02B89E38FEB", "hash_sha1": "454C0132295D76E8FAF8EEA39B12CCC7D9B0921E", "hash_sha256": "56572B71F9E7E3151FAD06EE724A1CC11C6D56B27981AD2E6FEEF0A0D759F12C", "hash_sha384": "87A018ECD8816C763C7D77EC5DA16A570CEF5B5D323817CD1F54BE6CCC9E0B46D975FA1E9D28A682ADF106226F8BF194", "hash_sha512": "1A232FDE52F3654F84AF5D7410EC8C7165CB753A02795D4821C5AB092994ABDF7A39C05FD5E0582567D86BE388AC8AD7E23239D0748F853C541C79E1AEE476AE", "hash_ssdeep": "384:7Hp44TPy7bcf4Q0jAvsrkkEsQ7yzNmqWrVW:lXy5FQ2zNmn", "hash_imp": "5C49C69DC9F9E8B85CB908313C7FCFF4", "hash_pesha1": "2489BD88583E66447E7DF239C51F33BB55075896", "hash_pe256": "4252DEFC966BC8CC6BD681A95D863CC5684BB0DB5471E782387E8D00DD49F57C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Access Command Line Dial UI", "meta_original_filename": "RASDIAL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/56572b71f9e7e3151fad06ee724a1cc11c6d56b27981ad2e6feef0a0d759f12c/detection", "output": "USAGE:\n\tC:\\Windows\\SysWOW64\\rasdial.exe entryname [username [password|*]] [/DOMAIN:domain]\n\t\t[/PHONE:phonenumber] [/CALLBACK:callbacknumber]\n\t\t[/PHONEBOOK:phonebookfile] [/PREFIXSUFFIX]\n\n\tC:\\Windows\\SysWOW64\\rasdial.exe [entryname] /DISCONNECT\n\n\tC:\\Windows\\SysWOW64\\rasdial.exe\n\n\tPlease refer to our privacy statement at \n\t'https://go.microsoft.com/fwlink/?LinkId=521839'\n\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\rasdial.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "raserver.exe-8DAD4E018504D7CDB0BED56EAEBF1927": { "file_name": "raserver.exe", "file_path": "C:\\Windows\\SysWOW64\\raserver.exe", "hash_md5": "8DAD4E018504D7CDB0BED56EAEBF1927", "hash_sha1": "846A6D77DF67C5C35D608FD68982DCCDE7A40104", "hash_sha256": "51E1D2363C200C8CE80C4D225E623CB3E359A0D9053D4AEB5F48C96ADB227A9E", "hash_sha384": "41E1A635E4C5B1E46EB53CA364A6792F1011294D73F59D813454BD114DBF09CB702B17BC912F51D8B57BAE33AFBCCA19", "hash_sha512": "3450DF4809306B3D1A643BA8E0D4E1E596659A5241C7E70EFDF9E21E71CD5C83EA18F6BEA4D93FE9B72BAAAD416ABBAC53433FEE35DEC6FA9BB7933DB397078E", "hash_ssdeep": "3072:Kw+5zIHclD1vj87b+DxdrvxPx2ozoYpiTAP6kz4bw:/gIHEvub+RxzoYpiTi4bw", "hash_imp": "D9A8DD346C90B8B52A3053514EC1AF8A", "hash_pesha1": "4999AF4608B8F58857DA95A704D449087528D366", "hash_pe256": "1A1C49000F278DC181E0CA9ADB7920415878D5463277D27350922D76E860CC36", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Remote Assistance COM Server", "meta_original_filename": "raserver.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/51e1d2363c200c8ce80c4d225e623cb3e359a0d9053d4aeb5f48c96adb227a9e/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\raserver.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\raserver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "rasphone.exe-B5D49238841360E079DA1EC4627684EA": { "file_name": "rasphone.exe", "file_path": "C:\\Windows\\SysWOW64\\rasphone.exe", "hash_md5": "B5D49238841360E079DA1EC4627684EA", "hash_sha1": "A60512734B1ACCE3B944736B1CBA20F8643A3CAA", "hash_sha256": "081F631D598C327C2E9093D34FEFEE01BC571BECF0B3B3EAF1F6537FE18A945E", "hash_sha384": "B612DB62DDF9281F37BDCF69B707EF5D083DB952BC8D5787FE4BDBF84E297A7AF8CC549963F580DDAB4E4CA2F77E06F8", "hash_sha512": "114FDB64F5D40EDA4F80087E383FB677C0B741B2A213399DBE117F93F521F6891023CE67C711BCE15773E0CE1F36555564E19BB545805870B24EF3A4C630A2B2", "hash_ssdeep": "768:bHaFkPaBnW5+Fxt49Jv4YXr1gIg8qgLPNKRN:blPaJWAxgJ3W7NWPN", "hash_imp": "1CE24F8D171D420DCF77580404DF2579", "hash_pesha1": "AE8DFB067CA0DE6B6966AE2D2845B7621FD346EC", "hash_pe256": "6E880DA60AA389C4FB2212F12F5976F049AABCD0BA5EC178C1ABD1C382175DAF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Access Phonebook", "meta_original_filename": "rasphone.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/081f631d598c327c2e9093d34fefee01bc571becf0b3b3eaf1f6537fe18a945e/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\rasphone.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\rasphone.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Dial-Up Networking Command Line" }, "RdpSa.exe-44115DB687ADFACA18D50640913FE87F": { "file_name": "RdpSa.exe", "file_path": "C:\\Windows\\SysWOW64\\RdpSa.exe", "hash_md5": "44115DB687ADFACA18D50640913FE87F", "hash_sha1": "29A65983AB40C3993D986460969058247F5A24E4", "hash_sha256": "47B333F35B84F5A13563C74D6BDB0E59D21627757C4AC3458E3515CCC7B3DD59", "hash_sha384": "8C60841EB2D7496F233A447CB4B8D4F9995BB2782F204BF28D32B11840BE1D756CFC814F8011A2A9C37ED26AC24001D9", "hash_sha512": "CD458EA3C53D646CF881F87F0F765608AF9619ED891A2F5E2BD2808578C1EB33B69D669899AFCFD77D74D8071DC59C8DAD637759786D908F8D62847182D4FF2E", "hash_ssdeep": "768:6lU1oEkGtETVP006mrmn4ILt3EHViyatq6qQ4ZIs1o2k:6+13kGtETt007rmn4Iy1iA6QZIs1oF", "hash_imp": "4D86CE84E4EB6CE9E7C94F1E0F629BC5", "hash_pesha1": "E5BFA4F995F5BD7BDED4B1ED747585DA008BF5B2", "hash_pe256": "1418417A2CD9FF29A3EED59432918BF1C3D589BDBF17BAD256496CC4B38E13D8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Agent", "meta_original_filename": "RdpSa.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/47b333f35b84f5a13563c74d6bdb0e59d21627757c4ac3458e3515ccc7b3dd59/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\RdpSa.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\RdpSa.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RdpSaProxy.exe-682791CECDD63F33EC364013B20FA41A": { "file_name": "RdpSaProxy.exe", "file_path": "C:\\Windows\\SysWOW64\\RdpSaProxy.exe", "hash_md5": "682791CECDD63F33EC364013B20FA41A", "hash_sha1": "53ADDBD09640C64993E0782009E11FBA0BC605B5", "hash_sha256": "F8E6D42EAEE102B1880B173AC56C091E2962EA4B724F9DDE7F01A8F85357600F", "hash_sha384": "B5FB38741E8B697C636A223492569BADE4661A50962D643543D0B2BB9C8FB854F166B44968A85EDFCA038DDC019FD579", "hash_sha512": "5CA41EBEFC9C1EAACF17D270EC604C6AC38D0358EE806E49BAEF3541E8FC1C3CB47164797DD82CC3FF9E1DBCE58948A42C2F93E1D79FC563B5606D75255D932F", "hash_ssdeep": "768:52lUYIq1QbEFwwBQqOmhYrNeekZoHE50A:52+YT1Q4zQ8YrNCZoHE50", "hash_imp": "BC8DE7E35E1A808ABB6A378720A335F6", "hash_pesha1": "C38056D2B90423248048AAA7D2C8E1E929180919", "hash_pe256": "79BD2D835B81DF1DC64BD0D29BCF918B5D33BE943D0400607E30DAD9D2F342C0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Agent Proxy", "meta_original_filename": "RdpSaProxy.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f8e6d42eaee102b1880b173ac56c091e2962ea4b724f9dde7f01a8f85357600f/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\RdpSaProxy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RdpSaUacHelper.exe-C7A9C48024D18E6631CF2AAA787ED2A2": { "file_name": "RdpSaUacHelper.exe", "file_path": "C:\\Windows\\SysWOW64\\RdpSaUacHelper.exe", "hash_md5": "C7A9C48024D18E6631CF2AAA787ED2A2", "hash_sha1": "4F48164E97DB9C492AA07A4272C47A9B7D3FEE9E", "hash_sha256": "CFCA756BD7FC0101D4E942E11B080176594999B1C38628015A459C1DE695BBE9", "hash_sha384": "B18BEFD8A136A0F7B4526FD8F5047AE28EE4B7BD1D9336262873327E7BC87649572893B2C82FDB8CC43BE15BA8A4C808", "hash_sha512": "5094163B0CC016A0F2C528CDFC045BACD6AB4E59D00DBC96ADA3B5D0C1348EA0DAF5AB16181D97EA991DFF16961279E412515DD0F96184C463AB90AA8B71745E", "hash_ssdeep": "768:vqkWhWBPbF7QQWWKmk2sBEJU3Gc3kZuI3kw:yThcR7QQ5C3UtZuI3b", "hash_imp": "DD221B2D98625B12DEED17280C43D2C3", "hash_pesha1": "2392D1A14A2EF811D2A3A5D21508A212771CE703", "hash_pe256": "C5885124A8740AA9DDCAB7D8BAFCEB415435F106058A652D1F1A6D6C31B43549", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Agent UAC Helper", "meta_original_filename": "RdpSaUacHelper.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/cfca756bd7fc0101d4e942e11b080176594999b1c38628015a459c1de695bbe9/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\RdpSaUacHelper.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "rdrleakdiag.exe-38493CA013248385CA27A62062636ABA": { "file_name": "rdrleakdiag.exe", "file_path": "C:\\Windows\\SysWOW64\\rdrleakdiag.exe", "hash_md5": "38493CA013248385CA27A62062636ABA", "hash_sha1": "C0FB3D581A4716F31537058C9FBDF4A97AC1CB18", "hash_sha256": "420797C47485EDB779E4ADC7445F12CE4C16BA310BCC9562492798E58EBA3352", "hash_sha384": "049341B4E19659E6EAAF5963FED00E08887729F52E9F67D7F03233E97EF90A788FF2C4957EE64C5EA6F46231F83FD217", "hash_sha512": "67E8FBFEC6E8C3590223EC55F7D6EB8AD722350268383CF176D24E83C6B19CB929AE83359F9C67F8E5DC9F818AB3FD74590BD9094E8A6FAB3C8D0E1D2C11BD4B", "hash_ssdeep": "768:H1XbCjzgom/r0LoKeM93UycvBNRgkgOcT7+cwQ7txGEhsO/pIS6VNco2NU+/zF3r:Ke+cM15HsE56VNB+1J1", "hash_imp": "98FF00193ED1CAD8E5DA182FB187B5D1", "hash_pesha1": "7CDA9DE51CD377EC1B1E17EA26FACBF654810D95", "hash_pe256": "49A21120FDD9D561B353678D38CD97D7F3830F162A6F668E0C89A2BFD62F15AA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Resource Leak Diagnostic", "meta_original_filename": "RdrLeakDiag.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/420797c47485edb779e4adc7445f12ce4c16ba310bcc9562492798e58eba3352/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\rdrleakdiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ReAgentc.exe-C73CD2CAD0C74A17E53B0B72DAA1509E": { "file_name": "ReAgentc.exe", "file_path": "C:\\Windows\\SysWOW64\\ReAgentc.exe", "hash_md5": "C73CD2CAD0C74A17E53B0B72DAA1509E", "hash_sha1": "F39352192D6B901453DEEB50228DBDA9DB73C755", "hash_sha256": "82B0A8EA592C68CA1F913E716A82D2BBE32A5A34654A836C35B1E7ADC77C9342", "hash_sha384": "AF0DAB5384FE0F85DED93C34DB73119F1E194068D305E253E670F0F40FA5C71E0C561A46065AB0E068E49C6CE55629BC", "hash_sha512": "280ECE6860043B5FF41F9391F8BA7BABC2BFE120C6013652B92B374708AB5E09979FE285AB90B580E97223F8C9C205F654D4FA194684B12DDEC49A12578A6ACC", "hash_ssdeep": "384:VvPVU/lmhoszrCl/0FFtdC1xbXbvOL1sL2H1WHwVt6fEn1/kkgPotHj2YWb/2CwH:VvPVU/lm5RHiHfvxwrSvAZWKQPv+z", "hash_imp": "D49693811FAE10A24C0FF7B2BE2B6CB4", "hash_pesha1": "5815C3C02AD371D99D153157582BB4071FE5A83B", "hash_pe256": "87A5C337207B1A09311CB61D5766AFE8DB0F845FA608528E6FFDFAA102C89792", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Recovery Agent", "meta_original_filename": "reagentc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/82b0a8ea592c68ca1f913e716a82d2bbe32a5a34654a836c35b1e7adc77c9342/detection", "output": "\r\nConfigures the Windows Recovery Environment (Windows RE) and system reset.\r\n\r\nREAGENTC.EXE <command> <arguments>\r\n\r\nThe following commands can be specified:\r\n\r\n /info - Displays Windows RE and system reset configuration\r\n information.\r\n /setreimage - Sets the location of the custom Windows RE image.\r\n /enable - Enables Windows RE.\r\n /disable - Disables Windows RE.\r\n /boottore - Configures the system to start Windows RE next time the\r\n system starts up.\r\n /setbootshelllink - Adds an entry to the Reset and Restore page in the boot\r\n menu.\r\n\r\nFor more information about these commands and their arguments, type\r\nREAGENTC.EXE <command> /?.\r\n\r\n Examples:\r\n REAGENTC.EXE /setreimage /?\r\n REAGENTC.EXE /disable /?\r\n\r\nREAGENTC.EXE: Operation Successful.\r\n \r\n", "error": "\r\nConfigures the Windows Recovery Environment (Windows RE) and system reset.\r\n\r\nREAGENTC.EXE <command> <arguments>\r\n\r\nThe following commands can be specified:\r\n\r\n /info - Displays Windows RE and system reset configuration\r\n information.\r\n /setreimage - Sets the location of the custom Windows RE image.\r\n /enable - Enables Windows RE.\r\n /disable - Disables Windows RE.\r\n /boottore - Configures the system to start Windows RE next time the\r\n system starts up.\r\n /setbootshelllink - Adds an entry to the Reset and Restore page in the boot\r\n menu.\r\n\r\nFor more information about these commands and their arguments, type\r\nREAGENTC.EXE <command> /?.\r\n\r\n Examples:\r\n REAGENTC.EXE /setreimage /?\r\n REAGENTC.EXE /disable /?\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ReAgentc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "recover.exe-D38B657A068016768CA9F3B5E100B472": { "file_name": "recover.exe", "file_path": "C:\\Windows\\SysWOW64\\recover.exe", "hash_md5": "D38B657A068016768CA9F3B5E100B472", "hash_sha1": "BEE11FDB9806B1527C46DF2F374B1716E13ACA20", "hash_sha256": "D971D5F962E2188A429DE6AC6DD6FBA3FA97199CDC1A8182E753069AEC2FB93E", "hash_sha384": "558A877D466D9D0B6BBD45AD9E797801DAD3456E2E5525A943274F7CE0E543C85CABF72D149A380081A00FF5D2B32FE5", "hash_sha512": "3128B173A47CFF9F53F904ADC757D4340D574847B5F7E9997CACA88C003244BFE17FE8412A52EEFD5791CFC797FCF3482CCEAB923FBFE6A34E276A4279A1F3C5", "hash_ssdeep": "192:gfmv5WKYs/pCjwY19qpXD9tAYq7xk2jWEnWyaAb4V:1v5gCpWwi9qp3AnS2jWEnWHAkV", "hash_imp": "CD8185705936323067B6715FDC1BF798", "hash_pesha1": "7CDCD3D937E9D39A4B202630AA2E169C29460064", "hash_pe256": "38FB1E2B6DFF01CAD1D949F553923B1F4BEF5C97C5E7CD4A1FD2B318BA43C0C0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Recover Files Utility", "meta_original_filename": "Recover.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d971d5f962e2188a429de6ac6dd6fba3fa97199cdc1a8182e753069aec2fb93e/detection", "output": "Recovers readable information from a bad or defective disk.\r\n\r\nRECOVER [drive:][path]filename\r\nConsult the online Command Reference in Windows Help\r\nbefore using the RECOVER command.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\recover.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "reg.exe-CDD462E86EC0F20DE2A1D781928B1B0C": { "file_name": "reg.exe", "file_path": "C:\\Windows\\SysWOW64\\reg.exe", "hash_md5": "CDD462E86EC0F20DE2A1D781928B1B0C", "hash_sha1": "F24D851FE8024CE9804DA6B540C588BC38A5BFAF", "hash_sha256": "224A746AEE2957C3FCA376F4457CFC044C1EC99E75756195B27CAB396174E2DB", "hash_sha384": "91A6AED40B22DD7C4962F2D55306049BA5E4858805E75234D0271E99067105221B2D34240BB57D741910F2D38E12D5FA", "hash_sha512": "8F3A63615FCC9F3EEA9EA2EF59E9CA33843159C0A3C7A259B84527DEBD6D464D54F531FFB61F0EE33065154B72CD6618594EB812E70C20C4F86997E70DD0AEEC", "hash_ssdeep": "1536:iBaTn8qdb7N71axmEYSSUFKOGbBm5nvoKwwDABXYSv2DaZ:ya7bR71axmBSJwOzvoxwDABXtv2u", "hash_imp": "869B9FF91668F96EF68FBE0DB3602587", "hash_pesha1": "2CE4670E3C1296DD56EA1639645328E053129B20", "hash_pe256": "2B996D2C98755F4EEE0B66935773C0BA98F64591BC7B6568DDE0D653EDDB80D8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Console Tool", "meta_original_filename": "reg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/224a746aee2957c3fca376f4457cfc044c1ec99e75756195b27cab396174e2db/detection", "output": "\r\nREG Operation [Parameter List]\r\r\n\r\r\n Operation [ QUERY | ADD | DELETE | COPY |\r\r\n SAVE | LOAD | UNLOAD | RESTORE |\r\r\n COMPARE | EXPORT | IMPORT | FLAGS ]\r\r\n\r\r\nReturn Code: (Except for REG COMPARE)\r\r\n\r\r\n 0 - Successful\r\r\n 1 - Failed\r\r\n\r\r\nFor help on a specific operation type:\r\r\n\r\r\n REG Operation /?\r\r\n\r\r\nExamples:\r\r\n\r\r\n REG QUERY /?\r\r\n REG ADD /?\r\r\n REG DELETE /?\r\r\n REG COPY /?\r\r\n REG SAVE /?\r\r\n REG RESTORE /?\r\r\n REG LOAD /?\r\r\n REG UNLOAD /?\r\r\n REG COMPARE /?\r\r\n REG EXPORT /?\r\r\n REG IMPORT /?\r\r\n REG FLAGS /?\r\r\n", "error": "ERROR: Invalid Argument/Option - '--help'.\r\nType \"REG /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\reg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "regedit.exe-08D8384279EB3E25242B270860193E1C": { "file_name": "regedit.exe", "file_path": "C:\\Windows\\SysWOW64\\regedit.exe", "hash_md5": "08D8384279EB3E25242B270860193E1C", "hash_sha1": "95A9C5AEE9B5211B93520B3CD965F2D20274DD9E", "hash_sha256": "92E81342732CCE1EEFC16629B4587E8C4338AE6B180018CFB870E51C64BBC203", "hash_sha384": "DBDA116D279EC1159A8F9200D607655D646619600B92DB18A8783F0D636C1629E57A5596FA8D81AE511C803463155BEC", "hash_sha512": "46AB72443B84A11D080895794988C42CB58D08D5B1DD030385B88DED0CE308A635A1E7E73CBFBCFCB54B4242C9DCDFFC62FFAC115A6BD18CD1E46D6E36F78078", "hash_ssdeep": "6144:R8e8Pp1u42+2LFd2KBiPQRZ66z+n4VZbd8g79pgrXNgRnVLjyzhbkidNN2:R8VPpS+aoKKQRZ66z24VZbdrpgrXN2LS", "hash_imp": "C6E1B8202ADED47B7C2380A87886D20C", "hash_pesha1": "840DCFBACF94AB99D434413433B157D335248F4C", "hash_pe256": "95686AFEF070818389C68A481593A910FC5420CF09E717C70CC547254645907C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Editor", "meta_original_filename": "REGEDIT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/92e81342732cce1eefc16629b4587e8c4338ae6b180018cfb870e51c64bbc203/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\regedit.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\aclui.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "Registry Editor", "runtime_modules": [ "C:\\Windows\\SysWOW64\\regedit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "regedt32.exe-49E9EA6F79338B350A8B23CEA47D1A86": { "file_name": "regedt32.exe", "file_path": "C:\\Windows\\SysWOW64\\regedt32.exe", "hash_md5": "49E9EA6F79338B350A8B23CEA47D1A86", "hash_sha1": "B51311EEE2A58FDF80CD55616B5A15291A5EE951", "hash_sha256": "B9A0659A5F8173629C2CC702F9D786F699BE2C1C1BD10EE354494DF75C618954", "hash_sha384": "0B7D872C1AE2C053CECCB83BEA2A393105F573E60C5FD8BF6397627A2511151A91A474B7BE855FB09D66B6DA0244002B", "hash_sha512": "A6F473794315E9A38C3D08F1777BA14D0DE3F98F560E8DB120F96ED6FB6EF2A14568F444783AE2520F958E872223A8D4CFAEB98718089E3BC5A3DA35539C85E0", "hash_ssdeep": "96:cT/8zwOtfZOWkcTLEp2TyIRoJIP3DGjsl3tTZFovnzeDJFMVWVEWlZhHWwB:cT8zwqrTaGRoTeTZFovnz0MWbxWG", "hash_imp": "FA8607DE86B3096660A35E6483D8EACA", "hash_pesha1": "0306A05C48621FA8AD80B1364AF9DCB540733308", "hash_pe256": "7F31C7F1219A508D4BF5EFEC627F58BC47EC0FF8DDB13003666F0A52C46E48A5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Editor Utility", "meta_original_filename": "regedt32.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b9a0659a5f8173629c2cc702f9d786f699be2c1c1bd10ee354494df75c618954/detection", "children": "regedit.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\regedt32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "regini.exe-C99C3BB423097FCF4990539FC1ED60E3": { "file_name": "regini.exe", "file_path": "C:\\Windows\\SysWOW64\\regini.exe", "hash_md5": "C99C3BB423097FCF4990539FC1ED60E3", "hash_sha1": "E31AB48D15AC4C70F591D75D7A43EE20DD3C2C9B", "hash_sha256": "04D137F3F2873A75FAB8D71D54E79B5792D047854B7B7501CC9D4E2B231D1CB1", "hash_sha384": "916B98A4DA2914EB58988545CE78099E40F42A86942F0069C9F1D5F437478162E9701A3E07610CA40F5C66A4E0088A0F", "hash_sha512": "DACAE80E98FEB789E0E09D763E047CCB1C54F3187059C6F5D0F4CDD433FE9D2E96C2E947327121111D1925A5740E25397C761F1AFD25FFB11AE8D34658A58BCC", "hash_ssdeep": "768:YyvGV2EIgkhyilxWRhBDjMQx40tEt9WCADa1urxFE5L+ax9GFtLNI:H5EiADjb69WCAZF8x9GFJNI", "hash_imp": "5356BCBDA656EB8E0846EEAF52BE48B1", "hash_pesha1": "5FEFDB3ABEF3275E9822DCDFD25F247DC6482547", "hash_pe256": "79A8B27B8391A75F5F002160693DEE90F6DE1CD084533B2346241E95B863E04C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Initializer", "meta_original_filename": "REGINI.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/04d137f3f2873a75fab8d71d54e79b5792d047854b7b7501cc9d4e2b231d1cb1/detection", "error": "usage: REGINI [-m \\\\machinename | -h hivefile hiveroot]\r\n [-i n] [-o outputWidth]\r\n [-b] textFiles...\r\n\r\nwhere: -m specifies a remote Windows NT machine whose registry is to be manipulated.\r\n -h specifies a specify local hive to manipulate.\r\n -i n specifies the display indentation multiple. Default is 4\r\n -o outputWidth specifies how wide the output is to be. By default the\r\n outputWidth is set to the width of the console window if standard\r\n output has not been redirected to a file. In the latter case, an\r\n outputWidth of 240 is used.\r\n\r\n -b specifies that REGINI should be backward compatible with older\r\n versions of REGINI that did not strictly enforce line continuations\r\n and quoted strings Specifically, REG_BINARY, REG_RESOURCE_LIST and\r\n REG_RESOURCE_REQUIREMENTS_LIST data types did not need line\r\n continuations after the first number that gave the size of the data.\r\n It just kept looking on following lines until it found enough data\r\n values to equal the data length or hit invalid input. Quoted\r\n strings were only allowed in REG_MULTI_SZ. They could not be\r\n specified around key or value names, or around values for REG_SZ or\r\n REG_EXPAND_SZ Finally, the old REGINI did not support the semicolon\r\n as an end of line comment character.\r\n \r\n textFiles is one or more ANSI or Unicode text files with registry data.\r\n \r\n Some general rules are:\r\n Semicolon character is an end-of-line comment character, provided it\r\n is the first non-blank character on a line\r\n \r\n Backslash character is a line continuation character. All\r\n characters from the backslash up to but not including the first\r\n non-blank character of the next line are ignored. If there is more\r\n than one space before the line continuation character, it is\r\n replaced by a single space.\r\n \r\n Indentation is used to indicate the tree structure of registry keys\r\n The REGDMP program uses indentation in multiples of 4. You may use\r\n hard tab characters for indentation, but embedded hard tab\r\n characters are converted to a single space regardless of their\r\n position\r\n \r\n Values should come before child keys, as they are associated with\r\n the previous key at or above the value's indentation level.\r\n \r\n For key names, leading and trailing space characters are ignored and\r\n not included in the key name, unless the key name is surrounded by\r\n quotes. Imbedded spaces are part of a key name.\r\n \r\n Key names can be followed by an Access Control List (ACL) which is a\r\n series of decimal numbers, separated by spaces, bracketed by a\r\n square brackets (e.g. [8 4 17]). The valid numbers and their\r\n meanings are:\r\n \r\n 1 - Administrators Full Access\r\n 2 - Administrators Read Access\r\n 3 - Administrators Read and Write Access\r\n 4 - Administrators Read, Write and Delete Access\r\n 5 - Creator Full Access\r\n 6 - Creator Read and Write Access\r\n 7 - World Full Access\r\n 8 - World Read Access\r\n 9 - World Read and Write Access\r\n 10 - World Read, Write and Delete Access\r\n 11 - Power Users Full Access\r\n 12 - Power Users Read and Write Access\r\n 13 - Power Users Read, Write and Delete Access\r\n 14 - System Operators Full Access\r\n 15 - System Operators Read and Write Access\r\n 16 - System Operators Read, Write and Delete Access\r\n 17 - System Full Access\r\n 18 - System Read and Write Access\r\n 19 - System Read Access\r\n 20 - Administrators Read, Write and Execute Access\r\n 21 - Interactive User Full Access\r\n 22 - Interactive User Read and Write Access\r\n 23 - Interactive User Read, Write and Delete Access\r\n \r\n If there is an equal sign on the same line as a left square bracket\r\n then the equal sign takes precedence, and the line is treated as a\r\n registry value. If the text between the square brackets is the\r\n string DELETE with no spaces, then REGINI will delete the key and\r\n any values and keys under it.\r\n \r\n For registry values, the syntax is:\r\n \r\n value Name = type data\r\n \r\n Leading spaces, spaces on either side of the equal sign and spaces\r\n between the type keyword and data are ignored, unless the value name\r\n is surrounded by quotes. If the text to the right of the equal sign\r\n is the string DELETE, then REGINI will delete the value.\r\n \r\n The value name may be left off or be specified by an at-sign\r\n character which is the same thing, namely the empty value name. So\r\n the following two lines are identical:\r\n \r\n = type data\r\n @ = type data\r\n \r\n This syntax means that you can't create a value with leading or\r\n trailing spaces, an equal sign or an at-sign in the value name,\r\n unless you put the name in quotes.\r\n \r\n Valid value types and format of data that follows are:\r\n \r\n REG_SZ text\r\n REG_EXPAND_SZ text\r\n REG_MULTI_SZ \"string1\" \"str\"\"ing2\" ...\r\n REG_DATE mm/dd/yyyy HH:MM DayOfWeek\r\n REG_DWORD numberDWORD\r\n REG_BINARY numberOfBytes numberDWORD(s)...\r\n REG_NONE (same format as REG_BINARY)\r\n REG_RESOURCE_LIST (same format as REG_BINARY)\r\n REG_RESOURCE_REQUIREMENTS (same format as REG_BINARY)\r\n REG_RESOURCE_REQUIREMENTS_LIST (same format as REG_BINARY)\r\n REG_FULL_RESOURCE_DESCRIPTOR (same format as REG_BINARY)\r\n REG_QWORD numberQWORD\r\n REG_MULTISZ_FILE fileName\r\n REG_BINARYFILE fileName\r\n \r\n If no value type is specified, default is REG_SZ\r\n \r\n For REG_SZ and REG_EXPAND_SZ, if you want leading or trailing spaces\r\n in the value text, surround the text with quotes. The value text\r\n can contain any number of imbedded quotes, and REGINI will ignore\r\n them, as it only looks at the first and last character for quote\r\n characters.\r\n \r\n For REG_MULTI_SZ, each component string is surrounded by quotes. If\r\n you want an imbedded quote character, then double quote it, as in\r\n string2 above.\r\n \r\n For REG_BINARY, the value data consists of one or more numbers The\r\n default base for numbers is decimal. Hexidecimal may be specified\r\n by using 0x prefix. The first number is the number of data bytes,\r\n excluding the first number. After the first number must come enough\r\n numbers to fill the value. Each number represents one DWORD or 4\r\n bytes. So if the first number was 0x5 you would need two more\r\n numbers after that to fill the 5 bytes. The high order 3 bytes\r\n of the second DWORD would be ignored.\r\n \r\n Whenever specifying a registry path, either on the command line\r\n or in an input file, the following prefix strings can be used:\r\n \r\n HKEY_LOCAL_MACHINE\r\n HKEY_USERS\r\n HKEY_CURRENT_USER\r\n USER:\r\n \r\n Each of these strings can stand alone as the key name or be followed\r\n a backslash and a subkey path.\r\n\r\n\r\nREGINI: Missing parameter(s) for -h switch\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\regini.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Register-CimProvider.exe-E9DE41F9FF6FF386EDB11B15717D3E56": { "file_name": "Register-CimProvider.exe", "file_path": "C:\\Windows\\SysWOW64\\Register-CimProvider.exe", "hash_md5": "E9DE41F9FF6FF386EDB11B15717D3E56", "hash_sha1": "1B85E53521F7D6361CF5FF124AB8F3A6138F2815", "hash_sha256": "7946DD01FD7A3C2B9F33ECEDF6CE04F04D6F494830900338F4469DE6464CAA0E", "hash_sha384": "1F7984D97E1E59F2BE71C9C99A0BA7D637FB3776A0529C46859B0B949FD3DBE9156A46E42877CBCA3C1236A01394A3A8", "hash_sha512": "8700C2C48507559D963123688A78C4B8368BCAD073F5F4676E440C745C4519215F8DFDC084B712591E573814DE53108963DE4D3CB709B5DA6A2A9CED7234B6E3", "hash_ssdeep": "384:m4HBsKmxpfjX564NvHWrEnN2LfQGOzzrkgMcCsenu4K7xIWK1Wk:mMlUt5XzYLfQGOykenu48x4x", "hash_imp": "E38114F7B41F83A6809D0A3C49C82EEE", "hash_pesha1": "A6C76DBCBF033FACE529324532B9D98957087009", "hash_pe256": "46A51311E90FA0BD3B23932F48360FB557931764BB10E483DFA255942C21FA3B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI", "meta_original_filename": "Register-CimProvider2.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7946dd01fd7a3c2b9f33ecedf6ce04f04d6f494830900338f4469de6464caa0e/detection", "output": "\r\nRegisters CIM Provider into system\r\n\r\nUsage: Register-CimProvider.exe\r\n\t\t-Namespace <NamespaceName>\r\n\t\t-ProviderName <ProviderName>\r\n\t\t-Path <ProviderDllPath>\r\n\t\t[-ClassList <Space delimited list of white-listed classes>]\r\n\t\t[-Impersonation <True or False>]\r\n\t\t[-Decoupled <SDDL>]\r\n\t\t[-HostingModel <HostingModel>]\r\n\t\t[-Localize <locale>]\r\n\t\t[-NoAutorecover]\r\n\t\t[-SupportWQL]\r\n\t\t[-GenerateUnregistration]\r\n\t\t[-ForceUpdate]\r\n\t\t[-Verbose]\r\n\r\n-Namespace <NamespaceName>\r\n\tSpecifies the target namespace of the provider.\r\n\r\n-ProviderName <ProviderName>\r\n\tSpecifies the provider name.\r\n\r\n-Path <ProviderDllPath>\r\n\tSpecifies the provider binary path.\r\n\r\n-Impersonation <True or False>\r\n\tSpecifies foldidentity of decoupled provider, by default is True.\r\n\r\n-Decoupled <SDDL>\r\n\tRegisters provider as decoupled and specifies the security descriptor\r\n\tthat determines the set of users that can successfully register\r\n\tthe provider.\r\n\r\n-HostingModel <HostingModel>\r\n\tSpecifies the HostingModel of coupled provider.\r\n\r\n-Localize <locale>\r\n\tLocalizes the provider with resource of specified locale.\r\n\r\n-NoAutorecover\r\n\tDoesn't autorecover the provider.\r\n\r\n-SupportWQL\r\n\tPasses the query expression to the filter.\r\n\r\n-GenerateUnregistration\r\n\tGenerate the uninstall mof for the registration,\r\n\twhich is disabled by default.\r\n\r\n-ForceUpdate\r\n\tForce update the class if it exists in the system.\r\n\r\n-ClassList <ProviderDllPath>\r\n\tSpecifies space delimited list of white-listed classes that\r\n\twill be generated in the mof.\r\n\r\n-Verbose\r\n\tOutputs registration log.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Register-CimProvider.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "regsvr32.exe-878E47C8656E53AE8A8A21E927C6F7E0": { "file_name": "regsvr32.exe", "file_path": "C:\\Windows\\SysWOW64\\regsvr32.exe", "hash_md5": "878E47C8656E53AE8A8A21E927C6F7E0", "hash_sha1": "CB377E2BA78E131D7A1887C58C073E23D003454F", "hash_sha256": "31AEE70F9705F6578C6B41849EA3B5A948A446F494F24BEFCF5B169A1C2A71D2", "hash_sha384": "82321E0910F69105992E4C997D8F1FD13292716757B1C60F2EBF3C89F2BAD20B16EDB227AD31DCF1C20BD1F149AE1E85", "hash_sha512": "DF5B43E3E539E61312938D779D4876E8A966685CF7086EB4427D3179309C0C04B2BE49A4B7FBD8AEEE830EA70E89828D66928680EC2876CCEA3BA5386A3B45C2", "hash_ssdeep": "384:K7qvDNxVs+Hl1ivs7LDGpcB4EkEskgXQl7YxA2WrcLHW+0:NvBzLXQ7X47YdL", "hash_imp": "99BBF1337F3DA5CFAB67854DF4ADE1D8", "hash_pesha1": "C55613BEA90E98E626582A948596B1021FDAA3EE", "hash_pe256": "F462EBC38A69219FDED4175E28578D4FF0476EE1E1B61EC8EA410CA5485C2331", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft(C) Register Server", "meta_original_filename": "REGSVR32.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/31aee70f9705f6578c6b41849ea3b5a948a446f494f24befcf5b169a1c2a71d2/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\regsvr32.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\regsvr32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "RegSvr32" }, "rekeywiz.exe-C0B0EB11C9B90C4B99D067AF64726344": { "file_name": "rekeywiz.exe", "file_path": "C:\\Windows\\SysWOW64\\rekeywiz.exe", "hash_md5": "C0B0EB11C9B90C4B99D067AF64726344", "hash_sha1": "FC23C6A268B9C07547719BB011EEA886C5713FAA", "hash_sha256": "1FD493E3FDED8E64F7C9B50EAB2E2062441728F4D3AEA8CA9FDC654C493794FF", "hash_sha384": "D89F39292B6AF6A9F9BEEB776D587D211285D7CD19B1B84618C956F05CBAE885E2D7A3C9DCC93FE5EC32346AD72FFC31", "hash_sha512": "FF179CB0936C16F591DA0F448C42CAABDBDA5F366944D7A4321DF2BB7B4956314CDB7D66100964C8C4380A0F1481D5F8803ED5102271E6ACCD775BEBAF14737E", "hash_ssdeep": "3072:fLvkQJ83UspFxd80BbZnXM27uP27ucBOitbBbP5QtvRBdh:jJJOTz2tvRBd", "hash_imp": "E267EC5FE7CB82D11E7C8F3E2763D776", "hash_pesha1": "BABDD64C39DF228C899CEA0D11B7809B546278A3", "hash_pe256": "7A21F5DE654D737D11AE5FF76F03E4A4614391F8FB83AE3CFED625E646499D10", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EFS REKEY wizard", "meta_original_filename": "rekeywiz.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/1fd493e3fded8e64f7c9b50eab2e2062441728f4d3aea8ca9fdc654c493794ff/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\rekeywiz.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\efsadu.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\rekeywiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Encrypting File System" }, "relog.exe-B5BD958DCD88565CC17E9330032F99CE": { "file_name": "relog.exe", "file_path": "C:\\Windows\\SysWOW64\\relog.exe", "hash_md5": "B5BD958DCD88565CC17E9330032F99CE", "hash_sha1": "86F8CC31C4996C7D1DACB060870E48733429CE68", "hash_sha256": "2030C6509CEE45E3629A9B47D09BD421B83F48F356ED597A03C89306610D720C", "hash_sha384": "6B687DF91A56B8C2AA6AB9D0B834E2FB9F2F9B64CF78234D15C3C34E98D8F85776849FC558BF4C3EA42905DBED695672", "hash_sha512": "55804FA3AABCDAF14628633D855A5113C6E26A027F45709E1AF8F8D91942125C923BD47C7C7082D4B6FDDF92981EC510890965518E382022753D209FA95DEB7E", "hash_ssdeep": "768:/zsVR22awTzqvJneZ/HI7vUjO9ZNvv/2rEaQLo6Ec22C2ieU0i:/zsVFdYJIQDv9raEqc2AieU0i", "hash_imp": "6224A72BD9E47088A3D467560173CDC1", "hash_pesha1": "5C2CF5F72F680F735599ED3A768694841EE58C8D", "hash_pe256": "2A169A626C8275D6ADC5DF9176A4F50B7F67A1EB6C13D98DBDE3406539C4E02B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Performance Relogging Utility", "meta_original_filename": "Relog.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2030c6509cee45e3629a9b47d09bd421b83f48f356ed597a03c89306610d720c/detection", "output": "\r\nMicrosoft r Relog.exe (10.0.19041.546)\r\n\r\nRelog creates new performance logs from data in existing performance logs by\r\nchanging the sampling rate and/or converting the file format. Supports all\r\nperformance log formats, including Windows NT 4.0 compressed logs.\r\n\r\nUsage:\r\nC:\\Windows\\SysWOW64\\relog.exe <filename [filename ...]> \r\n [options]\r\n\r\nParameters:\r\n <filename [filename ...]> Performance file to relog.\r\n\nOptions:\r\n -? Displays context sensitive help.\r\n -a Append output to the existing binary file.\r\n -c <path [path ...]> Counters to filter from the input log.\r\n -cf <filename> File listing performance counters to filter\r\n from the input log. Default is all counters\r\n in the original log file.\r\n -f <CSV|TSV|BIN|SQL> Output file format.\r\n -t <value> Only write every nth record into the output\r\n file. Default is to write every record.\r\n -o Output file path or SQL database.\r\n -b <M/d/yyyy h:mm:ss[AM|PM]> Begin time for the first record to write into\r\n the output file.\r\n -e <M/d/yyyy h:mm:ss[AM|PM]> End time for the last record to write into\r\n the output file.\r\n -config <filename> Settings file containing command options.\r\n -q List performance counters in the input file.\r\n -y Answer yes to all questions without prompting.\r\n\r\nExamples:\r\n relog logfile.csv -c \"\\Processor(_Total)\\% Processor Time\" -o logfile.blg\r\n relog logfile.blg -cf counters.txt -f bin\r\n relog logfile.blg -f csv -o logfile.csv -t 2\r\n relog logfile.blg -q -o counters.txt\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\relog.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "replace.exe-82B9440BF8D788460BE2FDD73C324659": { "file_name": "replace.exe", "file_path": "C:\\Windows\\SysWOW64\\replace.exe", "hash_md5": "82B9440BF8D788460BE2FDD73C324659", "hash_sha1": "FA64006A32B2E87B8A3B5029CE6A50C30950F73F", "hash_sha256": "855693AF7C72BC38B1F0ABCBA6686E1FE6A9D731D0B0A8BD5208149626D3F782", "hash_sha384": "1AC410C0593CAE63F397C4CB3B0D9A4D35205DB236B4757EC7A2FD194DC9C0F48F9FC59E9C52423D56E17FDF4C0865E2", "hash_sha512": "A913D727AC15AEC4F8541060709BC7CE806A17B7B2646FFA9A658CDB3137F0B9608F8F9B9769CFE48A98FCF81DD8C34D63D36D936FEBD01188742A391E5F15E1", "hash_ssdeep": "384:iqLur18nXyQO123rqXmkNo2K8tW2h/W4:iqLux8XyQO1IrREb", "hash_imp": "C4BFBBAC6078657DEBCDC17AF465AECD", "hash_pesha1": "C4C79AE7586145287E9C201E179D3896359B4EB3", "hash_pe256": "3D84EC48E5523BCFA0EEB912BD120EE287966FA6A7E5FB591681F9C124398D1D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Replace File Utility", "meta_original_filename": "REPLACE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/855693af7c72bc38b1f0abcba6686e1fe6a9d731d0b0a8bd5208149626d3f782/detection", "output": "Replaces files.\r\n\r\nREPLACE [drive1:][path1]filename [drive2:][path2] [/A] [/P] [/R] [/W]\r\nREPLACE [drive1:][path1]filename [drive2:][path2] [/P] [/R] [/S] [/W] [/U]\r\n\r\n [drive1:][path1]filename Specifies the source file or files.\r\n [drive2:][path2] Specifies the directory where files are to be\r\n replaced.\r\n /A Adds new files to destination directory. Cannot\r\n use with /S or /U switches.\r\n /P Prompts for confirmation before replacing a file or\r\n adding a source file.\r\n /R Replaces read-only files as well as unprotected\r\n files.\r\n /S Replaces files in all subdirectories of the\r\n destination directory. Cannot use with the /A\r\n switch.\r\n /W Waits for you to insert a disk before beginning.\r\n /U Replaces (updates) only files that are older than\r\n source files. Cannot use with the /A switch.\r\n", "error": "Invalid switch - --help\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\replace.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "resmon.exe-29C52C15D2D68A4BBE9A36701D31100E": { "file_name": "resmon.exe", "file_path": "C:\\Windows\\SysWOW64\\resmon.exe", "hash_md5": "29C52C15D2D68A4BBE9A36701D31100E", "hash_sha1": "6F0ECAC4D0DF233C7F20FF660A672E8C8D594232", "hash_sha256": "F3707C1D638F5487D1EF0A72173356023307DC6734DC738944C75F127FBCFD54", "hash_sha384": "AC6BD6FDB6469C78E75B9975C54B238D570C91C9982713AD350386B08226367E7AF0913056112B5A240587D4A84EA36A", "hash_sha512": "30E967CB19BE23D8595BFD0C86E3DCA888C118DA5957C8B7FE6C4DA693C69FBA1ACD5C63D296C974A55C3C76059799CFE2910737C8FBE1E8EC62D0E429A39EAE", "hash_ssdeep": "1536:L/YKBqY3KtrtizIo9plJSs9kYuZJnGZLzOcE6Ls7HXG84PK05Z34g/CO+sH:LgKghtYIo9piswTogiqQKy349", "hash_imp": "86521711CB1F214E18EA188295368818", "hash_pesha1": "4EF285A05A9C310BAA34DC3EAC3EBCE2FC268F58", "hash_pe256": "6FF84E0FC3C416CE5ECDBE50B53EE084528B169A5C1BD4F63825C5AF7378A220", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resource Monitor", "meta_original_filename": "resmon.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f3707c1d638f5487d1ef0a72173356023307dc6734dc738944c75f127fbcfd54/detection", "children": "perfmon.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\resmon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RMActivate.exe-C3BDA80F17FFA78BD5FF9DFB91BF65B7": { "file_name": "RMActivate.exe", "file_path": "C:\\Windows\\SysWOW64\\RMActivate.exe", "hash_md5": "C3BDA80F17FFA78BD5FF9DFB91BF65B7", "hash_sha1": "DEF8B8521D92542D872317C4A4EA5978E0F14448", "hash_sha256": "62E94CB99BD3207951211B8566BCAADF19BE925090404BD7AA0191BFC83FD08F", "hash_sha384": "CA2173D54CC485C36AE25C9D39CE37A25E96B923F7C25F68F140C68A4AA862F6854C82FBD609A74A0920048713C804D9", "hash_sha512": "33C59880DA6CDAA2E03A2D2F37558D1F47498895144F67CE76BB2CC43B4DBDE42160A8AD06C4FFB0582EAECBA2603F1FD838EF3E3649D61B5AAA0D509CA341A0", "hash_ssdeep": "12288:1fOj2FGKc4zSZpD1nswafC/+KGidvQPxUQ4e1kVg6TeGaB:12jOSZpDVswIC/+KGiyP34e1kK6KxB", "hash_imp": "EBCDFF4FE394A3E0CD90455A8A72EF29", "hash_pesha1": "7EC72FBD49280CACF340D0D41F5911A54A928919", "hash_pe256": "BAA0FB225012C2DC0BD57C4F04A7F21237774550945E3C8EE55CCEB3CC8825E1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Desktop Security Processor", "meta_original_filename": "rmactivate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/62e94cb99bd3207951211b8566bcaadf19be925090404bd7aa0191bfc83fd08f/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\RMActivate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RMActivate_isv.exe-F5DB05C308AE5103CFDD47105BAE8D1B": { "file_name": "RMActivate_isv.exe", "file_path": "C:\\Windows\\SysWOW64\\RMActivate_isv.exe", "hash_md5": "F5DB05C308AE5103CFDD47105BAE8D1B", "hash_sha1": "97BC04CF01C7DC7F4BA6DBDC4D246FD93E725C87", "hash_sha256": "2A2CA139764FD9449F547DA29BE38B660C1E89BDF5B56AD01055B122A12D9C73", "hash_sha384": "CADCF2130B322953FADD3DE10925B609B3A70CC9660357117A70CBFCD1A88B744FB3D4D2D37A86089460BE13253FD738", "hash_sha512": "C5247DD593128BA4D8B1CDC50107CF7FF52B478C49BF02E0B7035693238AFB8E8161680F66D84CFA18E73757FD53979E3B4241F2248D33273F06AADF0D485AD9", "hash_ssdeep": "12288:xGV+9pjWE/122veQS3LpJHur1Glh4GLQfIBo+HJ8LH838YAVgX4wHkDkm4NgOSt:IV+9pjb24ubpJHurglGGLQfIB7HJ8/Ye", "hash_imp": "EBCDFF4FE394A3E0CD90455A8A72EF29", "hash_pesha1": "A66CE4F1C3730D63EEDEEC3CB997691153A04B2E", "hash_pe256": "75740371F81FA5AA05C2281D002402832E9AE5D3BAE8C25456A4B18A3174A268", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Desktop Security Processor", "meta_original_filename": "rmactivate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2a2ca139764fd9449f547da29be38b660c1e89bdf5b56ad01055b122a12d9c73/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\RMActivate_isv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RMActivate_ssp.exe-081B5546353E81C7006F990C54B9D8B4": { "file_name": "RMActivate_ssp.exe", "file_path": "C:\\Windows\\SysWOW64\\RMActivate_ssp.exe", "hash_md5": "081B5546353E81C7006F990C54B9D8B4", "hash_sha1": "24AB10199A453D534AFCBC57A31B345586048081", "hash_sha256": "C7A5368A48A063B991E9B4EFFE43635ED7725B2DCC18B4AAD431577414D13AA4", "hash_sha384": "D90E593B389AB72C2A6173E26828B8ADA7F814CC24ED1188DA6F1D4CD30172C985C9587CC0340FB86ABAE2C321CC81A1", "hash_sha512": "FC15E2DD5C97CE37C45C4896A23E4817C4671E445F8835C58444F733F5CA91D66D4FAF66AE3C12EFD8D62665625291AF7CE28318B9AB5A0E7445440C1A8B04CA", "hash_ssdeep": "12288:9x5qySytLiYFAJDc22WP/z0/Z8/eUYmibY+4:9WSLiYFED0WPI/a/eUYmibY+4", "hash_imp": "7E5FF848353E2487D8DE47C6573CC310", "hash_pesha1": "CCDD5729E924C63D95FED94627B4AE35749ED404", "hash_pe256": "66E659756BA5037B79CB1B0E09FF065DECC09EF3B3E34255645AF3D2B5EC97D2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Server Security Processor", "meta_original_filename": "rmactivate_ssp.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "1/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c7a5368a48a063b991e9b4effe43635ed7725b2dcc18b4aad431577414d13aa4/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\RMActivate_ssp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RMActivate_ssp_isv.exe-E7516E154D7AEE0ECD4BF892C3BC33C2": { "file_name": "RMActivate_ssp_isv.exe", "file_path": "C:\\Windows\\SysWOW64\\RMActivate_ssp_isv.exe", "hash_md5": "E7516E154D7AEE0ECD4BF892C3BC33C2", "hash_sha1": "EC4670AE5179B98AAA50B14547018C7E06937735", "hash_sha256": "7D50EA6005CD3FD81B4D238081401FB6B248C0F5C7F815537D28A096FF5154A8", "hash_sha384": "1DAF9F889CD9BD376BBD387448223E62FA3CBEF6646BE7C0A6CD2380F9C11659E67BB5DBFA6997F30E6A7946E159B689", "hash_sha512": "11DFF5C0C2C3BAC389AC84457E4A09B0DFECF897BE666AF92661DD58D10409145C2167C95A60BF5FC696A236A0080D8565FD48FA3950D43837E78B69E9323D1F", "hash_ssdeep": "12288:Tv7hJziWrwrITXbIegTQAAiLYMAYmWjAZcRyLP9IzlesL:b1JziUaIbbxfADLVaWjAZeA9KpL", "hash_imp": "7E5FF848353E2487D8DE47C6573CC310", "hash_pesha1": "D00D0F3A5970E0DFD3F715C2FB3073C421683B8C", "hash_pe256": "E6BF88C7F81D46F8CD480DFDF80D21EB6EB72C185ADBEEE1157E784B7B6C5142", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Server Security Processor (Pre-production)", "meta_original_filename": "rmactivate_ssp_isv.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7d50ea6005cd3fd81b4d238081401fb6b248c0f5c7f815537d28a096ff5154a8/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\RMActivate_ssp_isv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RmClient.exe-CE765DCC7CDFDC1BFD94CCB772C75E41": { "file_name": "RmClient.exe", "file_path": "C:\\Windows\\SysWOW64\\RmClient.exe", "hash_md5": "CE765DCC7CDFDC1BFD94CCB772C75E41", "hash_sha1": "D960EC36D098774F5365517A8EB8DE410778609F", "hash_sha256": "B115961EA25EC6960C7BA788F5C206B1E604748FB26C5EB443FBCA02497AB743", "hash_sha384": "49E40E6F4B584ED2977A3245F67D9E531C6C0521CB987EE8C938079F78CD98C9FEBEA440BFA75037E25AC8ED43D19CA2", "hash_sha512": "6A86AF695F0756EE84BF2EA4B096DE4F77144A00AA38E649F0B65442EEDE75D6037B0D0AE06A8085FAF4624F7E1645D4DAED458689BA993892D274C238802250", "hash_ssdeep": "192:EhCEJCaRmbOufN9dyQdYwmzfrKbzBQHMH1TkHWozW5Bs7HpU:sJjmbFNHyQdYwm+BQsCHWozWfj", "hash_imp": "515D13B7AD9E8958E42761434A172217", "hash_pesha1": "89EA58E3D192F6812AF0DEC1C9B96DBE06688CD0", "hash_pe256": "532A0D0E13B2E0BB647958BCFF7D79136CEC0E592AD757B24F356409E47E09D9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Restart Manager LUA Restart Client", "meta_original_filename": "RmClient.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b115961ea25ec6960c7ba788f5c206b1e604748fb26c5eb443fbca02497ab743/detection", "output": "\r\n RmClient.exe pipename\r\n\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\RmClient.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Robocopy.exe-8B21EDAA13B0C6A413A610F9F64CAA29": { "file_name": "Robocopy.exe", "file_path": "C:\\Windows\\SysWOW64\\Robocopy.exe", "hash_md5": "8B21EDAA13B0C6A413A610F9F64CAA29", "hash_sha1": "F8BCAD682AE567D6DD7F6C3A53BC00C7A629F096", "hash_sha256": "D7A46FC5AF4DC3978F395DD601619111899D206C22AABDAC77C10EFE6A8425A9", "hash_sha384": "4DD98103A16449ADC9E2896A50C7AF60DCCE36CD5F894A30111F861FF139BE47B7473EF23319F1A77D6521C1A553A1B7", "hash_sha512": "789E7DBF1356479638400F84381D527216CDCBF686214DE107F415F9DA03FEA59322A9CD82AB52527F39232B114ACAC292037735A56D95F196A559A50595D513", "hash_ssdeep": "3072:KvpGEuRH3T+yMmVFKIVDU0SA7E9uhzFFWMYFqjx6pkpGCs9nvIp:8p7uFKyMmrA9uhOgxFpGa", "hash_imp": "CE8C66960DF71D94348CEDEE0368DDE9", "hash_pesha1": "45C7CEFB263A1924DC28560C5A67850230CE5AD4", "hash_pe256": "8DBC0DE35E07420F2A517B8D778E4604603F63522704955983BB4DB07A927192", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Robocopy", "meta_original_filename": "robocopy.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d7a46fc5af4dc3978f395dd601619111899d206c22aabdac77c10efe6a8425a9/detection", "output": "\r\n-------------------------------------------------------------------------------\r\n ROBOCOPY :: Robust File Copy for Windows \r\n-------------------------------------------------------------------------------\r\n\r\n Started : Saturday, December 12, 2020 11:09:52 PM\r\n Usage :: ROBOCOPY source destination [file [file]...] [options]\r\n\r\n source :: Source Directory (drive:\\path or \\\\server\\share\\path).\r\n destination :: Destination Dir (drive:\\path or \\\\server\\share\\path).\r\n file :: File(s) to copy (names/wildcards: default is \"*.*\").\r\n\r\n::\r\n:: Copy options :\r\n::\r\n /S :: copy Subdirectories, but not empty ones.\r\n /E :: copy subdirectories, including Empty ones.\r\n /LEV:n :: only copy the top n LEVels of the source directory tree.\r\n\r\n /Z :: copy files in restartable mode.\r\n /B :: copy files in Backup mode.\r\n /ZB :: use restartable mode; if access denied use Backup mode.\r\n /J :: copy using unbuffered I/O (recommended for large files).\r\n /EFSRAW :: copy all encrypted files in EFS RAW mode.\r\n\r\n /COPY:copyflag[s] :: what to COPY for files (default is /COPY:DAT).\r\n (copyflags : D=Data, A=Attributes, T=Timestamps, X=Skip alt data streams).\r\n (S=Security=NTFS ACLs, O=Owner info, U=aUditing info).\r\n\r\n \r\n /SEC :: copy files with SECurity (equivalent to /COPY:DATS).\r\n /COPYALL :: COPY ALL file info (equivalent to /COPY:DATSOU).\r\n /NOCOPY :: COPY NO file info (useful with /PURGE).\r\n /SECFIX :: FIX file SECurity on all files, even skipped files.\r\n /TIMFIX :: FIX file TIMes on all files, even skipped files.\r\n\r\n /PURGE :: delete dest files/dirs that no longer exist in source.\r\n /MIR :: MIRror a directory tree (equivalent to /E plus /PURGE).\r\n\r\n /MOV :: MOVe files (delete from source after copying).\r\n /MOVE :: MOVE files AND dirs (delete from source after copying).\r\n\r\n /A+:[RASHCNET] :: add the given Attributes to copied files.\r\n /A-:[RASHCNET] :: remove the given Attributes from copied files.\r\n\r\n /CREATE :: CREATE directory tree and zero-length files only.\r\n /FAT :: create destination files using 8.3 FAT file names only.\r\n /256 :: turn off very long path (> 256 characters) support.\r\n\r\n /MON:n :: MONitor source; run again when more than n changes seen.\r\n /MOT:m :: MOnitor source; run again in m minutes Time, if changed.\r\n\r\n /RH:hhmm-hhmm :: Run Hours - times when new copies may be started.\r\n /PF :: check run hours on a Per File (not per pass) basis.\r\n\r\n /IPG:n :: Inter-Packet Gap (ms), to free bandwidth on slow lines.\r\n\r\n /SJ :: copy Junctions as junctions instead of as the junction targets.\r\n /SL :: copy Symbolic Links as links instead of as the link targets.\r\n\r\n /MT[:n] :: Do multi-threaded copies with n threads (default 8).\r\n n must be at least 1 and not greater than 128.\r\n This option is incompatible with the /IPG and /EFSRAW options.\r\n Redirect output using /LOG option for better performance.\r\n\r\n /DCOPY:copyflag[s] :: what to COPY for directories (default is /DCOPY:DA).\r\n (copyflags : D=Data, A=Attributes, T=Timestamps, E=EAs, X=Skip alt data streams).\r\n\r\n /NODCOPY :: COPY NO directory info (by default /DCOPY:DA is done).\r\n\r\n /NOOFFLOAD :: copy files without using the Windows Copy Offload mechanism.\r\n\r\n /COMPRESS :: Request network compression during file transfer, if applicable.\r\n\r\n::\r\n:: File Selection Options :\r\n::\r\n /A :: copy only files with the Archive attribute set.\r\n /M :: copy only files with the Archive attribute and reset it.\r\n /IA:[RASHCNETO] :: Include only files with any of the given Attributes set.\r\n /XA:[RASHCNETO] :: eXclude files with any of the given Attributes set.\r\n\r\n /XF file [file]... :: eXclude Files matching given names/paths/wildcards.\r\n /XD dirs [dirs]... :: eXclude Directories matching given names/paths.\r\n\r\n /XC :: eXclude Changed files.\r\n /XN :: eXclude Newer files.\r\n /XO :: eXclude Older files.\r\n /XX :: eXclude eXtra files and directories.\r\n /XL :: eXclude Lonely files and directories.\r\n /IS :: Include Same files.\r\n /IT :: Include Tweaked files.\r\n\r\n /MAX:n :: MAXimum file size - exclude files bigger than n bytes.\r\n /MIN:n :: MINimum file size - exclude files smaller than n bytes.\r\n\r\n /MAXAGE:n :: MAXimum file AGE - exclude files older than n days/date.\r\n /MINAGE:n :: MINimum file AGE - exclude files newer than n days/date.\r\n /MAXLAD:n :: MAXimum Last Access Date - exclude files unused since n.\r\n /MINLAD:n :: MINimum Last Access Date - exclude files used since n.\r\n (If n < 1900 then n = n days, else n = YYYYMMDD date).\r\n\r\n /FFT :: assume FAT File Times (2-second granularity).\r\n /DST :: compensate for one-hour DST time differences.\r\n\r\n /XJ :: eXclude symbolic links (for both files and directories) and Junction points.\r\n /XJD :: eXclude symbolic links for Directories and Junction points.\r\n /XJF :: eXclude symbolic links for Files.\r\n\r\n /IM :: Include Modified files (differing change times).\r\n::\r\n:: Retry Options :\r\n::\r\n /R:n :: number of Retries on failed copies: default 1 million.\r\n /W:n :: Wait time between retries: default is 30 seconds.\r\n\r\n /REG :: Save /R:n and /W:n in the Registry as default settings.\r\n\r\n /TBD :: Wait for sharenames To Be Defined (retry error 67).\r\n\r\n /LFSM :: Operate in low free space mode, enabling copy pause and resume (see Remarks).\r\n\r\n /LFSM:n[KMG] :: /LFSM, specifying the floor size in n [K:kilo,M:mega,G:giga] bytes.\r\n\r\n::\r\n:: Logging Options :\r\n::\r\n /L :: List only - don't copy, timestamp or delete any files.\r\n /X :: report all eXtra files, not just those selected.\r\n /V :: produce Verbose output, showing skipped files.\r\n /TS :: include source file Time Stamps in the output.\r\n /FP :: include Full Pathname of files in the output.\r\n /BYTES :: Print sizes as bytes.\r\n\r\n /NS :: No Size - don't log file sizes.\r\n /NC :: No Class - don't log file classes.\r\n /NFL :: No File List - don't log file names.\r\n /NDL :: No Directory List - don't log directory names.\r\n\r\n /NP :: No Progress - don't display percentage copied.\r\n /ETA :: show Estimated Time of Arrival of copied files.\r\n\r\n /LOG:file :: output status to LOG file (overwrite existing log).\r\n /LOG+:file :: output status to LOG file (append to existing log).\r\n\r\n /UNILOG:file :: output status to LOG file as UNICODE (overwrite existing log).\r\n /UNILOG+:file :: output status to LOG file as UNICODE (append to existing log).\r\n\r\n /TEE :: output to console window, as well as the log file.\r\n\r\n /NJH :: No Job Header.\r\n /NJS :: No Job Summary.\r\n\r\n /UNICODE :: output status as UNICODE.\r\n\r\n::\r\n:: Job Options :\r\n::\r\n /JOB:jobname :: take parameters from the named JOB file.\r\n /SAVE:jobname :: SAVE parameters to the named job file\r\n /QUIT :: QUIT after processing command line (to view parameters). \r\n /NOSD :: NO Source Directory is specified.\r\n /NODD :: NO Destination Directory is specified.\r\n /IF :: Include the following Files.\r\n\r\n::\r\n:: Remarks :\r\n::\r\n Using /PURGE or /MIR on the root directory of the volume formerly caused \r\n robocopy to apply the requested operation on files inside the System \r\n Volume Information directory as well. This is no longer the case; if \r\n either is specified, robocopy will skip any files or directories with that \r\n name in the top-level source and destination directories of the copy session.\r\n\r\n The modified files classification applies only when both source \r\n and destination filesystems support change timestamps (e.g., NTFS) \r\n and the source and destination files have different change times but are \r\n otherwise the same. These files are not copied by default; specify /IM \r\n to include them.\r\n\r\n The /DCOPY:E flag requests that extended attribute copying should be \r\n attempted for directories. Note that currently robocopy will continue \r\n if a directory's EAs could not be copied. This flag is also not included \r\n in /COPYALL.\r\n\r\n Using /LFSM requests robocopy to operate in 'low free space mode'. \r\n In that mode, robocopy will pause whenever a file copy would cause the \r\n destination volume's free space to go below a 'floor' value, which \r\n can be explicitly specified by the LFSM:n[KMG] form of the flag. \r\n If /LFSM is specified with no explicit floor value, the floor is set to \r\n ten percent of the destination volume's size. \r\n Low free space mode is incompatible with /MT, /EFSRAW, /B, and /ZB.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Robocopy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ROUTE.EXE-C563191ED28A926BCFDB1071374575F1": { "file_name": "ROUTE.EXE", "file_path": "C:\\Windows\\SysWOW64\\ROUTE.EXE", "hash_md5": "C563191ED28A926BCFDB1071374575F1", "hash_sha1": "D835E16660647CF2EFF6D006E5E5AF22756AA30D", "hash_sha256": "3EEB168F75126E2DC62746E5231399E9B0F71E8B910195931189DDFC5EDF88C6", "hash_sha384": "78B672C878D620F3DCD1AD394A4E106481D39DF3DEAD8F40BDBFBF8E3A1212938030317DD409963685A59EC88DFBA70E", "hash_sha512": "F4DB8AE1EA3757ADD3365AE8B54DF8996CC6598D913945B886980814F37EB6159C6F13271F2C4A9BB813F3371DE61FF9B504F21CC1BB0C97DED5041C68811C41", "hash_ssdeep": "384:8h2JsK2FQCOwb2eorV3wtCGLJfF8HlE+Fq2K6WI0W8E:8htGJvv6tCAKlfFq2KUb", "hash_imp": "BB55D8CE15016A967F7AAA263ECB6116", "hash_pesha1": "0B5666DDCD7A47619D27D2F00A179295BA5823E9", "hash_pe256": "9E9EBE933604DC1AFE1742DB61963FDAA9001908EAFB31A8AAC15283AE05EB4F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Route Command", "meta_original_filename": "route.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3eeb168f75126e2dc62746e5231399e9b0f71e8b910195931189ddfc5edf88c6/detection", "error": "\r\nManipulates network routing tables.\r\n\r\nROUTE [-f] [-p] [-4|-6] command [destination]\r\n [MASK netmask] [gateway] [METRIC metric] [IF interface]\r\n\r\n -f Clears the routing tables of all gateway entries. If this is\r\n used in conjunction with one of the commands, the tables are\r\n cleared prior to running the command.\r\n \r\n -p When used with the ADD command, makes a route persistent across\r\n boots of the system. By default, routes are not preserved\r\n when the system is restarted. Ignored for all other commands, \r\n which always affect the appropriate persistent routes.\r\n \r\n -4\t Force using IPv4.\r\n\r\n -6 Force using IPv6. \r\n \r\n command One of these:\r\n PRINT Prints a route\r\n ADD Adds a route\r\n DELETE Deletes a route\r\n CHANGE Modifies an existing route\t\r\n destination Specifies the host.\r\n MASK Specifies that the next parameter is the 'netmask' value.\r\n netmask Specifies a subnet mask value for this route entry.\r\n If not specified, it defaults to 255.255.255.255.\r\n gateway Specifies gateway.\r\n interface the interface number for the specified route.\r\n METRIC specifies the metric, ie. cost for the destination.\r\n\r\nAll symbolic names used for destination are looked up in the network database\r\nfile NETWORKS. The symbolic names for gateway are looked up in the host name\r\ndatabase file HOSTS.\r\n\r\nIf the command is PRINT or DELETE. Destination or gateway can be a wildcard,\r\n(wildcard is specified as a star '*'), or the gateway argument may be omitted.\r\n\r\nIf Dest contains a * or ?, it is treated as a shell pattern, and only\r\nmatching destination routes are printed. The '*' matches any string,\r\nand '?' matches any one char. Examples: 157.*.1, 157.*, 127.*, *224*.\r\n\r\nPattern match is only allowed in PRINT command.\r\nDiagnostic Notes:\r\n Invalid MASK generates an error, that is when (DEST & MASK) != DEST.\r\n Example> route ADD 157.0.0.0 MASK 155.0.0.0 157.55.80.1 IF 1\r\n The route addition failed: The specified mask parameter is invalid. (Destination & Mask) != Destination.\r\n\r\nExamples:\r\n\r\n > route PRINT\r\n > route PRINT -4\r\n > route PRINT -6\r\n > route PRINT 157* .... Only prints those matching 157*\r\n\t\r\n > route ADD 157.0.0.0 MASK 255.0.0.0 157.55.80.1 METRIC 3 IF 2\r\n destination^ ^mask ^gateway metric^ ^\r\n Interface^\r\n If IF is not given, it tries to find the best interface for a given \r\n gateway.\r\n > route ADD 3ffe::/32 3ffe::1\r\n \r\n > route CHANGE 157.0.0.0 MASK 255.0.0.0 157.55.80.5 METRIC 2 IF 2\r\n \r\n CHANGE is used to modify gateway and/or metric only.\r\n \r\n > route DELETE 157.0.0.0\r\n > route DELETE 3ffe::/32\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ROUTE.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RpcPing.exe-F7DD5764D96A988F0CF9DD4813751473": { "file_name": "RpcPing.exe", "file_path": "C:\\Windows\\SysWOW64\\RpcPing.exe", "hash_md5": "F7DD5764D96A988F0CF9DD4813751473", "hash_sha1": "5771AB69270C04A6CDDB5B24701A6A7FAC65077F", "hash_sha256": "BE654B85B6B4FDF81A9DF93AD5259760382E3964030F938E63A17B5C5A11F10B", "hash_sha384": "41300DE74E5C467735CECE2EB40B50615BA178D6E0AED0480F1D1E47090AB2511022D442CDC333CA54BBFB8E67F829CD", "hash_sha512": "CF0698EB8159022BA53177C9DD697C5DFBC13DCDCB2959D7BBDA44840E845BEC6A7E4C2C4182AD737DCAE33D9EB0517880CC521B2E1713BB2FA4EBDCB6F08B60", "hash_ssdeep": "768:ZmzRY7uIyX5I309UeLCc0mzMa3QLFt5s:QRY7uN+309UeX0m4a3It5s", "hash_imp": "19813C5F838DD3B1151D1518F2F49579", "hash_pesha1": "98CDEB4797B0C4D4EE659E7866D1A573AD4F5B51", "hash_pe256": "7040D08D5DF7C815B61B498D473DDC6398FCDD4AD27743665812733C6233EB05", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RPC Ping Utility", "meta_original_filename": "RpcPing.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/be654b85b6b4fdf81a9df93ad5259760382e3964030f938e63a17b5c5a11f10b/detection", "output": "Usage: \r\nrpcping [-t <protseq>] [-s <server_addr>] [-e <endpoint> \r\n |-f <interface UUID>[,MajorVer]] [-O <Interface Object UUID]\r\n [-i <#_iterations>] [-u <security_package_id>] [-a <authn_level>] \r\n [-N <server_princ_name>] [-I <auth_identity>] [-C <capabilities>]\r\n [-T <identity_tracking>] [-M <impersonation_type>]\r\n [-S <server_sid>] [-P <proxy_auth_identity>] [-F <RPCHTTP_flags>]\r\n [-H <RPC/HTTP_authn_schemes>] [-o <binding_options>]\r\n [-B <server_certificate_subject>] [-b] [-E] [-q] [-c]\r\n [-A <http_proxy_auth_identity>] [-U <HTTP_proxy_authn_schemes>]\r\n [-r <report_results_interval>] [-v <verbose_level>] \r\n\r\nPings a server using RPC. Options are:\r\n\r\n-t <protseq> - protocol sequence to use. Can be one of the standard\r\n RPC protocol sequences - ncacn_ip_tcp, ncacn_np, ncacn_http, etc.\r\n If not specified, default is ncacn_ip_tcp.\r\n \r\n-s <server_addr> - the server address. If not specified, the local\r\n machine will be pinged. E.g. server, server.com, 157.59.244.141\r\n \r\n-e <endpoint> - the endpoint to ping. If none is specified, the endpoint\r\n mapper on the target machine will be pinged. This option is mutually\r\n exclusive with the interface (-f) option.\r\n\r\n-o <binding_options> - the binding options for the RPC ping. See the\r\n MSDN for more details (RpcStringBindingCompose and RPC over HTTP).\r\n \r\n-f <interface UUID>[,MajorVer] - the interface to ping. This option is\r\n mutually exclusive with the endpoint option. The interface is specified\r\n as a UUID. If the MajorVer is not specified, version 1 of the interface\r\n will be sought. When interface is specified, rpcping will query the\r\n endpoint mapper on the target machine to retrieve the endpoint for the\r\n specified interface. The endpoint mapper will be queried using the\r\n options specified in the command line.\r\n \r\n-O <Object UUID> - Object Uuid if the interface registerd one.\r\n\r\n-i <#_iterations> - number of calls to make. The default is 1. This\r\n option is useful for measuring connection latency if multiple\r\n iterations are specified.\r\n \r\n-u <security_package_id> - the security package (security provider) RPC\r\n will use to make the call. The security package is identified as a\r\n number or a name. If a number is used it is the same number as in the\r\n RpcBindingSetAuthInfoEx API. The table below gives the names and\r\n numbers. Names are not case sensitive:\r\n Negotiate - 9 or one of nego, snego or negotiate\r\n NTLM - 10 or NTLM\r\n SChannel - 14 or SChannel\r\n Kerberos - 16 or Kerberos\r\n Kernel - 20 or Kernel\r\n If you specify this option you must specify authentication level other\r\n than none. There is no default for this option. If it is not specified,\r\n RPC will not use security for the ping.\r\n \r\n-a <authn_level> - the authentication level to use. Possible values are\r\n connect, call, pkt, integrity and privacy. If this option is\r\n specified, the security package id (-u) must also be specified. There\r\n is no default for this option. If this option is not specified, RPC\r\n will not use security for the ping.\r\n\r\n-N <server_princ_name> - specifies a server principal name. Same semantics\r\n as the ServerPrincName argument to RpcBindingSetAuthInfoEx. See the\r\n MSDN for more information on RpcBidningSetAuthInfoEx. This field can be\r\n used only when authentication level and security package are selected.\r\n \r\n-I <auth_identity> - allows you to specify alternative identity to connect\r\n to the server. The identity is in the form user,domain,password where\r\n the three fields have the obvious meaning. If the user name, domain or\r\n password have special characters that can be interpreted by the shell\r\n be sure to enclose the identity in double quotes. You can specify *\r\n instead of the password and RPC will prompt you to enter the password\r\n without echoing it on the screen. If this field is not specified, the\r\n identity of the logged on user will be used. This field can be used\r\n only when authentication level and security package are selected.\r\n \r\n-C <capabilities> - a hex bitmask of flags. It has the same meaning as\r\n the Capabilities field in the RPC_SECURITY_QOS structure described\r\n in the MSDN. This field can be used only when authentication level and\r\n security package are selected.\r\n \r\n-T <identity_tracking> - can be static or dynamic. If not specified,\r\n dynamic is the default. This field can be used only when authentication\r\n level and security package are selected.\r\n\r\n-M <impersonation_type> - can be anonymous, identify, impersonate or\r\n delegate. Default is impersonate. This field can be used only when\r\n authentication level and security package are selected. \r\n\r\n-S <server_sid> - the expected SID of the server. For more information\r\n see the Sid field in the RPC_SECURITY_QOS structure in the MSDN. Using \r\n this option requires Windows .NET Server 2003 or higher. This field can\r\n be used only when authentication level and security package are\r\n selected.\r\n \r\n-Z <effectiveonly> - the EffectiveOnly setting to use. For more information\r\n see the EffectiveOnly field in the RPC_SECURITY_QOS structure in MSDN.\r\n Using this option requires Windows Vista or higher. This field can be\r\n used only when authentication level and security package are selected.\r\n\r\n-D <serversecuritydescriptor> - the security descriptor (in string format)\r\n of the server when using mutual authentication. For more information\r\n see the ServerSecurityDescriptor field in the RPC_SECURITY_QOS structure\r\n in MSDN. Using this option requires Windows 8 or higher. This field can\r\n be used only when authentication level and security package are\r\n selected.\r\n\r\n-P <proxy_auth_identity> - specifies the identity to authenticate with to\r\n the RPC/HTTP proxy. Has the same format as for the -I option. \r\n Also, you must specify security package (-u), authentication level \r\n (-a), and authentication schemes (-H) in order to use this option.\r\n \r\n-F <RPCHTTP_flags> - the flags to pass for RPC/HTTP front end\r\n authentication. The flags may be specified as numbers or names\r\n The currently recognized flags are:\r\n Use SSL - 1 or ssl or use_ssl\r\n Use first auth scheme - 2 or first or use_first\r\n See the Flags field in RPC_HTTP_TRANSPORT_CREDENTIALS for more \r\n information. Also, you must specify security package (-u) and \r\n authentication level (-a) in order to use this option.\r\n \r\n-H <RPC/HTTP_authn_schemes> - the authentication schemes to use for\r\n RPC/HTTP front end authentication. This option is a list of numerical\r\n values or names separated by comma. E.g. Basic,NTLM. Recognized values\r\n are (names are not case sensitive:\r\n Basic - 1 or Basic\r\n NTLM - 2 or NTLM\r\n Certificate - 65536 or Cert\r\n Also, you must specify security package (-u) and authentication level \r\n (-a) in order to use this option.\r\n \r\n-B <server_certificate_subject> - the server certificate subject. For\r\n more information, see the ServerCertificateSubject field in the\r\n RPC_HTTP_TRANSPORT_CREDENTIALS structure in the MSDN. You must use\r\n SSL for this option to work. Also, you must specify security package \r\n (-u) and authentication level (-a) in order to use this option.\r\n \r\n-b - retrieves the server certificate subject from the certificate sent\r\n by the server and prints it to a screen or a log file. Valid only when\r\n the Proxy Echo only option (-E) and the use SSL options are specified.\r\n Also, you must specify security package (-u) and authentication level \r\n (-a) in order to use this option.\r\n \r\n-R - specifies the HTTP proxy. if it's 'none', we will not use HTTP proxy but\r\n directly attempt the RPC proxy. the value 'default' means to use the IE\r\n settings in your client machine. any other value will be treated as the\r\n explicit HTTP proxy. if you don't specify this flag, the default value\r\n is assumed, that is, the IE settings are checked. this flag is valid\r\n only when the -E (Echo Only) flag is enabled.\r\n\r\n-E - restricts the ping to the RPC/HTTP proxy only. The ping does not\r\n reach the server. Useful when trying to establish whether the RPC/HTTP\r\n proxy is reachable. Also, you must specify security package (-u) and \r\n authentication level (-a) in order to use this option. To specify an \r\n HTTP proxy, use the -R flag. If an HTTP proxy is specified in the -o \r\n flag, this option will be ignored.\r\n \r\n-q - quiet mode. Does not issue any prompts except for passwords. Assumes\r\n 'Y' response to all queries. Use this option with care.\r\n \r\n-c - use smart card certificate. RPCPing will prompt user to choose\r\n smart card.\r\n \r\n-A <http_proxy_auth_identity> - specifies the identity to authenticate\r\n with to the HTTP proxy. Has the same format as for the -I option. \r\n Also, you must specify authentication schemes (-U), security package \r\n (-u) and authentication level (-a) in order to use this option.\r\n \r\n-U <HTTP_proxy_authn_schemes> - the authentication schemes to use for\r\n HTTP proxy authentication. This option is a list of numerical\r\n values or names separated by comma. E.g. Basic,NTLM. Recognized values \r\n are (names are not case sensitive:\r\n Basic - 1 or Basic\r\n NTLM - 2 or NTLM\r\n You must specify security package (-u) and authentication level (-a) \r\n in order to use this option.\r\n\r\n-r <report_results_interval> - if multiple iterations are specified, this\r\n option will make rpcping display current execution statistics\r\n periodically instead after the last call. The report interval is given\r\n in seconds. Default is 15.\r\n \r\n-v <verbose_level> - tells rpcping how verbose to make the output. Default\r\n value is 1. 2 and 3 provide more output from rpcping.\r\n \r\nExample: Find out if your Exchange server that you connect through\r\nRPC/HTTP is accessible:\r\n rpcping -t ncacn_http -s exchange_server -o RpcProxy=front_end_proxy\r\n -P \"username,domain,*\" -H Basic -u NTLM -a connect -F 3\r\nWhen prompted for the password, enter it. exchange_server is the name of\r\nyour exchange server, front_end_proxy is the name of your proxy, username\r\nand domain are your user name and domain as you would enter them in the\r\nOutlook prompt. The other parameters will ask rpcping to ping your\r\nExchange server in exactly the same way as Outlook will connect to it for\r\nthe typical profile.\r\n\r\n-p - Prompt for credentials if authentication fails.\r\n", "children": "perfmon.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\RpcPing.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "rrinstaller.exe-0FC620A6F80CB075E05CA72352D84584": { "file_name": "rrinstaller.exe", "file_path": "C:\\Windows\\SysWOW64\\rrinstaller.exe", "hash_md5": "0FC620A6F80CB075E05CA72352D84584", "hash_sha1": "DC9CBA68BA26359AC9F3CB3349131C624C72741A", "hash_sha256": "E580885A1DC294BF9C7653ABD08AB8DE490D63F8E30AB73BBF031A3CE8A57128", "hash_sha384": "12BCF659506029AC7F3C794909770C5E8D571F7364C201A1175968090D72B36456DB4FF16A3860BB65508367288EA523", "hash_sha512": "5DEC08D70ADBAC4C8E768D18B666F95CBF069EE7747127B32D0D80BB748B7B80E767ED8FE47528E9C2B8271A4BA14FFF452FC0E1ED9D5B4ECB05808DC416C154", "hash_ssdeep": "768:KHqsIfEFqPnmjtPHddqJYby8vhlNCE34HPt+4bz7ymo8:lfzmjtPHddqJYLhlKH/ymH", "hash_imp": "22CD5E9B5D2130049B28E3DC366A44AD", "hash_pesha1": "FD4FD6B1B9379547EF6B7FBDCF2DCBDF612E31E6", "hash_pe256": "2269B5C60D4821D3C5FB9347B41E1511AC218998CEC8B4BDC9849E3C6D03DBAA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "R&R installer", "meta_original_filename": "rrinstaller.exe", "meta_product_name": "Microsoft DRM", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.0.19041.1", "meta_product_version": "11.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e580885a1dc294bf9c7653abd08ab8de490d63f8e30ab73bbf031a3ce8a57128/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\rrinstaller.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "runas.exe-3C9AD13D268D1DFB106DD8C2017478C2": { "file_name": "runas.exe", "file_path": "C:\\Windows\\SysWOW64\\runas.exe", "hash_md5": "3C9AD13D268D1DFB106DD8C2017478C2", "hash_sha1": "9645690A9F0F22E66259C36DCCECB170EF8B4887", "hash_sha256": "C42AB0055B380E36BB4A5E5C3824F7ABFA5BC028B2747743271964065B1EF8BA", "hash_sha384": "1028D3B5A1F4CF092E2CBB2BAAF382BA624A731EB568671CDCD7AA07F56861A3A625766AD82107FC4C29920D9657E015", "hash_sha512": "3C22DBD4D831746D13198C3BE7149092D2C10873A58D64B291F1A8D447E55C0C54C70DB17A92CE4CE6F08464AFF1A5CAB145DFC604545EE58A0705DAAF4E68CA", "hash_ssdeep": "384:1jCBBv49184sWKMVaMgYCHq18FuNWWOW:AjY1tjgMT8Fur", "hash_imp": "63B4267CB5383EAE01A9DE96021E1731", "hash_pesha1": "A05DC9552DED89D5DA0AA8BAEFCA3970C8AEBE7D", "hash_pe256": "78E576A653CC9C414F5BB1979F3AB65BFF8AB5BA977E1CD827E4B3E6CA8093A0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Run As Utility", "meta_original_filename": "RUNAS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c42ab0055b380e36bb4a5e5c3824f7abfa5bc028b2747743271964065b1ef8ba/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\runas.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "rundll32.exe-4D3D5A68D1B9A98985DCF8F6CABA68F1": { "file_name": "rundll32.exe", "file_path": "C:\\Windows\\SysWOW64\\rundll32.exe", "hash_md5": "4D3D5A68D1B9A98985DCF8F6CABA68F1", "hash_sha1": "B8A3DD162A865C8AB923862FDD9AF626B81651A9", "hash_sha256": "BBBDE17D9D1F77E3DDF7B212E36EBDC094DDBA0F4115C8CACDE903E880E0E67D", "hash_sha384": "A63B289AC2F61CC320D9E8BF64EB642FD09F007B04DB3736F3BA7580360221AC8D15E92B3A354F861D620DD648E2E70B", "hash_sha512": "290C17136BD6733655B59AA803FC6A961E00F85B3B7FD6906DC34179F89196CD4C36BD84004AE4184C57E0BA14F9CAE18DC44A3473D9B32EB05D02A36E1E3E89", "hash_ssdeep": "768:EyYwyE6CQGFflfHWQiESLyXs+VsXgXm2NCYRGbSEln5IyYpamDjobj8Su8of:EyYtCQmFkrkVrmZYRuln5IUmDjoX68", "hash_imp": "30B6D4AA5B2B125B0ABCA749B5D12B3A", "hash_pesha1": "F7E37623C35175D834B526918E1A2A2367E0FCEC", "hash_pe256": "87FF0C97DD891A07AF92F9B9504E864F743E0905596697922B88B25EE528D08C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows host process (Rundll32)", "meta_original_filename": "RUNDLL32.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/bbbde17d9d1f77e3ddf7b212e36ebdc094ddba0f4115c8cacde903e880e0e67d/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\rundll32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RunLegacyCPLElevated.exe-848480B7DA5B0428E62938093C183BC0": { "file_name": "RunLegacyCPLElevated.exe", "file_path": "C:\\Windows\\SysWOW64\\RunLegacyCPLElevated.exe", "hash_md5": "848480B7DA5B0428E62938093C183BC0", "hash_sha1": "201930C8F3D08B35BE95DA27BED479F6494175B6", "hash_sha256": "E3F8C10EE5FE36CBFEED2AF0EDA485059459C5696ED0B54EA24BA6B7697F4589", "hash_sha384": "DF1D190A7187414620B03C625D202AA05EFD42DB7D9D440E2441056C64FA239AC2A6FC73E8E9E1F711B4A51F61DDB0CE", "hash_sha512": "DC038841F12402B0449F430F92BC5E0BE782DAB1A8B27AA197F6C6BEA0406A72FE1321225A2C60DC6194E8F2A9DDDBF65AB2CC1D8DD96708BDC5DA0FD2F6DB6F", "hash_ssdeep": "768:TdyMiHpWdUDSzLPNCspV1Ry8oxGSkVhWakkbB5eT905WGnUKxHUe7n8jKBFFptXB:5ynJAz1y8oxxakkn6oYY0ewiP8s", "hash_imp": "932B565960425EE7FA367E4081AFA26B", "hash_pesha1": "42FCBC79C76D87D77FE147E29A7E6E8383F5F60B", "hash_pe256": "DCFC940EEBCD88A903C6F75C0767744FCB0984088AC656F5A0A4D5B0A1FB0AB5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Run a legacy CPL elevated", "meta_original_filename": "RunLegacyCPLElevated.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/e3f8c10ee5fe36cbfeed2af0eda485059459c5696ed0b54ea24ba6b7697f4589/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\RunLegacyCPLElevated.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "runonce.exe-A368C8AFDAEB269F48E8D7A006EE6A15": { "file_name": "runonce.exe", "file_path": "C:\\Windows\\SysWOW64\\runonce.exe", "hash_md5": "A368C8AFDAEB269F48E8D7A006EE6A15", "hash_sha1": "9856DADD0F49B00C72524E0233A8BF027374DADF", "hash_sha256": "E2031017207A33A6FA147A5BB6E32AD5788DF03F783D424A0053BA1B16D561F5", "hash_sha384": "052FE97FB8C026D3ABB7311D64D5E9D7CAE993C9B12627433B9BA9BA5ED6943777620257CE27FA8105B9587B362C9552", "hash_sha512": "6D276E7969371FDA95A8411CCBFBC8E26ACDAFB8A2814B0FFB32DA6B39C6783A697C01F3BEB7232CEE3492D7F542487ACD5B675C292A6F8CCD8712B5733FC780", "hash_ssdeep": "768:A/6/iNbCpNS7yjLRUgHA9hIn7A1TI1B5keJx+DGtFwex8ZsAfFW:A/6/iNbcb3nI2mI1cq+ytlaZsAfQ", "hash_imp": "97CC98DB681CF599B4F85D3B9CF8A780", "hash_pesha1": "C5C871F3221A22325C67F0D70555F3BE76E5520E", "hash_pe256": "762F6C842007D550270AA71FA921AFEB3926850E46748BECDF4A9DE7D2250CD9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Run Once Wrapper", "meta_original_filename": "RUNONCE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e2031017207a33a6fa147a5bb6e32ad5788df03f783d424a0053ba1b16d561f5/detection", "children": "perfmon.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\runonce.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "sc.exe-D9D7684B8431A0D10D0E76FE9F5FFEC8": { "file_name": "sc.exe", "file_path": "C:\\Windows\\SysWOW64\\sc.exe", "hash_md5": "D9D7684B8431A0D10D0E76FE9F5FFEC8", "hash_sha1": "5D192324ADDD32BF93B5009981CDC6A454C5DB50", "hash_sha256": "4FE6D9EB8109FB79FF645138DE7CFF37906867AADE589BD68AFA503A9AB3CFB2", "hash_sha384": "CDC02975FE2B94D00710A4E20598E492E95EDB650E7861926CD1A05FD4C2582C00C47E23AC507C175DF4049D574C2793", "hash_sha512": "509C2FA6EF2791A76E36F255F33197729BDB650C9B2F7B8580B4C27A7BDAD09C783D3E149268EC2E4B3B9398C22BA8B5B3622C3DBEDC559C5B06305352EEF026", "hash_ssdeep": "1536:lFL6e3972zBpABZ+Tolu/tKd5mjuf0ntKfRILBNflBSuJWmQnVX+n0dqZuS8bmkD:lFLx3972zBpABZ+Tolu/tKd5mjuf0nt2", "hash_imp": "B037D0ADB81BF9CFC651DE01742089F1", "hash_pesha1": "6AE238799C7FA4F6B0D825D5F19336BBAF147592", "hash_pe256": "140DCC4F20D96DCE3BBDB77DDF868E32CEFDA4C3083DC90F97C7544F6864FD97", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Service Control Manager Configuration Tool", "meta_original_filename": "sc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4fe6d9eb8109fb79ff645138de7cff37906867aade589bd68afa503a9ab3cfb2/detection", "output": "\r\nERROR: Unrecognized command\r\n\r\nDESCRIPTION:\r\n SC is a command line program used for communicating with the\r\n Service Control Manager and services.\r\nUSAGE:\r\n sc <server> [command] [service name] <option1> <option2>...\r\n\r\n\r\n The option <server> has the form \"\\\\ServerName\"\r\n Further help on commands can be obtained by typing: \"sc [command]\"\r\n Commands:\r\n query-----------Queries the status for a service, or\r\n enumerates the status for types of services.\r\n queryex---------Queries the extended status for a service, or\r\n enumerates the status for types of services.\r\n start-----------Starts a service.\r\n pause-----------Sends a PAUSE control request to a service.\r\n interrogate-----Sends an INTERROGATE control request to a service.\r\n continue--------Sends a CONTINUE control request to a service.\r\n stop------------Sends a STOP request to a service.\r\n config----------Changes the configuration of a service (persistent).\r\n description-----Changes the description of a service.\r\n failure---------Changes the actions taken by a service upon failure.\r\n failureflag-----Changes the failure actions flag of a service.\r\n sidtype---------Changes the service SID type of a service.\r\n privs-----------Changes the required privileges of a service.\r\n managedaccount--Changes the service to mark the service account \r\n password as managed by LSA.\r\n qc--------------Queries the configuration information for a service.\r\n qdescription----Queries the description for a service.\r\n qfailure--------Queries the actions taken by a service upon failure.\r\n qfailureflag----Queries the failure actions flag of a service.\r\n qsidtype--------Queries the service SID type of a service.\r\n qprivs----------Queries the required privileges of a service.\r\n qtriggerinfo----Queries the trigger parameters of a service.\r\n qpreferrednode--Queries the preferred NUMA node of a service.\r\n qmanagedaccount-Queries whether a services uses an account with a \r\n password managed by LSA.\r\n qprotection-----Queries the process protection level of a service.\r\n quserservice----Queries for a local instance of a user service template.\r\n delete----------Deletes a service (from the registry).\r\n create----------Creates a service. (adds it to the registry).\r\n control---------Sends a control to a service.\r\n sdshow----------Displays a service's security descriptor.\r\n sdset-----------Sets a service's security descriptor.\r\n showsid---------Displays the service SID string corresponding to an arbitrary name.\r\n triggerinfo-----Configures the trigger parameters of a service.\r\n preferrednode---Sets the preferred NUMA node of a service.\r\n GetDisplayName--Gets the DisplayName for a service.\r\n GetKeyName------Gets the ServiceKeyName for a service.\r\n EnumDepend------Enumerates Service Dependencies.\r\n\r\n The following commands don't require a service name:\r\n sc <server> <command> <option>\r\n boot------------(ok | bad) Indicates whether the last boot should\r\n be saved as the last-known-good boot configuration\r\n Lock------------Locks the Service Database\r\n QueryLock-------Queries the LockStatus for the SCManager Database\r\nEXAMPLE:\r\n sc start MyService\r\n\r\n\r\nQUERY and QUERYEX OPTIONS:\r\n If the query command is followed by a service name, the status\r\n for that service is returned. Further options do not apply in\r\n this case. If the query command is followed by nothing or one of\r\n the options listed below, the services are enumerated.\r\n type= Type of services to enumerate (driver, service, userservice, all)\r\n (default = service)\r\n state= State of services to enumerate (inactive, all)\r\n (default = active)\r\n bufsize= The size (in bytes) of the enumeration buffer\r\n (default = 4096)\r\n ri= The resume index number at which to begin the enumeration\r\n (default = 0)\r\n group= Service group to enumerate\r\n (default = all groups)\r\n\r\nSYNTAX EXAMPLES\r\nsc query - Enumerates status for active services & drivers\r\nsc query eventlog - Displays status for the eventlog service\r\nsc queryex eventlog - Displays extended status for the eventlog service\r\nsc query type= driver - Enumerates only active drivers\r\nsc query type= service - Enumerates only Win32 services\r\nsc query state= all - Enumerates all services & drivers\r\nsc query bufsize= 50 - Enumerates with a 50 byte buffer\r\nsc query ri= 14 - Enumerates with resume index = 14\r\nsc queryex group= \"\" - Enumerates active services not in a group\r\nsc query type= interact - Enumerates all interactive services\r\nsc query type= driver group= NDIS - Enumerates all NDIS drivers\r\n\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\sc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "schtasks.exe-1A92D135C7D1F3EBD153900C2AEA2CC1": { "file_name": "schtasks.exe", "file_path": "C:\\Windows\\SysWOW64\\schtasks.exe", "hash_md5": "1A92D135C7D1F3EBD153900C2AEA2CC1", "hash_sha1": "F3FB074BEB83F07DBA128E55FA3C578A23B991AE", "hash_sha256": "33C21C9DAC8E26A6CAF6D3F7D26DBE93674D196D567AB291B3793A34A8D8B8A0", "hash_sha384": "85DA6774F930A91AFEC651DCB5CAE111E9D1EDF4A6A5C6D54AD788D23B7C96E3FD59762C4DE989331776CE190887A3CD", "hash_sha512": "C41060ADD74A88CE921E2E48666ABA9FD53ABD05ED48665C11B152D2FCEFD9697E0C18E73C7D287380C32F4BF6EADD651990BD52A85C3BA014A1464B3196106C", "hash_ssdeep": "6144:sVzhKcmndsH3txHDXfYMEAJcBKgysyUenT:sVzrUdsH3HDfYTA2g+I", "hash_imp": "A51577D184744391356DD5E26285BAB4", "hash_pesha1": "9E781C4904D8CC93FDFFC5183EFAA22C7F8B1E33", "hash_pe256": "A9207208326A4521661B7440119E4AA10C14ADED746F76CB82948194ABDDE6A3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Scheduler Configuration Tool", "meta_original_filename": "schtasks.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/33c21c9dac8e26a6caf6d3f7d26dbe93674d196d567ab291b3793a34a8d8b8a0/detection", "output": "\r\nSCHTASKS /parameter [arguments]\r\n\r\nDescription:\r\n Enables an administrator to create, delete, query, change, run and\r\n end scheduled tasks on a local or remote system. \r\n\r\nParameter List:\r\n /Create Creates a new scheduled task.\r\n\r\n /Delete Deletes the scheduled task(s).\r\n\r\n /Query Displays all scheduled tasks.\r\n\r\n /Change Changes the properties of scheduled task.\r\n\r\n /Run Runs the scheduled task on demand.\r\n\r\n /End Stops the currently running scheduled task.\r\n\r\n /ShowSid Shows the security identifier corresponding to a scheduled task name.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n SCHTASKS \r\n SCHTASKS /?\r\n SCHTASKS /Run /?\r\n SCHTASKS /End /?\r\n SCHTASKS /Create /?\r\n SCHTASKS /Delete /?\r\n SCHTASKS /Query /?\r\n SCHTASKS /Change /?\r\n SCHTASKS /ShowSid /?\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"SCHTASKS /QUERY /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\schtasks.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "sdbinst.exe-9BFFF44EBACF811FC4BDA574C51D4045": { "file_name": "sdbinst.exe", "file_path": "C:\\Windows\\SysWOW64\\sdbinst.exe", "hash_md5": "9BFFF44EBACF811FC4BDA574C51D4045", "hash_sha1": "3CBB03B75BC92379499B3B24CD8F24CBD85318C1", "hash_sha256": "20E69EEA897D3ABFD5CD7DF2FFECD6083961E9231FEB3D4ED1F029315E5FA88D", "hash_sha384": "4E59DC33B41BDBD8378C63A3B67B61310883C436AF69A75B5FC24E17CC927E9AAA62210C2F9868750322C0CD96CA381E", "hash_sha512": "C809598A094B24A92557FAAB49C67183579DA6398DD166D7B2D5C795F273CFC3A838433EE97AEC2CFA2E783D1C9D128B2255758A00EA152A70CA0F6F1B9B6E5F", "hash_ssdeep": "384:ZOhy/E2SJPJ4UdeW9A9y6KHSJ/fFpx1RuOQ1sHPrPDE9LWRgW:ZO8eDcW9oKHSl51YEHDPDE9S", "hash_imp": "DC04DAC563E65A0D0DAE0ACCC2AC61E2", "hash_pesha1": "D7B06E4D14E56BCC8F25EB5BF4FA6FD3F6DB3EA9", "hash_pe256": "B3657C7A860B776B6DBD01DC2789DC891E9BB32F83555052DF79CBB986E13F42", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Application Compatibility Database Installer", "meta_original_filename": "sdbinst.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/20e69eea897d3abfd5cd7df2ffecd6083961e9231feb3d4ed1f029315e5fa88d/detection", "output": "Error: Invalid switch --help.\nUsage: C:\\Windows\\SysWOW64\\sdbinst.exe [-?] [-q] [-u] [-g] [-p] [-n[:WIN32|WIN64]] myfile.sdb | {guid} | \"name\"\r\n\r\n -? - print this help text.\r\n -p - Allow SDBs containing patches.\r\n -q - Quiet mode: prompts are auto-accepted.\r\n -u - Uninstall.\r\n -g {guid} - GUID of file (uninstall only).\r\n -n \"name\" - Internal name of file (uninstall only).\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\sdbinst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "sdchange.exe-46970E8F2F2C362EB21BD9FBD7E14DF1": { "file_name": "sdchange.exe", "file_path": "C:\\Windows\\SysWOW64\\sdchange.exe", "hash_md5": "46970E8F2F2C362EB21BD9FBD7E14DF1", "hash_sha1": "E0B54C3385114A09CF1E4E035FA6431207394827", "hash_sha256": "77BEA7A0371E270B9BFCD6B51433CA8642078BD36E4FDBDB726F9815BF3B6A4F", "hash_sha384": "A547BC0632543D764EEDB05849B165AB0D4A565DBE057D10697D9E1431621D92142876F32B425AB58782D00F94A92A2D", "hash_sha512": "73D78E46ABD95F0470761C37851A79EB5FEA773BE1FDADFE00B4DB1D1959A009EB34252A6C1F97191F8E9914CF58824B7135A79E42327632670C3C72844B8ED1", "hash_ssdeep": "768:T/Y5y+q0Ev5bjsoQqlURS0KarrbMQb7/Fh6BG:U8v5b4oJle2YPmc", "hash_imp": "FEBDB8D41B96564D59EF7EC952028FD4", "hash_pesha1": "8D5ADFCB21BBE29821D67D7CF3883A7CBA5C97DB", "hash_pe256": "2C38854F23A1CDB32E7994C77766065AC6CB69DF041E3C403422CFBDFA6EAC19", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Remote Assistance SD Server", "meta_original_filename": "sdchange.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/77bea7a0371e270b9bfcd6b51433ca8642078bd36e4fdbdb726f9815bf3b6a4f/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\sdchange.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\sdchange.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "sdiagnhost.exe-43353191117C9236DDCCE362A8E74BA7": { "file_name": "sdiagnhost.exe", "file_path": "C:\\Windows\\SysWOW64\\sdiagnhost.exe", "hash_md5": "43353191117C9236DDCCE362A8E74BA7", "hash_sha1": "6A0B5CE7964379CE5019E46302EFDF6F5EC19A95", "hash_sha256": "3584436E99BD2D420E9066E3A237ED1BE41E964E92FB5E1C88E052E6C834B1DA", "hash_sha384": "401182DCA59A4CC3B3A28DDE61F52ADF67B28B70161EED5DE82AB34CA982F5C2742A00E520AA2F125C41E533DD3B9912", "hash_sha512": "94014C6EB596222A7E72E089518AA071F24C870DEDA3050B6EB4D9A9766A0291D31A009E94CF2874AB8FCEEAC8AFBA97465D38E295874025948573648A4E732F", "hash_ssdeep": "384:zHm8MXAvaHQ41cJluoPk8KWreBiyj7hZxaLelgWh7DWIH:wHElu4b8j75aLeN", "hash_imp": "1AC4615E680B9BC131EC1F2ADCF60B35", "hash_pesha1": "687EF5C2A6DA51ABC7EA3E15104034086017AC3E", "hash_pe256": "E415F46A53DCE06C8995B85E54A40D8F8DE5E27067A96E1B4E9B2BFC749D7240", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Scripted Diagnostics Native Host", "meta_original_filename": "sdiagnhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3584436e99bd2d420e9066e3a237ed1be41e964e92fb5e1c88e052e6c834b1da/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\sdiagnhost.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\sdiagnhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SearchFilterHost.exe-10D15D96253E0625329DF893C210A83F": { "file_name": "SearchFilterHost.exe", "file_path": "C:\\Windows\\SysWOW64\\SearchFilterHost.exe", "hash_md5": "10D15D96253E0625329DF893C210A83F", "hash_sha1": "74ED9E0870F84DAA0A7CEE72F66165FD13E902D4", "hash_sha256": "C80BF01B08858862E714995C669C3B3687614DA4AC20798248E413D7F62AB2B5", "hash_sha384": "946B1F954E9713084A93B9DEB2CAE996A851AD84C1B18DDDF34C4A5E73AD8C6925E60FBBF9286FC4D55F09A3F882C754", "hash_sha512": "B5A39C726DBED3178C9F17727E5B6CA156E75A93E95BDA94500B24B0B1B2B2B6A5F7AFE23966BAB025EEAD7672DE93743075E15860AD9D5BED4DF6B2DCD2C3F1", "hash_ssdeep": "3072:wcg+AkhImHlKKxv0465R5m6FuC0Utf+Y++nwErsHhTd1ihk6kvtfGq0ev3U5WNiW:Zg+lxzNktf++nwErsHhArkR10efUKi", "hash_imp": "EC65350EF20C54293FB94B3EA4ED0FE4", "hash_pesha1": "C4BF22E3B1D12287F3EBE5673FC4467F301AB418", "hash_pe256": "66B55FBF3A7AFAC779B220C50430373E6DCCD3E6FA915499A9AB0CD89BDFF05D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Search Filter Host", "meta_original_filename": "SearchFilterHost.exe", "meta_product_name": "Windows Search", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "7.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c80bf01b08858862e714995c669c3b3687614da4ac20798248e413d7f62ab2b5/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\SearchFilterHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SearchIndexer.exe-5BDB45ADBF0670E911C57F898877A002": { "file_name": "SearchIndexer.exe", "file_path": "C:\\Windows\\SysWOW64\\SearchIndexer.exe", "hash_md5": "5BDB45ADBF0670E911C57F898877A002", "hash_sha1": "349F721348F15C7357351A667683F7BBBAC76C25", "hash_sha256": "35DA9F518B4F90AF76B014C1D8B0232E1F58ADFABA900DF0E49DA8511ECEB932", "hash_sha384": "E30A0CCC214A66A22132EE452D032F0051B7E727D75BAAA2477451B9DC4FC32BD2A2465DC365379EE65F58C7706BB46A", "hash_sha512": "2584E820A81A07BE438F675F57B4AB63DF7321F9107A147E54EA9190AD74031824E9910DC660A5C085D0D7F1AA971C23CDEEA3BE24E7062F817ACF16709C68D0", "hash_ssdeep": "12288:iM67B8aYL4AGuVmhawphV0rzerghXafFGzqgYGslys1QogFbUTI/1ylWhrAB5:iM69vYL4iEsw0zeEhq4OB9V+ulWhcB5", "hash_imp": "812BC377718C5596E3E57EC10AA99C88", "hash_pesha1": "0C29244BFE8C10DCA813D348ACD5830F779AE972", "hash_pe256": "8561302E06A2A78F8D7A11CA7FD0FCD026A15C887CEB54350F1E1E47FE70D20E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Search Indexer", "meta_original_filename": "SearchIndexer.exe", "meta_product_name": "Windows Search", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "7.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/35da9f518b4f90af76b014c1d8b0232e1f58adfaba900df0e49da8511eceb932/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\SearchIndexer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SearchProtocolHost.exe-76FE9088E3D2BD04A346E480C7863CF7": { "file_name": "SearchProtocolHost.exe", "file_path": "C:\\Windows\\SysWOW64\\SearchProtocolHost.exe", "hash_md5": "76FE9088E3D2BD04A346E480C7863CF7", "hash_sha1": "084B18B740A447BEFEB037FCEBF1C4A8EF22E60C", "hash_sha256": "7B80A59D171BE36ECFE71488827EEAF882495B2B109A0619D33A8687887CA489", "hash_sha384": "8C9BDBF5D7BB080AA605B7619EA188FE94AC6211A71BB08328335C8E3D77A740F959E3E0BAC8AEC730697B808D16EF95", "hash_sha512": "24EC557C0E45AF1BFABB85280E079305F3A975118106118A2E63334BAC6090DAE9BEB1961CEBD58892B93CF05BB34769AF89CE682F0FEF054B54D4245887E2C4", "hash_ssdeep": "6144:WXR9ZY3lMMbuf0tDBUpwy0VnZ6VC/fb/2PaBfVzordfrkR10efUK3:w9ZYVMMifoBUpwxKc0alydfQztf9", "hash_imp": "1F5B4307B67AE3B1CBA7CA7438B42BD1", "hash_pesha1": "ED1874F8530774087F49BA43055B409D52749A4C", "hash_pe256": "33FEE190B4D12A0D8D6B845AFCCB1829E5A34FFC757D9051E681E7AA224D6219", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Search Protocol Host", "meta_original_filename": "SearchProtocolHost.exe", "meta_product_name": "Windows Search", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "7.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7b80a59d171be36ecfe71488827eeaf882495b2b109a0619d33a8687887ca489/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\SearchProtocolHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SecEdit.exe-BFC13856291E4B804D33BBAEFC8CB3B5": { "file_name": "SecEdit.exe", "file_path": "C:\\Windows\\SysWOW64\\SecEdit.exe", "hash_md5": "BFC13856291E4B804D33BBAEFC8CB3B5", "hash_sha1": "C6DFD5A7AEC5C4BB068C2FD4E5A4F4B17A65EA7A", "hash_sha256": "56CB815F0FDA92C4658296692E4F70DEE557137528482FE7A834296BFDB710C0", "hash_sha384": "D1B6025BD34255297627235485CE4FABDC69AFBFAAC13EE7BA329168245315A3016F612B14D1DFF4FA8B982BA9A1CF9E", "hash_sha512": "F6E169D040CD8FA6B4FB52A88255D1525B58685A55669B7487499A05D4FB21708DBCEC3C21CA4A1AA5B7AC94CADC91E8B28C2E347821723505C6242D06CB06CA", "hash_ssdeep": "384:xkqy2KUDuQAi1KVf8JWN00KIPyeBQekXMkPGWDWQzHiWeaXq0lDf2Bh7/oSXkoQ3:xr3KHV0JWNbHyiQzXpPGW7dJqT7/pXk", "hash_imp": "615449A6A25801F47AE0D7578EB950B4", "hash_pesha1": "575CDB3E7EA92EFD24452C53759503B6E0DD9FDC", "hash_pe256": "0A546395B921D0E93DA026D04B4E43822DD1FAD5FD09C5CD6385DF69CDE59F8F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Security Configuration Editor Command Tool", "meta_original_filename": "SeCEdit", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/56cb815f0fda92c4658296692e4f70dee557137528482fe7a834296bfdb710c0/detection", "output": "\r\nThe syntax of this command is:\r\n\r\nsecedit [/configure | /analyze | /import | /export | /validate | /generaterollback]\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\SecEdit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "secinit.exe-3B4B8DB765C75B8024A208AE6915223C": { "file_name": "secinit.exe", "file_path": "C:\\Windows\\SysWOW64\\secinit.exe", "hash_md5": "3B4B8DB765C75B8024A208AE6915223C", "hash_sha1": "21F946BBAE92921EEAD50381370EC54E14F0AA08", "hash_sha256": "AA365888AB4E37156F06EDF20049831BA7CD9203F6617A9632F1C8F3BCAFE15A", "hash_sha384": "17F4CBBDE238CF7AAF07BB55ACA18373DD88B90341D948D739837963363971811E846A4B88035FE6B577A6836EE22912", "hash_sha512": "F865FC7F9C368212A4BB9F0A02B1FDA92F2611E7BF08D10DD2BB1892E3C46C819CE3F76E96E2B32E6E72F6C6CDEC2846613B861F7899F93B872B0C4F9A407591", "hash_ssdeep": "192:9KNxTON8nIUGwrPwY7tv1GQkNW8vbzRiW:9JN8nIUGw7wYZ0rNW8vbzRiW", "hash_imp": "87C27A671C9F1DC5F6B0744E9E74293E", "hash_pesha1": "6B006F9DEFAB1AC099E5EBA5DB070EFFED829622", "hash_pe256": "FECD0AA8FADD232136959109761E479428196048FE1DF92A7A84C68DF2B3D1DF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Security Init", "meta_original_filename": "secinit", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/aa365888ab4e37156f06edf20049831ba7cd9203f6617a9632f1c8f3bcafe15a/detection", "children": "perfmon.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\secinit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll" ] }, "sethc.exe-AA9A6E4DADA121001CFDF184B9758BBE": { "file_name": "sethc.exe", "file_path": "C:\\Windows\\SysWOW64\\sethc.exe", "hash_md5": "AA9A6E4DADA121001CFDF184B9758BBE", "hash_sha1": "2BDF95CCA2FCF16019414F7FCB8735CCAC634BC7", "hash_sha256": "8798C149F63E1573E7AEC72E61796C95793866EF84375E521EB92940E2105F59", "hash_sha384": "8AF8B14B1AC389B7FBD31A0AB14289B48A7786309E1B4F3F437C64050FC7D9B5D516819834B6EAB73B2E6A839F8F22F4", "hash_sha512": "AAFC87160E4CEAC86FCE498B452726B448DCC9E307E080C08455909B3CA1249004838B9DC2E8A7BA38785038ADF58D3573FA83DFC6548A134396C7CDE1E23FCB", "hash_ssdeep": "1536:zLMxK3GKGDBpubXBby5IKf5ol2rl/1qzWO0vmTZB1+hKW/Gz4xugtZ:EI2ziXZc9OClBA4xu6Z", "hash_imp": "99214BEF6DDBD511D211D3F419512626", "hash_pesha1": "44D41F1978EEBCD3E053C7617E3A8DE486DBB847", "hash_pe256": "5EE2E0E7E2A0D98D03866B28FE9AAF3BFECCF9F68562872DD6820AE90EE99231", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Accessibility shortcut keys", "meta_original_filename": "sethc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.388 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.388", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8798c149f63e1573e7aec72e61796c95793866ef84375e521eb92940e2105f59/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\sethc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SettingSyncHost.exe-80F1E4DC853D07994906F68CF156EE70": { "file_name": "SettingSyncHost.exe", "file_path": "C:\\Windows\\SysWOW64\\SettingSyncHost.exe", "hash_md5": "80F1E4DC853D07994906F68CF156EE70", "hash_sha1": "C98AB79658ACDEC113B44B9757E53E275F35A991", "hash_sha256": "93F35856509E6332E6B1DDC883E960A103B14FF2C12B66CDFF2FED33F3C7659C", "hash_sha384": "53B29D9D49E7313315D36BA5E3D5D02A7110D775F90C019C4B85E8A636BB41D5999EC03946E842690868828BDE6DE456", "hash_sha512": "4C455EF80F32E31E7A30B6FE2C5781ECD917AA0AF2B56A9AAA6B60C065B7F4F928ACC5D4D538034981F1ED84096511CD928D45892509C3BA6483B0BCD71FBFC9", "hash_ssdeep": "24576:2vTLPZyX8XFy/1rRjJjpkmra8jADkpVx7yDZffo6Sjli:WTLPZyXawnkUdjDM9o68i", "hash_imp": "8872E42058372AAB0AB5AC752E0ADDD2", "hash_pesha1": "18A887262133D16CCB15CAC8DF711739D2EBE73C", "hash_pe256": "E791994011860240EBAF0271D24F07ADC49C60D1413FF41BC6C116E84248E2C4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Setting Synchronization", "meta_original_filename": "SettingSyncHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/93f35856509e6332e6b1ddc883e960a103b14ff2c12b66cdff2fed33f3c7659c/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\SettingSyncHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "setup16.exe-CB685A2EB72FB3F518595514EFF053CD": { "file_name": "setup16.exe", "file_path": "C:\\Windows\\SysWOW64\\setup16.exe", "hash_md5": "CB685A2EB72FB3F518595514EFF053CD", "hash_sha1": "BC10901A5F62D0270F11F2507D09E108FB79CBDA", "hash_sha256": "6FF2FA645DCC6DB79972B2415A712565DEBFFC2E43D5289DAF3D6219ED5E6087", "hash_sha384": "4BF2359D6EB2C84A7B042ED92841ADBDD78212F74B5A38D9895FA58A95934E51639EAC0359EFBF2A0BB0AA9F7B262726", "hash_sha512": "84E39F82B8B0AAFE7909BB209EA74CE33FF78F1CAFD7FBC91AB429DDCB6FE5E9E78603DEEF8223BAA28CF30867445E7A267A9292BE4A57F8A18E5C526B7A6770", "hash_ssdeep": "384:WZ3bbVOI/YN7g8hqRryTglnqtan2Mm4Wco6O18OlVgQxAIFeWSpyWv7L:Mw2YQnGan5mjV8ogfbn", "hash_imp": "4378AB751681DA98AB3B304461A9B42A", "hash_pesha1": "4D6F16240E9B0A38B39558B0880C1BDAB5E4C5F9", "hash_pe256": "2CA5257D41D042277702A5262F74889FAF0FB872E0C9566429F6E0B8B8D419D1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MS-Setup Setup Exe", "meta_original_filename": "SETUP.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "3.01 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright Microsoft Corp. 1991-1997", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/6ff2fa645dcc6db79972b2415a712565debffc2e43d5289daf3d6219ed5e6087/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\setup16.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\setup16.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Setup Initialization Error" }, "setupugc.exe-F8697B32AEE565871B6BC570C25C90A3": { "file_name": "setupugc.exe", "file_path": "C:\\Windows\\SysWOW64\\setupugc.exe", "hash_md5": "F8697B32AEE565871B6BC570C25C90A3", "hash_sha1": "8A28FEB5AB3DF88E3B28571E0D9071423F8B4A32", "hash_sha256": "7E3E17E8D56D07B33F55749F2DDF4F16A3B5C74E574449A52F8F91F796E9EE42", "hash_sha384": "60B67DF162737389BA162B4F5515D052CC8CDB2FF3B54C9850068DA68326248976CF42C5CCEB4BA15117D1C3682A02F7", "hash_sha512": "3C29AB3833473210BC6A21299C8D2CFC716F75D273E3D29AE40FAF750A333706F6F0B2FDC4979D88A8B45A6716CC22058E411298CF82E5BD28C6AEB2A632EBA9", "hash_ssdeep": "1536:i2bihsvVQWjIsCaUWO1bcj/hWmI+Lv5eaubP6+wQF0uRXXO:iyvu9sCGOm/J5Mb9w20SXXO", "hash_imp": "D378AD4D96842E8513913645DEB96870", "hash_pesha1": "2AD0E6CA2DE312FBDB19E6B64E402062E1F10EF2", "hash_pe256": "D3E35FC1B6D70857536B57CFA2CAF3A64672E4CD1326A750284DFE69BC2BA29E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Setup Unattend Generic Command Processor", "meta_original_filename": "SETUPUGC.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7e3e17e8d56d07b33f55749f2ddf4f16a3b5c74e574449a52f8f91f796e9ee42/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\setupugc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "setx.exe-5B700BC00E451033B2F9EEF349A91D1C": { "file_name": "setx.exe", "file_path": "C:\\Windows\\SysWOW64\\setx.exe", "hash_md5": "5B700BC00E451033B2F9EEF349A91D1C", "hash_sha1": "3E08F2AC69BF803AEBEB94E1E635C45E329FCE99", "hash_sha256": "84A5CE53747DDE0FBD2A9E94FD668591FBB7BDE1BBEE25A84A9E6216159DCB3A", "hash_sha384": "E3A0CC7D8043DF9616E1F221E3D6122C991081EDAE3AD95720EF0D33B2024F4A5F33D5E46652356DD4AF31C0936B13B8", "hash_sha512": "2E1CBE2EE1985AF8A9D176E5F4449165DC64206F2B51E06FBB6EADEAAA6226F6A7A5DD695A2EEE8224578AD11E59226ADB2D47D23116DB41DFD45D5CD31923F4", "hash_ssdeep": "768:4mvk3/a/BvQ6WKRdWhCUjc0juXbIbkOKrd/yrO3Xu17K+DZMwfT7CsjiyGwkEAHM:Bvk3Cl/LWFbj0bI45A+UfWijiVZIH+Na", "hash_imp": "87DEC5CA66F6F41BBF6CA5743F581342", "hash_pesha1": "79175EF31F927BA052158F6D96498A69E649E1F0", "hash_pe256": "9EF43EBEE752682100356FF57373FF32D9A17DA3E970A96777A8203F9A82FDFE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Setx - Sets environment variables", "meta_original_filename": "setx.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/84a5ce53747dde0fbd2a9e94fd668591fbb7bde1bbee25a84a9e6216159dcb3a/detection", "output": "\r\nSetX has three ways of working: \r\n\r\nSyntax 1:\r\n SETX [/S system [/U [domain\\]user [/P [password]]]] var value [/M]\r\n\r\nSyntax 2:\r\n SETX [/S system [/U [domain\\]user [/P [password]]]] var /K regpath [/M]\r\n\r\nSyntax 3:\r\n SETX [/S system [/U [domain\\]user [/P [password]]]]\r\n /F file {var {/A x,y | /R x,y string}[/M] | /X} [/D delimiters]\r\n\r\nDescription:\r\n Creates or modifies environment variables in the user or system\r\n environment. Can set variables based on arguments, regkeys or\r\n file input.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n var Specifies the environment variable to set.\r\n\r\n value Specifies a value to be assigned to the \r\n environment variable.\r\n\r\n /K regpath Specifies that the variable is set based\r\n on information from a registry key.\r\n Path should be specified in the format of\r\n hive\\key\\...\\value. For example,\r\n HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\\r\n Control\\TimeZoneInformation\\StandardName.\r\n\r\n /F file Specifies the filename of the text file\r\n to use.\r\n\r\n /A x,y Specifies absolute file coordinates\r\n (line X, item Y) as parameters to search \r\n within the file.\r\n\r\n /R x,y string Specifies relative file coordinates with\r\n respect to \"string\" as the search parameters.\r\n\r\n /M Specifies that the variable should be set in\r\n the system wide (HKEY_LOCAL_MACHINE)\r\n environment. The default is to set the\r\n variable under the HKEY_CURRENT_USER \r\n environment.\r\n\r\n /X Displays file contents with x,y coordinates.\r\n\r\n /D delimiters Specifies additional delimiters such as \",\"\r\n or \"\\\". The built-in delimiters are space,\r\n tab, carriage return, and linefeed. Any \r\n ASCII character can be used as an additional\r\n delimiter. The maximum number of delimiters,\r\n including the built-in delimiters, is 15.\r\n\r\n /? Displays this help message.\r\n\r\nNOTE: 1) SETX writes variables to the master environment in the registry.\r\n\r\n 2) On a local system, variables created or modified by this tool\r\n will be available in future command windows but not in the\r\n current CMD.exe command window.\r\n\r\n 3) On a remote system, variables created or modified by this tool\r\n will be available at the next logon session.\r\n\r\n 4) The valid Registry Key data types are REG_DWORD, REG_EXPAND_SZ,\r\n REG_SZ, REG_MULTI_SZ.\r\n\r\n 5) Supported hives: HKEY_LOCAL_MACHINE (HKLM),\r\n HKEY_CURRENT_USER (HKCU).\r\n\r\n 6) Delimiters are case sensitive.\r\n\r\n 7) REG_DWORD values are extracted from the registry in decimal \r\n format.\r\n\r\nExamples:\r\n SETX MACHINE COMPAQ \r\n SETX MACHINE \"COMPAQ COMPUTER\" /M\r\n SETX MYPATH \"%PATH%\"\r\n SETX MYPATH ~PATH~\r\n SETX /S system /U user /P password MACHINE COMPAQ \r\n SETX /S system /U user /P password MYPATH ^%PATH^% \r\n SETX TZONE /K HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\\r\n Control\\TimeZoneInformation\\StandardName\r\n SETX BUILD /K \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\r\n NT\\CurrentVersion\\CurrentBuildNumber\" /M\r\n SETX /S system /U user /P password TZONE /K HKEY_LOCAL_MACHINE\\\r\n System\\CurrentControlSet\\Control\\TimeZoneInformation\\\r\n StandardName\r\n SETX /S system /U user /P password BUILD /K \r\n \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\\r\n CurrentVersion\\CurrentBuildNumber\" /M\r\n SETX /F ipconfig.out /X \r\n SETX IPADDR /F ipconfig.out /A 5,11 \r\n SETX OCTET1 /F ipconfig.out /A 5,3 /D \"#$*.\" \r\n SETX IPGATEWAY /F ipconfig.out /R 0,7 Gateway\r\n SETX /S system /U user /P password /F c:\\ipconfig.out /X\r\n", "error": "ERROR: Invalid syntax.\r\nType \"SETX /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\setx.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "sfc.exe-4D2662964EF299131D049EC1278BE08B": { "file_name": "sfc.exe", "file_path": "C:\\Windows\\SysWOW64\\sfc.exe", "hash_md5": "4D2662964EF299131D049EC1278BE08B", "hash_sha1": "C89A23D318FADD7BEFC525EC8B396FBA42C0AD6B", "hash_sha256": "167A282DE037BCD2192205EC555890F849C4BF305CD284A763060F3332C453C6", "hash_sha384": "01291DD0A1C6CF4A1CEBC5215D0BE89839F94FD1400161D33C03DC03A057A462749023FF214658D1B5FD7FEF946975A0", "hash_sha512": "844B73A4C9D55F227FD4CACDF6634DA3BDFB992DAA5AFC5F14E1E28CB8CA9A66A4013E3835EAC934009EB35AA96664FD8D5E2380E41969810F5BB3693B7E8C44", "hash_ssdeep": "768:DQ4px32PIRdrO8Zxt6MmHgft1g8GjL6EvUio4dU03CFA2PHGTBpPPopUT:VNdr5oMmHgV1lGHfox0gPHGlpP4U", "hash_imp": "0E481D15F5D349B3A5B413EA7E093AE3", "hash_pesha1": "A300AEA0389D9C2AC2902BCBC25CC51B051A00E2", "hash_pe256": "0A64FE4CE5D824E282D92CC028C6EAD3F76F7A8CC54E5AFB39C2109AF9868A64", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Integrity Check and Repair", "meta_original_filename": "sfc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/167a282de037bcd2192205ec555890f849c4bf305cd284a763060f3332c453c6/detection", "output": "\r\r\nMicrosoft (R) Windows (R) Resource Checker Version 6.0\r\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\r\n\r\r\nScans the integrity of all protected system files and replaces incorrect versions with \r\r\ncorrect Microsoft versions.\r\r\n\r\r\nSFC [/SCANNOW] [/VERIFYONLY] [/SCANFILE=<file>] [/VERIFYFILE=<file>]\r\r\n [/OFFWINDIR=<offline windows directory> /OFFBOOTDIR=<offline boot directory> [/OFFLOGFILE=<log file path>]]\r\r\n\r\r\n/SCANNOW Scans integrity of all protected system files and repairs files with\r\r\n problems when possible.\r\r\n/VERIFYONLY Scans integrity of all protected system files. No repair operation is\r\r\n performed.\r\r\n/SCANFILE Scans integrity of the referenced file, repairs file if problems are\r\r\n identified. Specify full path <file>\r\r\n/VERIFYFILE Verifies the integrity of the file with full path <file>. No repair\r\r\n operation is performed.\r\r\n/OFFBOOTDIR For offline repair, specify the location of the offline boot directory\r\r\n/OFFWINDIR For offline repair, specify the location of the offline windows directory\r\r\n/OFFLOGFILE For offline repair, optionally enable logging by specifying a log file path\r\r\n\r\r\ne.g.\r\r\n\r\r\n sfc /SCANNOW\r\r\n sfc /VERIFYFILE=c:\\windows\\system32\\kernel32.dll\r\r\n sfc /SCANFILE=d:\\windows\\system32\\kernel32.dll /OFFBOOTDIR=d:\\ /OFFWINDIR=d:\\windows\r\r\n sfc /SCANFILE=d:\\windows\\system32\\kernel32.dll /OFFBOOTDIR=d:\\ /OFFWINDIR=d:\\windows /OFFLOGFILE=c:\\log.txt\r\r\n sfc /VERIFYONLY\r\r\n", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\sfc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "shrpubw.exe-539063395EFBB5480C0AC13CC9E5FB16": { "file_name": "shrpubw.exe", "file_path": "C:\\Windows\\SysWOW64\\shrpubw.exe", "hash_md5": "539063395EFBB5480C0AC13CC9E5FB16", "hash_sha1": "772038B6EDE76831AC02444CCD826089283FE0C0", "hash_sha256": "18F9DF881FFEB43EBF558CB5BFC2B40BB64E54A2DEE391B79CEBB10173FB41EB", "hash_sha384": "2BC340FCDB9A3D4A98134A065867A4E3B115E7E49471455783E80E662C1D6740F8161E6693DFFFD52A8DC7CF2BBCD250", "hash_sha512": "7D4CBE926EA364DAFCB7283AC78658ADC0DEE14BF41F1CD584975EA206C90511B155266B554D96175C24B3758DDFB40226BDB53C6EC9BACAC84C654C0A854550", "hash_ssdeep": "768:NXfEQgbKXSjjj/fAU7kpcyiPhZkbzKKkv6H+WnfFV6gWpMUt56Xf5rvZ/qWyIV6H:WVz/vOOsRzUyRR/q2upZm48", "hash_imp": "CB5F57CBFF541490C4351B177FF74EC2", "hash_pesha1": "45108AEA27CB6DCE1160A2176CB4E3A678A59531", "hash_pe256": "269848070598E317C3A35F12FFC0F634C12614F937A2245B1F0DEB8438339FCB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Share Creation Wizard", "meta_original_filename": "shrpubw.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/18f9df881ffeb43ebf558cb5bfc2b40bb64e54a2dee391b79cebb10173fb41eb/detection", "children": "powershell.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\shrpubw.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\aclui.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\shrpubw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Create A Shared Folder Wizard" }, "shutdown.exe-FCDE5AF99B82AE6137FB90C7571D40C3": { "file_name": "shutdown.exe", "file_path": "C:\\Windows\\SysWOW64\\shutdown.exe", "hash_md5": "FCDE5AF99B82AE6137FB90C7571D40C3", "hash_sha1": "91F6B1366737F1E71BAD6FE9DF6655882D9D968B", "hash_sha256": "DBDC6188128B32E6E3D99CD0B136FF0F0EA6CDFA2D3C748F342C5697E7BF4C58", "hash_sha384": "F2CD6CCE7DE9C78B980ACE219E3C7A941D24043FBE2C85ED42A9EEA30F8B8EDC8836B4884A9320D07454D5EC2D39576E", "hash_sha512": "6FA5BA9000E83DA160534FE597D81C60DAF9B9F85E761E515AA06E1D6E7A6D7E63453854851D52EC08B306FCB08C970539A450AD498F920874C4E92EA09C8A8F", "hash_ssdeep": "384:wmTUCPg+2lfUgpsVQ+mzM9tjz+fUpdQHW1+SWWc:w8rx2CgpsVV9tjzCUpdJ+ac", "hash_imp": "8B92347E56758D2E293224C162867097", "hash_pesha1": "28D51D773717086893CE114F72A541872E3C8F6E", "hash_pe256": "AEC954BD238BE91CCC213EC0C0A1538F5C930724DF6D46045472F5899556A4F5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Shutdown and Annotation Tool", "meta_original_filename": "SHUTDOWN.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/dbdc6188128b32e6e3d99cd0b136ff0f0ea6cdfa2d3c748f342c5697e7bf4c58/detection", "output": "Usage: C:\\Windows\\SysWOW64\\shutdown.exe [/i | /l | /s | /sg | /r | /g | /a | /p | /h | /e | /o] [/hybrid] [/soft] [/fw] [/f]\n [/m \\\\computer][/t xxx][/d [p|u:]xx:yy [/c \"comment\"]]\n\n No args Display help. This is the same as typing /?.\n /? Display help. This is the same as not typing any options.\n /i Display the graphical user interface (GUI).\n This must be the first option.\n /l Log off. This cannot be used with /m or /d options.\n /s Shutdown the computer.\n /sg Shutdown the computer. On the next boot, if Automatic Restart Sign-On\n is enabled, automatically sign in and lock last interactive user.\n After sign in, restart any registered applications.\n /r Full shutdown and restart the computer.\n /g Full shutdown and restart the computer. After the system is rebooted,\n if Automatic Restart Sign-On is enabled, automatically sign in and\n lock last interactive user.\n After sign in, restart any registered applications.\n /a Abort a system shutdown.\n This can only be used during the time-out period.\n Combine with /fw to clear any pending boots to firmware.\n /p Turn off the local computer with no time-out or warning.\n Can be used with /d and /f options.\n /h Hibernate the local computer.\n Can be used with the /f option.\n /hybrid Performs a shutdown of the computer and prepares it for fast startup.\n Must be used with /s option.\n /fw Combine with a shutdown option to cause the next boot to go to the\n firmware user interface.\n /e Document the reason for an unexpected shutdown of a computer.\n /o Go to the advanced boot options menu and restart the computer.\n Must be used with /r option.\n /m \\\\computer Specify the target computer.\n /t xxx Set the time-out period before shutdown to xxx seconds.\n The valid range is 0-315360000 (10 years), with a default of 30.\n If the timeout period is greater than 0, the /f parameter is\n implied.\n /c \"comment\" Comment on the reason for the restart or shutdown.\n Maximum of 512 characters allowed.\n /f Force running applications to close without forewarning users.\n The /f parameter is implied when a value greater than 0 is\n specified for the /t parameter.\n /d [p|u:]xx:yy Provide the reason for the restart or shutdown.\n p indicates that the restart or shutdown is planned.\n u indicates that the reason is user defined.\n If neither p nor u is specified the restart or shutdown is\n unplanned.\n xx is the major reason number (positive integer less than 256).\n yy is the minor reason number (positive integer less than 65536).\n\nReasons on this computer:\n(E = Expected U = Unexpected P = planned, C = customer defined)\nType\tMajor\tMinor\tTitle\n\n U \t0\t0\tOther (Unplanned)\nE \t0\t0\tOther (Unplanned)\nE P \t0\t0\tOther (Planned)\n U \t0\t5\tOther Failure: System Unresponsive\nE \t1\t1\tHardware: Maintenance (Unplanned)\nE P \t1\t1\tHardware: Maintenance (Planned)\nE \t1\t2\tHardware: Installation (Unplanned)\nE P \t1\t2\tHardware: Installation (Planned)\nE \t2\t2\tOperating System: Recovery (Unplanned)\nE P \t2\t2\tOperating System: Recovery (Planned)\n P \t2\t3\tOperating System: Upgrade (Planned)\nE \t2\t4\tOperating System: Reconfiguration (Unplanned)\nE P \t2\t4\tOperating System: Reconfiguration (Planned)\n P \t2\t16\tOperating System: Service pack (Planned)\n \t2\t17\tOperating System: Hot fix (Unplanned)\n P \t2\t17\tOperating System: Hot fix (Planned)\n \t2\t18\tOperating System: Security fix (Unplanned)\n P \t2\t18\tOperating System: Security fix (Planned)\nE \t4\t1\tApplication: Maintenance (Unplanned)\nE P \t4\t1\tApplication: Maintenance (Planned)\nE P \t4\t2\tApplication: Installation (Planned)\nE \t4\t5\tApplication: Unresponsive\nE \t4\t6\tApplication: Unstable\n U \t5\t15\tSystem Failure: Stop error\n U \t5\t19\tSecurity issue (Unplanned)\nE \t5\t19\tSecurity issue (Unplanned)\nE P \t5\t19\tSecurity issue (Planned)\nE \t5\t20\tLoss of network connectivity (Unplanned)\n U \t6\t11\tPower Failure: Cord Unplugged\n U \t6\t12\tPower Failure: Environment\n P \t7\t0\tLegacy API shutdown\n", "error": "Hibernation is not enabled on this system. You must enable hibernation in order to use the -h option.(126)\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\shutdown.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SndVol.exe-7D7D5466FCDCD28976A004B5B08864E3": { "file_name": "SndVol.exe", "file_path": "C:\\Windows\\SysWOW64\\SndVol.exe", "hash_md5": "7D7D5466FCDCD28976A004B5B08864E3", "hash_sha1": "FD4BB675F7DE68865596BA61759FFB1BED8716F5", "hash_sha256": "F9555FD7F2A7CE9EE6B5CE664762D1292908AC4C04C0D28C8ECC25EDC26435FA", "hash_sha384": "67D17FB8BEA7BA50256C5749C670E7A154AD6B69D3A12A4F7959083EF2C6DD8C56EEF288F88303020D5E566DDBAF5C7A", "hash_sha512": "5446CDCB45C4F088A994626CE32198B8328AF9D574FBD707ED37E27E403AEF94C085878E085639D2FE269103E9FB69E93C4922A0A878D86A15BAAF7A6BD69840", "hash_ssdeep": "3072:isaDAe8badZ1CILnv2xx9Nuxe+juLmf5Y5eP0RflQ/e0vkgjbEyB7HbITGF:ima0U2dNke+juLYD/dWy10S", "hash_imp": "5F3F3778A963E0C44DCFB0F587F80B8A", "hash_pesha1": "BAA36452A6EEFCE52BA444C0996711CB5E68E1BE", "hash_pe256": "A921F7472C784C96BDE0AAF6B422300398416C73D764C64CCA4CCB25142EC208", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Volume Mixer", "meta_original_filename": "SndVol.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/f9555fd7f2a7ce9ee6b5ce664762d1292908ac4c04c0d28c8ecc25edc26435fa/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_4299dbb28a92ae3e": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sndvol.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\wdmaud.drv.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SndVol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Volume Mixer - Remote Audio" }, "sort.exe-D0D6250804C3102A17051406BBDBF3D6": { "file_name": "sort.exe", "file_path": "C:\\Windows\\SysWOW64\\sort.exe", "hash_md5": "D0D6250804C3102A17051406BBDBF3D6", "hash_sha1": "F051AEE1679707D4791B324496CED9649103F821", "hash_sha256": "A0A4FB16F2E2469624E82D6F87C5180B40D6213C3A993B0A85E391BE1B149897", "hash_sha384": "7BA43D88FFA1E8C85F7C22DF9F71ED3A8014CCBA1597A95E8BC6ADCDF2E80766E26A07A3A630F5F133519FDC1CDBC43A", "hash_sha512": "CF9AACAAAFF2C4C1C8580CF201DDA03EF201CF71AA906A1873865DD1208E28502A1B913071CD946FF50899F76E8D34AFEA2F7AEA04743BC0E6EF299A9A0A7CF9", "hash_ssdeep": "384:qMBv6ZC+xjpPpEPzMcTJWUm8hWIc570eZHEb2CS0yxGMOfWMnWyr2:qMBslB/cTph8IxS08GpXLr", "hash_imp": "C30764D4D528C7CFA9CAA068FBEFF18D", "hash_pesha1": "88DF1F714618CCDE88A71C545A071E53C52CD23B", "hash_pe256": "8535737F442795D811C66DC02BD14DDEB16E1F3944281C952BAFD7656778D132", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Sort Utility", "meta_original_filename": "Sort.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a0a4fb16f2e2469624e82d6f87c5180b40d6213c3a993b0a85e391be1b149897/detection", "output": "SORT [/R] [/+n] [/M kilobytes] [/L locale] [/REC recordbytes]\r\r\n [[drive1:][path1]filename1] [/T [drive2:][path2]]\r\r\n [/O [drive3:][path3]filename3]\r\r\n /+n Specifies the character number, n, to\r\r\n begin each comparison. /+3 indicates that\r\r\n each comparison should begin at the 3rd\r\r\n character in each line. Lines with fewer\r\r\n than n characters collate before other lines.\r\r\n By default comparisons start at the first\r\r\n character in each line.\r\r\n /L[OCALE] locale Overrides the system default locale with\r\r\n the specified one. The \"\"C\"\" locale yields\r\r\n the fastest collating sequence and is\r\r\n currently the only alternative. The sort\r\r\n is always case insensitive.\r\r\n /M[EMORY] kilobytes Specifies amount of main memory to use for\r\r\n the sort, in kilobytes. The memory size is\r\r\n always constrained to be a minimum of 160\r\r\n kilobytes. If the memory size is specified\r\r\n the exact amount will be used for the sort,\r\r\n regardless of how much main memory is\r\r\n available.\r\r\n\r\r\n The best performance is usually achieved by\r\r\n not specifying a memory size. By default the\r\r\n sort will be done with one pass (no temporary\r\r\n file) if it fits in the default maximum\r\r\n memory size, otherwise the sort will be done\r\r\n in two passes (with the partially sorted data\r\r\n being stored in a temporary file) such that\r\r\n the amounts of memory used for both the sort\r\r\n and merge passes are equal. The default\r\r\n maximum memory size is 90% of available main\r\r\n memory if both the input and output are\r\r\n files, and 45% of main memory otherwise.\r\r\n /REC[ORD_MAXIMUM] characters Specifies the maximum number of characters\r\r\n in a record (default 4096, maximum 65535).\r\r\n /R[EVERSE] Reverses the sort order; that is,\r\r\n sorts Z to A, then 9 to 0.\r\r\n [drive1:][path1]filename1 Specifies the file to be sorted. If not\r\r\n specified, the standard input is sorted.\r\r\n Specifying the input file is faster than\r\r\n redirecting the same file as standard input.\r\r\n /T[EMPORARY]\r\r\n [drive2:][path2] Specifies the path of the directory to hold\r\r\n the sort's working storage, in case the data\r\r\n does not fit in main memory. The default is\r\r\n to use the system temporary directory.\r\r\n /O[UTPUT]\r\r\n [drive3:][path3]filename3 Specifies the file where the sorted input is\r\r\n to be stored. If not specified, the data is\r\r\n written to the standard output. Specifying\r\r\n the output file is faster than redirecting\r\r\n standard output to the same file.\r\r\n\r\n", "error": "Invalid switch.\r\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\sort.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SpatialAudioLicenseSrv.exe-CDFCD3099F7B36BDFFFEE84145FBE067": { "file_name": "SpatialAudioLicenseSrv.exe", "file_path": "C:\\Windows\\SysWOW64\\SpatialAudioLicenseSrv.exe", "hash_md5": "CDFCD3099F7B36BDFFFEE84145FBE067", "hash_sha1": "F72DDBED742196E124585661FA530F3543DF8C7D", "hash_sha256": "61D656F74DB78E231CF43671F4BBA789BFA1128FE267CDFD540E147065E58E79", "hash_sha384": "60FB51665353DCD4DAE9E148AB75AE9402E6744F5F3365929D9BCA0D00E68F50A102927C1F0285136783A1BF502ADC33", "hash_sha512": "DF22C3B0FF8997B87EE458AD980755BBF5731DBB525C19C72280C7D6E236F8DBF79BA22D7FEA04F6B48024051DB41E784FEAC3F2A3C646F4FA1D4D32AE171CBA", "hash_ssdeep": "3072:GjsBvkPpIAP5S7gZ0WB5VdyrRh7vs/zm5k4cZfliBMv:5GINPAzDNsU", "hash_imp": "885BEB9A291DC4D4E543D5D866FE82F2", "hash_pesha1": "7D29B433C4A1C31667085D92E9EADBCC42CFE049", "hash_pe256": "AA4FC78B55D8658F755681DAE775DB57083145A575BAD3557371885571A217A1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Spatial License AppService Broker", "meta_original_filename": "SpatialLicenseSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/61d656f74db78e231cf43671f4bba789bfa1128fe267cdfd540e147065e58e79/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SpatialAudioLicenseSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "srdelayed.exe-B5F31FDCE1BE4171124B9749F9D2C600": { "file_name": "srdelayed.exe", "file_path": "C:\\Windows\\SysWOW64\\srdelayed.exe", "hash_md5": "B5F31FDCE1BE4171124B9749F9D2C600", "hash_sha1": "84F9510B30BAB5F45FD2EE30EAB7F998B3372EFB", "hash_sha256": "F5F969345107E3B968C539106F6D759D440D264619E798A762BE30B63E3FDF17", "hash_sha384": "C810B53A4878A98679B805700D6729CC706E6061118E1DCA254E25047F91CC51B08B6C696FA2D2D9168D186A4B761253", "hash_sha512": "2B3D3D39D4FA6A1CA5FBD91BF8254D404F293B8D3232D3EA19DA153BECB273720F4D9C9E97BC35713F6FE6DC1F9346460DE55957DEF19C52D81B383650C6E376", "hash_ssdeep": "384:14cOISuNQSl2IubsCe0HCEfyIW16pZuXmwW19oW:plNzl2IgflVW1CZuW5", "hash_imp": "831BD17F96AA64BD895D9C5C62C92318", "hash_pesha1": "731680AA0A20B20B9C8A340BA6D8931C97720B66", "hash_pe256": "4877F40244D2923DD54A13D17E9D455C88525F1D1136A1D6D5D8198988B1EB46", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows System Restore Delayed File Renamer", "meta_original_filename": "srdelayed.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/f5f969345107e3b968c539106f6d759d440d264619e798a762be30b63e3fdf17/detection" }, "stordiag.exe-1F08FC87C373673944F6A7E8B18CD845": { "file_name": "stordiag.exe", "file_path": "C:\\Windows\\SysWOW64\\stordiag.exe", "hash_md5": "1F08FC87C373673944F6A7E8B18CD845", "hash_sha1": "EB78E97DEE03DC3C2F744A408087AD79FD067219", "hash_sha256": "B812162F140A347EC78756416302CBC9204EF484FEB7623C0FFF8FF7B4B3EC04", "hash_sha384": "5FFFDC39EDC75FD6AB1DA10CCA1CBEAD3FAD3A90C0A6105A59BB0165B40708C4C1A177EFD88713535B7B3744A9274793", "hash_sha512": "428CE4A0C9413D94EA1F9C041C6BA2282D017C6BDE36A28EC96679D439D8202A35AA7D652A78D8C710485C0006F7213E64C7D293BBA103FF3165E5298C804023", "hash_ssdeep": "1536:qwYYQyn8M801RXnItvNCl/iBeKiZfbOZE4RS8JRFahdqb3BuS:jY28M806enfbOZE4I8JRFEYb3BuS", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "A5E5500ACB8F0080F5C37EDDD4E326A39FF84A74", "hash_pe256": "FA81CDCA613277A54823444E28467F1EAB38646AC9AE57FAAE496F1A289E70CF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "stordiag.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b812162f140a347ec78756416302cbc9204ef484feb7623c0fff8ff7b4b3ec04/detection", "output": "\r\nCollects storage and filesystem diagnostic logs and outputs them to a folder.\r\n\r\nStorDiag [-collectEtw] [-out <PATH>]\r\n-collectEtw Collect a 30-second long ETW trace if run from an elevated session\r\n-collectPerf Collect disk performance counters\r\n-collectStorageBreakdown Collect system volume used space breakdown\r\n-checkFSConsistency Checks for the consistency of the NTFS file system\r\n-diagnostic outputs a storage diagnostic report\r\n-bootdiag output boot sectors of the disk\r\n-driverdiag output avaliable storport and storahci logs\r\n-out <PATH> Specify the output path. If not specified, logs are saved to %TEMP%\\StorDiag\r\n\r\n\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_5348": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Management\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Management.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R--) C:\\Users\\user\\AppData\\Local\\Temp\\StorDiag\\PSLogs.txt": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.Commands.Diagnostics\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.Commands.Diagnostics.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Management.Automation\\v4.0_3.0.0.0__31bf3856ad364e35\\System.Management.Automation.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Core\\v4.0_4.0.0.0__b77a5c561934e089\\System.Core.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration.Install\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.Install.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.ConsoleHost\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.ConsoleHost.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.Security\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.Security.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.Commands.Utility\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.Commands.Utility.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.Commands.Management\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.Commands.Management.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.Management.Infrastructure\\v4.0_1.0.0.0__31bf3856ad364e35\\Microsoft.Management.Infrastructure.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.ServiceProcess\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.ServiceProcess.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.WSMan.Management\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.WSMan.Management.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\stordiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "subst.exe-074106AE38474F73BB1B11F53309203D": { "file_name": "subst.exe", "file_path": "C:\\Windows\\SysWOW64\\subst.exe", "hash_md5": "074106AE38474F73BB1B11F53309203D", "hash_sha1": "558786B4E646B138E3A75FEB456A494A2588CE38", "hash_sha256": "2AEF2B8B7896FD5A0F2DA5781521B60D2FBF1AB361B0CE64AE8EEEB6C8E21AEB", "hash_sha384": "6D57DC0145FB474ABA3F17437E96C702EF318360186E7A318E7F9B193741D998E090B76403CC6CD5EF212ECE1E928271", "hash_sha512": "99AAE69EC4359AA56F68E228E545B9E07E85689ED904068B0AAA964E9F489ECE5A6B94AB7AECB1011BABCCD2B36F0113765470DE8A7AACE96EBFD7D20136393E", "hash_ssdeep": "192:ZqScdC+ZvdPAe5B2WVYtkGplhEdgwtjkdzQkJWzGWneD:cSc8+Zv1AyIUZGplhmg0jAJWzGWn", "hash_imp": "7DD76573763F447C2EF4E1C30B281996", "hash_pesha1": "B9846A082ABB29C83D238BDDAA7EC642B7EB676D", "hash_pe256": "8C0FD98BE2F4978AAA9DD542CD0DDB4A6D25AC274796302C906DE8C89410DD84", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Subst Utility", "meta_original_filename": "Subst.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2aef2b8b7896fd5a0f2da5781521b60d2fbf1ab361b0ce64ae8eeeb6c8e21aeb/detection", "output": "Associates a path with a drive letter.\r\n\r\nSUBST [drive1: [drive2:]path]\r\nSUBST drive1: /D\r\n\r\n drive1: Specifies a virtual drive to which you want to assign a path.\r\n [drive2:]path Specifies a physical drive and path you want to assign to\r\n a virtual drive.\r\n /D Deletes a substituted (virtual) drive.\r\n\r\nType SUBST with no parameters to display a list of current virtual drives.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\subst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "svchost.exe-B7C999040D80E5BF87886D70D992C51E": { "file_name": "svchost.exe", "file_path": "C:\\Windows\\SysWOW64\\svchost.exe", "hash_md5": "B7C999040D80E5BF87886D70D992C51E", "hash_sha1": "A8ED9A51CC14CCF99B670E60EBBC110756504929", "hash_sha256": "5C3257B277F160109071E7E716040E67657341D8C42AA68D9AFAFE1630FCC53E", "hash_sha384": "555219A415D9D0171DCECC3C1790D0A2C044C7FEF75E2EB2F5EF9E47FF988833C0C9485828F1FB80B607554C59D4F484", "hash_sha512": "71BA2FBD705E51B488AFE3BB33A67212CF297E97E8B1B20ADA33E16956F7EC8F89A79E04A4B256FD61A442FADA690AFF0C807C2BDCC9165A9C7BE3DE725DE309", "hash_ssdeep": "768:c2WS98tkOTFhAjOnKFURDsVRqmEvnMqvjZCu8HVTg4SR5KLY1PKH8://StkOTnAjOfARvan9Z0tgHEgP7", "hash_imp": "31245021771B01BCA0BE49250BDAA032", "hash_pesha1": "D4508455776A35AF654360D824EA41998A788DB4", "hash_pe256": "AD1573A8271B2D8EEC77D00158744E264A2BFAFD8792186DF5B18927B6361411", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Windows Services", "meta_original_filename": "svchost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5c3257b277f160109071e7e716040e67657341d8c42aa68d9afafe1630fcc53e/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\svchost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "sxstrace.exe-AC788961CF9E2CB97D0089A21EB5173E": { "file_name": "sxstrace.exe", "file_path": "C:\\Windows\\SysWOW64\\sxstrace.exe", "hash_md5": "AC788961CF9E2CB97D0089A21EB5173E", "hash_sha1": "D6EBB4F71EEDDF97DDA88EF8E50197BE44469AE7", "hash_sha256": "55E0805F0BEB5D8D1B395A9000599CED21A8CC9B824F2A2FA4CEEC0DCFA88D8B", "hash_sha384": "7E4A78AB58D915338F0CF990721CE7B1E46F1A5AB4AB5A42E11A3A6E95C2A098300DB724F54A4256EC567F887A7F9C59", "hash_sha512": "C63297EC2C1B0DA7091D191526A840D95A10C24BB3724ECF9F3508FDB79F6841DCFE14894A737410B71BD1B17958DFB3907EA59C1D46DBD171760CDFCA0F87E3", "hash_ssdeep": "384:8Kj6d1wF3TSsbFO7lS5NVyjjGvLkRRShKiNj8BGDT0GFcTFLFttrWXqQw+sNdua4:LISpMuy/pru0Gu5lrH7mltf/HD", "hash_imp": "E5F700CF708ED01F967809EB3E520C38", "hash_pesha1": "67DF17D8A02789BE58D0B82F87999E6061844A69", "hash_pe256": "57F276C589B64A434EC7A48FE13B8D5E5DAB47955400B2CC65D9250862A8D137", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Sxs Tracing Tool", "meta_original_filename": "sxstrace.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/55e0805f0beb5d8d1b395a9000599ced21a8cc9b824f2a2fa4ceec0dcfa88d8b/detection", "output": "WinSxs Tracing Utility.\r\nUsage: SxsTrace [Options]\r\nOptions:\r\n Trace -logfile:FileName [-nostop]\r\n Enabling tracing for sxs.\r\n Tracing log is saved to FileName.\r\n If -nostop is specified, will not prompt to stop tracing.\r\n Parse -logfile:FileName -outfile:ParsedFile [-filter:AppName]\r\n Translate the raw trace file into a human readable format and save the result to ParsedFile.\r\n Use -filter option to filter the output.\r\n Stoptrace\r\n Stop the trace if it is not stopped before.\r\nExample: SxsTrace Trace -logfile:SxsTrace.etl\r\n SxsTrace Parse -logfile:SxsTrace.etl -outfile:SxsTrace.txt\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\sxstrace.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SyncHost.exe-0BACFCE2339AAF205B5D99073C0191EE": { "file_name": "SyncHost.exe", "file_path": "C:\\Windows\\SysWOW64\\SyncHost.exe", "hash_md5": "0BACFCE2339AAF205B5D99073C0191EE", "hash_sha1": "5344FAE79ED3B81BDF45D75D53B5D6C646BD419A", "hash_sha256": "706B4F7CDD4F85E604DDC69FE8D4FAAE2401B41C1EBD1186266B6AB0AAA2BD79", "hash_sha384": "58782434985DD72F049FD123FC91CCDBD15C475B92326E5D05801EF83787472B03C8C8C5215CE22769E327939343C206", "hash_sha512": "76386715C1A1D378814551CEA24713B9E22B66EC49394232607687970D6E2FBF16A17AD1808FB466DEA66AB615FBAF36BDF6A5A49E29FEF409CD7C59BFA857FD", "hash_ssdeep": "768:b45QXE5H6A1h+HicJJwtY+BTKmqfS770UtKMVOr0ieA0O:keEFh+HicJJwtRd0fSptkd0", "hash_imp": "DA44A81E79B6C3BEC0D978860B3682DC", "hash_pesha1": "CB2F6E7BC99467970490217C01B2CF09B3254835", "hash_pe256": "74036A5D19EC37AE25F071CDE03959F441149D44D593F85B4887C7F037806F24", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Windows Sync", "meta_original_filename": "SyncHost.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/706b4f7cdd4f85e604ddc69fe8d4faae2401b41c1ebd1186266b6ab0aaa2bd79/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SyncHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "systeminfo.exe-36CCB1FFAFD651F64A22B5DA0A1EA5C5": { "file_name": "systeminfo.exe", "file_path": "C:\\Windows\\SysWOW64\\systeminfo.exe", "hash_md5": "36CCB1FFAFD651F64A22B5DA0A1EA5C5", "hash_sha1": "DC4CA5BBB894ED8E708BC40129C150C2771F3987", "hash_sha256": "F1E43F167059FF746E200B21DDC55326CD8B3ACD7D6BD9C541230DB6F8BC63D1", "hash_sha384": "B91D74201D439AE87F57B16882C088415E41781777C2BE9D40975ABB9E27C1505576EDA9EFD0EE8DF97D4BB701ACA682", "hash_sha512": "137AED54900DD441E88C388CC61A844B46F1F9E853FE0A29A5530931EDD97B90EB4F4A0A6861AA1E3E5C67055A1E5C0EA49380744E5F4818992C7503E6A94627", "hash_ssdeep": "1536:pHJiQWrRyhhyhQBb5qcQLKy94abf2hq04dHc4xiGsTFZ3dxNm9:uruBFq3Ky94p404dHcaiv73dxk9", "hash_imp": "601A2206AC4AA1CC36827CB12020D401", "hash_pesha1": "B346807AE10500A2C18E845D43AE3C365FCCB3D1", "hash_pe256": "A075A0B0C337D65BEBBBECE0D3906DA5C3FC6D79CAC9FFD1BC86497ADAC4F3EF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays system information", "meta_original_filename": "sysinfo.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f1e43f167059ff746e200b21ddc55326cd8b3acd7d6bd9c541230db6f8bc63d1/detection", "output": "\r\nSYSTEMINFO [/S system [/U username [/P [password]]]] [/FO format] [/NH]\r\n\r\nDescription:\r\n This tool displays operating system configuration information for\r\n a local or remote machine, including service pack levels.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /FO format Specifies the format in which the output\r\n is to be displayed.\r\n Valid values: \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" should\r\n not be displayed in the output.\r\n Valid only for \"TABLE\" and \"CSV\" formats.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n SYSTEMINFO\r\n SYSTEMINFO /?\r\n SYSTEMINFO /S system\r\n SYSTEMINFO /S system /U user\r\n SYSTEMINFO /S system /U domain\\user /P password /FO TABLE\r\n SYSTEMINFO /S system /FO LIST\r\n SYSTEMINFO /S system /FO CSV /NH\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"SYSTEMINFO /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\systeminfo.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemPropertiesAdvanced.exe-26230E6CBB94363405DCA88E06C96C12": { "file_name": "SystemPropertiesAdvanced.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesAdvanced.exe", "hash_md5": "26230E6CBB94363405DCA88E06C96C12", "hash_sha1": "45526CE11BD5D10073B2DA21B608A8DFA652A80A", "hash_sha256": "3C52E817A18EFD5670C1B8A2FEBBA53673DC70875271933C075116990EF0C255", "hash_sha384": "79F1A7BB5FD0FCD539592E73175FC2F4E8AFE5386D853991DA5C4E5BBA0D2B73CCCE188DA39301A87A633F01B6497172", "hash_sha512": "FD188FA79D341F717E920536B177D8C17626FC5AEE005CF5096DF3887602C67096E102297DF3F91765C5A01A8A6A85C753F7837C88E0FA4059E1945491BF622A", "hash_ssdeep": "1536:6fdZERtREC/rMcgEPJV+G57ThjEC0kzJP+V5Jaa:6HCzECTMpuDhjRVJGk", "hash_imp": "B788892AE84BA86201A726810F01CB07", "hash_pesha1": "B1D08414DC2340F49D0E9DB928F8AFCEC3C43E00", "hash_pe256": "BD6A64B619BBEB72CF6F76F7366C97E229BE54C95398E44BE1A98099E7112EF4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Advanced System Settings", "meta_original_filename": "SystemPropertiesAdvanced.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3c52e817a18efd5670c1b8a2febba53673dc70875271933c075116990ef0c255/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesAdvanced.exe.mui": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesAdvanced.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemPropertiesComputerName.exe-FE7C7F2202A9288E3580423C41546AAB": { "file_name": "SystemPropertiesComputerName.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesComputerName.exe", "hash_md5": "FE7C7F2202A9288E3580423C41546AAB", "hash_sha1": "D8B114AF6168FCFE5FFB5785D676600DE3C3BACA", "hash_sha256": "AEF9CB5CDA480566B3A8E1E0267F31D52F2B48B96CD3D04006B69345EB207820", "hash_sha384": "080FF246918B35D594F55DEC086F2403EB704DE09FDD15F6AAB064F6B49A2674D3EE47BE5C4D8B7162EAADDDA0024F62", "hash_sha512": "EDDDAA16CE8A3762CDAB72B07CD83894A4342232863845A2712366596836476DDF24904C4D448AD261E300397DF6611A796C4DB8320723F1119B7757A8E83721", "hash_ssdeep": "1536:mfdZKtREC/rMcgEPJV+G57ThjEC0kzJP+V5JuM:mHKzECTMpuDhjRVJGY", "hash_imp": "B788892AE84BA86201A726810F01CB07", "hash_pesha1": "3FCC61A4BA340227AE4409D47E060E11943D85F1", "hash_pe256": "1F0F4192FF283DA45F0F80CD07B71C5307AAD58CB442254801C95D8747E2C29C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Computer Settings", "meta_original_filename": "SystemPropertiesComputerName.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/aef9cb5cda480566b3a8e1e0267f31d52f2b48b96cd3d04006b69345eb207820/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesComputerName.exe.mui": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesComputerName.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll" ] }, "SystemPropertiesDataExecutionPrevention.exe-3C6B37E0CCCBC6671B92B2DF77BD3760": { "file_name": "SystemPropertiesDataExecutionPrevention.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesDataExecutionPrevention.exe", "hash_md5": "3C6B37E0CCCBC6671B92B2DF77BD3760", "hash_sha1": "1FFF021EE069B0341723360843C251FC5FDB681A", "hash_sha256": "58B01EACA5604FC46B170AA8C6EAC22C7B9DDC00CED8F1832530907DF2EC4189", "hash_sha384": "679B59BCBA92D094303EE10226274F4C43300CED5E929D8939FE8779DBA54B0F56F6DD5D2DBCD62FFA599125BD3C3D86", "hash_sha512": "44EB922873F65740C6F421D787B65CECE6ECF44F2699FF22FAF43F92F93C74B5BDCC776864527920CC62D9B3769FB5C79ABCF88BFD2448C03EF4002ACC920D33", "hash_ssdeep": "1536:YfdZKtREC/rMcgEPJV+G57ThjEC0kzJP+V5JfH:YHKzECTMpuDhjRVJGJ", "hash_imp": "B788892AE84BA86201A726810F01CB07", "hash_pesha1": "94BD1AD8FC34334703F9DE5EF4069120A1615CF8", "hash_pe256": "32479AD66D1E35B6D4FF34A8CF26708C91D4FB3BBFB60F25E51DC068324D42E7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Data Execution Prevention Settings", "meta_original_filename": "SystemPropertiesDataExecutionPrevention.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/58b01eaca5604fc46b170aa8c6eac22c7b9ddc00ced8f1832530907df2ec4189/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesDataExecutionPrevention.exe.mui": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesDataExecutionPrevention.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemPropertiesHardware.exe-B29A86F8E1B0EFF3E61FC3E43C7897AC": { "file_name": "SystemPropertiesHardware.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesHardware.exe", "hash_md5": "B29A86F8E1B0EFF3E61FC3E43C7897AC", "hash_sha1": "E6596DD5AB131CF9E7B613A946E43741DD923DCE", "hash_sha256": "803DB9536D3B097D4CD99F9D218E9327EC0F1E0683F1399F701F35BCE423FFCC", "hash_sha384": "4B85A723B51D22C5CAD2AB8A5C8B9C47FFEDDB607C30A582AB6AE7D366D79D8E168C97230A59FDD371BD3CC744461836", "hash_sha512": "ACDBE81B5B16B772022E1F386445B0A0F22630E1D3D772069A05C14E4AA0080BF8C3BFCA6E63A14085E904A8FC09298B9C1D24231D808C96A9D9BCCE56448A37", "hash_ssdeep": "1536:OfdZUFtREC/rMcgEPJV+G57ThjEC0kzJP+V5JXj:OH2zECTMpuDhjRVJGB", "hash_imp": "B788892AE84BA86201A726810F01CB07", "hash_pesha1": "53B3DB366B0AB218C5E66ECB81A669BDD0BFCA90", "hash_pe256": "F92AF6CF5447C788A7DA4A3B5AB9B77678E4D48E4F2EC88AE173C28B2598B927", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hardware Settings", "meta_original_filename": "SystemPropertiesHardware.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/803db9536d3b097d4cd99f9d218e9327ec0f1e0683f1399f701f35bce423ffcc/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesHardware.exe.mui": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesHardware.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemPropertiesPerformance.exe-52731F569118C488693E02C199A3DB77": { "file_name": "SystemPropertiesPerformance.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesPerformance.exe", "hash_md5": "52731F569118C488693E02C199A3DB77", "hash_sha1": "3230EA727E9983177CB3AB4E74EF688B94006891", "hash_sha256": "87D18B8AC27C3A0510B194FD6D5F36FE0AAFACB9F57F723E98AA6874DCA501FC", "hash_sha384": "761555EC77CDB9D2E913629C985DCB6098DBC4624E7C27F5E10E2D470E3BA78BE295CCFC0C3FF786D28BD136FB15CDA9", "hash_sha512": "0D258196C1A07924F1A9330F7F41098D45AF5C43371AD26BB88EA4BA42193B16F457369F2215212202A2DB0DF224B7ADC707F6D5B150A1890CEF06F004D60FE0", "hash_ssdeep": "1536:E5ZUtREC/rMcgEPJV+G57ThjEC0kzJP+V5JS:6UzECTMpuDhjRVJGc", "hash_imp": "0C021C23DE2070C3C89AA72CC7E919E9", "hash_pesha1": "7354D27F00F163A8A111B7593A9CD8280551B6A0", "hash_pe256": "7AA215C167D8A81A89BBDB54F376E0B60B6E4C1060E21A31149EB3B259E035A7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Computer Performance Settings", "meta_original_filename": "SystemPropertiesPerformance.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/87d18b8ac27c3a0510b194fd6d5f36fe0aafacb9f57f723e98aa6874dca501fc/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesPerformance.exe.mui": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\SystemResources\\shell32.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesPerformance.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemPropertiesProtection.exe-C10866CE474947F1842777D8E34315DD": { "file_name": "SystemPropertiesProtection.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesProtection.exe", "hash_md5": "C10866CE474947F1842777D8E34315DD", "hash_sha1": "8DE50722C833B82DCA0D8C9BFBE43B5EF95738AA", "hash_sha256": "64D46A44784B59500BE52A0E7F8F2B8ACC2FA679115C31C9DEFA04511662D8AA", "hash_sha384": "3469467984FB4EBF97333BD1BA2CD446EDDA1951C686A04E05A6E05FE164ACAE39BE587C4473458F068AC4E89F597D5D", "hash_sha512": "B4A9144F2810B85862B795CD45395B859BD73392DC3C379412F34665DE9FAD067D45D179FDE0813E10010C36C3601726F40B251AC15409C2F7150AD12DD1D50D", "hash_ssdeep": "1536:qfdZ2tREC/rMcgEPJV+G57ThjEC0kzJP+V5JPH:qH2zECTMpuDhjRVJGF", "hash_imp": "B788892AE84BA86201A726810F01CB07", "hash_pesha1": "DD9A26189ED4179A8F2E7197269FD6114C1243E2", "hash_pe256": "E71F004844A013910D440915075FF5D1B93350DA252221965F603F4F5716CF9A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Protection Settings", "meta_original_filename": "SSystemPropertiesProtection.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/64d46a44784b59500be52a0e7f8f2b8acc2fa679115c31c9defa04511662d8aa/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesProtection.exe.mui": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesProtection.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemPropertiesRemote.exe-0DE57A0B7FB7DA84154D92A1B5770873": { "file_name": "SystemPropertiesRemote.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesRemote.exe", "hash_md5": "0DE57A0B7FB7DA84154D92A1B5770873", "hash_sha1": "E53C34C8A5E91EBACCBA44D44DD0E15A3644CEAB", "hash_sha256": "75F0B2B0123CDAC9D250BCB51BCD79332E2ECC9F371850C058246D80C9886B6A", "hash_sha384": "A2C576FD371BFB7E4F91D175E0C245F906B5572D6FEBC8878926876BEC65DF935A1463B8710F665610438EA8D5537D00", "hash_sha512": "CE11C5848D1446061066EEF51C2FE146207A873B5C879703B558124D71737D684FEEBB9090D4C4AC9B761DFF79F6C50741857F83C86F9F373999C016D3CC1E4D", "hash_ssdeep": "1536:efMZsztREC/rMcgEPJV+G57ThjEC0kzJP+V5Jx:eOAzECTMpuDhjRVJGf", "hash_imp": "B788892AE84BA86201A726810F01CB07", "hash_pesha1": "049CF851A767B3D4ED61EC869F493F036E8BDA4C", "hash_pe256": "1356EF94D6BA4DA9DDA29F71D5AE146FEB83000083CEB47E47558EEEF0CB2317", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Remote Settings", "meta_original_filename": "SystemPropertiesRemote.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/75f0b2b0123cdac9d250bcb51bcd79332e2ecc9f371850c058246d80c9886b6a/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesRemote.exe.mui": "File", "(R-D) C:\\Windows\\SystemResources\\sysdm.cpl.mun": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_4299dbb28a92ae3e": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesRemote.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemUWPLauncher.exe-97FAEDBADBABF81D2B63383C0E563F45": { "file_name": "SystemUWPLauncher.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemUWPLauncher.exe", "hash_md5": "97FAEDBADBABF81D2B63383C0E563F45", "hash_sha1": "999A00EE03C6ACAFF564EE33C00A333EB3745736", "hash_sha256": "393462F20A4892225D4634B67A586F019B98C0A36A6966D2F9D2B9EE81711A4D", "hash_sha384": "89C78CDD394A4FA56ADF738B3A2112E40D08A7B169A0D5071FC9CBD5CDC6C118C0C035F9ADDC1A077697D208108EF9C1", "hash_sha512": "6C4ED140C5AA27DAD586A751B336A9AB7AAAA01EA6B8C9378DFB17F1A6967A09E61AA1AA77EF90AAAFAFA6218C5F73685A7D958ED8EDCAA92FA27C363821D8B3", "hash_ssdeep": "768:hqiz3rR5l4xdk+UhJVc/kzDzQ1srqwQ91VRZbQidlNFRu+kLy0x69iheP4Ny7wZ:hqy95N+yJOKQ1NZbQOkLy0Ci8P4o7w", "hash_imp": "281BD2F6F29211E81DC9BDF2B7F3E971", "hash_pesha1": "B41197B7A674CB7DE06474E5A4754A3A42507B55", "hash_pe256": "8555629388E9F9155D254F73030D68FCFDC9C341737B1289C67ADE26B8AF61A3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SystemUWPLauncher", "meta_original_filename": "SystemUWPLauncher.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.388 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.388", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/393462f20a4892225d4634b67a586f019b98c0a36a6966d2f9d2b9ee81711a4d/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemUWPLauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "systray.exe-28D565BB24D30E5E3DE8AFF6900AF098": { "file_name": "systray.exe", "file_path": "C:\\Windows\\SysWOW64\\systray.exe", "hash_md5": "28D565BB24D30E5E3DE8AFF6900AF098", "hash_sha1": "E255EAFC27B374A4489202A6C741E2CB53095A4F", "hash_sha256": "B1A7169522D690DBE3AD77604913637DC457C4885EBEDBDDFB1419B366099204", "hash_sha384": "410C5227571A9EF0FA870C83714B66F8B941DA24E0CF84F037AD087BF69C4FA6380E7599553C03BE2DF7F27EDAAC1813", "hash_sha512": "BED16FD998B2ED96F8B929E0372286B1E1C59F970A5114873EDFBACBAE9D1A93C76DF03E858EF26C38BA2F6CF2A41050FEC85BCD443E120788B32E45581D190D", "hash_ssdeep": "96:kTpMEQ2BQ3iQAO/4p2h4Yr1DGjsX+HsxpjxphoClJeWUSiDJdMs2bKveLoEWUGyh:kTJQ33cOSHrr0oCbeWZYNmWhyW89", "hash_imp": "BDEE2028E64A4C6E54156264705E7D10", "hash_pesha1": "9A168E2108D85515BC6B8AF5D1638B2756AB091D", "hash_pe256": "8E954A95EFD0315B37CAF72ECABD2B7F4140AFDFA716C188ADB93B3CF6B938A9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Systray .exe stub", "meta_original_filename": "systray.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b1a7169522d690dbe3ad77604913637dc457c4885ebedbddfb1419b366099204/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\systray.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "takeown.exe-A9AB2877AE82A53F5A387B045BF326A4": { "file_name": "takeown.exe", "file_path": "C:\\Windows\\SysWOW64\\takeown.exe", "hash_md5": "A9AB2877AE82A53F5A387B045BF326A4", "hash_sha1": "4FA3F15D369947026DC7BC6BA5283159B761F568", "hash_sha256": "C7159144C6403C38AAF3DEF4C2FC5759B6DF824AF003B304D4B77C6D72353B3E", "hash_sha384": "9ABE3D2C7B452D76F54DF32FCE67F39D4D25C3F67EF68AF107582F74DEC5964EB7A60D342FBF5BA3390B7B35C43AB378", "hash_sha512": "4674B650BFF29D90758D1964620C7FD5889B489C515362C236D91C05DAF4BC4A5BDCEF9F9C0C011E51350DA3A74D394CA98BAD06D18FDB937DA76F8A87EF3214", "hash_ssdeep": "1536:U3WcvOYMd57IAB/R0CO9derpMkT2MVd17ihh4SpWfbZay0d:SOYM/7hRVmc20liLVpObZaTd", "hash_imp": "3EFF225872A4BFF594AF402A5BBCC6F4", "hash_pesha1": "5E32AF77B27D164806E071CE660AAD63BA1D77B1", "hash_pe256": "59F2BAB40BB3C90780941FA04E1125DB381E59D2FEAB84636EE3E42030851DA1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Takes ownership of a file", "meta_original_filename": "takeown.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c7159144c6403c38aaf3def4c2fc5759b6df824af003b304d4b77c6d72353b3e/detection", "output": "\r\nTAKEOWN [/S system [/U username [/P [password]]]]\r\n /F filename [/A] [/R [/D prompt]]\r\n\r\nDescription:\r\n This tool allows an administrator to recover access to a file that\r\n was denied by re-assigning file ownership.\r\n\r\nParameter List: \r\n /S system Specifies the remote system to\r\n connect to.\r\n\r\n /U [domain\\]user Specifies the user context under\r\n which the command should execute.\r\n\r\n /P [password] Specifies the password for the\r\n given user context.\r\n Prompts for input if omitted.\r\n\r\n /F filename Specifies the filename or directory\r\n name pattern. Wildcard \"*\" can be used\r\n to specify the pattern. Allows\r\n sharename\\filename.\r\n\r\n /A Gives ownership to the administrators\r\n group instead of the current user.\r\n\r\n /R Recurse: instructs tool to operate on\r\n files in specified directory and all \r\n subdirectories.\r\n\r\n /D prompt Default answer used when the current user\r\n does not have the \"list folder\" permission\r\n on a directory. This occurs while operating\r\n recursively (/R) on sub-directories. Valid \r\n values \"Y\" to take ownership or \"N\" to skip.\r\n\r\n /SKIPSL Do not follow symbolic links.\r\n Only applicable with /R.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE: 1) If /A is not specified, file ownership will be given to the\r\n current logged on user.\r\n\r\n 2) Mixed patterns using \"?\" and \"*\" are not supported.\r\n\r\n 3) /D is used to suppress the confirmation prompt.\r\n\r\nExamples: \r\n TAKEOWN /?\r\n TAKEOWN /F lostfile\r\n TAKEOWN /F \\\\system\\share\\lostfile /A\r\n TAKEOWN /F directory /R /D N\r\n TAKEOWN /F directory /R /A\r\n TAKEOWN /F *\r\n TAKEOWN /F C:\\Windows\\System32\\acme.exe\r\n TAKEOWN /F %windir%\\*.txt\r\n TAKEOWN /S system /F MyShare\\Acme*.doc\r\n TAKEOWN /S system /U user /F MyShare\\MyBinary.dll\r\n TAKEOWN /S system /U domain\\user /P password /F share\\filename\r\n TAKEOWN /S system /U user /P password /F Doc\\Report.doc /A\r\n TAKEOWN /S system /U user /P password /F Myshare\\* \r\n TAKEOWN /S system /U user /P password /F Home\\Logon /R\r\n TAKEOWN /S system /U user /P password /F Myshare\\directory /R /A\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"TAKEOWN /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\takeown.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "TapiUnattend.exe-D5BFFD755F566AAACB57CF83FDAA5CD0": { "file_name": "TapiUnattend.exe", "file_path": "C:\\Windows\\SysWOW64\\TapiUnattend.exe", "hash_md5": "D5BFFD755F566AAACB57CF83FDAA5CD0", "hash_sha1": "16A24F8718FE0927517D6E75206BEB3988C01177", "hash_sha256": "9FFA72EAD7927F09D7106C62D5FDE25E27F7BFF27099101E15E5F7E903CD00F4", "hash_sha384": "9B3E5890E53C1FC5D7376CAA0E47C34DB4683554FCA0E7B62436924AA13724A2F4A67ECA2C4BDADCA37A586835D1FB53", "hash_sha512": "A20361DC3E9A4DC973BEE58E4E1D2047B82EFED3A48FCB2D3ED4613207BD83FDA7BAE4E716796A37595F9DECAB87236DF159C9DE9A468DFBDE9205677E1DC21D", "hash_ssdeep": "192:HUadkYPdilaGPwrnMcjpc0dVCOmm1NF7faTWDrDSX1MD8w1wGuW/GUW0:HhvPUYWkMy8m13TEWDSXWDUGuW/GUW0", "hash_imp": "38D2F52A7BB6275BB518DEE25030D230", "hash_pesha1": "1DA6370E5CB759A33C0F15A336CCCEB669DAD52D", "hash_pe256": "B8CF65139A938F669618E343C2D22B4918978C9749CE1E0814C9BB5EE17258C2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) Telephony Unattend Action", "meta_original_filename": "TapiUnattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9ffa72ead7927f09d7106c62d5fde25e27f7bff27099101e15e5f7e903cd00f4/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\TapiUnattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "tar.exe-4B26D4CD5CD5F7B074E31793979F17C5": { "file_name": "tar.exe", "file_path": "C:\\Windows\\SysWOW64\\tar.exe", "hash_md5": "4B26D4CD5CD5F7B074E31793979F17C5", "hash_sha1": "C627A94EFEFF9C105B0166A66AED6D7BD7D76047", "hash_sha256": "2319A2F1313A4BF4CF5E009B7CD8A6E97B4C5B63B679F5BD4FEFA29CD7B3F319", "hash_sha384": "74AF6149C1EC000030CB1384470FBD8DFB61FE1B9516C213420D60D875E67C6DE2B1410E7747808131C634D945A5DEA5", "hash_sha512": "058CBCDACCA4B1E8927072D844DEFBD34370E687A7EAC5C0A8938CD13772102A572844182D03E626300F62C9BCA75B6F7EC219FDEDCDD97E3549EFFB9B8A0987", "hash_ssdeep": "768:Gkjt3SD9dqPu7MhObt7skjusX52HmbUV2S3p5OBKajbc:GkMZdqPN2tdtoGoVvpoBKaj", "hash_imp": "A529BDD6841E94B24C9B370AD975BD9B", "hash_pesha1": "5640D50EEE50C9AAE5B894C493A8A0E8DE8FC889", "hash_pe256": "190F975C47B4BEFB3A820C2489C06DD30E48507EC3B13345AD537FE4D512B62E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "bsdtar archive tool", "meta_original_filename": "bsdtar", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "3.3.2 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (c) libarchive authors", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2319a2f1313a4bf4cf5e009b7cd8a6e97b4c5b63b679f5bd4fefa29cd7b3f319/detection", "error": "Usage:\r\n List: tar.exe -tf <archive-filename>\r\n Extract: tar.exe -xf <archive-filename>\r\n Create: tar.exe -cf <archive-filename> [filenames...]\r\n Help: tar.exe --help\r\n", "output": "tar.exe(bsdtar): manipulate archive files\r\nFirst option must be a mode specifier:\r\n -c Create -r Add/Replace -t List -u Update -x Extract\r\nCommon Options:\r\n -b # Use # 512-byte records per I/O block\r\n -f <filename> Location of archive (default \\\\.\\tape0)\r\n -v Verbose\r\n -w Interactive\r\nCreate: tar.exe -c [options] [<file> | <dir> | @<archive> | -C <dir> ]\r\n <file>, <dir> add these items to archive\r\n -z, -j, -J, --lzma Compress archive with gzip/bzip2/xz/lzma\r\n --format {ustar|pax|cpio|shar} Select archive format\r\n --exclude <pattern> Skip files that match pattern\r\n -C <dir> Change to <dir> before processing remaining files\r\n @<archive> Add entries from <archive> to output\r\nList: tar.exe -t [options] [<patterns>]\r\n <patterns> If specified, list only entries that match\r\nExtract: tar.exe -x [options] [<patterns>]\r\n <patterns> If specified, extract only entries that match\r\n -k Keep (don't overwrite) existing files\r\n -m Don't restore modification times\r\n -O Write entries to stdout, don't restore to disk\r\n -p Restore permissions (including ACLs, owner, file flags)\r\nbsdtar 3.3.2 - libarchive 3.3.2 zlib/1.2.5.f-ipp\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\tar.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "taskkill.exe-CA313FD7E6C2A778FFD21CFB5C1C56CD": { "file_name": "taskkill.exe", "file_path": "C:\\Windows\\SysWOW64\\taskkill.exe", "hash_md5": "CA313FD7E6C2A778FFD21CFB5C1C56CD", "hash_sha1": "AE2EBB9C1413FBE08B4D066A630F1D1457E0EE1C", "hash_sha256": "4E664B35E8DE6C6B38E3231DFAF00744435FFB806E00355FECE1E0CC1D2121C1", "hash_sha384": "26AAC7D75C7DA96F6BEFD2BF4DF8DECF75A1E951AED139184767A04CE293C29D0DDB7397D646B1CE63C0BB76AC16C1E5", "hash_sha512": "C9CFFB3BD0D241AC3F3DDE14B438F19C3FAD740CEC2D8B7704B317A88901AAADD441A012EC0FC472AA61737BCEB42087C7D14FCC6292F600B413FD80D7AC6401", "hash_ssdeep": "1536:OJYunSIBkNsVh8sPeYEvn0Dx4CqXlWqOzWc5hph8izZgJwW60PxStc:8SYAIAB0DaVWqOzWc5hpmi1gJNPx2c", "hash_imp": "E779593883533533463F2129C0406648", "hash_pesha1": "F7C410F05DC86D3C9B48F2B80B25156532E3FA6A", "hash_pe256": "2AAF13C3E465D9DFB15B6280AD6BA4041FD4F6A2FFE9988780F99FD4FE2E846E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Terminates Processes", "meta_original_filename": "taskkill.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4e664b35e8de6c6b38e3231dfaf00744435ffb806e00355fece1e0cc1d2121c1/detection", "output": "\r\nTASKKILL [/S system [/U username [/P [password]]]]\r\n { [/FI filter] [/PID processid | /IM imagename] } [/T] [/F]\r\n\r\nDescription:\r\n This tool is used to terminate tasks by process id (PID) or image name.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which the\r\n command should execute.\r\n\r\n /P [password] Specifies the password for the given user\r\n context. Prompts for input if omitted.\r\n\r\n /FI filter Applies a filter to select a set of tasks.\r\n Allows \"*\" to be used. ex. imagename eq acme*\r\n\r\n /PID processid Specifies the PID of the process to be terminated.\r\n Use TaskList to get the PID.\r\n\r\n /IM imagename Specifies the image name of the process\r\n to be terminated. Wildcard '*' can be used\r\n to specify all tasks or image names.\r\n\r\n /T Terminates the specified process and any\r\n child processes which were started by it.\r\n\r\n /F Specifies to forcefully terminate the process(es).\r\n\r\n /? Displays this help message.\r\n\r\nFilters:\r\n Filter Name Valid Operators Valid Value(s)\r\n ----------- --------------- -------------------------\r\n STATUS eq, ne RUNNING |\r\n NOT RESPONDING | UNKNOWN\r\n IMAGENAME eq, ne Image name\r\n PID eq, ne, gt, lt, ge, le PID value\r\n SESSION eq, ne, gt, lt, ge, le Session number.\r\n CPUTIME eq, ne, gt, lt, ge, le CPU time in the format\r\n of hh:mm:ss.\r\n hh - hours,\r\n mm - minutes, ss - seconds\r\n MEMUSAGE eq, ne, gt, lt, ge, le Memory usage in KB\r\n USERNAME eq, ne User name in [domain\\]user\r\n format\r\n MODULES eq, ne DLL name\r\n SERVICES eq, ne Service name\r\n WINDOWTITLE eq, ne Window title\r\n\r\n NOTE\r\n ----\r\n 1) Wildcard '*' for /IM switch is accepted only when a filter is applied.\r\n 2) Termination of remote processes will always be done forcefully (/F).\r\n 3) \"WINDOWTITLE\" and \"STATUS\" filters are not considered when a remote\r\n machine is specified.\r\n\r\nExamples:\r\n TASKKILL /IM notepad.exe\r\n TASKKILL /PID 1230 /PID 1241 /PID 1253 /T\r\n TASKKILL /F /IM cmd.exe /T \r\n TASKKILL /F /FI \"PID ge 1000\" /FI \"WINDOWTITLE ne untitle*\"\r\n TASKKILL /F /FI \"USERNAME eq NT AUTHORITY\\SYSTEM\" /IM notepad.exe\r\n TASKKILL /S system /U domain\\username /FI \"USERNAME ne NT*\" /IM *\r\n TASKKILL /S system /U username /P password /FI \"IMAGENAME eq note*\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"TASKKILL /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\taskkill.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "tasklist.exe-0A4448B31CE7F83CB7691A2657F330F1": { "file_name": "tasklist.exe", "file_path": "C:\\Windows\\SysWOW64\\tasklist.exe", "hash_md5": "0A4448B31CE7F83CB7691A2657F330F1", "hash_sha1": "7F50D8C3CF3EC79122A876E969BDB65D939BECD0", "hash_sha256": "76EAC7B5F53E0D58A98D5A6DDF9C97E19D1462EF65C0035D7798F89988B15AB4", "hash_sha384": "E69EE8E1AABB7173F6CF51F52A82F179D34CCA9686CB87806EACCFED1085EF72E0B6E1EC6863A188AC1DFC4D61BE3EE4", "hash_sha512": "5251DDA250FB1283A7A80B885919617C838CDE7C3B4420C6AA9A685141CB38326D679412298C9A49E8EB7B6526910BCE046FDCB458B1B3DC9A786F6450280908", "hash_ssdeep": "1536:bAkPj5C4gTCKzlBZ1tlxq4Bh3uecKnf0LdVn6DElgiS1xt8S2f:NCGYt3uQ3uecKnfGdR6IqR1xtf2f", "hash_imp": "19BBD9C4E73C288A3645E163F4B82682", "hash_pesha1": "443382F5344C42E5D823B05BC8DBA0E18E4E1256", "hash_pe256": "635F0491E89689F7B3E7416143EF01D12F8B60FE6934ADF2BBB69E051053BD55", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Lists the current running tasks", "meta_original_filename": "tasklist.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/76eac7b5f53e0d58a98d5a6ddf9c97e19d1462ef65c0035d7798f89988b15ab4/detection", "output": "\r\nTASKLIST [/S system [/U username [/P [password]]]]\r\n [/M [module] | /SVC | /V] [/FI filter] [/FO format] [/NH]\r\n\r\nDescription:\r\n This tool displays a list of currently running processes on\r\n either a local or remote machine.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /M [module] Lists all tasks currently using the given\r\n exe/dll name. If the module name is not\r\n specified all loaded modules are displayed.\r\n\r\n /SVC Displays services hosted in each process.\r\n\r\n /APPS Displays Store Apps and their associated processes.\r\n\r\n /V Displays verbose task information.\r\n\r\n /FI filter Displays a set of tasks that match a\r\n given criteria specified by the filter.\r\n\r\n /FO format Specifies the output format.\r\n Valid values: \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" should\r\n not be displayed in the output.\r\n Valid only for \"TABLE\" and \"CSV\" formats.\r\n\r\n /? Displays this help message.\r\n\r\nFilters:\r\n Filter Name Valid Operators Valid Value(s)\r\n ----------- --------------- --------------------------\r\n STATUS eq, ne RUNNING | SUSPENDED\r\n NOT RESPONDING | UNKNOWN\r\n IMAGENAME eq, ne Image name\r\n PID eq, ne, gt, lt, ge, le PID value\r\n SESSION eq, ne, gt, lt, ge, le Session number\r\n SESSIONNAME eq, ne Session name\r\n CPUTIME eq, ne, gt, lt, ge, le CPU time in the format\r\n of hh:mm:ss.\r\n hh - hours,\r\n mm - minutes, ss - seconds\r\n MEMUSAGE eq, ne, gt, lt, ge, le Memory usage in KB\r\n USERNAME eq, ne User name in [domain\\]user\r\n format\r\n SERVICES eq, ne Service name\r\n WINDOWTITLE eq, ne Window title\r\n MODULES eq, ne DLL name\r\n\r\nNOTE: \"WINDOWTITLE\" and \"STATUS\" filters are not supported when querying\r\n a remote machine.\r\n\r\nExamples:\r\n TASKLIST\r\n TASKLIST /M\r\n TASKLIST /V /FO CSV\r\n TASKLIST /SVC /FO LIST\r\n TASKLIST /APPS /FI \"STATUS eq RUNNING\"\r\n TASKLIST /M wbem*\r\n TASKLIST /S system /FO LIST\r\n TASKLIST /S system /U domain\\username /FO CSV /NH\r\n TASKLIST /S system /U username /P password /FO TABLE /NH\r\n TASKLIST /FI \"USERNAME ne NT AUTHORITY\\SYSTEM\" /FI \"STATUS eq running\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"TASKLIST /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\tasklist.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Taskmgr.exe-C5239F4DF441290CE4B7A5948F15604A": { "file_name": "Taskmgr.exe", "file_path": "C:\\Windows\\SysWOW64\\Taskmgr.exe", "hash_md5": "C5239F4DF441290CE4B7A5948F15604A", "hash_sha1": "2B40070F305F84C74C0D6F304DAB647657E42EEE", "hash_sha256": "5C5C162B1B5688FAA1928380829E4BDB12A84E07893A6C1EC39FEDBA1464D81D", "hash_sha384": "C09640BE0B2E50F6558A520ED1779AE7A81455F2A3387DA57798EF754C7AD70667CAB0B91BD0D32F09595265F63932A6", "hash_sha512": "2520069025E721655F131233B63DFBBD1D867B8CDB0D4EBBC2098AA30E3AFEECD85A1595E14C0723B7F8C63B155E5035F740B9D9149F4AF0EEFE77F26C0AD057", "hash_ssdeep": "24576:kzMSNfqoIUXK16MR4TpTfdI0sVTo8KJfF62W6f1dIRNKB:uNfqsXx5fdI02c8eg2jf1dIjK", "hash_imp": "7664BDECACB8B0F17968E983BF0717BE", "hash_pesha1": "F8A5C8A9A1D15CA09C69D8561DBCB16E6269215F", "hash_pe256": "3054E68E41BFB62AC1677D3E0E48A3E21351D2B76B6AA2579FADEBDE78F6C99E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Manager", "meta_original_filename": "Taskmgr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5c5c162b1b5688faa1928380829e4bdb12a84e07893a6c1ec39fedba1464d81d/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\Taskmgr.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\Taskmgr.exe.mun": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\C:*Users*user*AppData*Local*Microsoft*Windows*Caches*cversions.3.ro": "Section", "\\Sessions\\1\\BaseNamedObjects\\C:*Users*user*AppData*Local*Microsoft*Windows*Caches*{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000009.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_16.db": "File", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\Taskmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Task Manager" }, "tcmsetup.exe-4F76C99820BD3D1D785EBB4A1CD8B19A": { "file_name": "tcmsetup.exe", "file_path": "C:\\Windows\\SysWOW64\\tcmsetup.exe", "hash_md5": "4F76C99820BD3D1D785EBB4A1CD8B19A", "hash_sha1": "5AD4603F0AFF29B06E905BD8F665FA3DAC57ABF3", "hash_sha256": "D8827FD646B673E259C97417A17ABF6F1015B07384801933782337036F18FB25", "hash_sha384": "4FA30D57353B76901205826C29D31BCBE0AE5FFAAC7E4BEEE391A06B68436ED4925D4C792B9ED3562CB8CE13C2CDBF7E", "hash_sha512": "99676C22A7DA23B91C4FDF9CEFE65B7EF07BA8AFCE05A9898090599722D39A6CE29B48C03412837D51CFDB4EECB49C0DF0299F12E782456A7FF7A0B3BF77B323", "hash_ssdeep": "192:SI2aAWyEpgCU/MvlZ/HsDlWTsLloadczmvYWGroWfz:SfdJ8/HeWwLWkvYWGroW", "hash_imp": "EEFB875014ECDD920C8DA3D31E4C2FCB", "hash_pesha1": "92AD77F2E944C632ACC13C85AC133E9CF8DA9AC9", "hash_pe256": "2F9FB0E6C955F5936920081934527CC4C65E83EBBE04492BF1A9147BB26ED5E3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) Telephony Administration Setup", "meta_original_filename": "TCMSETUP.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/d8827fd646b673e259c97417a17abf6f1015b07384801933782337036f18fb25/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\tcmsetup.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\tcmsetup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Telephony Client Setup Help" }, "TCPSVCS.EXE-73905DB831B4F37F0673D2DD5BBF7779": { "file_name": "TCPSVCS.EXE", "file_path": "C:\\Windows\\SysWOW64\\TCPSVCS.EXE", "hash_md5": "73905DB831B4F37F0673D2DD5BBF7779", "hash_sha1": "C3E6486195CD4AC8C163914A2EA230AB797164E6", "hash_sha256": "7D6386A5BEBA7635C8FF0B0E24CEC90A409853440650AF583462C36B8E04971D", "hash_sha384": "54CCA84DE9CE58466C0E88658E282ECF9A58984F791E6D4AAF103E2B4BEF2C1870D1175992F614031EFC2308C1D41A63", "hash_sha512": "EFE2B9F34D962597372162A184DC05518DE973173823D0D87D02180BA8AEA183348A977DFB7B200B7FCB83DC2797EF60489EFC49B3E3AF253003D9F60DC28B33", "hash_ssdeep": "192:H8mF0o+XFBax64yNmt2b54rCeL6//1vKkW+/WgC:cmF0o4jax64yM294/6//QkW+/Wv", "hash_imp": "7EC53FBE050A90703B67A98FCB8BCFCC", "hash_pesha1": "33B38F9F3E36B3D73FF205D27C2614301082CF94", "hash_pe256": "FE2D9B65191C5BBAB047DC7D376828E085A1444C5E49DFA95335D0890F74287F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Services Application", "meta_original_filename": "TCPSVCS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/7d6386a5beba7635c8ff0b0e24cec90a409853440650af583462c36b8e04971d/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\TCPSVCS.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ThumbnailExtractionHost.exe-7E0E280E7C5C69377576761AEDF79F4B": { "file_name": "ThumbnailExtractionHost.exe", "file_path": "C:\\Windows\\SysWOW64\\ThumbnailExtractionHost.exe", "hash_md5": "7E0E280E7C5C69377576761AEDF79F4B", "hash_sha1": "44B58EE9E04E46CF3CD655EB8C7B6E826BF31CDB", "hash_sha256": "3C63AADAF7C52E13E296B11C20D92CB4B75A711A7E1DF3E91027BA69C7197AB6", "hash_sha384": "3F69D61F53408A560DAD30E6B96A6466222ED0808C71444809200834E1F74EC972FCBCAF432D3923B792E58CCE21BAA3", "hash_sha512": "3BACF77B2EAA10E6282639B40C7D309556B7B2F51D583C2A63DBEEEE865FCB991672B989F8421BFEF9209007927618261235BF186CB6E1DE730F4839F4482A23", "hash_ssdeep": "384:GgaDPfelVP1JQ+GOdhKM4J/4kQLJj28S6yCGtyoaWncWZNwft:GgaQP1adO/q0PSZTtyo79U", "hash_imp": "822B91B1F569458A853AF386AC9BF8E9", "hash_pesha1": "1B866FED0D6CD7BF913D7611EA65BC6AA5640FDB", "hash_pe256": "701E72544F39CADC83B2359E0AFA52C30FA355378DACE3D35CDE305C1B2974C9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Thumbnail Handler Extraction Host", "meta_original_filename": "ThumbnailExtractionHost.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3c63aadaf7c52e13e296b11c20d92cb4b75a711a7e1df3e91027ba69c7197ab6/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\ThumbnailExtractionHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "timeout.exe-976566BEEFCCA4A159ECBDB2D4B1A3E3": { "file_name": "timeout.exe", "file_path": "C:\\Windows\\SysWOW64\\timeout.exe", "hash_md5": "976566BEEFCCA4A159ECBDB2D4B1A3E3", "hash_sha1": "47585F879C7458083351ADB2985E56687DC3C790", "hash_sha256": "DAB1647E4A1F207835162D87192A173519B1BC1FC274F2E17421702FFFA578E7", "hash_sha384": "CAAB62CFBBC45F6C070C244824F880758A13CE545752ECCE14F2D5E49A5E4139EC413831B3C620D882A4E3DB0BC4A5C9", "hash_sha512": "896F8E546DD5E962A544C5B14DA88FD97AC20C7B1DE0179B56A149CF3370D04AE8C400163FCB948D8C135946B158CABFB2416FD77DA4D3B42529160D8E0BA266", "hash_ssdeep": "384:MIYBHPeLzzP7HsDb76jCIQEVODDEhGGxeCqbWoHqG1iw70ckyDRH8xQLlI7I1hk9:HYBHPqsDKj2DDbO4qcqGD798xLeh9G1", "hash_imp": "80CC4313933D9AFCC64EFD0255D4BD3C", "hash_pesha1": "00DE1CF42A35493408EB9DAB098331B33FDEC45B", "hash_pe256": "A51EE94F282DEC1F95F410C888CA8F3EC7C10230D689D27416EA8A7FB56E84F1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "timeout - pauses command processing", "meta_original_filename": "timeout.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/dab1647e4a1f207835162d87192a173519b1bc1fc274f2e17421702fffa578e7/detection", "output": "\r\nTIMEOUT [/T] timeout [/NOBREAK] \r\n\r\nDescription:\r\n This utility accepts a timeout parameter to wait for the specified\r\n time period (in seconds) or until any key is pressed. It also \r\n accepts a parameter to ignore the key press. \r\n\r\nParameter List:\r\n /T timeout Specifies the number of seconds to wait.\r\n Valid range is -1 to 99999 seconds.\r\n\r\n /NOBREAK Ignore key presses and wait specified time.\r\n\r\n /? Displays this help message.\r\n\r\nNOTE: A timeout value of -1 means to wait indefinitely for a key press.\r\n\r\nExamples:\r\n TIMEOUT /?\r\n TIMEOUT /T 10\r\n TIMEOUT /T 300 /NOBREAK\r\n TIMEOUT /T -1\r\n", "error": "ERROR: Invalid value for timeout (/T) specified. Valid range is -1 to 99999.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\timeout.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "TokenBrokerCookies.exe-D6FB32B2C3949855F34FEA4859578340": { "file_name": "TokenBrokerCookies.exe", "file_path": "C:\\Windows\\SysWOW64\\TokenBrokerCookies.exe", "hash_md5": "D6FB32B2C3949855F34FEA4859578340", "hash_sha1": "3CF27282F3801A413D6E9B654CC78DD5214734F0", "hash_sha256": "398A23608A0DB31951BE5A3EDDD979771BFFD84A4F1548609D3C8C608DE736CA", "hash_sha384": "EADE5D8982DF2A46E8BFB141BCC90FCADC8AFC2A35F3D007274A38531DD935910FEFD94905996A16C1877ACEC5397D32", "hash_sha512": "4364A88E51D65658B8510EDD75941F0A6DEA60CBD82ADBD0F37F0ABC8AE07D3E4C2B1B83B46237131D5A027510BE721DE73E3F857CFB39E60CC485688DCBF5AA", "hash_ssdeep": "768:/RPFSKuEHJ7XlQY5Ws/7nOa5YmWLed4B7/7ScxeF:/RPFS4prl3FbVxSed4lxeF", "hash_imp": "8AAEFF7072FBD0A5749AED594A7BB56E", "hash_pesha1": "5946079E82F8857C8D2551EB61A021F967EC537B", "hash_pe256": "63389773606DF42A829073D5CD5912A60DD62E6F2382FA78B3877898A96C6314", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Token Broker Cookie Helper", "meta_original_filename": "TokenBrokerCookies.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/398a23608a0db31951be5a3eddd979771bffd84a4f1548609d3c8c608de736ca/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\TokenBrokerCookies.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "TpmInit.exe-22A202B729CB70DF605D7E81D77B9B41": { "file_name": "TpmInit.exe", "file_path": "C:\\Windows\\SysWOW64\\TpmInit.exe", "hash_md5": "22A202B729CB70DF605D7E81D77B9B41", "hash_sha1": "6EDACF84D5512EF4F6DFEA78B60ADD7C91D3F7DF", "hash_sha256": "EA80B5FC2CC98EEA5376F3EF1B1DE3C447550AE5EE3C7CC8DFBBE9310C288880", "hash_sha384": "B2E114624AB4A690612C53F9A17FB16020284912FA165F37B38B722FD897C3BDC43C974DE6656024FBDC47C12F69D55E", "hash_sha512": "E15F456A4D299AFF33F2FDEE760DCA39A2D31397BB470FDCCDA6BDA2A1CAF408782A82CD2075C1F0E1B933FBCC6BBA621319911EE0CC333616D94886DC425B09", "hash_ssdeep": "1536:yUeflox5+Z7nUrwZliuuGiceY0lA3CJHkxUMK:nedox5+Z7nULNPYfSFkx1K", "hash_imp": "80D512028EB708EE52E1A6F4BAB6259F", "hash_pesha1": "EB59E33C262A27C02E1759D8E6F61073E98EC683", "hash_pe256": "C420F6543D27A7B0BE8A11FDDAFAC9C061517008883EA860DB49AC897B855D55", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TPM Initialization Wizard", "meta_original_filename": "TpmInit.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ea80b5fc2cc98eea5376f3ef1b1de3c447550ae5ee3c7cc8dfbbe9310c288880/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\TpmInit.exe.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\netmsg.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\TpmInit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Manage the TPM security hardware" }, "TpmTool.exe-321E99EF65F37E5F7DFC40D1E95684F5": { "file_name": "TpmTool.exe", "file_path": "C:\\Windows\\SysWOW64\\TpmTool.exe", "hash_md5": "321E99EF65F37E5F7DFC40D1E95684F5", "hash_sha1": "D13F021CA46B00151D870EA36AF7D337FAB1721F", "hash_sha256": "807FD9899F1C852B5350DD975B9A9614C5C7CA6BD1FFA71559A8B840BB0CD9AE", "hash_sha384": "EB0F8009076780E5A987202B371DE5735F00DA4F86AD8F22ADA391A590FE3DF334C0F09DED477A1725BF325A60DC4005", "hash_sha512": "38E6AF2EA64B6C84D5CB4CC320D962E63138DE7A51F62FBDFE1C7BD85D2E70F5E03B374340BF5F06BB98C28648FEB9FCAE186C1C51A34CA797F4CC3D7F269A65", "hash_ssdeep": "6144:tEHjV/e+Bi+BkSJQfqfDj3n6dyIzWueQCW:tEjRxJQfqfH3KYsCW", "hash_imp": "97EACDB477A98072815A1CAD741C6F35", "hash_pesha1": "3B644EF73733A09286F95A3E2CA140EF8A0372FF", "hash_pe256": "3FB454844E4C78EDA8600AC833C773D09F018D03401DAA582D59B49B640640F4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/807fd9899f1c852b5350dd975b9a9614c5c7ca6bd1ffa71559a8b840bb0cd9ae/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\TpmTool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "tracerpt.exe-1A5BC85BE140A2D7E6DE64EF2ECF3441": { "file_name": "tracerpt.exe", "file_path": "C:\\Windows\\SysWOW64\\tracerpt.exe", "hash_md5": "1A5BC85BE140A2D7E6DE64EF2ECF3441", "hash_sha1": "708B4AD7640BEC86C1F1951BD07DB18088A7B4AE", "hash_sha256": "A632C902E1E1161B19EC43D3A9F8B325A47E8F1F063B6396C8BE43AEFB88E8BC", "hash_sha384": "1B0FD065B7E8A11F0F52DC2184FE526C44198120299B8DA9CF725D35113C52BF78B5111CB44E5550854116421B06E963", "hash_sha512": "EA455876E382D3A925032EE516A59F8AA2D6B79DC588623A527D0EB30D343D8AEB3B5C93BC1D74E7BAA3DF455E879FE1B9F3BBFAA05EF9DC4CC3005756052471", "hash_ssdeep": "6144:l0H/soILQHvuuV1Ynuslq57WVsEanDbGBe:ufsoIgHYusE5SHaDbGBe", "hash_imp": "7835E3A9354323D36EDE92465DE72126", "hash_pesha1": "9257217FE1FF6B4EED8B02851B64F739ACBD855A", "hash_pe256": "DE9F40AF1F62D70AB73F6E6A262405616B888F34F094C87EEBD4B9F4C76B849E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Trace Report Tool", "meta_original_filename": "TraceRpt.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a632c902e1e1161b19ec43d3a9f8b325a47e8f1f063b6396c8be43aefb88e8bc/detection", "output": "\r\nMicrosoft r TraceRpt.Exe (10.0.19041.546)\r\n\r\nUsage:\r\n C:\\Windows\\SysWOW64\\tracerpt.exe <[-l] <value [value [...]]>|-rt <session_name [session_name [...]]>> [options]\r\n\r\nOptions:\r\n -? Displays context sensitive help.\r\n -config <filename> Settings file containing command options.\r\n -y Answer yes to all questions without prompting.\r\n -f <XML|HTML> Report format.\r\n -of <CSV|EVTX|XML> Dump format, the default is XML.\r\n -en <ANSI|Unicode> Output file encoding. Only allowed with CSV\n output format.\r\n -df <filename> Microsoft specific counting/reporting schema\n file.\r\n -import <filename [filename [...]]> Event Schema import file.\r\n -int <filename> Dump interpreted event structure into\n specified file.\r\n -rts Report raw timestamp in event trace header. \n Can only be used with -o, not -report or\n -summary.\r\n -tmf <filename> Trace Message Format definition file\r\n -tp <value> TMF file search path. Multiple paths can be\n used, separated with ';'.\r\n -i <value> Specifies the provider image path. The\n matching PDB will be located in the Symbol\n Server. Multiple paths can be used, separated\n with ';'.\r\n -pdb <value> Specifies the symbol server path. Multiple\n paths can be used, separated with ';'.\r\n -gmt Convert WPP payload timestamps to GMT time\r\n -rl <value> System Report Level from 1 to 5, the default\n value is 1.\r\n -summary [filename] Summary report text file. Default is\n summary.txt.\r\n -o [filename] Text output file. Default is dumpfile.xml.\r\n -report [filename] Text output report file. Default is\n workload.xml.\r\n -lr Less restrictive; use best effort for events\n not matching event schema.\r\n -export [filename] Event Schema export file. Default is\n schema.man.\r\n [-l] <value [value [...]]> Event Trace log file to process.\r\n -rt <session_name [session_name [...]]> Real-time Event Trace Session data\n source.\r\n\r\nExamples:\r\n tracerpt logfile1.etl logfile2.etl -o logdump.xml -of XML\n tracerpt logfile.etl -o logdmp.xml -of XML -lr -summary logdmp.txt -report logrpt.xml\n tracerpt logfile1.etl logfile2.etl -o -report\n tracerpt logfile.etl counterfile.blg -report logrpt.xml -df schema.xml\n tracerpt -rt \"NT Kernel Logger\" -o logfile.csv -of CSV\n\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\tracerpt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "TRACERT.EXE-ED0BE233116F475F3DB062EED8135B3C": { "file_name": "TRACERT.EXE", "file_path": "C:\\Windows\\SysWOW64\\TRACERT.EXE", "hash_md5": "ED0BE233116F475F3DB062EED8135B3C", "hash_sha1": "5B55CCEB017DA3F97FB1481C49CA91FAC05BC20D", "hash_sha256": "5572CCCBC800DDC2B9788C5B888007FC5DA88AB5712C3414AF7799E4F2E04FF9", "hash_sha384": "C32949C9B418CCA07CDBC2FE78BF64ABA42BAE9305E554E2F941C32E668B5A00744214E0206829BCDFC6E1D50F268488", "hash_sha512": "74E1F69BDD4BD3125665C14E603C2E08E5EA61B232299F075290A1E5B8C3D128AEC360F04A34B4D6ECACE6FC948B293350655610A1B5D725BE45B4CF630F1FBB", "hash_ssdeep": "192:ipULxBwumVE9IT2aA6lzTt8c7molvNBwKvTn2JKJCW7mEbAL1bwGmW6aW:ipy2VOIT2St/7NlFBwKR7mjL1bqW6aW", "hash_imp": "531AE91619D780EE6780A8E52862643F", "hash_pesha1": "EA521CF93C91F8D9A3D6828DD67CF029C4E60779", "hash_pe256": "E074C3E7A096E1EC2894C775F009C39DCF73467AFC6D02CE11301DBFBE5BABDD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Traceroute Command", "meta_original_filename": "tracert.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/5572cccbc800ddc2b9788c5b888007fc5da88ab5712c3414af7799e4f2e04ff9/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "output": "--help is not a valid command option.\r\n\r\nUsage: tracert [-d] [-h maximum_hops] [-j host-list] [-w timeout] \r\n [-R] [-S srcaddr] [-4] [-6] target_name\r\n\r\nOptions:\r\n -d Do not resolve addresses to hostnames.\r\n -h maximum_hops Maximum number of hops to search for target.\r\n -j host-list Loose source route along host-list (IPv4-only).\r\n -w timeout Wait timeout milliseconds for each reply.\r\n -R Trace round-trip path (IPv6-only).\r\n -S srcaddr Source address to use (IPv6-only).\r\n -4 Force using IPv4.\r\n -6 Force using IPv6.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\TRACERT.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "TSTheme.exe-CB32D9E4321504D8217683196149373A": { "file_name": "TSTheme.exe", "file_path": "C:\\Windows\\SysWOW64\\TSTheme.exe", "hash_md5": "CB32D9E4321504D8217683196149373A", "hash_sha1": "509F20BFE552800EBDFE0A37B6189B4343D99A94", "hash_sha256": "0A827CB624FB1DD5743DD5706A60FFED477988D4E939C6876BBCE398F2574065", "hash_sha384": "2EDEA61F7141C2F107FAB28F0752719FA91F71FC3544FEA227F547A661BB8868D3F6B15A0B570E7C189A607152509CD9", "hash_sha512": "5CFDDB139F254607D81F0E9ADDD0AB7D5FEC46FE8FACFC8F69BF789DA5DF7C0809A808144EC0A32CC841240F3C74DFC541C9BF9A24A33C57B3E4D2C9A88B2D9A", "hash_ssdeep": "1536:Y+7fA8LgWp8jweDL+l0YW2iwpjyrH/jak:Y+DAmgWEDL+zrim+L/2k", "hash_imp": "C059327BB81F9769B552D03F94C4F1A1", "hash_pesha1": "86126C61838F7F598E55482173F646ADCEECDCDC", "hash_pe256": "879F25E8E0304DC678BE79520EEF9FD22464DCD01C99758C896A9C11D9AFBD0B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TSTheme Server Module", "meta_original_filename": "TSThemeS.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0a827cb624fb1dd5743dd5706a60ffed477988d4e939c6876bbce398f2574065/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\TSTheme.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\TSTheme.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ttdinject.exe-901A932FAE9B16AE4ABFB3FEFFFD54F9": { "file_name": "ttdinject.exe", "file_path": "C:\\Windows\\SysWOW64\\ttdinject.exe", "hash_md5": "901A932FAE9B16AE4ABFB3FEFFFD54F9", "hash_sha1": "A83078097C3F823E864B3ACF7F57C6FFF8DEC333", "hash_sha256": "149306318334A101F6647718519477713A7ED2E50759258881AB28F4F04F5FA7", "hash_sha384": "12217046EE4D7E9311D083F8B769BC30330DCEEC9E698D1B1469770F7645594EFC2EDB27CBD9C607A636398782FA6E29", "hash_sha512": "B195819AC82BB7257DBCC216FD21EC4497B96770F80EF8EA15C51731B10CCCB893EC36A4BE39D379BC3D28542F1A8D8FD54B6821133F1218F6A23EA693DFA6E0", "hash_ssdeep": "6144:3LOdyc8ldPDGmSqJoCblTGq+yI/wSL/ZPELgaSdn:3L6yc6diqoCblTGq+XwSL/ZPEshh", "hash_imp": "A3665E1917D2E20AE758DA35DCB10292", "hash_pesha1": "32A9CB1F46825B222DAD8C4431ABDBC94E7A2D41", "hash_pe256": "A7CCE6F87ECB455A4E72D1FBA16521A32DFBF3449B3066F67AD0F0F6F4824295", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Time Traver Debugging Application Injector", "meta_original_filename": "TTDInject.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/149306318334a101f6647718519477713a7ed2e50759258881ab28f4f04f5fa7/detection", "output": "Microsoft (R) TTDInject Launcher 1.01.06\r\nRelease: 10.0.19041.1\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n", "error": "\b\b\b!!! Unexpected string 'help' after 'C:\\Windows\\SysWOW64\\ttdinject.exe'\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ttdinject.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "tttracer.exe-AAF4C8B847ADDA45EDB38E2768772E8D": { "file_name": "tttracer.exe", "file_path": "C:\\Windows\\SysWOW64\\tttracer.exe", "hash_md5": "AAF4C8B847ADDA45EDB38E2768772E8D", "hash_sha1": "AD630FB86CA8F52524B491F8A14E74A114006D52", "hash_sha256": "73FD8AA2603F3DF92DC6C912CC823099EF611340E6864A237D45C124AFC6EFB5", "hash_sha384": "0C00BECB397266209CD62D7CC3301674723D811420B9D03B3F58C8FA504E27CF736E47F1098252EDF13A0CD70936CEAD", "hash_sha512": "982BBA51C9093F7F6A75F8A6E219BBA8ADBF5195C728E7C54305EEBADE0B9DD21018E2198EC6F5FEDF8720ACDE2B218CBD6E2874801FEEB3D97F9CA1FB2A1A1F", "hash_ssdeep": "1536:8GqMbxBgvycQEdhC1/Hu+Kizxs7l9nvqGmESQQJczJe8s4TIew6QP1ICv:IMtavyFMG/OIzxAVSQQJkTu3v", "hash_imp": "F60B40636A512BD0BFE6ECF41CF49CBB", "hash_pesha1": "E8DB73389D46532DB8B7953614C67CE2732E5F08", "hash_pe256": "2247AA6C0ACBE620898D3E2BA58AA5D1F890CAF2D3C5B57092087455DFB4F9B6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Time Travel Debugging Tracer Tool", "meta_original_filename": "TTTracer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/73fd8aa2603f3df92dc6c912cc823099ef611340e6864a237d45c124afc6efb5/detection", "output": "MICROSOFT TIME TRAVEL DEBUGGING (TTD)\r\r\n\r\r\nTime Travel Debugging (TTD) command line utility is not meant for use in custom software or\r\r\nautomation. TTD is included with this version of Windows to improve diagnostics gathering and is not\r\r\nintended for direct use as a stand-alone solution.\r\r\n\r\r\nDISCLAIMER OF WARRANTY. THE SOFTWARE IS LICENSED \"AS IS.\" YOU BEAR THE RISK OF USING IT. MICROSOFT\r\r\nGIVES NO EXPRESS WARRANTIES, GUARANTEES, OR CONDITIONS. TO THE EXTENT PERMITTED UNDER APPLICABLE LAWS,\r\r\nMICROSOFT EXCLUDES ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE,\r\r\nAND NON-INFRINGEMENT.\r\r\n\r\r\n1. DATA COLLECTION. The software may collect information about you and your use of the software and send\r\r\n that to Microsoft. Microsoft may use this information to provide services and improve Microsoft's\r\r\n products and services. Your opt-out rights, if any, are described in the product documentation. Some\r\r\n features in the software may enable collection of data from users of your applications that access or\r\r\n use the software. If you use these features to enable data collection in your applications, you must\r\r\n comply with applicable law, including getting any required user consent, and maintain a prominent\r\r\n privacy policy that accurately informs users about how you use, collect, and share their data. You can\r\r\n learn more about Microsoft's data collection and use in the product documentation and the Microsoft\r\r\n Privacy Statement at https://go.microsoft.com/fwlink/?LinkId=521839. You agree to comply with all\r\r\n applicable provisions of the Microsoft Privacy Statement.\r\r\n\r\r\n2. SCOPE OF LICENSE. The software is licensed, not sold. Microsoft reserves all other rights. Unless\r\r\n applicable law gives you more rights despite this limitation, you will not (and have no right to):\r\r\n a) work around any technical limitations in the software that only allow you to use it in certain ways;\r\r\n b) reverse engineer, decompile or disassemble the software;\r\r\n c) remove, minimize, block, or modify any notices of Microsoft or its suppliers in the software;\r\r\n d) use the software for commercial, non-profit, or revenue-generating activities;\r\r\n e) use the software in any way that is against the law or to create or propagate malware; or\r\r\n f) share, publish, distribute, or lend the software, provide the software as a stand-alone hosted\r\r\n solution for others to use, or transfer the software or this agreement to any third party.\r\r\n\r\r\n3. SUPPORT SERVICES. Microsoft is not obligated under this agreement to provide any support services\r\r\n for the software. Any support provided is \"as is\", \"with all faults\", and without warranty of any kind.\r\r\n\r\n", "error": "Error: Unrecognized command line option '--help' (Error Code 0x80070057: The parameter is incorrect.)\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\tttracer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "typeperf.exe-3C451062FF170BCF0F68EF5A1FF4FE16": { "file_name": "typeperf.exe", "file_path": "C:\\Windows\\SysWOW64\\typeperf.exe", "hash_md5": "3C451062FF170BCF0F68EF5A1FF4FE16", "hash_sha1": "B9232D5C793597D0362C7CCE04598FA3F74E925E", "hash_sha256": "7BC9B82F3DCE94D42B13E93EA134864715C7CE2F6E1E62C0FE7F0DD4E18664AA", "hash_sha384": "60DEF226C9AF3DF34C39A7BD12D3DBAF73DA9B0ECADF179EF4AE93AFB2CCDAC037843AF43A02FC87A2DE8359D6336703", "hash_sha512": "EC102C6B2A260312B3295A9C7B024CA116609F03EE9E4521E86CB46DD3146DFDA38796BBB3FF7F895F205E7DE2E2272F3FA2946F332F7B8F0ACA9A771318A301", "hash_ssdeep": "768:Vrez2ecGi6KS8ak9ivuIwz8doMwQNd6YGvI3/YroadNomPQV+UEhAz:VJGiWre1mdsaGw3AMadNomOEhQ", "hash_imp": "5DCDDB44A0DA4CD1D962C12AD1A2DA22", "hash_pesha1": "FBC7B9A149023315A0B4B66A3F499BC59912A27A", "hash_pe256": "1BF241DEF9C1AB1887111B3C448D057516155EE0D98CF3A68853EEF00EDFDEAD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command line performance monitor", "meta_original_filename": "TypePerf.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7bc9b82f3dce94d42b13e93ea134864715c7ce2f6e1e62c0fe7f0dd4e18664aa/detection", "output": "\r\nMicrosoft r TypePerf.exe (10.0.19041.546)\r\n\r\nTypeperf writes performance data to the command window\r\nor to a log file. To stop Typeperf, press CTRL+C.\r\n\r\nUsage:\r\nC:\\Windows\\SysWOW64\\typeperf.exe { <counter [counter ...]> \r\n | -cf <filename> \r\n | -q [object] \r\n | -qx [object] \r\n } [options]\r\n\r\nParameters:\r\n <counter [counter ...]> Performance counters\r\n to monitor.\r\n\nOptions:\r\n -? Displays context\r\n sensitive help.\r\n -f <CSV|TSV|BIN|SQL> Output file format.\r\n Default is CSV.\r\n -cf <filename> File containing\r\n performance counters\r\n to monitor, one per\r\n line.\r\n -si <[[hh:]mm:]ss> Time between samples.\r\n Default is 1 second.\r\n -o <filename> Path of output file or\r\n SQL database. Default\r\n is STDOUT.\r\n -q [object] List installed\r\n counters (no\r\n instances). To list\r\n counters for one\r\n object, include the\r\n object name, such as\r\n Processor.\r\n -qx [object] List installed\r\n counters with\r\n instances. To list\r\n counters for one\r\n object, include the\r\n object name, such as\r\n Processor.\r\n -sc <samples> Number of samples to\r\n collect. Default is to\r\n sample until CTRL+C.\r\n -config <filename> Settings file\r\n containing command\r\n options.\r\n -s <computer_name> Server to monitor if\r\n no server is specified\r\n in the counter path.\r\n -y Answer yes to all\r\n questions without\r\n prompting.\r\n\r\nNote:\r\n Counter is the full name of a performance counter in\r\n \"\\\\<Computer>\\<Object>(<Instance>)\\<Counter>\" format,\r\n such as \"\\\\Server1\\Processor(0)\\% User Time\".\r\n\r\nExamples:\r\n typeperf \"\\Processor(_Total)\\% Processor Time\"\r\n typeperf -cf counters.txt -si 5 -sc 50 -f TSV -o domain2.tsv\r\n typeperf -qx PhysicalDisk -o counters.txt\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\typeperf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "tzutil.exe-31DE852CCF7CED517CC79596C76126B4": { "file_name": "tzutil.exe", "file_path": "C:\\Windows\\SysWOW64\\tzutil.exe", "hash_md5": "31DE852CCF7CED517CC79596C76126B4", "hash_sha1": "96994BBFE05406E21A0969CA110C2E5F0234CE64", "hash_sha256": "044C52F7B934C4EB64EAC31B1D8E5F29C9FEE2B3F080EA9BC6F180464CC8DB2D", "hash_sha384": "3DB6370767D15EDCFF4B92BB3A2B192CE00F56A029868BB68823804B0EA6E712EAE892DAF2663DE45853D69BCB680FC4", "hash_sha512": "12C87B636172253DE86DDE8A203F66EDD827D136A54306B4CA9F6C62BD1130E8E969D35FEEA158F00E881ACF2A4ADE85BC73147560217C306A3F82D4A63D8CD5", "hash_ssdeep": "768:3qaRM9gF04O6KHjiPqqNZOcjehPcALfRePBSLj8Vy/99:3JaKF09HeSa6BcGKBKAVy/9", "hash_imp": "C790BA0E7FECB0FFFC05EA7D2D0D5D32", "hash_pesha1": "BB5265CB2A7DE7A6E658611B07AAD147FB9D1A9E", "hash_pe256": "97947E72573E3839CAC8555C6B0EB38AE8BB2AF214CABF88CF65854048A18B54", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Time Zone Utility", "meta_original_filename": "tzutil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/044c52f7b934c4eb64eac31b1d8e5f29c9fee2b3f080ea9bc6f180464cc8db2d/detection", "output": "Windows Time Zone Utility\r\n\r\nUsage:\r\nTZUTIL </? | /g | /s TimeZoneID[_dstoff] | /l>\r\n\r\nParameters:\r\n /? Displays usage information.\r\n\r\n /g Displays the current time zone ID.\r\n\r\n /s TimeZoneID[_dstoff]\r\n Sets the current time zone using the specified time zone ID.\r\n The _dstoff suffix disables Daylight Saving Time adjustments\r\n for the time zone (where applicable).\r\n\r\n /l Lists all valid time zone IDs and display names. The output will\r\n be: \r\n <display name>\r\n <time zone ID>\r\n\r\nExamples:\r\n TZUTIL /g\r\n TZUTIL /s \"Pacific Standard Time\"\r\n TZUTIL /s \"Pacific Standard Time_dstoff\"\r\n\r\nRemarks:\r\n An exit code of 0 indicates the command completed successfully.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\tzutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "unlodctr.exe-EAF86537E26CC81C0767E58F66E01F52": { "file_name": "unlodctr.exe", "file_path": "C:\\Windows\\SysWOW64\\unlodctr.exe", "hash_md5": "EAF86537E26CC81C0767E58F66E01F52", "hash_sha1": "D9F24D699714586148342700F4490F7597AB0E7B", "hash_sha256": "68E5607D0AA1A52BFF70FE53C7EB0C5D27B342886BCBFEA7FBFEFD4168951F9B", "hash_sha384": "E797E79E9DF90E0A881B1253E0FE5C39C83F09C4A53BB242C3D3C1B2BF4149793D53268D684B09284A9D85FCC708CCDC", "hash_sha512": "75E591DBAC45ED1559559A47405D2E934D3D41D1E37CBB712F575DBF140509C3C60FE335E60006331C8E694558CE8635E116E7EDD244D5105664EAE79BFC2524", "hash_ssdeep": "768:jZlM8QoRNUQ8QkY6krH0CUEGuDSnhTUflUk:9lM8XUVYH0Cyu+nxUflU", "hash_imp": "6A4B1735A0F46C1BF9026F6600020288", "hash_pesha1": "23D8C0A6C8293D7D67DC2F7019C9F114C28F994D", "hash_pe256": "690A1C81EC98F8D4F8A9E5D6D19038654AE8F0D087F6200AA342150D3D246492", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Unload PerfMon Counters", "meta_original_filename": "UNLODCTR.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/68e5607d0aa1a52bff70fe53c7eb0c5d27b342886bcbfea7fbfefd4168951f9b/detection", "output": "\r\n \r\nUNLODCTR \r\n uninstalls a performance counter provider. \r\nUsage: \r\n UNLODCTR <service-name> \r\n uninstalls the v1.0 performance counter provider associated \r\n with the <service-name> service.\r\n UNLODCTR /m:<manifest> \r\n uninstall a v2.0 performance counter provider using the \r\n provider GUID from the specified XML manifest.\r\n UNLODCTR /g:{ProviderGuid} \r\n uninstall a v2.0 performance counter provider using the \r\n specified provider GUID. The GUID should be specified in \r\n registry form, i.e. {nnnnnnnn-nnnn...}\r\n UNLODCTR /p:<ProviderName> \r\n uninstall a v2.0 performance counter provider matching the \r\n specified provider name.\r\n\r\nNote: any arguments with spaces in the names must be enclosed within double \r\nquotation marks.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\unlodctr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "unregmp2.exe-51629AAAF753C6411D0B7D37620B7A83": { "file_name": "unregmp2.exe", "file_path": "C:\\Windows\\SysWOW64\\unregmp2.exe", "hash_md5": "51629AAAF753C6411D0B7D37620B7A83", "hash_sha1": "D9E3F08BD0B1C7282342CEA0E9D0B52CF7C54764", "hash_sha256": "CC883043ADCCFA1DD61B3DA09D89940F3B97A6E74A09AA32D0D339B0553CD728", "hash_sha384": "F46D27F793C24DF3D98A5A41BCB4FB6396B6A23A5440F10D30BCF8F7186654DA8AA56CA466D17F46361FC47761E00B3C", "hash_sha512": "BDFAE0E02F0E18171738ECB705770463E4696884AC279DE79F681A5A525C2BD58014DC8B0546A128C7AED92AEAED4219BF25009DD998F262C2ED30D965514CB3", "hash_ssdeep": "3072:9P6OfAg0IenWsWSwcCRCoE1mJ1C6U2z3maPfb9s:9gWsYRiO1CKzP3b", "hash_imp": "567DEBB2A156B506ED421C435F1B2E33", "hash_pesha1": "09F36CEC1068C1548C9DE9645C52C775E7FF2614", "hash_pe256": "539718FBE4934D85B1FBD9BC8E9DB2AD4BA08B1BEEE1E0A247A2D4DC46417ACE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Media Player Setup Utility", "meta_original_filename": "unregmp2.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/cc883043adccfa1dd61b3da09d89940f3b97a6e74a09aa32d0d339b0553cd728/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\unregmp2.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "upnpcont.exe-8079BABD3711AEE2371AA54090DAF987": { "file_name": "upnpcont.exe", "file_path": "C:\\Windows\\SysWOW64\\upnpcont.exe", "hash_md5": "8079BABD3711AEE2371AA54090DAF987", "hash_sha1": "4963E4921E238D349812241EDCB564F5C36B6DFD", "hash_sha256": "402D06EFF121D704268B193DD4FE00FD9FE37E8D1C0E1ABE6991F76E036F320F", "hash_sha384": "6BDD935604676EB47E82D11EE6F8D3F6FE23426F95DC1A8C5E11350BAA44E445A15739B01850338B0A8F606A961836A6", "hash_sha512": "5D7F867EBAFE6F265B896AB43535884DCDB4B4CAE519E8E13D767D02C7F47439C82F58C5B9CBCB122E6BBDBA8A0A371EE8E5773058EB6011E19A169D4B216B0B", "hash_ssdeep": "384:Hlhoz7hoJDDHb7mQNb3cktF8/AkNAnYB6LtDc5/ZKMZciW5MW3MUggHiADqPGL:Fhoz78HDX4hrGI/ZXZ0tMUhHGPS", "hash_imp": "7B6AE0B2821019CE4C865988D4D48C14", "hash_pesha1": "66A7B61747D28BBB8AD87C943CD4677D08184421", "hash_pe256": "78697802596957A03D4B53F67706E0030714CA4BD6B4EBA8CEA6A59478CDE3BC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UPnP Device Host Container", "meta_original_filename": "upnpcont.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.508 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.508", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/402d06eff121d704268b193dd4fe00fd9fe37e8d1c0e1abe6991f76e036f320f/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\upnpcont.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "user.exe-FD94F4868778F6142F68AC32928EDB58": { "file_name": "user.exe", "file_path": "C:\\Windows\\SysWOW64\\user.exe", "hash_md5": "FD94F4868778F6142F68AC32928EDB58", "hash_sha1": "33598712DFABE86851476DE7D68BF2AFE63D4CA7", "hash_sha256": "AE62BC1EA069F1E99EE71731A0A37A4C1AF4ED221B3F0714238989A92C533A44", "hash_sha384": "9DAEDEE868330F629B1141651E5D733A37D86F721927D1FF8FDDAAD7300D53B03F6305DB123A50B99C5F2C91D07579A3", "hash_sha512": "C3A43D720C179810E32C81AA3073687A8DFA644FFFB936A225A04927D8964CF3C64480831BB8B1A7EB66FD78CC3FF835574786F9EFCB5BB4A43576E6BC6A8502", "hash_ssdeep": "24:ev1GSAK+hAz888qTyNGK9fZY4to6IZW0gbN6l2Si35WWdPOPNm:qAJAzCqTafZY4tFIZWjh6no5Wwa", "hash_imp": "n/a", "hash_pesha1": "4E34E84C742074D1CE97A8945F75BD2537DEDEB6", "hash_pe256": "ACA820FD888A312CC9E895B66F2CE24CE4B377A6FE6B51F62250E050060901C6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "User", "meta_original_filename": "User.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ae62bc1ea069f1e99ee71731a0a37a4c1af4ed221b3f0714238989a92c533a44/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\user.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "UserAccountBroker.exe-23B09A4411EF03A09C9F119139DB9389": { "file_name": "UserAccountBroker.exe", "file_path": "C:\\Windows\\SysWOW64\\UserAccountBroker.exe", "hash_md5": "23B09A4411EF03A09C9F119139DB9389", "hash_sha1": "23F9FEB9882B00B520A9B4E37194F2AE5134729A", "hash_sha256": "CD28FE6B1B0ECFECF01AA674326FC250D158908F33EBD023356683CAE108C2BB", "hash_sha384": "AA85DB2E9016B8ABD67E5A2A13AD3BC8065ADD0A841192D58C56602C4EBDF98A9E37E7A43001C829F1D5B9D1A879BD82", "hash_sha512": "0B9A6F85CE555EB31CF6042B27144CCA3EE2389A76F9A7D5B09970C24F004B65C3FC263124EEF8146ADD19D005C738F884C4389E870D3A286AB8686D0C91D023", "hash_ssdeep": "768:qZJhrvq9Hbs0eJEsnkbQ1zWr6L2WKSF0ADpXPZ+mZlXRI1PcF3J:0JxvsHbs0eJEs7cr6BF9F/Z+mqPcX", "hash_imp": "47E33A59D99B513B43234DE272F7D64B", "hash_pesha1": "9F67EC5CABF7C74D448C67DE2BE85D89EC6BE92D", "hash_pe256": "53E54539D90126BA962F7FDD742264836C70F868DEA124B9717035F15D9B47BE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "User Account Control Panel Host", "meta_original_filename": "UserAccountBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/cd28fe6b1b0ecfecf01aa674326fc250d158908f33ebd023356683cae108c2bb/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\UserAccountBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "UserAccountControlSettings.exe-5AEA4CD2B6CA1E44E27D1A95917FEE60": { "file_name": "UserAccountControlSettings.exe", "file_path": "C:\\Windows\\SysWOW64\\UserAccountControlSettings.exe", "hash_md5": "5AEA4CD2B6CA1E44E27D1A95917FEE60", "hash_sha1": "C62BF5AF3E87BB9F990BD5436941E8837ABD55DE", "hash_sha256": "EB4C62E672647C1AD1A247356FFD738FEEA55FF0390EDFF2A2BDE89D9362250E", "hash_sha384": "E4753977FDB3BDDDC48BDCBF0A0DD146FEB2EC069426B4AA1A851D6B6B7DF8D196899937DD00D15076B08BA86D7270DC", "hash_sha512": "CAE8119ECC75CA27E2248C90B9EC04311199C86A26FE4A07F24CB1A690E5E990F9639855B3BB084EF7A00359E055504122A7D2889D2CDD9163C332DFCC1D5B02", "hash_ssdeep": "1536:I52HzscbxoZoJZ9olzy3sP751sNz0UCdkV/L7:lTZbNJZ9bcT5K", "hash_imp": "281B2F62B1066F5953A92A11BC46D367", "hash_pesha1": "1B84B6019FA85509215A46506FBA4E9CF9E72718", "hash_pe256": "D8D2C01D450B6FEF6966D7163C7423EE1279693BFE77E83045C3D47B6720455C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UserAccountControlSettings", "meta_original_filename": "UserAccountControlSettings.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/eb4c62e672647c1ad1a247356ffd738feea55ff0390edff2a2bde89d9362250e/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\UserAccountControlSettings.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "userinit.exe-05D02F412A916B7322AB94E5D8EA9767": { "file_name": "userinit.exe", "file_path": "C:\\Windows\\SysWOW64\\userinit.exe", "hash_md5": "05D02F412A916B7322AB94E5D8EA9767", "hash_sha1": "2A4291B224A998CFAAF81906529629C32ADCDB8E", "hash_sha256": "28C7D92EA3F248D2B13165E934E25C64F9D61CD2E5D293457EE62B345556A411", "hash_sha384": "A0B5FCF320B27D2F47F0412AEDCF7E03DE080EA35DB795BDC638AC6F16B5EDCD8770BCAF207CC83954664F4961310C38", "hash_sha512": "07470C315F26FD66DA8ABAC89CEBF172C3C5BC93DE4FDCD3935CFA8CD3EDC0669979CB3176755A248F43735E925B403F74906DFFABE0659EBC1BF9DFDE01D7C4", "hash_ssdeep": "384:KJR4M0xmpuIUzYzKplbKRtkkzkwm5qJeojInSDPQnMZWuymWXC/:KJR4z5bzy+14kkYwm5qcHnEonHPC/", "hash_imp": "113287C325C3EE58A84B18E1A4323892", "hash_pesha1": "81CBE1140662E00294E0E2991AFB04F87B391253", "hash_pe256": "ACBEE4886C16B07949F76FEACFC6DCAB10BDA87D547EA90A6ED8D5F569C90CC1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Userinit Logon Application", "meta_original_filename": "USERINIT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/28c7d92ea3f248d2b13165e934e25c64f9d61cd2e5d293457ee62b345556a411/detection", "children": "explorer.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\userinit.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\userinit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Utilman.exe-D5C509CBBCFA569F0A6D65C6C66B0D93": { "file_name": "Utilman.exe", "file_path": "C:\\Windows\\SysWOW64\\Utilman.exe", "hash_md5": "D5C509CBBCFA569F0A6D65C6C66B0D93", "hash_sha1": "352673FB76C6BA6A9BBEE0D77E209F5AEDF9C7D5", "hash_sha256": "9320FA0D6F39EF9650B0BBACAF413977D0D9D8BEDA578E75EB30C2E73F5011B2", "hash_sha384": "2ADECFA6F1DE4CBC6CA711E55573D6567FB712BE72C28C58F4D81DA18D703C8C67633EED2F66AB77AAB1C512BAF9F9B9", "hash_sha512": "A6F5C4EC8B30FCC77D5A1E7649C333C7C88824B33AF40C2A623A3B6CEEB71E2EA344EAEE338E8B72FC827E0F61BE81EAE43BC1391CA530BDE9E16FD81BD3428F", "hash_ssdeep": "1536:p60YTyifMZJ1acl8I/I/H0tflbqXvFZFxFKAZzPlliSPTcqgoLSbgvVoZtnrqMVr:/QysOahIZf8/HFxFKAtNX0", "hash_imp": "4B4C1E1CAFB5E924F5C11455D2B07507", "hash_pesha1": "B65BB4F36A50EA50C13644610F3FC003208CF83F", "hash_pe256": "A2FDEC93AB268AD89D3D67D3161B538142E099B82BB9E4368B2CA1E236FD942F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Utility Manager", "meta_original_filename": "utilman2.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9320fa0d6f39ef9650b0bbacaf413977d0d9d8beda578e75eb30c2e73f5011b2/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Utilman.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "verclsid.exe-190A347DF06F8486F193ADA0E90B49C5": { "file_name": "verclsid.exe", "file_path": "C:\\Windows\\SysWOW64\\verclsid.exe", "hash_md5": "190A347DF06F8486F193ADA0E90B49C5", "hash_sha1": "A2C097DB996DCAB5AC01D11DF4DDEEBC7D0F04B6", "hash_sha256": "5F6FD0BC72EB2E71918241213E97DCD8FD0DE2887A36BE58B769E8C5A4FF8598", "hash_sha384": "4B0FA5DAD679A62173E0D00C5FD5FDE5C8C446991957B830B9F25EDD49A1FBBDAC28157BBA03AF450D77A96503D564B8", "hash_sha512": "B7FFC21A13CA5A1C3520F3F1A41E35F313819A58D66F52EF78F7919945C6EB875992FA3C732F8A0E853E90AF32AE59AFF7D65F3CCF5DBF9D91679707A3E2D131", "hash_ssdeep": "192:K91EQfrn8bEjcTu8qknDtD1MJvgzNq/WSNWEN:KfTbnjcTu8qk5DWJoZSWSNWE", "hash_imp": "BDC7940F5DE0DB2F5978F34E0BD82FF0", "hash_pesha1": "304A8E030B188F081983B5C73B6D79A899F872F7", "hash_pe256": "06CA864E0F3B2596D7A68FC6748CF6917537DCE0CED0CE9A3445C1A5628635AA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extension CLSID Verification Host", "meta_original_filename": "verclsid.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5f6fd0bc72eb2e71918241213e97dcd8fd0de2887a36be58b769e8c5a4ff8598/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\verclsid.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "verifiergui.exe-56D77A92B6AFACDE189C0A5613A0F6CA": { "file_name": "verifiergui.exe", "file_path": "C:\\Windows\\SysWOW64\\verifiergui.exe", "hash_md5": "56D77A92B6AFACDE189C0A5613A0F6CA", "hash_sha1": "E9B3E76652345F59164A59CC0E2A41321012C4F9", "hash_sha256": "20385E5ADDD1D1AA1868A9999A5E336D2969BC47B985441B2C11D15EB7DD5643", "hash_sha384": "A3C87DBF9D67B8D9CB12C5D514F46FBE7F0985FE17603FC4B9D4CA8058CB67108BF66D3268692A673283ACD9B5204F98", "hash_sha512": "9D4EEDCF7DFCDE737FC050596D110478B7776AD9902D733C8EDEE3BFA96A9457119DB3663BF67497E586999E5EFA421C50C33A95699ED5E4FE88F34A92650EE8", "hash_ssdeep": "3072:+t89cJVIZen+Vcv2JBwwRBkBnRePnj0d+z7zqqxasSXoFoX5CEduASnx4k67yWNF:+tsxJ4cmYk0m92nzEcBKZ", "hash_imp": "69E8B39D5BF1D5577A79B400861EBBFB", "hash_pesha1": "D5AE3118D59DBA053E3A9AF1796FCC64FD591F97", "hash_pe256": "29AFE56707DFFE6B380F73F43AC7C62FA00BA65D06A9A178A16EA8C8FABC8146", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Driver Verifier Manager", "meta_original_filename": "verifiergui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/20385e5addd1d1aa1868a9999a5e336d2969bc47b985441b2c11d15eb7dd5643/detection", "output": " \r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n \r\nCOMMON USAGE: \r\n verifier /?\r\n verifier /standard /all\r\n verifier /standard /driver NAME [NAME ...]\r\n verifier /flags FLAGS /all\r\n verifier /flags FLAGS /driver NAME [NAME ...]\r\n verifier /rules [OPTION ...]\r\n verifier /query\r\n verifier /querysettings\r\n verifier /bootmode [persistent|resetonbootfail|oneboot]\r\n verifier /reset\r\n verifier /faults [PROB [TAGS [APPS [MINS]]]]\r\n verifier /faultssystematic [OPTION ...]\r\n verifier /log LOG_FILE_NAME [/interval SECONDS]\r\n verifier /volatile /flags FLAGS\r\n verifier /volatile /adddriver NAME [NAME ...]\r\n verifier /volatile /removedriver NAME [NAME ...]\r\n verifier /volatile /faults [PROB [TAGS [APPS [MINS]]]]\r\n \r\n/?\r\n This help.\r\n \r\n/standard\r\n Enable the Driver Verifier standard flags. \r\n This is functionally equivalent to '/flags 0x209BB'\r\n \r\n/all\r\n Enable Driver Verifier on all drivers in a system.\r\n \r\n/driver NAME [NAME ...]\r\n Specify the driver or list of drivers that should be verified.\r\n NAME is the name and extension of the file to verify (example: driver.sys).\r\n To enable Driver Verifier on more than one driver, list all drivers using a\r\n space separated list. Wildcard values (such as n*.sys) are not supported.\r\n \r\n/flags FLAGS \r\n Specify which options are enabled for verification. \r\n FLAGS value must be a number in decimal or hex (with 0x prefix).\r\n Note: Flags are applied to all drivers being checked by Driver Verifier. \r\n \r\n STANDARD FLAGS:\r\n These flags are considered standard options for Driver Verifier and can be \r\n set using '/standard' or by the combination of the options: '/flags 0x209BB'\r\n bit 0 (0x00000001) - Special pool\r\n bit 1 (0x00000002) - Force IRQL checking\r\n bit 3 (0x00000008) - Pool tracking\r\n bit 4 (0x00000010) - I/O verification\r\n bit 5 (0x00000020) - Deadlock detection\r\n bit 7 (0x00000080) - DMA checking\r\n bit 8 (0x00000100) - Security checks\r\n bit 11 (0x00000800) - Miscellaneous checks\r\n bit 17 (0x00020000) - DDI compliance checking\r\n \r\n ADDITIONAL FLAGS:\r\n These flags are designed for specific scenario testing.\r\n Flags marked with a (*) require I/O Verification (bit 4) also be enabled.\r\n Flags marked with a (**) support disabling of individual rules.\r\n bit 2 (0x00000004) - Randomized low resources simulation\r\n bit 9 (0x00000200) - Force pending I/O requests (*)\r\n bit 10 (0x00000400) - IRP logging (*)\r\n bit 13 (0x00002000) - Invariant MDL checking for stack (*)\r\n bit 14 (0x00004000) - Invariant MDL checking for driver (*)\r\n bit 15 (0x00008000) - Power framework delay fuzzing\r\n bit 16 (0x00010000) - Port/miniport interface checking\r\n bit 18 (0x00040000) - Systematic low resources simulation\r\n bit 19 (0x00080000) - DDI compliance checking (additional)\r\n bit 21 (0x00200000) - NDIS/WIFI verification (**)\r\n bit 23 (0x00800000) - Kernel synchronization delay fuzzing\r\n bit 24 (0x01000000) - VM switch verification\r\n bit 25 (0x02000000) - Code integrity checks\r\n \r\n/rules [OPTION ...]\r\n Options for rules that can be disabled (advanced). \r\n query: shows current status of controllable rules.\r\n reset: resets all rules to their default state.\r\n default ID: sets rule ID to its default state.\r\n disable ID: disables specified rule ID.\r\n \r\n/query\r\n Display a summary of Driver Verifier's current activity.\r\n \r\n/querysettings\r\n Display a summary of the options and drivers that are currently enabled, \r\n or options and drivers that will be verified after the next boot. The \r\n display does not include drivers and options added using /volatile.\r\n \r\n/bootmode\r\n Sets the verifier boot mode. Requires reboot to take effect.\r\n persistent: Ensures that DV settings are persistent over many reboots.\r\n This is default.\r\n resetonbootfail: If OS fails to boot, reset verifier for subsequent boots.\r\n oneboot: Only enable verifier for next boot.\r\n \r\n/reset\r\n Clear Driver Verifier flag and driver settings. Does not clear bootmode.\r\n Requires reboot to take effect.\r\n \r\n/faults [PROB [TAGS [APPS [MINS]]]]\r\n Enable the Randomized low resources simulation bit and optionally control\r\n parameters for the Randomized low resources simulation.\r\n PROB: A number between 1 and 10000 specifying the fault injection \r\n probability. If this parameter is not specified, then the default \r\n value of 600 (6%) will be used.\r\n TAGS: A space separated list of the pool tags to be injected with faults.\r\n If this parameter is not specified, then any pool allocation can be\r\n injected with faults.\r\n APPS: A space separated list of the image filename of the applications that\r\n will be injected with faults. If this parameter is not specified then\r\n the Randomized low resources simulation can take place in any\r\n application.\r\n MINS: A positive number indicating the of minutes after rebooting during \r\n which no fault injection will occur. If this parameter is not \r\n specified, then the default length of 8 minutes will be used.\r\n \r\n/faultssystematic [OPTION ...]\r\n Options for controlling the Systematic low resources simulation.\r\n enableboottime: enables fault injections across reboots.\r\n disableboottime: disables fault injections across reboots (default).\r\n recordboottime: enables fault injections in 'what if' mode across\r\n reboots.\r\n resetboottime: disables fault injections across reboots and clears\r\n the stack exclusion list.\r\n enableruntime: dynamically enables fault injections.\r\n disableruntime: dynamically disables fault injections.\r\n recordruntime: dynamically enables fault injections in 'what if'\r\n mode.\r\n resetruntime: dynamically disables fault injections and clears the\r\n previosly faulted stack list.\r\n querystatistics: shows the current fault injection statistics.\r\n incrementcounter: increments the test pass counter used to identify\r\n when a fault was injected.\r\n getstackid COUNTER: retrieves the indicated injected stack id.\r\n excludestack STACKID: excludes the stack from fault injection.\r\n \r\n/log LOG_FILE_NAME [/interval SECONDS]\r\n Create a log file with the name LOG_FILE_NAME. \r\n If '/interval' option is not specified, the default 30 seconds is used. \r\n Note: If a 'verifier /log' command is typed at the command line, the command\r\n prompt does not return. Use CTRL+C to close the log and return.\r\n \r\n/volatile\r\n Change the verifier settings dynamically without rebooting the system.\r\n Volatile settings are in effect until the next system reboot. \r\n \r\n/volatile /adddriver NAME [NAME ...]\r\n Add the specified driver or drivers to the list of drivers that will be \r\n checked with volatile settings. \r\n \r\n/volatile /removedriver NAME [NAME ...]\r\n Remove the specified driver or drivers from the list of drivers that are\r\n being checked with volatile settings. \r\n \r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\verifiergui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "w32tm.exe-E55B6A057FDDD35A7380FB2C6811A8EC": { "file_name": "w32tm.exe", "file_path": "C:\\Windows\\SysWOW64\\w32tm.exe", "hash_md5": "E55B6A057FDDD35A7380FB2C6811A8EC", "hash_sha1": "82278696B965951D33693EDC5F0B99525027BDDE", "hash_sha256": "8AB5C40895D73907B4F96BA73E73C5BF12A76A00965034A4146F85533B14F5C4", "hash_sha384": "AE76E7A4DB93F7B25A6BBDA9E809963415054C7DC9C580BFA884BCB5E176BBF5F6DCFFAEFEDC4A0819373157A3D86056", "hash_sha512": "F7C44CEDF76A8DAEF70AD49AE5E1A689D385404BC7D082A755B583FADA9322286877C76576969C7B1B74C17DD0C11A444CC0A97B7F07F7AEED5AD49D95ACF620", "hash_ssdeep": "1536:JkYpn6hGSs+J6+b2Y+q1cwg923QHDD1sXmQIIeaHWS0yZjXoHIdw:JN6hGSj3yiHAHDD1sXmQIKHV0yZDood", "hash_imp": "D1AE67178348CFD1F11538AA577D5EEE", "hash_pesha1": "99B3967DEF6992C66BFDBA7227A69B6EA8FE9FEE", "hash_pe256": "0D8A86A241EB4261BD1DDB050E5FD84EA629CDFEDCAFE9D6192AD5AE8E974A68", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Time Service Diagnostic Tool", "meta_original_filename": "w32time.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8ab5c40895d73907b4f96ba73e73c5bf12a76a00965034a4146f85533b14f5c4/detection", "output": "w32tm [/? | /register | /unregister ]\r\n ? - this help screen.\r\n register - register to run as a service and add default\r\n configuration to the registry.\r\n unregister - unregister service and remove all configuration\r\n information from the registry.\r\n\r\nw32tm /monitor [/domain:<domain name>]\r\n [/computers:<name>[,<name>[,<name>...]]]\r\n [/threads:<num>] [/ipprotocol:<4|6>] [/nowarn]\r\n domain - specifies which domain to monitor. If no domain name\r\n is given, or neither the domain nor computers option is\r\n specified, the default domain is used. This option may be\r\n used more than once.\r\n computers - monitors the given list of computers. Computer\r\n names are separated by commas, with no spaces. If a name is\r\n prefixed with a '*', it is treated as an AD PDC. This option\r\n may be used more than once.\r\n threads - how many computers to analyze simultaneously. The\r\n default value is 3. Allowed range is 1-50.\r\n ipprotocol - specify the IP protocol to use. The default is\r\n to use whatever is available.\r\n nowarn - skip warning message.\r\n\r\nw32tm /ntte <NT time epoch>\r\n Convert a NT system time, in (10^-7)s intervals from 0h 1-Jan 1601,\r\n into a readable format.\r\n\r\nw32tm /ntpte <NTP time epoch>\r\n Convert an NTP time, in (2^-32)s intervals from 0h 1-Jan 1900, into\r\n a readable format.\r\n\r\nw32tm /resync [/computer:<computer>] [/nowait] [/rediscover] [/soft]\r\n Tell a computer that it should resynchronize its clock as soon\r\n as possible, throwing out all accumulated error statistics.\r\n computer:<computer> - computer that should resync. If not\r\n specified, the local computer will resync.\r\n nowait - do not wait for the resync to occur;\r\n return immediately. Otherwise, wait for the resync to\r\n complete before returning.\r\n rediscover - redetect the network configuration and rediscover\r\n network sources, then resynchronize.\r\n soft - resync utilizing existing error statistics. Not useful,\r\n provided for compatibility.\r\n\r\nw32tm /stripchart /computer:<target> [/period:<refresh>]\r\n [/dataonly] [/samples:<count>] [/packetinfo] [/ipprotocol:<4|6>] [/rdtsc]\r\n Display a strip chart of the offset between this computer and\r\n another computer.\r\n computer:<target> - the computer to measure the offset against.\r\n period:<refresh> - the time between samples, in seconds. The\r\n default is 2s\r\n dataonly - display only the data, no graphics.\r\n samples:<count> - collect <count> samples, then stop. If not\r\n specified, samples will be collected until Ctrl-C is pressed.\r\n packetinfo - print out NTP packet response message.\r\n ipprotocol - specify the IP protocol to use. The default is \r\n to use whatever is available.\r\n rdtsc - display the TSC values and time offset data in CSV format.\r\n The output displays TSC and FILETIME values captured before the \r\n NTP request is sent, TSC value after an NTP response is received\r\n along with NTP roundtrip and time offset values.\r\n\r\n\r\nw32tm /config [/computer:<target>] [/update]\r\n [/manualpeerlist:<peers>] [/syncfromflags:<source>]\r\n [/LocalClockDispersion:<seconds>]\r\n [/reliable:(YES|NO)]\r\n [/largephaseoffset:<milliseconds>]\r\n computer:<target> - adjusts the configuration of <target>. If not\r\n specified, the default is the local computer.\r\n update - notifies the time service that the configuration has\r\n changed, causing the changes to take effect.\r\n manualpeerlist:<peers> - sets the manual peer list to <peers>,\r\n which is a space-delimited list of DNS and/or IP addresses.\r\n When specifying multiple peers, this switch must be enclosed in\r\n quotes.\r\n syncfromflags:<source> - sets what sources the NTP client should\r\n sync from. <source> should be a comma separated list of\r\n these keywords (not case sensitive):\r\n MANUAL - sync from peers in the manual peer list\r\n DOMHIER - sync from an AD DC in the domain hierarchy\r\n NO - sync from none\r\n ALL - sync from both manual and domain peers \r\n LocalClockDispersion:<seconds> - configures the accuracy of the\r\n internal clock that w32time will assume when it can't acquire \r\n time from its configured sources. \r\n reliable:(YES|NO) - set whether this machine is a reliable time source.\r\n This setting is only meaningful on domain controllers. \r\n YES - this machine is a reliable time service\r\n NO - this machine is not a reliable time service\r\n largephaseoffset:<milliseconds> - sets the time difference between \r\n local and network time which w32time will consider a spike. \r\n\r\nw32tm /tz\r\n Display the current time zone settings.\r\n\r\nw32tm /dumpreg [/subkey:<key>] [/computer:<target>]\r\n Display the values associated with a given registry key.\r\n The default key is HKLM\\System\\CurrentControlSet\\Services\\W32Time\r\n (the root key for the time service).\r\n subkey:<key> - displays the values associated with subkey <key> \r\n of the default key.\r\n computer:<target> - queries registry settings for computer <target>.\r\n\r\nw32tm /query [/computer:<target>] \r\n {/source | /configuration | /peers | /status} \r\n [/verbose]\r\n Display a computer's windows time service information.\r\n computer:<target> - query the information of <target>. If not\r\n specified, the default is the local computer.\r\n source: display the time source.\r\n configuration: display the configuration of run-time and where \r\n the setting comes from. In verbose mode, display the undefined \r\n or unused setting too.\r\n peers: display a list of peers and their status.\r\n status: display windows time service status.\r\n verbose: set the verbose mode to display more information.\r\n\r\nw32tm /debug {/disable | {/enable /file:<name> /size:<bytes> /entries:<value>\r\n [/truncate]}} \r\n Enable or disable local computer windows time service private log.\r\n disable: disable the private log.\r\n enable: enable the private log.\r\n file:<name> - specify the absolute filename.\r\n size:<bytes> - specify the maximum size for circular logging.\r\n entries:<value> - contains a list of flags, specified by number and\r\n separated by commas, that specify the types of information that \r\n should be logged. Valid numbers are 0 to 300. A range of numbers \r\n is valid, in addition to single numbers, such as 0-100,103,106. \r\n Value 0-300 is for logging all information.\r\n truncate: truncate the file if it exists.\r\n\r\nw32tm /leapseconds /getstatus [/verbose]\r\n Display the status of leap seconds on the local machine.\r\n verbose: Set the verbose mode to display more information.\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\w32tm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "waitfor.exe-E58E152B44F20DD099C5105DE482DF24": { "file_name": "waitfor.exe", "file_path": "C:\\Windows\\SysWOW64\\waitfor.exe", "hash_md5": "E58E152B44F20DD099C5105DE482DF24", "hash_sha1": "BD67490FD205C697CC481B5D1741D63A96D136EA", "hash_sha256": "D9E9DD5A87E171DCBEF7CA034E3A7DFB5C37A7F70AA7DB99A0CCAD24F16C97DC", "hash_sha384": "FAFB9D5FEB92EA3903DC92C59CCBA9AC04C310EF2FA0EB1277C12020B1689A249309F77A05EE21C2B5031072FD1C2B66", "hash_sha512": "3CE9EB3B9A3FBD40E1D4932A8E265CD80FBAF3767DD602631A96661F57BABF055031D99B635597D802E23A316CD5B22527AA9402CB0A39E486E9D701E35C78CC", "hash_ssdeep": "768:7HafjFdAjL+LAACIOtev4ioK5VDAeHeqO9xapd1pSx:7HafjFYIOg4if5Se+qCxidC", "hash_imp": "B03EDAA7CAD5E6CDC3A3B4CB4A721AD1", "hash_pesha1": "29B46F276A06968F55ED82DBB5FCA0DCFF85E2FD", "hash_pe256": "930643A9D187078EAFAEEF9849DE34F3EBF9BF891B6B67CE89341A13E79C4FDA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "waitfor - wait/send a signal over a network", "meta_original_filename": "waitfor.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d9e9dd5a87e171dcbef7ca034e3a7dfb5c37a7f70aa7db99a0ccad24f16c97dc/detection", "output": "\r\nWaitFor has two ways of working: \r\n\r\nSyntax 1: to send a signal\r\n WAITFOR [/S system [/U user [/P [password]]]] /SI signal\r\n\r\nSyntax 2: to wait for a signal\r\n WAITFOR [/T timeout] signal \r\n\r\nDescription:\r\n This tool sends, or waits for, a signal on a system. When /S is not\r\n specified, the signal will be broadcasted to all the systems in a\r\n domain. If /S is specified, then the signal will be sent only\r\n to the specified system.\r\n\r\nParameter List:\r\n /S system Specifies remote system to send signal to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given user context.\r\n\r\n /SI Sends the signal across the net to waiting machines\r\n\r\n /T timeout Number of seconds to wait for signal. Valid range\r\n is 1 - 99999. Default is to wait forever for signal.\r\n\r\n signal The name of the signal to wait for or to send.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE: A system can wait for multiple unique signal names.\r\n The signal name cannot exceed 225 characters and cannot\r\n contain characters other than a-z, A-Z, 0-9 and ASCII \r\n characters in the range 128-255.\r\n\r\nExamples:\r\n WAITFOR /?\r\n WAITFOR SetupReady \r\n WAITFOR CopyDone /T 100 \r\n WAITFOR /SI SetupReady \r\n WAITFOR /S system /U user /P password /SI CopyDone\r\n", "error": "ERROR: The signal cannot contain characters other than a-z, A-Z, 0-9 \r\nand ASCII characters in the range 128-255.\r\n", "children": "perfmon.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\waitfor.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\waitfor.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wecutil.exe-CC6FB0A8AB7197D1A0A85B00618924BE": { "file_name": "wecutil.exe", "file_path": "C:\\Windows\\SysWOW64\\wecutil.exe", "hash_md5": "CC6FB0A8AB7197D1A0A85B00618924BE", "hash_sha1": "78A0878B337C36F7D18005D38CCCB6C0D0A2221C", "hash_sha256": "6538B49C984D6C100A969A90F337C158C52AD072D84DF746F676176728E74520", "hash_sha384": "DF69EAF39FF71726EDE59FFA2541BD0E285297592640907FBAF8B59A37325120BC0E61CC1E57E5D7B93281C3DE851A7B", "hash_sha512": "380E2FF5C6CA11E499BD8BA46144BE6F5E91B5E05330AEECBAE52B32DCD4A9DFD90699E388087CB7A2496AB438EC6B89DB73A47D9F5D2BE4C38EC0FF387B04F1", "hash_ssdeep": "1536:Dqw+kFxE47uKKB3ZYaz17oNAXH8ElX6D7YAnQIdH:Dqw+k3xu/pYazloNi8ElX6vNn", "hash_imp": "36A8613F9674F9017579506661662D09", "hash_pesha1": "AC9F3BA8E42895E3375D1A3A2F6B9F9FB52117CF", "hash_pe256": "E04A6DA0EAE51FA9293DBB35C446537EC0319E2993286CA97F7E6763CD6F5B7A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Collector Command Line Utility", "meta_original_filename": "WECUTIL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "1/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/6538b49c984d6c100a969a90f337c158c52ad072d84df746f676176728e74520/detection", "output": "Windows Event Collector Utility\r\n\r\nEnables you to create and manage subscriptions to events forwarded from remote\r\nevent sources that support WS-Management protocol.\r\n\r\nUsage:\r\n\r\nYou can use either the short (i.e. es, /f) or long (i.e. enum-subscription, /format)\r\nversion of the command and option names. Commands, options and option values are\r\ncase-insensitive.\r\n\r\n(ALL UPPER-CASE = VARIABLE)\r\n\r\nwecutil COMMAND [ARGUMENT [ARGUMENT] ...] [/OPTION:VALUE [/OPTION:VALUE] ...]\r\n\r\nCommands:\r\n\r\nes (enum-subscription) List existent subscriptions.\r\ngs (get-subscription) Get subscription configuration.\r\ngr (get-subscriptionruntimestatus) Get subscription runtime status.\r\nss (set-subscription) Set subscription configuration.\r\ncs (create-subscription) Create new subscription.\r\nds (delete-subscription) Delete subscription.\r\nrs (retry-subscription) Retry subscription.\r\nqc (quick-config) Configure Windows Event Collector service.\r\n\r\nCommon options:\r\n\r\n/h|? (help)\r\nGet general help for the wecutil program.\r\n\r\nwecutil { -help | -h | -? }\r\n\r\nFor arguments and options, see usage of specific commands:\r\n\r\nwecutil COMMAND -?\r\n", "error": "Command help is not supported. Error = 0x57.\r\nThe parameter is incorrect.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wecutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WerFault.exe-449DAAB4CBDB9298FF841FE24B00A927": { "file_name": "WerFault.exe", "file_path": "C:\\Windows\\SysWOW64\\WerFault.exe", "hash_md5": "449DAAB4CBDB9298FF841FE24B00A927", "hash_sha1": "195477A0E2238F56C396C9D43863B6D2BCA54182", "hash_sha256": "83A761B12295B06047BE6CA13A142E2B944F7394D6BAEC64956612DC1CE64461", "hash_sha384": "A7C963B8A8FAC6110D693EAA3F7434594E221730C66CCCCE74F6270E3E428C8CE04C4289E2E71AA7352956CB966C8B01", "hash_sha512": "543EFC28CA37AEF8D66B3044F025267E7AF9D539AF9908EC205B1927D1458722F307B916ED5D8241C58195EE62AA1F79AB347AF7A540F3EE84A860E42F05296C", "hash_ssdeep": "12288:vwGGEy0sw6uJeIcxsDKHZ1L8ZzbcUUOevJec2HywPQWt:oGGE3l6IbcxsDshibcHOevJecyhPz", "hash_imp": "C8DD8BDD184BD81C95776BD2A73DCF11", "hash_pesha1": "4654A2B36F79610DE03764C5578E97A652F96430", "hash_pe256": "F99823C97D5BDF51DAEE52131E0C99443EB6B2436B02C36C60B427D8C1337F85", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Problem Reporting", "meta_original_filename": "WerFault.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.630 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.630", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/83a761b12295b06047be6ca13a142e2b944f7394d6baec64956612dc1ce64461/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\WerFault.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WerFaultSecure.exe-CD4F627126DA5122B6D4411131ED7DA6": { "file_name": "WerFaultSecure.exe", "file_path": "C:\\Windows\\SysWOW64\\WerFaultSecure.exe", "hash_md5": "CD4F627126DA5122B6D4411131ED7DA6", "hash_sha1": "D20253B1D8EF19590B167346948CFAF39C9BD5AB", "hash_sha256": "FEF2781843B51E8CB25C9F3757E0312652A205447297F9808B31196F84A9E70E", "hash_sha384": "8CABA2B67E1D2B251A622707C8E4F3A66A92459B1970F3913D45993AB6D49CEE080F552D678D917D4E7FBC192CE361E2", "hash_sha512": "C0BCE080BDE8AE9521D2F5B35EE14F8BCA994212FB5CC950364D7B9BDA09B9FDAC01BD33601D1BE8C4773AD29E70B0DD80ECDB1760AB19CB20A52B34781064F7", "hash_ssdeep": "3072:ygSUPrklN8uUMcHIQAHttdeoanOFJ+yC3pwRb6JPqB604HHy7hRCd39vjmxcr:y1Uz+N1UMwIQAHDdepVVJyB60OHyLC7d", "hash_imp": "AAE744DE1BB31F77049F9318A9550524", "hash_pesha1": "197FEE820CAC10F474B733726E0A45EE888E403D", "hash_pe256": "8A235E208F2D420C685F6594EDC02D1AD68921A80D3E343DD4474022B5FCA29B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Fault Reporting", "meta_original_filename": "WerFaultSecure.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/fef2781843b51e8cb25c9f3757e0312652a205447297f9808b31196f84a9e70e/detection" }, "wermgr.exe-B64826620DD8495C0191B536FA1B1D32": { "file_name": "wermgr.exe", "file_path": "C:\\Windows\\SysWOW64\\wermgr.exe", "hash_md5": "B64826620DD8495C0191B536FA1B1D32", "hash_sha1": "76F80FDB20EBFFBCB511E7E1314F1862ACE226D6", "hash_sha256": "D5B2188F3BB067DF02FBC194AF4E34E538F15BD1F9AF739B260FA0E59E6A9BDC", "hash_sha384": "102694CD5EB8076CD1365B00D63084F4EC4146008FA077E6473D98F4F42F2DC6CD563CCE6A68216804498D4A4147F457", "hash_sha512": "FE57B0A4DCD79CDF2409107F4032017956D0EFB4818A8716B7420F85BA6B129F5F935496DD71EBF235BDC6640D06F26E82B339E586CF741A6BEB65FFA62F7C92", "hash_ssdeep": "6144:8aeFsyQB/uPqGI27Hq+HsD5knZhscDg6obiO4VJyB60OHyLC7vu:u2oXKxDmnZhsSBTOQc2HywG", "hash_imp": "7FD2842DEB95BE732351A40A75FE7619", "hash_pesha1": "1165FDCDF7F4F1F99D8AB00A60D93DAD5C12E878", "hash_pe256": "4B78ADA4AB70973A3F3140948178A09E3C86825058FF8C48441389D1A8D8B712", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Problem Reporting", "meta_original_filename": "WerMgr", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.685 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.685", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d5b2188f3bb067df02fbc194af4e34e538f15bd1f9af739b260fa0e59e6a9bdc/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wermgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wevtutil.exe-0E025F26677E65AEE9C6099B4E5B2770": { "file_name": "wevtutil.exe", "file_path": "C:\\Windows\\SysWOW64\\wevtutil.exe", "hash_md5": "0E025F26677E65AEE9C6099B4E5B2770", "hash_sha1": "99369BD13B6D2DBA2A4B91A1287510B8986DAF1E", "hash_sha256": "F1F16A423959485A949536E61CC63D55879CD7D58F6FD563E918A719B59F8803", "hash_sha384": "B07F0F7A6EB9ACF12DA1EF487FCCFCD6A803DD6175CCF510FAE98CB195B9F828E291B63BB06C956626AA6430CB1C962E", "hash_sha512": "AD7905289C0800F52CA899AB6AA43E9B83A79DE74D191CC504722ECCE6C7194EEE108DB26866E360823058199516ADE778AF5D3F4FCC1331E48AF5C5FA512FDD", "hash_ssdeep": "3072:YD5yF00+oM7uvvaj2cnNSxwmmaK42n5O5BVXW9C5l7cSxVN/fBHmxe8LttfVLh:CmM7uvvw2cnNS6mmtiXW9Cv7cSjN/fB8", "hash_imp": "607622C9EE3CBE46492441745A46D822", "hash_pesha1": "C5439060F365854FBF5E59F8AE1690EBA318B9D9", "hash_pe256": "A30339FD04008D7DF1193557DFAB9A4CCE90190E901005DBDEDD75B636D4C13D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Eventing Command Line Utility", "meta_original_filename": "wevtutil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f1f16a423959485a949536e61cc63d55879cd7d58f6fd563e918a719b59f8803/detection", "output": "Windows Events Command Line Utility.\r\n\r\nEnables you to retrieve information about event logs and publishers, install\r\nand uninstall event manifests, run queries, and export, archive, and clear logs.\r\n\r\nUsage:\r\n\r\nYou can use either the short (for example, ep /uni) or long (for example, \r\nenum-publishers /unicode) version of the command and option names. Commands, \r\noptions and option values are not case-sensitive.\r\n\r\nVariables are noted in all upper-case.\r\n\r\nwevtutil COMMAND [ARGUMENT [ARGUMENT] ...] [/OPTION:VALUE [/OPTION:VALUE] ...]\r\n\r\nCommands:\r\n\r\nel | enum-logs List log names.\r\ngl | get-log Get log configuration information.\r\nsl | set-log Modify configuration of a log.\r\nep | enum-publishers List event publishers.\r\ngp | get-publisher Get publisher configuration information.\r\nim | install-manifest Install event publishers and logs from manifest.\r\num | uninstall-manifest Uninstall event publishers and logs from manifest.\r\nqe | query-events Query events from a log or log file.\r\ngli | get-log-info Get log status information.\r\nepl | export-log Export a log.\r\nal | archive-log Archive an exported log.\r\ncl | clear-log Clear a log.\r\n\r\nCommon options:\r\n\r\n/{r | remote}:VALUE\r\nIf specified, run the command on a remote computer. VALUE is the remote computer \r\nname. Options /im and /um do not support remote operations.\r\n\r\n/{u | username}:VALUE\r\nSpecify a different user to log on to the remote computer. VALUE is a user name\r\nin the form domain\\user or user. Only applicable when option /r is specified.\r\n\r\n/{p | password}:VALUE\r\nPassword for the specified user. If not specified, or if VALUE is \"*\", the user \r\nwill be prompted to enter a password. Only applicable when the /u option is\r\nspecified.\r\n\r\n/{a | authentication}:[Default|Negotiate|Kerberos|NTLM]\r\nAuthentication type for connecting to remote computer. The default is Negotiate.\r\n\r\n/{uni | unicode}:[true|false]\r\nDisplay output in Unicode. If true, then output is in Unicode. \r\n\r\nTo learn more about a specific command, type the following:\r\n\r\nwevtutil COMMAND /?\r\n", "error": "Command help is not supported.\r\nThe parameter is incorrect.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wevtutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wextract.exe-B9CC7E24DB7DE2E75678761B1D8BAC3E": { "file_name": "wextract.exe", "file_path": "C:\\Windows\\SysWOW64\\wextract.exe", "hash_md5": "B9CC7E24DB7DE2E75678761B1D8BAC3E", "hash_sha1": "863DD28F1702054C0F831C127A1E5EA6D9459A04", "hash_sha256": "085DE9DF12EB199667F49BA42BDC20EE7AD86BA5B856016AF17FDCBAD17F0043", "hash_sha384": "35CA9F6442609C2EF6114436F5E30449C7D67F7955FCE114F47823ED1D2FFCC6136D18EC5B37276BD5030D2361CEDAFB", "hash_sha512": "D3B555F63547CFEEB0EABDF5CC4F7ABAB3A40D90395B4CFC27C7A6FEA7B84FFCEA816BDDE6979FB278E0A966AC3AD4C1A1386EF1DC02DCAB1F891ED92EB206C8", "hash_ssdeep": "3072:QOhX0N7+f1O8Wp1icKAArDZz4N9GhbkUNEk956y:VhEN7+Y9p0yN90vEq", "hash_imp": "646167CCE332C1C252CDCB1839E0CF48", "hash_pesha1": "3A2EB5FC8096DF125463B756CC0FA5EEF073F642", "hash_pe256": "1F6839C00841CE7C3DE4B301F5BF9CA4F172E2AEE6B0AED718485F9750DB41F2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Win32 Cabinet Self-Extractor ", "meta_original_filename": "WEXTRACT.EXE .MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/085de9df12eb199667f49ba42bdc20ee7ad86ba5b856016af17fdcbad17f0043/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\wextract.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\wextract.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "where.exe-5630411B5F4F453CA575248F7AD4C89F": { "file_name": "where.exe", "file_path": "C:\\Windows\\SysWOW64\\where.exe", "hash_md5": "5630411B5F4F453CA575248F7AD4C89F", "hash_sha1": "A2A4EE39FD37AC45AED3C17DD32D8F0B9AB13400", "hash_sha256": "D591F730F356D7623D8B6DFE5DF48CB994322CA98F88CE2278EFD4090767DFA0", "hash_sha384": "6A3499734D85C8E6A784B57155DC88CD6ED1B7EDC467758FB7FF509F8033BFD733CC59ED0E8D90985D75369FFE38188A", "hash_sha512": "C951619F200186A0A4A49EE6792637D0ADEA4E7E66B3B07871FC1DAEE25FC25AC85D9085121024C5669CAABD897667765D2252264D6CC4D6E489EB166CAA40C5", "hash_ssdeep": "768:KbXPtGDcjUKc7ulvnk+8IkhhQC4/qYwUj847vClltxYOuO:kXPtGDcJcqlGUzVwhWIx3uO", "hash_imp": "C6F8BF70A2BF252E595BCF3EB4236860", "hash_pesha1": "D6E2C98AFF01BC6C10F92D4887041FCFA0D284F3", "hash_pe256": "017613EEED7207D06D47F4B46A0E19FF4C262761936211A2C451124F24D33E18", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Where - Lists location of files", "meta_original_filename": "where.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d591f730f356d7623d8b6dfe5df48cb994322ca98f88ce2278efd4090767dfa0/detection", "output": "\r\nWHERE [/R dir] [/Q] [/F] [/T] pattern...\r\n\r\nDescription:\r\n Displays the location of files that match the search pattern.\r\n By default, the search is done along the current directory and\r\n in the paths specified by the PATH environment variable.\r\n\r\nParameter List:\r\n /R Recursively searches and displays the files that match the\r\n given pattern starting from the specified directory.\r\n\r\n /Q Returns only the exit code, without displaying the list\r\n of matched files. (Quiet mode)\r\n\r\n /F Displays the matched filename in double quotes.\r\n\r\n /T Displays the file size, last modified date and time for all\r\n matched files.\r\n\r\n pattern Specifies the search pattern for the files to match.\r\n Wildcards * and ? can be used in the pattern. The\r\n \"$env:pattern\" and \"path:pattern\" formats can also be\r\n specified, where \"env\" is an environment variable and\r\n the search is done in the specified paths of the \"env\"\r\n environment variable. These formats should not be used\r\n with /R. The search is also done by appending the\r\n extensions of the PATHEXT variable to the pattern.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE: The tool returns an error level of 0 if the search is\r\n successful, of 1 if the search is unsuccessful and\r\n of 2 for failures or errors.\r\n\r\nExamples:\r\n WHERE /?\r\n WHERE myfilename1 myfile????.*\r\n WHERE $windir:*.* \r\n WHERE /R c:\\windows *.exe *.dll *.bat \r\n WHERE /Q ??.??? \r\n WHERE \"c:\\windows;c:\\windows\\system32:*.dll\"\r\n WHERE /F /T *.dll \r\n", "error": "ERROR: Invalid argument or option - '/h'.\r\nType \"WHERE /?\" for usage help.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\where.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "whoami.exe-801D9A1C1108360B84E60A457D5A773A": { "file_name": "whoami.exe", "file_path": "C:\\Windows\\SysWOW64\\whoami.exe", "hash_md5": "801D9A1C1108360B84E60A457D5A773A", "hash_sha1": "36E086A58BB94D8EAA63D5BA113348AA45611035", "hash_sha256": "91D257EC8800204642D96D2A0FB87937529C36DEBD5C3AD4380F79ACC91B62CF", "hash_sha384": "B54A7A901F0094CD806E6C2FDE432A31750EF208DFB3A9B0F8ABF873B99DEF37B03F021C4436D43BD4220C9D69B37B81", "hash_sha512": "C9930CC13B764AF163CEE908E88F1A82693336D506EEED3B31AA49D5F3D96E0ADA3A1BE407C232E7745320E68712B0A116BCFAADE7183FDE206A691FFF6A6340", "hash_ssdeep": "1536:2t/dhpMQIKr5tnv9e3QDDciEwNyZg7cznOQ85hxG4lWBH:3Cr5tVeADoiKg7cznOQIhx7lm", "hash_imp": "E91037BB26500603D5EE8666BA6C2510", "hash_pesha1": "9B0EE7D8A111953EA339CE1F2F88A98F7EBC6487", "hash_pe256": "AB60AB232820E9C8CC9E57C5B216FA2F3549190B611E3A52AF83290458EE8D7F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "whoami - displays logged on user information", "meta_original_filename": "whoami.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/91d257ec8800204642d96d2a0fb87937529c36debd5c3ad4380f79acc91b62cf/detection", "output": "\r\nWhoAmI has three ways of working: \r\n\r\nSyntax 1:\r\n WHOAMI [/UPN | /FQDN | /LOGONID]\r\n\r\nSyntax 2:\r\n WHOAMI { [/USER] [/GROUPS] [/CLAIMS] [/PRIV] } [/FO format] [/NH]\r\n\r\nSyntax 3:\r\n WHOAMI /ALL [/FO format] [/NH]\r\n\r\nDescription:\r\n This utility can be used to get user name and group information\r\n along with the respective security identifiers (SID), claims,\r\n privileges, logon identifier (logon ID) for the current user\r\n on the local system. I.e. who is the current logged on user?\r\n If no switch is specified, tool displays the user name in NTLM\r\n format (domain\\username).\r\n\r\nParameter List:\r\n /UPN Displays the user name in User Principal \r\n Name (UPN) format.\r\n\r\n /FQDN Displays the user name in Fully Qualified \r\n Distinguished Name (FQDN) format.\r\n\r\n /USER Displays information on the current user\r\n along with the security identifier (SID).\r\n\r\n /GROUPS Displays group membership for current user,\r\n type of account, security identifiers (SID)\r\n and attributes.\r\n\r\n /CLAIMS Displays claims for current user,\r\n including claim name, flags, type and values.\r\n\r\n /PRIV Displays security privileges of the current\r\n user.\r\n\r\n /LOGONID Displays the logon ID of the current user.\r\n\r\n /ALL Displays the current user name, groups \r\n belonged to along with the security \r\n identifiers (SID), claims and privileges for \r\n the current user access token.\r\n\r\n /FO format Specifies the output format to be displayed.\r\n Valid values are TABLE, LIST, CSV.\r\n Column headings are not displayed with CSV\r\n format. Default format is TABLE.\r\n\r\n /NH Specifies that the column header should not\r\n be displayed in the output. This is\r\n valid only for TABLE and CSV formats.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n WHOAMI\r\n WHOAMI /UPN\r\n WHOAMI /FQDN \r\n WHOAMI /LOGONID\r\n WHOAMI /USER\r\n WHOAMI /USER /FO LIST\r\n WHOAMI /USER /FO CSV\r\n WHOAMI /GROUPS\r\n WHOAMI /GROUPS /FO CSV /NH\r\n WHOAMI /CLAIMS\r\n WHOAMI /CLAIMS /FO LIST\r\n WHOAMI /PRIV\r\n WHOAMI /PRIV /FO TABLE\r\n WHOAMI /USER /GROUPS\r\n WHOAMI /USER /GROUPS /CLAIMS /PRIV\r\n WHOAMI /ALL\r\n WHOAMI /ALL /FO LIST\r\n WHOAMI /ALL /FO CSV /NH\r\n WHOAMI /?\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"WHOAMI /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\whoami.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wiaacmgr.exe-4CE6AE2F9E8242327252EE9C845C0E14": { "file_name": "wiaacmgr.exe", "file_path": "C:\\Windows\\SysWOW64\\wiaacmgr.exe", "hash_md5": "4CE6AE2F9E8242327252EE9C845C0E14", "hash_sha1": "4D82B4856FD8C479C9F0AA926A4CECA9512E6B2F", "hash_sha256": "446CF796101F82C546EBE0F4D82AC2110781D9DCB7EF617464E16FD042812D5F", "hash_sha384": "650F384F45EDD5C64ACF341267558EBDEF3F8AC5F5497502965F17EABF334B6373BA48B5A988AE4AC04BFA78520CA3DC", "hash_sha512": "13B1DAD88E4D7D58EDF5DFDC5774C015AFDD0A4EE3BCD857833582360AC1EAABB12FDED4E41457EBB08B2862C74A0BA742DBC35BC032121660522EE05A072D6A", "hash_ssdeep": "1536:uSI2/umhuxXo1Hk+CJ7ryp+UmBo6AtfEGe:uWbhuxXoyTJ7rymBo6nGe", "hash_imp": "1A1951DF009B708FE4E471176F4F890E", "hash_pesha1": "12FBA06798DF8DFF5FE6E6789170AD425CEA4AAC", "hash_pe256": "196631CAFED0106541078355CB3D0C0EE9B46D968D4C320513666F12796165DF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Picture Acquisition Wizard", "meta_original_filename": "WIAACMGR.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/446cf796101f82c546ebe0f4d82ac2110781d9dcb7ef617464e16fd042812d5f/detection", "runtime_window_title": "Scan", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.685_none_4299dbb28a92ae3e": "File", "(R-D) C:\\Windows\\System32\\en-US\\wiaacmgr.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\scansetting.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\wiaacmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Windows.Media.BackgroundPlayback.exe-A23082AF84891D599B09E3FA28ACE972": { "file_name": "Windows.Media.BackgroundPlayback.exe", "file_path": "C:\\Windows\\SysWOW64\\Windows.Media.BackgroundPlayback.exe", "hash_md5": "A23082AF84891D599B09E3FA28ACE972", "hash_sha1": "488DA3D344541FCF003B03C3A28CC1D1DF714E6B", "hash_sha256": "3B7CA2A56A36A3B767461C17D77F188A0308164D3E80AD39D17C13683346CA9B", "hash_sha384": "31855A0AEFA9214FF62BC0379B8115FE432B3F859161B1CC77EA73D3F15BA6DC505D085260AC275FA21DA1900626F4EC", "hash_sha512": "599CF2A022C2BDDBC1D83726DFA2F7F23B800FE83FA04166D02429E0A58C9A2F0977F500F64EDE36F298E0D36CFB3AC2FCBACD0DAE3CBF3F771E2BAB88FB9945", "hash_ssdeep": "192:9MMfr37MtZFkjDfSRM3qO4JD1hbe0HMW+5WkFH:uMr3wrFkjDlwlHMW+5Wkl", "hash_imp": "0378B911CA4B411C79AC0F70E4868A4E", "hash_pesha1": "9FD26E7A02E7D77EAA37B0228065BD87ACABDFAA", "hash_pe256": "F389A2ACB99B26222C40BD94A4B7C3A9AE37E1D135539E53B0FF7260B768A686", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Playback EXE", "meta_original_filename": "Windows.Media.Playback.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3b7ca2a56a36a3b767461c17d77f188a0308164d3e80ad39d17c13683346ca9b/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Windows.Media.BackgroundPlayback.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Windows.WARP.JITService.exe-64F1FF7EC91297345D9CA7DEE12C7032": { "file_name": "Windows.WARP.JITService.exe", "file_path": "C:\\Windows\\SysWOW64\\Windows.WARP.JITService.exe", "hash_md5": "64F1FF7EC91297345D9CA7DEE12C7032", "hash_sha1": "29EA647B29E2331F8859E0BD8DD2B5E8228FDF0D", "hash_sha256": "1C3797E47C68EBCB5EEEF0852FAD398205E0F0BCB1EB45D600D282A3B578EF5A", "hash_sha384": "6B3932740BC65E4932BF8D2C0DC395E9FE5AD3F6204B82CBE7F02F6395FF9942B773F073CF2EA4867B8753E99E608F2C", "hash_sha512": "B8E7B7453D01E1676820EA0C4BEEEE385ED20CC05373FA2DC1D865FCA6809D8BEE75097E1D1D39C286E0D7E8A4B37B811F86DA5204F5C3429847EFF80574CABA", "hash_ssdeep": "1536:+XzFipKZEdQjIImLMdcu9UvI/9MfTOoX:6XpzmwdBmIM6W", "hash_imp": "AEE778DFE1B256EC0FBE9F965DEE0410", "hash_pesha1": "C45CE1FB712CD443BD53F9076E1A97DF23F4ED93", "hash_pe256": "37FC38B7E10EF03691B38735E6E1F73F9864E20EA8309DAAC2F26E5A0D77A5B9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/1c3797e47c68ebcb5eeef0852fad398205e0f0bcb1eb45d600d282a3b578ef5a/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Windows.WARP.JITService.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "winrs.exe-E6C1CE56E6729A0B077C0F2384726B30": { "file_name": "winrs.exe", "file_path": "C:\\Windows\\SysWOW64\\winrs.exe", "hash_md5": "E6C1CE56E6729A0B077C0F2384726B30", "hash_sha1": "77BE0E1E44A6BCF15DA641C804E8A572BFD67107", "hash_sha256": "C0DD2782705893496765CD83BA9BE23C8C1B279F5B943756C380219A5BE15A6E", "hash_sha384": "A28333AE75AD05309FE2964C5062F357FD3A140A9D185460F637F528B400B02893F0430313C94AC701C43160218F8B46", "hash_sha512": "E92B72EA80BC9E6F30E793DBEB9E8E4150296E6FA028776D07C9F1924B558EB551CAB9AC189793754C7B3BF964A4A1972555E3B66AD6905CB1B7A3A6A62C1745", "hash_ssdeep": "768:eD1or/ZFDGspNEkXRs8pxXfA1q9EXEMLkwsrNxOh:eDC/bjoMfsYqLkwsrNxQ", "hash_imp": "F0EE307FE96339D2235693E095EC19FE", "hash_pesha1": "6A872FD9CA76752DCA996F4E2AE86B7A1ADE7088", "hash_pe256": "DAAFA9E563BE143DFF5DC8086FE498B3741687E82EDC4EB92698222640124F61", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "winrs", "meta_original_filename": "winrs.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/c0dd2782705893496765cd83ba9be23c8c1b279f5b943756c380219a5be15a6e/detection", "output": "\nUSAGE\n=====\n(ALL UPPER-CASE = value that must be supplied by user.)\n\nwinrs [-/SWITCH[:VALUE]] COMMAND\n\nCOMMAND - Any string that can be executed as a command in the cmd.exe shell.\n\nSWITCHES\n========\n(All switches accept both short form or long form. For example both -r and \n-remote are valid.)\n\n-r[emote]:ENDPOINT - The target endpoint using a NetBIOS name or the standard connection URL: [TRANSPORT://]TARGET[:PORT]. If not specified \n-r:localhost is used.\n\n-un[encrypted] - Specify that the messages to the remote shell will not be encrypted. This is useful for troubleshooting, or when the network traffic is already encrypted using ipsec, or when physical security is enforced. By default the messages are encrypted using Kerberos or NTLM keys. This switch is ignored when HTTPS transport is selected. \n\n-u[sername]:USERNAME - Specify username on command line. If not specified the tool will use Negotiate authentication or prompt for the name. \nIf -username is specified, -password must be as well.\n\n-p[assword]:PASSWORD - Specify password on command line. If -password is not specified but -username is the tool will prompt for the password. If -password is specified, -user must be specified as well.\n\n-t[imeout]:SECONDS - This option is deprecated. \n\n-d[irectory]:PATH - Specifies starting directory for remote shell. If not specified the remote shell will start in the user's home directory defined by the environment variable %USERPROFILE%.\n\n-env[ironment]:STRING=VALUE - Specifies a single environment variable to be set when shell starts, which allows changing default environment for shell. Multiple occurrences of this switch must be used to specify multiple environment variables.\n\n-noe[cho] - Specifies that echo should be disabled. This may be necessary to ensure that user's answers to remote prompts are not displayed locally. By default echo is \"on\".\n\n-nop[rofile] - Specifies that the user's profile should not be loaded. By default the server will attempt to load the user profile. If the remote user is not a local administrator on the target system then this option will be required (the default will result in error).\n\n-a[llow]d[elegate] - Specifies that the user's credentials can be used to access a remote share, for example, found on a different machine than the target endpoint.\n\n-comp[ression] - Turn on compression. Older installations on remote machines may not support compression so it is off by default.\n\n-[use]ssl - Use an SSL connection when using a remote endpoint. Specifying this instead of the transport \"https:\" will use the default WinRM default port. \n\n-? - Help\n\nTo terminate the remote command the user can type Ctrl-C or Ctrl-Break, which will be sent to the remote shell. The second Ctrl-C will force termination of winrs.exe.\n\nTo manage active remote shells or WinRS configuration, use the WinRM tool. The URI alias to manage active shells is shell/cmd. The URI alias for WinRS configuration is winrm/config/winrs. Example usage can be found in the WinRM tool by typing \"WinRM -?\".\n\nExamples:\nwinrs -r:https://myserver.com command\nwinrs -r:myserver.com -usessl command\nwinrs -r:myserver command\nwinrs -r:http://127.0.0.1 command\nwinrs -r:http://169.51.2.101:80 -unencrypted command\nwinrs -r:https://[::FFFF:129.144.52.38] command\nwinrs -r:http://[1080:0:0:0:8:800:200C:417A]:80 command\nwinrs -r:https://myserver.com -t:600 -u:administrator -p:$%fgh7 ipconfig\nwinrs -r:myserver -env:PATH=^%PATH^%;c:\\tools -env:TEMP=d:\\temp config.cmd\nwinrs -r:myserver netdom join myserver /domain:testdomain /userd:johns /passwordd:$%fgh789\nwinrs -r:myserver -ad -u:administrator -p:$%fgh7 dir \\\\anotherserver\\share\n", "children": "explorer.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "\\BaseNamedObjects\\F932B6C7-3A20-46A0-B8A0-8894AA421973": "Section", "(R-D) C:\\Windows\\System32\\en-US\\mswsock.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "error": "Winrs.exe: Unrecognized switch \"--help\"\r\nUse \"winrs -?\" to obtain the usage information", "runtime_modules": [ "C:\\Windows\\SysWOW64\\winrs.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "winrshost.exe-9EB3371F7B80A434CC9F468B330A9928": { "file_name": "winrshost.exe", "file_path": "C:\\Windows\\SysWOW64\\winrshost.exe", "hash_md5": "9EB3371F7B80A434CC9F468B330A9928", "hash_sha1": "B207B1D5B81B812F909F2434DADE79E8D9472877", "hash_sha256": "233E8EA78906FB63E306DD5FFDBE07716DAA9144A2B4715B0EF9C2C990EF60C0", "hash_sha384": "58EEE2B460AF981CE97611AD6E9BDCDDA73169BA2088E4BADCBFA2E3CEE5DAB34E9343D8D13DF7FFD9D4D91826932169", "hash_sha512": "DA32424F31950736471FB31D35DDA40B2DFF7CF568A8E1FF777C50D072CBF6479ED303390240E21947FD763A50B71367A2A2B17F776C7BBB478B4E4B19D0ED9D", "hash_ssdeep": "384:qCLwubRl9FlrAjArVdl8wEhUfDTW3ap/vFWscEW:brbD9FlrprVdgcaKp/vE", "hash_imp": "84E8D0734E85FF07FA62BE51BF7504A9", "hash_pesha1": "106387CB5156F49300C0A02249BD73174E8F0BCF", "hash_pe256": "FDF329ED11AD473BFEF6D2C25E7032E7B64CCA6C9A60FC6B0A0271F4EF36BF2D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for WinRM's Remote Shell plugin", "meta_original_filename": "winrshost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/233e8ea78906fb63e306dd5ffdbe07716daa9144a2b4715b0ef9c2c990ef60c0/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\winrshost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WinRTNetMUAHostServer.exe-BAA9E473912920F312E293A9F4A54DB4": { "file_name": "WinRTNetMUAHostServer.exe", "file_path": "C:\\Windows\\SysWOW64\\WinRTNetMUAHostServer.exe", "hash_md5": "BAA9E473912920F312E293A9F4A54DB4", "hash_sha1": "116BC7D82047B4EB2B51B442CEE076B92AC03427", "hash_sha256": "2167D6C0BDF6067F35E2928D6A8FB96D5CE13DD2A0967E03534FFD3D3DD6E0A8", "hash_sha384": "F4D536A117FE6D2EE32B255FF15C7A573FD31C84B494FAB28EDCE9A3B3092ABD8999C42053900C2F2E55055DED90DB62", "hash_sha512": "702C404B3A2C8D6E1D711379B409EF99B8508E987BB1656D5E9F88957BAF003ECE28A0B789C236B183146C5009464CE53E052AC0948DF1C01393E80AF104FC84", "hash_ssdeep": "384:FYhuKKzELOdEGSx//rWZhkpqBnJoVn82L308WxoWV8:HKKzEZGS1WZgL3+7", "hash_imp": "EC2AF497B775CAC0DB45C4E94907FA33", "hash_pesha1": "3569969A4CD9288C2FA6D23FCAD794E85AFE6B0E", "hash_pe256": "9F70CD4DFD453214021B087F8FAA3E82DBC6A49E9BD00936CCAE4DEB1481339D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WinRTNet MUA HostServer EXE", "meta_original_filename": "WinRTNetMUAHostServer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/2167d6c0bdf6067f35e2928d6a8fb96d5ce13dd2a0967e03534ffd3d3dd6e0a8/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\WinRTNetMUAHostServer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "winver.exe-B5471B0FB5402FC318C82C994C6BF84D": { "file_name": "winver.exe", "file_path": "C:\\Windows\\SysWOW64\\winver.exe", "hash_md5": "B5471B0FB5402FC318C82C994C6BF84D", "hash_sha1": "0FCA780392A495E96AA3FF92327A77B049150294", "hash_sha256": "E8086C9FA7A33E4E6445DAB05F79EDF8E843945764B21B1024AD2FDB724037DC", "hash_sha384": "006D622918DA6AF0D5983069FA342DDBE246A1592D77D9318E6C961FBC0E80E0F34AC73EF655DA4DE0C3335AC1C29EA4", "hash_sha512": "DAAA34C689610472F36328ED14F6398BD0C01BE80ACA6F19604F4C076C86A4DB51B94B9C2133D56F5F1879C203D16C7EB214A0A270E8A3E1B7615E972ED2B4F9", "hash_ssdeep": "768:QAK9l3ya+GSkVhWakkbB5eT905WGnUKxHUe7n8jKBFFptX/7wUXI6s:elya+xakkn6oYY0ewiP8J", "hash_imp": "6F6011B78CCFE72E1E21C99F70873A70", "hash_pesha1": "EDDA6A558E938CE9A688064A9A1DC68D318DFEEF", "hash_pe256": "9264014DDD52AC6FBA8C74CEEA19B6B598D510310728AFBFAC8BCDE5A3B5F974", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Version Reporter Applet", "meta_original_filename": "WINVER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e8086c9fa7a33e4e6445dab05f79edf8e843945764b21b1024ad2fdb724037dc/detection", "children": "mmc.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\winver.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\winver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "About Windows" }, "wlanext.exe-0D5F0A7CA2A8A47E3A26FB1CB67E118C": { "file_name": "wlanext.exe", "file_path": "C:\\Windows\\SysWOW64\\wlanext.exe", "hash_md5": "0D5F0A7CA2A8A47E3A26FB1CB67E118C", "hash_sha1": "CD2F50FD5A7BD6291DE1948F100415044C767E63", "hash_sha256": "3C928B9AFF2E651AA35EA798C29FDE398E9F7817E3451AE0F4C97C86630DC92B", "hash_sha384": "A00F79D689B1B09624415409AA92BE148E74F6957CCF2914FF8B49A038EA13910D573312C3FF6AEE11F3A154D98BD2E3", "hash_sha512": "84398D4E5680C2EA1679D0076468207A9503B053A233932FD3EFAEFDBF4559CFEAB5A0E95F526644C6382A88C17B6A62D3993323012211AB685DA4C4B025C045", "hash_ssdeep": "1536:UbDMdx4Tm9lSD2HAcOqa57xlYuNxo8b1E:+MduTm9lSD7rNKk6", "hash_imp": "DF1E2B2A61EF32982A6D4F4D8DD9F55A", "hash_pesha1": "DA974224A232E72806CA6C2B4D5BFAAF0547698D", "hash_pe256": "DAC922BF57E44406D6611671A0B2A85AE4CF5466BFF85CD9626F88CC5964D831", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Wireless LAN 802.11 Extensibility Framework", "meta_original_filename": "wlanext.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3c928b9aff2e651aa35ea798c29fde398e9f7817e3451ae0f4c97c86630dc92b/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wlanext.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wowreg32.exe-22DB63D3210C59C39A8606F0076547B3": { "file_name": "wowreg32.exe", "file_path": "C:\\Windows\\SysWOW64\\wowreg32.exe", "hash_md5": "22DB63D3210C59C39A8606F0076547B3", "hash_sha1": "51FAC499A91403EC17777A4A44EC26645C2E4C80", "hash_sha256": "26E34D8F1370E557F2D864AA552AA3D77C4BB6371C49778007A2DC91F206FFA7", "hash_sha384": "D271971470DD37FFEE5A9B49DAA4F8283738CA33B9FFEB5CEE8FD8E171F4B326626CF844B6CB25EA220A6A68538EE0EE", "hash_sha512": "6045813B111D55E06D22FDEB2D96B7ED38BD7B3E428B103AE67A4556864EEBBC245419B863A6B63E5731317287AACA4408748D921697E0D40BDDC248C04B120D", "hash_ssdeep": "192:KFOum/QejuwIld190/bazNm9vFYNrCt8LthOqiXpWgWZjHWFst:pjAd/0/bl9vqet8JmZWgWZjHWFK", "hash_imp": "8B8A143002F5FC8DCA7CC0A0DC979CEF", "hash_pesha1": "FC5455A03ACCE128B0C7F4CDA0613ABFE2FC1C1D", "hash_pe256": "626BABDFD33FB3480B8ED753EBC2974F9EF30AB746FD70F91E7441518B46A4FF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SetupAPI 32-bit Surrogate", "meta_original_filename": "WOWREG32.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/26e34d8f1370e557f2d864aa552aa3d77c4bb6371c49778007a2dc91f206ffa7/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wowreg32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WPDShextAutoplay.exe-1DE922DD77CFADA811DB26A0A591E121": { "file_name": "WPDShextAutoplay.exe", "file_path": "C:\\Windows\\SysWOW64\\WPDShextAutoplay.exe", "hash_md5": "1DE922DD77CFADA811DB26A0A591E121", "hash_sha1": "4EE18C311F7CC0B6F424C81AA265D9DC48397398", "hash_sha256": "F8AC6CE639FB1C444108974AD831AA10B67EAEE65BC2618570F8F18CF5DC5F78", "hash_sha384": "AEFA0896F96B31A23859E8322A9F6F2594A34BCE513B674881FD5F13BF7D59EF068F7A2D9D8B317117EAAC87E8BD3973", "hash_sha512": "E563CE1F60B17A74EA2C456C6F1D22BB9F9645B74FE90299469799453BCC6258CFB3FD79F3A5B5A05D14DF5CCAE49F4DFD69A93FEDC81886D7CFE387669445DC", "hash_ssdeep": "384:t1jDYp4Ybfo9aqIdnpUHuuhP/0kXdTLCMqfibDWgnWF9:t1jr/uSfqfirW", "hash_imp": "C26FA98179B5A82641E3913A19CB08AF", "hash_pesha1": "71ECD3CB5628ACBFAE2AE92506F965C8E33A0605", "hash_pe256": "CAA1A5D7AAB06075843D199B9FE7C5E4E4F1422BFF724068A1FF44C85A5C4287", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Portable Device Shell Extension Autoplay Handler", "meta_original_filename": "WpdShExtAutoplay.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f8ac6ce639fb1c444108974ad831aa10b67eaee65bc2618570f8f18cf5dc5f78/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\WPDShextAutoplay.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\WPDShextAutoplay.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "write.exe-3D6FDBA2878656FA9ECB81F6ECE45703": { "file_name": "write.exe", "file_path": "C:\\Windows\\SysWOW64\\write.exe", "hash_md5": "3D6FDBA2878656FA9ECB81F6ECE45703", "hash_sha1": "1765076E0E5B008AA14D8E5FCE5DE516E68F7771", "hash_sha256": "6F760002730A8CA55181EB61EB7D9764D91F236EFC602168F225CB0CD9180295", "hash_sha384": "991D34705B5477BC48F30C870E33B6914AF321E0772342197062D2AA733F2946E88D54D90B54F3B83DBC85AB630F7601", "hash_sha512": "F6E21B25D342D47A75ACC08A4165AA144B1DE7B0DDE0452FE9AF718D232AD76F2D1B99574890118C730F81FC2BF48F62960F3AE37276B840A419D14CA65D1D76", "hash_ssdeep": "96:wXEPsSNEdA+Bn9Jkp2kBjDDDGjg6GHDCMq1RDJdMi2bKveLrxuJRdlEWGOWwMj3:wXEUFdA+hyQgDCMq1hPuxu/sWGOWNj", "hash_imp": "B05C7142E6016FF931CDC4142BE82084", "hash_pesha1": "3E45FA268DAD96B552B414AD276F655E99E46781", "hash_pe256": "7A13C914E51109F249B0AA11F375F5730544ACEC4DCFA6C5A3B55121CA9CF995", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Write", "meta_original_filename": "write", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6f760002730a8ca55181eb61eb7d9764d91f236efc602168f225cb0cd9180295/detection", "children": "wordpad.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\write.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wscadminui.exe-9D156054E1754EDF164F6CF5537B2EE4": { "file_name": "wscadminui.exe", "file_path": "C:\\Windows\\SysWOW64\\wscadminui.exe", "hash_md5": "9D156054E1754EDF164F6CF5537B2EE4", "hash_sha1": "4565BDA12BD284EDBEC91E2A07C3EEB944FC12F7", "hash_sha256": "88CD7DF8A66E4D061BD9CD1FAA2B4FE2A56D5D27644C19DF8DA54D46FE7E5B3A", "hash_sha384": "1067965A025B1636716BB36F726197660F369061A159D1E5C240323FEF8E3C420AFF1C45ABB747ED33A8C88C4CA06D76", "hash_sha512": "B09F622C80C0B1B09C51A85BB1ED2AD66116B192072E129D5AF773C5360EF173C6340BD9C646199AAC6CA3B2CE770F1ADB3789B6848FD7A98E077FB9AC5A1E41", "hash_ssdeep": "96:eqB4XrXXYtsp20nGDrDGjQ5HEJuDWfMu1qEWehRWwcRF:1KrXXYwx7exDWfMu13WehRWtRF", "hash_imp": "3D14FF3AED50FB9C7612F737F4A41021", "hash_pesha1": "D0106906FF9D524BE79B6836BFD326920422263C", "hash_pe256": "BB6513FB36A72F2F2E7066C7CA1BD77FE8996ABC0C412B854A0950ADFE4D517E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Security Center Elevated UI App", "meta_original_filename": "wscadminui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/88cd7df8a66e4d061bd9cd1faa2b4fe2a56d5d27644c19df8da54d46fe7e5b3a/detection", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wscadminui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wscript.exe-4D780D8F77047EE1C65F747D9F63A1FE": { "file_name": "wscript.exe", "file_path": "C:\\Windows\\SysWOW64\\wscript.exe", "hash_md5": "4D780D8F77047EE1C65F747D9F63A1FE", "hash_sha1": "B57972FCCA8CC888EAB9B960DC84FA4B55991105", "hash_sha256": "391D47D21304F8F97254A6537AA65476609FC222AD0AD86E7008419D61735A9C", "hash_sha384": "E12B6FFA047C0EDAA2BEF317E3095EA3AFB2215EEAA90C2C40E44533F120CAB9172A52B3971E1623F797587935A80664", "hash_sha512": "9BC0CF9B8FCC5BEE7F0B5169BD857187CA6E47FEC47A0FF3C9F0519971A1D1352C6761988CE4A2A5CBB5B7BF801FB7ADCEEA2313371461FFCEF938ABE0FD3B21", "hash_ssdeep": "3072:GnWqXLDXmH3/QY5cyPeRigvXbzNQNjUptFruGTxt+:FqbDXmncfiaXX+CFrtT", "hash_imp": "3602F3C025378F418F804C5D183603FE", "hash_pesha1": "5F90475CD32C293FCA48841B433FB550DA441FC9", "hash_pe256": "C84713C948FA1ED351822C0A8A796C680B78E31C090E8B76512BF0B1963476D4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Based Script Host", "meta_original_filename": "wscript.exe", "meta_product_name": "Microsoft Windows Script Host", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.812.10240.16384", "meta_product_version": "5.812.10240.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/391d47d21304f8f97254a6537aa65476609fc222ad0ad86e7008419d61735a9c/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\wscript.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\wscript.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Script Host" }, "WSManHTTPConfig.exe-68147888D98E22C28A586FD85F7DD76F": { "file_name": "WSManHTTPConfig.exe", "file_path": "C:\\Windows\\SysWOW64\\WSManHTTPConfig.exe", "hash_md5": "68147888D98E22C28A586FD85F7DD76F", "hash_sha1": "2D1C82615D0F220D20CA05D0B7DE82F47DA0F2B6", "hash_sha256": "AF31760FAFEB4A2080923FC42F098B2F05A5F68153F8ACD42AD9DC3955C58313", "hash_sha384": "5F705FBC383E6DCABE811B07FAA8AC8A4FCABEEEFAEA870E9524911DBAF45F9E7D1E3E70EF88951FD82BCBFBAB41621E", "hash_sha512": "85A78CFCA9AEC6D851A0ED51D2EAB4D2EAD12654694727F6A7B02AD5367936C9FCCBA08C296118E1BB4E64F4807A44C8A3BC5C86E7D096AB455D65C6C351D926", "hash_ssdeep": "768:kX08+lU8xqo+YIBc1u212uc3BxU0jhebi//2xbHMq:a0n+gqRYBV12uSDfAbi/+bHM", "hash_imp": "C929AC237BE32CF84055E96DB4572D8E", "hash_pesha1": "71F9923FD0B7333509C133234BB5851E7063E506", "hash_pe256": "5887AFC91B0815EFA69823BA5B8E840DFCE9BEB87ACEBD20ACB8D781B0A29200", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WSMan HTTP Configuration File", "meta_original_filename": "WSManHTTPConfig.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/af31760fafeb4a2080923fc42f098b2f05a5f68153f8acd42ad9dc3955c58313/detection", "error": "WSMan Generic Command ERROR: Unknown switch: --help\r\nWSMan Generic Command ERROR: Error in parsing input\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\WSManHTTPConfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wsmprovhost.exe-8167AB7B0D7E8C5FEC4C2A1806C774F9": { "file_name": "wsmprovhost.exe", "file_path": "C:\\Windows\\SysWOW64\\wsmprovhost.exe", "hash_md5": "8167AB7B0D7E8C5FEC4C2A1806C774F9", "hash_sha1": "F390107E236742C2C0A07463D8C9CBC040021651", "hash_sha256": "4FC5D087E446AAA807946A54F99A7CA2083374CFACB87E01BBFE8E76A137D91F", "hash_sha384": "A332120DFBFD720C3B85897468EBCEABD00E56F899AFE4AB0EEC0A6DF2BCD4448CC8ADB354F3BBA68F3A0C0B3ED3451B", "hash_sha512": "EDB002DCA0C0BFFDDCD957E0D3F1437BBDD106456E8E1A864B64F1C31259E54D777FD49C24188AF454BCFCCF874241E49069F45E63FE65954AEB183C38B4A28F", "hash_ssdeep": "384:VsKmx9ygrKG3Jrh0qAvqa3FFi6GIBW4brMlphhmWQKymnbxiOC2W7UfW86He:VlU9BK0J8qa3r1G8OhhmW7hn9i94J", "hash_imp": "85FC9DC7C929E91AD67D98751023E144", "hash_pesha1": "B0B6CBA65D70F1BDDFB74CF8801C6C3DF2FCC2A8", "hash_pe256": "5DF2D0921E9AC17B0E184709846FA6614F8395B023D0E516F895F19746C72340", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host process for WinRM plug-ins", "meta_original_filename": "wsmprovhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4fc5d087e446aaa807946a54f99a7ca2083374cfacb87e01bbfe8e76a137d91f/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\wsmprovhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wusa.exe-A60D32269A6A6E7BFDC50E22A70B8F54": { "file_name": "wusa.exe", "file_path": "C:\\Windows\\SysWOW64\\wusa.exe", "hash_md5": "A60D32269A6A6E7BFDC50E22A70B8F54", "hash_sha1": "2ABB4D5643A058FCCAED525F878925ECEF5A660F", "hash_sha256": "5AE6A1F1135E9423D4CB409967591F776F7729C7B784E76380B4C727B89538AA", "hash_sha384": "F59D684F028480386F99C240A049A11DAD63DCF323212F3DC0C014326AA3925F7A9D5AB3D18B9B5F2E466BB56E3FEF28", "hash_sha512": "2166094A30E6F12E2B271022832DBC42FF23C9AD39C110A530D3842410ED79CAA0F8A5740F4AD17C03B9FFC74624B96BBB76962A3FCF65C8102FC6AF9E810509", "hash_ssdeep": "6144:Mcd8nRccMw5wypbQQYkYsy09vpxyN90vE:MO8nRcU5h1BYkHyy/y90", "hash_imp": "8B0E6AE8A465FE06366AC61E225F215E", "hash_pesha1": "CBF355B57F770B567D6A4A5D92BFEA385F96432E", "hash_pe256": "4EEFC5C066D2FA602B89EF79B7C8711DA20161A5D66B4E336B62973F3A83E7E5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Update Standalone Installer", "meta_original_filename": "wusa.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5ae6a1f1135e9423d4cb409967591f776f7729c7b784e76380b4c727b89538aa/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\System32\\en-US\\wusa.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\wusa.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Update Standalone Installer" }, "WWAHost.exe-DEB28584D07635778FF96EA8CBE727B3": { "file_name": "WWAHost.exe", "file_path": "C:\\Windows\\SysWOW64\\WWAHost.exe", "hash_md5": "DEB28584D07635778FF96EA8CBE727B3", "hash_sha1": "1DCFF27A94CF22633FD1CBD1013BD454C31FED27", "hash_sha256": "47A2C71B9DC22A967B0D4339FA93175CF1CCF0A982DCE3DCD542AFCDC54372F3", "hash_sha384": "3D23203B81EE8E16F5C621B9AE50B369C785A8441FD9D35707A8A2A67AC9F16FA248AEF6EADC65DB914D099368984755", "hash_sha512": "A67915065F26AE0C051A9362EC8FC95087EB6A109BA834D587285AC9E86C5FB3C53A9F5F2596F7A8E5AB85C9AAFC56B6E50DE3226C524B191AA694AC3E84F346", "hash_ssdeep": "12288:AfncQEATSlv2EywGUjLpL6LyLYLvLbLG0LfLhLkLCLkL5HYL2blvindboNoIozoQ:AOvCE18SrsRef3zkf+dvEEH7To", "hash_imp": "091D93B9BE01B4A6F5EC9F1358C8F0D7", "hash_pesha1": "120A7EB9693CED7AC1C9B7ADC45D447025226E53", "hash_pe256": "CB4F5FB0A8E9DD3840F1DC012760D0A885D379A4F362589B212025A526E01901", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft WWA Host", "meta_original_filename": "WWAHost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/47a2c71b9dc22a967b0d4339fa93175cf1ccf0a982dce3dcd542afcdc54372f3/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\WWAHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "xcopy.exe-7E9B7CE496D09F70C072930940F9F02C": { "file_name": "xcopy.exe", "file_path": "C:\\Windows\\SysWOW64\\xcopy.exe", "hash_md5": "7E9B7CE496D09F70C072930940F9F02C", "hash_sha1": "2F1A2A5156623A41F6C385F83B53F0C5A1DC6924", "hash_sha256": "B45997BB7C5FC6024685EE8752CF8AB871290A46B33E04FC4850A10077ACBA5A", "hash_sha384": "D1484DB8F3DB32AF14515A75D1464D038F0DB4270FFA189B8B8887134283261A65024DD48E5CD18C932A27B8D8BDE586", "hash_sha512": "4EAF8F1FD4718B034BDC067F8514B74C4A95AB6895C2CB26B7E0E4489C237D659883A9FD6CE9FA1C4121A68574885233FA15F8FF61443687E7FA19F98341D7B6", "hash_ssdeep": "768:1Mcs8Lv2E9OkHkh5bzvtCpgd7P/EtI5tvg0D71QijZjXDY8c5meOkL/H:N/3KpC0r3g0DxQgVzY8c5mexH", "hash_imp": "370E0F2A87317776FEB42A7B32DD037B", "hash_pesha1": "DD8F3FCA01984448F9EA501200F257DF8025E4BA", "hash_pe256": "12BA660CA2B1FB69B9476BD2FB3E1B2554C0196DB08C757CFBE570575A3FD7B3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extended Copy Utility", "meta_original_filename": "XCOPY.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "1/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b45997bb7c5fc6024685ee8752cf8ab871290a46b33e04fc4850a10077acba5a/detection", "output": "Copies files and directory trees.\r\n\r\nXCOPY source [destination] [/A | /M] [/D[:date]] [/P] [/S [/E]] [/V] [/W]\r\n [/C] [/I] [/Q] [/F] [/L] [/G] [/H] [/R] [/T] [/U]\r\n [/K] [/N] [/O] [/X] [/Y] [/-Y] [/Z] [/B] [/J]\r\n [/EXCLUDE:file1[+file2][+file3]...] [/COMPRESS]\r\n\r\n source Specifies the file(s) to copy.\r\n destination Specifies the location and/or name of new files.\r\n /A Copies only files with the archive attribute set,\r\n doesn't change the attribute.\r\n /M Copies only files with the archive attribute set,\r\n turns off the archive attribute.\r\n /D:m-d-y Copies files changed on or after the specified date.\r\n If no date is given, copies only those files whose\r\n source time is newer than the destination time.\r\n /EXCLUDE:file1[+file2][+file3]...\r\n Specifies a list of files containing strings. Each string\r\n should be in a separate line in the files. When any of the\r\n strings match any part of the absolute path of the file to be\r\n copied, that file will be excluded from being copied. For\r\n example, specifying a string like \\obj\\ or .obj will exclude\r\n all files underneath the directory obj or all files with the\r\n .obj extension respectively.\r\n /P Prompts you before creating each destination file.\r\n /S Copies directories and subdirectories except empty ones.\r\n /E Copies directories and subdirectories, including empty ones.\r\n Same as /S /E. May be used to modify /T.\r\n /V Verifies the size of each new file.\r\n /W Prompts you to press a key before copying.\r\n /C Continues copying even if errors occur.\r\n /I If destination does not exist and copying more than one file,\r\n assumes that destination must be a directory.\r\n /Q Does not display file names while copying.\r\n /F Displays full source and destination file names while copying.\r\n /L Displays files that would be copied.\r\n /G Allows the copying of encrypted files to destination that does\r\n not support encryption.\r\n /H Copies hidden and system files also.\r\n /R Overwrites read-only files.\r\n /T Creates directory structure, but does not copy files. Does not\r\n include empty directories or subdirectories. /T /E includes\r\n empty directories and subdirectories.\r\n /U Copies only files that already exist in destination.\r\n /K Copies attributes. Normal Xcopy will reset read-only attributes.\r\n /N Copies using the generated short names.\r\n /O Copies file ownership and ACL information.\r\n /X Copies file audit settings (implies /O).\r\n /Y Suppresses prompting to confirm you want to overwrite an\r\n existing destination file.\r\n /-Y Causes prompting to confirm you want to overwrite an\r\n existing destination file.\r\n /Z Copies networked files in restartable mode.\r\n /B Copies the Symbolic Link itself versus the target of the link.\r\n /J Copies using unbuffered I/O. Recommended for very large files.\r\n /COMPRESS Request network compression during file transfer where\r\n applicable.\r\n\r\nThe switch /Y may be preset in the COPYCMD environment variable.\r\nThis may be overridden with /-Y on the command line.\r\n", "error": "File cannot be copied onto itself\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\xcopy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "xwizard.exe-8581F29C5F84B72C053DBCC5372C5DB6": { "file_name": "xwizard.exe", "file_path": "C:\\Windows\\SysWOW64\\xwizard.exe", "hash_md5": "8581F29C5F84B72C053DBCC5372C5DB6", "hash_sha1": "64F9D0C258B0FD6CA49EDB722EF4270815DFB8E9", "hash_sha256": "03B63FD1AB52129733F576554DE9540D3F5E224405837A3D1ADF5C0A68B1D21B", "hash_sha384": "1B99DBC384329776F2427C706C092B1C103DBDB8DF164517237A755D2A681E757639AE830DFE474FF591B51F1569B69E", "hash_sha512": "774B6BD85E12AA3369A6830D806359D9CE8E9E1AC990144C57D1A9C6EF9D67B8A9640831A44185CFAF6915E82FAA29F1ED70354657C592C4234B86ACA58417F1", "hash_ssdeep": "1536:B//0VR2zUoK4VD2WTVcURDoq4OZZZLlCIib4:R/0VR2fVD2GV9RD68wb", "hash_imp": "878B18532266618387DC445E265148DD", "hash_pesha1": "380E347103DBD0406DED2C25BA90004F41BC6AB1", "hash_pe256": "381A68D61EC4E48CEB7DE8B2F714B08398EE0209F25182241B09CD3A6B0C6C4A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extensible Wizards Host Process", "meta_original_filename": "xwizard.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/03b63fd1ab52129733f576554de9540d3f5e224405837a3d1adf5c0a68b1d21b/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\xwizard.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\xwizard.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "comrepl.exe-8A15DD4230B2667BE68F1356140CC77B": { "file_name": "comrepl.exe", "file_path": "C:\\Windows\\SysWOW64\\Com\\comrepl.exe", "hash_md5": "8A15DD4230B2667BE68F1356140CC77B", "hash_sha1": "238519049ADA92169806B1889E98DB4F4C3C1ECB", "hash_sha256": "289B423E248CCBDF95184C549F8F16CEF29706FE9532EE167393FF171A262120", "hash_sha384": "063F20E41AA052DFEDB5DA40D9F5D2170A1EB4262AE867D20992F560818DE3A28C6D53363B2787A9B5E3B2D56A808447", "hash_sha512": "A961931736175FE9C610CE3D7A0855B10F923A1BE2E7D09870EDCB63732A060A29E3A58B95ED19F29C6BDF47E271D0189135E2E17CCBF468780007B91BC3BFEF", "hash_ssdeep": "384:fpT/7Ou51COEJ+imy48ZrWW5VuoWpADU:fpeueCy48hoUU", "hash_imp": "A1C21D02B295775CA1385E51D5DB789D", "hash_pesha1": "8A474317272FC424BF8B81D3396599D542504CBB", "hash_pe256": "E37C3CF942A9C1D027C9A1520B1F44165B9022A1107ACE1BAF1D76989C40D157", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+ Server Replication", "meta_original_filename": "COMREPL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/289b423e248ccbdf95184c549f8f16cef29706fe9532ee167393ff171a262120/detection", "output": "ERROR: WriteConsole failed = 00000001\r\r\nERROR: WriteConsole failed = 00000001\r\r\n", "children": "splwow64.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Com\\comrepl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MigRegDB.exe-8AB05C31C23248C2AE46809D5FB73E33": { "file_name": "MigRegDB.exe", "file_path": "C:\\Windows\\SysWOW64\\Com\\MigRegDB.exe", "hash_md5": "8AB05C31C23248C2AE46809D5FB73E33", "hash_sha1": "242C046A5FD614242E047D4C4BECE9FDC375C952", "hash_sha256": "781E7F15682FFC1D7D523BAA7835084199568054AB5161D63BA6A338B270D202", "hash_sha384": "87A7A18DD5B96BC8A6F66EBC253F70FC12E5F1D8B281B0C03C1BC3242CAC347DB80CDE628B9B83C4ED7CF24B5B737707", "hash_sha512": "81A1820BEEAE5F811716DA764A54F8BA8595A6A533CC63EFDFCD178EA84561153DEFF8434C8D804D7AA4B815F93E9DFC1FB986AE6D25F8B7F36866A159AE52DE", "hash_ssdeep": "192:/SESYass+uvL2WIDlbceQh3M0184zWYwWFB:/zOL2WwbceQSV4zWYwWFB", "hash_imp": "D09A6E719E5E2339B3631F455943742B", "hash_pesha1": "17EAE2D139FEABCE502B1B56A9E30FE08A217E1C", "hash_pe256": "BE30FB0B4FC55EC5A35F71D9DDBE234EBFF1A02969CEE1E6C6195FFE2907F200", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+", "meta_original_filename": "MIGREGDB.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/781e7f15682ffc1d7d523baa7835084199568054ab5161d63ba6a338b270d202/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Com\\MigRegDB.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "DismHost.exe-FD0B966C41AC54AA77E0D65C8DF7CA2D": { "file_name": "DismHost.exe", "file_path": "C:\\Windows\\SysWOW64\\Dism\\DismHost.exe", "hash_md5": "FD0B966C41AC54AA77E0D65C8DF7CA2D", "hash_sha1": "35467810D9D155E8DA7DC45E721FD123D9010033", "hash_sha256": "4D3B036A78298E64E8FEF0010CE98CE8B41E37621B613B4F35EE64765C724393", "hash_sha384": "6B4F61C3550FF78BB31ADAA93D09D6EB68089C9EB5D608B583C1F7C337CC141F1892931A2021EE5F4C304D9DEC9030FD", "hash_sha512": "B3D3B5B1603C9D468F89B48947A57AA5A5711334DB5F658560965C47DBD864C35193DD4145A91D0807C402C72AE43194D70F6BA47FBD9CABF5891861BC075455", "hash_ssdeep": "3072:DffYMtccoo7muBkaO8UHGHBaipik32cyHc0jq:btZ7mF8UH2RIk32RH+", "hash_imp": "6D22B1E1FDE3D53E4DD80D9E83A0E1C1", "hash_pesha1": "24298E87F2DEF054AA1F855DBB7AD670E399B9FF", "hash_pe256": "2FEB469F0867D4BD11BFCB26046760A16B0AB8D4D58994048EBD76A1BD2C26CE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Dism Host Servicing Process", "meta_original_filename": "DismHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/4d3b036a78298e64e8fef0010ce98ce8b41e37621b613b4f35ee64765c724393/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Dism\\DismHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "IEChooser.exe-92BA71A242D205D19D6E1B21EE2967A1": { "file_name": "IEChooser.exe", "file_path": "C:\\Windows\\SysWOW64\\F12\\IEChooser.exe", "hash_md5": "92BA71A242D205D19D6E1B21EE2967A1", "hash_sha1": "61035693150DEE2539D73E8298906750FFF23542", "hash_sha256": "08E4BE0EB2F1DB877B87A9677C1E140D02F3D67977B207FA3FD3E5C925B38973", "hash_sha384": "A50C5B8BD22C3DCF53D7AAEC692365C910D6EDF702021AAF031258986AFC55BBC05D1B0A7412616B39A296982A9D4E72", "hash_sha512": "82BEAAD7F86E7A9695BB97C264FB3C7D01362C3E1535AA57109A1A10BDB1CA9205E3246CBE4D82B88A511C20B9368527180EBCF46B5FBD1F6D9A69A03EC489F3", "hash_ssdeep": "3072:VMxXBmDKYyn3KmboRhtYBrfdG6AvUH3gYEcu7P8:VMxxPYyn3Kmb47cf4AQxcug", "hash_imp": "33A7ED8A53A124ECACEA08FE6D6C7AA5", "hash_pesha1": "7BE46EDB6DA01477804112C8DE2AB0269F1029D1", "hash_pe256": "B5E3616756C0E543C041F8C12BEFADB203957CA759211AA80A52F7884655F5CF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "F12 Attach Chooser executable", "meta_original_filename": "F12Chooser.exe.mui", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/08e4be0eb2f1db877b87a9677c1e140d02f3d67977b207fa3fd3e5c925b38973/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\F12\\IEChooser.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "IMJPDCT.EXE-2738A858F2F359DAE73DBEC745DDBE01": { "file_name": "IMJPDCT.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\IMEJP\\IMJPDCT.EXE", "hash_md5": "2738A858F2F359DAE73DBEC745DDBE01", "hash_sha1": "459D54AC03321B99079C7A1EE971A5DF0CE01FAE", "hash_sha256": "E8A4BB3EF340DD3A94E5F649A0F41B0EE0390349D435D020DCE8576AF42112DD", "hash_sha384": "8F592ACF04E77A495E04C76BB65831A36B395DE5726012362823475CECEC7913B8A318F6C0D88A427228AB734EA0E2B5", "hash_sha512": "FEB3016D9BD68FF01FF9A4CD056FB1C0F63CFE6BB46ED9406B5D9EDC82DB1FFB92216CFCB7B51929F3D84A5FFECB9D00AB5D512CE084D6D9A8F2BACCD00B6DC7", "hash_ssdeep": "12288:z2dXCJNAcvhunX1vRTbiY6+uabaXdAp8qrL1:wXcNBunlvRTGY6ZAaXdAp8qP", "hash_imp": "25A22308E06937DCF8797981123D18FC", "hash_pesha1": "C88784B9FFE99ED4D4592176226E34AE7D34728B", "hash_pe256": "27852B05B3BD7DC7044DDA50F5E4FB3A4D598C8A9FE4244CF4D891657CF90423", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imjpdct.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e8a4bb3ef340dd3a94e5f649a0f41b0ee0390349d435d020dce8576af42112dd/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\SatoriKnlDict_MemoryDictionary_IMJP_15__M_S-1-5-21-2047949552-857980807-821054962-504": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\1d54HWNDInterface:f0212": "Section", "\\Sessions\\1\\BaseNamedObjects\\1d54HWNDInterface:7304ae": "Section", "\\Sessions\\1\\BaseNamedObjects\\1d54HWNDInterface:b004b2": "Section", "\\Sessions\\1\\BaseNamedObjects\\_IMJP_15_UD_FileMapping_{b4f0aa5b-77d3-486f-b999-53049e87159e}_M_S-1-5-21-2047949552-857980807-821054962-504": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\IMEJP\\IMJPDCT.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Add Word" }, "IMJPSET.EXE-A7EE6301AE64907FEF06B2BCA4EA41C1": { "file_name": "IMJPSET.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\IMEJP\\IMJPSET.EXE", "hash_md5": "A7EE6301AE64907FEF06B2BCA4EA41C1", "hash_sha1": "7306A55740E225073142B0B0894FBACF87DA6B62", "hash_sha256": "4386FF9864A601116D5E8A165AFFBC00C2B642E7C4948641593A5114F0B675DF", "hash_sha384": "136884B1ED6FD47A4033887B23497999687EDCC5894C48F10E6A68411FDEE31210EDC656C8A5939503B9DB7332618D92", "hash_sha512": "278EA7780796C7A8E73C58CBCCF39359C977539B714D682AB112E2B64131CD5500AED8E2827687DD7C979EA47E2DC7E78A4FBD5438E22926299121A84426CE47", "hash_ssdeep": "3072:N+LLmZ70cI2B0CoIPe80j31dHQYyJ1Z0YH67IkK2NLPcV2:NdPB55G80L1dwYyJ1BmIkC", "hash_imp": "BB3D3D5AB97ABB6B74E68C292F476172", "hash_pesha1": "3566565EB0B54BCD684F31852BF534490AE78D94", "hash_pe256": "C2EB7A878F47B805BCB755E7D46D9B5581B436C9E497E30765A4C53E3791087E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "IMJPSET.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4386ff9864a601116d5e8a165affbc00c2b642e7c4948641593a5114f0b675df/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\_IMJP_15_UD_FileMapping_{b4f0aa5b-77d3-486f-b999-53049e87159e}_M_S-1-5-21-2047949552-857980807-821054962-504": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\IMEJP\\IMJPSET.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Settings for Microsoft IME" }, "IMJPUEX.EXE-4B3A94B9B826591C977679B493D5FE2B": { "file_name": "IMJPUEX.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\IMEJP\\IMJPUEX.EXE", "hash_md5": "4B3A94B9B826591C977679B493D5FE2B", "hash_sha1": "04CB26BEE5B66CC251FE3529A7BC19E5503F6BC3", "hash_sha256": "D063C93E6B4B3C6AC60950AEE6F981E5A0E804D907C1A11D5534008B56A8483D", "hash_sha384": "4DB9C81DC52811B3B2FC86866AE99CCEEEEBCE0F4AFE42C289BC3C80109275006BA35A06D341E0CAC05EB8A9115CE8DF", "hash_sha512": "9C75AE70F80F5E16CC79CD4DF2F0B1E25308405C02F5EB677FEE2C961E2147B5CADF371240C33AF8DC66BB0133E22C818BC6CD66544C0CD8AE419F2EF6BBE0CD", "hash_ssdeep": "1536:w+7qqVboOxOpYdxNxCBvnjYhnycXyrqNDcYH67nIWDK2NLPcrqs:w+PVboOxOpgUBvnjYhnpXyrqNYYH67ID", "hash_imp": "870FD0A6D06CED43109E434FD506DEB4", "hash_pesha1": "9709ABBA748CAB23ECD5AF790632D32D019BB2D0", "hash_pe256": "DD9CDCE29A4EBBC0E3CE11FEC19468390DBAB892E1E07B57CF60006C1E190AFE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imjpuex.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d063c93e6b4b3c6ac60950aee6f981e5a0e804d907c1a11d5534008b56a8483d/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\_IMJP_15_UD_FileMapping_{b4f0aa5b-77d3-486f-b999-53049e87159e}_M_S-1-5-21-2047949552-857980807-821054962-504": "Section", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\\comctl32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\IMEJP\\IMJPUEX.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Advanced Settings for Microsoft IME" }, "imjpuexc.exe-F69B82704650FEEDD98204214C78694B": { "file_name": "imjpuexc.exe", "file_path": "C:\\Windows\\SysWOW64\\IME\\IMEJP\\imjpuexc.exe", "hash_md5": "F69B82704650FEEDD98204214C78694B", "hash_sha1": "51EF621D56CA0F238E7C395783567E5C74AD3677", "hash_sha256": "5B5AFEF9CEC9B575ED8CA192F579AB5F8982DE276118D243DAA73498DF4B4FEC", "hash_sha384": "D30292B56DFBA4F6EFD3B029068F4A818903624CDCA2D98616293C8192ABBCF1F86A1883E8423E9727E7A6D1133CF274", "hash_sha512": "3A1B3B85A37DA43378500D8924F30291DA4DA073AA7C14EA3380F20517A768737E9A23D4F6DF5A40C331C0210FDA803C51F3FB920CCC479C1865355223335AB7", "hash_ssdeep": "6144:tRAhJ3+BmXsINM5vZf1vOjwXjMab1JbPvB/uuTyjcEI4J2oXUTDfcV:PAHOBmX25BflB70jVMY", "hash_imp": "811122C1B721C3C3D49790B4AED1DBE9", "hash_pesha1": "B34812433AA93C50B7DEAA8E73AE4972D8D2C9E9", "hash_pe256": "95F45AEAE85D5EF9908F5200BFBE20A01D011034F45252B60FB25834A1C1430C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imjpuexc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/5b5afef9cec9b575ed8ca192f579ab5f8982de276118d243daa73498df4b4fec/detection", "output": "Microsoft IME Property Command Line Tool (10.0.19041.1)\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nThe Syntax of this command is:\r\n\r\n IMJPUEXC HELP command\r\n\r\n Commands available are:\r\n \r\nIMJPUEXC ADDSYSDICT\t\tIMJPUEXC CHECKSYSDICT \r\nIMJPUEXC REMOVESYSDICT\t\tIMJPUEXC SETKANAINPUT \r\nIMJPUEXC GETKANAINPUT\t\tIMJPUEXC SETCUSTOMDICTPATH \r\nIMJPUEXC GETCUSTOMDICTPATH\tIMJPUEXC FIXCUSTOMDICT \r\nIMJPUEXC CODEAREAFORCONVERT\tIMJPUEXC SETOKURIGANAOPTION \r\nIMJPUEXC GETOKURIGANAOPTION\tIMJPUEXC SETKEYTEMPLATE \r\nIMJPUEXC SETKUTOUTEN\t\tIMJPUEXC RESET \r\nIMJPUEXC LOADAUTOTUNEDATA\tIMJPUEXC SAVEAUTOTUNEDATA \r\nIMJPUEXC REMOVEAUTOTUNEDATA\tIMJPUEXC SETFILTERDICT \r\nIMJPUEXC GETFILTERDICT\t\tIMJPUEXC REMOVEFILTERDICT\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\IMEJP\\imjpuexc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "IMTCLNWZ.EXE-FFC5AB5333DEA60739B3AAB472A106E5": { "file_name": "IMTCLNWZ.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\IMETC\\IMTCLNWZ.EXE", "hash_md5": "FFC5AB5333DEA60739B3AAB472A106E5", "hash_sha1": "AF7004ACAA6B32B01FE78B5CEE16CB7C4FF1E96C", "hash_sha256": "14DC557335BB9356B0E667AA26480ECA9255C4C3B0026990D81488B65E525617", "hash_sha384": "2497CEDC924E0DF6259CD9CB7753EA925C70261F5C9F6AFFFEC18A14485E28696517AFC3D8FD0CB2E0E48D96A2F49D82", "hash_sha512": "EC2A5CD754A0954DC6DEB16BCAC78251CB20B732CD200C61354168C03E5504B96148C0012589D04DE3691919D60A00B5145F34DB44E89811538F7496AFD01883", "hash_ssdeep": "1536:t+PSj1oXEIQScbIlLFBWEqGMrrlxUeBUsv6STTuCqOJat408RPvITqEIxjNqcG5D:t+q+L3lLFBWEqGMrrlWeBUsv6STT5qOH", "hash_imp": "6416AEAF0224B60B005C3DEB93B8F4C8", "hash_pesha1": "144A62F5B5DD884BDEAE041A2E1317ED1E09B206", "hash_pe256": "06AEACFC2828127486BE7058E3126A5D2D7C06633200DD28E8286FB71C064CFC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IMTCLNWZ.exe", "meta_original_filename": "IMTCLNWZ.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/14dc557335bb9356b0e667aa26480eca9255c4c3b0026990d81488b65e525617/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme601709542": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\IMETC\\IMTCLNWZ.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "ANSI" }, "IMTCPROP.exe-34622F025E78CD8102AF2279C627AE59": { "file_name": "IMTCPROP.exe", "file_path": "C:\\Windows\\SysWOW64\\IME\\IMETC\\IMTCPROP.exe", "hash_md5": "34622F025E78CD8102AF2279C627AE59", "hash_sha1": "607A07A73FB70393A16AC89CA4A424F2D8A7E2F0", "hash_sha256": "715D9157EECC8579D18DFECE27B95F7C4DC13D61C43FF2B41D6E87EBC7BA732A", "hash_sha384": "E40DD07797F3B48E82E1261E27DD7C055787C2CF256627367F696C64299DAF3DE0BD4F13FC884480569A51C08032E9EF", "hash_sha512": "42A1285F2DB8BC55A74AF2976DB9FAA93609B34D499E71C20F2607FC1A6B5DEDCD99B0259A04F21A9DA499155F1A9756FB6D837261E2D3EA815E92DD6E851FA3", "hash_ssdeep": "6144:YgB/7COPxFUwT1EU4XJBijINmKKRiT7fJAa:Ygl7ZT1EU2Kwu", "hash_imp": "18F6484D8D3D044E4441268FE29D8232", "hash_pesha1": "AE04155103992C8EF2954CC5EBE362BCDF9B8D53", "hash_pe256": "646D31E09BBE7D3E920A562AD11B5FB1E6CFB8D858DB7F562311D788EB9654A8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IMTCPROP.exe", "meta_original_filename": "IMTCPROP.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/715d9157eecc8579d18dfece27b95f7c4dc13d61c43ff2b41d6e87ebc7ba732a/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\IMETC\\IMTCPROP.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Microsoft Bopomofo" }, "IMCCPHR.exe-69A21227EB75F9100BAFD6CE573A1DC0": { "file_name": "IMCCPHR.exe", "file_path": "C:\\Windows\\SysWOW64\\IME\\SHARED\\IMCCPHR.exe", "hash_md5": "69A21227EB75F9100BAFD6CE573A1DC0", "hash_sha1": "E42F17588BC8A2FA0F54F6791EF69844C8D15129", "hash_sha256": "227A008863401D4C6D070A361CC036240ADD4ADAA9F715D11575A8A99A92AA2E", "hash_sha384": "33613C7F20E1C7A0148238161E8A899C60859DFF4F9EEA22BCE05934352D7E31445747F8AC6C978F7EF0EB1B37B97061", "hash_sha512": "9B18E229484C4E5560DDDE6BAB66BAE6BFC31759E5934642886D36EAE0078ADE507917693E9F5AEE9A01A4BE6C8A4E2548DB490C383960945D06C19D0F689F07", "hash_ssdeep": "6144:AxFUyw0VgKnhrgv+om/48VMxhn5roOlx8uSXmCPwP6k+kc8DZ5n:AxdB/ZMxhnkuSXmH6k+kcuv", "hash_imp": "DCCE6A97A60459F60530CBC8B0055A5F", "hash_pesha1": "7407F7143EB231D5F5A85C6F5B3D1AAB6C70D4C2", "hash_pe256": "00D35E8294F23123551A9B6540515072F9FF139BB0091703EB999F544309F74E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IMCCPHR.exe", "meta_original_filename": "IMCCPHR.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/227a008863401d4c6d070a361cc036240add4adaa9f715d11575a8a99a92aa2e/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\SHARED\\IMCCPHR.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "User-defined Phrase Tool for Microsoft Pinyin IME" }, "imecfmui.exe-E4FD27E531572F8A15B2C26AE2939501": { "file_name": "imecfmui.exe", "file_path": "C:\\Windows\\SysWOW64\\IME\\SHARED\\imecfmui.exe", "hash_md5": "E4FD27E531572F8A15B2C26AE2939501", "hash_sha1": "E0467228C14E436554DAD233969820E5B9BFFDE0", "hash_sha256": "858EFA815920DDBAA9A09F84CBD771D0983F128A16949E44DC57C6B328E22994", "hash_sha384": "8A90E037D1BA588BFB81474ED60FFA9988BF257D66EA338DE35F4EB4D2AEB249DA0BC72697F63ECDCE8A922DE7B33D9B", "hash_sha512": "154B673D47277EE1E369830561BADBE3FA9BE24EBF47B120616E5D465B37FB3583A63262D6DFDD5990B9557BD6E77462B671EC0746C6DA281564F1C670FB5240", "hash_ssdeep": "6144:iGAKQlmU1OxjLWvIHTgb6oPpJp3qUS+PAcwP2QJZgBk8SK1A:R1QlmU0HWvIibp6vrc0kS", "hash_imp": "7B9077DBED6642920A8FD5809C1BDC25", "hash_pesha1": "AF8392B01656A0346F820B166D1BC23217F27345", "hash_pe256": "A3C5F92D68342953161BD4BA846D5B1FA744D0D170DFA0CDA94A4CBE5949EB09", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imecfmui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/858efa815920ddbaa9a09f84cbd771d0983f128a16949e44dc57c6b328e22994/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\SHARED\\imecfmui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "IMEPADSV.EXE-278C897A5A394ED31F2F170FFF4C42E3": { "file_name": "IMEPADSV.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\SHARED\\IMEPADSV.EXE", "hash_md5": "278C897A5A394ED31F2F170FFF4C42E3", "hash_sha1": "0ED3B0763FF7675477E64EE316285E0EBA4BFC69", "hash_sha256": "1D19BA091648C5C999DBA1BF17C080A51BAE8405B6AFCD904A7DFACBE89731BB", "hash_sha384": "98674873F6712E6416E393F61FC71F5BA89CA08060D62F1B33FE2853D005E0FE35372CE2A6BEA54C7A0E45A7E04C9392", "hash_sha512": "73ED28CC9315C22E950DEB2F8BC3C5081589A25AE6FB83DD859C9024A7CF603EFB647D16EFD839BCB8F5160D2FF1A4FB18C66279EB7ABDC8D29228A93E5DF9F2", "hash_ssdeep": "6144:OlP4ypiESi8IM7NF5cMGaDGxIsD5ZjbbUz:OlP4+iri8xpF5c+8fK", "hash_imp": "86107913CB24B2D655CBD8BD76D3D77A", "hash_pesha1": "48CB15BB14692157EE5F68BC872B27F052DD5472", "hash_pe256": "D2C6D1548EB13F98FF117F61CF85F530CC34795D55BB5908640C02C440B81A47", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "Microsoft IME", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1d19ba091648c5c999dba1bf17c080a51bae8405b6afcd904a7dfacbe89731bb/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\SHARED\\IMEPADSV.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "IMESEARCH.EXE-9866162B14CBB6439A247BB3D4B843F2": { "file_name": "IMESEARCH.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\SHARED\\IMESEARCH.EXE", "hash_md5": "9866162B14CBB6439A247BB3D4B843F2", "hash_sha1": "432103579DF1833A08728FF17B924C831D171B6E", "hash_sha256": "AB50B25AC9495255682BBEEA7204960C823FDA570DC8ECDF8856B3A22E9190F6", "hash_sha384": "61F0E24E8784EFD19E0DD0C551D13954A784AFF573D28E48C56740019B1A911C5D6186A17B05E2029E02FF40791B7FBB", "hash_sha512": "9411DF7CFFD326CD5B56A5BA0D187F8AA6D6D2CAF89FA746308EB5D68CAC48FB99EB4C58D629741683FBBB51DA69BE3DB1CFB397C7DC5500AA64D16A1A4AC02B", "hash_ssdeep": "1536:yS+GxSHfg5S0bU9CiKEZlyDhm1Ea6RbFEISoCgFjhzeBRD0CuxkWY272cOsUp1D9:yS+tfg5S0boCBZs1EAPgFjhiQx8pDl2", "hash_imp": "B5E00C40105E465BD99DD69E6EDBEA13", "hash_pesha1": "971C858D867C054CD785B76A5B66F01A80C1AB7D", "hash_pe256": "CFBBC027DA5B3948336F5AB3605FDF48FBF9F81D5351C87FCEEDC5385A4DBD48", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IME search module", "meta_original_filename": "imesearch.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/ab50b25ac9495255682bbeea7204960c823fda570dc8ecdf8856b3a22e9190f6/detection", "children": "explorer.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\msxml6r.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netmsg.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\Windows\\Theme601709542": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\SHARED\\IMESEARCH.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Microsoft IME Search Provider" }, "IMEWDBLD.EXE-40FBB367D0F83472C170359D6E3446A0": { "file_name": "IMEWDBLD.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\SHARED\\IMEWDBLD.EXE", "hash_md5": "40FBB367D0F83472C170359D6E3446A0", "hash_sha1": "C274597DAB07491C3CA8D9863383145771E4EDBB", "hash_sha256": "0CFF477B20735E3E56EB8FB1866108362F3FED20E230F07BBC21F8C2D8E13C96", "hash_sha384": "030423B6426729A7BE096632F6CF46D4DBA4A8A57E45A8143ADD7380C9C932D6D926F52BE3EC1CB83928AC067A911059", "hash_sha512": "E53E7F2379B75755D4617AB13D2DBC60D705D11689763FC0335AB61A3E61330A86488705F4C2B92F2CB1264334243BD8A27027B3240AE477D4327A83129C939D", "hash_ssdeep": "6144:vBNjNNnj4mDYaW1rxK4Op4mBNqvcGSvSOkBvGemmq8V7Gs/UEVTppcX+LRe:vBNhNn0881rxK4Op4mB2cGuSOE1V7Gs2", "hash_imp": "589AC1368274910A75F86CA227986543", "hash_pesha1": "4A1200710DB7A3F462188687A543D4334AFE78CF", "hash_pe256": "24569DB8E668615F79A19AA6C57282AD259D721EA26E4AD3DF6F88C235D69FD7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME Open Extended Dictionary Module", "meta_original_filename": "imewdbld.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/0cff477b20735e3e56eb8fb1866108362f3fed20e230f07bbc21f8c2d8e13c96/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\SHARED\\IMEWDBLD.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Microsoft IME Open Extended Dictionary Error" }, "setup.exe-54A14F2C14537FA57BB31F52080733F4": { "file_name": "setup.exe", "file_path": "C:\\Windows\\SysWOW64\\InstallShield\\setup.exe", "hash_md5": "54A14F2C14537FA57BB31F52080733F4", "hash_sha1": "9DD717434E2598F3EAB73032A500DE93558541FB", "hash_sha256": "5D5CC12F985B30A43D79FA8D44EB6CB0CADDB47D2D33EC28FBC8416CFB7514DB", "hash_sha384": "4A0C0AC1EB016CA4A5F20CF8AE7AEBE101E6DD71B03C7E94C904F7CF5D30F37B5231B20D6FCF9F575C9BF2DFAC19C1B6", "hash_sha512": "0FD5A5C3E58D9160494772D193D6C0542C0089700A03F093217E4E4F9661825682F2F18F25CE5077FCB852DFF45D71505544B73D6AA341409C045C6333B99FFC", "hash_ssdeep": "1536:N8wNfktLYUqSfzC8wATsq3CRJMdzzOi3d0eFKg:N80ct8dSfmXosgCRJMdfO6FKg", "hash_imp": "09B39D9CC248E77D59A084898ED73E6C", "hash_pesha1": "D759828F7F9C3CC9BAF19CD188D8A4F990AB2094", "hash_pe256": "D71B72FDAFADA48378D8F5E63A1B65A6EB16D8AFCDE65433C3B7FD7E25036933", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "32-bit Setup Launcher", "meta_product_name": "InstallShield", "meta_company_name": "InstallShield Software Corporation", "meta_file_version": "5, 54, 001, 0", "meta_product_version": "5, 54", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 1990-2000 InstallShield Software Corporation, Phone: (847) 240-9111", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5d5cc12f985b30a43d79fa8d44eb6cb0caddb47d2d33ec28fbc8416cfb7514db/detection", "children": "explorer.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\InstallShield\\setup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Setup Initialization Error" }, "_isdel.exe-51161BF79F25FF278912005078AD93D5": { "file_name": "_isdel.exe", "file_path": "C:\\Windows\\SysWOW64\\InstallShield\\_isdel.exe", "hash_md5": "51161BF79F25FF278912005078AD93D5", "hash_sha1": "13CB580AA1D2823CA0F748B1FC262B7DB1689F19", "hash_sha256": "B5DC0FEB738A91CE3CFA982647FE2779787335C6C2C598D5B49818565D7C3E84", "hash_sha384": "AF6ED9D7226C7E459E66A1464A58E1442AC45BC3B8AAA0693BE644327D04EE811FBD73605D06CD4B24E7A3DE1D2D24CC", "hash_sha512": "C91EAC5A01EC7BFB4D3C9DF7F90A1C6C6211464ECFEDE54F7CE2F0C8A79561E4425A56EB41B48BCD89A80BD45228B2CE0C649ED92D24019A15916306D9131D8D", "hash_ssdeep": "384:K3wIA7GjPE6nnP9TDWsKAkk/fG8+lmQP+0JSfgyz:MwIA7Q7tDUAdnemQVSfg", "hash_imp": "AF417A432744D25669A269C31C292485", "hash_pesha1": "FB5C09800C25B6498A54C4F0C638282CB01376E5", "hash_pe256": "499342A59AAFF1C1AC5F1BA1E0967C1EA21963505BAA43C841C16B02F5F3A186", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "32-bit InstallShield Deleter.", "meta_product_name": "InstallShield", "meta_company_name": "InstallShield Software Corporation", "meta_file_version": "5, 51, 138, 0", "meta_product_version": "5, 51", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 1990-1998 InstallShield Software Corporation, Phone: (847) 240-9111", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/b5dc0feb738a91ce3cfa982647fe2779787335c6c2c598d5b49818565d7c3e84/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(R--) C:\\Windows\\SysWOW64\\InstallShield\\_isdel.exe": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\InstallShield\\_isdel.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "FlashUtil_ActiveX.exe-E2E8BF8FDAD0E1BF988A6830BA8FD4EA": { "file_name": "FlashUtil_ActiveX.exe", "file_path": "C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil_ActiveX.exe", "hash_md5": "E2E8BF8FDAD0E1BF988A6830BA8FD4EA", "hash_sha1": "7E9E12588C2112F9EBAA27917686C057D78D160E", "hash_sha256": "5DA7FE49B7F2F946F5E5D979BBCD0EBDC00FA52C76C0E931C09477B5C6B6FC65", "hash_sha384": "0A652870BFE600D37DC18AA5383D88AC565D35C8F33D0CF53B14F7A980F43720A42F2657169B97EFE003C9D1AEE0FBDA", "hash_sha512": "883B89E8BC17C219B4AA8AD08A6286AE10CC0D3DCF28EF8B6243D8DFD2C032CA140D411017AB683F34EE4B16F72B74DF035EB3AAF47486DEE31214647A151D69", "hash_ssdeep": "24576:6zcuarw+OoetMjwoNUTJE5HLaHh3NXYtVvMGNAOfBPCQgtkBfodSKfskl:6zd+detMjwcUTWo5KkGNA+CQikBfOSvc", "hash_imp": "828CF460486847D5A3B6F929569311D0", "hash_pesha1": "FEB79662A5CE3F8308FA34E4CCA5D887347EC853", "hash_pe256": "E48862638EB63AAC2B3F5F20AA84C567DDB7854846FCA7268FA3967314C60B4E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000008D391F9E635AAD4D5000000000008D", "signature_thumbprint": "B8A71534F400FF263831F8FD44D22053A3F6857F", "signature_issuer": "CN=Microsoft Windows Third Party Component CA 2013, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Third Party Application Component, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Adobe Flash Player Utility", "meta_original_filename": "FlashUtil.exe", "meta_product_name": "Adobe Flash Player Utility", "meta_company_name": "Adobe", "meta_file_version": "32,0,0,445", "meta_product_version": "32,0,0,445", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 1996-2020 Adobe", "meta_legal_trademarks": "Adobe Flash Player", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5da7fe49b7f2f946f5e5d979bbcd0ebdc00fa52c76c0e931c09477b5c6b6fc65/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Windows\\SysWOW64": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "Uninstall Adobe Flash Player", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil_ActiveX.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SpeechModelDownload.exe-18A63BFDCDF9AE0D4452E21E0CD672E2": { "file_name": "SpeechModelDownload.exe", "file_path": "C:\\Windows\\SysWOW64\\Speech_OneCore\\Common\\SpeechModelDownload.exe", "hash_md5": "18A63BFDCDF9AE0D4452E21E0CD672E2", "hash_sha1": "800D84A43E53984A5E515138A6EE49902B563F9B", "hash_sha256": "04A16F385D2992CF329F73BAB3BCB8DD76ACF132C9944D98B2EEE9A05605ED0A", "hash_sha384": "1AB5AA382C01AAA24A6449CF000710511250B8771DCE0A09F41326A39977FEF2ABA80286E107BC417FE02842D18D77F7", "hash_sha512": "6E8EBCAFEE5829530DE7B826672C3C4C31BCAD36A4B06DC39FAF429B815F2484889E23B6742ECD26A26F774458A1310ED02BB49472F6BC7B5625891CFA8AB69E", "hash_ssdeep": "3072:Ps6DkEK94sT+duVpsohLgz2vXgYLcIMrB31iFyd/MJj655JKH5Cy36Ko:0QkR1z8ohv/gYLpMrB3AFyd/+cw", "hash_imp": "A311B703E44765895AEF426CCC373259", "hash_pesha1": "C70EF7B7A2464FDD657E9FDD3527664EFF6A1804", "hash_pe256": "34C078B6CF73FA2991F761F6AFC2F828D0DEC85FC4F835F94387E4BA853747E6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Speech Model Download Executable", "meta_original_filename": "SpeechModelDownload.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/04a16f385d2992cf329f73bab3bcb8dd76acf132c9944d98b2eee9a05605ed0a/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Speech_OneCore\\Common\\SpeechModelDownload.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mofcomp.exe-33DCECD8F1424636308C3244A31BAF02": { "file_name": "mofcomp.exe", "file_path": "C:\\Windows\\SysWOW64\\wbem\\mofcomp.exe", "hash_md5": "33DCECD8F1424636308C3244A31BAF02", "hash_sha1": "5997AD70F87A6B161EDDC07ABF2B8229E4ACD579", "hash_sha256": "FF02023BD6AC4E65644FFC1D300D45544B047CAB7A96E33F63EDAA16A24E067D", "hash_sha384": "9587344F5BB48C9AE4A47C99B9413DE42D4F9A5B14DAC9CF6A7DDCB39ACD72867EA43C61FA78B2F73D521F14EFC62D28", "hash_sha512": "70C71BAD76C3BF669801E461F7FA8064096F68E69B35B201BF57B7240A5A85433F36A733E36C96244522CDC09AE159AF828299DA85FFA3C8CF5053F0C4155E42", "hash_ssdeep": "384:fwL8GsKmxnkWP8CMfpyZ4/5y9/QBh8pbBuyb/YE9pukKy2dd1oahu/VqWyoWRk:YPlUejvEV7BuFdd1oac/V2E", "hash_imp": "ACD3E0F2D0B3D1E0EF9E8B2AB96C581C", "hash_pesha1": "1E53B1E4100D4A8044C1F7E113BB31F1333C9847", "hash_pe256": "40690268B71C7D040880BFD1DC8E06C4355DD4C5B8136F049AE17CC23695FEB7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "The Managed Object Format (MOF) Compiler ", "meta_original_filename": "mofcomp.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ff02023bd6ac4e65644ffc1d300d45544b047cab7a96e33f63edaa16a24e067d/detection", "output": "Microsoft (R) MOF Compiler Version 10.0.19041.1\nCopyright (c) Microsoft Corp. 1997-2006. All rights reserved.\n\nusage: mofcomp [-check] [-N:<Path>]\n [-class:updateonly|-class:createonly]\n [-instance:updateonly|-instance:createonly]\n [-B:<filename>] [-P:<Password>] [-U:<UserName>]\n [-A:<Authority>] [-WMI] [-AUTORECOVER]\n [-MOF:<path>] [-MFL:<path>] [-AMENDMENT:<Locale>]\n [-ER:<ResourceName>] [-L:<ResourceLocale>] \n <MOF filename>\n\n -check Syntax check only\n -N:<path> Load into this namespace by default\n -class:updateonly Do not create new classes\n -class:safeupdate Update unless conflicts exist\n -class:forceupdate Update resolving conflicts if possible\n -class:createonly Do not change existing classes\n -instance:updateonly Do not create new instances\n -instance:createonly Do not change existing instances\n -U:<UserName> User Name\n -P:<Password> Login password\n -A:<Authority> Example: NTLMDOMAIN:Domain\n -B:<destination filename> Creates a binary MOF file, does not add to DB\n -WMI Do Windows Driver Model (WDM) checks, requires -B switch\n -AUTORECOVER Adds MOF to list of files compiled during DB recovery\n -Amendment:<LOCALE> splits MOF into language neutral and specific versions\n where locale is of the form \"MS_4??\"\n -MOF:<path> name of the language neutral output\n -MFL:<path> name of the language specific output\n -ER:<ResourceName> extracts binary mof from named resource\n -L:<ResourceLocale> optional specific locale number when using -ER switch\n\n Example c:>mofcomp -N:root\\default yourmof.mof\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wbem\\mofcomp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WinMgmt.exe-C68950E7D9C927A3E85BD95112DE45BC": { "file_name": "WinMgmt.exe", "file_path": "C:\\Windows\\SysWOW64\\wbem\\WinMgmt.exe", "hash_md5": "C68950E7D9C927A3E85BD95112DE45BC", "hash_sha1": "34A4012C9EB518446D76A26158FF980AF3CCF5FB", "hash_sha256": "3815FC3FA1DCCCFA9B698A93501C9AB1FB466CBFB2B218630BCAA7B26F0D3FD1", "hash_sha384": "4A47F536509BF94994085BCE6591C50A05F16AD2A41539DA1F08C39E1317BC403114FD95E6CFCE717BC773C159BC38D1", "hash_sha512": "7467BA1E74C81B4237E32F5CCAD196091FE1228272CDD41D62BF3FA49D8D59EEE8D37A3BCADC4BE1DE3A7B013449F7379D3C08A2CF1501D4E60744D1B9B25ECE", "hash_ssdeep": "1536:77DN3bEqMHiqudShIPoANJLlAXuSXv+qSFEAeOFiD:bN3wqmushIPFJRAhP2EAeXD", "hash_imp": "8807B6357F8C4C979DE1B85769E34B08", "hash_pesha1": "F2A02BDC118BF062FE86CE9194FA1CC4749D2B7E", "hash_pe256": "1AD695937328230C66E5AB636CF676B49EEE9A23D29159E90685DFC07E0B240E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Service Control Utility", "meta_original_filename": "winmgmt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3815fc3fa1dcccfa9b698a93501c9ab1fb466cbfb2b218630bcaa7b26f0d3fd1/detection", "output": "Invalid parameter\n\nWindows Management Instrumentation\n\nUsage: winmgmt\t[/backup <filename>] [/restore <filename> <flag>]\n\t\t[/resyncperf] [/standalonehost [<level>]] [/sharedhost]\n\t\t[/verifyrepository [<path>]] [/salvagerepository]\n\t\t[/resetrepository]\n\n/backup <filename>\n\tCauses WMI to back up the repository to the specified file name. The\n\tfilename argument should contain the full path to the file location.\n\tThis process requires a write lock on the repository so that write\n\toperations to the repository are suspended until the backup process is\n\tcompleted.\n\n/restore <filename> <flag>\n\tManually restores the WMI repository from the specified backup file.\n\tThe filename argument should contain the full path to the backup file\n\tlocation. To perform the restore operation, WMI saves the existing\n\trepository to write back if the operation fails. Then the repository is\n\trestored from the backup file that is specified in the filename\n\targument. If exclusive access to the repository cannot be achieved,\n\texisting clients are disconnected from WMI. The flag argument must be a\n\t1 (force - disconnect users and restore) or 0 (default - restore if no\n\tusers connected) and specifies the restore mode.\n\n/resyncperf\n\tRegisters the system performance libraries with WMI.\n\n/standalonehost [<level>]\n\tMoves the Winmgmt service to a standalone Svchost process that has a\n\tfixed DCOM endpoint. The default endpoint is \"ncacn_ip_tcp.0.24158\".\n\tHowever, the endpoint may be changed by running Dcomcnfg.exe. The level\n\targument is the authentication level for the Svchost process. If level\n\tis not specified, the default is 4 (RPC_C_AUTHN_LEVEL_PKT).\n\n/sharedhost\n\tMoves the Winmgmt service into the shared Svchost process.\n\n/verifyrepository [<path>]\n\tPerforms a consistency check on the WMI repository. When you add the\n\t/verifyrepository switch without the <path> argument, then the live\n\trepository currently used by WMI is verified. When you specify the path\n\targument, you can verify any saved copy of the repository. In this\n\tcase, the path argument should contain the full path to the saved\n\trepository copy. The saved repository should be a copy of the entire\n\trepository folder.\n\n/salvagerepository\n\tPerforms a consistency check on the WMI repository, and if an\n\tinconsistency is detected, rebuilds the repository. The content of the\n\tinconsistent repository is merged into the rebuilt repository, if it\n\tcan be read. The salvage operation always works with the repository\n\tthat the WMI service is currently using. MOF files that contain the\n\t#pragma autorecover preprocessor statement are restored to the\n\trepository.\n\n/resetrepository\n\tThe repository is reset to the initial state when the operating system\n\tis first installed. MOF files that contain the #pragma autorecover\n\tpreprocessor statement are restored to the repository.\n\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wbem\\WinMgmt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WMIADAP.exe-83CFA0ACAA299FD5B1B5A255CBD4602B": { "file_name": "WMIADAP.exe", "file_path": "C:\\Windows\\SysWOW64\\wbem\\WMIADAP.exe", "hash_md5": "83CFA0ACAA299FD5B1B5A255CBD4602B", "hash_sha1": "63305D366610DC2AFF85C0CBFF508231B1AC3A05", "hash_sha256": "2D484A551751F118EA7609EBA1400F29A98206551959ABECD464828F72CFA28A", "hash_sha384": "AC92227AB27C80B09E66D3524FA85CCA68E94840FFD16B849D26AB11E9AFF719996B7875C8C111DD6B93EF3A61581D8E", "hash_sha512": "49F7B62DE1E1EF19485E8F9EF42FD9408B6DF84101A0E6A8CE602D75311828BDFDDF972FDE57D81CB976D8111A20FA4287D5722EBBF19130BB109AEC359CB32C", "hash_ssdeep": "3072:6i+66+4VOWQZPOu2qgXRm6kMxmZO7kvg6/W:6ip4kWQ9x2qotkmmZO7kosW", "hash_imp": "8CFB5725B2F97204F3268EDACE605269", "hash_pesha1": "92F3132ED12A7C9AA869E057634E606DDBEE17B2", "hash_pe256": "62FB0C96B58BAD4D73A6A977EEDA949C7F4C2743BF88655FE25CC5938957A7BA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Reverse Performance Adapter Maintenance Utility", "meta_original_filename": "wmicookr.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2d484a551751f118ea7609eba1400f29a98206551959abecd464828f72cfa28a/detection", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wbem\\WMIADAP.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WMIC.exe-82BB8430531876FBF5266E53460A393E": { "file_name": "WMIC.exe", "file_path": "C:\\Windows\\SysWOW64\\wbem\\WMIC.exe", "hash_md5": "82BB8430531876FBF5266E53460A393E", "hash_sha1": "509D2F5427221366E6BF1DC2DFC0D23E9022EAAD", "hash_sha256": "9578C31E1B58FA75A2B612456EBCE324296E53A007E5697995CEC5785956AFE4", "hash_sha384": "9A50FDE7DF28E2BD7D2C43786084CB7238AC01A4DEFCF3FE254C6EEE4E774FD8C2CC079862F5435C4B206B5123F59777", "hash_sha512": "AD94A1F864366CBCDA675192BF16B698630A96B3672742B4ED8BC939634ED281478339F3E38A012A382FCBC535F1A16475B42CD7DB27A1B53F55854AD73905F4", "hash_ssdeep": "6144:nvVmVt4pxhNZhND013yAqLEWhJ4ZVGH5enhF:nvVtdY3yAGEwEVGH0nhF", "hash_imp": "09405355AF00B2202306292C39E63FB3", "hash_pesha1": "115B5E079859E6A5F9D986B69CF9E79909AAC7D4", "hash_pe256": "3D3D3B7506DEC13ECFA67C6717AE9D2584FA490C689F17BCD0B4133C7CFB4CB9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Commandline Utility", "meta_original_filename": "wmic.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/9578c31e1b58fa75a2b612456ebce324296e53a007e5697995cec5785956afe4/detection", "output": "\r\r\nWMIC is deprecated.\r\r\n\r\r\n[global switches] <command>\r\r\n\r\r\nThe following global switches are available:\r\r\n/NAMESPACE Path for the namespace the alias operate against.\r\r\n/ROLE Path for the role containing the alias definitions.\r\r\n/NODE Servers the alias will operate against.\r\r\n/IMPLEVEL Client impersonation level.\r\r\n/AUTHLEVEL Client authentication level.\r\r\n/LOCALE Language id the client should use.\r\r\n/PRIVILEGES Enable or disable all privileges.\r\r\n/TRACE Outputs debugging information to stderr.\r\r\n/RECORD Logs all input commands and output.\r\r\n/INTERACTIVE Sets or resets the interactive mode.\r\r\n/FAILFAST Sets or resets the FailFast mode.\r\r\n/USER User to be used during the session.\r\r\n/PASSWORD Password to be used for session login.\r\r\n/OUTPUT Specifies the mode for output redirection.\r\r\n/APPEND Specifies the mode for output redirection.\r\r\n/AGGREGATE Sets or resets aggregate mode.\r\r\n/AUTHORITY Specifies the <authority type> for the connection.\r\r\n/?[:<BRIEF|FULL>] Usage information.\r\r\n\r\r\nFor more information on a specific global switch, type: switch-name /?\r\r\n\r\r\n\r\r\nThe following alias/es are available in the current role:\r\r\nALIAS - Access to the aliases available on the local system\r\r\nBASEBOARD - Base board (also known as a motherboard or system board) management.\r\r\nBIOS - Basic input/output services (BIOS) management.\r\r\nBOOTCONFIG - Boot configuration management.\r\r\nCDROM - CD-ROM management.\r\r\nCOMPUTERSYSTEM - Computer system management.\r\r\nCPU - CPU management.\r\r\nCSPRODUCT - Computer system product information from SMBIOS. \r\r\nDATAFILE - DataFile Management. \r\r\nDCOMAPP - DCOM Application management.\r\r\nDESKTOP - User's Desktop management.\r\r\nDESKTOPMONITOR - Desktop Monitor management.\r\r\nDEVICEMEMORYADDRESS - Device memory addresses management.\r\r\nDISKDRIVE - Physical disk drive management. \r\r\nDISKQUOTA - Disk space usage for NTFS volumes.\r\r\nDMACHANNEL - Direct memory access (DMA) channel management.\r\r\nENVIRONMENT - System environment settings management.\r\r\nFSDIR - Filesystem directory entry management. \r\r\nGROUP - Group account management. \r\r\nIDECONTROLLER - IDE Controller management. \r\r\nIRQ - Interrupt request line (IRQ) management. \r\r\nJOB - Provides access to the jobs scheduled using the schedule service. \r\r\nLOADORDER - Management of system services that define execution dependencies. \r\r\nLOGICALDISK - Local storage device management.\r\r\nLOGON - LOGON Sessions. \r\r\nMEMCACHE - Cache memory management.\r\r\nMEMORYCHIP - Memory chip information.\r\r\nMEMPHYSICAL - Computer system's physical memory management. \r\r\nNETCLIENT - Network Client management.\r\r\nNETLOGIN - Network login information (of a particular user) management. \r\r\nNETPROTOCOL - Protocols (and their network characteristics) management.\r\r\nNETUSE - Active network connection management.\r\r\nNIC - Network Interface Controller (NIC) management.\r\r\nNICCONFIG - Network adapter management. \r\r\nNTDOMAIN - NT Domain management. \r\r\nNTEVENT - Entries in the NT Event Log. \r\r\nNTEVENTLOG - NT eventlog file management. \r\r\nONBOARDDEVICE - Management of common adapter devices built into the motherboard (system board).\r\r\nOS - Installed Operating System/s management. \r\r\nPAGEFILE - Virtual memory file swapping management. \r\r\nPAGEFILESET - Page file settings management. \r\r\nPARTITION - Management of partitioned areas of a physical disk.\r\r\nPORT - I/O port management.\r\r\nPORTCONNECTOR - Physical connection ports management.\r\r\nPRINTER - Printer device management. \r\r\nPRINTERCONFIG - Printer device configuration management. \r\r\nPRINTJOB - Print job management. \r\r\nPROCESS - Process management. \r\r\nPRODUCT - Installation package task management. \r\r\nQFE - Quick Fix Engineering. \r\r\nQUOTASETTING - Setting information for disk quotas on a volume. \r\r\nRDACCOUNT - Remote Desktop connection permission management.\r\r\nRDNIC - Remote Desktop connection management on a specific network adapter.\r\r\nRDPERMISSIONS - Permissions to a specific Remote Desktop connection.\r\r\nRDTOGGLE - Turning Remote Desktop listener on or off remotely.\r\r\nRECOVEROS - Information that will be gathered from memory when the operating system fails. \r\r\nREGISTRY - Computer system registry management.\r\r\nSCSICONTROLLER - SCSI Controller management. \r\r\nSERVER - Server information management. \r\r\nSERVICE - Service application management. \r\r\nSHADOWCOPY - Shadow copy management.\r\r\nSHADOWSTORAGE - Shadow copy storage area management.\r\r\nSHARE - Shared resource management. \r\r\nSOFTWAREELEMENT - Management of the elements of a software product installed on a system.\r\r\nSOFTWAREFEATURE - Management of software product subsets of SoftwareElement. \r\r\nSOUNDDEV - Sound Device management.\r\r\nSTARTUP - Management of commands that run automatically when users log onto the computer system.\r\r\nSYSACCOUNT - System account management. \r\r\nSYSDRIVER - Management of the system driver for a base service.\r\r\nSYSTEMENCLOSURE - Physical system enclosure management.\r\r\nSYSTEMSLOT - Management of physical connection points including ports, slots and peripherals, and proprietary connections points.\r\r\nTAPEDRIVE - Tape drive management. \r\r\nTEMPERATURE - Data management of a temperature sensor (electronic thermometer).\r\r\nTIMEZONE - Time zone data management. \r\r\nUPS - Uninterruptible power supply (UPS) management. \r\r\nUSERACCOUNT - User account management.\r\r\nVOLTAGE - Voltage sensor (electronic voltmeter) data management.\r\r\nVOLUME - Local storage volume management.\r\r\nVOLUMEQUOTASETTING - Associates the disk quota setting with a specific disk volume. \r\r\nVOLUMEUSERQUOTA - Per user storage volume quota management.\r\r\nWMISET - WMI service operational parameters management. \r\r\n\r\r\nFor more information on a specific alias, type: alias /?\r\r\n\r\r\nCLASS - Escapes to full WMI schema.\r\r\nPATH - Escapes to full WMI object paths.\r\r\nCONTEXT - Displays the state of all the global switches.\r\r\nQUIT/EXIT - Exits the program.\r\r\n\r\r\nFor more information on CLASS/PATH/CONTEXT, type: (CLASS | PATH | CONTEXT) /?\r\r\n\r\r\n", "error": "help - Alias not found.\r\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wbem\\WMIC.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WmiPrvSE.exe-64ACA4F48771A5BA50CD50F2410632AD": { "file_name": "WmiPrvSE.exe", "file_path": "C:\\Windows\\SysWOW64\\wbem\\WmiPrvSE.exe", "hash_md5": "64ACA4F48771A5BA50CD50F2410632AD", "hash_sha1": "F43BB99194F75A0FC535700D688E45750C4FF14D", "hash_sha256": "960056479DC34A7DE757813E9EB6ECC72C58EE5D5BA36151BAA86201BAE82F9F", "hash_sha384": "D969E2D9C3B185ADB0D223559D6AD0284F9114A1F5CA3BA56C0F09EA7F145084DCD7F9A494076A3ED884DB2E5E10E0B1", "hash_sha512": "2997F2B640816EAD0441B7C9B27B7CCCFB329D3647DAF6A77E34881F6FE6BABEA97A701AEAEA5FBA252C1ECFEB76011A96A1A1DC07E969C2B3D1619FFA83596E", "hash_ssdeep": "12288:vJT6x/4ScXEnFvznaqwIJyBdqa2gzhlE88IoJw:Ex2GFvTaqwIJyBdqaDzhlOI", "hash_imp": "0CA53E98401212233F08B3C410DCDA01", "hash_pesha1": "7A513989548DC05029F1BCDB22E087C9046DFC68", "hash_pe256": "68BBB7B160BB1E9E532803B131942A75CD75A396C06A8A266626A9A5CDD84120", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Provider Host", "meta_original_filename": "Wmiprvse.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/960056479dc34a7de757813e9eb6ecc72c58ee5d5ba36151baa86201bae82f9f/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\wbem\\WmiPrvSE.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "powershell.exe-C32CA4ACFCC635EC1EA6ED8A34DF5FAC": { "file_name": "powershell.exe", "file_path": "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe", "hash_md5": "C32CA4ACFCC635EC1EA6ED8A34DF5FAC", "hash_sha1": "F5EE89BB1E4A0B1C3C7F1E8D05D0677F2B2B5919", "hash_sha256": "73A3C4AEF5DE385875339FC2EB7E58A9E8A47B6161BDC6436BF78A763537BE70", "hash_sha384": "CC8012C1714E4A21CC6DC25E22FA88296673562B86D9C6102AF7D3775F9BFE2EDE75B029A25F1E90B46369ACEF3D945B", "hash_sha512": "6E43DCA1B92FAACE0C910CBF9308CF082A38DD39DA32375FAD72D6517DEA93E944B5E5464CF3C69A61EABF47B2A3E5AA014D6F24EFA1A379D4C81C32FA39DDBC", "hash_ssdeep": "6144:MF45pGVc4sqEoWwO9sV1yZywi/PzNKXzJ7BapCK5d3klRzULOnWyjLsPhAQzqO:95pGVcwW2KXzJ4pdd3klnnWosPhnzq", "hash_imp": "194427A488ED1DD0A91731658B071667", "hash_pesha1": "C0FCA8EB44CC6FA7C3EF3DD3EED7E2B573A6DB75", "hash_pe256": "B6F3EF35A570861DEDD3ED9BFAD1910B537AE38C701B4AB19C5966A05E61689E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows PowerShell", "meta_original_filename": "PowerShell.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/73a3c4aef5de385875339fc2eb7e58a9e8a47b6161bdc6436bf78a763537be70/detection", "output": "\r\nPowerShell[.exe] [-PSConsoleFile <file> | -Version <version>]\r\n [-NoLogo] [-NoExit] [-Sta] [-Mta] [-NoProfile] [-NonInteractive]\r\n [-InputFormat {Text | XML}] [-OutputFormat {Text | XML}]\r\n [-WindowStyle <style>] [-EncodedCommand <Base64EncodedCommand>]\r\n [-ConfigurationName <string>]\r\n [-File <filePath> <args>] [-ExecutionPolicy <ExecutionPolicy>]\r\n [-Command { - | <script-block> [-args <arg-array>]\r\n | <string> [<CommandParameters>] } ]\r\n\r\nPowerShell[.exe] -Help | -? | /?\r\n\r\n-PSConsoleFile\r\n Loads the specified Windows PowerShell console file. To create a console\r\n file, use Export-Console in Windows PowerShell.\r\n\r\n-Version\r\n Starts the specified version of Windows PowerShell. \r\n Enter a version number with the parameter, such as \"-version 2.0\".\r\n\r\n-NoLogo\r\n Hides the copyright banner at startup.\r\n\r\n-NoExit\r\n Does not exit after running startup commands.\r\n\r\n-Sta\r\n Starts the shell using a single-threaded apartment.\r\n Single-threaded apartment (STA) is the default.\r\n\r\n-Mta\r\n Start the shell using a multithreaded apartment.\r\n\r\n-NoProfile\r\n Does not load the Windows PowerShell profile.\r\n\r\n-NonInteractive\r\n Does not present an interactive prompt to the user.\r\n\r\n-InputFormat\r\n Describes the format of data sent to Windows PowerShell. Valid values are\r\n \"Text\" (text strings) or \"XML\" (serialized CLIXML format).\r\n\r\n-OutputFormat\r\n Determines how output from Windows PowerShell is formatted. Valid values\r\n are \"Text\" (text strings) or \"XML\" (serialized CLIXML format).\r\n\r\n-WindowStyle\r\n Sets the window style to Normal, Minimized, Maximized or Hidden.\r\n\r\n-EncodedCommand\r\n Accepts a base-64-encoded string version of a command. Use this parameter \r\n to submit commands to Windows PowerShell that require complex quotation \r\n marks or curly braces.\r\n\r\n-ConfigurationName\r\n Specifies a configuration endpoint in which Windows PowerShell is run.\r\n This can be any endpoint registered on the local machine including the\r\n default Windows PowerShell remoting endpoints or a custom endpoint having\r\n specific user role capabilities.\r\n \r\n-File\r\n Runs the specified script in the local scope (\"dot-sourced\"), so that the \r\n functions and variables that the script creates are available in the \r\n current session. Enter the script file path and any parameters. \r\n File must be the last parameter in the command, because all characters \r\n typed after the File parameter name are interpreted \r\n as the script file path followed by the script parameters.\r\n\r\n-ExecutionPolicy\r\n Sets the default execution policy for the current session and saves it \r\n in the $env:PSExecutionPolicyPreference environment variable. \r\n This parameter does not change the Windows PowerShell execution policy \r\n that is set in the registry.\r\n\r\n-Command\r\n Executes the specified commands (and any parameters) as though they were\r\n typed at the Windows PowerShell command prompt, and then exits, unless \r\n NoExit is specified. The value of Command can be \"-\", a string. or a\r\n script block.\r\n\r\n If the value of Command is \"-\", the command text is read from standard\r\n input.\r\n\r\n If the value of Command is a script block, the script block must be enclosed\r\n in braces ({}). You can specify a script block only when running PowerShell.exe\r\n in Windows PowerShell. The results of the script block are returned to the\r\n parent shell as deserialized XML objects, not live objects.\r\n\r\n If the value of Command is a string, Command must be the last parameter\r\n in the command , because any characters typed after the command are \r\n interpreted as the command arguments.\r\n\r\n To write a string that runs a Windows PowerShell command, use the format:\r\n\t\"& {<command>}\"\r\n where the quotation marks indicate a string and the invoke operator (&)\r\n causes the command to be executed.\r\n\r\n-Help, -?, /?\r\n Shows this message. If you are typing a PowerShell.exe command in Windows\r\n PowerShell, prepend the command parameters with a hyphen (-), not a forward\r\n slash (/). You can use either a hyphen or forward slash in Cmd.exe.\r\n\r\nEXAMPLES\r\n PowerShell -PSConsoleFile SqlSnapIn.Psc1\r\n PowerShell -version 2.0 -NoLogo -InputFormat text -OutputFormat XML\r\n PowerShell -ConfigurationName AdminRoles\r\n PowerShell -Command {Get-EventLog -LogName security}\r\n PowerShell -Command \"& {Get-EventLog -LogName security}\"\r\n\r\n # To use the -EncodedCommand parameter:\r\n $command = 'dir \"c:\\program files\" '\r\n $bytes = [System.Text.Encoding]::Unicode.GetBytes($command)\r\n $encodedCommand = [Convert]::ToBase64String($bytes)\r\n powershell.exe -encodedCommand $encodedCommand\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\en-US\\powershell.exe.mui": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_6316": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_32\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.ConsoleHost\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.ConsoleHost.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Management.Automation\\v4.0_3.0.0.0__31bf3856ad364e35\\System.Management.Automation.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Core\\v4.0_4.0.0.0__b77a5c561934e089\\System.Core.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Numerics\\v4.0_4.0.0.0__b77a5c561934e089\\System.Numerics.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.Management.Infrastructure\\v4.0_1.0.0.0__31bf3856ad364e35\\Microsoft.Management.Infrastructure.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.DirectoryServices\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.DirectoryServices.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Management\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Management.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_32\\System.Data\\v4.0_4.0.0.0__b77a5c561934e089\\System.Data.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.Security\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.Security.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_32\\System.Transactions\\v4.0_4.0.0.0__b77a5c561934e089\\System.Transactions.dll": "File", "(RWD) C:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\3.4.0\\Functions\\Assertions": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "error": "At line:1 char:3\r\n+ --help\r\n+ ~\r\nMissing expression after unary operator '--'.\r\nAt line:1 char:3\r\n+ --help\r\n+ ~~~~\r\nUnexpected token 'help' in expression or statement.\r\n + CategoryInfo : ParserError: (:) [], ParentContainsErrorRecordException\r\n + FullyQualifiedErrorId : MissingExpressionAfterOperator\r\n \r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "powershell_ise.exe-0722BC6EA7EB1A21AC2FAC7BE9B4C9A6": { "file_name": "powershell_ise.exe", "file_path": "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell_ise.exe", "hash_md5": "0722BC6EA7EB1A21AC2FAC7BE9B4C9A6", "hash_sha1": "433001D7173D18F5B294CC2B6F5F1FB411843764", "hash_sha256": "92A89AE883ED67889C50FA7AF84B1A94768C7A257DAA263211616D745D8DBDC3", "hash_sha384": "5D90625927DB70C74525971AC1AFC2EBAC2E2CF97D004397DFDCAB856758F5AB527627EDE455E2EABAD872EE08B3C842", "hash_sha512": "684EEC347F39D9135E856A827D6410C545CFB6E0F10A34E93785E975C958192C700B991A23A78817FBFDA14B4CD8FA2488D4F304B110CD3F46A22D1680E2B7C5", "hash_ssdeep": "3072:o9kVjGPsw40xLkVjqP4w6U+ToIuWNXmmZTWl/jC7gDooMLdx:0kauZToIuUXmmZbgDooMb", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "BF6BDEDA271A79E842CFF22C14536992BBBC28F9", "hash_pe256": "45C77CCBCE87AD3A7B87755E83E8947C7FF08701C239076BCC0336198EB790C8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows PowerShell ISE", "meta_original_filename": "powershell_ise.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/92a89ae883ed67889c50fa7af84b1a94768c7a257daa263211616d745d8dbdc3/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_948": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_32\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Management.Automation\\v4.0_3.0.0.0__31bf3856ad364e35\\System.Management.Automation.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Microsoft.PowerShell.ISECommon\\v4.0_3.0.0.0__31bf3856ad364e35\\Microsoft.PowerShell.ISECommon.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Core\\v4.0_4.0.0.0__b77a5c561934e089\\System.Core.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell_ise.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows PowerShell ISE" }, "Microsoft.AAD.BrokerPlugin.exe-94B216FE659A29BA863672DBD9827128": { "file_name": "Microsoft.AAD.BrokerPlugin.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\\Microsoft.AAD.BrokerPlugin.exe", "hash_md5": "94B216FE659A29BA863672DBD9827128", "hash_sha1": "C3A8C96906E19C9D66DCDD9440E2ABA757D0EF53", "hash_sha256": "D658782EB8EBABC7DFD4109E68BD396B521CD0C92775C429B7317C1018ACE75C", "hash_sha384": "4154376CA469185D95C0DF2A19CB0FCBE758A997C7FA5BAD3367F58CE8E4A971E30EC7B66D0D3539320C74CA36D0D6BA", "hash_sha512": "E23C216C6995C611DB6D4F2F93253660221B18350E41B8815A2FE0FD29C58D01B2EEC719E22114320EB18836CD3CDEAAB0F50FC42F6BC95E223AD30AE2B1BC0E", "hash_ssdeep": "3072:O5tbOxdJ28HJh1nTaL03RUkP1uKuJHykAkj+nmThte09J/eqW52wcw7O:O5tiDZ1TaL03RruAk5+naidqg2wc", "hash_imp": "1C7722EBBDCEE129017E54A6FBAF1A83", "hash_pesha1": "776B4002E762E18425F512D0CB0AF9CDFAADD0DB", "hash_pe256": "E4886F5181D898F0D9BBC5F4D401628B3EF872EFFCB43CEA2F747F4EEC2C85DD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AAD token broker plugin", "meta_original_filename": "Microsoft.AAD.BrokerPlugin.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d658782eb8ebabc7dfd4109e68bd396b521cd0c92775c429b7317c1018ace75c/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\\Microsoft.AAD.BrokerPlugin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "AccountsControlHost.exe-B5771BB2E606873149277940FFB4BCB5": { "file_name": "AccountsControlHost.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.AccountsControl_cw5n1h2txyewy\\AccountsControlHost.exe", "hash_md5": "B5771BB2E606873149277940FFB4BCB5", "hash_sha1": "0E6EF07FE7388A46C422EC3B8986E644CC40F4A1", "hash_sha256": "0F49D591D09C5F33635A2DCFF205EB7F40DEAF91C97C9F4A00EEA2CC787E4EC5", "hash_sha384": "5E342F0B0FE45559B168E93E598EBFEA92A148E86B43E126CB4676D9488F094B4BD36E1DC71B179B98C2A4135F54A9E7", "hash_sha512": "15D16D88B2F592622A9FDE5558243179F2D55AA96928ABCF421797128B85B823295BE723DFAFBD11F2EE99C1FC942FFC08961292FCD23583B7DE765CAEC8CFED", "hash_ssdeep": "6144:WC4wUHGK3KsVgYEvVB8O1Q9X9L/+T2MzX0BODSePK20rdUPq3R5LzzBrExzxwt:W9f3VeqvLgLnhK20Z2qt", "hash_imp": "8C99DF03E773B6F863719949AEFD5752", "hash_pesha1": "ADA5168869EC367D8231E7C7759FAA095E9E701F", "hash_pe256": "E35BD35007FCA23CAE1D25FFAB44CAF841025326174C930DAD65158487CA3EB3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Accounts Control Host", "meta_original_filename": "AccountsControlHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0f49d591d09c5f33635a2dcff205eb7f40deaf91c97c9f4a00eea2cc787e4ec5/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.AccountsControl_cw5n1h2txyewy\\AccountsControlHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "Microsoft.AsyncTextService.exe-14C1F0D63FA7C534AC316454CF4CEBB0": { "file_name": "Microsoft.AsyncTextService.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.AsyncTextService_8wekyb3d8bbwe\\Microsoft.AsyncTextService.exe", "hash_md5": "14C1F0D63FA7C534AC316454CF4CEBB0", "hash_sha1": "D1CC2114254B971901CF40C4B4E44896C6D4FF93", "hash_sha256": "7CC3FA92121EB04C82C0D6793856088106E53573049601809A96701952574997", "hash_sha384": "EA51720EDA049B7786CF7BC9ED6DAAF07782FF884CF00D5F59C838DDA89FA16C369E011121A15C6C639B500E15612955", "hash_sha512": "54627FE0AC77D602B70B569BED314155FA59F4F38363FE766BBE427E8EDEAA02769D58BACB36539D427AAA65ED593B8F111A92DFE6B02CE786B1C97ADA4E5CCA", "hash_ssdeep": "12288:xvh+Neynm43vGoEKWwgn/1Py9IVRT8PQ:+N9n93vGoEIg/1PyART", "hash_imp": "51FA5B19A371C4C6DCF497EC4CE8816F", "hash_pesha1": "AFBC995E8E9BB2B0D71F990E07DAB6C46CF4A37C", "hash_pe256": "682585D95DFA55A8EB723FA50CA6F4357B7FC06B4A8493D39C707B4BB037E358", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AsyncTextService", "meta_original_filename": "AsyncTextService.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7cc3fa92121eb04c82c0d6793856088106e53573049601809a96701952574997/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.AsyncTextService_8wekyb3d8bbwe\\Microsoft.AsyncTextService.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\CoreMessaging.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "BioEnrollmentHost.exe-5ECCF0A622681DDA5B1A2C6174EE8FE4": { "file_name": "BioEnrollmentHost.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.BioEnrollment_cw5n1h2txyewy\\BioEnrollmentHost.exe", "hash_md5": "5ECCF0A622681DDA5B1A2C6174EE8FE4", "hash_sha1": "5539CAEE2084539FDD9ACEF138AB1DBB5DD12324", "hash_sha256": "E63DD59D37D5540D3958841975562C4EC111ED20A86216FE7ADC320025E1D296", "hash_sha384": "C9D7230823BBB2C515DA548E1C4BF0524B0615AC5B3267E91D50FF9D676D2A3DD821D3626FC5C173E9933A2D1579952E", "hash_sha512": "22C8470AAC5EDC4E7BC01B17D8B4CF93AB283D1412D281F49F739A484DF6560E28E07DFF172F99F7AC42487AFDD39AFBF0861E05D820CCBA3956B0EEBC167E52", "hash_ssdeep": "6144:ev8YQRMd0XpA0nX5SKO3BUZvy+GNKIv+J92Zj/VN2EHBIQ67wz:ev8XROIeukBBAGNKIv+JCj/VNDCUz", "hash_imp": "0A9C4C929BA2C1D9668964D6DFDB1803", "hash_pesha1": "EF51482BB6D01C951778818FBBA417AEAA5598BC", "hash_pe256": "5FA74FDCD1CF376AA14FBB2A50E3E284C64A9BEA55DE977919689F5FD6AB254A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Biometric Enrollment Host", "meta_original_filename": "BioEnrollmentHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e63dd59d37d5540d3958841975562c4ec111ed20a86216fe7adc320025e1d296/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.BioEnrollment_cw5n1h2txyewy\\BioEnrollmentHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "CredDialogHost.exe-5294BC611C21CE8F133C2CAEE39D9964": { "file_name": "CredDialogHost.exe", "file_path": "C:\\Windows\\SystemApps\\microsoft.creddialoghost_cw5n1h2txyewy\\CredDialogHost.exe", "hash_md5": "5294BC611C21CE8F133C2CAEE39D9964", "hash_sha1": "1793634D3CA9304150E428A41A00F7196C01B4CB", "hash_sha256": "8878137D2032570D06204D28A201EC3D3F0B231A01764D3CE62CB443A7CA48DE", "hash_sha384": "0DD021F83AE10B0159177B52F84CD635BEF1385A0F986540944AF0A5203D3DD4F5F382BAC0879B2B2A8312EF970E2D32", "hash_sha512": "8E28AF2248790F4B286795D8E320F9E1E463DAB648AF0236AF9CDB820CD315CEA204F5C3C88AD0C950C110C937F59DF62C7D0DF219E6BB53B51F14503E09C950", "hash_ssdeep": "3072:ICP/zY5n0nx1Hh3AXWlYOsP7MXiV0ELzU+rQ1owjAwGYvzbSG3pP9vB86rDmDGlG:Iys50nhWWeOszEidLzObaG5S4wpwy9", "hash_imp": "192406A2F7D4B070926E244BCBEB566E", "hash_pesha1": "29FEA0216275D0C91955240C219799735BBF891A", "hash_pe256": "925F688E33F60B06C841D3771ACAF6D03F3597F9ED23D4DAB3F61B3F20098D4D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Dialog Host", "meta_original_filename": "CredDialogHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8878137d2032570d06204d28a201ec3d3f0b231a01764d3ce62cb443a7ca48de/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\microsoft.creddialoghost_cw5n1h2txyewy\\CredDialogHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "Microsoft.ECApp.exe-CA4105EB6450B7D6F6965A04133DDBA7": { "file_name": "Microsoft.ECApp.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.ECApp_8wekyb3d8bbwe\\Microsoft.ECApp.exe", "hash_md5": "CA4105EB6450B7D6F6965A04133DDBA7", "hash_sha1": "D1BA766946867DEC71E82EEE9EB0E3AD67979716", "hash_sha256": "81DE948AE002D378F928CAD38A00223ABD03F4EB3B9A158A3A28E8DB5A4F20EC", "hash_sha384": "B288F06D71AF0B01AF848B609057E507E77DD311C9B4387DFEE4C93A3151A144EFA38074A39A036A7B8D3800D6F6B0A0", "hash_sha512": "8464F1B6CE7A89B753DD1163E2C7081F58BD4F0D23677833B985AD0248D796E6D47272C15E38CC10DF4047591763854864BD852730CC7A2EC40ADE4D671F037E", "hash_ssdeep": "24576:Qtbqr+k8TStASv2BMzd/hdt/GlJngS/WsiDajpsz:2bqiStAu2BMzBPtungpDaW", "hash_imp": "A6223163DCAC1EE9250081E480477543", "hash_pesha1": "7C351168481205C339C46ADC771AF8EB99065597", "hash_pe256": "B77C6CEA5B1FFF926C2E254653C511D7501926DCAEF8CC16A472E9B6F085AAA8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EC App", "meta_original_filename": "ECApp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/81de948ae002d378f928cad38a00223abd03f4eb3b9a158a3a28e8db5a4f20ec/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.ECApp_8wekyb3d8bbwe\\Microsoft.ECApp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\CoreUIComponents.dll", "C:\\Windows\\SYSTEM32\\CoreMessaging.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\SHCORE.dll" ] }, "LockApp.exe-2B66408CCF9C34B57D583D7C1526AEDD": { "file_name": "LockApp.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.LockApp_cw5n1h2txyewy\\LockApp.exe", "hash_md5": "2B66408CCF9C34B57D583D7C1526AEDD", "hash_sha1": "D1DBFF0790D7BA0DC635FD440734651D554F3A11", "hash_sha256": "D4001DE20554935514046DB1A8D432935FFFFD6A5F874ADBBD8F03E603A1E155", "hash_sha384": "26D0037EC489BBCD2DF00710F32D6AB1C34320FFDBA29B5CDA1E5C1F081D03D88928057F27565EB2494B64A4BA58F3F3", "hash_sha512": "6271877C161B9718A470DAA2C993275FB7FB1AB94C7609834E00F72F5CFEAFF37FBA47D016B55E769B59AED7132715F3FFDF9DEF7FACF791B12325ABB4CDF65F", "hash_ssdeep": "98304:92y43iB4OPAvXACt0VekykyXOBvx7MNcUcOqBBII:oy43iB4OPAvXACt0VekykyXOBvxINcDN", "hash_imp": "8BDDE55626D5C216BF85BC67C145AB58", "hash_pesha1": "0F3935E1490183BBC95610C8F854B126A62D50EB", "hash_pe256": "5184863556165CD04B73E81BD43046CEBBEC6C25A23F0F32DBB05D5C81CA0EF9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "LockApp.exe", "meta_original_filename": "LockApp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d4001de20554935514046db1a8d432935ffffd6a5f874adbbd8f03e603a1e155/detection", "children": [ "LockApp.exe", "WerFault.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.LockApp_cw5n1h2txyewy\\LockApp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll" ] }, "MicrosoftEdge.exe-158227E21FCA62A3EA27577479C0E8B2": { "file_name": "MicrosoftEdge.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\\MicrosoftEdge.exe", "hash_md5": "158227E21FCA62A3EA27577479C0E8B2", "hash_sha1": "C2316DF0D5077059A4EAEB50269D4A9745F38FF9", "hash_sha256": "E04233F34C27E0DE1E3B2A47441F79A93D84638864FC7311F0B6145F31957046", "hash_sha384": "BD8E3A689B1DFBA919FBD66D426BCEEE7460E4B94EADED0705EC5E2E9701BACD0C398113E667E605F732F1EE12092A32", "hash_sha512": "0A327F1112392D04CD200A703EAC705409E85B77F4A39A8B27FF1F2C5DC2129B681BCAF2963927CC394D4B373D2543354A3320AB6B3A9EA19CC7290C75007575", "hash_ssdeep": "98304:WtxCRZFUD2jyv6GPPlqFjKOWmY5BGuaGmHJkOMFXLI7BHLyOQZ4mSvTKo5zI1eOB:MxCRI2jyvnPlyWONY5BGua0x4rI", "hash_imp": "9088956C5EF1E416B52CA0AE3DD80358", "hash_pesha1": "600E900029654A486F36D844A9D900AF76AAE791", "hash_pe256": "C7EB0F22FA3B50914803622810B33265EF8958DBDC02D36792372A578E45940C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Edge", "meta_original_filename": "MicrosoftEdge.exe", "meta_product_name": "Microsoft Edge", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.546 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e04233f34c27e0de1e3b2a47441f79a93d84638864fc7311f0b6145f31957046/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\\MicrosoftEdge.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "MicrosoftPdfReader.exe-334DF1319237270F9E220116D66C6F04": { "file_name": "MicrosoftPdfReader.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\\MicrosoftPdfReader.exe", "hash_md5": "334DF1319237270F9E220116D66C6F04", "hash_sha1": "7443D25A506F91F51E170E76E58231E607A1561F", "hash_sha256": "334A1BCB56E5BD832F1E745045B1D5DEE09FE909BBF39EBB4F4E25F669553409", "hash_sha384": "2823F73C2C8D6DD051BC3CB2E8ABE6F2844049C20B9FDE4FB2F843769993BBBA8FFEE338471098EE461809E112F75071", "hash_sha512": "D299FC1B64D00063FAB287842E712D411742BD42C1C18F5EA5AFA1B89CFA50A0A478334B305E0AC7D163CEDC3ABAB79AE0D51C93A763B072099594AAC8F52C34", "hash_ssdeep": "49152:9GJLgT829aVG7gzhWogfqtoql3ZGLGIprffc75BvfW5:9GtUaVG+hWobNNO5", "hash_imp": "27694AEC8C1F36EF9CA6F37E7B428526", "hash_pesha1": "D0FA7D66C63F8EE16D6D912AC32BD37CAEE29E90", "hash_pe256": "01E00DABD95E0FAF05F42DF9A9F0DA58E9F30540EC69D97045739A862E46088C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft PDF Reader Component", "meta_original_filename": "MicrosoftPdfReader.exe", "meta_product_name": "Microsoft Edge", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.423 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/334a1bcb56e5bd832f1e745045b1d5dee09fe909bbf39ebb4f4e25f669553409/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\\MicrosoftPdfReader.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\SYSTEM32\\iertutil.dll", "C:\\Windows\\SYSTEM32\\edgeIso.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "Win32WebViewHost.exe-5C3041041DD6480209B7BBF24143256C": { "file_name": "Win32WebViewHost.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Win32WebViewHost_cw5n1h2txyewy\\Win32WebViewHost.exe", "hash_md5": "5C3041041DD6480209B7BBF24143256C", "hash_sha1": "5811952C58045F17E5E24F67BAE86A35BA807454", "hash_sha256": "45F943799D75DFC90E6A1423595D861D0A400EA7BA5031FEBD9FA4B72BB9EC93", "hash_sha384": "BB22BC0F9F1580A7A4D06AA89E140B49C17AD2D836B7CA5874DDB66312B2FE6B2CD955CDED08E1FB88A28105249667EE", "hash_sha512": "814D9C4A99593C45E27F67A2F095ABB59E7F813937639E6B64FA058A63DC65F6065D0AB58F565E49E2E6CEF2B5D2B59E6A81AEBF74DB3C690C5F054C0033C386", "hash_ssdeep": "1536:e0TMP4W1oR8s7m2If74Trt7eFX738fOYkKZ4WJUCuTqB4JrN0kscP:Aiq1VT4TlAL38f5nTJU5qKJrOkJ", "hash_imp": "FFD4CDE8E7A048A780931445BE622364", "hash_pesha1": "691F381F85CF361F38E36A3A93954373FEAFF490", "hash_pe256": "4B2ED4404E9BE9663A7BD381028B17DC4D20C135F74284E52925880F863A01AF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Win32WebViewHost app", "meta_original_filename": "Win32WebViewHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/45f943799d75dfc90e6a1423595d861d0a400ea7ba5031febd9fa4b72bb9ec93/detection", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Win32WebViewHost_cw5n1h2txyewy\\Win32WebViewHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\edgemanager.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\SYSTEM32\\iertutil.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\SYSTEM32\\dcomp.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "AddSuggestedFoldersToLibraryDialog.exe-49D9889410F3E85F6E773634B4697B9C": { "file_name": "AddSuggestedFoldersToLibraryDialog.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.AddSuggestedFoldersToLibraryDialog_cw5n1h2txyewy\\AddSuggestedFoldersToLibraryDialog.exe", "hash_md5": "49D9889410F3E85F6E773634B4697B9C", "hash_sha1": "70D5E23F4DF1947BCC2930CE238088CC9C058095", "hash_sha256": "5E0E05EE5BAB5BCB5665F3A88C4A9F5ED6A4B9F9CD9CEE649A7635973A62667D", "hash_sha384": "F4A6F4D2298C828285C76B4FA1A5F67FCACE9742E6EF864B9406A8BDFD0AD9F8646610B5AFECFD22EC33CD7171769313", "hash_sha512": "156D34FC38E23507BCA4C8EEDA4F104CD80AE4A4F22BD596231998C066438AFFAF36CB1DA7ECA2C49DA4B3EC5AF2E004E1AC79450C0ACCDD762BCABCBB82BDCC", "hash_ssdeep": "6144:k0rOT4S8/lxdx5cBRq7YfWwzTBXQ3UlrB/qSgZRBcnaxKjzqMmaE2bsZ7TVZHzay:NOTBKD2fWl9ZTcnQSRXE2wZrCXPe", "hash_imp": "F0AFE50A912A0E5B660FAE4C50BD403B", "hash_pesha1": "2A78640F0C0B9C1A4A4A7213E454C852776070B1", "hash_pe256": "9A3D68F40D830C09CBB3225241D2E76C392A53280BB1699B15CFD60945F8C897", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AddSuggestedFoldersToLibraryDialog", "meta_original_filename": "AddSuggestedFoldersToLibraryDialog.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5e0e05ee5bab5bcb5665f3a88c4a9f5ed6a4b9f9cd9cee649a7635973a62667d/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.AddSuggestedFoldersToLibraryDialog_cw5n1h2txyewy\\AddSuggestedFoldersToLibraryDialog.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\SYSTEM32\\Wldp.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "CHXSmartScreen.exe-CF5AA1112831C808FF92D2AAAD60470F": { "file_name": "CHXSmartScreen.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\\CHXSmartScreen.exe", "hash_md5": "CF5AA1112831C808FF92D2AAAD60470F", "hash_sha1": "42A180444455E684B76413E328196F2C867B9490", "hash_sha256": "0E7BD226112B50482292276C0DE17E3FD6F1820FF1F3CFC014ED74A04FBC0EEB", "hash_sha384": "49CE05EC5B4EC34C3EE8CE0BCF9D5C90C206A879D5F28059FA7198AD1A61C626F8DDF33D84EF8A8BE9D1518B6AE59A09", "hash_sha512": "C6D40CB5FEFF68CB9B4C27FF7996FB1DEF8961E85304315D3ACBC09A7D21A42E2291C37F14906C08C2A2299861486A8B7DE8CC45BF9E6A298A511489A3CFCD2C", "hash_ssdeep": "6144:mPrC9897b9d+cFsXm44FYyu4ZBlW2bwnRpC8DvfShXPCb1Ui:Us89NyK1p8bCeuhi", "hash_imp": "2D98333547D6BF163598CA465BBA8134", "hash_pesha1": "2BA5BC06A9F0A3D4140993B46E036E2877D4FE33", "hash_pe256": "8B7DA7436B8832306FB451614FBE16F42E97E3CEE7BFBA36E523A009D7324908", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CHXSmartScreen.exe", "meta_original_filename": "CHXSmartScreen.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0e7bd226112b50482292276c0de17e3fd6f1820ff1f3cfc014ed74a04fbc0eeb/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\\CHXSmartScreen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll" ] }, "AppResolverUX.exe-4C53F7696849D565B98C774A90573ED2": { "file_name": "AppResolverUX.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.AppResolverUX_cw5n1h2txyewy\\AppResolverUX.exe", "hash_md5": "4C53F7696849D565B98C774A90573ED2", "hash_sha1": "ACC6E726A5683A528EE27F9C2F921F3DE0FF9202", "hash_sha256": "729BD07D3D216FA9E3B1209F8AFE0DD738C13372BD85400E918199D40E931B5E", "hash_sha384": "352506E882B2AA61512F0213B549E5B53B1985DB23364C9E8F69389989E61EB4B0606957BF48B365C819E28BCDD6CF25", "hash_sha512": "97F6836224E5E3D29877A77FF0E4DA644BA4D659F9986FB268052EB2589960C9A77CD135C63A5C7D944B6BCC7182A299CD5830659ABA847EA5197B18125FFF8E", "hash_ssdeep": "12288:1afn3diVP+s0ovphE1tt1B4Vg3TrY3u2yy:IUVl0o+lcWrY+2L", "hash_imp": "02520F7949C2457AA776745E981B4245", "hash_pesha1": "6DE08BBC62BA8CB685E8C91206A0D9593F9E70D4", "hash_pe256": "16111D30DD500D108B837D862E666BD239964B57A0B1FEA3CD25F913E8F15260", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AppResolverUX", "meta_original_filename": "AppResolverUX.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/729bd07d3d216fa9e3b1209f8afe0dd738c13372bd85400e918199d40e931b5e/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.AppResolverUX_cw5n1h2txyewy\\AppResolverUX.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "AssignedAccessLockApp.exe-ACD69AE954C7C6CB4122BAF876E6DB6C": { "file_name": "AssignedAccessLockApp.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\\AssignedAccessLockApp.exe", "hash_md5": "ACD69AE954C7C6CB4122BAF876E6DB6C", "hash_sha1": "87047E5611AE92C56DF0A95C5ED0B97F90901771", "hash_sha256": "9F3EAD3FC6EDE8DC8839428410648FDA74A41F1162CA7063FB0A8212E2FDE26F", "hash_sha384": "F79F431B2FE439D87D9270F6DBB35399DD11D0DBE68487869AC122DC0AC212EE48689D925C6AC6726A66C0E8558A7315", "hash_sha512": "FA83E5D7EE39D65C9A3FAAD59904E384AD65079EC875168BB9FAAA10725927FCD99467B27786F7D96D152F8BF8FD62689F321041D6BD51F91B4846781EE5223C", "hash_ssdeep": "6144:shx8a8sQV9/Zc5Bald2oeffF+DOSR4zUaSJttCRfoVQSS5M6ywg7Qs/KhH/C+2aA:s+sW/OwzyfSdxzK5M6ywgUsoMj", "hash_imp": "FE35D48291562BC6E0E58DB4317777B2", "hash_pesha1": "4494CAF9C006D067668B9C224040DF66DCC774EA", "hash_pe256": "29358F46CFF2041196B9F00C5E4523D7DE7CAAB77A4029A736F12202A49B5846", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AssignedAccessLockApp.exe", "meta_original_filename": "AssignedAccessLockApp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9f3ead3fc6ede8dc8839428410648fda74a41f1162ca7063fb0a8212e2fde26f/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\\AssignedAccessLockApp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "CallingShellApp.exe-C5415F104A4060D90CE1675383308A66": { "file_name": "CallingShellApp.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\\CallingShellApp.exe", "hash_md5": "C5415F104A4060D90CE1675383308A66", "hash_sha1": "1FF6961AF28778A3154A2522930F79CF25BC8861", "hash_sha256": "E3041999EB0A4378E18D792A3CAE1D8F60DD3C438069ACA0B17AA6457C2DA4FB", "hash_sha384": "EAD6789E0964EBEB46E7D54E06FFED2E71886F09FE967A56699431193850DD5424EFEA63AE96DDF0DC496D2EC25A9C3B", "hash_sha512": "FF6F7C208F8B42BF32ED0462D76D264D4D89277FB183D3ACFE4B62D4572D782C99D8EAFB430AC9AEE9C601D70282298C72645E3EACA2E217179969CC0E9F6FE2", "hash_ssdeep": "6144:+Gr4CVtlX5mblAO7rVLqUjKcHIgm0DtpY0ZpRO:+GrV5mOL3cHIgm0bD", "hash_imp": "B5960A682BD4DDB8B60C1FE8588A5B6B", "hash_pesha1": "0CEE4FBD40E832A215DDAB68E661432EF64E08D0", "hash_pe256": "9F9C901F7103998D7F8059EC795F5C153A983BA11542FE61E5A7CDAA201DDC58", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Calling App to host call progress on shell", "meta_original_filename": "CallingShellApp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e3041999eb0a4378e18d792a3cae1d8f60dd3c438069aca0b17aa6457c2da4fb/detection", "children": [ "CallingShellApp.exe", "WerFault.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\\CallingShellApp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "CapturePicker.exe-7BF745EB217B56CFC35B82B10343BC92": { "file_name": "CapturePicker.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\\CapturePicker.exe", "hash_md5": "7BF745EB217B56CFC35B82B10343BC92", "hash_sha1": "D1F484CA8E81599039A7B8EDF99ABAA76A4C94E4", "hash_sha256": "8DEDBF59904814FF1E455A29712451816A50FC9DD66066F617F09233FFF6E100", "hash_sha384": "149158EA4E2E32A8A293028F6B579087572BD6748EA4C9A31178284B9BBD25C30F9C994EDFF673561B9F23F22382D683", "hash_sha512": "AA8EFACEE31D6E59315490D24B9B1154D9FF33C15D43FCCB6AE0077C3681AB0EA07FADE759CBC2EF9C14C35D822797DDE1392C9420342C1752C7A15E4B20B8C4", "hash_ssdeep": "12288:9IbqjVdKRABMyfWjfqfi3FaH4Yfe3mfKes7:9ImjORlAxfi3FaH4Yfe3Su7", "hash_imp": "21E63282482CDDC14BC8F24072146F04", "hash_pesha1": "00E69900417E030A08CE4F3522F81A659C2AA0CC", "hash_pe256": "CBB0B4692906565BA81A74C15D1F8563E8B1B6E56E40BB5C09CE2FEA2CDF3D37", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/8dedbf59904814ff1e455a29712451816a50fc9dd66066f617f09233fff6e100/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\\CapturePicker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "FileExplorer.exe-95A4AF346BED7F75D645D4B692D0C859": { "file_name": "FileExplorer.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.FileExplorer_cw5n1h2txyewy\\FileExplorer.exe", "hash_md5": "95A4AF346BED7F75D645D4B692D0C859", "hash_sha1": "EA8CA5DD10BCA7073D0BA479DE6F9E1F48E75E3D", "hash_sha256": "D2A908C59A91AC03E74CD8A9AD32230FF0B53DC3CA2CA23991CDEE049D63A08C", "hash_sha384": "63B097B51422CA178D9183FB9D801EF3D7682AEC49B522ED24ABC7B215C903C535CD41D33415EF152E741CD42D426C98", "hash_sha512": "7E961398E328C96DAE634684DB9490FEEF6B70E013F9017721584AFDB8FD134253CE41B945629B795052638BB252E454307FA947607D3C8917D5EF57C8EA1723", "hash_ssdeep": "49152:ztLrjSB6nHiY90+VeqVYBCcA8g17671qLSPhVJiVpcEwWgIQf3d1M3gGIvH:zxSBgHiS0cVYBCcAEcL0GrwlIQFPP", "hash_imp": "C1A74A3E54C8FAD9F56F95944DF5BA08", "hash_pesha1": "52682C3250E171B85C5A66CE007A70ABE15131A8", "hash_pe256": "7BAE5C3B2663FD19E44CEA51A25A70837747E4E10483EE5B745B8D1FABA58E0C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Explorer", "meta_original_filename": "FileExplorer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d2a908c59a91ac03e74cd8a9ad32230ff0b53dc3ca2ca23991cdee049d63a08c/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.FileExplorer_cw5n1h2txyewy\\FileExplorer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\DWrite.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "FilePicker.exe-8119B201EB061423120167D8EFD21DA6": { "file_name": "FilePicker.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.FilePicker_cw5n1h2txyewy\\FilePicker.exe", "hash_md5": "8119B201EB061423120167D8EFD21DA6", "hash_sha1": "195AD09936339544E55FD1ED70BAF1CDDC196F05", "hash_sha256": "A5C929F32B4C760E50BCC77B9675C26A7950EF806FC2079F248BE5C226DFDC1A", "hash_sha384": "95BC15E675297E5D29F422A070F592EB44010DAE18ABA9E251804FB35394818170861520CE3E410BD92E05ADE9F53B21", "hash_sha512": "12C4E24E2AC33C6E4A9A0E9216A3B390DC83BDD735AFAE61701EB82C262E8DF732E1096A739DCDE4F4F7CDBC29A6EBA69169BF548680DA80B7CC2F697165C475", "hash_ssdeep": "12288:R7kIvFO/Zi9fEf+fqxRhgxKfPoL5peGfnq0OvCHfOjAkwppKE:HtyZqfEf+STWx2QNpDf/GjAFPKE", "hash_imp": "B228380E2357086711EB8B2649378142", "hash_pesha1": "6B06949C80733B5519ECC5D97238ADB5FF7B7F71", "hash_pe256": "3F32B5C6B54B26BB39681DDF275426AA300446BBD3F9E7E9E03E17C4981C9A84", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Picker", "meta_original_filename": "FilePicker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/a5c929f32b4c760e50bcc77b9675c26a7950ef806fc2079f248be5c226dfdc1a/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.FilePicker_cw5n1h2txyewy\\FilePicker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\SYSTEM32\\usermgrcli.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "NarratorQuickStart.exe-0F6BF15D33BD8E98FD906CF8BF3484DD": { "file_name": "NarratorQuickStart.exe", "file_path": "C:\\Windows\\SystemApps\\microsoft.windows.narratorquickstart_8wekyb3d8bbwe\\NarratorQuickStart.exe", "hash_md5": "0F6BF15D33BD8E98FD906CF8BF3484DD", "hash_sha1": "65EFFB44713B0B15D07B1280EB02C3DA3178055E", "hash_sha256": "E0CB7C907E4FE45EAEA60DDCC1200FC3DC1743CA188E578DC801E52A72711A05", "hash_sha384": "13CE93632D8227FDF2B9C90A29BCB96FD2F60090A1000379564905AE5CFD0C7EA693E47E2A85579239074774A1641E54", "hash_sha512": "A367E86364FD6749B519F2DB1F3D734499674B03ACD7EB721E47855AD8D4A87D71F7D3E53783A69B754E8E54EEC24C4A2C47E495686AA318D07F4CEE3C2F9143", "hash_ssdeep": "12288:wtPI8qHNDjDnMZZPRJq8SwqGQDIq+KAx:wt5uDMZZfb1qGQDIqC", "hash_imp": "757B2D8F5B5E67F3E4F8898C87984D5D", "hash_pesha1": "680825888C4E4ECA88FD6C6DF072D117C3E0CAC8", "hash_pe256": "60D17C2DAA2D3EB87FED36807070D8A0521DAF14360D8016F34CA4492DBFBA86", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/e0cb7c907e4fe45eaea60ddcc1200fc3dc1743ca188e578dc801e52a72711a05/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\microsoft.windows.narratorquickstart_8wekyb3d8bbwe\\NarratorQuickStart.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "OOBENetworkCaptivePortal.exe-13583AC903791057EBC1CD13EAD52703": { "file_name": "OOBENetworkCaptivePortal.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\\OOBENetworkCaptivePortal.exe", "hash_md5": "13583AC903791057EBC1CD13EAD52703", "hash_sha1": "E6103009B0A014ABC5F6909D1A057E3D420F3BB1", "hash_sha256": "D450E23F4813E5E059377CD7CBB4BD459930266980480BC161F8720E1330742C", "hash_sha384": "AF17CC45E770DA081827308C973ED0D5EC3F59066B3D425783544D750FC597616C7838D706F7470C19F519E08A1C1888", "hash_sha512": "865159B2A50DEAB9769AD7AAA08B475C6DE615DFBE9FECB851E5A688B8FACD6AC9FC52D36BC2A5F910E96489E076FCB941DDD7D8F1345A6E0A4488EAD7E7F065", "hash_ssdeep": "6144:8U74Xv7hbzpA0Yfc6X86OzSfksebizQmkAfUCtaNGoiI3ld+HoeWKbaq8vLDuQvw:b74XdbttYE6Szok7ObAGoicM1bgZvw", "hash_imp": "B9F9161C70721A82F623FAB957E5E353", "hash_pesha1": "E1FBB487451EE5AD9C7329DFE67FF55D26058DB7", "hash_pe256": "421365AA826AC6D95E33165BB99B2F2A50DA30644C9DFF98671A2B2F859FCD47", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "OOBE Captive Portal Flow", "meta_original_filename": "OOBECaptivePortalFlow.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d450e23f4813e5e059377cd7cbb4bd459930266980480bc161f8720e1330742c/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\\OOBENetworkCaptivePortal.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\nlaapi.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL" ] }, "OOBENetworkConnectionFlow.exe-43D3C917EC49FC15D5739760F888FFCD": { "file_name": "OOBENetworkConnectionFlow.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\\OOBENetworkConnectionFlow.exe", "hash_md5": "43D3C917EC49FC15D5739760F888FFCD", "hash_sha1": "8FFFC866BE4D8E8E484EFF460843E0D7BB322FCF", "hash_sha256": "E96EE7FA4C6EFD9558B8BEF071A93026B0A8D07D943E349AD85DBCB2BDB66A67", "hash_sha384": "B22C26C71E0D300154590795E78719388E151C2E23F23A8D6F224192DD51AD4BAF263226301AE75D030B8D6B6FF66746", "hash_sha512": "CB2AE0DCEF783D123601BEE3C6BC64CAD01EAF04B65BEE2C9BD070032B887899C4AC3E2068F2F81E80FA9757CD843F4AA2B7075D6BFCFC3F24B6625810CCC85D", "hash_ssdeep": "6144:G2r6GJeB/vge/g+6XHv4I9Ef4K7QbRU3i6wGAACE/fINyG6MxY7Cr:yG4B/QHv4I9/Nei6wGINpYWr", "hash_imp": "DD435DD80BBFEB0CF8D8C8B87AEC3A53", "hash_pesha1": "DF9A00DF2FF54752973F6D1D7149E4703E95143C", "hash_pe256": "C120DB637684F26849F20BB01EE14504551E7DEFEC5DB020F246C3EC5CD3C609", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "OOBE Network Connection Flow", "meta_original_filename": "OOBENetworkConnectionFlow.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/e96ee7fa4c6efd9558b8bef071a93026b0a8d07d943e349ad85dbcb2bdb66a67/detection", "children": "explorer.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\\OOBENetworkConnectionFlow.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "PeopleExperienceHost.exe-4DB57408AA06543E575368FEDC280B4A": { "file_name": "PeopleExperienceHost.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\\PeopleExperienceHost.exe", "hash_md5": "4DB57408AA06543E575368FEDC280B4A", "hash_sha1": "0B2F2495EC3BD05235212D5E0E9A056E08060881", "hash_sha256": "C581A056B647CE62177D0D05376B9016D585DE4310F5A89FEAC069181A5B7941", "hash_sha384": "26516CDB687208C70F43EDC2F7CA43322AD33BADFC875561627E824DACE81B7D69FE0A2E704B72D51967B543EEEED757", "hash_sha512": "DB6E4D515CA8E9C09A904B671877EA041C834412C8CDDDF49F1A0CC303C231ADDE3B1D41C7DDF4C37B9515EF7815935F50CCA39422B2DFCEA0539C673201F9F0", "hash_ssdeep": "6144:kUwObFpgNnLYINlxGd7lb2sFbKrZAuLtUjyL3hvXVJywLWCEBS1Z+o:kU1+QlbfqZLUjyLVyIaKZL", "hash_imp": "180179AABAB9EECB319183B94CF867C0", "hash_pesha1": "EBF30F0FA3C107AFD7537A323FA5811203FA766D", "hash_pe256": "54F704E30AAA418A3C0B0343D0DE85C5846667AE30E3DF6AB8641A2EBC71442A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows My People", "meta_original_filename": "PeopleExperienceHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c581a056b647ce62177d0d05376b9016d585de4310f5a89feac069181a5b7941/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\\PeopleExperienceHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "PinningConfirmationDialog.exe-B50C08EFB73D902BEB98FAA4D516526C": { "file_name": "PinningConfirmationDialog.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\\PinningConfirmationDialog.exe", "hash_md5": "B50C08EFB73D902BEB98FAA4D516526C", "hash_sha1": "51BD51E685FCB139E482C3BE5957E6C4AAB5080A", "hash_sha256": "6F4B8B74CD58406DB8A505D7C776607CFA77EE4337D9AEDC4F009D99BE52E0BD", "hash_sha384": "0D33327CBA9C8E21B00C5629E0A17BEDE925412CF0FF3E83CF774EAC5CE70686630934F2FC73CA47E5B043D4A1C9FD16", "hash_sha512": "220F7E504F9787167C462A066F55208B4DF74704BA0286AA52B35199345A100A82DEBEEA1D546D34A2AB7680AA3B5A5A385EBCF447B7F1589993286FA0EC80BB", "hash_ssdeep": "6144:O4+fjaJlEuya/0cPuzjgmVEa6Mti60lgG7BLPIDOwLwwM8:PJlEBcPAjEMylgSBLPIWF8", "hash_imp": "8CC7F5B6DB78C8599C66A2AC9DB47801", "hash_pesha1": "34C2EEE602813B8B3A0A7AE815376210650C5F0A", "hash_pe256": "469178E49368381B21C4BFA735D28DC855389A97B9A1DC41851B82F2B3D2F87D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PinningConfirmationDialog.exe", "meta_original_filename": "PinningConfirmationDialog.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6f4b8b74cd58406db8a505d7c776607cfa77ee4337d9aedc4f009d99be52e0bd/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\\PinningConfirmationDialog.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "SearchApp.exe-1AAF4CDC887A95E5515DC4C3FB58E46D": { "file_name": "SearchApp.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.Search_cw5n1h2txyewy\\SearchApp.exe", "hash_md5": "1AAF4CDC887A95E5515DC4C3FB58E46D", "hash_sha1": "BA56CAAD49E3601259D4043CCAF41E6E01841C3D", "hash_sha256": "BE1C4326648531600D4EDAFF0383AC6D1022844557B5AB4D89BAB71760113C41", "hash_sha384": "4F696BAE6B7428DE6861BE2D29A5C34DA6C6E1357E5B73C447E6404638C74775D77103C6C38F46AAD6BF61E33F49643E", "hash_sha512": "46613F510F9F2A13821213A523C928C4CE5711A4C20F62F835C079E133E54F85E346E239BE53DD4FC75D4F7F7C0C20D20A2E97FA49A6594FA00FD14E76A534BA", "hash_ssdeep": "49152:HqYniWUBJHYyHdtJqWtaO9WyOihpWw6Ab7376hN4l5aCggIaECl:HuJHYyHcyo23l", "hash_imp": "8C7769E14B9AA74143FD2C5BF4A40124", "hash_pesha1": "40402B76942DB631E3C0835787DE77440EF80340", "hash_pe256": "94EF61B8F807882E511DBCB13C1CF076291C2EA26DE1599A17CAE3DFE6FF60B5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Search application", "meta_original_filename": "SearchApp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/be1c4326648531600d4edaff0383ac6d1022844557b5ab4d89bab71760113c41/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.Search_cw5n1h2txyewy\\SearchApp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "SecHealthUI.exe-3BE8A98D1BC46121E31E5099BF8E49E9": { "file_name": "SecHealthUI.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\\SecHealthUI.exe", "hash_md5": "3BE8A98D1BC46121E31E5099BF8E49E9", "hash_sha1": "1C1E0E081CF9FD459F89C5A07FD6F430A67ACD1E", "hash_sha256": "497BCA027194DA4500C2FACB58CA10AF26EF2FB5945D630AC33ED792B13F3267", "hash_sha384": "2CD2FE3B829A2148B7B1C7A4A1215397E4D2B63F3AD1E46076D08095856AAD7BB4674744E2E4DFF45EE446CBC8161679", "hash_sha512": "D229F96E1F3EFAC3CCC6C3F841D86DBE1885DCB9D1D264FD3AF16D9875E077FAA67EE19163BD748334DCE7462AEA08E988309F30B5DC23D9008A78C59765F933", "hash_ssdeep": "49152:jl2Hp3y07pNEVcGTDkhFS7ITxNwTew3KIAiP3JgrDvHWUiKGi4Qnku45V71:jl2Jlg0wSLbihi4Qj", "hash_imp": "15BA6368A49AB7C784AD5D60F47CD58B", "hash_pesha1": "8209B04D8C3D08EAD0E59EF79099566FDB24AC56", "hash_pe256": "CBF077F8687B0240B60B9D57C0063FCFFC08B436CFF8E4D91ADB80C83C186C17", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Defender application", "meta_original_filename": "SecHealthUI.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.662 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.662", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/497bca027194da4500c2facb58ca10af26ef2fb5945d630ac33ed792b13f3267/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\\SecHealthUI.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\msvcrt.dll" ] }, "SecureAssessmentBrowser.exe-9997A632135DFB0C53479401E17A7367": { "file_name": "SecureAssessmentBrowser.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\\SecureAssessmentBrowser.exe", "hash_md5": "9997A632135DFB0C53479401E17A7367", "hash_sha1": "748F4C0A4267160174E2FC735D1F53EC78107502", "hash_sha256": "AAD8B016B42CC5D58B719795D235FD306C14D85F189DC3867C223BE9288D940E", "hash_sha384": "9669CBFD946058A4F96A732EC24FAEBA715CF3816FD0D5559FBC08CCFA77E4BEE6C2B036BD852EAEEB9D0233EA25621E", "hash_sha512": "76A5973C89A35158AA0120472EEABDB05B2BBEEA013571A693E48221267A037FBA42C78FEE058080B33AAD4B1AED0D487A7AA93862215BD82F472C2A5B33F5FC", "hash_ssdeep": "3072:GEMZqnBKOBcvwwSP2SSSSQSSSGSSkLSk+Siei/SGGFSS4aaaaQjUHzgMooi3pXC7:GnucvwwSvTgV", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "AE826EDF4E378673DCBBD1CFBDD7464960E9AE0D", "hash_pe256": "3F7CFC715D328518FECE7964EE6B8F5493F5CD70405EE221B241890624B89D49", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000026551AE1BBD005CBFBD000000000265", "signature_thumbprint": "E168609353F30FF2373157B4EB8CD519D07A2BFF", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Take a Test", "meta_original_filename": "SecureAssessmentBrowser.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_comments": "Take a Test", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423", "meta_product_version": "10.0.19041.423", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/aad8b016b42cc5d58b719795d235fd306c14d85f189dc3867c223be9288d940e/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\\SecureAssessmentBrowser.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "StartMenuExperienceHost.exe-6AECA53F405206CAD08032B2FE2423D7": { "file_name": "StartMenuExperienceHost.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\\StartMenuExperienceHost.exe", "hash_md5": "6AECA53F405206CAD08032B2FE2423D7", "hash_sha1": "428E60AD77F5A21B3AD8E6438E80074B09426C26", "hash_sha256": "03F57900A9324DF23DA95A46F58245649B0357F065B7F4128E387507CE9582E6", "hash_sha384": "F8E1A56596E0CFA2F8835221D3743D348AA265BBB1BDF471B041A07C3319C4822DA577CF7522AFAFAFF0F90F09DF2E7A", "hash_sha512": "E601FCDE00D487E79F25E985457A2FE1CDF7AD17706E77AA1D990FD1AE7D3CCC510C6C427C6BE69D953B5CCABA6CDD24965B94D486C2C66D5EE679C2170379CF", "hash_ssdeep": "12288:sBfIHnZMOQhy4vZ3GbpdHx58A2OCkRHskBCM4V3:sCHnzd4FQpX5f2OCkRHskBe1", "hash_imp": "2E421B1476FFB1DB0FFA09D9C0541147", "hash_pesha1": "A983E746E224A224DCA3DED83F5886C6A529F685", "hash_pe256": "FB092E3CDB5ED50156B9762474A620EB4743BEDD01C8938A404162A54463BC88", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/03f57900a9324df23da95a46f58245649b0357f065b7f4128e387507ce9582e6/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\\StartMenuExperienceHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "XGpuEjectDialog.exe-C7B82FFCE709555C80C10AF627B9EC89": { "file_name": "XGpuEjectDialog.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\\XGpuEjectDialog.exe", "hash_md5": "C7B82FFCE709555C80C10AF627B9EC89", "hash_sha1": "4A00C13EF476F3340079F18B47FF3F7870A898E4", "hash_sha256": "3C23B88A8F9B9FBAA3D14A6B34708A7AF3CD1AB3F9C954F3DE005E2F41D74E13", "hash_sha384": "80F425D7951463DD409AF597D7C1AC3139CE99D3664D768BDF29933C6C3A5AB2594FE81356DD119CED4E98A237A27E77", "hash_sha512": "A47467D7053441C230AF2CE81169337F4185D1F7B77DD6583C0BED2C695CCC7104F8AF71237615D200E6456928C5F2AFABA7FA88F1EE02963584AC8EE81B0EAE", "hash_ssdeep": "6144:VhOXIiSkG3/nmXNnCTDlFrzhryLkYeYvrZvdt0:VhziGoAr1WQWTZ1t0", "hash_imp": "0487EA951DC4014B583D512C3F8C9D24", "hash_pesha1": "BC2E43D5CEF180A9BDE872CCF1F735D9A2594736", "hash_pe256": "2459555B3A37F03E4CAF9B08F41E584FF1E173763AED011C35914565CDDDC4FE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/3c23b88a8f9b9fbaa3d14a6b34708a7af3cd1ab3f9c954f3de005e2f41d74e13/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\\XGpuEjectDialog.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "XBox.TCUI.exe-A5EEB77D79E9E3A8A4D13D897350324F": { "file_name": "XBox.TCUI.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\\XBox.TCUI.exe", "hash_md5": "A5EEB77D79E9E3A8A4D13D897350324F", "hash_sha1": "0F3F6F74F5AC42FFDAA3658C9D854F76B62FD36A", "hash_sha256": "159E6CC7CE57CAB0130F910E2852A8456511B286827B9BE11BD3ABC53BFF7464", "hash_sha384": "7B1BFC45B7770C5ABCAF40D943D53B01247334504AE5ADB1C0D4AA55114F0C16CFE1830522832D82171248C95D80149F", "hash_sha512": "87DA35D185920D28E05047DA9373FE81BECC3242EDEB9288FCA676DD9311516153FDAF4501AD19EDA7F35D5DA70B60B64AC67EB4B4DF9666BFBFDEB73863D13E", "hash_ssdeep": "3072:VVCmRqe3Svnm3uShuiHPulmesYBNtTeBq48jx:BgGhuculmNGqBq9", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "BFE25B51B3C390A9D819223091C3DE05B3206B4F", "hash_pe256": "4B94827593A1AED1C596C2BC6380F60CCCE3900CCA49D0B59DEBBCEBBA3F0EF3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCUI.UAP", "meta_original_filename": "XBox.TCUI.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423", "meta_product_version": "10.0.19041.423", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/159e6cc7ce57cab0130f910e2852a8456511b286827b9be11bd3abc53bff7464/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\\XBox.TCUI.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "TextInputHost.exe-75766BF7A652FED2C51D79AED9789394": { "file_name": "TextInputHost.exe", "file_path": "C:\\Windows\\SystemApps\\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\\InputApp\\TextInputHost.exe", "hash_md5": "75766BF7A652FED2C51D79AED9789394", "hash_sha1": "2A085105212E6B165A4F383ECD305923497C31F8", "hash_sha256": "399DFAA74CF9C50426A780137C6A06BA78D85E5D12CC9C8D89FF2352A0BE46D4", "hash_sha384": "59960EB14F3BCCE67E1DE027AA8B82CBDE3D449D28FF9B2D1BC43F344C8AEE3275E813FF714D95890114CF6E02D7D4E6", "hash_sha512": "E55A4B38727787034A22970B28BFF9418056FB94C49527F8A29D3685DBBB0C157FFCBF56C4A6253685C2C1169ECB36EFA953E8F35A2CD52E736150508C66B577", "hash_ssdeep": "384:epaQIF/2Y24/IW+GWJxDBRJenoiFWSlGsbhd:epJIF/24/E/1P3HPe", "hash_imp": "8ACCE29A751A218EBBCA39B834A66F0B", "hash_pesha1": "37DC0D40DBE19C55AA43114221A5FE85615AB336", "hash_pe256": "4D90CDF3EF763EB14762810B7A1DE4E0A6352F9B403A46131EEC9238C64B203F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "TextInputHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.22012.0.551", "meta_product_version": "2001.22012.0.551", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/399dfaa74cf9c50426a780137c6a06ba78d85e5d12cc9c8d89ff2352a0be46d4/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\\InputApp\\TextInputHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "ScreenClippingHost.exe-3C4E7F1BF05A5088430FB512081061B2": { "file_name": "ScreenClippingHost.exe", "file_path": "C:\\Windows\\SystemApps\\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\\ScreenClipping\\ScreenClippingHost.exe", "hash_md5": "3C4E7F1BF05A5088430FB512081061B2", "hash_sha1": "34625F3392E0139D36E33E5DEEFFC3A2DB16B8B6", "hash_sha256": "4491E15750B98EC9C920DF79947B9001C5B48F7285E8938051FBFA45F1328507", "hash_sha384": "8A08D96B3141202762A496F2795EDD94310F296B6D87FB0CD8EE7B6D37824F77D6E885E3E28BF65D2120918AA2E99909", "hash_sha512": "15F66F3397A448A72DD126A2D309DF1BA19750E6AF8E8CFBD93C43AC497985D065D2951811F1CC949CBD3B2A50DFBCD6502E15BDB6D32F7615352AC85DB37332", "hash_ssdeep": "192:hs6D+E0TmG7RgafpO59+WZHWxHp0VNxDBQABJ+WcQ2SkqnajKs9hG:q6JRGtXm+WZHWx0xDBRJTcQ3klGs9hG", "hash_imp": "44C701AD782D9785365B6D8072B898C8", "hash_pesha1": "4ADF3F586A93D9C7966737A2C08DBE7B4E92D390", "hash_pe256": "6B7C5098E4B16546B21A629F97AF3280DA167E5AB65743170515E64456F0DC1A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "ScreenClippingHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.22012.0.551", "meta_product_version": "2001.22012.0.551", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4491e15750b98ec9c920df79947b9001c5b48f7285e8938051fbfa45f1328507/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\\ScreenClipping\\ScreenClippingHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "UndockedDevKit.exe-C1FD0D396683E3F59646E4CEC2A55A85": { "file_name": "UndockedDevKit.exe", "file_path": "C:\\Windows\\SystemApps\\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\\UndockedDevKit.exe", "hash_md5": "C1FD0D396683E3F59646E4CEC2A55A85", "hash_sha1": "22BC4F2CAAF3B14E48DE0BB4839B88793EBE080B", "hash_sha256": "842AFA3909B01AD4A475DADD08FEB850B6A33DF9DD62F42EDC8272902AFCF865", "hash_sha384": "29FFB4AB557C436CF6FB7EF0D3C6FDB81E6F56D299656DB12480D42FAE76E683A3AF086EA4A9C0344160CB53780BB2FD", "hash_sha512": "B40923D964D8ECC7724C8BB9A03E803B6302E136E15BFE95952BFA7702C40D31146A7E08D9889FBF9F67E1078969E0935EEBFE3B4213908996A41437BE568203", "hash_ssdeep": "192:YjuhSazG6l57iQvEVqr2Xxt4jRy2XkEaMLhTSa6Nr8VHwDDBQABJVCNxXeRqnaj6:YkSaziqrGiyGjTer6wDDBRJV4JeRlY5", "hash_imp": "1AFA0949661B16256427E705407DF538", "hash_pesha1": "D3CFA759525FC7773CAEBC21BCD6F2A5F1A35260", "hash_pe256": "73CC001BD33D51D44C2B163C0A1F35E6D733B7ED83482BFF3086EDC1B4A1E5F8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/842afa3909b01ad4a475dadd08feb850b6a33df9dd62f42edc8272902afcf865/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\\UndockedDevKit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "NcsiUwpApp.exe-93472F82FF675DBCEED9ADC8556CD0BB": { "file_name": "NcsiUwpApp.exe", "file_path": "C:\\Windows\\SystemApps\\NcsiUwpApp_8wekyb3d8bbwe\\NcsiUwpApp.exe", "hash_md5": "93472F82FF675DBCEED9ADC8556CD0BB", "hash_sha1": "6AC778A68AE0EDEDACB4B549B7B793FD826BD1B4", "hash_sha256": "89B83F9F4E9DB22406CB0EC90D75CCF98492731BC5C8745F481745C31CB522FD", "hash_sha384": "B456C60FEAE70FBCDB0A9629AF696613E3C66DC954973A0CB1BFC17AEB637483E679E75E6F313C68E5C47D883EB88C1E", "hash_sha512": "35EDC260D7922CD2BCB760DA834F06F8D488BDEC255068682E0C2921636EB84352D76166B63D63CED5DE70FDBD2DB38C92D1F6837F1200DAAA06585688EC4239", "hash_ssdeep": "1536:IyqZAvsbHOYTI7U14iuhPax3R3GRoEdHppSfkThpbfbJXwjsaPiQ:IcMuQI7Uu/kRxGRoKp8f8hpbxa5", "hash_imp": "50543D972B7881279790C37E7F68D3BC", "hash_pesha1": "2CC408DB4607AB56BAAE7197407E9429ACA48B6F", "hash_pe256": "7900264C28B55C76ABE8DC957A11DB58EA2BFEF9178039E5143582EDE9F6EEE5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NcsiUwpApp", "meta_original_filename": "NcsiUwpApp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/89b83f9f4e9db22406cb0ec90d75ccf98492731bc5c8745f481745c31cb522fd/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\NcsiUwpApp_8wekyb3d8bbwe\\NcsiUwpApp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "WpcUapApp.exe-D3B81EADA490C8BB55728CD53DAA1ED9": { "file_name": "WpcUapApp.exe", "file_path": "C:\\Windows\\SystemApps\\ParentalControls_cw5n1h2txyewy\\WpcUapApp.exe", "hash_md5": "D3B81EADA490C8BB55728CD53DAA1ED9", "hash_sha1": "81A8AEABA1DE05C31B045620066CEACF150B5C66", "hash_sha256": "16AA2B2F0DEE8983B1C7C3A348090395CBA2FB41F8D12A308C846F8261BE18D8", "hash_sha384": "AE9B43A7ABB606F9F2587528D823FCC7724DE02FB5BC24F44E20084C267505100DCB7E9AF2F8E7B993A0A5933F11E94F", "hash_sha512": "0355CB52AF9768E31436EE5487524F839A523B0A135FC9C65BF3D51516F1275BFB38F2A8990E6EC029CC9CC890237474A1BFFBA8FA4506C394E7B8B67D438661", "hash_ssdeep": "6144:Hv+TTwXgGrlmP0hhRO1YtsT9n1Sv9kyhCwOxuS:P9XPBxrROmtsMhzS", "hash_imp": "4E70A38E3986D2834754EF9A0128CB64", "hash_pesha1": "B9AD9500B0F30DD8A57B2D0544FBD4DFF15F66DD", "hash_pe256": "09CCF3D812688AB3C6C79DA8824BD7EDDE8AB940137F460707EDCC4B6DEA60D8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/16aa2b2f0dee8983b1c7c3a348090395cba2fb41f8d12a308c846f8261be18d8/detection", "children": [ "WpcUapApp.exe", "WerFault.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SystemApps\\ParentalControls_cw5n1h2txyewy\\WpcUapApp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "ShellExperienceHost.exe-7D1C00D273AF86287DEE68C990A49CAD": { "file_name": "ShellExperienceHost.exe", "file_path": "C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe", "hash_md5": "7D1C00D273AF86287DEE68C990A49CAD", "hash_sha1": "0D1A489714E4693C0CDFC8FC26BE32E8D648EADD", "hash_sha256": "6CC44FBEE63233A379E08B2FDF451890F6FCE8615878C44BC1A680A6F13C9CBD", "hash_sha384": "F399A377BB27DBB1787D628298E9025C9575499BDFD38383B8AD67B412588183DB2B661B20010BA39C7409C6422E9257", "hash_sha512": "8BB13C5EE060AD28ED1049734F37EF69BF012686C2A5331799D3E8A1B4DE0B9322E464A1B80FA8050C6579ADF3C99920FA239E9A69CDDD0E4C5720DCD2D885B8", "hash_ssdeep": "24576:PtHDNH7J5FauyaNop0dvdq+HFjpi8KLVRPz3Y9rlxk7G:PtHDNH7J3Xdop+4COLerv", "hash_imp": "72533FD2CE483CDC50D7D46F66737E44", "hash_pesha1": "0996BD059D219471945156741ECBBF481395956E", "hash_pe256": "3311FD6C84DCEBE23D5BA2B517A3496EEA8638A5409263F093F39C09A56B1073", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Shell Experience Host", "meta_original_filename": "ShellExperienceHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/6cc44fbee63233a379e08b2fdf451890f6fce8615878c44bc1a680a6f13c9cbd/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\dxgi.dll", "C:\\Windows\\System32\\win32u.dll" ] }, "CameraBarcodeScannerPreview.exe-4EE408E0F7C59B9F472C4908336FFCD8": { "file_name": "CameraBarcodeScannerPreview.exe", "file_path": "C:\\Windows\\SystemApps\\Windows.CBSPreview_cw5n1h2txyewy\\CameraBarcodeScannerPreview.exe", "hash_md5": "4EE408E0F7C59B9F472C4908336FFCD8", "hash_sha1": "0EE71069D85C0625C2AE5466DEE6460364825FA3", "hash_sha256": "A7AC17698F7E9D0368A5287965507787A89048DB25DF84F79F09697BFB876198", "hash_sha384": "4E1B324FE9220ED7D50DDF88D15928485E37700F00552E8ECE7FC702B59A1E0F372CEAEA5963A41BF8801797299221B5", "hash_sha512": "BC7CFBE16C26A60241CEFDA78C01E55E1830AC3BFC1B2225E42A4C71A180253D401600AC50F82E524B103476E883FFDE2594A1D5E00D8AD14A76CB7409DBF722", "hash_ssdeep": "6144:X17sxtqiQ2xBt9HnFw7dF91UZ7B/rwCw6WdHiDoKOXY1H+Fcc9HqvDCzUH:XyuQpHnQrid/izCDo44tKvD", "hash_imp": "5343D8F9DE418FBB505870F23FA26B53", "hash_pesha1": "9C117333F045355C867B33D1E6ADAFBF705404DF", "hash_pe256": "F0CC1C5668F1537F401CB2A8A8802322C482A52684FCB7DEB86704F6308D23A6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CameraBarcodeScannerPreview", "meta_original_filename": "CameraBarcodeScannerPreview.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a7ac17698f7e9d0368a5287965507787a89048db25df84f79f09697bfb876198/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\Windows.CBSPreview_cw5n1h2txyewy\\CameraBarcodeScannerPreview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "sapisvr.exe-E54CD7DC3C2E3D0440F5D956C92EB369": { "file_name": "sapisvr.exe", "file_path": "C:\\Windows\\Speech\\Common\\sapisvr.exe", "hash_md5": "E54CD7DC3C2E3D0440F5D956C92EB369", "hash_sha1": "672653329EA86361922A69621F14276204627F82", "hash_sha256": "88DCA7A3343A4D5F3FB0DEB9128D4AC4CB1DB3F7530839D7E4BA23DA23A10198", "hash_sha384": "B69F7F4675290321E9469EC518FA920BC78132BF0AF093A61AB9B7DC30E3D1547E9D2F611EE7659DA090AEEE792D7F25", "hash_sha512": "71BF470DC4EDD6C1C6B016651C1F0CB22D0302BD5B810009CB64F2AB73FD1928979E6658258129AC86DA06B476420789C4965FE3ED5DF43B01272D97EF91F1C2", "hash_ssdeep": "768:iUvPtGgbxmOtdj/c+Wl84JzbfuDPnPqr7TVy8dWhL0aTdYF:iUXgusOkVX2yr7TVyWqxw", "hash_imp": "C6336161662DD1C2D176B595F0485D86", "hash_pesha1": "6758ADD61B2F41F7B00F56254B911F6A0EC6D2C8", "hash_pe256": "F34249F0A12ACD34D44AA1BED157183577B9A22DAB466A5192466511D63AC95D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Speech Recognition", "meta_original_filename": "sapisvr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.3.24006.00 (WinBuild.160101.0800)", "meta_product_version": "5.3.24006.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/88dca7a3343a4d5f3fb0deb9128d4ac4cb1db3f7530839d7e4ba23da23a10198/detection", "runtime_modules": [ "C:\\Windows\\Speech\\Common\\sapisvr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll" ] }, "PrintDialog.exe-394A1A970AF0F437FFABAA5BC02BAA8C": { "file_name": "PrintDialog.exe", "file_path": "C:\\Windows\\PrintDialog\\PrintDialog.exe", "hash_md5": "394A1A970AF0F437FFABAA5BC02BAA8C", "hash_sha1": "BA9B8ED608CD1C5BA57AC4FD0592DC0235FD27D7", "hash_sha256": "E1F05CC73233141FF39CB5E2423A368995848EE18E3650DDF8B4060D2A4494C6", "hash_sha384": "C25725CB2694B87F482BCB539A584EBA1B285280D9FAC704B9AED5807F8454573AA9220408ED6E7984C729F662CACD0B", "hash_sha512": "CE4C8B0AA3F0E9F96FE1F0AFCB19F7617636707D56163B8520326D1F63AA69803F501F10643F839DBB71FAFA93D7A7A357A0F2F19D64467D5E3B2793FAE37A50", "hash_ssdeep": "768:Cc2IKKOxK9MGEN7lL2o36deLGSqPqZhzOeeer9Zr04I1Pc:ICEN5q3FGhsNPc", "hash_imp": "02459D2BB92590D8FC82E2510F686172", "hash_pesha1": "E5B48A5071493D9ED0029706C0171BC78D0E555A", "hash_pe256": "474E3FF907852E78042D452769937CD1DF09542BAB87FF350EBBB2E969170745", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Print Dialog", "meta_original_filename": "PrintDialog.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e1f05cc73233141ff39cb5e2423a368995848ee18e3650ddf8b4060d2a4494c6/detection", "runtime_modules": [ "C:\\Windows\\PrintDialog\\PrintDialog.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "AddInProcess.exe-929EA1AF28AFEA2A3311FD4297425C94": { "file_name": "AddInProcess.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddInProcess.exe", "hash_md5": "929EA1AF28AFEA2A3311FD4297425C94", "hash_sha1": "2CA2E292B28CCA675DDF11EB1604208A724B59A0", "hash_sha256": "F0C5491DC3851DA576F0755319669C98809D82276B3E680350CD8E3F404F78F0", "hash_sha384": "6C16B85272AE123DC72A92AAF33DDC92FCADE3A62C9BAAAFA18169244C611B3C3FD744BF500E99DCF4C3FD0D43678454", "hash_sha512": "3DE842F1E5B4903F532709FF0A2BC5C2203B92960BF9B8CF963ED25B1D9B93B246C7D52259BCED44A7EA6B2757768F863913EE2BCE3C6E99CCE7082F07915FE0", "hash_ssdeep": "384:HvfIQRb67dOwRIeKJ9Yl6dnPU3SERztmbqCJstdMardz/JikPZ+6sPZZcWemn5fy:H3IX7dQ6Iq8eM/lG9TfqWh8fwL", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "D14D37097D399D09637CC352B7D038E1D28F807D", "hash_pe256": "5398E568D353CEEE75CB27CE9B020564466C613AB703D4F6FF58CF1F8A3808E9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AddInProcess.exe", "meta_original_filename": "AddInProcess.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/f0c5491dc3851da576f0755319669c98809d82276b3e680350cd8e3f404f78f0/detection", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddInProcess.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AddInProcess32.exe-9827FF3CDF4B83F9C86354606736CA9C": { "file_name": "AddInProcess32.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddInProcess32.exe", "hash_md5": "9827FF3CDF4B83F9C86354606736CA9C", "hash_sha1": "E73D73F42BB2A310F03EB1BCBB22BE2B8EB7C723", "hash_sha256": "C1CF3DC8FA1C7FC00F88E07AD539979B3706CA8D69223CFFD1D58BC8F521F63A", "hash_sha384": "81B8625E1C02C147E5EA1A27964397180374C2D123DD0D1F466338DAF291B27FA48A8B5305FEE50AF49D8A889191EDF4", "hash_sha512": "8261828D55F3B5134C0AEB98311C04E20C5395D4347251746F3BE0FB854F36CC7E118713CD00C9867537E6E47D5E71F2B2384FC00C67F0AE1B285B8310321579", "hash_ssdeep": "384:ac3JOvwWj8Gpw0A67dOpRipKJ9Yl6dnPU3SERztmbqCJstdMardz/JikPZ+TsPZX:a4JU8g17dG6Iq8XMnVYqW2Xmh829ukc", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "97EFB5E1E7D1982B1732753AE653B8E1240676CE", "hash_pe256": "35340519A74013FE0F3667CA391D0846942E31F58FFEEE7546238E71962F1D70", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AddInProcess.exe", "meta_original_filename": "AddInProcess32.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c1cf3dc8fa1c7fc00f88e07ad539979b3706ca8d69223cffd1d58bc8f521f63a/detection", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddInProcess32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "AddInUtil.exe-11BED2C86507F7DF04BA52CFC7EB7276": { "file_name": "AddInUtil.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddInUtil.exe", "hash_md5": "11BED2C86507F7DF04BA52CFC7EB7276", "hash_sha1": "00A4959609F92A1747885C2BAC941E0FE765C155", "hash_sha256": "EBA869EF2A566F1AA776344717E894A863B5BBCA79807E410C651D54D7C4D96D", "hash_sha384": "4B1AA346C22618AB7B8E0357E66DD3B6FB32332884BDD37D704AEE7F0A21AF28115B1C9D07513FB21EAEAF044C625B24", "hash_sha512": "2881045D4F6341AFCA8BB448C4ACAEFD8F7D1430B0CA82F88978968CB320E44E8C1BFBFFAAB3470FF70E78C16F905CC21CAD8AAF724C7E859CB852953349EC55", "hash_ssdeep": "384:AIQu7nR3M5gJMHfOdBqYIrKJ9Yl6dnPU3SERztmbqCJstdMardz/JikPZ+QtsPZP:PRZW/Od426Iq8cMITz2jBqWzrj8qlHx", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "6986AF5FDE95ED4A34DD635690D1131FBDB24450", "hash_pe256": "DEC132CD0838BAD1B48E5EA3467C9F864E80B93A7BE7AE443D4B6E4C350D2526", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AddInUtil.exe", "meta_original_filename": "AddInUtil.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/eba869ef2a566f1aa776344717e894a863b5bbca79807e410c651d54d7c4d96d/detection", "output": "Microsoft (R) Add-In deployment cache updating utility version 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nAddInUtil [-PipelineRoot:<path>] [-AddInRoot:<path>] [-Rebuild] [-Silent]\r\n\r\nThis tool updates the cache file in the specified folder, \r\ninforming the add-in model that new add-in segments have been deployed into \r\nthis folder. The pipeline root should be a folder containing subfolders for \r\nvarious add-in segments like host adapters, contracts, an optional AddIns \r\nsubfolder, etc. The AddIn Root path should be a folder that contains one \r\nsubfolder for each add-in.\r\n Options:\r\n -Rebuild Forcibly rebuild the cache file, even if not necessary.\r\n -Silent Ignore warnings about broken add-ins, etc.\r\n", "error": "Error: Unknown parameter \"--help\". Use -? for help.\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddInUtil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AppLaunch.exe-89D41E1CF478A3D3C2C701A27A5692B2": { "file_name": "AppLaunch.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AppLaunch.exe", "hash_md5": "89D41E1CF478A3D3C2C701A27A5692B2", "hash_sha1": "691E20583EF80CB9A2FD3258560E7F02481D12FD", "hash_sha256": "DC5AC8D4D6D5B230AB73415C80439B4DA77DA1CFDE18214EF601897F661ABDAC", "hash_sha384": "F9C2B94E8EDEC2B210B36294B2B5425897AA4527190D68C1E71AD1481CF9F25DD41930AA274596E4E4899DA099940440", "hash_sha512": "5C9658F6CA0D8D067BFC76072C438AC13DAA12D8C1FEF33369E1BC36A592D160A2BDB22B4F3EED73E8670BB65107A4134E18E6DC604897A80CC0768769F475DC", "hash_ssdeep": "1536:+BsZRVSXlyeg2JfVNUWWxvhKzIo0MYJuhkHyXBWge:+BsZGXMejUkzIo0MYJuhdR4", "hash_imp": "7C3C251F1EA8CF6C8DB7F4A2AD49741A", "hash_pesha1": "AEA16CBB0411FC8C47404A379AADA6016211B1F1", "hash_pe256": "59A638E503BD9E13B7D0176CD7096187C7AF8E0F20D9B2E614BA657DC1B22751", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET ClickOnce Launch Utility", "meta_original_filename": "applaunch.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/dc5ac8d4d6d5b230ab73415c80439b4da77da1cfde18214ef601897f661abdac/detection", "output": "\r\nMicrosoft (R) .NET ClickOnce Launch Utility Version 4.0.30319.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nError: Unrecognized option --help\r\nUsage: applaunch /activate <appFullName> [/manifests <manifestsPaths>] [/parameters <activationArguments>] [/nologo]\r\n applaunch /? or /help\r\n /nologo - Prevents displaying of logo\r\n Options:\r\n -activate <appFullName>\r\n Activates the application with the specified full name identity.\r\n -manifests <manifestPaths>\r\n Optional list of manifest paths to be used during the activation.\r\n -parameters <activationArguments>\r\n Optional list of activation arguments to be used during the activation.\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AppLaunch.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "aspnet_compiler.exe-FDA8C8F2A4E100AFB14C13DFCBCAB2D2": { "file_name": "aspnet_compiler.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_compiler.exe", "hash_md5": "FDA8C8F2A4E100AFB14C13DFCBCAB2D2", "hash_sha1": "19DFD86294C4A525BA21C6AF77681B2A9BBECB55", "hash_sha256": "99A2C778C9A6486639D0AFF1A7D2D494C2B0DC4C7913EBCB7BFEA50A2F1D0B09", "hash_sha384": "A078B71620EBD3CF44837940D6AED33F2C5B021D28D1AD108E25F72FF0B860CC70D00648040D1263B03601D1672279A8", "hash_sha512": "94F0ACE37CAE77BE9935CF4FC8AAA94691343D3B38DE5E16C663B902C220BFF513CD02256C7AF2D815A23DD30439582DDBB0880009C76BBF36FF8FBC1A6DDC18", "hash_ssdeep": "768:fF9E8FLLs2Zokf85d9PTV6Iq8Fnqf7P+WxqWKnz8DH:ffE6EkfOd9PT86dWvKgb", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "03D5ACF8DDFA65448F33D8C2E241A9E0AAFD6B5C", "hash_pe256": "CFA2158EBD24040C702CA7F589CF478C74C477DDB482824F4C8D183313FFE9DE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "aspnet_compiler.exe", "meta_original_filename": "aspnet_compiler.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/99a2c778c9a6486639d0aff1a7d2d494c2b0dc4c7913ebcb7bfea50a2f1d0b09/detection", "output": "Microsoft (R) ASP.NET Compilation Tool version 4.8.4084.0\r\nUtility to precompile an ASP.NET application\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage:\r\naspnet_compiler [-?] [-m metabasePath | -v virtualPath [-p physicalDir]]\r\n [[-u] [-f] [-d] [-fixednames] targetDir] [-c]\r\n [-x excludeVirtualPath [...]]\r\n [[-keyfile file | -keycontainer container]\r\n [-aptca] [-delaySign]]\r\n [-errorstack]\r\n\r\n-? Prints this help text.\r\n-m The full IIS metabase path of the application. This switch cannot\r\n be combined with the -v or -p switches.\r\n-v The virtual path of the application to be compiled (e.g.\r\n \"/MyApp\"). If -p is specified, the physical path is used to\r\n locate the application. Otherwise, the IIS metabase is used, and\r\n the application is assumed to be in the default site (under\r\n \"/LM/W3SVC/1/Root\"). This switch cannot be combined with the -m\r\n switch.\r\n-p The physical path of the application to be compiled. If -p is\r\n missing, the IIS metabase is used to locate the app. This switch\r\n must be combined with -v.\r\n-u If specified, the precompiled application is updatable.\r\n-f Overwrites the target directory if it already exists. Existing\r\n contents are lost.\r\n-d If specified, the debug information is emitted during\r\n compilation.\r\ntargetDir The physical path to which the application is compiled. If not\r\n specified, the application is precompiled in-place.\r\n-c If specified, the precompiled application is fully rebuilt. Any\r\n previously compiled components will be re-compiled. This option\r\n is always enabled when targetDir is specified.\r\n-x The virtual path of a directory that should be excluded from\r\n precompilation. This switch can be used multiple times.\r\n-keyfile The physical path to the strong name key file.\r\n-keycontainer Specifies a strong name key container.\r\n-aptca If specified, the strong-name assembly will allow partially\r\n trusted callers.\r\n-delaysign If specified, the assembly is not fully signed when created. \r\n-fixednames If specified, the compiled assemblies will be given fixed names.\r\n-nologo Suppress compiler copyright message.\r\n-errorstack Shows extra debugging information that can help debug certain\r\n conditions.\r\n\r\nExamples:\r\n\r\nThe following two commands are equivalent, and rely on the IIS metabase. The\r\ncompiled application is deployed to c:\\MyTarget:\r\n aspnet_compiler -m /LM/W3SVC/1/Root/MyApp c:\\MyTarget\r\n aspnet_compiler -v /MyApp c:\\MyTarget\r\n\r\nThe following command compiles the application /MyApp in-place. The effect is\r\nthat no more compilations will be needed when HTTP requests are sent to it:\r\n aspnet_compiler -v /MyApp\r\n\r\nThe following command does *not* rely on the IIS metabase, as it explicitly\r\nspecifies the physical source directory of the application:\r\n aspnet_compiler -v /MyApp -p c:\\myapp c:\\MyTarget\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_compiler.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "aspnet_regbrowsers.exe-BB8B6B54FD50C08AB579B84BF07918CF": { "file_name": "aspnet_regbrowsers.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_regbrowsers.exe", "hash_md5": "BB8B6B54FD50C08AB579B84BF07918CF", "hash_sha1": "3FC81B9C9FFB9A8D9BEBAB489F8C6B0938C1A711", "hash_sha256": "816939877FC16426EF1C32C25572BB763750FFE66A4E3FA3765543D0266E6505", "hash_sha384": "C1BA996239BC3D53359A2A406A2D8A1C05F7AFE8A8C37499B10816326B3B844E5C735D74E32B2151D24E8B6192C04AD7", "hash_sha512": "CE42920F15CD1167990B7A687EBCD7D832E21D45AF63E20984A234EF9C35001450B3CFE13273B2B1BE7C35BB1DA314570A74D7EEEBD7F554C6F2E91ED22F46E3", "hash_ssdeep": "384:ENAPwxabK/7YyoodyJ8Ood0XAKJ9Yl6dnPU3SERztmbqCJstdMardz/JikPZ+1Pv:mYGn//oAKodAT6Iq812HSpqWJ82n", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "FEF41A6C14FE802021764F0FEB0D0D553291A388", "hash_pe256": "C8ADD08CEEF78CE3090A3BBDBAD93DA0D32E6C6CACF90C4C94C8E6A3DEB5755E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "aspnet_regbrowsers.exe", "meta_original_filename": "aspnet_regbrowsers.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/816939877fc16426ef1c32c25572bb763750ffe66a4e3fa3765543d0266e6505/detection", "output": "Microsoft (R) ASP.NET Browser Registration Tool version 4.8.4084.0\r\nUtility to compile ASP.Net browser files.\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\nUsage:\r\naspnet_regbrowsers [-? | -i | -u]\r\n-? Prints this help text.\r\n-i Create and install the runtime browser capabilities assembly.\r\n-u Uninstall the browser capabilities assembly from the Global Assembly Cache.\r\n The default runtime browser capabilities will be used instead.\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_regbrowsers.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "aspnet_regiis.exe-5D1D74198D75640E889F0A577BBF31FC": { "file_name": "aspnet_regiis.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_regiis.exe", "hash_md5": "5D1D74198D75640E889F0A577BBF31FC", "hash_sha1": "C558F0E842C43E6B3BC066916B2F5D860C317BA5", "hash_sha256": "ED99C2402AC2CCC1CA9EBF21F10C12EE27E8D33F1E67BEA3CB34DA9CD0B4B58C", "hash_sha384": "39AE29063EEE2E1673BF140BC37AD4F6AE84C3B0CB4802FE51B59648248319F3E4F344352037ADD3539BD041D21DF806", "hash_sha512": "6F597153AC153151FF9E3D9F7E8E162F419535A8905592E0F7ADDB52AC12D2836F63073EB4D1F6F5042CF9A9EA94064D014510941E1F93C8D0F4E5C0F87634FB", "hash_ssdeep": "384:02DVsXz65YGYJjeUtJbZ/6J5DpuQX3xNR3CcYJqbZEQ3RmS3InWQVWATGpsfQpBR:0Ek6M1/WPRNR34IbwjJ7qWk84", "hash_imp": "0A40E9198D08B42CB0340923EF895D29", "hash_pesha1": "ED447374F8AA7ADDA77CB9F264434CA668A590CE", "hash_pe256": "431A8E4BC0F91A76017757C665C24E9136E484A69DC22CC07975C325819D4258", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "aspnet_regiis.exe", "meta_original_filename": "aspnet_regiis.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ed99c2402ac2ccc1ca9ebf21f10c12ee27e8d33f1e67bea3cb34da9cd0b4b58c/detection", "output": "Microsoft (R) ASP.NET RegIIS version 4.0.30319.0\r\nAdministration utility to install and uninstall ASP.NET on the local machine.\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n\r\r\n\r -- ASP.NET REGISTRATION OPTIONS --\r\n\r\r\n\r-i Install this version of ASP.NET and update IIS\r\n\r configuration at the root level to use this version of\r\n\r ASP.Net.\r\n\r\r\n\r-ir Install this version of ASP.NET, register only. Do not\r\n\r change any web applications to use this version.\r\n\r\r\n\r-iru Install this version of ASP.NET. If there are any existing\r\n\r applications that uses ASP.NET, it will not change IIS\r\n\r configuration to use this version.\r\n\r\r\n\r-enable When -enable is specified with -i, -ir or -r, ASP.NET will\r\n\r be enabled in the IIS security console (IIS 6.0 or later).\r\n\r\r\n\r-disable When -disable is specified with -i, -ir or -r, ASP.NET will\r\n\r be disabled in the IIS security console (IIS 6.0 or later).\r\n\r\r\n\r-s <path> Install scriptmaps for this version at the specified path,\r\n\r recursively.\r\n\r E.g. aspnet_regiis.exe -s W3SVC/1/ROOT/SampleApp1\r\n\r\r\n\r-sn <path> Install scriptmaps for this version at the specified path,\r\n\r non-recursively.\r\n\r\r\n\r-r Install this version of ASP.NET and update scriptmaps at\r\n\r the IIS metabase root and for all scriptmaps below the\r\n\r root. Existing scriptmaps are upgraded to this version\r\n\r regardless of the original versions.\r\n\r\r\n\r-u Uninstall this version of ASP.NET. Existing scriptmaps to\r\n\r this version are remapped to highest remaining version of\r\n\r ASP.NET installed on the machine.\r\n\r\r\n\r-ua Uninstall all versions of ASP.NET on the machine.\r\n\r\r\n\r-k <path> Remove all scriptmaps to any version of ASP.NET from the\r\n\r specified path, recursively (not supported on Windows Vista\r\n\r and higher versions).\r\n\r E.g. aspnet_regiis.exe -k W3SVC/1/ROOT/SampleApp1\r\n\r\r\n\r-kn <path> Remove all scriptmaps to any version ASP.NET from the\r\n\r specified path, non-recursively (not supported on Windows\r\n\r Vista and higher versions).\r\n\r\r\n\r-lv List all versions of ASP.NET that are installed on the\r\n\r machine, with status and installation path.\r\n\r\r\n\r-lk List all the path of all IIS metabase keys where ASP.NET is\r\n\r scriptmapped, together with the version. Keys that inherit\r\n\r ASP.NET scriptmaps from a parent key will not be displayed\r\n\r (not supported on Windows Vista and higher versions).\r\n\r\r\n\r-c Install the client side scripts for this version to the\r\n\r aspnet_client subdirectory of each IIS site directory.\r\n\r\r\n\r-e Remove the client side scripts for this version from the\r\n\r aspnet_client subdirectory of each IIS site directory.\r\n\r\r\n\r-ea Remove the client side scripts for all versions from the\r\n\r aspnet_client subdirectory of each IIS site directory.\r\n\r\r\n\r-ga <user> Grant the specified user or group access to the IIS\r\n\r metabase and other directories used by ASP.NET.\r\n\r\r\n\r\r\n\r\r\n\r -- CONFIGURATION ENCRYPTION OPTIONS --\r\n\r\r\n\r-pe section Encrypt the configuration section. Optional arguments:\r\n\r [-prov provider] Use this provider to encrypt.\r\n\r [-app virtual-path] Encrypt at this virtual path. Virtual\r\n\r path must begin with a forward slash. If it is '/', then it\r\n\r refers to the root of the site. If -app is not specified,\r\n\r the root web.config will be encrypted.\r\n\r [-site site-name-or-ID] The site of the virtual path\r\n\r specified in -app. If not specified, the default web site\r\n\r will be used.\r\n\r [-location sub-path] Location sub path.\r\n\r [-pkm] Encrypt/decrypt the machine.config instead of\r\n\r web.config.\r\n\r\r\n\r-pd section Decrypt the configuration section. Optional arguments:\r\n\r [-app virtual-path] Decrypt at this virtual path. Virtual\r\n\r path must begin with a forward slash. If it is '/', then it\r\n\r refers to the root of the site. If -app is not specified,\r\n\r the root web.config will be decrypted.\r\n\r [-site site-name-or-ID] The site of the virtual path\r\n\r specified in -app. If not specified, the default web site\r\n\r will be used.\r\n\r [-location sub-path] Location sub path.\r\n\r [-pkm] Encrypt/decrypt the machine.config instead of\r\n\r web.config.\r\n\r\r\n\r-pef section web-app-physical-dir\r\n\r Encrypt the configuration section. Optional arguments:\r\n\r [-prov provider] Use this provider to encrypt.\r\n\r\r\n\r-pdf section web-app-physical-dir\r\n\r Decrypt the configuration section.\r\n\r\r\n\r-pc container Create an RSA keypair in ContainerName. Optional arguments:\r\n\r [-size key-size] Key-size. Default is 1024.\r\n\r [-pku] User container instead of machine container.\r\n\r [-exp] Make the private keys exportable.\r\n\r [-csp provider] Csp Provider to use.\r\n\r\r\n\r-pz container Delete the ContainerName. Optional arguments:\r\n\r [-pku] User container instead of machine container.\r\n\r\r\n\r-pi container file Import an RSA keypair from the Xml file. Optional\r\n\r arguments:\r\n\r [-pku] User container instead of machine container.\r\n\r [-exp] Create exportable keys.\r\n\r [-csp provider] Csp Provider to use.\r\n\r\r\n\r-px container file Export an RSA keypair to the Xml file. Optional arguments:\r\n\r [-pku] User container instead of machine container.\r\n\r [-pri] Include private keys.\r\n\r [-csp provider] Csp Provider to use.\r\n\r\r\n\r-pa container account\r\n\r Add access for the account to the container. Arguments:\r\n\r [-pku] User container instead of machine container.\r\n\r [-csp provider] Csp Provider to use.\r\n\r [-full] Add full access (default is Read access).\r\n\r\r\n\r-pr container account\r\n\r Remove access for the account from the container.\r\n\r Arguments:\r\n\r [-pku] User container instead of machine container.\r\n\r [-csp provider] Csp Provider to use.\r\n\r\r\n\r\r\n\r\r\n\r -- CONFIGURATION REMOTE ACCESS OPTIONS --\r\n\r\r\n\r-config+ Enable remote access of configuration.\r\n\r\r\n\r-config- Disable remote access of configuration.\r\n\r\r\n\r", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_regiis.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "aspnet_regsql.exe-7A7139F35BC6A57AD087D1502E8B4047": { "file_name": "aspnet_regsql.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_regsql.exe", "hash_md5": "7A7139F35BC6A57AD087D1502E8B4047", "hash_sha1": "32516487736BBBE0EE7C792C1035BEA448446851", "hash_sha256": "7F582C408BB9C117142321B84D0D95DAA1225F06C696575AAF779F9A495E001C", "hash_sha384": "77074D54ADF7DF730BCB3DC8033C9808F9EA2204C8F0FB73E84E412FC4B3773AB8675051F89F852363CBBDFBE7F3D578", "hash_sha512": "00C18B8930BC4551D2ECA72A7EF3C19D1FEA4BD4756EA65D298DB40CE108BF54398D8C7112C55DE9EDF4FCBF27D598763E881784FFFEBA54C9DA18EC8EB02283", "hash_ssdeep": "3072:23am4bGr4tH1DK2cESdyXQxyAKFAJoXGM28:7q2LgoeBf8", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "96D41BB120A7E2010E4B9B24DB93D7F2C717B33A", "hash_pe256": "841E55606CBE80F5FA3737E80BFB86A689C51C288600ADD46AB3EC8D8AFC2582", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "aspnet_regsql.exe", "meta_original_filename": "aspnet_regsql.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7f582c408bb9c117142321b84d0d95daa1225f06c696575aaf779f9a495e001c/detection", "output": "Microsoft (R) ASP.NET SQL Registration Tool version 4.8.4084.0\r\nAdministrative utility to install and uninstall ASP.NET features on a SQL server.\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n\r\nThe argument '--help' is invalid.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_regsql.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "aspnet_state.exe-605B8238C7D0F1D128E2E2D7D75ADBCF": { "file_name": "aspnet_state.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_state.exe", "hash_md5": "605B8238C7D0F1D128E2E2D7D75ADBCF", "hash_sha1": "C253368183B09C18DC97261C95F9E623559D137C", "hash_sha256": "1C40AB0928E25EA20065147023B3984E88C959E7B93725FED3B7044F03565319", "hash_sha384": "AA3FA58173BC0215EA0A59BA3176B1319F6E63EEC32BA05549D1AA898517AD22DB81A1C81062BE08E3D7B0E0BBBA2469", "hash_sha512": "FF5AD0BB6CE770F457153238E2E427F3DF0ECAECC8672EF41BE328DD2953AD1639400EFB37B8105CA7B073B98532CDCE489ED0F81007227CBEC875F51ED57792", "hash_ssdeep": "768:3xVsf93Li4Y45z8DrEHVM6qrENCX90kMnMrXIud9BkqWU8pKW:hVa9mTgIH+VMD9G9nYXHTB2t4W", "hash_imp": "10160C4206D23C504CD2301E332CEF11", "hash_pesha1": "C4B72BABA9099B77D136945F088589921282E108", "hash_pe256": "6A4DDABFD12D6F9A7457D322DB924A30C9EE30F7889F6EB9E4ECB8B95056E00C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft ASP.NET State Server", "meta_original_filename": "aspnet_state.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/1c40ab0928e25ea20065147023b3984e88c959e7b93725fed3b7044f03565319/detection", "output": "aspnet_state: it can run only as a service\r\naspnet_state: exiting with error 0x80070057 The parameter is incorrect.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_state.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "aspnet_wp.exe-98C345E7F21D40B5D9102B83BC670DC6": { "file_name": "aspnet_wp.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_wp.exe", "hash_md5": "98C345E7F21D40B5D9102B83BC670DC6", "hash_sha1": "B353761EB187A426962E960037A9532DD15B9A15", "hash_sha256": "B4E267FA56EE9ABA91F5F645B6A62C9B31AC4A8E530843EF2D3A6AF3C4AE5BA9", "hash_sha384": "CEB8F37759C2B20D1C548286A1B25622B2065861416176B9388CF9B1F231FADA91CDB97F06D28AD907BEDC79C3087283", "hash_sha512": "5AC4F462E1BC13393D6699F94C887004AD912B5E1C89C144F78DD42F30C6FD0E1F4A1093BF4F93A7ED92C1C8F0C907B09B3C226D223FB531FBB61388DA7A1F52", "hash_ssdeep": "768:y8EJI+qW2tNpbjq5/Gk11d/8lOPNpWMHP:y8Ead1t7bjbk13pW6", "hash_imp": "86CD395A95E50E0FE5B24C196B560C16", "hash_pesha1": "8E1258060CB5734311C73BFF2EF3097B26A204C4", "hash_pe256": "41BECAA9DB66125E98943445206491537DCB5B4CAE805E7369A4FB9485BFD795", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000187721772155940C709000000000187", "signature_thumbprint": "2485A7AFA98E178CB8F30C9838346B514AEA4769", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "aspnet_wp.exe", "meta_original_filename": "aspnet_wp.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4250.0 built by: NET48REL1LAST_C", "meta_product_version": "4.8.4250.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b4e267fa56ee9aba91f5f645b6a62c9b31ac4a8e530843ef2d3a6af3c4ae5ba9/detection", "output": "Incorrect number of arguments. Note: ASP.NET worker process can not be used interactively. Exiting.\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_wp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "CasPol.exe-914F728C04D3EDDD5FBA59420E74E56B": { "file_name": "CasPol.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\CasPol.exe", "hash_md5": "914F728C04D3EDDD5FBA59420E74E56B", "hash_sha1": "8C68CA3F013C490161C0156EF359AF03594AE5E2", "hash_sha256": "7D3BDB5B7EE9685C7C18C0C3272DA2A593F6C5C326F1EA67F22AAE27C57BA1E6", "hash_sha384": "55418EEBE606C0A468C1F06260B800728DCFDAFAABF471F491898D552E1151C9D095C7B48555573D9D74C945D24A5B03", "hash_sha512": "D7E49B361544BA22A0C66CF097E9D84DB4F3759FBCC20386251CAAC6DA80C591861C1468CB7A102EEE1A1F86C974086EBC61DE4027F9CD22AD06D63550400D6D", "hash_ssdeep": "1536:QSF7vA1hRqHNxxMjlI3ZC+0CtOss6mdcQ6A4vhZ91RKGpQJN:nA1hYPMUs6mdclA4vhNRKG4N", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "4A7C1C23090B04DA96232E70B45477B69EE99721", "hash_pe256": "8C8B7CCDDF81E2812F188AF9E13D3767A7E8B9C59AF27D469BBCB22FD8441640", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework CAS Policy Manager", "meta_original_filename": "caspol.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/7d3bdb5b7ee9685c7c18c0c3272da2a593f6c5c326f1ea67f22aae27c57ba1e6/detection", "output": "Microsoft .NET Framework CasPol 4.8.4084.0\r\nfor Microsoft .NET Framework version 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nWARNING: The .NET Framework does not apply CAS policy by default. Any settings \r\nshown or modified by CasPol will only affect applications that opt into using \r\nCAS policy. \r\n\r\nPlease see http://go.microsoft.com/fwlink/?LinkId=131738 for more information. \r\n\r\n\r\nHelp screen requested\r\n\r\nUsage: caspol <option> <args> ...\r\n\r\ncaspol -m[achine]\r\n Modifier that makes additional commands act on the machine level\r\n\r\ncaspol -u[ser]\r\n Modifier that makes additional commands act on the user level\r\n\r\ncaspol -en[terprise]\r\n Modifier that makes additional commands act on the enterprise level\r\nPress <enter> to continue....\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4484": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_32\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\CasPol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ComSvcConfig.exe-D517F6B93C034F7C1FE68E379C01C417": { "file_name": "ComSvcConfig.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ComSvcConfig.exe", "hash_md5": "D517F6B93C034F7C1FE68E379C01C417", "hash_sha1": "7413AC167789623B396CAAE4C932EF0F891DA07F", "hash_sha256": "1AED983A83F653E4BEBDA5DBAC78E73AD5CBC1FACB1953D72512FA8CD613A074", "hash_sha384": "C97824F7BAAB84B169D6A5D2310541B4D3B9804974D2E41BE562E16B8F67B52ED13BD6B234AD7D0051BB36CED1882E67", "hash_sha512": "D35E81F8BC137F08E9C92E1825B686615595C29D17738E60E76A26025FDC3E75D31E720F66001761C6D8E748DFF545F793029BC61089D33396A8ECA7A8CC3553", "hash_ssdeep": "3072:Jo7sKLcmOLrT0bLOi48nOE3dz/qacuzYPa28Z31qB0Q:isKLcmOLgLln9ZRzQ", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "5C0C2BB73FFB81A0C0864C207DAF41401F07CFCA", "hash_pe256": "AE87A68C86823BFC0B664CFFAF4E77B2787B72F306CF4FE4B4E7A752D528DA7E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ComSvcConfig.exe", "meta_original_filename": "ComSvcConfig.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1aed983a83f653e4bebda5dbac78e73ad5cbc1facb1953d72512fa8cd613a074/detection", "output": "Microsoft (R) COM+ Service Model Integration Configuration Tool\r\n[Microsoft (R) Windows (R) Communication Foundation, Version 4.8.4084.0]\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUtility to configure Service Model integration for COM+ applications\r\n\r\n - USAGE -\r\n ComSvcConfig.exe mode [Options]\r\n\r\n - MODE - \r\n /install \r\n Configure Service Model integration for an application's component interfaces (short form /i)\r\n /uninstall \r\n Uninstall Service Model integration for an application's interfaces (short form /u)\r\n /list \r\n List applications and interfaces that are configured for Service Model integration (short form /l)\r\n\r\n - OPTIONS -\r\n /application:<ApplicationID|ApplicationName>\r\n Specify the COM+ application to configure (short form /a)\r\n /contract:<ClassID|ProgID|*, InterfaceID|InterfaceName|*[.*|{Method1,Method2,Method3}]>\r\n Specify the interface and methods (optional) to be configured (short form /c)\r\n /allowreferences\r\n Specify that object reference parameters are permitted (short form /r)\r\n /hosting:<complus|was>\r\n Specify the hosting process for the Service Model services (short form /h)\r\n /webSite:<WebsiteName>\r\n Specify the web site for web hosting (short form /w)\r\n /webDirectory:<WebDirectoryName>\r\n Specify the virtual directory for web hosting (short form /d)\r\n /mex\r\n Include an additional WS-MetadataExchange endpoint (short form /x)\r\n /id\r\n Displays the application,component and interface information as identifiers (short form /k)\r\n /nologo\r\n Prevent ComSvcConfig from displaying logo (short form /n)\r\n /verbose\r\n Shows all warnings (short form /v)\r\n /? or /help\r\n Display this usage message\r\n\r\n - EXAMPLES -\r\n ComSvcConfig.exe /install /application:TestApp /contract:* /hosting:complus\r\n ComSvcConfig.exe /install /application:TestApp /contract:TestComponent,ITest /hosting:was /webDirectory:testdir /mex\r\n ComSvcConfig.exe /list\r\n ComSvcConfig.exe /list /hosting:complus\r\n ComSvcConfig.exe /list /hosting:was\r\n ComSvcConfig.exe /uninstall /application:OnlineStore /contract:* /hosting:complus\r\n ComSvcConfig.exe /uninstall /application:OnlineStore /contract:* /hosting:was\r\n\r\n", "children": "powershell.exe", "error": "Error: The h option requires that a value be specified.\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ComSvcConfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "csc.exe-EB80BB1CA9B9C7F516FF69AFCFD75B7D": { "file_name": "csc.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\csc.exe", "hash_md5": "EB80BB1CA9B9C7F516FF69AFCFD75B7D", "hash_sha1": "DB402FB24B206C4A378A74FD649C60A413CE5A92", "hash_sha256": "38C407DBF41E99396B78D00DD796930D8838DCB4AF77C3F23BA0E800D1213EBE", "hash_sha384": "6D86F0BC541CE0933FFA8DE8A08F6856AA30FB83E2E8F722B6546886B0F6CEE9354DE469963056E4B14E9A066F8D5A33", "hash_sha512": "B7669D624366D1B2C0D162053DEE91AA2A319DEA90B32E314DD8C8ABC7306035C262454A500DEDA3EF9ED833D409E958CAD759D7925E8E352B499EB86A17E814", "hash_ssdeep": "49152:Mnqqr9wJI6S7RSSon9X6f4IeY0+h1s410I1xIdcxynt:Mnq29lFHon9X5Iddq41Lxry", "hash_imp": "950FB6F62526333E663D35BA72D19DDC", "hash_pesha1": "DCA21409A29C0E1D8AF8B590E83DDD0C13F2DC67", "hash_pe256": "80B1F1DE673F8CFE043E3CDA534313478AB6B72BB7ECAA5D22B83FAFFF6F108E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Visual C# Command Line Compiler", "meta_original_filename": "csc.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/38c407dbf41e99396b78d00dd796930d8838dcb4af77c3f23ba0e800d1213ebe/detection", "output": "Microsoft (R) Visual C# Compiler version 4.8.4084.0\r\r\nfor C# 5\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\r\n\r\r\nThis compiler is provided as part of the Microsoft (R) .NET Framework, but only supports language versions up to C# 5, which is no longer the latest version. For compilers that support newer versions of the C# programming language, see http://go.microsoft.com/fwlink/?LinkID=533240\r\n\r\n Visual C# Compiler Options\r\n\r\n - OUTPUT FILES -\r\n/out:<file> Specify output file name (default: base name of file with main class or first file)\r\n/target:exe Build a console executable (default) (Short form: /t:exe)\r\n/target:winexe Build a Windows executable (Short form: /t:winexe)\r\n/target:library Build a library (Short form: /t:library)\r\n/target:module Build a module that can be added to another assembly (Short form: /t:module)\r\n/target:appcontainerexe Build an Appcontainer executable (Short form: /t:appcontainerexe)\r\n/target:winmdobj Build a Windows Runtime intermediate file that is consumed by WinMDExp (Short form: /t:winmdobj)\r\n/doc:<file> XML Documentation file to generate\r\n/platform:<string> Limit which platforms this code can run on: x86, Itanium, x64, arm, anycpu32bitpreferred, or anycpu. The default is anycpu.\r\n\r\n - INPUT FILES -\r\n/recurse:<wildcard> Include all files in the current directory and subdirectories according to the wildcard specifications\r\n/reference:<alias>=<file> Reference metadata from the specified assembly file using the given alias (Short form: /r)\r\n/reference:<file list> Reference metadata from the specified assembly files (Short form: /r)\r\n/addmodule:<file list> Link the specified modules into this assembly\r\n/link:<file list> Embed metadata from the specified interop assembly files (Short form: /l)\r\n\r\n - RESOURCES -\r\n/win32res:<file> Specify a Win32 resource file (.res)\r\n/win32icon:<file> Use this icon for the output\r\n/win32manifest:<file> Specify a Win32 manifest file (.xml)\r\n/nowin32manifest Do not include the default Win32 manifest\r\n/resource:<resinfo> Embed the specified resource (Short form: /res)\r\n/linkresource:<resinfo> Link the specified resource to this assembly (Short form: /linkres)\r\n Where the resinfo format is <file>[,<string name>[,public|private]]\r\n\r\n - CODE GENERATION -\r\n/debug[+|-] Emit debugging information\r\n/debug:{full|pdbonly} Specify debugging type ('full' is default, and enables attaching a debugger to a running program)\r\n/optimize[+|-] Enable optimizations (Short form: /o)\r\n\r\n - ERRORS AND WARNINGS -\r\n/warnaserror[+|-] Report all warnings as errors\r\n/warnaserror[+|-]:<warn list> Report specific warnings as errors\r\n/warn:<n> Set warning level (0-4) (Short form: /w)\r\n/nowarn:<warn list> Disable specific warning messages\r\n\r\n - LANGUAGE -\r\n/checked[+|-] Generate overflow checks\r\n/unsafe[+|-] Allow 'unsafe' code\r\n/define:<symbol list> Define conditional compilation symbol(s) (Short form: /d)\r\n/langversion:<string> Specify language version mode: ISO-1, ISO-2, 3, 4, 5, or Default\r\n\r\n - SECURITY -\r\n/delaysign[+|-] Delay-sign the assembly using only the public portion of the strong name key\r\n/keyfile:<file> Specify a strong name key file\r\n/keycontainer:<string> Specify a strong name key container\r\n/highentropyva[+|-] Enable high-entropy ASLR\r\n/enforcecodeintegrity[+|-] Enforce code intergrity checks on all inputs to the compiler and enable loading compiled assemblies by other programs that enforce code integrity if the operating system is configured to do so.\r\n\r\n - MISCELLANEOUS -\r\n@<file> Read response file for more options\r\n/help Display this usage message (Short form: /?)\r\n/nologo Suppress compiler copyright message\r\n/noconfig Do not auto include CSC.RSP file\r\n\r\n - ADVANCED -\r\n/baseaddress:<address> Base address for the library to be built\r\n/bugreport:<file> Create a 'Bug Report' file\r\n/codepage:<n> Specify the codepage to use when opening source files\r\n/utf8output Output compiler messages in UTF-8 encoding\r\n/main:<type> Specify the type that contains the entry point (ignore all other possible entry points) (Short form: /m)\r\n/fullpaths Compiler generates fully qualified paths\r\n/filealign:<n> Specify the alignment used for output file sections\r\n/pdb:<file> Specify debug information file name (default: output file name with .pdb extension)\r\n/errorendlocation Output line and column of the end location of each error\r\n/preferreduilang Specify the preferred output language name.\r\n/nostdlib[+|-] Do not reference standard library (mscorlib.dll)\r\n/subsystemversion:<string> Specify subsystem version of this assembly\r\n/lib:<file list> Specify additional directories to search in for references\r\n/errorreport:<string> Specify how to handle internal compiler errors: prompt, send, queue, or none. The default is queue.\r\n/appconfig:<file> Specify an application configuration file containing assembly binding settings\r\n/moduleassemblyname:<string> Name of the assembly which this module will be a part of\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\csc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cvtres.exe-70D838A7DC5B359C3F938A71FAD77DB0": { "file_name": "cvtres.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\cvtres.exe", "hash_md5": "70D838A7DC5B359C3F938A71FAD77DB0", "hash_sha1": "66B83EB16481C334719EED406BC58A3C2B910923", "hash_sha256": "E4DBDBF7888EA96F3F8AA5C4C7F2BCF6E57D724DD8194FE5F35B673C6EF724EA", "hash_sha384": "DA6911C92262C8742B964F82C582D51B4A071C72FD3B5F871DB5F5C3EF928D4F73183EB964CA984AB709E872E11FA249", "hash_sha512": "9C9A945DB5B5E7FF8105BFE74578E6F00B5F707F7C3D8F1F1FB41553A6D0EAB29CEF026E77877A1AD6435FA7BC369141921442E1485F2B0894C6BBCBD7791034", "hash_ssdeep": "768:bINyGPbIriyUAfETlzjpyXcZ0R55GhrdRMJmcBkmcrH+ihBy3kM:3GjyUAfWNkFR5GTMJhkmM+wBxM", "hash_imp": "0FCE7AAB563778C495FB59AA62464473", "hash_pesha1": "5C888E327875860863798A0113E29BBDFF93DBE3", "hash_pe256": "C8FC5A7BD50569E6DE0E25278EC797C3AF36B7BD4F950940CEDE503201EDD1D3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Resource File To COFF Object Conversion Utility", "meta_original_filename": "CVTRES.EXE", "meta_product_name": "Microsoft .NET Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.10.25028.0 built by: VCTOOLSD15RTM", "meta_product_version": "14.10.25028.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e4dbdbf7888ea96f3f8aa5c4c7f2bcf6e57d724dd8194fe5f35b673c6ef724ea/detection", "output": "Microsoft (R) Windows Resource To Object Converter Version 14.10.25028.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nusage: CVTRES [options] [files]\r\n\r\n options:\r\n\r\n /DEFINE:symbol\r\n /FOLDDUPS\r\n /MACHINE:{ARM|EBC|IA64|X64|X86}\r\n /NOLOGO\r\n /OUT:filename\r\n /READONLY\r\n /VERBOSE\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\cvtres.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "DataSvcUtil.exe-DFFCFFD134C4F8540A828A2C7AFE3A7A": { "file_name": "DataSvcUtil.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\DataSvcUtil.exe", "hash_md5": "DFFCFFD134C4F8540A828A2C7AFE3A7A", "hash_sha1": "8337BE23C4C73166D800EBC3096BEA866CFF177A", "hash_sha256": "09165924FF4DA0BC6F58BA60C9EFF597907929B200A4A18FF1978263F5A40631", "hash_sha384": "A82B3EA93F3D563B6861769057BA0FDE9CAAA4801EEEFDB1C81E5DF00DDA18EE3F8D400E1D60823B3815DEC03B518DC3", "hash_sha512": "1F1512C7BBC157CE01891DF8547E3B0C9D05051B3F89A86D8E7764857FD79570FDC34C9F7A7F17B3B34456AF747E19F0F34E8F23A9EFEDD53F058072E233B3DB", "hash_ssdeep": "768:Ysp38EZc9l509m4LdwbKekWXAMdjr8b6Iq8jMgqS/i3G0oqWlP8S42:YG2P5/jb4WXNdn8SHS+GTiS42", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "755A13B035C75A8E7719639E3C6E04DD7E528000", "hash_pe256": "9587B6248DB5ED97F6AC04AF230D3AC7F522AB68C7D47E8129957C63B6355F50", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DataSvcUtil.exe", "meta_original_filename": "DataSvcUtil.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "DataSvcUtil.exe", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0", "meta_product_version": "4.8.4084.0", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/09165924ff4da0bc6f58ba60c9eff597907929b200a4a18ff1978263f5a40631/detection", "output": "DataSvcUtil for Microsoft (R) .NET Framework version 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n DataSvcUtil Options\r\n/in:<file> The file to read the conceptual model from\r\n/out:<file> The file to write the generated object layer to\r\n/language:CSharp Generate code using the C# language\r\n/language:VB Generate code using the VB language\r\n/Version:1.0 Accept CSDL documents tagged with\r\n m:DataServiceVersion=1.0 or lower\r\n/Version:2.0 Accept CSDL documents tagged with\r\n m:DataServiceVersion=2.0 or lower\r\n/DataServiceCollection Generate collections derived from DataServiceCollection/uri:<URL> The URI to read the conceptual model from\r\n/help Display the usage message (short form: /?)\r\n/nologo Suppress copyright message\r\n\r\n Examples\r\nTo generate code from a data service.\r\n DataSvcUtil /out:\"data.cs\" /uri:\"http://localhost/data.svc\"\r\n\r\nTo generate code from a conceptual model file.\r\n DataSvcUtil /out:\"data.cs\" /in:\"file.csdl\"\r\n\r\nTo generate code from a entity design model file.\r\n DataSvcUtil /out:\"data.cs\" /in:\"file.edmx\"\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\DataSvcUtil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dfsvc.exe-B4088F44B80D363902E11F897A7BAC09": { "file_name": "dfsvc.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\dfsvc.exe", "hash_md5": "B4088F44B80D363902E11F897A7BAC09", "hash_sha1": "34698AFDD3E84E7A7555A743EAA9F6971B970D5C", "hash_sha256": "375A75016C4FEDDB43C7EBFE9E78670C7C9FF0753CD8EA59E4CF601EE8624659", "hash_sha384": "8A95125AB19144C613C5FB10908948BD903FC375979E904CA8613CFE6B267F748779A460DA7E65E9046FF0E35F225730", "hash_sha512": "EC34C12B701C37E5FAA911BCD1797F2BED2C5E5D1CA3D5480F5D357688565216C45701C081C870D4EDECC56E40A5C934AA4F14AB0A8CDF6C945452B7D30C24CC", "hash_ssdeep": "384:sNlZPZmW5X16WTFZs2QpBj0HRN7YQHRN7/4lrK9e:svNHX1XU2qWY8M", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "CC60CE5B49B5B1F846DF5EA20DC85F81041B0994", "hash_pe256": "2AC6AA9BC6FDD7EC2E578A0AB18D665201F6F5527E890D0301F69D67931673AE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ClickOnce", "meta_original_filename": "dfsvc.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/375a75016c4feddb43c7ebfe9e78670c7c9ff0753cd8ea59e4cf601ee8624659/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_2932": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Deployment\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Deployment.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\dfsvc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "EdmGen.exe-38BA403812239FD9691F876F2DE3DBB4": { "file_name": "EdmGen.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\EdmGen.exe", "hash_md5": "38BA403812239FD9691F876F2DE3DBB4", "hash_sha1": "14F8BE6630A069EEEF0D6AE6DF725BCFB7508099", "hash_sha256": "83F32D1ED03C408E3387447AC9C527FE36D3AEFC46CEE37177800A7C3470D407", "hash_sha384": "EFC3C9DCFF243F42529E34516C816932705EB894A7714AE16F0C261BEA00F8FB44651E07CBC4433DFB1D23034C97CC9A", "hash_sha512": "55B97F49CBC04101FE7BFDA89504384AC0F1CF2A5AD29375BF9DE844365727E5333A1102B50F6F3BAB69DF11C71F908245C98F522D40B8A2B4468F83815D5DD7", "hash_ssdeep": "768:FWeBB6CB2k0pmBQklZXxRt/wMXfAYhnVTdJ/N6Iq8ZGMavlfILAQgARXqW080lF:l6CB2ksmOkl9xjw9YhtdNkUSfeAdArNM", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "78979905C81D310AA0784E9234BC4FD44822366D", "hash_pe256": "21FFCC6B438208CD1A108057E15CAFE05247F1A4AC032D8C41E45F607D0DD563", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EdmGen.exe", "meta_original_filename": "EdmGen.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "EdmGen.exe", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0", "meta_product_version": "4.8.4084.0", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/83f32d1ed03c408e3387447ac9c527fe36d3aefc46cee37177800a7c3470d407/detection", "output": "EdmGen for Microsoft (R) .NET Framework version 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n EdmGen Options\r\n/mode:EntityClassGeneration Generate objects from a csdl file\r\n/mode:FromSsdlGeneration Generate msl, csdl, and objects from an\r\n ssdl file\r\n/mode:ValidateArtifacts Validate the ssdl, msl, and csdl files\r\n/mode:ViewGeneration Generate mapping views from ssdl, msl,\r\n and csdl files \r\n/mode:FullGeneration Generate ssdl, msl, csdl, and objects\r\n from the database\r\n/project:<string> The base name to be used for all the\r\n artifact files (short form: /p)\r\n/provider:<string> The name of the ADO.NET data provider to be used for ssdl generation (short form: /prov)\r\n/connectionstring:<connection string> The connection string to the database\r\n that you would like to connect to (short form: /c)\r\n/incsdl:<file> The file to read the conceptual model\r\n from\r\n/refcsdl:<file> A csdl file that contains types that the /incsdl file is dependent upon\r\n/inmsl:<file> The file to read the mapping from\r\n/inssdl:<file> The file to read the storage model from\r\n/outcsdl:<file> The file to write the generated\r\n conceptual model to\r\n/outmsl:<file> The file to write the generated mapping\r\n to\r\n/outssdl:<file> The file to write the generated storage\r\n model to\r\n/outobjectlayer:<file> The file to write the generated object\r\n layer to\r\n/outviews:<file> The file to write the pre generated view objects to\r\n/targetversion:<string> The .NET Framework version that will be\r\n used to compile the generated code. The\r\n supported versions are 4 and 4.5.\r\n Defaults to 4.\r\n/language:CSharp Generate code using the C# language\r\n/language:VB Generate code using the Visual Basic\r\n language\r\n/namespace:<string> The namespace name to use for the\r\n conceptual model types\r\n/entitycontainer:<string> The name to use for the EntityContainer\r\n in the conceptual model\r\n/pluralize Automatically pluralize or singularize\r\n entity set name, entity type name, and\r\n navigation property name using English\r\n language rules (short form: /pl)\r\n/SuppressForeignKeyProperties Exclude foreign key properties in entity type definitions. (short form: /nofk)\r\n/help Display the usage message (short form:\r\n /?)\r\n/nologo Suppress copyright message\r\n\r\n Examples\r\nTo generate a full Entity Model from the Northwind sample database.\r\n EdmGen /mode:FullGeneration /project:Northwind /provider:System.Data.SqlClient /connectionstring:\"server=.\\sqlexpress;integrated security=true;\r\n database=northwind\" /targetversion:4.5\r\n\r\nTo generate an Entity Model starting from an ssdl file.\r\n EdmGen /mode:FromSSDLGeneration /inssdl:Northwind.ssdl /project:Northwind\r\n\r\nTo validate an Entity Model.\r\n EdmGen /mode:ValidateArtifacts /inssdl:Northwind.ssdl /inmsl:Northwind.msl\r\n /incsdl:Northwind.csdl\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\EdmGen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ilasm.exe-2B2AE2C9C5D693D2306EF388583B1A03": { "file_name": "ilasm.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe", "hash_md5": "2B2AE2C9C5D693D2306EF388583B1A03", "hash_sha1": "D0D62969D155207B1067C3030B56FCCDB0C6A637", "hash_sha256": "2BD4200161FC147790022F47F90A2E08A2E058BB8269D7D4035D5D46DEFFCE6A", "hash_sha384": "5F0E758657D40996538D7F0D61D6F05E76694ED8D51A7321A84612CFB6309C1356B14690434A191616CD6B4B732EF30A", "hash_sha512": "374718584035AB37AB10AA4C380887C1601632D9EB86E262DFAA91764E7964128B06BAFB62747DA7D7FEB40A3617FA14F656FF2A9CC3DB04E766EACB67B623A0", "hash_ssdeep": "6144:Ius35+ihkV0R0nONM7BwzdqUtZP7mT6TEY8ohydg3h:Iu+kmRKOe9w1tZDmT6TEY8oUg3h", "hash_imp": "75909521ECD39B683082F82FA13EAE5B", "hash_pesha1": "B7667A66635D08BA022A9976D5FC389B0C10BB2C", "hash_pe256": "C0CA2A77A8845B73E9E90C8711554D91B57F0C0B188F0F198D17EB16496477D0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework IL assembler", "meta_original_filename": "ilasm.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2bd4200161fc147790022f47f90a2e08a2e058bb8269d7d4035d5d46deffce6a/detection", "output": "\r\nMicrosoft (R) .NET Framework IL Assembler version 4.8.4084.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\n\r\n\r\nUsage: ilasm [Options] <sourcefile> [Options]\r\n\r\nOptions:\r\n/NOLOGO Don't type the logo\r\n/QUIET Don't report assembly progress\r\n/NOAUTOINHERIT Disable inheriting from System.Object by default\r\n/DLL Compile to .dll\r\n/EXE Compile to .exe (default)\r\n/PDB Create the PDB file without enabling debug info tracking\r\n/APPCONTAINER Create an AppContainer exe or dll\r\n/DEBUG Disable JIT optimization, create PDB file, use sequence points from PDB\r\n/DEBUG=IMPL Disable JIT optimization, create PDB file, use implicit sequence points\r\n/DEBUG=OPT Enable JIT optimization, create PDB file, use implicit sequence points\r\n/OPTIMIZE Optimize long instructions to short\r\n/FOLD Fold the identical method bodies into one\r\n/CLOCK Measure and report compilation times\r\n/RESOURCE=<res_file> Link the specified resource file (*.res) \r\n\t\t\tinto resulting .exe or .dll\r\n/OUTPUT=<targetfile> Compile to file with specified name \r\n\t\t\t(user must provide extension, if any)\r\n/KEY=<keyfile> Compile with strong signature \r\n\t\t\t(<keyfile> contains private key)\r\n/KEY=@<keysource> Compile with strong signature \r\n\t\t\t(<keysource> is the private key source name)\r\n/INCLUDE=<path> Set path to search for #include'd files\r\n/SUBSYSTEM=<int> Set Subsystem value in the NT Optional header\r\n/SSVER=<int>.<int> Set Subsystem version number in the NT Optional header\r\n/FLAGS=<int> Set CLR ImageFlags value in the CLR header\r\n/ALIGNMENT=<int> Set FileAlignment value in the NT Optional header\r\n/BASE=<int> Set ImageBase value in the NT Optional header (max 2GB for 32-bit images)\r\n/STACK=<int> Set SizeOfStackReserve value in the NT Optional header\r\n/MDV=<version_string> Set Metadata version string\r\n/MSV=<int>.<int> Set Metadata stream version (<major>.<minor>)\r\n/PE64 Create a 64bit image (PE32+)\r\n/HIGHENTROPYVA Set High Entropy Virtual Address capable PE32+ images (default for /APPCONTAINER)\r\n/NOCORSTUB Suppress generation of CORExeMain stub\r\n/STRIPRELOC Indicate that no base relocations are needed\r\n/ITANIUM Target processor: Intel Itanium\r\n/X64 Target processor: 64bit AMD processor\r\n/ARM Target processor: ARM processor\r\n/32BITPREFERRED Create a 32BitPreferred image (PE32)\r\n/ENC=<file> Create Edit-and-Continue deltas from specified source file\r\n\r\nKey may be '-' or '/'\r\nOptions are recognized by first 3 characters\r\nDefault source file extension is .il\r\n\r\nTarget defaults:\r\n/PE64 => /PE64 /ITANIUM\r\n/ITANIUM => /PE64 /ITANIUM\r\n/X64 => /PE64 /X64\r\n\r\n", "error": "Error : Invalid Option: --help\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "InstallUtil.exe-5D4073B2EB6D217C19F2B22F21BF8D57": { "file_name": "InstallUtil.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe", "hash_md5": "5D4073B2EB6D217C19F2B22F21BF8D57", "hash_sha1": "F0209900FBF08D004B886A0B3BA33EA2B0BF9DA8", "hash_sha256": "AC1A3F21FCC88F9CEE7BF51581EAFBA24CC76C924F0821DEB2AFDF1080DDF3D3", "hash_sha384": "3E9AE9529ADFA9761BD67D369ADFEC7C48221AEF5DCEBE187B3A1D5B9CDB520A0BC5FAE2C45F5AF96004735DE229743F", "hash_sha512": "9AC94880684933BA3407CDC135ABC3047543436567AF14CD9269C4ADC5A6535DB7B867D6DE0D6238A21B94E69F9890DBB5739155871A624520623A7E56872159", "hash_ssdeep": "384:qtpFVLK0MsihB9VKS7xdgl6KJ9Yl6dnPU3SERztmbqCJstdMardz/JikPZ+RPZTg:GBMs2SqdSZ6Iq8BxTfqWR8h7ukP", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "793F60036EE1B811BC1AAEC4257E0191D9B381FF", "hash_pe256": "29BCDA3CF8EB64A4634E5BCFB1949B734D27F5A9652A207F75E6DFA468AF4394", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Framework installation utility", "meta_original_filename": "InstallUtil.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ac1a3f21fcc88f9cee7bf51581eafba24cc76c924f0821deb2afdf1080ddf3d3/detection", "output": "Microsoft (R) .NET Framework Installation utility Version 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: InstallUtil [/u | /uninstall] [option [...]] assembly [[option [...]] assembly] [...]]\r\n\r\nInstallUtil executes the installers in each given assembly.\r\nIf the /u or /uninstall switch is specified, it uninstalls\r\nthe assemblies, otherwise it installs them. Unlike other\r\noptions, /u applies to all assemblies, regardless of where it\r\nappears on the command line.\r\n\r\nInstallation is done in a transactioned way: If one of the\r\nassemblies fails to install, the installations of all other\r\nassemblies are rolled back. Uninstall is not transactioned.\r\n\r\nOptions take the form /switch=[value]. Any option that occurs\r\nbefore the name of an assembly will apply to that assembly's\r\ninstallation. Options are cumulative but overridable - options\r\nspecified for one assembly will apply to the next as well unless\r\nthe option is specified with a new value. The default for all\r\noptions is empty or false unless otherwise specified.\r\n\r\nOptions recognized:\r\n\r\nOptions for installing any assembly:\r\n/AssemblyName\r\n The assembly parameter will be interpreted as an assembly name (Name,\r\n Locale, PublicKeyToken, Version). The default is to interpret the\r\n assembly parameter as the filename of the assembly on disk.\r\n\r\n/LogFile=[filename]\r\n File to write progress to. If empty, do not write log. Default\r\n is <assemblyname>.InstallLog\r\n\r\n/LogToConsole={true|false}\r\n If false, suppresses output to the console.\r\n\r\n/ShowCallStack\r\n If an exception occurs at any point during installation, the call\r\n stack will be printed to the log.\r\n\r\n/InstallStateDir=[directoryname]\r\n Directory in which the .InstallState file will be stored. Default\r\n is the directory of the assembly.\r\n\r\n\r\nIndividual installers used within an assembly may recognize other\r\noptions. To learn about these options, run InstallUtil with the paths\r\nof the assemblies on the command line along with the /? or /help option.\r\n\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "jsc.exe-94C8E57A80DFCA2482DEDB87B93D4FD9": { "file_name": "jsc.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\jsc.exe", "hash_md5": "94C8E57A80DFCA2482DEDB87B93D4FD9", "hash_sha1": "5729E6C7D2F5AB760F0093B9D44F8AC0F876A803", "hash_sha256": "39E87F0EDCDD15582CFEFDFAB1975AADD2C7CA1E3A5F07B1146CE3206F401BB5", "hash_sha384": "C5A46056673F0C19F547678539B818C6EC50E261B418CBF78DC377649D244C223C700846E43CFD2D21CF43418A498D0F", "hash_sha512": "1798A3607B2B94732B52DE51D2748C86F9453343B6D8A417E98E65DDB38E9198CDCB2F45BF60823CB429B312466B28C5103C7588F2C4EF69FA27BFDB4F4C67DC", "hash_ssdeep": "768:DeSZaMT79n3DwU8ZCM2o1QG/n29WERqqJaqW/P8+4W:DeoaElzEZ2fG/nmkK4s+4W", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "8234926D09B2F79069027A5A37DF2B63FC397B06", "hash_pe256": "814BBB177F256F4BBEF2E2542176A62E6BA6F07D5138B147762FF4BAB4866779", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "jsc.exe", "meta_original_filename": "jsc.exe", "meta_product_name": "Microsoft .NET Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.8.4084.0 built by: NET48REL1", "meta_product_version": "14.0.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/39e87f0edcdd15582cfefdfab1975aadd2c7ca1e3a5f07b1146ce3206f401bb5/detection", "output": "Microsoft (R) JScript Compiler version 14.00.4084\r\nfor Microsoft (R) .NET Framework version 4.0.30319\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\njsc [options] <source files> [[options] <source files>...]\r\n\r\n JScript Compiler Options\r\n\r\n - OUTPUT FILES -\r\n /out:<file> Specify name of binary output file\r\n /t[arget]:exe Create a console application (default)\r\n /t[arget]:winexe Create a windows application\r\n /t[arget]:library Create a library assembly\r\n /platform:<platform> Limit which platforms this code can run on; must be x86, Itanium, x64, or any cpu, which is the default\r\n\r\n - INPUT FILES -\r\n /autoref[+|-] Automatically reference assemblies based on imported namespaces and fully-qualified names (on by default)\r\n /lib:<path> Specify additional directories to search in for references\r\n /r[eference]:<file list> Reference metadata from the specified assembly file\r\n <file list>: <assembly name>[;<assembly name>...]\r\n\r\n - RESOURCES -\r\n /win32res:<file> Specifies Win32 resource file (.res)\r\n /res[ource]:<info> Embeds the specified resource\r\n <info>: <filename>[,<name>[,public|private]]\r\n /linkres[ource]:<info> Links the specified resource to this assembly\r\n <info>: <filename>[,<name>[,public|private]]\r\n\r\n - CODE GENERATION -\r\n /debug[+|-] Emit debugging information\r\n /fast[+|-] Disable language features to allow better code generation\r\n /warnaserror[+|-] Treat warnings as errors\r\n /w[arn]:<level> Set warning level (0-4)\r\n\r\n - MISCELLANEOUS -\r\n @<filename> Read response file for more options\r\n /? Display help\r\n /help Display help\r\n /d[efine]:<symbols> Define conditional compilation symbol(s)\r\n /nologo Do not display compiler copyright banner\r\n /print[+|-] Provide print() function\r\n\r\n - ADVANCED -\r\n /codepage:<id> Use the specified code page ID to open source files\r\n /lcid:<id> Use the specified lcid for messages and default code page\r\n /nostdlib[+|-] Do not import standard library (mscorlib.dll) and change autoref default to off\r\n /utf8output[+|-] Emit compiler output in UTF-8 character encoding\r\n /versionsafe[+|-] Specify default for members not marked 'override' or 'hide'\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\jsc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Microsoft.Workflow.Compiler.exe-FC9DE0484A269CE25C09B5B1D25139D1": { "file_name": "Microsoft.Workflow.Compiler.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Microsoft.Workflow.Compiler.exe", "hash_md5": "FC9DE0484A269CE25C09B5B1D25139D1", "hash_sha1": "930D4F60CF9699282AEEE123EBC1CFC9D99B3254", "hash_sha256": "698BE205BC3344D60A2D746D11A80174887B07FDE82A01CFBB835A555064C9D9", "hash_sha384": "2684EE1FA534B5D6E1F94C42CC28BFC5877FD3DE61609C381A58D907A0A8C90E444281EFED21D420991FEC0FFDA0DD0F", "hash_sha512": "D479431FDF8C1AA1C4D83AD69BADE35E5DCCA39CEB4FAA2998F20B7D2C7B53F4FC4548DAB9B3B26B177EB2779187651F2EED91A2256A60A5E198D4195C0EF80A", "hash_ssdeep": "384:Sr2jKFw1MHBYWaqlcrFC0xqehld2+Opm2CEWcHwW0FdTsuQpBj0HRN7pvQHRN7TP:Sr2jmHHoqclpPwakuPTfqWF8+Fh", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "F84F304E88D8702AA66152DC54076BF86B570BE5", "hash_pe256": "3AF6C4613EF373063C69CDED23126423B2F2B49E991A10F8EA060F077B9D9C3D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft.Workflow.Compiler.exe", "meta_original_filename": "Microsoft.Workflow.Compiler.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/698be205bc3344d60a2d746d11a80174887b07fde82a01cfbb835a555064c9d9/detection", "error": "\nUnhandled Exception: System.ArgumentException: The compiler process was not given arguments or was given an invalid set of arguments. When invoking the process the expected arguments are the path to the compiler input and the path to where the output should be placed.\r\nParameter name: args\r\n at Microsoft.Workflow.Compiler.Program.Main(String[] args)\n", "children": [ "conhost.exe", "Microsoft.Workflow.Compiler.exe", "WerFault.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4256": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Workflow.ComponentModel\\v4.0_4.0.0.0__31bf3856ad364e35\\System.Workflow.ComponentModel.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Microsoft.Workflow.Compiler.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mscorsvw.exe-8EA79E659DA869468746ABE850D67996": { "file_name": "mscorsvw.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe", "hash_md5": "8EA79E659DA869468746ABE850D67996", "hash_sha1": "C4D483AC89670539592D1B73733C25FB4FE3F574", "hash_sha256": "7D8D8696ACD1815316174FBA563F2E2AD0BE3B5E9C6A28E237F9131A41067169", "hash_sha384": "5C59CA2F6894DEC2EBA74B28D97BD842AC5816DD976B852588B0BCF8CE0432A9BBA045B03652BA692355BD9EAE9C1B8B", "hash_sha512": "F7D62FFA3F0CD1E3E8A163EE2D724854F749ECE3169180F573CA683F2641519E8C7FC4308E0E4CC362A78F40640649D2F251FF0E35CD1E1710F810D79B7512B5", "hash_ssdeep": "3072:5AiZiUHXe/Is2d9AKxIL3AHI+8YI/o1pGa7YTq:f9bV9sL3AiYI/8pGa7YW", "hash_imp": "924E0F5D11C8B561E5182D325FAB1C75", "hash_pesha1": "7CC9582DB528384E68F5F4ECB8958E38A33ADCBA", "hash_pe256": "9EFACF82747833017C8E65177A1605EB7EB5C7844823465324891337F59B35EF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Runtime Optimization Service", "meta_original_filename": "mscorsvw.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7d8d8696acd1815316174fba563f2e2ad0be3b5e9c6a28e237f9131a41067169/detection", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ngen.exe-45F125B592C34161732BFAE855C17628": { "file_name": "ngen.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe", "hash_md5": "45F125B592C34161732BFAE855C17628", "hash_sha1": "959EAB169395284F92717E7785CA9C7A2936CC60", "hash_sha256": "C555CF03BCBC780F8A39CBF8B95254FD3798A703BA71B84AF84EF33E36D0D761", "hash_sha384": "F6F90EC78EEFB9E0B67DD75DF912788D812A3A2E46FF8358F77500F0C438C7771FF7B00AB6F4A300ACAD35B8B844A43B", "hash_sha512": "B31E5EAD08F82F70618198DBEA2312822258CA8F58441A02B96F474623F8AEFE16CFF8A4AE75EC53E514283B308FCC8602C623D748B47075F54CCD8DAE41B9E7", "hash_ssdeep": "3072:OxJajVR3IHq658DCCOHuN4hIdpEGaYjs27MlZ:OnajVj6581jLzTssM3", "hash_imp": "05EC6CF51708237D25182181F0BEADEE", "hash_pesha1": "3452F853658646B494A12FB8A7A2BA9A52BF28E5", "hash_pe256": "1FBE058D58B06CD5C479CD623B4EDCF2E8D06F3A4EC638CD0D944DFB9FA23277", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Common Language Runtime native compiler", "meta_original_filename": "ngen.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c555cf03bcbc780f8a39cbf8b95254fd3798a703ba71b84af84ef33e36d0d761/detection", "output": "Microsoft (R) CLR Native Image Generator - Version 4.8.4084.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nError: Unrecognized option --help\r\nWARNING: This syntax is deprecated or you mis-typed your command. Run \"ngen /?\" to display a list of the currently supported parameters.\r\n\r\nUsage: ngen <action> [args] [/nologo] [/silent] [/verbose]\r\n ngen /? or /help\r\n\r\n /nologo - Prevents displaying of logo\r\n /silent - Prevents displaying of success messages\r\n /verbose - Displays verbose output for debugging\r\n\r\nActions:\r\n ngen install <assembly name> [scenarios] [config] [/queue[:[1|2|3]]\r\n Generate native images for an assembly and its dependencies\r\n and install them in the Native Images Cache\r\n If /queue is specified compilation job is queued up. If a priority \r\n is not specified, the default priority used is 3.\r\n ngen uninstall <assembly name> [scenarios] [config]\r\n Delete the native images of an assembly and its dependencies from\r\n the Native Images Cache.\r\n ngen update [/queue]\r\n Update native images that have become invalid\r\n If /queue is specified compilation jobs are queued up.\r\n ngen display [assembly name]\r\n Display the ngen state\r\n ngen executeQueuedItems [1|2|3]\r\n Executes queued compilation jobs.\r\n If priority is not specified all queued compilation jobs are done.\r\n If priority is specified compilation jobs with greater or equal\r\n priority than the specified are done. (Short form: eqi)\r\n ngen queue [pause|continue|status]\r\n Allows the user to pause and continue the NGen Service, and to\r\n query its status.\r\n ngen createPDB <path to native image> <directory to store PDB>\r\n [/lines [<search path for managed PDB>] ]\r\n Generates a native PDB file for a native image that was previously\r\n generated by NGen. The generated PDB file includes names of methods\r\n and ranges of IP offsets that map to those methods.\r\n If /lines is specified, then additional information is written to the\r\n PDB to map ranges of IP offsets to source file line numbers. /lines\r\n requires access to the managed PDB generated by the language compiler.\r\n <search path for managed PDB> may optionally be specified to help NGen\r\n find the managed PDB\r\n\r\nScenarios:\r\n /Debug - Generate images that can be used under a debugger\r\n /Profile - Generate images that can be used under a profiler\r\n /NoDependencies - Generate the minimal number of native images\r\n required by this scenario\r\n\r\nConfig:\r\n /ExeConfig:<path to exe> - Use the configuration of the specified\r\n executable assembly\r\n /AppBase:<path to appbase directory> - Use the specified directory as\r\n the appbase\r\n\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ngentask.exe-C6CE045CA7809169A017F73D45C21462": { "file_name": "ngentask.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngentask.exe", "hash_md5": "C6CE045CA7809169A017F73D45C21462", "hash_sha1": "7D2504133D8235E91C2E98355C4F223CDF500D4D", "hash_sha256": "41019BD2DFF58ECA53A25FFCE26E487AF0B693C3D305E67A0D4E8F8CD60C6EF6", "hash_sha384": "93CA8EF603A19035B6CEE21E2A40396C3E5A18366FF9C3D852081D7E072DBDC15E074CE69741346041ED51D83FC07DAC", "hash_sha512": "CB42D614F4E543BE090E2D09F0F6C28ECD346B8EA2CA06BA10389A735A23792BD4D4EC189F94C8DCDC0B35707B36BA0DF811C18B7608F8A2CC2B8D429242B205", "hash_ssdeep": "1536:wHbMtCb5ZAPx89Z9CL8nfQLKc8fnFdTK/9duoF:4UCbgx8rc8YLn8fFA/V", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "C103EDCE2651473DC771440727D999DB39D206F5", "hash_pe256": "FAA79FDC4C23D0F6A1E3E9B45783AD95AAF7F8784E86A79A29FBBA830FDC4C84", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework optimization service", "meta_original_filename": "NGenTask.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/41019bd2dff58eca53a25ffce26e487af0b693c3d305e67a0d4e8f8cd60c6ef6/detection", "error": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngentask.exe [options...]\r\n This tool reads from the usage log data produced by the runtime, and triggers NGen to occur.\r\n /RuntimeWide - Parse the fusion stream of the usage logs instead of the App stream. Task runs in machine-wide mode.\r\n /Critical - Runs as a critical idle task.\r\n", "output": "NGen Task starting, command line: \"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngentask.exe\" --help\r\nUnrecognized command line option --help\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngentask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RegAsm.exe-0D5DF43AF2916F47D00C1573797C1A13": { "file_name": "RegAsm.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegAsm.exe", "hash_md5": "0D5DF43AF2916F47D00C1573797C1A13", "hash_sha1": "230AB5559E806574D26B4C20847C368ED55483B0", "hash_sha256": "C066AEE7AA3AA83F763EBC5541DAA266ED6C648FBFFCDE0D836A13B221BB2ADC", "hash_sha384": "3B4D3715DC2C5CC65579F673250BB355D5B9590ECAB1BE1E2F845090E5482CEC6C05D9DD7167B39FEA785B1850EFA498", "hash_sha512": "F96CF9E1890746B12DAF839A6D0F16F062B72C1B8A40439F96583F242980F10F867720232A6FA0F7D4D7AC0A7A6143981A5A130D6417EA98B181447134C7CFE2", "hash_ssdeep": "768:X8XcJiMjm2ieHlPyCsSuJbn8dBhFwlSMF6Iq8KSYDKbQ22qWqO8w1R:rYMaNylPYSAb8dBnsHsPDKbQBqTY", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "045ADCAA09C5A7BE1AB28595CDEF3EB76103573A", "hash_pe256": "1D9DF24BC73C37A5CD72E6E4090260B968EBD50C4A74035C02851F46A118B515", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Assembly Registration Utility", "meta_original_filename": "RegAsm.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/c066aee7aa3aa83f763ebc5541daa266ed6c648fbffcde0d836a13b221bb2adc/detection", "output": "Microsoft .NET Framework Assembly Registration Utility version 4.8.4084.0\r\nfor Microsoft .NET Framework version 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nSyntax: RegAsm AssemblyName [Options]\r\nOptions:\r\n /unregister Unregister types\r\n /tlb[:FileName] Export the assembly to the specified type library\r\n and register it\r\n /regfile[:FileName] Generate a reg file with the specified name\r\n instead of registering the types. This option\r\n cannot be used with the /u or /tlb options\r\n /codebase Set the code base in the registry\r\n /registered Only refer to already registered type libraries\r\n /asmpath:Directory Look for assembly references here\r\n /nologo Prevents RegAsm from displaying logo\r\n /silent Silent mode. Prevents displaying of success messages\r\n /verbose Displays extra information\r\n /? or /help Display this usage message\r\n", "error": "RegAsm : error RA0000 : Failed to load 'C:\\Users\\user\\help' because it is not a valid .NET assembly\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegAsm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RegSvcs.exe-9D352BC46709F0CB5EC974633A0C3C94": { "file_name": "RegSvcs.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe", "hash_md5": "9D352BC46709F0CB5EC974633A0C3C94", "hash_sha1": "1969771B2F022F9A86D77AC4D4D239BECDF08D07", "hash_sha256": "2C1EEB7097023C784C2BD040A2005A5070ED6F3A4ABF13929377A9E39FAB1390", "hash_sha384": "AAE75E0B7A687B971D7F3C9694934F26243E79FE1487DBB8E7A255096694D7E8CF48E186F4C97832E1B0F5ADCDA09490", "hash_sha512": "13C714244EC56BEEB202279E4109D59C2A43C3CF29F90A374A751C04FD472B45228CA5A0178F41109ED863DBD34E0879E4A21F5E38AE3D89559C57E6BE990A9B", "hash_ssdeep": "768:4BbSoy+SdIBf0k2dsjYg6Iq8S1GYqWH8BR:noOIBf0ddsjY/ZGyc7", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "4FB62C3E5D8C0DE365BC6580A84DA17568B1A18A", "hash_pe256": "7E9CDAB4247511B6F2B3B360D0F2677688955F3093092F99659FD13EB371D4DD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Services Installation Utility", "meta_original_filename": "RegSvcs.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/2c1eeb7097023c784c2bd040a2005a5070ed6f3a4abf13929377a9e39fab1390/detection", "output": "Microsoft (R) .NET Framework Services Installation Utility Version 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nInvalid option: '--help'\r\n\nUSAGE: regsvcs.exe [options] AssemblyName\r\nOptions:\r\n /? or /help Display this usage message.\r\n /fc Find or create target application (default).\r\n /c Create target application, error if it already exists.\r\n /exapp Expect an existing application.\r\n /tlb:<tlbfile> Filename for the exported type library.\r\n /appname:<name> Use the specified name for the target application.\r\n /parname:<name> Use the specified name or id for the target partition.\r\n /extlb Use an existing type library.\r\n /reconfig Reconfigure existing target application (default).\r\n /noreconfig Don't reconfigure existing target application.\r\n /u Uninstall target application.\r\n /nologo Suppress logo output.\r\n /quiet Suppress logo output and success output.\r\n /componly Configure components only, no methods or interfaces.\r\n /appdir:<path> Set application root directory to specified path.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ServiceModelReg.exe-1132E8E6A3C7B72E290E07BD48EB08E7": { "file_name": "ServiceModelReg.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ServiceModelReg.exe", "hash_md5": "1132E8E6A3C7B72E290E07BD48EB08E7", "hash_sha1": "4AFA5141D45586FA4EAB89F275B002401BD567A4", "hash_sha256": "2B7E4DD728F186AD6F6E55F53F863A560006773CC97D17AC847A305B29F96782", "hash_sha384": "E5EFF017ED364CC6ACD532F4560720AB1C94A23A0CB27010FA886E417FE6420E1391D8F4F6E4CDD5CF21AD38A1E337E5", "hash_sha512": "3EAB6F2B44E68E5DC0BAB9DF9BCD4657A460A74BFA88338A01C22C26119382AB7936D74B4F47BC49D5B8003FB3D6B7B8139FF71F9A3581224AE26031C8D39715", "hash_ssdeep": "3072:5l8RCa6cA+LExtZ6bQJP/FS6UYwQHbKv4CpxQC2mCm1/ql70bN6qtoh5rK0UBk+L:0b6rL/w0g60QHGJQ74ahwk+QA", "hash_imp": "2396F3556CB4EAD513113A1FA46E57C3", "hash_pesha1": "713B6DBC36CA1278D5B47A5F685FB3DC8EC33E44", "hash_pe256": "7A5C78C46A1944AB63916AF0A5C6A31EDDDBEF34D4BB012DB9DCD5C840E58799", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WCF Generic Command for Vista Setup", "meta_original_filename": "ServiceModelReg.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/2b7e4dd728f186ad6f6e55f53f863a560006773cc97d17ac847a305b29f96782/detection", "output": "[Error]Unknown switch '--help'.Microsoft (R) WCF/WF registration tool version 4.5.0.0 \r\nCopyright (c) Microsoft Corporation. All rights reserved. \r\n \r\nAdministration utility that manages the installation and uninstallation of \r\nWCF and WF components on a single machine. \r\n\r\nUsage: \r\n ServiceModelReg.exe [(-ia|-ua|-r)|((-i|-u) -c:<command>)] [-v|-q] [-nologo] [-h] \r\n -ia \r\n Install all components \r\n -ua \r\n Uninstall all components \r\n -r \r\n Repairs all components \r\n -i \r\n Install components specified with -c \r\n -u \r\n Uninstall components specified with -c \r\n -c:<component> \r\n Install/uninstall a component: \r\n httpnamespace - HTTP namespace reservation \r\n tcpportsharing - TCP port sharing service \r\n tcpactivation - TCP activation service \r\n namedpipeactivation - Named pipe activation service \r\n msmqactivation - MSMQ activation service \r\n etw - ETW event tracing manifests (Windows Vista or later) \r\n Can be used to install several components at the same time \r\n -q \r\n Quiet mode (only error logging) \r\n -v \r\n Verbose mode \r\n -nologo \r\n Suppress the copyright and banner message \r\n -h \r\n Displays this help text. \r\n \r\nExamples: \r\n ServiceModelReg.exe -ia \r\n Installs all components \r\n ServiceModelReg.exe -i -c:httpnamespace -c:etw \r\n Installs HTTP namespace reservation and ETW manifests \r\n ServiceModelReg.exe -u -c:etw \r\n Uninstalls ETW manifests \r\n ServiceModelReg.exe -r \r\n Repairs the installation\r\n[Error]Switch '-c' requires a component to be specified for installation or uninstallation. Please specify which components to install or uninstall.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ServiceModelReg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SMSvcHost.exe-B9D455C60292DF5FCB064834CA5802AA": { "file_name": "SMSvcHost.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SMSvcHost.exe", "hash_md5": "B9D455C60292DF5FCB064834CA5802AA", "hash_sha1": "09AFEFF9CB54ED9620DBE6D04E7D418423BDFFAD", "hash_sha256": "75DCE4E5FA08CCEAF4D3D30FE8E26903FCDD14CC852E820F63B40F374C706DBD", "hash_sha384": "F09AFB8E4B8B6A0867B4365469116C4619D2DA6C8734F05C1C76263647965EFE2E2F6841DEBCEB74FAD5EDE7D8379776", "hash_sha512": "7413017C84316267CBB147562F70FA3AD0BE493872FC9ED7AE17CF1813AAF3349C7656AD8A4F467C37DF613A081BEC5C2762740842492C7A92699FDAA0620C50", "hash_ssdeep": "3072:E3Cpwak5J5ywaza+zDEJivKkuaj9/wwbK8L8G7LfU7IIHxICfUI/E1lcFH8:oCpGhTUua7bK8oYfU7IIHxHR/Enic", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "02C9277F61864302DE767C670CB398D118741614", "hash_pe256": "CE81CE348DAD8D3BF723FD2C24F0AE0F79F69C94F2EEEEBBD5F0E922B076E8B0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SMSvcHost.exe", "meta_original_filename": "SMSvcHost.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/75dce4e5fa08cceaf4d3d30fe8e26903fcdd14cc852e820f63b40f374c706dbd/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_6652": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.ServiceProcess\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.ServiceProcess.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.ServiceModel\\v4.0_4.0.0.0__b77a5c561934e089\\System.ServiceModel.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.ServiceModel.Internals\\v4.0_4.0.0.0__31bf3856ad364e35\\System.ServiceModel.Internals.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SMSvcHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ], "runtime_window_title": "Windows Service Start Failure" }, "vbc.exe-0A7608DB01CAE07792CEA95E792AA866": { "file_name": "vbc.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe", "hash_md5": "0A7608DB01CAE07792CEA95E792AA866", "hash_sha1": "71DFF876E4D5EDB6CEA78FEE7AA15845D4950E24", "hash_sha256": "C16336AB32195B08C1678220FBE0256FEE865F623E2B32FCFA4D9825FD68977E", "hash_sha384": "049291992D3D37046548513A278BCAAA23C0790E2AA35BD29A580C71D79B9AFF9003B995EA82C1FA917848DF11028DD8", "hash_sha512": "990A6FA1B8ADB6727B1DCD8931AD84FDCB556533B78F896A71EAE2A7E3AE3222E4B8EFAA4B629CED2841211750E0D8A75DDD546A983C2E586918DD8BA4E0DC42", "hash_ssdeep": "49152:S6F5PsH1IaspqACp//9NqqAJN77F29ZJOx2uc:jw16psLqqAJN77F29jOx27", "hash_imp": "1460E2E6D7F8ECA4240B7C78FA619D15", "hash_pesha1": "EC37F19EAD9F15E77719725C8D2ECFFBC04FD487", "hash_pe256": "33FD318B74C56B7653FE068D490047F1FF8FCDBB2CCFDC3F2E029548D54836CC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Visual Basic Command Line Compiler", "meta_original_filename": "vbc.exe", "meta_product_name": "Microsoft .NET Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.8.4084.0", "meta_product_version": "14.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/c16336ab32195b08c1678220fbe0256fee865f623e2b32fcfa4d9825fd68977e/detection", "output": "Microsoft (R) Visual Basic Compiler version 14.8.4084\nfor Visual Basic 2012\r\nCopyright (c) Microsoft Corporation. All rights reserved.\n\nThis compiler is provided as part of the Microsoft (R) .NET Framework, but only supports language versions up to Visual Basic 2012, which is no longer the latest version. For compilers that support newer versions of the Visual Basic programming language, see http://go.microsoft.com/fwlink/?LinkID=533241\r\n\r\n Visual Basic Compiler Options\r\n\r\n - OUTPUT FILE -\r\n/out:<file> Specifies the output file name.\r\n/target:exe Create a console application (default). (Short form: /t)\r\n/target:winexe Create a Windows application.\r\n/target:library Create a library assembly.\r\n/target:module Create a module that can be added to an assembly.\r\n/target:appcontainerexe Create a Windows application that runs in AppContainer.\r\n/target:winmdobj Create a Windows Metadata intermediate file\r\n/doc[+|-] Generates XML documentation file.\r\n/doc:<file> Generates XML documentation file to <file>.\r\n\r\n - INPUT FILES -\r\n/addmodule:<file_list> Reference metadata from the specified modules.\r\n/link:<file_list> Embed metadata from the specified interop assembly. (Short form: /l)\r\n/recurse:<wildcard> Include all files in the current directory and subdirectories according to the wildcard specifications.\r\n/reference:<file_list> Reference metadata from the specified assembly. (Short form: /r)\r\n\r\n - RESOURCES -\r\n/linkresource:<resinfo> Links the specified file as an external assembly resource. resinfo:<file>[,<name>[,public|private]] (Short form: /linkres)\r\n/nowin32manifest The default manifest should not be embedded in the manifest section of the output PE.\r\n/resource:<resinfo> Adds the specified file as an embedded assembly resource. resinfo:<file>[,<name>[,public|private]] (Short form: /res)\r\n/win32icon:<file> Specifies a Win32 icon file (.ico) for the default Win32 resources.\r\n/win32manifest:<file> The provided file is embedded in the manifest section of the output PE.\r\n/win32resource:<file> Specifies a Win32 resource file (.res).\r\n\r\n - CODE GENERATION -\r\n/optimize[+|-] Enable optimizations.\r\n/removeintchecks[+|-] Remove integer checks. Default off.\r\n/debug[+|-] Emit debugging information.\r\n/debug:full Emit full debugging information (default).\r\n/debug:pdbonly Emit PDB file only.\r\n\r\n - ERRORS AND WARNINGS -\r\n/nowarn Disable all warnings.\r\n/nowarn:<number_list> Disable a list of individual warnings.\r\n/warnaserror[+|-] Treat all warnings as errors.\r\n/warnaserror[+|-]:<number_list> Treat a list of warnings as errors.\r\n\r\n - LANGUAGE -\r\n/define:<symbol_list> Declare global conditional compilation symbol(s). symbol_list:name=value,... (Short form: /d)\r\n/imports:<import_list> Declare global Imports for namespaces in referenced metadata files. import_list:namespace,...\r\n/langversion:<number> Specify language version: 9|10|11.\r\n/optionexplicit[+|-] Require explicit declaration of variables.\r\n/optioninfer[+|-] Allow type inference of variables.\r\n/rootnamespace:<string> Specifies the root Namespace for all type declarations.\r\n/optionstrict[+|-] Enforce strict language semantics.\r\n/optionstrict:custom Warn when strict language semantics are not respected.\r\n/optioncompare:binary Specifies binary-style string comparisons. This is the default.\r\n/optioncompare:text Specifies text-style string comparisons.\r\n\r\n - MISCELLANEOUS -\r\n/help Display this usage message. (Short form: /?)\r\n/noconfig Do not auto-include VBC.RSP file.\r\n/nologo Do not display compiler copyright banner.\r\n/quiet Quiet output mode.\r\n/verbose Display verbose messages.\r\n\r\n - ADVANCED -\r\n/baseaddress:<number> The base address for a library or module (hex).\r\n/bugreport:<file> Create bug report file.\r\n/codepage:<number> Specifies the codepage to use when opening source files.\r\n/delaysign[+|-] Delay-sign the assembly using only the public portion of the strong name key.\r\n/errorreport:<string> Specifies how to handle internal compiler errors; must be prompt, send, none, or queue (default).\r\n/filealign:<number> Specify the alignment used for output file sections.\r\n/highentropyva[+|-] Enable high-entropy ASLR.\r\n/keycontainer:<string> Specifies a strong name key container.\r\n/keyfile:<file> Specifies a strong name key file.\r\n/libpath:<path_list> List of directories to search for metadata references. (Semi-colon delimited.)\r\n/main:<class> Specifies the Class or Module that contains Sub Main. It can also be a Class that inherits from System.Windows.Forms.Form. (Short form: /m)\r\n/moduleassemblyname:<string> Name of the assembly which this module will be a part of.\r\n/netcf Target the .NET Compact Framework.\r\n/nostdlib Do not reference standard libraries (system.dll and VBC.RSP file).\r\n/platform:<string> Limit which platforms this code can run on; must be x86, x64, Itanium, arm, AnyCPU32BitPreferred or anycpu (default).\r\n/sdkpath:<path> Location of the .NET Framework SDK directory (mscorlib.dll).\r\n/subsystemversion:<version> Specify subsystem version of the output PE. version:<number>[.<number>]\r\n/utf8output[+|-] Emit compiler output in UTF8 character encoding.\r\n@<file> Insert command-line settings from a text file.\r\n/vbruntime[+|-|*] Compile with/without the default Visual Basic runtime.\r\n/vbruntime:<file> Compile with the alternate Visual Basic runtime in <file>.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WsatConfig.exe-D7F8F9FE510F05C919F07DEEF56B8B3E": { "file_name": "WsatConfig.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\WsatConfig.exe", "hash_md5": "D7F8F9FE510F05C919F07DEEF56B8B3E", "hash_sha1": "C462EF992AAFFC75CC7AC3661369224DBFFA4F13", "hash_sha256": "1D2E773836CFFB7F8529A56B51B7AA385C8109EBC8BFD4D3EBC8818CD6D8C67C", "hash_sha384": "F38BDB5E100840D73107CEE586291BF38B39E38CCF031B103064217C35B636E1CA21BBD4819BB5CFF3A8EB152B6FDF8B", "hash_sha512": "5D4F233FAE99AA09BBC46561F2E16F4EE486A7C7DFE2A64CC20B9E7B539FF52BF29FCC45179D4D99B8BC0D75E451A9BF1D903A1B84A62AD603861CCBF0759C82", "hash_ssdeep": "3072:W95GnK+au5ef9xXMnbLUpdrsHvhoIfshxitOCq:mQdx5q9pOPh/fYiDq", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "1A3830961583B89523C424835A72DC507B538E2C", "hash_pe256": "A0BF75E9B36C2CC3EA0A29397B833FAEE2DABB0212CC1B1FC8919E6E1A384779", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MB Version update tool", "meta_original_filename": "WsatConfig.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/1d2e773836cffb7f8529a56b51b7aa385c8109ebc8bfd4d3ebc8818cd6d8c67c/detection", "output": "\r\nMicrosoft (R) WS-AtomicTransaction Configuration Utility\r\n[Microsoft (R) Windows (R) Communication Foundation, Version 4.8.4084.0]\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nUtility to configure WS-AtomicTransaction network support\r\n\r\n -- OPTIONS --\r\n -network:{enable|disable} - Enables or disables the WS-AtomicTransaction network support\r\n\r\n -port:<portNum> - Sets the HTTPS port for WS-AtomicTransaction\r\n\r\n -endpointCert:{machine|<thumb>| - Uses the machine certificate or another local endpoint certificate specified by thumbprint or Issuer\\SubjectName pair. Use {EMPTY} for the subject name if it's empty.\r\n \"Issuer\\SubjectName\"} \r\n\r\n -accounts:<account,> - Specifies the comma-separated list of accounts that can participate\r\n\r\n -accountsCerts:{<thumb>| - Specifies the comma-separated list of thumbprint or Issuer\\SubjectName identifiers for the certificates that can participate. Use {EMPTY} for the subject name if it's empty.\r\n \"Issuer\\SubjectName\",} \r\n\r\n -virtualServer:<virtualServer> - Specifies the DTC resource cluster name\r\n\r\n -timeout:<sec> - Specifies the default outgoing timeout in seconds\r\n\r\n -maxTimeout:<sec> - Specifies the maximum incoming timeout in seconds\r\n\r\n -traceLevel:{Off|Error|Critical| - Sets the trace level\r\n Warning|Information| \r\n Verbose|All} \r\n\r\n -traceActivity:{enable|disable} - Enables or disables the tracing of activity events\r\n\r\n -traceProp:{enable|disable} - Enables or disables the tracing of propagation events\r\n\r\n -tracePII:{enable|disable} - Enables or disables the tracing of personally identifiable information\r\n\r\n -show - Shows the current WS-AtomicTransaction protocol settings\r\n\r\n -restart - Restarts MSDTC to make changes active immediately. If not specified, the changes will take effect when MSDTC is next started.\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\WsatConfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AppLaunch.exe-E9C3EC13A9C77B393692D748D8EB83CE": { "file_name": "AppLaunch.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\AppLaunch.exe", "hash_md5": "E9C3EC13A9C77B393692D748D8EB83CE", "hash_sha1": "729E44CE32BC0709642EB79C46BD8C3E9F91232B", "hash_sha256": "3682F6C9357E653150B1B7A96C30347E1ABFA368A356DB7C65A4C805F4EEB25E", "hash_sha384": "7D4EA6A4630F0BFDABF2141F1D3D8E3089B6C4D7FDE447761837F930B055D43325315F49D3B54EE66B6FB0D233CAE5D6", "hash_sha512": "F1BDCC7CDED610B6821B8A322546864495DBD371EBED3FBE683BC3E3751ED57C6ECFDFE8FE701C77D9E1EE698406CB9D1C7B4E15B079F89A430895343AB51E79", "hash_ssdeep": "3072:39hN6RaYBxrDkKn52BNm8ZOx74CGgHUl:39HCdNgKn5ANmZGgHe", "hash_imp": "3CAA34EC21943714C9039790CA60D6CC", "hash_pesha1": "0E667DD43E39479E331F8E18EEDEF5699B6B8BB2", "hash_pe256": "16A1617E99349058DDF667381E03222A02421DF08B3BA2ED19BE6E9A467A5C39", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET ClickOnce Launch Utility", "meta_original_filename": "applaunch.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/3682f6c9357e653150b1b7a96c30347e1abfa368a356db7c65a4c805f4eeb25e/detection", "output": "\r\nMicrosoft (R) .NET ClickOnce Launch Utility Version 4.0.30319.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nError: Unrecognized option --help\r\nUsage: applaunch /activate <appFullName> [/manifests <manifestsPaths>] [/parameters <activationArguments>] [/nologo]\r\n applaunch /? or /help\r\n /nologo - Prevents displaying of logo\r\n Options:\r\n -activate <appFullName>\r\n Activates the application with the specified full name identity.\r\n -manifests <manifestPaths>\r\n Optional list of manifest paths to be used during the activation.\r\n -parameters <activationArguments>\r\n Optional list of activation arguments to be used during the activation.\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\AppLaunch.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\SYSTEM32\\mscoree.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\ucrtbase_clr0400.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\SYSTEM32\\VCRUNTIME140_CLR0400.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "aspnet_compiler.exe-DF5419B32657D2896514B6A1D041FE08": { "file_name": "aspnet_compiler.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe", "hash_md5": "DF5419B32657D2896514B6A1D041FE08", "hash_sha1": "EAE192043F75CA972697C3B1875988BEBD66F713", "hash_sha256": "9ED0AA0A40C864F65FF867FD6B8491467786CE1BC60FD1E55F300A0FAE5A77B4", "hash_sha384": "6C26ACC88CBF1EB9F1432FD02E1CFFC3D1B405B1D7CAA5A81302D2488BB4366476069D34C59B1F0A7218707C9E32632A", "hash_sha512": "F1A7A409C99942B39060D327BBC2F0B7CF600E8C3D8E60164AE27A78E1A16C07DE58872B8864A0783D71CCAD5800C02ADE0AC14954B30A75A6B5C8D4B1FCD560", "hash_ssdeep": "768:TF9E8FLSs2Zokf85d9ITV6Iq8Fnqf7PxoqHpqWSd8sa8:TfE6hkfOd9IT86lqnSesa8", "hash_imp": "n/a", "hash_pesha1": "705BB671A4C19169099E27ED41D9958C49E8B5D8", "hash_pe256": "79FBE5C1ABE4D3EA8985062A5508D299FE8E6EF56A483FB28506741E2BC6C987", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "aspnet_compiler.exe", "meta_original_filename": "aspnet_compiler.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/9ed0aa0a40c864f65ff867fd6b8491467786ce1bc60fd1e55f300a0fae5a77b4/detection", "output": "Microsoft (R) ASP.NET Compilation Tool version 4.8.4084.0\r\nUtility to precompile an ASP.NET application\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage:\r\naspnet_compiler [-?] [-m metabasePath | -v virtualPath [-p physicalDir]]\r\n [[-u] [-f] [-d] [-fixednames] targetDir] [-c]\r\n [-x excludeVirtualPath [...]]\r\n [[-keyfile file | -keycontainer container]\r\n [-aptca] [-delaySign]]\r\n [-errorstack]\r\n\r\n-? Prints this help text.\r\n-m The full IIS metabase path of the application. This switch cannot\r\n be combined with the -v or -p switches.\r\n-v The virtual path of the application to be compiled (e.g.\r\n \"/MyApp\"). If -p is specified, the physical path is used to\r\n locate the application. Otherwise, the IIS metabase is used, and\r\n the application is assumed to be in the default site (under\r\n \"/LM/W3SVC/1/Root\"). This switch cannot be combined with the -m\r\n switch.\r\n-p The physical path of the application to be compiled. If -p is\r\n missing, the IIS metabase is used to locate the app. This switch\r\n must be combined with -v.\r\n-u If specified, the precompiled application is updatable.\r\n-f Overwrites the target directory if it already exists. Existing\r\n contents are lost.\r\n-d If specified, the debug information is emitted during\r\n compilation.\r\ntargetDir The physical path to which the application is compiled. If not\r\n specified, the application is precompiled in-place.\r\n-c If specified, the precompiled application is fully rebuilt. Any\r\n previously compiled components will be re-compiled. This option\r\n is always enabled when targetDir is specified.\r\n-x The virtual path of a directory that should be excluded from\r\n precompilation. This switch can be used multiple times.\r\n-keyfile The physical path to the strong name key file.\r\n-keycontainer Specifies a strong name key container.\r\n-aptca If specified, the strong-name assembly will allow partially\r\n trusted callers.\r\n-delaysign If specified, the assembly is not fully signed when created. \r\n-fixednames If specified, the compiled assemblies will be given fixed names.\r\n-nologo Suppress compiler copyright message.\r\n-errorstack Shows extra debugging information that can help debug certain\r\n conditions.\r\n\r\nExamples:\r\n\r\nThe following two commands are equivalent, and rely on the IIS metabase. The\r\ncompiled application is deployed to c:\\MyTarget:\r\n aspnet_compiler -m /LM/W3SVC/1/Root/MyApp c:\\MyTarget\r\n aspnet_compiler -v /MyApp c:\\MyTarget\r\n\r\nThe following command compiles the application /MyApp in-place. The effect is\r\nthat no more compilations will be needed when HTTP requests are sent to it:\r\n aspnet_compiler -v /MyApp\r\n\r\nThe following command does *not* rely on the IIS metabase, as it explicitly\r\nspecifies the physical source directory of the application:\r\n aspnet_compiler -v /MyApp -p c:\\myapp c:\\MyTarget\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "aspnet_regbrowsers.exe-542F3F799FC63406802309E9D6415BA7": { "file_name": "aspnet_regbrowsers.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_regbrowsers.exe", "hash_md5": "542F3F799FC63406802309E9D6415BA7", "hash_sha1": "090C90AA3F450EAC6003EFF04883548D2E53905D", "hash_sha256": "CE6E8C88B125BD80D8E67384349ACE2140EF90DD59F702BC00555C19774EFFAE", "hash_sha384": "11AE1C6734C5C52B92FFB662B3696779C8AAD7B06FC1ADE63770CC22C96616997FE7D1F16565D61648034C713D04F0AA", "hash_sha512": "611665A0ED40D4A0A90F6198C063EA9D8207F0B772606B285CCCDC422A5287FD29BA9A783BA8F035279775D54E98E7579AA8E3111FA826448D8F2048344F5806", "hash_ssdeep": "384:yNAPwxaH7K/7YyoodyJ8Ood0GAKJ9Yl6dnPU3SERztmbqCJstdMardz/JikPZ+1q:IYGIm//oAKodRT6Iq812++gTfqWwJJ8w", "hash_imp": "n/a", "hash_pesha1": "F1F1B4748DD70437FF18EC872449FFDF86159D59", "hash_pe256": "11A1C10BAD89C56A40357B99471E0BCA8DA9EB6089A8267C69F825A6EF028234", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "aspnet_regbrowsers.exe", "meta_original_filename": "aspnet_regbrowsers.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/ce6e8c88b125bd80d8e67384349ace2140ef90dd59f702bc00555c19774effae/detection", "output": "Microsoft (R) ASP.NET Browser Registration Tool version 4.8.4084.0\r\nUtility to compile ASP.Net browser files.\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\nUsage:\r\naspnet_regbrowsers [-? | -i | -u]\r\n-? Prints this help text.\r\n-i Create and install the runtime browser capabilities assembly.\r\n-u Uninstall the browser capabilities assembly from the Global Assembly Cache.\r\n The default runtime browser capabilities will be used instead.\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_regbrowsers.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "aspnet_regiis.exe-06138ABFF3EEE34172D46C49BFD48978": { "file_name": "aspnet_regiis.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_regiis.exe", "hash_md5": "06138ABFF3EEE34172D46C49BFD48978", "hash_sha1": "A91AC3BF8967B40A5DC128DEC75AC269661FA725", "hash_sha256": "038F55A19B3EB3B4B5C6433B96F2E0BC1BDA40B071820F16AC3B5C74C56E308D", "hash_sha384": "A677FAB1CFE3AF0AF7F0DC30214DF6B90CC5B2A916AA7BE8A297C48AA1EB5D47621C433C936FBC3019389AB67DCA08F6", "hash_sha512": "277E0C8B6468AAFC052F582ACA0A8E7920A1656ACA14014C0835A46AEAEF46A2127BE35027F9DB763D84AC9F5F14F758AD63F477F16965CA9695CD5BCA9AA60F", "hash_ssdeep": "768:SzlGxPcOQomCr1rNDuKiA1d2qWwK8t6TXEJq:89grFuKt1Cwnt6V", "hash_imp": "6D868D8CB1EC5BC1E6BE42EF04B1146C", "hash_pesha1": "D384C748B3846FDDC95B6E4784934705A7CB7C20", "hash_pe256": "5877C4905776E01863A9B4A60FE73800F70494F3B47264D6CF936E9BCD23B5DA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "aspnet_regiis.exe", "meta_original_filename": "aspnet_regiis.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/038f55a19b3eb3b4b5c6433b96f2e0bc1bda40b071820f16ac3b5c74c56e308d/detection", "output": "Microsoft (R) ASP.NET RegIIS version 4.0.30319.0\r\nAdministration utility to install and uninstall ASP.NET on the local machine.\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n\r\r\n\r -- ASP.NET REGISTRATION OPTIONS --\r\n\r\r\n\r-i Install this version of ASP.NET and update IIS\r\n\r configuration at the root level to use this version of\r\n\r ASP.Net.\r\n\r\r\n\r-ir Install this version of ASP.NET, register only. Do not\r\n\r change any web applications to use this version.\r\n\r\r\n\r-iru Install this version of ASP.NET. If there are any existing\r\n\r applications that uses ASP.NET, it will not change IIS\r\n\r configuration to use this version.\r\n\r\r\n\r-enable When -enable is specified with -i, -ir or -r, ASP.NET will\r\n\r be enabled in the IIS security console (IIS 6.0 or later).\r\n\r\r\n\r-disable When -disable is specified with -i, -ir or -r, ASP.NET will\r\n\r be disabled in the IIS security console (IIS 6.0 or later).\r\n\r\r\n\r-s <path> Install scriptmaps for this version at the specified path,\r\n\r recursively.\r\n\r E.g. aspnet_regiis.exe -s W3SVC/1/ROOT/SampleApp1\r\n\r\r\n\r-sn <path> Install scriptmaps for this version at the specified path,\r\n\r non-recursively.\r\n\r\r\n\r-r Install this version of ASP.NET and update scriptmaps at\r\n\r the IIS metabase root and for all scriptmaps below the\r\n\r root. Existing scriptmaps are upgraded to this version\r\n\r regardless of the original versions.\r\n\r\r\n\r-u Uninstall this version of ASP.NET. Existing scriptmaps to\r\n\r this version are remapped to highest remaining version of\r\n\r ASP.NET installed on the machine.\r\n\r\r\n\r-ua Uninstall all versions of ASP.NET on the machine.\r\n\r\r\n\r-k <path> Remove all scriptmaps to any version of ASP.NET from the\r\n\r specified path, recursively (not supported on Windows Vista\r\n\r and higher versions).\r\n\r E.g. aspnet_regiis.exe -k W3SVC/1/ROOT/SampleApp1\r\n\r\r\n\r-kn <path> Remove all scriptmaps to any version ASP.NET from the\r\n\r specified path, non-recursively (not supported on Windows\r\n\r Vista and higher versions).\r\n\r\r\n\r-lv List all versions of ASP.NET that are installed on the\r\n\r machine, with status and installation path.\r\n\r\r\n\r-lk List all the path of all IIS metabase keys where ASP.NET is\r\n\r scriptmapped, together with the version. Keys that inherit\r\n\r ASP.NET scriptmaps from a parent key will not be displayed\r\n\r (not supported on Windows Vista and higher versions).\r\n\r\r\n\r-c Install the client side scripts for this version to the\r\n\r aspnet_client subdirectory of each IIS site directory.\r\n\r\r\n\r-e Remove the client side scripts for this version from the\r\n\r aspnet_client subdirectory of each IIS site directory.\r\n\r\r\n\r-ea Remove the client side scripts for all versions from the\r\n\r aspnet_client subdirectory of each IIS site directory.\r\n\r\r\n\r-ga <user> Grant the specified user or group access to the IIS\r\n\r metabase and other directories used by ASP.NET.\r\n\r\r\n\r\r\n\r\r\n\r -- CONFIGURATION ENCRYPTION OPTIONS --\r\n\r\r\n\r-pe section Encrypt the configuration section. Optional arguments:\r\n\r [-prov provider] Use this provider to encrypt.\r\n\r [-app virtual-path] Encrypt at this virtual path. Virtual\r\n\r path must begin with a forward slash. If it is '/', then it\r\n\r refers to the root of the site. If -app is not specified,\r\n\r the root web.config will be encrypted.\r\n\r [-site site-name-or-ID] The site of the virtual path\r\n\r specified in -app. If not specified, the default web site\r\n\r will be used.\r\n\r [-location sub-path] Location sub path.\r\n\r [-pkm] Encrypt/decrypt the machine.config instead of\r\n\r web.config.\r\n\r\r\n\r-pd section Decrypt the configuration section. Optional arguments:\r\n\r [-app virtual-path] Decrypt at this virtual path. Virtual\r\n\r path must begin with a forward slash. If it is '/', then it\r\n\r refers to the root of the site. If -app is not specified,\r\n\r the root web.config will be decrypted.\r\n\r [-site site-name-or-ID] The site of the virtual path\r\n\r specified in -app. If not specified, the default web site\r\n\r will be used.\r\n\r [-location sub-path] Location sub path.\r\n\r [-pkm] Encrypt/decrypt the machine.config instead of\r\n\r web.config.\r\n\r\r\n\r-pef section web-app-physical-dir\r\n\r Encrypt the configuration section. Optional arguments:\r\n\r [-prov provider] Use this provider to encrypt.\r\n\r\r\n\r-pdf section web-app-physical-dir\r\n\r Decrypt the configuration section.\r\n\r\r\n\r-pc container Create an RSA keypair in ContainerName. Optional arguments:\r\n\r [-size key-size] Key-size. Default is 1024.\r\n\r [-pku] User container instead of machine container.\r\n\r [-exp] Make the private keys exportable.\r\n\r [-csp provider] Csp Provider to use.\r\n\r\r\n\r-pz container Delete the ContainerName. Optional arguments:\r\n\r [-pku] User container instead of machine container.\r\n\r\r\n\r-pi container file Import an RSA keypair from the Xml file. Optional\r\n\r arguments:\r\n\r [-pku] User container instead of machine container.\r\n\r [-exp] Create exportable keys.\r\n\r [-csp provider] Csp Provider to use.\r\n\r\r\n\r-px container file Export an RSA keypair to the Xml file. Optional arguments:\r\n\r [-pku] User container instead of machine container.\r\n\r [-pri] Include private keys.\r\n\r [-csp provider] Csp Provider to use.\r\n\r\r\n\r-pa container account\r\n\r Add access for the account to the container. Arguments:\r\n\r [-pku] User container instead of machine container.\r\n\r [-csp provider] Csp Provider to use.\r\n\r [-full] Add full access (default is Read access).\r\n\r\r\n\r-pr container account\r\n\r Remove access for the account from the container.\r\n\r Arguments:\r\n\r [-pku] User container instead of machine container.\r\n\r [-csp provider] Csp Provider to use.\r\n\r\r\n\r\r\n\r\r\n\r -- CONFIGURATION REMOTE ACCESS OPTIONS --\r\n\r\r\n\r-config+ Enable remote access of configuration.\r\n\r\r\n\r-config- Disable remote access of configuration.\r\n\r\r\n\r", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_regiis.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "aspnet_regsql.exe-1FE651917E404A12B3B50001219034DE": { "file_name": "aspnet_regsql.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_regsql.exe", "hash_md5": "1FE651917E404A12B3B50001219034DE", "hash_sha1": "783C80B9F0839C5349835A7510B94B03EC2BEF6D", "hash_sha256": "BA5780A2EF7092DCD5EEB2625077FE558605983AB8486B2D7D0E3040630511AA", "hash_sha384": "5D5F8F75408A022F8B790679A51D7685FBF716F8B0EEEEDEAB3A6FBAFCC07652B53D6E57FAFAF74C29AD5F4C55418E94", "hash_sha512": "A9BC3C25077EFFE8589CDAB176D80D383EDEFBF0C1843BFF254BA96E536F5BF07C730881D303CEEFC26ADFFD0423ED0DA2585E68F9C23C4C93000AB3348C46F3", "hash_ssdeep": "3072:N3am4bGr4tH1wK2cESdyXQuyAKFAJoXGDaFmt:gT2Lg3eBGe", "hash_imp": "n/a", "hash_pesha1": "B46C510528E6FB8F560A37F73B3A099D382A4997", "hash_pe256": "26795EAA64ED8BDA9FA834C286040C13E8B703A617D256391798003FEE00871F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "aspnet_regsql.exe", "meta_original_filename": "aspnet_regsql.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/ba5780a2ef7092dcd5eeb2625077fe558605983ab8486b2d7d0e3040630511aa/detection", "output": "Microsoft (R) ASP.NET SQL Registration Tool version 4.8.4084.0\r\nAdministrative utility to install and uninstall ASP.NET features on a SQL server.\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n\r\nThe argument '--help' is invalid.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_regsql.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "aspnet_state.exe-E521372979F4F1AB092B6FC18EAF76F6": { "file_name": "aspnet_state.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_state.exe", "hash_md5": "E521372979F4F1AB092B6FC18EAF76F6", "hash_sha1": "18BE1C2484FFD93C484DDAD41DA03EDA7393DBCF", "hash_sha256": "64FAE007652F3F416E3F700BD4C80BFCA19B5076ABB231A549167A2C7D9A5A1A", "hash_sha384": "EDBE10DAEA1287091FE5971BFB2F676292875F5D4727892D4843E4B0DB20DD9D82BAB93FF8246D902C2E09FDF6FCC2FC", "hash_sha512": "717FDB230F7DC05DF6246BA3425DD25FDF0342AD872BF0D2E9E7ECDEF19BDA1152F6256FD0BBE61F8F1BD00C5E6F34844A5E0680C755F7620CEF0C18D20F9BAE", "hash_ssdeep": "768:rJOFJ7WuHTZCXX14M2RY2yg9dh3Ne2j8XkNKNmdrpqWQ8:QJWuHT+Qy2h35j4YKArHh", "hash_imp": "322F1C1FF4870EE88AF8AF80B98138A2", "hash_pesha1": "5C7A7CCEF55A302E410334E3A35E0E0303C77EF3", "hash_pe256": "5BC0852C3B211C8403864A499137E90A2B23AB8789F866D3C0E8E9B4169FDB9A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft ASP.NET State Server", "meta_original_filename": "aspnet_state.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/64fae007652f3f416e3f700bd4c80bfca19b5076abb231a549167a2c7d9a5a1a/detection", "output": "aspnet_state: it can run only as a service\r\naspnet_state: exiting with error 0x80070057 The parameter is incorrect.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_state.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "aspnet_wp.exe-1078E68E344E6C4CAFF47162BEACBF6E": { "file_name": "aspnet_wp.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_wp.exe", "hash_md5": "1078E68E344E6C4CAFF47162BEACBF6E", "hash_sha1": "A5378A61DB8C8D6EC528917D6154E4818D25DAD2", "hash_sha256": "83F96B69B125E09B4529AA449C643FD8E821A4E5187210A07C911836E6BAA3DC", "hash_sha384": "2D13A1D2F2EF8FF28B02DC21211A0E581832AB9188DFB56079FE0123ED533DCA8AACC704B25C622F50EE2CE07403DC8A", "hash_sha512": "1A0CDF03BA459280F0ED5197B022E126256179A1120186A2F22272349AE18C18BE2F62C2287915EE5B3C44CB42D2CC1079F2FE50AABC729B57ED89592D6811D4", "hash_ssdeep": "768:GjdwXPJ7EY8pcuOjkZaEMQyT8EZsWOjYRPrvyOAEfK:GjY7cRO4a0A8EC0rqOxi", "hash_imp": "E324A30FAAD4376F03EBC5A20675AB47", "hash_pesha1": "D8EA5F69544E332511B6AE92175C65FDE9BAE7B1", "hash_pe256": "4A9B46D26BD0253360F6DB33BEA11D3EF600D4097FD30ECB4D0BBECC2DF95C40", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000188AF52D6B9926DE8F9000000000188", "signature_thumbprint": "A5BCE29A2944105E0E25B626120264BB03499052", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "aspnet_wp.exe", "meta_original_filename": "aspnet_wp.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4250.0 built by: NET48REL1LAST_C", "meta_product_version": "4.8.4250.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/83f96b69b125e09b4529aa449c643fd8e821a4e5187210a07c911836e6baa3dc/detection", "output": "Incorrect number of arguments. Note: ASP.NET worker process can not be used interactively. Exiting.\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_wp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "CasPol.exe-C91C5994E9C0F1690C296B57DFCD2EDF": { "file_name": "CasPol.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\CasPol.exe", "hash_md5": "C91C5994E9C0F1690C296B57DFCD2EDF", "hash_sha1": "40A49427B3A4A39CD56110E51FE9D7B4CB361E18", "hash_sha256": "123CE330093975473F3266E08FFD3E993D9DBA8E60B554F85DC5AD5D17EE537D", "hash_sha384": "118FFF88C9F9C13D85ACF4C5A3E9BD42B420881F78DCD76871279CC3AF64448121E800B11C23E0D1E148CE28044C5DB5", "hash_sha512": "E1E635805779C816459E1D687F69F8B68171A8EDBDE92BB6B46C667B1AAED955DC0FB6792CA23E1524A473C8D163DE0F12EBDD980DC646C4A68D56FD7341C74E", "hash_ssdeep": "1536:USF7vA1hRqHNxxMjlI3ZC+av1MZBtOss6mdcQ6A4vvZ91RCGKA5h/42:7A1hYPMF1WJs6mdclA4vvNRrKAr42", "hash_imp": "n/a", "hash_pesha1": "39EDA79001A5DCC6B22E515FF71AACE22FC3FD5E", "hash_pe256": "543ABFEAB288876A44944B4B2A2EE7C81590C8E5C4903FE5C6BD64D43DC0ED70", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework CAS Policy Manager", "meta_original_filename": "caspol.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/123ce330093975473f3266e08ffd3e993d9dba8e60b554f85dc5ad5d17ee537d/detection", "output": "Microsoft .NET Framework CasPol 4.8.4084.0\r\nfor Microsoft .NET Framework version 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nWARNING: The .NET Framework does not apply CAS policy by default. Any settings \r\nshown or modified by CasPol will only affect applications that opt into using \r\nCAS policy. \r\n\r\nPlease see http://go.microsoft.com/fwlink/?LinkId=131738 for more information. \r\n\r\n\r\nHelp screen requested\r\n\r\nUsage: caspol <option> <args> ...\r\n\r\ncaspol -m[achine]\r\n Modifier that makes additional commands act on the machine level\r\n\r\ncaspol -u[ser]\r\n Modifier that makes additional commands act on the user level\r\n\r\ncaspol -en[terprise]\r\n Modifier that makes additional commands act on the enterprise level\r\nPress <enter> to continue....\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_7728": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\CasPol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "csc.exe-F65B029562077B648A6A5F6A1AA76A66": { "file_name": "csc.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe", "hash_md5": "F65B029562077B648A6A5F6A1AA76A66", "hash_sha1": "528973416456C780051889CA1709510B6BF73370", "hash_sha256": "4A6D0864E19C0368A47217C129B075DDDF61A6A262388F9D21045D82F3423ED7", "hash_sha384": "D82B3A803450C7171E92B99C9F408D086F08250E012C5E0E612CFAC17BFBF1DD53110067D3BC4B8E191F7D2BBB0522D1", "hash_sha512": "5C3B01B025AF8A872EAF6D1F5B98B918E277D1BE328BAD387E09C49687219A2F222C07012E1BCB31C3ED262B7E2256BEEA36F358FBAF6C0159583985AA5AFE69", "hash_ssdeep": "49152:xMSyAKnixTRPjSI3TyYHTEtlC5nPebVm+PW/I8YfSkLd2OQFNcgc73Ps:7VxT+QoB8YfScnQFNX43Ps", "hash_imp": "EE1E569AD02AA1F7AECA80AC0601D80D", "hash_pesha1": "6AB2E92B2724CBD53886384B9049D52040A221C4", "hash_pe256": "EEC59E3CFCF63DC6D233406A1447E9FE2B406706E1AA06B6BAEC4B0660896648", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Visual C# Command Line Compiler", "meta_original_filename": "csc.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4a6d0864e19c0368a47217c129b075dddf61a6a262388f9d21045d82f3423ed7/detection", "output": "Microsoft (R) Visual C# Compiler version 4.8.4084.0\r\r\nfor C# 5\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\r\n\r\r\nThis compiler is provided as part of the Microsoft (R) .NET Framework, but only supports language versions up to C# 5, which is no longer the latest version. For compilers that support newer versions of the C# programming language, see http://go.microsoft.com/fwlink/?LinkID=533240\r\n\r\n Visual C# Compiler Options\r\n\r\n - OUTPUT FILES -\r\n/out:<file> Specify output file name (default: base name of file with main class or first file)\r\n/target:exe Build a console executable (default) (Short form: /t:exe)\r\n/target:winexe Build a Windows executable (Short form: /t:winexe)\r\n/target:library Build a library (Short form: /t:library)\r\n/target:module Build a module that can be added to another assembly (Short form: /t:module)\r\n/target:appcontainerexe Build an Appcontainer executable (Short form: /t:appcontainerexe)\r\n/target:winmdobj Build a Windows Runtime intermediate file that is consumed by WinMDExp (Short form: /t:winmdobj)\r\n/doc:<file> XML Documentation file to generate\r\n/platform:<string> Limit which platforms this code can run on: x86, Itanium, x64, arm, anycpu32bitpreferred, or anycpu. The default is anycpu.\r\n\r\n - INPUT FILES -\r\n/recurse:<wildcard> Include all files in the current directory and subdirectories according to the wildcard specifications\r\n/reference:<alias>=<file> Reference metadata from the specified assembly file using the given alias (Short form: /r)\r\n/reference:<file list> Reference metadata from the specified assembly files (Short form: /r)\r\n/addmodule:<file list> Link the specified modules into this assembly\r\n/link:<file list> Embed metadata from the specified interop assembly files (Short form: /l)\r\n\r\n - RESOURCES -\r\n/win32res:<file> Specify a Win32 resource file (.res)\r\n/win32icon:<file> Use this icon for the output\r\n/win32manifest:<file> Specify a Win32 manifest file (.xml)\r\n/nowin32manifest Do not include the default Win32 manifest\r\n/resource:<resinfo> Embed the specified resource (Short form: /res)\r\n/linkresource:<resinfo> Link the specified resource to this assembly (Short form: /linkres)\r\n Where the resinfo format is <file>[,<string name>[,public|private]]\r\n\r\n - CODE GENERATION -\r\n/debug[+|-] Emit debugging information\r\n/debug:{full|pdbonly} Specify debugging type ('full' is default, and enables attaching a debugger to a running program)\r\n/optimize[+|-] Enable optimizations (Short form: /o)\r\n\r\n - ERRORS AND WARNINGS -\r\n/warnaserror[+|-] Report all warnings as errors\r\n/warnaserror[+|-]:<warn list> Report specific warnings as errors\r\n/warn:<n> Set warning level (0-4) (Short form: /w)\r\n/nowarn:<warn list> Disable specific warning messages\r\n\r\n - LANGUAGE -\r\n/checked[+|-] Generate overflow checks\r\n/unsafe[+|-] Allow 'unsafe' code\r\n/define:<symbol list> Define conditional compilation symbol(s) (Short form: /d)\r\n/langversion:<string> Specify language version mode: ISO-1, ISO-2, 3, 4, 5, or Default\r\n\r\n - SECURITY -\r\n/delaysign[+|-] Delay-sign the assembly using only the public portion of the strong name key\r\n/keyfile:<file> Specify a strong name key file\r\n/keycontainer:<string> Specify a strong name key container\r\n/highentropyva[+|-] Enable high-entropy ASLR\r\n/enforcecodeintegrity[+|-] Enforce code intergrity checks on all inputs to the compiler and enable loading compiled assemblies by other programs that enforce code integrity if the operating system is configured to do so.\r\n\r\n - MISCELLANEOUS -\r\n@<file> Read response file for more options\r\n/help Display this usage message (Short form: /?)\r\n/nologo Suppress compiler copyright message\r\n/noconfig Do not auto include CSC.RSP file\r\n\r\n - ADVANCED -\r\n/baseaddress:<address> Base address for the library to be built\r\n/bugreport:<file> Create a 'Bug Report' file\r\n/codepage:<n> Specify the codepage to use when opening source files\r\n/utf8output Output compiler messages in UTF-8 encoding\r\n/main:<type> Specify the type that contains the entry point (ignore all other possible entry points) (Short form: /m)\r\n/fullpaths Compiler generates fully qualified paths\r\n/filealign:<n> Specify the alignment used for output file sections\r\n/pdb:<file> Specify debug information file name (default: output file name with .pdb extension)\r\n/errorendlocation Output line and column of the end location of each error\r\n/preferreduilang Specify the preferred output language name.\r\n/nostdlib[+|-] Do not reference standard library (mscorlib.dll)\r\n/subsystemversion:<string> Specify subsystem version of this assembly\r\n/lib:<file list> Specify additional directories to search in for references\r\n/errorreport:<string> Specify how to handle internal compiler errors: prompt, send, queue, or none. The default is queue.\r\n/appconfig:<file> Specify an application configuration file containing assembly binding settings\r\n/moduleassemblyname:<string> Name of the assembly which this module will be a part of\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "cvtres.exe-C877CBB966EA5939AA2A17B6A5160950": { "file_name": "cvtres.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe", "hash_md5": "C877CBB966EA5939AA2A17B6A5160950", "hash_sha1": "2A3249732F5AA4588A4A9895FFE217355041D663", "hash_sha256": "1FE531EAC592B480AA4BD16052B909C3431434F17E7AE163D248355558CE43A6", "hash_sha384": "9EAEBBED65AA851C355135492531E58F4547B1AB3E118BA41ED32EE80A52BDE7E832053CEB7B713CA3FFC33F392B485F", "hash_sha512": "8D331C7D24BC5B790AFE565634843CDA0498C55A0BCB943EF5D22305871937887623849BBF75CC983E1CB6936766749B0EA627B069FD8B3F791B930CC2FC97D6", "hash_ssdeep": "768:akdac2JSz9RvzZFcmOUgMiMkRUop6nyMFsSLzmPQySlphYjkmE+iZMB4tF:ucXZFcmbcUyM2SnmdSlsjkmE+zBSF", "hash_imp": "55D76ADE7FFEA0F41FF2B55505C2B362", "hash_pesha1": "DBBF02824C68E986F7901576CD060AAE93D717C0", "hash_pe256": "9DED0B484DAB4C855638FF211AA738AB5ACFE45E12331060A363F0FC33FA365C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Resource File To COFF Object Conversion Utility", "meta_original_filename": "CVTRES.EXE", "meta_product_name": "Microsoft .NET Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.10.25028.0 built by: VCTOOLSD15RTM", "meta_product_version": "14.10.25028.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1fe531eac592b480aa4bd16052b909c3431434f17e7ae163d248355558ce43a6/detection", "output": "Microsoft (R) Windows Resource To Object Converter Version 14.10.25028.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nusage: CVTRES [options] [files]\r\n\r\n options:\r\n\r\n /DEFINE:symbol\r\n /FOLDDUPS\r\n /MACHINE:{ARM|EBC|IA64|X64|X86}\r\n /NOLOGO\r\n /OUT:filename\r\n /READONLY\r\n /VERBOSE\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ilasm.exe-5C0E98A6D6B8B42B165C2F415837DE1E": { "file_name": "ilasm.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe", "hash_md5": "5C0E98A6D6B8B42B165C2F415837DE1E", "hash_sha1": "6B1E04703BAFC0DCE38231055217E9B936073B0C", "hash_sha256": "584DBDAA56A351BD6EC6E02165060BCFAB6E6B572FF8E3E694D4B3F90475AAC9", "hash_sha384": "8FDC5DDF2777C2B74B6D9C98DE74D376590835803892E549040E61CFBE7B8AD5BBA998F3379A7FBCD862522576FDA0A9", "hash_sha512": "652F77DA742F7A176BFA518C7087BD79F472804FCE203C510F9E27785AFC5ACF83F26C7DD79CFE2B224A37F5C7056343D0C3A3F3E95CE960E8A2EB5BB950DB68", "hash_ssdeep": "6144:VG/TojdEL0iXFsTK0Z1a2kO72qfux5B0cEsQEsY0c6utVkO98:VG/ToZbiXFsTTwfOq4Eu", "hash_imp": "B5ACD3F4BA7467B8D6211B3A8B8E24E2", "hash_pesha1": "98F1D2AB20277D41D7A0B2327BA789F6358A6A2F", "hash_pe256": "9076FB059989C803C391BF3F25697440846478A175994C4382111E4333028213", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework IL assembler", "meta_original_filename": "ilasm.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/584dbdaa56a351bd6ec6e02165060bcfab6e6b572ff8e3e694d4b3f90475aac9/detection", "output": "\r\nMicrosoft (R) .NET Framework IL Assembler version 4.8.4084.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\n\r\n\r\nUsage: ilasm [Options] <sourcefile> [Options]\r\n\r\nOptions:\r\n/NOLOGO Don't type the logo\r\n/QUIET Don't report assembly progress\r\n/NOAUTOINHERIT Disable inheriting from System.Object by default\r\n/DLL Compile to .dll\r\n/EXE Compile to .exe (default)\r\n/PDB Create the PDB file without enabling debug info tracking\r\n/APPCONTAINER Create an AppContainer exe or dll\r\n/DEBUG Disable JIT optimization, create PDB file, use sequence points from PDB\r\n/DEBUG=IMPL Disable JIT optimization, create PDB file, use implicit sequence points\r\n/DEBUG=OPT Enable JIT optimization, create PDB file, use implicit sequence points\r\n/OPTIMIZE Optimize long instructions to short\r\n/FOLD Fold the identical method bodies into one\r\n/CLOCK Measure and report compilation times\r\n/RESOURCE=<res_file> Link the specified resource file (*.res) \r\n\t\t\tinto resulting .exe or .dll\r\n/OUTPUT=<targetfile> Compile to file with specified name \r\n\t\t\t(user must provide extension, if any)\r\n/KEY=<keyfile> Compile with strong signature \r\n\t\t\t(<keyfile> contains private key)\r\n/KEY=@<keysource> Compile with strong signature \r\n\t\t\t(<keysource> is the private key source name)\r\n/INCLUDE=<path> Set path to search for #include'd files\r\n/SUBSYSTEM=<int> Set Subsystem value in the NT Optional header\r\n/SSVER=<int>.<int> Set Subsystem version number in the NT Optional header\r\n/FLAGS=<int> Set CLR ImageFlags value in the CLR header\r\n/ALIGNMENT=<int> Set FileAlignment value in the NT Optional header\r\n/BASE=<int> Set ImageBase value in the NT Optional header (max 2GB for 32-bit images)\r\n/STACK=<int> Set SizeOfStackReserve value in the NT Optional header\r\n/MDV=<version_string> Set Metadata version string\r\n/MSV=<int>.<int> Set Metadata stream version (<major>.<minor>)\r\n/PE64 Create a 64bit image (PE32+)\r\n/HIGHENTROPYVA Set High Entropy Virtual Address capable PE32+ images (default for /APPCONTAINER)\r\n/NOCORSTUB Suppress generation of CORExeMain stub\r\n/STRIPRELOC Indicate that no base relocations are needed\r\n/ITANIUM Target processor: Intel Itanium\r\n/X64 Target processor: 64bit AMD processor\r\n/ARM Target processor: ARM processor\r\n/32BITPREFERRED Create a 32BitPreferred image (PE32)\r\n/ENC=<file> Create Edit-and-Continue deltas from specified source file\r\n\r\nKey may be '-' or '/'\r\nOptions are recognized by first 3 characters\r\nDefault source file extension is .il\r\n\r\nTarget defaults:\r\n/PE64 => /PE64 /ITANIUM\r\n/ITANIUM => /PE64 /ITANIUM\r\n/X64 => /PE64 /X64\r\n\r\n", "error": "Error : Invalid Option: --help\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "InstallUtil.exe-909A1D386235DD5F6BA61B91BA34119D": { "file_name": "InstallUtil.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe", "hash_md5": "909A1D386235DD5F6BA61B91BA34119D", "hash_sha1": "CEE32DD2FCA33AD540350FC83E651ADFEBAE9C37", "hash_sha256": "D0F224023900420D0E541360144BFBFB03CBB936391CE6D3E98590DDCA51BC6A", "hash_sha384": "8F2E4CE8708F3EA81657E255F4FAA09D10B994D4665BA651599001C5A1C1F9DFADE57C5DF02085895AD75D8C0BBE1731", "hash_sha512": "4F3167F627C54F90A7CC703FD5B010989F94E0567C744EC493D973E6687C8925BA563235D98BB527EAA0454303934C33D5EC0021F3586E0EF0AD3E56EAFC3942", "hash_ssdeep": "384:8tpFVymMsihB9VKS7xdgB6KJ9Yl6dnPU3SERztmbqCJstdMardz/JikPZ+RPZT3/:85Ms2SqdyZ6Iq8BLfX2qWf8Bn", "hash_imp": "n/a", "hash_pesha1": "305081E36C14BD3501158E354F15AE31081FA2E1", "hash_pe256": "C3C4A0BB9835ABDC5D3B01FA47D16C930BFD00EB8684DA55BD1CF8FAE7D5847E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Framework installation utility", "meta_original_filename": "InstallUtil.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/d0f224023900420d0e541360144bfbfb03cbb936391ce6d3e98590ddca51bc6a/detection", "output": "Microsoft (R) .NET Framework Installation utility Version 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: InstallUtil [/u | /uninstall] [option [...]] assembly [[option [...]] assembly] [...]]\r\n\r\nInstallUtil executes the installers in each given assembly.\r\nIf the /u or /uninstall switch is specified, it uninstalls\r\nthe assemblies, otherwise it installs them. Unlike other\r\noptions, /u applies to all assemblies, regardless of where it\r\nappears on the command line.\r\n\r\nInstallation is done in a transactioned way: If one of the\r\nassemblies fails to install, the installations of all other\r\nassemblies are rolled back. Uninstall is not transactioned.\r\n\r\nOptions take the form /switch=[value]. Any option that occurs\r\nbefore the name of an assembly will apply to that assembly's\r\ninstallation. Options are cumulative but overridable - options\r\nspecified for one assembly will apply to the next as well unless\r\nthe option is specified with a new value. The default for all\r\noptions is empty or false unless otherwise specified.\r\n\r\nOptions recognized:\r\n\r\nOptions for installing any assembly:\r\n/AssemblyName\r\n The assembly parameter will be interpreted as an assembly name (Name,\r\n Locale, PublicKeyToken, Version). The default is to interpret the\r\n assembly parameter as the filename of the assembly on disk.\r\n\r\n/LogFile=[filename]\r\n File to write progress to. If empty, do not write log. Default\r\n is <assemblyname>.InstallLog\r\n\r\n/LogToConsole={true|false}\r\n If false, suppresses output to the console.\r\n\r\n/ShowCallStack\r\n If an exception occurs at any point during installation, the call\r\n stack will be printed to the log.\r\n\r\n/InstallStateDir=[directoryname]\r\n Directory in which the .InstallState file will be stored. Default\r\n is the directory of the assembly.\r\n\r\n\r\nIndividual installers used within an assembly may recognize other\r\noptions. To learn about these options, run InstallUtil with the paths\r\nof the assemblies on the command line along with the /? or /help option.\r\n\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mscorsvw.exe-52CBB95C45D24784B0BDDA74A2D6A994": { "file_name": "mscorsvw.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe", "hash_md5": "52CBB95C45D24784B0BDDA74A2D6A994", "hash_sha1": "9E4EA76C491D88F6BC941EE20F8E40E2D7E1BADE", "hash_sha256": "1974BA6039355E657E78C97B5AC21E83087E43AAC9FB40DF5F0BC567D822A4A1", "hash_sha384": "C2BB0CE45C267E6A51D9F209B0D201DC2A2B3A5B06A701AA7F010238A156624196978B7D91398CDDB3EA9593B97A044F", "hash_sha512": "6B71DAA38FDB03A4D593FB63EFD7205000D2143581ECDEE37C307326BDEC3EA2100719E8178BCE55F4CF407E691DC0256B8DC30BD40C5BFAB26CBD0BE6AAB02D", "hash_ssdeep": "1536:zU9CKhO4uG8KStHYEyQaEuK9zNVnlK1WDh/hUeZOr2u+b+0czptbtC2dpc:zaD86ExaE1Jnk1QhZUeZOBtrzptLpc", "hash_imp": "B6FFAAE8AD145B27B7F899BF03C8EEE0", "hash_pesha1": "40253C4563CD4ABECFED1D8C7676B831EA0200F1", "hash_pe256": "0BDAFBB8AFC14213E52255F5F9168834FF62C419D683B7F01A7F1EFD7ADA7493", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": ".NET Runtime Optimization Service", "meta_original_filename": "mscorsvw.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1974ba6039355e657e78c97b5ac21e83087e43aac9fb40df5f0bc567d822a4a1/detection", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\SYSTEM32\\VCRUNTIME140_CLR0400.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\SYSTEM32\\ucrtbase_clr0400.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\SYSTEM32\\mscoree.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "ngen.exe-D253C39347487B5AB5928C6D31317E80": { "file_name": "ngen.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe", "hash_md5": "D253C39347487B5AB5928C6D31317E80", "hash_sha1": "1C8F02265CF6FE480BCD4D504F9E4D2A5A2F66CB", "hash_sha256": "7C151D31D31F61BD4794C57C3FB527F910A99BA81F84951F15CF4D58B2D63C24", "hash_sha384": "B5BAFD04D404492F97BCA65F177CE9CBB91C498F7498153BAA2E93700F67C2E790BB5F94E89CE60D89450FB304EBAA69", "hash_sha512": "025FB3A132B6B2B51948859F45EC37C76865E6379117E41F0DE7C1AB20AD158D2E6293943F639D0EC6EC6FEA981BCCEECD86B877A5511323B5AEC5B596EF209D", "hash_ssdeep": "3072:NabxrVrYEo7+ElRYS87HLXV2xoupmXPRFWvOHEpFMativW:NstVrYE/gRYSUHLXV29pmXPv/Epxt0W", "hash_imp": "5ABC114B8FD18C7E03AD3244A6DA0BC3", "hash_pesha1": "333EDD3BB7BF0891EFF86E655E1716C024FAC03C", "hash_pe256": "79AEA6D7E54301FC97FAD10370127058BC33C98F1C0CA6CBE8753996B86B2D7F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Common Language Runtime native compiler", "meta_original_filename": "ngen.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/7c151d31d31f61bd4794c57c3fb527f910a99ba81f84951f15cf4d58b2d63c24/detection", "output": "Microsoft (R) CLR Native Image Generator - Version 4.8.4084.0\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nError: Unrecognized option --help\r\nWARNING: This syntax is deprecated or you mis-typed your command. Run \"ngen /?\" to display a list of the currently supported parameters.\r\n\r\nUsage: ngen <action> [args] [/nologo] [/silent] [/verbose]\r\n ngen /? or /help\r\n\r\n /nologo - Prevents displaying of logo\r\n /silent - Prevents displaying of success messages\r\n /verbose - Displays verbose output for debugging\r\n\r\nActions:\r\n ngen install <assembly name> [scenarios] [config] [/queue[:[1|2|3]]\r\n Generate native images for an assembly and its dependencies\r\n and install them in the Native Images Cache\r\n If /queue is specified compilation job is queued up. If a priority \r\n is not specified, the default priority used is 3.\r\n ngen uninstall <assembly name> [scenarios] [config]\r\n Delete the native images of an assembly and its dependencies from\r\n the Native Images Cache.\r\n ngen update [/queue]\r\n Update native images that have become invalid\r\n If /queue is specified compilation jobs are queued up.\r\n ngen display [assembly name]\r\n Display the ngen state\r\n ngen executeQueuedItems [1|2|3]\r\n Executes queued compilation jobs.\r\n If priority is not specified all queued compilation jobs are done.\r\n If priority is specified compilation jobs with greater or equal\r\n priority than the specified are done. (Short form: eqi)\r\n ngen queue [pause|continue|status]\r\n Allows the user to pause and continue the NGen Service, and to\r\n query its status.\r\n ngen createPDB <path to native image> <directory to store PDB>\r\n [/lines [<search path for managed PDB>] ]\r\n Generates a native PDB file for a native image that was previously\r\n generated by NGen. The generated PDB file includes names of methods\r\n and ranges of IP offsets that map to those methods.\r\n If /lines is specified, then additional information is written to the\r\n PDB to map ranges of IP offsets to source file line numbers. /lines\r\n requires access to the managed PDB generated by the language compiler.\r\n <search path for managed PDB> may optionally be specified to help NGen\r\n find the managed PDB\r\n\r\nScenarios:\r\n /Debug - Generate images that can be used under a debugger\r\n /Profile - Generate images that can be used under a profiler\r\n /NoDependencies - Generate the minimal number of native images\r\n required by this scenario\r\n\r\nConfig:\r\n /ExeConfig:<path to exe> - Use the configuration of the specified\r\n executable assembly\r\n /AppBase:<path to appbase directory> - Use the specified directory as\r\n the appbase\r\n\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ngentask.exe-E983CDC58F22C7641CFAB9A21A3171DD": { "file_name": "ngentask.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngentask.exe", "hash_md5": "E983CDC58F22C7641CFAB9A21A3171DD", "hash_sha1": "E4C496B24B48F7DBA280CB2FDE9A6AC123E56620", "hash_sha256": "58920FDDCA62BC540072BA0EAA17429F9ADD01985B90768DA33C5CD73771E361", "hash_sha384": "A70647B841AD1AED0C240F0DFF9D76F520DD7D6421B856FEFAB4065916985C3A4026CAA4901C61F5A33441DD3D97F694", "hash_sha512": "CBC7209F8C73C070BA8C0D580DA0508C7604059BDB7BFCD70434C7B244338899BAB3A850802FAF685A83C5E0F4E41EBD11FD56F6ACEA9B7EF62B2E94E5B03327", "hash_ssdeep": "1536:GL9eXaGuBPGsL5x4+Jtpd8InFupB7PsXl:GZ7GuhhLXdtb8IFu7PU", "hash_imp": "n/a", "hash_pesha1": "D2CB48A10686ED66BD978E315B2E674C346FB5D5", "hash_pe256": "BB48E3E15E48BDEADAEA4BC3A2BBE30DDF5E2F53A25B8B19AF22DD16797534A1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Framework optimization service", "meta_original_filename": "NGenTask.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/58920fddca62bc540072ba0eaa17429f9add01985b90768da33c5cd73771e361/detection", "error": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngentask.exe [options...]\r\n This tool reads from the usage log data produced by the runtime, and triggers NGen to occur.\r\n /RuntimeWide - Parse the fusion stream of the usage logs instead of the App stream. Task runs in machine-wide mode.\r\n /Critical - Runs as a critical idle task.\r\n", "output": "NGen Task starting, command line: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngentask.exe\" --help\r\nUnrecognized command line option --help\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngentask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "RegAsm.exe-A4EB36BAE72C5CB7392F2B85609D4A7E": { "file_name": "RegAsm.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegAsm.exe", "hash_md5": "A4EB36BAE72C5CB7392F2B85609D4A7E", "hash_sha1": "5C58053A3A18C0226B98A4AC7E7320581300B6C9", "hash_sha256": "DC45704BA97D974D157C1C4A27DBA402AFA595EAC2468D8DEF2EE8D0A2EE9A81", "hash_sha384": "D01ADC95EF11EDBFD6B1EA1D926A7030A9782B655C641CACE6D5529287D2396E6226DB90DFD0F30FADD9E303A5962668", "hash_sha512": "8EBDD20B7C1EE87AA3766D812960B0D8CFA0A6BA6E371F730E589895D202DD540EB475F69940261C1532E90D1030370E9EB5102CADBF6E546F99B350DE79B95A", "hash_ssdeep": "768:/8XcJiMjm2ieHFYPyCsSuJbn8dBhFwjSMF6Iq8KSYDKvc7qWk81:zYMaNyFYPYSAb8dBnWHsPDKvcN91", "hash_imp": "n/a", "hash_pesha1": "EC1B45DF76B912BCAB4A524A47D2C3EF82EC98B1", "hash_pe256": "AC8DAEF33BF5CFD6A93FD30A9100A1F89413C0794F31A91F716A8CB4907BAA0D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Assembly Registration Utility", "meta_original_filename": "RegAsm.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/dc45704ba97d974d157c1c4a27dba402afa595eac2468d8def2ee8d0a2ee9a81/detection", "output": "Microsoft .NET Framework Assembly Registration Utility version 4.8.4084.0\r\nfor Microsoft .NET Framework version 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nSyntax: RegAsm AssemblyName [Options]\r\nOptions:\r\n /unregister Unregister types\r\n /tlb[:FileName] Export the assembly to the specified type library\r\n and register it\r\n /regfile[:FileName] Generate a reg file with the specified name\r\n instead of registering the types. This option\r\n cannot be used with the /u or /tlb options\r\n /codebase Set the code base in the registry\r\n /registered Only refer to already registered type libraries\r\n /asmpath:Directory Look for assembly references here\r\n /nologo Prevents RegAsm from displaying logo\r\n /silent Silent mode. Prevents displaying of success messages\r\n /verbose Displays extra information\r\n /? or /help Display this usage message\r\n", "error": "RegAsm : error RA0000 : Failed to load 'C:\\Users\\user\\help' because it is not a valid .NET assembly\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegAsm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "RegSvcs.exe-DC67ADE51149EC0C373A379473895BA1": { "file_name": "RegSvcs.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe", "hash_md5": "DC67ADE51149EC0C373A379473895BA1", "hash_sha1": "41CAF1DB97DE6568B5D76A1775F06B66F489BF8C", "hash_sha256": "DB727E9D8659D4D711C58B28D11E9E0B63DB08FED0DE9B6F550288FC8D37D137", "hash_sha384": "85EBEDF52EB05F5BE4B196FD9CAD69E67D66443FEE4EC4A89A461C21070AAE796668CF1CA695F948BDB3F46CC2226397", "hash_sha512": "739D5C850625F1C3FF0D8911176C5DC0D93F7627C06BA792FAF3B519FF3CE682E3A846791D3174A09DF214825C7267C2B85498421A13C7EE177BD4CECFCCB332", "hash_ssdeep": "768:bBbSoy+SNIBf0k2dsjDg6Iq8SeykqW88rK1:EoeIBf0ddsjD/Cy21u1", "hash_imp": "n/a", "hash_pesha1": "5013BD7E0BE5B832CCD4B4C0C9F29C3A483BA68D", "hash_pe256": "F26E60774D380B47078F795F002D52DD614BAD15CD232B09867206408D32DD9E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft .NET Services Installation Utility", "meta_original_filename": "RegSvcs.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/db727e9d8659d4d711c58b28d11e9e0b63db08fed0de9b6f550288fc8d37d137/detection", "output": "Microsoft (R) .NET Framework Services Installation Utility Version 4.8.4084.0\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nInvalid option: '--help'\r\n\nUSAGE: regsvcs.exe [options] AssemblyName\r\nOptions:\r\n /? or /help Display this usage message.\r\n /fc Find or create target application (default).\r\n /c Create target application, error if it already exists.\r\n /exapp Expect an existing application.\r\n /tlb:<tlbfile> Filename for the exported type library.\r\n /appname:<name> Use the specified name for the target application.\r\n /parname:<name> Use the specified name or id for the target partition.\r\n /extlb Use an existing type library.\r\n /reconfig Reconfigure existing target application (default).\r\n /noreconfig Don't reconfigure existing target application.\r\n /u Uninstall target application.\r\n /nologo Suppress logo output.\r\n /quiet Suppress logo output and success output.\r\n /componly Configure components only, no methods or interfaces.\r\n /appdir:<path> Set application root directory to specified path.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ServiceModelReg.exe-86A216436C5C68CF48875EE3A6DBAB4C": { "file_name": "ServiceModelReg.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ServiceModelReg.exe", "hash_md5": "86A216436C5C68CF48875EE3A6DBAB4C", "hash_sha1": "49D848D55A93B3F9040BC2D06DBB0C2BC316C4AD", "hash_sha256": "4E6240E12755D0F48534A42F78B860FFBA993D94D386A7D64063A89AFA250814", "hash_sha384": "237CEF16E02842B878EA874350B351E9DC7FEF7F1D41FF2F9F7A8F51B33365AB2E682CAD980611F1C15A6CFBBBC95DC8", "hash_sha512": "31E6D2915E2642BF094AA2554C15F8A342FA25C001C5E5C32214A003BF6BD0181B38ED2ECC7AB4037FC4150DEB7BD79766529E680B9B112B06A1830A85896D41", "hash_ssdeep": "6144:tvni+/0U2UgDSU7uOWpuxlzebez16/g2cHbm+zcguAXedr2nW2:Ji+/0U2UgDSU7ujuxlzeqp6/gPpxel2", "hash_imp": "F237FB4E5A065A1C3DEE4A01B2EDC0C0", "hash_pesha1": "14377B1F477FA0A42AC2AE8239CE88E86B216956", "hash_pe256": "9F95A7132C092A9C2F3FCDACFE6532D39415821C3C00CBD180846BABC01D6379", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WCF Generic Command for Vista Setup", "meta_original_filename": "ServiceModelReg.exe", "meta_product_name": "Microsoft .NET Framework", "meta_comments": "Flavor=Retail", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.8.4084.0 built by: NET48REL1", "meta_product_version": "4.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4e6240e12755d0f48534a42f78b860ffba993d94d386a7d64063a89afa250814/detection", "output": "[Error]Unknown switch '--help'.Microsoft (R) WCF/WF registration tool version 4.5.0.0 \r\nCopyright (c) Microsoft Corporation. All rights reserved. \r\n \r\nAdministration utility that manages the installation and uninstallation of \r\nWCF and WF components on a single machine. \r\n\r\nUsage: \r\n ServiceModelReg.exe [(-ia|-ua|-r)|((-i|-u) -c:<command>)] [-v|-q] [-nologo] [-h] \r\n -ia \r\n Install all components \r\n -ua \r\n Uninstall all components \r\n -r \r\n Repairs all components \r\n -i \r\n Install components specified with -c \r\n -u \r\n Uninstall components specified with -c \r\n -c:<component> \r\n Install/uninstall a component: \r\n httpnamespace - HTTP namespace reservation \r\n tcpportsharing - TCP port sharing service \r\n tcpactivation - TCP activation service \r\n namedpipeactivation - Named pipe activation service \r\n msmqactivation - MSMQ activation service \r\n etw - ETW event tracing manifests (Windows Vista or later) \r\n Can be used to install several components at the same time \r\n -q \r\n Quiet mode (only error logging) \r\n -v \r\n Verbose mode \r\n -nologo \r\n Suppress the copyright and banner message \r\n -h \r\n Displays this help text. \r\n \r\nExamples: \r\n ServiceModelReg.exe -ia \r\n Installs all components \r\n ServiceModelReg.exe -i -c:httpnamespace -c:etw \r\n Installs HTTP namespace reservation and ETW manifests \r\n ServiceModelReg.exe -u -c:etw \r\n Uninstalls ETW manifests \r\n ServiceModelReg.exe -r \r\n Repairs the installation\r\n[Error]Switch '-c' requires a component to be specified for installation or uninstallation. Please specify which components to install or uninstall.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ServiceModelReg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "vbc.exe-A526DE1F9DE51E1ACBC6B8A492673174": { "file_name": "vbc.exe", "file_path": "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe", "hash_md5": "A526DE1F9DE51E1ACBC6B8A492673174", "hash_sha1": "9DE369D588F9C95E6BA0A5E2CE525365E0531A89", "hash_sha256": "23C34FF2BB98F028FEFAB008F83AF6C74A5F7B99114E6140CD69212644BF8D3E", "hash_sha384": "6F4889A6E4CBB5466F460E3DE820651AE908D244138F017C9F04CF32140658CD3C4D18D9BFB74DAD573C5114434E7D19", "hash_sha512": "445B35A32F81541A987442980A6BAF98725629F454DC42D68921A4C5C901BF48F71FD8A8BFBE25ECCD16567688A5F566E65919BF2433BF6BEBA167035D1C94CE", "hash_ssdeep": "49152:KWt/e5tGMP6E/J2gEnA6YPLRU0hM5wKOcfOhGiLCa/Noz2j+19uPdQHqhCR:iP4lApU0hM5w1RCgNoKj56", "hash_imp": "820E2A2386C426F41813BF1E25691EB0", "hash_pesha1": "23C09CC2B927A01AB7309344D01B8C2AB76471DF", "hash_pe256": "6E95FFDDFF984D3E61AC68C812DF2C4CD6CA9E5BA7840DF41ED3125A99FF895A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000023241FB59996DCC4DFF000000000232", "signature_thumbprint": "FF82BC38E1DA5E596DF374C53E3617F7EDA36B06", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Visual Basic Command Line Compiler", "meta_original_filename": "vbc.exe", "meta_product_name": "Microsoft .NET Framework", "meta_company_name": "Microsoft Corporation", "meta_file_version": "14.8.4084.0", "meta_product_version": "14.8.4084.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/23c34ff2bb98f028fefab008f83af6c74a5f7b99114e6140cd69212644bf8d3e/detection", "output": "Microsoft (R) Visual Basic Compiler version 14.8.4084\nfor Visual Basic 2012\r\nCopyright (c) Microsoft Corporation. All rights reserved.\n\nThis compiler is provided as part of the Microsoft (R) .NET Framework, but only supports language versions up to Visual Basic 2012, which is no longer the latest version. For compilers that support newer versions of the Visual Basic programming language, see http://go.microsoft.com/fwlink/?LinkID=533241\r\n\r\n Visual Basic Compiler Options\r\n\r\n - OUTPUT FILE -\r\n/out:<file> Specifies the output file name.\r\n/target:exe Create a console application (default). (Short form: /t)\r\n/target:winexe Create a Windows application.\r\n/target:library Create a library assembly.\r\n/target:module Create a module that can be added to an assembly.\r\n/target:appcontainerexe Create a Windows application that runs in AppContainer.\r\n/target:winmdobj Create a Windows Metadata intermediate file\r\n/doc[+|-] Generates XML documentation file.\r\n/doc:<file> Generates XML documentation file to <file>.\r\n\r\n - INPUT FILES -\r\n/addmodule:<file_list> Reference metadata from the specified modules.\r\n/link:<file_list> Embed metadata from the specified interop assembly. (Short form: /l)\r\n/recurse:<wildcard> Include all files in the current directory and subdirectories according to the wildcard specifications.\r\n/reference:<file_list> Reference metadata from the specified assembly. (Short form: /r)\r\n\r\n - RESOURCES -\r\n/linkresource:<resinfo> Links the specified file as an external assembly resource. resinfo:<file>[,<name>[,public|private]] (Short form: /linkres)\r\n/nowin32manifest The default manifest should not be embedded in the manifest section of the output PE.\r\n/resource:<resinfo> Adds the specified file as an embedded assembly resource. resinfo:<file>[,<name>[,public|private]] (Short form: /res)\r\n/win32icon:<file> Specifies a Win32 icon file (.ico) for the default Win32 resources.\r\n/win32manifest:<file> The provided file is embedded in the manifest section of the output PE.\r\n/win32resource:<file> Specifies a Win32 resource file (.res).\r\n\r\n - CODE GENERATION -\r\n/optimize[+|-] Enable optimizations.\r\n/removeintchecks[+|-] Remove integer checks. Default off.\r\n/debug[+|-] Emit debugging information.\r\n/debug:full Emit full debugging information (default).\r\n/debug:pdbonly Emit PDB file only.\r\n\r\n - ERRORS AND WARNINGS -\r\n/nowarn Disable all warnings.\r\n/nowarn:<number_list> Disable a list of individual warnings.\r\n/warnaserror[+|-] Treat all warnings as errors.\r\n/warnaserror[+|-]:<number_list> Treat a list of warnings as errors.\r\n\r\n - LANGUAGE -\r\n/define:<symbol_list> Declare global conditional compilation symbol(s). symbol_list:name=value,... (Short form: /d)\r\n/imports:<import_list> Declare global Imports for namespaces in referenced metadata files. import_list:namespace,...\r\n/langversion:<number> Specify language version: 9|10|11.\r\n/optionexplicit[+|-] Require explicit declaration of variables.\r\n/optioninfer[+|-] Allow type inference of variables.\r\n/rootnamespace:<string> Specifies the root Namespace for all type declarations.\r\n/optionstrict[+|-] Enforce strict language semantics.\r\n/optionstrict:custom Warn when strict language semantics are not respected.\r\n/optioncompare:binary Specifies binary-style string comparisons. This is the default.\r\n/optioncompare:text Specifies text-style string comparisons.\r\n\r\n - MISCELLANEOUS -\r\n/help Display this usage message. (Short form: /?)\r\n/noconfig Do not auto-include VBC.RSP file.\r\n/nologo Do not display compiler copyright banner.\r\n/quiet Quiet output mode.\r\n/verbose Display verbose messages.\r\n\r\n - ADVANCED -\r\n/baseaddress:<number> The base address for a library or module (hex).\r\n/bugreport:<file> Create bug report file.\r\n/codepage:<number> Specifies the codepage to use when opening source files.\r\n/delaysign[+|-] Delay-sign the assembly using only the public portion of the strong name key.\r\n/errorreport:<string> Specifies how to handle internal compiler errors; must be prompt, send, none, or queue (default).\r\n/filealign:<number> Specify the alignment used for output file sections.\r\n/highentropyva[+|-] Enable high-entropy ASLR.\r\n/keycontainer:<string> Specifies a strong name key container.\r\n/keyfile:<file> Specifies a strong name key file.\r\n/libpath:<path_list> List of directories to search for metadata references. (Semi-colon delimited.)\r\n/main:<class> Specifies the Class or Module that contains Sub Main. It can also be a Class that inherits from System.Windows.Forms.Form. (Short form: /m)\r\n/moduleassemblyname:<string> Name of the assembly which this module will be a part of.\r\n/netcf Target the .NET Compact Framework.\r\n/nostdlib Do not reference standard libraries (system.dll and VBC.RSP file).\r\n/platform:<string> Limit which platforms this code can run on; must be x86, x64, Itanium, arm, AnyCPU32BitPreferred or anycpu (default).\r\n/sdkpath:<path> Location of the .NET Framework SDK directory (mscorlib.dll).\r\n/subsystemversion:<version> Specify subsystem version of the output PE. version:<number>[.<number>]\r\n/utf8output[+|-] Emit compiler output in UTF8 character encoding.\r\n@<file> Insert command-line settings from a text file.\r\n/vbruntime[+|-|*] Compile with/without the default Visual Basic runtime.\r\n/vbruntime:<file> Compile with the alternate Visual Basic runtime in <file>.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "memtest.exe-3CBDCBD85E81B8266505B6031EE9AD7D": { "file_name": "memtest.exe", "file_path": "C:\\Windows\\Boot\\PCAT\\memtest.exe", "hash_md5": "3CBDCBD85E81B8266505B6031EE9AD7D", "hash_sha1": "775FAB41A99CA7C83C59339BD397D011D8089BA3", "hash_sha256": "0BE241024D19C89F811B31057C0951A64D12A78FD101CE4A533AE0DDE2F9F488", "hash_sha384": "B01F671664982F4FE19F5ADB8E6EACA19FE9DBDDFC17CB3E9D05495289A955008E47B9FB351E6EFAD464A051C52B8DAA", "hash_sha512": "D8566C9D0C75EA9FE1505942799BD0D736113EE034ACEE7C80E308466E452D09D237A053DD29A33778033A014CCE9878C99A684929BAB0344FB85EF5DAB1CA13", "hash_ssdeep": "24576:xLGvETEEzaTKN6smkEsMNJQYhYA/GLGHMjjrAOrIZThQoc7J:xLG1KN1IXPSYGwUj01hpu", "hash_imp": "n/a", "hash_pesha1": "C56DCDBA3413AB7BC2B77E15447A58F66EDA06F3", "hash_pe256": "E868275D1E486F8E3A2E659FAE9E5C97BE79766B1321AA6FF360B0902D74433C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Memory Diagnostic", "meta_original_filename": "memdiag.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/0be241024d19c89f811b31057c0951a64d12a78fd101ce4a533ae0dde2f9f488/detection" }, "MicrosoftEdge.exe-": { "file_name": "MicrosoftEdge.exe", "file_path": "C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\MicrosoftEdge.exe", "hash_md5": null, "hash_sha1": null, "hash_sha256": null, "hash_sha384": null, "hash_sha512": null, "hash_imp": "n/a", "hash_pesha1": "n/a", "hash_pe256": "n/a", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "n/a", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "bfsvc.exe-0726E07524335D86FC9C6BB2EBAB71F7": { "file_name": "bfsvc.exe", "file_path": "C:\\Windows\\bfsvc.exe", "hash_md5": "0726E07524335D86FC9C6BB2EBAB71F7", "hash_sha1": "C0B8221A063D133014C2B29197ACD70FE0A7C0FF", "hash_sha256": "1B17747065AA027A0995460A2E5C9C4C2FE255918892AF16C3545B925687F5DF", "hash_sha384": "A7E28EEBBDF82879D50693E58247D6063039005F74B9E363D0295A37A148FAA94521BB96356307A69326AF22BFA44721", "hash_sha512": "9B41C6BA32FC7F8FB058006DA64D2699888BC4856351569E813C49598148F109A8C898060FF323E2B5979F1AE2E3D1974598B056B8F8E219F5E5DA4ABE01DE9D", "hash_ssdeep": "1536:zKPEy6iopQUevUYr33JZHOvBfwn6NXI9M6eynTDuae10jguBybF:E8Q++ZHOvBfw6N4CAeWjc", "hash_imp": "0036D0ED215BD5342506902CA36E0BD3", "hash_pesha1": "EBC8680FCF5CAEDCFB706C58094DE4C9FA0EE8C9", "hash_pe256": "270F3CF361AF1D3915F70B0EE833DAE98D4DA6FC116BB0E1183572508B94B33B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Boot File Servicing Utility", "meta_original_filename": "bfsvc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/1b17747065aa027a0995460a2e5c9c4c2fe255918892af16c3545b925687f5df/detection", "error": "BFSVC Error: Failed to get partition name. Status = 0xc0000452\r\nBFSVC Error: Failed to get system partition! Last Error = 0x3bc3\r\nBFSVC Error: ServicingBootFiles failed. Error = 0x3bc3\r\n", "runtime_modules": [ "C:\\Windows\\bfsvc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "explorer.exe-12321D7CB0BB6BB113297E915BC248C4": { "file_name": "explorer.exe", "file_path": "C:\\Windows\\explorer.exe", "hash_md5": "12321D7CB0BB6BB113297E915BC248C4", "hash_sha1": "3F9D089A8A4E2BEF13CB28CDD3A016FA155DD04D", "hash_sha256": "04441A2E82A4BD350B448B135D52F0A981CF8D011279BED98AFE48F500767B66", "hash_sha384": "28791828D2B62FD36BA594C474A42614BC1EAD454864C40F5AFE316B10B4F74D5A91F991F08FCCC0BF792306FBF7F772", "hash_sha512": "090E68E84706EAA454A2B798955032CBE38B11EBF4D4781EA92E5497E127E0436A2E5B21C5E60F2C7E00F8BAB6932BF470CC470D304B2C0698092F2BCF498510", "hash_ssdeep": "49152:6m6dAhcYFbgFmDhR5IbW+gvy6TxnHHJGLPE+6DY8aHHiacY+vK659zDw+w8A7/eH:dgOMky6FcjE+dW9w8a0cDW", "hash_imp": "F878258E75C60DB12F65170C43A01F2F", "hash_pesha1": "9BB91AF54A76D732D3DC1C13F58445D5279FB260", "hash_pe256": "48058AE48EC7A373BE4BB8120949ABA0FDFC3B84B8704CA295E6CE332128BC6B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Explorer", "meta_original_filename": "EXPLORER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/04441a2e82a4bd350b448b135d52f0a981cf8d011279bed98afe48f500767b66/detection", "runtime_modules": [ "C:\\Windows\\explorer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\AEPIC.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\TWINAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\System32\\SHELL32.dll" ] }, "HelpPane.exe-9A6D44491772E8AA3EBDDC63C1CEF991": { "file_name": "HelpPane.exe", "file_path": "C:\\Windows\\HelpPane.exe", "hash_md5": "9A6D44491772E8AA3EBDDC63C1CEF991", "hash_sha1": "2E5284A0574F5B17ADF2C5105DC0F598919BD92D", "hash_sha256": "587943F7A42FC21D636B3BAE0CAD17D66E9AA919F0689730A01A77035F7BD767", "hash_sha384": "AF7ED6366A9BE1C185896D69BD25FACA7D16699CF8E09030B26A20098568E740C2028AA234BE187AC32A6D4DEFFC26BB", "hash_sha512": "A1917A06606697EABBA0A73332DFAFD3CA7D44A0F3F5AE887AB0A5C219F49803A59F690FEE7F11BAB21435CAE57A28857366CC4CAFD76AF6FAF916C599F78675", "hash_ssdeep": "12288:VGoI5cF1qtS8e5QIjFAPWAlkS+ExyEXsXKPXPiXuHNHGb6bH/zx/GCLW/nh/X:E+qtSZJFA+ekS+El", "hash_imp": "A71B59777FDF47EB06D8F9729F3BF423", "hash_pesha1": "9A9A7D8753F507DFCE0252DA29B378BD013B2F14", "hash_pe256": "BBB63B5E1E12461C01D9CB302568385684FD72B6D1593CBC92BD6E77332A972B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Help and Support", "meta_original_filename": "HelpPane.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/587943f7a42fc21d636b3bae0cad17d66e9aa919f0689730a01a77035f7bd767/detection", "runtime_modules": [ "C:\\Windows\\HelpPane.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll" ] }, "hh.exe-2C8FE78D53C8CA27523A71DFD2938241": { "file_name": "hh.exe", "file_path": "C:\\Windows\\hh.exe", "hash_md5": "2C8FE78D53C8CA27523A71DFD2938241", "hash_sha1": "0111959E0F521D0C01D258ABBB42BBA9C23E407D", "hash_sha256": "EB63FD45ED7EC773ECCAF0F20D44BC9B4ED0A3E01779D62321B1DA954A0F6EB8", "hash_sha384": "FC24F86CFAF2D1CC7EBFBF7718D7ABDFC65B12BE11C76E2260835438A2D3B60655D6248E58F482610BD138CB0BE4E3D4", "hash_sha512": "4FBA46ECC4F12BAE5F4C46D4D6136BB0BABF1ABF7327E5210D1291D786CE2262473212A64DA35114776B1CE26EAD734A9FD3972FFA0F294D97AB6907953FD137", "hash_ssdeep": "192:U8kHEFbfhORz4NqRGQE7KpcPUKU/dlk06Sl0+m5GJ1KDJD/QWc7:U8kH67heMMRGQEOpR/dlk06I1KDuWc7", "hash_imp": "D3D9C3E81A404E7F5C5302429636F04C", "hash_pesha1": "59C8F3207BFFB145504CFAE687C1BBD6AE2B7E25", "hash_pe256": "12F6D248A1D3661735FDC7AF92632A3DE629361D6AB9B68E9760DED97C784B71", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft HTML Help Executable", "meta_original_filename": "HH.exe.mui", "meta_product_name": "HTML Help", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/eb63fd45ed7ec773eccaf0f20d44bc9b4ed0a3e01779d62321b1da954a0f6eb8/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "(R-D) C:\\Windows\\en-US\\hh.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\hhctrl.ocx.mui": "File", "\\Windows\\Theme601709542": "Section", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(R--) C:\\Users\\user\\AppData\\Local\\Temp\\~DF742340B93F3B9977.TMP": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Temp\\~DF7CA6DA5EA1AEEB02.TMP": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\Sessions\\1\\BaseNamedObjects\\d34HWNDInterface:3e0720": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_ie_global_counters": "Section", "(R-D) C:\\Windows\\System32\\ieframe.dll": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\ieframe.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_webcache_counters_{9B6AB5B3-91BC-4097-835C-EA2DEC95E9CC}_S-1-5-21-2047949552-857980807-821054962-504": "Section", "(R-D) C:\\Windows\\SystemResources\\ieframe.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\mshtml.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\urlmon.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\Sessions\\1\\BaseNamedObjects\\d34HWNDInterface:6d0474": "Section", "(R-D) C:\\Windows\\apppatch\\DirectXApps_FOD.sdb": "File", "(RWD) C:\\Users\\user": "File", "\\Sessions\\1\\BaseNamedObjects\\MSIMGSIZECacheMap": "Section", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(RWD) C:\\Windows\\Fonts": "File", "(RW-) C:\\Users\\user\\help": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_32.db": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "File Download", "runtime_modules": [ "C:\\Windows\\hh.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\hhctrl.ocx", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28\\COMCTL32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "regedit.exe-0EE48CC819E58D266827F8605AF17ABD": { "file_name": "regedit.exe", "file_path": "C:\\Windows\\regedit.exe", "hash_md5": "0EE48CC819E58D266827F8605AF17ABD", "hash_sha1": "E9F9FFF398040CB8E7427F29A49A7931645A67AA", "hash_sha256": "F5CB9796E4517D2E2D3468A5DE1DA12BC57D0A582CAB46F8A70B69B0FFDE928D", "hash_sha384": "A8D26C695F7BD2DEF60E43ABC979E354C7D810D85525CD5D3514107F198C54FF7AE805D07874601B8EB368D720E48BB9", "hash_sha512": "93871D27FFB4E5F1E03BEB692464EB33344AF1571E18C45D311713AA1305F13794ED988878E9161FDD8E4EA36ABF845E7852D881319F1C4D658287A1850E22A5", "hash_ssdeep": "6144:R8e8Pp1u42+2LFd2KBiPQRZ66z+n4VZbd8g79pgrXNgRnVLjyzhbkidNN2:R8VPpS+aoKKQRZ66z24VZbdrpgrXN2LS", "hash_imp": "7FEBF576192E34BDF7D07877CBACC413", "hash_pesha1": "DA94E2A519FF6DF052B123643B9118FE9F6BC49D", "hash_pe256": "966FFD52367BF3410F46C029F9BE9086CB78617CB3BDCC22BA7D7CA4C3D8555B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Editor", "meta_original_filename": "REGEDIT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f5cb9796e4517d2e2d3468a5de1da12bc57d0a582cab46f8a70b69b0ffde928d/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\en-US\\regedit.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\aclui.dll.mui": "File", "\\Windows\\Theme601709542": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "\\Sessions\\1\\Windows\\Theme1175649999": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "Registry Editor", "runtime_modules": [ "C:\\Windows\\regedit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\SYSTEM32\\AUTHZ.dll", "C:\\Windows\\SYSTEM32\\ACLUI.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\ulib.dll", "C:\\Windows\\SYSTEM32\\clb.dll", "C:\\Windows\\SYSTEM32\\UxTheme.dll", "C:\\Windows\\SYSTEM32\\NTDSAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\SYSTEM32\\XmlLite.dll" ] }, "splwow64.exe-09EC082A13633BAEDE8FF155A0ACCF9E": { "file_name": "splwow64.exe", "file_path": "C:\\Windows\\splwow64.exe", "hash_md5": "09EC082A13633BAEDE8FF155A0ACCF9E", "hash_sha1": "2D962BA8E740C70FFEC00FEED2E2DC3D02729CB1", "hash_sha256": "F00450B2DCEA43504642C00C4D5B725003E23AD00928BE0A5AD381E920561EA7", "hash_sha384": "B16F937170FABBC81CA538AC7081F6559E26BAF4B30EBEAD4543FD570D641AE8F9E5374AF6CF6B2290B6F7A8CC1886BD", "hash_sha512": "3A818D8B26BBCAAAE4DA456AF64A67746AF4E670513E4DC2E03AA6E951B351F3DAF8A569429D91BF2D156B987D6E2B720C7549C2F082EFCE2327DC7CE72B958C", "hash_ssdeep": "3072:xMvRNJWRNsoGlAi+iKJKUZsQgV1HQbPRyZ2pPTc:mvRNJyNsoGlAid4sF78AZ2", "hash_imp": "260422772873DF4417E4B473F68B1ADE", "hash_pesha1": "787F42EF194F2A9687F8B1F18DB58FA030E94170", "hash_pe256": "CD22F48C381844D9E6D063BC4B81B54F1507990CF623F21E7E3BB505FFAFE19E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Print driver host for applications", "meta_original_filename": "splwow64.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.685 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.685", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f00450b2dcea43504642c00c4d5b725003e23ad00928be0a5ad381e920561ea7/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\splwow64.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll" ] }, "winhlp32.exe-0629E6D130F226C009EA9AB329F37ACC": { "file_name": "winhlp32.exe", "file_path": "C:\\Windows\\winhlp32.exe", "hash_md5": "0629E6D130F226C009EA9AB329F37ACC", "hash_sha1": "1529C6CF3265311B690992DC975443B35177BC7C", "hash_sha256": "4FCE997BDD3475C42BA856D8C288FD4F9F91FD1370075AD7E0B11B1E71AE69CE", "hash_sha384": "5ACC4C750A0CAC12E69E652967BAB059D050AC71533F4157176ABB3967D80D9D68A33DC57108BDC9AC5DB76FE0BB7563", "hash_sha512": "A36F25CD5B79891F0CC5A8E85636CE4EF10C91EC6D6C7C0F5C5B622D0AF1F4F400C864D331CAFFAA8A51D9A2734777B5B9CE87CABB7667A9ACEAF8837E88C847", "hash_ssdeep": "192:ZomhYgSgGvZx5qdoth1Pdk7WneHWGhh4j8q05:L67gGnP7q7WneHWGhh44q", "hash_imp": "0DFDE2C713801A5C7E6DC0108384FB68", "hash_pesha1": "DE7923B88BC3FDFFFB5F3EB94DAD49AC7B3AA33E", "hash_pe256": "84910CAE848CAD56B1F0B2AFC05F6A045EFB837FB7A3931F48BBC0A8B5055BD1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Winhlp32 Stub", "meta_original_filename": "WINHLP32.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/4fce997bdd3475c42ba856d8c288fd4f9f91fd1370075ad7e0b11b1e71ae69ce/detection", "runtime_modules": [ "C:\\Windows\\winhlp32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "agentactivationruntimestarter.exe-B556B608D4B1D770EBAAFD23DECF1F88": { "file_name": "agentactivationruntimestarter.exe", "file_path": "C:\\Windows\\system32\\agentactivationruntimestarter.exe", "hash_md5": "B556B608D4B1D770EBAAFD23DECF1F88", "hash_sha1": "1BF317D77FD63483D812865925A3CEE81879193F", "hash_sha256": "CE2903AC725F5DCE0E2F658996132858FAAF14F2EEF18B28CDBA9CA807A21F77", "hash_sha384": "7E220976925C51D256607F6F9816040C706F0F24A2E6355BE8BA8F3D8BF8CE693DB61575366B77FF4202AA6E8529D1D2", "hash_sha512": "DCF4266FEE1EB592D27D78210DDACD4EE4E590F7EABE2D67CA80C6B1C917D0AA0675BB4C56AA873103E243F416C6D1F0597C3966B4146CC556FB48C096DD442A", "hash_ssdeep": "192:wKcdVHZqzn/3dbd3380z/hDU48AoAvclD2eFZp/sBJGTZ6lEo6Uc7EN:2dVH8Tdbx8ExPvt0lD1KHMUc7", "hash_imp": "9FF2CEFB944FB06F3C5F295C519519AE", "hash_pesha1": "05082B9E6450F6B26B79DCB81071BC757F3EAF07", "hash_pe256": "A4FA071A27CBF127A8B7D2638A899540D12738165708C86A5647CA85B4AF9387", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/ce2903ac725f5dce0e2f658996132858faaf14f2eef18b28cdba9ca807a21f77/detection", "runtime_modules": [ "C:\\Windows\\system32\\agentactivationruntimestarter.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "ApplyTrustOffline.exe-9B9A38FA70D9DD0ED975170938077744": { "file_name": "ApplyTrustOffline.exe", "file_path": "C:\\Windows\\system32\\ApplyTrustOffline.exe", "hash_md5": "9B9A38FA70D9DD0ED975170938077744", "hash_sha1": "8059281FCFF2638405B7FC320D7CD86171F40CD9", "hash_sha256": "3A68D7E8C0D380C98C6ADB36EA1633CEDC7F07D43ECDAB3D3BCCBC8B062E2A27", "hash_sha384": "50D8FC2A5BAE67BAD55B233D7CEAD014125386A5D588ABD9EC0182DEA80723F28EB8120FC6E1E591114B0D64FF9E90EE", "hash_sha512": "9539D481FE9FFBB6D3B526B022CA4D482478F8DB491EE082A7780DFF1DC31FF0A23040863325D7C2F30517B466AA66C30D9669E0DF35057241C0F218E469CB1F", "hash_ssdeep": "12288:ko16kmdy3Gu9JpHW8PMJcatIWywlUV51BF5r24MLbekgfAch+I:k86k0qHHXHwI6UV51r5mmkrchf", "hash_imp": "76B11698645386AFEE2F4A2A8DB4EF06", "hash_pesha1": "93FBA57B1E42380336FBD931116C381B915D8D58", "hash_pe256": "B964E37189AB750EF61DDB1673AF162BEF9E6E926788B351D2E5E3B3EEA06A25", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "\"ApplyTrustOffline.PROGRAM\"", "meta_original_filename": "\"ApplyTrustOffline.PROGRAM\"", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3a68d7e8c0d380c98c6adb36ea1633cedc7f07d43ecdab3d3bccbc8b062e2a27/detection", "runtime_modules": [ "C:\\Windows\\system32\\ApplyTrustOffline.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "audiodg.exe-8BBBC4F638F4822D97AA3297DE8D6F64": { "file_name": "audiodg.exe", "file_path": "C:\\Windows\\system32\\audiodg.exe", "hash_md5": "8BBBC4F638F4822D97AA3297DE8D6F64", "hash_sha1": "3021F747D121FEDE2ACF00AB968A44E1E20941CF", "hash_sha256": "97C8AAEDBA3A89174BC6DDD8B5B40504A81E7ADAE8DF6B11230EB34B150FFC3B", "hash_sha384": "D116F8CBFF91C75092A5122E4268147CEE7AAA346E3AEA2AE57BDD1C2197277E1C2A4C35AB9908BB74CDBFC379A0C19F", "hash_sha512": "11889940A1E989CA2D5E05CBB4668938F53D0B553E0CA1745B06274E2154A0CD4F4D6C95B2CF5C6CD1CBF824E278EF085912570A7D3940A36B2CF059CAF989ED", "hash_ssdeep": "12288:7ShVuOWu9UY2EsIyyAKe9BcOBscwOo5tbyH:+hVCuqYmIfAKq6ablo5tk", "hash_imp": "356C5FB039EB7424A518F132A23D3232", "hash_pesha1": "105F308736BB958ECFC1B046C290975E4CEE7D31", "hash_pe256": "6D2DEB2E7004EAA74405B71B2DC18FBC75F92C70FBC3F288458ECB36B94C1532", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Audio Device Graph Isolation ", "meta_original_filename": "audioadg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/97c8aaedba3a89174bc6ddd8b5b40504a81e7adae8df6b11230eb34b150ffc3b/detection", "runtime_modules": [ "C:\\Windows\\system32\\audiodg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\combase.dll" ] }, "autochk.exe-1089F10A70508032686BAFCEAF132BB0": { "file_name": "autochk.exe", "file_path": "C:\\Windows\\system32\\autochk.exe", "hash_md5": "1089F10A70508032686BAFCEAF132BB0", "hash_sha1": "7747FEEDE7C2390CB4D2416B5DC85735AA95E04C", "hash_sha256": "C43EE7BF6051E228FCED1BA1249CCB35C24DEE5F17C96B5FE633031E62C3DA05", "hash_sha384": "FA4914C7C8CE36962A5E89EFD0D747DED2108E4C7E9565DCC7518319CEE7D47D3E3E176389C348202E00E782AF659A2C", "hash_sha512": "3A4D73D60339C0D3B888EDCC5A3DB7BEFBE1989F895318D0E928EE095EEAAB77E8374144362FAA6D4E104611F0D7E58FBEB72A6D7D2A5B3E40F4B7704C4A7EE6", "hash_ssdeep": "12288:hH0vVWz0ep2EZy/q+ImHhfdkMOdp7bV4WnmbWKB9zREhX2Lr:hHKXSnZIq+ImHNdk3dp7bVku23", "hash_imp": "6F131342C7A3A9D197C81C3DBDAA7885", "hash_pesha1": "6DBC0833B98915AC328A8F74B4ADED33B2C5A947", "hash_pe256": "01874583F0488EA32483B0F31AF75E09E9FC3DD6055C88986B642FC696ADEDA2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto Check Utility", "meta_original_filename": "AutoChk.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c43ee7bf6051e228fced1ba1249ccb35c24dee5f17c96b5fe633031e62c3da05/detection" }, "autoconv.exe-E30D46B57775A96BA95C278B5585F461": { "file_name": "autoconv.exe", "file_path": "C:\\Windows\\system32\\autoconv.exe", "hash_md5": "E30D46B57775A96BA95C278B5585F461", "hash_sha1": "E2FD0D30BEC1BCB79DE2F475974AE4D7EFD09375", "hash_sha256": "B903052E0D28C704BB0D7C1A36ECED237369C7AE0418145D4BB65C63005CDA2F", "hash_sha384": "C9BB2BE934B5AF711E9299548EF766CA2028CBEF1FBC06CEEDF33F43603AA4758242119A8D1E7F08EEE9416FD1BDE8BC", "hash_sha512": "C611460732311640FAF595FC5EA0D4BA425E3A1F1F8CE29C14AFCDDE347A75572BDD27ADD0E397112AE07F96E0FD325D3E415580F878F0F88ED8D54A40F63766", "hash_ssdeep": "12288:ZKjQS7zj4CAjH0cQNMLazUrFRtyFEvEo3uXDMhHncRqRLr:ZKj5dAjH0cjLazUJR8Fv9U3", "hash_imp": "E9FDC6BDE106C2C586A88FF5CCC36209", "hash_pesha1": "9025BF3BDD1F065EBB6563A82E0FDF60B291E60A", "hash_pe256": "42F4262A2217DB3AFEAF292313BA34C9771ADE8768CD4412C125134B81225D52", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto File System Conversion Utility", "meta_original_filename": "AUTOCONV.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/b903052e0d28c704bb0d7c1a36eced237369c7ae0418145d4bb65c63005cda2f/detection" }, "autofmt.exe-32A667471894397EFB1CBCFE95DBDD87": { "file_name": "autofmt.exe", "file_path": "C:\\Windows\\system32\\autofmt.exe", "hash_md5": "32A667471894397EFB1CBCFE95DBDD87", "hash_sha1": "674FCB573252A4DEAEAA7DAB2F2E7EE3414A04E7", "hash_sha256": "DDDA05B812AFDF53F7D9C76400EE7A8024C94C89EF67A55D96B8688239454227", "hash_sha384": "62B37D2D226178AA5E57050D261743B9E182001E00A19350A5E0D7DEF44B31405FED9A1C4ECA99A3FDC6C9B858665F3C", "hash_sha512": "B9EB1546C64826DD0483FCA2C6DFAADFC46AF86E9F0C196747B510760E84CE7E978A6CC870DD7AD1B1C2E60FA759C8BAF35A7374C9907F92B8C42DF6E5E6CBFD", "hash_ssdeep": "12288:jj3yCQ6dYzqR54tCifuAa5XkKXq0yfQKpz1bGjWjgmEVRLr:f3UFzqD40ifuAa5XbXqRQy1iD3", "hash_imp": "8638BA07BFC49AE3C095FC867CB48C4E", "hash_pesha1": "088F13ACA66B551A62A02CE763ECB15C5DB6510F", "hash_pe256": "BCE061DFF7F6B6B99E1108FC0E6C9C5FE9F553F83956E3B29F42C7E7CB3BF6E2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto File System Format Utility", "meta_original_filename": "AUTOFMT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/ddda05b812afdf53f7d9c76400ee7a8024c94c89ef67a55d96b8688239454227/detection" }, "conhost.exe-073E88797983A660B454098E9EF97067": { "file_name": "conhost.exe", "file_path": "C:\\Windows\\system32\\conhost.exe", "hash_md5": "073E88797983A660B454098E9EF97067", "hash_sha1": "A1E4B2CC40A39BF64012D1411F92B12D1F9791E8", "hash_sha256": "57B0CCD3AEBC6C7126E7C19F5DAC492DF51D904A505C5F5B0CB02270D53F8684", "hash_sha384": "B26A3DF0F4E15E4E85BE05E4C1C44AF4A9FDF89E4CE9C6AABF794562B58A561EB4BB80A0C66DF02B54EBA8E22DE11ECA", "hash_sha512": "BCD629220D94B2AF5BFCB1ABAE204AAB7E0B22EAAD3CE6CE2333C10B02A09DAF511132BAC98598CED28CBBD046111B86FE073FB7C0A034C2DE7FBB66BA273FF8", "hash_ssdeep": "12288:vCizPzIITF3oN/baXEz3de4X+9MMBeVm/FzYeRBlPC:qizEITF3oBRzrSMbVYFzYGBA", "hash_imp": "AFFE8C3BE3BBE4F0AC2EF124256F372D", "hash_pesha1": "BF58014BA5B120BED91B7FB8D8C688E44E3C4AE7", "hash_pe256": "531859FBA0BF1F531D6E3005A023833087ECB639667B5B268C39AFBF9F03A069", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Console Window Host", "meta_original_filename": "CONHOST.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/57b0ccd3aebc6c7126e7c19f5dac492df51d904a505c5f5b0cb02270d53f8684/detection", "output": "For more information on a specific command, type HELP command-name\r\nASSOC Displays or modifies file extension associations.\r\nATTRIB Displays or changes file attributes.\r\nBREAK Sets or clears extended CTRL+C checking.\r\nBCDEDIT Sets properties in boot database to control boot loading.\r\nCACLS Displays or modifies access control lists (ACLs) of files.\r\nCALL Calls one batch program from another.\r\nCD Displays the name of or changes the current directory.\r\nCHCP Displays or sets the active code page number.\r\nCHDIR Displays the name of or changes the current directory.\r\nCHKDSK Checks a disk and displays a status report.\r\nCHKNTFS Displays or modifies the checking of disk at boot time.\r\nCLS Clears the screen.\r\nCMD Starts a new instance of the Windows command interpreter.\r\n]0;C:\\Windows\\system32\\conhost.exe[?25h\n\n\n\n\n\n\n\n\nCOLOR Sets the default console foreground and background colors.\r\nCOMP Compares the contents of two files or sets of files.\r\nCOMPACT Displays or alters the compression of files on NTFS partitions.\r\nCONVERT Converts FAT volumes to NTFS. You cannot convert the\r\n current drive.\r\nCOPY Copies one or more files to another location.\r\nDATE Displays or sets the date.\r\nDEL Deletes one or more files.\r\nDIR Displays a list of files and subdirectories in a directory.\r\nDISKPART Displays or configures Disk Partition properties.\r\nDOSKEY Edits command lines, recalls Windows commands, and\r\n creates macros.\r\nDRIVERQUERY Displays current device driver status and properties.\r\nECHO Displays messages, or turns command echoing on or off.\r\nENDLOCAL Ends localization of environment changes in a batch file.\r\nERASE Deletes one or more files.\r\nEXIT Quits the CMD.EXE program (command interpreter).\r\nFC Compares two files or sets of files, and displays the\r\n differences between them.\r\nFIND Searches for a text string in a file or files.\r\nFINDSTR Searches for strings in files.\r\nFOR Runs a specified command for each file in a set of files.\r\nFORMAT Formats a disk for use with Windows.\r\nFSUTIL Displays or configures the file system properties.\r\n[?25h\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\nFTYPE Displays or modifies file types used in file extension\r\n associations.\r\nGOTO Directs the Windows command interpreter to a labeled line in\r\n a batch program.\r\nGPRESULT Displays Group Policy information for machine or user.\r\nGRAFTABL Enables Windows to display an extended character set in\r\n graphics mode.\r\nHELP Provides Help information for Windows commands.\r\nICACLS Display, modify, backup, or restore ACLs for files and\r\n directories.\r\nIF Performs conditional processing in batch programs.\r\nLABEL Creates, changes, or deletes the volume label of a disk.\r\nMD Creates a directory.\r\nMKDIR Creates a directory.\r\nMKLINK Creates Symbolic Links and Hard Links\r\nMODE Configures a system device.\r\nMORE Displays output one screen at a time.\r\nMOVE Moves one or more files from one directory to another\r\n directory.\r\nOPENFILES Displays files opened by remote users for a file share.\r\nPATH Displays or sets a search path for executable files.\r\nPAUSE Suspends processing of a batch file and displays a message.\r\n[?25h\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\nPOPD Restores the previous value of the current directory saved by\r\n PUSHD.\r\nPRINT Prints a text file.\r\nPROMPT Changes the Windows command prompt.\r\nPUSHD Saves the current directory then changes it.\r\nRD Removes a directory.\r\nRECOVER Recovers readable information from a bad or defective disk.\r\nREM Records comments (remarks) in batch files or CONFIG.SYS.\r\nREN Renames a file or files.\r\nRENAME Renames a file or files.\r\nREPLACE Replaces files.\r\nRMDIR Removes a directory.\r\nROBOCOPY Advanced utility to copy files and directory trees\r\nSET Displays, sets, or removes Windows environment variables.\r\nSETLOCAL Begins localization of environment changes in a batch file.\r\nSC Displays or configures services (background processes).\r\nSCHTASKS Schedules commands and programs to run on a computer.\r\nSHIFT Shifts the position of replaceable parameters in batch files.\r\nSHUTDOWN Allows proper local or remote shutdown of machine.\r\nSORT Sorts input.\r\nSTART Starts a separate window to run a specified program or command.\r\nSUBST Associates a path with a drive letter.\r\nSYSTEMINFO Displays machine specific properties and configuration.\r\nTASKLIST Displays all currently running tasks including services.\r\n[?25h\n\n\n\n\n\n\n\n\n\n\n\n\n\nTASKKILL Kill or stop a running process or application.\r\nTIME Displays or sets the system time.\r\nTITLE Sets the window title for a CMD.EXE session.\r\nTREE Graphically displays the directory structure of a drive or\r\n path.\r\nTYPE Displays the contents of a text file.\r\nVER Displays the Windows version.\r\nVERIFY Tells Windows whether to verify that your files are written\r\n correctly to a disk.\r\nVOL Displays a disk volume label and serial number.\r\nXCOPY Copies files and directory trees.\r\nWMIC Displays WMI information inside interactive command shell.\r\n\r\nFor more information on tools see the command-line reference in the online help.\r\n[?25h", "runtime_modules": [ "C:\\Windows\\system32\\conhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "CustomInstallExec.exe-2D9C1A95D0F847641FEC94D2575F3C32": { "file_name": "CustomInstallExec.exe", "file_path": "C:\\Windows\\system32\\CustomInstallExec.exe", "hash_md5": "2D9C1A95D0F847641FEC94D2575F3C32", "hash_sha1": "768E5C32C946C2B71C0DBBC577ABBF4087C8B8EA", "hash_sha256": "F7E9E640085AAA1AD10B0E486A85DA3753F8C532B9F11202152E27A7A86F089C", "hash_sha384": "D1C08BF54B3262D3EF8978B2A6CDE26483A616A171583695AF4CE6FA261B9A03C52ACCEE7095C332859320746EA30004", "hash_sha512": "10F56FDF4D5EB9218F84B39189D4D2F28A646B96EA4923FA919B3508391854542918CCD7A61CEB10AF11397EDCAB05640BA183003D7622578015A73C1E614C12", "hash_ssdeep": "1536:TojGI8jwL9/ApyiEcgPhpP5ysQ/d1+d1txfTFGsp/VbGJgHVmnlc7DR/S33N:w0wLWPENpxysq1+dBfrlBGJg10ODR/", "hash_imp": "932FD25545AE94A1CE9C7E00FD2ABDFC", "hash_pesha1": "7B4B796B62A9B534857D614CE094F9124F698B54", "hash_pe256": "296A395734DAF201ECDE7F7141B3C55B72F8C8F7DDF163A0547DAC17F31F0ABC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Store Package Dependency Installer", "meta_original_filename": "CUSTOMINSTALLEXEC.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f7e9e640085aaa1ad10b0e486a85da3753f8c532b9f11202152e27a7a86f089c/detection", "runtime_modules": [ "C:\\Windows\\system32\\CustomInstallExec.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "DataStoreCacheDumpTool.exe-C4374D34436E1E1F659DC17490310CC9": { "file_name": "DataStoreCacheDumpTool.exe", "file_path": "C:\\Windows\\system32\\DataStoreCacheDumpTool.exe", "hash_md5": "C4374D34436E1E1F659DC17490310CC9", "hash_sha1": "6B471E8CFD8AB4E0884905457FAE5573925EA5B6", "hash_sha256": "A751ED722C10FCF97EE15C98214032C4537929B09CE752A840200E6B6BC9E032", "hash_sha384": "A04676AB14FF606641BD070BE2AEE27D4E928E9D0266CF4D36F4A25522DF83E442DA097BEC39487E3C686046AB9AA9EA", "hash_sha512": "C8A073F45580F6094F557B3D69805C5C085AB44A705BE685D75D31CC20AD2F2C6D2999D4FE4917B0F8ED6A3CAF7D86A4526290FAC81325A6DB1005B116C1F462", "hash_ssdeep": "3072:uIDclqSx5tkDXI6DqU1Zx2Uab5/5v9rBXnBLpFRyedyRol+2Kn:uIYoq5Ej1Zx2Uab5/RjrXKn", "hash_imp": "C491B3BD905877FC1C844F4EF62647C9", "hash_pesha1": "32172B679D1F443888343AA729063F3A75D05F87", "hash_pe256": "4B662CD0B744D7DC83444FE64C2CB8519E3F7A272F6CF92035E5419C087C80D1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a751ed722c10fcf97ee15c98214032c4537929b09ce752a840200e6b6bc9e032/detection", "runtime_modules": [ "C:\\Windows\\system32\\DataStoreCacheDumpTool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DeviceEnroller.exe-1041383E30E1920B4678E89A4BB18F9C": { "file_name": "DeviceEnroller.exe", "file_path": "C:\\Windows\\system32\\DeviceEnroller.exe", "hash_md5": "1041383E30E1920B4678E89A4BB18F9C", "hash_sha1": "8B0F34D60EED4583F82F764A11DCE4B00048A4A7", "hash_sha256": "B9ABAA487AB9F4F25EC61A98485766FB4D6EE97C4B0ECB202C23B9807FEEBC9B", "hash_sha384": "44262A0E713B4BA7DBC33ED069B3056A0AA0FC6F8414BD5306CF26EEE8479DB853DCF208BA1A3DDA295FA860C61F728D", "hash_sha512": "86C9F0F80AE8288E5579A2F6F4DD9FFFAB0C7EE2FF4A9145248DACB2003FE8F8D019D565404D9F06ECD543B5EC3624FA6985817E0461DE78040033BB52BDFF16", "hash_ssdeep": "6144:z9phZbNsvOdG4FF87Vb5fB3Doz5gUPXk/2mZ7HZTRIhsVcJw16F:fhZq487Z5fBTW5gU+2U5TRImcJwo", "hash_imp": "4C5FF3E49D0CFA853B183D09EA0613F4", "hash_pesha1": "11C7CA145DDE39718651485F3537478846050AE4", "hash_pe256": "46979DFB2E0AB7E6B0CEF177E2A066C9F297A06C21A7D70C9103FED3222A2763", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "API for MDM Enrollment", "meta_original_filename": "deviceenroller.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/b9abaa487ab9f4f25ec61a98485766fb4d6ee97c4b0ecb202c23b9807feebc9b/detection", "runtime_modules": [ "C:\\Windows\\system32\\DeviceEnroller.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\dmEnrollEngine.DLL", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\system32\\CRYPTSP.dll", "C:\\Windows\\system32\\iri.dll", "C:\\Windows\\system32\\UMPDC.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\system32\\DEVOBJ.dll" ] }, "drvinst.exe-7CE4D740E3B60338CB4ABDEA9744371C": { "file_name": "drvinst.exe", "file_path": "C:\\Windows\\system32\\drvinst.exe", "hash_md5": "7CE4D740E3B60338CB4ABDEA9744371C", "hash_sha1": "5AEDE130F364410373B91D10FC767F2C32B1D5C9", "hash_sha256": "FA4BE1F424EC5B2D68C54652C3ED3E9C0189F5B4E1BE532B07807E2817B03F2D", "hash_sha384": "C79507A9628FC1979DFCC660946F8D9AE2D185E02BA751BC407FC17C649A47870E92E35D262904E16F8171AE5FFB8E41", "hash_sha512": "074382CAD5D5F43CF2302FFBAB6677B437023F73FD47C7ED91C273C57D37B453C0E4DF636CD89898B8D8661AE4A80FC1D5E449F98E2B0AF671C60DE3386C7E5F", "hash_ssdeep": "6144:Md+YnIoLzaX8Bx8iW+ACHgpGh++IOWjYTll:e+EIwzRv8f+ACAsh0OWjYJl", "hash_imp": "C403B07CA1498FF165F2D0545FAF0C57", "hash_pesha1": "F2E3357691E712BCF511B0D0885641F72A8F1FA4", "hash_pe256": "F5EA3C8D2FDA2220EF37F595D2E395B11430E701F57E94811DE00ACB0037D264", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Driver Installation Module", "meta_original_filename": "DrvInst.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/fa4be1f424ec5b2d68c54652c3ed3e9c0189f5b4e1be532b07807e2817b03f2d/detection", "runtime_modules": [ "C:\\Windows\\system32\\drvinst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dsregcmd.exe-F77A026636AA594B6A75EBA9CE157B76": { "file_name": "dsregcmd.exe", "file_path": "C:\\Windows\\system32\\dsregcmd.exe", "hash_md5": "F77A026636AA594B6A75EBA9CE157B76", "hash_sha1": "89639FE6E862D074068EF77620FC32CB4DECD12F", "hash_sha256": "94E9C63044E4C789896C9747340319E85053A16A69AE5BE0F22A2645BF11D472", "hash_sha384": "EC31283CA2EBF6300BB316646DF10293D663111ED53C793BAAD8B62F2602A57FDB71F384EC8FF6315D0AE243331FA813", "hash_sha512": "97AFDA6C1615EC651A05294ABDF11594071273D9254AD8907BCC9B935CD453769525C1EE3233806AA8C16EB4267A50E218CC1FADA34F4D81223C834CD539DC44", "hash_ssdeep": "6144:z0TUHV8egnGJK4nM07pIV4klKKFc3e17dwGfdHZlTyrCHVMFbACJnRnDX:E3egYK47pq4kldiu17PJjl1TId", "hash_imp": "C2D1A2C9FFEA6DDBC11DE8E37CF589D3", "hash_pesha1": "7A7B44F79D8DA580BF487972742DD85BDA1F388A", "hash_pe256": "74658E480E080A9FB2401CC4D86108ECCA3C74B0F0C1CFBD2950B6A6A93E1746", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DSREG commandline tool", "meta_original_filename": "dsregcmd.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/94e9c63044e4c789896c9747340319e85053a16a69ae5be0f22a2645bf11d472/detection", "output": "DSREGCMD switches\r\n /? : Displays the help message for DSREGCMD\r\n /status : Displays the device join status\r\n /status_old : Displays the device join status in old format\r\n /join : Schedules and monitors the Autojoin task to Hybrid Join the device\r\n /leave : Performs Hybrid Unjoin\r\n /debug : Displays debug messages\r\n", "runtime_modules": [ "C:\\Windows\\system32\\dsregcmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DWWIN.EXE-62A69C0D15AF353430245A12EE9970E3": { "file_name": "DWWIN.EXE", "file_path": "C:\\Windows\\system32\\DWWIN.EXE", "hash_md5": "62A69C0D15AF353430245A12EE9970E3", "hash_sha1": "1D62AF1A76092A8D307847E2828FFD9EFFA9C32B", "hash_sha256": "38BE333CD288A2E17A7E0E82925B57BB8A949E6E4EE5DC16C6B68A57A6BCBB7A", "hash_sha384": "583ADCDF0862FC6F1FE2AF0929E233263A9ED04910C4A1FA09F2C3E3EE780F887A6F406B333444027667CC15EFBFC379", "hash_sha512": "1D32D723BE536350A46B2B21DFE8A833781CE5EA5B33891507153990C19A2B1E8CFD29CFFC8950A282AD897FCBC15A068F1B013C0FFDB0DA19664DC41E70FAE1", "hash_ssdeep": "3072:Xf+lhn9C/wBjG6/nvUjMlfbpyClJdvtLySs5lM0RbT2VC7a5wA74s7iTxf1zHcU:whn9Sw5nUjYpPBtLi5lM8OVCKp7it1z", "hash_imp": "FE9551C19FFA0B0B4EC670BA900DCB7F", "hash_pesha1": "8461CC7D6D40CAB1869CEFCFA52D2EABB3F6413A", "hash_pe256": "D31F0E9167B659382DD35C71858735979DDB24717EDBE4F3429F39E300A59E26", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Error Reporting", "meta_original_filename": "DWWIN", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/38be333cd288a2e17a7e0e82925b57bb8a949e6e4ee5dc16c6b68a57a6bcbb7a/detection", "runtime_modules": [ "C:\\Windows\\system32\\DWWIN.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\system32\\wer.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "fontdrvhost.exe-AB10FC03FDC2DA3FF6FFDC18FC436C65": { "file_name": "fontdrvhost.exe", "file_path": "C:\\Windows\\system32\\fontdrvhost.exe", "hash_md5": "AB10FC03FDC2DA3FF6FFDC18FC436C65", "hash_sha1": "ABF50E3E518683D3BB832D8D8AE738F2D8151A09", "hash_sha256": "418FBE7F21915384A1A87010DE7CDBF86690B497999547E6C5BE93FBA8E91FF7", "hash_sha384": "05BD8343B4B3B35CEEC05AD114B61394F165FC5217C17B1AA112AB47BB6688A66AEE7496A89870FA7B0A6E31CD4A3C7C", "hash_sha512": "402B1099F7C60D79A21C852A092608C49A6DBA64915FB664F4D02908C1363A949BB6EAD7222D669983FA985CB43D0B7C83C67770286B9845FB9866A4588EA604", "hash_ssdeep": "12288:unJQhYKmRvF7hud+xinPVorE5ZlaAqHsLdPRMrpfZ8O1XA1gA0geEhDA1clm:/YKEvLLiPVyEtXpeNhA1JYUDA1cU", "hash_imp": "6F99B3F14EB64D3801C2C98B4B171BF8", "hash_pesha1": "930090E93AC05C9427C17E311778B838C830C8A6", "hash_pe256": "C32E481B70EE3B1EEA11860476E21FED8F3D85CF071AB4884126DEA6DDC15A6B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Usermode Font Driver Host", "meta_original_filename": "fontdrvhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/418fbe7f21915384a1a87010de7cdbf86690b497999547e6c5be93fba8e91ff7/detection" }, "FsIso.exe-63AD8D6E7B22287EB23DFB33DA2BD8FE": { "file_name": "FsIso.exe", "file_path": "C:\\Windows\\system32\\FsIso.exe", "hash_md5": "63AD8D6E7B22287EB23DFB33DA2BD8FE", "hash_sha1": "880D6C7B5A0A66F2F36CD0F0509356C5AAF9633A", "hash_sha256": "FF419466845F99A7E5AAC084150BBD4C0A2A4AAAEF2118F8AFA41716B8790E88", "hash_sha384": "963F010F76CC15CA7002943EA53BDDE3C5035BD72F75EB5074CCA0C1963E3C3D2FB0979E46AE87C54EE5B8004141E0EF", "hash_sha512": "F1296643F5E1AAEB0B655C42A62E881EC345F31CB4E715041081CF9E7CB399649BE8B5A2797BDF572FB3624C441F83433CC2B78F19E3713974E845919B3BE32D", "hash_ssdeep": "1536:fep6LVdosYWZau3+p9kxQqZzNiLyCKs79sLP3u9Qy0xIrLPPL:feEwHWZau38kx39Mhb5sTe9QROL3L", "hash_imp": "54FDA49E38FC53ED5FD39A6AE34568E0", "hash_pesha1": "B4963E7B7A18CC57689FCB7EFFE1D6248441DC25", "hash_pe256": "72C06E8495BBE7E9CDEB9B9398BEE23971AA2B9CFE1BC8BA27F454369DFBB08B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Secure Frame Server Helper", "meta_original_filename": "FsIso.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.329 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.329", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/ff419466845f99a7e5aac084150bbd4c0a2a4aaaef2118f8afa41716b8790e88/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\FsIso.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\IumSdk.dll", "C:\\Windows\\system32\\iumbase.DLL", "C:\\Windows\\SYSTEM32\\IUMDLL.dll" ] }, "hvax64.exe-FC2BA24B78F9F1BDEB9BC06167394F7A": { "file_name": "hvax64.exe", "file_path": "C:\\Windows\\system32\\hvax64.exe", "hash_md5": "FC2BA24B78F9F1BDEB9BC06167394F7A", "hash_sha1": "4F895A2327EE8A91E1471D65AA7001D51C92ED5E", "hash_sha256": "FBDE7CFE00144490EE095F7A28F67C69EFE74FF8710CF8C9A8D98AC9EB6B8599", "hash_sha384": "1B6667735FCAEBA7C6B7F93DCA4A166487A77172C7A8B726A6C985DAF38F193649439A72545F27BC7BA17C8977CCFFD6", "hash_sha512": "1528CECF4D960A55199E6D427048CC46B3931EDA1E6D728C3CF1E0ACA836B7847219C2D65D74D7AFA3EDD3EDBD9FC938342DE1C1101B4E97E0B4DC71C39D59DE", "hash_ssdeep": "24576:T9ytVds7Mk9X3mPNgTw8l1dPpJ+jCK9UNoIjDp2:Ks7MUHmPgv+v9UKs2", "hash_imp": "D5AEC1C1F764856CFB4155CEE3321234", "hash_pesha1": "952FB911AD5916F62FB062551533A2E68B9E9652", "hash_pe256": "B3218BBBE8441305559E6AFE4BBEB73AE428687D2001D3D00CAC8C2D14A9C910", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hypervisor V2.0", "meta_original_filename": "hvax64.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/fbde7cfe00144490ee095f7a28f67c69efe74ff8710cf8c9a8d98ac9eb6b8599/detection", "runtime_modules": [ "C:\\Windows\\system32\\hvax64.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "hvix64.exe-81EDB42BDD9D6A64FBBD2A15FF3C11BD": { "file_name": "hvix64.exe", "file_path": "C:\\Windows\\system32\\hvix64.exe", "hash_md5": "81EDB42BDD9D6A64FBBD2A15FF3C11BD", "hash_sha1": "F5B7CF4887346F16C847E465F28805A72D5D0CAB", "hash_sha256": "98A70B131D9049DC45AE86E5153D17E6E611ECA66C19635F8336B88A6DE3D6AA", "hash_sha384": "6B18F4DB224FE0A291224632B19109AED4BC258E1BFCF2C9E554D2BB56B9984793D4274B619AAA45FCDA64727CBF0CE2", "hash_sha512": "CAA6FEAEC737FFA7D3C8212867681701A80245F340A6D95197A0B052413291A224F38F0BF0F98961061847A614099CBFC3DB1D01EFBF3E747FEB69C10C1FF699", "hash_ssdeep": "24576:zVJbHJhyoySIFpFn8NTuOCXt9c6Jf3o5V/LXqXJhH+uds42gUpUQjhWcFKaq+TRo:vyRF38du5cY3WU3HEmoUQtVKr+TR0TDn", "hash_imp": "D5AEC1C1F764856CFB4155CEE3321234", "hash_pesha1": "9777083DF8C06220ECB07B7BE7F3ABE7D0652E2B", "hash_pe256": "D2A3C55103B951B529BBE2D7748FE8E6D6BF69CFC82CA394F3AB327A9364CBCE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hypervisor V2.0", "meta_original_filename": "hvix64.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/98a70b131d9049dc45ae86e5153d17e6e611eca66c19635f8336b88a6de3d6aa/detection", "runtime_modules": [ "C:\\Windows\\system32\\hvix64.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "hvsiproxyapp.exe-DCF8F469454EAA1C513DFEDA5E89D4CA": { "file_name": "hvsiproxyapp.exe", "file_path": "C:\\Windows\\system32\\hvsiproxyapp.exe", "hash_md5": "DCF8F469454EAA1C513DFEDA5E89D4CA", "hash_sha1": "8FF44EA27A329332E763EAD557C086E32182B717", "hash_sha256": "CB722F4D47E6477C16E7373A8C0C16905C5105AEADC0B4479785103001F070CB", "hash_sha384": "53E547B709838470694773C22D27AC69F5ADECCC2006AEB2C293C289555630003FE03D3221C9EC00FEA46967B552A2B0", "hash_sha512": "D114025D64EF9E0A23DB8D3B0E9E73A75B02C373DC61FEE2E32D1C8BBF2A77F0CC2C1A22031069E0B6B1239998176884D579508996252E14458828216173FEC2", "hash_ssdeep": "3072:0jbizQyYBjNZPaSC/cRe+vXxGt/Nln7Bumw2hg:0n/HPaf/cRe+vXxGZb7U2h", "hash_imp": "3307EF43A6791CF6DBB79F1906C90828", "hash_pesha1": "60E57754BA2099AD4D93C2FF9156ECC9FE98FB5E", "hash_pe256": "C933063EF6F7AD0540B6A3DAEE312D58DBAF6AA36442C3E5FFA882AA8CA48B4C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/cb722f4d47e6477c16e7373a8c0c16905c5105aeadc0b4479785103001f070cb/detection", "runtime_modules": [ "C:\\Windows\\system32\\hvsiproxyapp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\WTSAPI32.dll", "C:\\Windows\\SYSTEM32\\urlmon.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\System32\\shcore.dll" ] }, "HvsiSettingsWorker.exe-248B44158748F3C7DCA5277360818C54": { "file_name": "HvsiSettingsWorker.exe", "file_path": "C:\\Windows\\system32\\HvsiSettingsWorker.exe", "hash_md5": "248B44158748F3C7DCA5277360818C54", "hash_sha1": "557E2E91C0812F3D3ECCF2D420C0D40FE782B398", "hash_sha256": "A9A61B8D6CF706AAC9C7CEAC78988A85CA05572E128E316B41262701FA86267E", "hash_sha384": "C70858002DF2C641D9A32C6EEE377CD967E2391E0B5AE3EA6DA9AEB607EA086E6F9FBCA5B7500426720EA26449462390", "hash_sha512": "0A389BD9100D256E04E84B8A5C486BE1EFCD087B6FFDCF9F63B745814B0BA73EF3D162DF0D40B150E260EAFD5CC18CD605C7C6A55737EAAE4B3AF4D36AA3CEAF", "hash_ssdeep": "3072:8fs+BgDF7a7j00jQQw/QtkR0NUQNOncC4fYzd1e4cx1:+s+BgGY0MQw/QWaNXlfSd1b2", "hash_imp": "73FA5FA64AFF60B2BF419F3ED6B8BE1A", "hash_pesha1": "5F624731D3882BE56BBFB1F95B2A53ACEF084410", "hash_pe256": "EBE131557B261FD840492FA3FE132E01B329091F9102ABE4F0E504FA5350E4B2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a9a61b8d6cf706aac9c7ceac78988a85ca05572e128e316b41262701fa86267e/detection", "runtime_modules": [ "C:\\Windows\\system32\\HvsiSettingsWorker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\HvsiSettingsProvider.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\system32\\WTSAPI32.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\Bcp47Langs.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\FirewallAPI.dll", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "IESettingSync.exe-85E0E12767A3DF758C97ACB31C6F3C81": { "file_name": "IESettingSync.exe", "file_path": "C:\\Windows\\system32\\IESettingSync.exe", "hash_md5": "85E0E12767A3DF758C97ACB31C6F3C81", "hash_sha1": "EF4C7AE36357E0A0B6DC44DC0A0CD13E22C65D55", "hash_sha256": "0AF12C71E0DFE450EFBE6464F19430E2C9AA48B5729AB558817AC71E3050A68D", "hash_sha384": "E6596E5B3E90EB46CB288CB5533369DA59D18F1A46AB37AD0E7C9153ECC596A9C0A647DA60FB6948F940DCAD690774A5", "hash_sha512": "A915730BC580CC0DECC18C81F9075E2C109D4CF634686CA062645AB4BD287615C00B816AC331CAB6919C60AA7B7CB49650CA3EA904B3932235A931872EB9181B", "hash_ssdeep": "12288:5QmkkQzOK24lRjd8PG9Xxqg2NEeq71Z/0f6DgBpU:5QmbAOK24lRue9Xxqgi1qYf+gf", "hash_imp": "4F00D504881D899D006AA39F1A427096", "hash_pesha1": "D571A516296221AE8ACE844BB15D42446E6F55CD", "hash_pe256": "85C1524022DB07086D51C0D88965890D4CE4D59EFB2C7E56F826914A4C7D568F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IE Setting Sync Background Application", "meta_original_filename": "IESettingSync.exe", "meta_product_name": "IESettingSync", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.19041.610 (WinBuild.160101.0800)", "meta_product_version": "11.00.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0af12c71e0dfe450efbe6464f19430e2c9aa48b5729ab558817ac71e3050a68d/detection", "runtime_modules": [ "C:\\Windows\\system32\\IESettingSync.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\system32\\UMPDC.dll", "C:\\Windows\\system32\\SspiCli.dll" ] }, "LaunchTM.exe-1F20DC3E0AA92B3E4A449F65FFAD1A54": { "file_name": "LaunchTM.exe", "file_path": "C:\\Windows\\system32\\LaunchTM.exe", "hash_md5": "1F20DC3E0AA92B3E4A449F65FFAD1A54", "hash_sha1": "E43B01CF95FD1FC538C6164D59ECBC4116C5EFD6", "hash_sha256": "A80F5DB6CFE14A4A5C4BBEADCDBD8F329C61578FDD6F336C128074DB11421E79", "hash_sha384": "84A8F48E2DD98BFB93E3B2766B17389F30DB45ED2184A1ADBC5B7D7201E14442D6E20469020AF534B55E831B8D1723E9", "hash_sha512": "91F159D27921B1C7BE91C06538FB9ADFA27B8E9157B7541B2039A4DDED5D7031EF6E30B6FCE9A452F5758FAFE104E415561ED1C0DEC897087A903F7C21E83464", "hash_ssdeep": "192:JgvRQ0/cEyT/uufqR1MFtG1pd1fskvB0+WIqayW:ARsxT2lLVp/jBpWIqayW", "hash_imp": "AD4CEE994BCE4BEC755FC55C249B5C5F", "hash_pesha1": "0FF12155A5781556B5DC49378BBDE0604CE8257E", "hash_pe256": "80697D91B83A2601D971F85D261F0E3739D703B2A3F5699A2B69A94B15D3EFA6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Manager Launcher", "meta_original_filename": "LaunchTM.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a80f5db6cfe14a4a5c4bbeadcdbd8f329c61578fdd6f336c128074db11421e79/detection", "children": "Taskmgr.exe", "runtime_modules": [ "C:\\Windows\\system32\\LaunchTM.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\SHCORE.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\SYSTEM32\\windows.storage.dll", "C:\\Windows\\system32\\Wldp.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\profapi.dll", "C:\\Windows\\System32\\CFGMGR32.dll", "C:\\Windows\\system32\\edputil.dll" ] }, "lsass.exe-CB662E24CADF976EEFED93E9373D45D2": { "file_name": "lsass.exe", "file_path": "C:\\Windows\\system32\\lsass.exe", "hash_md5": "CB662E24CADF976EEFED93E9373D45D2", "hash_sha1": "B544386912CEA1C1DB67CEA82439E17AD27BC20F", "hash_sha256": "56E91451FEAD9946ACA8E2F0AAE99FDEA302FD90F0708F68013BDDEDAB580F3B", "hash_sha384": "9B36696AF4F0A137ED626826B530B96E994368FEE9B74185787A8E5A1A81CEB21C887BCE6508B56CFAF28B104C41AA1A", "hash_sha512": "946B49843A35C58B4E86B04D699D4856152E945F03F6B4763B572D66F9E73BE3EC2342BEC6CA53B9B0E30EB5B208DF057AD5029C4FBBF694C78F783CB1E589B9", "hash_ssdeep": "1536:35JpE9iBd8GwcGaRShIJkw9b8ueL7fqMQgyHv+4gPIsY:bO9iBd8Gwcp0BdLwP+HQsY", "hash_imp": "09FDE88C65E2BC5F1F90E96B673C52B1", "hash_pesha1": "3C4FCC2647587E34CBCA30304FB447D6F1A2951F", "hash_pe256": "2E7BD3C3D9BE0CCCE61929BF13DCD957EAC0F7E9E1C0E988F3FB8BD183328067", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Local Security Authority Process", "meta_original_filename": "lsass.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/56e91451fead9946aca8e2f0aae99fdea302fd90f0708f68013bddedab580f3b/detection" }, "MoUsoCoreWorker.exe-3EBF79D6BDDE4D6D566E460E11CBC497": { "file_name": "MoUsoCoreWorker.exe", "file_path": "C:\\Windows\\system32\\MoUsoCoreWorker.exe", "hash_md5": "3EBF79D6BDDE4D6D566E460E11CBC497", "hash_sha1": "B23A4B75408B417BD15BA3B029AFDCCA38A66D38", "hash_sha256": "A4414D96BD4BA8E42656966171F2A78A7AE9F1D0700CDD04B0801C1DDAE38AC6", "hash_sha384": "212525D83E5B02ABB2064A444F53786C3B46D1B8CFF2F60F92682385E8D35125CD2A044795DADAE64249F620D2581283", "hash_sha512": "002DD7D3E948DD33EE0A5F4D9AB2A843433B1CC7F0F7A2D16BBCFF2BA01B8F42BB229156A77ACD95D71DBBDECF885E120BCD87900791390F48561F24E0981030", "hash_ssdeep": "24576:eXF1XqblSgUYKSy30vXbzSntzDRNhATmFPxtsG3Cp:GpqwnRvR/ATmhtC", "hash_imp": "39233DDAE71CD9D2B0CA5AA6FDD61054", "hash_pesha1": "80285CC1EE43DD47009458C18CC194D3D738EE3B", "hash_pe256": "38C54805231D005D7308F81C688252AB829AE6B796C0A3544F451D86B1808512", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MoUSO Core Worker Process", "meta_original_filename": "MoUSOCoreWorker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a4414d96bd4ba8e42656966171f2a78a7ae9f1d0700cdd04b0801c1ddae38ac6/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\MoUsoCoreWorker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\dmiso8601utils.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\UMPDC.dll", "C:\\Windows\\system32\\UpdatePolicy.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\system32\\winsqlite3.dll", "C:\\Windows\\system32\\profapi.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\system32\\Cabinet.dll" ] }, "MuiUnattend.exe-1DE290CD4183EAEBF34DE700274C0DB8": { "file_name": "MuiUnattend.exe", "file_path": "C:\\Windows\\system32\\MuiUnattend.exe", "hash_md5": "1DE290CD4183EAEBF34DE700274C0DB8", "hash_sha1": "623EE12EC860D543A900697908BDC93026499A86", "hash_sha256": "3FE9FA358A03426BA327B4C70FE581303500BA5791844715ACF7911FEC5D2DEF", "hash_sha384": "6B96588A197A5A48602CE64FAB60D393A0A753596419DD43D111DB3C206BD7D6B86186A6F73C7D59E88AED3D0EE0AF4E", "hash_sha512": "E5318743D7E9CD3A868899554EA886FAE3523FD83D6DF6199BCD6CC9CCCC1D90E1197FCE8AFAB6FAE7CB25027C77A5F6C52B2C31B4B9C82297A5EF2C12E2AA72", "hash_ssdeep": "1536:8H3bs9Ctb6EHi3Ll5YBK5bTHNhRjkqgVn+LlM2Huo9lY+KAbDnhrHXtD+:yHi7l5igbTHNhRjkqgFDhUiyZDI", "hash_imp": "8294C508F274BD27CF6CD858E5F05B86", "hash_pesha1": "29742E15A0714D7EB067F0F131E282442A6D9CE7", "hash_pe256": "3E1D051AC7A127C9FD4186BF43D49DF716B4F955740FDC27AF29F53654803C13", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MUI unattend action", "meta_original_filename": "MuiUnattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/3fe9fa358a03426ba327b4c70fe581303500ba5791844715acf7911fec5d2def/detection", "runtime_modules": [ "C:\\Windows\\system32\\MuiUnattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "nltest.exe-396EC29E0B1F77824E6479D8D810D315": { "file_name": "nltest.exe", "file_path": "C:\\Windows\\system32\\nltest.exe", "hash_md5": "396EC29E0B1F77824E6479D8D810D315", "hash_sha1": "5E2FEB9DD4EF65A59579A53BF6240E1A630ADAC4", "hash_sha256": "A0AB27588BAA72C13F1BDD3A59CC6B76B1C9789EF9E30F0B8BEF968316BE77B5", "hash_sha384": "B0C1FA42B5F40A8803D7B2F9F3A62ABA9F66B53DD495ACD241465432A6E98BA428EFFB9FD40C6D8FCA6FA421374BA93C", "hash_sha512": "EAC37CAE455A235959028FD8C68DEFD8806ACA07E2BAEB197D8B0EEA68A086781F1BADBDF6617DB0F93E1ED2E8EBF20BCA36F6AF6C6921BCFA1311C586DC9140", "hash_ssdeep": "6144:fhCtTfmDzLPxjpOMUoikXV3OV87zWzN0cOXXn3:f4q/PxjpEzJ", "hash_imp": "BDE16641FA6CCBD4479899C4CA44D983", "hash_pesha1": "39B470A4537784860CDAE537B1C2221CE902ECE3", "hash_pe256": "07C4C6449B0C92752B301F34A28EB76C6D8FBB7D60A7A8D6F0DC4341084B1144", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Logon Server Test Utility", "meta_original_filename": "nltestrk.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/a0ab27588baa72c13f1bdd3a59cc6b76b1c9789ef9e30f0b8bef968316be77b5/detection", "error": "Usage: nltest [/OPTIONS]\r\n\r\n\r\n /SERVER:<ServerName> - Specify <ServerName>\r\n\r\n /QUERY - Query <ServerName> netlogon service\r\n /REPL - Force partial sync on <ServerName> BDC\r\n /SYNC - Force full sync on <ServerName> BDC\r\n /PDC_REPL - Force UAS change message from <ServerName> PDC\r\n\r\n /SC_QUERY:<DomainName> - Query secure channel for <Domain> on <ServerName>\r\n /SC_RESET:<DomainName>[\\<DcName>] - Reset secure channel for <Domain> on <ServerName> to <DcName>\r\n /SC_VERIFY:<DomainName> - Verify secure channel for <Domain> on <ServerName>\r\n /SC_CHANGE_PWD:<DomainName> - Change a secure channel password for <Domain> on <ServerName>\r\n /DCLIST:<DomainName> - Get list of DC's for <DomainName>\r\n /DCNAME:<DomainName> - Get the PDC name for <DomainName>\r\n /DSGETDC:<DomainName> - Call DsGetDcName /PDC /DS /DSP /GC /KDC\r\n /TIMESERV /GTIMESERV /WS /NETBIOS /DNS /IP /FORCE /WRITABLE /AVOIDSELF /LDAPONLY /BACKG /DS_6 /DS_8 /DS_9 /DS_10\r\n /KEYLIST /TRY_NEXT_CLOSEST_SITE /SITE:<SiteName> /ACCOUNT:<AccountName> /RET_DNS /RET_NETBIOS\r\n /DNSGETDC:<DomainName> - Call DsGetDcOpen/Next/Close /PDC /GC\r\n /KDC /WRITABLE /LDAPONLY /FORCE /SITESPEC\r\n /DSGETFTI:<DomainName> - Call DsGetForestTrustInformation\r\n /UPDATE_TDO\r\n /DSGETSITE - Call DsGetSiteName\r\n /DSGETSITECOV - Call DsGetDcSiteCoverage\r\n /DSADDRESSTOSITE:[MachineName] - Call DsAddressToSiteNamesEx\r\n /ADDRESSES:<Address1,Address2,...>\r\n /PARENTDOMAIN - Get the name of the parent domain of this machine\r\n /WHOWILL:<Domain>* <User> [<Iteration>] - See if <Domain> will log on <User>\r\n /FINDUSER:<User> - See which trusted domain will log on <User>\r\n /TRANSPORT_NOTIFY - Notify netlogon of new transport\r\n\r\n /DBFLAG:<HexFlags> - New debug flag\r\n\r\n /USER:<UserName> - Query User info on <ServerName>\r\n\r\n /TIME:<Hex LSL> <Hex MSL> - Convert NT GMT time to ascii\r\n /LOGON_QUERY - Query number of cumulative logon attempts\r\n /DOMAIN_TRUSTS - Query domain trusts on <ServerName>\r\n /PRIMARY /FOREST /DIRECT_OUT /DIRECT_IN /ALL_TRUSTS /V\r\n /DSREGDNS - Force registration of all DC-specific DNS records\r\n /DSDEREGDNS:<DnsHostName> - Deregister DC-specific DNS records for specified DC\r\n /DOM:<DnsDomainName> /DOMGUID:<DomainGuid> /DSAGUID:<DsaGuid>\r\n /DSQUERYDNS - Query the status of the last update for all DC-specific DNS records\r\n\r\n /BDC_QUERY:<DomainName> - Query replication status of BDCs for <DomainName>\r\n\r\n /LIST_DELTAS:<FileName> - display the content of given change log file \r\n\r\n /CDIGEST:<Message> /DOMAIN:<DomainName> - Get client digest\r\n /SDIGEST:<Message> /RID:<RID in hex> - Get server digest\r\n\r\n /SHUTDOWN:<Reason> [<Seconds>] - Shutdown <ServerName> for <Reason>\r\n /SHUTDOWN_ABORT - Abort a system shutdown\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\nltest.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ntoskrnl.exe-247F07BED19389B12AA2EC550FB5FF90": { "file_name": "ntoskrnl.exe", "file_path": "C:\\Windows\\system32\\ntoskrnl.exe", "hash_md5": "247F07BED19389B12AA2EC550FB5FF90", "hash_sha1": "81CB5B2B8521AE59B3BF932CDDC04100C581F5DA", "hash_sha256": "ADBA735E87F72021A87D10E67710F15B44486A0720711A324E03849DA528834B", "hash_sha384": "F2C71948C05FA8A0A67DCDAA8AEED3C222FB9B1BB86B87FE1FBA3C8B96D47E5580559F52DC61AD6B4B2A0DA39293ED01", "hash_sha512": "18106F48EA8D6A86E1115A871E21108B9EBBB96557EF5A753619408990307BB255B93FD8E382F1816AA81ACBDC4C610EA52D32FD34D93B8D336FBA6CFBABED58", "hash_ssdeep": "98304:RdfRjVM5rIaScBStSelf4fuX75jbr5uyOLTSfu1jOVu1giesSezNluj:JuRSwUSelf4fuX75jbr5uycDjO8Wi5pC", "hash_imp": "E0E869BBD92F59B58E146BA81EEE3F6D", "hash_pesha1": "23A330A84B293ACA2898B7195D655F4A39289631", "hash_pe256": "991E62450BA177BA5CD74235BD7EC5780D7EDF31DD2D335BD2EEDE95FA4B2B2A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NT Kernel & System", "meta_original_filename": "ntkrnlmp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/adba735e87f72021a87d10e67710f15b44486a0720711a324e03849da528834b/detection" }, "poqexec.exe-542B537B7547E4BB334D1D3DA7A9A17C": { "file_name": "poqexec.exe", "file_path": "C:\\Windows\\system32\\poqexec.exe", "hash_md5": "542B537B7547E4BB334D1D3DA7A9A17C", "hash_sha1": "C2A27AB8BDB0891C5D3167E498B143E9E570B1BC", "hash_sha256": "C0C8FFC51F4BF8DD4154BCA0A55839BA360364B7D50377CE06564B24CBC6F09C", "hash_sha384": "BD5ABFABF1D7E8BAB94120A9643BF1B3DCFFFBAD3A44F814B492D9D38A94ACB4CCFADEF4A4074FAF1C19BAE56122595D", "hash_sha512": "7B8CBA30CA5BE6C01C9E1ED549BE9F469191889B2E97B9898B34E5EEB58499F32B6DE5E1DEEC5D3932AAAE0AD657DB4E4850B921AF8F5FE951595156A755B99E", "hash_ssdeep": "12288:ba08Hr0ycItJ3KEoz8XQ1C+1TEpt9MpkFoxrInyH5q7l:h8HrPj3oymC4TGMGmxrL5m", "hash_imp": "BD47FF03174DF83245815823DFE013EC", "hash_pesha1": "E1CEC342A12CFBD3F75EBDEE488E602EA3D7B77E", "hash_pe256": "776F139DF2848FDCD8508A0A3909D1EE4FD41E00D04237C9DB172311BF8864D6", "signature_status": 2, "signature_status_message": "The file C:\\Windows\\system32\\poqexec.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Primitive Operations Queue Executor", "meta_original_filename": "poqexec.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/c0c8ffc51f4bf8dd4154bca0a55839ba360364b7d50377ce06564b24cbc6f09c/detection" }, "ResetEngine.exe-09C06B0224F439DF8666CF7B411B7B1C": { "file_name": "ResetEngine.exe", "file_path": "C:\\Windows\\system32\\ResetEngine.exe", "hash_md5": "09C06B0224F439DF8666CF7B411B7B1C", "hash_sha1": "DE53FC67D1E8995A4F068EEC644CA11844879ADF", "hash_sha256": "16F7DFCC1ECDCC2783A031510D413EDD98182A1BD117CB2DFEB2153768426CA5", "hash_sha384": "99FFB6EE8F265A4F904F7C84096A99D5918651671B98F14592EE9038945F4E4D534FB871BFE48E65FEFE7BD59CCC4620", "hash_sha512": "7BE18F5100E7314FB3815F4D014E65F8A980E8B58D2D3A1676F249B387FF8D599EB11AB1B44E8639A98DC5D98AB3C936BD6017BA9E38F538CF4973702AA94F87", "hash_ssdeep": "384:FlfHLUNi4m16fs41swWfeWEr6wDDBRJ54JeRlYA:/rC7LshEr6wD1PyK", "hash_imp": "D1CCC9D0A0240603DC3279F82F80F8D3", "hash_pesha1": "A0FEF7CC9095C0357A17D5E91109289643329260", "hash_pe256": "E983117C052D9BF74E26C1E9DFD0C509E18808A5832C9E2183464CDE25EA0D61", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Push-Button Reset Engine", "meta_original_filename": "RESETENGINE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/16f7dfcc1ecdcc2783a031510d413edd98182a1bd117cb2dfeb2153768426ca5/detection", "runtime_modules": [ "C:\\Windows\\system32\\ResetEngine.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\ResetEngine.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "runexehelper.exe-E4B7BEDE4746B36BA8CD92A4EB03AD2A": { "file_name": "runexehelper.exe", "file_path": "C:\\Windows\\system32\\runexehelper.exe", "hash_md5": "E4B7BEDE4746B36BA8CD92A4EB03AD2A", "hash_sha1": "99109627310CA8024913444A106AC6E11A51FF10", "hash_sha256": "8485B0A140AF4E1A83526DB121F95D866BA51A1E6092D61B7E78E32EBBB0E228", "hash_sha384": "D1804600BD62A18E24FB321AD01749DB1460A30FADD178173CE1CF74B093516D6088597FCF9E5D01B1C777C9ADAFC354", "hash_sha512": "E023BA839FC84B88D1724DB1E6022AD2840F3EB4342219DBAB265994CFE2B73E06A2003C431C27EA2BD498D41372C366FD00948F904F14DB49CE36D348904086", "hash_ssdeep": "1536:cdRi2fgLob1qyzzC4P2BBmh845ueTxUSg/:c/nb8qzC4PmU8Sue6", "hash_imp": "E66B94547D97B956C966DB1C1C41DBD6", "hash_pesha1": "902336CB5080347E55DB8C1C8847373C0A0EE295", "hash_pe256": "84855290796193FA7F53AFA4F591F8F502AFA22122548F8E27C9237ADB8710E6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/8485b0a140af4e1a83526db121f95d866ba51a1e6092d61b7e78e32ebbb0e228/detection", "runtime_modules": [ "C:\\Windows\\system32\\runexehelper.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "schtasks.exe-8A0C868920214321438EABFBD0E93BC2": { "file_name": "schtasks.exe", "file_path": "C:\\Windows\\system32\\schtasks.exe", "hash_md5": "8A0C868920214321438EABFBD0E93BC2", "hash_sha1": "EF173058B6BDA8B7E0C1A56B63A9E504E463D2DA", "hash_sha256": "1AC5741B075111E49CB16B1BD3A00EEF9B03FF6F34244CE05512DA7B66165936", "hash_sha384": "96D3C74151A57C544F1C89A7AF9F2FC7074A9AFA6CC843359849850CFBA406622DE4F8B16DA7A06093F251864A5B8115", "hash_sha512": "507F0BF477D095DF67B40633B8CF842FBBA2845C7FFDA03950D20C11CA51EB65F5D023CCD36EFC6C5A1E0D8EE7B6B6310A48CF2432D6E7593F8B32B4FBB512EC", "hash_ssdeep": "6144:FJa++aMG+mHjDygbk23dJuQEWiGJtpHZbJnzf9B:+aMSHjKWiGJtpN9fD", "hash_imp": "67E0780CD4E2405CEB6CBEC4EB6999F9", "hash_pesha1": "91B4760349B8C76C7B6299EAB0899177AEB5077C", "hash_pe256": "842E40C4B0A197DB8EC77ED78EE551BDAE1B8B566993438144ACA7967EF49F0A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Scheduler Configuration Tool", "meta_original_filename": "schtasks.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1ac5741b075111e49cb16b1bd3a00eef9b03ff6f34244ce05512da7b66165936/detection", "output": "\r\nSCHTASKS /parameter [arguments]\r\n\r\nDescription:\r\n Enables an administrator to create, delete, query, change, run and\r\n end scheduled tasks on a local or remote system. \r\n\r\nParameter List:\r\n /Create Creates a new scheduled task.\r\n\r\n /Delete Deletes the scheduled task(s).\r\n\r\n /Query Displays all scheduled tasks.\r\n\r\n /Change Changes the properties of scheduled task.\r\n\r\n /Run Runs the scheduled task on demand.\r\n\r\n /End Stops the currently running scheduled task.\r\n\r\n /ShowSid Shows the security identifier corresponding to a scheduled task name.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n SCHTASKS \r\n SCHTASKS /?\r\n SCHTASKS /Run /?\r\n SCHTASKS /End /?\r\n SCHTASKS /Create /?\r\n SCHTASKS /Delete /?\r\n SCHTASKS /Query /?\r\n SCHTASKS /Change /?\r\n SCHTASKS /ShowSid /?\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"SCHTASKS /QUERY /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\schtasks.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "sdclt.exe-B0C397303D58CCC9E27BF71073E46F49": { "file_name": "sdclt.exe", "file_path": "C:\\Windows\\system32\\sdclt.exe", "hash_md5": "B0C397303D58CCC9E27BF71073E46F49", "hash_sha1": "AEE738CF3F4D541BD0964D065BED7F00CA443B65", "hash_sha256": "1558A9DC9D6749DDA20A1846CD26887486AF40C569C9A1DEB911C43A78A61978", "hash_sha384": "69A5EFF1D3406293C8F35B0DFCDB20CF52A99C2F2FBEBF051571F42FCD780DA273EBD495BA79B0EA568F1F494C79CBFB", "hash_sha512": "DD661785D2CD88F5C0B0AD3D0BD2CA619D7AC402AB0034B002F4713231A3B4499BB2AA08EEC3B4C8F98AA262D21C1C691B40D11466689A61ED52ECFFE0404C26", "hash_ssdeep": "24576:MJjr1lDybzUNu/oCexLLIh9yptQHZ7RHegR:I9N2oHL0aQ5dH9", "hash_imp": "1F4349F0C287A904C0483B5CD434DF28", "hash_pesha1": "4F85C7D7D15E8ACC1AB02AEB6B69225EF2ABF0BB", "hash_pe256": "24DA4585652C7E758CFCE71E432EC00D65DA3944F79BBF3D4851040B07D41CCF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Backup", "meta_original_filename": "sdclt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/1558a9dc9d6749dda20a1846cd26887486af40c569c9a1deb911c43a78a61978/detection", "runtime_modules": [ "C:\\Windows\\system32\\sdclt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\SPP.dll", "C:\\Windows\\system32\\wer.dll", "C:\\Windows\\system32\\ReAgent.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\VSSAPI.DLL", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\VssTrace.DLL", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\system32\\WTSAPI32.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\system32\\DPAPI.DLL", "C:\\Windows\\System32\\IMM32.DLL" ] }, "securekernel.exe-C03B99DA5CB6E65B9055B1BC6B972AD7": { "file_name": "securekernel.exe", "file_path": "C:\\Windows\\system32\\securekernel.exe", "hash_md5": "C03B99DA5CB6E65B9055B1BC6B972AD7", "hash_sha1": "4DD2F4C88ABA790BB3B7029E57FBC5C63CDD8458", "hash_sha256": "96E7806B10255D429A05EA93C36FCFEDA8A4C3B7C7A9E7AC06342A3085512762", "hash_sha384": "52BFB39B564A452380E0E72331D840A834788CB2AB2EF154BBE6C6CB950354A90D2CD1570C9BDC5E20F2BE5C4C9533CD", "hash_sha512": "1EA65F8A69D3353891EFB21C5AC99167123CA8531181A8D448D43A33DD20BADE37A0DDE5759A5D9F3DBF3940B16F2B98EFF7E24242A8683EAA6706A5B9BA2DEC", "hash_ssdeep": "12288:ySuydwHJmS/d3BvqxvRitgUfAr0MKWjFZVir9OXN/elJYFHaRttttZ3OLzH0Cb7R:Nbg/d3qaMjFTG0XgwFHQttttR4HlL", "hash_imp": "18399EDE6C02958819045C1CB263C0B9", "hash_pesha1": "034C06C41E429E977EA44D0AEB7EA64DE279AF12", "hash_pe256": "301F83353998503ABC9465E5345DCD06CFF498DE71EAC54A62156F9C5A57ECF9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NT Secure Kernel", "meta_original_filename": "securekernel.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/96e7806b10255d429a05ea93c36fcfeda8a4c3b7c7a9e7ac06342a3085512762/detection" }, "SecurityHealthHost.exe-09318E2C571D00C8AA0FD478BBA7FB76": { "file_name": "SecurityHealthHost.exe", "file_path": "C:\\Windows\\system32\\SecurityHealthHost.exe", "hash_md5": "09318E2C571D00C8AA0FD478BBA7FB76", "hash_sha1": "9643D8C9B8C5A6056047F94FBB85724BA012414F", "hash_sha256": "690DA9B46E5F3F4C15344266E88FB2B4760D54E2F33E8FA1D4AD1329E1F7BA6C", "hash_sha384": "751D57A09F6A881B30906B57356207862ACBA3F85E5DFA015A1092E138530DFAF544F6077E34DE50DC2CCD10B43ECC87", "hash_sha512": "56E06598284FD93E105E08C3C984052A070A4A1E065C8CBD398624B4A26E0B3B6B953AD06F1C2295379B4A88CC255DAD9B66572F4ED11F7CEBB0E3B2D6F85B59", "hash_ssdeep": "1536:Ui7x3sT6ALT1T3nFr68IVtTLjnQiJxYtGAi+J8hgiHbodPGTL:GNVFhgLDD3hysodq", "hash_imp": "4E28FDA241BEFA94F219E0683850258F", "hash_pesha1": "880EE59E0C0F0AF1EF15A0800E9A09762402E15B", "hash_pe256": "6CF280F20E73625B77CCD7E46C6A95F05C573C643D4FED0A2BAA30D8989D68D6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Security Health Host", "meta_original_filename": "SecurityHealthHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.1907.16384 (WinBuild.160101.0800)", "meta_product_version": "4.18.1907.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/690da9b46e5f3f4c15344266e88fb2b4760d54e2f33e8fa1d4ad1329e1f7ba6c/detection", "runtime_modules": [ "C:\\Windows\\system32\\SecurityHealthHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL" ] }, "SecurityHealthService.exe-4F1EEF1FF02D11D9134E26478C88749A": { "file_name": "SecurityHealthService.exe", "file_path": "C:\\Windows\\system32\\SecurityHealthService.exe", "hash_md5": "4F1EEF1FF02D11D9134E26478C88749A", "hash_sha1": "5FD4406017DACE6C58D12F8878C59807751FDE03", "hash_sha256": "265D4D30A5998C7F38BA187300CAC868107826DC93A82E4009A887CAC26B1FEF", "hash_sha384": "D70B0D531472A152B8E87B4FEC8BD32EB1CA6F3579C97DD8E943638D17C905A664B0F17113006E18B75D5773C0B5D11E", "hash_sha512": "BA84CB221A15EFC92E443F5A5A14D5ED349C822EFC74AD9BB035FA33C35721F93FD45789956D822CBBF69CC912EB3963C01440C5A90B279995B355810371037A", "hash_ssdeep": "24576:mSO4f21Gdm1jBzPIrBimsmzVntc0fTum9+L:mlpdIYSnRTum9+L", "hash_imp": "2601842F772C1F9ABA3AAD89180D20E0", "hash_pesha1": "C6A80942BBA57165B8D0491DF5069A69B17E3D74", "hash_pe256": "DEF0E25F9EA5C42BEF5B8820CB408EB8FF92861311C5F36CB4B7ECB45D52E6F8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Security Health Service", "meta_original_filename": "SecurityHealthService.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.1907.16384 (WinBuild.160101.0800)", "meta_product_version": "4.18.1907.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/265d4d30a5998c7f38ba187300cac868107826dc93a82e4009a887cac26b1fef/detection", "output": "Unknown switch.\r\n" }, "services.exe-448CC197BC3B10D3E36A2CD30CF32DFE": { "file_name": "services.exe", "file_path": "C:\\Windows\\system32\\services.exe", "hash_md5": "448CC197BC3B10D3E36A2CD30CF32DFE", "hash_sha1": "C64D109BF116EEB3705BAED974FD54AFDB87DC9A", "hash_sha256": "2E18DC3466566DF55792D6AFAD818D1E28FFA2C32017770A959419736DB577EE", "hash_sha384": "A6647E2008B28A4A4F6B17D55F4A94A22BD94B82687A9F315E4AF893EC6BAB9429F675054C4920C1CD1973CF276989F7", "hash_sha512": "814A4E794B8565FBB86241BE02AAEC7DFC8C57A158EB2F824CE96C505A6232884655333859D2C3A79039E785C12CD085090A9E683B9DBB49F836A8E94BEFE19F", "hash_ssdeep": "12288:+Ft8MDQW0yNuJTCqxoG7CNmWQzTDQaXcdBTDFXY2X/o0wjy4Y:+4yvUTvxt7CN50QGQNI2X/o0wuD", "hash_imp": "3E8F35E928E235EAB2F768AE3F697C62", "hash_pesha1": "621E1F4EBE288F44D569E09E1A83DA3173392700", "hash_pe256": "50F23B15B9FB4ADDE1764E8D9AD76A4BCA0F65D46B6B8939150EB4034B0BE210", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Services and Controller app", "meta_original_filename": "services.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2e18dc3466566df55792d6afad818d1e28ffa2c32017770a959419736db577ee/detection" }, "SpatialAudioLicenseSrv.exe-3020DD6621DEBF4E1B8315EA7D9D7DD9": { "file_name": "SpatialAudioLicenseSrv.exe", "file_path": "C:\\Windows\\system32\\SpatialAudioLicenseSrv.exe", "hash_md5": "3020DD6621DEBF4E1B8315EA7D9D7DD9", "hash_sha1": "0351D27AFC6509568CEC81B90070961D756C84D1", "hash_sha256": "3C010EF9CE445CB95805937AB5172BBECB15E6B5EB8D662B174742BC08C7DCFC", "hash_sha384": "8B99869A9BEEDF40453852032BB62D740B2A00A355D5C5C5DC2C38F99F10945AE7D3F59AB98D5F9539883702028DFA1C", "hash_sha512": "390887764F4491EF80D2828960466B079A778D9B1C32E8B00330D3BA8D8AD729545F2800EDF14B0359916077A02AC24C78BECB131427C4D4F94ABBB635270FDE", "hash_ssdeep": "3072:9lyFjABNr9Rrx7hoxPXIC7IckrB/N8Cozx5wWA2savkkXgddWBRvMqV8rxcy:EAp+XIC7FCozxuW5cGGc", "hash_imp": "ABB101FE9A06CD5E31B234938EA2320D", "hash_pesha1": "44DA6682E40BB91AF23B032684451C5639F4DC12", "hash_pe256": "53A20347991524BA43F080614AC97598E1F4734A09D03584F03A7D8BF4D7C2B5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Spatial License AppService Broker", "meta_original_filename": "SpatialLicenseSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/3c010ef9ce445cb95805937ab5172bbecb15e6b5eb8d662b174742bc08c7dcfc/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SpatialAudioLicenseSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll" ] }, "Spectrum.exe-BAB70FA030162B32CED3DA7D034940B8": { "file_name": "Spectrum.exe", "file_path": "C:\\Windows\\system32\\Spectrum.exe", "hash_md5": "BAB70FA030162B32CED3DA7D034940B8", "hash_sha1": "AE54F026D1B121017FF4F6080342C1270E90E2B9", "hash_sha256": "AFF3D4AB8B126FA099E6B7C6899C0C7FCCD04401C5AC1890C96C689A65CD16B1", "hash_sha384": "BED72835D0D959663E09ABCAD23B2B0EF8C9226ACA2C2FEEF80EC142DAF6C89571765BBD64F8BD9428C25DB7E257E007", "hash_sha512": "C51ACCFF8BA45244200A27ADE5B44B85134E874B8D1A1244A4D5903968614AB545081DCB4B4893F7150ECC081F15E0F2870B44A1DC0D73DE229F86DA3B538B40", "hash_ssdeep": "6144:rIEp1wJUYJpBb+qkysObJiMzTv5J54tTeXMbNyV7dNJQMlX5Hq62ZCLOJ6RF7FMO:rdp1mNE+lJR3v1aeZtQ+K62cxFkrS", "hash_imp": "2D430AF2F5D536907F1205720822457A", "hash_pesha1": "BAE24C2A99210F458CA885448CE7D49C87C95CF9", "hash_pe256": "5343AEFFCFBAFAC96147A8A20FD74EB5305DEC59710B4CFD93FB1CB9F192B5CD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Perception Service", "meta_original_filename": "Spectrum.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/aff3d4ab8b126fa099e6b7c6899c0c7fccd04401c5ac1890c96c689a65cd16b1/detection", "output": "Unrecognized parameter: --help\r\nParameters:\r\n /debug to run the service executable in debug mode\r\n /safemode to set up the service to run in safe mode\r\n /safemode:off to disable safe mode if enabled\r\n", "runtime_modules": [ "C:\\Windows\\system32\\Spectrum.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "spoolsv.exe-C98A3A0395AE60D108CBED7ACEBC0531": { "file_name": "spoolsv.exe", "file_path": "C:\\Windows\\system32\\spoolsv.exe", "hash_md5": "C98A3A0395AE60D108CBED7ACEBC0531", "hash_sha1": "76931B75A68EEBFF58FC38A1C8D40159E98DB54A", "hash_sha256": "00AC7E58DFC2F6757C0C2268EB441E4E8FB317427840971A1049011CD2888A35", "hash_sha384": "25A7CBC8ECC5D5145BC2B2893C6C590EAC71306FC060A44A6D8E542ADCF9B311685C089A6CEEC054189C4CA3DB9C3582", "hash_sha512": "A06123C622EFCDCE4934E83B56280273AB029E0D094DA273A1404301A7CC685C031600B145AE5CAD6659250879F0D5FD60740A1CBFA414554101F205996C26A6", "hash_ssdeep": "24576:7uhB4Q43JLDzWBYnuesJLK27QDndkYQQZsU9ocTwSb105K:7u74n3JLDzWBYnuesJLK27QDndkYQQZV", "hash_imp": "6D527F52CF7772DC1BF45147E1BD0544", "hash_pesha1": "8050CB6D401955725C6B4775EB4471F6CB3A6E4F", "hash_pe256": "63D9053CC4354C4EFA3F3349530B72748DD61125E99BF213484C9675C679D954", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Spooler SubSystem App", "meta_original_filename": "spoolsv.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/00ac7e58dfc2f6757c0c2268eb441e4e8fb317427840971a1049011cd2888a35/detection", "runtime_modules": [ "C:\\Windows\\system32\\spoolsv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "SppExtComObj.Exe-84EBE9E2E54272C01CBA8F1B5AD40EBD": { "file_name": "SppExtComObj.Exe", "file_path": "C:\\Windows\\system32\\SppExtComObj.Exe", "hash_md5": "84EBE9E2E54272C01CBA8F1B5AD40EBD", "hash_sha1": "AC9E64DACF8BE4AD0F9D59D93272DCC4C07A346A", "hash_sha256": "0EDD19C320B603E2DF71CF6CE90844DC3ABDF4CDDC4B6DAAE1675704C8B84DEC", "hash_sha384": "0B2391B35FC68CE3264260CF26D80A64D90274CDEFFF83D3CDB0749FE0CD2898E53D32D1EA8BE17F41B0CA2C71B6C783", "hash_sha512": "121CDFFD1A3407CEC4AA1485D11F6BB6AF61CD78995340702713DB2BA3C6602E234E1CA414ED72D82FD25F478604E1FDF6C575A5AF4D9F136CCB6E291BC03D00", "hash_ssdeep": "6144:TBWCvetky4MaPTV0ridMroOdInoG25Mijp5GlD77zCNpFlX8sV8gJCexTP9kIQGs:TBGyPP++edIXiNuW/FxT9kIQbw/HE", "hash_imp": "4C96B0E079D994B8689C66F7872425EB", "hash_pesha1": "3512515CC429776849E8466CE4DE2767C8068815", "hash_pe256": "2589240DAEDA5152026BA36BF5A6DC057A83920C5C3996A27A6B10C6EC516303", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "KMS Connection Broker", "meta_original_filename": "SppExtComObj.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/0edd19c320b603e2df71cf6ce90844dc3abdf4cddc4b6daae1675704c8b84dec/detection", "runtime_modules": [ "C:\\Windows\\system32\\SppExtComObj.Exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\system32\\ACTIVEDS.dll", "C:\\Windows\\system32\\adsldpc.dll", "C:\\Windows\\System32\\WLDAP32.dll" ] }, "sppsvc.exe-64384A7CA0834695460AD8D80945DE9C": { "file_name": "sppsvc.exe", "file_path": "C:\\Windows\\system32\\sppsvc.exe", "hash_md5": "64384A7CA0834695460AD8D80945DE9C", "hash_sha1": "50A3035376C6F6351D38B3029C37AD2496BC9441", "hash_sha256": "FB0371D958BCC0ADE0B75C4EF7072296B1A0E16E05A1193B37068F44765BD12A", "hash_sha384": "AA15C830BD6BAE3768C10F0F151DBE412E3EC3C2E7D8A186F289C9C79199847AD0D6666B4C0DADB834440AB80F86A7BF", "hash_sha512": "8EB0EE039AE7B185DC73A73D03C115C10A1AD1E4E72FBB51DF85B703AC53B459ADAB8A9B77C5738CFCD5737F3DDB2F5725A305A010D67822C7F9AAAB990EC543", "hash_ssdeep": "98304:snZqizyePIQcw/NG2i8nujmaQn9WCsRCG5sDhWMGn:snDzyePIQfRi8nujmp9WC9G5cOn", "hash_imp": "865C812E4E3E6E8C398A0757574C8DA3", "hash_pesha1": "46EC971764E9BC5A0721FC3C0FC4BF7CABAF6C29", "hash_pe256": "A26B6EBF5395ABC795C07C17BC229C2C490C50ACA1223F6E1A28603AD88B57E1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Software Protection Platform Service", "meta_original_filename": "sppsvc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/fb0371d958bcc0ade0b75c4ef7072296b1a0e16e05a1193b37068f44765bd12a/detection" }, "SysResetErr.exe-3CAB51BC753E5A3B1C029CD7B987BC1F": { "file_name": "SysResetErr.exe", "file_path": "C:\\Windows\\system32\\SysResetErr.exe", "hash_md5": "3CAB51BC753E5A3B1C029CD7B987BC1F", "hash_sha1": "CE333A58B0C16756F15FB401ED117FB909AB70D0", "hash_sha256": "27F03DC93FA9362B72565F8F193F56800063C708395DC3DEF584CFD34B96DECA", "hash_sha384": "F0AB70948584FC014DFD8A2A0511E7EA17C0DE788A2F17624C298B79F9A043B420B17AF3E4A81628C0247D58E6C635CF", "hash_sha512": "484C2F2AD5E4637629B7F05FAA27ECC9272A81E0CBCFDDA9C34645EDEBC8EB4EC92E6EB87F15B5A4AA79E65E5044BE84CFD8093A488B3532607F600C9941F8C3", "hash_ssdeep": "768:hYNRFEviZppsecI+WChGhzsSNcgOQp+kyH4r6wD1PpCz:hYNRF7s7I919jp+kyHWPQ", "hash_imp": "94756B15804C0785AB207C72059C788E", "hash_pesha1": "709348150FB5F55BADAC02212FD83D1990832704", "hash_pe256": "A26CC787EABB1C01E985A044409E6968780108BAC6F2E2E9614D3277C9776825", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows System Reset", "meta_original_filename": "SysResetErr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/27f03dc93fa9362b72565f8f193f56800063c708395dc3def584cfd34b96deca/detection", "runtime_modules": [ "C:\\Windows\\system32\\SysResetErr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\WDSCORE.dll" ] }, "systemreset.exe-BC34993578A955D1215F5B475A056EC0": { "file_name": "systemreset.exe", "file_path": "C:\\Windows\\system32\\systemreset.exe", "hash_md5": "BC34993578A955D1215F5B475A056EC0", "hash_sha1": "6E3C8A0256A7E463EDC609BCB1B8B01C05D8A099", "hash_sha256": "E0A8451C708C5B30A3B703F009FE68F7EB903359AB525BC86FF9303FCD68360A", "hash_sha384": "75AEBFD9563273A33CFDBCF0F61744D3CD7DD502AD226CDEFEF4655918038623C287D244293071C74A2FDE1757F34DA0", "hash_sha512": "6D2BBBFEB648711DD35CADF1A67EF04C346466D3D450877B36D5E89593932E64459B0AC4272CC82C63635D978CACC28E00CB0C95E569CE0EC45553C2D86C6B19", "hash_ssdeep": "12288:dgpFRJj0HM469MP3PQaC84S4M9Ox8z4B:ypjJQM4BP3hbZz", "hash_imp": "8B0F5D4A63127835DC3CA54D48C2BA57", "hash_pesha1": "CBCCF889E5FA6B6D2375ACFE61A06A54D5C40FD3", "hash_pe256": "48751680B5F5495B46D09034914C80D0FFF1E510E10E43ACD2A1731DBAC39F13", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Reset for Windows", "meta_original_filename": "systemreset.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/e0a8451c708c5b30a3b703f009fe68f7eb903359ab525bc86ff9303fcd68360a/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\systemreset.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\SetupLogSection": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(RW-) C:\\$SysReset\\Logs\\setupact.log": "File", "(RW-) C:\\$SysReset\\Logs\\setuperr.log": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\SystemResources\\Windows.UI.Immersive.dll.mun": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\Windows.UI.Immersive.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Windows\\System32\\en-US\\bootux.dll.mui": "File", "(RW-) C:\\Windows\\System32": "File", "(RWD) C:\\Windows\\Fonts\\seguisym.ttf": "File", "(RWD) C:\\Windows\\Fonts\\segoeuisl.ttf": "File", "(RWD) C:\\Windows\\Fonts\\seguisb.ttf": "File", "(RWD) C:\\Windows\\Fonts\\segoeuil.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\systemreset.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\ReAgent.dll", "C:\\Windows\\system32\\WDSCORE.dll", "C:\\Windows\\system32\\ResetEngine.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\system32\\WTSAPI32.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\system32\\DismApi.DLL", "C:\\Windows\\system32\\FVEAPI.dll", "C:\\Windows\\system32\\profapi.dll", "C:\\Windows\\system32\\WIMGAPI.DLL", "C:\\Windows\\system32\\tbs.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\system32\\Cabinet.dll" ], "runtime_window_title": "Choose an option" }, "taskhostw.exe-AF8D8590B0F74A7F514438DF3F1F4C22": { "file_name": "taskhostw.exe", "file_path": "C:\\Windows\\system32\\taskhostw.exe", "hash_md5": "AF8D8590B0F74A7F514438DF3F1F4C22", "hash_sha1": "91896DF7DFC43D7018E10781C8AF392559BED7F7", "hash_sha256": "72279AD47EED7FBF2472214824696351B9CB2571B8EE5D8C92FADA23B378D812", "hash_sha384": "024E5B20311E6AC92017CE75BD9975BD66CDB5092D8976E614C56873467F79A269E3A754110A77D6ACF4091D629D9BBE", "hash_sha512": "966E9B793EAE2C522AE627C0CAECCD919382CB4B260BD6E830E4E106B3B5838744DE3A54C271466ED59E5260D4A5D7E207BBAC43A63259D1BBBA6B3E9D73C113", "hash_ssdeep": "1536:+1ZCzBzDm9RGtcpHyxlLfE38VsPPh2mBqXh+M2fBBjrg8KMOg7pPd:0Ezp1tcJyxlLfE38wP7sXh+nfB5g8KM7", "hash_imp": "3A0C6863CDE566AF997DB2DEFFF9D924", "hash_pesha1": "B714F79561971686E83C2A9A3B38E864B4D24FA8", "hash_pe256": "6288F6548D4DA4EA4EC6298B72E2DA21580F859B0BCD108E983C265851AEB8CC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Windows Tasks", "meta_original_filename": "taskhostw.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/72279ad47eed7fbf2472214824696351b9cb2571b8ee5d8c92fada23b378d812/detection", "runtime_modules": [ "C:\\Windows\\system32\\taskhostw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "Taskmgr.exe-BBDA546A4ABF0D49C7F67EF9F8FE1E61": { "file_name": "Taskmgr.exe", "file_path": "C:\\Windows\\system32\\Taskmgr.exe", "hash_md5": "BBDA546A4ABF0D49C7F67EF9F8FE1E61", "hash_sha1": "68183C4C677633D422248C3EF8EBCDDE138C4025", "hash_sha256": "83C76DB0CC6940E9C653F346A560090BE2B782168B3E04AD8BBAC791D33272FA", "hash_sha384": "B19A0ED92DDCE442BC5E71544D1E5948677318F7A6F8C59729384686DCBDEAFE0FC60B9F8DB81842149BA747D478F207", "hash_sha512": "36B1F18202892D83904A4C5252C101924897D332799F094712EA3CB853A24080751D7131CC725A6AC845E6F28AB77DDD1467229BABD795DFAEF211628FC2A4A6", "hash_ssdeep": "24576:yXt9CnmDYfI0q1F39GCchAdaamxka+KvgUHg05n421d1WUq:UHuI0q1F39Ahdka+KVg05n421d1w", "hash_imp": "6C979042BFB94D319299531016A3C673", "hash_pesha1": "3152209B5A9108D8FA0DCF7D515021DDDF10362E", "hash_pe256": "1C6E04E6CD0C42A3331B64DDEE5B93B22F1B24294B38DD67E46F95654DE1ABC7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Manager", "meta_original_filename": "Taskmgr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/83c76db0cc6940e9c653f346a560090be2b782168b3e04ad8bbac791d33272fa/detection", "children": "explorer.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\System32\\en-US\\Taskmgr.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme722103516": "Section", "\\Sessions\\1\\Windows\\Theme1800662698": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\Taskmgr.exe.mun": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\Sessions\\1\\BaseNamedObjects\\C:*Users*user*AppData*Local*Microsoft*Windows*Caches*cversions.3.ro": "Section", "\\Sessions\\1\\BaseNamedObjects\\C:*Users*user*AppData*Local*Microsoft*Windows*Caches*{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000008.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_16.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Taskmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\\COMCTL32.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\credui.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\pdh.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\system32\\dxcore.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\system32\\d3d12.dll", "C:\\Windows\\System32\\SHCORE.DLL", "C:\\Windows\\system32\\UMPDC.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "runtime_window_title": "Task Manager" }, "tcblaunch.exe-CB69B5DE01ABC9EFD103FF2E06CB86D3": { "file_name": "tcblaunch.exe", "file_path": "C:\\Windows\\system32\\tcblaunch.exe", "hash_md5": "CB69B5DE01ABC9EFD103FF2E06CB86D3", "hash_sha1": "54595B2A4E3E8E50C6F6798FF40C28AD770D42D5", "hash_sha256": "49BA88149A7F58094860887E593592651CB15C475239566F1B39BFC373F73B12", "hash_sha384": "244FC247C944890B7F6B92463FCA53D839D3747BAC8B9F85B9F9E9F265EB3B063A96CAC7383C3707DD500BF6B44F26AC", "hash_sha512": "E3B7BFACC9570D1D0C2984047DF15745CA30B83B29B6B587B8C785E426E0E85E55740FBAC1EC66C5897C246048E72649E46CCE9FE1D64D3E1E7FF93B96884FC9", "hash_ssdeep": "12288:gl6JqKeG/EAZinGZqzscfSrPm0VO2QzxtbSX+Tj9L/D:gl6JeG/E+inGusHPmNn3++Td", "hash_imp": "n/a", "hash_pesha1": "69636AF699DED0BF8A70A52277E1E6B8FCDED6D3", "hash_pe256": "4379E0C6A704D8E22B34AE1CFCE1013DBD0709F7581CD22388E821F358E23685", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCB Launcher", "meta_original_filename": "tcblaunch.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/49ba88149a7f58094860887e593592651cb15c475239566f1b39bfc373f73b12/detection" }, "UsoClient.exe-0713F7831AC1247123C2C02864D17E6B": { "file_name": "UsoClient.exe", "file_path": "C:\\Windows\\system32\\UsoClient.exe", "hash_md5": "0713F7831AC1247123C2C02864D17E6B", "hash_sha1": "CEA0C16BFEFA040B15BA098506292EC4B0F17B25", "hash_sha256": "85E6F2D57908B4B6095D3FD01D6488AF4B4E8664658048525DDDEE7CD8D1BFE4", "hash_sha384": "386DE3AE5C453760BE337ADAB34FF872C58B31CD7C6C52CED18131F9D514B99C1CD66E1B73BC030F4CD174A3F234DE3F", "hash_sha512": "6A9886F14AF96BF05533E5531F2B82DCD5E673E2167C442E32161BD013F87080D589F5DC2D4F42CAF566C99397A2308B7AB5F7D8ECFEC4A84373F6A2AB28DC39", "hash_ssdeep": "1536:grE4qAXFQtrwF9azElGFk3yFx3RDoVmOILIVI6KvV5imo5:A2rjzaGFk3yFx3RD4HILIJKN5fo5", "hash_imp": "CDD14B0D34C0DE2114AEBC3998CDE3E7", "hash_pesha1": "453E00A847022FBE097E9E4451F9489D2A8E0A0B", "hash_pe256": "E2494C838DF502CBC621ED68938D0E34CB6B2C5BC5AAD50E10B70E8093FB0DDC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UsoClient", "meta_original_filename": "UsoClient", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.508 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.508", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/85e6f2d57908b4b6095d3fd01d6488af4b4e8664658048525dddee7cd8d1bfe4/detection", "runtime_modules": [ "C:\\Windows\\system32\\UsoClient.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\UpdatePolicy.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\system32\\profapi.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\system32\\MSASN1.dll" ] }, "usocoreworker.exe-27C961B231DE15DC3CC0D82B6A39B9B2": { "file_name": "usocoreworker.exe", "file_path": "C:\\Windows\\system32\\usocoreworker.exe", "hash_md5": "27C961B231DE15DC3CC0D82B6A39B9B2", "hash_sha1": "CFA1F7346F117712B0A5CCA06E814F6C7C631B0C", "hash_sha256": "6F18C71D9C2F065861656B23402FEBB0CBFFFB95A7976CC6BBF5B602353FC2AA", "hash_sha384": "ADD9FC499B427C1D2A7FD71D010A592ECF1F48326939DE9F792EB11A204C593AE53230905EB1CB7054F1A4253FB914E0", "hash_sha512": "CBD59ABE689820173105AD6560C78D953C2D1E74B0AE956FC34228B1D6A6620C853431290630BA1F6994D7B2AB25BF89EF2887323D6BAD63FA8C7616BDC7467C", "hash_ssdeep": "24576:JNHNxQISVbSxo8GDsmtmVzmJ/yVd1ZX8mK9n5fGaag/CHkGQts9:TMIgRs9DDS9ffGaxCHq", "hash_imp": "5832569D3382CE32D02E5DA0D33C4C13", "hash_pesha1": "A55BA420D49D4793AAE4CE7C144DC4FB49E2BACA", "hash_pe256": "12D60B32B5B52906979790730F6E59F2A4B789E97D5B4E0386D40C4BA0E2D4E5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "USO Core Worker Process", "meta_original_filename": "USOCoreWorker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/6f18c71d9c2f065861656b23402febb0cbfffb95a7976cc6bbf5b602353fc2aa/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\ProgramData\\USOShared\\Logs\\User\\UsoCoreWorker.48feeed5-8047-4052-a7cf-6a713d99a965.1.etl": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\usocoreworker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\profapi.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\UMPDC.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\dmiso8601utils.dll", "C:\\Windows\\system32\\UpdatePolicy.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\system32\\DMOleAutUtils.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\system32\\iri.dll", "C:\\Windows\\system32\\Cabinet.dll" ] }, "UtcDecoderHost.exe-341CF8CFE37C711E3FEE3F05E0F20275": { "file_name": "UtcDecoderHost.exe", "file_path": "C:\\Windows\\system32\\UtcDecoderHost.exe", "hash_md5": "341CF8CFE37C711E3FEE3F05E0F20275", "hash_sha1": "FCA848AB1B38817522D7FA2033DD86A761E1E04A", "hash_sha256": "07493B3176D7CC35A9E25BF4DAE820FBDF7C576C0A6F361D5909518DE289DBA4", "hash_sha384": "9F5C1618A077917EE3F002E2EF5D4975BD038FAF04F76F7537AF02680749BB6B973EBA046505CE96F2BDFDE2D8048381", "hash_sha512": "966B94E5A020BEFF20436B46D4276AD774E1246910EB6F598C8332784B8A5BCBC51FD45234155FACA35C7089A054DAE8110024B561A82A60723FD66C7D068B39", "hash_ssdeep": "3072:0nAZm0OvWZh9GvX6cCQkAqSqy0nYIglJ7QC7deLMb3y8NJG6bnxdD0znEbjio:NIeeLb8nKp", "hash_imp": "0B25406AFEBFAE2E90EEE1EF452D0457", "hash_pesha1": "15A5501E10FC71C2CFD14A1F4A92D83FAC3888A6", "hash_pe256": "49370C52DE2902F935C7A4E1C0FA63B9E47DB2C98CEAF73FBDED52C14BBDE859", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Diagnostics Tracking Decoder Host", "meta_original_filename": "UtcDecoderHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/07493b3176d7cc35a9e25bf4dae820fbdf7c576c0a6f361d5909518de289dba4/detection", "runtime_modules": [ "C:\\Windows\\system32\\UtcDecoderHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "VmComputeAgent.exe-27A860247AA0A240513C743F96053928": { "file_name": "VmComputeAgent.exe", "file_path": "C:\\Windows\\system32\\VmComputeAgent.exe", "hash_md5": "27A860247AA0A240513C743F96053928", "hash_sha1": "B26B7D8C944C555326ADDF5F7CD06C88A9C27FF6", "hash_sha256": "C900FC9627796F92C3CDCFFFA0B6E7781FC8FFD3DAC04BE32549F34E841C030B", "hash_sha384": "C2B32D2E0C0851C007FB304DE8C030E0521E486ADFB1714827FE07FD3DD3A9E87170B948B68A7FA7853098AA018ECFF7", "hash_sha512": "5578759DC5C01B85AA6B3E1EB3AE46DC3D040417E772D0B24563EDCC4AAAC1392C38079F409E9028635348DAAEB060E9DAB909A392232648D4591FE53B9C2FC6", "hash_ssdeep": "24576:XinN0bjahjFcnroNCfGlo/pY+BVigJ2aZV+6brb9qnF:XiN0bjahj+nroNCfl/pY+VJB+s9qF", "hash_imp": "78D6614749B85E892B168EA2E2B6D5ED", "hash_pesha1": "66B777CF93D17FDD188B4940506A086DF3A5A7B6", "hash_pe256": "C3163D5A5D09E8CF343EEC197471616E0761B50CB08A878E2C1873481F4FA4A0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hyper-V Guest Compute Service", "meta_original_filename": "VmComputeAgent.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/c900fc9627796f92c3cdcfffa0b6e7781fc8ffd3dac04be32549f34e841c030b/detection", "runtime_modules": [ "C:\\Windows\\system32\\VmComputeAgent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\container.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\wc_storage.dll", "C:\\Windows\\system32\\HvSocket.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\system32\\GNS.dll", "C:\\Windows\\system32\\wevtapi.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\system32\\CIMFS.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\FLTLIB.DLL", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\system32\\FirewallAPI.dll", "C:\\Windows\\system32\\NetSetupApi.dll", "C:\\Windows\\system32\\fwpuclnt.dll", "C:\\Windows\\system32\\DNSAPI.dll" ] }, "WaaSMedicAgent.exe-A42CE607E8E9B0333F14762AE9C1419E": { "file_name": "WaaSMedicAgent.exe", "file_path": "C:\\Windows\\system32\\WaaSMedicAgent.exe", "hash_md5": "A42CE607E8E9B0333F14762AE9C1419E", "hash_sha1": "26644D06B7B07C0F4FD548FC8514C550C06A0501", "hash_sha256": "85FB7CF779AF202942D7F7E23AA9913484A9252482DAA6E87AB15218CE407147", "hash_sha384": "5CD4EA3D64C86FE5D63D46318AF74E1BEB90086755775BDF2DF75DFF84F5FE25FE38C0C0C8F516EC7530CBDBE3791D2C", "hash_sha512": "38F9CAAC4E66CAFE551FC2D6BE3867A0FD24A30F84FD8DE764F87039D1ECE7B24C3EAC948EB19AAC22F314CC223A9A6190D3FD492D212DF62F56D148C4ACB37C", "hash_ssdeep": "1536:rClV+9a+UI6d3TqUTqsVLwf2FcLCjfg1BKKP4VxGS1a7XHJ7y:rW+whI64UToe6L8fg1BKM4Vx1azp7y", "hash_imp": "8BF2E50F2577178F691B2781ECF73CAB", "hash_pesha1": "38DB68DF05B942EED220E75DEA89559EFF1D9668", "hash_pe256": "ACFD5DA5664ED74431D374AF0BC30BEE2068983ED84034C79E53239FBCF50C58", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WaasMedic Agent Exe", "meta_original_filename": "WaasMedicAgent.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.450 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.450", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/85fb7cf779af202942d7f7e23aa9913484a9252482daa6e87ab15218ce407147/detection", "runtime_modules": [ "C:\\Windows\\system32\\WaaSMedicAgent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "wecutil.exe-2DC4DFFB9B1513E7750CD6BA6D2DD2C7": { "file_name": "wecutil.exe", "file_path": "C:\\Windows\\system32\\wecutil.exe", "hash_md5": "2DC4DFFB9B1513E7750CD6BA6D2DD2C7", "hash_sha1": "DF287B3867B9B241339723C970D5FABD909BF4DB", "hash_sha256": "32E06B5E1ACB62625B9805450F9030ED4E074031C6FA3D769A44F3AC6F5A1598", "hash_sha384": "977C7AA8B4C25229387E9B5B5630F22EA02D01B0547234189C6A781B5059E0B572A23DFAE10C77DA5146B6B03871CFE5", "hash_sha512": "3560ABE0713DAF8E0C29984BD3AEC2B4F40D7F84AD1F968FEB5BAE2D9CEF417821E66D1DC4BFAC3826A67B0788D4FCDDEA27FE2F4EF480D78A02A71BFA6001FA", "hash_ssdeep": "3072:y52vOgyTrK+xYnl3byVA+eZEa+UU4REcB3:y52vcHZibEcZEa13EcB", "hash_imp": "B72EE51C5FE65846BB96655320BB4A02", "hash_pesha1": "77EC8CA30F1E2461C0D56D76720D2913F914CF5D", "hash_pe256": "74A9C8577B6C6211E07051110B9E470BECDC88A27E5535A971537E85F68DD815", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Collector Command Line Utility", "meta_original_filename": "WECUTIL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/32e06b5e1acb62625b9805450f9030ed4e074031c6fa3d769a44f3ac6f5a1598/detection", "output": "Windows Event Collector Utility\r\n\r\nEnables you to create and manage subscriptions to events forwarded from remote\r\nevent sources that support WS-Management protocol.\r\n\r\nUsage:\r\n\r\nYou can use either the short (i.e. es, /f) or long (i.e. enum-subscription, /format)\r\nversion of the command and option names. Commands, options and option values are\r\ncase-insensitive.\r\n\r\n(ALL UPPER-CASE = VARIABLE)\r\n\r\nwecutil COMMAND [ARGUMENT [ARGUMENT] ...] [/OPTION:VALUE [/OPTION:VALUE] ...]\r\n\r\nCommands:\r\n\r\nes (enum-subscription) List existent subscriptions.\r\ngs (get-subscription) Get subscription configuration.\r\ngr (get-subscriptionruntimestatus) Get subscription runtime status.\r\nss (set-subscription) Set subscription configuration.\r\ncs (create-subscription) Create new subscription.\r\nds (delete-subscription) Delete subscription.\r\nrs (retry-subscription) Retry subscription.\r\nqc (quick-config) Configure Windows Event Collector service.\r\n\r\nCommon options:\r\n\r\n/h|? (help)\r\nGet general help for the wecutil program.\r\n\r\nwecutil { -help | -h | -? }\r\n\r\nFor arguments and options, see usage of specific commands:\r\n\r\nwecutil COMMAND -?\r\n", "error": "Command help is not supported. Error = 0x57.\r\nThe parameter is incorrect.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\wecutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "WerFault.exe-7DEF45F3DC7946073D1128FE2D061511": { "file_name": "WerFault.exe", "file_path": "C:\\Windows\\system32\\WerFault.exe", "hash_md5": "7DEF45F3DC7946073D1128FE2D061511", "hash_sha1": "7C6560566535E966989F80E45FC3FEF426B0B48A", "hash_sha256": "F69FF67FD26F7659D6D92C1A6D060D9BC6915E4FE048671C46BB42E57CC64518", "hash_sha384": "8FEC5CDBE087C1939F17B5846419AD0EC9BF4DA271C8D38012A1BA59CEA41981FB8183404DF03547AFA1AD0D983E6C53", "hash_sha512": "4E6A6F6929F8E4CE868CEA6E1A466053FB3961BE50AC74E9685559F4E3A97E087F1EBEE0D98CAFBB717EB0DBF83B1A504FB7846580FE4D66900130BB71D36678", "hash_ssdeep": "12288:809l9MkWWUV8mKTPKbO1CRIOzvlPzc2HywP:8K6HPV8muXOzvlPzcyhP", "hash_imp": "A8411DCFB6906C782549D77E5571DC7E", "hash_pesha1": "0C9932141E14AC6821707902ED7404DA6D73C3B9", "hash_pe256": "0D468C9DD7B8C8F65CCE9177A89FBCD674CE6175A0DE2085B707A21A6D794F56", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Problem Reporting", "meta_original_filename": "WerFault.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/f69ff67fd26f7659d6d92c1a6d060d9bc6915e4fe048671c46bb42e57cc64518/detection", "runtime_modules": [ "C:\\Windows\\system32\\WerFault.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\CRYPTSP.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\wer.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\system32\\faultrep.dll", "C:\\Windows\\system32\\dbgcore.DLL" ] }, "wermgr.exe-E856524BF40EB2A050195C39989C8DD5": { "file_name": "wermgr.exe", "file_path": "C:\\Windows\\system32\\wermgr.exe", "hash_md5": "E856524BF40EB2A050195C39989C8DD5", "hash_sha1": "1844AB985105E15B224EEAFE2820FE5D12E8AE03", "hash_sha256": "23DE870A5147F2E3E9ACA874530394EF1D6F5E68A469A242A8EB1D1669FDFA01", "hash_sha384": "585A51B9CE9118F0896B6AC59C5EF8CF96D7FA2EE1DB6FC1A72F977A6CAA16A0374115C9A4B9E1A9F14CA80410118EEC", "hash_sha512": "A50DBD9B2F31FDDCEEF2F11DEFBAF0DC04C06DE15A99A2C0C3E5347E74537C689D29E447B84344E7073FDEB29B58DB18B25EC66D2438EA9D23138A9DD0826DF9", "hash_ssdeep": "3072:qNRhlAgWx+QvXKpBduvtjtuzd++hpsU+O7FJ+yC3pwRb6JPqB604HHy7hRCd39vr:YR0GHIcdbjsU+OmVJyB60OHyLC7vr", "hash_imp": "70F5990F8FE8FCFC99DCF4D791F596C8", "hash_pesha1": "03A451E1DE14F77E698B3EA6FED9E6D7CCE68C0C", "hash_pe256": "BACB81361ADA74892A6FF172753B6A4A71D6369EFFBB5AB8919B709C4A557EF6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Problem Reporting", "meta_original_filename": "WerMgr", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/23de870a5147f2e3e9aca874530394ef1d6f5e68a469a242a8eb1d1669fdfa01/detection", "runtime_modules": [ "C:\\Windows\\system32\\wermgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\wer.dll" ] }, "wininit.exe-DB516676B9D40004985E6D25A74943D7": { "file_name": "wininit.exe", "file_path": "C:\\Windows\\system32\\wininit.exe", "hash_md5": "DB516676B9D40004985E6D25A74943D7", "hash_sha1": "6038C6B6788F98832506B788A3D55F30941D1FBB", "hash_sha256": "69EEC502A5423F3E947465D3EAF8D1DF9CCB8477A27C361BE314E21671D71205", "hash_sha384": "FE489D42FBC10C1A3E1658F89E818639800D7F650F7DBB1B1FFFDAC7539A96B699012458108CFE2CBC81C508334D52C5", "hash_sha512": "F6EDB903529250A913D33DC409D4257A7E80982DA74CEDDB935451EA8B0E0DAEB1BF369974BA368CB8CBFF715B7F0B0F4B944FA2038AEFF51FCC9EA74F5C0576", "hash_ssdeep": "6144:GM7PELSPbmhw6ZRxTtkNHWriIE/Fc89lzZkc2i2ZubIpsgeoAXLnwJDu:GM7Eomhw67zKHWriH/Fc8rzXHULDu", "hash_imp": "5DD14AFAB46B0C83EA7A6093D7355FA9", "hash_pesha1": "3C985E7372C97D97C6998B983C02699607132AC0", "hash_pe256": "2063A415E532F2BA5BD3D59B474FB0D5F614B887DA5B08637DF3B3DCB19E541D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Start-Up Application", "meta_original_filename": "WinInit.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/69eec502a5423f3e947465d3eaf8d1df9ccb8477a27c361be314e21671d71205/detection" }, "winload.exe-4BD3DA89F470D7940C9DA5F5D992148D": { "file_name": "winload.exe", "file_path": "C:\\Windows\\system32\\winload.exe", "hash_md5": "4BD3DA89F470D7940C9DA5F5D992148D", "hash_sha1": "3C8BCC0DDF13F3BF8BB6D88ED79A2258DBFCD8AA", "hash_sha256": "5B2AEBAECAC16325CB6E123F06AC882C7C9ADEF6287D2E596F535C24861D6CBB", "hash_sha384": "9E2D87D96C96FA17ECDAC351BD9D3486F53933986B659E8740D1CDEE0988E848AA798935E9A86520400243A1C54A24D5", "hash_sha512": "7325E3357CAF17921F857C76A2A011B91E8593B236758077746547471CA2A4DB5FFE436AE9D3B87AC8FB297EE9B3FB178C43B27247313B39583B539F39F0C513", "hash_ssdeep": "24576:Hwp/jMxeIRsrsLNt2DT32e3tISfi2gD1KPm2+7ly+E+KOXPK4KoI5S+8:HwpwRZm62/m20pPK4faC", "hash_imp": "n/a", "hash_pesha1": "01F9FD7EEB1A90849F500E7B7AF3AA2EDD39A11D", "hash_pe256": "9983A9945050BBE24B3BAF1D5E7DBC884408E69AF9E7E55DF547B608B25DCE12", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "OS Loader", "meta_original_filename": "osloader.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/5b2aebaecac16325cb6e123f06ac882c7c9adef6287d2e596f535c24861d6cbb/detection" }, "winlogon.exe-790D2A6C194038513919DA17C6B91549": { "file_name": "winlogon.exe", "file_path": "C:\\Windows\\system32\\winlogon.exe", "hash_md5": "790D2A6C194038513919DA17C6B91549", "hash_sha1": "68648430E41DA124215C8E36BCD85CA0C1714304", "hash_sha256": "A4D74C4A92007E3D6B893187F67DEA65C15A0A551E1F8956685D115A3F202958", "hash_sha384": "02159675E7169FDB99F9A2F2890BAEDD377FAC70F1EF6338EBD83010A2602E7EA213444988C74205860E978718475814", "hash_sha512": "CF5C721C1DA4C8732ABD5D307BC69728B2076749998E1DA6CC415DD747DA84114F7264619BBEBA730AAEFDCF4B0500C65F053CEF446CDED25D13BD4090B80322", "hash_ssdeep": "12288:+eZdyNQyKs/xgcprEmr4QDiwKIYKR565vXfPyoKu1OO+io/:+cNyKpMErcxKIwnyoKu1Do", "hash_imp": "C399754881779489CBD0F5D180C41465", "hash_pesha1": "BADE994A46421A7CD1F8238399B8D13F7AC9ACC6", "hash_pe256": "169E5A43D23F98E5E38ED35D98BFEDCAFBCE1ED0EE3FA556CFA9C892398A3A09", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Logon Application", "meta_original_filename": "WINLOGON.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/a4d74c4a92007e3d6b893187f67dea65c15a0a551e1f8956685d115a3f202958/detection", "runtime_modules": [ "C:\\Windows\\system32\\winlogon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\system32\\UMPDC.dll", "C:\\Windows\\SYSTEM32\\dwminit.dll", "C:\\Windows\\SYSTEM32\\uxinit.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "winresume.exe-29B7C4C781750BCD5D8FB79952B3F1FF": { "file_name": "winresume.exe", "file_path": "C:\\Windows\\system32\\winresume.exe", "hash_md5": "29B7C4C781750BCD5D8FB79952B3F1FF", "hash_sha1": "A1BA967B9665CBC04565704E301D40F1795B716B", "hash_sha256": "9088E8382EF526EDCB9CD68F31643A9BFF0487834A6B3C89DC6B1A4057D1BAF5", "hash_sha384": "291F2AF8EB675B1B2F3E70ACB2855E7CE1391E97743EF3A68CF66DBCC317C0B1047C4C2F4578F0CA9F3A5421BD4DA2C8", "hash_sha512": "EDDFE15C15D1D0E8FD8AD6EDEBC15ED0C241788A9B47B6C8B80CE3449847145E7354D2DB8E7386B378A5D3465B31A26F12EEDB1FFB45704F45CEC3E1F4E1D0DB", "hash_ssdeep": "24576:5d+Or1HKsCcBEzLYxiNBAMniGSZdPmmoIy:e6C7W8BVinZhmr1", "hash_imp": "n/a", "hash_pesha1": "70410C257D836F7BD9864D8E612E953AA6A46757", "hash_pe256": "82B78A8D35C9EF6C8C5478DAA6029782E3C950777BADA0294A56CCB155BF0877", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resume From Hibernate boot application", "meta_original_filename": "hiberrsm.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9088e8382ef526edcb9cd68f31643a9bff0487834a6b3c89dc6b1a4057d1baf5/detection" }, "WpcMon.exe-A3A06E7A7A5F0DDACF8C8E6A408D16E4": { "file_name": "WpcMon.exe", "file_path": "C:\\Windows\\system32\\WpcMon.exe", "hash_md5": "A3A06E7A7A5F0DDACF8C8E6A408D16E4", "hash_sha1": "41DD12B1F589C77FC55B14B8DDF27EEFD1BC8FF8", "hash_sha256": "5BBAA50D2B9D2242CB2F83C0BEF935EA170736286813B2A774C36FDE34D44588", "hash_sha384": "A4DDAF41D97E8141F33C3129F4F8BCBBF0F5D1E4F13C5945C10D3D4DA4E161C19D8997101DEFBD951060C049D801477B", "hash_sha512": "D576C091D445144CDE03038407F56D7708973E104407CCD12A2C910AD51C1C0FE9D6F6B4450F58D7ED631DE195DAEC79612C18C29E4DA15BDB65CA35E5F13BA5", "hash_ssdeep": "24576:kDcYPVm9VZMUKT2/TB/9N0+CvNsFwGI2:kn0Twq/Vg+aCFZ", "hash_imp": "D7BF6777BE67ACBE091F892E19199749", "hash_pesha1": "DEEDBF37A7EF3564F08A1DD1AF40EF04D4670AE9", "hash_pe256": "F6BDC8D98F8C37B47BB5C449E705B92C7E007F321E283197B1047B82C3C598AA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Family Safety Monitor", "meta_original_filename": "WpcMon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/5bbaa50d2b9d2242cb2f83c0bef935ea170736286813b2a774c36fde34d44588/detection", "runtime_modules": [ "C:\\Windows\\system32\\WpcMon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "WpcTok.exe-09013BC3AA26A23515971B793AF73CF2": { "file_name": "WpcTok.exe", "file_path": "C:\\Windows\\system32\\WpcTok.exe", "hash_md5": "09013BC3AA26A23515971B793AF73CF2", "hash_sha1": "335912ABE3FFE06C3C3FC568DCC5AB4C3E8EC32F", "hash_sha256": "D2B8B1924C90AE02EA71255083938BEB4F02A44C3350DCE21941136E7A93CF68", "hash_sha384": "D9EC2427EFE24320A8A7FFC915AB0B0A91F446F7436DF912C358F53014ABF74180485A5958A5E202477592B3E4C4E0AD", "hash_sha512": "A62562EF898839B68B1E8487FDE98C35DF97002F848FAC1697BFC53072A221F6D875F3D698DF01600EFCD258BEF6267788A5011C03BF67B05C3F21FB7C5C12B4", "hash_ssdeep": "6144:kqBg/jlFYCB/60uNZhyf+429dxqlqGsHbN:kl/5FYCB/60uNZ4f+427oqG", "hash_imp": "52DE82B8B6B24E3AA23CAC4F0B872BF8", "hash_pesha1": "28816C5705C6EA79CA9F79F64F12569DC28962B6", "hash_pe256": "9D8B69E6C6ACE97B624CCE352C20554991F1DA93677C19A3E1D6C2BD58ED3ADE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Family Safety Token Auth", "meta_original_filename": "WpcTok.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/d2b8b1924c90ae02ea71255083938beb4f02a44c3350dce21941136e7a93cf68/detection", "runtime_modules": [ "C:\\Windows\\system32\\WpcTok.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mighost.exe-79BBFF97E65EED53564150A9B4CE1372": { "file_name": "mighost.exe", "file_path": "C:\\Windows\\system32\\migwiz\\mighost.exe", "hash_md5": "79BBFF97E65EED53564150A9B4CE1372", "hash_sha1": "6891D79DC35AD7E7923DCB8112D4A58F49CCA9CE", "hash_sha256": "C8240FC9F799A5EB4FCFA83ACEE64D53B8D1DC955269E1CBEF816CFE72F91EB8", "hash_sha384": "3D2FA7C91FD8BA88FAC6C2AF7B4A6B8EFDC9E58DC6F21B5A3ECADC18145C76A26EFA64578FB494AA5BF9CA8D25EF8041", "hash_sha512": "28A4B88AA05DE96157D129DA8CD8BA8CED97749A00EC890E3E60EFDA8E39BDE396E6FED9798967CEF7A1B8E07B0F8340DE8294297E38447267A177913035CC57", "hash_ssdeep": "6144:DTP+SYlDKFv4mojDuUlMtq10Q8m7NNqM9N+hN1UFpfNS5iXjD56Gpovgp2H32nqf:DrgmeDuUlEqatglsLbF", "hash_imp": "1A2E6FBE71CAA18E49B7AEBBC2EAC135", "hash_pesha1": "2D8CF4AE6E8BC6C86393FFB93972D5104C1BA018", "hash_pe256": "14A8C7BF6DA4EB4DA2D499E67ECD9543F860855951F6C8EB7D8707138022E16B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Migration Plugins host program", "meta_original_filename": "MigHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c8240fc9f799a5eb4fcfa83acee64d53b8d1dc955269e1cbef816cfe72f91eb8/detection", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme722103516": "Section", "\\Sessions\\1\\Windows\\Theme1800662698": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\migwiz\\mighost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "runtime_window_title": "MigHost.exe" }, "agentactivationruntimestarter.exe-E5CDA52CD709780E81013C4D5ABA58BF": { "file_name": "agentactivationruntimestarter.exe", "file_path": "C:\\Windows\\SysWOW64\\agentactivationruntimestarter.exe", "hash_md5": "E5CDA52CD709780E81013C4D5ABA58BF", "hash_sha1": "9DB9791798EF08C6000EF879CB5B4612B27D6636", "hash_sha256": "88EFFCA42907259B29DCE23AF9683E07973B0BC22463488DD5D149715291C944", "hash_sha384": "4FB1E42354FA2BF7DC3547096350CAD1F7652A7F25894648A27EAC7C2CAF28BEDA515C0167682C4F9D81C53F3C6504CF", "hash_sha512": "08A71EA588B4F7401709FBAC137014C97B4CFE7F2800BC0D268DD43599E8D06B250D9579C994D65166BAD37F39EB0B2644FC57F2B426F274B727E037C6013B17", "hash_ssdeep": "192:HsT0Y/q7lyttXwJcPqT/0WlygTMf5ZmlEo6UTQj:HSbS7lyMcPqr0AyjGMUT", "hash_imp": "C92464C94895CEE3BD3869E057DA0432", "hash_pesha1": "1C753469BADD1B7E687BD8B87D2AFD0CD9971A6D", "hash_pe256": "9D10192F83E5FAE15EDE1F83FBB703F94DD3B8CB8A08F3D2C0602B1A9BBAE37E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/88effca42907259b29dce23af9683e07973b0bc22463488dd5d149715291c944/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\agentactivationruntimestarter.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "autochk.exe-26FC8049B74859DD17C33CA8DDB09903": { "file_name": "autochk.exe", "file_path": "C:\\Windows\\SysWOW64\\autochk.exe", "hash_md5": "26FC8049B74859DD17C33CA8DDB09903", "hash_sha1": "41AEC7A0680DD61FA0EBC8E1DEE2DA4BC0B41241", "hash_sha256": "864D476F56543128FD756E3B5491E811D69B0121E26F010F3CF7DDBA8334B0FC", "hash_sha384": "298D4EF6C801B2F2F2B8D6600483FB33F5F78CE9FE2E5ED9880E68107B65CE1AB23CE433457DA1DD02503E239DFCAD13", "hash_sha512": "4F8E1BB0C6347683D9E45AD4749F8E7ABB23D1DBFBA79868C882C72B500F0BF9D6BCD77023F7FDDC74B458A6B6D182838BA8FB79947A791BA25E0370925B56CE", "hash_ssdeep": "24576:/XT3OmNgpdvnHFigqCsZd+2RAG8BAhmM9n3M:/XappFixCanRAGcOH9n3M", "hash_imp": "9A89A0DBC9259DDF70AEA95E61C9437B", "hash_pesha1": "E4A5971DCED3D3BE7A7A88420768A9A95400A0AC", "hash_pe256": "6FE8C9489930D819636964ED2575F8F0E1B1A587ABA29BA820FF7B69588E9E54", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto Check Utility", "meta_original_filename": "AutoChk.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/864d476f56543128fd756e3b5491e811d69b0121e26f010f3cf7ddba8334b0fc/detection" }, "autoconv.exe-2D7C3DAB443C2F316D134ED17BED82F9": { "file_name": "autoconv.exe", "file_path": "C:\\Windows\\SysWOW64\\autoconv.exe", "hash_md5": "2D7C3DAB443C2F316D134ED17BED82F9", "hash_sha1": "93BBC8180D0B8354EA00D73E514CBDE41F631EF5", "hash_sha256": "9DDA6341087E07B7C50E3C1816B7076C2D7B2BE7D281C231F99144FC144A11A4", "hash_sha384": "C5AA282ABE821FD84708D478904A02466EE1EE8A984AFE537B7D7667CDBF6E19BE643F138A4504501F45EAB19455F2DA", "hash_sha512": "34FD16816438B58FC1B7DD7A6194A0DD602DF1B5DA66F155F63B95DCC34E72270ADE4F48C23887DD4EFBB227DD9F91AC87FC5802CF6AD36FD7CCB2CF84102DB3", "hash_ssdeep": "24576:fqDKn0C4VusZpMZFHB0JIX0/RtWh48U8R3:fKCN4SvHBu7/RYhBU8R3", "hash_imp": "AC2AA7C2A531F2F88A81ABC0EB309F2A", "hash_pesha1": "36301B4911DEC8A9F363E730998132CE5410BC5E", "hash_pe256": "E72D3C41537B03460ED8A9AB685F43D0BF8374331434A104740E9498F98781FC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto File System Conversion Utility", "meta_original_filename": "AUTOCONV.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/9dda6341087e07b7c50e3c1816b7076c2d7b2be7d281c231f99144fc144a11a4/detection" }, "autofmt.exe-38936432FF854DE493D1445777184873": { "file_name": "autofmt.exe", "file_path": "C:\\Windows\\SysWOW64\\autofmt.exe", "hash_md5": "38936432FF854DE493D1445777184873", "hash_sha1": "131413737966C25423D35BB14F1E803A28201083", "hash_sha256": "279C7E6EC8F21A6F8A18E8A448E5523D5A37790937E43EDF86743D25884494B6", "hash_sha384": "06DD094640EC4AF01BDF94823B5BCA9CF14D51410544D89285F4FFC7144253DEF60DC49B047D5CD34BD78D74BB79318F", "hash_sha512": "4442F96443E6F3362D4C087E641963F8F1E01EA8076F7B1825D4FD2A37C526A95F36BEC6DFA0EF4D34A9EE2E0ED6292098AF1E2841F231B279A2359F01D9DB8B", "hash_ssdeep": "24576:WTCXpLrviyltPhMOdpzTz/rpunSu+MGMD3F:WavvPhldpzP0nx+dMD3F", "hash_imp": "5BF5EA6308D70F227A08DFF51F95ADAE", "hash_pesha1": "94F0EBAB2F3F66099F4111A8DD2DC97BD6A43C60", "hash_pe256": "C81C08DBE3628E594A5F2A209EAE5B5B2F05BEE2BB89AB90050BA7ECA178D1E2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto File System Format Utility", "meta_original_filename": "AUTOFMT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/279c7e6ec8f21a6f8a18e8a448e5523d5a37790937e43edf86743d25884494b6/detection" }, "dtdump.exe-BA0B3A8DC23346DDB9D6AE92736DDA9F": { "file_name": "dtdump.exe", "file_path": "C:\\Windows\\SysWOW64\\dtdump.exe", "hash_md5": "BA0B3A8DC23346DDB9D6AE92736DDA9F", "hash_sha1": "7D19F0607CA337A23A74383B9AD7C2CEF0CC19A5", "hash_sha256": "4B440553F1F1B69E3CAD4DE540FDCF3569F4205AC2ACCCEEC0689E069B446161", "hash_sha384": "90A60E686E7D17307ACD8CEA179139EE92B44B1F4DFBCCAC78AF3B8B5163F032D2800E24B1B8469ECBA53C1AE9CE31BE", "hash_sha512": "67D35EBF0D357FC7D86DA9663951DEDAE0BAB6049A27666E8E2B0DB04E0316806C89B0E9B18CE3D81B26737ECE32798158E5D1A3837F3C366988B043E9BFEF11", "hash_ssdeep": "1536:5sCWpbeR866jRHDCdlkpukQ+17A9xSfJilbRKKfGMphSBOuQZEofOd4oOyzvQ+aI:5sCWpbeQ5mdlk4kQZ8QlbRKKfrpElofo", "hash_imp": "4A03FD182BD0DDE1234B51ECCE34E598", "hash_pesha1": "4303675BAD8EFEEE0F56807557ECD0E9F5EDA533", "hash_pe256": "187F0112EFF61122E1A7F3458427B1764F4EE1664797D2236F432E42B1E2FCCA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DTDUMP.EXE", "meta_original_filename": "DTDUMP.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.488 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.488", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/4b440553f1f1b69e3cad4de540fdcf3569f4205ac2accceec0689e069b446161/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\dtdump.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "DWWIN.EXE-9819F8F5336B2313D71B0C70CC2EBF00": { "file_name": "DWWIN.EXE", "file_path": "C:\\Windows\\SysWOW64\\DWWIN.EXE", "hash_md5": "9819F8F5336B2313D71B0C70CC2EBF00", "hash_sha1": "BE141F38AF46D5AC03EFE55B9FCC8D5BBBD3CEB9", "hash_sha256": "84AB9F2F1E3B38BD86D7F8D05783C9119B4347C49FFAF94CE736D12ACE6ED5B3", "hash_sha384": "98DEAAC797DE902EE3DF3201FA0AAB05748EED58B8792B581DC35063AEE4DA2F6D9E457E6472A6491D1102D2255499B3", "hash_sha512": "2BE95FEDB78C510DE9DE97DFBA1B10D3E64CCCE9F02FB4F212E59674C9BA19A92F27269691172FE4D3FBB4E454D7CE23357733966447E01B6374D17C3893F145", "hash_ssdeep": "3072:vD3R43BKKbhcngAwJwICH7VemmL+Y3XbselNDahIR7IEaGifQF9K7CuJYz+kJ0LB:rB43BZb7J5CbECYnrlah2Mgifu9Pz+kq", "hash_imp": "51824BC71568257DA5A091A60BB84DBE", "hash_pesha1": "BA1C30D57092794992B46AF1B1E2C590014FD6F1", "hash_pe256": "63550CC4FFF3653F46335428C5D44967983514E539967643B85FD8828C1E1090", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Error Reporting", "meta_original_filename": "DWWIN", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/84ab9f2f1e3b38bd86d7f8d05783c9119b4347c49ffaf94ce736d12ace6ed5b3/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\DWWIN.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "explorer.exe-0E43AA24BF23EAEC5F4A4A77B318AD58": { "file_name": "explorer.exe", "file_path": "C:\\Windows\\SysWOW64\\explorer.exe", "hash_md5": "0E43AA24BF23EAEC5F4A4A77B318AD58", "hash_sha1": "DF5B71662E6172A5125387DA420B6F3CA18E8823", "hash_sha256": "8F002979214BD06227820FD2996AE54904EBC6E44CC96C9E821A0795EF13DDAB", "hash_sha384": "77DBA7316682C81D48FF53859ADD4800495BAD82C6E2C03F9ED52CD75512DE4CBA461955AF69F5460C25E562C9342853", "hash_sha512": "B694FD4D8A0D81442B7069EC44EADC23AAA17FFF7A5A9B14AD7AD5BEA0ACE7CAB4B739F14F9E5BB973EB4A7FCE7BE6F145F11BC26EDA86C891E9B5289D95E937", "hash_ssdeep": "98304:2pGtbGMOI6S8FvcvwoiDFdQ5c269zbw8a0cDcLAS:2pGtbGMd6SUvcv1iDFdQ5cBwFZxS", "hash_imp": "DA93B6E05D24F45A142A4B56BAB08E66", "hash_pesha1": "837BDC704971F521443CFFC0926CD244203D4AA9", "hash_pe256": "036F61D8B29FD303FBAB3E55C39A8BF5992579E8B0E24EAB2133F6521D618F19", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Explorer", "meta_original_filename": "EXPLORER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/8f002979214bd06227820fd2996ae54904ebc6e44cc96c9e821a0795ef13ddab/detection", "children": [ "csrss.exe", "winlogon.exe" ], "runtime_modules": [ "C:\\Windows\\SysWOW64\\explorer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "fontdrvhost.exe-688D7B90F5E8FFC17006DAC046AC4AED": { "file_name": "fontdrvhost.exe", "file_path": "C:\\Windows\\SysWOW64\\fontdrvhost.exe", "hash_md5": "688D7B90F5E8FFC17006DAC046AC4AED", "hash_sha1": "A525AE17132474DA8F017B51C112383944DC7F58", "hash_sha256": "FD7D157F3D96EAA831B76928905D028095A4DED3744E312B2F93DE2F3A25B609", "hash_sha384": "114FDBFBC2285D4A8069A5FD8464FE462125967C548DE29D0FCD8AD6B3F15B63C753EBE1C968AF559DC47105783F966F", "hash_sha512": "1230EEB460FC646839079402104B7B7DA67AE73B5FA7DFB7B6286521934A025C1619FD7604A3D91363D063FA7A97ED262C51FF8B56CF80021FFBC6B5D31EDC79", "hash_ssdeep": "12288:jAzJbfM4QFuvp8VJjpf8CV9zD19CHVu3Jy6Q:jAzJbfMZc+Jjt8CfrCHVi", "hash_imp": "7C5B72E9C85B4AACD28EB4806FA7623F", "hash_pesha1": "6CE8787E0157B21C2C7C4BE7D55FD3ADDDA5EF3A", "hash_pe256": "138A851F5C304B3EFC64EB3E550F52CB90E2B8E6C2B20BD24553D4EC77E2E297", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Usermode Font Driver Host", "meta_original_filename": "fontdrvhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/fd7d157f3d96eaa831b76928905d028095a4ded3744e312b2f93de2f3a25b609/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\fontdrvhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "LaunchTM.exe-3F2765B3BAF0C8643704BEB2F53A74FC": { "file_name": "LaunchTM.exe", "file_path": "C:\\Windows\\SysWOW64\\LaunchTM.exe", "hash_md5": "3F2765B3BAF0C8643704BEB2F53A74FC", "hash_sha1": "469314D70377FCB1CFEF5A5D3ABA05ECF07D8FE1", "hash_sha256": "41EE06DF3C85D1C06207AD97BE3D0C52E2415B179622777AC6D73D1D93DA9074", "hash_sha384": "6E2D2DA02D492BBEB7DB1BE9F234CE9D8124EF553B02A74D2FF2396CEC52931ABBFEA7BB1109B9686E9222072C549BF2", "hash_sha512": "91D2786CDFBD821987EB6C43C6337ECB263723581D4EC1ED2B47AE0E73054A051D8FD239E232E401136FC3BAC8C1D6EB6D3711B6803A732D26FFE0F2E2A393E0", "hash_ssdeep": "96:Sr8S1kUpDiN0OEusn9ndcp2k3jD02DGjQLRHMizB4MocflJkvcS8DJ+XVpH6b+iV:mkUp7Oru24IMi94MDfbkvB/MWIqayW", "hash_imp": "E28D1A46BA8C0C2DD607DFE0E3A12845", "hash_pesha1": "1BC87F2E7233E98BF5892E3056A1DFD656EB3DC2", "hash_pe256": "B7E587C6A5E766FC5E0256704E9318888F4F6E09E7ED221F5AFE02EDA2038ED0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Manager Launcher", "meta_original_filename": "LaunchTM.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/41ee06df3c85d1c06207ad97be3d0c52e2415b179622777ac6d73d1d93da9074/detection", "children": "Taskmgr.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\LaunchTM.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MuiUnattend.exe-BB125A957366042614B817D8108BFCDB": { "file_name": "MuiUnattend.exe", "file_path": "C:\\Windows\\SysWOW64\\MuiUnattend.exe", "hash_md5": "BB125A957366042614B817D8108BFCDB", "hash_sha1": "9FA610533083632E0DD6585BF1856094AB89DD9F", "hash_sha256": "BB438514A62CA5DE5B43736574666EFD241A7B56B258531B26BE89D6D32F4A72", "hash_sha384": "DD79904CB39B1A0FE82D7B756F72869FA7E1C9435EBF526728D5C946BCF33D5483DD84673E88D0458175CD2FC09F22E6", "hash_sha512": "65ACE902DCFA2F14912720AB3AAA07CA65CAACE2B9C89539E4E23CEB36BDCB420627D36DB599FFB19003B27C1ED34A87544FA2159E657BB86693606F365A2BDF", "hash_ssdeep": "1536:SMc5tcmHe4tdCoVJLjQBSboznKtW28f4jmo/+UCGkRQbAbDyh/iiGq7:SmhwEo3LjQBjWtHk4x+TGqAUS", "hash_imp": "EB7186D0510E0F5B777005ABB635BE6D", "hash_pesha1": "8EF245086E6C7A0844E0884AAB07CC45FA5610C3", "hash_pe256": "1E6BF5858FE44A704D70AF0D63411C97C982A30A848F5289164578D0C08FF2C7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MUI unattend action", "meta_original_filename": "MuiUnattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/bb438514a62ca5de5b43736574666efd241a7b56b258531b26be89d6d32f4a72/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\MuiUnattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "poqexec.exe-74530CC0F5149D38B1F9D694C99CA1A2": { "file_name": "poqexec.exe", "file_path": "C:\\Windows\\SysWOW64\\poqexec.exe", "hash_md5": "74530CC0F5149D38B1F9D694C99CA1A2", "hash_sha1": "146887DAC2D6973C2F5F26E0593003D49805240A", "hash_sha256": "5679910005C1A1DF6705BDF6FD034A9EC023CD73981333C0F1CC621175A1F1E5", "hash_sha384": "C288C4F20C9E857C60201B6E61766712FF123E1B2D217A0E5FD77F0ADF63BD34460666D98B47D146BBC1DFBF8C4A0E60", "hash_sha512": "91F019B78D9B34BDAF3A0937EBA5DA9F2D6F058D83F344C1427588CE81882CC99E4782D0CDC9AD170B21D7968A025A0B09BD191C4310CFC6C56BF7816F92C2DC", "hash_ssdeep": "6144:lW5uKmK3eyy33PInY24RQHMt/N+MP7ikFvm1a9ZpHBufqnPCOjvCa4aOnUWkQok5:lW5feyy339WsJN+MP7ikc1c3BufqnPC/", "hash_imp": "49D7FAB9D4B1A98A8BD1BC23B4876852", "hash_pesha1": "53DAABE415A7E3D57380DE0BE09B2A372B767B38", "hash_pe256": "882A457B46EC28F168E96BE5082FE2395B3561D03DC2C03D2D2400C4336C82CA", "signature_status": 2, "signature_status_message": "The file C:\\Windows\\SysWOW64\\poqexec.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Primitive Operations Queue Executor", "meta_original_filename": "poqexec.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.504 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.504", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/5679910005c1a1df6705bdf6fd034a9ec023cd73981333c0f1cc621175a1f1e5/detection" }, "schtasks.exe-7BDA210A40E741B62948CB56C7F1F883": { "file_name": "schtasks.exe", "file_path": "C:\\Windows\\SysWOW64\\schtasks.exe", "hash_md5": "7BDA210A40E741B62948CB56C7F1F883", "hash_sha1": "2975F2AB72EE6E1886C555280C31D1AA6B0148D6", "hash_sha256": "25B617E0C8D3FE9A4D3D70C1835B6676485B9767F19F4B4E93E8FE96DF9F466A", "hash_sha384": "42109BE328BA4CEAC3A6153009B564BC0616D2A5420FE79545D08198B3BC6458A52BEA977AD6EE357AFE63ECE336F0EB", "hash_sha512": "7A909AA5A4E937DBE9AC8EAAA1957E9B4A2A04D82C4F6D30FD0455861368A02BC802031AAB19012A92E0D428AA4096309E08241C4171A3CC4122D33B46675AD0", "hash_ssdeep": "3072:Z+Aq6DXkRLZKzdoR/xMefkcHbiBduCo5VJtKCc7GHBhFZX5WnAaty9:Z86MZQohlW/c7KCcihhL5Wnz", "hash_imp": "F17EC07B6AFEC23E66CD1D082F9A6930", "hash_pesha1": "1A5FDC9ADFAA8A7007B41CAAE987858066B4815F", "hash_pe256": "500FC3B16214FD3531DE5A78772B5BEEB2055C8A857499A435C2DE3D56F444A8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Scheduler Configuration Tool", "meta_original_filename": "schtasks.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/25b617e0c8d3fe9a4d3d70c1835b6676485b9767f19f4b4e93e8fe96df9f466a/detection", "output": "\r\nSCHTASKS /parameter [arguments]\r\n\r\nDescription:\r\n Enables an administrator to create, delete, query, change, run and\r\n end scheduled tasks on a local or remote system. \r\n\r\nParameter List:\r\n /Create Creates a new scheduled task.\r\n\r\n /Delete Deletes the scheduled task(s).\r\n\r\n /Query Displays all scheduled tasks.\r\n\r\n /Change Changes the properties of scheduled task.\r\n\r\n /Run Runs the scheduled task on demand.\r\n\r\n /End Stops the currently running scheduled task.\r\n\r\n /ShowSid Shows the security identifier corresponding to a scheduled task name.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n SCHTASKS \r\n SCHTASKS /?\r\n SCHTASKS /Run /?\r\n SCHTASKS /End /?\r\n SCHTASKS /Create /?\r\n SCHTASKS /Delete /?\r\n SCHTASKS /Query /?\r\n SCHTASKS /Change /?\r\n SCHTASKS /ShowSid /?\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"SCHTASKS /QUERY /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\schtasks.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SpatialAudioLicenseSrv.exe-8E2EC4676700E4BB6016786F4C412B89": { "file_name": "SpatialAudioLicenseSrv.exe", "file_path": "C:\\Windows\\SysWOW64\\SpatialAudioLicenseSrv.exe", "hash_md5": "8E2EC4676700E4BB6016786F4C412B89", "hash_sha1": "5C19FC274702E0371ADEC61BD8C8128D902C4A0B", "hash_sha256": "386F0D88A343A404458B060114DA84B314F1BCC01547F12BAA1F90A6B7DEB0DA", "hash_sha384": "11564B335BA23AB4995BEB69A3101463C313B62ACD718A18F031FEEBF2168C9CBEA9F7876669CBFD6DF77C45435E03E8", "hash_sha512": "2C61212404910F235CC333DAD61FD9195D99162C1591EFF434B8F496E67723BA73F45B02071208EC19FF76B19983352344A0978B75CED70E33F949339B980DBF", "hash_ssdeep": "3072:YjsBvk3pdAP5S7gZ0WB5VdyrRh7vs/zm5k4cZqliC3v:bmnNPAzDQsM", "hash_imp": "885BEB9A291DC4D4E543D5D866FE82F2", "hash_pesha1": "1DA4ED672AB34DB175A078C857432FD762C8B967", "hash_pe256": "D07467CC795675D854F6BCD80ECD86B3FB6712C189F434A891809DAEC497B0D7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Spatial License AppService Broker", "meta_original_filename": "SpatialLicenseSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/386f0d88a343a404458b060114da84b314f1bcc01547f12baa1f90a6b7deb0da/detection", "children": "powershell.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SpatialAudioLicenseSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Taskmgr.exe-719821FAFBB0255708C1F3709DFF090A": { "file_name": "Taskmgr.exe", "file_path": "C:\\Windows\\SysWOW64\\Taskmgr.exe", "hash_md5": "719821FAFBB0255708C1F3709DFF090A", "hash_sha1": "6C584DC8A8CCCEBCEF486478EE65BF5C0DD3A4E6", "hash_sha256": "2CD93ADD1272E528E4D46A24F06CAFE4DAC90EFDC509B49E168EA164BE495803", "hash_sha384": "B5F5259051CC836E668520FC7F24D9EEF0D73C361EEF8F138391B8C61B8D440884E7C74CE009C27393CC0E616EFA6C15", "hash_sha512": "4FB68B00A6A2943CB59DF4DA338314A95010182EAD5F7B628113CD69875BA970C8C24C772A6E4EA24DA5288D6C63D26587CB88FE814D141CC3D67D7C628C8FE7", "hash_ssdeep": "24576:TzMMjpncoJGNdpPbHelpMiLdzFcRg/6u1Xsknsf1dzev:1jpnkdpkpLdzWuzcff1dzo", "hash_imp": "6D526B071B0AD117CAE0160341F4627E", "hash_pesha1": "61B55477B8961E4F6363E270D92E980700A461F9", "hash_pe256": "A9AB411F6F7766E14B290EAAF29EC915ADEEBDF2CDACF991FF74BC1B03CDED9F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Manager", "meta_original_filename": "Taskmgr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.546 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.546", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/2cd93add1272e528e4d46a24f06cafe4dac90efdc509b49e168ea164be495803/detection", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\Taskmgr.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\Windows\\Theme722103516": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Sessions\\1\\Windows\\Theme1800662698": "Section", "(R-D) C:\\Windows\\SystemResources\\Taskmgr.exe.mun": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\Sessions\\1\\BaseNamedObjects\\C:*Users*user*AppData*Local*Microsoft*Windows*Caches*cversions.3.ro": "Section", "\\Sessions\\1\\BaseNamedObjects\\C:*Users*user*AppData*Local*Microsoft*Windows*Caches*{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000008.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "(RWD) C:\\Windows": "File", "(RWD) C:\\Windows\\SystemApps\\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\\pris": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\Taskmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Task Manager" }, "wecutil.exe-B39FD1E0A4471761DC3651270B706D1F": { "file_name": "wecutil.exe", "file_path": "C:\\Windows\\SysWOW64\\wecutil.exe", "hash_md5": "B39FD1E0A4471761DC3651270B706D1F", "hash_sha1": "4B7CE12B7BBAF945BF7A4CACE5E89D8E752FE3DE", "hash_sha256": "C9669A68F4A2D84D0D330E190D500AE15F0A1E5DBD5B5A5D06BA076990BD2891", "hash_sha384": "5364A5F342AB23BBF34759BA9864303D4E4C9A3BE695B9B815B5292CACF0D53025AC9C6007CECD2FFCD210E457643D5F", "hash_sha512": "FB9006C5C1A040F07DB05DA2634EAE07C2BB498AEB9AB67A477ADBCF275D0D3349309977A451EDD1802C36469280CD8E9B874C07D05137A7A61FAFC9A646071E", "hash_ssdeep": "1536:Vqw+kkxE47uKKB3ZYaz17oNAXH8ElX6C7YH4QIdH:Vqw+k0xu/pYazloNi8ElX6++4", "hash_imp": "36A8613F9674F9017579506661662D09", "hash_pesha1": "91016BA4256C67AE861BA6724E1CFA9A56046F55", "hash_pe256": "3FE78BC5A1EA2B792F19283F4037E7C4B528506AC39D5304487D124B0E5E7A5C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Collector Command Line Utility", "meta_original_filename": "WECUTIL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/c9669a68f4a2d84d0d330e190d500ae15f0a1e5dbd5b5a5d06ba076990bd2891/detection", "output": "Windows Event Collector Utility\r\n\r\nEnables you to create and manage subscriptions to events forwarded from remote\r\nevent sources that support WS-Management protocol.\r\n\r\nUsage:\r\n\r\nYou can use either the short (i.e. es, /f) or long (i.e. enum-subscription, /format)\r\nversion of the command and option names. Commands, options and option values are\r\ncase-insensitive.\r\n\r\n(ALL UPPER-CASE = VARIABLE)\r\n\r\nwecutil COMMAND [ARGUMENT [ARGUMENT] ...] [/OPTION:VALUE [/OPTION:VALUE] ...]\r\n\r\nCommands:\r\n\r\nes (enum-subscription) List existent subscriptions.\r\ngs (get-subscription) Get subscription configuration.\r\ngr (get-subscriptionruntimestatus) Get subscription runtime status.\r\nss (set-subscription) Set subscription configuration.\r\ncs (create-subscription) Create new subscription.\r\nds (delete-subscription) Delete subscription.\r\nrs (retry-subscription) Retry subscription.\r\nqc (quick-config) Configure Windows Event Collector service.\r\n\r\nCommon options:\r\n\r\n/h|? (help)\r\nGet general help for the wecutil program.\r\n\r\nwecutil { -help | -h | -? }\r\n\r\nFor arguments and options, see usage of specific commands:\r\n\r\nwecutil COMMAND -?\r\n", "error": "Command help is not supported. Error = 0x57.\r\nThe parameter is incorrect.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wecutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WerFault.exe-B104A868C53A6A59807AD86722A58C84": { "file_name": "WerFault.exe", "file_path": "C:\\Windows\\SysWOW64\\WerFault.exe", "hash_md5": "B104A868C53A6A59807AD86722A58C84", "hash_sha1": "4F396329A5406584058E344452957322DA65A157", "hash_sha256": "49FC3B1FEBD3F56466D930E35B1CB5BE76113CFEE92D721923EC2C8034C8DCF0", "hash_sha384": "332AAC70D8EAC240FAA405E631309878037C1C8DC7A36E1C568F31E93C1A39D2CE84303A874EFB179872798E5021845A", "hash_sha512": "2E535F27A283CA84A38DB722F4ACC3E3934E260C264C08E81D447200A493E46EF0A3266518511AB0665783DC80133D3C45BB7B476EBC2DC0407CC0E6914EC78B", "hash_ssdeep": "12288:zcGGEOQ1w6uJeIcxsDKHZ1L8ZzbcUUOevJec2Hyw3QWL:gGGE7S6IbcxsDshibcHOevJecyh3V", "hash_imp": "C8DD8BDD184BD81C95776BD2A73DCF11", "hash_pesha1": "71B6D3B02DDC9723EB1CE61205DE5126C186DED2", "hash_pe256": "B0F6F41D9103830124235D3D9889D1A32FF1D66A6A45E7F16D179A40A6703387", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Problem Reporting", "meta_original_filename": "WerFault.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/49fc3b1febd3f56466d930e35b1cb5be76113cfee92d721923ec2c8034c8dcf0/detection", "runtime_modules": [ "C:\\Windows\\SysWOW64\\WerFault.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wermgr.exe-4C68AD8928D6DE43040805B45118212C": { "file_name": "wermgr.exe", "file_path": "C:\\Windows\\SysWOW64\\wermgr.exe", "hash_md5": "4C68AD8928D6DE43040805B45118212C", "hash_sha1": "BAAB9D6A773B03622230D04BFE101271F02EA23F", "hash_sha256": "163B8E6177378572CC370BD71F79400E5A94D39994F624B88930A8192EA000E3", "hash_sha384": "E36EF1D4DAD666EBB05B4E06EF8C85FF4EF2E67394ADC3908F3F432DBF1BD44A82F5A1773B75CA72B6271CCF52AC64F0", "hash_sha512": "F23B98C9BAB538A0732A1F81D56078FF58DE65F2D31C4785105C30718542880DC0DE902E1B63A6A5E5A36449BA6DB9665A436488F64151F640061E5F0BABCA64", "hash_ssdeep": "6144:MvelAWXB/uPqGI24HqRH4S0gC4C2kEFuobiO7VJyB60OHyLC7vtP:de5cKx4FgC4C2pcTOZc2HywR", "hash_imp": "7FD2842DEB95BE732351A40A75FE7619", "hash_pesha1": "08B1D5849BA5D61B910E3EFB524F216E70715FE1", "hash_pe256": "AE79C7FFF9BCC60A5C06061ECE0C99E261157378B532CA56DFF13A0EB6E5B244", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Problem Reporting", "meta_original_filename": "WerMgr", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.572 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.572", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/163b8e6177378572cc370bd71f79400e5a94d39994f624b88930a8192ea000e3/detection", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wermgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Microsoft.AAD.BrokerPlugin.exe-45069EE7925ABC1E9F980376D3C53E97": { "file_name": "Microsoft.AAD.BrokerPlugin.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\\Microsoft.AAD.BrokerPlugin.exe", "hash_md5": "45069EE7925ABC1E9F980376D3C53E97", "hash_sha1": "FA986514A4EBD9843A074E7DE8730111B879C05C", "hash_sha256": "0B9C5BE55849BFDA6886D54DDF422570906DAC32F7CDB7B62AB1140FF7E4D734", "hash_sha384": "2698AB2CC34853326B3B7DC61695BBF3B46CB4BCF8435530B0B61BC205150E0666A902D3C272C5BC11F6709E66F7BF79", "hash_sha512": "F128D898787BED82D698E92DB99A66384DA7275978D327E964E0D432881DAF51A090BA0650ADC489A8E6D1A61D52D267E6082C7E15D2CCB566F33B6C6DF4CA0D", "hash_ssdeep": "3072:X1fiWJjzGZpxu8dn9LMBrZ4JiKwDr5skekjAHLShPnjMMWp3wk510pS:X1f5dN8V9LMBrXDOk7AHGlngMw3wiz", "hash_imp": "1C7722EBBDCEE129017E54A6FBAF1A83", "hash_pesha1": "1D70F2175D7108ADB87251111CD5A5CA10ABDF92", "hash_pe256": "56CDAB71740034907CE33D34A869B57F3109A4094FB2BB88BE9466D44FE24CEA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AAD token broker plugin", "meta_original_filename": "Microsoft.AAD.BrokerPlugin.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/0b9c5be55849bfda6886d54ddf422570906dac32f7cdb7b62ab1140ff7e4d734/detection", "children": [ "Microsoft.AAD.BrokerPlugin.exe", "WerFault.exe" ], "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\\Microsoft.AAD.BrokerPlugin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "SecHealthUI.exe-45E27468C22AC2C433B65462CB2EB390": { "file_name": "SecHealthUI.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\\SecHealthUI.exe", "hash_md5": "45E27468C22AC2C433B65462CB2EB390", "hash_sha1": "7A26110A85147F7C479D7884090E8B9D7A72DCD4", "hash_sha256": "2DC1933711424608C670EA23830AA8915B1F65BC0B8A1F58D57EAB48FF60957B", "hash_sha384": "D08A3078C9A96AE97D98EBA65E8A59EEDF5F36C287251FBBDE7AC79284907F2651F8670D4B6CD392D9E09FB7B4B29FCC", "hash_sha512": "46103402CDD4F81E0AAC3BC7D0244C7B68295FF7912AB3B976A9B3E010716525FD8CE696737AB404DE02363410081F2B730F004DB09D57C5C2290416A5C7E176", "hash_ssdeep": "49152:fSdzQ+46G92b0+jfj6dnNkoUJh/ItMDn7Pn6+kT20YO444D0aq/ktX7EWqXHRNtN:fSJcI9wt2r69QrtqXTRW", "hash_imp": "15BA6368A49AB7C784AD5D60F47CD58B", "hash_pesha1": "6A272673F352D0F285B0BD7054DE7EFBA88C7DDC", "hash_pe256": "9D16EC16466AB3DA45551FD74C1683BB30EAF7450BC6B0ED6DE7EEA45062A040", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Defender application", "meta_original_filename": "SecHealthUI.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/76", "filescan_vtlink": "https://www.virustotal.com/gui/file/2dc1933711424608c670ea23830aa8915b1f65bc0b8a1f58d57eab48ff60957b/detection", "children": [ "SecHealthUI.exe", "WerFault.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\\SecHealthUI.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\msvcrt.dll" ] }, "TextInputHost.exe-090C77C5426E84F8B39044C37152FA64": { "file_name": "TextInputHost.exe", "file_path": "C:\\Windows\\SystemApps\\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\\InputApp\\TextInputHost.exe", "hash_md5": "090C77C5426E84F8B39044C37152FA64", "hash_sha1": "4B9FAC8F6F517D0B685D8303BA36A98363E59BCE", "hash_sha256": "C480752FBA0E9DAF476B548248A47A2C6BF14F3DE8045945FBEE9F9E92A7B41A", "hash_sha384": "B289BBC2A89466A176796C2C701563CEB20D233B2C2539D9EB42FE1F8AB79CC1A86591E9AFCDD2BB5C1DA5414941917A", "hash_sha512": "4D9BC5B5F0B4DB34E18DBA03CB0988A75A73F9A5C2D267307AD9C0F9CDA05AD4DF48FD712D14B1D95F82D0F11FD0BAAA53B23B4A099BDEE005DE4A0947705F53", "hash_ssdeep": "192:CaTuvZF9lmuNPsQRMJoO5H1WOGWbNp3qA/DBQABJs9mihqnajygfE:CaAZF/FPxH41WOGWbn/DBRJs9fleg8", "hash_imp": "8ACCE29A751A218EBBCA39B834A66F0B", "hash_pesha1": "58A8236E067D35919FF69A52BFD1B97D43F03F50", "hash_pe256": "EA56B9F41E04E89E46A98E041F0C8B0D14003E12307DA76F5FDC6126422369EA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "TextInputHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.22012.0.31", "meta_product_version": "2001.22012.0.31", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/c480752fba0e9daf476b548248a47a2c6bf14f3de8045945fbee9f9e92a7b41a/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\\InputApp\\TextInputHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "ScreenClippingHost.exe-E0B2D3AEEA39DA0BAC694E77ED7533ED": { "file_name": "ScreenClippingHost.exe", "file_path": "C:\\Windows\\SystemApps\\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\\ScreenClipping\\ScreenClippingHost.exe", "hash_md5": "E0B2D3AEEA39DA0BAC694E77ED7533ED", "hash_sha1": "204E8BAFD1292EA18081DBB55B65951E22000A20", "hash_sha256": "4BB0DD05BE05D654B4672BB12ED2EC187EE9BDB124606E2431B919C97937EE8B", "hash_sha384": "EE30589B5D390BCA69A9D314C1FFA5E9CD6E33471E8CE736623FA71B48A8AC59A399B076D9C3323DE6E3F2996E568766", "hash_sha512": "51784513B13E9562A55BED1B2CEF694E73EBB872C9F7750AE8D005BC6D67E87114A31ADBB32A3D5A3B545741F5479456E58B84C4E6DC99DF3B96E653280C3170", "hash_ssdeep": "192:Ms6D+10TmGHOp4fpO59QWJHWxHJYp3qA/DBQABJGmYihqnajygfLdRd:96MRGu6mQWJHWxp4/DBRJHplegD7d", "hash_imp": "44C701AD782D9785365B6D8072B898C8", "hash_pesha1": "E0C42B7CE858600105CF75CE77C351A4DA327F16", "hash_pe256": "C4DAE41D62368F78EE1FB41DFF189BEF6189FA376B75695B9A8F8DFDD5F58CE0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "ScreenClippingHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.22012.0.31", "meta_product_version": "2001.22012.0.31", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/4bb0dd05be05d654b4672bb12ed2ec187ee9bdb124606e2431b919c97937ee8b/detection", "runtime_modules": [ "C:\\Windows\\SystemApps\\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\\ScreenClipping\\ScreenClippingHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll" ] }, "explorer.exe-3EAF5EA1C929922873016439091C21A0": { "file_name": "explorer.exe", "file_path": "C:\\Windows\\explorer.exe", "hash_md5": "3EAF5EA1C929922873016439091C21A0", "hash_sha1": "32A63F39DE625BA8642545CCFC60F9E3A91DC80F", "hash_sha256": "04DD313F7DBD4F392ADA63D41DB19EABB4B48C81A5F322EC6712F54F0DC70625", "hash_sha384": "AD5E59EC823E18BBC4B6AEE4D4DD6FD3D7109DA0EC635FC939285592942A62E0E4BC5D71A69E0457CF150B6CB85DF281", "hash_sha512": "0DED8D57D5E662A6454FCD4B25EE85D0455C512FCE2A347E27DAF17149B937165F28D79CC0DA6CDF37DD6E1BA64B9817BC72A57E367E5B49AE0F839EABF3675C", "hash_ssdeep": "49152:zXBDcrRUJNLEQXfcoGdDDLNK9Bxsh4zu21J4uzcldGJGT/7UZoK9/47uc0Kz/TWc:A2E+93XJ/zcvFspw8a0cD7", "hash_imp": "95098181244E528957BBEA6BB1AB119C", "hash_pesha1": "A8D736E2292C139F111A1616D379C5A644B85E41", "hash_pe256": "2753EB0B153482ED2A0FDA987C2193CB5B898907EF99CE1B00F6CD002305CB9F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Explorer", "meta_original_filename": "EXPLORER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.610 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.610", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/04dd313f7dbd4f392ada63d41db19eabb4b48c81a5f322ec6712f54f0dc70625/detection", "runtime_modules": [ "C:\\Windows\\explorer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\SYSTEM32\\AEPIC.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\SYSTEM32\\TWINAPI.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\SYSTEM32\\powrprof.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\SYSTEM32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\windows.storage.dll", "C:\\Windows\\SYSTEM32\\dxgi.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\SYSTEM32\\WININET.dll", "C:\\Windows\\SYSTEM32\\UxTheme.dll", "C:\\Windows\\SYSTEM32\\twinapi.appcore.dll", "C:\\Windows\\SYSTEM32\\dwmapi.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll" ] }, "splwow64.exe-AA4138C0FBC6D41F9EBC5C4EFE20ECCA": { "file_name": "splwow64.exe", "file_path": "C:\\Windows\\splwow64.exe", "hash_md5": "AA4138C0FBC6D41F9EBC5C4EFE20ECCA", "hash_sha1": "57CE75D728BCFCAA6F373C9461D7D4DA0787842E", "hash_sha256": "EDEC0ED8FB5DF666834D1C1D49C920CE23060A81B8121E4BC8E46369E026CF7E", "hash_sha384": "BA2FEDF3C3455AC5D8ACDE9FED1A0927A41932ACB97ED96AC02246B48042F65E91C2E73FBC6816461C11455D7D5A5308", "hash_sha512": "90D7BA835E1899FF1337253D2F50DCA9BFF1F8E811398C9A037B2B9D4148331B55E5017051744A72EAC3057532C7D34795E32F4CEA44F5F6F009458AF201B876", "hash_ssdeep": "3072:Z8TRNBWRNsoGlAi++KOn2ZsQgWlUHQbPRyZ2pPTo:eTRNByNsoGlAiJSsFUU8AZ2", "hash_imp": "260422772873DF4417E4B473F68B1ADE", "hash_pesha1": "BE5737DF8069F59F813B409CF5753B79266E475F", "hash_pe256": "F6E1D968E6039B13661D16027380C51B989D8B5D9B156520A9B1FD99B7F3CFC6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Print driver host for applications", "meta_original_filename": "splwow64.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.388 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.388", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/75", "filescan_vtlink": "https://www.virustotal.com/gui/file/edec0ed8fb5df666834d1c1d49c920ce23060a81b8121e4bc8e46369e026cf7e/detection", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\splwow64.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\SYSTEM32\\WINSPOOL.DRV", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\PrintIsolationProxy.dll", "C:\\Windows\\SYSTEM32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\SYSTEM32\\sspicli.dll" ] }, "SecHealthUI.exe-66D2B7A1A4EA74F9D83308E6DEC8DA77": { "file_name": "SecHealthUI.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\\SecHealthUI.exe", "hash_md5": "66D2B7A1A4EA74F9D83308E6DEC8DA77", "hash_sha1": "17E78E5860844F0F386D7221A9852C25E5D8D9E7", "hash_sha256": "5C4DAE002E96B96BB79CC2F5D59B74B969DEFAC7C8C1DB7AA19870C4BA55F9E9", "hash_sha384": "A34D8CE6C164E5866D1C1BE0F75B62172C28FFB1E0CC6A95351AA52A46AE72CD2E3D6F11BF0BCB3D8CFEDD5065D21622", "hash_sha512": "237D1363814CD1F47DDDE7ABD3B8BB3EA4B3E72A3B9C18949135F386BC800B2773B10E8A18BF37A7903894D827CCE1A61F840FA5C6C9C54DF8513390F7F1C97A", "hash_ssdeep": "49152:ghzDinsH46SCz2er5P0+ZFMlMb20D+oGnCsrYyFuZWowsFewI2Ko97qTYcbi6M6p:gh3jcn8GfAkG6M6T5j", "hash_imp": "15BA6368A49AB7C784AD5D60F47CD58B", "hash_pesha1": "C00F01E39A8EBD0AC8206584C5B0530E8181EB53", "hash_pe256": "62F21A06AB461CB0E57FD1FC85507132D77BC12E7F1DCD24990AA246AE98A5EC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Defender application", "meta_original_filename": "SecHealthUI.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/5c4dae002e96b96bb79cc2f5d59b74b969defac7c8c1db7aa19870c4ba55f9e9/detection/", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\\SecHealthUI.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL" ] }, "StartMenuExperienceHost.exe-1A22F5A210423A8BDDBC16102BD49E5D": { "file_name": "StartMenuExperienceHost.exe", "file_path": "C:\\Windows\\SystemApps\\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\\StartMenuExperienceHost.exe", "hash_md5": "1A22F5A210423A8BDDBC16102BD49E5D", "hash_sha1": "73CCE12CEFF63976D125732863375A38946199FE", "hash_sha256": "185339CAC3F7A459F91731D7DC1F50B55A19725F05BBF676BD99BA10CFB33010", "hash_sha384": "BDE31F8D350F2E7EEEE0CBBD0BF000750AC8C03C82C735CE423883D672AA7545850B03344CDDCEA90A6788268691D619", "hash_sha512": "B3BE7D27415E45AA0B1AD209A80DF891C9453806366EE8B8AA45C9AB81CF8D58786535F5C9B17DF26741FDDE45577BC670BA4DE65CA3134EA2BE5009E965EF18", "hash_ssdeep": "12288:lSBKWtVsf0z3uSPpvmJQX2e68ORkODsa6y86XuJQ:lbWtyf07Xpvm8JORkODs69", "hash_imp": "2E421B1476FFB1DB0FFA09D9C0541147", "hash_pesha1": "D069F842FDBEA73295C90345931881D7998A3BF2", "hash_pe256": "7393708F32E071D19AB0C361A78AA85C087AF078448D3FF3E6116032522EB336", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/62", "filescan_vtlink": "https://www.virustotal.com/gui/file/185339cac3f7a459f91731d7dc1f50b55a19725f05bbf676bd99ba10cfb33010/detection/", "runtime_modules": [ "C:\\Windows\\SystemApps\\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\\StartMenuExperienceHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\wincorlib.DLL", "C:\\Windows\\System32\\msvcrt.dll" ] }, "ShellExperienceHost.exe-AE0649A8A807B60E79B4E9C96529E3A5": { "file_name": "ShellExperienceHost.exe", "file_path": "C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe", "hash_md5": "AE0649A8A807B60E79B4E9C96529E3A5", "hash_sha1": "F9607A424E6D1CFCEEE0E205139B8A0CF0721309", "hash_sha256": "C8AF972A1AA4132C0C43B05B4B66515394F7A49235653AC273BB947E321E0BE2", "hash_sha384": "0A91CF82B7451234141F2635769B46A1B60F92EF15EE95012F751216AF144AB8636F2CD521F3AE4D7A39849C8392DC0C", "hash_sha512": "97E925AA79E5CFE428F4DF260AB819E938A789BA560B2BDC55B8667081ED2BD78151423E3FC20AA9282E7853254942E9CC1F6F16EB565B983588848674A755F8", "hash_ssdeep": "24576:MurW0hhIoiGw/qwsluJor7UWkDYRDIEcRqXnlqz7qpt4e:MurW0PIoiiLUs7UWaYRUqVUqce", "hash_imp": "72533FD2CE483CDC50D7D46F66737E44", "hash_pesha1": "A2847608E179B5CE03A02A7761C7F5689EB63939", "hash_pe256": "27A903E8B10EAC75F5E0A3D4415C450B4896636DAB2C884670FB9719D4BCB15A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Shell Experience Host", "meta_original_filename": "ShellExperienceHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19041.423 (WinBuild.160101.0800)", "meta_product_version": "10.0.19041.423", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/61", "filescan_vtlink": "https://www.virustotal.com/gui/file/c8af972a1aa4132c0c43b05b4b66515394f7a49235653ac273bb947e321e0be2/detection/", "children": [ "PowerToys.exe", "ShellExperienceHost.exe", "WerFault.exe" ], "runtime_handles": { "(RW-) C:\\xCyclopedia": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "BingWallpaperApp.exe-EA8FC88103A8E3047C3E8600FBCB572B": { "file_name": "BingWallpaperApp.exe", "file_path": "C:\\Users\\user\\AppData\\Local\\Microsoft\\BingWallpaperApp\\BingWallpaperApp.exe", "hash_md5": "EA8FC88103A8E3047C3E8600FBCB572B", "hash_sha1": "51C329B8BE8ABC381E49BA4FD42D2CBE67D4D74F", "hash_sha256": "C372D998C3D076EE063CD85C1BE0C4E06274530468C0004CC93545A6EA1156B1", "hash_sha384": "C72A525B81B747802A8BC39738427BDC71F7FF2A578C7D6AFBF017D7E31406C4212E68618FFCD9B1FC600D7FF5EB8661", "hash_sha512": "086A1E99B579E27FED36DA4599AF017D59E88B28F34BEACA067C07E78B34FDEBB23C3A351007A1ADEABB3F555BD722C802AC06ACF74D3C4E4EDEF75C1FDC1071", "hash_ssdeep": "196608:SCfyJoHLmGxSr9aV9DDYYZOVpbZgBifyJoHLmGxSr9aV9DDYK:S9JoHiSSr9NYZ0ZgBdJoHiSSr9NK", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "96ED203FD002D20D2D343293F8C1A7B25266105C", "hash_pe256": "165EBF19F09B2CC7DF4C96B84401EFF3EBCAD7E5FBC335E4D25DBD30925EF759", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000187721772155940C709000000000187", "signature_thumbprint": "2485A7AFA98E178CB8F30C9838346B514AEA4769", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Bing Wallpaper", "meta_original_filename": "BingWallpaperApp.exe", "meta_product_name": "Bing Wallpaper", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.0.7.6", "meta_product_version": "1.0.7.6", "meta_language": "Language Neutral", "meta_legal_copyright": " 2020 Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/c372d998c3d076ee063cd85c1be0c4e06274530468c0004cc93545a6ea1156b1/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\xCyclopedia": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_1532": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_32\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Numerics\\v4.0_4.0.0.0__b77a5c561934e089\\System.Numerics.dll": "File", "\\Windows\\Theme1665484522": "Section", "\\Sessions\\1\\Windows\\Theme289354956": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Core\\v4.0_4.0.0.0__b77a5c561934e089\\System.Core.dll": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.572_none_4296d9128a9564c1": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_32\\System.Data\\v4.0_4.0.0.0__b77a5c561934e089\\System.Data.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Runtime.Serialization\\v4.0_4.0.0.0__b77a5c561934e089\\System.Runtime.Serialization.dll": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Users\\user\\AppData\\Local\\Microsoft\\BingWallpaperApp\\BingWallpaperApp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "BWCProcessor.exe-DC976DAF22DEB2F90BC24869CE03D3D2": { "file_name": "BWCProcessor.exe", "file_path": "C:\\Users\\user\\AppData\\Local\\Microsoft\\BingWallpaperApp\\BWCProcessor.exe", "hash_md5": "DC976DAF22DEB2F90BC24869CE03D3D2", "hash_sha1": "D128A20834D4BEC836C464D6E614F57C1783D3A7", "hash_sha256": "820207F1CFE7424BC724D96EC1943704149B174809F1894D7758B03B28687140", "hash_sha384": "2253EDD274F3C136A7AF80CD967AA5FD3B5414EC0BF59ACA3F098FAA50150E53E607D60D053D14DD5E9127AFAE4DACB6", "hash_sha512": "B3C0DF71F377BB184D95AF9F62FEBA53C662BF61DDF1C4F596EAA5A62D54B85AD92AE1E1F98AE618F14BE4141DC2A233177D41415FECF9D92074ACDA8AFCB552", "hash_ssdeep": "12288:bf6luh9TIJCxvOcnTmV/RWPhY3+O3U32uuU7HqK1+01BY0KRr6BUGlu0a74STOl+:NTIJCxSV/khY3N3U32uzrp19TKRr+YTD", "hash_imp": "E98065242600539EBB0DB804366384B9", "hash_pesha1": "20FDAD79F8D8E585FA2E436BC6DF8D758CADEE4F", "hash_pe256": "B022CEF7538F9CC032D41E4862E693BCB7E95DC248F2A14B0F03F5C8FDC6DBCF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000187721772155940C709000000000187", "signature_thumbprint": "2485A7AFA98E178CB8F30C9838346B514AEA4769", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BWCProcessor", "meta_original_filename": "BWCProcessor.exe", "meta_product_name": "BWCProcessor", "meta_company_name": " 2020 Microsoft Corporation", "meta_file_version": "1.0.7.6", "meta_product_version": "1.0.7.6", "meta_language": "English (United States)", "meta_legal_copyright": " 2020 Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/820207f1cfe7424bc724d96ec1943704149b174809f1894d7758b03b28687140/detection/", "runtime_modules": [ "C:\\Users\\user\\AppData\\Local\\Microsoft\\BingWallpaperApp\\BWCProcessor.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "BWCUpdater.exe-DC3832152BE72828750DAC6E2C87D4B1": { "file_name": "BWCUpdater.exe", "file_path": "C:\\Users\\user\\AppData\\Local\\Microsoft\\BingWallpaperApp\\BWCUpdater.exe", "hash_md5": "DC3832152BE72828750DAC6E2C87D4B1", "hash_sha1": "F9948CA39F765B922C32B31B28A9224A21F3BC3A", "hash_sha256": "0B2A0C5B9C3A794DE91A5522CF4B841581797C95F1392E936DD3A083A5C3A145", "hash_sha384": "05DB29AA9FFB9B3D3F4A56DEC182549F3F0D6DA750762463B7B4A4891CDDF839ACBD09C51FCA75490A93FE261D40CEAB", "hash_sha512": "945A755CC2F8ADE96BBD48D72B9EAE92FA8422BE7CF6AAF72EA14DA0C26413A6206BC54076A4B31362228272072DAD9E436EC48FBD2A9FFCD303E5BD011030EE", "hash_ssdeep": "6144:vkIdhoxu3KcrMuJQS1yYaWGMeVIaRAnlK5t9JMeuG9YNpOU:vDhoxu3KcrMuJbEUeVIaWnlK5t93uG9m", "hash_imp": "980E273C213CE26D06EAD04428337368", "hash_pesha1": "54B3F247661D31FFC928E155FD25AA1E64BBF64A", "hash_pe256": "7BE7F4F9544E3A01F4000D49B30F8C4221ECF68681B19B91AFC759ADDF6EB8D7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000187721772155940C709000000000187", "signature_thumbprint": "2485A7AFA98E178CB8F30C9838346B514AEA4769", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BWCUpdater", "meta_original_filename": "BWCUpdater.exe", "meta_product_name": "BWCUpdater", "meta_company_name": " 2020 Microsoft Corporation", "meta_file_version": "1.0.7.7", "meta_product_version": "1.0.7.7", "meta_language": "English (United States)", "meta_legal_copyright": " 2020 Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/61", "filescan_vtlink": "https://www.virustotal.com/gui/file/0b2a0c5b9c3a794de91a5522cf4b841581797c95f1392e936dd3a083a5c3a145/detection/", "runtime_modules": [ "C:\\Users\\user\\AppData\\Local\\Microsoft\\BingWallpaperApp\\BWCUpdater.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "action_runner.exe-7913456F440A99B152DDDDDCFA6CDC22": { "file_name": "action_runner.exe", "file_path": "C:\\Users\\user\\AppData\\Local\\Temp\\action_runner.exe", "hash_md5": "7913456F440A99B152DDDDDCFA6CDC22", "hash_sha1": "9367DC9BC25B7FF9190237CB1FE4F8F90100D391", "hash_sha256": "6587BA1F05405A2E5655E8B4C95D6D70D543894A00451F418AC548E6BB5D320B", "hash_sha384": "1AC3CA38E446E196292D1E1E1F76D903161B0D864A79FE51D74739EC6F9EE7EDB2D2C2E7FF1A6B5F51FD478A7DD02DC8", "hash_sha512": "17ADE056A3D96B015764334B1FD5453928E3AAED789F001663F6C40D0F22FF3E5922E15AEC9703469E6C42ED71D400A4CE2AA569A4844A1C37D8EA9118686734", "hash_ssdeep": "6144:XiaUviy9/GJ2NTlikp0Gbo9coeX8f1053ecSyI+rd11e8CfVGd3yfBkdA+ohBS0M:hy9/GJAikAcfvayI+B+BfYA+oZZaoYR", "hash_imp": "7233A0C46408E1C57C4A60564D677521", "hash_pesha1": "C6D7AF2A2D50B8993B9B819BEC8FC4C2D492008C", "hash_pe256": "A4C5DDF5B1B7A456CB980D3C285D9F160ACA1281E1A0CB4665AD6CA3BEC6FBE2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001864D2175A0D907BE2C000000000186", "signature_thumbprint": "8EE1E4E037942BE5BC7E58B061FB559BDC381D82", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PowerToys ActionRunner", "meta_original_filename": "action_runner.exe", "meta_product_name": "PowerToys", "meta_company_name": "Microsoft Corporation", "meta_file_version": "0.23.0.0", "meta_product_version": "0.23.0.0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 2020 Microsoft Corporation", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/6587ba1f05405a2e5655e8b4c95d6d70d543894a00451f418ac548e6bb5d320b/detection/", "runtime_modules": [ "C:\\Users\\user\\AppData\\Local\\Temp\\action_runner.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "windowsdesktop-runtime.exe-5123CAF3B8355A4F278C3B08AFB23090": { "file_name": "windowsdesktop-runtime.exe", "file_path": "C:\\Users\\user\\AppData\\Local\\Temp\\windowsdesktop-runtime.exe", "hash_md5": "5123CAF3B8355A4F278C3B08AFB23090", "hash_sha1": "63B4DE61FD5D62829C636534D02B2846DD97B845", "hash_sha256": "75F80882ADE213B5D75AB4E003CFEAAFE93D4F377A5D7A76077BB82728BCBA58", "hash_sha384": "50D1ADA240631D4F8B3077DFC6313437F5475112DD62B5DD0354ECA24C3B4D2EF40287C9767C21D0C11776AE30119B73", "hash_sha512": "6B413E1A434339E084FC2E194A59251ACF144FA5351998F505261B4459664FFC611447BF476FBF29624FBD346427B9044C53D301DA99D63C6ED2EE6651AD4D4D", "hash_ssdeep": "1572864:Oo0odQiv4fn/Sd6TP2+u57+JDw1YVVk5osdR8Y:Oo0oanTP2+6+meVkSsdh", "hash_imp": "1A5CDBF711FEE14B077E599D13FDDAB2", "hash_pesha1": "922A00527FA8AE75ABCD66D81A5AC17079ADC22A", "hash_pe256": "7786A9A8E621737D02EFC0A2AEBB2DE8C73E381C01206471B8ECCDC4A6FF9855", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000187721772155940C709000000000187", "signature_thumbprint": "2485A7AFA98E178CB8F30C9838346B514AEA4769", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Desktop Runtime - 3.1.6 (x64)", "meta_original_filename": "windowsdesktop-runtime-3.1.6-win-x64.exe", "meta_product_name": "Microsoft Windows Desktop Runtime - 3.1.6 (x64)", "meta_company_name": "Microsoft Corporation", "meta_file_version": "3.1.6.29016", "meta_product_version": "3.1.6.29016", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/75f80882ade213b5d75ab4e003cfeaafe93d4f377a5d7a76077bb82728bcba58/detection/", "children": "windowsdesktop-runtime.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\xCyclopedia": "File", "(R-D) C:\\Users\\user\\AppData\\Local\\Temp\\windowsdesktop-runtime.exe": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\Temp\\{F8C9A86D-7869-43C9-9F6E-206A2062826F}\\.cr\\windowsdesktop-runtime.exe": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Users\\user\\AppData\\Local\\Temp\\windowsdesktop-runtime.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "action_runner.exe-73A6DD5DB7FF6212549F47AF75E007E2": { "file_name": "action_runner.exe", "file_path": "C:\\Program Files\\PowerToys\\action_runner.exe", "hash_md5": "73A6DD5DB7FF6212549F47AF75E007E2", "hash_sha1": "131A6FF6484D53536257E12EB70F44F1C02217F0", "hash_sha256": "63CA35D2C97520EEB96265A1D90449D2138597F43BACEEE8D3F126A222191C4A", "hash_sha384": "88C1DA0A766C002163701A2E159922F247FA7FD490B68833CBEA45AA489898C399BC685562CA8611F7796BAD757BDCEE", "hash_sha512": "F6BEBC1BE26EB35E21A05C4AED5B67725E83A8D20D82628B4A16E8EF72552C75FFAEDDA4F6D890D124DEEE5FC86BDFFBA80B81ADE74F8275AB2FB0B6B0231AD6", "hash_ssdeep": "6144:3CaEv4q9/eJ2NTlikp0Gbo9coeX8f1053ecSyI+rd11e8CfVGd3yfBkdA+oYOqtW:Tq9/eJAikAcfvayI+B+BfYA+omZaoYn", "hash_imp": "7233A0C46408E1C57C4A60564D677521", "hash_pesha1": "C6CFA8618F91BA9951D217C5277F4D748268CAB3", "hash_pe256": "3A70C54111B3D30EED296AE449D6F3C7C64DB636ADA7CFBCB569BE6BFF4127BF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001864D2175A0D907BE2C000000000186", "signature_thumbprint": "8EE1E4E037942BE5BC7E58B061FB559BDC381D82", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PowerToys ActionRunner", "meta_original_filename": "action_runner.exe", "meta_product_name": "PowerToys", "meta_company_name": "Microsoft Corporation", "meta_file_version": "0.23.2.0", "meta_product_version": "0.23.2.0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 2020 Microsoft Corporation", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/63ca35d2c97520eeb96265a1d90449d2138597f43baceee8d3f126a222191c4a/detection/", "runtime_modules": [ "C:\\Program Files\\PowerToys\\action_runner.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll" ] }, "PowerToys.exe-9AF4545C8798CC3366870504BC9A8821": { "file_name": "PowerToys.exe", "file_path": "C:\\Program Files\\PowerToys\\PowerToys.exe", "hash_md5": "9AF4545C8798CC3366870504BC9A8821", "hash_sha1": "F8147FAE0B21499921377630F9BD02A07E083F04", "hash_sha256": "4FE089B9A2F007B07537EF682C92BCC5EED2AED4DECE0034FB4F340405680AEB", "hash_sha384": "8D74D13E115FA4FB52852EC5934F66E4F66FA54A868ACBF263AE0F230E17275B4AFDCB02F526B2E809F0C6E76074360D", "hash_sha512": "6755BC0567A3A2213EB9D20BB2EEA6B35FCE6300E25FB94BE2EF65BFDB2C54613325728AF3508C27091DC5ABB87968ED235F677742FB969942AE4D0877695736", "hash_ssdeep": "12288:29xRHHU81FNR+xWijXiUM615eGYnVTcmicZomYL3C8FGp0bPU:2DRSWoiUT5KnVTc9sGL3C8Fjc", "hash_imp": "6ED8EE6B7E669389A675C4783F2A263F", "hash_pesha1": "5EC65203F6F1B8C50134B0D9C089C6DC37367DC4", "hash_pe256": "5ACBDD4A847E9AF96B6719186086701B6ECA60765B56E31D903F16C68806C907", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001864D2175A0D907BE2C000000000186", "signature_thumbprint": "8EE1E4E037942BE5BC7E58B061FB559BDC381D82", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PowerToys Runner", "meta_original_filename": "PowerToys.exe", "meta_product_name": "PowerToys", "meta_company_name": "Microsoft Corporation", "meta_file_version": "0.23.2.0", "meta_product_version": "0.23.2.0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 2020 Microsoft Corporation", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/4fe089b9a2f007b07537ef682c92bcc5eed2aed4dece0034fb4f340405680aeb/detection/", "children": "ColorPicker.exe", "runtime_handles": { "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme1665484522": "Section", "\\Sessions\\1\\Windows\\Theme289354956": "Section", "(RW-) C:\\Program Files\\PowerToys": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.572_none_fae9a23b76193bbb": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\PowerToys\\PowerToys.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\SYSTEM32\\msi.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "PowerToysSettings.exe-8130FC9F772BABBA70A2805F32193673": { "file_name": "PowerToysSettings.exe", "file_path": "C:\\Program Files\\PowerToys\\PowerToysSettings.exe", "hash_md5": "8130FC9F772BABBA70A2805F32193673", "hash_sha1": "FFCC32DF0B41393018FE7B603F222CE6C79AFD4F", "hash_sha256": "081B2E251566A5DEC34CDC490743BBA5681839A0542FBC6CD6D14FBB32241FFD", "hash_sha384": "25F0B21684B3F19B789C6E2E18192DB8BC588EB01BB97B13880C01E2601B670D1FA636092E59BC33C143808A6127CBE5", "hash_sha512": "D644590C4B106497DEA93562793F389E0D6051757A7BC187F651ACF87330E8C40050780434B0A923C3F46C30AC3C5073B0C798060E9DCEEB623D6406BF561A1A", "hash_ssdeep": "6144:+gjn5Xx7uBM8VbGgtnhX+NbpMD3J13Usqk6nckk+iKNzuvzxoKDCe+seg9t:LlxsM8bhuNwXUs96ny+bPU", "hash_imp": "D946DF6D8FF364E24FF118D53A8C8F4F", "hash_pesha1": "B777A9064C0C7FE963C235F72142EC93806D631D", "hash_pe256": "AB73B1FB2F4AEEDFD4CCEB0B55E84CD61FB59B216BA2002D124D0B1F6F5AA59C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001864D2175A0D907BE2C000000000186", "signature_thumbprint": "8EE1E4E037942BE5BC7E58B061FB559BDC381D82", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PowerToys Settings", "meta_original_filename": "PowerToysSettings.exe", "meta_product_name": "PowerToys", "meta_company_name": "Microsoft Corporation", "meta_file_version": "0.23.2.0", "meta_product_version": "0.23.2.0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 2020 Microsoft Corporation", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/57", "filescan_vtlink": "https://www.virustotal.com/gui/file/081b2e251566a5dec34cdc490743bba5681839a0542fbc6cd6d14fbb32241ffd/detection/", "runtime_handles": { "(RW-) C:\\xCyclopedia": "File", "\\Windows\\Theme1665484522": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Sessions\\1\\Windows\\Theme289354956": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\PowerToys\\PowerToysSettings.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ], "runtime_window_title": "Error running settings" }, "ColorPicker.exe-566AA09D2B171D222A4508F86A9293E7": { "file_name": "ColorPicker.exe", "file_path": "C:\\Program Files\\PowerToys\\modules\\ColorPicker\\ColorPicker.exe", "hash_md5": "566AA09D2B171D222A4508F86A9293E7", "hash_sha1": "FD921AA6B8E8F9464AB5CE8422638B7B63A6E31D", "hash_sha256": "274134813E7DC413B3F70951E89A15B63A83757F72EDDF0FC6F2CDAF42665DC2", "hash_sha384": "B06971C91F3FD055FEDB9826C35ABA07183630A7127B10E617835A94285CD48A671959A1D9E5CB66BD1D8915D60205FB", "hash_sha512": "B9CD0C1232174E16E50C39C0B7E289E1DAEF2926FB15B8872A143DABCA64E36B531EF0A34E6480582AA4CC4F7E088D2F172F071B52D3211A801D0598B79B8981", "hash_ssdeep": "1536:9F3EQTDtR0IxU0idb4++avrQZEOKfeLEz0rkmVcliXF:9F3EQ30IdYzQWOKfeYz0rk8YU", "hash_imp": "n/a", "hash_pesha1": "68DEE25E621ED1D9A7BA4EF1E6A8780B06A8AEBB", "hash_pe256": "253570B49464E6CD3C07A23CB42892569E0A212B53A76243633D4DC2199B3C8C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001864D2175A0D907BE2C000000000186", "signature_thumbprint": "8EE1E4E037942BE5BC7E58B061FB559BDC381D82", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ColorPicker", "meta_original_filename": "ColorPicker.exe", "meta_product_name": "PowerToys", "meta_comments": "PowerToys ColorPicker", "meta_company_name": "Microsoft Corp.", "meta_file_version": "0.23.2.0", "meta_product_version": "0.23.2.0", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (C) 2020 Microsoft Corporation", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/274134813e7dc413b3f70951e89a15b63a83757f72eddf0fc6f2cdaf42665dc2/detection/", "runtime_handles": { "(RW-) C:\\xCyclopedia": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_3840": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\PresentationFramework\\v4.0_4.0.0.0__31bf3856ad364e35\\PresentationFramework.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\WindowsBase\\v4.0_4.0.0.0__31bf3856ad364e35\\WindowsBase.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xaml\\v4.0_4.0.0.0__b77a5c561934e089\\System.Xaml.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\PresentationCore\\v4.0_4.0.0.0__31bf3856ad364e35\\PresentationCore.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Core\\v4.0_4.0.0.0__b77a5c561934e089\\System.Core.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Windows\\Theme1665484522": "Section", "\\Sessions\\1\\Windows\\Theme289354956": "Section", "(R-D) C:\\Program Files\\PowerToys\\modules\\ColorPicker\\ManagedCommon.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\netstandard\\v4.0_2.0.0.0__cc7b13ffcd2ddd51\\netstandard.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\ColorPicker\\Telemetry.dll": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\UIAutomationTypes\\v4.0_4.0.0.0__31bf3856ad364e35\\UIAutomationTypes.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.ComponentModel.Composition\\v4.0_4.0.0.0__b77a5c561934e089\\System.ComponentModel.Composition.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\ColorPicker\\System.Windows.Interactivity.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\PowerToys\\modules\\ColorPicker\\ColorPicker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "FancyZonesEditor.exe-DE8F669623601C0148EBFD16A7FAE5FA": { "file_name": "FancyZonesEditor.exe", "file_path": "C:\\Program Files\\PowerToys\\modules\\FancyZones\\FancyZonesEditor.exe", "hash_md5": "DE8F669623601C0148EBFD16A7FAE5FA", "hash_sha1": "A3A895D50A79CDD58132BE7B8399D09B00AB3464", "hash_sha256": "34400BAB5CDB0C1CCA240A6AA487D9D8F10D6919C9264677DC74C09BC2403F97", "hash_sha384": "A1E0C092FE155017B8726DDF744D7B8132BB1FED7A7DA031FC455DB7FE01C4093F41F91912DBD6415FDA40F407A0D4E9", "hash_sha512": "F70EC15CE96C364A42920DBF09459AE70B261F3A9F0EBE77BAF0FF92A507C24F58DAA5D5736A6D254C465A3056FAFA7BE64CCBB950D4A00CF66905C7B41F61A2", "hash_ssdeep": "3072:E63e0xf5i8Pbe4bZKdmwAejb8EQk4D70rjDgvHU+/5xggvycbtG:ht+mijb4n0rj89/5x5tw", "hash_imp": "n/a", "hash_pesha1": "E4E849E5892B91B1A2AF842A0FDB7AE35BD7E4C6", "hash_pe256": "4CB5668613B03077D863028AD84AC839BB0FEE88D2FC287FF6D184BF579370A8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001864D2175A0D907BE2C000000000186", "signature_thumbprint": "8EE1E4E037942BE5BC7E58B061FB559BDC381D82", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "FancyZonesEditor", "meta_original_filename": "FancyZonesEditor.exe", "meta_product_name": "PowerToys", "meta_comments": "PowerToys FancyZones Editor", "meta_company_name": "Microsoft Corp.", "meta_file_version": "0.23.2.0", "meta_product_version": "0.23.2.0", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (C) 2020 Microsoft Corporation", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/34400bab5cdb0c1cca240a6aa487d9d8f10d6919c9264677dc74c09bc2403f97/detection/", "runtime_handles": { "(RW-) C:\\xCyclopedia": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4932": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\PresentationFramework\\v4.0_4.0.0.0__31bf3856ad364e35\\PresentationFramework.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\WindowsBase\\v4.0_4.0.0.0__31bf3856ad364e35\\WindowsBase.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xaml\\v4.0_4.0.0.0__b77a5c561934e089\\System.Xaml.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\PresentationCore\\v4.0_4.0.0.0__31bf3856ad364e35\\PresentationCore.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Core\\v4.0_4.0.0.0__b77a5c561934e089\\System.Core.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme1665484522": "Section", "\\Sessions\\1\\Windows\\Theme289354956": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\PowerToys\\modules\\FancyZones\\FancyZonesEditor.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll" ], "runtime_window_title": "FancyZones Editor Error" }, "ImageResizer.exe-6C82C1A8F21E08279B6F5814D8D90B53": { "file_name": "ImageResizer.exe", "file_path": "C:\\Program Files\\PowerToys\\modules\\ImageResizer\\ImageResizer.exe", "hash_md5": "6C82C1A8F21E08279B6F5814D8D90B53", "hash_sha1": "BF508DD482F5E7A6C6BFCA334A13566574242AC6", "hash_sha256": "9B55E865061DB98668BC739A0DE80186EFD54E6EE1FFA1A13D66389A730F8C24", "hash_sha384": "95280E041DB491A7A25491E74356AF74AA937DE33CB9EFF95D62781381F0B5D79685CFDBACFB463BE43DB36D0D1ACF60", "hash_sha512": "4D36C3DEB60C16A0B19169AC07710320683F8220CC43664CF011C92035DEC19509474ADA8994EE3EF2F24E62817B90B06EB59F7424F1E70B9EA59C378D2D2BB2", "hash_ssdeep": "3072:bameheVXijxReJLv4pqgGN0FPCvqwozzKqqeJLv4pqgGN0F5CvqwTj:babhpVReJT480FTzzHqeJT480Fk", "hash_imp": "n/a", "hash_pesha1": "B228BB6196CC1801CFADBE0006FA47D8A88038A1", "hash_pe256": "DAF43EFE2B0BF87F141202F8CFA99B6C0932999B39631938D6353DC358B48220", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001864D2175A0D907BE2C000000000186", "signature_thumbprint": "8EE1E4E037942BE5BC7E58B061FB559BDC381D82", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ImageResizer", "meta_original_filename": "ImageResizer.exe", "meta_product_name": "ImageResizer", "meta_company_name": "Microsoft Corp.", "meta_file_version": "0.23.2.0", "meta_product_version": "0.23.2.0", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (C) 2019 Microsoft Corp.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/56", "filescan_vtlink": "https://www.virustotal.com/gui/file/9b55e865061db98668bc739a0de80186efd54e6ee1ffa1a13d66389a730f8c24/detection/", "runtime_handles": { "(RW-) C:\\xCyclopedia": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4756": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\PresentationFramework\\v4.0_4.0.0.0__31bf3856ad364e35\\PresentationFramework.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\WindowsBase\\v4.0_4.0.0.0__31bf3856ad364e35\\WindowsBase.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xaml\\v4.0_4.0.0.0__b77a5c561934e089\\System.Xaml.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\ImageResizer\\GalaSoft.MvvmLight.Platform.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Core\\v4.0_4.0.0.0__b77a5c561934e089\\System.Core.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\PresentationCore\\v4.0_4.0.0.0__31bf3856ad364e35\\PresentationCore.dll": "File", "\\Windows\\Theme1665484522": "Section", "\\Sessions\\1\\Windows\\Theme289354956": "Section", "(R-D) C:\\Program Files\\PowerToys\\modules\\ImageResizer\\GalaSoft.MvvmLight.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Runtime\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Runtime.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.ObjectModel\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.ObjectModel.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\ImageResizer\\Newtonsoft.Json.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Collections\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Collections.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Numerics\\v4.0_4.0.0.0__b77a5c561934e089\\System.Numerics.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Runtime.Serialization\\v4.0_4.0.0.0__b77a5c561934e089\\System.Runtime.Serialization.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\System.Data\\v4.0_4.0.0.0__b77a5c561934e089\\System.Data.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\PowerToys\\modules\\ImageResizer\\ImageResizer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll" ] }, "PowerLauncher.exe-0831705DB7DA6426E602950F1DFF6343": { "file_name": "PowerLauncher.exe", "file_path": "C:\\Program Files\\PowerToys\\modules\\launcher\\PowerLauncher.exe", "hash_md5": "0831705DB7DA6426E602950F1DFF6343", "hash_sha1": "6E994E5B21098B2176436281C7A2955E7F041926", "hash_sha256": "07F71AF4B32DEF22BBF13A6FC53AC31B17A74AECCE5903F165591E4ABA1637AB", "hash_sha384": "F438F70CEF4EDE5E2774E969DCC751683081BE9A7AB4901ED6C8A50FEB52189F84C2949FB9676E49B06A58804FA7A14A", "hash_sha512": "938C9EAE0E3329B891B15367512883EA58CF95D6985E432140867C2D83193EF3D72194832A65C64687176759C1A4720D3142CA748AABFD7D86F741906F93FD10", "hash_ssdeep": "3072:x8eBqhy5aV5gwqY8sXwoEHXfwaN+M+/ORSs5G2Ms4J6TFZboQ3prme:xhT1sXOfDj+/r6Jqqp1", "hash_imp": "7D19699275E08B389D5869DC7132EFBC", "hash_pesha1": "BB60C590C3C2CF9120550FF03449A8481B2FD858", "hash_pe256": "AC79A700484355292BC0237CB9AED459C0FD285C04B52525291AFD0519065378", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001864D2175A0D907BE2C000000000186", "signature_thumbprint": "8EE1E4E037942BE5BC7E58B061FB559BDC381D82", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PowerLauncher", "meta_original_filename": "PowerLauncher.dll", "meta_product_name": "PowerToys", "meta_comments": "PowerToys PowerLauncher", "meta_company_name": "Microsoft Corporation", "meta_file_version": "0.23.2.0", "meta_product_version": "0.23.2.0", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (C) 2020 Microsoft Corporation", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/07f71af4b32def22bbf13a6fc53ac31b17a74aecce5903f165591e4aba1637ab/detection/", "runtime_handles": { "(RW-) C:\\xCyclopedia": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Private.CoreLib.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\PowerLauncher.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\PresentationFramework.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\WindowsBase.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\System.Xaml.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.Extensions.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Threading.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\Microsoft.Win32.SystemEvents.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.ComponentModel.EventBasedAsync.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Threading.Tasks.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.IO.Pipes.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Security.AccessControl.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Security.Principal.Windows.dll": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\Wox.Infrastructure.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\Pinyin4Net.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\mscorlib.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\System.IO.Packaging.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\netstandard.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Private.Uri.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\PresentationCore.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\DirectWriteForwarder.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.InteropServices.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.CompilerServices.VisualC.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Diagnostics.Debug.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Resources.ResourceManager.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\Microsoft.Win32.Primitives.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Collections.NonGeneric.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Linq.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Collections.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\Microsoft.Win32.Registry.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Collections.Specialized.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.ComponentModel.Primitives.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Diagnostics.Process.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\System.Configuration.ConfigurationManager.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Threading.Thread.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Xml.ReaderWriter.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Private.Xml.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.IO.FileSystem.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Net.WebClient.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Memory.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Security.Cryptography.Algorithms.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Text.Encoding.Extensions.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\Microsoft.PowerToys.Settings.UI.Lib.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\PowerToysInterop.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Threading.ThreadPool.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Diagnostics.TraceSource.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.ComponentModel.TypeConverter.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\System.Windows.Extensions.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.ComponentModel.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Collections.Concurrent.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.ObjectModel.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Net.Requests.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Net.Primitives.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Security.Principal.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Net.WebHeaderCollection.dll": "File", "\\Windows\\Theme1665484522": "Section", "\\Sessions\\1\\Windows\\Theme289354956": "Section", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\ManagedCommon.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\Wox.Plugin.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\Wox.Core.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\Telemetry.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Diagnostics.Tracing.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\PowerLauncher.Telemetry.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\NLog.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Diagnostics.FileVersionInfo.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Threading.Timer.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.IO.FileSystem.Watcher.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Data.Common.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Net.Mail.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Net.Sockets.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Linq.Expressions.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Diagnostics.Tools.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\NLog.Extensions.Logging.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\Microsoft.Extensions.Logging.Abstractions.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\Microsoft.Extensions.Logging.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\ControlzEx.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\PresentationFramework-SystemXml.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\MahApps.Metro.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\System.Windows.Controls.Ribbon.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\PresentationFramework-SystemData.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.Numerics.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.Serialization.Formatters.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "(R--) C:\\Program Files\\PowerToys\\modules\\launcher\\Images\\app.dark.png": "File", "(R--) C:\\Program Files\\PowerToys\\modules\\launcher\\Images\\app_error.dark.png": "File", "(R--) C:\\Program Files\\PowerToys\\modules\\launcher\\Images\\app.light.png": "File", "(R--) C:\\Program Files\\PowerToys\\modules\\launcher\\Images\\app_error.light.png": "File", "(R-D) C:\\Program Files\\PowerToys\\modules\\launcher\\Newtonsoft.Json.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.WindowsRuntime.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Drawing.Primitives.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Linq.Parallel.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.Serialization.Primitives.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Reflection.Emit.ILGeneration.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Reflection.Primitives.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Reflection.Emit.Lightweight.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\System.Drawing.Common.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.572_none_fae9a23b76193bbb": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Core.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.Loader.dll": "File", "(R-D) C:\\Windows\\System32\\WinMetadata\\Windows.Foundation.winmd": "File", "(R-D) C:\\Windows\\System32\\WinMetadata\\Windows.ApplicationModel.winmd": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.InteropServices.WindowsRuntime.dll": "File", "(RWD) C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Threading.Overlapped.dll": "File", "(RWD) C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs": "File", "(R-D) C:\\Windows\\System32\\WinMetadata\\Windows.Management.winmd": "File", "(RWD) C:\\Users\\user\\Desktop": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Security.Claims.dll": "File", "(R-D) C:\\Windows\\System32\\WinMetadata\\Windows.Storage.winmd": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Buffers.dll": "File", "(R-D) C:\\Windows\\System32\\WinMetadata\\Windows.System.winmd": "File", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db": "Section", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Xml.XDocument.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Private.Xml.Linq.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\msxml6r.dll.mui": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\Accessibility.dll": "File", "(RWD) C:\\Windows\\SystemApps\\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\\AppxManifest.xml": "File", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "(RWD) C:\\Windows\\SystemApps\\Microsoft.Windows.Search_cw5n1h2txyewy\\AppxManifest.xml": "File", "(RWD) C:\\Windows\\ImmersiveControlPanel\\appxmanifest.xml": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "(RWD) C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\AppxManifest.xml": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Diagnostics.StackTrace.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Reflection.Metadata.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Collections.Immutable.dll": "File" }, "runtime_modules": [ "C:\\Program Files\\PowerToys\\modules\\launcher\\PowerLauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "Microsoft.PowerToys.Settings.UI.exe-C34132C8CC696831759D14393497ADA9": { "file_name": "Microsoft.PowerToys.Settings.UI.exe", "file_path": "C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.PowerToys.Settings.UI.exe", "hash_md5": "C34132C8CC696831759D14393497ADA9", "hash_sha1": "FD04F621C96D377CDB1628CCECA2806202424A3C", "hash_sha256": "49C9E1D36B8876832C5306E1CC25DC2F6CB30287455EDBFBE2FB9D48397FB720", "hash_sha384": "881B04E220D417201B6B767803554D99D272D60D565185035BCB3D3B592CA3605005EE36799B53EE25CA73E9F42F576C", "hash_sha512": "14B9DBDB63AE32F213D4F46A5BBEAC0D7F842876384C3C8FBFC9E91DF1D549A019D4DF15924E54D2990DCF785F865BB7B70E84F2462F3257A77600884645BCBE", "hash_ssdeep": "3072:9gmw3vyhyAqoIiGzQqfc1iuaSvsEeKxFR1Uw+Dvf5t258mHDeADtrUwl:WypIi1sSvsEeK0D35A58eFxp", "hash_imp": "n/a", "hash_pesha1": "8EBCA7D5A0B112FF42825C109B05EA4A843E160B", "hash_pe256": "69A2E556760A2CDEA270D45CA267C24A0557AD3017EED647F0F9FB38E1B975DD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001864D2175A0D907BE2C000000000186", "signature_thumbprint": "8EE1E4E037942BE5BC7E58B061FB559BDC381D82", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft.PowerToys.Settings.UI", "meta_original_filename": "Microsoft.PowerToys.Settings.UI.exe", "meta_product_name": "PowerToys", "meta_comments": "PowerToys Settings UI", "meta_company_name": "Microsoft Corp.", "meta_file_version": "0.23.2.0", "meta_product_version": "0.23.2.0", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (C) 2020 Microsoft Corp.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/49c9e1d36b8876832c5306e1cc25dc2f6cb30287455edbfbe2fb9d48397fb720/detection/", "error": "\nUnhandled Exception: System.IO.FileNotFoundException: Could not load file or assembly 'System.Runtime, Version=4.2.1.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a' or one of its dependencies. The system cannot find the file specified.\n", "children": [ "Microsoft.PowerToys.Settings.UI.exe", "WerFault.exe" ], "runtime_handles": { "(RW-) C:\\xCyclopedia": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_3704": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.PowerToys.Settings.UI.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "Microsoft.PowerToys.Settings.UI.Runner.exe-AC41EF8F180E8AF6483406690F34B8A6": { "file_name": "Microsoft.PowerToys.Settings.UI.Runner.exe", "file_path": "C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.PowerToys.Settings.UI.Runner.exe", "hash_md5": "AC41EF8F180E8AF6483406690F34B8A6", "hash_sha1": "36694187B6E183A89A866A8CB794F5801FCB1003", "hash_sha256": "6C504B2828B8A3CB4EBDEA5005F1E99CC8DD21E4C78DD41C64B8800545FB65DB", "hash_sha384": "A554BF9A271A938AB48F3302E6FA17518D7BBA89194E01C7A9706FE6D4F744A8C20EFD2415A38A7682CFA95093371FAB", "hash_sha512": "07056003D0AB986F1C1042F2924F46E54E31E703CBB6FFAE8C9B8A7ACCEA9A6689959A87D94B3995B08B08EDBFFC2C437C5D3DE2C6393A806917B706F2A67205", "hash_ssdeep": "3072:+8eBqhy5aV5gwqY8sXwoEHXfwaN+M+/ORSs5G2Ms4f6TFZbude+seUmB3sTK:+hT1sXOfDj+/N6JAde+se5", "hash_imp": "7D19699275E08B389D5869DC7132EFBC", "hash_pesha1": "479FCA843B72D1FD4D163FF98D1E5B9CD7E295F4", "hash_pe256": "3495B645E1B3719BF0D8ADBE489B0FD6F007231A2EA568D651AC044EA270F14A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001864D2175A0D907BE2C000000000186", "signature_thumbprint": "8EE1E4E037942BE5BC7E58B061FB559BDC381D82", "signature_issuer": "CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft.PowerToys.Settings.UI.Runner", "meta_original_filename": "Microsoft.PowerToys.Settings.UI.Runner.dll", "meta_product_name": "PowerToys", "meta_comments": "PowerToys Settings UI Runner", "meta_company_name": "Microsoft Corporation", "meta_file_version": "0.23.2.0", "meta_product_version": "0.23.2.0", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (C) 2020 Microsoft Corporation", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/6c504b2828b8a3cb4ebdea5005f1e99cc8dd21e4c78dd41c64b8800545fb65db/detection/", "runtime_handles": { "(RW-) C:\\xCyclopedia": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Private.CoreLib.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.PowerToys.Settings.UI.Runner.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.PowerToys.Settings.UI.exe": "File", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.Toolkit.Win32.UI.XamlHost.winmd": "File", "(R-D) C:\\Windows\\System32\\WinMetadata\\Windows.UI.Xaml.winmd": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\mscorlib.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.InteropServices.WindowsRuntime.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\PresentationFramework.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\WindowsBase.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\System.Xaml.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\ManagedCommon.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\netstandard.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\PowerToysInterop.dll": "File", "(R-D) C:\\Windows\\System32\\WinMetadata\\Windows.UI.winmd": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Collections.NonGeneric.dll": "File", "(R-D) C:\\Windows\\System32\\WinMetadata\\Windows.Foundation.winmd": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.WindowsRuntime.dll": "File", "(R-D) C:\\Windows\\System32\\WinMetadata\\Windows.System.winmd": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Program Files\\PowerToys\\SettingsUIRunner": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.Xaml.Interactivity.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.PowerToys.Settings.UI.Lib.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.ObjectModel.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Collections.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.Toolkit.Uwp.UI.dll": "File", "(R-D) C:\\Windows\\System32\\WinMetadata\\Windows.Globalization.winmd": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Threading.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.UI.Xaml.winmd": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Numerics.Vectors.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.WindowsRuntime.UI.Xaml.dll": "File", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.Xaml.Interactions.dll": "File", "(R-D) C:\\Windows\\System32\\WinMetadata\\Windows.Data.winmd": "File", "\\Sessions\\1\\BaseNamedObjects\\1714HWNDInterface:330526": "Section", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.InteropServices.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\System.IO.Packaging.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Private.Uri.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\PresentationCore.dll": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\DirectWriteForwarder.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.Extensions.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.CompilerServices.VisualC.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Diagnostics.Debug.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Resources.ResourceManager.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\Microsoft.Win32.Primitives.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Linq.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\Microsoft.Win32.Registry.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Collections.Specialized.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.ComponentModel.Primitives.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Diagnostics.Process.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Threading.Thread.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\System.Configuration.ConfigurationManager.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Xml.ReaderWriter.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Private.Xml.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.IO.FileSystem.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Net.WebClient.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Memory.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Security.Cryptography.Algorithms.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Text.Encoding.Extensions.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Threading.Tasks.dll": "File", "\\Windows\\Theme1665484522": "Section", "\\Sessions\\1\\Windows\\Theme289354956": "Section", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.ComponentModel.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Diagnostics.TraceSource.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.ComponentModel.TypeConverter.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\System.Windows.Extensions.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Threading.ThreadPool.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Collections.Concurrent.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\Telemetry.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Diagnostics.Tracing.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\UIAutomationTypes.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.Toolkit.Wpf.UI.XamlHost.dll": "File", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.Toolkit.Win32.UI.XamlHost.Managed.dll": "File", "(RW-) C:\\Windows\\System32": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\PresentationFramework.Aero2.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\1714HWNDInterface:330528": "Section", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Diagnostics.StackTrace.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Globalization.dll": "File", "(R-D) C:\\Windows\\System32\\WinMetadata\\Windows.ApplicationModel.winmd": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Reflection.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Reflection.Extensions.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Buffers.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Text.Json.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Reflection.Primitives.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Reflection.Emit.Lightweight.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Reflection.Emit.ILGeneration.dll": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\3.1.6\\System.Runtime.CompilerServices.Unsafe.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\msctfui.dll.mui": "File", "(R-D) C:\\Program Files\\dotnet\\shared\\Microsoft.WindowsDesktop.App\\3.1.6\\UIAutomationProvider.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\1714HWNDInterface:2e0394": "Section", "(R-D) C:\\Program Files\\PowerToys\\SettingsUIRunner\\Assets\\Modules\\PT.png": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "(RWD) C:\\Windows\\Fonts\\segoeuib.ttf": "File", "(R-D) C:\\Windows\\System32\\en-US\\windows.ui.xaml.dll.mui": "File", "(RWD) C:\\Windows\\Fonts\\seguisb.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\PowerToys\\SettingsUIRunner\\Microsoft.PowerToys.Settings.UI.Runner.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Program Files\\dotnet\\host\\fxr\\3.1.6\\hostfxr.dll" ], "runtime_window_title": "Forbidden" }, "mRemoteNG.exe-26D6A0729744CDFE6B2BF38243F6E287": { "file_name": "mRemoteNG.exe", "file_path": "C:\\Program Files (x86)\\mRemoteNG\\mRemoteNG.exe", "hash_md5": "26D6A0729744CDFE6B2BF38243F6E287", "hash_sha1": "8141BFDCFC280F29B48CE1C751E9515AC08EEB1C", "hash_sha256": "6EC4C234894AC6CA598477E45B6EB5C187B1B75E250A6C78954805463BDA17B9", "hash_sha384": "1133FCF9A60558302C0942728F520AAF95722E3638D2DB49317AF80C5DFC02FA0748368E7D5B5FE3F74A078A33F9A43B", "hash_sha512": "0CD09B2D07AF9FB219531D798C5D1A223B935423DEE9FDDC91FDD5454E87B0C3E974B6EE416D9F18856AD0C0A3DC7A83FA9360EAF9BF166528832A8FC80E4006", "hash_ssdeep": "24576:1+i8BCRKyo8UWX0HNNIFb9sv7VdyMOJlXcTJwTK6Ej7jc:eBC0vBWX0HNNIFbavLyMOJlXcdwTZG3c", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "92B93E3D3CEF6871358E670C55EDE8BECF7D724B", "hash_pe256": "88E0D15B0EB011384BCDE73BDA9F40B009A45BD02C72D5D45DE2B810EA5703A3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "0C1FDD2DDD38ACC9AFE620097FBB3B65", "signature_thumbprint": "DEFFB77C09F5ADC3691A0EA8A36E2617577AF8AB", "signature_issuer": "CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US", "signature_subject": "CN=David Sparer, O=David Sparer, L=Prescott, S=Wisconsin, C=US", "meta_description": "mRemoteNG", "meta_original_filename": "mRemoteNG.exe", "meta_product_name": "mRemoteNG", "meta_comments": "Multi-protocol remote connections manager", "meta_file_version": "1.76.20.24615", "meta_product_version": "1.76.20.24615", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright 2019 mRemoteNG Dev Team; 2010-2013 Riley McArdle; 2007-2009 Felix Deimel", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/6ec4c234894ac6ca598477e45b6eb5c187b1b75e250a6c78954805463bda17b9/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\xCyclopedia": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_3288": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_32\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "\\Sessions\\1\\BaseNamedObjects\\UrlZonesSM_user": "Section", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(R-D) C:\\Program Files (x86)\\mRemoteNG\\WeifenLuo.WinFormsUI.Docking.dll": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "\\Windows\\Theme1665484522": "Section", "\\Sessions\\1\\Windows\\Theme289354956": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.572_none_4296d9128a9564c1": "File", "(R-D) C:\\Program Files (x86)\\mRemoteNG\\en-US\\mRemoteNG.resources.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Core\\v4.0_4.0.0.0__b77a5c561934e089\\System.Core.dll": "File", "(R-D) C:\\Program Files (x86)\\mRemoteNG\\WeifenLuo.WinFormsUI.Docking.ThemeVS2003.dll": "File", "(R-D) C:\\Program Files (x86)\\mRemoteNG\\WeifenLuo.WinFormsUI.Docking.ThemeVS2012.dll": "File", "(R-D) C:\\Program Files (x86)\\mRemoteNG\\WeifenLuo.WinFormsUI.Docking.ThemeVS2013.dll": "File", "(R-D) C:\\Program Files (x86)\\mRemoteNG\\WeifenLuo.WinFormsUI.Docking.ThemeVS2015.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml.Linq\\v4.0_4.0.0.0__b77a5c561934e089\\System.Xml.Linq.dll": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Program Files (x86)\\mRemoteNG\\MagicLibrary.dll": "File", "\\Sessions\\1\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Program Files (x86)\\mRemoteNG\\log4net.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "(R-D) C:\\Program Files (x86)\\mRemoteNG\\BouncyCastle.Crypto.dll": "File", "(R--) C:\\Users\\user\\AppData\\Roaming\\mRemoteNG\\mRemoteNG.log": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\mRemoteNG\\mRemoteNG.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "PuTTYNG.exe-4B72D2A0D937D678AA5C89DF45A58A6E": { "file_name": "PuTTYNG.exe", "file_path": "C:\\Program Files (x86)\\mRemoteNG\\PuTTYNG.exe", "hash_md5": "4B72D2A0D937D678AA5C89DF45A58A6E", "hash_sha1": "601E9EBBA183CA409D8B175F4DF29C80BA931CD3", "hash_sha256": "FE4748B5B538933442C5681F126090F87E56AA1F6907FEA0C480497B9E4EE4A6", "hash_sha384": "3E89DFBE1494E72A11EBF46B0BB289D1BC63A1AD8472C3AE47CDA2BA8CC53D55B8F9A0AA1107B41802073F85C0BBE63A", "hash_sha512": "48EF94B22C2CFE92E41210EF95D36125A27A826BB38A6BA48A7FA784AD755940744503DD843D2C0CFE7087A34FBF5A677F78D80A00843EAB5E6570CFD4BAEB15", "hash_ssdeep": "24576:BRNIhe68XUm3EjQDyWy/2crLWxBJbOWZ5ZxaoS6EGA:BRMKYQb22+WZ5kG", "hash_imp": "F2B227A5A3682CDF0538DBC87F949168", "hash_pesha1": "C20BDC55F4577CFEB41621B4D92C200753D38370", "hash_pe256": "E17C0C3927A71C9EDCFB5BA73542506339109500214C5A1534C2368CEBC5D8E7", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\mRemoteNG\\PuTTYNG.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "SSH, Telnet and Rlogin client", "meta_original_filename": "PuTTYNG.exe", "meta_product_name": "PuTTYNG", "meta_company_name": "Simon Tatham", "meta_file_version": "Release 0.71 (without embedded help)", "meta_product_version": "Release 0.71", "meta_language": "English (United Kingdom)", "meta_legal_copyright": "Copyright 1997-2019 Simon Tatham.", "meta_machinetype": "32-bit", "filescan_vtdetection": "2/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/fe4748b5b538933442c5681f126090f87e56aa1f6907fea0c480497b9e4ee4a6/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\xCyclopedia": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_89e6152f0b32762e": "File", "\\Windows\\Theme1665484522": "Section", "\\Sessions\\1\\Windows\\Theme289354956": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SystemResources\\imageres.dll.mun": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\mRemoteNG\\PuTTYNG.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "PuTTYNG Command Line Error" }, "plugin-container.exe-A857F3ACA2BD496568F68E694E013505": { "file_name": "plugin-container.exe", "file_path": "C:\\Program Files (x86)\\mRemoteNG\\Firefox\\plugin-container.exe", "hash_md5": "A857F3ACA2BD496568F68E694E013505", "hash_sha1": "2BDB48F6E9631B8E81A05E97598FB6239BEA10E5", "hash_sha256": "C2524C9A22B2DBEF5F49493CD0086BC4F590E352DF41B1E6F41006B755600164", "hash_sha384": "3366527819505B5A74BA4196A0A5E8593FE8878EB19D232191A9BACDED722049410D89EB380B1B65D556D8339E6CDDCA", "hash_sha512": "A6D306DB93A42E8F51EA74348CE87BDFD8A00AC74BF5F415AB5F43A58A0B20C1987FB3E18471546618F848B39C0AC3522BF1B71BEA87D8B8CD0D805B3A09998D", "hash_ssdeep": "3072:SXrc/WyKGoPBGRbvQoDkbNdHm+aXeuqmojE92z60KTJFpM+sg9WgTH0nvT6Dc:SA/WyOatDkJA+auQezz2YMrT0v4c", "hash_imp": "22C3CAB8143760E4E7C07109C6A001C4", "hash_pesha1": "64757406130E5D185544E8D557E187E230F108DF", "hash_pe256": "0CB2F25BC1710AFEEE4A86D3849F9DE1566D4A4276938B6EE70929BE3259D04F", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\mRemoteNG\\Firefox\\plugin-container.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Plugin Container for Nightly", "meta_original_filename": "plugin-container.exe", "meta_product_name": "Nightly", "meta_company_name": "Mozilla Corporation", "meta_file_version": "45.0.1", "meta_product_version": "45.0.1", "meta_language": "Language Neutral", "meta_legal_copyright": "License: MPL 2", "meta_legal_trademarks": "Mozilla", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/c2524c9a22b2dbef5f49493cd0086bc4f590e352df41b1e6f41006b755600164/detection/", "runtime_modules": [ "C:\\Program Files (x86)\\mRemoteNG\\Firefox\\plugin-container.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "plugin-hang-ui.exe-98A9579549A5320FEDA97FD671D8134A": { "file_name": "plugin-hang-ui.exe", "file_path": "C:\\Program Files (x86)\\mRemoteNG\\Firefox\\plugin-hang-ui.exe", "hash_md5": "98A9579549A5320FEDA97FD671D8134A", "hash_sha1": "7200904FA0F5FEE9F373AA0831584FB107208870", "hash_sha256": "6938C3E8D4C0F7BC04BB4F81EAF45E592F1E2CA030957C9B71FC6E589C7265E7", "hash_sha384": "A129D1EC782F86C2800C21F59CD980F807E7174C06E360C4A46387D42915014019430D5619B16542C9B72323D72C4DCA", "hash_sha512": "9FE17F7636A3761C1DBA8BDD7DF6E9052565881FA32E4475A37373DDC51ADA161A7CFA7B3AC88EF3C3F3B3543C570F64F057BF596C0DC967A462A53C0D0C880B", "hash_ssdeep": "3072:Bz6yXG3WtDEDpnskXVJofvNQcfxo+3cCtCd6Ncm1vVCE:gygWa6Tfvi4odZm1t", "hash_imp": "20420BF8B12D2A88B5E4751ED36E1B46", "hash_pesha1": "8852F02F1A4F98E7E0D3A84BBE57540819CDB956", "hash_pe256": "C399C107C60B7EE492C2917DC763CBFA1DEC1E1EC453B7AA98EF6B2626B7523F", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\mRemoteNG\\Firefox\\plugin-hang-ui.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Plugin Hang UI for Nightly", "meta_original_filename": "plugin-hang-ui.exe", "meta_product_name": "Nightly", "meta_company_name": "Mozilla Corporation", "meta_file_version": "45.0.1", "meta_product_version": "45.0.1", "meta_language": "Language Neutral", "meta_legal_copyright": "License: MPL 2", "meta_legal_trademarks": "Mozilla", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/6938c3e8d4c0f7bc04bb4f81eaf45e592f1e2ca030957c9b71fc6e589c7265e7/detection/", "runtime_modules": [ "C:\\Program Files (x86)\\mRemoteNG\\Firefox\\plugin-hang-ui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "AdmPwd.UI.exe-EB1F189A47442D38EF3D1F39CDE6D6D5": { "file_name": "AdmPwd.UI.exe", "file_path": "C:\\Program Files\\LAPS\\AdmPwd.UI.exe", "hash_md5": "EB1F189A47442D38EF3D1F39CDE6D6D5", "hash_sha1": "AFC8051AFDB3298F3131095E8B269C7EF84211E1", "hash_sha256": "EBE04BA22BB944169E14A61C5D834CCD9DED9C9F7294A2EBEDC5AECD653168B9", "hash_sha384": "FAF118905F53ABC1BCB02B9F7A6F4B32FB7F3ACD79A03B3DFB0E4EB580133E9FBFE69C0AE796E15BA0305169D0FBF440", "hash_sha512": "5A5C1E1D6DA6FAC213A4CA049B974BC11F50FDDB3AF41909208C3A033DB874BABCAD1001CBBC2AD79593AFA473F65E41F9E4E47B627BA6E5965F17659D3AFB8C", "hash_ssdeep": "768:4aKOme4rkssYBzw51isIPM3mIdKisIPasilVEB4S1:h4jdzwOsIPMbdsIPasQEB40", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "008942A0C4752B2B858B6FBF744A0C036BED4D19", "hash_pe256": "87CE1821226DA93A63861A4A6CF487F9AAC4E64F676F3C7699D9B6D605F4F90B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000014096A9EE7056FECC07000100000140", "signature_thumbprint": "98ED99A67886D020C564923B7DF25E9AC019DF26", "signature_issuer": "CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AdmPwd.UI", "meta_original_filename": "AdmPwd.UI.exe", "meta_product_name": "AdmPwd.UI", "meta_comments": "UI for AdmPwd management", "meta_company_name": "Microsoft Corporation", "meta_file_version": "6.2.0.0", "meta_product_version": "6.2.0.0", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright Microsoft Corporation", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/ebe04ba22bb944169e14a61c5d834ccd9ded9c9f7294a2ebedc5aecd653168b9/detection/", "runtime_handles": { "(RW-) C:\\xCyclopedia": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4580": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\mscorlib\\v4.0_4.0.0.0__b77a5c561934e089\\mscorlib.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Windows.Forms\\v4.0_4.0.0.0__b77a5c561934e089\\System.Windows.Forms.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System\\v4.0_4.0.0.0__b77a5c561934e089\\System.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Configuration\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Configuration.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Drawing\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\System.Drawing.dll": "File", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\System.Xml\\v4.0_4.0.0.0__b77a5c561934e089\\System.XML.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.488_none_4238de57f6b64d28": "File", "\\Sessions\\1\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\1\\Windows\\Theme289354956": "Section", "\\Windows\\Theme1665484522": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_MSIL\\Accessibility\\v4.0_4.0.0.0__b03f5f7f11d50a3a\\Accessibility.dll": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.572_none_fae9a23b76193bbb": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\\comctl32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\LAPS\\AdmPwd.UI.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ], "runtime_window_title": "LAPS UI" }, "AgentService.exe-B9FB053751BC2DEF497D8E803C568B11": { "file_name": "AgentService.exe", "file_path": "C:\\Windows\\system32\\AgentService.exe", "hash_md5": "B9FB053751BC2DEF497D8E803C568B11", "hash_sha1": "AB990E062C576BD7551814F85932F52B78391934", "hash_sha256": "31826FCEC35683B43170876F0B26B306277B1669F62259D5FE3CD5C10BC05D11", "hash_sha384": "39E6152517EB59FDBC71E17DAB3A1E0215C17298A2145C51604450422128D248593B01899B9DF45BE9B6E0266279EAB2", "hash_sha512": "1A82AB0D95940C2F5112C8E4BBCEF19100394FCFABA853649AF74DE738F365E9080CA79FACE765A778ADA46C76BDF6A3C57541909C2D93C411CB8B04F85C77DC", "hash_ssdeep": "24576:svW3adOkl5C8I47I5fNLMD2vJ9THqZLnHOmn8jRXcRYh9epZ4pkRXyX+:oW3adOuYr47IpdMavZkR", "hash_imp": "26726E2F78645AD9C311F13886AFE185", "hash_pesha1": "B58EAB17CC57A230E015EF7F7E81399831663DC6", "hash_pe256": "15B8396CA2B0B61ED16041F71465C6996B061C211F31D7843246E80FC05C34C7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AgentService EXE", "meta_original_filename": "AgentService.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/31826fcec35683b43170876f0b26b306277b1669f62259d5fe3cd5c10bc05d11/detection/", "runtime_modules": [ "C:\\Windows\\system32\\AgentService.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\FLTLIB.DLL", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\system32\\ACTIVEDS.dll" ] }, "aitstatic.exe-27D53636B86A9CE2366BA584DF09227F": { "file_name": "aitstatic.exe", "file_path": "C:\\Windows\\system32\\aitstatic.exe", "hash_md5": "27D53636B86A9CE2366BA584DF09227F", "hash_sha1": "4507133B37588A052D390B535BE65865EE8ECA92", "hash_sha256": "6D20F18CF10653B7324AB41B1A3F633CCC1CE48A737949616B336071F4277924", "hash_sha384": "19A11BC6DC85DE7CD50FEF46DE7913113BE7536AF35DA6FDAA172DE3BB91FCB34BD4A011DDF758A7C6CC3AA71EB073BC", "hash_sha512": "FE02550487BFEA75916F76A767EE81725A98E5FC37627085AC9569C98E4AAEB22DCC4B1B1482CE2D10F2D37D94FD1BACADB67AE8CB74FFB6A517804C67FA6E3A", "hash_ssdeep": "49152:qjt1+tENWqA/+pSYryLTQ4ullYF5svlRlZPAoTMZmhJv3eEkF/LL:qveAwvAImAoTMgJvuLL", "hash_imp": "F72ACD5834B43927998E9B0707B7AE4B", "hash_pesha1": "CFC33455CBE24E7CADCB92FAD4AF8E034E5A1B6D", "hash_pe256": "DEEE0C488309C70CF1F5B6B79B7B6A4FCD3A8DF20E3EBF9D9E0E19C655A9134C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Application Impact Telemetry Static Analyzer", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19645.1016 (WinBuild.160101.0800)", "meta_product_version": "10.0.19645.1016", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Windows\\system32\\aitstatic.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\mscoree.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll" ], "children": [ "csrss.exe", "winlogon.exe" ] }, "alg.exe-E67AEB5F9FA81EE896EC3F0EB837BB12": { "file_name": "alg.exe", "file_path": "C:\\Windows\\system32\\alg.exe", "hash_md5": "E67AEB5F9FA81EE896EC3F0EB837BB12", "hash_sha1": "EE7149A52241AD1285ACED57C56DCB7EA5DA56B3", "hash_sha256": "0EEFD2619D77D7BAFED95197E0C0EF30147ACADDCD81EB2761EE9893FD55F91B", "hash_sha384": "4D4820FA58F34B3BCE62295AF8B5D12B9BCB31C6A255BA848848E1BB92B789D15B0D3093279942FB753A47D57D7B589F", "hash_sha512": "86A4E07BB0374B91431A9AE27FB9BEF7D43AD6F455CEDFF501AC0CAA8189596FAD420E1BCECC74A6964EF3617F9E6657280D2412C9C5730A3D94AA979AD257B7", "hash_ssdeep": "1536:iZjnXPG3vJ/HUXfaPIZ2J9Y9DhT1gd5ULVTgVATG6gpH3:iFnXPqvufig2EXnLpgVYK", "hash_imp": "F718D257CB3A4BBBE8310FA60E7D1DED", "hash_pesha1": "0F67FEEC1A730E7915E36B89012BA37D0254773A", "hash_pe256": "82C02A543D5A08260A38B2F4DAD58A04A7A6F0D6BEE951EFDBA00E88E4CCF848", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Application Layer Gateway Service", "meta_original_filename": "ALG.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/0eefd2619d77d7bafed95197e0c0ef30147acaddcd81eb2761ee9893fd55f91b/detection/" }, "AppHostRegistrationVerifier.exe-6E3FA2CAB3A58209EA4C3FCC522D5F16": { "file_name": "AppHostRegistrationVerifier.exe", "file_path": "C:\\Windows\\system32\\AppHostRegistrationVerifier.exe", "hash_md5": "6E3FA2CAB3A58209EA4C3FCC522D5F16", "hash_sha1": "7D3A6EEAEB2FEA7F7A5F5F8E86672AA9A0113BDD", "hash_sha256": "619E84381F1387B59B623ECF8E8CE46F661C2E6F41A5CA908AC670F180EA7DFF", "hash_sha384": "74E36E9E302D10C1AAFCEE343DF8B0519A33B3FF29C6408E5F8AF0E28BA42EBB5F66E4314A916AA77A5DDEBB1EFF79F5", "hash_sha512": "46E6061750A5D5503FB67E4811941B8270197DE8A7B2948CE69CB421E1F7364D23440783A9081484E1D2FF0954E3561605FB6B9CFB8C7E983B1C2DE7DE878F57", "hash_ssdeep": "3072:VbGud/LlijmvSU4E6ilAODb+r7RNDrMqIvq5fAf/:BGgLlmvJiZvK7MBb", "hash_imp": "8D965FB1B2ED7357844CE14892233CD3", "hash_pesha1": "684DF6C229224B61CEA078EDD6A056CFF5DF00E2", "hash_pe256": "AB4C435A75CE130DCE618F531268F7C068EB94CD4C6485E4EA29E52F6795B596", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "App Uri Handlers Registration Verifier", "meta_original_filename": "AppHostNameRegistrationVerifier.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/619e84381f1387b59b623ecf8e8ce46f661c2e6f41a5ca908ac670f180ea7dff/detection/" }, "appidcertstorecheck.exe-0A83494678BDA0EE8A6DF733CE7AED4F": { "file_name": "appidcertstorecheck.exe", "file_path": "C:\\Windows\\system32\\appidcertstorecheck.exe", "hash_md5": "0A83494678BDA0EE8A6DF733CE7AED4F", "hash_sha1": "52729F901BAFE702D93A4FC7936825E0F46F0D7B", "hash_sha256": "F00EA11118B39D06A3D361E851B6D13B29A3FC0C787AB763E9C351F718CB90BB", "hash_sha384": "21E42A9CC1350A3731BD24A4651E04D3C0BB28CDB2D4936035500C69B7B8C1FD7C92DAA96FC1DF70D676EA6B1F52031F", "hash_sha512": "9AAD049B675685DB93B89C556ACFC588629998B2C4488301CE5FD6F2298CFCBDC6BE841071ED442A6ACC4702581E11B8A8E8127F27644F49903022BAE6A744E9", "hash_ssdeep": "384:AZjMZWmfU49uFAQlH1eAXGPm+aea2EBpAAx2xBe9feW4aK1W:AZj0ffUkQldXGfa2cJwxBKf4aK", "hash_imp": "0CCBBA73193E73A96FCFB925C3CA3B3C", "hash_pesha1": "9E0BF37711978BD002F3D0AB026AE46682B246BB", "hash_pe256": "D783370D0C3716126E1F2130E165DBCF9EA52A431FB5BF0AB5E3D9D3D479AC08", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AppID Certificate Store Verification Task", "meta_original_filename": "AppIDCertstoreCheck.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/f00ea11118b39d06a3d361e851b6d13b29a3fc0c787ab763e9c351f718cb90bb/detection/", "runtime_modules": [ "C:\\Windows\\system32\\appidcertstorecheck.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "appidpolicyconverter.exe-240293AE678DF1481232EC345F57454C": { "file_name": "appidpolicyconverter.exe", "file_path": "C:\\Windows\\system32\\appidpolicyconverter.exe", "hash_md5": "240293AE678DF1481232EC345F57454C", "hash_sha1": "6829C0A876C85BF1533AD1DC147D26F36A43BDBE", "hash_sha256": "139E1B46169664E8530AB0098037858C205E26B7B2021F8A3609091CC07A4BF0", "hash_sha384": "5A013E526F94925F25DF0CEA7DB4B26BD6B2069B712DD4EFB6218D9BFCE502BBEBDD38865C74FBC9AC55BF359BF13891", "hash_sha512": "CCD14616C34BCAE6F73EAF492BCACF16690F97B1BFCC80F34213CE626C05BDB9C99607ACBD39293BB3D4929A233AFCA89E9DC4E5E603D7D811B40BEE28A0B77E", "hash_ssdeep": "3072:gNuZf8p1wxJK4am/3nHT7hsQRJUFu1CIy8jg8ibb:Sp18V3T7hxfku1g8ib", "hash_imp": "199D9082717EEED46087D88B6AD2C2DE", "hash_pesha1": "38D3AFA97829C041FB70283F217D91665A730D17", "hash_pe256": "A5A05AF6A5D2E1C063C3C850A77DA2BF392683A4DFE773A9DECB9B53315BE812", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AppID Policy Converter Task", "meta_original_filename": "AppIDPolicyConverter.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/139e1b46169664e8530ab0098037858c205e26b7b2021f8a3609091cc07a4bf0/detection/", "runtime_modules": [ "C:\\Windows\\system32\\appidpolicyconverter.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\system32\\srpapi.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\uxtheme.dll" ] }, "appidtel.exe-00DEBC48A45BF89972A43F337CE4D32E": { "file_name": "appidtel.exe", "file_path": "C:\\Windows\\system32\\appidtel.exe", "hash_md5": "00DEBC48A45BF89972A43F337CE4D32E", "hash_sha1": "B153CC462F52FFA44D49EB2A688201A233FD5D45", "hash_sha256": "2ECFEAA5C9788FE9197D1A1B34CF5128AB4EE7E7828113B3FA83700BFB4680A7", "hash_sha384": "B49F8CBB765CFAA6E706740049E09BA6DB980E3B8E3B4FE5964775749F34D796CAFE8E150A2AA960D1BB88C852E878A3", "hash_sha512": "189AE673F6E980C14FADA03E6547F334C3D978C991817EFD1E1C618D4E96F07B4903D7D45489585A6509BF1A4D5801809B6A23FCD1D9AE3024677BAFB691AD54", "hash_ssdeep": "384:+IrLeecOjRDf0c6lQyB91AN431RHB+YZ1l2R5k/r+YV8Jcn+WsdsWkv:1OecVr1eOB+Cl05o6U8Jz", "hash_imp": "85042296267FAC79E897C8302E744A31", "hash_pesha1": "8A1F479E3ABD4934D1BF0C1CC492D8B802870BE9", "hash_pe256": "8A38C595B0CA81320EC62A4C36E37EFAB2DFDFD9AB95B05CEE71EF307D432FEA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Initializes Appid ManagedInstaller and Smartscreen Telemetry", "meta_original_filename": "APPIDTEL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/2ecfeaa5c9788fe9197d1a1b34cf5128ab4ee7e7828113b3fa83700bfb4680a7/detection/" }, "ApplicationFrameHost.exe-1F50B3E973A84610EF9B7D6954BDAC1D": { "file_name": "ApplicationFrameHost.exe", "file_path": "C:\\Windows\\system32\\ApplicationFrameHost.exe", "hash_md5": "1F50B3E973A84610EF9B7D6954BDAC1D", "hash_sha1": "9BFF770007755E0EAF9E3FD33F0D4B01FF84D66C", "hash_sha256": "ED51F16E0ACB2707E509AD476F8EE600038B6AC42A9588A054E501CAFE598132", "hash_sha384": "BDD7223C3176C0995EB9820381E4D2255B69379BD265F42819C9CD935C4D2DFEEC7DE255CC3567ACC8003EF025BE3AA2", "hash_sha512": "16D3A2FABE88541F287CA10354FCD94195E4CD87401A656AAD9BB4DC07F451C03E42296BBCFB106106497C714913F05357AABE993BD64A3BD2CE6A424056679E", "hash_ssdeep": "1536:Ts+HzHJpQe9vtTxj3rZfyot3fxg+szv3UR2bGP8g1:LHTJFvnp62fxg+szvS2St1", "hash_imp": "09ACF1642E301359F90E7DA59EE838C6", "hash_pesha1": "9B741AE6B9D331A3921C066736A455ABCCEBA5B8", "hash_pe256": "9543E714B8A711E029D58B4CA96D9B43C3C9716BBA5E4BC802A4F6D1E0D0A234", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Application Frame Host", "meta_original_filename": "ApplicationFrameHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/ed51f16e0acb2707e509ad476f8ee600038b6ac42a9588a054e501cafe598132/detection/", "runtime_modules": [ "C:\\Windows\\system32\\ApplicationFrameHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\gdi32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll" ] }, "ApplySettingsTemplateCatalog.exe-D44681FD4AABFCB68ED25DADDAA4F28B": { "file_name": "ApplySettingsTemplateCatalog.exe", "file_path": "C:\\Windows\\system32\\ApplySettingsTemplateCatalog.exe", "hash_md5": "D44681FD4AABFCB68ED25DADDAA4F28B", "hash_sha1": "A491A800564AF7DF8ACE503598B96584B836671A", "hash_sha256": "54062BD49C1120990100AB837D08F976D0159FF4208A279B6BF81A607C27B989", "hash_sha384": "E3380703BBDF766859DE881F4B51FF9F040C121C811CAECD1E309FA9251B4D99200284DAF6AB096C2D03E0469978A819", "hash_sha512": "02CF7888CD7EC34F7D5E715E41C96B52D7AA340B4D52E163855195D831979CF64563E2A01529BA4B65E28DE16FD08A62378D9C2910A5C93ECCC589FA8247E480", "hash_ssdeep": "24576:3LVP6YQsKv5FSZw9BBb5zqfjv1NETP0LrMPrJ9f9Jcsq/nG6zaQVd9nMUq:3LElsc4wHBN+f71Zd9M", "hash_imp": "1575278B212AEB557747C4F050F7DD68", "hash_pesha1": "48F9B30872101A9D61A7D7DACE4D54EA41830A41", "hash_pe256": "CCC66722997D67064AED1284621587C576DFF16E70C0BB1D167317BF9FA61415", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ApplySettingsTemplateCatalog EXE", "meta_original_filename": "ApplySettingsTemplateCatalog.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1007 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1007", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/54062bd49c1120990100ab837d08f976d0159ff4208a279b6bf81a607c27b989/detection/" }, "ApplyTrustOffline.exe-98B12E2A9465260A0315BBA96F82B984": { "file_name": "ApplyTrustOffline.exe", "file_path": "C:\\Windows\\system32\\ApplyTrustOffline.exe", "hash_md5": "98B12E2A9465260A0315BBA96F82B984", "hash_sha1": "2679A50B96AD884081297504D1D44931D300EE32", "hash_sha256": "BBD53941261C777991A8235191105B13CC8EF7F1E375493E9CBE5FEA8FD13EEC", "hash_sha384": "7BCB3DA392C2681BBABB84B5D3ECFFDE90075153B65DFD27D2FBA614D2483C585DB31DF9BD367FE677C5A797FA4FA783", "hash_sha512": "4C79352500F89931C7E49680FE5EC2A4F353D4F709581F0FE47194AE7AF714AFB295DAB0503A2A52782B033A4DC493C586CE5CE4078F67A683139C5B70A6163E", "hash_ssdeep": "12288:vpGKCVlGCCANK58REqyqbW2WvHlTyulRCrWVkRGT4s/SXQx3zu/oskZrgIr:N5t8uNuW2uTyGV3P/SuH9Fr", "hash_imp": "C29511AEACCBAA54DEBC6733AB3B0226", "hash_pesha1": "A0A3566031D9A70966A5F291DA6AA79A6C106BDD", "hash_pe256": "FAFBFA06A9F7AC4C3EAEA8A4F065A02F02623E233FEE8A01DB349EB575470748", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "\"ApplyTrustOffline.PROGRAM\"", "meta_original_filename": "\"ApplyTrustOffline.PROGRAM\"", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "AppVClient.exe-64650F0876BE00054EA65B7C3A081450": { "file_name": "AppVClient.exe", "file_path": "C:\\Windows\\system32\\AppVClient.exe", "hash_md5": "64650F0876BE00054EA65B7C3A081450", "hash_sha1": "488520C688D96219E057D54942DBCC23D7F5C881", "hash_sha256": "B9D349C732032C405415B2F85A9365526D3EAE3007E404042957B73D647F534A", "hash_sha384": "BE6EA327942ECD8DF49CCB3EC79D48FF36B45B5FD06FA0671931092F970FB244D5377C3E0539CDDFAE9CB61877E42AD1", "hash_sha512": "B0A5E5DAB0DB46E142F3444E8D003F9D7BA11472CB2733CDEEF97297EAC8BB954A21F4B95C7190146508C0458B5DEF7A95A5EFA0A7CDB93350CB4D6B2ABB431C", "hash_ssdeep": "12288:EA3NOjSfAJuWjHArR57r/zmCGNUbTNR0MXsJl:EA3uXJdHArR57rmMX0l", "hash_imp": "5054081A378EFBE521A9C039EA173CC4", "hash_pesha1": "E63B2CF784F590789E9F0822DCA650316BDCBFD5", "hash_pe256": "DB408A265F7159AFC433653C2D3B1F48911F2A5357F406D2D587364A2F185767", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Application Virtualization Client Service", "meta_original_filename": "AppVClient.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1007 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1007", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/b9d349c732032c405415b2f85a9365526d3eae3007e404042957b73d647f534a/detection/", "runtime_modules": [ "C:\\Windows\\system32\\AppVClient.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AppVDllSurrogate.exe-EAA5FF4ED735D3D1FE292600A9E3DEC6": { "file_name": "AppVDllSurrogate.exe", "file_path": "C:\\Windows\\system32\\AppVDllSurrogate.exe", "hash_md5": "EAA5FF4ED735D3D1FE292600A9E3DEC6", "hash_sha1": "2F00C04A34D02C481A61682DC9A8C345E4A89516", "hash_sha256": "DDEFAEDB6E9DA7E17BE3EE8E0A8563A6AB5751E85ACA55B90666F449B93D92EC", "hash_sha384": "E64E7B0644196B098198A657034A2F70CEB5F42E01EA187167667526389717D701C9DDA53D4D138E35B0A0D7F2F3C7AE", "hash_sha512": "071FB8A66B3B6E487FC0C7256943F0AEAC998508F9DA06689A8C09EB49D9B9A1E30B11619FA0F57AA74E4735A02649D388B4C0F828DC5D73BE7ABCBB4B07C2AC", "hash_ssdeep": "3072:2mo1lH61ONQVOmu8OsJOjWGNU6ITLjWIa6b1vC:QEONaFu8OsJMWGNU6ITLjnn1", "hash_imp": "5C1D020956A4CA9FDE213E3BB2F85CAF", "hash_pesha1": "00487821966CA71D2CAEB0A0912AE78768F2D0E1", "hash_pe256": "24C31B59762A6FDEB2E2A3794B37DEA095B7ED2F37E982702F4DC61924769900", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Client DLL Surrogate Host", "meta_original_filename": "AppVDllSurrogate.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/ddefaedb6e9da7e17be3ee8e0a8563a6ab5751e85aca55b90666f449b93d92ec/detection/" }, "AppVNice.exe-E4CC15631219560406D2CE920CB2C133": { "file_name": "AppVNice.exe", "file_path": "C:\\Windows\\system32\\AppVNice.exe", "hash_md5": "E4CC15631219560406D2CE920CB2C133", "hash_sha1": "97E7780EBDB258081DC788BE0B4A4751033B054A", "hash_sha256": "E04A7680D80E671A20641680C062AF29B8021FE3A8BFCE93810DC978F1635EE1", "hash_sha384": "9BCB4EBA66A1D12D78DF5DDE81288F6FA31E7FE5FA71C82754E7BEACBFF970B2F46AEF5EFB913238C7ECF8E09F577500", "hash_sha512": "E21329AE32C4BEABDC139D0444E92075DE1B34756B44F945BDA923C50359CC0DBDF40D37F499EBE9F2F5A54CA7BA07CFBD4CF4574D47D331CD2EE79AE07BE7C0", "hash_ssdeep": "3072:0dYlE+eJ6uuhfRMVTMPzZAWGNU6ITLJcW+K6hqIFp:gLJ6uugTM2WGNU6ITLJChqE", "hash_imp": "0D7E940177BCA133F6A9A67319DF7115", "hash_pesha1": "4FB8695500B5854296D99365D0BDC52D48DEE61F", "hash_pe256": "C480F8859FC9DC4B1864EF9C6999DD21AEC822D5883CB21ECA68DFA74552BB47", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Application Virtualization appvnice", "meta_original_filename": "appvnice.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/e04a7680d80e671a20641680c062af29b8021fe3a8bfce93810dc978f1635ee1/detection/" }, "AppVShNotify.exe-3E705409974662FD944B65C3B9ADAC31": { "file_name": "AppVShNotify.exe", "file_path": "C:\\Windows\\system32\\AppVShNotify.exe", "hash_md5": "3E705409974662FD944B65C3B9ADAC31", "hash_sha1": "B702CF10D14455C899DE34001EAE342C1BA5B6CF", "hash_sha256": "071DA06DA3D61E49C4A0EDCA37097B39B7C96A1AA820453F8CC6C8AA55CFD98E", "hash_sha384": "1B8D1DC1A21CF819D154AB262403B1CC87B678CF1B1A41843457B927B3DDD9B5B6F67A258A4FA9A400649212612E393E", "hash_sha512": "C16C88443B1743BE70CDBCC450A736CE2BE4FFA18E1AF038582657C613238E9ED02D24FD7AE1D16C2E86A36AAD42368B3BAE815BEFDC7DA2CEC6748788222B1A", "hash_ssdeep": "3072:RyMlaAj0JtLslVgqTyhq0+UJI0yWGNU6ITLz0cnVwEKTYGUh:Ry22JtQnTyhq0X1yWGNU6ITLzBxKTYn", "hash_imp": "8EFF6DA1273F73B87836F1E27FFFB536", "hash_pesha1": "EDF3E496032A9BE2966014849CB204145282043F", "hash_pe256": "586E62C5919AAD25985CA5FF51C86912C8494CAFBA2A395EA2760147C557D2E7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Application Virtualization Client Shell Notifier", "meta_original_filename": "AppVShNotify.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/071da06da3d61e49c4a0edca37097b39b7c96a1aa820453f8cc6c8aa55cfd98e/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\RPC Control\\DSEC1088": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\AppVShNotify.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\sspicli.dll" ] }, "ARP.EXE-4ACDF3F896F2E34FBBB4BBA816E89B3E": { "file_name": "ARP.EXE", "file_path": "C:\\Windows\\system32\\ARP.EXE", "hash_md5": "4ACDF3F896F2E34FBBB4BBA816E89B3E", "hash_sha1": "EB1C8778D17B5393B857AD80733EE00CBEA300A1", "hash_sha256": "F0B2969246808AAA41DC74FE8138A542560564474DFBA79DA329B44A951CC574", "hash_sha384": "73C8A6213BE7CB4FAE5A27AF429FCB8E4D5D8380D312AD5C6F77B0F7D494E20A1567515FFE6E3201CAD8557CBF63544E", "hash_sha512": "048A621CA80F1336E702A75CE318A70B37BBAB0F2481C26C930293D2E4236992B219BE650E2A6F78DDF4F5AC2D195BE0E16CC9145EC9F28007FFE7BABBAC3AA2", "hash_ssdeep": "384:tqw4GqYQzOo+yDOpU6OoS2EMIOAqjOMuG767wjG256nWSSmW:tTlqX2pU6O21JAzvG2wjb56O", "hash_imp": "02E80B21355ED722444F540585E82D1D", "hash_pesha1": "DB3826110BC5E20D872F2175A1AAAA43C57DA401", "hash_pe256": "A4A987CFC4A75F160C6B4377F8976A685754EA074B8FBF628DA9D29FA3D9AEDF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Arp Command", "meta_original_filename": "arp.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/f0b2969246808aaa41dc74fe8138a542560564474dfba79da329b44a951cc574/detection/", "output": "\r\nDisplays and modifies the IP-to-Physical address translation tables used by\r\naddress resolution protocol (ARP).\r\n\r\nARP -s inet_addr eth_addr [if_addr]\r\nARP -d inet_addr [if_addr]\r\nARP -a [inet_addr] [-N if_addr] [-v]\r\n\r\n -a Displays current ARP entries by interrogating the current\r\n protocol data. If inet_addr is specified, the IP and Physical\r\n addresses for only the specified computer are displayed. If\r\n more than one network interface uses ARP, entries for each ARP\r\n table are displayed.\r\n -g Same as -a.\r\n -v Displays current ARP entries in verbose mode. All invalid \r\n entries and entries on the loop-back interface will be shown.\r\n inet_addr Specifies an internet address.\r\n -N if_addr Displays the ARP entries for the network interface specified\r\n by if_addr.\r\n -d Deletes the host specified by inet_addr. inet_addr may be \r\n wildcarded with * to delete all hosts.\r\n -s Adds the host and associates the Internet address inet_addr\r\n with the Physical address eth_addr. The Physical address is\r\n given as 6 hexadecimal bytes separated by hyphens. The entry\r\n is permanent.\r\n eth_addr Specifies a physical address.\r\n if_addr If present, this specifies the Internet address of the\r\n interface whose address translation table should be modified.\r\n If not present, the first applicable interface will be used.\r\nExample:\r\n > arp -s 157.55.85.212 00-aa-00-62-c6-09 .... Adds a static entry.\r\n > arp -a .... Displays the arp table.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\ARP.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\snmpapi.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\System32\\NSI.dll" ] }, "at.exe-F4416891D11BBA6975E5067FA10507C8": { "file_name": "at.exe", "file_path": "C:\\Windows\\system32\\at.exe", "hash_md5": "F4416891D11BBA6975E5067FA10507C8", "hash_sha1": "EC6F04AA61D8F0FA0945EBFC58F6CC7CEBB1377A", "hash_sha256": "73A9A6A4C9CF19FCD117EB3C430E1C9ACADED31B42875BA4F02FA61DA1B8A6DC", "hash_sha384": "2862687074918DC554A4C300F887D68B48E5967E670B499DB8B188072FB8DC412B1E4B18DC49FD8C5BE9C12F3013F701", "hash_sha512": "AE12DD30AFD9D9EFA45A22BF256D1E6BF781F407A07208DD9B832E3B8FC78AF31FEA5E77CEC2F3B83471F20462DF4626E68AECA8BC4D940B169E72B2003EF380", "hash_ssdeep": "768:ddvxiSkGxY6ZQppLMVt+QFZ7Xu9qAJ9jq2g:ncXGhcC+QFBFAJJdg", "hash_imp": "FA9A9B0D471E4B5F3683C346C3D880BD", "hash_pesha1": "50100574B4582C8F47E396B53381740431C28B06", "hash_pe256": "AA623094D8EE1C822CBB5EB044FFC58EB085E49733DF47F4382840EF1C35C8B2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Schedule service command line interface", "meta_original_filename": "AT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/73a9a6a4c9cf19fcd117eb3c430e1c9acaded31b42875ba4f02fa61da1b8a6dc/detection/", "output": "The AT command has been deprecated. Please use schtasks.exe instead.\r\n\r\nInvalid command.\r\n\r\nThe AT command schedules commands and programs to run on a computer at \r\na specified time and date. The Schedule service must be running to use \r\nthe AT command.\r\n \r\nAT [\\\\computername] [ [id] [/DELETE] | /DELETE [/YES]] \r\nAT [\\\\computername] time [/INTERACTIVE]\r\n [ /EVERY:date[,...] | /NEXT:date[,...]] \"command\"\r\n\r\n\\\\computername Specifies a remote computer. Commands are scheduled on the\r\n local computer if this parameter is omitted. \r\nid Is an identification number assigned to a scheduled \r\n command. \r\n/delete Cancels a scheduled command. If id is omitted, all the\r\n scheduled commands on the computer are canceled.\r\n/yes Used with cancel all jobs command when no further\r\n confirmation is desired.\r\ntime Specifies the time when command is to run.\r\n/interactive Allows the job to interact with the desktop of the user \r\n who is logged on at the time the job runs.\r\n/every:date[,...] Runs the command on each specified day(s) of the week or\r\n month. If date is omitted, the current day of the month\r\n is assumed. \r\n/next:date[,...] Runs the specified command on the next occurrence of the\r\n day (for example, next Thursday). If date is omitted, the\r\n current day of the month is assumed.\r\n\"command\" Is the Windows NT command, or batch program to be run.\r\n\r\n", "children": [ "csrss.exe", "wininit.exe" ], "runtime_modules": [ "C:\\Windows\\system32\\at.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AtBroker.exe-0E175C40A722407F804F30BFB45CEDA8": { "file_name": "AtBroker.exe", "file_path": "C:\\Windows\\system32\\AtBroker.exe", "hash_md5": "0E175C40A722407F804F30BFB45CEDA8", "hash_sha1": "5B9938BC8FB5158043063C55EB795884BE6F621C", "hash_sha256": "6837E1C70823796EB24D9E5E0209BEA5C857A34F70B936D6D1CF5791C4F74961", "hash_sha384": "6287D56143A13D0E41923A4055FBA5BA7CF62232813951FCB4CCC9076CDB3EC695E6CCB04B4AE5A23E910BC15B50686F", "hash_sha512": "742D088A8559D0C6DD13B5B5C21453BF736E5F0EDA2071F279401595F360195677D7053106969CC41852096B357B0A88986603B00A01977124641C5A38A1E0A5", "hash_ssdeep": "1536:U58+Dquaetf7kqOMFsi8ZkHbto3W94e3er7JENPUjdJa/YGO:UyIF/f3X+BZCtCZr7JEaj/OYGO", "hash_imp": "587B1C3FD47818346FB8557408E17403", "hash_pesha1": "EA32733357843029F570463FBEAF7E380247D907", "hash_pe256": "FD427027C62AE45B2314D59CC47812C1437499356152A1FB49F3B1DF66DD4CD8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Assistive Technology Manager", "meta_original_filename": "ATBroker.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/6837e1c70823796eb24d9e5e0209bea5c857a34f70b936d6d1cf5791c4f74961/detection/" }, "attrib.exe-3A536CC896D9C6CA2C2EE4C21CCA1DFA": { "file_name": "attrib.exe", "file_path": "C:\\Windows\\system32\\attrib.exe", "hash_md5": "3A536CC896D9C6CA2C2EE4C21CCA1DFA", "hash_sha1": "D7760F53EA5CF3E919E4E035E01AA24AB45C6D6D", "hash_sha256": "B101350BCEEB773B7E77759613BB33C28FBF1D79A13C2CB783575A9D893D52E6", "hash_sha384": "81E47574B1AF0AA44E44270DA94E1304A12EA5744ED6112275B77949EE233B947D60F575C8167A56F8A817306DBA338B", "hash_sha512": "904E85ACAF5AEC8A1A0D39526191FF3E78A7D7C5C57DEB049D51EFF15B4BA4A8D187B3D4DD1692E0DB4F61522EFEA08578F0B8D8E8834D152666B2F4B7004931", "hash_ssdeep": "384:7RnxnIHHLmsXk7YoiOBDb4nK1g0m3CcBJH2TuERfKXW4tW:dniH6smYvOJ4nK1k3JHoRfK7", "hash_imp": "2CB38FE7D8F223D9DA50B7CBA9B95A6D", "hash_pesha1": "EF08709AAE044E2DE1676A2A478D0898A4C1FCDB", "hash_pe256": "6EFCC1158C436D21110CD3C058E3A1F793637E9C374C190901C450C93D9735F4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Attribute Utility", "meta_original_filename": "ATTRIB.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/b101350bceeb773b7e77759613bb33c28fbf1d79a13c2cb783575a9d893d52e6/detection/", "output": "Displays or changes file attributes.\r\n\r\nATTRIB [+R | -R] [+A | -A] [+S | -S] [+H | -H] [+O | -O] [+I | -I] [+X | -X] [+P | -P] [+U | -U]\r\n [drive:][path][filename] [/S [/D]] [/L]\r\n\r\n + Sets an attribute.\r\n - Clears an attribute.\r\n R Read-only file attribute.\r\n A Archive file attribute.\r\n S System file attribute.\r\n H Hidden file attribute.\r\n O Offline attribute.\r\n I Not content indexed file attribute.\r\n X No scrub file attribute.\r\n V Integrity attribute.\r\n P Pinned attribute.\r\n U Unpinned attribute.\r\n B SMR Blob attribute.\r\n [drive:][path][filename]\r\n Specifies a file or files for attrib to process.\r\n /S Processes matching files in the current folder\r\n and all subfolders.\r\n /D Processes folders as well.\r\n /L Work on the attributes of the Symbolic Link versus\r\n the target of the Symbolic Link\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\attrib.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "audiodg.exe-E791E1D0340715D40E21D3D3C597F626": { "file_name": "audiodg.exe", "file_path": "C:\\Windows\\system32\\audiodg.exe", "hash_md5": "E791E1D0340715D40E21D3D3C597F626", "hash_sha1": "4319623AAFCF9B5AE6BB21153DCE66F6D3CFFB0F", "hash_sha256": "BDBFE066F1981FE67CFB883C592DAC491EFC58B61E17042E31D3BACE8731C41F", "hash_sha384": "DB0E2282F0C44C2C594353FF3EC4EA1D744C1AA3070A9CF83F22781CEEAA44924A5FFE709B44A0BB3EF6B547D7C7C496", "hash_sha512": "2BADC97758AD9F019E0960CC6113F5BC69B29D4B0C356F70CFCE417ABD65541F876DBAD7173460FB3EA03BBC0B0F93E937C3B486BDBBF47F35BBD9AC89B9890B", "hash_ssdeep": "12288:k+R8p42ZtfKixtfPqXHJ0yBLPcgu76LKmGDZVHda:k+Rz2ZtfQHxLPccLEDrE", "hash_imp": "952B47AE2CBEF2B729D43731280B0997", "hash_pesha1": "1FEF489F8B716FBF4BF08BEF33E3F2DF0AFE0555", "hash_pe256": "E19CEA57013C78FE2B342BBACDF5E0C5A5992583420D4E8FF7AC9B06EE9696BF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Audio Device Graph Isolation ", "meta_original_filename": "audioadg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/bdbfe066f1981fe67cfb883c592dac491efc58b61e17042e31d3bace8731c41f/detection/", "runtime_modules": [ "C:\\Windows\\system32\\audiodg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\MMDevAPI.DLL" ] }, "auditpol.exe-F97C0041886519CEAE336B06AEBFC9E1": { "file_name": "auditpol.exe", "file_path": "C:\\Windows\\system32\\auditpol.exe", "hash_md5": "F97C0041886519CEAE336B06AEBFC9E1", "hash_sha1": "0A81854C79D49EF3241A962EBFBAEE438CEF1160", "hash_sha256": "969306E33A469096EFA20BEE264FB37AC4DA86899F2659007D6BE0D1EB666B1C", "hash_sha384": "F4B90A40FA4E52D82DE8F7375E5D2E898DD5E9BA776CB0F272A58086B5242EB44CF84AD5324C443A2D1570B8AA03DD52", "hash_sha512": "CE8A1A2D13D9CB8503F7AD2B03F331275F2361F9F3004C19EEC0EDE24928BD84795202E8FBB3BCE9BCF8B68A390CAB127525B9B4D6797F0B36796B2A82C9F5CC", "hash_ssdeep": "768:nVWCDXCmFOv7yG8Ts+m7BwVRRde98Hom3NCWE6gn:1DgeXPm6om3NVgn", "hash_imp": "D401223A63DBFDCD11C945B9EEE0BD7E", "hash_pesha1": "30537E917CAC4C56B59C7B640D595F1CBF781CCF", "hash_pe256": "CC067F540B96A893DDC9DC8184E5A7DAFBD869751864BB4590DEBB74C966E99D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Audit Policy Program", "meta_original_filename": "AUDITPOL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/969306e33a469096efa20bee264fb37ac4da86899f2659007d6be0d1eb666b1c/detection/", "output": "Usage: AuditPol command [<sub-command><options>]\r\r\n\r\r\n\r\r\nCommands (only one command permitted per execution)\r\r\n /? Help (context-sensitive)\r\r\n /get Displays the current audit policy.\r\r\n /set Sets the audit policy.\r\r\n /list Displays selectable policy elements.\r\r\n /backup Saves the audit policy to a file.\r\r\n /restore Restores the audit policy from a file.\r\r\n /clear Clears the audit policy.\r\r\n /remove Removes the per-user audit policy for a user account.\r\r\n /resourceSACL Configure global resource SACLs\r\r\n\r\r\n\r\r\nUse AuditPol <command> /? for details on each command\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\auditpol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ], "error": "Error 0x00000057 occurred:\r\r\nThe parameter is incorrect.\r\r\n\r\r\n" }, "AuthHost.exe-2FE5754CA6E422559C3EE6AA9F91C14A": { "file_name": "AuthHost.exe", "file_path": "C:\\Windows\\system32\\AuthHost.exe", "hash_md5": "2FE5754CA6E422559C3EE6AA9F91C14A", "hash_sha1": "F96CEFBB1C4BC9478C2E2924EB3E76D8930EE259", "hash_sha256": "EA48B4F5787D0941991B17A9A2075CD89F8217CD00260C5283E2A2BF97EFAC64", "hash_sha384": "8F7ACED01A725069095EC818B65BECB808206E2FEFFF097166FF57358F035999F2EBC28BB9B389E8836446465A6DDD37", "hash_sha512": "22E22820C997B2786D91DB79E376115795D753647C5A05C6565A58CE722C2A697EB018767D82EAABA1F3E3503E595569BBF199916E07D30BFE73A232A50FFB3A", "hash_ssdeep": "3072:CfP1T1kCAx6I+TaUXcFewJBmc6S46twPIwCejp:Cfh1kCAAbc85ctyIcjp", "hash_imp": "BBE19CD2123CFF9950607C1C0C8E74A2", "hash_pesha1": "0FBA1640326AD1898E75B01C27C9DED272A2B2EB", "hash_pe256": "020E1890FF455B39B3C0FC093BEE2B655526D3FDCC73893F0CD04346B49826C0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft AuthHost", "meta_original_filename": "AuthHost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/ea48b4f5787d0941991b17a9a2075cd89f8217cd00260c5283e2a2bf97efac64/detection/" }, "autochk.exe-4D73C03DB77874D95F5F4B2A45CB9768": { "file_name": "autochk.exe", "file_path": "C:\\Windows\\system32\\autochk.exe", "hash_md5": "4D73C03DB77874D95F5F4B2A45CB9768", "hash_sha1": "BA29B4D746C2D41AE5BD990A053CEA4227996694", "hash_sha256": "109141E6EE9055C7C1605BBC4C2CDF0FA5D86A3E30825C9B2DD360DEF7FE6975", "hash_sha384": "A69E188C391E530237FC69AC7609BA0418FDE0E632ED663237C446D9B8CB1E19A745E1E7F41005F1D5C942CD093A8CFB", "hash_sha512": "B0ACCCA5E8FAF3EA1EC2D38FEBE95A6F60A207BAD2D5240C0B8A45CF8690C1E24BDD771CF69B8FEAE420E259EE713CD9AFAD6E77865945F0DF09CD244080EE1E", "hash_ssdeep": "24576:quBwTUf1WwTnNhC0etz+H4hCNeNcVN7V:VfMWzjmqxV", "hash_imp": "E397049C6CFD2707112C5BC2906414C1", "hash_pesha1": "5B4CB8350A7012D89515DB279DF417134C9860F3", "hash_pe256": "2EABDB0420B1C74184E01BE0084AB2BCE83AE1026D6F14CB9D912D7E23C57A4A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto Check Utility", "meta_original_filename": "AutoChk.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/109141e6ee9055c7c1605bbc4c2cdf0fa5d86a3e30825c9b2dd360def7fe6975/detection/" }, "autoconv.exe-7EAAC0EC5E46F117AB37456C113D1E27": { "file_name": "autoconv.exe", "file_path": "C:\\Windows\\system32\\autoconv.exe", "hash_md5": "7EAAC0EC5E46F117AB37456C113D1E27", "hash_sha1": "E462DD3FAF36B307C5A3FDCB1CA6BC808E35BEE8", "hash_sha256": "31CF1CD007394E0E6F8926666917659927008BBEE9E6F4B218D4F359C215EBAA", "hash_sha384": "692181E35C1150C9B13DBF37C863E480FF14F8E06A4E70FD7B0514206BCC842ED8E52A7DB2D4E9C649C9EC99F47FEB56", "hash_sha512": "2A761987D453833064DF0F24EF017790CB05910559362CB22D874F7615E50F4819776850A2F00091C5310E1E8D39AD45D60DC3EE65289F20BB6306E5245BF6F0", "hash_ssdeep": "12288:ny7ALnaqABtb8wAnlWK82FDLpY12PyhgGP15N00Y6d6fBBtZr:y74nBetb8wAwkLpY126hgGP1H0aeTV", "hash_imp": "8BE61045829921D740DCA13576D33FA7", "hash_pesha1": "36346D9134A8719C5ABC99B668CC69750E55A1B5", "hash_pe256": "8567E9B59BCABEBA4DAE7ED79A1DDB6E9BA321754B333A5CDD9ABE06A31B8EFE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto File System Conversion Utility", "meta_original_filename": "AUTOCONV.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "autofmt.exe-A71C87DB3F4D1B6735C3A83EE0869719": { "file_name": "autofmt.exe", "file_path": "C:\\Windows\\system32\\autofmt.exe", "hash_md5": "A71C87DB3F4D1B6735C3A83EE0869719", "hash_sha1": "8F0AD5CF3CE0FF89EBBE08E4B6F0E26DCD62B506", "hash_sha256": "428A3B0ABE59983DFF07B302C2527F5DD0161F96B8534BA64AB230AFD2B114AB", "hash_sha384": "B5CE245932867AFD4B13D78A72F3AF2BEEA2E26083703C5CCFEBCD874D4DE50E05AD72D50279827D43DE6C08147F305C", "hash_sha512": "A32691BB3FFD0985AE49C9508BB313BDAF56B3E80C7F80B37327769D7A97AF4AFE3C2E7E0D60321FAA89E0BF60DBF756C81770A00B73C174B86BDE8D3E0FF343", "hash_ssdeep": "12288:mpWlj4EndNzyKR9A9QXZCWcZpCJhP2a23ZNW8jNZr:mwljlndRy+9AQJCWcZp6hd2WmV", "hash_imp": "D5BFC4F75A279B722513C393439678B7", "hash_pesha1": "CD426DF8467BC6AE27FACC538E4C023AAC515741", "hash_pe256": "9B3838BB9E76D0AF76F4B364904145002FE4C28DDDA229B24B4FCE067B843985", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto File System Format Utility", "meta_original_filename": "AUTOFMT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "AxInstUI.exe-3573538F2EC013D2AE9C273310925EE8": { "file_name": "AxInstUI.exe", "file_path": "C:\\Windows\\system32\\AxInstUI.exe", "hash_md5": "3573538F2EC013D2AE9C273310925EE8", "hash_sha1": "F962038EBB7F3D74C09FEA6EF3D54295AD70F82E", "hash_sha256": "FDD4BC2D78D4567B9309B637F6126A898F97E1B80A4DD9035E671683B6BBEE3E", "hash_sha384": "2A916EDF990EC637663A3760395745979D36AF406A6764ACF6D00CB7F868D6A61F34BCF7BA073F2EBD0DDBBCD2E33A74", "hash_sha512": "A3626E3EBFBFCC798411A273872386323A8C1B3754801AF65C2651431A904413193FD0386570F0EBAF244E40E4F69129F60873A6DEEB6BBF346AC59AC3753543", "hash_ssdeep": "384:NHLVTMIzi8ySmAg4Ziiw+1xq3UZU9a1xq3UZU9eWGIW:VLZMc634Ziiw8ZU9QZU9G", "hash_imp": "7D8DEE85A40FC5307CB205608512D381", "hash_pesha1": "F7DAE34CEE10BD8EAD001C4F9C662DAE5D89D7A5", "hash_pe256": "40A483372884A2DEE06BBE8D4FA7843286AE1F54CA2A65535AAC2C9709AD431D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ActiveX Installer Service", "meta_original_filename": "AxInstUI.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1339 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1339", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/fdd4bc2d78d4567b9309b637f6126a898f97e1b80a4dd9035e671683b6bbee3e/detection/" }, "backgroundTaskHost.exe-50D5FD1290D94D46ACCA0585311E74D5": { "file_name": "backgroundTaskHost.exe", "file_path": "C:\\Windows\\system32\\backgroundTaskHost.exe", "hash_md5": "50D5FD1290D94D46ACCA0585311E74D5", "hash_sha1": "339E4E69D2120B97CE34B9A8D3597FF8E0A73561", "hash_sha256": "B8E176FE76A1454A00C4AF0F8BF8870650D9C33D3E333239A59445C5B35C9A37", "hash_sha384": "652E1102EDEB000B95F54DDC85BE8C4D7E92001F17AB8E8F6CF0021F0F6EFF087626F40B1C1C357C35E4FF141FA62700", "hash_sha512": "A89427027064F3B60948F6CD89D467A9E54A6947B8C73E73F9A252E1608CBA1A144DA77C47D5E36BD991649D878772934D93007A4B8A2AF005A39837851635D6", "hash_ssdeep": "384:H1dPOeFIR79Mjs0HijWFGWCmXjDBRJWrKudlZp06:PPO6tHimrXj1PWrTzB", "hash_imp": "D2ACF1CBC4A6DB14A34C687B9362D66B", "hash_pesha1": "5A701540717DCE09B46A5B32C4E4D3AF1772249B", "hash_pe256": "0E4697A91FAE48B1615889413132351D216890E78A07E67734222FFEA2E78B61", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Background Task Host", "meta_original_filename": "backgroundTaskHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/b8e176fe76a1454a00c4af0f8bf8870650d9c33d3e333239a59445c5b35c9a37/detection/", "runtime_modules": [ "C:\\Windows\\system32\\backgroundTaskHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\twinapi.appcore.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\RMCLIENT.dll", "C:\\Windows\\System32\\WinTypes.dll", "C:\\Windows\\System32\\shcore.dll" ] }, "BackgroundTransferHost.exe-BF255B52B25761E750889EA4984C328D": { "file_name": "BackgroundTransferHost.exe", "file_path": "C:\\Windows\\system32\\BackgroundTransferHost.exe", "hash_md5": "BF255B52B25761E750889EA4984C328D", "hash_sha1": "A8139027AFDACFE20ECFE204FB495B40A3CD3236", "hash_sha256": "50E46406C00182189F74EC64CA3AED40B35B99F999B254BE4205C1E7DE3194F6", "hash_sha384": "8BBBE506FA60A6B71F28D61D220580388F96D6999C57B2B6E94655374B87A0E5B5A4389CDF114132095B0BFFA3196980", "hash_sha512": "22296D8CBD4BC009CE7F62E0BD55FB3461A14CC9B37A73B70FBC7892D4E912E753AE6306E46AF0D2602B0AF028B6C6DC87B4EC0C7BEAB00CEFB4EB5B27154E72", "hash_ssdeep": "384:cWvdgXRnD6omd6W23IkskDPocFsp2WveSdpW0rgWwQE0g7qW2RPT/8rFeZmJhk:LynOD2YUhUeIfo2a", "hash_imp": "43BA7C14F952D3784267C6946F79BD81", "hash_pesha1": "CE43B2EA6F5B7EA2A8018245BC0CBE32D53A9785", "hash_pe256": "467ED5D3234FB9684F4AF0406C13B1671F5C7667900B13C361122A5BA396461E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Download/Upload Host", "meta_original_filename": "BackgroundTransferHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/50e46406c00182189f74ec64ca3aed40b35b99f999b254be4205c1e7de3194f6/detection/", "runtime_modules": [ "C:\\Windows\\system32\\BackgroundTransferHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\twinapi.appcore.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\RMCLIENT.dll", "C:\\Windows\\System32\\WinTypes.dll", "C:\\Windows\\System32\\shcore.dll" ] }, "bcdboot.exe-6ECBB7E78F52877F39EB2AD9ADAB5CE9": { "file_name": "bcdboot.exe", "file_path": "C:\\Windows\\system32\\bcdboot.exe", "hash_md5": "6ECBB7E78F52877F39EB2AD9ADAB5CE9", "hash_sha1": "4D04271BD419CEF7D219C702A779BB85BC01334E", "hash_sha256": "D8F1C8A9D019A9430366322D78D76D5647E30664E2D96B3A5FB87738D603D19B", "hash_sha384": "5AE5A7B48C8587ECDEE726DB3FE5F56A51E0447EB4CBDD7755D54FDD823A59F246BF8B70E75AA67E0615AF63351BBDA4", "hash_sha512": "D247606D7CAD16C7DC5927F8AEA64CD3C2E80DBE80183685F7721F105D447816CF1DDEF126A9C13BE5305E3E028D09A76AB78E4CD209B619BAF5488524B18988", "hash_ssdeep": "3072:/82iEYVE+5UdD2To8pN8mNlxYPcKrg2aP6nONeeR++2LKn2ONUml:biZVNUdDa7N8yjKrg5PeKWjKUm", "hash_imp": "F4BBB8FABFB86F652548E2B91DF66B99", "hash_pesha1": "6BE8794E215504DDB4C25E4A9DC1018A3D13C0D7", "hash_pe256": "8355A29037F7B3C17DD61B8B08BD0390249A64A01FD19C6315458A96790D986E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Bcdboot utility", "meta_original_filename": "bcdboot.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/d8f1c8a9d019a9430366322d78d76d5647e30664e2d96b3a5fb87738d603d19b/detection/", "output": "\r\nBcdboot - Bcd boot file creation and repair tool.\r\n\r\nThe bcdboot.exe command-line tool is used to copy critical boot files to the\r\nsystem partition and to create a new system BCD store.\r\n\r\nbcdboot <source> [/l <locale>] [/s <volume-letter> [/f <firmware>]] [/v]\r\n [/m [{OS Loader ID}]] [/addlast] [/p] [/c]\r\n\r\n source Specifies the location of the windows system root.\r\n\r\n /l Specifies an optional locale parameter to use when\r\n initializing the BCD store. The default is US English.\r\n\r\n /s Specifies an optional volume letter parameter to designate\r\n the target system partition where boot environment files are\r\n copied. The default is the system partition identified by\r\n the firmware.\r\n\r\n /v Enables verbose mode.\r\n\r\n /m If an OS loader GUID is provided, this option merges the\r\n given loader object with the system template to produce a\r\n bootable entry. Otherwise, only global objects are merged.\r\n\r\n /d Specifies that the existing default windows boot entry\r\n should be preserved.\r\n\r\n /f Used with the /s command, specifies the firmware type of the\r\n target system partition. Options for <firmware> are 'UEFI',\r\n 'BIOS', or 'ALL'.\r\n\r\n /addlast Specifies that the windows boot manager firmware entry\r\n should be added last. The default behavior is to add it\r\n first.\r\n\r\n /bcdclean Clean the BCD Store. By default, simply removes any duplicate\r\n entries in the BCD. Can be followed by 'full'. In this case,\r\n each entry is scanned. If the corresponding device for that entry\r\n does not exist, the entry is deleted.\r\n\r\n /p Specifies that the windows boot manager firmware entry\r\n position should be preserved. If entry does not exist,\r\n new entry will be added in the first position.\r\n\r\n /c Specifies that any existing objects described by the template\r\n should not be migrated.\r\n\r\nExamples: bcdboot c:\\windows /l en-us\r\n bcdboot c:\\windows /s h:\r\n bcdboot c:\\windows /s h: /f UEFI\r\n bcdboot c:\\windows /m {d58d10c6-df53-11dc-878f-00064f4f4e08}\r\n bcdboot c:\\windows /d /addlast\r\n bcdboot c:\\windows /p\r\n" }, "bcdedit.exe-F9C28576DCB87442AE2A7FFD8E48D30E": { "file_name": "bcdedit.exe", "file_path": "C:\\Windows\\system32\\bcdedit.exe", "hash_md5": "F9C28576DCB87442AE2A7FFD8E48D30E", "hash_sha1": "4B6FBD0608CFF57205628C1FC72AC60A02BFDF68", "hash_sha256": "4D922E307AAB064F072017593CA0D77F2599096696EF15C5E92137E915A51B8B", "hash_sha384": "31C550D63A95ACCE34E6F98F2231ED838C3BC2A138ADDA2449FE49933970985BFC86CD6D2450DFC94BA5F6AE9F39B40A", "hash_sha512": "9807E3F1265DB56E52E22089AD1F096774F2588FC8FA6776CD259D68F08CC7F1AD782DF0A83D79B654B802449EA07388B4F6D23F9F7CF7B840A781D6EEBF6FB4", "hash_ssdeep": "6144:Ac+I6NFfE7yesVdvc0pkhFf8NuH98Ka7ssAV:Ac+I6NR1esDOFEEH2l7sZ", "hash_imp": "2137581C3B28D7B500B0C8EB08EE2057", "hash_pesha1": "A809C0543963A7B3BF6D47BB7C640DE8669041F9", "hash_pe256": "DCEF9FA259661DF6E1033711AC1218D4027499E0B79FD56F5F868527C43BA77D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Boot Configuration Data Editor", "meta_original_filename": "bcdedit.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/4d922e307aab064f072017593ca0d77f2599096696ef15c5e92137e915a51b8b/detection/", "output": "\r\nBCDEDIT - Boot Configuration Data Store Editor\r\n\r\nThe Bcdedit.exe command-line tool modifies the boot configuration data store.\r\nThe boot configuration data store contains boot configuration parameters and\r\ncontrols how the operating system is booted. These parameters were previously\r\nin the Boot.ini file (in BIOS-based operating systems) or in the nonvolatile\r\nRAM entries (in Extensible Firmware Interface-based operating systems). You can\r\nuse Bcdedit.exe to add, delete, edit, and append entries in the boot\r\nconfiguration data store.\r\n\r\nFor detailed command and option information, type bcdedit.exe /? <command>. For\r\nexample, to display detailed information about the /createstore command, type:\r\n\r\n bcdedit.exe /? /createstore\r\n\r\nFor an alphabetical list of topics in this help file, run \"bcdedit /? TOPICS\".\r\n\r\nCommands that operate on a store\r\n================================\r\n/store Used to specify a BCD store other than the current system default.\r\n/createstore Creates a new and empty boot configuration data store.\r\n/export Exports the contents of the system store to a file. This file\r\n can be used later to restore the state of the system store.\r\n/import Restores the state of the system store using a backup file\r\n created with the /export command.\r\n/sysstore Sets the system store device (only affects EFI systems, does\r\n not persist across reboots, and is only used in cases where\r\n the system store device is ambiguous).\r\n\r\nCommands that operate on entries in a store\r\n===========================================\r\n/copy Makes copies of entries in the store.\r\n/create Creates new entries in the store.\r\n/delete Deletes entries from the store.\r\n/mirror Creates mirror of entries in the store.\r\n\r\nRun bcdedit /? ID for information about identifiers used by these commands.\r\n\r\nCommands that operate on entry options\r\n======================================\r\n/deletevalue Deletes entry options from the store.\r\n/set Sets entry option values in the store.\r\n\r\nRun bcdedit /? TYPES for a list of datatypes used by these commands.\r\nRun bcdedit /? FORMATS for a list of valid data formats.\r\n\r\nCommands that control output\r\n============================\r\n/enum Lists entries in the store.\r\n/v Command-line option that displays entry identifiers in full,\r\n rather than using names for well-known identifiers.\r\n Use /v by itself as a command to display entry identifiers\r\n in full for the ACTIVE type.\r\n\r\nRunning \"bcdedit\" by itself is equivalent to running \"bcdedit /enum ACTIVE\".\r\n\r\nCommands that control the boot manager\r\n======================================\r\n/bootsequence Sets the one-time boot sequence for the boot manager.\r\n/default Sets the default entry that the boot manager will use.\r\n/displayorder Sets the order in which the boot manager displays the\r\n multiboot menu.\r\n/timeout Sets the boot manager time-out value.\r\n/toolsdisplayorder Sets the order in which the boot manager displays\r\n the tools menu.\r\n\r\nCommands that control Emergency Management Services for a boot application\r\n==========================================================================\r\n/bootems Enables or disables Emergency Management Services\r\n for a boot application.\r\n/ems Enables or disables Emergency Management Services for an\r\n operating system entry.\r\n/emssettings Sets the global Emergency Management Services parameters.\r\n\r\nCommand that control debugging\r\n==============================\r\n/bootdebug Enables or disables boot debugging for a boot application.\r\n/dbgsettings Sets the global debugger parameters.\r\n/debug Enables or disables kernel debugging for an operating system\r\n entry.\r\n/hypervisorsettings Sets the hypervisor parameters.\r\n\r\nCommand that control remote event logging\r\n=========================================\r\n/eventsettings Sets the global remote event logging parameters.\r\n/event Enables or disables remote event logging for an operating \r\n system entry.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\bcdedit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\CRYPTSP.dll" ] }, "bitsadmin.exe-5CD8838F1E275B0C8EADF4B755C04E4F": { "file_name": "bitsadmin.exe", "file_path": "C:\\Windows\\system32\\bitsadmin.exe", "hash_md5": "5CD8838F1E275B0C8EADF4B755C04E4F", "hash_sha1": "5DEB6EC7BB9BD0C85BBE91CBFD92BDC774FE5F8A", "hash_sha256": "03C7E317E277BBD6C9C1159F8718A9D302E6F78E0D80C09D52A994B7598C0F30", "hash_sha384": "781A5959CE3FBD7CA3BB37181ACC90998E249DF75D095C1D7122EEA857571C7EF036E9C670B974942AC78C632D6BB46A", "hash_sha512": "0620F52E3321FDF398326B36C7477E647CBD2A5D5CACB549088284D75E5539A570FA967D9C6B6E4ADE19C2AB7E845960929AE87D99A6F080B3C844FA19063880", "hash_ssdeep": "3072:3m6xtJckj/dV6l5LOufzzkyVRj56+YKsdZetQUC6kIvDg/0jok:3m6xEElM5LOWz4yVRkUL1o", "hash_imp": "B0A3CFF8CFDE112945189719F82F9EA9", "hash_pesha1": "1294B399E2E7921303B6FE4F76879B36A80D276F", "hash_pe256": "2103AE898B3D5E5FE18F51ACC366B5C43F3102825D60F4CEBFF7CE5A00F236F1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BITS administration utility", "meta_original_filename": "bitsadmin.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.8.17763.1 (WinBuild.160101.0800)", "meta_product_version": "7.8.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/03c7e317e277bbd6c9c1159f8718a9d302e6f78e0d80c09d52a994b7598c0f30/detection/", "output": "\r\nBITSADMIN version 3.0\r\nBITS administration utility.\r\n(C) Copyright Microsoft Corp.\r\n\r\nInvalid command\r\nUSAGE: BITSADMIN [/RAWRETURN] [/WRAP | /NOWRAP] command\r\nThe following commands are available:\r\n\r\n/HELP Prints this help \r\n/? Prints this help \r\n/UTIL /? Prints the list of utilities commands \r\n/PEERCACHING /? Prints the list of commands to manage Peercaching\r\n/CACHE /? Prints the list of cache management commands \r\n/PEERS /? Prints the list of peer management commands\r\n\r\n/LIST [/ALLUSERS] [/VERBOSE] List the jobs\r\n/MONITOR [/ALLUSERS] [/REFRESH sec] Monitors the copy manager\r\n/RESET [/ALLUSERS] Deletes all jobs in the manager\r\n\r\n/TRANSFER <job name> [type] [/PRIORITY priority] [/ACLFLAGS flags] [/DYNAMIC] \r\n remote_url local_name\r\n Transfers one of more files.\r\n [type] may be /DOWNLOAD or /UPLOAD; default is download\r\n Multiple URL/file pairs may be specified.\r\n Unlike most commands, <job name> may only be a name and not a GUID.\r\n /DYNAMIC configures the job with BITS_JOB_PROPERTY_DYNAMIC_CONTENT, which relaxes the server-side requirements.\r\n\r\n/CREATE [type] <job name> Creates a job\r\n [type] may be /DOWNLOAD, /UPLOAD, or /UPLOAD-REPLY; default is download\r\n Unlike most commands, <job name> may only be a name and not a GUID.\r\n\r\n/INFO <job> [/VERBOSE] Displays information about the job\r\n/ADDFILE <job> <remote_url> <local_name> Adds a file to the job\r\n/ADDFILESET <job> <textfile> Adds multiple files to the job\r\n Each line of <textfile> lists a file's remote name and local name, separated\r\n by spaces. A line beginning with '#' is treated as a comment.\r\n Once the file set is read into memory, the contents are added to the job.\r\n\r\n/ADDFILEWITHRANGES <job> <remote_url> <local_name range_list>\r\n Like /ADDFILE, but BITS will read only selected byte ranges of the URL.\r\n range_list is a comma-delimited series of offset and length pairs.\r\n For example,\r\n\r\n 0:100,2000:100,5000:eof\r\n\r\n instructs BITS to read 100 bytes starting at offset zero, 100 bytes starting\r\n at offset 2000, and the remainder of the URL starting at offset 5000.\r\n\r\n/REPLACEREMOTEPREFIX <job> <old_prefix> <new_prefix>\r\n All files whose URL begins with <old_prefix> are changed to use <new_prefix>\r\n\r\nNote that BITS currently supports HTTP/HTTPS downloads and uploads.\r\nIt also supports UNC paths and file:// paths as URLS\r\n\r\n/LISTFILES <job> Lists the files in the job\r\n/SUSPEND <job> Suspends the job\r\n/RESUME <job> Resumes the job\r\n/CANCEL <job> Cancels the job\r\n/COMPLETE <job> Completes the job\r\n\r\n/GETTYPE <job> Retrieves the job type\r\n/GETACLFLAGS <job> Retrieves the ACL propagation flags\r\n\r\n/SETACLFLAGS <job> <ACL_flags> Sets the ACL propagation flags for the job\r\n O - OWNER G - GROUP \r\n D - DACL S - SACL \r\n\r\n Examples:\r\n bitsadmin /setaclflags MyJob OGDS\r\n bitsadmin /setaclflags MyJob OGD\r\n\r\n/GETBYTESTOTAL <job> Retrieves the size of the job\r\n/GETBYTESTRANSFERRED <job> Retrieves the number of bytes transferred\r\n/GETFILESTOTAL <job> Retrieves the number of files in the job\r\n/GETFILESTRANSFERRED <job> Retrieves the number of files transferred\r\n/GETCREATIONTIME <job> Retrieves the job creation time\r\n/GETMODIFICATIONTIME <job> Retrieves the job modification time\r\n/GETCOMPLETIONTIME <job> Retrieves the job completion time\r\n/GETSTATE <job> Retrieves the job state\r\n/GETERROR <job> Retrieves detailed error information\r\n/GETOWNER <job> Retrieves the job owner\r\n/GETDISPLAYNAME <job> Retrieves the job display name\r\n/SETDISPLAYNAME <job> <display_name> Sets the job display name\r\n/GETDESCRIPTION <job> Retrieves the job description\r\n/SETDESCRIPTION <job> <description> Sets the job description\r\n/GETPRIORITY <job> Retrieves the job priority\r\n/SETPRIORITY <job> <priority> Sets the job priority\r\n Priority usage choices:\r\n FOREGROUND \r\n HIGH\r\n NORMAL\r\n LOW\r\n/GETNOTIFYFLAGS <job> Retrieves the notify flags\r\n/SETNOTIFYFLAGS <job> <notify_flags> Sets the notify flags\r\n For more help on this option, please refer to the MSDN help page for SetNotifyFlags/GETNOTIFYINTERFACE <job> Determines if notify interface is registered\r\n/GETMINRETRYDELAY <job> Retrieves the retry delay in seconds\r\n/SETMINRETRYDELAY <job> <retry_delay> Sets the retry delay in seconds\r\n/GETNOPROGRESSTIMEOUT <job> Retrieves the no progress timeout in seconds\r\n/SETNOPROGRESSTIMEOUT <job> <timeout> Sets the no progress timeout in seconds\r\n/GETMAXDOWNLOADTIME <job> Retrieves the download timeout in seconds\r\n/SETMAXDOWNLOADTIME <job> <timeout> Sets the download timeout in seconds\r\n/GETERRORCOUNT <job> Retrieves an error count for the job\r\n\r\n/SETPROXYSETTINGS <job> <usage> Sets the proxy usage\r\n usage choices:\r\n PRECONFIG - Use the owner's default Internet settings.\r\n AUTODETECT - Force autodetection of proxy.\r\n NO_PROXY - Do not use a proxy server.\r\n OVERRIDE - Use an explicit proxy list and bypass list. \r\n Must be followed by a proxy list and a proxy bypass list.\r\n NULL or \"\" may be used for an empty proxy bypass list.\r\n Examples:\r\n bitsadmin /setproxysettings MyJob PRECONFIG\r\n bitsadmin /setproxysettings MyJob AUTODETECT\r\n bitsadmin /setproxysettings MyJob NO_PROXY\r\n bitsadmin /setproxysettings MyJob OVERRIDE proxy1:80 \"<local>\" \r\n bitsadmin /setproxysettings MyJob OVERRIDE proxy1,proxy2,proxy3 NULL \r\n\r\n/GETPROXYUSAGE <job> Retrieves the proxy usage setting\r\n/GETPROXYLIST <job> Retrieves the proxy list\r\n/GETPROXYBYPASSLIST <job> Retrieves the proxy bypass list\r\n\r\n/TAKEOWNERSHIP <job> Take ownership of the job\r\n\r\n/SETNOTIFYCMDLINE <job> <program_name> [program_parameters] \r\n Sets a program to execute for notification, and optionally parameters.\r\n The program name and parameters can be NULL.\r\n IMPORTANT: if parameters are non-NULL, then the program name should be the\r\n first parameter.\r\n\r\n Examples:\r\n bitsadmin /SetNotifyCmdLine MyJob c:\\winnt\\system32\\notepad.exe NULL\r\n bitsadmin /SetNotifyCmdLine MyJob c:\\callback.exe \"c:\\callback.exe parm1 parm2\" \r\n bitsadmin /SetNotifyCmdLine MyJob NULL NULL\r\n\r\n/GETNOTIFYCMDLINE <job> Returns the job's notification command line\r\n\r\n/SETCREDENTIALS <job> <target> <scheme> <username> <password>\r\n Adds credentials to a job.\r\n <target> may be either SERVER or PROXY\r\n <scheme> may be BASIC, DIGEST, NTLM, NEGOTIATE, or PASSPORT. \r\n\r\n/REMOVECREDENTIALS <job> <target> <scheme> \r\n Removes credentials from a job.\r\n/GETCUSTOMHEADERS <job> Gets the Custom HTTP Headers\r\n/SETCUSTOMHEADERS <job> <header1> <header2> <...> Sets the Custom HTTP Headers\r\n\r\n/GETHTTPMETHOD <job> Gets the HTTP verb to use.\r\n/SETHTTPMETHOD <job> <HTTPMethod> Sets the HTTP verb to use.\r\n\r\n/GETCLIENTCERTIFICATE <job> Gets the job's Client Certificate Information\r\n/SETCLIENTCERTIFICATEBYID <job> <store_location> <store_name> <hexa-decimal_cert_id>\r\n Sets a client authentication certificate to a job.\r\n <store_location> may be \r\n\t1(CURRENT_USER), 2(LOCAL_MACHINE), 3(CURRENT_SERVICE),\r\n\t4(SERVICES), 5(USERS), 6(CURRENT_USER_GROUP_POLICY),\r\n\t7(LOCAL_MACHINE_GROUP_POLICY) or 8(LOCAL_MACHINE_ENTERPRISE). \r\n\r\n/SETCLIENTCERTIFICATEBYNAME <job> <store_location> <store_name> <subject_name>\r\n Sets a client authentication certificate to a job.\r\n <store_location> may be \r\n\t1(CURRENT_USER), 2(LOCAL_MACHINE), 3(CURRENT_SERVICE),\r\n\t4(SERVICES), 5(USERS), 6(CURRENT_USER_GROUP_POLICY),\r\n\t7(LOCAL_MACHINE_GROUP_POLICY) or 8(LOCAL_MACHINE_ENTERPRISE). \r\n\r\n/REMOVECLIENTCERTIFICATE <job> Removes the Client Certificate Information from the job\r\n\r\n/SETSECURITYFLAGS <job> <value> \r\n Sets the HTTP security flags for URL redirection and checks performed on the server certificate during the transfer.\r\n The value is an unsigned integer with the following interpretation for the bits in the binary representation.\r\n Enable CRL Check : Set the least significant bit\r\n Ignore invalid common name in server certificate : Set the 2nd bit from right\r\n Ignore invalid date in server certificate : Set the 3rd bit from right\r\n Ignore invalid certificate authority in server\r\n certificate : Set the 4th bit from right\r\n Ignore invalid usage of certificate : Set the 5th bit from right\r\n Redirection policy : Controlled by the 9th-11th bits from right\r\n 0,0,0 - Redirects will be automatically allowed.\r\n 0,0,1 - Remote name in the IBackgroundCopyFile interface will be updated if a redirect occurs.\r\n 0,1,0 - BITS will fail the job if a redirect occurs.\r\n\r\n Allow redirection from HTTPS to HTTP : Set the 12th bit from right\r\n\r\n/GETSECURITYFLAGS <job> \r\n Reports the HTTP security flags for URL redirection and checks performed on the server certificate during the transfer.\r\n\r\n/SETVALIDATIONSTATE <job> <file-index> <true|false>\r\n <file-index> starts from 0 \r\n Sets the content-validation state of the given file within the job.\r\n\r\n/GETVALIDATIONSTATE <job> <file-index> \r\n <file-index> starts from 0 \r\n Reports the content-validation state of the given file within the job.\r\n\r\n/GETTEMPORARYNAME <job> <file-index> \r\n <file-index> starts from 0 \r\n Reports the temporary filename of the given file within the job.\r\n\r\nThe following options control peercaching of a particular job:\r\n\r\n/SETPEERCACHINGFLAGS <job> <value> \r\n Sets the flags for the job's peercaching behavior.\r\n The value is an unsigned integer with the following interpretation for the bits in the binary representation.\r\n Allow the job's data to be downloaded from a peer : Set the least significant bit\r\n Allow the job's data to be served to peers : Set the 2nd bit from right\r\n\r\n/GETPEERCACHINGFLAGS <job> \r\n Reports the flags for the job's peercaching behavior.\r\n\r\nThe following options are valid for UPLOAD-REPLY jobs only:\r\n\r\n/GETREPLYFILENAME <job> Gets the path of the file containing the server reply\r\n/SETREPLYFILENAME <job> <path> Sets the path of the file containing the server reply\r\n/GETREPLYPROGRESS <job> Gets the size and progress of the server reply\r\n/GETREPLYDATA <job> Dumps the server's reply data in hex format\r\n\r\n/SETHELPERTOKEN <job> Sets the current command prompt's primary token as a job's helper token\r\n/GETHELPERTOKENSID <job> Reports the user account SID of a job's helper token, if one is set\r\n\r\n/SETHELPERTOKENFLAGS <job> <flags> \r\n Sets the helper token usage flags for a job. Possible values are:\r\n 1 - The helper token is used when accessing the local filesystem.\r\n 2 - The helper token is used when accessing the network.\r\n 3 - The helper token is used when accessing both the local filesystem and the network.\r\n\r\n/GETHELPERTOKENFLAGS <job> \r\n Reports a job's helper token usage flags.\r\n\r\n/GETPEERSTATS <job> <file-index> \r\n <file-index> starts from 0 \r\n Reports statistics about the amount of data downloaded from peers and origin servers for a specific file within a job.\r\n\r\nThe following options can be placed before the command:\r\n/RAWRETURN Return data more suitable for parsing\r\n/WRAP Wrap output around console (default)\r\n/NOWRAP Don't wrap output around console\r\n\r\nThe /RAWRETURN option strips new line characters and formatting.\r\nIt is recognized by the /CREATE and /GET* commands.\r\n\r\nCommands that take a <job> parameter will accept either a job name or a job ID\r\nGUID inside braces. BITSADMIN reports an error if a name is ambiguous.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\bitsadmin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll" ] }, "bootcfg.exe-580B143C690E8921E365943B935C7854": { "file_name": "bootcfg.exe", "file_path": "C:\\Windows\\system32\\bootcfg.exe", "hash_md5": "580B143C690E8921E365943B935C7854", "hash_sha1": "921FAFCACF782D85C68122511CC748C3DF94B454", "hash_sha256": "BE45A65C9A57A9B47B2656C057230D0C37C18299761AF5DBB24EE5DCE2429EC5", "hash_sha384": "98D377B8B6A89336872951B5B16D89338A7CA90383575DEAE76D05CF7426245E369C25FC22E7DBAE150A3B7319DC824A", "hash_sha512": "9ACA418370E5978848637003C64A4B5FF7457B7447EFAB9384AA0F5397E24A225DD25C3E5835DABF725304750B26620F13E819D6F2AF77F5F1E6BDEA1F4D4980", "hash_ssdeep": "1536:rijQlcYBI2AlQM8yBTSCUiC4dTLFjJwpH/sy0OJQv+KE5PFa+ctf:rijBlQZu+/iCYJwpH0p3+KaPFa+cp", "hash_imp": "F3ADCD04B0BF69589B2B3643D6CF3803", "hash_pesha1": "70EF04C5F328873F96EA91725CA43850ED829E28", "hash_pe256": "F21E2382DDAB11FA7E01CBE0CD8E7013EAEA5B63727785625B5EAB6EE42B5618", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BootCfg - Lists or changes the boot settings.", "meta_original_filename": "bootcfg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/be45a65c9a57a9b47b2656c057230d0c37c18299761af5dbb24ee5dce2429ec5/detection/", "output": "\r\nBOOTCFG /parameter [arguments]\r\n\r\nDescription:\r\n This command line tool can be used to configure, query, change or \r\n delete the boot entry settings in the BOOT.INI file.\r\n\r\nParameter List:\r\n /Copy Makes a copy of an existing boot entry.\r\n\r\n /Delete Deletes an existing boot entry from the BOOT.INI file.\r\n\r\n /Query Displays the current boot entries and their settings.\r\n\r\n /Raw Allows the user to specify any switch to be added.\r\n\r\n /Timeout Allows the user to change the Timeout value.\r\n\r\n /Default Allows the user to change the Default boot entry.\r\n\r\n /EMS Allows the user to configure the /redirect switch\r\n for headless support.\r\n\r\n /Debug Allows the user to specify the port and baudrate for \r\n remote debugging.\r\n\r\n /Addsw Allows the user to add predefined switches.\r\n\r\n /Rmsw Allows the user to remove predefined switches.\r\n\r\n /Dbg1394 Allows the user to configure 1394 port for debugging.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n BOOTCFG /Copy /?\r\n BOOTCFG /Delete /?\r\n BOOTCFG /Query /?\r\n BOOTCFG /Raw /?\r\n BOOTCFG /Timeout /?\r\n BOOTCFG /EMS /?\r\n BOOTCFG /Debug /?\r\n BOOTCFG /Addsw /?\r\n BOOTCFG /Rmsw /?\r\n BOOTCFG /Dbg1394 /?\r\n BOOTCFG /Default /?\r\n BOOTCFG /?\r\n\r\nWARNING: BOOT.INI is used for boot options on Windows XP and earlier\r\n operating systems. Use the BCDEDIT command line tool to modify\r\n Windows Vista boot options.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\bootcfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\NETAPI32.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\SRVCLI.DLL", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\NETUTILS.DLL" ], "error": "ERROR: Invalid syntax.\r\nType \"BOOTCFG /?\" for usage.\r\n" }, "bootim.exe-C31EA91BA21D71BFD1E606745BE1973C": { "file_name": "bootim.exe", "file_path": "C:\\Windows\\system32\\bootim.exe", "hash_md5": "C31EA91BA21D71BFD1E606745BE1973C", "hash_sha1": "F44E651E269848EB26F589447E37EAABA22B3162", "hash_sha256": "E233391AF22BE0E39D8D2E3FAEECE9D424031CE97DFA9AE3A7A453F2E6F5C5CB", "hash_sha384": "217CA41077EAD8C75B284C0475141410624621CCF2F6723F6E2FF1961D52D8AE62F64BC4FE16F493788842DB43E13883", "hash_sha512": "63FEEA27B05881103D6647EC5E413C8ABE1638508679BCE9056D975755667EAE6472601B7CC25154C93906CB0D8DA41C23DB32A9F3E21BFCEEA73F8D9D819772", "hash_ssdeep": "768:Zy+J0gV1F9PMaaKYTA31XuY6n2DGGwPx8:8E5DYTS1+Y6sGGwPx8", "hash_imp": "518DDF1B5D2EAA775607E0D8B554C455", "hash_pesha1": "91DF7124DC1AD6A58B1DC1563791A9FEB4154518", "hash_pe256": "ADA84A75845A9D09294FE58CE125C9DCA71EB9D43C39B94D49FDCF5C9BBE35F0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "boot immersive menus", "meta_original_filename": "bootim.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e233391af22be0e39d8d2e3faeece9d424031ce97dfa9ae3a7a453f2e6f5c5cb/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\bootux.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RWD) C:\\Windows\\Fonts\\segoeuil.ttf": "File", "\\Sessions\\2\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(RWD) C:\\Windows\\Fonts\\segoeuisl.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\bootim.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\BOOTUX.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\UIAutomationCore.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\Bcp47Langs.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\Comctl32.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwrite.dll" ], "runtime_window_title": "Boot App" }, "bridgeunattend.exe-3368F87D649D23E123FDD2A285A581B2": { "file_name": "bridgeunattend.exe", "file_path": "C:\\Windows\\system32\\bridgeunattend.exe", "hash_md5": "3368F87D649D23E123FDD2A285A581B2", "hash_sha1": "AA0A06E45CEE8EF63D6AED48DD17A5E25D4D6E88", "hash_sha256": "7F7FAE31CF7B8B04112F746C27B51BB37F3DCCEF08E5459AB65CBE0F44A146B5", "hash_sha384": "95F28064D9A75A41026E5962ADC95923C689B10FDF04424EFB010719796C4D7967DE9BB9004A7A1BA5DB46AE6D1E28AF", "hash_sha512": "4EFE2C7C45CF5EA75B7ABF172A96121064E6C393DC4C721BC5B6008130282989DF13E19B6AEDE8078AA7A63ED0E679A03408BA018E4340D4FABC9843898D3A11", "hash_ssdeep": "384:0uvJeoW5iyUVbpJrv5FCgxmyytdcW9qp4EaIHqbfW4fW:Pefx+rcygjQp4wHqj", "hash_imp": "43414F81FC52CAF520B560A4956A39CC", "hash_pesha1": "1484828766C0EDE2F12A8BC4FB675D29B0CA4DB8", "hash_pe256": "16C49AF09DCC0330648E1366432D3244F32AABE34862BEA16CE0E25FCA7CA335", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Bridge Unattend Utility", "meta_original_filename": "bridgeunattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/7f7fae31cf7b8b04112f746c27b51bb37f3dccef08e5459ab65cbe0f44a146b5/detection/" }, "browserexport.exe-E462FE296AB0E6CAAC8C527AE0AEFB8E": { "file_name": "browserexport.exe", "file_path": "C:\\Windows\\system32\\browserexport.exe", "hash_md5": "E462FE296AB0E6CAAC8C527AE0AEFB8E", "hash_sha1": "3C9ADA09B943097DC2C7A4A7167E255C00C7186C", "hash_sha256": "C1F0E89FAA6595649C786BF3012D8E6BA45BBF319E587AB9BBDD94BEA87228EF", "hash_sha384": "932662301A38E777159F340687FA5DC335167D3223195CC9A3EB7A2B6E853FC4846CAA062F1ACBFC5F6D878F4F64C5F1", "hash_sha512": "A87EF914494F0A6E3FA79DF4765379A6BA71B51AB80732B9C6F30CE1FCAAC401F9576D0E1E8B138B6C5D09DD6ADF7B6B9F42B93A177AADF9AA29DAD33EA768E3", "hash_ssdeep": "3072:ZMWHOmxD81wmJUv+JwkVjrqjlymf2RdOPIXwQNbPbMshTcMP6AoTIYDGh:ZMWHOmxDEwmJkkVjJmf2RAP0jbPbMsWv", "hash_imp": "6C05DA5727CE1DE8F162D91AC3415DCE", "hash_pesha1": "771B806AF39F467A7CD9CCDF7DC2E0D2BFCFB9E6", "hash_pe256": "AE20949AFAE6C63D6F35944D30F20D2874469B2492DA9A442F4B46278844BF27", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Edge Browser Exporter", "meta_original_filename": "browserexport.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c1f0e89faa6595649c786bf3012d8e6ba45bbf319e587ab9bbdd94bea87228ef/detection/", "runtime_modules": [ "C:\\Windows\\system32\\browserexport.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\WININET.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\system32\\winsqlite3.dll", "C:\\Windows\\system32\\msIso.dll" ] }, "browser_broker.exe-08EAE2A042C90DB1DBA4FB34E4D56264": { "file_name": "browser_broker.exe", "file_path": "C:\\Windows\\system32\\browser_broker.exe", "hash_md5": "08EAE2A042C90DB1DBA4FB34E4D56264", "hash_sha1": "8F1330D097A3A612DBBC7C1E39E1D1E2C06E6634", "hash_sha256": "609A3A73A983A1C47511282D31D9FCFE7909950944AC5324344596215CD778AA", "hash_sha384": "CF52DCDDC438BD501ACA067B4F290BEA98A5F4B125353702D34B084DE762DBB2AEA755E86176FD6606C317E366EE00D0", "hash_sha512": "CC46D7F0639E91ED5F3299B6CC85A9E527C183E5EEA6CC00B26180B5DB2ED1C92B67547ECF42CD28C644C4A29BCC855C5B96F3235896655DC68E4C40B153FB86", "hash_ssdeep": "768:m5DLT73BzR6tz6fzM7eIU6mvKue4GEXj1PMYC:mBLH3hR6CzEU6oKue4G6pPLC", "hash_imp": "DB359A050881ECD06E06DC1C90FF4448", "hash_pesha1": "004F27B4EC8386ED6C72B49B93A69580389F80D3", "hash_pe256": "7F8B28791DAC5B0980B96CCE650F2A00EAA834C8D7B12C5130029A75EDA52D3A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Browser_Broker", "meta_original_filename": "browser_broker.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.316 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.316", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/609a3a73a983a1c47511282d31d9fcfe7909950944ac5324344596215cd778aa/detection/" }, "bthudtask.exe-84E6105AB4B8F6949F123A56B5C5DBA4": { "file_name": "bthudtask.exe", "file_path": "C:\\Windows\\system32\\bthudtask.exe", "hash_md5": "84E6105AB4B8F6949F123A56B5C5DBA4", "hash_sha1": "210FDE06627403BEC71B181969A0476FAE500EC8", "hash_sha256": "B725D71CBD9C135BA77B6A6214DB0E7D5C738A7D240AE8DF5996D5056F832D79", "hash_sha384": "2DFC2E3FD7838B8A1D62147222B34956F7EAE5AA6ABFBD856831B1E39F7B86EBE1316AAB0B86462136E7829EBB94EA9E", "hash_sha512": "B6C7F4A9D32CFDD01E9CCFA0FF9C27440F14C87080F4D6A103118EB07DCF3CA51B3207B9A0DA881D2C08A51D4C00CE2EFD7767CE58E35764A0C5DA6216558B0C", "hash_ssdeep": "384:kW+OgaDoFkMczuETsFOLpfINIaef3RmSivWWwHWeKJajXDO1/EagS817l:kIdEFJSOGpfo9ys1Y/zDO", "hash_imp": "9ABEB2B37A47478C60D77A46A439A38B", "hash_pesha1": "5D6F8F5633B702432CD5DB46FBA75F64326D8C26", "hash_pe256": "4FDD2CC4C624278BEE08F143E381CC93A1E53B426B2A13F4E797EC276EBBB849", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Bluetooth Uninstall Device Task", "meta_original_filename": "BthUdTask.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/63", "filescan_vtlink": "https://www.virustotal.com/gui/file/b725d71cbd9c135ba77b6a6214db0e7d5c738a7d240ae8df5996d5056f832d79/detection/" }, "ByteCodeGenerator.exe-12C0DAB03BF98F1BCAA6D5AB6B41F727": { "file_name": "ByteCodeGenerator.exe", "file_path": "C:\\Windows\\system32\\ByteCodeGenerator.exe", "hash_md5": "12C0DAB03BF98F1BCAA6D5AB6B41F727", "hash_sha1": "16F455AB91F9DD817A154EB297C54320528AA243", "hash_sha256": "E2A97DA4EFD83513BD97010F00BCD746C9AC3F73ED0A6B9D398851AC59FC19CC", "hash_sha384": "76EF7BA2D17E95962C8BA73A44B45BB0BF6FB242BE1B32096287EFB4679A3842CBFD3CDEFD699F0EF938B2FDB79D6CC6", "hash_sha512": "CA667D163DDBFE266978E9EFB37642EF7259FC71023EDA2672A37CCE98B48E8FAC2AEC3B0AB883711609B82DFA46C323D867CA3BE70D22CA7CE56E992E79C35A", "hash_ssdeep": "1536:OEqDOXp+O+vHDcU5EIfN8qhymeO0Fe8PfcI+:L4O+h6MDySQcn", "hash_imp": "F5ACE670FDFC5D9ED1DE776EE2927575", "hash_pesha1": "63DCC9543077AE1067F9A3C501336249323E3317", "hash_pe256": "05F0BC325618D7FF7555F1BBB465264C03B4C7DF39CF7DDB98BE631FEB980F3F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AppX Deployment Bytecode Generator EXE", "meta_original_filename": "BytecodeGenerator.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/e2a97da4efd83513bd97010f00bcd746c9ac3f73ed0a6b9d398851ac59fc19cc/detection/", "runtime_modules": [ "C:\\Windows\\system32\\ByteCodeGenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "cacls.exe-7B353F98E18FD9BEA92D4CA9AEEBA9CC": { "file_name": "cacls.exe", "file_path": "C:\\Windows\\system32\\cacls.exe", "hash_md5": "7B353F98E18FD9BEA92D4CA9AEEBA9CC", "hash_sha1": "4861B3D04E2DB776782736126E71E08F80BB6803", "hash_sha256": "C81018F19C8C104E568D5168C7CA7011FAA9C7BA7310510B303E54A7FAFCE84C", "hash_sha384": "8B0A4EAECB47D0C0355B5A1CE9B452139143B41A2A96B2CC4B9BCDDD9757B649528EABF184A8DA133EC7706EC9557670", "hash_sha512": "F0A3B6E6EA41FAE0E506936B85B4C437425F73C8F0704DC4A289D0B77CDC7CD4804536807CF4AE534C713A21DF1A2500CCD3C23BB6D284DF62E21BB66ED807B3", "hash_ssdeep": "768:gczFYtcN4HFs+QJp5UWh2/w/FxP9HnCi20b0DhDqG1+i2K:hzmtlnQJbUW8w/FxP1nkPDqGf2K", "hash_imp": "8F09CA312ABDFEB8B57BA1170C68E893", "hash_pesha1": "7BC9CA4D81C2F9A314581FF7F14703C4A45ABF41", "hash_pe256": "E70ACC3BDFCA5255D7836E32A8483E9A75317DCF5C88FD67F3176B634E1609DC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Control ACLs Program", "meta_original_filename": "CACLS.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/c81018f19c8c104e568d5168c7ca7011faa9c7ba7310510b303e54a7fafce84c/detection/", "output": "\r\r\n NOTE: Cacls is now deprecated, please use Icacls.\r\r\n\r\r\n Displays or modifies access control lists (ACLs) of files\r\r\n\r\r\n CACLS filename [/T] [/M] [/L] [/S[:SDDL]] [/E] [/C] [/G user:perm]\r\r\n [/R user [...]] [/P user:perm [...]] [/D user [...]]\r\r\n filename Displays ACLs.\r\r\n /T Changes ACLs of specified files in\r\r\n the current directory and all subdirectories.\r\r\n /L Work on the Symbolic Link itself versus the target\r\r\n /M Changes ACLs of volumes mounted to a directory\r\r\n /S Displays the SDDL string for the DACL.\r\r\n /S:SDDL Replaces the ACLs with those specified in the SDDL string\r\r\n (not valid with /E, /G, /R, /P, or /D).\r\r\n /E Edit ACL instead of replacing it.\r\r\n /C Continue on access denied errors.\r\r\n /G user:perm Grant specified user access rights.\r\r\n Perm can be: R Read\r\r\n W Write\r\r\n C Change (write)\r\r\n F Full control\r\r\n /R user Revoke specified user's access rights (only valid with /E).\r\r\n /P user:perm Replace specified user's access rights.\r\r\n Perm can be: N None\r\r\n R Read\r\r\n W Write\r\r\n C Change (write)\r\r\n F Full control\r\r\n /D user Deny specified user access.\r\r\n Wildcards can be used to specify more than one file in a command.\r\r\n You can specify more than one user in a command.\r\r\n\r\r\n Abbreviations:\r\r\n CI - Container Inherit.\r\r\n The ACE will be inherited by directories.\r\r\n OI - Object Inherit.\r\r\n The ACE will be inherited by files.\r\r\n IO - Inherit Only.\r\r\n The ACE does not apply to the current file/directory.\r\r\n ID - Inherited.\r\r\n The ACE was inherited from the parent directory's ACL.\r\r\n", "error": "The system cannot find the file specified.\r\r\n" }, "calc.exe-DEAD69D07BC33B762ABD466FB6F53E11": { "file_name": "calc.exe", "file_path": "C:\\Windows\\system32\\calc.exe", "hash_md5": "DEAD69D07BC33B762ABD466FB6F53E11", "hash_sha1": "F5ED372FD8EC7C455FF66BCE73F16CA51CBC0302", "hash_sha256": "3091E2ABFB55D05D6284B6C4B058B62C8C28AFC1D883B699E9A2B5482EC6FD51", "hash_sha384": "3F375EA1E6F6A82213CF665066557B16DFDCA4E56EAE36CFC2CCBBE6E82CAA7D905F6EEFD60B42A8D6901866AEEC6424", "hash_sha512": "F33A402E96474FC10F870293058B7252517456B4053D85885EBF21D0F9166F9A8A86457327A3E307624864B30CA9888AE0399A90C6248C50B781B28D9981C0C6", "hash_ssdeep": "384:S3B2ChTCfxWqHPuOOLE8eWS0YWbiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiLih:a2CwxTmOv8zG", "hash_imp": "8EEAA9499666119D13B3F44ECD77A729", "hash_pesha1": "79396B68649B074C8E305418072B543D6C9C4C81", "hash_pe256": "9BD6A9258FDB68AC01A937BB26848A27FCC508C985B780F7186642F0BE756500", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Calculator", "meta_original_filename": "CALC.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/3091e2abfb55d05d6284b6c4b058b62c8c28afc1d883b699e9a2b5482ec6fd51/detection/", "children": "win32calc.exe", "runtime_modules": [ "C:\\Windows\\system32\\calc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "CameraSettingsUIHost.exe-10B7D969121E3EA751148BA39C5AEF4E": { "file_name": "CameraSettingsUIHost.exe", "file_path": "C:\\Windows\\system32\\CameraSettingsUIHost.exe", "hash_md5": "10B7D969121E3EA751148BA39C5AEF4E", "hash_sha1": "30AFD1D047E64200728C58D140A79D191461D5F3", "hash_sha256": "224A94BD020E7F06CC9BF9A82C415981C6F677C2A357AC64616A5FDB53A3D605", "hash_sha384": "A9B4C55A3FC8B3F310A1B654500324365EFC84C9B9573AFADDBC9D21B57B1D4FB72C96DEDFF27A8FDE54A50ACDB687AE", "hash_sha512": "7CC4EAA955F358719F08BC4812B6F8C80E2E210DBD86DBC1C603B4B2D38A87823F564380880188A12E6B62C7E34BE69605B30D4D3940B8FD7DB5159029B6B00C", "hash_ssdeep": "768:EQ5CeJyHBiCouAXxqGZSwUSwXBMa7OTXj1Pu0gT:Ehh/Nqxqo/a7ObpPuhT", "hash_imp": "12631E1054B137DD8582235338EFAE7A", "hash_pesha1": "7BCB4A55B1535BC2F0902A266913D0517F0D4F85", "hash_pe256": "000EA58F022B22190C9D4392D23B83ADFABEFD9A3ACB9E0B31735A0375DB6461", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Camera Settings UI Host", "meta_original_filename": "CameraSettingsUIHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/224a94bd020e7f06cc9bf9a82c415981c6f677c2a357ac64616a5fdb53a3d605/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECE4C": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\CameraSettingsUIHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\ole32.dll" ] }, "CastSrv.exe-4BFD0F15DC0C5EB166578D1D8CB74E80": { "file_name": "CastSrv.exe", "file_path": "C:\\Windows\\system32\\CastSrv.exe", "hash_md5": "4BFD0F15DC0C5EB166578D1D8CB74E80", "hash_sha1": "3BD788F7CDEF5FEB59E82FDF39E47CCF7E904F0E", "hash_sha256": "3EACC4101F8D7E0360CFB1BE38CF46FB3A6901FCB89DBCF45A0806C751219A73", "hash_sha384": "50BBF042950A8E55D9C1F07B81B235633C42C2FF2D706C29E0FE0769A6A8DF000528451A73C5E3ACD27F80B76E272F5E", "hash_sha512": "66115690085153ED96BC8A004200B48B2147C9BD3B0AE892E573F032B6ECAAA17D5D2C34D8A1319BCB2465656BEA08C792D2868521A7AAEAFC6062AE7D374AA9", "hash_ssdeep": "768:hfjayqpFKRwl32wGcXNpk55vPDPwIxsX2l09GCcQqMlJji8M7j5ifrVXj1P:l2Fh3DdU7PbsGaUCxqMvi8Wj5irJpP", "hash_imp": "C72DA8053EBE1390070DE23E82991E7F", "hash_pesha1": "BF9C20C6CE4040528E0B836BDEA983BDB54F2FBC", "hash_pe256": "A19517943A0F06E19975DB3F4D85594F1AC0FA00ACCA925886FB31C8976341E7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Casting protocol connection listener", "meta_original_filename": "CastSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/3eacc4101f8d7e0360cfb1be38cf46fb3a6901fcb89dbcf45a0806c751219a73/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\CastSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\MFPlat.DLL", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\RTWorkQ.DLL", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "CertEnrollCtrl.exe-021F0494762A3060149B29038373347B": { "file_name": "CertEnrollCtrl.exe", "file_path": "C:\\Windows\\system32\\CertEnrollCtrl.exe", "hash_md5": "021F0494762A3060149B29038373347B", "hash_sha1": "DC6CDDFE56F15A097D2D0FB6BAD417E80A030496", "hash_sha256": "E127AFCE74594A9C51CC0B22B3E7650A1BAE2B6F00EE976B4B0C1280DCAEFF6C", "hash_sha384": "E9DE4F850DD3FED885D4DF440417C218DA86AB2E48814F658314F7FB4A464787B1BBFA38B29AC950C17D700509D890E6", "hash_sha512": "64549CACD3F82C48179CAE3238A221F65EE5BC7D4FB9751E0016D3B9877B834DAAEA0D838BB5D0B47141E5120B87384B631B312CCA785187AC03BAF523841525", "hash_ssdeep": "768:1oYmUxLLGnu9qdtDOkc7gO2OxFyAlBOZ+iaOjprTllDyVO1vTzw6hnhZC3yNv:1oxoWdO/MO2AyvHuYHwEZCCNv", "hash_imp": "C7DE19F0FD50B729129C6693FF1FEDA2", "hash_pesha1": "9422BE2A1AAE07ACC6328DA277125F578B9E2ADC", "hash_pe256": "0D29D05F8A64D53D2907B62B70D82F3EB22CDD7B893419D55D6286601388EC9F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Certificate Enrollment Control", "meta_original_filename": "EnrollComServer.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e127afce74594a9c51cc0b22b3e7650a1bae2b6f00ee976b4b0c1280dcaeff6c/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\CertEnrollCtrl.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1190": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\CertEnrollCtrl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\certca.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\certenroll.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\DSPARSE.dll", "C:\\Windows\\system32\\DPAPI.DLL" ] }, "certoc.exe-D75A554FDA8443AA0CC236D2768F7F21": { "file_name": "certoc.exe", "file_path": "C:\\Windows\\system32\\certoc.exe", "hash_md5": "D75A554FDA8443AA0CC236D2768F7F21", "hash_sha1": "FD0717D291A287DA36553B43AB3E661C1FC657DB", "hash_sha256": "DEBC4F3E7B3D7AA72763170660EC9382021935E675F3BAA5E1A585B3C94FCD73", "hash_sha384": "2E43462033B1146E00E715CD0AB2C7694BD06FE3521792D2EF66571DA797A86F29D51A22F1D0BB67A0E03C1AB2307ACD", "hash_sha512": "5642E65A389B89A98A615D3AC868CAE7CC4CE211193F0C8DDDB380772A32512ECA414FE31FB332A36F2A32A5210C4DAE51CF13B623FD5C5C4228A46CC81862D0", "hash_ssdeep": "1536:eicU1pleiOsnoGqfEOF11f1mPgKCftrUtWD0i4c1B2T6TvnF9cWT8YlrDbMtLR3s:Af0otsOFJmuftYWD0ix8rtLFifaYkM", "hash_imp": "964F0F5F0131DAC0DAD3E441F0CC521B", "hash_pesha1": "3A06C5DEB3AF4FCF83BED0DD5999AC293DEDE7C4", "hash_pe256": "E724BA5AE14BBF5CBE71B1B0CDCB638985C2F125B49061CCDC92FCF9C0238453", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CertOC.exe", "meta_original_filename": "CertOC.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/debc4f3e7b3d7aa72763170660ec9382021935e675f3baa5e1a585b3c94fcd73/detection/", "output": "Missing command\r\n\r\nUsage:\r\n certoc -GetCACaps URL\r\n certoc -SCEP [-User] URL\r\n certoc -store [-User] StoreName [CertId]\r\n certoc -addstore [-User] StoreName file\r\n certoc -delstore [-User] StoreName CertId [SaveFile.sst]\r\n certoc -viewstore [-User] StoreName\r\n certoc -ImportPFX [-User] [-p password] StoreName file\r\n certoc -ExportPFX [-User] [-p password] StoreName CertId file\r\n certoc -ImportPFXToProvider [-User] [-p password] file [Provider [ContainerPrefix [ImportPFXFlags]]]\r\n certoc -Pulse {Pregen,PregenDelay,PregenOOBE,AIKEnroll}\r\n certoc -CredUI [-User] [-Modal] StoreName [CertId]\r\n certoc -LoadDll ModuleName\r\n certoc -AddTestEKCert\r\n certoc -EKCert\r\n\r\nThe parameter is incorrect. 0x80070057 (WIN32: 87 ERROR_INVALID_PARAMETER)\r\n", "runtime_modules": [ "C:\\Windows\\system32\\certoc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\ncrypt.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\NTASN1.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "certreq.exe-7D99C3B2EEF43CA0548FF13D2D4A1CE8": { "file_name": "certreq.exe", "file_path": "C:\\Windows\\system32\\certreq.exe", "hash_md5": "7D99C3B2EEF43CA0548FF13D2D4A1CE8", "hash_sha1": "4C0A33BBE4D2BA923689C40E7A05A6E6A171B72F", "hash_sha256": "4065FB5985ADBBC7EBAF8A366B231C92F951EEBF5C65B95483D7E6167788AEE6", "hash_sha384": "D1A0E946708FC1C6C5121050B72B6C2CDFA372CA79C630DE2D4000972BC30131A3636313003DFB637E31D9A92AD3DFEA", "hash_sha512": "6694737B5223DEE8A08C11B727FECE18DE51B99E1FD86EB616B85F2B0B04EB8CE12DDE49820213BB9A6AC396FEDAA272621A4AB6E33E0AC3A6428687BCC90171", "hash_ssdeep": "6144:M62AdniOoa+LXUHicxKwmiduCNsjFC0bQxJoKMncc5FtgTRjF/Q:L2KniOlKCxxEidxsjFLyyVnd5OzY", "hash_imp": "229AAC8C84DBF30E51CDA201437DC2C8", "hash_pesha1": "BA9B677EA1836C5860796011E558F91BE9F60121", "hash_pe256": "2A5FD90664A5C5CFF0128FE913E73321045DD40AC9522847F306B9A207913494", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CertReq.exe", "meta_original_filename": "CertReq.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/4065fb5985adbbc7ebaf8a366b231c92f951eebf5c65b95483d7e6167788aee6/detection/", "children": "conhost.exe", "output": "Usage:\r\r\n CertReq -?\r\r\n CertReq [-v] -?\r\r\n CertReq [-Command] -?\r\r\n\r\n CertReq [-Submit] [Options] [RequestFileIn [CertFileOut [CertChainFileOut [FullResponseFileOut]]]]\r\r\n Submit a request to a Certification Authority.\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -binary\r\r\n -PolicyServer PolicyServer\r\r\n -config ConfigString\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -crl\r\r\n -rpc\r\r\n -AdminForceMachine\r\r\n -RenewOnBehalfOf\r\r\n -NoChallenge\r\r\n\r\n CertReq -Retrieve [Options] RequestId [CertFileOut [CertChainFileOut [FullResponseFileOut]]]\r\r\n Retrieve a response to a previous request from a Certification Authority.\r\r\n\r\n Options:\r\r\n -binary\r\r\n -PolicyServer PolicyServer\r\r\n -config ConfigString\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -crl\r\r\n -rpc\r\r\n -AdminForceMachine\r\r\n\r\n CertReq -New [Options] [PolicyFileIn [RequestFileOut]]\r\r\n Create a new request as directed by PolicyFileIn\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -binary\r\r\n -cert CertId\r\r\n -PolicyServer PolicyServer\r\r\n -config ConfigString\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -pin Pin\r\r\n -user\r\r\n -machine\r\r\n -xchg ExchangeCertFile\r\r\n\r\n CertReq -Accept [Options] [CertChainFileIn | FullResponseFileIn | CertFileIn]\r\r\n Accept and install a response to a previous new request.\r\r\n\r\n Options:\r\r\n -user \r\r\n -machine \r\r\n -pin Pin\r\r\n\r\n CertReq -Policy [Options] [RequestFileIn [PolicyFileIn [RequestFileOut [PKCS10FileOut]]]]\r\r\n Construct a cross certification or qualified subordination request\r\r\n from an existing CA certificate or from an existing request.\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -binary\r\r\n -cert CertId\r\r\n -PolicyServer PolicyServer\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -pin Pin\r\r\n -noEKU\r\r\n -AlternateSignatureAlgorithm\r\r\n -HashAlgorithm HashAlgorithm\r\r\n\r\n CertReq -Sign [Options] [RequestFileIn [RequestFileOut]]\r\r\n Sign a certificate request with an enrollment agent or qualified\r\r\n subordination signing certificate.\r\r\n\r\n Options:\r\r\n -binary\r\r\n -cert CertId\r\r\n -PolicyServer PolicyServer\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -pin Pin\r\r\n -crl\r\r\n -noEKU\r\r\n -HashAlgorithm HashAlgorithm\r\r\n\r\n CertReq -Enroll [Options] TemplateName\r\r\n CertReq -Enroll -cert CertId [Options] Renew [ReuseKeys]\r\r\n Enroll for or renew a certificate.\r\r\n\r\n Options:\r\r\n -PolicyServer PolicyServer\r\r\n -user \r\r\n -machine \r\r\n -pin Pin\r\r\n\r\n CertReq -EnrollAIK [Options] [KeyContainerName]\r\r\n Enroll for AIK certificate.\r\r\n\r\n Options:\r\r\n -config\r\r\n\r\n CertReq -EnrollCredGuardCert [Options] TemplateName [ExtensionInfFile]\r\r\n Enroll for machine account Credential Guard certificate.\r\r\n\r\n Options:\r\r\n -config\r\r\n\r\n CertReq -EnrollLogon [Options]\r\r\n Enroll for Hello for Business Logon certificate via ADFS.\r\r\n\r\n Options:\r\r\n -q\r\r\n\r\n CertReq -Post [Options]\r\r\n POST an http request.\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -config URL\r\r\n\r\nUnknown argument: --help\r\n", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\certreq.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\certreq.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\Normaliz.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\certcli.dll", "C:\\Windows\\system32\\ncrypt.dll", "C:\\Windows\\system32\\Secur32.dll", "C:\\Windows\\system32\\WININET.dll", "C:\\Windows\\system32\\certca.dll", "C:\\Windows\\system32\\NTASN1.dll", "C:\\Windows\\system32\\SSPICLI.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ], "runtime_window_title": "Certificate Request Processor" }, "certutil.exe-535CF1F8E8CF3382AB8F62013F967DD8": { "file_name": "certutil.exe", "file_path": "C:\\Windows\\system32\\certutil.exe", "hash_md5": "535CF1F8E8CF3382AB8F62013F967DD8", "hash_sha1": "459D928381CDDFDC31D03C3DA5C28E63B1190194", "hash_sha256": "85DD6F8EDF142F53746A51D11DCBA853104BB0207CDF2D6C3529917C3C0FC8DF", "hash_sha384": "6C0D362F4433F3541BBB8D1ACD314C4EDE33A568C99790694E04C5314311E6C6E522657357529764AE77BC8AD312434B", "hash_sha512": "1305A38AB25316BE740A4ACB343FFBE80D314370B95B31168D357C226C872ED79E179EC1B5D646FDC8B625F1B6D4A0D223B8A40E63B939583C56E28DDC43E4DD", "hash_ssdeep": "24576:P297/FD95VXqMybmsTDOSChclVDV3NhK+sytIuZSrsRBdUf3s7KD1gOn/Y2:P47/x9/ByyAfVD3syzjRrUfs7KxI2", "hash_imp": "683B8A445B00A271FC57848D893BD6C4", "hash_pesha1": "D0DCC9DDD0223E986291A59EBBDC59C8D52D7393", "hash_pe256": "15B6EFA463D84060ECA08D543E2EEED2602E0DA295B9E6EADAD53DFB5FA1CD66", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CertUtil.exe", "meta_original_filename": "CertUtil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/85dd6f8edf142f53746a51d11dcba853104bb0207cdf2d6c3529917c3c0fc8df/detection/", "output": "\r\nVerbs:\r\n -dump -- Dump configuration information or file\r\n -dumpPFX -- Dump PFX structure\r\n -asn -- Parse ASN.1 file\r\n\r\n -decodehex -- Decode hexadecimal-encoded file\r\n -decode -- Decode Base64-encoded file\r\n -encode -- Encode file to Base64\r\n\r\n -deny -- Deny pending request\r\n -resubmit -- Resubmit pending request\r\n -setattributes -- Set attributes for pending request\r\n -setextension -- Set extension for pending request\r\n -revoke -- Revoke Certificate\r\n -isvalid -- Display current certificate disposition\r\n\r\n -getconfig -- Get default configuration string\r\n -ping -- Ping Active Directory Certificate Services Request interface\r\n -pingadmin -- Ping Active Directory Certificate Services Admin interface\r\n -CAInfo -- Display CA Information\r\n -ca.cert -- Retrieve the CA's certificate\r\n -ca.chain -- Retrieve the CA's certificate chain\r\n -GetCRL -- Get CRL\r\n -CRL -- Publish new CRLs [or delta CRLs only]\r\n -shutdown -- Shutdown Active Directory Certificate Services\r\n\r\n -installCert -- Install Certification Authority certificate\r\n -renewCert -- Renew Certification Authority certificate\r\n\r\n -schema -- Dump Certificate Schema\r\n -view -- Dump Certificate View\r\n -db -- Dump Raw Database\r\n -deleterow -- Delete server database row\r\n\r\n -backup -- Backup Active Directory Certificate Services\r\n -backupDB -- Backup Active Directory Certificate Services database\r\n -backupKey -- Backup Active Directory Certificate Services certificate and private key\r\n -restore -- Restore Active Directory Certificate Services\r\n -restoreDB -- Restore Active Directory Certificate Services database\r\n -restoreKey -- Restore Active Directory Certificate Services certificate and private key\r\n -importPFX -- Import certificate and private key\r\n -dynamicfilelist -- Display dynamic file List\r\n -databaselocations -- Display database locations\r\n -hashfile -- Generate and display cryptographic hash over a file\r\n\r\n -store -- Dump certificate store\r\n -enumstore -- Enumerate certificate stores\r\n -addstore -- Add certificate to store\r\n -delstore -- Delete certificate from store\r\n -verifystore -- Verify certificate in store\r\n -repairstore -- Repair key association or update certificate properties or key security descriptor\r\n -viewstore -- Dump certificate store\r\n -viewdelstore -- Delete certificate from store\r\n -UI -- invoke CryptUI\r\n -attest -- Verify Key Attestation Request\r\n\r\n -dsPublish -- Publish certificate or CRL to Active Directory\r\n\r\n -ADTemplate -- Display AD templates\r\n -Template -- Display Enrollment Policy templates\r\n -TemplateCAs -- Display CAs for template\r\n -CATemplates -- Display templates for CA\r\n -SetCASites -- Manage Site Names for CAs\r\n -enrollmentServerURL -- Display, add or delete enrollment server URLs associated with a CA\r\n -ADCA -- Display AD CAs\r\n -CA -- Display Enrollment Policy CAs\r\n -Policy -- Display Enrollment Policy\r\n -PolicyCache -- Display or delete Enrollment Policy Cache entries\r\n -CredStore -- Display, add or delete Credential Store entries\r\n -InstallDefaultTemplates -- Install default certificate templates\r\n -URLCache -- Display or delete URL cache entries\r\n -pulse -- Pulse autoenrollment event or NGC task\r\n -MachineInfo -- Display Active Directory machine object information\r\n -DCInfo -- Display domain controller information\r\n -EntInfo -- Display enterprise information\r\n -TCAInfo -- Display CA information\r\n -SCInfo -- Display smart card information\r\n\r\n -SCRoots -- Manage smart card root certificates\r\n\r\n -verifykeys -- Verify public/private key set\r\n -verify -- Verify certificate, CRL or chain\r\n -verifyCTL -- Verify AuthRoot or Disallowed Certificates CTL\r\n -syncWithWU -- Sync with Windows Update\r\n -generateSSTFromWU -- Generate SST from Windows Update\r\n -generatePinRulesCTL -- Generate Pin Rules CTL\r\n -downloadOcsp -- Download OCSP Responses and Write to Directory\r\n -generateHpkpHeader -- Generate HPKP header using certificates in specified file or directory\r\n -flushCache -- Flush specified caches in selected process, such as, lsass.exe\r\n -addEccCurve -- Add ECC Curve\r\n -deleteEccCurve -- Delete ECC Curve\r\n -displayEccCurve -- Display ECC Curve\r\n -sign -- Re-sign CRL or certificate\r\n\r\n -vroot -- Create/delete web virtual roots and file shares\r\n -vocsproot -- Create/delete web virtual roots for OCSP web proxy\r\n -addEnrollmentServer -- Add an Enrollment Server application\r\n -deleteEnrollmentServer -- Delete an Enrollment Server application\r\n -addPolicyServer -- Add a Policy Server application\r\n -deletePolicyServer -- Delete a Policy Server application\r\n -oid -- Display ObjectId or set display name\r\n -error -- Display error code message text\r\n -getreg -- Display registry value\r\n -setreg -- Set registry value\r\n -delreg -- Delete registry value\r\n\r\n -ImportKMS -- Import user keys and certificates into server database for key archival\r\n -ImportCert -- Import a certificate file into the database\r\n -GetKey -- Retrieve archived private key recovery blob, generate a recovery script,\r\n or recover archived keys\r\n -RecoverKey -- Recover archived private key\r\n -MergePFX -- Merge PFX files\r\n -ConvertEPF -- Convert PFX files to EPF file\r\n\r\n -add-chain -- (-AddChain) Add certificate chain\r\n -add-pre-chain -- (-AddPrechain) Add pre-certificate chain\r\n -get-sth -- (-GetSTH) Get signed tree head\r\n -get-sth-consistency -- (-GetSTHConsistency) Get signed tree head changes\r\n -get-proof-by-hash -- (-GetProofByHash) Get proof by hash\r\n -get-entries -- (-GetEntries) Get entries\r\n -get-roots -- (-GetRoots) Get roots\r\n -get-entry-and-proof -- (-GetEntryAndProof) Get entry and proof\r\n -VerifyCT -- Verify certificate SCT\r\n -? -- Display this usage message\r\n\r\n\r\nCertUtil -? -- Display a verb list (command list)\r\nCertUtil -dump -? -- Display help text for the \"dump\" verb\r\nCertUtil -v -? -- Display all help text for all verbs\r\n\r\nCertUtil: -? command completed successfully.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\certutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\Normaliz.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\certcli.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326\\COMCTL32.dll", "C:\\Windows\\system32\\ncrypt.dll", "C:\\Windows\\system32\\NETAPI32.dll" ] }, "change.exe-5171C542F9F07AE7D7068ED8FE0FADE0": { "file_name": "change.exe", "file_path": "C:\\Windows\\system32\\change.exe", "hash_md5": "5171C542F9F07AE7D7068ED8FE0FADE0", "hash_sha1": "85CA914A1441EF2F5209D06A02B8A501B9C83AF6", "hash_sha256": "17CAC86C16CF40741B5E0FD87FF02830694E1DA2715F75E18231867B79E6DF45", "hash_sha384": "240A4315D6514A4743C1D7152FCC62EA812E5F2E6D8958170525C91D2152C06086BF83B73EA76DC2E8B77411D3BE5244", "hash_sha512": "7749EEAFCB3C39291E500B87BA2156BA351941C4F2EFB39A83648F3604A8A5047812D4E4C175726AE67C01BB08F9633F4114860912450C9C3558AFCC06253CD0", "hash_ssdeep": "384:PyyvwEHdWH1ZMqxdBeEh+9JnXfGHK2aanWZLW:ayv5SVBA9Jn4vG", "hash_imp": "CCC9DA4A55E90DFE34CBCDB066D6A6B3", "hash_pesha1": "A56F8D983210C7835754E0DA8F4CBE23C7067FFD", "hash_pe256": "F50897D1F83802F46B34CCDB73D2448D853D0D40A7DBEA983ED1DA5C4795EFC9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Services Change Utility", "meta_original_filename": "change.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/17cac86c16cf40741b5e0fd87ff02830694e1da2715f75e18231867b79e6df45/detection/", "output": "CHANGE { LOGON | PORT | USER }\r\n", "error": "Invalid parameter(s)\r\nCHANGE { LOGON | PORT | USER }\r\n" }, "changepk.exe-712C2F1E1A8AC13E7DB69B2253294484": { "file_name": "changepk.exe", "file_path": "C:\\Windows\\system32\\changepk.exe", "hash_md5": "712C2F1E1A8AC13E7DB69B2253294484", "hash_sha1": "38F033D14EFD15DCBA2387656B3099141B6E8261", "hash_sha256": "0D07EC1EB0FF9DCABE175C93E5F354484FF2BA1FF5ACCE13ED3872A31E7FE22A", "hash_sha384": "DE9EA2E08B211EB54A956F8D498D7CAE70AF1C6BDF4909B58E70A551DE2B29F1EFCA0B611D74BF80020FFBF4192D4EC3", "hash_sha512": "8D24B801147E4E159158C0F1E0FF1F716784E1957800734DB906E417EFCB5969134D430964305F392B389312704370405432962FC4CE822359209E5EB6D32FDD", "hash_ssdeep": "1536:0NQZep+vv1Tj9aZ1q5TOvzj07j5Uff3vpP:Pv1Tj9aZ18yK5Uff3B", "hash_imp": "EE22AD7AC89E2E7EACBAF51750A69C27", "hash_pesha1": "F0CAEC0354BF8A916B7E9701BCF74E844ACFCEC3", "hash_pe256": "4AC715DF233ACEE5965DF6B31E8750D8B7204A8B93A1A08207F85196F9C0DEA3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Activation", "meta_original_filename": "changepk.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/0d07ec1eb0ff9dcabe175c93e5f354484ff2ba1ff5acce13ed3872a31e7fe22a/detection/", "runtime_modules": [ "C:\\Windows\\system32\\changepk.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "charmap.exe-AD1FC94B3D6E12283B0E1AF32F53005D": { "file_name": "charmap.exe", "file_path": "C:\\Windows\\system32\\charmap.exe", "hash_md5": "AD1FC94B3D6E12283B0E1AF32F53005D", "hash_sha1": "71694AACEAB550FABC716AAA5F3948A8EE8BCB9B", "hash_sha256": "62E3F767F4867A067BA102970EE7CE4B925F22C35F064EC764A5A67CE163F3A1", "hash_sha384": "40F4A5CFA95A3CB6525722BB242F5F4BA042F86F84E4E02CB7D061676E749F1D7983DD957B30A8F14F1103A69DDB9604", "hash_sha512": "669A8F0E0CC529077F8E31C690E47059794CEFDA684479D5266C5F354366BE3C6CCE8A0EE00DB358A08C6D5DD7F47D2699DF0D4440A2763BB9DF110A4F6DCBED", "hash_ssdeep": "3072:JXzxkkfJoAkYFFSxo2wqTIseSPBAce8brLF5NUdrSO9K/tagbdDu5nB:JzJTjixhTrQrEbgqt5g", "hash_imp": "D3B5ECC092C10C57527B9F07A9254FD9", "hash_pesha1": "2CAE2F49D1D189FE040916050BE5CACADF728047", "hash_pe256": "83279D10201CDF4CA35AF8EFD6E84BB393D8778BF9D8ACA00B89313C3D560B74", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Character Map", "meta_original_filename": "charmap.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/62e3f767f4867a067ba102970ee7ce4b925f22c35f064ec764a5a67ce163f3a1/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\charmap.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme966197582": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\RPC Control\\DSEC115C": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\115cHWNDInterface:1402f6": "Section", "(R--) C:\\Windows\\System32\\bopomofo.uce": "File", "(R--) C:\\Windows\\System32\\gb2312.uce": "File", "(R--) C:\\Windows\\System32\\ideograf.uce": "File", "(R--) C:\\Windows\\System32\\kanji_1.uce": "File", "(R--) C:\\Windows\\System32\\kanji_2.uce": "File", "(R--) C:\\Windows\\System32\\korean.uce": "File", "(R--) C:\\Windows\\System32\\ShiftJIS.uce": "File", "(R--) C:\\Windows\\System32\\SubRange.uce": "File", "(R-D) C:\\Windows\\System32\\en-US\\getuname.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\charmap.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\GetUName.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll" ], "runtime_window_title": "Character Map" }, "CheckNetIsolation.exe-D10C9B005F33BF144A26A18EF0D73213": { "file_name": "CheckNetIsolation.exe", "file_path": "C:\\Windows\\system32\\CheckNetIsolation.exe", "hash_md5": "D10C9B005F33BF144A26A18EF0D73213", "hash_sha1": "77A2D770C1CA10A1E01DB8E83D067A729E22E90C", "hash_sha256": "67BC058C8EA0B7FD21C412EFC0D2EECC4AFB67CF5BDC5981A8212E1AF8FDF49E", "hash_sha384": "EF6E88DA7131B3A32C6529D07490318FDB9327CA0B498DA1680139D31CF7E97325A6EB7FAB54605DAC968F8C9D6CF9EC", "hash_sha512": "C152DF850C66D9018F8310E44FA989145317E80374BB33EC9A008D96F9931A2EB9CE3FF502B54CCA0E3C2D381739BB316C30FE84630BEC7BF2DB7DB3C2209E75", "hash_ssdeep": "384:JumhBXqAPA+fPt1NTSNq5XbdnGWEBFg1tf1qaaUeQVtdtNtqObOW77pOWM:PhB6A4+t1PmHBFg1ia4QJ3tLbr7p8", "hash_imp": "E437A3A0162600CE23B282A0DFA53D7B", "hash_pesha1": "A5E2F0EA13CB065B5E606D5A98EF419C387C2C18", "hash_pe256": "F47E743125963798BAED006E408DFA6862993905BC04A84AE3738EDE1F46B7E0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AppContainer Network Isolation Diagnostic Tool", "meta_original_filename": "CheckNetIsolation.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/67bc058c8ea0b7fd21c412efc0d2eecc4afb67cf5bdc5981a8212e1af8fdf49e/detection/", "output": "Error: Invalid Parameters\r\n\r\nUsage:\r\n CheckNetIsolation [Module]\r\n List Of Modules: \r\n LoopbackExempt - controls the loopback exemption of AppContainers\r\n and Package Families to ease application\r\n development.\r\n Debug - Starts a network traffic troubleshooting session\r\n of an AppContainer or Package Family. Generates a\r\n report of network capabilities that are used, not\r\n used or missing, together with the network traffic\r\n generated by the application.\r\n -? - Displays this help message.\r\n \r\n", "runtime_modules": [ "C:\\Windows\\system32\\CheckNetIsolation.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "chglogon.exe-043CC77ED997F7E4BD153030A18304DC": { "file_name": "chglogon.exe", "file_path": "C:\\Windows\\system32\\chglogon.exe", "hash_md5": "043CC77ED997F7E4BD153030A18304DC", "hash_sha1": "A2F0F37CA9072E048C8CE9FE8E9F09F37C5E1EC4", "hash_sha256": "C91F6B286B59AE125BC039512FF9801354C10E74DCA9CD803067D2CD1441592F", "hash_sha384": "A738E63FFEC8E070BFA1868266B1B7A48C692080128B17845EBF8BA633365B5DA5F1028210BA4B53B6C0ABCD1E7122DF", "hash_sha512": "62188CA77C4220B4C5CBFC3E6524463A592C20182EAC3898976255E407C3D2FA3EAB60A658DC3F22C2A1C87FCA9A96011AC118FE9CADED7EF04B9EB8BCD3660A", "hash_ssdeep": "384:BHKiqXNzrO3TVneuEvz5+Yc1K8OSGHnhNAmd2P45HCMHtC4qCW9EW:Bq7FrOj9edg91K8E0rAEjp", "hash_imp": "39CDC867B4449192C880F526495B2B10", "hash_pesha1": "0B20715E2F46DE6D9F89FD6846C878C113209A9B", "hash_pe256": "698D6317016FDE34AB9E6244E903B523E04A78E29F0B6F1B45AB8EA0F1F52C09", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Logon Utility", "meta_original_filename": "chglogon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c91f6b286b59ae125bc039512ff9801354c10e74dca9cd803067d2cd1441592f/detection/", "error": "Invalid parameter(s)\r\nEnable, disable, or drain session logins.\r\n\r\nCHANGE LOGON {/QUERY | /ENABLE | /DISABLE | /DRAIN | /DRAINUNTILRESTART}\r\n\r\n /QUERY Query current session login mode.\r\n /ENABLE Enable user login from sessions.\r\n /DISABLE Disable user login from sessions.\r\n /DRAIN Disable new user logons, but allow reconnections to existing sessions.\r\n /DRAINUNTILRESTART Disable new user logons until the server is restarted, but allow reconnections to existing sessions.\r\n" }, "chgport.exe-7FF1E566408BB6AA60401DFB0A8CCAB9": { "file_name": "chgport.exe", "file_path": "C:\\Windows\\system32\\chgport.exe", "hash_md5": "7FF1E566408BB6AA60401DFB0A8CCAB9", "hash_sha1": "21DD46155DE91B6196F0ADD2BB90BACF6DD51891", "hash_sha256": "92E224A1E945B43143D74D1396B391C0FE9E123FD075C8FF368A7800B1FCD985", "hash_sha384": "1FDAB386A5DF32A08FC4C084775BE4943A68FABB598700AED55320A2DB255EC98489CE650E2E9BFD16CC2AF98CBBFD14", "hash_sha512": "3FA30CE26D3FBD2BF97EFD27D5A4953A90FBE8CEE455314F53F011B139612837080F527D0133EE4179E09692EACBBF210D24E746836033D0A88291C089D13859", "hash_ssdeep": "768:9r+otF1NLLreAtASiVnK8NV+HMAjMujy:cYPr8SykHjXy", "hash_imp": "F3A2024F3062FC17B3AAB1815BE21C38", "hash_pesha1": "13C5775D6527802CF2E80FF226102B7309777C11", "hash_pe256": "08EFDF87E8B14C2F748983D1177DB090B021784D30F9468C7AE34E2C78B32A12", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change port Utility", "meta_original_filename": "chgport.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/92e224a1e945b43143d74d1396b391c0fe9e123fd075c8ff368a7800b1fcd985/detection/", "runtime_modules": [ "C:\\Windows\\system32\\chgport.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "error": "Invalid parameter(s)\r\nList or change COM port mappings for DOS application compatibility.\r\n\r\nCHANGE PORT [portx=porty | /D portx | /QUERY]\r\n\r\n portx=porty Map port x to port y.\r\n /D portx Delete mapping for port x.\r\n /QUERY Display current mapping ports.\r\n\r\n" }, "chgusr.exe-8DAF58E7E05F72467DE0FAFDED21BA1A": { "file_name": "chgusr.exe", "file_path": "C:\\Windows\\system32\\chgusr.exe", "hash_md5": "8DAF58E7E05F72467DE0FAFDED21BA1A", "hash_sha1": "4FDAD69A0DEAAA7E223E9329F7C6BEBA5E5F6721", "hash_sha256": "4DA3797B3AAB0BDC53A2B923C43A84E16269C4683A556FAE0F491B827BAEE1C8", "hash_sha384": "B8FF53262730CC2E1E0A8695FDC00056E1275FADE3A281FB6ABA9A73C3B24A3DFDCF7ABB11B98A9287E4A0828AC9238F", "hash_sha512": "6A175AED80E18AD9F847F0D3E9D8A956B1CEC273521A0AE6408FBD8567F6AD1D6EFB98A545022BE599372B495458FCEF45D83F1F73E6E9292BFCBC1026D70E33", "hash_ssdeep": "384:GX2Y08rYQ/8x7nVmEoz5XukK8vW5kLS43eYH2TwHKXTSWoVW:W08rYQ/G7n8AkK8u5klJIT8", "hash_imp": "EA17270B67FAE16B05714FD14BE68EA3", "hash_pesha1": "22C334C65F3530A56A47CA1D779A97EA4CF411FC", "hash_pe256": "A085DAC2EC0B104F49BE9186C95DC2C7BB75DC4C632AFDA63E3D03A64663EF10", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change INI File Mapping Utility", "meta_original_filename": "chgusr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/4da3797b3aab0bdc53a2b923c43a84e16269c4683a556fae0f491b827baee1c8/detection/", "output": "Change Install Mode.\r\n\r\nCHANGE USER {/EXECUTE | /INSTALL | /QUERY}\r\n\r\n /EXECUTE Enable execute mode (default).\r\n /INSTALL Enable install mode.\r\n /QUERY Display current settings.\r\n\r\n", "error": "Invalid parameter(s)\r\nChange Install Mode.\r\n\r\nCHANGE USER {/EXECUTE | /INSTALL | /QUERY}\r\n\r\n /EXECUTE Enable execute mode (default).\r\n /INSTALL Enable install mode.\r\n /QUERY Display current settings.\r\n\r\n", "children": [ "csrss.exe", "wininit.exe" ], "runtime_modules": [ "C:\\Windows\\system32\\chgusr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "chkdsk.exe-76875ED530A6E245E6202C31B50898CB": { "file_name": "chkdsk.exe", "file_path": "C:\\Windows\\system32\\chkdsk.exe", "hash_md5": "76875ED530A6E245E6202C31B50898CB", "hash_sha1": "16B6AA45DBA190FC7748AF33BD37466637076695", "hash_sha256": "813C050393486B336E9E3F11742F600F2EB118656881F99D32463BAEDB512DBA", "hash_sha384": "1673E42B819F168F9DAB798417FE3E9A82C38E6C72585F005DAB15681CCB1BBFFBB270294A0010AB71BA939063D84069", "hash_sha512": "63C8FBC590CFA60D7C8A2410F8AAD8B1BAF5DE98D0391B2CDBE9D69149FD87347B641B5570FC6686620C082DB5E1104D574C0BB7321527C520F2BAF81460D7E5", "hash_ssdeep": "384:X68TBguhg73tiss79hI7x0+8OQMC483yGRlp9wi0RSnGNyWSFFhW:X68lZEtijIFiOaF39Hp9P0cGaF", "hash_imp": "4179F4D327A59B2C4B4F624BAC5C4090", "hash_pesha1": "0BD186926860664D9591E6FE0278B53244A21DCE", "hash_pe256": "2B468257660F669AA67BD0AC5E003E60CE42492D4591A6FA9A2FD8E4A2C24D72", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Check Disk Utility", "meta_original_filename": "CHKDSK.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/813c050393486b336e9e3f11742f600f2eb118656881f99d32463baedb512dba/detection/", "output": "Checks a disk and displays a status report.\r\n\r\n\r\nCHKDSK [volume[[path]filename]]] [/F] [/V] [/R] [/X] [/I] [/C] [/L[:size]] [/B] [/scan] [/spotfix]\r\n\r\n\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name.\r\n filename FAT/FAT32 only: Specifies the files to check for\r\n fragmentation.\r\n /F Fixes errors on the disk.\r\n /V On FAT/FAT32: Displays the full path and name of every\r\n file on the disk.\r\n On NTFS: Displays cleanup messages if any.\r\n /R Locates bad sectors and recovers readable information\r\n (implies /F, when /scan not specified).\r\n /L:size NTFS only: Changes the log file size to the specified\r\n number of kilobytes. If size is not specified, displays\r\n current size.\r\n /X Forces the volume to dismount first if necessary.\r\n All opened handles to the volume would then be invalid\r\n (implies /F).\r\n /I NTFS only: Performs a less vigorous check of index\r\n entries.\r\n /C NTFS only: Skips checking of cycles within the folder\r\n structure.\r\n /B NTFS only: Re-evaluates bad clusters on the volume\r\n (implies /R)\r\n /scan NTFS only: Runs an online scan on the volume\r\n /forceofflinefix NTFS only: (Must be used with \"/scan\")\r\n Bypass all online repair; all defects found\r\n are queued for offline repair (i.e. \"chkdsk /spotfix\").\r\n /perf NTFS only: (Must be used with \"/scan\")\r\n Uses more system resources to complete a scan as fast as\r\n possible. This may have a negative performance impact on\r\n other tasks running on the system.\r\n /spotfix NTFS only: Runs spot fixing on the volume\r\n /sdcleanup NTFS only: Garbage collect unneeded security descriptor\r\n data (implies /F).\r\n /offlinescanandfix Runs an offline scan and fix on the volume.\r\n /freeorphanedchains FAT/FAT32/exFAT only: Frees any orphaned cluster chains\r\n instead of recovering their contents.\r\n /markclean FAT/FAT32/exFAT only: Marks the volume clean if no\r\n corruption was detected, even if /F was not specified.\r\n\r\nThe /I or /C switch reduces the amount of time required to run Chkdsk by\r\nskipping certain checks of the volume.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\chkdsk.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\ulib.dll", "C:\\Windows\\system32\\IfsUtil.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\SYSTEM32\\fsutilext.dll" ] }, "chkntfs.exe-B8FDF02067F9B4091B2EB66F1940E9F7": { "file_name": "chkntfs.exe", "file_path": "C:\\Windows\\system32\\chkntfs.exe", "hash_md5": "B8FDF02067F9B4091B2EB66F1940E9F7", "hash_sha1": "C8940225E194E3D58B2679C737DB0D167A0A09C0", "hash_sha256": "1F8A47270E85216DA798516FB59C6C81F0DAA33F3FCC2EFC8DC88C5EF40FB360", "hash_sha384": "334A18C8FEAB6846F92F360A04BE2C7BCD02E9FBCB1AC28FBC5010CD72DCC560A797EA967BDA72D92D19FE9447A12248", "hash_sha512": "BFA4C595D29CEA4A0D871195D1F67FA1DF5ED04C9B5B203F9D910C5787961FE6E5E7CC2A04B6DF965F80986EC19AFA22483BCE6D579DA74B3CA407326F8C0E87", "hash_ssdeep": "384:RyAa2zX85M8KULdBXHRgb9I1mNBXFX7gTVEzNMWd6W:ra2TCpDXHCbBNVFMU9", "hash_imp": "D41BF2F313E9EE8CBB20EF9AD2025250", "hash_pesha1": "278EC289471FD2FEFC20AE3D136F095ACE3E047D", "hash_pe256": "76FE10A021923CC2BB79BD1764B3AE5E1903F6FAF0A289303DA11427B09F36A3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NTFS Volume Maintenance Utility", "meta_original_filename": "CHKNTFS.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/1f8a47270e85216da798516fb59c6c81f0daa33f3fcc2efc8dc88c5ef40fb360/detection/", "output": "Displays or modifies the checking of disk at boot time.\r\n\r\nCHKNTFS volume [...]\r\nCHKNTFS /D\r\nCHKNTFS /T[:time]\r\nCHKNTFS /X volume [...]\r\nCHKNTFS /C volume [...]\r\n\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name.\r\n /D Restores the machine to the default behavior; all drives are\r\n checked at boot time and chkdsk is run on those that are\r\n dirty.\r\n /T:time Changes the AUTOCHK initiation countdown time to the\r\n specified amount of time in seconds. If time is not\r\n specified, displays the current setting.\r\n /X Excludes a drive from the default boot-time check. Excluded\r\n drives are not accumulated between command invocations.\r\n /C Schedules a drive to be checked at boot time; chkdsk will run\r\n if the drive is dirty.\r\n\r\nIf no switches are specified, CHKNTFS will display if the specified drive is\r\ndirty or scheduled to be checked on next reboot.\r\n" }, "choice.exe-463B5477FF96AB86A01BA49BCC02B539": { "file_name": "choice.exe", "file_path": "C:\\Windows\\system32\\choice.exe", "hash_md5": "463B5477FF96AB86A01BA49BCC02B539", "hash_sha1": "6CD4FDB9FA548883E32E5AA153E2569B84661190", "hash_sha256": "90F352C1FB7B21CC0216B2F0701A236DB92B786E4301904D28F4EC4CB81F2A0B", "hash_sha384": "99CDD79EFBB4F2ACF283DD5C300B86C2BCE45CAAF921B773AE06BFB268AA0D2FD3B996C969DCFA8D068A58FE3A16A81F", "hash_sha512": "2BFEEDF406E931A398F6939166ECB565C97F708436E637E12E2A306623859E2123987C2F7AB009721E60C08C9F18CD56DB75233E7E59AAD75AF715F90932EA30", "hash_ssdeep": "768:jypBm8ZjpDE42fyl13rBRxjpPN6biqU1vr/i191NfxzqpHk:0mGHRv16biqU1vr/k1lxGpHk", "hash_imp": "F181EBCAA9D1344F02A766BAC8E1CFAA", "hash_pesha1": "C78797AFDBCA18072C163C765B3565DC06F66EEF", "hash_pe256": "505D51B7ED91C22953741A6AC54DA41350147FFD822CF44CAFF82EFBF9193C06", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Offers the user a choice", "meta_original_filename": "choice.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/90f352c1fb7b21cc0216b2f0701a236db92b786e4301904d28f4ec4cb81f2a0b/detection/", "output": "\r\nCHOICE [/C choices] [/N] [/CS] [/T timeout /D choice] [/M text]\r\n\r\nDescription:\r\n This tool allows users to select one item from a list \r\n of choices and returns the index of the selected choice.\r\n\r\nParameter List:\r\n /C choices Specifies the list of choices to be created.\r\n Default list is \"YN\".\r\n\r\n /N Hides the list of choices in the prompt.\r\n The message before the prompt is displayed\r\n and the choices are still enabled.\r\n\r\n /CS Enables case-sensitive choices to be selected.\r\n By default, the utility is case-insensitive.\r\n\r\n /T timeout The number of seconds to pause before a default \r\n choice is made. Acceptable values are from 0 to \r\n 9999. If 0 is specified, there will be no pause \r\n and the default choice is selected.\r\n\r\n /D choice Specifies the default choice after nnnn seconds.\r\n Character must be in the set of choices specified\r\n by /C option and must also specify nnnn with /T.\r\n\r\n /M text Specifies the message to be displayed before \r\n the prompt. If not specified, the utility \r\n displays only a prompt.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE:\r\n The ERRORLEVEL environment variable is set to the index of the\r\n key that was selected from the set of choices. The first choice\r\n listed returns a value of 1, the second a value of 2, and so on.\r\n If the user presses a key that is not a valid choice, the tool \r\n sounds a warning beep. If tool detects an error condition,\r\n it returns an ERRORLEVEL value of 255. If the user presses \r\n CTRL+BREAK or CTRL+C, the tool returns an ERRORLEVEL value\r\n of 0. When you use ERRORLEVEL parameters in a batch program, list\r\n them in decreasing order.\r\n\r\nExamples:\r\n CHOICE /?\r\n CHOICE /C YNC /M \"Press Y for Yes, N for No or C for Cancel.\"\r\n CHOICE /T 10 /C ync /CS /D y \r\n CHOICE /C ab /M \"Select a for option 1 and b for option 2.\"\r\n CHOICE /C ab /N /M \"Select a for option 1 and b for option 2.\"\r\n", "runtime_modules": [ "C:\\Windows\\system32\\choice.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"CHOICE /?\" for usage.\r\n" }, "cipher.exe-1DE5A4875FEDBCBD57BFC0549476C52E": { "file_name": "cipher.exe", "file_path": "C:\\Windows\\system32\\cipher.exe", "hash_md5": "1DE5A4875FEDBCBD57BFC0549476C52E", "hash_sha1": "0E8E28F81A4BB5F972DCD02B0080D04D78A1574B", "hash_sha256": "1C7BAFE5742197741FC3724753C952C9AF890F8A6B2C61561C33CAABA8CF07CC", "hash_sha384": "6D788736A0671AEB80728465806799940159B1B65502BAF334298A3C95A5D77F55FDCDFC09BE586E16AC0F1D36AEDF6E", "hash_sha512": "AAD20EB9F8C1DB140875DFB81661C3F156659A94B4EEBABD308F5BDBFCE9E0AD21C7E203A742C29B31EEE70D4144027640111F5083F880D199825DB73D9F524E", "hash_ssdeep": "768:v0m+PdVMFMu28U3M4GqRhSE9XpweDLYnB7jgCQ5VNhoGueph/qyppnFwT:e/MauB5E9XpjDMnwQ+h/qyKT", "hash_imp": "E83B4C457AFD5EEA31874B00E8A3A956", "hash_pesha1": "644F479C66B092F14F7CF325D645F182D586A45F", "hash_pe256": "21C4CAD17CC8A0F48698FF250AD2BC5CEF684EFF131DCD807D3EB0FA07F27FA0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Encryption Utility", "meta_original_filename": "CIPHER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/1c7bafe5742197741fc3724753c952c9af890f8a6b2c61561c33caaba8cf07cc/detection/", "output": "Displays or alters the encryption of directories [files] on NTFS partitions.\r\n\r\n CIPHER [/E | /D | /C]\r\n [/S:directory] [/B] [/H] [pathname [...]]\r\n\r\n CIPHER /K [/ECC:256|384|521]\r\n\r\n CIPHER /R:filename [/SMARTCARD] [/ECC:256|384|521]\r\n\r\n CIPHER /P:filename.cer\r\n\r\n CIPHER /U [/N]\r\n\r\n CIPHER /W:directory\r\n\r\n CIPHER /X[:efsfile] [filename]\r\n\r\n CIPHER /Y\r\n\r\n CIPHER /ADDUSER [/CERTHASH:hash | /CERTFILE:filename | /USER:username]\r\n [/S:directory] [/B] [/H] [pathname [...]]\r\n\r\n CIPHER /FLUSHCACHE [/SERVER:servername]\r\n\r\n CIPHER /REMOVEUSER /CERTHASH:hash\r\n [/S:directory] [/B] [/H] [pathname [...]]\r\n\r\n CIPHER /REKEY [pathname [...]]\r\n\r\n /B Abort if an error is encountered. By default, CIPHER continues\r\n executing even if errors are encountered.\r\n /C Displays information on the encrypted file.\r\n /D Decrypts the specified files or directories.\r\n /E Encrypts the specified files or directories. Directories will be\r\n marked so that files added afterward will be encrypted. The\r\n encrypted file could become decrypted when it is modified if the\r\n parent directory is not encrypted. It is recommended that you\r\n encrypt the file and the parent directory.\r\n /H Displays files with the hidden or system attributes. These files\r\n are omitted by default.\r\n /K Creates a new certificate and key for use with EFS. If this\r\n option is chosen, all the other options will be ignored.\r\n\r\n Note: By default, /K creates a certificate and key that conform\r\n to current group policy. If ECC is specified, a self-signed\r\n certificate will be created with the supplied key size.\r\n\r\n /N This option only works with /U. This will prevent keys being\r\n updated. This is used to find all the encrypted files on the\r\n local drives.\r\n /R Generates an EFS recovery key and certificate, then writes them\r\n to a .PFX file (containing certificate and private key) and a\r\n .CER file (containing only the certificate). An administrator may\r\n add the contents of the .CER to the EFS recovery policy to create\r\n the recovery key for users, and import the .PFX to recover\r\n individual files. If SMARTCARD is specified, then writes the\r\n recovery key and certificate to a smart card. A .CER file is\r\n generated (containing only the certificate). No .PFX file is\r\n generated.\r\n\r\n Note: By default, /R creates an 2048-bit RSA recovery key and\r\n certificate. If ECC is specified, it must be followed by a\r\n key size of 256, 384, or 521.\r\n\r\n /P Creates a base64-encoded recovery-policy blob from the passed-in\r\n certificate. This blob can be used to set DRA policy for\r\n MDM deployments.\r\n /S Performs the specified operation on the given directory and all\r\n files and subdirectories within it.\r\n /U Tries to touch all the encrypted files on local drives. This will\r\n update user's file encryption key or recovery keys to the current\r\n ones if they are changed. This option does not work with other\r\n options except /N.\r\n /W Removes data from available unused disk space on the entire\r\n volume. If this option is chosen, all other options are ignored.\r\n The directory specified can be anywhere in a local volume. If it\r\n is a mount point or points to a directory in another volume, the\r\n data on that volume will be removed.\r\n /X Backup EFS certificate and keys into file filename. If efsfile is\r\n provided, the current user's certificate(s) used to encrypt the\r\n file will be backed up. Otherwise, the user's current EFS\r\n certificate and keys will be backed up.\r\n /Y Displays your current EFS certificate thumbprint on the local PC.\r\n /ADDUSER Adds a user to the specified encrypted file(s). If CERTHASH is\r\n provided, cipher will search for a certificate with this SHA1\r\n hash. If CERTFILE is provided, cipher will extract the\r\n certificate from the file. If USER is provided, cipher will\r\n try to locate the user's certificate in Active Directory Domain\r\n Services.\r\n /FLUSHCACHE\r\n Clears the calling user's EFS key cache on the specified server.\r\n If servername is not provided, cipher clears the user's key cache\r\n on the local machine.\r\n /REKEY Updates the specified encrypted file(s) to use the configured\r\n EFS current key.\r\n /REMOVEUSER\r\n Removes a user from the specified file(s). CERTHASH must be the\r\n SHA1 hash of the certificate to remove.\r\n\r\n directory A directory path.\r\n filename A filename without extensions.\r\n pathname Specifies a pattern, file or directory.\r\n efsfile An encrypted file path.\r\n\r\n Used without parameters, CIPHER displays the encryption state of the\r\n current directory and any files it contains. You may use multiple directory\r\n names and wildcards. You must put spaces between multiple parameters.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\cipher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "cleanmgr.exe-FC13869B5250959618FA81B9AAA2BDF8": { "file_name": "cleanmgr.exe", "file_path": "C:\\Windows\\system32\\cleanmgr.exe", "hash_md5": "FC13869B5250959618FA81B9AAA2BDF8", "hash_sha1": "A87D781671F3DA5C553D5AE3AC6CBA5EB0D1B442", "hash_sha256": "1BDAB94440132410D1AB623DED8F2427B34C233A063A150617AF271B9394025B", "hash_sha384": "9D8F1E958F8A6176BDF276029D62A9B06747EF9828027301833B99C46E8A972BAAEA5145483C82D0780021413CB44D42", "hash_sha512": "071A19BACF5311B9B09E2362CB3EFF2894CC790FAE5F450419B5C8750D650E035D991A188D1F679A6E8EBF430B90C1272807FA7136C6AFA1282C14484B810723", "hash_ssdeep": "3072:99eq+KCx3PwALkqnAEPGRvQhRkKqUa9antF5hvvJkuXpe:9NCBkqAE+ohSKq99UF5hvv/", "hash_imp": "7584FA8DCE2F762EE14571E18B3B4F97", "hash_pesha1": "71BF61A98FC78223B863F05BFC85681795B2CFDC", "hash_pe256": "D148806D01C36DC2EEF62DF3A087E3AFBC4644E7F0D9AFB1ECA964FF7C667E49", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Space Cleanup Manager for Windows", "meta_original_filename": "CLEANMGR.DLL.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/1bdab94440132410d1ab623ded8f2427b34c233a063a150617af271b9394025b/detection/", "children": "DismHost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\cleanmgr.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\cleanmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\VSSAPI.DLL", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\VssTrace.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll" ], "runtime_window_title": "USAGE" }, "cliconfg.exe-2F01F4A027E09027DBD2651FF3359DF9": { "file_name": "cliconfg.exe", "file_path": "C:\\Windows\\system32\\cliconfg.exe", "hash_md5": "2F01F4A027E09027DBD2651FF3359DF9", "hash_sha1": "DD2A6B32B9F2C746A504632A45D349740C8319A5", "hash_sha256": "890D486F00726E694BE483CDEEF17A22EAD2853D8D8C6D4BF1453D7CB44A6BCA", "hash_sha384": "D67A01687A619CB07B61C2221470DAD2359C3D6F72651DFE68128CE08580812C4F02E8292D9CC6DC0E067A9FD1BACCCF", "hash_sha512": "DE24B51CEDCF0CFBFC1A9ECAB0916E0F2358B63F17A19D8BC9AC6FF4F52B66D8C95696E0AC16207FABB79AEA9246BC79E081596FB0C96CC5F80CD63DFDD8D53B", "hash_ssdeep": "384:qbyf4ZRmiVJklCrxPQu8hWPwWsPXuNvBQAMYJQ2JQSkdowyo:qbyYRm4uLGKuI30lJBkvT", "hash_imp": "E0A4A433A88E43CFE20831B905227E5B", "hash_pesha1": "532459482EE00280C0436CB1D3EE317B0AC86AB6", "hash_pe256": "F90E0CD9BC67EABF33657ADBE6F8875347FEF74E4710904C3B843CAB61D841D2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SQL Client Configuration Utility EXE", "meta_original_filename": "cliconfg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/890d486f00726e694be483cdeef17a22ead2853d8d8c6d4bf1453d7cb44a6bca/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\cliconfg.rll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.17763.1518_en-us_831447e1869d6513": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.17763.1518_en-us_831447e1869d6513\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\cliconfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\cliconfg.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\SYSTEM32\\cliconfg.RLL" ], "runtime_window_title": "SQL Server Client Network Utility" }, "clip.exe-F56C16B8084DBCC7BF636312E217438C": { "file_name": "clip.exe", "file_path": "C:\\Windows\\system32\\clip.exe", "hash_md5": "F56C16B8084DBCC7BF636312E217438C", "hash_sha1": "77E807562692250DEB4A8D42AECC053B1670C84C", "hash_sha256": "79A0404570D2AE09CA66D7B68B3528679DA03337EC1C6BC59EC8105DF2417B1C", "hash_sha384": "0037851050ED43F0E4E4DE92266CF720DDFA9DC32CF99F0FEDAE7D48F0FF221842D7B93EC32E69C62349CFC1C2D8670A", "hash_sha512": "264A353AC5EB12A4C893728BFD53B908491E5EC99AD5669C52A8332BEFEE34824F5CE0D9BBC27FAD981E21FCA5235484D1DD269E80BB084562893B2A5EC294CE", "hash_ssdeep": "768:L3PWNWvDDqEst0ta03KiFVWTUgy/7d6efsdAxK0TZ:L36oyUjZ/7d6effx/T", "hash_imp": "D4F9D4B3E58F3C49F0B3042F0B20C802", "hash_pesha1": "EF05BF05E34C242678301D2120A3985AFB9057F6", "hash_pe256": "352116D5751778B3BF35E0840B8E6B1E87DDFC02B80ABF4826F632850A10AD3B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Clip - copies the data into clipboard", "meta_original_filename": "clip.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/79a0404570d2ae09ca66d7b68b3528679da03337ec1c6bc59ec8105df2417b1c/detection/", "output": "\r\nCLIP\r\n\r\nDescription:\r\n Redirects output of command line tools to the Windows clipboard.\r\n This text output can then be pasted into other programs.\r\n\r\nParameter List:\r\n /? Displays this help message.\r\n\r\nExamples:\r\n DIR | CLIP Places a copy of the current directory\r\n listing into the Windows clipboard.\r\n\r\n CLIP < README.TXT Places a copy of the text from readme.txt\r\n on to the Windows clipboard.\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"CLIP /?\" for usage.\r\n" }, "ClipUp.exe-0C4B3D8C6E8DF52A58A19D306A8F1712": { "file_name": "ClipUp.exe", "file_path": "C:\\Windows\\system32\\ClipUp.exe", "hash_md5": "0C4B3D8C6E8DF52A58A19D306A8F1712", "hash_sha1": "2FC6DD677C7F786977DC6C8F84911C02BBE74338", "hash_sha256": "36B6C08C86514A332CBDDE4B908AC0E045DD92309EF564DEBD3825CA55316CD2", "hash_sha384": "5EF24B9C3CAF38963C685475A6FB989EC2B4A60C09EA7040AED2E6AF68E9F4C332E0E43CE0001DA40A55AF67AFF533B3", "hash_sha512": "7FCD23BE4B02F36892A7A0BE6A6AC5D682CE4354B1C1FFF0E70046D7A371A0F56AAB67F08844B2BAD7FE91A6EB150CB5B939CDA0895BBA9A8D033F09B57A9E46", "hash_ssdeep": "24576:oUM9HgdVoa2Q/Bd7twtlbFRspx9+GJTZoXoqRp7zAR:oH6H/Bxmlb7sbrBO4qHE", "hash_imp": "9F99F14179075A92847CE4E8C8A1B987", "hash_pesha1": "6123891024F1E1375705B656168DB9B5CDB58BAA", "hash_pe256": "0806712BB551B3FB1AD9BB66E25CD183D587C56D44530E0BC818AC2B90A447E5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Client License Platform migration tool", "meta_original_filename": "ClipUp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1432 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1432", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/36b6c08c86514a332cbdde4b908ac0e045dd92309ef564debd3825ca55316cd2/detection/", "error": "Failed! Error 0x80070057.\r\n", "output": "Done.\r\nC:\\Windows\\system32\\ClipUp.exe Usage: \r\n-?/-h\tThis help menu\r\n-p \tAttempts to migrate data from the legacy Windows Phone database\r\n-o \tAttempts to migrate data from Windows Genuine Authorization blob\r\n-altto \t[path] Optional alternative Windows Genuine Authorization blob folder location\r\n-d \tGenerate a genuine ticket for the BIOS key\r\n-k \t[5X5 product key] Windows product key\r\n-pfm \t[package family name] Optional package family name to look for a migratable license\r\n-l \t[path] Optional folder of legacy Windows Store licenses\r\n-v \tEnables optional verbose logging\r\n-previd \tDevice ID prior to hardware-related changes\r\n[path]\tOptional alternative output location for migrated data\r\nDone.\r\n", "children": [ "csrss.exe", "winlogon.exe" ], "runtime_modules": [ "C:\\Windows\\system32\\ClipUp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\CRYPTXML.dll", "C:\\Windows\\system32\\ncrypt.dll", "C:\\Windows\\system32\\webservices.dll", "C:\\Windows\\system32\\NTASN1.dll" ] }, "CloudExperienceHostBroker.exe-79589A62B39A37B790E06DA52B2D1040": { "file_name": "CloudExperienceHostBroker.exe", "file_path": "C:\\Windows\\system32\\CloudExperienceHostBroker.exe", "hash_md5": "79589A62B39A37B790E06DA52B2D1040", "hash_sha1": "C78A70879A9A8824839C4F3724D1897749AEE82F", "hash_sha256": "FDFC37E84BD4FCC1132CB44E1B06DB8082DF4B9D5DAE395D8324EB64610FCAAA", "hash_sha384": "F4FEF0BC9BB760E38D05A21A3DD895F98DFAFDD25201A42C294B1DD79CB64D8D97ECA5010557E1EEB7C2A23D38204A5F", "hash_sha512": "92583EF18F6B75DA7954924437149432D8F451F80D51188A5798B5EDCA4973D66912AA3A8B5568BEBA25364C5B7A8065DDF823EBC4C65E6FFF452F4FF1321359", "hash_ssdeep": "1536:0P5QUcEVTorTj7qZph7L+Znm/zEnKu/B1PaD:0BQTjGZX+Zm/IKup1a", "hash_imp": "95BFAA5798555940E5EECA729EDE93CD", "hash_pesha1": "D12BD7D8CA78693F2305A19E96C8DF80B2C432C3", "hash_pe256": "70D5165FCB4E2B4C57EE82293D06429ACA86BCA9C31426F1B6E32B9B3203DA5F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CloudExperienceHost Broker", "meta_original_filename": "CloudExperienceHostBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1457 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1457", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/fdfc37e84bd4fcc1132cb44e1b06db8082df4b9d5dae395d8324eb64610fcaaa/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC734": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\CloudExperienceHostBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "cmd.exe-975B45B669930B0CC773EAF2B414206F": { "file_name": "cmd.exe", "file_path": "C:\\Windows\\system32\\cmd.exe", "hash_md5": "975B45B669930B0CC773EAF2B414206F", "hash_sha1": "8C5437CD76A89EC983E3B364E219944DA3DAB464", "hash_sha256": "3656F37A1C6951EC4496FABB8EE957D3A6E3C276D5A3785476B482C9C0D32EA2", "hash_sha384": "B2E8BB5140B7C76AD97CDE056F5CF3594E08630252431B366E11A5FAC77C6623C095821B474169B67EE9E69F5ACC79E1", "hash_sha512": "F08B7131BB3F5BB941C0445FC01B592AECFF6ADCB58E1803643073C44CF49BA11A5309B0DCF93C9CD91D60D2753DAFFA86CE4A882C74EB5C912CA0ADCCEB257D", "hash_ssdeep": "6144:xRekiTbWl/hVKhSuEAIKUa86F7iENfeLHl6OUtdSJm:u3TbA/hVCrIKUaNF7iEN2LHwP+J", "hash_imp": "272245E2988E1E430500B852C4FB5E18", "hash_pesha1": "B647000BC9250724925FB8ECCB839DFAB152E631", "hash_pe256": "5E630BE0CDC281C008F85A1772423DB21E5B8FFCF10337521589EFA0B4ADE6E2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Command Processor", "meta_original_filename": "Cmd.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/3656f37a1c6951ec4496fabb8ee957d3a6e3c276d5a3785476b482c9c0d32ea2/detection/", "output": "Starts a new instance of the Windows command interpreter\r\n\r\nCMD [/A | /U] [/Q] [/D] [/E:ON | /E:OFF] [/F:ON | /F:OFF] [/V:ON | /V:OFF]\r\n [[/S] [/C | /K] string]\r\n\r\n/C Carries out the command specified by string and then terminates\r\n/K Carries out the command specified by string but remains\r\n/S Modifies the treatment of string after /C or /K (see below)\r\n/Q Turns echo off\r\n/D Disable execution of AutoRun commands from registry (see below)\r\n/A Causes the output of internal commands to a pipe or file to be ANSI\r\n/U Causes the output of internal commands to a pipe or file to be\r\n Unicode\r\n/T:fg Sets the foreground/background colors (see COLOR /? for more info)\r\n/E:ON Enable command extensions (see below)\r\n/E:OFF Disable command extensions (see below)\r\n/F:ON Enable file and directory name completion characters (see below)\r\n/F:OFF Disable file and directory name completion characters (see below)\r\n/V:ON Enable delayed environment variable expansion using ! as the\r\n delimiter. For example, /V:ON would allow !var! to expand the\r\n variable var at execution time. The var syntax expands variables\r\n at input time, which is quite a different thing when inside of a FOR\r\n loop.\r\n/V:OFF Disable delayed environment expansion.\r\n\r\nNote that multiple commands separated by the command separator '&&'\r\nare accepted for string if surrounded by quotes. Also, for compatibility\r\nreasons, /X is the same as /E:ON, /Y is the same as /E:OFF and /R is the\r\nsame as /C. Any other switches are ignored.\r\n\r\nIf /C or /K is specified, then the remainder of the command line after\r\nthe switch is processed as a command line, where the following logic is\r\nused to process quote (\") characters:\r\n\r\n 1. If all of the following conditions are met, then quote characters\r\n on the command line are preserved:\r\n\r\n - no /S switch\r\n - exactly two quote characters\r\n - no special characters between the two quote characters,\r\n where special is one of: &<>()@^|\r\n - there are one or more whitespace characters between the\r\n two quote characters\r\n - the string between the two quote characters is the name\r\n of an executable file.\r\n\r\n 2. Otherwise, old behavior is to see if the first character is\r\n a quote character and if so, strip the leading character and\r\n remove the last quote character on the command line, preserving\r\n any text after the last quote character.\r\n\r\nIf /D was NOT specified on the command line, then when CMD.EXE starts, it\r\nlooks for the following REG_SZ/REG_EXPAND_SZ registry variables, and if\r\neither or both are present, they are executed first.\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\AutoRun\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\AutoRun\r\n\r\nCommand Extensions are enabled by default. You may also disable\r\nextensions for a particular invocation by using the /E:OFF switch. You\r\ncan enable or disable extensions for all invocations of CMD.EXE on a\r\nmachine and/or user logon session by setting either or both of the\r\nfollowing REG_DWORD values in the registry using REGEDIT.EXE:\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\EnableExtensions\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\EnableExtensions\r\n\r\nto either 0x1 or 0x0. The user specific setting takes precedence over\r\nthe machine setting. The command line switches take precedence over the\r\nregistry settings.\r\n\r\nIn a batch file, the SETLOCAL ENABLEEXTENSIONS or DISABLEEXTENSIONS arguments\r\ntakes precedence over the /E:ON or /E:OFF switch. See SETLOCAL /? for details.\r\n\r\nThe command extensions involve changes and/or additions to the following\r\ncommands:\r\n\r\n DEL or ERASE\r\n COLOR\r\n CD or CHDIR\r\n MD or MKDIR\r\n PROMPT\r\n PUSHD\r\n POPD\r\n SET\r\n SETLOCAL\r\n ENDLOCAL\r\n IF\r\n FOR\r\n CALL\r\n SHIFT\r\n GOTO\r\n START (also includes changes to external command invocation)\r\n ASSOC\r\n FTYPE\r\n\r\nTo get specific details, type commandname /? to view the specifics.\r\n\r\nDelayed environment variable expansion is NOT enabled by default. You\r\ncan enable or disable delayed environment variable expansion for a\r\nparticular invocation of CMD.EXE with the /V:ON or /V:OFF switch. You\r\ncan enable or disable delayed expansion for all invocations of CMD.EXE on a\r\nmachine and/or user logon session by setting either or both of the\r\nfollowing REG_DWORD values in the registry using REGEDIT.EXE:\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\DelayedExpansion\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DelayedExpansion\r\n\r\nto either 0x1 or 0x0. The user specific setting takes precedence over\r\nthe machine setting. The command line switches take precedence over the\r\nregistry settings.\r\n\r\nIn a batch file the SETLOCAL ENABLEDELAYEDEXPANSION or DISABLEDELAYEDEXPANSION\r\narguments takes precedence over the /V:ON or /V:OFF switch. See SETLOCAL /?\r\nfor details.\r\n\r\nIf delayed environment variable expansion is enabled, then the exclamation\r\ncharacter can be used to substitute the value of an environment variable\r\nat execution time.\r\n\r\nYou can enable or disable file name completion for a particular\r\ninvocation of CMD.EXE with the /F:ON or /F:OFF switch. You can enable\r\nor disable completion for all invocations of CMD.EXE on a machine and/or\r\nuser logon session by setting either or both of the following REG_DWORD\r\nvalues in the registry using REGEDIT.EXE:\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\CompletionChar\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\PathCompletionChar\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\CompletionChar\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\PathCompletionChar\r\n\r\nwith the hex value of a control character to use for a particular\r\nfunction (e.g. 0x4 is Ctrl-D and 0x6 is Ctrl-F). The user specific\r\nsettings take precedence over the machine settings. The command line\r\nswitches take precedence over the registry settings.\r\n\r\nIf completion is enabled with the /F:ON switch, the two control\r\ncharacters used are Ctrl-D for directory name completion and Ctrl-F for\r\nfile name completion. To disable a particular completion character in\r\nthe registry, use the value for space (0x20) as it is not a valid\r\ncontrol character.\r\n\r\nCompletion is invoked when you type either of the two control\r\ncharacters. The completion function takes the path string to the left\r\nof the cursor appends a wild card character to it if none is already\r\npresent and builds up a list of paths that match. It then displays the\r\nfirst matching path. If no paths match, it just beeps and leaves the\r\ndisplay alone. Thereafter, repeated pressing of the same control\r\ncharacter will cycle through the list of matching paths. Pressing the\r\nShift key with the control character will move through the list\r\nbackwards. If you edit the line in any way and press the control\r\ncharacter again, the saved list of matching paths is discarded and a new\r\none generated. The same occurs if you switch between file and directory\r\nname completion. The only difference between the two control characters\r\nis the file completion character matches both file and directory names,\r\nwhile the directory completion character only matches directory names.\r\nIf file completion is used on any of the built in directory commands\r\n(CD, MD or RD) then directory completion is assumed.\r\n\r\nThe completion code deals correctly with file names that contain spaces\r\nor other special characters by placing quotes around the matching path.\r\nAlso, if you back up, then invoke completion from within a line, the\r\ntext to the right of the cursor at the point completion was invoked is\r\ndiscarded.\r\n\r\nThe special characters that require quotes are:\r\n <space>\r\n &()[]{}^=;!'+,`~\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\cmd.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\cmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\SYSTEM32\\winbrand.dll" ] }, "cmdkey.exe-2C6DFF18B542601CC6EF0B64AEC48A95": { "file_name": "cmdkey.exe", "file_path": "C:\\Windows\\system32\\cmdkey.exe", "hash_md5": "2C6DFF18B542601CC6EF0B64AEC48A95", "hash_sha1": "4E4A61B185DC1140FAAFC4E4A37A79AC97D3072E", "hash_sha256": "2B9A9B9F93369BF0A4F2616398FB4A20C89567807FBFDDB9AA9257EE7A0CA241", "hash_sha384": "3F39A2332323765803A8F143FA373F3C0F94A7067F7CC37D530BE8E0A272455DE5CC2481A6E93134DD324B80745E0E46", "hash_sha512": "3B03605F778AD6CEDEED5D830BADD29E46435A56A34847C35EE5E9D0594597310E539C6A5761B2458056901522F14C90088D61E54E86B0BB35F4A5EC2723F83B", "hash_ssdeep": "384:Rv3K4N9/4sTPWtvuKlmPiELHONDLXHJqBG3QOdWswW:coQrm6akD7cG3z9", "hash_imp": "03AD7A1AF78BF7A500FB199CABE4C34A", "hash_pesha1": "836EE25A5A4ED02EBF077CF3522E498A8DC77911", "hash_pe256": "872F7C28B29DA294985622040522E0660DB7FEB50BB06C138C1B79D9D68250C8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Manager Command Line Utility", "meta_original_filename": "cmdkey.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/2b9a9b9f93369bf0a4f2616398fb4a20c89567807fbfddb9aa9257ee7a0ca241/detection/", "output": "\r\nCreates, displays, and deletes stored user names and passwords.\r\n\r\nThe syntax of this command is:\r\n\r\nCMDKEY [{/add | /generic}:targetname {/smartcard | /user:username {/pass{:password}}} | /delete{:targetname | /ras} | /list{:targetname}]\r\n\r\nExamples:\r\n\r\n To list available credentials:\r\n cmdkey /list\r\n cmdkey /list:targetname\r\n\r\n To create domain credentials:\r\n cmdkey /add:targetname /user:username /pass:password\r\n cmdkey /add:targetname /user:username /pass\r\n cmdkey /add:targetname /user:username\r\n cmdkey /add:targetname /smartcard\r\n \r\n To create generic credentials:\r\n The /add switch may be replaced by /generic to create generic credentials\r\n\r\n To delete existing credentials:\r\n cmdkey /delete:targetname\r\n\r\n To delete RAS credentials:\r\n cmdkey /delete /ras\r\n \r\n" }, "cmdl32.exe-A7D1CD7846E8414CB349EF577D616F2E": { "file_name": "cmdl32.exe", "file_path": "C:\\Windows\\system32\\cmdl32.exe", "hash_md5": "A7D1CD7846E8414CB349EF577D616F2E", "hash_sha1": "0A059F90BB3BA51CF1332406BE70275983C8452F", "hash_sha256": "B12F21E80553CDD21DE07AB3067E4F8AD026BEA29EFB6420B50E448CDA852AFE", "hash_sha384": "A64B0BA78B52D001DB1CA87B4313F48EF27488611A17C45D3E04D3A147CF783A2FA6FD5DF25D05401401F7E9FD2E0CB4", "hash_sha512": "E9AB33747249AF46780A0164869E5455262889CF163B90E0ADDC7FB68F314E8A5B1C892FE11D1316CDDD0E324D47D9193B61D4843E26BC06DD91C2EA993B3B26", "hash_ssdeep": "1536:sZrrs/ADRq7ZyRju6/cZ6k+zevkp8KdK26kb94DNjZI:sZcA4dbZe8KdK8i9I", "hash_imp": "AD55713E249A605BD30190ACBD0F9776", "hash_pesha1": "F2B18A4DFAB3D3111B9CBFEC84F616CCF5CD1D34", "hash_pe256": "1BC5BE54EB8F040DBE548DB613621E17A4B4EF1EE9F6541F9A6BDA4731AE43D4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Connection Manager Auto-Download", "meta_original_filename": "CMDL32.EXE.MUI", "meta_product_name": "Microsoft(R) Connection Manager", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.17763.1 (WinBuild.160101.0800)", "meta_product_version": "7.2.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b12f21e80553cdd21de07ab3067e4f8ad026bea29efb6420b50e448cda852afe/detection/", "runtime_modules": [ "C:\\Windows\\system32\\cmdl32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "cmmon32.exe-C3651D3DDC8D85B590F7CC6583EA4374": { "file_name": "cmmon32.exe", "file_path": "C:\\Windows\\system32\\cmmon32.exe", "hash_md5": "C3651D3DDC8D85B590F7CC6583EA4374", "hash_sha1": "AF11555907BE7A18BC3E2A9BAB994C48975AA721", "hash_sha256": "EACBFDF9C84013D21AA0B71AC08EDD0D56293C63723CD80FC667127410067A8E", "hash_sha384": "7618481AA7FEC1D19C0EA669F295F29775B88D32039C06BF3F755112E0AAEE443071A5103D17F38AD93C512AFB6E95EF", "hash_sha512": "4D35D8653BEE7E9E4EAA72D502293B75AD89011F61B8F66B679A4504B3C7441E809E97EF9A6ECB65134D732EA8E788C1ECF6322F04BFC1E7DE7166AF8D0EA240", "hash_ssdeep": "768:lCG6pZeJOyW9ZkrgGu5Go3ty5HDnOHh9UASn1gmNDJ5a9t:lRybkrg5Hty5HDq9YNDJ5Ot", "hash_imp": "99EE87FB928DFE3DEA854430CDA54850", "hash_pesha1": "303E71455A8BF83696B2B16479CAE320C4150CCE", "hash_pe256": "81D8B1A868C905DB686733A1B47964E79C4EA2752F44A62A3365825EBB5F6E5E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Connection Manager Monitor", "meta_original_filename": "CMMON32.exe.mui", "meta_product_name": "Microsoft(R) Connection Manager", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.17763.1 (WinBuild.160101.0800)", "meta_product_version": "7.2.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/eacbfdf9c84013d21aa0b71ac08edd0d56293c63723cd80fc667127410067a8e/detection/", "runtime_modules": [ "C:\\Windows\\system32\\cmmon32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\cmutil.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\VERSION.dll" ] }, "cmstp.exe-D9818B3C3BC0AF0A5374C71272581C08": { "file_name": "cmstp.exe", "file_path": "C:\\Windows\\system32\\cmstp.exe", "hash_md5": "D9818B3C3BC0AF0A5374C71272581C08", "hash_sha1": "89030EB0DE2B856B47105CA67DAAC722ABAF0BDF", "hash_sha256": "DB3F360BDB292C0679C13149AC6F454F7DCE768BDE559D87CE718023A6985A0D", "hash_sha384": "80F6CF838D29DF688E727878770F17DE03624A819B6B480C256673A61FDA62BCB098430DF2FF7454EDD4198880615FAA", "hash_sha512": "9330F1929D3F14425F23B508CB9449F44B8BF5BB14C3CFB7130599B20CBAEE9A0DFC5F40C8FA9AE928C4893614DD9787AD7003D1A3072AD8D7774774A3881571", "hash_ssdeep": "1536:+ovqTsD+XrQyOWPAfrUetMY7lDUKhyvj2ihR/87BMKM/SO1URZ:nv5HyOWeLeklwv/Rk7BMK6SO1gZ", "hash_imp": "109BA8ED3C458360A74EA1216207CA09", "hash_pesha1": "7C6FF4D8E4A744871C99F7C6485BBD63B006835E", "hash_pe256": "BC53C3DBC4912885D7AF6D6208268651BD73A670979AA97F7306BA74C1F0315D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Connection Manager Profile Installer", "meta_original_filename": "CMSTP.EXE.MUI", "meta_product_name": "Microsoft(R) Connection Manager", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.17763.1 (WinBuild.160101.0800)", "meta_product_version": "7.2.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/db3f360bdb292c0679c13149ac6f454f7dce768bde559d87ce718023a6985a0d/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\cmstp.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\cmstp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\cmutil.dll", "C:\\Windows\\system32\\VERSION.dll" ], "runtime_window_title": "Connection Manager Profile Installer" }, "cofire.exe-698E0C4F178784A5EB308AFAB490485C": { "file_name": "cofire.exe", "file_path": "C:\\Windows\\system32\\cofire.exe", "hash_md5": "698E0C4F178784A5EB308AFAB490485C", "hash_sha1": "DCA10EC60B4A4A45795903555C32C8DE3D812EA3", "hash_sha256": "A99ACDFC69C9A7C3E027A9BEC724D3C366D3FC52429BF6E2C1FFC8156BEB7D75", "hash_sha384": "4CE8D7962CDEBD7355D772AA2B974F8C328199DE922F5C83C5269BB7A880FA7C1B1E392FBEA3171DDF763AE5D4A56B5B", "hash_sha512": "B8421C17813AC5837D6818CC063E8BC9DDBD26E720224EC2F72510C149A082C9E50C63C0567766B8C60715B101BCDF879906FCE9C82BDDA8419968F8B3019736", "hash_ssdeep": "384:hM7fEoW34+EjLflv0Ipr3VqeoZ/7R4/RMP3OtmV7RGWvJW:hCfEX3yLflvpNlmx+tmX3", "hash_imp": "49C319693A3F09328AFCB91C7F2E2CBE", "hash_pesha1": "A9B7A447D6D8371E0BFF702751CA2A95640322E9", "hash_pe256": "466FF9A2F587679367727EBD59BAE784786CA5267FFC7E5533A94AF1699EAFFF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Corrupted File Recovery Client", "meta_original_filename": "cofire.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/a99acdfc69c9a7c3e027a9bec724d3c366d3fc52429bf6e2c1ffc8156beb7d75/detection/" }, "colorcpl.exe-F24913A27288728064D4B1EE4FBC2354": { "file_name": "colorcpl.exe", "file_path": "C:\\Windows\\system32\\colorcpl.exe", "hash_md5": "F24913A27288728064D4B1EE4FBC2354", "hash_sha1": "81289E917142E9C188DBEBAEDB280772F7F9AFA0", "hash_sha256": "C57CB5E7B90F921FB9C6F4992513D58941397F7ADBB03ACDFAC1E36E7E763A31", "hash_sha384": "89E5C19EB933B1425A0259839B1972FFC7F6FB7EFE455A651E748121535BF9D0FF9C6FC65EA1B16F32043CC20CD3E763", "hash_sha512": "43C7A0F67697DE959F51D74A3A4D66FCEDF1879A9C6EF0461DD216E0F976C4849860FC314FCD9C0A1B1B7B82ADAFCB2A3678E409D041B5BD89CB91793EF9F0AE", "hash_ssdeep": "1536:btiIPfSbS9vMBN7rQOJ7CFToTCzhcRguhwxTyPCb3lZpdym4dy7p:x1Xlvq7jSP1cR2prbpdCY9", "hash_imp": "BF699192BC903253BE75CBD63776138C", "hash_pesha1": "D335F44F8B4DFFEDEEE538878286F58E01F253B4", "hash_pe256": "1128663FA2D0AA6354001180F084923D95B6A6FD51943487933088A92BDBBD0E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Color Control Panel", "meta_original_filename": "colorcpl.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/c57cb5e7b90f921fb9c6f4992513d58941397f7adbb03acdfac1e36e7e763a31/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\colorcpl.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\colorui.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\colorcpl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\colorui.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\WINSPOOL.DRV", "C:\\Windows\\system32\\mscms.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\ColorAdapterClient.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\SYSTEM32\\sti.dll", "C:\\Windows\\SYSTEM32\\DUser.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\SYSTEM32\\WindowsCodecs.dll" ], "runtime_window_title": "Color Management" }, "comp.exe-2B195E666FB46D1B8DD32EB8733FACC4": { "file_name": "comp.exe", "file_path": "C:\\Windows\\system32\\comp.exe", "hash_md5": "2B195E666FB46D1B8DD32EB8733FACC4", "hash_sha1": "D3AFC299864820ADEC4321753BE20D87527DB51D", "hash_sha256": "663B831A79CE13D456C375D7CF28081164FC0E5CA513B7BEB3C07A0D1E1B1C4D", "hash_sha384": "1E61A278CBCFC9A06B344653760D96330A957DC1294FA8F087B696A5CA5C90D91BA571C0229CDB1CEF72D60E63A15553", "hash_sha512": "CD81E5009B33FE037A775EE36F7FFBED1DAE82D2DE8BEA95D4E9C036013AB85277DF9A16CCAF5F37D06EEDC362822AD843646030774C131089F0B29BEF17D64E", "hash_ssdeep": "384:Ax0+V/mMGgXRW/JhcyV6/LzCpkLi5FYhAey4xZjxONzWncW:R+NJSJh5SK+i5mhXjxO2", "hash_imp": "02B63B93BB0FF42FF5BEB4C6E62D06B7", "hash_pesha1": "E45C8BB4526EA3F60BA9AE668556B42DB5FA6449", "hash_pe256": "B396FD7FC05857BAC8FE48C4551FAA02C8A2349F105E25A8337284188E8B29E9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Compare Utility", "meta_original_filename": "Comp.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/663b831a79ce13d456c375d7cf28081164fc0e5ca513b7beb3c07a0d1e1b1c4d/detection/", "output": "Compares the contents of two files or sets of files.\r\n\r\nCOMP [data1] [data2] [/D] [/A] [/L] [/N=number] [/C] [/OFF[LINE]] [/M]\r\n\r\n data1 Specifies location and name(s) of first file(s) to compare.\r\n data2 Specifies location and name(s) of second files to compare.\r\n /D Displays differences in decimal format.\r\n /A Displays differences in ASCII characters.\r\n /L Displays line numbers for differences.\r\n /N=number Compares only the first specified number of lines in each file.\r\n /C Disregards case of ASCII letters when comparing files.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n /M Do not prompt for compare more files.\r\n\r\nTo compare sets of files, use wildcards in data1 and data2 parameters.\r\n", "error": "Name of second file to compare: ", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\ulib.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\comp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\ulib.dll", "C:\\Windows\\SYSTEM32\\fsutilext.dll" ] }, "compact.exe-A3BBBFB18D598EF2E494F6FCC77EE26B": { "file_name": "compact.exe", "file_path": "C:\\Windows\\system32\\compact.exe", "hash_md5": "A3BBBFB18D598EF2E494F6FCC77EE26B", "hash_sha1": "ED449D2C531459019D13ED8066A2ED8E6C2F4F5B", "hash_sha256": "2628746328128A4F5F36D9079A976DE685AE54229BEB12A8E3F3BF11797A79C8", "hash_sha384": "C6C22330487DA4CC7E0AC69C93BC9330E374186CD800925B83D1B279DEC0D9C93A86FCD2690B1CB7ADED23EB85661EF0", "hash_sha512": "76ABF829430A30B5D26D055DB98B90DE9AD31418E3C56D5374F4C89F98554D8693F82636E83FCAA314E34A9E91EC2801DDF368AD13C26FE91EFCE27422C425F8", "hash_ssdeep": "768:n1M1Vy4hlew3W/H+g3GK+wt3sY7unVdfpomaJQcTlpHpo78RNCmxr5uIDxd:9wIH+gWK+s3vuTfpomaJQcTlpHpPCmxp", "hash_imp": "928C9114035A0164EB94B966F4A358C8", "hash_pesha1": "12940E6E8B25A0CED8CCA499039BA7558E4363F0", "hash_pe256": "C8F55C8CCE9BE2BBDC5A546CC0F2573ED942E4B89A88548249592698C43D2619", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Compress Utility", "meta_original_filename": "COMPACT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.831 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.831", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/2628746328128a4f5f36d9079a976de685ae54229beb12a8e3f3bf11797a79c8/detection/", "output": "Displays or alters the compression of files on NTFS partitions.\r\n\r\nCOMPACT [/C | /U] [/S[:dir]] [/A] [/I] [/F] [/Q] [/EXE[:algorithm]]\r\n [/CompactOs[:option] [/WinDir:dir]] [filename [...]]\r\n\r\n /C Compresses the specified files. Directories will be marked\r\n so that files added afterward will be compressed unless /EXE\r\n is specified.\r\n /U Uncompresses the specified files. Directories will be marked\r\n so that files added afterward will not be compressed. If\r\n /EXE is specified, only files compressed as executables will\r\n be uncompressed; if this is omitted, only NTFS compressed\r\n files will be uncompressed.\r\n /S Performs the specified operation on files in the given\r\n directory and all subdirectories. Default \"dir\" is the\r\n current directory.\r\n /A Displays files with the hidden or system attributes. These\r\n files are omitted by default.\r\n /I Continues performing the specified operation even after errors\r\n have occurred. By default, COMPACT stops when an error is\r\n encountered.\r\n /F Forces the compress operation on all specified files, even\r\n those which are already compressed. Already-compressed files\r\n are skipped by default.\r\n /Q Reports only the most essential information.\r\n /EXE Use compression optimized for executable files which are read\r\n frequently and not modified. Supported algorithms are:\r\n XPRESS4K (fastest) (default)\r\n XPRESS8K\r\n XPRESS16K\r\n LZX (most compact)\r\n /CompactOs Set or query the system's compression state. Supported options are:\r\n query - Query the system's Compact state.\r\n always - Compress all OS binaries and set the system state to Compact\r\n which remains unless administrator changes it.\r\n never - Uncompress all OS binaries and set the system state to non\r\n Compact which remains unless administrator changes it.\r\n /WinDir Used with /CompactOs:query, when querying the offline OS. Specifies\r\n the directory where Windows is installed.\r\n filename Specifies a pattern, file, or directory.\r\n\r\n Used without parameters, COMPACT displays the compression state of\r\n the current directory and any files it contains. You may use multiple\r\n filenames and wildcards. You must put spaces between multiple\r\n parameters.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\compact.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "CompatTelRunner.exe-32D8EEFAB5942B37C8C04CED08E47139": { "file_name": "CompatTelRunner.exe", "file_path": "C:\\Windows\\system32\\CompatTelRunner.exe", "hash_md5": "32D8EEFAB5942B37C8C04CED08E47139", "hash_sha1": "995FE5540E3CAF8E9EA80951F5B2B1F783190EF1", "hash_sha256": "C0A5986A4DD6D7CACF09C5A980DF634C44FF73028206D99CB561E64A74A0958A", "hash_sha384": "48ECDA940284522818FCAF7A2638BB1EA9E5FD94618DF3A9E8BB72BAE8B3DE2552671825AF43F60BEA0CEF824FA2226B", "hash_sha512": "7FBD60BFA3C54E872083DC7365AB0030E22650D613F2AE6F6A4689A127890942B14B624007DC5D68FC459B9562FB5B59D07A8251052CE85C3E42054944B12F3E", "hash_ssdeep": "3072:fm18wDYYRZVaVWELsqeW+arDGi9UkIHLLeDDAtwJ2H260L:f88wn3VaVMqeWY1k4WDDA6j", "hash_imp": "5E4D55883A5FB7A7D7CAB55A34B42708", "hash_pesha1": "F45336CFC6E2AFD609643AA2AE285DA231D93870", "hash_pe256": "F35C42CD3A7F2F5468C8F61857766FF55738A88B03A2F9455A2760F9F012A32E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Compatibility Telemetry", "meta_original_filename": "CompatTelRunner.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19645.1016 (WinBuild.160101.0800)", "meta_product_version": "10.0.19645.1016", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c0a5986a4dd6d7cacf09c5a980df634c44ff73028206d99cb561e64a74a0958a/detection/", "runtime_modules": [ "C:\\Windows\\system32\\CompatTelRunner.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll" ] }, "CompMgmtLauncher.exe-ED3867E805501925E10070A1430E13DF": { "file_name": "CompMgmtLauncher.exe", "file_path": "C:\\Windows\\system32\\CompMgmtLauncher.exe", "hash_md5": "ED3867E805501925E10070A1430E13DF", "hash_sha1": "58743A6E4BE8076B5D84DDC484B6093FB0123049", "hash_sha256": "E95853AA8C13062CDF99342D307B13BBE62D61FC653EE0FE7E6EAD4CCD4A46A2", "hash_sha384": "E790A90FC55A01ABB1C4EC94713FE0F2EDEAE3238ECA97A612CDE11D045F73B9509238693720F04F4AB90C8EC3AB6A10", "hash_sha512": "E4784B15C3B374F4BD422A5BD948C39A7D95D8A0D6A908B50AEF65E7F19C433892A3F69B4DA896209354698590D2125D0EF55EA98193C0A62FF78B0B965D9BC1", "hash_ssdeep": "1536:F3V5MYdZ1e5zb6j6g8gZ7fRMv3ilVOFGxVz9lOo+vi6Uf:FlbL1epuj6AZ7fRMvusFGxVz9co+Q", "hash_imp": "5C07F48325D782CDDABE04AA4F7F5B0B", "hash_pesha1": "2DBE31B9C629B3FD472312C2EEBF49135240CFD7", "hash_pe256": "C5D0ED5331B06373B4CF46D08E9252A6CB3B54B6703BCB8B7812BEA66FC58BEE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Computer Management Snapin Launcher", "meta_original_filename": "CompMgmtLauncher.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/e95853aa8c13062cdf99342d307b13bbe62d61fc653ee0fe7e6ead4ccd4a46a2/detection/", "children": "ServerManager.exe", "runtime_modules": [ "C:\\Windows\\system32\\CompMgmtLauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "CompPkgSrv.exe-F11B0823C22C4AD1643E7853E302C0C3": { "file_name": "CompPkgSrv.exe", "file_path": "C:\\Windows\\system32\\CompPkgSrv.exe", "hash_md5": "F11B0823C22C4AD1643E7853E302C0C3", "hash_sha1": "F50F6CB9274361B172248C4494B9302CE8E3829B", "hash_sha256": "739A4C71D0D5069B1E18A1B88665F3F22496637F534A308E6FF032C42E44973A", "hash_sha384": "4E999DF2C9197A5CC3A9A5EA2CA5E156C3E08D70809E427CE8C1E2B7A5225EB43AB79EF9BE7ADFC45D0EF999BB904F0E", "hash_sha512": "A57651EA171AB7AA0BF79095CCD47AC68317ACA104557640834088950D549B3AA355E56E9568ED2E7FCF2B473CA2DC3BF897F2636E15B1285919E6CC561A6640", "hash_ssdeep": "3072:2+I7VFp9rfg+fbAP7ittKsXmYU9ojbCurhWhx4f+eenYNX8WU+Dkr4koxleNYg8f:2FvxIebjtgAmYU0yCg8", "hash_imp": "9C5365A9CDB8687F59320109F3CE439E", "hash_pesha1": "A8463C5E294C8882A848C0EFA845E09B038EBFFD", "hash_pe256": "1D70B3ADF7B49C0BB03BFDDD18C141D879CABED6EA2EE1A09FA796EFBA7D5C41", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Component Package Support Server", "meta_original_filename": "CompPkgSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.529 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.529", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/739a4c71d0d5069b1e18a1b88665f3f22496637f534a308e6ff032c42e44973a/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECF68": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\CompPkgSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\clbcatq.dll" ] }, "ComputerDefaults.exe-AC4C3945A3E6DFFF98145096DA4EDA93": { "file_name": "ComputerDefaults.exe", "file_path": "C:\\Windows\\system32\\ComputerDefaults.exe", "hash_md5": "AC4C3945A3E6DFFF98145096DA4EDA93", "hash_sha1": "FFA8ADAAA31F7B6FF7764C6AE877FCEDDB6AE975", "hash_sha256": "B2C06A97827F403848620CAAE012C284604B5093ED7950AC4EAD2B9EE4D28EB3", "hash_sha384": "1452E7096764F43725E2D6489441052D5BB61AAD9E2EF5A1688255FDD9564F289AD0DA309692CD29C220C094B567C9A6", "hash_sha512": "EA67E6656E87F5DF1ADB718D7B445CD49E89D210C4E4DE94B13FBF4B0B3AF96A665609B8A1AB02765F90012049C3D2B46CAF388E52EC71292F2C46B46C0DF878", "hash_ssdeep": "1536:kQOtu50MZS8EVCioHoL6u/a7WryQqURDoq4OZZZLlCIibB:knrWyiILS79KRD68wbB", "hash_imp": "00B74CCF8A4820BD574431AE64ECF0C5", "hash_pesha1": "07F68410C832FEDCF539890DCC56BE6392603CC2", "hash_pe256": "447E2060FAE609120FB0BC83995F7BEA0EC29C968D2A74DF9D928F9BC1822958", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Set Program Access and Computer Defaults Control Panel", "meta_original_filename": "ComputerDefaults.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/b2c06a97827f403848620caae012c284604b5093ed7950ac4ead2b9ee4d28eb3/detection/", "runtime_modules": [ "C:\\Windows\\system32\\ComputerDefaults.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\uxtheme.dll" ] }, "Configure-SMRemoting.exe-01B26A8919A84F68E836BD7F43AE646E": { "file_name": "Configure-SMRemoting.exe", "file_path": "C:\\Windows\\system32\\Configure-SMRemoting.exe", "hash_md5": "01B26A8919A84F68E836BD7F43AE646E", "hash_sha1": "423CC045915C20424A54C8BC01C5AFA0EEBF38DC", "hash_sha256": "C42B1CDBA6020D3858CE47C6A0D279045A741F21263BB417742371D0C04AE79A", "hash_sha384": "1F6796B57389D37C696EA4871184894B102E673AC54DA6A10BBBDAE79C919F801F5DFF123BE24E57EFE82004307B8EE0", "hash_sha512": "630A66C6F75931A68BCA8DCD81893874D90DB4C777837281C4F307E8AD4226EB3829E56FFDB735D305122A8B8668C74979B4D8D3037B05998120C06431904851", "hash_ssdeep": "768:HcDIGqtaELu1Sbx9XxH8/QTmD3J+aPW6a8EkiHT45IdEgWDJbkYLEzXQbJcRmIld:c39c9XxHcQW5zHEkWT45SWD2FT7", "hash_imp": "403E36D730F1BA1D4A5AF9FE98AB6A3C", "hash_pesha1": "4BCBB9B4364A7A893EA273E4DCD761DB98A6F77A", "hash_pe256": "42AA80348E8EF4460F99A3D11A2FCCF48763B5F627138D94717696AD292E96F2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Configure-SMRemoting", "meta_original_filename": "Configure-SMRemoting.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/c42b1cdba6020d3858ce47c6a0d279045a741f21263bb417742371d0c04ae79a/detection/", "error": "Configure-SMRemoting.exe -GET | -ENABLE | -DISABLE\r\n", "runtime_modules": [ "C:\\Windows\\system32\\Configure-SMRemoting.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\XmlLite.dll" ] }, "conhost.exe-1B0E9B5FCB62DE0787235ECCA560B610": { "file_name": "conhost.exe", "file_path": "C:\\Windows\\system32\\conhost.exe", "hash_md5": "1B0E9B5FCB62DE0787235ECCA560B610", "hash_sha1": "E19DA2C35BA1C38ADF12D1A472C1FCF1F1A811A7", "hash_sha256": "697334C236CCE7D4C9E223146EE683A1219ADCED9729D4AE771FD6A1502A6B63", "hash_sha384": "A8572EB5D98A4F1F641D91B517A14FD714CFE337C060BE33A7B6EE4078602FAAF5CC8E0C938574DA3CF65CED5185EC05", "hash_sha512": "B71C46E301F5F415368AD7D7FF9A0E4CA6997DECF11053756F85C2CD83BB8B456EDB41CF5708169E2CC6E94940DB13339A970BECEE0F7CDFB786DABDDF94AC08", "hash_ssdeep": "12288:qFkZjRZXh71jot4IXPXa1nV5AvkT+SpueXUVY9uDHT1aMTzo8RP:qGZjbh7BZIv85+kixeXUaYDHZaMT88p", "hash_imp": "9833F5715D91CDA5A84888790AE9BB45", "hash_pesha1": "CD8839B768DEB85023A95689EFA90A72DB2A7408", "hash_pe256": "53B647BFBAD80E8E5E5E0001B2B300A434B48262EC09193F7C3D2AF74E3CF710", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Console Window Host", "meta_original_filename": "CONHOST.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/697334c236cce7d4c9e223146ee683a1219adced9729d4ae771fd6a1502a6b63/detection/", "output": "[?25l\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\nRENAME Renames a file or files.\r\nREPLACE Replaces files.\r\nRMDIR Removes a directory.\r\nROBOCOPY Advanced utility to copy files and directory trees\r\nSET Displays, sets, or removes Windows environment variables.\r\nSETLOCAL Begins localization of environment changes in a batch file.\r\nSC Displays or configures services (background processes).\r\nSCHTASKS Schedules commands and programs to run on a computer.\r\nSHIFT Shifts the position of replaceable parameters in batch files.\r\nSHUTDOWN Allows proper local or remote shutdown of machine.\r\nSORT Sorts input.\r\nSTART Starts a separate window to run a specified program or command.\r\nSUBST Associates a path with a drive letter.\r\nSYSTEMINFO Displays machine specific properties and configuration.\r\nTASKLIST Displays all currently running tasks including services.\r\nTASKKILL Kill or stop a running process or application.\r\nTIME Displays or sets the system time.\r\nTITLE Sets the window title for a CMD.EXE session.\r\nTREE Graphically displays the directory structure of a drive or\r\n path.\r\nTYPE Displays the contents of a text file.\r\nVER Displays the Windows version.\r\nVERIFY Tells Windows whether to verify that your files are written\r\n correctly to a disk.\r\nVOL Displays a disk volume label and serial number.\r\nXCOPY Copies files and directory trees.\r\nWMIC Displays WMI information inside interactive command shell.\r\n\r\nFor more information on tools see the command-line reference in the online help.\r\n\r]0;C:\\Windows\\system32\\help.exe[?25hR", "runtime_modules": [ "C:\\Windows\\system32\\conhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "consent.exe-27992D7EBE51AEC655A088DE88BAD5C9": { "file_name": "consent.exe", "file_path": "C:\\Windows\\system32\\consent.exe", "hash_md5": "27992D7EBE51AEC655A088DE88BAD5C9", "hash_sha1": "9329B2362078DE27242DD4534F588AF3264BF0BF", "hash_sha256": "8F112431143A22BAAAFB448EEFD63BF90E7691C890AC69A296574FD07BA03EC6", "hash_sha384": "E42F693B1A7A4EE8E31FA033FEB4B05367A25C3AEC9835366985357D002BCC46C09C1EE7FA4C987CB51DFE06B5E97BF8", "hash_sha512": "7D129C79A594D57DFB3C0726C8B51C263A551D991F47703BB06811E4AE68A7DD09F17476A540C16E51C0D9CA46527F399581A1A5F3A41C6FA73431F3A2E70ABC", "hash_ssdeep": "1536:nzWTXOK1vnpop7BIFFlUDKcCjXifIOAmQt/f4k7eDkXV+JEIuaikX4sVQbf/7X2r:ydKtTqyfumQF7NoJeSX4sC7mzkMv", "hash_imp": "522D83761201075834F05037F5307949", "hash_pesha1": "4447852F03AB225E6F4073760A9006AA76498608", "hash_pe256": "8EFC32DE5E57A43DADD621C5728E677CAB95411AC9F28CDD0F39E61B19D34F7F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Consent UI for administrative applications", "meta_original_filename": "consent.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/8f112431143a22baaafb448eefd63bf90e7691c890ac69a296574fd07ba03ec6/detection/", "runtime_modules": [ "C:\\Windows\\system32\\consent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\SYSTEM32\\WMsgAPI.dll", "C:\\Windows\\SYSTEM32\\Amsi.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\MsCtfMonitor.DLL", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\SYSTEM32\\MSIMG32.dll", "C:\\Windows\\SYSTEM32\\WINSTA.dll", "C:\\Windows\\SYSTEM32\\WTSAPI32.dll", "C:\\Windows\\system32\\MSUTB.dll" ] }, "control.exe-88EA810385F455C74306D71C4879C61C": { "file_name": "control.exe", "file_path": "C:\\Windows\\system32\\control.exe", "hash_md5": "88EA810385F455C74306D71C4879C61C", "hash_sha1": "391FF1F690C0912C217B3CF625900D4F50128867", "hash_sha256": "4774A931C9D97828323C9E829917D82C27A05DAB9FEA6A0CEF9EBBA59942231F", "hash_sha384": "2D51CBBBEA71C5A687265880F9217579E944B4B2FD674EFF2084346B091B17F0837AA760802D1B7DDC40735BD10B7E45", "hash_sha512": "D816977F9B9B147050937DF7663BE074FD44AA6DBFF608A0E673BC2739FC1A1DBEE506668A252D0A3A0B7E430A9B084502A9E7F7D4BB5EE69621FEFE861D5646", "hash_ssdeep": "1536:trl0+A4FF/P4yXBe/qzSpZ3r1q6QkjfkQUk8+k6kawM1x8Dkf8dani25imK:tyt43/g4B7Sp5+1k12b/Af885RK", "hash_imp": "7A8EC2645C24D85DE8216D63022623C0", "hash_pesha1": "02AAB43D7AC03E57605ED06AC76CC4341940D632", "hash_pe256": "B634DD6A48F90C911758842BE7ED72324363CDE8EF7C72BB37813EC2B67DFAE0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Control Panel", "meta_original_filename": "CONTROL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/4774a931c9d97828323c9e829917d82c27a05dab9fea6a0cef9ebba59942231f/detection/", "runtime_modules": [ "C:\\Windows\\system32\\control.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\edputil.dll" ] }, "convert.exe-2DCC49AB7278C4FE65E485837CACB929": { "file_name": "convert.exe", "file_path": "C:\\Windows\\system32\\convert.exe", "hash_md5": "2DCC49AB7278C4FE65E485837CACB929", "hash_sha1": "6FB0722EFABFF5BB9B2F5E67C36CB7CF01DD006D", "hash_sha256": "91C6B20A6D953A3B0769323918D0EAC216C9F9BBDD5880A1A1CCFB9E43179F69", "hash_sha384": "CF8786462B72F16D5DF2C9F6E6F5E3A4BE91204A7A7F696B4E873AF71B148341A1E43B559D284E770D3C82C395289CC7", "hash_sha512": "A349DB8154472F10979CD7CE4E4C8DCCF420723DD13F531E9A9A585684FC2506EC4702B89A6A7C9A9C33FAE2433E932D2D5C88B8B875DDDC9410CD0F6B581437", "hash_ssdeep": "384:XNWxTBrvw5Fz/Zc8bY3piv5R6QUZqhKsy7jNTW9qW:M9Lw7LWMY8xRlWjo", "hash_imp": "D950A0891AA3651B49F0BAFE5E2CEF68", "hash_pesha1": "89CE0F9C02539D5E1C9A9E9A8EE20E4D7607EF3A", "hash_pe256": "378F14AF93B8DC8BC06FC97E8C2059DBB7BC155B1606937F35B01F68ABF9B609", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File System Conversion Utility", "meta_original_filename": "CONVERT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/91c6b20a6d953a3b0769323918d0eac216c9f9bbdd5880a1a1ccfb9e43179f69/detection/", "output": "Converts a FAT volume to NTFS.\r\n\r\nCONVERT volume /FS:NTFS [/V] [/CvtArea:filename] [/NoSecurity] [/X]\r\n\r\n\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name.\r\n /FS:NTFS Specifies that the volume will be converted to NTFS.\r\n /V Specifies that Convert will be run in verbose mode.\r\n /CvtArea:filename\r\n Specifies a contiguous file in the root directory\r\n that will be the place holder for NTFS system files.\r\n /NoSecurity Specifies that the security settings on the converted\r\n files and directories allow access by all users.\r\n /X Forces the volume to dismount first if necessary.\r\n All open handles to the volume will not be valid.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\convert.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\ulib.dll", "C:\\Windows\\system32\\IfsUtil.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\SCECLI.dll" ], "error": "Invalid drive specification.\r\n" }, "convertvhd.exe-8532453CD16B6A9DC0F0AFC815F303A2": { "file_name": "convertvhd.exe", "file_path": "C:\\Windows\\system32\\convertvhd.exe", "hash_md5": "8532453CD16B6A9DC0F0AFC815F303A2", "hash_sha1": "C2A5499E485FA83B136E15093C2DD16180B2AA8F", "hash_sha256": "3DCD82B2B87F8B6DEB6F88AA41692D4FBDE2D887C3BE177D62BDDA8AB74EB917", "hash_sha384": "B83549368B691063E161BAF21EB173E001189E3F07BA50E7C554D160A19FABE89FDC9119A1A55E5AA1B8678C35CDEAD8", "hash_sha512": "5AFAB0325FF57864FA63BD9197036DAE5A7F4DE49D9CF895D0DBFA35FCD7A5ECE454533F53E634A51D9D2271A67FE7ECD07FA08BD3A7FD37EF2C1A78FE812BF7", "hash_ssdeep": "3072:PvqGqk2hWI4qASYzWdk1Zgv6IYt2/GJdxw8FxzB0gzncY6XE+O:PH4hWISnyWgiIVGJdxw8FxzBJ6XM", "hash_imp": "316E8DA32C980B2D5631F2CB08B7CD56", "hash_pesha1": "593B93F69F680D1AC569C28B400066F8D960751C", "hash_pe256": "3203021A0EF1D14417E59F7D152AFEC01FA91F726CC54B00568ED66A876DAA42", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "VHD Conversion Tool", "meta_original_filename": "ConvertVhd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/3dcd82b2b87f8b6deb6f88aa41692d4fbde2d887c3be177d62bdda8ab74eb917/detection/", "output": "VHD Conversion Tool [Version 1.00]\r\nCopyright (C) 2017 Microsoft Corporation. All rights reserved.\r\n", "error": "onecore\\vm\\dv\\storage\\vhd\\btt\\tools\\convertvhdmodule.cpp(112)\\convertvhd.exe!00007FF771B47CE7: (caller: 00007FF771B48954) Exception(1) tid(1008) 80070057 The parameter is incorrect.\r\r\n Msg:[\r\n\r\nUSAGE:\r\nconvertvhd.exe -source <filepath> -destination <filepath> [-btt] [-toPMem]\r\nconvertvhd.exe -sourceToken <file handle> -destinationToken <file handle> [-btt] [-toPMem]\r\n\r\n] \r\n", "runtime_modules": [ "C:\\Windows\\system32\\convertvhd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ] }, "coredpussvr.exe-C279BCBE0CF0EBEAA325E1252460EBDB": { "file_name": "coredpussvr.exe", "file_path": "C:\\Windows\\system32\\coredpussvr.exe", "hash_md5": "C279BCBE0CF0EBEAA325E1252460EBDB", "hash_sha1": "A176C48E767D654D633BB55B9C66746049794259", "hash_sha256": "635E2AC851924A4D78A869452C450AE8CB5A4DD1E8DEB3CE1E14909CBF57B11C", "hash_sha384": "63CF5C3565B189B985568AAA1376D7C69B90C24CCD8157BFC777CF06BDF5F5FBE435CFD504009FC9BE365B3F762AE6E7", "hash_sha512": "7CABEBE26FEFDF2EE2D21035F21967A2DB6AA9121F5C337A664CFA4F981C9BBCE889F3A62B9E8C2AAE4EDE928130F9CB9DE325921E1C72D53F2FF429C4DA3B8E", "hash_ssdeep": "1536:2f6TWLAu0T0NLzm7lBfoVoLSSjuhHPhIwu6t3Urd8q9NATMo5z7Rro:2CJ6jCLpqNPZuK3iGt7RU", "hash_imp": "E2CF56C678AB1BD46F2230E50F3171DD", "hash_pesha1": "AB7996E35DD025F23A9B875D53189D041B460381", "hash_pe256": "84407515FD9DF848F37C60B580E1A73A93E01003AC57D2F727247C6EE29E5C10", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "coredpussvr.exe", "meta_original_filename": "coredpussvr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/635e2ac851924a4d78a869452c450ae8cb5a4dd1e8deb3ce1e14909cbf57b11c/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECEE4": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\coredpussvr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "CredentialUIBroker.exe-DFDC8C3F5C8C39DB30C09574D611D3AD": { "file_name": "CredentialUIBroker.exe", "file_path": "C:\\Windows\\system32\\CredentialUIBroker.exe", "hash_md5": "DFDC8C3F5C8C39DB30C09574D611D3AD", "hash_sha1": "225820568843E16ECCF15E3A4958A79D88BA01C9", "hash_sha256": "B81B3AA5C5C239B13584C1F5425439075213802EF55683F1EA7760DC62BD876A", "hash_sha384": "86C2D474025BE919E9F68E186C86674272136529C2749E418A6B7BB56A75D3623E8AD477FB14C339D108FCF3D5D001CF", "hash_sha512": "7138CCA7FD9F174AC61BA15CFC017FD31BFEDC6C9B41BD75D4099C97D52702E2B7DDAE032640AF552E83B7FA7CAA7405B608C7B307CA883672C4244A6B3784C7", "hash_ssdeep": "3072:yegU/924jrshSnRkgLOrD6tl42k9h0tVbZEX8x+aatj:yegU42GSnfLM6tG21tY8wJ", "hash_imp": "5B712233484DC38671F4B7D0CA01345A", "hash_pesha1": "A054DA32A77393AB3CE0A98C0A624067948A65F9", "hash_pe256": "D7A2288880616A89E3A1C0F0A0564720BB31D8CD866F1C04CD4A5A2D04062183", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Manager UI Host", "meta_original_filename": "CredentialUIBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b81b3aa5c5c239b13584c1f5425439075213802ef55683f1ea7760dc62bd876a/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\CredentialUIBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll" ] }, "credwiz.exe-5944AD75821F321AFEFCB8C027A5F00F": { "file_name": "credwiz.exe", "file_path": "C:\\Windows\\system32\\credwiz.exe", "hash_md5": "5944AD75821F321AFEFCB8C027A5F00F", "hash_sha1": "437AB418743820189763E649C210458DD512248F", "hash_sha256": "6DDA8D8158BF23069B64014EEDB2C2B2AC8334E4F13DBF88D555F67DFEBDBABA", "hash_sha384": "790C7A6FCDA90DFBFB8437E00B687EC21D3CC32EF4E7C96643B8ED5AD00DD959EA10C9451C2B5DAE520DDCB172F6D698", "hash_sha512": "BA753D425509E95B4CDD79938A67117C20EA6D411AD48E847AD5817998ED72E0F6167522E43C4C0DE8A43802C16FAD439CF2126D93130C76B558744574BB570D", "hash_ssdeep": "768:3zqDzcebdDCWpCn+BVhKR/jBWLNk0tA3kVMPnqtA3I6/KZnpu:DqUGDdBGR7BWL+0tA3kVMPqtA3fKZnp", "hash_imp": "1DD00699999764F96356FE23CCDE82BD", "hash_pesha1": "5E80C0C07709C51FCD3BB48944AC5F0A68479A1E", "hash_pe256": "B1028388F07C4DFDA4576E694C0856B60BA6F5A603BE9A3DE41134A0715987C0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Backup and Restore Wizard", "meta_original_filename": "credwiz.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/6dda8d8158bf23069b64014eedb2c2b2ac8334e4f13dbf88d555f67dfebdbaba/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\credwiz.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\credwiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\MsCtfMonitor.DLL", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\system32\\MSUTB.dll", "C:\\Windows\\system32\\WINSTA.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\system32\\OLEACC.dll", "C:\\Windows\\system32\\WindowsCodecs.dll" ], "runtime_window_title": "Stored User Names and Passwords" }, "cscript.exe-A45586B3A5A291516CD10EF4FD3EE768": { "file_name": "cscript.exe", "file_path": "C:\\Windows\\system32\\cscript.exe", "hash_md5": "A45586B3A5A291516CD10EF4FD3EE768", "hash_sha1": "0E3C0779D8EAAD3B00363D7890DDC8272B510D49", "hash_sha256": "59D3CDC7D51FA34C6B27B8B04EA17992955466EB25022B7BD64880AB35DF0BBC", "hash_sha384": "6E3273A5B9D42EE0156A80A7CE3566F6C8FEEE265917A164A597231581147496EAB6036549C4B6F5394E7DAB13AF10BA", "hash_sha512": "3C2FD1F27F3850B329C0B0854A69FDE140C27AD366D663302FEE16210049CE1E25A04D600C7FE4569E68DE00EDD31EAEA761133977FE7011B21B425DDD99F27A", "hash_ssdeep": "3072:7x3CrpEcfyIZEcqQznVzA1ie5CNRwe9K9FNUxrfi66IZxtt:V38pEcbZzznVsMPRzE8fVfZh", "hash_imp": "2B44D2206B9865383429E9C1524F1CAC", "hash_pesha1": "5F928AE254B645D6D0B4B3B77FD8C667E18B6994", "hash_pe256": "7EA894876FF19F8E2B3D2803BE3D3317FDFD23297BCACC116D79230C8A9E1741", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Console Based Script Host", "meta_original_filename": "cscript.exe.mui", "meta_product_name": "Microsoft Windows Script Host", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.812.10240.16384", "meta_product_version": "5.812.10240.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/59d3cdc7d51fa34c6b27b8b04ea17992955466eb25022b7bd64880ab35df0bbc/detection/", "output": "Microsoft (R) Windows Script Host Version 5.812\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: CScript scriptname.extension [option...] [arguments...]\r\n\r\nOptions:\r\n //B Batch mode: Suppresses script errors and prompts from displaying\r\n //D Enable Active Debugging\r\n //E:engine Use engine for executing script\r\n //H:CScript Changes the default script host to CScript.exe\r\n //H:WScript Changes the default script host to WScript.exe (default)\r\n //I Interactive mode (default, opposite of //B)\r\n //Job:xxxx Execute a WSF job\r\n //Logo Display logo (default)\r\n //Nologo Prevent logo display: No banner will be shown at execution time\r\n //S Save current command line options for this user\r\n //T:nn Time out in seconds: Maximum time a script is permitted to run\r\n //X Execute script in debugger\r\n //U Use Unicode for redirected I/O from the console\r\n", "runtime_modules": [ "C:\\Windows\\system32\\cscript.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\SYSTEM32\\sxs.dll" ] }, "csrss.exe-7D64128BC1EECE41196858897596EBC8": { "file_name": "csrss.exe", "file_path": "C:\\Windows\\system32\\csrss.exe", "hash_md5": "7D64128BC1EECE41196858897596EBC8", "hash_sha1": "779B8AFC3FA2528B090F400EF3D592E0E2775955", "hash_sha256": "FB40ED0FFA6BC795923A941DAB6B7D6B43583D0F152A6DF4D8953D2C1A0CB417", "hash_sha384": "2826B9684B1297FB729AD0A964CB6FD08FC5EAFC7DE521E9FFB02151A55985F123CBB9F3FA26D692141CFD762FE35D36", "hash_sha512": "23E87A86B1D0B206047DD24ABD053F6C5472CD969A870EEBE7DBF01F0FA3237F77D3AA5D5526D6165DAA21F6ADCE7449E1B838F64AE129B0829CF8B82D40090D", "hash_ssdeep": "192:rnbFaItc7IqC+DlmHW5nnWELKN7OwDBQABJtW7KKEaeqnaj8mOgp22PM:sDUHW5nnWFNHDBRJw/Zell22PM", "hash_imp": "A96FA9912E09E361274AD77F1A4B252C", "hash_pesha1": "DE0BBE376A6C75AA21D1DD642AFE705048B1567F", "hash_pe256": "5541F15C0428407AF00D4F5C7E716DCFB365840B44C9ECBCF6DAAA27866B5789", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Client Server Runtime Process", "meta_original_filename": "CSRSS.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/fb40ed0ffa6bc795923a941dab6b7d6b43583d0f152a6df4d8953d2c1a0cb417/detection/" }, "ctfmon.exe-AFE653CCC2592633C22DD5DA4124AB59": { "file_name": "ctfmon.exe", "file_path": "C:\\Windows\\system32\\ctfmon.exe", "hash_md5": "AFE653CCC2592633C22DD5DA4124AB59", "hash_sha1": "65597164F3BFC193EAC140A8BCA7EAA3FCE8A92C", "hash_sha256": "2D88AB60714D7CAA53B06653CDD31E14093121CEBF3BB7EB7CA0F1B9F04A3A8A", "hash_sha384": "0F35AC7A9427183F31F18C352E013A911F8F774BA6FE6AC23C087A9EE8F80D108A5CF1049A22952DFD99A1F44BD97D77", "hash_sha512": "D2CD6B392C22E6A02CC67BB2D1927298670F47A2CD8C62891EB8D46CD87BAD6FEE2061CECF4E09E450BE2D9AC9673562CFF77AAF5625A578163D0F4AFAF9F432", "hash_ssdeep": "192:jQJ1u2Llzc5pjlPJ3hF+JF+q617XCMW2gW:20KlQXlh3hF+z+qg/W2gW", "hash_imp": "6FD43544FB51C12382CAD7C88F550240", "hash_pesha1": "461B9C0A6701A6EC91034012C22BA4F53F19AD30", "hash_pe256": "74F843A49267EAA3472F9F585F83E741C175DCA106B00E444559E9DA1AF8117F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CTF Loader", "meta_original_filename": "CTFMON.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/2d88ab60714d7caa53b06653cdd31e14093121cebf3bb7eb7ca0f1b9f04a3a8a/detection/" }, "cttune.exe-7573E129035AA191B752FAB5BED546AF": { "file_name": "cttune.exe", "file_path": "C:\\Windows\\system32\\cttune.exe", "hash_md5": "7573E129035AA191B752FAB5BED546AF", "hash_sha1": "AA00D7055E80D942B6B801021830A4EC105DD1DD", "hash_sha256": "232783F87C7DA0F6FA9BAE2FDBDC94095130BAAF2125AFF974BAEFD8EE16C69B", "hash_sha384": "3E5B943CE5921858EC4558ECD6C676BC836DCC11465D2D9D5E75A350D8025BC90880404A2C104B7CCE8BC67C2F2075DB", "hash_sha512": "8BABE22D0DFD05ADED11F9ABF5EF53123EE19A19636BB2BF655A70CBCDA2CEDD4279D6AAA7F12D9CD7420272F214336EBC5D5B57427FC221F604BF1D04106CAC", "hash_ssdeep": "3072:zm4yGRFz+l/tZGacUk8bfkTWVnwqZkvJqxEm4x1ESuQG+3SeyRS6CSfKVu1xgCAo:zNF6dt6U/kiJwqZkvoxEvTEPp/F", "hash_imp": "35651CDC802429DEB29A7C2312B9569F", "hash_pesha1": "67ACF7DED6F21F8960C9702A68F91EC11359097E", "hash_pe256": "301181301F9AFEF0996252348E6808256EFFBAD17CA8D327712E6D377EC5F6C0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ClearType Tuner", "meta_original_filename": "CTTUNE.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/232783f87c7da0f6fa9bae2fdbdc94095130baaf2125aff974baefd8ee16c69b/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\cttune.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1318": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\cttune.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\DWrite.dll", "C:\\Windows\\system32\\OLEACC.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\wbem\\wbemprox.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\system32\\wbem\\wbemsvc.dll", "C:\\Windows\\system32\\wbem\\fastprox.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ], "runtime_window_title": "ClearType Text Tuner" }, "cttunesvr.exe-22C73A156EF2EBC1426B714B5130899A": { "file_name": "cttunesvr.exe", "file_path": "C:\\Windows\\system32\\cttunesvr.exe", "hash_md5": "22C73A156EF2EBC1426B714B5130899A", "hash_sha1": "F00661A56AFBA8D96E225BEECA96476D28C5E115", "hash_sha256": "06B9311698EE2EF39BA44A48B6DA23F678B6F32DFFADFC1FDC9B48E18D3D2838", "hash_sha384": "380EE219227A75D0C6FBE4F1998610D3A321D38FE16BC4F3F6E1312E2D2EBD5BB3D106049599C7DCA3D768B3B0391351", "hash_sha512": "D2756AE96BBE0EE3F786A64A3BB8E691E970C9AC141B1157B645847610881C2D60C9B4FFCECB391A999C09196DAC3344B7218937C0301151605601FB71971C58", "hash_ssdeep": "768:taY+NIPckKZ1d9mD85fV8/WdALEzKZQJL4g1tl1dVldJIdB+62LCVHTv:rTAd5N80tKZkL71tl1dVldGdB+Pszv", "hash_imp": "B4869B44437954AFF623E907CAA503F1", "hash_pesha1": "D30CA1D10753C6006DFB34D941AE76686836460F", "hash_pe256": "803741C470D7C3EF3A12399C97A13B7E21ABE4F59D5B26B07E32D9CA9F5A4E6A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ClearType Tuner", "meta_original_filename": "CTTUNESVR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/06b9311698ee2ef39ba44a48b6da23f678b6f32dffadfc1fdc9b48e18d3d2838/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\cttunesvr.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECEB8": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\cttunesvr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "curl.exe-2419907A0BB9A14F1871F0BDA7F65578": { "file_name": "curl.exe", "file_path": "C:\\Windows\\system32\\curl.exe", "hash_md5": "2419907A0BB9A14F1871F0BDA7F65578", "hash_sha1": "B073B1B84A589B7FEFD380AE9E097C3040E4DD07", "hash_sha256": "C53B0901C262071DA3F3FBB69C30C2C26E2AB7866C7C42183C830B9A609C7994", "hash_sha384": "7A6BA899D9161FA16A78F06F9D67BA8121CDB4DF27451A32F9CEB18ED2FD26265967BEA6A9401CD3773061A811D8FCD7", "hash_sha512": "096C15AF30DB0D69682FB120C5C2E24584D95F4F751F59DD482B65EC513056A046EE9FB6E1AEC99AE44E1EE4053AE226E9D394F9A7AA5CAA974B0A6D1FEE84C6", "hash_ssdeep": "6144:AycXoA0oHKhKkkNc48DD4w8u8L1GtnzuQEqAqM+BbTQhGKgcvQsFME1P9YRS:oxSzx48PlqQsNYFE1P9YRS", "hash_imp": "93009B50C3F15A001009BCDE9939BF92", "hash_pesha1": "C3284E0828587E2D7842DD1693D059F99B90E1B0", "hash_pe256": "8078AC680C937FF8419C0763CF6D51BB66ACB4B7BB0AEAFDBDEED88D609CE908", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "The curl executable", "meta_original_filename": "curl.exe", "meta_product_name": "The curl executable", "meta_company_name": "curl, https://curl.haxx.se/", "meta_file_version": "7.55.1", "meta_product_version": "7.55.1", "meta_language": "English (United States)", "meta_legal_copyright": " 1996 - 2017 Daniel Stenberg, <daniel@haxx.se>.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c53b0901c262071da3f3fbb69c30c2c26e2ab7866c7c42183c830b9a609c7994/detection/", "output": "Usage: curl [options...] <url>\r\n --abstract-unix-socket <path> Connect via abstract Unix domain socket\r\n --anyauth Pick any authentication method\r\n -a, --append Append to target file when uploading\r\n --basic Use HTTP Basic Authentication\r\n --cacert <CA certificate> CA certificate to verify peer against\r\n --capath <dir> CA directory to verify peer against\r\n -E, --cert <certificate[:password]> Client certificate file and password\r\n --cert-status Verify the status of the server certificate\r\n --cert-type <type> Certificate file type (DER/PEM/ENG)\r\n --ciphers <list of ciphers> SSL ciphers to use\r\n --compressed Request compressed response\r\n -K, --config <file> Read config from a file\r\n --connect-timeout <seconds> Maximum time allowed for connection\r\n --connect-to <HOST1:PORT1:HOST2:PORT2> Connect to host\r\n -C, --continue-at <offset> Resumed transfer offset\r\n -b, --cookie <data> Send cookies from string/file\r\n -c, --cookie-jar <filename> Write cookies to <filename> after operation\r\n --create-dirs Create necessary local directory hierarchy\r\n --crlf Convert LF to CRLF in upload\r\n --crlfile <file> Get a CRL list in PEM format from the given file\r\n -d, --data <data> HTTP POST data\r\n --data-ascii <data> HTTP POST ASCII data\r\n --data-binary <data> HTTP POST binary data\r\n --data-raw <data> HTTP POST data, '@' allowed\r\n --data-urlencode <data> HTTP POST data url encoded\r\n --delegation <LEVEL> GSS-API delegation permission\r\n --digest Use HTTP Digest Authentication\r\n -q, --disable Disable .curlrc\r\n --disable-eprt Inhibit using EPRT or LPRT\r\n --disable-epsv Inhibit using EPSV\r\n --dns-interface <interface> Interface to use for DNS requests\r\n --dns-ipv4-addr <address> IPv4 address to use for DNS requests\r\n --dns-ipv6-addr <address> IPv6 address to use for DNS requests\r\n --dns-servers <addresses> DNS server addrs to use\r\n -D, --dump-header <filename> Write the received headers to <filename>\r\n --egd-file <file> EGD socket path for random data\r\n --engine <name> Crypto engine to use\r\n --expect100-timeout <seconds> How long to wait for 100-continue\r\n -f, --fail Fail silently (no output at all) on HTTP errors\r\n --fail-early Fail on first transfer error, do not continue\r\n --false-start Enable TLS False Start\r\n -F, --form <name=content> Specify HTTP multipart POST data\r\n --form-string <name=string> Specify HTTP multipart POST data\r\n --ftp-account <data> Account data string\r\n --ftp-alternative-to-user <command> String to replace USER [name]\r\n --ftp-create-dirs Create the remote dirs if not present\r\n --ftp-method <method> Control CWD usage\r\n --ftp-pasv Use PASV/EPSV instead of PORT\r\n -P, --ftp-port <address> Use PORT instead of PASV\r\n --ftp-pret Send PRET before PASV\r\n --ftp-skip-pasv-ip Skip the IP address for PASV\r\n --ftp-ssl-ccc Send CCC after authenticating\r\n --ftp-ssl-ccc-mode <active/passive> Set CCC mode\r\n --ftp-ssl-control Require SSL/TLS for FTP login, clear for transfer\r\n -G, --get Put the post data in the URL and use GET\r\n -g, --globoff Disable URL sequences and ranges using {} and []\r\n -I, --head Show document info only\r\n -H, --header <header/@file> Pass custom header(s) to server\r\n -h, --help This help text\r\n --hostpubmd5 <md5> Acceptable MD5 hash of the host public key\r\n -0, --http1.0 Use HTTP 1.0\r\n --http1.1 Use HTTP 1.1\r\n --http2 Use HTTP 2\r\n --http2-prior-knowledge Use HTTP 2 without HTTP/1.1 Upgrade\r\n --ignore-content-length Ignore the size of the remote resource\r\n -i, --include Include protocol response headers in the output\r\n -k, --insecure Allow insecure server connections when using SSL\r\n --interface <name> Use network INTERFACE (or address)\r\n -4, --ipv4 Resolve names to IPv4 addresses\r\n -6, --ipv6 Resolve names to IPv6 addresses\r\n -j, --junk-session-cookies Ignore session cookies read from file\r\n --keepalive-time <seconds> Interval time for keepalive probes\r\n --key <key> Private key file name\r\n --key-type <type> Private key file type (DER/PEM/ENG)\r\n --krb <level> Enable Kerberos with security <level>\r\n --libcurl <file> Dump libcurl equivalent code of this command line\r\n --limit-rate <speed> Limit transfer speed to RATE\r\n -l, --list-only List only mode\r\n --local-port <num/range> Force use of RANGE for local port numbers\r\n -L, --location Follow redirects\r\n --location-trusted Like --location, and send auth to other hosts\r\n --login-options <options> Server login options\r\n --mail-auth <address> Originator address of the original email\r\n --mail-from <address> Mail from this address\r\n --mail-rcpt <address> Mail from this address\r\n -M, --manual Display the full manual\r\n --max-filesize <bytes> Maximum file size to download\r\n --max-redirs <num> Maximum number of redirects allowed\r\n -m, --max-time <time> Maximum time allowed for the transfer\r\n --metalink Process given URLs as metalink XML file\r\n --negotiate Use HTTP Negotiate (SPNEGO) authentication\r\n -n, --netrc Must read .netrc for user name and password\r\n --netrc-file <filename> Specify FILE for netrc\r\n --netrc-optional Use either .netrc or URL\r\n -:, --next Make next URL use its separate set of options\r\n --no-alpn Disable the ALPN TLS extension\r\n -N, --no-buffer Disable buffering of the output stream\r\n --no-keepalive Disable TCP keepalive on the connection\r\n --no-npn Disable the NPN TLS extension\r\n --no-sessionid Disable SSL session-ID reusing\r\n --noproxy <no-proxy-list> List of hosts which do not use proxy\r\n --ntlm Use HTTP NTLM authentication\r\n --ntlm-wb Use HTTP NTLM authentication with winbind\r\n --oauth2-bearer <token> OAuth 2 Bearer Token\r\n -o, --output <file> Write to file instead of stdout\r\n --pass <phrase> Pass phrase for the private key\r\n --path-as-is Do not squash .. sequences in URL path\r\n --pinnedpubkey <hashes> FILE/HASHES Public key to verify peer against\r\n --post301 Do not switch to GET after following a 301\r\n --post302 Do not switch to GET after following a 302\r\n --post303 Do not switch to GET after following a 303\r\n --preproxy [protocol://]host[:port] Use this proxy first\r\n -#, --progress-bar Display transfer progress as a bar\r\n --proto <protocols> Enable/disable PROTOCOLS\r\n --proto-default <protocol> Use PROTOCOL for any URL missing a scheme\r\n --proto-redir <protocols> Enable/disable PROTOCOLS on redirect\r\n -x, --proxy [protocol://]host[:port] Use this proxy\r\n --proxy-anyauth Pick any proxy authentication method\r\n --proxy-basic Use Basic authentication on the proxy\r\n --proxy-cacert <file> CA certificate to verify peer against for proxy\r\n --proxy-capath <dir> CA directory to verify peer against for proxy\r\n --proxy-cert <cert[:passwd]> Set client certificate for proxy\r\n --proxy-cert-type <type> Client certificate type for HTTS proxy\r\n --proxy-ciphers <list> SSL ciphers to use for proxy\r\n --proxy-crlfile <file> Set a CRL list for proxy\r\n --proxy-digest Use Digest authentication on the proxy\r\n --proxy-header <header/@file> Pass custom header(s) to proxy\r\n --proxy-insecure Do HTTPS proxy connections without verifying the proxy\r\n --proxy-key <key> Private key for HTTPS proxy\r\n --proxy-key-type <type> Private key file type for proxy\r\n --proxy-negotiate Use HTTP Negotiate (SPNEGO) authentication on the proxy\r\n --proxy-ntlm Use NTLM authentication on the proxy\r\n --proxy-pass <phrase> Pass phrase for the private key for HTTPS proxy\r\n --proxy-service-name <name> SPNEGO proxy service name\r\n --proxy-ssl-allow-beast Allow security flaw for interop for HTTPS proxy\r\n --proxy-tlsauthtype <type> TLS authentication type for HTTPS proxy\r\n --proxy-tlspassword <string> TLS password for HTTPS proxy\r\n --proxy-tlsuser <name> TLS username for HTTPS proxy\r\n --proxy-tlsv1 Use TLSv1 for HTTPS proxy\r\n -U, --proxy-user <user:password> Proxy user and password\r\n --proxy1.0 <host[:port]> Use HTTP/1.0 proxy on given port\r\n -p, --proxytunnel Operate through a HTTP proxy tunnel (using CONNECT)\r\n --pubkey <key> SSH Public key file name\r\n -Q, --quote Send command(s) to server before transfer\r\n --random-file <file> File for reading random data from\r\n -r, --range <range> Retrieve only the bytes within RANGE\r\n --raw Do HTTP \"raw\"; no transfer decoding\r\n -e, --referer <URL> Referrer URL\r\n -J, --remote-header-name Use the header-provided filename\r\n -O, --remote-name Write output to a file named as the remote file\r\n --remote-name-all Use the remote file name for all URLs\r\n -R, --remote-time Set the remote file's time on the local output\r\n -X, --request <command> Specify request command to use\r\n --request-target Specify the target for this request\r\n --resolve <host:port:address> Resolve the host+port to this address\r\n --retry <num> Retry request if transient problems occur\r\n --retry-connrefused Retry on connection refused (use with --retry)\r\n --retry-delay <seconds> Wait time between retries\r\n --retry-max-time <seconds> Retry only within this period\r\n --sasl-ir Enable initial response in SASL authentication\r\n --service-name <name> SPNEGO service name\r\n -S, --show-error Show error even when -s is used\r\n -s, --silent Silent mode\r\n --socks4 <host[:port]> SOCKS4 proxy on given host + port\r\n --socks4a <host[:port]> SOCKS4a proxy on given host + port\r\n --socks5 <host[:port]> SOCKS5 proxy on given host + port\r\n --socks5-basic Enable username/password auth for SOCKS5 proxies\r\n --socks5-gssapi Enable GSS-API auth for SOCKS5 proxies\r\n --socks5-gssapi-nec Compatibility with NEC SOCKS5 server\r\n --socks5-gssapi-service <name> SOCKS5 proxy service name for GSS-API\r\n --socks5-hostname <host[:port]> SOCKS5 proxy, pass host name to proxy\r\n -Y, --speed-limit <speed> Stop transfers slower than this\r\n -y, --speed-time <seconds> Trigger 'speed-limit' abort after this time\r\n --ssl Try SSL/TLS\r\n --ssl-allow-beast Allow security flaw to improve interop\r\n --ssl-no-revoke Disable cert revocation checks (WinSSL)\r\n --ssl-reqd Require SSL/TLS\r\n -2, --sslv2 Use SSLv2\r\n -3, --sslv3 Use SSLv3\r\n --stderr Where to redirect stderr\r\n --suppress-connect-headers Suppress proxy CONNECT response headers\r\n --tcp-fastopen Use TCP Fast Open\r\n --tcp-nodelay Use the TCP_NODELAY option\r\n -t, --telnet-option <opt=val> Set telnet option\r\n --tftp-blksize <value> Set TFTP BLKSIZE option\r\n --tftp-no-options Do not send any TFTP options\r\n -z, --time-cond <time> Transfer based on a time condition\r\n --tls-max <VERSION> Use TLSv1.0 or greater\r\n --tlsauthtype <type> TLS authentication type\r\n --tlspassword TLS password\r\n --tlsuser <name> TLS user name\r\n -1, --tlsv1 Use TLSv1.0 or greater\r\n --tlsv1.0 Use TLSv1.0\r\n --tlsv1.1 Use TLSv1.1\r\n --tlsv1.2 Use TLSv1.2\r\n --tlsv1.3 Use TLSv1.3\r\n --tr-encoding Request compressed transfer encoding\r\n --trace <file> Write a debug trace to FILE\r\n --trace-ascii <file> Like --trace, but without hex output\r\n --trace-time Add time stamps to trace/verbose output\r\n --unix-socket <path> Connect through this Unix domain socket\r\n -T, --upload-file <file> Transfer local FILE to destination\r\n --url <url> URL to work with\r\n -B, --use-ascii Use ASCII/text transfer\r\n -u, --user <user:password> Server user and password\r\n -A, --user-agent <name> Send User-Agent <name> to server\r\n -v, --verbose Make the operation more talkative\r\n -V, --version Show version number and quit\r\n -w, --write-out <format> Use output FORMAT after completion\r\n --xattr Store metadata in extended file attributes\r\n", "error": " % Total % Received % Xferd Average Speed Time Time Time Current\r\n Dload Upload Total Spent Left Speed\r\n\r 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0\r 0 0 0 0 0 0 0 0 --:--:-- 0:00:01 --:--:-- 0", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\curl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\secur32.dll", "C:\\Windows\\SYSTEM32\\SSPICLI.DLL", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\mswsock.dll" ] }, "dasHost.exe-3323FA7D6EBA946EC070186927573E62": { "file_name": "dasHost.exe", "file_path": "C:\\Windows\\system32\\dasHost.exe", "hash_md5": "3323FA7D6EBA946EC070186927573E62", "hash_sha1": "9C733385DC181E27C9E2282CA8766C47D2B4A818", "hash_sha256": "7F2F046AD83E7AC41F4A5F9319AB3564BAC0C91F36C042D08BE2B298BF3F8292", "hash_sha384": "9323BFE1C3B8B2488558415AAEA0DCD8B9C37EC66E1B9C7FA0B58C29B75D9483FC069ECA1465D143063DE6D190AB0016", "hash_sha512": "DB75EFDC6EA8C5CD19BCB98205C715E5A7146B8D2FB82599A496FC7BD8D0E7A882672CED75F00B60F372E84F43736E7BFD608B659391E8A73CD34658A3B54C10", "hash_ssdeep": "1536:a8wrrC7paw1ykiaZbKIWCvywnqnjPnCCCCCCCCTLCCCCCCCCCCTCeqWHi0SbR+JY:MHfki49WCKHnjfCCCCCCCCTLCCCCCCCr", "hash_imp": "1BC45163AAF98E5CA55EA53B525E7010", "hash_pesha1": "182711C5AEBC50D55B958880DDE223FD9AE07A90", "hash_pe256": "76F575E97727877E5EBCC7E8483E17CAF45B275C54B2ED3B9603EBDE4281597A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Association Framework Provider Host", "meta_original_filename": "dasHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/7f2f046ad83e7ac41f4a5f9319ab3564bac0c91f36c042d08be2b298bf3f8292/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\RPC Control\\DSECF3C": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\dasHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "DataExchangeHost.exe-72A9CD3247AABD7564F5D251965965AC": { "file_name": "DataExchangeHost.exe", "file_path": "C:\\Windows\\system32\\DataExchangeHost.exe", "hash_md5": "72A9CD3247AABD7564F5D251965965AC", "hash_sha1": "6993285E53CFE13F2D6AA672591077A2C25C857A", "hash_sha256": "52021E9CA05B48BD4B17E54179BDE71D9664EF6FF81E260B572A1B80CB1B1EBA", "hash_sha384": "1E6CDB34C221EA500FE7F4FC3CAF50464279E8FDB774D4B6617A2755CD611AEDD8B43F1809C00B1428DD6BE59B48868E", "hash_sha512": "458AB35BF607F145D67ED91B1B3FC2771A0CC64AAE0E4F6AA1AE60EAF9B8EC1AA25603B235FCFBCF5A630AF142DD65CB5DAFFD5B1001FDD4BC66B3F36B257BFD", "hash_ssdeep": "3072:Lxe/arPMslKknPnyKQ/fjeVYewbYBIZU0lCL45F1tvoO+MRPTqI7dApus1pSsa4:FeUksIknaxEBjBWU0lfFoONUIuVp1", "hash_imp": "FC5227CF37437AC08B058F1016F70459", "hash_pesha1": "2B8A98C24EADA159CC8A96F2092E3E7B30F7A69A", "hash_pe256": "69336EEC4056FC8AA2963D28E796FBDE60D5C64687635A32DF81736AF625881D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Data Exchange Host", "meta_original_filename": "DataExchangeHost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/52021e9ca05b48bd4b17e54179bde71d9664ef6ff81e260b572a1b80cb1b1eba/detection/", "runtime_modules": [ "C:\\Windows\\system32\\DataExchangeHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\DWrite.dll", "C:\\Windows\\system32\\TWINAPI.dll", "C:\\Windows\\system32\\d2d1.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\system32\\dcomp.dll" ] }, "DataStoreCacheDumpTool.exe-48B9206E498014CF33A625817330A7E4": { "file_name": "DataStoreCacheDumpTool.exe", "file_path": "C:\\Windows\\system32\\DataStoreCacheDumpTool.exe", "hash_md5": "48B9206E498014CF33A625817330A7E4", "hash_sha1": "7F179D5B123D4697F21C9099C607F41CFEBEEFBE", "hash_sha256": "2C67D8B1BA2325D61B7A4CCA7F7A491D31C2CB1EA9522146A12E85EC7B19F86C", "hash_sha384": "D853C78D99168E86B1C1709EE1B82B1E644FA9B4DAA39FF5468999B03687C7B910D8689ACBE3D7746439FC123A1B6255", "hash_sha512": "203AD7C2C105E4D75533F68BDBAD8C7D56FE8690AE14C1B0B871698394555A360AB91FFE424F4CBF92AF89EA287F2B73E0FA4985953AABD7C23638D83CEC4453", "hash_ssdeep": "3072:VHFMuVLmj9ZD1KzZN4EaVa5kWhPJLpFRkLzC/UdF1xF7/i0:VFVLmjHW49Va5kW1bUzJi", "hash_imp": "A01FF0BD6C4A8C092BE972A2EED00430", "hash_pesha1": "E3A95940E75C3EB641AE57462876E1C8FF3D19DF", "hash_pe256": "B33ADA85316BA6F1C10E8CF25A5FA417232884988F1EE1E5B1AEC5BD28B27BD7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/2c67d8b1ba2325d61b7a4cca7f7a491d31c2cb1ea9522146a12e85ec7b19f86c/detection/", "runtime_modules": [ "C:\\Windows\\system32\\DataStoreCacheDumpTool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\StartTileData.dll" ] }, "dccw.exe-2FA157F391C6C8B7A1EC3D5036D78241": { "file_name": "dccw.exe", "file_path": "C:\\Windows\\system32\\dccw.exe", "hash_md5": "2FA157F391C6C8B7A1EC3D5036D78241", "hash_sha1": "30C3A962981CBAFDDA33DA3DCAF5B8ABEB069FB2", "hash_sha256": "DADC160FAD6DA3433FB2BA799FCEF0DA05BBCA754C82B7320D779DBC68BA6909", "hash_sha384": "5BED109D3A2E7A51AF3A3134DC910B4C23D77B626D054CB4760FACA6138F5500A04D545FF1DB3885D302546F0F631123", "hash_sha512": "7B99B7856DE0E3144367530A544FE0946C563EECC741DDECDD939FDAC9B8BAD5AB8D0A44462C96CB8C1698702180C8647E3DED4E31735DC65D09D208425FAE1D", "hash_ssdeep": "12288:yUKWpKGOhS/IzJqrraq/t2qXy6xdRhMA:9K0nGS/EEn/tkI", "hash_imp": "9CCBC0B043B0005011465308DDF20663", "hash_pesha1": "8B6E5EF23ABFEFD5B165E3471FC165ACD8D27866", "hash_pe256": "FD747FDA081C04956A40DDD44EFB03D366D3EC14173532710A444F17391B7885", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Display Color Calibration", "meta_original_filename": "dccw.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/dadc160fad6da3433fb2ba799fcef0da05bbca754c82b7320d779dbc68ba6909/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\dccw.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\dccw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dxva2.dll", "C:\\Windows\\system32\\mscms.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\ColorAdapterClient.dll" ], "runtime_window_title": "Display Color Calibration" }, "dcgpofix.exe-B9EB232A72D4DA051AC75FAD5C5129B5": { "file_name": "dcgpofix.exe", "file_path": "C:\\Windows\\system32\\dcgpofix.exe", "hash_md5": "B9EB232A72D4DA051AC75FAD5C5129B5", "hash_sha1": "E63D8A94BFBF425E302B5E8281CC5AFDE38E4D30", "hash_sha256": "E6C6951CCA541FF83DA924C6B15EFED8101A08F863CA44AFCC8128C63379E53B", "hash_sha384": "87AD6019DFA4ACA066C109175FDF9E1369321F1440C2D98BAADDFE84AB3836D7557D44F75B4CD34F72CEA4AC0F1CB5AA", "hash_sha512": "651C3F9493B7D3B283E9CE654F9F1AD64243FE18A1BAD2699C173BEB041FA4E650F3A1DC5E22B106D99C5C72EBEBDAA5818784F7B0DC26BA27E6DFF8D9736AA9", "hash_ssdeep": "1536:JMXeKJD8lAN7EYJFQJlrxx+p0boBqRVIJUy:AkriuJxT+p0boBaqJ", "hash_imp": "D58CDC9ADABD63CD50BB2E1BD9868ACA", "hash_pesha1": "8A0DB0635ED958B31F4F08E8BB4B470A6105DDFA", "hash_pe256": "81F468EAEDBB620A156D570DC0EEB3A00508FB11EF642982AE30D7A1E5D3EEB2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (C) Default Group Policy Object Restore Utility", "meta_original_filename": "DefaultGPOFix", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nMicrosoft(R) Windows(R) Operating System Default Group Policy Restore Utility v5.1\r\n\r\nCopyright (C) Microsoft Corporation. 1981-2003\r\n\r\nDescription: Recreates the Default Group Policy Objects (GPOs) for a domain\r\n\r\nSyntax: DcGPOFix [/ignoreschema] [/Target: Domain | DC | BOTH]\r\n\r\n/target: {Domain | DC | BOTH}\r\nOptional. Specifies the GPO to be restored: the Default Domain Policy GPO, the Default Domain Controllers Policy GPO, or both.\r\n\r\n/ignoreschema:\r\nOptional. Use this switch to enable this tool to ignore the schema version of Active Directory. Otherwise, this tool will only work on the same AD schema version as the Windows version in which the tool was shipped.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\dcgpofix.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dcomcnfg.exe-2230E122EB447CBC9EAAE68AF853F3B7": { "file_name": "dcomcnfg.exe", "file_path": "C:\\Windows\\system32\\dcomcnfg.exe", "hash_md5": "2230E122EB447CBC9EAAE68AF853F3B7", "hash_sha1": "3A43D052EAB26653625DE7165759DB5B562391B9", "hash_sha256": "3D81ACA24167405433617B364C23C51393C31597DA36A48476FD59549A2D0A99", "hash_sha384": "92C4AB6B2B20DB462360F92E3F421E3AE7B2A8019F734ED85E876B418455D67D04F3F79AE16B0B5C7188B55E5FFD49FA", "hash_sha512": "3490BF51E8DCDB307591F22AFDCDF2948716CD2592065A7B0920D47A200AEFB9758C74816B5F5D0FD80C04C6DE36F6736BF20F40AF21D66CD1C39E6EB185A3A9", "hash_ssdeep": "192:M8Wc+Sfv9pI82dlXUqYLHhIekoW7acSQvnbvGo/CDf1W0EW:M8WjS3PrclXUqYLBZk57a2vnbvqW0EW", "hash_imp": "4C7F165DA8DA80935D61C0512A3469C1", "hash_pesha1": "311AE8188DA4BCC4B033846BB09BEEC9D7CA9940", "hash_pe256": "B6360DE206DEF9F808561D24E5D715178AA0DBBAC3D6D8E8E956517272A29C58", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+", "meta_original_filename": "DCOMCNFG.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/3d81aca24167405433617b364c23c51393c31597da36a48476fd59549a2d0a99/detection/", "children": "mmc.exe", "runtime_modules": [ "C:\\Windows\\system32\\dcomcnfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "dcpromo.exe-B3A3293FE670FCC5FA3F520FF21BEDBD": { "file_name": "dcpromo.exe", "file_path": "C:\\Windows\\system32\\dcpromo.exe", "hash_md5": "B3A3293FE670FCC5FA3F520FF21BEDBD", "hash_sha1": "A78C34F665975F418131F1622B77E42501BDC95A", "hash_sha256": "DC0761B7C8B4732715674E7D5CADEB3BB4917A48ECDFE37200236A112A10C76F", "hash_sha384": "50E5FFBBF8D81D0C2F15B959408C9E7A9B240BE091EED9C3B64C5367B88F7269C8BA2EAEE1AB89F33AD57273C404FAC0", "hash_sha512": "0EDCA15F512FE65780533631229A744574CCC8AFDBEED6EDEF8529213F8F7F0D57023B87A0A181D77BB346BF178239541398BDFAE97451AA3785AC3C15CCBC18", "hash_ssdeep": "6144:Wnw7PfVxVxjFxmM/HeWjq32r6AjhRZaghY:WnKPfVLnsM/HeMTQg", "hash_imp": "A15203373C362CB4816E21E34638E78A", "hash_pesha1": "B73391A011FC318CC088C282AD03C7DF640A4060", "hash_pe256": "432382259F5BDFD753450F3CB8A9B13F2920F7FCD7C830DC4864A3369A378ACA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Active Directory Domain Services Installer", "meta_original_filename": "dcpromo.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/dc0761b7c8b4732715674e7d5cadeb3bb4917a48ecdfe37200236a112a10c76f/detection/", "children": "conhost.exe", "output": "The specified argument 'help' should start with '/' or '-'.\r\n", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\dcpromo.exe.mui": "File", "(RW-) C:\\Windows\\debug\\dcpromoui.log": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\dcpromo.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\system32\\NETAPI32.dll", "C:\\Windows\\system32\\DSROLE.DLL", "C:\\Windows\\system32\\NETUTILS.DLL", "C:\\Windows\\System32\\IMM32.DLL" ], "runtime_window_title": "Active Directory Domain Services Installer" }, "ddodiag.exe-DECF7B40F170889DA82C0F54749AE3E9": { "file_name": "ddodiag.exe", "file_path": "C:\\Windows\\system32\\ddodiag.exe", "hash_md5": "DECF7B40F170889DA82C0F54749AE3E9", "hash_sha1": "FC1EBF9FBE414AA772382784B6C9B5EED6518B14", "hash_sha256": "A67110C259924E1DE43D648C700337226E57D6DF55099CAC5D4602137706BC81", "hash_sha384": "59F9D4303E65AA252CADB333A40FEFADBF1B2E2D651EB10502E16FBCFE93C95408371608D79035DD0A5C6CF0363B5688", "hash_sha512": "5279FE7CA4214700944BB1146D160D12E76C62F8F3C9DE24EACD00B25A530FC45286ECA9F675E4CE48DF4DEB94F9608E6A82E244897CC31EB3FDA22A72CCDE92", "hash_ssdeep": "768:ugN8V3tWzMtfY6RGK/hc3aZkLmMgMaouZl6iSSpottXT:0dVfY6RGK/hc3aZkLmMgMaouZl6iSZtD", "hash_imp": "AD808CB5DB2E29BB8CC94083572DF977", "hash_pesha1": "E1FDACAA2CC91C0213D966DE54F3CF0082C758F4", "hash_pe256": "D0619014F04A8ED5D324702E417FE839257BDD116CFEFB070FE923710300742D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DDODiag is a tool that collects Device Display Object (DDO) information from the system and logs it", "meta_original_filename": "DDODiag.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a67110c259924e1de43d648c700337226e57d6df55099cac5d4602137706bc81/detection/" }, "Defrag.exe-D340F5AE00E1C33F8BDC538D9888C459": { "file_name": "Defrag.exe", "file_path": "C:\\Windows\\system32\\Defrag.exe", "hash_md5": "D340F5AE00E1C33F8BDC538D9888C459", "hash_sha1": "76B4944AD561C2E5B33971BF84408EB5B65E421C", "hash_sha256": "E97F31C6A63C8FE8176892DA0D993B6D7DC9FE8850C91F1FA95C7FCB0177AD65", "hash_sha384": "11768410E9FB425D93386AF531435081D1B8F8DDA74EA6A2C2B4144BFE1BE2893FE89EB6CBDFD237C8DC6D89D52518E6", "hash_sha512": "826A7746CD8F52C2F9CC9F72CF021FC16178ED489D1F04E03CCC8302691DBC861ED741A6C11FB25A249D72537F5947E161F5CAF11CE15530D21B2073D52AEFBC", "hash_ssdeep": "3072:jraLDabiUpYXN9XK3HbnQb4C6c5Q3eSjlR+8qxLijgJyfFOG83Yj34YFnw6OC2cs:6faOU42rt3lRGOUZGKc4YFnwjCpW", "hash_imp": "C451FEB9457D50EB689BA55A85F91B2C", "hash_pesha1": "44CF6DBB2A21F758863F0DC1D4CF10781B0EC98D", "hash_pe256": "AC77C2EB356ABDA9D5343F6D35BB960672A1B2AEEB6BC5DBB4757CB579861004", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Defragmenter Module", "meta_original_filename": "Defrag.EXE.MUI", "meta_product_name": "Windows Drive Optimizer", "meta_company_name": "Microsoft Corp.", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corp.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/e97f31c6a63c8fe8176892da0d993b6d7dc9fe8850c91f1fa95c7fcb0177ad65/detection/", "output": "Microsoft Drive Optimizer\r\nCopyright (c) Microsoft Corp.\r\n\r\nPlease specify a volume to perform the operation on. (0x89000007)\r\n\r\nDescription:\r\n\r\n\tOptimizes and defragments files on local volumes to\r\n\timprove system performance.\r\n\r\nSyntax:\r\n\r\n\tdefrag <volumes> | /C | /E <volumes> [<task(s)>] [/H] [/M [n] | [/U] [/V]] [/I n]\r\n\r\n\tWhere <task(s)> is omitted (traditional defrag), or as follows:\r\n\t\t/A | [/D] [/K] [/L] | /O | /X\r\n\r\n\tOr, to track an operation already in progress on a volume:\r\n\tdefrag <volume> /T\r\n\r\nParameters:\r\n\r\n\tValue\tDescription\r\n\t/A\tPerform analysis on the specified volumes.\r\n\t/C\tPerform the operation on all volumes.\r\n\t/D\tPerform traditional defrag (this is the default). On a tiered volume\r\n\t\tthough, traditional defrag is performed only on the Capacity tier.\r\n\t/E\tPerform the operation on all volumes except those specified.\r\n\t/G\tOptimize the storage tiers on the specified volumes.\r\n\t/H\tRun the operation at normal priority (default is low).\r\n\t/I n\tTier optimization would run for at most n seconds on each volume.\r\n\t/K\tPerform slab consolidation on the specified volumes.\r\n\t/L\tPerform retrim on the specified volumes.\r\n\t/M [n]\tRun the operation on each volume in parallel in the background.\r\n\t\tAt most n threads optimize the storage tiers in parallel.\r\n\t/O\tPerform the proper optimization for each media type.\r\n\t/T\tTrack an operation already in progress on the specified volume.\r\n\t/U\tPrint the progress of the operation on the screen.\r\n\t/V\tPrint verbose output containing the fragmentation statistics.\r\n\t/X\tPerform free space consolidation on the specified volumes.\r\n\r\nExamples:\r\n\r\n\tdefrag C: /U /V\r\n\tdefrag C: D: /M\r\n\tdefrag C:\\mountpoint /A /U\r\n\tdefrag /C /H /V\r\n", "runtime_modules": [ "C:\\Windows\\system32\\Defrag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\SXSHARED.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "desktopimgdownldr.exe-A6DAD18B0AA125535C7FB9BBFDA25266": { "file_name": "desktopimgdownldr.exe", "file_path": "C:\\Windows\\system32\\desktopimgdownldr.exe", "hash_md5": "A6DAD18B0AA125535C7FB9BBFDA25266", "hash_sha1": "BCDDCFFCA3754875261EF1427EC4F5F4BFB8C2CE", "hash_sha256": "0A6A2690C68CF685D8FCC9F3EA78C35BBF6F296B7B33C956B39400DF749DBC78", "hash_sha384": "A2A6A2AB35ABE8A3243DAA61F3271D897141DBA8B67DB9EB75C63A0217883C96A127767F48C4F808AECF3C9D356AD767", "hash_sha512": "524000008EA887067422943C34489E2F73DA17C194A36B5929C8E5783FF3CCC5FCCFA66F4663A58A8B9EDCC64DFAE1485139D153AEBC67D6FF4C5688B4579439", "hash_ssdeep": "1536:x1QqAHgKLYb9GoboIdVEVLbIafdXRXnwW4sO0lZTJOd2:xsAlUITE5HVXRXnwW9Ow5JJ", "hash_imp": "F8D617766CF1026390A712DFC1AE2EDA", "hash_pesha1": "73362A8848700DF46375F56BB90ECDBED4B54678", "hash_pe256": "E27EA5D623865C81054AF196AE390E289C5EC88004763719E726A06CD3BDE6EB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "desktopimgdownldr.exe", "meta_original_filename": "desktopimgdownldr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/0a6a2690c68cf685d8fcc9f3ea78c35bbf6f296b7b33c956b39400df749dbc78/detection/" }, "DeviceCensus.exe-ABA7E7513886979AF8A3B68A1F4E591D": { "file_name": "DeviceCensus.exe", "file_path": "C:\\Windows\\system32\\DeviceCensus.exe", "hash_md5": "ABA7E7513886979AF8A3B68A1F4E591D", "hash_sha1": "A94E7B939A8A1007F6719503BE54A09F64801AC7", "hash_sha256": "AFD0D80A782E9392664CA32811055B958BD4D373F4F2BA52BFA8F7FE9C893190", "hash_sha384": "C17CC639144ADFCF68DEE0B8E98F82AFAC4F94E71651838090E22B4D87050D0F190E6F4107B17385DEB7FADD8F37EA51", "hash_sha512": "009BC8CC1F65585642813222884D2BE1882C0A09981DC4CC947925FEDEDAB9F8368DC19A1E9BF012477C68826B961134E96B90AE01DED6535A1F3F8AB1AC42DA", "hash_ssdeep": "384:1hbaEPVaYmPw5gyLjuCrHGOl2R3qj37nec/gWJXn7fRUWbgWPc32Kr6wDDBRJNSk:LmEsxwGPcrl08Cc/giXn7nSdr6wD1PSA", "hash_imp": "69755EB5A4F06F0B816F7B23B33E44E8", "hash_pesha1": "6522AD1A8757A9F38761C7E46AFCE10B8A2FF8F2", "hash_pe256": "FAE15D42944FDAE6A68B1E5A83CCB5055F781C909009C3F44CAA668D4BA36E23", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Census", "meta_original_filename": "DeviceCensus.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.19645.1016 (WinBuild.160101.0800)", "meta_product_version": "10.0.19645.1016", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/afd0d80a782e9392664ca32811055b958bd4d373f4f2ba52bfa8f7fe9c893190/detection/", "runtime_modules": [ "C:\\Windows\\system32\\DeviceCensus.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\dcntel.dll" ] }, "DeviceCredentialDeployment.exe-1291D3FEF05BD0E19ABB25CF793AE0A2": { "file_name": "DeviceCredentialDeployment.exe", "file_path": "C:\\Windows\\system32\\DeviceCredentialDeployment.exe", "hash_md5": "1291D3FEF05BD0E19ABB25CF793AE0A2", "hash_sha1": "4EF0B1F8529094170C74B43DA8ECFAFF4DC23AB7", "hash_sha256": "3274D12CDB16A7F44A96335AE17151C6C8667FBFE36E4C11EDC9D1B825078E17", "hash_sha384": "89FB08843EBCC4528763F021E15D06A5FBC09B5ABC31070D27EAD6F5B0969E3222C3D2523342D619824C143A117F6751", "hash_sha512": "325C083838F8C2709331C9E34421F737EADED2B42B68B0112CA010F03E914DCC72AC39BE623288418BECA40E5126F1A458ACF255E1595D30EF6B7B639587FD01", "hash_ssdeep": "1536:oL2smQbOqBxE3DFoeAkKg4g7VXoSuoi3ugNBOl8tPxxNfhIAjy8:ylzE3DFoeAkKg9XoSuoi3ugNBNtPxfpv", "hash_imp": "97F75D693CAACCC77367970A720F6F65", "hash_pesha1": "CE9EB2725EC959E7103A8F382464E22B6457905C", "hash_pe256": "0BB86755C618F9D4AEDEB01986981940447C2D2E65DD6D74E8140F0626B24F44", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "\"DeviceCredentialDeployment.exe\"", "meta_original_filename": "\"DeviceCredentialDeployment.exe\"", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/3274d12cdb16a7f44a96335ae17151c6c8667fbfe36e4c11edc9d1b825078e17/detection/", "runtime_modules": [ "C:\\Windows\\system32\\DeviceCredentialDeployment.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DeviceEject.exe-CC08386BEF1A9846F41D1F7381B5661E": { "file_name": "DeviceEject.exe", "file_path": "C:\\Windows\\system32\\DeviceEject.exe", "hash_md5": "CC08386BEF1A9846F41D1F7381B5661E", "hash_sha1": "C9D794326C056DCAD60CA562A30A2521E73994F9", "hash_sha256": "8C7D1A4A1F1F8732A92EB1EDF3384C0B5496246A40A88165D9845A805A90899B", "hash_sha384": "ED4E1EC83DFE712030E914AD8FBB389C4A133095A6694A6B93467DCC5F9BF56FB5586493BCFC3D19BBF6D5A002C4E840", "hash_sha512": "89D2DB9578C07BBBEEB7466867B29C95FF70310C33A86CAB9E57C8959F779C9AA68012C6D58A96BCD6A140B0D4392E166F9C6AD087E6C4D6EB2DB788EF6736F3", "hash_ssdeep": "384:9EOZmrWEcZ3e9kLilvWsR9wLXjoGOTZWqBfynSWU5947lTwWNwWmJY0ehA/9gnl0:9Ey/pe1AsUxek+Ie5glvoJYQ/9gnl0", "hash_imp": "AB64CAD77300884807D6A17DC89ED1A4", "hash_pesha1": "22A1736EFA5C1B220AD68484C6169C53D25C88B0", "hash_pe256": "829749F79C5D0D3764A7F08C6AA9FF6AF95C22014DC43D4DC7F55DB3C58D5845", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Eject Device", "meta_original_filename": "DeviceEject.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/8c7d1a4a1f1f8732a92eb1edf3384c0b5496246a40a88165d9845a805a90899b/detection/" }, "DeviceEnroller.exe-3F35801C79C2EA45ABB85645DA66D7E6": { "file_name": "DeviceEnroller.exe", "file_path": "C:\\Windows\\system32\\DeviceEnroller.exe", "hash_md5": "3F35801C79C2EA45ABB85645DA66D7E6", "hash_sha1": "997A0BC3C35CBA9863057F758F2D34F0864BCBE9", "hash_sha256": "A3B38A659B9939703CB31A819288C711450CE1135C0143329801F8CABEE0D288", "hash_sha384": "32FCDA6110776D68E6EF0A1DF316E7CE1C41C74071BC13E084DD9F5AE2D8FBA0E4AD22612E4D64BAD0F052ACC4B3928E", "hash_sha512": "E326390046437A14BA4111388E892AD673B606C1305D2FFC60653D9273206C65E6334A85F80AAC881EA57152AD186B83B585FB722903087D8099E778D29CFC73", "hash_ssdeep": "6144:j/xk5py+XqCdPWzskwq3j0QPkl0VI1kFqQOQ2DrRaOQQJK4k:azyqPWzskwq3oQPklHSOrRmB4", "hash_imp": "2ED7EADD460E2FCDF75F4C11011A4EBD", "hash_pesha1": "8ACA85F9B33AA79817783534ECA9BA64F0659A0F", "hash_pe256": "A62D22E765C8D985D4FBB9BA2AD57C6FE2FAF27AD7B6303DF4D8FD20CDEE163D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "API for MDM Enrollment", "meta_original_filename": "deviceenroller.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.831 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.831", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/a3b38a659b9939703cb31a819288c711450ce1135c0143329801f8cabee0d288/detection/", "runtime_modules": [ "C:\\Windows\\system32\\DeviceEnroller.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\dmEnrollEngine.DLL", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\system32\\dmenterprisediagnostics.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\system32\\iri.dll" ] }, "DevicePairingWizard.exe-D1D2077CFFDFA3AA3D8B0D165E0D4056": { "file_name": "DevicePairingWizard.exe", "file_path": "C:\\Windows\\system32\\DevicePairingWizard.exe", "hash_md5": "D1D2077CFFDFA3AA3D8B0D165E0D4056", "hash_sha1": "40BB0E12D4F1F179E1AE3EE92930EE0EF9DB9616", "hash_sha256": "1003A2E8786EF3F2BDB2C9A017DD5712192EB2C2AC88C296FA290B7F15C47EFB", "hash_sha384": "0DD7CAFD3D412FF8F248FFBA85CB1B8F5C115A23BF750963D68FC3ACCD5D4CE46463E2C1FB329C04A4B61F9029F76EE1", "hash_sha512": "9706DB92DA5939A5704085C8F22E5BD9586BB2BDC468EE988A1962AE7FBCEE3FB7D844EB9C99FF02A864CDA2DD8F3DB40CAE21BAAC544E1FFD096A7993617D39", "hash_ssdeep": "768:pjNfqeerm2QoU47ltKE92Djb+e7Ynn7IiE1+t3+kxGyTHA4G0In3BhzhWM1GOVzh:tN72QoptKDwn7IiEwtLxGyTHqZ3qOTf", "hash_imp": "048D96A843A6DF20276E268A873746A7", "hash_pesha1": "1287FD773F3A100EEFF201A546D1BCACE45F29A5", "hash_pe256": "FA8E9F5F57B9D27ED492F1E6E06ACECD25A44C1CB5E1B85F0AA87020725D9E0F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Pairing Application", "meta_original_filename": "DevicePairing.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/1003a2e8786ef3f2bdb2c9a017dd5712192eb2c2ac88c296fa290b7f15c47efb/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC504": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\DevicePairing.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\DevicePairingWizard.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\DevicePairing.dll", "C:\\Windows\\System32\\SHCORE.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\Windows.UI.Immersive.dll", "C:\\Windows\\System32\\deviceassociation.dll", "C:\\Windows\\System32\\DUI70.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\System32\\DevicePairingProxy.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\Comctl32.dll", "C:\\Windows\\System32\\DUser.dll", "C:\\Windows\\system32\\xwizards.dll", "C:\\Windows\\system32\\xwtpw32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\xmllite.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\System32\\PROPSYS.dll", "C:\\Windows\\system32\\OLEACC.dll" ], "runtime_window_title": "Add a device" }, "DeviceProperties.exe-24AC8FD0EA0CDE206D34CD41C7168248": { "file_name": "DeviceProperties.exe", "file_path": "C:\\Windows\\system32\\DeviceProperties.exe", "hash_md5": "24AC8FD0EA0CDE206D34CD41C7168248", "hash_sha1": "7D017E33B89F2F15C96153D13C868E9C583C0411", "hash_sha256": "45AE712FCF3B3F5259C850D4BA0531AD656F6C770155D0BB306E1637C1C7FD6B", "hash_sha384": "6D3159730042AF3D14B750C901F42C2197AC82EDA62896F1B80A6F6733A621D06066C90D9AE8A3405D7C60A9FEB17172", "hash_sha512": "914E76E3CECF4B5209CDDFC8B4D0BDDC37D1A5D96FDD8A2C0F9C6655F0EF5E8667A6DE21A0993191280AE3B772EF397B6B064D9329FCF971EA82557E39B00613", "hash_ssdeep": "1536:8Z/fI2y5nNWLJpBpTybQ74i6u0dw9Wegi85mChdlzwCxi658:8xI55NOFpTyIcuz9WzF4Chdlzri6C", "hash_imp": "987DCEE8E6AD88968255DA46F110A7CB", "hash_pesha1": "AC6EA470177DBFB8A63FD2461DD729BACFF8F58F", "hash_pe256": "99D8894A31C2FD9CF5D588C4C1DE0D70ED3DE48A6A4541B9D9A667001E680876", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Properties", "meta_original_filename": "DeviceProperties.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/45ae712fcf3b3f5259c850d4ba0531ad656f6c770155d0bb306e1637c1c7fd6b/detection/", "runtime_modules": [ "C:\\Windows\\system32\\DeviceProperties.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "DFDWiz.exe-DAEDF5E7E9522E3E415108E6F58739C0": { "file_name": "DFDWiz.exe", "file_path": "C:\\Windows\\system32\\DFDWiz.exe", "hash_md5": "DAEDF5E7E9522E3E415108E6F58739C0", "hash_sha1": "D579F7E5185F66B0D62B2C9501787B150AC1C184", "hash_sha256": "6B2EEA8205FB9A603F49A638CFBA45A0C32D71C8F26E9B10CB01050B42FD0BD8", "hash_sha384": "1C4D623B284086B03EDECDF32B54F040A9E11F5AFD5D15BF471328251E5C1561B3E4128FA79E92A43D2C91EED7D65ACC", "hash_sha512": "96497B8F281687E7DA6B46254CC899B040ED6DA4C64E9D3FA952A9876BE300F0031B9BC6ADAE4FAD71473BDE1A27B646F79B29BF0BB59D998730F2050F731622", "hash_ssdeep": "768:H4xb57nT2FZlJ5Abtf3ifC5dVtgy1tG78AUsj6o3BlQA6UreK:GJKFA1NTg/8AUTo3BSlB", "hash_imp": "E513C960F7D5AA8D43E2A5AA898DD995", "hash_pesha1": "4A1FAFA0E7066A8BF4746C5456423B27B9838223", "hash_pe256": "9634C78B263EC083FE9FA127B5181020430192BAC781432405E957F1F708C7AA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Disk Diagnostic User Resolver", "meta_original_filename": "DFDWiz.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/6b2eea8205fb9a603f49a638cfba45a0c32d71c8f26e9b10cb01050b42fd0bd8/detection/", "runtime_modules": [ "C:\\Windows\\system32\\DFDWiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\taskschd.dll" ] }, "dfrgui.exe-5D773715386E186D1FAEADDA6AA75384": { "file_name": "dfrgui.exe", "file_path": "C:\\Windows\\system32\\dfrgui.exe", "hash_md5": "5D773715386E186D1FAEADDA6AA75384", "hash_sha1": "9E2943C80F53AC3013D9C106649114CDFE0DCE3B", "hash_sha256": "9487BAB1AD799898C56F328FD74D92A99E8FE9983B33D5E60A70C58069310D60", "hash_sha384": "5DC264C8B257093FA7DF63549D04ED2B29BBB56D213908604644D5CCA73AC60C6474E8AFE77B1B7D47DC7C066C689730", "hash_sha512": "0B55FC0CCF859D80EEAE771D2CBAC4920931E0964A0A2B0DE3CCE8F552A2BC1A3F8BA1A90361BA880F04446DCFA2072FF48511B8F9AEECDF71A8A0CCC2D01B63", "hash_ssdeep": "12288:P393ZejWw8Xd3lRkRc4YFwjsWOfRg6gtPbcTTn7qxerx7:Pp4XWd3/kRc4l6g6gtPbcHn7q", "hash_imp": "DBC6A511D0953EA43092B8A6949494BB", "hash_pesha1": "3223AD7FDF320BB9C3CC4BBBF8202D012ED5BC84", "hash_pe256": "68BD4A30CF73185A0BFA8719E86D864D7899D55DA99C79E4064D1395DC7869FC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Drive Optimizer", "meta_original_filename": "lhdfrgui.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/9487bab1ad799898c56f328fd74d92a99e8fe9983b33d5e60a70c58069310d60/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\DfrgUI.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECC14": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\dfrgui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\SXSHARED.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\defragproxy.dll", "C:\\Windows\\System32\\taskschd.dll", "C:\\Windows\\System32\\SspiCli.dll", "C:\\Windows\\System32\\XmlLite.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\propsys.dll", "C:\\Windows\\system32\\WindowsCodecs.dll", "C:\\Windows\\System32\\thumbcache.dll", "C:\\Windows\\SYSTEM32\\policymanager.dll", "C:\\Windows\\system32\\msvcp110_win.dll" ], "runtime_window_title": "Optimize Drives" }, "dfsrdiag.exe-1B372DB4C30EF438EA4BF06C2794744A": { "file_name": "dfsrdiag.exe", "file_path": "C:\\Windows\\system32\\dfsrdiag.exe", "hash_md5": "1B372DB4C30EF438EA4BF06C2794744A", "hash_sha1": "8C8FFE4A18CF268C4BDB9918F329BF9B8108F5E0", "hash_sha256": "1C5B4D77AC17CE224FDB1354B75ADFBB411A8BDDD2F3FB5174CC5341128BAD1E", "hash_sha384": "E11623ED788B7C5DE5EFE4D831E74B11132C982A000B4931E6E6F4618D0A67379D56D0EE22228AE94F008D6990A2B728", "hash_sha512": "3B9701FF13DBEDE274833FB81A599E4548B600706DE408849FE0A3DBA54829823CD48773B23602533F42BD1E8C308F1699D770CE7540AFB8744B07A270597360", "hash_ssdeep": "49152:mEvW2r8faYvZ7OMM0ZHuBVCc4MsuW4O3hm1cxarJ3YK/5TRE5PX:mEvW2r8faYvZ7OMM0RyUIjY", "hash_imp": "3B33F6CADE6896FA67F2374E4B8E27C3", "hash_pesha1": "8DB5E6020AA351CAE01042F35DAD0CF16E5873DC", "hash_pe256": "770B480587D577AFBE50D7E386FC5731462C7EFF069ABFB53038443360546721", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DFS Replication Diagnostics Tool", "meta_original_filename": "dfsrdiag.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.529 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.529", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/1c5b4d77ac17ce224fdb1354b75adfbb411a8bddd2f3fb5174cc5341128bad1e/detection/", "runtime_modules": [ "C:\\Windows\\system32\\dfsrdiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "output": "[ERROR] Unknown Command <--help>\r\n\r\n\r\nDFSRDIAG - DFS Replication operational and diagnostics command line utility\r\n SyncNow - Forces replication over a given connection; ignore\r\n schedule for n minutes\r\n StopNow - Stop replication over a given connection; ignore\r\n schedule for n minutes\r\n PollAD - Trigger a sync with the global information store in\r\n Active Directory Domain Services\r\n DumpAdCfg - Dump AD configuration settings pertaining to a certain\r\n member\r\n DumpMachineCfg - Dump service-wide configuration of a given server\r\n hosting the DFS Replication service\r\n StaticRPC - Set static RPC port for DFS Replication\r\n Backlog - Display the backlog of replication data to send from\r\n one replication group member to another replication\r\n group member\r\n GUID2NAME - Translate GUIDs to user friendly names\r\n PropagationTest - Test replication progress by dropping a test file under\r\n replicated folder\r\n PropagationReport - Generate a tracking report for the replication progress\r\n of the propagation test file\r\n FileHash - Displays a hash value identical to that computed by the\r\n DFS Replication service for the specified file or\r\n folder\r\n IDRecord - Displays the contents of a replicated file's ID record\r\n ReplicationState - Displays the updates that are currently being\r\n transferred on inbound and outbound connections\r\n\r\n" }, "dialer.exe-03A3A40DCEAF13FDE10ECA591D92DB4B": { "file_name": "dialer.exe", "file_path": "C:\\Windows\\system32\\dialer.exe", "hash_md5": "03A3A40DCEAF13FDE10ECA591D92DB4B", "hash_sha1": "0197C751EDEA68BD0639E9BC57AC132D707591D2", "hash_sha256": "D628E54194E14F8077B283ADC60EF069B4D43543FA7D7BE55E1A60E65AC52C01", "hash_sha384": "A6A27875898DF0E8CAD823479479CBCB70F29F0E3B91E63B3ADDC9EDDE72EBDAAEB215D07C31E950534B323A1DC6E052", "hash_sha512": "1DED4CA2A0A3480474DE49D5BD37B3EE01A7B27479B55CF21E5840B459B3EC87A3BEFCA3FA7602696E42A58B52A1AD2AA7CB5204118801704CFC3CF2AA815538", "hash_ssdeep": "768:RCnwJHY47PQznCKSEYp6qN7O7wz59hF7VRI4C3hD7Oi7/d:1YUPR4aOoFTbKhD7F/d", "hash_imp": "EA84F2A49408D51D324DE27B0D115B5E", "hash_pesha1": "0869C50ABEC9AA2CA89516B42D888DA6B92766F2", "hash_pe256": "838863A45EC412CE864CB5B99E732DFA22F54EAA153A1BC43FCB3A4080239705", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Phone Dialer", "meta_original_filename": "DIALER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/d628e54194e14f8077b283adc60ef069b4d43543fa7d7be55e1a60e65ac52c01/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\dialer.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\dialer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\TAPI32.dll" ], "runtime_window_title": "Phone Dialer" }, "DIMC.exe-EA8A0C993231DA2150F5F6DC378EF811": { "file_name": "DIMC.exe", "file_path": "C:\\Windows\\system32\\DIMC.exe", "hash_md5": "EA8A0C993231DA2150F5F6DC378EF811", "hash_sha1": "5496F9F70767F0888B005F1E8BA59800FC4C8988", "hash_sha256": "67A0B476403215532896B12B7C20C2C49651B866AD323F729B668BAEAD241B3E", "hash_sha384": "25562F91FB27ED668C7B0ADD79E87BF69C511DEC4712BD930B1B8A5517BF57BF886C857FA074F807FCB073EE68B50F7F", "hash_sha512": "4DC3C2C68051902010760ABC35AED644EAE8877A469FFB8138F8CFA45AAC11D70FD99A76ABF935175E07F944A935A3F0F60A4D6A34C10FF3AE7148E34A6DD734", "hash_ssdeep": "384:SNxGBuBvyliu1gEcsyGLDVCPTgx2FAzYv7fHmwsFUO9/0Kh1l2mfOi4YPMhp4Rt3:1lsVGHWT7kYvT3YZmi4YPMhp4R/1", "hash_imp": "40A37D1A738E3858103FA2253CD7FCA2", "hash_pesha1": "040590F8719AF5F356BE970868A6730BA75A9462", "hash_pe256": "2A24A8890B5C6FE9D058B23F34B98CC36D88CC4C956585C1933BB8954D3759C5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Deployment Initial Machine Configuration Tool", "meta_original_filename": "DIMC.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/67a0b476403215532896b12b7c20c2c49651b866ad323f729b668baead241b3e/detection/", "output": "\nDeployment Initial Machine Configuration Tool:\n\nUsage: DIMC.exe -UnattendPath <Unattend_file> -HivePath <IMC_hive> [-SequenceNumber <Sequence_number>] \n\n -UnattendPath Specify the path to an unattend file.\n -HivePath Specify the path to an IMC hive.\n -SequenceNumber Specify the IMC sequence number. This is optional.\n -? Display help. This is the same as not typing any options.\n", "runtime_modules": [ "C:\\Windows\\system32\\DIMC.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "diskpart.exe-46E1617553370612F5EE81D460B91318": { "file_name": "diskpart.exe", "file_path": "C:\\Windows\\system32\\diskpart.exe", "hash_md5": "46E1617553370612F5EE81D460B91318", "hash_sha1": "3C25EB87CD9966F31209D95129EF72E434628CF7", "hash_sha256": "2FF5665B87450D2D81C61C3128DE95418EA99A7B329C99B4FF16EC65DECE2DE2", "hash_sha384": "E7E7B02544A8464CF12231E3F72183A9CB96636C714CAA0BFCC487BE300DCF6F17788A6DC44D778CB3232B888A8E6F18", "hash_sha512": "668655AE0814A188FA32BF2420EF5C1DCC550683AEAEBFC500D0FED515F5DFD149F6E4FC39B5BB21E63A6FE1EE48AA605D3E1090F38156C6048B847C147D6170", "hash_ssdeep": "3072:KtHwJOXNE1ntLGA3zlAsMz3rHfrQrE0I5et372xaU62:HJOXNuntiAz3Mvfrv5etrP", "hash_imp": "B985D106F2EED6C2BADE4F1EFE2FE39D", "hash_pesha1": "086D327704DB9D924F62B2D6ABE7F1511F4B6A2B", "hash_pe256": "1A12AE53ABFB30C8BE488AECEE6B53095B1A8BAEE6A9AACFF68FECA88FC92243", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DiskPart", "meta_original_filename": "diskpart.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/2ff5665b87450d2d81c61c3128de95418ea99a7b329c99b4ff16ec65dece2de2/detection/", "output": "\r\nMicrosoft DiskPart version 10.0.17763.1\r\n\r\nCopyright (C) Microsoft Corporation.\r\nOn computer: Default-PC\r\n\r\nMicrosoft DiskPart syntax:\r\n\tdiskpart [/s <script>] [/?]\r\n\r\n\t/s <script> - Use a DiskPart script.\r\n\t/? - Show this help screen.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\diskpart.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "diskperf.exe-62878AC98008FE21396427160C975295": { "file_name": "diskperf.exe", "file_path": "C:\\Windows\\system32\\diskperf.exe", "hash_md5": "62878AC98008FE21396427160C975295", "hash_sha1": "95CEEBCAA74ABEC902392261497C199DE87795C7", "hash_sha256": "3A6D5E97DC08B85EA6E0372791D4F68CB93DC0020D195823C0CE1AD8B891B3F5", "hash_sha384": "F245B0EDA2D8D186344C1EDF0795720B8DDC3F3B54E69436FFEEC6E268258A8416619564EC8CA4A18EA277CD38EAE648", "hash_sha512": "154C9CD4B6E75210F70AEF305C88236B814421D76B159C8199F7E82FD8CC76EC2D6E1B6F5D25B3967836CF6B4401E3424D7943F30684EC4E71DBA7AD8D1142A5", "hash_ssdeep": "384:zxEB938kEwctfXzJD1etM47N7WfUry8AihfgiOMyAsN7cK74Zv/FWoJW:zBkE9JD1epWEA2fgiOMy57cKkZ3x", "hash_imp": "BE6FE1119CB4F6C79CE34221D93EACE6", "hash_pesha1": "7F7D1E9A6F5725528293EDE35F38781D840EE0ED", "hash_pe256": "5420F757265CD540ED864A691627C7E436DBBA065B2020798B707E9384340F8F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Performance Configuration Utility", "meta_original_filename": "DISKPERF.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/3a6d5e97dc08b85ea6e0372791d4f68cb93dc0020d195823c0ce1ad8b891b3f5/detection/", "runtime_modules": [ "C:\\Windows\\system32\\diskperf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ], "output": "\r\n\r\nDISKPERF=====================\r\n\r\nStarts and stops system disk performance counters.\r\n\r\nUsed without the command switches, DISKPERF reports what disk\r\nperformance counters are enabled on the specified Windows 2000 computer.\r\n\r\nDisk performance counters can be specified to report the\r\nperformance of the individual physical drives, or the individual\r\nlogical drives or storage volumes. Note that these two sets of\r\nperformance counters are measured independently. The user\r\nhas the option of enabling and disabling them independently\r\nusing the command line switches.\r\nNOTE: This command can only be used to control remote\r\nWindows 2000 systems. In newer systems, these performance counters\r\nare automatically enabled.\r\n\r\nDISKPERF [-Y[D|V] | -N[D|V]] [\\\\computername]\r\n\r\n -Y Sets the system to start all disk performance counters\r\n when the system is restarted.\r\n\r\n -YD Enables the disk performance counters for physical drives.\r\n when the system is restarted.\r\n -YV Enables the disk performance counters for logical drives\r\n or storage volumes when the system is restarted.\r\n -N Sets the system to disable all disk performance counters\r\n when the system is restarted.\r\n\r\n -ND Disables the disk performance counters for physical drives.\r\n -NV Disables the disk performance counters for logical drives.\r\n \\\\computername Is the name of the computer you want to\r\n see or set disk performance counter use.\r\n The computer must be a Windows 2000 system.\r\n NOTE: Disk performance counters are permanently enabled on\r\n systems beyond Windows 2000.\r\n" }, "diskraid.exe-E7DE148C2D2B431C2069874C766F68EB": { "file_name": "diskraid.exe", "file_path": "C:\\Windows\\system32\\diskraid.exe", "hash_md5": "E7DE148C2D2B431C2069874C766F68EB", "hash_sha1": "61E2EF5743A912F57FF41E983E1BFDE8A82D0DC2", "hash_sha256": "7D4C3D063E8DA3250B94A3C81EDAD89ED3AC218228EA177C3576590A42D027B6", "hash_sha384": "A127266F79FD5CC511B2CF7922713DC03FF3C39E8DF06EF8045C302DD94698E394F4A63F992A8873B3588AF9FB6971D7", "hash_sha512": "352A733D5418B210EEAC37D5A339A882395EFD5B7407CD0F595A769B0A3AA46E057FCA5509CB8797063100980B9895D48A225DEA3EB6448EEDDEBE4854FAC862", "hash_ssdeep": "6144:39KZruydrGIPoaP1SLkWPEiBEo4SPujg:39K0ydKadPoEj", "hash_imp": "701F69CB7F69911A0C2E0D44935719EB", "hash_pesha1": "6544CB1093BDA0E8D475BD4D81DA25135E2D5A36", "hash_pe256": "04D2A5B26CEE5B379991822B3F1C4477DAB727CD928E6C03F5FFD85724C83CE6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DiskRAID", "meta_original_filename": "diskraid.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/7d4c3d063e8da3250b94a3c81edad89ed3ac218228ea177c3576590a42d027b6/detection/", "output": "\r\nMicrosoft DiskRAID version 10.0.17763.1\r\n\r\nCopyright (C) 2003-2013 Microsoft Corporation.\r\nOn computer: Default-PC\r\n\r\nUsage: DISKRAID [/? | [/s <script>] [/v]]\r\n\r\n Launches the DiskRAID application.\r\n\r\n /? specifies that DiskRAID should display this usage text.\r\n\r\n /s <script> specifies that DiskRAID should execute commands from the script\r\n file at the location specified.\r\n\r\n /v specifies that DiskRAID should run in verbose mode, printing\r\n out additional information about each command being executed.\r\n\r\nExamples:\r\n\r\n DISKRAID\r\n DISKRAID /v\r\n", "runtime_modules": [ "C:\\Windows\\system32\\diskraid.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "diskshadow.exe-EE6DAEF7CDB52EA62B4E7BB0C9601961": { "file_name": "diskshadow.exe", "file_path": "C:\\Windows\\system32\\diskshadow.exe", "hash_md5": "EE6DAEF7CDB52EA62B4E7BB0C9601961", "hash_sha1": "6A8B13C1F7EFD9C3965A81D072EC86D2B44F54BF", "hash_sha256": "7D08B3B10F1918135C0270BB0CF1CED0927EF61E7348E908CCAE8CA00132F0D8", "hash_sha384": "C607293A54F2C3584EC64375DD2A483C94ECDCB67B65D95D924213F3A37FA1968539AC7F579580ECE7C21C12C599C3D4", "hash_sha512": "37A181C570252BC6D2DFAE3535B8B67A7123D58818B63B04915E5EBFAE9C281650DBDEAC9B39F7B84B627B742F3ED7BB906F7DE9CD4CE5A4B6620F21E4F8ADBE", "hash_ssdeep": "6144:T9zxMYiej4GcxUp6Ki2tXpC98i0e6AQNs3/6dB7RIHrad5t11XEh/SJfcJ+:T9zm1ej1B6990RsS72I5/dOJ+", "hash_imp": "FD2A36FBBAEE53A16DE80CA1D24ACE93", "hash_pesha1": "CB8B2FED861C11DBA2BB2063F503EDD37362E89F", "hash_pe256": "98F6DEA3CBF9B37DE59935259DE942495A63DC6E57628E2B545533AB90689F45", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DiskShadow", "meta_original_filename": "diskshadow.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/7d08b3b10f1918135c0270bb0cf1ced0927ef61e7348e908ccae8ca00132f0d8/detection/", "output": "Microsoft DiskShadow version 1.0\r\nCopyright (C) 2013 Microsoft Corporation\r\nOn computer: Default-PC, 10/19/2020 8:38:03 PM\r\n\r\nDISKSHADOW.EXE [/s <scriptfile> [param1] [param2] [param3] ...] [/l <logfile>]\r\n - Runs script mode\r\n\r\nDISKSHADOW.EXE [/l <logfile>]\r\n - Interactive mode\r\n\r\n /s <scriptfile> [param1] [param2] [param3] ... [paramX]\r\n - Script mode. Include environment parameters in script using\r\n %DISKSH_PARAM_1%, %DISKSH_PARAM_2%, %DISKSH_PARAM_3%, ..., %DISKSH_PARAM_X%\r\n to reference [paramX] above.\r\n /l <logfile> - Output log file\r\n", "runtime_modules": [ "C:\\Windows\\system32\\diskshadow.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DiskSnapshot.exe-ECE311FF51BD847A3874BFAC85449C6B": { "file_name": "DiskSnapshot.exe", "file_path": "C:\\Windows\\system32\\DiskSnapshot.exe", "hash_md5": "ECE311FF51BD847A3874BFAC85449C6B", "hash_sha1": "61B4D8D4757E15259E1E92C8236F37237B5380D1", "hash_sha256": "C7B9591EB4DD78286615401C138C7C1A89F0E358CAAE1786DE2C3B08E904FFDC", "hash_sha384": "EFB43B763BC7F7E42D0EC01FBF1458913A38FE08F120A17E70B70E353B7BF33613AEB70564817BC0582FCE5F1784547E", "hash_sha512": "8334FCD3E551FCAF21FE2AA88218A411A7C6BA8FFB91EB2880F5970BA3AC4893EF214318EB0DA298353C515370A18124FEE9970BED55002CD9145CAFAA181FD8", "hash_ssdeep": "1536:ew6HOlxhH1IFf9mNm+QfjgU4H+En4x9Xl0B4ki/5co:esk2fAgUq+En43l0BdmP", "hash_imp": "69BDABB73B409F40AD05F057CEC29380", "hash_pesha1": "B146A720BF9D4E18B90AF00A3D1D747A2DFEBE50", "hash_pe256": "9C4BCD9E74FB242372FDD4BF940F6C0ECB642A15A0669C209AD8A29929E480BD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DiskSnapshot.exe", "meta_original_filename": "DiskSnapshot.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.652 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.652", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/c7b9591eb4dd78286615401c138c7c1a89f0e358caae1786de2c3b08e904ffdc/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "error": "DiskSnapshot: illegal option: --\r\nDiskSnapshot.exe [options]\r\n\t-c console output\r\n\t-i (deprecated) detail data to console\r\n\t-s (deprecated) summary data to console\r\n\t-u process large volumes (no limit)\r\n\t-j [config] specifies an alternate config file\r\n\t-w [output-file] dumps MFT to a file (v arg required) for testing or reparsing\r\n\t-r [input-file] parses a previously dumped MFT file\r\n\t-v [volume][path] specifies volume(+path) to process, e.g. \"d:\" or \"d:\\foo\" \r\n\t-d [input-file] print encoded versions of the strings in the input file, for decoding purposes\r\n\t-e prints out escalation keywords\r\n\t-k calculate checksums for files, used to investigate duplicated on-disk content (c arg required).\r\n", "runtime_modules": [ "C:\\Windows\\system32\\DiskSnapshot.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "Dism.exe-E9033A5EA69A63A5446CEC4A9AF4D7D0": { "file_name": "Dism.exe", "file_path": "C:\\Windows\\system32\\Dism.exe", "hash_md5": "E9033A5EA69A63A5446CEC4A9AF4D7D0", "hash_sha1": "64B2851656FE5D14029A8EF943F57F30FB44B822", "hash_sha256": "1AF747DBB1E03359D64925E7D76F7B63127814EEBF48449C605372DBA22DF811", "hash_sha384": "A4CBBB03B7090D444ACBDE80D12F077106243B2C5F800DF1C8DB79DAB375635B8AB5C8B59768839E5DB6D2CDE9272712", "hash_sha512": "0AC1BAE6875A406A3005E265EFC04804A2C4779F2FFB9CCF3459EF5BD903E6ABAB24CF09996ACDDD29D9D0C8D37C98863A98D05EC2900CF99A89F7D63D0B891B", "hash_ssdeep": "3072:d9IcAhQ27aL9L56lgWEDBPpaigARZyzns4rj0JSr5RWvj4ALXEff+L95MyxMVr3R:IP/7awoBvhRSnbrg2vWfXEff+L9crB", "hash_imp": "DC72798A2F0E80C035CA0B0421E1A969", "hash_pesha1": "EA95742F0F5C41E6593162F11AF4C23B5D5F4496", "hash_pe256": "D4ABD5F36FB97DDBAB9CE16453DC5B8F42D38D4B8F058856F7EAE0DED0F7C536", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Dism Image Servicing Utility", "meta_original_filename": "DISM.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/1af747dbb1e03359d64925e7d76f7b63127814eebf48449c605372dba22df811/detection/", "output": "\r\nDeployment Image Servicing and Management tool\r\nVersion: 10.0.17763.1518\r\n\r\n\r\nDISM.exe [dism_options] {Imaging_command} [<Imaging_arguments>]\r\nDISM.exe {/Image:<path_to_offline_image> | /Online} [dism_options] \r\n {servicing_command} [<servicing_arguments>]\r\n\r\nDESCRIPTION:\r\n\r\n DISM enumerates, installs, uninstalls, configures, and updates features\r\n and packages in Windows images. The commands that are available depend \r\n on the image being serviced and whether the image is offline or running.\r\n\r\n\r\nGENERIC IMAGING COMMANDS:\r\n\r\n /Split-Image - Splits an existing .wim file into multiple \r\n read-only split WIM (SWM) files.\r\n /Apply-Image - Applies an image.\r\n /Get-MountedImageInfo - Displays information about mounted WIM and VHD\r\n images.\r\n /Get-ImageInfo - Displays information about images in a WIM, a VHD\r\n or a FFU file.\r\n /Commit-Image - Saves changes to a mounted WIM or VHD image.\r\n /Unmount-Image - Unmounts a mounted WIM or VHD image.\r\n /Mount-Image - Mounts an image from a WIM or VHD file.\r\n /Remount-Image - Recovers an orphaned image mount directory.\r\n /Cleanup-Mountpoints - Deletes resources associated with corrupted\r\n mounted images.\r\n\r\nWIM COMMANDS:\r\n\r\n /Apply-CustomDataImage - Dehydrates files contained in the custom data image.\r\n /Capture-CustomImage - Captures customizations into a delta WIM file on a \r\n WIMBoot system. Captured directories include all \r\n subfolders and data.\r\n /Get-WIMBootEntry - Displays WIMBoot configuration entries for the \r\n specified disk volume.\r\n /Update-WIMBootEntry - Updates WIMBoot configuration entry for the \r\n specified disk volume.\r\n /List-Image - Displays a list of the files and folders in a \r\n specified image.\r\n /Delete-Image - Deletes the specified volume image from a WIM file\r\n that has multiple volume images.\r\n /Export-Image - Exports a copy of the specified image to another\r\n file.\r\n /Append-Image - Adds another image to a WIM file.\r\n /Capture-Image - Captures an image of a drive into a new WIM file.\r\n Captured directories include all subfolders and \r\n data.\r\n /Get-MountedWimInfo - Displays information about mounted WIM images.\r\n /Get-WimInfo - Displays information about images in a WIM file.\r\n /Commit-Wim - Saves changes to a mounted WIM image.\r\n /Unmount-Wim - Unmounts a mounted WIM image.\r\n /Mount-Wim - Mounts an image from a WIM file.\r\n /Remount-Wim - Recovers an orphaned WIM mount directory.\r\n /Cleanup-Wim - Deletes resources associated with mounted WIM \r\n images that are corrupted.\r\n\r\nFFU COMMANDS:\r\n\r\n /Capture-Ffu - Captures a physical disk image into a new FFU file.\r\n /Apply-Ffu - Applies an .ffu image.\r\n /Split-Ffu - Splits an existing .ffu file into multiple read-only\r\n split FFU files.\r\n\r\nIMAGE SPECIFICATIONS:\r\n\r\n /Online - Targets the running operating system.\r\n /Image - Specifies the path to the root directory of an\r\n offline Windows image.\r\n\r\nDISM OPTIONS:\r\n\r\n /English - Displays command line output in English.\r\n /Format - Specifies the report output format.\r\n /WinDir - Specifies the path to the Windows directory.\r\n /SysDriveDir - Specifies the path to the system-loader file named\r\n BootMgr.\r\n /LogPath - Specifies the logfile path.\r\n /LogLevel - Specifies the output level shown in the log (1-4).\r\n /NoRestart - Suppresses automatic reboots and reboot prompts.\r\n /Quiet - Suppresses all output except for error messages.\r\n /ScratchDir - Specifies the path to a scratch directory.\r\n\r\nFor more information about these DISM options and their arguments, specify an\r\noption immediately before /?.\r\n\r\n Examples: \r\n DISM.exe /Mount-Wim /?\r\n DISM.exe /ScratchDir /?\r\n DISM.exe /Image:C:\\test\\offline /?\r\n DISM.exe /Online /?\r\n\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\Dism.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dispdiag.exe-BBFA0CA006EAB6884B032144DB236410": { "file_name": "dispdiag.exe", "file_path": "C:\\Windows\\system32\\dispdiag.exe", "hash_md5": "BBFA0CA006EAB6884B032144DB236410", "hash_sha1": "272ED6EC0EA0954447FBB1A2BFD5E030FCB8491B", "hash_sha256": "0B5E810C20FC5E8906AA993BB09EA021982C95A8244C2D56518EA16D22F16362", "hash_sha384": "AEF77386BDB4D5F535148CAC9CA82EB1839A9DC14DB3A45281D836B16ADCBF3A0C03FCFEB790EE1217613145FAF29FDE", "hash_sha512": "093B3279097D4676061BB2519F8BA85526E9F9FE0E5A20466FCDD2139074A23B7992B68081405A95C8065C0E1369548CDA669B47DF6DC76B296E8E6CDE7FBD6E", "hash_ssdeep": "3072:Hnhcq7iLbXtm9x5X32170rSPQRnzix1qm:BcAiLex5mJcSGnzix1", "hash_imp": "CB790495654EEEC1710841B2DBCF3C87", "hash_pesha1": "94370C6B65CE553E33DCE9DE356E8F7C40C9DCEA", "hash_pe256": "B3532823499CB049DA44431EAB28FF942B5D1114D188FC0BB820CC4B1FA085CB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Display Diagnostics", "meta_original_filename": "dispdiag.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/0b5e810c20fc5e8906aa993bb09ea021982c95a8244c2d56518ea16d22f16362/detection/", "output": "Logs display information to a file in the current directory.\r\n\r\nUsage: dispdiag [-testacpi] [-d] [-delay <seconds>] [-brightnesslogging] [-out <FilePath>]\r\n\t-testacpi runs hotkey diagnostics test\r\n\t-d generates a dmp file as well with additional data.\r\n\t-delay delays the collection of data by specified time in seconds.\r\n\t-out <FilePath> path where the dispdiag file should be saved, including filename. This must be the last parameter\r\n\t-DumpIdDiag force Indirect DIsplay framework to dump diag info via WPP\r\n\t-brightnesslogging toggle verbose brightness logging.\r\n\t-ccddatabaselogging <on|off> toggle Ccd database access logging.\r\n\t-dxgautologger <on|off> toggle DxgDiagnostics autologger. Requires admin and a reboot.\r\n\t-DodFullscreenupdates <on|off> toggle if all active display only drivers should process each present\r\n\t as full screen dirty.\r\n\t-Msg <Message to log> Inserts the specified message into the diagnostic buffers\r\nOutput:\r\n\tName of the saved file.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\dispdiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\system32\\WMICLNT.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "DisplaySwitch.exe-371A7018C898652DD0F4F227F09B587C": { "file_name": "DisplaySwitch.exe", "file_path": "C:\\Windows\\system32\\DisplaySwitch.exe", "hash_md5": "371A7018C898652DD0F4F227F09B587C", "hash_sha1": "586FA91F18EBA31E4552D16A8E2867D660BE5F7E", "hash_sha256": "5E4E1662EB2D4D08D8D0D52F4F9BB9B30B61634F2B5E0799B03CFC098D8BEF0A", "hash_sha384": "47DF298F6668E1DD0F418FE35718F138632EF735C5310F7632EB999B1EE078835E7EDEECEE9C67F3CA7D1D78AA7F9B10", "hash_sha512": "3E444C62CB595DBA50414C44DAE98EB02457FC029E6D2F0B358FB084D1B8CAFBCD329E7386A623D3548DAF6883BA80202DB49DE03516BF9ACF8F8153DE22C672", "hash_ssdeep": "3072:+eJVmi/wGrmvdEcW9cIEd/qGhtIdRHORSqvkqxXfoOETWB+/VSHP9a:+emi6vdEcyId/q06zHORNvxJp+k9", "hash_imp": "35BD06246B07F938DD6E5AE1B25C3715", "hash_pesha1": "F0BDD91C9D2B3017F3CB72844ECE9D6918C2CAE9", "hash_pe256": "BCA34E93D4AC9B6D69244C7DCF72BC246B035C099605D3FEE097807B042FAC99", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Display Switch", "meta_original_filename": "DisplaySwitch.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/5e4e1662eb2d4d08d8d0d52f4f9bb9b30b61634f2b5e0799b03cfc098d8bef0a/detection/", "runtime_modules": [ "C:\\Windows\\system32\\DisplaySwitch.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\system32\\policymanager.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\WINSTA.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\msvcp110_win.dll" ] }, "djoin.exe-576896524DD1552F84AFC9A2CDF57EA1": { "file_name": "djoin.exe", "file_path": "C:\\Windows\\system32\\djoin.exe", "hash_md5": "576896524DD1552F84AFC9A2CDF57EA1", "hash_sha1": "20D8FB1FD3A09AD9CA810A0E37C5286DAB83F49B", "hash_sha256": "A7B6AC2649E6398CEC55A349929FE1DE8DA137B9F77ECD7D9036F4BACB29BB59", "hash_sha384": "9F5A5EAE10A2875C09B45EACE67CB1B1F01726A152100A69D55492C32BBEB830180BFF37F30FF130172F1862D3D01C40", "hash_sha512": "A620669FB886FB2F5D4154F23E4A076ED70247B7DA3F230B4E40707A227A4537D729A57E892D6155B642396B74F7E3AA42EF110C546C45CF492EB8093D6B6A5F", "hash_ssdeep": "768:wTEh5BWZ33NBsU9fFiLe/DmUJJMT9NUnPW1vLpppWIj8FT82zpp0vh9rrb0vQYaU:4kk3NR9xtoMW1vVpbGTpW7rXd3EQJ", "hash_imp": "67ED2180B06686FECAA36DBFD2D9C7A6", "hash_pesha1": "B09D43ABA968A1B7908CD87815D8566C8729417C", "hash_pe256": "8B7C3585B2AFB949D09663DC654E920C325F8C8850013C2440353B38BF8924A9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Unattended Setup Generic Command For Domain Join", "meta_original_filename": "djoin.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a7b6ac2649e6398cec55a349929fe1de8da137b9f77ecd7d9036f4bacb29bb59/detection/", "output": "Usage: djoin.exe [/OPTIONS]\r\r\n\r\r\n /PROVISION - Provision a computer account in the domain\r\r\n /DOMAIN <Name> - <Name> of the domain to join\r\r\n /MACHINE <Name> - Host <Name> of the computer joining the domain\r\r\n /MACHINEOU <OU> - Optional <OU> where the account is created\r\r\n /DCNAME <DC> - Optional <DC> to target for account creation\r\r\n /REUSE - Reuse any existing account (password will be reset)\r\r\n /SAVEFILE <FilePath> - Save provisioning data to a file at <FilePath>\r\r\n /NOSEARCH - Skip account conflict detection, requires DCNAME (faster)\r\r\n /DOWNLEVEL - Support using a Windows Server 2008 DC or earlier\r\r\n /PRINTBLOB - Return base64 encoded metadata blob for an answer file\r\r\n /DEFPWD - Use default machine account password (not recommended)\r\r\n /ROOTCACERTS - Opt. include root Certificate Authority certificates.\r\r\n /CERTTEMPLATE <Name> - Optional <Name> of machine certificate template.\r\r\n Includes root Certificate Authority certificates.\r\r\n /POLICYNAMES <Name(s)> - Opt. semicolon-separated list of policy names.\r\r\n Each name is the displayName of the GPO in AD.\r\r\n /POLICYPATHS <Path(s)> - Opt. semicolon-separated list of policy paths.\r\r\n Each path is a path to a registry policy file.\r\r\n /NETBIOS <Name> - Opt. Netbios <Name> of the computer joining the domain.\r\r\n /PSITE <Name> - Opt. <Name> of persistent site to put the computer joining\r\r\n the domain in.\r\r\n /DSITE <Name> - Opt. <Name> of dynamic site to initially put the computer \r\r\n joining the domain in.\r\r\n /PRIMARYDNS <Name> - Opt. <Name> of primary DNS domain of the computer\r\r\n joining the domain.\r\r\n\r\r\n /REQUESTODJ - Request offline domain join at next boot\r\r\n /LOADFILE <FilePath> - <FilePath> specified previously via /SAVEFILE\r\r\n /WINDOWSPATH <Path> - <Path> to the Windows directory in an offline image\r\r\n /LOCALOS - Allows /WINDOWSPATH to specify the locally running OS.\r\r\n This command must be run as a local Administrator.\r\r\n This option requires a reboot for changes to be applied.\r\r\n \r\r\nExamples:\r\r\n\r\r\nTo provision a computer account in the domain:\r\r\ndjoin.exe /PROVISION /DOMAIN <DomainName> /MACHINE <MachineName>\r\r\n /SAVEFILE <FilePath>\r\r\n Note: Other parameters are optional\r\r\n \r\r\nTo request the local machine to perform an offline domain join:\r\r\ndjoin.exe /REQUESTODJ /LOADFILE <FilePath> /WINDOWSPATH <Path>\r\r\n Note: Other parameters are optional\r\r\nThe parameter is incorrect.\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\djoin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\netprovfw.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\logoncli.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\JOINUTIL.DLL", "C:\\Windows\\system32\\wdscore.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\system32\\dbgcore.DLL" ] }, "dllhost.exe-D2AB39EA2C0FCD172751F84BDA723A97": { "file_name": "dllhost.exe", "file_path": "C:\\Windows\\system32\\dllhost.exe", "hash_md5": "D2AB39EA2C0FCD172751F84BDA723A97", "hash_sha1": "DCE2AF90E45FB9FC05ECBC9BEDDEE53FB66F3C6D", "hash_sha256": "C4E078607DB2784BE7761C86048DFFA6F3EF04B551354A32FCDEC3B6A3450905", "hash_sha384": "CCC1F0E8A510FD05AB9BBFCD47454760C85FCC926C2563853DEDC9873E78CE0F13FCCEF52081A654B90EC5ED9A93DADD", "hash_sha512": "2EBDF10D0052507DDBC6E1E1190488CB55A206B6911055EC6C96B013A40512DEF75E01E701B6413BAC38737EC2ED65FF2A731AFAA86D5662D4EA33F592ED641C", "hash_ssdeep": "384:1fL7t7tzRB8sdDNacPWL5WjmXjDBRJ9olLRPpt:1fltzRhacQrXj1PY", "hash_imp": "68E651F131674892AE7E46556EB24726", "hash_pesha1": "4436AAF849CB924FB521EC14365AD6E9C4F7A94B", "hash_pe256": "993991710080440F1678B9A877B554F7C7A21349A42D0173557E1B0A94A491FE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM Surrogate", "meta_original_filename": "dllhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/c4e078607db2784be7761c86048dffa6f3ef04b551354a32fcdec3b6a3450905/detection/" }, "dllhst3g.exe-9E71634DE97DBDBA7998FC08643FAEC0": { "file_name": "dllhst3g.exe", "file_path": "C:\\Windows\\system32\\dllhst3g.exe", "hash_md5": "9E71634DE97DBDBA7998FC08643FAEC0", "hash_sha1": "D7013D36B0F699481D53B975101DE00C42B9A4BA", "hash_sha256": "A4DC2C67C733DF3B9D7E4B9B4B7C300374EE6922CCD5DBD21ACFDC4E4D2068D1", "hash_sha384": "B822829F298AEB3BBD188FBF9203586E0FD8680E74F0C70AA2285B941AAEA411A99DF1F6678600DD9693CC1142861EF9", "hash_sha512": "920A04C4F397323F48A7FF1AF74AFD693444E0A1DC729DC7018763C2200B49A6A13D1276CA80263BD02CD0C7AE46258CA95A0EE67A8DE2129E78D5705B916C0C", "hash_ssdeep": "192:Uw7txqnAtPapwRBKJsdRJKFJvb5n+ufEDc8cWeyW:F7t7tzRB8sdDMCcfWeyW", "hash_imp": "68E651F131674892AE7E46556EB24726", "hash_pesha1": "CD1FA1C2AF7D986E6BA0E4931CD166C0209D1E73", "hash_pe256": "64E7466328F99122DBA349478E28454B1335E0A838FC188CD252CF1546CE68DD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM Surrogate", "meta_original_filename": "dllhst3g.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a4dc2c67c733df3b9d7e4b9b4b7c300374ee6922ccd5dbd21acfdc4e4d2068d1/detection/" }, "dmcertinst.exe-3C2FB606A2F4045002E08997921CB5B7": { "file_name": "dmcertinst.exe", "file_path": "C:\\Windows\\system32\\dmcertinst.exe", "hash_md5": "3C2FB606A2F4045002E08997921CB5B7", "hash_sha1": "FB92E0072B4F5522529B5E627340A372FA77A24E", "hash_sha256": "41B3F0AF54F2351288992247826D96727BDB95F3467F5DD02D27DFD562F7767F", "hash_sha384": "5F985395F2C347822BEA93F4855DC2366952F31F71297C2381833BA013183886CE8131DD641106BD5856934F8D534A63", "hash_sha512": "04E90E7AAE1BC5A9571831A127AD770E23183AC6A9788B4CAFCF3494160AEBEC3A0040FFA2C0E6ED1FF314ABD8852891352D33A66AF8016AF63C0D3620F5173C", "hash_ssdeep": "3072:BSTT02OXemBH50P6WUSxJUr4WzYJuz47RQOQ2dtZvS1MVW:BSTT0fbeSmxw4zysRQOQ2BvS1", "hash_imp": "2064CCC8D877E771AB8B868AD581A1A4", "hash_pesha1": "7B57234FCE1745EB86A29EFEDC2AD4590EED2218", "hash_pe256": "6FA91D3F46674821F3C75DC49D5CD38DA2A032DD5832E14B675BD59CB3A6D6C5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DM Certificate Installer", "meta_original_filename": "dmcertinst.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/41b3f0af54f2351288992247826d96727bdb95f3467f5dd02d27dfd562f7767f/detection/", "runtime_modules": [ "C:\\Windows\\system32\\dmcertinst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\system32\\certenroll.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\ncrypt.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\certca.dll", "C:\\Windows\\system32\\DSPARSE.dll", "C:\\Windows\\system32\\NTASN1.dll", "C:\\Windows\\system32\\iri.dll", "C:\\Windows\\system32\\DPAPI.DLL", "C:\\Windows\\System32\\WLDAP32.dll" ] }, "dmcfghost.exe-2CBA8AF4416C13808584E564469AB235": { "file_name": "dmcfghost.exe", "file_path": "C:\\Windows\\system32\\dmcfghost.exe", "hash_md5": "2CBA8AF4416C13808584E564469AB235", "hash_sha1": "0DEEDB9174313E04358669E28194A371373EC9F5", "hash_sha256": "B9B24776156D0448EC1EA55019AE85F2E17A2D0D133D1A7D1A86D82561073DA5", "hash_sha384": "B0BA80F3FA26552814AE3C67A693D25E3344AE8832FFEB8CE6C4B276A2D1DB9F117AC06E27B8B7440FD0FCB758EAC2C9", "hash_sha512": "7A601FC8B062FB536151D63EF73BFDAF64031031DC3CD6D19B72B0AA0211C55E0B33E2966B6D773652850B34ADDBE92DF36C48AFCB4F3C2E7440858C0670D803", "hash_ssdeep": "768:DjrbdtLbBb/NE/n4J14j7RoWMl0ywqJMx2zOlsGQ:D/1/NE/n6WM+y1JMxKOlsGQ", "hash_imp": "6FCA673968906FA1EB9C396AD8DFDF7E", "hash_pesha1": "E8212EEC249CD4DE9759A703F954137532EA8A4F", "hash_pe256": "5BB76F914B1FA024101E69894D3E3B2FFAC00E94B47FD0AD2B7AA595F94D2F2B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Push Router Client of OMA-CP", "meta_original_filename": "dmcfghost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b9b24776156d0448ec1ea55019ae85f2e17a2d0d133d1a7d1a86d82561073da5/detection/", "runtime_modules": [ "C:\\Windows\\system32\\dmcfghost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ] }, "DmNotificationBroker.exe-332EDED7FA6795E0FAA905EB1B323150": { "file_name": "DmNotificationBroker.exe", "file_path": "C:\\Windows\\system32\\DmNotificationBroker.exe", "hash_md5": "332EDED7FA6795E0FAA905EB1B323150", "hash_sha1": "6D08B17EEF81CDDD5532ECB02CE1A0D21C2D92AC", "hash_sha256": "C36543DCB42B09122114CE7C9EE347CEB69693B87CBFA6308A37100B64BAAE20", "hash_sha384": "23C140240D981EC8FA56284F093AD62B96FB53CFADCA5F8E735933549FF12E34F160AE52D32B73936F750FE3CA5079AB", "hash_sha512": "8DF25EC3B59349CCE41F931CAA5A77D3A2874A849FE38EF178DCF10110BDEE547404E6AC603AA888DF8ECEC7F5332BE71357750C990E0A167319A33D1B92C35C", "hash_ssdeep": "768:NnJ4zlyQy46gAoTtet82Bl0/+l8Cmj5z:X0y4IZ82+/C8Fj5z", "hash_imp": "289708B41323FCB3D276BCFB9F56B2E7", "hash_pesha1": "ED1B97584BE7C06DFD89D3BC53F950CAD2A67BD3", "hash_pe256": "D30C0705E7B7E085E9E48449E05776A893D6DE2E80D2990AE67AA551531F2445", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DmNotificationBroker", "meta_original_filename": "DmNotificationBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/c36543dcb42b09122114ce7c9ee347ceb69693b87cbfa6308a37100b64baae20/detection/" }, "DmOmaCpMo.exe-3C2F82D254D4184C9F5CC056325DD680": { "file_name": "DmOmaCpMo.exe", "file_path": "C:\\Windows\\system32\\DmOmaCpMo.exe", "hash_md5": "3C2F82D254D4184C9F5CC056325DD680", "hash_sha1": "9B3077A7F0BDC5A7C7E100C3EC23F3CFCDD9FDB4", "hash_sha256": "9910D2C25F494B1C1668E6B67EFEDEF17109419CE73CFAD2D9DE5BD2896D400A", "hash_sha384": "892B6F1F1DF8704736BBF064C064362D25B4162B287FFC67597E2338972CA90A5C4CC5015931AA4347F69D012D6CF866", "hash_sha512": "7B842A54F43E8241758333A65507D52AB4A22C8368098F7063B5328FC787503AFC96AD566ADFFED22AADF87ED31FC81A80D994073D9B3D9FF431D30865D16FBB", "hash_ssdeep": "768:njteu1aym9kYXcScG/rqEGoGNtUUPFTE6N6YbiMao618BnKkbg3G9o6wbIKD4X1:nV1CM7euiGNttTEtYbiFo6Wg3Wo66IKo", "hash_imp": "CF308790E494EF6E2671CD289C4EA3D2", "hash_pesha1": "EA991130CEB6B86A888B02693126BC8EB41CA6B0", "hash_pe256": "2990454E2EB243EF118D12F56A64759A440A487E7FA355959F1448C4A46D3DCF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for OMA-CP Client", "meta_original_filename": "DmOmaCpMo.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/9910d2c25f494b1c1668e6b67efedef17109419ce73cfad2d9de5bd2896d400a/detection/" }, "dnscacheugc.exe-217CD6402D7413486D78340E89A48A64": { "file_name": "dnscacheugc.exe", "file_path": "C:\\Windows\\system32\\dnscacheugc.exe", "hash_md5": "217CD6402D7413486D78340E89A48A64", "hash_sha1": "63D53FFD118BD6F0BECEBD2DBC95539816CB806A", "hash_sha256": "5131AB09AC9F309607A8D7DAE578AEDBFB5931C8A419187ABAC231350DB38CFD", "hash_sha384": "C093B08303F6C29D9CC423905E73F14BC29DF1D912404BD83A27A7AE116A934E9348BD5E7503C3E17E3B364D41644988", "hash_sha512": "E683A5F71FCC4DA1C96061065CBBCB16FBD71B1AD9E99ABA7104C4E6CD1BFE13A51908B7C3056DE8187C1357E5D887C1EEB30A889798F7A432CF9EFFC1E5260B", "hash_ssdeep": "384:xmP+UlYbpy8KVWnBEhYPz6ZAFRZMcbWlHZ61at/VYMXPryc1ObH9uosk4z/UI2fq:xezKb2Wn2/6FLeR+a99Zf/UI2faRW", "hash_imp": "5C561F392016B5D9832D2D36362CA7F0", "hash_pesha1": "28DEF1803B286597342506DEBC5F44F8D9B6C570", "hash_pe256": "EB1B7E91E6D41A5B5554DD1EA7A072C2F3C67DF8858F80D6756315CEAA1C456C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DNSCache Unattend Generic Command", "meta_original_filename": "dnscacheugc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/5131ab09ac9f309607a8d7dae578aedbfb5931c8a419187abac231350db38cfd/detection/", "runtime_modules": [ "C:\\Windows\\system32\\dnscacheugc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\wdscore.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\system32\\dbgcore.DLL" ] }, "doskey.exe-BB1CE26B03564489620E07D9BBC308BF": { "file_name": "doskey.exe", "file_path": "C:\\Windows\\system32\\doskey.exe", "hash_md5": "BB1CE26B03564489620E07D9BBC308BF", "hash_sha1": "1FEEB663387F73097DA32CE937EC9D4FF0E25197", "hash_sha256": "65182EA1E90CBA3C6369F6111AFE050699966309010F72EBA7707222D949D836", "hash_sha384": "A85392A3A39E4E91AC660764F366F7CFD4ED4F6C4E93990CB749BE02811AE759C05A1601F93101DF0872FBD1F279C64D", "hash_sha512": "D060B46437780B48AEB2316CF46EAA5349D53DDED6179854ACD332D12E8FC7445C2006B07BF34033058835EEBD02187F451F8997BA78BF5ECF3EC7B546E34ED3", "hash_ssdeep": "384:TvozV3t9ZnTVSFQMYBIAPtzHtztLmkEUSI/3WTiW:TvozzrnTVkLIlLtyUSI/Q", "hash_imp": "A1EA9D934205151494B8180E6C772F08", "hash_pesha1": "47E38690023215E385CF7331F2F9397AAD8489C3", "hash_pe256": "688D8C6135B08624EB2EDD5717707D248A6C2082CFCD841DE5F5747056F51AA8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Keyboard History Utility", "meta_original_filename": "DOSKEY.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/65182ea1e90cba3c6369f6111afe050699966309010f72eba7707222d949d836/detection/", "output": "Edits command lines, recalls Windows commands, and creates macros.\r\n\r\nDOSKEY [/REINSTALL] [/LISTSIZE=size] [/MACROS[:ALL | :exename]]\r\n [/HISTORY] [/INSERT | /OVERSTRIKE] [/EXENAME=exename] [/MACROFILE=filename]\r\n [macroname=[text]]\r\n\r\n /REINSTALL Installs a new copy of Doskey.\r\n /LISTSIZE=size Sets size of command history buffer.\r\n /MACROS Displays all Doskey macros.\r\n /MACROS:ALL Displays all Doskey macros for all executables which have\r\n Doskey macros.\r\n /MACROS:exename Displays all Doskey macros for the given executable.\r\n /HISTORY Displays all commands stored in memory.\r\n /INSERT Specifies that new text you type is inserted in old text.\r\n /OVERSTRIKE Specifies that new text overwrites old text.\r\n /EXENAME=exename Specifies the executable.\r\n /MACROFILE=filename Specifies a file of macros to install.\r\n macroname Specifies a name for a macro you create.\r\n text Specifies commands you want to record.\r\n\r\nUP and DOWN ARROWS recall commands; ESC clears command line; F7 displays\r\ncommand history; ALT+F7 clears command history; F8 searches command\r\nhistory; F9 selects a command by number; ALT+F10 clears macro definitions.\r\n\r\nThe following are some special codes in Doskey macro definitions:\r\n$T Command separator. Allows multiple commands in a macro.\r\n$1-$9 Batch parameters. Equivalent to %1-%9 in batch programs.\r\n$* Symbol replaced by everything following macro name on command line.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\doskey.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\ulib.dll" ] }, "dpapimig.exe-B9F5824DA03CF216F7F8F0E9D874670E": { "file_name": "dpapimig.exe", "file_path": "C:\\Windows\\system32\\dpapimig.exe", "hash_md5": "B9F5824DA03CF216F7F8F0E9D874670E", "hash_sha1": "A1AA04BB68BE6FDD5CC4272D120BA78BA7C6F39D", "hash_sha256": "86B408E98C6C96EC0109228EDFD37C6AC6903129B85E4BB8B24734ABE6986CF0", "hash_sha384": "C52321BE3FB213E5391C08D0372E7669364FFD9432DAB65D4439D53728C7EFA75D483FC008AD2AEED4BF9503B39BAD99", "hash_sha512": "600224F72C8BD5DA8E775E9465539F466ADB67E24966128708CB910623CEC5CF9081EEBB47D3B38CC7DDDC7378C7F9B21A5279ADC292093444998D8BB71DC86E", "hash_ssdeep": "1536:vXU94MQHmKdIZAQ00l3uU1HIED1fCbWpygzU:/U6wKEA/SJj16bE", "hash_imp": "5BACEA135D7122680523ECF81DEF2D51", "hash_pesha1": "8A8D7FBDAEF83AD215CBC184AC9CDEB648306469", "hash_pe256": "EA7C4F1C2E1DD22AEB6FD099FE2A2187B4A055C62A92C84104CAC2656086BCC3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DPAPI Key Migration Wizard", "meta_original_filename": "dpapimig.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/86b408e98c6c96ec0109228edfd37c6ac6903129b85e4bb8b24734abe6986cf0/detection/" }, "DpiScaling.exe-833A4FD57FCF875A70C19D1FF7FAC341": { "file_name": "DpiScaling.exe", "file_path": "C:\\Windows\\system32\\DpiScaling.exe", "hash_md5": "833A4FD57FCF875A70C19D1FF7FAC341", "hash_sha1": "0407F42433D47FF3ADB1CE11EA6D57ADE50E76D1", "hash_sha256": "A12D94DA4B2A392937B81ECAEB7074804633DCBF33ED74F1B8F0AAEBDE7D2F74", "hash_sha384": "7F0B933181F6CE650ED0ED704B0BC2596077DCD23E9D672AE9EBE80838CB4401280137EA6256E933B37CA91D43BD249A", "hash_sha512": "E17AF096540364183A1C24C1E024F60BC785657B318728B5141CA560CF674015610A7A17CAB6EA4ECAB3A28E28C143308B3787AFEBA8E102C7D13D303EC7442E", "hash_ssdeep": "1536:BVZG91OwxgwYfPSqlGv+BNXNvuZS36EDtAZ7jz6dTdMQiMtYwJjP:1EOwNMSqoKXNvuZAFDqXzlzQz", "hash_imp": "79AF10FA7C10573B0B9B52F39C28B0F2", "hash_pesha1": "D70E6E4D38CD58BAE902DF88061E42554E1356E6", "hash_pe256": "68E3124D921B5AB0C5B2E3E0640098360868654A3BC5E76F0B3AE79AD9EE5063", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Display Control Panel", "meta_original_filename": "DPISCALING.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/a12d94da4b2a392937b81ecaeb7074804633dcbf33ed74f1b8f0aaebde7d2f74/detection/", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\system32\\DpiScaling.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll" ] }, "dpnsvr.exe-7AD4186FF349795164C8DFE868A601FC": { "file_name": "dpnsvr.exe", "file_path": "C:\\Windows\\system32\\dpnsvr.exe", "hash_md5": "7AD4186FF349795164C8DFE868A601FC", "hash_sha1": "8308EC6E372C2E3C8D960DE5374E82A9EBA5B7BB", "hash_sha256": "C5B6515460587E3932BAE23165DE3E83A0A6BCA20475220C21D1DE1D74C0D000", "hash_sha384": "FF2D12F8F229526D61F85391CD9BC451843E272B4A929FD3E96167C3775FBD10EC5BCD2DE3C78AE0CE13F76FF6FA0282", "hash_sha512": "E491730B7D84CE98E9DBFF2388DEC3709917BE92E562141716597E6B1E1F0B99C37E2C527C474C5291B959B3BD3BA439358345FEA0E7D9FF7240C844B61F9318", "hash_ssdeep": "96:dxhHXIrEDNjdk2Qz6Pl/3ZLtestaAbmU/Et40EWGuWw:zOAzzPl/pLt5aAmU/PWGuW", "hash_imp": "5C317B4785C1C3CE395F95788FB0F892", "hash_pesha1": "EEDED85EE33203F63133373685249C48A6109694", "hash_pe256": "50A1B1F1434F5AB5995F64D13779F6AD9C8AA104D52D9460D1DB901FAC68C670", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DirectPlay Stub", "meta_original_filename": "wcodstub.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/c5b6515460587e3932bae23165de3e83a0a6bca20475220c21d1de1d74c0d000/detection/" }, "driverquery.exe-45C068A7D9C9D304FCEC5ED4CB6CEBB2": { "file_name": "driverquery.exe", "file_path": "C:\\Windows\\system32\\driverquery.exe", "hash_md5": "45C068A7D9C9D304FCEC5ED4CB6CEBB2", "hash_sha1": "CB2B37FA13EA4AD18746A6CC85EC68A27B058B5F", "hash_sha256": "4CB5B035E0F4E62350F91366BF16CA816BEC39AEDA4F11DFF44B01525DDBE272", "hash_sha384": "89E1B4D4ECEC52BA8FAA45A5261A5AA999EA3EA51C8052596529F65EF40F42B02A5A3B4D02183A1EFE585C6F146849C1", "hash_sha512": "A9D73FB2A4D30D76913CDB3F9E6C2425C223DDDDD6FFF7E2FF071E9A05502433B10BCA9D01D3750998E89D703E4FD7A50B0ED7865169E9B4858717FBB5C69A24", "hash_ssdeep": "1536:jilIWf1LzmJoPtvMRS5TZhvL3lw6+SJlZRSF/NvSIexKxyVKR:mlDmJo1vZhL3HPZsFVexXg", "hash_imp": "A87A1089836CF0B5D0149F0CD61532AF", "hash_pesha1": "9D9667B15FB190C3E21C391F5DD2841E61EADD69", "hash_pe256": "9B3B494DD2866053EC300C0AECAC4D1A0D9B34427BE2F1E08535AE6A58BD9596", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Queries the drivers on a system", "meta_original_filename": "drvqry.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/4cb5b035e0f4e62350f91366bf16ca816bec39aeda4f11dff44b01525ddbe272/detection/", "output": "\r\nDRIVERQUERY [/S system [/U username [/P [password]]]]\r\n [/FO format] [/NH] [/SI] [/V] \r\nDescription:\r\n Enables an administrator to display a list of \r\n installed device drivers.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context \r\n under which the command should execute.\r\n\r\n /P [password] Specify the password for the given \r\n user context.\r\n\r\n /FO format Specifies the type of output to display.\r\n Valid values to be passed with the\r\n switch are \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" \r\n should not be displayed. Valid for \r\n \"TABLE\" and \"CSV\" format only.\r\n\r\n /SI Provides information about signed drivers.\r\n\r\n /V Displays verbose output. Not valid \r\n for signed drivers.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n DRIVERQUERY\r\n DRIVERQUERY /FO CSV /SI\r\n DRIVERQUERY /NH\r\n DRIVERQUERY /S ipaddress /U user /V \r\n DRIVERQUERY /S system /U domain\\user /P password /FO LIST\r\n", "children": [ "csrss.exe", "winlogon.exe" ], "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"DRIVERQUERY /?\" for usage.\r\n" }, "drvcfg.exe-77A98ED80D47108364469E5203F3BE00": { "file_name": "drvcfg.exe", "file_path": "C:\\Windows\\system32\\drvcfg.exe", "hash_md5": "77A98ED80D47108364469E5203F3BE00", "hash_sha1": "7A6D3867424A743FECFAB29F13C98C2D17F781DA", "hash_sha256": "20475A39E2C44FEE59E1C7D68D99866DC65CA45740B5212DB9E83DA2B7D1F575", "hash_sha384": "40ACD69FAF2C37DF5D7715447D33CA1C346F95075835E5E1DCE96CB6BA53EFD09BB5C18184B28AE5D048EBD710746FE4", "hash_sha512": "5D0E5F9E11B8B81D3C68FAF4DFD6805084FA05EAD978D6510D2724FF1DFE68754F11442F73B9BF61049082A7589F033DDE413DD419D6B034D6A3977841C0AEBF", "hash_ssdeep": "1536:cKJwYs/DkdyExtWZQVUl/Za+/GZ2RsHc4E+ST2q6iq/M:TJqkdy8gDlRavyVdp6iZ", "hash_imp": "554198353DA136A534ACCE2ADE5DBBFD", "hash_pesha1": "06C7004C66FA83FB200FA84341E6C22901073888", "hash_pe256": "F3F1FFC13CC099BDF5B32B3E74A6B8EC342D5DDB664D87AD53062CC4E95CDF0C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Driver Configuration Module", "meta_original_filename": "DrvCfg.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/20475a39e2c44fee59e1c7d68d99866dc65ca45740b5212db9e83da2b7d1f575/detection/", "runtime_modules": [ "C:\\Windows\\system32\\drvcfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "drvinst.exe-6EB5F4358950B3FE313FE60449A3CDA5": { "file_name": "drvinst.exe", "file_path": "C:\\Windows\\system32\\drvinst.exe", "hash_md5": "6EB5F4358950B3FE313FE60449A3CDA5", "hash_sha1": "3B170E8BAC1D2F671436423BE8A5E8E9F68B79FF", "hash_sha256": "D0FE99477FE70549D0C240185B77FD9DB4124A0B6BF413248986EFF16F3B2A85", "hash_sha384": "477DA9F96864229F36947D86DB37A619FF804B826F1040B0CDFC91A7EB9ACDDD5EA23C0336E53BAA8994A938278A532D", "hash_sha512": "63900372ABCEAA8D9DBBD17D18831F5E41722C03861F8C6A8B648900D4AC0E07789CBB0A99369B93ABDDE165EBCF4D21491B17493BC2EF08C1E9990B38601DF6", "hash_ssdeep": "3072:nnzgTRGJjiWdi2T4pAb6cDjMNOQf+uFvpwpTLJ9/0Rhd0q:nnew5N4pA1jMMk+rtLJ9/sh+", "hash_imp": "DA1305F01AF9CDF200C7B0F24F75FAAE", "hash_pesha1": "B292175C300600903C2EEDFE0386AE793B638F0D", "hash_pe256": "AAB7C70DA81E8E01CE0BF500B08A2297866E05637988EA291C4855CBC1EE142F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Driver Installation Module", "meta_original_filename": "DrvInst.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/d0fe99477fe70549d0c240185b77fd9db4124a0b6bf413248986eff16f3b2a85/detection/", "runtime_modules": [ "C:\\Windows\\system32\\drvinst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "DsmUserTask.exe-FA240258E18A91A6A80F128A4CE613C3": { "file_name": "DsmUserTask.exe", "file_path": "C:\\Windows\\system32\\DsmUserTask.exe", "hash_md5": "FA240258E18A91A6A80F128A4CE613C3", "hash_sha1": "A65A01868F61266D9AFE16E667F9C4AD87701944", "hash_sha256": "E2544E63FE1C1BA957EC5723B74CF78476A2C54568AF569A37D7A4F9FB804C93", "hash_sha384": "3481C786BE9C9F2D2633325C71679779B5199F078B6270E5FC697634DF67AB38252D890788C95A9191CE3D570EF037A8", "hash_sha512": "51880D919F5E13564DA0463E5C12AF26C8031B062E1A32F53C4DB8D35D089255244D0ECD7938838EFC83B915D7A07654C822C0F01A10E14450DAB1429C78D615", "hash_ssdeep": "384:mP9ivV3S52/qLY+wE+g/6dDk3DDi0zDyqWtzW:mG3STLY+wMIDk3DDhzDyx", "hash_imp": "1EE71F4B1B1F5EF99871A31778D7A339", "hash_pesha1": "FD22C7F02C271184FCDC23C4E9B93885F3DB4A60", "hash_pe256": "273214EB505D79AADF9CAD2B55C31E851402C0BFF82DEA12515D61215B10C440", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Setup Manager User Task Handler", "meta_original_filename": "DsmUserTask.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/e2544e63fe1c1ba957ec5723b74cf78476a2c54568af569a37d7a4f9fb804c93/detection/", "runtime_modules": [ "C:\\Windows\\system32\\DsmUserTask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\cfgmgr32.dll" ] }, "dsregcmd.exe-41354397D7D58FFAA96593FEA1DA43BF": { "file_name": "dsregcmd.exe", "file_path": "C:\\Windows\\system32\\dsregcmd.exe", "hash_md5": "41354397D7D58FFAA96593FEA1DA43BF", "hash_sha1": "399751716641D7DA21146B4AB3DCB6C27748B4A7", "hash_sha256": "BB2E36193782ED2DE2444309ED95206B8ABBD4665D348C4FAF9EB3E4A7481D3F", "hash_sha384": "CEEC2797846602C8F36F42BAE82084FA1C6543C1023C0081DB6AECB7A16E24E4F8E013E07B76EA3C474E9DB642A97AD4", "hash_sha512": "B1241EFC69D6F59FA195489355C2F28849586648B3607DF9379503FB52DE31DCBC52428898AE3C4AA2337EB4D0AAED8CD828DC91A5F9EDB46F1D04D55D563A8F", "hash_ssdeep": "12288:bEmIvyopbq5wv7y/7MG1AoFwIMIoDc4PlLFuUytMMivo49:bhm9q5wv7yDN1AoFwl9JlLFuUya9vo", "hash_imp": "97281AC8A8D49241F0356DD998A7CE2F", "hash_pesha1": "F737E8C9ED064B7262F61A739EA2E9863452C4F3", "hash_pe256": "3445DC1EF58FE6B84096EAC093A9EA4802905A61F603571712A1E2BED51B34B0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DSREG commandline tool", "meta_original_filename": "dsregcmd.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/bb2e36193782ed2de2444309ed95206b8abbd4665d348c4faf9eb3e4a7481d3f/detection/", "output": "DSREGCMD switches\r\n /? : Displays the help message for DSREGCMD\r\n /status : Displays the device join status\r\n /status_old : Displays the device join status in old format\r\n /join : Schedules and monitors the Autojoin task to Hybrid Join the device\r\n /leave : Performs Hybrid Unjoin\r\n /debug : Displays debug messages\r\n", "runtime_modules": [ "C:\\Windows\\system32\\dsregcmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\system32\\ncrypt.dll", "C:\\Windows\\system32\\logoncli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\WINHTTP.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\dsreg.dll", "C:\\Windows\\system32\\WININET.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\Secur32.dll", "C:\\Windows\\system32\\NTASN1.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\system32\\SSPICLI.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "dstokenclean.exe-6A7D8561BCBA33ED64E3BEFD67C10CA0": { "file_name": "dstokenclean.exe", "file_path": "C:\\Windows\\system32\\dstokenclean.exe", "hash_md5": "6A7D8561BCBA33ED64E3BEFD67C10CA0", "hash_sha1": "D1B5C11C2A17AD2BA78271FE2BC683A47831E63B", "hash_sha256": "066AEB24EC4007483EDB2AC0893236069F463E598FC18FF5646B28D067A74F58", "hash_sha384": "18D2C9361F127733EC06BAE4746E23CEC2F935B20FA141D627A644414AB70C4DA36B68F7F0253D395F2EB3A13590D087", "hash_sha512": "D658E05C3128793DB84F27A7C569DB243A7174D68DFE2AE6AE0069E25EE74E4311E1B894EC77150A981B36E5FC536D0818650A8C04085F989C334067866E7054", "hash_ssdeep": "192:7dhA1C19DpWZxDvupAW9EfOyAD2Y9Gt7WdhXlVXAw54WHEW:778gxp81WpXPyrY9q7WhVv4WHEW", "hash_imp": "F1D06B8C52F369E9C51A17B21E2BD700", "hash_pesha1": "DC61F24DE37B0748CD7407B3334723AAA94CCA40", "hash_pe256": "1661B500B4E75184B05D9447064C92E36DDF10415A64CB54851B785E174CC0F4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Data Sharing Service Maintenance Driver", "meta_original_filename": "dstokenclean.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/066aeb24ec4007483edb2ac0893236069f463e598fc18ff5646b28d067a74f58/detection/", "runtime_modules": [ "C:\\Windows\\system32\\dstokenclean.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\dsclient.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "dvdplay.exe-5AEA5B5787AF2AD9DB4CE8B0E8FF2A62": { "file_name": "dvdplay.exe", "file_path": "C:\\Windows\\system32\\dvdplay.exe", "hash_md5": "5AEA5B5787AF2AD9DB4CE8B0E8FF2A62", "hash_sha1": "694B2ACC0435C0D60C55189EA70BFF9E89B1E0C8", "hash_sha256": "5A1EB8CC2898AED6894E840D89BA33314629EBEB422D5F7A91CF8FBD5BE528C7", "hash_sha384": "85EF550A1E24EA7AF23409663A5B5B07E8904019F2D4F2EBC78B117F5F1D335882CEC8D62CF6FFF86457D78459A6C911", "hash_sha512": "3ABCAF9DD181B33D44A009F218463FE04E247B93FB68CFE339249B0B8618CFB2C7755165DC2387502D39113F987C281912E5D7B81C87A3754D4B07367D64663E", "hash_ssdeep": "192:ZwgmrJ6JOSIXT6BkhZHUwT4JUc0Iq6vuU29mQPjhFiwWdZW:Zwgu6JZEeCVLEJh0Iq1o8xWdZW", "hash_imp": "9D517BD4783BA5BC3C67F3120C6BA649", "hash_pesha1": "3787451B29E9C0DE692CF29799BA3AE9BCA97612", "hash_pe256": "9685347E6F43B263E24EA69C685D9D217F6526104E4AFC9AD11271E0E0863E29", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "dvdplay placeholder Application", "meta_original_filename": "dvdplay", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/5a1eb8cc2898aed6894e840d89ba33314629ebeb422d5f7a91cf8fbd5be528c7/detection/", "children": "wmplayer.exe", "runtime_modules": [ "C:\\Windows\\system32\\dvdplay.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL" ] }, "dwm.exe-5CE3CCA35D8B19967B25806B7FF69D0F": { "file_name": "dwm.exe", "file_path": "C:\\Windows\\system32\\dwm.exe", "hash_md5": "5CE3CCA35D8B19967B25806B7FF69D0F", "hash_sha1": "2371C02842FD9670FA47B2EAE4CB08FA7A6070C1", "hash_sha256": "5954A267C8F271798EC0AC18D5F67F21A70B47258B10601511CA2109FFFDCF71", "hash_sha384": "E6CAE26BBB80F2DEAC8EA9FC14DB5D22DA2C58E4879205E9F107CBC622F85ECE9A9D9053742642C8D846A781024E5E3A", "hash_sha512": "E8726804478C54F122CEA6435D9538FFF3D6694A93B2A367F78D70BA8309B0AB2612A50E698A7DF48DDC1A7AFEC4D9A9D51D8B40338B2CA5B6E31F7E4EC9D519", "hash_ssdeep": "1536:XTjrLnX87oRLb0Pi3DoaegoWRottVMaq:/X1OPUr9oHtYaq", "hash_imp": "CC05EDB80F10F1D5E7EC964B8C83F969", "hash_pesha1": "E0376577500942E16E46833659D6CD2F46DD2E6A", "hash_pe256": "095DFC2B348A91503E0FA73EBD1A384CF683AF41A2A8DD5AC3328907FBDAC719", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Desktop Window Manager", "meta_original_filename": "dwm.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/5954a267c8f271798ec0ac18d5f67f21a70b47258b10601511ca2109fffdcf71/detection/", "runtime_modules": [ "C:\\Windows\\system32\\dwm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\gdi32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\SYSTEM32\\dwmredir.dll", "C:\\Windows\\SYSTEM32\\udwm.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\system32\\dwmcore.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\CoreMessaging.dll", "C:\\Windows\\system32\\dcomp.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\d2d1.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\system32\\D3DCOMPILER_47.dll", "C:\\Windows\\System32\\CRYPTSP.dll" ] }, "DWWIN.EXE-EF672F7CAF77C3106ED33A7A9FB0B439": { "file_name": "DWWIN.EXE", "file_path": "C:\\Windows\\system32\\DWWIN.EXE", "hash_md5": "EF672F7CAF77C3106ED33A7A9FB0B439", "hash_sha1": "A6DF44312A6F04CC0480D593C8AC996847F6BAA5", "hash_sha256": "80EFA2321618D983A52EF01DE6171257900E77B454D3BE5E2039FE3D0BF72DE9", "hash_sha384": "F94A927380D761CA4ECB6548267D93625F30DA3F2D90E1AA305503245B97B256FED524E2D160EA767522E9FDA19C94B7", "hash_sha512": "ABAD0F9EF304A4426370577F4338B034C60CB2684B2661FA2F134DA0A80C6E78540C97CA038DBA863A821A04C4C82F7B2B097F0663FB02C3CDB11B05AC87395D", "hash_ssdeep": "6144:NVDSBAb0KhrJ5Z4mgvoNv51tyEJlggBcm:CAAKBJQmgvyv51tyo5O", "hash_imp": "BC2E815ECE3C1675A8266AF7C8F84D5E", "hash_pesha1": "120E8FCD56AA717B5A96D6B1E6D9CD99DF768D0D", "hash_pe256": "76F16B1CA6814F54EB6495FA6B511A5519B7D1FC598C6FD8F4126DE6B5CBDBDC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Error Reporting", "meta_original_filename": "DWWIN", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/80efa2321618d983a52ef01de6171257900e77b454d3be5e2039fe3d0bf72de9/detection/" }, "dxdiag.exe-EB34E3F86DB8971684A65F5DEA5A535E": { "file_name": "dxdiag.exe", "file_path": "C:\\Windows\\system32\\dxdiag.exe", "hash_md5": "EB34E3F86DB8971684A65F5DEA5A535E", "hash_sha1": "5178A1338FBCABA34699B871EECD1C04266EE06F", "hash_sha256": "942F70ACE785DC2A2D7377ABC3DB1A2B769C5FF8AD4DFF0D3CD66B9E029CD178", "hash_sha384": "E1E8C430F5B3481961E8FE03CC411B6B8243122F398D5A25E2653EBCD9394581E69308AC11F250E3C21317CF577C94C7", "hash_sha512": "60259625AB2708D8824C51BDA8AB106729B98224C42D2FB919ECAF7278FCE4898E13584FFA697EE19E96AD6F67482CAB3C821342C142EF7F456B81C72FA8AA4A", "hash_ssdeep": "6144:9wKhyJ1CduTR4CchMK1NSAqjMYzo6o/7tzRGOBDE4P:9wGWdwMiIo6POBFP", "hash_imp": "7D3E50DE92EA99CC2501F8ABADF36063", "hash_pesha1": "6F0D35CC7D5706EE08FFD6A79AFBF58D608BC532", "hash_pe256": "D2CA3D96EE102685E89B964E69D894C5A3BBD0C78B84E883951F08E8F0217FFA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft DirectX Diagnostic Tool", "meta_original_filename": "dxdiag.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/942f70ace785dc2a2d7377abc3db1a2b769c5ff8ad4dff0d3cd66b9e029cd178/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\dxdiag.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\dxdiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\WindowsCodecs.dll" ], "runtime_window_title": "DirectX Diagnostic Tool" }, "dxgiadaptercache.exe-CEA17E28EFF3B2EED6B49B5DDCC7327F": { "file_name": "dxgiadaptercache.exe", "file_path": "C:\\Windows\\system32\\dxgiadaptercache.exe", "hash_md5": "CEA17E28EFF3B2EED6B49B5DDCC7327F", "hash_sha1": "898AD000DF8317837B5CF97FA32509739346EDDB", "hash_sha256": "BA598EFD9D9C4449DEAC83F78CEC893AA127F31767902D6DD69A157B65450240", "hash_sha384": "BEBA6744C25C6306CED806D26E8D0C5D6E1188015219ACC236F50FD7E141CF0F4887A49081AB9439BB561797A3F88651", "hash_sha512": "C839DB19463274B9849FE4A046B538148E7C2EE3FB12DD34E35BBF5723FA5DBDFFE3B36F2DDAD49EBEF344F4420E2C22FB897BF7D03C1A2F3B8466916CE6CF79", "hash_ssdeep": "768:BWbOzcY09TeSj00IS9yFlZy2GP7CFecVDZwd/rQ1RrXduoRLRRBUTjD1:BEO6TeGQl7ZyV7tcfwxM1RrtuiNzUnD1", "hash_imp": "88A45A1AD2822D23AF808E0A0C8194B7", "hash_pesha1": "0222DE3688747DE4211348D9947476B3BFA4E680", "hash_pe256": "C57AADEB76B6BFF1250CDD605A7AA819C4D59FABB60957999F81AF5784EB235F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DXGI Adapter Cache", "meta_original_filename": "DXGIAdapterCache.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/ba598efd9d9c4449deac83f78cec893aa127f31767902d6dd69a157b65450240/detection/", "runtime_modules": [ "C:\\Windows\\system32\\dxgiadaptercache.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\gdi32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\system32\\d3d12.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "Dxpserver.exe-9965747D48FDAB2B468051F1168339DA": { "file_name": "Dxpserver.exe", "file_path": "C:\\Windows\\system32\\Dxpserver.exe", "hash_md5": "9965747D48FDAB2B468051F1168339DA", "hash_sha1": "6820AF53C10814A666D6FEDFCB49FB79C9DE53AB", "hash_sha256": "914714AC5287F34E5C836ABD6BD918C8F68FCB805990EF7BAB378BFE4DA27F44", "hash_sha384": "DA20563E838D33385D62062D48E499CA9B0343B13E1B98B68F1858273CADB8198B73DDE1C802D6CD003C7ECDDA3B1755", "hash_sha512": "1C20C51A487C4227FD057B8821FF55AE4E4874EC5FF495DA0920D21088A88669F22BAA88DFD2E55461F76AFDAD95A64E08A287E57F1D60B670B1A59E953947E5", "hash_ssdeep": "6144:NtyMZ6s/52E+/7pJ0mYNJ8V6IreJm3wAV:NtyMU4sRdoICawA", "hash_imp": "D9B5765D61DA505C6A851775EF26187C", "hash_pesha1": "BDBB0B933A3EC80ACCA7A10B45A74D40214E4849", "hash_pe256": "17028AEB448E2E6C6AD70B84D4AEB3FA3F8D96B18FA2420158DA64064365479C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Stage Platform Server", "meta_original_filename": "DXPServer.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/57", "filescan_vtlink": "https://www.virustotal.com/gui/file/914714ac5287f34e5c836abd6bd918c8f68fcb805990ef7bab378bfe4da27f44/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "(R-D) C:\\Windows\\System32\\en-US\\dxpserver.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\RPC Control\\DSECB94": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Dxpserver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\system32\\msi.dll", "C:\\Windows\\System32\\bcrypt.dll" ] }, "Eap3Host.exe-ECF9FA34803CBA8A3FC78E8BFB1C707E": { "file_name": "Eap3Host.exe", "file_path": "C:\\Windows\\system32\\Eap3Host.exe", "hash_md5": "ECF9FA34803CBA8A3FC78E8BFB1C707E", "hash_sha1": "04B46438D399DBAB474969957E60AE35BCB77525", "hash_sha256": "02879A69BB7A97A15FFF2FA2F9CE1FDC2811104C88B72873E915167C9B70AEBB", "hash_sha384": "E0161462D70A417F7CD47F3CE7AEBBD1369E1BE39E376DB0E2EED386B73169A551F8B654E5AB5083684800EE28E3167A", "hash_sha512": "B299EE31068A6A2243FE6523F683174B08838E362FF821FD7EB2C37AC8890066ACFE8EED0B189ACBEB477FEEB7B9CB27491A27EA7B4353A723970E72A7A3C6D2", "hash_ssdeep": "384:rFVnmTTtoIY70NLe2LVWOPVN6elBO84papWJaW:r4TtU0NpWON00O84paU", "hash_imp": "39A0A62D4EC9FCB9DC7B3B19151FB19A", "hash_pesha1": "4042B4548EF438F1C9E24A3B4EC89E3C21DC1DC8", "hash_pe256": "2F5942C6C670EB133A9425457787B81A24332653A5F2FDB8334E8B92FFEB2D92", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Eap Third Party Surrogate Host", "meta_original_filename": "Eap3Host.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/02879a69bb7a97a15fff2fa2f9ce1fdc2811104c88b72873e915167c9b70aebb/detection/" }, "EaseOfAccessDialog.exe-0490B8F08575C7AB5F358B07C1617F28": { "file_name": "EaseOfAccessDialog.exe", "file_path": "C:\\Windows\\system32\\EaseOfAccessDialog.exe", "hash_md5": "0490B8F08575C7AB5F358B07C1617F28", "hash_sha1": "E036E3E33F85B5C294A084B7B3ABCEB1D507440E", "hash_sha256": "E9BD8D062577D377C11E78F39E004574E8ED809E3D7D311F1965259467185805", "hash_sha384": "DCF34CD887EFDBA5F9DA5DBF634454647E79549F54F3EB9BC1A0DFF8FC5F6CD15EC1FBAC704BA27448D8D380F702B161", "hash_sha512": "23309AE73F8DFF58DE68DFEC9E026682EAA2F447364F08A6C255E07A6D897D499F9BC99C2D6CB1FB01C1F193482FF212389728DF22EE496BF40DBA779EBAFBC2", "hash_ssdeep": "6144:Cf5vq5uionZZ76aAlGrX6uFz2LJGRg4kLNnei36cw:oy5up60FCdUc", "hash_imp": "18778CF3FE502E34DB051EF365A692CB", "hash_pesha1": "66624FD76E0E81804A40BA7F51CF3B05CB1719D9", "hash_pe256": "D65562DB98661B4CC2DDC091C01AA19B892BFDFBA6CCED663298D36A4542BABA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Ease of Access Dialog Host", "meta_original_filename": "EaseOfAccessDialog.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e9bd8d062577d377c11e78f39e004574e8ed809e3d7d311f1965259467185805/detection/" }, "easinvoker.exe-BEBA5F5A62E1E3A01F1ADB028192E475": { "file_name": "easinvoker.exe", "file_path": "C:\\Windows\\system32\\easinvoker.exe", "hash_md5": "BEBA5F5A62E1E3A01F1ADB028192E475", "hash_sha1": "9E22D7A129074E118531BF328E75235FA5135BE4", "hash_sha256": "D6C7259046E76E147E2D0F40329E0605287C80A51E6417BABCD4B5D9998949CE", "hash_sha384": "A2B06AC98D3DD403AD51F5B957EA0F09F9916594E2F843F805471C2B58B7CDBB4838C46999A93A71C1120C36AAF4A686", "hash_sha512": "648F10DC7FFBE660C9BEAB755AABC831299D78AFA70BB94FA89CDE6DD3A1CEFFA567C9509B0045A078D587300034342151E5434FCB8ECBEE44C1FE232FE9856B", "hash_ssdeep": "1536:TUilM88czDUYbnZl9GRUx996Zu2xXibswbTYJz5R6ZfQ3qpPK:TZDRZl9GRPu2xXibswbUT6RSii", "hash_imp": "B9666648F462F12EAFF9CE3670385097", "hash_pesha1": "3F7870F750EE6090F88429254ACA3570C8B18FD9", "hash_pe256": "FC5EB0D00B2004E8C62F800D098BFA32FAB073A0FCCD8E07B242B1C785D7306E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Exchange ActiveSync Invoker", "meta_original_filename": "easinvoker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/d6c7259046e76e147e2d0f40329e0605287c80a51e6417babcd4b5d9998949ce/detection/" }, "EDPCleanup.exe-92D3F4463E797E03B18496B33385745F": { "file_name": "EDPCleanup.exe", "file_path": "C:\\Windows\\system32\\EDPCleanup.exe", "hash_md5": "92D3F4463E797E03B18496B33385745F", "hash_sha1": "93A04F93804211A3B10177C674F3D8F5CFB4BD4B", "hash_sha256": "520FB5B97E1CEE2865DA53405E346C55F62F0CD6B2E7741C1345F5693CEE0E92", "hash_sha384": "A0A75D92225EB498EACE67B04D437A18AE9CC459954AA8D259ADB133862561255E3550C1BFA04E8ADE1C30723BA57D69", "hash_sha512": "B8692F7D22CFC996C1062E4B09061C23E960224E28BA712A89166E7A7EE7E2D9D2AA90D2D4E5BC548C7D832E0FC65464E41D461188504BFF78943DBF9EA86CDD", "hash_ssdeep": "3072:eEgphPw5x+oy3FuF/gCw9J8smY2f2q1XW/3NtHhj243cw:1ggi53QhgCg8smY2f2yXWDHhq43", "hash_imp": "3A5B90E227CE52C373C5E5BCF0550518", "hash_pesha1": "499E03E7AF8B3AAA0FC96059B23000AD3A0DD707", "hash_pe256": "FB6EA94EB4CB28B1B23FD9C10BC7F4DAF77D70F1111CF0CA5FEA274E770E99E4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EDP Cleanup", "meta_original_filename": "EDPCleanup.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/520fb5b97e1cee2865da53405e346c55f62f0cd6b2e7741c1345f5693cee0e92/detection/", "runtime_modules": [ "C:\\Windows\\system32\\EDPCleanup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\system32\\policymanager.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\FirewallAPI.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\netutils.dll" ] }, "edpnotify.exe-1049B4F14CECCEDBB21C4DA2B66E0306": { "file_name": "edpnotify.exe", "file_path": "C:\\Windows\\system32\\edpnotify.exe", "hash_md5": "1049B4F14CECCEDBB21C4DA2B66E0306", "hash_sha1": "9BAA57A3AC96C049C337E1894451BE8715855301", "hash_sha256": "22632A042E750A84FA52FF9561C03570334B11E5CEA2D50C525EB0EDC3ECD30B", "hash_sha384": "04D2FBAAA6EAD19ADE0AE3247EF84541F45B54551171CE228AEB8F336009F18AA1454D3605A948399A7664FAF29CC41A", "hash_sha512": "911BC9B2EC6216801130D063A12FE922C59E7EECF7878C2BA9835A302F3702F5BD4B674B0217742C18105B5F3C95E7D765630C36ABF1BF6EEA4F842C4A95EEC4", "hash_ssdeep": "1536:4JeKrS1/TfkQ1Ilb5ZCLplPd1t9mt9TrjNMfjdG47xdI:Ejg43b5ZSlS5+g41dI", "hash_imp": "4FEA0B63B180AD82ADA7841BA45D9E3C", "hash_pesha1": "4568A037A4B521690AE788E302E7019214E7E76F", "hash_pe256": "84C0285D3B9D4DB325C012A30818DE6C4E24687BD289BFE929AC9EECB359BC5B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Enterpise Data Protection", "meta_original_filename": "EdpNotify.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/22632a042e750a84fa52ff9561c03570334b11e5cea2d50c525eb0edc3ecd30b/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC11F8": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\edpnotify.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "efsui.exe-B7B54EB2FB46687264EDB25B9ADEC536": { "file_name": "efsui.exe", "file_path": "C:\\Windows\\system32\\efsui.exe", "hash_md5": "B7B54EB2FB46687264EDB25B9ADEC536", "hash_sha1": "9657819143FD2E3C87D0DE889B7380851E9CF7F7", "hash_sha256": "FE57813687D951FFA8ACC02BD4CA2AD8D7D4BC70584072DB66C46A404186DDF3", "hash_sha384": "CE46DB93B2418D8447C1CABA537D5D3D970E45C765C136D14377DD0C421E0202332C6243B86B58E2F09AC38ADE9E3E85", "hash_sha512": "EACB9BBBF516C3521D1D16E8E869E87D180C8AFBFDFFE8CF2A3C1FC51BFAE01A983690EF7F2E5DF0D4E7F456FB3B45AC3A6A12B7F2EE7A853571A2CC9827D8E7", "hash_ssdeep": "384:Xbv3o1u/syTtfHIifI1pIZX34ThWSoRW:rA16siaMIIZn4T2", "hash_imp": "79780253655B3282FD06EA62FCA2F32F", "hash_pesha1": "B8689BAEF0FB7FFAA84083F2700C22F9690BDC6F", "hash_pe256": "2BF2F499A77402ABB16617B5B5332E96725B4216DB8ABBB5A5C969D634F14D6C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EFS UI Application", "meta_original_filename": "efsui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/fe57813687d951ffa8acc02bd4ca2ad8d7d4bc70584072db66c46a404186ddf3/detection/", "runtime_modules": [ "C:\\Windows\\system32\\efsui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\EFSADU.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\EFSUTIL.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\system32\\DSROLE.dll", "C:\\Windows\\system32\\logoncli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\VAULTCLI.dll", "C:\\Windows\\system32\\credui.dll", "C:\\Windows\\system32\\CRYPTUI.dll", "C:\\Windows\\system32\\FeClient.dll", "C:\\Windows\\system32\\urlmon.dll", "C:\\Windows\\system32\\ncrypt.dll", "C:\\Windows\\SYSTEM32\\wintypes.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\system32\\NTASN1.dll", "C:\\Windows\\system32\\CRYPTBASE.DLL", "C:\\Windows\\System32\\IMM32.DLL" ] }, "EhStorAuthn.exe-9657C921DC6703DE71288C1BE50A7826": { "file_name": "EhStorAuthn.exe", "file_path": "C:\\Windows\\system32\\EhStorAuthn.exe", "hash_md5": "9657C921DC6703DE71288C1BE50A7826", "hash_sha1": "2D1DD4B8ABBED219FDD9938144284E75F13F8396", "hash_sha256": "F7A1ACF775987523B769F2C5E389BC0B6BCB2DC8D80B3EA0F76C1014E824B3C1", "hash_sha384": "03505CCD8F77A73B71BE964DEDEA07991421FF3AA271BF0B93850A4397C2F2A61B3E3BACDD77268F6946B861FC421F40", "hash_sha512": "2207E351704909B6C84661A8BACEECAA48F6053C3F2885143EC288547378B45E1DD1A6D199995F1CC146DE13EE06B47215087169AC0102577A0A325519679A86", "hash_ssdeep": "1536:/tUJVgNnVqfBDkNe0XZ28Pmj/YQq2hKxyy2L5IIw0oeomgPHA5kG9mQ7N6wMkNaA:/+yqfBD18uTzvPL2b0oxPxQZDFcZIZR", "hash_imp": "781D28469BB74D268EAF05BBBB5DA822", "hash_pesha1": "039E2D537239AF4637574BD4C30E6382D9932E89", "hash_pe256": "02789E2544FCD31E50A376F51835E0A9F7938AABB900FB9F3149D3C96EC89CC9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Enhanced Storage Authentication Program", "meta_original_filename": "EhStorAuthn.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/f7a1acf775987523b769f2c5e389bc0b6bcb2dc8d80b3ea0f76c1014e824b3c1/detection/" }, "escUnattend.exe-218719C38D2A27B9788782CE92ECDD84": { "file_name": "escUnattend.exe", "file_path": "C:\\Windows\\system32\\escUnattend.exe", "hash_md5": "218719C38D2A27B9788782CE92ECDD84", "hash_sha1": "48E8EE7C34084BAE62758D03894A3D0CB0C1F408", "hash_sha256": "10BBC02017496413F6D31AD21561B96443D9582D5A4FE528F54FCB479EEF4FC9", "hash_sha384": "9EE57FF2AABF10ADDECD896712B444B26FB1D35FDBF8BC8E1AB875F93B2C2E5CE61CB9EBD7E0956F1ADCA65050B1B0B5", "hash_sha512": "FE61F70579FA103ACC2FB990EF6A9CF70E48973652DA11B60227C79BE7E7D5A3B974878893427D5B68FC53436BEA06AC9F53132C2B497F8340D48BA2C0148D85", "hash_ssdeep": "1536:lBRGiEZmylLzo+IDUmh7peWqm/VqL4lp7C8ti:40+g5QngpO2i", "hash_imp": "8B048653C852C221057F23F7F73AE071", "hash_pesha1": "4E6462B3F6D031F26089C2445A51BF7888937DCF", "hash_pe256": "D0FD173706D557DC12FEE3FBC5317B5672CA570EDA73408DD1A76D6F2B24FDB6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IE ESC 7.0 Unattended Install Utility", "meta_original_filename": "ESCUNATTEND.EXE", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/10bbc02017496413f6d31ad21561b96443d9582d5a4fe528f54fcb479eef4fc9/detection/", "children": "rundll32.exe", "runtime_modules": [ "C:\\Windows\\system32\\escUnattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "esentutl.exe-F4A95FA21D15E8F93B75EA73D6E915CA": { "file_name": "esentutl.exe", "file_path": "C:\\Windows\\system32\\esentutl.exe", "hash_md5": "F4A95FA21D15E8F93B75EA73D6E915CA", "hash_sha1": "488E665A9727699D65EF1E16258CB50B3A649376", "hash_sha256": "A3EE005C46F1DEA44F2AFFD99C3BD1545B7D5448CB54CF774841CF93DA5A7208", "hash_sha384": "575619539856EF93F885FC332233F78491914B33F801855E061A4A22EA4543FC637C71AEBC0ED5DBDD27555F47FD05B6", "hash_sha512": "461D6B69110EF0C948AA85006F8E3A6FC241EE660981FE3D34C3DA237CDDDEB78DE97DEF43DE752AAACA802B3212B172849F95B23C806221273159D856A15624", "hash_ssdeep": "6144:fDv96MPOaLjjT3LpVEcZZ06TkVzxtaEpVJo5BeOuLK2G0LaoYd5kHjz:7l6MpjXLpnZUMBeOuLG0Nj", "hash_imp": "9CD95101939BE1ED73A8EBE85664EB5E", "hash_pesha1": "1274E5AAEB8442F59EA280E49584E2318B6F2D97", "hash_pe256": "3F113AF80182FD3B5475BA9D3C6792976A896839E60099AFF352DC8C3AE866A2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extensible Storage Engine Utilities for Microsoft(R) Windows(R)", "meta_original_filename": "esentutl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.529 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.529", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/a3ee005c46f1dea44f2affd99c3bd1545b7d5448cb54cf774841cf93da5a7208/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\esentutl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\ESENT.dll" ] }, "eudcedit.exe-408DC5DB105FFCE3B70B09AF77E12AEC": { "file_name": "eudcedit.exe", "file_path": "C:\\Windows\\system32\\eudcedit.exe", "hash_md5": "408DC5DB105FFCE3B70B09AF77E12AEC", "hash_sha1": "2250405290FF03EFC545235A438ACDA532E0C843", "hash_sha256": "69A75AF2A72D2BB5BDFE7FBED5D155BD0CA0F466C8AFF9F762C3C8CB182CE8ED", "hash_sha384": "4274D7F7FA166225260E99FFB79CBF22A2D2B3810A0C5462D8795E6722778287BE92CEAD3809252FF430E540C4582241", "hash_sha512": "E5EA5BB824933FA65EED59ED2EA2CD3289211FE5EF8CEC03C891BCAF1914D22641E9501CA7797B61E56767E09FD667E205D935EE7DC4E24249BFA04B7A3B8AA2", "hash_ssdeep": "6144:CjbJp4VmCeYhDnyyEdRFs4ds4WTRANeEpCem6j4TPhqyF1PZSqtYVY:Cjn4tdERFsxTRnTB13tYC", "hash_imp": "55BB7E6E402D2FD81031D28641F5F78D", "hash_pesha1": "D39282C9E4BB9107B50DE674ED9B127AE3E4E680", "hash_pe256": "7E24572911F575E0EC53D3D3A1D53EA0ADCDADA347B7EFD3A75E91F76D694A3C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Private Character Editor", "meta_original_filename": "EUDCEDIT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/69a75af2a72d2bb5bdfe7fbed5d155bd0ca0f466c8aff9f762c3c8cb182ce8ed/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\eudcedit.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\eudcedit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\MFC42u.dll" ], "runtime_window_title": "Private Character Editor " }, "eventcreate.exe-2A8F8AF71D1ADB9E15153593D2B7E795": { "file_name": "eventcreate.exe", "file_path": "C:\\Windows\\system32\\eventcreate.exe", "hash_md5": "2A8F8AF71D1ADB9E15153593D2B7E795", "hash_sha1": "2D50B3F659240762714789DB84C2A35A983CC15F", "hash_sha256": "F8A2DE8135A402BEDBDC3DBEB87677B70793E4AFEEF8A66B9792EA0C0315302E", "hash_sha384": "8AEC22F3F31570C9DB32E8CE08F32D4662168998E0CE3BBADEE0FD4DE830BA3E0B19276D81522C17972A13CA96954DB0", "hash_sha512": "01FBE73D08961161B356AAE8E134CFD578AC591ADC379FCF5A127BEC0BBE552AB819A0D5515F10EF70624CE33348FB888453C884DDDC65B94DC312EB47A09A19", "hash_ssdeep": "768:A08kXeHVlWS2W/7YrgVWtSVSP3xt/WS9SkYQTpGZnlXOoa/QU:Ake74EV0Oi79SkYQmnlXva/QU", "hash_imp": "AFD01C6C03BABAB564D0A0CDA1CD4649", "hash_pesha1": "891AE2E0F8DC8E81D9DD90C05DF9C832266D54DF", "hash_pe256": "A84B01C7D6600D722DC648F416814BEF04999433226F6AAA928B192B037973CC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Create - Creates a custom event in an event log", "meta_original_filename": "evcreate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/f8a2de8135a402bedbdc3dbeb87677b70793e4afeef8a66b9792ea0c0315302e/detection/", "output": "\r\nEVENTCREATE [/S system [/U username [/P [password]]]] /ID eventid\r\n [/L logname] [/SO srcname] /T type /D description\r\n\r\nDescription:\r\n This command line tool enables an administrator to create\r\n a custom event ID and message in a specified event log.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /L logname Specifies the event log to create\r\n an event in.\r\n\r\n /T type Specifies the type of event to create.\r\n Valid types: SUCCESS, ERROR, WARNING, INFORMATION.\r\n\r\n /SO source Specifies the source to use for the\r\n event (if not specified, source will default\r\n to 'eventcreate'). A valid source can be any\r\n string and should represent the application\r\n or component that is generating the event.\r\n\r\n /ID id Specifies the event ID for the event. A\r\n valid custom message ID is in the range\r\n of 1 - 1000.\r\n\r\n /D description Specifies the description text for the new event.\r\n\r\n /? Displays this help message.\r\n\r\n\r\nExamples:\r\n EVENTCREATE /T ERROR /ID 1000\r\n /L APPLICATION /D \"My custom error event for the application log\"\r\n\r\n EVENTCREATE /T ERROR /ID 999 /L APPLICATION\r\n /SO WinWord /D \"Winword event 999 happened due to low diskspace\"\r\n\r\n EVENTCREATE /S system /T ERROR /ID 100\r\n /L APPLICATION /D \"Custom job failed to install\"\r\n\r\n EVENTCREATE /S system /U user /P password /ID 1 /T ERROR\r\n /L APPLICATION /D \"User access failed due to invalid user credentials\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"EVENTCREATE /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\eventcreate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "eventvwr.exe-43129C3BFC9746CE9FFE8E45D10FE050": { "file_name": "eventvwr.exe", "file_path": "C:\\Windows\\system32\\eventvwr.exe", "hash_md5": "43129C3BFC9746CE9FFE8E45D10FE050", "hash_sha1": "1AF3BB8D63A0ED48DF1F1706B791404DEE28524F", "hash_sha256": "BC87E4F462F00B826EC09AC16B625D0F70439C48FC04A52A41B4CD9E78401F70", "hash_sha384": "4F268286A2CB8D2D911AE4B15AF7C96D2A2695525CBE25B1146F0F1F84E6FAE9372CA7C7513F0B6B9C98E443B9CF86AF", "hash_sha512": "09113DBB676B7F169A19842B2EF87C1EE206AB7C0C0947A302D04F8C3832B88BA4D5AD13215D4C007FC3F21FAA78CF0F4294121C50EDA5CB57CC01D32A462D5C", "hash_ssdeep": "1536:vpq3DFB5IMfoJUhSU6nPlTggJ2oj71BgR/Vp8dY1k:x6V3lhzslTZJ9j7Heb8C1k", "hash_imp": "5843AE9886BB500E05E07EE59BB5AD42", "hash_pesha1": "6663EA2A20FA8FD9A70D60D2486635FED9E3196B", "hash_pe256": "CBD31726B6AE4B8E545F7CD0111A49135DFC3FDAE61852B74465B9F5399A29A2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Viewer Snapin Launcher", "meta_original_filename": "eventvwr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/bc87e4f462f00b826ec09ac16b625d0f70439c48fc04a52a41b4cd9e78401f70/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\eventvwr.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "Event Viewer", "children": "mmc.exe", "runtime_modules": [ "C:\\Windows\\system32\\eventvwr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll" ] }, "expand.exe-7395D1ACEAC1FD7790DD59F12DFCDEFB": { "file_name": "expand.exe", "file_path": "C:\\Windows\\system32\\expand.exe", "hash_md5": "7395D1ACEAC1FD7790DD59F12DFCDEFB", "hash_sha1": "4EF388EA8716D903CA8EE1E1C4AC341594C2A41C", "hash_sha256": "3D263DF4D7AB8B2B408713ED42B87EC355E33617B8B8249FCBD8BE52D1A50F25", "hash_sha384": "F39355A0D205CD9C4EB88B98D2BA4CCEF909F783B3FEA6D43E86979E599DA9A16F5C29BC05B867E6BD4FFDC89ABAE85B", "hash_sha512": "5FD8AB89081CD3E20BA93E6F219C43796F4B0679C7C8E6808E89C1C249DE7ED8F8D719CC49BFB29D790427BA03D4949BC3D3385601B382FE6C04985318CE52B9", "hash_ssdeep": "768:Ou/msq2r0flBpp4C2f7FNr9Zx2zP+7bbDD3ihyhXxvP8viaAjprTllDyVO1vTzwV:OSmsdeBpparkzG7DcI1PRHuYHwFaUn", "hash_imp": "8BB8291E08A891E3DCA4B595B2F1D718", "hash_pesha1": "7AEA782B2689A8ABA57321CA71315A16795251D7", "hash_pe256": "30BE3E30CD4DE6B69A850DC74664613F677D37F8BDA1EBB754D2CE14BC94744D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "LZ Expansion Utility", "meta_original_filename": "expand", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.00 (WinBuild.160101.0800)", "meta_product_version": "5.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/3d263df4d7ab8b2b408713ed42b87ec355e33617b8b8249fcbd8be52d1a50f25/detection/", "output": "Microsoft (R) File Expansion Utility\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nExpands one or more compressed files.\r\n\r\nEXPAND [-R] Source Destination\r\nEXPAND -R Source [Destination]\r\nEXPAND -I Source [Destination]\r\nEXPAND -D Source.cab [-F:Files]\r\nEXPAND Source.cab -F:Files Destination\r\n\r\n -R\t\tRename expanded files.\r\n -I\t\tRename expanded files but ignore directory structure.\r\n -D\t\tDisplay list of files in source.\r\n Source\tSource file specification. Wildcards may be used.\r\n -F:Files\tName of files to expand from a .CAB.\r\n Destination\tDestination file | path specification.\r\n\t\tDestination may be a directory.\r\n\t\tIf Source is multiple files and -r is not specified,\r\n\t\tDestination must be a directory.\r\n" }, "extrac32.exe-8D6D545BA6D9BA01A18D52A28BDAC15A": { "file_name": "extrac32.exe", "file_path": "C:\\Windows\\system32\\extrac32.exe", "hash_md5": "8D6D545BA6D9BA01A18D52A28BDAC15A", "hash_sha1": "8935E73FDC7927E853E06CC2BC798CEBF9BC8B7E", "hash_sha256": "53BEF52AA01713756DB903DC6A6983543217219D898B78E75B0E0642C02BBD45", "hash_sha384": "5FC9344F054962E3DFBA2FCCC25F3C4CCADFD44489BC98C5948FD027C0EFEC8E6E447C721C9801CE9B4765410076A128", "hash_sha512": "3636BA749CFCC9DC072F2A91B420D2752649AE25A0A58835D78386F7F13B74CBA27B3D8B51A84713DC5BFED6DECBB8C5D01ED24B0585B5D085088E95ED88963A", "hash_ssdeep": "768:LGR0UuK1ZZEAYPE9i1q5FhlNzxTfjz7zaoDxeaP9OUe2TvKA:QT5EJE9iwxxTfjz7zaexeq9OUeiKA", "hash_imp": "9E8A016B1763601647B4DFBEF00DAC86", "hash_pesha1": "C4448FCB9F8F8DFEA2E74540763EC3B5D926C3CA", "hash_pe256": "D9C629DFA7D64A5E0F3E9B51999D7274934AB09D1A0D8C6058D5A3A56BCCEF64", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft CAB File Extract Utility", "meta_original_filename": "extrac32.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.00 (WinBuild.160101.0800)", "meta_product_version": "5.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/53bef52aa01713756db903dc6a6983543217219d898b78e75b0e0642c02bbd45/detection/", "output": "Microsoft (R) Cabinet Extraction Tool\r\nCopyright (c) Microsoft Corporation. All rights reserved..\r\n\r\nEXTRACT [/Y] [/A] [/D | /E] [/L dir] cabinet [filename ...]\r\nEXTRACT [/Y] source [newname]\r\nEXTRACT [/Y] /C source destination\r\n\r\n cabinet - Cabinet file (contains two or more files).\r\n filename - Name of the file to extract from the cabinet.\r\n Wild cards and multiple filenames (separated by\r\n blanks) may be used.\r\n\r\n source - Compressed file (a cabinet with only one file).\r\n newname - New filename to give the extracted file.\r\n If not supplied, the original name is used.\r\n\r\n /A Process ALL cabinets. Follows cabinet chain\r\n starting in first cabinet mentioned.\r\n /C Copy source file to destination (to copy from DMF disks).\r\n /D Display cabinet directory (use with filename to avoid extract).\r\n /E Extract (use instead of *.* to extract all files).\r\n /L dir Location to place extracted files (default is current directory).\r\n /Y Do not prompt before overwriting an existing file." }, "fc.exe-041DD62718BF388E6671F00BF2FE68A4": { "file_name": "fc.exe", "file_path": "C:\\Windows\\system32\\fc.exe", "hash_md5": "041DD62718BF388E6671F00BF2FE68A4", "hash_sha1": "D808ED9E5FEAA8DC9227CE05DE4F352B52B35ECC", "hash_sha256": "953BCC35710ED410212BD56CDEA2E25FD9BC013707DF17CB203E102A4F9C05DA", "hash_sha384": "ACC6FCCCCBC0F20340A46D27F814711D36DAD5CB046C135226561696C8712E41F8CBEA81B6D92C032E5211BDA229DE44", "hash_sha512": "A6FC31D6479A50994733757ECD8628120424EEEE87D31DA697807746C885EF637F6E033C2781873E96DAFFA337BBC8F0F040323675FFE56CAC4C6059FDAF5E56", "hash_ssdeep": "384:gZC8g8G2Za8TMqgJBsByUWRcAzjLhgXWC5XGKK74KC81WWaYW:QC8UUAqgUM3t6XWWXGXfC", "hash_imp": "89BAD98DE0A45ABD45AFD0C86A8F82A6", "hash_pesha1": "10728099AD1863D7487F6FBE91CA164003D100DB", "hash_pe256": "77A5D50CF4E3FE0FE6EF9B2C6FD48FFC97672533249CFFA1B6AA08B62D0E5C74", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DOS 5 File Compare Utility", "meta_original_filename": "FC.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/953bcc35710ed410212bd56cdea2e25fd9bc013707df17cb203e102a4f9c05da/detection/", "output": "Compares two files or sets of files and displays the differences between\r\nthem\r\n\r\n\r\nFC [/A] [/C] [/L] [/LBn] [/N] [/OFF[LINE]] [/T] [/U] [/W] [/nnnn]\r\n [drive1:][path1]filename1 [drive2:][path2]filename2\r\nFC /B [drive1:][path1]filename1 [drive2:][path2]filename2\r\n\r\n /A Displays only first and last lines for each set of differences.\r\n /B Performs a binary comparison.\r\n /C Disregards the case of letters.\r\n /L Compares files as ASCII text.\r\n /LBn Sets the maximum consecutive mismatches to the specified\r\n number of lines.\r\n /N Displays the line numbers on an ASCII comparison.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n /T Does not expand tabs to spaces.\r\n /U Compare files as UNICODE text files.\r\n /W Compresses white space (tabs and spaces) for comparison.\r\n /nnnn Specifies the number of consecutive lines that must match\r\n after a mismatch.\r\n [drive1:][path1]filename1\r\n Specifies the first file or set of files to compare.\r\n [drive2:][path2]filename2\r\n Specifies the second file or set of files to compare.\r\n\r\n", "error": "FC: Insufficient number of file specifications\r\n\r\n" }, "find.exe-C5444A421B6A80A5BEEE96BC612D0F3D": { "file_name": "find.exe", "file_path": "C:\\Windows\\system32\\find.exe", "hash_md5": "C5444A421B6A80A5BEEE96BC612D0F3D", "hash_sha1": "F7921C43BBE20B5A9B75FDE5A0B0443C5BB6D63F", "hash_sha256": "A3D85036BCB0B3B50691E02D1952821E7B943680D8F8E4CC16613D2C72F44E6C", "hash_sha384": "CBFA6A0582C340774644CC02B1559F2FE706DB281F3CEA07FBBFD6693D557C4F16A88B54092038D366588D8ECFA0D038", "hash_sha512": "CC6C3D95D1E18C5B35FA1BA84957C4332A2792DF3183C5B5BFC367448CA167265C430DCB4EA3C3925D6A60247DA3A75CE2B218ABAF4CC14741B716158A22F451", "hash_ssdeep": "384:PBUoQMh4zBUseDqS1TqT/npl1LYo9DWpIW:ujKD1spTL99i", "hash_imp": "EF85879194FF4D8C5632D025B0B0AFDE", "hash_pesha1": "4D767957AA19E3CFB943D7827A337920A663D5B6", "hash_pe256": "CCAF9542B8B8E168C332984BC42A473922A7B121895914BD24DE27B48C92F612", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Find String (grep) Utility", "meta_original_filename": "FIND.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a3d85036bcb0b3b50691e02d1952821e7b943680d8f8e4cc16613d2c72f44e6c/detection/", "output": "Searches for a text string in a file or files.\r\n\r\nFIND [/V] [/C] [/N] [/I] [/OFF[LINE]] \"string\" [[drive:][path]filename[ ...]]\r\n\r\n /V Displays all lines NOT containing the specified string.\r\n /C Displays only the count of lines containing the string.\r\n /N Displays line numbers with the displayed lines.\r\n /I Ignores the case of characters when searching for the string.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n \"string\" Specifies the text string to find.\r\n [drive:][path]filename\r\n Specifies a file or files to search.\r\n\r\nIf a path is not specified, FIND searches the text typed at the prompt\r\nor piped from another command.\r\n", "error": "FIND: Parameter format not correct\r\n" }, "findstr.exe-DC0816790EFA08AA5B55C1EECFDDB525": { "file_name": "findstr.exe", "file_path": "C:\\Windows\\system32\\findstr.exe", "hash_md5": "DC0816790EFA08AA5B55C1EECFDDB525", "hash_sha1": "393F2422D22079BFB0022598D70BEB294F2024F4", "hash_sha256": "750AB5E1F3EB18CC42A4A4C7BAB27753F6B26FB9752AD3861833753091044281", "hash_sha384": "E93D7C15A9B9A70C84AB2D796A1FE5445A9DDA1C06AAC0E21EF16EF85273FA06A7DC1FAF1639B6BEC9CB33F3DC7BDF0D", "hash_sha512": "0DFE914706EFE1C3888636029A00C67E10D8E7B0729F6E46BA27B6EC37617A863BFD7838D4634D0CDCFE7894069F5B549BA70225FC334DAB65276EEAFF17F8E5", "hash_ssdeep": "768:Nr9pUJQVmhBubVEvVuVXU9/biWClj9RB8BgS7uTyRe6S9th0lTd:hTuH6bVEqEwNlj9RW7umRdSXh0lTd", "hash_imp": "A27641A39DA5A6B0717E06BA00E56B7F", "hash_pesha1": "3189BD7DEC888728609B901362829FEDA8E88BD8", "hash_pe256": "B92CF70DF5CE8DC6BE224A520679CF467C7FBEDF54433D9A3B54CCAADA95AE3D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Find String (QGREP) Utility", "meta_original_filename": "FINDSTR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/750ab5e1f3eb18cc42a4a4c7bab27753f6b26fb9752ad3861833753091044281/detection/", "output": "Searches for strings in files.\r\n\r\nFINDSTR [/B] [/E] [/L] [/R] [/S] [/I] [/X] [/V] [/N] [/M] [/O] [/P] [/F:file]\r\n [/C:string] [/G:file] [/D:dir list] [/A:color attributes] [/OFF[LINE]]\r\n strings [[drive:][path]filename[ ...]]\r\n\r\n /B Matches pattern if at the beginning of a line.\r\n /E Matches pattern if at the end of a line.\r\n /L Uses search strings literally.\r\n /R Uses search strings as regular expressions.\r\n /S Searches for matching files in the current directory and all\r\n subdirectories.\r\n /I Specifies that the search is not to be case-sensitive.\r\n /X Prints lines that match exactly.\r\n /V Prints only lines that do not contain a match.\r\n /N Prints the line number before each line that matches.\r\n /M Prints only the filename if a file contains a match.\r\n /O Prints character offset before each matching line.\r\n /P Skip files with non-printable characters.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n /A:attr Specifies color attribute with two hex digits. See \"color /?\"\r\n /F:file Reads file list from the specified file(/ stands for console).\r\n /C:string Uses specified string as a literal search string.\r\n /G:file Gets search strings from the specified file(/ stands for console).\r\n /D:dir Search a semicolon delimited list of directories\r\n strings Text to be searched for.\r\n [drive:][path]filename\r\n Specifies a file or files to search.\r\n\r\nUse spaces to separate multiple search strings unless the argument is prefixed\r\nwith /C. For example, 'FINDSTR \"hello there\" x.y' searches for \"hello\" or\r\n\"there\" in file x.y. 'FINDSTR /C:\"hello there\" x.y' searches for\r\n\"hello there\" in file x.y.\r\n\r\nRegular expression quick reference:\r\n . Wildcard: any character\r\n * Repeat: zero or more occurrences of previous character or class\r\n ^ Line position: beginning of line\r\n $ Line position: end of line\r\n [class] Character class: any one character in set\r\n [^class] Inverse class: any one character not in set\r\n [x-y] Range: any characters within the specified range\r\n \\x Escape: literal use of metacharacter x\r\n \\<xyz Word position: beginning of word\r\n xyz\\> Word position: end of word\r\n\r\nFor full information on FINDSTR regular expressions refer to the online Command\r\nReference.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\findstr.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\findstr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "error": "FINDSTR: /- ignored\r\nFINDSTR: /h ignored\r\nFINDSTR: Bad command line\r\n" }, "finger.exe-7072125EE25D342DF114919ED68D34A1": { "file_name": "finger.exe", "file_path": "C:\\Windows\\system32\\finger.exe", "hash_md5": "7072125EE25D342DF114919ED68D34A1", "hash_sha1": "080F2EDD1356B97E2C90268F68CC9BA3177F7B83", "hash_sha256": "BBB90F52D01BE03C297A6D4921C79E26D3CEDA6DAB20366E32A20907E015FBE1", "hash_sha384": "5DF72AABADF58D4088AFAF4F5BB43D6FC5C290F1976CFEEF965F0E7A29BB98630F0E8D1BAFC0837533B2AE2A1D0DAE0C", "hash_sha512": "29F86BFD186FE2BFC93A32548F9BB4476FFC4F8F60D9B10917357B0BED977EEFB80AEBD3814762B5A3A8BF8CE1E1C66525023586174D8797ACE0CC6BFDA8297C", "hash_ssdeep": "192:vT+V81sDF09kycvbhH+u6pePFkzCM0Mh08G9EQjNEwzru/aW60W:vT+VCUF09FcDdEpedkU58EjNbzHW60W", "hash_imp": "E1B908A2F0F52AE305808122ED02A033", "hash_pesha1": "26E66493598AB124A5371D1A11FD128689F94D68", "hash_pe256": "20A5FAD6EE8E6C59D23F6191A7FC20C973175FE83E5104F37B40A3109A56B4DC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCPIP Finger Command", "meta_original_filename": "finger.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/bbb90f52d01be03c297a6d4921c79e26d3ceda6dab20366e32a20907e015fbe1/detection/", "error": "\r\nDisplays information about a user on a specified system running the\r\nFinger service. Output varies based on the remote system.\r\n\r\nFINGER [-l] [user]@host [...]\r\n\r\n -l Displays information in long list format.\r\n user Specifies the user you want information about. Omit the user\r\n parameter to display information about all users on the\r\n specifed host.\r\n @host Specifies the server on the remote system whose users you\r\n want information about.\r\n\r\n", "output": "\r\n[Default-PC]\r\n", "children": "conhost.exe", "runtime_modules": [ "C:\\Windows\\system32\\finger.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "fixmapi.exe-87D4EAD5A9010859F0F9D624069E329A": { "file_name": "fixmapi.exe", "file_path": "C:\\Windows\\system32\\fixmapi.exe", "hash_md5": "87D4EAD5A9010859F0F9D624069E329A", "hash_sha1": "4B36BF973C92C580FAD37BEA52C0FF1F028DB4EE", "hash_sha256": "E8731BD8598B3021F209AEA528B8BAEA94B6C11B893247132BB8CAD16A018E7A", "hash_sha384": "0E4EE125B77D9AFA52FA3B34512611C6BAEA087B0E7510AD3F34EA21227A67B5ED4966AC73B13617AE8C1F38E302C95B", "hash_sha512": "787F18507A2D4C81A3D0EEDAAF04F373FD34F4506781E7F64B81BB98888FE7E5C37C2D67487E5BAA921B33132D308AB003C61434E3767E9BD4278D7361365007", "hash_ssdeep": "384:b0OMetkg5B8lbH0NbNDhJK9tvWqJkAaLIDtlLLarajmgWWnWDw:2wkVH0NbND69tvWpLIplva50", "hash_imp": "671476B97F9417A9DD566A255C7365DD", "hash_pesha1": "D18796D0DE595C34CDDECACFE15428FCF3635D21", "hash_pe256": "D9382410FAFCD045806321404E9AFD4ED876C192F852535EBF629FCBD596381B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "FIXMAPI 1.0 MAPI Repair Tool", "meta_original_filename": "FIXMAPI.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e8731bd8598b3021f209aea528b8baea94b6c11b893247132bb8cad16a018e7a/detection/", "runtime_modules": [ "C:\\Windows\\system32\\fixmapi.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "fltMC.exe-BCACCF194BEED1DCE5619C63D21F7112": { "file_name": "fltMC.exe", "file_path": "C:\\Windows\\system32\\fltMC.exe", "hash_md5": "BCACCF194BEED1DCE5619C63D21F7112", "hash_sha1": "D687EFAFF69FDE523BF638A87CDA3011307742F7", "hash_sha256": "E353C7945308C1220319CBB69E2A2370334D7849304EB3BB7B1D2FD811C4324E", "hash_sha384": "6487559081277CB80496884D977BD8BB9B2991A38CBB3C74FB8660BC4DB171381BB8DA92B16BC0C907C06957A192F11E", "hash_sha512": "54C725FD71AA38C573505B9544487A1144298B0E1C5B5551D2FFF3BE461DE2FDFCBFBB9D6F288D480D0665141C8E9494A93901184EE52379565EADFD79B9F1CA", "hash_ssdeep": "384:ootQpz/lfQ1lNMqTXLnOKY3DpcfgDBsOc3a8emPu0XfIRpBwi1WT9W:oow/lfQLNMa7nOKY1DmLXIRpBwiW", "hash_imp": "F3A130AFBB5F42C25DFB7D99CBAFA050", "hash_pesha1": "CA3EFA517BFDF55C64D40811069B932DEEB50E21", "hash_pe256": "1F5E7DD2858C11EF2A2915332E5F11C7529F34BFD491D298CA0DA6AACB71E863", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Filter Manager Control Program", "meta_original_filename": "fltMC.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/e353c7945308c1220319cbb69e2a2370334d7849304eb3bb7b1d2fd811c4324e/detection/", "output": "\r\n** Invalid command\r\nValid commands:\r\n load Loads a Filter driver\r\n unload Unloads a Filter driver\r\n filters Lists the Filters currently registered in the system\r\n instances Lists the Instances for a Filter or Volume currently\r\n registered in the system\r\n volumes Lists all volumes/RDRs in the system\r\n attach Creates a Filter Instance to a Volume\r\n detach Removes a Filter Instance from a Volume\r\n\r\n Use fltmc help [ command ] for help on a specific command\r\n" }, "fodhelper.exe-F23BCF023D5039CCAB3AA40F6A07B817": { "file_name": "fodhelper.exe", "file_path": "C:\\Windows\\system32\\fodhelper.exe", "hash_md5": "F23BCF023D5039CCAB3AA40F6A07B817", "hash_sha1": "4D0DE1C3121F202604A01C6DC6F6A36F4A0A4619", "hash_sha256": "B1223B86D03C3583B84E46A9A6AD009D770FC4114640402EDE19793167593A8F", "hash_sha384": "9558658080010B4C92BE066A6090AE7E6063D6899476FFB4B4183FA3067BA55341D666B67871F6FF1D2DF062BEDCB0FD", "hash_sha512": "93249CCBF00B0CC62C9EB05535563C443A37830CE5EAB6EC068CA50EF544E9643F8C5E3E6EC484F6A1767F3D21894CD99D9329EC4BBF02FEE7BB895CC75BA394", "hash_ssdeep": "768:YqpZqknV+b+pvxg9JWSALQJnjpt6V3Glw1mHXrzg31TdavZZ7RRr:pqQApW3WOV3Gy1mHX61TSZZTr", "hash_imp": "2BD851C90720C3E5FEE7E3FF3ACFA3D5", "hash_pesha1": "36A86EAA24EBFFE7CF80D3A89E308F6799152FEE", "hash_pe256": "F3A3C2E5533051AD881B35EB27CFF08234552D03F198BBC7ED8E8DD662A41514", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Features On Demand Helper", "meta_original_filename": "FodHelper.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/b1223b86d03c3583b84e46a9a6ad009d770fc4114640402ede19793167593a8f/detection/", "runtime_modules": [ "C:\\Windows\\system32\\fodhelper.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll" ] }, "Fondue.exe-EEE0F4A169799F00BAD87C7D0834E348": { "file_name": "Fondue.exe", "file_path": "C:\\Windows\\system32\\Fondue.exe", "hash_md5": "EEE0F4A169799F00BAD87C7D0834E348", "hash_sha1": "32739C7A48F6EC534BD4A371D1838246BCCCA114", "hash_sha256": "E86B8997664E14FB6D0972D1E9D394A99AFE9E877A7911CBE7A0E575EF04791E", "hash_sha384": "E3FC368FAB4C8648530E0272D4B3D8040394DED57674CF5ADEA18147B2E61016C790AB6092F3B0D921A962B7B34D9625", "hash_sha512": "691923223EE63DFE76E42342EC02FA385D358E328A53964FEC60BFE6B6CB4C1175BFF2AAE3FBDD66C82F0C3B77965C368E0258AB56FE73692A5C77AF73F29EA1", "hash_ssdeep": "3072:SyQQtGibEaznWfH22ZsuX2xKwMPTnaSrIrvD2:SyHG0znWjZnXeKwMLnaqY", "hash_imp": "E8309E14FD0CD5D0959FCC7F5E47D546", "hash_pesha1": "4FCA7FAFE331AED4789633D5EA018B4DD0376FC2", "hash_pe256": "F7AA832D64AE5609C5D6EE347F2BB8CAF3D91D1A3F5153EA46E81CFA39B36811", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Features on Demand UX", "meta_original_filename": "Fondue.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e86b8997664e14fb6d0972d1e9d394a99afe9e877a7911cbe7a0e575ef04791e/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\Fondue.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\appwiz.cpl.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Fondue.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\system32\\APPWIZ.CPL", "C:\\Windows\\System32\\SHCORE.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\system32\\osbaseln.dll", "C:\\Windows\\system32\\msi.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll" ], "runtime_window_title": "Windows Features" }, "fontdrvhost.exe-8B65985D82C8295B20DDE9C2DA04D71A": { "file_name": "fontdrvhost.exe", "file_path": "C:\\Windows\\system32\\fontdrvhost.exe", "hash_md5": "8B65985D82C8295B20DDE9C2DA04D71A", "hash_sha1": "C070912781413AF71DE5600C7B54661FB71F1630", "hash_sha256": "13D9CE74A99FE00496EBE7461C5D505FD957B83D313AA9B2A23C359B470CEC9F", "hash_sha384": "E9724890050155E96ACE0E3FD9D12E6428FD31BAAB576100073316C2291BAAE00B494416B51148A42853644A1BC107FF", "hash_sha512": "7FB0C0DEF5463D42380BBDB38A4C48A856FC275D4A2A490279B971B140A57064549EEB63E0746BD83F0D8A2B33CBEF86A655E9E19511B24949902E3E65482EC6", "hash_ssdeep": "24576:ExCuXCeqx5y4OZyZZU7nhb30rmNeATdV1:ExbXqx51HZcArmNeAT5", "hash_imp": "C2350BA0585D80C231955257E371356D", "hash_pesha1": "188D3A9E4D4771F422A8770276565CB2F22F7F8F", "hash_pe256": "C721008ECC6B084BF533668CDC73EE98E6D90FB094CE5D035AE6020FC8D58090", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Usermode Font Driver Host", "meta_original_filename": "fontdrvhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/13d9ce74a99fe00496ebe7461c5d505fd957b83d313aa9b2a23c359b470cec9f/detection/" }, "fontview.exe-EF5974EAF2890C9D9F659C42F356B5D1": { "file_name": "fontview.exe", "file_path": "C:\\Windows\\system32\\fontview.exe", "hash_md5": "EF5974EAF2890C9D9F659C42F356B5D1", "hash_sha1": "D8BFC2648FF264DD527E6513DA1882002776B81F", "hash_sha256": "4409862CC66632C1D5A4753C5A59B741273BBD8CC73B44D412D0500370996A93", "hash_sha384": "20FB9CB5183E2B238D2E64E8B7F0D311D5A5993894F2C8864D4CD8F3E502CBA2F7415E2A6A6524BFDCAAB64510E4B03E", "hash_sha512": "E6438E30672946E2F1C0BC82F0990694178872F2625FE1C395336FF7418031A6DDE6C41B91262DFE78C3D9EC1C4E8E6685F2295B12A2D9973D69477CC12AB254", "hash_ssdeep": "3072:M0bCSSdBIgqZSp8NJjWRkOtHxtt3EOL2QvIsitSYV5:M0b6G/wcWRRZzqGY", "hash_imp": "CE80D2BBAE2A3F37CA3BC062CBCF1F8C", "hash_pesha1": "A77B9F63B51F46B14B5736980BA3B5BEAD7593C8", "hash_pe256": "7C375B6F96EDEAF8F655F3F118C2B7EF2E27C4D1F6965DFFE7EB28F346E8B6DB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Font Viewer", "meta_original_filename": "FONTVIEW.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/4409862cc66632c1d5a4753c5a59b741273bbd8cc73b44d412d0500370996a93/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\fontview.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\fontview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\WindowsCodecs.dll" ], "runtime_window_title": "Windows Font Viewer " }, "forfiles.exe-6E9F3CBB041D0670E2AC3378C3360045": { "file_name": "forfiles.exe", "file_path": "C:\\Windows\\system32\\forfiles.exe", "hash_md5": "6E9F3CBB041D0670E2AC3378C3360045", "hash_sha1": "B7002C1601C326ED60C38E23366E5E8C919F326A", "hash_sha256": "FA84D5B043EAD140FE304CBC71A9BFB3D24D3542FAB45DB65606C47808BD9272", "hash_sha384": "142305263B02C68060B7BD6861A674726B0B6C54E0D1F9EEF9173703A7BD21C73640F0990C7B79B362E8D91146598795", "hash_sha512": "3BBAE247D9DB0A44273E27F5A1ACBCDA91C989D749D40A8D5CCCCF68AF1C9E2CE4DC780DDCC10B21A48007E7CFC85C9C2A9F864238865E7FD83075E1AFDC616E", "hash_ssdeep": "768:o7s33yWDc3PBXmk1cE+aB3bUbauvk43Y3bFE0d/O18MNt6QbTduQxBTjFLhw:oArc3P47aB3bUb1Ey518at601xBhhw", "hash_imp": "BB3BC1A3FEF88F916302D61DDC886F80", "hash_pesha1": "D54A3AA417202B108DDAF3CF8F49B304722FB18C", "hash_pe256": "8B1F68E285EAC6735A6B0C2840D4AF5DED78C737304C2E874FCC9D56EBA6B29E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ForFiles - Executes a command on selected files", "meta_original_filename": "forfiles.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/fa84d5b043ead140fe304cbc71a9bfb3d24d3542fab45db65606c47808bd9272/detection/", "output": "\r\nFORFILES [/P pathname] [/M searchmask] [/S]\r\n [/C command] [/D [+ | -] {MM/dd/yyyy | dd}]\r\n\r\nDescription:\r\n Selects a file (or set of files) and executes a \r\n command on that file. This is helpful for batch jobs.\r\n\r\nParameter List:\r\n /P pathname Indicates the path to start searching.\r\n The default folder is the current working\r\n directory (.).\r\n\r\n /M searchmask Searches files according to a searchmask.\r\n The default searchmask is '*' .\r\n\r\n /S Instructs forfiles to recurse into\r\n subdirectories. Like \"DIR /S\".\r\n\r\n /C command Indicates the command to execute for each file.\r\n Command strings should be wrapped in double\r\n quotes. \r\n\r\n The default command is \"cmd /c echo @file\".\r\n\r\n The following variables can be used in the\r\n command string:\r\n @file - returns the name of the file.\r\n @fname - returns the file name without\r\n extension.\r\n @ext - returns only the extension of the\r\n file.\r\n @path - returns the full path of the file.\r\n @relpath - returns the relative path of the\r\n file.\r\n @isdir - returns \"TRUE\" if a file type is\r\n a directory, and \"FALSE\" for files.\r\n @fsize - returns the size of the file in\r\n bytes.\r\n @fdate - returns the last modified date of the\r\n file.\r\n @ftime - returns the last modified time of the\r\n file.\r\n\r\n To include special characters in the command \r\n line, use the hexadecimal code for the character\r\n in 0xHH format (ex. 0x09 for tab). Internal\r\n CMD.exe commands should be preceded with\r\n \"cmd /c\".\r\n\r\n /D date Selects files with a last modified date greater\r\n than or equal to (+), or less than or equal to\r\n (-), the specified date using the\r\n \"MM/dd/yyyy\" format; or selects files with a\r\n last modified date greater than or equal to (+)\r\n the current date plus \"dd\" days, or less than or\r\n equal to (-) the current date minus \"dd\" days. A\r\n valid \"dd\" number of days can be any number in\r\n the range of 0 - 32768.\r\n \"+\" is taken as default sign if not specified.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n FORFILES /?\r\n FORFILES \r\n FORFILES /P C:\\WINDOWS /S /M DNS*.* \r\n FORFILES /S /M *.txt /C \"cmd /c type @file | more\"\r\n FORFILES /P C:\\ /S /M *.bat\r\n FORFILES /D -30 /M *.exe\r\n /C \"cmd /c echo @path 0x09 was changed 30 days ago\"\r\n FORFILES /D 01/01/2001\r\n /C \"cmd /c echo @fname is new since Jan 1st 2001\"\r\n FORFILES /D +10/19/2020 /C \"cmd /c echo @fname is new today\"\r\n FORFILES /M *.exe /D +1\r\n FORFILES /S /M *.doc /C \"cmd /c echo @fsize\" \r\n FORFILES /M *.txt /C \"cmd /c if @isdir==FALSE notepad.exe @file\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"FORFILES /?\" for usage.\r\n" }, "fsavailux.exe-D5B08266F38ECF15CBE8202174BC68A9": { "file_name": "fsavailux.exe", "file_path": "C:\\Windows\\system32\\fsavailux.exe", "hash_md5": "D5B08266F38ECF15CBE8202174BC68A9", "hash_sha1": "2E56FD68BC63B09C1BDEF19A8420D9602906A961", "hash_sha256": "4BCD912B99B7DDFC456CC45AAFE81D8F14598D02816851F9AF195E875607B797", "hash_sha384": "7832A9A45B7919AA2E8FE0209805727FE0F3EB605DF7E3B1EECE4682F5A733F134BD987AEA808D0F6379A88350C93F18", "hash_sha512": "A7506B4F14A8CE7013CEBE84C786A48636713711D7BF5AF635CBA3CF92ACE260D8A8750B29D8C21480AA48F1E60AC2FD0DA499A8CABFE4B276F29067D3B0CC76", "hash_ssdeep": "384:PqWqnu8F25jWIg+Hi1pPIUekSDCufb9NNDbhWgxWW:PqRu5SqHKwUwC6nfB", "hash_imp": "7906A2680F0C0553216922F1E3808813", "hash_pesha1": "3C38C32E29542B21A908285D4AA37EBD128055E5", "hash_pe256": "97B0566676461A9AE9B40A502BD9A52585271CBCFFAE8389DBA1DC1DB027D86E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft\\fsavailux", "meta_original_filename": "fsavailux.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/4bcd912b99b7ddfc456cc45aafe81d8f14598d02816851f9af195e875607b797/detection/", "runtime_modules": [ "C:\\Windows\\system32\\fsavailux.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\ulib.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\IfsUtil.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "FsIso.exe-ECD39E4135153642436BAFDD2EECB1B9": { "file_name": "FsIso.exe", "file_path": "C:\\Windows\\system32\\FsIso.exe", "hash_md5": "ECD39E4135153642436BAFDD2EECB1B9", "hash_sha1": "824C220E0DC48D889182F9C734D5C1A4FF7B6458", "hash_sha256": "A0DD2217D4B652179805015F9AFD3698ADFA2E178ADDE8AF0931A6861FC88FF8", "hash_sha384": "2F4B91658B7E064CF71D2BFF0B08C37579D8546BA5F10C6576A1EFFD3E354C38B559900EB2634B9AD94C991AA4389981", "hash_sha512": "DE3C3843E246795E0DCD19D26846D8BB26EB1A48202CE70882C85EAA90BE4CA0C2229FCBC43D49D014C7CD6FFE71416F0DF02148E77EC582ADCEEA35304B5F35", "hash_ssdeep": "1536:YZzd7r9rLZa494FTyTVDFrUYsTIOe3u9ZkJX9xPB:EzNBZa49wTyTVlUYsTGe9ZmNx5", "hash_imp": "DCD8680B7D9EBE6D1DBEC6053633BC90", "hash_pesha1": "B5A43F200C11AC75535DFAAFBB19FB4007FD0739", "hash_pe256": "4635A0BA450B683CF0038C9EAB8FF427A1399764C1C1025F3BADC6E85D1A3405", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Secure Frame Server Helper", "meta_original_filename": "FsIso.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1282 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1282", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/a0dd2217d4b652179805015f9afd3698adfa2e178adde8af0931a6861fc88ff8/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\RPC Control\\DSEC8D4": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\FsIso.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\IumSdk.dll", "C:\\Windows\\system32\\iumbase.DLL", "C:\\Windows\\SYSTEM32\\IUMDLL.dll" ] }, "fsquirt.exe-03C5F1355E3E725B9B82E2516CD9D410": { "file_name": "fsquirt.exe", "file_path": "C:\\Windows\\system32\\fsquirt.exe", "hash_md5": "03C5F1355E3E725B9B82E2516CD9D410", "hash_sha1": "F36659E10E6F55A850059BEDD9DEF3284FD97A02", "hash_sha256": "6224E08C0D005DCAFA87763EDA77CD85E851703E49527FB26713B4EB895502B5", "hash_sha384": "3D628339C72148BF8C36FD4D0D165E36224B8C30338EBA2FF04B54048C95C39414FF63747F61EEEF744D3459D69CE2C1", "hash_sha512": "488866A46EFB7753126E7E285BADA09A832A84C1AFD593DD7DB243F09D7ECEE8CA5CA94D44DB866BD50C25EA9CF28A4BE5444CC7E264815D60F4E00AFA58DBD5", "hash_ssdeep": "1536:jy8F5ldIqOcA7EXjYu24AnXHyPPuoablnCI6dmgDGsX+lrwFmrXshUdB6QJnhI:mGN24AXH0PFknL6dmgyw/hUd40h", "hash_imp": "56C3E3DC70F092E2F6D3C347A472607E", "hash_pesha1": "7CF1A652A97EF9104606CD63C9B372E14EC2FFFB", "hash_pe256": "66067E352C214C9198A283F766B535852C6B29461429433AFCEE02ACBBB7773D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "fsquirt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/6224e08c0d005dcafa87763eda77cd85e851703e49527fb26713b4eb895502b5/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\fsquirt.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\fsquirt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\MSWSOCK.dll", "C:\\Windows\\system32\\bthprops.cpl", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\system32\\OLEACC.dll" ], "runtime_window_title": "Bluetooth File Transfer" }, "fsutil.exe-5A946DE1BE7650FE36F165BA275D6041": { "file_name": "fsutil.exe", "file_path": "C:\\Windows\\system32\\fsutil.exe", "hash_md5": "5A946DE1BE7650FE36F165BA275D6041", "hash_sha1": "4C3A12FB2F70B1B51E2AFEC6A57020A46F3B5D19", "hash_sha256": "C302730B6088C6E28D1D9692D4D7D512C622979E58A1F6CCEC396AC1231F3DE2", "hash_sha384": "CE1396D7B3A518F1517A9C01E407983BA5A087A27DA9EE4F2F262AE20C6148B80D94AEC3526FB7A011FE30505F7C2EFF", "hash_sha512": "178C9033F513B64DECC15B2DA91BF3AC1D6CCAAE94ADDF557FAED134BB1B4C54355DB191A9A66DEF38C4EF2BD1B6A652B0A57AF3F8E26C286B94BC9BDF9BF7F3", "hash_ssdeep": "3072:Ni8n7ZB1tIRkH6VVadIA16IltsV6NSga1PnNlXY1XoD+VlOd2bhhU9+y8fOpr2u1:b7ZTtIRkH6VVadIA16IltsV6NSga1jXe", "hash_imp": "2899A95AD421A518591D7F87D363DB79", "hash_pesha1": "1E7F35F87632EC41F35F61E1CD3ABE0ACF5B98A3", "hash_pe256": "47FFD67631E0DDB7F139D0D17BCC97112DEDD8C0A5DDDBE99F91E90D428B8E47", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "fsutil.exe", "meta_original_filename": "fsutil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.652 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.652", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/c302730b6088c6e28d1d9692d4d7d512c622979e58a1f6ccec396ac1231f3de2/detection/", "output": "--help is an invalid parameter.\r\n---- Commands Supported ----\r\n\r\n8dot3name 8dot3name management\r\nbehavior Control file system behavior\r\ndax Dax volume management\r\ndirty Manage volume dirty bit\r\nfile File specific commands\r\nfsInfo File system information\r\nhardlink Hardlink management\r\nobjectID Object ID management\r\nquota Quota management\r\nrepair Self healing management\r\nreparsePoint Reparse point management\r\nresource Transactional Resource Manager management\r\nsparse Sparse file control\r\ntiering Storage tiering property management\r\ntransaction Transaction management\r\nusn USN management\r\nvolume Volume management\r\nwim Transparent wim hosting management\r\n" }, "ftp.exe-D53C97FE21E6BCBDEB80EECAE274E4D4": { "file_name": "ftp.exe", "file_path": "C:\\Windows\\system32\\ftp.exe", "hash_md5": "D53C97FE21E6BCBDEB80EECAE274E4D4", "hash_sha1": "01A84CB1733048520C6E8E099C07F748DAB52648", "hash_sha256": "D7FB0E7E7E6C653E0DB554433DFA6AAD8BE33B99431DD0A31E25943D0EFB91F0", "hash_sha384": "367DFB74FD0EF20BDD9E1AE0C8D67349C08977B99BF64658A428CDFF981677FF62C1003F285ACB6E6F69FC835C3AE3F1", "hash_sha512": "3B52296964D3FEEF5605F36B3D601660C9BE01FEBEED9DE8ECE5D70932C3E985995144A30F6B853C6EC69EC2A2B59D65634B207C255BFA59D81B2226567BB824", "hash_ssdeep": "1536:SL9q/bXmnLhUc+4p5obG48INnRDwCvGiLMYnw:SL9dZ+8pmnR0nv+w", "hash_imp": "77FB959251723204D9A218FADEE0AF08", "hash_pesha1": "3F03913A860FF5F8F26A4017E5EAE60976F96C6F", "hash_pe256": "18979577E49BD0C4FA8D99C115FB3EE87327A93E68F92165902577A5444648F9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Transfer Program", "meta_original_filename": "ftp.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/d7fb0e7e7e6c653e0db554433dfa6aad8be33b99431dd0a31e25943d0efb91f0/detection/", "error": "\r\nTransfers files to and from a computer running an FTP server service\r\n(sometimes called a daemon). Ftp can be used interactively.\r\n\r\nFTP [-v] [-d] [-i] [-n] [-g] [-s:filename] [-a] [-A] [-x:sendbuffer] [-r:recvbuffer] [-b:asyncbuffers] [-w:windowsize] [host]\r\n\r\n -v Suppresses display of remote server responses.\r\n -n Suppresses auto-login upon initial connection.\r\n -i Turns off interactive prompting during multiple file\r\n transfers.\r\n -d Enables debugging.\r\n -g Disables filename globbing (see GLOB command).\r\n -s:filename Specifies a text file containing FTP commands; the\r\n commands will automatically run after FTP starts.\r\n -a Use any local interface when binding data connection.\r\n -A login as anonymous.\r\n -x:send sockbuf Overrides the default SO_SNDBUF size of 8192.\r\n -r:recv sockbuf Overrides the default SO_RCVBUF size of 8192.\r\n -b:async count Overrides the default async count of 3\r\n -w:windowsize Overrides the default transfer buffer size of 65535.\r\n host Specifies the host name or IP address of the remote\r\n host to connect to.\r\n\r\nNotes:\r\n - mget and mput commands take y/n/q for yes/no/quit.\r\n - Use Control-C to abort commands.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\ftp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\MSWSOCK.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\napinsp.dll", "C:\\Windows\\SYSTEM32\\DNSAPI.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\System32\\winrnr.dll", "C:\\Windows\\system32\\NLAapi.dll", "C:\\Windows\\system32\\wshbth.dll", "C:\\Windows\\System32\\rasadhlp.dll" ] }, "GenValObj.exe-F6DFB21747A8012CFABD07AE075CCA45": { "file_name": "GenValObj.exe", "file_path": "C:\\Windows\\system32\\GenValObj.exe", "hash_md5": "F6DFB21747A8012CFABD07AE075CCA45", "hash_sha1": "FDF154591D3307E44F1C8C2350F7B030141EB1D6", "hash_sha256": "C8C6F0629403C87C36D42D5AED07D9602B6AB0D8E48CBF727A2FA3BF22469730", "hash_sha384": "EB3CCD80CC887EA1FF189EA8ABD64BCFAAA0C3178C4BA09C549190BD424F8592EA3B996F9C4FF48EAF1D1ADD52B16D2D", "hash_sha512": "51507FE44D44D0196134DEC3867742B1057C94698A3BCB5CB044276FD67C0C2DB93FABB6BC14C091221A15260A4C955BF89142AE3DBFB9BF3F40400B05E99F0B", "hash_ssdeep": "12288:xvLVdwybSY9thloyxBQE6a6LtUz+nGdLzkbFv+keg57P:xv5dwVMhlVxBQM6Liz+nGdMbFvX7", "hash_imp": "46AA772C99E3ABAFE91346DF0960F328", "hash_pesha1": "697C6752CA2EA875C8F072F95DC691AEF853F18D", "hash_pe256": "BDE6FD1F82F4A82647BA4EB1A8DC9BF4999912A24D06B2A08B97EA7EAE3D5E4A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Software Protection Platform Admin Object", "meta_original_filename": "GenValObj.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/c8c6f0629403c87c36d42d5aed07d9602b6ab0d8e48cbf727a2fa3bf22469730/detection/" }, "getmac.exe-AFF4CB80DA66CF74426CA8089FCD0BB6": { "file_name": "getmac.exe", "file_path": "C:\\Windows\\system32\\getmac.exe", "hash_md5": "AFF4CB80DA66CF74426CA8089FCD0BB6", "hash_sha1": "BBF3F30E24B97D6B7C8FD6417672B797DF596627", "hash_sha256": "31A48B157DB2CED030516B0F41604EF7BB51149FBA3FAFD1926347F92B9CA5E2", "hash_sha384": "4E391E22E05F758136B42D96F77CB520EBD47665522F2E4F0BE20DB6C619F30F7A5858330F9F6953FF874ED29C4ECA65", "hash_sha512": "D1F654DBAF4FD3A2E4ACD3457F40C757574B1D6527A2469A41B06999D09132E02644B017426C8922E3ECD11C7ADAF19284E76D2B4DD8BE4FC65E3FD6B4183A20", "hash_ssdeep": "1536:BjEOQ0AcBjnfgqI84EvJsyU810TSdCpYaz4bxTkEaGCUasmN:BjREcBTg7qJNL+TSdHbxpTCUaX", "hash_imp": "8E550FD6D80E97018F9097BB725420C8", "hash_pesha1": "71F07792C4B2790AC534EA7D49150EA88793ED4B", "hash_pe256": "D53B41677226C59748B8B1724ECF08871BC899232CF70A119DBD9A79AD947E39", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays NIC MAC information", "meta_original_filename": "GetMac.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/31a48b157db2ced030516b0f41604ef7bb51149fba3fafd1926347f92b9ca5e2/detection/", "output": "\r\nGETMAC [/S system [/U username [/P [password]]]] [/FO format] [/NH] [/V]\r\n\r\nDescription:\r\n This tool enables an administrator to display the MAC address\r\n for network adapters on a system.\r\n\r\nParameter List: \r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under \r\n which the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /FO format Specifies the format in which the output\r\n is to be displayed.\r\n Valid values: \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" should\r\n not be displayed in the output.\r\n Valid only for TABLE and CSV formats.\r\n\r\n /V Specifies that verbose output is displayed.\r\n\r\n /? Displays this help message.\r\n\r\nExamples: \r\n GETMAC /? \r\n GETMAC /FO csv \r\n GETMAC /S system /NH /V\r\n GETMAC /S system /U user\r\n GETMAC /S system /U domain\\user /P password /FO list /V\r\n GETMAC /S system /U domain\\user /P password /FO table /NH\r\n", "runtime_modules": [ "C:\\Windows\\system32\\getmac.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"GETMAC /?\" for usage.\r\n" }, "gpresult.exe-275641D5B143B578FB364AE2644F423A": { "file_name": "gpresult.exe", "file_path": "C:\\Windows\\system32\\gpresult.exe", "hash_md5": "275641D5B143B578FB364AE2644F423A", "hash_sha1": "510DD16BF44C376E2EBD2C40540A4EC83342964B", "hash_sha256": "E71A9E7D0B66976B97A7E6411D5F15581698B48AAC2D225B98F0C70B2859B451", "hash_sha384": "F24DB3B823C5504B775BB03C608A42BC331750C59398EAD82E718F3EF9D2AF773B6AFEB71C05446E91B72BB933F3DD1D", "hash_sha512": "9FF3B3C2EA1B061BBBE4B8736DA6D8348FC555C4D1C2CBB97CF9B0AB0064FDEA8EC95CA3BFF3B66FB718407BB83BE9F17584961BDC216DAC2C2CB95BF6EE5258", "hash_ssdeep": "6144:Ek1bBIyNQupCGdgCqX3zXjBcr3ogZebWuYM/hkMazb:Ek1lpQuE/DXjBiZ6mMa", "hash_imp": "21D279ACCB0EB1F3C23C57EB6C9C576B", "hash_pesha1": "8E45AA5480AFA37872065C2DC881B30E088910DE", "hash_pe256": "1D540B5906546629CA2108426D816A829B8E5AAD88075BA9CF2EAEF7627BD0EA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query Group Policy RSOP Data", "meta_original_filename": "gprslt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/e71a9e7d0b66976b97a7e6411d5f15581698b48aac2d225b98f0c70b2859b451/detection/", "output": "\r\nGPRESULT [/S system [/U username [/P [password]]]] [/SCOPE scope]\r\n [/USER targetusername] [/R | /V | /Z] [(/X | /H) <filename> [/F]]\r\n\r\nDescription:\r\n This command line tool displays the Resultant Set of Policy (RSoP)\r\n information for a target user and computer.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which the\r\n command should run.\r\n Can not be used with /X, /H.\r\n\r\n /P [password] Specifies the password for the given user\r\n context. Prompts for input if omitted.\r\n Cannot be used with /X, /H.\r\n\r\n /SCOPE scope Specifies whether the user or the\r\n computer settings need to be displayed.\r\n Valid values: \"USER\", \"COMPUTER\".\r\n\r\n /USER [domain\\]user Specifies the user name for which the\r\n RSoP data is to be displayed.\r\n\r\n /X <filename> Saves the report in XML format at the\r\n location and with the file name specified\r\n by the <filename> parameter. (valid in Windows\r\n Vista SP1 and later and Windows Server 2008 and later)\r\n\r\n /H <filename> Saves the report in HTML format at the\r\n location and with the file name specified by\r\n the <filename> parameter. (valid in Windows\r\n at least Vista SP1 and at least Windows Server 2008)\r\n\r\n /F Forces Gpresult to overwrite the file name\r\n specified in the /X or /H command.\r\n\r\n /R Displays RSoP summary data.\r\n\r\n /V Specifies that verbose information should\r\n be displayed. Verbose information provides\r\n additional detailed settings that have\r\n been applied with a precedence of 1.\r\n\r\n /Z Specifies that the super-verbose\r\n information should be displayed. Super-\r\n verbose information provides additional\r\n detailed settings that have been applied\r\n with a precedence of 1 and higher. This\r\n allows you to see if a setting was set in\r\n multiple places. See the Group Policy\r\n online help topic for more information.\r\n\r\n /? Displays this help message.\r\n\r\n\r\nExamples:\r\n GPRESULT /R\r\n GPRESULT /H GPReport.html\r\n GPRESULT /USER targetusername /V\r\n GPRESULT /S system /USER targetusername /SCOPE COMPUTER /Z\r\n GPRESULT /S system /U username /P password /SCOPE USER /V\r\n", "runtime_modules": [ "C:\\Windows\\system32\\gpresult.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\logoncli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\system32\\srvcli.dll", "C:\\Windows\\system32\\framedynos.dll", "C:\\Windows\\system32\\NTDSAPI.dll", "C:\\Windows\\system32\\Secur32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\wbem\\wbemprox.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\System32\\bcrypt.dll" ], "error": "ERROR: Invalid syntax. Value expected for '/h'.\r\nType \"GPRESULT /?\" for usage.\r\n" }, "gpscript.exe-30428B3173B15CFE22457523CE381A74": { "file_name": "gpscript.exe", "file_path": "C:\\Windows\\system32\\gpscript.exe", "hash_md5": "30428B3173B15CFE22457523CE381A74", "hash_sha1": "4CF52B13BBB97F97C07B90C61C7546E97A4D4BBE", "hash_sha256": "8BEEC3990687ECBDDF7A7E2A4278F8C220314688F914C5D87280A55A97FB6DFA", "hash_sha384": "873D3EACCDC98BCB0DBE10AB277011DBADC6E59FE15C31755E3BA442EDCC075CFD33FB458D528F9EB31E8B75719331A2", "hash_sha512": "D8FCBA2A25868A18DD834402657E8F57AC069295AA7CE1FC8E26B2F1267B19F9F8818650BB2BB9677F5A096AE822E780ADC33F03BF2914421D246737A3280A34", "hash_ssdeep": "768:V3L2ztRYJU4MgmP2I2dKAIyel0ex0HLykudTSY2R6OSJ:ZIHGUvBf0KAe+ex0HRudTn2R6nJ", "hash_imp": "BAC4D390D64C9513CF9CEE8307C17C47", "hash_pesha1": "DD48D0C2467139A90A35BFF1E3D2513C37C37E66", "hash_pe256": "DAAFD67A4F2D605ECF28E27571E75D82E3C132A4267063709C0C83ED70C6971D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Group Policy Script Application", "meta_original_filename": "GPSCRIPT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/8beec3990687ecbddf7a7e2a4278f8c220314688f914c5d87280a55a97fb6dfa/detection/" }, "gpupdate.exe-EE5892A6168658FF9C7784FF94346AA2": { "file_name": "gpupdate.exe", "file_path": "C:\\Windows\\system32\\gpupdate.exe", "hash_md5": "EE5892A6168658FF9C7784FF94346AA2", "hash_sha1": "B418D6BE3BC8D85776049975147088483CA1A3D2", "hash_sha256": "0E8606BA02828D403E321E37F1568AA321A95D3BDBDB83B73583105B666D79BA", "hash_sha384": "DB285845E593EA6AD91DAE60E0377EF8D888270467E77095B4230EAC1495DC42E6E7BA8A252A8A670120285ED3423A52", "hash_sha512": "6404B18DB2AAF46692372D549F9BEF431AE783461FA8EEB50AF111E9A20CF1647AB722918768E109E8EC2682258AFF4D9D44633CC53D33450D693F7FB2FC0EAA", "hash_ssdeep": "384:nXEN7h0+fnIbGpfbzzhL7t4mL6DdY9J4QPk/jsAkF0Pp/7tl2R/WoDgEh4ercmR7:nIh0KnIALhL+D+6kq7tl0zh4e9qC", "hash_imp": "F150A94E73644B4EE8C4FF24DFEA3216", "hash_pesha1": "A9E97D35E88C631BA99D92746E5B82AF2CB8A4F8", "hash_pe256": "C6C2B499CCB28CCA12CD042507095F8AA5652B109EC745E850B3EACC05772BB1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Group Policy Update Utility", "meta_original_filename": "GPUpdate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/0e8606ba02828d403e321e37f1568aa321a95d3bdbdb83b73583105b666d79ba/detection/", "output": "Description: Updates multiple Group Policy settings.\r\r\n\r\r\nSyntax: Gpupdate [/Target:{Computer | User}] [/Force] [/Wait:<value>]\r\r\n [/Logoff] [/Boot] [/Sync] \r\r\n\r\r\nParameters:\r\r\n\r\r\nValue Description\r\r\n/Target:{Computer | User} Specifies that only User or only Computer\r\r\n policy settings are updated. By default,\r\r\n both User and Computer policy settings are\r\r\n updated.\r\r\n\r\r\n/Force Reapplies all policy settings. By default,\r\r\n only policy settings that have changed are\r\r\n applied.\r\r\n\r\r\n/Wait:{value} Sets the number of seconds to wait for policy\r\r\n processing to finish. The default is 600\r\r\n seconds. The value '0' means not to wait.\r\r\n The value '-1' means to wait indefinitely.\r\r\n When the time limit is exceeded, the command\r\r\n prompt returns, but policy processing\r\r\n continues.\r\r\n\r\r\n/Logoff Causes a logoff after the Group Policy settings\r\r\n have been updated. This is required for\r\r\n those Group Policy client-side extensions\r\r\n that do not process policy on a background\r\r\n update cycle but do process policy when a\r\r\n user logs on. Examples include user-targeted\r\r\n Software Installation and Folder Redirection.\r\r\n This option has no effect if there are no\r\r\n extensions called that require a logoff.\r\r\n\r\r\n/Boot Causes a computer restart after the Group Policy settings\r\r\n are applied. This is required for those\r\r\n Group Policy client-side extensions that do\r\r\n not process policy on a background update cycle\r\r\n but do process policy at computer startup.\r\r\n Examples include computer-targeted Software\r\r\n Installation. This option has no effect if\r\r\n there are no extensions called that require\r\r\n a restart.\r\r\n\r\r\n/Sync Causes the next foreground policy application to\r\r\n be done synchronously. Foreground policy\r\r\n applications occur at computer start up and user\r\r\n logon. You can specify this for the user,\r\r\n computer or both using the /Target parameter.\r\r\n The /Force and /Wait parameters will be ignored\r\r\n if specified.\r\r\n\r\r\n" }, "grpconv.exe-FF2F3130C373AE4F8F01812D1D2AF6FA": { "file_name": "grpconv.exe", "file_path": "C:\\Windows\\system32\\grpconv.exe", "hash_md5": "FF2F3130C373AE4F8F01812D1D2AF6FA", "hash_sha1": "552875BF49749EB87AE97AA8B55E10ACA795CC28", "hash_sha256": "8B188B7050533BA36335AA17DFBFC579935EAF0A9BD5009A524754513216A978", "hash_sha384": "FE845CBC3F5B1F545C6C69C51AD6F5A77276EA84341742042F6C56FEA9DF11C1BCF1594964817E30819D417F25269920", "hash_sha512": "4AFFBA01E8BF7E29ECA56CCC7C751FCC8E5730D789698D5F6E6895D896BEFCCE4C913E4F206CFE3D5DAA2597C8BBC496D58C461E2BA9273641C92DCAE0916A36", "hash_ssdeep": "768:i4lLHWxurvlN2nxibl5IVn3lwOlYaj9elRhFYSKwpzYwSwES4cP8rVGyjlq3:i4lLHb328sShDKwpEwSwicOGyBq3", "hash_imp": "671EAFCFCFA86F159D56B51A22BF5C87", "hash_pesha1": "1FB37B4A1A989AA5DD9F745C921038F70BC70331", "hash_pe256": "5B5224EDB77EBEC16BFAB3D6693E8AD33F0AEC6DDBDC98CE27E2DC7437EA501F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Progman Group Converter", "meta_original_filename": "GRPCONV.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/8b188b7050533ba36335aa17dfbfc579935eaf0a9bd5009a524754513216a978/detection/" }, "hdwwiz.exe-03D43D90394DCF6D10F0AA4C4D2F8605": { "file_name": "hdwwiz.exe", "file_path": "C:\\Windows\\system32\\hdwwiz.exe", "hash_md5": "03D43D90394DCF6D10F0AA4C4D2F8605", "hash_sha1": "55ED813E7ECE60D66FC84B9BAA100AF830E5CE5F", "hash_sha256": "A18F734A82EE009F0AF72768B6A22DC585083296C1CB7499A280FF603281CDFC", "hash_sha384": "133419589533D3D0731D86E8AF709B520B5CAE8510014BD6F8B1099F274296324AF319FBF0624B5175CE6104F29FF561", "hash_sha512": "9E2841FABDBA05E14623C868E4EB63F0E36FAD301A898B84A074C28D53A6C9B52B838DE6A21335FA2EB040B58860C3C5EF07E5F1DE1A2AE5494A174E4343A1D1", "hash_ssdeep": "768:6HVlJIWhk6WTny4G0In3BhzhWM1GOVz17:61jIWhtUn4Z3qOT", "hash_imp": "D29F9D9964A47D9B3AE4D07DBC78DAA8", "hash_pesha1": "8387FE22371FE85A270C97779FE9B71A7EF9BC12", "hash_pe256": "A1AB0DADDC2ACBE43C18C8279E3779DBB36E7BA9F32A38020439AC4AD9E20E14", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Add Hardware Wizard", "meta_original_filename": "HdwWiz.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a18f734a82ee009f0af72768b6a22dc585083296c1cb7499a280ff603281cdfc/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\hdwwiz.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\newdev.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\devmgr.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\hdwwiz.cpl.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\setupapi.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\hdwwiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\hdwwiz.cpl", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\newdev.dll", "C:\\Windows\\system32\\DEVRTL.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\system32\\devmgr.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\wevtapi.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll" ], "runtime_window_title": "Add Hardware" }, "help.exe-DB1F19E6BAADBD36EA51F31F4210D756": { "file_name": "help.exe", "file_path": "C:\\Windows\\system32\\help.exe", "hash_md5": "DB1F19E6BAADBD36EA51F31F4210D756", "hash_sha1": "B2EDFE4C13455B8683B93FAB63D0C1E1CAFFDD05", "hash_sha256": "11863176A0FAD587304C0EE21474DBAA8F40650F34BC47F2666D379BD3A7D7AB", "hash_sha384": "84B902BE73C027DAE8C071A1C8EC151F8E91CBCD664B06F23205E7896F2C3C5764A95290A5AA99914096FC5373AC7D54", "hash_sha512": "7F0A6DC92768A609ADAE0B4D078316340E9DDB2D3CDF11D4EA5E81D7BDD371A49B181E6FE63A5D26C59D31F0615AA708D305BD2C827289885E37CB5683267CC4", "hash_ssdeep": "192:iPIFjwNw/KqfEyXAS/+aYUebe51RlwOs8e51woGsxcNzmAWncW:igt+wpc/S+Vtbe74Os8e7LXAWncW", "hash_imp": "AC4BF9C2AE25ADA7A4716EBEAF3CC839", "hash_pesha1": "10FEF7B93DE3020F5DAC610D4E68C0A8491A91AF", "hash_pe256": "64076DC025E18BD2A5B31F96F7F0465C2646E2D1602ED4663ED279EEBBDBE7A2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command Line Help Utility", "meta_original_filename": "Help.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/11863176a0fad587304c0ee21474dbaa8f40650f34bc47f2666d379bd3a7d7ab/detection/", "output": "Provides help information for Windows commands.\r\n\r\nHELP [command]\r\n\r\n command - displays help information on that command.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\help.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "HOSTNAME.EXE-7F95220A65A5A5D4A98873E86EF2E549": { "file_name": "HOSTNAME.EXE", "file_path": "C:\\Windows\\system32\\HOSTNAME.EXE", "hash_md5": "7F95220A65A5A5D4A98873E86EF2E549", "hash_sha1": "28BFFEA3033FDAED22759324FE691992FB533A9C", "hash_sha256": "1BFF2907C456F99277F45F9B2A21B1B3F11F6C01587D9E6D6F0B2B5F1472FE92", "hash_sha384": "FC43816F09F42FFA85EF1E0E6F9794D90DDB224F785100E991049BF098B652BE894EB7343FB3E1AF4013D460BAC07185", "hash_sha512": "6F88603EE204D1131E37515D198D663549D73C0B5D2127CC88DCA1E5FD4DC7CC2EDBBD0E425AC330DAA746564578AF9344909B1C7B939D0762B9B9B38D31C42A", "hash_ssdeep": "192:OxyxH6lzKFcnrRYUvZfdsCEeQgEebGXgEXabtwlQNWa6W:GyUuFoFPvraNkg8bttWa6W", "hash_imp": "5CD891320C666621E9783444DB8CBA78", "hash_pesha1": "ECCF136EB2AB43DF9F07D30F48533A0E284E2653", "hash_pe256": "5FC6E42C17DB2DC8F5F91CC2FFA6579F7B20FE01D27BC301586108E66019D5E9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hostname APP", "meta_original_filename": "hostname.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/1bff2907c456f99277f45f9b2a21b1b3f11f6c01587d9e6d6f0b2b5f1472fe92/detection/", "output": "\r\nPrints the name of the current host.\r\n\r\nhostname\r\n\r\n", "error": "sethostname: Use the Network Control Panel Applet to set hostname.\r\nhostname -s is not supported.\r\n" }, "hvax64.exe-DCC9B5AD11AC6F179102B3F70EE4F71E": { "file_name": "hvax64.exe", "file_path": "C:\\Windows\\system32\\hvax64.exe", "hash_md5": "DCC9B5AD11AC6F179102B3F70EE4F71E", "hash_sha1": "FE35D280F9A0147B7792AF6A6E7EA6E33FEF21B6", "hash_sha256": "80AAB0CBB6C5428ED4FDC6081EF40CB4F03D796960D770159152366BBF8AD7B7", "hash_sha384": "EE70767A38AE349ED87C1E376E1E13971EF4E83DBD1707E660FA5F3B015A7D346BE8B0C7E277D3A62668DF0A167E9F62", "hash_sha512": "B5E76DE9DC7AD24151D3AF1180EB208E02DC361D37001754A1B7CC39E0A4284D9552AB30D40E06F7F1A2C48808842AE7EA1F375E0239E054C40EFF3256B85AC5", "hash_ssdeep": "24576:qLpdQu9CDpUsLd3ejDTzRE2Q85HjHDEaloIBEZYtG5tS:qowCDpzJ3AnsqTiS", "hash_imp": "D5AEC1C1F764856CFB4155CEE3321234", "hash_pesha1": "25707BA1DCAC8931761F5DE94488A6E752FB78C5", "hash_pe256": "570798ABFBA377DC5A496DE8EBE5514864C8CDDC2A9DD6DFBBA86D530CC8A84D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hypervisor V2.0", "meta_original_filename": "hvax64.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Windows\\system32\\hvax64.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "hvix64.exe-0AC9EE1ACCF3DBBBB073B671DF6736E0": { "file_name": "hvix64.exe", "file_path": "C:\\Windows\\system32\\hvix64.exe", "hash_md5": "0AC9EE1ACCF3DBBBB073B671DF6736E0", "hash_sha1": "17CA3AF4E52209F1B4F7EBD06ED1A025A46F8DE1", "hash_sha256": "C2B5396220DAE1B1980C9BC6A494ED34DB813D562A10269625EE313E00FA41C0", "hash_sha384": "BA66BDCCF2C3952E71FC1192D72A4DE2EB78724F5EE791F849EA08F3C8386F24C5DD2C35E87E811E326AA096C504586D", "hash_sha512": "8B037826D644F1A1484CE29F8631691214A9CAE34D5BEEB90B055915E923CEC417F1FBFDA03AD1DED32AF3616F5210F912373B510B541B01BEB34EF76A2D0EE5", "hash_ssdeep": "24576:bMxCSEMmOgVU1729lh5SXtv09dL2Widu9UoW3ojZ3gLI5ToIJWVHqiY6:A0/c2qXwdyWEu6oBG850u6", "hash_imp": "D5AEC1C1F764856CFB4155CEE3321234", "hash_pesha1": "7388E0BFD71722EE3DA16EFEC81159BBC1F3A031", "hash_pe256": "25A297FB20D5398C6B1D9A58F3F3C5A5F62527E92FB9F48119AD20473B13B221", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hypervisor V2.0", "meta_original_filename": "hvix64.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Windows\\system32\\hvix64.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "iashost.exe-B333E0E253F91DE8B6FAD360217CBA5B": { "file_name": "iashost.exe", "file_path": "C:\\Windows\\system32\\iashost.exe", "hash_md5": "B333E0E253F91DE8B6FAD360217CBA5B", "hash_sha1": "DB4C8E8C5B90C98291B3C8B4A933A8D25A6F1EF5", "hash_sha256": "B7D9A6C4DDCE7889B63E894279A4312C1E42806AA03BA8CE04D99344EB3DB05B", "hash_sha384": "6F3626E9D6B2ECEACFDAA2401BC636D17ED19A96B64B88BDB2B3476EA7A1892A3F36C861E3A41C1BB615D95188A6F20D", "hash_sha512": "7BA86716A0BF35F92BF66B15A7DE256818B3463A71ACDA601A0FB7FC1F3D5FF50249B1CA4B8115ECC627FD2E9F9344287232F9DFE2741133F416D76DE7F873DC", "hash_ssdeep": "384:+p1Rc815/Xxq3jykP02iWcd2zgEGhGpxLH/+yXK/XtXgkiWruWr:+TRb3/Xo+k0WrzJyG7Lf+nXmkf7", "hash_imp": "54F5C531C1CF6311D38019E6231FE8D3", "hash_pesha1": "382B17BD64CC340F7C9DD768018F169BDEF8C4AF", "hash_pe256": "C361AD18436025459DAFFFABDDD7BB37272C3F91D6FB3E6AF2BF77C40CE1351D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IAS Host", "meta_original_filename": "IASHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/b7d9a6c4ddce7889b63e894279a4312c1e42806aa03ba8ce04d99344eb3db05b/detection/" }, "icacls.exe-0EE40690DEE405A3693B0C23864363C8": { "file_name": "icacls.exe", "file_path": "C:\\Windows\\system32\\icacls.exe", "hash_md5": "0EE40690DEE405A3693B0C23864363C8", "hash_sha1": "350BC92A74D022CE0EC7C613ED3F66040CD61DBC", "hash_sha256": "8DFC26EEFC94BD4FA35736444D8D9703AA2D3802D17896835F9EA9DE136A68C8", "hash_sha384": "CF6F4A40C1C6566DB8DD9AA4DD6FE30E2D393B69CB195769A983DA16FB13DB1CF368FD3BCED574DCF13EFB48E8086051", "hash_sha512": "6D1559AAF57C2D706DCFFA0D9BA5B646D089225ACB2963D00281731B1FBDEE01A3FB5CB9093F741FC6323605554EF893B54F4DFBC7DE9646AF59C10CD812446D", "hash_ssdeep": "768:ZKohWnN0KvXGp55EaT6b0HCKp1KnrUEg84TWMsrk:woU/ZKp1KrUEgHTWMEk", "hash_imp": "446163A548337B5BCF2727BCD1CFB399", "hash_pesha1": "D345B0E50B1A9BDE84C2DF8A39E0A4618220C013", "hash_pe256": "E3AB5BB8D04504383B07F0062F0F0CC8F1904919D0D4CF4ED6DC22CEAD5BA4F7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "iCACLS.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/8dfc26eefc94bd4fa35736444d8d9703aa2d3802d17896835f9ea9de136a68c8/detection/", "output": "\r\nICACLS name /save aclfile [/T] [/C] [/L] [/Q]\r\n stores the DACLs for the files and folders that match the name\r\n into aclfile for later use with /restore. Note that SACLs,\r\n owner, or integrity labels are not saved.\r\n\r\nICACLS directory [/substitute SidOld SidNew [...]] /restore aclfile\r\n [/C] [/L] [/Q]\r\n applies the stored DACLs to files in directory.\r\n\r\nICACLS name /setowner user [/T] [/C] [/L] [/Q]\r\n changes the owner of all matching names. This option does not\r\n force a change of ownership; use the takeown.exe utility for\r\n that purpose.\r\n\r\nICACLS name /findsid Sid [/T] [/C] [/L] [/Q]\r\n finds all matching names that contain an ACL\r\n explicitly mentioning Sid.\r\n\r\nICACLS name /verify [/T] [/C] [/L] [/Q]\r\n finds all files whose ACL is not in canonical form or whose\r\n lengths are inconsistent with ACE counts.\r\n\r\nICACLS name /reset [/T] [/C] [/L] [/Q]\r\n replaces ACLs with default inherited ACLs for all matching files.\r\n\r\nICACLS name [/grant[:r] Sid:perm[...]]\r\n [/deny Sid:perm [...]]\r\n [/remove[:g|:d]] Sid[...]] [/T] [/C] [/L] [/Q]\r\n [/setintegritylevel Level:policy[...]]\r\n\r\n /grant[:r] Sid:perm grants the specified user access rights. With :r,\r\n the permissions replace any previously granted explicit permissions.\r\n Without :r, the permissions are added to any previously granted\r\n explicit permissions.\r\n\r\n /deny Sid:perm explicitly denies the specified user access rights.\r\n An explicit deny ACE is added for the stated permissions and\r\n the same permissions in any explicit grant are removed.\r\n\r\n /remove[:[g|d]] Sid removes all occurrences of Sid in the ACL. With\r\n :g, it removes all occurrences of granted rights to that Sid. With\r\n :d, it removes all occurrences of denied rights to that Sid.\r\n\r\n /setintegritylevel [(CI)(OI)]Level explicitly adds an integrity\r\n ACE to all matching files. The level is to be specified as one\r\n of:\r\n L[ow]\r\n M[edium]\r\n H[igh]\r\n Inheritance options for the integrity ACE may precede the level\r\n and are applied only to directories.\r\n\r\n /inheritance:e|d|r\r\n e - enables inheritance\r\n d - disables inheritance and copy the ACEs\r\n r - remove all inherited ACEs\r\n\r\n\r\nNote:\r\n Sids may be in either numerical or friendly name form. If a numerical\r\n form is given, affix a * to the start of the SID.\r\n\r\n /T indicates that this operation is performed on all matching\r\n files/directories below the directories specified in the name.\r\n\r\n /C indicates that this operation will continue on all file errors.\r\n Error messages will still be displayed.\r\n\r\n /L indicates that this operation is performed on a symbolic link\r\n itself versus its target.\r\n\r\n /Q indicates that icacls should suppress success messages.\r\n\r\n ICACLS preserves the canonical ordering of ACE entries:\r\n Explicit denials\r\n Explicit grants\r\n Inherited denials\r\n Inherited grants\r\n\r\n perm is a permission mask and can be specified in one of two forms:\r\n a sequence of simple rights:\r\n N - no access\r\n F - full access\r\n M - modify access\r\n RX - read and execute access\r\n R - read-only access\r\n W - write-only access\r\n D - delete access\r\n a comma-separated list in parentheses of specific rights:\r\n DE - delete\r\n RC - read control\r\n WDAC - write DAC\r\n WO - write owner\r\n S - synchronize\r\n AS - access system security\r\n MA - maximum allowed\r\n GR - generic read\r\n GW - generic write\r\n GE - generic execute\r\n GA - generic all\r\n RD - read data/list directory\r\n WD - write data/add file\r\n AD - append data/add subdirectory\r\n REA - read extended attributes\r\n WEA - write extended attributes\r\n X - execute/traverse\r\n DC - delete child\r\n RA - read attributes\r\n WA - write attributes\r\n inheritance rights may precede either form and are applied\r\n only to directories:\r\n (OI) - object inherit\r\n (CI) - container inherit\r\n (IO) - inherit only\r\n (NP) - don't propagate inherit\r\n (I) - permission inherited from parent container\r\n\r\nExamples:\r\n\r\n icacls c:\\windows\\* /save AclFile /T\r\n - Will save the ACLs for all files under c:\\windows\r\n and its subdirectories to AclFile.\r\n\r\n icacls c:\\windows\\ /restore AclFile\r\n - Will restore the Acls for every file within\r\n AclFile that exists in c:\\windows and its subdirectories.\r\n\r\n icacls file /grant Administrator:(D,WDAC)\r\n - Will grant the user Administrator Delete and Write DAC\r\n permissions to file.\r\n\r\n icacls file /grant *S-1-1-0:(D,WDAC)\r\n - Will grant the user defined by sid S-1-1-0 Delete and\r\n Write DAC permissions to file.\r\n", "error": "First parameter must be a file name pattern or \"/?\"\r\n", "runtime_modules": [ "C:\\Windows\\system32\\icacls.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "IcsEntitlementHost.exe-2D3C9011F0C0A0A1FD215376072CEC3C": { "file_name": "IcsEntitlementHost.exe", "file_path": "C:\\Windows\\system32\\IcsEntitlementHost.exe", "hash_md5": "2D3C9011F0C0A0A1FD215376072CEC3C", "hash_sha1": "26BA67C70ABB7D18E9E2E79919E6A89DFF376E06", "hash_sha256": "C34D682AFDE0423F9E4DCDAA3A88392281F35AA21D2BC301CA28F9938286B519", "hash_sha384": "F7EC91D9CDBFB1C0022292EAF7ABD268EB218E72F122424DE3B99BD0B454BE397339F30518A1BE7684A8A26C9C54A0B6", "hash_sha512": "98EA33C776E8FFB8C4A42EBAFB30C320A01DC98DCDAD9144074E1AE74CE2070E913240E4194F0B9BD810F8E881A4860CFBAE27272A338EF43C7422F6D3C354D5", "hash_ssdeep": "768:GN8/i29O0ZG9xmUm/QpNOHrQ51f9l0daiB42BMHEY:88brZG9xJhpNirQDV+daW46Mx", "hash_imp": "4F5540E6872E1985ABF6F28DE3CD8DBF", "hash_pesha1": "FF2D2149F7BA94282ABA7356AAC55A788C7051F8", "hash_pe256": "7D173B91A86A048C31EC508BAC6A00DD80285FB67209F3FE8FA5E0EACADC9F50", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ICS Entitlement Host", "meta_original_filename": "IcsEntitlementHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c34d682afde0423f9e4dcdaa3a88392281f35aa21d2bc301ca28f9938286b519/detection/" }, "icsunattend.exe-56CA1EEC05E6A41B86D2D37B69D84FDE": { "file_name": "icsunattend.exe", "file_path": "C:\\Windows\\system32\\icsunattend.exe", "hash_md5": "56CA1EEC05E6A41B86D2D37B69D84FDE", "hash_sha1": "D73E3D18A486BE521699BDD6C271CF7F92B3FBC4", "hash_sha256": "E9793C8A4A3008F0B60F0717E96B67EE68B0F113C5E3928B9ABEABE63E74BE4F", "hash_sha384": "411B8CF89AC3B65AC3533E0D70C213C20A606698B9A9FDC53945BEE2A792FA8928D6AAB3708856E57DBBC6190B371E01", "hash_sha512": "3A0C9F7B4EB2B11F92A147954B357D4FD940414D1E83595988DB48AAA068EE750F74E42012F9B37F07E89F0E1B2EA9E8217401232219A5AB6C7CB064D6FF8535", "hash_ssdeep": "384:J9pX+ksm7YaQpuaii8wZkq+BPTQ7HCaPBBGzXWNRW:JPgHo04XBPE7HzPBYza", "hash_imp": "5D29BB7F24E26672EF5DBC9E3F499716", "hash_pesha1": "194A428A25E5767D0B70104B26B06473F41FD424", "hash_pe256": "2A43D2335BAD1761A02A120688C9F76F6F50A0482F57C193B86D7CABB149E4E7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ICS Unattend Utility", "meta_original_filename": "icsunattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/e9793c8a4a3008f0b60f0717e96b67ee68b0f113c5e3928b9abeabe63e74be4f/detection/" }, "ie4uinit.exe-A52B135E1865F98C90BF23B3807E51C0": { "file_name": "ie4uinit.exe", "file_path": "C:\\Windows\\system32\\ie4uinit.exe", "hash_md5": "A52B135E1865F98C90BF23B3807E51C0", "hash_sha1": "BF142E7FA17591BAF7D97E342781C8BCA8545C63", "hash_sha256": "46A3D721ADB36114A5141E5795E4DFC02644FDF8F6C602BCCFDC057784F29DB0", "hash_sha384": "5AA92BCDD9D69BC129DE2444F3CEDCBE9F9E548C0238A7112B83BC87EF120123F60A7BA228F9C5301D04AAF76617B6A5", "hash_sha512": "E97A8803B343677A15D2F84E161AA0A2C1C424FC973E933273768C5EB9F21C354F506AF396879C4B59145CFF83E28F0636446A11AB61A240AE36335DC47584E2", "hash_ssdeep": "6144:2wFUGsVC9US0r+ELOC2esAfxd4beLQ+V5h6X:2wuhVw01OCtfz4bexy", "hash_imp": "B898E7CB8AA65CE3FA6187EE093D7F6B", "hash_pesha1": "5F223F5350D78F32C311B521A04233DF8966A9D9", "hash_pe256": "12C51A253AD15B14BA64730360801B3A1D5DCF8DCB82C9C9ACA996852D2692DB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IE Per-User Initialization Utility", "meta_original_filename": "IE4UINIT.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/46a3d721adb36114a5141e5795e4dfc02644fdf8f6c602bccfdc057784f29db0/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326": "File", "(R-D) C:\\Windows\\System32\\en-US\\ie4uinit.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\ie4uinit--help.log": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\ie4uinit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\IEADVPACK.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\system32\\iedkcs32.dll", "C:\\Windows\\system32\\urlmon.dll", "C:\\Windows\\system32\\WININET.dll", "C:\\Windows\\system32\\NETAPI32.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\system32\\MLANG.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326\\COMCTL32.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\system32\\CRYPTBASE.DLL" ] }, "ie4ushowIE.exe-4A77945623689C8B748D3C3700FA77B0": { "file_name": "ie4ushowIE.exe", "file_path": "C:\\Windows\\system32\\ie4ushowIE.exe", "hash_md5": "4A77945623689C8B748D3C3700FA77B0", "hash_sha1": "391AA1AEDDB3D834EF2BC491525B0D569ADA2326", "hash_sha256": "A7F4BCC5958B493E4022E1424100E6A7DA2A6EB3345818DC0B41CDC1C7BD86FC", "hash_sha384": "27603C93F405A36D831D7FEEABE1CE0DEDF61F86B950E85A3A2960682B5DD94F4869710B61C97F64A3C191F1AF8A61DB", "hash_sha512": "55E7488DECF493C2012A7FD2A13AD9E47A0EA06CF13BE6318554C02FA7E39AB224A6E0EDE4C23B8F5ED8059626F09DDC775C9764F25FA702D148B0E3307B47D2", "hash_ssdeep": "1536:G8bOuwnhJ90LqJ2QYSljbcePu6uq846+46EbDQpQDI+Qg7IJ1yx2:G8bQJ90LMYS1ol6v8NZaQDAWIJ1yx2", "hash_imp": "9ECBC12BDE36FBF21E1F9352FC04C8ED", "hash_pesha1": "DA1EF08D443C5BF497E610C7D2932EFB0F0095C2", "hash_pe256": "B4234391CE5846859ADE321ABF18EBA13A66C72EC4A1EFEC593147A9E2C257E5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IE Per-User Show IE Icon Utility", "meta_original_filename": "IE4USHOWIE.EXE", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/a7f4bcc5958b493e4022e1424100e6a7da2a6eb3345818dc0b41cdc1c7bd86fc/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\ie4ushowIE.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\VERSION.dll" ] }, "ieUnatt.exe-823DD9E72637AEA160CC8D0403DA66EF": { "file_name": "ieUnatt.exe", "file_path": "C:\\Windows\\system32\\ieUnatt.exe", "hash_md5": "823DD9E72637AEA160CC8D0403DA66EF", "hash_sha1": "17D6270E28D649C3A2BE1321DCD9D3ACBA63D237", "hash_sha256": "6C5544DDB855671E733158541094883E8FC3450E7CDCF8EE6E7DF94FA2F71766", "hash_sha384": "B4DD6C1D004693DC4B125C6C2EF46EEB71AE29DCB7E238C6660E6A620E54F7E4B9B36C7A5A733A9EA446575A48B5D07D", "hash_sha512": "8965310F0A7883820B30E055EA7CEFA954C4590FAB6D17B346A63F04D6C1C315F93F66764014DA159C41CF28A18D355FA9B216367B6F5F0ABC1C8B13EC89A2E3", "hash_ssdeep": "1536:tEoZbs5pFAbVEzFsFZAUFLWEHB5eBnO723xzrdPpybgoml7XKmrp/VJmJycvX1kz:tEX5QF6EEx/1pa6qygkyg", "hash_imp": "B64E74C9EF4910F661A667100F10C23B", "hash_pesha1": "31E338AA50BF2BEC9299791F8F1CF9AE30C24077", "hash_pe256": "E1861EB85AC44523CD112C81F5DF0581EBBA1FBA7D40DECC19143CAA441EFE8A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IE 7.0 Unattended Install Utility", "meta_original_filename": "IEUNATT.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/6c5544ddb855671e733158541094883e8fc3450e7cdcf8ee6e7df94fa2f71766/detection/", "runtime_modules": [ "C:\\Windows\\system32\\ieUnatt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\system32\\dbgcore.DLL" ] }, "iexpress.exe-81DE6E1BC6067389835A8A56A5BAE61C": { "file_name": "iexpress.exe", "file_path": "C:\\Windows\\system32\\iexpress.exe", "hash_md5": "81DE6E1BC6067389835A8A56A5BAE61C", "hash_sha1": "E8AA1F42D49C41B27DFBCAF22D5869557589367B", "hash_sha256": "333CC4A72F1FC71300678FD35906AEA6AE908C384A97E01F24055B2BF5115CB5", "hash_sha384": "54CFA39AB7D5CD31CF1D66552F84F28521E58F7AF8F7A7B1E123DCD9E5D828B23DED7620F8DF01F549A02AF934088C5F", "hash_sha512": "DD0B4C89C3DD2A2A0A1C33BF9633ACCD4440901E1FFB95B84E17C6842AA94B317E5AC0D892D28859EE342EF0B5EBAE8BA09460CB36F9523834F12752ACDC4754", "hash_ssdeep": "3072:OHsPnjpOABiyML1dNDnGOb+ahXNqJohePnq45L84c:3dOAy7NDGOb+asEwv5L", "hash_imp": "EB7245009D5161BC32C51EA9DCB81D49", "hash_pesha1": "CD1B7E92A0368FC2F4CF997353779B926CB33945", "hash_pe256": "F2F6D07A95723BE0FC22B3DFFE3323F27B4579159E0C0CD3F10BE0C45E915B0C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Wizard", "meta_original_filename": "IEXPRESS.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/333cc4a72f1fc71300678fd35906aea6ae908c384a97e01f24055b2bf5115cb5/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326": "File", "(R-D) C:\\Windows\\System32\\en-US\\iexpress.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.17763.1518_en-us_831447e1869d6513": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.17763.1518_en-us_831447e1869d6513\\comctl32.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\iexpress.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326\\COMCTL32.dll", "C:\\Windows\\system32\\VERSION.dll" ], "runtime_window_title": "IExpress Wizard" }, "immersivetpmvscmgrsvr.exe-95704D0AAFF45834E1275A57BA769CFE": { "file_name": "immersivetpmvscmgrsvr.exe", "file_path": "C:\\Windows\\system32\\immersivetpmvscmgrsvr.exe", "hash_md5": "95704D0AAFF45834E1275A57BA769CFE", "hash_sha1": "4613CA99078B13D7DD1AC6CADB8F2ADAAC71D439", "hash_sha256": "0E930949FAD2BCD206D0B1129F21DEFBB5EAE4B21DF5A7099E8B17814EA90F30", "hash_sha384": "7D719E89CF3EFC9C31F8B9DE8D3FA02F6A04CDD6A7254F147B29AAC4705BF23970C73300E30A768077DBD85CC08068F1", "hash_sha512": "88BD95440C7222A302EA8F6425CD656FF75C89F40207B62040E3F6F9A8DC7D4D24A3D48DED9B48EDAD6110174F7807B27824651FA6B1108694FBB0948A90208E", "hash_ssdeep": "3072:YN2e8UOUJfew76COReX6cnjYOJKO/RTextgd:6Nrz7X6cnj31RSxt", "hash_imp": "CB08FE3D4D0EEF41E14CCD1B5D50E3D8", "hash_pesha1": "D7753D8A77EC545DD44AB544E0EFB085C2964DC4", "hash_pe256": "52BCE2E94F55AD6D5E40546AB7774EAA68AE3BA1C59C457D96E6466D3400DD40", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Immersive TPM Virtual Smart Card Manager COM Server", "meta_original_filename": "ImmersiveTpmVscMgrSvr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/0e930949fad2bcd206d0b1129f21defbb5eae4b21df5a7099e8b17814ea90f30/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\immersivetpmvscmgrsvr.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC112C": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\immersivetpmvscmgrsvr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\WinSCard.dll", "C:\\Windows\\system32\\DEVOBJ.dll" ] }, "InfDefaultInstall.exe-A18B52BBC5C39DAD58703CF92ACAA37C": { "file_name": "InfDefaultInstall.exe", "file_path": "C:\\Windows\\system32\\InfDefaultInstall.exe", "hash_md5": "A18B52BBC5C39DAD58703CF92ACAA37C", "hash_sha1": "01D14AE4CDC53F0B163AFE3ECAEE5D73DA78D09F", "hash_sha256": "B9407FDE5938ED7E2F467F85A465790D4BB9DF4210678067C43D44D1C0BC7CD1", "hash_sha384": "9BF9A2EFF24588113F5B91742B35B9B118FD32034F64EC46FB09B6FB2858B921C4EFAE0F9266BDED6C9AD475B214C718", "hash_sha512": "02E26C4C319139F4E85BE6CE83F51B43F1A0EE1AF2DA17500E95606463080AA4CA3D39ED9D832E1948078E4E5674C43E70D277EDD88249F13FFBF2B8CD7F4A59", "hash_ssdeep": "192:GsHUBEUUsyJYnfiDdHes4sDBeR4OI6iCIys9aW/GW:GhBzcYfih+QWIGcaW/GW", "hash_imp": "F43AA5D6A80539D248D371D78F9F66BF", "hash_pesha1": "D5DE6A9D3FDEDC556293F3ECEBD713984C1EA31E", "hash_pe256": "8CA7973309F67650291371CDF214A58BE3ACDF189A264938EEF319CBE767AD15", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "INF Default Install", "meta_original_filename": "InfDefaultInstall.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/b9407fde5938ed7e2f467f85a465790d4bb9df4210678067c43d44d1c0bc7cd1/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\InfDefaultInstall.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\newdev.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\InfDefaultInstall.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\newdev.dll", "C:\\Windows\\system32\\DEVRTL.dll" ], "runtime_window_title": "Install Error" }, "ipconfig.exe-3D33188ECD39ECFEEA2E08996891C76E": { "file_name": "ipconfig.exe", "file_path": "C:\\Windows\\system32\\ipconfig.exe", "hash_md5": "3D33188ECD39ECFEEA2E08996891C76E", "hash_sha1": "80D6D97B90BCCDD9DE6301E074A8EF2F5B8F600C", "hash_sha256": "C5DBBDDD1193C7ADCA1E30CD17B8C7AF6A76C406DD84DC164BB959C135F1AA70", "hash_sha384": "B3D89E9143D507477761AAEC9D1DB0023998E03D6C8BA7D82379B7551E4FA41C663857F5C2FB3F4EB68D6A7B8046AA62", "hash_sha512": "5404CFB23F038441617582F6840368C0911764D3C2932E8D1E565F9BA04A9D64918895395A63D4D2D78164863B10228A231FD56957EF7BF45AE3ED7894E6D79E", "hash_ssdeep": "768:u23HOsYksucX/iBYuoQeR38BgCnkkYIb9V:ZHO7eYuqR38BFkfc9V", "hash_imp": "15167A60983BFC39B2DA4F53B9B1F28C", "hash_pesha1": "7DB93D56411709851C5A6FD0C64DCB48AECAD8E1", "hash_pe256": "EEA545B20217B812B15C8D1FCAD047A8A745B2FA79E47C55C370687BB1998887", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IP Configuration Utility", "meta_original_filename": "ipconfig.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/c5dbbddd1193c7adca1e30cd17b8c7af6a76c406dd84dc164bb959c135f1aa70/detection/", "output": "\r\nError: unrecognized or incomplete command line.\r\n\r\nUSAGE:\r\n ipconfig [/allcompartments] [/? | /all | \r\n /renew [adapter] | /release [adapter] |\r\n /renew6 [adapter] | /release6 [adapter] |\r\n /flushdns | /displaydns | /registerdns |\r\n /showclassid adapter |\r\n /setclassid adapter [classid] |\r\n /showclassid6 adapter |\r\n /setclassid6 adapter [classid] ]\r\n\r\nwhere\r\n adapter Connection name \r\n (wildcard characters * and ? allowed, see examples)\r\n\r\n Options:\r\n /? Display this help message\r\n /all Display full configuration information.\r\n /release Release the IPv4 address for the specified adapter.\r\n /release6 Release the IPv6 address for the specified adapter.\r\n /renew Renew the IPv4 address for the specified adapter.\r\n /renew6 Renew the IPv6 address for the specified adapter.\r\n /flushdns Purges the DNS Resolver cache.\r\n /registerdns Refreshes all DHCP leases and re-registers DNS names\r\n /displaydns Display the contents of the DNS Resolver Cache.\r\n /showclassid Displays all the dhcp class IDs allowed for adapter.\r\n /setclassid Modifies the dhcp class id. \r\n /showclassid6 Displays all the IPv6 DHCP class IDs allowed for adapter.\r\n /setclassid6 Modifies the IPv6 DHCP class id.\r\n\r\n\r\nThe default is to display only the IP address, subnet mask and\r\ndefault gateway for each adapter bound to TCP/IP.\r\n\r\nFor Release and Renew, if no adapter name is specified, then the IP address\r\nleases for all adapters bound to TCP/IP will be released or renewed.\r\n\r\nFor Setclassid and Setclassid6, if no ClassId is specified, then the ClassId is removed.\r\n\r\nExamples:\r\n > ipconfig ... Show information\r\n > ipconfig /all ... Show detailed information\r\n > ipconfig /renew ... renew all adapters\r\n > ipconfig /renew EL* ... renew any connection that has its \r\n name starting with EL\r\n > ipconfig /release *Con* ... release all matching connections,\r\n eg. \"Wired Ethernet Connection 1\" or\r\n \"Wired Ethernet Connection 2\"\r\n > ipconfig /allcompartments ... Show information about all \r\n compartments\r\n > ipconfig /allcompartments /all ... Show detailed information about all\r\n compartments\r\n" }, "iscsicli.exe-DDD4ADBFC4B3C951084CB5F59D46E7C3": { "file_name": "iscsicli.exe", "file_path": "C:\\Windows\\system32\\iscsicli.exe", "hash_md5": "DDD4ADBFC4B3C951084CB5F59D46E7C3", "hash_sha1": "66DD269949BC599F5B1ECF9E5EFC1AE280132D39", "hash_sha256": "B62ED416F061FBF96185743DE993D0EF17F552C91EFA7D0C1001BBC845A03E97", "hash_sha384": "077AFD58C85FA8E7F81C8ED90A4B049F4ED4FE6687EB096D37362B373217BF440CA5A1CB75F187F1CF1B498A9CCD1CB6", "hash_sha512": "1D353DDA46892EBE11EAF603A27E4E0F97484BEE9F1BC451FC7F42720D4D8C816961212DD8D1C963794D290846D4FEBA9C7FBCC398A51C8159B030B6312911AF", "hash_ssdeep": "3072:JCspsGa2SxmsYO2uAICgKOKaeqUKOpVk/qfWJTfS1n37MX:U5eOjYORKRaeqUp3WJrM", "hash_imp": "AE81E7728A105B6C0D5F14DA87EA23C1", "hash_pesha1": "3753DCAAA8B086F442658ACD72E9498808DFC68C", "hash_pe256": "87AAE2C79F94FE0DC2B133D0D7EC2878156FA90B6783851E173B30C1A4166D6C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "iSCSI Discovery tool", "meta_original_filename": "iscsicli.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b62ed416f061fbf96185743de993d0ef17f552c91efa7d0c1001bbc845a03e97/detection/", "output": "Microsoft iSCSI Initiator Version 10.0 Build 17763\n\niscsicli\n\niscsicli AddTarget <TargetName> <TargetAlias> <TargetPortalAddress>\n <TargetPortalSocket> <Target flags>\n <Persist> <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType>\n <Mapping Count> <Target Lun> <OS Bus> <Os Target> \n <OS Lun> ...\n\niscsicli RemoveTarget <TargetName> \n\niscsicli AddTargetPortal <TargetPortalAddress> <TargetPortalSocket> \n [HBA Name] [Port Number]\n <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType>\n\niscsicli RemoveTargetPortal <TargetPortalAddress> <TargetPortalSocket> [HBA Name] [Port Number]\n\niscsicli RefreshTargetPortal <TargetPortalAddress> <TargetPortalSocket> [HBA Name] [Port Number]\n\niscsicli ListTargets [ForceUpdate]\n\niscsicli ListTargetPortals\n\niscsicli TargetInfo <TargetName> [Discovery Mechanism]\n\niscsicli LoginTarget <TargetName> <ReportToPNP>\n <TargetPortalAddress> <TargetPortalSocket>\n <InitiatorInstance> <Port number> <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType> <Key>\n <Mapping Count> <Target Lun> <OS Bus> <Os Target> \n <OS Lun> ...\n\niscsicli LogoutTarget <SessionId>\n\niscsicli PersistentLoginTarget <TargetName> <ReportToPNP>\n <TargetPortalAddress> <TargetPortalSocket>\n <InitiatorInstance> <Port number> <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType> <Key>\n <Mapping Count> <Target Lun> <OS Bus> <Os Target> \n <OS Lun> ...\n\niscsicli ListPersistentTargets\n\niscsicli RemovePersistentTarget <Initiator Name> <TargetName> \n <Port Number> \n <Target Portal Address> \n <Target Portal Socket> \n\niscsicli AddConnection <SessionId> <Initiator Instance>\n <Port Number> <Target Portal Address>\n <Target Portal Socket> <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType> <Key>\n\niscsicli RemoveConnection <SessionId> <ConnectionId> \niscsicli ScsiInquiry <SessionId> <LUN> <EvpdCmddt> <PageCode>\n\niscsicli ReadCapacity <SessionId> <LUN>\n\niscsicli ReportLUNs <SessionId>\n\niscsicli ReportTargetMappings\n\niscsicli ListInitiators\n\niscsicli AddiSNSServer <iSNS Server Address>\n\niscsicli RemoveiSNSServer <iSNS Server Address>\n\niscsicli RefreshiSNSServer <iSNS Server Address>\n\niscsicli ListiSNSServers\n\niscsicli FirewallExemptiSNSServer\n\niscsicli NodeName <node name>\n\niscsicli SessionList <Show Session Info>\n\niscsicli CHAPSecret <chap secret>\n\niscsicli TunnelAddr <Initiator Name> <InitiatorPort> <Destination Address> <Tunnel Address> <Persist>\n\niscsicli GroupKey <Key> <Persist>\n\niscsicli BindPersistentVolumes\n\niscsicli BindPersistentDevices\n\niscsicli ReportPersistentDevices\n\niscsicli AddPersistentDevice <Volume or Device Path>\n\niscsicli RemovePersistentDevice <Volume or Device Path>\n\niscsicli ClearPersistentDevices\n\niscsicli Ping <Initiator Name> <Address> [Request Count] [Request Size] [Request Timeout]\n\niscsicli GetPSKey <Initiator Name> <initiator Port> <Id Type> <Id>\n\niscsicli PSKey <Initiator Name> <initiator Port> <Security Flags> <Id Type> <Id> <Key> <persist>\nQuick Commands\n\niscsicli QLoginTarget <TargetName> [CHAP Username] [CHAP Password]\n\niscsicli QAddTarget <TargetName> <TargetPortalAddress>\n\niscsicli QAddTargetPortal <TargetPortalAddress>\n [CHAP Username] [CHAP Password]\n\niscsicli QAddConnection <SessionId> <Initiator Instance>\n <Target Portal Address>\n [CHAP Username] [CHAP Password]\n\nTarget Mappings:\n <Target Lun> is the LUN value the target uses to expose the LUN.\n It must be in the form 0x0123456789abcdef\n <OS Bus> is the bus number the OS should use to surface the LUN\n <OS Target> is the target number the OS should use to surface the LUN\n <OS LUN> is the LUN number the OS should use to surface the LUN\n\nPayload Id Type:\n ID_IPV4_ADDR is 1 - Id format is 1.2.3.4\n ID_FQDN is 2 - Id format is ComputerName\n ID_IPV6_ADDR is 5 - Id form is IPv6 Address\nSecurity Flags:\n TunnelMode is 0x00000040\n TransportMode is 0x00000020\n PFS Enabled is 0x00000010\n Aggressive Mode is 0x00000008\n Main mode is 0x00000004\n IPSEC/IKE Enabled is 0x00000002\n Valid Flags is 0x00000001\n\nLogin Flags:\n ISCSI_LOGIN_FLAG_REQUIRE_IPSEC 0x00000001\n IPsec is required for the operation\n\n ISCSI_LOGIN_FLAG_MULTIPATH_ENABLED 0x00000002\n Multipathing is enabled for the target on this initiator\n\nAuthType:\n ISCSI_NO_AUTH_TYPE = 0,\n No iSCSI in-band authentication is used\n\n ISCSI_CHAP_AUTH_TYPE = 1,\n One way CHAP (Target authenticates initiator is used)\n\n ISCSI_MUTUAL_CHAP_AUTH_TYPE = 2\n Mutual CHAP (Target and Initiator authenticate each other is used)\n\nTarget Flags:\n ISCSI_TARGET_FLAG_HIDE_STATIC_TARGET 0x00000002\n If this flag is set then the target will never be reported unless it\n is also discovered dynamically.\n\n ISCSI_TARGET_FLAG_MERGE_TARGET_INFORMATION 0x00000004\n If this flag is set then the target information passed will be\n merged with any target information already statically configured for\n the target\n\nCHAP secrets, CHAP passwords and IPSEC preshared keys can be specified as\na text string or as a sequence of hexadecimal values. The value specified on\nthe command line is always considered a string unless the first two characters\n0x in which case it is considered a hexadecimal value.\n\nFor example 0x12345678 specifies a 4 byte secret\n\nAll numerical values are assumed decimal unless preceeded by 0x. If\npreceeded by 0x then value is assumed to be hex\n\niscsicli can also be run in command line mode where iscsicli commands\ncan be entered directly from the console. To enter command line\nmode, just run iscsicli without any parameters\n\nThe operation completed successfully. \n", "runtime_modules": [ "C:\\Windows\\system32\\iscsicli.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\ISCSIDSC.dll", "C:\\Windows\\system32\\ISCSIUM.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\WMICLNT.dll", "C:\\Windows\\system32\\DEVOBJ.dll" ] }, "iscsicpl.exe-369DE501B34D7A13F0D847BAC1F73354": { "file_name": "iscsicpl.exe", "file_path": "C:\\Windows\\system32\\iscsicpl.exe", "hash_md5": "369DE501B34D7A13F0D847BAC1F73354", "hash_sha1": "31CD3206A8AB0477773FBC01F3FC8F4ACBA2C2F8", "hash_sha256": "FEB783C81B0BC6A5E7BEDF3E1EB71106C95B2B818272B841902F14F33B507DD5", "hash_sha384": "DD1917D4153A877740B3B81495D2BB670DC689CACBA4EC947058A6D716E8D89F3EBAA6E7B153FFB397130BAAD60A33AF", "hash_sha512": "3988030325CF08F04D765AAFDEFE9E1BA72421A9CA58DFE6B480989EB7BE8527AAB7C1D0DF84A16A6E996267BC43AE961CB781DBB73D392C8830A9EFDCC4F416", "hash_ssdeep": "3072:1KPRFAEM82n7GC2jctoKpsusT2rEFpeoIUpZ:1K8X8I0jct5rEJdp", "hash_imp": "23B7709C37B2C36EA9464F15DEA83D64", "hash_pesha1": "1F17A7F1422351B776878A70917580024381024C", "hash_pe256": "A2E982D247E38C632EDF5E055FDFF5E60EC92C6D9BA44ED31F523CBF73ADDF8E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft iSCSI Initiator Configuration Tool", "meta_original_filename": "iscsicpl.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/feb783c81b0bc6a5e7bedf3e1eb71106c95b2b818272b841902f14f33b507dd5/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\iscsicpl.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\iscsicpl.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\iscsicpl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\apphelp.dll", "C:\\Windows\\system32\\iscsicpl.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\system32\\ISCSIDSC.dll", "C:\\Windows\\system32\\ISCSIUM.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\ISCSIED.dll", "C:\\Windows\\system32\\WMICLNT.dll", "C:\\Windows\\system32\\ISCSIEXE.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\fwpuclnt.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll" ] }, "isoburn.exe-C03E53FF88AEE435050361147F76FF75": { "file_name": "isoburn.exe", "file_path": "C:\\Windows\\system32\\isoburn.exe", "hash_md5": "C03E53FF88AEE435050361147F76FF75", "hash_sha1": "11C367729B989DBBC29C26D84F49E9D2315EBF60", "hash_sha256": "D7914543D7B90F43EB069E1152F0B992A39A3E18ED4C0753D1A650677D03002C", "hash_sha384": "0C9D561CAABB5031E74265D6070FE6199106D31ED5DDFF3477C5361BCA302FFEC87E1DFDD015ACE518206D73B7BAD2E1", "hash_sha512": "37A1B85FC937B58F9E0A5527440E75C78528FEB0D13AA5230DFDECEDFA05D00AFA1218B8EB90AD4B7B2B24BF2D0C87E97511EF8B4B620334F9D7ED1F01AEA7B0", "hash_ssdeep": "1536:5m5quEiU/tvAyVK4Sb97eNJYDxwHIHR7psE5ykl9YAbeHZrQqf:eEL/V47e8Dxw89sEAknDeHd3", "hash_imp": "B23BD79BF8103DBFFE35ECE5A60DB146", "hash_pesha1": "613B73AE2B4DEEFEDA1E19E94201A892B98431E6", "hash_pe256": "23D3F46F4A20E87453C48678EF64C3832931E665DBEC8AAB677C083D7A27712E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Disc Image Burning Tool", "meta_original_filename": "ISOBURN.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/d7914543d7b90f43eb069e1152f0b992a39a3e18ed4c0753d1a650677d03002c/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\isoburn.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\isoburn.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll" ], "runtime_window_title": "Windows Disc Image Burner" }, "klist.exe-D15C2108D9A0356CBA6B850749F920F2": { "file_name": "klist.exe", "file_path": "C:\\Windows\\system32\\klist.exe", "hash_md5": "D15C2108D9A0356CBA6B850749F920F2", "hash_sha1": "AAABE874C1C196C88E38989F3722B0D34CB845A3", "hash_sha256": "6AC1BB76543C10B5294AAF286132152757F90825EFECB3C0066F5F2ACC7AA1D7", "hash_sha384": "2FCB433773AD423419ECC57FA6F444E45C3DDEC25B0CB5EC0BAEF65FA18E5788B9537F7855F5C4747514CA63588279EA", "hash_sha512": "51EA0F402D6E353D77B1A35D9328F6238607F299A05BB5A3955B70C18D4B2832B04E1D28E545F36E52739D963F2864B13FF6D015FC8AA21E028D435BBF706B89", "hash_ssdeep": "768:Jp6Xn8kHYsHq1vDUkp7b6vjn4HuyD/AgzfjErQ8Fci4n8D1cSGQeOdJo3Fotta:JcRHYQqJp6vjn4Hpt7EdGQewK3Fotk", "hash_imp": "85207CDD890ACE87BF7EF7906D90318B", "hash_pesha1": "5DF85F162DE119E5B978C9BC498A4EFDE648030E", "hash_pe256": "0CA72AB1B64C5E18A5C30890FFECB308F1011C5DE17A4259E3A5C5628825E00E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Tool for managing the Kerberos ticket cache", "meta_original_filename": "klist.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/6ac1bb76543c10b5294aaf286132152757f90825efecb3c0066f5f2acc7aa1d7/detection/", "output": "\r\nUsage: klist.exe [command]\r\n\r\nCommand list:\r\n [tickets] [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n tgt [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n purge [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n sessions [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n kcd_cache [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n get <SPN> [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n [-kdcoptions <options>] [-cacheoptions <options>]\r\n add_bind <DOMAIN> <DC>\r\n query_bind\r\n purge_bind\r\n" }, "ksetup.exe-65DDBDDC57FAF9C526E467C6039BF3B4": { "file_name": "ksetup.exe", "file_path": "C:\\Windows\\system32\\ksetup.exe", "hash_md5": "65DDBDDC57FAF9C526E467C6039BF3B4", "hash_sha1": "8496259E36433ACEE25363E52668B3F8BA2C39B9", "hash_sha256": "19373ACC55F4DAA9810341A2B164F0B7346A1E2EE5D18A6C75D20E7B0394FB08", "hash_sha384": "23526F8BF61586F9051224349385CF4D57D7CE9673B4004A267F50A1CECA0F55F467D300A41FE90C43966FDD67DF32CE", "hash_sha512": "DFA79E5E0FBF90D97CD5029CD085D6AAD0F463635F921ABC7E1385439F970EC244161211926F7EF96F47804311EC8DBE69D1956E3CE413B653B811CEFB719D4F", "hash_ssdeep": "768:1jyqze1MrTpG0Zl4YBxpc/2BUF+XfQl3ObeefFw6oDOprI4IdHG1gd:HvlGFIXlafef/QO1ING1g", "hash_imp": "1F57ADDB730D5E4437682FEAF1F27C0D", "hash_pesha1": "F56883A7B4E3C04BF9A803F6E4E6E58A0CDEAA95", "hash_pe256": "9EC5A244A9987769BD9BD3F024156DBA410291B73FF270ED10B51E31AE6C3228", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Kerberos Setup tool", "meta_original_filename": "ksetup.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/19373acc55f4daa9810341a2b164f0b7346a1e2ee5d18a6c75d20e7b0394fb08/detection/", "output": "\r\nUSAGE:\r\n/SetRealm <DnsDomainName>\r\n\tMakes this computer a member of an RFC1510 Kerberos Realm\r\n/MapUser <Principal> [Account]\r\n\tMaps a Kerberos Principal ('*' = any principal)\r\r\n\tto an account ('*' = an account by same name);\r\r\n\tIf account name is omitted, mapping is deleted \r\r\n\tfor the specified principal\r\n/AddKdc <RealmName> [KdcName]\r\n\tDefines a KDC entry for the given realm.\r\r\n\tIf KdcName omitted, DNS may be used to locate KDCs.\r\n/DelKdc <RealmName> [KdcName]\r\n\tdeletes a KDC entry for the realm.\r\r\n\tIf KdcName omitted, the realm entry itself is deleted.\r\n/AddKpasswd <Realmname> <KpasswdName>\r\n\tAdd Kpasswd server address for a realm\r\n/DelKpasswd <Realmname> <KpasswdName>\r\n\tDelete Kpasswd server address for a realm\r\n/Server <Servername>\r\n\tspecify name of a Windows machine to target the changes.\r\n/SetComputerPassword <Password>\r\n\tSets the password for the computer's domain account\r\r\n\t(or host principal)\r\n/RemoveRealm <RealmName>\r\n\tdelete all information for this realm from the registry.\r\n/Domain [DomainName]\r\n\tuse this domain (if DomainName is unspecified, detect it)\r\n/ChangePassword <OldPasswd> <NewPasswd>\r\n\tUse Kpasswd to change the logged-on user's password.\r\r\n\tUse '*' to be prompted for passwords.\r\n/ListRealmFlags (no args)\r\n\tLists the available Realm flags that ksetup knows\r\n/SetRealmFlags <realm> <flag> [flag] [flag] [...]\r\n\tSets RealmFlags for a specific realm\r\n/AddRealmFlags <realm> <flag> [flag] [flag] [...]\r\n\tAdds additional RealmFlags to a realm\r\n/DelRealmFlags <realm> <flag> [flag] [flag] [...]\r\n\tDeletes RealmFlags from a realm.\r\n/DumpState (no args)\r\n\tAnalyze the kerberos configuration on the given machine.\r\n/AddHostToRealmMap <host> <realm>\r\n\tAdds a mapping for <host> to <realm> to the registry.\r\n/DelHostToRealmMap <host> <realm>\r\n\tDeletes existing mapping for <host> to <realm> from the registry.\r\n/SetEncTypeAttr <domainname> <enctypes>\r\n\tSets the encryption types trust attribute for <domain> to <enctypes> (multiple types should be separated by spaces).\r\r\n\tSupported encryption types are:\r\r\n\t DES-CBC-CRC, DES-CBC-MD5, RC4-HMAC-MD5, \r\r\n\t AES128-CTS-HMAC-SHA1-96, AES256-CTS-HMAC-SHA1-96\r\n/GetEncTypeAttr <domainname>\r\n\tGets the encryption types trust attribute for <domain>.\r\n/AddEncTypeAttr <domainname> <enctypes>\r\n\tAdds <enctypes> to the encryption types trust attribute for <domain> (multiple types should be separated by spaces).\r\n/DelEncTypeAttr <domainname>\r\n\tDeletes the encryption types trust attribute for <domain>.\r\n" }, "ktmutil.exe-4EA868EA2484EB3DE0598855BA3D8926": { "file_name": "ktmutil.exe", "file_path": "C:\\Windows\\system32\\ktmutil.exe", "hash_md5": "4EA868EA2484EB3DE0598855BA3D8926", "hash_sha1": "5F8DDD3AB39B9DA65B7B77E70AFF46873360C89F", "hash_sha256": "87883CF0DBE0893AE99305EC110E9B0359BF2844865BEB44706A4C2A14F72481", "hash_sha384": "0FDF5628F929B741085632D3BDEC4834F96A95AE9F453F12301BBB399DE30D86A4F1016D5CB3A706090C6E6315F56C0A", "hash_sha512": "AC2DFD2B4C746929B27EE2B389FC4521360F1AE519E2A4B47E5A05AE5BD6B17C0F4AC3B05C29A3A4E866F57AB28803CBA170199ACBC826193D538CEA11015B9C", "hash_ssdeep": "384:DRG4uefNzVpqIuf+N22emFmNdlfATsLS3FsOWIjW:AJeFV8FNNw7FsY", "hash_imp": "9FA70F22B9E5A636D36F7353DFE63DB7", "hash_pesha1": "17F1B7482FDF2C4A07A3C0861155906C006D4F9D", "hash_pe256": "A10F618513024EACD1360F62647E197EE77734F583E0F3FF4C41AED1332D86F3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Kernel Transaction Management Utility", "meta_original_filename": "ktmutil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/87883cf0dbe0893ae99305ec110e9b0359bf2844865beb44706a4c2a14f72481/detection/", "output": "--help is an invalid parameter.\r\n---- Commands Supported ----\r\n\r\ntx Commands related to transactions\r\ntm Commands related to transaction managers\r\n" }, "ktpass.exe-D5357DB7C2352D93F90592DD883DE359": { "file_name": "ktpass.exe", "file_path": "C:\\Windows\\system32\\ktpass.exe", "hash_md5": "D5357DB7C2352D93F90592DD883DE359", "hash_sha1": "1C0BD60334FDBEF6FE9D6209E9C2171A8E345614", "hash_sha256": "167598E4A40A414F075C1B7EDE6BC21DA208EBC736AF8CE222A865A54E98AF26", "hash_sha384": "4EE656C4AC9E3A64F3BB9AB4134DC15349379D6F3F19D0635E52007A18F4A84915DFA02420C072C0C4E04591F8AE86DC", "hash_sha512": "6E6344ACA3A6258E45961A65808C18613BFA9A54BAD0264B070F04E1F5B51E19F1529879C6031B71391DE68FB5242B94FE8C0004D07E6FC85E4AB2755D0E0E93", "hash_ssdeep": "1536:C2CWKlabHmvlOJ28Du27WFRJeIZ5n9Gu/D:C291GvWDlmBH9Gu", "hash_imp": "4121D9F6BAEE42F65D5A86DDD3A96994", "hash_pesha1": "1FD218736BBBDD35CF64E889E8B7D802D5E66179", "hash_pe256": "E406FE4695A6DCF09E32A3A1CFF9410DE0A8B56ABD4C3BE20F047ED3C2A22773", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Kerberos keytab tool", "meta_original_filename": "ktpass.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.652 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.652", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/167598e4a40a414f075c1b7ede6bc21da208ebc736af8ce222a865a54e98af26/detection/", "runtime_modules": [ "C:\\Windows\\system32\\ktpass.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "error": "unknown option '--help'.\r\nCommand line options:\r\n\r\n---------------------most useful args\n[- /] out : Keytab to produce\n[- /] princ : Principal name (user@REALM)\n[- /] pass : password to use\n use '*' to prompt for password.\n[- +] rndPass : ... or use +rndPass to generate a random password\n[- /] minPass : minimum length for random password (def:15)\n[- /] maxPass : maximum length for random password (def:256)\n---------------------less useful stuff\n[- /] mapuser : map princ (above) to this user account (default: don't)\n[- /] mapOp : how to set the mapping attribute (default: add it)\n[- /] mapOp : is one of: \r\n[- /] mapOp : add : add value (default) \n[- /] mapOp : set : set value \n[- +] DesOnly : Set account for des-only encryption (default:don't)\n[- /] in : Keytab to read/digest\n---------------------options for key generation\n[- /] crypto : Cryptosystem to use\n[- /] crypto : is one of: \r\n[- /] crypto : DES-CBC-CRC : for compatibility \n[- /] crypto : DES-CBC-MD5 : for compatibility \n[- /] crypto : RC4-HMAC-NT : default 128-bit encryption \n[- /] crypto : AES256-SHA1 : AES256-CTS-HMAC-SHA1-96 \n[- /] crypto : AES128-SHA1 : AES128-CTS-HMAC-SHA1-96 \n[- /] crypto : All : All supported types \n[- /] IterCount : Iteration Count used for AES encryption\n Default: ignored for non-AES, 4096 for AES\n[- /] ptype : principal type in question\n[- /] ptype : is one of: \r\n[- /] ptype : KRB5_NT_PRINCIPAL : The general ptype-- recommended \n[- /] ptype : KRB5_NT_SRV_INST : user service instance \n[- /] ptype : KRB5_NT_SRV_HST : host service instance \n[- /] ptype : KRB5_NT_SRV_XHST : \n[- /] kvno : Override Key Version Number\n Default: query DC for kvno. Use /kvno 1 for Win2K compat.\n[- +] Answer : +Answer answers YES to prompts. -Answer answers NO.\n[- /] Target : Which DC to use. Default:detect\n[- /] RawSalt : raw salt to use when generating key (not needed)\n[- +] DumpSalt : show us the MIT salt being used to generate the key\n[- +] SetUpn : Set the UPN in addition to the SPN. Default DO.\n[- +] SetPass : Set the user's password if supplied.\n" }, "label.exe-AD94075B470831D51794ECCA453C33AE": { "file_name": "label.exe", "file_path": "C:\\Windows\\system32\\label.exe", "hash_md5": "AD94075B470831D51794ECCA453C33AE", "hash_sha1": "3165121A8332A010C2FEF8E9E11B3171B3098859", "hash_sha256": "7BACC9FD1870A349740E7995AC1BA06FCE69DA50F7542902C23648FD52354E65", "hash_sha384": "3080394DD7AA894E785040BE0256499D8496449C446E9FC4FF8599E3ABB7D05DD649271B8D7E73561E4485216AAA6133", "hash_sha512": "69457E094358E6E2A443E53E6D0E8ACC7137811E66D1213DBADF605027100C26D753420B611D337EF2FC1948901BF4FFA696D11B3D34E52E00373C32BBA2EC4E", "hash_ssdeep": "384:48CobJejxdNDRfn5YjRBfQVRJT54WStjW:487bJcxdHfQrkPT58", "hash_imp": "9D31AD7E7AE990941EB6693E119F8284", "hash_pesha1": "3DA701346B69BB84DE3FD83ADF8365223A5B6F42", "hash_pe256": "CD06B220E9494FC1D78C5435345C00ABB869B68A56001DC07B1ACB1FD9FC0F0E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Label Utility", "meta_original_filename": "Label.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/7bacc9fd1870a349740e7995ac1ba06fce69da50f7542902c23648fd52354e65/detection/", "output": "Creates, changes, or deletes the volume label of a disk.\r\n\r\nLABEL [drive:][label]\r\nLABEL [/MP] [volume] [label]\r\n\r\n drive: Specifies the drive letter of a drive.\r\n label Specifies the label of the volume.\r\n /MP Specifies that the volume should be treated as a\r\n mount point or volume name.\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name. If volume name is specified,\r\n the /MP flag is unnecessary.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\label.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "LanguageComponentsInstallerComHandler.exe-3C4FF01038EF7CDDFC7728AB694E049F": { "file_name": "LanguageComponentsInstallerComHandler.exe", "file_path": "C:\\Windows\\system32\\LanguageComponentsInstallerComHandler.exe", "hash_md5": "3C4FF01038EF7CDDFC7728AB694E049F", "hash_sha1": "EB8CA02398715C9DF0ABCBCCC2D6363C761F5844", "hash_sha256": "2E3BD3DE5C065B1518A32C9104769726E9B51CA15ACB810FCEDD2B26B2148D75", "hash_sha384": "D1613F3DC319B233E55DD8FB05FA4DE5474535BC32765A874A7993C75FD4A03F8DEE210E95EC638D32C56615673196A8", "hash_sha512": "2A923E93272DA6B890307216BD6A40A5001947F4D7887D86B0C752DBD74B45AEEA4F410F73A88F04230964AAB99EE5834E70342C2EF50A39846DA586ADDDF9F5", "hash_ssdeep": "1536:YJrjqjYsObJKvKEeHx0BHC3j1+2yL54RS9:GMvsR0Y+P449", "hash_imp": "D0D0FD91F38D8127BAAE5B6571B84A5A", "hash_pesha1": "52F53F6110A0911EE83B79CEE83DA1D4123A6A23", "hash_pe256": "650636C997F406C326FD70543DDBB394859AE4F6D779AA1C1DCF60D2DD65EB28", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "LanguageComponentsInstaller COM Handler", "meta_original_filename": "LanguageComponentsInstallerComHandler.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/2e3bd3de5c065b1518a32c9104769726e9b51ca15acb810fcedd2b26b2148d75/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1348": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\LanguageComponentsInstallerComHandler.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "LaunchTM.exe-D4889220D216BEEB0D36C132D8ECE979": { "file_name": "LaunchTM.exe", "file_path": "C:\\Windows\\system32\\LaunchTM.exe", "hash_md5": "D4889220D216BEEB0D36C132D8ECE979", "hash_sha1": "972B108F689E0F7E7AFD3CD2A14BB9E2532E03B4", "hash_sha256": "397FEFBE33FF0677250C856B28B12080F2C0EB22A939E53B4A74AE464F43EB17", "hash_sha384": "816B48667629F0ABE71BD4C240782C9E7A7CF5202C8530BE6B04A1809BBED40143D4A85AFA1BC060AC90D2E01993D7BB", "hash_sha512": "F98C68CBEDF470B14AD0B0C42864D9257EE9479252B8C86891BB25A02C05C5575460EC420E88C56A64E340A75613B4F88532AD6B5E1FC37723120FAC5F100B58", "hash_ssdeep": "1536:AtHBUPm8UngMCw2I8FXmzOGDBdpunOl1UIHmejrDwkKgT43FVkXXPKedjXfaW:OU3eCO8FXUO0iOlCIHmeRKPKk", "hash_imp": "AD4CEE994BCE4BEC755FC55C249B5C5F", "hash_pesha1": "32FE30D60691C5972A583B1D376D84E96F43B7EC", "hash_pe256": "BF6687F70C3F8203FE15BB44929C3DB4E2E51DAD5964DA85897DCF9D4CF26214", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Manager Launcher", "meta_original_filename": "LaunchTM.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/397fefbe33ff0677250c856b28b12080f2c0eb22a939e53b4a74ae464f43eb17/detection/", "children": "Taskmgr.exe", "runtime_modules": [ "C:\\Windows\\system32\\LaunchTM.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll" ] }, "LaunchWinApp.exe-64D4E881CC9284FF841A6CDA4D4CFCCA": { "file_name": "LaunchWinApp.exe", "file_path": "C:\\Windows\\system32\\LaunchWinApp.exe", "hash_md5": "64D4E881CC9284FF841A6CDA4D4CFCCA", "hash_sha1": "73F8E9196D5EBB27F114B113F15C176973321B7E", "hash_sha256": "D31EDD1B63864881C2EC88BBC0C23EBCF4FB16109B6F94E5F2987B8C62EA92CE", "hash_sha384": "B11737593BDFBF446F1593DFA94D4E9175FB6C887A1535EF06923DACCC29D98EDD5B59D389DA8145D52EB923AA453495", "hash_sha512": "78D753904038D461B6A5B36C81CEF02F329F4FBA8389DA58A36A98F0EAD5AB3CEE85CEC06B940E231872DE05CAD11FDFFD88690743EEB161255AE087FE61F156", "hash_ssdeep": "768:prkRt577y0Qs34j+wmV+0HcYidGQp1vjsl0UzpUduN8GgKNyWI:VkM0Q8FVV+kcYnQp5s+4pUduOKNy3", "hash_imp": "FB80953F255441A0AB4C8FF4BFE35C97", "hash_pesha1": "0EAC11029C92F25DD787C1EA08860F993A9F7FD7", "hash_pe256": "7404F49050B35AE5C964A4A8F00B2357C82F46B32351B74468270C464D79DE3A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Launch Windows App", "meta_original_filename": "LaunchWinApp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/d31edd1b63864881c2ec88bbc0c23ebcf4fb16109b6f94e5f2987b8c62ea92ce/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\LaunchWinApp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\ndfapi.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\wdi.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\SYSTEM32\\DUser.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll" ], "runtime_window_title": "--help" }, "LbfoAdmin.exe-911DC9868BBFEA5E95DC88BE10BC9C11": { "file_name": "LbfoAdmin.exe", "file_path": "C:\\Windows\\system32\\LbfoAdmin.exe", "hash_md5": "911DC9868BBFEA5E95DC88BE10BC9C11", "hash_sha1": "6C451C32E74F99C8823DB0EB82799958C2458334", "hash_sha256": "457C99EF5D87D7EFC4B853CCC0D07FF16F9E411EFB59A8B0FDE4E85FED704B39", "hash_sha384": "D20D1B5F517F9D6E27B6A31D003A1F349C5BC5D33FF51B0CC0189B152F30FFFDC734B7AAB7F15E26305E0054586FFFCF", "hash_sha512": "8911F561602D6517CC58EE390665794810205B73F8E25D872D1980D70FD22167258BFCF25116E0CCE8A2A3B58EE89D0D7F1DCDBAE41E6382693B1AD0AED54229", "hash_ssdeep": "1536:BtVcjj4PBuhUYXH1VydQShStyJPnqbye86opC3M/EgmnryqPbvAWc14zUWJGCTBH:lxP8hUYXH1+mty9quegO7jS4VzTN", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "4825BF02792DA52E65100B9414806B6951CBF8AA", "hash_pe256": "B83976D52CA198B307119327803D342AC3B520961DAA19C20D4B97F2AEDFBFF3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NIC Teaming", "meta_original_filename": "LBFOADMIN.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/457c99ef5d87d7efc4b853ccc0d07ff16f9e411efb59a8b0fde4e85fed704b39/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\LbfoAdmin.exe.mui": "File", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_1528": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\LbfoAdminLib.dll": "File", "\\RPC Control\\DSEC5F8": "Section", "\\Sessions\\2\\BaseNamedObjects\\701647d8-b9fe-44e8-853f-bc4f86189ce0": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\2\\BaseNamedObjects\\UrlZonesSM_Administrator": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\5f8HWNDInterface:5a02de": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R--) C:\\Windows\\System32\\spool\\drivers\\color\\sRGB Color Space Profile.icm": "File", "(R-D) C:\\Windows\\System32\\en-US\\msctfui.dll.mui": "File", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\LbfoAdmin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\5543cca0df435801e2303ff46a482ed5\\mscorlib.ni.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\CRYPTBASE.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\6885802f40fd803e49150d8a2b43a09b\\System.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Core\\f29b1120627489754c4b8dd317bbe950\\System.Core.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\WindowsBase\\7766b716f453669f6453022ce957c6ad\\WindowsBase.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\PresentationCore\\8fad18d47be73b98845c53d0e6d3b964\\PresentationCore.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Presentatio5ae0f00f#\\d1101640429a2c3d8c6c257103ad22c1\\PresentationFramework.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Xaml\\12c01954752c224882de75b4418c8382\\System.Xaml.ni.dll", "C:\\Windows\\SYSTEM32\\dwrite.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\WPF\\wpfgfx_v0400.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\MSVCP120_CLR0400.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\WPF\\PresentationNative_v0400.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll" ], "runtime_window_title": "NIC Teaming" }, "LegacyNetUXHost.exe-7F8A3F4EB64E412D4FFBCA36CB1EB589": { "file_name": "LegacyNetUXHost.exe", "file_path": "C:\\Windows\\system32\\LegacyNetUXHost.exe", "hash_md5": "7F8A3F4EB64E412D4FFBCA36CB1EB589", "hash_sha1": "FC321011CAC8AA257DB14C74F5FA3B71741E796D", "hash_sha256": "F16D328095FFC06989CCEEBAD3D880565896F9460812889C544B4D956D5C047D", "hash_sha384": "F4A775BFE169E5583730BDE46E97B595AABD109D350347E7CA6B6064AA13FA6831FEE070DC8334455C7A398201537D30", "hash_sha512": "1508EEEA80666BEE84D9CA19274707852733DB3F1F854B73FF37D826D3F82A7FAB9452C3A6AF7703BB5CFC02B46E204F629211257991C34E1EFE1FDB0D9E8583", "hash_ssdeep": "3072:QLIsMfC5Tkkd+uri3KtMJLO+HiQILZx7+Uv5a9R0zo04+HvJyWqJ:AIsMfUTkc7mRC1X34+HvJyWq", "hash_imp": "ED2CE9C8716ED66089AAD02749C2CEDB", "hash_pesha1": "43C00FB0786447CD6B04A07A4E593110A3D3265A", "hash_pe256": "5D8F7023D36D1AC19E99D09F4E5CEC4158BB94967C5AE94A567D2CDD0D6E5C22", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Legacy Net UX Host", "meta_original_filename": "LegacyNetUXHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/f16d328095ffc06989cceebad3d880565896f9460812889c544b4d956d5c047d/detection/" }, "LicenseManagerShellext.exe-2B709239211F06886CAE4E52E4E365F0": { "file_name": "LicenseManagerShellext.exe", "file_path": "C:\\Windows\\system32\\LicenseManagerShellext.exe", "hash_md5": "2B709239211F06886CAE4E52E4E365F0", "hash_sha1": "520AACD6A091723B464A9B37FDC1C97BF48632FF", "hash_sha256": "EDE5C31B07B327336A5E9877BA00982B5A81EACA029A66E051B9C9554FD34119", "hash_sha384": "A8D27EB6E387F9E0A94AB502581752287F017A50B8031620CBBD327CF09E4C13407CA31EFE9420C2575A9EB5E8210E29", "hash_sha512": "21CC73BF60E5EF9F1BD498A1BCC7A22B02705A2A592C71BC9F658C7A18B8AF9C12EB348A6D09AD23D7D00361052F6B2169138153F0708D01D95E9692234B2509", "hash_ssdeep": "768:hkH4soAWYHAldcbQDycJn9ND5xdpfo7MhfxMG7CTXUKKsy7TTs:uHuYHm4+zND51foIgGmXdTy7TTs", "hash_imp": "D168387995C627858937450BDD488EE4", "hash_pesha1": "4FE2FD952F76A36E4BC2709F80EF102D662024E7", "hash_pe256": "D5ECAD99DE91E4A84253C50BF1F8DDF57CA4C56B4BD0CF059F0401927B9BC577", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "LicenseManagerShellExt", "meta_original_filename": "LicenseManagerShellExt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/ede5c31b07b327336a5e9877ba00982b5a81eaca029a66e051b9c9554fd34119/detection/", "runtime_modules": [ "C:\\Windows\\system32\\LicenseManagerShellext.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\LicenseManager.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\CLIPC.dll" ] }, "licensingdiag.exe-7DB967FA1ABF5C637AFDD41DF6AEFC43": { "file_name": "licensingdiag.exe", "file_path": "C:\\Windows\\system32\\licensingdiag.exe", "hash_md5": "7DB967FA1ABF5C637AFDD41DF6AEFC43", "hash_sha1": "405A49315CE12219B2E4CCD92CDA6C6674EA2403", "hash_sha256": "AD50D6F3F21A34D2FE251D5C3CC0E0F42170E2C70E45B7712BDBDA0543B8BBF8", "hash_sha384": "C1195C22E782E1E85516A3CA3AB0DFAE725BD87F5A6AABAC617644984AEFB1C7E9DE4BC3EB154CBB47027F365028F483", "hash_sha512": "42AAE30E2A08450770D7045CA10B14ADB6613CFF7604A7521D049C93E0F642B14FE0AF46070A60CD5AEEDFCC35E8BB19034E1553FD90A44B08D4AD6765BC9346", "hash_ssdeep": "6144:YVtC3MmyBfL0HlMfMezbQOS3mJUd/Wo+1ghgFxS:aQmfL06bzbQN3gUwophgFxS", "hash_imp": "60DBED06C36EE4441DD6D6C5DB80F524", "hash_pesha1": "181FB8FE9D098E7BBAC20AB52EDB3AFAD2E321E7", "hash_pe256": "AD485C6A940F82D88521C72C13871B008BEF86EDB5DAD327C6A50995F22F507A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Licensing Diagnostic Tool", "meta_original_filename": "LicensingDiag.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/ad50d6f3f21a34d2fe251d5c3cc0e0f42170e2c70e45b7712bdbda0543b8bbf8/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\licensingdiag.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\licensingdiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\system32\\CLIPC.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll" ], "runtime_window_title": "Microsoft Licensing Diagnostic Tool" }, "LicensingUI.exe-257764F6BAF41E205C15C1856080E490": { "file_name": "LicensingUI.exe", "file_path": "C:\\Windows\\system32\\LicensingUI.exe", "hash_md5": "257764F6BAF41E205C15C1856080E490", "hash_sha1": "8D6F2960A718D05F21C9D2F41B0C634107686419", "hash_sha256": "5106206F1502ED82EEC42F2A592D3C9DEEF70ED54B2967BC0EA8FF4D9BA1BD28", "hash_sha384": "7474673AD2EC0C3F6F0D3A6CA055349BC437C527E3C9A26331019C288D748E731D807D10705206DB1CA812B544460A86", "hash_sha512": "1015222DD724B9C824D077CD1E849F6D7FC97AF76959392FD99A1D41D642EA028BDC59E33EB826FC17658012828B4DFC516EEFF8ECC9033F1999CD171DACB06D", "hash_ssdeep": "3072:MyYIqXIwfFdM74fb+NI3rMx6KbIqFmvkgaAhEq8iX:M1fzF9bpAx6nVoQ", "hash_imp": "C24579D42F42DAD7A0B7F6D48F57EBFE", "hash_pesha1": "8A3A5E32257D6DA394F02C18DA267B4B37B8D1CB", "hash_pe256": "372CDB5A5E62C079D6CAAD8144FB3F3226B8165191A34A30A6F05FEF8A8E06A5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Licensing UI", "meta_original_filename": "LicensingUI.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/5106206f1502ed82eec42f2a592d3c9deef70ed54b2967bc0ea8ff4d9ba1bd28/detection/" }, "LocationNotificationWindows.exe-CB595539F2D6F546678A956350447932": { "file_name": "LocationNotificationWindows.exe", "file_path": "C:\\Windows\\system32\\LocationNotificationWindows.exe", "hash_md5": "CB595539F2D6F546678A956350447932", "hash_sha1": "AA48C7C755EFD1FFCBDD88B508125929F72B597E", "hash_sha256": "4FB18811FED500A9D1E24F14C158CCD7095D5777D2F2F8247982D14119DBC8DD", "hash_sha384": "1094C93817D901A4ACDDE05C81C3FB926C2275F903CBCD94B094B2502E9B175D2FF1820ACDAD8514757EBDD9DFA5AD12", "hash_sha512": "298AF821B9FEDDFA03CAACCA3B27C28038B31C2D47E4197BFEA29615FC5B3ED9E222A2494DABE9317DDB30C4F577AD199DF735CCEE113C9A655BB778453C23DF", "hash_ssdeep": "1536:rWu809ToV8jxaGZx1wKTZsGHUj/zkVRLYTL1DPpLv:Th/jxaGEGHs8RkxP5v", "hash_imp": "E6E756CE193748D21E1CE4FE0FFE94E4", "hash_pesha1": "8C8D1C28AACE1A323CA0BCF35A4E173F315733ED", "hash_pe256": "6FF66743A69B51B6525C567ED4FC42D4D83CCD2B2B4201B7D96B4376B8B5F2D5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Location Notification", "meta_original_filename": "LocationNotificationWindows.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/4fb18811fed500a9d1e24f14c158ccd7095d5777d2f2f8247982d14119dbc8dd/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\LocationNotificationWindows.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\LocationNotificationWindows.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\msvcp110_win.dll" ] }, "Locator.exe-A0DD6042F7734F61D55D6A62D60FE498": { "file_name": "Locator.exe", "file_path": "C:\\Windows\\system32\\Locator.exe", "hash_md5": "A0DD6042F7734F61D55D6A62D60FE498", "hash_sha1": "47D3CD96D2D9776F4CCE212859EAD98E2B4FC4DF", "hash_sha256": "8B5743D4ACF8C571F039F83464672306D9F899E4C8512FAB9538807C43DF4A67", "hash_sha384": "5BC396F747EAE4121C26326C4BE82B51B7ABE860B1B8C057D528CF6E7E8942424FC03D72F67C02C6F2BCB151F5933880", "hash_sha512": "2DE5658F244D5196D501D5E3ED56256995FCCBF6691B78B843BC2866B10CC4CE46F8573E8FCC01BE7AD6914FF81CD7F4A25D724083A17A99ABBEE55C23B26D1A", "hash_ssdeep": "192:GkJX2saUpB315IDs0sCESBFJDK0zK5T9PCGFrsa1q18oDDoie21mDyW/lW:GcjF3u5E+JiPCArpo1ZDOLDyW/lW", "hash_imp": "CBECBDF0E16268273DCA4CB132D15D23", "hash_pesha1": "59565DBE8FFB2D4A88E341D2148CBA7F8B6DC9F9", "hash_pe256": "AA5DEE2A205FFB2BAC7EE69DECDA27AA973A2733DE134DC349A931B067DA50C1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Rpc Locator", "meta_original_filename": "locator.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/8b5743d4acf8c571f039f83464672306d9f899e4c8512fab9538807c43df4a67/detection/" }, "LockAppHost.exe-3EC8A3E31B73E8289423A06C8A1A53F7": { "file_name": "LockAppHost.exe", "file_path": "C:\\Windows\\system32\\LockAppHost.exe", "hash_md5": "3EC8A3E31B73E8289423A06C8A1A53F7", "hash_sha1": "8F165BFD30C636B68EC8C63724CE14D0D5D0CF3C", "hash_sha256": "27002A3328E8288299204B1D1D145DE57968534523F5DEC668008409080ED1DA", "hash_sha384": "E1A71C49C42DA3728F740D1525070C2A2AF9C2372CB87EB5DDC6CA6943C7D973E3C86EADD146C54A00F563D38C3621A9", "hash_sha512": "10D63DF97EDB8BA141AD1DBDEA56C5E4F863B430428B9512CD337B901D393CF52FF79D07220022B1B6A5F9EA43238EB864C4887AF40394DCF33BDF7118DA7AFD", "hash_ssdeep": "1536:qneMQN+/BJvjk+plcvjBwX+YSF7IRlfb/xVW0yfCyGb+K341ZLqwkmmNf2lPHIp:qoN+J54+8BwGI/7rW0v+K3mZLqrmmt2K", "hash_imp": "992BE79AE17ED3220C3E4B4D1B7E29B5", "hash_pesha1": "BC01FB3BBD360EAFCA2E1E1357D025E7559F6C88", "hash_pe256": "E797FAA92799649E44BBBBEE5B4961D76F75CD390672B690D1FF20C2D85D05FE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "LockAppHost", "meta_original_filename": "LockAppHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/27002a3328e8288299204b1d1d145de57968534523f5dec668008409080ed1da/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECE94": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\LockAppHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\system32\\LockHostingFramework.dll", "C:\\Windows\\System32\\SHCORE.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\UxTheme.dll" ] }, "LockScreenContentServer.exe-3EDCC6F8A9DA6E6C54E89613A8074562": { "file_name": "LockScreenContentServer.exe", "file_path": "C:\\Windows\\system32\\LockScreenContentServer.exe", "hash_md5": "3EDCC6F8A9DA6E6C54E89613A8074562", "hash_sha1": "F10D01E0FE76D18CB0EBE4321F158635DED12892", "hash_sha256": "1F7DE5D4699A7129B1C02F963DFECF0E6009804BC27C90A105C9E8907417766A", "hash_sha384": "3A346DC8E52D421F0D733DD397DA7FE9949E1F91162C57932FCB94EE855B5C90D5A4B362FDA7387E0880180EF0E70ADC", "hash_sha512": "6648741D8CFFC627471B7FF54DDF396DD47B3DCC44826407B4F66061718F2055D44EFA4C80D6220F2CC4556AC051C59074FBF809EF6A48E486A08C64F5B09D73", "hash_ssdeep": "768:os9qts03uq797jOLL0h6LsiGAdiGtk6ZxWnPHJ1UXSXj1PkXLP3:bsztosiziX6ZxWnPHJ1xpPkbP", "hash_imp": "6841727964D36EC5DE2FA2C75DD8971B", "hash_pesha1": "DF320ACFC8F2BF87EFF9B429FAEF823BA7C21488", "hash_pe256": "20C38A509E1D70E2282ED8A6C0EB989C68F7E11A153CB473DF1F1DDC2B43E15F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "LockScreenContent Server", "meta_original_filename": "LockScreenContentServer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/1f7de5d4699a7129b1c02f963dfecf0e6009804bc27c90a105c9e8907417766a/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC11E8": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\LockScreenContentServer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll" ] }, "lodctr.exe-4FCD147FDB2985F73B7FA8C93C655FC5": { "file_name": "lodctr.exe", "file_path": "C:\\Windows\\system32\\lodctr.exe", "hash_md5": "4FCD147FDB2985F73B7FA8C93C655FC5", "hash_sha1": "94DC43EB604194B88789464446468F791A38D735", "hash_sha256": "7810A59464D4BD915B3225471FF32F8B4CEC67D09BBBC90C67326AB264B96007", "hash_sha384": "2BF3F6272E00524B9A3562308CE1E8E2B1A5562961AB373E36D6AB26DE58E5574867CF30E3A741D664B48F4A3A2B4B6D", "hash_sha512": "6716C5C1BFC7CC2D4F6298F15F93116C08691AAE94358E499B2CF1EBB05171AE564D3FF168C28B2D69E07E7D4A6DBBCD6FD227900F604F8213D126E039801006", "hash_ssdeep": "768:nFh9FLaBw3r06I4y6XlnLAsoUq6iomo2TjMDmOtHplMcJc2mJHfwNAdAk:T8AJrBtBUomHjMDmOvlMcZ8HfwCdAk", "hash_imp": "5CD21FCBA296BDF1A70DBEDF29A58AE1", "hash_pesha1": "6032B7447CB864FF3607B92871CAE28375E1E120", "hash_pe256": "2878A8AA21199B1E59F97FC6DE22B8D5B46A0E092D8C5C8C3C1527112C18329B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Load PerfMon Counters", "meta_original_filename": "LODCTR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/7810a59464d4bd915b3225471ff32f8b4cec67d09bbbc90c67326ab264b96007/detection/", "output": "\r\n\r\nLODCTR\r\n Updates registry values related to performance counters.\r\n\r\nUsage:\r\n LODCTR <INI-FileName>\r\n INI-FileName is the name of the initialization file that contains\r\n the counter name definitions and explain text for an extensible\r\n counter DLL.\r\n\r\n LODCTR /S:<Backup-FileName>\r\n save the current perf registry strings and info to <Backup-FileName>\r\n\r\n LODCTR /R:<Backup-FileName>\r\n restore the perf registry strings and info using <Backup-FileName>\r\n\r\n LODCTR /R\r\n rebuild the perf registry strings and info from scratch based on the current\r\n registry settings and backup INI files.\r\n\r\n LODCTR /T:<Service-Name>\r\n set the performance counter service as trusted.\r\n\r\n LODCTR /E:<Service-Name>\r\n enable the performance counter service.\r\n\r\n LODCTR /D:<Service-Name>\r\n disable the performance counter service.\r\n\r\n LODCTR /Q\r\n\r\n LODCTR /Q:<Service-Name>\r\n query the performance counter service information, either query all or specified one.\r\n\r\n LODCTR /M:<Counter-Manifest>\r\n install Windows Vista performance counter provider definition XML file\r\n to system repository.\r\n\r\nNote: any arguments with spaces in the names must be enclosed within\r\nDouble Quotation marks.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\lodctr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\loadperf.dll" ] }, "logagent.exe-E864AB7D07946FF8CC459AA4CDDC713F": { "file_name": "logagent.exe", "file_path": "C:\\Windows\\system32\\logagent.exe", "hash_md5": "E864AB7D07946FF8CC459AA4CDDC713F", "hash_sha1": "DDCD707E7DE8E9D874BBFBBE911415521793472A", "hash_sha256": "EC86199B43A0C82A06365EBEDBD6396BF93A418B18FB9FC4F6C8BC8B3A83D079", "hash_sha384": "82AE376A56DEEF040E2D3055A19DB5D4C95BB865BD5028BE6CF599D13D9409558D4236EBA19B26F82E8DC2DF5F4B80D0", "hash_sha512": "53E424B98B5C527E610806CBAAD1F47364D003405E5B7B9F1BCB86CE78645115124026AEF6BB3C53779F31BFD758DF50121EA6736F45F30784404C79A851B160", "hash_ssdeep": "3072:kPIdlYIcKInlBqMFI0+uvndrZPXb56sz3aD+amCKv2:kPhqMh+ondrVNZ3aD+amCK", "hash_imp": "D41074F30A9619E57B1244FFD6A35B53", "hash_pesha1": "D7F69AD9B1B5BF567D9249605D7788AFB536AABB", "hash_pe256": "87F37CFADEDE0E5B73D51A819745C39E839F9F48DD83F2A474C598204D8BA6B9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Logagent", "meta_original_filename": "logagent.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/ec86199b43a0c82a06365ebedbd6396bf93a418b18fb9fc4f6c8bc8b3a83d079/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECE2C": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\logagent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\WININET.dll", "C:\\Windows\\system32\\WSOCK32.dll", "C:\\Windows\\System32\\WS2_32.dll" ] }, "logman.exe-8599C7688C23F1822E2C4B454005CC28": { "file_name": "logman.exe", "file_path": "C:\\Windows\\system32\\logman.exe", "hash_md5": "8599C7688C23F1822E2C4B454005CC28", "hash_sha1": "04A320BBDB623BBCDC84D99DA3A5118AEFCD80B3", "hash_sha256": "2E40AC8FECF1FF562DE9AAFAEA5192985AC3CC13BE32B508771C885FD43673DA", "hash_sha384": "C7691C4E1506D489DCA966AE98BF2AD6064BCA081494CFCCAE08D7230A4681F2349477ED3AC7B2E3652D9D207DF3465C", "hash_sha512": "A41086312DC2433B0071350F374ABC66345FE97F2F13C1ECDC232ED8C1B86B94FF11CB1A7A2E646ABD280349CD42D9DF8E4E3B5A9CFC5812C5022955740C5A6E", "hash_ssdeep": "1536:w/6DGGrJK5ZYkP7poyR4XlGX/lgxnHXKYT2OXmHuYHwMy3O2KY2naCigXly:w0X9kN94XligXDNxecFKRnaD7", "hash_imp": "6B33B29610D8D91ACB7A22E2E6972E9D", "hash_pesha1": "A43AE8D4C7B9BAAB58097C80241BCC278F6248F7", "hash_pe256": "F71CBF478C814AE710EC8F6587048A8667A6990C6BC767CD4DE8A8758233E336", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Performance Log Utility", "meta_original_filename": "Logman.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/2e40ac8fecf1ff562de9aafaea5192985ac3cc13be32b508771c885fd43673da/detection/", "output": "\r\nMicrosoft r Logman.exe (10.0.17763.1)\r\n\r\nUsage:\r\n C:\\Windows\\system32\\logman.exe [create|query|start|stop|delete|update|import|export] [options]\r\n\r\nVerbs:\r\n create Create a new data collector.\r\n query Query data collector properties. If no name\n is given all data collectors are listed.\r\n start Start an existing data collector and set the\n begin time to manual.\r\n stop Stop an existing data collector and set the\n end time to manual.\r\n delete Delete an existing data collector.\r\n update Update an existing data collector's properties.\r\n import Import a data collector set from an XML file.\r\n export Export a data collector set to an XML file.\r\n\r\nAdverbs:\r\n counter Create a counter data collector.\r\n trace Create a trace data collector.\r\n alert Create an alert data collector.\r\n cfg Create a configuration data collector.\r\n providers Show registered providers.\r\n\r\nOptions (counter):\r\n -c <path [path [...]]> Performance counters to collect.\r\n -cf <filename> File listing performance counters to collect,\n one per line.\r\n -f <bin|bincirc|csv|tsv|sql> Specifies the log format for the data\n collector. For SQL database format, you must\n use the -o option in the command line with\n the DNS!log option. The defaults is binary.\r\n -sc <value> Maximum number of samples to collect with a\n performance counter data collector.\r\n -si <[[hh:]mm:]ss> Sample interval for performance counter data\n collectors.\r\n\r\nOptions (trace):\r\n -f <bin|bincirc|csv|tsv|sql> Specifies the log format for the data\n collector. For SQL database format, you must\n use the -o option in the command line with\n the DNS!log option. The defaults is binary.\r\n -mode <trace_mode> Event Trace Session logger mode. For more\n information visit -\n https://go.microsoft.com/fwlink/?LinkID=136464\r\n -ct <perf|system|cycle> Specifies the clock resolution to use when\n logging the time stamp for each event. You\n can use query performance counter, system\n time, or CPU cycle.\r\n -ln <logger_name> Logger name for Event Trace Sessions.\r\n -ft <[[hh:]mm:]ss> Event Trace Session flush timer.\r\n -[-]p <provider [flags [level]]> A single Event Trace provider to enable.\n The terms 'Flags' and 'Keywords' are\n synonymous in this context.\r\n -pf <filename> File listing multiple Event Trace providers\n to enable.\r\n -[-]rt Run the Event Trace Session in real-time mode.\r\n -[-]ul Run the Event Trace Session in user mode.\r\n -bs <value> Event Trace Session buffer size in kb.\r\n -nb <min max> Number of Event Trace Session buffers.\r\n\r\nOptions (alert):\r\n -[-]el Enable/Disable event log reporting.\r\n -th <threshold [threshold [...]]> Specify counters and their threshold\n values for and alert.\r\n -[-]rdcs <name> Data collector set to start when alert fires.\r\n -[-]tn <task> Task to run when alert fires.\r\n -[-]targ <argument> Task arguments.\r\n -si <[[hh:]mm:]ss> Sample interval for performance counter data\n collectors.\r\n\r\nOptions (cfg):\r\n -[-]ni Enable/Disable network interface query.\r\n -reg <path [path [...]]> Registry values to collect.\r\n -mgt <query [query [...]]> WMI objects to collect.\r\n -ftc <path [path [...]]> Full path to the files to collect.\r\n\r\nOptions:\r\n -? Displays context sensitive help.\r\n -s <computer> Perform the command on specified remote system.\r\n -config <filename> Settings file containing command options.\r\n [-n] <name> Name of the target object.\r\n -pid <pid> Process identifier.\r\n -xml <filename> Name of the XML file to import or export.\r\n -as Perform the requested operation asynchronously.\r\n -[-]u <user [password]> User to Run As. Entering a * for the password\n produces a prompt for the password. The\n password is not displayed when you type it at\n the password prompt.\r\n -m <[start] [stop]> Change to manual start or stop instead of a\n scheduled begin or end time.\r\n -rf <[[hh:]mm:]ss> Run the data collector for the specified\n period of time.\r\n -b <M/d/yyyy h:mm:ss[AM|PM]> Begin the data collector at specified time.\r\n -e <M/d/yyyy h:mm:ss[AM|PM]> End the data collector at specified time.\r\n -o <path|dsn!log> Path of the output log file or the DSN and\n log set name in a SQL database. The default\n path is '%systemdrive%\\PerfLogs\\Admin'.\r\n -[-]r Repeat the data collector daily at the\n specified begin and end times.\r\n -[-]a Append to an existing log file.\r\n -[-]ow Overwrite an existing log file.\r\n -[-]v <nnnnnn|mmddhhmm> Attach file versioning information to the end\n of the log name.\r\n -[-]rc <task> Run the command specified each time the log\n is closed.\r\n -[-]max <value> Maximum log file size in MB or number of\n records for SQL logs.\r\n -[-]cnf <[[hh:]mm:]ss> Create a new file when the specified time has\n elapsed or when the max size is exceeded.\r\n -y Answer yes to all questions without prompting.\r\n -fd Flushes all the active buffers of an existing\n Event Trace Session to disk.\r\n -ets Send commands to Event Trace Sessions\n directly without saving or scheduling.\r\n\r\nNote:\r\n Where [-] is listed, an extra - negates the option.\r\n For example --u turns off the -u option.\r\n\r\nMore Information:\r\n Microsoft TechNet - https://go.microsoft.com/fwlink/?LinkID=136332\n\r\nExamples:\r\n logman start perf_log\n logman update perf_log -si 10 -f csv -v mmddhhmm\n logman create counter perf_log -c \"\\Processor(_Total)\\% Processor Time\"\n logman create counter perf_log -c \"\\Processor(_Total)\\% Processor Time\" -max 10 -rf 01:00\n logman create trace trace_log -nb 16 256 -bs 64 -o c:\\logfile\n logman create alert new_alert -th \"\\Processor(_Total)\\% Processor Time>50\"\n logman create cfg cfg_log -reg \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\\\\"\n logman create cfg cfg_log -mgt \"root\\cimv2:SELECT * FROM Win32_OperatingSystem\"\n logman query providers\n logman query providers Microsoft-Windows-Diagnostics-Networking\n logman start process_trace -p Microsoft-Windows-Kernel-Process 0x10 win:Informational -ets\n logman start usermode_trace -p \"Service Control Manager Trace\" -ul -ets\n logman query usermode_trace -p \"Service Control Manager Trace\" -ul -ets\n logman stop usermode_trace -p \"Service Control Manager Trace\" -ul -ets\n logman start process_trace -p Microsoft-Windows-Kernel-Process -mode newfile -max 1 -o output%d.etl -ets\n logman start \"NT Kernel Logger\" -o log.etl -ets\n logman start \"NT Kernel Logger\" -p \"Windows Kernel Trace\" (process,thread) -ets\n", "runtime_modules": [ "C:\\Windows\\system32\\logman.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "logoff.exe-8D2514979820B970A4E4E7D5CF93DE28": { "file_name": "logoff.exe", "file_path": "C:\\Windows\\system32\\logoff.exe", "hash_md5": "8D2514979820B970A4E4E7D5CF93DE28", "hash_sha1": "04D171619689103D1E3C946A462E4D4BB5A765A6", "hash_sha256": "A8801F55523961A7DC8B38CBF48FBC1E46AE8E993E09153A240AC8F996C3A46F", "hash_sha384": "3199DDDAA55A88E0F7B84DA47F91B8912595D72CF0D06CAA1E3F11EDBAB03662E95F232288348501183DBA9FE01D3FBE", "hash_sha512": "9312835DA78C5BBBDA7AB1FE92AC2015047EF2450F2DDC94B1EBE96F1096963670C4A2F00E0C95165ED421520468081ED3842F50D49E4F931B0C0C82A7A58D4A", "hash_ssdeep": "384:43i4l2W1q3dkKm7E57ECz5z4FK8u2k49uEmqJrrXfWjMcZexKW3PuW:43JsCsdk7o5fSFK8nk4nmeiwxj", "hash_imp": "5DEE48EC7C50D677FA5BFE4D23399111", "hash_pesha1": "7F42CFC27035AA79B91C176764D5B46542A6D940", "hash_pe256": "8AD6546D85540C73A5E4E153FE5A61B73124893B7B524494E87E3D6E07F2C78C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Session Logoff Utility", "meta_original_filename": "logoff.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a8801f55523961a7dc8b38cbf48fbc1e46ae8e993e09153a240ac8f996c3a46f/detection/", "runtime_modules": [ "C:\\Windows\\system32\\logoff.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "error": "Invalid parameter(s)\r\nTerminates a session.\r\n\r\nLOGOFF [sessionname | sessionid] [/SERVER:servername] [/V] [/VM]\r\n\r\n sessionname The name of the session.\r\n sessionid The ID of the session.\r\n /SERVER:servername Specifies the Remote Desktop server containing the user\r\n session to log off (default is current).\r\n /V Displays information about the actions performed.\r\n /VM Logs off a session on server or within virtual machine. The unique ID of the session needs to be specified.\r\n\r\n" }, "LogonUI.exe-33F89DD9629CB0422A2C17268376232D": { "file_name": "LogonUI.exe", "file_path": "C:\\Windows\\system32\\LogonUI.exe", "hash_md5": "33F89DD9629CB0422A2C17268376232D", "hash_sha1": "E1AB36E5C3C1453C592E2901330EB13C5D29B351", "hash_sha256": "9358EF8CB7FB08581D74274005263BD8FA2E6E0FC443930B25FD345CF6CE9071", "hash_sha384": "9FF778D98AD2E947032CB357E64CB3D9BB00B969DEF284B72907B9001403EFDCC255A409D6AAFA48E652E7E544C702E8", "hash_sha512": "0FEE2E5626750AB6B15D82CD12F736790C4C703D02109D2704235186E3E85AAA22114D0E302626ABD960AECCCCFB03C11087668E8778D6523E4635400FB783F3", "hash_ssdeep": "192:i/1JmsaTvA/oN+wHKBCB0lJUKsRFdNEuZssvllWjUW:IKTvGq+eKB9JUFTZssvvWjUW", "hash_imp": "B9B0B64B08B38276711093CA94348D39", "hash_pesha1": "A2E16B65814BC4F7537E22EDC67ED47ABDBF7D5E", "hash_pe256": "935DEC6642A055C04A4149E9D26FE3F2FA6B82E5F8DE51B5125C6D798DC26F11", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Logon User Interface Host", "meta_original_filename": "logonui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/9358ef8cb7fb08581d74274005263bd8fa2e6e0fc443930b25fd345cf6ce9071/detection/" }, "lpkinstall.exe-D5B6D21D36D702292398E15A1C9444CE": { "file_name": "lpkinstall.exe", "file_path": "C:\\Windows\\system32\\lpkinstall.exe", "hash_md5": "D5B6D21D36D702292398E15A1C9444CE", "hash_sha1": "6DB084AA066E015EE8398081B7380FFBAC3EE06B", "hash_sha256": "AF29BA348E7181F42BFA9D69B829C1049D7F1FA30C6909475A6E0BB5A2A3AFDF", "hash_sha384": "926F1DEB27406FC91A599AEA203F84C5A77FF58D8D9E21889A5D61D9FF3B7C1C4CE8CA7FD6440AF9B7E1365636D2B636", "hash_sha512": "9464441AF094EC032E1B900B0EF4D8194D1202FEF24C6BD71AC33ED83165EAEDF2EB32848693D446F2FD20C06E1F72D23E67648F6CBF650A576B0F0AB09CF992", "hash_ssdeep": "1536:0XbuAH/44H164FZoCofv4k3+w94pQDTfdE:2S7Muzfv/3+jpc7u", "hash_imp": "09719FF5C856A6C28DC96E157B632D01", "hash_pesha1": "64BE370DB4B63ED71351C94E15868E05AEB9ED74", "hash_pe256": "A9363C408F76D43E1426BF3C6E81F72AB6E244852108F2263B5A8F22B8DAFD78", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Language Pack Installer", "meta_original_filename": "lpkinstall.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1457 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1457", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECA90": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\lpkinstall.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\wuapi.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\wups.dll" ] }, "lpksetup.exe-56CCA7441E152D0B0F7F2383521536A2": { "file_name": "lpksetup.exe", "file_path": "C:\\Windows\\system32\\lpksetup.exe", "hash_md5": "56CCA7441E152D0B0F7F2383521536A2", "hash_sha1": "C8177CFC5AB19FF7C0536FA6BC25C62D1F368C5F", "hash_sha256": "5A04255B366666CB669CA216E64C61463936363955D71CD86E6F04A3641B18C4", "hash_sha384": "9E403F7DC9F2A34AE581B77EE060135A72062BD6C2EEA3BFB2033A128BF99ABAAE79E661CC4EFBC25C5EB7DF66486F4B", "hash_sha512": "90FE7832070778A476176197EFC928181C58DBBEF7C809E68DC1D656D2CA6C654F53F7FFDC0FD7B64549ED5114B9256D6A353D15C1312BAFAC45F5BC6506F32D", "hash_ssdeep": "12288:00xnenkLxnnxd7aR/hnyA2zuw3gX7L/OVcrNStde1yfndmLh:3enkLBxd7abyA2Sw3gXX/OVENSu1emd", "hash_imp": "81A7F12B85647E066101CC62943AD9DF", "hash_pesha1": "100CCF286F18547F51FC6EF9F448402AFB1C3627", "hash_pe256": "4329C22C04AF84166ECC08EBD0A0FBEDC43FE6499A5D8ECBFBCE9D6DA323FF44", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Language Pack Installer", "meta_original_filename": "lpksetup.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/5a04255b366666cb669ca216e64c61463936363955d71cd86e6f04a3641b18c4/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\lpksetup.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\RotHintTable": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\RPC Control\\DSECEA0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\lpksetup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\dpx.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\comsvcs.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\CRYPTBASE.dll", "C:\\Windows\\system32\\lpksetupproxyserv.dll", "C:\\Windows\\System32\\CoreMessaging.dll" ] }, "lpremove.exe-C1C6A67FA093B4218E20D7339039F09C": { "file_name": "lpremove.exe", "file_path": "C:\\Windows\\system32\\lpremove.exe", "hash_md5": "C1C6A67FA093B4218E20D7339039F09C", "hash_sha1": "E61DB7A6870D895FDB5402B0F80BB9BEEFC6CEE8", "hash_sha256": "148B7B678FE8E74F8D92412B14EFF11496D7B1AB7B8A548B327594F806DF77AF", "hash_sha384": "9D38684523CCB4E0BC00F4D45350B3E34CA43B106B8E5D635D308880AFC56012208B0C84F8ABADE7574F5551CC457947", "hash_sha512": "CBF7E71C910D0C497AA06F9A6EB805FD5BC35CC958112742AE0C012439381B8CA64FABD8D25B6280E210111D06A195B64C4B18A81C5378FF5EA801E1615481A7", "hash_ssdeep": "768:q67S3bre0GmpYMzKxFPhdMc4hID8bcoICZDMYDfUbcTv43bLTCXDp6rm08:q67L0Gm2bBQECVZDfUb1bfCXDp6rm08", "hash_imp": "BC8B53A40E2042348C46E384FDE1F769", "hash_pesha1": "0E3D00DF24515ACF8815C775D7FB79C4F743EFF6", "hash_pe256": "DEFB2A32C8CA0D09CE82000124CA0C9B65B713E4CB621C800222F2A88B50A901", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MUI Language pack cleanup", "meta_original_filename": "lpremove.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/148b7b678fe8e74f8d92412b14eff11496d7b1ab7b8a548b327594f806df77af/detection/", "runtime_modules": [ "C:\\Windows\\system32\\lpremove.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\Bcp47Langs.dll", "C:\\Windows\\system32\\AppXDeploymentClient.dll", "C:\\Windows\\system32\\StateRepository.Core.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "LsaIso.exe-8B1A7347222A11C41F777A5782F3EEE1": { "file_name": "LsaIso.exe", "file_path": "C:\\Windows\\system32\\LsaIso.exe", "hash_md5": "8B1A7347222A11C41F777A5782F3EEE1", "hash_sha1": "5A9E5FFE14352CBEC1A1F70318866FC35756AF72", "hash_sha256": "D66ADB00F5EB0C5A08E7D844288D5ACDBB38294830D5370D0B1395171382C87F", "hash_sha384": "456AE3F7106ED0387ED7190BCDEFC543E3F80A7189EAAFBD73517C1A9481EA2CB77ACA465E8F6D14710BA22069EEE75B", "hash_sha512": "FF7FA268D4291A4F1E14D4884AE8297D190B1FC20F8754CEE009B67595EB9FE3312B3F5528898DD4B0C82B2CB44D4FBA09FF8527BE58CDE7BFBE82056EA3CA41", "hash_ssdeep": "6144:2dVV1+DhcBM2IvUqNvlTjw3PVscKS6ItXh:jd1XNv89jR", "hash_imp": "4DE439CBF6EAF63C94456970B7FE7CEB", "hash_pesha1": "0FE8742A12036E40E9FB141A9ED8267EA615B24D", "hash_pe256": "45166C7960B4415D00E3EC125BD6DCB09EE981159DA54C25B799838374DEC0BA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Guard & Key Guard", "meta_original_filename": "LsaIso.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1192 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1192", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/d66adb00f5eb0c5a08e7d844288d5acdbb38294830d5370d0b1395171382c87f/detection/" }, "lsass.exe-568C5CBF9877F6B9E39D1E7CA0FF0A36": { "file_name": "lsass.exe", "file_path": "C:\\Windows\\system32\\lsass.exe", "hash_md5": "568C5CBF9877F6B9E39D1E7CA0FF0A36", "hash_sha1": "0FB26350106C9BDD196D4E7D01EB30007663687C", "hash_sha256": "BBC83E4759D4B82BAD31E371AD679AA414C72273BF97CEE5AED8337ED8A4D79F", "hash_sha384": "BB32136FA03EAE48F4141076915659A6784CB1FABA071F29B9017751A5C31E82C8DE81B35B9875039872C98B4F01F416", "hash_sha512": "8F524F42B1639D8527899D67637D82232DDDE279364AAF3911C8F333DED813C42855B77A27CB959C92A14427DBC5E29246347E81C15A9AE283F99A95C2FE40BB", "hash_ssdeep": "768:fYxiGsg80u9X81GrNeLSfsXgOXrOpMkL3anMHy1PXg/:fEGg8xeGrNeLptrOykziMiPc", "hash_imp": "09FDE88C65E2BC5F1F90E96B673C52B1", "hash_pesha1": "0C862C52CFD7F91440C1DAC58360DB15C51D7BFF", "hash_pe256": "BD5901A617BE5B8E60260B8FCFA920C5879A686CED485ADFBF4E212A573EFE5F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Local Security Authority Process", "meta_original_filename": "lsass.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/bbc83e4759d4b82bad31e371ad679aa414c72273bf97cee5aed8337ed8a4d79f/detection/" }, "Magnify.exe-1B8EFE43AE616AEC6D19AFFC54183FA5": { "file_name": "Magnify.exe", "file_path": "C:\\Windows\\system32\\Magnify.exe", "hash_md5": "1B8EFE43AE616AEC6D19AFFC54183FA5", "hash_sha1": "51E6426C2CD901332F48913ABF281711F71E8FA1", "hash_sha256": "C4C643F6F8BBD577F3D108B8DFD14DD72DF32BF96A87C811F60D4240F7CA7306", "hash_sha384": "62C2151E01C32AFBD4C5865A24358F9182FCBBE5B5A4999AA614904E7E6D12561F6B1D2DB79F15F1515F9C910D435440", "hash_sha512": "6AF1129B4418F5DF1C738EE23757B20E4B714E4B19AB3D0C1CFFFB872729B631FDFA28B11B2E9360AEB44B89835853772F88CE81DD166295C7B3E88B33222151", "hash_ssdeep": "6144:gSbS7BH6ALCOX1VRJ1GdyGdTY/qbbVBDxra1xr4t9Mykz5gzNOx8XA08bAhMWUyJ:/bcBPnYdTYcfWGMtt8XOykpyk", "hash_imp": "89B08BB1E1A7820A0B6AF3CD06248264", "hash_pesha1": "FD26E8B60859D42F0F01495D99F28821F4F67E01", "hash_pe256": "817FF08BF1351C2A5BF48B68061AEBFE04DFB2844D1712F64B55B6349453EAD7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Screen Magnifier", "meta_original_filename": "ScreenMagnifier.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c4c643f6f8bbd577f3d108b8dfd14dd72df32bf96a87c811f60d4240f7ca7306/detection/" }, "makecab.exe-24B7CD3EB624B4D8A6091FF6CD626C7C": { "file_name": "makecab.exe", "file_path": "C:\\Windows\\system32\\makecab.exe", "hash_md5": "24B7CD3EB624B4D8A6091FF6CD626C7C", "hash_sha1": "A045F18C532966F7792524CB3EC3BE850DD07574", "hash_sha256": "F9EBAA95C93AA8CE217A4AD8715CCF2B7A3FC7A951DA44B78A9BB2C53B9BCACE", "hash_sha384": "EC149983E17B7A688CBB3E350C5E4F95A133DD4B3965385038FB56F10925A891E424043434ADEEE8FD994DFA829ECDD6", "hash_sha512": "AC0CB470AF147251644DE15E91B8138A61F4461967881F5F2FC15D19B9BFD0D3BCF06DB2E1B33DD8094200E53D543F7F5523CA4489B04697CA0C1A308646DC57", "hash_ssdeep": "1536:MCz/Ppo0HDGxuOevIJGA7wiMrLI6jbdHFmYPmKv3PYyMKT63EDel7Z0vfu:MCzH+aGxuOQIJGgjMrLTpHFHeG3PfFTa", "hash_imp": "A9326A6F3C34256D97D8CD7972ACC242", "hash_pesha1": "6F2B92EC6CFF318D76F8BF02F6F4615C0BDA9901", "hash_pe256": "D34F579AD2F966DE75647D094AF8100EF2F2E3FE36D0286924AA075FB6C81D94", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Cabinet Maker", "meta_original_filename": "makecab.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.00 (WinBuild.160101.0800)", "meta_product_version": "5.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/f9ebaa95c93aa8ce217a4ad8715ccf2b7a3fc7a951da44b78a9bb2c53b9bcace/detection/", "output": "Cabinet Maker - Lossless Data Compression Tool\r\n\r\nMAKECAB [/V[n]] [/D var=value ...] [/L dir] source [destination]\r\nMAKECAB [/V[n]] [/D var=value ...] /F directive_file [...]\r\n\r\n source File to compress.\r\n destination File name to give compressed file. If omitted, the\r\n last character of the source file name is replaced\r\n with an underscore (_) and used as the destination.\r\n /F directives A file with MakeCAB directives (may be repeated). Refer to\r\n Microsoft Cabinet SDK for information on directive_file.\r\n /D var=value Defines variable with specified value.\r\n /L dir Location to place destination (default is current directory).\r\n /V[n] Verbosity level (1..3).\r\n" }, "mavinject.exe-750E7456BAA3820527FFA4653EF5A516": { "file_name": "mavinject.exe", "file_path": "C:\\Windows\\system32\\mavinject.exe", "hash_md5": "750E7456BAA3820527FFA4653EF5A516", "hash_sha1": "5C075FF3AE849CF093341C96765C00D28657E15D", "hash_sha256": "BEF978F32A3E9582CDB86770509925CB9DDC797C7F6A2055AB2702C6D57302D9", "hash_sha384": "BD6317FE9DA276180A7750629A95F0BF31C03B749F556848F05FFE725E7E20331F298092E7D211434BDDC9B4A71116CD", "hash_sha512": "2B26EAEF5E64D7F31A64C693CEC83BE53BB84693F160E319C66BEC1E55C4F234A2CA357F8654563ED58F7BC84A4303D07A1D335D017A7645E8B774B65B4171E4", "hash_ssdeep": "1536:riYolfN/elJ5yb+UXgBzabn9r4PiW/cWafKYbkkbsFDfSIT0nJ2QC7pwAAZw1ltZ:riYo3/MdWgA54PifWGNU6ITLxb1LiyZ", "hash_imp": "96A5873241D90136570C05E55F0B5B2A", "hash_pesha1": "BB427119E0E2EF5B3B06666AA361BD370674E9F7", "hash_pe256": "985A3AE6188D452E5146F42E6B9A3E852A3AC299F8B7929A762FEC94F33663FB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Application Virtualization Injector", "meta_original_filename": "mavinject64.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "MbaeParserTask.exe-1AFD1BE73FA44061275270CB961C5D2B": { "file_name": "MbaeParserTask.exe", "file_path": "C:\\Windows\\system32\\MbaeParserTask.exe", "hash_md5": "1AFD1BE73FA44061275270CB961C5D2B", "hash_sha1": "F93D79AA7E0B12248E04021DA774EDBFCCEAA665", "hash_sha256": "D60BE154D0807E322F110A8CB51D25776B6D08547921283AE6E5CF7BC98E686F", "hash_sha384": "40388FCE3864FC7603A56971B9C493BB37FECA20340E57C7CA0D1DE97326AD1C5C79A285BD9D71CE5C9E24EB9ACCB291", "hash_sha512": "D8BC94584CA6DB4A0928DF5AAE838BE81399795269B8A41CD8ADE08A6375D70CAF3016152319F1CCAFB8FDE606D74A7B95F719A0E8F196B8AF31303E71CBE6B0", "hash_ssdeep": "1536:esJpCV55CdzgWPeYfHDGy6fMHpz155ChJRefXSqg7grneh9ZY/Nom:TnoszjP9jMU3OhJkfX/gkre7ZZm", "hash_imp": "CC74F226AEA5B9AA0008AA828712DF95", "hash_pesha1": "EA3B0B28521FDB657D8A5D0EFFF6D6AF79B1C3CE", "hash_pe256": "3B0D537FFE2529310AA208DAFB7B9D9DAAFDE520E787CA4E338CEDD2017F6DBC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Mobile Broadband Account Experience Parser Task", "meta_original_filename": "MbaeParserTask.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/d60be154d0807e322f110a8cb51d25776b6d08547921283ae6e5cf7bc98e686f/detection/", "runtime_modules": [ "C:\\Windows\\system32\\MbaeParserTask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mblctr.exe-BF6E710F30D7981EF0F90225D9C51001": { "file_name": "mblctr.exe", "file_path": "C:\\Windows\\system32\\mblctr.exe", "hash_md5": "BF6E710F30D7981EF0F90225D9C51001", "hash_sha1": "E36DF52A20CD4B504CB0525BCF3719B1528B7F3A", "hash_sha256": "B77B21A524249000737112909827CEFBBE582FD863DFF54612050AE69CB5A80C", "hash_sha384": "41979BCEDB6A3960DD17106DDA0B51A221BB0B49792AF5B4E02B3890E130008FEA1F64DDEF21BAF5AC05C9CE6439D88D", "hash_sha512": "182B15DEB9DAB9E313EBE50EB623613EE05B689087861521E1DCBAAF691675FAA33758C61F7177275AF057E56AEAB2E8FE9C2F96453F31245925EBAE096C0CD3", "hash_ssdeep": "12288:i1BpdCZ7rwYBoQRxVZDxG/L+N51qviizQBODAKylkm5ZUxXrc5Zh5ZG5Ze:i1YZfwaoQRhIL+N5kRzAKcjY8poA", "hash_imp": "0A9A6590A79FA4EE4A1D7AFB1A6982BA", "hash_pesha1": "051C4DD88991652ED4A54CA1AB725DED3B3CE22A", "hash_pe256": "3AA784E574BB61C97F16287B69D5D959B0752FD6C51A1905D1B605F6B23E143D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Mobility Center", "meta_original_filename": "MBLCTR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) Microsoft. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/b77b21a524249000737112909827cefbbe582fd863dff54612050ae69cb5a80c/detection/", "runtime_modules": [ "C:\\Windows\\system32\\mblctr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\BatMeter.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\system32\\WINMM.dll", "C:\\Windows\\system32\\WTSAPI32.dll", "C:\\Windows\\system32\\WINMMBASE.dll" ] }, "MBR2GPT.EXE-5ABBF63546215112B77BD3176231FED2": { "file_name": "MBR2GPT.EXE", "file_path": "C:\\Windows\\system32\\MBR2GPT.EXE", "hash_md5": "5ABBF63546215112B77BD3176231FED2", "hash_sha1": "A4FC9605276047280DEFE561E056AB01093FF257", "hash_sha256": "6C6452F2461D9F77D8AB9378C089F08F73481B3DB1E1E8E5911FAC3857CD0752", "hash_sha384": "3B34B549BD50E89C70268B50D181E11CC105352296ADED566D62E8E109536C3943739E711E2B5739C55D90918B8239DD", "hash_sha512": "B4535D144C1B12FE1B8850E48CC33AC206C027CBE469259E5EB49FEE9B7E774000DC56FF07FCE366A57E906C4044562E95552985FFD7BBC4132797C16D604380", "hash_ssdeep": "12288:+x6NcdicF9e4Yb1pLAqCwNUnilk8Hx+ppxlUyJ8GjTuFGSFLQVP7xvlzb:Qkcdez123wNgTB7Sle7xN", "hash_imp": "E3A65FE55A8ECE1517AA67B167383A33", "hash_pesha1": "7243688F30ADE97712CDD9F2B2AD8B8CD18B6556", "hash_pe256": "BBEC14BCF655711A50698F328A37CB20829C38D3546772A219DC1E438F389865", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nConverts a disk from MBR to GPT partitioning without modifying or deleting data on the disk.\r\n\r\nMBR2GPT.exe /validate|convert [/disk:<diskNumber>] [/logs:<logDirectory>] [/map:<source>=<destination>] [/allowFullOS]\r\n\r\nWhere:\r\n\r\n /validate\r\n - Validates that the selected disk can be converted\r\n without performing the actual conversion.\r\n\r\n /convert\r\n - Validates that the selected disk can be converted\r\n and performs the actual conversion.\r\n\r\n /disk:<diskNumber>\r\n - Specifies the disk number of the disk to be processed.\r\n If not specified, the system disk is processed.\r\n\r\n /logs:<logDirectory>\r\n - Specifies the directory for logging. By default logs\r\n are created in the %windir% directory.\r\n\r\n /map:<source>=<destination>\r\n - Specifies the GPT partition type to be used for a\r\n given MBR partition type not recognized by Windows.\r\n Multiple /map switches are allowed.\r\n\r\n /allowFullOS\r\n - Allows the tool to be used from the full Windows\r\n environment. By default, this tool can only be used\r\n from the Windows Preinstallation Environment.\r\n\r\n", "error": "Invalid argument: --help\r\n\r\nInvalid arguments\r\n\r\n" }, "mcbuilder.exe-7B786EF4D8FD478B2709D138672384B8": { "file_name": "mcbuilder.exe", "file_path": "C:\\Windows\\system32\\mcbuilder.exe", "hash_md5": "7B786EF4D8FD478B2709D138672384B8", "hash_sha1": "AD98CD2C7F51E8BC0CDFCBED42A426B61131CDC1", "hash_sha256": "41BBD3B038263161D5098891C98F0693AF4B7AE42A150E2B644012087D2414F7", "hash_sha384": "5B9E0C699A19ABB4C9950EB3608228F66EB5FAEC8D42F528D60B8B23AE49ECA59AFD70CA64A4541009A5051243D149C6", "hash_sha512": "118EF087867FAF9EE179CB10A4B0FEFEBA9A8799A595DCAFDE5A8554ECEB2489191B6EFB5D48F87C69BEC5FF1F1BC0D3AD98BE58F5A6D60766BE2C0E0961E93A", "hash_ssdeep": "1536:7gCtn7SKASvalkQQYp4w3XHp09B2ssW4d09dlh9uWCpqYBVs:7PtneKA6OkQQYp4w3XaBmMX9nCLBG", "hash_imp": "91CCEB10DE1061E3BF15D1523E5FB7F9", "hash_pesha1": "487B5FFF71C9C0FEEC482FB2A1A7BCEF62AE836B", "hash_pe256": "853D7C5EF4AF3B11B5B65C62BCED8B9B76EB2A97C43A676739A59790B00B338C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resource cache builder tool", "meta_original_filename": "mcbuilder.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.719 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.719", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/41bbd3b038263161d5098891c98f0693af4b7ae42a150e2b644012087d2414f7/detection/", "runtime_modules": [ "C:\\Windows\\system32\\mcbuilder.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\mrmcoreR.dll" ] }, "MDEServer.exe-0388A957D8CA227F4417D0BD7A4D2D3B": { "file_name": "MDEServer.exe", "file_path": "C:\\Windows\\system32\\MDEServer.exe", "hash_md5": "0388A957D8CA227F4417D0BD7A4D2D3B", "hash_sha1": "A1743D87B54211B732D799A1C52584CF2D6B2BC5", "hash_sha256": "41BB53BE1EE4C34CC75511F0E416F289D1E95A40864DC1AFEBE66A3DD77C8F9A", "hash_sha384": "7E5A56925C0DAC36021361374B7FF02EC3273B6358A48429143635264F4C8F98E0C47B51EA6F595B43BC811421B21792", "hash_sha512": "119A2E6FACE2A873AAFAFE28642EC66D137D5CC95B2C5BCF863E60E61C66646823ED5162A8926ABEDA6C25381A8D8BE1B1BC273FE301C46056ADFBDE39BD5FDE", "hash_ssdeep": "6144:NXL46ikZ/ASzzb9fOgvUJ28ZgCKLj5K9NJeG0yX2crpCo4Z:NXoRSz5OgvUYgg7H5KZXNrpCl", "hash_imp": "B5C649687D38753A958F69230A1E5C34", "hash_pesha1": "1B5A107F1E08804CB2DAD1B91280F9B3FD43E84D", "hash_pe256": "A9F330A630412FD247B603ADB07B0D83649AE3A156ED56C442C8644B3A8B58D2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Cast to Device Server", "meta_original_filename": "MDEServer.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/41bb53be1ee4c34cc75511f0e416f289d1e95a40864dc1afebe66a3dd77c8f9a/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MDEServer.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECCB0": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\MDEServer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\winmde.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\system32\\RTWorkQ.DLL", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\MFPlat.DLL", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "MDMAgent.exe-40A522C2F89681519468566933C5429A": { "file_name": "MDMAgent.exe", "file_path": "C:\\Windows\\system32\\MDMAgent.exe", "hash_md5": "40A522C2F89681519468566933C5429A", "hash_sha1": "CE67647BF6A5B6A8A7C3A420592DB17F18B47807", "hash_sha256": "489E36752E19E566410AEA869888033AA630D8BC433DDDF842DC4BED1CA18CC0", "hash_sha384": "B7A05C75B4BC3252FAC51E15F04ED055039AE6C4CD954BDAF547CD40EB974DCC990FCB056D94641F322FE6A17E51A6C5", "hash_sha512": "71B889E47E00090859D064D9A898E8F5ACD3A5BE28FA0CD52FF3DF82F20A2DFE42792FB74CED8CDA45C9F1A2FC8879AC762A669C720A658C6716D6DF258776A5", "hash_ssdeep": "3072:VzIFn3f23BLHwQCc1wnFsHW2HsnZjHiP6G38C:VzIR+51wFVMPrs", "hash_imp": "4E278F06A4DC1675FD6CF67F253DA848", "hash_pesha1": "117649A5C256AD771C07160EBEA75C2098F3CAC7", "hash_pe256": "7ADA999BD136734619C67428CFC3F0BD73A6B41D5F6D2567952A06DF0DE48761", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MDMAgent", "meta_original_filename": "MDMAgent", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.592 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.592", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/489e36752e19e566410aea869888033aa630d8bc433dddf842dc4bed1ca18cc0/detection/", "runtime_modules": [ "C:\\Windows\\system32\\MDMAgent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\dmEnrollEngine.DLL", "C:\\Windows\\system32\\iri.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\cfgmgr32.dll" ] }, "MDMAppInstaller.exe-E9D29FCBD87A6CE88529189046FA0604": { "file_name": "MDMAppInstaller.exe", "file_path": "C:\\Windows\\system32\\MDMAppInstaller.exe", "hash_md5": "E9D29FCBD87A6CE88529189046FA0604", "hash_sha1": "14265CA038F5610C8C969E214DFB9AE6252AF829", "hash_sha256": "DC8085816DD0FCD8FB2AB8DA264ED65CF264387EDEBFBB7221E80AA68F4785EE", "hash_sha384": "D2C2A905EDF26F0911C38C89251D7A0953A96EC871604F051949E0D0D5433899264D10CA91031B236BDFBA13ABDC14D2", "hash_sha512": "627EE6A9FF8490E56329EDC81BD0D95179FCA5941E0570A7DF8306E79ADB2816EB1D9C65FFCC99DA065EB2948AEC69F0081656D8ED5E8D9D5448CE533F5148EB", "hash_ssdeep": "3072:qV1LVnIRSJPPC4fbWc9V9pNhxe7VqqgNro:qV1l9JPq4f/bIqqgl", "hash_imp": "33078C956CE9BF4E8DA431AF7CFEFDCA", "hash_pesha1": "2A9352A8E74D392120EF306305D964692F8C39E5", "hash_pe256": "B11706EA7EC3EB29E933A89F99AD340E18A1A1E9E5F9F7A526CF793F39525828", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MDM App Installer", "meta_original_filename": "MDMAppInstaller.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1098 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1098", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/dc8085816dd0fcd8fb2ab8da264ed65cf264387edebfbb7221e80aa68f4785ee/detection/", "runtime_modules": [ "C:\\Windows\\system32\\MDMAppInstaller.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\system32\\dmEnrollEngine.DLL", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\WTSAPI32.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\iri.dll", "C:\\Windows\\system32\\msi.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\taskschd.dll", "C:\\Windows\\System32\\SspiCli.dll" ] }, "MdmDiagnosticsTool.exe-EF7505D7277092A7F2703CB8EEE9EA8A": { "file_name": "MdmDiagnosticsTool.exe", "file_path": "C:\\Windows\\system32\\MdmDiagnosticsTool.exe", "hash_md5": "EF7505D7277092A7F2703CB8EEE9EA8A", "hash_sha1": "D500207160D929D9D9D9B73828EB204EB825F7A0", "hash_sha256": "9B0A7EA1EE9C9BC427DCEEFC394361D74E7FB7A597A09439C3768CC689301D48", "hash_sha384": "1036236CA1F9E33297D0E530CAC1B60C1846FD7FDD8114228E3AECDB02F144A76960291FCFA60BD81A8411961779B71C", "hash_sha512": "3204E7883CB60E6D24F6663D4727A9DB784E0104CBB6447871984A33E7A1B306AD90C4E3ED715F3BBC900DB1A940E4ADE5C060D1502129411EC4712D91FBE15B", "hash_ssdeep": "1536:aA+3nEATZklqlsCmHlnry0R3BTcl+GdGnqcweYb:YHAy0RRYl+GdGqcxYb", "hash_imp": "C2629DC74DBE9DD271C4A59A43BF4896", "hash_pesha1": "48C991AFC350A4B753D54566D5BC61E846D1C9A5", "hash_pe256": "8773D8BCC4DBDE66FE0643EFE992F4998EF89E961AFDE5EB1612DFF3576EEA46", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MdmDiagnosticsTool", "meta_original_filename": "MdmDiagnosticsTool.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1282 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1282", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/64", "filescan_vtlink": "https://www.virustotal.com/gui/file/9b0a7ea1ee9c9bc427dceefc394361d74e7fb7a597a09439c3768cc689301d48/detection/", "output": "\r\n Usage1: C:\\Windows\\system32\\MdmDiagnosticsTool.exe -out <output folder path>\r\n * Output MDM diagnostics info only to given folder path specified in -out parameter.\r\n eg: C:\\Windows\\system32\\MdmDiagnosticsTool.exe -out c:\\temp\\outputfolder\r\n\r\n Usage2: C:\\Windows\\system32\\MdmDiagnosticsTool.exe -area <area name(s)> -cab <output cab file path>\r\n * Collect predefined area logs and create a log cab to given cab file.\r\n * Supported area name example:\r\n Autopilot\r\n DeviceProvisioning\r\n Tpm\r\n * It also supports multiple areas, separated by ';', example:\r\n Autopilot;DeviceEnrollment;Tpm\r\n * Please find all possible areas in registry under:\r\n HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\MdmDiagnostics\\Area\r\n eg: C:\\Windows\\system32\\MdmDiagnosticsTool.exe -area Autopilot;Tpm -cab c:\\temp\\AutopilotDiag.cab\r\n Usage3: C:\\Windows\\system32\\MdmDiagnosticsTool.exe -area <area name(s)> -zip <output zip file path>\r\n * Collect predefined area logs and create a log zip to given zip file. Areas supported are the same as Usage2 for creating cab\r\n Usage4: C:\\Windows\\system32\\MdmDiagnosticsTool.exe -xml <xml file of information to gather> -zip <output zip file path> -server <MDM Server to alert>\r\n * Collect information specified in the xml and create a log zip to given zip file. \r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\MdmDiagnosticsTool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\iri.dll" ] }, "MdRes.exe-D597D3941EB75B50F23A607FAD0FCB9E": { "file_name": "MdRes.exe", "file_path": "C:\\Windows\\system32\\MdRes.exe", "hash_md5": "D597D3941EB75B50F23A607FAD0FCB9E", "hash_sha1": "743DE50CE0EABFD731E3682AA497C472AF2E16D4", "hash_sha256": "D1A6FD804666268F55416B5AA0E0CD127738FEBC0EC62181E68E676DE4A028A9", "hash_sha384": "247B06AB81277CBF5826520A7AC2EB0980493ACC6A82C715A42F5B3F2FE60BF502262B01EBE88242AEA901E20040D842", "hash_sha512": "CF44B8AE9D530C630F8D52B558DB54EEFB944EF76F8E95894A92E8EF9711428E8BE53F990EE1D6DA23CC58C986EF6CF2C282DA9F4A9BFCF2E95DEBC90C145AF6", "hash_ssdeep": "1536:uQcD0sIm+65tFI720+VpmDOzc4JNWxwB1MjVJmRc:uQcDPIe/FO+VQDUcUNWs+jm6", "hash_imp": "3D553FEF2350214DF4679F35FF59A173", "hash_pesha1": "95235A37FE055268D2A5B48AD3F2A08BE9E324F0", "hash_pe256": "72FA6476687480F716C57F2F7BF5D8ECAD94BAC0EE216D8217F3E9C97677158B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Memory Diagnostic", "meta_original_filename": "MdRes.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/d1a6fd804666268f55416b5aa0e0cd127738febc0ec62181e68e676de4a028a9/detection/", "runtime_modules": [ "C:\\Windows\\system32\\MdRes.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll" ] }, "MdSched.exe-26F5DBA1FB3B8E477BF3941879B23E59": { "file_name": "MdSched.exe", "file_path": "C:\\Windows\\system32\\MdSched.exe", "hash_md5": "26F5DBA1FB3B8E477BF3941879B23E59", "hash_sha1": "B16FE1174F84B5B04A865C0E1200EFC486DF7D0F", "hash_sha256": "BC516F17AFC7658C4F20726272D9CE9F77C83DD5575307B15DBBDECA6F04D273", "hash_sha384": "9C75D86AE8730BC3E5E272D0B622C6C0F20870DBFAD69CA715338DB14C2067C6370316F2DF6CFEE8C816522B2B0D4E55", "hash_sha512": "ECB85B5435A2D35478857C269F9A61244CB3A0105AEB782201CE79B305D85B68A29B09A05C5070AF02951C0DE69A5618967DE7DDF674271F988B340ABE448CDC", "hash_ssdeep": "1536:yt3ItM+oMQwH9m+65tFI720+VpmDOzc4JNWxwB1MjVJmRc:yytMbEH9e/FO+VQDUcUNWs+jm6", "hash_imp": "AAA5D23775A803F6978426A3C7A1F259", "hash_pesha1": "416E7DA0726A156FC5CA692883921D8FF773D45C", "hash_pe256": "7D8BFC7023A31DB8460C438075325E87221FF25BF4A4EB32C2EA090353DE97C7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Memory Diagnostics Tool", "meta_original_filename": "MdSched.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/bc516f17afc7658c4f20726272d9ce9f77c83dd5575307b15dbbdeca6f04d273/detection/" }, "mfpmp.exe-6DD50C00234841A2005A22E8486FAB63": { "file_name": "mfpmp.exe", "file_path": "C:\\Windows\\system32\\mfpmp.exe", "hash_md5": "6DD50C00234841A2005A22E8486FAB63", "hash_sha1": "857EB88AE4A34F5F08EF9E608D6058C4AC0E2F28", "hash_sha256": "444BBAC8386B3895ED92400B77C4E8A933A9F4E76CC7633CEBA89DA539A1EC09", "hash_sha384": "174A1FF2173C5EAB808754E0549B19E68A5136A925F56423A994F5A09E635CA2981095852A9F6405AE3B2955E06A5DF0", "hash_sha512": "222406BA888A09CD2D330AFA56FF54C768A28208E24F5B0996FA5CA6AD0C625A9E084CC38532027ED035A4DB9CD06C8370CB9EB585CF0F26EA1A8598294541CA", "hash_ssdeep": "768:3v/5aH6gxvJv/CUEbp73TG6t0cbxRz1kEAO2LxqObXj1PfRI:ZPgBJ3GF7DGe0OxRz2EAnxq2pPZI", "hash_imp": "7AC270787865AB99D9D94F85C379C3CB", "hash_pesha1": "61A10C176ED8EDB8CC1969899E9111D84818AA6E", "hash_pe256": "5F68ECB1036F01DC4D33CA77093D7C2662C6C3045B97C8049F24B078F314B26E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Media Foundation Protected Pipeline EXE", "meta_original_filename": "mf.dll.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/444bbac8386b3895ed92400b77c4e8a933a9f4e76cc7633ceba89da539a1ec09/detection/", "runtime_modules": [ "C:\\Windows\\system32\\mfpmp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\MFPlat.DLL", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\MFCORE.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\ksuser.dll", "C:\\Windows\\system32\\CRYPTBASE.DLL" ] }, "Microsoft.Uev.CscUnpinTool.exe-A621473D0984AC88C1B04B7254A1AE18": { "file_name": "Microsoft.Uev.CscUnpinTool.exe", "file_path": "C:\\Windows\\system32\\Microsoft.Uev.CscUnpinTool.exe", "hash_md5": "A621473D0984AC88C1B04B7254A1AE18", "hash_sha1": "6472E36B7AA459DFB3D04F3C51B39FA8E821DB68", "hash_sha256": "0AA862A9D84ABF0EE2E69AECE938B93F45587D3FA133086A21B7CC3120602F6F", "hash_sha384": "07B73DA7DD701F7D659C6679366B4E4A800B6FBE6A6295A83EB466E090F7E8BF877BB9C751AD7591FD40BBBAFEE63B30", "hash_sha512": "DC2865BCEAB04152A71F68A2EBE34100D881FDEE5869520DF4C3C24EA0D084D7B1658E4E15DE6AF67893B56FCFBFDAB37730D355071ED15520C3D62873B151A8", "hash_ssdeep": "6144:cxbk1lTidFaSEy3cRaZv5zBMxLCiGeV7HJ4oPa9S:6b0yFNcRa51axmMzQS", "hash_imp": "46810FCA14A4C2E6B87EAD9212D4A482", "hash_pesha1": "EC08F8EF3FFBBDCC267A674AB0D6395412D7F936", "hash_pe256": "4F1781E3C742F4671C773DA77721ECFD8FA08B84B48FF929AD1218FD2BBF56E2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft.Uev.CscUnpinTool EXE", "meta_original_filename": "Microsoft.Uev.CscUnpinTool.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.719 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.719", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/0aa862a9d84abf0ee2e69aece938b93f45587d3fa133086a21b7cc3120602f6f/detection/" }, "Microsoft.Uev.SyncController.exe-A15E06A45812CDE8B959C1BC0F64A619": { "file_name": "Microsoft.Uev.SyncController.exe", "file_path": "C:\\Windows\\system32\\Microsoft.Uev.SyncController.exe", "hash_md5": "A15E06A45812CDE8B959C1BC0F64A619", "hash_sha1": "80053EBC91A7EF419C4A00AD5E568BAC9B5D3F0F", "hash_sha256": "E45DA137BA831E3FA0EA5A5B016742D1D64054702A553917CC87DD9ADD83FCFE", "hash_sha384": "5BDDD418617C900017C31857F100A3AE1B31C23FC870820E1B4302757CB4453DBDAB491E1A9057BDCB643A1C07826A1A", "hash_sha512": "0C932C06A2BBFA9E617DE21A7ABC8346CB67E4E9073D0490E0F678AB4E0C8C6EE5A3F64EEC98FB3FE770FA653B2A4FA3E5967558E3A9395698E0BFD218043709", "hash_ssdeep": "1536:ChCtaUCKV/Qt1d1sTNe+6NwiKE10DHlB:RCKV/Qt1d1sTNGBl10r", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "C4B8A9A078D26F178DBE32DC7E7922D6D10C5F68", "hash_pe256": "DE0CA3680374C762EF92C4D69EA28B8FBEF3647D2C2F56AB362E99AE6E7A90AB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "Microsoft.Uev.SyncController.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1", "meta_product_version": "10.0.17763.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/e45da137ba831e3fa0ea5a5b016742d1d64054702a553917cc87dd9add83fcfe/detection/", "runtime_modules": [ "C:\\Windows\\system32\\Microsoft.Uev.SyncController.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\5543cca0df435801e2303ff46a482ed5\\mscorlib.ni.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll" ] }, "MicrosoftEdgeCP.exe-3FAE70080E7D900A469355C85ADACBDB": { "file_name": "MicrosoftEdgeCP.exe", "file_path": "C:\\Windows\\system32\\MicrosoftEdgeCP.exe", "hash_md5": "3FAE70080E7D900A469355C85ADACBDB", "hash_sha1": "DEA5960571532F73D886F5DD79B0F7EED6F10582", "hash_sha256": "34B6D32D2345DB5DFE803573F4AA74479EA961004B2F72D25A486D55369AECD8", "hash_sha384": "A0AC924BDB2BC8B264BE59D9A3C29B7A511D0BB1A603319215849FDFC589F8A61A19248E3256A0CBC2EFD913A67B2E01", "hash_sha512": "C8909FAD5F3FCEAB7A825C30B033844645E49F171C285A560CF8E0DFD0D848356B8E2CC0DF8019E42B1EFE69623B715BF3237D7DD42D3EC63A462D2682711ABD", "hash_ssdeep": "1536:zermIcat/7LnbR8l/DNRo04HwnVC8AknP8RsK:zeryK3V8l/804oV3TP8Rs", "hash_imp": "0D3AB4A466B72F3ECB4D7E053A19134B", "hash_pesha1": "DA7999586252647430728A1B6E2F7027596B0256", "hash_pe256": "DD31F49F1D8F63BC55BAFF847A74D28C6D0408298B0E211B48CA5AE03E36F7B4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Edge Content Process", "meta_original_filename": "MicrosoftEdgeCP.exe", "meta_product_name": "Microsoft Edge Web Platform", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/34b6d32d2345db5dfe803573f4aa74479ea961004b2f72d25a486d55369aecd8/detection/", "runtime_modules": [ "C:\\Windows\\system32\\MicrosoftEdgeCP.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll" ] }, "MicrosoftEdgeSH.exe-2785CEE75163F3C8755BE16BDBA68155": { "file_name": "MicrosoftEdgeSH.exe", "file_path": "C:\\Windows\\system32\\MicrosoftEdgeSH.exe", "hash_md5": "2785CEE75163F3C8755BE16BDBA68155", "hash_sha1": "CE41DC5BBDDE4F779C2CCFFB119FEFAFDFCAF01D", "hash_sha256": "D7A4F824B02C13DAACA06815F1D579612B24D6B0FC4138317FC23D2AA7E24025", "hash_sha384": "D8780F65B5672BC4CC496C40F03CC5B8A3A4AACF8BAE509CFDF1E79AB6F4E441B81B47BA1C986899AE6B9D85A3A9A7DA", "hash_sha512": "85C126DC5C38E9354035E32FADDBBA11778FBE8EC47B6F7A108BAD35D7762A0B01C4B17CB1184F8C449F8E1138D1A97D6C7EC75030E6DF1B707F428D81741CB2", "hash_ssdeep": "768:FZymeD5NFlGX3MAtrpgBD+YGiYH3j5cTnYSu9aeqb1+ync+:FZm5NFlGX3ZtrpgClNtSuHq5+ync+", "hash_imp": "A34FE6D82B7B3A5185FB8B7B2D288801", "hash_pesha1": "A16BE3B8BFDA60477E3757896886848995F04890", "hash_pe256": "7E34D92FF0D975A33563B5F3E0D5AD4EB57866E5DBF73C8A94D98EEF6A5FF1FF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Edge Web Platform", "meta_original_filename": "MicrosoftEdgeSH.exe", "meta_product_name": "Microsoft Edge Web Platform", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/d7a4f824b02c13daaca06815f1d579612b24d6b0fc4138317fc23d2aa7e24025/detection/", "runtime_modules": [ "C:\\Windows\\system32\\MicrosoftEdgeSH.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\edgeIso.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\SYSTEM32\\profext.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll" ] }, "mmc.exe-9317AC7FF7ED5E614E17E49D1EB474CB": { "file_name": "mmc.exe", "file_path": "C:\\Windows\\system32\\mmc.exe", "hash_md5": "9317AC7FF7ED5E614E17E49D1EB474CB", "hash_sha1": "5A819AF29BA9567E701BA0F1D60B7269A4125AF6", "hash_sha256": "B82E5D5E2EEBE6EE0AFD1C233148BF5A46DC83A7358FEB86C83E46A388D23B13", "hash_sha384": "AB9C6CB001538BDD48D8C352B5DB7567B146D337929B4DB59057F7E837EB3A1D9F88C4EA8B79918C415B3C9B0257947C", "hash_sha512": "D88B56A8E57B28FAA2735B10340BDFAABE849BA3200AD3FBF92385A30BBCBE07A639F1E73318D322A57BE95622E058B3FB1F09FCE524EC639F95F7AE0705EF93", "hash_ssdeep": "24576:sd4qiadffSbED3FULzf+WbnIVqiSdrvMo7wMo7DHO:sOQdffPD3FYfTbYqiSdr77e7DHO", "hash_imp": "B8EE2D6252332A68B70B22E3D6E377D2", "hash_pesha1": "EBC3A0429E5B44BDDCB4EADAD12F78AACCD759C5", "hash_pe256": "7DCA8CDC524AF33333145710A984D183BB36A12C82E976E2DD20B96E698CA9DF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Management Console", "meta_original_filename": "mmc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/b82e5d5e2eebe6ee0afd1c233148bf5a46dc83a7358feb86c83e46a388d23b13/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\mmc.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\mmcbase.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\RPC Control\\DSEC10C8": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326": "File", "\\Sessions\\2\\BaseNamedObjects\\10c8HWNDInterface:a02e6": "Section", "\\Sessions\\2\\BaseNamedObjects\\10c8HWNDInterface:802fa": "Section", "(R-D) C:\\Windows\\System32\\en-US\\mmcndmgr.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\mmc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\SYSTEM32\\AcGenral.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\SYSTEM32\\MPR.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\mmcbase.DLL", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\SYSTEM32\\ninput.dll" ], "runtime_window_title": "Console1 - [Console Root]" }, "mmgaserver.exe-BE31DA117588C57A0E889C1C12702066": { "file_name": "mmgaserver.exe", "file_path": "C:\\Windows\\system32\\mmgaserver.exe", "hash_md5": "BE31DA117588C57A0E889C1C12702066", "hash_sha1": "A6F55AA21A8DE8C71A60B33A91189BDD2F2BE745", "hash_sha256": "4F0F1006BF048614F71803778E1ECA54F737C10F61A6CAF3732865EDDC9C09A7", "hash_sha384": "13ECD5B6BC71E3DE8CC3B7845FEE4357F244FC6A7EAE764012A758175A1964EB16A621EBDCDB0267F8B4723B1DCF25C0", "hash_sha512": "837B55113768507CFCB05B9102DFCEEC38C2EB493D549F87EC02409E99C4A6B03B8222AE795A2EDF5C5CFC37CEF13E6C45B5691ADB246B22DD5B197E7F6ED280", "hash_ssdeep": "12288:0+zSb/Qc5Du8rw3fKQHJcqv03qAO99eFAULcCHKv:D2/QcFu8rw3fcAgqAA9u3Fqv", "hash_imp": "8EBE27F0E956AA23162D303E1B1C97D4", "hash_pesha1": "23025643AE538F8ED75A0FC9243BE854E9BE5313", "hash_pe256": "42868E579293F2F70CF61A5280372F4BA9A235F5E2029E4BE69994288BEB03B4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MMGA Server", "meta_original_filename": "mmgaserver.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/4f0f1006bf048614f71803778e1eca54f737c10f61a6caf3732865eddc9c09a7/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1024": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\mmgaserver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ] }, "mobsync.exe-0E04F05DCC0CC91D8AF043AD0D267F0F": { "file_name": "mobsync.exe", "file_path": "C:\\Windows\\system32\\mobsync.exe", "hash_md5": "0E04F05DCC0CC91D8AF043AD0D267F0F", "hash_sha1": "DD9146CFE11FBD59E85005BC0AE31F6F256D32EC", "hash_sha256": "61248F04A068B1FF16C3609E1454B8E787DD40BFF57CC46F4FC18DB40FFB8028", "hash_sha384": "B3C41D4E2129E1883363FF8C0CE123C1B80CD3675ACFCA6F19A2F3D7072FDA959A54BBB6633D51C9B6CA332947038542", "hash_sha512": "1BC860DE418F8D93F745FA53F87CD7CB6AAB87758975EFB3A5350558A718E7365832C4229B706FD8962D3E04DC710D89D7F1E260DEE57ADD0923435FC602258D", "hash_ssdeep": "1536:RTNBdfclkhu40ZiG6pGPoCGVjGWmt8CXZ+63x+w4JD+0NL+fK:RpwC4iZpGPo9St8WHxSD+09+S", "hash_imp": "F247D587E13B170D2246BD033539DBFB", "hash_pesha1": "BB950D46B1047428F68545F654FEE763DD278FB5", "hash_pe256": "BB8615E329396ECE9443996F3490BD4C463673BE854FD70049E54FF412F1E066", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Sync Center", "meta_original_filename": "mobsync.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/61248f04a068b1ff16c3609e1454b8e787dd40bff57cc46f4fc18db40ffb8028/detection/", "runtime_modules": [ "C:\\Windows\\system32\\mobsync.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\ActXPrxy.dll" ] }, "mountvol.exe-7FDBD108C947065E1CDD7A94C08E7B67": { "file_name": "mountvol.exe", "file_path": "C:\\Windows\\system32\\mountvol.exe", "hash_md5": "7FDBD108C947065E1CDD7A94C08E7B67", "hash_sha1": "79F4D3E65ABC3C7345FD3263DE9F837A6D83A558", "hash_sha256": "0B6BBFD83C4A34DF78289470FF338E93F5A769317015043A121349A7836D8862", "hash_sha384": "5C7F8E6334E94D3DE95C77764BE96A9C7B1E21728A882C0C11F13E0336694208EB08D56CE4AEF3077E5259DBF69B6383", "hash_sha512": "281B0EB721B914356E8B1EEDF3C5012FC57B6CAC783A767ED17E61709D4E47791BD76A92CD87FB23D9091DDC6914D84A11D97845142CC8FB5559A9EABBD1C2BB", "hash_ssdeep": "384:SUWTPFjINDIAUlJhiNljlyGVEnW/3Rl1laIxNves8WQFW:SUWTPADElenJUWvRl1TNvesm", "hash_imp": "97872558B429C0A84C0AE62A365088F3", "hash_pesha1": "39EF4249C30E87AC2A8234D19F2859407E05741F", "hash_pe256": "6DAC1439A33AA6AD667AB1687E5FEA0557B374507EA76A8228BF3DE833033C42", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Mount Volume Utility", "meta_original_filename": "MOUNTVOL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/0b6bbfd83c4a34df78289470ff338e93f5a769317015043a121349a7836d8862/detection/", "output": "Creates, deletes, or lists a volume mount point.\r\n\r\nMOUNTVOL [drive:]path VolumeName\r\nMOUNTVOL [drive:]path /D\r\nMOUNTVOL [drive:]path /L\r\nMOUNTVOL [drive:]path /P\r\nMOUNTVOL /R\r\nMOUNTVOL /N\r\nMOUNTVOL /E\r\n\r\n path Specifies the existing NTFS directory where the mount\r\n point will reside.\r\n VolumeName Specifies the volume name that is the target of the mount\r\n point.\r\n /D Removes the volume mount point from the specified directory.\r\n /L Lists the mounted volume name for the specified directory.\r\n /P Removes the volume mount point from the specified directory,\r\n dismounts the volume, and makes the volume not mountable.\r\n You can make the volume mountable again by creating a volume\r\n mount point.\r\n /R Removes volume mount point directories and registry settings\r\n for volumes that are no longer in the system.\r\n /N Disables automatic mounting of new volumes.\r\n /E Re-enables automatic mounting of new volumes.\r\n\r\nPossible values for VolumeName along with current mount points are:\r\n\r\n \\\\?\\Volume{7c775138-0000-0000-0000-100000000000}\\\r\n C:\\\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\mountvol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "mpnotify.exe-EC713E42A58FCC6F32A8AF42601A6943": { "file_name": "mpnotify.exe", "file_path": "C:\\Windows\\system32\\mpnotify.exe", "hash_md5": "EC713E42A58FCC6F32A8AF42601A6943", "hash_sha1": "0D6AFD1BF684F4DD4BC823C3489EA12EFB0DFB28", "hash_sha256": "909BD459E937642E17C188C998FE0A6E228C4E48CDF8F0645168D4F09A97DAC2", "hash_sha384": "416E0469F25F3EE2008D9C9883E8E4A34F1B83D7BF6EB3C971E7A416D420402503B419CF957BB45B8E4E07F594F1DD46", "hash_sha512": "1C3DBC3985231D22E74019A7B1CBDC586EA1723BFCC0FD19B80BAE3C1BE5CD0E714AFF8FDD891AF63E5B50B6D05DC48129CFA651CE62AFF887990FFDEC1724EE", "hash_ssdeep": "384:q1nTPEzAbWLzC6qOA4yziiWdYD0MZLqTWAjW:2nT8kbW2Lz+ZMZG/", "hash_imp": "CD22AC47106D5026EA3B26DED33E58CD", "hash_pesha1": "A75231085B02F577C365EA1B17CCFD7C9EC57E12", "hash_pe256": "EB332C8067DB9C7110A4E55D4F7A7E5D6F1E03CF6EFB68388A50DC546BA204BA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows NT Multiple Provider Notification Application", "meta_original_filename": "mpnotify.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/909bd459e937642e17c188c998fe0a6e228c4e48cdf8f0645168d4f09a97dac2/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\RPC Control\\DSECB00": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\mpnotify.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ] }, "MpSigStub.exe-89614F78EABF194EF6586F7807B6A1BC": { "file_name": "MpSigStub.exe", "file_path": "C:\\Windows\\system32\\MpSigStub.exe", "hash_md5": "89614F78EABF194EF6586F7807B6A1BC", "hash_sha1": "2F4FC0C4E204F2A430D0BFB9D9BB166C42F5D767", "hash_sha256": "D0772BFB0687E068D4D21749C90DBAC7FB7F71F74F3A8CAF6D69CAC483A1C17F", "hash_sha384": "9753C9D305AF70256801AECD2F4A32E059E0988E8B565C6F63D46B6CD15B1ED98490736958167405CB716A82042C8B73", "hash_sha512": "F430E40714A7CF74141792BF1E2E364D100ADF6B44324BCBD1FF3826BBBE86FFFA1A301CE5436771A61A761083A0AC2DBF617685195A1F662E50DFD9B8E91DDC", "hash_ssdeep": "12288:1ukxwlT4Opldy3LDSaapZKt+t5lqvbWR0bwpAUUFNECeNPF/z:ckx48OplQ3LDqpZKt+t7gb2tIDECelFr", "hash_imp": "9EC6E03165E3120AE00585DA50B9B538", "hash_pesha1": "3561565AD66948B2B96693646FB36F0CD50AF42F", "hash_pe256": "784929591FD299E7F4979C40873065C0547D6EE597F69D23A898523085B61794", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002C2813CEF6A1E0924010000000002C2", "signature_thumbprint": "019B59FACD194B9FB72232CD7F1FF21A2CE8C5A4", "signature_issuer": "CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Malware Protection Signature Update Stub", "meta_original_filename": "MpSigStub.exe", "meta_product_name": "Microsoft Malware Protection", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.1.16900.5 (f6fe444569f9663015a6e1992ed19388cf741704)", "meta_product_version": "1.1.16900.5", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/d0772bfb0687e068d4d21749c90dbac7fb7f71f74f3a8caf6d69cac483a1c17f/detection/", "runtime_modules": [ "C:\\Windows\\system32\\MpSigStub.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\version.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ] }, "MRINFO.EXE-E770C27BF6BF43B7F9796511CF6361F2": { "file_name": "MRINFO.EXE", "file_path": "C:\\Windows\\system32\\MRINFO.EXE", "hash_md5": "E770C27BF6BF43B7F9796511CF6361F2", "hash_sha1": "21CA4B8CC54479095E817ED8B8355454011F70AF", "hash_sha256": "20BB1370F14AD18C0AD78BD2C16FAE467CA9912F31EE77352C87BC5CBAD38206", "hash_sha384": "333CB3D21C62AF132C10ECF22E74F8B1AE055F649EE88CCE4BC296312D2A69D7974F19EB6145785F96DD588CCA24A4C6", "hash_sha512": "3E386BC86C6C5A41AB92BF26DAD288EABD40E3AA343AF65BA281E9BB9EB3FF576D6A9C2CCDFCE08330D8D6EF7E6223686B4A86E6C483A95CDD66DD6A895989F4", "hash_ssdeep": "384:YBezrKfXxCcqJKYAfGPiUl13MfyPiK0WJ8W:YEsX8gNful13Mf5Kb", "hash_imp": "293E4CA0CECE9CF71F0DB8AA9DCA02F6", "hash_pesha1": "430F64F08B0D695918E85801672AC6E58CD4CC41", "hash_pe256": "20122AFF5D6A3DE5DE04C252C1D45EA15B20653F2B52CD9EDE59CC8FADAAC0B5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Multicast Information", "meta_original_filename": "mrinfo.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/20bb1370f14ad18c0ad78bd2c16fae467ca9912f31ee77352c87bc5cbad38206/detection/", "output": "\r\nUsage: mrinfo [-n?] [-i address] [-t secs] [-r retries] destination\r\n \r\n -n Display IP addresses in numeric format\r\n -i address Address of local interface to send query out\r\n -t seconds Timeout in seconds for IGMP queries (default = 3 seconds) \r\n -r retries Number of extra times to send the SNMP queries (default = 0) \r\n -? Print Usage\r\n destination Address or name of destination\r\n\r\n", "children": [ "csrss.exe", "winlogon.exe", "conhost.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\MRINFO.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\mswsock.dll", "C:\\Windows\\SYSTEM32\\DNSAPI.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL" ] }, "MRT.exe-66CFF638C4886C3ADFD7F4A8C4E5305C": { "file_name": "MRT.exe", "file_path": "C:\\Windows\\system32\\MRT.exe", "hash_md5": "66CFF638C4886C3ADFD7F4A8C4E5305C", "hash_sha1": "7590E18B8BD55B77326797D2DBBF57E992FECEFC", "hash_sha256": "A96F8928BEC28857706E01FFFD043DD88D863B23105937F8A83D763025254684", "hash_sha384": "A9C46FE6D8A8BBACFDCC0C223CC36A6BEF50DBDCBD2F561164D87A7087F3950C3BDDACE52DAC8F314D8E635D7EF0B549", "hash_sha512": "7CD46208E4519EDC30E1411B37AD1ED3008BD8AE9549CEFC09A287BA10A4EFC9F40C27E8735901B791CA91A5E5E8B24EFE06123EF56E145B5AC8E349E2D4151D", "hash_ssdeep": "3145728:1Su+FSpLoVlpM/6/w/65xV/jE5xf5xd5xX/h5x55xN5xg5xA5x85xK5xA5xkItJg:UFd3iItJPo", "hash_imp": "B280AA6D77CEF1859E15BCD2A3D67751", "hash_pesha1": "1564C2F08C3F7DB0A48BC2B8398D918F83A9CEDC", "hash_pe256": "0B11FDF901039EB4CAC508CC4DF4CC7E8CE187F78CC925735C0BDE47ECB82A13", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000002689ACC74C3B73DBA47000000000268", "signature_thumbprint": "26E1ECEDA18F82CCE5EE18F25C98F1AC9C02DA16", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Malicious Software Removal Tool", "meta_original_filename": "mrt.exe", "meta_product_name": "Microsoft Windows Malicious Software Removal Tool", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.83.17439.1", "meta_product_version": "5.83.17439.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/a96f8928bec28857706e01fffd043dd88d863b23105937f8a83d763025254684/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\MRT.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\version.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\system32\\WindowsCodecs.dll" ], "runtime_window_title": "Malicious Software Removal Tool" }, "MSchedExe.exe-4D08AB6F00FCD7273568C7D3F8429BC3": { "file_name": "MSchedExe.exe", "file_path": "C:\\Windows\\system32\\MSchedExe.exe", "hash_md5": "4D08AB6F00FCD7273568C7D3F8429BC3", "hash_sha1": "F3C95AAFF5A84A786D5133775828E075C049098E", "hash_sha256": "2E248EA87C79D1142C6B03D4CD296B610BAE6A88E9F72D2BA1BF646A67A05A0B", "hash_sha384": "AB28F6CD535CC69B4E7446DA7B6C05BB961A2688FC216913B27359EDCDE99AD4087CA0414A80FEF2257D05BCEE3F754C", "hash_sha512": "55AB386922185F83815E3F53B0637BFC46FABDB4AFF04D3EDDDD8AAD1F1A1198476F343BCA04AF060A730CA85D6AC9C48E5F12EF38A3A7CDB42289E359A8A990", "hash_ssdeep": "1536:yRtREC/rMcgEPJV+G57ThjEC0kzJP+V5JO:gzECTMpuDhjRVJG4", "hash_imp": "9BB805D1418F5443C74B46538E23AA97", "hash_pesha1": "04BBA9413370D641D265D42201AF0BC80A5EDE89", "hash_pe256": "C7C25C49E608735A380B6D7D4FE37ABF7CFEF8039D69CBBC3EE9AF50D1367E57", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Automatic Maintenance", "meta_original_filename": "MSchedExe.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/2e248ea87c79d1142c6b03d4cd296b610bae6a88e9f72d2ba1bf646a67a05a0b/detection/", "runtime_modules": [ "C:\\Windows\\system32\\MSchedExe.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "msconfig.exe-FA81544250A477790C003D6D88256078": { "file_name": "msconfig.exe", "file_path": "C:\\Windows\\system32\\msconfig.exe", "hash_md5": "FA81544250A477790C003D6D88256078", "hash_sha1": "E5BA6703A3F6DA5C6B80A890CD78A9F909F3A9C3", "hash_sha256": "2782A7F6336DAF4CC25A88995456678F02AFE0F01C86D24EF75CF54996710A75", "hash_sha384": "AEA25702129EB5012FC4B08818369A23F27EBFC24AD79DED31D96F7D696511FAB0AA9544BB3369A27A103CC1B19921A8", "hash_sha512": "E06475AE7C045E265BBA0FE3938D4DDEB43A2B4541BCFBF78243BC5BD389FEBAB3EB225C1BAEBC57D80BF9CE558C823360A96B50B687B70D54051B4C83B55E6F", "hash_ssdeep": "3072:hqEa1DAvAaBSChjo4nZYRywPeChrL5fUd0/HlGJRA18:3eAjj9nO9mCFJUdSGJRW", "hash_imp": "1100993220365A868FFB68CDD3511FBE", "hash_pesha1": "D804BB7803E5E46567941C8AFAE7337ECED0702F", "hash_pe256": "82E71DC0857EC7044B9562F2BE623CD995C86F6303A70EF0D9019254EBD010AA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Configuration Utility", "meta_original_filename": "msconfig.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/2782a7f6336daf4cc25a88995456678f02afe0f01c86d24ef75cf54996710a75/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\msconfig.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\msconfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\system32\\ATL.DLL", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll" ], "runtime_window_title": "System Configuration" }, "msdt.exe-728A1A72370AF1A7641650FD43DB7DBE": { "file_name": "msdt.exe", "file_path": "C:\\Windows\\system32\\msdt.exe", "hash_md5": "728A1A72370AF1A7641650FD43DB7DBE", "hash_sha1": "12609AF89C97A98668B2C93542EDA78B6E67850D", "hash_sha256": "7253695FED91C65571BF59A7C61F1F1C72A081CA6EF687043CB039C7B35CA623", "hash_sha384": "244791C3E7B39E32641A985C7D75F0DBD2529FFBB70EF1ADA95BC5855F9AEE5E3DF10E7622BE99D73BD699B5503A3388", "hash_sha512": "DC8155755DA8BD58FD1EAA3C0CBC8416659D1B98B6018FA71C35182036DF8BF2FA1BF77215C1A64F1DDD8B1367ABE7B1F9D1390FA7C7FA6C4F3134859CC6B52C", "hash_ssdeep": "24576:6ZE6Yj7JKD6XH4qvIReK1odddGdBnyE0k26kVZnBm:9aqNK7utRB", "hash_imp": "321EDF3F2984E7A7F62B38C0675AEA7A", "hash_pesha1": "BE6778D264FE5FF87A374401173E0698EB85743A", "hash_pe256": "1392E8A05F5535798A4418899E6E1CCF04CFB353AA3146B4A8CA2E73BA3078DF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Diagnostics Troubleshooting Wizard", "meta_original_filename": "msdt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/7253695fed91c65571bf59a7c61f1f1c72a081ca6ef687043cb039c7b35ca623/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\msdt.exe.mui": "File", "(---) C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2\\msdtadmin\\_696BBE53-1179-4AE5-910E-DF6CCFEE257F_\\inuse": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\msdt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\ATL.DLL", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\wer.dll", "C:\\Windows\\system32\\Secur32.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\WINHTTP.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\system32\\SSPICLI.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\MSFTEDIT.DLL", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\system32\\OLEACC.dll", "C:\\Windows\\system32\\xmllite.dll" ], "runtime_window_title": "An error occurred" }, "msdtc.exe-7215CE218BDEAD41B708F098258CF972": { "file_name": "msdtc.exe", "file_path": "C:\\Windows\\system32\\msdtc.exe", "hash_md5": "7215CE218BDEAD41B708F098258CF972", "hash_sha1": "A002BC39095E7F9A3C3281505A42876F480FB95F", "hash_sha256": "1EAB4B9691E9EFA1DA02BDCB84035F65EDA4B525E5AEE925A6E1E4107F8E4F31", "hash_sha384": "DCD1B3A7FA630620C1567F4249B6DA7650A1907F0D593445AB643CADF5B438057BCE08F5A7401F1C20A2DD5D55A31CED", "hash_sha512": "58D10D21AB916A4E1D21DBFD65856ED95D484622989B2CB6A95C0D6EA49757B18C97AE06DC3B9F32AA88A0D534E0121F04ECA9F0597A952E057FFC69B93426D3", "hash_ssdeep": "1536:wpfx6C1a800NG/qtbC15ZkuH1A0a4qDLZAQcEzok3E8vroH3S7NtiXE/Lp:u1aLyMBkNv7fcmEAkyXiqp", "hash_imp": "D76D41E51FC79BF5C56F90FE6A798765", "hash_pesha1": "283A9A4B8AA73DB517D2ED2C021263AB3DAE18EA", "hash_pe256": "7BC6646161700CC43F520B7684EEB40C0E94E2D0806B12616214DE3AABA0AD00", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Distributed Transaction Coordinator Service", "meta_original_filename": "MSDTC.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/1eab4b9691e9efa1da02bdcb84035f65eda4b525e5aee925a6e1e4107f8e4f31/detection/", "runtime_modules": [ "C:\\Windows\\system32\\msdtc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\MSDTCTM.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\MSDTCPRX.dll", "C:\\Windows\\system32\\MSDTCLOG.dll" ] }, "msfeedssync.exe-7B78EFE7918C41A90C554BD7362C66E9": { "file_name": "msfeedssync.exe", "file_path": "C:\\Windows\\system32\\msfeedssync.exe", "hash_md5": "7B78EFE7918C41A90C554BD7362C66E9", "hash_sha1": "94E4AC749FEB5CCAAFA3B198E99A79AEA9D77E66", "hash_sha256": "CE95233922882F70354D637B12F4738042E189F9A92F4E99945FCBF84EC611F7", "hash_sha384": "10C5508A3A2D11E0C5A4784209B3A122DA0F922852547BE9C4237D31ABECBE3455965D7B5F2A607A38AEEC5E2E2C96A9", "hash_sha512": "4924CE094816FF9757ABA6FD2AD7E67BAD5DE3733F4E2A5C818F40FCC7C8CE7E31EFBD57658CE5943B7328F69A374CF3883E3B92C90B6755DFEAE14B28CAB3C1", "hash_ssdeep": "192:5hMHubsargEfoNuwHozeh5nKjB2v5v5UHGlndjadGHULBlS5WcsH:5hQMrXqueomnKNEhnnjaC8s5WcsH", "hash_imp": "E22B4193AC1639CCDCA0DCF2C8C3F735", "hash_pesha1": "4485C523018D02B762ECB9F8121856D7A8864485", "hash_pe256": "3A8009B98BFAA16EB927B84012A0EE8950CB8CB7C6BC482BB7FF77D5B18F68A1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Feeds Synchronization", "meta_original_filename": "msfeedssync.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/ce95233922882f70354d637b12f4738042e189f9a92f4e99945fcbf84ec611f7/detection/", "runtime_modules": [ "C:\\Windows\\system32\\msfeedssync.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ] }, "msg.exe-19F739EF36C5B97158AE639EB79E205F": { "file_name": "msg.exe", "file_path": "C:\\Windows\\system32\\msg.exe", "hash_md5": "19F739EF36C5B97158AE639EB79E205F", "hash_sha1": "2550979706A69EE32622B30A8032C45CAD4755FB", "hash_sha256": "9DBCA701E0A0F9CF7D98F5BC7A5E7D0C844F992EE4E2670F124F6344FA182E42", "hash_sha384": "B4CAE34A447AD7712A48B16A6E8A9F2FB3BB201D64D0B46E9479A7CEA520C4D080EBF965A40F8370581B8623491F5870", "hash_sha512": "D064CC88748D7E15AD0E4E3A586954106040070E5DAA9DE73D7B2A6F009FAB0CE3F9E597113C2FE88C9C39106CF982FC89662BA402BC9772848389022CCBDF48", "hash_ssdeep": "384:hd2EwJxreLEQQ8oo9Z0pWPouQmjeeEETz5TwOK8j7eACMivFYKVRfK9bIjLyW4UW:hUEwLrJQgoPEmoupae3yOK8WfvBV4ic", "hash_imp": "CD3B5466F111A79E4AC06248B98E0B04", "hash_pesha1": "19A93009DCE54E5D03E6A4FB2E539520960F1600", "hash_pe256": "C0A042EEA8C8E4D5F0DE928DFDB36FBFEED9970F70F6F30FE3F182A97DADF694", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Message Utility", "meta_original_filename": "msg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/9dbca701e0a0f9cf7d98f5bc7a5e7d0c844f992ee4e2670f124f6344fa182e42/detection/", "output": "Send a message to a user.\r\n\r\nMSG {username | sessionname | sessionid | @filename | *}\r\n [/SERVER:servername] [/TIME:seconds] [/V] [/W] [message]\r\n\r\n username Identifies the specified username.\r\n sessionname The name of the session.\r\n sessionid The ID of the session.\r\n @filename Identifies a file containing a list of usernames,\r\n sessionnames, and sessionids to send the message to.\r\n * Send message to all sessions on specified server.\r\n /SERVER:servername server to contact (default is current).\r\n /TIME:seconds Time delay to wait for receiver to acknowledge msg.\r\n /V Display information about actions being performed.\r\n /W Wait for response from user, useful with /V.\r\n message Message to send. If none specified, prompts for it\r\n or reads from stdin.\r\n\r\n", "error": "Invalid parameter(s)\r\nSend a message to a user.\r\n\r\nMSG {username | sessionname | sessionid | @filename | *}\r\n [/SERVER:servername] [/TIME:seconds] [/V] [/W] [message]\r\n\r\n username Identifies the specified username.\r\n sessionname The name of the session.\r\n sessionid The ID of the session.\r\n @filename Identifies a file containing a list of usernames,\r\n sessionnames, and sessionids to send the message to.\r\n * Send message to all sessions on specified server.\r\n /SERVER:servername server to contact (default is current).\r\n /TIME:seconds Time delay to wait for receiver to acknowledge msg.\r\n /V Display information about actions being performed.\r\n /W Wait for response from user, useful with /V.\r\n message Message to send. If none specified, prompts for it\r\n or reads from stdin.\r\n\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\msg.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\msg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\WINSTA.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "mshta.exe-F328FDCFF05BF02C2C986D52AED8BC2A": { "file_name": "mshta.exe", "file_path": "C:\\Windows\\system32\\mshta.exe", "hash_md5": "F328FDCFF05BF02C2C986D52AED8BC2A", "hash_sha1": "DD8B22ACEA424823BB64ABF71F61A03D41177C38", "hash_sha256": "E616C5CE71886652C13E2E1FA45A653B44D492B054F16B15A38418B8507F57C7", "hash_sha384": "0E55ADA950494D9A7F6E0425BC2A7B8D9586F3B356F5D1E70427266EB58CFAC06B80FFF0B6ADBE803B46A9E5C9B450E6", "hash_sha512": "EE6EB657562C746737E89ADB7C6E0D142FDDE8CADA1725EDF15BC82DF623A9AB547BDAB5830B811CE87D5F0F6FEED87B3194BC80544780F9914FDF96571023DE", "hash_ssdeep": "192:ZA27mrbZUIhKPxwya+TW0/z5S7X6Bz3vEXPXWwG/IR:T7wFXh6mD+TW0kXSvEXfWwG", "hash_imp": "42DA177DE2FAA97C3DFAEC9562772A7F", "hash_pesha1": "B52EDABFCEE656CC77281EF1A876BBBF95048EC7", "hash_pe256": "3537A373EABD126B60E0A743950C5744271341D06E91491F86F4418886A11EF2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) HTML Application host", "meta_original_filename": "MSHTA.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/e616c5ce71886652c13e2e1fa45a653b44d492b054f16b15a38418b8507f57c7/detection/", "runtime_modules": [ "C:\\Windows\\system32\\mshta.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\mshtml.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\WINHTTP.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\urlmon.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\CRYPTBASE.DLL", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\system32\\srpapi.dll", "C:\\Windows\\system32\\msIso.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326\\COMCTL32.dll" ] }, "msiexec.exe-51DFBA4D2992DA8320FC23B9D648F069": { "file_name": "msiexec.exe", "file_path": "C:\\Windows\\system32\\msiexec.exe", "hash_md5": "51DFBA4D2992DA8320FC23B9D648F069", "hash_sha1": "25E73A0DA4F0A5A031E27B9DDA0A4FC5BB489B4E", "hash_sha256": "DC52A89F2FCBD8E31F2D466BD2D35414A86BB907382251FABB88CD3969FB3EC8", "hash_sha384": "3666E1BA7A450C4128870113990760356A2EFBD841AEFED7C8245219DC5D596AEC27FA8BCE1B330BE07FB12B36737CF3", "hash_sha512": "E6CFC66AE78EA372922E54CFE7DE804E73F05267C9722704BEB56F73FE7E1D31A599E07B27803DA2E110748D45845E2DAC5C5FAC6917F7FA44A236F98EEAB8C3", "hash_ssdeep": "768:1bzmTyNIJ8gxZ8HCOz6yapzBoHFV0sNi4BVAF25hSMizYlv/u57sHrWTx4rn15CJ:kXIB4zuA4zAFq8zzY+5nTx4r15L6V", "hash_imp": "13C7ACE23F99CD5FBC3ABD5C16BF2DCE", "hash_pesha1": "23CEF38308A823B64132C2ACCFC48FC12DB3309D", "hash_pe256": "A931ED4E42E33738C4AEA8494966E8FE71211C0107CE7612E417B5B322D56491", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows installer", "meta_original_filename": "msiexec.exe.mui", "meta_product_name": "Windows Installer - Unicode", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "5.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/dc52a89f2fcbd8e31f2d466bd2d35414a86bb907382251fabb88cd3969fb3ec8/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\msiexec.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\msimsg.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\msiexec.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\SYSTEM32\\AcLayers.DLL", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\sfc.dll", "C:\\Windows\\SYSTEM32\\WINSPOOL.DRV", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\SYSTEM32\\sfc_os.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.DLL", "C:\\Windows\\system32\\msi.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\VERSION.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll" ], "runtime_window_title": "Windows Installer" }, "msinfo32.exe-41AA3C8C427A773B6C08460535EE8070": { "file_name": "msinfo32.exe", "file_path": "C:\\Windows\\system32\\msinfo32.exe", "hash_md5": "41AA3C8C427A773B6C08460535EE8070", "hash_sha1": "A43ADB2303F09887A5E62F6B3EA5F728AD323E2E", "hash_sha256": "B3B40CF1227F21ED74DE6904C99E346EE1DC2B7D5E949D0F44FDCB1D10423307", "hash_sha384": "544C9C5594F63551ABF39ACE2978694496657FF9F9D0D2E3EFFD2EC940178E95B7EFA10499A1EB04D0F66CCF955A0477", "hash_sha512": "22EF26597E8728EA30D307ECFD40567B847845B10CD3822859781E50F96854E07C1E1D8BA45875EE166C313BC3647E0D8D77116D5B701AC614CB2547D72CF443", "hash_ssdeep": "6144:+r2K7TX6A9pEHWI8Ub8mZEOHHrpm1XUZLxEZEOHHrpm1XUZLx:+2AcHaqtLpm1EwtLpm1E", "hash_imp": "6AFCFEF40BD31E27B12E97D724B4E513", "hash_pesha1": "978AB6700E4DA05BDF8E177E8ACA8D4AF92CC5AB", "hash_pe256": "14BC1AB0CD3586D67814B68D4CAD71370642A20D0F4D006EDDD76F4177BFCA7B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Information", "meta_original_filename": "msinfo.dll.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b3b40cf1227f21ed74de6904c99e346ee1dc2b7d5e949d0f44fdcb1d10423307/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\msinfo32.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1304": "Section", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\msinfo32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\system32\\ATL.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\SLC.dll", "C:\\Windows\\system32\\sppc.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\wbem\\wbemprox.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\system32\\wbem\\wbemsvc.dll", "C:\\Windows\\system32\\wbem\\fastprox.dll" ], "runtime_window_title": "System Information" }, "mspaint.exe-67C68B11E98970966DF59D2FAD6152BF": { "file_name": "mspaint.exe", "file_path": "C:\\Windows\\system32\\mspaint.exe", "hash_md5": "67C68B11E98970966DF59D2FAD6152BF", "hash_sha1": "8956D4DFF2E321B7308D7FDD8BD32BF47D61F398", "hash_sha256": "615CFFE98CAD0DB5F7F261CE915F13BBBC22378BB2A80591D38205D5658A8092", "hash_sha384": "DDA836D6E9F58A535871386D191A9FA9EE1C8EE9B099F7F2F86133758B2E1618CE33E1C190CF59E7AEEF23761D0FFF33", "hash_sha512": "0B2D663E7E2611092EBBB6771321B33A128675144E2CE4260998949A486F91BC7F51ABF429CD0489004947FCE584C21DD14AE0BB06820ADA82E2D8377366B9A2", "hash_ssdeep": "98304:70eQ2u7InCOgQwyRPM1mlawYL260GBGrGrGWAub7jPhivQ:7096n/gQw4MIlawYVb7jP8v", "hash_imp": "ABBE6AE1A46B5D03FCCC5A2C2F1DF4D0", "hash_pesha1": "9D093A33FE90EAC236136BC5553D263F2E8D247D", "hash_pe256": "03A967DAEAC5FCB54E2FE202D188A2CF33250FC6A315AA7F6947DAE670FD8146", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Paint", "meta_original_filename": "MSPAINT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/615cffe98cad0db5f7f261ce915f13bbbc22378bb2a80591d38205d5658a8092/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\mspaint.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1374": "Section", "(RW-) C:\\Windows\\debug\\WIA\\wiatrace.log": "File", "(R-D) C:\\Windows\\System32\\en-US\\UIRibbon.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\RotHintTable": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "Paint", "runtime_modules": [ "C:\\Windows\\system32\\mspaint.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\SYSTEM32\\AcGenral.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\SYSTEM32\\MPR.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\system32\\WINMM.dll", "C:\\Windows\\system32\\WINMMBASE.dll", "C:\\Windows\\SYSTEM32\\ninput.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\system32\\MSFTEDIT.DLL", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\UIRibbon.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\System32\\efswrt.dll", "C:\\Windows\\SYSTEM32\\wintypes.dll", "C:\\Windows\\System32\\twinapi.appcore.dll", "C:\\Windows\\System32\\RMCLIENT.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\sti.dll", "C:\\Windows\\SYSTEM32\\wiatrace.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\System32\\msxml6.dll", "C:\\Windows\\system32\\windowscodecs.dll" ] }, "MsSpellCheckingHost.exe-1B664685DFB5D8C40B49A9A2AAD3D004": { "file_name": "MsSpellCheckingHost.exe", "file_path": "C:\\Windows\\system32\\MsSpellCheckingHost.exe", "hash_md5": "1B664685DFB5D8C40B49A9A2AAD3D004", "hash_sha1": "2DE69AE760359F128F9B06D784CED4B72D970AAA", "hash_sha256": "933410F4A3CD7142CD6950C0D9E33E11B5E37B129DC142022A67C06313581541", "hash_sha384": "4BFA85633BD6FBDA4E4887565EB5458245489669AC4147FDD4FA9FE2DC47D2C8E355242F53AE1A16E1E416C7B670A338", "hash_sha512": "2DBE34565E3D6599346992B98B9769B9878844563661722D4C9DA618C4F2080B31220D96E5C1BD4580F4F338A713D68DE63097C86E1309FB5BBBC1E8F5CCCD4B", "hash_ssdeep": "1536:buS2idsrzBK1WG0wN8bnHbgHyDTlyKNr+NFOB127fAUgO/3Apzly:bnyzU1Wu8bnHbgH8+XOm73g23Apzl", "hash_imp": "F2968B370A0C760CA6C260CBD50F7EDA", "hash_pesha1": "174BD3DAC7285FDB9C26ED48EEEFCCC53D20F0D7", "hash_pe256": "B3DB59D18AC2FE7C0A3FE675D8F3B4FFB3BC22D4C7AF5F1FB83992E5CFB0C995", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Spell Checking Host", "meta_original_filename": "MsSpellCheckingHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/933410f4a3cd7142cd6950c0d9e33e11b5e37b129dc142022a67c06313581541/detection/" }, "mstsc.exe-620B161E49B1AD04292B2D3973366385": { "file_name": "mstsc.exe", "file_path": "C:\\Windows\\system32\\mstsc.exe", "hash_md5": "620B161E49B1AD04292B2D3973366385", "hash_sha1": "3B3A80B78D15AA647E520BE71EAD454805049A11", "hash_sha256": "CF7882E388852EB0D62C4B5B40832947D18DAFCA4D2503BB30C4C8AE53A65647", "hash_sha384": "D46AC8D1B0268EDBB187855ECE0F399A99DED6703BD1916497DC96FA310FC7E1B2FA23603FC8CAF45740180514C231D0", "hash_sha512": "49E27AB2A2767587CC3B04D624619CDACF79A09248F678EDFB6A87C4F03EC29ED9A8AEA8E5A66F2FA4106C20FB6F30B419BC6BD23A9635A76435B9F64B5DFC9A", "hash_ssdeep": "98304:wqZ5q1jVV5SZ5ptRnFMn4Y2Z8jnwgI7bv3F8esVNxOWM9Mg:wqZ5q1jVV5SZ5ptRnFMn4Y2Z8jnwgI7D", "hash_imp": "43D4C98DB4E05AF16115818C6E500A33", "hash_pesha1": "D8655DB63971B0A9E15C73BAB24240E3F429A0F0", "hash_pe256": "FC6C857EE6379B8B923FC840C6E1005506A98B6DEDBB3C777D8DCC6740CA2221", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Connection", "meta_original_filename": "mstsc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/cf7882e388852eb0d62c4b5b40832947d18dafca4d2503bb30c4c8ae53a65647/detection/" }, "mtstocom.exe-0E92741054E83065E2E90B6033F6FCCE": { "file_name": "mtstocom.exe", "file_path": "C:\\Windows\\system32\\mtstocom.exe", "hash_md5": "0E92741054E83065E2E90B6033F6FCCE", "hash_sha1": "D86FBB0C51955E50FA13637D53A33A3B0AD6F291", "hash_sha256": "6E620945BED6DBAFCF7893AA243F156800CDB62FF0EC4068A5F12B5D9BAF3356", "hash_sha384": "9FF3E9D942FBF854A9942E00F7176BC43CA70CB2450DD3BABD712F1496B29EB113DB183B12119D62AF7E3B5AA387577C", "hash_sha512": "C04DAE4AF6336A91B6093D4CDD6D544EB3F90790F2340EFDF1EC9704124CF4B8D9BBD5FD6F6020E45068A7B2F418E5A47BE3F45A7D7FA5D75479484EA3CE3B6F", "hash_ssdeep": "1536:XOsEm8OlaUP6QZMXM70U97a34VuGkG0D4ZVqEwCZ07E2yTxk3oLjmjkS3rN:esEm8OlHruo41D47Zf2yF5jiVh", "hash_imp": "FFB47EBDE759F6772304D459D3AFD55A", "hash_pesha1": "05F10BD60156287F541C0A0B709977050052EDCB", "hash_pe256": "74895720A399520E2B283601FB78AF53EE1CD6D789D7E9CD8B2C06F32E068975", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+", "meta_original_filename": "MTSTOCOM.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/6e620945bed6dbafcf7893aa243f156800cdb62ff0ec4068a5f12b5d9baf3356/detection/", "runtime_modules": [ "C:\\Windows\\system32\\mtstocom.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CLBCatQ.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "MuiUnattend.exe-8187B63A9163C0C396F317660C3FAAF6": { "file_name": "MuiUnattend.exe", "file_path": "C:\\Windows\\system32\\MuiUnattend.exe", "hash_md5": "8187B63A9163C0C396F317660C3FAAF6", "hash_sha1": "BB55332396CD35F74642E1E3CB0813B8C408D8C2", "hash_sha256": "6F2F265D4C5DF2FF2BD63D7AF2D6BBFFBF95CC76B3D92E396CC3ABD6DDAA4A63", "hash_sha384": "7AA6D7EA3C31904C7DFBFBBC83E9B8FE98424FF886D500458FB8AB162513B479DFE9776F169B0AF2D5D970301E172225", "hash_sha512": "C8800C479D3CABE45E1023F2A4BB2FA33D8C5812C6349A19B411B217A296DAF2EA4779C6436B9CA6D68D23B6C94BADAC35F8D5059A64E5C0D14190D4258CBB0E", "hash_ssdeep": "1536:D6z33UGx1wK+lTo+5EPLDGndAgt0Bg+Rj1HuiTwgXKqAbiwh2F5pArg:Itx1wK+l8+5EPLDGndAHBgYYcRyz2S8", "hash_imp": "53B6A2E562D76927BE540889A357C2DC", "hash_pesha1": "A8B0B796E4B2CD9B542D41E5A9CFFC343F0B720D", "hash_pe256": "AB3FB10854EC913A707F4103E6C78A4F1B98DB257606A97E0A62E97D82FF25F6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MUI unattend action", "meta_original_filename": "MuiUnattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/6f2f265d4c5df2ff2bd63d7af2d6bbffbf95cc76b3d92e396cc3abd6ddaa4a63/detection/", "runtime_modules": [ "C:\\Windows\\system32\\MuiUnattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\wdscore.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\system32\\dbgcore.DLL" ] }, "MultiDigiMon.exe-22E44F19E1150076CC57D13EA2AD1299": { "file_name": "MultiDigiMon.exe", "file_path": "C:\\Windows\\system32\\MultiDigiMon.exe", "hash_md5": "22E44F19E1150076CC57D13EA2AD1299", "hash_sha1": "DB28AFD7FB31AEB8DE3790582CD56CCE2B216F77", "hash_sha256": "104F7DDF72823F0516861BCD5E1D25D0617B9754AADFA24796404124DD120C42", "hash_sha384": "2D5D4ED6385D52C8DC52BEE6DAD790C07D61495B25AE5D7CAC7F37E0D5B1B0A37E9F37B7D85A4C9C7CF2A2715D51201C", "hash_sha512": "4ECD61FD5CAB6856EA5E507E42DC0E918BC8B3DCEF487C70E4FD966393767338FA1B7BDE647B1ADDF758788D2EFBB17EDC394945292673A1B1A05C15C90DFA0F", "hash_ssdeep": "768:EMQVwFkb1dyP82uHYSz+O7W1jNrJsgrrH1Xzij9V+//qdfdh22C+BH7sFpCKcKP:Va08j7+O7WDvrgV+/ydfW2jbJK", "hash_imp": "E2B29DA5A898E5378D53FC923C78C72E", "hash_pesha1": "04EE5780D40EB6C73424DF95ADE64D8B30AD326E", "hash_pe256": "35CA5A3D44EAA666B75B22DD394A71821797A5D3E5D2D0F7CB5AA5D8C100FEB1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Digitizer to Monitor Mapping Tool", "meta_original_filename": "MultiDigiMon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/104f7ddf72823f0516861bcd5e1d25d0617b9754aadfa24796404124dd120c42/detection/", "runtime_modules": [ "C:\\Windows\\system32\\MultiDigiMon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\system32\\NInput.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "MusNotification.exe-C3CDEF82940ADE0CCE5BDDA32FC01DFA": { "file_name": "MusNotification.exe", "file_path": "C:\\Windows\\system32\\MusNotification.exe", "hash_md5": "C3CDEF82940ADE0CCE5BDDA32FC01DFA", "hash_sha1": "891BCBFF355E2174E3FFF44D3C1B30BF83EA169B", "hash_sha256": "6473E672F264C10B4F5853CB5BA8FABF5F4A9355341A8C162F42A58D00777B49", "hash_sha384": "7BE3D5504EDA50E7E0CA3FA1374A86A0FA93C947341410D7BD4B25A46ED68C0A2FE80C7B37A57F61398AAEB72E86CB38", "hash_sha512": "DFEC90C13FDE72FC8712E7343EAA4BC636ABA25CC954A3440340E326777F052323ACB7CBE6259CDEE31EF9B82DAD9599C97566B9E9B941730CC3EE5923203BE2", "hash_ssdeep": "6144:LKnSGmDzIJBXzXMbSS6NL/LM28BzTEqW3Zsoeu0GaSQoOqCT6a6oR5HbHHI9prOj:LKYQJxZNL/LF8BvTS/o", "hash_imp": "EF3DCD1A56214FC79DEFF3253344CC26", "hash_pesha1": "2CD94A2CD4A4FE7E9CEE1D0A3CB43165003C8282", "hash_pe256": "1D1004203A8F7B56AF163DA7543A04D47C8AB5B00F46B2CB7F3FFB4BFE41E9B6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MusNotificationBroker", "meta_original_filename": "MusNotification.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1192 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1192", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/6473e672f264c10b4f5853cb5ba8fabf5f4a9355341a8c162f42a58d00777b49/detection/", "runtime_modules": [ "C:\\Windows\\system32\\MusNotification.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\system32\\USOCore.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\dmiso8601utils.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\system32\\UpdatePolicy.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\clbcatq.dll" ] }, "MusNotificationUx.exe-FE62881CF0014493C049B1DCEB017648": { "file_name": "MusNotificationUx.exe", "file_path": "C:\\Windows\\system32\\MusNotificationUx.exe", "hash_md5": "FE62881CF0014493C049B1DCEB017648", "hash_sha1": "CACDE094D417290B2ED0E4033F15068176EFE30E", "hash_sha256": "C67726D20F1A5770F0605FE02479197A045F5B8572CE71356D9CA99F8F6B3251", "hash_sha384": "7F565A356E1BB83CFEE078DE4DF8CE7E6BF8A6EFB4FCE9ECDEF8AADBFE3A0A0BDB929FABE02746C6B9C4B4B6C15205F1", "hash_sha512": "9A8778B6B5F0A3E834607E90266449EA07B343EA93B8D473E9542F350DA6CC99B52BC86463EE9035F10E80C511AE907B625F7155FC97733F0BF9AB055A62874B", "hash_ssdeep": "6144:Z9GVidiQRfoYdzQgAF6s+CH0XrmnfMAW9hMt/xPo39WXYGYvAYVeuqw986t00Mom:eQdiQ/dzQzXxo", "hash_imp": "58D67480ACA100232C9AB2442FE86961", "hash_pesha1": "70AD27F1B6714E15AC569817584A9718D2394DD3", "hash_pe256": "2E4C84F42B655AD48D31F56936691103B3558A585B9A656E299141AB68F73024", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MusNotificationUx.exe", "meta_original_filename": "MusNotificationUx.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1192 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1192", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/c67726d20f1a5770f0605fe02479197a045f5b8572ce71356d9ca99f8f6b3251/detection/", "runtime_modules": [ "C:\\Windows\\system32\\MusNotificationUx.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\USOCore.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\UpdatePolicy.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\clbcatq.dll" ] }, "MusNotifyIcon.exe-25D194A948C16E2AFE764D18ECA644D5": { "file_name": "MusNotifyIcon.exe", "file_path": "C:\\Windows\\system32\\MusNotifyIcon.exe", "hash_md5": "25D194A948C16E2AFE764D18ECA644D5", "hash_sha1": "2669433058B210A3076296E09F601D6D1FF95831", "hash_sha256": "22D66F68490EFEFC49BC6FD861B337661DBC02B63B7F38A85A781914EB27C801", "hash_sha384": "D45CA61A47DACB8C3284CBCF4A70499DFB8113C379FD5B580324C39FCAC032841787452BE4A405211E45B01D563CA53A", "hash_sha512": "5755499CE2578BCACF86706BBFC78677049DFEC7F4C8B487E0A42587E37A7B851E9368C18C7DC361C440F4DC8581BEC53AE1A96317E8ED65EB38F9CA8F5BA3C4", "hash_ssdeep": "3072:fYnP1luB5Q8s4onI2lbuklOJOG6xAcEv/IG3SeczEM:4P1lks4/mnlOJOG/IMbI/", "hash_imp": "66347AB7C85B5A3E9B71FD6DE905ACEC", "hash_pesha1": "0E597DD65AC7ACDF27E47C77FDA5620AA30A6D0E", "hash_pe256": "C60A9A1E9409CE97CED5F52490312EC388CD9F144BF908A913D4B35331EFFACA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MusNotifyIcon.exe", "meta_original_filename": "MusNotifyIcon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/65", "filescan_vtlink": "https://www.virustotal.com/gui/file/22d66f68490efefc49bc6fd861b337661dbc02b63b7f38a85a781914eb27c801/detection/", "runtime_modules": [ "C:\\Windows\\system32\\MusNotifyIcon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "Narrator.exe-72E6BB735FAE36942575D0E9BB998DE5": { "file_name": "Narrator.exe", "file_path": "C:\\Windows\\system32\\Narrator.exe", "hash_md5": "72E6BB735FAE36942575D0E9BB998DE5", "hash_sha1": "2119746F730403BF15D9F44F0FFB8E642B95C9B3", "hash_sha256": "7CB42636E62C41160BDC26882AC3347F30E277D54835EA30E1E847519E5CD229", "hash_sha384": "24361A32BE55215817DB92A438703FA31D0C04FE031DE15C652EC5522E5BD9B41F9C3914A1CE1F2C5848E334AAFFABF1", "hash_sha512": "9E20D6D076F846711B7AA878539FDCEFBA73CC5494863346695D4B716F841796DF209325036AE0D19894F2E0EB334F0809E8E1577A9E6E869DA351B8E743251E", "hash_ssdeep": "6144:QpaUuFEcH1sbDUZujO34yoVAjk9AQFgZKUV:suFESmDUCOr3kiAuV", "hash_imp": "B0F5FB1C8AFEF23B8E84D6CE920F88DB", "hash_pesha1": "37047A9E2471679F1D0257CA395A5EAA81F131DA", "hash_pe256": "0F422DB8D8D541BE44BA101A3CD36F1526685FECEAC1E202F6B95E3B12CA7C58", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Screen Reader", "meta_original_filename": "SR.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/7cb42636e62c41160bdc26882ac3347f30e277d54835ea30e1e847519e5cd229/detection/" }, "nbtstat.exe-4D2930FE4EC73273FADB62A397E0C71C": { "file_name": "nbtstat.exe", "file_path": "C:\\Windows\\system32\\nbtstat.exe", "hash_md5": "4D2930FE4EC73273FADB62A397E0C71C", "hash_sha1": "C9CBE229813163AE626925A27BFD101E25E3FA51", "hash_sha256": "28C46C4EE53050720E06C4BB0D1F64AEF651438E3A712398D488426355A330C7", "hash_sha384": "132F4BE41D7E5AF30E000AF8BAEF6865DBBC8FF41196177157E3AE347A60AC87B3A344EADBA3D4100485F6F49FD4B84A", "hash_sha512": "C3087515F715649B9C9C9C3BF250CCE1B40B315FD38EAA60851E364747F50E7130A1E2596681206B330C6A1BB1103A5377475C1412EEA01D5818F2006408A644", "hash_ssdeep": "384:eCli1f2vdVdViTxC06n9RllSNnNgwFI7JWWarW:eCi1+vTdIc0YPeNnNgQ", "hash_imp": "207F3D1F113DEB58D9E4C6ACA8E0FA3F", "hash_pesha1": "4E9D1798E8561F3701A0F7A2760BA08C220FBFB8", "hash_pe256": "B413E6AF7D7BB44DD7D63BB1414753184EAF963CCBF32DCF2C9C50F5E72957DB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP NetBios Information", "meta_original_filename": "nbtinfo.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/28c46c4ee53050720e06c4bb0d1f64aef651438e3a712398d488426355a330c7/detection/", "error": "\r\nDisplays protocol statistics and current TCP/IP connections using NBT\r\n(NetBIOS over TCP/IP).\r\n\r\nNBTSTAT [ [-a RemoteName] [-A IP address] [-c] [-n]\r\n [-r] [-R] [-RR] [-s] [-S] [interval] ]\r\n\r\n -a (adapter status) Lists the remote machine's name table given its name\r\n -A (Adapter status) Lists the remote machine's name table given its\r\n IP address.\r\n -c (cache) Lists NBT's cache of remote [machine] names and their IP addresses\r\n -n (names) Lists local NetBIOS names.\r\n -r (resolved) Lists names resolved by broadcast and via WINS\r\n -R (Reload) Purges and reloads the remote cache name table\r\n -S (Sessions) Lists sessions table with the destination IP addresses\r\n -s (sessions) Lists sessions table converting destination IP\r\n addresses to computer NETBIOS names.\r\n -RR (ReleaseRefresh) Sends Name Release packets to WINS and then, starts Refresh\r\n\r\n RemoteName Remote host machine name.\r\n IP address Dotted decimal representation of the IP address.\r\n interval Redisplays selected statistics, pausing interval seconds\r\n between each display. Press Ctrl+C to stop redisplaying\r\n statistics.\r\n\r\n" }, "ndadmin.exe-C1E5E50078D849CE539FE60B0AAC1C43": { "file_name": "ndadmin.exe", "file_path": "C:\\Windows\\system32\\ndadmin.exe", "hash_md5": "C1E5E50078D849CE539FE60B0AAC1C43", "hash_sha1": "271513070D9193B4E6E1D0857AC423D088FF8140", "hash_sha256": "612B00C9C83C96E3E5A866B95A42A21ED42D9C4CC58A8F19297E3E6586976D30", "hash_sha384": "E4DFF96E1E4CE164782DA9BC9D0B2128A1F2C9D5B8B9FA644548BC3C13EEF9ADFEDC30EA35AA83403375E5C8D498EC12", "hash_sha512": "CEE50A1AF1A820DE4128ACF2E4A6158C72B08C6248FB348145C3C3B4254222FEC321526A12619ED4562CE175096495BA9CC633E8D51258F3F1CF0836B5062950", "hash_ssdeep": "768:6vyYSuGKYQmMjXmtarjQAhtqIrn8+1hrpFIUUUUUUUUUUUUqRcxM:YGKYQmMjXmwrjfFrGUUUUUUUUUUUU3+", "hash_imp": "3AED82C66B004C977279044836A79845", "hash_pesha1": "D59FE8E342E4FBB86D904E669FB15ADF862A1467", "hash_pe256": "112CD4E44F7176E5E4C513BB072F0E5AD04BE65BB053E512CBB185A627AB2F80", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device driver software installation", "meta_original_filename": "NDAdmin.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/612b00c9c83c96e3e5a866b95a42a21ed42d9c4cc58a8f19297e3e6586976d30/detection/" }, "net.exe-AE61D8F04BCDE8158304067913160B31": { "file_name": "net.exe", "file_path": "C:\\Windows\\system32\\net.exe", "hash_md5": "AE61D8F04BCDE8158304067913160B31", "hash_sha1": "4F4970C3545972FEA2BC1984D597FC810E6321E0", "hash_sha256": "25C8266D2BC1D5626DCDF72419838B397D28D44D00AC09F02FF4E421B43EC369", "hash_sha384": "044C249B23A8F7583C7BB20F8CD1F1F7AD4A26CA335F917906D487E792E2E6B23F6051D180952977F37F975A52CFFA85", "hash_sha512": "0B3B8662FF95CD4D9CF42B9179E111C9A51654908938E25F9BD5EAE2A4177F767EA2EBD0EFD9DED5DCA2D7D4FF18ADD7AA945D6638439F7A848B11C630CD153D", "hash_ssdeep": "768:MxLuocL47+gV+tNnXJ8t+vsKDaZ3I9eEFJDCtIyLQZ0uZnJ:9ocLQ+DRXOasKDBLD+NsZJJ", "hash_imp": "57F0C47AE2A1A2C06C8B987372AB0B07", "hash_pesha1": "EC7616F37AA3C497C111E6DD0F721EB5D2024DCB", "hash_pe256": "2D16BF609CB22E6F923D76098B47F619FE2CEF93E28961810069C30ACAF789B8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Net Command", "meta_original_filename": "net.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/25c8266d2bc1d5626dcdf72419838b397d28d44d00ac09f02ff4e421b43ec369/detection/", "error": "The syntax of this command is:\r\n\r\nNET\r\n [ ACCOUNTS | COMPUTER | CONFIG | CONTINUE | FILE | GROUP | HELP |\r\n HELPMSG | LOCALGROUP | PAUSE | SESSION | SHARE | START |\r\n STATISTICS | STOP | TIME | USE | USER | VIEW ]\r\n", "runtime_modules": [ "C:\\Windows\\system32\\net.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\srvcli.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL" ], "output": "The syntax of this command is:\r\n\r\nNET HELP\r\ncommand\r\n -or-\r\nNET command /HELP\r\n\r\n Commands available are:\r\n\r\n NET ACCOUNTS NET HELPMSG NET STATISTICS\r\n NET COMPUTER NET LOCALGROUP NET STOP\r\n NET CONFIG NET PAUSE NET TIME\r\n NET CONTINUE NET SESSION NET USE\r\n NET FILE NET SHARE NET USER\r\n NET GROUP NET START NET VIEW\r\n NET HELP\r\n\r\n NET HELP NAMES explains different types of names in NET HELP syntax lines.\r\n NET HELP SERVICES lists some of the services you can start.\r\n NET HELP SYNTAX explains how to read NET HELP syntax lines.\r\n NET HELP command | MORE displays Help one screen at a time.\r\n\r\n" }, "net1.exe-63DD4523677E62A73A8A7494DB321EA2": { "file_name": "net1.exe", "file_path": "C:\\Windows\\system32\\net1.exe", "hash_md5": "63DD4523677E62A73A8A7494DB321EA2", "hash_sha1": "085E23DF67774ED89FD0215E1F144824F79F812B", "hash_sha256": "C687157FD58EAA51757CDA87D06C30953A31F03F5356B9F5A9C004FA4BAD4BF5", "hash_sha384": "B5A0B600BE1C83DFB2D8DCA07D5DC6FC0A98FE93C5B48A3153C0A89D4075BB36FA587BE3FE77F72B026FE98F4B3BF4FE", "hash_sha512": "72F488E4FBBB169C96F3038638292549AC9E37F65DC0F709B2212B0AB678ADE01A813D8876693EC3D07CCD4A9D93195D3FA6BBBD5E5CBCD57BD944C91A28182D", "hash_ssdeep": "3072:d2ruQy5w+DoHcR1Bp4+dJjUHhYzcvmefyB2V7c86cscWE/37iJ3gmnK6HqF1A01p:d2RyoHAp4EJjUBYzcvXO2V7cfcscWE/9", "hash_imp": "41DBA1AF77E1A2260F0CE46D59ADCB5E", "hash_pesha1": "50D779A6E6EFE2DF4CB0101372590D52EAFE7B6D", "hash_pe256": "6204A84B2E0F6EFBEFD50D51756EF7C92889EB91E2C5FBC705B898030A55D35B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Net Command", "meta_original_filename": "net1.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/c687157fd58eaa51757cda87d06c30953a31f03f5356b9f5a9c004fa4bad4bf5/detection/", "error": "The syntax of this command is:\r\n\r\nNET\r\n [ ACCOUNTS | COMPUTER | CONFIG | CONTINUE | FILE | GROUP | HELP |\r\n HELPMSG | LOCALGROUP | PAUSE | SESSION | SHARE | START |\r\n STATISTICS | STOP | TIME | USE | USER | VIEW ]\r\n", "output": "The syntax of this command is:\r\n\r\nNET HELP\r\ncommand\r\n -or-\r\nNET command /HELP\r\n\r\n Commands available are:\r\n\r\n NET ACCOUNTS NET HELPMSG NET STATISTICS\r\n NET COMPUTER NET LOCALGROUP NET STOP\r\n NET CONFIG NET PAUSE NET TIME\r\n NET CONTINUE NET SESSION NET USE\r\n NET FILE NET SHARE NET USER\r\n NET GROUP NET START NET VIEW\r\n NET HELP\r\n\r\n NET HELP NAMES explains different types of names in NET HELP syntax lines.\r\n NET HELP SERVICES lists some of the services you can start.\r\n NET HELP SYNTAX explains how to read NET HELP syntax lines.\r\n NET HELP command | MORE displays Help one screen at a time.\r\n\r\n" }, "netbtugc.exe-4F65D6E9B482043831C169DB586E410E": { "file_name": "netbtugc.exe", "file_path": "C:\\Windows\\system32\\netbtugc.exe", "hash_md5": "4F65D6E9B482043831C169DB586E410E", "hash_sha1": "7702537147BD0F04BA0EC3DF882A40D1842D3139", "hash_sha256": "524A6F2366533C30C6F447215C7BCCB6F5C8F20B7DC377C791A7B3E886EC1A76", "hash_sha384": "8961FA96AB86AD51D655E2864E5FD303F28D9246F7D2CED6BEC651D851EC257CC659AAB51848DF0D3EFBF5C983FCC639", "hash_sha512": "F6EFF640FCE9DC89B76352F7D44AC71859ECBB5DA4EDFF2614B34D48080A3ED24E207FC487ABEF15C517BA8D14B2B20999BE89D43AB1CFE306F9DA309AA29C14", "hash_ssdeep": "384:gLz1Ta0f0pScSlHS4cGZoDb7ILHigFKXC08fPCdjWoskS2CRmsi1jdc6emPW/JFW:U0pSlfcWGk+XCaqLQN1jkm2", "hash_imp": "34133D53B90A18DF679C80EB178CA803", "hash_pesha1": "261FE7D8C49608AD49044E35108E30048F914D14", "hash_pe256": "9549C15CD113D15E7743897510D9AD08AF28AC49FEF7A09C8BA92A6E850B8941", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NetBT Unattend Generic Command", "meta_original_filename": "netbtugc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/524a6f2366533c30c6f447215c7bccb6f5c8f20b7dc377c791a7b3e886ec1a76/detection/", "runtime_modules": [ "C:\\Windows\\system32\\netbtugc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\wdscore.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\system32\\dbgcore.DLL" ] }, "netcfg.exe-E0F05223E5B6F6AD317772ADFE6DC98D": { "file_name": "netcfg.exe", "file_path": "C:\\Windows\\system32\\netcfg.exe", "hash_md5": "E0F05223E5B6F6AD317772ADFE6DC98D", "hash_sha1": "FBA117CF6F936DDCA974A5F6B041075F9736F053", "hash_sha256": "6820988B6804A05C7FC2F674961275861163395C2D73F6AD4A450F49282CC735", "hash_sha384": "FD4DB9544A3F1B62F8D6EDBCF98B9A1FCE551B470F61E8C2034FFF73CF000284DB0BE6F0E45A6117BAE7DA1C7B2D06D6", "hash_sha512": "97663EF126AFC48B4196045DBDAA6E2F9C744C8263E4BC2B6BAB5121312CDC872DB65758A70AF3BF6C6F9840A9D52CE198999D9D8792F9606659CB45393F16DE", "hash_ssdeep": "768:98aXLV7adQObHc9kP4eVjI/SyVufQicMu/0M0FKS:TRudXHYkP7VjrEuYM009gS", "hash_imp": "063284B04368D850FDDF9DECD7EA9EE7", "hash_pesha1": "458328D42F2EF99987F290C53D162C1803F015EB", "hash_pe256": "E74A30B8D4390DA8574DA5BBB27B38CBE382910C795691572B89C2C7B2449F84", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WinPE network installer", "meta_original_filename": "netcfg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/6820988b6804a05c7fc2f674961275861163395c2d73f6ad4a450f49282cc735/detection/", "output": "netcfg [-v] [-winpe] [-l <full-path-to-component-INF>] -c <p|s|c> \r\r\n -i <comp-id>\r\r\n \r\r\n -winpe installs TCP/IP, NetBIOS and Microsoft Client for Windows \r\r\n preinstallation environment\r\r\n -l\t provides the location of INF\r\r\n -c\t provides the class of the component to be installed (p == Protocol, \r\r\n s == Service, c == Client)\r\r\n -i\t provides the component ID\r\r\n\r\r\n The arguments must be passed in the order shown.\r\r\n\r\r\n Examples:\r\r\n \r\r\n netcfg -l c:\\oemdir\\myprot.inf -c p -i myprot\r\r\n \r\r\n Installs protocol 'myprot' using c:\\oemdir\\myprot.inf\r\r\n\r\r\n netcfg -c s -i MS_Server\r\r\n \r\r\n Installs service 'MS_Server'\r\r\n \r\r\nOR\r\r\n\r\r\nnetcfg [-v] -winpe\r\r\n\r\r\n Example:\r\r\n \r\r\n netcfg -v -winpe\r\r\n\r\r\n Installs TCP/IP, NetBIOS, and Microsoft Client for Windows \r\r\n preinstallation environment\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg [-v] -q <comp-id>\r\r\n\r\r\n Example:\r\r\n \r\r\n netcfg -q MS_IPX\r\r\n \r\r\n Displays if component 'MS_IPX' is installed\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg [-v] -u <comp-id>\r\r\n\r\r\n Example:\r\r\n\r\r\n netcfg -u MS_IPX\r\r\n\r\r\n Uninstalls component 'MS_IPX'\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg [-v] -s <a|n>\r\r\n\r\r\n -s provides the type of components to show (a == adapters, \r\r\n n == net components)\r\r\n\r\r\n Example:\r\r\n \r\r\n netcfg -s n\r\r\n\r\r\n Shows all installed net components\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg [-v] -b <comp-id>\r\r\n\r\r\n Example:\r\r\n\r\r\n netcfg -b ms_tcpip\r\r\n\r\r\n Shows binding paths containing 'MS_TCPIP'\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg [-v] -m\r\r\n\r\r\n Example:\r\r\n\r\r\n netcfg -m \r\r\n\r\r\n Outputs the binding map to NetworkBindingMap.txt in the current directory.\r\r\n -v will also display the binding map to the console.\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg -d\r\r\n\r\r\n Example:\r\r\n\r\r\n netcfg -d\r\r\n\r\r\n Performs a cleanup on all networking devices.\r\r\n\t\tThis will require a reboot.\r\r\n\r\r\nOR\r\r\n\r\r\nnetcfg -x\r\r\n\r\r\n Example:\r\r\n\r\r\n netcfg -x\r\r\n\r\r\n Performs a cleanup on networking devices, skipping those without physical\r\r\n object names.\r\r\n\t\tThis will require a reboot.\r\r\n\r\r\nGeneral Notes:\r\r\n -v\tRun in verbose (detailed) mode\r\r\n -?\tDisplays this help information\r\r\n\r\n" }, "NetCfgNotifyObjectHost.exe-55790CBC7A189C0D546CD265FB946272": { "file_name": "NetCfgNotifyObjectHost.exe", "file_path": "C:\\Windows\\system32\\NetCfgNotifyObjectHost.exe", "hash_md5": "55790CBC7A189C0D546CD265FB946272", "hash_sha1": "DCCA6D8C7B8C4821323B316FF2DEF639EB8BD3F4", "hash_sha256": "9521687C6C6A0DD8B479A8F22734BD2A5582681FC239D9D67318A233FE5BB55E", "hash_sha384": "6EB96B57C277F0AEC001401FB3193B2FBFE839270BF0C77A7096F204592F750CF4102F705B49879616115F8D83C0D0F3", "hash_sha512": "81BA68FD4600151C61A5E7C65ADE55EE721078D6ACA1303642AB545E10E6EF267E1C960483E5246B6480CC13B3D5BACCED7FB893A0B0D71888FA49D7EA91BF29", "hash_ssdeep": "1536:gehrBT123JBqpfoI4g/5fGRwbXKcOfpXiHHLJD9RQ6:F1iJBYt/6cmXitD9N", "hash_imp": "AD6FBD678C8596994CD14FBBDFCA1A41", "hash_pesha1": "8A46C66E86E2C6FFDA9893351DF748DBEF15B597", "hash_pe256": "C88A5E38A2ABAFE703F8100CE764BFA40CE68EE04932B780F8693DC8E38F450E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Network Driver Configuration Plugins", "meta_original_filename": "NetCfgNotifyObjectHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/9521687c6c6a0dd8b479a8f22734bd2a5582681fc239d9d67318a233fe5bb55e/detection/", "runtime_modules": [ "C:\\Windows\\system32\\NetCfgNotifyObjectHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "netdom.exe-35FB6DCED4641EB20BE416AB9D10DD37": { "file_name": "netdom.exe", "file_path": "C:\\Windows\\system32\\netdom.exe", "hash_md5": "35FB6DCED4641EB20BE416AB9D10DD37", "hash_sha1": "98C0B7B2F4B0619AF3A1CECBAAFB51F4ADB473F4", "hash_sha256": "F2CAAFC70211041E0D4ED16EF6D6478BAF97D7C0C366DBFE24756D49F66FCEAC", "hash_sha384": "7E790313C7E1FF4259D51F10E81EF53D55ABCC3CE2082A9453D8DCDC0166E6701C0713A4DFCDD327C3FA9EAD3C87DF01", "hash_sha512": "1790910CE1B016499532AF6E097645DDF2764C9C4B40E9AF41BE12A5F5EC8751CAA74C4F42493EE5A400C9595A874E50154AD48EAD187D5579AD2DC2898F602E", "hash_ssdeep": "1536:qfjkEpEe1ZEI7oKbHo4KdCXMNoD4vT/3q+UeV2Zv27OTFsqIpk7:GjLGAoznZNVLhUeV2hKO2Npk7", "hash_imp": "C1C4CF9A5AC7CC782CC63223FAECF887", "hash_pesha1": "94AE2D60D11B5D88EB27E92127F4823A0E9ADA70", "hash_pe256": "A9B0A7B063E08EB6E99ED767114673E128623FDB2EF0BD7F3CA095E4280610D8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NETDOM5", "meta_original_filename": "NETDOM.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.503 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.503", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/f2caafc70211041e0d4ed16ef6d6478baf97d7c0c366dbfe24756d49f66fceac/detection/", "output": "The syntax of this command is:\r\n\nNETDOM HELP command\r\n -or-\r\nNETDOM command /help\r\n\r\n Commands available are:\r\n\r\n NETDOM ADD NETDOM RESETPWD NETDOM RESET\r\n NETDOM COMPUTERNAME NETDOM QUERY NETDOM TRUST\r\n NETDOM HELP NETDOM REMOVE NETDOM VERIFY\r\n NETDOM JOIN NETDOM MOVENT4BDC\r\n NETDOM MOVE NETDOM RENAMECOMPUTER\r\n\r\n NETDOM HELP SYNTAX explains how to read NET HELP syntax lines.\r\n NETDOM HELP command | MORE displays Help one screen at a time.\r\n\r\n Note that verbose output can be specified by including /VERBOSE with\r\n any of the above netdom commands.\r\n\r\n\nThe command completed successfully.\r\n\n", "runtime_modules": [ "C:\\Windows\\system32\\netdom.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\logoncli.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\System32\\bcrypt.dll" ] }, "NetEvtFwdr.exe-10D9999118819AC4C919278186BBA258": { "file_name": "NetEvtFwdr.exe", "file_path": "C:\\Windows\\system32\\NetEvtFwdr.exe", "hash_md5": "10D9999118819AC4C919278186BBA258", "hash_sha1": "24191CC77B7826C61BF485F5A3EB7234088E535D", "hash_sha256": "C1D31010BB094ED0208E9C177C865B49976F23EC22C67373600746109801EFE8", "hash_sha384": "1085892EA38B37D8C3CCBD96A425A48139139DF993F6686440E2EAC9021AFE1AC76D42D2CE0D91AC093CB331E13AC8E2", "hash_sha512": "29F26F2121EA339A1E5B8966FBA93792E9163DE4E9F75A1A42CC464DA78E7E7A004A723534DB448D6E71A31819D51398028B89C7ED195E633FAB1E44B4120074", "hash_ssdeep": "768:IW/IjGpQYmBM3BHn7QI99KdX/qMSbquZTX3K/b20QOQ2R0sCLg40m/uIQBSe:Z/IjGiBqxHVHUXEeqK/y0QOQ2R0sSOms", "hash_imp": "67B772554D7527AE78D3651C71F21024", "hash_pesha1": "45F6172331E27F6500BA5E0E89EB0495BA58A6D9", "hash_pe256": "F935B891DE73FDCCFC112E7C7D54CDAC7CA7C376A3B3492488E447D2FD0FE611", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Forwarder", "meta_original_filename": "NetEvtFwdr.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c1d31010bb094ed0208e9c177c865b49976f23ec22c67373600746109801efe8/detection/", "runtime_modules": [ "C:\\Windows\\system32\\NetEvtFwdr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "NetHost.exe-D7DDC0404F4F360DB6CE67130B176BD3": { "file_name": "NetHost.exe", "file_path": "C:\\Windows\\system32\\NetHost.exe", "hash_md5": "D7DDC0404F4F360DB6CE67130B176BD3", "hash_sha1": "A2746F1E4CD2AC26F385A93EF420C69E881B2265", "hash_sha256": "77264F41C4107B9C7E9ABC32E82CF0F6097F16902DE096F32BDD0EC298C07AD2", "hash_sha384": "C113C9E7C375DACB035AB19E206D1A538075785313D6A30DE850E1E9245630805D88E8E61A75CADFD3514E9A960CE45B", "hash_sha512": "49EA2601E4C994A105BCB879775A360D0F61D0F3DE328550F058B507BB95386A34853F5EFA64F12D17EB35CDF4FBFDE3B8C4D994FCABDBD36843B6CF60BAC5DF", "hash_ssdeep": "192:0Ukp7DelQmX+jF2ynCJHkyVXhGyEXkfhzWdvqW:0v36XaFdnWHBXh1fhzWdvqW", "hash_imp": "68873B7B30277427484800907F68E033", "hash_pesha1": "0FC5D22AF187CCEDC119B2A935C95B4F551A79CD", "hash_pe256": "A2B0399357D7819FB27D5549DFD0D73006BC13233E955010AC862FBBFEE3551C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EXE for configuring VPN proxy", "meta_original_filename": "nethost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/77264f41c4107b9c7e9abc32e82cf0f6097f16902de096f32bdd0ec298c07ad2/detection/", "runtime_modules": [ "C:\\Windows\\system32\\NetHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\RASAPI32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\rasman.dll" ] }, "netiougc.exe-1CC1B944D8642D9330D2B871A35D5A2C": { "file_name": "netiougc.exe", "file_path": "C:\\Windows\\system32\\netiougc.exe", "hash_md5": "1CC1B944D8642D9330D2B871A35D5A2C", "hash_sha1": "01AF61C7A3A33AA8C689722074BD24D8A39998AB", "hash_sha256": "43D706ADAE70DE7AF538E7AD02D7ED989A582E1108610E29597E8F11902DC783", "hash_sha384": "D63B7F79E6F188C7726AE1AC12CCEB955BD06EE45F3F24ACE143B23426EC55A7AAE7BC82E40BDBC817BDA96A0B676436", "hash_sha512": "B0DD4ABB468C4D1F6CD6A7504D400925837B46ACF7ADB75C2C06F3E34E3F5D38054AD81AD651AFEBF121CF2F18AE9265415238F38DC7A4E2771361E2FA60FC70", "hash_ssdeep": "768:ULcz1bM9RihRsjIt3gXEaJRphb/80Zwkj/3rvpQ:AQ1biijRZRaJFbr/7pQ", "hash_imp": "829B8AA7C4AE59A47DC478B664A94813", "hash_pesha1": "9B3E07DFBD42BF3E9C58DCC4A8E050639B33A73A", "hash_pe256": "5856F87CEA9C0D4F8D3B95562DD784A87D5F588FD94AF91828C2C35A93031BEF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Netio Unattend Generic Command", "meta_original_filename": "netiougc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/43d706adae70de7af538e7ad02d7ed989a582e1108610e29597e8f11902dc783/detection/", "runtime_modules": [ "C:\\Windows\\system32\\netiougc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\dhcpcsvc.DLL", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\wdscore.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\system32\\dbgcore.DLL" ] }, "Netplwiz.exe-A8581BA45F03CBC449DED52F9D09D4E0": { "file_name": "Netplwiz.exe", "file_path": "C:\\Windows\\system32\\Netplwiz.exe", "hash_md5": "A8581BA45F03CBC449DED52F9D09D4E0", "hash_sha1": "7D04FBC91A98B5BC7ED86E9E40C9D19F9B5DE1DC", "hash_sha256": "F0BDEAE93F385D0242E902DEAC742EE3A2D3B928996AB9A9F539ED26C496DAA1", "hash_sha384": "3232CBF72F9CE4BF952D53000F0ED1024898B400523CCEDDE412AB819C3BFFF2D37CCC12B914B71FFEC564557C1512FA", "hash_sha512": "4C3EFB45E1BE25B2EAAC09B384930FA9D4167C4AE85439BA1A9B764882AC4C7FDBB6A5581780360F925C7CD5CB732378D3FD0FF3F2AD69957EA7E229C03A7C3D", "hash_ssdeep": "768:+FoZk59am3Fe0HEIBsJWGDS2C+6BcryOfUrh6WeENiJDBPrxZt4G:WRR3z2JWnR+3ryReWSDBPrxZaG", "hash_imp": "33207161F1F01D54E759E316F16998D2", "hash_pesha1": "315CB743B3A49ABBF767D4FA77EBBA3E1B2EBF60", "hash_pe256": "1FED4E5174B0BA1C2559D6897AA7322AECC618A130448D84F2109EAD873BF7E9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Advanced User Accounts Control Panel", "meta_original_filename": "NETPLWIZ.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/f0bdeae93f385d0242e902deac742ee3a2d3b928996ab9a9f539ed26c496daa1/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\Netplwiz.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\netplwiz.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Netplwiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\NETPLWIZ.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\CRYPTBASE.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\DSROLE.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\SAMLIB.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\dsreg.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\SYSTEM32\\policymanager.dll", "C:\\Windows\\SYSTEM32\\slc.dll", "C:\\Windows\\system32\\sppc.dll" ] }, "netsh.exe-758B8449357017A158163ECC0E5E52B2": { "file_name": "netsh.exe", "file_path": "C:\\Windows\\system32\\netsh.exe", "hash_md5": "758B8449357017A158163ECC0E5E52B2", "hash_sha1": "21190DE3629B7A40409897CAF9563EB1EE1944B2", "hash_sha256": "D70D165B6706C61C56F2CA91307F4BBDB9846ACAE1DA3CFD84BF978FFB21AF23", "hash_sha384": "D5ACD229C559F8699783B4B072DE45CC6010F815ECFDBAAE3649BFC72AA1F3AE2833D30F3F8E77B09800A254FFDA1D85", "hash_sha512": "3A8CB1435A6503B9AC100E2CA49C347386143595E40AF81D8334F665740B414B3628DC4E461316E25A33DD9106B9D7D9B157067F368DD9ADB3FA5DC1B4DCC0F0", "hash_ssdeep": "1536:xb5iUv5pSTKh6SwRe2nrA56c6PlCNbiA9SDi:xb5i+7SToHwRe2n056vPlCdhke", "hash_imp": "90B4317BE51850B8EF9F14EB56FB7DDC", "hash_pesha1": "FD72D611DBDC94D9F3D23A749F2AEEBB8DDFCF90", "hash_pe256": "E59EC436DFC12EA561AAE563C414206636EF5A556509A01CA56E45FDD238B14F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Network Command Shell", "meta_original_filename": "netsh.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/d70d165b6706c61c56f2ca91307f4bbdb9846acae1da3cfd84bf978ffb21af23/detection/", "output": "\r\nUsage: C:\\Windows\\system32\\netsh.exe [-a AliasFile] [-c Context] [-r RemoteMachine] [-u [DomainName\\]UserName] [-p Password | *]\r\n [Command | -f ScriptFile]\r\n\r\nThe following commands are available:\r\n\r\nCommands in this context:\r\n? - Displays a list of commands.\r\nadd - Adds a configuration entry to a list of entries.\r\nadvfirewall - Changes to the `netsh advfirewall' context.\r\nbranchcache - Changes to the `netsh branchcache' context.\r\nbridge - Changes to the `netsh bridge' context.\r\ndelete - Deletes a configuration entry from a list of entries.\r\ndhcpclient - Changes to the `netsh dhcpclient' context.\r\ndnsclient - Changes to the `netsh dnsclient' context.\r\ndump - Displays a configuration script.\r\nexec - Runs a script file.\r\nfirewall - Changes to the `netsh firewall' context.\r\nhelp - Displays a list of commands.\r\nhttp - Changes to the `netsh http' context.\r\ninterface - Changes to the `netsh interface' context.\r\nipsec - Changes to the `netsh ipsec' context.\r\nipsecdosprotection - Changes to the `netsh ipsecdosprotection' context.\r\nlan - Changes to the `netsh lan' context.\r\nnamespace - Changes to the `netsh namespace' context.\r\nnetio - Changes to the `netsh netio' context.\r\nras - Changes to the `netsh ras' context.\r\nrpc - Changes to the `netsh rpc' context.\r\nset - Updates configuration settings.\r\nshow - Displays information.\r\ntrace - Changes to the `netsh trace' context.\r\nwfp - Changes to the `netsh wfp' context.\r\nwinhttp - Changes to the `netsh winhttp' context.\r\nwinsock - Changes to the `netsh winsock' context.\r\n\r\nThe following sub-contexts are available:\r\n advfirewall branchcache bridge dhcpclient dnsclient firewall http interface ipsec ipsecdosprotection lan namespace netio ras rpc trace wfp winhttp winsock\r\n\r\nTo view help for a command, type the command, followed by a space, and then\r\n type ?.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\netsh.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "NETSTAT.EXE-9244576DDD10643BCEABE63EC36950E6": { "file_name": "NETSTAT.EXE", "file_path": "C:\\Windows\\system32\\NETSTAT.EXE", "hash_md5": "9244576DDD10643BCEABE63EC36950E6", "hash_sha1": "E779B3B03CC8DB5CFE920E1CAB1169F66A20BB9F", "hash_sha256": "9372044B501FEFAE7333A59624379DBFC7E4ECCBEA965EE7058F2583709C2287", "hash_sha384": "0688A0EC78134C6A911B0F117481641D589B32E566C0F582848A97085D780CA5C5BDD7B3D74EC39C140307FE3220CB17", "hash_sha512": "41313807AC23F551FE63CC5E7C5863862793CFC936E7D59486784527AC5DE64B00DC4D23E78C44948929B554B65F0D4D041A7D89D059059499A495E1806C4382", "hash_ssdeep": "768:oCyJjjv6Nd/4GzTzvr+JcOCoORiGpU6OsOHphRiyRHJ:Xz3ycOC5q6tOHtiyRHJ", "hash_imp": "F495C58FFEE3A623AD7AAA6BE78756D5", "hash_pesha1": "2A3BD0E10F041E22857A071EC9E00D07A18FA66F", "hash_pe256": "7252EEDF33F3A7D1FE88633B789226FAE9D801B91DD0B705F6F02015719657D9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Netstat Command", "meta_original_filename": "netstat.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/9372044b501fefae7333a59624379dbfc7e4eccbea965ee7058f2583709c2287/detection/", "error": "\r\nDisplays protocol statistics and current TCP/IP network connections.\r\n\r\nNETSTAT [-a] [-b] [-e] [-f] [-n] [-o] [-p proto] [-r] [-s] [-x] [-t] [interval]\r\n\r\n -a Displays all connections and listening ports.\r\n -b Displays the executable involved in creating each connection or\r\n listening port. In some cases well-known executables host\r\n multiple independent components, and in these cases the\r\n sequence of components involved in creating the connection\r\n or listening port is displayed. In this case the executable\r\n name is in [] at the bottom, on top is the component it called,\r\n and so forth until TCP/IP was reached. Note that this option\r\n can be time-consuming and will fail unless you have sufficient\r\n permissions.\r\n -e Displays Ethernet statistics. This may be combined with the -s\r\n option.\r\n -f Displays Fully Qualified Domain Names (FQDN) for foreign\r\n addresses.\r\n -n Displays addresses and port numbers in numerical form.\r\n -o Displays the owning process ID associated with each connection.\r\n -p proto Shows connections for the protocol specified by proto; proto\r\n may be any of: TCP, UDP, TCPv6, or UDPv6. If used with the -s\r\n option to display per-protocol statistics, proto may be any of:\r\n IP, IPv6, ICMP, ICMPv6, TCP, TCPv6, UDP, or UDPv6.\r\n -q Displays all connections, listening ports, and bound\r\n nonlistening TCP ports. Bound nonlistening ports may or may not\r\n be associated with an active connection.\r\n -r Displays the routing table.\r\n -s Displays per-protocol statistics. By default, statistics are\r\n shown for IP, IPv6, ICMP, ICMPv6, TCP, TCPv6, UDP, and UDPv6;\r\n the -p option may be used to specify a subset of the default.\r\n -t Displays the current connection offload state.\r\n -x Displays NetworkDirect connections, listeners, and shared\r\n endpoints.\r\n -y Displays the TCP connection template for all connections.\r\n Cannot be combined with the other options.\r\n interval Redisplays selected statistics, pausing interval seconds\r\n between each display. Press CTRL+C to stop redisplaying\r\n statistics. If omitted, netstat will print the current\r\n configuration information once.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\NETSTAT.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\snmpapi.dll" ] }, "newdev.exe-FD9D8BCD91AC3ADBE818A312600908DD": { "file_name": "newdev.exe", "file_path": "C:\\Windows\\system32\\newdev.exe", "hash_md5": "FD9D8BCD91AC3ADBE818A312600908DD", "hash_sha1": "91779EC02A72435FFAA5FDA208FB25C574E325ED", "hash_sha256": "2CBF1FA6A259A39E14F3C02C6CD1BEF205F7C6BB4B922B61C2E5F17372503481", "hash_sha384": "1699F0F89CD246429CCA21BA36E098F7949E7FBB4C8B9D497239EEFD2A9E36F1A24DCC968298B69E7563E9162237DAEF", "hash_sha512": "50F35CB4097D6D22EF52D2A5199856CB1B13BE9E592783F233A35F32670F7D657E1E1E69BB9804BF552E7ED844B07A0F6D9FEA367644290CBD140FFD1F775BDD", "hash_ssdeep": "1536:Vaaowgx1sh/xgS5x2NCJfFrGUUUUUUUUUUUU3+:VQ1yx04Jh", "hash_imp": "48DD034AB19D7BA73498C3949ED8DC2B", "hash_pesha1": "320228C7711B137963491836E6A278F5C61A8A9E", "hash_pe256": "BC3AD11F06B2B116497B4B354859FA8A2CE96B958B0BEB7AE4A40A135BCF2964", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device driver software installation", "meta_original_filename": "NewDev.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/2cbf1fa6a259a39e14f3c02c6cd1bef205f7c6bb4b922b61c2e5f17372503481/detection/" }, "nltest.exe-D0F2751CA874BAFDB8A263BB1D2D1F87": { "file_name": "nltest.exe", "file_path": "C:\\Windows\\system32\\nltest.exe", "hash_md5": "D0F2751CA874BAFDB8A263BB1D2D1F87", "hash_sha1": "0D4290A96E7B6C4883787BA44739B45AA4B59903", "hash_sha256": "4E8AA26AD71243D13F7EC156C31ACBF1A0F1041303570E4E5CB910CC6D990567", "hash_sha384": "60DA2F7E80A483FC1A2885FF5DB73355C4F41F8ACDBAFBA2E25C21F1E49F30B51EC61DF4E94DB604135F9B08AB128B66", "hash_sha512": "68F4C2EFE149D6363D8CC051DE2C916C93D2BF10501A7920BE6757E5FC40E0B0D37967C56693103EF99F93816E99E7603030833CB21F17B895581C457CD8CAA6", "hash_ssdeep": "3072:a7Y8UIPeSjSfCo5VMWT/zJeOdrRrSH1rTvEXiEvFxG+5wIoJTrZPOdUoSn4g0LGN:a7DnsCkxjVOiUoYSKfSBuxPIF4VVT", "hash_imp": "97476B99B5801A0CF4E2172400A1BF78", "hash_pesha1": "1426D90AB12E46A701109E49B703092318274333", "hash_pe256": "2E9B660EA7C8BF6067B2E3E02DF7546E45FE9CF20E17BBCB8385C22A76C280E7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Logon Server Test Utility", "meta_original_filename": "nltestrk.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/4e8aa26ad71243d13f7ec156c31acbf1a0f1041303570e4e5cb910cc6d990567/detection/", "error": "Usage: nltest [/OPTIONS]\r\n\r\n\r\n /SERVER:<ServerName> - Specify <ServerName>\r\n\r\n /QUERY - Query <ServerName> netlogon service\r\n /REPL - Force partial sync on <ServerName> BDC\r\n /SYNC - Force full sync on <ServerName> BDC\r\n /PDC_REPL - Force UAS change message from <ServerName> PDC\r\n\r\n /SC_QUERY:<DomainName> - Query secure channel for <Domain> on <ServerName>\r\n /SC_RESET:<DomainName>[\\<DcName>] - Reset secure channel for <Domain> on <ServerName> to <DcName>\r\n /SC_VERIFY:<DomainName> - Verify secure channel for <Domain> on <ServerName>\r\n /SC_CHANGE_PWD:<DomainName> - Change a secure channel password for <Domain> on <ServerName>\r\n /DCLIST:<DomainName> - Get list of DC's for <DomainName>\r\n /DCNAME:<DomainName> - Get the PDC name for <DomainName>\r\n /DSGETDC:<DomainName> - Call DsGetDcName /PDC /DS /DSP /GC /KDC\r\n /TIMESERV /GTIMESERV /WS /NETBIOS /DNS /IP /FORCE /WRITABLE /AVOIDSELF /LDAPONLY /BACKG /DS_6 /DS_8 /DS_9 /DS_10\r\n /TRY_NEXT_CLOSEST_SITE /SITE:<SiteName> /ACCOUNT:<AccountName> /RET_DNS /RET_NETBIOS\r\n /DNSGETDC:<DomainName> - Call DsGetDcOpen/Next/Close /PDC /GC\r\n /KDC /WRITABLE /LDAPONLY /FORCE /SITESPEC\r\n /DSGETFTI:<DomainName> - Call DsGetForestTrustInformation\r\n /UPDATE_TDO\r\n /DSGETSITE - Call DsGetSiteName\r\n /DSGETSITECOV - Call DsGetDcSiteCoverage\r\n /DSADDRESSTOSITE:[MachineName] - Call DsAddressToSiteNamesEx\r\n /ADDRESSES:<Address1,Address2,...>\r\n /PARENTDOMAIN - Get the name of the parent domain of this machine\r\n /WHOWILL:<Domain>* <User> [<Iteration>] - See if <Domain> will log on <User>\r\n /FINDUSER:<User> - See which trusted domain will log on <User>\r\n /TRANSPORT_NOTIFY - Notify netlogon of new transport\r\n\r\n /DBFLAG:<HexFlags> - New debug flag\r\n\r\n /USER:<UserName> - Query User info on <ServerName>\r\n\r\n /TIME:<Hex LSL> <Hex MSL> - Convert NT GMT time to ascii\r\n /LOGON_QUERY - Query number of cumulative logon attempts\r\n /DOMAIN_TRUSTS - Query domain trusts on <ServerName>\r\n /PRIMARY /FOREST /DIRECT_OUT /DIRECT_IN /ALL_TRUSTS /V\r\n /DSREGDNS - Force registration of all DC-specific DNS records\r\n /DSDEREGDNS:<DnsHostName> - Deregister DC-specific DNS records for specified DC\r\n /DOM:<DnsDomainName> /DOMGUID:<DomainGuid> /DSAGUID:<DsaGuid>\r\n /DSQUERYDNS - Query the status of the last update for all DC-specific DNS records\r\n\r\n /BDC_QUERY:<DomainName> - Query replication status of BDCs for <DomainName>\r\n\r\n /LIST_DELTAS:<FileName> - display the content of given change log file \r\n\r\n /CDIGEST:<Message> /DOMAIN:<DomainName> - Get client digest\r\n /SDIGEST:<Message> /RID:<RID in hex> - Get server digest\r\n\r\n /SHUTDOWN:<Reason> [<Seconds>] - Shutdown <ServerName> for <Reason>\r\n /SHUTDOWN_ABORT - Abort a system shutdown\r\n\r\n" }, "notepad.exe-0E61079D3283687D2E279272966AE99D": { "file_name": "notepad.exe", "file_path": "C:\\Windows\\system32\\notepad.exe", "hash_md5": "0E61079D3283687D2E279272966AE99D", "hash_sha1": "B6D237154F2E528F0B503B58B025862D66B02B73", "hash_sha256": "A92056D772260B39A876D01552496B2F8B4610A0B1E084952FE1176784E2CE77", "hash_sha384": "D129C74C8B745BE2E03795096FEABBF6196A428A3C8BBA9ECE08C4AC7C1EC6C04248B7563EA51836BF7A533955C5DB9A", "hash_sha512": "95C4044BA8DE69D50F1099F9A932322D2891ADC86E58467E130EB7A41FDA72BC8B659CAE11B69E8A464833E53D1B7AAB905F2A458AA3AEFB9B0C428139D587C6", "hash_ssdeep": "3072:ClYcXcm6M8Poo69k7t+eJ3h4x7rDpljMceSJvkwEpNSLyhYsJLgf7nDVF6PUp1Yr:ClumDoz7PDO7pljMsfd455gfzDVlVXg", "hash_imp": "C8922BE3DCDFEB5994C9EEE7745DC22E", "hash_pesha1": "885382CFEC84300F1E9CFBF00D837B669EF25FB6", "hash_pe256": "99B02BF40B78BBC026FA08497DB6634650353A3264A589DCDA2FC9B6951543A5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Notepad", "meta_original_filename": "NOTEPAD.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a92056d772260b39a876d01552496b2f8b4610a0b1e084952fe1176784e2ce77/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\notepad.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\RPC Control\\DSEC11B0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\notepad.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\WINSPOOL.DRV", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\urlmon.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\system32\\CRYPTBASE.DLL" ], "runtime_window_title": "Untitled - Notepad" }, "nslookup.exe-AD20D425C3012EE191535AD65E56DEBB": { "file_name": "nslookup.exe", "file_path": "C:\\Windows\\system32\\nslookup.exe", "hash_md5": "AD20D425C3012EE191535AD65E56DEBB", "hash_sha1": "9A3BE34E8316EBB945A4D5818A4066C91FE98C95", "hash_sha256": "54DAF167F8DBE7FE0F23B37A600BD8D9D16B756D3B83F0804B5037CBBE895EB6", "hash_sha384": "3389C98384E113765999B5F313078BBF667BACC75C51A64AC80C11B23C428C2DBAE394EA350356CC6F37CAC7F98C6C0A", "hash_sha512": "FC6C0C4CD72803F411F3E9BC30940B2C18C3EA3C5D692AEF7301EC13763D3EDFF341F341E0E2DDFD3A89FD1230FF7F0BB4196E9C548CE550216A79A73E14C25C", "hash_ssdeep": "768:3xx2FQe580dMI0GA4/YQFRWsWlYviTs3lvW22Mn1tZRyNXVkjheTFRYnM0qLdYG6:wazQFSI1j/cFRy9ydF9+5lK2hJLxf", "hash_imp": "F9A02896E71DF610AF20835CEAEF5BE9", "hash_pesha1": "957A8337DBB7F3378EAE64EB17EED2842C6A08FF", "hash_pe256": "5ADB10A6860293DF7CFA3B66F22AF056DCFFF4818E28F273925539470489D1CA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "nslookup", "meta_original_filename": "nslookup.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/54daf167f8dbe7fe0f23b37a600bd8d9d16b756d3b83f0804b5037cbbe895eb6/detection/", "error": "Usage:\r\r\n nslookup [-opt ...] # interactive mode using default server\r\r\n nslookup [-opt ...] - server # interactive mode using 'server'\r\r\n nslookup [-opt ...] host # just look up 'host' using default server\r\r\n nslookup [-opt ...] host server # just look up 'host' using 'server'\r\r\n", "output": "Default Server: ip-172-31-0-2.us-east-2.compute.internal\r\nAddress: 172.31.0.2\r\n\r\n> ", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\nslookup.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\nslookup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\MSWSOCK.dll", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\dhcpcsvc6.DLL", "C:\\Windows\\SYSTEM32\\dhcpcsvc.DLL", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\WINNSI.DLL" ] }, "ntoskrnl.exe-87A2EA32A2FD980E6D373A3CB3A370AF": { "file_name": "ntoskrnl.exe", "file_path": "C:\\Windows\\system32\\ntoskrnl.exe", "hash_md5": "87A2EA32A2FD980E6D373A3CB3A370AF", "hash_sha1": "AEE8B64BB4A4C66EDB68EF2570CC9345E22B6B9F", "hash_sha256": "0E039C3BBD86D31CEB8F3FD2046134D067EE41EBD974597E59F6518B4D9B60B7", "hash_sha384": "392B334B570DEDA1D5ED60F33D4E867A716F34084692BF691250396AB628A06DBB38BE28FF4D53E7DE4B8AC0C9A7D290", "hash_sha512": "C514EF205D27C6880140AFE3EE8DB5CC6CEC60065AB615CDDC40EBC2BBD6718E458EF645F3A6093AB58F44299D70B0728182263F37AE41EBC941F0C04385BF01", "hash_ssdeep": "98304:CMe7W9UTG0Ka5Sj+Y6TmqHiqSpRbXR0HGWF6NRUL+jE7Or:ClVG0KaTaS6bB0HGWF6NaKjEqr", "hash_imp": "4D717BA02FC8AA76777B033C52AA4694", "hash_pesha1": "313A04DAAE83E27DF425343C0FD1D1C8363F6ADB", "hash_pe256": "417758D845E8CED56D2E8E82D9A19DBF40FE92DDD4D096FEE45AE19915FE7078", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NT Kernel & System", "meta_original_filename": "ntkrnlmp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/0e039c3bbd86d31ceb8f3fd2046134d067ee41ebd974597e59f6518b4d9b60b7/detection/" }, "ntprint.exe-2E2ECAA11EF51F60ABB73C29AA20002B": { "file_name": "ntprint.exe", "file_path": "C:\\Windows\\system32\\ntprint.exe", "hash_md5": "2E2ECAA11EF51F60ABB73C29AA20002B", "hash_sha1": "40942A75A9007507CAE486231C0EAAC49E8D74B6", "hash_sha256": "2393676C8C888142363980E0E72279E6F9743CA5215C88BE2CB13F89540F3A70", "hash_sha384": "89C47D1F9EE3F2B8268A7306CFCE1D2E28C5483EB33EE9B5FB8B0D3B36B485E3D77305FD780067821F31040623B3C56A", "hash_sha512": "B26BCFCFCBC4D88C0845110DB30DA9AFE719F4A6EF5F76526BA8684A29710B125DEC0CBE0E2A767A9948539BFF9B76DE8D08727D7EEAD355668D5B4D45B3624E", "hash_ssdeep": "768:U29O2D7w4r95vI1iQfCIWVM9G4qW4ne+S/ly+PKAoXRZX6fbX57UWkCRPPA7/QnR:UcO2XvxVIPd4n+lbeRZIbSQPPA78", "hash_imp": "598CA250C4CE0ED92CFA650D081AD874", "hash_pesha1": "39EDFE4560DB57094AC2A8714F69B75C1F7D3689", "hash_pe256": "85A99AC9037070363B96D0986B12F07C915CCE1ED5201DEDEDE3DF0822B828A9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Printer driver software installation", "meta_original_filename": "ntprint.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/2393676c8c888142363980e0e72279e6f9743ca5215c88be2cb13f89540f3a70/detection/", "runtime_modules": [ "C:\\Windows\\system32\\ntprint.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "odbcad32.exe-4BE67E1672D32EBEB5D8EE8317B2760A": { "file_name": "odbcad32.exe", "file_path": "C:\\Windows\\system32\\odbcad32.exe", "hash_md5": "4BE67E1672D32EBEB5D8EE8317B2760A", "hash_sha1": "9890A8FBCF1B172D95616627F89EC6A723A4DF14", "hash_sha256": "E98522037AC6DE502178B3DB469C54C7F6F1FCDCACA302C96ED0A9CD1C2E3E45", "hash_sha384": "ED11D78405457F8B1F35D079FBBB3436371F23E25F4BE582B12AB9D4B159FC1F9958261B2E902098B636D7840D8975D6", "hash_sha512": "DA0C91717D49E9585BF713FD7AB2062C2F3F187B80F739BAACBB81FE2267B6E2D58FB4457349DF5F9A5BD4A865AD18A82A0343FC75138397CF9FA02DA8B0FCE0", "hash_ssdeep": "1536:N928khYf0Dytv3Jrz6q9EyYt9FlUIlbvBjIloW:u8F0UUKI9jo", "hash_imp": "69FEEBD40FEB17DCC302C7A64D65BD53", "hash_pesha1": "4979DD26F7092FE9AC16F28A466FD4CA68E9EE36", "hash_pe256": "42A7BA0B013F167E47001289FE10DF22D1A1E6883F7B5B540FDF53CECBF34345", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ODBC Administrator", "meta_original_filename": "odbcad32.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e98522037ac6de502178b3db469c54c7f6f1fcdcaca302c96ed0a9cd1c2e3e45/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\odbcad32.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\odbcint.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\odbcad32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\odbccp32.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ], "runtime_window_title": "Microsoft ODBC Administrator" }, "odbcconf.exe-55A9886E094558260AA43A20B76F388D": { "file_name": "odbcconf.exe", "file_path": "C:\\Windows\\system32\\odbcconf.exe", "hash_md5": "55A9886E094558260AA43A20B76F388D", "hash_sha1": "650D9F1B851355BFA85C203782952E55E7C65E22", "hash_sha256": "40274D2B55355D30230CEE9C75335290C0692F6D7CFE5FAA529A582D9CDAA232", "hash_sha384": "BBFBDA14C80D13396280B83423B777E9CC8729D0269DE5570B69E4D2A7ECBF6347FD736BD5FB63F1BA35E7013C5C55C4", "hash_sha512": "7040FD42732B424200958C2CB39A8B7FB7D28DD5B370F06A90B86BA9035E8AD2942738189A098AF54DBDE5B707DFB7FBCFC4BD598C3182B50A9FC2DA58BCFC58", "hash_ssdeep": "768:FCr3bf1LVAj09N+b8sI/mv9JNBmCPx9NS:FmhLVAQ9N+AmvTmCNS", "hash_imp": "09AE8655C843B33D7FA4CDD4F87AD0BF", "hash_pesha1": "AA2E773739DB68BFAC5F1E66959EF76F71B471AD", "hash_pe256": "CC90893CEE6188ACC18F77C1DAED0D704AA56A5FA8C1B3357A71195F31244EA5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ODBC Driver Configuration Program", "meta_original_filename": "odbcconf.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/40274d2b55355d30230cee9c75335290c0692f6d7cfe5faa529a582d9cdaa232/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\odbcconf.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\odbcconf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\odbcconf.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ], "runtime_window_title": "Invalid Parameter" }, "omadmclient.exe-976713BD9379685B2ED4F64C1C8E4EC9": { "file_name": "omadmclient.exe", "file_path": "C:\\Windows\\system32\\omadmclient.exe", "hash_md5": "976713BD9379685B2ED4F64C1C8E4EC9", "hash_sha1": "AD828BCB37875F3EEC2E17F8B7201AA394DB5DF8", "hash_sha256": "C4FA3F2B3569CF99E865709D437E2D60D432AB4D48DFCC56B0DD2F316BC76F42", "hash_sha384": "67F540E100340BA627208689A185752E5CFC58C7C8BD1CB817287DFA5EC7EB12A87C7C8D71F1967E507B6167278CD412", "hash_sha512": "C20A88F1A11D5EB3A6F3EDE31EF04CB1F47A7CD31027FA6AF0AC6584FEB5630F2DE79724616833AB387C9F5640BEF7496CDD78E77BCC818CA67B73E2C0A669D4", "hash_ssdeep": "6144:59To+0WweMP/89Qra08RNp2DHQNNzGdVC2gQQOQ2Fj8hk:vo+0fdM9W8bp2D2Caij+", "hash_imp": "79279C5010EF9943019EDA59666C2560", "hash_pesha1": "5A4D31C42AA5DA619F3AF7C8D377A1181BAD22E9", "hash_pe256": "0BD2FA045D8B9FC3FDC5FEADA98EDE1005714D1B3CC341E4703F4E34B05335B4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for OMA-DM Client", "meta_original_filename": "omadmclient.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1432 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1432", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/c4fa3f2b3569cf99e865709d437e2d60d432ab4d48dfcc56b0dd2f316bc76f42/detection/", "runtime_modules": [ "C:\\Windows\\system32\\omadmclient.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\system32\\coredpus.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\system32\\dmiso8601utils.dll", "C:\\Windows\\system32\\dmEnrollEngine.DLL", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\dmenterprisediagnostics.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\DMOleAutUtils.dll", "C:\\Windows\\system32\\policymanager.dll", "C:\\Windows\\system32\\DMCfgUtils.dll", "C:\\Windows\\system32\\iri.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\dmxmlhelputils.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "omadmprc.exe-57E94ADD4AD74521156BAB12142A8C10": { "file_name": "omadmprc.exe", "file_path": "C:\\Windows\\system32\\omadmprc.exe", "hash_md5": "57E94ADD4AD74521156BAB12142A8C10", "hash_sha1": "62E0451A629A725F03E7946D0B1BDA3B7255CC3B", "hash_sha256": "1EEF86C7E1736D42DC5C061D7FA29D6DB13BF4B0FEC0136A6A172735686B1F1C", "hash_sha384": "567DAEDCE0C5410648DC1883317CFF28B34756A262C48A38F0F0EDEF2A659B3A3005A2B0F56A7ADF44CF57BE00EF854E", "hash_sha512": "EDDA17548CB01ECD28F5D4339563C7504BC34CBD606B2EDB48A49DBA1DB78C2A58A997B393252985F921DF3214B5561A5F3C5FE1D5D74DEBABAEFB50ADE0AD12", "hash_ssdeep": "1536:3/ywGvuhy/a9FEQZ2nrEmxv/GKr3qCh779CO+edTniyJ+GHpqc9TYS:z8u2O2xvesp1+edTniGbUc99", "hash_imp": "6B29C7AFC9F9971B08BB9F9E09A90989", "hash_pesha1": "8B262FDD721745D30C8A3062A18F99E89D7C3761", "hash_pe256": "907ADE0F03F14978AE1412C43AD884ADE9BCD6939988EF93156231F5642BEDEA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Push Router Client of OMA-DM", "meta_original_filename": "omadmprc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/1eef86c7e1736d42dc5c061d7fa29d6db13bf4b0fec0136a6a172735686b1f1c/detection/", "runtime_modules": [ "C:\\Windows\\system32\\omadmprc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\DMCmnUtils.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\DMPushProxy.dll", "C:\\Windows\\system32\\omadmapi.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\msvcp110_win.dll", "C:\\Windows\\system32\\iri.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "openfiles.exe-057FE584AACC6B6ED44C2349C5F2DECD": { "file_name": "openfiles.exe", "file_path": "C:\\Windows\\system32\\openfiles.exe", "hash_md5": "057FE584AACC6B6ED44C2349C5F2DECD", "hash_sha1": "031BEA77B801D2401400CE2B25A10A6D543F6266", "hash_sha256": "4B27C43035B1C35D4F3185709F7D097BB52751A066180F4979A5AD49FF8C5A62", "hash_sha384": "AA26A6E6A1F9B804CFC5EC1F06CBEE21822CC05D15908B5C602EFE2526675B2A250F851C01284F51F5098539B7F818B5", "hash_sha512": "16908444FD15378AACF52ADDEE534DFA008F3B33C4F2392D003CA1DDCA3FB605713D40722F86EB48139A274A6432BE7259A322989F20590E18F42D11B17583C4", "hash_ssdeep": "1536:N/xGaUDxpvZowbaepliAjPYDSINH7LEbv9efZWbgjxzCLC:TGa0NcDHxLECWbgjxGO", "hash_imp": "A7F4C437854AA08D24A43D35AF38A943", "hash_pesha1": "C67B456BD0CFF1C83EB39AEA9023C3569C6A5482", "hash_pe256": "FFFDEF679EB1F8EC65D294B8F03A2138C7C391C8CED0651C3AE610B6EE69BEA2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays the current open files list", "meta_original_filename": "opnfiles.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/4b27c43035b1c35d4f3185709f7d097bb52751a066180f4979a5ad49ff8c5a62/detection/", "output": "\r\nOPENFILES /parameter [arguments]\r\n\r\nDescription:\r\n Enables an administrator to list or disconnect files and folders\r\n that have been opened on a system.\r\n\r\nParameter List:\r\n /Disconnect Disconnects one or more open files.\r\n\r\n /Query Displays files opened locally or from shared\r\n folders.\r\n\r\n /Local Enables / Disables the display of local open files.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n OPENFILES /Disconnect /?\r\n OPENFILES /Query /?\r\n OPENFILES /Local /?\r\n", "runtime_modules": [ "C:\\Windows\\system32\\openfiles.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "error": "ERROR: Invalid syntax.\r\nType \"OPENFILES /?\" for usage.\r\n" }, "OpenWith.exe-2CBE77C5FE6617C174954532A0C189BB": { "file_name": "OpenWith.exe", "file_path": "C:\\Windows\\system32\\OpenWith.exe", "hash_md5": "2CBE77C5FE6617C174954532A0C189BB", "hash_sha1": "96328A6316797B1AD90DF0FE7855F36D01D77A44", "hash_sha256": "79F13786B0EE6EB813ECD90C739FF48F078DFAE6B8F7AEDFEB526FFE86B81EB2", "hash_sha384": "841A6014E066AF113F1AA9C28DB8D910C86877AB07AA98241DD7E268299701B606ACDB8AACE23CC21154AA9355A1981D", "hash_sha512": "6FC291FD91EF219440D15D46EB7C6C478BA428C0E03F2B59D773CC3096538D3053D5A59A393BDF3994531DE6838AB0D6DE2D9E87F9341756F990A8005C390914", "hash_ssdeep": "1536:dDI9ao9Lv8OUqKRrorQoTyU46iz7bKp3GcaBaLy5tpzKQfKQTzBNer+CE+Ge+z8J:89wOmorFWlY3GcaBBkkrer+CE+GF8Vz", "hash_imp": "A77B6C517B9F2590BF7CEBD852A3DD71", "hash_pesha1": "47CEBA7C05AEDAD09E6985C0A0789537082AF4C8", "hash_pe256": "095E661118F97C30A251A368245D29061C14B8735E1AB0817A83AA7D4690717E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Pick an app", "meta_original_filename": "OpenWith.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/79f13786b0ee6eb813ecd90c739ff48f078dfae6b8f7aedfeb526ffe86b81eb2/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\OpenWith.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\RPC Control\\DSEC9E0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\Windows.UI.Immersive.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Windows\\System32\\en-US\\twinui.dll.mui": "File", "(RW-) C:\\Windows\\System32": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_32.db": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(RWD) C:\\Windows\\Fonts\\seguisb.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\OpenWith.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHCORE.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\twinui.dll" ] }, "OptionalFeatures.exe-F5E6A72C8DC8F430EB2C56958665EBA6": { "file_name": "OptionalFeatures.exe", "file_path": "C:\\Windows\\system32\\OptionalFeatures.exe", "hash_md5": "F5E6A72C8DC8F430EB2C56958665EBA6", "hash_sha1": "665ABC9724947087381110ABBDFEE0B1EC54FEBD", "hash_sha256": "AA82381AEFF9D1908F76D5FFCF7DBF2492CE4725AF7DF06818E6D574B97EA1CB", "hash_sha384": "EC5E9EBEA0EF12E3823C17F0A47513D02BEEA52DE2FF14B9E0494194A2D467ABB2345CB90231D6621FD951DB0038CCED", "hash_sha512": "93A7CA1D2898A572F26426B81783B6AB63CBFFC74F7A318CC95CC9C928AD897C08C29C5F2CB265954C39CC99DD21FC38EA2521A4C75FB3C0558C76F733A03664", "hash_ssdeep": "3072:TFHbEbEaznWfH22ZsuX2xKwMPTnaSrIrvDe:J7KznWjZnXeKwMLnaqY", "hash_imp": "B1DA23E5BF146552E38FA70DEE47601E", "hash_pesha1": "A2836E0E0FE37DF9786293CD43D270CA0BF2205C", "hash_pe256": "B971805EEEFB5DFA684B579112A2B217E90AB884259A917B94DCCB70EE1C5A2F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Features", "meta_original_filename": "OptionalFeatures.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/aa82381aeff9d1908f76d5ffcf7dbf2492ce4725af7df06818e6d574b97ea1cb/detection/", "runtime_modules": [ "C:\\Windows\\system32\\OptionalFeatures.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\appwiz.cpl", "C:\\Windows\\System32\\SHCORE.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\system32\\osbaseln.dll", "C:\\Windows\\system32\\DUser.dll" ] }, "osk.exe-B160BA195ACC126E2ECA539094914688": { "file_name": "osk.exe", "file_path": "C:\\Windows\\system32\\osk.exe", "hash_md5": "B160BA195ACC126E2ECA539094914688", "hash_sha1": "80BB21B6B77A671765219517D0D8E064E22396E2", "hash_sha256": "79C62BDE821FBB73CCD72621E4EDDFF3D5DAE7B915BB7620084FA72E324B3CC0", "hash_sha384": "43C20D2783F395B86D98065837ADE6932B900AE41EC55C0597CD19F4935C68E1AA9908C84E699F408300E95934A93521", "hash_sha512": "579CD2E5A17F35D7A2487B229D3018D974A7A44D3380F2D697061B54D81E72FA472D8AEA59006F15FFB688E1C17E2CF9FC5E6CCA7A9072A59EEBB6DA10D1201B", "hash_ssdeep": "6144:Yb/lKGivRTnrr1hf7Wc1OcvH3AdKy9HGeofJgDEvr6slnCUGw/xIRLtxIRLuovZ:I9KGMRTXQjmNwzaoo", "hash_imp": "43F678788A11C4B7A238705AFC2BE436", "hash_pesha1": "39623A1092AF6297730BBEC201290E2E00D5165E", "hash_pe256": "EBB2599536EF8C4810FC3A8191F64F56156E81ACB7A5EA730924661CA2A6FB92", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Accessibility On-Screen Keyboard", "meta_original_filename": "osk.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/79c62bde821fbb73ccd72621e4eddff3d5dae7b915bb7620084fa72e324b3cc0/detection/" }, "pacjsworker.exe-AB205B08FCDF1A81B380557ACD05F68E": { "file_name": "pacjsworker.exe", "file_path": "C:\\Windows\\system32\\pacjsworker.exe", "hash_md5": "AB205B08FCDF1A81B380557ACD05F68E", "hash_sha1": "2E0E637FEC6D135FBD7E8A8034F3F7953B90B982", "hash_sha256": "FF4D515CDCBE9CE053D9CC4D3412F962875098AC87133019EEB12A0F9494BB91", "hash_sha384": "B9C0620BC6EBD0BE63B030048010EA9345D0BC73A487C0C3545081498FC2DABBECEB12CCE04ED29CEC08ED7E7658FC46", "hash_sha512": "CB310EDDE3F571E54D16C69E40F10908B2E8B235F8E65D594B5AEB5F0964F55FA4089B566081466AD5167E771D5C481F457AE8E7722D4E4B2FB8F778FDCDCFAB", "hash_ssdeep": "192:5YUGvPC1gAnUAV8NvdwZT1yE9cBqWauAW:qDAnU08OcIWauAW", "hash_imp": "8C60A21850D55B0FB469B1E4A95BC2F5", "hash_pesha1": "F250160C4D0903AFD7018D64E068CF52DAC9027A", "hash_pe256": "54969EE65C0E4361B96375E2CBD9D7ADCC83991D11806487A44899BDE868948F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "HTTP Auto Proxy Detection Worker Process", "meta_original_filename": "pacjsworker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/52", "filescan_vtlink": "https://www.virustotal.com/gui/file/ff4d515cdcbe9ce053d9cc4d3412f962875098ac87133019eeb12a0f9494bb91/detection/" }, "PackagedCWALauncher.exe-6569775445662605B4876BF9EACCA767": { "file_name": "PackagedCWALauncher.exe", "file_path": "C:\\Windows\\system32\\PackagedCWALauncher.exe", "hash_md5": "6569775445662605B4876BF9EACCA767", "hash_sha1": "A374865EE93279A432B735F7A085939548482255", "hash_sha256": "B3C953E34AE93919586941129884FAE101A410C93AF0A2975C190BA31A32C65A", "hash_sha384": "BF3C30BBD1A92AAFEDC4B06379F6C2F3CFCAB83E60405285D855B522EB4F2D8889554E451DE93EA301CEBB98E5D8D548", "hash_sha512": "80B2DBA2BD249827EC38789C8EF084B82841ECDDE3AD28BB9AE6BC8AFE14008DAEC173E7188354AB0FC32510825E0B53F8116F24AFB93505302A8D98919F2C2E", "hash_ssdeep": "768:VFFwTnzuHfbl20V2Ks0KZr39SUY6S23VgLrNUS0qMUi:PyIfbQz5ZrNSUYM3VgH+S0qW", "hash_imp": "85200C522AEECEDFF4551238547F8E74", "hash_pesha1": "DAA08BC2749CEB46C825810269B82871874A2E02", "hash_pe256": "7C27C6C1834742A8B4381383DAA4BF9C04E561A70004483BD1C2CF2FB06976BE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Packaged CWA Launcher", "meta_original_filename": "PackagedCWALauncher.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/b3c953e34ae93919586941129884fae101a410c93af0a2975c190ba31a32c65a/detection/" }, "PackageInspector.exe-13ED5BF602AA9FC2DDD673CC756E8463": { "file_name": "PackageInspector.exe", "file_path": "C:\\Windows\\system32\\PackageInspector.exe", "hash_md5": "13ED5BF602AA9FC2DDD673CC756E8463", "hash_sha1": "E874CA3952F8CB00EE78E1FE681AA7E6C319F6C6", "hash_sha256": "758D9E687DC94A11CEE15E4D415FB619C64E854A6D642E42CB83F4838E4E4C4F", "hash_sha384": "F00AD0025917E86938DDDE52B179F731D70C5AE70C9F9B0CEC6AF9A7668096BA44A2830BC0044615D6757B449A922E21", "hash_sha512": "C2EF1E8D6A82A940547EDBF2BDF463F22F2A29161A3E631BD5075AD14242772A0006D18A570ACEC4943272952F44846DD44988E45894B308746DCA28126E1D1A", "hash_ssdeep": "1536:43MYxS09QtinMKpk0iz0+Ni9k+ql+l4cPAWWJIVKRn:YZSGQtoMtK+Ni6j+l42xWJIVKB", "hash_imp": "78DC365E842607A715DB0094139A0709", "hash_pesha1": "4CCEEF2B3CD06F3A8F227DC6889B6B2CE64B2E61", "hash_pe256": "2ACCA548F2F1346A2B9D0F76A3C05B46669DFA138172F422603DA430519D15C8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PackageInspector allows creation of a catalog containing all executable files laid down by an installer", "meta_original_filename": "PACKAGEINSPECTOR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/758d9e687dc94a11cee15e4d415fb619c64e854a6d642e42cb83f4838e4e4c4f/detection/", "output": "Usage:\r\r\nPackageInspector.exe <command> <DriveLetter or Path> [options]\r\r\nPackageInspector.exe start <DriveLetter>: [-path <pathToInstaller>]\r\r\nPackageInspector.exe stop <DriveLetter>: -out cdf|cat|list [-cdfPath <outputCdfPath>] [-name <nameOfCat>] [-resdir <directoryForCat>] [-ph true | false] [-en <encoding type>] [-ca1 <CATATTR1>] [-ca2 <CATATTR2>] [-listPath <pathToOutputList.txt>]\r\r\nPackageInspector.exe scan <PathToScan> -out cdf|cat|list [-cdfPath <outputCdfPath>] [-name <nameOfCat>] [-resdir <directoryForCat>] [-ph true | false] [-en <encoding type>] [-ca1 <CATATTR1>] [-ca2 <CATATTR2>] [-listPath <pathToOutputList.txt>]\r\r\n\r\r\nValid Commands : \r\r\n\tstart \t--\tSpecifies that a user will start a scan\r\r\n\tstop \t--\tSpecifies that a scan is complete and one of the supported outputs it to be produced\r\r\n\tscan \t--\tSpecifies that PackageInspector is to directly scan the given path rather than monitor created files. Takes same options as stop\r\r\n\r\r\nStart Options : \r\r\n\tpath \t--\tFile path to the package being inspected\r\r\n\r\r\nStop/Scan Options : \r\r\n\tout \t--\tSpecifies what the tool should output from the scan (CAT, CDF, or List)\r\r\n\tcdfPath \t--\tSpecifies the full path for output of CDF including filename\r\r\n\tname \t--\tSpecifies the name of the catalog to produce\r\r\n\tresdir \t--\tSpecifies the result directory of the catalog\r\r\n\tph \t--\tSpecifies whether page hashes should be included in the catalog\r\r\n\ten \t--\tSpecifies the encoding type of the catalog\r\r\n\tca1 \t--\tSpecifies CATATTR1 in the CDF or CAT\r\r\n\tca2 \t--\tSpecifies CATATTR2 in the CDF or CAT\r\r\n\tlistPath\t--\tSpecifies location to output list of files laid down by installer (for -out list)\r\r\n" }, "PasswordOnWakeSettingFlyout.exe-FC7528E89D3DEDB5F1ECDB9078492226": { "file_name": "PasswordOnWakeSettingFlyout.exe", "file_path": "C:\\Windows\\system32\\PasswordOnWakeSettingFlyout.exe", "hash_md5": "FC7528E89D3DEDB5F1ECDB9078492226", "hash_sha1": "BE2D70E152BB76E6CDB3B58ECAB58F7AE6B4A184", "hash_sha256": "93E37875D30884F2B748A4BABDB8777D0D5EB2683F54283A032C0433A058D01F", "hash_sha384": "5DEDF8E84CA2E8078B5B48FC1B4ADB3E1F4CF3A963F3A257755A82728E897C161C698A43D63E087EAA118F03005D0597", "hash_sha512": "CA0824CB1EC47819C6C1A9A2DEF32DDEEB2A90AB5AF5A1E45B090881A9E4F88A22900287EF6E822DCCBE9BAB75B3C8BE39A59000B068A7FE6BFEF761DEA82BBB", "hash_ssdeep": "768:F0JLsZWvx4I5UD5iVibsTLg7cVvoumrGBW80VaRx0HcMZJinUnI1Pk2:zW54bijgMmrlb8Rx0NZ0nUQPp", "hash_imp": "EFBB2AE327C24AC043BA293919F6DEDD", "hash_pesha1": "FC1D9A7C0824C121F1249BDA06D67AA2E9EA0E82", "hash_pe256": "0B453212D1382A91866572BA9CFC7DEE2B201C241B7FCE0BEDF1254E025211D2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "User CPL Password on wake setting flyout", "meta_original_filename": "PasswordOnWakeSettingFlyout.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/93e37875d30884f2b748a4babdb8777d0d5eb2683f54283a032c0433a058d01f/detection/", "runtime_modules": [ "C:\\Windows\\system32\\PasswordOnWakeSettingFlyout.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\DUI70.dll" ] }, "PATHPING.EXE-5FB848A0BC3322AD439CD83602B2B420": { "file_name": "PATHPING.EXE", "file_path": "C:\\Windows\\system32\\PATHPING.EXE", "hash_md5": "5FB848A0BC3322AD439CD83602B2B420", "hash_sha1": "411F82573E003FB6BE7294EA335143F3F6355AC5", "hash_sha256": "96A0FA913D1688D61496B0001F5264FC1727C9A7AF9232D1EB02811252ED1908", "hash_sha384": "FD944F062FF4B8FC0C81F4467245C118AE06D3EE7EA59DF7D66DE3248434C221CD7C53A73106C491B14755C3E688619D", "hash_sha512": "391AE1C8CA8C39DBACA9CCE8F14EFB048F6D8C56B3206BD0E432B2EEE5BE223516303099E88A1ACC9499B4F598DE12BBFDDB867D5A45FC8A189BC2694C5FE881", "hash_ssdeep": "384:dmSjRRQsfowYYmUO68sd2HMWU6ltmTL8SdxW6AW:BY+LdL+4TL8I", "hash_imp": "527F94868035A5EFB9B24DFA6322F29D", "hash_pesha1": "765D87E1C72DE0F6D71FB333053BF387AAEE0C9F", "hash_pe256": "400AFDB027767975109C89D67C661C9F964058094E1B42977DC81140A1AB08BC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP PathPing Command", "meta_original_filename": "pathping.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/96a0fa913d1688d61496b0001f5264fc1727c9a7af9232d1eb02811252ed1908/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\PATHPING.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\mswsock.dll", "C:\\Windows\\SYSTEM32\\DNSAPI.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\System32\\rasadhlp.dll" ], "output": "--help is not a valid command option.\r\n\r\nUsage: pathping [-g host-list] [-h maximum_hops] [-i address] [-n] \r\n [-p period] [-q num_queries] [-w timeout] \r\n [-4] [-6] target_name\r\n\r\nOptions:\r\n -g host-list Loose source route along host-list.\r\n -h maximum_hops Maximum number of hops to search for target.\r\n -i address Use the specified source address. \r\n -n Do not resolve addresses to hostnames.\r\n -p period Wait period milliseconds between pings.\r\n -q num_queries Number of queries per hop.\r\n -w timeout Wait timeout milliseconds for each reply.\r\n -4 Force using IPv4.\r\n -6 Force using IPv6.\r\n" }, "pcalua.exe-1E9E8B2CFCFDA570B5E07C014770A1B3": { "file_name": "pcalua.exe", "file_path": "C:\\Windows\\system32\\pcalua.exe", "hash_md5": "1E9E8B2CFCFDA570B5E07C014770A1B3", "hash_sha1": "E6A15B8FF17F8656458581FC0B97B0852F69F362", "hash_sha256": "36EF04735ADFFF417AE761BF6595BADB54A4CCEB3550ABA7CFD4F7234C90EE7D", "hash_sha384": "C12C54FCDB0869AC6D8C688FB39642D5B339EA8792C07BA0E5DCE204F3D7EC3E73B74A3C2B3468B64E33F01681E2A425", "hash_sha512": "3AB25ABEB9764B33A059BA94754ADB73A14D965F908BD36E69132BC2A47F4261691217B7180E091E945C17EF28E2A5291DD12797C78D2E08BE87F4E7B679DB92", "hash_ssdeep": "1536:PAIyANGQ0WV0fvIsL57qmPs00DfJw6Bb9v2:P7yA/enIG57q/VDfJLt4", "hash_imp": "9580FB84ACAA83C6D353A5A1F7F5E653", "hash_pesha1": "EFF4F417D448B3CAECB9F68D51110BD7B9B2D000", "hash_pe256": "F3508F1F5E72DADA6BCF90038A8E29E4207E1CA5BCFE23713E6225A63B089234", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Program Compatibility Assistant", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/36ef04735adfff417ae761bf6595badb54a4cceb3550aba7cfd4f7234c90ee7d/detection/", "runtime_modules": [ "C:\\Windows\\system32\\pcalua.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll" ] }, "pcaui.exe-58AA937F732746248FF63B521855675E": { "file_name": "pcaui.exe", "file_path": "C:\\Windows\\system32\\pcaui.exe", "hash_md5": "58AA937F732746248FF63B521855675E", "hash_sha1": "CB8BE8AF92F5A537109692C65B1E24C788EA5B4B", "hash_sha256": "39817B66C11DAD6D7A5B606C7146CC8B6590371AC3A942D700D2EA3E4BC3FF1F", "hash_sha384": "0193AE70CBCBCCCAEE149D543D87E547716C9D98C7F35E018B21FE6E11FC4EE947ED3E945BDC0A56EEE685A82AA631A5", "hash_sha512": "E98A4F3B5F4113F662FDE51371D2D90F818EFC369BAE979742BBE83C23B9B398C45067DB656E1BB072FAEDF43254CA0D9FEE8DE91BF229996FC624511954A156", "hash_ssdeep": "3072:Yk5BaNPMsZzaNRNQQE6ef5POfQEpRZWQiPWgvP9lcZ9uD3P0hLGvySHqT:Xn+kia/QQYQokWQiOgvP9qiySHq", "hash_imp": "51E81965BC709DAD22A5E21A1645B37F", "hash_pesha1": "5415F050C827E06CE5E080E696A533F9710C4000", "hash_pe256": "0DD0B50EC2334E27298B264AB834F1628BA74EE4BBC253622FDD32A8F26E493E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Program Compatibility Assistant User Interface", "meta_original_filename": "pcaui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/39817b66c11dad6d7a5b606c7146cc8b6590371ac3a942d700d2ea3e4bc3ff1f/detection/" }, "pcwrun.exe-FEE8B8FE78C3B7C9FC1C7ABB6FBCBCF6": { "file_name": "pcwrun.exe", "file_path": "C:\\Windows\\system32\\pcwrun.exe", "hash_md5": "FEE8B8FE78C3B7C9FC1C7ABB6FBCBCF6", "hash_sha1": "B49557BDAB527B36BE2DD1E3D9049772DCDBCFB3", "hash_sha256": "3DE0D85F8170457E741B8C7B2EC0CBFC5BDF6EB37012E4A5E7EEE93B149AE7CF", "hash_sha384": "06DB31B19C4868B733C3734482475E38EA0140E04A1E75D5523A00578927C4DD06B61CCB15823BCD71477396BDCBA7B3", "hash_sha512": "C8FE23122B7EB5425E93BDB72FCA0E8E449DF57D72D0892E95C79C578013A1EFD02A17A3187094C0E886FAB95433B0D5007ABE29F889A5745DB930EDF0DC1A8F", "hash_ssdeep": "192:0HWN2ogLOLwB1EcMOchQXfRpO5gSlNssAQG7SU2dR75lvmsWHgW:0HEgLOLZhOc6R0Ogmnl2TesWHgW", "hash_imp": "B78658A8BFA515AFA2CD46E53317253F", "hash_pesha1": "12D00258523DDABF4DF090D4B3694035BD98AF12", "hash_pe256": "680E41882A700A705762F936A205D828669D329AC18AB06BB4007DA1F987A1CC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Program Compatibility Troubleshooter Invoker", "meta_original_filename": "pcwrun.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/3de0d85f8170457e741b8c7b2ec0cbfc5bdf6eb37012e4a5e7eee93b149ae7cf/detection/", "children": "msdt.exe", "runtime_modules": [ "C:\\Windows\\system32\\pcwrun.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll" ] }, "perfmon.exe-52BC3295597B70B1380FAA6E32BEFAD3": { "file_name": "perfmon.exe", "file_path": "C:\\Windows\\system32\\perfmon.exe", "hash_md5": "52BC3295597B70B1380FAA6E32BEFAD3", "hash_sha1": "DAE1D1D4B3D632F42CB4696E0370B714B37BE48A", "hash_sha256": "94E0ECEB1A5DB9D3C32FC83015AC0CC58DB8A5B3E2D3A190631607A0E6736E1B", "hash_sha384": "6E3932447337718652E7F9A6003FF2F988547ED6A47A5362F16CAEE9CE18C2245D212C7DEE8F005CFC0C2FE70D40F7D5", "hash_sha512": "13CCBFCFB093ED00CCE06D6D92DE961E005509A67B47D92DD6CED502786C7CD063E167B168BAF4AD54F293629CA182436B5FA57A6E649778CD844E53D6ED831E", "hash_ssdeep": "3072:9pIwWHTowsNMHF1+CalGghtYIo9piswTogiqQKy349:+HZsNMHF3aphqIo9s37iTK24", "hash_imp": "B38A3E88D8F80E2CA7A2637E0B8D9FAC", "hash_pesha1": "CDABB5664B738D0E4A084AA3BFC26517F8FF1273", "hash_pe256": "126B35806905F690605338EC35C1F36F3BAAFBB1AB15C3D3EA16BF41919E3DFA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resource and Performance Monitor", "meta_original_filename": "perfmon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.00", "meta_product_version": "10.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/94e0eceb1a5db9d3c32fc83015ac0cc58db8a5b3e2d3a190631607a0e6736e1b/detection/", "output": "Argument '-help' is unknown.\r\n", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\perfmon.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\perfmon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\ATL.DLL", "C:\\Windows\\system32\\credui.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\Comctl32.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll" ], "runtime_window_title": "Resource and Performance Monitor" }, "phoneactivate.exe-FC51534BDC5948B235AE23848FCA67C6": { "file_name": "phoneactivate.exe", "file_path": "C:\\Windows\\system32\\phoneactivate.exe", "hash_md5": "FC51534BDC5948B235AE23848FCA67C6", "hash_sha1": "39C53CFCF20511BAFB23631659DB11BFC1E5646D", "hash_sha256": "A2F5AF6E07F164BFA44BEC802A877BEE157F0DC830C8D33FC341411249A1B99B", "hash_sha384": "6B01A577BE99D58E1D6666D6265034F064E0E6CD67AF4C94AFFFB42540EF53622710C1B7DC9EF4D0B350C779AC947EE9", "hash_sha512": "CBB02FA04FCAB41B57E0DA0F682B05D3CF18907F223C858F516BDE2DD94593D6E499BB09547EE01E71AC90679AC5BB4CCF4232B8E3A9D9886F78C7CB1813992F", "hash_ssdeep": "1536:KDIv8OvRpZDqENAlZn22MgI8/OlCJIF53E1t7J5Xld9g6n6Lpjj0nPD:KKbRpEeSty6n6LBgr", "hash_imp": "526D83889244C77D6C7C6579ACBB9166", "hash_pesha1": "DF1E8C665E111121694F76924B6712A666117888", "hash_pe256": "A674E69127C02815ACC795265453751F4102C1077CB8EE2F2D5234B3F229054D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Phone Activation UI", "meta_original_filename": "phoneactivate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/a2f5af6e07f164bfa44bec802a877bee157f0dc830c8d33fc341411249a1b99b/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\phoneactivate.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\Windows.UI.Immersive.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(RW-) C:\\Windows\\System32": "File", "\\RPC Control\\DSEC1368": "Section", "(RWD) C:\\Windows\\Fonts\\seguisym.ttf": "File", "(RWD) C:\\Windows\\Fonts\\segoeuisl.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(RWD) C:\\Windows\\Fonts\\seguisb.ttf": "File", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\phoneactivate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\Windows.UI.Immersive.dll", "C:\\Windows\\system32\\SLC.dll", "C:\\Windows\\system32\\sppc.dll", "C:\\Windows\\system32\\sppcext.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\WinSCard.dll", "C:\\Windows\\system32\\WINHTTP.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\system32\\CRYPTBASE.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\Comctl32.dll" ] }, "PickerHost.exe-A22CCBA3076963F4C79111A60864472D": { "file_name": "PickerHost.exe", "file_path": "C:\\Windows\\system32\\PickerHost.exe", "hash_md5": "A22CCBA3076963F4C79111A60864472D", "hash_sha1": "22CCFDE664BE96C5F6DF4B793F5E962A2F4D24F5", "hash_sha256": "82834848DCDEDE5A8509F2905D576CF00E576162B80FF85E6A0286A4F5B6AD29", "hash_sha384": "ECB475DDE88B849052305F8A65EF32C7A222F8BEA315F557E7ED101090C31616DB189E99804BC52190F88E2BD3013BB3", "hash_sha512": "17403C14DD1790ACAFAFFF2A2197EF3D4C8FCA667709EBD8B4393A070663F7EA7BF33BAB941EA5206FE64CC327F34A29B7FB6BDB60AE347CCC7D993C6EF8DDA3", "hash_ssdeep": "1536:RA1KkjQXkUvaJaxoboCv6y4KVK54YRJ+f97i2WJFZAgQUHYx6K4Py:CnevafUCv69KVsJ+fx1WJQgHcf46", "hash_imp": "DACB65CE9BEBA9F12700649D9E201316", "hash_pesha1": "254D9EB4C9A19FD86B4739C61792E1F372E06E75", "hash_pe256": "65FAE8D56FEBDF5AC6BF5A2A2A18275B848A665F430E0BC3A59E0A4446D11770", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Picker UI Host", "meta_original_filename": "PickerHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/65", "filescan_vtlink": "https://www.virustotal.com/gui/file/82834848dcdede5a8509f2905d576cf00e576162b80ff85e6a0286a4f5b6ad29/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1220": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\PickerHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll" ] }, "PING.EXE-56633150D77AE242D07727B0564430BB": { "file_name": "PING.EXE", "file_path": "C:\\Windows\\system32\\PING.EXE", "hash_md5": "56633150D77AE242D07727B0564430BB", "hash_sha1": "8757646428A176F76E6F38458A25902A8FEBA9C0", "hash_sha256": "741AD992403C78A8A7DBD97C74FDA06594A247E9E2FA05A40BB6945403A90056", "hash_sha384": "67594E897FF8564B57F201DD62462F553D5B51362AE76ED4AEAB7B56E6341B403343D408BED54B1FBFE680999E54E432", "hash_sha512": "6FD34F6EADD44E39C19A7B50732D4B85CC18F96F9D7E360AC4597F3D8DFC2611A5B72009A8C235AEC49D7528DCF9BE53E752F47CC5B31C343446A512E02C9737", "hash_ssdeep": "384:DL97irkr1hp22PeQw78T5HfjQ1H6PE7Apvu0pFjSbuLmq1mLQhWE2WmlW:DLFfASeQw78TpYGuO4CL11mLQG", "hash_imp": "8C3BE1286CDAD6AC1136D0BB6C83FF41", "hash_pesha1": "37E12A30BC0CC01FE4AEF5A4718F006B3774FEE4", "hash_pe256": "3482ED866C391A8E2EE9E65545D65BCBC7A76EFF8C416B80D434CC6D0E2F1627", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Ping Command", "meta_original_filename": "ping.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/741ad992403c78a8a7dbd97c74fda06594a247e9e2fa05a40bb6945403a90056/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\PING.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\mswsock.dll", "C:\\Windows\\SYSTEM32\\DNSAPI.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\System32\\rasadhlp.dll" ], "output": "Bad option --help.\r\n\r\nUsage: ping [-t] [-a] [-n count] [-l size] [-f] [-i TTL] [-v TOS]\r\n [-r count] [-s count] [[-j host-list] | [-k host-list]]\r\n [-w timeout] [-R] [-S srcaddr] [-c compartment] [-p]\r\n [-4] [-6] target_name\r\n\r\nOptions:\r\n -t Ping the specified host until stopped.\r\n To see statistics and continue - type Control-Break;\r\n To stop - type Control-C.\r\n -a Resolve addresses to hostnames.\r\n -n count Number of echo requests to send.\r\n -l size Send buffer size.\r\n -f Set Don't Fragment flag in packet (IPv4-only).\r\n -i TTL Time To Live.\r\n -v TOS Type Of Service (IPv4-only. This setting has been deprecated\r\n and has no effect on the type of service field in the IP\r\n Header).\r\n -r count Record route for count hops (IPv4-only).\r\n -s count Timestamp for count hops (IPv4-only).\r\n -j host-list Loose source route along host-list (IPv4-only).\r\n -k host-list Strict source route along host-list (IPv4-only).\r\n -w timeout Timeout in milliseconds to wait for each reply.\r\n -R Use routing header to test reverse route also (IPv6-only).\r\n Per RFC 5095 the use of this routing header has been\r\n deprecated. Some systems may drop echo requests if\r\n this header is used.\r\n -S srcaddr Source address to use.\r\n -c compartment Routing compartment identifier.\r\n -p Ping a Hyper-V Network Virtualization provider address.\r\n -4 Force using IPv4.\r\n -6 Force using IPv6.\r\n\r\n" }, "PkgMgr.exe-DDE0B63F2E276B969C9C1E6983990CB2": { "file_name": "PkgMgr.exe", "file_path": "C:\\Windows\\system32\\PkgMgr.exe", "hash_md5": "DDE0B63F2E276B969C9C1E6983990CB2", "hash_sha1": "6D3027D9187F38F4B10047A6E9194FC2B409B08C", "hash_sha256": "5BED2AA29ECB2AEF1A41E8B33A0CEFD32DDEFBFA1F7767430A311C064CF13D67", "hash_sha384": "C16C88BE49B555A2FCC4D6AE507D1B1B0E6DD74CD0237EF67725232BD5441D89D185F6CAACBE70BCA3F71AFE5FBC540D", "hash_sha512": "33D2B7A8918EF14996CFB21BDFB8C6DA5BDA937FACB9B7911FCA0D40D4D7F2696FDF65C3F30D45E3186C470CF05D92F33E8E3DBA1C0E7579780EB29E479655BF", "hash_ssdeep": "3072:JdN18XlC0HmKIbTENXK6JRAqs4xjw8m1IsF/Xq:fX89HmtbTMHxM8cT/X", "hash_imp": "BEE03492F0B5EDD4B94BB7DD6E56B8A1", "hash_pesha1": "4BDF4E683B3E2ECCD0B98802CAC9F07148A3B867", "hash_pe256": "3623BDA85D57AAD0EAF2F4729D0849F7A236D6029C3A72E98C0DA70BBC4DD314", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Package Manager", "meta_original_filename": "PkgMgr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/5bed2aa29ecb2aef1a41e8b33a0cefd32ddefbfa1f7767430a311c064cf13d67/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\PkgMgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll" ], "runtime_window_title": "Windows Package Manager" }, "PktMon.exe-21A491ECAB4340C7E6B6A805405BA1B5": { "file_name": "PktMon.exe", "file_path": "C:\\Windows\\system32\\PktMon.exe", "hash_md5": "21A491ECAB4340C7E6B6A805405BA1B5", "hash_sha1": "A511B97672EE1C05566261F4D35DCC90A0129782", "hash_sha256": "5A5E71245F9FC0D109452FE867192CEAE3CFE7803950EAB2F4E0A7BDA8677DD4", "hash_sha384": "5EA888E15E0298182FE0859BDF42C8904D9F7C3ABFCAA6B7384F69F12577309BCA1CA2225B1C80CBD20BC0FF81490994", "hash_sha512": "9E01F02564602E38A5C6BD6F972CBD9574D99ABC5DD2379A1D1073196FE30D9AF19A2439C6C9F0D7AA51ABBE1E65ECEC53FC83722EAF3882EA1752731D4B0EC1", "hash_ssdeep": "1536:yGfEpBuoiTpD/r5CFfk7nVGMTwH+f4J7YWojB9fE5SZVqKwdUn2qfMp:CmtTduk7VGMTwH+6UWojB9Vm3+3fc", "hash_imp": "D5EBB7E1938F5C766EEEFA65BF1A291C", "hash_pesha1": "FEEE09027EA7BE4D440E170FC5BADED997D823E5", "hash_pe256": "3C35C1FD8D6837D10B7CFBA6A254738E28AC96B796CED33624CC09F7A0105A83", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Packet Monitor", "meta_original_filename": "PktMon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Windows\\system32\\PktMon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ], "output": "pktmon { filter | comp | reset | start | stop } [OPTIONS | help]\r\n Monitor internal packet propagation and packet drop reports.\r\n\r\nCommands\r\n filter Manage packet filters.\r\n comp Manage registered components.\r\n\r\n reset Reset counters to zero.\r\n start Start packet monitoring.\r\n stop Stop monitoring.\r\n\r\nhelp\r\n Show help text for a command.\r\n\r\n", "error": "Unknown command '--help'. See pktmon \b help.\r\n" }, "plasrv.exe-B9C0F1B4FD8F16205A82FCB4795EC25F": { "file_name": "plasrv.exe", "file_path": "C:\\Windows\\system32\\plasrv.exe", "hash_md5": "B9C0F1B4FD8F16205A82FCB4795EC25F", "hash_sha1": "D4718B9C535A8631C2A74F0CF8EC5ED0DF6DECF6", "hash_sha256": "42D13DB2BE5A3B913EF39622F8357752A6CA625AE1280992C21D971CE9B7E701", "hash_sha384": "ACB2778EC999414D4901B276CD96EF8089887A2500897D25E7E3779A91E1EA101B0E595E145DFA29BDEA89129A43C437", "hash_sha512": "69304197C2805F908DFEB79EF48CF3C573A1FDD1C2038A7BB7FC39DA4E8BCF480A6D235DE101DD2F0CD542F20D5CAF1E27111DE3AD75D12B298402B78F931254", "hash_ssdeep": "192:kD/feVr4m7RI5cRoW0hmRZec6TXdTuUg52WZXW:kD/fE7K6oWYmyfTXEZ4WZXW", "hash_imp": "71297308FDB1BE310422F78B8E23F73C", "hash_pesha1": "39935852666B8505A73EF2E62871ED765354C331", "hash_pe256": "445B198C98C12D695843136918042AD02F81475201EB11FA726D9EDE8260C5FD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Performance Logs and Alerts DCOM Server", "meta_original_filename": "plasrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/42d13db2be5a3b913ef39622f8357752a6ca625ae1280992c21d971ce9b7e701/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC90C": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\plasrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\pla.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\pdh.dll", "C:\\Windows\\system32\\tdh.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\system32\\wevtapi.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\mintdh.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHCORE.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "PnPUnattend.exe-73AFF4E9ECEBD44114FC78A442B13741": { "file_name": "PnPUnattend.exe", "file_path": "C:\\Windows\\system32\\PnPUnattend.exe", "hash_md5": "73AFF4E9ECEBD44114FC78A442B13741", "hash_sha1": "2CC9A0852622B32C4B152C862838EA93C654BE16", "hash_sha256": "1BD75ED2ADBB32C2863B5A3B117DEC61EE2BFBDF4AA6892670CA5E23C2D9424F", "hash_sha384": "D2661A67DB484D908529DF6B1DD057DF72B765D7414DD9EE0FCE70E1697EF98E47D90BEEFCE238CD9D1662EFF4C19E7A", "hash_sha512": "A0081ED1E2CB734BA5B2311C6CB8942F425E69CACCE00348CB00AE23842A6DC96E4F2EC5C4CC4001C9C3DB2FE26BDC7F9256F060D6526870793F2695F0F49010", "hash_ssdeep": "768:hyPKrBx6AkCDTKAcrYeKRcdvQv7J3JAZVkhIjgkp5e0cVnxDQVW5RKpLdRh5VnDb:IK10XCqAcrYeitJ3siloeZ3QkS3y/a", "hash_imp": "43B208E7D537FA25FB5182C0A73AD298", "hash_pesha1": "E7707193EE9FA537A510A23D06AD6CDAC3604B47", "hash_pe256": "9A9C3E979B737CB4BE00D5A86CEB00CED084E0F0218DD3DCFC0EACC9F0F1F963", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PnP unattend action", "meta_original_filename": "PnPUnattend.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/1bd75ed2adbb32c2863b5a3b117dec61ee2bfbdf4aa6892670ca5e23c2d9424f/detection/", "output": "DESCRIPTION:\r\r\nAuditSystem, Unattend online driver install \r\r\n\r\nUSAGE:\r\r\n PnPUnattend.exe [auditSystem | /help /? /h] [/s] [/L]\r\r\n auditSystem Online driver install.\r\r\n /help /? /h This help.\r\r\n /s Search without installing.\r\r\n /L Print Logging information to the command line.\r\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\PnPUnattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\newdev.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\system32\\DEVRTL.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\wdscore.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\system32\\dbgcore.DLL" ] }, "pnputil.exe-F90F59AC0DD8F246070E4CFB97362610": { "file_name": "pnputil.exe", "file_path": "C:\\Windows\\system32\\pnputil.exe", "hash_md5": "F90F59AC0DD8F246070E4CFB97362610", "hash_sha1": "18FEEFE0E5F5930C254E646177AA3E17DC5717C8", "hash_sha256": "38F65CCC55E9C28BFB8E44A11A8295F3DD9F73DE29F67FF5E043F0BD5A2003EF", "hash_sha384": "D8930B60C15FD69020462A15B2C1886820A084B2EC6401DCA12A86B58742A647A52A1D0066984E894DCA9C737F4878F3", "hash_sha512": "3EC466E0CCB4302FFFEB7725560C38A67812EE58F930F7B937CB7744E002DE4A1494FE2DC1DC955C44EBCDF06CA627A19D742CCB622160A8F399178DFD15B32D", "hash_ssdeep": "3072:BCJDyM6Wz63GfINmCTfzAn6SFD4bJjgwQ+sJ6ZtAupdZppPsYtaLC:BCJDyM6WzBfINmccn6qxH78UY", "hash_imp": "77C66AA0A4495185A477C13839B45D00", "hash_pesha1": "02A13D0EC2E66FAA2620485FAAA83A02B481FFEC", "hash_pe256": "4519624068417F62BE85012857D34B3F9BA9BCA350C30A3D66D41C2286B57773", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft PnP Utility - Tool to add, delete, export, and enumerate driver packages.", "meta_original_filename": "pnputil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/38f65ccc55e9c28bfb8e44a11a8295f3dd9f73de29f67ff5e043f0bd5a2003ef/detection/", "output": "Microsoft PnP Utility\r\n\r\nPNPUTIL [/add-driver <...> | /delete-driver <...> |\r\n /export-driver <...> | /enum-drivers | /?]\r\n\r\nCommands:\r\n\r\n /add-driver <filename.inf | *.inf> [/subdirs] [/install] [/reboot]\r\n\r\n Add driver package(s) into the driver store.\r\n /subdirs - traverse sub directories for driver packages.\r\n /install - install/update drivers on any matching devices.\r\n /reboot - reboot system if needed to complete the operation.\r\n\r\n /delete-driver <oem#.inf> [/uninstall] [/force] [/reboot]\r\n\r\n Delete driver package from the driver store.\r\n /uninstall - uninstall driver package from any devices using it.\r\n /force - delete driver package even when it is in use by devices.\r\n /reboot - reboot system if needed to complete the operation.\r\n\r\n /export-driver <oem#.inf | *> <target directory>\r\n\r\n Export driver package(s) from the driver store into a target directory.\r\n\r\n /enum-drivers\r\n\r\n Enumerate all 3rd party driver packages in the driver store.\r\n\r\n /?\r\n\r\n Show this usage screen.\r\n\r\nLegacy Commands:\r\n\r\n [-i] -a <filename.inf> ==> /add-driver <filename.inf> [/install]\r\n [-f] -d <oem#.inf> ==> /delete-driver <oem#.inf> [/force]\r\n -e ==> /enum-drivers\r\n\r\nExamples:\r\n\r\n pnputil /add-driver x:\\driver.inf <- Add driver package\r\n pnputil /add-driver c:\\oem\\*.inf <- Add multiple driver packages\r\n pnputil /add-driver device.inf /install <- Add and install driver package\r\n pnputil /enum-drivers <- Enumerate OEM driver packages\r\n pnputil /delete-driver oem0.inf <- Delete driver package\r\n pnputil /delete-driver oem1.inf /force <- Force delete driver package\r\n pnputil /export-driver oem6.inf . <- Export driver package\r\n pnputil /export-driver * c:\\backup <- Export all driver packages\r\n\r\n" }, "poqexec.exe-4895143A779A1B4A9465C7BF36BAEC29": { "file_name": "poqexec.exe", "file_path": "C:\\Windows\\system32\\poqexec.exe", "hash_md5": "4895143A779A1B4A9465C7BF36BAEC29", "hash_sha1": "6AAB6FB59EA87DC2842825CE5737D3571208BC54", "hash_sha256": "164BC59090DC8FC229EB3F62D1C549C8F2496F31C3499A36A7359D1CD9768AE9", "hash_sha384": "4C21788298D56A5B503A0EA85204BCC571481353FD2B343CF0713DDEE9E925FF094795802F590F28CA9E143018EF9CE8", "hash_sha512": "266FAE8335CEFCA881046C035997CC9240FA8D7A24C5F7871D7990A35C3C6080E97E5E696FC6A9AF3819E85A2A89580D06CF1083ECF9976CEDD1BF414FA7B009", "hash_ssdeep": "3072:CvlYeTJue2RjE3vOB5C2o6gBMpZ4Nbso508IxFkfh:CvlYgJ+RjE/OB5Vo6vqNYw08I4f", "hash_imp": "CF34294C2236A14E04714F40E66019C6", "hash_pesha1": "8F3DE05A109175ABEA746598D66137E715D0CC1D", "hash_pe256": "4EC49FC9981D847F28916E53299DF3A102AF9D32AC1C0E19DF2AE5BBCCB61739", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Primitive Operations Queue Executor", "meta_original_filename": "poqexec.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/164bc59090dc8fc229eb3f62d1c549c8f2496f31c3499a36a7359d1cd9768ae9/detection/" }, "powercfg.exe-16DB9ABBECB40F14C5656E7AC3C16AAD": { "file_name": "powercfg.exe", "file_path": "C:\\Windows\\system32\\powercfg.exe", "hash_md5": "16DB9ABBECB40F14C5656E7AC3C16AAD", "hash_sha1": "B4AC55C4E13D62C666DF689F3D77F721D66B85B4", "hash_sha256": "A6E1A555D365AB5F57DE1B077012B2B7AF65D7D9DD2500E6354CE47448EE7A1A", "hash_sha384": "D71B972A49AAF797DD7562E67DE150D09AD963683A4BF8ACA577B343D16A2236A7E158362763B44F1F9372A375A6B5DC", "hash_sha512": "6CFD3BDE155F330DA9BF65F9835C835BF78B5AA82D7F00D01D07FED90DDC9B45FE9729CFF552DB19F7458B0B1D724236CBFADAC11F3044E5876A6029FA29DEA4", "hash_ssdeep": "1536:FIatr7fAY77qstV4fZ/WIhDwltMPjl+3n3CW4GGt3mPI:FnA81aVjwlt25+HCWra3r", "hash_imp": "AFD7A8191DAF440071BC428C20F25CC4", "hash_pesha1": "04B5EC5E1B7F977DBB42AA1DC61A666D4B3FCF96", "hash_pe256": "24CAF0B8A05D9CA378312396B4EBD4F27180BC2C05136E5226BD1F599AAB55BD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Power Settings Command-Line Tool", "meta_original_filename": "PowerCfg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/a6e1a555d365ab5f57de1b077012b2b7af65d7d9dd2500e6354ce47448ee7a1a/detection/", "output": "\r\nPOWERCFG /COMMAND [ARGUMENTS]\r\n\r\nDescription:\r\n Enables users to control power settings on a local system.\r\n\r\n For detailed command and option information, run \"POWERCFG /? <COMMAND>\"\r\n\r\nCommand List:\r\n /LIST, /L Lists all power schemes.\r\n\r\n /QUERY, /Q Displays the contents of a power scheme.\r\n\r\n /CHANGE, /X Modifies a setting value in the current power scheme.\r\n\r\n /CHANGENAME Modifies the name and description of a power scheme.\r\n\r\n /DUPLICATESCHEME Duplicates a power scheme.\r\n\r\n /DELETE, /D Deletes a power scheme.\r\n\r\n /DELETESETTING Deletes a power setting.\r\n\r\n /SETACTIVE, /S Makes a power scheme active on the system.\r\n\r\n /GETACTIVESCHEME Retrieves the currently active power scheme.\r\n\r\n /SETACVALUEINDEX Sets the value associated with a power setting\r\n while the system is powered by AC power.\r\n\r\n /SETDCVALUEINDEX Sets the value associated with a power setting\r\n while the system is powered by DC power.\r\n\r\n /IMPORT Imports all power settings from a file.\r\n\r\n /EXPORT Exports a power scheme to a file.\r\n\r\n /ALIASES Displays all aliases and their corresponding GUIDs.\r\n\r\n /GETSECURITYDESCRIPTOR\r\n Gets a security descriptor associated with a specified\r\n power setting, power scheme, or action.\r\n\r\n /SETSECURITYDESCRIPTOR\r\n Sets a security descriptor associated with a\r\n power setting, power scheme, or action.\r\n\r\n /HIBERNATE, /H Enables and disables the hibernate feature.\r\n\r\n /AVAILABLESLEEPSTATES, /A\r\n Reports the sleep states available on the system.\r\n\r\n /DEVICEQUERY Returns a list of devices that meet specified criteria.\r\n\r\n /DEVICEENABLEWAKE Enables a device to wake the system from a sleep state.\r\n\r\n /DEVICEDISABLEWAKE Disables a device from waking the system from a sleep\r\n state.\r\n\r\n /LASTWAKE Reports information about what woke the system from the\r\n last sleep transition.\r\n\r\n /WAKETIMERS Enumerates active wake timers.\r\n\r\n /REQUESTS Enumerates application and driver Power Requests.\r\n\r\n /REQUESTSOVERRIDE Sets a Power Request override for a particular Process,\r\n Service, or Driver.\r\n\r\n /ENERGY Analyzes the system for common energy-efficiency and\r\n battery life problems.\r\n\r\n /BATTERYREPORT Generates a report of battery usage.\r\n\r\n /SLEEPSTUDY Generates a diagnostic system power transition report.\r\n\r\n /SYSTEMSLEEPDIAGNOSTICS\r\n Generates a diagnostic report of system sleep transitions.\r\n\r\n /SYSTEMPOWERREPORT Generates a diagnostic system power transition report.\r\n\r\n /POWERTHROTTLING Control power throttling for an application.\r\n\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\powercfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll" ], "error": "Invalid Parameters -- try \"/?\" for help\r\n" }, "PresentationHost.exe-193F1CA0ADF261816AC02CFD6553C96D": { "file_name": "PresentationHost.exe", "file_path": "C:\\Windows\\system32\\PresentationHost.exe", "hash_md5": "193F1CA0ADF261816AC02CFD6553C96D", "hash_sha1": "1A53BBECD49F42F4B919241E5C0F8F4DA55807CE", "hash_sha256": "6A51D20B0D5E3889A5BF168BF6C9A81AE50CCF74C5349547146F11C6016A87DB", "hash_sha384": "6896012A88A39FA5E822B0EC126FBE2BB44BBD385557F0D09344250BAC1418BB787B6D056CEFF347E24F67E151453550", "hash_sha512": "EF778890C769FAC09B770902FC6D1F03417105BF947E3FA96A06287F9866D585A5C1F008756B4E3B0C707C4A13893F02C51A199012CA0882CBB934808512AA96", "hash_ssdeep": "6144:aM9Qd26/6a7xX2LOgh5KNXwy3Odjp19k5KNXf:z9QA6/rGikKVwy3OdLaKV", "hash_imp": "9BACECDCCE64D5DF2F33D2DEB36930D0", "hash_pesha1": "B9A69E2123FB36B74D71A994A5FEF6906D455103", "hash_pe256": "B8ABCF810E3A2783133DF57CA7E57A7BC47D1CE3E3317366EB5DB501B4A46EE8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Presentation Foundation Host", "meta_original_filename": "PresentationHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/6a51d20b0d5e3889a5bf168bf6c9a81ae50ccf74c5349547146f11c6016a87db/detection/", "children": "iexplore.exe", "runtime_modules": [ "C:\\Windows\\system32\\PresentationHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\system32\\mscoree.dll", "C:\\Windows\\system32\\WININET.dll", "C:\\Windows\\system32\\urlmon.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\system32\\CRYPTBASE.DLL" ] }, "PresentationSettings.exe-D95F3087AC0C9E29F7C9D56EC4D85E93": { "file_name": "PresentationSettings.exe", "file_path": "C:\\Windows\\system32\\PresentationSettings.exe", "hash_md5": "D95F3087AC0C9E29F7C9D56EC4D85E93", "hash_sha1": "895219259FF21ACF7586F74CB3DAA1CD549F1FEA", "hash_sha256": "A1F2954DBB7D9111FB2DC9497A320E29E3A0CC2C00AFE9D96C58F78B1247CD70", "hash_sha384": "A633E24FB74F7944E56D156A4F05AEC2EE3250E25AAECCDEB77C83978C7C65DFC410646C544F045DB23776A6D004A60B", "hash_sha512": "B0C5123CE169B2D08805C9E4461A1E1CF16C0DBBC2B2D957AEC07827FDBE9A06D49726BCDACE656F147F42F3F72CFAA90FFB6B2713E78F35924FF22533BB6151", "hash_ssdeep": "6144:79iUJm0KX24r6IeeYpxpts2xmhfGKraEH:5iiyuIeeUQ2Gfn", "hash_imp": "2FD654F4DE23D9E1562F109BD5F81CEB", "hash_pesha1": "57A36CFA1C9C00E64BF2661012ECECB6261F569C", "hash_pe256": "07E520636EEFA381C835B511890034B28C7B23680FAF6A9ED6C0DA6DF87C4B81", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Mobile PC Presentation Adaptability Client", "meta_original_filename": "PresentationSettings.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) Microsoft. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/a1f2954dbb7d9111fb2dc9497a320e29e3a0cc2c00afe9d96c58f78b1247cd70/detection/", "runtime_modules": [ "C:\\Windows\\system32\\PresentationSettings.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\WINMM.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\system32\\WINMMBASE.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "prevhost.exe-5066713642F23C6CE51680639A681CAD": { "file_name": "prevhost.exe", "file_path": "C:\\Windows\\system32\\prevhost.exe", "hash_md5": "5066713642F23C6CE51680639A681CAD", "hash_sha1": "55CFABF2E432A6F87C18BDD5E67670D364912753", "hash_sha256": "0D7D86F67AAE91FFDE3AB7B2A4A2C8404F399A3FB01B4DDBE7530D55729B2DBC", "hash_sha384": "14AA433ABA555E8297ADFCB7E1A11BC65AF572F9B9FEF19FA7D9BCC3AE411C4F75E96CEE5FB42B3F3517346B89C37F87", "hash_sha512": "AD5EB803782C9EACB2D34BCB8845E92900BC7A02EDE55EAA4701C3820CBF9D331C854E2E00C6DCED04458EB2E3BB6DAC6F77699B67B2C3F8DC803275EFF975E5", "hash_ssdeep": "768:kz64Pu9WJCFolnOtcr2XqmHZ2x01kNnjCMi1pYyfQ8:m6PWgqmHEK1kNnjLSYyfQ8", "hash_imp": "14E7A56CE14DAD875047D7EC617BC003", "hash_pesha1": "674F85B5022B96CA9E1A68025C70C8F30E092E25", "hash_pe256": "1E18D7FCA7538D63AE02D7265510BC4EAB450539221CDA5B69E603A58E2FA2D5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Preview Handler Surrogate Host", "meta_original_filename": "PREVHOST.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/0d7d86f67aae91ffde3ab7b2a4a2c8404f399a3fb01b4ddbe7530d55729b2dbc/detection/" }, "print.exe-6C61491C83995551EF434840AAB5F5C1": { "file_name": "print.exe", "file_path": "C:\\Windows\\system32\\print.exe", "hash_md5": "6C61491C83995551EF434840AAB5F5C1", "hash_sha1": "D13E1FE413CD1CB07F3985DF4990BD870B8F9046", "hash_sha256": "16C7C773BF7CB099132D30D1ED5160D10918DB0101F5CC3D4D197E1E4D0D4CCA", "hash_sha384": "20F1821B741F0EDB6B55F15BD184C54E0061912ABCAD33BADDBF7CD977F9399C488943F19619BA502F4EA9F85322DD88", "hash_sha512": "4DF25A63EC689FCAD6F1296E1880BDB61B94CA213EC52CA203F808874FD6B867C6F8E2FEB3119CD47FD915281F88B773307C031AA12FD5BE2FC3646E8F7E120E", "hash_ssdeep": "384:Nq7VBlo9dJkqeS2ThhUuTX/3dPKLlWIUW:NQBlo9doS2TjX/3dPIR", "hash_imp": "D67C73847BD1DC0D9109BA544AD6C11D", "hash_pesha1": "231131C8719BE0CC656B4211868728F1530D2EDC", "hash_pe256": "138D25D4900C3AC42E115C2563303D3E8CE613A1B809E9198B2FB07E227759EF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Print Utility", "meta_original_filename": "Print.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/16c7c773bf7cb099132d30d1ed5160d10918db0101f5cc3d4d197e1e4d0d4cca/detection/", "output": "Prints a text file.\r\n\r\nPRINT [/D:device] [[drive:][path]filename[...]]\r\n\r\n /D:device Specifies a print device.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\print.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\ulib.dll" ] }, "PrintBrmUi.exe-E2E5292FA22FC82DC73CDC13D11E044B": { "file_name": "PrintBrmUi.exe", "file_path": "C:\\Windows\\system32\\PrintBrmUi.exe", "hash_md5": "E2E5292FA22FC82DC73CDC13D11E044B", "hash_sha1": "116DF95FFC225113812B7688EDE455D727C863EE", "hash_sha256": "C66D4D5A57FB0A3266B9C194C86712C504720B8F1E666244C25F1C8689C23C27", "hash_sha384": "3130D58E03DB0994E76B3F8771702C1815699342675942D1E6DA44C3B609A442B92AD059E9A1B2C76DD323E781FC0D79", "hash_sha512": "9E70A927E41749EADB1BC745C067E32430629E16111C7D32E5325C7BC1D54284CCAE90C69D7C12CFAA806BEB70D57193FCF4E07A3835029EA76E712644E5B56A", "hash_ssdeep": "1536:HetskLRR+gY6w73KyTrdtJHQAAiyvvKayDQ:8FL3BAKyqANynDN", "hash_imp": "D2225A1D5CB618A27802604174449643", "hash_pesha1": "5475B5EDAE9130BEA06035DE6EC65016484DA0DA", "hash_pe256": "E30BE824E0835A52D28C33708757AC71521B0258DA6C5CB36605099477192E55", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PrintBrm Application", "meta_original_filename": "PrintBrmUi.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c66d4d5a57fb0a3266b9c194c86712c504720b8f1e666244c25f1c8689c23c27/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\PrintBrmUi.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\PrintBrmUi.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\WINSPOOL.DRV", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\system32\\WindowsCodecs.dll" ], "runtime_window_title": "Printer Migration" }, "printfilterpipelinesvc.exe-B873D53F9FDF8BA2950FB769DEA60A3E": { "file_name": "printfilterpipelinesvc.exe", "file_path": "C:\\Windows\\system32\\printfilterpipelinesvc.exe", "hash_md5": "B873D53F9FDF8BA2950FB769DEA60A3E", "hash_sha1": "11F7FD99477305FA869F37B8AD280C5A0B44EC05", "hash_sha256": "E8CC7B67B10F92560DF2501DABDC5B72980E7AD3BB63908AA650FD02FA277C39", "hash_sha384": "CDD3C5EC39B0054484522E4F7F057BB7DC7C281F5D7D6BE73BFEF91AB297079217EDC1A67C7E752EFC08795DFB477E20", "hash_sha512": "CB7B172D10712299A81F067416DBFED7FECBFB909C33BDAC15E9C8CD163F62CF776442EB0B9C3DCC3D9A41395B9DDF4683A466BC61B899A4035EFBBA42391119", "hash_ssdeep": "12288:Fo2C+mqGCoF04H+ERlvqXQOaYRyxG4T4Uqg0Qm0enaEc6gW:Fot+mqGSE+m0urUtg7i", "hash_imp": "7266CB5C2C150887140ED7B4FA902C54", "hash_pesha1": "50D300D74FF6A32BB557FEB85253C1399BD1583E", "hash_pe256": "248AD7E6EDCB6060243CDFF5EAB2195DDF32333EDDB120230C84774396D02BD8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Print Filter Pipeline Host", "meta_original_filename": "PrintFilterPipelineSvc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1217 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1217", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/e8cc7b67b10f92560df2501dabdc5b72980e7ad3bb63908aa650fd02fa277c39/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\RPC Control\\DSEC1248": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\printfilterpipelinesvc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\POWRPROF.dll", "C:\\Windows\\system32\\WINSPOOL.DRV", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\prntvpt.dll", "C:\\Windows\\system32\\xpsservices.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\system32\\OpcServices.DLL", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\urlmon.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\system32\\CRYPTBASE.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\mscoree.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "PrintIsolationHost.exe-845208306E73B805D5B293DD02CD47D4": { "file_name": "PrintIsolationHost.exe", "file_path": "C:\\Windows\\system32\\PrintIsolationHost.exe", "hash_md5": "845208306E73B805D5B293DD02CD47D4", "hash_sha1": "149C8888F4D78C119F8FFB503749D4C4BA435288", "hash_sha256": "F0D0591C4CD1A475ED985659B03D16C0FC772A82A7EFB643B8D94AE851B4A2B7", "hash_sha384": "2130ECECF18D51D211742884B51120C229AAAA8F7B4138F45BFBE3FC9252A66EFD8ED3C5D98C3123424AFF35F41CA432", "hash_sha512": "2F92B3C2944EE44DE92D5CE56289D0436C7D5C69B41D9808D626C441D3D7367967958BF3A4D14D0CF4FA80DC837F14B2307D989123CD7A085C0CC844A334293A", "hash_ssdeep": "768:RRRK4KNDiSypfg7X195F8VasYdTItA3iQfMQnKnZA7t9G4qW4ne+S/ly+PKAoXRc:c4Eycz8Vt3A7HPd4n+lbeRZIbSQPT", "hash_imp": "A72E30CEDC830E820B420B45666127BC", "hash_pesha1": "A3504C95E267C3052FB1A8D00E7314C80DC9E867", "hash_pe256": "C5E1D96F676273E5A80A5F65BB1EB983359730D26C63C58AE3C86903E85E8059", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PrintIsolationHost", "meta_original_filename": "PrintIsolationHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/f0d0591c4cd1a475ed985659b03d16c0fc772a82a7efb643b8d94ae851b4a2b7/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECC74": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\PrintIsolationHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ] }, "printui.exe-13554E4D7EFFD6EB9719D884DC5D3D1C": { "file_name": "printui.exe", "file_path": "C:\\Windows\\system32\\printui.exe", "hash_md5": "13554E4D7EFFD6EB9719D884DC5D3D1C", "hash_sha1": "041F0D59CFCF6074D18242C0B3A75E4AEC37FDBE", "hash_sha256": "EAF14CDF857DB35360416939DBF04D08A0C9C8FA58ACC63249EC501B3636F52A", "hash_sha384": "3A3397CF16FA4CE00E4787DEA0C3657BEB613648656D5273FE43F96D5C0B7C295D0E474B2158413CF14B60DCEF6BBADB", "hash_sha512": "EB912029829C710A75F75E25B421DBCB9C792E46140D40DB6D5D6AD3ACBF84A63E60C14A105AEFAF648BD93635FD4078EB984CAE885A3C45D9FC092814861CF3", "hash_ssdeep": "768:uuyxmCZt5vI1iQfCIWVM9G4qW4ne+S/ly+PKAoXRZX6fbX57UWkCRPPA7/QnA:JCDVIPd4n+lbeRZIbSQPPA7t", "hash_imp": "DE8C59512CA98FB3E224769147985370", "hash_pesha1": "D047DA237A2A4DDC048F3E3728877DA72C95D603", "hash_pe256": "9ACACC499E9A1F546FDEB2102E78A37E1526B164D87F5A57452C5C5401EFF376", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Printing Settings", "meta_original_filename": "printui.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/eaf14cdf857db35360416939dbf04d08a0c9c8fa58acc63249ec501b3636f52a/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\printui.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\printui.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\printui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\printui.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\system32\\WINSPOOL.DRV", "C:\\Windows\\system32\\puiapi.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\Comctl32.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\system32\\WindowsCodecs.dll" ], "runtime_window_title": "Printers" }, "proquota.exe-40812BA1AC616723A1D2857ADF685E86": { "file_name": "proquota.exe", "file_path": "C:\\Windows\\system32\\proquota.exe", "hash_md5": "40812BA1AC616723A1D2857ADF685E86", "hash_sha1": "7931D9F82993DC00AD027461042B412373D232F8", "hash_sha256": "5CFD021B0E2D250F6396CF7D63FDDF0D126EC3FFE4E99304E63DF6868F0BF491", "hash_sha384": "CB591F8A5242D5D044815B9FD2B969E91E4CCD8B4F209C1AF3A39818DA17085EE855B0775CA6B2BF7D9747CD7E7E44EF", "hash_sha512": "81448E371ED3E84D0E4790CD61DFC5F58F6F370F2C6C0AB2FF2298CE464A63814B5600DB943B6D0F18CBF2E81C0F3B2DE468A38276A295EA1E19A98E1DAC6051", "hash_ssdeep": "768:2q4OZn30fiC4QDfqqXLaRjt2ErkZVZMPa:280N4lqbaRjgTVZ4a", "hash_imp": "E745A71411BBFEBE37E7961702971996", "hash_pesha1": "2006CF311F076F5406E64B758FE7E59765859257", "hash_pe256": "08C02BC30D50EB28778DC8614434DD1F825AAAF1BB052502453356898BA9A93E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ProQuota", "meta_original_filename": "proquota.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/5cfd021b0e2d250f6396cf7d63fddf0d126ec3ffe4e99304e63df6868f0bf491/detection/" }, "prproc.exe-7ABD17EE7B6B0F79CD4D2F3D4B4B11C2": { "file_name": "prproc.exe", "file_path": "C:\\Windows\\system32\\prproc.exe", "hash_md5": "7ABD17EE7B6B0F79CD4D2F3D4B4B11C2", "hash_sha1": "1E2F9AE2B2583E2E6E1658B542E2CA823270B318", "hash_sha256": "F6112B403195D586D859F1D4E1C3A5A7D2D4380A450F06E62EA9EE877F019818", "hash_sha384": "BADDB6B3A79BFABE443EB7FB5FA5D019D27082E76B00CA3E9EC7FA9547D6CE773909A312CEC42483D057B4C6D385573B", "hash_sha512": "A035DCBDDE9121A74EF58E95D47421EB3F86CCAE9B3CC565D923F40D563046173F38787E6B98B238023C7A6A6A18CF3D164AE619CC0AA080040108D16BCFE22D", "hash_ssdeep": "384:+IuK0So4BTBQ2VvHaWmrDYgWrymXjDBRJoBxl2EAJI:ZYShBQ2V/QMXj1P0Cra", "hash_imp": "A18C4D14BD67CD77D653245D9C7D8D1A", "hash_pesha1": "BF2A150AF6267A96638436BB45A8D000334B9DCB", "hash_pe256": "E9AD679EC1193D3C2B95FB1EB01E9E2862B921B6F61C7740501E585892BB5FA3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PlayReady Process EXE", "meta_original_filename": "PlayReady Process EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/f6112b403195d586d859f1d4e1c3a5a7d2d4380a450f06e62ea9ee877f019818/detection/" }, "psr.exe-402F1EFF59C025CF3BB134B27CB1E729": { "file_name": "psr.exe", "file_path": "C:\\Windows\\system32\\psr.exe", "hash_md5": "402F1EFF59C025CF3BB134B27CB1E729", "hash_sha1": "11BF3A146940D214D9BBAD019E17C432F041481C", "hash_sha256": "43BFF52AEC02A3851737CB2DD5799A5196BD0C3EDF30FB482F9F0AA2326910DA", "hash_sha384": "96663EFAA7ED6D337B45F71F883C251F1D423D4AEB33BB6B11EA3CB242051AE8604A0472998163BCB4A8FFC3C8C9A68F", "hash_sha512": "60ACB47B3616C26BC2BBF27F6BE706A7ADFBEB66DDF32C64F2457EBE031F331FBD43E8EE64992B9024DB824392A433894B86CFE80CC06ED2338798F373B45FDF", "hash_ssdeep": "6144:z1yxV51DmDVQwwwoHsmbM/NzV/JAVcD8LPhSiWofQr2k5l8BmMxowi/EH1:z1yr5EVoHjbM/WcD8pellpco//EH1", "hash_imp": "12931ABAD86FDA80B59207BCB7A378CA", "hash_pesha1": "A289A8982856FC4AD5D898D840C220D444D77AAD", "hash_pe256": "4D1FAD768148DEDEA18F108FCD190EF7B60787D11BC711F9E117A57098E11496", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Steps Recorder", "meta_original_filename": "psr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/43bff52aec02a3851737cb2dd5799a5196bd0c3edf30fb482f9f0aa2326910da/detection/" }, "pwlauncher.exe-DE74239A71969470748C4CF9533EFDD0": { "file_name": "pwlauncher.exe", "file_path": "C:\\Windows\\system32\\pwlauncher.exe", "hash_md5": "DE74239A71969470748C4CF9533EFDD0", "hash_sha1": "5E6C3E0FBA13176D3D88896E81317D9B78C00508", "hash_sha256": "1C8227150762B47731DD6B99304D3E5647824F9C1B4D7FB8CD755B29F00BC93B", "hash_sha384": "46A8F73B6C84A69E78BFB48EBAD8ED43BB0E82D509B4EFF3CEC9298514587A3D8556D590C10E5AFF83E0629DB8DD08BA", "hash_sha512": "1449119C19C96DB045A3A0DBA69A79CF74DAB6B98E66927D16D4EECF957CE99CCA743D963CCB80E950B2781F6F051A2C8CF6F4ABD9B96415CD039F0D0D66411C", "hash_ssdeep": "768:74VleU0Q2RiX8nuVGqQd2Ej2FNkY4EABbnLM8mWP/:UV2wCiEaFNkYU5nLNmWH", "hash_imp": "10E2E3C83FAD470F2219B3E8C8A1881E", "hash_pesha1": "9790A47BE9FE62EEB32B14B0F7CA115CCD933622", "hash_pe256": "72580C513B1637AF431B34D2F91A3894DF9D444815B54F4402514B4B45B7E55D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows To Go Startup Options Command Line Tool", "meta_original_filename": "pwlauncher.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/1c8227150762b47731dd6b99304d3e5647824f9c1b4d7fb8cd755b29f00bc93b/detection/", "output": "pwlauncher.exe - Windows To Go startup options command-line tool.\r\r\n\r\r\nThe pwlauncher.exe command-line tool is used to query or change your Windows To\r\r\nGo startup options.\r\r\n\r\r\npwlauncher [/enable | /disable]\r\r\n\r\r\n <<no parameter>> Display the current state.\r\r\n\r\r\n /enable Enable the startup option.\r\r\n\r\r\n /disable Disable the startup option.\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\pwlauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\bcrypt.dll" ] }, "qappsrv.exe-50A8F36BFB30F05701AD643173DADB89": { "file_name": "qappsrv.exe", "file_path": "C:\\Windows\\system32\\qappsrv.exe", "hash_md5": "50A8F36BFB30F05701AD643173DADB89", "hash_sha1": "E6C4431F5727F1CB3D899E0B4FC132F91808BA3D", "hash_sha256": "CB7F28D3121604628402DB28B7627DE8D64A1B7116B883C83AE496D6F6D0B667", "hash_sha384": "FA180BEA1554DEBF129ED3E6EEDF90B3EA6B0C996EC0DA8DFC15678E25B9683F53951CE1AA993DDFB7AB2CE641D320B3", "hash_sha512": "5DE9CE7C15530FAE1FCB49C07B7D1C4AA03842024B00B1B496F712BE06B4A6527A0AF4B3BEF33D18E665D3A6EF7999D4CDAB0A9A34879C68723223ABA318238D", "hash_ssdeep": "384:F/U7HX5bP44grDMkiUHdE5z5XWjK8mKk5VGqqKEcgEgPJ5HPwe9Kp/14ED0lWLad:dGp8rDMOHKMjK8NO5NDOq94EQe", "hash_imp": "C715564F456F9C30B145ACEC03F1E5C4", "hash_pesha1": "EB00938B5942323335D53D58A4D8C1C52A7383E3", "hash_pe256": "E4B65071CDAC0AC2EE4E9ADDE59118483182D8A1AED0510E0F481BF6EEE9EDA3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query Remote Desktop Session Host Server Utility", "meta_original_filename": "qappsrv.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/cb7f28d3121604628402db28b7627de8d64a1b7116b883c83ae496d6f6d0b667/detection/", "output": "Displays the available Remote Desktop Session Host servers on the network.\r\n\r\nQUERY TERMSERVER [servername] [/DOMAIN:domain] [/ADDRESS] [/CONTINUE]\r\n\r\n servername Identifies a Remote Desktop Session Host server.\r\n /DOMAIN:domain Displays information for the specified domain (defaults \r\n to the current domain).\r\n /ADDRESS Displays network and node addresses.\r\n /CONTINUE Does not pause after each screen of information.\r\n\r\n", "error": "Invalid parameter(s)\r\nDisplays the available Remote Desktop Session Host servers on the network.\r\n\r\nQUERY TERMSERVER [servername] [/DOMAIN:domain] [/ADDRESS] [/CONTINUE]\r\n\r\n servername Identifies a Remote Desktop Session Host server.\r\n /DOMAIN:domain Displays information for the specified domain (defaults \r\n to the current domain).\r\n /ADDRESS Displays network and node addresses.\r\n /CONTINUE Does not pause after each screen of information.\r\n\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\qappsrv.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\qappsrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\NETAPI32.dll", "C:\\Windows\\system32\\SRVCLI.DLL", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\NETUTILS.DLL", "C:\\Windows\\System32\\IMM32.DLL" ] }, "qprocess.exe-8D3FA14EBFF47BF9CBB1E27B5992A228": { "file_name": "qprocess.exe", "file_path": "C:\\Windows\\system32\\qprocess.exe", "hash_md5": "8D3FA14EBFF47BF9CBB1E27B5992A228", "hash_sha1": "7EAF631ECBE8258AFE32BFB890CEACA1D13737AA", "hash_sha256": "7EE7A6FB1BDD972502D1EB23B7BD471A66CAD63CA3B57D787A173FB290808EB6", "hash_sha384": "263838CE532FD563A7CC7887CA39668634858D50201B2FB03F0B966686D708A5705837D78D222140FB7F356989E707BC", "hash_sha512": "DFF0CBDACCA1C850A3C5F8BB851647B60FDA6352F2FB486B90B0005F79E1D3A8651703EE0F634E967047DCB25E396CE2B5E235B3694D5B1C78D97E5B731F6153", "hash_ssdeep": "768:w8igjPq3JqPcvSphuU1EK8vB0MCYnvAMODDM:ZGZipYfB06InM", "hash_imp": "2C0AA5527727A67BD252EF9D0F3BEB31", "hash_pesha1": "65E412C36503BCCE42A28F99245599158FBAFED2", "hash_pe256": "DFEC3B3D0DBA5EF66138F833A7A03F1FF28C3CA20BD8154C5CBE60F5820E72E4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query Process Utility", "meta_original_filename": "qprocess.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/7ee7a6fb1bdd972502d1eb23b7bd471a66cad63ca3b57d787a173fb290808eb6/detection/", "output": "Displays information about processes.\r\n\r\nQUERY PROCESS [* | processid | username | sessionname | /ID:nn | programname]\r\n [/SERVER:servername]\r\n\r\n * Display all visible processes.\r\n processid Display process specified by processid.\r\n username Display all processes belonging to username.\r\n sessionname Display all processes running at sessionname.\r\n /ID:nn Display all processes running at session nn.\r\n programname Display all processes associated with programname.\r\n /SERVER:servername The Remote Desktop Session Host server to be queried.\r\n", "error": "Invalid parameter(s)\r\nDisplays information about processes.\r\n\r\nQUERY PROCESS [* | processid | username | sessionname | /ID:nn | programname]\r\n [/SERVER:servername]\r\n\r\n * Display all visible processes.\r\n processid Display process specified by processid.\r\n username Display all processes belonging to username.\r\n sessionname Display all processes running at sessionname.\r\n /ID:nn Display all processes running at session nn.\r\n programname Display all processes associated with programname.\r\n /SERVER:servername The Remote Desktop Session Host server to be queried.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\qprocess.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\WINSTA.dll", "C:\\Windows\\system32\\UTILDLL.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\srvcli.dll", "C:\\Windows\\system32\\browcli.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\logoncli.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "query.exe-8A7520A6CC2A2968F4A8EE4DB946AD8D": { "file_name": "query.exe", "file_path": "C:\\Windows\\system32\\query.exe", "hash_md5": "8A7520A6CC2A2968F4A8EE4DB946AD8D", "hash_sha1": "B7B0589F7CA2A526F77E39BD6534CBD8A53BC7D0", "hash_sha256": "3369E8FEA09C3C226D636B13108DA357093D0D98214236417839A94F56D3BA02", "hash_sha384": "DB9ED4EACEEB20C1F895DC2066E0F1AD08B2485EDA4A0D1864B463180B2A0EF1B635E34287AD824EA614C9A651F4B093", "hash_sha512": "A0643B80F86B18F40BF7717B131341AFCB43158705B8339C717BC78D79F3BFA318759CF8A548427F2D3AD59EF5296B1EA70CEA0E1E812417CB2D02AA61D7D48D", "hash_ssdeep": "384:5yKvwEHdWH1ZMqxdBeEh+98XfGHK2aKPoWW3W:8Kv5SVBA984vP8", "hash_imp": "CCC9DA4A55E90DFE34CBCDB066D6A6B3", "hash_pesha1": "A4493A79E3020E560A71C4B67CE78FAE8ABC66D4", "hash_pe256": "720EBD80DA487D87055B12A3596F6EEAD620FB458CCEF94CB0F51532EEC87FB3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MultiUser Query Utility", "meta_original_filename": "query.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/3369e8fea09c3c226d636b13108da357093d0d98214236417839a94f56d3ba02/detection/", "output": "QUERY { PROCESS | SESSION | TERMSERVER | USER }\r\n", "runtime_modules": [ "C:\\Windows\\system32\\query.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\REGAPI.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "error": "Invalid parameter(s)\r\nQUERY { PROCESS | SESSION | TERMSERVER | USER }\r\n" }, "quser.exe-6309F1482DAB3BDE91074316892BDCA7": { "file_name": "quser.exe", "file_path": "C:\\Windows\\system32\\quser.exe", "hash_md5": "6309F1482DAB3BDE91074316892BDCA7", "hash_sha1": "02FF8CF4670F02626DF7FD9868751819A402AF84", "hash_sha256": "CCFAF494E520E4F265AD1DE5252979809F1A28EB002F0E79C52981B00E63AC4F", "hash_sha384": "0495B01968C28A67BC6B7183F631342CE94127C69889C2068984AE0E58BB6D9C16230497F5A30CE81EAA6EEE12E072C2", "hash_sha512": "C3AFEF77938B7E21A0438F9D06A65680EED07038314D7C7B7D3DF5ACD536EBF9CCFDBB3A4D02237FF09634E8855003AC1C3E291A95A15AF4FF45BE44B68548FB", "hash_ssdeep": "768:WdcgSIZE45pVrLSoYMmWyDwK89SaAY9JxxXp:69SgVrqySaAYpxXp", "hash_imp": "EA8421BD383CD44D7C13D5BBB67DDFA5", "hash_pesha1": "1BD4DE1A2F2CAC59060157D895D8850BBA1C074C", "hash_pe256": "A34E9C89FA4240FDB6BA99DE94BEEE3DE7A7E4A76F021266ED900E1DE0B9877A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query User Utility", "meta_original_filename": "quser.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/ccfaf494e520e4f265ad1de5252979809f1a28eb002f0e79c52981b00e63ac4f/detection/", "output": "Display information about users logged on to the system.\r\n\r\nQUERY USER [username | sessionname | sessionid] [/SERVER:servername]\r\n\r\n username Identifies the username.\r\n sessionname Identifies the session named sessionname.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server to be queried (default is current).\r\n\r\n", "error": "Invalid parameter(s)\r\nDisplay information about users logged on to the system.\r\n\r\nQUERY USER [username | sessionname | sessionid] [/SERVER:servername]\r\n\r\n username Identifies the username.\r\n sessionname Identifies the session named sessionname.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server to be queried (default is current).\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\quser.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\WINSTA.dll", "C:\\Windows\\system32\\UTILDLL.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\srvcli.dll", "C:\\Windows\\system32\\browcli.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\logoncli.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "qwinsta.exe-9322C72AB11E725B098552A5FAE0F655": { "file_name": "qwinsta.exe", "file_path": "C:\\Windows\\system32\\qwinsta.exe", "hash_md5": "9322C72AB11E725B098552A5FAE0F655", "hash_sha1": "C47948B8701E1197AC582C50F5E1D1A74607285F", "hash_sha256": "E1AE2EC83FEC0C8CF01B9E4C3DA910BE61ABF3071E56EDA834590C405E8E4E69", "hash_sha384": "70006E1A37A607F00F63B1222671653C4FF5BDAD6B98DD81DBDE1F88DD7AE585F71509FFCBDE1958CF23197371E428D1", "hash_sha512": "C11682E2229B4A2E7EC2FD1FE2FA4A988109D4743373C5530D7BC45EDB75B78541993B948DA08A63FEF894AC3D8AAA37575F2CF485191AE66BFE235C0DDF5EBD", "hash_ssdeep": "768:xLqMld2QHrlnu6X5rJZc1l3SCAKK8rPXugLxVay:0dsBNX5rjGP6y", "hash_imp": "45B4A06EB57D86287767753D3ED73862", "hash_pesha1": "CC77569004C78AC0FC628B1AC7ED6987BABDCAEE", "hash_pe256": "EC16345A41095FB4A8A3E7B2C26F06B6A149788D23B73B15D44AEEA30853F759", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query Session Utility", "meta_original_filename": "qwinsta.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/e1ae2ec83fec0c8cf01b9e4c3da910be61abf3071e56eda834590c405e8e4e69/detection/", "output": "Display information about Remote Desktop Services sessions.\r\n\r\nQUERY SESSION [sessionname | username | sessionid]\r\n [/SERVER:servername] [/MODE] [/FLOW] [/CONNECT] [/COUNTER] [/VM]\r\n\r\n sessionname Identifies the session named sessionname.\r\n username Identifies the session with user username.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server to be queried (default is current).\r\n /MODE Display current line settings.\r\n /FLOW Display current flow control settings.\r\n /CONNECT Display current connect settings.\r\n /COUNTER Display current Remote Desktop Services counters information.\r\n /VM Display information about sessions within virtual machines.\r\n\r\n", "error": "Invalid parameter(s)\r\nDisplay information about Remote Desktop Services sessions.\r\n\r\nQUERY SESSION [sessionname | username | sessionid]\r\n [/SERVER:servername] [/MODE] [/FLOW] [/CONNECT] [/COUNTER] [/VM]\r\n\r\n sessionname Identifies the session named sessionname.\r\n username Identifies the session with user username.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server to be queried (default is current).\r\n /MODE Display current line settings.\r\n /FLOW Display current flow control settings.\r\n /CONNECT Display current connect settings.\r\n /COUNTER Display current Remote Desktop Services counters information.\r\n /VM Display information about sessions within virtual machines.\r\n\r\n" }, "rasautou.exe-33AA72B1C83985F0FE3F51E1E0C8C5DF": { "file_name": "rasautou.exe", "file_path": "C:\\Windows\\system32\\rasautou.exe", "hash_md5": "33AA72B1C83985F0FE3F51E1E0C8C5DF", "hash_sha1": "BC228FD0EDF7E3E2E07DE9325FD4BB6E76EC2AE7", "hash_sha256": "F9A9DB182517C828FC9E23EA1FDC9902C07BAD260DD4FD34086446BD9C109B70", "hash_sha384": "3E851178181C9BA16B0F60B9B8196DBC05725A4CD83EE1EB259911F7C6814658F691A72A5A774EFA656445F2A0745379", "hash_sha512": "EF5855018AA76FD6D36D78B53AEC28337D2D708E7EF85C83D92E07E3D29390C3B5B318B149EFFE25C1205FBFEEEE0D2CD9C529866C1111A49CEAE3621EE971C4", "hash_ssdeep": "384:/v5URAsJftvOTs27O++QETwRLRxkWMBW:XFSt4Y+bfx6", "hash_imp": "5EFE6408CA2D8147E0964600DE72232E", "hash_pesha1": "6C76BE40ED117095B7A1FA7DFA7217A9AFA893E7", "hash_pe256": "FCE02A7A9FDC57912213D451CB7C2617D3A65C0294BB2FD43178A07416998F68", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Access Dialer", "meta_original_filename": "rasdlui.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/f9a9db182517c828fc9e23ea1fdc9902c07bad260dd4fd34086446bd9c109b70/detection/", "children": "conhost.exe", "output": "Usage: rasautou [-f phonebook] [-a address] [-e entry] [-s]\r\n", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\rasautou.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\rasdlg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\rasautou.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\RASAPI32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\RASDLG.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\system32\\rasman.dll", "C:\\Windows\\system32\\MPRAPI.dll", "C:\\Windows\\system32\\rtutils.dll", "C:\\Windows\\system32\\DPAPI.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\TAPI32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "rasdial.exe-92260053B3B48CFEC6113464C76235FD": { "file_name": "rasdial.exe", "file_path": "C:\\Windows\\system32\\rasdial.exe", "hash_md5": "92260053B3B48CFEC6113464C76235FD", "hash_sha1": "D6CD743EC4F3910DF0E59977E5E68EA110EC33B4", "hash_sha256": "7427FE46C5A8B9A8E2A85FFE4AF8706473CE02ECD4168517C3FF81E6802302E1", "hash_sha384": "ACEEA98F8AC2311D25EF9428906EDF25D43BD7067ED3054F100D7C843C7A227C34B1D328BA74D621AD628790BB80AFD2", "hash_sha512": "E5016E501D7D5276D08DA3735260FE7C5F29FD3DEDD4C3F9B2DECECD9C3EBB6CC87AE4EA18A5E4746A054D28EAA9177DFD0A6B35A91D97452ADE2E7A71E9E9A7", "hash_ssdeep": "384:qMrNEf9uohXdznu+hyUje+GRmLjM2OOAIf+bxVY9t0yNwKWQVW:qMrN2uohXQ60NRa4DRbLytNNws", "hash_imp": "D893FB6DD140FF7107D0E41FFBAAAEC9", "hash_pesha1": "57B804D50266E680C52C58286255F12394CE1B88", "hash_pe256": "CEFEB555BDE7FE1DC9B0D6C8ADF0759590D0170D7611239192C1C5C07509ADA9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Access Command Line Dial UI", "meta_original_filename": "RASDIAL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/7427fe46c5a8b9a8e2a85ffe4af8706473ce02ecd4168517c3ff81e6802302e1/detection/", "output": "USAGE:\n\tC:\\Windows\\system32\\rasdial.exe entryname [username [password|*]] [/DOMAIN:domain]\n\t\t[/PHONE:phonenumber] [/CALLBACK:callbacknumber]\n\t\t[/PHONEBOOK:phonebookfile] [/PREFIXSUFFIX]\n\n\tC:\\Windows\\system32\\rasdial.exe [entryname] /DISCONNECT\n\n\tC:\\Windows\\system32\\rasdial.exe\n\n\tPlease refer to our privacy statement at \n\t'https://go.microsoft.com/fwlink/?LinkId=521839'\n\n", "runtime_modules": [ "C:\\Windows\\system32\\rasdial.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\RASAPI32.dll", "C:\\Windows\\system32\\rasman.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\rtutils.dll" ] }, "rasphone.exe-BD8A5DE9265002F340B476F626947BD8": { "file_name": "rasphone.exe", "file_path": "C:\\Windows\\system32\\rasphone.exe", "hash_md5": "BD8A5DE9265002F340B476F626947BD8", "hash_sha1": "BC919C43247EEA3470A2D3AEB523F0351B84F6F2", "hash_sha256": "A3124A4C8AA0EE06D9C1BCE39DD9C5E1E38BBC895D14FA36B75AFE1F2FD758E3", "hash_sha384": "32DF79D273D25449C506DDFEB4EEDD1B5D1C0B129DF24D21AED2C8CF145509946A9E47532226312550F6CEC71DBF1488", "hash_sha512": "47C82457B1166EB8678F773B63DF3D1D9C480B0DC051511063F8CE065BA02AAEB4FE4183D3DBA1D69E21BE57EF01B3DC60418B51F66CE9A5EBBF339D0C05F832", "hash_ssdeep": "768:pDwNtItOtllxfGxZtcDlr9jb7WsA6klONFEYkwy:poWAYZyhhWN6k9Zwy", "hash_imp": "C940443312A7232B26BCFD8DB2823083", "hash_pesha1": "A1F99694EEB50BE728126F18A28921F104FAAAB9", "hash_pe256": "1676CF6BCCC14C5EE863EA8B15083C979894C84A66F44051574B514B155FE7B9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Access Phonebook", "meta_original_filename": "rasphone.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/a3124a4c8aa0ee06d9c1bce39dd9c5e1e38bbc895d14fa36b75afe1f2fd758e3/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\rasphone.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\rasphone.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\rtutils.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll" ], "runtime_window_title": "Dial-Up Networking Command Line" }, "rdpclip.exe-9E089ECF8B86983B7A77E3844CD02BB5": { "file_name": "rdpclip.exe", "file_path": "C:\\Windows\\system32\\rdpclip.exe", "hash_md5": "9E089ECF8B86983B7A77E3844CD02BB5", "hash_sha1": "0265C1718EC95B025D9719F3B4872826F8F4661F", "hash_sha256": "AF5CAE4B514215E530643A7FEA2D7A47A1B15F6E5610347B217D1ABFA4AE0F92", "hash_sha384": "E6D9E48E90A602FE3A19EDF4B56036CA427D727901C9ED6B4E1D6A0691F8F515BAE1287C5FD1C061D97E3212BB876313", "hash_sha512": "E7EE8D7D56D19BDD5103A58D5DE00BEAD5960BCD46703D5D5FC7F371DB1FD1C0F29F80B67DF2658EF508F80C41947C9CCB1258A7E252908E784AE519F4E71657", "hash_ssdeep": "12288:57MvYJAP0qgCcvijGlkEaaO1arUG94Ft+VN81h8bk969xh0yl:BMvYJw9ncvijGlkEaagarUGakN81hwDe", "hash_imp": "E3F33CEBF67721DAC951AFBD20321206", "hash_pesha1": "3EAC0DA1DDE4EB05E3CF74EEDBD36D03D7CF5508", "hash_pe256": "3EE747892157E03603B0909E0BE34986CDFF8298B50F4CCAAE0DFB5709AE1997", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Clipboard Monitor", "meta_original_filename": "rdpclip.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/af5cae4b514215e530643a7fea2d7a47a1b15f6e5610347b217d1abfa4ae0f92/detection/" }, "rdpinit.exe-21EEA9062EF5170CDA2BE72BE1FE4E6E": { "file_name": "rdpinit.exe", "file_path": "C:\\Windows\\system32\\rdpinit.exe", "hash_md5": "21EEA9062EF5170CDA2BE72BE1FE4E6E", "hash_sha1": "8AB546DB47EABAC4EBE0DD53BDDAAA1F530DB953", "hash_sha256": "22014BB1E218FD88042A894AB46D0008D8E85C9CCCF66C2B84CC123D432A7130", "hash_sha384": "762D1B08EC6921CCE0AF79E88D5084682A3938892DA2934C38639A80AC083CC64F600E8C46EF6A3B4B51F733773722E1", "hash_sha512": "2887943A0F9748CF86E02E65F22AE5565C412E32431B3884EE8B128D6F14A144BA8B0FAE30DA678B21948D0EFF221FD458D8E14C484C56DC7605E54AE2C84132", "hash_ssdeep": "6144:JioFXqVYUxrqnfuvB0bCQcECcH/fkqbheY/gsp7ShQ7XfIliL7HU3iYO:go60fuZ0bCWkqNeYoEWxiHw", "hash_imp": "03C2C81ACC74797856F58D21B0731BB8", "hash_pesha1": "E1B667D910F019167D5442164FA4F04B4BC48026", "hash_pe256": "F38AD3805FA91F26E1160649133E768334273DBEA735DCFBBC3CFB1FDB9F0075", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RemoteApp Logon Application", "meta_original_filename": "rdpinit.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/22014bb1e218fd88042a894ab46d0008d8e85c9cccf66c2b84cc123d432a7130/detection/" }, "rdpinput.exe-D9AECBDDE1C8307842E271CC6BD9C8B4": { "file_name": "rdpinput.exe", "file_path": "C:\\Windows\\system32\\rdpinput.exe", "hash_md5": "D9AECBDDE1C8307842E271CC6BD9C8B4", "hash_sha1": "780E9A8210D193E4E15DE0026169D056A93729FB", "hash_sha256": "0327DA6CF9C4F737758A45818F1DB141A0BA13DB7DFFE64F472193A8E72A8409", "hash_sha384": "369E5A3ADA0C3029AB907DFE553614B3E0BC77E248C970861FBC717A4FA371E82400FB859BF4511F5635DD8DB966EA10", "hash_sha512": "DE7F7771538197F3F3224D51229D6BC531D0240A8C0CABBA1D2399219E4429F03FDCC74EF2CE3371F056F4C6FF88DDA480DA5DA12527E727971180DA4DF780F6", "hash_ssdeep": "3072:5H+4ehRauwFQ3RB6h3BwJA+AUkatRfeFr15LlLWj8G4QJM:F+4tPQBB6h3BwJAUHw55dk", "hash_imp": "6F59526D95C39A80A445CB75532949FE", "hash_pesha1": "AAD6D3856938202EAC97E369BFFEAB2E68256F8A", "hash_pe256": "E0F4355AC58826DC00E0AF89241CD4DBA5666AFB325F71FA7D8EDF7499118B6D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Input Handler", "meta_original_filename": "rdpinput.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/0327da6cf9c4f737758a45818f1db141a0ba13db7dffe64f472193a8e72a8409/detection/" }, "RdpSa.exe-8B0E3A0C7B04E726AE7312DE79E6A817": { "file_name": "RdpSa.exe", "file_path": "C:\\Windows\\system32\\RdpSa.exe", "hash_md5": "8B0E3A0C7B04E726AE7312DE79E6A817", "hash_sha1": "956C964BC22F0C11458A1964431C70CBA964991D", "hash_sha256": "7BEA697939C4D7C207D1A7C3EA109392D214868311A7BDF1E8055367D9D27238", "hash_sha384": "2550840C994689E7F5EC991F09A03489E1EA12D44EB4AFA79AF3AFEC52A803A8767ACEFA1C24A2FF58FB4A3820888DC0", "hash_sha512": "695F892B217C45C51E13E0C422C118BCD55BAD8216578C01648E0D454D5437D22377FA62C3CC658B29F44A140D8C2AF704AB0A82372032CA8B1D034FA9EFD5A8", "hash_ssdeep": "768:gxjO/6AOeyqPsaaoRHRRXQoGGysFwZ3l27eeMeJJNtFAGqR:HGqLmoVzwX27eBedzZqR", "hash_imp": "3619BD154055B4F6C99B1940FA8DD864", "hash_pesha1": "E8181BBFCFD8371EAEDFC2DFB8FFD6D2A559B095", "hash_pe256": "B1F83C477FBF6D61B33AA1542C650370367EF8EBFFBA624D5B479496EC745C75", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Agent", "meta_original_filename": "RdpSa.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/64", "filescan_vtlink": "https://www.virustotal.com/gui/file/7bea697939c4d7c207d1a7c3ea109392d214868311a7bdf1e8055367d9d27238/detection/" }, "RdpSaProxy.exe-17B2235D6C0FB3E415CB29FC749CDF3C": { "file_name": "RdpSaProxy.exe", "file_path": "C:\\Windows\\system32\\RdpSaProxy.exe", "hash_md5": "17B2235D6C0FB3E415CB29FC749CDF3C", "hash_sha1": "FF3BF7BB3B9B9EA76C9B64CEC737B5FF531765F3", "hash_sha256": "FD58018194B07A634AD8F7D900BC8F97CA13D09A7C5064842D250A84F42D764D", "hash_sha384": "243E2CE4471667ADCE33CBE1B18F3BF1DFA1F447099BEF35AD66D33D4960FADBF1A29CFDF28E0C5603937652E2AAE682", "hash_sha512": "94A188F41C171726C4DD51C419CA09BA046A652D7A155F8B58C8A29F8E2F68E24A09F797DD295BE1EE131488DBF41AE1BEA3066BF4EDFD496C2A8734C772E865", "hash_ssdeep": "384:IEj5ZES2CVOz0XqC4Bcy8ABpxRCLmvKvKPNPtRvrAJyuWF9VWb:pPES2CIIXz4Bcs3xRCLmSCP1veyv", "hash_imp": "88A583FEAC58400B2FEE56AAD46A39B5", "hash_pesha1": "46B6E7B6BF9D7210728862EC01850088BEEAB87C", "hash_pe256": "9EBB2AA01AC448C41E942A2D88E7E889962CEAAF8109234B020170C16F750773", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Agent Proxy", "meta_original_filename": "RdpSaProxy.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/fd58018194b07a634ad8f7d900bc8f97ca13d09a7c5064842d250a84f42d764d/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC520": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\RdpSaProxy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "RdpSaUacHelper.exe-044DD898DDA4FA15E3ECF8CC5268DB3F": { "file_name": "RdpSaUacHelper.exe", "file_path": "C:\\Windows\\system32\\RdpSaUacHelper.exe", "hash_md5": "044DD898DDA4FA15E3ECF8CC5268DB3F", "hash_sha1": "C77AEAB0FDED7B1CE989CD9C5C435E5B9CE7AC9C", "hash_sha256": "EB835AB51C25B6B42BBCF488E65B06ABAA4131CC1617579C89AC8C7F4A1B24EC", "hash_sha384": "369DD20DBCD7A9A0DB9D6F4FEDA6C274B3F64992A1FAF2BD49D345850356C68A521198EC9B583796DE5F09951891B9DC", "hash_sha512": "55427BFBEE8E96B087E39C3C53C211C45DB396FD105D93EB062BA172E5970AAC6E7D7AF25F9343252399AF724C53092D149194A15D940159B0D95F1023D12560", "hash_ssdeep": "768:rYNypwAus4mk3zSS+NZwHzolhBBKnZ/8zs:rYIqbLSSs2HkLBUnZIs", "hash_imp": "CC73C1B0B35D95829ABCD9C03CEFCE0C", "hash_pesha1": "41D885F91983F35C9FB17B982624376C868B1259", "hash_pe256": "AD9A895CD897129ABC9A384ACB98AD9A5CDA16C37C89114DBBCD3524ABF9D894", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Agent UAC Helper", "meta_original_filename": "RdpSaUacHelper.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/eb835ab51c25b6b42bbcf488e65b06abaa4131cc1617579c89ac8c7f4a1b24ec/detection/", "runtime_modules": [ "C:\\Windows\\system32\\RdpSaUacHelper.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\WINSTA.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\coml2.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "rdpshell.exe-2E72DBCF0B650CFB8DE025782A760077": { "file_name": "rdpshell.exe", "file_path": "C:\\Windows\\system32\\rdpshell.exe", "hash_md5": "2E72DBCF0B650CFB8DE025782A760077", "hash_sha1": "D88A8C3981655E6E610D01173586ABB9EC9D0490", "hash_sha256": "0BA3EC75C65C2EB4FF89D6CAF49C0E46E6611DFDE6D0B92D9DE18C09D4C77678", "hash_sha384": "06BD1B03A799B30C9752B72B3917DC536655BED6C5F3FC64FE79E75D64654F8D34DE831C3AB1BDA3386998717497DB26", "hash_sha512": "D1563F2AEC8F7953CD0396EF443E3D0ACAB4040E78E561422A4B0DF1D6F902C66754B23E4778918C669474C2DBD0421E3AB553393C73D0A408B79E3C9A2D5A45", "hash_ssdeep": "12288:bu6cg57GqBj6x4h2oH4a8aIsiLykNcuNnkEX:bu699rxP0mp9iWuS", "hash_imp": "2A234F3A3B489835EBC515602FAEC4D0", "hash_pesha1": "8253DAD13A986936648A9E83BD5A22E82A12AE52", "hash_pe256": "7262E912C0B476B2879BDFEB117BE13F1CA37D6FA4DED231E1E8813D49AE756D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RemoteApp Shell", "meta_original_filename": "rdpshell.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/0ba3ec75c65c2eb4ff89d6caf49c0e46e6611dfde6d0b92d9de18c09d4c77678/detection/" }, "rdpsign.exe-B5A7F34701B56588E883679DFFF94974": { "file_name": "rdpsign.exe", "file_path": "C:\\Windows\\system32\\rdpsign.exe", "hash_md5": "B5A7F34701B56588E883679DFFF94974", "hash_sha1": "692695B128435BD941D19B2241EF6121803966E7", "hash_sha256": "D58172FFC44BC94722C950984D056919739FDFF69EAB646A06F499CB137204F6", "hash_sha384": "92AE9C45B04040700DEF13C18EAF0F9C51FA185420EE048601FA3E9771E83F3531C7636D865782BF62785ACA6B53174D", "hash_sha512": "A31CDB09B153516658017D5D7541EF8169BC168F413C82FF7C345706CC9233072AA0E9752A18C30A08AB5A4D95C1B0642B9224E06BC3170CB941084FC046264C", "hash_ssdeep": "1536:zLw3MR+4Owb0KL4cVr89b8u6XI52CLV1Ss3Nisj18XFf+tLt1wO8fHlXi2Wcn:oMg+oLbA452M1SqL1WmFl8fHE2W8", "hash_imp": "93E7CBA8D80F69855D2E770C0795E77F", "hash_pesha1": "265974455178D3D40EB7637E666D1045036D1BC5", "hash_pe256": "60053A42B9A993A92C53C1D45165863A322AFD4860C21A44308139A25F01F77D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Session Host Server Sign Tool", "meta_original_filename": "TSSignTool.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/d58172ffc44bc94722c950984d056919739fdff69eab646a06f499cb137204f6/detection/", "output": "All rdp file(s) have been succesfully signed.\r\n", "error": "NAME\r\n\r\nrdpsign [options] [items to sign]\r\n\r\nOPTIONS\r\n\r\n /sha256 HASH\r\n Specified the SHA256 hash of the signing certificate.\r\n /q\r\n Quiet mode: No output when success, minimal output when failed.\r\n /v\r\n Verbose mode: Display all warnings, messages, and status.\r\n /l\r\n Test signing and output results without actually replacing any of the inputs. Ignores when input files are on stdin.\r\n\r\n\r\n" }, "rdrleakdiag.exe-964A196D0F005A3F54F39B3E61D91770": { "file_name": "rdrleakdiag.exe", "file_path": "C:\\Windows\\system32\\rdrleakdiag.exe", "hash_md5": "964A196D0F005A3F54F39B3E61D91770", "hash_sha1": "0ED1D6EC09943BC33CD4AEAA56BAF822989412CA", "hash_sha256": "541A5E886E9D9767E66E8925D9C93C67AE5A01637A1826A6E34FB23CC6587387", "hash_sha384": "C020BF2EB7F6BCA640D4C34B7182CA8C9F98A782A9047689A2F6B68D1C155707D9AEBFA297A90B2B5A58EF022F229663", "hash_sha512": "7A456759FE49A743FF5ABD389654160C9C718F468012BD096DE20CE92B153643467F3306505044F87F819E2146AB6445072B238649AAC4AF9052113D552399E9", "hash_ssdeep": "768:4TJ1oCGHKPqnUO9/cr50wp/Ub8qQH/2I36oNco2N/pIz:EYKPCrcCowQfr6oN2p", "hash_imp": "BAE40B14C0B85003690796B449FFD0E2", "hash_pesha1": "5694B8C1FB5C903D406AE98E304E2A1FB5DBE1EA", "hash_pe256": "2D5189991F2C9055970C9B41A16A2D0C184B09FAE0E335D5272BAB05051EA920", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Resource Leak Diagnostic", "meta_original_filename": "RdrLeakDiag.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/541a5e886e9d9767e66e8925d9c93c67ae5a01637a1826a6e34fb23cc6587387/detection/" }, "RDSPnf.exe-2D6D03BCF7356C0FAC6503DF461ED7F7": { "file_name": "RDSPnf.exe", "file_path": "C:\\Windows\\system32\\RDSPnf.exe", "hash_md5": "2D6D03BCF7356C0FAC6503DF461ED7F7", "hash_sha1": "10894E9C7FD89A390E9AC104507140BBDCE51B39", "hash_sha256": "BF40CB2B501FB0D61CEEA0EC56967A7599447ED2480407620CB4BAA1668F5F6C", "hash_sha384": "8B56A3248BBF9AE9350F95F50CBFF1704E6DA8ABACB0A384BA1EA550075F5C7ECD279D44ABC2E32DBD891B22F3FD1F3D", "hash_sha512": "6D8A5313DD4E292C4D6D4A521558AFBF57804DF5E92B2ED2AEA8C744CB625FFA7678D4487BF162AA413AD16C0E8A972C430E9916C5B1CD9EE82FFAD227A0EB13", "hash_ssdeep": "1536:MbFlAu/QGfcAUMnphJNAoLNIW56HursL/feLihAKOpUoYsVik+TMhZfyo8DdyvWc:Mbd/5/1LNMPLHe+hFOMANyo8DUf9", "hash_imp": "98BF2FB38C5038CB4939587E47F8A01B", "hash_pesha1": "0B7CD68D446712F69460EC0A4EAC1BA59C9F1ED9", "hash_pe256": "57B17B8150FDD0BA966051D0C847F8712A0A0A6A27AF63E843295DA6FE9A7176", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows All-User Installer Profile Processing Module", "meta_original_filename": "RDSPnf.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1432 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1432", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/bf40cb2b501fb0d61ceea0ec56967a7599447ed2480407620cb4baa1668f5f6c/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC3DC": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\RDSPnf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\AppXAllUserStore.dll", "C:\\Windows\\system32\\FirewallAPI.dll", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\fwbase.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\rdsappxhelper.dll", "C:\\Windows\\system32\\AppXDeploymentClient.dll", "C:\\Windows\\system32\\StateRepository.Core.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "RDVGHelper.exe-07FA6595AEF88D7E31BF8F37F3B5F22E": { "file_name": "RDVGHelper.exe", "file_path": "C:\\Windows\\system32\\RDVGHelper.exe", "hash_md5": "07FA6595AEF88D7E31BF8F37F3B5F22E", "hash_sha1": "84B27C022F082E291E2C42D853C0C78FBDF80423", "hash_sha256": "CA4C0E31BB8DDF99B5F3DF595B09FB4BC93A1CC7D465ADC289488D16683CD935", "hash_sha384": "EC265A85FEF53F0FBA32F5486A081184DF03F787637ACAFFB30D3F0710C1CB8AED7A480052082C2F32A73E4257A9BEED", "hash_sha512": "853231466B2BD69E159CCF359F55DF4962DF31678BBE5882A351CA70426698041CEF496AB0288A0684760D5E2C6CBCC08C580682E67E57369295538ED1BC3F12", "hash_ssdeep": "1536:1z0Rj6X0UIlQBtL07MoVly+xhAlnPVZ6mgDPKA8hBRhOSE/1XpnvybPDTHYY4l48:146zLGIShAtgIhbhEbvykY4sSVvSIXp", "hash_imp": "77C9A6F5B3BB2C2530EC50E139498CFB", "hash_pesha1": "AF08C0331EC6CF036603889B712BE25CCDDDAA81", "hash_pe256": "60A5915CBF9AAEFBA8A6FA1881FD1622868EA15B6F74F0187D6691154BF38E8D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RemoteFX Helper", "meta_original_filename": "RDVGHelper.exe", "meta_product_name": "RemoteFX Helper", "meta_file_version": "1, 1, 0, 0", "meta_product_version": "0, 0, 0, 1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 2009", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/ca4c0e31bb8ddf99b5f3df595b09fb4bc93a1cc7d465adc289488d16683cd935/detection/", "runtime_modules": [ "C:\\Windows\\system32\\RDVGHelper.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\WTSAPI32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "ReAgentc.exe-4FF3D4C021431F4A09A363E6F1D5B550": { "file_name": "ReAgentc.exe", "file_path": "C:\\Windows\\system32\\ReAgentc.exe", "hash_md5": "4FF3D4C021431F4A09A363E6F1D5B550", "hash_sha1": "DD63841FA98500C0FCB54991201696D7F3B26607", "hash_sha256": "93CD96077494331129E20718A8E9B21E7BAD04DA6CE563FCC56D03AE986DC800", "hash_sha384": "8FADA4FB844BD67154EB96B58CB642EF8B8B4E835B1D7DAC78E1F4181913D84044AE64FA8DEFEE7BA999ACEC6AD7AC8D", "hash_sha512": "FD5A0281392AC56F67E555D14177DE65BA293B69CD0A2315065BA938196AC71073D407A2C1BF40FFECD5AAF1D4E592B5C2585A1751889D312E4E1264127014A1", "hash_ssdeep": "768:K+xfqLK+0Snlpr/yLg2oobvPk/l6s9owLptiAJ:KuhgtA9oow/l62owPiAJ", "hash_imp": "2455C15D4650B236D7331E66AA15D2CD", "hash_pesha1": "041378BFD205ED4413A85ECD1DD4797FC88E8EF7", "hash_pe256": "51703251823B212DD86B746323E9C40FFB09F9F54B113EAF285F88C2A635B68A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Recovery Agent", "meta_original_filename": "reagentc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/93cd96077494331129e20718a8e9b21e7bad04da6ce563fcc56d03ae986dc800/detection/", "output": "\r\nConfigures the Windows Recovery Environment (Windows RE) and system reset.\r\n\r\nREAGENTC.EXE <command> <arguments>\r\n\r\nThe following commands can be specified:\r\n\r\n /info - Displays Windows RE and system reset configuration\r\n information.\r\n /setreimage - Sets the location of the custom Windows RE image.\r\n /enable - Enables Windows RE.\r\n /disable - Disables Windows RE.\r\n /boottore - Configures the system to start Windows RE next time the\r\n system starts up.\r\n /setbootshelllink - Adds an entry to the Reset and Restore page in the boot\r\n menu.\r\n\r\nFor more information about these commands and their arguments, type\r\nREAGENTC.EXE <command> /?.\r\n\r\n Examples:\r\n REAGENTC.EXE /setreimage /?\r\n REAGENTC.EXE /disable /?\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\ReAgentc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll" ], "error": "\r\nConfigures the Windows Recovery Environment (Windows RE) and system reset.\r\n\r\nREAGENTC.EXE <command> <arguments>\r\n\r\nThe following commands can be specified:\r\n\r\n /info - Displays Windows RE and system reset configuration\r\n information.\r\n /setreimage - Sets the location of the custom Windows RE image.\r\n /enable - Enables Windows RE.\r\n /disable - Disables Windows RE.\r\n /boottore - Configures the system to start Windows RE next time the\r\n system starts up.\r\n /setbootshelllink - Adds an entry to the Reset and Restore page in the boot\r\n menu.\r\n\r\nFor more information about these commands and their arguments, type\r\nREAGENTC.EXE <command> /?.\r\n\r\n Examples:\r\n REAGENTC.EXE /setreimage /?\r\n REAGENTC.EXE /disable /?\r\n\r\n" }, "recover.exe-B86B2EABEDC1FC6980C802F75FB9C408": { "file_name": "recover.exe", "file_path": "C:\\Windows\\system32\\recover.exe", "hash_md5": "B86B2EABEDC1FC6980C802F75FB9C408", "hash_sha1": "F906C8F84C5E9C96766B9F02A17B7312ED658D66", "hash_sha256": "B6EC80D55C7BA99165767D74E219D9393E81CA0B7CC1B65E6A697E84E62B9DFD", "hash_sha384": "AEE2FE41FAAF2A2457FC9DC1F4BDB1E87361631FCC608C20D3320890615E058C5611FC334ADCBAD0A878EDBBE3916A9A", "hash_sha512": "C0566422314622CF27D761765CA16AA404686B226496885F5691DDCF3F57D057F01FF8D78347F13B563FDE188AD4B090ED8FE3AF9AF02B3DE3A958B035E6CCF5", "hash_ssdeep": "192:E8nsoUysmXLBrQQ/Ao1mzY1RDfN09BpUZTj6qZ2G08lTSm2TWPnWnh:xn5XL51oo1mEPDm9XUZv12jW2TWPnW", "hash_imp": "15EC0ACE85D3228ADCC66943670EF7D8", "hash_pesha1": "2F1F2690104C9D62A1A45C1C045BDD361E9B133F", "hash_pe256": "1944910EED648E72F490AEE459D2155A0B7FF21D8B405938BD3D17C5407A582A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Recover Files Utility", "meta_original_filename": "Recover.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b6ec80d55c7ba99165767d74e219d9393e81ca0b7cc1b65e6a697e84e62b9dfd/detection/", "output": "Recovers readable information from a bad or defective disk.\r\n\r\nRECOVER [drive:][path]filename\r\nConsult the online Command Reference in Windows Help\r\nbefore using the RECOVER command.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\ulib.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\recover.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\ulib.dll", "C:\\Windows\\system32\\IfsUtil.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\SYSTEM32\\fsutilext.dll", "C:\\Windows\\system32\\UNTFS.DLL", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "RecoveryDrive.exe-49AAFC5D89D8F9C6663798C9A251D464": { "file_name": "RecoveryDrive.exe", "file_path": "C:\\Windows\\system32\\RecoveryDrive.exe", "hash_md5": "49AAFC5D89D8F9C6663798C9A251D464", "hash_sha1": "9B6E2067DDC128EC38C02D1DC364D32404083E2F", "hash_sha256": "CAA922BE6428AB6D74795745C197F2F2AC23F16EF4C41255591C8513B0013FB6", "hash_sha384": "5DD5243FADCC6E6A73F79CCD6DDD9BA3F241A7E09159C7196B6B4ADC7281F890B08A7D23EE70698CF2AD292B14345A82", "hash_sha512": "4C8C938F9CD0B7C71D24D81259079649F045B07E7992B63E7AC67BA65B8B56D9CDBCCC589044D708FDD860FF02DA6513D8A170A16F88FA74C7A8BBE74D245AD7", "hash_ssdeep": "12288:Q6yg/pQ4jFwzkiizxRZACS5P8oJhVRGOTo5tFnYtBMbJ4YRWDEzp7BJD83HEl1:Q6y34jDK5RJh+mWS+Lzp7DiE", "hash_imp": "F734444B0097091027AF9D4569A74AAD", "hash_pesha1": "6FFAA7E53EB816F543E19EA405A7078E5950130C", "hash_pe256": "666B947F39832DF8D8302A8A4E6C659122628C04534760BCCB2825973142C3D3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Recovery Media Creator", "meta_original_filename": "RECOVERYDRIVE.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "1/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/caa922be6428ab6d74795745c197f2f2ac23f16ef4c41255591c8513b0013fb6/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\RecoveryDrive.exe.mui": "File", "(RW-) C:\\Windows\\Logs\\RecoveryDrive\\setupact.log": "File", "\\BaseNamedObjects\\SetupLogSection": "Section", "(RW-) C:\\Windows\\Logs\\RecoveryDrive\\setuperr.log": "File", "(RW-) C:\\Windows\\Logs\\RecoveryDrive\\diagerr.xml": "File", "(RW-) C:\\Windows\\Logs\\RecoveryDrive\\diagwrn.xml": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\RecoveryDrive.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\system32\\UNATTEND.DLL", "C:\\Windows\\system32\\WIMGAPI.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\VSSAPI.DLL", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\ReAgent.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\WDSCORE.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\system32\\WOFUTIL.dll", "C:\\Windows\\system32\\WINHTTP.dll", "C:\\Windows\\system32\\VssTrace.DLL", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\system32\\dbgcore.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\OLEACC.dll" ], "runtime_window_title": "Recovery Drive" }, "refsutil.exe-16618CD3AE14EE8715E4C9CAFEE5E711": { "file_name": "refsutil.exe", "file_path": "C:\\Windows\\system32\\refsutil.exe", "hash_md5": "16618CD3AE14EE8715E4C9CAFEE5E711", "hash_sha1": "3C8AFBE88E40BEE226F81462B02B87150255BA4D", "hash_sha256": "DD917BF2A33B6B68C49F3FA8EBD18FA3EC90320633C87988C97C468C57F5E793", "hash_sha384": "EB7ABDB8F16C596DB3EE276D5E9F226726CBFA281B1DE90B343BB6013B8F4118EFCE40D911FB17794B620FB8184C5B9B", "hash_sha512": "7F5A0FF3B85EBC361EDC5C38C5A7B06BCE64E3F39F70A1C457D9DF5881F496F58A196E5CFD38663F7EB50FB142F8DB0AAB9DCF389B6E95BA2D3F74BE93E838B1", "hash_ssdeep": "24576:Cg4UOcxn8jYUOwuDfHT1joSsiN8nqdvcp0BYbbnEGKx:RPOYn8jYUOHjHJcSsixpG0ibbEGKx", "hash_imp": "741B8A56CE763DB1E1006B767138126E", "hash_pesha1": "C830F7EF8ED683E13C3C4B90260335328EB80BCF", "hash_pe256": "48D452CE65DD8199E66B3AD1E36B423D974E9DFF023DB1DC1BADD65286EEA69E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "refsutil.exe", "meta_original_filename": "refsutil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/dd917bf2a33b6b68c49f3fa8ebd18fa3ec90320633c87988c97c468c57f5e793/detection/", "output": "---- Commands Supported ----\r\nfixboot Repair boot sectors\r\nleak Leak Detection and Fixing\r\nsalvage Salvage operations for corrupt volume\r\ntriage Handle corruptions\r\n", "runtime_modules": [ "C:\\Windows\\system32\\refsutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "reg.exe-8A93ACAC33151793F8D52000071C0B06": { "file_name": "reg.exe", "file_path": "C:\\Windows\\system32\\reg.exe", "hash_md5": "8A93ACAC33151793F8D52000071C0B06", "hash_sha1": "429DF8371B437209D79DC97978C33157D1A71C4B", "hash_sha256": "19316D4266D0B776D9B2A05D5903D8CBC8F0EA1520E9C2A7E6D5960B6FA4DCAF", "hash_sha384": "2C6EF95487F35401C121BBED23F686E976E0DCA52537E03542C44E0A3B3D84AC536ABE17D9D83F693EBFAC47F350B3E7", "hash_sha512": "79B676C9E349E38AEF652271D406551F9C350CCAAAB01FAA305D9E40F11059E4F814A5FA91863AF1B94AB198B563D9F57009158CFA5E535ED1236FAEB163F7E5", "hash_ssdeep": "1536:CbKnXHpwaQBT4Tl9RuV9DXs11jy1Cz/Y1Z+2hGfVhtOXKnv86F1:CGb+4x9RwDXEW1CaMS8DOXqv86", "hash_imp": "BE482BE427FE212CFEF2CDA0E61F19AC", "hash_pesha1": "2E1E9F034F57388A5401653C942CC8BA6A7D92AC", "hash_pe256": "44AB6478A02D197714785D1BB2CCD1B48C9B31F6D3491201738F954CEB7F604E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Console Tool", "meta_original_filename": "reg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/19316d4266d0b776d9b2a05d5903d8cbc8f0ea1520e9c2a7e6d5960b6fa4dcaf/detection/", "output": "\r\nREG Operation [Parameter List]\r\r\n\r\r\n Operation [ QUERY | ADD | DELETE | COPY |\r\r\n SAVE | LOAD | UNLOAD | RESTORE |\r\r\n COMPARE | EXPORT | IMPORT | FLAGS ]\r\r\n\r\r\nReturn Code: (Except for REG COMPARE)\r\r\n\r\r\n 0 - Successful\r\r\n 1 - Failed\r\r\n\r\r\nFor help on a specific operation type:\r\r\n\r\r\n REG Operation /?\r\r\n\r\r\nExamples:\r\r\n\r\r\n REG QUERY /?\r\r\n REG ADD /?\r\r\n REG DELETE /?\r\r\n REG COPY /?\r\r\n REG SAVE /?\r\r\n REG RESTORE /?\r\r\n REG LOAD /?\r\r\n REG UNLOAD /?\r\r\n REG COMPARE /?\r\r\n REG EXPORT /?\r\r\n REG IMPORT /?\r\r\n REG FLAGS /?\r\r\n", "error": "ERROR: Invalid Argument/Option - '--help'.\r\nType \"REG /?\" for usage.\r\n" }, "regedt32.exe-21A5E8E802DE750575AE1FE9EB4CCBFA": { "file_name": "regedt32.exe", "file_path": "C:\\Windows\\system32\\regedt32.exe", "hash_md5": "21A5E8E802DE750575AE1FE9EB4CCBFA", "hash_sha1": "14B5F144402DD793958799EF9E0EB25F3C20597C", "hash_sha256": "8E0AFE17637281A257CA5BCAE90CE4AA9EF4E9C2EC57B16DFDA08B27DCC6C72F", "hash_sha384": "3D5BE37DA429158D35207C1C9BC814D911F7BACD144B44564D20D67DE29665D979400030DB554A3DD4869C0656E919F0", "hash_sha512": "EC8316EC73DDF85C33E09A827F2B50FBA1DF371B7200F2EC44F6C89047E2939F36FB34D15D0E11A6B613177F14D555F28AD2732A4443C6C85589601B6C73405C", "hash_ssdeep": "192:E2ry5uafCNQdQ54r1yQ7CuMKzgNi6xtU/1EWQxW:E2ujS2RF7CucNi8tQEWQxW", "hash_imp": "A3060EC916831020104FAE5BC9414975", "hash_pesha1": "C02C998DE32B4D4B53710F5E5BA504FB6743FA6B", "hash_pe256": "5342162CB00EB324773ADB05BF2D2981859EB1068CBCA95F7E27EE843BC99735", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Editor Utility", "meta_original_filename": "regedt32.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/8e0afe17637281a257ca5bcae90ce4aa9ef4e9c2ec57b16dfda08b27dcc6c72f/detection/", "children": "regedit.exe", "runtime_modules": [ "C:\\Windows\\system32\\regedt32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll" ] }, "regini.exe-28CA983582606E250402D02510A2C1F8": { "file_name": "regini.exe", "file_path": "C:\\Windows\\system32\\regini.exe", "hash_md5": "28CA983582606E250402D02510A2C1F8", "hash_sha1": "BABD9AD165050EBA11269E40DFB251473D7CE40D", "hash_sha256": "CE02C12CFF31E588EE786462599F38528F899EAB8690EDA74744D04215107DFF", "hash_sha384": "46129E47A56245F7A7E036FDA610EE78B36DEB8BDEFFB35A2ADCC5922BE92A8A4B6B8E33878CA83A71EFCBA7E2CF3C50", "hash_sha512": "4CFD9DFC2F2F122DED375E494A374632699C51902D14C1C20424B97DD94BEE9579344329421E5905023A3C1D4AEF40A9F6DBB3DE6DF5F102C8C03A308F16BE17", "hash_ssdeep": "768:my2UkLBpkMEkutacvTKWU5X1Py+cP7MHliYw82i/PGlVogExyylwIcgSz:mJUWlEkz5Wmy+cMERi/pUu/Sz", "hash_imp": "59EADF2E64B87E9C2B8F545B5E2B4A03", "hash_pesha1": "8D40760C3E2D5F42983B914544D2A943224EA9C5", "hash_pe256": "34D0E1F681813A46DA43B1E02F69D3006E754DDE8B083F7A2A8F780920DEB060", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Initializer", "meta_original_filename": "REGINI.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/ce02c12cff31e588ee786462599f38528f899eab8690eda74744d04215107dff/detection/", "error": "usage: REGINI [-m \\\\machinename | -h hivefile hiveroot]\r\n [-i n] [-o outputWidth]\r\n [-b] textFiles...\r\n\r\nwhere: -m specifies a remote Windows NT machine whose registry is to be manipulated.\r\n -h specifies a specify local hive to manipulate.\r\n -i n specifies the display indentation multiple. Default is 4\r\n -o outputWidth specifies how wide the output is to be. By default the\r\n outputWidth is set to the width of the console window if standard\r\n output has not been redirected to a file. In the latter case, an\r\n outputWidth of 240 is used.\r\n\r\n -b specifies that REGINI should be backward compatible with older\r\n versions of REGINI that did not strictly enforce line continuations\r\n and quoted strings Specifically, REG_BINARY, REG_RESOURCE_LIST and\r\n REG_RESOURCE_REQUIREMENTS_LIST data types did not need line\r\n continuations after the first number that gave the size of the data.\r\n It just kept looking on following lines until it found enough data\r\n values to equal the data length or hit invalid input. Quoted\r\n strings were only allowed in REG_MULTI_SZ. They could not be\r\n specified around key or value names, or around values for REG_SZ or\r\n REG_EXPAND_SZ Finally, the old REGINI did not support the semicolon\r\n as an end of line comment character.\r\n \r\n textFiles is one or more ANSI or Unicode text files with registry data.\r\n \r\n Some general rules are:\r\n Semicolon character is an end-of-line comment character, provided it\r\n is the first non-blank character on a line\r\n \r\n Backslash character is a line continuation character. All\r\n characters from the backslash up to but not including the first\r\n non-blank character of the next line are ignored. If there is more\r\n than one space before the line continuation character, it is\r\n replaced by a single space.\r\n \r\n Indentation is used to indicate the tree structure of registry keys\r\n The REGDMP program uses indentation in multiples of 4. You may use\r\n hard tab characters for indentation, but embedded hard tab\r\n characters are converted to a single space regardless of their\r\n position\r\n \r\n Values should come before child keys, as they are associated with\r\n the previous key at or above the value's indentation level.\r\n \r\n For key names, leading and trailing space characters are ignored and\r\n not included in the key name, unless the key name is surrounded by\r\n quotes. Imbedded spaces are part of a key name.\r\n \r\n Key names can be followed by an Access Control List (ACL) which is a\r\n series of decimal numbers, separated by spaces, bracketed by a\r\n square brackets (e.g. [8 4 17]). The valid numbers and their\r\n meanings are:\r\n \r\n 1 - Administrators Full Access\r\n 2 - Administrators Read Access\r\n 3 - Administrators Read and Write Access\r\n 4 - Administrators Read, Write and Delete Access\r\n 5 - Creator Full Access\r\n 6 - Creator Read and Write Access\r\n 7 - World Full Access\r\n 8 - World Read Access\r\n 9 - World Read and Write Access\r\n 10 - World Read, Write and Delete Access\r\n 11 - Power Users Full Access\r\n 12 - Power Users Read and Write Access\r\n 13 - Power Users Read, Write and Delete Access\r\n 14 - System Operators Full Access\r\n 15 - System Operators Read and Write Access\r\n 16 - System Operators Read, Write and Delete Access\r\n 17 - System Full Access\r\n 18 - System Read and Write Access\r\n 19 - System Read Access\r\n 20 - Administrators Read, Write and Execute Access\r\n 21 - Interactive User Full Access\r\n 22 - Interactive User Read and Write Access\r\n 23 - Interactive User Read, Write and Delete Access\r\n \r\n If there is an equal sign on the same line as a left square bracket\r\n then the equal sign takes precedence, and the line is treated as a\r\n registry value. If the text between the square brackets is the\r\n string DELETE with no spaces, then REGINI will delete the key and\r\n any values and keys under it.\r\n \r\n For registry values, the syntax is:\r\n \r\n value Name = type data\r\n \r\n Leading spaces, spaces on either side of the equal sign and spaces\r\n between the type keyword and data are ignored, unless the value name\r\n is surrounded by quotes. If the text to the right of the equal sign\r\n is the string DELETE, then REGINI will delete the value.\r\n \r\n The value name may be left off or be specified by an at-sign\r\n character which is the same thing, namely the empty value name. So\r\n the following two lines are identical:\r\n \r\n = type data\r\n @ = type data\r\n \r\n This syntax means that you can't create a value with leading or\r\n trailing spaces, an equal sign or an at-sign in the value name,\r\n unless you put the name in quotes.\r\n \r\n Valid value types and format of data that follows are:\r\n \r\n REG_SZ text\r\n REG_EXPAND_SZ text\r\n REG_MULTI_SZ \"string1\" \"str\"\"ing2\" ...\r\n REG_DATE mm/dd/yyyy HH:MM DayOfWeek\r\n REG_DWORD numberDWORD\r\n REG_BINARY numberOfBytes numberDWORD(s)...\r\n REG_NONE (same format as REG_BINARY)\r\n REG_RESOURCE_LIST (same format as REG_BINARY)\r\n REG_RESOURCE_REQUIREMENTS (same format as REG_BINARY)\r\n REG_RESOURCE_REQUIREMENTS_LIST (same format as REG_BINARY)\r\n REG_FULL_RESOURCE_DESCRIPTOR (same format as REG_BINARY)\r\n REG_QWORD numberQWORD\r\n REG_MULTISZ_FILE fileName\r\n REG_BINARYFILE fileName\r\n \r\n If no value type is specified, default is REG_SZ\r\n \r\n For REG_SZ and REG_EXPAND_SZ, if you want leading or trailing spaces\r\n in the value text, surround the text with quotes. The value text\r\n can contain any number of imbedded quotes, and REGINI will ignore\r\n them, as it only looks at the first and last character for quote\r\n characters.\r\n \r\n For REG_MULTI_SZ, each component string is surrounded by quotes. If\r\n you want an imbedded quote character, then double quote it, as in\r\n string2 above.\r\n \r\n For REG_BINARY, the value data consists of one or more numbers The\r\n default base for numbers is decimal. Hexidecimal may be specified\r\n by using 0x prefix. The first number is the number of data bytes,\r\n excluding the first number. After the first number must come enough\r\n numbers to fill the value. Each number represents one DWORD or 4\r\n bytes. So if the first number was 0x5 you would need two more\r\n numbers after that to fill the 5 bytes. The high order 3 bytes\r\n of the second DWORD would be ignored.\r\n \r\n Whenever specifying a registry path, either on the command line\r\n or in an input file, the following prefix strings can be used:\r\n \r\n HKEY_LOCAL_MACHINE\r\n HKEY_USERS\r\n HKEY_CURRENT_USER\r\n USER:\r\n \r\n Each of these strings can stand alone as the key name or be followed\r\n a backslash and a subkey path.\r\n\r\n\r\nREGINI: Missing parameter(s) for -h switch\r\n", "runtime_modules": [ "C:\\Windows\\system32\\regini.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "Register-CimProvider.exe-CF426CFE35CA3AABBBF62C31244EF9E3": { "file_name": "Register-CimProvider.exe", "file_path": "C:\\Windows\\system32\\Register-CimProvider.exe", "hash_md5": "CF426CFE35CA3AABBBF62C31244EF9E3", "hash_sha1": "4957F28C6C18B2D14D9C4879C5A6769FB0D9618E", "hash_sha256": "088DE004B2ABC256739060C61B89A4B3EAA892907B0A61EA30C2EB4533ADD373", "hash_sha384": "F2D9A734C93F39A344C11319B0C244E74D924A941BBD4A8D27AB0B071287121D97D7279252E20A99ECFF52870221B3B3", "hash_sha512": "13874C7A150CF1DFFD1FA5211A738F73FDDBA9F2A55E60A281EF1276D7F1E7B4CE897789BAEBB922CEF639FDA2099B8B70D5BC1E43C6628E80EC7BE13C9F4027", "hash_ssdeep": "384:gbeG/bazHusjK0sZT9hm5ACy0io4Sq9JFadXZceP5P23tHj14KVGGx4WV1W:gr4OHk2XS4Fg2AqHj14E5xT", "hash_imp": "4AC40E439D637601F5F9F12A23F83148", "hash_pesha1": "5230D677A82A1389E268D06E498462B8C1596CCB", "hash_pe256": "B49BDB97F6C0B31F54F209649FD4656D2F774E7D738DAE60B85871A772A81E37", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI", "meta_original_filename": "Register-CimProvider2.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/088de004b2abc256739060c61b89a4b3eaa892907b0a61ea30c2eb4533add373/detection/", "runtime_modules": [ "C:\\Windows\\system32\\Register-CimProvider.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll" ], "children": "RdpSa.exe", "output": "\r\nRegisters CIM Provider into system\r\n\r\nUsage: Register-CimProvider.exe\r\n\t\t-Namespace <NamespaceName>\r\n\t\t-ProviderName <ProviderName>\r\n\t\t-Path <ProviderDllPath>\r\n\t\t[-ClassList <Space delimited list of white-listed classes>]\r\n\t\t[-Impersonation <True or False>]\r\n\t\t[-Decoupled <SDDL>]\r\n\t\t[-HostingModel <HostingModel>]\r\n\t\t[-Localize <locale>]\r\n\t\t[-NoAutorecover]\r\n\t\t[-SupportWQL]\r\n\t\t[-GenerateUnregistration]\r\n\t\t[-ForceUpdate]\r\n\t\t[-Verbose]\r\n\r\n-Namespace <NamespaceName>\r\n\tSpecifies the target namespace of the provider.\r\n\r\n-ProviderName <ProviderName>\r\n\tSpecifies the provider name.\r\n\r\n-Path <ProviderDllPath>\r\n\tSpecifies the provider binary path.\r\n\r\n-Impersonation <True or False>\r\n\tSpecifies foldidentity of decoupled provider, by default is True.\r\n\r\n-Decoupled <SDDL>\r\n\tRegisters provider as decoupled and specifies the security descriptor\r\n\tthat determines the set of users that can successfully register\r\n\tthe provider.\r\n\r\n-HostingModel <HostingModel>\r\n\tSpecifies the HostingModel of coupled provider.\r\n\r\n-Localize <locale>\r\n\tLocalizes the provider with resource of specified locale.\r\n\r\n-NoAutorecover\r\n\tDoesn't autorecover the provider.\r\n\r\n-SupportWQL\r\n\tPasses the query expression to the filter.\r\n\r\n-GenerateUnregistration\r\n\tGenerate the uninstall mof for the registration,\r\n\twhich is disabled by default.\r\n\r\n-ForceUpdate\r\n\tForce update the class if it exists in the system.\r\n\r\n-ClassList <ProviderDllPath>\r\n\tSpecifies space delimited list of white-listed classes that\r\n\twill be generated in the mof.\r\n\r\n-Verbose\r\n\tOutputs registration log.\r\n\r\n" }, "regsvr32.exe-DA0E9A7777D16AE18BD9C642A9F42223": { "file_name": "regsvr32.exe", "file_path": "C:\\Windows\\system32\\regsvr32.exe", "hash_md5": "DA0E9A7777D16AE18BD9C642A9F42223", "hash_sha1": "FC99212A5F929D707AF49E8151CAB1E30FF658EB", "hash_sha256": "F098FA150D9199732B4EC2E81528A951503A30F75AFEBF7E7A48360301758C67", "hash_sha384": "6C3A7F8CA950E09AD85D774B4DB80781E9715A2A7011D784CFB86AC28A63A75AE8EE49F7BB12574412439FC0F94AD960", "hash_sha512": "1ED60C4D41EAE79A85F975891A018951503A53F083D2140B1F537A88AB5976D1DA239C8ACE57173B8CE3BA8CBD3DE07D5AEA5FA1B7C271E5F7B4444594D04D7D", "hash_ssdeep": "384:JPDotrdGJJHqNFYJypeqMKMPlhd5QkSg4rT9m/iGcQlUHB2rAOWrnLHWB:lDotrdGCNFR4XP9+khi9m/iGc4Uh2cL", "hash_imp": "0235FF9A007804882636BCCCFB4D1A2F", "hash_pesha1": "3F560BAEF52531C6A0A2935525802A9B82066D76", "hash_pe256": "FA2F47546E63D978C53CB703509435FCBE34CD8560B35D9C17AA2FA13E1CADCA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft(C) Register Server", "meta_original_filename": "REGSVR32.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/f098fa150d9199732b4ec2e81528a951503a30f75afebf7e7a48360301758c67/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\regsvr32.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\regsvr32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\SYSTEM32\\AcLayers.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\sfc.dll", "C:\\Windows\\SYSTEM32\\WINSPOOL.DRV", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\SYSTEM32\\sfc_os.DLL" ], "runtime_window_title": "RegSvr32" }, "rekeywiz.exe-719DC5C9D293D76A836F637C28D4D8BB": { "file_name": "rekeywiz.exe", "file_path": "C:\\Windows\\system32\\rekeywiz.exe", "hash_md5": "719DC5C9D293D76A836F637C28D4D8BB", "hash_sha1": "D8AE2D10832DE0D00E16F8F30AE2FDB11523037D", "hash_sha256": "3B934CB9D1196CA92C803FD76C04496936D4AA553F0409F99F835994FCB3A9E7", "hash_sha384": "670E8E0485F02DB7DCE79DFFAAD61F931778388E758205E6D6A417CA152AA397E826CD5A58F4BA7A0FD7DD1DBE5B72D9", "hash_sha512": "F730CDE58D0E466EE057D44A4F6CBB6EB766A8693B243AE1D77016707697B8EE5B59FF70D61971C456B764E1E3E28206249B834DC90F6A18AB92C1FF8CC9C3E4", "hash_ssdeep": "1536:Z8402ZRYq4zYefhmB06LxAagSp/8oEf7rn1+1G//jwLL4jbkrvtKy3DCDkvvvvvv:ZVV4zYkkB0KAK/Qno7gvkrvt3sBd+", "hash_imp": "0186B48C4B71FBB2942FA3FE4E920D76", "hash_pesha1": "96AE1CB6EF09CE9560F50C18CC8C5F2A7C84D859", "hash_pe256": "A26CB98A20B3893C1DAB88514CE128D1DA22E6F4E8D2046ED17E470A08F97B80", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EFS REKEY wizard", "meta_original_filename": "rekeywiz.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/3b934cb9d1196ca92c803fd76c04496936d4aa553f0409f99f835994fcb3a9e7/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\rekeywiz.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\efsadu.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\rekeywiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\EFSADU.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\system32\\DSROLE.dll", "C:\\Windows\\system32\\EFSUTIL.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\CRYPTUI.dll", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\system32\\logoncli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\VAULTCLI.dll", "C:\\Windows\\system32\\credui.dll", "C:\\Windows\\system32\\FeClient.dll", "C:\\Windows\\system32\\urlmon.dll", "C:\\Windows\\system32\\ncrypt.dll", "C:\\Windows\\SYSTEM32\\wintypes.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\system32\\NTASN1.dll", "C:\\Windows\\system32\\CRYPTBASE.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\system32\\OLEACC.dll" ], "runtime_window_title": "Encrypting File System" }, "relog.exe-4C7A9A333AFB2B0896B4E8A948E58B79": { "file_name": "relog.exe", "file_path": "C:\\Windows\\system32\\relog.exe", "hash_md5": "4C7A9A333AFB2B0896B4E8A948E58B79", "hash_sha1": "948FEBD5456420916256FCC94E3ED19AAFE5390B", "hash_sha256": "100AF46C952E58105DBC51EB92510F6990377A3FFC57E82074A8BFB64C56C529", "hash_sha384": "01D078341EF753B90A6737429F665524C16F1CED299F33048EB7B285BFEB66E3F2384B307218DF78BA0FEF3CC7B6B6CC", "hash_sha512": "2FBB960AAA2322F0BD5BC14096F9640F0AEAD480BEAB9DF687837516B7EE898E1A2B3C14FFD34BA663B0F11AC1B4B0EA81850AC92176903F324D38D1BADD872D", "hash_ssdeep": "768:mC+N6nlPSz0JPC/3c6f7Jl1/zdBNZj99mNUkiyDvkejoLWoe3F22Ms/qc/:7+HMUl5zbNB99mNUkiy4KWWTF2U/qc/", "hash_imp": "6043170F48FA2A2802231975BB43BBDA", "hash_pesha1": "F7D903EBBB41E638AB9406B1AAC947604E2C4049", "hash_pe256": "8475E6AFC739930ADDAEB208656E9F648A42A43761913D6E00169945B73BD074", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Performance Relogging Utility", "meta_original_filename": "Relog.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/100af46c952e58105dbc51eb92510f6990377a3ffc57e82074a8bfb64c56c529/detection/", "output": "\r\nMicrosoft r Relog.exe (10.0.17763.1)\r\n\r\nRelog creates new performance logs from data in existing performance logs by\r\nchanging the sampling rate and/or converting the file format. Supports all\r\nperformance log formats, including Windows NT 4.0 compressed logs.\r\n\r\nUsage:\r\nC:\\Windows\\system32\\relog.exe <filename [filename ...]> \r\n [options]\r\n\r\nParameters:\r\n <filename [filename ...]> Performance file to relog.\r\n\nOptions:\r\n -? Displays context sensitive help.\r\n -a Append output to the existing binary file.\r\n -c <path [path ...]> Counters to filter from the input log.\r\n -cf <filename> File listing performance counters to filter\r\n from the input log. Default is all counters\r\n in the original log file.\r\n -f <CSV|TSV|BIN|SQL> Output file format.\r\n -t <value> Only write every nth record into the output\r\n file. Default is to write every record.\r\n -o Output file path or SQL database.\r\n -b <M/d/yyyy h:mm:ss[AM|PM]> Begin time for the first record to write into\r\n the output file.\r\n -e <M/d/yyyy h:mm:ss[AM|PM]> End time for the last record to write into\r\n the output file.\r\n -config <filename> Settings file containing command options.\r\n -q List performance counters in the input file.\r\n -y Answer yes to all questions without prompting.\r\n\r\nExamples:\r\n relog logfile.csv -c \"\\Processor(_Total)\\% Processor Time\" -o logfile.blg\r\n relog logfile.blg -cf counters.txt -f bin\r\n relog logfile.blg -f csv -o logfile.csv -t 2\r\n relog logfile.blg -q -o counters.txt\r\n", "runtime_modules": [ "C:\\Windows\\system32\\relog.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\pdh.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "RelPost.exe-1291A9F82F82C0B57F312300A1B09895": { "file_name": "RelPost.exe", "file_path": "C:\\Windows\\system32\\RelPost.exe", "hash_md5": "1291A9F82F82C0B57F312300A1B09895", "hash_sha1": "90CBB32F4D24E7871D63A771C1ED074FA05499EB", "hash_sha256": "036E9C86B1D9338C2328822680FA51DBBC0E7855BC73254F147EA99A24C17602", "hash_sha384": "A3865745284A6E338D4D9F6E8210955F69AEF09A60BCE3C26549B5972EAF3F0CC51DA52255AD31B695332FF741C1A9A0", "hash_sha512": "643381A71846C355ABD5D61597ABC2102E03B909EE39899C936CBF92AEF3465055E103A72BBB438D3736FC49EF53A2B2E8C5379249B1CEEB9D782C067104A963", "hash_ssdeep": "3072:PW60aMspTl8Z7W2wOIiBVWJBxqhGapLGuAuegPO8evTq2V9:P5METWB/OExFegEv+2V", "hash_imp": "DC797A665163FBB4A885E91E7062BEFB", "hash_pesha1": "C4155596EFC6931CD83F6F221862A4EF29A427BA", "hash_pe256": "78DE363D0D1C7E8CB7DF9DFE64FC0C8D54762D4C77DAAD7DF25458C5FC563D6F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Diagnosis and Recovery", "meta_original_filename": "RelPost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/036e9c86b1d9338c2328822680fa51dbbc0e7855bc73254f147ea99a24c17602/detection/" }, "RemoteFXvGPUDisablement.exe-DA10AD97CE891EE6C483BF2FDE66877E": { "file_name": "RemoteFXvGPUDisablement.exe", "file_path": "C:\\Windows\\system32\\RemoteFXvGPUDisablement.exe", "hash_md5": "DA10AD97CE891EE6C483BF2FDE66877E", "hash_sha1": "CB724F848EB36257E725F4444B0B54DA2279DD3F", "hash_sha256": "A42B55BF02179C8676F260EC9FD89EC8AED9FB5117C914D928EC711D96771424", "hash_sha384": "BCE1800AF2CA295A93BC3FE2D5ABC7EBBE3898464389133E9BB19EF645C45447C7E878FE737CCDCC87051F16CE78970D", "hash_sha512": "80ECD40762D80AAE98629A0FF7A1C412F8D567E7115D13FAB36C990B59B01A12CE247004B761DAF6CA6C9BC85CD65F39EBDC1718107849582D2F82D6D974AAFF", "hash_ssdeep": "192:+Y2sL84qxeU2VtRjOzRDnEtzMPUOY/0svGS0lTYwWTfWR:+VeU2hjO9Et0UOSokwWTfW", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "078044F770D8C33CD62E9976649783EAF0F4CD7A", "hash_pe256": "13FA78246B167A0714DE6EC87FADE1AEAD8D2006E33A6707E701C3605DA9F6FF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "RemoteFXvGPUDisablement.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1339", "meta_product_version": "10.0.17763.1339", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/a42b55bf02179c8676f260ec9fd89ec8aed9fb5117c914d928ec711d96771424/detection/", "runtime_modules": [ "C:\\Windows\\system32\\RemoteFXvGPUDisablement.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll" ] }, "RemotePosWorker.exe-CA8CBA4456A18263425CBF7EF23F71D5": { "file_name": "RemotePosWorker.exe", "file_path": "C:\\Windows\\system32\\RemotePosWorker.exe", "hash_md5": "CA8CBA4456A18263425CBF7EF23F71D5", "hash_sha1": "B5D6BE97AD24CDB7119E9CA384F83534026693A7", "hash_sha256": "B1A25D53C302C3B4E7D6AFFBC309E67C3761E0D189B9FC1389E16C626EF8B09D", "hash_sha384": "05762764C12B3EBC61E4588C28C0AAFD68B6E66C25AB168F68DCF8D60D79C17B4380747C5C63E458610C467F75654492", "hash_sha512": "3773E459C9DA70D7DAEC812426AC01C6DAC4B2A067C0DAB6C1EA64CF2A2855ECB643E8F5A59CE29E3FEE7DD32529CE23641D68F2E2E34BF004E900F1D2414998", "hash_ssdeep": "192:Yt9PydQJai6viLbkI4oN6BHevMqjsWPuzPCd4qigEXaRk3WF7W:YfydQJm6Leq6peviWWzPCFpRk3WF7W", "hash_imp": "C6E4FB88ABA54E5E339120511BB8F20D", "hash_pesha1": "C856FDC789F58E794FB378910D7D4CF5B18FDAC8", "hash_pe256": "52041A3AB1A5168FE71BB35283B2D1FB82F0F945F6969CACA5CF51E37AE966B8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Pos Driver Worker", "meta_original_filename": "RemotePosWorker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b1a25d53c302c3b4e7d6affbc309e67c3761e0d189b9fc1389e16c626ef8b09d/detection/" }, "replace.exe-5ACE617B14602EF7CEDD2FCF9332F26E": { "file_name": "replace.exe", "file_path": "C:\\Windows\\system32\\replace.exe", "hash_md5": "5ACE617B14602EF7CEDD2FCF9332F26E", "hash_sha1": "0591B8DF497C30ABE26BA0A5B1468E4B3EAAF3FB", "hash_sha256": "83E2714735C365C3C01D8D8D56434983C1238A2A806D23AB48F42F59E2DF8093", "hash_sha384": "D720EA84ECCD0B8CCA75CCB3E92A30ACFFE0F0F5606C7419DFAD2B9B7CF5500658AA711F32811E137D5C432A16BD3DA3", "hash_sha512": "45E9A5AEC15BA8FB92A69DD9FEBA56ED878DA895C001F317573383BBA562BBD045E514014631A17D62CC64E3B16CD39DAF892333C31709150D8CFDF3EDD93874", "hash_ssdeep": "384:Ug5VC14y5FqaPDONbolmoznbvGll6rk0/jnU/jw16PZNWRh/W:ohevCljbvgkk0bnUsIZQ", "hash_imp": "7F915E73EEE8F7CA67BD9BA9264315DA", "hash_pesha1": "F71C81DF63ED9DA0D61FC8840DD7D2EBD0629145", "hash_pe256": "268A1D43E26E016B817E04862700FC2559A0F7E61AD8DC353DABB7A684ECF103", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Replace File Utility", "meta_original_filename": "REPLACE.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/83e2714735c365c3c01d8d8d56434983c1238a2a806d23ab48f42f59e2df8093/detection/", "output": "Replaces files.\r\n\r\nREPLACE [drive1:][path1]filename [drive2:][path2] [/A] [/P] [/R] [/W]\r\nREPLACE [drive1:][path1]filename [drive2:][path2] [/P] [/R] [/S] [/W] [/U]\r\n\r\n [drive1:][path1]filename Specifies the source file or files.\r\n [drive2:][path2] Specifies the directory where files are to be\r\n replaced.\r\n /A Adds new files to destination directory. Cannot\r\n use with /S or /U switches.\r\n /P Prompts for confirmation before replacing a file or\r\n adding a source file.\r\n /R Replaces read-only files as well as unprotected\r\n files.\r\n /S Replaces files in all subdirectories of the\r\n destination directory. Cannot use with the /A\r\n switch.\r\n /W Waits for you to insert a disk before beginning.\r\n /U Replaces (updates) only files that are older than\r\n source files. Cannot use with the /A switch.\r\n", "error": "Invalid switch - --help\r\n" }, "reset.exe-EDE443A63F4A5914F87DFDC6F8F59697": { "file_name": "reset.exe", "file_path": "C:\\Windows\\system32\\reset.exe", "hash_md5": "EDE443A63F4A5914F87DFDC6F8F59697", "hash_sha1": "596A5DD2803009763FB0AE7AA3AA8713AE2FF4D4", "hash_sha256": "C1E2A96B5D73D08A52BC5A2E634D408C2D42071147D40A894C8B4606DE83484D", "hash_sha384": "7C15DCADA03F53B2DEC6BB2FDE04DE8ACE3E5815DAB9895A94A46E8DFAE4A9D4A840B10D27AC546380114374F4A748DF", "hash_sha512": "CA049EA57DA4A35539436586E115858B9253B65378997AE3B2C68CF20980B542345E4B78AC25EA5ABD15DD0F3E87BC054760E37FF2A97E70E78C0B5E2D712699", "hash_ssdeep": "384:P6k7EHdWH1ZMqxdBeEh+91XfGHK2ahyWQgW:P6kQSVBA914cU", "hash_imp": "CCC9DA4A55E90DFE34CBCDB066D6A6B3", "hash_pesha1": "5FA733035807DB51AD18E44794460BA43881851C", "hash_pe256": "17625218764110E1D06656A96F39BEA39B116493E3D7DFEB6AD2879599BF2E19", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Services Reset Utility", "meta_original_filename": "reset.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/c1e2a96b5d73d08a52bc5a2e634d408c2d42071147d40a894c8b4606de83484d/detection/", "output": "RESET { SESSION }\r\n", "error": "Invalid parameter(s)\r\nRESET { SESSION }\r\n" }, "ResetEngine.exe-E5BB9067EE3690FCD641F9369E1B8A1C": { "file_name": "ResetEngine.exe", "file_path": "C:\\Windows\\system32\\ResetEngine.exe", "hash_md5": "E5BB9067EE3690FCD641F9369E1B8A1C", "hash_sha1": "092C34F35FDAE79E1FD82E8ABA8FAC9E0AB2B5F4", "hash_sha256": "CD4649748EEF2D035B01039D1113DDE1194E4608A3A0C665E8FA689C1CAB7BFD", "hash_sha384": "C176D3773798E325C044A876CBC881B1AA0EE96B13DBA10A138326D99740DD75C9466C18E306B926A2FF951440D0BC2A", "hash_sha512": "F275799B8341A0E81F7A3726DF1BE77E8DD1CC710ED1F91F3D13F26BF63B6871E8FC84B6E26EB642B91CC6BD169DA5E5B444875CEF0785DEFDBF3AF816A3F865", "hash_ssdeep": "192:ukXL6vhw27mroy/DBSuPN3NazB9JP3L8dm5uU/pMWaeW:bL65w2aEyl/PiJz8sgsMWaeW", "hash_imp": "D1CCC9D0A0240603DC3279F82F80F8D3", "hash_pesha1": "41423E80F2F271EEF64509E03FEAF082524C2D9C", "hash_pe256": "7C26875FE4D36A0BFB06CF3D693B478B7D7553E11C25B0A51BB020CA4FF29DB2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Push-Button Reset Engine", "meta_original_filename": "RESETENGINE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/cd4649748eef2d035b01039d1113dde1194e4608a3a0c665e8fa689c1cab7bfd/detection/", "runtime_modules": [ "C:\\Windows\\system32\\ResetEngine.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "resmon.exe-A01AB6C669DCC17E87C84C0C07D2CFAE": { "file_name": "resmon.exe", "file_path": "C:\\Windows\\system32\\resmon.exe", "hash_md5": "A01AB6C669DCC17E87C84C0C07D2CFAE", "hash_sha1": "9B6EF117022714BADD3C0627207127AD885BAE96", "hash_sha256": "956CD8B2C832E631917281B131EE9B137D2702FFC929AEF6FC2C71AD1C761F8B", "hash_sha384": "35A153CBFD8AD962B7E79A6B76A1A109CB446195C4B955413F4CC7743DCE4CCD07F821BB2A4DD0FB818F7E047FED731D", "hash_sha512": "40330B2D3D7E82812E6471E861408832FA637F72F309E12C3F9DC61CA219F117450D93C9D97BAA670045E95F1852C81D872F246E29BE68A501E5600A8FAC27BB", "hash_ssdeep": "1536:T7n1b6HBqY3KtrtizIo9plJSs9kYuZJnGZLzOcE6Ls7HXG84PK05Z34g/CO+sH:TpOHghtYIo9piswTogiqQKy349", "hash_imp": "C489853A1F490DCDAEA1E10E57C136E4", "hash_pesha1": "FA1E63FD53EE235DEA2FC7AFE943F978A189AC42", "hash_pe256": "9A011C4230ED22092591A8B70B170062FCCE16A117777EE3D9FDA1AEB1D5DF11", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resource Monitor", "meta_original_filename": "resmon.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/956cd8b2c832e631917281b131ee9b137d2702ffc929aef6fc2c71ad1c761f8b/detection/", "children": "perfmon.exe", "runtime_modules": [ "C:\\Windows\\system32\\resmon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll" ] }, "RMActivate.exe-D55D7E2157D851310385BB8638132890": { "file_name": "RMActivate.exe", "file_path": "C:\\Windows\\system32\\RMActivate.exe", "hash_md5": "D55D7E2157D851310385BB8638132890", "hash_sha1": "FF67E4E9569E67C66BB8103F9E12F105E557A7E6", "hash_sha256": "847DC04D5E873C130027D901309339F490A01085A8BEFF2FC475BC3C8F117C04", "hash_sha384": "44D76D2ED2992B344242B58024D41B1B75D78F48314C7F8EF5831CEF54E47FFB088D9299A42E653CB2CADB1918C9976B", "hash_sha512": "C0D7256D9735435EC73E9F59AF1E19B7A161BA527F1AF0E762DA38019AF4308008C54023B0C0C79C2AA9F8D88D70A002E9449BC65D9D040027CF26FFC0CD253B", "hash_ssdeep": "12288:OyTJtslBVQwM19Z8XaeNZjdDov+qLUN8DToZ:4BV6ZqH3Mv+IToZ", "hash_imp": "A64B00149541ECB0FA84FD98B79BF54D", "hash_pesha1": "B6B843D5F159DEF693937A2072B5DCEE76F6AAB2", "hash_pe256": "5CC58CAB792FF7F9BCCFDD4A0B5524BBACAF5D5F75F0B58E6FA1A951C16C22AE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Desktop Security Processor", "meta_original_filename": "rmactivate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/847dc04d5e873c130027d901309339f490a01085a8beff2fc475bc3c8f117c04/detection/", "runtime_modules": [ "C:\\Windows\\system32\\RMActivate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\CRYPTBASE.dll" ] }, "RMActivate_isv.exe-B26403F5BE7BAFB716E74D810031DA28": { "file_name": "RMActivate_isv.exe", "file_path": "C:\\Windows\\system32\\RMActivate_isv.exe", "hash_md5": "B26403F5BE7BAFB716E74D810031DA28", "hash_sha1": "A93FDCDBE553E472CFF4677ADBD8EEEC6A63047F", "hash_sha256": "CDA1F53A70A83B13B48C10AF395D94D6A76A21CFE43FFE34BE76D3099683DC3A", "hash_sha384": "4B01407FAE5A005550AD61D2487467A118533C75EF081F931AF12AD3B7B9102E30AD5A63DC45F57A818EFE70383B2120", "hash_sha512": "9EBA77A53ADF68D858CADBB94D1E405F1F1BE65308CD8570D41D17C11F4C716023A5F44F36D49E1B14D4452FD1046787D6FF60679C28A08929E9746D0CD98C90", "hash_ssdeep": "12288:m9wWxpaoM9zkuEjqNjxUV+9UT4kAXYfHg:HxL3UV+9UT4b", "hash_imp": "A64B00149541ECB0FA84FD98B79BF54D", "hash_pesha1": "E17278C167D36B86001F49B110A0831CC896D7AA", "hash_pe256": "F6DA8D74AD2C0DFEAAEDCF6DCEACB0E3FFCF06A02F39B5517E47DEB995361F59", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Desktop Security Processor", "meta_original_filename": "rmactivate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/cda1f53a70a83b13b48c10af395d94d6a76a21cfe43ffe34be76d3099683dc3a/detection/", "runtime_modules": [ "C:\\Windows\\system32\\RMActivate_isv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\CRYPTBASE.dll", "C:\\Windows\\system32\\DPAPI.dll", "C:\\Windows\\system32\\msdrm.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "RMActivate_ssp.exe-55DCD30BCB4A54AB2F3BBD107B8D5EFB": { "file_name": "RMActivate_ssp.exe", "file_path": "C:\\Windows\\system32\\RMActivate_ssp.exe", "hash_md5": "55DCD30BCB4A54AB2F3BBD107B8D5EFB", "hash_sha1": "43517BA6475E71A8868DA46CFB4A940060207322", "hash_sha256": "C310B3E2390D428172AE9040D469BB871305C502479CAEFF1C893B8940F16F7A", "hash_sha384": "9699BE018CF71D37DD09CEFD956866FAA0838C52433D049B8B85FFAEE48A6731A20BF9D17FE09D4C7942EDED45DED876", "hash_sha512": "9B45CF939B92E954D62B30CCDD0F3DF7C130C14C7C250A97C78B860B40448280CD5D9B65B191240F56F0DBE4F45CD0FA79F550ECD483BAEE53596E68CC341856", "hash_ssdeep": "12288:xQiIBMT4bannhj6mr1UbCF9DeuVPBmtGKNmWdP19E7t:2iIBMsbUnhj66SaBBafTPkZ", "hash_imp": "0A975696C1EBDA2FE57027FB43C0A3BD", "hash_pesha1": "C9D5040F902C3F0B4B05B036D2368151DB69FF3C", "hash_pe256": "6221DFE77A04E527627E9DA12F9AF3ACDA4DC598D28AC10CFA5EA022ECE6F896", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Server Security Processor", "meta_original_filename": "rmactivate_ssp.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c310b3e2390d428172ae9040d469bb871305c502479caeff1c893b8940f16f7a/detection/", "runtime_modules": [ "C:\\Windows\\system32\\RMActivate_ssp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\system32\\CRYPTBASE.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\DPAPI.dll" ] }, "RMActivate_ssp_isv.exe-342376866AF2714CC5436AB15289367F": { "file_name": "RMActivate_ssp_isv.exe", "file_path": "C:\\Windows\\system32\\RMActivate_ssp_isv.exe", "hash_md5": "342376866AF2714CC5436AB15289367F", "hash_sha1": "4E49C8753C2C1958BBA883BE60387120926E2CDF", "hash_sha256": "62DA7F512FADD7821A46E12230D18E3ABA6C0EC6827C1B9DB8E8424CB5E9159B", "hash_sha384": "F36232E4C7076960A246F40CEDFBA4A59FA57028DC64CA8D65E885D2BFFB7F96B2AF0AFE30395BA8BE9599FD43348981", "hash_sha512": "40BEBF97BF8353F9B8BF3B9911A08F58E8AD5454193F9C03B458872D66557B0AF787E1F334EC315245FF1352AC1AAC3A46AEC7A7EAF16777CEA7C69405AB5031", "hash_ssdeep": "12288:06RI39AFHJWGNNuh+rpVQzcwXihJTi3uf4j9Pc:ZR1FJpruwlVSaJTi3uAjhc", "hash_imp": "0A975696C1EBDA2FE57027FB43C0A3BD", "hash_pesha1": "76916752AE27A0CDD944E2D64BFB4C61937D815A", "hash_pe256": "8A1BA1F2A4C950FBD7CC8E6A48AF628905593BBEFF2312EB7AC83933716D42F3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Server Security Processor (Pre-production)", "meta_original_filename": "rmactivate_ssp_isv.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/62da7f512fadd7821a46e12230d18e3aba6c0ec6827c1b9db8e8424cb5e9159b/detection/", "runtime_modules": [ "C:\\Windows\\system32\\RMActivate_ssp_isv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\DPAPI.dll", "C:\\Windows\\system32\\CRYPTBASE.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\msdrm.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "children": "RdpSa.exe" }, "RmClient.exe-BBD4253FE3119FED2DB593CAFF48B791": { "file_name": "RmClient.exe", "file_path": "C:\\Windows\\system32\\RmClient.exe", "hash_md5": "BBD4253FE3119FED2DB593CAFF48B791", "hash_sha1": "CBEE6F737DA4EF3086C832299841BA31F0EAAD06", "hash_sha256": "C87253F2AB5615CAE492EB9C5D62FCA55E78616DBFB991A6FB1F88215458F674", "hash_sha384": "EA93B4DE4A248679DADEA7D219E4E98087E7742D235887299B4FE520C767D52A648C6261ACAFF75B6425009351005D1D", "hash_sha512": "EAFF2F73E921F49ED799A9C2C81CB087F3F1FD7D8469CB026DC76144DEDFFEB37B071D9DC25BA936CDB3B8BCF851704C70DE115BBD3E6202650CD2EDD76966F3", "hash_ssdeep": "384:1UZGRPItlJDtYbL2X85du4ypUQ6o/203WTzW:1s4PIt7DtiLH5dDt0w", "hash_imp": "EB0E8D586B57D8075925424DA3BD6710", "hash_pesha1": "8CBFC2B92DE7E38C40C0094748DCC6834433A2DD", "hash_pe256": "C4CABC3EEDC7CADBFBFCF6F2A592914B39314D16C19D7A59DC5A1FBF04407B59", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Restart Manager LUA Restart Client", "meta_original_filename": "RmClient.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/c87253f2ab5615cae492eb9c5d62fca55e78616dbfb991a6fb1f88215458f674/detection/", "output": "\r\n RmClient.exe pipename\r\n\r\n\r\n" }, "rmttpmvscmgrsvr.exe-D4D16AC9ADC3F85D042622A4B9BFD8F6": { "file_name": "rmttpmvscmgrsvr.exe", "file_path": "C:\\Windows\\system32\\rmttpmvscmgrsvr.exe", "hash_md5": "D4D16AC9ADC3F85D042622A4B9BFD8F6", "hash_sha1": "7300C398073E4297C9F07D57968A8960E4BDBDB4", "hash_sha256": "63C358D7BBA1AD1C3D015EF625FDF659AE527595C82366866AB557D1CDC87B06", "hash_sha384": "976154E830FE1365002FB4CA5381F2F81710F44AAC27F57B673103A197D724DA73F186D031ED57E8324020872F637DAA", "hash_sha512": "92136064C0EA414CC8DBCEDC484E422CC16FE318FAF0849A419146367E8DB42A19A0E0AA9B6F84728C9BF8C5061D00FF566BA416C2E5888CF1230ED500E8EC6A", "hash_ssdeep": "3072:LWmZBgGFCvMIU/Zl4Y8uMVhvmbPEzmTO:JXhWAl4Y8uMV9mwz", "hash_imp": "01170AF3AC64C08EF5BEFED4FEBE2E2A", "hash_pesha1": "6E94DEDFF5FB47CC7C39C6BDDD688C8C50F3541C", "hash_pe256": "70131232F2AA185E574774512E6F5E0BA88FB350B1B2E5B905AE1071C29BD77E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TPM Virtual Smart Card Manager DCOM Server", "meta_original_filename": "RmtTpmVscMgrSvr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/63c358d7bba1ad1c3d015ef625fdf659ae527595c82366866ab557d1cdc87b06/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC734": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\rmttpmvscmgrsvr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\WinSCard.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "Robocopy.exe-25AF99E8804F5237844A7757FB0AB6EE": { "file_name": "Robocopy.exe", "file_path": "C:\\Windows\\system32\\Robocopy.exe", "hash_md5": "25AF99E8804F5237844A7757FB0AB6EE", "hash_sha1": "DD81B0A433DC5FCFBAC1A8ADD42377F99448196B", "hash_sha256": "8A8F7C4C97B3E03A472AB99E0D22727435AE4350981056A63624F7C913417803", "hash_sha384": "9276952D61BF04F57C5CE71966F85CABDE98137402E7E87F9EA150B60E345CCD121C094A2F0593FBCB0D7727D695352C", "hash_sha512": "D1F04C75E4289F4A4E23C4861C37135AEED422019BE9F84B90ABAE7F6BC416DEE1892AC5BA563C4EC239919CA988B764EDB95C4DC49E72F22ADD25B00017D88E", "hash_ssdeep": "3072:0QHFzhH+guUqvrtVVzCBrBMLy8cr5GtpMU97kNWgUH4:0Q+gHur9KdMe825KpJlqW", "hash_imp": "1E9FEA3A91DC30B3394FA0A3DDB1EFC4", "hash_pesha1": "EA2608FEE5CA09ECA9309B3EA26072105F05737B", "hash_pe256": "195729F01889E45638B942CAD0E5D1326DF0214767BCD79948C651E9EAC903D3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Robocopy", "meta_original_filename": "robocopy.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\n-------------------------------------------------------------------------------\r\n ROBOCOPY :: Robust File Copy for Windows \r\n-------------------------------------------------------------------------------\r\n\r\n Started : Monday, October 19, 2020 9:11:16 PM\r\n Usage :: ROBOCOPY source destination [file [file]...] [options]\r\n\r\n source :: Source Directory (drive:\\path or \\\\server\\share\\path).\r\n destination :: Destination Dir (drive:\\path or \\\\server\\share\\path).\r\n file :: File(s) to copy (names/wildcards: default is \"*.*\").\r\n\r\n::\r\n:: Copy options :\r\n::\r\n /S :: copy Subdirectories, but not empty ones.\r\n /E :: copy subdirectories, including Empty ones.\r\n /LEV:n :: only copy the top n LEVels of the source directory tree.\r\n\r\n /Z :: copy files in restartable mode.\r\n /B :: copy files in Backup mode.\r\n /ZB :: use restartable mode; if access denied use Backup mode.\r\n /J :: copy using unbuffered I/O (recommended for large files).\r\n /EFSRAW :: copy all encrypted files in EFS RAW mode.\r\n\r\n /COPY:copyflag[s] :: what to COPY for files (default is /COPY:DAT).\r\n (copyflags : D=Data, A=Attributes, T=Timestamps).\r\n (S=Security=NTFS ACLs, O=Owner info, U=aUditing info).\r\n\r\n \r\n /SEC :: copy files with SECurity (equivalent to /COPY:DATS).\r\n /COPYALL :: COPY ALL file info (equivalent to /COPY:DATSOU).\r\n /NOCOPY :: COPY NO file info (useful with /PURGE).\r\n /SECFIX :: FIX file SECurity on all files, even skipped files.\r\n /TIMFIX :: FIX file TIMes on all files, even skipped files.\r\n\r\n /PURGE :: delete dest files/dirs that no longer exist in source.\r\n /MIR :: MIRror a directory tree (equivalent to /E plus /PURGE).\r\n\r\n /MOV :: MOVe files (delete from source after copying).\r\n /MOVE :: MOVE files AND dirs (delete from source after copying).\r\n\r\n /A+:[RASHCNET] :: add the given Attributes to copied files.\r\n /A-:[RASHCNET] :: remove the given Attributes from copied files.\r\n\r\n /CREATE :: CREATE directory tree and zero-length files only.\r\n /FAT :: create destination files using 8.3 FAT file names only.\r\n /256 :: turn off very long path (> 256 characters) support.\r\n\r\n /MON:n :: MONitor source; run again when more than n changes seen.\r\n /MOT:m :: MOnitor source; run again in m minutes Time, if changed.\r\n\r\n /RH:hhmm-hhmm :: Run Hours - times when new copies may be started.\r\n /PF :: check run hours on a Per File (not per pass) basis.\r\n\r\n /IPG:n :: Inter-Packet Gap (ms), to free bandwidth on slow lines.\r\n\r\n /SL :: copy symbolic links versus the target.\r\n\r\n /MT[:n] :: Do multi-threaded copies with n threads (default 8).\r\n n must be at least 1 and not greater than 128.\r\n This option is incompatible with the /IPG and /EFSRAW options.\r\n Redirect output using /LOG option for better performance.\r\n\r\n /DCOPY:copyflag[s] :: what to COPY for directories (default is /DCOPY:DA).\r\n (copyflags : D=Data, A=Attributes, T=Timestamps).\r\n\r\n /NODCOPY :: COPY NO directory info (by default /DCOPY:DA is done).\r\n\r\n /NOOFFLOAD :: copy files without using the Windows Copy Offload mechanism.\r\n\r\n::\r\n:: File Selection Options :\r\n::\r\n /A :: copy only files with the Archive attribute set.\r\n /M :: copy only files with the Archive attribute and reset it.\r\n /IA:[RASHCNETO] :: Include only files with any of the given Attributes set.\r\n /XA:[RASHCNETO] :: eXclude files with any of the given Attributes set.\r\n\r\n /XF file [file]... :: eXclude Files matching given names/paths/wildcards.\r\n /XD dirs [dirs]... :: eXclude Directories matching given names/paths.\r\n\r\n /XC :: eXclude Changed files.\r\n /XN :: eXclude Newer files.\r\n /XO :: eXclude Older files.\r\n /XX :: eXclude eXtra files and directories.\r\n /XL :: eXclude Lonely files and directories.\r\n /IS :: Include Same files.\r\n /IT :: Include Tweaked files.\r\n\r\n /MAX:n :: MAXimum file size - exclude files bigger than n bytes.\r\n /MIN:n :: MINimum file size - exclude files smaller than n bytes.\r\n\r\n /MAXAGE:n :: MAXimum file AGE - exclude files older than n days/date.\r\n /MINAGE:n :: MINimum file AGE - exclude files newer than n days/date.\r\n /MAXLAD:n :: MAXimum Last Access Date - exclude files unused since n.\r\n /MINLAD:n :: MINimum Last Access Date - exclude files used since n.\r\n (If n < 1900 then n = n days, else n = YYYYMMDD date).\r\n\r\n /XJ :: eXclude Junction points and symbolic links. (normally included by default).\r\n\r\n /FFT :: assume FAT File Times (2-second granularity).\r\n /DST :: compensate for one-hour DST time differences.\r\n\r\n /XJD :: eXclude Junction points and symbolic links for Directories.\r\n /XJF :: eXclude symbolic links for Files.\r\n\r\n /IM :: Include Modified files (differing change times).\r\n::\r\n:: Retry Options :\r\n::\r\n /R:n :: number of Retries on failed copies: default 1 million.\r\n /W:n :: Wait time between retries: default is 30 seconds.\r\n\r\n /REG :: Save /R:n and /W:n in the Registry as default settings.\r\n\r\n /TBD :: Wait for sharenames To Be Defined (retry error 67).\r\n\r\n /LFSM :: Operate in low free space mode, enabling copy pause and resume (see Remarks).\r\n\r\n /LFSM:n[KMG] :: /LFSM, specifying the floor size in n [K:kilo,M:mega,G:giga] bytes.\r\n\r\n::\r\n:: Logging Options :\r\n::\r\n /L :: List only - don't copy, timestamp or delete any files.\r\n /X :: report all eXtra files, not just those selected.\r\n /V :: produce Verbose output, showing skipped files.\r\n /TS :: include source file Time Stamps in the output.\r\n /FP :: include Full Pathname of files in the output.\r\n /BYTES :: Print sizes as bytes.\r\n\r\n /NS :: No Size - don't log file sizes.\r\n /NC :: No Class - don't log file classes.\r\n /NFL :: No File List - don't log file names.\r\n /NDL :: No Directory List - don't log directory names.\r\n\r\n /NP :: No Progress - don't display percentage copied.\r\n /ETA :: show Estimated Time of Arrival of copied files.\r\n\r\n /LOG:file :: output status to LOG file (overwrite existing log).\r\n /LOG+:file :: output status to LOG file (append to existing log).\r\n\r\n /UNILOG:file :: output status to LOG file as UNICODE (overwrite existing log).\r\n /UNILOG+:file :: output status to LOG file as UNICODE (append to existing log).\r\n\r\n /TEE :: output to console window, as well as the log file.\r\n\r\n /NJH :: No Job Header.\r\n /NJS :: No Job Summary.\r\n\r\n /UNICODE :: output status as UNICODE.\r\n\r\n::\r\n:: Job Options :\r\n::\r\n /JOB:jobname :: take parameters from the named JOB file.\r\n /SAVE:jobname :: SAVE parameters to the named job file\r\n /QUIT :: QUIT after processing command line (to view parameters). \r\n /NOSD :: NO Source Directory is specified.\r\n /NODD :: NO Destination Directory is specified.\r\n /IF :: Include the following Files.\r\n\r\n::\r\n:: Remarks :\r\n::\r\n Using /PURGE or /MIR on the root directory of the volume formerly caused \r\n robocopy to apply the requested operation on files inside the System \r\n Volume Information directory as well. This is no longer the case; if \r\n either is specified, robocopy will skip any files or directories with that \r\n name in the top-level source and destination directories of the copy session.\r\n\r\n The modified files classification applies only when both source \r\n and destination filesystems support change timestamps (e.g., NTFS) \r\n and the source and destination files have different change times but are \r\n otherwise the same. These files are not copied by default; specify /IM \r\n to include them. \r\n\r\n Using /LFSM requests robocopy to operate in 'low free space mode'. \r\n In that mode, robocopy will pause whenever a file copy would cause the \r\n destination volume's free space to go below a 'floor' value, which \r\n can be explicitly specified by the LFSM:n[KMG] form of the flag. \r\n If /LFSM is specified with no explicit floor value, the floor is set to \r\n ten percent of the destination volume's size. \r\n Low free space mode is incompatible with /MT, /EFSRAW, /B, and /ZB.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\Robocopy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "ROUTE.EXE-E522E09416A0991612DD1B46B11768B1": { "file_name": "ROUTE.EXE", "file_path": "C:\\Windows\\system32\\ROUTE.EXE", "hash_md5": "E522E09416A0991612DD1B46B11768B1", "hash_sha1": "9BEDE2EAF0B5770CFE8C05573E93FA69BB3C9A73", "hash_sha256": "3EE231B69BCCACFBF961D2A8C624F4B4236EC54A239490B080D31D82B03F7C2D", "hash_sha384": "434047FF2728C627A2BA4884FA990687C81783E43F4C87DC1B30EFC7FBBA1E5964725A0BBDF837CA52B1658B7D590D20", "hash_sha512": "C3163A037EC491311AA2A56813B512654FC88718ECEF45A53A0C6EF6DC31D3B0ACB61A6F14721AD189F1AE27F0A46FAA1B052B8B82CFA75A064912CADAB73ADA", "hash_ssdeep": "384:l+IVcCyCip64J3HHXnM5eXuxEfhtzbzSqlqArF42xr90Tn5acke7FqO3qWj0W:0CF2hXnM5eXxJslAr7P0NYcFqO3/", "hash_imp": "95110DF86CE2E63EB457CE5860C12E57", "hash_pesha1": "6FE7166E972C41D1C612E9B0F2C62FB2F0426668", "hash_pe256": "172B931B2311E3609DF256C804A0E058F37D0B222154E15B5AE3E94796D39AB1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Route Command", "meta_original_filename": "route.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/3ee231b69bccacfbf961d2a8c624f4b4236ec54a239490b080d31d82b03f7c2d/detection/", "error": "\r\nManipulates network routing tables.\r\n\r\nROUTE [-f] [-p] [-4|-6] command [destination]\r\n [MASK netmask] [gateway] [METRIC metric] [IF interface]\r\n\r\n -f Clears the routing tables of all gateway entries. If this is\r\n used in conjunction with one of the commands, the tables are\r\n cleared prior to running the command.\r\n \r\n -p When used with the ADD command, makes a route persistent across\r\n boots of the system. By default, routes are not preserved\r\n when the system is restarted. Ignored for all other commands, \r\n which always affect the appropriate persistent routes.\r\n \r\n -4\t Force using IPv4.\r\n\r\n -6 Force using IPv6. \r\n \r\n command One of these:\r\n PRINT Prints a route\r\n ADD Adds a route\r\n DELETE Deletes a route\r\n CHANGE Modifies an existing route\t\r\n destination Specifies the host.\r\n MASK Specifies that the next parameter is the 'netmask' value.\r\n netmask Specifies a subnet mask value for this route entry.\r\n If not specified, it defaults to 255.255.255.255.\r\n gateway Specifies gateway.\r\n interface the interface number for the specified route.\r\n METRIC specifies the metric, ie. cost for the destination.\r\n\r\nAll symbolic names used for destination are looked up in the network database\r\nfile NETWORKS. The symbolic names for gateway are looked up in the host name\r\ndatabase file HOSTS.\r\n\r\nIf the command is PRINT or DELETE. Destination or gateway can be a wildcard,\r\n(wildcard is specified as a star '*'), or the gateway argument may be omitted.\r\n\r\nIf Dest contains a * or ?, it is treated as a shell pattern, and only\r\nmatching destination routes are printed. The '*' matches any string,\r\nand '?' matches any one char. Examples: 157.*.1, 157.*, 127.*, *224*.\r\n\r\nPattern match is only allowed in PRINT command.\r\nDiagnostic Notes:\r\n Invalid MASK generates an error, that is when (DEST & MASK) != DEST.\r\n Example> route ADD 157.0.0.0 MASK 155.0.0.0 157.55.80.1 IF 1\r\n The route addition failed: The specified mask parameter is invalid. (Destination & Mask) != Destination.\r\n\r\nExamples:\r\n\r\n > route PRINT\r\n > route PRINT -4\r\n > route PRINT -6\r\n > route PRINT 157* .... Only prints those matching 157*\r\n\t\r\n > route ADD 157.0.0.0 MASK 255.0.0.0 157.55.80.1 METRIC 3 IF 2\r\n destination^ ^mask ^gateway metric^ ^\r\n Interface^\r\n If IF is not given, it tries to find the best interface for a given \r\n gateway.\r\n > route ADD 3ffe::/32 3ffe::1\r\n \r\n > route CHANGE 157.0.0.0 MASK 255.0.0.0 157.55.80.5 METRIC 2 IF 2\r\n \r\n CHANGE is used to modify gateway and/or metric only.\r\n \r\n > route DELETE 157.0.0.0\r\n > route DELETE 3ffe::/32\r\n", "children": "RdpSa.exe" }, "RpcPing.exe-CA811321D81F4F5CF2762083A08502D5": { "file_name": "RpcPing.exe", "file_path": "C:\\Windows\\system32\\RpcPing.exe", "hash_md5": "CA811321D81F4F5CF2762083A08502D5", "hash_sha1": "5E3AA23E2A70DC2AD4172A3AF018521BABC95446", "hash_sha256": "CD6013ED67E859A186F43C5964BA877F1A22F36295AA70FD0B68E6D96AA284E8", "hash_sha384": "E0993D7F9070263CF3C264F83CFD8363406F0C364D0D25B372B3437B5E78D5A88C6EB8C135DD36B6DF5654A538CC4D9A", "hash_sha512": "F92F9E5623C7C210B5465A8E8D6B31A642D447C481FD7D5DCA3E4F13074F18F12818183592171ADC264F2964AA12920BDD1DFEEF1AF0F2C4BEA60BAFEAC35834", "hash_ssdeep": "768:5KVksgNKSs6yQdqlSlGwE5Dc5sg5IMlz:4yNKnK8SlG75Gsg5Plz", "hash_imp": "AA6B2A7321AE60F227BDF8367761D35D", "hash_pesha1": "238E5E06EB10E228FEB5FDEC5CA3785A99093A7B", "hash_pe256": "8AF1C4C493AB149BADD47C91FEAC8FB36FFBAF7FD527D62961B431A43FADA556", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RPC Ping Utility", "meta_original_filename": "RpcPing.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/cd6013ed67e859a186f43c5964ba877f1a22f36295aa70fd0b68e6d96aa284e8/detection/", "output": "Usage: \r\nrpcping [-t <protseq>] [-s <server_addr>] [-e <endpoint> \r\n |-f <interface UUID>[,MajorVer]] [-O <Interface Object UUID]\r\n [-i <#_iterations>] [-u <security_package_id>] [-a <authn_level>] \r\n [-N <server_princ_name>] [-I <auth_identity>] [-C <capabilities>]\r\n [-T <identity_tracking>] [-M <impersonation_type>]\r\n [-S <server_sid>] [-P <proxy_auth_identity>] [-F <RPCHTTP_flags>]\r\n [-H <RPC/HTTP_authn_schemes>] [-o <binding_options>]\r\n [-B <server_certificate_subject>] [-b] [-E] [-q] [-c]\r\n [-A <http_proxy_auth_identity>] [-U <HTTP_proxy_authn_schemes>]\r\n [-r <report_results_interval>] [-v <verbose_level>] \r\n\r\nPings a server using RPC. Options are:\r\n\r\n-t <protseq> - protocol sequence to use. Can be one of the standard\r\n RPC protocol sequences - ncacn_ip_tcp, ncacn_np, ncacn_http, etc.\r\n If not specified, default is ncacn_ip_tcp.\r\n \r\n-s <server_addr> - the server address. If not specified, the local\r\n machine will be pinged. E.g. server, server.com, 157.59.244.141\r\n \r\n-e <endpoint> - the endpoint to ping. If none is specified, the endpoint\r\n mapper on the target machine will be pinged. This option is mutually\r\n exclusive with the interface (-f) option.\r\n\r\n-o <binding_options> - the binding options for the RPC ping. See the\r\n MSDN for more details (RpcStringBindingCompose and RPC over HTTP).\r\n \r\n-f <interface UUID>[,MajorVer] - the interface to ping. This option is\r\n mutually exclusive with the endpoint option. The interface is specified\r\n as a UUID. If the MajorVer is not specified, version 1 of the interface\r\n will be sought. When interface is specified, rpcping will query the\r\n endpoint mapper on the target machine to retrieve the endpoint for the\r\n specified interface. The endpoint mapper will be queried using the\r\n options specified in the command line.\r\n \r\n-O <Object UUID> - Object Uuid if the interface registerd one.\r\n\r\n-i <#_iterations> - number of calls to make. The default is 1. This\r\n option is useful for measuring connection latency if multiple\r\n iterations are specified.\r\n \r\n-u <security_package_id> - the security package (security provider) RPC\r\n will use to make the call. The security package is identified as a\r\n number or a name. If a number is used it is the same number as in the\r\n RpcBindingSetAuthInfoEx API. The table below gives the names and\r\n numbers. Names are not case sensitive:\r\n Negotiate - 9 or one of nego, snego or negotiate\r\n NTLM - 10 or NTLM\r\n SChannel - 14 or SChannel\r\n Kerberos - 16 or Kerberos\r\n Kernel - 20 or Kernel\r\n If you specify this option you must specify authentication level other\r\n than none. There is no default for this option. If it is not specified,\r\n RPC will not use security for the ping.\r\n \r\n-a <authn_level> - the authentication level to use. Possible values are\r\n connect, call, pkt, integrity and privacy. If this option is\r\n specified, the security package id (-u) must also be specified. There\r\n is no default for this option. If this option is not specified, RPC\r\n will not use security for the ping.\r\n\r\n-N <server_princ_name> - specifies a server principal name. Same semantics\r\n as the ServerPrincName argument to RpcBindingSetAuthInfoEx. See the\r\n MSDN for more information on RpcBidningSetAuthInfoEx. This field can be\r\n used only when authentication level and security package are selected.\r\n \r\n-I <auth_identity> - allows you to specify alternative identity to connect\r\n to the server. The identity is in the form user,domain,password where\r\n the three fields have the obvious meaning. If the user name, domain or\r\n password have special characters that can be interpreted by the shell\r\n be sure to enclose the identity in double quotes. You can specify *\r\n instead of the password and RPC will prompt you to enter the password\r\n without echoing it on the screen. If this field is not specified, the\r\n identity of the logged on user will be used. This field can be used\r\n only when authentication level and security package are selected.\r\n \r\n-C <capabilities> - a hex bitmask of flags. It has the same meaning as\r\n the Capabilities field in the RPC_SECURITY_QOS structure described\r\n in the MSDN. This field can be used only when authentication level and\r\n security package are selected.\r\n \r\n-T <identity_tracking> - can be static or dynamic. If not specified,\r\n dynamic is the default. This field can be used only when authentication\r\n level and security package are selected.\r\n\r\n-M <impersonation_type> - can be anonymous, identify, impersonate or\r\n delegate. Default is impersonate. This field can be used only when\r\n authentication level and security package are selected. \r\n\r\n-S <server_sid> - the expected SID of the server. For more information\r\n see the Sid field in the RPC_SECURITY_QOS structure in the MSDN. Using \r\n this option requires Windows .NET Server 2003 or higher. This field can\r\n be used only when authentication level and security package are\r\n selected.\r\n \r\n-Z <effectiveonly> - the EffectiveOnly setting to use. For more information\r\n see the EffectiveOnly field in the RPC_SECURITY_QOS structure in MSDN.\r\n Using this option requires Windows Vista or higher. This field can be\r\n used only when authentication level and security package are selected.\r\n\r\n-D <serversecuritydescriptor> - the security descriptor (in string format)\r\n of the server when using mutual authentication. For more information\r\n see the ServerSecurityDescriptor field in the RPC_SECURITY_QOS structure\r\n in MSDN. Using this option requires Windows 8 or higher. This field can\r\n be used only when authentication level and security package are\r\n selected.\r\n\r\n-P <proxy_auth_identity> - specifies the identity to authenticate with to\r\n the RPC/HTTP proxy. Has the same format as for the -I option. \r\n Also, you must specify security package (-u), authentication level \r\n (-a), and authentication schemes (-H) in order to use this option.\r\n \r\n-F <RPCHTTP_flags> - the flags to pass for RPC/HTTP front end\r\n authentication. The flags may be specified as numbers or names\r\n The currently recognized flags are:\r\n Use SSL - 1 or ssl or use_ssl\r\n Use first auth scheme - 2 or first or use_first\r\n See the Flags field in RPC_HTTP_TRANSPORT_CREDENTIALS for more \r\n information. Also, you must specify security package (-u) and \r\n authentication level (-a) in order to use this option.\r\n \r\n-H <RPC/HTTP_authn_schemes> - the authentication schemes to use for\r\n RPC/HTTP front end authentication. This option is a list of numerical\r\n values or names separated by comma. E.g. Basic,NTLM. Recognized values\r\n are (names are not case sensitive:\r\n Basic - 1 or Basic\r\n NTLM - 2 or NTLM\r\n Certificate - 65536 or Cert\r\n Also, you must specify security package (-u) and authentication level \r\n (-a) in order to use this option.\r\n \r\n-B <server_certificate_subject> - the server certificate subject. For\r\n more information, see the ServerCertificateSubject field in the\r\n RPC_HTTP_TRANSPORT_CREDENTIALS structure in the MSDN. You must use\r\n SSL for this option to work. Also, you must specify security package \r\n (-u) and authentication level (-a) in order to use this option.\r\n \r\n-b - retrieves the server certificate subject from the certificate sent\r\n by the server and prints it to a screen or a log file. Valid only when\r\n the Proxy Echo only option (-E) and the use SSL options are specified.\r\n Also, you must specify security package (-u) and authentication level \r\n (-a) in order to use this option.\r\n \r\n-R - specifies the HTTP proxy. if it's 'none', we will not use HTTP proxy but\r\n directly attempt the RPC proxy. the value 'default' means to use the IE\r\n settings in your client machine. any other value will be treated as the\r\n explicit HTTP proxy. if you don't specify this flag, the default value\r\n is assumed, that is, the IE settings are checked. this flag is valid\r\n only when the -E (Echo Only) flag is enabled.\r\n\r\n-E - restricts the ping to the RPC/HTTP proxy only. The ping does not\r\n reach the server. Useful when trying to establish whether the RPC/HTTP\r\n proxy is reachable. Also, you must specify security package (-u) and \r\n authentication level (-a) in order to use this option. To specify an \r\n HTTP proxy, use the -R flag. If an HTTP proxy is specified in the -o \r\n flag, this option will be ignored.\r\n \r\n-q - quiet mode. Does not issue any prompts except for passwords. Assumes\r\n 'Y' response to all queries. Use this option with care.\r\n \r\n-c - use smart card certificate. RPCPing will prompt user to choose\r\n smart card.\r\n \r\n-A <http_proxy_auth_identity> - specifies the identity to authenticate\r\n with to the HTTP proxy. Has the same format as for the -I option. \r\n Also, you must specify authentication schemes (-U), security package \r\n (-u) and authentication level (-a) in order to use this option.\r\n \r\n-U <HTTP_proxy_authn_schemes> - the authentication schemes to use for\r\n HTTP proxy authentication. This option is a list of numerical\r\n values or names separated by comma. E.g. Basic,NTLM. Recognized values \r\n are (names are not case sensitive:\r\n Basic - 1 or Basic\r\n NTLM - 2 or NTLM\r\n You must specify security package (-u) and authentication level (-a) \r\n in order to use this option.\r\n\r\n-r <report_results_interval> - if multiple iterations are specified, this\r\n option will make rpcping display current execution statistics\r\n periodically instead after the last call. The report interval is given\r\n in seconds. Default is 15.\r\n \r\n-v <verbose_level> - tells rpcping how verbose to make the output. Default\r\n value is 1. 2 and 3 provide more output from rpcping.\r\n \r\nExample: Find out if your Exchange server that you connect through\r\nRPC/HTTP is accessible:\r\n rpcping -t ncacn_http -s exchange_server -o RpcProxy=front_end_proxy\r\n -P \"username,domain,*\" -H Basic -u NTLM -a connect -F 3\r\nWhen prompted for the password, enter it. exchange_server is the name of\r\nyour exchange server, front_end_proxy is the name of your proxy, username\r\nand domain are your user name and domain as you would enter them in the\r\nOutlook prompt. The other parameters will ask rpcping to ping your\r\nExchange server in exactly the same way as Outlook will connect to it for\r\nthe typical profile.\r\n\r\n-p - Prompt for credentials if authentication fails.\r\n", "children": "RdpSa.exe", "runtime_modules": [ "C:\\Windows\\system32\\RpcPing.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\WINHTTP.dll", "C:\\Windows\\system32\\credui.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\rpchttp.dll", "C:\\Windows\\system32\\Secur32.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\mswsock.dll" ] }, "rrinstaller.exe-9CA38CCC600710A97F7813E74C42C08A": { "file_name": "rrinstaller.exe", "file_path": "C:\\Windows\\system32\\rrinstaller.exe", "hash_md5": "9CA38CCC600710A97F7813E74C42C08A", "hash_sha1": "A1E18F2359DFE58303C5158A265AD0448494799C", "hash_sha256": "AC5814DF94802962346A77C6D5ACD315F499C4C8AC2E2578875663EC88382B08", "hash_sha384": "ADBA25FDBB08D649D397E35FFBA4D9696A7401A7949D5AE603C0BA700B58C2A148BC71C3144AA1D7185769799CC975DA", "hash_sha512": "12CD81A6667D2AD49EB38964072A773A628BC37E5E4AB9212F7324C1863A3E55FE048E76D6BC4B8D41DF5AA1527EEAB522677895F4892F6091C285A13C899287", "hash_ssdeep": "768:iQkknGJ9XiQobtfrATJu24graGtNkg+lJPxuJJPLFWqvpKf+6cIYtrKftH5+XmUm:iQnny9yDqdu2FlAJPIJPL1RZ0YtrK0XC", "hash_imp": "0F7716C51D703DF0FEA1B2EE96B8C0C7", "hash_pesha1": "65141E93A0527B4DD85B862A8B71832ADB985810", "hash_pe256": "3D2FE754D5EABDE609D356CDFAA95E759B10DCEE8B74FF1565F959B7FD0992D1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "R&R installer", "meta_original_filename": "rrinstaller.exe", "meta_product_name": "Microsoft DRM", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.0.17763.1", "meta_product_version": "11.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/ac5814df94802962346a77c6d5acd315f499c4c8ac2e2578875663ec88382b08/detection/", "runtime_modules": [ "C:\\Windows\\system32\\rrinstaller.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\comctl32.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "rsopprov.exe-36AF828F5600E4EF4FFC280EE0ACC2F8": { "file_name": "rsopprov.exe", "file_path": "C:\\Windows\\system32\\rsopprov.exe", "hash_md5": "36AF828F5600E4EF4FFC280EE0ACC2F8", "hash_sha1": "DA4E11C085B28B78F9F58BF294706EAC21BB892F", "hash_sha256": "9E64203785BBE78A22F8F8F89603FC9E7706A4D36E28B5FD7667BF3FCA49938B", "hash_sha384": "376073A214D8E6585097900EC3777D713FDFF150907D8EB3FF1621CE3AFAF4717DA7BE7D1CFFA8A1F6032E73A5F199F9", "hash_sha512": "99652AC1B5C80944C0F368E5ADF9256BF43BB8C3125468CBE2D54402E3F6FB660B7860D9A0D2A75DD8A8619A065112F849EB7CB62A86F23C61AFDD71FB71A65A", "hash_ssdeep": "1536:CVMBYjg4AbfGDGgfnvaCqpNUzA4HtQEKYG++Rb9Md42hOg+cnjBITByRfp+:CVMBYj3dH+aHcYG+0b9Md42hOg+cnjBs", "hash_imp": "0303CFCDB1A86B2E54CAA3CBB14195DB", "hash_pesha1": "081D36306D8CDAE27D996DB5924458B6E1615B63", "hash_pe256": "5CCF14029F00050C5CC1C8ADA1A7748BCE6C3141E5045C60B86C90485B374B7B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RSoP Service Application", "meta_original_filename": "RSOPPROV.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/9e64203785bbe78a22f8f8f89603fc9e7706a4d36e28b5fd7667bf3fca49938b/detection/", "runtime_modules": [ "C:\\Windows\\system32\\rsopprov.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\GPAPI.dll", "C:\\Windows\\system32\\NTDSAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\Secur32.dll", "C:\\Windows\\system32\\GPSVC.dll", "C:\\Windows\\system32\\SYSNTFY.dll", "C:\\Windows\\system32\\nlaapi.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\System32\\IMM32.DLL" ] }, "runas.exe-CAC532847757A87F5F114D1DC8CB329C": { "file_name": "runas.exe", "file_path": "C:\\Windows\\system32\\runas.exe", "hash_md5": "CAC532847757A87F5F114D1DC8CB329C", "hash_sha1": "7F71F9A43D484FB9860AE5B23B0AC1A2D419EAD9", "hash_sha256": "018394B4655446EC0895601AC25879C80428C72FAB4361792ED69C5FA6C97C34", "hash_sha384": "1FB0B5917C730FCB3909918F4F943221CC32D55BE3ABCC551DBBC078CAA5F143B2249597F34F12DDEEBA8010FFC0CF9A", "hash_sha512": "07DCE057CE7C3F96D5BDD3CE37CBCB2F27D5E3FDFFAA5E8FCE13DA9A24F7F80C54E74969FB255950F067A6D7D85EB0DC6AE803AAC1DBFCA2340D442D7515B1AD", "hash_ssdeep": "384:10Zk1395kbLiXKsxlDzb0jTivTsy0MKffCO6nLMQLlYSQ3tytWBOW:uZkP5kbLib1QTibsy0dCtnb/Q9yQ", "hash_imp": "5B7B2489AAE1B4C266ABE004F393E61C", "hash_pesha1": "513C64F9940FC6E9E4B28CDE3C773EDA6F391C6F", "hash_pe256": "FD1A4DD56A55871D2B717D5DA6F30218923DF72C2AB893F9F30A0AECB9B06401", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Run As Utility", "meta_original_filename": "RUNAS.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/018394b4655446ec0895601ac25879c80428c72fab4361792ed69c5fa6c97c34/detection/" }, "rundll32.exe-C73BA51880F5A7FB20C84185A23212EF": { "file_name": "rundll32.exe", "file_path": "C:\\Windows\\system32\\rundll32.exe", "hash_md5": "C73BA51880F5A7FB20C84185A23212EF", "hash_sha1": "F3BA3415DD068A8871F285570BEA2E29874CBFF1", "hash_sha256": "01B407AF0200B66A34D9B1FA6D9EAAB758EFA36A36BB99B554384F59F8690B1A", "hash_sha384": "24BE5241AF6FBEA4DF047DC2BFB643A76AD3FE7FAC5407D8E6A6C3F0799A8B53E2919054B7F81B241FACCEA7AF8459D8", "hash_sha512": "F5AA1650436AAD76B50364F9677A14127B02AFF044F5A62A46C7A884F178C7AFF9FEFDA172A6D19AF31B3FD635B1A42178FC5D3B31F83372BF5B3E2FA019B92C", "hash_ssdeep": "1536:zTJrjNfTZ+Y0WDxEsGepjmJ1BRNln5IUmDjoX:DfTZjp1EsHqhRNln5I", "hash_imp": "F27A7FC3A53E74F45BE370131953896A", "hash_pesha1": "5511493C2132AF46878F4BC09735B6A81DA33C27", "hash_pe256": "F62DA09F93E0FC2D25421842B0688D56C5EFE756C6C9C9D8FD5E36026F6A67CD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows host process (Rundll32)", "meta_original_filename": "RUNDLL32.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/01b407af0200b66a34d9b1fa6d9eaab758efa36a36bb99b554384f59f8690b1a/detection/" }, "runexehelper.exe-822113BA3C8E8FD11723FEAB1A144175": { "file_name": "runexehelper.exe", "file_path": "C:\\Windows\\system32\\runexehelper.exe", "hash_md5": "822113BA3C8E8FD11723FEAB1A144175", "hash_sha1": "79203AAE7D83419809378405770C380C774048EA", "hash_sha256": "3424FAF87604930DAEB0F98BD820E9288422BB847471993D927A8C77F345FDB6", "hash_sha384": "F0514020D209F5F22D0938451CC23204B1C93CB6CA2C406046A5582209EF5E2A342ADA14FCC6360BA832161F9EDBF208", "hash_sha512": "053CA49DB9E50DEF8A19D735C51EB7527A9F68BDE458AD539DFE2D641E40CA04E699FA5CCE6326BF551D2AB8D4431D93C5CF278BA0E449D8EA9E7009A6384DE8", "hash_ssdeep": "1536:gyXzOMgKLMfE+rVMJDokHccTyBMj61X45ujDRlvi:gsNaE+rVMJDok88kQ6RSuj", "hash_imp": "C3F7EF5A2F0F2AF4CEF56598F5E44D36", "hash_pesha1": "91B8E4CE91486DD123D41EDC54B622B0313D240D", "hash_pe256": "F08B0AEBC822B587E90C6612966DB5CD6C5D697CF8A352B83170E7385A7FC449", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/50", "filescan_vtlink": "https://www.virustotal.com/gui/file/3424faf87604930daeb0f98bd820e9288422bb847471993d927a8c77f345fdb6/detection/" }, "RunLegacyCPLElevated.exe-087E9B620445BD9C32451060138DEB23": { "file_name": "RunLegacyCPLElevated.exe", "file_path": "C:\\Windows\\system32\\RunLegacyCPLElevated.exe", "hash_md5": "087E9B620445BD9C32451060138DEB23", "hash_sha1": "4420C47590CC4F1FD2D404BA3CC8D4F8E82E01E7", "hash_sha256": "8809B4EEC6249DA237D5AA0D49DD73C4CEB40D0DF52F1DD0EA9DD5E13360F0ED", "hash_sha384": "1D61DAC1B187C365210B235C498672F758DB9C3A7D74914BFEC94E2F021E526F4C6C42D09F365E67FC81CFC94C40DBDA", "hash_sha512": "CF5EBB0865C9BCB67A3D9BCDCC01F1195A69F40FCD73FF1C6DE6BB0967B288178535F707F9D309FFE5CAB3A2737A724DD8A130CFF5C9E9A629D18D44A95EE4BE", "hash_ssdeep": "768:fghJh8xm92NDohEG7b6OeCH8HyZEyzAKyshQ9SGSkVhWakkbB5eT905WGnUKxHUW:ov9dEc6Q1+KyN9Sxakkn6oYY0ewiP8", "hash_imp": "994147192F9A5486FF1045A684507004", "hash_pesha1": "F64DF022ED86557025770B6220BA7ACADCF075EE", "hash_pe256": "112F424C031CC7B7A845D0EACCF207FAFF271F8D21D1718897EA841DC1013ABE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Run a legacy CPL elevated", "meta_original_filename": "RunLegacyCPLElevated.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/8809b4eec6249da237d5aa0d49dd73c4ceb40d0df52f1dd0ea9dd5e13360f0ed/detection/", "runtime_modules": [ "C:\\Windows\\system32\\RunLegacyCPLElevated.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll" ] }, "runonce.exe-05B30AB4768E5108E18986A5867C68F7": { "file_name": "runonce.exe", "file_path": "C:\\Windows\\system32\\runonce.exe", "hash_md5": "05B30AB4768E5108E18986A5867C68F7", "hash_sha1": "9A10295C54450788722A8C97BDCA5857D8666CF6", "hash_sha256": "E4AFEF687BCEFB9A581299FB35946C869C6D0E000966E688589A48907C352432", "hash_sha384": "6A92BE80EA3C41057B29760D7B2FE18C024A7A9CF7A698A47D520920FA98F0A778640766A522F90A85DB111752A8D04E", "hash_sha512": "D49CB830DA90DFC873FFB105C58599098F6E67B97B8DD159F668C2968864E3DDB340CC3DA4AF3E087529AB4DC85ACF7D1130518C201330D0245D7AD987065A41", "hash_ssdeep": "1536:ooX4KqGA17ukVmCgnTAX0ZgdZK7lonRm9NVcqDoZq+Sh:ooZOVkCgnTAysk9N+cCq+C", "hash_imp": "EC2020E2A17AC9DD377F6A8CA39994C4", "hash_pesha1": "BE53B5FC19DB84C9F8AAFBB346C8FB5C29D57E88", "hash_pe256": "E876276A94326DA85FB139D6BECA07BECD791C6F6A333799531CC08645D22C6C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Run Once Wrapper", "meta_original_filename": "RUNONCE.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/e4afef687bcefb9a581299fb35946c869c6d0e000966e688589a48907c352432/detection/", "runtime_modules": [ "C:\\Windows\\system32\\runonce.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CoreMessaging.dll" ] }, "RuntimeBroker.exe-57ACEB23C3E8F94FE0393AA2029BADDC": { "file_name": "RuntimeBroker.exe", "file_path": "C:\\Windows\\system32\\RuntimeBroker.exe", "hash_md5": "57ACEB23C3E8F94FE0393AA2029BADDC", "hash_sha1": "E17AB3C6C038F086D0654626B62979795AD06EFE", "hash_sha256": "E00345A3DF0EE01EDBD9C14E39EA8C8D5FA0A7D09DE8141155333391F8AAA453", "hash_sha384": "4CB19CB602B964BA4DB15729C5D479E4C3A22632882BCC4456191013419BA5C911E9E475935A0672DE64D51DC94067CD", "hash_sha512": "EE52F0FCAB28A05AE7FF2A9EBD248C94886192C46BB585770C02D235AA0D48C0CA4BD15617772BC0A859593F2A97E70DD8D94946F01E62698C1F2F044F9AE3BD", "hash_ssdeep": "1536:/vCUohAf8DfSSSeoucmUgLGJssg1NKxV1jLEAOV/ySSyQEA5X+VU2e5fPmkK:/gQufSSSSFaJjJO/yfyQBIfqf+kK", "hash_imp": "0EED46A2FDA377B907A358F23DB4199F", "hash_pesha1": "5E7C87CCA1625B1F048CECAEF829EFE1AB9A8202", "hash_pe256": "B21CB49168436529063E11E79130D1068DAC350982056D6D8DE23F88DC76C0F5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Runtime Broker", "meta_original_filename": "RuntimeBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e00345a3df0ee01edbd9c14e39ea8c8d5fa0a7d09de8141155333391f8aaa453/detection/" }, "rwinsta.exe-BB409E77E0EF5A6645A0E665586C7440": { "file_name": "rwinsta.exe", "file_path": "C:\\Windows\\system32\\rwinsta.exe", "hash_md5": "BB409E77E0EF5A6645A0E665586C7440", "hash_sha1": "E87E7EB825F16DBB3DE635557441115465DF6C58", "hash_sha256": "1689688B1D2F5F75FA038D340CA6FFB379C99DF9137E6BE57861B80D68727A23", "hash_sha384": "F28797BC53AD0A0EB15E5F3D4539EA5B9F942FCD858C96CA189D05947293C2B479EE86B8D3A60FF977076FC8FC5BE9BC", "hash_sha512": "BDE11815163B2DC5425052906AEE54A7ABFCFB06744D1B650FD439BDDB4F46D3F099C3A3E2A670EBE31EAA2080390CED6FE3CC94242D69C7EC1A571793295091", "hash_ssdeep": "384:issqyMYMx/kBrpVNcENkE1z5YcsK80vnkt8HhdoWjMcZpeS1xvWdZW:fdbY8ErpV5NNHsK8ChnVLeSrS", "hash_imp": "ACE7E1CA440DD0C4C63E4D2682CA6E8B", "hash_pesha1": "8EC50D68C254A3C4E7C0A7DC0CFB51FFC60DC9F1", "hash_pe256": "CE990DCEDC734A73AEC34835F4A06D115D4CB8C193C54AC2F0B21E40C1FFA139", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Reset Session Utility", "meta_original_filename": "rwinsta.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/1689688b1d2f5f75fa038d340ca6ffb379c99df9137e6be57861b80d68727a23/detection/", "output": "Reset the session subsytem hardware and software to known initial values.\r\n\r\nRESET SESSION {sessionname | sessionid} [/SERVER:servername] [/V]\r\n\r\n sessionname Identifies the session with name sessionname.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server containing the session (default is current).\r\n /V Display additional information.\r\n\r\n", "error": "Invalid parameter(s)\r\nReset the session subsytem hardware and software to known initial values.\r\n\r\nRESET SESSION {sessionname | sessionid} [/SERVER:servername] [/V]\r\n\r\n sessionname Identifies the session with name sessionname.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server containing the session (default is current).\r\n /V Display additional information.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\rwinsta.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "sacsess.exe-F52B6C21995158EFA3FF9A17E13A6836": { "file_name": "sacsess.exe", "file_path": "C:\\Windows\\system32\\sacsess.exe", "hash_md5": "F52B6C21995158EFA3FF9A17E13A6836", "hash_sha1": "DD5E1CFFA6C82BEA7430D6BFFD81C089A72ACB26", "hash_sha256": "4BCC833D4262AB483DA3273D4AF1F86CDD7C43EA7B41580DD53958E6287CD6B7", "hash_sha384": "EF3AD01FBE4FB5B1B34C53CD2391667B4FC5DD6AB1F07D7D9282F24C656DE4F9F49F257C53DD8A981D3BEBDEDF1F6E64", "hash_sha512": "935890756FC7E1EE2152CD836C36D3C85550B965B1D0E3908440413F9C42083C25A9D98116689172F1258683CFC8F0690595CEBCDD9823B1F4E6263DD891DAE0", "hash_ssdeep": "768:bQPZHEsRCImDih+xVUhCfvVUPYi/1QSvklt0xuZ81c:0hNRPh+xtVUPYM6axuZQc", "hash_imp": "B744C97D3547C93EAA6F369428367421", "hash_pesha1": "A78F98281C9E1F87FD42D7D61A605C210FE64E47", "hash_pe256": "197E1FD0535E7048F1B58C38616CC3B033A9EF7685689159BED447E923B3488C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft SAC Service Helper", "meta_original_filename": "sacsess.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/4bcc833d4262ab483da3273d4af1f86cdd7c43ea7b41580dd53958e6287cd6b7/detection/" }, "sc.exe-ABB56882148DE65D53ABFC55544A49A8": { "file_name": "sc.exe", "file_path": "C:\\Windows\\system32\\sc.exe", "hash_md5": "ABB56882148DE65D53ABFC55544A49A8", "hash_sha1": "622FA2729408E5F467A592223219DA7C547E7CC7", "hash_sha256": "78097C7CD0E57902536C60B7FA17528C313DB20869E5F944223A0BA4C801D39B", "hash_sha384": "76B40634370C6B8C96FE9CC24372015E0E32A895358C0798E56158A265B0215010CFB38A970896BB1BB31D1AD77B0683", "hash_sha512": "D04AE715C5A9D350D6CBE42A7F10624404C7117461FC5606C07C2A7009D5373090043900BE2FE580BACE69035F927B2BF9FB2D894193955BA8FCA08FB0C55821", "hash_ssdeep": "768:BS23fIZCq5rhrahiDuBk3nFO1NV7JrKyS3P2NXjzb222/0NUOAX3mrvH6tY9xS37:E2wgYhOEKKO3V7zNXt5Z9xtOgzZgH", "hash_imp": "35A7FFDE18D444A92D32C8B2879450FF", "hash_pesha1": "F3BCBF44E6D65D8E14DC5CC4B45D831E8F3E00F1", "hash_pe256": "B3376F2450D342F68C7771F7BAE2C39973D19CF40A17265791F158497ED6A26D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Service Control Manager Configuration Tool", "meta_original_filename": "sc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/78097c7cd0e57902536c60b7fa17528c313db20869e5f944223a0ba4c801d39b/detection/", "output": "\r\nERROR: Unrecognized command\r\n\r\nDESCRIPTION:\r\n SC is a command line program used for communicating with the\r\n Service Control Manager and services.\r\nUSAGE:\r\n sc <server> [command] [service name] <option1> <option2>...\r\n\r\n\r\n The option <server> has the form \"\\\\ServerName\"\r\n Further help on commands can be obtained by typing: \"sc [command]\"\r\n Commands:\r\n query-----------Queries the status for a service, or\r\n enumerates the status for types of services.\r\n queryex---------Queries the extended status for a service, or\r\n enumerates the status for types of services.\r\n start-----------Starts a service.\r\n pause-----------Sends a PAUSE control request to a service.\r\n interrogate-----Sends an INTERROGATE control request to a service.\r\n continue--------Sends a CONTINUE control request to a service.\r\n stop------------Sends a STOP request to a service.\r\n config----------Changes the configuration of a service (persistent).\r\n description-----Changes the description of a service.\r\n failure---------Changes the actions taken by a service upon failure.\r\n failureflag-----Changes the failure actions flag of a service.\r\n sidtype---------Changes the service SID type of a service.\r\n privs-----------Changes the required privileges of a service.\r\n managedaccount--Changes the service to mark the service account \r\n password as managed by LSA.\r\n qc--------------Queries the configuration information for a service.\r\n qdescription----Queries the description for a service.\r\n qfailure--------Queries the actions taken by a service upon failure.\r\n qfailureflag----Queries the failure actions flag of a service.\r\n qsidtype--------Queries the service SID type of a service.\r\n qprivs----------Queries the required privileges of a service.\r\n qtriggerinfo----Queries the trigger parameters of a service.\r\n qpreferrednode--Queries the preferred NUMA node of a service.\r\n qmanagedaccount-Queries whether a services uses an account with a \r\n password managed by LSA.\r\n qprotection-----Queries the process protection level of a service.\r\n quserservice----Queries for a local instance of a user service template.\r\n delete----------Deletes a service (from the registry).\r\n create----------Creates a service. (adds it to the registry).\r\n control---------Sends a control to a service.\r\n sdshow----------Displays a service's security descriptor.\r\n sdset-----------Sets a service's security descriptor.\r\n showsid---------Displays the service SID string corresponding to an arbitrary name.\r\n triggerinfo-----Configures the trigger parameters of a service.\r\n preferrednode---Sets the preferred NUMA node of a service.\r\n GetDisplayName--Gets the DisplayName for a service.\r\n GetKeyName------Gets the ServiceKeyName for a service.\r\n EnumDepend------Enumerates Service Dependencies.\r\n\r\n The following commands don't require a service name:\r\n sc <server> <command> <option>\r\n boot------------(ok | bad) Indicates whether the last boot should\r\n be saved as the last-known-good boot configuration\r\n Lock------------Locks the Service Database\r\n QueryLock-------Queries the LockStatus for the SCManager Database\r\nEXAMPLE:\r\n sc start MyService\r\n\r\n\r\nQUERY and QUERYEX OPTIONS:\r\n If the query command is followed by a service name, the status\r\n for that service is returned. Further options do not apply in\r\n this case. If the query command is followed by nothing or one of\r\n the options listed below, the services are enumerated.\r\n type= Type of services to enumerate (driver, service, userservice, all)\r\n (default = service)\r\n state= State of services to enumerate (inactive, all)\r\n (default = active)\r\n bufsize= The size (in bytes) of the enumeration buffer\r\n (default = 4096)\r\n ri= The resume index number at which to begin the enumeration\r\n (default = 0)\r\n group= Service group to enumerate\r\n (default = all groups)\r\n\r\nSYNTAX EXAMPLES\r\nsc query - Enumerates status for active services & drivers\r\nsc query eventlog - Displays status for the eventlog service\r\nsc queryex eventlog - Displays extended status for the eventlog service\r\nsc query type= driver - Enumerates only active drivers\r\nsc query type= service - Enumerates only Win32 services\r\nsc query state= all - Enumerates all services & drivers\r\nsc query bufsize= 50 - Enumerates with a 50 byte buffer\r\nsc query ri= 14 - Enumerates with resume index = 14\r\nsc queryex group= \"\" - Enumerates active services not in a group\r\nsc query type= interact - Enumerates all interactive services\r\nsc query type= driver group= NDIS - Enumerates all NDIS drivers\r\n\n", "runtime_modules": [ "C:\\Windows\\system32\\sc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "schtasks.exe-3F9FD6D3B3E96B8F576DB72035DB38A7": { "file_name": "schtasks.exe", "file_path": "C:\\Windows\\system32\\schtasks.exe", "hash_md5": "3F9FD6D3B3E96B8F576DB72035DB38A7", "hash_sha1": "112C8FFA1C0934ACAAD2C58B3C7E81F3FB8E4A2C", "hash_sha256": "D6BA2CD73799477C051D9D864C47FCF5108064CDE07D3565871AFA10FC548086", "hash_sha384": "5079931C9324C089DB2399C9F010AEB1DF81F455EDEE5318EEB121C3EF93FEB7401AA939005224A97685D6934D6D3216", "hash_sha512": "B5A49F7E7F576506BED1AFC56598ADD48E905FACCA977B88E39A77E860566E0E6F4EB2681655B684F2E62565646B95074B610EB6C9F967A49B077AD32CD94734", "hash_ssdeep": "3072:4+okQr133swwjnvuU43spTVmpUWkppIphWhS8+oAxT/aC4Sk2pGh9mk+4SW0AatY:FpQV3sVnOYVmSz8rES1XxTaCD4SW0z", "hash_imp": "7EE4BC5589713B3470B8A950256E2E69", "hash_pesha1": "35D1E14F67BCFE72E8E00F9D347098F9ABB17B0B", "hash_pe256": "054CF3E19D6BE04ABE22BE6FD39681F5557C75531A745583D40DFF92205E459D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Scheduler Configuration Tool", "meta_original_filename": "schtasks.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/d6ba2cd73799477c051d9d864c47fcf5108064cde07d3565871afa10fc548086/detection/", "output": "\r\nSCHTASKS /parameter [arguments]\r\n\r\nDescription:\r\n Enables an administrator to create, delete, query, change, run and\r\n end scheduled tasks on a local or remote system. \r\n\r\nParameter List:\r\n /Create Creates a new scheduled task.\r\n\r\n /Delete Deletes the scheduled task(s).\r\n\r\n /Query Displays all scheduled tasks.\r\n\r\n /Change Changes the properties of scheduled task.\r\n\r\n /Run Runs the scheduled task on demand.\r\n\r\n /End Stops the currently running scheduled task.\r\n\r\n /ShowSid Shows the security identifier corresponding to a scheduled task name.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n SCHTASKS \r\n SCHTASKS /?\r\n SCHTASKS /Run /?\r\n SCHTASKS /End /?\r\n SCHTASKS /Create /?\r\n SCHTASKS /Delete /?\r\n SCHTASKS /Query /?\r\n SCHTASKS /Change /?\r\n SCHTASKS /ShowSid /?\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"SCHTASKS /QUERY /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\schtasks.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ScriptRunner.exe-71B9062F02950BAA4441E2FB79677E99": { "file_name": "ScriptRunner.exe", "file_path": "C:\\Windows\\system32\\ScriptRunner.exe", "hash_md5": "71B9062F02950BAA4441E2FB79677E99", "hash_sha1": "96801898A334E56321E7CAF57E4219A7D9FA02A1", "hash_sha256": "9FAAC81785C13368908C6A64C0A0B88D58060CF9F0148717EA3DEB64ADD1A874", "hash_sha384": "B84609538C6B0B3D6C686F05B4A6305F3DDDEDAF79307BCD82AF7C5BD418C051DBD658EE759F7419182E8C9CEBFCDF4A", "hash_sha512": "5F4A102D6034E535F51D70876F6E22523D481BB1417921758208F3B4D3A28BB41B39D28B6BB9509F15AC07FF9B6651E5D0EE66B51C7ECE13DE3E146AA7CA0918", "hash_ssdeep": "384:T9zXIqagu/0Ei6GmtpWowWcmXjDBRJDRjY1lxd:BzdG/0TZ8VzXj1P", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "F6E0DA3F1D552F1013E29F01F86467AC3E1E0598", "hash_pe256": "A6C9478E691C65D19AD9C6B03C7D53F1217BFA766876BF72949C89618C59B04D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "ScriptRunner.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1", "meta_product_version": "10.0.17763.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/9faac81785c13368908c6a64c0a0b88d58060cf9f0148717ea3deb64add1a874/detection/", "runtime_modules": [ "C:\\Windows\\system32\\ScriptRunner.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\5543cca0df435801e2303ff46a482ed5\\mscorlib.ni.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\CRYPTBASE.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\6885802f40fd803e49150d8a2b43a09b\\System.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Core\\f29b1120627489754c4b8dd317bbe950\\System.Core.ni.dll" ], "output": "Invalid argument specified: --help\r\nUsage:\r\nScriptRunner.exe\r\n-appvscript scriptFileName [Arguments] [-appvscriptrunnerparameters [-wait] [-timeout=<TimeInSeconds>] [-rollbackonerror]] \r\n-appvscript scriptFileName [Arguments] [-appvscriptrunnerparameters [-wait] [-timeout=<TimeInSeconds>] [-rollbackonerror]] \r\n...\r\nDefault values for -appvscriptrunnerparameters: No wait, No timeout, No rollback on error\r\nEvery parameter must be separated by a unicode space character (U+0020)\r\nExample:\r\nScriptRunner.exe -appvscript foo.cmd arg1 arg2 -appvscriptrunnerparameters -wait -timeout=30 -rollbackonerror -appvscript foobar.exe arg1 arg2\r\nError: Invalid argument specified\r\n" }, "sdbinst.exe-6A4B8C7090D67687D9A46E9BEC67FE48": { "file_name": "sdbinst.exe", "file_path": "C:\\Windows\\system32\\sdbinst.exe", "hash_md5": "6A4B8C7090D67687D9A46E9BEC67FE48", "hash_sha1": "3FEA26A8E6E66B373C954F0601EAA22F544341D2", "hash_sha256": "E4F4F22E877C3A417EEA12E7B94CB014CA44CDCDD8F28E3875D90DEF937F182D", "hash_sha384": "CCAB3F10FA1519B34A4E24497BD7BEB23F6093DFF325316281C5B2F537067CDAB93930F4B9791E7A36CC32D48F320E0C", "hash_sha512": "A0E27C7D23BAA4637739913F6DA5B9C8D8AA65AAFE4EF9E1D25D9E819BE6D0FCEFCC78112CB817427B278DAC4CBC5DCE4F521B1FAEBCC42310584862F5A82C5E", "hash_ssdeep": "384:s/y/Z0MK6L81zXovOym1a5gOFxYIzr/GdsEri/EXD4pLCIy2BcmQ7WngW:2y/ZhgYfm1WgEWT0WIy2BcmQg", "hash_imp": "5D01C40092C3C1075F7A8335CD70663B", "hash_pesha1": "1AD379D6F1D33D08742DDD8718C1A4F9DF296888", "hash_pe256": "80E7233BCFBBF7A7963B0003EDFEFA1225FC4F2BBE102012FAD3D9A0C1D4AA88", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Application Compatibility Database Installer", "meta_original_filename": "sdbinst.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/e4f4f22e877c3a417eea12e7b94cb014ca44cdcdd8f28e3875d90def937f182d/detection/", "output": "Error: Invalid switch --help.\nUsage: C:\\Windows\\system32\\sdbinst.exe [-?] [-q] [-u] [-g] [-p] [-n[:WIN32|WIN64]] myfile.sdb | {guid} | \"name\"\r\n\r\n -? - print this help text.\r\n -p - Allow SDBs containing patches.\r\n -q - Quiet mode: prompts are auto-accepted.\r\n -u - Uninstall.\r\n -g {guid} - GUID of file (uninstall only).\r\n -n \"name\" - Internal name of file (uninstall only).\n" }, "sdiagnhost.exe-9BB47FC39CB24A16A0AB0302960645BA": { "file_name": "sdiagnhost.exe", "file_path": "C:\\Windows\\system32\\sdiagnhost.exe", "hash_md5": "9BB47FC39CB24A16A0AB0302960645BA", "hash_sha1": "8963ED884F78D263A039A9A68719840412ED30AD", "hash_sha256": "50A816FE57195376AD30AEEC2EA7968936A706508E26299302F30366CC7FF3A4", "hash_sha384": "3D48D1810E0ADF70CE8DEC34A387E63A1F3AB8C83822A989D7A4F94B374A4CCFB67814537087802392B08DA048689FBE", "hash_sha512": "BC4EBE417272BFDAAF85D073C7D598C8B7DB74CF26FC220AE1AE247DF08F6D30D804D16BDE4AE12D2CDA1039F3BABF877EEB7469C6DD29CE3CC77B0382BB097B", "hash_ssdeep": "384:9NaPLsFWEjuhHKkTy8YBFMHgrQMylq1MIHGcMXgva/HRlsvfyxKil8WG7DW:bsL0W7gkzy/Wd/HPsnaKim", "hash_imp": "88C840A970A1633DCA61E1CD2D926E21", "hash_pesha1": "B0492CFE4BFE941D05A26A6C4C09E67102C3CC54", "hash_pe256": "FED938CCB061C0319F45AB611B8362AD79927BDCDB49E97188754C7FFA1F0E58", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Scripted Diagnostics Native Host", "meta_original_filename": "sdiagnhost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/50a816fe57195376ad30aeec2ea7968936a706508e26299302f30366cc7ff3a4/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\sdiagnhost.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECDB4": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\sdiagnhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "SDNDiagnosticsTask.exe-F549E1ADFABDAE71E52ACF5A7A731889": { "file_name": "SDNDiagnosticsTask.exe", "file_path": "C:\\Windows\\system32\\SDNDiagnosticsTask.exe", "hash_md5": "F549E1ADFABDAE71E52ACF5A7A731889", "hash_sha1": "64BBA578397F8664D32B7AF70DA6AFE56BFE79DE", "hash_sha256": "BCD016A12224EF58BC28D77D6E241107CE596CC29C977F7550CE4AA003898C57", "hash_sha384": "E7F56C9C861F5443F57ADA39DBA88A2619DEF3342AC727B97EC01510FC874B1C33F86B9EF90323A4ADFF41C6222A0BBD", "hash_sha512": "66B23ECA1164E954DE4DD724292D7E1A7EE89D0661D86C090DADF4E9BB7F8E6731869304E56FB0BEC5CAEF3033FCEA94126BF3BDAB9AACCA2DB3AAA24BA9E3E7", "hash_ssdeep": "3072:h/ptMDBBWODzsSEvtd5BeeoPl+Pomva0PI/xdGSlaImiK7J3PL3YMgS58YV4dXca:wBxDzsSrtT04vS95lVJM/Ci", "hash_imp": "98CD58D954674F61351E93A625644B1E", "hash_pesha1": "F8B8C096FB6D81AAB47312BC60A1FBCFE6B10692", "hash_pe256": "E8C589569C1282C2346D99E359614E6B33C9ED9E29DD8A1955AD946D573A3EE3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/bcd016a12224ef58bc28d77d6e241107ce596cc29c977f7550ce4aa003898c57/detection/", "runtime_modules": [ "C:\\Windows\\system32\\SDNDiagnosticsTask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\Cabinet.dll" ] }, "SearchFilterHost.exe-BB3FEB38673DB103CAB1634AECE1DC21": { "file_name": "SearchFilterHost.exe", "file_path": "C:\\Windows\\system32\\SearchFilterHost.exe", "hash_md5": "BB3FEB38673DB103CAB1634AECE1DC21", "hash_sha1": "C97971CCC7D89D4E2953F758C24AD1F271936AD2", "hash_sha256": "574D2D970451B89B6C646253345628AA692CF76F6A6FE4404086D20CAEB6A211", "hash_sha384": "884F816FE61BBD6E1C94DF37DE050F578C991A3D40A535D92ABCF92FEE9D35046C474BAC007D37547EEC740E94D97ADE", "hash_sha512": "E0379D6FC047F74C5ECDE2F9E4E9022B8DE7FAC62436298AFAD9E3E78A51B15EB02FFCF4CA496CC0242D44189898E04B36CE296E32A52A0D00AEB2D4B8AF615F", "hash_ssdeep": "3072:MSMHLMd+gXSCbWm2YLIl9EM/++80hwQNpmr+UrgCf9Br51ihk6kvtfGq0ev3U5WN:Mv5I5WHYIl9EM/Hpmr+BYkrkR10efUK", "hash_imp": "837968E736EE58A7F0780D1DA007BB63", "hash_pesha1": "88EC76215A5BD99470616C1607CD542B7EE34C9B", "hash_pe256": "5801CC1A41F35C82EFDC5E5DA61A16A06DBCF59EB2761D89142A702C671DE39B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Search Filter Host", "meta_original_filename": "SearchFilterHost.exe", "meta_product_name": "Windows Search", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.0.17763.831 (WinBuild.160101.0800)", "meta_product_version": "7.0.17763.831", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/574d2d970451b89b6c646253345628aa692cf76f6a6fe4404086d20caeb6a211/detection/", "runtime_modules": [ "C:\\Windows\\system32\\SearchFilterHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\TQUERY.DLL", "C:\\Windows\\system32\\cryptdll.dll", "C:\\Windows\\System32\\imm32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "SearchIndexer.exe-6D8E4B6107149B1495C44103C264235E": { "file_name": "SearchIndexer.exe", "file_path": "C:\\Windows\\system32\\SearchIndexer.exe", "hash_md5": "6D8E4B6107149B1495C44103C264235E", "hash_sha1": "CE134E47F166EF2C6E113BA424EE7C4ACFB13768", "hash_sha256": "1B31E6CB35F3AAC01E663D3BD98FA90129B5F1744AE70BF1DC3AF464F284A573", "hash_sha384": "6EAD760E0254EA109F269E6AA3C9572C00F16CC220D8566BD9C3409E6C68D2C41F4B74AD55D7129AF189EBB7E3BE7D3F", "hash_sha512": "34E0B032DDA7EED51926FE0FC6C76B2DB2C3C52CE95C514EE246F079398B06B29AE61FD69DB9AB544D267399B52D0A8D50DC86182A0704016D6BFF7E784978B4", "hash_ssdeep": "24576:zWhJZcGjnQ/V0R2BN+os7clUI2j7Xeo0h6VQ:6hJ8mR2BVsOUIG7Xeo0h6Q", "hash_imp": "33213C2BA466112DF0653CF508365950", "hash_pesha1": "47AB0A23FCB17095E6158E8669546E058478A4A0", "hash_pe256": "3DBA1D2FE5DDCB880946BD38AACD389FD7237A93B82B1A4D144235B5ABABF0FA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Search Indexer", "meta_original_filename": "SearchIndexer.exe.mui", "meta_product_name": "Windows Search", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "7.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/1b31e6cb35f3aac01e663d3bd98fa90129b5f1744ae70bf1dc3af464f284a573/detection/", "runtime_modules": [ "C:\\Windows\\system32\\SearchIndexer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\TQUERY.DLL", "C:\\Windows\\system32\\cryptdll.dll", "C:\\Windows\\system32\\MSSRCH.DLL", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\ESENT.dll" ] }, "SearchProtocolHost.exe-003B2FB715F4459920E5C0B9F8F7CF7A": { "file_name": "SearchProtocolHost.exe", "file_path": "C:\\Windows\\system32\\SearchProtocolHost.exe", "hash_md5": "003B2FB715F4459920E5C0B9F8F7CF7A", "hash_sha1": "03A250AAAE7D1F64BC3B72B787B4930B586E9946", "hash_sha256": "0C18644B7B7A04CE50620FB622B4A424766DEB31B0D8AF608AF15ED5336F122D", "hash_sha384": "570A5823B166DBE54942BB624DE9501003FDA6FF735DD9C46B32C532F1F01D7570AC2C4043AADCB03128F93D142C81EE", "hash_sha512": "E3B8C0D54E2AFFD54A85C1BD617C8EDBE84BFE021DF03F93CFFEA50CDBA05F265984503919435D97FC661A79E6E469E8225F43CFDF2295B7D64AD50D2AD16BFC", "hash_ssdeep": "6144:NDcYNngXBJzeME0TCwgmOUTa+6qevmxdjeyJSiO1R2rkR10efUK3:tcYc3k0+wgmOYa+Bek/JSikR2Qztf9", "hash_imp": "E28C03509E7F23FEA2BCD7E77FF0B52B", "hash_pesha1": "9CBE57B8A0EB1AF5B704D7B9D2D6C1F0F86F159E", "hash_pe256": "4C1C9A1E21F0AE94A9B6FE7C9D3A30A13B7F00EED6DDBEC234D6C79E2A04A11B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Search Protocol Host", "meta_original_filename": "SearchProtocolHost.exe", "meta_product_name": "Windows Search", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "7.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/0c18644b7b7a04ce50620fb622b4a424766deb31b0d8af608af15ed5336f122d/detection/" }, "SecEdit.exe-093D5982A0E3797E6B114562541A93C8": { "file_name": "SecEdit.exe", "file_path": "C:\\Windows\\system32\\SecEdit.exe", "hash_md5": "093D5982A0E3797E6B114562541A93C8", "hash_sha1": "38A6095A95E2778ED23A6D74D0066A06B7704549", "hash_sha256": "FA402723445B88A6050D5B7D003B13A7118AA32BF3558DAD1D50C6FE2AC6A16D", "hash_sha384": "12B6F655E49693F3811E172968DB6563F6C3C57DC2E102DCA17EC8A5B3FE7308FA3491634B4236626EE066935597936F", "hash_sha512": "A683AFCFDAA9A06B0F6A8D627C362EB01F2B53695BC66DE324A57D24B3B3A94E71759ADD655E17FCC5D29734485B96991F24D35C70233CA9BF217FC52D9ED2C2", "hash_ssdeep": "768:9bIQdrhdSuOu0qr1SgaNsi/KGZguJqT7/pXk:9IcddSuOCSgvsKGZgd", "hash_imp": "58A66C69176097C9B8C5C9AE4273BD6F", "hash_pesha1": "79F3EBC34CCBC7CAC61903303629626CB4ACFFA4", "hash_pe256": "69F1163456CA1161B6B72699F72043D394FA5437AABA5B8A79850AB17C966E9A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Security Configuration Editor Command Tool", "meta_original_filename": "SeCEdit", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/fa402723445b88a6050d5b7d003b13a7118aa32bf3558dad1d50c6fe2ac6a16d/detection/", "output": "\r\nThe syntax of this command is:\r\n\r\nsecedit [/configure | /analyze | /import | /export | /validate | /generaterollback]\r\n", "runtime_modules": [ "C:\\Windows\\system32\\SecEdit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SCECLI.dll" ] }, "secinit.exe-7AFB95AB0136F93059C5C2DE7D809412": { "file_name": "secinit.exe", "file_path": "C:\\Windows\\system32\\secinit.exe", "hash_md5": "7AFB95AB0136F93059C5C2DE7D809412", "hash_sha1": "8B67C04DB37E88C8017451E7DFFF3C7271F4CD22", "hash_sha256": "207A29388719600501B533360575A1D44E46DB6D0E670F24B12E36A7EC9C4221", "hash_sha384": "EB9D6CB151908116188836FE7E1AF6FFB323CFA11D539785CECB75D36F5E28773960D0549778EED2A3B58EE5B3350BD0", "hash_sha512": "CA209479B49F121179919FE9CC04C3681199EADEF055ECAE7F4CA6C31FC01C544B889F4584E89703CCBAF854D3B3DC491B47AD38FD5E85A95DAFC2F55F90F163", "hash_ssdeep": "192:Ja2M7hPBuLkrkkTkSlUpku2o9KN1xfRKGPPCTmtW8vQzRiW:Ja22ZBxlxlOku2AO5KWxtW8vQzRiW", "hash_imp": "26553A8E11C5CC5CD0F898A06C1EEBEA", "hash_pesha1": "37B53348FA4F09C9C3077620E2F0154B2D52B4F6", "hash_pe256": "65A2E882B3D405B6186DCFF41BF316C2DE30AD1326EEB210B0359DBAAA188888", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Security Init", "meta_original_filename": "secinit", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/207a29388719600501b533360575a1d44e46db6d0e670f24b12e36a7ec9c4221/detection/" }, "securekernel.exe-0A4E56575776EBDB0E69885AFBA8B1E0": { "file_name": "securekernel.exe", "file_path": "C:\\Windows\\system32\\securekernel.exe", "hash_md5": "0A4E56575776EBDB0E69885AFBA8B1E0", "hash_sha1": "B32D880B77BC2F96D16A871A9F5199B5603A236D", "hash_sha256": "B24A313E33CA411D6510DE7A6101C594D10EE6922A58A9DC59328429E2E86007", "hash_sha384": "78D91CB0CE6B106579FE0A1897642D07DAB52C47E85BB7E12C2E9796A27AB8F72A3B87943A514265CF6F4D8E6417817A", "hash_sha512": "169D2AAAE31B89EC2B43C423AF87D036FE8C99D819B0AE7CFD76046EF9B5E46D920FA6153DB7BFF07D03227657EF29C3863C3BC8F530B5ACC0562BD9E6E86E9D", "hash_ssdeep": "12288:sLs48BBpPqv93e+z6DCyPDymGKj4nHqvbMCbts4m/r4D22TwF7u+crattttpNyu2:2WBBYv93e+z6DCyPDymGdibMCbts4U4t", "hash_imp": "DB0403C15A18773F1CBC7FF2F808026D", "hash_pesha1": "CC124AFB1D72678D5720672B4ACCD9027C96C20C", "hash_pe256": "1C36F4EC0327FAF46ADEBBFD52F16A7108E5C0633D00DB5E39D7E0128FA142B9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NT Secure Kernel", "meta_original_filename": "securekernel.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "SecurityHealthService.exe-0C29D470959F1AE4AC208AA2D2BA3E87": { "file_name": "SecurityHealthService.exe", "file_path": "C:\\Windows\\system32\\SecurityHealthService.exe", "hash_md5": "0C29D470959F1AE4AC208AA2D2BA3E87", "hash_sha1": "AE4A8E321A4CA28FBED8AE5719E00478CE797F51", "hash_sha256": "61B1BCA1EF2073482C5A14FD9F5DB31FE54AAD61FFA8DA2A708BA974912C037C", "hash_sha384": "ED7322391330F25A3FEB471E23613A8DEDA607E7C5A918907A04523011928657377B1A7D069B65191767C672AF3C874E", "hash_sha512": "B480FD0A84B997BFA8C9A0BED858562B94AEFB1020255DE6BEFDD40C2674716C7463C386C62DF8FA18FFDCAEB69024653FF35220D950DA2F7CB95BCBA9F333BC", "hash_ssdeep": "12288:37b7ap/kykn6zszmeXJr7jZn4JholqKYLzERYVSOreV1uEL8/ah:37fap8yaiiZ5lIhowKYLzIYVQV1uEL8o", "hash_imp": "F5BD79DC95E0303BDD85756328F16293", "hash_pesha1": "1BB8ED7A045CDB13ED7295DD202224D22E083103", "hash_pe256": "B31738A3887B84E2A1D6DE1CDC45EB81E4C738858BEE2E64814FD0C61345A31B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Security Health Service", "meta_original_filename": "SecurityHealthService.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.1807.16384 (WinBuild.160101.0800)", "meta_product_version": "4.18.1807.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/61b1bca1ef2073482c5a14fd9f5db31fe54aad61ffa8da2a708ba974912c037c/detection/", "output": "Unknown switch.\r\n" }, "SecurityHealthSystray.exe-09F3F2298DDA6EBB57B12C530D35C52C": { "file_name": "SecurityHealthSystray.exe", "file_path": "C:\\Windows\\system32\\SecurityHealthSystray.exe", "hash_md5": "09F3F2298DDA6EBB57B12C530D35C52C", "hash_sha1": "D7FC50DC0A08C9EC089E428A03606EE4A2E8C759", "hash_sha256": "48F852164EF4747FCDDFF463034CAD33167E341D241536B122AE74FC8841C941", "hash_sha384": "6B0AA524C96521577EA0CC227EAF03D3F900F5E3E83AC9F0E1D13A73D508D0EAD5D3D414DF16464CAD5963B2E8201CBE", "hash_sha512": "D1491EA60863C8EE7C7961966E8332F0E26160BEC19731E7108B4CC3594BDA3E1C6102194765B80DF6F110938BD6BCCE91393DCCB16D62E986C389E37C243C81", "hash_ssdeep": "768:Funf3GoSnuAWTAuU+PSLw18j3+igYAuIiSl5Fe3kkyGQyq3q90:ItSnyTAuk818aiSiSl5Fe3kk9Qyq3qq", "hash_imp": "44315EF1FEB6193B3AB5492033CEFAAE", "hash_pesha1": "258864A6871EEA36380479F2885C0B1B327DC455", "hash_pe256": "4A942D68E3E6456C8D940B868E8512B01FA753CD662B29F2AFB3ADE88E722092", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Security notification icon", "meta_original_filename": "SecurityHealthSystray.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/48f852164ef4747fcddff463034cad33167e341d241536b122ae74fc8841c941/detection/", "runtime_modules": [ "C:\\Windows\\system32\\SecurityHealthSystray.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "SensorDataService.exe-E77A116240C022634504C54ACA876E62": { "file_name": "SensorDataService.exe", "file_path": "C:\\Windows\\system32\\SensorDataService.exe", "hash_md5": "E77A116240C022634504C54ACA876E62", "hash_sha1": "F987BDB80EC55E443ED3EC01465D66A74C4FB69F", "hash_sha256": "071E545DAAE61B9ADED9D889BF4E8D953D825C1203793F9B4C09E02550544216", "hash_sha384": "6222D39597B29FEA0FC58CA130D8590B81F2CBD46C760F57B346A409BC4264ADABB4C10418E408D2978304D0F7B81AED", "hash_sha512": "C3B6B2022AF9B0DFFB8F5D861567B140206CD15F79D14EE28AB14B64DD31705C3782CD3581CAA04E3453B783964213F4F12A5DBB923D3030EA84085DA1013BFB", "hash_ssdeep": "24576:kdTcl1a/sOMelS7mAzOMGA8yEQzlj9MO3Yqo9qq:kdQl1ksKS7FqMhZEQzlj9MOI", "hash_imp": "BF8CA776FCD758066A7B45AADC6B7F37", "hash_pesha1": "65545D7AD617BC0DBED13F9507EF2E2F0AABA9C8", "hash_pe256": "3C8E8BFF93BD1A9B8CD2293C42DBAD0467367FEF69C0766535CB211FDF2CB069", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Sensor Data Service", "meta_original_filename": "SensorDataService.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/071e545daae61b9aded9d889bf4e8d953d825c1203793f9b4c09e02550544216/detection/", "runtime_modules": [ "C:\\Windows\\system32\\SensorDataService.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\MFPlat.dll" ] }, "ServerManager.exe-65ADE21DC82C01972891285581D85866": { "file_name": "ServerManager.exe", "file_path": "C:\\Windows\\system32\\ServerManager.exe", "hash_md5": "65ADE21DC82C01972891285581D85866", "hash_sha1": "D6E44F1F5D9DF6EBEEDB3D986EA057D42D48EB83", "hash_sha256": "57FB008FAEB05DD34FC1C224CE456B38CED950243FBAC7F7CB348DF68F990EBE", "hash_sha384": "80D3F5E653E25C67C3F55F91EE339E9FE26854360DD48C74A280552D3522BAF53D4FF8B2CC40F77357BEACDAE657BC3C", "hash_sha512": "AA9D0C7F33F64EACE2E0350065BEEE138457E73A263B145D98E1BAEA0A8EE48AABB27C057C6582A7D6A2CC8FAAA59ED2503F02BA4ECC662FD937048656BE809B", "hash_ssdeep": "3072:2X/CdVBluX1B/7a5jLf8fyOcR1HnPYctZLF9nM6zQf:2vCdrElhwfzAGR9M", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "5F43FC13EC92E5599B4A8138030F1E790ED59D2E", "hash_pe256": "75AEAF515FDD94240EDE99FA86D1CEC0D3F154835C816E26B4FE44F064424FA7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Server Manager", "meta_original_filename": "servermanager.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.168 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.168", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/57fb008faeb05dd34fc1c224ce456b38ced950243fbac7f7cb348df68f990ebe/detection/", "children": "Configure-SMRemoting.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4240": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\ServerManagerMultiMachine": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\2\\BaseNamedObjects\\UrlZonesSM_Administrator": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1090": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(RWD) C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools": "File", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\1090HWNDInterface:f04ae": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\msctfui.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\ServerManager.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\5543cca0df435801e2303ff46a482ed5\\mscorlib.ni.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\CRYPTBASE.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\6885802f40fd803e49150d8a2b43a09b\\System.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Core\\f29b1120627489754c4b8dd317bbe950\\System.Core.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\WindowsBase\\7766b716f453669f6453022ce957c6ad\\WindowsBase.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\PresentationCore\\8fad18d47be73b98845c53d0e6d3b964\\PresentationCore.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Presentatio5ae0f00f#\\d1101640429a2c3d8c6c257103ad22c1\\PresentationFramework.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Xaml\\12c01954752c224882de75b4418c8382\\System.Xaml.ni.dll", "C:\\Windows\\SYSTEM32\\dwrite.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\WPF\\wpfgfx_v0400.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\MSVCP120_CLR0400.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\WPF\\PresentationNative_v0400.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Wf493a5fb#\\0c9a1da5f56dfaa4fb36197766a8741f\\Microsoft.Windows.ServerManager.Common.ni.dll", "C:\\Windows\\SYSTEM32\\WindowsCodecs.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Configuration\\875dc3cfd53efc9f9a5c63016cd239d7\\System.Configuration.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Xml\\488d073901c2c0fb8ccbcbe182b6b160\\System.Xml.ni.dll", "C:\\Windows\\System32\\shell32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Meefd589e#\\56fe9c165d19a05f8b992578906dd4d4\\Microsoft.Management.UI.ni.dll", "C:\\Windows\\system32\\urlmon.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Presentatioaec034ca#\\fc91c5553de4f5b4c206769962382b62\\PresentationFramework.Aero2.ni.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\d3d9.dll", "C:\\Windows\\system32\\d3d10warp.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\WindowsForm0b574481#\\e2c08b0632621691500c621ae2daec64\\WindowsFormsIntegration.ni.dll", "C:\\Windows\\SYSTEM32\\wtsapi32.dll", "C:\\Windows\\SYSTEM32\\WINSTA.dll", "C:\\Windows\\system32\\dataexchange.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\system32\\dcomp.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\system32\\twinapi.appcore.dll", "C:\\Windows\\system32\\RMCLIENT.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Presentatio1c9175f8#\\5aed9b86d6cdfe40010a07e62084f773\\PresentationFramework.Aero.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Presentatio49d6fefe#\\2765d5dfb05e889760491cc0e1f68a4e\\PresentationFramework-SystemXml.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Presentatio84a6349c#\\3f2a862342191027edcb96c316333f89\\PresentationFramework-SystemCore.ni.dll", "C:\\Windows\\system32\\msctfui.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\UIAutomationTypes\\f898d852ca0a3bf2329018f1997c623a\\UIAutomationTypes.ni.dll", "C:\\Windows\\SYSTEM32\\UIAutomationCore.dll", "C:\\Windows\\SYSTEM32\\Bcp47Langs.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Drawing\\6c6bbae87386b6a33957366eae0e4470\\System.Drawing.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Windows.Forms\\23c1e20aa87eccaf2c33ba9f47d2319e\\System.Windows.Forms.ni.dll", "C:\\Windows\\system32\\mscms.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\ColorAdapterClient.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\bb0ca52db926eaec4a94a8b656f61a94\\System.Management.Automation.ni.dll" ], "runtime_window_title": "Server Manager" }, "ServerManagerLauncher.exe-984C9F7202A43577C2A3D52A1300FFE7": { "file_name": "ServerManagerLauncher.exe", "file_path": "C:\\Windows\\system32\\ServerManagerLauncher.exe", "hash_md5": "984C9F7202A43577C2A3D52A1300FFE7", "hash_sha1": "D315D99134C96D727AF131D451029211A3B3F5F7", "hash_sha256": "8D583C54E942EE079E6D2F59A5914D1A5C5194385ED42C717648A3106CC0F20B", "hash_sha384": "6AD747E97E59D97CF0BC814019D9A6680EAD4F3757108CEA2AE54C3FFF2D6B35A54E38934090BDF24B60783E5F208D89", "hash_sha512": "A84FA0F6EC5AAE69B34FA7B585AB8CA9DC70D46ECBD3D383286E4CE5CC2A8306F059911CF0E33D5FF68F1B51EE626251EC7989D35BDFC96AA9553E64097C241F", "hash_ssdeep": "1536:WJ41FMOgdPNvNAa6iZq0Sv7fWDTkhVzvOmvOj8lOo+vi6Uf:WS1CdNvaXiZNSv7fWDTaVGmvOj8co+Q", "hash_imp": "0733094C6B29D3B7ADFAE066B06EF5AF", "hash_pesha1": "C618B2EDB7865534FE1C4BCE9E2BD56D79DACB9E", "hash_pe256": "8BD91D2E0BA977B16DC21FB4FFFF885D2F30CA15A9EDD3AD8BAF93BB36F638FB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Server Manager Launcher", "meta_original_filename": "ServerManagerLauncher.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/8d583c54e942ee079e6d2f59a5914d1a5c5194385ed42c717648a3106cc0f20b/detection/", "runtime_modules": [ "C:\\Windows\\system32\\ServerManagerLauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll" ] }, "services.exe-DB896369FB58241ADF28515E3765C514": { "file_name": "services.exe", "file_path": "C:\\Windows\\system32\\services.exe", "hash_md5": "DB896369FB58241ADF28515E3765C514", "hash_sha1": "617A0A0BAAB180541DB739C4A6851D784943C317", "hash_sha256": "A2E369DF26C88015FE1F97C7542D6023B5B1E4830C25F94819507EE5BCB1DFCC", "hash_sha384": "E725F9E26419C4708AFEA2350A3D3EDF0B968DAF1FDAE6F12822BD08F6305E74779A3B06688392BF31CB6A1182A69D7D", "hash_sha512": "C47F469E3ED2D358C51E8B804A6E1DB37C6B33543919BEE938279902D01D44F171E132C29D2A36EC3B4369E1441F597993E727CE2F2D087A4AB384ACE345C959", "hash_ssdeep": "12288:EBcEZkiKFRQVcO09OEIXXfHx0q6BgQP/pA9cY2l1JlmruvjXT2C57p3XewSH9uLi:OcAkiKFscODvnfH+OQXyaY2lPT6gFXen", "hash_imp": "7D2820FC8CAF521DC2058168B480D204", "hash_pesha1": "65C5931468115B27320CE4297D64CAA8AC8F706B", "hash_pe256": "A03CD7126C83845A879E153B45DE6553E2160BE1E57D4BF32B416608FC99104F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Services and Controller app", "meta_original_filename": "services.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a2e369df26c88015fe1f97c7542d6023b5b1e4830c25f94819507ee5bcb1dfcc/detection/" }, "sessionmsg.exe-50E5850CC18C2F6FBB7A6CBD3D819E43": { "file_name": "sessionmsg.exe", "file_path": "C:\\Windows\\system32\\sessionmsg.exe", "hash_md5": "50E5850CC18C2F6FBB7A6CBD3D819E43", "hash_sha1": "1659CDA940EB63003088D982F1E898BF886DFBDE", "hash_sha256": "20247E34C5139FA1EF689C134148B2373BE2D1A1E1A568950D9641826F6A1D4E", "hash_sha384": "0400186A72177496B2B8943DE498DA9998736212EA9110419286E31813A6E764D4B963E32E78058A221059435E853C01", "hash_sha512": "5F06E3F6973BE8B67C9D9E7D161DF60520FDBA8CA84855BB5C94F825CBD5C911C5FADCC46C9D856CF02B02287ED7F2819DD104CDA7D0C9D0B7B182BCB4AB9E9D", "hash_ssdeep": "1536:mD7n7LmmQIC/F/G6n15yaIBGUjHpZMzvZJ86pPX:yHmXtw6yBTTpZMLQSP", "hash_imp": "235F1B1EFA9D4B3F43DCE3357ADECBFA", "hash_pesha1": "3CD4080D8255526AC5D2311FEF279249D83457AF", "hash_pe256": "98623AAC73B52E226EBBE371053B945FB348C7D82CC7F9729B2B976AAA23B256", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Remote Desktop Services Session Message Server", "meta_original_filename": "SessionMsg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/20247e34c5139fa1ef689c134148b2373be2d1a1e1a568950d9641826f6a1d4e/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\sessionmsg.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECDA4": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\sessionmsg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "sethc.exe-062940BA26F1204EBD5F62DF37D0C3A7": { "file_name": "sethc.exe", "file_path": "C:\\Windows\\system32\\sethc.exe", "hash_md5": "062940BA26F1204EBD5F62DF37D0C3A7", "hash_sha1": "24FF66352198774F912DC27B7F3B310DAC311EC8", "hash_sha256": "52A9E16B777D1FFBBA54A686F9D77AE0AA622EC2FD7A501CEA398B7A53E64793", "hash_sha384": "F7594E16B8C4E083E2A1965C545206737ED35F392D26D2FE21D5D33CD879134A0E1E2427DA049B6383166280C164B0E5", "hash_sha512": "B710FD81AF5974B7FA7F075DB64D9CD63F5043C3A27BF53AAD3BD13A53A40E7EDDF3CA51941662F7288FE138D01F0EB926087052A28B0477FB3683D6D225E56E", "hash_ssdeep": "6144:U4AA83sWjfA/unAlGr66uFz2LJGRg4kLNnei36cw:RAAwE/ucFCdUc", "hash_imp": "22FF4F8C831128EFE52978F175ADCEC0", "hash_pesha1": "27AE2FD4296F9667AD93AFD92C5A356B5E5DF61E", "hash_pe256": "6F009E2AD41F70DA5705D91C942C43CE8525AA1ADF19C201565E56387C05A448", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Accessibility shortcut keys", "meta_original_filename": "sethc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/52a9e16b777d1ffbba54a686f9d77ae0aa622ec2fd7a501cea398b7a53e64793/detection/" }, "setres.exe-4D067428EAD2B01FAF1010FBC802CE48": { "file_name": "setres.exe", "file_path": "C:\\Windows\\system32\\setres.exe", "hash_md5": "4D067428EAD2B01FAF1010FBC802CE48", "hash_sha1": "8CB974CF463434544D19BB41ADC6A7437FBB8B0A", "hash_sha256": "5465CA0A2666C2B403359B4238FE649E44B9C3E0C7CC696D872525E018121651", "hash_sha384": "D404D19A55CBBE9617811315B1A5EB81F2ED956B16B486A0C93A6B744B3044D6A707EED7331D615A5B50F535173659CF", "hash_sha512": "15F6B9B6C5B9DD1E45C1EB3951E3653980806D9B5503403DE26CADBF06AAEBCE987AD57552A290D4F1D451CD1453ABA15DEA355C4E4DCD95BB6E6A3438C197A1", "hash_ssdeep": "192:RvpNNn15rEeOIjj7q+TTL1H13DaAensTtK6nGduUIaR+IwW5zW:DNJ1Oe5jn3Tn1V35eiK6nTTaoZW5zW", "hash_imp": "6CE3AB4FE62639CD35A70C601B246411", "hash_pesha1": "5C0FD4484F8A8B9D489AAD1B60D62F27EDEA4DFD", "hash_pe256": "7D532043D8BE60C09EA881CC367DC91A4ED55600FBFF9516B9C6330F98139233", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Configures display settings.", "meta_original_filename": "setres.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/5465ca0a2666c2b403359b4238fe649e44b9c3e0c7cc696d872525e018121651/detection/", "output": "Error: \"help\" is not a valid argument.\r\n\r\nsetres [-w # -h #] [-f] [-i]\r\n\r\nDescription:\r\n This tool configures the display settings.\r\n\r\n-w <width> Specify the screen width in pixels. \r\r\n-h <height> Specify the screen height in pixels. \r\r\n-f Do not ask for confirmation upon resolution change.\r\r\n-i Display the current screen resolution.\r\r\n" }, "setspn.exe-706FBA8F9F67D479A792860289853C1B": { "file_name": "setspn.exe", "file_path": "C:\\Windows\\system32\\setspn.exe", "hash_md5": "706FBA8F9F67D479A792860289853C1B", "hash_sha1": "87C43AD8514AF87F069391F96630D4439F537B2B", "hash_sha256": "CF095DBD04EBAB55B598E0F27C88304571EDC70F41156567C1700B70CD5E728B", "hash_sha384": "C495F6282D75A4E75C2BC6C39FA09A4DD0BB2D4BB17AD721C0803D130C3A619C246DC8488BF9D72F98D265E9E4B25D92", "hash_sha512": "2DF637F1A0AC31F66330F4A93EB6C2957CA4F4D501DF4718FAA6982208B794A8D34BB7D4890561D07A11B26677DCAC0B5A4E88EF646CEA83EF6820983E9B6CBC", "hash_ssdeep": "384:5Q/B9iDavPAwpJt45OYFNIPPvgwYqzzYrdz24w8W4fM3n/NxzCqzv7YyMsUrlYW2:5ZawDOEagwFzYrdi4ZfUvDOq3Yhrla", "hash_imp": "1393340AAB23F97BCF1E08682E940E45", "hash_pesha1": "46A4BF73D22A0A0068061BFC471137D153D5FAF6", "hash_pe256": "63E5821296D8A1EBAF2124DC0E74C70784E580BB51C1DB64354886F73937C434", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query or reset the computer's SPN attribute", "meta_original_filename": "setspn.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/cf095dbd04ebab55b598e0f27c88304571edc70f41156567c1700b70cd5e728b/detection/", "output": "Usage: C:\\Windows\\system32\\setspn.exe [modifiers switch] [accountname] \r\n Where \"accountname\" can be the name or domain\\name\r\n of the target computer or user account\r\n\r\n Edit Mode Switches:\r\n -R = reset HOST ServicePrincipalName\r\n Usage: setspn -R accountname\r\n -S = add arbitrary SPN after verifying no duplicates exist\r\n Usage: setspn -S SPN accountname\r\n -D = delete arbitrary SPN\r\n Usage: setspn -D SPN accountname\r\n -L = list SPNs registered to target account\r\n Usage: setspn [-L] accountname \r\n\r\n Edit Mode Modifiers:\r\n -C = specify that accountname is a computer account\r\n -U = specify that accountname is a user account\r\n \r\n Note: -C and -U are exclusive. If neither is specified, the tool\r\n will interpret accountname as a computer name if such a computer\r\n exists, and a user name if it does not.\r\n\r\n Query Mode Switches:\r\n -Q = query for existence of SPN\r\n Usage: setspn -Q SPN \r\n -X = search for duplicate SPNs\r\n Usage: setspn -X \r\n\r\n Note: searching for duplicates, especially forestwide, can take\r\n a long period of time and a large amount of memory. -Q will execute\r\n on each target domain/forest. -X will return duplicates that exist\r\n across all targets. SPNs are not required to be unique across forests,\r\n but duplicates can cause authentication issues when authenticating\r\n cross-forest.\r\n\r\n Query Mode Modifiers:\r\n -P = suppresses progress to the console and can be used when redirecting\r\n output to a file or when used in an unattended script. There will be no\r\n output until the command is complete.\r\n -F = perform queries at the forest, rather than domain level\r\n -T = perform query on the speicified domain or forest (when -F is also used)\r\n Usage: setspn -T domain (switches and other parameters)\r\n \"\" or * can be used to indicate the current domain or forest.\r\n\r\n Note: these modifiers can be used with the -S switch in order to specify\r\n where the check for duplicates should be performed before adding the SPN.\r\n Note: -T can be specified multiple times.\r\n\r\nExamples: \r\nsetspn -R daserver1 \r\n It will register SPN \"HOST/daserver1\" and \"HOST/{DNS of daserver1}\" \r\nsetspn -S http/daserver daserver1 \r\n It will register SPN \"http/daserver\" for computer \"daserver1\" \r\n if no such SPN exists in the domain\r\nsetspn -D http/daserver daserver1 \r\n It will delete SPN \"http/daserver\" for computer \"daserver1\" \r\nsetspn -F -S http/daserver daserver1 \r\n It will register SPN \"http/daserver\" for computer \"daserver1\"\r\n if no such SPN exists in the forest\r\nsetspn -U -S http/daserver dauser \r\n It will register SPN \"http/daserver\" for user account \"dauser\" \r\n if no such SPN exists in the domain\r\nsetspn -T * -T bar -X\r\n It will report all duplicate registration of SPNs in this domain and bar\r\nsetspn -T bar -F -Q */daserver\r\n It will find all SPNs of the form */daserver registered in the forest to\r\n which bar belongs\r\n", "error": "FindDomainForAccount: Call to DsGetDcNameWithAccountW failed with return value 0x0000054B\r\nCould not find account help\r\n", "runtime_modules": [ "C:\\Windows\\system32\\setspn.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\logoncli.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\NTDSAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "SettingSyncHost.exe-06393D54087A796B8C2FF4B63936AFC3": { "file_name": "SettingSyncHost.exe", "file_path": "C:\\Windows\\system32\\SettingSyncHost.exe", "hash_md5": "06393D54087A796B8C2FF4B63936AFC3", "hash_sha1": "BA333CA74945F6A694E52F27C5132CDE8384787D", "hash_sha256": "C6F310EE401EFFB174271BB44D3CA76704C186E76995498D14C5C9B8040BAD04", "hash_sha384": "662AB025C0EF2215EBBFD6BEDC26D38958FFB456CE9775D4B79AEB5C673A1528A4A5F18B0D89042F3B81450B3893D7AF", "hash_sha512": "8BAADA6B0A375848184852F9F3C3907794CBB116EC0BCFDAE5EA7E7FE907F1E3BC19C1B8B846C6DB29C4EF9733747BD0A23ACD4761B3C5F41293CE6CB813AC7C", "hash_ssdeep": "24576:Pdyu/PtZBrzXj92+tVAZRYC0H4fXJq4w0Tf9oM:AWZBvj9viZjo4fZq6Tf9o", "hash_imp": "340A6EC50943D4A1A0A0FF2FE4B8B939", "hash_pesha1": "00F9C6ED1A8C3763F6E7F052F67E9269F9C2A8C5", "hash_pe256": "9A47BCE1F6D071D0AEC3F2FD06BD87CA5FEF6F8C26D757FAC23A689FBC9489A0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Setting Synchronization", "meta_original_filename": "SettingSyncHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/c6f310ee401effb174271bb44d3ca76704c186e76995498d14c5c9b8040bad04/detection/", "runtime_modules": [ "C:\\Windows\\system32\\SettingSyncHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\profapi.dll" ] }, "setupcl.exe-5B63937486DF0F27B8550A3F526F4B04": { "file_name": "setupcl.exe", "file_path": "C:\\Windows\\system32\\setupcl.exe", "hash_md5": "5B63937486DF0F27B8550A3F526F4B04", "hash_sha1": "29636C92D8911FE04FA1569B6D0725FE364D1611", "hash_sha256": "319F6B8916B14029F541813354850D9F5526028DE35A44C873FF4A3F8278DE35", "hash_sha384": "2507060296902F502A79A9DBDE9F9ECAEC1CC0EF96C55EF3DCC4BC361D9902175519C15E1EF129DC337510CB17ED9BC4", "hash_sha512": "A10330A7F004857ED2AF11B6D85A16172F3ABE9C960D394758A1CDBA49ECA5D1849DF37DA13E00D104DF20243EB8CB66E9B0934EF4358F371AEF4823E9800ADE", "hash_ssdeep": "3072:cRwbBYR6ZnwBeKc+kslNZgsTlmg/v/QZ/TLTdaZ2XKC3AuQp/:c2BYRSwB93DaMQZrg", "hash_imp": "6E8B9984C3A892446C593BDEB012E570", "hash_pesha1": "9228279FF710ABF68158C7431D95C2F697C3A936", "hash_pe256": "119A6BB9064526CA031471F500F27345AD23F4076258144ECC0093217FCF173E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Clone Tool", "meta_original_filename": "Setupcl.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/319f6b8916b14029f541813354850d9f5526028de35a44c873ff4a3f8278de35/detection/" }, "setupugc.exe-E0FBEF60EDFF9797D3AA08149726220E": { "file_name": "setupugc.exe", "file_path": "C:\\Windows\\system32\\setupugc.exe", "hash_md5": "E0FBEF60EDFF9797D3AA08149726220E", "hash_sha1": "6275684913DBF06AC810C1826B10A2602A2A5BD4", "hash_sha256": "0C20322A2009E5D986E31483811218B8AB8A8E23FA87A61E8F9126236B7A2D18", "hash_sha384": "2FEAA6546F8BCA2A83D55724EDA27357A12647EF962CA49B98D89F7CB9ABA0ABEB95EBD67879759F07262F2CEFE7687E", "hash_sha512": "658FAD39020CFCBAD7E971CA68ACCE1A756783919D92FA9CC9F4FD1E417B35D66EA3F8E2F6A97D5086DEC81ECFF49011E21E312B6E43636415F1B76FCF1F59C6", "hash_ssdeep": "1536:a6Xi1P+nDNxiCYvL3cVStJ1NeFwqmXXoFPJvxcbihsPk8bmQQFvbuH9olRny:a6X5DNucVStJcnndJ5UPkAj2vqdcny", "hash_imp": "CA52351826C256E30C776EBA867FF630", "hash_pesha1": "F92A6CEAF344C25F46F90A4C35D4EC415619A469", "hash_pe256": "A595E74EA4DB903A776402F79CB344B22AFD0E0730DED5C6C2E4C217B17224A6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Setup Unattend Generic Command Processor", "meta_original_filename": "SETUPUGC.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "1/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/0c20322a2009e5d986e31483811218b8ab8a8e23fa87a61e8f9126236b7a2d18/detection/", "runtime_modules": [ "C:\\Windows\\system32\\setupugc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\WDSCORE.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\system32\\dbgcore.DLL" ] }, "setx.exe-252BD1EAF7F8119C671D287E3A32F353": { "file_name": "setx.exe", "file_path": "C:\\Windows\\system32\\setx.exe", "hash_md5": "252BD1EAF7F8119C671D287E3A32F353", "hash_sha1": "AF923A340FFF4FE46029C54F753CBF45512CE1EC", "hash_sha256": "4DF07BC2F74879A6F190922CEDAFB9652F6488DE0084FE91C6B62E62955A3A0A", "hash_sha384": "3DB6159930790F1D32ED90976C6535371E3F382FEC13C5E93B147229894524FD381B099F99F4991994D0B148ACE057DA", "hash_sha512": "AEA8E61FFE8F1CF2D3F94C37F8F6FBEA8078EDC7574D05751B788EC7204D590C1872CCE10796F5432D7B7E53EC0CCBBC95AAC51737AC0080D344282940416165", "hash_ssdeep": "1536:YgQNdI+cPV6D8KBQTWrY/EKWHWNa1X8R:VKViaQTWOWWNa1Xs", "hash_imp": "5D33CC16B4BC3AC1E5495AE857B9B8AB", "hash_pesha1": "9B1286CD25FC8D8D68FB21B1B43D343022BBAE96", "hash_pe256": "A74584EFBE23E2E9E8682B6FD4DD914C4439B6223454348BB62587C1909DD9CE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Setx - Sets environment variables", "meta_original_filename": "setx.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/4df07bc2f74879a6f190922cedafb9652f6488de0084fe91c6b62e62955a3a0a/detection/", "output": "\r\nSetX has three ways of working: \r\n\r\nSyntax 1:\r\n SETX [/S system [/U [domain\\]user [/P [password]]]] var value [/M]\r\n\r\nSyntax 2:\r\n SETX [/S system [/U [domain\\]user [/P [password]]]] var /K regpath [/M]\r\n\r\nSyntax 3:\r\n SETX [/S system [/U [domain\\]user [/P [password]]]]\r\n /F file {var {/A x,y | /R x,y string}[/M] | /X} [/D delimiters]\r\n\r\nDescription:\r\n Creates or modifies environment variables in the user or system\r\n environment. Can set variables based on arguments, regkeys or\r\n file input.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n var Specifies the environment variable to set.\r\n\r\n value Specifies a value to be assigned to the \r\n environment variable.\r\n\r\n /K regpath Specifies that the variable is set based\r\n on information from a registry key.\r\n Path should be specified in the format of\r\n hive\\key\\...\\value. For example,\r\n HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\\r\n Control\\TimeZoneInformation\\StandardName.\r\n\r\n /F file Specifies the filename of the text file\r\n to use.\r\n\r\n /A x,y Specifies absolute file coordinates\r\n (line X, item Y) as parameters to search \r\n within the file.\r\n\r\n /R x,y string Specifies relative file coordinates with\r\n respect to \"string\" as the search parameters.\r\n\r\n /M Specifies that the variable should be set in\r\n the system wide (HKEY_LOCAL_MACHINE)\r\n environment. The default is to set the\r\n variable under the HKEY_CURRENT_USER \r\n environment.\r\n\r\n /X Displays file contents with x,y coordinates.\r\n\r\n /D delimiters Specifies additional delimiters such as \",\"\r\n or \"\\\". The built-in delimiters are space,\r\n tab, carriage return, and linefeed. Any \r\n ASCII character can be used as an additional\r\n delimiter. The maximum number of delimiters,\r\n including the built-in delimiters, is 15.\r\n\r\n /? Displays this help message.\r\n\r\nNOTE: 1) SETX writes variables to the master environment in the registry.\r\n\r\n 2) On a local system, variables created or modified by this tool\r\n will be available in future command windows but not in the\r\n current CMD.exe command window.\r\n\r\n 3) On a remote system, variables created or modified by this tool\r\n will be available at the next logon session.\r\n\r\n 4) The valid Registry Key data types are REG_DWORD, REG_EXPAND_SZ,\r\n REG_SZ, REG_MULTI_SZ.\r\n\r\n 5) Supported hives: HKEY_LOCAL_MACHINE (HKLM),\r\n HKEY_CURRENT_USER (HKCU).\r\n\r\n 6) Delimiters are case sensitive.\r\n\r\n 7) REG_DWORD values are extracted from the registry in decimal \r\n format.\r\n\r\nExamples:\r\n SETX MACHINE COMPAQ \r\n SETX MACHINE \"COMPAQ COMPUTER\" /M\r\n SETX MYPATH \"%PATH%\"\r\n SETX MYPATH ~PATH~\r\n SETX /S system /U user /P password MACHINE COMPAQ \r\n SETX /S system /U user /P password MYPATH ^%PATH^% \r\n SETX TZONE /K HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\\r\n Control\\TimeZoneInformation\\StandardName\r\n SETX BUILD /K \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\r\n NT\\CurrentVersion\\CurrentBuildNumber\" /M\r\n SETX /S system /U user /P password TZONE /K HKEY_LOCAL_MACHINE\\\r\n System\\CurrentControlSet\\Control\\TimeZoneInformation\\\r\n StandardName\r\n SETX /S system /U user /P password BUILD /K \r\n \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\\r\n CurrentVersion\\CurrentBuildNumber\" /M\r\n SETX /F ipconfig.out /X \r\n SETX IPADDR /F ipconfig.out /A 5,11 \r\n SETX OCTET1 /F ipconfig.out /A 5,3 /D \"#$*.\" \r\n SETX IPGATEWAY /F ipconfig.out /R 0,7 Gateway\r\n SETX /S system /U user /P password /F c:\\ipconfig.out /X\r\n", "runtime_modules": [ "C:\\Windows\\system32\\setx.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\SspiCli.dll" ], "error": "ERROR: Invalid syntax.\r\nType \"SETX /?\" for usage.\r\n" }, "sfc.exe-8DEA2F87316B5DCF4A6776318C308EB7": { "file_name": "sfc.exe", "file_path": "C:\\Windows\\system32\\sfc.exe", "hash_md5": "8DEA2F87316B5DCF4A6776318C308EB7", "hash_sha1": "B351728CAE37E6418BD8EC5FB03AD541520F1825", "hash_sha256": "BAF13CE3859FC727B767818B27262D549519870E6CCA5E960EEA266EB90E99C9", "hash_sha384": "E9D6932430F1AED2E85A7A7D1651B9BF3BC0DB28E01087858AEC27ABD2F59F6C9D2590AD99551E90585E439F5F41FFB9", "hash_sha512": "CE6669815C28D97E8D1C1911F07D6B23938A67D2FF038D7D32C1C98D379FC2F4832449DBFD61AFADEE121AACC82B7C7AE775CA519CBEF3FD22EF0F80941AF28D", "hash_ssdeep": "768:EIWuwKxUjiD7KCi3HsfVRzll5RQ9aHLedvYw9rD6zhiaSkPpzKYokcHG56Zk:BwCECVJ5C9ar49QiaRVKTHGEZk", "hash_imp": "137C3B2894C7A641569E3A7B636778D4", "hash_pesha1": "9889A749413D3154181970D76CE3918F21735B88", "hash_pe256": "92854D957813B63C542A5D2EE21ED397AD623C99F8DC156EC256FBCEDA0C8FEA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Integrity Check and Repair", "meta_original_filename": "sfc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/baf13ce3859fc727b767818b27262d549519870e6cca5e960eea266eb90e99c9/detection/", "output": "\r\r\nMicrosoft (R) Windows (R) Resource Checker Version 6.0\r\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\r\n\r\r\nScans the integrity of all protected system files and replaces incorrect versions with \r\r\ncorrect Microsoft versions.\r\r\n\r\r\nSFC [/SCANNOW] [/VERIFYONLY] [/SCANFILE=<file>] [/VERIFYFILE=<file>]\r\r\n [/OFFWINDIR=<offline windows directory> /OFFBOOTDIR=<offline boot directory> [/OFFLOGFILE=<log file path>]]\r\r\n\r\r\n/SCANNOW Scans integrity of all protected system files and repairs files with\r\r\n problems when possible.\r\r\n/VERIFYONLY Scans integrity of all protected system files. No repair operation is\r\r\n performed.\r\r\n/SCANFILE Scans integrity of the referenced file, repairs file if problems are\r\r\n identified. Specify full path <file>\r\r\n/VERIFYFILE Verifies the integrity of the file with full path <file>. No repair\r\r\n operation is performed.\r\r\n/OFFBOOTDIR For offline repair, specify the location of the offline boot directory\r\r\n/OFFWINDIR For offline repair, specify the location of the offline windows directory\r\r\n/OFFLOGFILE For offline repair, optionally enable logging by specifying a log file path\r\r\n\r\r\ne.g.\r\r\n\r\r\n sfc /SCANNOW\r\r\n sfc /VERIFYFILE=c:\\windows\\system32\\kernel32.dll\r\r\n sfc /SCANFILE=d:\\windows\\system32\\kernel32.dll /OFFBOOTDIR=d:\\ /OFFWINDIR=d:\\windows\r\r\n sfc /SCANFILE=d:\\windows\\system32\\kernel32.dll /OFFBOOTDIR=d:\\ /OFFWINDIR=d:\\windows /OFFLOGFILE=c:\\log.txt\r\r\n sfc /VERIFYONLY\r\r\n" }, "SgrmBroker.exe-1CC295CC202C3AD250D4FDA811E6EC47": { "file_name": "SgrmBroker.exe", "file_path": "C:\\Windows\\system32\\SgrmBroker.exe", "hash_md5": "1CC295CC202C3AD250D4FDA811E6EC47", "hash_sha1": "A75CA4B147E4FD9966F3B5F556C96DFCD9291511", "hash_sha256": "A428E6C8F23145DC75A0425E56A6C2A687BB78548AC697BA20465876CCA2DECA", "hash_sha384": "7E3D6331DDB887CBA28B5BA73E94A5CA8F50D2533A02C932676A30AB71CB31CE0FDB5E0637A79792215B8BC85EF05F07", "hash_sha512": "2FFF097BE38CFF175327368958F556B630209B95B028B21BB7E72DE63E6918BC577D35440258E764761D3C04A7C9EAE2C35EDAFB4D5B6FED0D0306470B1AB155", "hash_ssdeep": "3072:vHBbnguVjx2eDtGN3WES5GGn+0afFIa4LPzVVefJEP3ct94RUxn+/DfiYItQHi:vHV30iGgj5Gb0afFIXPmfJYcARUQ/TI", "hash_imp": "7883701E47B5B0153AF8D1DC05EB4E03", "hash_pesha1": "185E457001318EB0731680E004063F986895FF02", "hash_pe256": "F3367CB9D2DF3DAFE26BA0D3B6941D5B71B6549AD186EF0C7CFAA1A2115F33B6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Guard Runtime Monitor Broker Service", "meta_original_filename": "SgrmBroker.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a428e6c8f23145dc75a0425e56a6c2a687bb78548ac697ba20465876cca2deca/detection/" }, "SgrmLpac.exe-4C3628722D46BFAA80AF2D741C6D7657": { "file_name": "SgrmLpac.exe", "file_path": "C:\\Windows\\system32\\SgrmLpac.exe", "hash_md5": "4C3628722D46BFAA80AF2D741C6D7657", "hash_sha1": "51D61D1F9E8BA6300BADDD5C0E6EEE3AD6A18A93", "hash_sha256": "68601CAEE437FDD4CC9C85EC4F10344E4E13FCFC1597656978B541042FC8BEEC", "hash_sha384": "2EAE43C2CC0239F546FE65CCC1E98B2D05D01A7CD0D93316556E0E8B4318A8D671B53E34A3393B2321198175A39CAE05", "hash_sha512": "5B752DD6AAD7CBF60B05B70E302B376BF5B8C14608B0CEEE0E813B7490322BD476B52CCADF81236EB26A4F66048B560A577D6C331E1CA1D01F12E0B2F339D3AE", "hash_ssdeep": "768:DW4bg0R/Jt1q6eNZt2dHULmVAblJ7sxE9KBYtgMNiIGJsm4vl2peyDw4Xj1PY:64fRt1q6mJDsxkFfc7sm4v0pey8WpP", "hash_imp": "A386DD86C20D1B48463B54D65253242B", "hash_pesha1": "8A856618A297194381C0D7DA82E32F2BCF2910A6", "hash_pe256": "EF6249D3EF54E74FD2228E306159FAD562296BFC0EDF341E711064CFB2B880A3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Guard Runtime Monitor LPAC", "meta_original_filename": "SgrmLpac.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/68601caee437fdd4cc9c85ec4f10344e4e13fcfc1597656978b541042fc8beec/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\RPC Control\\DSECEA8": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SgrmLpac.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\WINHTTP.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\sspicli.dll" ] }, "shrpubw.exe-B3456B75C4FF03EE621D8FB9C86E3200": { "file_name": "shrpubw.exe", "file_path": "C:\\Windows\\system32\\shrpubw.exe", "hash_md5": "B3456B75C4FF03EE621D8FB9C86E3200", "hash_sha1": "52862AB5E6EA9409727E0F500B725B927E104F9E", "hash_sha256": "25736365D4FB5EB9165A474CF2FBCFB478CA190BFE93CC21AB03FAC81A5A2E5C", "hash_sha384": "4BB4AF82AC974C5857AAEC14AF4AA318997860A8FEBF8E72821D0BDD632C6C775C167106DD0C2BE2FC15A8BF54E48B6F", "hash_sha512": "F68C404EFFBF6956C68ACB6E593EEB1894619C70D506FE443CBA365F8DA7044DDC195DCFD412CB6F9C0019CDFAC117294EDAB5AE1E6599D2F244C8BE827A1FED", "hash_ssdeep": "1536:lI5RMIC9qsqAt2ZKRUsOrVukBTxWJF51KsvhFsVq:lkRMI5sqy28RUsOrVPgJFWsvN", "hash_imp": "CD08880A1ADA46C89D1F4FAA23C62C5F", "hash_pesha1": "6793A1398D24BCA5F1961F852866BE6B209EAAA9", "hash_pe256": "4F98356D8C46FFF3B21CF24D45DD99CCAE3AA0173B6AC233DF17614702B32616", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Share Creation Wizard", "meta_original_filename": "shrpubw.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/25736365d4fb5eb9165a474cf2fbcfb478ca190bfe93cc21ab03fac81a5a2e5c/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\shrpubw.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\aclui.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\shrpubw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\srvcli.dll", "C:\\Windows\\system32\\ACLUI.dll", "C:\\Windows\\system32\\NTDSAPI.dll", "C:\\Windows\\system32\\XmlLite.dll" ], "runtime_window_title": "Create A Shared Folder Wizard" }, "shutdown.exe-9BD3C486D5A6378C92A8BE34EAF3088E": { "file_name": "shutdown.exe", "file_path": "C:\\Windows\\system32\\shutdown.exe", "hash_md5": "9BD3C486D5A6378C92A8BE34EAF3088E", "hash_sha1": "072E9A9974BAD1A77702E3B58E67B997EDB107B5", "hash_sha256": "6D262B3CBEDAC276C3EB960DF923167FE0449218721334DCC48A561E981B5790", "hash_sha384": "F64BF9FC0A4C98E0616C13628F1E40FF79FA032CF0E87B8431E8C2180C8234C3A7496E9619B45F6F2804E18F017A1CB4", "hash_sha512": "3621131F16DB5B13AE92FE918A9B3D8F8E19F533E00B9107FDE9B6D0E5B1D2EA645F0895E516FBA98696AA4FACCBFFFAC85F44864258E75804EF486F844147E5", "hash_ssdeep": "384:tconz+fzZMnkcwk8bCFr5LdXKxOszuLZ1P08ypXdQXWK+SW:7nz+7GnSNbE5LQvzuZ1P/ypXde+", "hash_imp": "7381EF144DB2B1CFEA7EEF9BB9B7A530", "hash_pesha1": "C86B9CD6F9FCA561ACD23C2887448BA6B4EEF970", "hash_pe256": "9CEC60A88625153B3A923319B75140092F707BB9875097564B2DED01F709235B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Shutdown and Annotation Tool", "meta_original_filename": "SHUTDOWN.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/6d262b3cbedac276c3eb960df923167fe0449218721334dcc48a561e981b5790/detection/", "output": "Usage: C:\\Windows\\system32\\shutdown.exe [/i | /l | /s | /sg | /r | /g | /a | /p | /h | /e | /o] [/hybrid] [/soft] [/fw] [/f]\n [/m \\\\computer][/t xxx][/d [p|u:]xx:yy [/c \"comment\"]]\n\n No args Display help. This is the same as typing /?.\n /? Display help. This is the same as not typing any options.\n /i Display the graphical user interface (GUI).\n This must be the first option.\n /l Log off. This cannot be used with /m or /d options.\n /s Shutdown the computer.\n /sg Shutdown the computer. On the next boot,\n restart any registered applications.\n /r Full shutdown and restart the computer.\n /g Full shutdown and restart the computer. After the system is\n rebooted, restart any registered applications.\n /a Abort a system shutdown.\n This can only be used during the time-out period.\n Combine with /fw to clear any pending boots to firmware.\n /p Turn off the local computer with no time-out or warning.\n Can be used with /d and /f options.\n /h Hibernate the local computer.\n Can be used with the /f option.\n /hybrid Performs a shutdown of the computer and prepares it for fast startup.\n Must be used with /s option.\n /fw Combine with a shutdown option to cause the next boot to go to the\n firmware user interface.\n /e Document the reason for an unexpected shutdown of a computer.\n /o Go to the advanced boot options menu and restart the computer.\n Must be used with /r option.\n /m \\\\computer Specify the target computer.\n /t xxx Set the time-out period before shutdown to xxx seconds.\n The valid range is 0-315360000 (10 years), with a default of 30.\n If the timeout period is greater than 0, the /f parameter is\n implied.\n /c \"comment\" Comment on the reason for the restart or shutdown.\n Maximum of 512 characters allowed.\n /f Force running applications to close without forewarning users.\n The /f parameter is implied when a value greater than 0 is\n specified for the /t parameter.\n /d [p|u:]xx:yy Provide the reason for the restart or shutdown.\n p indicates that the restart or shutdown is planned.\n u indicates that the reason is user defined.\n If neither p nor u is specified the restart or shutdown is\n unplanned.\n xx is the major reason number (positive integer less than 256).\n yy is the minor reason number (positive integer less than 65536).\n\nReasons on this computer:\n(E = Expected U = Unexpected P = planned, C = customer defined)\nType\tMajor\tMinor\tTitle\n\n U \t0\t0\tOther (Unplanned)\nE \t0\t0\tOther (Unplanned)\nE P \t0\t0\tOther (Planned)\n U \t0\t5\tOther Failure: System Unresponsive\nE \t1\t1\tHardware: Maintenance (Unplanned)\nE P \t1\t1\tHardware: Maintenance (Planned)\nE \t1\t2\tHardware: Installation (Unplanned)\nE P \t1\t2\tHardware: Installation (Planned)\nE \t2\t2\tOperating System: Recovery (Unplanned)\nE P \t2\t2\tOperating System: Recovery (Planned)\n P \t2\t3\tOperating System: Upgrade (Planned)\nE \t2\t4\tOperating System: Reconfiguration (Unplanned)\nE P \t2\t4\tOperating System: Reconfiguration (Planned)\n P \t2\t16\tOperating System: Service pack (Planned)\n \t2\t17\tOperating System: Hot fix (Unplanned)\n P \t2\t17\tOperating System: Hot fix (Planned)\n \t2\t18\tOperating System: Security fix (Unplanned)\n P \t2\t18\tOperating System: Security fix (Planned)\nE \t4\t1\tApplication: Maintenance (Unplanned)\nE P \t4\t1\tApplication: Maintenance (Planned)\nE P \t4\t2\tApplication: Installation (Planned)\nE \t4\t5\tApplication: Unresponsive\nE \t4\t6\tApplication: Unstable\n U \t5\t15\tSystem Failure: Stop error\n U \t5\t19\tSecurity issue (Unplanned)\nE \t5\t19\tSecurity issue (Unplanned)\nE P \t5\t19\tSecurity issue (Planned)\nE \t5\t20\tLoss of network connectivity (Unplanned)\n U \t6\t11\tPower Failure: Cord Unplugged\n U \t6\t12\tPower Failure: Environment\n P \t7\t0\tLegacy API shutdown\n", "error": "Hibernation is not enabled on this system. You must enable hibernation in order to use the -h option.(126)\n", "children": "RdpSa.exe", "runtime_modules": [ "C:\\Windows\\system32\\shutdown.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\shutdownext.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "sigverif.exe-B98262535B58BB43081FA4FC1B3E92B7": { "file_name": "sigverif.exe", "file_path": "C:\\Windows\\system32\\sigverif.exe", "hash_md5": "B98262535B58BB43081FA4FC1B3E92B7", "hash_sha1": "F6205DAF6397CD3B0B2D7CBF19079588916DB90E", "hash_sha256": "776501B9C220B910503BE488126970E5D5159AFA543706B528B8A0737184EF9E", "hash_sha384": "EE76E6393D557436E337417B01835F251AF13817B3EDD14D78C45E5D7C17EB2ACE5E9EEC9AB75864A801E70D0A21B3D9", "hash_sha512": "CE629BF3245D8C0D8D1DF1B80A8C4EA71DEAD56BCF1648E638D4816074941EBAEDB8350D71B5D63A7304722384ED25507EBC918BAD97EEF20018D8F2B770E498", "hash_ssdeep": "1536:6bgBQ0kEmXSYlI99uTT7MY02gewtrHatxzAZT3WuEs:i0ECYlI9UZZgltrHakB7", "hash_imp": "AA4B4E6BDB1A12EF8952DD7EDDDE3EED", "hash_pesha1": "6FFB46E634027CCF94EAC92AC00348B7E27B40C0", "hash_pe256": "14A1A8D9A015455681A979B691BB431511296DB5BCB6FCADD6F99AE3F3BDCA18", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Signature Verification", "meta_original_filename": "sigverif.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/776501b9c220b910503be488126970e5d5159afa543706b528b8a0737184ef9e/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\sigverif.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\sigverif.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll" ], "runtime_window_title": "File Signature Verification" }, "SIHClient.exe-01AB9A5EB2137F371CE2E30013599F78": { "file_name": "SIHClient.exe", "file_path": "C:\\Windows\\system32\\SIHClient.exe", "hash_md5": "01AB9A5EB2137F371CE2E30013599F78", "hash_sha1": "F8A6BAF69AD4BC962B4C35DD476C413E1C41EFCE", "hash_sha256": "FE7054C47862CA79944FAE4F6892CB75000D4196DC9B739993B052817B89D688", "hash_sha384": "B29BAFA5F3B3CBD9A40932229044193C2429297EF5FAB6AD4F521CCAD78F52F4CE89AE11F37F8233FE0DFB78AA36DF55", "hash_sha512": "A82AA563A5DAA0FD6CFDD4C310E6DA05FE04D574E96DF4A70F8143A4511C1C8CAC3F9A9B0690B534E2A1661CB868E50F90DF051ED0FC2AD71B6700226AA70D50", "hash_ssdeep": "6144:DwyRLJHU5DASaLGBHCWm+Of/vlyoJdr4M5aT9Z:DwQJ+IGBin+UltTE8a9Z", "hash_imp": "6F6CDE46652EF17415C88C40F3A26CEB", "hash_pesha1": "4ACE42DE9F59B9F1E1BDFF2AC471069F121DA5EE", "hash_pe256": "3757680290C6C977F11CDFF1DD72B188403C0B199F1A20577D4FF669A8AC9A72", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SIH Client", "meta_original_filename": "sihclient.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/fe7054c47862ca79944fae4f6892cb75000d4196dc9b739993b052817b89d688/detection/" }, "sihost.exe-F6A576DCC3EA8F62B8818434B163D25B": { "file_name": "sihost.exe", "file_path": "C:\\Windows\\system32\\sihost.exe", "hash_md5": "F6A576DCC3EA8F62B8818434B163D25B", "hash_sha1": "A72247134CA39DA0B1F706F6B339DC912C0EE0D3", "hash_sha256": "FDF2362A69C542996A8AC84B938DE62CA97AC209762171D2F8B6B543D3A966D0", "hash_sha384": "0E53778852D51252DD3E83D2641C6C5C0358FEDA818487FB159F04E0937796EE6225B5BE80DC0DDCD70EDAF1B2F01792", "hash_sha512": "92159635D475DC21BE9C543142C79370F3A80F9C1D8ECCBCF6D959517165FF40FE0DB59215C105406D0E0F7F8B060B3B0A67C4E3260DAAA2E0B34C13F38415E0", "hash_ssdeep": "3072:HoGHHEEU+WYAKG+DizpogS+qWe9AN5rytOU/:HoekV+PA/PpVSGb5rytOU", "hash_imp": "D79FA753A3003DE97EDFC038DF32C136", "hash_pesha1": "114DFFE1E84E1B996F246FD3F1FB17F40985E6CF", "hash_pe256": "F9CCDD6AD8FE167C0810354427225C90239F985B6692F11CCE05747E8ED9590F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Shell Infrastructure Host", "meta_original_filename": "sihost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/fdf2362a69c542996a8ac84b938de62ca97ac209762171d2f8b6b543d3a966d0/detection/", "children": "explorer.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC3F8": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\sihost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\CoreMessaging.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\desktopshellext.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\wtsapi32.dll", "C:\\Windows\\SYSTEM32\\WINSTA.dll" ] }, "SlideToShutDown.exe-2CE65A4F9A63402F38537BE59FA1689D": { "file_name": "SlideToShutDown.exe", "file_path": "C:\\Windows\\system32\\SlideToShutDown.exe", "hash_md5": "2CE65A4F9A63402F38537BE59FA1689D", "hash_sha1": "5F07C968F8F6178B0FF5A26267A07F5DC2E775EC", "hash_sha256": "3EF3BF77DC2440BB6A234CE5F42C916DC9359B5EA452680676A0BE85C6AD459B", "hash_sha384": "ECC5D2BF7422EAF972B1B0DB4ADAEDF4850E5328B90F646F3E57478B7896E2E889874846CEB9E317746136EA47F4FAA0", "hash_sha512": "ECA6CCC9E054AA246CC1A024D575BA998A665346A449B0594A5DAB8A18586503AABFC38AE8D180D64D6213B200C0D1A7A706F7C393FE4CCF44138DD19E2AEFD0", "hash_ssdeep": "384:dJ250h4ucSVCB9+5BZfrWWBRC6WoGmXjDBRJwZ1MgKlxsYAj:iCaMCB9gBZfNBRCcPXj1Pw8g2e", "hash_imp": "BB14032CDADDA2A586E94DCE4AF0AF58", "hash_pesha1": "C8F5B12C4905FD23E733CC37659A8BFE0E43A104", "hash_pe256": "179A8A6BC7D7224006A7F2EF6DB9561C99FA0D18B96906FAFBC9647F6C44DB7B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SlideToShutDown", "meta_original_filename": "SlideToShutDown.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/3ef3bf77dc2440bb6a234ce5f42c916dc9359b5ea452680676a0be85c6ad459b/detection/" }, "slui.exe-10B472E52F5F0592076D7E093858A2C3": { "file_name": "slui.exe", "file_path": "C:\\Windows\\system32\\slui.exe", "hash_md5": "10B472E52F5F0592076D7E093858A2C3", "hash_sha1": "9CBB8EAB50D0C00616044CBF04BFE2959C25EF7C", "hash_sha256": "A9E691D1E6763B8895168E8EB3FCC7F9A072C7E46C216F4DEDA3F246EDBC3438", "hash_sha384": "BDEEA7254844CB2C7407E889498F0EE3B5A56E22A1FFD22EB7E96A36CF0338FCA952D5489E3F4B54FAD34C51173A83D3", "hash_sha512": "DBE57A42DD234ACCE10DEE8D74F7CD235E789E3ACC8B886A58267C21A200F04F4F2EAC4DE248247F12164463EEFAD971E96AF5677301904C7C29DF9EE94120F3", "hash_ssdeep": "6144:RVxpC1u+z53bQeILDS7LZAwHfMqY/W5R02qO7VKCyWQp:rxIptMX26Jq3nyR", "hash_imp": "F2014F5555EEFEC494A169DEEBA0FEE5", "hash_pesha1": "67C31874A6AE8082E7B80C5602B80C49F30A54CF", "hash_pe256": "8B139592FB16114EB1310E04257B2C8A0A5D4E6994A3453DC58836C64F0E6E99", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Activation Client", "meta_original_filename": "slui.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/a9e691d1e6763b8895168e8eb3fcc7f9a072c7e46c216f4deda3f246edbc3438/detection/", "runtime_modules": [ "C:\\Windows\\system32\\slui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\WINBRAND.dll", "C:\\Windows\\system32\\sppc.dll", "C:\\Windows\\system32\\WTSAPI32.dll", "C:\\Windows\\system32\\SLC.dll" ] }, "smartscreen.exe-ECB25D2AE78812CF3AC4C1FFF6696AF4": { "file_name": "smartscreen.exe", "file_path": "C:\\Windows\\system32\\smartscreen.exe", "hash_md5": "ECB25D2AE78812CF3AC4C1FFF6696AF4", "hash_sha1": "1CA1ABDC815C06D187E5BA84950715DF162EF4F7", "hash_sha256": "F740FBA7B6791ABF3E000A6C4A04DDEE68D0A0722A3F5C0B44EB4E4D713BF7C9", "hash_sha384": "3104230C2296629A9241D0465882EE46902757A034FF10D4E1F82B8052450D54C1238D75EC5DC1108B182FF815FF104D", "hash_sha512": "6313AD8B68A1BA4CB4948A58F7395FE78F61A5018DE40FEC43A3EFEE1F4207B2579E02555CB3EEE3C60C529109A6293649C6D1F86CEB32040E2A32F66C2C3B2E", "hash_ssdeep": "49152:yf8eXaDPX9+m7rAIIqZA3IlvQpefUiHZDZdVeJ6aUFwNDVahv3nmUb:MI3VgNshv39b", "hash_imp": "C204EBCC4372F95F645AF852BFE02ADB", "hash_pesha1": "C372CE6D7B1F734D951CCD05A89190C47FFD77FA", "hash_pe256": "00A098A9B958131AA6C7275D466E97E355D6D0ECC8BD5D34C8C863A99702B62F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Defender SmartScreen", "meta_original_filename": "smartscreen.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "1/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/f740fba7b6791abf3e000a6c4a04ddee68d0a0722a3f5c0b44eb4e4d713bf7c9/detection/", "runtime_modules": [ "C:\\Windows\\system32\\smartscreen.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\SYSTEM32\\wintypes.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "smss.exe-38E6700BAA0E5484D2E00EC980FDD2E0": { "file_name": "smss.exe", "file_path": "C:\\Windows\\system32\\smss.exe", "hash_md5": "38E6700BAA0E5484D2E00EC980FDD2E0", "hash_sha1": "5B61A25931437D4210EE3CBC8AE3A337B62F3DF0", "hash_sha256": "B6E357B520478920810317B363AA539595D386BC5EF3D5CF9581F325026BA397", "hash_sha384": "80CCDF399DCDE005009AAF4F5FD63EF4963A4AD1C67A8079AD3C2966AD92C9DDD71C9B02B4821700D36F57C62D4432BC", "hash_sha512": "780736F49EF9E7435BAF413BE740DFBD5C6056FAE70B3C8B1FC785892F41C9158128019FBCC00C9AD432243109D7A864DB90C47AFC9BCA72CE5083A021E1190E", "hash_ssdeep": "3072:hFDGXDoqgsEKeBLbwZcfTEs20a26E8FjQp0Bf3:LDGU6ElIGapLFjQpm", "hash_imp": "BC32B6662261DE8469D6EB034C62A6A5", "hash_pesha1": "6BA4AA9F3CA9C60F4E388358407B0CF02482E1F5", "hash_pe256": "3D8174FB4AEEF8D671711BBDE18A299500CDE763688739AB82EAA4D4D0B025F7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Session Manager", "meta_original_filename": "smss.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/b6e357b520478920810317b363aa539595d386bc5ef3d5cf9581f325026ba397/detection/" }, "SndVol.exe-0D8208F039702F6D7FEA2FC002836408": { "file_name": "SndVol.exe", "file_path": "C:\\Windows\\system32\\SndVol.exe", "hash_md5": "0D8208F039702F6D7FEA2FC002836408", "hash_sha1": "B3E64E264C4C0D69BE7817D9B9F9E73AB67D0C93", "hash_sha256": "496FEEBC8BECE33F0D6B5F11B7D03A6A7826EA3D72AC253FBC528C5C3AEE72FF", "hash_sha384": "BA610FFC108ADF4AC320831535D8BE04357260CC9459CCB9207AE50E30D54F42C19C23168889644484DE9B0DFB77AB91", "hash_sha512": "CC5718701FFB6BD48A34F86F8261AF2B2A4D0CE64E9935D632430ED2019DFF5A2742C5E2EA5651921BB1A7BE311C9A10247365D358B2761684532A006E2C967E", "hash_ssdeep": "3072:GnKtvVY2qCA4eXt+e0k95N4HfRyqPAP/PKiAcLfJ9sBjbEyB7HbIHP/:GnKYCA5XEed5N4HfRVjcrJ9fy103", "hash_imp": "C9F852C96B7C3A52C280EB97D52DA386", "hash_pesha1": "A1C46DD7126E0BAECCD5E10A8EB62E158336C226", "hash_pe256": "C04C30469D9133F1FF35D753EEB1D31AE1DFDC742C508C1A39340E2281809D0D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Volume Mixer", "meta_original_filename": "SndVol.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/496feebc8bece33f0d6b5f11b7d03a6a7826ea3d72ac253fbc528c5c3aee72ff/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "(R-D) C:\\Windows\\System32\\en-US\\sndvol.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SndVol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll" ], "runtime_window_title": "Volume Mixer" }, "SnippingTool.exe-B7B2F164769C738D5CB30A418EEAE8B2": { "file_name": "SnippingTool.exe", "file_path": "C:\\Windows\\system32\\SnippingTool.exe", "hash_md5": "B7B2F164769C738D5CB30A418EEAE8B2", "hash_sha1": "7AF2E12D6D0283886F90F22D3AC7D8A9677CE0A9", "hash_sha256": "9F769E52AC15AE1D0B6A3DA293F612AC24303882B1D49EF7A5105ED1B24210D3", "hash_sha384": "1DF26F3BB82235F726F8C34B0B7E2BC65DFA5EED95A38FCC3E3AB1B8AAD0C1E6329E4656C492DE41409B3B77590BC940", "hash_sha512": "24921344E215E1BC197CFE8BD0E163A295CB000A6D5EC03C67CD261AAC436A7E200CFDA9B4D55E6DD95E3DC3EFEEBE17A3A87CC8556E8D714D7C2823631C7F8A", "hash_ssdeep": "98304:MYFlxL4TsqaA2SRmXUrymuXB2rmaOOaCa2PKCZZNRwtPV3Oy:MYFvDqaA2SRmXUrymuXB2rmaOOaCa2Po", "hash_imp": "2FFB3F1A15C731516339C4020F75E1C2", "hash_pesha1": "0D243E3E0B6573BE7F7940C4B6C4B6DF2B6F0465", "hash_pe256": "62AE5DE07552FD9DDBB44DEA2F9B9400C014EA93CDABF38B4F9812C25AE5589B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Snipping Tool", "meta_original_filename": "SnippingTool.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/9f769e52ac15ae1d0b6a3da293f612ac24303882b1d49ef7a5105ed1b24210d3/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\SnippingTool.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\RPC Control\\DSEC10A0": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(RWD) C:\\Windows\\Fonts\\seguisym.ttf": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SnippingTool.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\OLEACC.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\msdrm.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Program Files\\Common Files\\Microsoft Shared\\Ink\\InkObj.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\wisp.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Program Files\\Common Files\\Microsoft Shared\\Ink\\tpcps.dll", "C:\\Windows\\system32\\DWrite.dll", "C:\\Windows\\system32\\WindowsCodecs.dll" ], "runtime_window_title": "Error" }, "snmptrap.exe-58983BFDDDB09E21AF8F3BA3EC45FC7D": { "file_name": "snmptrap.exe", "file_path": "C:\\Windows\\system32\\snmptrap.exe", "hash_md5": "58983BFDDDB09E21AF8F3BA3EC45FC7D", "hash_sha1": "EC79F827947C95B9BA0C4E9584E45A06553CAB5C", "hash_sha256": "9CFC867BECEC3E1FCE830526108F7A7C3E9B0E2FC001EE6CDE6E49C956F781E9", "hash_sha384": "15733B97A92F22DF8FFC04D20E6C385968C7B7D7B9102B1122A759359ACB4321F9AA04185414EF7367C8E14E6111D7A5", "hash_sha512": "0289414E398B7E001571DD94C5B77655A00C435E81CA9002AAA8F6012BD4BA34B793FD6C4063BC851FF69A6DBAE8938DF90D38BAAAC687FD6AFD289BC4E4A1F6", "hash_ssdeep": "384:0ulRaMStzN+lsamt6ZCCW2gOUy2QsifpKWqyW:06RwteA35y2f+u", "hash_imp": "1B8B61707212B76DF87FB8E972F18842", "hash_pesha1": "99C1BDF6629F43A41D7AA89B5070AFCD808F8F8A", "hash_pe256": "5A264565B4F3E3506FA7C9103CC915207344FCF2BF323798BC96ACF2D5253F29", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SNMP Trap", "meta_original_filename": "snmptrap.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/9cfc867becec3e1fce830526108f7a7c3e9b0e2fc001ee6cde6e49c956f781e9/detection/" }, "sort.exe-463CD48BDC468149D6ED607163F30725": { "file_name": "sort.exe", "file_path": "C:\\Windows\\system32\\sort.exe", "hash_md5": "463CD48BDC468149D6ED607163F30725", "hash_sha1": "BC8116747DC7CBDEC4F7BD537488A37863CDD8BE", "hash_sha256": "AC5FFF22F5B5E2B94D8C95203BDC9AB30E883CBE2E9AD07477BD0284D84D1916", "hash_sha384": "B31EA540E9B82FF1C2F357DDCDFB1591E68233C9C08E3BD2FD7AB8574210E4A61B5ADE48D5008C16A7402111072CE21D", "hash_sha512": "108EC5B9F67805EC38EB170E751D08D07467868F6ADA54BE5B0CDB38F0CBA09CF54E3FD771E457E0BEC699CACCB5FC831E4F9959F8DA4D6025B6E77BD6BE8FF4", "hash_ssdeep": "768:vwjgo4HanHn2H6ex+fxwRhHVofGITPI8:vDQeGIHVfN8", "hash_imp": "96BC073D8286B37DFA22A171D067DA0F", "hash_pesha1": "5791BF13EDB0605731491899CF887C6FC9E634C4", "hash_pe256": "DB0C01FBA724340B4AA6A3B5A7CB37E59DC01D3F5A653A2628BFF2B7CD390BBB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Sort Utility", "meta_original_filename": "Sort.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/ac5fff22f5b5e2b94d8c95203bdc9ab30e883cbe2e9ad07477bd0284d84d1916/detection/", "output": "SORT [/R] [/+n] [/M kilobytes] [/L locale] [/REC recordbytes]\r\r\n [[drive1:][path1]filename1] [/T [drive2:][path2]]\r\r\n [/O [drive3:][path3]filename3]\r\r\n /+n Specifies the character number, n, to\r\r\n begin each comparison. /+3 indicates that\r\r\n each comparison should begin at the 3rd\r\r\n character in each line. Lines with fewer\r\r\n than n characters collate before other lines.\r\r\n By default comparisons start at the first\r\r\n character in each line.\r\r\n /L[OCALE] locale Overrides the system default locale with\r\r\n the specified one. The \"\"C\"\" locale yields\r\r\n the fastest collating sequence and is\r\r\n currently the only alternative. The sort\r\r\n is always case insensitive.\r\r\n /M[EMORY] kilobytes Specifies amount of main memory to use for\r\r\n the sort, in kilobytes. The memory size is\r\r\n always constrained to be a minimum of 160\r\r\n kilobytes. If the memory size is specified\r\r\n the exact amount will be used for the sort,\r\r\n regardless of how much main memory is\r\r\n available.\r\r\n\r\r\n The best performance is usually achieved by\r\r\n not specifying a memory size. By default the\r\r\n sort will be done with one pass (no temporary\r\r\n file) if it fits in the default maximum\r\r\n memory size, otherwise the sort will be done\r\r\n in two passes (with the partially sorted data\r\r\n being stored in a temporary file) such that\r\r\n the amounts of memory used for both the sort\r\r\n and merge passes are equal. The default\r\r\n maximum memory size is 90% of available main\r\r\n memory if both the input and output are\r\r\n files, and 45% of main memory otherwise.\r\r\n /REC[ORD_MAXIMUM] characters Specifies the maximum number of characters\r\r\n in a record (default 4096, maximum 65535).\r\r\n /R[EVERSE] Reverses the sort order; that is,\r\r\n sorts Z to A, then 9 to 0.\r\r\n [drive1:][path1]filename1 Specifies the file to be sorted. If not\r\r\n specified, the standard input is sorted.\r\r\n Specifying the input file is faster than\r\r\n redirecting the same file as standard input.\r\r\n /T[EMPORARY]\r\r\n [drive2:][path2] Specifies the path of the directory to hold\r\r\n the sort's working storage, in case the data\r\r\n does not fit in main memory. The default is\r\r\n to use the system temporary directory.\r\r\n /O[UTPUT]\r\r\n [drive3:][path3]filename3 Specifies the file where the sorted input is\r\r\n to be stored. If not specified, the data is\r\r\n written to the standard output. Specifying\r\r\n the output file is faster than redirecting\r\r\n standard output to the same file.\r\r\n\r\n", "error": "--helpThe system cannot find the file specified.\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\sort.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "SpaceAgent.exe-5C9CC1762FA63E9225A479B01C4129E9": { "file_name": "SpaceAgent.exe", "file_path": "C:\\Windows\\system32\\SpaceAgent.exe", "hash_md5": "5C9CC1762FA63E9225A479B01C4129E9", "hash_sha1": "3787480CA2165F99BDF1D0C4C363777E287E22EF", "hash_sha256": "A5BE694313F0F1FBC79E6FB32A86937379AC9EE1840A44709A1993F1493A634B", "hash_sha384": "5E986F881C60EC974613326299E5B6FAB56458871E214C9511D75BE86D926EAE958CC09146317800438745ED2837B389", "hash_sha512": "65384BDE658B0BB39FA5A551256070F8F8C6A7297D5CA46B8EF6E4D5DF8F8C36E319A107D6C8990C03F7AA1545ED1D69630665362F1DF4D5D92FA80E416F7398", "hash_ssdeep": "3072:MJO71Qgh2x07vhXqCBY83XEV4VyMrgjMD5YR9:Hvh2x075XvEV4VyMsodYR", "hash_imp": "E96BA4B07BEB2BD746D95955A1690849", "hash_pesha1": "6B70E8FE421811D42635761E7E4AAC45F38FA625", "hash_pe256": "FC20517C6E9977BA730FE03FAB0C65B1EE83C07F3ECB17F4C743FF56291F7195", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Storage Spaces Settings", "meta_original_filename": "SpaceAgent.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/a5be694313f0f1fbc79e6fb32a86937379ac9ee1840a44709a1993f1493a634b/detection/", "runtime_modules": [ "C:\\Windows\\system32\\SpaceAgent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\CFGMGR32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\NETAPI32.dll", "C:\\Windows\\system32\\CRYPTBASE.DLL", "C:\\Windows\\system32\\SRVCLI.DLL", "C:\\Windows\\system32\\NETUTILS.DLL", "C:\\Windows\\System32\\IMM32.DLL" ] }, "spaceman.exe-5F2D6AF2C3F3571DD6EAD29A20CFEECB": { "file_name": "spaceman.exe", "file_path": "C:\\Windows\\system32\\spaceman.exe", "hash_md5": "5F2D6AF2C3F3571DD6EAD29A20CFEECB", "hash_sha1": "BC4A5BD60FE3942D9F0D87FCB1DB88B3FE185B64", "hash_sha256": "C0F1BE86B069C215EFD362EC77C8CBCA03941B3B92362B0CBCBDF422218C2265", "hash_sha384": "36C953E2830759A503BE32CAF981A59A81258C22A4B837FF64A00D99ABD458CACDF59ACD493DCCA43A343FD95DE8D1BE", "hash_sha512": "D9EE8627F147F94AFDD34379DE797568D98355E31FEB1D37A773D706BB98C7142E7234B0F0EBE3A78BD58E6F608F17CFEBC967B5EFF54E946AD3C8DC049481F3", "hash_ssdeep": "768:VlC9LQkDpsygrQ/uyWlLPTpwFb5PVk2mtsPcQnZrOkN1bwWSnvIqbO6Zf:VcFjg8m/lL7p2dk2nPcQnY01bwWSngqt", "hash_imp": "127353511735A016F01BB0ED9D058893", "hash_pesha1": "8651CFF9D877BFB5E8410E4E13718D7EC0E246CA", "hash_pe256": "091E529B7D7158C85C70DC5173165F727E41BA33CEDD0F2326F14819AC272B23", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Storage Spaces Manager", "meta_original_filename": "spaceman.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/c0f1be86b069c215efd362ec77c8cbca03941b3b92362b0cbcbdf422218c2265/detection/" }, "SpatialAudioLicenseSrv.exe-3C24C425A1216DABA139E8310EBDFAF6": { "file_name": "SpatialAudioLicenseSrv.exe", "file_path": "C:\\Windows\\system32\\SpatialAudioLicenseSrv.exe", "hash_md5": "3C24C425A1216DABA139E8310EBDFAF6", "hash_sha1": "51F3CD82D94B978CD8EB918FB8EA430E9F5DBF35", "hash_sha256": "7F62BA34E5CF6711042847DB9CBB9BB9D56EC4CEA78F486EBB1FE665C223F65A", "hash_sha384": "183C69D1D35B7F5ED4E9D81B1AC51BF5B9229D5C70B48AA684711F1D6A787E2AA946C4A817D9447DE89BEFF044C791A2", "hash_sha512": "47249A5177217942F3BCDAC241381E3C8286838AF4B69CED14E849F7D0FAE1F9E922BA8A456676E9B3A2AF6A9B8B9FC1BB5890B5B1039DD72DBB9AF928246F0C", "hash_ssdeep": "3072:iqkH4xDfMKHcsboMGyGdlZXsbcPPkZiA7jFOiCEKH7DEHPPPsXvkPc+pJxjkuE1l:ipo9HJGyGx8bmPkZiAFCEKH7DEHYepJQ", "hash_imp": "26F8A3301FFF7B955780333C2FE8048C", "hash_pesha1": "C91AAE6E90740C43802D5CD32FA2BCE530EB4485", "hash_pe256": "0B9E3C2963C155D130F86AA9F68F0DF5619082A335910937F636D7F3A9C12C98", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Spatial License AppService Broker", "meta_original_filename": "SpatialLicenseSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/7f62ba34e5cf6711042847db9cbb9bb9d56ec4cea78f486ebb1fe665c223f65a/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SpatialAudioLicenseSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "spoolsv.exe-67F08E3B724AA92414A2CD62E7ADF45E": { "file_name": "spoolsv.exe", "file_path": "C:\\Windows\\system32\\spoolsv.exe", "hash_md5": "67F08E3B724AA92414A2CD62E7ADF45E", "hash_sha1": "1B30CBC2C5778749F72163298FE215B7068DC512", "hash_sha256": "5C9CEB1DF468AF22BF96C87ACAEBE58EC2CC936CFC89DCBD18D0684C72C32C78", "hash_sha384": "EB7CDED00A624942E129EC5CB6BC541C3B82C64C3438D099CDA9601A4E8F9A6BC04598857319A6281364B94EBA8A53DB", "hash_sha512": "7C9A115E2D3D0D867FAFCFEC7239D6D28D967C19FC7820BF8E2B07C2B592223345F7338277DA5F65E9B31B757278C36FE515EFE209A802720EE9343E5DFBA164", "hash_ssdeep": "12288:NCutTZFac05kb2k0RSdv9xi+su3Xwp+OVGDsocstlUSMOLgK8wyjvOeTMK9hYLxy:N37VYiPdP8wyjvOeTMK9hYLxP1UpzaJc", "hash_imp": "73C6E22E27C816FF68B618E9C1CEA622", "hash_pesha1": "0664B1E9329271D118334C95D283FC4C4DB0FBD2", "hash_pe256": "2A86C8EE25215716B6B72068E10A1E2598544B7541D31B0222FA93891ABE49BD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Spooler SubSystem App", "meta_original_filename": "spoolsv.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/5c9ceb1df468af22bf96c87acaebe58ec2cc936cfc89dcbd18d0684c72c32c78/detection/" }, "SppExtComObj.Exe-D0BAB67DD8B87045A7AFCFF45F7022AA": { "file_name": "SppExtComObj.Exe", "file_path": "C:\\Windows\\system32\\SppExtComObj.Exe", "hash_md5": "D0BAB67DD8B87045A7AFCFF45F7022AA", "hash_sha1": "7A0EA2654D0952B65E35FFF71936AA25CB903FD9", "hash_sha256": "144C86F05D93EA0D95998C17B07BFF39B79CC82A46F9A3B378F454EC00F903D6", "hash_sha384": "CD85B505248EEAF269762AD99C45EF90A4AE527170DAFB824A48C259E9781662A046B6E90567D6CB9FE7152E931A0850", "hash_sha512": "B07A2450612F666CF3A57B6F26671EC97F02C0EE46BAC5636E5EBF9CEB7A54086065369F9C512DB58842CD4030A377FE6B3361C661C7CD68048EFEAB66CF9DB6", "hash_ssdeep": "12288:zIb2UlW2pNnW1SFMLq/WYeL2eHKhAwMkNIDrIQbwf8fuk1:zIbjWk6SP/WYeavEkL8fu", "hash_imp": "4C96B0E079D994B8689C66F7872425EB", "hash_pesha1": "4EE58065A47A166303B6801E5EED249933FC3893", "hash_pe256": "AFEFBA73693867BC678C32CD5732BEE946E47222CB7D3D1A55AFB38A8DF62F56", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "KMS Connection Broker", "meta_original_filename": "SppExtComObj.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1432 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1432", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/144c86f05d93ea0d95998c17b07bff39b79cc82a46f9a3b378f454ec00f903d6/detection/" }, "sppsvc.exe-DC187E07593481BCE07A8AE2F027A682": { "file_name": "sppsvc.exe", "file_path": "C:\\Windows\\system32\\sppsvc.exe", "hash_md5": "DC187E07593481BCE07A8AE2F027A682", "hash_sha1": "129D5C85090E47EBE4C08CD72C1EE5F5FA28B73F", "hash_sha256": "E508A3816A1073C0A4E83B2A7C02D0B57DF6A8B473AD77C530C9691245607F52", "hash_sha384": "0A908A0991F1793B234FC0B5BC1B5794D9DF53F178EF31A8666FD9F6DD876F9E31DF492BB4B02998B7EB33FC983CBB79", "hash_sha512": "A3C94A7A63F795D700B67764DC3B6E1536DFE306BC27F1BD61522E689C929537464E769350A7D66CF8EAA45A96A51597B609D0EC44C3FABFB63F9A9169E8A38F", "hash_ssdeep": "49152:2PPVCW5WWoCmWDdGnIQsW0NG335grD8esdqA4tPngdEKoqMvNs2ZzoJZxUOHFac0:AQGWyYxRMel4PqoqMV9n7o+sDhEU4", "hash_imp": "41577F20179B0B22CBA46170F1773F1D", "hash_pesha1": "99CA62DA5EEECFDA7FD3616886E9B6FE332BDD02", "hash_pe256": "C150F0B31B4195C826CDA0CCCD55B171B920B7FD395D8DC8AEEEDCC620B8814C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Software Protection Platform Service", "meta_original_filename": "sppsvc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e508a3816a1073c0a4e83b2a7c02d0b57df6a8b473ad77c530c9691245607f52/detection/" }, "SrvInitConfig.exe-D100D2A375B403C1C7C00617B4D3A59F": { "file_name": "SrvInitConfig.exe", "file_path": "C:\\Windows\\system32\\SrvInitConfig.exe", "hash_md5": "D100D2A375B403C1C7C00617B4D3A59F", "hash_sha1": "D69C3EEB4252D9CBCF643547D82F6AB6898FDE0D", "hash_sha256": "910DBB5FF276AF300C23A7D1C22007837A2D455496DDE1D9D23A8EBB05DB0C0C", "hash_sha384": "12514774D4DA864B33E6AC37A69AEE9610EDD2070CBA2BD945FEAB5E1ED994410709F64D5C15DE13DA2285CC5468BB35", "hash_sha512": "DF5EA8D4BE2FD9EF3B2EE353FF53405F1AACE5207398A00E16054F024DB768549129DE126B118507188623DADA067E0F39DC6702E9E94CCD9603D2374D987580", "hash_ssdeep": "768:YI/wSnCLnj0zNAXiQXYgUFhTSPpIwAXxb9lWlyQUjycdt:YItCL4yXzXYVGPpIwAXxb9pycb", "hash_imp": "DB946DCDAA8238D0C1887135D6CBC2D7", "hash_pesha1": "45F45FA9E719F7993956FAEFA777C5F6DD7765C0", "hash_pe256": "09D409262BAD6C4B64299A0366DDEF851881A9932E35E964A52FBEEA97D0B0AD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Server Configurations", "meta_original_filename": "SrvInitConfig.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1432 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1432", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/910dbb5ff276af300c23a7d1c22007837a2d455496dde1d9d23a8ebb05db0c0c/detection/", "runtime_modules": [ "C:\\Windows\\system32\\SrvInitConfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll" ] }, "stordiag.exe-EA1A603CE352708C94C964508034E010": { "file_name": "stordiag.exe", "file_path": "C:\\Windows\\system32\\stordiag.exe", "hash_md5": "EA1A603CE352708C94C964508034E010", "hash_sha1": "2E8AA7B1EBDFDD6DDB487D69B8C0B46699F7C9B2", "hash_sha256": "DDC1C81667A942F91F25E18EAF3AFC453F7FE3A4CC4140CBA82FB49732011536", "hash_sha384": "310263FC7606CF4954127D403EAD35A0995A3E2E9C10FB2E09E84B4A85EE4592285631E509E958111A5AC06988F362CF", "hash_sha512": "A573335D8AE94B842E45E0913A81806B658E78D57E426D428A97A6918FEB7CEE4F2D2BF1EA3F5829464F3425524B036A69A548ED0BEACA92836FBB01A567DC87", "hash_ssdeep": "1536:dSXiToaguRN2LT0SA6Tny2esoOCd+LbJWE4KWh+fbN0:QXBagGA0SAGy8jbJWE4t2bN0", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "5FAE9F9EEFAA1FE1963A2A84CC7E231592508108", "hash_pe256": "85FED5D0C95C7A5823CC1610DCEEC0D9D9411CCFA15B69E90B921C45DFF883C1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "stordiag.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1", "meta_product_version": "10.0.17763.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/ddc1c81667a942f91f25e18eaf3afc453f7fe3a4cc4140cba82fb49732011536/detection/", "output": "\r\nCollects storage and filesystem diagnostic logs and outputs them to a folder.\r\n\r\nStorDiag [-collectEtw] [-out <PATH>]\r\n-collectEtw Collect a 30-second long ETW trace if run from an elevated session\r\n-collectPerf Collect disk performance counters\r\n-checkFSConsistency Checks for the consistency of the NTFS file system\r\n-diagnostic outputs a storage diagnostic report\r\n-bootdiag output boot sectors of the disk\r\n-driverdiag output avaliable storport and storahci logs\r\n-out <PATH> Specify the output path. If not specified, logs are saved to %TEMP%\\StorDiag\r\n\r\n\r\n", "children": [ "conhost.exe", "systeminfo.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R--) C:\\Users\\user\\AppData\\Local\\Temp\\2\\StorDiag\\PSLogs.txt": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_2904": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\stordiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\5543cca0df435801e2303ff46a482ed5\\mscorlib.ni.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\CRYPTBASE.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\6885802f40fd803e49150d8a2b43a09b\\System.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Management\\35d31e1630335aeb7e7cb2ed836e7230\\System.Management.ni.dll" ] }, "subst.exe-4BFB2ED4A3F52E323F3AE31F3C3A08AC": { "file_name": "subst.exe", "file_path": "C:\\Windows\\system32\\subst.exe", "hash_md5": "4BFB2ED4A3F52E323F3AE31F3C3A08AC", "hash_sha1": "BB8D85B8CE05AF67A0CDA65F25EFD86748E3E1FF", "hash_sha256": "899A5E7E86B1B9F63A1D5E8C63F93C28565528B25EB6C7199B85A0FD69D79AD1", "hash_sha384": "E67D1DB36DB9BB60BDA1F2D6C9F62D57084A1505332ED3CBDBABA27DE258BFC750D2B52FFBA486EBA5B74C7F003050BA", "hash_sha512": "1D262C243E47E9DCF2FBFA176E7D397D8E1E11CEA240198C37B5BFC853C2444B1D4A6A5A5D9672BF337D9171590DDDF9F106CC9C027A8364E20E7D066C16543B", "hash_ssdeep": "192:aL9CaXjtsVIoPNPeXj2UC32DWtKayvOc1OCS+3SFzGGVj4/iqmpWYGW:s9B2siUwy7lvp1Viz/jFnpWYGW", "hash_imp": "657724BEF967C549A066ECF72A628438", "hash_pesha1": "D886FA8AEB4CD5FE8F2C9C2DCC91B526F312B347", "hash_pe256": "BED605200A2F5E035F06850AFBC5F8CA3C974BF6F1F57393D45686EF2A19AB5F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Subst Utility", "meta_original_filename": "Subst.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/899a5e7e86b1b9f63a1d5e8c63f93c28565528b25eb6c7199b85a0fd69d79ad1/detection/", "output": "Associates a path with a drive letter.\r\n\r\nSUBST [drive1: [drive2:]path]\r\nSUBST drive1: /D\r\n\r\n drive1: Specifies a virtual drive to which you want to assign a path.\r\n [drive2:]path Specifies a physical drive and path you want to assign to\r\n a virtual drive.\r\n /D Deletes a substituted (virtual) drive.\r\n\r\nType SUBST with no parameters to display a list of current virtual drives.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\subst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "svchost.exe-8A0A29438052FAED8A2532DA50455756": { "file_name": "svchost.exe", "file_path": "C:\\Windows\\system32\\svchost.exe", "hash_md5": "8A0A29438052FAED8A2532DA50455756", "hash_sha1": "A1385CE20AD79F55DF235EFFD9780C31442AA234", "hash_sha256": "7FD065BAC18C5278777AE44908101CDFED72D26FA741367F0AD4D02020787AB6", "hash_sha384": "A98FFEDB18BFEC038E6709ED2866A247B528316677FCD3145A1631358709FF8F657FC4F7295806ED62C10A9B90DF22FE", "hash_sha512": "CEC8A61A646C76B86D7F3DFD25BB61687D82C07F30198FA05AFE036A859C2B418DA59FFDBE566BC1AB8E91B5D94CD9B76D4BA4FF65B0BD6EBCD7BD3B327A7293", "hash_ssdeep": "768:1eXbpl80992LzEpW5cFiPjFNf7Xg4YCo8cVUy2uGbDy1P8unz:wL/7OL6W5cFKJ7w4Yudy2t6Ptz", "hash_imp": "247B9220E5D9B720A82B2C8B5069AD69", "hash_pesha1": "68BF3DA91310A277BC971C25F7F7F60EAE921B70", "hash_pe256": "A42A20DA16F83B8467DCED74AB028B58D5927D15D9D74C5C7B0D5C9DAC042CB2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Windows Services", "meta_original_filename": "svchost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/7fd065bac18c5278777ae44908101cdfed72d26fa741367f0ad4d02020787ab6/detection/" }, "sxstrace.exe-70A0CFCA8CCE69502D42DF56AE6408D2": { "file_name": "sxstrace.exe", "file_path": "C:\\Windows\\system32\\sxstrace.exe", "hash_md5": "70A0CFCA8CCE69502D42DF56AE6408D2", "hash_sha1": "B949C2BD2DF5E6005D0D17019C352EAD30629B91", "hash_sha256": "85BDD568FEDC81B48FE18F5C4B2E2799ACEAC8049F6F36A42E5A7868E83DE938", "hash_sha384": "CD6CDA3D89867FF7B757278B636E705D78E6962DE19721BA332EA30B2CD1905BDEFBC84961DF3CBD70794E5DD5E302D0", "hash_sha512": "9FB4BBBC3AF7B6F1CA49C078A50F7FD7418CA0BFE9D1CF7DE8C28D8A8458B6D34562807B6E91DF6B4EAB06E34E324D469672A18E520CA2914D713276227FDD51", "hash_ssdeep": "768:pDyWlTdSnfYlJmA/GJpAD9aWgrs4a8wxmlmxDoyIC94rK0R8:1JmA/GTO8AZJhoy9KrPR8", "hash_imp": "608C121F28B6837B15D6067BE234792E", "hash_pesha1": "3ABDF8163B31F30FBAF610401E8DB41B852BE78E", "hash_pe256": "AC119984B238BC3A28C2CD64389196DF08380F1A0A3F3E42A0F88B19374CD54E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Sxs Tracing Tool", "meta_original_filename": "sxstrace.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/85bdd568fedc81b48fe18f5c4b2e2799aceac8049f6f36a42e5a7868e83de938/detection/", "output": "WinSxs Tracing Utility.\r\nUsage: SxsTrace [Options]\r\nOptions:\r\n Trace -logfile:FileName [-nostop]\r\n Enabling tracing for sxs.\r\n Tracing log is saved to FileName.\r\n If -nostop is specified, will not prompt to stop tracing.\r\n Parse -logfile:FileName -outfile:ParsedFile [-filter:AppName]\r\n Translate the raw trace file into a human readable format and save the result to ParsedFile.\r\n Use -filter option to filter the output.\r\n Stoptrace\r\n Stop the trace if it is not stopped before.\r\nExample: SxsTrace Trace -logfile:SxsTrace.etl\r\n SxsTrace Parse -logfile:SxsTrace.etl -outfile:SxsTrace.txt\r\n" }, "SyncAppvPublishingServer.exe-5354113EC1C24E84613C53467F51E133": { "file_name": "SyncAppvPublishingServer.exe", "file_path": "C:\\Windows\\system32\\SyncAppvPublishingServer.exe", "hash_md5": "5354113EC1C24E84613C53467F51E133", "hash_sha1": "417B8A86886C304184AD68966CA188C81D0EF045", "hash_sha256": "BCF02179AC47CE43DD46BF50D0F758B49F925DAE41A3263167119FA1138A6214", "hash_sha384": "85BDFB444867ADB44E8D8F3AFD9E526FC3519F7FC76FCDD7351E00FD8F1066F03F7BE1441FD9FF5F3392791B54280E9C", "hash_sha512": "182DA303B47F219C3D7FE6A9A9743E4C84FB088F8F3E0831F15B00616BEF06EB215CD7BEEEAEF32900EBC9AFCB8F0AE2CB17C2961CEB9F8FF86F08F7808CD21A", "hash_ssdeep": "768:uWqD/7ecTnUtXzu81lWGFNIRTShXj1Pwjz:7LcTnCu82GFNI5StpPo", "hash_imp": "FAECF41B059F08D0AF080D7BEABDBFCC", "hash_pesha1": "08249EDDA66C36BB62AF0978180737EC207524CE", "hash_pe256": "6345C4D5219466E608F682360D69F4D7C1AC0EA29CB09F359E840D0797A2D7FC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/64", "filescan_vtlink": "https://www.virustotal.com/gui/file/bcf02179ac47ce43dd46bf50d0f758b49f925dae41a3263167119fa1138a6214/detection/" }, "SyncHost.exe-11A1A8E958B8334207ADA4F8DB79A82A": { "file_name": "SyncHost.exe", "file_path": "C:\\Windows\\system32\\SyncHost.exe", "hash_md5": "11A1A8E958B8334207ADA4F8DB79A82A", "hash_sha1": "0760949816563C39461DF50FA1594B79A8222428", "hash_sha256": "3CD03758490F23167FC21A5285167C601752117FB87594B7ACFA5AD4248825C7", "hash_sha384": "CFE66FE4DB38F0E67BD1F60AF80A1185683A43321F980AB596769E080AF366EB8DFB48D3D30A83FE12ACEA029167CC64", "hash_sha512": "3E180500E63B99A6BB5331001261EE7FE9B4FF2AFB26C42E0AC08F1CFBBB6DCEC702837291AF62F7589F50E46D91F25106EEC9D9B44007DFFB1B3DA19DF15F0F", "hash_ssdeep": "768:DDLuDZhtLf4AV7/uGI3vwmaJJqKBPTNlfKo1rOs6ulgNK1AejjOJD2Rry6j8GT:DDi9Lf4AYZfwjJqkPL1HmaPjK4hyXG", "hash_imp": "49B558CFF6EB0AA461D3A1C0FC9F8220", "hash_pesha1": "A1B4A73A9ABC60D33CB0287859CBE3C1BA11440F", "hash_pe256": "F15301362B13C14A8D0970C26FEBBE16B19BDD382D1576163A9BDBE40C918E18", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Windows Sync", "meta_original_filename": "SyncHost.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/3cd03758490f23167fc21a5285167c601752117fb87594b7acfa5ad4248825c7/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC5D0": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SyncHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\system32\\WinSync.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "SysResetErr.exe-5B6C38F465AC2903E65D9F870F22A053": { "file_name": "SysResetErr.exe", "file_path": "C:\\Windows\\system32\\SysResetErr.exe", "hash_md5": "5B6C38F465AC2903E65D9F870F22A053", "hash_sha1": "729CFB7C2E86B1CD29B28EC72DBBD9D53D294B46", "hash_sha256": "7994237531700A8FAE449AC3C38176E5220D167F4053466C1343F400B6AF2D47", "hash_sha384": "6B31E186973DF0361934522ADF3DA00E351B3F817CCA33C8816F84EC2CC6009549E9C20949CCE5B70078432F7E208AF2", "hash_sha512": "BBFFA9CA7D119652DBC43340F19DFB75AFF1CCA61B02F1CA8B30B268F1C608B7C59A33E1F281CEC8F5EF433505325A4486F6C0DF854CC8747DB19F7C1C41B75E", "hash_ssdeep": "384:zBZHQ8g+bAEfmv224L+S9Z22BLfCeXFzQcA433QESlW5jvXVOjQ9p31EpvWOzMWF:z7HQFlEi22A4iSSbmQGHA1Xj1Px03aQ", "hash_imp": "34B123D5CDCFEE611E73848C5A2816DD", "hash_pesha1": "9CBD4983E9CD5AD36A6BC5CB8CA84F09F9AEB1EF", "hash_pe256": "959333BF5B9980A60D95A4C3B24F8B5569D1EF828C343697F412D36474516A23", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows System Reset", "meta_original_filename": "SysResetErr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/7994237531700a8fae449ac3c38176e5220d167f4053466c1343f400b6af2d47/detection/", "runtime_modules": [ "C:\\Windows\\system32\\SysResetErr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\WDSCORE.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "systeminfo.exe-F2D7816271A27223945E8AE24B6F81F7": { "file_name": "systeminfo.exe", "file_path": "C:\\Windows\\system32\\systeminfo.exe", "hash_md5": "F2D7816271A27223945E8AE24B6F81F7", "hash_sha1": "B1A8FB81070A8E5B1A389BB825BED7F9CB4BAE98", "hash_sha256": "1084ADF2DDBE903BD71A496720B0D6616882F120D1B3FFEAE8D47FEB0D9CC123", "hash_sha384": "8C11CE27E114F2816BFA46DFEE23A2EF3C46ADA7E1730163AB81CC29D70EF0D87425864BECFEC2844F72AD7645C88DBD", "hash_sha512": "0B308FDD3E617B104DB0A65DA7D269A199EEA3F829027C59506917B9ED543655787BACACED7BAEAC2BB786E2D276BEEFA673F96D1F036CF97EDFE14AF95E78C9", "hash_ssdeep": "1536:xMHrgDS5e4ZpCSoeuktTZXrHkpb+AXIpFkDpQfM0Gff3JyYcpliIjIep6KCNxji7:xsgDSgdEEnIpFkX0Gf/poIesKex27", "hash_imp": "C5985EAB8C1ED292344936A4595C1438", "hash_pesha1": "160EC3FAF1C0265584CF7428642A4248F052CEC5", "hash_pe256": "094871EB27C44FA77F0E9C7830D4F960ADF6A64D263D8A228A9F410D69BB36B4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays system information", "meta_original_filename": "sysinfo.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/1084adf2ddbe903bd71a496720b0d6616882f120d1b3ffeae8d47feb0d9cc123/detection/", "output": "\r\nSYSTEMINFO [/S system [/U username [/P [password]]]] [/FO format] [/NH]\r\n\r\nDescription:\r\n This tool displays operating system configuration information for\r\n a local or remote machine, including service pack levels.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /FO format Specifies the format in which the output\r\n is to be displayed.\r\n Valid values: \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" should\r\n not be displayed in the output.\r\n Valid only for \"TABLE\" and \"CSV\" formats.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n SYSTEMINFO\r\n SYSTEMINFO /?\r\n SYSTEMINFO /S system\r\n SYSTEMINFO /S system /U user\r\n SYSTEMINFO /S system /U domain\\user /P password /FO TABLE\r\n SYSTEMINFO /S system /FO LIST\r\n SYSTEMINFO /S system /FO CSV /NH\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"SYSTEMINFO /?\" for usage.\r\n" }, "SystemPropertiesAdvanced.exe-EF9954642D921EBE2AE21D7D4035FA27": { "file_name": "SystemPropertiesAdvanced.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesAdvanced.exe", "hash_md5": "EF9954642D921EBE2AE21D7D4035FA27", "hash_sha1": "878746BD0E165338A98948B0A4E45C7E7DF4DE9C", "hash_sha256": "8D7826605D9C8428EFE3FC374C32C6DACE4A574462192F4A8DD187C6916D31C0", "hash_sha384": "47C01B196FE268F44C7E9C72A0CD5E5C8384664BC4C8ADAFD345AEE72547CC677E8B5CACD5D46F8CF78EE51EA0FB18D0", "hash_sha512": "6549837F9A6B4826B8804DAC78623B3B7FAD39B4991F3E70677E84152A911D12631A821133EA78ED317867CDE510FAA47B689ECD2A83632C88112A06024C94A0", "hash_ssdeep": "1536:CjEN6hZktREC/rMcgEPJV+G57ThjEC0kzJP+V5Jt:CIN6DkzECTMpuDhjRVJGX", "hash_imp": "68CA080EE65AE9EA92581804B773ECBD", "hash_pesha1": "FF6338ECFA0176F36A124707D6DA8A76AADB0492", "hash_pe256": "13F0507C4E02DA155A9912FCD5338567501EB2066425D8968C8529FCC8E14792", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Advanced System Settings", "meta_original_filename": "SystemPropertiesAdvanced.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/8d7826605d9c8428efe3fc374c32c6dace4a574462192f4a8dd187c6916d31c0/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesAdvanced.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesAdvanced.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\system32\\WINSTA.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\MsftEdit.dll", "C:\\Windows\\system32\\netid.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\system32\\NETAPI32.dll", "C:\\Windows\\system32\\credui.dll", "C:\\Windows\\system32\\WINBRAND.dll", "C:\\Windows\\system32\\DPAPI.dll", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\system32\\DSROLE.DLL", "C:\\Windows\\system32\\LOGONCLI.DLL", "C:\\Windows\\system32\\NETUTILS.DLL", "C:\\Windows\\system32\\WKSCLI.DLL", "C:\\Windows\\system32\\SRVCLI.DLL", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\apphelp.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\remotepg.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\REGAPI.dll" ] }, "SystemPropertiesComputerName.exe-4FDAEBA7E608FD084177D28646773CA5": { "file_name": "SystemPropertiesComputerName.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesComputerName.exe", "hash_md5": "4FDAEBA7E608FD084177D28646773CA5", "hash_sha1": "5116CC34CE8C910D8F90142414F0F04289D5ECF8", "hash_sha256": "ACA5320EEB23777B050F7AB1483C216D5F951E34C1C350B93EAD5D59BD83BF81", "hash_sha384": "20F971351B5B6B625F3A8A1C2202A78DD6EDA09046A5186545245E0C2DD8BD92DBE10B7E2931ED64C0F44BAA2AF60B55", "hash_sha512": "7468A451CBD909E63F32A77923F68D14B122E33DC0B53316179CF68F7252F9BEF65007E4604765441DF5770517939636EB369C80A96566E7F4F6197E3EE92E57", "hash_ssdeep": "1536:qIZctREC/rMcgEPJV+G57ThjEC0kzJP+V5Jx:lczECTMpuDhjRVJG7", "hash_imp": "68CA080EE65AE9EA92581804B773ECBD", "hash_pesha1": "79059B07695FF0643AEA9079E0275A1829DF1A4D", "hash_pe256": "3D501F7E4E030F85AB8679AA6F4FF530C300065F0FC5F2F517943D49F4E475D8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Computer Settings", "meta_original_filename": "SystemPropertiesComputerName.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/aca5320eeb23777b050f7ab1483c216d5f951e34c1c350b93ead5d59bd83bf81/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesComputerName.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesComputerName.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\system32\\WINSTA.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\MsftEdit.dll", "C:\\Windows\\system32\\netid.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\system32\\NETAPI32.dll", "C:\\Windows\\system32\\credui.dll", "C:\\Windows\\system32\\WINBRAND.dll", "C:\\Windows\\system32\\DPAPI.dll", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\system32\\DSROLE.DLL", "C:\\Windows\\system32\\LOGONCLI.DLL", "C:\\Windows\\system32\\NETUTILS.DLL", "C:\\Windows\\system32\\WKSCLI.DLL", "C:\\Windows\\system32\\SRVCLI.DLL", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\apphelp.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\remotepg.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\REGAPI.dll", "C:\\Windows\\SYSTEM32\\netjoin.dll", "C:\\Windows\\system32\\NETPROVFW.DLL", "C:\\Windows\\system32\\JOINUTIL.DLL", "C:\\Windows\\system32\\WindowsCodecs.dll" ] }, "SystemPropertiesDataExecutionPrevention.exe-5AC38FE8FBAFA83DC19D96480EB0DFAF": { "file_name": "SystemPropertiesDataExecutionPrevention.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesDataExecutionPrevention.exe", "hash_md5": "5AC38FE8FBAFA83DC19D96480EB0DFAF", "hash_sha1": "150A6681E427476379197539F991934D4423A4A6", "hash_sha256": "2A68E97CBC5EB55C687E7499A08B827910619FEEB5674A980E5E118D382416CF", "hash_sha384": "F65F56EBA61A6A116FC576DB99522238BCD02963576F7E6DB2D86388EAE69A3C54BA0F1C3259FEB9BC151087D4BEE1FB", "hash_sha512": "8436DD7C7154B6F50219553927E35D149601C4565C9D738563B0ACD5EFFCA12704FE1F03D6815E0A8B8B785386E56A060F5374E050E622139C5FE7B17A236A42", "hash_ssdeep": "1536:5bZ7tREC/rMcgEPJV+G57ThjEC0kzJP+V5J0:/7zECTMpuDhjRVJGe", "hash_imp": "68CA080EE65AE9EA92581804B773ECBD", "hash_pesha1": "778B9C535BF9F011042DD9825DFFAE868239F481", "hash_pe256": "D56FDACEE6D1D8E501830F5B197FEC1832A23E1D0B8490E9C3FEB9CD8C702AD7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Data Execution Prevention Settings", "meta_original_filename": "SystemPropertiesDataExecutionPrevention.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/2a68e97cbc5eb55c687e7499a08b827910619feeb5674a980e5e118d382416cf/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesDataExecutionPrevention.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesDataExecutionPrevention.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\system32\\WINSTA.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\WindowsCodecs.dll" ] }, "SystemPropertiesHardware.exe-951F9402C3D7C1520912574C19D0BFFE": { "file_name": "SystemPropertiesHardware.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesHardware.exe", "hash_md5": "951F9402C3D7C1520912574C19D0BFFE", "hash_sha1": "0B37971904A05C2A2D5F5A52845C5122CBC63946", "hash_sha256": "E15AD3001AC462DA9BDD9510F85E19FB0397C4D467C16DB1067FFC72E9EE8DC6", "hash_sha384": "8154305C6630EA9410E915B15DD6349FF5938CDB2ADCECE3E79B69D812D395850B4F8EE14EE75CE0699B2DB14C8E7F26", "hash_sha512": "68C477302367D3282EE63E8604AA1A08FC566048FA80BD025F1D9EDAB17C57A3AA135CF52F171BB0EEA1EF078D8B5705F5E3174204EAACC20A1C5F378CAFED1D", "hash_ssdeep": "1536:GvZMtREC/rMcgEPJV+G57ThjEC0kzJP+V5Jk:aMzECTMpuDhjRVJGu", "hash_imp": "68CA080EE65AE9EA92581804B773ECBD", "hash_pesha1": "3A1CC464411ECA0157A81E72FC02B4A309968A41", "hash_pe256": "3ACA2A8D5FD19831D1DA4B09A5469ECB52F94FB5B33389334F8D31B57FFED034", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hardware Settings", "meta_original_filename": "SystemPropertiesHardware.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e15ad3001ac462da9bdd9510f85e19fb0397c4d467c16db1067ffc72e9ee8dc6/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesHardware.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesHardware.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\system32\\WINSTA.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\MsftEdit.dll", "C:\\Windows\\system32\\netid.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\system32\\NETAPI32.dll", "C:\\Windows\\system32\\credui.dll", "C:\\Windows\\system32\\WINBRAND.dll", "C:\\Windows\\system32\\DPAPI.dll", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\system32\\DSROLE.DLL", "C:\\Windows\\system32\\LOGONCLI.DLL", "C:\\Windows\\system32\\NETUTILS.DLL", "C:\\Windows\\system32\\WKSCLI.DLL", "C:\\Windows\\system32\\SRVCLI.DLL", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\apphelp.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\remotepg.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\REGAPI.dll", "C:\\Windows\\system32\\WindowsCodecs.dll" ] }, "SystemPropertiesPerformance.exe-AB32E55D2DAC9E9427F89D835054F8D7": { "file_name": "SystemPropertiesPerformance.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesPerformance.exe", "hash_md5": "AB32E55D2DAC9E9427F89D835054F8D7", "hash_sha1": "5ED9658FA4DD4D1EC70157F148D4AE7ABDDE4B66", "hash_sha256": "357BDAD469524CDF42680FF44E17CE41C64B38872C4F55E89DE0560FBD003693", "hash_sha384": "B2263627B403559C47F50CC05B185B669DDBF82B5C4503714A7B20A017743E5E1596FFCEE2425BA745259B5DB5659C9F", "hash_sha512": "D001A698E41842C6B81D8912E0EC78FE7DB174E9248F320C46A9E717D59E1E8E43678325792814A1685E055CECDADFA4852D677554C4DA184757543FD89ED4CC", "hash_ssdeep": "1536:o0oZbtREC/rMcgEPJV+G57ThjEC0kzJP+V5JV:orbzECTMpuDhjRVJG/", "hash_imp": "835402499FB5903791DBBE73881263B5", "hash_pesha1": "284D49497AB1D71F4F6AB471A42B322BA185D5A5", "hash_pe256": "E0B8AB13E07B8599AE6187EBAE82422D6D9AC879C2264DE3E8E32D1A816A6340", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Computer Performance Settings", "meta_original_filename": "SystemPropertiesPerformance.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/357bdad469524cdf42680ff44e17ce41c64b38872c4f55e89de0560fbd003693/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesPerformance.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesPerformance.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\system32\\WINSTA.dll" ] }, "SystemPropertiesProtection.exe-83A6F5D5B65906B811F4D92CAE30A22D": { "file_name": "SystemPropertiesProtection.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesProtection.exe", "hash_md5": "83A6F5D5B65906B811F4D92CAE30A22D", "hash_sha1": "7164EC293D2F98AB8267AB098AFA4F31085BC80A", "hash_sha256": "71438D2A073507B0D8A41ACD59418EC9F0659DC01CB0ECF8F23517B33F2CC454", "hash_sha384": "D910CA0A8DC3BC5B2C0173908EC22277E8CC196F59657E2CCC3FE3C0CC3C2E8A1F66DE5742AB97320AA24E83AE914A3E", "hash_sha512": "9452A1C0C92075BB3BF40BDBB0EE3960A1ADC8C882CC9854AF94C87DD71C935CA7D471800418B5113480662176895028B06589D1210166F143ECB358074E408B", "hash_ssdeep": "1536:VfMZAtREC/rMcgEPJV+G57ThjEC0kzJP+V5Js:hmAzECTMpuDhjRVJGy", "hash_imp": "68CA080EE65AE9EA92581804B773ECBD", "hash_pesha1": "9BB26AD93AFBA170EEB0B41B5023EC6C496D2895", "hash_pe256": "EC5F15CC7B31376CCD150C55E25EAB21EDCFF812F9AB422ADD4F813B210C6152", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Protection Settings", "meta_original_filename": "SSystemPropertiesProtection.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/71438d2a073507b0d8a41acd59418ec9f0659dc01cb0ecf8f23517b33f2cc454/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesProtection.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesProtection.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\system32\\WINSTA.dll" ] }, "SystemPropertiesRemote.exe-637924A0C2CA772D516741840E7D9FAB": { "file_name": "SystemPropertiesRemote.exe", "file_path": "C:\\Windows\\system32\\SystemPropertiesRemote.exe", "hash_md5": "637924A0C2CA772D516741840E7D9FAB", "hash_sha1": "0C035900BF8251BC49C3BD71DAD4D3E87B86E287", "hash_sha256": "E0178C05597090522E268645D572622ACF91ACA4EF91DDB87F8E7FB14B66B67B", "hash_sha384": "CD78937B9C2C9F297E9487DDBD9DF923CF11D89E8ACFF660EC5DEA1512701D5C418D015F36D632229007AFA26F4C23E7", "hash_sha512": "1AB16A43813273EE8E8939872DA295884DF11F7BD6434124758C41DE8E0957C2A18C09021E3192B9A7FC45B1BA9AFD86FF3DFADC8F93BF8A79DE8749D9747E24", "hash_ssdeep": "1536:ICZitREC/rMcgEPJV+G57ThjEC0kzJP+V5Ju:lizECTMpuDhjRVJGc", "hash_imp": "68CA080EE65AE9EA92581804B773ECBD", "hash_pesha1": "61E61EF90BFEB0EEF472E5F52473C1844D6C5ECE", "hash_pe256": "C950519AE5857CCD33A10F5706CF8E50EAC220136B4C34044DE127E70C0634F9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Remote Settings", "meta_original_filename": "SystemPropertiesRemote.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e0178c05597090522e268645d572622acf91aca4ef91ddb87f8e7fb14b66b67b/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesRemote.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemPropertiesRemote.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\SYSDM.CPL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\system32\\WINSTA.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\MsftEdit.dll", "C:\\Windows\\system32\\netid.dll", "C:\\Windows\\System32\\WLDAP32.dll", "C:\\Windows\\system32\\NETAPI32.dll", "C:\\Windows\\system32\\credui.dll", "C:\\Windows\\system32\\WINBRAND.dll", "C:\\Windows\\system32\\DPAPI.dll", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\system32\\DSROLE.DLL", "C:\\Windows\\system32\\LOGONCLI.DLL", "C:\\Windows\\system32\\NETUTILS.DLL", "C:\\Windows\\system32\\WKSCLI.DLL", "C:\\Windows\\system32\\SRVCLI.DLL", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\apphelp.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\remotepg.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\REGAPI.dll", "C:\\Windows\\system32\\SAMLIB.dll" ] }, "systemreset.exe-64E0C3EDF365A23CF76E4C446E16F4FC": { "file_name": "systemreset.exe", "file_path": "C:\\Windows\\system32\\systemreset.exe", "hash_md5": "64E0C3EDF365A23CF76E4C446E16F4FC", "hash_sha1": "5CC7777BD6C305643BFFA9F867301E1EC1036747", "hash_sha256": "D7203C53192BAC31211A12FC1623EE75A28013184B29B98B2227A409AB7A2CB1", "hash_sha384": "06404AFA9E844DEACA03178CF2D7805455BE5C861EC067EAD0F9D8313FEBFBF55EE9407E338A9F38A32ADB53B7F21794", "hash_sha512": "3534D77FEF9B775F3B72A5D9AAE59E3446E7A800DF1F3C55400A935F0786DE54BC4D971B0E446EE233E76F8345A4B121ADFE5D7B3178EFD39D3995B7697E191A", "hash_ssdeep": "6144:QY4OukGjBq58XAfGCdzxSWgCIj35SYpeeaM42RzxCllozRD1gNL57KUgQGEEEsNC:OOCg8XAe+zxSWgB35SYpBaM42Rkoz4t", "hash_imp": "869A3AEFF7DAE7E0A6E4A94DB1E9088C", "hash_pesha1": "9F0AF4EA2390F18B72B3D150504B0C89D83CCA65", "hash_pe256": "F49671F8CA5757C7EEDDE5339F254878D9459DB96E8E8985AB32B51BA61AFA94", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Reset for Windows", "meta_original_filename": "systemreset.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "children": "explorer.exe" }, "SystemSettingsAdminFlows.exe-91D36819B3E7ECD49196C8DD58BBA1C5": { "file_name": "SystemSettingsAdminFlows.exe", "file_path": "C:\\Windows\\system32\\SystemSettingsAdminFlows.exe", "hash_md5": "91D36819B3E7ECD49196C8DD58BBA1C5", "hash_sha1": "1163117BE8557E25A4FE1C81F6221405FB32A57C", "hash_sha256": "C93EF792B92D6D5F4423ABCFDA9FE1B2B2C60BE247447D80B6EFD7C58ADA4478", "hash_sha384": "548886DFBA8F588101C3FE569098C3E8D6F56254C48410755811220364B645480BAED361290A02DB4DC2C0EC5E111A1E", "hash_sha512": "1BE18CF7E74EE011AA76CFF9B6316C2F388B52AA0C443414C07AC0F28ACC471E1CD9963CB28A75CC13C9E82653100AA561E489542E672E172C1FAA46FA23D203", "hash_ssdeep": "6144:wki7wQLf6RlLo42DLEU+6sZzydAoFMY3KAsKD+bjtO:3cLf6RabDLEUJrFQBjt", "hash_imp": "B769F162070BAF857E5B12E34A7DE2C8", "hash_pesha1": "769C87147D6AFDC078F41B49E6E5BA09EBAC8549", "hash_pe256": "D6BAE2CFD8E1F92969FC62512C8815C50A0648AEE65B6C742A6201FE679CF84A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Settings", "meta_original_filename": "SystemSettingsAdminFlows.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c93ef792b92d6d5f4423abcfda9fe1b2b2c60be247447d80b6efd7c58ada4478/detection/", "runtime_modules": [ "C:\\Windows\\system32\\SystemSettingsAdminFlows.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\SystemSettingsThresholdAdminFlowUI.dll", "C:\\Windows\\system32\\newdev.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\system32\\logoncli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\DismApi.DLL", "C:\\Windows\\system32\\Wldp.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\system32\\Bcp47Langs.dll", "C:\\Windows\\system32\\samcli.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\WTSAPI32.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\system32\\AppXDeploymentClient.dll", "C:\\Windows\\system32\\WINBRAND.dll", "C:\\Windows\\system32\\wincorlib.DLL" ] }, "SystemSettingsBroker.exe-0B028C71256D0D72215FE40330B03B6B": { "file_name": "SystemSettingsBroker.exe", "file_path": "C:\\Windows\\system32\\SystemSettingsBroker.exe", "hash_md5": "0B028C71256D0D72215FE40330B03B6B", "hash_sha1": "7CD618F0174BBE7463EB93A3B446F88B5E4BA5B5", "hash_sha256": "18FDB4262A2A83F9F8D58E7A4370B18AB73DC0C89E0AD12264BFAC266144AB26", "hash_sha384": "6A2B26DED3D1F206418783C6DBFC78530CA77BF360A216D770002B6E9C3800ECBE93E90C95A6D766E9DA0FA1C6E891EC", "hash_sha512": "6FCDC00C1EB75E2A1D15F950DF1A1A0E51DA0690377713131882C881BB82B906546C635D63F99F24906164A6068D9ABCEAF0C68DC704A390599C4752696E63C5", "hash_ssdeep": "3072:6eeCLRMRtLRHdilrl4ltLkV9y4PeS6eom+KgY+dIctL6Ps7:VORtLf6p+KgXjt77", "hash_imp": "D8FD7EE63C957698ACE58B0F1030A947", "hash_pesha1": "BC28A9E75CA90CAA5EB000CFFB35C9E637407E58", "hash_pe256": "385040CF85DEBBA563877179A5E48038F934E936DB4521AE63DCEA26DF724652", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Settings Broker", "meta_original_filename": "SystemSettingsBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/18fdb4262a2a83f9f8d58e7a4370b18ab73dc0c89e0ad12264bfac266144ab26/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECD04": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\SystemSettingsBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "SystemSettingsRemoveDevice.exe-38094CF7418F80261FBCFE4288E4A95D": { "file_name": "SystemSettingsRemoveDevice.exe", "file_path": "C:\\Windows\\system32\\SystemSettingsRemoveDevice.exe", "hash_md5": "38094CF7418F80261FBCFE4288E4A95D", "hash_sha1": "282977AB479CA2A8748DA83212CD4C142A921060", "hash_sha256": "27440393C18EBCCD75ABEE131F60DAAB6B2B017FDF71F6DD741C631316786E8A", "hash_sha384": "B8C3FFD024AAE1E160F418A8789FE7079B5481D62A10EF85034D4046A8E7D810A7DF6228DFCC06220748A3E078B00D53", "hash_sha512": "231F3CFB449629EEBB22158C6C75D4D71694B28DC1D94C8AC43E6326EE2054BDF0223FCC44861123EB80EC47889181D5C4E993696241B8E954F8791F9FA5CB34", "hash_ssdeep": "768:kYNC/XUjRVVYuaS9bvhko6LgatpOt+VDpOZczcEBgXj1PcO6:fFTso6MMpO1ZG1+pP76", "hash_imp": "9DC9B6E9378726AD78F12FE890DECC7F", "hash_pesha1": "B57E8793778426C885022A812F2D8DE896F0FC9A", "hash_pe256": "19E7069914125BF8223765F62C241D4F65BE4ACAC960C1344AC998D6B1E5CDCA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SystemSettingsRemoveDevice", "meta_original_filename": "SystemSettingsRemoveDevice.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/27440393c18ebccd75abee131f60daab6b2b017fdf71f6dd741c631316786e8a/detection/", "runtime_modules": [ "C:\\Windows\\system32\\SystemSettingsRemoveDevice.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\Comctl32.dll" ] }, "SystemUWPLauncher.exe-3DCB05C8B63DFA2D0757B59592637F59": { "file_name": "SystemUWPLauncher.exe", "file_path": "C:\\Windows\\system32\\SystemUWPLauncher.exe", "hash_md5": "3DCB05C8B63DFA2D0757B59592637F59", "hash_sha1": "BF1F6AC0949AF61448312D6C582A076054E8608B", "hash_sha256": "73B60714E59C471924707F7EC6A77D6F24B4868173C2640D711A80FD880F90FD", "hash_sha384": "3D26D92E116FA85903E0F2D4CF4490D15796F8610ADF8DE35818AC45C3F8FA74C43F287FBD09CF36122CF0D8312BE6CD", "hash_sha512": "822FAC6C3D426BDF411DC13893F2345CB320E831B15A6C22172A932A9AF26CBBD1BAE76075170B64B10A0B9E39D500249C5095A5A7607AC52C637D8892178958", "hash_ssdeep": "1536:yxc0sFybTXP63CLiiPxwSEsiezrAr/ekorWpyFejP1hqmdpus:p0sMLLiiPxwSEBeA2rnFUbqmL", "hash_imp": "28C5170A16482A4202C80CC05C102BDD", "hash_pesha1": "18F1F7342E8893A02C9A3D5E52A95130111DCBBF", "hash_pe256": "1E950B353E29B54733EFCE01B1162444A6A8CB28379CA5E2D3C689EE64DDDDD4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SystemUWPLauncher", "meta_original_filename": "SystemUWPLauncher.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1339 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1339", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/73b60714e59c471924707f7ec6a77d6f24b4868173c2640d711a80fd880f90fd/detection/", "runtime_modules": [ "C:\\Windows\\system32\\SystemUWPLauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\usermgrcli.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\usermgrproxy.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll" ] }, "systray.exe-D89C468DEA5486F75A848E7D0AB23D32": { "file_name": "systray.exe", "file_path": "C:\\Windows\\system32\\systray.exe", "hash_md5": "D89C468DEA5486F75A848E7D0AB23D32", "hash_sha1": "BB6C508A4428367906E475D20C36D6C4AB7CA6C3", "hash_sha256": "14AD2E29FEA1ED57DFAACAAF35757737BAF5ECA340AC302B30BB75A8A2BC412E", "hash_sha384": "A110ED69EC2DA3B43C84A11295106AD96F7B08E21DF2149D775418719F724D24D983031FECDF7BCDE23C01D5D86FE884", "hash_sha512": "5961C33B7807EC57444852074221870C88D25020B6F8DBF935F8300C91556E20934EFE764D9871CE832E8295FCB656B5792AF3D9B76E84661FC87ECCD703BF3E", "hash_ssdeep": "192:Fxd48p69sIYji12mHi7YEW6UEXWZKfGWWyW:Fxm8c6te17C7bWlZKOWWyW", "hash_imp": "5487E920EA68F003A70EB2B7EC92C4EB", "hash_pesha1": "56703B2647E1B0FAC4784848242DBD80FE254367", "hash_pe256": "06DED775FCA25447AE3A33433619D3E380F272C88A6966C31AC903001A721D79", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Systray .exe stub", "meta_original_filename": "systray.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/14ad2e29fea1ed57dfaacaaf35757737baf5eca340ac302b30bb75a8a2bc412e/detection/" }, "tabcal.exe-E32FFD826EFE0B0620244A64362CC275": { "file_name": "tabcal.exe", "file_path": "C:\\Windows\\system32\\tabcal.exe", "hash_md5": "E32FFD826EFE0B0620244A64362CC275", "hash_sha1": "2B1F23C18E724ED2C600F4A3B89BDDEFD93EFE4A", "hash_sha256": "093270617770DE311AEF2126236AD404F114BC5C75AAB1F954444683526D6626", "hash_sha384": "33B7226B6FCDE5A5B3D29AC8C36A1F9BA138E552EBC286AC64074455AF62945305B98F24649D67B66208711ED6330896", "hash_sha512": "0BBEB13DF41709A735F600C5B852BEC2D2FDBE3A35489E789FEE4EBB7901675D85EDB707D0A4C026DADAC46179F5193C5DC40936D4C777A4E62FA76AAAB93B74", "hash_ssdeep": "1536:sRZ16h5zgp3sY2rPrPoGVtJ2nV+RLXdfW2jbJK:s/48p3sY2HoGqVQXdfZbs", "hash_imp": "AE0F94FDC8914C190BEEBCE401A3F4B2", "hash_pesha1": "A2866144BD0AA5BBBDB681BE5B32F0B11F255676", "hash_pe256": "076334C2D6C5C9A90CBF0D23617BB12A4BE452915F51DFF35875C8B1B8642CE2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Digitizer Calibration Tool", "meta_original_filename": "tabcal.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/093270617770de311aef2126236ad404f114bc5c75aab1f954444683526d6626/detection/", "children": "explorer.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\tabcal.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\tabcal.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\HID.DLL", "C:\\Windows\\system32\\NInput.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\WindowsCodecs.dll" ], "runtime_window_title": "Digitizer Calibration Tool" }, "takeown.exe-1654666A501B109F2BE0D56B9F6B8738": { "file_name": "takeown.exe", "file_path": "C:\\Windows\\system32\\takeown.exe", "hash_md5": "1654666A501B109F2BE0D56B9F6B8738", "hash_sha1": "CA2F4EEE2F8F168CC77340A9A61D26AE50DACF15", "hash_sha256": "820BF585A941580590CAAA0B4AD767CA7EC91549006DD949CCDE9E550398B9C1", "hash_sha384": "1EB9664B14EE1E16BC5DE733C3DF07C70452F9E5483ABDDAEC9D68ADAFDBCD801FE20E5C517042512C4D063D30BE4C15", "hash_sha512": "FD02417B5A265F5E632CE972AD1189D0BC0CD2C9FB5AD00BBAADF8194E9F1CD42F5EADFB92F87EF9B1A698D542CF4832C5D62A9E9C77F5DC8D46689D70750317", "hash_ssdeep": "1536:gLgw3cgEmZhS1MyUGaMnGRl0pWfqZac/P:gLamZoMyUNnl0pOqZaq", "hash_imp": "3BF02FC8FEFDCA08F1DB0D03C18BF179", "hash_pesha1": "71D0FF503F2CC956E3F9086F167B6E2EE751F713", "hash_pe256": "F797A82816C3F6BED6E3544B7E0B90E93A6098A5FE83066DCA31256BE48466FA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Takes ownership of a file", "meta_original_filename": "takeown.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/820bf585a941580590caaa0b4ad767ca7ec91549006dd949ccde9e550398b9c1/detection/", "output": "\r\nTAKEOWN [/S system [/U username [/P [password]]]]\r\n /F filename [/A] [/R [/D prompt]]\r\n\r\nDescription:\r\n This tool allows an administrator to recover access to a file that\r\n was denied by re-assigning file ownership.\r\n\r\nParameter List: \r\n /S system Specifies the remote system to\r\n connect to.\r\n\r\n /U [domain\\]user Specifies the user context under\r\n which the command should execute.\r\n\r\n /P [password] Specifies the password for the\r\n given user context.\r\n Prompts for input if omitted.\r\n\r\n /F filename Specifies the filename or directory\r\n name pattern. Wildcard \"*\" can be used\r\n to specify the pattern. Allows\r\n sharename\\filename.\r\n\r\n /A Gives ownership to the administrators\r\n group instead of the current user.\r\n\r\n /R Recurse: instructs tool to operate on\r\n files in specified directory and all \r\n subdirectories.\r\n\r\n /D prompt Default answer used when the current user\r\n does not have the \"list folder\" permission\r\n on a directory. This occurs while operating\r\n recursively (/R) on sub-directories. Valid \r\n values \"Y\" to take ownership or \"N\" to skip.\r\n\r\n /SKIPSL Do not follow symbolic links.\r\n Only applicable with /R.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE: 1) If /A is not specified, file ownership will be given to the\r\n current logged on user.\r\n\r\n 2) Mixed patterns using \"?\" and \"*\" are not supported.\r\n\r\n 3) /D is used to suppress the confirmation prompt.\r\n\r\nExamples: \r\n TAKEOWN /?\r\n TAKEOWN /F lostfile\r\n TAKEOWN /F \\\\system\\share\\lostfile /A\r\n TAKEOWN /F directory /R /D N\r\n TAKEOWN /F directory /R /A\r\n TAKEOWN /F *\r\n TAKEOWN /F C:\\Windows\\System32\\acme.exe\r\n TAKEOWN /F %windir%\\*.txt\r\n TAKEOWN /S system /F MyShare\\Acme*.doc\r\n TAKEOWN /S system /U user /F MyShare\\MyBinary.dll\r\n TAKEOWN /S system /U domain\\user /P password /F share\\filename\r\n TAKEOWN /S system /U user /P password /F Doc\\Report.doc /A\r\n TAKEOWN /S system /U user /P password /F Myshare\\* \r\n TAKEOWN /S system /U user /P password /F Home\\Logon /R\r\n TAKEOWN /S system /U user /P password /F Myshare\\directory /R /A\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"TAKEOWN /?\" for usage.\r\n" }, "TapiUnattend.exe-C69729656CFE1790A1B746AC5F598694": { "file_name": "TapiUnattend.exe", "file_path": "C:\\Windows\\system32\\TapiUnattend.exe", "hash_md5": "C69729656CFE1790A1B746AC5F598694", "hash_sha1": "1EE56DF1168DBE72B886D5F0E399EBAB24086D2B", "hash_sha256": "C1496333E673BBA7D4FE460E3AA9FD59F79B1A62CCE060875DD7A4E71D8EA388", "hash_sha384": "84556A2078EB9F0AB72ADA3C6A1D027E138311AE579B18A8D15FB67E7DFE3777A4A7EED97816FA721FB432E7A64B0FF9", "hash_sha512": "89F67809579C2A0F9D0A793090D4F75A9B1567989D5156792ADE16183F2394FA0A73F178D0DE00D321DB69645B836985B01F41457B19FC7378DCBDD37B9E8568", "hash_ssdeep": "384:lGZBptzPI5CthqPvkYvUTF16L4EH0eW/BUW:sZTy5ZPvkYcT+Vo", "hash_imp": "42F88FF1F6019E68C40B1CFD658DDBCE", "hash_pesha1": "E123B5B797DEED60CAFB3D522A1C0969C7FE5977", "hash_pe256": "E196DA5EF76E9A35A413DF408B2BD15CF1D946D45F9059C5B2A50C010F4E8A58", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) Telephony Unattend Action", "meta_original_filename": "TapiUnattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/c1496333e673bba7d4fe460e3aa9fd59f79b1a62cce060875dd7a4e71d8ea388/detection/" }, "tar.exe-0B8821B257EEE9C01CD29C62AE9D3EF9": { "file_name": "tar.exe", "file_path": "C:\\Windows\\system32\\tar.exe", "hash_md5": "0B8821B257EEE9C01CD29C62AE9D3EF9", "hash_sha1": "2F52C7715751AEE0ABDDDEE30C1B61586C36D1AD", "hash_sha256": "1407B5BED4602A67C684363AE1582967193DF1CE7CE387B684AF031D9C94EEFA", "hash_sha384": "131E8069F7139159704485252EA79407037878A7D7BF31FF2ED37E7F30CB814B93599E2C9D863A9823F300E06B2E707E", "hash_sha512": "242E0124D966926FC3AF392A05404A980BFC7F59691FBB9BD3D532F1476EEF5E1ED5789F3E39BDE7DD6F6231F62432CD80965A0E7DCB0012A4ECB8FA61F4A5B2", "hash_ssdeep": "768:tsqAYUa+Fx7guW7clM5NuTmN9+/CeL1EjuqmbSchDArcMbv+BzcijXjHM7J5SpxJ:WDYUa+35l2bNcR6oWx7yDvHMLSp7xAk", "hash_imp": "B2FD3710D1AE79BE9E799D9F908BB89C", "hash_pesha1": "84ED72A388F6FA6714834F0A1EA5EB9F29037E30", "hash_pe256": "DD9002395D60B7291372DA1420AACBF1291BEF1DF91D1A42DF3F89C5B7E0301D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "bsdtar archive tool", "meta_original_filename": "bsdtar", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "3.3.2 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (c) libarchive authors", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/1407b5bed4602a67c684363ae1582967193df1ce7ce387b684af031d9c94eefa/detection/", "error": "Usage:\r\n List: tar.exe -tf <archive-filename>\r\n Extract: tar.exe -xf <archive-filename>\r\n Create: tar.exe -cf <archive-filename> [filenames...]\r\n Help: tar.exe --help\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tar.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll" ], "output": "tar.exe(bsdtar): manipulate archive files\r\nFirst option must be a mode specifier:\r\n -c Create -r Add/Replace -t List -u Update -x Extract\r\nCommon Options:\r\n -b # Use # 512-byte records per I/O block\r\n -f <filename> Location of archive (default \\\\.\\tape0)\r\n -v Verbose\r\n -w Interactive\r\nCreate: tar.exe -c [options] [<file> | <dir> | @<archive> | -C <dir> ]\r\n <file>, <dir> add these items to archive\r\n -z, -j, -J, --lzma Compress archive with gzip/bzip2/xz/lzma\r\n --format {ustar|pax|cpio|shar} Select archive format\r\n --exclude <pattern> Skip files that match pattern\r\n -C <dir> Change to <dir> before processing remaining files\r\n @<archive> Add entries from <archive> to output\r\nList: tar.exe -t [options] [<patterns>]\r\n <patterns> If specified, list only entries that match\r\nExtract: tar.exe -x [options] [<patterns>]\r\n <patterns> If specified, extract only entries that match\r\n -k Keep (don't overwrite) existing files\r\n -m Don't restore modification times\r\n -O Write entries to stdout, don't restore to disk\r\n -p Restore permissions (including ACLs, owner, file flags)\r\nbsdtar 3.3.2 - libarchive 3.3.2 zlib/1.2.5.f-ipp\r\n" }, "taskhostw.exe-106B2AEC107DFD22DB51C7A1B29623F8": { "file_name": "taskhostw.exe", "file_path": "C:\\Windows\\system32\\taskhostw.exe", "hash_md5": "106B2AEC107DFD22DB51C7A1B29623F8", "hash_sha1": "77A6E223BF95348B3FA413B244CBB82598DAC9A2", "hash_sha256": "CA620F4DE4A426F129445E4D8A545B7B08B021080E7375A3EA3ED8C8A7212A8F", "hash_sha384": "927AA22383E339D7A33BB95E4A064E9C3F355B4C0CCC742AB922911FBB591E9E1B22602DBB040618A599B4C740C50331", "hash_sha512": "3FC3638B6178BED7C4D75EFFFC7F276C7D742A20A2513FF69374B69C86D651C0B89390C7F9DD48856C04A9B8413C9C579BCD43EB06CCB34ABEB1D73609C8DE39", "hash_ssdeep": "1536:w69m34ldr8tMxKLruZ9CFpfWswrfHK4gAULUVPrT:w69m3ad6MQPkMFpf/QfHK4gAUoV/", "hash_imp": "9839C7FD9649496B162F72128209528A", "hash_pesha1": "25F897B00FF613C2C29438BA0B4F2E5B216A63A1", "hash_pe256": "5051AD8587E4ECCF5355B2AB3A972ED8899DC61001720C8F3359A2BCBC830AA3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Windows Tasks", "meta_original_filename": "taskhostw.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/ca620f4de4a426f129445e4d8a545b7b08b021080e7375a3ea3ed8c8a7212a8f/detection/", "runtime_modules": [ "C:\\Windows\\system32\\taskhostw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\imm32.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "taskkill.exe-ABA3AAD5620E89D22D51028EEDAD3FD6": { "file_name": "taskkill.exe", "file_path": "C:\\Windows\\system32\\taskkill.exe", "hash_md5": "ABA3AAD5620E89D22D51028EEDAD3FD6", "hash_sha1": "B32550D8266D1DC12321256A22E9F04E9EBF9399", "hash_sha256": "9472F2DA48163A7BF36AF3D5A923957788721DCE35A3DA543CC5E7A1F5CA5475", "hash_sha384": "56B76699A1D772CFEAC9D2EC8C240D2B435FA1038A45E0D164618F6B4593620345C351D67786B35BE436A785EDC53766", "hash_sha512": "A7F714909113F5AC779B125605DACFD78A3EF4295803F6854E016CF48883342F397A364EDE7E2C493A23596A6D54D009C5A11439E431E4FF77A3B4467F86E8B4", "hash_ssdeep": "1536:cAp6xbI3UqPle0lubx7WapilgWXZpf8mhPBdsakczahKq4o+rpWwzD7aInBxleUX:cAp6xbI3UqPleYXiaLH7dsakcGhaWIaw", "hash_imp": "100938B32F577E925618EA395A8C469B", "hash_pesha1": "9BE55E3B57E5349957E8D8FF27856CCC54A38641", "hash_pe256": "9022AC50A57A60589C16A7E1917AAFF4C879EE2BCB98367D9068A5450A63A18B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Terminates Processes", "meta_original_filename": "taskkill.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/9472f2da48163a7bf36af3d5a923957788721dce35a3da543cc5e7a1f5ca5475/detection/", "output": "\r\nTASKKILL [/S system [/U username [/P [password]]]]\r\n { [/FI filter] [/PID processid | /IM imagename] } [/T] [/F]\r\n\r\nDescription:\r\n This tool is used to terminate tasks by process id (PID) or image name.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which the\r\n command should execute.\r\n\r\n /P [password] Specifies the password for the given user\r\n context. Prompts for input if omitted.\r\n\r\n /FI filter Applies a filter to select a set of tasks.\r\n Allows \"*\" to be used. ex. imagename eq acme*\r\n\r\n /PID processid Specifies the PID of the process to be terminated.\r\n Use TaskList to get the PID.\r\n\r\n /IM imagename Specifies the image name of the process\r\n to be terminated. Wildcard '*' can be used\r\n to specify all tasks or image names.\r\n\r\n /T Terminates the specified process and any\r\n child processes which were started by it.\r\n\r\n /F Specifies to forcefully terminate the process(es).\r\n\r\n /? Displays this help message.\r\n\r\nFilters:\r\n Filter Name Valid Operators Valid Value(s)\r\n ----------- --------------- -------------------------\r\n STATUS eq, ne RUNNING |\r\n NOT RESPONDING | UNKNOWN\r\n IMAGENAME eq, ne Image name\r\n PID eq, ne, gt, lt, ge, le PID value\r\n SESSION eq, ne, gt, lt, ge, le Session number.\r\n CPUTIME eq, ne, gt, lt, ge, le CPU time in the format\r\n of hh:mm:ss.\r\n hh - hours,\r\n mm - minutes, ss - seconds\r\n MEMUSAGE eq, ne, gt, lt, ge, le Memory usage in KB\r\n USERNAME eq, ne User name in [domain\\]user\r\n format\r\n MODULES eq, ne DLL name\r\n SERVICES eq, ne Service name\r\n WINDOWTITLE eq, ne Window title\r\n\r\n NOTE\r\n ----\r\n 1) Wildcard '*' for /IM switch is accepted only when a filter is applied.\r\n 2) Termination of remote processes will always be done forcefully (/F).\r\n 3) \"WINDOWTITLE\" and \"STATUS\" filters are not considered when a remote\r\n machine is specified.\r\n\r\nExamples:\r\n TASKKILL /IM notepad.exe\r\n TASKKILL /PID 1230 /PID 1241 /PID 1253 /T\r\n TASKKILL /F /IM cmd.exe /T \r\n TASKKILL /F /FI \"PID ge 1000\" /FI \"WINDOWTITLE ne untitle*\"\r\n TASKKILL /F /FI \"USERNAME eq NT AUTHORITY\\SYSTEM\" /IM notepad.exe\r\n TASKKILL /S system /U domain\\username /FI \"USERNAME ne NT*\" /IM *\r\n TASKKILL /S system /U username /P password /FI \"IMAGENAME eq note*\"\r\n", "runtime_modules": [ "C:\\Windows\\system32\\taskkill.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\system32\\framedynos.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\srvcli.dll", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"TASKKILL /?\" for usage.\r\n" }, "tasklist.exe-B802C79BE392F3BFCC51CDA425BC94D2": { "file_name": "tasklist.exe", "file_path": "C:\\Windows\\system32\\tasklist.exe", "hash_md5": "B802C79BE392F3BFCC51CDA425BC94D2", "hash_sha1": "97477D293816C4636B239A3307B5C5E165E6B4DE", "hash_sha256": "113C4D989A47B80905E92C06E48E03B24D44CADBF7BC7E86D948D7DA9DC98252", "hash_sha384": "EE79A60CA874A4EDA826E37AA698AB4FC92B67B391EDA1DBD5F8F562CCB9CC5ED64E8C3465E3D832F078FDD3F8260AC3", "hash_sha512": "AF403E30285D9EEA9408457081B6D3061D3328532C2F60CB4BF6EAFAC6E76C46047FE8A4731D3BE32A78B5AC28312B6F8E98F7993F043DA42B02744AC19E5DB8", "hash_ssdeep": "1536:u9dOni6cHpACNklrpfX+OLY1sDq7+uLaOv3el2fwXQ5P8MnxbfwhUx09N:QCitpjypfdLY1sG7+zXl2jxbGUx4", "hash_imp": "DCE1F3B1BD09BBAD166CE65677E33EDB", "hash_pesha1": "3759BF2820EC6DF816475021ABFE5EB9C0F44F89", "hash_pe256": "E23455C2A07549D9A6B4BDECB3D2FFED02163A8A145EA8AE8F2F860B5EC945C1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Lists the current running tasks", "meta_original_filename": "tasklist.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/113c4d989a47b80905e92c06e48e03b24d44cadbf7bc7e86d948d7da9dc98252/detection/", "output": "\r\nTASKLIST [/S system [/U username [/P [password]]]]\r\n [/M [module] | /SVC | /V] [/FI filter] [/FO format] [/NH]\r\n\r\nDescription:\r\n This tool displays a list of currently running processes on\r\n either a local or remote machine.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /M [module] Lists all tasks currently using the given\r\n exe/dll name. If the module name is not\r\n specified all loaded modules are displayed.\r\n\r\n /SVC Displays services hosted in each process.\r\n\r\n /APPS Displays Store Apps and their associated processes.\r\n\r\n /V Displays verbose task information.\r\n\r\n /FI filter Displays a set of tasks that match a\r\n given criteria specified by the filter.\r\n\r\n /FO format Specifies the output format.\r\n Valid values: \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" should\r\n not be displayed in the output.\r\n Valid only for \"TABLE\" and \"CSV\" formats.\r\n\r\n /? Displays this help message.\r\n\r\nFilters:\r\n Filter Name Valid Operators Valid Value(s)\r\n ----------- --------------- --------------------------\r\n STATUS eq, ne RUNNING | SUSPENDED\r\n NOT RESPONDING | UNKNOWN\r\n IMAGENAME eq, ne Image name\r\n PID eq, ne, gt, lt, ge, le PID value\r\n SESSION eq, ne, gt, lt, ge, le Session number\r\n SESSIONNAME eq, ne Session name\r\n CPUTIME eq, ne, gt, lt, ge, le CPU time in the format\r\n of hh:mm:ss.\r\n hh - hours,\r\n mm - minutes, ss - seconds\r\n MEMUSAGE eq, ne, gt, lt, ge, le Memory usage in KB\r\n USERNAME eq, ne User name in [domain\\]user\r\n format\r\n SERVICES eq, ne Service name\r\n WINDOWTITLE eq, ne Window title\r\n MODULES eq, ne DLL name\r\n\r\nNOTE: \"WINDOWTITLE\" and \"STATUS\" filters are not supported when querying\r\n a remote machine.\r\n\r\nExamples:\r\n TASKLIST\r\n TASKLIST /M\r\n TASKLIST /V /FO CSV\r\n TASKLIST /SVC /FO LIST\r\n TASKLIST /APPS /FI \"STATUS eq RUNNING\"\r\n TASKLIST /M wbem*\r\n TASKLIST /S system /FO LIST\r\n TASKLIST /S system /U domain\\username /FO CSV /NH\r\n TASKLIST /S system /U username /P password /FO TABLE /NH\r\n TASKLIST /FI \"USERNAME ne NT AUTHORITY\\SYSTEM\" /FI \"STATUS eq running\"\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tasklist.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\system32\\framedynos.dll", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\srvcli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\wbem\\wbemprox.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\Winsta.dll" ], "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"TASKLIST /?\" for usage.\r\n" }, "Taskmgr.exe-BE497D144DBC4F9689AA9846033D2A95": { "file_name": "Taskmgr.exe", "file_path": "C:\\Windows\\system32\\Taskmgr.exe", "hash_md5": "BE497D144DBC4F9689AA9846033D2A95", "hash_sha1": "4332D5B7FCC7FD6E65F247069A4C67B70C93E0F4", "hash_sha256": "8A6B7BCE25506A2D7B2B4449404CC312794051DB3AA1BB964CDAC956E930CAD5", "hash_sha384": "6D6581AF4470650789FDE75013ACB251C5D033A4FC2C4AB3977638DB3A37EC2867EFD90E01DE1175C5040A455832FE26", "hash_sha512": "307C5C225C6B0F48D7E553083AAADE9F86A8779C26F7BB2E99D8D44607F423B5B03D2DA99612DDBA204654EB26059F0126A3B4CF24D09503E297609DE51E5FFD", "hash_ssdeep": "24576:IaTZtOf9HXGblr3uYnL/V6kEnnCUaPYULBe7q4D:3GRX43uYnrVannCUa5e7q4", "hash_imp": "DA57E277C35794A416E83153D21D8EBB", "hash_pesha1": "3B0733C54FC049076B41F60F38CACE69C3D7F594", "hash_pe256": "B8AF303F293599C991735EE466F419650D8CF27CEBDB6A69F9A7FC4A86891CF1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Manager", "meta_original_filename": "Taskmgr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/8a6b7bce25506a2d7b2b4449404cc312794051db3aa1bb964cdac956e930cad5/detection/", "children": [ "csrss.exe", "winlogon.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\Taskmgr.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\2\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\RPC Control\\DSEC13AC": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\propsys.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\C:*Users*Administrator*AppData*Local*Microsoft*Windows*Caches*{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\C:*Users*Administrator*AppData*Local*Microsoft*Windows*Caches*cversions.3.ro": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Taskmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\credui.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\pdh.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\system32\\d3d12.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "runtime_window_title": "Task Manager" }, "tcblaunch.exe-DC5470C341F90B2D4CE55C563CCDCD55": { "file_name": "tcblaunch.exe", "file_path": "C:\\Windows\\system32\\tcblaunch.exe", "hash_md5": "DC5470C341F90B2D4CE55C563CCDCD55", "hash_sha1": "23765A5FAD01689D47468BA44A74B1DABED3379C", "hash_sha256": "A210392342E8BF7705837D7DA44CDCAB8C43FF8C9F22606E40035E889766856D", "hash_sha384": "F99653D143B69C9B92ED3A4F51123A5E987C14CA0B5B1416A8A4EF58435754314FE55679FF61BDF60F26104C59B7FF7F", "hash_sha512": "EC5EBDE3108D45EFDD65D2FA6A6F474EC97D9D734470DC8311BFEC006273B9430413A3A0A60F00037148116637DBF031CE2062D0AE9B9017B5F387EC9C131F2C", "hash_ssdeep": "12288:R6JqMN651gw7RBysMZ25NyQyT1KyJuT/Rfu8t4WibWU/61qK2qbE2BOD:R6JVAsgR5MZ25/7yJSRfuOEbWE61qf22", "hash_imp": "n/a", "hash_pesha1": "4127E17A6BD31FAFFA88270102E58EB804653348", "hash_pe256": "BDB25DD7FD79A077A1F37C382F623324D9C139DC65672CE91FEE7FF0BE05E929", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCB Launcher", "meta_original_filename": "tcblaunch.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "tcmsetup.exe-2C32B625127DE85FB0273569687060E1": { "file_name": "tcmsetup.exe", "file_path": "C:\\Windows\\system32\\tcmsetup.exe", "hash_md5": "2C32B625127DE85FB0273569687060E1", "hash_sha1": "4E5861950F56F44528EC52B829F0FD236445C78E", "hash_sha256": "7C159CDD1FB7C5359439DA809B5BEB15E1FFDF769D2249054C36F99C7B9BF609", "hash_sha384": "3E09745D001E2F91BBE80D3C35AD2A554EC73D610386AF6946CA422AB5E08C0F571331DF308C59C05FBBFC59113C25DC", "hash_sha512": "32A4B20A1188ED6F1315686CC1EFF87820D6D361D452E68780316AA8E4AE00740B178DD30A866662AF3C20BFE6091DFB02C4A906F24F4DFF01A323C0224FF051", "hash_ssdeep": "192:Xz8yrtsYOD7iyxXQw3IE2zDrxLCY7f8WS3qb6UdOU/QN99OWGQoW:ab7ieXKdzDrx207dbKV9OWGQoW", "hash_imp": "AE7E4F06CC6D11D0E730DEFD22D14777", "hash_pesha1": "31FC3E79D18A82CF0B683F8C6C10B4A401306590", "hash_pe256": "C390EB6269F66647E79F0FCEC1B3DB3BD8712904E98EC4CD7852B65D224FA19B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) Telephony Administration Setup", "meta_original_filename": "TCMSETUP.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/7c159cdd1fb7c5359439da809b5beb15e1ffdf769d2249054c36f99c7b9bf609/detection/", "children": "explorer.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\tcmsetup.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\tcmsetup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\TAPI32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ], "runtime_window_title": "Telephony Client Setup Help" }, "TCPSVCS.EXE-5351CC2CB27678FCC6EAE550269D5D3A": { "file_name": "TCPSVCS.EXE", "file_path": "C:\\Windows\\system32\\TCPSVCS.EXE", "hash_md5": "5351CC2CB27678FCC6EAE550269D5D3A", "hash_sha1": "08A0A5A21244BB16DF14DD9D7FF99A190A4C59D2", "hash_sha256": "03C299DB96AD76879007BAE4D248292E15E574A03FD080A868EC289E07A0D917", "hash_sha384": "FA54C32C939CCFECB1610D30686A629225B867E0EEA6F7860F7985686428F4E1D7D45C9B8082C7B9F4F6997770047A30", "hash_sha512": "E2941FD9DF6D77BD8984127D4603506E8651FEBA86CB0149E6FAD1E742FEE97F4BE9A1272EFE4F2E7E4FDD8B157E14139C4E9E6BA0B07B22E75807015AA27060", "hash_ssdeep": "192:p8NmZjr2lgz/hpYOtNFdk7l0o+KMlH2GjbUXodXL6//1SIwUW5/W:p8NmZiwJmOB+7l0oBv4QXE6//8UW5/W", "hash_imp": "5FB43D31195A81197A7053C4A202BCED", "hash_pesha1": "D38040B9563A42BF5D151F5E6D0742A630BFBA94", "hash_pe256": "349524AC3A75E4CDECBB8D893D97353B6AE66FE33336B9C5909D9EC025AA0FCD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Services Application", "meta_original_filename": "TCPSVCS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/03c299db96ad76879007bae4d248292e15e574a03fd080a868ec289e07a0d917/detection/" }, "ThumbnailExtractionHost.exe-1519AC5136CDF3601AFF23A90D4FD9EC": { "file_name": "ThumbnailExtractionHost.exe", "file_path": "C:\\Windows\\system32\\ThumbnailExtractionHost.exe", "hash_md5": "1519AC5136CDF3601AFF23A90D4FD9EC", "hash_sha1": "21FDD62BC011BC336371358BB19C37A8E9DC6666", "hash_sha256": "AB58BAB0565BE06DBE5EAF5EE4CD0C3281A6BB6EFA4F23CEBC9E0F71CA29A797", "hash_sha384": "CE7E4AC7A50A1752B2897A68D7B36E3AC8778EFE320FF6412763CE0F1E6D9673FD07F7025305DDA002337E062E90995F", "hash_sha512": "10FD0D18D75350C762D239022748EF9B491CB6397BE0F0C02A667B91F4E4DDEA385EFDFBF385B11FC732B594C78F5C7C11CCB0CF4B45F9E01B4578F669AAE8E2", "hash_ssdeep": "768:Wj8TiS8w6Z3NUR0rW7IjgTb5Z/VPMOquoFyEi:Wj8Gw6NWxtHMTjyEi", "hash_imp": "B7157C377178E6B1B34EFFAD517664F4", "hash_pesha1": "EC94983ECA2D0744CFDE60A3E8AD8B29B05555AE", "hash_pe256": "09228E3BAB86A8A28F9CEAD8835D93E397C9518D8DAE7F8CA64B799D2B2225B6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Thumbnail Handler Extraction Host", "meta_original_filename": "ThumbnailExtractionHost.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/ab58bab0565be06dbe5eaf5ee4cd0c3281a6bb6efa4f23cebc9e0f71ca29a797/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC864": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\ThumbnailExtractionHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll" ] }, "TieringEngineService.exe-33E60A1BD76A877683FCD7DC93A10635": { "file_name": "TieringEngineService.exe", "file_path": "C:\\Windows\\system32\\TieringEngineService.exe", "hash_md5": "33E60A1BD76A877683FCD7DC93A10635", "hash_sha1": "57A3F1BB5D26537F9735BDDDA9B6DE300F218C9F", "hash_sha256": "917F104892FF1890BE2AB218B99C2DFED8287AB93EA6895BA74090783D4E341C", "hash_sha384": "675D4F03D5594DC1E51C213726AEBBD9875689F86B37D64F8782ACDD792DED51051F779E61386A0CA3F3ACDF74F72069", "hash_sha512": "C3A715BB6D3771E7839FC7B38B307B9BF6DEB7411203CA42020084F54438070570D59277FE2A320F83512170FF9A99B522207A21335C999AA896794DF2463D40", "hash_ssdeep": "6144:EjWq9JnJtFSsydvFyshpyNqZkNw16puxRbkGqG:Ei2JnJyhh+gkyxIg", "hash_imp": "E803DC35CC0F3853734DD4B09D47793A", "hash_pesha1": "044F73E41575278E9ABED6EE144D9DC49A663D4E", "hash_pe256": "88D69DB706EE1CE5397E65C23281CDF36EE371916A2B6038FDF3A4BEC1F2DEAC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Storage Tiers Management", "meta_original_filename": "TieringEngineService.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/917f104892ff1890be2ab218b99c2dfed8287ab93ea6895ba74090783d4e341c/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\TieringEngineService.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\TieringEngineService.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\ESENT.dll", "C:\\Windows\\system32\\CLUSAPI.dll", "C:\\Windows\\System32\\bcrypt.dll" ] }, "timeout.exe-8E5650109EFFB36F456846F2CA14F5B3": { "file_name": "timeout.exe", "file_path": "C:\\Windows\\system32\\timeout.exe", "hash_md5": "8E5650109EFFB36F456846F2CA14F5B3", "hash_sha1": "5346C77A5FC3245C79408802D1CBA9E42D707809", "hash_sha256": "9DE395721EEE865D97F27734B0EAA3D204384EEE005FC247BE026C24D277AA1C", "hash_sha384": "908394BAF7B330DB406601C054B217153895A335C0EB590EB9F6F696BB468ED1665206089354101E68F3818FDA70B9D1", "hash_sha512": "82A8F86779B8F22FEA1B48070DBC0AA0CE2C514CF1B36BF8AEB1CC1FD4EFBD8CC39B398941BF1076C5E8EA391940080B44F885F3D11E959BABCE384059AD0B3D", "hash_ssdeep": "384:qy2AeK9bJOLsn92DjOZ66KwJNpkE3KCqb3cMmm+WkUIER80fa/SCMV6Hfs15MQx0:qybe61UOiE3W9m6DqdHfs15MQxv8KC", "hash_imp": "0C91A5CE0FB26F4C5CE39E340F43873B", "hash_pesha1": "9C8E5A99D8207FA55A027D76C6C6806097D2A579", "hash_pe256": "BADA66A6E887A9DC6D878FF554F6E49BC3EC6FE0DDA7DF3AA1FAECD7DB139306", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "timeout - pauses command processing", "meta_original_filename": "timeout.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/9de395721eee865d97f27734b0eaa3d204384eee005fc247be026c24d277aa1c/detection/", "output": "\r\nTIMEOUT [/T] timeout [/NOBREAK] \r\n\r\nDescription:\r\n This utility accepts a timeout parameter to wait for the specified\r\n time period (in seconds) or until any key is pressed. It also \r\n accepts a parameter to ignore the key press. \r\n\r\nParameter List:\r\n /T timeout Specifies the number of seconds to wait.\r\n Valid range is -1 to 99999 seconds.\r\n\r\n /NOBREAK Ignore key presses and wait specified time.\r\n\r\n /? Displays this help message.\r\n\r\nNOTE: A timeout value of -1 means to wait indefinitely for a key press.\r\n\r\nExamples:\r\n TIMEOUT /?\r\n TIMEOUT /T 10\r\n TIMEOUT /T 300 /NOBREAK\r\n TIMEOUT /T -1\r\n", "error": "ERROR: Invalid value for timeout (/T) specified. Valid range is -1 to 99999.\r\n", "children": [ "csrss.exe", "wininit.exe" ] }, "TokenBrokerCookies.exe-58A7C5118089021229B89639D1E6FD57": { "file_name": "TokenBrokerCookies.exe", "file_path": "C:\\Windows\\system32\\TokenBrokerCookies.exe", "hash_md5": "58A7C5118089021229B89639D1E6FD57", "hash_sha1": "0FCABD0C7D5BA48F476A10F6B471DAEDDE3C311D", "hash_sha256": "950FB6C29989F0291446281BB4CD2F1477855197F52F5AA8901C0E7B5F96D0A6", "hash_sha384": "1AA0E78DE2176253A824FAA70F1485B0B7CB988B34E1095AA31222228725A5C4D676504A79DFACB8E68B57C123644E9D", "hash_sha512": "F13A76FEFEB9D6EBBA8F04652DB9527BE71E50BBAB2B755EBA640EA7F33B374D6DC4F0710D6589C8E7955463C26DBE91838D191368B1BEDA37008842AD71C732", "hash_ssdeep": "768:tMUZi+ojuTSUIulmkniTYG6xmF87lMAVMn:uUuuTScmkiTYG6xmF8ZMAVMn", "hash_imp": "5BA559CB6C27122C28307F60D707EC00", "hash_pesha1": "DE142147A193BC0872FFEC601973E2C40D6963DA", "hash_pe256": "AFE41E54C31B4E8BCF23EDED74528C98C08B3699135400F9646BBECFEF7CEAB0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Token Broker Cookie Helper", "meta_original_filename": "TokenBrokerCookies.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/950fb6c29989f0291446281bb4cd2f1477855197f52f5aa8901c0e7b5f96d0a6/detection/" }, "TpmInit.exe-578EF2B7D0C63504C39DD1BF3CADB2A8": { "file_name": "TpmInit.exe", "file_path": "C:\\Windows\\system32\\TpmInit.exe", "hash_md5": "578EF2B7D0C63504C39DD1BF3CADB2A8", "hash_sha1": "CAAF8D868E3A1DA26C15A136AFF55ADEA9F82929", "hash_sha256": "452CD44F2920387AD9D25E5285A5C70E2D404F96F61AFD48CAF3F0DC04645CEE", "hash_sha384": "28063041E8CD5E8DAB05CABF3C40FEA2D90648306F9EB3A1411F53DEE451CFA1D77C974E8E1F11A79B8B0F52A3B94C45", "hash_sha512": "CD45DCCC3891185120AD3C2C54281249A9E18AF615FB34C5DDC3A7462668C2D765011EDA0F473627397B4E30037DD1CCD72D0741F650EF430CA861D7F323C140", "hash_ssdeep": "1536:X5QXz+MMhkJ101a6HuGiceY0lA3CJHkxUM:GXzuhX1L+PYfSFkx1", "hash_imp": "CB0FB4D269B59D4F60F985CCD3A90C83", "hash_pesha1": "B69E122832297A0AA41D3BD7CD2F05D507A0A30A", "hash_pe256": "A37BBB4BDC2069461526B0971FEDAB1AFC81B49FA18959C780C98E09683A32AA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TPM Initialization Wizard", "meta_original_filename": "TpmInit.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/452cd44f2920387ad9d25e5285a5c70e2d404f96f61afd48caf3f0dc04645cee/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\TpmInit.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC780": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netmsg.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\TpmInit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\system32\\OLEACC.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\wbem\\wbemprox.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\wbem\\wbemsvc.dll", "C:\\Windows\\system32\\wbem\\fastprox.dll", "C:\\Windows\\system32\\WindowsCodecs.dll", "C:\\Windows\\System32\\TextInputFramework.dll", "C:\\Windows\\System32\\CoreUIComponents.dll", "C:\\Windows\\System32\\CoreMessaging.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\SYSTEM32\\wintypes.dll" ], "runtime_window_title": "Manage the TPM security hardware" }, "tpmvscmgr.exe-42CCDF06971545E08763B74ED74E5C0F": { "file_name": "tpmvscmgr.exe", "file_path": "C:\\Windows\\system32\\tpmvscmgr.exe", "hash_md5": "42CCDF06971545E08763B74ED74E5C0F", "hash_sha1": "0F83DB9B2CCA397F7D3B7C60374E4F7A173B9578", "hash_sha256": "93BAC4D5013074DBE590BEDED6CF4A9CFF601AC0DACFAAFA79D8CFB698FE7B4C", "hash_sha384": "1E19B3AD6FC2625B4FC1AAACEB970C56F804769BC66ED18352B5FCDF4091851F0182F5B38AEEA4B4AAEF7C7CB8089B99", "hash_sha512": "7AA40899E945FF69E7568D6FF97E032BE0E7DC88756CAAEB76C16D42661111FC4632F9CEB96A3FC41C3321A956637E26EF8D42E55809166AE6A2BA03D1249672", "hash_ssdeep": "3072:K9qC82ZNmaPEhdt/yFvYH9K6hr277WvvJia8xDUPeO35:K9XV2hh9eGvB6O", "hash_imp": "E7BC6345875250D0B05D11D154C20848", "hash_pesha1": "5E50A49D35DF9B18214B5A8BFAA5611D1EA1ED38", "hash_pe256": "A39DD1B03FF9DEDD7AE9C0D1AB07D6D8B6B775DD1ED02D5368BD113648551001", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TPM Virtual Smartcard Setup Utility", "meta_original_filename": "TpmVscMgr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/93bac4d5013074dbe590beded6cf4a9cff601ac0dacfaafa79d8cfb698fe7b4c/detection/", "error": "Unknown action: /-help\r\nTpmVscMgr.exe \r\n \r\n Commands: \r\n\tcreate \r\n\t\t[/quiet] \r\n\t\t/name <name> \r\n\t\t/adminkey 'PROMPT'|'DEFAULT'|'RANDOM' \r\n\t\t[/puk 'PROMPT'|'DEFAULT'] \r\n\t\t/pin 'PROMPT'|'DEFAULT' \r\n\t\t[/generate] \r\n\t\t[/machine <machine name>] \r\n\t\t[/pinpolicy [policy options]] \r\n\t\t policy options: \r\n\t\t\tminlen <minimum PIN length> \r\n\t\t\tmaxlen <maximum PIN length> \r\n\t\t\tuppercase 'ALLOWED'|'DISALLOWED'|'REQUIRED' \r\n\t\t\tlowercase 'ALLOWED'|'DISALLOWED'|'REQUIRED' \r\n\t\t\tdigits 'ALLOWED'|'DISALLOWED'|'REQUIRED' \r\n\t\t\tspecialchars 'ALLOWED'|'DISALLOWED'|'REQUIRED' \r\n\t\t[/attestation 'AIK_AND_CERT'|'AIK_ONLY'] \r\n \r\n\tdestroy \r\n\t\t[/quiet] \r\n\t\t/instance <device instance ID> \r\n\t\t[/machine <machine name>] \r\n \r\n Legend: \r\n\t\t'PROMPT' => prompt for parameter \r\n\t\t'DEFAULT' => default value for parameter \r\n\t\t'RANDOM' => generate a random value \r\n\t\t'ALLOWED' => these characters are allowed \r\n\t\t'DISALLOWED' => these characters are not \r\n\t\t allowed \r\n\t\t'REQUIRED' => at least one such character \r\n\t\t is required \r\n\t\t'AIK_AND_CERT' => Creates an AIK and obtains\r\n\t\t an AIK certificate from the cloud CA \r\n\t\t'AIK_ONLY' => Creates an AIK but \r\n\t\t does not obtain an AIK certificate \r\n \r\n Note: \r\n\t\tThe generate command formats the TPM \r\n\t\tvirtual smart card so that it can be used \r\n\t\tto enroll for certificates. If this option \r\n\t\tis not specified, a card management \r\n\t\tsystem/tool will need to be used to format \r\n\t\tthe card before first use. \r\n \r\n Note: \r\n\t\t/pinpolicy may only be used in conjunction \r\n\t\twith /pin prompt. \r\n \r\n Note: \r\n\t\tThe default PIN policy options are as \r\n\t\tfollows: \r\n\t\t minlen 8 \r\n\t\t maxlen 127 \r\n\t\t uppercase allowed \r\n\t\t lowercase allowed \r\n\t\t digits allowed \r\n\t\t specialchars allowed \r\n\r\n\t\tThe lower and upper bounds on PIN length \r\n\t\tare 4 and 127, respectively. When using \r\n\t\t/pinpolicy, PIN characters must be \r\n\t\tprintable ASCII characters. \r\n \r\n Note: \r\n\t\tIf '/attestation AIK_AND_CERT' is specified, it\r\n\t\tis possible that VSC creation will fail if\r\n\t\tthere is no network connectivity. \r\n Examples: \r\n Create a TPM virtual smart card with default value for \r\n PIN and a random admin key with no attestation: \r\n\r\n\tTpmVscMgr create /name MyVSC /pin default /adminkey random /generate \r\n\r\n Create a TPM virtual smart card with default value for \r\n admin key and a specified PIN policy and attestation method: \r\n\r\n\tTpmVscMgr create /name MyVSC /pin prompt /pinpolicy minlen 4 maxlen 8 \r\n\t /adminkey default /attestation AIK_AND_CERT /generate \r\n\r\n Destroy a TPM virtual smart card using the instance ID \r\n that was returned when the card was created: \r\n\r\n\tTpmVscMgr destroy /instance root\\smartcardreader\\0000\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tpmvscmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\system32\\CRYPTBASE.DLL", "C:\\Windows\\System32\\IMM32.DLL" ] }, "tpmvscmgrsvr.exe-42C77102083CFB4457C006730010ADB3": { "file_name": "tpmvscmgrsvr.exe", "file_path": "C:\\Windows\\system32\\tpmvscmgrsvr.exe", "hash_md5": "42C77102083CFB4457C006730010ADB3", "hash_sha1": "EEC02AD598172D476FF6AB7B409B32E4A5F884AE", "hash_sha256": "1DAAB7AC618071E392A2FF6DE6D8EED170A96E29D064EB67EA9C135E72731B44", "hash_sha384": "1AB33D9993FE325DA98B788EA3519F999D24C7B31AF27EA9218CD7BEFB42A44E2DA78E38F2C5B6572423833CA6E286DE", "hash_sha512": "C03650102BEFA4DBB241C90B73CDD275EFE74675081810B7EC8997A6B1A988F97455451EEDC3FEA039F720605308A8808B5199920800668A069E82C458D8E80E", "hash_ssdeep": "3072:gfqmXhrzv+CP2GTZR44pSNUeVEivvESwDbP:pYdzGCNZR4gSqea7SWb", "hash_imp": "7ECA3682D5DA99F6DCEF0C197A39AC8D", "hash_pesha1": "52BFE02AC828D49B6E0ACFC6EC5298D9C99B18E4", "hash_pe256": "E0B539AF5512C121B5441E37E7EF691A5E8EC7B2B46F2B74179BCEB241B9885D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TPM Virtual Smart Card Manager COM Server", "meta_original_filename": "TpmVscMgrSvr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/1daab7ac618071e392a2ff6de6d8eed170a96e29d064eb67ea9c135e72731b44/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\tpmvscmgrsvr.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC11C4": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\tpmvscmgrsvr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\WinSCard.dll", "C:\\Windows\\system32\\DEVOBJ.dll" ] }, "tracerpt.exe-63C2D43BAD9DBB2EB9406961DFF44A84": { "file_name": "tracerpt.exe", "file_path": "C:\\Windows\\system32\\tracerpt.exe", "hash_md5": "63C2D43BAD9DBB2EB9406961DFF44A84", "hash_sha1": "243D0657DD81DD6C78CFA5DB34E1B9ECBEFAFA40", "hash_sha256": "0D65F590893A350D22F9287DDFFB196AB452E8DD17287FD1A502E13EA8563DA7", "hash_sha384": "FDF6C4DBA43C276C48718CCD93CE23E6D2E7ECA425C071365AE7F46DD5F6F7B4EE932B85F36DDAE5129E5370FA7311D2", "hash_sha512": "C32A9F5EAF20EF2F218D874B320CFD845C82DF82F7AE7299DCBD3496437BC56811A816F7DE35331AF9298C24B0DE7C42A47D5826A25A80506025621F8D44209A", "hash_ssdeep": "6144:N4JwyvnsCtJbP3zkRFZ6HpN3ZAJZWRJDEKdBGf/0rNdDEle3LQ:WGUnsYzcWF4UrNB7Q", "hash_imp": "56C3E7A76BEE5B97592DCD867AB6C40C", "hash_pesha1": "E5C547EFC13F4DB58932EFCC79A3A47D66086FF5", "hash_pe256": "C2AB296D64E1CFD2D82BAA6F1E9ABC41F5588F7128B972568DD32D3ED777292F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Trace Report Tool", "meta_original_filename": "TraceRpt.Exe.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nMicrosoft r TraceRpt.Exe (10.0.17763.1490)\r\n\r\nUsage:\r\n C:\\Windows\\system32\\tracerpt.exe <[-l] <value [value [...]]>|-rt <session_name [session_name [...]]>> [options]\r\n\r\nOptions:\r\n -? Displays context sensitive help.\r\n -config <filename> Settings file containing command options.\r\n -y Answer yes to all questions without prompting.\r\n -f <XML|HTML> Report format.\r\n -of <CSV|EVTX|XML> Dump format, the default is XML.\r\n -en <ANSI|Unicode> Output file encoding. Only allowed with CSV\n output format.\r\n -df <filename> Microsoft specific counting/reporting schema\n file.\r\n -import <filename [filename [...]]> Event Schema import file.\r\n -int <filename> Dump interpreted event structure into\n specified file.\r\n -rts Report raw timestamp in event trace header. \n Can only be used with -o, not -report or\n -summary.\r\n -tmf <filename> Trace Message Format definition file\r\n -tp <value> TMF file search path. Multiple paths can be\n used, separated with ';'.\r\n -i <value> Specifies the provider image path. The\n matching PDB will be located in the Symbol\n Server. Multiple paths can be used, separated\n with ';'.\r\n -pdb <value> Specifies the symbol server path. Multiple\n paths can be used, separated with ';'.\r\n -gmt Convert WPP payload timestamps to GMT time\r\n -rl <value> System Report Level from 1 to 5, the default\n value is 1.\r\n -summary [filename] Summary report text file. Default is\n summary.txt.\r\n -o [filename] Text output file. Default is dumpfile.xml.\r\n -report [filename] Text output report file. Default is\n workload.xml.\r\n -lr Less restrictive; use best effort for events\n not matching event schema.\r\n -export [filename] Event Schema export file. Default is\n schema.man.\r\n [-l] <value [value [...]]> Event Trace log file to process.\r\n -rt <session_name [session_name [...]]> Real-time Event Trace Session data\n source.\r\n\r\nExamples:\r\n tracerpt logfile1.etl logfile2.etl -o logdump.xml -of XML\n tracerpt logfile.etl -o logdmp.xml -of XML -lr -summary logdmp.txt -report logrpt.xml\n tracerpt logfile1.etl logfile2.etl -o -report\n tracerpt logfile.etl counterfile.blg -report logrpt.xml -df schema.xml\n tracerpt -rt \"NT Kernel Logger\" -o logfile.csv -of CSV\n\n" }, "TRACERT.EXE-FE01242CC5414473B0BF3A09D4216D3D": { "file_name": "TRACERT.EXE", "file_path": "C:\\Windows\\system32\\TRACERT.EXE", "hash_md5": "FE01242CC5414473B0BF3A09D4216D3D", "hash_sha1": "6D8D0CE1EB068D30D88376DA5D5E1B133F5D8390", "hash_sha256": "A7A0CB3A7867D8CE594DAEBFC7571EB5CD59BE321D4D45296BE378EFE66109A2", "hash_sha384": "A858F6A9E9B1428FEF4642673BADB6A86474AED39CA75CA47486BC226F0EBD61296E42094269FA71D8EA2F208B9BEC3B", "hash_sha512": "70C253534FD51F0281CE9A58C6EA90B7FF5ADA6A0A22DCF95488E397B9F9C335EF632ECF037A5805C1BEADE529975CDD74D23EEADDF956D70494C451DF9175B9", "hash_ssdeep": "384:NYdbSRXUC+tQnnmoTRw3lYs9Q7aQMlmZL1ysWWlaW:NXj+mnu3Y6QZL1f", "hash_imp": "7A80F2FE2DD40125FA241B4F53DF08D1", "hash_pesha1": "750E5247B4033A42277CB1D874BC1988CDBC7B54", "hash_pe256": "DF347FB5CF06659358F00A845B6D76C82B991ED029E36950992246D6D86B5B94", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Traceroute Command", "meta_original_filename": "tracert.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a7a0cb3a7867d8ce594daebfc7571eb5cd59be321d4d45296be378efe66109a2/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\TRACERT.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\IPHLPAPI.DLL", "C:\\Windows\\system32\\mswsock.dll", "C:\\Windows\\SYSTEM32\\DNSAPI.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\System32\\rasadhlp.dll" ], "output": "--help is not a valid command option.\r\n\r\nUsage: tracert [-d] [-h maximum_hops] [-j host-list] [-w timeout] \r\n [-R] [-S srcaddr] [-4] [-6] target_name\r\n\r\nOptions:\r\n -d Do not resolve addresses to hostnames.\r\n -h maximum_hops Maximum number of hops to search for target.\r\n -j host-list Loose source route along host-list (IPv4-only).\r\n -w timeout Wait timeout milliseconds for each reply.\r\n -R Trace round-trip path (IPv6-only).\r\n -S srcaddr Source address to use (IPv6-only).\r\n -4 Force using IPv4.\r\n -6 Force using IPv6.\r\n" }, "tscon.exe-C00AF21B675DF6DD88EB61BB297B8500": { "file_name": "tscon.exe", "file_path": "C:\\Windows\\system32\\tscon.exe", "hash_md5": "C00AF21B675DF6DD88EB61BB297B8500", "hash_sha1": "FDADC71222269C8E13E7FC1318C2A1469610F96A", "hash_sha256": "2877E57B2490F708413B93D8E8CCFAB21542BF4F7D5EF582C995FB3059E2DBDD", "hash_sha384": "DE4182F19191E9447240599759CC39B04F99DC7F73B3B83F43A76B62C85E0E244F92C07CFE89B558800C164C0C079A8B", "hash_sha512": "9D81F28591294709E491539B52F25BB4797868EE6F6BE86E3FBE58E744CA4114A3E7FDF13C9A48E38904CE984C3F84FC2352044C919CE404C6EB9B2C31FB79ED", "hash_ssdeep": "384:94GaOjrQ0Vd5mIbhzELz58xYK8+iVbCODeuwRH/bJHc5ycZDHbWjigW:nXAcd4UhaeYK8NlCqe5H/bmRN", "hash_imp": "24472C36A35ED9C96546FC249317D860", "hash_pesha1": "3DD216A8DF91B498CBC025FF7D0F91E6009F7F19", "hash_pe256": "DFC0260BB537E68820C1609ED0DD77BAAE3D739D80368D46A7339BF02D1D6E43", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Session Connection Utility", "meta_original_filename": "tscon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/2877e57b2490f708413b93d8e8ccfab21542bf4f7d5ef582c995fb3059e2dbdd/detection/", "output": "Attaches a user session to a remote desktop session.\r\n\r\nTSCON {sessionid | sessionname} [/DEST:sessionname]\r\n [/PASSWORD:pw | /PASSWORD:*] [/V]\r\n\r\n sessionid The ID of the session.\r\n sessionname The name of the session.\r\n /DEST:sessionname Connect the session to destination sessionname.\r\n /PASSWORD:pw Password of user owning identified session.\r\n /V Displays information about the actions performed.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tscon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "error": "Invalid parameter(s)\r\nAttaches a user session to a remote desktop session.\r\n\r\nTSCON {sessionid | sessionname} [/DEST:sessionname]\r\n [/PASSWORD:pw | /PASSWORD:*] [/V]\r\n\r\n sessionid The ID of the session.\r\n sessionname The name of the session.\r\n /DEST:sessionname Connect the session to destination sessionname.\r\n /PASSWORD:pw Password of user owning identified session.\r\n /V Displays information about the actions performed.\r\n\r\n" }, "tsdiscon.exe-FF6DB497822BC8A969A83E70F717EFA2": { "file_name": "tsdiscon.exe", "file_path": "C:\\Windows\\system32\\tsdiscon.exe", "hash_md5": "FF6DB497822BC8A969A83E70F717EFA2", "hash_sha1": "77910AECEA5906537F325738ECC103F24FDDB0AD", "hash_sha256": "7D3104A15F906D28E302B00E440366DDC4C91A4CC9C2806ABD27C123E3009A79", "hash_sha384": "D57273332387D94702A33FF1B841E23EEB8492982DB9E7EBCB91862B53A9355C40858CE1F7ABD4C3C5BE63E0B1412BE5", "hash_sha512": "1D4CCFC0C299394BA1D4DBA6FD088A1A1CF52797BCBA19C79F13943E276C61B64A85A98A7E191AC9F5B70BEC48411CEF339D827D7EF794C7F4674E7AE7980F3F", "hash_ssdeep": "384:iHgA1skjOvoOAslmmRN0E4z5dIcK8umtsdbOwGVrffjdMrQoWjMcZVaUXWMqWW:iHgA1/ymskcNsEcK8ViOVrfZMr0dc", "hash_imp": "3FC6BB9BBEE32550C1847BB966FD1F6C", "hash_pesha1": "46C48ACFE84F8CCF75C933D4C7C37EA0054B698C", "hash_pe256": "0A89973196DE9BA80D5FED8D462A99EF05291488BFC2588F622F63AF81EA99A3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Session Disconnection Utility", "meta_original_filename": "tsdiscon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/7d3104a15f906d28e302b00e440366ddc4c91a4cc9c2806abd27c123e3009a79/detection/", "output": "Disconnects a Remote Desktop Services session.\r\n\r\nTSDISCON [sessionid | sessionname] [/SERVER:servername] [/V] [/VM]\r\n\r\n sessionid The ID of the session.\r\n sessionname The name of the session.\r\n /SERVER:servername Specifies the Remote Desktop Session Host server (default is current).\r\n /V Displays information about the actions performed.\r\n /VM Disconnects session on server or within virtual machine. The unique ID of the session needs to be specified.\r\n\r\n", "error": "Invalid parameter(s)\r\nDisconnects a Remote Desktop Services session.\r\n\r\nTSDISCON [sessionid | sessionname] [/SERVER:servername] [/V] [/VM]\r\n\r\n sessionid The ID of the session.\r\n sessionname The name of the session.\r\n /SERVER:servername Specifies the Remote Desktop Session Host server (default is current).\r\n /V Displays information about the actions performed.\r\n /VM Disconnects session on server or within virtual machine. The unique ID of the session needs to be specified.\r\n\r\n" }, "tsecimp.exe-07EBFCFC505D089DDE8452CB9B0ED834": { "file_name": "tsecimp.exe", "file_path": "C:\\Windows\\system32\\tsecimp.exe", "hash_md5": "07EBFCFC505D089DDE8452CB9B0ED834", "hash_sha1": "55CDD1691B3B43AC1215C7DACA95E9C6FC12120A", "hash_sha256": "29D1216A866F09D88DE8F9825DD62FE27A6981F4116DCEB2EF8376EA701259E6", "hash_sha384": "230F47AC244B89572D3BEC45B172DA8DC4BA4A14003B400A23AD3F7E62678A4F7F36FDD410F09F1DC86B6CD4B4C6C1C7", "hash_sha512": "63A07B17B9CF6CFC92763C7AC4595026EB9536E9E37AC750FF6461319C184F955311164B40EECDD308322A52A627CB2B15F1945B832B5280A90AF2295B25F16B", "hash_ssdeep": "384:2ogQnqWCY9Ft7h6weGqrkByS6aE/3nXaWyezEioduMmt/1ULAia6Cj+J0l2Wqr40:/fnqWLBb6k4a05h4MtJfiFC+I0+KC", "hash_imp": "7AB7329133389F594CF54872DDA762B9", "hash_pesha1": "52AD924C8A0873A873FD38647C5319811D8592ED", "hash_pe256": "5ABE99FCF10686F7F9E14DB767D583FB632C36420A7D9480130E080185880F27", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) TAPI Security File Importer", "meta_original_filename": "TSECIMP.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/29d1216a866f09d88de8f9825dd62fe27a6981f4116dceb2ef8376ea701259e6/detection/", "output": "Microsoft Windows(TM) TAPI Security File Importer\r\n\r\nThe syntax of this command is:\r\n\r\ntsecimp {-?|-h |-H} | { [ {-v|-V} | {-u|-U} ] -f filename} | {-d|-D}\r\n\r\n-?|-h|-H\tTo print this help page\r\n-v|-V\t\tValidate the input XML file only\r\n-u|-U\t\tValidate user accounts (slower)\r\n-f filename\tThe XML file to be processed\r\n-d|-D\t\tDisplay current configuration\r\n\r\n", "children": [ "csrss.exe", "wininit.exe" ] }, "tskill.exe-ECB28BE6AB10EC79A0E817A27F9AA6DD": { "file_name": "tskill.exe", "file_path": "C:\\Windows\\system32\\tskill.exe", "hash_md5": "ECB28BE6AB10EC79A0E817A27F9AA6DD", "hash_sha1": "2D2F4442D825FBF47E9D4081738211BB2C6532D7", "hash_sha256": "56E8D6C41D904C855FC44BC50E7460AC0D1803111C0C8032B12C00B3C0482816", "hash_sha384": "4D7843AA7B77A4F52EB5E82946722A9C5BD87F2B88F22B8FF7FD6F39DB6C95E98AD9D83042574EB0D864C7C0C43A5015", "hash_sha512": "06DD864E107E835100F31E20EE32D70600E1914A9F017D90EF6A7C183EC735C50F10D55F2351781B9212C64FA8FE12D556585EAA26BFDFE66D32845382540EC5", "hash_ssdeep": "384:i3siK/v9kWMiajErDSPVQgE4z5mtpBK8bgqKl4uwkU2oTAUHWqSUZp51wCW4wQW:i8Ph9TrDS9QwA7BK8brKZwPXAQLIB", "hash_imp": "0568AF4DCDD3B8A976BBBBC1530C6847", "hash_pesha1": "BC46D5579AE3FE633C2B78747A394F1E44774575", "hash_pe256": "C48509A6853221E7E4C85BB8CEEA7D09D6D0FD420C4835624275638B1CDF455D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Services End Process Utility", "meta_original_filename": "tskill.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/56e8d6c41d904c855fc44bc50e7460ac0d1803111c0c8032b12c00b3c0482816/detection/", "error": "Invalid parameter(s)\r\nEnds a process.\r\n\r\nTSKILL processid | processname [/SERVER:servername] [/ID:sessionid | /A] [/V]\r\n\r\n processid Process ID for the process to be terminated.\r\n processname Process name to be terminated.\r\n /SERVER:servername Server containing processID (default is current).\r\n /ID or /A must be specified when using processname\r\n and /SERVER\r\n /ID:sessionid End process running under the specified session.\r\n /A End process running under ALL sessions.\r\n /V Display information about actions being performed.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tskill.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\WINSTA.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "TSTheme.exe-7F664C2449A91878B131716D2DD79553": { "file_name": "TSTheme.exe", "file_path": "C:\\Windows\\system32\\TSTheme.exe", "hash_md5": "7F664C2449A91878B131716D2DD79553", "hash_sha1": "9BF3F1EF045E15BF6B2B941A67BB4918222DB362", "hash_sha256": "0DA195AECD8794062AB5CB3BDEF2BE0230C1E76050C7B11CF609E4F3F23A9DDC", "hash_sha384": "9D7526C80131BA671970B3BB7962D61955F2B2708750DE17B20298C3C504D70D1DED7EA58E073DE7BE0D566BCA2E7F9A", "hash_sha512": "4986387C88D7165CB8B871C48478235C76B9845F8B3053A093936269C5D2A662A940E385744E001703428945E477D3600899E380854A60D4BC54D582AA6163A9", "hash_ssdeep": "1536:YhT+AO0YYhOi/oX6CJYX0YOWbKuhuEiiGWv2:Y9+qpoX1U0YOshuEi9W+", "hash_imp": "B70390445EE6DE87340DFE5CB7439893", "hash_pesha1": "D3392E1A944486152FA4C0CF8BA23843E0BBAD34", "hash_pe256": "66D627187EC252BD70A503D6FB35F0B4B362EA9EC77A67AEC7A86056F2FD9DF0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TSTheme Server Module", "meta_original_filename": "TSThemeS.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/0da195aecd8794062ab5cb3bdef2be0230c1e76050c7b11cf609e4f3f23a9ddc/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\TSTheme.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECA50": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\TSTheme.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ] }, "TSWbPrxy.exe-F1C0EECC4E95C1DC84D3A0324F765D4C": { "file_name": "TSWbPrxy.exe", "file_path": "C:\\Windows\\system32\\TSWbPrxy.exe", "hash_md5": "F1C0EECC4E95C1DC84D3A0324F765D4C", "hash_sha1": "165E0D17CE0915851AE16BFB16151537B313FD02", "hash_sha256": "8C4EB1CFB1A741D23F4598218FFE3654DDC8E02485D718A823C24A7C7E899401", "hash_sha384": "F558ED334BC4C3539A43A06904A2180634E46A6BCA4F83F744856BDD6D49BC28C1EA78E5B38BF08FE5D9AA9F3C236D3E", "hash_sha512": "0C1D2F810C5D9AAC24867B1A41282A1CE6CF0C91A7F6782C0701FF89126045A2BC36F90B9B7D78B5AC396EA50AF402037F68FA60616D6981A0DA2F9B561EEFAF", "hash_ssdeep": "1536:SqnMwN1hNfe6sTWjR8raGiyBX5BbqB8rI6Srqsaw+NhQ:S8fm6DR8OGpfb68s6sL", "hash_imp": "BA735407B23D456EDCE8E1D15A38BD7B", "hash_pesha1": "CA0313AC6910557C41343663ECD1C0550D5F6853", "hash_pe256": "54342F66D14D2CEFE4641511A3AC5129177BED2F63E3F1569E67F57D59A23989", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Remote Desktop Services Web Proxy", "meta_original_filename": "TSWbPrxy.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/8c4eb1cfb1a741d23f4598218ffe3654ddc8e02485d718a823c24a7c7e899401/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC108C": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\TSWbPrxy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll" ] }, "ttdinject.exe-4397196D35B96EB6B55DA0F8D86AB79D": { "file_name": "ttdinject.exe", "file_path": "C:\\Windows\\system32\\ttdinject.exe", "hash_md5": "4397196D35B96EB6B55DA0F8D86AB79D", "hash_sha1": "C43DFC99F5F0EB3F0A133DA791CD5D1362DD27B1", "hash_sha256": "C071BA0575AC5C43A97AAC99AB5AFC12B0D8B753FC575DE07E893906C1DC003E", "hash_sha384": "EAE5F5F58810D22249D9753487138AC0EC4CEE44896F75ACC2784200840695059DE16975391BDAFFAF253017B64919AC", "hash_sha512": "4CECB003425901BCB12ECE2F20862850C115D6359D4214E5B34DB11E6EAEB2BE024293F5B89526217264B10164DB9CD899028D0678BF50C3A37A9E8D0C221312", "hash_ssdeep": "6144:UXqEDI4QDdGJl7DSkMVIvQ6mkwgzj7vckk5kVbRle/CMrVMb/7Gv:UXtgip/fYKbRcDrVMr", "hash_imp": "8D51D50F8F759EDF48244E7F3AC1AE0A", "hash_pesha1": "3C956A54504C62CA445F94362ABCA9342C325F9F", "hash_pe256": "7B1041097B7DD406D73CD77513376730A77BD32B0DBCFE8AF28CD26E88B6012E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Time Traver Debugger Application Launcher", "meta_original_filename": "TTDInject.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/c071ba0575ac5c43a97aac99ab5afc12b0d8b753fc575de07e893906c1dc003e/detection/", "output": "Microsoft (R) TTDInject Launcher 1.01.03\r\nRelease: 10.0.17763.1\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n", "children": [ "csrss.exe", "wininit.exe" ], "error": "\b\b\b!!! Unexpected string 'help' after 'C:\\Windows\\system32\\ttdinject.exe'\r\n\r\n" }, "tttracer.exe-9EAFF78CE415BC5475FC24C1B86FB0D5": { "file_name": "tttracer.exe", "file_path": "C:\\Windows\\system32\\tttracer.exe", "hash_md5": "9EAFF78CE415BC5475FC24C1B86FB0D5", "hash_sha1": "275D7657F35575291C7A18C01FD964C97C377C65", "hash_sha256": "4D94208E7D497B5BEDD481263FEA903C9CD66962A5DBA9F5353CCA15FAF0D9FD", "hash_sha384": "0A305E8279170F3D67CFCC4E9A5941C928A0628F8C6BE3A03C12767001DB7A287C8438B061F02465D6A09A91D4479752", "hash_sha512": "4C1D73D136DE4B57CD3E0F6CAB14B13E26375279D1BB51C0641BE23E9A9B063B50F8FDB29B0F1066255A50113CBA86EF3E4D5EBDAB61AC63B986D12198CA3216", "hash_ssdeep": "6144:zRe4oPhepmdFB47+E1q9pyMFOIDixHmev9:g4oP0mcWHRiJm29", "hash_imp": "2DD7AC615E10A236D551AAFD2B7BB0B7", "hash_pesha1": "859DC01FD5EA1329D7FC4E112B9B271556B009E2", "hash_pe256": "77E3A77906B506DD41C963F003A97DD8CB0EEB88AA779A23D4158626F28856AF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Time Travel Tracing Tracer Tool", "meta_original_filename": "TTTracer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/4d94208e7d497b5bedd481263fea903c9cd66962a5dba9f5353cca15faf0d9fd/detection/", "output": "Microsoft (R) TTTracer 1.01.03\r\nRelease: 10.0.17763.1\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n", "error": "MICROSOFT TIME TRAVEL DEBUGGING (TTD)\r\r\n\r\r\nTime Travel Debugging (TTD) command line utility is not meant for use in custom software or\r\r\nautomation. TTD is included with this version of Windows to improve diagnostics gathering and is not\r\r\nintended for direct use as a stand-alone solution.\r\r\n\r\r\nDISCLAIMER OF WARRANTY. THE SOFTWARE IS LICENSED \"AS IS.\" YOU BEAR THE RISK OF USING IT. MICROSOFT\r\r\nGIVES NO EXPRESS WARRANTIES, GUARANTEES, OR CONDITIONS. TO THE EXTENT PERMITTED UNDER APPLICABLE LAWS,\r\r\nMICROSOFT EXCLUDES ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE,\r\r\nAND NON-INFRINGEMENT.\r\r\n\r\r\n1. DATA COLLECTION. The software may collect information about you and your use of the software and send\r\r\n that to Microsoft. Microsoft may use this information to provide services and improve Microsoft's\r\r\n products and services. Your opt-out rights, if any, are described in the product documentation. Some\r\r\n features in the software may enable collection of data from users of your applications that access or\r\r\n use the software. If you use these features to enable data collection in your applications, you must\r\r\n comply with applicable law, including getting any required user consent, and maintain a prominent\r\r\n privacy policy that accurately informs users about how you use, collect, and share their data. You can\r\r\n learn more about Microsoft's data collection and use in the product documentation and the Microsoft\r\r\n Privacy Statement at https://go.microsoft.com/fwlink/?LinkId=521839. You agree to comply with all\r\r\n applicable provisions of the Microsoft Privacy Statement.\r\r\n\r\r\n2. SCOPE OF LICENSE. The software is licensed, not sold. Microsoft reserves all other rights. Unless\r\r\n applicable law gives you more rights despite this limitation, you will not (and have no right to):\r\r\n a) work around any technical limitations in the software that only allow you to use it in certain ways;\r\r\n b) reverse engineer, decompile or disassemble the software;\r\r\n c) remove, minimize, block, or modify any notices of Microsoft or its suppliers in the software;\r\r\n d) use the software for commercial, non-profit, or revenue-generating activities;\r\r\n e) use the software in any way that is against the law or to create or propagate malware; or\r\r\n f) share, publish, distribute, or lend the software, provide the software as a stand-alone hosted\r\r\n solution for others to use, or transfer the software or this agreement to any third party.\r\r\n\r\r\n3. SUPPORT SERVICES. Microsoft is not obligated under this agreement to provide any support services\r\r\n for the software. Any support provided is \"as is\", \"with all faults\", and without warranty of any kind.\r\r\n\r\n", "children": [ "conhost.exe", "help.exe", "ttdinject.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RWD) C:\\Users\\user\\help01.run": "File", "(---) C:\\Users\\user\\help01.out": "File", "\\BaseNamedObjects\\ttdSeq_s_2_01_03": "Section", "\\Sessions\\2\\BaseNamedObjects\\ttd_s_2_01_03_1164": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\tttracer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "typeperf.exe-D2B0060C7624A4E7BD899170D4C9D050": { "file_name": "typeperf.exe", "file_path": "C:\\Windows\\system32\\typeperf.exe", "hash_md5": "D2B0060C7624A4E7BD899170D4C9D050", "hash_sha1": "A3FE05127C8A352604BF3D0AE8516F79334D461E", "hash_sha256": "1D0B5DAF3B8CF646E277597709A1592731D44C816A6665818EE3A1EF54E65FC2", "hash_sha384": "28955AABAD1D732BA1F5756B8EA8B2FF52C581F52149BAEEC5CAA519C4E06532776EAAC0A2A0D6DAEC262B87BA4B01CA", "hash_sha512": "2FAFEBBBDB0ED170B52B612DC3EFCF767D461DEDCCE83BCC38F8132336D4134D82CDB72B595132804023579074BE1A063B81D65647BB325836560AC405A97DD2", "hash_ssdeep": "768:Q+mKvnjthMTEXzbOhX4ijj71giN8IBfBJ9yfMjBQMUpdEj7+DUjCJHroaMN4uLF5:7jdEjfii1BJJ99nUpWj1CdMaMNV5", "hash_imp": "6C6EF5458AE158C242617DDB457DC4C9", "hash_pesha1": "68E132EBA8CCE66AA7E6E504D6587981C78D7CEE", "hash_pe256": "4BAA6E9594B2757E8190C42227338794DCE26351EEA7FD1AADC8930401B0FB49", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command line performance monitor", "meta_original_filename": "TypePerf.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/1d0b5daf3b8cf646e277597709a1592731d44c816a6665818ee3a1ef54e65fc2/detection/", "output": "\r\nMicrosoft r TypePerf.exe (10.0.17763.1)\r\n\r\nTypeperf writes performance data to the command window or to a log file. To\r\nstop Typeperf, press CTRL+C.\r\n\r\nUsage:\r\nC:\\Windows\\system32\\typeperf.exe { <counter [counter ...]> \r\n | -cf <filename> \r\n | -q [object] \r\n | -qx [object] \r\n } [options]\r\n\r\nParameters:\r\n <counter [counter ...]> Performance counters to monitor.\r\n\nOptions:\r\n -? Displays context sensitive help.\r\n -f <CSV|TSV|BIN|SQL> Output file format. Default is CSV.\r\n -cf <filename> File containing performance counters to\r\n monitor, one per line.\r\n -si <[[hh:]mm:]ss> Time between samples. Default is 1 second.\r\n -o <filename> Path of output file or SQL database. Default\r\n is STDOUT.\r\n -q [object] List installed counters (no instances). To\r\n list counters for one object, include the\r\n object name, such as Processor.\r\n -qx [object] List installed counters with instances. To\r\n list counters for one object, include the\r\n object name, such as Processor.\r\n -sc <samples> Number of samples to collect. Default is to\r\n sample until CTRL+C.\r\n -config <filename> Settings file containing command options.\r\n -s <computer_name> Server to monitor if no server is specified\r\n in the counter path.\r\n -y Answer yes to all questions without prompting.\r\n\r\nNote:\r\n Counter is the full name of a performance counter in\r\n \"\\\\<Computer>\\<Object>(<Instance>)\\<Counter>\" format,\r\n such as \"\\\\Server1\\Processor(0)\\% User Time\".\r\n\r\nExamples:\r\n typeperf \"\\Processor(_Total)\\% Processor Time\"\r\n typeperf -cf counters.txt -si 5 -sc 50 -f TSV -o domain2.tsv\r\n typeperf -qx PhysicalDisk -o counters.txt\r\n", "runtime_modules": [ "C:\\Windows\\system32\\typeperf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\pdh.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "tzsync.exe-5BB8DEB569B92CAE95617286BD25ED99": { "file_name": "tzsync.exe", "file_path": "C:\\Windows\\system32\\tzsync.exe", "hash_md5": "5BB8DEB569B92CAE95617286BD25ED99", "hash_sha1": "FA842CE6A2778035F902B93AC7D855D30934EF34", "hash_sha256": "26A12639EF4893A2A9FB3970661956B21C500B8A61D8B07DDE53100A17970559", "hash_sha384": "69D6D5D8F1A983748B1B865F3D77344352BCEC56E422D949D65E9D1256F7AED3B830965FF55AFC6CC27691F348F56761", "hash_sha512": "6FAD287E42E71E39E6D0874F09419921F8C7A6404CFF62EDD130883BD0954924F79849FF4418AC92A6D33857DBD92F25C908E8A050EA22ABE04D343BBFCEC7FF", "hash_ssdeep": "768:AMO7WXWGRTSkGJR2YW8buEhXt9us3AC6fe7MGMEf9jZpAXDRXBfjPQ:uGlSXP2H8b/hdEs3AXL1+", "hash_imp": "n/a", "hash_pesha1": "CE41D5A2CDFA0E11749B8D99BCF49DB3DEF13BEA", "hash_pe256": "62C88D5221F3A4A377C8056D030DD13974525586FCC393AC1625D0342732C229", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TimeZone Sync Task", "meta_original_filename": "tzsync.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/26a12639ef4893a2a9fb3970661956b21c500b8a61d8b07dde53100a17970559/detection/", "runtime_modules": [ "C:\\Windows\\system32\\tzsync.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "tzutil.exe-9DAABD70528904EA05C5605D2FC75717": { "file_name": "tzutil.exe", "file_path": "C:\\Windows\\system32\\tzutil.exe", "hash_md5": "9DAABD70528904EA05C5605D2FC75717", "hash_sha1": "3B4BAB8731706768D412CF75376DA23283EA1602", "hash_sha256": "C65E9D883299477C6F26AFC78139038B81D33A03CFED9172410D9FEBE5576C12", "hash_sha384": "24DCF30A45BA3F7C4F50AE676D2D2A03614C4D235CEC83B0E8739779235CA788C26128BBD964F5B3E0B4EDE17794907B", "hash_sha512": "AC326949F3399CE7CF5EAFB742AB3BF8DF8AA696F6BDCA4BD4946868125A126945F31FC5E054AD9D4AFA08F1892DE99364F7C4D253A395AD103DB2293450053C", "hash_ssdeep": "768:kEhcXK5+RltDFBkyX29DhPMkQRjprTllDyVO1vTzwSI1YCmoBoD2O:JhcX+Yl3+o2WHuYHwAX2oD2O", "hash_imp": "2F5915A9C19B98144A69C2036DC4B667", "hash_pesha1": "BC652A6687703FB6DAEAA673A8B7E5BFC631A049", "hash_pe256": "F8D8CE39C78321FA3A1FC23C465A7DAEA4C1F87D962728C7EB245CA32CE66B25", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Time Zone Utility", "meta_original_filename": "tzutil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/c65e9d883299477c6f26afc78139038b81d33a03cfed9172410d9febe5576c12/detection/", "output": "Windows Time Zone Utility\r\n\r\nUsage:\r\nTZUTIL </? | /g | /s TimeZoneID[_dstoff] | /l>\r\n\r\nParameters:\r\n /? Displays usage information.\r\n\r\n /g Displays the current time zone ID.\r\n\r\n /s TimeZoneID[_dstoff]\r\n Sets the current time zone using the specified time zone ID.\r\n The _dstoff suffix disables Daylight Saving Time adjustments\r\n for the time zone (where applicable).\r\n\r\n /l Lists all valid time zone IDs and display names. The output will\r\n be: \r\n <display name>\r\n <time zone ID>\r\n\r\nExamples:\r\n TZUTIL /g\r\n TZUTIL /s \"Pacific Standard Time\"\r\n TZUTIL /s \"Pacific Standard Time_dstoff\"\r\n\r\nRemarks:\r\n An exit code of 0 indicates the command completed successfully.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\tzutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "ucsvc.exe-9A8FCC488BA62A6B3719A608E605C4B3": { "file_name": "ucsvc.exe", "file_path": "C:\\Windows\\system32\\ucsvc.exe", "hash_md5": "9A8FCC488BA62A6B3719A608E605C4B3", "hash_sha1": "48A6CBD45C467A189303FD38DFD362E1DEF42158", "hash_sha256": "B36628817A85B2491CB70B6F1F7283C5C9CCB7EFDE9ACE06AE09A9360BCDBB53", "hash_sha384": "3BE037524F8C8E0473025E6DF708BCAC99ED1CA5BB7DFED836464F94F2FD698068FD81F690745DC1278A38666C93046A", "hash_sha512": "8BF7E129C2E6B98DB8384D09445242332CF0BB834FCB1E84F07952725A12215A252E43B63A2D92379A8FD9DE0F027FBFFF6526534607CFC7A960BE8ED6817735", "hash_ssdeep": "1536:4NXPgCE66sI0vmJr7u4yIUk0vG9m0+oLjvpPY:+g166shuV7u4y60vGIBoHBg", "hash_imp": "0E0328595A346203B68DE1869CCFF8C2", "hash_pesha1": "CE44E04F40A182D28FD67D254418F0B09AA01E06", "hash_pe256": "F8D4903DB2B0190D4D3608D0263110977564DEA7B1381EC82C6274A9CAB5CD40", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Boot File Servicing Utility", "meta_original_filename": "bfsvc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b36628817a85b2491cb70b6f1f7283c5c9ccb7efde9ace06ae09a9360bcdbb53/detection/" }, "UevAgentPolicyGenerator.exe-23DEA2A17AB38BB991A593070F4CEC6A": { "file_name": "UevAgentPolicyGenerator.exe", "file_path": "C:\\Windows\\system32\\UevAgentPolicyGenerator.exe", "hash_md5": "23DEA2A17AB38BB991A593070F4CEC6A", "hash_sha1": "DAE2E8C518E7E978F0BB8C249B705340E15EBC14", "hash_sha256": "338A5550F705A07286DE0747D94E247FDEAB2850CD215EE7DAE976DAFCEDDA7F", "hash_sha384": "9B68307DAEC979282225548FC340D8609170F2401DF0FBC457387B313216C024E643C54715014C45E63503689743EA7F", "hash_sha512": "72562BE8299439BFBDD06EBE5E90F3CD034F124440E0B38416BB6AC6C98DBD8045519B4AE0113153F5D8056A0BF45E4B7335D6499E0AE9C59554ACA671E8D906", "hash_ssdeep": "384:tZm0fhsl8PKzKq06MUt3jt/KJSaI3DDvQS114fOmDH1J/8rfZuKRSfDOya2VFkm8:tkllzqD2ZRP2VFk8vnjHn6twxY", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "BC45AF368EC118C279DBFFFFB5F7E31FFD5B5381", "hash_pe256": "8A881133E47B2A5A4CA824E0A71DE47F6D3D18D33673930298363C1A2680458A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "UevAgentPolicyGenerator.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1", "meta_product_version": "10.0.17763.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/338a5550f705a07286de0747d94e247fdeab2850cd215ee7dae976dafcedda7f/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_b4b635d36e735c2c": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\UevAgentPolicyGenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "UevAgentPolicyGenerator.exe - This application could not be started." }, "UevAppMonitor.exe-C3163D61262081660226C0A8047F8A67": { "file_name": "UevAppMonitor.exe", "file_path": "C:\\Windows\\system32\\UevAppMonitor.exe", "hash_md5": "C3163D61262081660226C0A8047F8A67", "hash_sha1": "D466BBFE1A95060BA31E589B692B655BAEE2F1A4", "hash_sha256": "07BA56ACA60F76DD7FF7261C25A653A5F1E55CCE9D30842F8169C364923DC165", "hash_sha384": "F68B82E6EAC720313E0C54DDBEC6D937BD3D292CE4B77FCF71FD7523C5F99337CE3516FADB6DD1DABCBB47B64B168B5A", "hash_sha512": "DCFCDA858257C21C6E7B47FC431C517FC1DB21C8049E8DEE48A1866AF797B4BBAF0020212EE7A6CDEA7E72F614DB98A8E493099325BDBA7A9EF726C7EDCCC3B2", "hash_ssdeep": "768:3N0yKm62+wl+A191slxN+u996swwiKEtycTY5lkQ7Vy9ylDXo:zKyj91szN++6NwiKE10Djl8", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "5D3A9F099E90B5C1F5673BCA750EEDCBAADE0529", "hash_pe256": "6E998E0D2518255A5C4D8BBDDCF97C5688737700E0B03E359ACB972EF8A1A63B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "UevAppMonitor.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.348", "meta_product_version": "10.0.17763.348", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/07ba56aca60f76dd7ff7261c25a653a5f1e55cce9d30842f8169c364923dc165/detection/", "runtime_modules": [ "C:\\Windows\\system32\\UevAppMonitor.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "UevTemplateBaselineGenerator.exe-D748880CFCC6FC33A14BD6A9CF7CCF25": { "file_name": "UevTemplateBaselineGenerator.exe", "file_path": "C:\\Windows\\system32\\UevTemplateBaselineGenerator.exe", "hash_md5": "D748880CFCC6FC33A14BD6A9CF7CCF25", "hash_sha1": "453C43A0E55AE3CD1A9AE65E566C52B40236AEAE", "hash_sha256": "B188598D844F927A8B361622A6E16E004D7D1BC6D86D0DF17B2E1A66995D0EA3", "hash_sha384": "56B759F7D03254D80A36464642D5B0D9AB36FA29A13067A256CD91F171996A2272082EB8063BBFAFA688FE9770BBEBFD", "hash_sha512": "1F03F6AE73CB4B85F3CD3F630C4BE814D70F01A3838B2439EF200620532876BBAC5F9CF22D1CF695344D1EE4B39D495E5732B8E093EB0E5BC13944602B4D3A8F", "hash_ssdeep": "384:/aL8CUA6oNTSAkBcYKPdIQX6GIp0t6PMSK+NWIJWGZ:y4CbTSviBqAIp", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "158986A1551EDE77D3E0A2C0CE181E5E8297CE7C", "hash_pe256": "260F8A82194BED50D0669A6388BBFC8C97C8183255CF6F3A786E6F6B92A3853A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "UevTemplateBaselineGenerator.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1", "meta_product_version": "10.0.17763.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b188598d844f927a8b361622a6e16e004d7d1bc6d86d0df17b2e1a66995d0ea3/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_b4b635d36e735c2c": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\UevTemplateBaselineGenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "UevTemplateBaselineGenerator.exe - This application could not be started." }, "UevTemplateConfigItemGenerator.exe-45FB133A09574504B7548E74E3A27992": { "file_name": "UevTemplateConfigItemGenerator.exe", "file_path": "C:\\Windows\\system32\\UevTemplateConfigItemGenerator.exe", "hash_md5": "45FB133A09574504B7548E74E3A27992", "hash_sha1": "BFD0D23624371D54FAD847C4EB76009F0E435352", "hash_sha256": "DEC77615D3A9750AC4DAD68BDA96C4794033CDFF2C3E52E99EE0934326943663", "hash_sha384": "F67B941F01E6B08A375920CECE50A381D1C8E3CB245682DBCE7540A88771F6EDF6E376963CAAB88ACDD985CBA2F53AF5", "hash_sha512": "8F81597DE061EDFD5B619B1A18C5C54F884E0F53B922FB946C6F8AAB4FEC00DD0F40FE5C776B35B5B1E6F0EAFCDBC08D885EBD18E5FC5C6A8121D6BAC84C1B0F", "hash_ssdeep": "192:xq0JHU41GGkZ1ElGTubagmrCdsa/2pk0rqWp8eMPOHnGW8FW4zv:c0pU4G1MCIbmOdsa/2psWp8esW8FW4L", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "71591D9CC9EF214CD7E7558473F97B6CC308C482", "hash_pe256": "C93645E0DB9C59CA1B3CBE33F738A4AF220464644683AD08F26D9325ECDECD7A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "UevTemplateConfigItemGenerator.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1", "meta_product_version": "10.0.17763.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/dec77615d3a9750ac4dad68bda96c4794033cdff2c3e52e99ee0934326943663/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_b4b635d36e735c2c": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\UevTemplateConfigItemGenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "UevTemplateConfigItemGenerator.exe - This application could not be started." }, "UIMgrBroker.exe-B0D3EEB36512235D76B00F883DA3C231": { "file_name": "UIMgrBroker.exe", "file_path": "C:\\Windows\\system32\\UIMgrBroker.exe", "hash_md5": "B0D3EEB36512235D76B00F883DA3C231", "hash_sha1": "B3CF26D0DEF2B20DE4F05571EBC8A093D926E089", "hash_sha256": "B09DCFEDBB4A4F39A0F0D854D20842123DE9D75163821DDBDDC9AC4E149A2FDB", "hash_sha384": "E355C1761E05B546A9B3EB2E9B450A79EC7ACFD4CA075C72F82B9E324DD063EA8096011E81D90C2B1FD13586C1FC5B92", "hash_sha512": "D5C77EA12A8C4EB0D69422C4F20F3279194EAE9F28F027C3A6CDF9C5AE0149F6181CCD58B032C379DDF8DF87EAB7D5DA1F8BAB77303A4768382066B7E2BF6F7F", "hash_ssdeep": "768:5fc7opvzYTqQfm9wIRviJbsRvPVPZ1MUl/CEkAf9Fq8LkQBPWB9iNz:yoEqQoMJbWH/SUgef9Fq32PWB9Mz", "hash_imp": "68B9DCA137FA8179CE80445E610B5C16", "hash_pesha1": "10E7792B7378A0DE48395D99672F60AA575958A4", "hash_pe256": "83F7298E1C40902E9230B5D71833462DE3E96DFD072CA5FB5D0ACFF8CA5E06F9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft UIManager Broker", "meta_original_filename": "UIMgrBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1339 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1339", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/b09dcfedbb4a4f39a0f0d854d20842123de9d75163821ddbddc9ac4e149a2fdb/detection/", "runtime_modules": [ "C:\\Windows\\system32\\UIMgrBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll" ] }, "unlodctr.exe-4848684A588767F7CFFCB3A4A082298C": { "file_name": "unlodctr.exe", "file_path": "C:\\Windows\\system32\\unlodctr.exe", "hash_md5": "4848684A588767F7CFFCB3A4A082298C", "hash_sha1": "0E0FD513510B023AE108BF6FB62F490627415B4C", "hash_sha256": "9B602BD2CF08116F97E1027DD3E298CE5E2B68E80BED44F036F05B69A3FEF611", "hash_sha384": "C81A4E2FE575FB05510FE0D35C4CCC6FA1312110B446F449AF6515BCF8C5A77D9D708394651F0914E52719AE473E56B9", "hash_sha512": "F74D965F60FB1DA090A01A2CD79120A186AB05792FB33D97CD7475AC53DBA2E019A230368DD7DB2D373C2A3CB5FA0BF757589675545D0CEF9D173F3DE2F094AB", "hash_ssdeep": "768:g9NoRoVpmPn7iPm/e8JbRbUAQetzNBwSsplMcAF91hBMNfrY/6k:8lVY/eY9brQetzNBwXlMcsWNf8/6k", "hash_imp": "364FF6B7A19CFFA3572DE0AF156CB0D6", "hash_pesha1": "B095A64F19CEA689DD863A62A0FF8DB9335A7958", "hash_pe256": "23453A7969F7810F45EE1622B00BDAD6066D4A13829A9DA216F1EC86F67B26DD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Unload PerfMon Counters", "meta_original_filename": "UNLODCTR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/9b602bd2cf08116f97e1027dd3e298ce5e2b68e80bed44f036f05b69a3fef611/detection/", "output": "\r\n\r\nUNLODCTR\r\n Removes counter names and explain text for the specified extensible counter.\r\n\r\nUsage:\r\n\r\n UNLODCTR <driver>\r\n driver is the name of the device driver which is to have its\r\n counter name definitions and explain text removed from the system's\r\n registry.\r\n\r\n UNLODCTR /m:<manifest>\r\n manifest is the name of the manifest file that contains performance\r\n counter definitions. These counters will be removed from local system.\r\n\r\n UNLODCTR /g:{ProviderGuid}\r\n ProviderGuid identifies the performance counter provider being unloaded.\r\n\r\n UNLODCTR /p:<ProviderName>\r\n ProviderName identifies the performance counter provider being unloaded.\r\n\r\nNote: any arguments with spaces in the names must be enclosed within\r\nDouble Quotation marks.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\unlodctr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\loadperf.dll" ] }, "unregmp2.exe-9CF8E80F71544316E5F90F2B87F2350C": { "file_name": "unregmp2.exe", "file_path": "C:\\Windows\\system32\\unregmp2.exe", "hash_md5": "9CF8E80F71544316E5F90F2B87F2350C", "hash_sha1": "5D5BF791D38DF29D52F4585A6853FC8242CDB73C", "hash_sha256": "DF160ACED402899269A07872038E7CEBE64CBB24DD09D8A4474B12AA6F760653", "hash_sha384": "B14699BE9DFFF7BF2069DBE877F0FED1984361C3FD7F9AC817B7DB99150F518543D9E7D719D15FA2CABD3C408C42834A", "hash_sha512": "53541DB1DB2ED366471CC8B8211D3F689F89621C7151C27547D26CEA8F27A20BF9D34260A3FCDC884806325EAB10B98F7DFF5971FF64122BAE69DDBDD6739D91", "hash_ssdeep": "3072:h6GXcCkMzR9sf9390cbXoRVJKL37A9q+ZcSPI+CR7sBvAwk4Oy7eTma4Z:UGkM9S5UOD", "hash_imp": "1DE1DA351E000239456F4F921473BDC8", "hash_pesha1": "60A53C9A311C3DBB32BC22517FAC97750D01C716", "hash_pe256": "B05E2B6C7C1DA403546ED91EEAEE303357ED400BFD36E0A36EA175767D41C2F2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Media Player Setup Utility", "meta_original_filename": "unregmp2.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/df160aced402899269a07872038e7cebe64cbb24dd09d8a4474b12aa6f760653/detection/", "runtime_modules": [ "C:\\Windows\\system32\\unregmp2.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\VERSION.dll" ] }, "upfc.exe-AC3DA8AAC02C94DC65ECDF9548E6372D": { "file_name": "upfc.exe", "file_path": "C:\\Windows\\system32\\upfc.exe", "hash_md5": "AC3DA8AAC02C94DC65ECDF9548E6372D", "hash_sha1": "D35A6D77ACF8E9AC80E345BDE15032AE632A976D", "hash_sha256": "AE4B0E81C601521DA974D53E44295C98331CED7C9CC2F260434E6BC0C475DDA3", "hash_sha384": "49707DEBEE678D3E498C8335AD75353E89CA5D84AC6CABE0CA1C1B601B556821DA6768ACD04AF926AD8228B112E10608", "hash_sha512": "160CB907BE18819817A0B3887DD899EE6D91F6B0EBAB6D8BA99011FB69416D9ED3232A49B159915ED484C28FD691C0743D93B4A54CC5ECCF1EE41BB652F2FCD7", "hash_ssdeep": "3072:sKSFjUnnqGDv7N+CunvkCO9wT6fPRp/RW:AFjAqOv7N+C+69w+PbI", "hash_imp": "B3371ED99D25FEFF460973E2D1E5A076", "hash_pesha1": "2DCCE3D1149E1F0F32C9607DF852E9F1BB76D8D4", "hash_pe256": "D226DE746AC1D76E4CF03439027D21836DF65BAC58F4E20829F1AEC24A133BDE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Updateability From SCM", "meta_original_filename": "upfc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/ae4b0e81c601521da974d53e44295c98331ced7c9cc2f260434e6bc0c475dda3/detection/", "runtime_modules": [ "C:\\Windows\\system32\\upfc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\XmlLite.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "UpgradeResultsUI.exe-A60CFD26EECB03644530EB63FCA485CD": { "file_name": "UpgradeResultsUI.exe", "file_path": "C:\\Windows\\system32\\UpgradeResultsUI.exe", "hash_md5": "A60CFD26EECB03644530EB63FCA485CD", "hash_sha1": "2F1DFAE4CA73EA523A37FBADEE77189277019063", "hash_sha256": "BC67E0619DD6A6DA18DA1BB60FA226DC83666A460F41D994507774CBA09FD6BB", "hash_sha384": "D5F286FD7B949990CD88089BAEB0B8BD7ABCE3F0D9023084F07ADF4B95489D302DA1B16B4DA8F427EF84005289221DE4", "hash_sha512": "4E165E9B356604C64358B320FF5FACB3FB40D9051DD10BD100FFF6B3BCCE779BA46A0C4D856DD2B77FA3C8970C3F69765AFAA694B10C9E966C2096A0A117F558", "hash_ssdeep": "768:K+0w47J3GXFkoC5mYjw+IRuJPZs1ibMmFfURSiJdd6JUnTG:K+0H0qmYjZIRMIgEJdUJITG", "hash_imp": "3E4D2A74C908635F8078AE98E9A14FA8", "hash_pesha1": "D92FB0AF3DDB2FFEA12313988F20689D3780C134", "hash_pe256": "141CB516069DB1DD68DC9061F17F5C833EA61F0187830007923F0E838D75BF7F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Add features to Windows Results", "meta_original_filename": "UpgradeResultsUI.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/bc67e0619dd6a6da18da1bb60fa226dc83666a460f41d994507774cba09fd6bb/detection/", "runtime_modules": [ "C:\\Windows\\system32\\UpgradeResultsUI.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\DMCmnUtils.dll" ] }, "upnpcont.exe-91C9C58212B070283DE1E586A57140AC": { "file_name": "upnpcont.exe", "file_path": "C:\\Windows\\system32\\upnpcont.exe", "hash_md5": "91C9C58212B070283DE1E586A57140AC", "hash_sha1": "9CA7A9396C116F1FA369BE06518D01D495E8E3E5", "hash_sha256": "481542DBAFC0494531864444544E54B5292565AAD7547428DBD1D2F76D361A4B", "hash_sha384": "EDF0871A7259755FC5BF9E38B82845D55738AFBFB300B7279B3AA612187C0A35B5C89B4F166E9B7E0D38B22026EF8BDF", "hash_sha512": "0FA4BB3F87F75C20C42A7531CF165D366091A49321ED11CCDFC03966BC5B671F43474AF08180719F961FC6D8601FB0EB9F088CDD80993EB0FE6C00A567E325EC", "hash_ssdeep": "768:X29CbQbWLdJQCsav7Hz6hVrPdITC9leUNbNqZThoLyUh5:mUcbYJQPVDK00SoZN4p", "hash_imp": "7B81D592E2E0E57EBD2E87234270AF60", "hash_pesha1": "6F15BB6AB25A91A2BEABC137FB00F0162A92215A", "hash_pe256": "18EC5BEEE2A21236ECD46F54E640B86A595DE36FD0D6F1765638E35D0FAFFE95", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UPnP Device Host Container", "meta_original_filename": "upnpcont.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/56", "filescan_vtlink": "https://www.virustotal.com/gui/file/481542dbafc0494531864444544e54b5292565aad7547428dbd1d2f76d361a4b/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC534": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\upnpcont.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "UserAccountBroker.exe-E2873A4B77297A21AB36972712A25BAA": { "file_name": "UserAccountBroker.exe", "file_path": "C:\\Windows\\system32\\UserAccountBroker.exe", "hash_md5": "E2873A4B77297A21AB36972712A25BAA", "hash_sha1": "05FDC1CB2BF2EA97FEBA42BD0DD23490EE109D45", "hash_sha256": "EFBF9D87EEBA124B157C9D0068450B1880A2A5A09D59C41ADDE3A292392D0984", "hash_sha384": "6465BBBA5FAB297F95622631D2F53A6EF9C3C15E7176E53260E69C0DD1BBD78003EFD52F16B7814DFF1270487417BD4D", "hash_sha512": "389E8E004D106A1E55951F5364DCC1E9FCCA32B0B31DA9DFB55932BCCB169700D8BBFC0456663A6E13B4E1911D9AB11DD577E71F47A4ED0D0A6D6F326E0EF257", "hash_ssdeep": "768:r2tK/96NezOFrcczXpdzPOt4sE/P9ZOA71aySTfB0QYiPWrdUPZXszSpXj1Pm+/T:rYYn8771H1ay+faCqyZXszSVpPm+/T", "hash_imp": "BACBDE65B57012389CEB9F9FF921076A", "hash_pesha1": "60D810E7DF441EF8CCB7EE24F711AF29CF5488DE", "hash_pe256": "8B4844A5AFC85AC801E1F3CB09054D0C9541B148C9621A979ADF06C45E22C3AF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "User Account Control Panel Host", "meta_original_filename": "UserAccountBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/efbf9d87eeba124b157c9d0068450b1880a2a5a09d59c41adde3a292392d0984/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECFB4": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\UserAccountBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll" ] }, "UserAccountControlSettings.exe-66FF2AA9B02466037C85E3B59A9E308A": { "file_name": "UserAccountControlSettings.exe", "file_path": "C:\\Windows\\system32\\UserAccountControlSettings.exe", "hash_md5": "66FF2AA9B02466037C85E3B59A9E308A", "hash_sha1": "D9091C5AB23AB535CEE30A18F9657555D814BCEE", "hash_sha256": "51AFE88D1828724912800CE6507AF145838C3457EE6105B4A33782819D3944A7", "hash_sha384": "E3604E665797CC07251154D3DC18F47B1E9AC4F4EDEE5C9E7F8ED995811C3657A29F6D252C4D6377F3FD3133CC990B12", "hash_sha512": "12F50F9B1324C8905D34B74F827A078B2D70E7A4E3E56C93CAEC3A2D16B3EBFAC216C0A4DD7B9A7671BE55567DF61AE786C7192E369671F9960505A8BEC85317", "hash_ssdeep": "1536:iR/VLhrWt2ijoJoXFeXb+eAyD+YT751sNz0UCdkV/L7:4svMeVWR335K", "hash_imp": "535666E355558A85F423E8C8D4D12F36", "hash_pesha1": "86E0BFBA1DC0E860EB01690BA9DD254D17CC5EDC", "hash_pe256": "C1DB73591261EABBFFB7356BED9A0DA3C54BFCEE228BE2ADA4F25044782852A5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UserAccountControlSettings", "meta_original_filename": "UserAccountControlSettings.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/51afe88d1828724912800ce6507af145838c3457ee6105b4a33782819d3944a7/detection/" }, "userinit.exe-BF8825D08BC235F0609CA8BBEF4E179C": { "file_name": "userinit.exe", "file_path": "C:\\Windows\\system32\\userinit.exe", "hash_md5": "BF8825D08BC235F0609CA8BBEF4E179C", "hash_sha1": "470C3E60F9B2B6D83F95C7916A5361E34DEC3471", "hash_sha256": "1FE7F7C59EC7EAA276739FA85F7DDA6136D81184E0AEB385B6AC9FEAAA8C4394", "hash_sha384": "2F6C88E35212D628149451D95FE10F37B8ECDDADA4CA9216451573415C9DF440A3C1FF432C6E4EE5D12161BC87808BA6", "hash_sha512": "0D54F15CDD2245A540B588566C3F5FE70E1401AABE08C2052C72CB7A8E10741A37817816C29E41FD50F9BE57D01AA0DAC911120E7CBB44E9DBD6B07D3BD6E70C", "hash_ssdeep": "384:UPn1lWx3jWG/eBjZH7ehyFQQ65SEvhmaB9YQTpkEBVSC+lfPIeb51MQneA6pgWxk:UPnyWG/e1Zbo/rSiPTpr+Rh5XnhMa", "hash_imp": "8419D97ABDFEB6C320F0C39028647572", "hash_pesha1": "DF688108336B5E2AC79D652521CAE6F14BC4D450", "hash_pe256": "A5160EF5F4B97E938DA7E956A3331FB66EA3F9EA7E7D8BEEF313F318F2C11B98", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Userinit Logon Application", "meta_original_filename": "USERINIT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/1fe7f7c59ec7eaa276739fa85f7dda6136d81184e0aeb385b6ac9feaaa8c4394/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\userinit.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\userinit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\SYSTEM32\\userinitext.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\system32\\USERENV.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\SYSTEM32\\winsta.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "UsoClient.exe-39750D33D277617B322ADBB917F7B626": { "file_name": "UsoClient.exe", "file_path": "C:\\Windows\\system32\\UsoClient.exe", "hash_md5": "39750D33D277617B322ADBB917F7B626", "hash_sha1": "EBF56AD89D4740359D5D3D5370B31E56614BBB79", "hash_sha256": "DF3900CDC3C6F023037AAF2D4407C4E8AAA909013A69539FB4688E2BD099DB85", "hash_sha384": "FA47CCAF9B39943E3D2053FF058D7AE05A4674B322886A57CEC5D2628F581A34CCD730C0D07F4092B0A6486F641F7915", "hash_sha512": "DFA9CA745519208C31F6DD2E55730854FF12AD11CCCCD7721A562CCE79B248E2C82CBC35AB0BC3E20B8D12B2D4997BFD830F2875B0EAC751160DD875079BF91D", "hash_ssdeep": "768:VHXH+s5pISHJdZw5aMzPCQj6tx4/bp96oPapcwNYQM+Zb0honK6gc:V3lpIcwXzPCQyUb7apcwNdM+ZohoK6gc", "hash_imp": "2510E8A4554AEF2CAF0A913BE015929F", "hash_pesha1": "498EAC24097B2922398AF1972B051BECED820134", "hash_pe256": "A314458338BF571D155F76D519341F55B387C6049EC07C7ABADD8F543D333A12", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UsoClient", "meta_original_filename": "UsoClient", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1007 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1007", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/df3900cdc3c6f023037aaf2d4407c4e8aaa909013a69539fb4688e2bd099db85/detection/", "runtime_modules": [ "C:\\Windows\\system32\\UsoClient.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "Utilman.exe-1FEE3EF75593F715AC858AA5DCFB724F": { "file_name": "Utilman.exe", "file_path": "C:\\Windows\\system32\\Utilman.exe", "hash_md5": "1FEE3EF75593F715AC858AA5DCFB724F", "hash_sha1": "1F4FDE393AA0A8FC8EE8B91C278FEAD43FA95796", "hash_sha256": "006EAB15D43639B420AC7380A923230CB47D96F35A0B0377538FF49725EFC23E", "hash_sha384": "262009FD10F3DE03E5A6DE929A8DCED875CDBCDCC7876D131D9723A704F4F37661F39580D8D425DAFC62BD865D617244", "hash_sha512": "4FC3DAE9E657BA77F60413A803B12D14C477F1286DE6E483C60917B33BA9204A07D8ABF70A6324D0EB041C4B14B8E20D495BFA8FDA9121ED08BAE906E2EF9A7F", "hash_ssdeep": "1536:bqHblWpQbaGfRM1pfdJzfpSOUqwGg+xKeXUj8VFylBvhizTcNNk25W:k5WQba4M11rJUJPnYdqBvozQNNH5", "hash_imp": "FF20EBB2220D02C4DCD7EB2674E139BA", "hash_pesha1": "B10A9624AD917D4D9B7854291A213A86473F04C8", "hash_pe256": "33213E01DED5B2F066DEC3A72D978745574DDA645AF6C7DF962DBDD2FFAD515C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Utility Manager", "meta_original_filename": "utilman2.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/006eab15d43639b420ac7380a923230cb47d96f35a0b0377538ff49725efc23e/detection/", "runtime_modules": [ "C:\\Windows\\system32\\Utilman.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\OLEACC.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "VaultCmd.exe-24AD59DBE3B726704E1444C83F6CEF06": { "file_name": "VaultCmd.exe", "file_path": "C:\\Windows\\system32\\VaultCmd.exe", "hash_md5": "24AD59DBE3B726704E1444C83F6CEF06", "hash_sha1": "52C21668784B9FB9D3B53B16EE517A0B221C8A82", "hash_sha256": "9E68FCF6FD1104BBD1CA47BB36347ABC621329924F880B75793638AF04DC607E", "hash_sha384": "52FA6970A00986CF3C57A5D4FDFE1F3AB517CE7711F506A39902983254A6AC8EB2DC43669B8B7E92B6A198ADABDFA00F", "hash_sha512": "B8C1F49716CEDD9D60799B827948E401D0FEA6DE3AF5BDC8FA157E9C97F5A4B3767C98EBDFA22F72972202A4C9806EFBB823BD72AC7F9A55183C879ECF7394D3", "hash_ssdeep": "384:aFkTw4jG7MLuUSuky8aRT9gcBIWGfPYwC+1ESMCmqOORy1RCVYxX530vB+WMFW:aEGMqUSukIxxoYwP1EGvy+WxX530vBs", "hash_imp": "53455FAA9B96202832E76BC0279ED4D5", "hash_pesha1": "CAE9EF5C7FECD83B03DDA966490068E13972A1BA", "hash_pe256": "11FC40546F9A30427A253F006A462FB51626C7977EBF1E0121850D81D93ADC78", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Vault cmdline Program", "meta_original_filename": "VAULTCMD.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/9e68fcf6fd1104bbd1ca47bb36347abc621329924f880b75793638af04dc607e/detection/", "output": "Creates, displays and deletes stored credentials.\r\nFollowing commands are supported.Use VaultCmd /<command> /? for further help \r\nVaultCmd /list\r\nVaultCmd /listschema\r\nVaultCmd /listcreds\r\nVaultCmd /addcreds\r\nVaultCmd /deletecreds\r\nVaultCmd /listproperties\r\nVaultCmd /sync\r\n", "runtime_modules": [ "C:\\Windows\\system32\\VaultCmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "vds.exe-E845A556FC6574216078A02FE53189C1": { "file_name": "vds.exe", "file_path": "C:\\Windows\\system32\\vds.exe", "hash_md5": "E845A556FC6574216078A02FE53189C1", "hash_sha1": "EEFD84BCBB943CDD21B292FA5F5A811E3C4CC711", "hash_sha256": "9CECFC7977BAA23A840F987A28813227BAB3F2DFDF1D571B51327107B5AA8CE2", "hash_sha384": "D993646D5A6F5EB71A529F3CDEBB15438E7E09A189B55DCFB52253EC6A7BFC29DAA9D755E6438793E1CF14D8411F8A92", "hash_sha512": "055C28953FA8CA1E7DF848EA2048CA6D02232A84C71F79DCB47820B9AAE7ABB758170DB940845CE00474A23E11D7D29AB51C6B463B9FA9643DCE9ABC868FDA47", "hash_ssdeep": "6144:1MPs1dwUXYhQqD2TkbqEXfYmjHc+ZDcaysxbhH/TLhmhDnlIn+i:3yQqD2ufP8+V9L4Ns", "hash_imp": "E2F880E899B5A451B9B030D7BCFA2EAE", "hash_pesha1": "FB25BF4C73B7C3235769CB21BE9D2DD1C6A16537", "hash_pe256": "FC75597F41D1D0697771F34233E053703FDF8A60AC70BD97CF29CB01BC0ECFE3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Virtual Disk Service", "meta_original_filename": "vds.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/9cecfc7977baa23a840f987a28813227bab3f2dfdf1d571b51327107b5aa8ce2/detection/", "runtime_modules": [ "C:\\Windows\\system32\\vds.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\ATL.DLL", "C:\\Windows\\system32\\OSUNINST.dll" ] }, "vdsldr.exe-2FEAB32458F981DF0D9688DA2F22F663": { "file_name": "vdsldr.exe", "file_path": "C:\\Windows\\system32\\vdsldr.exe", "hash_md5": "2FEAB32458F981DF0D9688DA2F22F663", "hash_sha1": "4EC987234F91026484499F62EB0B34070C391B08", "hash_sha256": "DDC920ACFDB76DD6DFDC0CAE7714C1D2995FD6042D1FC2EFB1CC1DF9478FA26F", "hash_sha384": "5D6E776A1F50B935F3244C69F856EE30696CF8E439FAA617EC0E6DDC6F78BD4BAE60176F3D13EC23DBCFECC1B057CA9B", "hash_sha512": "4D245344FA4E323A5629D1DF7EF834144889B04EBB21446B7288E9D138784F0BE96F3E43E992C0E2286983F78D1CEE7DE97FC77CF8CAAD749F6C520A59E44DA0", "hash_ssdeep": "384:ErmxCvevTTtBKViMoURewyTK9vZ1zis5+6ULVLMLBr+d6qDvnWd+WW4E:E9evTB2roURewyTw7uLMLF0tDvq2", "hash_imp": "C25737B6F6D492CDA69D7F8126F4755B", "hash_pesha1": "44510232C53E493697E332EE95608C08B330C052", "hash_pe256": "AED31C5979B380B61A2C4CC4F51811654E040B6F34700E101DF6982FB7685991", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Virtual Disk Service Loader", "meta_original_filename": "vdsldr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/ddc920acfdb76dd6dfdc0cae7714c1d2995fd6042d1fc2efb1cc1df9478fa26f/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1228": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\vdsldr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\ATL.DLL", "C:\\Windows\\system32\\vdsutil.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "verclsid.exe-00E31F606C082A42247D3BDE2CA8A171": { "file_name": "verclsid.exe", "file_path": "C:\\Windows\\system32\\verclsid.exe", "hash_md5": "00E31F606C082A42247D3BDE2CA8A171", "hash_sha1": "31EB54997B6EE5E126F3DB038EE73F34D4D84EDB", "hash_sha256": "18C4E76431643AAF2113A5C4556CBE1D79CBC8113E4B0904A6205D73A8926045", "hash_sha384": "A7A1AC01393598C37A59228CFF0F1695ACF0AB23617903FE0D979D56B1F016DB39B7B34C48A3F1B7E82F956ACE6737D1", "hash_sha512": "BB0C09334197AF868B469634E842A81C5205A00639FB95CE93581F231719E17DBE0C49FE6C3C6B0FF831FE9B1A51BB2B387E7F2DF3EC9A42CABF7282C6D9B074", "hash_ssdeep": "192:sCtBf9auhKg6rZ6wQrp9g4FxfJZGmuJAxcNukPWNNW:saBljwrgwC9T1JZHuYoWNNW", "hash_imp": "FA65D753209C7382631265744DE49154", "hash_pesha1": "37DE54C96F9BB00832F43E3B958CE563BE1FB087", "hash_pe256": "F3BD5375A7C0D44BBF04E29D7131A14845992262D1A92AECF1F28DE6E6575899", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extension CLSID Verification Host", "meta_original_filename": "verclsid.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/18c4e76431643aaf2113a5c4556cbe1d79cbc8113e4b0904a6205d73a8926045/detection/" }, "verifier.exe-33D4E51F4BEFAE3ACEFA2F5EFFD19F7C": { "file_name": "verifier.exe", "file_path": "C:\\Windows\\system32\\verifier.exe", "hash_md5": "33D4E51F4BEFAE3ACEFA2F5EFFD19F7C", "hash_sha1": "C80E66A0A608C1CC044AD95841D9EDA67D191DB5", "hash_sha256": "9DC1E17904C26FB63F7568087DF8E844714E567D31E0CAF03EC56941525B16F7", "hash_sha384": "6B751F7AC756FCF9BFC93CDE691B36130E9C939C6FEBB6377049A042BBD84D663142E70B5223FF3EA6587CAF4B93D03C", "hash_sha512": "0D151064D333B4CF18AAA7A4A56084BCC71A2E73DFF0E97D088078E6DF1D561C760BCAFF837BE780B82A23B75C046651EF60DE4BC3F48F041BB3C377BAE20245", "hash_ssdeep": "3072:XSH+PhTx1XEGOoH13XfFdvgnX4c5VoJe3+Vcv2JxQQBBEB3BefnjKrjqR+feT2IX:X0+PhTXXEa1vnAX4ca", "hash_imp": "1D99B99C14180C8AF81D7709A624847D", "hash_pesha1": "49C56E379CE07DAEFAB97715611F5D3C5B4CE005", "hash_pe256": "9550B199D5789B0798A2EA8337C4EC1FE45ACC353731D86C67B6A257128AB87F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Verifier Configuration Editor", "meta_original_filename": "verifier.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/9dc1e17904c26fb63f7568087df8e844714e567d31e0caf03ec56941525b16f7/detection/", "output": "\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nSYNTAX:\r\n\r\n verifier {/? | /help}\r\n verifier /standard /all\r\n verifier /standard /driver <name> [<name> ...]\r\n verifier {/ruleclasses | /rc} <options> [<ruleclass_1> <ruleclass_2> ...] /all\r\n verifier /flags <options> [<options> ...] /all\r\n verifier /flags <options> [<options> ...] /driver <name> [<name> ...]\r\n verifier /rules {query | reset | default <id> | disable <id>}\r\n verifier /query\r\n verifier /querysettings\r\n verifier /bootmode {persistent | resetonbootfail | oneboot | resetonunusualshutdown}\r\n verifier /persistthroughupgrade\r\n verifier /reset\r\n verifier /faults [probability [pool_tags [applications [delay_minutes]]]]\r\n verifier /faultssystematic [<options> ...]\r\n verifier /log <file_name> [/interval <seconds>]\r\n verifier /volatile /flags <options> [<options> ...]\r\n verifier /volatile /adddriver <name> [<name> ...]\r\n verifier /volatile /removedriver <name> [<name> ...]\r\n verifier /volatile /faults [probability [pool_tags [applications\r\n [delay_minutes]]]]\r\n verifier /domain {wdm | ndis | ks | audio} [rules.all | rules.default ]\r\n /driver ... [/logging | /livedump]\r\n verifier /logging\r\n verifier /livedump\r\n\r\nPARAMETERS:\r\n\r\n /? or /help\r\n Displays this help message.\r\n\r\n /standard\r\n Specifies standard Driver Verifier flags.\r\n\r\n /all\r\n Specifies that all installed drivers will be verified after the next\r\n boot.\r\n\r\n /driver <name> [<name> ...]\r\n Specifies one or more drivers (image names) that will be verified.\r\n Wildcard values (e.g. n*.sys) are not supported.\r\n\r\n /driver.exclude <name> [<name> ...]\r\n Specifies one or more drivers (image names) that will be excluded\r\n from verification. This parameter is applicable only if all drivers\r\n are selected for verification. Wildcard values (e.g. n*.sys) are not\r\n supported.\r\n\r\n /flags <options> [<options> ...]\r\n Specifies one or more options that should be enabled for verification.\r\n Flags are applied to all drivers being checked by Driver Verifier. The\r\n provided options values must be either in decimal, hexadecimal (\"0x\"\r\n prefix), octal (\"0o\" prefix) or binary (\"0b\" prefix) format.\r\n\r\n Standard Flags:\r\n Standard Driver Verifier options can be specified using '/standard'.\r\n WDF verification is included in /standard but is not shown here.\r\n\r\n 0x00000001 (bit 0) - Special pool\r\n 0x00000002 (bit 1) - Force IRQL checking\r\n 0x00000008 (bit 3) - Pool tracking\r\n 0x00000010 (bit 4) - I/O verification\r\n 0x00000020 (bit 5) - Deadlock detection\r\n 0x00000080 (bit 7) - DMA checking\r\n 0x00000100 (bit 8) - Security checks\r\n 0x00000800 (bit 11) - Miscellaneous checks\r\n 0x00020000 (bit 17) - DDI compliance checking\r\n\r\n Additional Flags:\r\n These flags are intended for specific scenario testing. Flags marked\r\n with (*) require I/O Verification (bit 4) that will be automatically\r\n enabled. Flags marked with (**) support disabling of individual\r\n rules.\r\n\r\n 0x00000004 (bit 2) - Randomized low resources simulation\r\n 0x00000200 (bit 9) - Force pending I/O requests (*)\r\n 0x00000400 (bit 10) - IRP logging (*)\r\n 0x00002000 (bit 13) - Invariant MDL checking for stack (*)\r\n 0x00004000 (bit 14) - Invariant MDL checking for driver (*)\r\n 0x00008000 (bit 15) - Power framework delay fuzzing\r\n 0x00010000 (bit 16) - Port/miniport interface checking\r\n 0x00040000 (bit 18) - Systematic low resources simulation\r\n 0x00080000 (bit 19) - DDI compliance checking (additional)\r\n 0x00200000 (bit 21) - NDIS/WIFI verification (**)\r\n 0x00800000 (bit 23) - Kernel synchronization delay fuzzing\r\n 0x01000000 (bit 24) - VM switch verification\r\n 0x02000000 (bit 25) - Code integrity checks\r\n\r\n /ruleclasses or /rc [<ruleclass_1> <ruleclass_2> ... <ruleclass_k>]\r\n This parameter is larger set of '/flags' above. While '/flags' is\r\n limited to 32 bit bitmap expression, this can include more than 32\r\n verification classes. Each positive decimal integer represents a\r\n verification class. Multiple classes can be expressed by separating\r\n each class id with space character. Following rule classes IDs are\r\n available and leading 0's can be omitted.\r\n\r\n Standard Rule Classes:\r\n\r\n 1 - Special pool\r\n 2 - Force IRQL checking\r\n 4 - Pool tracking\r\n 5 - I/O verification\r\n 6 - Deadlock detection\r\n 8 - DMA checking\r\n 9 - Security checks\r\n 12 - Miscellaneous checks\r\n 18 - DDI compliance checking\r\n 34 - WDF Verification\r\n\r\n Additional Rule Classes:\r\n These rule classes are intended for specific scenario testing. Rule\r\n classes are marked with (*) require I/O Verification (5) that will\r\n be automatically enabled. Flags marked with (**) support disabling\r\n of individual rules.\r\n\r\n 3 - Randomized low resources simulation\r\n 10 - Force pending I/O requests (*)\r\n 11 - IRP logging (*)\r\n 14 - Invariant MDL checking for stack (*)\r\n 15 - Invariant MDL checking for driver (*)\r\n 16 - Power framework delay fuzzing\r\n 17 - Port/miniport interface checking\r\n 19 - Systematic low resources simulation\r\n 20 - DDI compliance checking (additional)\r\n 22 - NDIS/WIFI verification (**)\r\n 24 - Kernel synchronization delay fuzzing\r\n 25 - VM switch verification\r\n 26 - Code integrity checks\r\n\r\n /log.code_integrity\r\n This option suppresses Code Integrity violation breaks and collects\r\n only statistics for verified drivers. Statistics could be extracted\r\n via /log option or kernel debugger. This parameter is applicable only\r\n if Code Integrity checks are enabled.\r\n\r\n /rules {query | reset | default <id> | disable <id>}\r\n Specifies rules level control (advanced).\r\n\r\n query Shows current status of controllable rules.\r\n reset Resets all rules to their default state.\r\n default <id> Sets rule ID to its default state.\r\n disable <id> Disables specified rule ID.\r\n\r\n /query\r\n Display runtime Driver Verifier statistics and settings.\r\n\r\n /querysettings\r\n Displays a summary of the options and drivers that are currently\r\n enabled, or options and drivers that will be verified after the\r\n next boot. The display does not include drivers and options added\r\n using /volatile.\r\n\r\n /bootmode\r\n Specifies the Driver Verifier boot mode. This option requires system\r\n reboot to take effect.\r\n\r\n persistent Ensures that Driver Verifier settings are\r\n persistent across reboots. This is the default\r\n value.\r\n resetonbootfail Disables Driver Verifier for subsequent reboots\r\n if the system failed to start.\r\n resetonunusualshutdown\r\n Driver Verifier persists until unusual shutdown\r\n happens. Its abbrevation, 'rous', can be used.\r\n oneboot Enables Driver Verifier only for the next boot.\r\n\r\n /persistthroughupgrade\r\n Makes the Driver Verifier settings persist through upgrade. Driver\r\n Verifier will be active during system upgrade.\r\n\r\n /reset\r\n Clears Driver Verifier flags and driver settings. This option requires\r\n system reboot to take effect.\r\n\r\n /faults [probability [pool_tags [applications [delay_minutes]]]]\r\n Enable the Randomized low resources simulation feature and optionally\r\n control parameters for the Randomized low resources simulation.\r\n\r\n Probability Specifies the probability that Driver Verifier will\r\n fail a given allocation. The value represents the\r\n number of chances in 10,000 that Driver Verifier will\r\n fail the allocation. The default value 600, means\r\n 600/10000 or 6.\r\n Pool Tags: Specifies a space separated list of the pool tags to\r\n be injected with faults. By default, any pool\r\n allocation can be injected with faults.\r\n Applications Specifies a space separated list of image file names\r\n (an executable) that will be injected with faults. By\r\n default, any pool allocation can be injected with\r\n faults.\r\n DelayMinutes Specifies the number of minutes after booting during\r\n which Driver Verifier does not intentionally fail any\r\n allocations. This delay allows the drivers to load\r\n and the system to stabilize before the test begins.\r\n The default value is 8 minutes.\r\n\r\n /faultssystematic [<options> ...]\r\n Controls the Systematic low resources simulation parameters.\r\n\r\n enableboottime Enables fault injections across reboots.\r\n disableboottime Disables fault injections across reboots.\r\n This is the default value.\r\n recordboottime Enables fault injections in 'what if' mode\r\n across reboots.\r\n resetboottime Disables fault injections across reboots and\r\n clears the stack exclusion list.\r\n enableruntime Dynamically enables fault injections.\r\n disableruntime Dynamically disables fault injections.\r\n recordruntime Dynamically enables fault injections in\r\n 'what if' mode.\r\n resetruntime Dynamically disables fault injections and\r\n clears the previously faulted stack list.\r\n querystatistics Shows the current fault injection statistics.\r\n incrementcounter Increments the test pass counter used to\r\n identify when a fault was injected.\r\n getstackid <counter> Retrieves the indicated injected stack id.\r\n excludestack <stack_id> Excludes the stack from fault injection.\r\n\r\n /log <file_name> [/interval <seconds>]\r\n Creates a log file with the specified name and periodically writes the\r\n runtime statistics to this file. The interval between log file updates\r\n is controlled by the '/interval' parameter. The default value is 30\r\n seconds. Use CTRL+C to close the log and return.\r\n\r\n /volatile\r\n Changes Driver Verifier settings without rebooting the computer.\r\n Volatile settings take effect immediately and are in effect until the\r\n next system reboot.\r\n\r\n /volatile /adddriver <name> [<name> ...]\r\n Starts the verification for the specified driver or drivers.\r\n\r\n /volatile /removedriver <name> [<name> ...]\r\n Stops the verification for the specified driver or drivers.\r\n\r\n /domain {wdm | ndis | ks | audio} [rules.all | rules.default] /driver ...\r\n [/logging | /livedump]\r\n Controls the verifier extension settings. The following verifier\r\n extension types are supported:\r\n\r\n wdm Enabled verifier extension for WDM drivers.\r\n ndis Enabled verifier extension for networking drivers.\r\n ks Enabled verifier extension for kernel mode\r\n streaming drivers.\r\n audio Enabled verifier extension for audio drivers.\r\n\r\n The following extension options are supported:\r\n\r\n rules.default Enables default validation rules for the selected\r\n verifier extension.\r\n rules.all Enables all validation rules for the selected\r\n verifier extension.\r\n\r\n /logging\r\n Enables logging for violated rules detected by the selected verifier\r\n extensions.\r\n\r\n /livedump\r\n Enables live memory dump collection for violated rules detected by\r\n the selected verifier extensions.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\verifier.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll" ] }, "verifiergui.exe-D6E799255D28472DB220D7270B445728": { "file_name": "verifiergui.exe", "file_path": "C:\\Windows\\system32\\verifiergui.exe", "hash_md5": "D6E799255D28472DB220D7270B445728", "hash_sha1": "07092974428BAA7ED3AA926AD4F277BC84DABE7C", "hash_sha256": "5D1868E396A185B1893A9092858CDEE53664D5554DF4D3F797B48CFF8E94F7AF", "hash_sha384": "A293CA98B890B1A6453CD6614FACEEF68BB9C61D92FE773C4CC01E6575F084AE754F97FBDDA807EE3B052537CD7CEFE6", "hash_sha512": "25443CF769286BB194B60E62335735080B772ADE98D5131E92CC4076BC4DC3713E229B7DE95149AD1DB738BF8337AB679B24F56BE6B61DD9EEC1C5DF78897CB9", "hash_ssdeep": "3072:6uSWXsgFf1R7Wx6maDkCc8XDc5VoJe3+Vcv2JxQQBBEB3BefnjA+Trjq+rfCFG2P:Y7gBjm6g2b2F8a", "hash_imp": "21008BDE061FD8E970A7B9F78832EBE1", "hash_pesha1": "DEA8AC30547C25CAD1337F1B6287EEDEFE1949D8", "hash_pe256": "766DB8BADA9DC495468BB135ECFAA6495C7A8C9CE8C9C37CFA4BD64C59384D04", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Driver Verifier Manager", "meta_original_filename": "verifiergui.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/5d1868e396a185b1893a9092858cdee53664d5554df4d3f797b48cff8e94f7af/detection/", "output": " \r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n \r\nCOMMON USAGE: \r\n verifier /?\r\n verifier /standard /all\r\n verifier /standard /driver NAME [NAME ...]\r\n verifier /flags FLAGS /all\r\n verifier /flags FLAGS /driver NAME [NAME ...]\r\n verifier /rules [OPTION ...]\r\n verifier /query\r\n verifier /querysettings\r\n verifier /bootmode [persistent|resetonbootfail|oneboot]\r\n verifier /reset\r\n verifier /faults [PROB [TAGS [APPS [MINS]]]]\r\n verifier /faultssystematic [OPTION ...]\r\n verifier /log LOG_FILE_NAME [/interval SECONDS]\r\n verifier /volatile /flags FLAGS\r\n verifier /volatile /adddriver NAME [NAME ...]\r\n verifier /volatile /removedriver NAME [NAME ...]\r\n verifier /volatile /faults [PROB [TAGS [APPS [MINS]]]]\r\n \r\n/?\r\n This help.\r\n \r\n/standard\r\n Enable the Driver Verifier standard flags. \r\n This is functionally equivalent to '/flags 0x209BB'\r\n \r\n/all\r\n Enable Driver Verifier on all drivers in a system.\r\n \r\n/driver NAME [NAME ...]\r\n Specify the driver or list of drivers that should be verified.\r\n NAME is the name and extension of the file to verify (example: driver.sys).\r\n To enable Driver Verifier on more than one driver, list all drivers using a\r\n space separated list. Wildcard values (such as n*.sys) are not supported.\r\n \r\n/flags FLAGS \r\n Specify which options are enabled for verification. \r\n FLAGS value must be a number in decimal or hex (with 0x prefix).\r\n Note: Flags are applied to all drivers being checked by Driver Verifier. \r\n \r\n STANDARD FLAGS:\r\n These flags are considered standard options for Driver Verifier and can be \r\n set using '/standard' or by the combination of the options: '/flags 0x209BB'\r\n bit 0 (0x00000001) - Special pool\r\n bit 1 (0x00000002) - Force IRQL checking\r\n bit 3 (0x00000008) - Pool tracking\r\n bit 4 (0x00000010) - I/O verification\r\n bit 5 (0x00000020) - Deadlock detection\r\n bit 7 (0x00000080) - DMA checking\r\n bit 8 (0x00000100) - Security checks\r\n bit 11 (0x00000800) - Miscellaneous checks\r\n bit 17 (0x00020000) - DDI compliance checking\r\n \r\n ADDITIONAL FLAGS:\r\n These flags are designed for specific scenario testing.\r\n Flags marked with a (*) require I/O Verification (bit 4) also be enabled.\r\n Flags marked with a (**) support disabling of individual rules.\r\n bit 2 (0x00000004) - Randomized low resources simulation\r\n bit 9 (0x00000200) - Force pending I/O requests (*)\r\n bit 10 (0x00000400) - IRP logging (*)\r\n bit 13 (0x00002000) - Invariant MDL checking for stack (*)\r\n bit 14 (0x00004000) - Invariant MDL checking for driver (*)\r\n bit 15 (0x00008000) - Power framework delay fuzzing\r\n bit 16 (0x00010000) - Port/miniport interface checking\r\n bit 18 (0x00040000) - Systematic low resources simulation\r\n bit 19 (0x00080000) - DDI compliance checking (additional)\r\n bit 21 (0x00200000) - NDIS/WIFI verification (**)\r\n bit 23 (0x00800000) - Kernel synchronization delay fuzzing\r\n bit 24 (0x01000000) - VM switch verification\r\n bit 25 (0x02000000) - Code integrity checks\r\n \r\n/rules [OPTION ...]\r\n Options for rules that can be disabled (advanced). \r\n query: shows current status of controllable rules.\r\n reset: resets all rules to their default state.\r\n default ID: sets rule ID to its default state.\r\n disable ID: disables specified rule ID.\r\n \r\n/query\r\n Display a summary of Driver Verifier's current activity.\r\n \r\n/querysettings\r\n Display a summary of the options and drivers that are currently enabled, \r\n or options and drivers that will be verified after the next boot. The \r\n display does not include drivers and options added using /volatile.\r\n \r\n/bootmode\r\n Sets the verifier boot mode. Requires reboot to take effect.\r\n persistent: Ensures that DV settings are persistent over many reboots.\r\n This is default.\r\n resetonbootfail: If OS fails to boot, reset verifier for subsequent boots.\r\n oneboot: Only enable verifier for next boot.\r\n \r\n/reset\r\n Clear Driver Verifier flag and driver settings. Does not clear bootmode.\r\n Requires reboot to take effect.\r\n \r\n/faults [PROB [TAGS [APPS [MINS]]]]\r\n Enable the Randomized low resources simulation bit and optionally control\r\n parameters for the Randomized low resources simulation.\r\n PROB: A number between 1 and 10000 specifying the fault injection \r\n probability. If this parameter is not specified, then the default \r\n value of 600 (6%) will be used.\r\n TAGS: A space separated list of the pool tags to be injected with faults.\r\n If this parameter is not specified, then any pool allocation can be\r\n injected with faults.\r\n APPS: A space separated list of the image filename of the applications that\r\n will be injected with faults. If this parameter is not specified then\r\n the Randomized low resources simulation can take place in any\r\n application.\r\n MINS: A positive number indicating the of minutes after rebooting during \r\n which no fault injection will occur. If this parameter is not \r\n specified, then the default length of 8 minutes will be used.\r\n \r\n/faultssystematic [OPTION ...]\r\n Options for controlling the Systematic low resources simulation.\r\n enableboottime: enables fault injections across reboots.\r\n disableboottime: disables fault injections across reboots (default).\r\n recordboottime: enables fault injections in 'what if' mode across\r\n reboots.\r\n resetboottime: disables fault injections across reboots and clears\r\n the stack exclusion list.\r\n enableruntime: dynamically enables fault injections.\r\n disableruntime: dynamically disables fault injections.\r\n recordruntime: dynamically enables fault injections in 'what if'\r\n mode.\r\n resetruntime: dynamically disables fault injections and clears the\r\n previosly faulted stack list.\r\n querystatistics: shows the current fault injection statistics.\r\n incrementcounter: increments the test pass counter used to identify\r\n when a fault was injected.\r\n getstackid COUNTER: retrieves the indicated injected stack id.\r\n excludestack STACKID: excludes the stack from fault injection.\r\n \r\n/log LOG_FILE_NAME [/interval SECONDS]\r\n Create a log file with the name LOG_FILE_NAME. \r\n If '/interval' option is not specified, the default 30 seconds is used. \r\n Note: If a 'verifier /log' command is typed at the command line, the command\r\n prompt does not return. Use CTRL+C to close the log and return.\r\n \r\n/volatile\r\n Change the verifier settings dynamically without rebooting the system.\r\n Volatile settings are in effect until the next system reboot. \r\n \r\n/volatile /adddriver NAME [NAME ...]\r\n Add the specified driver or drivers to the list of drivers that will be \r\n checked with volatile settings. \r\n \r\n/volatile /removedriver NAME [NAME ...]\r\n Remove the specified driver or drivers from the list of drivers that are\r\n being checked with volatile settings. \r\n \r\n", "runtime_modules": [ "C:\\Windows\\system32\\verifiergui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll" ] }, "vssadmin.exe-614B5C4238977130AA2270C8AD58CE6C": { "file_name": "vssadmin.exe", "file_path": "C:\\Windows\\system32\\vssadmin.exe", "hash_md5": "614B5C4238977130AA2270C8AD58CE6C", "hash_sha1": "AC561205CD59BBCDB158525978FF65BDF17FDC3C", "hash_sha256": "D7577FB88CCA3169C7931DC0D8EC9A444227DC14F6C71D6D39D86A0C5CAD1976", "hash_sha384": "A5CC6C58F275621BC479BAD4FACB612857EBC45684E1426CE1EB37C63A5641758775666C87CDE674106B0558629D39F5", "hash_sha512": "CFED1C11B8383F548F623123F3AA5063A695010727E94FF66577D460C2714BCA9DBEA2AF4C9D0E0DE4458DE7FCB011ED5CB03E56ED54B3DCC19873479F19C82E", "hash_ssdeep": "3072:m8wU1BVAWWu70choKR5517xpMHm47pyePYYoC3I5f0g8IQ:m+BVsu7rhoG551t+m47pdPYYB3I5f0gb", "hash_imp": "C1EDC431CD345F0A0F32019895D13FCE", "hash_pesha1": "1B3592D410EBB8BC0CE5B4F5B261945755C8D852", "hash_pe256": "148E98E363B30F648E8CC116B6BED69428A05DADB6F738521833C0FA9C06AC2C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command Line Interface for Microsoft Volume Shadow Copy Service ", "meta_original_filename": "VSSADMIN.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/d7577fb88cca3169c7931dc0d8ec9a444227dc14f6c71d6d39d86a0c5cad1976/detection/", "output": "vssadmin 1.1 - Volume Shadow Copy Service administrative command-line tool\r\n(C) Copyright 2001-2013 Microsoft Corp.\r\n\r\nError: Invalid command.\r\n \r\n---- Commands Supported ----\r\n\r\nAdd ShadowStorage - Add a new volume shadow copy storage association\r\nCreate Shadow - Create a new volume shadow copy\r\nDelete Shadows - Delete volume shadow copies\r\nDelete ShadowStorage - Delete volume shadow copy storage associations\r\nList Providers - List registered volume shadow copy providers\r\nList Shadows - List existing volume shadow copies\r\nList ShadowStorage - List volume shadow copy storage associations\r\nList Volumes - List volumes eligible for shadow copies\r\nList Writers - List subscribed volume shadow copy writers\r\nResize ShadowStorage - Resize a volume shadow copy storage association\r\nRevert Shadow - Revert a volume to a shadow copy\r\nQuery Reverts - Query the progress of in-progress revert operations.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\vssadmin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "VSSUIRUN.exe-19C1BE4655954E6E7AB7394C627A270F": { "file_name": "VSSUIRUN.exe", "file_path": "C:\\Windows\\system32\\VSSUIRUN.exe", "hash_md5": "19C1BE4655954E6E7AB7394C627A270F", "hash_sha1": "ACAC20D601168E4CEBC834AD748066207F2A0315", "hash_sha256": "5FB2A2AB658633C67EB870009BEF09307CFCAC8FEC25F00C1F358C602C340705", "hash_sha384": "7BF54E4B35CE78280CEE5A300E057745FA21F86F72DB6970B82C8FD48AB72E94BE1060036F2D77DC8D33D362C72C4657", "hash_sha512": "AD7FF0EB15BFC77AD75E67EAE126027DA3DBB0BCD2EA158729CE8CF8F1683A8D60600A4C770EE8DA132BA1B4B7E1565F63D3444F8E8B6335339027F6DD374CBB", "hash_ssdeep": "768:NDaynkEt1iGEL3tf5nwrqPOH7wWhyXZKwys4O5vJzSb6OG6HC+szbkN4dppainbo:XkE7FExRSEWhyXSZGQC+sfk64inb", "hash_imp": "05535B3A257AF8A8AE0A85A7B9EB4720", "hash_pesha1": "0AE93CA653DD2BC4503E4BAA845D33990C1E95E6", "hash_pe256": "4725309A3B1271AFCDA1AC772C4B1786552B3D2CEE3B58685546974763D2355C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Configure Shadow Copies", "meta_original_filename": "VSSUIRUN.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/5fb2a2ab658633c67eb870009bef09307cfcac8fec25f00c1f358c602c340705/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\VSSUI.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECD28": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\VSSUIRUN.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\VssTrace.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\system32\\vssui.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\system32\\ATL.DLL", "C:\\Windows\\system32\\NETAPI32.dll", "C:\\Windows\\system32\\VSSAPI.DLL", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\CLUSAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\SRVCLI.DLL", "C:\\Windows\\system32\\NETUTILS.DLL", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\vss_ps.dll", "C:\\Windows\\System32\\mstask.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\system32\\cscapi.dll" ], "runtime_window_title": "Shadow Copies" }, "VSSVC.exe-183B5C67CF8AACDF33CFD357A72F9490": { "file_name": "VSSVC.exe", "file_path": "C:\\Windows\\system32\\VSSVC.exe", "hash_md5": "183B5C67CF8AACDF33CFD357A72F9490", "hash_sha1": "9515ACD323639BB5A55515B625CFA6CF5135BEDE", "hash_sha256": "8A2E257EFE4E583B6379E91009DE252FA64F2A43F134B7FC1560CC3E8FBF3688", "hash_sha384": "BAF743000A8F94765B5B78410343071AD1628F43D8A4138E27DF07C79B3801F3DBD446B20D44C0EF7E979FAECC1B45F8", "hash_sha512": "5556EEC8D863929D195BF70597A05180AAF4FA785727EB45E5CBA8E89CF3BA4C8330D7FB6A10C5F428C8E2EAA6718A05EA8A5A2D0CE44DD04BF8FE3FB5F9D83C", "hash_ssdeep": "24576:uJwA9WElVxAGjQIjoBcd8ZcGldiPnqOxsX9A:uVFVMoo6uZjldiPJxsX", "hash_imp": "D013BBE605003724306CBF26BE73548F", "hash_pesha1": "2F89363FE79FB60AA0FFB6BE8BD0CA37A87D4FD4", "hash_pe256": "02D75AE609764D0829B7465AF85B3E17A1ED09FA97432417944DF2FC9E818194", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Volume Shadow Copy Service", "meta_original_filename": "VSSVC.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/8a2e257efe4e583b6379e91009de252fa64f2a43f134b7fc1560cc3e8fbf3688/detection/", "runtime_modules": [ "C:\\Windows\\system32\\VSSVC.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\DEVOBJ.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\system32\\VSSAPI.DLL", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\VssTrace.DLL", "C:\\Windows\\system32\\AUTHZ.dll", "C:\\Windows\\system32\\VirtDisk.dll", "C:\\Windows\\system32\\bcd.dll", "C:\\Windows\\system32\\FLTLIB.DLL" ] }, "w32tm.exe-EB05B99953C30E25B4CA97F903A0DEA9": { "file_name": "w32tm.exe", "file_path": "C:\\Windows\\system32\\w32tm.exe", "hash_md5": "EB05B99953C30E25B4CA97F903A0DEA9", "hash_sha1": "2EB828994FA91E61376917496D87972EB116F6AE", "hash_sha256": "A6068FDD06A779798BE73420AE7E91544C23B96EB01D75A1BE86EAD8C0413E6B", "hash_sha384": "1A20536290E92B4F2CEB9FCA1E601A98D41A73AF28F991209BA8876CE9245D2A58FA953ACBBFF959CDBC9E7BA439F18E", "hash_sha512": "F8AEF1FC53B8A3E8AFBD881959CAEC65E7BFB6C8BFA2723223A94AFF93466BAF8657809100E0B1F3BAE517F1DCDB2D773BD81EFC0770F71E334F3912D8A23C6F", "hash_ssdeep": "3072:eaze49f0cro8wkY0hWbmemIcTQX1WRfWvxv+RhUZ4JmQGKbUCyUXpn7cIW5exIs7:eaqVkTATcI1WRk+RhU2hZPWodZJuhz", "hash_imp": "386119C6C0099E2C065ADCD2AA770E11", "hash_pesha1": "EEE5E0ABF6067EEB771FC0590159C977543C2D82", "hash_pe256": "D05C714B751B78B901282399AD8DA7328BD9E5C5AFBC64FD193FAA58B89C928C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Time Service Diagnostic Tool", "meta_original_filename": "w32time.dll.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a6068fdd06a779798be73420ae7e91544c23b96eb01d75a1be86ead8c0413e6b/detection/", "output": "w32tm [/? | /register | /unregister ]\r\n ? - this help screen.\r\n register - register to run as a service and add default\r\n configuration to the registry.\r\n unregister - unregister service and remove all configuration\r\n information from the registry.\r\n\r\nw32tm /monitor [/domain:<domain name>]\r\n [/computers:<name>[,<name>[,<name>...]]]\r\n [/threads:<num>] [/ipprotocol:<4|6>] [/nowarn]\r\n domain - specifies which domain to monitor. If no domain name\r\n is given, or neither the domain nor computers option is\r\n specified, the default domain is used. This option may be\r\n used more than once.\r\n computers - monitors the given list of computers. Computer\r\n names are separated by commas, with no spaces. If a name is\r\n prefixed with a '*', it is treated as an AD PDC. This option\r\n may be used more than once.\r\n threads - how many computers to analyze simultaneously. The\r\n default value is 3. Allowed range is 1-50.\r\n ipprotocol - specify the IP protocol to use. The default is\r\n to use whatever is available.\r\n nowarn - skip warning message.\r\n\r\nw32tm /ntte <NT time epoch>\r\n Convert a NT system time, in (10^-7)s intervals from 0h 1-Jan 1601,\r\n into a readable format.\r\n\r\nw32tm /ntpte <NTP time epoch>\r\n Convert an NTP time, in (2^-32)s intervals from 0h 1-Jan 1900, into\r\n a readable format.\r\n\r\nw32tm /resync [/computer:<computer>] [/nowait] [/rediscover] [/soft]\r\n Tell a computer that it should resynchronize its clock as soon\r\n as possible, throwing out all accumulated error statistics.\r\n computer:<computer> - computer that should resync. If not\r\n specified, the local computer will resync.\r\n nowait - do not wait for the resync to occur;\r\n return immediately. Otherwise, wait for the resync to\r\n complete before returning.\r\n rediscover - redetect the network configuration and rediscover\r\n network sources, then resynchronize.\r\n soft - resync utilizing existing error statistics. Not useful,\r\n provided for compatibility.\r\n\r\nw32tm /stripchart /computer:<target> [/period:<refresh>]\r\n [/dataonly] [/samples:<count>] [/packetinfo] [/ipprotocol:<4|6>] [/rdtsc]\r\n Display a strip chart of the offset between this computer and\r\n another computer.\r\n computer:<target> - the computer to measure the offset against.\r\n period:<refresh> - the time between samples, in seconds. The\r\n default is 2s\r\n dataonly - display only the data, no graphics.\r\n samples:<count> - collect <count> samples, then stop. If not\r\n specified, samples will be collected until Ctrl-C is pressed.\r\n packetinfo - print out NTP packet response message.\r\n ipprotocol - specify the IP protocol to use. The default is \r\n to use whatever is available.\r\n rdtsc - display the TSC values and time offset data in CSV format.\r\n The output displays TSC and FILETIME values captured before the \r\n NTP request is sent, TSC value after an NTP response is received\r\n along with NTP roundtrip and time offset values.\r\n\r\n\r\nw32tm /config [/computer:<target>] [/update]\r\n [/manualpeerlist:<peers>] [/syncfromflags:<source>]\r\n [/LocalClockDispersion:<seconds>]\r\n [/reliable:(YES|NO)]\r\n [/largephaseoffset:<milliseconds>]\r\n computer:<target> - adjusts the configuration of <target>. If not\r\n specified, the default is the local computer.\r\n update - notifies the time service that the configuration has\r\n changed, causing the changes to take effect.\r\n manualpeerlist:<peers> - sets the manual peer list to <peers>,\r\n which is a space-delimited list of DNS and/or IP addresses.\r\n When specifying multiple peers, this switch must be enclosed in\r\n quotes.\r\n syncfromflags:<source> - sets what sources the NTP client should\r\n sync from. <source> should be a comma separated list of\r\n these keywords (not case sensitive):\r\n MANUAL - sync from peers in the manual peer list\r\n DOMHIER - sync from an AD DC in the domain hierarchy\r\n NO - sync from none\r\n ALL - sync from both manual and domain peers \r\n LocalClockDispersion:<seconds> - configures the accuracy of the\r\n internal clock that w32time will assume when it can't acquire \r\n time from its configured sources. \r\n reliable:(YES|NO) - set whether this machine is a reliable time source.\r\n This setting is only meaningful on domain controllers. \r\n YES - this machine is a reliable time service\r\n NO - this machine is not a reliable time service\r\n largephaseoffset:<milliseconds> - sets the time difference between \r\n local and network time which w32time will consider a spike. \r\n\r\nw32tm /tz\r\n Display the current time zone settings.\r\n\r\nw32tm /dumpreg [/subkey:<key>] [/computer:<target>]\r\n Display the values associated with a given registry key.\r\n The default key is HKLM\\System\\CurrentControlSet\\Services\\W32Time\r\n (the root key for the time service).\r\n subkey:<key> - displays the values associated with subkey <key> \r\n of the default key.\r\n computer:<target> - queries registry settings for computer <target>.\r\n\r\nw32tm /query [/computer:<target>] \r\n {/source | /configuration | /peers | /status} \r\n [/verbose]\r\n Display a computer's windows time service information.\r\n computer:<target> - query the information of <target>. If not\r\n specified, the default is the local computer.\r\n source: display the time source.\r\n configuration: display the configuration of run-time and where \r\n the setting comes from. In verbose mode, display the undefined \r\n or unused setting too.\r\n peers: display a list of peers and their status.\r\n status: display windows time service status.\r\n verbose: set the verbose mode to display more information.\r\n\r\nw32tm /debug {/disable | {/enable /file:<name> /size:<bytes> /entries:<value>\r\n [/truncate]}} \r\n Enable or disable local computer windows time service private log.\r\n disable: disable the private log.\r\n enable: enable the private log.\r\n file:<name> - specify the absolute filename.\r\n size:<bytes> - specify the maximum size for circular logging.\r\n entries:<value> - contains a list of flags, specified by number and\r\n separated by commas, that specify the types of information that \r\n should be logged. Valid numbers are 0 to 300. A range of numbers \r\n is valid, in addition to single numbers, such as 0-100,103,106. \r\n Value 0-300 is for logging all information.\r\n truncate: truncate the file if it exists.\r\n\r\nw32tm /leapseconds /getstatus [/verbose]\r\n Display the status of leap seconds on the local machine.\r\n verbose: Set the verbose mode to display more information.\n", "runtime_modules": [ "C:\\Windows\\system32\\w32tm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "WaaSMedicAgent.exe-9FFE5A2D772BC2EF8090339286838086": { "file_name": "WaaSMedicAgent.exe", "file_path": "C:\\Windows\\system32\\WaaSMedicAgent.exe", "hash_md5": "9FFE5A2D772BC2EF8090339286838086", "hash_sha1": "A149037DF9BC8C3E3658B81154934AE4344A5BC1", "hash_sha256": "C25AB34D03892CA1D96562BAC72C2A49BCE5CB1468C104AA59CF8603A7037D25", "hash_sha384": "74965B46E9AA4A72A9FE7BD732F090CBF0798C8DF14D1D6E6E915593F326487D8FFD1003E7215FE4F5986FFF2E2C2A16", "hash_sha512": "0B151606A29EB1C31421BB9C5BDC6B871390D38E0662EE92A80DFCD5D822EF634D58BBCE85AC5D86ECB612E594E277C909C66A626105671E17104488EF3C9988", "hash_ssdeep": "1536:gYqyRPTu9Om35c26ToYuVwcQ47t7Gtqbm54fg4B1MMEatm5Q1SSjS5H8Nxd:gcJyQkbx7GCbfg4B1M1UDrjS5c9", "hash_imp": "56EC755D1DB43659CE880C239FDFA1D8", "hash_pesha1": "954F6BC1B17C0FEAA1A9FC5CA040199171035184", "hash_pe256": "F368A2655BF3CA3BE9BD908B0EA1A862101337B4641EAC07AA4CDA246A0DB30F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WaasMedic Agent Exe", "meta_original_filename": "WaasMedicAgent.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.802 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.802", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c25ab34d03892ca1d96562bac72c2a49bce5cb1468c104aa59cf8603a7037d25/detection/", "runtime_modules": [ "C:\\Windows\\system32\\WaaSMedicAgent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "waitfor.exe-2C94AFFDC7A23AD60BD0BC8A37B503B5": { "file_name": "waitfor.exe", "file_path": "C:\\Windows\\system32\\waitfor.exe", "hash_md5": "2C94AFFDC7A23AD60BD0BC8A37B503B5", "hash_sha1": "E1EAEB740A3313249EFA1C1C040353316CDDFABC", "hash_sha256": "A414E8721A683EC797508EB8DB094398BA35D4980416DEAEAEC9683C813BB844", "hash_sha384": "9409E21B56B2ABF07A36C313FFD5E1C42024C9F44BBA7826B07B4A24C96E176462AF1C05ACD5683683D2D1983335C188", "hash_sha512": "A922E00A81BB008E1B89611325995FF7D1E1BF933F17EEB5EF6E64A1D8D925B53DB621646F1F33BCDD3A5FC704F152226A10C6BD2C629A29338DDC502637FF0B", "hash_ssdeep": "768:1WCxySqrC5SHa/zzsuPuyX3mmVFUpu4cxLBPHKSa2sx6nDCS:P54ctwu4CHKdx6DCS", "hash_imp": "8275F58C1058DF4BAFF590DA991AC78C", "hash_pesha1": "FD76B78A17107F0F2F9301539222020391526202", "hash_pe256": "67EEA8832BC9E946D0A018D22AFDCEFC887A9259570128894A0BED06A877DBC0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "waitfor - wait/send a signal over a network", "meta_original_filename": "waitfor.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/a414e8721a683ec797508eb8db094398ba35d4980416deaeaec9683c813bb844/detection/", "output": "\r\nWaitFor has two ways of working: \r\n\r\nSyntax 1: to send a signal\r\n WAITFOR [/S system [/U user [/P [password]]]] /SI signal\r\n\r\nSyntax 2: to wait for a signal\r\n WAITFOR [/T timeout] signal \r\n\r\nDescription:\r\n This tool sends, or waits for, a signal on a system. When /S is not\r\n specified, the signal will be broadcasted to all the systems in a\r\n domain. If /S is specified, then the signal will be sent only\r\n to the specified system.\r\n\r\nParameter List:\r\n /S system Specifies remote system to send signal to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given user context.\r\n\r\n /SI Sends the signal across the net to waiting machines\r\n\r\n /T timeout Number of seconds to wait for signal. Valid range\r\n is 1 - 99999. Default is to wait forever for signal.\r\n\r\n signal The name of the signal to wait for or to send.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE: A system can wait for multiple unique signal names.\r\n The signal name cannot exceed 225 characters and cannot\r\n contain characters other than a-z, A-Z, 0-9 and ASCII \r\n characters in the range 128-255.\r\n\r\nExamples:\r\n WAITFOR /?\r\n WAITFOR SetupReady \r\n WAITFOR CopyDone /T 100 \r\n WAITFOR /SI SetupReady \r\n WAITFOR /S system /U user /P password /SI CopyDone\r\n", "error": "ERROR: The signal cannot contain characters other than a-z, A-Z, 0-9 \r\nand ASCII characters in the range 128-255.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\waitfor.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\waitfor.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\MPR.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\system32\\srvcli.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "WallpaperHost.exe-9A6E3B49314E770F0BA69EFFF69EC044": { "file_name": "WallpaperHost.exe", "file_path": "C:\\Windows\\system32\\WallpaperHost.exe", "hash_md5": "9A6E3B49314E770F0BA69EFFF69EC044", "hash_sha1": "4515FE3DDEC9E8A941F56C348DE3A83F0426BA07", "hash_sha256": "564F1C7B9F5E9818656DFDCE2BDFB7AF2C7A78819E67A2F8766CB2DD785F01E5", "hash_sha384": "1B08EBED064D4382C2C789C079C67469B0A5A8007B1D4329E6D91FD6BCF90B9CC8302E6935560B01E15ED20EAD9B2019", "hash_sha512": "433F7F4BE9AA4C0C00274CFD9E529955EFBC7F9B33DC571CA031A298C0475C2909F28AF9F1760873DF59F573A52B61904B03C808B5DF8BE18B8B2D3FDDFEB180", "hash_ssdeep": "384:442IUibo4a5QKNlZLFDTb5E5Da5YDgkeeC3k6bGRRSenrzKJIWljgL1GGyvMXLWh:442IUibjaHDTFEeYkke5U6SRRfrSIwju", "hash_imp": "A1F991B4FDC56F63965DBE7640A1BE21", "hash_pesha1": "C685709AA8EBC27DBCD9FEFE2D45D8BDC2B909BB", "hash_pe256": "7086C771717A2CE8CEB9FC767CE350D259CABC6968986B67D9DB29ED0A3C69E4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Wallpaper Host Process", "meta_original_filename": "WallpaperHost.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/564f1c7b9f5e9818656dfdce2bdfb7af2c7a78819e67a2f8766cb2dd785f01e5/detection/", "runtime_modules": [ "C:\\Windows\\system32\\WallpaperHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll" ] }, "WebCache.exe-30A437405E42AB2E5DBEA6B97D20A84C": { "file_name": "WebCache.exe", "file_path": "C:\\Windows\\system32\\WebCache.exe", "hash_md5": "30A437405E42AB2E5DBEA6B97D20A84C", "hash_sha1": "D01119082619E9567148C0F77F5199B4648EF4A2", "hash_sha256": "925F4358D32C7DFC9D8B8E0107EC638D23B72B538E45E438F5686C83E342A4C3", "hash_sha384": "2E83F361A1224CF145DFF10D8433B80AE80B2485A78C815A99C7681BC41D7237B7BB021EAA6896BC5E543C665C0D9363", "hash_sha512": "EE348705DF1462193BA1932C32FCD10754B032E9819D874A65000E2F3C2E2A29586DEEE7E51CCD53F34704EE47BAEDA3B358607503616C84CF91C42760999FA5", "hash_ssdeep": "192:weUS6xJKE4xL85laIVEtrNe7Tt3nGohB4ERWBhBlWgFf3:wPzU4mIuxG9hB2BZWgFv", "hash_imp": "1E6C1E2F583A2D21FFDA9BEFA7230B3A", "hash_pesha1": "CB1979330EA995A4CE083066627025E31A05B56F", "hash_pe256": "374A1D22B18F60446CD36045D837000A93556E1A13A71018F0392BE571506E0F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Web Cache", "meta_original_filename": "webcache.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/925f4358d32c7dfc9d8b8e0107ec638d23b72b538e45e438f5686c83e342a4c3/detection/" }, "wecutil.exe-21F57C1E019094BC410FDFFFE542C62E": { "file_name": "wecutil.exe", "file_path": "C:\\Windows\\system32\\wecutil.exe", "hash_md5": "21F57C1E019094BC410FDFFFE542C62E", "hash_sha1": "E198E04C7BCC584779CAB9A42E5D6AA13D668395", "hash_sha256": "96F7CA1B02C1A0D63747F0BD1448A723A4F49CBEF45A0DBB168E69B2F5FB98F5", "hash_sha384": "3140A0357CE042D7C4604D4DB3ADEE995B2E7FC25138048626CA29BE8741DA5B004EFC320946E27CAADB287C8A3FC0DD", "hash_sha512": "2F843C9034B8E274E4A9C4F101E95B3917AF2D29215B41D1FC4B17B47C2EE0F64D15953AAF5D06FAF73D223662D631593445981C0854959E7D4814F10820672A", "hash_ssdeep": "3072:9m7rsTmitRNqIc9rijGByFvW6nuFe7jjf:9m7Amd7iaUZuFAj", "hash_imp": "187E199429496C39FF6A95AD245ED45E", "hash_pesha1": "3DA032388544992188B50A032CCD492C07A7866E", "hash_pe256": "CF9581624778B7830C49DE06038BEC51382CD6A16E03337A2B4F33C86DDCFF1B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Collector Command Line Utility", "meta_original_filename": "WECUTIL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/96f7ca1b02c1a0d63747f0bd1448a723a4f49cbef45a0dbb168e69b2f5fb98f5/detection/", "output": "Windows Event Collector Utility\r\n\r\nEnables you to create and manage subscriptions to events forwarded from remote\r\nevent sources that support WS-Management protocol.\r\n\r\nUsage:\r\n\r\nYou can use either the short (i.e. es, /f) or long (i.e. enum-subscription, /format)\r\nversion of the command and option names. Commands, options and option values are\r\ncase-insensitive.\r\n\r\n(ALL UPPER-CASE = VARIABLE)\r\n\r\nwecutil COMMAND [ARGUMENT [ARGUMENT] ...] [/OPTION:VALUE [/OPTION:VALUE] ...]\r\n\r\nCommands:\r\n\r\nes (enum-subscription) List existent subscriptions.\r\ngs (get-subscription) Get subscription configuration.\r\ngr (get-subscriptionruntimestatus) Get subscription runtime status.\r\nss (set-subscription) Set subscription configuration.\r\ncs (create-subscription) Create new subscription.\r\nds (delete-subscription) Delete subscription.\r\nrs (retry-subscription) Retry subscription.\r\nqc (quick-config) Configure Windows Event Collector service.\r\n\r\nCommon options:\r\n\r\n/h|? (help)\r\nGet general help for the wecutil program.\r\n\r\nwecutil { -help | -h | -? }\r\n\r\nFor arguments and options, see usage of specific commands:\r\n\r\nwecutil COMMAND -?\r\n", "runtime_modules": [ "C:\\Windows\\system32\\wecutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ], "error": "Command help is not supported. Error = 0x57.\r\nThe parameter is incorrect.\r\n" }, "WerFault.exe-D6DA73EF6271A7C2B5DD7CE94393470C": { "file_name": "WerFault.exe", "file_path": "C:\\Windows\\system32\\WerFault.exe", "hash_md5": "D6DA73EF6271A7C2B5DD7CE94393470C", "hash_sha1": "B468FC0EB9977F2F2DC9B6C2A0B10A1969A0C29E", "hash_sha256": "3B4CEFD893A605D8CC768A09AB0F34BBB02D21495EB088F582095D985944F247", "hash_sha384": "DA8B3A74D45B39C6A5FA473868BD19645CAB9F0D8EC766B813D7EF1E800B4C1E4B9179950DA823605BDEFBDDCD91547F", "hash_sha512": "DB8FF115A232D56DCDE8D584699DBE2FFE8D18F43CFD7683152F63B97E6C560542578F971C0F8B5EF98281DE58ED581779CF5F74B66FB79452FE85E2F40A41C0", "hash_ssdeep": "6144:MUSFI3/9XHlM6PamS1XFhPpDB1/VliLomj10uyHOE71+qiOBnUGVJyB60OHyLC7b:UIdK6+1XFTDbVUom50DiOBnUGc2Hywb", "hash_imp": "58646A08EC3B9CF4BF7D3A86852FFDC4", "hash_pesha1": "7C0C955D020098427237C9587B8D2223664D1421", "hash_pe256": "DB33652A5DBE1F9F29DF71FA3047E6A3CA8346F668B93E5FDB8A113EFE5BDF3C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Problem Reporting", "meta_original_filename": "WerFault.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/3b4cefd893a605d8cc768a09ab0f34bbb02d21495eb088f582095d985944f247/detection/", "runtime_modules": [ "C:\\Windows\\system32\\WerFault.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\wer.dll", "C:\\Windows\\system32\\dbghelp.dll" ] }, "WerFaultSecure.exe-BBF0F7C628D7487C47CD0B78C2DF0676": { "file_name": "WerFaultSecure.exe", "file_path": "C:\\Windows\\system32\\WerFaultSecure.exe", "hash_md5": "BBF0F7C628D7487C47CD0B78C2DF0676", "hash_sha1": "51AEFBF71219242B221EAAA20BAB01C3FB90CE8C", "hash_sha256": "6BD285A4FFC2C5CEABFF9A4B510FFB709557B21A8EAEE0C542906C185A71909A", "hash_sha384": "191A8E19AB88DBA1C8ACC3C4A8DFAD3752009A9E62A16B3552A70B0CC8898BC33383020FDC45EB3D251BAE8D13D3F471", "hash_sha512": "C9FA427FADA77600415E2E1E848D293BD4628EBE37E7F7215E8010CA3C3B577A319D251BC6583A215FEB9B91C1DECD93290C654D871A09698E5BC04D367C688E", "hash_ssdeep": "3072:GrAenrF+vLh/aEFJ+yC3pwRb6JPqB604HHy7hRCd39vyj/:GrAg5ih2VJyB60OHyLC7vy", "hash_imp": "4BD7B270C28F49463C975E7E22284E05", "hash_pesha1": "F14390000EFEA6A539DC58A6555412D9214090DE", "hash_pe256": "78593C66C71BB5B1F1F7862A377AE0746EB8B54DCCB59354E4A7226C273BD8EC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Fault Reporting", "meta_original_filename": "WerFaultSecure.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Windows": "File", "(R-D) C:\\Windows\\System32\\dbghelp.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" } }, "wermgr.exe-319F191E142B2720AE7E200F31E5413A": { "file_name": "wermgr.exe", "file_path": "C:\\Windows\\system32\\wermgr.exe", "hash_md5": "319F191E142B2720AE7E200F31E5413A", "hash_sha1": "6ABA542F080BF2F2B91CDEB8A571EA7BCBC6224A", "hash_sha256": "54D4F163BA41963A1E1BE46E14882BBBE98A45F635B098326D8E7DA2F2F77320", "hash_sha384": "9983201FFBE185C47F24C39B97597843D7F20F75227AA8043221E7F92B3B0CC20972CD9590D7F08DF4E4DD0ABB9538A0", "hash_sha512": "4DAAE41CFF8B95658F85EC59F06D5E754E1AF6DA1E23A00C3E23342E7459FDF0B1F45B4F4F3C743C12B02C702084261801637E92948F9C3CD9E61914AF5685D9", "hash_ssdeep": "6144:es5GeSJH/yTgTnPInbJkMuFO1VJyB60OHyLC7vSk:eVedTgjEkhOzc2HywJ", "hash_imp": "D22C26E0BC8292A264EB6FB659373A7E", "hash_pesha1": "DDA0414C5BE27758991D773B66E484C789AFA895", "hash_pe256": "8C5BC54EB2E9478AAF44A4B050C4699D174FD5F03D548C1F6B6F93E924055EB0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Problem Reporting", "meta_original_filename": "WerMgr", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/54d4f163ba41963a1e1be46e14882bbbe98a45f635b098326d8e7da2f2f77320/detection/", "runtime_modules": [ "C:\\Windows\\system32\\wermgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\wer.dll", "C:\\Windows\\System32\\advapi32.dll" ] }, "wevtutil.exe-3D2AA064E7017000B1219BBA83D03DC6": { "file_name": "wevtutil.exe", "file_path": "C:\\Windows\\system32\\wevtutil.exe", "hash_md5": "3D2AA064E7017000B1219BBA83D03DC6", "hash_sha1": "B8CD8BE1CD2D5F4C0F60F217D517454BDB3EB43E", "hash_sha256": "CCFFE548D686EB10FD825171D9C6D1C20AA59E639130AC8A9098776369E77B99", "hash_sha384": "B64263574BFB651EEB2B38184E80ED86A2EEACCCEC5D56BF4BE1E28B98654438D1DA25C5EDB1F073619001923D47A0C3", "hash_sha512": "83C2779F0E36B4342D06C22028F188C41D043E66E179E0CF71E02AFDFAB68F85BFAD49F0976C00D15E43390AAC0CD26EE2AC440E7C48691C8F4D385213F8F37A", "hash_ssdeep": "6144:KPdbXe7TVkB6MxYDjHtSVH4keBbGLRtE:KPdbO7mRijcVm6dt", "hash_imp": "05EF63632ADCBF76EE5EE8705934B349", "hash_pesha1": "C407AE78981B2D3C24E8E1CBC7F9B97380D2FA23", "hash_pe256": "FBDB0D6D74B0AAC621169625B908082FFF2DB4CEEBF8D57CD6C4D193C75BEE62", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Eventing Command Line Utility", "meta_original_filename": "wevtutil.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/ccffe548d686eb10fd825171d9c6d1c20aa59e639130ac8a9098776369e77b99/detection/", "output": "Windows Events Command Line Utility.\r\n\r\nEnables you to retrieve information about event logs and publishers, install\r\nand uninstall event manifests, run queries, and export, archive, and clear logs.\r\n\r\nUsage:\r\n\r\nYou can use either the short (for example, ep /uni) or long (for example, \r\nenum-publishers /unicode) version of the command and option names. Commands, \r\noptions and option values are not case-sensitive.\r\n\r\nVariables are noted in all upper-case.\r\n\r\nwevtutil COMMAND [ARGUMENT [ARGUMENT] ...] [/OPTION:VALUE [/OPTION:VALUE] ...]\r\n\r\nCommands:\r\n\r\nel | enum-logs List log names.\r\ngl | get-log Get log configuration information.\r\nsl | set-log Modify configuration of a log.\r\nep | enum-publishers List event publishers.\r\ngp | get-publisher Get publisher configuration information.\r\nim | install-manifest Install event publishers and logs from manifest.\r\num | uninstall-manifest Uninstall event publishers and logs from manifest.\r\nqe | query-events Query events from a log or log file.\r\ngli | get-log-info Get log status information.\r\nepl | export-log Export a log.\r\nal | archive-log Archive an exported log.\r\ncl | clear-log Clear a log.\r\n\r\nCommon options:\r\n\r\n/{r | remote}:VALUE\r\nIf specified, run the command on a remote computer. VALUE is the remote computer \r\nname. Options /im and /um do not support remote operations.\r\n\r\n/{u | username}:VALUE\r\nSpecify a different user to log on to the remote computer. VALUE is a user name\r\nin the form domain\\user or user. Only applicable when option /r is specified.\r\n\r\n/{p | password}:VALUE\r\nPassword for the specified user. If not specified, or if VALUE is \"*\", the user \r\nwill be prompted to enter a password. Only applicable when the /u option is\r\nspecified.\r\n\r\n/{a | authentication}:[Default|Negotiate|Kerberos|NTLM]\r\nAuthentication type for connecting to remote computer. The default is Negotiate.\r\n\r\n/{uni | unicode}:[true|false]\r\nDisplay output in Unicode. If true, then output is in Unicode. \r\n\r\nTo learn more about a specific command, type the following:\r\n\r\nwevtutil COMMAND /?\r\n", "error": "Command help is not supported.\r\nThe parameter is incorrect.\r\n" }, "wextract.exe-91243AFCF25E3A7705CAAA03492996B7": { "file_name": "wextract.exe", "file_path": "C:\\Windows\\system32\\wextract.exe", "hash_md5": "91243AFCF25E3A7705CAAA03492996B7", "hash_sha1": "527FE1F72699819687B882BDC076B13297010EC8", "hash_sha256": "1C010BE91AC208AAC741A2A5BF2439D9EDAECDC537B9303F09E5E1668766892B", "hash_sha384": "8C54CB9FF73C7E35FE1ECC80BBA2142D5528B6942F080002FCF17CA1C4DA4F84CCD9356C4CF8B31ECA92D7CFE27592F5", "hash_sha512": "3D0C0D7E1E84D1C2FDCAF58D582F664ADF780EBA0731D8143B184313EB2A3D837D08F18C873564B2482141F5789EF1E9B71D097B7408F70FE7576B28E8284BF8", "hash_ssdeep": "3072:3vGyYiSDnt1pcWp1icKAArDZz4N9GhbkUNEk951:54Zdp0yN90vE", "hash_imp": "4CEA7AE85C87DDC7295D39FF9CDA31D1", "hash_pesha1": "32E4587AFFD8F1B92B81CD2FD52D84BF276E9E18", "hash_pe256": "CAB4A65458C881F75E77550F3D69BC52A8A92741A1C14F68FA066C7AC155FA9F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Win32 Cabinet Self-Extractor ", "meta_original_filename": "WEXTRACT.EXE .MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/65", "filescan_vtlink": "https://www.virustotal.com/gui/file/1c010be91ac208aac741a2a5bf2439d9edaecdc537b9303f09e5e1668766892b/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\wextract.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wextract.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "where.exe-9C7F19C9975979E2ED1B2CE5383BA4E8": { "file_name": "where.exe", "file_path": "C:\\Windows\\system32\\where.exe", "hash_md5": "9C7F19C9975979E2ED1B2CE5383BA4E8", "hash_sha1": "471B458EDCB8613BEDA1EAED03F696CF72C763C3", "hash_sha256": "FD9D35CAE2120C38CB96D38F040737CA80E41F1FC59B1B02324EFB7E091AA255", "hash_sha384": "E5A50DAA3386D46040338FFC4983708B73C8854F82871856DD9471B5957270133A1B0E6C3ADB0767AC187404A4AA6B63", "hash_sha512": "1164092A2A1CD8767761237A14EFE714041B66A37B77D91262A0B7FEA1BE88FDA86EF3B8416F97242D171CF88FF7B7458D99359FC42D4E3C3D424DB31402A4FA", "hash_ssdeep": "768:tPSuf/amM13jf0X9Zz3qMXs3wp4MqfHX3/YvHnwx+dp:+fQP4JP3/hxGp", "hash_imp": "1B253A651AEF9DCAAFF94AFE777011D1", "hash_pesha1": "23D11271D9FE5D9074E97A86FCF577E6C8065817", "hash_pe256": "277DFEA2D2CDACF8C57EAB63D98B56DA5BD1E153790411E43B1FFA41DB05522D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Where - Lists location of files", "meta_original_filename": "where.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/fd9d35cae2120c38cb96d38f040737ca80e41f1fc59b1b02324efb7e091aa255/detection/", "output": "\r\nWHERE [/R dir] [/Q] [/F] [/T] pattern...\r\n\r\nDescription:\r\n Displays the location of files that match the search pattern.\r\n By default, the search is done along the current directory and\r\n in the paths specified by the PATH environment variable.\r\n\r\nParameter List:\r\n /R Recursively searches and displays the files that match the\r\n given pattern starting from the specified directory.\r\n\r\n /Q Returns only the exit code, without displaying the list\r\n of matched files. (Quiet mode)\r\n\r\n /F Displays the matched filename in double quotes.\r\n\r\n /T Displays the file size, last modified date and time for all\r\n matched files.\r\n\r\n pattern Specifies the search pattern for the files to match.\r\n Wildcards * and ? can be used in the pattern. The\r\n \"$env:pattern\" and \"path:pattern\" formats can also be\r\n specified, where \"env\" is an environment variable and\r\n the search is done in the specified paths of the \"env\"\r\n environment variable. These formats should not be used\r\n with /R. The search is also done by appending the\r\n extensions of the PATHEXT variable to the pattern.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE: The tool returns an error level of 0 if the search is\r\n successful, of 1 if the search is unsuccessful and\r\n of 2 for failures or errors.\r\n\r\nExamples:\r\n WHERE /?\r\n WHERE myfilename1 myfile????.*\r\n WHERE $windir:*.* \r\n WHERE /R c:\\windows *.exe *.dll *.bat \r\n WHERE /Q ??.??? \r\n WHERE \"c:\\windows;c:\\windows\\system32:*.dll\"\r\n WHERE /F /T *.dll \r\n", "error": "ERROR: Invalid argument or option - '/h'.\r\nType \"WHERE /?\" for usage help.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\where.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "whoami.exe-43C2D3293AD939241DF61B3630A9D3B6": { "file_name": "whoami.exe", "file_path": "C:\\Windows\\system32\\whoami.exe", "hash_md5": "43C2D3293AD939241DF61B3630A9D3B6", "hash_sha1": "47D7864D26FC67E0D60391CBF170D33DA518C322", "hash_sha256": "1D5491E3C468EE4B4EF6EDFF4BBC7D06EE83180F6F0B1576763EA2EFE049493A", "hash_sha384": "7AD554DB5C90AF3DCF1ACF2FA1EB3D872B0AC1F6ED39E91A63F82DDB878013A51B89508D91C0F269D8B1FEA7ED212FAE", "hash_sha512": "C060C9A1D1702726B0F742C158EBB7B8DA9A47EF144746ECA8E702EF8A9D8BC59FCF14E21EE5C43B3B1D7847C9BF9B7EA19FB9F1318116498CC9340FA019F1F0", "hash_ssdeep": "1536:bGv/7yW0HOeaie0SL/ecAb6D/MPL/8sGYJOyxQVj:bGbypueHcG6DXsGAOyxQ5", "hash_imp": "7FF0758B766F747CE57DFAC70743FB88", "hash_pesha1": "6C6274A3854C89E7903B51003C9C1FE07B3BD5F0", "hash_pe256": "17FDF6EA4B1E3C08C17AF121C9E174240BEB743F4BE9EB661AC26681D1031946", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "whoami - displays logged on user information", "meta_original_filename": "whoami.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/1d5491e3c468ee4b4ef6edff4bbc7d06ee83180f6f0b1576763ea2efe049493a/detection/", "output": "\r\nWhoAmI has three ways of working: \r\n\r\nSyntax 1:\r\n WHOAMI [/UPN | /FQDN | /LOGONID]\r\n\r\nSyntax 2:\r\n WHOAMI { [/USER] [/GROUPS] [/CLAIMS] [/PRIV] } [/FO format] [/NH]\r\n\r\nSyntax 3:\r\n WHOAMI /ALL [/FO format] [/NH]\r\n\r\nDescription:\r\n This utility can be used to get user name and group information\r\n along with the respective security identifiers (SID), claims,\r\n privileges, logon identifier (logon ID) for the current user\r\n on the local system. I.e. who is the current logged on user?\r\n If no switch is specified, tool displays the user name in NTLM\r\n format (domain\\username).\r\n\r\nParameter List:\r\n /UPN Displays the user name in User Principal \r\n Name (UPN) format.\r\n\r\n /FQDN Displays the user name in Fully Qualified \r\n Distinguished Name (FQDN) format.\r\n\r\n /USER Displays information on the current user\r\n along with the security identifier (SID).\r\n\r\n /GROUPS Displays group membership for current user,\r\n type of account, security identifiers (SID)\r\n and attributes.\r\n\r\n /CLAIMS Displays claims for current user,\r\n including claim name, flags, type and values.\r\n\r\n /PRIV Displays security privileges of the current\r\n user.\r\n\r\n /LOGONID Displays the logon ID of the current user.\r\n\r\n /ALL Displays the current user name, groups \r\n belonged to along with the security \r\n identifiers (SID), claims and privileges for \r\n the current user access token.\r\n\r\n /FO format Specifies the output format to be displayed.\r\n Valid values are TABLE, LIST, CSV.\r\n Column headings are not displayed with CSV\r\n format. Default format is TABLE.\r\n\r\n /NH Specifies that the column header should not\r\n be displayed in the output. This is\r\n valid only for TABLE and CSV formats.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n WHOAMI\r\n WHOAMI /UPN\r\n WHOAMI /FQDN \r\n WHOAMI /LOGONID\r\n WHOAMI /USER\r\n WHOAMI /USER /FO LIST\r\n WHOAMI /USER /FO CSV\r\n WHOAMI /GROUPS\r\n WHOAMI /GROUPS /FO CSV /NH\r\n WHOAMI /CLAIMS\r\n WHOAMI /CLAIMS /FO LIST\r\n WHOAMI /PRIV\r\n WHOAMI /PRIV /FO TABLE\r\n WHOAMI /USER /GROUPS\r\n WHOAMI /USER /GROUPS /CLAIMS /PRIV\r\n WHOAMI /ALL\r\n WHOAMI /ALL /FO LIST\r\n WHOAMI /ALL /FO CSV /NH\r\n WHOAMI /?\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"WHOAMI /?\" for usage.\r\n" }, "wiaacmgr.exe-7CAFCC5FAAA4FDDC3BDFED3BAD0FF147": { "file_name": "wiaacmgr.exe", "file_path": "C:\\Windows\\system32\\wiaacmgr.exe", "hash_md5": "7CAFCC5FAAA4FDDC3BDFED3BAD0FF147", "hash_sha1": "A71C62913D1B831FFCDE740EADCDCA5CF6170657", "hash_sha256": "C485B377A3982A890B91F71495B1D74B7E0244D8B571800D462BFA051B0BF6C3", "hash_sha384": "A902890C79A7D971072526B1EB4E91B98EBDC325A7628C427DE55F1C6B45B92D1629657A251B74CE2AF15D6AF86602F3", "hash_sha512": "51A8F74BA208E45A4288F72E31A2752B1DA5D686226C01D794537481DFF1E5622BD89DD6031494C26CA40311D5623D11BBAA35067877ACBD9EB130098203D3B3", "hash_ssdeep": "1536:wL46uxQPZnlN3EIpXey07p352nDXg3Ln6cMFQWd+uYiuWp+UmBo6Atf7:U4r6AIpOy0lEDXM+d+uMGmBo6Q", "hash_imp": "A33A978964804D79AED85FB0267A592E", "hash_pesha1": "7B712AE57C98D090A6067966D4E3718E419F6948", "hash_pe256": "C3D0A0C7E87F59CB311279F498E7B07042A5BFBA75C4CB5CFAD2C61A52E22800", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Picture Acquisition Wizard", "meta_original_filename": "WIAACMGR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c485b377a3982a890b91f71495b1d74b7e0244d8b571800d462bfa051b0bf6c3/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "(R-D) C:\\Windows\\System32\\en-US\\wiaacmgr.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\scansetting.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1144": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wiaacmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\ScanSetting.DLL", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\system32\\MSIMG32.dll", "C:\\Windows\\system32\\UxTheme.dll" ] }, "wiawow64.exe-0352500A387C5C2512EEE104FB13506A": { "file_name": "wiawow64.exe", "file_path": "C:\\Windows\\system32\\wiawow64.exe", "hash_md5": "0352500A387C5C2512EEE104FB13506A", "hash_sha1": "5936340CA1E4EC563E2AE3D9F3DBCF60647113E4", "hash_sha256": "310D64EB8F9D0B8CDE591AA0B8857BF2BCD3CD25A232429904C34388D1B9F829", "hash_sha384": "6C0E70387E060F1F8BBBE51A2E726047CF391A96D2308248554A1B287694ADAE452DEAE5F11CFB98807509E32C17E412", "hash_sha512": "2B1A2BED5ACE22FEDB9A777EF8EC72F21D7116B1156B854FDCF5015BF998745FEA53185323A51F8019C27391885871919EF02822275F49586F314D264537D775", "hash_ssdeep": "768:CxWWbCxn1DZsIo9JGxa1ArwlrDSomFA2//WQpaMls8GDSlmY:3nPsyai8BDmFA7QphBz", "hash_imp": "AEE5239EB39B2A68BBB39BB42EAC0312", "hash_pesha1": "3599957F445ABF6F129C3B356956DF15CCF3C02B", "hash_pe256": "CCD76F1B2650F3917A1C82417AC3E503E5A5F4F213667F95905D26E722573A6F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Thunking WIA APIS from 32 to 64 Process", "meta_original_filename": "wiawow64.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/310d64eb8f9d0b8cde591aa0b8857bf2bcd3cd25a232429904c34388d1b9f829/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\scansetting.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\RPC Control\\DSEC744": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wiawow64.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\CFGMGR32.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\ScanSetting.DLL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\MFC42u.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\system32\\MSIMG32.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "wimserv.exe-2466B0BDEB916DB79519E8228D5BB209": { "file_name": "wimserv.exe", "file_path": "C:\\Windows\\system32\\wimserv.exe", "hash_md5": "2466B0BDEB916DB79519E8228D5BB209", "hash_sha1": "49816EF2976C9F6B85A7869C88BE7B60A1018CB4", "hash_sha256": "BA2B58BC77D665E43C9CEC3B8D8B88AEBFFD67114F38B29A0D1635AE4D7643EA", "hash_sha384": "D646841F9B1C9E7D9C9F8244CFC8F775AD20D5A5761C32D7416DC433D681ABBCA074FC71ED9761631BA0DBD0D9216D23", "hash_sha512": "51530F785666F50ED69FF0541B03CBDF2F1BAE75349A7F40147B505A2DF0FED699BD40F8A90A3583693C995B45407763B4861B7B2FFB495D26B067EF59BD8E1F", "hash_ssdeep": "12288:yz3cdi8KxgGNaCJTJrQMTIFXCu+GWx4aLY:yzv8KxgGAl3XCsi4a0", "hash_imp": "21FF17E6BA14FECC2B52892F3530717B", "hash_pesha1": "7C2FDAC070CA65AFDE7161D6252361BCCC0C9DFF", "hash_pe256": "ACADB94306DC2EDB940D2A87994157DA42DC7138179D986804556A3EA3FF7C6B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Wimfltr v2 extractor", "meta_original_filename": "extractr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Windows\\system32\\wimserv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\Cabinet.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\system32\\FLTLIB.DLL", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "win32calc.exe-46CDCA3D2EB9B837EC3C4CDA60D0D0D9": { "file_name": "win32calc.exe", "file_path": "C:\\Windows\\system32\\win32calc.exe", "hash_md5": "46CDCA3D2EB9B837EC3C4CDA60D0D0D9", "hash_sha1": "EC73FCAB989C8D525FE3BBCC3736BC3E6192A112", "hash_sha256": "3E2300394C15B59A964EAB45D9EB96D317650E2F7448FD1B4AE825A134402B7A", "hash_sha384": "8A2859D7B84CC78C77610FADCD00809C3616EB378279516EB9170DA0693409174E4F37463CBB3D63D285948494BD4C44", "hash_sha512": "D7264A701B04E4AF1344018E99EA9E4199EA4B5AEDAB29222D9FB01AFF2AD201E77A9E57A82133053379C327F686D3278749A1A160596614FB1C6BB4A026BFB3", "hash_ssdeep": "12288:P8aCOcE5uPG8aoSyTc7wGlsOOwCXDYferUAHeeN7c6O:PbP5mGzL7wYOwCXDY2rUmeh", "hash_imp": "BDE48881DABC2774907583E3DE072A63", "hash_pesha1": "BB8A214B9E1EB2FA49ACBE08C899571CEAE6AD57", "hash_pe256": "F4A61C49F81E474373C38CC4B57104FED8E7A4C21636953C75A85047C1A7CCC3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Calculator", "meta_original_filename": "WIN32CALC.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.771 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.771", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/3e2300394c15b59a964eab45d9eb96d317650e2f7448fd1b4ae825a134402b7a/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\win32calc.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\win32calc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\WINMM.dll", "C:\\Windows\\system32\\WINMMBASE.dll" ], "runtime_window_title": "Calculator" }, "WinBioDataModelOOBE.exe-511A80FD512020500CD58596317E3752": { "file_name": "WinBioDataModelOOBE.exe", "file_path": "C:\\Windows\\system32\\WinBioDataModelOOBE.exe", "hash_md5": "511A80FD512020500CD58596317E3752", "hash_sha1": "B6F90C47E7C2B5C6EC6BA0150A58B03C83425735", "hash_sha256": "67247AA01F43E691FEBB1000DA0DF0EF50837BCA39115F1C76E088F6E509952F", "hash_sha384": "199874A03F78F79A7B9C5C8B87D220DF41C6B8E521087BF600E7133A75A58E85A1CB0D9A6773EFC9260E3998F1CD59FD", "hash_sha512": "A195B67D277A5685FAE852A36940469F7100E0DBE78497EA821DAAE3DBE22589869FFFE3FAF47BC4E1987E59875EDC40FEC7F22FF7817C32777391C35B3B2BBC", "hash_ssdeep": "1536:ImzvYSFO4Seqv3ojmd6qT+t1HxsWs6qkNRsy2EPuR:PFO4SRv3ojeNT3kNT/m", "hash_imp": "095692A1EE5A4119C53E9D0EF3C12FB6", "hash_pesha1": "B6852F43D11D8B4600B2B317160C10934756BBEE", "hash_pe256": "1F4DD84EAC28B3426FCA195ECEDF8CCB4500D682962B025AD076EEBAF44850F7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WinBioDataModel OOBE", "meta_original_filename": "WinBioDataModelOOBE.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/67247aa01f43e691febb1000da0df0ef50837bca39115f1c76e088f6e509952f/detection/", "runtime_modules": [ "C:\\Windows\\system32\\WinBioDataModelOOBE.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ] }, "Windows.Media.BackgroundPlayback.exe-A59AB8DA93A8A340DB61D2D72A210C61": { "file_name": "Windows.Media.BackgroundPlayback.exe", "file_path": "C:\\Windows\\system32\\Windows.Media.BackgroundPlayback.exe", "hash_md5": "A59AB8DA93A8A340DB61D2D72A210C61", "hash_sha1": "2AE02F0FE88EE2757DFE222E90718E1D2CED8FBA", "hash_sha256": "FA7DA9587F07D847C492D371CFE18CCE09C54B49A1CBF05EFBB569B75939751F", "hash_sha384": "CDEBB45934E48B5EC8FE3A8E2B0A3568E41A6562FF77A2CBD7FA60A1E785A6E73D436E8CF0D4C866905DF8419D4708B0", "hash_sha512": "0D86361CAEEBE4A421AA5034DD773130CC55A08C03960082EA215A8C78A3FA3373CF72CF81C5D855D0687C4882368C3C1BB489EC241860A387402D5702B4A2DD", "hash_ssdeep": "384:3yVSWye4tCt2Ci4PytyMWGe2LJQ8HOrWZ5Wp:32S+t2CDPXPF2LXHT", "hash_imp": "475266A2489617ACC64ABDFCAE452AE0", "hash_pesha1": "27B16400E76E016068BB7E33B455C8520D57B33F", "hash_pe256": "541D2F25E61D4744C351E3CCA3AA9798E3558DBDA9296071A62E3D460EEBAC19", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Playback EXE", "meta_original_filename": "Windows.Media.Playback.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/fa7da9587f07d847c492d371cfe18cce09c54b49a1cbf05efbb569b75939751f/detection/", "runtime_modules": [ "C:\\Windows\\system32\\Windows.Media.BackgroundPlayback.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\Windows.Media.BackgroundMediaPlayback.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\MFPlat.DLL", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RTWorkQ.DLL", "C:\\Windows\\System32\\twinapi.appcore.dll", "C:\\Windows\\System32\\RMCLIENT.dll", "C:\\Windows\\System32\\WinTypes.dll" ] }, "Windows.WARP.JITService.exe-225B29274B30D4BA443619182BC3CC87": { "file_name": "Windows.WARP.JITService.exe", "file_path": "C:\\Windows\\system32\\Windows.WARP.JITService.exe", "hash_md5": "225B29274B30D4BA443619182BC3CC87", "hash_sha1": "EA5C1B9F4ABE1CB89BD29074A6E8940B0E7F4C94", "hash_sha256": "AB125094950E14CFA65DA7434C57839603C1086AF5D22646D2A667520099F6A3", "hash_sha384": "E5644F59A548B1DEE4D4D0D4E48DB11B57FD3284C33FB883B6EA61F9335204EA5F68587533CE63701F08010CC8DC95D3", "hash_sha512": "4281D256FFB6D65A1DCE842F365F6E601703A2DA494D7225A925E145DE681950FB9D15400B5A2AF65B92960FE626DFE706DF0FAE559A18D5D39694A4C1075692", "hash_ssdeep": "384:iE0BxeDKqMdmBKKoKGc4vPdL+l59k7v8TMtB6SZv3/f1l5lZPwuwgm738Dri09/I:i/xeDKBreELsTCU+X/3wug38Hi+3jiq", "hash_imp": "13444DB081562101A9054128190A4C11", "hash_pesha1": "CF5C7430B189A4A059FF13F28917CBE53FD2AFB8", "hash_pe256": "D0494796CABE989B4AD80853D4629980EFBFBAD00739923AEA94749D35A95175", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/ab125094950e14cfa65da7434c57839603c1086af5d22646d2a667520099f6a3/detection/", "runtime_modules": [ "C:\\Windows\\system32\\Windows.WARP.JITService.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll" ] }, "WindowsActionDialog.exe-5767BAF6F0209D1AE4A8CD2489B48876": { "file_name": "WindowsActionDialog.exe", "file_path": "C:\\Windows\\system32\\WindowsActionDialog.exe", "hash_md5": "5767BAF6F0209D1AE4A8CD2489B48876", "hash_sha1": "E6345A811331D11C1B9342479A413C616D441473", "hash_sha256": "F27A32776E3FCE6C6A5D3A9D46A84A286F71FD8380C5A7065EE34C3EC3D7932F", "hash_sha384": "7E6338787ECE06C7D563A8683A7E79DA1128BD5762E4EF3EF36B2B4664C48F68C7B6B94D6C850361A9542281752CA9E8", "hash_sha512": "795435DFB72C2384DCC9D5EB3D941AC120940AD3E3640CD4F79A6FC33F56DF2BE8E366D4C386D561A016BF8992A9CB05F607E6A93752EC814B47211A5FFD548E", "hash_ssdeep": "1536:GyLheN/QeJUatmaAa0/4kvqq4/ZnBNir9cIB5y4:GmG/DtVV0lQtiWIBA4", "hash_imp": "F42F7A5425CB00E71D7C4716F98BCA8F", "hash_pesha1": "42E72E22CB4C8A5D49A04C2404EA93333B25B807", "hash_pe256": "405DD46AD5B58B005045E95E9D28AB13E508E986706C482638CB84719D106111", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Action Dialog Broker", "meta_original_filename": "WindowsActionDialog.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/f27a32776e3fce6c6a5d3a9d46a84a286f71fd8380c5a7065ee34c3ec3d7932f/detection/" }, "WindowsUpdateElevatedInstaller.exe-AB7047923B7B8542902C6F9689E42CCB": { "file_name": "WindowsUpdateElevatedInstaller.exe", "file_path": "C:\\Windows\\system32\\WindowsUpdateElevatedInstaller.exe", "hash_md5": "AB7047923B7B8542902C6F9689E42CCB", "hash_sha1": "E8D3FBBAE8ECBADB35F38DB96A357AF31B1B3A36", "hash_sha256": "401F666B3FFCC3D9C77D9E8B2E0C0838467E93F4CEA83E34D659B2639BB65D32", "hash_sha384": "AA396EEFC95A5958547D86E95A09D677CA53E8DF828B2B51E8788189960D081DC72F55C4E4822ECC0F2282F3F482E79D", "hash_sha512": "D6183E939EB8FAA0DDD3AA850B5FF272C1331D436483DC092C6C3ABF1FAD71C64F10E1D6A26C60FAAF2C4A38E7D7575FA73AA8F697C69FAA71B4472A7D850B16", "hash_ssdeep": "768:nKNQ94605Gi5wvfJgo0J3wpppB15Qy5+3Q0Kj7rGHrLUNYjgBnL4nVUyb:YNh5bRZwjpB1T50K3rGHfOBL4nVpb", "hash_imp": "4D1584DE34010CF8BE9B582235B283C0", "hash_pesha1": "3830F90AFA627E9489DEBC8EE761D3597A255DC3", "hash_pe256": "3C87B299DFE877D2F9D9EB293ED0376DD4DCEDB8B1259FB186549FA8D31D07A9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WindowsUpdateElevatedInstaller", "meta_original_filename": "WindowsUpdateElevatedInstaller", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.652 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.652", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/401f666b3ffcc3d9c77d9e8b2e0c0838467e93f4cea83e34d659b2639bb65d32/detection/" }, "wininit.exe-4E20895E641F2C3E68AB3DB91A1A16F1": { "file_name": "wininit.exe", "file_path": "C:\\Windows\\system32\\wininit.exe", "hash_md5": "4E20895E641F2C3E68AB3DB91A1A16F1", "hash_sha1": "389E257A924EA521E830C31712494D33B38841A8", "hash_sha256": "13AD43EE6D19DFC9709C3106D796BC3F21791A564E443D042A5AA117F2680649", "hash_sha384": "C71640EA1868CC86442CDDAD20B78050CEBC621CD40A683CA24372129DC1369268BA68CEFDB1A51F15645D9363BF766F", "hash_sha512": "A07B7A2E15DF539EB30191EA299647DB76094FD6E82DD64C5B3BB95D3580E0B2B0626F820D1173FE1BB2101C6218F1BA0F9935A0E97A5096E4D9854D96CBFC1D", "hash_ssdeep": "6144:AVLkQEn9bUD8CMLCwauZ16ST3wZCGe3kVzW7V7aDVkOTeeBRIrfjBpH:AWN9ID3C37Z16ST45eHaR5gfjj", "hash_imp": "C2F90ACB28AF147D0D0C3408B9EE38C5", "hash_pesha1": "691F52A416F67F16FD77EA3C833D07FBEA2887A7", "hash_pe256": "41D8B8DFDF9EFE46FA36847129BC544F65CC7F22E98C6D0B051162871115A0D6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Start-Up Application", "meta_original_filename": "WinInit.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/13ad43ee6d19dfc9709c3106d796bc3f21791a564e443d042a5aa117f2680649/detection/" }, "winload.exe-508BDD7AC11E609D4F8572ED3EADA0FC": { "file_name": "winload.exe", "file_path": "C:\\Windows\\system32\\winload.exe", "hash_md5": "508BDD7AC11E609D4F8572ED3EADA0FC", "hash_sha1": "DF4FD34A007C17DD5683CA07DFE05E8BB269D6D7", "hash_sha256": "E291E5754C31CD14A4B81899DC8ED14953C922274F77BAE35117B76C9957C862", "hash_sha384": "3534410BFCD9877DA686EC9837FE2F9C3E81679F58684062598BD64E82051229A7B4DE0DD573E867A93B4AA7972A5E13", "hash_sha512": "33F5D9D8E9316B392C4C5539E46209157AAC3E6728082C0C3DE2C1D1F982758F5CD8B0140EB649E960E6DA0253D4EEC91F84C4B78B4892716FA6E3850FBA5F6C", "hash_ssdeep": "24576:7j/Thh5Or/K6+7ZOmcdNtQF2dsH8ybxbyvfVdVejswu6JMWhL:7jr70r/KpmgF200vHVejsxY", "hash_imp": "n/a", "hash_pesha1": "163B9F2F5ADA8C7B9C9652834DA1604CAFBCA873", "hash_pe256": "3511D54B3FBF0CD70C012AEA7ADADC70C64209CAA7D473771B1527A9F71092EA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "OS Loader", "meta_original_filename": "osloader.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "winlogon.exe-E8B1A6B8C6EA5972C123A816DF237AF8": { "file_name": "winlogon.exe", "file_path": "C:\\Windows\\system32\\winlogon.exe", "hash_md5": "E8B1A6B8C6EA5972C123A816DF237AF8", "hash_sha1": "573ED5AED255DCEC948BCEA8C28EC9F3802A2E64", "hash_sha256": "290C8C4B387B669B3988938D0083AA4B210365FB0855EAE010F49062A9DDEB04", "hash_sha384": "BA07CC249C938A0B59CCBF0642D722DF5B0FA598D844E054997417A97744C70522125847403F88B7A56CDE496D82838F", "hash_sha512": "62DA4D9CF429E2387449C99A6F97E5923EA6B967E29C5EBC78575568B4CA648C790A0897D391495887863F85A910905CDBA04A7F8B9D9D57F7EFA835523BE8AF", "hash_ssdeep": "12288:LB6L/iEapA3fCxZJUlZDWuiIUjdZaNu76w4eGK2Tjo/:0DPaK62QCk7p4eGh3o", "hash_imp": "A5F3EBEF8618DCA7C7ACCF623BABBB86", "hash_pesha1": "6632D5C085634466C426C6C9D76B01CCB6D8ABBE", "hash_pe256": "1024DE27675C11D4A1F6313F24882CC7A83CF74209B02ADF16BE43ECB5F79F34", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Logon Application", "meta_original_filename": "WINLOGON.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/290c8c4b387b669b3988938d0083aa4b210365fb0855eae010f49062a9ddeb04/detection/", "runtime_modules": [ "C:\\Windows\\system32\\winlogon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\SYSTEM32\\dwminit.dll" ] }, "winresume.exe-FFC7A70B844C3CBA7F97D7E0434AB7F7": { "file_name": "winresume.exe", "file_path": "C:\\Windows\\system32\\winresume.exe", "hash_md5": "FFC7A70B844C3CBA7F97D7E0434AB7F7", "hash_sha1": "8388231DF03CF07C6FFD7A35760AD740CCCAA0B3", "hash_sha256": "5F55D1A1DEB8508A31F5630F9716F81E58A8E05FA1A7B8043F26BE618149B9EA", "hash_sha384": "87B898539B4AC6F5E153BE2DAA40AC99740B4AC9203DEF5F6DE4552BE224C793823742D43E3AD6FB8143597F2D971820", "hash_sha512": "060E15141DE39C8DEBB6EBB8FC04FB1561FDE576A41BEFBC27A65D2F5FE5F5E92293AEAC00B1C72786A9CE1F05D0134FA59F1DC9DE790C1EE68F0A6B25A92E18", "hash_ssdeep": "24576:BP4+yfOzoiHHgHMzOFncU32P+0p/y1uoImZuZRVb:BA+yf8qHF932+cqZ0b", "hash_imp": "n/a", "hash_pesha1": "B1C45934895D4B64803D4F865E5C7AB73976BAEF", "hash_pe256": "0A4A24F766CFE65D143FF20BE4056192B907CC4F4D416E92FEEE46C28943E0F2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resume From Hibernate boot application", "meta_original_filename": "hiberrsm.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "winrs.exe-FF0007592245B0EF82886AB224CC8302": { "file_name": "winrs.exe", "file_path": "C:\\Windows\\system32\\winrs.exe", "hash_md5": "FF0007592245B0EF82886AB224CC8302", "hash_sha1": "2CC5351F80F716449CB1E095DDFBE75D0A573CC8", "hash_sha256": "83790021F6315747DECCE5A9E15006DCDA7A7E7003660B5B3D07D1862261E73A", "hash_sha384": "6F2C899B19ECA3886E9267D2C7AE8A6F34494EA6B2881B56F93917677C2BE387C3780D73B77D816975996255BFDB920D", "hash_sha512": "C40BB8C045623E96F4AA9CD581576E61D39E8B64024C73CBC648A4DB9D176B0E175853D84BF7FAEC0558E561C73CC728D6427A163557D4F53F79B2760936C0B9", "hash_ssdeep": "768:pInxbNVlEREoDorHyymOqRnRNOEJZXKhhOYc5DwK+PXcMmkQNsEoKma+GJxXJN5a:gRE6oESy3E/oOdDGXmkkiX", "hash_imp": "2A6F61CB3D8B085F04D934C7B0CC98A1", "hash_pesha1": "9B92236C7ADA6BC2B9CB4838F5D84A411C99A12D", "hash_pe256": "4F9C63F9C65323675C78041F86818AE419DAADF525DD4FD144E696C56E28E180", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "winrs", "meta_original_filename": "winrs.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/83790021f6315747decce5a9e15006dcda7a7e7003660b5b3d07d1862261e73a/detection/", "output": "For more information on a specific command, type HELP command-name\r\nASSOC Displays or modifies file extension associations.\r\nATTRIB Displays or changes file attributes.\r\nBREAK Sets or clears extended CTRL+C checking.\r\nBCDEDIT Sets properties in boot database to control boot loading.\r\nCACLS Displays or modifies access control lists (ACLs) of files.\r\nCALL Calls one batch program from another.\r\nCD Displays the name of or changes the current directory.\r\nCHCP Displays or sets the active code page number.\r\nCHDIR Displays the name of or changes the current directory.\r\nCHKDSK Checks a disk and displays a status report.\r\nCHKNTFS Displays or modifies the checking of disk at boot time.\r\nCLS Clears the screen.\r\nCMD Starts a new instance of the Windows command interpreter.\r\nCOLOR Sets the default console foreground and background colors.\r\nCOMP Compares the contents of two files or sets of files.\r\nCOMPACT Displays or alters the compression of files on NTFS partitions.\r\nCONVERT Converts FAT volumes to NTFS. You cannot convert the\r\n current drive.\r\nCOPY Copies one or more files to another location.\r\nDATE Displays or sets the date.\r\nDEL Deletes one or more files.\r\nDIR Displays a list of files and subdirectories in a directory.\r\nDISKPART Displays or configures Disk Partition properties.\r\nDOSKEY Edits command lines, recalls Windows commands, and \r\n creates macros.\r\nDRIVERQUERY Displays current device driver status and properties.\r\nECHO Displays messages, or turns command echoing on or off.\r\nENDLOCAL Ends localization of environment changes in a batch file.\r\nERASE Deletes one or more files.\r\nEXIT Quits the CMD.EXE program (command interpreter).\r\nFC Compares two files or sets of files, and displays the \r\n differences between them.\r\nFIND Searches for a text string in a file or files.\r\nFINDSTR Searches for strings in files.\r\nFOR Runs a specified command for each file in a set of files.\r\nFORMAT Formats a disk for use with Windows.\r\nFSUTIL Displays or configures the file system properties.\r\nFTYPE Displays or modifies file types used in file extension \r\n associations.\r\nGOTO Directs the Windows command interpreter to a labeled line in \r\n a batch program.\r\nGPRESULT Displays Group Policy information for machine or user.\r\nGRAFTABL Enables Windows to display an extended character set in \r\n graphics mode.\r\nHELP Provides Help information for Windows commands.\r\nICACLS Display, modify, backup, or restore ACLs for files and \r\n directories.\r\nIF Performs conditional processing in batch programs.\r\nLABEL Creates, changes, or deletes the volume label of a disk.\r\nMD Creates a directory.\r\nMKDIR Creates a directory.\r\nMKLINK Creates Symbolic Links and Hard Links\r\nMODE Configures a system device.\r\nMORE Displays output one screen at a time.\r\nMOVE Moves one or more files from one directory to another \r\n directory.\r\nOPENFILES Displays files opened by remote users for a file share.\r\nPATH Displays or sets a search path for executable files.\r\nPAUSE Suspends processing of a batch file and displays a message.\r\nPOPD Restores the previous value of the current directory saved by \r\n PUSHD.\r\nPRINT Prints a text file.\r\nPROMPT Changes the Windows command prompt.\r\nPUSHD Saves the current directory then changes it.\r\nRD Removes a directory.\r\nRECOVER Recovers readable information from a bad or defective disk.\r\nREM Records comments (remarks) in batch files or CONFIG.SYS.\r\nREN Renames a file or files.\r\nRENAME Renames a file or files.\r\nREPLACE Replaces files.\r\nRMDIR Removes a directory.\r\nROBOCOPY Advanced utility to copy files and directory trees\r\nSET Displays, sets, or removes Windows environment variables.\r\nSETLOCAL Begins localization of environment changes in a batch file.\r\nSC Displays or configures services (background processes).\r\nSCHTASKS Schedules commands and programs to run on a computer.\r\nSHIFT Shifts the position of replaceable parameters in batch files.\r\nSHUTDOWN Allows proper local or remote shutdown of machine.\r\nSORT Sorts input.\r\nSTART Starts a separate window to run a specified program or command.\r\nSUBST Associates a path with a drive letter.\r\nSYSTEMINFO Displays machine specific properties and configuration.\r\nTASKLIST Displays all currently running tasks including services.\r\nTASKKILL Kill or stop a running process or application.\r\nTIME Displays or sets the system time.\r\nTITLE Sets the window title for a CMD.EXE session.\r\nTREE Graphically displays the directory structure of a drive or \r\n path.\r\nTYPE Displays the contents of a text file.\r\nVER Displays the Windows version.\r\nVERIFY Tells Windows whether to verify that your files are written\r\n correctly to a disk.\r\nVOL Displays a disk volume label and serial number.\r\nXCOPY Copies files and directory trees.\r\nWMIC Displays WMI information inside interactive command shell.\r\n\r\nFor more information on tools see the command-line reference in the online help.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\winrs.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\WsmSvc.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\miutils.dll", "C:\\Windows\\system32\\DSROLE.dll", "C:\\Windows\\system32\\pcwum.dll", "C:\\Windows\\system32\\mi.dll" ], "error": "Winrs.exe: Unrecognized switch \"--help\"\r\nUse \"winrs -?\" to obtain the usage information" }, "winrshost.exe-BF647BDF510B2504A3503E075A0E5ECF": { "file_name": "winrshost.exe", "file_path": "C:\\Windows\\system32\\winrshost.exe", "hash_md5": "BF647BDF510B2504A3503E075A0E5ECF", "hash_sha1": "FC80CB4CE262D2FB249ABD4C6D53B8BF6E335194", "hash_sha256": "401441DB1DBE8189EB5CF230714D8271F10F1023E893901C6DB95E6325B46884", "hash_sha384": "786020887707D8FF972151B17A6477C2CC30562E3CB8C00AC20DC5B6F8100F40455613369A722BDBA7ADE7A1C169C151", "hash_sha512": "7A3992FBD2C889EFE34875157BF302F2CAF90F9EFD37CC18DE22B1DAFE79B7B5EAC6BEDDC21105647BE62C2D8441596EE3C311DB7ED0E6852C2D027C8CF1983E", "hash_ssdeep": "384:bSI3EN4QWUXQ5RUaoerG0e3ZVSGhEngiWvwGkpIVCmv+7c3AECAWUwv5W00a8/gP:7LZ2a0bXhEngDoGkp6Cmm7c3N8x8/If", "hash_imp": "94B88BB1A488481A09FB94AE3B531ED2", "hash_pesha1": "665DF2BCD2EFB8562DD92D0900952CA102370C95", "hash_pe256": "5AAC2D34F7FCC86FCA8863996C4ED4204648763721D6080BD5529721D6C59A76", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for WinRM's Remote Shell plugin", "meta_original_filename": "winrshost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/63", "filescan_vtlink": "https://www.virustotal.com/gui/file/401441db1dbe8189eb5cf230714d8271f10f1023e893901c6db95e6325b46884/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC12C8": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\winrshost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "WinSAT.exe-D21AA5C451C43D15B2BA3611F57F2321": { "file_name": "WinSAT.exe", "file_path": "C:\\Windows\\system32\\WinSAT.exe", "hash_md5": "D21AA5C451C43D15B2BA3611F57F2321", "hash_sha1": "BD152D8C2467B974DCA7B2B11982D3EA06B2B4F9", "hash_sha256": "2380049E6E56B969990C598A3731E8322E8DEF86B08DFE44E452392CF529498D", "hash_sha384": "534D32F50C97A3BAC33C98C9F586877A66C1B8DE393C53ED50C435D0F4B0D242B770869F6EFBDBAC4138DE7C7EECB2DA", "hash_sha512": "08BE8EB24D22C41623BA482CB89B8995C52BB06555A3F4A24E8075C5C913D760456DFE95C95E347252F2975DB254F32349C55C21E0BD69F4268B48D891915CB7", "hash_ssdeep": "49152:/XpiCMrI7ninpTyjY7Q9i9GYmq1dKwdfU2bECbe:PUCUzT1DFE/", "hash_imp": "9B913D600A7557750BD6D8AE12F90CF7", "hash_pesha1": "D3A43BACE47FC0DBBDC6B42BB1119CD1ADEC65CA", "hash_pe256": "10E07AC825486FBBF203B579EA74FB16F131F4F2757037B9764C067C80E345CD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows System Assessment Tool", "meta_original_filename": "WinSAT.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/2380049e6e56b969990c598a3731e8322e8def86b08dfe44e452392cf529498d/detection/", "output": "\r\nWindows System Assessment Tool\r\n\r\n \r\nCOMMAND LINE USAGE : \r\n WINSAT <assessment_name> [switches]\r\n\r\nIt's necessary to supply an assessment name. In contrast, switches are optional. \r\nValid assessment names already seen in Vista include: \r\n\r\n formal\t\trun the full set of assessments \r\n\r\n dwm\t\tRun the Desktop Windows Manager assessment\r\n - Re-assess the systems graphics capabilities and \r\n restart the Desktop Window Manager.\r\n\r\n cpu\t\tRun the CPU assessment. \r\n mem\t\tRun the system memory assessment. \r\n d3d\t\tRun the d3d assessment \r\n (Note that the d3d assessment no longer runs the workload. \r\n For backward compatibility, pre-determined scores and metrics are reported.)\r\n disk\t\tRun the storage assessment\r\n media\t\tRun the media assessment \t\t\t\r\n mfmedia\t\tRun the Media Foundation based assessment\t\r\n features\tRun just the features assessment \t\t\r\n - Enumerates the system's features. \r\n - It's best used with the -xml <filename> switch \r\n to save the data. \r\n - The 'eef'switch can be used to enumerate extra \r\n features such as optical disks,\tmemory modules, \r\n and other items.\r\n \r\nPRE-POPULATION: \r\nThe new command-line options for pre-populating WinSAT assessment results are : \r\n \r\n Winsat prepop [-datastore <directory>] [ -graphics | -cpu | -mem | -disk | -dwm ]\r\n\r\n\r\nThis generates WinSAT xml files whose filenames contain \"prepop\". For example :\r\n 0008-09-26 14.48.28.542 Cpu.Assessment (Prepop).WinSAT.xml\r\n\r\nThe filename pattern is :\t\r\n %IdentifierDerivedFromDate% %Component%.Assessment(Prepop).WinSAT.xml\r\n\r\nThe datastore directory option specifies an alternative target location for generated xml files. \r\nIf no location is specified, everything is pre-populated to \r\n %WINDIR%\\performance\\winsat\\datastore. \r\n\r\nTo generate a full set of result xml files, use \"winsat prepop\". \r\n\r\nIt is also possible to pre-populate results for a subsystem, such as CPU, \r\nsubject to the following dependencies:\r\n\r\n The CPU assessment has a secondary dependency on the Memory assessment\r\n The Memory assessment has a secondary dependency on the CPU assessment\r\n The Graphics assessment has a secondary dependency on both CPU and Memory assessments\r\n The DWM assessment can run standalone\r\n The Disk assessment can run standalone \r\n\r\nIf the assessment for a secondary dependency is not present, WinSAT will run the \r\nsecondary assessment along with the requested primary assessment. \r\n\r\nFor example, \"winsat prepop -cpu\" will run both the CPU and the Memory test, \r\nif the xml file for the Memory test is not present.\t\r\n\r\n\r\n\r\nOTHER NEW Win7 ASSESSMENT OPTIONS :\r\n\r\n dwmformal\tRun Desktop Windows Manager assessment to generate the WinSAT Graphics score\r\n cpuformal\tRun CPU assessment to generate the WinSAT Processor score\r\n memformal\tRun Memory assessment to generate the WinSAT Memory (RAM) score\r\n graphicsformal\tRun Graphics assessment to generate the WinSAT Gaming Graphics score\r\n diskformal\tRun Disk assessment to generate the WinSAT Primary Hard Disk score\r\n \r\nAll formal assessments will save the data (xml files) in \r\n %WINDIR%\\performance\\winsat\\datastore. \r\n\r\nIf a system has been prepopulated (using files generated by the \"winsat prepop\" option), \r\nit is not necessary to run formal assessments.\r\n\r\n\r\nSUB-ASSESSMENTS:\r\nWhile investigating results, it may be convenient to look at individual assessments. \r\nOptions for running Gaming Graphics sub-assessments include:\r\n\r\n Winsat graphicsformal3d\r\n Winsat graphicsformalmedia\r\n\r\n DX9 Variations: \r\n Winsat d3d -dx9\r\n winsat d3d -batch\r\n winsat d3d -alpha\r\n winsat d3d -tex\r\n winsat d3d -alu\r\n\r\n DWM/DX10 variations: \r\n Winsat d3d -dx10\r\n winsat d3d -dx10 -alpha\r\n winsat d3d -dx10 -tex\r\n winsat d3d -dx10 -alu\r\n winsat d3d -dx10 -batch\r\n winsat d3d -dx10 -geomf4\r\n winsat d3d -dx10 -geomf27\r\n winsat d3d -dx10 -geomv8\r\n winsat d3d -dx10 -gemov32\r\n winsat d3d -dx10 -cbuffer\r\n\r\n\r\n\r\nOPTIONS FOR FORMAL ASSESSMENTS FOR SUBSEQUENT RUNS ON THE SAME MACHINE:\r\n\r\nThe default behavior for \"WinSAT formal\" when a complete set of winsat formal files is present \r\nand a second \"winsat formal\" run is requested is to \r\n 1) Run incrementally if component change implies that an assessment needs to be re-run, \r\n e.g. if a video card were updated \r\n 2) If no component updates were detected, re-run all assessments.\r\n\r\n The restart option enables behavior other than the default. The syntax is : \t\r\n Winsat formal -restart [clean|never]\r\n \r\n Winsat formal -restart\t \tReruns all assessments. \r\n Winsat formal -restart never \tAttempts to run incrementally.\r\n Winsat formal -restart clean \tReruns all assessments and provides the same functionality as \"forgethistory\". \r\n Winsat forgethistory\t\tChoosing to forgethistory will rate a machine as if for the first time.\r\n\r\n\r\nOTHER COMMAND LINE OPTIONS :\r\n -v\t\t\tEnables verbose output\r\n -xml\t\t\tSaves the XML output to 'filename'\r\n\r\n <command> -log <fn>\tGenerates a log file associated with the specified command, such as disk\r\n The -log switch can be used with any WinSAT command.\r\n\r\n viewlog -i <filename> \tDumps the results of a log file . \r\n viewevents \t\tUsed to view relevant winsat events in the event log. \r\n (This launches the event log)\r\n query \t\t\tCan be used to query the current datastore.\r\n", "error": "ERROR: Cannot process the command line\r\n Assessment name 'help' is not valid\r\n", "runtime_modules": [ "C:\\Windows\\system32\\WinSAT.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\VERSION.dll", "C:\\Windows\\system32\\WINMM.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\system32\\d3d10_1.dll", "C:\\Windows\\system32\\d3d10.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\system32\\WINMMBASE.dll", "C:\\Windows\\system32\\d3d10_1core.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\system32\\d3d10core.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\ntmarta.dll" ] }, "winver.exe-2FAF36CA1A8C76A14294ABB5E2048CF6": { "file_name": "winver.exe", "file_path": "C:\\Windows\\system32\\winver.exe", "hash_md5": "2FAF36CA1A8C76A14294ABB5E2048CF6", "hash_sha1": "E66AC0632530C66D37935472F4303C02D8ACDFBF", "hash_sha256": "71E5E4B68B93E8B557FE0651E3D39C57279E694D07B42C67269224E2FC603AEE", "hash_sha384": "63E64F2342B29A32DB0D63212915B2ABEFA2B48E9ABC0E0DE9E272FE14C0E2FCDC5BBAED1A0C19469F9A9EB12DB888FA", "hash_sha512": "B4E646BBE1C541655C73FFB58003A8C1F35EF2B32E4114F22056621C7B4495093DAF51E932810E8D0EE86122E3936E3294799A0BA553559F2AC8B7AAD3758C7E", "hash_ssdeep": "768:lJgdAO/cAxy0oGSkVhWakkbB5eT905WGnUKxHUe7n8jKBFFptX/7wUXj:l6GO/c8y0oxakkn6oYY0ewiP82", "hash_imp": "92BE77A081419D46930EEB51BF20D61B", "hash_pesha1": "2187C82B8E0A96490D65B9AB68921AFB9C3F15F8", "hash_pe256": "BBDEF78B41FBAEB36D4123F1AA61829628922673E74B8C4593EF113D40BB8A9B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Version Reporter Applet", "meta_original_filename": "WINVER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/71e5e4b68b93e8b557fe0651e3d39c57279e694d07b42c67269224e2fc603aee/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\winver.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\winver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll" ], "runtime_window_title": "About Windows" }, "wkspbroker.exe-228C4C2AF89A60563609F47A3CA7361B": { "file_name": "wkspbroker.exe", "file_path": "C:\\Windows\\system32\\wkspbroker.exe", "hash_md5": "228C4C2AF89A60563609F47A3CA7361B", "hash_sha1": "86D2CBDBC7F060971D9CA3A73406C963658B92CA", "hash_sha256": "2418929FEC25B3A30C10FE01901F4D75D6895480DF500BEB19717517CCD5BB41", "hash_sha384": "D36E08EFDB4C71F93B8487F15598A96BF3106F383D9DFB390090D5D79AD197409F9F06CBE21B238C4058AC0E74DDC373", "hash_sha512": "F257BDFA45BC9A79539C65D9CF921A9CC5445B88514B5D4B1B2362FC5793F77978C0658745B872AD4DA6F0E5F44B9A25CF3608FEEECB8164AFC2E24AACFB5FCA", "hash_ssdeep": "6144:7ww7aIItFKhjYpOqmjvoJa4XsSgaWyZWR3O:7w7II7jOLjvUa4XZWyn", "hash_imp": "7CDC3C5C42F622F28AAA8DD99463C85B", "hash_pesha1": "B9D3382655A767B846C2404BFAB4548A600C1DD4", "hash_pe256": "0D3705B06E875A4F5DE4A99E345FDBE2CB8E1A602B280BE9CD279BE660385796", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RemoteApp and Desktop Connection Runtime Broker", "meta_original_filename": "wkspbroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/65", "filescan_vtlink": "https://www.virustotal.com/gui/file/2418929fec25b3a30c10fe01901f4d75d6895480df500beb19717517ccd5bb41/detection/", "runtime_modules": [ "C:\\Windows\\system32\\wkspbroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\system32\\WININET.dll", "C:\\Windows\\system32\\RADCUI.dll", "C:\\Windows\\system32\\DUI70.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\system32\\Windows.UI.Immersive.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\system32\\tsworkspace.dll", "C:\\Windows\\System32\\Normaliz.dll", "C:\\Windows\\system32\\DNSAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\system32\\SspiCli.dll", "C:\\Windows\\system32\\WINHTTP.dll", "C:\\Windows\\system32\\credui.dll", "C:\\Windows\\system32\\ktmw32.dll", "C:\\Windows\\system32\\DPAPI.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL" ] }, "wksprt.exe-A500FC34666C2BD1D178B0163748F7F0": { "file_name": "wksprt.exe", "file_path": "C:\\Windows\\system32\\wksprt.exe", "hash_md5": "A500FC34666C2BD1D178B0163748F7F0", "hash_sha1": "3358DBCF09D10BD1F7FCF7625E7A2BEB32811273", "hash_sha256": "6C5E5C792FF17B6CE2987DC7CD84E9AFD0CFC9F21CBEBDD674BDA5A70DB6FCF0", "hash_sha384": "E76C4AB99E45C42A71E9471EC56A1BF392E17B3F2D0BD727D97ADDC3B9060A62B6510AF7D7E2DD3D554A4CB066ED7613", "hash_sha512": "675B7C91CFF936865719FEF50B2FD461C3E7D54A3B13FBF1E755A166796F49A5302F34F9A8CF5786D5D513EF7CEBDC8BB9CE8F8E042D07318005E0573019CF20", "hash_ssdeep": "12288:LH+OHVp6H59J9HMpTuIRJ4r7GXIB7GjFMvT3lxR:LeOHD6HjUdRJ4r7GimI", "hash_imp": "F60EAA8AC4165371E5EA639793BC771F", "hash_pesha1": "1FCBC689D9F9C117B81D9BEB9D3775C1FFBFAEE8", "hash_pe256": "BCC974BE22D54306D3B2B82CD3A710366232BB677B9F002C2E358593A8232787", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RemoteApp and Desktop Connection Runtime", "meta_original_filename": "wksprt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/6c5e5c792ff17b6ce2987dc7cd84e9afd0cfc9f21cbebdd674bda5a70db6fcf0/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\wksprt.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\RPC Control\\DSECD94": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wksprt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\webservices.dll", "C:\\Windows\\system32\\WININET.dll" ] }, "wlrmdr.exe-3B4132776636F37787317DA4E0A75ED3": { "file_name": "wlrmdr.exe", "file_path": "C:\\Windows\\system32\\wlrmdr.exe", "hash_md5": "3B4132776636F37787317DA4E0A75ED3", "hash_sha1": "6C7FDD7A10B051889771F087AB1596A521A2820C", "hash_sha256": "4C13CCD996D58673BEC9FA19B1F06B8CA1D6823307B76C5A2A79799F1073BF64", "hash_sha384": "DADD6EF5E36A29C773989F7797692295E23E11AB5194A94BF57891AD3B87894923D5B756B11ED459D15A25AE789ECF27", "hash_sha512": "E2E2F9C5FCFE5AD99C3B0C69E9BFAC5D4FE54009C7137D39200C4567FEF91ECEBD05D780F3C4C0522CDDD32A35FCD9AD476EE837882A62E67168EC168E74B79A", "hash_ssdeep": "1536:Y4gMLrY6x6g+d5cKswSjhbTvXylmAbsvqr9PxDtESpPTo:1rY6YxdsrvClEu9ZDtE6E", "hash_imp": "0C029EF03BE0DFE4324558843609A28E", "hash_pesha1": "D5D5A69D3C1F0BB0B32E96431D0148AAFC16AEEC", "hash_pe256": "AC249FA332512ACB2579D2633A454E9F0CB2316FA484B08441D27BDC5055657D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows logon reminder", "meta_original_filename": "WLRMNDR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/4c13ccd996d58673bec9fa19b1f06b8ca1d6823307b76c5a2a79799f1073bf64/detection/" }, "WMPDMC.exe-7480C878A04B3CED7C2E13D98131B72A": { "file_name": "WMPDMC.exe", "file_path": "C:\\Windows\\system32\\WMPDMC.exe", "hash_md5": "7480C878A04B3CED7C2E13D98131B72A", "hash_sha1": "8FE69B3CFB5EF59C07F71EA954F1A150C6A6669A", "hash_sha256": "FE6A7C6E23FF1EA7D297AEB0D2B4C5E6E39DB31764A3AFEC31B4CA3F385E3FC8", "hash_sha384": "18CC9488D7D26C23C0C4B78D38794A09EFAE5A40D78C41DBAF35BD06923B1CA1C62A2B57488108B117D683BED1176D89", "hash_sha512": "ACBEE367F6BFAC72BC1FE9BB6B2F27A54CE9DAE2B9CE01C52AF0DDD24F356DCBAA79C67A486C90EF378473C86E549F6F394657EF405331F9F65C358C841FD46A", "hash_ssdeep": "24576:vXPNtETuhimApEjvZmHAcBnw/jqY1vLqyi4yR5QuQmulrjGHVJZh/u:v/IT+iHpI2AcFed+yi7PQuQm2uHVU", "hash_imp": "E9EF175E927E5E27A3E372E1E76D0A34", "hash_pesha1": "A21E66317B2EA0DF3345D883798E8248C444B0C3", "hash_pe256": "2A15A207CFF2E54B9FD903BE3291CD32201C42F5B543FBBE4A593F51CEB93B1B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Cast to Device", "meta_original_filename": "WMPDMC.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/fe6a7c6e23ff1ea7d297aeb0d2b4c5e6e39db31764a3afec31b4ca3f385e3fc8/detection/", "runtime_modules": [ "C:\\Windows\\system32\\WMPDMC.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\system32\\UxTheme.dll", "C:\\Windows\\system32\\wmpdui.dll", "C:\\Windows\\system32\\OLEACC.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\WindowsCodecs.dll" ] }, "wowreg32.exe-A4DC42341D9F165D284743AEC28A623A": { "file_name": "wowreg32.exe", "file_path": "C:\\Windows\\system32\\wowreg32.exe", "hash_md5": "A4DC42341D9F165D284743AEC28A623A", "hash_sha1": "169675291D9CCA14B37A84210C77333F7F816F1B", "hash_sha256": "5FBED7838E7AE5306B25B05B85D8A78F57BADBF76EDDC103A4A60AA55BF999C1", "hash_sha384": "F1725EB62734F79FF81A5130CDACA406D2B821BEB7C57E1B052D2FE6E89E2936FB50ADEA3097D711983776BD22CA173B", "hash_sha512": "06D340BEE22335C669B59926462D6414E08EA5B7CD85B7139BA8A3E6BF9B21E66BC6F2DF73059ECBC19F18C8C4D1D2BCDF1A53C4EAB29DD45F7AB7E575EB8F7E", "hash_ssdeep": "384:FPtZ6gy7vB/1JOHBeFOSD1tR4dLjWgoZjHW:FPWgkbJOeP+xuZj", "hash_imp": "9E395710D74BF587FAC4F5CA37BF2548", "hash_pesha1": "2D46638E588747A93ADAB3F6DFAE2AAB6C8D0AB0", "hash_pe256": "1F71120EDAB6F5B6AE31A2EC9EFEB7D2235806BBE5AE6280E7E5B79F13E61F9A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SetupAPI 64-bit Surrogate", "meta_original_filename": "WOWREG32.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/5fbed7838e7ae5306b25b05b85d8a78f57badbf76eddc103a4a60aa55bf999c1/detection/" }, "WPDShextAutoplay.exe-D5D413B3DFBC7657CCF6C6ECBA237F3E": { "file_name": "WPDShextAutoplay.exe", "file_path": "C:\\Windows\\system32\\WPDShextAutoplay.exe", "hash_md5": "D5D413B3DFBC7657CCF6C6ECBA237F3E", "hash_sha1": "FFF567FBA6F583978AC6DB35548984E9342AC230", "hash_sha256": "1C5E965F4471F558E688EAD0DDB32C3B3D1D22EA1FACEF76B1FD541AE09379EB", "hash_sha384": "03C6492E797799A22A39C087C1769BE8C7846647369399650538B873A6C7AC195CBB39A4E9C0D1BAC72FDF102EA11DD4", "hash_sha512": "E9F5C0370830AE3322EB235363868654194C295568D6E1D137F464B3D7BA8947F1E7920253CF564B24BC8BAC6805DD19BC1BD591AB98D0AE90E5AAF1404F9577", "hash_ssdeep": "768:3VeL0v4AU3Tnfqe88xo8dAiOHfD6kiJ8DQ:Vv4AKnCYo8dARfJDQ", "hash_imp": "D6E136D4A9E27F31C5602B427D3226E9", "hash_pesha1": "B38778B261D33BE96125945EDF5AAE3B54042148", "hash_pe256": "8209D491C19A423A5FFECB8DC6A97AACB5A1A54E07A525BA946F6B418F976AD6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Portable Device Shell Extension Autoplay Handler", "meta_original_filename": "WpdShExtAutoplay.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/1c5e965f4471f558e688ead0ddb32c3b3d1d22ea1facef76b1fd541ae09379eb/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\WPDShextAutoplay.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC10BC": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\WPDShextAutoplay.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll" ] }, "wpr.exe-1CC236FBB811D624BEA16548D75D3A46": { "file_name": "wpr.exe", "file_path": "C:\\Windows\\system32\\wpr.exe", "hash_md5": "1CC236FBB811D624BEA16548D75D3A46", "hash_sha1": "52E2454464DEDD872218A4B3AFA74B573CFA71D2", "hash_sha256": "37869599B8F17A1D5F7BF91A20A1CE4555919A4758078FFE8DDDAD422BE5CCAA", "hash_sha384": "E1CD5530816B663204511ECEBA8AEACEBB3C859AE77CD921AB6692F29A86DBF884095DAE6D2FF356031A8DDBB4CC2B71", "hash_sha512": "E3AF862AE5D47E0DEE7356A45E740A8FA5F5305FD834C4BE3517E00DA457B0514C7F0E173D1509C653BAF78444EA71AB1C76D2FF41A433110FA33658DC4F4733", "hash_ssdeep": "6144:kUgeiahIngARB1uU5cwmwoL59jaTg85YtcpwCXE:FIbuU5cwtoHja01lCX", "hash_imp": "0F7365EDF941165E0FACBC5296015670", "hash_pesha1": "26A9828A7837E7F12D2EE098593DD43D74FEEB35", "hash_pe256": "61171C07ADCF9258D0C77BDF32D7367C1D29B4A68C91F69FE7BE9443B43E4297", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Performance Recorder", "meta_original_filename": "WPR.exe", "meta_product_name": "Microsoft Windows Performance Recorder", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " 2018 Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/37869599b8f17a1d5f7bf91a20a1ce4555919a4758078ffe8dddad422be5ccaa/detection/", "output": "\r\nMicrosoft Windows Performance Recorder Version 10.0.17763 (CoreSystem)\r\nCopyright (c) 2018 Microsoft Corporation. All rights reserved.\r\n\r\n\tUsage: wpr options ...\r\n\r\n\t-help\t\t\t - Provide command line help information\r\n\t-profiles\t\t - Enumerates the profile names and descriptions from a profile file\r\n\t-purgecache\t\t - Purges the dynamic symbols cache\r\n\t-start\t\t\t - Starts one or more profiles\r\n\t-marker\t\t\t - Fires an event marker\r\n\t-markerflush\t\t - Fires an event marker and flushes the working set\r\n\t-status\t\t\t - Displays status on active recording (if any)\r\n\t-profiledetails\t\t - Displays the detailed information about a set of profiles\r\n\t-providers\t\t - Displays detailed information about providers\r\n\t-cancel\t\t\t - Cancels recording initiated via WPR (if any)\r\n\t-stop\t\t\t - Stops recording initiated via WPR (if any) and saves\r\n\t-flush\t\t\t - Flushes logging sessions initiated through WPR (if any)\r\n\t-log\t\t\t - Configure debug logging to the event log\r\n\t-disablepagingexecutive\t - Change the Disable Paging Executive settings\r\n\t-heaptracingconfig\t - Change heap tracing settings for a process\r\n\t-snapshotconfig\t\t - Change snapshot settings for a process\r\n\t-capturestateondemand\t - Capture states for the configured providers in the current recording\r\n\t-pmcsources\t\t - Query the list of hardware counters available on the system\r\n\t-setprofint\t\t - Set sampled profile interval\r\n\t-profint\t\t - Query the current profile interval\r\n\t-resetprofint\t\t - Restores the default profile interval values\r\n\t-boottrace\t\t - Configures the registry entries for autologger/globallogger sessions\r\n\t-enableperiodicsnapshot\t - Enable Periodic Snapshot for the specified interval and given process id\r\n\t-disableperiodicsnapshot - Disable Periodic Snapshot for all process\r\n\t-singlesnapshot\t\t - On demand Snapshot for the specified process\r\n\t-instancename\t\t - Specifies a name to uniquely identify the tracing instance. \r\n\t\t\t\t Useful when managing multiple concurrent wpr sessions. Must be last parameter.\r\n", "runtime_modules": [ "C:\\Windows\\system32\\wpr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\WindowsPerformanceRecorderControl.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ], "error": "\r\n\tInvalid command syntax.\r\r\n\r\n\tError code: 0xc5600602\r\n\tInvalid option: --help\r\n" }, "write.exe-10F2BC4209233AB34BDA602967D0F798": { "file_name": "write.exe", "file_path": "C:\\Windows\\system32\\write.exe", "hash_md5": "10F2BC4209233AB34BDA602967D0F798", "hash_sha1": "923BE1A95641EC2BE6F8F7E2CFF51E40C2655D65", "hash_sha256": "664256FDE0E3A7C39801D91DD20204250638048E0E3F12C5891A84FFE283680A", "hash_sha384": "149D613DFD9FB7A153DD2603D1A93F71B271A9DD4C2FC3C0C4DE09F727F65279FE6DAC7E88162B6FCC13658377BB430C", "hash_sha512": "3B57E4832D29071782D9A18B1F1D7D70789368E6DFA10707BE27903DCECBC53A233015F397CAEC1EE896E24CE8273FF791D5946CAD03912E56D107FC3F79BFA6", "hash_ssdeep": "192:kfN8IBpmrj0DyjZ3NRvWkHbTTHrdguUxhWxu/0WhOW:kCIB20uddBWMb9Ioxu/0WhOW", "hash_imp": "90A23F469BA0443719430CBA4569B220", "hash_pesha1": "9A77A959845F1EA9C1550BD205B9EE0E2F588A69", "hash_pe256": "C56A2287601FB53393F35585F4D12C76A740742B8BCA1503F6CA9860BDF60029", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Write", "meta_original_filename": "write", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/664256fde0e3a7c39801d91dd20204250638048e0e3f12c5891a84ffe283680a/detection/", "children": "wordpad.exe", "runtime_modules": [ "C:\\Windows\\system32\\write.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\edputil.dll" ] }, "WSCollect.exe-6212500CE0BBE755AFCC8DDF64698A87": { "file_name": "WSCollect.exe", "file_path": "C:\\Windows\\system32\\WSCollect.exe", "hash_md5": "6212500CE0BBE755AFCC8DDF64698A87", "hash_sha1": "D6F3D05BFC0A621AC531C2529F9BB7B484F122AC", "hash_sha256": "D50771E8DBC656CBE87670806F9A9FA4146A354858E549CFF70BCB07B69D1C02", "hash_sha384": "54849B8D01825FBE6C53E3109D1B1735FA7C04BA76C728314C89A8F6089F7220545BB873C0AA01C69BEC39B965CE50D1", "hash_sha512": "46A27A50E9D8239CFE3B13B3A3AA59F045A1DD71EB22F5A128CF1E63D657DDB1CD9CAE80A5FB296462D73B9917A4D7EF0A1B42AEEF1E7AFA755244D64709ED44", "hash_ssdeep": "768:b9fjhGHXzsCoiGdxCU52dfo5DNsn4FOBkStBWp:bTuXzsCoiGdxChfo5Ag0Yp", "hash_imp": "9F02A366D38804E1F04B39C5385F776C", "hash_pesha1": "A485F257A6DE5B866160232383781E16205C4A49", "hash_pe256": "1473B28D67BBA1D4CC901BB9670E1FD35BF795D3208FDA1EC45F6AABCE963E72", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "This tool collects Windows Store log files", "meta_original_filename": "WSCollect.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/d50771e8dbc656cbe87670806f9a9fa4146a354858e549cff70bcb07b69d1c02/detection/", "output": "Error: 0x8007007b\r\n", "runtime_modules": [ "C:\\Windows\\system32\\WSCollect.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\Windows.ApplicationModel.Store.dll", "C:\\Windows\\System32\\Cabinet.dll", "C:\\Windows\\System32\\iertutil.dll", "C:\\Windows\\System32\\WINHTTP.dll", "C:\\Windows\\System32\\webservices.dll", "C:\\Windows\\System32\\wevtapi.dll", "C:\\Windows\\System32\\bcrypt.dll" ] }, "wscript.exe-F5E5DF6C9D62F4E940B334954A2046FC": { "file_name": "wscript.exe", "file_path": "C:\\Windows\\system32\\wscript.exe", "hash_md5": "F5E5DF6C9D62F4E940B334954A2046FC", "hash_sha1": "267D05CE8D10D97620BE1C7773757668BAEB19EE", "hash_sha256": "47CACD60D91441137D055184614B1A418C0457992977857A76CA05C75BBC1B56", "hash_sha384": "BA747E5BD43ED901821A72B97CD42BA28171ABCB7383D6C44481A23C4AFFBA116D7AC263DF39564BAF0450604165FCF4", "hash_sha512": "F9A0425AB09706FF070A82B214EABE3F396C427F3EE486DD729B65AF370112DDE10D2BFE8D4670E44E72607BD5881FDECEABEF74B9D79709B007D5EFF82726A5", "hash_ssdeep": "3072:JmpjcDrUzmyV5p5zeV3BNUVM1duWUZxtt:JmxcDrU+XzXunZh", "hash_imp": "0F71D5F6F4CBB935CE1B09754102419C", "hash_pesha1": "DAFC5BFA9B41BA5A78EBBADF7A87068B3A218419", "hash_pe256": "3CA214C85CACDF48F697E9E13137936B85ACC4F6E894632072C5DDA102781295", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Based Script Host", "meta_original_filename": "wscript.exe.mui", "meta_product_name": "Microsoft Windows Script Host", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.812.10240.16384", "meta_product_version": "5.812.10240.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/47cacd60d91441137d055184614b1a418c0457992977857a76ca05c75bbc1b56/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\wscript.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wscript.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\VERSION.dll" ], "runtime_window_title": "Windows Script Host" }, "WSManHTTPConfig.exe-7C0A337D8666F226C8587B675326BBE1": { "file_name": "WSManHTTPConfig.exe", "file_path": "C:\\Windows\\system32\\WSManHTTPConfig.exe", "hash_md5": "7C0A337D8666F226C8587B675326BBE1", "hash_sha1": "F14E67BBB8353DBB29C96F10C4BD796D0950263C", "hash_sha256": "587852FA20AC5F36047F3D51041298873BD6D4986490A0C2DD433EFDE1096917", "hash_sha384": "4622B7190BBD4EA5CB0D6B6F09407C912F6CB5FEDD9AE67C4A22A10CB652E10C5C4CE2A25F763CA3DB65D3C1F5E3E3CB", "hash_sha512": "668D79B6CCF5B0FD83A7016F3820603305A2FEAF72E999646128D713C690A4DCB03292EAEF7E77F74654416960A1F796814F9469691920F68F3C10C0E8FAEA84", "hash_ssdeep": "384:Z2RKxIf1gZDw1F0VTHrjfKHPCfxiDgqgrg5gsgBgVgT8PJv1HVTi//2B/2/LWlRW:Z1Idgdw1GvjbfxaJtHFi//2FKu", "hash_imp": "566D264164FA6535966756FF3AE6625D", "hash_pesha1": "BF8A34308AC59D94CB940FFCAB3829F4A32C2421", "hash_pe256": "59BB1FD0B6AF51E6E5A929211011C9CC67109402F7B8E9FA2A304C0BB2CD4230", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WSMan HTTP Configuration File", "meta_original_filename": "WSManHTTPConfig.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.134 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.134", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/587852fa20ac5f36047f3d51041298873bd6d4986490a0c2dd433efde1096917/detection/", "runtime_modules": [ "C:\\Windows\\system32\\WSManHTTPConfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\WsmSvc.DLL", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\miutils.dll", "C:\\Windows\\system32\\DSROLE.dll", "C:\\Windows\\system32\\pcwum.dll", "C:\\Windows\\system32\\mi.dll", "C:\\Windows\\system32\\HTTPAPI.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ], "error": "WSMan Generic Command ERROR: Unknown switch: --help\r\nWSMan Generic Command ERROR: Error in parsing input\r\n" }, "wsmprovhost.exe-AB4AB98654635CABADB5F1A60BDA1C05": { "file_name": "wsmprovhost.exe", "file_path": "C:\\Windows\\system32\\wsmprovhost.exe", "hash_md5": "AB4AB98654635CABADB5F1A60BDA1C05", "hash_sha1": "147FCAC6D6C4E2C397BAC2F1173F0183E05F6636", "hash_sha256": "5FCCFF57D379CDC4CF6196FEF554CEF753B4C76DC315F371F90AEBF07B6A18C3", "hash_sha384": "C33DE3C6FE97F1D94B812EF408880EAD6F1C7D3E0F2C0F90DAF075205E735BC94EB456397D32BDEC4AC0E468C413536B", "hash_sha512": "E2F23DE71037683A18457A2913439C54AB3E9FAE325DD17E2ED2FC78202073FCCA222F08BE3614F27F44A34F5E9AC9F44AE0FAFE11C2E4B558BD6B76EAB8B940", "hash_ssdeep": "768:m3YZGi6egGak3T7J8a+LONvhQ4XtbEuivwC:m3cVg6T7ia+LONvi4XREuivwC", "hash_imp": "566283D9BC4787CDF98CCF90FD58FC2E", "hash_pesha1": "EF20372AF1455A9608C31087C001517EA8A33419", "hash_pe256": "17EBAE4803DE14EC45E333AE7BFFE7874E28B49026E872C4797FE79B883C8175", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host process for WinRM plug-ins", "meta_original_filename": "wsmprovhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/5fccff57d379cdc4cf6196fef554cef753b4c76dc315f371f90aebf07b6a18c3/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECCD8": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wsmprovhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\system32\\WsmSvc.DLL", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\system32\\miutils.dll", "C:\\Windows\\system32\\DSROLE.dll", "C:\\Windows\\system32\\pcwum.dll", "C:\\Windows\\system32\\mi.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll" ] }, "wsqmcons.exe-207A52DB4D9CB6A252722D51E54AB01D": { "file_name": "wsqmcons.exe", "file_path": "C:\\Windows\\system32\\wsqmcons.exe", "hash_md5": "207A52DB4D9CB6A252722D51E54AB01D", "hash_sha1": "8CCBC67E74B01B3D90387A4F099FB3C49F7F3EB0", "hash_sha256": "C1D4CE55169A1EE0FB5E11DBF907DF52EBBA5A3914A754F4557CBEC96A857C20", "hash_sha384": "D03345B611046A09424798E9574577EAF26AA9EF9D4F517597453C451D29BD0A64605B403159BEFC7A218CEF1E2FB111", "hash_sha512": "7251D0CF73D44259D0A9FC78FE96F03B56C709BBB615CC9C36C5D2A24CFCE5C3286E7D7221AEA9B51BAFC083C9E24164C322CAD62C7851B67B4DD197EB8AEC28", "hash_ssdeep": "1536:Up3uiFiV/3QA1R0y4ZG6zROCEjyXTC/xlkWSZJaGQumre2q6J:we/Jf6zwjQUSZJNQuCe2B", "hash_imp": "D704D43E51FEE7E15E186F930CEF45D0", "hash_pesha1": "301FD8BF31E67BCEFFFB0778B9BF664514D61983", "hash_pe256": "06B7016A59035F984F1DF6366F4A0E58AF1B0FC63CCC20C69F846FE03AFDE56F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows SQM Consolidator", "meta_original_filename": "wsqmcons.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/c1d4ce55169a1ee0fb5e11dbf907df52ebba5a3914a754f4557cbec96a857c20/detection/", "runtime_modules": [ "C:\\Windows\\system32\\wsqmcons.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ] }, "WSReset.exe-0D2BE4AE7AE5B93B47E12F4EFF38A0D7": { "file_name": "WSReset.exe", "file_path": "C:\\Windows\\system32\\WSReset.exe", "hash_md5": "0D2BE4AE7AE5B93B47E12F4EFF38A0D7", "hash_sha1": "A75F9C233E1C56AD0B3A0FDCFF1368E7FB3EA1D7", "hash_sha256": "5FDDA5D5E3AE48A72CD3E71410BF0A67512B7793006CAB5878D1361000616AD6", "hash_sha384": "987F38A48EB5B6B940D63F1B301D90777983378D9537DF13DCD59076A448298853F1DB15554B257631B37C61F169B208", "hash_sha512": "A059D2656D2130D26D8195989B6DE11851307FE85073A7473D8F80B74BC14795101663A6C2FBF0F5B23D274B0DDE7A284D38A0D300589B124895389C261B18B4", "hash_ssdeep": "768:SnEer5SWnW7Sk0lKdoR9+1Nsn4FOBkStBWX:g/8tSk0lKd1Gg0YX", "hash_imp": "AB03184F9306BF7E8482C6F987BA1832", "hash_pesha1": "36C962529458A83A35631E26D965CF559EA4C7A4", "hash_pe256": "315FF3F3BB1FEE25AFC0C973173B1404B87FC32759474FCCC841BFB915EDE03D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "This tool resets the Windows Store without changing account settings or deleting installed apps", "meta_original_filename": "WSReset.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.592 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.592", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/5fdda5d5e3ae48a72cd3e71410bf0a67512b7793006cab5878d1361000616ad6/detection/", "runtime_modules": [ "C:\\Windows\\system32\\WSReset.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\wevtapi.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\system32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\urlmon.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\system32\\CRYPTBASE.DLL", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\ieframe.dll", "C:\\Windows\\System32\\NETAPI32.dll", "C:\\Windows\\System32\\VERSION.dll", "C:\\Windows\\System32\\USERENV.dll", "C:\\Windows\\System32\\WINHTTP.dll", "C:\\Windows\\System32\\NETUTILS.DLL", "C:\\Windows\\System32\\WKSCLI.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\System32\\Windows.StateRepositoryPS.dll", "C:\\Windows\\system32\\edputil.dll", "C:\\Windows\\system32\\Secur32.dll", "C:\\Windows\\system32\\SSPICLI.DLL", "C:\\Windows\\system32\\MLANG.dll", "C:\\Windows\\system32\\WININET.dll", "C:\\Windows\\System32\\Windows.UI.AppDefaults.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll" ] }, "wuapihost.exe-6A1BA5277F81CD8C5C7A2047E26F4A02": { "file_name": "wuapihost.exe", "file_path": "C:\\Windows\\system32\\wuapihost.exe", "hash_md5": "6A1BA5277F81CD8C5C7A2047E26F4A02", "hash_sha1": "BBBA5247500218E4983C8AE9E8C92CFDC969DD28", "hash_sha256": "5A7C14146018CDF58BBA0B291AE2B6E4826DC1A45F335F4DFC378E1EB545D27B", "hash_sha384": "164A3279254F582D116E801D22C3C8C3C13AD1968EC20E31B82B3275AD6CB7CE1FEBB60364B16D97B6D7E3AEC9B7BBC8", "hash_sha512": "3E806821298FA017CB19B5BCA20CFF8B9D3F1F9DE68A290AF85BA6B29BC888A4B629BC6D825DC93C7DAD0F8819FBF3FCF31A69930120D5C9484381D31C8E84DF", "hash_ssdeep": "192:AHLClUp6EqYR+mZYYFq62zd7WvsNuUWv5dzy8ZfXt/N2WEfW:+ClUp2YRx2Yk6Wd2uI5Pb/YWEfW", "hash_imp": "04AC43054DE90C6C2629EAD16AB86780", "hash_pesha1": "F35FC60AA0B7EB927E1F8F923B7984C155D5F824", "hash_pe256": "7482470D103ED4366F3843B13C678C589212AA3B99F1CFED7A2A6B2BB09AB263", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "wuapihost", "meta_original_filename": "wuapihost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/5a7c14146018cdf58bba0b291ae2b6e4826dc1a45f335f4dfc378e1eb545d27b/detection/", "runtime_modules": [ "C:\\Windows\\system32\\wuapihost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\wuapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\wups.dll" ] }, "wuauclt.exe-2DC92DE9298D82A2ADC787E22306239D": { "file_name": "wuauclt.exe", "file_path": "C:\\Windows\\system32\\wuauclt.exe", "hash_md5": "2DC92DE9298D82A2ADC787E22306239D", "hash_sha1": "C5317A49B291F1CE71136A432B71685D70FD4FAF", "hash_sha256": "6858C6B1F3C45F9788C9988EF6319483D9C7AEBBC5B59DAF71C2F4208997B59A", "hash_sha384": "C824993933678802459A4CF22DBCC8217B1302763241208E2BF4673D0ED8CE637C144D0C1FA5CF366391DEC03BA265F6", "hash_sha512": "2B05E204D49F876F135E910C85B9BD7769EE0F3CED6D4D6EEBB0FC882FDE8C1F582C408E081F55B0F5EF1647D85C52F78D03504C2B44EC928ACA2EC5A0E8B959", "hash_ssdeep": "768:ao+yE/Mvy1sxCf1eQAqTE0OVJzOH/K4FVQcqj5fCuKAEXOaEnw1BulMWZqy4Z951:LE/Skra/Cle7lM7jYCfRdglPc", "hash_imp": "51E0B3CA4E9BE50477C08867FFEF206F", "hash_pesha1": "B2E4010138A9FB40A83C6B3D72983E9609D3BC37", "hash_pe256": "3614B8E342466C44D4AF84AA1ABCCB9579170D51253010CB000EFA108B948AE2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Update", "meta_original_filename": "wuauclt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1457 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1457", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/6858c6b1f3c45f9788c9988ef6319483d9c7aebbc5b59daf71c2f4208997b59a/detection/" }, "WUDFCompanionHost.exe-C5AF6942B174DEB2E4483A5111DD0B28": { "file_name": "WUDFCompanionHost.exe", "file_path": "C:\\Windows\\system32\\WUDFCompanionHost.exe", "hash_md5": "C5AF6942B174DEB2E4483A5111DD0B28", "hash_sha1": "28B24DADC9758ADD62E369F157B9D791B7DBBBA6", "hash_sha256": "648CD26CB4F955F1C5F0FD6A4D3CD58A8D1F6EB6B082A7791B5B2A0A5B46F327", "hash_sha384": "FF7E84BF37F23A36A076BA60AE5848A0DB8BCCD1F980DE86C482A44F3F6E39E8FD96C74962B8BD05414E4B3E4EAD0BB0", "hash_sha512": "D93ECE808F17EA38D1C8882F32C09A6FD63F32D85167D92A0DB176F66301302FB6565F39AD0CD25E46A688C6AF696B0C2AA3CB8F56A0D8485A2D9EFAA5A8CF90", "hash_ssdeep": "3072:b219zCqAw/Qvkhly2h+cCu0kmvBYQUh55uatT+Ovh:b21hCqP/Qvkry8+u0uQU3", "hash_imp": "7B21670FB2AFAC237D5B032D5E6A35FB", "hash_pesha1": "7DDC22E49F588FF0ED7E42572DF5AD329B0808D1", "hash_pe256": "842422DCF3CABA2C3104A0A885815D114C16C4A597CC46C2AA3979E9ADE63CE3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Driver Foundation - User-mode Driver Companion Framework Host Process", "meta_original_filename": "WUDFCompanionHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/648cd26cb4f955f1c5f0fd6a4d3cd58a8d1f6eb6b082a7791b5b2a0a5b46f327/detection/" }, "WUDFHost.exe-902D7BA5FADD42DB2DC6C7DD5F9C0CF7": { "file_name": "WUDFHost.exe", "file_path": "C:\\Windows\\system32\\WUDFHost.exe", "hash_md5": "902D7BA5FADD42DB2DC6C7DD5F9C0CF7", "hash_sha1": "5D1194767DE49B6882C6083D52B2CA966E05CB75", "hash_sha256": "2E9EDAC8AD372BD9ADFFE852A18F5FBD25DE804C0CA39C2F5B88365CC443C138", "hash_sha384": "FE7A8F017E45C30E6D6A7F24ED8C88CEC4B8EF3E773463DFA8A6986A410C166BE77EDA3E50ED952FEAD6B571ACAFBCBF", "hash_sha512": "C017AE2EEFAA459E20678C300D399811A525A0B78D75B850858E03711A4BAFC063B29695848ECCABFEAC6B009D8C4B1EA89A31D1A81E6C51D93AA22B96B0236A", "hash_ssdeep": "6144:zPyPToujGJt70lxeD8gBwPZGp6I+zkY5oU+xCK0/v:zPETQIlED8gaZJk8/v", "hash_imp": "3FB4FBF226FDE242843AE0A7C907D1D5", "hash_pesha1": "8E3E750747412C1CA1A948D2C36AF590D652FDCC", "hash_pe256": "1047BDBABC03E3D85C1ACFB2F665F9711B5BCC4D073617848BDFC763FF8F10E4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Driver Foundation - User-mode Driver Framework Host Process", "meta_original_filename": "WUDFHost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/2e9edac8ad372bd9adffe852a18f5fbd25de804c0ca39c2f5b88365cc443c138/detection/", "runtime_modules": [ "C:\\Windows\\system32\\WUDFHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\DEVOBJ.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\SYSTEM32\\WUDFPlatform.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "wusa.exe-59701FE9C8BA85BCEB73A9B1B3E8E1C4": { "file_name": "wusa.exe", "file_path": "C:\\Windows\\system32\\wusa.exe", "hash_md5": "59701FE9C8BA85BCEB73A9B1B3E8E1C4", "hash_sha1": "41C0812B0BE63153F3B68EA76C8B985D69DDCFBB", "hash_sha256": "E0438C5594A4EEB8515518989EE3A773581F414273B857B885D2201F66A95B06", "hash_sha384": "8CF139BA0B9ADF180448ED29660BCE78D19D6BB8FE55CF52104CD5C83B1FB8FC3D9FE61364A3C80D39D765B13E55CC39", "hash_sha512": "197279F4F762D2746E5D67FEC5B94CD569647B9BEB79B0A6069C20A1D4C2DD36808F8B546CD8F0E7E515D744F05654D9D704C3FBD8ECA951F6B4A8E16BAB8C8A", "hash_ssdeep": "3072:SjomFcaF4iHSd5bqcoENXK6JRAqs4xjw8m1IRpR9/BRMp3cKAArDZz4N9GhbkUNJ:Sj9FjuiebqcoMHxM8cg9wpxyN90vE", "hash_imp": "D5E97853B4CD1F8376A7D9FDA250C21E", "hash_pesha1": "A9F059D328FE2356577499E1448DAB78EC29ACBE", "hash_pe256": "D82C40386D1ACC422D41BA0F041D08C4AF97F74CF4177A2DC648E8A7568938F4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Update Standalone Installer", "meta_original_filename": "wusa.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/e0438c5594a4eeb8515518989ee3a773581f414273b857b885d2201f66a95b06/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\wusa.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wusa.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\dpx.dll", "C:\\Windows\\system32\\WTSAPI32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\system32\\DUser.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\system32\\WindowsCodecs.dll" ], "runtime_window_title": "Windows Update Standalone Installer" }, "WWAHost.exe-F981C29A73292182380F3E1797C7087B": { "file_name": "WWAHost.exe", "file_path": "C:\\Windows\\system32\\WWAHost.exe", "hash_md5": "F981C29A73292182380F3E1797C7087B", "hash_sha1": "6C0AB97D0E8B355468EB1C19EC719D342E3DA54F", "hash_sha256": "406C71C2BC1C4710EC2A034EA1FA7DC0E689E87C04A6B3A980F485B72ED41E08", "hash_sha384": "4BD0A7FC7F6F55149F78AC522485E3176330E4A93A6F6AFD56B4A5E95B7019B41CCBA88D5005F0AC6E5CEECE31AB7344", "hash_sha512": "6440C185A9ACC3129468DF7D2C6E758BFB256ABE892FDD972068F073BEAAC73E51B0DEBAFC9177725B231861054D5206C672B7B52D9D99EB730CD1CB63FD20A8", "hash_ssdeep": "12288:hXBvJB88SecfzGmtkBIHBJqm1EDKlNje+sz8g2ZZ2lrYEIMNR/z3LaLpLbLvL4Lk:hXBvJBvSC9BIqmjh1AlrYENKfLujE", "hash_imp": "74B31225FEB2200BE95DD13498C7B16B", "hash_pesha1": "9A6F22A7B473BA4E4197DC1DE022032D4F063373", "hash_pe256": "C10C5FEE38DB09C55B51BEEEEE10E5A8CD4161EF80E07BAB14367E2F8D6F831E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft WWA Host", "meta_original_filename": "WWAHost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/406c71c2bc1c4710ec2a034ea1fa7dc0e689e87c04a6b3a980f485b72ed41e08/detection/", "runtime_modules": [ "C:\\Windows\\system32\\WWAHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\system32\\iertutil.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\SYSTEM32\\wintypes.dll" ] }, "xcopy.exe-ACBA3C52830DD747DEF2241E3151CCB8": { "file_name": "xcopy.exe", "file_path": "C:\\Windows\\system32\\xcopy.exe", "hash_md5": "ACBA3C52830DD747DEF2241E3151CCB8", "hash_sha1": "A2D8E1A994CB7D774DA09896CBB275238268B085", "hash_sha256": "1C58E29C25B4065893DD4FBB6ED27BD8A04828A30396D581D7C641D21E910DC8", "hash_sha384": "93BB75A68DA75F05405B0169AC6DA145ACDA50E2E36251C5C5DC643EDB11EBE42A5FCDED9213D501D442A9462E9F26EF", "hash_sha512": "131D0B4DCCFE17CB283AB4E2325EADE15C04F159096083922D9484169100914788491399B994C41A89E29E1CE7AC11E2CE19979CAF884B1F85F6E72EB78A5874", "hash_ssdeep": "768:A+jOQasvktyjMOViT/bech/UAHXjPc/vkxU5R:nOgMyjMrec5UOxU5R", "hash_imp": "35EA203988B3D2B863842077BCE520C7", "hash_pesha1": "B37D8D39842B3C5D029A969DBAE322ABF5D90235", "hash_pe256": "E75E429018680669BEBD831BF65E19C844B9D97D9B1BA63D4310E576C672FBE3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extended Copy Utility", "meta_original_filename": "XCOPY.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/1c58e29c25b4065893dd4fbb6ed27bd8a04828a30396d581d7c641d21e910dc8/detection/", "output": "Copies files and directory trees.\r\n\r\nXCOPY source [destination] [/A | /M] [/D[:date]] [/P] [/S [/E]] [/V] [/W]\r\n [/C] [/I] [/Q] [/F] [/L] [/G] [/H] [/R] [/T] [/U]\r\n [/K] [/N] [/O] [/X] [/Y] [/-Y] [/Z] [/B] [/J]\r\n [/EXCLUDE:file1[+file2][+file3]...]\r\n\r\n source Specifies the file(s) to copy.\r\n destination Specifies the location and/or name of new files.\r\n /A Copies only files with the archive attribute set,\r\n doesn't change the attribute.\r\n /M Copies only files with the archive attribute set,\r\n turns off the archive attribute.\r\n /D:m-d-y Copies files changed on or after the specified date.\r\n If no date is given, copies only those files whose\r\n source time is newer than the destination time.\r\n /EXCLUDE:file1[+file2][+file3]...\r\n Specifies a list of files containing strings. Each string\r\n should be in a separate line in the files. When any of the\r\n strings match any part of the absolute path of the file to be\r\n copied, that file will be excluded from being copied. For\r\n example, specifying a string like \\obj\\ or .obj will exclude\r\n all files underneath the directory obj or all files with the\r\n .obj extension respectively.\r\n /P Prompts you before creating each destination file.\r\n /S Copies directories and subdirectories except empty ones.\r\n /E Copies directories and subdirectories, including empty ones.\r\n Same as /S /E. May be used to modify /T.\r\n /V Verifies the size of each new file.\r\n /W Prompts you to press a key before copying.\r\n /C Continues copying even if errors occur.\r\n /I If destination does not exist and copying more than one file,\r\n assumes that destination must be a directory.\r\n /Q Does not display file names while copying.\r\n /F Displays full source and destination file names while copying.\r\n /L Displays files that would be copied.\r\n /G Allows the copying of encrypted files to destination that does\r\n not support encryption.\r\n /H Copies hidden and system files also.\r\n /R Overwrites read-only files.\r\n /T Creates directory structure, but does not copy files. Does not\r\n include empty directories or subdirectories. /T /E includes\r\n empty directories and subdirectories.\r\n /U Copies only files that already exist in destination.\r\n /K Copies attributes. Normal Xcopy will reset read-only attributes.\r\n /N Copies using the generated short names.\r\n /O Copies file ownership and ACL information.\r\n /X Copies file audit settings (implies /O).\r\n /Y Suppresses prompting to confirm you want to overwrite an\r\n existing destination file.\r\n /-Y Causes prompting to confirm you want to overwrite an\r\n existing destination file.\r\n /Z Copies networked files in restartable mode.\r\n /B Copies the Symbolic Link itself versus the target of the link.\r\n /J Copies using unbuffered I/O. Recommended for very large files.\r\n\r\nThe switch /Y may be preset in the COPYCMD environment variable.\r\nThis may be overridden with /-Y on the command line.\r\n", "error": "File cannot be copied onto itself\r\n", "runtime_modules": [ "C:\\Windows\\system32\\xcopy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "xpsrchvw.exe-27B26DAF04DFF2EDBF6CCEE360C2332A": { "file_name": "xpsrchvw.exe", "file_path": "C:\\Windows\\system32\\xpsrchvw.exe", "hash_md5": "27B26DAF04DFF2EDBF6CCEE360C2332A", "hash_sha1": "49F10594D41868F71C1F81C901FD4CC741AF496A", "hash_sha256": "3E35BF6359B05915C42F13F6AC3A3A357B64E55E201ABFD3541E4FA6BE542AB6", "hash_sha384": "BAE6D016A4FF0401E8BF6D77582B4FF4B5D12C75DFF2E8D3BF18F6AAE1A433D39EB43850272DA359569AA81140E8C617", "hash_sha512": "5B1C371D6E47788ADD90FC0ABC6B532AD8507FBC3FBBCF954CC8466AE51E1F42859B2986521DC3DB2DA9AFD03BDD60EA117D0B58C796B4CAED2EE4B5DCAE9597", "hash_ssdeep": "49152:styjW9niFk06taWPZOdz508nue+fTGAuaOvf4EM4kNSxlcXX2RHQibnGf/TraEMf:uyjA8nifqo8f4relcXFHMtaQMw", "hash_imp": "F48866488FE50FA84A68E37B79E2D4F5", "hash_pesha1": "8809B42A48837DD978308E431209A62A1ADB777F", "hash_pe256": "CA876FB51CB7C45EC3DEC3EF49E086D8AA87A66F94A29E3FCA4C0795A1CCEC13", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "XPS Viewer", "meta_original_filename": "xpsrchvw.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/3e35bf6359b05915c42f13f6ac3a3a357b64e55e201abfd3541e4fa6be542ab6/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "(R-D) C:\\Windows\\System32\\en-US\\xpsrchvw.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\System32": "File", "\\RPC Control\\DSECE34": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\xpsrchvw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\system32\\netutils.dll", "C:\\Windows\\system32\\wkscli.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\DWrite.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\system32\\WINMM.dll", "C:\\Windows\\system32\\CRYPTXML.dll", "C:\\Windows\\system32\\ncrypt.dll", "C:\\Windows\\system32\\WINMMBASE.dll", "C:\\Windows\\system32\\webservices.dll", "C:\\Windows\\system32\\NTASN1.dll" ], "runtime_window_title": "XPS Viewer" }, "xwizard.exe-10B8BDC83EF7CFBBD344F2587453AD29": { "file_name": "xwizard.exe", "file_path": "C:\\Windows\\system32\\xwizard.exe", "hash_md5": "10B8BDC83EF7CFBBD344F2587453AD29", "hash_sha1": "AFB419905F2CB4A48714836C5D3D5527A8FD6B80", "hash_sha256": "B0C08A32F7F9FF3696DFEB67924D873604F20D7561A0800F39148C7B82552710", "hash_sha384": "3E23BB960B5C2378CE90F9C6938ABF10F65AEBD8EEF4DE3709B0149B65D5D4D20C1BAC4BB6393566F04FF7015A44B1D8", "hash_sha512": "53CB82832ABA22AAAD8CB7CA8FECBD87A1BA0FED5FEB2C4D87FF56B1C992B1B38D83A32D570A5B06CE26014B05BAAEF44611C1E2509481106441CA4B41C239B4", "hash_ssdeep": "1536:Cpc6rrqCnPKFuT9lt53gbi1SCDURDoq4OZZZLlCIib:Ca6nhnPmuB53H1BoRD68wb", "hash_imp": "42465F712C75BD79EB46ECE0D31A4B8D", "hash_pesha1": "554EF3EA22305D641FD1F4A742E434B25419CA08", "hash_pe256": "05C211837B116CC94944D8C247CDDFC366AAF0919E1D5ABA3E2A1E2F2930BC45", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extensible Wizards Host Process", "meta_original_filename": "xwizard.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/b0c08a32f7f9ff3696dfeb67924d873604f20d7561a0800f39148c7b82552710/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\xwizard.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\xwizard.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll" ] }, "AppVStreamingUX.exe-17028EE25ADAF871E45BAB091C93554E": { "file_name": "AppVStreamingUX.exe", "file_path": "C:\\Windows\\system32\\AppV\\AppVStreamingUX.exe", "hash_md5": "17028EE25ADAF871E45BAB091C93554E", "hash_sha1": "CD02B996ED8A3E8FE57CC40080FDF1E1D5659F2E", "hash_sha256": "588A12EDAC02C93A449E9570BFFF0D9DFD6C297841EB593B2001EF9AE75BF5EB", "hash_sha384": "0807462B2C38C207EAC3498B01EF72AC56AD7ABBA0DD82EC520E545BB6014B0AF40BDE8C5F4A744CA5FF8DC34FE7F0B1", "hash_sha512": "8A7FE421B25F25E84E0DD53CAA2E4229EF1E396483DCD64307A9A5D7825B2B1F7AE5322BFBAFBA9840E8B267A014B88DF57D207EF8BF10EC981D79686888925F", "hash_ssdeep": "3072:wyIen7ExTWZTSddxYkEmIjy+pjMqVVdmabWcONiHNp6ei/EzoHMqVVdmabWcONiN:X7ExKZUdgCaqg6RcKCaqg6Rhu", "hash_imp": "n/a", "hash_pesha1": "EA76E4F932041E210E705B74DBD3FC15943ABF89", "hash_pe256": "B93A15868803AA170D440033CDF099DB07BD8D404CF6F440A329F8E987B07B9F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/588a12edac02c93a449e9570bfff0d9dfd6c297841eb593b2001ef9ae75bf5eb/detection/", "runtime_modules": [ "C:\\Windows\\system32\\AppV\\AppVStreamingUX.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll" ] }, "comrepl.exe-2ECEF8604EC6C46B607B40F12FBB01FE": { "file_name": "comrepl.exe", "file_path": "C:\\Windows\\system32\\com\\comrepl.exe", "hash_md5": "2ECEF8604EC6C46B607B40F12FBB01FE", "hash_sha1": "9CE64D69B7AA8C77467BA4F29B577E47011933DC", "hash_sha256": "EAC4D267FC7EAF129CA81DE26590E0C54583B3AFD3E4F48EEDA255972D70E41E", "hash_sha384": "DA725B3B39D172FFC078EC40A46FEBA9154416C39AF1183A156A1FC22597CCD51343076304887C9038523F2ED29C4A07", "hash_sha512": "DC3E38479795956DCE08278483FD2637115FA384F4851DE37557DD958C912161B0FD350592FF87034E4758F5D2939F9992D3E071870BF93502F086B2CFA96F24", "hash_ssdeep": "384:5yHW6Uay4yg///OGc56VRtnQxm4XZrFW5VuoW:5yHPLnQC6m4XE", "hash_imp": "7361F50FBCDC282E828EFD5A9C317E2B", "hash_pesha1": "4630E485E3B6BFED3EA3708503A693714D9880CD", "hash_pe256": "01BC0638539AFB4741305E1BCC994EFB12F85033D39E97422D0ECB69BBC4B4C3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+ Server Replication", "meta_original_filename": "COMREPL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/eac4d267fc7eaf129ca81de26590e0c54583b3afd3e4f48eeda255972d70e41e/detection/", "output": "ERROR: WriteConsole failed = 00000001\r\r\nERROR: WriteConsole failed = 00000001\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\com\\comrepl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "MigRegDB.exe-4AFD76EEDFD38B370AC829BD567CF718": { "file_name": "MigRegDB.exe", "file_path": "C:\\Windows\\system32\\com\\MigRegDB.exe", "hash_md5": "4AFD76EEDFD38B370AC829BD567CF718", "hash_sha1": "DFC334CD78ACF6E81F8FCBD39B931BB74CCE8032", "hash_sha256": "D34C95146D362C3F7B0FE02E940AB2FD30F434C13D05723831A75422C8D19D35", "hash_sha384": "E91E3212B9CA9ED746AB5FAA1A8AFD1213ACB3D3E5D03B26ABE0FD050A7B14C5A8C8CF096B5FB70A070794A8370A2275", "hash_sha512": "AF7C4EADDC7E456856050F1F1CABC48BEE66034BF7A7BFB105FE9EB7A8426C816F8D38606C2E6846A0675FB8FF3FB960A4E95616D810775748E40F2F62CDCE9A", "hash_ssdeep": "192:mH4mCGi9GIGRs6MnXMF01psxyTvEP7wEhIzHG7uU+74QWYwW:24mC1YIGdgce16y8/hIrp/74QWYwW", "hash_imp": "3ABC19FA8AADAB98440F63CE4EBA6EE2", "hash_pesha1": "6BF02A6C4A17FE8C1D5EDAE244732A0E6BDFC65E", "hash_pe256": "8F588087E916CF192214CBC043A9C39D4FBD28F90048B52071A943F1A224CBFA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+", "meta_original_filename": "MIGREGDB.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/d34c95146d362c3f7b0fe02e940ab2fd30f434c13d05723831a75422c8d19d35/detection/", "runtime_modules": [ "C:\\Windows\\system32\\com\\MigRegDB.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\CLBCatQ.DLL", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ] }, "DiagnosticsHub.StandardCollector.Service.exe-65414CDBEB90C0D6E20A9A214E013EB0": { "file_name": "DiagnosticsHub.StandardCollector.Service.exe", "file_path": "C:\\Windows\\system32\\DiagSvcs\\DiagnosticsHub.StandardCollector.Service.exe", "hash_md5": "65414CDBEB90C0D6E20A9A214E013EB0", "hash_sha1": "EF5054468A6940168BD117D6EE5761C7A1B68597", "hash_sha256": "F1F299EF5A2D463E5860A3D26AD33CA3BB7ED3C55BCE156E4245C35A857A2C46", "hash_sha384": "BE51E7B3190BD08BA209CA74FF36642F35FEADDB4A45112C6607470E095A1DC0DADC5A6A647A0FED66946C52D4AF71C1", "hash_sha512": "6356235CB466E03F1B04827C7FD5536D94DD21843BF70C18BE8178FE059842C9500D230CBD637B7280D561F87E562F8B10CBC596200EE590524E7B9B95112A63", "hash_ssdeep": "1536:mqmHNa0IWwL83Pvxk4mfuQJw4WWxqiqeOQm1K7KjtcMjE:mbQHHLgq4m3JrWWwA+KmjtbjE", "hash_imp": "70C0C680A07469D2A372362DE29CFC53", "hash_pesha1": "E702617B3259502281ED029E04E52420CCC334C6", "hash_pe256": "2880FA473CDE75C3EB2734AB949BD15CE4C0C0D0A35C8C3E061444E0B2BDC189", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) Diagnostics Hub Standard Collector", "meta_original_filename": "DiagnosticsHub.StandardCollector.Service.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.503 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.503", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/f1f299ef5a2d463e5860a3d26ad33ca3bb7ed3c55bce156e4245c35a857a2c46/detection/", "runtime_modules": [ "C:\\Windows\\system32\\DiagSvcs\\DiagnosticsHub.StandardCollector.Service.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\msvcrt.dll" ], "output": "Unrecognized option: --help\r\n" }, "DismHost.exe-1AE12EB030839C374CF89CA82B7F45C0": { "file_name": "DismHost.exe", "file_path": "C:\\Windows\\system32\\Dism\\DismHost.exe", "hash_md5": "1AE12EB030839C374CF89CA82B7F45C0", "hash_sha1": "E3040F7D963A366AD6FCF0DE3D64A0277CD9A140", "hash_sha256": "F81B2F9FBBFA6E16D59D8AB703B3EF5A4A63BF4B23E002BD7B5BFA01CE62B937", "hash_sha384": "E6A728567D14A45598152E1CF04309B68CECFDFCF7F2FFFC9B65F548DB81743CE23EF65776A7BF6050005936459C1ED4", "hash_sha512": "854B67DE4E03124D8B94EF71EDAD92876225F6CA4EF82D8319287C001D4B0F3335C50C95424E4A5DA14F49F7CEECEF5C303B862B03D0C1F5E0367BC3A265995A", "hash_ssdeep": "1536:gcyoV9r967An2g8+V3NkqmKs0dwymJaw9oyDTSEjf9/DSzLO5LxMQSGP8:gcyk9rU7G22V/7w56fy5LxDBU", "hash_imp": "C601FA732FF0599995A293BA7882B84D", "hash_pesha1": "DF41B1F3C84CEF9439CF49B592B9B80A43160D3C", "hash_pe256": "7945F4870C90EA05B65A0A5A4A237C442294FDDC550988CE5DC5E99BF2866303", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Dism Host Servicing Process", "meta_original_filename": "DismHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/f81b2f9fbbfa6e16d59d8ab703b3ef5a4a63bf4b23e002bd7b5bfa01ce62b937/detection/", "children": [ "csrss.exe", "wininit.exe" ] }, "IEChooser.exe-2ED5D27984D5B4240FC9AD9E2A348623": { "file_name": "IEChooser.exe", "file_path": "C:\\Windows\\system32\\F12\\IEChooser.exe", "hash_md5": "2ED5D27984D5B4240FC9AD9E2A348623", "hash_sha1": "E884DD89B826C4306714AD82406120EC47EB322D", "hash_sha256": "07646115E1B288FDB859FF72253956E2AAD7AD8AB0F8ED83CF4745BB02B8C659", "hash_sha384": "23D47316EB97C2BDFE5E0DD79EE398F0717E82B2A3C88C88A992784848D2518683EE175568B6470906F52B94175B89EF", "hash_sha512": "5FD784A0B886A5532A23C7FBE0CDC097770C1E296C4C71742667111B81DE5DEED9FECDF416F4ED51FE86D17C8C6C68B88325CB9704DDB970A8631E50E2E5C6A3", "hash_ssdeep": "3072:vpEDMnVh72SKc7AWWbk8TQhIhp9IK/x31hKkDZvy01Mho/b6nvRgY:vWsKc7AWjVU9IK/hKkDZv7MhA6nve", "hash_imp": "E6FFA43295C71034355FC73AB36E6C26", "hash_pesha1": "CFE6A4A430EF2FBBC504E0B3336597A5FC6BD0B1", "hash_pe256": "19DBE7E5CEC58451DF703776C0F31D300BD41FCA3CC2DFD9B969326FB91E79B6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "F12 Attach Chooser executable", "meta_original_filename": "F12Chooser.exe.mui", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/07646115e1b288fdb859ff72253956e2aad7ad8ab0f8ed83cf4745bb02b8c659/detection/", "runtime_modules": [ "C:\\Windows\\system32\\F12\\IEChooser.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\iertutil.dll", "C:\\Windows\\SYSTEM32\\urlmon.dll", "C:\\Windows\\SYSTEM32\\OLEACC.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.DLL" ] }, "IMJPDCT.EXE-D977E424B5108DE9D3F2C6A4C1975258": { "file_name": "IMJPDCT.EXE", "file_path": "C:\\Windows\\system32\\IME\\IMEJP\\IMJPDCT.EXE", "hash_md5": "D977E424B5108DE9D3F2C6A4C1975258", "hash_sha1": "0EAAD5CB104D87510E06E78072F8E52ADD7713E7", "hash_sha256": "1157E39DDBB67CC21837D251553D51D3F30E57AA8BFB6D0BCC0A82162EE35AF2", "hash_sha384": "E4EA167E2CD7A23DB68AF023EAAC42F1C8382746083618D41ED2E68774480344F6AC97E0A34B14D5DADC0C641A132458", "hash_sha512": "28F0B20DCA33BB531A7968D0BCB18C357AE106C50997A8921DFC6CB3C656F3B7482EA62BC965D4B2D8816C347E74BB75A7CDD4FA5379E374A476CE9E77F0E476", "hash_ssdeep": "12288:n5PPpu995+vPbnrhVbFDq6pE58GMXFiXdAp8qr:5u01qzKFiXdAp8q", "hash_imp": "258D4323ACDF3A1142F636970661A8E3", "hash_pesha1": "F6CB1F96ED4D1548DE9D0B514E91190D0A56D7C1", "hash_pe256": "E4C1542700B276AE7771223BCEC1236D58816D02D6908D5C649E46C420F8FC0B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imjpdct.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/1157e39ddbb67cc21837d251553d51d3f30e57aa8bfb6d0bcc0a82162ee35af2/detection/", "children": "IMJPDCT.EXE", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\RPC Control\\DSEC10CC": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\SatoriKnlDict_MemoryDictionary_IMJP_15__M_S-1-5-21-4075667164-670084373-454571106-500": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\2\\BaseNamedObjects\\10ccHWNDInterface:1703d6": "Section", "\\Sessions\\2\\BaseNamedObjects\\10ccHWNDInterface:1904fa": "Section", "\\Sessions\\2\\BaseNamedObjects\\10ccHWNDInterface:200502": "Section", "\\Sessions\\2\\BaseNamedObjects\\_IMJP_15_UD_FileMapping_{b4f0aa5b-77d3-486f-b999-53049e87159e}_M_S-1-5-21-4075667164-670084373-454571106-500": "Section", "\\Sessions\\2\\BaseNamedObjects\\c:_users_user_appdata_roaming_microsoft_ime_15.0_imejp_userdict_imjp15cu.dic_IMJP_15_UD_ManagementBlock_{8bbff7b9-ccde-414f-96ed-936990babd2d}_M_S-1-5-21-4075667164-670084373-454571106-500": "Section", "\\Sessions\\2\\BaseNamedObjects\\mem_c:_users_user_appdata_roaming_microsoft_ime_15.0_imejp_userdict_imjp15cu.dic_M_S-1-5-21-4075667164-670084373-454571106-50000041000": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\IMEJP\\IMJPDCT.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\uxtheme.dll" ], "runtime_window_title": "Add Word" }, "IMJPSET.EXE-6FEC8EEB04AE0BE04ADD090B26EC27C1": { "file_name": "IMJPSET.EXE", "file_path": "C:\\Windows\\system32\\IME\\IMEJP\\IMJPSET.EXE", "hash_md5": "6FEC8EEB04AE0BE04ADD090B26EC27C1", "hash_sha1": "BDDB3FE363A38C4C5E745444C04B99A8BFE2B9FE", "hash_sha256": "8C36EF4B4A75747F10290D1BA7EEBDF7CD8787C90D4A747F26972EB8FF367822", "hash_sha384": "EF6A4625470C1099C2919525B487AA75F44DFC45D1165AB48CEFE8824CB00321921FA563A6E253AE62BAB973676C19A1", "hash_sha512": "428AB573EF04E34C4EEB303FE7D130130F7B2367642D2B1E5FB179F4B085C035B0D5576A6CEBEA8C1A375EDC2B2D8501620FAC16257291900348078227B5CAAE", "hash_ssdeep": "3072:KvWVfwfSl6VGYjPil0+3b2dtMk9ilDDiHmax1PcYYH67IkK2NLPcV2:KvCfw6lnuPiuNHiFDiG1mIkC", "hash_imp": "7A01B94F243CA37EE83F0B4E38BFD809", "hash_pesha1": "A4DDF24B61077185320CB2E64FC34A77FE937833", "hash_pe256": "010797BBF53C29E7DBCDF3D30453D04625C68448030A2990D44435AA5F5DE8ED", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "IMJPSET.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/8c36ef4b4a75747f10290d1ba7eebdf7cd8787c90d4a747f26972eb8ff367822/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\_IMJP_15_UD_FileMapping_{b4f0aa5b-77d3-486f-b999-53049e87159e}_M_S-1-5-21-4075667164-670084373-454571106-500": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\RPC Control\\DSEC744": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\IMEJP\\IMJPSET.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\SYSTEM32\\DUI70.dll" ], "runtime_window_title": "Settings for Microsoft IME" }, "IMJPUEX.EXE-6B59D6B19D912836B63BDF82E6225E2E": { "file_name": "IMJPUEX.EXE", "file_path": "C:\\Windows\\system32\\IME\\IMEJP\\IMJPUEX.EXE", "hash_md5": "6B59D6B19D912836B63BDF82E6225E2E", "hash_sha1": "15823431B1934E97843923DB95E2B8A31F5262CF", "hash_sha256": "0BB4E662016AA3F9642CA49F7BE46C3DD5000AF101417D608A114E802E21E522", "hash_sha384": "37A445D42AAE19D71CC80534D1609B64DF80FFDD88BDF85D8E1E54A830BA211B88FC7A5F035CB6EA0317D20B31679F2F", "hash_sha512": "097E41B2FB6D5D0BBAF61F828A84051FAAE1A4F46F253DC32F106BFE8D79A3061E23A7E8E413E7FA6426ADA1BF5D37CFC71B52C8FECC12E85AAD0F4A4E766915", "hash_ssdeep": "1536:5BmGeQOGoPsWj0uEhLoYatHz+XNW3hy1cd3cYH67nIWDK2NLPcr:BePPjYatT+XNohyidMYH67IkK2NLPcr", "hash_imp": "C22124FFBB1D8A8177B201170462A33E", "hash_pesha1": "AF12A1EC1C769345D91E3CA022B9918418A0D6F6", "hash_pe256": "18015D524D075E34AF5E48A291036F4B089DDED6A5D334A98C7DDF29DBD8392B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imjpuex.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/0bb4e662016aa3f9642ca49f7be46c3dd5000af101417d608a114e802e21e522/detection/", "children": [ "csrss.exe", "wininit.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\_IMJP_15_UD_FileMapping_{b4f0aa5b-77d3-486f-b999-53049e87159e}_M_S-1-5-21-4075667164-670084373-454571106-500": "Section", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\IMEJP\\IMJPUEX.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\MFC42u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\system32\\IME\\IMEJP\\imjputyc.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\SYSTEM32\\oleacc.dll", "C:\\Windows\\SYSTEM32\\policymanager.dll", "C:\\Windows\\SYSTEM32\\msvcp110_win.dll", "C:\\Windows\\System32\\IME\\IMEJP\\imjpapi.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\IME\\shared\\imjkapi.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\IME\\IMEJP\\imjppred.dll" ], "runtime_window_title": "Advanced Settings for Microsoft IME" }, "imjpuexc.exe-B2F27EB0D4B90DB0DFE74EA81083F3EB": { "file_name": "imjpuexc.exe", "file_path": "C:\\Windows\\system32\\IME\\IMEJP\\imjpuexc.exe", "hash_md5": "B2F27EB0D4B90DB0DFE74EA81083F3EB", "hash_sha1": "0451136BDE208C8D6D2FDEEFAA378B98FA1F51FC", "hash_sha256": "D3CD759CBA9AA5299501331CF4C7A4A9855996BECA9D2EB76D750B6338AF7353", "hash_sha384": "E4CF454268A3F5DB506BDE10862A54D84C4BA4A4CF47F4607ED4E9D9473084175BC7E319176071EE65B0FD3268C04061", "hash_sha512": "6646003F29B4565AEEB69BD0EB1F290D058D47EC1A9E579FB9209DD02C2510901FC3167D28DB679869AE83C241AFA7FCB7B5CF1415E22132CC4AC7CF6D0B5A7D", "hash_ssdeep": "6144:3lr1y7Om2Qphzpdx+le8/04Hvsf25IQdWj/4kK6f9AjIKQ:3h1UYQphksYJHu2Stj/4kK6S8", "hash_imp": "752E42F702F05E57C8B20CAF52E14C4B", "hash_pesha1": "DEE3C73D7E0697171208C263C91D7B568DCB158C", "hash_pe256": "CB361E11DEA2AEDE585994C7F194EA5C14B9E12B96D24EB6401B14D66DEC1B00", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imjpuexc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/d3cd759cba9aa5299501331cf4c7a4a9855996beca9d2eb76d750b6338af7353/detection/", "output": "Microsoft IME Property Command Line Tool (10.0.17763.1075)\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nThe Syntax of this command is:\r\n\r\n IMJPUEXC HELP command\r\n\r\n Commands available are:\r\n \r\nIMJPUEXC ADDSYSDICT\t\tIMJPUEXC CHECKSYSDICT \r\nIMJPUEXC REMOVESYSDICT\t\tIMJPUEXC SETKANAINPUT \r\nIMJPUEXC GETKANAINPUT\t\tIMJPUEXC SETCUSTOMDICTPATH \r\nIMJPUEXC GETCUSTOMDICTPATH\tIMJPUEXC FIXCUSTOMDICT \r\nIMJPUEXC CODEAREAFORCONVERT\tIMJPUEXC SETOKURIGANAOPTION \r\nIMJPUEXC GETOKURIGANAOPTION\tIMJPUEXC SETKEYTEMPLATE \r\nIMJPUEXC SETKUTOUTEN\t\tIMJPUEXC RESET \r\nIMJPUEXC LOADAUTOTUNEDATA\tIMJPUEXC SAVEAUTOTUNEDATA \r\nIMJPUEXC REMOVEAUTOTUNEDATA\tIMJPUEXC SETFILTERDICT \r\nIMJPUEXC GETFILTERDICT\t\tIMJPUEXC REMOVEFILTERDICT\r\n" }, "IMTCLNWZ.EXE-DDBC3C5C85BCEC556FC9251478488628": { "file_name": "IMTCLNWZ.EXE", "file_path": "C:\\Windows\\system32\\IME\\IMETC\\IMTCLNWZ.EXE", "hash_md5": "DDBC3C5C85BCEC556FC9251478488628", "hash_sha1": "CE4B8DA1CBDEFD81B6E3174B86EA65F74BA50C7B", "hash_sha256": "9D47494BBD5709085585359533F632278359278A87E70F40CF9EDE6788A49489", "hash_sha384": "01117F1BD42B97A8AEB9118FEAC5EF74E6DF7143959C8D523ED6551B298B0DAF8DD5B10240DB5591FB50D84624300338", "hash_sha512": "0C761217F3CC26915B254D3A0F862E62B8A29126A423F0859738DC187DFA6AAAC03B4971E63AEAFDA743214D1C3AD65859BBF463534384AD6A74C12C88E81C71", "hash_ssdeep": "3072:Yeph9guiW2j2h7iBoJ+K9P+Dp10GWNqc:xn9guh2j2h7xJf49ewc", "hash_imp": "4D4BEC34B5B0A60A6FEE7DBF995FE92B", "hash_pesha1": "17F58CEE5208154647B2A24DD220BF5BB6C21153", "hash_pe256": "233F4367DDE50B4E95E83DE60E5373BEF318145BEF37216416E2A8A6444B2D38", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IMTCLNWZ.exe", "meta_original_filename": "IMTCLNWZ.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/9d47494bbd5709085585359533f632278359278a87e70f40cf9ede6788a49489/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326": "File", "\\Windows\\Theme966197582": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\IMETC\\IMTCLNWZ.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326\\COMCTL32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.DLL" ], "runtime_window_title": "ANSI" }, "IMTCPROP.exe-CB750586C353E12636F45780B5D5A0C7": { "file_name": "IMTCPROP.exe", "file_path": "C:\\Windows\\system32\\IME\\IMETC\\IMTCPROP.exe", "hash_md5": "CB750586C353E12636F45780B5D5A0C7", "hash_sha1": "9F14D5FE99E295A5624B61F3609943D8491B6DF8", "hash_sha256": "ED632ABD60C909259E668D958A2FE0152E4B6BE3EE755089BB4B15AFA6DD40E6", "hash_sha384": "53E5143A12693358F6E1D0F942D65BEB2417A5DA04ACE73ED4B1BC499168279C6FB90A749E858E7A89DBE713ECE3D8C2", "hash_sha512": "1AC8F92B83478F6A41BFF6830020C9EBF6B8E1071E21ED3C0B0AD4153C98CAB0AD290B5574E6BCB062F36B364C3185AA84A50E522BE0B3A72E845FAD7FA7B510", "hash_ssdeep": "3072:d3KLqS+wNRjvZS21E3S+g0p+yUttq/L2F7r21P7I/Xg+mClKRiTPqcfYMlf/:1KLH+wNRNx1gSG+9F+jINmKKRiT7fJ", "hash_imp": "689383DB375CC21E4F232E3AD658F75B", "hash_pesha1": "44C52DDFDB09C80946FE2F388A404E4BE3391CF4", "hash_pe256": "F1619A2A53D2A7EEB1C01B36BDB1F83422C5F85AADA012E00D56DD9B51359582", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IMTCPROP.exe", "meta_original_filename": "IMTCPROP.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/ed632abd60c909259e668d958a2fe0152e4b6be3ee755089bb4b15afa6dd40e6/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\IMETC\\IMTCPROP.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll" ], "runtime_window_title": "Microsoft Bopomofo" }, "IMCCPHR.exe-B93342B4F48B46FCBC46B969702C49C3": { "file_name": "IMCCPHR.exe", "file_path": "C:\\Windows\\system32\\IME\\shared\\IMCCPHR.exe", "hash_md5": "B93342B4F48B46FCBC46B969702C49C3", "hash_sha1": "4B33BC606B6F32F870668D76CCD83665A34F431A", "hash_sha256": "7CE685C16CB96D26816B64B4A91247756A67E17A4E82DC4F1C39F62EFDF45CCC", "hash_sha384": "5F0787FE056E4595445AD770B251D6D91E57CB9D299ED09FC9C2DAB3841E8337A5A7E0B7CE195F92AD369AE7EA4192F3", "hash_sha512": "6BA4C36583C736ECC43D39A56EBEF40D772EBFBF22A73039AA39E30071AD0D409170CE7143D681A651AC69C82C749E87B9AA65550A9A81C4792877A6757A3D75", "hash_ssdeep": "6144:j6pNypbzJxhf0vFMK35cUt7dRr7X66Olx8uSXmCPwP6k+kc8DZ5n:jKNCzJx6vqocUbRKEuSXmH6k+kcuv", "hash_imp": "D11A78DA639900F66EB2DAFEABE7C177", "hash_pesha1": "7B2410F4D61416EC14FF71AC4F69ADCBF59B82C2", "hash_pe256": "DBDEA25A124DAAA88DB04142B46BDAA7AB5357B6D9F3EDC311F3668638EFD5CB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IMCCPHR.exe", "meta_original_filename": "IMCCPHR.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/7ce685c16cb96d26816b64b4a91247756a67e17a4e82dc4f1c39f62efdf45ccc/detection/", "children": [ "csrss.exe", "wininit.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\shared\\IMCCPHR.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll" ], "runtime_window_title": "User-defined Phrase Tool for Microsoft Pinyin IME" }, "ImeBroker.exe-657A3C2BEDC04CE7A69C4325954DFF39": { "file_name": "ImeBroker.exe", "file_path": "C:\\Windows\\system32\\IME\\shared\\ImeBroker.exe", "hash_md5": "657A3C2BEDC04CE7A69C4325954DFF39", "hash_sha1": "022180230FDB2325D7CEF2038624DA6E49AF705D", "hash_sha256": "E37AF0474AA463E544ABC4E202D0A5E43A9B24423B51601AB4DD1A58CF5EF2A5", "hash_sha384": "C4C277084F530F3A3D30C616FBE9833D6502CE332833C07D82D355CF686B8769BB763AD40D87F8818F30A55C17B94C0F", "hash_sha512": "263BF7100238603406DAB9AA5CB6D5EF6273B32B9A77A3F054D04C9F098961BD3823B8CC82149E70FD42C6D03D0D7F988C406DC2B188332B2AEF2CBAB16920E0", "hash_ssdeep": "12288:Lt2QakYYBeo/D9eRIrDSav/ynU+Cq5dz5ycel7:L5YYBptSnH1dz5yco", "hash_imp": "99FBB9713ACD706C274D04C3A5701BB4", "hash_pesha1": "1ABE1ACF97F4C5233AB10E23D691BCC206D30F29", "hash_pe256": "B57145B6F94D40155C2D08CCB1C0C7CCBA02032050BA4529C728D555F17D5106", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "ImeBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/e37af0474aa463e544abc4e202d0a5e43a9b24423b51601ab4dd1a58cf5ef2a5/detection/", "runtime_modules": [ "C:\\Windows\\system32\\IME\\shared\\ImeBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\SYSTEM32\\XmlLite.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\ContactHarvesterDS.dll", "C:\\Windows\\System32\\PIMSTORE.dll", "C:\\Windows\\System32\\UserDataLanguageUtil.dll", "C:\\Windows\\System32\\UserDataPlatformHelperUtil.dll", "C:\\Windows\\System32\\Speech_OneCore\\Common\\sapi_onecore.dll", "C:\\Windows\\System32\\POWRPROF.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\msvcp110_win.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\SYSTEM32\\urlmon.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\SYSTEM32\\winmmbase.dll", "C:\\Windows\\SYSTEM32\\MMDevAPI.DLL", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\SYSTEM32\\WINHTTP.dll", "C:\\Windows\\SYSTEM32\\iertutil.dll", "C:\\Windows\\SYSTEM32\\DEVOBJ.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll" ] }, "imecfmui.exe-1526BBC215A76EACBF3563D02D166F8E": { "file_name": "imecfmui.exe", "file_path": "C:\\Windows\\system32\\IME\\shared\\imecfmui.exe", "hash_md5": "1526BBC215A76EACBF3563D02D166F8E", "hash_sha1": "6021ECB22408EF72198D98B3FC48FC535D1238A5", "hash_sha256": "EEF2EC581BE0420B5BF7E95373A7A183366A40A89DC05E32F835E5A9F38127D7", "hash_sha384": "A5A5ECAD642AA95F1223814087F59D69880C9216C21AC9E932FC9E8632CD245D028CD2FB0635023B20DEEC19F25261D6", "hash_sha512": "7483DE9DAE6A761990E775FD34AE8B23E9168EDC8A7F3028D948BAAFFCC9FAD7B3965E68D8224CAC2DDE26469CF7E2DEAF9A6B041C26915391C0E0129F247A68", "hash_ssdeep": "6144:wq+CpJui0Bjun7F8VXip88+lm0lT+Yi9EZgBk8SK0Q:w9CpJn2KuJiq8+lm05epS", "hash_imp": "46D68F12664897EF501CED0F4ECBC646", "hash_pesha1": "4F4C8ECB4BE1EC5058C1CE30BE1552B307D435E8", "hash_pe256": "8CAF4C4B4C04679DCE2D6CAA658987AD91D4AB11BE4253CB7B7DD946782E1769", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imecfmui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/eef2ec581be0420b5bf7e95373a7a183366a40a89dc05e32f835e5a9f38127d7/detection/" }, "IMEPADSV.EXE-3956DB588F443ECB1277EF532E304BF7": { "file_name": "IMEPADSV.EXE", "file_path": "C:\\Windows\\system32\\IME\\shared\\IMEPADSV.EXE", "hash_md5": "3956DB588F443ECB1277EF532E304BF7", "hash_sha1": "0BB25234A908B993DF387E7C900A99435379EB61", "hash_sha256": "8D0E4A6F790C7A3C9476AEF96DFA9FDDEC16B646E7F762B534D5019798C7F60D", "hash_sha384": "8C0B49BE743AF91B813A540970F8F768BCF0A7F8B1316734B17904279731E015C8691238DAF6CDA842391295DE60FA26", "hash_sha512": "F552C5F39E205C912C08F77818C5FDC2D0F81538C4D798B811A077A41FF395056261D2987AF38851EF75636AD18C31DA821211EB975613EC50BB106B9B7F307C", "hash_ssdeep": "6144:9A0XXM11x2fWw5Fy1QgJTbK2i4Q/qIFLgbbUz:DG1x2By+gJg40qC4K", "hash_imp": "00AF5A3A0946E3708BAF4B2FBEFD84E8", "hash_pesha1": "F600199E3F5F5C34CA805E551522A9A21AFD707E", "hash_pe256": "C1D6A5F6C4D6A78275F611E955D2F86183F5C1A5CE3ABE42625EB5A6573FC6F7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "Microsoft IME", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/8d0e4a6f790c7a3c9476aef96dfa9fddec16b646e7f762b534d5019798c7f60d/detection/" }, "IMESEARCH.EXE-E741F94C643B63429862E20E20D1E5C4": { "file_name": "IMESEARCH.EXE", "file_path": "C:\\Windows\\system32\\IME\\shared\\IMESEARCH.EXE", "hash_md5": "E741F94C643B63429862E20E20D1E5C4", "hash_sha1": "71C4772D9F69801CCE6912256C96B48CD214235B", "hash_sha256": "00392619A3D8FA5AD0090135B6D86A0B0CE94442C3EE0D143B6D1CE92C73A3DF", "hash_sha384": "838B0DF72539A34678790AC1D16E864C9312D286EDB8562610008650F5D4543E15717485617A955DEEAAB10F97B833C8", "hash_sha512": "AB860BE7332B2701EE3B9D40A23E99DFC4D0FACE96522ECBB2B2E64CBC0265DEBEAC181A1EB65E523F295419BCC5791C45B0839CBC6BA932EE9EFC4006DD5961", "hash_ssdeep": "3072:cbth8LNIhe/Jbp5NtIdhqZL+1gAiDtPaBRPl:9IMJl5Nt5ZLs0a/", "hash_imp": "21E0326B1B87512F97069C5D679A8DE6", "hash_pesha1": "8D71BDDDD85E74D9DBCB237D8C83768204AAE338", "hash_pe256": "44C352DD3461C59CF22DA99EBEC7E582E0EFA35F7B468D280D09A73582D74CD3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IME search module", "meta_original_filename": "imesearch.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "1/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/00392619a3d8fa5ad0090135b6d86a0b0ce94442c3ee0d143b6d1ce92c73a3df/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "(R-D) C:\\Windows\\System32\\en-US\\msxml6r.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\netmsg.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\shared\\IMESEARCH.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\msxml6.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll" ], "runtime_window_title": "Microsoft IME Search Provider" }, "IMEWDBLD.EXE-8B8C8F73B4E96963DD9A6E760C5F77DD": { "file_name": "IMEWDBLD.EXE", "file_path": "C:\\Windows\\system32\\IME\\shared\\IMEWDBLD.EXE", "hash_md5": "8B8C8F73B4E96963DD9A6E760C5F77DD", "hash_sha1": "71F3B5DA45334B704E5B738F442A5997A9EEC19E", "hash_sha256": "51E8741641C33D13908F3260BEE589871D5EFD9210504F7B4CDEEE50BAE17C2C", "hash_sha384": "3D57C2A6F93AB54849FC755C705B655C2B2F75D38B7DCEE95B5683751795FDB2C51890E677A7A376C3D90E153A4DB374", "hash_sha512": "31C97E1B37727CB5E1208CB468A4DF2BB9C1CBD7B31443B32BA4C0028DD221C386DEBF745639C4094C4C428E0D382145050F77D46A42EB399BC0FBF6CB366504", "hash_ssdeep": "6144:wDVtT8kSl4FnvSGrwuTUJD3PAfjHPPnsFGUPg7Gs/UEVTppNX+:wBd89iFaGrwuTiAfbaXPg7Gs/r", "hash_imp": "5D2E928CFCDF45D4BEE31908ADE49B06", "hash_pesha1": "941B69469AB7711F9796AE1957DD3D5C766C724C", "hash_pe256": "6CB60099DCEC6173E073A4FB505036B9A05E0FEE733CC76BEB57949FBD793E38", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME Open Extended Dictionary Module", "meta_original_filename": "imewdbld.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/51e8741641c33d13908f3260bee589871d5efd9210504f7b4cdeee50bae17c2c/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\IME\\shared\\IMEWDBLD.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\Cabinet.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\UxTheme.dll" ], "runtime_window_title": "Microsoft IME Open Extended Dictionary Error" }, "ChsIME.exe-C8BC76C87563E78C9BC85EE9F4F96760": { "file_name": "ChsIME.exe", "file_path": "C:\\Windows\\system32\\InputMethod\\CHS\\ChsIME.exe", "hash_md5": "C8BC76C87563E78C9BC85EE9F4F96760", "hash_sha1": "38D59451945F1C989D867E2CCE8E47979C833FCC", "hash_sha256": "A725999F72A036C2E84DB47FEB70F091246E71AC9AACB7B887F82EE3AF04D7B6", "hash_sha384": "EBD38468CD234A6B21D872ED0F301CFEC049FB9033C7078748F794A0AFBC537CD87FA14EFFC05DFDE52E5AB0897BA6DA", "hash_sha512": "24701CDDB0007EDFC01EC154D66067156C00E9BDB6CD7C7CD2348F42D367B87C4364133181A0F22582299035CF13CC5DACE89921ACF97B3D3D92D6EC5499EDFE", "hash_ssdeep": "3072:SzfkoirjjMs6v2CSO1JCIDGZl5/RxBfGreRIRe41BuCJoL+lV8lPHbV7ToM9sYvq:SzsoonMsSPCIDE5/RxPwoLgQP75oM6", "hash_imp": "D2954AB051E3494C0CB6FAB636221E07", "hash_pesha1": "656C51076747ED32D12C8F60A49E8FCA3E342B7D", "hash_pe256": "98DD44ACFCE6310004B8349AD557733EB5E85431E00209E2507C2D71AA0F8448", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "ChsIME.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/a725999f72a036c2e84db47feb70f091246e71ac9aacb7b887f82ee3af04d7b6/detection/" }, "ChtIME.exe-2C37EE45D5C0BA007BB78D7BFD9A656C": { "file_name": "ChtIME.exe", "file_path": "C:\\Windows\\system32\\InputMethod\\CHT\\ChtIME.exe", "hash_md5": "2C37EE45D5C0BA007BB78D7BFD9A656C", "hash_sha1": "DFDFE50EE67AF452DEB9141AD8F5A275C5EE5071", "hash_sha256": "E06A143A8A83337A3C76BCCA15F15594DA2CEEACEC0AAFBD3E8C74C90532E120", "hash_sha384": "2449363EFD8B7EE4F3A20615DBA409F5F7B4C80CB93E31FCF0DC9B4FFCD4DD9045BC6ECF5350309A582F380B15E7AC57", "hash_sha512": "A53D368F5182BD25914D406FE9B24E056421B9FCBE0C2B79FEAD86104B10D417B43111C408D1BDF357068867D43EE288DD5A8363BB798C33298C37F540E33F1F", "hash_ssdeep": "3072:wRSg466NsAFLl3FnAg25FcuU3jmoJ9+Pa1udAZ9VBa2W:wRb4hNNFLl4LUTl+aWUBa", "hash_imp": "9E87258FE3AAACAF4AA1366470B682DE", "hash_pesha1": "D1F91B8A9F8A2EC9277C5262D2029643D3F1CE77", "hash_pe256": "9CB35DF3C7C9E021C87C4C7F5F67697BA004EB55DFF7223001BE89A81D93B976", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "ChtIME.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/e06a143a8a83337a3c76bcca15f15594da2ceeacec0aafbd3e8c74c90532e120/detection/", "runtime_modules": [ "C:\\Windows\\system32\\InputMethod\\CHT\\ChtIME.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll" ], "children": "explorer.exe" }, "mighost.exe-91CFBA2810448592EB63F04A8E0C0805": { "file_name": "mighost.exe", "file_path": "C:\\Windows\\system32\\migwiz\\mighost.exe", "hash_md5": "91CFBA2810448592EB63F04A8E0C0805", "hash_sha1": "2D93E8CDC84F865924D24EA1A0C6785E9490162E", "hash_sha256": "03DC58AA00E5773631C70E11766FAD0B2E244798ADF706E0967F54AB05570C1D", "hash_sha384": "EEF812767A4014AF6FB105A7408F1AC52B632828433FF1C3019AD03F81CF83AEB35FAD3CD55CA2ECAE73BA6C9B71FFBD", "hash_sha512": "B51F510E985C33AEDA7308C16B4089234B54BB7CD57154F9C245D2569AEAD6161F79C329647ACDCC9AEDE71E2BD437291F35E906664FBD2C4C02A884EE0BEC9D", "hash_ssdeep": "6144:AYUW8Kw2pojDuUlMtq10Q8m7NNqM9N+hN1UFpfNS5iXjD56Gpovgp2H32nq54945:AYH86eDuUlEqatglsLb1", "hash_imp": "1A2E6FBE71CAA18E49B7AEBBC2EAC135", "hash_pesha1": "5CDC9CD3D0E384C9F57E480913A65B797FF77E05", "hash_pe256": "9F5730A2040626C56989803579179EC2DD5F059B600C55D986590AFF12F1A944", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Migration Plugins host program", "meta_original_filename": "MigHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/03dc58aa00e5773631c70e11766fad0b2e244798adf706e0967f54ab05570c1d/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\migwiz\\mighost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\WDSCORE.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll" ], "runtime_window_title": "MigHost.exe" }, "audit.exe-0DEAC8D84F1220F2B220EDB1AEFEAF0B": { "file_name": "audit.exe", "file_path": "C:\\Windows\\system32\\oobe\\audit.exe", "hash_md5": "0DEAC8D84F1220F2B220EDB1AEFEAF0B", "hash_sha1": "51545E0074A28F1B8EB4EECCE17289801E016D5C", "hash_sha256": "EC9F9F6E77F243ED783819194D2CB88EC6E64BD6696CA49CA4227F763CB9CAD3", "hash_sha384": "CC38637718566D0F3E4BF5E8973DA7246E67B812B28ECC2B771DEEE74B1C21A337BA8A19901714CE7AAE8F11F0CEF9A0", "hash_sha512": "A1B728A6F9D24CBDE93E400152160BCD3111110AE69DE6D468B0658AE47807DB3D2F3D720317A34667BBE9A7E082BF88277E6C6C655EE1153A1C813F2B3CBE9C", "hash_ssdeep": "1536:+bwDgtMA/s8BW2jHFw91TBbIPiJZVNmvEEL:+EEtMGs8B1jHFw91TBbdkt", "hash_imp": "96EFEAA0CC7415C0B7F3055DAD541001", "hash_pesha1": "4DF83D28BD8D4CCBE6EDF7791711FADBC10534B8", "hash_pe256": "132491D15CA8816DC180D52093D6EBC926D220CC187D809A8A04848431BC29A0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Audit", "meta_original_filename": "AUDIT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "children": [ "csrss.exe", "wininit.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\SetupLogSection": "Section", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setupact.log": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setuperr.log": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagerr.xml": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagwrn.xml": "File", "(R-D) C:\\Windows\\System32\\oobe\\en-US\\audit.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\oobe\\audit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\UNATTEND.DLL", "C:\\Windows\\SYSTEM32\\ActionQueue.dll", "C:\\Windows\\SYSTEM32\\samcli.dll", "C:\\Windows\\SYSTEM32\\netutils.dll", "C:\\Windows\\SYSTEM32\\wdscore.dll", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\SYSTEM32\\dbgcore.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\TextInputFramework.dll", "C:\\Windows\\System32\\CoreUIComponents.dll", "C:\\Windows\\System32\\CoreMessaging.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\SYSTEM32\\wintypes.dll" ], "runtime_window_title": "Install Windows" }, "AuditShD.exe-2404E60A42629FD1242DE3EE440C9AB0": { "file_name": "AuditShD.exe", "file_path": "C:\\Windows\\system32\\oobe\\AuditShD.exe", "hash_md5": "2404E60A42629FD1242DE3EE440C9AB0", "hash_sha1": "99C7BCC0B11FD49FE90EBFEAA42DA75DE2CD7873", "hash_sha256": "AC9284E17FEB93F313FA31B5B62CF6E6743F0DF3797C3D513E6FD3E55382115F", "hash_sha384": "DB6BC6BA6F9AACC251B9174CE504FC1072C38F2D583267AF24AB2EC2CDEFB7CAECD1BF8BD3B33F3D4C1581ADD2296FF2", "hash_sha512": "73CFFE43D1E516AE256B5A6E8BA8B45BD7B29CA00EBA7752D2B9B7E845C2B091FC1547C8B42411C10D62A42929E7E4134AAF5BDA4F2D23B0CD422F046A1D4CFE", "hash_ssdeep": "384:j/5LaX/4UEmZrsu/ZoajJGDuyHWBSTe0nEkKhGwOr3fpgHuWGfErnUoskBR4ogg+:xagKrswVeGS/Do4ojPvX", "hash_imp": "07BD07129FA2DAD62B0A7258CB241DE5", "hash_pesha1": "2AE4068034B90DA4440CEDA2D1DD5EB9C01EDF86", "hash_pe256": "E95CF725FD50C456D4C5B53FBEA41DDA48A9D8109123FDFDBF54B30FD26C32B0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Audit Mode Desktop Switch Utility", "meta_original_filename": "AuditShD.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/ac9284e17feb93f313fa31b5b62cf6e6743f0df3797c3d513e6fd3e55382115f/detection/" }, "FirstLogonAnim.exe-6DD5ECC82E9118B2DE1CAE3B35550E14": { "file_name": "FirstLogonAnim.exe", "file_path": "C:\\Windows\\system32\\oobe\\FirstLogonAnim.exe", "hash_md5": "6DD5ECC82E9118B2DE1CAE3B35550E14", "hash_sha1": "58EA81C9FA4D4557DE4251836D0CE9BF094167B5", "hash_sha256": "7FB56536D846405D6B9BE71BC8BC485E01B54AA336AC9A6BE47ADFE7410D2B2C", "hash_sha384": "3F4034E63F19AFBF5B50F90B9491AB40E1F14507B97635DB5B61DAACA03993FA4251328F445E00B1E1118100CD41B5A2", "hash_sha512": "89BEB989D97FE2BAB724C7B52FB4DCEE1BFACD73A627AA66AAE5E9C2C372EE708A268ED0AC5AF56F21657368E32A61F5045C8347E17CDA5C510467DE73434BB0", "hash_ssdeep": "384:upoTBN5OpgYcv9oZNeWMxWpmXjDBRJRhlImCCA:SEBFYaoZNM1Xj1PRN/A", "hash_imp": "3803F409406CF069F54F47AB8EC15EF4", "hash_pesha1": "49AF34337625EADB7378ECBF318AFCA0F025F1D9", "hash_pe256": "E23E78E024CAF89E30DE3F7BC47906F90016F787A2354C64A4C74BE5D04E3010", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "First Sign-in Animation", "meta_original_filename": "FirstLogonAnim.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/7fb56536d846405d6b9be71bc8bc485e01b54aa336ac9a6be47adfe7410d2b2c/detection/" }, "msoobe.exe-A1C5AE013FA1BB8BBE2D2FCA6BA28341": { "file_name": "msoobe.exe", "file_path": "C:\\Windows\\system32\\oobe\\msoobe.exe", "hash_md5": "A1C5AE013FA1BB8BBE2D2FCA6BA28341", "hash_sha1": "E1DD6912C08B25A9CA47C8F18A22FA2CBE603E87", "hash_sha256": "82DFDA730AF302A9AF30CF61F74B6A3976D9B3BDE8C49C54632C566DEDCD69E9", "hash_sha384": "C7C01BBB7D50C28C69939FCE27CB00AC6B6B091503BA2909623F20EDDADFB89C6769538F02E5C0FEA97A937F645622A9", "hash_sha512": "A08F958DC7CD786F4E7CCA0F9F737C3491C95C177F333DE40B1A53E46574E3969E758516054270CD6F74C4A8F3195D90CCD02EAF1D7A254870DCD20CA4B48289", "hash_ssdeep": "3072:YeJG4KYZ8+SXycMvEXCfklBBukUypu+GdAVxenrhDjyB2oB:YejhZ8+cyTvlclikyXdNtDjyB2", "hash_imp": "80729D39F118E94694BE0E4AAECA042C", "hash_pesha1": "C5BE9795DC1E40A4D5F67A71C3FF598110BF6439", "hash_pe256": "AF892C01C2D33181F4D665AEEDF1F0B47E2F2B7CA7B2DFC8F25188E1B5F557AB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MSOOBE EXE", "meta_original_filename": "msoobe.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_window_title": "Set up Windows", "children": "FirstLogonAnim.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\BaseNamedObjects\\SetupLogSection": "Section", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setupact.log": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setuperr.log": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagerr.xml": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagwrn.xml": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\input.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "\\RPC Control\\DSEC8A4": "Section", "(R-D) C:\\Windows\\System32\\oobe\\en-US\\msoobedui.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Windows\\System32\\en-US\\profext.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\oobe\\msoobe.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\MsCtfMonitor.DLL", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\SYSTEM32\\MSUTB.dll" ] }, "oobeldr.exe-30B8229A7C3990862504B2F2D62B92FB": { "file_name": "oobeldr.exe", "file_path": "C:\\Windows\\system32\\oobe\\oobeldr.exe", "hash_md5": "30B8229A7C3990862504B2F2D62B92FB", "hash_sha1": "7B5E834FE9F657F68A9D28D9D5BA6D9B5097E977", "hash_sha256": "741557D1144AF05A7445F95EE200EA772BDF8C50D2C9798604B1D322FA24E87F", "hash_sha384": "36BD1D03755A430D0545FE5C3554B87F43032B15C3DB311EA139404337568C66A9F321D7F31BCEECA58D0E0651B9FB10", "hash_sha512": "B28ABA490C938716F282D1BD456EC4E3CCD52116530F2D909CF55FB457C7FEA9F9DEAFB8ED01A49DE85C02B7A4C6B19CA65360ABA21841FC2A37FBD3E4FC4C27", "hash_ssdeep": "1536:TFL33dtnZnQ6RY8FObvKxZVnVS88ol9SBv:53NtnZnQ6RNFObvKxZ9V5fXG", "hash_imp": "7F3D5A75E06A11A6C201C558F8DEDAE3", "hash_pesha1": "5DFEDE2EB99AEF37A790AF4C893F660168246BDF", "hash_pe256": "AA6688F08CB2D7E219D49F9F108F3D6238F78EFB9D38FE90440030BBDE840555", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "OOBE Loader", "meta_original_filename": "OOBELDR.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_window_title": "Install Windows", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\SetupLogSection": "Section", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setupact.log": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setuperr.log": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagerr.xml": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagwrn.xml": "File", "(R-D) C:\\Windows\\System32\\oobe\\en-US\\oobeldr.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\oobe\\oobeldr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\UNATTEND.DLL", "C:\\Windows\\SYSTEM32\\ActionQueue.dll", "C:\\Windows\\SYSTEM32\\wdscore.dll", "C:\\Windows\\system32\\dbghelp.dll", "C:\\Windows\\SYSTEM32\\dbgcore.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\TextInputFramework.dll" ] }, "Setup.exe-76BC388FC9021985BC478C9B101649C6": { "file_name": "Setup.exe", "file_path": "C:\\Windows\\system32\\oobe\\Setup.exe", "hash_md5": "76BC388FC9021985BC478C9B101649C6", "hash_sha1": "B770FA55137CA25568DF981356ECC415B12CBC76", "hash_sha256": "5ED119F1AFF65F89B4A0368FDB005E589152B3E08A64A0CBB7B082A02015E63F", "hash_sha384": "BA95A59E1F5A323733E08E477CA39213BDE03250010E9BAA20A331D0A1811B0FC1C073E5C2B197B5BF459032FE00F4A3", "hash_sha512": "713872534F8473C2996585B3359BBCD293A4CB3F798F0ACA150EBAAF1B9E66F15FDBDDF3BFEA7B22B5DF01EE5605994E8CB386C2AB2F939E5869DF3C1ECBA36B", "hash_ssdeep": "6144:lUQB61dHkvKHcXHDARu/RdJP7VA6HtzhQXJgzBU4GfjTI:lUN1dE8mjfRHHag1", "hash_imp": "3CEE34234FE6747E9A48559BC10D342C", "hash_pesha1": "430CB106F476013444B386B3700EE0544A356CCF", "hash_pe256": "54E6D27E11F343F31EF3D8812C391AEB0DCE1938F3714E0DF2175B6554B4D1DE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Installation and Setup", "meta_original_filename": "SETUP.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\oobe\\en-US\\setup.exe.mui": "File", "(RW-) C:\\Windows\\System32\\oobe": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\oobe\\Setup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll" ], "runtime_window_title": "Install Windows" }, "UserOOBEBroker.exe-EB2151FD79952B53F83A3AF9D7F15AA7": { "file_name": "UserOOBEBroker.exe", "file_path": "C:\\Windows\\system32\\oobe\\UserOOBEBroker.exe", "hash_md5": "EB2151FD79952B53F83A3AF9D7F15AA7", "hash_sha1": "C34058945789CD4322214516772519A3A45F652F", "hash_sha256": "F66C11D32206E0B26CDD2A70B103A18585E59CB1A16020B8A4B6FBCCCE131AC4", "hash_sha384": "424CFF9DBB3B4A9CACBA6BB928B3C48087A078D422AFFDC92AE50966B6DBCFA4A7DB2F31BA8D3CA09F08F095D4171AC5", "hash_sha512": "42FDE07AD1E0E8235629DED6183E80B1764373C33A1F2EA44CBD5E7D5D8AAA934C219E010A221399FD15028A0D58B2FD1EE439E68305151E044B039909689CB6", "hash_ssdeep": "1536:Q5f6mOEJxfUl+RJ9pdkumPQ+rku28ZyGWim+V:QtK+RDlmI+rF2VRO", "hash_imp": "B7B03D63E43E0414A3D42BA134F12296", "hash_pesha1": "695D9FB6C28AFE1C63F8CC873F35A60B077432F2", "hash_pe256": "BF305740D5FF9FC571D58D9AF16DC1A712611DDF8CFE9F80AEBF71F66C196FAB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "User OOBE Broker", "meta_original_filename": "UserOOBEBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1457 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1457", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC134C": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\oobe\\UserOOBEBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll" ] }, "windeploy.exe-145E50EC9804AA8B8AE1DB12D5F012DA": { "file_name": "windeploy.exe", "file_path": "C:\\Windows\\system32\\oobe\\windeploy.exe", "hash_md5": "145E50EC9804AA8B8AE1DB12D5F012DA", "hash_sha1": "8C22E464A1643B711D6D7F27B4B1DD7DDBB9C507", "hash_sha256": "ED50056744B459A7DE66275C152967FB4919105FEFD51C96D018DE2F68C1272B", "hash_sha384": "153BC3A5C291DC875756D9C4D0776295BFCD92A127785D202E36371E61CC7BA34EF69E01A1B56585F86CF20D1F445001", "hash_sha512": "6ECABB10C12E97BB5D0E3EFA1D65E1653D2A4C4D713DA55903E22A06B3294BB301A8FB3AA2BD74B5AD688A5BFB8DCC9E00CBDA64B6051D06C336298FE19F7659", "hash_ssdeep": "3072:EWcxz1Nk0m2n0FN5Eb9nirGWxfT0+e/aKu8/KD4ds59iW:rEw3LQx1WxfT9BD4dV", "hash_imp": "8B8C86E394E7C5381921CAB6944577AF", "hash_pesha1": "ABE2B6A86327C0F75759CF3B9B893D7879831951", "hash_pe256": "5396EDA65C345E471E55112D00418264B13E50B22847D0181D2B2B2F86DEEBC4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Deployment Loader", "meta_original_filename": "WinDeploy.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/ed50056744b459a7de66275c152967fb4919105fefd51c96d018de2f68c1272b/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\oobe\\en-US\\windeploy.exe.mui": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagerr.xml": "File", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setuperr.log": "File", "\\BaseNamedObjects\\SetupLogSection": "Section", "(RW-) C:\\Windows\\Panther\\UnattendGC\\setupact.log": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\Panther\\UnattendGC\\diagwrn.xml": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\oobe\\windeploy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\bcd.dll" ] }, "SpeechUXWiz.exe-12BEDBBE10C9281CADB3A1CE54F716E5": { "file_name": "SpeechUXWiz.exe", "file_path": "C:\\Windows\\system32\\Speech\\SpeechUX\\SpeechUXWiz.exe", "hash_md5": "12BEDBBE10C9281CADB3A1CE54F716E5", "hash_sha1": "FB12317DB697CDB124BF887AFF5FD432BF766ED3", "hash_sha256": "EC39F8FDBDA62DC70392D7EFFF271FD189C087336DC716E51ABAE888CAEF5A32", "hash_sha384": "E78D7676FAD475A2B5BAF5096D4A4C5369474EE7A2A7524E496797346B4C70483C2D31914AEBDF8C285EAF8AC689F7D2", "hash_sha512": "669703BCF5CFC8CD4E233C1A3703C211CE6E381ED213375F336D839EFD605B284263A5F2FCE429E27AED0331E289234A562ACA760BDA1AB4A7732E69F6F11CAB", "hash_ssdeep": "12288:7V4uURvVDA75nRr08YbVe0TIrf8NbywLkRLgLBAgV:54ub75nRo82VLTIrfMy8oLg", "hash_imp": "D707EC2D8BBC3B3E102C7CE118F1E271", "hash_pesha1": "E8A363987FD851F95DBA525FDC3D19D000BA3B7A", "hash_pe256": "ECF8409D267299582E7826D39F412CD4F15DB6DFFB4CA45D502119EA42BA3DE8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Speech UX Configuration", "meta_original_filename": "SpeechUXWiz.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/ec39f8fdbda62dc70392d7efff271fd189c087336dc716e51abae888caef5a32/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\Speech\\SpeechUX\\en-US\\SpeechUXWiz.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\shlwapi.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Speech\\SpeechUX\\SpeechUXWiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\DUI70.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\wer.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll" ], "runtime_window_title": " " }, "SpeechModelDownload.exe-3FD687E97E03D303E02BB37EC85DE962": { "file_name": "SpeechModelDownload.exe", "file_path": "C:\\Windows\\system32\\Speech_OneCore\\common\\SpeechModelDownload.exe", "hash_md5": "3FD687E97E03D303E02BB37EC85DE962", "hash_sha1": "03E6E81192621DFD873814DE3787C6E7D6AF1509", "hash_sha256": "963FD9DC1B82C44D00EB91D61E2CB442AF7357E3A603C23D469DF53A6376F073", "hash_sha384": "524BABCD001C16C7DAA2825C50EB7D39CC860D9BAAD99B81B9B3E974AD30DB0407B9D85D5F9EAA4F7C9C4A4D44513ABC", "hash_sha512": "7516ADB80DE90AB8DD911F7ABCB11DCB0D2416EB9DADCE2008B5DA52D27BE595D5F60FE0EAAEB37A0D2EB7AADB825014A241B678FC2874511BE5A0487E5E1B78", "hash_ssdeep": "3072:pGw4YdI0jD0GKJPgdU5F0+BKHIVBIzsazlSmS8zaS650xKUk:pGw4SLK96Uj0iKoXNQlTuAb", "hash_imp": "23BD5F904494D14029D9263CEBAE088D", "hash_pesha1": "215CC77FAFF74D39BBEDF03232587158786887E2", "hash_pe256": "A761B1C097E62BEB252A56B49561D69D9055DB5F18763DD8C20DED6F476935E7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Speech Model Download Executable", "meta_original_filename": "SpeechModelDownload.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1369 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1369", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/963fd9dc1b82c44d00eb91d61e2cb442af7357e3a603c23d469df53a6376f073/detection/", "runtime_modules": [ "C:\\Windows\\system32\\Speech_OneCore\\common\\SpeechModelDownload.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\msvcp110_win.dll", "C:\\Windows\\SYSTEM32\\policymanager.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\WINHTTP.dll", "C:\\Windows\\System32\\kernel.appcore.dll" ] }, "SpeechRuntime.exe-9D171724ACA980F853ABDAB2FFAA1432": { "file_name": "SpeechRuntime.exe", "file_path": "C:\\Windows\\system32\\Speech_OneCore\\common\\SpeechRuntime.exe", "hash_md5": "9D171724ACA980F853ABDAB2FFAA1432", "hash_sha1": "A43741867A2610DA4B719C5EECF02CDACF8932B8", "hash_sha256": "C3E4880ACE893EE607D4401179EE7920ED7D2116AB6BAC427E9F4C9160217F5E", "hash_sha384": "42FDF0E2CCF648EAF38198791571493DDD6E812FE249F669F501EDEFE001CF415F842C336662002D9E7C4C597D0FFF12", "hash_sha512": "C47F17BCC50D357AFD89038C28D4C1CB20D5C497450A6B5667FEC1F5A53C54B512D14D67FAB9984CF3BD37C0F2D2378370B39D90B6048EB6AEEEAF071B74726C", "hash_ssdeep": "3072:SUaK29Q2gAEYuHqB401d0j3hsz59mSysGDXQuI5v0jH3D5j+:TaKQgAETHqu01d0dsz59M5XQz0rF", "hash_imp": "669016FB58D5405A86AA730E56B9F0B6", "hash_pesha1": "1536C646AC1E48007D4E352317A3EDC9FDA4DE8A", "hash_pe256": "31BA69D3F853F870332C2224414AAE43D39AE704690BBE154EA2D582DEB83B92", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Speech Runtime Executable", "meta_original_filename": "SpeechRuntime.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1397 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1397", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/c3e4880ace893ee607d4401179ee7920ed7d2116ab6bac427e9f4c9160217f5e/detection/", "runtime_modules": [ "C:\\Windows\\system32\\Speech_OneCore\\common\\SpeechRuntime.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\msvcp110_win.dll", "C:\\Windows\\SYSTEM32\\twinapi.appcore.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\MMDevAPI.DLL", "C:\\Windows\\SYSTEM32\\CoreMessaging.dll", "C:\\Windows\\SYSTEM32\\RMCLIENT.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\DEVOBJ.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\Speech_OneCore\\Common\\sapi_onecore.dll", "C:\\Windows\\System32\\POWRPROF.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\SYSTEM32\\urlmon.dll" ] }, "PrintBrm.exe-D3BB8D39A9E5E574DE869AAC80E93433": { "file_name": "PrintBrm.exe", "file_path": "C:\\Windows\\system32\\spool\\tools\\PrintBrm.exe", "hash_md5": "D3BB8D39A9E5E574DE869AAC80E93433", "hash_sha1": "5A65531FCF201369D6DF40EA592A66ECFFFF2BF2", "hash_sha256": "71B5F4AA8D12DD4B7982B2D5607CB9B5F40C7E7676DC36F2AEEB482561117251", "hash_sha384": "30F6DC186126B4F93C28D8969F5065DC9D1C32CE4C6C5469C32C796BCB57BA2E86875B5764B8B8B252AF242FB4EB6F3F", "hash_sha512": "DB1C1D99EEF0A9262CEFB4824863101BB3F9B6698A026729146E7388B0675578D223E78006C1898E14B1AC766ED035174D2B019DC9D560E5E358F8199361FC00", "hash_ssdeep": "384:J6MYdFEU63Tj32q4gKX52R1XueGLujZYJQ7zRMjHJKqDT1n+0SNxTY/OlVufVXhm:4OU6j7tOJ2CI9rxapVDTuNh+Oryx3a2/", "hash_imp": "C41B1537E18BBD1DFB2420E52994CAEF", "hash_pesha1": "123EF9F6F8E075CB38E43E6B991782F935DCC1C5", "hash_pe256": "06FD8CB7E9075B10554E557B7547A8B531CEFA681DE1418DE722E5F5324A8150", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Print BRM command line tool", "meta_original_filename": "PrintBrm.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/71b5f4aa8d12dd4b7982b2d5607cb9b5f40c7e7676dc36f2aeeb482561117251/detection/", "output": "Error: A single mode must be selected!\n\nAccess the Backup Recovery Migration tool through a command line interface.\n\nPrintBrm -B|R|Q [-S <server>] -F <file> [-D <directory>] [-O FORCE] [-P ALL|ORIG] [-NOBIN] [-LPR2TCP] [-C <config file>] [-NOACL] [-?]\n-B Backup the server to the specified file\n-R Restore the configuration in the file to the server\n-Q Query the server or the backup file\n-S <server name> Target server\n-F <file name> Target backup File\n-D <directory> Unpack the backup file to (with -R) or repack a backup file from (with -B) the given directory\n-O FORCE Force overwriting of existing objects\n-P ALL|ORIG Publish all printers in directory, or publish printers that were published originally\n-NOBIN Omit the binaries from the backup\n-LPR2TCP Convert LPR ports to Standard TCP/IP ports on restore\n-C <file name> Use the specified configuration file for BRM\n-NOACL Remove ACLs from print queues on restore\n-? Display this help\n" }, "PrintBrmEngine.exe-82C5CCB9C24982ADDC3369AE67D22F48": { "file_name": "PrintBrmEngine.exe", "file_path": "C:\\Windows\\system32\\spool\\tools\\PrintBrmEngine.exe", "hash_md5": "82C5CCB9C24982ADDC3369AE67D22F48", "hash_sha1": "0E74E51A702056CB52DC4E525F694913A3A4A6BD", "hash_sha256": "B45E80D042BD7F45FFCE382F7C299A22EE480E066CD40F971C40D96CD78C85EB", "hash_sha384": "A81CB0ADC9BF5E2742DEE0C92A66251A5916424C8AC887D96B0B1103CEE6ABB2E8DCE2B5E8BEACEA3020578288C1BB44", "hash_sha512": "14CAA14E407792840E1228FC124D6421BB298CB2C821D5A178355926C90BBDC2074F14A51E8B13BEF0CB3118C1727164D18B54887E52C825AA7F62684E205040", "hash_ssdeep": "6144:kul742ilvXbVIISJ5YPwLhxOSNAvdn7Kltc:Nl7ClvbVIISXmwLhkSNA17Klt", "hash_imp": "7B4A0F411CD34A08A69BAB9D0217D8BB", "hash_pesha1": "F051972D3B23E4C141A4253B169393077A7882DD", "hash_pe256": "FDB1536F2B7BF7FCEF566FB012B660F1BFFF0C6C04BCE5B1BD07FF1036CAFA8D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "PrintBrmEngine EXE", "meta_original_filename": "PrintBrmEng.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\spool\\tools\\en-US\\PrintBrmEngine.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\RPC Control\\DSEC10CC": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\spool\\tools\\PrintBrmEngine.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\SYSTEM32\\NETAPI32.dll", "C:\\Windows\\SYSTEM32\\mscms.dll", "C:\\Windows\\SYSTEM32\\WINSPOOL.DRV", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\CLUSAPI.dll", "C:\\Windows\\SYSTEM32\\RESUTILS.dll", "C:\\Windows\\SYSTEM32\\Cabinet.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\SYSTEM32\\ColorAdapterClient.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\SYSTEM32\\SRVCLI.DLL", "C:\\Windows\\SYSTEM32\\NETUTILS.DLL", "C:\\Windows\\SYSTEM32\\DNSAPI.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\clbcatq.dll" ] }, "sysprep.exe-C22F1DE66E08A5B405C8F0615A4D262F": { "file_name": "sysprep.exe", "file_path": "C:\\Windows\\system32\\Sysprep\\sysprep.exe", "hash_md5": "C22F1DE66E08A5B405C8F0615A4D262F", "hash_sha1": "5D2A254E3945BE583E819D65A8D6D5F46D2ACC5F", "hash_sha256": "F5CFD1631D2DFE7C2E4BAC631374CC793179C1D3757801B4BCA9C77E9A3FCFBB", "hash_sha384": "1A7941B86ECD5590DFE3371B774FB9CECC442933874BE11473D2CCE25793BD2DC0198D193655FC0921B700D85876401E", "hash_sha512": "429810D619EB261AF41965F70BFEDAE5F6929AC46E5D46B99A1C25803718AF252A48D0562B7C9075CEB3F605B90FF1DA285091E0074BAEF6B6CD5640BC5861FE", "hash_ssdeep": "12288:9F3KCOg79hKXPRKuabsG7o++Q6DLg2APKiCtxbyvfnxlmfcSEOe1yvU:9B/OgxhgPRKxbNjYpzbyvfnxlMrEOeV", "hash_imp": "1CA114DF64828C5F35E8777BF42AC360", "hash_pesha1": "8352E0D7492E281BB6401571A94D90547A981AE3", "hash_pe256": "A45794B6BB7BA7F023C4293D447EEBADC0CE14992C9CB5E31F22A20823BA8556", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Preparation Tool", "meta_original_filename": "sysprep.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\Sysprep\\en-US\\sysprep.exe.mui": "File", "(RW-) C:\\Windows\\System32\\Sysprep\\Panther\\setupact.log": "File", "\\BaseNamedObjects\\SetupLogSection": "Section", "(RW-) C:\\Windows\\System32\\Sysprep\\Panther\\setuperr.log": "File", "(RW-) C:\\Windows\\System32\\Sysprep\\Panther\\diagerr.xml": "File", "(RW-) C:\\Windows\\System32\\Sysprep\\Panther\\diagwrn.xml": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\Sysprep\\sysprep.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptprimitives.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\XmlLite.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\system32\\actionqueue.dll", "C:\\Windows\\system32\\unattend.dll", "C:\\Windows\\system32\\wdscore.dll" ], "runtime_window_title": "System Preparation Tool 3.14" }, "SystemResetPlatform.exe-C690F0C2909BA39276AE43C5F012FBB5": { "file_name": "SystemResetPlatform.exe", "file_path": "C:\\Windows\\system32\\SystemResetPlatform\\SystemResetPlatform.exe", "hash_md5": "C690F0C2909BA39276AE43C5F012FBB5", "hash_sha1": "817FFFECBBB701B081DA082A9CFFB9155CD5B4FD", "hash_sha256": "1F1599817CF846587E419C2C121D66AE33D4B3201A677B6FCCD9754E61E2CD60", "hash_sha384": "1EBD6B4D5F56AEB0806D1220DCAE1153EFAAEC4B0D878B19CFD48FF82BDE6886DA2951D8036B9C238A65053CD419336A", "hash_sha512": "DCA7B028F04439A21169D2BE10A6D707DCCB29A3812D9402147B97F732D70DECD5D319D439C569902D406453CE3523AB8BA4E6D848EE7871926F50E03164C64F", "hash_ssdeep": "192:ubaDyeCriN2OBMTDg9lAkhN7cTVN19GUGvCy2WuSW:mEGu1ifylzhcPGURWuSW", "hash_imp": "E058437B06D0330796EF05165724B390", "hash_pesha1": "1D681EDCA2ACB2ECAFF45BE400699950CFC914AF", "hash_pe256": "B203D8EA0BC4398BF295143468F9AF4560F8D533D7213933F262CF3C1B2737D0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows System Reset Platform", "meta_original_filename": "SystemResetPlatform.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/1f1599817cf846587e419c2c121d66ae33d4b3201a677b6fccd9754e61e2cd60/detection/" }, "mofcomp.exe-5D4918AD2054B0BA69E760BEA2F551DB": { "file_name": "mofcomp.exe", "file_path": "C:\\Windows\\system32\\wbem\\mofcomp.exe", "hash_md5": "5D4918AD2054B0BA69E760BEA2F551DB", "hash_sha1": "55C41854AB4096CC0526A056768E0CAB59BAEA6B", "hash_sha256": "EC049A032436A2BD31491AEE3BF054AAE9D63B24282186F208D93A4CF4C946C9", "hash_sha384": "B1157E620713AAF715598C3D6C4403C2460B8DF1BB23C746FE2311371D509E673925CA53779ECF51D2D135CA140CB3B4", "hash_sha512": "458D2C1B2BBB28300B627D80A6358E7B6B38E28143E6193E5DFF99D647A094EC562B303B850583EFDE59A842B679EDA71475FE7D46A1E97DEFF2C7D2BCDDE710", "hash_ssdeep": "384:h0Muz/PafIvOMvK+bsxGrsM1tBm66loHKc0x0NvoahE/djiW1oW:g2fIvOMv4xcBGkp0x0Nvoa6/5x", "hash_imp": "4BDF4258DBC932662B0ABC3DFBD4A0C3", "hash_pesha1": "F178DB7E50A9359BFDFE9A6A32492371DCD7EA26", "hash_pe256": "0965FDC4AD2F543C4BC39C55415377BDB8BD422D5C50E6EB9B7D11DE342ABFE4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "The Managed Object Format (MOF) Compiler ", "meta_original_filename": "mofcomp.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/ec049a032436a2bd31491aee3bf054aae9d63b24282186f208d93a4cf4c946c9/detection/", "output": "Microsoft (R) MOF Compiler Version 10.0.17763.1\nCopyright (c) Microsoft Corp. 1997-2006. All rights reserved.\n\nusage: mofcomp [-check] [-N:<Path>]\n [-class:updateonly|-class:createonly]\n [-instance:updateonly|-instance:createonly]\n [-B:<filename>] [-P:<Password>] [-U:<UserName>]\n [-A:<Authority>] [-WMI] [-AUTORECOVER]\n [-MOF:<path>] [-MFL:<path>] [-AMENDMENT:<Locale>]\n [-ER:<ResourceName>] [-L:<ResourceLocale>] \n <MOF filename>\n\n -check Syntax check only\n -N:<path> Load into this namespace by default\n -class:updateonly Do not create new classes\n -class:safeupdate Update unless conflicts exist\n -class:forceupdate Update resolving conflicts if possible\n -class:createonly Do not change existing classes\n -instance:updateonly Do not create new instances\n -instance:createonly Do not change existing instances\n -U:<UserName> User Name\n -P:<Password> Login password\n -A:<Authority> Example: NTLMDOMAIN:Domain\n -B:<destination filename> Creates a binary MOF file, does not add to DB\n -WMI Do Windows Driver Model (WDM) checks, requires -B switch\n -AUTORECOVER Adds MOF to list of files compiled during DB recovery\n -Amendment:<LOCALE> splits MOF into language neutral and specific versions\n where locale is of the form \"MS_4??\"\n -MOF:<path> name of the language neutral output\n -MFL:<path> name of the language specific output\n -ER:<ResourceName> extracts binary mof from named resource\n -L:<ResourceLocale> optional specific locale number when using -ER switch\n\n Example c:>mofcomp -N:root\\default yourmof.mof\n", "runtime_modules": [ "C:\\Windows\\system32\\wbem\\mofcomp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\wbem\\mofd.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\system32\\wbem\\wmiutils.dll" ] }, "scrcons.exe-AE2951B6F89CAD07E48A8C2C4097243A": { "file_name": "scrcons.exe", "file_path": "C:\\Windows\\system32\\wbem\\scrcons.exe", "hash_md5": "AE2951B6F89CAD07E48A8C2C4097243A", "hash_sha1": "2F88A2A21F4A40600EE3ED6B7D8D10B62CFEF7AB", "hash_sha256": "2C91F17DD33E78430451D47F2E26715EB6E1FD8125E530182EC0CACEB4CD755F", "hash_sha384": "D0D746A6089D6D33C76749110630656536984B55D95ED843149E43C34EF827CA7BDD9A7084E11E36A9A625C30DF383A6", "hash_sha512": "B744E20E86C61B84FC1BDDD72F81E080B2A1399CB748F6767D4F563974607249A7FFEC640240A7C87852FBEECDC6314638D149D4A7133D203519E292C93491EC", "hash_ssdeep": "768:Wnc2NqrHdzJRSnc+N5QM78l/r70SA/pyf51Gk1Oxju+nzFSTIT+4i/qKVTPnyo:e5yw+w8pr70SAQf51R1OVu+nzFAnyo", "hash_imp": "33D9F246D162F5E1E1312E28E566A69E", "hash_pesha1": "83872FBF9C0123F03166DFEA1869362849F3E754", "hash_pe256": "A8685B0C5C2688B34E77F45E854DE63F04132C736252077EC40B02A907CDD229", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Standard Event Consumer - scripting", "meta_original_filename": "ScrCons", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/2c91f17dd33e78430451d47f2e26715eb6e1fd8125e530182ec0caceb4cd755f/detection/", "output": "Cannot run standalone\r\n", "runtime_modules": [ "C:\\Windows\\system32\\wbem\\scrcons.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\wbem\\esscli.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\system32\\wbem\\FastProx.dll" ] }, "unsecapp.exe-8B0E699F01BDD3B9AD741D1BD7343248": { "file_name": "unsecapp.exe", "file_path": "C:\\Windows\\system32\\wbem\\unsecapp.exe", "hash_md5": "8B0E699F01BDD3B9AD741D1BD7343248", "hash_sha1": "BA0B729D2E78D533DFC771238F1BF8188D2DB2BC", "hash_sha256": "8095D4D7726438F8665E00C1A405AB94DB6358DC14740783795CF8617A64F19E", "hash_sha384": "330F3C4E9F8A4D15A435C6B113F8D96BA8A61DE979261433385B26E5F6118150C03BBC1F5B92EBD0804AB70EFD2A55F8", "hash_sha512": "699B796C26DE15D4017CD5156431BD392A591BEB6ACDD2A692C5982E0140173D67ADBE39320C0580B1BC2F1E12C975ED7F23B2D3DF975C617FBBAE033AF80602", "hash_ssdeep": "768:UGq5NFAcMTnRsAvQCo1CLImfqTgzjKPH+15jf520AfSHIT+4OX/L+kKVBfu:UGAFMLSmQmImfegzjUH+1tf5LAfo+fu", "hash_imp": "9E0E0DA3FF0E183298AEDC6F7ECB7E05", "hash_pesha1": "921B609CBF6FCAB16D07C036C394E5A5E7A49DAA", "hash_pe256": "2853A942EADCAC74FE5C1222787F117CDCB024BC905C2839F826F718441DBD06", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Sink to receive asynchronous callbacks for WMI client application", "meta_original_filename": "unsecapp.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/8095d4d7726438f8665e00c1a405ab94db6358dc14740783795cf8617a64f19e/detection/", "output": "Cannot run standalone\r\n", "runtime_modules": [ "C:\\Windows\\system32\\wbem\\unsecapp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\WS2_32.dll" ] }, "wbemtest.exe-7191ED192D1E26E50B671C2AAD99D451": { "file_name": "wbemtest.exe", "file_path": "C:\\Windows\\system32\\wbem\\wbemtest.exe", "hash_md5": "7191ED192D1E26E50B671C2AAD99D451", "hash_sha1": "09F44936A472D838AC78BD4B87AB6454C05E3152", "hash_sha256": "3406B6ADF7D5BF8D7B75C9761B9BA24D1DABA8EE00BC5D014FE947B2DC0423A4", "hash_sha384": "5CC6E2B7919594CFDCF946F43BEBE9FA959E37E7879F748226F755D3BF6B63EE1F21F8AF3FAE52D9A4A05FE5A0FBDAB9", "hash_sha512": "BD92E3C4181F2ADDF4F8C37454B9AC516EABA9288DE48F1AD3BE3EAD8766B6B6A62912251CC507E9ED5F0751896E1A0EC5EC558E5ADC726A80EED3CF6FC9C6FF", "hash_ssdeep": "3072:g/UskdhY3KILrzFHS1r5GMezOhflHwEwgIcENsz8JirIz4TqGf5KhIPFJRAhP2Ey:g/UskdhYLLHFHSx5GMXdQU5bDeP", "hash_imp": "CDFDFC84E739873776D87479B9819CD0", "hash_pesha1": "4F43608B2D9A3DCED123ACB0770EBC95685F759F", "hash_pe256": "E4812DA33D352BB17EEA11DE8402DF98C086307098CAFC45623B8F0DEB9777E2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Test Tool", "meta_original_filename": "wbemtest.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/3406b6adf7d5bf8d7b75c9761b9ba24d1daba8ee00bc5d014fe947b2dc0423a4/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\wbem\\en-US\\wbemtest.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wbem\\wbemtest.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\WS2_32.dll" ], "runtime_window_title": "Windows Management Instrumentation Tester" }, "WinMgmt.exe-7EEBC2D73DB966BC35A8031FA60FC161": { "file_name": "WinMgmt.exe", "file_path": "C:\\Windows\\system32\\wbem\\WinMgmt.exe", "hash_md5": "7EEBC2D73DB966BC35A8031FA60FC161", "hash_sha1": "1CE5CC0376C2D939A56AEFD57465EA5D2E311DA9", "hash_sha256": "720A7ADB445F98C7A71F406711A4AFF6C0E3143AA18A12DF851B806D2D5B00FD", "hash_sha384": "7277500DC1EF5FF3C9D916AEA774E06C16FA6CBA22702BC09812171300C0DFF742D3218D1876B7D53754D23E39334728", "hash_sha512": "50F88D2093F0D9A3117B4C491AD58FF9E14341C9952385EF5160521938569EB93A46BD51700F193F64A38D17D7EE5C18A99ED948EB76FAFD8C677EC4DD141084", "hash_ssdeep": "1536:tX//E02UqhgvRdShIPoANJLlAXuSXv+qSFEAeOFt:omRshIPFJRAhP2EAeU", "hash_imp": "2C3AB885FA820ED6993A6974E34AA636", "hash_pesha1": "6FA978BB29316380B066BE6DA093C7EFB212FD3D", "hash_pe256": "49D9CC5F2C07BAD54B4992C3C821155D5A626822D553C51D6CA2EF3EB632C4EB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Service Control Utility", "meta_original_filename": "winmgmt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/720a7adb445f98c7a71f406711a4aff6c0e3143aa18a12df851b806d2d5b00fd/detection/", "output": "Invalid parameter\n\nWindows Management Instrumentation\n\nUsage: winmgmt\t[/backup <filename>] [/restore <filename> <flag>]\n\t\t[/resyncperf] [/standalonehost [<level>]] [/sharedhost]\n\t\t[/verifyrepository [<path>]] [/salvagerepository]\n\t\t[/resetrepository]\n\n/backup <filename>\n\tCauses WMI to back up the repository to the specified file name. The\n\tfilename argument should contain the full path to the file location.\n\tThis process requires a write lock on the repository so that write\n\toperations to the repository are suspended until the backup process is\n\tcompleted.\n\n/restore <filename> <flag>\n\tManually restores the WMI repository from the specified backup file.\n\tThe filename argument should contain the full path to the backup file\n\tlocation. To perform the restore operation, WMI saves the existing\n\trepository to write back if the operation fails. Then the repository is\n\trestored from the backup file that is specified in the filename\n\targument. If exclusive access to the repository cannot be achieved,\n\texisting clients are disconnected from WMI. The flag argument must be a\n\t1 (force - disconnect users and restore) or 0 (default - restore if no\n\tusers connected) and specifies the restore mode.\n\n/resyncperf\n\tRegisters the system performance libraries with WMI.\n\n/standalonehost [<level>]\n\tMoves the Winmgmt service to a standalone Svchost process that has a\n\tfixed DCOM endpoint. The default endpoint is \"ncacn_ip_tcp.0.24158\".\n\tHowever, the endpoint may be changed by running Dcomcnfg.exe. The level\n\targument is the authentication level for the Svchost process. If level\n\tis not specified, the default is 4 (RPC_C_AUTHN_LEVEL_PKT).\n\n/sharedhost\n\tMoves the Winmgmt service into the shared Svchost process.\n\n/verifyrepository [<path>]\n\tPerforms a consistency check on the WMI repository. When you add the\n\t/verifyrepository switch without the <path> argument, then the live\n\trepository currently used by WMI is verified. When you specify the path\n\targument, you can verify any saved copy of the repository. In this\n\tcase, the path argument should contain the full path to the saved\n\trepository copy. The saved repository should be a copy of the entire\n\trepository folder.\n\n/salvagerepository\n\tPerforms a consistency check on the WMI repository, and if an\n\tinconsistency is detected, rebuilds the repository. The content of the\n\tinconsistent repository is merged into the rebuilt repository, if it\n\tcan be read. The salvage operation always works with the repository\n\tthat the WMI service is currently using. MOF files that contain the\n\t#pragma autorecover preprocessor statement are restored to the\n\trepository.\n\n/resetrepository\n\tThe repository is reset to the initial state when the operating system\n\tis first installed. MOF files that contain the #pragma autorecover\n\tpreprocessor statement are restored to the repository.\n\n", "runtime_modules": [ "C:\\Windows\\system32\\wbem\\WinMgmt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "WMIADAP.exe-48D2B54B729DB3AACDD181BA3BD16DFF": { "file_name": "WMIADAP.exe", "file_path": "C:\\Windows\\system32\\wbem\\WMIADAP.exe", "hash_md5": "48D2B54B729DB3AACDD181BA3BD16DFF", "hash_sha1": "0B7F22CC31E3CA24EA60F2422D37571F91442238", "hash_sha256": "E2BA31E0F13310FC4BECBECEFC0253C4F7A7F76463A774EF3B434D46BF559291", "hash_sha384": "A695AEA9FCA5D22F7E3ACDF160471A6FDFC97B169F40AEFB5B4ECFFF62211FFAE343CD2CF95AAF7BE88A284E14048880", "hash_sha512": "221ECA48CB37E5252DBD387E415E1E39DF33A17FCCEDF84D57A88F0181E6527ED77B509CB17E8B52611D7899D05F5C3AA7EBDDED5B7F5F22317F362779D53F59", "hash_ssdeep": "1536:32cS5vyDlERp1EgLXL1luMiVHoGYsHJWD6xWTv+cIA+Y6hQay7kqJF0TMQ/Smcf0:S5vjoQhkMeoFI9AjdIRb6m2tishkX", "hash_imp": "4F983A9ED8F3DD91C6E9C506B9B53863", "hash_pesha1": "B8EC6BD7CF38C2ADFA0EB913D313B08ECF67DE81", "hash_pe256": "0DC314D6F673E3C7D6F390594490373E0A4291AF0DB7B0713AD13F0EB0E8E8F3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Reverse Performance Adapter Maintenance Utility", "meta_original_filename": "wmicookr.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/e2ba31e0f13310fc4becbecefc0253c4f7a7f76463a774ef3b434d46bf559291/detection/" }, "WmiApSrv.exe-D0A901EE141FE5AD78A12AE6A6378990": { "file_name": "WmiApSrv.exe", "file_path": "C:\\Windows\\system32\\wbem\\WmiApSrv.exe", "hash_md5": "D0A901EE141FE5AD78A12AE6A6378990", "hash_sha1": "CDB1CAF9EB1EDF441375F320450C0CA7D637D63F", "hash_sha256": "DBA5D56949BA383DAB17C3AB95EAC8B3F1B693729676D1A5637790F6E7F01ABD", "hash_sha384": "D85D4A64A723131ABF5E236E6C9825E0C6FE15E89B7DD8C7B751E332BC287E0BDDF58F4CD4831709C77A3A0129CE9FC1", "hash_sha512": "F4C856FF4C0A6D307CDEA5951E63A39D9E6F636DB7D73ED65B06D1ADFDB60BAE4AA8DDC0A66E7F06A1B5C2C777D297BE7F2E07BBD67AC653E11B79A764B99427", "hash_ssdeep": "3072:4jTP38cDpi9I/yt5ynxcXK4y4lDh3DU5YbYK7jZWSMTwrlT:OTPscti9Ig4gy4r3o5g7jZWSMTwr", "hash_imp": "6BC4858696E88B947919D50200792509", "hash_pesha1": "2928AD0A6B472D45F300DE24886B8446C95455D1", "hash_pe256": "74B8EA4441F86956AE2FF6DF3B759FF5D3BD1A50CEE571D2A805288E4EE20EB6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Performance Reverse Adapter", "meta_original_filename": "WmiApSrv.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/dba5d56949ba383dab17c3ab95eac8b3f1b693729676d1a5637790f6e7f01abd/detection/", "runtime_modules": [ "C:\\Windows\\system32\\wbem\\WmiApSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\sechost.dll" ] }, "WMIC.exe-390B2038C9ED2C94AB505921BC827FC7": { "file_name": "WMIC.exe", "file_path": "C:\\Windows\\system32\\wbem\\WMIC.exe", "hash_md5": "390B2038C9ED2C94AB505921BC827FC7", "hash_sha1": "4004528344D02FD143DAFD94BFE056041B633E0D", "hash_sha256": "34C4ED50A3441BD7CB6411749771C637A8C18C791525D8FCB5AE71B0B1969BA6", "hash_sha384": "CEB67964FC8F3B6416F57647DFBCA7EF0CBD3F0B123AFB54097A09E6A5BD7EA490E9D815CA667E747323C799C3B9CB15", "hash_sha512": "E0ED06637262ECD399495BFD61E2DF39EECB8E7F7583B6025A8168D38FCBED7B6712FE62079D9A1DA862C42026AEAB335ABEACB022EEB657FBE3ADB0BB6056E3", "hash_ssdeep": "6144:0kQflATq5Otf7DWNaJux0e/bNQnST/iikGy7QZQPGw9ZexWGH5enh:0LizBeoJuec3iikNTF9ZeEGH0nh", "hash_imp": "AF8CD6625FCE3244397EE550EFF4091E", "hash_pesha1": "FE44D357705361D3099FA325192BF4EB45FEE139", "hash_pe256": "154911087A936359BA936871A2999C56641693630CD64FC6D30E53974A88D790", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Commandline Utility", "meta_original_filename": "wmic.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/34c4ed50a3441bd7cb6411749771c637a8c18c791525d8fcb5ae71b0b1969ba6/detection/", "output": "\r\r\nWMIC is deprecated.\r\r\n\r\r\n[global switches] <command>\r\r\n\r\r\nThe following global switches are available:\r\r\n/NAMESPACE Path for the namespace the alias operate against.\r\r\n/ROLE Path for the role containing the alias definitions.\r\r\n/NODE Servers the alias will operate against.\r\r\n/IMPLEVEL Client impersonation level.\r\r\n/AUTHLEVEL Client authentication level.\r\r\n/LOCALE Language id the client should use.\r\r\n/PRIVILEGES Enable or disable all privileges.\r\r\n/TRACE Outputs debugging information to stderr.\r\r\n/RECORD Logs all input commands and output.\r\r\n/INTERACTIVE Sets or resets the interactive mode.\r\r\n/FAILFAST Sets or resets the FailFast mode.\r\r\n/USER User to be used during the session.\r\r\n/PASSWORD Password to be used for session login.\r\r\n/OUTPUT Specifies the mode for output redirection.\r\r\n/APPEND Specifies the mode for output redirection.\r\r\n/AGGREGATE Sets or resets aggregate mode.\r\r\n/AUTHORITY Specifies the <authority type> for the connection.\r\r\n/?[:<BRIEF|FULL>] Usage information.\r\r\n\r\r\nFor more information on a specific global switch, type: switch-name /?\r\r\n\r\r\n\r\r\nThe following alias/es are available in the current role:\r\r\nALIAS - Access to the aliases available on the local system\r\r\nBASEBOARD - Base board (also known as a motherboard or system board) management.\r\r\nBIOS - Basic input/output services (BIOS) management.\r\r\nBOOTCONFIG - Boot configuration management.\r\r\nCDROM - CD-ROM management.\r\r\nCOMPUTERSYSTEM - Computer system management.\r\r\nCPU - CPU management.\r\r\nCSPRODUCT - Computer system product information from SMBIOS. \r\r\nDATAFILE - DataFile Management. \r\r\nDCOMAPP - DCOM Application management.\r\r\nDESKTOP - User's Desktop management.\r\r\nDESKTOPMONITOR - Desktop Monitor management.\r\r\nDEVICEMEMORYADDRESS - Device memory addresses management.\r\r\nDISKDRIVE - Physical disk drive management. \r\r\nDISKQUOTA - Disk space usage for NTFS volumes.\r\r\nDMACHANNEL - Direct memory access (DMA) channel management.\r\r\nENVIRONMENT - System environment settings management.\r\r\nFSDIR - Filesystem directory entry management. \r\r\nGROUP - Group account management. \r\r\nIDECONTROLLER - IDE Controller management. \r\r\nIRQ - Interrupt request line (IRQ) management. \r\r\nJOB - Provides access to the jobs scheduled using the schedule service. \r\r\nLOADORDER - Management of system services that define execution dependencies. \r\r\nLOGICALDISK - Local storage device management.\r\r\nLOGON - LOGON Sessions. \r\r\nMEMCACHE - Cache memory management.\r\r\nMEMORYCHIP - Memory chip information.\r\r\nMEMPHYSICAL - Computer system's physical memory management. \r\r\nNETCLIENT - Network Client management.\r\r\nNETLOGIN - Network login information (of a particular user) management. \r\r\nNETPROTOCOL - Protocols (and their network characteristics) management.\r\r\nNETUSE - Active network connection management.\r\r\nNIC - Network Interface Controller (NIC) management.\r\r\nNICCONFIG - Network adapter management. \r\r\nNTDOMAIN - NT Domain management. \r\r\nNTEVENT - Entries in the NT Event Log. \r\r\nNTEVENTLOG - NT eventlog file management. \r\r\nONBOARDDEVICE - Management of common adapter devices built into the motherboard (system board).\r\r\nOS - Installed Operating System/s management. \r\r\nPAGEFILE - Virtual memory file swapping management. \r\r\nPAGEFILESET - Page file settings management. \r\r\nPARTITION - Management of partitioned areas of a physical disk.\r\r\nPORT - I/O port management.\r\r\nPORTCONNECTOR - Physical connection ports management.\r\r\nPRINTER - Printer device management. \r\r\nPRINTERCONFIG - Printer device configuration management. \r\r\nPRINTJOB - Print job management. \r\r\nPROCESS - Process management. \r\r\nPRODUCT - Installation package task management. \r\r\nQFE - Quick Fix Engineering. \r\r\nQUOTASETTING - Setting information for disk quotas on a volume. \r\r\nRDACCOUNT - Remote Desktop connection permission management.\r\r\nRDNIC - Remote Desktop connection management on a specific network adapter.\r\r\nRDPERMISSIONS - Permissions to a specific Remote Desktop connection.\r\r\nRDTOGGLE - Turning Remote Desktop listener on or off remotely.\r\r\nRECOVEROS - Information that will be gathered from memory when the operating system fails. \r\r\nREGISTRY - Computer system registry management.\r\r\nSCSICONTROLLER - SCSI Controller management. \r\r\nSERVER - Server information management. \r\r\nSERVICE - Service application management. \r\r\nSHADOWCOPY - Shadow copy management.\r\r\nSHADOWSTORAGE - Shadow copy storage area management.\r\r\nSHARE - Shared resource management. \r\r\nSOFTWAREELEMENT - Management of the elements of a software product installed on a system.\r\r\nSOFTWAREFEATURE - Management of software product subsets of SoftwareElement. \r\r\nSOUNDDEV - Sound Device management.\r\r\nSTARTUP - Management of commands that run automatically when users log onto the computer system.\r\r\nSYSACCOUNT - System account management. \r\r\nSYSDRIVER - Management of the system driver for a base service.\r\r\nSYSTEMENCLOSURE - Physical system enclosure management.\r\r\nSYSTEMSLOT - Management of physical connection points including ports, slots and peripherals, and proprietary connections points.\r\r\nTAPEDRIVE - Tape drive management. \r\r\nTEMPERATURE - Data management of a temperature sensor (electronic thermometer).\r\r\nTIMEZONE - Time zone data management. \r\r\nUPS - Uninterruptible power supply (UPS) management. \r\r\nUSERACCOUNT - User account management.\r\r\nVOLTAGE - Voltage sensor (electronic voltmeter) data management.\r\r\nVOLUME - Local storage volume management.\r\r\nVOLUMEQUOTASETTING - Associates the disk quota setting with a specific disk volume. \r\r\nVOLUMEUSERQUOTA - Per user storage volume quota management.\r\r\nWMISET - WMI service operational parameters management. \r\r\n\r\r\nFor more information on a specific alias, type: alias /?\r\r\n\r\r\nCLASS - Escapes to full WMI schema.\r\r\nPATH - Escapes to full WMI object paths.\r\r\nCONTEXT - Displays the state of all the global switches.\r\r\nQUIT/EXIT - Exits the program.\r\r\n\r\r\nFor more information on CLASS/PATH/CONTEXT, type: (CLASS | PATH | CONTEXT) /?\r\r\n\r\r\n", "error": "help - Alias not found.\r\r\n", "runtime_modules": [ "C:\\Windows\\system32\\wbem\\WMIC.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\framedynos.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\wbem\\wbemprox.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\msxml6.dll", "C:\\Windows\\SYSTEM32\\urlmon.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\iertutil.dll", "C:\\Windows\\System32\\CRYPTBASE.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\wbem\\wbemsvc.dll", "C:\\Windows\\system32\\wbem\\fastprox.dll" ] }, "WmiPrvSE.exe-06C66FF5CCDC2D22344A3EB761A4D38A": { "file_name": "WmiPrvSE.exe", "file_path": "C:\\Windows\\system32\\wbem\\WmiPrvSE.exe", "hash_md5": "06C66FF5CCDC2D22344A3EB761A4D38A", "hash_sha1": "67C25C8F28B5FA7F5BAA85BF1D2726AED48E9CF0", "hash_sha256": "B5C78BEF3883E3099F7EF844DA1446DB29107E5C0223B97F29E7FAFAB5527F15", "hash_sha384": "17849BDEBC360BDD488958A7A7B322ADE0B507DB1C0C15731243AC378426310FA81C196A480E28B873093B28E53471B3", "hash_sha512": "DF9E47A007CC831AB396C83806A3F92F837522759D11FBFC8B069EA513832252CB9C0DDD713AA09A2BA7762B57CFB18CDB13E74B166338EFAA616CD2BD13CDE9", "hash_ssdeep": "6144:n55U8ziMJNIlFZVLizDI38GbSgHneOx3sZTSvq4rjyzuJDeP:53+qelFLLiYsGbSgHnD6cvqicuB8", "hash_imp": "CFECEDC01015A4FD1BAACAC9E592D88B", "hash_pesha1": "FF50ABF7CC185C0BDE3E41E96EC3656D00AAFE87", "hash_pe256": "396DDF55D2A25F460AA96436859A9B82FFC581F1DE9DE425E6168F1D73D03AA5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Provider Host", "meta_original_filename": "Wmiprvse.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/b5c78bef3883e3099f7ef844da1446db29107e5c0223b97f29e7fafab5527f15/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC6F4": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\wbem\\WmiPrvSE.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\system32\\wbem\\FastProx.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\SYSTEM32\\NCObjAPI.DLL", "C:\\Windows\\SYSTEM32\\wbemcomn.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\wbem\\wbemprox.dll", "C:\\Windows\\system32\\wbem\\wbemsvc.dll" ] }, "powershell.exe-7353F60B1739074EB17C5F4DDDEFE239": { "file_name": "powershell.exe", "file_path": "C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\powershell.exe", "hash_md5": "7353F60B1739074EB17C5F4DDDEFE239", "hash_sha1": "6CBCE4A295C163791B60FC23D285E6D84F28EE4C", "hash_sha256": "DE96A6E69944335375DC1AC238336066889D9FFC7D73628EF4FE1B1B160AB32C", "hash_sha384": "6A8916B36014D3E2EBDAB5A948EF39808E6159F0FCE3EA4334BB7AE89BAB694AA54F235ED3AACFC63D354B0A6B51900D", "hash_sha512": "BD98C8AEE1138D17C39F2FB0E09BF79EF2D6096464CEB459CC66C5FB670DF093414A373BBB4B4D8E7063C2EACB120449C45DF218033F2258F56BEC1618B43C4C", "hash_ssdeep": "6144:+srKopvMWwO9sV1yZywi/PzNKXzJ7BapCK5d3klRzULOnWyjLsPhAQzqO:BrKopEW2KXzJ4pdd3klnnWosPhnzq", "hash_imp": "741776AACCFC5B71FF59832DCDCACE0F", "hash_pesha1": "D26D99E01EDFABF842342DFFA2DDE1EAC7F803B7", "hash_pe256": "68705285F7914823244E19E4F6DBC4A75C4DE807EA1CF128AEC2CCAFCE5FE109", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows PowerShell", "meta_original_filename": "PowerShell.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c/detection/", "output": "\r\nPowerShell[.exe] [-PSConsoleFile <file> | -Version <version>]\r\n [-NoLogo] [-NoExit] [-Sta] [-Mta] [-NoProfile] [-NonInteractive]\r\n [-InputFormat {Text | XML}] [-OutputFormat {Text | XML}]\r\n [-WindowStyle <style>] [-EncodedCommand <Base64EncodedCommand>]\r\n [-ConfigurationName <string>]\r\n [-File <filePath> <args>] [-ExecutionPolicy <ExecutionPolicy>]\r\n [-Command { - | <script-block> [-args <arg-array>]\r\n | <string> [<CommandParameters>] } ]\r\n\r\nPowerShell[.exe] -Help | -? | /?\r\n\r\n-PSConsoleFile\r\n Loads the specified Windows PowerShell console file. To create a console\r\n file, use Export-Console in Windows PowerShell.\r\n\r\n-Version\r\n Starts the specified version of Windows PowerShell. \r\n Enter a version number with the parameter, such as \"-version 2.0\".\r\n\r\n-NoLogo\r\n Hides the copyright banner at startup.\r\n\r\n-NoExit\r\n Does not exit after running startup commands.\r\n\r\n-Sta\r\n Starts the shell using a single-threaded apartment.\r\n Single-threaded apartment (STA) is the default.\r\n\r\n-Mta\r\n Start the shell using a multithreaded apartment.\r\n\r\n-NoProfile\r\n Does not load the Windows PowerShell profile.\r\n\r\n-NonInteractive\r\n Does not present an interactive prompt to the user.\r\n\r\n-InputFormat\r\n Describes the format of data sent to Windows PowerShell. Valid values are\r\n \"Text\" (text strings) or \"XML\" (serialized CLIXML format).\r\n\r\n-OutputFormat\r\n Determines how output from Windows PowerShell is formatted. Valid values\r\n are \"Text\" (text strings) or \"XML\" (serialized CLIXML format).\r\n\r\n-WindowStyle\r\n Sets the window style to Normal, Minimized, Maximized or Hidden.\r\n\r\n-EncodedCommand\r\n Accepts a base-64-encoded string version of a command. Use this parameter \r\n to submit commands to Windows PowerShell that require complex quotation \r\n marks or curly braces.\r\n\r\n-ConfigurationName\r\n Specifies a configuration endpoint in which Windows PowerShell is run.\r\n This can be any endpoint registered on the local machine including the\r\n default Windows PowerShell remoting endpoints or a custom endpoint having\r\n specific user role capabilities.\r\n \r\n-File\r\n Runs the specified script in the local scope (\"dot-sourced\"), so that the \r\n functions and variables that the script creates are available in the \r\n current session. Enter the script file path and any parameters. \r\n File must be the last parameter in the command, because all characters \r\n typed after the File parameter name are interpreted \r\n as the script file path followed by the script parameters.\r\n\r\n-ExecutionPolicy\r\n Sets the default execution policy for the current session and saves it \r\n in the $env:PSExecutionPolicyPreference environment variable. \r\n This parameter does not change the Windows PowerShell execution policy \r\n that is set in the registry.\r\n\r\n-Command\r\n Executes the specified commands (and any parameters) as though they were\r\n typed at the Windows PowerShell command prompt, and then exits, unless \r\n NoExit is specified. The value of Command can be \"-\", a string. or a\r\n script block.\r\n\r\n If the value of Command is \"-\", the command text is read from standard\r\n input.\r\n\r\n If the value of Command is a script block, the script block must be enclosed\r\n in braces ({}). You can specify a script block only when running PowerShell.exe\r\n in Windows PowerShell. The results of the script block are returned to the\r\n parent shell as deserialized XML objects, not live objects.\r\n\r\n If the value of Command is a string, Command must be the last parameter\r\n in the command , because any characters typed after the command are \r\n interpreted as the command arguments.\r\n\r\n To write a string that runs a Windows PowerShell command, use the format:\r\n\t\"& {<command>}\"\r\n where the quotation marks indicate a string and the invoke operator (&)\r\n causes the command to be executed.\r\n\r\n-Help, -?, /?\r\n Shows this message. If you are typing a PowerShell.exe command in Windows\r\n PowerShell, prepend the command parameters with a hyphen (-), not a forward\r\n slash (/). You can use either a hyphen or forward slash in Cmd.exe.\r\n\r\nEXAMPLES\r\n PowerShell -PSConsoleFile SqlSnapIn.Psc1\r\n PowerShell -version 2.0 -NoLogo -InputFormat text -OutputFormat XML\r\n PowerShell -ConfigurationName AdminRoles\r\n PowerShell -Command {Get-EventLog -LogName security}\r\n PowerShell -Command \"& {Get-EventLog -LogName security}\"\r\n\r\n # To use the -EncodedCommand parameter:\r\n $command = 'dir \"c:\\program files\" '\r\n $bytes = [System.Text.Encoding]::Unicode.GetBytes($command)\r\n $encodedCommand = [Convert]::ToBase64String($bytes)\r\n powershell.exe -encodedCommand $encodedCommand\r\n", "error": "At line:1 char:3\r\n+ --help\r\n+ ~\r\nMissing expression after unary operator '--'.\r\nAt line:1 char:3\r\n+ --help\r\n+ ~~~~\r\nUnexpected token 'help' in expression or statement.\r\n + CategoryInfo : ParserError: (:) [], ParentContainsErrorRecordException\r\n + FullyQualifiedErrorId : MissingExpressionAfterOperator\r\n \r\n", "runtime_modules": [ "C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\powershell.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\OLE32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\SYSTEM32\\ATL.DLL", "C:\\Windows\\SYSTEM32\\mscoree.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\5543cca0df435801e2303ff46a482ed5\\mscorlib.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\6885802f40fd803e49150d8a2b43a09b\\System.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Core\\f29b1120627489754c4b8dd317bbe950\\System.Core.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pb378ec07#\\09c476bb8e1a5db27f8b3af858e06714\\Microsoft.PowerShell.ConsoleHost.ni.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\bb0ca52db926eaec4a94a8b656f61a94\\System.Management.Automation.ni.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\psapi.dll", "C:\\Windows\\System32\\shell32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\wintrust.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\SYSTEM32\\gpapi.dll", "C:\\Windows\\SYSTEM32\\amsi.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\ProgramData\\Microsoft\\Windows Defender\\platform\\4.18.2009.7-0\\MpOav.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Mf49f6405#\\eef1c844e068e37a11b89ec1bfe58c6a\\Microsoft.Management.Infrastructure.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Management\\35d31e1630335aeb7e7cb2ed836e7230\\System.Management.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Dired13b18a9#\\056cc0ec5d17f063bfd68aef0dfdff2e\\System.DirectoryServices.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Xml\\488d073901c2c0fb8ccbcbe182b6b160\\System.Xml.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Numerics\\65da063a028c3cfc846f5ddfffc32558\\System.Numerics.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Data\\a39e284ddde9013349d1f350607766b8\\System.Data.ni.dll", "C:\\Windows\\Microsoft.Net\\assembly\\GAC_64\\System.Data\\v4.0_4.0.0.0__b77a5c561934e089\\System.Data.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\SYSTEM32\\wldp.dll", "C:\\Windows\\System32\\MSISIP.DLL", "C:\\Windows\\System32\\coml2.dll", "C:\\Windows\\System32\\wshext.dll", "C:\\Windows\\System32\\AppxSip.dll", "C:\\Windows\\SYSTEM32\\OpcServices.DLL", "C:\\Windows\\SYSTEM32\\tdh.dll", "C:\\Windows\\SYSTEM32\\XmlLite.dll", "C:\\Windows\\SYSTEM32\\urlmon.dll", "C:\\Windows\\SYSTEM32\\mintdh.dll", "C:\\Windows\\SYSTEM32\\iertutil.dll", "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\pwrshsip.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Configuration\\875dc3cfd53efc9f9a5c63016cd239d7\\System.Configuration.ni.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P6f792626#\\c8e961023e9ebb284f5ac038896f7f8b\\Microsoft.PowerShell.Security.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Transactions\\c474b0144ec78b5ee7d68047d878855e\\System.Transactions.ni.dll", "C:\\Windows\\Microsoft.Net\\assembly\\GAC_64\\System.Transactions\\v4.0_4.0.0.0__b77a5c561934e089\\System.Transactions.dll", "C:\\Windows\\SYSTEM32\\secur32.dll", "C:\\Windows\\SYSTEM32\\SSPICLI.DLL", "C:\\Windows\\system32\\uxtheme.dll" ] }, "powershell_ise.exe-9577A63626D2536E7416494F09F0EEC2": { "file_name": "powershell_ise.exe", "file_path": "C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\powershell_ise.exe", "hash_md5": "9577A63626D2536E7416494F09F0EEC2", "hash_sha1": "044CA0FECF2436AAC3F9E7ACC3C97B30588C594D", "hash_sha256": "77B4C0F9929073CE132223F3169349F3E7A626C392B7DBC1A39FA89265C2C6BF", "hash_sha384": "677980CAF0309103FD3DE0AB26B08814926235E8F427ACB24AD409927A2F1613CEFA18BCD14EF76E8B2D02DE2036D6D4", "hash_sha512": "5098BBA829A795C2AEFA85A583388B71690F588DDA92BB85B5304FD698E1AA77A610FE98EF93767803FC6FA11A46F94711BF1A4F9E0B7DC464CE61823B9E8763", "hash_ssdeep": "3072:KDEkVjGPsw40vLkVjqP4w6U+ToIuWNXmmZTWl/jC7gDooMLa6:K4kSuZToIuUXmmZbgDooMz", "hash_imp": "n/a", "hash_pesha1": "6D8E1F84FD8DBD336C84593169B6FAF9868E1B48", "hash_pe256": "5F22050604E95FCC7F8D93F85E9BB1EB7B732CDDA10E2EF36804F768C56BC22E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows PowerShell ISE", "meta_original_filename": "powershell_ise.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/77b4c0f9929073ce132223f3169349f3e7a626c392b7dbc1a39fa89265c2c6bf/detection/", "children": "explorer.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4760": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\powershell_ise.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\5543cca0df435801e2303ff46a482ed5\\mscorlib.ni.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\6885802f40fd803e49150d8a2b43a09b\\System.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pd3efef62#\\8ebae32cd8bf9bc337e933a45adb2ffa\\Microsoft.PowerShell.ISECommon.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Drawing\\6c6bbae87386b6a33957366eae0e4470\\System.Drawing.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Windows.Forms\\23c1e20aa87eccaf2c33ba9f47d2319e\\System.Windows.Forms.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Core\\f29b1120627489754c4b8dd317bbe950\\System.Core.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\bb0ca52db926eaec4a94a8b656f61a94\\System.Management.Automation.ni.dll", "C:\\Windows\\System32\\psapi.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\System32\\TextInputFramework.dll", "C:\\Windows\\System32\\CoreUIComponents.dll", "C:\\Windows\\System32\\SHCORE.dll", "C:\\Windows\\System32\\CoreMessaging.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\SYSTEM32\\wintypes.dll" ], "runtime_window_title": "Windows PowerShell ISE" }, "appidtel.exe-DA0BCC7829D8675AD442E44863AAE820": { "file_name": "appidtel.exe", "file_path": "C:\\Windows\\SysWOW64\\appidtel.exe", "hash_md5": "DA0BCC7829D8675AD442E44863AAE820", "hash_sha1": "B54118A2270A9ECB9089C7D64E5D11CDF3B137CE", "hash_sha256": "6F6067FE2D9FF65BCCD9FB974C57E6EFE707756CBB672E839D01486B116985C2", "hash_sha384": "F39349D15AB5013DC9AAF55C541C1CCF3D5A9DBEC2EE826426B89944D48DC7643339AFCB7346AF3A8DA5F72D17EE51FC", "hash_sha512": "1133EC0C0A894E8545AB0C49419440E9E1581CDCD6876A52E129AA14A23A703742C7BA1D34C04DB03062E388DDE6A415936DEE298BACE73FEAA1DE323F339BE4", "hash_ssdeep": "384:nlRT3SsKmxpVoXA6YHbeHWbHmeSkEkvAddk3YLAr21iEBWsdsWkiJ:lJClUpN3bHmbdu3Yf1iWuiJ", "hash_imp": "45B4E0F623405C276E4DA9F4816C57F0", "hash_pesha1": "599F4450D41A47DCC5BC71055E930257DC7FB93C", "hash_pe256": "B8878B0B7C260BA61201C76D50014136406753CCC7385D969D1D1B608C16AD74", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Initializes Appid ManagedInstaller and Smartscreen Telemetry", "meta_original_filename": "APPIDTEL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "1.00 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/6f6067fe2d9ff65bccd9fb974c57e6efe707756cbb672e839d01486b116985c2/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\appidtel.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ARP.EXE-09AE57A8E85E55EED4F2E80F25BA0B5B": { "file_name": "ARP.EXE", "file_path": "C:\\Windows\\SysWOW64\\ARP.EXE", "hash_md5": "09AE57A8E85E55EED4F2E80F25BA0B5B", "hash_sha1": "04B5DEE34B03FA9EEAD06FA7061E7AC4D4FB917F", "hash_sha256": "6F928475E24F329DFD465D7B2411573B9824C317C704708E077F4732E58D0153", "hash_sha384": "65837E6A828DFDD14EEE9FF66F63FE60A1B02B945EB5F7773A883EB6AA2425BD2A8DFF53B6140898DA09AC5D190BFEAA", "hash_sha512": "DEE5C6B5495D3591DE384FB5DEB510507AAE7D7C77B72B84F166791A3E0CF80E7A210666099F808E592A3D893B9BD8921ACED0E6AF21E0BADEE912740D5DFE97", "hash_ssdeep": "384:yskrMiJfmm5ssEt/FXgAYITeqGujP25QWSSmWW:srM5melt9XZ9iuj+5f", "hash_imp": "E8C32549669D3BF8F046BB43E47AF972", "hash_pesha1": "0B7676BE099233BB7F5A4EB1B55885B33094C1B9", "hash_pe256": "605AB6EC78469D3DE2280A765198D4F654EF0EE42C0EBFF45F1BD2ED042FFD86", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Arp Command", "meta_original_filename": "arp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/6f928475e24f329dfd465d7b2411573b9824c317c704708e077f4732e58d0153/detection/", "output": "\r\nDisplays and modifies the IP-to-Physical address translation tables used by\r\naddress resolution protocol (ARP).\r\n\r\nARP -s inet_addr eth_addr [if_addr]\r\nARP -d inet_addr [if_addr]\r\nARP -a [inet_addr] [-N if_addr] [-v]\r\n\r\n -a Displays current ARP entries by interrogating the current\r\n protocol data. If inet_addr is specified, the IP and Physical\r\n addresses for only the specified computer are displayed. If\r\n more than one network interface uses ARP, entries for each ARP\r\n table are displayed.\r\n -g Same as -a.\r\n -v Displays current ARP entries in verbose mode. All invalid \r\n entries and entries on the loop-back interface will be shown.\r\n inet_addr Specifies an internet address.\r\n -N if_addr Displays the ARP entries for the network interface specified\r\n by if_addr.\r\n -d Deletes the host specified by inet_addr. inet_addr may be \r\n wildcarded with * to delete all hosts.\r\n -s Adds the host and associates the Internet address inet_addr\r\n with the Physical address eth_addr. The Physical address is\r\n given as 6 hexadecimal bytes separated by hyphens. The entry\r\n is permanent.\r\n eth_addr Specifies a physical address.\r\n if_addr If present, this specifies the Internet address of the\r\n interface whose address translation table should be modified.\r\n If not present, the first applicable interface will be used.\r\nExample:\r\n > arp -s 157.55.85.212 00-aa-00-62-c6-09 .... Adds a static entry.\r\n > arp -a .... Displays the arp table.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ARP.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "at.exe-B31EE2A06C982B9749978B84FD5503F0": { "file_name": "at.exe", "file_path": "C:\\Windows\\SysWOW64\\at.exe", "hash_md5": "B31EE2A06C982B9749978B84FD5503F0", "hash_sha1": "351498CAEFF9C766A3DA1D2B81127C7D02A0A093", "hash_sha256": "26DDA3026E983CA98575339A0C8FFB5700DD9FB03693E92D5F192489B3F44067", "hash_sha384": "86B0ACF99D0D3F66A540D1721EA1DA0427580D817A5F23596B415EA5CFFBA175953434DCCADBC1323254E39EB3D914C6", "hash_sha512": "F4090A3DAB7C0562116211DFCCD37DDD5060ABC249A14FF5218FE5ABB8F88EFF7A7108E7CF2523FEE2EFABEA8E6B982F1128A75051BA5E42AEBBF3CDF8F407C6", "hash_ssdeep": "384:pOYoAVSIfwGL3VodhqD50sIlFWv/PqyaYgKCfIbl5wYfspFJzvHWrwWT3ET:p7gIIGRodhCHgFWvXCLxYgFJzg", "hash_imp": "5E73167C9D018AE22337A300A51487A7", "hash_pesha1": "D339BB37CBEA3B9C37DECD30A1B5FFF843B80E8F", "hash_pe256": "9F2D3C0DC45B3ABAF323813F1C5FF21DEDBD3FF0F3E34146717A87C3880ECE69", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Schedule service command line interface", "meta_original_filename": "AT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/26dda3026e983ca98575339a0c8ffb5700dd9fb03693e92d5f192489b3f44067/detection/", "output": "The AT command has been deprecated. Please use schtasks.exe instead.\r\n\r\nInvalid command.\r\n\r\nThe AT command schedules commands and programs to run on a computer at \r\na specified time and date. The Schedule service must be running to use \r\nthe AT command.\r\n \r\nAT [\\\\computername] [ [id] [/DELETE] | /DELETE [/YES]] \r\nAT [\\\\computername] time [/INTERACTIVE]\r\n [ /EVERY:date[,...] | /NEXT:date[,...]] \"command\"\r\n\r\n\\\\computername Specifies a remote computer. Commands are scheduled on the\r\n local computer if this parameter is omitted. \r\nid Is an identification number assigned to a scheduled \r\n command. \r\n/delete Cancels a scheduled command. If id is omitted, all the\r\n scheduled commands on the computer are canceled.\r\n/yes Used with cancel all jobs command when no further\r\n confirmation is desired.\r\ntime Specifies the time when command is to run.\r\n/interactive Allows the job to interact with the desktop of the user \r\n who is logged on at the time the job runs.\r\n/every:date[,...] Runs the command on each specified day(s) of the week or\r\n month. If date is omitted, the current day of the month\r\n is assumed. \r\n/next:date[,...] Runs the specified command on the next occurrence of the\r\n day (for example, next Thursday). If date is omitted, the\r\n current day of the month is assumed.\r\n\"command\" Is the Windows NT command, or batch program to be run.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\at.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "AtBroker.exe-9BDC479E59B6983589576F1865F25247": { "file_name": "AtBroker.exe", "file_path": "C:\\Windows\\SysWOW64\\AtBroker.exe", "hash_md5": "9BDC479E59B6983589576F1865F25247", "hash_sha1": "770904DA1FAD1B0A5FE7347BB2FE817E0F299FFD", "hash_sha256": "22B2A930D97C30BF53B7BC9838F8C4C938D7D0F806EAE3601F9A01AEAC803443", "hash_sha384": "9A28B5BE91C23353CB0C869585B6271CCB1127FF4BD8B7CB881F19EDEFC876D2E6A1FC7F67176C3ACE7C306C72BF871E", "hash_sha512": "736A1216B361D49426D7CFCFFE97C50207948139BD98F2C4D5C174553C3BF49D4F752C7C7E704E1A54F8474B9EE69925634DAFA7B7F670317DC3F6EDE4F94F61", "hash_ssdeep": "768:3T+Kjgbmte3DLwhxr5Fo2cMfUuc0xpkh9hwTPGV5X62UbtGeKJaD+RIu62EMKaHs:3Tlxr5FoJ+dvO9hwTGV9GfDg7DHpmV", "hash_imp": "F791708993F51197FF73758E81E9637C", "hash_pesha1": "D203AFA581E27593A46961A41B021E0B7B54871B", "hash_pe256": "D0EC86755BE20CD389C6CFC60CA825A561BC543AE16550A4E73B9533A1736746", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Assistive Technology Manager", "meta_original_filename": "ATBroker.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/22b2a930d97c30bf53b7bc9838f8c4c938d7d0f806eae3601f9a01aeac803443/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\AtBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "attrib.exe-8A6D490C0EC9BE27B97FE1E37CDE1325": { "file_name": "attrib.exe", "file_path": "C:\\Windows\\SysWOW64\\attrib.exe", "hash_md5": "8A6D490C0EC9BE27B97FE1E37CDE1325", "hash_sha1": "D1783E413929B312709C58EE1BAC0BD80B2F703B", "hash_sha256": "B0FA083D8276EDE756D9E525B18EEBC9067357747228F0D965D452FA194E0C47", "hash_sha384": "20A91B58555B3137122F091DDEAD1A137A162944AA84480E55D7DF8A0765CD627EC752E6AD4A5FD1CF7A836E0112AAC5", "hash_sha512": "877939CFEF26F5548A84E4579AA2B8B9EFE1FBC45E505056E69BE254B0EC6AA317CF884D3F15A1E94B942FF643605AA699E2FAA51711A36321DAE4309B82D3C8", "hash_ssdeep": "384:l6RtFqGdTDEhg5qqGiH1ZNQqYCfw3W4tWY:l6HFqGPES2Cfwbf", "hash_imp": "F0A82FEBA5B0EF2BE614622AE3E32C1C", "hash_pesha1": "6DF0A3CD15CF1CFCEE0E1C6C93AE99F039A96FCE", "hash_pe256": "F5913BE4079DC309F522D06580E634F14047FD20F2430AE7F7259F243F3E6A7F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Attribute Utility", "meta_original_filename": "ATTRIB.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b0fa083d8276ede756d9e525b18eebc9067357747228f0d965d452fa194e0c47/detection/", "output": "Displays or changes file attributes.\r\n\r\nATTRIB [+R | -R] [+A | -A] [+S | -S] [+H | -H] [+O | -O] [+I | -I] [+X | -X] [+P | -P] [+U | -U]\r\n [drive:][path][filename] [/S [/D]] [/L]\r\n\r\n + Sets an attribute.\r\n - Clears an attribute.\r\n R Read-only file attribute.\r\n A Archive file attribute.\r\n S System file attribute.\r\n H Hidden file attribute.\r\n O Offline attribute.\r\n I Not content indexed file attribute.\r\n X No scrub file attribute.\r\n V Integrity attribute.\r\n P Pinned attribute.\r\n U Unpinned attribute.\r\n B SMR Blob attribute.\r\n [drive:][path][filename]\r\n Specifies a file or files for attrib to process.\r\n /S Processes matching files in the current folder\r\n and all subfolders.\r\n /D Processes folders as well.\r\n /L Work on the attributes of the Symbolic Link versus\r\n the target of the Symbolic Link\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\attrib.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "auditpol.exe-F69564DE88DDE5408EB37687D8CC7DAC": { "file_name": "auditpol.exe", "file_path": "C:\\Windows\\SysWOW64\\auditpol.exe", "hash_md5": "F69564DE88DDE5408EB37687D8CC7DAC", "hash_sha1": "2E4C06A8D3A26E7C04BBFDCBD3807A2773EB2BD4", "hash_sha256": "B01B1FAD43094C5B336F8ED8818013DB66D2A71141EE5C3602B951A7BF78B989", "hash_sha384": "53F57B767B7126A4B2A4D589A9C84E5BFE1B8F20F4F83A8DA52498B9909CB838AA2A1E5C27C6ACB6601B95BD3A005E25", "hash_sha512": "4A3722189957779DA2EDCDAC79616BC957B0811A42DF36850F94D8DFC8642BB1485448981161ABEB03599EF6418C1BB5C08B95E87FCE9E4E8C4A9BF14E42E9C9", "hash_ssdeep": "768:WHvXkRIp0iHKMyUeNt2LCPqeZv2NUX7el:A0vayNNt2SZv2NUX7y", "hash_imp": "A69EC672A5B73C1F227F39DC959E6FA4", "hash_pesha1": "CB2BCE3D7B02483D638AA3DDA5BB550BCF23AB1A", "hash_pe256": "646FA5E4AA5E7C690994D17FD4090012443CB55664DB8AE8D9DA57851064E756", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Audit Policy Program", "meta_original_filename": "AUDITPOL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/b01b1fad43094c5b336f8ed8818013db66d2a71141ee5c3602b951a7bf78b989/detection/", "output": "Usage: AuditPol command [<sub-command><options>]\r\r\n\r\r\n\r\r\nCommands (only one command permitted per execution)\r\r\n /? Help (context-sensitive)\r\r\n /get Displays the current audit policy.\r\r\n /set Sets the audit policy.\r\r\n /list Displays selectable policy elements.\r\r\n /backup Saves the audit policy to a file.\r\r\n /restore Restores the audit policy from a file.\r\r\n /clear Clears the audit policy.\r\r\n /remove Removes the per-user audit policy for a user account.\r\r\n /resourceSACL Configure global resource SACLs\r\r\n\r\r\n\r\r\nUse AuditPol <command> /? for details on each command\r\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\auditpol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "Error 0x00000057 occurred:\r\r\nThe parameter is incorrect.\r\r\n\r\r\n" }, "autochk.exe-8AF3440A14DBF0D5D034E1AF7B7B7B9B": { "file_name": "autochk.exe", "file_path": "C:\\Windows\\SysWOW64\\autochk.exe", "hash_md5": "8AF3440A14DBF0D5D034E1AF7B7B7B9B", "hash_sha1": "F58F3C79963227A3C71AAC3E4EF037A96FD0CC9A", "hash_sha256": "6B3BAF126D1250EE3E8896F8D6197B8BEDE1850171D5B518D475D1CC52BAAF07", "hash_sha384": "6FA66EE3F7223CE1AC565139286620C48FBE72285E63829020B966DE0740C356DFE28430DA4BD190198167F01F3BFE56", "hash_sha512": "D48DBADB88D47C62EC743D43334A2572CFA3B166F57200FDF99BBF7DCD9082A81B2E8FF2C196D9D5A2513ABD9B600DC76E8E6677787FA6EA9DC554EC64A7D758", "hash_ssdeep": "24576:F5/QnDpWGRG1+aDzFgyoLstNbeIbTv+aExzV2:FCJI1+aDzFgyoANbpTv+aExzV2", "hash_imp": "B753F48261F46F0BEB1B3613EDC3F37A", "hash_pesha1": "DD1074D239649CB3486A1A1156EA2F1875A97CAF", "hash_pe256": "7892D5DAC22E667625AEBDB2F227C1D84447738477A8C55094F60CE772E7B4D9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto Check Utility", "meta_original_filename": "AutoChk.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/6b3baf126d1250ee3e8896f8d6197b8bede1850171d5b518d475d1cc52baaf07/detection/" }, "autoconv.exe-AD6A0951757BBDFE781DF92C6CD8B7CD": { "file_name": "autoconv.exe", "file_path": "C:\\Windows\\SysWOW64\\autoconv.exe", "hash_md5": "AD6A0951757BBDFE781DF92C6CD8B7CD", "hash_sha1": "33B6E8749390BF7EDC3C07E8855F585281B1CFCD", "hash_sha256": "BFE7DC2AB8C610FBA1339A86C7E3C0D8D574A82F17670C31C32C11558000C54E", "hash_sha384": "6235D5F5637FCB3827C39E52728E12FE1C6E85D9B1FF30C24037669CB71F561302205891556D11985CC59291514F9FCB", "hash_sha512": "FFC44F79878F1244A7F7E91D32257548000742962D640113EB657116C0852BE7DB7A2D7FF10DEE741AF3CC0B5F586CEA9CDA75FDEB88522AB464A8CC677F081B", "hash_ssdeep": "24576:BT24NzkbRbXN07U7n4xrZND06NfD0wcy6H0zMV:ZzkFG7U7n4xrZlNbcy6UzMV", "hash_imp": "135495E54FD99DE3B1B5BAD0EB1B49C4", "hash_pesha1": "29AF6D9ED0DA50890FDAE5107E80C60F2DC87C99", "hash_pe256": "D2370649F6794FBFBC021060DB64DC3654C1149F883EE8D250F310982095BB4E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto File System Conversion Utility", "meta_original_filename": "AUTOCONV.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "autofmt.exe-0F00EE36D9EACE96786D374CC55BA03B": { "file_name": "autofmt.exe", "file_path": "C:\\Windows\\SysWOW64\\autofmt.exe", "hash_md5": "0F00EE36D9EACE96786D374CC55BA03B", "hash_sha1": "A04D0939E7FB38C0486029E99216C95CBEEAAFCE", "hash_sha256": "A27F730F1313D5A5759A6A8353AF042766F0050154DD53389B3F316E1E9732A7", "hash_sha384": "7140AF4FD27642354B8C651F1D202F30B4A0F95788DE7B1DAA8417C86539BBCF16A18CEF6392EE5F71B4C12941553F2C", "hash_sha512": "160F37EDD35249D681F3E623F4B5CA9A799E45F70FAFC1D0A087D6E76C17ECEF85E159F1B694664CC927014CA01D798FAB9E9F31334525D61EE2D6E42E8D34BE", "hash_ssdeep": "24576:MBu7M947vHKZ4sUzBszsgYVw/QiCmEWblV:FTHK6sUzBrgYVP1mEWblV", "hash_imp": "991870467B2BD93E6A5285B2DEDABA22", "hash_pesha1": "6D06D6D2FCDC0C83D3DE7520D0B5911D397FA4D1", "hash_pe256": "49DBB5D5E306E31C585443B68B6240A5F24E380112C2E9F98DC75123C8F39A92", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Auto File System Format Utility", "meta_original_filename": "AUTOFMT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "backgroundTaskHost.exe-F8D636BD68156F0C653DBC3D69FC0F08": { "file_name": "backgroundTaskHost.exe", "file_path": "C:\\Windows\\SysWOW64\\backgroundTaskHost.exe", "hash_md5": "F8D636BD68156F0C653DBC3D69FC0F08", "hash_sha1": "7202469A81C40BD2494C10B3DEF77F5F57CA97A1", "hash_sha256": "1B170E9624D0C6A699F6FED4F612802B3D82C21B6C27F9B41296C1F814A0F668", "hash_sha384": "28BB3C6125D637A0214D9C72FB47EE1646D9091EA2C4B9FE7066EACA2200BAEF6AF9DB35C765B3CD85BF3E84C9AEE557", "hash_sha512": "2A8225F311C545796FEEB3901611E4EBB611247D3FC05AFFC9DF8FA6031413E337B0283E99C62F682097B7C419E7D237898080C645883D7C3E82F67CD5A4CE40", "hash_ssdeep": "192:EADhE8DRi+A44ArvBucqK9to2AfXQHWH5WqeGWz+U/3XjDBQABJysQlmqnajzhfN:EiPA41vBTo0HWZWFGWamXjDBRJy6lPZN", "hash_imp": "B01956F70C2FC1C81D9AF197F35D4D75", "hash_pesha1": "C486BE40F0928FB172C0A16E8869B731F7BABB4B", "hash_pe256": "CD9D65C63206D407B1426555A3F42680B9FD7555A178485309481AE5B8FEDB3B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Background Task Host", "meta_original_filename": "backgroundTaskHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/1b170e9624d0c6a699f6fed4f612802b3d82c21b6c27f9b41296c1f814a0f668/detection/", "children": [ "backgroundTaskHost.exe", "WerFault.exe" ], "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\backgroundTaskHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "BackgroundTransferHost.exe-26D9648F16F1379272FF20AAA888B5D6": { "file_name": "BackgroundTransferHost.exe", "file_path": "C:\\Windows\\SysWOW64\\BackgroundTransferHost.exe", "hash_md5": "26D9648F16F1379272FF20AAA888B5D6", "hash_sha1": "57155800B595C6AE94F76954EC6BA2A9907D6E36", "hash_sha256": "F393D6FBCBBE46CC63C7996D0F35763BA46E512CC18ADC3EAD71855C59BAB946", "hash_sha384": "29274C6F853B4E7A122010E587801F5F3E387CDE05CCC67E9ADDA3F875B06D56D03C52210B06F3526FAA97DE26D76CDD", "hash_sha512": "EBCE6FE916EA41EAEC8654C33F712FD7F14762B66D7B894FE097B17BD9142D2288AA4D6353B69CA22ABFF94204BE20C8D2AB92051D40F2F333634AD5E1C7897B", "hash_ssdeep": "384:DPFoJH2c1GZPjYAv3EMyEXAL8xspKqveBXW0rgWwQE0g7qW2RPT/8rFeZmJhzc:DPFoJH2cUZb3zbQeBxo2a3c", "hash_imp": "2C84391D64B2AF34A9B9E60431B39091", "hash_pesha1": "1D897EEDBB9F5B0D82CCCE891D4B19300170CEE0", "hash_pe256": "F4A15E80752CAC68593BDC6E49641DEDF9C6A0F6BD933A4AF38AD4D3600A26DD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Download/Upload Host", "meta_original_filename": "BackgroundTransferHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/f393d6fbcbbe46cc63c7996d0f35763ba46e512cc18adc3ead71855c59bab946/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\BackgroundTransferHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "bitsadmin.exe-AA6DA383C2B8E0C8CCE3EEE077B9877F": { "file_name": "bitsadmin.exe", "file_path": "C:\\Windows\\SysWOW64\\bitsadmin.exe", "hash_md5": "AA6DA383C2B8E0C8CCE3EEE077B9877F", "hash_sha1": "20822754E83C605FA73131D42C44A0641E3472C1", "hash_sha256": "4ADC7B6E2E43726EFF05BB3FF3DF554F8427AB093EF3EFED6A425769BD52F158", "hash_sha384": "D7F9A79BAF045D55E89D1F6AA8CE88D76A4CA9036734F82EADD843A51DF3347D1FD5C74ACD34BA5046D7156225F929F8", "hash_sha512": "C7B48F99D95EA662933F9FA278862F99D9168BD51CC28F69E70D132B21429AEDC3C62009F2385222E033A2271C7A3EDC645CA1A3693C365768B18BFC6B841A1E", "hash_ssdeep": "3072:c356+YK8tJONgEjX0S9JnQtJRHmMF0se0jMIX:REAS/SXGM/R3", "hash_imp": "624396CC8A12A6CA65B0467CE6DD9FD3", "hash_pesha1": "ABA984FEB5A599DD55590F98C7546F3E54FCAA89", "hash_pe256": "BB577849C929F31510573B4B2BFE47E9AF5A9FC6B51051D29E45563C8F0574C6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BITS administration utility", "meta_original_filename": "bitsadmin.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.8.17763.1 (WinBuild.160101.0800)", "meta_product_version": "7.8.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/4adc7b6e2e43726eff05bb3ff3df554f8427ab093ef3efed6a425769bd52f158/detection/", "output": "\r\nBITSADMIN version 3.0\r\nBITS administration utility.\r\n(C) Copyright Microsoft Corp.\r\n\r\nInvalid command\r\nUSAGE: BITSADMIN [/RAWRETURN] [/WRAP | /NOWRAP] command\r\nThe following commands are available:\r\n\r\n/HELP Prints this help \r\n/? Prints this help \r\n/UTIL /? Prints the list of utilities commands \r\n/PEERCACHING /? Prints the list of commands to manage Peercaching\r\n/CACHE /? Prints the list of cache management commands \r\n/PEERS /? Prints the list of peer management commands\r\n\r\n/LIST [/ALLUSERS] [/VERBOSE] List the jobs\r\n/MONITOR [/ALLUSERS] [/REFRESH sec] Monitors the copy manager\r\n/RESET [/ALLUSERS] Deletes all jobs in the manager\r\n\r\n/TRANSFER <job name> [type] [/PRIORITY priority] [/ACLFLAGS flags] [/DYNAMIC] \r\n remote_url local_name\r\n Transfers one of more files.\r\n [type] may be /DOWNLOAD or /UPLOAD; default is download\r\n Multiple URL/file pairs may be specified.\r\n Unlike most commands, <job name> may only be a name and not a GUID.\r\n /DYNAMIC configures the job with BITS_JOB_PROPERTY_DYNAMIC_CONTENT, which relaxes the server-side requirements.\r\n\r\n/CREATE [type] <job name> Creates a job\r\n [type] may be /DOWNLOAD, /UPLOAD, or /UPLOAD-REPLY; default is download\r\n Unlike most commands, <job name> may only be a name and not a GUID.\r\n\r\n/INFO <job> [/VERBOSE] Displays information about the job\r\n/ADDFILE <job> <remote_url> <local_name> Adds a file to the job\r\n/ADDFILESET <job> <textfile> Adds multiple files to the job\r\n Each line of <textfile> lists a file's remote name and local name, separated\r\n by spaces. A line beginning with '#' is treated as a comment.\r\n Once the file set is read into memory, the contents are added to the job.\r\n\r\n/ADDFILEWITHRANGES <job> <remote_url> <local_name range_list>\r\n Like /ADDFILE, but BITS will read only selected byte ranges of the URL.\r\n range_list is a comma-delimited series of offset and length pairs.\r\n For example,\r\n\r\n 0:100,2000:100,5000:eof\r\n\r\n instructs BITS to read 100 bytes starting at offset zero, 100 bytes starting\r\n at offset 2000, and the remainder of the URL starting at offset 5000.\r\n\r\n/REPLACEREMOTEPREFIX <job> <old_prefix> <new_prefix>\r\n All files whose URL begins with <old_prefix> are changed to use <new_prefix>\r\n\r\nNote that BITS currently supports HTTP/HTTPS downloads and uploads.\r\nIt also supports UNC paths and file:// paths as URLS\r\n\r\n/LISTFILES <job> Lists the files in the job\r\n/SUSPEND <job> Suspends the job\r\n/RESUME <job> Resumes the job\r\n/CANCEL <job> Cancels the job\r\n/COMPLETE <job> Completes the job\r\n\r\n/GETTYPE <job> Retrieves the job type\r\n/GETACLFLAGS <job> Retrieves the ACL propagation flags\r\n\r\n/SETACLFLAGS <job> <ACL_flags> Sets the ACL propagation flags for the job\r\n O - OWNER G - GROUP \r\n D - DACL S - SACL \r\n\r\n Examples:\r\n bitsadmin /setaclflags MyJob OGDS\r\n bitsadmin /setaclflags MyJob OGD\r\n\r\n/GETBYTESTOTAL <job> Retrieves the size of the job\r\n/GETBYTESTRANSFERRED <job> Retrieves the number of bytes transferred\r\n/GETFILESTOTAL <job> Retrieves the number of files in the job\r\n/GETFILESTRANSFERRED <job> Retrieves the number of files transferred\r\n/GETCREATIONTIME <job> Retrieves the job creation time\r\n/GETMODIFICATIONTIME <job> Retrieves the job modification time\r\n/GETCOMPLETIONTIME <job> Retrieves the job completion time\r\n/GETSTATE <job> Retrieves the job state\r\n/GETERROR <job> Retrieves detailed error information\r\n/GETOWNER <job> Retrieves the job owner\r\n/GETDISPLAYNAME <job> Retrieves the job display name\r\n/SETDISPLAYNAME <job> <display_name> Sets the job display name\r\n/GETDESCRIPTION <job> Retrieves the job description\r\n/SETDESCRIPTION <job> <description> Sets the job description\r\n/GETPRIORITY <job> Retrieves the job priority\r\n/SETPRIORITY <job> <priority> Sets the job priority\r\n Priority usage choices:\r\n FOREGROUND \r\n HIGH\r\n NORMAL\r\n LOW\r\n/GETNOTIFYFLAGS <job> Retrieves the notify flags\r\n/SETNOTIFYFLAGS <job> <notify_flags> Sets the notify flags\r\n For more help on this option, please refer to the MSDN help page for SetNotifyFlags/GETNOTIFYINTERFACE <job> Determines if notify interface is registered\r\n/GETMINRETRYDELAY <job> Retrieves the retry delay in seconds\r\n/SETMINRETRYDELAY <job> <retry_delay> Sets the retry delay in seconds\r\n/GETNOPROGRESSTIMEOUT <job> Retrieves the no progress timeout in seconds\r\n/SETNOPROGRESSTIMEOUT <job> <timeout> Sets the no progress timeout in seconds\r\n/GETMAXDOWNLOADTIME <job> Retrieves the download timeout in seconds\r\n/SETMAXDOWNLOADTIME <job> <timeout> Sets the download timeout in seconds\r\n/GETERRORCOUNT <job> Retrieves an error count for the job\r\n\r\n/SETPROXYSETTINGS <job> <usage> Sets the proxy usage\r\n usage choices:\r\n PRECONFIG - Use the owner's default Internet settings.\r\n AUTODETECT - Force autodetection of proxy.\r\n NO_PROXY - Do not use a proxy server.\r\n OVERRIDE - Use an explicit proxy list and bypass list. \r\n Must be followed by a proxy list and a proxy bypass list.\r\n NULL or \"\" may be used for an empty proxy bypass list.\r\n Examples:\r\n bitsadmin /setproxysettings MyJob PRECONFIG\r\n bitsadmin /setproxysettings MyJob AUTODETECT\r\n bitsadmin /setproxysettings MyJob NO_PROXY\r\n bitsadmin /setproxysettings MyJob OVERRIDE proxy1:80 \"<local>\" \r\n bitsadmin /setproxysettings MyJob OVERRIDE proxy1,proxy2,proxy3 NULL \r\n\r\n/GETPROXYUSAGE <job> Retrieves the proxy usage setting\r\n/GETPROXYLIST <job> Retrieves the proxy list\r\n/GETPROXYBYPASSLIST <job> Retrieves the proxy bypass list\r\n\r\n/TAKEOWNERSHIP <job> Take ownership of the job\r\n\r\n/SETNOTIFYCMDLINE <job> <program_name> [program_parameters] \r\n Sets a program to execute for notification, and optionally parameters.\r\n The program name and parameters can be NULL.\r\n IMPORTANT: if parameters are non-NULL, then the program name should be the\r\n first parameter.\r\n\r\n Examples:\r\n bitsadmin /SetNotifyCmdLine MyJob c:\\winnt\\system32\\notepad.exe NULL\r\n bitsadmin /SetNotifyCmdLine MyJob c:\\callback.exe \"c:\\callback.exe parm1 parm2\" \r\n bitsadmin /SetNotifyCmdLine MyJob NULL NULL\r\n\r\n/GETNOTIFYCMDLINE <job> Returns the job's notification command line\r\n\r\n/SETCREDENTIALS <job> <target> <scheme> <username> <password>\r\n Adds credentials to a job.\r\n <target> may be either SERVER or PROXY\r\n <scheme> may be BASIC, DIGEST, NTLM, NEGOTIATE, or PASSPORT. \r\n\r\n/REMOVECREDENTIALS <job> <target> <scheme> \r\n Removes credentials from a job.\r\n/GETCUSTOMHEADERS <job> Gets the Custom HTTP Headers\r\n/SETCUSTOMHEADERS <job> <header1> <header2> <...> Sets the Custom HTTP Headers\r\n\r\n/GETHTTPMETHOD <job> Gets the HTTP verb to use.\r\n/SETHTTPMETHOD <job> <HTTPMethod> Sets the HTTP verb to use.\r\n\r\n/GETCLIENTCERTIFICATE <job> Gets the job's Client Certificate Information\r\n/SETCLIENTCERTIFICATEBYID <job> <store_location> <store_name> <hexa-decimal_cert_id>\r\n Sets a client authentication certificate to a job.\r\n <store_location> may be \r\n\t1(CURRENT_USER), 2(LOCAL_MACHINE), 3(CURRENT_SERVICE),\r\n\t4(SERVICES), 5(USERS), 6(CURRENT_USER_GROUP_POLICY),\r\n\t7(LOCAL_MACHINE_GROUP_POLICY) or 8(LOCAL_MACHINE_ENTERPRISE). \r\n\r\n/SETCLIENTCERTIFICATEBYNAME <job> <store_location> <store_name> <subject_name>\r\n Sets a client authentication certificate to a job.\r\n <store_location> may be \r\n\t1(CURRENT_USER), 2(LOCAL_MACHINE), 3(CURRENT_SERVICE),\r\n\t4(SERVICES), 5(USERS), 6(CURRENT_USER_GROUP_POLICY),\r\n\t7(LOCAL_MACHINE_GROUP_POLICY) or 8(LOCAL_MACHINE_ENTERPRISE). \r\n\r\n/REMOVECLIENTCERTIFICATE <job> Removes the Client Certificate Information from the job\r\n\r\n/SETSECURITYFLAGS <job> <value> \r\n Sets the HTTP security flags for URL redirection and checks performed on the server certificate during the transfer.\r\n The value is an unsigned integer with the following interpretation for the bits in the binary representation.\r\n Enable CRL Check : Set the least significant bit\r\n Ignore invalid common name in server certificate : Set the 2nd bit from right\r\n Ignore invalid date in server certificate : Set the 3rd bit from right\r\n Ignore invalid certificate authority in server\r\n certificate : Set the 4th bit from right\r\n Ignore invalid usage of certificate : Set the 5th bit from right\r\n Redirection policy : Controlled by the 9th-11th bits from right\r\n 0,0,0 - Redirects will be automatically allowed.\r\n 0,0,1 - Remote name in the IBackgroundCopyFile interface will be updated if a redirect occurs.\r\n 0,1,0 - BITS will fail the job if a redirect occurs.\r\n\r\n Allow redirection from HTTPS to HTTP : Set the 12th bit from right\r\n\r\n/GETSECURITYFLAGS <job> \r\n Reports the HTTP security flags for URL redirection and checks performed on the server certificate during the transfer.\r\n\r\n/SETVALIDATIONSTATE <job> <file-index> <true|false>\r\n <file-index> starts from 0 \r\n Sets the content-validation state of the given file within the job.\r\n\r\n/GETVALIDATIONSTATE <job> <file-index> \r\n <file-index> starts from 0 \r\n Reports the content-validation state of the given file within the job.\r\n\r\n/GETTEMPORARYNAME <job> <file-index> \r\n <file-index> starts from 0 \r\n Reports the temporary filename of the given file within the job.\r\n\r\nThe following options control peercaching of a particular job:\r\n\r\n/SETPEERCACHINGFLAGS <job> <value> \r\n Sets the flags for the job's peercaching behavior.\r\n The value is an unsigned integer with the following interpretation for the bits in the binary representation.\r\n Allow the job's data to be downloaded from a peer : Set the least significant bit\r\n Allow the job's data to be served to peers : Set the 2nd bit from right\r\n\r\n/GETPEERCACHINGFLAGS <job> \r\n Reports the flags for the job's peercaching behavior.\r\n\r\nThe following options are valid for UPLOAD-REPLY jobs only:\r\n\r\n/GETREPLYFILENAME <job> Gets the path of the file containing the server reply\r\n/SETREPLYFILENAME <job> <path> Sets the path of the file containing the server reply\r\n/GETREPLYPROGRESS <job> Gets the size and progress of the server reply\r\n/GETREPLYDATA <job> Dumps the server's reply data in hex format\r\n\r\n/SETHELPERTOKEN <job> Sets the current command prompt's primary token as a job's helper token\r\n/GETHELPERTOKENSID <job> Reports the user account SID of a job's helper token, if one is set\r\n\r\n/SETHELPERTOKENFLAGS <job> <flags> \r\n Sets the helper token usage flags for a job. Possible values are:\r\n 1 - The helper token is used when accessing the local filesystem.\r\n 2 - The helper token is used when accessing the network.\r\n 3 - The helper token is used when accessing both the local filesystem and the network.\r\n\r\n/GETHELPERTOKENFLAGS <job> \r\n Reports a job's helper token usage flags.\r\n\r\n/GETPEERSTATS <job> <file-index> \r\n <file-index> starts from 0 \r\n Reports statistics about the amount of data downloaded from peers and origin servers for a specific file within a job.\r\n\r\nThe following options can be placed before the command:\r\n/RAWRETURN Return data more suitable for parsing\r\n/WRAP Wrap output around console (default)\r\n/NOWRAP Don't wrap output around console\r\n\r\nThe /RAWRETURN option strips new line characters and formatting.\r\nIt is recognized by the /CREATE and /GET* commands.\r\n\r\nCommands that take a <job> parameter will accept either a job name or a job ID\r\nGUID inside braces. BITSADMIN reports an error if a name is ambiguous.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\bitsadmin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "bootcfg.exe-6736D6AAF20515889050140B0BEEF7D9": { "file_name": "bootcfg.exe", "file_path": "C:\\Windows\\SysWOW64\\bootcfg.exe", "hash_md5": "6736D6AAF20515889050140B0BEEF7D9", "hash_sha1": "8FA63A93E94C8EFB8E782F68D03653AD637FD1C5", "hash_sha256": "A599E319BC738B22EF91AA1A0770B823CF7AFFE2CEFB09E46421F614066C5D54", "hash_sha384": "FFE1165C7CB1F69A220F921DBA96F0DAE09DC307E2E96682975C5C5AB8C32C22CFBF33572ED7C5F75F274BA997E4A37F", "hash_sha512": "FF93E6199D1A1B219E07DCCAD5911D156C695483821F91B1D792C78979972DFFFA52A76AB2BF3049ACD2301587E3073612982420D3CCCF0A90CC8AB52B63BEF5", "hash_ssdeep": "1536:F5Qg8zImSkSO6W31OGqZ80xijfuwB1jsvXli3vJSozuql5JymifCbkcFa+pXT:d2SkXF1OGq20La1jsvlifJNt5EmifhcH", "hash_imp": "1326F3C4127B0B966C0872341E0A5A17", "hash_pesha1": "F21F5AEEF4CAEA1C20DF59F3A628CFBCBCFE553D", "hash_pe256": "CEA65BFB719140748BE54D9A2E72AC0D736AE96A2752F7E214F8E3075AA0B9E1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BootCfg - Lists or changes the boot settings.", "meta_original_filename": "bootcfg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/a599e319bc738b22ef91aa1a0770b823cf7affe2cefb09e46421f614066c5d54/detection/", "output": "\r\nBOOTCFG /parameter [arguments]\r\n\r\nDescription:\r\n This command line tool can be used to configure, query, change or \r\n delete the boot entry settings in the BOOT.INI file.\r\n\r\nParameter List:\r\n /Copy Makes a copy of an existing boot entry.\r\n\r\n /Delete Deletes an existing boot entry from the BOOT.INI file.\r\n\r\n /Query Displays the current boot entries and their settings.\r\n\r\n /Raw Allows the user to specify any switch to be added.\r\n\r\n /Timeout Allows the user to change the Timeout value.\r\n\r\n /Default Allows the user to change the Default boot entry.\r\n\r\n /EMS Allows the user to configure the /redirect switch\r\n for headless support.\r\n\r\n /Debug Allows the user to specify the port and baudrate for \r\n remote debugging.\r\n\r\n /Addsw Allows the user to add predefined switches.\r\n\r\n /Rmsw Allows the user to remove predefined switches.\r\n\r\n /Dbg1394 Allows the user to configure 1394 port for debugging.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n BOOTCFG /Copy /?\r\n BOOTCFG /Delete /?\r\n BOOTCFG /Query /?\r\n BOOTCFG /Raw /?\r\n BOOTCFG /Timeout /?\r\n BOOTCFG /EMS /?\r\n BOOTCFG /Debug /?\r\n BOOTCFG /Addsw /?\r\n BOOTCFG /Rmsw /?\r\n BOOTCFG /Dbg1394 /?\r\n BOOTCFG /Default /?\r\n BOOTCFG /?\r\n\r\nWARNING: BOOT.INI is used for boot options on Windows XP and earlier\r\n operating systems. Use the BCDEDIT command line tool to modify\r\n Windows Vista boot options.\r\n", "error": "ERROR: Invalid syntax.\r\nType \"BOOTCFG /?\" for usage.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\bootcfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "bthudtask.exe-2233C4A464523B33B42762ED74C9B88D": { "file_name": "bthudtask.exe", "file_path": "C:\\Windows\\SysWOW64\\bthudtask.exe", "hash_md5": "2233C4A464523B33B42762ED74C9B88D", "hash_sha1": "BFBC9B51DA48EE17E076FD2746E11B9BA1E1F881", "hash_sha256": "E7ABFE2896F3A3F7C71797535E2016AA24F1363482C1EB799A51E5B0444B8082", "hash_sha384": "D5C1FF51C2A42D2C05FC7E7298F04DA41A7AF78B4EDACD878D239D8EED3ADF07D7257754C84331BA9AC1655FE973F4B5", "hash_sha512": "1DF700161D65F4951A2A5E4704D5C240BAB2BAE9AA182ABF13F205A7C00771B488BD1A3B00D4EFD7948AAFAE729A60A378CF58051978860A9209D3D6DB12D920", "hash_ssdeep": "384:S0WfYNIht5jVS6EZY3BhWWwHWeKJajXDO1/EagS817lS1:S0WfYij5T3By/zDO5", "hash_imp": "AB106F86DFB187B013004B44C843D3E8", "hash_pesha1": "D70B5DB80772C28DF175DF85F17CDE7DA7884C90", "hash_pe256": "A479BB8AC19AEA34C7F9E2F179B039684648FB5565C3FB3E9CE5AFDB6D745579", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Bluetooth Uninstall Device Task", "meta_original_filename": "BthUdTask.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/e7abfe2896f3a3f7c71797535e2016aa24f1363482c1eb799a51e5b0444b8082/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\bthudtask.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ByteCodeGenerator.exe-7CA75F27A3DF55D60DDB4A563EF066EA": { "file_name": "ByteCodeGenerator.exe", "file_path": "C:\\Windows\\SysWOW64\\ByteCodeGenerator.exe", "hash_md5": "7CA75F27A3DF55D60DDB4A563EF066EA", "hash_sha1": "EB0C6B7E68C9211C1CD2CF32184F0F4E4BCEF4AF", "hash_sha256": "A0BB35738D10A16190F279A30C27E1E217A5E121EC0B2A2608506DD107342C6A", "hash_sha384": "4061BAAAE0FA6EE3B6397D08A3245BD645A6F0968B36E19D1CE77DB2587FDC11EE5F356293DDE3DFE9F3495C8ACE74EB", "hash_sha512": "84F340D5B47C299B6085167D0729E1AEE9C8773CC05B005626F9B8895B249EFA3D3E6BE9B88C5CA548766ADDCC589832C3C56BB59CF499C933786FA6A6F77C59", "hash_ssdeep": "1536:prn6AzKc+c9fNBtBjftarv0T5YpCK0fM23B3:pr6AzTtdYru1rx3", "hash_imp": "BC8C627D82F56569B4B2686ED2E1AF03", "hash_pesha1": "6303337D1FA9FB893AD2CA78DA9570BC091A74A3", "hash_pe256": "FDA304188F40452B6E8BFB133BDDE6B88220CBBCDD6E4866C80592B9009F0DA5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AppX Deployment Bytecode Generator EXE", "meta_original_filename": "BytecodeGenerator.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/a0bb35738d10a16190f279a30c27e1e217a5e121ec0b2a2608506dd107342c6a/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ByteCodeGenerator.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cacls.exe-E1FF71AB0680F2043DC70A4DA64A4384": { "file_name": "cacls.exe", "file_path": "C:\\Windows\\SysWOW64\\cacls.exe", "hash_md5": "E1FF71AB0680F2043DC70A4DA64A4384", "hash_sha1": "73EC42332FE02036E5D18A76BCEC9F281456FF2C", "hash_sha256": "BC42118AAA1877EEFF34B9A93DCA8B94ED50109FB6436AE22E27D8E3B2BCA78F", "hash_sha384": "4ACBF18E4056D99356968D5E6EF77AB14626755224B50A0FD64A1C4C54125985724F489FB6408D8170621CAA7F1EDF19", "hash_sha512": "2B2422D3F36964771398164E50B1B80D14F41C82C30AE2D8552534AFCEC0123CB81028205C4148F4A55853D7EBF5917E1DCF6DC89F4624C581E0ECB146FE0C5A", "hash_ssdeep": "384:5SC64JchhMN4djZ8aN62ym/mBEGRVYg3d1FLZBFvZhmi0DqGwNR9WXDWH:A4JchtZjA2nmEivHpeDqGwaI", "hash_imp": "29323867CDC9A8BC7E9164C47C4E0B13", "hash_pesha1": "51889B7ABB53080A5D46119678ACFFD626CF7E91", "hash_pe256": "6143891A3A5300760AD6604E77E05DA6166AB4D5454FC8AFBEC768CD8CFD9988", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Control ACLs Program", "meta_original_filename": "CACLS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/bc42118aaa1877eeff34b9a93dca8b94ed50109fb6436ae22e27d8e3b2bca78f/detection/", "output": "\r\r\n NOTE: Cacls is now deprecated, please use Icacls.\r\r\n\r\r\n Displays or modifies access control lists (ACLs) of files\r\r\n\r\r\n CACLS filename [/T] [/M] [/L] [/S[:SDDL]] [/E] [/C] [/G user:perm]\r\r\n [/R user [...]] [/P user:perm [...]] [/D user [...]]\r\r\n filename Displays ACLs.\r\r\n /T Changes ACLs of specified files in\r\r\n the current directory and all subdirectories.\r\r\n /L Work on the Symbolic Link itself versus the target\r\r\n /M Changes ACLs of volumes mounted to a directory\r\r\n /S Displays the SDDL string for the DACL.\r\r\n /S:SDDL Replaces the ACLs with those specified in the SDDL string\r\r\n (not valid with /E, /G, /R, /P, or /D).\r\r\n /E Edit ACL instead of replacing it.\r\r\n /C Continue on access denied errors.\r\r\n /G user:perm Grant specified user access rights.\r\r\n Perm can be: R Read\r\r\n W Write\r\r\n C Change (write)\r\r\n F Full control\r\r\n /R user Revoke specified user's access rights (only valid with /E).\r\r\n /P user:perm Replace specified user's access rights.\r\r\n Perm can be: N None\r\r\n R Read\r\r\n W Write\r\r\n C Change (write)\r\r\n F Full control\r\r\n /D user Deny specified user access.\r\r\n Wildcards can be used to specify more than one file in a command.\r\r\n You can specify more than one user in a command.\r\r\n\r\r\n Abbreviations:\r\r\n CI - Container Inherit.\r\r\n The ACE will be inherited by directories.\r\r\n OI - Object Inherit.\r\r\n The ACE will be inherited by files.\r\r\n IO - Inherit Only.\r\r\n The ACE does not apply to the current file/directory.\r\r\n ID - Inherited.\r\r\n The ACE was inherited from the parent directory's ACL.\r\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\cacls.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "calc.exe-60FF7F830695B46E4E978968D9A995FE": { "file_name": "calc.exe", "file_path": "C:\\Windows\\SysWOW64\\calc.exe", "hash_md5": "60FF7F830695B46E4E978968D9A995FE", "hash_sha1": "B24FDB248D36D0AB86675169414AB8FED4A21A88", "hash_sha256": "381A38D6E7A146B99E2BE866B9E95FFE31F0DCFCEC62272C7C0D6B7114C9227F", "hash_sha384": "50DEE8E0221BFC188A90C1F206FDE459C2C9E76BA229C8501CAD99B617AE3E264CF7C1FF8D6C63069FDE7BDC3197A723", "hash_sha512": "F5D5AF45DAC59C4F2602F13608C7F346D114A1E4A5D12B029D75D970E0CB6CFCF39AD3F5B49FAC08CDCF036A2C02EABFCFEA828F3808F1033ADDD245C1000AB7", "hash_ssdeep": "384:dz6kMrov88/sYWS0YWbiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiLiiiiiriiiI:dV7/s1G", "hash_imp": "BA072A972FE6C47C8CF7A0347BB0AF7A", "hash_pesha1": "12478E95FC8A1BEF2D99344A17AF7C97481104E7", "hash_pe256": "5023ED42968DA7B12DC4343CA409741A2222DD9F68289765BCB2783A30FDC168", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Calculator", "meta_original_filename": "CALC.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/381a38d6e7a146b99e2be866b9e95ffe31f0dcfcec62272c7c0d6b7114c9227f/detection/", "children": "win32calc.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\calc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "CameraSettingsUIHost.exe-443AFE0E4385A46CFE2AD14890DC1FD4": { "file_name": "CameraSettingsUIHost.exe", "file_path": "C:\\Windows\\SysWOW64\\CameraSettingsUIHost.exe", "hash_md5": "443AFE0E4385A46CFE2AD14890DC1FD4", "hash_sha1": "BE8E58B409B6D4C7FB08762D8E0C499677DC8522", "hash_sha256": "463180573F43CC8A3C2879E9AE442D751D1B9541C8E81A547FB6449D3E5DD2B5", "hash_sha384": "1337C388C8D861C691B0F4D0D6B706C00D9B4E15762C7AD9A948E2365147C3920781B2CD98134082945325EB3704C516", "hash_sha512": "5DF6523257790DF6F08286F43E1597392C493BBAC04D9A63282E5322962D81238AB720816F8A412A81484F72E48EEC6950653CEDB11D3C784360BC935A88A72E", "hash_ssdeep": "384:3V50X9btA8aEdAhh24jHxHvzY+7Qg2qXp0BTW+dW0PAmXjDBRJQ9gl3t3M2U:3T0NbtAIda2+ExBN3pXj1Py/r", "hash_imp": "6EFFC501FA8CD22D12C091494401AE22", "hash_pesha1": "1FCC2329BB8F3967D4246A75C0B67AC2C8ED2FB1", "hash_pe256": "F732C3397A38CD1B13641AB2CDF78E769FA933A9A55097E667334102A60D0327", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Camera Settings UI Host", "meta_original_filename": "CameraSettingsUIHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/463180573f43cc8a3c2879e9ae442d751d1b9541c8e81a547fb6449d3e5dd2b5/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECA50": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\CameraSettingsUIHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "CertEnrollCtrl.exe-56808A6D43D550A1999E1D729BE77C0F": { "file_name": "CertEnrollCtrl.exe", "file_path": "C:\\Windows\\SysWOW64\\CertEnrollCtrl.exe", "hash_md5": "56808A6D43D550A1999E1D729BE77C0F", "hash_sha1": "A75F3BA116CC24E63CF454C20C32FC65635BFAD2", "hash_sha256": "8DE895A62785C1294F402260671CFDBB2223E3448947C3ACE893B8A298A1D37A", "hash_sha384": "94272C1AF3CE6C5E281882115A800D24AC05A97522F5A45E9205D4CCB17B35519AA204B1B54C7B9B3A761BB7F09856F4", "hash_sha512": "D47E6C3C57330D7B67779D4529F1B51BC766053737C4A3AE6BF316CB66E68C52BB15FD0EBD5BC7A8155DABD3500C48F45FB9361F91CFB59EDB1898C210455DE9", "hash_ssdeep": "768:s8tcJ5+iavKHTiPgnwmhHx4RbrbKB1+YAfAihZmt5nBo6K:70PHOonwmBxMNZmt5n/", "hash_imp": "53BFF466353268C27743D2EE8757D592", "hash_pesha1": "E617747888D4AE6F8CDE1954E7808A550BFDD8D6", "hash_pe256": "6D87E9640941AF761302B4CB758B2B56972E71265FD34C7AAA4FF1E401290D94", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Certificate Enrollment Control", "meta_original_filename": "EnrollComServer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/8de895a62785c1294f402260671cfdbb2223e3448947c3ace893b8a298a1d37a/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\CertEnrollCtrl.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC4C8": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\CertEnrollCtrl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "certreq.exe-05E63A152974EA6DBDA31CAFB7B7FAAA": { "file_name": "certreq.exe", "file_path": "C:\\Windows\\SysWOW64\\certreq.exe", "hash_md5": "05E63A152974EA6DBDA31CAFB7B7FAAA", "hash_sha1": "6DC909C799328C27431E5ADD58D84A3B80DDE0B1", "hash_sha256": "D973513E4C048829EA1281A7C57A4C352A366B5B8FC9E39F177781AF68E36396", "hash_sha384": "8FC6F2C0CEAD132597667FE10E2C255BBDB6E210FA98962590BCA816B7B67A7E08E833B68E976044725FE12E14816851", "hash_sha512": "6D355F45D4142673048AC0DF8702BB08B90935723C5CCEC31A87E2B53BF9843B9E9BE70678DE34A7E42D2059B58183A581E567261954A605C6EC78CC7CCAC81A", "hash_ssdeep": "6144:q2bcvB1l7GpOKAlGNFc0GogbH2Z1VTrj5IwWJtbi+KATSr5F3NC9Nl+:qCil7Ejc0hgbe1VTrywP+VSL9CXl+", "hash_imp": "F66C876B7855BFF538606AE262764AC3", "hash_pesha1": "116B8C7FD1114D05B2F38E80C156DAE6BE76135E", "hash_pe256": "35C4578B14BC0E63A52AC355E00A99DDE078EB2790852DE8D40B75AC23B4C6D3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CertReq.exe", "meta_original_filename": "CertReq.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/d973513e4c048829ea1281a7c57a4c352a366b5b8fc9e39f177781af68e36396/detection/", "children": "conhost.exe", "output": "Usage:\r\r\n CertReq -?\r\r\n CertReq [-v] -?\r\r\n CertReq [-Command] -?\r\r\n\r\n CertReq [-Submit] [Options] [RequestFileIn [CertFileOut [CertChainFileOut [FullResponseFileOut]]]]\r\r\n Submit a request to a Certification Authority.\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -binary\r\r\n -PolicyServer PolicyServer\r\r\n -config ConfigString\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -crl\r\r\n -rpc\r\r\n -AdminForceMachine\r\r\n -RenewOnBehalfOf\r\r\n -NoChallenge\r\r\n\r\n CertReq -Retrieve [Options] RequestId [CertFileOut [CertChainFileOut [FullResponseFileOut]]]\r\r\n Retrieve a response to a previous request from a Certification Authority.\r\r\n\r\n Options:\r\r\n -binary\r\r\n -PolicyServer PolicyServer\r\r\n -config ConfigString\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -crl\r\r\n -rpc\r\r\n -AdminForceMachine\r\r\n\r\n CertReq -New [Options] [PolicyFileIn [RequestFileOut]]\r\r\n Create a new request as directed by PolicyFileIn\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -binary\r\r\n -cert CertId\r\r\n -PolicyServer PolicyServer\r\r\n -config ConfigString\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -pin Pin\r\r\n -user\r\r\n -machine\r\r\n -xchg ExchangeCertFile\r\r\n\r\n CertReq -Accept [Options] [CertChainFileIn | FullResponseFileIn | CertFileIn]\r\r\n Accept and install a response to a previous new request.\r\r\n\r\n Options:\r\r\n -user \r\r\n -machine \r\r\n -pin Pin\r\r\n\r\n CertReq -Policy [Options] [RequestFileIn [PolicyFileIn [RequestFileOut [PKCS10FileOut]]]]\r\r\n Construct a cross certification or qualified subordination request\r\r\n from an existing CA certificate or from an existing request.\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -binary\r\r\n -cert CertId\r\r\n -PolicyServer PolicyServer\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -pin Pin\r\r\n -noEKU\r\r\n -AlternateSignatureAlgorithm\r\r\n -HashAlgorithm HashAlgorithm\r\r\n\r\n CertReq -Sign [Options] [RequestFileIn [RequestFileOut]]\r\r\n Sign a certificate request with an enrollment agent or qualified\r\r\n subordination signing certificate.\r\r\n\r\n Options:\r\r\n -binary\r\r\n -cert CertId\r\r\n -PolicyServer PolicyServer\r\r\n -Anonymous\r\r\n -Kerberos\r\r\n -ClientCertificate ClientCertId\r\r\n -UserName UserName\r\r\n -p Password\r\r\n -pin Pin\r\r\n -crl\r\r\n -noEKU\r\r\n -HashAlgorithm HashAlgorithm\r\r\n\r\n CertReq -Enroll [Options] TemplateName\r\r\n CertReq -Enroll -cert CertId [Options] Renew [ReuseKeys]\r\r\n Enroll for or renew a certificate.\r\r\n\r\n Options:\r\r\n -PolicyServer PolicyServer\r\r\n -user \r\r\n -machine \r\r\n -pin Pin\r\r\n\r\n CertReq -EnrollAIK [Options] [KeyContainerName]\r\r\n Enroll for AIK certificate.\r\r\n\r\n Options:\r\r\n -config\r\r\n\r\n CertReq -EnrollCredGuardCert [Options] TemplateName [ExtensionInfFile]\r\r\n NOTE: Enrolling for machine account Credential Guard certificate is not supported on this platform.\r\r\n\r\n Options:\r\r\n Not supported on this platform\r\r\n\r\n CertReq -EnrollLogon [Options]\r\r\n Enroll for Hello for Business Logon certificate via ADFS.\r\r\n\r\n Options:\r\r\n -q\r\r\n\r\n CertReq -Post [Options]\r\r\n POST an http request.\r\r\n\r\n Options:\r\r\n -attrib AttributeString\r\r\n -config URL\r\r\n\r\nUnknown argument: --help\r\n", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\certreq.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\certreq.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Certificate Request Processor" }, "certutil.exe-FD60D24DDCCDFAE396F0D2349F040484": { "file_name": "certutil.exe", "file_path": "C:\\Windows\\SysWOW64\\certutil.exe", "hash_md5": "FD60D24DDCCDFAE396F0D2349F040484", "hash_sha1": "84749205782385FAC1B22B21BA0CA401E744EEB9", "hash_sha256": "555A8B4B7C5E9614E3EF7AF2FAFC6181AA98AD9D10EBFD845D82F33EFEB7E1C7", "hash_sha384": "9B3C4E6CF74C2A032886CEA3A699C41F95C0C019C6F6D7F752DEDC4F4E55E7F424939E01C9147D116F10E661A9D0EB73", "hash_sha512": "8A4E6BCFD7AD9109790C891AAA07F3A27E1A57F860F67691D7F91AD74A167CC31BF48549B0FD229004B5F29073189378EB68C33548C86CE42C86AC44CC7B5544", "hash_ssdeep": "24576:tZ4ktHwWTlP5eyZ7fdfZVPta42p2g4qJGY07glXtyxDivUvrr1IJbTVrgYL2lzUb:tRxBdlO2g4l7cMDwLL2lABh3", "hash_imp": "E8D77122DFEFBA52E492A9E89B1F9BEB", "hash_pesha1": "CCA99A0725E710E5F5FC5198C754A46FE097B963", "hash_pe256": "74903DFA2934DBCCB7039223628B6952F84A1043989A2228151051002CD20762", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CertUtil.exe", "meta_original_filename": "CertUtil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/555a8b4b7c5e9614e3ef7af2fafc6181aa98ad9d10ebfd845d82f33efeb7e1c7/detection/", "output": "\r\nVerbs:\r\n -dump -- Dump configuration information or file\r\n -dumpPFX -- Dump PFX structure\r\n -asn -- Parse ASN.1 file\r\n\r\n -decodehex -- Decode hexadecimal-encoded file\r\n -decode -- Decode Base64-encoded file\r\n -encode -- Encode file to Base64\r\n\r\n -deny -- Deny pending request\r\n -resubmit -- Resubmit pending request\r\n -setattributes -- Set attributes for pending request\r\n -setextension -- Set extension for pending request\r\n -revoke -- Revoke Certificate\r\n -isvalid -- Display current certificate disposition\r\n\r\n -getconfig -- Get default configuration string\r\n -ping -- Ping Active Directory Certificate Services Request interface\r\n -pingadmin -- Ping Active Directory Certificate Services Admin interface\r\n -CAInfo -- Display CA Information\r\n -ca.cert -- Retrieve the CA's certificate\r\n -ca.chain -- Retrieve the CA's certificate chain\r\n -GetCRL -- Get CRL\r\n -CRL -- Publish new CRLs [or delta CRLs only]\r\n -shutdown -- Shutdown Active Directory Certificate Services\r\n\r\n -installCert -- Install Certification Authority certificate\r\n -renewCert -- Renew Certification Authority certificate\r\n\r\n -schema -- Dump Certificate Schema\r\n -view -- Dump Certificate View\r\n -db -- Dump Raw Database\r\n -deleterow -- Delete server database row\r\n\r\n -backup -- Backup Active Directory Certificate Services\r\n -backupDB -- Backup Active Directory Certificate Services database\r\n -backupKey -- Backup Active Directory Certificate Services certificate and private key\r\n -restore -- Restore Active Directory Certificate Services\r\n -restoreDB -- Restore Active Directory Certificate Services database\r\n -restoreKey -- Restore Active Directory Certificate Services certificate and private key\r\n -importPFX -- Import certificate and private key\r\n -dynamicfilelist -- Display dynamic file List\r\n -databaselocations -- Display database locations\r\n -hashfile -- Generate and display cryptographic hash over a file\r\n\r\n -store -- Dump certificate store\r\n -enumstore -- Enumerate certificate stores\r\n -addstore -- Add certificate to store\r\n -delstore -- Delete certificate from store\r\n -verifystore -- Verify certificate in store\r\n -repairstore -- Repair key association or update certificate properties or key security descriptor\r\n -viewstore -- Dump certificate store\r\n -viewdelstore -- Delete certificate from store\r\n -UI -- invoke CryptUI\r\n -attest -- Verify Key Attestation Request\r\n\r\n -dsPublish -- Publish certificate or CRL to Active Directory\r\n\r\n -ADTemplate -- Display AD templates\r\n -Template -- Display Enrollment Policy templates\r\n -TemplateCAs -- Display CAs for template\r\n -CATemplates -- Display templates for CA\r\n -SetCASites -- Manage Site Names for CAs\r\n -enrollmentServerURL -- Display, add or delete enrollment server URLs associated with a CA\r\n -ADCA -- Display AD CAs\r\n -CA -- Display Enrollment Policy CAs\r\n -Policy -- Display Enrollment Policy\r\n -PolicyCache -- Display or delete Enrollment Policy Cache entries\r\n -CredStore -- Display, add or delete Credential Store entries\r\n -InstallDefaultTemplates -- Install default certificate templates\r\n -URLCache -- Display or delete URL cache entries\r\n -pulse -- Pulse autoenrollment event or NGC task\r\n -MachineInfo -- Display Active Directory machine object information\r\n -DCInfo -- Display domain controller information\r\n -EntInfo -- Display enterprise information\r\n -TCAInfo -- Display CA information\r\n -SCInfo -- Display smart card information\r\n\r\n -SCRoots -- Manage smart card root certificates\r\n\r\n -verifykeys -- Verify public/private key set\r\n -verify -- Verify certificate, CRL or chain\r\n -verifyCTL -- Verify AuthRoot or Disallowed Certificates CTL\r\n -syncWithWU -- Sync with Windows Update\r\n -generateSSTFromWU -- Generate SST from Windows Update\r\n -generatePinRulesCTL -- Generate Pin Rules CTL\r\n -downloadOcsp -- Download OCSP Responses and Write to Directory\r\n -generateHpkpHeader -- Generate HPKP header using certificates in specified file or directory\r\n -flushCache -- Flush specified caches in selected process, such as, lsass.exe\r\n -addEccCurve -- Add ECC Curve\r\n -deleteEccCurve -- Delete ECC Curve\r\n -displayEccCurve -- Display ECC Curve\r\n -sign -- Re-sign CRL or certificate\r\n\r\n -vroot -- Create/delete web virtual roots and file shares\r\n -vocsproot -- Create/delete web virtual roots for OCSP web proxy\r\n -addEnrollmentServer -- Add an Enrollment Server application\r\n -deleteEnrollmentServer -- Delete an Enrollment Server application\r\n -addPolicyServer -- Add a Policy Server application\r\n -deletePolicyServer -- Delete a Policy Server application\r\n -oid -- Display ObjectId or set display name\r\n -error -- Display error code message text\r\n -getreg -- Display registry value\r\n -setreg -- Set registry value\r\n -delreg -- Delete registry value\r\n\r\n -ImportKMS -- Import user keys and certificates into server database for key archival\r\n -ImportCert -- Import a certificate file into the database\r\n -GetKey -- Retrieve archived private key recovery blob, generate a recovery script,\r\n or recover archived keys\r\n -RecoverKey -- Recover archived private key\r\n -MergePFX -- Merge PFX files\r\n -ConvertEPF -- Convert PFX files to EPF file\r\n\r\n -add-chain -- (-AddChain) Add certificate chain\r\n -add-pre-chain -- (-AddPrechain) Add pre-certificate chain\r\n -get-sth -- (-GetSTH) Get signed tree head\r\n -get-sth-consistency -- (-GetSTHConsistency) Get signed tree head changes\r\n -get-proof-by-hash -- (-GetProofByHash) Get proof by hash\r\n -get-entries -- (-GetEntries) Get entries\r\n -get-roots -- (-GetRoots) Get roots\r\n -get-entry-and-proof -- (-GetEntryAndProof) Get entry and proof\r\n -VerifyCT -- Verify certificate SCT\r\n -? -- Display this usage message\r\n\r\n\r\nCertUtil -? -- Display a verb list (command list)\r\nCertUtil -dump -? -- Display help text for the \"dump\" verb\r\nCertUtil -v -? -- Display all help text for all verbs\r\n\r\nCertUtil: -? command completed successfully.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\certutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "change.exe-582214B45CA2404BE73109AE47A8A6C7": { "file_name": "change.exe", "file_path": "C:\\Windows\\SysWOW64\\change.exe", "hash_md5": "582214B45CA2404BE73109AE47A8A6C7", "hash_sha1": "A7774C5CB46E39E493D63CE1C32B66DD2353B503", "hash_sha256": "41DC113DA22BD4CF8454F12CD69E1B695FC2C78EE149EBC0DC02624425F00CA6", "hash_sha384": "1D89AC9E430012BB371E7EC98AC9EF22B96E7719D15FD28C9E34DDAA0B91E2B5B21AECF80763498E1440E552E0F46F51", "hash_sha512": "070C7346DE337F1EA9941209DCB10D5CDDC46D98D007032BB3B8BF07EDE920F093953386164A0E57BF01BE5B81E60136835BFF3BD49BBA236570A6E4ED1B41C3", "hash_ssdeep": "192:Ew0YSkgF5ne93NhfTqVc+1pd/1mt2WcogKkPWZLW7:EVxDe93NhfTqy+R/1qlg9PWZLW7", "hash_imp": "EC309FD93AE54D1FFDF17E744E71C366", "hash_pesha1": "F9D4A2E9893179E41475761E8A2E0BE81677DCF6", "hash_pe256": "B248CCAE3EFB3156139439BE1EC6E821DF1885A01002FAB11FC0C28D51643A69", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Services Change Utility", "meta_original_filename": "change.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/41dc113da22bd4cf8454f12cd69e1b695fc2c78ee149ebc0dc02624425f00ca6/detection/", "output": "CHANGE { LOGON | PORT | USER }\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\change.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "Invalid parameter(s)\r\nCHANGE { LOGON | PORT | USER }\r\n" }, "charmap.exe-B21D8C4FBAF5C9324EA279F4EE38D733": { "file_name": "charmap.exe", "file_path": "C:\\Windows\\SysWOW64\\charmap.exe", "hash_md5": "B21D8C4FBAF5C9324EA279F4EE38D733", "hash_sha1": "A82068DE34D71C5C558B0782F0EA2429B347257F", "hash_sha256": "E3F7F0CC0CB19FAA1549B6648E16846E4D981F14E6B2B731C15B2E57D9D791C4", "hash_sha384": "CCB0036A2014567AB784F6FF6838193FB8BE5DD67092AC4C1DDE7DC07BA10C64F5AFA1D3BC3C7F2BBD6C636439613539", "hash_sha512": "E750FA7F7EEB2C4984A4164B5EA0B69E4FA2BF8D0574BDC53A824FF9D1DAE6E1862D3C34D758542016D4972816DC2FCA163671BD2F6E79F7CBA8299EE0AD8582", "hash_ssdeep": "3072:VgVkUh7btworuDENUTzAs6dgDnXIVbrLF5NUdrSO9K/tagbdDu5nBdeG:A7btIDENUTzAbdgDnYlbgqt5g5e", "hash_imp": "A2B8753C5EBB12172F2A39992D1E7973", "hash_pesha1": "C7DFA83B25EC15A36E85F2A918C74F9406AFFC2D", "hash_pe256": "26E8F07C52A7DF6412843856D255018CD1E54990D9FFF72AAA766D7BB595DDB6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Character Map", "meta_original_filename": "charmap.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/e3f7f0cc0cb19faa1549b6648e16846e4d981f14e6b2b731c15b2e57d9d791c4/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\charmap.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme966197582": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\RPC Control\\DSECDA0": "Section", "\\Sessions\\2\\BaseNamedObjects\\da0HWNDInterface:23045e": "Section", "(R--) C:\\Windows\\SysWOW64\\bopomofo.uce": "File", "(R--) C:\\Windows\\SysWOW64\\gb2312.uce": "File", "(R--) C:\\Windows\\SysWOW64\\ideograf.uce": "File", "(R--) C:\\Windows\\SysWOW64\\kanji_1.uce": "File", "(R--) C:\\Windows\\SysWOW64\\kanji_2.uce": "File", "(R--) C:\\Windows\\SysWOW64\\korean.uce": "File", "(R--) C:\\Windows\\SysWOW64\\ShiftJIS.uce": "File", "(R--) C:\\Windows\\SysWOW64\\SubRange.uce": "File", "(R-D) C:\\Windows\\System32\\en-US\\getuname.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\charmap.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Character Map" }, "CheckNetIsolation.exe-14E5BC4376305A12F0CB1CAA880CCA8F": { "file_name": "CheckNetIsolation.exe", "file_path": "C:\\Windows\\SysWOW64\\CheckNetIsolation.exe", "hash_md5": "14E5BC4376305A12F0CB1CAA880CCA8F", "hash_sha1": "611B406116CC0B4F5A321973CCE8DF4182910F7D", "hash_sha256": "BF557534CED01CF06A6D53C9B61CBE7668163C7B3AAB7BFF386FADA0F68A122E", "hash_sha384": "3C9B91F9B69BE30C3B69CC94D0DD98FA0AB0D03B6D44DAF24DB81D890FB3DEFDC101C77D5E8338505A4A80FFBF7D6E18", "hash_sha512": "0E29B55C49DE00458D84802E48D45FB861399C2CB967B2D587432D562284E9FF91090121CE3D42DE2DB02A395EB42072416651594FDF95C6E6BB055C8E948091", "hash_ssdeep": "384:TUaax35t3/A2PUTqNL0aRqdKXLsJvIBRjHGCiTGNt8MAW77pOWMJv:TUacUelVRqdOhiTqt8MV7p8Jv", "hash_imp": "8C4B70B06FD4E738845E670CA5E4F39B", "hash_pesha1": "42DB6E1B5CE68B0A5726F2E3FF5D2589054A5168", "hash_pe256": "30EF1D5208D3C76189E4366CCE5E543641262BC06206C33EE59D5D2094D6C9FB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "AppContainer Network Isolation Diagnostic Tool", "meta_original_filename": "CheckNetIsolation.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/bf557534ced01cf06a6d53c9b61cbe7668163c7b3aab7bff386fada0f68a122e/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\CheckNetIsolation.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "output": "Error: Invalid Parameters\r\n\r\nUsage:\r\n CheckNetIsolation [Module]\r\n List Of Modules: \r\n LoopbackExempt - controls the loopback exemption of AppContainers\r\n and Package Families to ease application\r\n development.\r\n Debug - Starts a network traffic troubleshooting session\r\n of an AppContainer or Package Family. Generates a\r\n report of network capabilities that are used, not\r\n used or missing, together with the network traffic\r\n generated by the application.\r\n -? - Displays this help message.\r\n \r\n" }, "chglogon.exe-CFEE172286F48AA1A6A2B2AA3645F699": { "file_name": "chglogon.exe", "file_path": "C:\\Windows\\SysWOW64\\chglogon.exe", "hash_md5": "CFEE172286F48AA1A6A2B2AA3645F699", "hash_sha1": "1BD3492FBC72369F22749FB58197897B89222402", "hash_sha256": "AF8EFCA7D19796276A3B6A9FCB352A9B15B2626DDCE0EE0AEEABCD756CF3788E", "hash_sha384": "166A11919A72BD534BD12AE07259C957BA9869546241C5ED3AC1982097E462D475F8082571EB57F28FF92128918D5512", "hash_sha512": "005FC9B063EF1A237DC344B75916A6BCB0B47152A2C7619BA81DB0EA9A82C91A14AF683CC8AA0BCF7BEF79A1BA6868D48A1A872633751F12C3B5DE01645E5C7B", "hash_ssdeep": "384:s4pwPylhbRXSQJxDbLafHRzd2oc6W9EWp:npZxzar2Pxv", "hash_imp": "F6FC784018617DBB3B914E1E40B3A303", "hash_pesha1": "9F5F8B232FD5AC7D132F1EB1E4AC204B1277DA89", "hash_pe256": "1DA5C4C3C3A7A5D2DF598D76948BCBEB6E39CE2B578811128AC708B50325F649", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Logon Utility", "meta_original_filename": "chglogon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/af8efca7d19796276a3b6a9fcb352a9b15b2626ddce0ee0aeeabcd756cf3788e/detection/", "error": "Invalid parameter(s)\r\nEnable, disable, or drain session logins.\r\n\r\nCHANGE LOGON {/QUERY | /ENABLE | /DISABLE | /DRAIN | /DRAINUNTILRESTART}\r\n\r\n /QUERY Query current session login mode.\r\n /ENABLE Enable user login from sessions.\r\n /DISABLE Disable user login from sessions.\r\n /DRAIN Disable new user logons, but allow reconnections to existing sessions.\r\n /DRAINUNTILRESTART Disable new user logons until the server is restarted, but allow reconnections to existing sessions.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\chglogon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "chgport.exe-849721CF4D2163AA64F86E2F6968F089": { "file_name": "chgport.exe", "file_path": "C:\\Windows\\SysWOW64\\chgport.exe", "hash_md5": "849721CF4D2163AA64F86E2F6968F089", "hash_sha1": "EC86716154A7595AAC94DE054974C9F318155995", "hash_sha256": "7B58FD0E18BC8969CE5E5B3C790E032D7E29AF591F374075C645073C236B148D", "hash_sha384": "2691A250615B01DBCAFE8B5EC2F92F6B85C3E74CB1492FC695346CC044B75B89EEC39676B7B0A09C1DCEEBBF6A564455", "hash_sha512": "5458A30DAC3A4B5BAC9A489D66863B835EF45AD5DB6EC995684DA97A593829F84AB7911520580346F04DDF6CDD2563E6D373FA0DC3C1F3E6330BA1F8CADB963A", "hash_ssdeep": "384:v8N5YwthcLXn3ts/koKXWS21ot+xnEptG276MWUQWTW:v8N5/bcLK/J2+a5W", "hash_imp": "E9B09FFCE2C3B071390CDAC0EDA0A4F6", "hash_pesha1": "93E82D31D7B8469F3426FD3DB934022B54A610F7", "hash_pe256": "CAA2C8B2FD6CBADCA09244B2D6143CD5B72B67762F1524FBAD03942871CE6DA1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change port Utility", "meta_original_filename": "chgport.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/7b58fd0e18bc8969ce5e5b3c790e032d7e29af591f374075c645073c236b148d/detection/", "error": "Invalid parameter(s)\r\nList or change COM port mappings for DOS application compatibility.\r\n\r\nCHANGE PORT [portx=porty | /D portx | /QUERY]\r\n\r\n portx=porty Map port x to port y.\r\n /D portx Delete mapping for port x.\r\n /QUERY Display current mapping ports.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\chgport.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "chgusr.exe-9C35B63C99C6D7F66D80626636CF87E9": { "file_name": "chgusr.exe", "file_path": "C:\\Windows\\SysWOW64\\chgusr.exe", "hash_md5": "9C35B63C99C6D7F66D80626636CF87E9", "hash_sha1": "7E037CBE757C163994BD975FAD36DC065C620453", "hash_sha256": "1E393B27F64524042C49E1B34F1FC48389421E16169D7F08B205E810AD101074", "hash_sha384": "EA37F355938A6093F20ABAAD7064189887EE6939CFB2845DD8C18FC8128A71D6D6403EB6A82B7A3B5F0766F30F9BDE12", "hash_sha512": "9CD9FD73155CDCAF32EE0E2C351EF0D7F6FB99B9DA4BCCC7C8532242869F854C77964442A33B012C28AB771D4DDBD1A3F600027E8373A28FA277BBDCE7C02B23", "hash_ssdeep": "384:G0zNw4Ft1Rfq6SZGMpLsiSHLJ6qtvId2o5KWoVWZ:GGw8RfFMp5C6x2Ck", "hash_imp": "16ABF6D272567AB4C0C765D31B5E0B36", "hash_pesha1": "120599F7C6A549682E8B4F9690FF14BD6A0334CD", "hash_pe256": "C574675E7B8869D2687F31A0C698BA0FC5C9632DE3A8137ED9F9CCC5C47140C4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change INI File Mapping Utility", "meta_original_filename": "chgusr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/1e393b27f64524042c49e1b34f1fc48389421e16169d7f08b205e810ad101074/detection/", "output": "Change Install Mode.\r\n\r\nCHANGE USER {/EXECUTE | /INSTALL | /QUERY}\r\n\r\n /EXECUTE Enable execute mode (default).\r\n /INSTALL Enable install mode.\r\n /QUERY Display current settings.\r\n\r\n", "error": "Invalid parameter(s)\r\nChange Install Mode.\r\n\r\nCHANGE USER {/EXECUTE | /INSTALL | /QUERY}\r\n\r\n /EXECUTE Enable execute mode (default).\r\n /INSTALL Enable install mode.\r\n /QUERY Display current settings.\r\n\r\n" }, "chkdsk.exe-C9633D9EE3B603DBCA0D6DDCB8F14FAA": { "file_name": "chkdsk.exe", "file_path": "C:\\Windows\\SysWOW64\\chkdsk.exe", "hash_md5": "C9633D9EE3B603DBCA0D6DDCB8F14FAA", "hash_sha1": "8B3875E95DCE39D03DAEB25E183293EB2391652E", "hash_sha256": "0883578668BF5AA07BA2C4CFD8B0CCFCCDD048B8E741E5B3DE0C03AC84A09D2E", "hash_sha384": "15F60C5A4ACF9A6A98683D86C1FBE915D60579E8A17933BEFBF365549E8A4CD7D400E50ED865EE2ADF10DFC5445705CD", "hash_sha512": "BACF0740D09D8293E00828FEAF7666243DBCFD547B71D84A701E89717243EE4858DDB81107F8DFF92EEDEE1AECF6F5452C886C6CA91D277C0289544A19CCDE95", "hash_ssdeep": "384:QEmpq5pqD0YaJA/ujwZtzgHiCQk0yNBwHo0cjh5N6WSFFhWZn+oN:lmg54aJA/ujwZtzgHiC3RXZ0Y5yF0F", "hash_imp": "C74C32AF58B39ADAA7A52C5582724228", "hash_pesha1": "F0958B3382C123F31D26C51E30CE785320168300", "hash_pe256": "4048D1650E1E15E31BDF62342AA5A72324F6A70E140AC62D2BD684DF33F0E47B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Check Disk Utility", "meta_original_filename": "CHKDSK.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/0883578668bf5aa07ba2c4cfd8b0ccfccdd048b8e741e5b3de0c03ac84a09d2e/detection/", "output": "Checks a disk and displays a status report.\r\n\r\n\r\nCHKDSK [volume[[path]filename]]] [/F] [/V] [/R] [/X] [/I] [/C] [/L[:size]] [/B] [/scan] [/spotfix]\r\n\r\n\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name.\r\n filename FAT/FAT32 only: Specifies the files to check for\r\n fragmentation.\r\n /F Fixes errors on the disk.\r\n /V On FAT/FAT32: Displays the full path and name of every\r\n file on the disk.\r\n On NTFS: Displays cleanup messages if any.\r\n /R Locates bad sectors and recovers readable information\r\n (implies /F, when /scan not specified).\r\n /L:size NTFS only: Changes the log file size to the specified\r\n number of kilobytes. If size is not specified, displays\r\n current size.\r\n /X Forces the volume to dismount first if necessary.\r\n All opened handles to the volume would then be invalid\r\n (implies /F).\r\n /I NTFS only: Performs a less vigorous check of index\r\n entries.\r\n /C NTFS only: Skips checking of cycles within the folder\r\n structure.\r\n /B NTFS only: Re-evaluates bad clusters on the volume\r\n (implies /R)\r\n /scan NTFS only: Runs an online scan on the volume\r\n /forceofflinefix NTFS only: (Must be used with \"/scan\")\r\n Bypass all online repair; all defects found\r\n are queued for offline repair (i.e. \"chkdsk /spotfix\").\r\n /perf NTFS only: (Must be used with \"/scan\")\r\n Uses more system resources to complete a scan as fast as\r\n possible. This may have a negative performance impact on\r\n other tasks running on the system.\r\n /spotfix NTFS only: Runs spot fixing on the volume\r\n /sdcleanup NTFS only: Garbage collect unneeded security descriptor\r\n data (implies /F).\r\n /offlinescanandfix Runs an offline scan and fix on the volume.\r\n /freeorphanedchains FAT/FAT32/exFAT only: Frees any orphaned cluster chains\r\n instead of recovering their contents.\r\n /markclean FAT/FAT32/exFAT only: Marks the volume clean if no\r\n corruption was detected, even if /F was not specified.\r\n\r\nThe /I or /C switch reduces the amount of time required to run Chkdsk by\r\nskipping certain checks of the volume.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\chkdsk.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "chkntfs.exe-C7B3C2CDD7778366B007965BCB661147": { "file_name": "chkntfs.exe", "file_path": "C:\\Windows\\SysWOW64\\chkntfs.exe", "hash_md5": "C7B3C2CDD7778366B007965BCB661147", "hash_sha1": "5C8D77B7552C6325AFF417B398EB643696281947", "hash_sha256": "7F2C546AB66AA9AED47EEAD71170BDA9DB6D5ECD6CFDC0CE0A7BC80B92D157E8", "hash_sha384": "1B8C0D2DBC9B1F62418B605B69222B2E69BA7B0D9256E26CBE2B06555B59561BFB41EAE4C05606297401C19AC2B61829", "hash_sha512": "AB889DEE6CE6F1B4592969428788C4E82B61B364E133F5811AFE04982E348749EEBD7A111192A9C33EDA970046647BCD610EA23BFC676B728479984384F9C651", "hash_ssdeep": "384:JHo0S2ZwW8OmCh3ivEEUN0Wd6Wgjc0Kg:JNS2ZbmwyQlY", "hash_imp": "D0F4E345E64F27143A66B4C09C8B88D7", "hash_pesha1": "DEA0805CA18D170E99445C481A02B44A7971308E", "hash_pe256": "64BADC87AC5753C19AC0825226B90F9F3C9F9E0DDE6B1B7821315251828A209A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NTFS Volume Maintenance Utility", "meta_original_filename": "CHKNTFS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/7f2c546ab66aa9aed47eead71170bda9db6d5ecd6cfdc0ce0a7bc80b92d157e8/detection/", "output": "Displays or modifies the checking of disk at boot time.\r\n\r\nCHKNTFS volume [...]\r\nCHKNTFS /D\r\nCHKNTFS /T[:time]\r\nCHKNTFS /X volume [...]\r\nCHKNTFS /C volume [...]\r\n\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name.\r\n /D Restores the machine to the default behavior; all drives are\r\n checked at boot time and chkdsk is run on those that are\r\n dirty.\r\n /T:time Changes the AUTOCHK initiation countdown time to the\r\n specified amount of time in seconds. If time is not\r\n specified, displays the current setting.\r\n /X Excludes a drive from the default boot-time check. Excluded\r\n drives are not accumulated between command invocations.\r\n /C Schedules a drive to be checked at boot time; chkdsk will run\r\n if the drive is dirty.\r\n\r\nIf no switches are specified, CHKNTFS will display if the specified drive is\r\ndirty or scheduled to be checked on next reboot.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\chkntfs.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "choice.exe-D2255B85CA041A1B59D2B245374EFD04": { "file_name": "choice.exe", "file_path": "C:\\Windows\\SysWOW64\\choice.exe", "hash_md5": "D2255B85CA041A1B59D2B245374EFD04", "hash_sha1": "6C737FAA6B7DA3E605AF6612F92406526B1F1A68", "hash_sha256": "58900C00BA169518386D4F114A91EDEF83C2CC1040CC1A0210449F86B1104453", "hash_sha384": "1403BFA2D48D77732D6834FD23DC668A8AA81AB6084D85FD1C9F6DC42D6CED0520815D3F45637BEE60B94E45340A9DEF", "hash_sha512": "2A0E484D9C7C37DD158261FA0ECDF079A9FBCCA136AA9AFEB4A60652A0CAE09618B6EE54E0A5EF61CBEB9DA510ACB8ED1BEDB38F0C83B1BF4E2E49E69A05BE0D", "hash_ssdeep": "768:1rfF0eHcc1s2U+AnDLzGiX75W59NDah9VCxGrdHkV:1rfF0e8EhB0PzGilWBDah94xiHkV", "hash_imp": "A445244C63114214072FAF6C3DCE1438", "hash_pesha1": "49E48EB3AD533F34A2FC5D017D3BAF1556122ADF", "hash_pe256": "F8E0F458B7397A2C05A7C0614FB7C134C904E7CEBC93EF27518E2B1DEB332FB2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Offers the user a choice", "meta_original_filename": "choice.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/58900c00ba169518386d4f114a91edef83c2cc1040cc1a0210449f86b1104453/detection/", "output": "\r\nCHOICE [/C choices] [/N] [/CS] [/T timeout /D choice] [/M text]\r\n\r\nDescription:\r\n This tool allows users to select one item from a list \r\n of choices and returns the index of the selected choice.\r\n\r\nParameter List:\r\n /C choices Specifies the list of choices to be created.\r\n Default list is \"YN\".\r\n\r\n /N Hides the list of choices in the prompt.\r\n The message before the prompt is displayed\r\n and the choices are still enabled.\r\n\r\n /CS Enables case-sensitive choices to be selected.\r\n By default, the utility is case-insensitive.\r\n\r\n /T timeout The number of seconds to pause before a default \r\n choice is made. Acceptable values are from 0 to \r\n 9999. If 0 is specified, there will be no pause \r\n and the default choice is selected.\r\n\r\n /D choice Specifies the default choice after nnnn seconds.\r\n Character must be in the set of choices specified\r\n by /C option and must also specify nnnn with /T.\r\n\r\n /M text Specifies the message to be displayed before \r\n the prompt. If not specified, the utility \r\n displays only a prompt.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE:\r\n The ERRORLEVEL environment variable is set to the index of the\r\n key that was selected from the set of choices. The first choice\r\n listed returns a value of 1, the second a value of 2, and so on.\r\n If the user presses a key that is not a valid choice, the tool \r\n sounds a warning beep. If tool detects an error condition,\r\n it returns an ERRORLEVEL value of 255. If the user presses \r\n CTRL+BREAK or CTRL+C, the tool returns an ERRORLEVEL value\r\n of 0. When you use ERRORLEVEL parameters in a batch program, list\r\n them in decreasing order.\r\n\r\nExamples:\r\n CHOICE /?\r\n CHOICE /C YNC /M \"Press Y for Yes, N for No or C for Cancel.\"\r\n CHOICE /T 10 /C ync /CS /D y \r\n CHOICE /C ab /M \"Select a for option 1 and b for option 2.\"\r\n CHOICE /C ab /N /M \"Select a for option 1 and b for option 2.\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"CHOICE /?\" for usage.\r\n" }, "cipher.exe-A3630EF795BD7CFC6B2A7371A625A40B": { "file_name": "cipher.exe", "file_path": "C:\\Windows\\SysWOW64\\cipher.exe", "hash_md5": "A3630EF795BD7CFC6B2A7371A625A40B", "hash_sha1": "6A6B963F96D5471DD971A5945EFC095B82A03596", "hash_sha256": "BFFE1B9F0B4139C5FCBF318149E54B71DD53DAECF34D8E1F281549A02DE1F332", "hash_sha384": "ABE55BC6AA8EDEB3837410AFD3343BAA203D348BF6668C6DDFBB227D90D4100D292C17C2AF59C7527FE070EFB14DA0EA", "hash_sha512": "D2DD6FC5A6C297F721F90B1D2330776BE4B69587ED7B0D12155347D0DD65ABF30AC33E489F5D0C0C75124E224984A3B30EC7A6775AECE91062CFA7641A1FE959", "hash_ssdeep": "768:jIuxw8oIMaXnge2bDn5RBIM4WXZnuA+ZEYuozDYE:j/x+i3GvBF4ZABozDY", "hash_imp": "3709556898BEAA4E2B5F857FFA0F54BA", "hash_pesha1": "EA15B3BFC3A69CCC93C9828FFA7BF1D358E7FD20", "hash_pe256": "24A199EFB27A736C5E5BCEA197B1D1A25D27509A911B0529DE57AD1A02972474", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Encryption Utility", "meta_original_filename": "CIPHER.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/bffe1b9f0b4139c5fcbf318149e54b71dd53daecf34d8e1f281549a02de1f332/detection/", "output": "Displays or alters the encryption of directories [files] on NTFS partitions.\r\n\r\n CIPHER [/E | /D | /C]\r\n [/S:directory] [/B] [/H] [pathname [...]]\r\n\r\n CIPHER /K [/ECC:256|384|521]\r\n\r\n CIPHER /R:filename [/SMARTCARD] [/ECC:256|384|521]\r\n\r\n CIPHER /P:filename.cer\r\n\r\n CIPHER /U [/N]\r\n\r\n CIPHER /W:directory\r\n\r\n CIPHER /X[:efsfile] [filename]\r\n\r\n CIPHER /Y\r\n\r\n CIPHER /ADDUSER [/CERTHASH:hash | /CERTFILE:filename | /USER:username]\r\n [/S:directory] [/B] [/H] [pathname [...]]\r\n\r\n CIPHER /FLUSHCACHE [/SERVER:servername]\r\n\r\n CIPHER /REMOVEUSER /CERTHASH:hash\r\n [/S:directory] [/B] [/H] [pathname [...]]\r\n\r\n CIPHER /REKEY [pathname [...]]\r\n\r\n /B Abort if an error is encountered. By default, CIPHER continues\r\n executing even if errors are encountered.\r\n /C Displays information on the encrypted file.\r\n /D Decrypts the specified files or directories.\r\n /E Encrypts the specified files or directories. Directories will be\r\n marked so that files added afterward will be encrypted. The\r\n encrypted file could become decrypted when it is modified if the\r\n parent directory is not encrypted. It is recommended that you\r\n encrypt the file and the parent directory.\r\n /H Displays files with the hidden or system attributes. These files\r\n are omitted by default.\r\n /K Creates a new certificate and key for use with EFS. If this\r\n option is chosen, all the other options will be ignored.\r\n\r\n Note: By default, /K creates a certificate and key that conform\r\n to current group policy. If ECC is specified, a self-signed\r\n certificate will be created with the supplied key size.\r\n\r\n /N This option only works with /U. This will prevent keys being\r\n updated. This is used to find all the encrypted files on the\r\n local drives.\r\n /R Generates an EFS recovery key and certificate, then writes them\r\n to a .PFX file (containing certificate and private key) and a\r\n .CER file (containing only the certificate). An administrator may\r\n add the contents of the .CER to the EFS recovery policy to create\r\n the recovery key for users, and import the .PFX to recover\r\n individual files. If SMARTCARD is specified, then writes the\r\n recovery key and certificate to a smart card. A .CER file is\r\n generated (containing only the certificate). No .PFX file is\r\n generated.\r\n\r\n Note: By default, /R creates an 2048-bit RSA recovery key and\r\n certificate. If ECC is specified, it must be followed by a\r\n key size of 256, 384, or 521.\r\n\r\n /P Creates a base64-encoded recovery-policy blob from the passed-in\r\n certificate. This blob can be used to set DRA policy for\r\n MDM deployments.\r\n /S Performs the specified operation on the given directory and all\r\n files and subdirectories within it.\r\n /U Tries to touch all the encrypted files on local drives. This will\r\n update user's file encryption key or recovery keys to the current\r\n ones if they are changed. This option does not work with other\r\n options except /N.\r\n /W Removes data from available unused disk space on the entire\r\n volume. If this option is chosen, all other options are ignored.\r\n The directory specified can be anywhere in a local volume. If it\r\n is a mount point or points to a directory in another volume, the\r\n data on that volume will be removed.\r\n /X Backup EFS certificate and keys into file filename. If efsfile is\r\n provided, the current user's certificate(s) used to encrypt the\r\n file will be backed up. Otherwise, the user's current EFS\r\n certificate and keys will be backed up.\r\n /Y Displays your current EFS certificate thumbprint on the local PC.\r\n /ADDUSER Adds a user to the specified encrypted file(s). If CERTHASH is\r\n provided, cipher will search for a certificate with this SHA1\r\n hash. If CERTFILE is provided, cipher will extract the\r\n certificate from the file. If USER is provided, cipher will\r\n try to locate the user's certificate in Active Directory Domain\r\n Services.\r\n /FLUSHCACHE\r\n Clears the calling user's EFS key cache on the specified server.\r\n If servername is not provided, cipher clears the user's key cache\r\n on the local machine.\r\n /REKEY Updates the specified encrypted file(s) to use the configured\r\n EFS current key.\r\n /REMOVEUSER\r\n Removes a user from the specified file(s). CERTHASH must be the\r\n SHA1 hash of the certificate to remove.\r\n\r\n directory A directory path.\r\n filename A filename without extensions.\r\n pathname Specifies a pattern, file or directory.\r\n efsfile An encrypted file path.\r\n\r\n Used without parameters, CIPHER displays the encryption state of the\r\n current directory and any files it contains. You may use multiple directory\r\n names and wildcards. You must put spaces between multiple parameters.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\cipher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cleanmgr.exe-485C3639234C59ED6BF09F73704B110E": { "file_name": "cleanmgr.exe", "file_path": "C:\\Windows\\SysWOW64\\cleanmgr.exe", "hash_md5": "485C3639234C59ED6BF09F73704B110E", "hash_sha1": "84E544A280ADC90FF11FC047B14BF51EE6084DBA", "hash_sha256": "5502BC3DD8F997BEE50DBC9A3445C3B0E6407E916503589E3FDA06A8759C0DE3", "hash_sha384": "70D83A6F91F8D113617250CE5A34BD651CF7ACED2AF94E0DE7DB3C87302545D14B70CDA0C2D918147288473B5C55A7D5", "hash_sha512": "C371045F0C76EB563F95ED1D61BCADF1900AED980FC0D4AE3774D2E94DF4EE93DF8FE4207B919B9FCC840F533DBD965E16CD8CBF4423F9F50F894B5544B08E09", "hash_ssdeep": "3072:ldUsMg4kML0HAEPGRvQhRkKqUa9antF5hvvJkuXpeV0:s+S0gE+ohSKq99UF5hvv/", "hash_imp": "ED6B85CD7015D439B422F14335CB986C", "hash_pesha1": "6C7EAF11B530D0AD3075289B7C8816272517A6E2", "hash_pe256": "2398BA689893CCB294E5EFD4636223D0D1FBB33B2E796332FC6A8CAA12177B85", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Space Cleanup Manager for Windows", "meta_original_filename": "CLEANMGR.DLL", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/5502bc3dd8f997bee50dbc9a3445c3b0e6407e916503589e3fda06a8759c0de3/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\cleanmgr.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\cleanmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "USAGE" }, "cliconfg.exe-5924FC77AC5B646CCF8CEF54DBED2D69": { "file_name": "cliconfg.exe", "file_path": "C:\\Windows\\SysWOW64\\cliconfg.exe", "hash_md5": "5924FC77AC5B646CCF8CEF54DBED2D69", "hash_sha1": "75CC23EB3792D843D6E42614F2754DE9FB72F284", "hash_sha256": "656671D3874B77AABDFB3D1CC3B32703DA33DBE9E7711D645C4CC9C46E03C5D6", "hash_sha384": "0786BCC369D42FACA16682A16984F7DD987A1DC9FF48AE6FBC60239D675759B0F58F98E9E882A2911E843050D07C8653", "hash_sha512": "8A2E49BA0BA55DDB5D338C85C3B3AEF3FFCD52E03787B57FAF3429C24D55F87A912CA53418799EC8B7E88D92674CFA602348529BA682372200FFF090034AC751", "hash_ssdeep": "384:9GwGobCwk/63JWPwWsPXuNvBQAMYJQ2JQSkdowyohy:9ir63OKuI30lJBkvTh", "hash_imp": "0BDCEE28946450C424EEAF4F97F264EE", "hash_pesha1": "CA67D42E5003E1C352DBBA447EF7F17768434A2A", "hash_pe256": "2764807431D45E3696EF766FFFCA2CBA2105653FD5431E22E1C3356AE2359318", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SQL Client Configuration Utility EXE", "meta_original_filename": "cliconfg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/656671d3874b77aabdfb3d1cc3b32703da33dbe9e7711d645c4cc9c46e03c5d6/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\cliconfg.rll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_b4b635d36e735c2c": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.17763.1518_en-us_cac17eb89b198e19": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.17763.1518_en-us_cac17eb89b198e19\\comctl32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\cliconfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "SQL Server Client Network Utility" }, "clip.exe-2027FBB56BED959CD8E66C38866BE43D": { "file_name": "clip.exe", "file_path": "C:\\Windows\\SysWOW64\\clip.exe", "hash_md5": "2027FBB56BED959CD8E66C38866BE43D", "hash_sha1": "36F83DEFA499360A440F8379885B3A572416E505", "hash_sha256": "32F91B0CE7278E96F19B134722AB5260990D59D1B3381116BC5078B860AE57A8", "hash_sha384": "AD555738A50AA9D75F2C0FD6A3CFBA095B21F782857D4E5C4E3D70CA77CB837B51ABC37764BEF81CAFF0CFE9E6B3E7BA", "hash_sha512": "E1AD8B831762C6BBA90F1B5475CDA4817258B8E5341E05078DC48BE5C18C041F8DBC7E578C8D3BEBB8170E74B2094B404EC4D1C1B75BE3B9BB7D783717554B9F", "hash_ssdeep": "384:aOPcSYBilVtzqcbZPjAgt6XLyN0xNdGnlIG6wSYHFJMr6wFojNe0x+gnL3NQWPTa:aOPllVlqc17AgL0xTGlIG69YE+wFq3xt", "hash_imp": "2E4F8B6217B6FC3E22F837FF8337F26B", "hash_pesha1": "C4DCD4058AE6A55A400699583960BEBDE743D92D", "hash_pe256": "0C098042DD3A13A13BD394F16E265BA109BA50B31602C48FD023000B09CE663B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Clip - copies the data into clipboard", "meta_original_filename": "clip.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/32f91b0ce7278e96f19b134722ab5260990d59d1b3381116bc5078b860ae57a8/detection/", "output": "\r\nCLIP\r\n\r\nDescription:\r\n Redirects output of command line tools to the Windows clipboard.\r\n This text output can then be pasted into other programs.\r\n\r\nParameter List:\r\n /? Displays this help message.\r\n\r\nExamples:\r\n DIR | CLIP Places a copy of the current directory\r\n listing into the Windows clipboard.\r\n\r\n CLIP < README.TXT Places a copy of the text from readme.txt\r\n on to the Windows clipboard.\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"CLIP /?\" for usage.\r\n" }, "cmd.exe-C43699F84A68608E7E57C43B7761BBB8": { "file_name": "cmd.exe", "file_path": "C:\\Windows\\SysWOW64\\cmd.exe", "hash_md5": "C43699F84A68608E7E57C43B7761BBB8", "hash_sha1": "E2EAD0993B917E1828A658ADA0B87E01D5B8424F", "hash_sha256": "2EDB180274A51C83DDF8414D99E90315A9047B18C51DFD070326214D4DA59651", "hash_sha384": "0C8FF1036BB31C6D06BF6166E7A8DC1B944C26889ACED1743CB36CF86B3ED7A74D345A92C35EB90302B4ED62EF8AA6B3", "hash_sha512": "206E34AA4AE6E9BC82DDA01FE3912D70D3654573EA21E9D03A1A0112A6AF405290294B9B30E4533737E321ADC0A7CF0660399A8DB7AC0900593804798ACF8B4C", "hash_ssdeep": "6144:+jlxsNrZ64JZEj2Xnj9ppi/FGnZaUtzmig:+jlArg4J5p/Bpz", "hash_imp": "392B4D61B1D1DADC1F06444DF258188A", "hash_pesha1": "FCC8F3D5679C4BB78C9B0DD630F2A79676FCF77C", "hash_pe256": "B903F5021724BEB8A1835AA6069F8F1149722220194129A16739C724FC171D9D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Command Processor", "meta_original_filename": "Cmd.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.592 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.592", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/2edb180274a51c83ddf8414d99e90315a9047b18c51dfd070326214d4da59651/detection/", "output": "Starts a new instance of the Windows command interpreter\r\n\r\nCMD [/A | /U] [/Q] [/D] [/E:ON | /E:OFF] [/F:ON | /F:OFF] [/V:ON | /V:OFF]\r\n [[/S] [/C | /K] string]\r\n\r\n/C Carries out the command specified by string and then terminates\r\n/K Carries out the command specified by string but remains\r\n/S Modifies the treatment of string after /C or /K (see below)\r\n/Q Turns echo off\r\n/D Disable execution of AutoRun commands from registry (see below)\r\n/A Causes the output of internal commands to a pipe or file to be ANSI\r\n/U Causes the output of internal commands to a pipe or file to be\r\n Unicode\r\n/T:fg Sets the foreground/background colors (see COLOR /? for more info)\r\n/E:ON Enable command extensions (see below)\r\n/E:OFF Disable command extensions (see below)\r\n/F:ON Enable file and directory name completion characters (see below)\r\n/F:OFF Disable file and directory name completion characters (see below)\r\n/V:ON Enable delayed environment variable expansion using ! as the\r\n delimiter. For example, /V:ON would allow !var! to expand the\r\n variable var at execution time. The var syntax expands variables\r\n at input time, which is quite a different thing when inside of a FOR\r\n loop.\r\n/V:OFF Disable delayed environment expansion.\r\n\r\nNote that multiple commands separated by the command separator '&&'\r\nare accepted for string if surrounded by quotes. Also, for compatibility\r\nreasons, /X is the same as /E:ON, /Y is the same as /E:OFF and /R is the\r\nsame as /C. Any other switches are ignored.\r\n\r\nIf /C or /K is specified, then the remainder of the command line after\r\nthe switch is processed as a command line, where the following logic is\r\nused to process quote (\") characters:\r\n\r\n 1. If all of the following conditions are met, then quote characters\r\n on the command line are preserved:\r\n\r\n - no /S switch\r\n - exactly two quote characters\r\n - no special characters between the two quote characters,\r\n where special is one of: &<>()@^|\r\n - there are one or more whitespace characters between the\r\n two quote characters\r\n - the string between the two quote characters is the name\r\n of an executable file.\r\n\r\n 2. Otherwise, old behavior is to see if the first character is\r\n a quote character and if so, strip the leading character and\r\n remove the last quote character on the command line, preserving\r\n any text after the last quote character.\r\n\r\nIf /D was NOT specified on the command line, then when CMD.EXE starts, it\r\nlooks for the following REG_SZ/REG_EXPAND_SZ registry variables, and if\r\neither or both are present, they are executed first.\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\AutoRun\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\AutoRun\r\n\r\nCommand Extensions are enabled by default. You may also disable\r\nextensions for a particular invocation by using the /E:OFF switch. You\r\ncan enable or disable extensions for all invocations of CMD.EXE on a\r\nmachine and/or user logon session by setting either or both of the\r\nfollowing REG_DWORD values in the registry using REGEDIT.EXE:\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\EnableExtensions\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\EnableExtensions\r\n\r\nto either 0x1 or 0x0. The user specific setting takes precedence over\r\nthe machine setting. The command line switches take precedence over the\r\nregistry settings.\r\n\r\nIn a batch file, the SETLOCAL ENABLEEXTENSIONS or DISABLEEXTENSIONS arguments\r\ntakes precedence over the /E:ON or /E:OFF switch. See SETLOCAL /? for details.\r\n\r\nThe command extensions involve changes and/or additions to the following\r\ncommands:\r\n\r\n DEL or ERASE\r\n COLOR\r\n CD or CHDIR\r\n MD or MKDIR\r\n PROMPT\r\n PUSHD\r\n POPD\r\n SET\r\n SETLOCAL\r\n ENDLOCAL\r\n IF\r\n FOR\r\n CALL\r\n SHIFT\r\n GOTO\r\n START (also includes changes to external command invocation)\r\n ASSOC\r\n FTYPE\r\n\r\nTo get specific details, type commandname /? to view the specifics.\r\n\r\nDelayed environment variable expansion is NOT enabled by default. You\r\ncan enable or disable delayed environment variable expansion for a\r\nparticular invocation of CMD.EXE with the /V:ON or /V:OFF switch. You\r\ncan enable or disable delayed expansion for all invocations of CMD.EXE on a\r\nmachine and/or user logon session by setting either or both of the\r\nfollowing REG_DWORD values in the registry using REGEDIT.EXE:\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\DelayedExpansion\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DelayedExpansion\r\n\r\nto either 0x1 or 0x0. The user specific setting takes precedence over\r\nthe machine setting. The command line switches take precedence over the\r\nregistry settings.\r\n\r\nIn a batch file the SETLOCAL ENABLEDELAYEDEXPANSION or DISABLEDELAYEDEXPANSION\r\narguments takes precedence over the /V:ON or /V:OFF switch. See SETLOCAL /?\r\nfor details.\r\n\r\nIf delayed environment variable expansion is enabled, then the exclamation\r\ncharacter can be used to substitute the value of an environment variable\r\nat execution time.\r\n\r\nYou can enable or disable file name completion for a particular\r\ninvocation of CMD.EXE with the /F:ON or /F:OFF switch. You can enable\r\nor disable completion for all invocations of CMD.EXE on a machine and/or\r\nuser logon session by setting either or both of the following REG_DWORD\r\nvalues in the registry using REGEDIT.EXE:\r\n\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\CompletionChar\r\n HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor\\PathCompletionChar\r\n\r\n and/or\r\n\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\CompletionChar\r\n HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\PathCompletionChar\r\n\r\nwith the hex value of a control character to use for a particular\r\nfunction (e.g. 0x4 is Ctrl-D and 0x6 is Ctrl-F). The user specific\r\nsettings take precedence over the machine settings. The command line\r\nswitches take precedence over the registry settings.\r\n\r\nIf completion is enabled with the /F:ON switch, the two control\r\ncharacters used are Ctrl-D for directory name completion and Ctrl-F for\r\nfile name completion. To disable a particular completion character in\r\nthe registry, use the value for space (0x20) as it is not a valid\r\ncontrol character.\r\n\r\nCompletion is invoked when you type either of the two control\r\ncharacters. The completion function takes the path string to the left\r\nof the cursor appends a wild card character to it if none is already\r\npresent and builds up a list of paths that match. It then displays the\r\nfirst matching path. If no paths match, it just beeps and leaves the\r\ndisplay alone. Thereafter, repeated pressing of the same control\r\ncharacter will cycle through the list of matching paths. Pressing the\r\nShift key with the control character will move through the list\r\nbackwards. If you edit the line in any way and press the control\r\ncharacter again, the saved list of matching paths is discarded and a new\r\none generated. The same occurs if you switch between file and directory\r\nname completion. The only difference between the two control characters\r\nis the file completion character matches both file and directory names,\r\nwhile the directory completion character only matches directory names.\r\nIf file completion is used on any of the built in directory commands\r\n(CD, MD or RD) then directory completion is assumed.\r\n\r\nThe completion code deals correctly with file names that contain spaces\r\nor other special characters by placing quotes around the matching path.\r\nAlso, if you back up, then invoke completion from within a line, the\r\ntext to the right of the cursor at the point completion was invoked is\r\ndiscarded.\r\n\r\nThe special characters that require quotes are:\r\n <space>\r\n &()[]{}^=;!'+,`~\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\cmd.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\cmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cmdkey.exe-AB608C5A4F22E1BC11C26EBC394E4F61": { "file_name": "cmdkey.exe", "file_path": "C:\\Windows\\SysWOW64\\cmdkey.exe", "hash_md5": "AB608C5A4F22E1BC11C26EBC394E4F61", "hash_sha1": "16814597D6BB2F18CB36A2630A281DE4936068E1", "hash_sha256": "EA468EF7815F4E628C295BD05ED247DCD942CD71AFA991B9EC4B94D963110AA4", "hash_sha384": "265D05507870697C523FC9E7C9521403C597418F8338B8FDBD5C8F1DA67292242B8352227D3E098D670BF776DF6E72AE", "hash_sha512": "E00DEC46B6770AA160B9048156B6F69751F08F00312326318AAAC3EFF4268A568FEF2AA43DE800EB9F98DCCDA51755D6EB06F28C51D20425E475178C1E88C580", "hash_ssdeep": "384:UDhVrF3i5shjB0uOZdR7sx34zd/qcGDlWswW:UDhOYPOZdI4hbGDF", "hash_imp": "19CAF11535B9CA1BEB2EF45EB8724422", "hash_pesha1": "00FC36920CC363B42CD365619C468B87175E6E20", "hash_pe256": "E93B14868CC994C770EBFB915307902B3CF2BBEB04FD14EAE41547C2E0EB0A40", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Manager Command Line Utility", "meta_original_filename": "cmdkey.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/ea468ef7815f4e628c295bd05ed247dcd942cd71afa991b9ec4b94d963110aa4/detection/", "output": "\r\nCreates, displays, and deletes stored user names and passwords.\r\n\r\nThe syntax of this command is:\r\n\r\nCMDKEY [{/add | /generic}:targetname {/smartcard | /user:username {/pass{:password}}} | /delete{:targetname | /ras} | /list{:targetname}]\r\n\r\nExamples:\r\n\r\n To list available credentials:\r\n cmdkey /list\r\n cmdkey /list:targetname\r\n\r\n To create domain credentials:\r\n cmdkey /add:targetname /user:username /pass:password\r\n cmdkey /add:targetname /user:username /pass\r\n cmdkey /add:targetname /user:username\r\n cmdkey /add:targetname /smartcard\r\n \r\n To create generic credentials:\r\n The /add switch may be replaced by /generic to create generic credentials\r\n\r\n To delete existing credentials:\r\n cmdkey /delete:targetname\r\n\r\n To delete RAS credentials:\r\n cmdkey /delete /ras\r\n \r\n" }, "cmdl32.exe-87390E37E36622B054D4BDCBB7997B6C": { "file_name": "cmdl32.exe", "file_path": "C:\\Windows\\SysWOW64\\cmdl32.exe", "hash_md5": "87390E37E36622B054D4BDCBB7997B6C", "hash_sha1": "4D591F310318FD95A95109D7965A79729B65C69E", "hash_sha256": "5F067F86AD0F88A629263162810BF5052F5EBBD97D5D0DE936311BB44C9F35E7", "hash_sha384": "1601628950C2123FF9DC5A3F59D48751F9C8D1647928E556DDB64A670D57C48385C7FB32EF6B987FE406CD72E648E092", "hash_sha512": "285ABB19138A5DD109DFC0E76F4A4F96B3731A84CA9229E6EF9315513B052FD7AD7B2E0392AC9BECBF4CAF2C9BBDBD87F5B66486FB2AE1385C1FBE6E1ED643DD", "hash_ssdeep": "768:GTqHPEiucKtaMwxru9UMYriMPWBiAlZv12+6m/dJaJCO0dsZIYG8w:GT+PEJcKtaMII+e3vR6AiZI58", "hash_imp": "BA2BC70069F6B2E3580725012BA0CDE5", "hash_pesha1": "45228C157307297DB800C74DC6385BBAB99870C8", "hash_pe256": "732DD1051D555920FD64D4A121C2087ABCD594A34198C658512DBCC15FF04D6A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Connection Manager Auto-Download", "meta_original_filename": "CMDL32.EXE.MUI", "meta_product_name": "Microsoft(R) Connection Manager", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.17763.1 (WinBuild.160101.0800)", "meta_product_version": "7.2.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/5f067f86ad0f88a629263162810bf5052f5ebbd97d5d0de936311bb44c9f35e7/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\cmdl32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cmmon32.exe-DEAA709A71519E24B72574A666A82C2D": { "file_name": "cmmon32.exe", "file_path": "C:\\Windows\\SysWOW64\\cmmon32.exe", "hash_md5": "DEAA709A71519E24B72574A666A82C2D", "hash_sha1": "E3203715CC85465CC99C4FCD6E1771661091A86F", "hash_sha256": "5FE9D729C8D187AAA44FE5396C5E0301A2C8D2D6A2F33E9C9814DAE97DD49071", "hash_sha384": "D4D8EFE68FC0CC3372365C1BB50D09B540F9F14D777D03C68EC1261C284639F59854ED151246960294A24E76B4DC68D8", "hash_sha512": "4B5A442A8A80D2718B8D25F88A21CE0B446C41A009C2FCBC2F67FA99F87E6CF3C1E5433D8147B58506E8ABA3CD6A9AA82D246F17D38A802BA8E3C17B4BEF998D", "hash_ssdeep": "768:pPHDnOXh9Uwyn6iCe41C3hioRm/yyT91FPFJz5tKCNW:FHD69YCe41C3Vm1b9r5tKCNW", "hash_imp": "D3E67DC5271176E155375662C3682D3F", "hash_pesha1": "ED457B8041E04B5ECA408D8EA9D2E233D5993447", "hash_pe256": "6B746CABF81B85D15CE69BC78C5D2112AE720EFE4307110223103525DBB149EA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Connection Manager Monitor", "meta_original_filename": "CMMON32.exe.mui", "meta_product_name": "Microsoft(R) Connection Manager", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.17763.1 (WinBuild.160101.0800)", "meta_product_version": "7.2.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/5fe9d729c8d187aaa44fe5396c5e0301a2c8d2d6a2f33e9c9814dae97dd49071/detection/" }, "cmstp.exe-C24C55991ED37AA52BCF07A70899DDFA": { "file_name": "cmstp.exe", "file_path": "C:\\Windows\\SysWOW64\\cmstp.exe", "hash_md5": "C24C55991ED37AA52BCF07A70899DDFA", "hash_sha1": "85A4BADA186C7957E17E2076187B0C75E3B195AA", "hash_sha256": "E3EA8B0B905F0CB4B355C0650672962A18212420AA75732B689439FBD956B208", "hash_sha384": "FF7C2EE1B5E000A68781AA95866B26CD8014B91D0A790463FD80CB0633787F3612FBB9572B8A418F8139220B68CCA4EF", "hash_sha512": "B9D37CE30D1FB631ECC04D0893D85ED65F5E5D5A79788EEB1DD5BED8012D89A3CCD3D3D1A4FB8AE4ADE8D910BC57A75FE0A95398FC3323A5C5F90EF39B5EAC16", "hash_ssdeep": "1536:PvsrU8+dzwKsTCmxywevV9mi2oLIYYAXraLY1qYqNRe1uZZbNDa:PErU8+JwKsTpymmjmkqYqNRe12ZJDa", "hash_imp": "1BFCD0AAD19887A1035BF48D79219292", "hash_pesha1": "152DE521B2A480FA2D99D337CE84C52789CF7241", "hash_pe256": "1AFC585FC5A6F5A5B803CBB5E521783B2367C86CC6D6FE3620514A159AA8B345", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Connection Manager Profile Installer", "meta_original_filename": "CMSTP.EXE.MUI", "meta_product_name": "Microsoft(R) Connection Manager", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.2.17763.1 (WinBuild.160101.0800)", "meta_product_version": "7.2.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e3ea8b0b905f0cb4b355c0650672962a18212420aa75732b689439fbd956b208/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\cmstp.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "Connection Manager Profile Installer", "runtime_modules": [ "C:\\Windows\\SysWOW64\\cmstp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "colorcpl.exe-BFCDDC11FE74898B5099303303A24595": { "file_name": "colorcpl.exe", "file_path": "C:\\Windows\\SysWOW64\\colorcpl.exe", "hash_md5": "BFCDDC11FE74898B5099303303A24595", "hash_sha1": "CA5C10B6C738E14F9B4F111500C79AB70165B4C1", "hash_sha256": "4FECEA309763CBA5109B644C4DB5DA4E17CB69E0772AABD00716AADA14EF9B2F", "hash_sha384": "071CA155BE051712BEEA50E9B8AF0DF496DEE2728D5B0FA85C60F653A9EDB24D9BD28BA3D8E30437E81A9957FF2DE79E", "hash_sha512": "9A12C28E3E30E91BD9119EB54EA8FA370EC3EDA7D8805DB87471CBE66E00C7D0E763357787C367F7DFD897246EEA7C097E1C6D6607C256F6BCF4ED137296DF2C", "hash_ssdeep": "1536:D1iIPfSbS9vMBN7rQOJ7CFToTCzhcRguhwxTyPCb3lZpdym4dy7p:x1Xlvq7jSP1cR2prbpdCY9", "hash_imp": "FE642844D8BB41A0A5162838127D9366", "hash_pesha1": "F7F3EF45AFCA21A8D66071CD6474411CF796CB67", "hash_pe256": "537FB7C45C62663B38709AED81C7B2213D9FDE0887BA9175683A752B0CF1A297", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Color Control Panel", "meta_original_filename": "colorcpl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/4fecea309763cba5109b644c4db5da4e17cb69e0772aabd00716aada14ef9b2f/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\colorcpl.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\colorui.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\colorcpl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Color Management" }, "comp.exe-2D5AD16FC0D1A72A4B7F6807BAB67507": { "file_name": "comp.exe", "file_path": "C:\\Windows\\SysWOW64\\comp.exe", "hash_md5": "2D5AD16FC0D1A72A4B7F6807BAB67507", "hash_sha1": "39F95C6441C45B918CDAC1B0E3DBBF67D8847612", "hash_sha256": "255AE38C59BCDC3AE0C706BEE5EB333041F3B52DE15BBF2A4B1E4C1723F33864", "hash_sha384": "D2CDC60447DCAD2D0649B9B2A913AD8E6C68027340722FFA0FC1D8651636F0B53E0226C7635FDDFEB1BD55AC49B07530", "hash_sha512": "F673E0170E317500B2FAE7A230A60F6FADCACE47646C4FB7F0C5B4BB823623DF79612E061B39157FA614CEDEC8B0105368135A2350CF47D5639B61AF1D1697B1", "hash_ssdeep": "384:3iMnVXnDPYohE+ouPP/iqil23/TaAdrNvD31LONzWncWFwJ:3iMnVjtP3iqilq+Mx1LOmPS", "hash_imp": "FFD97A520B1CE23CD1FC4B5F8E5BCB3C", "hash_pesha1": "F25D693444F7F7DC5DF719B87FD474FF85DAB7DB", "hash_pe256": "51479598D42DB705A0D95FFAB8BB8018B129877AF950A027771A85971F862DDE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Compare Utility", "meta_original_filename": "Comp.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/255ae38c59bcdc3ae0c706bee5eb333041f3b52de15bbf2a4b1e4c1723f33864/detection/", "output": "Compares the contents of two files or sets of files.\r\n\r\nCOMP [data1] [data2] [/D] [/A] [/L] [/N=number] [/C] [/OFF[LINE]] [/M]\r\n\r\n data1 Specifies location and name(s) of first file(s) to compare.\r\n data2 Specifies location and name(s) of second files to compare.\r\n /D Displays differences in decimal format.\r\n /A Displays differences in ASCII characters.\r\n /L Displays line numbers for differences.\r\n /N=number Compares only the first specified number of lines in each file.\r\n /C Disregards case of ASCII letters when comparing files.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n /M Do not prompt for compare more files.\r\n\r\nTo compare sets of files, use wildcards in data1 and data2 parameters.\r\n", "error": "Name of second file to compare: ", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\ulib.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\comp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "compact.exe-D9A6C940D8AF7BFBA08D010B85F155A2": { "file_name": "compact.exe", "file_path": "C:\\Windows\\SysWOW64\\compact.exe", "hash_md5": "D9A6C940D8AF7BFBA08D010B85F155A2", "hash_sha1": "C6E7DF7BBDAE0AE442C0D95B4DA31BEE14918D48", "hash_sha256": "23867E6ED3A2A7355E5E129C6C795EBE9C858A5ABB13ED575B9E7814CCD19282", "hash_sha384": "0A57AD415A991040A6B61D2BD2F279F772CD0E1A46AB004EFC4CC3F6D82C38043B8EB86595FEFBCF033390841227808B", "hash_sha512": "CDB480BF5FF087671EF5A7D4E655289C859AE6A2B8A7CB41C0C7A8D29BCA59E8FD1E8491A15050C293E3363FC2CB8FD376C0605670D6AD5F118D8A104CA581D3", "hash_ssdeep": "768:CZQMj1pHpILF3CP7rGE5ibfI3A8nkLwV6r0kftjjo8X82HSDWYvzPxjGr5u1KJda:CZQMj1pHpcF3uTUwwr06tHlYvzpjGr5n", "hash_imp": "F62B024CE3F1C2441731CA2486368509", "hash_pesha1": "3ABB1968AA8E11F94919FAECFBDF9225F0FFF5AB", "hash_pe256": "CC64E79E6B2487AF6620C733A0E3A791C334B78569D5608C177E55D095A98758", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Compress Utility", "meta_original_filename": "COMPACT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.831 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.831", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/23867e6ed3a2a7355e5e129c6c795ebe9c858a5abb13ed575b9e7814ccd19282/detection/", "output": "Displays or alters the compression of files on NTFS partitions.\r\n\r\nCOMPACT [/C | /U] [/S[:dir]] [/A] [/I] [/F] [/Q] [/EXE[:algorithm]]\r\n [/CompactOs[:option] [/WinDir:dir]] [filename [...]]\r\n\r\n /C Compresses the specified files. Directories will be marked\r\n so that files added afterward will be compressed unless /EXE\r\n is specified.\r\n /U Uncompresses the specified files. Directories will be marked\r\n so that files added afterward will not be compressed. If\r\n /EXE is specified, only files compressed as executables will\r\n be uncompressed; if this is omitted, only NTFS compressed\r\n files will be uncompressed.\r\n /S Performs the specified operation on files in the given\r\n directory and all subdirectories. Default \"dir\" is the\r\n current directory.\r\n /A Displays files with the hidden or system attributes. These\r\n files are omitted by default.\r\n /I Continues performing the specified operation even after errors\r\n have occurred. By default, COMPACT stops when an error is\r\n encountered.\r\n /F Forces the compress operation on all specified files, even\r\n those which are already compressed. Already-compressed files\r\n are skipped by default.\r\n /Q Reports only the most essential information.\r\n /EXE Use compression optimized for executable files which are read\r\n frequently and not modified. Supported algorithms are:\r\n XPRESS4K (fastest) (default)\r\n XPRESS8K\r\n XPRESS16K\r\n LZX (most compact)\r\n /CompactOs Set or query the system's compression state. Supported options are:\r\n query - Query the system's Compact state.\r\n always - Compress all OS binaries and set the system state to Compact\r\n which remains unless administrator changes it.\r\n never - Uncompress all OS binaries and set the system state to non\r\n Compact which remains unless administrator changes it.\r\n /WinDir Used with /CompactOs:query, when querying the offline OS. Specifies\r\n the directory where Windows is installed.\r\n filename Specifies a pattern, file, or directory.\r\n\r\n Used without parameters, COMPACT displays the compression state of\r\n the current directory and any files it contains. You may use multiple\r\n filenames and wildcards. You must put spaces between multiple\r\n parameters.\r\n" }, "ComputerDefaults.exe-FF2E0EABBB610CD9D4F06C8C0E33B92F": { "file_name": "ComputerDefaults.exe", "file_path": "C:\\Windows\\SysWOW64\\ComputerDefaults.exe", "hash_md5": "FF2E0EABBB610CD9D4F06C8C0E33B92F", "hash_sha1": "F696720044C5D04691369DE179892B4FC18A8D83", "hash_sha256": "88A550361C783FE8C807882462A0CC988FEA24426ABF5AA3AB9FD5A300DD296A", "hash_sha384": "7B9A8E9264A3EB7C212785F0B9F1CE64FAFAAAE7E7D2217301CE9130F121F6818E65BD441BF184B2471888F5C75A5DF9", "hash_sha512": "FB03F9449F9C54FA2643D32EA0105037F53550A61C71E655D02C69D926148A0E04A9A1D63A496A9F74F859521F3F09184415099B308BC670E1AE698BEA893176", "hash_ssdeep": "1536:0IQOnuDjXYdD0JrePojh6tGryrURDoq4OZZZLlCIibB8:X7ufYdDVwRD68wbB8", "hash_imp": "DCF24A295065FCFB6B7F451585917C44", "hash_pesha1": "2738AACDCBE035494E99F1533DE77B870BD3ACE0", "hash_pe256": "AFA76271ED7A0C9E2BAFFE9507A3B666C1053827C805CEBB3696DFE4DA0EB1E3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Set Program Access and Computer Defaults Control Panel", "meta_original_filename": "ComputerDefaults.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/88a550361c783fe8c807882462a0cc988fea24426abf5aa3ab9fd5a300dd296a/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\ComputerDefaults.exe.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\RPC Control\\DSEC1344": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_webcache_counters_{9B6AB5B3-91BC-4097-835C-EA2DEC95E9CC}_S-1-5-21-4075667164-670084373-454571106-500": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\ComputerDefaults.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "control.exe-1F13E714A0FEA8887707DFF49287996F": { "file_name": "control.exe", "file_path": "C:\\Windows\\SysWOW64\\control.exe", "hash_md5": "1F13E714A0FEA8887707DFF49287996F", "hash_sha1": "176B874D0C163C9561E35C0CF7EE4D5A56292877", "hash_sha256": "CF19EAFF8AE1D6A4AB70A2E2CE996F49D3AFDC193EE8F69AEF881E5727BC8F38", "hash_sha384": "93901F13FBA747693FD5E84E008511137BC5EE719D025F6EC2AE1D18D1EE95B725A27B7F534BCC6800DB322D80AD4A01", "hash_sha512": "625221290EBDD98F75022A9FBFED9E4218A13B7F1CF062E9B4BC1FB48678E41B3C6A1FE7BFE9AC882245C86E4471E751765BA1F886BA605E348701E9A5CE09B8", "hash_ssdeep": "1536:pDhE4VlBe/qzSpZ3r1q6QkjfkQUk8+k6kawM1x8Dkf8dani25imK:lpzB7Sp5+1k12b/Af885RK", "hash_imp": "A3EBCFE0050EB5B2420A836D354C33A7", "hash_pesha1": "0ED80D5F18920094D365BBC0090175181CCC42C9", "hash_pe256": "DED6B1CC2903F554CD0427153323658EF9BB4169D736594C7DD2B064726502E5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Control Panel", "meta_original_filename": "CONTROL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/cf19eaff8ae1d6a4ab70a2e2ce996f49d3afdc193ee8f69aef881e5727bc8f38/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\control.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "convert.exe-90FE6B0994E8BDE133A650963EDBD6C2": { "file_name": "convert.exe", "file_path": "C:\\Windows\\SysWOW64\\convert.exe", "hash_md5": "90FE6B0994E8BDE133A650963EDBD6C2", "hash_sha1": "3D77A83C69C603A4D09DB0EF5D183484EB62E38B", "hash_sha256": "D280FF3983AF2B77EEEA7C5D1F021CCCD254444C30F65700DF097328B6E3AD2F", "hash_sha384": "F5D0C798B5C26AE8E6181C582C7665CF226BC99618AFEBF0217398F1D6E6D037E56CCBEDE2CC33BCCC2FFAFC3B5C787A", "hash_sha512": "E7E1A719F012A1DFF49B58FB68BEB76A8DB310E3914D0E72906E774704C2CFF935482CB8126C2E0A77F38D7CAB4E7B66B6AF3544E112324DB0C31D1387A04628", "hash_ssdeep": "384:5UXz59OBNRiActWgMgcMXKXHXZTac+7xNzW9qWl:5vPRxctWPJpx6xYZ", "hash_imp": "67458FAEC238A61DD838DD54CA17F2A9", "hash_pesha1": "244861C1EEEC55557C8D08F57214FB1A5594FC23", "hash_pe256": "63DB4CA601E6DDEEFC611E17D708AAB9311E453DA6F9381F70ECBABCE31CB01B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File System Conversion Utility", "meta_original_filename": "CONVERT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/d280ff3983af2b77eeea7c5d1f021cccd254444c30f65700df097328b6e3ad2f/detection/", "output": "Converts a FAT volume to NTFS.\r\n\r\nCONVERT volume /FS:NTFS [/V] [/CvtArea:filename] [/NoSecurity] [/X]\r\n\r\n\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name.\r\n /FS:NTFS Specifies that the volume will be converted to NTFS.\r\n /V Specifies that Convert will be run in verbose mode.\r\n /CvtArea:filename\r\n Specifies a contiguous file in the root directory\r\n that will be the place holder for NTFS system files.\r\n /NoSecurity Specifies that the security settings on the converted\r\n files and directories allow access by all users.\r\n /X Forces the volume to dismount first if necessary.\r\n All open handles to the volume will not be valid.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\convert.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "Invalid drive specification.\r\n" }, "CredentialUIBroker.exe-0755D1D90E195D3382EEA880D67F62BA": { "file_name": "CredentialUIBroker.exe", "file_path": "C:\\Windows\\SysWOW64\\CredentialUIBroker.exe", "hash_md5": "0755D1D90E195D3382EEA880D67F62BA", "hash_sha1": "AEDF016A97FB3BED51C8368575D462A8672C6A47", "hash_sha256": "B47AE441FBB2C3307EE6B8F7807D9DE244D5127EFF68474ADCFE3C0ADF8D335D", "hash_sha384": "AB3F590B783A9C023D514A2A42A249B65EF70C460971D634068B7BEC842E7C649CB755530BD5457678BDE45D627822B7", "hash_sha512": "5996AA9D4D4C67C0B5F1260D4091D1254A384582F4339272AE0889E77ADA0BAB0A042A6DF3A2BA4A3FCF0CD8AAE8179AB3CF41F3E9D1AE8038B94B54AD0DC417", "hash_ssdeep": "3072:fK+qPcjDKaSwSKWADSbsqJIq7qLTAwtCL:f9qkvvSKWAD9qJIqQc", "hash_imp": "9E5A992F00D199694C78175EF1EF7757", "hash_pesha1": "D5664F151981A944A09FFF48BFB1CD5AF72E2E5A", "hash_pe256": "5F72C6300CF803D42023033CBAAE8D88980357650CED95FB74DC8CE8C47380F8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Manager UI Host", "meta_original_filename": "CredentialUIBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/b47ae441fbb2c3307ee6b8f7807d9de244d5127eff68474adcfe3c0adf8d335d/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\CredentialUIBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "credwiz.exe-411DF674BB6196FE4E704F4B180627E8": { "file_name": "credwiz.exe", "file_path": "C:\\Windows\\SysWOW64\\credwiz.exe", "hash_md5": "411DF674BB6196FE4E704F4B180627E8", "hash_sha1": "50D94C8BFD13DCD42EE7B220221E9896DB8540BB", "hash_sha256": "C3BF35B99F90D420B879F5F7BBEA8B39AD265865EE7538A72FD147F8A900F1C7", "hash_sha384": "94AD32AC643661295E33849AEC80216406450B2FF51C062C988C9C85E50FCA12CFAEA22EC1B8A543FBF77405ADDC181F", "hash_sha512": "4CA7F7F7A31993309DFA73C1CD437AEF1D8D33BE71820E21EFD72CAF05192FA32388A4D6B01EBD222A23D7E2572CB84138D0EF7272BC2D5E6183EF1CE7156A9B", "hash_ssdeep": "384:iuFGSBYIHFxYE6ZU6b76jbIq4Fol2i0o9ekmtbekrKfUopOyERZ8GzWC5WUNuTly:/1YIGLujbIDFj1NFJ0D8ZHJuTlHE1", "hash_imp": "7811C1109D45B9069E28DFEE0C0F979D", "hash_pesha1": "AEF80F08613261ED43DEA14934A66620725C24EC", "hash_pe256": "8D345A7E8F0A772506C159894253B67A3B6AA412CB846E3A16DF0B6F226EB72D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Credential Backup and Restore Wizard", "meta_original_filename": "credwiz.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c3bf35b99f90d420b879f5f7bbea8b39ad265865ee7538a72fd147f8a900f1c7/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\credwiz.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\oleaccrc.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\credwiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Stored User Names and Passwords" }, "cscript.exe-79E4FBFE24A81B3A2AEB3B3D3DEB3D75": { "file_name": "cscript.exe", "file_path": "C:\\Windows\\SysWOW64\\cscript.exe", "hash_md5": "79E4FBFE24A81B3A2AEB3B3D3DEB3D75", "hash_sha1": "9C7C87842FED7649412B035DF3712B605E40DBED", "hash_sha256": "BBD44AC1C7DFD0102EBA486AA1552742A11C4A94283133ED0C4AAC92FAD6A4D9", "hash_sha384": "C77391A6EB09C7632F996F0CCF693C2B2903D0AC1A35F908DFD4E15066C6D23C822F2F64FB6F74DEBD07592E920DB575", "hash_sha512": "FD967765BD6E671740FC053C1795A355F9E3B8D47A6B6DF4B3B7CED66A5E84C54038EE3F3231FE6D91ECE2D833F564F4515744E4CFF7369256526B58FC0AFBC4", "hash_ssdeep": "3072:ogRukzrvPutB4woyKzs3mYnfEG6NNUSstgNUt9qyyqTxt/I:vvng93mY8sKEqylTk", "hash_imp": "E4D90F9825B64532B46F2C87EC5B0A16", "hash_pesha1": "995511CDD28C6469BB3326310286192DDEC5B5B2", "hash_pe256": "B3EA6658D04C8C1653CBF3D35AD316D097229F923DFAC1C27E73604A0ADAD788", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Console Based Script Host", "meta_original_filename": "cscript.exe", "meta_product_name": "Microsoft Windows Script Host", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.812.10240.16384", "meta_product_version": "5.812.10240.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/bbd44ac1c7dfd0102eba486aa1552742a11c4a94283133ed0c4aac92fad6a4d9/detection/", "output": "Microsoft (R) Windows Script Host Version 5.812\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\nUsage: CScript scriptname.extension [option...] [arguments...]\r\n\r\nOptions:\r\n //B Batch mode: Suppresses script errors and prompts from displaying\r\n //D Enable Active Debugging\r\n //E:engine Use engine for executing script\r\n //H:CScript Changes the default script host to CScript.exe\r\n //H:WScript Changes the default script host to WScript.exe (default)\r\n //I Interactive mode (default, opposite of //B)\r\n //Job:xxxx Execute a WSF job\r\n //Logo Display logo (default)\r\n //Nologo Prevent logo display: No banner will be shown at execution time\r\n //S Save current command line options for this user\r\n //T:nn Time out in seconds: Maximum time a script is permitted to run\r\n //X Execute script in debugger\r\n //U Use Unicode for redirected I/O from the console\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\cscript.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ctfmon.exe-97D7FF9EED95ADF3785F2D0219EEED46": { "file_name": "ctfmon.exe", "file_path": "C:\\Windows\\SysWOW64\\ctfmon.exe", "hash_md5": "97D7FF9EED95ADF3785F2D0219EEED46", "hash_sha1": "C5DED3D1979BA5CB731C7ED003AC0C8172575A8E", "hash_sha256": "81CA60464F7E079A3F3411968CFEA5EADE8085A5B96EF46621E07319DC404F1E", "hash_sha384": "1B342B7CECDAEF8FFD6BF066FE79E4B44D40E671835EDFB3C2E3482FA35F9F3A42F8CAC56F79C243CDB043EC3D519A24", "hash_sha512": "5F2EB7F50709AE0576D471B55B14428B78DE0394A05E8B695BD20E38585FB658A72E0E85E146054FAE0368695A4FBED64A096254716E3737B28F9AA549EA48F9", "hash_ssdeep": "96:2E7+2I1ySDnEtAp2RLZHDGjoaS2Hy9osw2mpDJ7pRKRULEW2gWw3epu4:7Itn598ey9osw2m/yW2gWF", "hash_imp": "A0DF2CAE30CD48F978A8D80039C738E5", "hash_pesha1": "D9E57C0E8EBC5CF8AE904884BAF3227FD1642A61", "hash_pe256": "735A04890A6CA9B619F2019A209B4DD57646D60D8F9D263277AC7B79D648FD0B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "CTF Loader", "meta_original_filename": "CTFMON.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/81ca60464f7e079a3f3411968cfea5eade8085a5b96ef46621e07319dc404f1e/detection/" }, "cttune.exe-B3D58D03EF76001519914F49DF180DA5": { "file_name": "cttune.exe", "file_path": "C:\\Windows\\SysWOW64\\cttune.exe", "hash_md5": "B3D58D03EF76001519914F49DF180DA5", "hash_sha1": "929ADD14D1246D8211B515E2B5A5F7C58C050DDE", "hash_sha256": "4527102D9B5AA52AD008C99E5740FBE4307B19C1BCEB1C6FD8606BC23AEF344A", "hash_sha384": "753F731B7BCDA2C79F263EBF24271F6D9C1B9CC77DF88E562A01E009A75F29E44C1A3A37C251DB1964949CC2F84C7DF4", "hash_sha512": "27020F4A2C4854A2B6FFDD8E1EDAC24726BEE85F83AA8E83BAE6628D0141BCC70917FB61EA2E9F238B3D898270AAC9CE285A3662A830B51EF3032A98AE2D18CC", "hash_ssdeep": "3072:Qly6KLXlMlvctAyvJqxEm4x1ESuQG+3SeyRS6CSfKVu1xgCAWUMZ8:mZKLVMlvctAyvoxEvTEPp/Fu", "hash_imp": "A60865A48632A4AED254ABEBA0F53107", "hash_pesha1": "0C328F81CDE754E1E601F4420B24BDE2A2A1EAAE", "hash_pe256": "D267140B31B0140223B33D899B5C29BF34A7852E1BA71E06DD832577A03147B3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ClearType Tuner", "meta_original_filename": "CTTUNE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/4527102d9b5aa52ad008c99e5740fbe4307b19c1bceb1c6fd8606bc23aef344a/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\cttune.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\RPC Control\\DSEC1034": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\cttune.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "ClearType Text Tuner" }, "cttunesvr.exe-C01E8F98583B3938295954039164816A": { "file_name": "cttunesvr.exe", "file_path": "C:\\Windows\\SysWOW64\\cttunesvr.exe", "hash_md5": "C01E8F98583B3938295954039164816A", "hash_sha1": "4F7D6796F8CD3B89CA9E73F80DAFA713C12CB234", "hash_sha256": "79210132E336DD6B885E3A74FB6B916A5BBDAA75FBE10108E8A6287C2F92459F", "hash_sha384": "A53958C42E430D40F09D691012BFFA021968BCD9E6675866DD295E555C13E279D1659CC66C668898428C22403D82E9D6", "hash_sha512": "8166D7AFEC09794D932DCB48811D79EDF4883DC4F6BF7DAF4469824A1FF72B528BD2368E1C6E1214D5B376468D1681236B681BC4CBABA502CDBE405CA8FA2506", "hash_ssdeep": "768:N+ICEQ5YxfRLfI8cSAyJr5L/IK3pC8hTn/:ZCEQcfI8cSAyJr5nM8dn", "hash_imp": "C888235856577B905938185E0F1CDC12", "hash_pesha1": "627C1C557227150B2221ACB89A6BAA0EF839D477", "hash_pe256": "30977BA93E03C0671D18F582A2E6455E25802A7A486F7FA174573D1BF97E6D9E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ClearType Tuner", "meta_original_filename": "CTTUNESVR.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/79210132e336dd6b885e3a74fb6b916a5bbdaa75fbe10108e8a6287c2f92459f/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\cttunesvr.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECDB4": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\cttunesvr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "curl.exe-1E02A122FE09272058FC1EF0B1B6265E": { "file_name": "curl.exe", "file_path": "C:\\Windows\\SysWOW64\\curl.exe", "hash_md5": "1E02A122FE09272058FC1EF0B1B6265E", "hash_sha1": "4B0223110D11A6613FD863E9F9B10C83EF1D7B71", "hash_sha256": "F835E15ACEB0E995EAD000641019AEC2162F74D45C5732CEE9E3C77D13FA038A", "hash_sha384": "969526FA4BAF4256E98258CD52255D65A2C12EB13D7A2EDADFC1C610BBFCCCB87DACDDD132FB0DB69A2B85F68F763810", "hash_sha512": "63B1E31D75E3794588AA16CEC9908C7E86A1D40221354E635003CF4CE4651834CD4D19B22D85F9295E27A7BFBBF0A2607B2E6A31D9907CB209DE04CF9BACB367", "hash_ssdeep": "6144:IxbPJ8VKmGuGVM2SG0E+l1kJ9XRSG78l9b0Y3m6+Riil9TU9ZNJwZwSDQI50Vvel:IvmGuGVM2SzMR778lpp3n+UYQC0VveRz", "hash_imp": "6C8E9C47D7DAB2C7337C88852362AB90", "hash_pesha1": "F02197DFAD89ABF54467EA5F69075E4C05A29BE0", "hash_pe256": "9F3F52EA3A9F50ECDCC94BB1E278A7828AB351404565678D054A0845AA8C95E8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "The curl executable", "meta_original_filename": "curl.exe", "meta_product_name": "The curl executable", "meta_company_name": "curl, https://curl.haxx.se/", "meta_file_version": "7.55.1", "meta_product_version": "7.55.1", "meta_language": "English (United States)", "meta_legal_copyright": " 1996 - 2017 Daniel Stenberg, <daniel@haxx.se>.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/f835e15aceb0e995ead000641019aec2162f74d45c5732cee9e3c77d13fa038a/detection/", "output": "Usage: curl [options...] <url>\r\n --abstract-unix-socket <path> Connect via abstract Unix domain socket\r\n --anyauth Pick any authentication method\r\n -a, --append Append to target file when uploading\r\n --basic Use HTTP Basic Authentication\r\n --cacert <CA certificate> CA certificate to verify peer against\r\n --capath <dir> CA directory to verify peer against\r\n -E, --cert <certificate[:password]> Client certificate file and password\r\n --cert-status Verify the status of the server certificate\r\n --cert-type <type> Certificate file type (DER/PEM/ENG)\r\n --ciphers <list of ciphers> SSL ciphers to use\r\n --compressed Request compressed response\r\n -K, --config <file> Read config from a file\r\n --connect-timeout <seconds> Maximum time allowed for connection\r\n --connect-to <HOST1:PORT1:HOST2:PORT2> Connect to host\r\n -C, --continue-at <offset> Resumed transfer offset\r\n -b, --cookie <data> Send cookies from string/file\r\n -c, --cookie-jar <filename> Write cookies to <filename> after operation\r\n --create-dirs Create necessary local directory hierarchy\r\n --crlf Convert LF to CRLF in upload\r\n --crlfile <file> Get a CRL list in PEM format from the given file\r\n -d, --data <data> HTTP POST data\r\n --data-ascii <data> HTTP POST ASCII data\r\n --data-binary <data> HTTP POST binary data\r\n --data-raw <data> HTTP POST data, '@' allowed\r\n --data-urlencode <data> HTTP POST data url encoded\r\n --delegation <LEVEL> GSS-API delegation permission\r\n --digest Use HTTP Digest Authentication\r\n -q, --disable Disable .curlrc\r\n --disable-eprt Inhibit using EPRT or LPRT\r\n --disable-epsv Inhibit using EPSV\r\n --dns-interface <interface> Interface to use for DNS requests\r\n --dns-ipv4-addr <address> IPv4 address to use for DNS requests\r\n --dns-ipv6-addr <address> IPv6 address to use for DNS requests\r\n --dns-servers <addresses> DNS server addrs to use\r\n -D, --dump-header <filename> Write the received headers to <filename>\r\n --egd-file <file> EGD socket path for random data\r\n --engine <name> Crypto engine to use\r\n --expect100-timeout <seconds> How long to wait for 100-continue\r\n -f, --fail Fail silently (no output at all) on HTTP errors\r\n --fail-early Fail on first transfer error, do not continue\r\n --false-start Enable TLS False Start\r\n -F, --form <name=content> Specify HTTP multipart POST data\r\n --form-string <name=string> Specify HTTP multipart POST data\r\n --ftp-account <data> Account data string\r\n --ftp-alternative-to-user <command> String to replace USER [name]\r\n --ftp-create-dirs Create the remote dirs if not present\r\n --ftp-method <method> Control CWD usage\r\n --ftp-pasv Use PASV/EPSV instead of PORT\r\n -P, --ftp-port <address> Use PORT instead of PASV\r\n --ftp-pret Send PRET before PASV\r\n --ftp-skip-pasv-ip Skip the IP address for PASV\r\n --ftp-ssl-ccc Send CCC after authenticating\r\n --ftp-ssl-ccc-mode <active/passive> Set CCC mode\r\n --ftp-ssl-control Require SSL/TLS for FTP login, clear for transfer\r\n -G, --get Put the post data in the URL and use GET\r\n -g, --globoff Disable URL sequences and ranges using {} and []\r\n -I, --head Show document info only\r\n -H, --header <header/@file> Pass custom header(s) to server\r\n -h, --help This help text\r\n --hostpubmd5 <md5> Acceptable MD5 hash of the host public key\r\n -0, --http1.0 Use HTTP 1.0\r\n --http1.1 Use HTTP 1.1\r\n --http2 Use HTTP 2\r\n --http2-prior-knowledge Use HTTP 2 without HTTP/1.1 Upgrade\r\n --ignore-content-length Ignore the size of the remote resource\r\n -i, --include Include protocol response headers in the output\r\n -k, --insecure Allow insecure server connections when using SSL\r\n --interface <name> Use network INTERFACE (or address)\r\n -4, --ipv4 Resolve names to IPv4 addresses\r\n -6, --ipv6 Resolve names to IPv6 addresses\r\n -j, --junk-session-cookies Ignore session cookies read from file\r\n --keepalive-time <seconds> Interval time for keepalive probes\r\n --key <key> Private key file name\r\n --key-type <type> Private key file type (DER/PEM/ENG)\r\n --krb <level> Enable Kerberos with security <level>\r\n --libcurl <file> Dump libcurl equivalent code of this command line\r\n --limit-rate <speed> Limit transfer speed to RATE\r\n -l, --list-only List only mode\r\n --local-port <num/range> Force use of RANGE for local port numbers\r\n -L, --location Follow redirects\r\n --location-trusted Like --location, and send auth to other hosts\r\n --login-options <options> Server login options\r\n --mail-auth <address> Originator address of the original email\r\n --mail-from <address> Mail from this address\r\n --mail-rcpt <address> Mail from this address\r\n -M, --manual Display the full manual\r\n --max-filesize <bytes> Maximum file size to download\r\n --max-redirs <num> Maximum number of redirects allowed\r\n -m, --max-time <time> Maximum time allowed for the transfer\r\n --metalink Process given URLs as metalink XML file\r\n --negotiate Use HTTP Negotiate (SPNEGO) authentication\r\n -n, --netrc Must read .netrc for user name and password\r\n --netrc-file <filename> Specify FILE for netrc\r\n --netrc-optional Use either .netrc or URL\r\n -:, --next Make next URL use its separate set of options\r\n --no-alpn Disable the ALPN TLS extension\r\n -N, --no-buffer Disable buffering of the output stream\r\n --no-keepalive Disable TCP keepalive on the connection\r\n --no-npn Disable the NPN TLS extension\r\n --no-sessionid Disable SSL session-ID reusing\r\n --noproxy <no-proxy-list> List of hosts which do not use proxy\r\n --ntlm Use HTTP NTLM authentication\r\n --ntlm-wb Use HTTP NTLM authentication with winbind\r\n --oauth2-bearer <token> OAuth 2 Bearer Token\r\n -o, --output <file> Write to file instead of stdout\r\n --pass <phrase> Pass phrase for the private key\r\n --path-as-is Do not squash .. sequences in URL path\r\n --pinnedpubkey <hashes> FILE/HASHES Public key to verify peer against\r\n --post301 Do not switch to GET after following a 301\r\n --post302 Do not switch to GET after following a 302\r\n --post303 Do not switch to GET after following a 303\r\n --preproxy [protocol://]host[:port] Use this proxy first\r\n -#, --progress-bar Display transfer progress as a bar\r\n --proto <protocols> Enable/disable PROTOCOLS\r\n --proto-default <protocol> Use PROTOCOL for any URL missing a scheme\r\n --proto-redir <protocols> Enable/disable PROTOCOLS on redirect\r\n -x, --proxy [protocol://]host[:port] Use this proxy\r\n --proxy-anyauth Pick any proxy authentication method\r\n --proxy-basic Use Basic authentication on the proxy\r\n --proxy-cacert <file> CA certificate to verify peer against for proxy\r\n --proxy-capath <dir> CA directory to verify peer against for proxy\r\n --proxy-cert <cert[:passwd]> Set client certificate for proxy\r\n --proxy-cert-type <type> Client certificate type for HTTS proxy\r\n --proxy-ciphers <list> SSL ciphers to use for proxy\r\n --proxy-crlfile <file> Set a CRL list for proxy\r\n --proxy-digest Use Digest authentication on the proxy\r\n --proxy-header <header/@file> Pass custom header(s) to proxy\r\n --proxy-insecure Do HTTPS proxy connections without verifying the proxy\r\n --proxy-key <key> Private key for HTTPS proxy\r\n --proxy-key-type <type> Private key file type for proxy\r\n --proxy-negotiate Use HTTP Negotiate (SPNEGO) authentication on the proxy\r\n --proxy-ntlm Use NTLM authentication on the proxy\r\n --proxy-pass <phrase> Pass phrase for the private key for HTTPS proxy\r\n --proxy-service-name <name> SPNEGO proxy service name\r\n --proxy-ssl-allow-beast Allow security flaw for interop for HTTPS proxy\r\n --proxy-tlsauthtype <type> TLS authentication type for HTTPS proxy\r\n --proxy-tlspassword <string> TLS password for HTTPS proxy\r\n --proxy-tlsuser <name> TLS username for HTTPS proxy\r\n --proxy-tlsv1 Use TLSv1 for HTTPS proxy\r\n -U, --proxy-user <user:password> Proxy user and password\r\n --proxy1.0 <host[:port]> Use HTTP/1.0 proxy on given port\r\n -p, --proxytunnel Operate through a HTTP proxy tunnel (using CONNECT)\r\n --pubkey <key> SSH Public key file name\r\n -Q, --quote Send command(s) to server before transfer\r\n --random-file <file> File for reading random data from\r\n -r, --range <range> Retrieve only the bytes within RANGE\r\n --raw Do HTTP \"raw\"; no transfer decoding\r\n -e, --referer <URL> Referrer URL\r\n -J, --remote-header-name Use the header-provided filename\r\n -O, --remote-name Write output to a file named as the remote file\r\n --remote-name-all Use the remote file name for all URLs\r\n -R, --remote-time Set the remote file's time on the local output\r\n -X, --request <command> Specify request command to use\r\n --request-target Specify the target for this request\r\n --resolve <host:port:address> Resolve the host+port to this address\r\n --retry <num> Retry request if transient problems occur\r\n --retry-connrefused Retry on connection refused (use with --retry)\r\n --retry-delay <seconds> Wait time between retries\r\n --retry-max-time <seconds> Retry only within this period\r\n --sasl-ir Enable initial response in SASL authentication\r\n --service-name <name> SPNEGO service name\r\n -S, --show-error Show error even when -s is used\r\n -s, --silent Silent mode\r\n --socks4 <host[:port]> SOCKS4 proxy on given host + port\r\n --socks4a <host[:port]> SOCKS4a proxy on given host + port\r\n --socks5 <host[:port]> SOCKS5 proxy on given host + port\r\n --socks5-basic Enable username/password auth for SOCKS5 proxies\r\n --socks5-gssapi Enable GSS-API auth for SOCKS5 proxies\r\n --socks5-gssapi-nec Compatibility with NEC SOCKS5 server\r\n --socks5-gssapi-service <name> SOCKS5 proxy service name for GSS-API\r\n --socks5-hostname <host[:port]> SOCKS5 proxy, pass host name to proxy\r\n -Y, --speed-limit <speed> Stop transfers slower than this\r\n -y, --speed-time <seconds> Trigger 'speed-limit' abort after this time\r\n --ssl Try SSL/TLS\r\n --ssl-allow-beast Allow security flaw to improve interop\r\n --ssl-no-revoke Disable cert revocation checks (WinSSL)\r\n --ssl-reqd Require SSL/TLS\r\n -2, --sslv2 Use SSLv2\r\n -3, --sslv3 Use SSLv3\r\n --stderr Where to redirect stderr\r\n --suppress-connect-headers Suppress proxy CONNECT response headers\r\n --tcp-fastopen Use TCP Fast Open\r\n --tcp-nodelay Use the TCP_NODELAY option\r\n -t, --telnet-option <opt=val> Set telnet option\r\n --tftp-blksize <value> Set TFTP BLKSIZE option\r\n --tftp-no-options Do not send any TFTP options\r\n -z, --time-cond <time> Transfer based on a time condition\r\n --tls-max <VERSION> Use TLSv1.0 or greater\r\n --tlsauthtype <type> TLS authentication type\r\n --tlspassword TLS password\r\n --tlsuser <name> TLS user name\r\n -1, --tlsv1 Use TLSv1.0 or greater\r\n --tlsv1.0 Use TLSv1.0\r\n --tlsv1.1 Use TLSv1.1\r\n --tlsv1.2 Use TLSv1.2\r\n --tlsv1.3 Use TLSv1.3\r\n --tr-encoding Request compressed transfer encoding\r\n --trace <file> Write a debug trace to FILE\r\n --trace-ascii <file> Like --trace, but without hex output\r\n --trace-time Add time stamps to trace/verbose output\r\n --unix-socket <path> Connect through this Unix domain socket\r\n -T, --upload-file <file> Transfer local FILE to destination\r\n --url <url> URL to work with\r\n -B, --use-ascii Use ASCII/text transfer\r\n -u, --user <user:password> Server user and password\r\n -A, --user-agent <name> Send User-Agent <name> to server\r\n -v, --verbose Make the operation more talkative\r\n -V, --version Show version number and quit\r\n -w, --write-out <format> Use output FORMAT after completion\r\n --xattr Store metadata in extended file attributes\r\n", "error": " % Total % Received % Xferd Average Speed Time Time Time Current\r\n Dload Upload Total Spent Left Speed\r\n\r 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0\r 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0\r 0 0 0 0 0 0 0 0 --:--:-- 0:00:01 --:--:-- 0", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\curl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dccw.exe-AA76EB7D3BB05E726748802E555A2173": { "file_name": "dccw.exe", "file_path": "C:\\Windows\\SysWOW64\\dccw.exe", "hash_md5": "AA76EB7D3BB05E726748802E555A2173", "hash_sha1": "B389EAB83667E32C3DD33B553ABDE3AA0A7FB72B", "hash_sha256": "94C5C38AD8252B9481330D500185D57B0A8A40C319A4DF5F35912BBB2B791CDA", "hash_sha384": "AFD0FD42E9191C9E7C729ECAE0CECA334188FC7B283467E787B78CD5B0C0C2F7C7BDFB0335D60C9AA3DB95ED74BC6E50", "hash_sha512": "86174674A27495B89EE3C68107083A778C321495DE82A18CFEEAE78E30E8254B117DB640EBDAF0C6EDFBC317BA4DDDDF9755384406E58DBBE10BAA0BB4BFA424", "hash_ssdeep": "12288:iulfTVcBGOhS/IzJqrraq/t2qXy6xdRhMA:iulfZTGS/EEn/tkI", "hash_imp": "2B7F19B45958484CF7F3CF5ED96C7C95", "hash_pesha1": "85DCD283EF912DEC5B381EEBD56F3A44F4985D0A", "hash_pe256": "D5A411CCB74AC36BF8233262D0373D0BCB0A17C1CB44730768D844F89CD96511", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Display Color Calibration", "meta_original_filename": "dccw.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/94c5c38ad8252b9481330d500185d57b0a8a40c319a4df5f35912bbb2b791cda/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_5706558cc25cc83b": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\dccw.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\dccw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Display Color Calibration" }, "dcgpofix.exe-547C37574A1793806996C8892760A0B0": { "file_name": "dcgpofix.exe", "file_path": "C:\\Windows\\SysWOW64\\dcgpofix.exe", "hash_md5": "547C37574A1793806996C8892760A0B0", "hash_sha1": "2247E90EBE34B625C399FF23E379CC0126603BBF", "hash_sha256": "BC85D2FCFFC0B1231A3C867DDC7F72C4715C39C94C94FE952932545691DD92DC", "hash_sha384": "EB9DE0C7B72CED66F8DF692AF464985F0F04365665A0377BFB00EB29BAF5D7874B18BA512883A3D41EEC766D625A7648", "hash_sha512": "B948D145329D097FC13DB0E5E5BD1F31F9BFCD095F37EC70CF0116C8C252EE52F395547F087EC78B75231E2E361C09E54BF4ECAEF265A3B04B86CAEE3E16183D", "hash_ssdeep": "1536:gd+GIbKXNiuVlDyfpFjEt4EFqEIOEyXB:gd+GguVlDg8qEwrQX", "hash_imp": "E5DBFF31C174826963755E2AB1E6C867", "hash_pesha1": "0FA2958E565FC6E2B547661B75DDA3F22D9E1B04", "hash_pe256": "7DEE92307E4D2DC36BCE9F9D1F24FA5EAB19D827EB76145515A451B612F154DE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (C) Default Group Policy Object Restore Utility", "meta_original_filename": "DefaultGPOFix", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nMicrosoft(R) Windows(R) Operating System Default Group Policy Restore Utility v5.1\r\n\r\nCopyright (C) Microsoft Corporation. 1981-2003\r\n\r\nDescription: Recreates the Default Group Policy Objects (GPOs) for a domain\r\n\r\nSyntax: DcGPOFix [/ignoreschema] [/Target: Domain | DC | BOTH]\r\n\r\n/target: {Domain | DC | BOTH}\r\nOptional. Specifies the GPO to be restored: the Default Domain Policy GPO, the Default Domain Controllers Policy GPO, or both.\r\n\r\n/ignoreschema:\r\nOptional. Use this switch to enable this tool to ignore the schema version of Active Directory. Otherwise, this tool will only work on the same AD schema version as the Windows version in which the tool was shipped.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\dcgpofix.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dcomcnfg.exe-CF23005187F904FC2B510E52B4EF5DD9": { "file_name": "dcomcnfg.exe", "file_path": "C:\\Windows\\SysWOW64\\dcomcnfg.exe", "hash_md5": "CF23005187F904FC2B510E52B4EF5DD9", "hash_sha1": "60DCF414B53F61D8B3483303E607246C999EA16B", "hash_sha256": "A122AF3090368A1C1AEC1B56F66858AEF6979367A512E01A6E4F6F56A7204926", "hash_sha384": "7CB286CBF9C962EF98B24CC002B6F47188E21242E4A5A7CB5DC00D1C275CD0A16A072784BFD74C084756E387BA310A2A", "hash_sha512": "598009F5862F5B99488770ACDDDA32A9EEC42E47BECFBEA3674C2A7224F62D9946ED73142BB65AB061049CD617147EC27E2318AD3B6D1C1DC1D4CD72301024DF", "hash_ssdeep": "96:Ojxj2cfOg0OE4NnEp2iyIRo2yI3nc4d/UDGjA2HtEY2wjtoVcJDP2LVD7KkBKEWX:wxjdO4NGJRoi355nEYljtoVcMf1W0EW", "hash_imp": "09DC7C84FC3FF557D19CADF0EA6EB40E", "hash_pesha1": "0A9ED9CD5991D3F7F5E0FFE671719E422F37CDF5", "hash_pe256": "A1FC8D6F32757FC3DF9F7BE8F08EFA727824B00EC5A319D05F5E10994772AAE4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+", "meta_original_filename": "DCOMCNFG.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/a122af3090368a1c1aec1b56f66858aef6979367a512e01a6e4f6f56a7204926/detection/", "children": "mmc.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\dcomcnfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ddodiag.exe-FB0CD493A4A666D652D4468E19008A61": { "file_name": "ddodiag.exe", "file_path": "C:\\Windows\\SysWOW64\\ddodiag.exe", "hash_md5": "FB0CD493A4A666D652D4468E19008A61", "hash_sha1": "8767C134E8FA26CCAB6CFD8DE2A4678D98AE4BB8", "hash_sha256": "B8E52ABD573AF6B8773A567425A5FA667BE939E3BC1E522B0DB388A4F0FA2B5D", "hash_sha384": "0B417DE83E01E5505B604E38A52217C041A16CBBCF2EE524B17EFCA42FFF86368A3B40923C55AD420890A65FEA02C4E0", "hash_sha512": "B3A003A6EA19B721C4DFA77126A92C2B5BEB5F3F7851E9B1B2394A4503A6E22519148693212676017A40705854DA05C852E4E8A92A40DDB50233DAB9A793C5BC", "hash_ssdeep": "768:om6fhsXKZkrWcwMa4uZlqimiST8iOOz6+Db:om6fhsXKZkrWcwMa4uZlqimF8/OBDb", "hash_imp": "9C77374063C1B46991F749CD1E215781", "hash_pesha1": "741EF0CBC15F7BF4B21449BBAC719A6891F82CAE", "hash_pe256": "C83B44AB4E73604530E4F22C7FC7CCE98BC38B14DEA30263D3E6E7963AF2328F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DDODiag is a tool that collects Device Display Object (DDO) information from the system and logs it", "meta_original_filename": "DDODiag.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b8e52abd573af6b8773a567425a5fa667be939e3bc1e522b0db388a4f0fa2b5d/detection/" }, "DevicePairingWizard.exe-BC95978508CD50D1A831B9DE752D0B15": { "file_name": "DevicePairingWizard.exe", "file_path": "C:\\Windows\\SysWOW64\\DevicePairingWizard.exe", "hash_md5": "BC95978508CD50D1A831B9DE752D0B15", "hash_sha1": "3DD1DD06107E2C0634E16DD0C6E451402F24AE57", "hash_sha256": "B8E0841130EB3DC73E827E8CDD0CA7A8CAA2DA7AA0D7DE74433B13B0C19AB7A1", "hash_sha384": "B3FFB1A7DA6AB402542FC9F8E751043934615E58EC5C12B3E0C78215305376D483B4FC7F0FE37C9A781763E0E78EB393", "hash_sha512": "F614CB8CE25B1D288CC6256579B5AD734D1EA8C41427696951085AE22695627439F687CE29345691CAD15DE7FF1AB6CD913C9963CE210872030EDFC8FD85832C", "hash_ssdeep": "768:KrSiEYEdvml88AVAwsWPitgfvNmWv/6oueZBryb24G0In3BhzhWM1GOVz177c:KrSiEYOY19eed2/6f8ryb8Z3qOTfc", "hash_imp": "E22F4F896B9960494DDA33E77FEBFA53", "hash_pesha1": "1747DAB744B2472FF15CA11F741CA42C7A7621CF", "hash_pe256": "D0D4323A5C7C0F35AAF1FCB72D5DFC44CF49181DC3514FC845FF8D2EEFAA3F46", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device Pairing Application", "meta_original_filename": "DevicePairing.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/b8e0841130eb3dc73e827e8cdd0ca7a8caa2da7aa0d7de74433b13b0c19ab7a1/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECE20": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\DevicePairing.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\oleaccrc.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\DevicePairingWizard.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Add a device" }, "dfrgui.exe-7023EC5BAEF3BDE3C77C0FA08D924501": { "file_name": "dfrgui.exe", "file_path": "C:\\Windows\\SysWOW64\\dfrgui.exe", "hash_md5": "7023EC5BAEF3BDE3C77C0FA08D924501", "hash_sha1": "A15115AF3640B1C1DF4221E25513685A618916B5", "hash_sha256": "8B74F00EB983DC749438861AC524955D7241633B6973778BBEE73D9904304705", "hash_sha384": "1DD56080B0ACFD88AB48D5B2A9FFF67104B9EE1F9ABA1137CE3D76E5E7532F207A801B47907E630DDB63685881CB8FC4", "hash_sha512": "3B7E7D48CB95967495B77A8D02C57DF0406BDC0E99784F54E8F3A8E204E254D14D0FC3351F5AC2521312589D725E7F1B27371F55541531B5A91960E647285742", "hash_ssdeep": "12288:1hWgnZ6Kb8Xd3lRkRc4YFwjsWOfRg6gtPbcTTn7qxerx7:HQsWd3/kRc4l6g6gtPbcHn7q", "hash_imp": "B72A9DEF4CB346F15A8F458293B62F22", "hash_pesha1": "1EB91FCF1A1BCE267C56977024626D5F76CE4F9B", "hash_pe256": "3B85420076CB3A9D8468DB56F7EDB062B4720E8F4E6A015E2735535CD5809444", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Drive Optimizer", "meta_original_filename": "lhdfrgui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1039 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1039", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/8b74f00eb983dc749438861ac524955d7241633b6973778bbee73d9904304705/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\dfrgui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dialer.exe-4467865D2CD15FDA91C9D64758A9BAFE": { "file_name": "dialer.exe", "file_path": "C:\\Windows\\SysWOW64\\dialer.exe", "hash_md5": "4467865D2CD15FDA91C9D64758A9BAFE", "hash_sha1": "C789DB914C3DFD64440235E1C0A315B66C002134", "hash_sha256": "366857DE6E835CA6A12E33503F6726A2E8528E7F1F9AC74435E2A6BD3C3ED481", "hash_sha384": "A3B5206E049751F194F272D3FA4A4B6769EDC5E28A2A1A7F0705CC156FBDA404E31749AB4AB714C105DA5023DAC3F1B4", "hash_sha512": "A99BBD09F1E50AC8D2C6DBD26791354BBC1BD8AE9655E7D43793A7D3EAADF7AD49F0A64E0A898622B527B7963B3BAA23EF4DF1FB05885298DFE265A59836AFAB", "hash_ssdeep": "384:tBp25iPnE6e9vGoH+WWjOMd213y1CaUgDgkK384jLhMFVRLg4R81dULWtUKWjdXz:tG5xMoHCjbd213+Ugk70P+1dU/dv", "hash_imp": "76E0D8D65462216E7B0903BC27D606D1", "hash_pesha1": "4C1946B2584FBBFED2A7820F32BBB5D0AC999408", "hash_pe256": "62DF8B532A02F469B82D43E0A99E93916AC8D25DFFFA68CFD1370DA88BAA9249", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Phone Dialer", "meta_original_filename": "DIALER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/366857de6e835ca6a12e33503f6726a2e8528e7f1f9ac74435e2a6bd3c3ed481/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\dialer.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\dialer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Phone Dialer" }, "diskpart.exe-80F589F5084671EE558096AF648936D7": { "file_name": "diskpart.exe", "file_path": "C:\\Windows\\SysWOW64\\diskpart.exe", "hash_md5": "80F589F5084671EE558096AF648936D7", "hash_sha1": "DB4163F570E8D597ADC483B5C09B088DD0C0006B", "hash_sha256": "24F001784D68CC80E944422807C052C0D2E9E51C75C3CD578DA610576208ABAA", "hash_sha384": "59ECFE462D5B2A244734E3AF14A426D3AAE3ADFB1DFBE2E9B2DC3DFFCFAA3A3266D57DA8A67A31306C0D2C0C66690E52", "hash_sha512": "21AD20469076D47F76802F6ED7030F2E510C019E9D819AE6E266CB8AC3DD25B99E39C6CF0472106CD7C05CE424396538595A7CE18F1DAA5751D5C5097775F444", "hash_ssdeep": "3072:FpPTkkd482hZtTG2IZOmaIoEuImgCh4NYXKAZWcclJDZZflnaK3QxiZeiO:Fpr9drn2MRagCh2CqzDLlnpTzO", "hash_imp": "037D23EC0A7AA77EB4DD8BDA72D2A94E", "hash_pesha1": "9E1543FBCB732708A9ACF8522067236B035F998A", "hash_pe256": "7E85440B153582A5A2621DE23AB13081A5E63D0821D67ECE594D24EC9C45E67B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DiskPart", "meta_original_filename": "diskpart.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/24f001784d68cc80e944422807c052c0d2e9e51c75c3cd578da610576208abaa/detection/", "output": "\r\nMicrosoft DiskPart version 10.0.17763.1\r\n\r\nCopyright (C) Microsoft Corporation.\r\nOn computer: Default-PC\r\n\r\nMicrosoft DiskPart syntax:\r\n\tdiskpart [/s <script>] [/?]\r\n\r\n\t/s <script> - Use a DiskPart script.\r\n\t/? - Show this help screen.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\diskpart.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "diskperf.exe-6803A60F4711EF57837FE9F44D4D953E": { "file_name": "diskperf.exe", "file_path": "C:\\Windows\\SysWOW64\\diskperf.exe", "hash_md5": "6803A60F4711EF57837FE9F44D4D953E", "hash_sha1": "B8659BE11EDE50CFAE5467AB837EC4BF95AB6EE1", "hash_sha256": "1839A4AAD437B18B30E9FE880EDBDA89EEA9B76DD0725DAD2C99029CEB4E64BC", "hash_sha384": "A7B02C7CD35D8423639FF25116DEDC18B3206E6F685B18B15876B22642D4375226A6C54F03D9A611B013E2ACD728C6C6", "hash_sha512": "3EAD8149FE47CC80F1A27BACEB1BB78040165F91811D8D1DCB8327023533668DF64925D05351110798C1EEF506E31CEF893A325F3B553DA5B0B4F533E531ADE5", "hash_ssdeep": "384:gCOMTMpVlHw8jwHmz3Db9SIb/n7RZXdWoJW2:gCOMW/Hw8RjDbljnlZXJB", "hash_imp": "241BF50230A3DBE17E5AC2F48DA766C1", "hash_pesha1": "6BF3927BF6FD1243342FBB27ED47480F0F9797D1", "hash_pe256": "98F081B297CF768851AD6B0EE314F38A37FC2EC52755F07C84C30E2B301DBE71", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Performance Configuration Utility", "meta_original_filename": "DISKPERF.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/1839a4aad437b18b30e9fe880edbda89eea9b76dd0725dad2c99029ceb4e64bc/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\diskperf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "output": "\r\n\r\nDISKPERF=====================\r\n\r\nStarts and stops system disk performance counters.\r\n\r\nUsed without the command switches, DISKPERF reports what disk\r\nperformance counters are enabled on the specified Windows 2000 computer.\r\n\r\nDisk performance counters can be specified to report the\r\nperformance of the individual physical drives, or the individual\r\nlogical drives or storage volumes. Note that these two sets of\r\nperformance counters are measured independently. The user\r\nhas the option of enabling and disabling them independently\r\nusing the command line switches.\r\nNOTE: This command can only be used to control remote\r\nWindows 2000 systems. In newer systems, these performance counters\r\nare automatically enabled.\r\n\r\nDISKPERF [-Y[D|V] | -N[D|V]] [\\\\computername]\r\n\r\n -Y Sets the system to start all disk performance counters\r\n when the system is restarted.\r\n\r\n -YD Enables the disk performance counters for physical drives.\r\n when the system is restarted.\r\n -YV Enables the disk performance counters for logical drives\r\n or storage volumes when the system is restarted.\r\n -N Sets the system to disable all disk performance counters\r\n when the system is restarted.\r\n\r\n -ND Disables the disk performance counters for physical drives.\r\n -NV Disables the disk performance counters for logical drives.\r\n \\\\computername Is the name of the computer you want to\r\n see or set disk performance counter use.\r\n The computer must be a Windows 2000 system.\r\n NOTE: Disk performance counters are permanently enabled on\r\n systems beyond Windows 2000.\r\n" }, "diskshadow.exe-25D9F4FFB0BCD199ED4B819C24C1277D": { "file_name": "diskshadow.exe", "file_path": "C:\\Windows\\SysWOW64\\diskshadow.exe", "hash_md5": "25D9F4FFB0BCD199ED4B819C24C1277D", "hash_sha1": "CDA5557ABE6F6D52CAD546D3839B29AAF3749D90", "hash_sha256": "4DC14FAD188ADAD5F06442F40C1698362BA0C7FA585B108AEDCDC792921DF233", "hash_sha384": "07EE3E59DF73C18936FDED63B7141A8B61A768C83B5560453832B00300A8AF7412367B1CEF5E47FC854D2FAD42B57A5F", "hash_sha512": "83B0F8C3E16299C7F540A0C4CA25181B2B529F3A42B000E488C5FAAF2D9E3CE939DDFDAA26925D3BF6251975E09ABCFF202D245BACC02D80B7207C98CEE66BE9", "hash_ssdeep": "6144:PZQ5sJS74kNNodXUDWiOzRQVZwR5SinzKa:PZAsJSzNoxUVO1QVZALnua", "hash_imp": "1A4F9685945290778DB93CF99E1C71CF", "hash_pesha1": "D172931BEE4CA97BB5C1DB3D08ACAF1565E15C1B", "hash_pe256": "B736B129F1925A63994A7EB2347803AD43D67DAE3751B071FABB302C1456A650", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DiskShadow", "meta_original_filename": "diskshadow.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/4dc14fad188adad5f06442f40c1698362ba0c7fa585b108aedcdc792921df233/detection/", "output": "Microsoft DiskShadow version 1.0\r\nCopyright (C) 2013 Microsoft Corporation\r\nOn computer: Default-PC, 10/19/2020 9:57:13 PM\r\n\r\nDISKSHADOW.EXE [/s <scriptfile> [param1] [param2] [param3] ...] [/l <logfile>]\r\n - Runs script mode\r\n\r\nDISKSHADOW.EXE [/l <logfile>]\r\n - Interactive mode\r\n\r\n /s <scriptfile> [param1] [param2] [param3] ... [paramX]\r\n - Script mode. Include environment parameters in script using\r\n %DISKSH_PARAM_1%, %DISKSH_PARAM_2%, %DISKSH_PARAM_3%, ..., %DISKSH_PARAM_X%\r\n to reference [paramX] above.\r\n /l <logfile> - Output log file\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\diskshadow.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Dism.exe-9D670E39C17B5E6375EA17B41CF3A47A": { "file_name": "Dism.exe", "file_path": "C:\\Windows\\SysWOW64\\Dism.exe", "hash_md5": "9D670E39C17B5E6375EA17B41CF3A47A", "hash_sha1": "DB7558C23CF0B603C48F89D1424F4BBBF9AF5BA2", "hash_sha256": "86352060D90D48AFFABDED6F50BA676F25C472AABF421B17A2B19C0B8C29A1FB", "hash_sha384": "7FB46156BAFDB89A68FE9D3347A39B867F6BC7A67660C9BF3AFA998FC5A3526E83677994C5B8090A13511472259009B1", "hash_sha512": "25CF5DA672D53E953513B5C3C9AAFE39E10FE659F0B3B362131399D757F8182E1A18D3B9A2F865C4F000A97AD122614D726AAEE08CBD60D656937137E7A2A464", "hash_ssdeep": "3072:Cgu75RF5ZQ582+GHGFi3oZmNxsK3WRSX7AdwTqBUIhzcTzL/M0MVrT3RT0b:C9vF5m82Hb3oB5RSEwWUIJ2zLgro", "hash_imp": "73B26C2319D9DCA391B1F2968C70999C", "hash_pesha1": "16AB956B028E33DBE498F507F309CFFDC37CCB31", "hash_pe256": "FE1448A0FA370EAF87138BEEFD9D73EE292F058EBBE4EBB09E46F704F90BCD0C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Dism Image Servicing Utility", "meta_original_filename": "DISM.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nDeployment Image Servicing and Management tool\r\nVersion: 10.0.17763.1518\r\n\r\n\r\nDISM.exe [dism_options] {Imaging_command} [<Imaging_arguments>]\r\nDISM.exe {/Image:<path_to_offline_image> | /Online} [dism_options] \r\n {servicing_command} [<servicing_arguments>]\r\n\r\nDESCRIPTION:\r\n\r\n DISM enumerates, installs, uninstalls, configures, and updates features\r\n and packages in Windows images. The commands that are available depend \r\n on the image being serviced and whether the image is offline or running.\r\n\r\n\r\nGENERIC IMAGING COMMANDS:\r\n\r\n /Split-Image - Splits an existing .wim file into multiple \r\n read-only split WIM (SWM) files.\r\n /Apply-Image - Applies an image.\r\n /Get-MountedImageInfo - Displays information about mounted WIM and VHD\r\n images.\r\n /Get-ImageInfo - Displays information about images in a WIM, a VHD\r\n or a FFU file.\r\n /Commit-Image - Saves changes to a mounted WIM or VHD image.\r\n /Unmount-Image - Unmounts a mounted WIM or VHD image.\r\n /Mount-Image - Mounts an image from a WIM or VHD file.\r\n /Remount-Image - Recovers an orphaned image mount directory.\r\n /Cleanup-Mountpoints - Deletes resources associated with corrupted\r\n mounted images.\r\n\r\nWIM COMMANDS:\r\n\r\n /Apply-CustomDataImage - Dehydrates files contained in the custom data image.\r\n /Capture-CustomImage - Captures customizations into a delta WIM file on a \r\n WIMBoot system. Captured directories include all \r\n subfolders and data.\r\n /Get-WIMBootEntry - Displays WIMBoot configuration entries for the \r\n specified disk volume.\r\n /Update-WIMBootEntry - Updates WIMBoot configuration entry for the \r\n specified disk volume.\r\n /List-Image - Displays a list of the files and folders in a \r\n specified image.\r\n /Delete-Image - Deletes the specified volume image from a WIM file\r\n that has multiple volume images.\r\n /Export-Image - Exports a copy of the specified image to another\r\n file.\r\n /Append-Image - Adds another image to a WIM file.\r\n /Capture-Image - Captures an image of a drive into a new WIM file.\r\n Captured directories include all subfolders and \r\n data.\r\n /Get-MountedWimInfo - Displays information about mounted WIM images.\r\n /Get-WimInfo - Displays information about images in a WIM file.\r\n /Commit-Wim - Saves changes to a mounted WIM image.\r\n /Unmount-Wim - Unmounts a mounted WIM image.\r\n /Mount-Wim - Mounts an image from a WIM file.\r\n /Remount-Wim - Recovers an orphaned WIM mount directory.\r\n /Cleanup-Wim - Deletes resources associated with mounted WIM \r\n images that are corrupted.\r\n\r\nFFU COMMANDS:\r\n\r\n /Capture-Ffu - Captures a physical disk image into a new FFU file.\r\n /Apply-Ffu - Applies an .ffu image.\r\n /Split-Ffu - Splits an existing .ffu file into multiple read-only\r\n split FFU files.\r\n\r\nIMAGE SPECIFICATIONS:\r\n\r\n /Online - Targets the running operating system.\r\n /Image - Specifies the path to the root directory of an\r\n offline Windows image.\r\n\r\nDISM OPTIONS:\r\n\r\n /English - Displays command line output in English.\r\n /Format - Specifies the report output format.\r\n /WinDir - Specifies the path to the Windows directory.\r\n /SysDriveDir - Specifies the path to the system-loader file named\r\n BootMgr.\r\n /LogPath - Specifies the logfile path.\r\n /LogLevel - Specifies the output level shown in the log (1-4).\r\n /NoRestart - Suppresses automatic reboots and reboot prompts.\r\n /Quiet - Suppresses all output except for error messages.\r\n /ScratchDir - Specifies the path to a scratch directory.\r\n\r\nFor more information about these DISM options and their arguments, specify an\r\noption immediately before /?.\r\n\r\n Examples: \r\n DISM.exe /Mount-Wim /?\r\n DISM.exe /ScratchDir /?\r\n DISM.exe /Image:C:\\test\\offline /?\r\n DISM.exe /Online /?\r\n\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Dism.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dllhost.exe-B5A6D2FB3F4521C37D613DE52AB3467D": { "file_name": "dllhost.exe", "file_path": "C:\\Windows\\SysWOW64\\dllhost.exe", "hash_md5": "B5A6D2FB3F4521C37D613DE52AB3467D", "hash_sha1": "ACCEC11EA57BF2260D9C31C2C32D01CCA940E3D6", "hash_sha256": "F95B7BA752C6452DA9D83F84CA7307AE079D220718BCB2BABF145903BAC894DD", "hash_sha384": "C57856474AD5B0067A6576726CB0699C5E0B0EBC5EF67EBE103D9AA6916067E349C6D50E704CA88C897300459A4E5792", "hash_sha512": "FBE13C39C6FC6CD8653F3BCE97F36104D2457F62574336A4E5FFEA0FC51A9D3FBBE657AEA8CF037F492AE4983B2141E116235208EBBBA3CB55F9C291ACB6641E", "hash_ssdeep": "384:3bme1zCcDlan3MNcyWL5W6RmXjDBRJadWJZ6lPUs2L:K0XBe3MNc/doXj1PaWb", "hash_imp": "FB1328DBA53A95E7775F51164B2E5AEB", "hash_pesha1": "488EDC7DD3B05021B69B3AF76702CAEAD44C9E34", "hash_pe256": "1D4128888B571B4DF5E627BAF56E2D6254D43CFC3D08BD94795EFE882AF0EFD3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM Surrogate", "meta_original_filename": "dllhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/f95b7ba752c6452da9d83f84ca7307ae079d220718bcb2babf145903bac894dd/detection/" }, "dllhst3g.exe-1B28F879A5BC06E9710F3B22B4F32998": { "file_name": "dllhst3g.exe", "file_path": "C:\\Windows\\SysWOW64\\dllhst3g.exe", "hash_md5": "1B28F879A5BC06E9710F3B22B4F32998", "hash_sha1": "DA753CDEC1EFEC0B7BDDD438A9D0D386AB2F651C", "hash_sha256": "F814061AD1FF183B6A8AC3DF9A8377E042F527C9A15D276CCC0493FB47AA8962", "hash_sha384": "F48526BE9407EAA9B4090608245D1ECA738D163008A21DD53E3B8E452343BD3A6B76331B06C710B278F97A295B192AF2", "hash_sha512": "F0FAF5EE940BE78FE989364527A136AA871C552B02996574C53D2A78EFB6F42FAF1FB1B0A31E97DD2FC4500523789E514B0A845A4B24C3780D769A1BAA46274F", "hash_ssdeep": "192:3XB7q1RVfvzCMeSD9Q9nn3MCKw0ufEDcCWeyWag:3XRe1zCcD9an3MNcCWeyWa", "hash_imp": "FB1328DBA53A95E7775F51164B2E5AEB", "hash_pesha1": "7340BF7CD07510C7AE8793FC123C68597068B1BE", "hash_pe256": "0221189BAA6CEBFEFB87EB24843FB722576706AC7E9FE01C84791716B7B96928", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM Surrogate", "meta_original_filename": "dllhst3g.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/f814061ad1ff183b6a8ac3df9a8377e042f527c9a15d276ccc0493fb47aa8962/detection/" }, "doskey.exe-F2031043788E6020B7E517A4ACCA4715": { "file_name": "doskey.exe", "file_path": "C:\\Windows\\SysWOW64\\doskey.exe", "hash_md5": "F2031043788E6020B7E517A4ACCA4715", "hash_sha1": "B24E777B5B27F70CAC26300E1AD64FE024E6B509", "hash_sha256": "59F8910653EF69DCCD0E1C4EF13FD13E5162AFD8EAE96D8DD75F73A7F0A4D442", "hash_sha384": "0FFC10D64F22270B765377BBCCB80D856D24A6EABA05CF0A878715968A1072016E910DD4CF4EDDB3E6AD132A6A0AB4F1", "hash_sha512": "C1B2D65E7E0D112C4BE8BF38D238DE0FFF23983EEB1DBA64147422EBD7CED40BA7C901617EC0966A0D9064B021D72BEBFA41B15726DF2AB70ADB962AF98CF26F", "hash_ssdeep": "192:b7QqWEftZbnLlltRLMRoeXpafGhW4doS2mDXUkSV3tSWRRkXWTiWbVjFC:/xZbnLLIXI8WNS2bFMXWTiWb", "hash_imp": "815CEBC8099878FCFC3EEFE858FAB97B", "hash_pesha1": "646C542F9BA2E444FA93820E3302FDDCCD333148", "hash_pe256": "B4DF61395DF6A84005D553BAE8E3AE6B2D5F0C811AE6F8610DC14DB215181680", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Keyboard History Utility", "meta_original_filename": "DOSKEY.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/59f8910653ef69dccd0e1c4ef13fd13e5162afd8eae96d8dd75f73a7f0a4d442/detection/", "output": "Edits command lines, recalls Windows commands, and creates macros.\r\n\r\nDOSKEY [/REINSTALL] [/LISTSIZE=size] [/MACROS[:ALL | :exename]]\r\n [/HISTORY] [/INSERT | /OVERSTRIKE] [/EXENAME=exename] [/MACROFILE=filename]\r\n [macroname=[text]]\r\n\r\n /REINSTALL Installs a new copy of Doskey.\r\n /LISTSIZE=size Sets size of command history buffer.\r\n /MACROS Displays all Doskey macros.\r\n /MACROS:ALL Displays all Doskey macros for all executables which have\r\n Doskey macros.\r\n /MACROS:exename Displays all Doskey macros for the given executable.\r\n /HISTORY Displays all commands stored in memory.\r\n /INSERT Specifies that new text you type is inserted in old text.\r\n /OVERSTRIKE Specifies that new text overwrites old text.\r\n /EXENAME=exename Specifies the executable.\r\n /MACROFILE=filename Specifies a file of macros to install.\r\n macroname Specifies a name for a macro you create.\r\n text Specifies commands you want to record.\r\n\r\nUP and DOWN ARROWS recall commands; ESC clears command line; F7 displays\r\ncommand history; ALT+F7 clears command history; F8 searches command\r\nhistory; F9 selects a command by number; ALT+F10 clears macro definitions.\r\n\r\nThe following are some special codes in Doskey macro definitions:\r\n$T Command separator. Allows multiple commands in a macro.\r\n$1-$9 Batch parameters. Equivalent to %1-%9 in batch programs.\r\n$* Symbol replaced by everything following macro name on command line.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\doskey.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dpapimig.exe-6795AC963DD19F525D4C003128B541E6": { "file_name": "dpapimig.exe", "file_path": "C:\\Windows\\SysWOW64\\dpapimig.exe", "hash_md5": "6795AC963DD19F525D4C003128B541E6", "hash_sha1": "11F9F6CE7CA99094EAFCFC71A963A2083C2A871F", "hash_sha256": "E9F1F2C4FBCA349CBA6D1F3039FF6AD9375A702101A9D69D602E263323BC15FE", "hash_sha384": "168639BCC9501C0890E9D4D50C65CA3C055DF2C635C7943A91BB1857B26C714EA26D47407F9C607B89CD5511CEBEEE01", "hash_sha512": "30754BD089B15938305EE8FF29103C973EE42891E91CFB859C2EB42E7F3281C28D26DF976E8FE72ECC062BE6E8784DD17BB05AA186960E36EC7DF517EB94E59F", "hash_ssdeep": "1536:ZpYmmfMkDbZKQUZir/QxkvstQ00l3uU1HIED1fCbWpygzU:rYmmfpKlt/SJj16bE", "hash_imp": "DA3FB0A7EB3F23A19BB11529165AC3DA", "hash_pesha1": "5FF76E0D46548432015956DFE065EFD23BD7F61E", "hash_pe256": "021D77E2B70BB3FB8AC9542539B28C45EB714371AB14EF762FB6B7EFA3A248D7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DPAPI Key Migration Wizard", "meta_original_filename": "dpapimig.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/e9f1f2c4fbca349cba6d1f3039ff6ad9375a702101a9d69d602e263323bc15fe/detection/" }, "DpiScaling.exe-4D298B8E380BA853A5FCCE8E6DDE6A87": { "file_name": "DpiScaling.exe", "file_path": "C:\\Windows\\SysWOW64\\DpiScaling.exe", "hash_md5": "4D298B8E380BA853A5FCCE8E6DDE6A87", "hash_sha1": "0EE09F34BE96B9D17DC7952241748A9B781A8500", "hash_sha256": "F791BBE8DFAA3456FC94E0525BFEDCEEDFB4F0B1F38F17829199FCA5F0D9D09D", "hash_sha384": "252B6AD2FA246A107E0C9C2EFDE2546240754B11603DDE3723DDABB0EEF8D099B70FA69EA852F423E7EF7CD9361CCC43", "hash_sha512": "445B258A58CC5820C7D1584CA6F937DAD8A8E079A51CDB5E900392C284D69EE8497ED3056C5B3CDBCEA22E0BDDC062AEBA2D157BEE7FF3861D491CABF66B1711", "hash_ssdeep": "1536:EpxZI91OwxgwYfPSqlGv+BNXNvuZS36EDtAZ7jz6dTdMQiMtYwJjPS:E1OOwNMSqoKXNvuZAFDqXzlzQz", "hash_imp": "91ACA85D178C3B3F6B7A2FAD4CCCBEE7", "hash_pesha1": "DDA17A9512A1DBEC43FF40ACA77EB4898ED7924A", "hash_pe256": "EC79D8397F9B8AA5A0B48AE0FD1745C69ADB31922BFE2A498A07D9A0C981D53C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Display Control Panel", "meta_original_filename": "DPISCALING.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/f791bbe8dfaa3456fc94e0525bfedceedfb4f0b1f38f17829199fca5f0d9d09d/detection/", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\DpiScaling.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dplaysvr.exe-CAE5B6694E11B44098AD7F5C2FC8C8B9": { "file_name": "dplaysvr.exe", "file_path": "C:\\Windows\\SysWOW64\\dplaysvr.exe", "hash_md5": "CAE5B6694E11B44098AD7F5C2FC8C8B9", "hash_sha1": "FDB32678A46D15007A0030644B5F49E4A634BADA", "hash_sha256": "991AAB6B229A376B02B64D95F5DAC5059C33AA8CC914A640201A95D556B21399", "hash_sha384": "300044B87C048CD6469F5A29F2DC1A366E9921670E352887549E22AFCC45D5C6975827496B1FF448C79329ABE540A904", "hash_sha512": "C4EFE82FA2466BFDDE190CAB36BED277E7E205E13C666BDA22BC0D75956344F45C35E71B5590D68F52C65ACC612DFF9B2C6205C36975592BEFC387C6621A759A", "hash_ssdeep": "96:vpah+44u+Mm9Kf+cCZnM2jsh/O2ZwmV40EWGuWwIV:vMQ4V+MEcK0GKwmVqWGuW", "hash_imp": "E0BD3263FD5EA99B1D0C2F6F5194CC24", "hash_pesha1": "E9096EB4F59712F1627126154A953F4871A386A5", "hash_pe256": "475683ABAFB5E83601CAA7A117FCEF116271FD01526D645AC60D810D72B2FADE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DirectPlay Stub", "meta_original_filename": "wcodstub.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/991aab6b229a376b02b64d95f5dac5059c33aa8cc914a640201a95d556b21399/detection/" }, "dpnsvr.exe-CAE5B6694E11B44098AD7F5C2FC8C8B9": { "file_name": "dpnsvr.exe", "file_path": "C:\\Windows\\SysWOW64\\dpnsvr.exe", "hash_md5": "CAE5B6694E11B44098AD7F5C2FC8C8B9", "hash_sha1": "FDB32678A46D15007A0030644B5F49E4A634BADA", "hash_sha256": "991AAB6B229A376B02B64D95F5DAC5059C33AA8CC914A640201A95D556B21399", "hash_sha384": "300044B87C048CD6469F5A29F2DC1A366E9921670E352887549E22AFCC45D5C6975827496B1FF448C79329ABE540A904", "hash_sha512": "C4EFE82FA2466BFDDE190CAB36BED277E7E205E13C666BDA22BC0D75956344F45C35E71B5590D68F52C65ACC612DFF9B2C6205C36975592BEFC387C6621A759A", "hash_ssdeep": "96:vpah+44u+Mm9Kf+cCZnM2jsh/O2ZwmV40EWGuWwIV:vMQ4V+MEcK0GKwmVqWGuW", "hash_imp": "E0BD3263FD5EA99B1D0C2F6F5194CC24", "hash_pesha1": "E9096EB4F59712F1627126154A953F4871A386A5", "hash_pe256": "475683ABAFB5E83601CAA7A117FCEF116271FD01526D645AC60D810D72B2FADE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DirectPlay Stub", "meta_original_filename": "wcodstub.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/991aab6b229a376b02b64d95f5dac5059c33aa8cc914a640201a95d556b21399/detection/" }, "driverquery.exe-35E01178B770031DCDFF984A49F57D90": { "file_name": "driverquery.exe", "file_path": "C:\\Windows\\SysWOW64\\driverquery.exe", "hash_md5": "35E01178B770031DCDFF984A49F57D90", "hash_sha1": "575D01167CE84F32E30C597113434076BAA1901F", "hash_sha256": "54BD0E8075F63285C1408516913ABD9913BA058A80A43E345AD42B34F36F6C12", "hash_sha384": "B87E37B6A1E173F8AA31933F569CDF5E6749C67E5836EC688ED9E20E92A7C91AF287F2D6ED02702148D1960051AA414F", "hash_sha512": "EB0935C6E6CFDC2AF4F3687957C0FCE837BC95765CAB646E237F90A46D3046A063A57C9BD568955E867C6AE900DB1B17EF930F154AF4D62AE96D07F49B2DC654", "hash_ssdeep": "1536:USJKP28Q/NA/HleeW38KYYcW+lQgi/uTjBgS/InxDJjLTK:E0NA/UsbYcGgikgnxdjL2", "hash_imp": "F43657274705381484D63C59A47DACF7", "hash_pesha1": "9E074AAF1A4FF0FFC4970D95B52F761643BEE989", "hash_pe256": "9C25217A56AE02764ACC1AD6DFAEA87B795A73F68782A7F28A5E793A20DAEF68", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Queries the drivers on a system", "meta_original_filename": "drvqry.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/54bd0e8075f63285c1408516913abd9913ba058a80a43e345ad42b34f36f6c12/detection/", "output": "\r\nDRIVERQUERY [/S system [/U username [/P [password]]]]\r\n [/FO format] [/NH] [/SI] [/V] \r\nDescription:\r\n Enables an administrator to display a list of \r\n installed device drivers.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context \r\n under which the command should execute.\r\n\r\n /P [password] Specify the password for the given \r\n user context.\r\n\r\n /FO format Specifies the type of output to display.\r\n Valid values to be passed with the\r\n switch are \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" \r\n should not be displayed. Valid for \r\n \"TABLE\" and \"CSV\" format only.\r\n\r\n /SI Provides information about signed drivers.\r\n\r\n /V Displays verbose output. Not valid \r\n for signed drivers.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n DRIVERQUERY\r\n DRIVERQUERY /FO CSV /SI\r\n DRIVERQUERY /NH\r\n DRIVERQUERY /S ipaddress /U user /V \r\n DRIVERQUERY /S system /U domain\\user /P password /FO LIST\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\driverquery.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"DRIVERQUERY /?\" for usage.\r\n" }, "dtdump.exe-74A3A862FB349D64357D5219EA711D4F": { "file_name": "dtdump.exe", "file_path": "C:\\Windows\\SysWOW64\\dtdump.exe", "hash_md5": "74A3A862FB349D64357D5219EA711D4F", "hash_sha1": "5FFEC70E8133232E956F65703B998FC0DA5CDE9C", "hash_sha256": "6EE12F9E2FF2341F8C7ACDFFF069F33EB3733AFABB79276D14CB3FD78D61ADE5", "hash_sha384": "F272D5FEA444449E2E710DA542500B2518F3A9EACE667C7905902EDEE97D91CAA6F3B3BCBF260EB2473682AA6538BAF5", "hash_sha512": "F5478CB30B63640433390F1510AFE104AF7430DBDD3D576E0953856C066A5DAAC2217E430445ABC88A700393CE502340422505FA51421B2C4B97FC4486FC2027", "hash_ssdeep": "1536:5jaJT/bph6rM1ZsXZ6gvP2WSHV+SsunZfzBO0LeBzvIN35DAjRj8:haFD6rM1+Igv+WSHlnZ9pDkZ", "hash_imp": "E9EE3C17FDA6CDAFA2FEBE014F32BF8D", "hash_pesha1": "BEB714635940A22D0A1B5DC6D3BB51B19F285178", "hash_pe256": "F5775390D3D64B36124C7404EE38524A3F8746E7677F8F77E84DE29B27AAFF09", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DTDUMP.EXE", "meta_original_filename": "DTDUMP.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Windows\\SysWOW64\\dtdump.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "dvdplay.exe-D240F4F3C7AABA6F1F7D52A99FDF0F22": { "file_name": "dvdplay.exe", "file_path": "C:\\Windows\\SysWOW64\\dvdplay.exe", "hash_md5": "D240F4F3C7AABA6F1F7D52A99FDF0F22", "hash_sha1": "54FA660F636DFABA419271E0D62AE5671F143D94", "hash_sha256": "28695005C5B4780B5258367964580AF6568AC187D0E8726EB1C70370AD042CB8", "hash_sha384": "597D38E9501D93339EA2CFE64CFD96934B0C730FBD249356AAFBF3D2C8A81034351155CC579199BCFA842AC26552488D", "hash_sha512": "0B69B622C33D7769B9BE67A4A6AB2B30D0F28F4C55500CFD71F4D37042F25306C9A78FAB9C11DB2EE23DAA2A27AAD2F95ED2532E28675ECEC856E09C5C79F2C2", "hash_ssdeep": "192:5SbXs35rsq9oqtm/koPjhFiwWdZW2okh:0s35rsqum/ExWdZW2h", "hash_imp": "E039C46E30A89ABAF651718C922747B4", "hash_pesha1": "22DA1C74D2EA395CE0E235E2959D577E32EB293F", "hash_pe256": "8FC353D49DBB9656E67F7C2FCCA13BB984DAFFC6F6382936999A7E17587D5B38", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "dvdplay placeholder Application", "meta_original_filename": "dvdplay", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/28695005c5b4780b5258367964580af6568ac187d0e8726eb1c70370ad042cb8/detection/", "children": "wmplayer.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\dvdplay.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "DWWIN.EXE-D99D78D1814071C80407766FBE4D74A9": { "file_name": "DWWIN.EXE", "file_path": "C:\\Windows\\SysWOW64\\DWWIN.EXE", "hash_md5": "D99D78D1814071C80407766FBE4D74A9", "hash_sha1": "BDC8B6A87BA68384518A313786C60B8530F0E2BF", "hash_sha256": "63DA39C618ACF8FFD5BCA9E2AFA80E97307BE6E5FE61A90D491242709CF04274", "hash_sha384": "502D92EE434F07F3B4A47D5420AE3483F002239248ED6D566543EDE6984518FC691CF023C5203D345DA2A127F65DFAAB", "hash_sha512": "71FC9BF905C83683C41E70E96545FCAACC386ADD06633D7B0865840DFEF9475ECA19CBDBC1AD27BEC60C2F2894FE6BA446A4536D7270E6613EFE719142C7C070", "hash_ssdeep": "3072:k43XN650sLfsyu1xoVcEI2JiQyhz8EfVs3WlxeeGAibGkNChq8x5KuB4dA3b:kMXNs02nQxoVSQTEtccxAmKuZL", "hash_imp": "D500768FFA90AE7CF06B5D354276BFBD", "hash_pesha1": "C2D29F0634978565F3C81C42FB367FF9E0A13F62", "hash_pe256": "D77EE52586BDCCC5D71E92F0589A0DB893FF5F97DA9B195CF98FDA06B8F48F1F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Error Reporting", "meta_original_filename": "DWWIN", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "dxdiag.exe-7B13D1B4C73C9662BE1543657BA1809E": { "file_name": "dxdiag.exe", "file_path": "C:\\Windows\\SysWOW64\\dxdiag.exe", "hash_md5": "7B13D1B4C73C9662BE1543657BA1809E", "hash_sha1": "5C29EC83D21A84D55A85C7D968ED848872E7B222", "hash_sha256": "61A5F3A9E4307DCBA263F68D6BC470EBDC7DC4BBDF75F872E200E10E97552341", "hash_sha384": "9C80FE46A01D4064FEDEB64CD7530EF84D3698A6BDF73613AAA5F09F76CA88FCDF1A1902CD62CE0B1325FABE2C976728", "hash_sha512": "6AD712CC325DD9D43292267842BA0E364A9316DE3CCD492B59428B1899338B31039222B0801C5243D8523F94DFF6EADD55675E7DA7335AE1781BC2F3E4500827", "hash_ssdeep": "6144:LhALu5bNoRvngmNZnzJ4P1inCb0BFkmPHK:LhERvgWB94P1uu0BxP", "hash_imp": "565C6ED75710FE55AB5863E72FE6F1D4", "hash_pesha1": "4F9E53EB74336EAB2F0F0D4C60C33036F4F7CC0A", "hash_pe256": "25AE5DFC52DF81FAB81B72A201CE9379910F1670E33B742FDB9AF849C7FC6445", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft DirectX Diagnostic Tool", "meta_original_filename": "dxdiag.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.475 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.475", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/61a5f3a9e4307dcba263f68d6bc470ebdc7dc4bbdf75f872e200e10e97552341/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\dxdiag.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\dxdiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "DirectX Diagnostic Tool" }, "EaseOfAccessDialog.exe-07A336072239B2FAEC1FEA0E23A23A88": { "file_name": "EaseOfAccessDialog.exe", "file_path": "C:\\Windows\\SysWOW64\\EaseOfAccessDialog.exe", "hash_md5": "07A336072239B2FAEC1FEA0E23A23A88", "hash_sha1": "8D80E55F03BEE760F0D91BEA9353257507CA1914", "hash_sha256": "A0AC8FD55F8500F5290DCD890820B8FABF1CA31A06676F4F0DCE85B26C4A14A3", "hash_sha384": "9249C76B4F2DF8F9697D8F3952472EE05483187AEFE5434D8EC1481511D561B0CF24807F5687BBD2BBAD319E11515E1F", "hash_sha512": "8E75951D12AF020C7634704091AC9390B11E0CBD8AABEAA41756A3BE8D932060D5EFBD71F8DBE77AECF3FC2461BDC8D5D540D278953C1F6857DB1ED912326816", "hash_ssdeep": "6144:CqtFTcISa/yD0b5AlGrX6uFz2LJGRg4kLNnei36cw:FfSa/yGTFCdUc", "hash_imp": "C746B9EED21F897731F409C49E591446", "hash_pesha1": "C761923AE4210736960B660F11B0EAA20253817F", "hash_pe256": "033B4CFCD6F8507C653E74E8D3F6559B6DEE702C8637C14E52D810F8375474E3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Ease of Access Dialog Host", "meta_original_filename": "EaseOfAccessDialog.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/a0ac8fd55f8500f5290dcd890820b8fabf1ca31a06676f4f0dce85b26c4a14a3/detection/" }, "edpnotify.exe-B882664AAABD678F3CC399C2980B466E": { "file_name": "edpnotify.exe", "file_path": "C:\\Windows\\SysWOW64\\edpnotify.exe", "hash_md5": "B882664AAABD678F3CC399C2980B466E", "hash_sha1": "9B1C151D49E241E410F8BBD9EE88223C106A282A", "hash_sha256": "7CE0D1716206EA262EAC237EDFAD7C98CC0C73ECADDB5F0C307330190A44C5B1", "hash_sha384": "C78E9911BC06F1DA899058E8E0D904E501D867C55C4520075C37AD07A606E6D61EAFE65E04F63DA857208D70778B0DC3", "hash_sha512": "3EC75047848DF450D92870679AE990E9AA95F21F07F343B9A5A8F8E4BB19139A06F48CE09D2D35F830B09BAE44C95152EC7653D158DCFFA4DB270FC44852FA3C", "hash_ssdeep": "768:mih2lpRKt7hUtQgZnVUOxrhWRRPm67xcuIGE:miklcAQunaKAH/7xc5GE", "hash_imp": "A212252AB049E401F16861C6DCD5B30D", "hash_pesha1": "671A676EE6F70308EA0E0AEDED7204750E353231", "hash_pe256": "CA32C1A1E446FB75C3FCC8EA9F8922BF264B3E7D41E674A0A1C11B314C42663F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Enterpise Data Protection", "meta_original_filename": "EdpNotify.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/7ce0d1716206ea262eac237edfad7c98cc0c73ecaddb5f0c307330190a44c5b1/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECEBC": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\edpnotify.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "efsui.exe-8768372760F9FDFFA7C8B79C02DC3362": { "file_name": "efsui.exe", "file_path": "C:\\Windows\\SysWOW64\\efsui.exe", "hash_md5": "8768372760F9FDFFA7C8B79C02DC3362", "hash_sha1": "B6FF44BBC50A9EC12C46A568ED90691F34481A19", "hash_sha256": "7F9304A0B0492F3E18C46EA4D17EE1323B9AB27EE584FF4F25487F1D04820A6E", "hash_sha384": "8F37DF8E546AFF982B044717F5509287D6582C6A88DA13BAD4B458FF94397A8A31B1144B407D5BCE05EC56084C6AEA8F", "hash_sha512": "4831CC5855991089A50AE26B68EAAFFBA00BCFF389A42BB16912306B07B9780386F3966765853C04046F10FFC40C8B5FC35C9F653F2DAC1EA0CC91AC5CD91BEC", "hash_ssdeep": "192:Rle21dd+CWai6HIJO8AwO3DmBoBf1Z0kTxWSoRWUoD7:/JBWai6oRAwOqqDZHTxWSoRWX", "hash_imp": "FBFCDB62E39168BD77F5A0D82001C66C", "hash_pesha1": "B8FD2E63483FC8011DC07DD8E7F7AFD1D59BAF5B", "hash_pe256": "EF73CC25E543A798A9A60061DD807B633F49928EF6EC3AB1679C98F064F66DAE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EFS UI Application", "meta_original_filename": "efsui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/7f9304a0b0492f3e18c46ea4d17ee1323b9ab27ee584ff4f25487f1d04820a6e/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\efsui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "EhStorAuthn.exe-FA27C3D81CC5E8E13913771FC785BC5B": { "file_name": "EhStorAuthn.exe", "file_path": "C:\\Windows\\SysWOW64\\EhStorAuthn.exe", "hash_md5": "FA27C3D81CC5E8E13913771FC785BC5B", "hash_sha1": "BC7C42C626C1CF87849D3273221E3F9772ED233D", "hash_sha256": "3E8E7238533A1E251C9C607D84890FFA02983F02D5911A79DF557E328801A5DA", "hash_sha384": "F367E8C71D63783BFD4285C043834120B9C9C06F6A5BFB157D90507940B010650FA43B35952762CE4D1CA8CE3FF190EB", "hash_sha512": "69650257DEA801FC8DA0BC3A9FBAB8EAADF6F0447382B44E94F52105CEAC9E7024C912C66C052A1D5E4A9F6A67DD924861F247EEA27A12E241457E08298C5111", "hash_ssdeep": "1536:hqxyFsH2GHvnKVcTbdWfC0oeomgPHA5kG9mQ7N6wMkNaAYG5n8sJlkWP:9o2GfKV8MK0oxPxQZDFcZIZJlD", "hash_imp": "D8BEA4FEF46578B7424738F766C2A7CC", "hash_pesha1": "F4564CC26ECF30B2D4DDD071BD83C23A820B4965", "hash_pe256": "AEE8AAAE42AA37481AE2BF8BD56E57D0E14E0A2A3E3905B029AB6497600207BC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Enhanced Storage Authentication Program", "meta_original_filename": "EhStorAuthn.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/3e8e7238533a1e251c9c607d84890ffa02983f02d5911a79df557e328801a5da/detection/", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\EhStorAuthn.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "esentutl.exe-9489B81DE623E4C92342EF258D84B30F": { "file_name": "esentutl.exe", "file_path": "C:\\Windows\\SysWOW64\\esentutl.exe", "hash_md5": "9489B81DE623E4C92342EF258D84B30F", "hash_sha1": "13E0808AFD68FBB31DE1BF49082C017881E019A3", "hash_sha256": "1423E39922CF30ED6A9D0EB9BA463E6723FE166641DAB9F3B27E4A8D30ADDCB5", "hash_sha384": "5FAF132E09805B7822A52AE70A56E6421FCD1E78A413E736428ADC90989C042B0049C5F883C7829BD8A0A49F952DA6BD", "hash_sha512": "92EB6314C75DD04C815873578F34DF5171A58815ED9CC8FB0046B94EFFFA0131AB65565352B2C60C00B6781D85BAB0CF8BCE1024A75E44A4FA1437F6F4786660", "hash_ssdeep": "6144:4OrKGG0GHqzPRHGfRldZ+YWvWmA97UX0RA0jPqNBSljUvVF0:4ObG0chfbGvQBUX0RA0jPqHojUvL", "hash_imp": "71099B51C33E38DAA19CD45879503390", "hash_pesha1": "889C453A79B4496FB4EAE8EB4322FF31AB70C4B2", "hash_pe256": "EBE3C086288597CFF9F6CCA77690CA5B318271488918A3E9E4DC3F2D808F55E5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extensible Storage Engine Utilities for Microsoft(R) Windows(R)", "meta_original_filename": "esentutl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.529 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.529", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/1423e39922cf30ed6a9d0eb9ba463e6723fe166641dab9f3b27e4a8d30addcb5/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\esentutl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "eudcedit.exe-D306B9780453DF3FC0B8FF2538EFC064": { "file_name": "eudcedit.exe", "file_path": "C:\\Windows\\SysWOW64\\eudcedit.exe", "hash_md5": "D306B9780453DF3FC0B8FF2538EFC064", "hash_sha1": "736DCC0A6BFA7DF04131A909AD5B95705BBFEEC5", "hash_sha256": "4541091E0F28F0FE29A1C3ED9086922F0FCA4910AC3BD4178064B3CB8097AD20", "hash_sha384": "B0D7F1007B8EA62BC667470B32B4E0BE02B9DC8A4B60DAC9F4A9966071091DD5BF18A62D703E412FAC69E88C410ADA50", "hash_sha512": "E02C1A4C2F1547C98F3F29C176D87785D15D30C81A7829D29D29568FF47F3D39A340139FD30AFD3CD4D1E948EF942881F868C87A7626B0983FE5A551D6B14AB0", "hash_ssdeep": "6144:HCYgQlque35j+HeQ9kwFQ5TXHGLNIfqKoTJMGsWz3x1PZSqtYVmI:HqKxe3J+HvfKoTJMGj13tYEI", "hash_imp": "EEF3646DFC23E3A1E483EA3447F6D23F", "hash_pesha1": "47CBF0F92CB80F1EC4F7BE0E3C88464DDF6F65C1", "hash_pe256": "412933A95CD709D744CB04A5C4FBCF89DC941B8E8FEAC8D0C4BF35B6E467580C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Private Character Editor", "meta_original_filename": "EUDCEDIT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/4541091e0f28f0fe29a1c3ed9086922f0fca4910ac3bd4178064b3cb8097ad20/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\eudcedit.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\eudcedit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Private Character Editor " }, "eventcreate.exe-F4F9C1965981A7840F300E0FD6504793": { "file_name": "eventcreate.exe", "file_path": "C:\\Windows\\SysWOW64\\eventcreate.exe", "hash_md5": "F4F9C1965981A7840F300E0FD6504793", "hash_sha1": "1C364E47EEE0F542E60BC31DDC298512AA4D303C", "hash_sha256": "CF7F814331696E120864D5D8227EE5ABC3BA8B2E46D7E7DF20DC317DFA1D1434", "hash_sha384": "1E3555D1EE159B3096BCD22DDEEDE6D7BDE036C455F9A22C2DE709E9C111B033DEE13C0E0525E42D894ACFB243E8B4A4", "hash_sha512": "B8CC96923548CDBE5DA052227D5F14F3E1F16240D42F2F58CE8EB218C736789B2CA3B8A7208BE1C4A7C1812EB7722B9D04AFDE659DC207F04DED77BA664F1989", "hash_ssdeep": "768:x7Yg8N9Kk0JtbAvNNTCI6RPia8BSs8eUSndlVOoa+4U7:x7Yg8N91cRwzoRPi7VJVdlVva+4U", "hash_imp": "D9D5E96F73EC284F3BDBECE646CCF1EC", "hash_pesha1": "A8C112E86B9B7AD5EC6D3B1328A9E89C1BD03AE4", "hash_pe256": "B1D592AB9C0C0E6C7714EF2E3AC064E1409D5D2CDBAA7B60F669C790702CFF8F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Create - Creates a custom event in an event log", "meta_original_filename": "evcreate.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/cf7f814331696e120864d5d8227ee5abc3ba8b2e46d7e7df20dc317dfa1d1434/detection/", "output": "\r\nEVENTCREATE [/S system [/U username [/P [password]]]] /ID eventid\r\n [/L logname] [/SO srcname] /T type /D description\r\n\r\nDescription:\r\n This command line tool enables an administrator to create\r\n a custom event ID and message in a specified event log.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /L logname Specifies the event log to create\r\n an event in.\r\n\r\n /T type Specifies the type of event to create.\r\n Valid types: SUCCESS, ERROR, WARNING, INFORMATION.\r\n\r\n /SO source Specifies the source to use for the\r\n event (if not specified, source will default\r\n to 'eventcreate'). A valid source can be any\r\n string and should represent the application\r\n or component that is generating the event.\r\n\r\n /ID id Specifies the event ID for the event. A\r\n valid custom message ID is in the range\r\n of 1 - 1000.\r\n\r\n /D description Specifies the description text for the new event.\r\n\r\n /? Displays this help message.\r\n\r\n\r\nExamples:\r\n EVENTCREATE /T ERROR /ID 1000\r\n /L APPLICATION /D \"My custom error event for the application log\"\r\n\r\n EVENTCREATE /T ERROR /ID 999 /L APPLICATION\r\n /SO WinWord /D \"Winword event 999 happened due to low diskspace\"\r\n\r\n EVENTCREATE /S system /T ERROR /ID 100\r\n /L APPLICATION /D \"Custom job failed to install\"\r\n\r\n EVENTCREATE /S system /U user /P password /ID 1 /T ERROR\r\n /L APPLICATION /D \"User access failed due to invalid user credentials\"\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\eventcreate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"EVENTCREATE /?\" for usage.\r\n" }, "eventvwr.exe-B16623FDB9C4EB80BEC647F082D34969": { "file_name": "eventvwr.exe", "file_path": "C:\\Windows\\SysWOW64\\eventvwr.exe", "hash_md5": "B16623FDB9C4EB80BEC647F082D34969", "hash_sha1": "4BF0E85C7D84894427864051D012D30D610E6348", "hash_sha256": "963E6A79B77518FA2D4E45604764A5065EB4563F7AF7D1526DAD76AED49CD96E", "hash_sha384": "A64A1B527D3268E91D7BE70794E07F2EA0E8D14A4E8945E9F05F85C921B2B00B5D5E6917146510F4A4694D811796F471", "hash_sha512": "169F7707283F1892D092F620755A4E9F21DA8796AF945D9EB65DD2B7730B7A41CF6E8A15019D5EBC7AE2A762E5BCAC9C03BD3094BCF6C261A515B153DB85CD90", "hash_ssdeep": "1536:MzS4hIMfoJUhSU6nPlTggJ2oj71BgR/Vp8dY1kEF:W3lhzslTZJ9j7Heb8C1k", "hash_imp": "6202C13AD7EF6559EA1F41430390B2E0", "hash_pesha1": "5A271F0C36E75AB154EF6C6407DB2F1632D7FEE8", "hash_pe256": "1A21AD1A97FD1C026FF7AB3EF546DF116F4F4FC14722AE3F5CF6F14DA1CDB3D8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Viewer Snapin Launcher", "meta_original_filename": "eventvwr.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/963e6a79b77518fa2d4e45604764a5065eb4563f7af7d1526dad76aed49cd96e/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\eventvwr.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "Event Viewer", "children": "explorer.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\eventvwr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "expand.exe-B245CEEC35156CB95CAB80865F1A6D56": { "file_name": "expand.exe", "file_path": "C:\\Windows\\SysWOW64\\expand.exe", "hash_md5": "B245CEEC35156CB95CAB80865F1A6D56", "hash_sha1": "79374B8230443624E788DF8C9B0964D9B5D16FD4", "hash_sha256": "F8603F7E5E3158E5E381854E1036781269C56A7671555628AB20C1102640AC3F", "hash_sha384": "A53D012065A518179327DBA99528C12B1C933CE3D74A3A397ACB3503F36709EFCA13A38592933B185ECBDFB84B68B718", "hash_sha512": "C0930E0775EC60F8CA80D2FCA73B2721186F935FF8922F4AF02DB913D287F2EAA9532E325B062FFBD62F879458A5D93D2D2A11C833BB2D93368E294628CB6CE8", "hash_ssdeep": "768:C6xmXuiialKHTiPgnwFdPAMA2mciTtbnlveD7UUVAxCMUn:C6xiu/HOonwFdPAQmHT9nxtsMUn", "hash_imp": "69150CCEA4BC1D53D379CE29BCAE7760", "hash_pesha1": "4DCD88B2BE3EB13D2F0718E28ECD79A898167560", "hash_pe256": "80550E6E0DF28D6BE5E800BAF25E4B0C03537FD6978B78EDF089AB142863309E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "LZ Expansion Utility", "meta_original_filename": "expand", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.00 (WinBuild.160101.0800)", "meta_product_version": "5.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/f8603f7e5e3158e5e381854e1036781269c56a7671555628ab20c1102640ac3f/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\expand.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "output": "Microsoft (R) File Expansion Utility\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nNo destination specified for: help.\r\n" }, "explorer.exe-AA0CA518E66F290FE0BAC6169473E8A9": { "file_name": "explorer.exe", "file_path": "C:\\Windows\\SysWOW64\\explorer.exe", "hash_md5": "AA0CA518E66F290FE0BAC6169473E8A9", "hash_sha1": "60E3F357B06AF9EB84FB9019BF08FB4DD109D4EC", "hash_sha256": "0D7CB0B75CD61CDFFE0E53910829FFA5C02C8759EBD27A49E2EF7A907A10E506", "hash_sha384": "9EF43F15495851E67AD8D758B34A318D8331631295C101DBE8FAF7FB1548B6F84795988D9C759F8C8EB03C613D252B33", "hash_sha512": "35ACAD9DA3161873B21F73516F351C8C6F7FD49DD2B8E23105E230D8DAB97C15607AF7F8EA3725F2C013D11CDB0B95CF26DD556E713ADC134EC8354CAB494869", "hash_ssdeep": "49152:7LSf3pfF98als35V86y45nxm2GwHEbcOeZaauUgrKo/Ww8A7/eFwjDvv:o3pf38LVs45nI2GwHEY1A9jrcw8a0cD", "hash_imp": "FBEBD61CE702929C1F33B522FD572C5D", "hash_pesha1": "C8C30FDF3FD62E19528B0107BF1A200432CB6421", "hash_pe256": "435B9896B5C6E8F54F375B5BBCDF1587319DB9B52D2AF7D50D1EB35AEE108DD0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Explorer", "meta_original_filename": "EXPLORER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/0d7cb0b75cd61cdffe0e53910829ffa5c02c8759ebd27a49e2ef7a907a10e506/detection/", "children": "mmc.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\explorer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "extrac32.exe-86B9CB961782E250DC9ABA701AF1C4FA": { "file_name": "extrac32.exe", "file_path": "C:\\Windows\\SysWOW64\\extrac32.exe", "hash_md5": "86B9CB961782E250DC9ABA701AF1C4FA", "hash_sha1": "998B6BDC5AD215818F45246E0DD053D1ACAF9A2A", "hash_sha256": "2E2CAFD7954A9FB3FD321194BD3BB691CECEE01189A51E821ED1B40DCE929007", "hash_sha384": "F184B267CBDBA09A7F451CDFCB9EBF765CBA5E0FDC4C15304CA3505C9E37C268F1F45081997808600D0F24819F823A56", "hash_sha512": "C8B36D911AA86F209417218BAA11427FE926B71A3FC9387BE205FBDEF7655E788EBE274461070132EC9223E097CB485A54FFB1A75C572DB5F5B3D8A33AFDACBE", "hash_ssdeep": "768:zYDhe6vxKKGWodru4ZpzBnaLR6ZQhLhstdNus:zOheqxKbpz5a1nhYXus", "hash_imp": "7B1D3FE0DC6AA68A34FB0D96A1457FE6", "hash_pesha1": "22A91BE5D344D76F3FD2F1A2ED73E010CBB01A6C", "hash_pe256": "080FE009C5345D5D80687ABA9E37DB967040DBDCF3201376A72FB9C84E5B3502", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft CAB File Extract Utility", "meta_original_filename": "extrac32.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.00 (WinBuild.160101.0800)", "meta_product_version": "5.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/2e2cafd7954a9fb3fd321194bd3bb691cecee01189a51e821ed1b40dce929007/detection/", "output": "Microsoft (R) Cabinet Extraction Tool\r\nCopyright (c) Microsoft Corporation. All rights reserved..\r\n\r\nEXTRACT [/Y] [/A] [/D | /E] [/L dir] cabinet [filename ...]\r\nEXTRACT [/Y] source [newname]\r\nEXTRACT [/Y] /C source destination\r\n\r\n cabinet - Cabinet file (contains two or more files).\r\n filename - Name of the file to extract from the cabinet.\r\n Wild cards and multiple filenames (separated by\r\n blanks) may be used.\r\n\r\n source - Compressed file (a cabinet with only one file).\r\n newname - New filename to give the extracted file.\r\n If not supplied, the original name is used.\r\n\r\n /A Process ALL cabinets. Follows cabinet chain\r\n starting in first cabinet mentioned.\r\n /C Copy source file to destination (to copy from DMF disks).\r\n /D Display cabinet directory (use with filename to avoid extract).\r\n /E Extract (use instead of *.* to extract all files).\r\n /L dir Location to place extracted files (default is current directory).\r\n /Y Do not prompt before overwriting an existing file.", "runtime_modules": [ "C:\\Windows\\SysWOW64\\extrac32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "fc.exe-DA85B2D6FDAE50FEA32F2A507FCA3B87": { "file_name": "fc.exe", "file_path": "C:\\Windows\\SysWOW64\\fc.exe", "hash_md5": "DA85B2D6FDAE50FEA32F2A507FCA3B87", "hash_sha1": "B3F220EF9343E1C8AEF4BFBDCF946BB172378584", "hash_sha256": "F22B3505D734E3733B39072664262EA84F8EF7FAA09CB3A4C1D589785D115EC1", "hash_sha384": "2521942F018A57F0DC8F8A8ACBEE4B16AB6A1EF3060A9CBD6A3BF7C0FC81DF196F0502A0DE075A9961B952AC3ACB97C6", "hash_sha512": "66E13C2189B69767CBB5CC24AA450A301794052B5A6C13EDBB78C344BA7F3E28A0D8A4BD02C47615EF60B1B94339A1E3CB51F777E60A5078AB2C85A42DD03B57", "hash_ssdeep": "384:beCpDo4g/qHpwwp9svt+j43NmRilpsQodDdXsxAES8Min6qbeWaYWM0i1:PDo4g2wwp9sF73o2YgaGaq1", "hash_imp": "8737B5A2A0AC9AC3783A38A0C047A140", "hash_pesha1": "E16BFCD7120F81C2CC09536516389749AC3256CA", "hash_pe256": "0C3F33587D68E659429F7BD7F809F129E047EFF27FA586405735670343D66B7A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DOS 5 File Compare Utility", "meta_original_filename": "FC.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/f22b3505d734e3733b39072664262ea84f8ef7faa09cb3a4c1d589785d115ec1/detection/", "output": "Compares two files or sets of files and displays the differences between\r\nthem\r\n\r\n\r\nFC [/A] [/C] [/L] [/LBn] [/N] [/OFF[LINE]] [/T] [/U] [/W] [/nnnn]\r\n [drive1:][path1]filename1 [drive2:][path2]filename2\r\nFC /B [drive1:][path1]filename1 [drive2:][path2]filename2\r\n\r\n /A Displays only first and last lines for each set of differences.\r\n /B Performs a binary comparison.\r\n /C Disregards the case of letters.\r\n /L Compares files as ASCII text.\r\n /LBn Sets the maximum consecutive mismatches to the specified\r\n number of lines.\r\n /N Displays the line numbers on an ASCII comparison.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n /T Does not expand tabs to spaces.\r\n /U Compare files as UNICODE text files.\r\n /W Compresses white space (tabs and spaces) for comparison.\r\n /nnnn Specifies the number of consecutive lines that must match\r\n after a mismatch.\r\n [drive1:][path1]filename1\r\n Specifies the first file or set of files to compare.\r\n [drive2:][path2]filename2\r\n Specifies the second file or set of files to compare.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\fc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "FC: Insufficient number of file specifications\r\n\r\n" }, "find.exe-F61F39E72D0874BA52D83B8D1BFDFDB4": { "file_name": "find.exe", "file_path": "C:\\Windows\\SysWOW64\\find.exe", "hash_md5": "F61F39E72D0874BA52D83B8D1BFDFDB4", "hash_sha1": "ECC0E6E32A27FFA8A78DCCA4DC0C645EBA72F459", "hash_sha256": "6A42C41B345F3F8A22E5F3658B4673ABAE612242ACF12042EC5DE4DEE57A98D8", "hash_sha384": "028D3BB098E820D6B7CDA8F8037BA88A6E2786822E506FB31DAA20F0C0E7647D4ABD6D88DD6D18AA4439E895F5080904", "hash_sha512": "E37A6621D44E2F25C27FCA07E3EB57B77FA71A439412050E3FE9900012CA0040B89BF530B9898D450AE67EDB6AE7DA338C5853270F12C8919A97A10DD786490F", "hash_ssdeep": "384:KyST+0IAVY83RUHNQ2m9MeKZKYe6QO0jWpIWju:KySS0IAVY83RUtLm9MeKZK6J0Cp", "hash_imp": "F1CCECB8E289C2632DEE607CD74A0CCA", "hash_pesha1": "9880DD0D6505751EB7A77C4B40A0E4126A24675F", "hash_pe256": "CE8DD57773D81EB78433FA7F640F1CE0D48A7567977BADF6F737E5443C8F68EC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Find String (grep) Utility", "meta_original_filename": "FIND.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/6a42c41b345f3f8a22e5f3658b4673abae612242acf12042ec5de4dee57a98d8/detection/", "output": "Searches for a text string in a file or files.\r\n\r\nFIND [/V] [/C] [/N] [/I] [/OFF[LINE]] \"string\" [[drive:][path]filename[ ...]]\r\n\r\n /V Displays all lines NOT containing the specified string.\r\n /C Displays only the count of lines containing the string.\r\n /N Displays line numbers with the displayed lines.\r\n /I Ignores the case of characters when searching for the string.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n \"string\" Specifies the text string to find.\r\n [drive:][path]filename\r\n Specifies a file or files to search.\r\n\r\nIf a path is not specified, FIND searches the text typed at the prompt\r\nor piped from another command.\r\n", "error": "FIND: Parameter format not correct\r\n" }, "findstr.exe-0CF22201B4A50DFF346974A17A5BC0ED": { "file_name": "findstr.exe", "file_path": "C:\\Windows\\SysWOW64\\findstr.exe", "hash_md5": "0CF22201B4A50DFF346974A17A5BC0ED", "hash_sha1": "EFD02B322F9B2C5D18C198AA80B0F68FB1F96217", "hash_sha256": "6212E4EB194109C71815ACE1ED8D56139DDA04BE2F6E1BB01EAC9315C6FB5ABF", "hash_sha384": "FB133FF62EAFA075219B0E4262644EE5B3D7EFB8E051356FB3EDD24227885FA2175EC60944B320E91D6C86118E4A2476", "hash_sha512": "5A19CC9C2EF879B69F9C71FCBC0AFFDF9AA1D8F193D8BACBC3CCF6788B83704F19CA2784F73E5D539552902C44EB7AD58CBD42519B03CBE344BF2BBC479A7AF5", "hash_ssdeep": "384:ZpHel/BQrlTB7hfbKoq0dhRUb+AZu8Lx9XyFkBRonD1VQjWf5GNYoCPUh0D3fWXv:Wl/GhN9OuJuHaCqgYAh0zdvQ", "hash_imp": "AD72E3C04C1BC40AB74532464B40A96E", "hash_pesha1": "CCA78180816B48FACD56DB7695C240F3C85736E9", "hash_pe256": "DCD06C4C41F3FB9138489761B47105F15CCF49A292AB14115032E1B20BD4FEBB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Find String (QGREP) Utility", "meta_original_filename": "FINDSTR.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/6212e4eb194109c71815ace1ed8d56139dda04be2f6e1bb01eac9315c6fb5abf/detection/", "output": "Searches for strings in files.\r\n\r\nFINDSTR [/B] [/E] [/L] [/R] [/S] [/I] [/X] [/V] [/N] [/M] [/O] [/P] [/F:file]\r\n [/C:string] [/G:file] [/D:dir list] [/A:color attributes] [/OFF[LINE]]\r\n strings [[drive:][path]filename[ ...]]\r\n\r\n /B Matches pattern if at the beginning of a line.\r\n /E Matches pattern if at the end of a line.\r\n /L Uses search strings literally.\r\n /R Uses search strings as regular expressions.\r\n /S Searches for matching files in the current directory and all\r\n subdirectories.\r\n /I Specifies that the search is not to be case-sensitive.\r\n /X Prints lines that match exactly.\r\n /V Prints only lines that do not contain a match.\r\n /N Prints the line number before each line that matches.\r\n /M Prints only the filename if a file contains a match.\r\n /O Prints character offset before each matching line.\r\n /P Skip files with non-printable characters.\r\n /OFF[LINE] Do not skip files with offline attribute set.\r\n /A:attr Specifies color attribute with two hex digits. See \"color /?\"\r\n /F:file Reads file list from the specified file(/ stands for console).\r\n /C:string Uses specified string as a literal search string.\r\n /G:file Gets search strings from the specified file(/ stands for console).\r\n /D:dir Search a semicolon delimited list of directories\r\n strings Text to be searched for.\r\n [drive:][path]filename\r\n Specifies a file or files to search.\r\n\r\nUse spaces to separate multiple search strings unless the argument is prefixed\r\nwith /C. For example, 'FINDSTR \"hello there\" x.y' searches for \"hello\" or\r\n\"there\" in file x.y. 'FINDSTR /C:\"hello there\" x.y' searches for\r\n\"hello there\" in file x.y.\r\n\r\nRegular expression quick reference:\r\n . Wildcard: any character\r\n * Repeat: zero or more occurrences of previous character or class\r\n ^ Line position: beginning of line\r\n $ Line position: end of line\r\n [class] Character class: any one character in set\r\n [^class] Inverse class: any one character not in set\r\n [x-y] Range: any characters within the specified range\r\n \\x Escape: literal use of metacharacter x\r\n \\<xyz Word position: beginning of word\r\n xyz\\> Word position: end of word\r\n\r\nFor full information on FINDSTR regular expressions refer to the online Command\r\nReference.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\findstr.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\findstr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "FINDSTR: /- ignored\r\nFINDSTR: /h ignored\r\nFINDSTR: Bad command line\r\n" }, "finger.exe-12F4A450805172B74227AB0D3F7AF151": { "file_name": "finger.exe", "file_path": "C:\\Windows\\SysWOW64\\finger.exe", "hash_md5": "12F4A450805172B74227AB0D3F7AF151", "hash_sha1": "2EC3DDA4BB72FC136774F84A1FE15B1CCE047C9F", "hash_sha256": "621F2CC798234A31B17B90CFC91B6E6F9A3A249E37EA9C235AB83E39FA4C7E63", "hash_sha384": "83DE091890CE4A0A327616CC1B52E3BE755F13F79B18C54DEDBC691AFBB816B12204370AB3D0E1371798DA92D86688A7", "hash_sha512": "384B922062077EED7983E751180C61F34716CF94777AF9C4C6EE7B4B3559DDCAADE662060D0B8C9A34F85201B1099410F3C1E8405CBAE9CD87ED022A6D07DECB", "hash_ssdeep": "192:W9W/jd6t+vAJLcH9CXDYqTgDmXfmXp6MvERjJ6wWAW60WjTFf:9bLvAJY9C0qTDX+XROjJ15W60Wj", "hash_imp": "DD36F61A81704582E5C476E946B3969A", "hash_pesha1": "F35A8B7999B3C0354CDDDF79B5A9E10C21133ADF", "hash_pe256": "64686262DCA3231F4D8D55DB4065E57BEE0946B9DC27B790ACF7D072979F6BB1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCPIP Finger Command", "meta_original_filename": "finger.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/621f2cc798234a31b17b90cfc91b6e6f9a3a249e37ea9c235ab83e39fa4c7e63/detection/", "error": "\r\nDisplays information about a user on a specified system running the\r\nFinger service. Output varies based on the remote system.\r\n\r\nFINGER [-l] [user]@host [...]\r\n\r\n -l Displays information in long list format.\r\n user Specifies the user you want information about. Omit the user\r\n parameter to display information about all users on the\r\n specifed host.\r\n @host Specifies the server on the remote system whose users you\r\n want information about.\r\n\r\n", "output": "\r\n[Default-PC]\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\finger.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\finger.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "fixmapi.exe-3174ECF9B3C9AC16DDF77BAB13DA6D27": { "file_name": "fixmapi.exe", "file_path": "C:\\Windows\\SysWOW64\\fixmapi.exe", "hash_md5": "3174ECF9B3C9AC16DDF77BAB13DA6D27", "hash_sha1": "EBE54FF381866277C95AB77CEFEF3FA5F0D97B53", "hash_sha256": "9ABF9DC2CD723D9C8BC68D16BC8C175C4F5445E18C0B7B5628329C750C4DFC73", "hash_sha384": "DBA071B0C47A93F63F80D715AB8149F253794F9574D3F549142D28AFE44847EA08FC35B43EA3C8041C4E499DD5D9CC89", "hash_sha512": "8452C238650D2FA735836BEAB39B3C7313424937FBB331BA674A5716477F2977BA709BB949662042F8E0751E74F0F72219A1B4318B67B5D3AEC48F2C9D97022C", "hash_ssdeep": "192:SCZn71JlGz626X29pcsIZQUnEB1roeSMNRrgtm9p5kYWWnWD9d2:R1Z2xke+EX04RrsRYWWnWD", "hash_imp": "AA30E33727F4F0E9977929AB0E68947A", "hash_pesha1": "9A396020D7A1BDF5C3FA380F2D0053A8E7C79B91", "hash_pe256": "E12C2DBFA20C56B205AF1D6CE7B30850366B1C2587DCE505614DF7F16BD99F7D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "FIXMAPI 1.0 MAPI Repair Tool", "meta_original_filename": "FIXMAPI.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/9abf9dc2cd723d9c8bc68d16bc8c175c4f5445e18c0b7b5628329c750c4dfc73/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\fixmapi.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "FlashPlayerApp.exe-418C7E05EA340C6CEE3129B037560451": { "file_name": "FlashPlayerApp.exe", "file_path": "C:\\Windows\\SysWOW64\\FlashPlayerApp.exe", "hash_md5": "418C7E05EA340C6CEE3129B037560451", "hash_sha1": "66045B36AC2D8313E23DE5F4532EA8FCB185CD4C", "hash_sha256": "DB06A4565A02858E132921CDC35E74D4656E822BD4AB6C70995FFDF4592B892B", "hash_sha384": "4EE60498F2B00185AB0E46BF354B719138C8105691749B9DD8A31637149FE033FF9EFD7CAA61012820FB3A66FB884304", "hash_sha512": "365D0E7E206BE4FFA9D7F59E55EEAD895AD41FCBDB4682CD51D15E2C076470124A86FD74C02B38D7D82A0581CFFDF9801FBB4539B02DF485706A75782C574D4F", "hash_ssdeep": "12288:oB0z4tN/qGDb+DLUFoYkp6d1BtOkodxduog/TXJa/x82IErOJsnV/Qt6Mq:2CA+OoJuog/TXJmxOMIc", "hash_imp": "D248E7506BBB57C42AB299A2D816544C", "hash_pesha1": "3E95DB811781FF432F239D8D5C155D15C0D6F2C0", "hash_pe256": "BAEE77630450BB10C0015FA04532A71D9D182EA1B685D15A8AF40338C7035C69", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Adobe Flash Player Control Panel Applet", "meta_original_filename": "FlashPlayerCPLApp.cpl", "meta_product_name": "Adobe Flash Player Control Panel Applet", "meta_company_name": "Adobe", "meta_file_version": "32,0,0,445", "meta_product_version": "32,0,0,445", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 1996-2020 Adobe. All Rights Reserved. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.", "meta_legal_trademarks": "Adobe Flash Player", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/db06a4565a02858e132921cdc35e74d4656e822bd4ab6c70995ffdf4592b892b/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\RPC Control\\DSEC10D0": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\FlashPlayerApp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Flash Player Settings Manager" }, "fltMC.exe-8A973456D8B1CDE50EC102A01A61E788": { "file_name": "fltMC.exe", "file_path": "C:\\Windows\\SysWOW64\\fltMC.exe", "hash_md5": "8A973456D8B1CDE50EC102A01A61E788", "hash_sha1": "66CEE9CF45573F90601822E8325789D404698736", "hash_sha256": "7C0B13D17FAB5EA169B9C637C604B71503F86728C03D27C1AB81A18F8CAAE391", "hash_sha384": "45540126942C2D10818C604E36E5E5A332F60111366038C8062D75E89F6C407A3063668211DAA60D5F093B2F0B0A5208", "hash_sha512": "0676E49002210A879FA9FD8090BD48C7C6818668A5DB23B90356314333AB63AF332CBBF9CBDE3F8144EDDD5C1752AA7AFF2F939B07A157C2BE3420A597A47A37", "hash_ssdeep": "384:WM+7nj57cY3SIBbSySM/aRgoW1xup8czUUE6XfIR2lWT9Wp:KnN3SIBbSySM/aRgdMNgmIR2G", "hash_imp": "8C8C09D4509B63B5CE0F14A2DD512C04", "hash_pesha1": "CF9F4D1D68B516E00AF7C24C91F41F8629693E4F", "hash_pe256": "132FBFE8637A117B314AFAD086EF2358DB2CFE1C45E98FB1871173173C3F7EE7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Filter Manager Control Program", "meta_original_filename": "fltMC.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/7c0b13d17fab5ea169b9c637c604b71503f86728c03d27c1ab81a18f8caae391/detection/", "output": "\r\n** Invalid command\r\nValid commands:\r\n load Loads a Filter driver\r\n unload Unloads a Filter driver\r\n filters Lists the Filters currently registered in the system\r\n instances Lists the Instances for a Filter or Volume currently\r\n registered in the system\r\n volumes Lists all volumes/RDRs in the system\r\n attach Creates a Filter Instance to a Volume\r\n detach Removes a Filter Instance from a Volume\r\n\r\n Use fltmc help [ command ] for help on a specific command\r\n" }, "Fondue.exe-0E9BE52DB9A66E19CF012D33E10E5EA7": { "file_name": "Fondue.exe", "file_path": "C:\\Windows\\SysWOW64\\Fondue.exe", "hash_md5": "0E9BE52DB9A66E19CF012D33E10E5EA7", "hash_sha1": "51296EF62A0AA10ED107D89D03F1D268B4451CCF", "hash_sha256": "CE88D88E233A9AB9B47BEA00AF705ECF49869BE78E671BD09AA4F7D5A34C9953", "hash_sha384": "CDEFA2895FA1380C3CF8FD37D450397AFDCEB8C5BCB648E845A0DB94C28EBF22EA435B1002A959D22BAED48474C9BE7E", "hash_sha512": "C4E3C7319C3536BB04312068D5C9BA89ACD0A7EC0D6C6E7EEA0F5881317FAF4FF83EF95E12C2835DEC4401353916275C600D0A6CC6F3A69C6F51808CDDFFA4A7", "hash_ssdeep": "3072:DM5ObEaznWfH22ZsuX2xKwMPTnaSrIrvD2:MoznWjZnXeKwMLnaqY", "hash_imp": "C90A9B51B5004E7BF81F560D871186E8", "hash_pesha1": "D05AC06EA055F0C25E017EE3170F7EE3FAB8E76D", "hash_pe256": "E094A15283B13A324333CDDADC065422790A61F80C2B135AB0B0DC2111B471CA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Features on Demand UX", "meta_original_filename": "Fondue.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/ce88d88e233a9ab9b47bea00af705ecf49869be78e671bd09aa4f7d5a34c9953/detection/", "children": "Fondue.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\Fondue.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\propsys.dll.mui": "File", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\RPC Control\\DSECDA4": "Section", "\\Sessions\\2\\BaseNamedObjects\\UrlZonesSM_Administrator": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\Fondue.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "fontdrvhost.exe-955BEE2BDC0B62A255CA7FC99EC8E2F4": { "file_name": "fontdrvhost.exe", "file_path": "C:\\Windows\\SysWOW64\\fontdrvhost.exe", "hash_md5": "955BEE2BDC0B62A255CA7FC99EC8E2F4", "hash_sha1": "1349677AAC18E760FEC8F24542CD6156189F321E", "hash_sha256": "F1A5E53B6CBEA2011F5B7F46F5D65708DC43EF78EEC8EC3EF69F6736B1D12020", "hash_sha384": "513CA052459ACA9B6D772490842AB52705E060B839BA54C69642EF92448820E5E9C32C672E78C4A602307B6FC3D33BE7", "hash_sha512": "D6710DD40057026B61E6AE63AA519C46BA4BC7DB053527605BEFAB6B5FD38B2EF68C54C09A850EF97AD1E44A179BE6895E33C009953DF0278C451A35EF1EBBC0", "hash_ssdeep": "12288:wANyWRo/Lrcq2dELKhj29U/ihacIjWMcjMPKk5rXYXKwZaMOlNU:wANyWa/M9ELKF4LhacIjWMkUKk5rXmK6", "hash_imp": "1E28BE7B53EA775BC96A429CBD714D3C", "hash_pesha1": "29BAE4C63E33653F248CCE5F3095223952C34AFE", "hash_pe256": "F9701A280E05D4196A523C0E7246CB0E3E30C26B5F9A45D8E65C08D68F0632C8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Usermode Font Driver Host", "meta_original_filename": "fontdrvhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Windows\\SysWOW64\\fontdrvhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "fontview.exe-A8E73AF0EEBD57BDC848C2A58B8CF8BD": { "file_name": "fontview.exe", "file_path": "C:\\Windows\\SysWOW64\\fontview.exe", "hash_md5": "A8E73AF0EEBD57BDC848C2A58B8CF8BD", "hash_sha1": "D49CFBE533C630AD635EAA5F1FFF9350A4ED5400", "hash_sha256": "1641406FEA81F03972E0F9FBE72F335032628FF6B17A9CD28A56DC5BC2983C40", "hash_sha384": "B2FD38DA386846095BFF9DD66D34891A2130E016F4EF793CA2C000A383C7D8E1CB53D27C618FBD2CA5D538E4E2491F9B", "hash_sha512": "FD8E75B9F93D1B948C1CF383F0A903354445B8BFD6FC2B97CB01969EF9F0ACD87AEC3008C3742CC23590110E6849FBF235EFF7E6B2A9D3BBB3CF4C1E50FC3924", "hash_ssdeep": "3072:koZOnEBeNJjWRkOtHxtt3EOL2QvIsitSYV5p:DZOnEBiWRRZzqGYL", "hash_imp": "45C6DEC368899AF38B3C2F1BD3E62E67", "hash_pesha1": "E0791B26C06E6E449D414E287B52333F7EDD9C6C", "hash_pe256": "B7148B4A6CBC49E1A8A0FB2DD25BE42C372873ADDA24ED3CB595BCA74589083E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Font Viewer", "meta_original_filename": "FONTVIEW.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/1641406fea81f03972e0f9fbe72f335032628ff6b17a9cd28a56dc5bc2983c40/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\fontview.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\fontview.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Font Viewer " }, "forfiles.exe-F284BB15A424D1B4A7E0EB8BEAB478E5": { "file_name": "forfiles.exe", "file_path": "C:\\Windows\\SysWOW64\\forfiles.exe", "hash_md5": "F284BB15A424D1B4A7E0EB8BEAB478E5", "hash_sha1": "E05AD2C5D92A2C6F091689BFB696079454CA1D59", "hash_sha256": "FF892CC591BED1B9BA539AEABD86E9D19387D4378F050676553F21E340DF68EF", "hash_sha384": "567A9C2FA8BB9EC74828ABB8B6F01733E210CBFD4EC5BF85DAE6F54DD6590578CC4FF6F5C20B751F08F2D464809792C2", "hash_sha512": "5123E8CF60DF1774615EBFDC8B9E9A5B67216BAAAAACC60BFABE770AA59DB34F012BCCC9760B9C1C3E536A3708F551770AC36023E6242AAC6B4837089B9CCD58", "hash_ssdeep": "768:E96R5XpJwwpx7bEXRvCkkkSQU8Diw3szKiaz90JZxtbc9RwzSLn:E967wyYvcka8Dies7BxtMRwzU", "hash_imp": "64E68F7B6E212C1F2B12FFE1C1CFE372", "hash_pesha1": "D0DD27DA0DCFD40020CAB67BA0780082F7A7ACD9", "hash_pe256": "73249999B49456B3A0EC50AA3E5662606555EE1AFA2EDC6B1561CF4ECAD859CF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ForFiles - Executes a command on selected files", "meta_original_filename": "forfiles.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/ff892cc591bed1b9ba539aeabd86e9d19387d4378f050676553f21e340df68ef/detection/", "output": "\r\nFORFILES [/P pathname] [/M searchmask] [/S]\r\n [/C command] [/D [+ | -] {MM/dd/yyyy | dd}]\r\n\r\nDescription:\r\n Selects a file (or set of files) and executes a \r\n command on that file. This is helpful for batch jobs.\r\n\r\nParameter List:\r\n /P pathname Indicates the path to start searching.\r\n The default folder is the current working\r\n directory (.).\r\n\r\n /M searchmask Searches files according to a searchmask.\r\n The default searchmask is '*' .\r\n\r\n /S Instructs forfiles to recurse into\r\n subdirectories. Like \"DIR /S\".\r\n\r\n /C command Indicates the command to execute for each file.\r\n Command strings should be wrapped in double\r\n quotes. \r\n\r\n The default command is \"cmd /c echo @file\".\r\n\r\n The following variables can be used in the\r\n command string:\r\n @file - returns the name of the file.\r\n @fname - returns the file name without\r\n extension.\r\n @ext - returns only the extension of the\r\n file.\r\n @path - returns the full path of the file.\r\n @relpath - returns the relative path of the\r\n file.\r\n @isdir - returns \"TRUE\" if a file type is\r\n a directory, and \"FALSE\" for files.\r\n @fsize - returns the size of the file in\r\n bytes.\r\n @fdate - returns the last modified date of the\r\n file.\r\n @ftime - returns the last modified time of the\r\n file.\r\n\r\n To include special characters in the command \r\n line, use the hexadecimal code for the character\r\n in 0xHH format (ex. 0x09 for tab). Internal\r\n CMD.exe commands should be preceded with\r\n \"cmd /c\".\r\n\r\n /D date Selects files with a last modified date greater\r\n than or equal to (+), or less than or equal to\r\n (-), the specified date using the\r\n \"MM/dd/yyyy\" format; or selects files with a\r\n last modified date greater than or equal to (+)\r\n the current date plus \"dd\" days, or less than or\r\n equal to (-) the current date minus \"dd\" days. A\r\n valid \"dd\" number of days can be any number in\r\n the range of 0 - 32768.\r\n \"+\" is taken as default sign if not specified.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n FORFILES /?\r\n FORFILES \r\n FORFILES /P C:\\WINDOWS /S /M DNS*.* \r\n FORFILES /S /M *.txt /C \"cmd /c type @file | more\"\r\n FORFILES /P C:\\ /S /M *.bat\r\n FORFILES /D -30 /M *.exe\r\n /C \"cmd /c echo @path 0x09 was changed 30 days ago\"\r\n FORFILES /D 01/01/2001\r\n /C \"cmd /c echo @fname is new since Jan 1st 2001\"\r\n FORFILES /D +10/19/2020 /C \"cmd /c echo @fname is new today\"\r\n FORFILES /M *.exe /D +1\r\n FORFILES /S /M *.doc /C \"cmd /c echo @fsize\" \r\n FORFILES /M *.txt /C \"cmd /c if @isdir==FALSE notepad.exe @file\"\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"FORFILES /?\" for usage.\r\n" }, "fsquirt.exe-A2B54CB7967B7269488C40152FBFBB9F": { "file_name": "fsquirt.exe", "file_path": "C:\\Windows\\SysWOW64\\fsquirt.exe", "hash_md5": "A2B54CB7967B7269488C40152FBFBB9F", "hash_sha1": "900C763BC847FDDE8960A3BF9AE86282C6BFC521", "hash_sha256": "E1491B1F6921849FCDE3BC4B5CBB5D07890A997ED18F0051ABBA3407B8C0F39B", "hash_sha384": "6D9B805BCE7F5FA1A82D1902B2D3177405FD2B85A8320DE1B7D4D5398236F6EE41C7A8C112C21F3241816C6017FA97DB", "hash_sha512": "C5B2747235909432901CC23F3FF5E59CCFDE090B97D0CB4343A5A2FAF6F117280A9BBE99840CEC11C28C3D8D9560F9815ADA2C337EFE528EA4AC69B02C4364A4", "hash_ssdeep": "1536:orT+6Ola5kAB2hd9MQtZt9h1PeuSW/mWDyj3hoSQJnhI/axZ1:oN2lMMf/1yW/mWDY3hX0h91", "hash_imp": "59D0559E6C4FFF7E0083BB2B9A048BF8", "hash_pesha1": "0CA84B7B8EAA5C7D24513FD8E9CB4B2BA1756B69", "hash_pe256": "80296BCCDD3BD0BEEE8A61ADFE4D970DBB01474FC285B973951562B1F6F20CAE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "fsquirt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/e1491b1f6921849fcde3bc4b5cbb5d07890a997ed18f0051abba3407b8c0f39b/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\fsquirt.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\fsquirt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Bluetooth File Transfer" }, "fsutil.exe-1E7299471C2963F47624FD365B9B5E60": { "file_name": "fsutil.exe", "file_path": "C:\\Windows\\SysWOW64\\fsutil.exe", "hash_md5": "1E7299471C2963F47624FD365B9B5E60", "hash_sha1": "B5AB72EDD818FF7B82EB5239CAC9BC0AD45BA9BB", "hash_sha256": "3B13A67DD25962BB50AB60ACA722B0AEC4810C9C23F2F8D6E3648AD6D694B194", "hash_sha384": "7D947E0A25C14338E2BDA8B732483CB36C22F21ADC3664CA866141814549FFDA3B57481496B6B04A66ED349855EAB409", "hash_sha512": "3E4B4F5D9F8AF054556AAA03C651360434D7DAA81E46CBE8053E6575807F540A76C1EABAA26C9D878466A9B4889EFBDFF2FBF9267AFACFCB70974C7360781D93", "hash_ssdeep": "3072:cysAQ3C2HZ2byEfGCUuyHzy6lMg87j6jUr+87CXbRMuhrG:feZeyEeCUu11fpx7QRMuB", "hash_imp": "3AFDA70FA7E12943E4F800C706B88A82", "hash_pesha1": "457097C0BA7F287EEC687EDE16A4542EC1B1ED72", "hash_pe256": "FD0933087EE2983678595EEB0E65CF2AD35C54BC7D9B8AA5836C2BE4875CA508", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "fsutil.exe", "meta_original_filename": "fsutil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.652 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.652", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/3b13a67dd25962bb50ab60aca722b0aec4810c9c23f2f8d6e3648ad6d694b194/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\fsutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "output": "--help is an invalid parameter.\r\n---- Commands Supported ----\r\n\r\n8dot3name 8dot3name management\r\nbehavior Control file system behavior\r\ndax Dax volume management\r\ndirty Manage volume dirty bit\r\nfile File specific commands\r\nfsInfo File system information\r\nhardlink Hardlink management\r\nobjectID Object ID management\r\nquota Quota management\r\nrepair Self healing management\r\nreparsePoint Reparse point management\r\nresource Transactional Resource Manager management\r\nsparse Sparse file control\r\ntiering Storage tiering property management\r\ntransaction Transaction management\r\nusn USN management\r\nvolume Volume management\r\nwim Transparent wim hosting management\r\n" }, "ftp.exe-F0707986208091066AFD2AB0A73D1693": { "file_name": "ftp.exe", "file_path": "C:\\Windows\\SysWOW64\\ftp.exe", "hash_md5": "F0707986208091066AFD2AB0A73D1693", "hash_sha1": "3F79C30934FB96FAABE9DF828592F41280D394F2", "hash_sha256": "BE279F10D7FF4C18D69724EF0EB04C91D8A34AAC0DB610E638B000991DFB8B02", "hash_sha384": "580CCCCD3F91EDE1DFB91471C83C28018017E0680812CF19443C027DE2AD501DF24E726171909F4B23BDD24C9849020B", "hash_sha512": "5D442EEB2E69B8CE6EFD8EB4302E4DC3E7B6EC0326C9F35965E299B130AAF8927769CB6BEB9B0B8D670D84B06824B0311EEFD8B0EACA9C56F1804E9592B874AF", "hash_ssdeep": "768:q9TSteOAJzRjbEm1kvWZhCwZeNyQbsVoSVzBHIeoG5BIFYB2BC4pOU5:qViejSWZYwZeNyqb0B7DIFxBC415", "hash_imp": "F76AC455BB3971C0CB2A43FDCD1FF525", "hash_pesha1": "AF0B7487E479E952A6D7519DC6886E944E0F691F", "hash_pe256": "9E05810F224ECEBA50D8E128C7F2F54318342E3C79AC73CFFFA0B122AB90BBCB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Transfer Program", "meta_original_filename": "ftp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/be279f10d7ff4c18d69724ef0eb04c91d8a34aac0db610e638b000991dfb8b02/detection/", "error": "\r\nTransfers files to and from a computer running an FTP server service\r\n(sometimes called a daemon). Ftp can be used interactively.\r\n\r\nFTP [-v] [-d] [-i] [-n] [-g] [-s:filename] [-a] [-A] [-x:sendbuffer] [-r:recvbuffer] [-b:asyncbuffers] [-w:windowsize] [host]\r\n\r\n -v Suppresses display of remote server responses.\r\n -n Suppresses auto-login upon initial connection.\r\n -i Turns off interactive prompting during multiple file\r\n transfers.\r\n -d Enables debugging.\r\n -g Disables filename globbing (see GLOB command).\r\n -s:filename Specifies a text file containing FTP commands; the\r\n commands will automatically run after FTP starts.\r\n -a Use any local interface when binding data connection.\r\n -A login as anonymous.\r\n -x:send sockbuf Overrides the default SO_SNDBUF size of 8192.\r\n -r:recv sockbuf Overrides the default SO_RCVBUF size of 8192.\r\n -b:async count Overrides the default async count of 3\r\n -w:windowsize Overrides the default transfer buffer size of 65535.\r\n host Specifies the host name or IP address of the remote\r\n host to connect to.\r\n\r\nNotes:\r\n - mget and mput commands take y/n/q for yes/no/quit.\r\n - Use Control-C to abort commands.\r\n", "children": [ "csrss.exe", "wininit.exe", "conhost.exe" ], "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\ftp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "getmac.exe-74628029B1DFDD8A9885EB175F8E6A6F": { "file_name": "getmac.exe", "file_path": "C:\\Windows\\SysWOW64\\getmac.exe", "hash_md5": "74628029B1DFDD8A9885EB175F8E6A6F", "hash_sha1": "56AC7E4482093F1136F8D7BC49F727672CD403AB", "hash_sha256": "35E08AE5AE1D826C5FC8E41CFA5CFD30A0463975059BD4E8FF710A94F7D9F31A", "hash_sha384": "5BA0178C66DBEC7802E5DB3CD073C2201A1FAD11077D7722ECF607E49836C78966F636CEF99E10B4803761FB207F1057", "hash_sha512": "FB15BDE58A85EB7F445AEDD51EA9D85321B5D0CB3AEBFD89BFF33A799D1740B24A0D2266DFC1B9C6585B4C27B844C392AF82ED5ABCAB2A75AD342F0D49E845C4", "hash_ssdeep": "1536:y4azWKEoXLhu42lDc/ApSi894HlHAJTtUaPduz:DKrXVj2lDcCSi89NtUaF", "hash_imp": "5AD2D88C0BF8CBFEFAEC540D70672C23", "hash_pesha1": "DD5562A48B2B74BB01D1BDBBEA757CA401911411", "hash_pe256": "AEA7E9C4895B6061DD41B81652E13466CF3CBD4E9E1BEE3F7F902EBE519B1D71", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays NIC MAC information", "meta_original_filename": "GetMac.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/35e08ae5ae1d826c5fc8e41cfa5cfd30a0463975059bd4e8ff710a94f7d9f31a/detection/", "output": "\r\nGETMAC [/S system [/U username [/P [password]]]] [/FO format] [/NH] [/V]\r\n\r\nDescription:\r\n This tool enables an administrator to display the MAC address\r\n for network adapters on a system.\r\n\r\nParameter List: \r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under \r\n which the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /FO format Specifies the format in which the output\r\n is to be displayed.\r\n Valid values: \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" should\r\n not be displayed in the output.\r\n Valid only for TABLE and CSV formats.\r\n\r\n /V Specifies that verbose output is displayed.\r\n\r\n /? Displays this help message.\r\n\r\nExamples: \r\n GETMAC /? \r\n GETMAC /FO csv \r\n GETMAC /S system /NH /V\r\n GETMAC /S system /U user\r\n GETMAC /S system /U domain\\user /P password /FO list /V\r\n GETMAC /S system /U domain\\user /P password /FO table /NH\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"GETMAC /?\" for usage.\r\n" }, "gpresult.exe-4CE46E3DEDF809788CA8438AD491559F": { "file_name": "gpresult.exe", "file_path": "C:\\Windows\\SysWOW64\\gpresult.exe", "hash_md5": "4CE46E3DEDF809788CA8438AD491559F", "hash_sha1": "E2DEA8C3294544614BDFACD7B77B100B0F4497C8", "hash_sha256": "3286F3271943104E023E36323F0ABBB114C2C59E3A95D64951B1AAFE964272A0", "hash_sha384": "434787D367F2E94475DCEA8C7637F04D225B03505F07A0759380FA0320EC6DB9E600E6E3F9CD58E916F73E220D85D59E", "hash_sha512": "835227D54F1BC7222C9575DAB48061A85E8547BD4F4D4986240F08B3EE65B3D6CF577BB537460908545D0E9D8E5E3767AD6B99A1BDDA08DCD823AD1694818FA8", "hash_ssdeep": "3072:uQ+sOKvkZ05VarRlyE19HmHmPbVrA/ZbaZ48FfIiPe0mc3CPbuw7MWktI:hBbValME19HmHmPbmRbb8JIirmcyPb9K", "hash_imp": "01C94545980BD083D50BD5F70C211D99", "hash_pesha1": "2CCAC1027CED739CAACA9F5FC1FC82734ACED8AE", "hash_pe256": "F95F2903F49B5AE1E31220ED7995241F8D14E7B3FCA479719434C3C3739A8632", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query Group Policy RSOP Data", "meta_original_filename": "gprslt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/3286f3271943104e023e36323f0abbb114c2c59e3a95d64951b1aafe964272a0/detection/", "output": "\r\nGPRESULT [/S system [/U username [/P [password]]]] [/SCOPE scope]\r\n [/USER targetusername] [/R | /V | /Z] [(/X | /H) <filename> [/F]]\r\n\r\nDescription:\r\n This command line tool displays the Resultant Set of Policy (RSoP)\r\n information for a target user and computer.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which the\r\n command should run.\r\n Can not be used with /X, /H.\r\n\r\n /P [password] Specifies the password for the given user\r\n context. Prompts for input if omitted.\r\n Cannot be used with /X, /H.\r\n\r\n /SCOPE scope Specifies whether the user or the\r\n computer settings need to be displayed.\r\n Valid values: \"USER\", \"COMPUTER\".\r\n\r\n /USER [domain\\]user Specifies the user name for which the\r\n RSoP data is to be displayed.\r\n\r\n /X <filename> Saves the report in XML format at the\r\n location and with the file name specified\r\n by the <filename> parameter. (valid in Windows\r\n Vista SP1 and later and Windows Server 2008 and later)\r\n\r\n /H <filename> Saves the report in HTML format at the\r\n location and with the file name specified by\r\n the <filename> parameter. (valid in Windows\r\n at least Vista SP1 and at least Windows Server 2008)\r\n\r\n /F Forces Gpresult to overwrite the file name\r\n specified in the /X or /H command.\r\n\r\n /R Displays RSoP summary data.\r\n\r\n /V Specifies that verbose information should\r\n be displayed. Verbose information provides\r\n additional detailed settings that have\r\n been applied with a precedence of 1.\r\n\r\n /Z Specifies that the super-verbose\r\n information should be displayed. Super-\r\n verbose information provides additional\r\n detailed settings that have been applied\r\n with a precedence of 1 and higher. This\r\n allows you to see if a setting was set in\r\n multiple places. See the Group Policy\r\n online help topic for more information.\r\n\r\n /? Displays this help message.\r\n\r\n\r\nExamples:\r\n GPRESULT /R\r\n GPRESULT /H GPReport.html\r\n GPRESULT /USER targetusername /V\r\n GPRESULT /S system /USER targetusername /SCOPE COMPUTER /Z\r\n GPRESULT /S system /U username /P password /SCOPE USER /V\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\gpresult.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "ERROR: Invalid syntax. Value expected for '/h'.\r\nType \"GPRESULT /?\" for usage.\r\n" }, "gpscript.exe-CD4E4D21E316810DAC1274761D79D84B": { "file_name": "gpscript.exe", "file_path": "C:\\Windows\\SysWOW64\\gpscript.exe", "hash_md5": "CD4E4D21E316810DAC1274761D79D84B", "hash_sha1": "D8785C2442A34EBFAED7A8F95E064374261A5B57", "hash_sha256": "BA34765365FE1D6CE2864CABBC3A8864782C38722F7B24B7A0325E6A144868EE", "hash_sha384": "F596492BDB6D7E08BA4C94E146362866C805EC22CE00C838F60C7FCE70425E3FB55BEF1B05C5B9513D5A0028BD2F71D9", "hash_sha512": "51BF13A0B899B2303E04ADFF8BB9394FD4669D4984338715903176B812FBE4F7A0F5C99104A42D757E97730AB3A95E80F57C3F519823DCFDA7DFAE279846B4CA", "hash_ssdeep": "768:FMQX1flU+Bk3sc5At0j45vz/SrO7LJfiMzoKtudTy7Mapo0x:z++Bk3sc5W0j4Vz/SrU45QudTMMapv", "hash_imp": "53F08A1EE2C1A1E73577729E316B9F9F", "hash_pesha1": "55BFEDC45A1B5B18B8170AD6E64F6140D7A7402E", "hash_pe256": "02212692010035817FF13AD6355FB4F72B163136054F8352C0818CF60FF65923", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Group Policy Script Application", "meta_original_filename": "GPSCRIPT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Windows\\SysWOW64\\gpscript.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "gpupdate.exe-24402960F8F624BA9189AE62748C0D3D": { "file_name": "gpupdate.exe", "file_path": "C:\\Windows\\SysWOW64\\gpupdate.exe", "hash_md5": "24402960F8F624BA9189AE62748C0D3D", "hash_sha1": "1FACC9140278F0BDC83221C1FDBF44FA32361DA1", "hash_sha256": "4B95BABE99ABBEFBCBD78E61D977C006354022923419DB557579E87FE516B207", "hash_sha384": "99482D5B432FE80B7F506DCD0DAD3D1E9BF5179B09D67C22AB1368D5599F3C7791C0035542A5247B5EDD1622CDF8DA39", "hash_sha512": "2F5E535FDB5295B070570DBEA90B4C182463F392AC3AC31D3414B96A5322109B13A1A861F1E41C9097B9B9B7E0F0E4FA4B8EAE59539F14708B297B71E6FF54A6", "hash_ssdeep": "384:glRT3fMCsKmxTDoAuioVXBUPHk44ccFEqBRPMMKRumRu/dU4Nxo/yWFIDWB6:4JPRlUhkPEQNU4I/ya6", "hash_imp": "515F47AF8578CCA4344D9CC5437CE44F", "hash_pesha1": "0EB69FFC8E18F1B0CF4FA1AEECB7DB1BFC2AEE62", "hash_pe256": "302C4FB2F4272F4299D71DC325056AD4A107391ABAB078A0DA854F092CE79639", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Group Policy Update Utility", "meta_original_filename": "GPUpdate.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Description: Updates multiple Group Policy settings.\r\r\n\r\r\nSyntax: Gpupdate [/Target:{Computer | User}] [/Force] [/Wait:<value>]\r\r\n [/Logoff] [/Boot] [/Sync] \r\r\n\r\r\nParameters:\r\r\n\r\r\nValue Description\r\r\n/Target:{Computer | User} Specifies that only User or only Computer\r\r\n policy settings are updated. By default,\r\r\n both User and Computer policy settings are\r\r\n updated.\r\r\n\r\r\n/Force Reapplies all policy settings. By default,\r\r\n only policy settings that have changed are\r\r\n applied.\r\r\n\r\r\n/Wait:{value} Sets the number of seconds to wait for policy\r\r\n processing to finish. The default is 600\r\r\n seconds. The value '0' means not to wait.\r\r\n The value '-1' means to wait indefinitely.\r\r\n When the time limit is exceeded, the command\r\r\n prompt returns, but policy processing\r\r\n continues.\r\r\n\r\r\n/Logoff Causes a logoff after the Group Policy settings\r\r\n have been updated. This is required for\r\r\n those Group Policy client-side extensions\r\r\n that do not process policy on a background\r\r\n update cycle but do process policy when a\r\r\n user logs on. Examples include user-targeted\r\r\n Software Installation and Folder Redirection.\r\r\n This option has no effect if there are no\r\r\n extensions called that require a logoff.\r\r\n\r\r\n/Boot Causes a computer restart after the Group Policy settings\r\r\n are applied. This is required for those\r\r\n Group Policy client-side extensions that do\r\r\n not process policy on a background update cycle\r\r\n but do process policy at computer startup.\r\r\n Examples include computer-targeted Software\r\r\n Installation. This option has no effect if\r\r\n there are no extensions called that require\r\r\n a restart.\r\r\n\r\r\n/Sync Causes the next foreground policy application to\r\r\n be done synchronously. Foreground policy\r\r\n applications occur at computer start up and user\r\r\n logon. You can specify this for the user,\r\r\n computer or both using the /Target parameter.\r\r\n The /Force and /Wait parameters will be ignored\r\r\n if specified.\r\r\n\r\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\gpupdate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "grpconv.exe-74E9D5CD051F96AB01C3B577669CF4D6": { "file_name": "grpconv.exe", "file_path": "C:\\Windows\\SysWOW64\\grpconv.exe", "hash_md5": "74E9D5CD051F96AB01C3B577669CF4D6", "hash_sha1": "81BC5E6D0890E8AD28B5F936EFE1069FF42398E2", "hash_sha256": "542C4B92D2FA26E0C26771A3624440DF3EF09CCD2EAF1A2873486CE461F9DC30", "hash_sha384": "E51A6D0B5AAE49ED6C4FEE69F985EF7F53572ECF9406A376C4C1242BC68790D56BFF0537201501B04119F6177D88DA6E", "hash_sha512": "D031F80E8B07CCECEBAF34A61D0B050873F3B60C789F207039A27B485BE689152F4BA85AAA74B69CB92AB1A84354BFA722F8A39A1A175019343DA43ACFB051B6", "hash_ssdeep": "768:8K/nMfbqDir+ox/QkI8frhR3aYz75y95:8KPMfRKK11o2y95", "hash_imp": "132C218B1F2E13F78FEE548483028E32", "hash_pesha1": "55E670B23BC066E83427DD4A5C6660F2667A53BE", "hash_pe256": "B080ECA85E574E9A8EE676AF9AA397FDAA67F71D4F4DE60C9288B1DA0B5F3DEB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Progman Group Converter", "meta_original_filename": "GRPCONV.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/542c4b92d2fa26e0c26771a3624440df3ef09ccd2eaf1a2873486ce461f9dc30/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\grpconv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "hdwwiz.exe-AAB85DCBD157E87F02D6CA30E31A5CB4": { "file_name": "hdwwiz.exe", "file_path": "C:\\Windows\\SysWOW64\\hdwwiz.exe", "hash_md5": "AAB85DCBD157E87F02D6CA30E31A5CB4", "hash_sha1": "78565EDE1FDE1545B670BD1A9ADD6848144C0E9F", "hash_sha256": "79CCCF88DD152C2AB8BE92BC8B835CDA56728D381BE3617042620B0A5CD9308B", "hash_sha384": "24A647E19588E14196127CEFA37C842EECD7A6FA44DF5C8D68EBC80691D963EB95B9F37B4C144C4ED2E183C40F846739", "hash_sha512": "50C341D3B5E382B96E6023E75BF457D8A367A5F3AEEF1BDA91F19C48EFEFDEE2A3ADE77AD8BC474CC764C32DBADAC0436218D605623DB312F007EF3D05EFE22D", "hash_ssdeep": "768:5f9l5eg2CdmmZy4G0In3BhzhWM1GOVz17Lu:V9begXZ4Z3qOTH", "hash_imp": "16C7138C6C79EEC345D753F88CF4C38D", "hash_pesha1": "76B52F2DC406628181A6745DEDDAE87D81637C14", "hash_pe256": "1710DE00C714815FD3ACA9B1E3B05A0B96B3D45354B07729655FD568C0B68E2B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Add Hardware Wizard", "meta_original_filename": "HdwWiz.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/79cccf88dd152c2ab8be92bc8b835cda56728d381be3617042620b0a5cd9308b/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\hdwwiz.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\newdev.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\devmgr.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\hdwwiz.cpl.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\setupapi.dll.mui": "File", "(R-D) C:\\Windows\\System32\\shell32.dll": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\hdwwiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Add Hardware" }, "help.exe-BF60A4B7DC84EBFD9CA3A9C022BE1E32": { "file_name": "help.exe", "file_path": "C:\\Windows\\SysWOW64\\help.exe", "hash_md5": "BF60A4B7DC84EBFD9CA3A9C022BE1E32", "hash_sha1": "D84D0ED9DC7722AA50B9CC0C3D49C6264DD36358", "hash_sha256": "09948762942FC066EB07C479FA49B63F3CFF299AF2EE8256904BA9B098EC50DF", "hash_sha384": "082DAD3C71D64E1D0A9E8D4A71DFA942A1A3CCD7093AB589E5C948277915D29A18849E507F0FA582BEAD8ADF603C1F2E", "hash_sha512": "2E2E727AA539EDE54C7CFF92C984C025D6BD9E76816D51FA013AF5C5F30DE0F4B573D77E3E7052FCA1C1279CBDDC2F67483222F0728D5AF9A3BE7036F0F39DC3", "hash_ssdeep": "192:uEAbwN3O1nvZ7O183isM2WRfCkYWncWv9:l7gvZ7O18srYWncWv9", "hash_imp": "611805A7C3221EBB521E87BF9182D982", "hash_pesha1": "701BC1CD855FC082801682A665454CD0A995D437", "hash_pe256": "3B9544072A357D1121002FD664013EBD23ED3A5C3F00184DA36928AB991C8041", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command Line Help Utility", "meta_original_filename": "Help.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/09948762942fc066eb07c479fa49b63f3cff299af2ee8256904ba9b098ec50df/detection/", "output": "Provides help information for Windows commands.\r\n\r\nHELP [command]\r\n\r\n command - displays help information on that command.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\help.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "hh.exe-A97778801ABF79482E757200E4035A01": { "file_name": "hh.exe", "file_path": "C:\\Windows\\SysWOW64\\hh.exe", "hash_md5": "A97778801ABF79482E757200E4035A01", "hash_sha1": "F9EED275D9D1D432F2ECDE6B5A9DA08C783B2B2A", "hash_sha256": "974C70FA3CAFB802CCA0A4D2D01A84FACB9CF66C8EDFC5F69D3514BB5488783D", "hash_sha384": "9ED2B71B70825D7D0B87C1E174B6804A47A4CF1CF4BEB4BA8B03C0CE7D160168DB8286116B7367A022FBCA5A4C611E8B", "hash_sha512": "D1C946214875CCE5F0BC597329BD9F68FCCB5F83064888D6EF551314E0E5B10F6DE909E6FD0917D3E55A8F559A23D23DBB1B9573A0B1DC6605C57B2A5A45B02C", "hash_ssdeep": "192:KCeaZNtjK0Cd0tNSwyRLoOVR4kBGJ1KDJD/4Wcgk:Sat+0eUSwyRUSzA1KDWWcg", "hash_imp": "F937A8A0DD0B39468FF87DDE8D9CDB45", "hash_pesha1": "3587AB82E5AA719F715159476EE1349B647C47C3", "hash_pe256": "0EF5B13FBBB91A17976BCA8579DC26FDCAF07FE2DCBDB9F02E92E1E93539E93D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft HTML Help Executable", "meta_original_filename": "HH.exe.mui", "meta_product_name": "HTML Help", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/974c70fa3cafb802cca0a4d2d01a84facb9cf66c8edfc5f69d3514bb5488783d/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_b4b635d36e735c2c": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\hh.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\hhctrl.ocx.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "(R--) C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2\\~DF11EBC92012353841.TMP": "File", "(RWD) C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2\\~DF34C84F59028B78DC.TMP": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\RPC Control\\DSEC91C": "Section", "\\Sessions\\2\\BaseNamedObjects\\91cHWNDInterface:2103ec": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_ie_global_counters": "Section", "(R-D) C:\\Windows\\SysWOW64\\ieframe.dll": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\ieframe.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\UrlZonesSM_Administrator": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_webcache_counters_{9B6AB5B3-91BC-4097-835C-EA2DEC95E9CC}_S-1-5-21-4075667164-670084373-454571106-500": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\urlmon.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\mshtml.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\91cHWNDInterface:2a04aa": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RWD) C:\\Users\\user": "File", "\\Sessions\\2\\BaseNamedObjects\\MSIMGSIZECacheMap": "Section", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(RWD) C:\\Windows\\Fonts": "File", "(RW-) C:\\Users\\user\\help": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\propsys.dll.mui": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_32.db": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\hh.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "File Download" }, "HOSTNAME.EXE-5E616C9669D38258231AF5EECDE4E221": { "file_name": "HOSTNAME.EXE", "file_path": "C:\\Windows\\SysWOW64\\HOSTNAME.EXE", "hash_md5": "5E616C9669D38258231AF5EECDE4E221", "hash_sha1": "B99FABC8BA76828FCA672B6CB1B66DD719F95D2B", "hash_sha256": "5FB2D17787FFEC622AB296775632F9B7A4BE42CC06D3DA92B4CD6BC288AD035C", "hash_sha384": "E4FD0303478DB9C48E2DBDFD36B7001C1FC9A069E1FCD56BEEDBA6974581B2AB7973442955037BBBCC9070DBCF91CB25", "hash_sha512": "64ABAF35019AF831ECC3DDC452626E6B7AEF00D07B4990C294C888336D114885E2675C339A752E641CC41DCEFE00D63B9D98C0BAFA2387EDD2E0AA1125EF5FD2", "hash_ssdeep": "192:9q00yPTs6Aqq6Nz1B1ZWWgfXabxwu7Wa6WEDB:A00GTszqqA1B1gWpbxHWa6WE", "hash_imp": "2177BAFF198B6BCDCF56F96FB63DD54C", "hash_pesha1": "DF65F0A820B215B46F1362DB96A0E9D00CBD8C08", "hash_pe256": "39CEE0C1111380BE96561BF19AB8BDCF1A8E4CC815157617D4CF50994EAE75DB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hostname APP", "meta_original_filename": "hostname.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/5fb2d17787ffec622ab296775632f9b7a4be42cc06d3da92b4cd6bc288ad035c/detection/", "output": "\r\nPrints the name of the current host.\r\n\r\nhostname\r\n\r\n", "error": "sethostname: Use the Network Control Panel Applet to set hostname.\r\nhostname -s is not supported.\r\n" }, "iashost.exe-F45E4F5DB36742A372EB13FDED59163C": { "file_name": "iashost.exe", "file_path": "C:\\Windows\\SysWOW64\\iashost.exe", "hash_md5": "F45E4F5DB36742A372EB13FDED59163C", "hash_sha1": "C02155B10B45604FECD252BC008BCE8F1E786623", "hash_sha256": "E0C63C25C5233ACC9B9599846EA315E587A0921D4081563DE3D3E23AA457A180", "hash_sha384": "00FC74DDADCF091FE7A38F411AD1635C6A753AE0098EE316CAD40AC66F83E52022738EE4939537DA0E91621506FFB724", "hash_sha512": "0E52717C07A50B4E2763C7AC6C6A912716325B604B181DECE3ABFA1F1F967A292A655EDC5D2A8BB2D9CB68091BF7DD9BC06F389DA749968A512A5BF05C546E18", "hash_ssdeep": "384:zIcTY/haVO9g9vLXGh0KZ0VoLhrLk73Er6NeiGWruWfEY:z9Ijgm0VTNeiTv", "hash_imp": "8C6D16DBB1DDEEF910D034201691F333", "hash_pesha1": "CFAAA065C27B29DF3E0F13B5A3BA6DB57FE6F456", "hash_pe256": "37C892A9339F30325B3CC06B36BBB32A0847DE58FC5A8DAC82D3272086A908BF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IAS Host", "meta_original_filename": "IASHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/e0c63c25c5233acc9b9599846ea315e587a0921d4081563de3d3e23aa457a180/detection/" }, "icacls.exe-C61AA179437F1114DCE7E14C49D547FD": { "file_name": "icacls.exe", "file_path": "C:\\Windows\\SysWOW64\\icacls.exe", "hash_md5": "C61AA179437F1114DCE7E14C49D547FD", "hash_sha1": "03247796CF3CA7F40F4BC30638B650A43E70DED2", "hash_sha256": "ACE546697CC29946F459EECC3B0C3035530AA603880B811C7D1B0156AD7EB692", "hash_sha384": "49C2D8C6C078CE9D6ECA98B8EF81119244DA0081B704322738266DD5B636FC4E4EA8D380501B709DE0C2EB5753CC8885", "hash_sha512": "CE94C8F96F75273AC85A333E6CF67B51F6D026385DEA21F13275F2B7348168779E142438FA327B57CBF714EFE8B88B947E4A91C82AB82093E1B5AB145F5C3D51", "hash_ssdeep": "384:KawV5B6iovfhlJwS7RVmATDoXErbGlx6Omf2AQlWrnctalrqsr5Aer8PpXTWMYnH:U4iovZ/wS7zpeO9Ov6rqsrmeaTWMYkk", "hash_imp": "019F88299D7F5E77F17221DA15112A43", "hash_pesha1": "AB526BE00A7FF4CD7684DDB7C76198A0CDF7B522", "hash_pe256": "9E7173EB1B2C2079093B12B96E5760ADB60D7BDAD1CD344E0F92980FB8B6D31B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_original_filename": "iCACLS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/ace546697cc29946f459eecc3b0c3035530aa603880b811c7d1b0156ad7eb692/detection/", "output": "\r\nICACLS name /save aclfile [/T] [/C] [/L] [/Q]\r\n stores the DACLs for the files and folders that match the name\r\n into aclfile for later use with /restore. Note that SACLs,\r\n owner, or integrity labels are not saved.\r\n\r\nICACLS directory [/substitute SidOld SidNew [...]] /restore aclfile\r\n [/C] [/L] [/Q]\r\n applies the stored DACLs to files in directory.\r\n\r\nICACLS name /setowner user [/T] [/C] [/L] [/Q]\r\n changes the owner of all matching names. This option does not\r\n force a change of ownership; use the takeown.exe utility for\r\n that purpose.\r\n\r\nICACLS name /findsid Sid [/T] [/C] [/L] [/Q]\r\n finds all matching names that contain an ACL\r\n explicitly mentioning Sid.\r\n\r\nICACLS name /verify [/T] [/C] [/L] [/Q]\r\n finds all files whose ACL is not in canonical form or whose\r\n lengths are inconsistent with ACE counts.\r\n\r\nICACLS name /reset [/T] [/C] [/L] [/Q]\r\n replaces ACLs with default inherited ACLs for all matching files.\r\n\r\nICACLS name [/grant[:r] Sid:perm[...]]\r\n [/deny Sid:perm [...]]\r\n [/remove[:g|:d]] Sid[...]] [/T] [/C] [/L] [/Q]\r\n [/setintegritylevel Level:policy[...]]\r\n\r\n /grant[:r] Sid:perm grants the specified user access rights. With :r,\r\n the permissions replace any previously granted explicit permissions.\r\n Without :r, the permissions are added to any previously granted\r\n explicit permissions.\r\n\r\n /deny Sid:perm explicitly denies the specified user access rights.\r\n An explicit deny ACE is added for the stated permissions and\r\n the same permissions in any explicit grant are removed.\r\n\r\n /remove[:[g|d]] Sid removes all occurrences of Sid in the ACL. With\r\n :g, it removes all occurrences of granted rights to that Sid. With\r\n :d, it removes all occurrences of denied rights to that Sid.\r\n\r\n /setintegritylevel [(CI)(OI)]Level explicitly adds an integrity\r\n ACE to all matching files. The level is to be specified as one\r\n of:\r\n L[ow]\r\n M[edium]\r\n H[igh]\r\n Inheritance options for the integrity ACE may precede the level\r\n and are applied only to directories.\r\n\r\n /inheritance:e|d|r\r\n e - enables inheritance\r\n d - disables inheritance and copy the ACEs\r\n r - remove all inherited ACEs\r\n\r\n\r\nNote:\r\n Sids may be in either numerical or friendly name form. If a numerical\r\n form is given, affix a * to the start of the SID.\r\n\r\n /T indicates that this operation is performed on all matching\r\n files/directories below the directories specified in the name.\r\n\r\n /C indicates that this operation will continue on all file errors.\r\n Error messages will still be displayed.\r\n\r\n /L indicates that this operation is performed on a symbolic link\r\n itself versus its target.\r\n\r\n /Q indicates that icacls should suppress success messages.\r\n\r\n ICACLS preserves the canonical ordering of ACE entries:\r\n Explicit denials\r\n Explicit grants\r\n Inherited denials\r\n Inherited grants\r\n\r\n perm is a permission mask and can be specified in one of two forms:\r\n a sequence of simple rights:\r\n N - no access\r\n F - full access\r\n M - modify access\r\n RX - read and execute access\r\n R - read-only access\r\n W - write-only access\r\n D - delete access\r\n a comma-separated list in parentheses of specific rights:\r\n DE - delete\r\n RC - read control\r\n WDAC - write DAC\r\n WO - write owner\r\n S - synchronize\r\n AS - access system security\r\n MA - maximum allowed\r\n GR - generic read\r\n GW - generic write\r\n GE - generic execute\r\n GA - generic all\r\n RD - read data/list directory\r\n WD - write data/add file\r\n AD - append data/add subdirectory\r\n REA - read extended attributes\r\n WEA - write extended attributes\r\n X - execute/traverse\r\n DC - delete child\r\n RA - read attributes\r\n WA - write attributes\r\n inheritance rights may precede either form and are applied\r\n only to directories:\r\n (OI) - object inherit\r\n (CI) - container inherit\r\n (IO) - inherit only\r\n (NP) - don't propagate inherit\r\n (I) - permission inherited from parent container\r\n\r\nExamples:\r\n\r\n icacls c:\\windows\\* /save AclFile /T\r\n - Will save the ACLs for all files under c:\\windows\r\n and its subdirectories to AclFile.\r\n\r\n icacls c:\\windows\\ /restore AclFile\r\n - Will restore the Acls for every file within\r\n AclFile that exists in c:\\windows and its subdirectories.\r\n\r\n icacls file /grant Administrator:(D,WDAC)\r\n - Will grant the user Administrator Delete and Write DAC\r\n permissions to file.\r\n\r\n icacls file /grant *S-1-1-0:(D,WDAC)\r\n - Will grant the user defined by sid S-1-1-0 Delete and\r\n Write DAC permissions to file.\r\n", "error": "First parameter must be a file name pattern or \"/?\"\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\icacls.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "icsunattend.exe-90FDAD5C24FAC9EADB12268E62DC2A3B": { "file_name": "icsunattend.exe", "file_path": "C:\\Windows\\SysWOW64\\icsunattend.exe", "hash_md5": "90FDAD5C24FAC9EADB12268E62DC2A3B", "hash_sha1": "BC2767E7FEF828A685A433BD6EA41EA175648D58", "hash_sha256": "B10CB64A755F67C25D42A5716D9C89094C799DD736D0A4E0639574B1ED5E7096", "hash_sha384": "2A3EA92ED4C8617E505270125C2DE4244D8B31D36C29B840F476640D9E856298A18D26D374737752560329D655F507ED", "hash_sha512": "8BD17E54922CB6283194776BE671FA3151653126558FBBCB156AA0ADAC89BF44964DC80F6EC705FAD8787D823C5C33DF19732D03482E49F4F45BB9BA5FB0222E", "hash_ssdeep": "192:4hTXLdol9dJw9Z9mHbPraFZc7ZEKVQN2Nn1teDaufXDBakz3WNRWuH:4hzLNQbOFZc7ZTV6KeDaSBNz3WNRWQ", "hash_imp": "E5BAC4237CDFEFED24138C9D44950ABE", "hash_pesha1": "E7A706AD096313D774265519BF468C0051A8D720", "hash_pe256": "CC346D27C2D5926A878DFA4D2516789B372962A1F833BD8FFED7FB123EA64B7E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ICS Unattend Utility", "meta_original_filename": "icsunattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/b10cb64a755f67c25d42a5716d9c89094c799dd736d0a4e0639574b1ed5e7096/detection/" }, "ieUnatt.exe-188049D51E59EBAFC4C5D36E26CF34EA": { "file_name": "ieUnatt.exe", "file_path": "C:\\Windows\\SysWOW64\\ieUnatt.exe", "hash_md5": "188049D51E59EBAFC4C5D36E26CF34EA", "hash_sha1": "8E88D69F154F75B9C200577A6FBDD397E8415C14", "hash_sha256": "BA468FAC470FD88E72A7253189BF3673079D1E31BB1F7725516F9FA757047A7A", "hash_sha384": "B483E61A688728B557CD62F629D421DB984C4508188A0020F56017838E0D0DE5536678A04AD7113B3FBBD09537C62D6F", "hash_sha512": "CE72DC46B0225C34EFE010B72DBC5DBE41F85A7799E2352D1CEF77A50ADB640F44B8BB883162AA9561BBD2E005FDC8779A367554E68038E6809BC62F76E4D9A8", "hash_ssdeep": "1536:DtmdpPle5HviZAWGY16OoSs63l757Qz/bqYDGdxEPvwmmxu/9:oOvIX6OoSs63l57QKYDGdxcwjxu/9", "hash_imp": "FA575E2C1B7ED2EDFE9055C531A3211D", "hash_pesha1": "437242D5B311120897AE6CBBCF82FE4DD1083AA4", "hash_pe256": "7E248AD7EFB829A7C5A8C76624AF9CE2A54883CB791AAB44D665E252AE6C3D19", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IE 7.0 Unattended Install Utility", "meta_original_filename": "IEUNATT.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/ba468fac470fd88e72a7253189bf3673079d1e31bb1f7725516f9fa757047a7a/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ieUnatt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "iexpress.exe-D96FCBCCB9CCE01ED1F35DBDAF6D1FE4": { "file_name": "iexpress.exe", "file_path": "C:\\Windows\\SysWOW64\\iexpress.exe", "hash_md5": "D96FCBCCB9CCE01ED1F35DBDAF6D1FE4", "hash_sha1": "AF84EF757BE8DD1A09BADD03618A8AAEF836A6DB", "hash_sha256": "7E125B3AF9E9BC1FAF52C24E5E0A4E287D362EC07AF491FA8D7F27609BEFBE43", "hash_sha384": "49F3B4ED6F01852DC9B8153C3FB92C6EEBAFF7E287F45A6DE58E5931D028F7E19A5E447DD6E8CCFA9B483CD51DD8FB6F", "hash_sha512": "93BBAB4D25053D5590938F78612FF5EC407E3D9C5B3D98DF61596E35F1442234794A633D3CF051A6B3EFDBCBD083DB0427439956D3F9B2CEC42496324D247A02", "hash_ssdeep": "3072:Sn9/1I5mkNKPKR1VNDnGOb+ahXNqJohePnq45L84ciFB:e1IE4U+NDGOb+asEwv5LbFB", "hash_imp": "74C91AAB7B963325BC9BC79D27993FB4", "hash_pesha1": "A8EAC0B7689C94F9F649DF08E6248FB61303BA43", "hash_pe256": "DFBA78E085EA0F717EA01BD65077CE43146240D004C1EB785BAB873DC22152E6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Wizard", "meta_original_filename": "IEXPRESS.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/7e125b3af9e9bc1faf52c24e5e0a4e287d362ec07af491fa8d7f27609befbe43/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_b4b635d36e735c2c": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\iexpress.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.17763.1518_en-us_cac17eb89b198e19": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.17763.1518_en-us_cac17eb89b198e19\\comctl32.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\iexpress.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "IExpress Wizard" }, "InfDefaultInstall.exe-95BE9B12D200216D84F4D4BFED75FB30": { "file_name": "InfDefaultInstall.exe", "file_path": "C:\\Windows\\SysWOW64\\InfDefaultInstall.exe", "hash_md5": "95BE9B12D200216D84F4D4BFED75FB30", "hash_sha1": "131C829F7E4C8F8040AF3A3EC0C31CEC04E5443B", "hash_sha256": "0A07E8ABEDEA7406F4F1BD0A2A10CC46FD9461D464118D23E2845EB68AF26E1A", "hash_sha384": "A4040315057F0B013D243A5AFB9A86664F2114B87793146A7209D425EBF9C1AB4FFF96D7F936103D717BD3A20A4C50FA", "hash_sha512": "C0631A03FB5D4FCE8235342C2F1983A5A94EFDDFCCE62CF24BFC132342ADD2D944FE37820A81970277462C16642399BD2C289158BC9B50D322F914FD45D7CD1A", "hash_ssdeep": "192:v7sbtMNudIEpxpVW+3Dg/otbtmisZKW/GW:vQt/lpTVW+sAtRVoKW/GW", "hash_imp": "18DD7632ACAED909AC51C5507BC777FE", "hash_pesha1": "514F98025B39950057E1D24BFD2C1F5249036ADE", "hash_pe256": "EF9275CA958779293A09EBF2F8ECA6EE8882AF81D9630C9DF8D7E4AD81FD6CDB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "INF Default Install", "meta_original_filename": "InfDefaultInstall.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/0a07e8abedea7406f4f1bd0a2a10cc46fd9461d464118d23e2845eb68af26e1a/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\InfDefaultInstall.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\newdev.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\InfDefaultInstall.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Install Error" }, "instnm.exe-A97C2FF8A508B3FB5281AEF76AC28867": { "file_name": "instnm.exe", "file_path": "C:\\Windows\\SysWOW64\\instnm.exe", "hash_md5": "A97C2FF8A508B3FB5281AEF76AC28867", "hash_sha1": "2E2204EF8A42DB29031A44CBEB554A342A1DED50", "hash_sha256": "686EA820F3BDF8DA8A6B73DBCA069C846896C5885B0193D23AF2CA9D5F1D6D9B", "hash_sha384": "741DF6E268093553DF06ECACAD3A35D0935B2DA9FDA7D2DA166EA8715AE7114A83D868B7C6043B819B0F0183A3196203", "hash_sha512": "5AC76995703B7E272D05AA7CB06F038DC9328405C9700E16EDB2F8B3E66B7439FCE1D27EFC4A69FA3C46D22128D327FB95D42DA115CC0D85A577B227C8B8206A", "hash_ssdeep": "96:7XMzMP19tzJplqEp2UuSdZDGj4PXeVHcmDMsf3tm/EW7wIXuWwraAkD:78zMP19BJr3YHP5cmDMKtmcWx+WiaAm", "hash_imp": "34EF1D42EB1DA272F024F086EE53F0D2", "hash_pesha1": "401C29CD8A64F21D75EFACF09BBE8155755B9B4F", "hash_pe256": "ADC5B8532B4283EA7CE20A339CF10EE0AF22044C56A04CD26C9BD5805FAD4C05", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "32-bit NetMeeting Installer for Win64", "meta_original_filename": "instnm.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/686ea820f3bdf8da8a6b73dbca069c846896c5885b0193d23af2ca9d5f1d6d9b/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\instnm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ipconfig.exe-B8CB2DFCA7379908B0605331A759AF4C": { "file_name": "ipconfig.exe", "file_path": "C:\\Windows\\SysWOW64\\ipconfig.exe", "hash_md5": "B8CB2DFCA7379908B0605331A759AF4C", "hash_sha1": "A7128F925D4B95C074013F545102BBCD753A10BD", "hash_sha256": "B0832DEC07A4CB6228B7B392D6ABAFB79E9BF7327605AE3E86E1E617DE7495A5", "hash_sha384": "126EE417BFDE112AE2B12DF5B1E7906DB166C8444292BEF79279A2F1570ADF0060D124A6B3414970E71A42F4BCC97216", "hash_sha512": "91E672BD9DE4F5C08DF68B3FF64808B4267846F0A36C76E62DFEE4888FDFBCF295BCCECCD67DC4ACE5F444D4352B6E95601EAD6A1B3130FB339FFBDF25DD5FDD", "hash_ssdeep": "384:0STbXEOM7LqKYZHrWn5yu3Qso6uVCgXvtCZvE0zb4M8XG1tbyf9Wxyypvb976hWP:0fmKYZQQyJukgXvtCOeB83Wxymb9D", "hash_imp": "98CEEAF3EB55DE32686F14F2CF79FC6F", "hash_pesha1": "86EAB569A85DCBD47611D73842E4073A3415D8D9", "hash_pe256": "1CDE2A2549B76CF1FCF8096191A650F08A89C39768204386546A2F5246F4F096", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IP Configuration Utility", "meta_original_filename": "ipconfig.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/b0832dec07a4cb6228b7b392d6abafb79e9bf7327605ae3e86e1e617de7495a5/detection/", "output": "\r\nError: unrecognized or incomplete command line.\r\n\r\nUSAGE:\r\n ipconfig [/allcompartments] [/? | /all | \r\n /renew [adapter] | /release [adapter] |\r\n /renew6 [adapter] | /release6 [adapter] |\r\n /flushdns | /displaydns | /registerdns |\r\n /showclassid adapter |\r\n /setclassid adapter [classid] |\r\n /showclassid6 adapter |\r\n /setclassid6 adapter [classid] ]\r\n\r\nwhere\r\n adapter Connection name \r\n (wildcard characters * and ? allowed, see examples)\r\n\r\n Options:\r\n /? Display this help message\r\n /all Display full configuration information.\r\n /release Release the IPv4 address for the specified adapter.\r\n /release6 Release the IPv6 address for the specified adapter.\r\n /renew Renew the IPv4 address for the specified adapter.\r\n /renew6 Renew the IPv6 address for the specified adapter.\r\n /flushdns Purges the DNS Resolver cache.\r\n /registerdns Refreshes all DHCP leases and re-registers DNS names\r\n /displaydns Display the contents of the DNS Resolver Cache.\r\n /showclassid Displays all the dhcp class IDs allowed for adapter.\r\n /setclassid Modifies the dhcp class id. \r\n /showclassid6 Displays all the IPv6 DHCP class IDs allowed for adapter.\r\n /setclassid6 Modifies the IPv6 DHCP class id.\r\n\r\n\r\nThe default is to display only the IP address, subnet mask and\r\ndefault gateway for each adapter bound to TCP/IP.\r\n\r\nFor Release and Renew, if no adapter name is specified, then the IP address\r\nleases for all adapters bound to TCP/IP will be released or renewed.\r\n\r\nFor Setclassid and Setclassid6, if no ClassId is specified, then the ClassId is removed.\r\n\r\nExamples:\r\n > ipconfig ... Show information\r\n > ipconfig /all ... Show detailed information\r\n > ipconfig /renew ... renew all adapters\r\n > ipconfig /renew EL* ... renew any connection that has its \r\n name starting with EL\r\n > ipconfig /release *Con* ... release all matching connections,\r\n eg. \"Wired Ethernet Connection 1\" or\r\n \"Wired Ethernet Connection 2\"\r\n > ipconfig /allcompartments ... Show information about all \r\n compartments\r\n > ipconfig /allcompartments /all ... Show detailed information about all\r\n compartments\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ipconfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "iscsicli.exe-8E8F391704E2A0E15B67740BC79B7B38": { "file_name": "iscsicli.exe", "file_path": "C:\\Windows\\SysWOW64\\iscsicli.exe", "hash_md5": "8E8F391704E2A0E15B67740BC79B7B38", "hash_sha1": "AB477DB6C15BC6426226A365BA5C82D9202B466A", "hash_sha256": "5A9DE5AB7FE13CE4841C14238CEADD4FB86521FCD75C351F605BCA66D3F99B8F", "hash_sha384": "756E9CE14A278E253D7B9970C912A253416C90EBD61637500DBB486308F56950842EBCC60ABBE06E02BBDAA77E3AC023", "hash_sha512": "4D2248DDC7AEE47BBB5D78DF29AA8DFD099FF22D5DD1CB6901ED29558B278E82E8911227F01789EC2226FCE010D2320D77EF1F5425CD49FBB8C323CFFA630087", "hash_ssdeep": "3072:YKITtU1RhKorvhOIjx9mnx/OOuAICgKOKaeqUKOpVk/qfWJTfS1n37My:QTtU1RhXBjxIOZKRaeqUp3WJrM", "hash_imp": "848034C374AF0C845CDCD484AC34CFD6", "hash_pesha1": "4CB73BFFC48146B4DC9B8DD6BEECCD8D98B6F8FF", "hash_pe256": "1648B92F90D7C7BEE073FEB71CBCE1356AF7868FDCDA3609FA25010153CCD3BB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "iSCSI Discovery tool", "meta_original_filename": "iscsicli.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/5a9de5ab7fe13ce4841c14238ceadd4fb86521fcd75c351f605bca66d3f99b8f/detection/", "output": "Microsoft iSCSI Initiator Version 10.0 Build 17763\n\niscsicli\n\niscsicli AddTarget <TargetName> <TargetAlias> <TargetPortalAddress>\n <TargetPortalSocket> <Target flags>\n <Persist> <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType>\n <Mapping Count> <Target Lun> <OS Bus> <Os Target> \n <OS Lun> ...\n\niscsicli RemoveTarget <TargetName> \n\niscsicli AddTargetPortal <TargetPortalAddress> <TargetPortalSocket> \n [HBA Name] [Port Number]\n <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType>\n\niscsicli RemoveTargetPortal <TargetPortalAddress> <TargetPortalSocket> [HBA Name] [Port Number]\n\niscsicli RefreshTargetPortal <TargetPortalAddress> <TargetPortalSocket> [HBA Name] [Port Number]\n\niscsicli ListTargets [ForceUpdate]\n\niscsicli ListTargetPortals\n\niscsicli TargetInfo <TargetName> [Discovery Mechanism]\n\niscsicli LoginTarget <TargetName> <ReportToPNP>\n <TargetPortalAddress> <TargetPortalSocket>\n <InitiatorInstance> <Port number> <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType> <Key>\n <Mapping Count> <Target Lun> <OS Bus> <Os Target> \n <OS Lun> ...\n\niscsicli LogoutTarget <SessionId>\n\niscsicli PersistentLoginTarget <TargetName> <ReportToPNP>\n <TargetPortalAddress> <TargetPortalSocket>\n <InitiatorInstance> <Port number> <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType> <Key>\n <Mapping Count> <Target Lun> <OS Bus> <Os Target> \n <OS Lun> ...\n\niscsicli ListPersistentTargets\n\niscsicli RemovePersistentTarget <Initiator Name> <TargetName> \n <Port Number> \n <Target Portal Address> \n <Target Portal Socket> \n\niscsicli AddConnection <SessionId> <Initiator Instance>\n <Port Number> <Target Portal Address>\n <Target Portal Socket> <Security Flags>\n <Login Flags> <Header Digest> <Data Digest> \n <Max Connections> <DefaultTime2Wait>\n <DefaultTime2Retain> <Username> <Password> <AuthType> <Key>\n\niscsicli RemoveConnection <SessionId> <ConnectionId> \niscsicli ScsiInquiry <SessionId> <LUN> <EvpdCmddt> <PageCode>\n\niscsicli ReadCapacity <SessionId> <LUN>\n\niscsicli ReportLUNs <SessionId>\n\niscsicli ReportTargetMappings\n\niscsicli ListInitiators\n\niscsicli AddiSNSServer <iSNS Server Address>\n\niscsicli RemoveiSNSServer <iSNS Server Address>\n\niscsicli RefreshiSNSServer <iSNS Server Address>\n\niscsicli ListiSNSServers\n\niscsicli FirewallExemptiSNSServer\n\niscsicli NodeName <node name>\n\niscsicli SessionList <Show Session Info>\n\niscsicli CHAPSecret <chap secret>\n\niscsicli TunnelAddr <Initiator Name> <InitiatorPort> <Destination Address> <Tunnel Address> <Persist>\n\niscsicli GroupKey <Key> <Persist>\n\niscsicli BindPersistentVolumes\n\niscsicli BindPersistentDevices\n\niscsicli ReportPersistentDevices\n\niscsicli AddPersistentDevice <Volume or Device Path>\n\niscsicli RemovePersistentDevice <Volume or Device Path>\n\niscsicli ClearPersistentDevices\n\niscsicli Ping <Initiator Name> <Address> [Request Count] [Request Size] [Request Timeout]\n\niscsicli GetPSKey <Initiator Name> <initiator Port> <Id Type> <Id>\n\niscsicli PSKey <Initiator Name> <initiator Port> <Security Flags> <Id Type> <Id> <Key> <persist>\nQuick Commands\n\niscsicli QLoginTarget <TargetName> [CHAP Username] [CHAP Password]\n\niscsicli QAddTarget <TargetName> <TargetPortalAddress>\n\niscsicli QAddTargetPortal <TargetPortalAddress>\n [CHAP Username] [CHAP Password]\n\niscsicli QAddConnection <SessionId> <Initiator Instance>\n <Target Portal Address>\n [CHAP Username] [CHAP Password]\n\nTarget Mappings:\n <Target Lun> is the LUN value the target uses to expose the LUN.\n It must be in the form 0x0123456789abcdef\n <OS Bus> is the bus number the OS should use to surface the LUN\n <OS Target> is the target number the OS should use to surface the LUN\n <OS LUN> is the LUN number the OS should use to surface the LUN\n\nPayload Id Type:\n ID_IPV4_ADDR is 1 - Id format is 1.2.3.4\n ID_FQDN is 2 - Id format is ComputerName\n ID_IPV6_ADDR is 5 - Id form is IPv6 Address\nSecurity Flags:\n TunnelMode is 0x00000040\n TransportMode is 0x00000020\n PFS Enabled is 0x00000010\n Aggressive Mode is 0x00000008\n Main mode is 0x00000004\n IPSEC/IKE Enabled is 0x00000002\n Valid Flags is 0x00000001\n\nLogin Flags:\n ISCSI_LOGIN_FLAG_REQUIRE_IPSEC 0x00000001\n IPsec is required for the operation\n\n ISCSI_LOGIN_FLAG_MULTIPATH_ENABLED 0x00000002\n Multipathing is enabled for the target on this initiator\n\nAuthType:\n ISCSI_NO_AUTH_TYPE = 0,\n No iSCSI in-band authentication is used\n\n ISCSI_CHAP_AUTH_TYPE = 1,\n One way CHAP (Target authenticates initiator is used)\n\n ISCSI_MUTUAL_CHAP_AUTH_TYPE = 2\n Mutual CHAP (Target and Initiator authenticate each other is used)\n\nTarget Flags:\n ISCSI_TARGET_FLAG_HIDE_STATIC_TARGET 0x00000002\n If this flag is set then the target will never be reported unless it\n is also discovered dynamically.\n\n ISCSI_TARGET_FLAG_MERGE_TARGET_INFORMATION 0x00000004\n If this flag is set then the target information passed will be\n merged with any target information already statically configured for\n the target\n\nCHAP secrets, CHAP passwords and IPSEC preshared keys can be specified as\na text string or as a sequence of hexadecimal values. The value specified on\nthe command line is always considered a string unless the first two characters\n0x in which case it is considered a hexadecimal value.\n\nFor example 0x12345678 specifies a 4 byte secret\n\nAll numerical values are assumed decimal unless preceeded by 0x. If\npreceeded by 0x then value is assumed to be hex\n\niscsicli can also be run in command line mode where iscsicli commands\ncan be entered directly from the console. To enter command line\nmode, just run iscsicli without any parameters\n\nThe operation completed successfully. \n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\iscsicli.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "iscsicpl.exe-A985A6EBE1B37BC6028D035AC2E0D73F": { "file_name": "iscsicpl.exe", "file_path": "C:\\Windows\\SysWOW64\\iscsicpl.exe", "hash_md5": "A985A6EBE1B37BC6028D035AC2E0D73F", "hash_sha1": "14F92E5DB9AAEF65419606EF7377928274961E38", "hash_sha256": "F3A8986ADB353E75FDFCA44A0C1DC6796DDBFBDEB936F2482C5386F6F7A27DF7", "hash_sha384": "5677DE55041F97B5B03A81EC4EDC74C0EDB5E3A572982F109788389E497DCD25FCAE97445FEB15594406F8A7AC2B85FD", "hash_sha512": "00BBCF64978C0FF54488983FE380549942F0296CEF72073839706C9DD292BF6ECD17158842ECFEF8AD22CB583060403F566B05E3EED459D14C49724D9287E1E9", "hash_ssdeep": "3072:OEnRFAEM82n7GC2jctoKpsusT2rEFpeoIUpZ:x0X8I0jct5rEJdp", "hash_imp": "4751D16FE4697EBBF94F37D0EBC833C3", "hash_pesha1": "C8A67AD477D212826E9E1F66C1F17F77CB9B937C", "hash_pe256": "6FD2AE7031909DEC23B06ED7913B1198375850042856201F750CE03BB0184F53", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft iSCSI Initiator Configuration Tool", "meta_original_filename": "iscsicpl.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/f3a8986adb353e75fdfca44a0c1dc6796ddbfbdeb936f2482c5386f6f7a27df7/detection/", "children": "rundll32.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\iscsicpl.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\iscsicpl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "isoburn.exe-4133422034F384BC58988D75844A4BD5": { "file_name": "isoburn.exe", "file_path": "C:\\Windows\\SysWOW64\\isoburn.exe", "hash_md5": "4133422034F384BC58988D75844A4BD5", "hash_sha1": "491EA265E40900FDCEDE637919E8A3FC11EB08EF", "hash_sha256": "1CCA7028745528DD38CE2A385F5DAD4EF6BE6B4A5E2D31C760CF9F21A0510774", "hash_sha384": "174B4B5E6A481B36CCEF0FB9A808D46F646CECC2FE60ED468852D81AA02BC7A5D2D19920CAEE5C8F6F87355ABFBE3832", "hash_sha512": "F16D79A84EECC7E991D892564FF5A695507B76CCDCAFFDB7A91EF979A76A312755F7D4714E4109E99591B9CA8E67F74D76A28369C45E20ED18D3ECA25F297FC8", "hash_ssdeep": "768:aByiST623T40hbYDD2Ng7vj8VHRMkL+dlzYa5Kiyk/g3qmPerYon2OwLHha2m0Jv:tT6gmD4gTGHR7aJyk/YAbeHZrQqf", "hash_imp": "DC797046CC7D70AD1A7A33DAFA70C466", "hash_pesha1": "CA3E4A478007AC2AC8B95776C9FB6A8E28285194", "hash_pe256": "699477D58048B9E47F34F68F53C9B4AD438F8E43485807B94A86C7E70174DFB7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Disc Image Burning Tool", "meta_original_filename": "ISOBURN.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/1cca7028745528dd38ce2a385f5dad4ef6be6b4a5e2d31c760cf9f21a0510774/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\isoburn.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\isoburn.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Disc Image Burner" }, "klist.exe-E69A6624A40AC6700AF7FC55DD3FA626": { "file_name": "klist.exe", "file_path": "C:\\Windows\\SysWOW64\\klist.exe", "hash_md5": "E69A6624A40AC6700AF7FC55DD3FA626", "hash_sha1": "3EC53303A5E9D2F19F8E35DD63EE6BD6787701D4", "hash_sha256": "4628D2F60C73A24EC6DC626F0F4B242F59DDF6778614895DA2AAE78AB029EE60", "hash_sha384": "16DD2A5EF163CA966FCF5208AD550F9F382EFA19FA5531B2627E6E0E688707333AF8529906C925C470769C9A7A8D858E", "hash_sha512": "6652A56A61D9F80875110FCE251445F085657291E526D9716E2D0295081600A9B4C9D5A499C53697AF4D4ABDE99EBE79D3BF52B8E205B2D61DB8EC46622C488D", "hash_ssdeep": "768:oQ8Fci4n+BT1s1Ns4jpqsHkv6AG3F5kDmG:Yj4ksK613F5kDmG", "hash_imp": "C5E30BAFFF9013AE080E92B8421843BB", "hash_pesha1": "43313B161EFFA0354DDD4264664AB903A9511545", "hash_pe256": "7C116DCD2800C0DCCDE295668BF455DDA7A57ADDCF1D1926E5F5FB70E24ACD20", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Tool for managing the Kerberos ticket cache", "meta_original_filename": "klist.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/4628d2f60c73a24ec6dc626f0f4b242f59ddf6778614895da2aae78ab029ee60/detection/", "output": "\r\nUsage: klist.exe [command]\r\n\r\nCommand list:\r\n [tickets] [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n tgt [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n purge [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n sessions [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n kcd_cache [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n get <SPN> [-lh <LogonId.HighPart>] [-li <LogonId.LowPart>]\r\n [-kdcoptions <options>] [-cacheoptions <options>]\r\n add_bind <DOMAIN> <DC>\r\n query_bind\r\n purge_bind\r\n" }, "ksetup.exe-3C4241E6A8FC2288378D07CD378DF42C": { "file_name": "ksetup.exe", "file_path": "C:\\Windows\\SysWOW64\\ksetup.exe", "hash_md5": "3C4241E6A8FC2288378D07CD378DF42C", "hash_sha1": "207BB73474EA60F1EF2DAE901E43D789E8B29A95", "hash_sha256": "83B79562A118524EF74F15B264E50AEB5307BDDA765F5413AADDB894ED742DA5", "hash_sha384": "CDEC9087E4B8A30DDA89052DB6255C356BB8D842784D15099F46E9A57009ED9B3C3F89EAB3654F8A76B0D493BC86FA6C", "hash_sha512": "39570A9F77D812BB5442619CC104A7C9E561C0D9D5563D23A74AED1D7A4C083C067581FCEE79AE3E5E3D33A6FBA16DC18F6968B1A4EDBAE180F00842120E3E24", "hash_ssdeep": "768:x0twZ+bFWzclX3uV/+YvdT7iwrZVFx4ZVrjqe6td2dIpg:xj+b4olX3C+AdT7iw1VFx4XfOtduIpg", "hash_imp": "EA5012A878F0C2120889BBC97F54D267", "hash_pesha1": "9CC3E72235CD9B59E46FE623CCCBAB680C2D36F1", "hash_pe256": "39CD6B6FC45E2CD38DC694A7BBA5A9283A778E2A95CF8F689796CF323F08E9CC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Kerberos Setup tool", "meta_original_filename": "ksetup.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/64", "filescan_vtlink": "https://www.virustotal.com/gui/file/83b79562a118524ef74f15b264e50aeb5307bdda765f5413aaddb894ed742da5/detection/", "output": "\r\nUSAGE:\r\n/SetRealm <DnsDomainName>\r\n\tMakes this computer a member of an RFC1510 Kerberos Realm\r\n/MapUser <Principal> [Account]\r\n\tMaps a Kerberos Principal ('*' = any principal)\r\r\n\tto an account ('*' = an account by same name);\r\r\n\tIf account name is omitted, mapping is deleted \r\r\n\tfor the specified principal\r\n/AddKdc <RealmName> [KdcName]\r\n\tDefines a KDC entry for the given realm.\r\r\n\tIf KdcName omitted, DNS may be used to locate KDCs.\r\n/DelKdc <RealmName> [KdcName]\r\n\tdeletes a KDC entry for the realm.\r\r\n\tIf KdcName omitted, the realm entry itself is deleted.\r\n/AddKpasswd <Realmname> <KpasswdName>\r\n\tAdd Kpasswd server address for a realm\r\n/DelKpasswd <Realmname> <KpasswdName>\r\n\tDelete Kpasswd server address for a realm\r\n/Server <Servername>\r\n\tspecify name of a Windows machine to target the changes.\r\n/SetComputerPassword <Password>\r\n\tSets the password for the computer's domain account\r\r\n\t(or host principal)\r\n/RemoveRealm <RealmName>\r\n\tdelete all information for this realm from the registry.\r\n/Domain [DomainName]\r\n\tuse this domain (if DomainName is unspecified, detect it)\r\n/ChangePassword <OldPasswd> <NewPasswd>\r\n\tUse Kpasswd to change the logged-on user's password.\r\r\n\tUse '*' to be prompted for passwords.\r\n/ListRealmFlags (no args)\r\n\tLists the available Realm flags that ksetup knows\r\n/SetRealmFlags <realm> <flag> [flag] [flag] [...]\r\n\tSets RealmFlags for a specific realm\r\n/AddRealmFlags <realm> <flag> [flag] [flag] [...]\r\n\tAdds additional RealmFlags to a realm\r\n/DelRealmFlags <realm> <flag> [flag] [flag] [...]\r\n\tDeletes RealmFlags from a realm.\r\n/DumpState (no args)\r\n\tAnalyze the kerberos configuration on the given machine.\r\n/AddHostToRealmMap <host> <realm>\r\n\tAdds a mapping for <host> to <realm> to the registry.\r\n/DelHostToRealmMap <host> <realm>\r\n\tDeletes existing mapping for <host> to <realm> from the registry.\r\n/SetEncTypeAttr <domainname> <enctypes>\r\n\tSets the encryption types trust attribute for <domain> to <enctypes> (multiple types should be separated by spaces).\r\r\n\tSupported encryption types are:\r\r\n\t DES-CBC-CRC, DES-CBC-MD5, RC4-HMAC-MD5, \r\r\n\t AES128-CTS-HMAC-SHA1-96, AES256-CTS-HMAC-SHA1-96\r\n/GetEncTypeAttr <domainname>\r\n\tGets the encryption types trust attribute for <domain>.\r\n/AddEncTypeAttr <domainname> <enctypes>\r\n\tAdds <enctypes> to the encryption types trust attribute for <domain> (multiple types should be separated by spaces).\r\n/DelEncTypeAttr <domainname>\r\n\tDeletes the encryption types trust attribute for <domain>.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ksetup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ktmutil.exe-070A0079E0B0602CB63E17C41AE7ABD2": { "file_name": "ktmutil.exe", "file_path": "C:\\Windows\\SysWOW64\\ktmutil.exe", "hash_md5": "070A0079E0B0602CB63E17C41AE7ABD2", "hash_sha1": "B21A37732073B350E944DC09B7D9D5A96663B27F", "hash_sha256": "A436C4FF2539B2A65F4787A0AF777075A0E40EF019B78F7276273266F439873C", "hash_sha384": "B036C40E3968A313D06B9670D9522493179FAE1B47511AA996216FD65201FF54ABB00B49D6ED06FF17CB3E67D07F6C49", "hash_sha512": "F60B2519147C7E2EF7882BF97FC760738311370A3D37E6E015C94E0B25D9154F8ED274A8334A70CC77876ED737F7E97EF7F06722536CB1928D9C26307AD18917", "hash_ssdeep": "192:kSxPqeQrKDmxryckkF11Hvoz217xi1/6qWkR2m1keWIjWW1T:TxPqUarycPJv62Fx6yhhNeWIjWW1", "hash_imp": "E096B10874B4B45A595EAE17714B7AEE", "hash_pesha1": "A2D17052C95A3B76A63EF80A5AFC0F4F6FDB8EE6", "hash_pe256": "F39E7D59DF0AB467F739B091D631DFF273709FB4E74EEFFE78EF198B0E97DCA4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Kernel Transaction Management Utility", "meta_original_filename": "ktmutil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/a436c4ff2539b2a65f4787a0af777075a0e40ef019b78f7276273266f439873c/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ktmutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "output": "--help is an invalid parameter.\r\n---- Commands Supported ----\r\n\r\ntx Commands related to transactions\r\ntm Commands related to transaction managers\r\n" }, "ktpass.exe-DAA65D78C6728CC3CFCCC966F195A02D": { "file_name": "ktpass.exe", "file_path": "C:\\Windows\\SysWOW64\\ktpass.exe", "hash_md5": "DAA65D78C6728CC3CFCCC966F195A02D", "hash_sha1": "534EF57DF649229E1633F0B91AC7F97E79A425D8", "hash_sha256": "48B30EAFC82DC388DFE5BBD55C26C863FC3EC53ABEF16B2B8BB42BC7AD471885", "hash_sha384": "5D93B853E7586D72831859D96CBE69F8A5FC617BB592AE3DA1F2186782C50B261A12DFAABCA50CDA1B688E346EABA29C", "hash_sha512": "FC1AD93270F72E36FD06E6811E8335AD06EB4ED85C0BCA64232540A9DF3409C61B514936843C6D06513A176F6E1759D601DCA17747BF3644D7A732F2E38BD7D9", "hash_ssdeep": "1536:gRYcEn5C+md8bsCBjaQCQ1zITn9Gu/DD4:zvCHi1f0T9Gu/", "hash_imp": "6B4DAF16B8CA0A105FADE9AD3A440777", "hash_pesha1": "F4F064B1528D3CAA4381F41E219CB36618C727A8", "hash_pe256": "04E5700505CD7F20F481B59D383535C4A889D024C9CFACF545BBFA4209ABDFD5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Kerberos keytab tool", "meta_original_filename": "ktpass.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.652 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.652", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/48b30eafc82dc388dfe5bbd55c26c863fc3ec53abef16b2b8bb42bc7ad471885/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ktpass.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "unknown option '--help'.\r\nCommand line options:\r\n\r\n---------------------most useful args\n[- /] out : Keytab to produce\n[- /] princ : Principal name (user@REALM)\n[- /] pass : password to use\n use '*' to prompt for password.\n[- +] rndPass : ... or use +rndPass to generate a random password\n[- /] minPass : minimum length for random password (def:15)\n[- /] maxPass : maximum length for random password (def:256)\n---------------------less useful stuff\n[- /] mapuser : map princ (above) to this user account (default: don't)\n[- /] mapOp : how to set the mapping attribute (default: add it)\n[- /] mapOp : is one of: \r\n[- /] mapOp : add : add value (default) \n[- /] mapOp : set : set value \n[- +] DesOnly : Set account for des-only encryption (default:don't)\n[- /] in : Keytab to read/digest\n---------------------options for key generation\n[- /] crypto : Cryptosystem to use\n[- /] crypto : is one of: \r\n[- /] crypto : DES-CBC-CRC : for compatibility \n[- /] crypto : DES-CBC-MD5 : for compatibility \n[- /] crypto : RC4-HMAC-NT : default 128-bit encryption \n[- /] crypto : AES256-SHA1 : AES256-CTS-HMAC-SHA1-96 \n[- /] crypto : AES128-SHA1 : AES128-CTS-HMAC-SHA1-96 \n[- /] crypto : All : All supported types \n[- /] IterCount : Iteration Count used for AES encryption\n Default: ignored for non-AES, 4096 for AES\n[- /] ptype : principal type in question\n[- /] ptype : is one of: \r\n[- /] ptype : KRB5_NT_PRINCIPAL : The general ptype-- recommended \n[- /] ptype : KRB5_NT_SRV_INST : user service instance \n[- /] ptype : KRB5_NT_SRV_HST : host service instance \n[- /] ptype : KRB5_NT_SRV_XHST : \n[- /] kvno : Override Key Version Number\n Default: query DC for kvno. Use /kvno 1 for Win2K compat.\n[- +] Answer : +Answer answers YES to prompts. -Answer answers NO.\n[- /] Target : Which DC to use. Default:detect\n[- /] RawSalt : raw salt to use when generating key (not needed)\n[- +] DumpSalt : show us the MIT salt being used to generate the key\n[- +] SetUpn : Set the UPN in addition to the SPN. Default DO.\n[- +] SetPass : Set the user's password if supplied.\n" }, "label.exe-F05BF97ABF40E4D6620C44C02F93DA67": { "file_name": "label.exe", "file_path": "C:\\Windows\\SysWOW64\\label.exe", "hash_md5": "F05BF97ABF40E4D6620C44C02F93DA67", "hash_sha1": "2BAE11E3A9B67B3692D55D4481BB2640101537A5", "hash_sha256": "332FA83BDC982AB5A509EFF6FDAC3161034BF55B32B7F7DC3C7551FE3A6A0CBC", "hash_sha384": "5C029D1925A7645E96F86576D219DFD7FE0FBA0D7D951E3F0915621F7E25A761B2FFC8EC3AA6C6BB50BFB436877E786F", "hash_sha512": "5CE47F545883B4BAE5DC2E3090B39753A21862AB3C505B1CA8F42BB04F7686DAB790939FC528C2ECA37B46AE6393E74DD85B40037F02390FF30A7A19049EFD67", "hash_ssdeep": "192:ukoZDUEfi8wI0THvYBB+vhCl4EIC2SDp9td5kdtm1kgWStjWxoNNezd1O:WZgrIVUhCl2C2gPANgWStjWxoOzd", "hash_imp": "89817B62874F5050E534349B8EB33EB0", "hash_pesha1": "8B4E62A8DC3F7A09F21F7EB0C1D26DC3A1E071AE", "hash_pe256": "47AB7C7912248BD69277A1A9ECE1BAE2CC4D6C9B45FA0ADE088AD53B4E4BB72D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Disk Label Utility", "meta_original_filename": "Label.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/332fa83bdc982ab5a509eff6fdac3161034bf55b32b7f7dc3c7551fe3a6a0cbc/detection/", "output": "Creates, changes, or deletes the volume label of a disk.\r\n\r\nLABEL [drive:][label]\r\nLABEL [/MP] [volume] [label]\r\n\r\n drive: Specifies the drive letter of a drive.\r\n label Specifies the label of the volume.\r\n /MP Specifies that the volume should be treated as a\r\n mount point or volume name.\r\n volume Specifies the drive letter (followed by a colon),\r\n mount point, or volume name. If volume name is specified,\r\n the /MP flag is unnecessary.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\label.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "LaunchTM.exe-E68ABE4D3218D6A029F1889E7DCC3D5B": { "file_name": "LaunchTM.exe", "file_path": "C:\\Windows\\SysWOW64\\LaunchTM.exe", "hash_md5": "E68ABE4D3218D6A029F1889E7DCC3D5B", "hash_sha1": "AFCBAF1C3BAE5D87077BF54D43ADD68E73D0023A", "hash_sha256": "61261391D8F4283D539BA4CD19BED875296BA8E1AADCEAB272C9353F90A22DF4", "hash_sha384": "92F999C3DB912986CE6BA6BAFB0061697AC5B496C7E3F78D232E6E75A28B7083C7F2FE3CAAD1EF2BD75099395062A985", "hash_sha512": "2DFA0F2D824BEF66DBAAED8E2E0B873C757A5A69A5F6FB5B8988152ACA4C8221966B779D093C27186EABD64A45B05EE40C80283F2DE7A6714D1A34C579A58C83", "hash_ssdeep": "1536:zUBuPm8UngMCw2I8FXmzOGDBdpunOl1UIHmejrDwkKgT43FVkXXPKedjXfaW:Ou3eCO8FXUO0iOlCIHmeRKPKk", "hash_imp": "E28D1A46BA8C0C2DD607DFE0E3A12845", "hash_pesha1": "947FF0EFDCBAFA3B185AD518A85A3A835A186B98", "hash_pe256": "6182D74B49B12E71C368916825051DCE8C9CC1FC1A0E6BE82763560CECDECF08", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Manager Launcher", "meta_original_filename": "LaunchTM.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/61261391d8f4283d539ba4cd19bed875296ba8e1aadceab272c9353f90a22df4/detection/", "children": [ "explorer.exe", "Taskmgr.exe" ], "runtime_modules": [ "C:\\Windows\\SysWOW64\\LaunchTM.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "LaunchWinApp.exe-4867DFD104ADF0D1A7DEB2969A3D37D1": { "file_name": "LaunchWinApp.exe", "file_path": "C:\\Windows\\SysWOW64\\LaunchWinApp.exe", "hash_md5": "4867DFD104ADF0D1A7DEB2969A3D37D1", "hash_sha1": "0EBA1404B0472706D4F0DBD7AEABEA5B414D5D6A", "hash_sha256": "EA9A82AC3F573C55C9FAD569C18075D0C56BB6A2BD3CBB9C6991C09203176FCC", "hash_sha384": "F9D30EC611CA02D9E8AD31ED8F57E5D931B4FD65AFF9952690195BF9BB97CD77C38582E5A6D21FDE8AB67A9C32FD9D0E", "hash_sha512": "C2591E350080AED89677BD5A4E3A909887E5721F70CCEFC875022B6247923CB98B4C2E1238143815E66A2FF1C60D606434A28CF4C19CA5CE1EA250B11A66E36D", "hash_ssdeep": "768:6K2lUwokKNUYOYKG2z9VnahXd5GMJ2mZJyVqdd:n2+wozfmT2GMJyVqD", "hash_imp": "DC2B1716CFFBC8111A0FF83C20CA0AC4", "hash_pesha1": "3B5FC353F0D0655995C3D4AB77F61B73E903EAD1", "hash_pe256": "5B5B5421B54526DD39EFB432B9C69F98D6EDB4A641DDE3216DDD1007C4F3FE54", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Launch Windows App", "meta_original_filename": "LaunchWinApp.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/ea9a82ac3f573c55c9fad569c18075d0c56bb6a2bd3cbb9c6991c09203176fcc/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "/h", "runtime_modules": [ "C:\\Windows\\SysWOW64\\LaunchWinApp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "lodctr.exe-640372474B52B6E6AD5270B715EF8BB7": { "file_name": "lodctr.exe", "file_path": "C:\\Windows\\SysWOW64\\lodctr.exe", "hash_md5": "640372474B52B6E6AD5270B715EF8BB7", "hash_sha1": "4E7FC5F7D9B661870BDA024FA54504F5C7BAE269", "hash_sha256": "914650F6DC5783422E107159E0B69A0917D43CD5016ECDC14F06577A11FF36F0", "hash_sha384": "AE56A672D41CC78F12B613A6CEFFA298F56AB5561789DE1456A6581B992497F953122D6A2BF307988887E63E5396375A", "hash_sha512": "9FC20F8B0174D5A0C50E04B8BCDE19E501ED9CDD2156050E7E743D681387A7BE15427625CA54C8461E1340E90CAF1BA4735DC13EED132DE383434045D863EDAE", "hash_ssdeep": "768:5C3ZlM8ZNqJEwWrGqYhv3THEDyHLeFm58VpczADyMbGegaYnHSw7tDQg:glM8qJEDSv3THEDqeFBVC5HSw7tD", "hash_imp": "71291F34C89AC0954E83161A791661D5", "hash_pesha1": "AB1A41C2FCA99F3209E3C3BA2DDDB8F8DDFC30B7", "hash_pe256": "77C367EA2FC992CEBEFDA809C730001A5353E37B0D2EF85E8758C35ADE74553B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Load PerfMon Counters", "meta_original_filename": "LODCTR.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/914650f6dc5783422e107159e0b69a0917d43cd5016ecdc14f06577a11ff36f0/detection/", "output": "\r\n\r\nLODCTR\r\n Updates registry values related to performance counters.\r\n\r\nUsage:\r\n LODCTR <INI-FileName>\r\n INI-FileName is the name of the initialization file that contains\r\n the counter name definitions and explain text for an extensible\r\n counter DLL.\r\n\r\n LODCTR /S:<Backup-FileName>\r\n save the current perf registry strings and info to <Backup-FileName>\r\n\r\n LODCTR /R:<Backup-FileName>\r\n restore the perf registry strings and info using <Backup-FileName>\r\n\r\n LODCTR /R\r\n rebuild the perf registry strings and info from scratch based on the current\r\n registry settings and backup INI files.\r\n\r\n LODCTR /T:<Service-Name>\r\n set the performance counter service as trusted.\r\n\r\n LODCTR /E:<Service-Name>\r\n enable the performance counter service.\r\n\r\n LODCTR /D:<Service-Name>\r\n disable the performance counter service.\r\n\r\n LODCTR /Q\r\n\r\n LODCTR /Q:<Service-Name>\r\n query the performance counter service information, either query all or specified one.\r\n\r\n LODCTR /M:<Counter-Manifest>\r\n install Windows Vista performance counter provider definition XML file\r\n to system repository.\r\n\r\nNote: any arguments with spaces in the names must be enclosed within\r\nDouble Quotation marks.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\lodctr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "children": "explorer.exe" }, "logagent.exe-B94C35E526542B190295AC35DED86E32": { "file_name": "logagent.exe", "file_path": "C:\\Windows\\SysWOW64\\logagent.exe", "hash_md5": "B94C35E526542B190295AC35DED86E32", "hash_sha1": "937FD2A0329CDE05992A84E6F0F15A33702D9D20", "hash_sha256": "F100F9542A3D3B48868ADFCA2A5CA4C48960C66D5C0EA1B5D28F994A3B0D3739", "hash_sha384": "C51C6ED7C34E9E83D167C3107DD0D9EEE024B1870D3807AD16884B68F3A4CC870FF1D803E99CA4578E4AC3392C3371C5", "hash_sha512": "4F45244C5DCC1CBDAF5F982234D6FE7827BC2B07815F4BD71A90B75279E8592FE04641677AD870FF5634147748775D27FB4019F77F3E55910F595E6B6F6D4157", "hash_ssdeep": "1536:m8JS2sV0ast4CpgSDXik+WuEeTJWcmX2oIuhkZHgxTMxFKrCKtmtZ:XS240RCCpgj7JWcS24SZHSeECKktZ", "hash_imp": "B6C7B26AD38A6146C7BB1A6BF5FBAAA8", "hash_pesha1": "C707D3973FEFF262231885A86BC02333FF0B9932", "hash_pe256": "5DBA9F082A530D7336374B43EF60C30E97294CE1CCFC4F0046BD81F7DEEE2A46", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Logagent", "meta_original_filename": "logagent.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/f100f9542a3d3b48868adfca2a5ca4c48960c66d5c0ea1b5d28f994a3b0d3739/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1334": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\logagent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "logman.exe-5860F6BEB77FF00C02F41EEA44E9E804": { "file_name": "logman.exe", "file_path": "C:\\Windows\\SysWOW64\\logman.exe", "hash_md5": "5860F6BEB77FF00C02F41EEA44E9E804", "hash_sha1": "94A91F551909287C936194B938D1A551F4003F1C", "hash_sha256": "F1D7464233146E55DEDF17ED942521EF2274E51963D6E4441279D100278A53E6", "hash_sha384": "EE9430F680C0A502F33D8F27923817F7C77E6BE6AB8141AF649B79E045F23FA753745DB5761ED233C08C07651D5C4973", "hash_sha512": "95DD845E7F6DC601349066AA4223C15F777C3A3C43AEF3EFB3592D7B73AA9F7CF70FF0F6279461BA23FDCA34858323A3E1A68C950DA4155562060CAFD7A57E79", "hash_ssdeep": "1536:xrKMkGHOonwthzqV7gGSJsh/D5LUziHKyX8aCL6ovv:hMxuIzqVs7JUD5LLKq8aLm", "hash_imp": "6F2F80DC8B566C199CA43083ACB8E5C1", "hash_pesha1": "60703816F338279F9E55A2FC25456AB2DB63A6EA", "hash_pe256": "ADC74190BC3FDD7239F567D0DAD7B6FD5471C66EBB7C961E7B1492845296C011", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Performance Log Utility", "meta_original_filename": "Logman.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/f1d7464233146e55dedf17ed942521ef2274e51963d6e4441279d100278a53e6/detection/", "output": "\r\nMicrosoft r Logman.exe (10.0.17763.1)\r\n\r\nUsage:\r\n C:\\Windows\\SysWOW64\\logman.exe [create|query|start|stop|delete|update|import|export] [options]\r\n\r\nVerbs:\r\n create Create a new data collector.\r\n query Query data collector properties. If no name\n is given all data collectors are listed.\r\n start Start an existing data collector and set the\n begin time to manual.\r\n stop Stop an existing data collector and set the\n end time to manual.\r\n delete Delete an existing data collector.\r\n update Update an existing data collector's properties.\r\n import Import a data collector set from an XML file.\r\n export Export a data collector set to an XML file.\r\n\r\nAdverbs:\r\n counter Create a counter data collector.\r\n trace Create a trace data collector.\r\n alert Create an alert data collector.\r\n cfg Create a configuration data collector.\r\n providers Show registered providers.\r\n\r\nOptions (counter):\r\n -c <path [path [...]]> Performance counters to collect.\r\n -cf <filename> File listing performance counters to collect,\n one per line.\r\n -f <bin|bincirc|csv|tsv|sql> Specifies the log format for the data\n collector. For SQL database format, you must\n use the -o option in the command line with\n the DNS!log option. The defaults is binary.\r\n -sc <value> Maximum number of samples to collect with a\n performance counter data collector.\r\n -si <[[hh:]mm:]ss> Sample interval for performance counter data\n collectors.\r\n\r\nOptions (trace):\r\n -f <bin|bincirc|csv|tsv|sql> Specifies the log format for the data\n collector. For SQL database format, you must\n use the -o option in the command line with\n the DNS!log option. The defaults is binary.\r\n -mode <trace_mode> Event Trace Session logger mode. For more\n information visit -\n https://go.microsoft.com/fwlink/?LinkID=136464\r\n -ct <perf|system|cycle> Specifies the clock resolution to use when\n logging the time stamp for each event. You\n can use query performance counter, system\n time, or CPU cycle.\r\n -ln <logger_name> Logger name for Event Trace Sessions.\r\n -ft <[[hh:]mm:]ss> Event Trace Session flush timer.\r\n -[-]p <provider [flags [level]]> A single Event Trace provider to enable.\n The terms 'Flags' and 'Keywords' are\n synonymous in this context.\r\n -pf <filename> File listing multiple Event Trace providers\n to enable.\r\n -[-]rt Run the Event Trace Session in real-time mode.\r\n -[-]ul Run the Event Trace Session in user mode.\r\n -bs <value> Event Trace Session buffer size in kb.\r\n -nb <min max> Number of Event Trace Session buffers.\r\n\r\nOptions (alert):\r\n -[-]el Enable/Disable event log reporting.\r\n -th <threshold [threshold [...]]> Specify counters and their threshold\n values for and alert.\r\n -[-]rdcs <name> Data collector set to start when alert fires.\r\n -[-]tn <task> Task to run when alert fires.\r\n -[-]targ <argument> Task arguments.\r\n -si <[[hh:]mm:]ss> Sample interval for performance counter data\n collectors.\r\n\r\nOptions (cfg):\r\n -[-]ni Enable/Disable network interface query.\r\n -reg <path [path [...]]> Registry values to collect.\r\n -mgt <query [query [...]]> WMI objects to collect.\r\n -ftc <path [path [...]]> Full path to the files to collect.\r\n\r\nOptions:\r\n -? Displays context sensitive help.\r\n -s <computer> Perform the command on specified remote system.\r\n -config <filename> Settings file containing command options.\r\n [-n] <name> Name of the target object.\r\n -pid <pid> Process identifier.\r\n -xml <filename> Name of the XML file to import or export.\r\n -as Perform the requested operation asynchronously.\r\n -[-]u <user [password]> User to Run As. Entering a * for the password\n produces a prompt for the password. The\n password is not displayed when you type it at\n the password prompt.\r\n -m <[start] [stop]> Change to manual start or stop instead of a\n scheduled begin or end time.\r\n -rf <[[hh:]mm:]ss> Run the data collector for the specified\n period of time.\r\n -b <M/d/yyyy h:mm:ss[AM|PM]> Begin the data collector at specified time.\r\n -e <M/d/yyyy h:mm:ss[AM|PM]> End the data collector at specified time.\r\n -o <path|dsn!log> Path of the output log file or the DSN and\n log set name in a SQL database. The default\n path is '%systemdrive%\\PerfLogs\\Admin'.\r\n -[-]r Repeat the data collector daily at the\n specified begin and end times.\r\n -[-]a Append to an existing log file.\r\n -[-]ow Overwrite an existing log file.\r\n -[-]v <nnnnnn|mmddhhmm> Attach file versioning information to the end\n of the log name.\r\n -[-]rc <task> Run the command specified each time the log\n is closed.\r\n -[-]max <value> Maximum log file size in MB or number of\n records for SQL logs.\r\n -[-]cnf <[[hh:]mm:]ss> Create a new file when the specified time has\n elapsed or when the max size is exceeded.\r\n -y Answer yes to all questions without prompting.\r\n -fd Flushes all the active buffers of an existing\n Event Trace Session to disk.\r\n -ets Send commands to Event Trace Sessions\n directly without saving or scheduling.\r\n\r\nNote:\r\n Where [-] is listed, an extra - negates the option.\r\n For example --u turns off the -u option.\r\n\r\nMore Information:\r\n Microsoft TechNet - https://go.microsoft.com/fwlink/?LinkID=136332\n\r\nExamples:\r\n logman start perf_log\n logman update perf_log -si 10 -f csv -v mmddhhmm\n logman create counter perf_log -c \"\\Processor(_Total)\\% Processor Time\"\n logman create counter perf_log -c \"\\Processor(_Total)\\% Processor Time\" -max 10 -rf 01:00\n logman create trace trace_log -nb 16 256 -bs 64 -o c:\\logfile\n logman create alert new_alert -th \"\\Processor(_Total)\\% Processor Time>50\"\n logman create cfg cfg_log -reg \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\\\\"\n logman create cfg cfg_log -mgt \"root\\cimv2:SELECT * FROM Win32_OperatingSystem\"\n logman query providers\n logman query providers Microsoft-Windows-Diagnostics-Networking\n logman start process_trace -p Microsoft-Windows-Kernel-Process 0x10 win:Informational -ets\n logman start usermode_trace -p \"Service Control Manager Trace\" -ul -ets\n logman query usermode_trace -p \"Service Control Manager Trace\" -ul -ets\n logman stop usermode_trace -p \"Service Control Manager Trace\" -ul -ets\n logman start process_trace -p Microsoft-Windows-Kernel-Process -mode newfile -max 1 -o output%d.etl -ets\n logman start \"NT Kernel Logger\" -o log.etl -ets\n logman start \"NT Kernel Logger\" -p \"Windows Kernel Trace\" (process,thread) -ets\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\logman.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "logoff.exe-D62B037F763C15D8715980D4B33BFD32": { "file_name": "logoff.exe", "file_path": "C:\\Windows\\SysWOW64\\logoff.exe", "hash_md5": "D62B037F763C15D8715980D4B33BFD32", "hash_sha1": "CA53527267DD2067462FCF791B0262989BDDCC47", "hash_sha256": "44C5395E75BADAE29DFFDCA73F3327D3EE64F70E2E60BA7D7EA367693E622EF5", "hash_sha384": "3057DD6E8BBD93134BC11C95706C9DD8A4E325AB0757CBDA6D74BC97BE6945A11F3E8B855C2418EDE9DDE3478EC852C5", "hash_sha512": "2E9E1761BBA190B3F6770F6BDDF5539F9E416FBF5499C56A5BD2274AF088A42580D21CBA34F863DC5BABE04DDBFB3D150ADC59B52DB0427103D4EB70DB71CB35", "hash_ssdeep": "384:IcmY9Y6rbXSvw/kWmAPlSDCpHMpHD747nx27gCW3PuW:IcmqY6rb/8s2s7", "hash_imp": "7221C66767075D303F4DBDE5A363626C", "hash_pesha1": "62292F93393BDDEAE43E08784EC5C7C16347518F", "hash_pe256": "2BF43671282264A37DF51DECC3BBCB0984D0F402893830B800580A97026CE640", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Session Logoff Utility", "meta_original_filename": "logoff.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/44c5395e75badae29dffdca73f3327d3ee64f70e2e60ba7d7ea367693e622ef5/detection/", "error": "Invalid parameter(s)\r\nTerminates a session.\r\n\r\nLOGOFF [sessionname | sessionid] [/SERVER:servername] [/V] [/VM]\r\n\r\n sessionname The name of the session.\r\n sessionid The ID of the session.\r\n /SERVER:servername Specifies the Remote Desktop server containing the user\r\n session to log off (default is current).\r\n /V Displays information about the actions performed.\r\n /VM Logs off a session on server or within virtual machine. The unique ID of the session needs to be specified.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\logoff.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Magnify.exe-FF2AF01E03CCD707B9DD937E49436F3F": { "file_name": "Magnify.exe", "file_path": "C:\\Windows\\SysWOW64\\Magnify.exe", "hash_md5": "FF2AF01E03CCD707B9DD937E49436F3F", "hash_sha1": "9BC4A22DC2E8931C21B931875A16EC8A94F5F5B0", "hash_sha256": "33FCD1363966AB6478FE5B1061FA5A401BB8BF5C0996A837E1B08FF892393EF1", "hash_sha384": "D274C665D44B43D8FFCCD3EAA5EC08E9AB4F0032F71ED08E051E8C715BD163AC142915B679F2A9DE4E14030474A74EE4", "hash_sha512": "450AA663C3BF7A772E7C5FCFD6E7748BD7ECBDEAD23873E57E1B38927B446EFB792CA5FE27CDD910F646E222C96A3A66800B870319D95D6DDFF3FA760DC4ED88", "hash_ssdeep": "12288:6jeZBV2/droHDy3hAgNEFTt8XOykpyklYx:rZB8/drojy3hAgNYTzykpykix", "hash_imp": "5A38C436F6513FD9B5358A509D9AE21A", "hash_pesha1": "1DBA70A0BF6041D7872994E9F03D48CE0E45684C", "hash_pe256": "07D0CE6DBBDF9C913ADA2D5CE0D74CCD69AA43CF9BD8327A41D4FFBF702625B0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Screen Magnifier", "meta_original_filename": "ScreenMagnifier.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/33fcd1363966ab6478fe5b1061fa5a401bb8bf5c0996a837e1b08ff892393ef1/detection/" }, "makecab.exe-C6C9DD27A824F361E3072AAB962CBA95": { "file_name": "makecab.exe", "file_path": "C:\\Windows\\SysWOW64\\makecab.exe", "hash_md5": "C6C9DD27A824F361E3072AAB962CBA95", "hash_sha1": "7B0BD3D654951E8ACB49BDD13B4D67F7351EC9C2", "hash_sha256": "6FE68E81DA381F3BD1852E18D9223F73D453DD08A9C076B10C3852A1381D802E", "hash_sha384": "C5CA475F8197822B63EE41488F4146257B563650C5F845C04D3BC1C775F56B6141F6502D89652C02492E040DA9B805E2", "hash_sha512": "99CEAFA64687B0A46492180BBECD01DD9386A1483FFA4287DB48168FFD31155C0C854DBD488E4DD0BD9252B140404A643E458DABA9D5860498393E9D0319F783", "hash_ssdeep": "1536:/HETQm8UMt6F0DrDwjM/b6spLZhOVlFeIBDrBP5+hXoL0ghgTtpnIKXUrvoYQYva:/ETQlUMt6F0DrDwjM/b6spLZhOVlFeI+", "hash_imp": "DB419917F8DBA7D951EB3BCBFC2572AA", "hash_pesha1": "9F83586C6C3CC824C234E484FAFBDC0754CD1F21", "hash_pe256": "981929DA01127F83D2220851677B473279AE16D38F644E3564BED2A15805DD89", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Cabinet Maker", "meta_original_filename": "makecab.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.00 (WinBuild.160101.0800)", "meta_product_version": "5.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/6fe68e81da381f3bd1852e18d9223f73d453dd08a9c076b10c3852a1381d802e/detection/", "output": "Cabinet Maker - Lossless Data Compression Tool\r\n\r\nMAKECAB [/V[n]] [/D var=value ...] [/L dir] source [destination]\r\nMAKECAB [/V[n]] [/D var=value ...] /F directive_file [...]\r\n\r\n source File to compress.\r\n destination File name to give compressed file. If omitted, the\r\n last character of the source file name is replaced\r\n with an underscore (_) and used as the destination.\r\n /F directives A file with MakeCAB directives (may be repeated). Refer to\r\n Microsoft Cabinet SDK for information on directive_file.\r\n /D var=value Defines variable with specified value.\r\n /L dir Location to place destination (default is current directory).\r\n /V[n] Verbosity level (1..3).\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\makecab.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mavinject.exe-CB3E03CBECB798CE4254E1D17716C623": { "file_name": "mavinject.exe", "file_path": "C:\\Windows\\SysWOW64\\mavinject.exe", "hash_md5": "CB3E03CBECB798CE4254E1D17716C623", "hash_sha1": "3AA7EFE5F35150EF44AD9DB0690AF0FABFD80983", "hash_sha256": "784BBC33E7DB4BB5B680BD22EA330B094884A639CD156ADA576A45DC85F92174", "hash_sha384": "D5A3CCAD06F419A1400F87355C85C36BE74E8701633F21A87B61C85A81EFAF9BB96AD4E2675AB6C5B44690D0F09F5B3C", "hash_sha512": "60359D5281F41FF2383992AB5B3728D352D8C4E5460B08CC878B54C37E5B7B34843E18C5905D958063016317C55296F1C3F3A5C35354B56B4C08203EC6628D3B", "hash_ssdeep": "1536:J7xsb7M5mTGDRbNubo7yfkgG6W4fXSoDEnAkbGwCL5AQcGjAnmtphoYccIivRhWt:xr5mmt0fSoD7RcG1phR/vGDNhLcRX8dt", "hash_imp": "AB78DC0C35824E888F988515C11197D6", "hash_pesha1": "85D761758F52A58214E2FC3555DDF5D4083916CF", "hash_pe256": "47325FE0FDFCD287FD8114CB19812DCB2A9FBA5707BE35495FB05E2587B07A31", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Application Virtualization Injector", "meta_original_filename": "mavinject32.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "mcbuilder.exe-FF7CBBE1BCCE1AACD427DBDEABC5E00F": { "file_name": "mcbuilder.exe", "file_path": "C:\\Windows\\SysWOW64\\mcbuilder.exe", "hash_md5": "FF7CBBE1BCCE1AACD427DBDEABC5E00F", "hash_sha1": "4C41E8DB7B53D55B18C764EC38E0F0C3E9D37F6B", "hash_sha256": "6C608704AAD806F7E3D6E821E2745EA82530E756215F8BA39662245D57A04A47", "hash_sha384": "E7DC087964349376018A6E61231BA3F56E7BC60A4AC8E3C7DDD27B5F2B3D73F8EC4D20CE6501724BCD220C298A0DFD29", "hash_sha512": "AD14FC9F6CAE01C5DABA4DA9E473944339C6F86453472EFD667DD326A8FEA2B8AC389F88332694DF09E5B4AAA66097FAFD40D8533DE1F02397ABC446FA8D9DED", "hash_ssdeep": "1536:8k0hBmMsWjcdISFZ2fY1DWgFZCmj88+Tnvb9hQBscHiRUE+w82Qu6tUQkv/:IBGISFxtFZCM5+HkBscHiRU7w8RtUdv", "hash_imp": "2E830BAB4715B9FEFD4EF5EE59008A0A", "hash_pesha1": "9E1D2D513D936E18F9EBE4FE4E54232E5B6EE078", "hash_pe256": "06E1848F261DA0CA5006625E4FEF40274454A3D4CBE41008BE5498340F3B860D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resource cache builder tool", "meta_original_filename": "mcbuilder.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.719 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.719", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/6c608704aad806f7e3d6e821e2745ea82530e756215f8ba39662245d57a04a47/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mcbuilder.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mfpmp.exe-C8A5F9BB0304ECB5FCE4BA58B39D9D58": { "file_name": "mfpmp.exe", "file_path": "C:\\Windows\\SysWOW64\\mfpmp.exe", "hash_md5": "C8A5F9BB0304ECB5FCE4BA58B39D9D58", "hash_sha1": "F9042C21296752358692231AF27DA890324DA578", "hash_sha256": "40AE510AE126FE5775904851384EC91D53D5F97232ABB7FA723D19767BC88AA6", "hash_sha384": "395060E5ECF9C40E13F2E8C4F1CA760678DBF4EF23F3145FAC428A1F59CF706C6EB15875CEDBD17BB1E485D521CD5D4B", "hash_sha512": "5C3793D99E1DBDFCE2701885C47B48D027312D8D392F1AD8AD9FEC3A5DA19B3CC6C808978A1EE06115EA2BAA54586055D3B7EEFF6206EBB8574413E96831856E", "hash_ssdeep": "768:RVfigZdCi1Ml7ag5ImoUgeR0XqwEFPBqMwXj1PaHP:RhhKi1MleBmoU0zEFPBqTpP", "hash_imp": "1400817A8D5E718385972C7F4D671ADD", "hash_pesha1": "DA56BD3FBCADED4D1A779E050CE6760D05D606EC", "hash_pe256": "9DADDB3CDC696632540CEB980B2A77E8F44EE34012ABB0FDF370EA8E83E961A7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Media Foundation Protected Pipeline EXE", "meta_original_filename": "mf.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/40ae510ae126fe5775904851384ec91d53d5f97232abb7fa723d19767bc88aa6/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mfpmp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mmc.exe-08CA3F1D18A0B8F55098C3940AFD088E": { "file_name": "mmc.exe", "file_path": "C:\\Windows\\SysWOW64\\mmc.exe", "hash_md5": "08CA3F1D18A0B8F55098C3940AFD088E", "hash_sha1": "9767ED8E2F8281A8FB97412B01FA852D8217CCAF", "hash_sha256": "8A0DDA9BE75167FCA4094CA23B2091E78A9E690EF3A584E815048BA9DB24AFFD", "hash_sha384": "B3D6A7E66D6DA3EEC7131EC1002FC3510E5956C7EA2D33C4AA86CA3D4CDD01E2ACE96BFD4A94E21E9DB542E9311E23A7", "hash_sha512": "94219C6143FEA5BAF6F0E38FC8C8F099576A0C884FFE1AEE7C426EAE147ECDE3AA57CB8A883018DB03578714CB4EBEC9B390E295537B68745325C76D84626378", "hash_ssdeep": "24576:lrvfwg1B79V2fSiqr39cUbMo7wMo7DH7UBwOstnLjqW:Bw6WK7e7DH7rPnvqW", "hash_imp": "7DBDBB686BA1917B8DEC4BF0D54883CB", "hash_pesha1": "8C2B98A1B51B3FCB12564095B043C33AD862499B", "hash_pe256": "EBD1B07D5F31EC17E111FD8C7B1159189BE67C72E3CA7E4C51D74D98515BA196", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Management Console", "meta_original_filename": "mmc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/8a0dda9be75167fca4094ca23b2091e78a9e690ef3a584e815048ba9db24affd/detection/", "children": "mmc.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mmc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mmgaserver.exe-7B5446F0EADE402E15716F7EAE1DA8A9": { "file_name": "mmgaserver.exe", "file_path": "C:\\Windows\\SysWOW64\\mmgaserver.exe", "hash_md5": "7B5446F0EADE402E15716F7EAE1DA8A9", "hash_sha1": "B9A2307175DD3D9E63524D2002FF4992A9A7A470", "hash_sha256": "B8375160593C224F2CACDD8D3C97A5B320AC0A9EC6E75CFCB2D2FB76605F4A1F", "hash_sha384": "34E2038DDCAC9A4A19E4B16019B03A08DDE84A36520843FCE1B459F3592AAFA88F1F6CD2713C7018C62A5C0C6796EDA5", "hash_sha512": "5C9116DC3D08D6E555AD84C5F85D379885D703DB8698193A4770407074B80A9F07F72A9F71D8E35325ACAB24843A0B80AFA607DCDA5DA0BB6717327C7A3A55DE", "hash_ssdeep": "12288:2nD9/Y3kJ/TcrDgjVPawkofUH66nd9Xd/iITvD71TK:2nD9/Y3G/TjFawkooBt/zTvDh", "hash_imp": "6D77288AD3092D9EA00C60EE64F6EC9D", "hash_pesha1": "3F02285712A9B40763D61829648AF3A3CE727F38", "hash_pe256": "683D9DFBE6F369017BE50F3EE098F5AEDC986E76161DBDF3238C0F98CC4643B8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MMGA Server", "meta_original_filename": "mmgaserver.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/b8375160593c224f2cacdd8d3c97a5b320ac0a9ec6e75cfcb2d2fb76605f4a1f/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC720": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\mmgaserver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mobsync.exe-C35C45414482512BB45D6DEE14BCA942": { "file_name": "mobsync.exe", "file_path": "C:\\Windows\\SysWOW64\\mobsync.exe", "hash_md5": "C35C45414482512BB45D6DEE14BCA942", "hash_sha1": "836EB0919F0F4E0CBB5D13CB698F8C302B20AFE3", "hash_sha256": "A584B2DD163DAABDC51F9E41AB3EF154B3E880D17C06DC3FDAFD62FC6E266C4F", "hash_sha384": "8B9381322CF61C534BE1A833C4CFA2BC620269762747F6C39B9518DB970FD2681954571BBB832938601B0AF981FEDFCE", "hash_sha512": "141213B488387070812067C15EE9BCD904350DD3C98A7B36C7B3EF3E67F27EE147A901C218C1DEDB7F7B07D43A8EF46D2A934267C19B86CCC3E516FAE160CBD3", "hash_ssdeep": "1536:lep3oQsgy4T9ZqEpGPoCGVjGWmt8CXZ+63x+w4JD+0NL+fK:sGqyMPpGPo9St8WHxSD+09+S", "hash_imp": "B4668B610D5FA04C01B79CE854744B5B", "hash_pesha1": "299E9C6AEA8C708534BB1179DFCF479A7D78D586", "hash_pe256": "7D410F6AF44F504CF9D1B7E2B3DFF3111D27351339871BDE6A8E9C8A4984025A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Sync Center", "meta_original_filename": "mobsync.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/a584b2dd163daabdc51f9e41ab3ef154b3e880d17c06dc3fdafd62fc6e266c4f/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mobsync.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mountvol.exe-15AA34D64152527D4542546C3CFAC9A9": { "file_name": "mountvol.exe", "file_path": "C:\\Windows\\SysWOW64\\mountvol.exe", "hash_md5": "15AA34D64152527D4542546C3CFAC9A9", "hash_sha1": "4C7A7DE6005873D751C942671EAF7B4B50635452", "hash_sha256": "3408B443926447C03A7575C563163B8E9ADF54AAE9F4FAD959A4A61D588FA234", "hash_sha384": "079A6267617262F1C837C9DAB84D2A291B2E6DC379172D2B35FCB1DA958396256EEAE58ED8711EB9FE1FA5B1F29FBCED", "hash_sha512": "926341DEC7FBF72519B58E92A76BAA125D1AEC9EE58BE294E0D2014BAD8334C3AD9B91940D804121C6F3FCAD22B144E46B376D5655A258E75059B9B529B6BBD6", "hash_ssdeep": "192:/lI1xnAe4RQEXUbgOW0xDAGpfO2cjt9aO0uUOxPtLHwI7ER2NuzkkWQFWfK+:/sGUEOWgAG1OtGO0YxVLQIXNuIkWQFW", "hash_imp": "30F2C65A9103A7536B77118A741917B8", "hash_pesha1": "89037692831A333ECFE83B1AFC3D87E5AE107B20", "hash_pe256": "6162604C611198C68377DD4FB97E71ED68B5F59BCD9A32AD51A5A59AD27FE1C8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Mount Volume Utility", "meta_original_filename": "MOUNTVOL.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/3408b443926447c03a7575c563163b8e9adf54aae9f4fad959a4a61d588fa234/detection/", "output": "Creates, deletes, or lists a volume mount point.\r\n\r\nMOUNTVOL [drive:]path VolumeName\r\nMOUNTVOL [drive:]path /D\r\nMOUNTVOL [drive:]path /L\r\nMOUNTVOL [drive:]path /P\r\nMOUNTVOL /R\r\nMOUNTVOL /N\r\nMOUNTVOL /E\r\n\r\n path Specifies the existing NTFS directory where the mount\r\n point will reside.\r\n VolumeName Specifies the volume name that is the target of the mount\r\n point.\r\n /D Removes the volume mount point from the specified directory.\r\n /L Lists the mounted volume name for the specified directory.\r\n /P Removes the volume mount point from the specified directory,\r\n dismounts the volume, and makes the volume not mountable.\r\n You can make the volume mountable again by creating a volume\r\n mount point.\r\n /R Removes volume mount point directories and registry settings\r\n for volumes that are no longer in the system.\r\n /N Disables automatic mounting of new volumes.\r\n /E Re-enables automatic mounting of new volumes.\r\n\r\nPossible values for VolumeName along with current mount points are:\r\n\r\n \\\\?\\Volume{7c775138-0000-0000-0000-100000000000}\\\r\n C:\\\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mountvol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MRINFO.EXE-ECB0A294338EEF33EBC9F036A2B2FD6A": { "file_name": "MRINFO.EXE", "file_path": "C:\\Windows\\SysWOW64\\MRINFO.EXE", "hash_md5": "ECB0A294338EEF33EBC9F036A2B2FD6A", "hash_sha1": "3FB50537FB008A27B92CAACF0C5251BE9E6280A0", "hash_sha256": "7442C2AD1EB752832FB6D4F6AD0E66C8163A055D27CCF894F65ADB8441D4F2D2", "hash_sha384": "F7AFB386266DE5BB09FBEECCCE0B92FDA1D86FB4D70B14294C6D9B9D0FC26E46A96AC9F66E6EB62309B28F3EE160215D", "hash_sha512": "E69CDDC46FFF47BFFAD50AD43F1BD5EA55A18B33E0DA4E414F211F0411DF095226B832FBE2D20822BF55D15FBB78F742D5A3FE2864C916FD516594B3F9A5C432", "hash_ssdeep": "384:ZyokBIlWjwAIY39p0pT2pQ/kMfbP3B8WJ8WgUA:ZylBIlc0EHASpykMfLBTa", "hash_imp": "190D14EA18A077D297455C1871A8223C", "hash_pesha1": "6C5D7201258C739AA5928A768C8870DF60AEB908", "hash_pe256": "3EC5374C07C0B2B71F32DD4BD71D8AD83EC3AF44FD9F33DC6414449D3809F8C1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Multicast Information", "meta_original_filename": "mrinfo.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/7442c2ad1eb752832fb6d4f6ad0e66c8163a055d27ccf894f65adb8441d4f2d2/detection/", "output": "\r\nUsage: mrinfo [-n?] [-i address] [-t secs] [-r retries] destination\r\n \r\n -n Display IP addresses in numeric format\r\n -i address Address of local interface to send query out\r\n -t seconds Timeout in seconds for IGMP queries (default = 3 seconds) \r\n -r retries Number of extra times to send the SNMP queries (default = 0) \r\n -? Print Usage\r\n destination Address or name of destination\r\n\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\MRINFO.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "msdt.exe-4EBC38519675FB0BA6915D0D8A7FCD01": { "file_name": "msdt.exe", "file_path": "C:\\Windows\\SysWOW64\\msdt.exe", "hash_md5": "4EBC38519675FB0BA6915D0D8A7FCD01", "hash_sha1": "6C2D11F171754B07FD1975E36B828CDD9A3027A4", "hash_sha256": "1BE8AFD2962596807611E6A8836952D6BBDC24BDE52A34905006FF78F1AD5D12", "hash_sha384": "50B0CCE6BCB2F7489B7CBE74625E15CF2F9A6AC66885EE68C538CE3AA57522F7BAB842087ACA56642177A919BF6505E0", "hash_sha512": "88E41AE4A7D82BD885FBD6619541B5D7558BADB6AA683CB4B7CA702A6283353C3C936C8E6BE3C9AB7AC43727135A690C245C9945D1AF5775736D4B5DF1948E33", "hash_ssdeep": "24576:PZMSufiUbtkQw03V3hfi6XH4qvIReK1odddGdBnyE0k26kVZnBm4F:GLw03wqNK7utRB", "hash_imp": "AF42CCE29BF30BC07C0496AF0420FD91", "hash_pesha1": "2E806266A61D1986FC2D2B6ECAB55C11B69BB67C", "hash_pe256": "42DE31905CAC03C74062ECDB8730DB640FA62ABDDDCCE2DB80DA914E05438603", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Diagnostics Troubleshooting Wizard", "meta_original_filename": "msdt.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/1be8afd2962596807611e6a8836952d6bbdc24bde52a34905006ff78f1ad5d12/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\msdt.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(---) C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2\\msdtadmin\\_B8AF5F4E-2B52-467E-AEDC-CDEF437D5F4F_\\inuse": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\oleaccrc.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\msdt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "An error occurred" }, "msfeedssync.exe-E5DAF79825C26A4B30977F99EF3C586B": { "file_name": "msfeedssync.exe", "file_path": "C:\\Windows\\SysWOW64\\msfeedssync.exe", "hash_md5": "E5DAF79825C26A4B30977F99EF3C586B", "hash_sha1": "7CCE795933C950BA9780D5F412148ACDF54504D7", "hash_sha256": "FF2144014012A9BDEB2F2E1775BA18EA0810CFA2771CFDC9BC075A2E3716C219", "hash_sha384": "3A6AAEE7DF51E0D61B746152F13B048B6F1D1D0B6B471A250C7DE3898CA55B83480803A5661086179B6249E1BE0EF3B4", "hash_sha512": "F258341EF0E88324AAD807968572CA9C29F970BB73CF13213135026317580F4FF416E0461828FCC27B58A0EE0726E43BE9243590AEF34CC3DAF22C7D2D7305A4", "hash_ssdeep": "192:Iu6hgnIpf3E4CAjSUb+lDAB808qmqObZDRM/2mdopWcsHMhQY8:IbSnIhFCgFb+2imqbZDC+PpWcsHQQV", "hash_imp": "DE0A5745C03122C45CEE6351F40B8247", "hash_pesha1": "1211E82F7D9EC1C2B20CC2847852FCE2AE60D03B", "hash_pe256": "6DD93302ED26A79287E82CD510FBA886092813CF742F91003A74164FFB02DFD2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Feeds Synchronization", "meta_original_filename": "msfeedssync.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/65", "filescan_vtlink": "https://www.virustotal.com/gui/file/ff2144014012a9bdeb2f2e1775ba18ea0810cfa2771cfdc9bc075a2e3716c219/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\msfeedssync.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "msg.exe-B7284CED7C87668BA2676AF020C00970": { "file_name": "msg.exe", "file_path": "C:\\Windows\\SysWOW64\\msg.exe", "hash_md5": "B7284CED7C87668BA2676AF020C00970", "hash_sha1": "3844D23A6B08076BFD86C26655690129C5D1C6B9", "hash_sha256": "BCDD7F71B81BB24F6DCC0DDDA5280E2DB3E268CD8E0EE869B7DAA768F1DB7438", "hash_sha384": "9ECF1BFC9533974AFA9B8367C2C7E1F0B95E3CFF51D00609E18B40948F503C6C4475BCE4FB73E18BBED3DDAE50AF7C60", "hash_sha512": "81964618F0A01A3B2C2613CCD3D50DEBFB2D95E141C7DDCBD368254E31ECB1D2548F13CCA041B42914117B6A407D4765C52AC89AF54193E1778C4C10E62448BE", "hash_ssdeep": "384:NrZ4yzjcon07xz6E//Y1SFRxXFuL3CcwKKeDoPYLXyqW4UWZz3:9Z7jcoMjNHXF9cpoPD0L", "hash_imp": "E0786872A185609E8E4F301D75F409EF", "hash_pesha1": "E9F361D65D1080559C0B175B3ED600D174FF5D22", "hash_pe256": "A909AD0EC94B056BB6A530B2D5E0F7CC6353C3A2E31D8FA053668861CFAFE4AB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Message Utility", "meta_original_filename": "msg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/bcdd7f71b81bb24f6dcc0ddda5280e2db3e268cd8e0ee869b7daa768f1db7438/detection/", "output": "Send a message to a user.\r\n\r\nMSG {username | sessionname | sessionid | @filename | *}\r\n [/SERVER:servername] [/TIME:seconds] [/V] [/W] [message]\r\n\r\n username Identifies the specified username.\r\n sessionname The name of the session.\r\n sessionid The ID of the session.\r\n @filename Identifies a file containing a list of usernames,\r\n sessionnames, and sessionids to send the message to.\r\n * Send message to all sessions on specified server.\r\n /SERVER:servername server to contact (default is current).\r\n /TIME:seconds Time delay to wait for receiver to acknowledge msg.\r\n /V Display information about actions being performed.\r\n /W Wait for response from user, useful with /V.\r\n message Message to send. If none specified, prompts for it\r\n or reads from stdin.\r\n\r\n", "error": "Invalid parameter(s)\r\nSend a message to a user.\r\n\r\nMSG {username | sessionname | sessionid | @filename | *}\r\n [/SERVER:servername] [/TIME:seconds] [/V] [/W] [message]\r\n\r\n username Identifies the specified username.\r\n sessionname The name of the session.\r\n sessionid The ID of the session.\r\n @filename Identifies a file containing a list of usernames,\r\n sessionnames, and sessionids to send the message to.\r\n * Send message to all sessions on specified server.\r\n /SERVER:servername server to contact (default is current).\r\n /TIME:seconds Time delay to wait for receiver to acknowledge msg.\r\n /V Display information about actions being performed.\r\n /W Wait for response from user, useful with /V.\r\n message Message to send. If none specified, prompts for it\r\n or reads from stdin.\r\n\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\msg.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\msg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mshta.exe-4DBAFC3C0B7A9CAA67D6C2C3D99422F2": { "file_name": "mshta.exe", "file_path": "C:\\Windows\\SysWOW64\\mshta.exe", "hash_md5": "4DBAFC3C0B7A9CAA67D6C2C3D99422F2", "hash_sha1": "EE1ED6AEA892E2ABCFA64D9D51078EFDFAEA6253", "hash_sha256": "12C94C614FB752DC1F6797B5FB3AD67719E3C924FACDA35DC36792C8E5AC45FC", "hash_sha384": "4E809BF993545BEF678851E4486BB28B122543E73CC615558CDA8856490E132E78C481B5F8DF11F9B8DFC8FFB36BFE5E", "hash_sha512": "AE72B05AC175E15A4EF0FC9353D031B6F57ACBF788688EAB22FFFB617B1DDBFA7AC13C91AE9D5025172ED60350B5139A4E315CD3CC3271678B421C58BB3F29F8", "hash_ssdeep": "192:e9Ca8YZgW7N6rSp8/DJgoneEFDBWwG/IR:XkN6rSp89RvnWwG", "hash_imp": "4CB8A74361E70A5FF774A0A1A7C65989", "hash_pesha1": "52D29298610B53F01F3E6D5740B2DDB834D09A02", "hash_pe256": "2305A037E747BEBF21D71D62B5B8A0331EA49BFF89FF4AECBD671560EF67A3F6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) HTML Application host", "meta_original_filename": "MSHTA.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/12c94c614fb752dc1f6797b5fb3ad67719e3c924facda35dc36792c8e5ac45fc/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mshta.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "msiexec.exe-747C6064888F11F5431B34A422780650": { "file_name": "msiexec.exe", "file_path": "C:\\Windows\\SysWOW64\\msiexec.exe", "hash_md5": "747C6064888F11F5431B34A422780650", "hash_sha1": "B54CE57731B58A49800EFA31894DDF6AB6B6A4F4", "hash_sha256": "64F5BABD1B013CB35CA489AF2531203261FA0B05A70A77FBC0A3D53ABFDC8CAB", "hash_sha384": "CF1AA47FC3C7EFA673919E1943AAD885AD4B660BE8BC5495C21C6F5C43865A3053A1094CD7C956CD194FABBBE8F62542", "hash_sha512": "DB3144910DD257E1C473EBEB64A56E5A753CEC431089799C9F4C0DC3C2F4880678B7C2D4561392505EC884B300AB62D7546195BA3CA5563A02B9CC07F46EF522", "hash_ssdeep": "768:No8HL2TB4LH97PQtGNSNuuNELvInbOv8PAZWmDXIMLXq6CAy/Cc:sTB4LRPOF5ELw81b4MO6bc", "hash_imp": "E4E40938E4BF6C66424859ED02171C41", "hash_pesha1": "CF7159A88CB19AF6DC9991704B9EEA3301814AAD", "hash_pe256": "62BE64C470C51D3CF71135E25C2F83D3DE7BEF31D111E0528D2013537FBAE5CB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows installer", "meta_original_filename": "msiexec.exe", "meta_product_name": "Windows Installer - Unicode", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.0.17763.404 (WinBuild.160101.0800)", "meta_product_version": "5.0.17763.404", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/64f5babd1b013cb35ca489af2531203261fa0b05a70a77fbc0a3d53abfdc8cab/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\msiexec.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\msimsg.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\msiexec.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Installer" }, "msinfo32.exe-F589A0D3F0DA328F90A2A9556EF513B5": { "file_name": "msinfo32.exe", "file_path": "C:\\Windows\\SysWOW64\\msinfo32.exe", "hash_md5": "F589A0D3F0DA328F90A2A9556EF513B5", "hash_sha1": "CA714A87F2DB9B17DE10095713748425076CCBDE", "hash_sha256": "9D9EFB1655826BC2CC5F0767C2F461BBE6D8E743113EB6B396B5966740373DEC", "hash_sha384": "D8ABCEC2963AD3AFB9067023D10F542F9D3D4C4C7E6E81C374DE24B420FC603760D92E197179C891B2BC96830FDFA952", "hash_sha512": "09F769849517095A491217E5BA65F39F9BD6056BA0C71D6DA82BCE00BFB63ACD1D8088C73A54E51D8D37A9C9C89A7141A65F663FD5728C3BA50AEFFD1660E09F", "hash_ssdeep": "6144:uHJ3+9UJO4va8O8Qu0dIlUD7Drj7jmyh27ZEOHHrpm1XUZLxEZEOHHrpm1XUZLxO:uHJ3+9UkMOG0dIlUD7Drj7jmJFtLpm1G", "hash_imp": "72E2900DB084B32F54B445BDE1B7E0E8", "hash_pesha1": "13B28A68CD8D2EBF25F62EEAF92B3AE553DEFD4A", "hash_pe256": "73CCA4A2956F6225504501A9E49648AF62D0E6B2E87A6B574C23F1200F7DC1EA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Information", "meta_original_filename": "msinfo.dll.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/9d9efb1655826bc2cc5f0767c2f461bbe6d8e743113eb6b396b5966740373dec/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\msinfo32.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC13FC": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\propsys.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\msinfo32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "System Information" }, "mspaint.exe-7598568851B293CD82E958C3B9735F7C": { "file_name": "mspaint.exe", "file_path": "C:\\Windows\\SysWOW64\\mspaint.exe", "hash_md5": "7598568851B293CD82E958C3B9735F7C", "hash_sha1": "1585F1047546B6162D8A9ACCA9599BF92EF31986", "hash_sha256": "C6CA40EFB55F70C704B7686DE8FF1DB7CC9B1C8DFE1754CB046F77DF73D99FB4", "hash_sha384": "A4F69FEEA2765C7EC764DCACEF8311BDEF5F65C1DFE4A25CDE14021A6D19F6F2C34CF7FE136E18D49AA538FA53648CB5", "hash_sha512": "D2DBC87814E8ADF1C2E166D3D34C35F967ECEF292871126BFEE4DDD357D6487BA34C4451C2F9C5D51A6ADB91831F8A34C2DDD155EE29FB396037BC92FE55F43E", "hash_ssdeep": "98304:0mHdN2u7InCOgQwyRPM1mlawYL260GBGrGrGWAub7jPhivQv:0mHdN6n/gQw4MIlawYVb7jP8vE", "hash_imp": "3733CF0F57E520DAEA85AF65FAF8D8E3", "hash_pesha1": "CED507FCFF5F47A3CEED41EA7B5FE9D5B37E5393", "hash_pe256": "85A1262C9E590D2DF1767E9DAE9447DA37B4A30220D269B95C25869B3CAED048", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Paint", "meta_original_filename": "MSPAINT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c6ca40efb55f70c704b7686de8ff1db7cc9b1c8dfe1754cb046f77df73d99fb4/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\mspaint.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_5706558cc25cc83b": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1084": "Section", "(RW-) C:\\Windows\\debug\\WIA\\wiatrace.log": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\UIRibbon.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\RotHintTable": "Section", "(R--) C:\\Users\\user\\--help": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\mspaint.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Paint" }, "mstsc.exe-8E986D439CE87C13F6A40F38C6B494B2": { "file_name": "mstsc.exe", "file_path": "C:\\Windows\\SysWOW64\\mstsc.exe", "hash_md5": "8E986D439CE87C13F6A40F38C6B494B2", "hash_sha1": "2921E4B1D8452A208331D1AE1D818D3103D6DEF7", "hash_sha256": "280F1F1B21D6A8A6607E43B66AE528B1EB80E187E2ED3FF954A046C9EB6A23C2", "hash_sha384": "997903A8FD1F8485424872DD6CDD774C3517222B936814ACA4AC763782367D645B2B574E2CA98BC0F565D8772223B662", "hash_sha512": "C886956A861B5E07F834F16C70853856C989CBAB55FA5E6E8437AC159C61FA1B419906D9DA954FBEB57F456043FBCA5955AB00C08783717AB8EB0C31E94F4283", "hash_ssdeep": "24576:rN0/uZQC57AknPDqr849hYeHmh9HunnB8bGGkN/2OotOFbLpwC5Krz7OikYv3hTa:CGZ/c31NOOqO9LpwCn0xfpMg1KLJ", "hash_imp": "58767D53A8B8A06E41CC8FE52FAD6560", "hash_pesha1": "48B01F1673E098C2BF7CF05B501C27015401FB98", "hash_pe256": "521F423BE69CD2317DFDFEE8653DCE124890E50B2DEC932D158A751EB51BA939", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Connection", "meta_original_filename": "mstsc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.404 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.404", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/280f1f1b21d6a8a6607e43b66ae528b1eb80e187e2ed3ff954a046c9eb6a23c2/detection/" }, "mtstocom.exe-2227FB3085739C8160A279D4047FAAB0": { "file_name": "mtstocom.exe", "file_path": "C:\\Windows\\SysWOW64\\mtstocom.exe", "hash_md5": "2227FB3085739C8160A279D4047FAAB0", "hash_sha1": "68665DCE5373F7F109998C1CE666F4778C930F67", "hash_sha256": "A278EAB3C60F800FE4155A69147FA6F491B3DC021B83599A035B9C77D29096B5", "hash_sha384": "A8201339D9B7A1A12EC27C00BBE1B33469F7E6DA18EE7FF0223577CE56303F88D790A656FE8FD1CD81E9E2F25FAED4B5", "hash_sha512": "ED1728D3BE9C0681A261AAEA9AA73496B6B7F67B4C1CBE2F282FBEB691AECFECE7E66FD4E7A61D1458E89AA424E5D26F85DC88644D8EE2DDA24C6BC4CEA22A64", "hash_ssdeep": "3072:zu2CaqNCjbW2bgtHohPBYiu2mXT00QB3X13SM:q1rNCjBPBYi+XT00QB3XNSM", "hash_imp": "AB1CFC2F34980AED9F6C3FE4199906D4", "hash_pesha1": "EAA359CFD401EF7973B74660795C14499A756B20", "hash_pe256": "A8239CB04A1D5CA51E7AB7C773895A96ECA3BBBA803EE2597A793C424384CAC4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+", "meta_original_filename": "MTSTOCOM.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/a278eab3c60f800fe4155a69147fa6f491b3dc021b83599a035b9c77d29096b5/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\mtstocom.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MuiUnattend.exe-8DD6ADB6C17242CB24F14B72B41F1F0B": { "file_name": "MuiUnattend.exe", "file_path": "C:\\Windows\\SysWOW64\\MuiUnattend.exe", "hash_md5": "8DD6ADB6C17242CB24F14B72B41F1F0B", "hash_sha1": "6EE76E10112197D2645B6945DC7EF502A75646CB", "hash_sha256": "43408CD5855C5ADF95258DF630279F32BBF92396A1508984C412E8B54E865192", "hash_sha384": "321EE77FFB5FD6D2E613739CF76F4524D1EEDA241345569B2F15E1E806FFCABE6D9FB394BD35E55BE2BA1B7351BC40E5", "hash_sha512": "6DDC0B3723A3511170EB96D0B91F2CD0D376887E4D759B02118BBB13D3F324691C7539289A772CC9B84D2EB818CADED851C8982D2776BC8EE5EC6BBBC0DBDEB0", "hash_ssdeep": "1536:u9TVHOyjwV/6sV4WXsocqj2EryRr6nnIf8wWjQVfoAbi5hyi0DI0v:KYMUCu4WXsocYhyRr6nIjW0T2V", "hash_imp": "5946C3849822E811886BB76DA4DC44C1", "hash_pesha1": "8E21E4CAE48756E95C4F25F64BA6402744769F5D", "hash_pe256": "2466ACFB1E5A4C80BABA937CB36E247CAEAC4815B34EFDC650E8932E24A321E5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MUI unattend action", "meta_original_filename": "MuiUnattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/43408cd5855c5adf95258df630279f32bbf92396a1508984c412e8b54e865192/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\MuiUnattend.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ndadmin.exe-8126A090A1F30D3C9A42F69D55E7E1EC": { "file_name": "ndadmin.exe", "file_path": "C:\\Windows\\SysWOW64\\ndadmin.exe", "hash_md5": "8126A090A1F30D3C9A42F69D55E7E1EC", "hash_sha1": "3EF2BD44EE4F03ACB674C55D0D4C50414D9FB2CA", "hash_sha256": "3BF9B0D64AFB7250743BD8C5594D76F0DE70373314EDE370FDCDF83ACF929758", "hash_sha384": "DE81F1131334E9B6AAEF885838719D3FBD5AD0BD928F021EB7226483B3B5AF0F22010EBE6CF6B50C63B6B15A2B54D561", "hash_sha512": "48C59922C9E92D95398E451CD1329A6C4ECCE00D121B1412ED6B774874DBF1029444F5B92BFD5C33EB5121BD9850D3EA9692AD5636DC01AE80CCABD1B4BAA706", "hash_ssdeep": "768:3s5V3rJ3OZ0bjQAhtqIrn8+1hrpFIUUUUUUUUUUUUqRcxMhF:3sf3rZxbjfFrGUUUUUUUUUUUU3+h", "hash_imp": "402F875FFA8D12465311E99FF1B64065", "hash_pesha1": "DD106EA1A96BF3FD51D0BE61E328E3B6A77DA7A6", "hash_pe256": "FE09B11F417CAA79846B67AC771C5A2D39E4BF3BD00CD72D70D123975EFC8DB8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device driver software installation", "meta_original_filename": "NDAdmin.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/3bf9b0d64afb7250743bd8c5594d76f0de70373314ede370fdcdf83acf929758/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ndadmin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "net.exe-CB0744AA7ACB8B8A960FCCE3259739EC": { "file_name": "net.exe", "file_path": "C:\\Windows\\SysWOW64\\net.exe", "hash_md5": "CB0744AA7ACB8B8A960FCCE3259739EC", "hash_sha1": "283A91DE102E088E6568A711BAC024BF962D7D25", "hash_sha256": "1FB73D95BD75DCC9734C2586E8D9C5EEA74706786D6AD71523FFC8799817348F", "hash_sha384": "690EFB964FC05B688BFA3BE264FFDE572A12B10738D7236048C299D2F1C34330457F1EEAEF239203F26EFA3101D411D2", "hash_sha512": "BCD4F37C2C21759891A0E24304CBB13AA5246438579F5B3A9D44F10548881D16A0AF99FD7A20AA5117F107D0595F8764F381D7D4083258FBBA92947EB2C35085", "hash_ssdeep": "768:KDSZgXEZQ1jqEnJQItLh+vXvnlRYGX2mpcpcbkYwQZ8BMgnASf:KDS32tTQoAvxpcpcbPBZ8BMxS", "hash_imp": "AC592B83B5CAEB41A6F6DF7DB53F9076", "hash_pesha1": "90983D39CCF90F7558F1DBB3C191D771B2C3D673", "hash_pe256": "5481F3730F676AF5DD9F5EFF89F973B01B1F119C7117D14112102EBEDE5F870E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Net Command", "meta_original_filename": "net.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/1fb73d95bd75dcc9734c2586e8d9c5eea74706786d6ad71523ffc8799817348f/detection/", "error": "The syntax of this command is:\r\n\r\nNET\r\n [ ACCOUNTS | COMPUTER | CONFIG | CONTINUE | FILE | GROUP | HELP |\r\n HELPMSG | LOCALGROUP | PAUSE | SESSION | SHARE | START |\r\n STATISTICS | STOP | TIME | USE | USER | VIEW ]\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\net.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "output": "The syntax of this command is:\r\n\r\nNET HELP\r\ncommand\r\n -or-\r\nNET command /HELP\r\n\r\n Commands available are:\r\n\r\n NET ACCOUNTS NET HELPMSG NET STATISTICS\r\n NET COMPUTER NET LOCALGROUP NET STOP\r\n NET CONFIG NET PAUSE NET TIME\r\n NET CONTINUE NET SESSION NET USE\r\n NET FILE NET SHARE NET USER\r\n NET GROUP NET START NET VIEW\r\n NET HELP\r\n\r\n NET HELP NAMES explains different types of names in NET HELP syntax lines.\r\n NET HELP SERVICES lists some of the services you can start.\r\n NET HELP SYNTAX explains how to read NET HELP syntax lines.\r\n NET HELP command | MORE displays Help one screen at a time.\r\n\r\n" }, "net1.exe-E28124DF01CA79FD93F3B7C48DECDAC0": { "file_name": "net1.exe", "file_path": "C:\\Windows\\SysWOW64\\net1.exe", "hash_md5": "E28124DF01CA79FD93F3B7C48DECDAC0", "hash_sha1": "EB3293C3DFDCEA9696269CCA0BA5714B2F16DC6C", "hash_sha256": "383ECC5DBCDD98163C556CA6E4486C5DC6A35C3F1CFF88DCF12DA2CDABA80970", "hash_sha384": "02E8F8479D921EF39667894096F09F6CA3F6CA6CAE3A32934404C474CF767202917D558C3E14BC228C34C379478C5586", "hash_sha512": "4CDFF4E09CF438A31D9F87EEF5DC210FA04ED484BE98EFF936B7143CF95366839BC7D6A08A24F12468F0ED4653BDA35148D40C0CDD3A52E4316E84913E94A4E1", "hash_ssdeep": "3072:y19tv9wWaaI15Ya6iFj2clpulGOKzHB5wvF:e9tvOWKf6iFj2clpusOKzHBSvF", "hash_imp": "F44A3CB56AC156111E03B2437FC54F18", "hash_pesha1": "C258E358308B9BE18D0801D6842BC2B6019C840C", "hash_pe256": "E7B72370B418F73C7F68715FB57CC6CAFA4FAE859CB576956F208612F6032537", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Net Command", "meta_original_filename": "net1.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/383ecc5dbcdd98163c556ca6e4486c5dc6a35c3f1cff88dcf12da2cdaba80970/detection/", "error": "The syntax of this command is:\r\n\r\nNET\r\n [ ACCOUNTS | COMPUTER | CONFIG | CONTINUE | FILE | GROUP | HELP |\r\n HELPMSG | LOCALGROUP | PAUSE | SESSION | SHARE | START |\r\n STATISTICS | STOP | TIME | USE | USER | VIEW ]\r\n", "output": "The syntax of this command is:\r\n\r\nNET HELP\r\ncommand\r\n -or-\r\nNET command /HELP\r\n\r\n Commands available are:\r\n\r\n NET ACCOUNTS NET HELPMSG NET STATISTICS\r\n NET COMPUTER NET LOCALGROUP NET STOP\r\n NET CONFIG NET PAUSE NET TIME\r\n NET CONTINUE NET SESSION NET USE\r\n NET FILE NET SHARE NET USER\r\n NET GROUP NET START NET VIEW\r\n NET HELP\r\n\r\n NET HELP NAMES explains different types of names in NET HELP syntax lines.\r\n NET HELP SERVICES lists some of the services you can start.\r\n NET HELP SYNTAX explains how to read NET HELP syntax lines.\r\n NET HELP command | MORE displays Help one screen at a time.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\net1.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "netbtugc.exe-0CE2A67BCA66F75C65DC6FD76B29184B": { "file_name": "netbtugc.exe", "file_path": "C:\\Windows\\SysWOW64\\netbtugc.exe", "hash_md5": "0CE2A67BCA66F75C65DC6FD76B29184B", "hash_sha1": "A76FA33487AEEE6EB6DF363EE386F361A91325B5", "hash_sha256": "040377CD45A4E0540FC5C3D4850CB01072D6668750E1379392E884E500748B69", "hash_sha384": "DEFFD5DF9FC60168B56FA1CCC28DCCDBAA156C74BBAB6B3C3CC4F3FC29CDFA3BC052E5C11A52E29A2F8EC2A7C4AA8D82", "hash_sha512": "3541652FA91D2C785417E7580009F74D0E784F7D125B96AA18A5DD35523F022A45289122B461DA6C002CDFCE53D206247448C3A1ACD558C89D7C3D7DE8398612", "hash_ssdeep": "384:ivj2osEHN3gdeTT8BoMtij7J2goiuaxrmkmDkqQFnME/XW/JFWc:C0eTioXj7JXuUGAqQFle", "hash_imp": "87737AAA79CDA87BE67E0C47B9192C03", "hash_pesha1": "6A3D6474C6F6463FEE12161372F2522980CA03DD", "hash_pe256": "CA824BAE2C16662AE7554C3D8244A515720B3358A3C9CE9A47735E32334B3E07", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NetBT Unattend Generic Command", "meta_original_filename": "netbtugc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/040377cd45a4e0540fc5c3d4850cb01072d6668750e1379392e884e500748b69/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\netbtugc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "NetCfgNotifyObjectHost.exe-D9FD8A8BFAD8EFF4C946A224F488AC35": { "file_name": "NetCfgNotifyObjectHost.exe", "file_path": "C:\\Windows\\SysWOW64\\NetCfgNotifyObjectHost.exe", "hash_md5": "D9FD8A8BFAD8EFF4C946A224F488AC35", "hash_sha1": "113B90D25C15B4C705CEE4AB48164A1FA7E235CC", "hash_sha256": "5F5FD58DD10D655C83F76FB074014E5428C667D1B415E647B44BFCD38183CFB0", "hash_sha384": "AF7DAE3693823D5B44564A1F842E3FCEF040FD1095CE7512C363406E87077295B79AA8C7A0F8EBD316D2A758D6712FDE", "hash_sha512": "BCFC6D19AF9E59443DAFD2D43238300A2454F377D59B0292F571A423D3B8B535E7B132DE47D817D03B591FFB5203F7D5DFF989C4FDF167330E43999755AFB8F8", "hash_ssdeep": "1536:kcSIW3cKNVWankND5okn+GC9NaGu5AL/MPbXDcyJEigM9:ksLCVWakvokn+GC9NaGu5AL/eD1Lg", "hash_imp": "74F2F413E447FF482F844B08235C6F6C", "hash_pesha1": "80EF0646B0EF5F728E6EA844D095EF6FFAA280AD", "hash_pe256": "B9CCAC541F3E460963F5F94BB52DE16E0FABD851F2EF4566E08B75196FC7EC8D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Network Driver Configuration Plugins", "meta_original_filename": "NetCfgNotifyObjectHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/5f5fd58dd10d655c83f76fb074014e5428c667d1b415e647b44bfcd38183cfb0/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\NetCfgNotifyObjectHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "netdom.exe-50A4CAB95BBCED9568016F123AD61CDF": { "file_name": "netdom.exe", "file_path": "C:\\Windows\\SysWOW64\\netdom.exe", "hash_md5": "50A4CAB95BBCED9568016F123AD61CDF", "hash_sha1": "DFCF9A40D8C0ED10D16CE903283E5586016FC64F", "hash_sha256": "1642E1D362A61CD9B943C6229019134E41489E8BFD2B04DD9B50E9DDD80051CD", "hash_sha384": "80B758F577F83C6C1BEE194A12CD1E36216CEE877F1907C76702BA59ECA6A7A0289744A4D68E222D303DF8D2F04BB94F", "hash_sha512": "50C640358D6AF8D067CBD7106650EEEECC91BBBC823DC080933610CF96D05A2C66BC6E9F1294AF5666D6358F2BF0F40D45D517D03ED4163AEA9344BC797854ED", "hash_ssdeep": "1536:Z8rc59d7qaon3CROcoYCcTs3mDRcrEwAIBXaTb0nj0acsILdI42wD4QIskS:Wrc5D3on3CRONnj0NoeD4HskS", "hash_imp": "2675DF3CEA83BE5DF33DD0A04ADAD645", "hash_pesha1": "161441F01DB856F324C1132B87679D11272FB950", "hash_pe256": "E4BD44DB8833B94DAD26BCC2C711A2C3D5BDC31478E85B3CF4609058E30391A8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "NETDOM5", "meta_original_filename": "NETDOM.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.503 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.503", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/1642e1d362a61cd9b943c6229019134e41489e8bfd2b04dd9b50e9ddd80051cd/detection/", "output": "The syntax of this command is:\r\n\nNETDOM HELP command\r\n -or-\r\nNETDOM command /help\r\n\r\n Commands available are:\r\n\r\n NETDOM ADD NETDOM RESETPWD NETDOM RESET\r\n NETDOM COMPUTERNAME NETDOM QUERY NETDOM TRUST\r\n NETDOM HELP NETDOM REMOVE NETDOM VERIFY\r\n NETDOM JOIN NETDOM MOVENT4BDC\r\n NETDOM MOVE NETDOM RENAMECOMPUTER\r\n\r\n NETDOM HELP SYNTAX explains how to read NET HELP syntax lines.\r\n NETDOM HELP command | MORE displays Help one screen at a time.\r\n\r\n Note that verbose output can be specified by including /VERBOSE with\r\n any of the above netdom commands.\r\n\r\n\nThe command completed successfully.\r\n\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\netdom.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "netiougc.exe-0D3601683DDA721BF3CC56119171E2A3": { "file_name": "netiougc.exe", "file_path": "C:\\Windows\\SysWOW64\\netiougc.exe", "hash_md5": "0D3601683DDA721BF3CC56119171E2A3", "hash_sha1": "CAAC552EC5320F823F6E018A7207FDDBFE087D0A", "hash_sha256": "08956005E9902380D46FF6506FBC3A93D0712CA57BFEEAED2CFAE54C52987F4B", "hash_sha384": "80BC1C5E1961EF29C006A24E0C2D4B195F014B1D5815916BA57518307036D3763A7FFF91A8F5C988935AD4F6183C02C2", "hash_sha512": "71DFD625564E4D31BE8D582BBD86669530F9342F4361BCD7E89664C5AF9CD73677529BA529CC11655DCF3A233629A980B96E87E7EA2CBEF91D1E920652E51B2C", "hash_ssdeep": "384:Qx59osEfFMl7qvOTVTBOp/yo1M+Ud6Riz53+93j/3qqEyVWXRNW:Qx5rPOp3W6gz5w3j/3vvo", "hash_imp": "C1C022C4532A6E4423680DF33E606B07", "hash_pesha1": "95CA00C1739116E93048FC7E06F357B10B7F01E5", "hash_pe256": "D76C18EF6D0DEDC8A733BEFFDB5691AC6AFC31A36FF0A6A9B1C4CD7107927852", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Netio Unattend Generic Command", "meta_original_filename": "netiougc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/08956005e9902380d46ff6506fbc3a93d0712ca57bfeeaed2cfae54c52987f4b/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\netiougc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Netplwiz.exe-2CCA5ECF833419FFD7140A4E189C1FC9": { "file_name": "Netplwiz.exe", "file_path": "C:\\Windows\\SysWOW64\\Netplwiz.exe", "hash_md5": "2CCA5ECF833419FFD7140A4E189C1FC9", "hash_sha1": "CBF9CBAE3694B7762ED6DF356CFE4177CF3B11AE", "hash_sha256": "4D65D42A1AF2C1193B6DDDFCC1393E4887CAB79C109103E7B234B518D9001207", "hash_sha384": "7B03ECEC7721B98827F587CF01271CF8A6FCFF9B6F21C206AFBDD34A6332231A84E1A588E2453E4D891A0557FF816033", "hash_sha512": "84C11B24A9636C5A16CE7C2028C9F8AE83D2F34EB27872979C54AC6BCF8605882BE0B1BB818A157E211A0B55BC2E429FE067AFB0FCDB80FF3EA1302F7752EF5E", "hash_ssdeep": "768:PAztekoshSAy7fUrh6WeENiJDBPrxZt4GM:PsyOeWSDBPrxZaG", "hash_imp": "983415DF1D541F291D0E1A1B15A0047E", "hash_pesha1": "723DD223D44421A0566C3647F19179A13E2B61A6", "hash_pe256": "50A9B6663E1881D85AD06BF5959B44903F414B90A00B0CFE3299023833DF4BAB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Advanced User Accounts Control Panel", "meta_original_filename": "NETPLWIZ.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/4d65d42a1af2c1193b6dddfcc1393e4887cab79c109103e7b234b518d9001207/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\Netplwiz.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\netplwiz.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\Netplwiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "netsh.exe-847B74DC766070B0FAD7DABF0B239999": { "file_name": "netsh.exe", "file_path": "C:\\Windows\\SysWOW64\\netsh.exe", "hash_md5": "847B74DC766070B0FAD7DABF0B239999", "hash_sha1": "93F0DBBE81C7ED0343F29879A0E62762A637EC1E", "hash_sha256": "C94D41B92D051C1D7F30FC60196958799B4ACFF3FA2A2CDF8CED9D0B8B42B583", "hash_sha384": "F6D8BA25B3718C15609F4ADB26CF6DF79CB051339B67F18BA466B1DE7258A73383F67ABAD27D894E8EC8FCC1A4277937", "hash_sha512": "2B82E26694F7096379B6BDC4C9DC84DB9B9743330004BD25ABAD489205A61C4AAFA3A9824DC8581EAB8A47F38AC80AA18B2802D65C7DA9FFB987FDCF5F5E2334", "hash_ssdeep": "768:pLsMGla4aMvfv84lJ6TAMO5QZt6ljIbfSotJZy:Zs7p1/8O6DOy3GIbfS8D", "hash_imp": "C8D91522FEEE1152DC40833F6A4717E7", "hash_pesha1": "4414A44A9AA719CEEE1CD50E5BB8ADC659D92280", "hash_pe256": "990D6E2C3869DADD8574957C363B38CD20FFCE2AB41D31D373B118D5C8E1E8E1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Network Command Shell", "meta_original_filename": "netsh.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/c94d41b92d051c1d7f30fc60196958799b4acff3fa2a2cdf8ced9d0b8b42b583/detection/", "output": "\r\nUsage: C:\\Windows\\SysWOW64\\netsh.exe [-a AliasFile] [-c Context] [-r RemoteMachine] [-u [DomainName\\]UserName] [-p Password | *]\r\n [Command | -f ScriptFile]\r\n\r\nThe following commands are available:\r\n\r\nCommands in this context:\r\n? - Displays a list of commands.\r\nadd - Adds a configuration entry to a list of entries.\r\nadvfirewall - Changes to the `netsh advfirewall' context.\r\nbranchcache - Changes to the `netsh branchcache' context.\r\nbridge - Changes to the `netsh bridge' context.\r\ndelete - Deletes a configuration entry from a list of entries.\r\ndhcpclient - Changes to the `netsh dhcpclient' context.\r\ndnsclient - Changes to the `netsh dnsclient' context.\r\ndump - Displays a configuration script.\r\nexec - Runs a script file.\r\nfirewall - Changes to the `netsh firewall' context.\r\nhelp - Displays a list of commands.\r\nhttp - Changes to the `netsh http' context.\r\ninterface - Changes to the `netsh interface' context.\r\nipsec - Changes to the `netsh ipsec' context.\r\nipsecdosprotection - Changes to the `netsh ipsecdosprotection' context.\r\nlan - Changes to the `netsh lan' context.\r\nnamespace - Changes to the `netsh namespace' context.\r\nnetio - Changes to the `netsh netio' context.\r\nras - Changes to the `netsh ras' context.\r\nrpc - Changes to the `netsh rpc' context.\r\nset - Updates configuration settings.\r\nshow - Displays information.\r\nwfp - Changes to the `netsh wfp' context.\r\nwinhttp - Changes to the `netsh winhttp' context.\r\nwinsock - Changes to the `netsh winsock' context.\r\n\r\nThe following sub-contexts are available:\r\n advfirewall branchcache bridge dhcpclient dnsclient firewall http interface ipsec ipsecdosprotection lan namespace netio ras rpc wfp winhttp winsock\r\n\r\nTo view help for a command, type the command, followed by a space, and then\r\n type ?.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\netsh.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "NETSTAT.EXE-1911DCAACF3590CBA64316F3250B0F80": { "file_name": "NETSTAT.EXE", "file_path": "C:\\Windows\\SysWOW64\\NETSTAT.EXE", "hash_md5": "1911DCAACF3590CBA64316F3250B0F80", "hash_sha1": "0C0D47B6F1B9DB018DDDE9ADD8F325806455465F", "hash_sha256": "ACA66F4BC15E1B8EDE8F05F59DFAFB15FA47D9E89EA1D4CF59264BA3D483F47C", "hash_sha384": "0534EDE1327E1C16BA05A1372150EB7E2E865D6859D20434A10C570DA76F9C22788B33CF973EB061E121DE8D888F5131", "hash_sha512": "9DCFC6BE4CB9CDE4B240222F3C20366CC8EDCD17558E3AA6F2F84DC4CE2164BFD3CFDC089810B9E95AA41F35FA38D5916615961ACED61D7BE534B1F357D33B4A", "hash_ssdeep": "384:cS5vXEHf5q3+JwWH2ePKC/Rvnt3uD8r2slOUdAHqiY0tkCJh4gDi9t1WlQWup2:cS5v0xGLyfwIVQr/Y06uif8", "hash_imp": "4A124D4C214DBB24BCE7F0447B727173", "hash_pesha1": "4F5844826A001548A4F0456C63960C387D01946E", "hash_pe256": "6C50455D5C128BAC3CF093D0D8FE4DC2FAE956DD55FA938D5D31CC6F48CBD255", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Netstat Command", "meta_original_filename": "netstat.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/aca66f4bc15e1b8ede8f05f59dfafb15fa47d9e89ea1d4cf59264ba3d483f47c/detection/", "error": "\r\nDisplays protocol statistics and current TCP/IP network connections.\r\n\r\nNETSTAT [-a] [-b] [-e] [-f] [-n] [-o] [-p proto] [-r] [-s] [-x] [-t] [interval]\r\n\r\n -a Displays all connections and listening ports.\r\n -b Displays the executable involved in creating each connection or\r\n listening port. In some cases well-known executables host\r\n multiple independent components, and in these cases the\r\n sequence of components involved in creating the connection\r\n or listening port is displayed. In this case the executable\r\n name is in [] at the bottom, on top is the component it called,\r\n and so forth until TCP/IP was reached. Note that this option\r\n can be time-consuming and will fail unless you have sufficient\r\n permissions.\r\n -e Displays Ethernet statistics. This may be combined with the -s\r\n option.\r\n -f Displays Fully Qualified Domain Names (FQDN) for foreign\r\n addresses.\r\n -n Displays addresses and port numbers in numerical form.\r\n -o Displays the owning process ID associated with each connection.\r\n -p proto Shows connections for the protocol specified by proto; proto\r\n may be any of: TCP, UDP, TCPv6, or UDPv6. If used with the -s\r\n option to display per-protocol statistics, proto may be any of:\r\n IP, IPv6, ICMP, ICMPv6, TCP, TCPv6, UDP, or UDPv6.\r\n -q Displays all connections, listening ports, and bound\r\n nonlistening TCP ports. Bound nonlistening ports may or may not\r\n be associated with an active connection.\r\n -r Displays the routing table.\r\n -s Displays per-protocol statistics. By default, statistics are\r\n shown for IP, IPv6, ICMP, ICMPv6, TCP, TCPv6, UDP, and UDPv6;\r\n the -p option may be used to specify a subset of the default.\r\n -t Displays the current connection offload state.\r\n -x Displays NetworkDirect connections, listeners, and shared\r\n endpoints.\r\n -y Displays the TCP connection template for all connections.\r\n Cannot be combined with the other options.\r\n interval Redisplays selected statistics, pausing interval seconds\r\n between each display. Press CTRL+C to stop redisplaying\r\n statistics. If omitted, netstat will print the current\r\n configuration information once.\r\n\r\n", "children": "powershell.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\NETSTAT.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "newdev.exe-E636FCC34E83BA6D6EB415D79AE9A52A": { "file_name": "newdev.exe", "file_path": "C:\\Windows\\SysWOW64\\newdev.exe", "hash_md5": "E636FCC34E83BA6D6EB415D79AE9A52A", "hash_sha1": "03E6721EA99E6BE307EE58CBEDFC6845FD49AE28", "hash_sha256": "626117A7AABF84D6DB68E5D670C72EF5D0D586B474DDF5B7ECA85B046F97582E", "hash_sha384": "04E46D53D1E23400BC6DEC01F960B21B12F19405170849D12AFB04221103706A50E451CD5CC4BED5931BB4BF401C424E", "hash_sha512": "98205F73CECF92397DBFCBE00B66416020F5213D5B99BAC6898DA09ED7509B5F92743531D57B02D3397CE3CBA1A05E08BC0D9E915D7ED6259CEAF371B172B957", "hash_ssdeep": "768:cYifd7en3h09/2AaJQAhtqIrn8+1hrpFIUUUUUUUUUUUUqRcxM6:Hif5enGx2AaJfFrGUUUUUUUUUUUU3+6", "hash_imp": "CC7A41389B1DF730B98F1088FC6BC987", "hash_pesha1": "102CCAABA6F1800D1841B51E03C252CE7496AED4", "hash_pe256": "081378ABABB4AB0580ACDEAB3A625BE368885523340C2AD4BF922DB14884A7F2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Device driver software installation", "meta_original_filename": "NewDev.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.2.3668.0", "meta_product_version": "5.2.3668.0", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/626117a7aabf84d6db68e5d670c72ef5d0d586b474ddf5b7eca85b046f97582e/detection/" }, "nltest.exe-F501EFB48F9A5B14626726FE29CD27F9": { "file_name": "nltest.exe", "file_path": "C:\\Windows\\SysWOW64\\nltest.exe", "hash_md5": "F501EFB48F9A5B14626726FE29CD27F9", "hash_sha1": "644B1958D82D5528C30FB1CD29EEBC9690E1FB6F", "hash_sha256": "67667BE06E369FD7B62328BFE70DE34C34B40C2FA5837A8D241D59B37822ECC1", "hash_sha384": "7912B2A2EF70E914DAF038E4FB4E59AE9798CB628BA90B01E1EAB5CAD21D9936F801AB5D16C1C45F04A1029FF7221BF5", "hash_sha512": "DF4C285D58E65D5D7421C366A44CA26539F235C1029BBFC278D6C462C0DEBCB2A88E99D2708DA871B36A9FF9017DDB578788E7306500C6A4BC712CDCEECBE4FF", "hash_ssdeep": "12288:y0RT1sBTBUg3UdrueO+XWO+ueO+ueOdN:y0RT23UdrueO+XWO+ueO+ueOdN", "hash_imp": "B327F2B9F5DCA387FF8B86B4D729F08B", "hash_pesha1": "5D6184EA7E2FD6E1EBD47A9419326F32DF3719A9", "hash_pe256": "0898DA16CAC8BB4CA59305414C2B4C0DAA738CE92A47CF5FDE3EFAFEF80F0A91", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Logon Server Test Utility", "meta_original_filename": "nltestrk.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "Usage: nltest [/OPTIONS]\r\n\r\n\r\n /SERVER:<ServerName> - Specify <ServerName>\r\n\r\n /QUERY - Query <ServerName> netlogon service\r\n /REPL - Force partial sync on <ServerName> BDC\r\n /SYNC - Force full sync on <ServerName> BDC\r\n /PDC_REPL - Force UAS change message from <ServerName> PDC\r\n\r\n /SC_QUERY:<DomainName> - Query secure channel for <Domain> on <ServerName>\r\n /SC_RESET:<DomainName>[\\<DcName>] - Reset secure channel for <Domain> on <ServerName> to <DcName>\r\n /SC_VERIFY:<DomainName> - Verify secure channel for <Domain> on <ServerName>\r\n /SC_CHANGE_PWD:<DomainName> - Change a secure channel password for <Domain> on <ServerName>\r\n /DCLIST:<DomainName> - Get list of DC's for <DomainName>\r\n /DCNAME:<DomainName> - Get the PDC name for <DomainName>\r\n /DSGETDC:<DomainName> - Call DsGetDcName /PDC /DS /DSP /GC /KDC\r\n /TIMESERV /GTIMESERV /WS /NETBIOS /DNS /IP /FORCE /WRITABLE /AVOIDSELF /LDAPONLY /BACKG /DS_6 /DS_8 /DS_9 /DS_10\r\n /TRY_NEXT_CLOSEST_SITE /SITE:<SiteName> /ACCOUNT:<AccountName> /RET_DNS /RET_NETBIOS\r\n /DNSGETDC:<DomainName> - Call DsGetDcOpen/Next/Close /PDC /GC\r\n /KDC /WRITABLE /LDAPONLY /FORCE /SITESPEC\r\n /DSGETFTI:<DomainName> - Call DsGetForestTrustInformation\r\n /UPDATE_TDO\r\n /DSGETSITE - Call DsGetSiteName\r\n /DSGETSITECOV - Call DsGetDcSiteCoverage\r\n /DSADDRESSTOSITE:[MachineName] - Call DsAddressToSiteNamesEx\r\n /ADDRESSES:<Address1,Address2,...>\r\n /PARENTDOMAIN - Get the name of the parent domain of this machine\r\n /WHOWILL:<Domain>* <User> [<Iteration>] - See if <Domain> will log on <User>\r\n /FINDUSER:<User> - See which trusted domain will log on <User>\r\n /TRANSPORT_NOTIFY - Notify netlogon of new transport\r\n\r\n /DBFLAG:<HexFlags> - New debug flag\r\n\r\n /USER:<UserName> - Query User info on <ServerName>\r\n\r\n /TIME:<Hex LSL> <Hex MSL> - Convert NT GMT time to ascii\r\n /LOGON_QUERY - Query number of cumulative logon attempts\r\n /DOMAIN_TRUSTS - Query domain trusts on <ServerName>\r\n /PRIMARY /FOREST /DIRECT_OUT /DIRECT_IN /ALL_TRUSTS /V\r\n /DSREGDNS - Force registration of all DC-specific DNS records\r\n /DSDEREGDNS:<DnsHostName> - Deregister DC-specific DNS records for specified DC\r\n /DOM:<DnsDomainName> /DOMGUID:<DomainGuid> /DSAGUID:<DsaGuid>\r\n /DSQUERYDNS - Query the status of the last update for all DC-specific DNS records\r\n\r\n /BDC_QUERY:<DomainName> - Query replication status of BDCs for <DomainName>\r\n\r\n /LIST_DELTAS:<FileName> - display the content of given change log file \r\n\r\n /CDIGEST:<Message> /DOMAIN:<DomainName> - Get client digest\r\n /SDIGEST:<Message> /RID:<RID in hex> - Get server digest\r\n\r\n /SHUTDOWN:<Reason> [<Seconds>] - Shutdown <ServerName> for <Reason>\r\n /SHUTDOWN_ABORT - Abort a system shutdown\r\n\r\n" }, "notepad.exe-87E35E5F0B085E0D29BBDF6659C6D3D7": { "file_name": "notepad.exe", "file_path": "C:\\Windows\\SysWOW64\\notepad.exe", "hash_md5": "87E35E5F0B085E0D29BBDF6659C6D3D7", "hash_sha1": "84573F22D31282D975190ADC6A3D0C3307BF2A5E", "hash_sha256": "2CC3EC4F97E1A018B2F5A92E088775214AA2B0ABF2814DCA8242414FA2A88718", "hash_sha384": "4852777335EB71772BEC70C8F09F7FEA493D55EA67FF6F43F6C4F922063FBA08329D222C569756C6AD73FC8BF22FE538", "hash_sha512": "FAF3C7D9D5D436D12E069B140B9F6753A2615014CFB771F55906450CD13754CED186DBAFB7DA8726E9D969DC757D2743C7C1D31AC9FD824A572791473991236C", "hash_ssdeep": "3072:mvkpqzWP+Rag1kCAwPttIC3iPeqPc7bg6j8CYJJLgf7nDVF6PUp1Yo3ICgHs5aG5:q6WTR8CZ9PqPc7bg6jQJ5gfzDVlVXgI", "hash_imp": "F8ED88B6D1F3E2640242464940D1B553", "hash_pesha1": "CEC33F6602793B5813773E75FE629EABB134C03B", "hash_pe256": "7C6DCA892E8C11C934B72FB1CD405EC7B5185858F82E54D8177E548E1B6F31B9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Notepad", "meta_original_filename": "NOTEPAD.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.475 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.475", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/2cc3ec4f97e1a018b2f5a92e088775214aa2b0abf2814dca8242414fa2a88718/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\notepad.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\RPC Control\\DSEC734": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\notepad.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "--help - Notepad" }, "nslookup.exe-5C6C55E5DE7F0A8B1F8B42A6D9305E4D": { "file_name": "nslookup.exe", "file_path": "C:\\Windows\\SysWOW64\\nslookup.exe", "hash_md5": "5C6C55E5DE7F0A8B1F8B42A6D9305E4D", "hash_sha1": "B93CA789C28D48ADF60544FA9E538E5949C34EA1", "hash_sha256": "B137EFEBC097FDA9311A4526E450238B07E15B6EA78F78B0C14C1EB073A171F6", "hash_sha384": "DC339058B58AC2F5B4F3D09FE46F0417F0744587053AE899FA0A1916BB08516679CE693069A6DF6F0E812AE3E0B5584E", "hash_sha512": "728B14DA54BAF8085673C7C0F05AA0190245B9CBF8BA58ABF96247FEA46BE8A01D518652D63BE342ED62FDB9F5076AF1CA36D7ACCF4B64267FF42BC51C523FBC", "hash_ssdeep": "1536:zyiuSPDRY4uNQCqTL7HxttSf68XigRoZfYjk:ewFYhqNH7tSf68XB0f", "hash_imp": "6A3E1358BC46591E817A18E666B710E4", "hash_pesha1": "0C22C503F29B1DEFBA733185C4F0272153B4DB46", "hash_pe256": "085E40CD4016B0A5B7F8248C7F2EA09C901E0C077E52176FB4D8033B90DAB6A3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "nslookup", "meta_original_filename": "nslookup.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/b137efebc097fda9311a4526e450238b07e15b6ea78f78b0c14c1eb073a171f6/detection/", "error": "Usage:\r\r\n nslookup [-opt ...] # interactive mode using default server\r\r\n nslookup [-opt ...] - server # interactive mode using 'server'\r\r\n nslookup [-opt ...] host # just look up 'host' using default server\r\r\n nslookup [-opt ...] host server # just look up 'host' using 'server'\r\r\n", "output": "Default Server: ip-172-31-0-2.us-east-2.compute.internal\r\nAddress: 172.31.0.2\r\n\r\n> ", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\nslookup.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\nslookup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ntprint.exe-68214347E67BC0450711A23BDFAA3D8E": { "file_name": "ntprint.exe", "file_path": "C:\\Windows\\SysWOW64\\ntprint.exe", "hash_md5": "68214347E67BC0450711A23BDFAA3D8E", "hash_sha1": "89A3FD38D6E5550BF6254B54FFC52E6B7FD11E0A", "hash_sha256": "CC0500C90955A751AE3E2ED274422B2B2B5CA586D610EE1D71E006DD07687ECC", "hash_sha384": "30F921D320B7CB370E890733D9563F34A17BB395FDC19371D7507EBCF9737F1B2F32C782398B0B36EBF4BDC3E2D83C32", "hash_sha512": "119B217564E0B412CD5704DB473A82A375C23C53079128F21C6E606453E5A8F125CAA9A9A240D86807077B66275C4ED91E7762AAC783391E37EF9E190812D5D9", "hash_ssdeep": "768:6MtIdB36ulFT5vI1iQfCIWVM9G4qW4ne+S/ly+PKAoXRZX6fbX57UWkCRPPA7/QR:/MHVIPd4n+lbeRZIbSQPPA78", "hash_imp": "84E6CE32AD78D98B8E208DD970DC233E", "hash_pesha1": "80400F9055AE79A9EF74CBD28400C1A2C9728A75", "hash_pe256": "12457ED5CB4959D0307CC7F63FC89CDC6130145766B2B29BB4AF833B00C710E9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Printer driver software installation", "meta_original_filename": "ntprint.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/cc0500c90955a751ae3e2ed274422b2b2b5ca586d610ee1d71e006dd07687ecc/detection/" }, "odbcad32.exe-28AD5E456CCF3D267F7370671B52AD5E": { "file_name": "odbcad32.exe", "file_path": "C:\\Windows\\SysWOW64\\odbcad32.exe", "hash_md5": "28AD5E456CCF3D267F7370671B52AD5E", "hash_sha1": "DE99EB2B2F57C426D25198967AB100E65BA5A2E2", "hash_sha256": "6E28C875BFA690D77CDC3FE2E9E1209EC9517034DAEDE8BD28903E3FB6915D40", "hash_sha384": "6F036A7E56BD3B6136A533DD145D19B2F01FAF8B05DBE974CDBCE7BBCD9838E73EA9A07DB211A48093FFB91FC8181401", "hash_sha512": "00C6F9CABACB77698D2B3F0695C912562510FE881678358FAEE5098583B78EAE7707639E81BCC9C784A440112ADD4CE68BAA8F0DA14DBE3A61AFE2D410375CB0", "hash_ssdeep": "1536:ZN0Dytv3Jrz6q9EyYt9FlUIlbvBjIloW:ZN0UUKI9jo", "hash_imp": "5EA6AB8804656F81EFFBB0E2F39649E5", "hash_pesha1": "D3A4EA8C17239592AD58AB39E6A580ABFE8B5849", "hash_pe256": "1E03F77AC553A859F9DECC480AC9C386D178D8B794E930A1A01BE4AF70EFBC99", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ODBC Administrator", "meta_original_filename": "odbcad32.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/6e28c875bfa690d77cdc3fe2e9e1209ec9517034daede8bd28903e3fb6915d40/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\odbcad32.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\odbcint.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\odbcad32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Microsoft ODBC Administrator" }, "odbcconf.exe-35CDB46FD7E96B9357D75FF285099B14": { "file_name": "odbcconf.exe", "file_path": "C:\\Windows\\SysWOW64\\odbcconf.exe", "hash_md5": "35CDB46FD7E96B9357D75FF285099B14", "hash_sha1": "3DA25ACA4E86908C7FE514E53684FE52A83B0A36", "hash_sha256": "82984508D7814CAF0E73D70ABA19359297CF23A53FF1AC891BCB84B803321858", "hash_sha384": "3F194EA79189232CB8FF8603CB069F3FB4028FF6C062E321A8DD27186304FB9C4A6E04B8F7569788068000DD2DFACA39", "hash_sha512": "6D2236E79932B9E6D7D88094F7A2663448AE403611925C92E7E7B94728CCD3B029963DBA286D59654FDA4D282F5A20801BAD5E2B0FEEEA8388D5EC513459609D", "hash_ssdeep": "384:yVrAigT9MLuRYdwgm+E1lPK2tCnnnA2OyYOFdsvwnunVNhdpStF1a1rSCvC1yJX2:gutkmUdsHjtC1PSQygx", "hash_imp": "0BFFB84095E2F3283A30D28326BDE550", "hash_pesha1": "EDF8E8BA03FC8F642F1E8EA883402ABE17F3AB8E", "hash_pe256": "46894A13E488783DD7C64BC19FEBF9CBD03E7A93A577B83DCD8569BE6F6B15A8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ODBC Driver Configuration Program", "meta_original_filename": "odbcconf.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/82984508d7814caf0e73d70aba19359297cf23a53ff1ac891bcb84b803321858/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\odbcconf.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\odbcconf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Invalid Parameter" }, "openfiles.exe-41BCEE851834601FCAF03A9372A477AF": { "file_name": "openfiles.exe", "file_path": "C:\\Windows\\SysWOW64\\openfiles.exe", "hash_md5": "41BCEE851834601FCAF03A9372A477AF", "hash_sha1": "D96A322CBACD7E4DD78500BBED2A84DC51A6AB8B", "hash_sha256": "AE663F66615F66A4F5970FFF2EBC7B50142BB5FA809B472D942B50887DAF9F0F", "hash_sha384": "4BB66ACAB0016BC010A8E9D5FBE82903CEED662EB6BF73F8C2BDC21B9DCBB513F5300B0F34A55F795DFDC80D73EF899D", "hash_sha512": "151938F70B2848C10004B07CD9E860B8739A7E4B07F25B95E60D5EA083C869ADA2BAAD2AE616E5CFAE27E3704C265A342D39F60A7B5755D228D420D8FD495129", "hash_ssdeep": "1536:FORf+E6e0Obn96ysWUux88cs3+tamCxdqc:W6e0O9X7Uum8clamCxQ", "hash_imp": "F4871A9C2C4D47CC68C3AE460CFDE7D8", "hash_pesha1": "9B08B26E44FBFC20A0B74AF15B579654C69E7B89", "hash_pe256": "89E562EF4B2DA3F6E58299BEEB1DFB3031D6F35C2310AD6935D5942D9DBFDDFA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays the current open files list", "meta_original_filename": "opnfiles.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/ae663f66615f66a4f5970fff2ebc7b50142bb5fa809b472d942b50887daf9f0f/detection/", "error": "ERROR: The target system must be running a 32 bit OS.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\openfiles.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "OpenWith.exe-C6CEF89904DEC9404CCCD414E353C344": { "file_name": "OpenWith.exe", "file_path": "C:\\Windows\\SysWOW64\\OpenWith.exe", "hash_md5": "C6CEF89904DEC9404CCCD414E353C344", "hash_sha1": "E6853843F2A70BF03B2B107758A22F3F951AAA67", "hash_sha256": "FCF7C8545CDC4763B0D74D94F06E29F0DDFFDBADCABD096A35D82959B9F562E2", "hash_sha384": "72A404E7B003397D9EABA4512EE859BE04A9CD4B5CE81F36004EB1216A6A3FA1A2B11AF0C5F17EF17BC83250FEE4D92B", "hash_sha512": "46434021876CCD62569CA7AC2CB2FF30D91F9B3AEBA136600410B3DC4E9AB88E5EAC7973DDAF4C4EBA17C08CBE198A90E41E8BF08379B8CBA3F7ACB5EEE82348", "hash_ssdeep": "1536:hl6g16xnOg26tRxwMF50aimuCHLswrKyLFKQfKQTzBNer+CE+Ge+av7FPW4yA:76cOtRxwavr3wkrer+CE+G8F+A", "hash_imp": "FDF10BE5B78520728DF2C4E8D89DF1DA", "hash_pesha1": "C4C4320439BED35070F6076226994E84FE6BB5C0", "hash_pe256": "6D72574D24E24544AA2278CCF89392E2BFBE846F6A6E73656DC115C260D42AB0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Pick an app", "meta_original_filename": "OpenWith.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/fcf7c8545cdc4763b0d74d94f06e29f0ddffdbadcabd096a35d82959b9f562e2/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\OpenWith.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\RPC Control\\DSEC618": "Section", "(R-D) C:\\Windows\\System32\\en-US\\dui70.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\Windows.UI.Immersive.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\Sessions\\2\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Windows\\System32\\en-US\\twinui.dll.mui": "File", "(RW-) C:\\Windows\\SysWOW64": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\oleaccrc.dll.mui": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_32.db": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(RWD) C:\\Windows\\Fonts\\seguisb.ttf": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\OpenWith.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "OposHost.exe-D68AAD2C0C33B67DC4C9053DF252F125": { "file_name": "OposHost.exe", "file_path": "C:\\Windows\\SysWOW64\\OposHost.exe", "hash_md5": "D68AAD2C0C33B67DC4C9053DF252F125", "hash_sha1": "2D1546AAD6423C82062775CCEC233BB85B9F4945", "hash_sha256": "0BDA29FC48C8D6F66D823577E136E39B185A5FFEE086C1258BBBD66EF3A92084", "hash_sha384": "88C0DB42474CE29B11A42B03D88A112A0A2E14F7C4ACD25AAD7EC82A6CBF76D8E92631A747D751A83F3AF40E2F478EDA", "hash_sha512": "B2BEB469EC436A6EF06BFA708B4DD7D4BE14FB7F035B31C63E9A41CD8D1CB696F436018A31C672A49EB0413BF684C2960DDB0846F92BBCEB718B1DB5AC419CC9", "hash_ssdeep": "768:dz3WqA8o4DJNwzA1nJouPvdBSKqBDPErgoZXXxSN3Aro/BA:p3/BDJNgA1nf3wBDMCaopA", "hash_imp": "4A3167BDF5CF7721B06A0EB42034DD6C", "hash_pesha1": "013C72A92659360C10C1711DBA7C3AC7B2CD6970", "hash_pe256": "0E12B655E95268ACC630B266AE7F8F546FFE3EA36BD0F13D0D6BFFF29895FCF6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "OPOS Service Object Host", "meta_original_filename": "oposhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/0bda29fc48c8d6f66d823577e136e39b185a5ffee086c1258bbbd66ef3a92084/detection/" }, "PackagedCWALauncher.exe-416CCB1416BC6548EFBEF88A865E43A0": { "file_name": "PackagedCWALauncher.exe", "file_path": "C:\\Windows\\SysWOW64\\PackagedCWALauncher.exe", "hash_md5": "416CCB1416BC6548EFBEF88A865E43A0", "hash_sha1": "EEB58B915EA45F7300B675D8553EB3A48880BB4A", "hash_sha256": "C6AA828881CE6871F1C15F9A4CE466F9DB9D459A5E81950DCC069A3CF2D81C3E", "hash_sha384": "9AF15BFBBAC9C7AF898E4842597B3E7A523AA67C40A86C02598114B4012D251D786488A4C85D7C41AD0CADF22DE5E765", "hash_sha512": "D39AEB3F2D2E98EBC4D03AE00F73E59196EBD61CF866B25FCD27C12DF90ACB1CA40E034DD59D06AF5CABAFCCA5532ADD9655044DB6B1337341DBB3FAD3A2C7C5", "hash_ssdeep": "384:uAQjfJTZP6qefRWvSHpR4N8qQ5fxLpU/AF+yicCKRg+1xnqU0KOM+ietj72S8WCK:uA6leQKv4N85f4/Aoh5KR1OM+USses", "hash_imp": "0D14A9F6A66B170ABCB7FCEBF02B0822", "hash_pesha1": "E1C001100B7018D01A74BB8D1AEA7A2F66A64B47", "hash_pe256": "DA7F7394C2BB37EAED2C14E4CF3C31D076FD6F9EF2A01552A4CBB0520B2A4C85", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Packaged CWA Launcher", "meta_original_filename": "PackagedCWALauncher.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/45", "filescan_vtlink": "https://www.virustotal.com/gui/file/c6aa828881ce6871f1c15f9a4ce466f9db9d459a5e81950dcc069a3cf2d81c3e/detection/" }, "PasswordOnWakeSettingFlyout.exe-008528DD5373011FE99F7964CABFA486": { "file_name": "PasswordOnWakeSettingFlyout.exe", "file_path": "C:\\Windows\\SysWOW64\\PasswordOnWakeSettingFlyout.exe", "hash_md5": "008528DD5373011FE99F7964CABFA486", "hash_sha1": "06C8F091E2F48DF3698BA96BCC0847B4E340DF60", "hash_sha256": "6B3F606A36F3D54D77EDB0FD20E03CC4E838C93153B90E30A04ABA89C6DD4E4F", "hash_sha384": "2B73F82E5054ED8B637B30E555BE819D88A8BA4EC7BC8A20E56A6B4FE121025593A65D55640B7424EEDF35CC82C7000E", "hash_sha512": "12766A7CD5666F0246D0E172A78040F250CDE9B80BBB00001276B641CE9B5748DDDB8AD3D3FF797800FBADF02955A226D1178C8E67DF882AF82EA4CB9C73043B", "hash_ssdeep": "768:wqqJhlfGhYnPh32DYcdMMZIxl3vbOOLAxd6BtI1PjFU8:wqqJhlv4YcPZQl3vbOOLAxdEqPZU8", "hash_imp": "33D63270D927C05E54560A274D4D4932", "hash_pesha1": "FFD54E2FA6EFF4B6B33B444E8616464FE77E34CD", "hash_pe256": "D2575A902F5B30D45C889F6FAAC85D51CCFD8D7AD88EFB3C13F8E464CBD7CD1B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "User CPL Password on wake setting flyout", "meta_original_filename": "PasswordOnWakeSettingFlyout.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.771 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.771", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/6b3f606a36f3d54d77edb0fd20e03cc4e838c93153b90e30a04aba89c6dd4e4f/detection/" }, "PATHPING.EXE-018FAC646ABD50B51E525DB2CB0E2CAC": { "file_name": "PATHPING.EXE", "file_path": "C:\\Windows\\SysWOW64\\PATHPING.EXE", "hash_md5": "018FAC646ABD50B51E525DB2CB0E2CAC", "hash_sha1": "D7426426F6681F5A3115BA37CBFFE436C9801027", "hash_sha256": "58037E8767CAFF16722C3DBC1E3B733B9FD269C5A244CE1FA3973E3D31C13FA8", "hash_sha384": "B633D9052D9A79327564F58FE47B8A5A96A2074F9B5EF33495684053B107C9ACA65B18A63C0F3B58BE5F10BC0CEB8C01", "hash_sha512": "4867B681E106876C67EE2FF1D13E53F2110A84CBFB7223D6AD3F5D4A836CF0715ECA9EC4F9AF96FFBA257F73F8C9FDBE3CB090468B9214E54CB98AF8D4FE3513", "hash_ssdeep": "384:JbcztcANGb1BwYRn2mirBrvm6L8fzSW6AW3:JFwYR8ru6L8S1", "hash_imp": "ECB4C43808A5E78D58E2DCAEA3958691", "hash_pesha1": "5EAB4F841621458E358381FE34ED62640FDD57D5", "hash_pe256": "81180135A8C84935DBD8F63BD91C9517D3CF40059EEF1FB0E3032A59B26A60DE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP PathPing Command", "meta_original_filename": "pathping.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/58037e8767caff16722c3dbc1e3b733b9fd269c5a244ce1fa3973e3d31c13fa8/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\PATHPING.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "output": "--help is not a valid command option.\r\n\r\nUsage: pathping [-g host-list] [-h maximum_hops] [-i address] [-n] \r\n [-p period] [-q num_queries] [-w timeout] \r\n [-4] [-6] target_name\r\n\r\nOptions:\r\n -g host-list Loose source route along host-list.\r\n -h maximum_hops Maximum number of hops to search for target.\r\n -i address Use the specified source address. \r\n -n Do not resolve addresses to hostnames.\r\n -p period Wait period milliseconds between pings.\r\n -q num_queries Number of queries per hop.\r\n -w timeout Wait timeout milliseconds for each reply.\r\n -4 Force using IPv4.\r\n -6 Force using IPv6.\r\n" }, "pcaui.exe-E999171F420BDD0BB8EAED1412D61061": { "file_name": "pcaui.exe", "file_path": "C:\\Windows\\SysWOW64\\pcaui.exe", "hash_md5": "E999171F420BDD0BB8EAED1412D61061", "hash_sha1": "ABEFE55A3F66599C2AD8276B00416172F8F79880", "hash_sha256": "1D16441035EB9C6EA116DE582BBC9B6E794C4BED3B4045348CF10A62F6CC71A1", "hash_sha384": "4A1FDEDD38401A42A264515378C3EC04B80775020E9CB721C17499669BF25FE6434962ED90B0ED00FC842CE92872A9B2", "hash_sha512": "5D4EAEAA62F375BE1116ACAB56D086C61B3FEFD4DA3DDA1BCF5416AB08BE2E2A7D569D10551EF703D9A60342FA052A070D72FEFA5C4A2B3D55A8B2704F7A6258", "hash_ssdeep": "3072:+9+TZPEKlvesKFxqhR7/k24dNR/roGMPGdjw:/4dFxeRRsNRMGMPK8", "hash_imp": "1F08E356FCF5725081252F5DEAEFEC0B", "hash_pesha1": "1466CA9732252ADF45B55DD8D12B21C9CECABBEE", "hash_pe256": "90DAA827095D32A7D61D1B2882BB9FB448041E9E9B19CDC75968AAE7A02BB9D0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Program Compatibility Assistant User Interface", "meta_original_filename": "pcaui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/1d16441035eb9c6ea116de582bbc9b6e794c4bed3b4045348cf10a62f6cc71a1/detection/" }, "perfhost.exe-CC037C3D8F265E65F7200D9665D653FD": { "file_name": "perfhost.exe", "file_path": "C:\\Windows\\SysWOW64\\perfhost.exe", "hash_md5": "CC037C3D8F265E65F7200D9665D653FD", "hash_sha1": "08D3D23C735DF2EA0546FCBCC2FEFEBB7D340216", "hash_sha256": "68654262029A6F62DEE7F9D296A69A99DD6811C7AA6056DE40CE34440D4513CE", "hash_sha384": "FCE7528DD0852DAE9BC8ED7A71A719D7106731130A5C7D3C394B16C50A5E8B051EBD82BA3C61D9DB27BA577FA72915B9", "hash_sha512": "C31F8E4E20AE648093AE545A772F921C93BBA0D238A19F1B94D00C72EA64DBEB6ADB649C494547DB3F834B8EC6F76401FFA3E0C27C1CDA17F82266BC6F2D9AF9", "hash_ssdeep": "384:labbAjvuy1J69I3JkNMo7rkCY1ZO+l8KW00WG5FtgIQ:EQjtCFMS+OO8Y0G", "hash_imp": "A1C222418608BCB31033CAA32FBD8D6A", "hash_pesha1": "4EBC3700B339EE552D653862C3058073903BB127", "hash_pe256": "2CC3958323A7F7CFEF8F28B6C89FB3FACD9316FE23316124E24391C99E59A35A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "x86 Performance Counter Host", "meta_original_filename": "perfhost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/68654262029a6f62dee7f9d296a69a99dd6811c7aa6056de40ce34440d4513ce/detection/" }, "perfmon.exe-97F73727B423C2FEE513EB7A06E357E5": { "file_name": "perfmon.exe", "file_path": "C:\\Windows\\SysWOW64\\perfmon.exe", "hash_md5": "97F73727B423C2FEE513EB7A06E357E5", "hash_sha1": "CA1668D8D389B48A5BA574925B4496DF2950434D", "hash_sha256": "5D4C3EF49BB510B7FBB943ACF60BD6B74FC6D295B9CC93933155CBAF535F03EB", "hash_sha384": "909000B6202806525E935D9B55A51949358BE564129857760DE1D3F81F23439623349CE7EF007083A23DA5D2F8D68F9F", "hash_sha512": "E510D43DC2534DE86D2D9826B59353AA3153E14B4B4BF2286C829B37277F4BCFCEFD2E5B044132C56C528A3BC7704535D4B1EED37E90B4CF1F6239FD2BA75C6E", "hash_ssdeep": "3072:6utzRwSpaYHrz1m2dyGghtYIo9piswTogiqQKy349tm:ZaSpaAn42dyhqIo9s37iTK24nm", "hash_imp": "B9EFBBF3710DB144F0FAEC23B813B32E", "hash_pesha1": "5307B5742DACC8DB9CE4455C63D1405BD50A8C3E", "hash_pe256": "F1BC7DFC850BFC45A750CA991ED0556E840CDDFD43F96F620245E0B34CA41531", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resource and Performance Monitor", "meta_original_filename": "perfmon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.00", "meta_product_version": "10.00", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/5d4c3ef49bb510b7fbb943acf60bd6b74fc6d295b9cc93933155cbaf535f03eb/detection/", "output": "Argument '-help' is unknown.\r\n", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\perfmon.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\perfmon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Resource and Performance Monitor" }, "PickerHost.exe-C7721213B06567AB730B99046F611F1A": { "file_name": "PickerHost.exe", "file_path": "C:\\Windows\\SysWOW64\\PickerHost.exe", "hash_md5": "C7721213B06567AB730B99046F611F1A", "hash_sha1": "815AED71960F10B8640692DBFA9E829ACEC515B1", "hash_sha256": "7E6E3F5EC8BF74886709652DEA921BFDBAEB243074715691D890B738A03784C6", "hash_sha384": "A232B7958BA3E1FD5EDC8FE6F17ED43ED62CF2F1DE683AFA348B3D8173FD3BF6813F5028AA6AFD89881ED22F0387F8B6", "hash_sha512": "F3FACAF5A034D0F4F6D7FDEDBA365F9FBD262023BEBDD3B7DC0449195861946C91BAA4B39D600FA051D022C1286068F40DC0B99659D6822DD9D8B89413704814", "hash_ssdeep": "1536:y+PMPEytWYnCl2CM0EjOE11wJrePojhSWicQfcg99iNtP/kBPd:y+UP7WYnCzJEjO+1pfpkg998FsBF", "hash_imp": "70F69413452F347EA29B67A603D9BC75", "hash_pesha1": "D813BB14B68B1B2CD68EC58469775D82BA5EABC4", "hash_pe256": "935FEC0A04D76629FF706A6945B5DD2CA6B0C34D18CF5B08C8A7DBD97ACEE5B0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "File Picker UI Host", "meta_original_filename": "PickerHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/7e6e3f5ec8bf74886709652dea921bfdbaeb243074715691d890b738a03784c6/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC750": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\PickerHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "PING.EXE-A0BC49F1C99A101E06125FD260CB59FB": { "file_name": "PING.EXE", "file_path": "C:\\Windows\\SysWOW64\\PING.EXE", "hash_md5": "A0BC49F1C99A101E06125FD260CB59FB", "hash_sha1": "7AC59B5D53E9DAE61D9991BC5D71E2D5202F5AE6", "hash_sha256": "C370E9606A929ACA877E7E5267A9F05FFA09A7CC4C53575B3BE8216DFED945B1", "hash_sha384": "EFE684925ECB81FF8F3424CF7603BA14263FB52A29CF2EF1583F6C9A43C62D8B1BB9F252A5551ADA114E2B715D8ABC1D", "hash_sha512": "E0032D167BB088248E0F757783511139C5CE17F6A7133E46104B9D8D7CE27E955A13517DFD5A1270DCC97B15223841463121549D8876696282DC024C2CF8830E", "hash_ssdeep": "384:QfSk6DAmGh5hv7GRXPoL8LPgooZNLZbKWmlW2k:sv5hv7C6/oYNLZWRk", "hash_imp": "6C1FE20B3F9688A9263FFDF9FF417272", "hash_pesha1": "8D9227EAF3C780D1D4C8E08AFBC58E65C0309E9D", "hash_pe256": "B65F26D8DBF8C28E5325FA43BD05FDD21E0B38F24B4F15C597A7C0BD15C2CDBC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Ping Command", "meta_original_filename": "ping.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/c370e9606a929aca877e7e5267a9f05ffa09a7cc4c53575b3be8216dfed945b1/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "output": "Bad option --help.\r\n\r\nUsage: ping [-t] [-a] [-n count] [-l size] [-f] [-i TTL] [-v TOS]\r\n [-r count] [-s count] [[-j host-list] | [-k host-list]]\r\n [-w timeout] [-R] [-S srcaddr] [-c compartment] [-p]\r\n [-4] [-6] target_name\r\n\r\nOptions:\r\n -t Ping the specified host until stopped.\r\n To see statistics and continue - type Control-Break;\r\n To stop - type Control-C.\r\n -a Resolve addresses to hostnames.\r\n -n count Number of echo requests to send.\r\n -l size Send buffer size.\r\n -f Set Don't Fragment flag in packet (IPv4-only).\r\n -i TTL Time To Live.\r\n -v TOS Type Of Service (IPv4-only. This setting has been deprecated\r\n and has no effect on the type of service field in the IP\r\n Header).\r\n -r count Record route for count hops (IPv4-only).\r\n -s count Timestamp for count hops (IPv4-only).\r\n -j host-list Loose source route along host-list (IPv4-only).\r\n -k host-list Strict source route along host-list (IPv4-only).\r\n -w timeout Timeout in milliseconds to wait for each reply.\r\n -R Use routing header to test reverse route also (IPv6-only).\r\n Per RFC 5095 the use of this routing header has been\r\n deprecated. Some systems may drop echo requests if\r\n this header is used.\r\n -S srcaddr Source address to use.\r\n -c compartment Routing compartment identifier.\r\n -p Ping a Hyper-V Network Virtualization provider address.\r\n -4 Force using IPv4.\r\n -6 Force using IPv6.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\PING.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "PkgMgr.exe-299F9CBA823CFB6F7AD965877154902B": { "file_name": "PkgMgr.exe", "file_path": "C:\\Windows\\SysWOW64\\PkgMgr.exe", "hash_md5": "299F9CBA823CFB6F7AD965877154902B", "hash_sha1": "6917CD5FAF32809CA8EA46F2FA97D75ED33119AA", "hash_sha256": "A1F495FB35CC72823BF0C556C59C0A1E7589F7109A3B287ABAA5F803C652009E", "hash_sha384": "A5C549CE421FE3003D54AB16043566FBE290EB57D2A3608B2935C6C37B50B6453B6E400677DFB81DF70576415446E0E8", "hash_sha512": "5B36639EC28DC09D875BE5E837551B246F067F920FBA520F6BDCF064A33F1FC00A7260474483570D78BEA53CDD2F94E46D8EEBEEB68558D8710A983BA6A73C7C", "hash_ssdeep": "3072:m/r5ENnKKphw6s4RTQcWl4xEGS2PQo9tW+R/MYg+S:er58nRccMUEGS2PbxR/T", "hash_imp": "59565FB94D24BF5F6F2207C5CBF343B0", "hash_pesha1": "6DA67B1A3E596DFBF5BFDA6B50B1D420EB446C2D", "hash_pe256": "9C57490182F6793E2FA862398AEDA5710A013035608504B3B587E60C780938A5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Package Manager", "meta_original_filename": "PkgMgr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/a1f495fb35cc72823bf0c556c59c0a1e7589f7109a3b287abaa5f803c652009e/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\PkgMgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Package Manager" }, "poqexec.exe-3C14CEA2018AEB67B71627D8CFA07656": { "file_name": "poqexec.exe", "file_path": "C:\\Windows\\SysWOW64\\poqexec.exe", "hash_md5": "3C14CEA2018AEB67B71627D8CFA07656", "hash_sha1": "5014AAE4492FD83FADB48D29BB1C5CAE51207DA9", "hash_sha256": "ED38D575D3CE8E16710182C17AFC86181FFA23B9023156938C2C14141279867F", "hash_sha384": "A0591D1F36A25439AB42908DE5A664F06BD6BD29F2A87DE453F18583293DA4C245E4545965F4C26F5A4117143C3D9F7C", "hash_sha512": "D9EA11AC1DF1683D42039F685343A72461577B7E423CFA02551BEBF4D9C9DB51B317950F3933BE089AF0F877DE32063B672813AD98F783DE634E86851DBB33E1", "hash_ssdeep": "3072:PbaVDo9SW3a81e6EmAwGqeXK1RfzRf9xSPCI2DAP:Pb8aSW3a81u/qe61RbR2qi", "hash_imp": "19FE0F206F9F2BBD963A860D56552FBB", "hash_pesha1": "027E387210927B592C6C979BF4AC695093E8069A", "hash_pe256": "C2A17CAF87E6B7C603F7B203BFDD469692D65DD718FCB23FABEE28B3FBDE765E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Primitive Operations Queue Executor", "meta_original_filename": "poqexec.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/ed38d575d3ce8e16710182c17afc86181ffa23b9023156938c2c14141279867f/detection/" }, "powercfg.exe-44ED24D9FA61D24D081288E7D0CB67FB": { "file_name": "powercfg.exe", "file_path": "C:\\Windows\\SysWOW64\\powercfg.exe", "hash_md5": "44ED24D9FA61D24D081288E7D0CB67FB", "hash_sha1": "0C4B2184E0CB1F702C3AFDA1F6A2731174459AD4", "hash_sha256": "80A8911BD52933500D8F2E554E7CF0954C250DF13D151D080011C2BE3A5AFF68", "hash_sha384": "CF11B9558FD7CA9829E7D7AA8748653F8972CFDF4FD5423EB50BB7E3D70486284150B14CC6DD6FD7315025F68192ED1C", "hash_sha512": "F6FC8BCFD9F5299F492B605A2A32E83CF765AFAAE049A97D9A7286EA314CA61BD14EB74A786CD1A00EB51EE6C878534B131385EFBF9B30724334986BA635919A", "hash_ssdeep": "1536:phDwlNsVPCCokFmrEv3LNuDhpEFQIoxpL0LSI5ijfW4GzYS6SLQiY:HwlNwP7euEhdrx2LSISfWrkS6E", "hash_imp": "CE71DDA6B161943096FA9731005EC5FD", "hash_pesha1": "76E1A599763064F63A1C0BA7E86AF85614437E03", "hash_pe256": "1923AC66BDB8D5655558F739239B809342713DFF212EA15D7FC263DFE2FD38AB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Power Settings Command-Line Tool", "meta_original_filename": "PowerCfg.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/80a8911bd52933500d8f2e554e7cf0954c250df13d151d080011c2be3a5aff68/detection/", "output": "\r\nPOWERCFG /COMMAND [ARGUMENTS]\r\n\r\nDescription:\r\n Enables users to control power settings on a local system.\r\n\r\n For detailed command and option information, run \"POWERCFG /? <COMMAND>\"\r\n\r\nCommand List:\r\n /LIST, /L Lists all power schemes.\r\n\r\n /QUERY, /Q Displays the contents of a power scheme.\r\n\r\n /CHANGE, /X Modifies a setting value in the current power scheme.\r\n\r\n /CHANGENAME Modifies the name and description of a power scheme.\r\n\r\n /DUPLICATESCHEME Duplicates a power scheme.\r\n\r\n /DELETE, /D Deletes a power scheme.\r\n\r\n /DELETESETTING Deletes a power setting.\r\n\r\n /SETACTIVE, /S Makes a power scheme active on the system.\r\n\r\n /GETACTIVESCHEME Retrieves the currently active power scheme.\r\n\r\n /SETACVALUEINDEX Sets the value associated with a power setting\r\n while the system is powered by AC power.\r\n\r\n /SETDCVALUEINDEX Sets the value associated with a power setting\r\n while the system is powered by DC power.\r\n\r\n /IMPORT Imports all power settings from a file.\r\n\r\n /EXPORT Exports a power scheme to a file.\r\n\r\n /ALIASES Displays all aliases and their corresponding GUIDs.\r\n\r\n /GETSECURITYDESCRIPTOR\r\n Gets a security descriptor associated with a specified\r\n power setting, power scheme, or action.\r\n\r\n /SETSECURITYDESCRIPTOR\r\n Sets a security descriptor associated with a\r\n power setting, power scheme, or action.\r\n\r\n /HIBERNATE, /H Enables and disables the hibernate feature.\r\n\r\n /AVAILABLESLEEPSTATES, /A\r\n Reports the sleep states available on the system.\r\n\r\n /DEVICEQUERY Returns a list of devices that meet specified criteria.\r\n\r\n /DEVICEENABLEWAKE Enables a device to wake the system from a sleep state.\r\n\r\n /DEVICEDISABLEWAKE Disables a device from waking the system from a sleep\r\n state.\r\n\r\n /LASTWAKE Reports information about what woke the system from the\r\n last sleep transition.\r\n\r\n /WAKETIMERS Enumerates active wake timers.\r\n\r\n /REQUESTS Enumerates application and driver Power Requests.\r\n\r\n /REQUESTSOVERRIDE Sets a Power Request override for a particular Process,\r\n Service, or Driver.\r\n\r\n /SYSTEMSLEEPDIAGNOSTICS\r\n Generates a diagnostic report of system sleep transitions.\r\n\r\n /SYSTEMPOWERREPORT Generates a diagnostic system power transition report.\r\n\r\n /POWERTHROTTLING Control power throttling for an application.\r\n\r\n\r\n", "error": "Invalid Parameters -- try \"/?\" for help\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\powercfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "PresentationHost.exe-B73ECB016B35D5B7ACB91125924525E5": { "file_name": "PresentationHost.exe", "file_path": "C:\\Windows\\SysWOW64\\PresentationHost.exe", "hash_md5": "B73ECB016B35D5B7ACB91125924525E5", "hash_sha1": "37FE45C0A85900D869A41F996DD19949F78C4EC4", "hash_sha256": "B3982E67820ABC7B41818A7236232CE6DE92689B76B6F152FAB9EF302528566D", "hash_sha384": "C2EDBBA50566EC3BDB8153E6144B15F5C6EDE8EA441B0E2625F0449277DBB4D9A40E767ABFF0D8481CDEE2460BFC00D8", "hash_sha512": "0BEA9890DBCD3AFD2889D0E7C0F2746995169E7B424F58D4998C50BC49D2B37D30F5BD1845D3079B25F9963AF2B71F136719CBD9FDA37F7B85874992096B3E1D", "hash_ssdeep": "6144:gW/3xqCu+WWzLw5KNXwy3Odjp19k5KNXfB:1/3U9cQKVwy3OdLaKV", "hash_imp": "88138F425FD4CF0102598C830D4A0EB1", "hash_pesha1": "E31F07A26406252D97DB2AC1E06B8E20264CA31C", "hash_pe256": "F471CDFB85D96D0466230FC9306F2C000993394B7643C42559799ED99965CE90", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Presentation Foundation Host", "meta_original_filename": "PresentationHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/b3982e67820abc7b41818a7236232ce6de92689b76b6f152fab9ef302528566d/detection/", "children": "iexplore.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\PresentationHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "prevhost.exe-4AE23D1615D5DE88EB3D7ECFAFC98F3B": { "file_name": "prevhost.exe", "file_path": "C:\\Windows\\SysWOW64\\prevhost.exe", "hash_md5": "4AE23D1615D5DE88EB3D7ECFAFC98F3B", "hash_sha1": "9329C4CB41342F6A63B0F66E127B2B2ED4BD9A20", "hash_sha256": "243D1AB7B5573B2E816E7ADC93BB36C40FD19E8C7E2F39D81172F32DFB13D802", "hash_sha384": "88A1B1EF2B058E833CB9DA8F7F9D041A8D2CD584A151E2C1008B052D093A8DDC249E87B7063FBAE440429EC2A4EAF758", "hash_sha512": "460F9E16A58058FD3ECDBC11AA0BFBC47051EA92F7CE82B388E343E6DE0D4FA7293C1DBB04B0245C417B36514BCD7EDAFB4481F94BB0EFA34F0E3D93CDF7652D", "hash_ssdeep": "384:OdBp18ng9H0Ecy+X3Tu5PLo/i3SzrnAN1qLkthCy6dyamW6cWXp:OdBpKng+lTueHrnANPhidyaiNp", "hash_imp": "64AD0500B99B03083D39C3F6AFAF2C66", "hash_pesha1": "B3AB17453EB80EF7CE3EEF8AC0396493044341BA", "hash_pe256": "C4206A940B58B47AF55CA03F5A62EE9924FF41B8173FFA8FA3C6E6D3D5C0CC4C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Preview Handler Surrogate Host", "meta_original_filename": "PREVHOST.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/243d1ab7b5573b2e816e7adc93bb36c40fd19e8c7e2f39d81172f32dfb13d802/detection/" }, "print.exe-249E7A692D56C8E523945E701E06474A": { "file_name": "print.exe", "file_path": "C:\\Windows\\SysWOW64\\print.exe", "hash_md5": "249E7A692D56C8E523945E701E06474A", "hash_sha1": "11B1DE9EF9246D9DE4DAAD52D69DD9FE4D01E5C0", "hash_sha256": "9EB93FBDE0A661888A0ACE44906DC7DA3872FE610A348CAFA81E56F8B8EA4975", "hash_sha384": "61516B45AC3FFF8894CF5F966665208850000C22E76A40201BDDC0478BBE6A25A1A99F05316636CFFA6C83E812AF423E", "hash_sha512": "9A534454170444C9EAA6D705859D540C1433BFB245C61175F4B8EF524DB1D1C093DCAA677DD084251950EFEDD889D35B8A37798F340A318BFF17B6B5294ED5E2", "hash_ssdeep": "192:ni//XcIBtPIgNqzPfsj0DlGTIIB8U6Sp+DcliQlixtU3CtmYk1WIUW1:i//80MIj6SpHl5l8UOs1WIUW", "hash_imp": "EC8AF21EA60135BB82EBEBEAF1752064", "hash_pesha1": "FFA9B0CD1D302B929E8D9A83ECE765D8FCD624DF", "hash_pe256": "D9B2A1D44FECBF416CB0641704D0BF597D23C9A7D806AFCC73C737395A269434", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Print Utility", "meta_original_filename": "Print.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/9eb93fbde0a661888a0ace44906dc7da3872fe610a348cafa81e56f8b8ea4975/detection/", "output": "Prints a text file.\r\n\r\nPRINT [/D:device] [[drive:][path]filename[...]]\r\n\r\n /D:device Specifies a print device.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\print.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "printui.exe-A33E43C6E26BF582B98B639217639DA6": { "file_name": "printui.exe", "file_path": "C:\\Windows\\SysWOW64\\printui.exe", "hash_md5": "A33E43C6E26BF582B98B639217639DA6", "hash_sha1": "5F0D60CFB3EE1E130F19BC8454F77BC0C5480EBF", "hash_sha256": "0FD82B7B6F97DF74DF7C02B2CD79E9AE306AC5B66709874146F5D042AA8C38FC", "hash_sha384": "56BDC6681A89C9C4C59FB99D46CC5E906CD728EB10156FACA8845422B21D20145BD176427892C9D04821EF8EE8E2ADDF", "hash_sha512": "BA8B7277A6A600930676C3AB4FD216A6CF5779EC899B3FF1D71C7303D996CC4D86D58C4428FAF058959F3E37F6314D5A2DAA251C6592079638F9D3239B218AAA", "hash_ssdeep": "768:Q0gL0CJheuF5vI1iQfCIWVM9G4qW4ne+S/ly+PKAoXRZX6fbX57UWkCRPPA7/QnA:bCJh1VIPd4n+lbeRZIbSQPPA7t", "hash_imp": "6F4EF9E489C40856B4C2A7590D1E7B05", "hash_pesha1": "9CE1A6EBD2BD308B3D6B4C2C0BFFBC0FC937A5B7", "hash_pe256": "F3659F17E92939F52D1CBCCFFEBE6ABB6639AFFA9BD80A28BFDE141D76240ADE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Printing Settings", "meta_original_filename": "printui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/0fd82b7b6f97df74df7c02b2cd79e9ae306ac5b66709874146f5d042aa8c38fc/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\printui.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\printui.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\printui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Printers" }, "proquota.exe-CDDF9E547309F29892FBC5922C535770": { "file_name": "proquota.exe", "file_path": "C:\\Windows\\SysWOW64\\proquota.exe", "hash_md5": "CDDF9E547309F29892FBC5922C535770", "hash_sha1": "E69375F1116E0461672310B972E4ABC44FCDC2B8", "hash_sha256": "CD0F437D9658F06E19FE93809270E2906148807314703475457C70C59D54C354", "hash_sha384": "04640949A9B6D9D4DFF8CA08895D9DFC7149BC53E2CD7F3BB6B7F4BBB5695CF63C0A8F90E76BC3AE78B5E7331314F777", "hash_sha512": "3D1C78DE572DFE5A4C250932E3762DBC330FE8D7A996400E6323D4A7419F978F3EF8422FED22252BC2915AED48FC0AAF0FA460F975AA23844302D7978C90A9AE", "hash_ssdeep": "384:8ZzhBPZsCHCOeEC9crAObqBLZfFB6bF6s0+hYhUGU68VVrVjkZecZjsWbuWbKAe6:6VBPZ7HBPY/jc6sUUGUV5kZe6zl", "hash_imp": "9E64C66B08DB18BB977AB395CAE4C0A2", "hash_pesha1": "42F718DCD147A6BE5F5D25012D6A89E970BA89B7", "hash_pe256": "141B922C8BBABE94619D823F3853A5FBC6D1B63E7CCC973629723050EB87BAB7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "ProQuota", "meta_original_filename": "proquota.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/cd0f437d9658f06e19fe93809270e2906148807314703475457c70c59d54c354/detection/" }, "psr.exe-A1B3839290C9485182436E2D2B12A644": { "file_name": "psr.exe", "file_path": "C:\\Windows\\SysWOW64\\psr.exe", "hash_md5": "A1B3839290C9485182436E2D2B12A644", "hash_sha1": "2842A3C8875BD3C214633554DDE47AC401EFE559", "hash_sha256": "7D944CE0DFE4FAB3D6D56D7D30F2AF8615C6E4CF4311B589022C3BBAFB3B7411", "hash_sha384": "125EE29982914E1BF9264FA2B11DFA4DD55ACBAADE7D8BA5A673CF5B0D24C6C7B20919991AA32D9E2CFA244915782A1D", "hash_sha512": "18F5C1273D6F23EE73F1E3CF81A015888C48FCA469C4607120C376D1D310851F6C3C01204F5A22273FA30F6F80C0B49AF835D3F83F773CF51DC374C24061DB57", "hash_ssdeep": "6144:XskrYkkRu4JYf/DDVrkv2tde70JAVcD8LPhSiWofQr2k5l8BmMxowi/EH1qf:/hc9oLDVw2fucD8pellpco//EH1", "hash_imp": "712ABE6C53B8E8EA9FE1C6BA6DB384D2", "hash_pesha1": "974EE29D5F7A0E30C3E69D260477A2869DA0F192", "hash_pe256": "99D6C5EE8309E81F2E2F00BBBECC90C391A421612F1B9E0B738F2E1779476773", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Steps Recorder", "meta_original_filename": "psr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1282 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1282", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/7d944ce0dfe4fab3d6d56d7d30f2af8615c6e4cf4311b589022c3bbafb3b7411/detection/" }, "qappsrv.exe-D8C8828C9204592955566C8BEDAD419A": { "file_name": "qappsrv.exe", "file_path": "C:\\Windows\\SysWOW64\\qappsrv.exe", "hash_md5": "D8C8828C9204592955566C8BEDAD419A", "hash_sha1": "32EC1EEEB0A2F61423AE47B19F7306F227526A82", "hash_sha256": "FE90F56D6830C6A908B113BBA48BF4101F14B54AE7423801AE499050605FC350", "hash_sha384": "B4FE56E8DE99F4BEE5C84FD124D544AF408DCE2B338C0CBE65E1823035A881A20E917DA605FBEC40039BC91C7AA61135", "hash_sha512": "F5E92D5A3913C3C30C7715F5B05E22576B2C90B414376F08D5187333B7CCC5F4854ED64C1BC56CF40658762B2D2326EFEC350B71EFDF7F710FFC14B89795864C", "hash_ssdeep": "384:8ZpTvaEfkbGhoLwP33/koPHS/UFdt8Hq9zW2oOdWLaWUeh:8Zp+ocGhoK/qn2Fm/", "hash_imp": "1A15C5ED7BC4BF3801523763FB69275D", "hash_pesha1": "D5408E96D5A0C8903AF2D1CCEA13E1212473CF62", "hash_pe256": "E948351D3756F6EC6BD7CE6F1AEA4232565DB4E6DB5172C37E6E2DD80609B22C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query Remote Desktop Session Host Server Utility", "meta_original_filename": "qappsrv.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/fe90f56d6830c6a908b113bba48bf4101f14b54ae7423801ae499050605fc350/detection/", "output": "Displays the available Remote Desktop Session Host servers on the network.\r\n\r\nQUERY TERMSERVER [servername] [/DOMAIN:domain] [/ADDRESS] [/CONTINUE]\r\n\r\n servername Identifies a Remote Desktop Session Host server.\r\n /DOMAIN:domain Displays information for the specified domain (defaults \r\n to the current domain).\r\n /ADDRESS Displays network and node addresses.\r\n /CONTINUE Does not pause after each screen of information.\r\n\r\n", "error": "Invalid parameter(s)\r\nDisplays the available Remote Desktop Session Host servers on the network.\r\n\r\nQUERY TERMSERVER [servername] [/DOMAIN:domain] [/ADDRESS] [/CONTINUE]\r\n\r\n servername Identifies a Remote Desktop Session Host server.\r\n /DOMAIN:domain Displays information for the specified domain (defaults \r\n to the current domain).\r\n /ADDRESS Displays network and node addresses.\r\n /CONTINUE Does not pause after each screen of information.\r\n\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\qappsrv.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\qappsrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "qprocess.exe-6C731AF0B86FA5ADF1B3E75556FF7D2A": { "file_name": "qprocess.exe", "file_path": "C:\\Windows\\SysWOW64\\qprocess.exe", "hash_md5": "6C731AF0B86FA5ADF1B3E75556FF7D2A", "hash_sha1": "6F4F6C36379E86B3E22A5E568D968D71D0E0E341", "hash_sha256": "23E556151BCA6472A7885AA78A812EC783B4498D036CB2BAAE1D22442111CDD9", "hash_sha384": "D663C0AFF111510BF0B341616CD6DCBC40AD1A6830E1F6DD7C692170F220CAD2F29DE31B619C6034D7CC898D35385DF9", "hash_sha512": "EE6A997BF5F0C78A40DC802C6D212FFA948390E16E81395FEAA47809A93E4EB78F95A95DBCEEB46EE51C47BACE67D675C5A297EA3879266D9167B523CB74D3F0", "hash_ssdeep": "384:yAFeyeTX4z4D2CKk8FrSPEDKJhoE882eaU2H9JWLME+2We9q:9Eyerlqk8W2dcV9", "hash_imp": "AAB82838221289B44013358AF9976ECD", "hash_pesha1": "785A89900898C0F1E66BAEE53CD40EDC345FA8B0", "hash_pe256": "1695A76BFB6544106B4A00EDC7C89AF824B0D8CEE1BD3BBABD0567F77DFB73F5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query Process Utility", "meta_original_filename": "qprocess.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/23e556151bca6472a7885aa78a812ec783b4498d036cb2baae1d22442111cdd9/detection/", "output": "Displays information about processes.\r\n\r\nQUERY PROCESS [* | processid | username | sessionname | /ID:nn | programname]\r\n [/SERVER:servername]\r\n\r\n * Display all visible processes.\r\n processid Display process specified by processid.\r\n username Display all processes belonging to username.\r\n sessionname Display all processes running at sessionname.\r\n /ID:nn Display all processes running at session nn.\r\n programname Display all processes associated with programname.\r\n /SERVER:servername The Remote Desktop Session Host server to be queried.\r\n", "error": "Invalid parameter(s)\r\nDisplays information about processes.\r\n\r\nQUERY PROCESS [* | processid | username | sessionname | /ID:nn | programname]\r\n [/SERVER:servername]\r\n\r\n * Display all visible processes.\r\n processid Display process specified by processid.\r\n username Display all processes belonging to username.\r\n sessionname Display all processes running at sessionname.\r\n /ID:nn Display all processes running at session nn.\r\n programname Display all processes associated with programname.\r\n /SERVER:servername The Remote Desktop Session Host server to be queried.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\qprocess.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "query.exe-BCB053556213C5755EAEF97D2F68BF0C": { "file_name": "query.exe", "file_path": "C:\\Windows\\SysWOW64\\query.exe", "hash_md5": "BCB053556213C5755EAEF97D2F68BF0C", "hash_sha1": "49B715FBEC24F1B1787DCD8D1658757BAFB8186A", "hash_sha256": "856EA448CE7E099496A0C9D7783FFFD2A28E9F1F931D2146714AB7640C39BADA", "hash_sha384": "81848D8F554C4C1E6F02FC8C7E9AAFDAC373EABE8F20CF6BC8B2B2B9D30F8A887355EC9FF04606B62F6AE0F383FB9242", "hash_sha512": "F1C504270EDD6FCD7401979ED6DB86C5DF3C4E58D440E521D83D62CD5DB72C08791B423ADC543B4C54F3BB0C6489FB7AF46A924571E2F4AB94A302516F7FD706", "hash_ssdeep": "192:+WzogF5/eyf1wzT4Fce1pN/1mt2Wco7kPAWW3Wd8:HVDGyf1wzT4ieh/1qlwPAWW3W", "hash_imp": "EC309FD93AE54D1FFDF17E744E71C366", "hash_pesha1": "972E27D94CFCDA78CC1C0C9E299C58F1D3081A5F", "hash_pe256": "7CC838D6491EF4498196B06C020BCDDCC0D4FA29428E51817D1EBC4A63A95AA2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MultiUser Query Utility", "meta_original_filename": "query.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/856ea448ce7e099496a0c9d7783fffd2a28e9f1f931d2146714ab7640c39bada/detection/", "output": "QUERY { PROCESS | SESSION | TERMSERVER | USER }\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\query.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "Invalid parameter(s)\r\nQUERY { PROCESS | SESSION | TERMSERVER | USER }\r\n" }, "quser.exe-C56FB0AA843D2D58F3166F6708B4613F": { "file_name": "quser.exe", "file_path": "C:\\Windows\\SysWOW64\\quser.exe", "hash_md5": "C56FB0AA843D2D58F3166F6708B4613F", "hash_sha1": "8DB5D2B2109CA42AD231553EADF0D6B01F2A1545", "hash_sha256": "8A56B2B043ED340FFEEC3845498005EBF972AF3B937340F0FBA064EA014AB1BB", "hash_sha384": "294DE575B62F43C68F615CD7775D445CD45820321B4F0DE8B64CF75181EC708D4F56A244A0E9A4AA33ED8B6A27962BE6", "hash_sha512": "7DF28E5D792F52270E51FF355EF3F067C84AAD90425F6287E4D7C9038F9D2B1195A416B742C3D190321641215158FE7244BF9664E401DA8E670AF5C943700485", "hash_ssdeep": "384:2DFv6/9BVUogQjfR+/kyF7rASHJwnhHVJPwWU273XWSjFWu5:2DBgBKoFQ/MHK2TXp5", "hash_imp": "E9E1589ED6F2469789346FC3BDABFCE5", "hash_pesha1": "E80BF2159DB6CC9D10B87FC1A8ED263444B9020E", "hash_pe256": "9F21FA1546849608346AA60553292B7E253698FF22B624D7327A2F2BC258FCD3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query User Utility", "meta_original_filename": "quser.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/8a56b2b043ed340ffeec3845498005ebf972af3b937340f0fba064ea014ab1bb/detection/", "output": "Display information about users logged on to the system.\r\n\r\nQUERY USER [username | sessionname | sessionid] [/SERVER:servername]\r\n\r\n username Identifies the username.\r\n sessionname Identifies the session named sessionname.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server to be queried (default is current).\r\n\r\n", "children": "powershell.exe", "error": "Invalid parameter(s)\r\nDisplay information about users logged on to the system.\r\n\r\nQUERY USER [username | sessionname | sessionid] [/SERVER:servername]\r\n\r\n username Identifies the username.\r\n sessionname Identifies the session named sessionname.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server to be queried (default is current).\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\quser.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "qwinsta.exe-1FF9B1AEED99DD811AA7E9749B707529": { "file_name": "qwinsta.exe", "file_path": "C:\\Windows\\SysWOW64\\qwinsta.exe", "hash_md5": "1FF9B1AEED99DD811AA7E9749B707529", "hash_sha1": "5C27E855F00FAA2DD5F2F0D4BF3BFBB9B2482808", "hash_sha256": "1644B3F0CDE757EDD7100243B5FBDDDE0A15F73041F5E666D11089BA07E9ED86", "hash_sha384": "98CF026518D533580498240728EE0DC97E9B7D352AF14DE69DD039CF830D399D607279DE86692F029389D8C00E0A88E4", "hash_sha512": "F91429603BFC33D90B14091B5054359DD46564767583E7868D9EB7253A8605CDDA0654B76036B029D9CA7F393FEA6EBDCBD313527418FB2EEF52A100E3D2C14A", "hash_ssdeep": "384:x+ku06aRM2jZFVfstBQS2jIj9o0U8xjFJSXZAg14ODPFWU27c7WR6Wxqf8:xQ0ZRDxszQS2bT32wyl", "hash_imp": "1234BA58D47CA5DA651AFE0A91CF2841", "hash_pesha1": "8C7B512A5120E45AFF1980E1DFB794474407EEBA", "hash_pe256": "BF79E54B76FCCC5A836B2CC52C4DF7599BC29F11A9EC5B269EAE21E25AADF9AF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query Session Utility", "meta_original_filename": "qwinsta.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/1644b3f0cde757edd7100243b5fbddde0a15f73041f5e666d11089ba07e9ed86/detection/", "output": "Display information about Remote Desktop Services sessions.\r\n\r\nQUERY SESSION [sessionname | username | sessionid]\r\n [/SERVER:servername] [/MODE] [/FLOW] [/CONNECT] [/COUNTER] [/VM]\r\n\r\n sessionname Identifies the session named sessionname.\r\n username Identifies the session with user username.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server to be queried (default is current).\r\n /MODE Display current line settings.\r\n /FLOW Display current flow control settings.\r\n /CONNECT Display current connect settings.\r\n /COUNTER Display current Remote Desktop Services counters information.\r\n /VM Display information about sessions within virtual machines.\r\n\r\n", "error": "Invalid parameter(s)\r\nDisplay information about Remote Desktop Services sessions.\r\n\r\nQUERY SESSION [sessionname | username | sessionid]\r\n [/SERVER:servername] [/MODE] [/FLOW] [/CONNECT] [/COUNTER] [/VM]\r\n\r\n sessionname Identifies the session named sessionname.\r\n username Identifies the session with user username.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server to be queried (default is current).\r\n /MODE Display current line settings.\r\n /FLOW Display current flow control settings.\r\n /CONNECT Display current connect settings.\r\n /COUNTER Display current Remote Desktop Services counters information.\r\n /VM Display information about sessions within virtual machines.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\qwinsta.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "rasautou.exe-4B0B29981F228F7CD6281AF298C0E6B6": { "file_name": "rasautou.exe", "file_path": "C:\\Windows\\SysWOW64\\rasautou.exe", "hash_md5": "4B0B29981F228F7CD6281AF298C0E6B6", "hash_sha1": "3A0AF8EB6E4E9C2B59495768FD016A4E23C1C466", "hash_sha256": "F5FE16960331D2CB819706BAA6E1935097CC09A843A4747FFBCD3C8E27ED1CD5", "hash_sha384": "BDF0A0AF5A277342A814528913398E69B7B4EBF9A134E538C915709C4B7AB46D66A738759C10042320DA5FFB7991426E", "hash_sha512": "806663DBEF0DA05E2911689DCE2A52BCC1BB497398027939B8238AA33312888775D89628C89608FCE393432428E04BDB03C943D1C126878003806DDC1A72AD2A", "hash_ssdeep": "384:tKILjqA5B9v4YCOSPQlxZuHfs2CWMBWlGB7wp:t7rQYof/s24sM7wp", "hash_imp": "6FD6CB5E209EBD24A870B74D8EE7F599", "hash_pesha1": "753BE8A7CA5DC598D61D25B8F8B1B7C921A418D4", "hash_pe256": "3ABA7A4E76F381145973EC81B0EDABFB4636C1B2A78FB87B5D5A8E9B44346083", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Access Dialer", "meta_original_filename": "rasdlui.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/f5fe16960331d2cb819706baa6e1935097cc09a843a4747ffbcd3c8e27ed1cd5/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\rasautou.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "output": "Usage: rasautou [-f phonebook] [-a address] [-e entry] [-s]\r\n" }, "rasdial.exe-116770FB23376B4B6DB1EC83702B5095": { "file_name": "rasdial.exe", "file_path": "C:\\Windows\\SysWOW64\\rasdial.exe", "hash_md5": "116770FB23376B4B6DB1EC83702B5095", "hash_sha1": "BC48CDF604824AA06DE7D99FEED73520EE17E65A", "hash_sha256": "974A95D16A089B476CA8F931CD0D5CD59C8061B04CCE8FFD423AAB555A1DFBE3", "hash_sha384": "5FE82B5DB09F54AC739D86478AA4340CD6BB93B8638D0B52CD160A81F908D0FA7E2BE72CE48EA032CCC4DB6571A8DDF6", "hash_sha512": "929C1C030DC8B1D47606F88F586E59929B6D126BE0190870885250034BF6F06E1D9EF29C29730AF02E80A0D64E4D23663C3EA5EE248646B414EBD1494DE59A64", "hash_ssdeep": "384:hzej6G9rUtmjYGFqR0XONQQ0Tf6WQVWTgK:drcq5QQAfccg", "hash_imp": "5C49C69DC9F9E8B85CB908313C7FCFF4", "hash_pesha1": "90E0D3A90870008D8468C2D225C4C2B2049D7775", "hash_pe256": "CB2B2B750AF5A4D20CABF7F10759A087216C840B81494D04013D19542F0FC941", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Access Command Line Dial UI", "meta_original_filename": "RASDIAL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/974a95d16a089b476ca8f931cd0d5cd59c8061b04cce8ffd423aab555a1dfbe3/detection/", "output": "USAGE:\n\tC:\\Windows\\SysWOW64\\rasdial.exe entryname [username [password|*]] [/DOMAIN:domain]\n\t\t[/PHONE:phonenumber] [/CALLBACK:callbacknumber]\n\t\t[/PHONEBOOK:phonebookfile] [/PREFIXSUFFIX]\n\n\tC:\\Windows\\SysWOW64\\rasdial.exe [entryname] /DISCONNECT\n\n\tC:\\Windows\\SysWOW64\\rasdial.exe\n\n\tPlease refer to our privacy statement at \n\t'https://go.microsoft.com/fwlink/?LinkId=521839'\n\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\rasdial.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "rasphone.exe-42B5CB0F2EC59AF2333C9141C33135A0": { "file_name": "rasphone.exe", "file_path": "C:\\Windows\\SysWOW64\\rasphone.exe", "hash_md5": "42B5CB0F2EC59AF2333C9141C33135A0", "hash_sha1": "BAED8BCF0D6CBF3DFAACD3C04E364983A27E12E2", "hash_sha256": "45453FDAD201A4699F6CCB1799A8B14041600CFBC77C3FF79FF9F7964BE89DDE", "hash_sha384": "817F7C5486FF894B98F8EE186ACDC932BF60A2D30A1802B7892258E3AFBA9DF5A4A2D0A28F1A968A6302F13F7308D678", "hash_sha512": "FCE0CAF9D0DF5CDF68523E4A090A2608BEB04AB936FC80C0EF931BCB7BA4A9DE0618467F8E0CA0277247BDC7C9A9A7E7EB8FF98D20C0A9CB6F7A348012A75EE4", "hash_ssdeep": "768:Pw5LCkWUbOtDMAIegg1lKm84gIg8vhcaGyfeD:iCkRMDhIVR7UFGys", "hash_imp": "1CE24F8D171D420DCF77580404DF2579", "hash_pesha1": "D8BED41993230DF5DB3664A1C961F493B4D2F521", "hash_pe256": "DA043D2C3CDF7B3EB42501BD8E6CD1E2B121B066FB25DD74B7996020C8BFC193", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Access Phonebook", "meta_original_filename": "rasphone.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/45453fdad201a4699f6ccb1799a8b14041600cfbc77c3ff79ff9f7964be89dde/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\rasphone.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\rasphone.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Dial-Up Networking Command Line" }, "rdpinit.exe-EEB9B254BE974EA12826F3441CC8B7F9": { "file_name": "rdpinit.exe", "file_path": "C:\\Windows\\SysWOW64\\rdpinit.exe", "hash_md5": "EEB9B254BE974EA12826F3441CC8B7F9", "hash_sha1": "153F4462CE812A1F355B4DA8C631558D30BBFFE1", "hash_sha256": "F9A9873DAA66B4B2D65B028CF17056DE94C988708FAE9260EFA64DDECFAAB1B4", "hash_sha384": "4A48E4BE1E1A38EB99560B81E2DB01D19A7C7E9D4B01DD6797678E1340C0ABAD0C1ADF55FF3902FE74019FFA2E77B1E0", "hash_sha512": "C070840A3794BEC7ACEAA45BFB661536239AE05C5963AEBCE3B13699CDAEFD50B3EB80A7B38A3F515C4C7D9F803C5507C8CE4137C14B5BFCB2B5FE14999103B6", "hash_ssdeep": "6144:fNiTmdIptKNX2OT6i3fZeAmoYlRcpNYHCuFRk0Fjcq:fSmdIptw2OTWAmJlRcbYHxRbFj", "hash_imp": "7FBE6508CE43599EDF48E660BC3E1D0E", "hash_pesha1": "5B8C77B71CF20528DCBAB55942A7AE85A556CED3", "hash_pe256": "D97D3135C9F955ED92EE301343040F16378A8B3FEB3DB52025EA280B49E5E3C1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RemoteApp Logon Application", "meta_original_filename": "rdpinit.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "RdpSa.exe-2B8CD41BBEECAB7F5962E1680C98C320": { "file_name": "RdpSa.exe", "file_path": "C:\\Windows\\SysWOW64\\RdpSa.exe", "hash_md5": "2B8CD41BBEECAB7F5962E1680C98C320", "hash_sha1": "1386224D84F08B7B3B915339C082F776E2F36D50", "hash_sha256": "BCB046625DB80875AF6732CEEF40BFBAF801875A1BE9E9D4D8B4C94111018E47", "hash_sha384": "63EE6BEF5AF1D5EC72960E926CE91D8AE023775EE9806C194EE527975180D8A6EDF6367DB998B00130871D304A0EB8E2", "hash_sha512": "D0C93D3DC02AC8C7995F495DE8E1B129187937189DB89D9C7C60DC052B76ACF96E4E8286758258137EC304138EAB825B3B50C1F38C04B4E35BE54CAA8ACE69ED", "hash_ssdeep": "768:9NBjOLW0RhoGQvaf52NOZcu1ugqREL58/:9vjOLPHo9vaf8E/qRK2", "hash_imp": "AA56A9F62AC8760D6F9C78B4CDE649FC", "hash_pesha1": "DFF5C3294324B525E16E545D603A9DC8E611C211", "hash_pe256": "6288B65B8A53F8226C2CADB6A1874CAF66B3B09D54F2AF6B727EF8BBC0A665E0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Agent", "meta_original_filename": "RdpSa.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/bcb046625db80875af6732ceef40bfbaf801875a1be9e9d4d8b4c94111018e47/detection/" }, "RdpSaProxy.exe-2947DF559BDB11FD255C05A4EAF361B8": { "file_name": "RdpSaProxy.exe", "file_path": "C:\\Windows\\SysWOW64\\RdpSaProxy.exe", "hash_md5": "2947DF559BDB11FD255C05A4EAF361B8", "hash_sha1": "93ED4B33F966CC08F031D8B87D18C27360AC6672", "hash_sha256": "112725AA0A890535231F201529CB5F382E5F00959F268A6A637818B74216D13C", "hash_sha384": "3943AC1EAA42298C2041DB743EE3F22596F9DAA7FA5CAE63D1594115A93BEC07ECD17FBE9D3956B7D3D96F8BCCB425FD", "hash_sha512": "6CA065C8CD00FEAEFBF02B609F3B4A48B6ACF56B47DDD804DD0CC6D9CEC92F6635A6A99C7AA89D0948BAA075C99FC2C2E5418808F9548ABB04734DD85B0D4176", "hash_ssdeep": "384:DWHcb1IjTeoxeuOgZ3RuXWCAEavz9xwJMxZFWWF9VWfbz:a01I/eoxew9RJCqxRZFHmb", "hash_imp": "52C8BEB74378C339317377944C96BDD7", "hash_pesha1": "751EB271E5CF2EFB5B83D1F44A595913CA073FE1", "hash_pe256": "17BADA9D0F1CD4BA6FF9551E477AF52BF2CDE99556C19D8D4C0262EB6541E54B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Agent Proxy", "meta_original_filename": "RdpSaProxy.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/112725aa0a890535231f201529cb5f382e5f00959f268a6a637818b74216d13c/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\RPC Control\\DSECE24": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\RdpSaProxy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RdpSaUacHelper.exe-95309FCD8BDC2AB2C45590BBA26BF5E1": { "file_name": "RdpSaUacHelper.exe", "file_path": "C:\\Windows\\SysWOW64\\RdpSaUacHelper.exe", "hash_md5": "95309FCD8BDC2AB2C45590BBA26BF5E1", "hash_sha1": "1B6B5E947E682806FDE6FC66D2926FA2604BF92E", "hash_sha256": "CBD3DBD850289F1888B4DC6884F0E5474063FE4D57E9F8BEF0B325F76284BBD6", "hash_sha384": "794DBE36DE06E0B5A44A8F1E8D0CAEA83CE7393667852E10352416AAC6FBA41E8D2C48FB5B4A18909ADEAD9BFFC98A5B", "hash_sha512": "E208882F22230FBFC82925FAB5DF65C1579AD0BD1AB2860BB5C6E803844D7C7DC5772D93B41DF9A468A6C35800B2789E765EE8292F90D79BC88DE460CD7691A5", "hash_ssdeep": "384:oQuhI4l7w+OVe6LkiOiGamZnWHiVBf7tkZky7fumIQcJGnZ/87YWWgWmNbx:opl7w+mjAiOYmZSiVBTg7k7GnZ/87MU", "hash_imp": "77810F2FCFA5731B3F60CA5339B7BD2D", "hash_pesha1": "6D55078667166FA302956560EE9B7988A0A40C34", "hash_pe256": "567FDF154BD16964992BC9FB379A5381C46B530664A1C25AF79E69A7236611CB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RDP Session Agent UAC Helper", "meta_original_filename": "RdpSaUacHelper.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/cbd3dbd850289f1888b4dc6884f0e5474063fe4d57e9f8bef0b325f76284bbd6/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\RdpSaUacHelper.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "rdpshell.exe-57398890C054387424BA518C1BB5CC33": { "file_name": "rdpshell.exe", "file_path": "C:\\Windows\\SysWOW64\\rdpshell.exe", "hash_md5": "57398890C054387424BA518C1BB5CC33", "hash_sha1": "A0684172570FE14168AD470A1F9CE004A4289C78", "hash_sha256": "B1BFB826A9E765AAAFEA339F585C4E66E7DD61673094ABAAAAC23E093C1374ED", "hash_sha384": "03D1772F668348032A6A4816A944EDE7921783A8B4CCC347E359C93D26004C5DD3DEF52EFB7FB4BAB7B14C5F6A81FD4D", "hash_sha512": "FE76DB8F9E0FFF527CF85D66CA570E41B7977A63C216518AD4533590E8E680513150A362B02BE2421E490FF691FAAD8B1579B020EBAB327337E804A47240D970", "hash_ssdeep": "6144:tSB/053CMox5gVkHcr3u331rfP2yX+Oxr/l268m/xz+:AXT5MbD+rO6r/lF8mxz", "hash_imp": "A00A1F5C000626FE86C2E86DE8433E26", "hash_pesha1": "CCBDA78C9A8E41725670DBF2115B4D31F7F52463", "hash_pe256": "9B4F5A3AA888FE7D450AF55F5A8498A87447113991DBC788829B11121F540865", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RemoteApp Shell", "meta_original_filename": "rdpshell.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "1/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/b1bfb826a9e765aaafea339f585c4e66e7dd61673094abaaaac23e093c1374ed/detection/" }, "rdpsign.exe-119E004E27AE94F130DC52060AAAE433": { "file_name": "rdpsign.exe", "file_path": "C:\\Windows\\SysWOW64\\rdpsign.exe", "hash_md5": "119E004E27AE94F130DC52060AAAE433", "hash_sha1": "AD87124EACAB4D64A728BB5972F9F73D5E7C7168", "hash_sha256": "64F5500E72011CAAF9B0F0B354163E89EE1656A15DA23959D3109BC1ED7FC36F", "hash_sha384": "1A4655E7D6D009B40CFC510E6D0B072636CB959B0CBA24E3D4771CFA3A4BC81378C35EDD6F34DFE528FB0F98E3E6F3B2", "hash_sha512": "B8AB154C91E8316AA21FD0C9284CE09F1238C284E8868F714F55C45AF8D07FA1B8EAFB4275C83ACCEC57D76226A818F96D300C2968772CE5D0C8ACD488CF38DF", "hash_ssdeep": "1536:ffAOMvFpee3Psl1RZxTFxGe0jjf7w4vejR2VQONdn:fflMvFpee/slHZj/ejc8ejR2mONdn", "hash_imp": "A8CB62E36E9F851D954E9757B540C497", "hash_pesha1": "1B87706EF5648FA813CD5159514109A15637C59E", "hash_pe256": "122D30882C8EB1D223CA9D4E04C0BB3520C17F6EE5D50D3A19D0D0B791215AF1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Session Host Server Sign Tool", "meta_original_filename": "TSSignTool.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/64f5500e72011caaf9b0f0b354163e89ee1656a15da23959d3109bc1ed7fc36f/detection/", "output": "All rdp file(s) have been succesfully signed.\r\n", "error": "NAME\r\n\r\nrdpsign [options] [items to sign]\r\n\r\nOPTIONS\r\n\r\n /sha256 HASH\r\n Specified the SHA256 hash of the signing certificate.\r\n /q\r\n Quiet mode: No output when success, minimal output when failed.\r\n /v\r\n Verbose mode: Display all warnings, messages, and status.\r\n /l\r\n Test signing and output results without actually replacing any of the inputs. Ignores when input files are on stdin.\r\n\r\n\r\n" }, "rdrleakdiag.exe-A44B52E1F19718E6C5CC4A3DF406E2A3": { "file_name": "rdrleakdiag.exe", "file_path": "C:\\Windows\\SysWOW64\\rdrleakdiag.exe", "hash_md5": "A44B52E1F19718E6C5CC4A3DF406E2A3", "hash_sha1": "EC8F78868D0BEF3780D0BE82B2975539B9844449", "hash_sha256": "20ADE22FA45A4BF6C0EF5C17B21E9661DB6AAC6968AED663349B27C4F3021961", "hash_sha384": "9DDC87B3F0B2825DCC5E24AB372B4DD77438C3E1CD877A8731AEFA81AECF33F8C204572C8D2793C6C9366B88156EE4A9", "hash_sha512": "E32E5A5EB98E4D282C32DB9EA878FF87111390D2733268C468209C448D7F9F2C03983DB5AEF733F5251EEBBD8A8C392B9B527741477EDEE3A92B1F74266BD954", "hash_ssdeep": "768:7heXra9e4GeB8yM/2Iy6/Nco2NVhIz6A:Q7aiemyKe6/Noh", "hash_imp": "26A323EA27CD8D60E52073979B67F593", "hash_pesha1": "75A7845D3068912236A74D51F67337261903C02C", "hash_pe256": "74AE6D2897BBC00FA35CE7C450091492F980F56A41D29CCC883F883ACB063219", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Resource Leak Diagnostic", "meta_original_filename": "RdrLeakDiag.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/20ade22fa45a4bf6c0ef5c17b21e9661db6aac6968aed663349b27c4f3021961/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\rdrleakdiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ReAgentc.exe-67118D8D0AD2EFE5009C0B1414E02B1C": { "file_name": "ReAgentc.exe", "file_path": "C:\\Windows\\SysWOW64\\ReAgentc.exe", "hash_md5": "67118D8D0AD2EFE5009C0B1414E02B1C", "hash_sha1": "9F74EE3AFD81EBFAEE407FF4C57C03A3C3CB4F69", "hash_sha256": "EF577D51307E12C4315C0504199B8A01175BF7E742D1CE4C4D41CAE4543D6AC4", "hash_sha384": "760E7A1FF5D2A9E910122A35E948F88B2029DE10C51359599491AF47958D3AD053DB2A61410A9843A24513888D537F0B", "hash_sha512": "0132C51FF958A50374BA23555FAB3573F0953E0391EB3BA80491FD1F0A474A57FC77E3D7945797A4E64B8F05118763E6090B479160DF3B4C0D8DDC6F215A1AC8", "hash_ssdeep": "384:/vPE/ltos9cPTPagDC46h+A3CE49mBkwPM+vwoAHw1w4DO04bl5+TuuNC+NpvqW9:/vPE/liCSA3MfHwnq+uEN5xyq", "hash_imp": "76D2AE3842F571E99D57B74E38981DD2", "hash_pesha1": "686FD1507E2F29811D8953E1D6F7520485C5F6FD", "hash_pe256": "EA7333A16A5264E03FAAB1AF1FE9DE274F6C43881728920243F3D646819DC414", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Recovery Agent", "meta_original_filename": "reagentc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/ef577d51307e12c4315c0504199b8a01175bf7e742d1ce4c4d41cae4543d6ac4/detection/", "output": "\r\nConfigures the Windows Recovery Environment (Windows RE) and system reset.\r\n\r\nREAGENTC.EXE <command> <arguments>\r\n\r\nThe following commands can be specified:\r\n\r\n /info - Displays Windows RE and system reset configuration\r\n information.\r\n /setreimage - Sets the location of the custom Windows RE image.\r\n /enable - Enables Windows RE.\r\n /disable - Disables Windows RE.\r\n /boottore - Configures the system to start Windows RE next time the\r\n system starts up.\r\n /setbootshelllink - Adds an entry to the Reset and Restore page in the boot\r\n menu.\r\n\r\nFor more information about these commands and their arguments, type\r\nREAGENTC.EXE <command> /?.\r\n\r\n Examples:\r\n REAGENTC.EXE /setreimage /?\r\n REAGENTC.EXE /disable /?\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ReAgentc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "\r\nConfigures the Windows Recovery Environment (Windows RE) and system reset.\r\n\r\nREAGENTC.EXE <command> <arguments>\r\n\r\nThe following commands can be specified:\r\n\r\n /info - Displays Windows RE and system reset configuration\r\n information.\r\n /setreimage - Sets the location of the custom Windows RE image.\r\n /enable - Enables Windows RE.\r\n /disable - Disables Windows RE.\r\n /boottore - Configures the system to start Windows RE next time the\r\n system starts up.\r\n /setbootshelllink - Adds an entry to the Reset and Restore page in the boot\r\n menu.\r\n\r\nFor more information about these commands and their arguments, type\r\nREAGENTC.EXE <command> /?.\r\n\r\n Examples:\r\n REAGENTC.EXE /setreimage /?\r\n REAGENTC.EXE /disable /?\r\n\r\n" }, "recover.exe-2B90F99E5723A85A1E2F4E321500C451": { "file_name": "recover.exe", "file_path": "C:\\Windows\\SysWOW64\\recover.exe", "hash_md5": "2B90F99E5723A85A1E2F4E321500C451", "hash_sha1": "D1E49EE7B38B25BA94DC216DB9959040D475FE25", "hash_sha256": "29F48C967EFD519B84C8FF518BF7F6CAFA13BB34D8FA9AF893C05A10197F3A34", "hash_sha384": "E8148A0A936094245E2315DFC79AC1C444E7713F119145CBA67D31AC7820145B4C66A9EFA92ACD4FF684C83D4D2B5EFD", "hash_sha512": "3065FE4F4FAAF223048B4961DA07BDFEB840FC49350BF634D5AC6D24ECAEB9CF8BF1BA5E6122646DD8830AC26DEB9DF1CCE9754C48F8BBB94D47E06C1C93F479", "hash_ssdeep": "192:P94R+sms/RBGk4NFOp+DWt2SHsk2TWPnWnhIBw9Go:+RYCR8kiFOpb2q2TWPnWhIi0o", "hash_imp": "CD8185705936323067B6715FDC1BF798", "hash_pesha1": "D79DA7D46E82B7DAAE37A34BAF6A859174F511F8", "hash_pe256": "4DBE05B38E4521574AF13F8935D56B3603A7D68465540FA7B3302A7493D1ACCB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Recover Files Utility", "meta_original_filename": "Recover.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/29f48c967efd519b84c8ff518bf7f6cafa13bb34d8fa9af893c05a10197f3a34/detection/", "output": "Recovers readable information from a bad or defective disk.\r\n\r\nRECOVER [drive:][path]filename\r\nConsult the online Command Reference in Windows Help\r\nbefore using the RECOVER command.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\ulib.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\recover.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "reg.exe-DACAC17455D4EEFE433B41BA82CD106F": { "file_name": "reg.exe", "file_path": "C:\\Windows\\SysWOW64\\reg.exe", "hash_md5": "DACAC17455D4EEFE433B41BA82CD106F", "hash_sha1": "F590419F8327BC2CAC08FBAC4D28E32EB3759B43", "hash_sha256": "E3046D83040D114AF09C6B7738F69B14EC180ECE999573489A7D3386E4ABABB5", "hash_sha384": "00F72475B9A809D48650F05FF3F6990BE84AAE6D161E655221C19864FC8DF56372661154538ED7898688ABEA4FC33029", "hash_sha512": "01F73139F1BF0A57A067F8E8B90604ED4B962A50767B294299EF02FD3547479DB661F3020EC8430315813B137F4C3CE45204ED755817F8FF16C5B54657073964", "hash_ssdeep": "1536:R5K+dgNJbFk/wvzA2m6rhoBC8yBt3DQBXvSvODF6fO:rKFJhk/wvznm63Bt3DQBX6vO562", "hash_imp": "869B9FF91668F96EF68FBE0DB3602587", "hash_pesha1": "6FEB8B9ACFC6ED0D1C8686733CAEAF9139B9B5D0", "hash_pe256": "D205DB536ED98E8DC737577ED3A85ABA49A0E557F5395DE10F7AC0CEDF30678A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Console Tool", "meta_original_filename": "reg.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/e3046d83040d114af09c6b7738f69b14ec180ece999573489a7d3386e4ababb5/detection/", "output": "\r\nREG Operation [Parameter List]\r\r\n\r\r\n Operation [ QUERY | ADD | DELETE | COPY |\r\r\n SAVE | LOAD | UNLOAD | RESTORE |\r\r\n COMPARE | EXPORT | IMPORT | FLAGS ]\r\r\n\r\r\nReturn Code: (Except for REG COMPARE)\r\r\n\r\r\n 0 - Successful\r\r\n 1 - Failed\r\r\n\r\r\nFor help on a specific operation type:\r\r\n\r\r\n REG Operation /?\r\r\n\r\r\nExamples:\r\r\n\r\r\n REG QUERY /?\r\r\n REG ADD /?\r\r\n REG DELETE /?\r\r\n REG COPY /?\r\r\n REG SAVE /?\r\r\n REG RESTORE /?\r\r\n REG LOAD /?\r\r\n REG UNLOAD /?\r\r\n REG COMPARE /?\r\r\n REG EXPORT /?\r\r\n REG IMPORT /?\r\r\n REG FLAGS /?\r\r\n", "error": "ERROR: Invalid Argument/Option - '--help'.\r\nType \"REG /?\" for usage.\r\n" }, "regedit.exe-092D4E7FA32499F18B879080AA994C46": { "file_name": "regedit.exe", "file_path": "C:\\Windows\\SysWOW64\\regedit.exe", "hash_md5": "092D4E7FA32499F18B879080AA994C46", "hash_sha1": "4375B47A094F329D75D36233098CE20F9883DDE0", "hash_sha256": "A9BFE5633CED879D8A94B66A06A294BC6D6EF466EAEE46AE4D25CB0E3A1D79A5", "hash_sha384": "74C69C9FE9FA94B6D2DAC1FF1B575563FF605ADE6C0B922470FC02F41BE1E25DD234F8B044C681B9B8A79A2818A78DE5", "hash_sha512": "9996121974FB41F0190E1CB94E8E243124CD475368B6381C491368D3731F19ADBFD450A4EA0B8D3DE66EC5A83D79CB09CA930F5DED746A877AF68D13675A5B26", "hash_ssdeep": "6144:6qoAOc6qKhTsywE2KBiBQRZ66z+n4VZbd8g79pgrXNgRnVLjyzhbkidNN2:6qvOFhg5KIQRZ66z24VZbdrpgrXN2LWr", "hash_imp": "C6E1B8202ADED47B7C2380A87886D20C", "hash_pesha1": "AC8E4DF25B2A578A4212B88F1F73EBF20DBD76C4", "hash_pe256": "A2C465D4D011BF9C55835647046EC90AE71E44B8CBAA38B0326C105E2B98D625", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Editor", "meta_original_filename": "REGEDIT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/a9bfe5633ced879d8a94b66a06a294bc6d6ef466eaee46ae4d25cb0e3a1d79a5/detection/", "children": "RdpSa.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\regedit.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\aclui.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\regedit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Registry Editor" }, "regedt32.exe-1F64004A05B6B683C49E877084CFF97E": { "file_name": "regedt32.exe", "file_path": "C:\\Windows\\SysWOW64\\regedt32.exe", "hash_md5": "1F64004A05B6B683C49E877084CFF97E", "hash_sha1": "FFA8C1F38BC6E162B586AB71D53A3D04689DD50D", "hash_sha256": "D575C86DD61B1B45314B2015A31A700E4636437F1B1738E60725119D68982603", "hash_sha384": "E3F7EF2291E0BCABCD9965A486C877B35896697310596214B4272A9C8A32B37E59A41C776C3D7B1D408C4F6E0C7BE8CB", "hash_sha512": "E3999CE0320A78877FB5B5D11D63770DE79DA29AACE754B0F13D126468E228F817AF1D766F4832F2989EA102E11E9D425256900CED5378A8225F77BBE0E1DFA9", "hash_ssdeep": "96:BQP6yb6/tfZO0ac95Ep2zyIRoVoxsDGjs0KtAtUFo3NVRrDJFMVW9EWaZhHWwD5L:BpCC39E2RowGAtUFo3NVRbEWQxWqF", "hash_imp": "FA8607DE86B3096660A35E6483D8EACA", "hash_pesha1": "AD73841707EA833215847C97CBE91D0155EFED2A", "hash_pe256": "3DD765D882A0872C9C55401DC880806B0E897184656555F367DE6E34B2F179B6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Editor Utility", "meta_original_filename": "regedt32.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/d575c86dd61b1b45314b2015a31a700e4636437f1b1738e60725119d68982603/detection/", "children": "regedit.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\regedt32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "regini.exe-8E9CB202467E209A7C4C5C15A7727DA2": { "file_name": "regini.exe", "file_path": "C:\\Windows\\SysWOW64\\regini.exe", "hash_md5": "8E9CB202467E209A7C4C5C15A7727DA2", "hash_sha1": "921F415DA47760A3D885FEC0A31472BAD2210605", "hash_sha256": "40ED5EE39901B8537BCBC487B939ED7F50EC3A86EAF248DB1783641DAA0E47C9", "hash_sha384": "C11A59BEC2AA9E5B920CC20876D3A0A3D288A2A3097239C05BAA4523ECD30540444BD6A88A71EF35AE648A1771590565", "hash_sha512": "D7E0911BD62A451C7A6B58122D3B38C9A5DF9B58FE62359F2AE156B41E9C17D804A68DBB75A08311C8AE715E13A85771CA9966FDA1FA87A85103248ECD2732EE", "hash_ssdeep": "768:CvGV2EIgkhyil4RBDxJuAQx40tmVbIPwUWee6cNPYb5JcQHgUWvt4QmODDIxW:C5ERDxJubwbIBWee60PYlJEUWveSDsW", "hash_imp": "5356BCBDA656EB8E0846EEAF52BE48B1", "hash_pesha1": "BAF09B72C54DED857E29FB708ED3C91AA0B825ED", "hash_pe256": "44E9A114FA5A0856FE7BFE626E6F207E13DE54AB7F4092A530BA799B150583F7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Initializer", "meta_original_filename": "REGINI.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/40ed5ee39901b8537bcbc487b939ed7f50ec3a86eaf248db1783641daa0e47c9/detection/", "error": "usage: REGINI [-m \\\\machinename | -h hivefile hiveroot]\r\n [-i n] [-o outputWidth]\r\n [-b] textFiles...\r\n\r\nwhere: -m specifies a remote Windows NT machine whose registry is to be manipulated.\r\n -h specifies a specify local hive to manipulate.\r\n -i n specifies the display indentation multiple. Default is 4\r\n -o outputWidth specifies how wide the output is to be. By default the\r\n outputWidth is set to the width of the console window if standard\r\n output has not been redirected to a file. In the latter case, an\r\n outputWidth of 240 is used.\r\n\r\n -b specifies that REGINI should be backward compatible with older\r\n versions of REGINI that did not strictly enforce line continuations\r\n and quoted strings Specifically, REG_BINARY, REG_RESOURCE_LIST and\r\n REG_RESOURCE_REQUIREMENTS_LIST data types did not need line\r\n continuations after the first number that gave the size of the data.\r\n It just kept looking on following lines until it found enough data\r\n values to equal the data length or hit invalid input. Quoted\r\n strings were only allowed in REG_MULTI_SZ. They could not be\r\n specified around key or value names, or around values for REG_SZ or\r\n REG_EXPAND_SZ Finally, the old REGINI did not support the semicolon\r\n as an end of line comment character.\r\n \r\n textFiles is one or more ANSI or Unicode text files with registry data.\r\n \r\n Some general rules are:\r\n Semicolon character is an end-of-line comment character, provided it\r\n is the first non-blank character on a line\r\n \r\n Backslash character is a line continuation character. All\r\n characters from the backslash up to but not including the first\r\n non-blank character of the next line are ignored. If there is more\r\n than one space before the line continuation character, it is\r\n replaced by a single space.\r\n \r\n Indentation is used to indicate the tree structure of registry keys\r\n The REGDMP program uses indentation in multiples of 4. You may use\r\n hard tab characters for indentation, but embedded hard tab\r\n characters are converted to a single space regardless of their\r\n position\r\n \r\n Values should come before child keys, as they are associated with\r\n the previous key at or above the value's indentation level.\r\n \r\n For key names, leading and trailing space characters are ignored and\r\n not included in the key name, unless the key name is surrounded by\r\n quotes. Imbedded spaces are part of a key name.\r\n \r\n Key names can be followed by an Access Control List (ACL) which is a\r\n series of decimal numbers, separated by spaces, bracketed by a\r\n square brackets (e.g. [8 4 17]). The valid numbers and their\r\n meanings are:\r\n \r\n 1 - Administrators Full Access\r\n 2 - Administrators Read Access\r\n 3 - Administrators Read and Write Access\r\n 4 - Administrators Read, Write and Delete Access\r\n 5 - Creator Full Access\r\n 6 - Creator Read and Write Access\r\n 7 - World Full Access\r\n 8 - World Read Access\r\n 9 - World Read and Write Access\r\n 10 - World Read, Write and Delete Access\r\n 11 - Power Users Full Access\r\n 12 - Power Users Read and Write Access\r\n 13 - Power Users Read, Write and Delete Access\r\n 14 - System Operators Full Access\r\n 15 - System Operators Read and Write Access\r\n 16 - System Operators Read, Write and Delete Access\r\n 17 - System Full Access\r\n 18 - System Read and Write Access\r\n 19 - System Read Access\r\n 20 - Administrators Read, Write and Execute Access\r\n 21 - Interactive User Full Access\r\n 22 - Interactive User Read and Write Access\r\n 23 - Interactive User Read, Write and Delete Access\r\n \r\n If there is an equal sign on the same line as a left square bracket\r\n then the equal sign takes precedence, and the line is treated as a\r\n registry value. If the text between the square brackets is the\r\n string DELETE with no spaces, then REGINI will delete the key and\r\n any values and keys under it.\r\n \r\n For registry values, the syntax is:\r\n \r\n value Name = type data\r\n \r\n Leading spaces, spaces on either side of the equal sign and spaces\r\n between the type keyword and data are ignored, unless the value name\r\n is surrounded by quotes. If the text to the right of the equal sign\r\n is the string DELETE, then REGINI will delete the value.\r\n \r\n The value name may be left off or be specified by an at-sign\r\n character which is the same thing, namely the empty value name. So\r\n the following two lines are identical:\r\n \r\n = type data\r\n @ = type data\r\n \r\n This syntax means that you can't create a value with leading or\r\n trailing spaces, an equal sign or an at-sign in the value name,\r\n unless you put the name in quotes.\r\n \r\n Valid value types and format of data that follows are:\r\n \r\n REG_SZ text\r\n REG_EXPAND_SZ text\r\n REG_MULTI_SZ \"string1\" \"str\"\"ing2\" ...\r\n REG_DATE mm/dd/yyyy HH:MM DayOfWeek\r\n REG_DWORD numberDWORD\r\n REG_BINARY numberOfBytes numberDWORD(s)...\r\n REG_NONE (same format as REG_BINARY)\r\n REG_RESOURCE_LIST (same format as REG_BINARY)\r\n REG_RESOURCE_REQUIREMENTS (same format as REG_BINARY)\r\n REG_RESOURCE_REQUIREMENTS_LIST (same format as REG_BINARY)\r\n REG_FULL_RESOURCE_DESCRIPTOR (same format as REG_BINARY)\r\n REG_QWORD numberQWORD\r\n REG_MULTISZ_FILE fileName\r\n REG_BINARYFILE fileName\r\n \r\n If no value type is specified, default is REG_SZ\r\n \r\n For REG_SZ and REG_EXPAND_SZ, if you want leading or trailing spaces\r\n in the value text, surround the text with quotes. The value text\r\n can contain any number of imbedded quotes, and REGINI will ignore\r\n them, as it only looks at the first and last character for quote\r\n characters.\r\n \r\n For REG_MULTI_SZ, each component string is surrounded by quotes. If\r\n you want an imbedded quote character, then double quote it, as in\r\n string2 above.\r\n \r\n For REG_BINARY, the value data consists of one or more numbers The\r\n default base for numbers is decimal. Hexidecimal may be specified\r\n by using 0x prefix. The first number is the number of data bytes,\r\n excluding the first number. After the first number must come enough\r\n numbers to fill the value. Each number represents one DWORD or 4\r\n bytes. So if the first number was 0x5 you would need two more\r\n numbers after that to fill the 5 bytes. The high order 3 bytes\r\n of the second DWORD would be ignored.\r\n \r\n Whenever specifying a registry path, either on the command line\r\n or in an input file, the following prefix strings can be used:\r\n \r\n HKEY_LOCAL_MACHINE\r\n HKEY_USERS\r\n HKEY_CURRENT_USER\r\n USER:\r\n \r\n Each of these strings can stand alone as the key name or be followed\r\n a backslash and a subkey path.\r\n\r\n\r\nREGINI: Missing parameter(s) for -h switch\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\regini.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Register-CimProvider.exe-04073FE74835F8FD8822E1568C98F42A": { "file_name": "Register-CimProvider.exe", "file_path": "C:\\Windows\\SysWOW64\\Register-CimProvider.exe", "hash_md5": "04073FE74835F8FD8822E1568C98F42A", "hash_sha1": "8FA520CF46BFAAAFEC909F2F979F098C4C281E83", "hash_sha256": "11FC84778B6B88DDE720B4B84354A64F3256BE6149CD5F558350BB3F5CE8C204", "hash_sha384": "C5A9466528D2F5CEEF1053B81FFCC220B3A89D166EA912DE68214C107A619ED5D416043FFAC8F382C45DA8CE0EA004F3", "hash_sha512": "9DB6FAA3FDEF57E758EC8CB62193F855C9E12C355A95EC7B77783EC84C822A61B9711B7D0C3AA3A3F95C9D6DCD2307A65A91048475CC5FF778552D1A1086B53F", "hash_ssdeep": "384:s6xOg6dVw4VUQh8BOzxg4b1x5qQkwQcQGVjeeM4KbxQWV1WYRQp:sDiFQHx5VcGheeM4Mx7W", "hash_imp": "0FB0548A3D9D48194DC4FA7F08F5D988", "hash_pesha1": "58A819B80A6B982B2B8CBB78AE60A135B470EF6B", "hash_pe256": "1873452BFAD347C5B08F0C9F9C8BDA6A45C044455D9C03E93392BD300F4AC592", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI", "meta_original_filename": "Register-CimProvider2.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/11fc84778b6b88dde720b4b84354a64f3256be6149cd5f558350bb3f5ce8c204/detection/", "output": "\r\nRegisters CIM Provider into system\r\n\r\nUsage: Register-CimProvider.exe\r\n\t\t-Namespace <NamespaceName>\r\n\t\t-ProviderName <ProviderName>\r\n\t\t-Path <ProviderDllPath>\r\n\t\t[-ClassList <Space delimited list of white-listed classes>]\r\n\t\t[-Impersonation <True or False>]\r\n\t\t[-Decoupled <SDDL>]\r\n\t\t[-HostingModel <HostingModel>]\r\n\t\t[-Localize <locale>]\r\n\t\t[-NoAutorecover]\r\n\t\t[-SupportWQL]\r\n\t\t[-GenerateUnregistration]\r\n\t\t[-ForceUpdate]\r\n\t\t[-Verbose]\r\n\r\n-Namespace <NamespaceName>\r\n\tSpecifies the target namespace of the provider.\r\n\r\n-ProviderName <ProviderName>\r\n\tSpecifies the provider name.\r\n\r\n-Path <ProviderDllPath>\r\n\tSpecifies the provider binary path.\r\n\r\n-Impersonation <True or False>\r\n\tSpecifies foldidentity of decoupled provider, by default is True.\r\n\r\n-Decoupled <SDDL>\r\n\tRegisters provider as decoupled and specifies the security descriptor\r\n\tthat determines the set of users that can successfully register\r\n\tthe provider.\r\n\r\n-HostingModel <HostingModel>\r\n\tSpecifies the HostingModel of coupled provider.\r\n\r\n-Localize <locale>\r\n\tLocalizes the provider with resource of specified locale.\r\n\r\n-NoAutorecover\r\n\tDoesn't autorecover the provider.\r\n\r\n-SupportWQL\r\n\tPasses the query expression to the filter.\r\n\r\n-GenerateUnregistration\r\n\tGenerate the uninstall mof for the registration,\r\n\twhich is disabled by default.\r\n\r\n-ForceUpdate\r\n\tForce update the class if it exists in the system.\r\n\r\n-ClassList <ProviderDllPath>\r\n\tSpecifies space delimited list of white-listed classes that\r\n\twill be generated in the mof.\r\n\r\n-Verbose\r\n\tOutputs registration log.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Register-CimProvider.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "regsvr32.exe-4D97D6FC07642D4F744C8C59DB674302": { "file_name": "regsvr32.exe", "file_path": "C:\\Windows\\SysWOW64\\regsvr32.exe", "hash_md5": "4D97D6FC07642D4F744C8C59DB674302", "hash_sha1": "CE09FA2A1DD10D0F675A1F0513F3C4EE4D7C3AC0", "hash_sha256": "E0E722A00C127E0425D2078E738B7A684C9F55A9BF521C67E9A40D796C8BE0E9", "hash_sha384": "31DD74D86D9A47B906E0C2AA1CA595F2F41C21A993520B8468F9C73713EEEA214EAB24AA72DA7665BCE9CFC132F17447", "hash_sha512": "0A4D3C22056FF19F37DCF9A0443B07D1D8F74BA4FF8A2795103F4D78E54D2F9A935117B0F193F93FB760E7437771BBFA9DDAFA5F68DBFED10A7CB42C50CB79D0", "hash_ssdeep": "384:wte9jI+ixZu70NgDGLQQgykkskgSQlUPxAOWrnLHW0uv:k8exZYXS4UPSLXs", "hash_imp": "99BBF1337F3DA5CFAB67854DF4ADE1D8", "hash_pesha1": "5DBB559ACDB6630C1A32551482E963483DBFFD88", "hash_pe256": "D5AB93A0D8A06BC8F2DA1068053233AD5FA69D1D0BECF1CD222ADED924D23873", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft(C) Register Server", "meta_original_filename": "REGSVR32.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e0e722a00c127e0425d2078e738b7a684c9f55a9bf521c67e9a40d796c8be0e9/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\regsvr32.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\regsvr32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "RegSvr32" }, "rekeywiz.exe-792769FDE307FA0D6B125CCAF4F6AEBB": { "file_name": "rekeywiz.exe", "file_path": "C:\\Windows\\SysWOW64\\rekeywiz.exe", "hash_md5": "792769FDE307FA0D6B125CCAF4F6AEBB", "hash_sha1": "3DA09A128E10C6C3423BC47C39A7940EC0D297DF", "hash_sha256": "9A42EBD4ABF86FFEF637D63FA8445D582EA720BB59D81713A23D918414D9EFC5", "hash_sha384": "CF6865E661618B5C812C5FF88B7782E133D026C5BC6DE724743250E9D4B34929F5FA526C542AEF1356B42A341173F2DC", "hash_sha512": "2501A4FFF1A05F57D70137C7A0D9E309965EDEAA7F6914FE9EBCE61753FDC038C7DC59279F914FC4228B2ADF3EA9749E39745649351EAD1D908F99DF9FF480F2", "hash_ssdeep": "3072:BvktTME7iN2ZBPPkJ4LXmCMdvWBx9zJNXgcH7f1I1BtDrfJt7BBd+I:ZcME7224gSJt7BBd", "hash_imp": "E267EC5FE7CB82D11E7C8F3E2763D776", "hash_pesha1": "12C17CE4AA339C25532527981A45E14E614665A9", "hash_pe256": "09E53E9E58FE654BBD8C03464205B3FC252F1CC7C05679305D23944BC554B149", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "EFS REKEY wizard", "meta_original_filename": "rekeywiz.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/9a42ebd4abf86ffef637d63fa8445d582ea720bb59d81713a23d918414d9efc5/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\rekeywiz.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\efsadu.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\rekeywiz.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Encrypting File System" }, "relog.exe-6DA2830D30B8F7A246AC8BA77D9B07AA": { "file_name": "relog.exe", "file_path": "C:\\Windows\\SysWOW64\\relog.exe", "hash_md5": "6DA2830D30B8F7A246AC8BA77D9B07AA", "hash_sha1": "602CB7D2DDE90F80AB0A22213DB1AA1588AE5D8B", "hash_sha256": "74F5B521D214D9DBBDFBB46F2124B87B9585098AC68A23C6FF101055E7A1C3B3", "hash_sha384": "7B41025DFB4CE2162E35AF118401B18582668734329290D15014BE04E1DB021217286E01F3F1F7F73DD3E48643CF2D95", "hash_sha512": "9EE647451ADEF60323531941C863654A9C4D05E803B680BFC7CFB16D4AADF86BB97E507CF0E46ECFC9D1F3F7A27ACD28E798C7801DC6933B2218C49431E43F59", "hash_ssdeep": "768:vzdUhTX4I/Y8bPgtS1S4Y+SH5KiNdiDNVbtpFGPm+v6E22MkiQXtn:vzeB4m4OY+SEpD9pFGPF6E2MiQXh", "hash_imp": "5712881CA4CBAAD4AB8F619CFA1616DF", "hash_pesha1": "24EBADDDA5FBFE670F1A8F53C7C501B9A15BB450", "hash_pe256": "ADC19BEDC70262136C254E6A740607AC7777CA991A1B63C0340F2856F8092D59", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Performance Relogging Utility", "meta_original_filename": "Relog.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/74f5b521d214d9dbbdfbb46f2124b87b9585098ac68a23c6ff101055e7a1c3b3/detection/", "output": "\r\nMicrosoft r Relog.exe (10.0.17763.1)\r\n\r\nRelog\r\ncreates\r\nnew\r\nperformance logs from data in existing performance logs by changing the sampling rate and/or converting the file format. Supports all performance log formats, including Windows NT 4.0 compressed logs.\r\n\r\nUsage:\r\nC:\\Windows\\SysWOW64\\relog.exe <filename [filename ...]> \r\n [options]\r\n\r\nParameters:\r\n <filename [filename ...]> Performance file to relog.\r\n\nOptions:\r\n -? Displays context sensitive help.\r\n -a Append output to the existing binary file.\r\n -c <path [path ...]> Counters to filter from the input log.\r\n -cf <filename> File listing performance counters to filter\r\n from the input log. Default is all counters\r\n in the original log file.\r\n -f <CSV|TSV|BIN|SQL> Output file format.\r\n -t <value> Only write every nth record into the output\r\n file. Default is to write every record.\r\n -o Output file path or SQL database.\r\n -b <M/d/yyyy h:mm:ss[AM|PM]> Begin time for the first record to write into\r\n the output file.\r\n -e <M/d/yyyy h:mm:ss[AM|PM]> End time for the last record to write into\r\n the output file.\r\n -config <filename> Settings file containing command options.\r\n -q List performance counters in the input file.\r\n -y Answer yes to all questions without prompting.\r\n\r\nExamples:\r\n relog logfile.csv -c \"\\Processor(_Total)\\% Processor Time\" -o logfile.blg\r\n relog logfile.blg -cf counters.txt -f bin\r\n relog logfile.blg -f csv -o logfile.csv -t 2\r\n relog logfile.blg -q -o counters.txt\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\relog.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "replace.exe-A467AFEB15D2301BC29E3F55CF9FB60B": { "file_name": "replace.exe", "file_path": "C:\\Windows\\SysWOW64\\replace.exe", "hash_md5": "A467AFEB15D2301BC29E3F55CF9FB60B", "hash_sha1": "5DCAF91CEF46C9074ED0440933E7FE21B9377F2F", "hash_sha256": "084B1740D0AFA302D7EB48AF224A7346252BEDFBC3CD46FEAF42F89269F1A1A5", "hash_sha384": "0740D5909B1EFED284A0123F7B211499D131205C8BFBC665D823DD1EC054BD7385539B7148631683FFB2D8F328B364AC", "hash_sha512": "9B15E137F61E3F8B58FE8AC87EB62446A447D003BE4F25E046B9CE9411353783B5BAF6D7689122EF9AEAB6A024FA27C72AB85D882CC7B0C9AA081E58181A7E45", "hash_ssdeep": "384:tfLph00yJ59m5nbllwPdJ9dAnl1g59TldWRh/W90p:tfL70hjmhb3wPz9brlg1", "hash_imp": "C4BFBBAC6078657DEBCDC17AF465AECD", "hash_pesha1": "D7197832AFEA6D488FD1B1193F9C753CA9AF4BC0", "hash_pe256": "5953DFAE5DBC53AF5CB4B526B2B05E36A7DACE5D01E560DDD5937B51E5034754", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Replace File Utility", "meta_original_filename": "REPLACE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/084b1740d0afa302d7eb48af224a7346252bedfbc3cd46feaf42f89269f1a1a5/detection/", "output": "Replaces files.\r\n\r\nREPLACE [drive1:][path1]filename [drive2:][path2] [/A] [/P] [/R] [/W]\r\nREPLACE [drive1:][path1]filename [drive2:][path2] [/P] [/R] [/S] [/W] [/U]\r\n\r\n [drive1:][path1]filename Specifies the source file or files.\r\n [drive2:][path2] Specifies the directory where files are to be\r\n replaced.\r\n /A Adds new files to destination directory. Cannot\r\n use with /S or /U switches.\r\n /P Prompts for confirmation before replacing a file or\r\n adding a source file.\r\n /R Replaces read-only files as well as unprotected\r\n files.\r\n /S Replaces files in all subdirectories of the\r\n destination directory. Cannot use with the /A\r\n switch.\r\n /W Waits for you to insert a disk before beginning.\r\n /U Replaces (updates) only files that are older than\r\n source files. Cannot use with the /A switch.\r\n", "error": "Invalid switch - --help\r\n" }, "reset.exe-8459B5D2B47AB266516A26D9DD080979": { "file_name": "reset.exe", "file_path": "C:\\Windows\\SysWOW64\\reset.exe", "hash_md5": "8459B5D2B47AB266516A26D9DD080979", "hash_sha1": "71614B0B7D2B57E3FA63AFF933781415F2A3D54C", "hash_sha256": "EF8641FDCBC876E51CEAA2FFF825D3E25A57B8694433FFF58588A6F35FA17908", "hash_sha384": "FB45813646F3DB2EF0B3280EB445F2ECE99BBE1EB4E89EDF0D8AB5CF9F3E26DBC4D183DD182FFB4D4AA97CE2C929D9D3", "hash_sha512": "6F2EB544B32C8AF136C722B8EE608CD4B23B17BC4022E765F352D8EA6507D0D6DD434CBCF16D3CA717125807D7F1CE274178E23392A96B636AFBB094565AEBE4", "hash_ssdeep": "192:1YzogF5/eyf1wzT4Fce1pN/1mt2Wco5kqWQgWF8:sVDGyf1wzT4ieh/1qlOqWQgW", "hash_imp": "EC309FD93AE54D1FFDF17E744E71C366", "hash_pesha1": "8A8AA0C303E5643FE962D2A44D7F8BF3F4C2FFA4", "hash_pe256": "94CD208B53764EE03B1AEB4109F703B4C3C1400512FBAF322020D03957ABBBD6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Services Reset Utility", "meta_original_filename": "reset.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/ef8641fdcbc876e51ceaa2fff825d3e25a57b8694433fff58588a6f35fa17908/detection/", "output": "RESET { SESSION }\r\n", "error": "Invalid parameter(s)\r\nRESET { SESSION }\r\n" }, "resmon.exe-C182C3463D5E5DFFED8F949D2BB781D3": { "file_name": "resmon.exe", "file_path": "C:\\Windows\\SysWOW64\\resmon.exe", "hash_md5": "C182C3463D5E5DFFED8F949D2BB781D3", "hash_sha1": "91C8BA668F5990B610C84EF714D80E5EFAA9449B", "hash_sha256": "10D4937D6D559D7B445AF08DFCDC953BDB9079E78C02C3C54BF4343499FB66E5", "hash_sha384": "E05B03BA0FFF12CF84195D9F1D11894E6A079B0A83F9E64BE1677FE7C99FB2F320337FF3E309D935877DFD42B9A5EE2B", "hash_sha512": "49D9CB1FDB8199484BFA947F0849386558A2F406E45FD7CDC6C98346CEFF1FA944FB2B08C3A0ABA7972E2EB282D53D590E23968B5EE0E77360F017664DF8E613", "hash_ssdeep": "1536:xbsHBqY3KtrtizIo9plJSs9kYuZJnGZLzOcE6Ls7HXG84PK05Z34g/CO+sH:xwHghtYIo9piswTogiqQKy349", "hash_imp": "86521711CB1F214E18EA188295368818", "hash_pesha1": "0D0CCCAEC859CA5219ED5413C0CAC46329C306C7", "hash_pe256": "2C36E1EFD96C9B896E62798BA0C137F23F5F298BF1846E70B0D8649F1B1C5563", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Resource Monitor", "meta_original_filename": "resmon.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/10d4937d6d559d7b445af08dfcdc953bdb9079e78c02c3c54bf4343499fb66e5/detection/", "children": "perfmon.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\resmon.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RMActivate.exe-F3C14E99DD1854F66EC94B389FF6AB1A": { "file_name": "RMActivate.exe", "file_path": "C:\\Windows\\SysWOW64\\RMActivate.exe", "hash_md5": "F3C14E99DD1854F66EC94B389FF6AB1A", "hash_sha1": "A266D5B561EB31AE4C7F56C1A239B0263F265667", "hash_sha256": "9162B0FF6453363794763BFCF06BD80F560780A20F8A2B590BAE987034F3A48E", "hash_sha384": "A35AF18CCE1FC7C233092A712D46BCD0852BBB7E0B13239C99183A851F154E428E037FE8F6934258A15E20C7A8C9327B", "hash_sha512": "6692205E8ADC7879A5D36842A66D8C2E4876B4F15BAEFD4D661367162BBF23439B59AEFC9039372C338F6484482C2609EE91F2EABA8D7962088DD1F056B8C07F", "hash_ssdeep": "12288:dcbjRXYik0+0TAFJ/m2lmdfk8/ZdZpECITu8tutVNf/yTlZ3:2jFj7+xD/mGmdfk8/ZREbu8tutPXyZZ3", "hash_imp": "EBCDFF4FE394A3E0CD90455A8A72EF29", "hash_pesha1": "051305F4D35DDC2CDB732765144D4485C2607FC6", "hash_pe256": "DD9ED24EA508B5EE0A2731882FEDD88B83C462F9BA220E54F8D8096957086070", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Desktop Security Processor", "meta_original_filename": "rmactivate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/9162b0ff6453363794763bfcf06bd80f560780a20f8a2b590bae987034f3a48e/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\crypt32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\RMActivate.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RMActivate_isv.exe-572D9CEE80416DBDAB2D3BC3FEB6A4F2": { "file_name": "RMActivate_isv.exe", "file_path": "C:\\Windows\\SysWOW64\\RMActivate_isv.exe", "hash_md5": "572D9CEE80416DBDAB2D3BC3FEB6A4F2", "hash_sha1": "49A3CCFDF64E6D0D02246C3724D9D412324E48C4", "hash_sha256": "F983D1A5EAA26F8300DC6D8CC7B15782E6F0BF3F7B3A57C845BC4B2C470E0879", "hash_sha384": "C6723EB5273D37731CA94759D8CCA7769E5E901E8E2159579CE5BA421462EAD7FEA995BE67DF380C709BAF7DBA4395E3", "hash_sha512": "BCE6F0C4BE19119CE5C731A9FD5ACAD340B466494F096B29961D2F0D929B0775D97A892AD2177B6DD308F3503F06B516ACBCDE2DCA3BF48939F70DF596560994", "hash_ssdeep": "12288:HDV+9MjWE/1pLKDRXbEh6OwhKUWr8D0oDpJ2QbMS/Qs4HnTs12vROdBie42WoQD:jV+9MjbpLqpyfUWYDXDpJ2qMS/YTsUOs", "hash_imp": "EBCDFF4FE394A3E0CD90455A8A72EF29", "hash_pesha1": "AE5EE9B9EF255397FF3418452716188F985A97B8", "hash_pe256": "FC9C9BAF65283983794F1AC6FD05682AEAA1B84599C2A4F1A99791541E05DAB5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Desktop Security Processor", "meta_original_filename": "rmactivate.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/f983d1a5eaa26f8300dc6d8cc7b15782e6f0bf3f7b3a57c845bc4b2c470e0879/detection/", "children": "conhost.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\RMActivate_isv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RMActivate_ssp.exe-3581D88D48A6B744CC1B1670287ABD99": { "file_name": "RMActivate_ssp.exe", "file_path": "C:\\Windows\\SysWOW64\\RMActivate_ssp.exe", "hash_md5": "3581D88D48A6B744CC1B1670287ABD99", "hash_sha1": "D96BA2A904A64B4CD24E0BDEE5DDA1490003736E", "hash_sha256": "B437FEC40DBCD4105EED821FF75BA7EEA5145BAE15783701AE09D52F31DB3E98", "hash_sha384": "2CBAA4153729145834190FE7562DED06357FF618EB851C79FCC722265CE3A35BDDB7FEA7903E11A92561EE11EE7BC5D8", "hash_sha512": "B5BE64B4B6989F676E7ED841F6F5E88A24534B67393C43738D6BD4B6C9271D5FB490949C6D00BBA30637EBF631F63B269FE1029D631AA6612A3E92B32F027572", "hash_ssdeep": "12288:E5rihVY+H388+34E7oYX7Uu9iLZUBzKUC:ExAVY+H38D3RoYou9iLZUBzKUC", "hash_imp": "7E5FF848353E2487D8DE47C6573CC310", "hash_pesha1": "4D6E086ED9EA8582E94E117E5116D3926157427D", "hash_pe256": "E94AC079A11767BFDFD263C3D6C1D3FE5D877FCBAD91C162CFD82DA9AF6849BA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Server Security Processor", "meta_original_filename": "rmactivate_ssp.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b437fec40dbcd4105eed821ff75ba7eea5145bae15783701ae09d52f31db3e98/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\RMActivate_ssp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RMActivate_ssp_isv.exe-524C7A31A75638AE2B921338157B6C48": { "file_name": "RMActivate_ssp_isv.exe", "file_path": "C:\\Windows\\SysWOW64\\RMActivate_ssp_isv.exe", "hash_md5": "524C7A31A75638AE2B921338157B6C48", "hash_sha1": "BB91C60FB8187A043EDDCBF247F1EC9EA8D032A5", "hash_sha256": "29BD8C3471B341CA78B9C2612DE89CE3558A3CD07D675995000E0B3C79B05509", "hash_sha384": "3A99003840710B45185CF844692E998946445F110C7B1111CDDDEDF347982A0A933EEB530354275716811468ACB6FEE1", "hash_sha512": "D654AFFC19CF14B9F973A2A529BE53DD95967A6B82EC358E90F11CBB06001F194A914316E73D8FAF2E6FC89B0F8C20CCA1DE2FE09652F1970A12021EBDA6E399", "hash_ssdeep": "12288:oCVhJzivvvk13ntYeHczJsGYjA004B6RgmDFbnRWvrBY9zihL2W:BrJziy3ntdHoWGYjA004B6RnDFbRoBaY", "hash_imp": "7E5FF848353E2487D8DE47C6573CC310", "hash_pesha1": "7E5DC74E4EFCE0EFB7D823C92CC91F93B1B1AEC3", "hash_pe256": "64875464DCC5B35D1F29C43561259CFF7B07DC0CDEF61530224F0C6C8D34A1E6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Rights Management Services Activation for Server Security Processor (Pre-production)", "meta_original_filename": "rmactivate_ssp_isv.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/29bd8c3471b341ca78b9c2612de89ce3558a3cd07d675995000e0b3c79b05509/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\RMActivate_ssp_isv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RmClient.exe-E6BECD6BB535D6E6750A247398B87CEA": { "file_name": "RmClient.exe", "file_path": "C:\\Windows\\SysWOW64\\RmClient.exe", "hash_md5": "E6BECD6BB535D6E6750A247398B87CEA", "hash_sha1": "60774D16A37742C57FE9A758FD16AA6B94881B6E", "hash_sha256": "1AAA904C2AFCCA523962461F16B5ECBF202C621E06693DDD787C533B17043793", "hash_sha384": "33B280E515E5B26A91C0D2D786E002DB1CCF371E02609CACD182BDB729293B70921B23E30064BA85B041DA17B64D2898", "hash_sha512": "F4505AE277697F507F62C59124760E89B947B09EF9C11E50742AC32A964287D07CCE7A3B30DA5914A1BE7DEBDAE8A8A41DD18F29C8679502902EF1D11CD83ED8", "hash_ssdeep": "192:02SMJsXqZTdCWp2/GMgHL6xfQKbprpHMRtmZkvWTzWVpnpZ:0oJhTks2/piL69rps/JvWTzWVpn", "hash_imp": "515D13B7AD9E8958E42761434A172217", "hash_pesha1": "C26BBFBCC0BB51825942828DA4E39FAC1FDB81F1", "hash_pe256": "B46E7A3ACC5EDB4A3288942F3262FB9284D59B31D550100EAA40B68F8DE2D38B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Restart Manager LUA Restart Client", "meta_original_filename": "RmClient.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/1aaa904c2afcca523962461f16b5ecbf202c621e06693ddd787c533b17043793/detection/", "output": "\r\n RmClient.exe pipename\r\n\r\n\r\n" }, "Robocopy.exe-C29611871BE53A510DE07167A6FB3F48": { "file_name": "Robocopy.exe", "file_path": "C:\\Windows\\SysWOW64\\Robocopy.exe", "hash_md5": "C29611871BE53A510DE07167A6FB3F48", "hash_sha1": "59A90CE2A43422F645858E327E082926DDC6902D", "hash_sha256": "5D5ADA9608945B0F18005A0EC867D1A6690A2D57DDCF9534F4519BDB402538B5", "hash_sha384": "C3C3BB2E86633FC3E4F4E84AEDA9E5BC45E7F5DB61BAE5E488FE0C1062FB04ABCB5631D15E41C87ACAD6CE59422E1EFB", "hash_sha512": "63F362D757338BCA73E4452F00ADEF67A0DA995379FB1A73B7AB2FBF484EBA125C70FEA26F402F839B0A42E14BCE365F957C0787536F1DF939B0A9608554546D", "hash_ssdeep": "3072:P3VZp0OSgvxoM5/fXs5I/HVoYG66vlVGQg7EdlPw6j4:fPpPF5o88WP6ZgBal2", "hash_imp": "B953C8C22C1B69C5416BB3D0886C4CB9", "hash_pesha1": "AF9809EEBA5F712203AE26538F7A3B8EDFE78B09", "hash_pe256": "3BD532A97892BFE8FBE1068F8C31D2166CEEB5611A4A75335A76CA7A5CD444A9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Robocopy", "meta_original_filename": "robocopy.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\n-------------------------------------------------------------------------------\r\n ROBOCOPY :: Robust File Copy for Windows \r\n-------------------------------------------------------------------------------\r\n\r\n Started : Monday, October 19, 2020 10:19:50 PM\r\n Usage :: ROBOCOPY source destination [file [file]...] [options]\r\n\r\n source :: Source Directory (drive:\\path or \\\\server\\share\\path).\r\n destination :: Destination Dir (drive:\\path or \\\\server\\share\\path).\r\n file :: File(s) to copy (names/wildcards: default is \"*.*\").\r\n\r\n::\r\n:: Copy options :\r\n::\r\n /S :: copy Subdirectories, but not empty ones.\r\n /E :: copy subdirectories, including Empty ones.\r\n /LEV:n :: only copy the top n LEVels of the source directory tree.\r\n\r\n /Z :: copy files in restartable mode.\r\n /B :: copy files in Backup mode.\r\n /ZB :: use restartable mode; if access denied use Backup mode.\r\n /J :: copy using unbuffered I/O (recommended for large files).\r\n /EFSRAW :: copy all encrypted files in EFS RAW mode.\r\n\r\n /COPY:copyflag[s] :: what to COPY for files (default is /COPY:DAT).\r\n (copyflags : D=Data, A=Attributes, T=Timestamps).\r\n (S=Security=NTFS ACLs, O=Owner info, U=aUditing info).\r\n\r\n \r\n /SEC :: copy files with SECurity (equivalent to /COPY:DATS).\r\n /COPYALL :: COPY ALL file info (equivalent to /COPY:DATSOU).\r\n /NOCOPY :: COPY NO file info (useful with /PURGE).\r\n /SECFIX :: FIX file SECurity on all files, even skipped files.\r\n /TIMFIX :: FIX file TIMes on all files, even skipped files.\r\n\r\n /PURGE :: delete dest files/dirs that no longer exist in source.\r\n /MIR :: MIRror a directory tree (equivalent to /E plus /PURGE).\r\n\r\n /MOV :: MOVe files (delete from source after copying).\r\n /MOVE :: MOVE files AND dirs (delete from source after copying).\r\n\r\n /A+:[RASHCNET] :: add the given Attributes to copied files.\r\n /A-:[RASHCNET] :: remove the given Attributes from copied files.\r\n\r\n /CREATE :: CREATE directory tree and zero-length files only.\r\n /FAT :: create destination files using 8.3 FAT file names only.\r\n /256 :: turn off very long path (> 256 characters) support.\r\n\r\n /MON:n :: MONitor source; run again when more than n changes seen.\r\n /MOT:m :: MOnitor source; run again in m minutes Time, if changed.\r\n\r\n /RH:hhmm-hhmm :: Run Hours - times when new copies may be started.\r\n /PF :: check run hours on a Per File (not per pass) basis.\r\n\r\n /IPG:n :: Inter-Packet Gap (ms), to free bandwidth on slow lines.\r\n\r\n /SL :: copy symbolic links versus the target.\r\n\r\n /MT[:n] :: Do multi-threaded copies with n threads (default 8).\r\n n must be at least 1 and not greater than 128.\r\n This option is incompatible with the /IPG and /EFSRAW options.\r\n Redirect output using /LOG option for better performance.\r\n\r\n /DCOPY:copyflag[s] :: what to COPY for directories (default is /DCOPY:DA).\r\n (copyflags : D=Data, A=Attributes, T=Timestamps).\r\n\r\n /NODCOPY :: COPY NO directory info (by default /DCOPY:DA is done).\r\n\r\n /NOOFFLOAD :: copy files without using the Windows Copy Offload mechanism.\r\n\r\n::\r\n:: File Selection Options :\r\n::\r\n /A :: copy only files with the Archive attribute set.\r\n /M :: copy only files with the Archive attribute and reset it.\r\n /IA:[RASHCNETO] :: Include only files with any of the given Attributes set.\r\n /XA:[RASHCNETO] :: eXclude files with any of the given Attributes set.\r\n\r\n /XF file [file]... :: eXclude Files matching given names/paths/wildcards.\r\n /XD dirs [dirs]... :: eXclude Directories matching given names/paths.\r\n\r\n /XC :: eXclude Changed files.\r\n /XN :: eXclude Newer files.\r\n /XO :: eXclude Older files.\r\n /XX :: eXclude eXtra files and directories.\r\n /XL :: eXclude Lonely files and directories.\r\n /IS :: Include Same files.\r\n /IT :: Include Tweaked files.\r\n\r\n /MAX:n :: MAXimum file size - exclude files bigger than n bytes.\r\n /MIN:n :: MINimum file size - exclude files smaller than n bytes.\r\n\r\n /MAXAGE:n :: MAXimum file AGE - exclude files older than n days/date.\r\n /MINAGE:n :: MINimum file AGE - exclude files newer than n days/date.\r\n /MAXLAD:n :: MAXimum Last Access Date - exclude files unused since n.\r\n /MINLAD:n :: MINimum Last Access Date - exclude files used since n.\r\n (If n < 1900 then n = n days, else n = YYYYMMDD date).\r\n\r\n /XJ :: eXclude Junction points and symbolic links. (normally included by default).\r\n\r\n /FFT :: assume FAT File Times (2-second granularity).\r\n /DST :: compensate for one-hour DST time differences.\r\n\r\n /XJD :: eXclude Junction points and symbolic links for Directories.\r\n /XJF :: eXclude symbolic links for Files.\r\n\r\n /IM :: Include Modified files (differing change times).\r\n::\r\n:: Retry Options :\r\n::\r\n /R:n :: number of Retries on failed copies: default 1 million.\r\n /W:n :: Wait time between retries: default is 30 seconds.\r\n\r\n /REG :: Save /R:n and /W:n in the Registry as default settings.\r\n\r\n /TBD :: Wait for sharenames To Be Defined (retry error 67).\r\n\r\n /LFSM :: Operate in low free space mode, enabling copy pause and resume (see Remarks).\r\n\r\n /LFSM:n[KMG] :: /LFSM, specifying the floor size in n [K:kilo,M:mega,G:giga] bytes.\r\n\r\n::\r\n:: Logging Options :\r\n::\r\n /L :: List only - don't copy, timestamp or delete any files.\r\n /X :: report all eXtra files, not just those selected.\r\n /V :: produce Verbose output, showing skipped files.\r\n /TS :: include source file Time Stamps in the output.\r\n /FP :: include Full Pathname of files in the output.\r\n /BYTES :: Print sizes as bytes.\r\n\r\n /NS :: No Size - don't log file sizes.\r\n /NC :: No Class - don't log file classes.\r\n /NFL :: No File List - don't log file names.\r\n /NDL :: No Directory List - don't log directory names.\r\n\r\n /NP :: No Progress - don't display percentage copied.\r\n /ETA :: show Estimated Time of Arrival of copied files.\r\n\r\n /LOG:file :: output status to LOG file (overwrite existing log).\r\n /LOG+:file :: output status to LOG file (append to existing log).\r\n\r\n /UNILOG:file :: output status to LOG file as UNICODE (overwrite existing log).\r\n /UNILOG+:file :: output status to LOG file as UNICODE (append to existing log).\r\n\r\n /TEE :: output to console window, as well as the log file.\r\n\r\n /NJH :: No Job Header.\r\n /NJS :: No Job Summary.\r\n\r\n /UNICODE :: output status as UNICODE.\r\n\r\n::\r\n:: Job Options :\r\n::\r\n /JOB:jobname :: take parameters from the named JOB file.\r\n /SAVE:jobname :: SAVE parameters to the named job file\r\n /QUIT :: QUIT after processing command line (to view parameters). \r\n /NOSD :: NO Source Directory is specified.\r\n /NODD :: NO Destination Directory is specified.\r\n /IF :: Include the following Files.\r\n\r\n::\r\n:: Remarks :\r\n::\r\n Using /PURGE or /MIR on the root directory of the volume formerly caused \r\n robocopy to apply the requested operation on files inside the System \r\n Volume Information directory as well. This is no longer the case; if \r\n either is specified, robocopy will skip any files or directories with that \r\n name in the top-level source and destination directories of the copy session.\r\n\r\n The modified files classification applies only when both source \r\n and destination filesystems support change timestamps (e.g., NTFS) \r\n and the source and destination files have different change times but are \r\n otherwise the same. These files are not copied by default; specify /IM \r\n to include them. \r\n\r\n Using /LFSM requests robocopy to operate in 'low free space mode'. \r\n In that mode, robocopy will pause whenever a file copy would cause the \r\n destination volume's free space to go below a 'floor' value, which \r\n can be explicitly specified by the LFSM:n[KMG] form of the flag. \r\n If /LFSM is specified with no explicit floor value, the floor is set to \r\n ten percent of the destination volume's size. \r\n Low free space mode is incompatible with /MT, /EFSRAW, /B, and /ZB.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Robocopy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ROUTE.EXE-765B4565AD4DFCE38B43E62B35344492": { "file_name": "ROUTE.EXE", "file_path": "C:\\Windows\\SysWOW64\\ROUTE.EXE", "hash_md5": "765B4565AD4DFCE38B43E62B35344492", "hash_sha1": "4E867649592AA1DF6ABCC93760DD332AA8D87B0C", "hash_sha256": "CCDCC49B612BD8C3C5075BF760B2E49DDA20A23A16E156EC3955DD349BCB5805", "hash_sha384": "7D7F1203FA90C08AAC0C6BA0D44D94D66EE86E8379252C7D102D96676EB1A9E5E96B287F1661A2CC5C0ED712FC1DDF36", "hash_sha512": "0825A20C975C62E455D126EF9BFB97164F9ED641C5EB0CCAD4D5BC014A51FF002AD2C15D03420AD2ED9261EB641974397068452350B064E99F42B7D706B52054", "hash_ssdeep": "384:oJCBVc4YeJwV2f/1Cv3wkzb7lQl8HlEeFqBKyWj0WC3:oJQbJZ34IkzIKlnFqBKXo3", "hash_imp": "BB55D8CE15016A967F7AAA263ECB6116", "hash_pesha1": "56BD8748C2CC29E217C951E5F1873E6BBACAAF1D", "hash_pe256": "5A37BAA8A7958937A6AB88DE67F5D0C7B457667A6764E80A7FB4B324961FCC29", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Route Command", "meta_original_filename": "route.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/ccdcc49b612bd8c3c5075bf760b2e49dda20a23a16e156ec3955dd349bcb5805/detection/", "error": "\r\nManipulates network routing tables.\r\n\r\nROUTE [-f] [-p] [-4|-6] command [destination]\r\n [MASK netmask] [gateway] [METRIC metric] [IF interface]\r\n\r\n -f Clears the routing tables of all gateway entries. If this is\r\n used in conjunction with one of the commands, the tables are\r\n cleared prior to running the command.\r\n \r\n -p When used with the ADD command, makes a route persistent across\r\n boots of the system. By default, routes are not preserved\r\n when the system is restarted. Ignored for all other commands, \r\n which always affect the appropriate persistent routes.\r\n \r\n -4\t Force using IPv4.\r\n\r\n -6 Force using IPv6. \r\n \r\n command One of these:\r\n PRINT Prints a route\r\n ADD Adds a route\r\n DELETE Deletes a route\r\n CHANGE Modifies an existing route\t\r\n destination Specifies the host.\r\n MASK Specifies that the next parameter is the 'netmask' value.\r\n netmask Specifies a subnet mask value for this route entry.\r\n If not specified, it defaults to 255.255.255.255.\r\n gateway Specifies gateway.\r\n interface the interface number for the specified route.\r\n METRIC specifies the metric, ie. cost for the destination.\r\n\r\nAll symbolic names used for destination are looked up in the network database\r\nfile NETWORKS. The symbolic names for gateway are looked up in the host name\r\ndatabase file HOSTS.\r\n\r\nIf the command is PRINT or DELETE. Destination or gateway can be a wildcard,\r\n(wildcard is specified as a star '*'), or the gateway argument may be omitted.\r\n\r\nIf Dest contains a * or ?, it is treated as a shell pattern, and only\r\nmatching destination routes are printed. The '*' matches any string,\r\nand '?' matches any one char. Examples: 157.*.1, 157.*, 127.*, *224*.\r\n\r\nPattern match is only allowed in PRINT command.\r\nDiagnostic Notes:\r\n Invalid MASK generates an error, that is when (DEST & MASK) != DEST.\r\n Example> route ADD 157.0.0.0 MASK 155.0.0.0 157.55.80.1 IF 1\r\n The route addition failed: The specified mask parameter is invalid. (Destination & Mask) != Destination.\r\n\r\nExamples:\r\n\r\n > route PRINT\r\n > route PRINT -4\r\n > route PRINT -6\r\n > route PRINT 157* .... Only prints those matching 157*\r\n\t\r\n > route ADD 157.0.0.0 MASK 255.0.0.0 157.55.80.1 METRIC 3 IF 2\r\n destination^ ^mask ^gateway metric^ ^\r\n Interface^\r\n If IF is not given, it tries to find the best interface for a given \r\n gateway.\r\n > route ADD 3ffe::/32 3ffe::1\r\n \r\n > route CHANGE 157.0.0.0 MASK 255.0.0.0 157.55.80.5 METRIC 2 IF 2\r\n \r\n CHANGE is used to modify gateway and/or metric only.\r\n \r\n > route DELETE 157.0.0.0\r\n > route DELETE 3ffe::/32\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\ROUTE.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RpcPing.exe-4F78FB21DC5ECFE9EEAED939F15D64FE": { "file_name": "RpcPing.exe", "file_path": "C:\\Windows\\SysWOW64\\RpcPing.exe", "hash_md5": "4F78FB21DC5ECFE9EEAED939F15D64FE", "hash_sha1": "908EC79EB707948D8E23C2810C20ED37E105414B", "hash_sha256": "D46E6BC917443DCF55ECEE73CBAD10D2FE65CE461705ED5ACF7A3CF05E6968E8", "hash_sha384": "5B62CDEED552DDD32BDF619CF1889F8F66BCF1AE9DDF45DC8ABC3A26A63DBCCD83908D33617669F66D3D3D688EB53B5F", "hash_sha512": "A873E2D02EAFA0D0A2B56F7FAD1974D02DB93163D0F8CAF582E1B2DE062D9F295597F0B2C84A29F910AC63A1D1D1A83BB8DC2C69CEC89D0D3748BA08358B7751", "hash_ssdeep": "768:ommSD8e7v5ujXI9UencjQMghcm3naKq9l/ze7g:GSD8CYI9UeGtghcmXa/zj", "hash_imp": "19813C5F838DD3B1151D1518F2F49579", "hash_pesha1": "ED6BB936956C18E8D67255B16C675E29598F3495", "hash_pe256": "20852E6A2CAE0B5C3EFE7C60AEB7A99183A6FF8E08C8403436E0B1B223E41F24", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RPC Ping Utility", "meta_original_filename": "RpcPing.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/d46e6bc917443dcf55ecee73cbad10d2fe65ce461705ed5acf7a3cf05e6968e8/detection/", "output": "Usage: \r\nrpcping [-t <protseq>] [-s <server_addr>] [-e <endpoint> \r\n |-f <interface UUID>[,MajorVer]] [-O <Interface Object UUID]\r\n [-i <#_iterations>] [-u <security_package_id>] [-a <authn_level>] \r\n [-N <server_princ_name>] [-I <auth_identity>] [-C <capabilities>]\r\n [-T <identity_tracking>] [-M <impersonation_type>]\r\n [-S <server_sid>] [-P <proxy_auth_identity>] [-F <RPCHTTP_flags>]\r\n [-H <RPC/HTTP_authn_schemes>] [-o <binding_options>]\r\n [-B <server_certificate_subject>] [-b] [-E] [-q] [-c]\r\n [-A <http_proxy_auth_identity>] [-U <HTTP_proxy_authn_schemes>]\r\n [-r <report_results_interval>] [-v <verbose_level>] \r\n\r\nPings a server using RPC. Options are:\r\n\r\n-t <protseq> - protocol sequence to use. Can be one of the standard\r\n RPC protocol sequences - ncacn_ip_tcp, ncacn_np, ncacn_http, etc.\r\n If not specified, default is ncacn_ip_tcp.\r\n \r\n-s <server_addr> - the server address. If not specified, the local\r\n machine will be pinged. E.g. server, server.com, 157.59.244.141\r\n \r\n-e <endpoint> - the endpoint to ping. If none is specified, the endpoint\r\n mapper on the target machine will be pinged. This option is mutually\r\n exclusive with the interface (-f) option.\r\n\r\n-o <binding_options> - the binding options for the RPC ping. See the\r\n MSDN for more details (RpcStringBindingCompose and RPC over HTTP).\r\n \r\n-f <interface UUID>[,MajorVer] - the interface to ping. This option is\r\n mutually exclusive with the endpoint option. The interface is specified\r\n as a UUID. If the MajorVer is not specified, version 1 of the interface\r\n will be sought. When interface is specified, rpcping will query the\r\n endpoint mapper on the target machine to retrieve the endpoint for the\r\n specified interface. The endpoint mapper will be queried using the\r\n options specified in the command line.\r\n \r\n-O <Object UUID> - Object Uuid if the interface registerd one.\r\n\r\n-i <#_iterations> - number of calls to make. The default is 1. This\r\n option is useful for measuring connection latency if multiple\r\n iterations are specified.\r\n \r\n-u <security_package_id> - the security package (security provider) RPC\r\n will use to make the call. The security package is identified as a\r\n number or a name. If a number is used it is the same number as in the\r\n RpcBindingSetAuthInfoEx API. The table below gives the names and\r\n numbers. Names are not case sensitive:\r\n Negotiate - 9 or one of nego, snego or negotiate\r\n NTLM - 10 or NTLM\r\n SChannel - 14 or SChannel\r\n Kerberos - 16 or Kerberos\r\n Kernel - 20 or Kernel\r\n If you specify this option you must specify authentication level other\r\n than none. There is no default for this option. If it is not specified,\r\n RPC will not use security for the ping.\r\n \r\n-a <authn_level> - the authentication level to use. Possible values are\r\n connect, call, pkt, integrity and privacy. If this option is\r\n specified, the security package id (-u) must also be specified. There\r\n is no default for this option. If this option is not specified, RPC\r\n will not use security for the ping.\r\n\r\n-N <server_princ_name> - specifies a server principal name. Same semantics\r\n as the ServerPrincName argument to RpcBindingSetAuthInfoEx. See the\r\n MSDN for more information on RpcBidningSetAuthInfoEx. This field can be\r\n used only when authentication level and security package are selected.\r\n \r\n-I <auth_identity> - allows you to specify alternative identity to connect\r\n to the server. The identity is in the form user,domain,password where\r\n the three fields have the obvious meaning. If the user name, domain or\r\n password have special characters that can be interpreted by the shell\r\n be sure to enclose the identity in double quotes. You can specify *\r\n instead of the password and RPC will prompt you to enter the password\r\n without echoing it on the screen. If this field is not specified, the\r\n identity of the logged on user will be used. This field can be used\r\n only when authentication level and security package are selected.\r\n \r\n-C <capabilities> - a hex bitmask of flags. It has the same meaning as\r\n the Capabilities field in the RPC_SECURITY_QOS structure described\r\n in the MSDN. This field can be used only when authentication level and\r\n security package are selected.\r\n \r\n-T <identity_tracking> - can be static or dynamic. If not specified,\r\n dynamic is the default. This field can be used only when authentication\r\n level and security package are selected.\r\n\r\n-M <impersonation_type> - can be anonymous, identify, impersonate or\r\n delegate. Default is impersonate. This field can be used only when\r\n authentication level and security package are selected. \r\n\r\n-S <server_sid> - the expected SID of the server. For more information\r\n see the Sid field in the RPC_SECURITY_QOS structure in the MSDN. Using \r\n this option requires Windows .NET Server 2003 or higher. This field can\r\n be used only when authentication level and security package are\r\n selected.\r\n \r\n-Z <effectiveonly> - the EffectiveOnly setting to use. For more information\r\n see the EffectiveOnly field in the RPC_SECURITY_QOS structure in MSDN.\r\n Using this option requires Windows Vista or higher. This field can be\r\n used only when authentication level and security package are selected.\r\n\r\n-D <serversecuritydescriptor> - the security descriptor (in string format)\r\n of the server when using mutual authentication. For more information\r\n see the ServerSecurityDescriptor field in the RPC_SECURITY_QOS structure\r\n in MSDN. Using this option requires Windows 8 or higher. This field can\r\n be used only when authentication level and security package are\r\n selected.\r\n\r\n-P <proxy_auth_identity> - specifies the identity to authenticate with to\r\n the RPC/HTTP proxy. Has the same format as for the -I option. \r\n Also, you must specify security package (-u), authentication level \r\n (-a), and authentication schemes (-H) in order to use this option.\r\n \r\n-F <RPCHTTP_flags> - the flags to pass for RPC/HTTP front end\r\n authentication. The flags may be specified as numbers or names\r\n The currently recognized flags are:\r\n Use SSL - 1 or ssl or use_ssl\r\n Use first auth scheme - 2 or first or use_first\r\n See the Flags field in RPC_HTTP_TRANSPORT_CREDENTIALS for more \r\n information. Also, you must specify security package (-u) and \r\n authentication level (-a) in order to use this option.\r\n \r\n-H <RPC/HTTP_authn_schemes> - the authentication schemes to use for\r\n RPC/HTTP front end authentication. This option is a list of numerical\r\n values or names separated by comma. E.g. Basic,NTLM. Recognized values\r\n are (names are not case sensitive:\r\n Basic - 1 or Basic\r\n NTLM - 2 or NTLM\r\n Certificate - 65536 or Cert\r\n Also, you must specify security package (-u) and authentication level \r\n (-a) in order to use this option.\r\n \r\n-B <server_certificate_subject> - the server certificate subject. For\r\n more information, see the ServerCertificateSubject field in the\r\n RPC_HTTP_TRANSPORT_CREDENTIALS structure in the MSDN. You must use\r\n SSL for this option to work. Also, you must specify security package \r\n (-u) and authentication level (-a) in order to use this option.\r\n \r\n-b - retrieves the server certificate subject from the certificate sent\r\n by the server and prints it to a screen or a log file. Valid only when\r\n the Proxy Echo only option (-E) and the use SSL options are specified.\r\n Also, you must specify security package (-u) and authentication level \r\n (-a) in order to use this option.\r\n \r\n-R - specifies the HTTP proxy. if it's 'none', we will not use HTTP proxy but\r\n directly attempt the RPC proxy. the value 'default' means to use the IE\r\n settings in your client machine. any other value will be treated as the\r\n explicit HTTP proxy. if you don't specify this flag, the default value\r\n is assumed, that is, the IE settings are checked. this flag is valid\r\n only when the -E (Echo Only) flag is enabled.\r\n\r\n-E - restricts the ping to the RPC/HTTP proxy only. The ping does not\r\n reach the server. Useful when trying to establish whether the RPC/HTTP\r\n proxy is reachable. Also, you must specify security package (-u) and \r\n authentication level (-a) in order to use this option. To specify an \r\n HTTP proxy, use the -R flag. If an HTTP proxy is specified in the -o \r\n flag, this option will be ignored.\r\n \r\n-q - quiet mode. Does not issue any prompts except for passwords. Assumes\r\n 'Y' response to all queries. Use this option with care.\r\n \r\n-c - use smart card certificate. RPCPing will prompt user to choose\r\n smart card.\r\n \r\n-A <http_proxy_auth_identity> - specifies the identity to authenticate\r\n with to the HTTP proxy. Has the same format as for the -I option. \r\n Also, you must specify authentication schemes (-U), security package \r\n (-u) and authentication level (-a) in order to use this option.\r\n \r\n-U <HTTP_proxy_authn_schemes> - the authentication schemes to use for\r\n HTTP proxy authentication. This option is a list of numerical\r\n values or names separated by comma. E.g. Basic,NTLM. Recognized values \r\n are (names are not case sensitive:\r\n Basic - 1 or Basic\r\n NTLM - 2 or NTLM\r\n You must specify security package (-u) and authentication level (-a) \r\n in order to use this option.\r\n\r\n-r <report_results_interval> - if multiple iterations are specified, this\r\n option will make rpcping display current execution statistics\r\n periodically instead after the last call. The report interval is given\r\n in seconds. Default is 15.\r\n \r\n-v <verbose_level> - tells rpcping how verbose to make the output. Default\r\n value is 1. 2 and 3 provide more output from rpcping.\r\n \r\nExample: Find out if your Exchange server that you connect through\r\nRPC/HTTP is accessible:\r\n rpcping -t ncacn_http -s exchange_server -o RpcProxy=front_end_proxy\r\n -P \"username,domain,*\" -H Basic -u NTLM -a connect -F 3\r\nWhen prompted for the password, enter it. exchange_server is the name of\r\nyour exchange server, front_end_proxy is the name of your proxy, username\r\nand domain are your user name and domain as you would enter them in the\r\nOutlook prompt. The other parameters will ask rpcping to ping your\r\nExchange server in exactly the same way as Outlook will connect to it for\r\nthe typical profile.\r\n\r\n-p - Prompt for credentials if authentication fails.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\RpcPing.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "rrinstaller.exe-AC07152EA4403FC6FEF907AA65434E44": { "file_name": "rrinstaller.exe", "file_path": "C:\\Windows\\SysWOW64\\rrinstaller.exe", "hash_md5": "AC07152EA4403FC6FEF907AA65434E44", "hash_sha1": "3DD14043C4809830049632784A3F2209C0571A48", "hash_sha256": "837115F05F375B2506C57FC917C21905B46679126035113D38A60DCE9B5B675F", "hash_sha384": "3AFD03AB3144B252D50483EB28E90904946C8F325FACC4261015C5AC87F52CE3FF883EC0A8FD4F07CC9CA1CD1D0B45D2", "hash_sha512": "29FE206F385480C413A052DDA32802225C891A2A24B171A9EBEA04396232D4B41C0A1EACC1DBA72531C5F92C9B6FE40736F7B8669A6EF1A045494E30CDC4BA73", "hash_ssdeep": "768:AwnsIqYJNt3s3herFbyJj0H+hHsh0dYJ3OwdO4T5Ey0G/Fu:AwhqKs3herFbyJgqsh5Xey9/", "hash_imp": "22CD5E9B5D2130049B28E3DC366A44AD", "hash_pesha1": "1B2EDEC253444CAC595B3481433DA049BEA7B944", "hash_pe256": "8E51E1C9817B49DE793059FD55B0B69CB7D7DCFA6C69E22FFF97AA81121D36AD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "R&R installer", "meta_original_filename": "rrinstaller.exe", "meta_product_name": "Microsoft DRM", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.0.17763.1", "meta_product_version": "11.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/837115f05f375b2506c57fc917c21905b46679126035113d38a60dce9b5b675f/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\rrinstaller.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "rsopprov.exe-CF2CCD5FEF4CADD5933BBC011B5F6404": { "file_name": "rsopprov.exe", "file_path": "C:\\Windows\\SysWOW64\\rsopprov.exe", "hash_md5": "CF2CCD5FEF4CADD5933BBC011B5F6404", "hash_sha1": "C355DCC6F4D2BB8F354AD1714045113D96143769", "hash_sha256": "B67AB720F53058838DACB5266A30CB22DC6B3CA891CE80C6B2C185D4B0857807", "hash_sha384": "FEADCB2FF9F955E3C7E6EB47D44EA474500FBD0BEBB8B5E8B34B8BCAF57C7B5C4008F38ADD3392CD13AB1C26644DAB2C", "hash_sha512": "6ED80518BC50F9C7EA09DBE40C706398A5A28A1D037DC392D341F3495A86F15CD3CB8C2AECD53A23E53B81BB0042C9A107ECE66A4E571AC8F5E4CD336DD15D0C", "hash_ssdeep": "1536:q+gBL9MdYWhOgecR6h2oIfzgLNSwY9J41qHaWVN2uhgbNRPHfMMyru:q++L9MdYWhOgecch2oI71KAHHmNB/MdK", "hash_imp": "7B46B2764DA8409F685916B14A77CA1F", "hash_pesha1": "0CA817483BB0D8583E824FEB4BD69A8024A2CC3A", "hash_pe256": "290B7982ED5F864762699AF8CCBF336B2469616DCA90A42D85FDFB40DC5F5DD5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "RSoP Service Application", "meta_original_filename": "RSOPPROV.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "runas.exe-E9021926EC348EED9D128468AEEC81D0": { "file_name": "runas.exe", "file_path": "C:\\Windows\\SysWOW64\\runas.exe", "hash_md5": "E9021926EC348EED9D128468AEEC81D0", "hash_sha1": "00948076C37870B65B7DB5BE924CFCBDB3594B08", "hash_sha256": "F633828387901A9F6DB431A410B5F7FE18BDDDC4F630C6A839A46B061E59860E", "hash_sha384": "ED4E034A103C566736CDA3E83F5EDBD05E60BDF04DE51C3116FDEE80A4EC5EDB6F7FFAE67456210F46FD2CDE6A30931E", "hash_sha512": "43EEC51A571D196C91F3181F73AC681902986B649D786ED8A40D4A0C19E5DAEB822B383FFD337C55F1E1D9EAE4CBBE756A6D5A8BD0388DD24725E82578F7EAAD", "hash_ssdeep": "384:Tc2IOvX+3WUq4WMeXMsuscYMHudWBOW0Qr:T2MwWTjMTYMHuArr", "hash_imp": "63B4267CB5383EAE01A9DE96021E1731", "hash_pesha1": "2F05B8132672FC1085EBCBB91614E3D42910A668", "hash_pe256": "8056884FD7022112A2554523811DDC94933E610EEC341BBC5F3188FA960D9A57", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Run As Utility", "meta_original_filename": "RUNAS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/f633828387901a9f6db431a410b5f7fe18bdddc4f630c6a839a46b061e59860e/detection/" }, "rundll32.exe-2F633406BC9875AA48D6CC5884B70862": { "file_name": "rundll32.exe", "file_path": "C:\\Windows\\SysWOW64\\rundll32.exe", "hash_md5": "2F633406BC9875AA48D6CC5884B70862", "hash_sha1": "6778DAD71C8B06264CF2929A5242D2612D3EB026", "hash_sha256": "26E68D4381774A6FD0BF5CA2EACEF55F2AB28536E3176A1C6362DFFC68B22B8A", "hash_sha384": "B3E247DAE87DBDDE91A31446E84FC04708FC21E83AEE02AB3D0CED93BDCA612B4919812CB0F44D98FFFB8BA84FC0A49F", "hash_sha512": "7F298EEBC0523B4113F4D95A6A02458BCD34D52945DB7ADB8DE0667C00FEDD0D9C2156DCC980E8AE0A1B95F841190A7214AEAFE3B8F771C44F0BD6F3C2244FBA", "hash_ssdeep": "768:bcNE1DAVSspt/KWgkXDbmekuTRzbSEln5IyYpamDjobj8Sjj:4+uZatKm0TRNln5IUmDjoX", "hash_imp": "BB17B2FBBFF4BBF5EBDCA7D0BB9E4A5B", "hash_pesha1": "DF07BC9FDB1EFEFA6C128E9ABDB2DB8F76F88BD3", "hash_pe256": "95F47CDD7803D6CB61765326E8B794B703EB56970898FE1E450376D77A825622", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows host process (Rundll32)", "meta_original_filename": "RUNDLL32.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/26e68d4381774a6fd0bf5ca2eacef55f2ab28536e3176a1c6362dffc68b22b8a/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\rundll32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "RunLegacyCPLElevated.exe-6C47B937FD6B890B201B451FE7B1FF76": { "file_name": "RunLegacyCPLElevated.exe", "file_path": "C:\\Windows\\SysWOW64\\RunLegacyCPLElevated.exe", "hash_md5": "6C47B937FD6B890B201B451FE7B1FF76", "hash_sha1": "A73A58F87AC036B65E4E2ED68641EFB88B60625F", "hash_sha256": "D74C1659560E1244D9097A3F61DE5A588C4BACE7F5E6676B5D65BBED6FF1675C", "hash_sha384": "F968404D65C6834CCA3FCB5C8CD2845E796C82651D94050F4C18EA94F760319C40AB08B065C53D797F6075B206C25672", "hash_sha512": "35407747B8786844A4CAA7765D4FA23DD4003DE924797DD4C9B4118A132DAC6CEB787219BDCA8669BA406C887CE2B94A96B4198A93976388AE537659762D53DD", "hash_ssdeep": "768:gO7X3ZwhXXv4U5xYFhMty8jSGSkVhWakkbB5eT905WGnUKxHUe7n8jKBFFptX/7z:lKLy8jSxakkn6oYY0ewiP8", "hash_imp": "932B565960425EE7FA367E4081AFA26B", "hash_pesha1": "A33C2883742E4E4EFE25777B1607AA68BD993B7C", "hash_pe256": "C85218211AB9A92832AA59158176A58BAB00CE1205AC1A28072F3C42CF3A0F9B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Run a legacy CPL elevated", "meta_original_filename": "RunLegacyCPLElevated.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/d74c1659560e1244d9097a3f61de5a588c4bace7f5e6676b5d65bbed6ff1675c/detection/" }, "runonce.exe-6FEF96ED9F43ADB12929A3E84856C6FB": { "file_name": "runonce.exe", "file_path": "C:\\Windows\\SysWOW64\\runonce.exe", "hash_md5": "6FEF96ED9F43ADB12929A3E84856C6FB", "hash_sha1": "996F26AFA18D8747DBCA1F2DE180E05E95614D5A", "hash_sha256": "78B8D920926EBCC685865A5AC91F21ED40889D538DDE6A4092764F44D7C015F4", "hash_sha384": "2F9FC335725459DF4C39DEAEAA0DEB23D639701E3FC2F124C026BB325509DC10062B42FF61681EAA5E0AF618FC4BE478", "hash_sha512": "E57DD984F3CC7C10BADA4D06DFACADBCC6D71B4E341A332A41527A16CF5A824F89DD416E6EAD84C2E7CA1F15094BF80244F3778183E29F97C90F493079C7A9BF", "hash_ssdeep": "768:mymNyL7EVeOf2xegirOiEjMOvDQVhxgMjxI+otootdNK2G8ZELz7Krs:mymNyckiyiobQ1gM1IltPtJdZELz7Krs", "hash_imp": "6294B7E7E5122F6D1B0C1EA4C1DB0725", "hash_pesha1": "80ACBAC9E63CA31A5AADBB5F1F5394F4681BB474", "hash_pe256": "5E1E7762650711B8448813A8498C4F7A0D6FAC3A755DFB919583BE1B9E137040", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Run Once Wrapper", "meta_original_filename": "RUNONCE.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/78b8d920926ebcc685865a5ac91f21ed40889d538dde6a4092764f44d7c015f4/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\runonce.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "rwinsta.exe-04EB0FA622B5AA58AEC203F5FABB057B": { "file_name": "rwinsta.exe", "file_path": "C:\\Windows\\SysWOW64\\rwinsta.exe", "hash_md5": "04EB0FA622B5AA58AEC203F5FABB057B", "hash_sha1": "59EBADE1AB55A2B7157D4EE64D562126FD5287BF", "hash_sha256": "0C5B4F925D9EAEE1F899B5497B807402F00B20BB19706285218F1A7D8EEB85C2", "hash_sha384": "463EBAF97847D463FF5A193795B5B9478632131F8B5BB84689DC532CBD7A5673C0CA45BE4C78B504CE01E9E5B7147940", "hash_sha512": "687FF3E5CCC78F07CCE2CDEC7E4517F04FFA38CE6D09ADFBBB69AD7B1D074C2D30400AB9DBE27571A86C5F02DAFB755EBD400E4868D8715CE184DC46E4DF8A65", "hash_ssdeep": "384:3gMiaCE0mL0M8WTsFapjPSWfOl52o2j47nx278PWdZW/CM:wbE0moDQc2o222QytM", "hash_imp": "09B3435A74D77CE7C500B1C424B63FD1", "hash_pesha1": "21903E3CF3616623D9613584C4CA0953495CBAEE", "hash_pe256": "B999ECF5F7209080F8B7D6E0B9C50E91FF4B98B8F89CC85A54A1DF0953FB1648", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Reset Session Utility", "meta_original_filename": "rwinsta.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/0c5b4f925d9eaee1f899b5497b807402f00b20bb19706285218f1a7d8eeb85c2/detection/", "output": "Reset the session subsytem hardware and software to known initial values.\r\n\r\nRESET SESSION {sessionname | sessionid} [/SERVER:servername] [/V]\r\n\r\n sessionname Identifies the session with name sessionname.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server containing the session (default is current).\r\n /V Display additional information.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\rwinsta.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "Invalid parameter(s)\r\nReset the session subsytem hardware and software to known initial values.\r\n\r\nRESET SESSION {sessionname | sessionid} [/SERVER:servername] [/V]\r\n\r\n sessionname Identifies the session with name sessionname.\r\n sessionid Identifies the session with ID sessionid.\r\n /SERVER:servername The server containing the session (default is current).\r\n /V Display additional information.\r\n\r\n" }, "sc.exe-293A38365BEE67829AE093D10BF4BC85": { "file_name": "sc.exe", "file_path": "C:\\Windows\\SysWOW64\\sc.exe", "hash_md5": "293A38365BEE67829AE093D10BF4BC85", "hash_sha1": "AFCCEB4DB08190D15739D0D369ABE0F66B99557C", "hash_sha256": "604492B8398751F0798079CEC26D674C125885F55B2BEAB1BC484EBDB723BB63", "hash_sha384": "F68F7A7539AC69B6F8A0ED2E4B2732EE8A71780F51941A7F28C0C83FF51172BCE2FE6DD83AD118451F2A5D64CAB7C3F6", "hash_sha512": "F8EBD11D3DF291889FAA38BEF19DFDE877B040D7F279CB20C6CABE0A9D422B2F6BE5872B0C9D330C0286115A99C37769615083C4D573EC4C0F57031519BD385B", "hash_ssdeep": "1536:VpFLNeH99G055y3em18biVPOvOTjbVTFNXo4HBxP/HOTnOsJ19XW4D8rjkQytP1F:HFLQH99G055y3em18biVPOvOTjbVTFNi", "hash_imp": "B037D0ADB81BF9CFC651DE01742089F1", "hash_pesha1": "A43608306923FA12F6B53D2B2FC79EE111868FDA", "hash_pe256": "61F6AB4E6B1C1EBE8302EB136966D33145E846EDBDB9997643EC7BD05C654707", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Service Control Manager Configuration Tool", "meta_original_filename": "sc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/604492b8398751f0798079cec26d674c125885f55b2beab1bc484ebdb723bb63/detection/", "output": "\r\nERROR: Unrecognized command\r\n\r\nDESCRIPTION:\r\n SC is a command line program used for communicating with the\r\n Service Control Manager and services.\r\nUSAGE:\r\n sc <server> [command] [service name] <option1> <option2>...\r\n\r\n\r\n The option <server> has the form \"\\\\ServerName\"\r\n Further help on commands can be obtained by typing: \"sc [command]\"\r\n Commands:\r\n query-----------Queries the status for a service, or\r\n enumerates the status for types of services.\r\n queryex---------Queries the extended status for a service, or\r\n enumerates the status for types of services.\r\n start-----------Starts a service.\r\n pause-----------Sends a PAUSE control request to a service.\r\n interrogate-----Sends an INTERROGATE control request to a service.\r\n continue--------Sends a CONTINUE control request to a service.\r\n stop------------Sends a STOP request to a service.\r\n config----------Changes the configuration of a service (persistent).\r\n description-----Changes the description of a service.\r\n failure---------Changes the actions taken by a service upon failure.\r\n failureflag-----Changes the failure actions flag of a service.\r\n sidtype---------Changes the service SID type of a service.\r\n privs-----------Changes the required privileges of a service.\r\n managedaccount--Changes the service to mark the service account \r\n password as managed by LSA.\r\n qc--------------Queries the configuration information for a service.\r\n qdescription----Queries the description for a service.\r\n qfailure--------Queries the actions taken by a service upon failure.\r\n qfailureflag----Queries the failure actions flag of a service.\r\n qsidtype--------Queries the service SID type of a service.\r\n qprivs----------Queries the required privileges of a service.\r\n qtriggerinfo----Queries the trigger parameters of a service.\r\n qpreferrednode--Queries the preferred NUMA node of a service.\r\n qmanagedaccount-Queries whether a services uses an account with a \r\n password managed by LSA.\r\n qprotection-----Queries the process protection level of a service.\r\n quserservice----Queries for a local instance of a user service template.\r\n delete----------Deletes a service (from the registry).\r\n create----------Creates a service. (adds it to the registry).\r\n control---------Sends a control to a service.\r\n sdshow----------Displays a service's security descriptor.\r\n sdset-----------Sets a service's security descriptor.\r\n showsid---------Displays the service SID string corresponding to an arbitrary name.\r\n triggerinfo-----Configures the trigger parameters of a service.\r\n preferrednode---Sets the preferred NUMA node of a service.\r\n GetDisplayName--Gets the DisplayName for a service.\r\n GetKeyName------Gets the ServiceKeyName for a service.\r\n EnumDepend------Enumerates Service Dependencies.\r\n\r\n The following commands don't require a service name:\r\n sc <server> <command> <option>\r\n boot------------(ok | bad) Indicates whether the last boot should\r\n be saved as the last-known-good boot configuration\r\n Lock------------Locks the Service Database\r\n QueryLock-------Queries the LockStatus for the SCManager Database\r\nEXAMPLE:\r\n sc start MyService\r\n\r\n\r\nQUERY and QUERYEX OPTIONS:\r\n If the query command is followed by a service name, the status\r\n for that service is returned. Further options do not apply in\r\n this case. If the query command is followed by nothing or one of\r\n the options listed below, the services are enumerated.\r\n type= Type of services to enumerate (driver, service, userservice, all)\r\n (default = service)\r\n state= State of services to enumerate (inactive, all)\r\n (default = active)\r\n bufsize= The size (in bytes) of the enumeration buffer\r\n (default = 4096)\r\n ri= The resume index number at which to begin the enumeration\r\n (default = 0)\r\n group= Service group to enumerate\r\n (default = all groups)\r\n\r\nSYNTAX EXAMPLES\r\nsc query - Enumerates status for active services & drivers\r\nsc query eventlog - Displays status for the eventlog service\r\nsc queryex eventlog - Displays extended status for the eventlog service\r\nsc query type= driver - Enumerates only active drivers\r\nsc query type= service - Enumerates only Win32 services\r\nsc query state= all - Enumerates all services & drivers\r\nsc query bufsize= 50 - Enumerates with a 50 byte buffer\r\nsc query ri= 14 - Enumerates with resume index = 14\r\nsc queryex group= \"\" - Enumerates active services not in a group\r\nsc query type= interact - Enumerates all interactive services\r\nsc query type= driver group= NDIS - Enumerates all NDIS drivers\r\n\n", "children": "powershell.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\sc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "schtasks.exe-5BD86A7193D38880F339D4AFB1F9B63A": { "file_name": "schtasks.exe", "file_path": "C:\\Windows\\SysWOW64\\schtasks.exe", "hash_md5": "5BD86A7193D38880F339D4AFB1F9B63A", "hash_sha1": "77F125CE5840293890E1359483C7104AADE25FA7", "hash_sha256": "72900A86F3BED7570AA708657A76DD76BB80B68DB543D303DA401AC6983E39CE", "hash_sha384": "95783B6CA6815C3661112F307D00FCFFF6D28C0C32F67BA5A4881D196BFAB135AA84A93081D560D9D09AEF3BB6BD317D", "hash_sha512": "CA0B0768BAB2DDF2BB710E25FE81682B380F59CE3D190F411E405120BBDEEDC9DB66A94614E1F317E21959344D6E389B37CD8C678BC9F3AFB02B4A5DDBE306FD", "hash_ssdeep": "3072:6Nt0/FwuqP11qVK0tFRdvQLwSKJrBfVxrrccLcPBYe0Aat/t7+pq:g0//qP1cV9FRWjA9VJrccApYe0zlIq", "hash_imp": "012D1B3C5FD8B10F0F36DB7243A28CB8", "hash_pesha1": "91B24FB95F24FA5E2BBE5FCA57D37BD6543C56C1", "hash_pe256": "45ED92131403AA6F3BC9AB2AF7E677874602F317AA55681ECFC536AE5862FF59", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Scheduler Configuration Tool", "meta_original_filename": "schtasks.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/72900a86f3bed7570aa708657a76dd76bb80b68db543d303da401ac6983e39ce/detection/", "output": "\r\nSCHTASKS /parameter [arguments]\r\n\r\nDescription:\r\n Enables an administrator to create, delete, query, change, run and\r\n end scheduled tasks on a local or remote system. \r\n\r\nParameter List:\r\n /Create Creates a new scheduled task.\r\n\r\n /Delete Deletes the scheduled task(s).\r\n\r\n /Query Displays all scheduled tasks.\r\n\r\n /Change Changes the properties of scheduled task.\r\n\r\n /Run Runs the scheduled task on demand.\r\n\r\n /End Stops the currently running scheduled task.\r\n\r\n /ShowSid Shows the security identifier corresponding to a scheduled task name.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n SCHTASKS \r\n SCHTASKS /?\r\n SCHTASKS /Run /?\r\n SCHTASKS /End /?\r\n SCHTASKS /Create /?\r\n SCHTASKS /Delete /?\r\n SCHTASKS /Query /?\r\n SCHTASKS /Change /?\r\n SCHTASKS /ShowSid /?\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"SCHTASKS /QUERY /?\" for usage.\r\n" }, "sdbinst.exe-9A081E86E9FF0AA957EDA8E8D0624BAC": { "file_name": "sdbinst.exe", "file_path": "C:\\Windows\\SysWOW64\\sdbinst.exe", "hash_md5": "9A081E86E9FF0AA957EDA8E8D0624BAC", "hash_sha1": "326C4C3E1C05D66F1E646AF7CB2E4A5FEDB026F7", "hash_sha256": "837C16C1CA64E6DB32421FC56EFBD80BFCA8E9C8888E9240AB859C43ADAC1442", "hash_sha384": "089BCE4CFE6AA2906C5809A55BC5144FB25AF25B28AEF6EF484D2F84413024B89FE9ED9094AB676F84CB07CB63CA84C4", "hash_sha512": "D4490E47F58B0229FD368974103A1F3B7F5696B613856AA09E26658823F098AFADE8D050B2D944D7FDE530325053D8A29204EA9E387F9913D3A5654C9833DD29", "hash_ssdeep": "384:5ahy/EnSJIKqKziIyt4RRcHAnl+5nRl7Sew1sYmsPDErjWngWuTu:5aJZ+ziI9RRM6IlGUYmsPDEro0Tu", "hash_imp": "DC04DAC563E65A0D0DAE0ACCC2AC61E2", "hash_pesha1": "F504937E50FF3801235B252D9689880AF701E6AF", "hash_pe256": "545CB407B1D1B3C283F1A225F495530AE151256E9A5FF8E11C33080908A20E1F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Application Compatibility Database Installer", "meta_original_filename": "sdbinst.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/837c16c1ca64e6db32421fc56efbd80bfca8e9c8888e9240ab859c43adac1442/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\sdbinst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "output": "Error: Invalid switch --help.\nUsage: C:\\Windows\\SysWOW64\\sdbinst.exe [-?] [-q] [-u] [-g] [-p] [-n[:WIN32|WIN64]] myfile.sdb | {guid} | \"name\"\r\n\r\n -? - print this help text.\r\n -p - Allow SDBs containing patches.\r\n -q - Quiet mode: prompts are auto-accepted.\r\n -u - Uninstall.\r\n -g {guid} - GUID of file (uninstall only).\r\n -n \"name\" - Internal name of file (uninstall only).\n" }, "sdiagnhost.exe-48582EF64F96E054C0CDCF3055258101": { "file_name": "sdiagnhost.exe", "file_path": "C:\\Windows\\SysWOW64\\sdiagnhost.exe", "hash_md5": "48582EF64F96E054C0CDCF3055258101", "hash_sha1": "F60F1B93B7172336137CE353E0DB018A42996B80", "hash_sha256": "B2ADF4CB63C8B1B2FF014BD328DEAC96354C6F834FAF0660EFD8F7E89F1B2399", "hash_sha384": "D4EA6A0AE2C8CDD09580F7E40B99213F2C78B28A5ED2468E7C0075CCFD2AF38E98E2B4B14AF9EBE45D2B7AC307772F12", "hash_sha512": "E8AF437B086FF1FE00AA3C372EAEEA00CEEF754A5CC713DD150CDB205DC36EE394FD932321128F4489C60947FBDCC9436669AC0AD0F1A2E8D554113B605D0C1E", "hash_ssdeep": "384:QHm8MXAvaaGVWyxfAzfVRmffQ7MPrOrye7mEZxaLelgWG7DWz:F1VnILVRmg7f7mmaLeC2", "hash_imp": "1AC4615E680B9BC131EC1F2ADCF60B35", "hash_pesha1": "43F4CDC04527CAA55FCC340F95D7BFB9A1269BF0", "hash_pe256": "8638CC4929363E9FFC12D92BE0FEAD6E9E6C7900D65FDBB5454EE3C1B86FFA86", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Scripted Diagnostics Native Host", "meta_original_filename": "sdiagnhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/64", "filescan_vtlink": "https://www.virustotal.com/gui/file/b2adf4cb63c8b1b2ff014bd328deac96354c6f834faf0660efd8f7e89f1b2399/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\sdiagnhost.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECB58": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\sdiagnhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SearchFilterHost.exe-A2E770284F3AF4AFA09407862E73ADFB": { "file_name": "SearchFilterHost.exe", "file_path": "C:\\Windows\\SysWOW64\\SearchFilterHost.exe", "hash_md5": "A2E770284F3AF4AFA09407862E73ADFB", "hash_sha1": "F7D149FB922FF5D7DB376DD47A63E5A10CA736C7", "hash_sha256": "DD8A449737CA241BF34BE50DF7ACF09BB62AF97CC6AE8E6E5B4CCCB6DA7F4DEC", "hash_sha384": "5D2D71C802D29E84310AB9FDAC5512FEF2D39F4AF09F582CF0CE660C360228DA0B199FDAB9E8079A9B96EABDDF44CCDF", "hash_sha512": "49F90D7AF756F168E0453788BE26674879ACDABD774B90104A75ECD70C5343E317DB1416BF3C1DB05AFE845E688E13523C27B4564B546BC5B11A89AE85435164", "hash_ssdeep": "3072:xO+RuXFRkFpIkGFc6aB3TnrdsAw1ihk6kvtfGq0ev3U5WNlEeXR:k5gxn68DnrdswrkR10efUKlr", "hash_imp": "5CA6A4101092874D62A3DDE80F619F69", "hash_pesha1": "A608ACAF74869EA3B9CE09DEFD3B9417C2DD4DCC", "hash_pe256": "7147AB22E00B8790987EAB1D80BC28E5C51535E91662C0F670FBF4A28D01FD88", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Search Filter Host", "meta_original_filename": "SearchFilterHost.exe", "meta_product_name": "Windows Search", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "7.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/dd8a449737ca241bf34be50df7acf09bb62af97cc6ae8e6e5b4cccb6da7f4dec/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\SearchFilterHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SearchIndexer.exe-5A0F15EF559F58AFBBA185BFBFE7A423": { "file_name": "SearchIndexer.exe", "file_path": "C:\\Windows\\SysWOW64\\SearchIndexer.exe", "hash_md5": "5A0F15EF559F58AFBBA185BFBFE7A423", "hash_sha1": "A902225C5BB62A5215CE4439DD87124CAF545F10", "hash_sha256": "8FAC5E5EE7E0CFAD8684EA66605282D0B006FA151A484904860A961EEEF09750", "hash_sha384": "4CF252CB518EB46CCAA3A1763109EE49B6A87A91B7F5F53C113C269C3C2BD1191B24E07C8C3D36603A54DDC3934C0BE8", "hash_sha512": "8011C3B12739EEB75808570FE1A8EDBDD805D9888B3AF130FB0283723105FB87796A956F40CF6DD8699C8DFF5BDF9D9CE9C9EF89BBE5303274403D7AC6903D49", "hash_ssdeep": "12288:0955IPx4W4oT6KdobHSQrYmDN7zhZp/ZS8y37mW4Oxu/hQQztf/jd:Q6Px4HoT9GbHk2NfhZphVyrlu/hQQ5", "hash_imp": "C6066FACB10B8EEA5BB61F38891A0A29", "hash_pesha1": "4A5F8A4672E4076C9608480D3AF86BE9AF9E11D0", "hash_pe256": "995A0D9E58074E9CAB08ABE63B81955239E96FE5259CD562C163934DEBA8E9C6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Search Indexer", "meta_original_filename": "SearchIndexer.exe", "meta_product_name": "Windows Search", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "7.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/8fac5e5ee7e0cfad8684ea66605282d0b006fa151a484904860a961eeef09750/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\SearchIndexer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SearchProtocolHost.exe-F71E4867152289828CA8063BA1732507": { "file_name": "SearchProtocolHost.exe", "file_path": "C:\\Windows\\SysWOW64\\SearchProtocolHost.exe", "hash_md5": "F71E4867152289828CA8063BA1732507", "hash_sha1": "704248DC32DB40F5D330406A67579BBF3956B7D1", "hash_sha256": "4C17B29541A680EB3E9D11B2031F1DD3F4074B4708BA704948216B0DCF231318", "hash_sha384": "183566B39590AC97D90B0C2AB449CDF46CB02F367D17ABF57B3A7263A756BDA47CC0B3C326F0C8B570E5852BC1AF184A", "hash_sha512": "B59BE01B955053E68816647989CBEFA7C04CC85A338B6278F89A49DEA3B1B35D9FB907140F31B8812ACA1808A9F85C532017ABED29C0A2CB2F34BE30066EA643", "hash_ssdeep": "6144:A0YhARuVyfqFcZhN6NCqD0vSoTRHRMP+Ojs+HD2JrkR10efUK3y4Ck:zYhARuVyfqqZb6hgNRS+r42JQztf9y4X", "hash_imp": "E36C335AD6A4B0A6E8C0779D5E84EB6E", "hash_pesha1": "53CE51262592010ED2D07150AA75661E4EF806BA", "hash_pe256": "0286F577CE04B31F7AB6F51F7BD78C8CF4E5C3A5BF74F51D37F5A9CDDB10F1CA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Search Protocol Host", "meta_original_filename": "SearchProtocolHost.exe", "meta_product_name": "Windows Search", "meta_company_name": "Microsoft Corporation", "meta_file_version": "7.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "7.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/4c17b29541a680eb3e9d11b2031f1dd3f4074b4708ba704948216b0dcf231318/detection/" }, "SecEdit.exe-B1FA162422034FB5E52499D0198F96B4": { "file_name": "SecEdit.exe", "file_path": "C:\\Windows\\SysWOW64\\SecEdit.exe", "hash_md5": "B1FA162422034FB5E52499D0198F96B4", "hash_sha1": "161CEC4D2B3FDD3A804AB9B8DA2B1C2B005A68AF", "hash_sha256": "343E8924EA917F83DED38FFF89675A233011D82B2ABA9D4A9675C24A039F5BE5", "hash_sha384": "0ADD4B725C05F6FE7F32E972DBCA09F72F415EF1F70E68D10B10F48A232D2867B947BD14D61CE67CD49F88C5D767F3F3", "hash_sha512": "1DAA11B669CA33ABA0077FD1C2ED7CF5B2F43FA44A72DDC6E57FF474D84F1F0C55CB5958A87A76514630521B2F5AC05F91CE7F35C75A05B961C136E343B64B03", "hash_ssdeep": "768:jhvDE20EyZuhDQzXgPGJ4uJqT7/pXkBEz:tg20Ez0zwPGJ4dgE", "hash_imp": "615449A6A25801F47AE0D7578EB950B4", "hash_pesha1": "71E64BF8350FE5F0E64ADF66A730083634EB6FF2", "hash_pe256": "5BBAEC56CEEEA820AB4127D180BD26144268059C1CBFEC4CEFB4A24A5BA95F30", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Security Configuration Editor Command Tool", "meta_original_filename": "SeCEdit", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/343e8924ea917f83ded38fff89675a233011d82b2aba9d4a9675c24a039f5be5/detection/", "output": "\r\nThe syntax of this command is:\r\n\r\nsecedit [/configure | /analyze | /import | /export | /validate | /generaterollback]\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\SecEdit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "secinit.exe-E92ABBDEAAA05EDD19DC9972D3B98DE8": { "file_name": "secinit.exe", "file_path": "C:\\Windows\\SysWOW64\\secinit.exe", "hash_md5": "E92ABBDEAAA05EDD19DC9972D3B98DE8", "hash_sha1": "2F523CDB09413CFC9CB64530F84ED20A1087B63D", "hash_sha256": "DDCE139B59FAFFE5ABDB12FB6C7FBD256E6E18CA7FA5938CB164E94857BA07E9", "hash_sha384": "72CDB9861EE60860FC40EB6871E3988C79DD1E6746B222E9B1B666D042569AC929C43401819130379E1E3F13B0AA5A5F", "hash_sha512": "57C606E09B770BED61450CC8DDDEDA4404254E509569081B7C941C3616C107377D12D21BF5E8A170D56A72FB702A6BC6CBA907395C1C1120399EA656E8A4F3E4", "hash_ssdeep": "192:wKNJVLN9VfIA628ghXhtNtm+Qk9W8vQzRiWGh:wm1N9tIA628gRv7Pr9W8vQzRiWG", "hash_imp": "87C27A671C9F1DC5F6B0744E9E74293E", "hash_pesha1": "83A09F3BC3E990192CAC7F1E7ECE61FEA44DBB8A", "hash_pe256": "952558317800320615F833865F15271E78A02AA7F80116221144356B191416A7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Security Init", "meta_original_filename": "secinit", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/ddce139b59faffe5abdb12fb6c7fbd256e6e18ca7fa5938cb164e94857ba07e9/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\secinit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "sethc.exe-999F4E59B7DB7AC9BA0A6F8DA894E2B9": { "file_name": "sethc.exe", "file_path": "C:\\Windows\\SysWOW64\\sethc.exe", "hash_md5": "999F4E59B7DB7AC9BA0A6F8DA894E2B9", "hash_sha1": "F4ADDE09E6993D881CDB992141028AA2A750679D", "hash_sha256": "CE13C119E81D353FD25FF6088AD011251259210BB2F2E72399A67887A4F2C2FB", "hash_sha384": "002E575EFD71C915910A0CA5A6FBD438360A2587BD5279640158DF2B98BAA2B98FB38BC5CD93684AAF6483BDC17BDEFE", "hash_sha512": "F84C9D0D8D4F4C042D95DF1419E762728D1685557D4E9307458A0670A8CF1449C50D63E1DA447B7C9AFEE8BCFF1DC876C441809039CF5D2F722D0CCE710D246F", "hash_ssdeep": "6144:v/eV0vQYHKAlGr66uFz2LJGRg4kLNnei36cw:nuChpFCdUc", "hash_imp": "1BA2225EBB5F11B47CA8667F66733C88", "hash_pesha1": "8C0E4D5FDE7D552CF390B3C63C55CC35904E3027", "hash_pe256": "78249B15336B9368D3FB5EC698CA5A3179DB6CC2D7929F8A484EE688AC8B557B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Accessibility shortcut keys", "meta_original_filename": "sethc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/ce13c119e81d353fd25ff6088ad011251259210bb2f2e72399a67887a4f2c2fb/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\sethc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "setspn.exe-B5C40D227A34916C35CD20C1D0F82DE0": { "file_name": "setspn.exe", "file_path": "C:\\Windows\\SysWOW64\\setspn.exe", "hash_md5": "B5C40D227A34916C35CD20C1D0F82DE0", "hash_sha1": "8881BCC3C119E478D57DC0DEE7F9D0EBF5E33510", "hash_sha256": "8438388897DFB56415372C74AA23D7C39F6863C0146024ED94E331B50574221E", "hash_sha384": "6E8CE17EC2379473FCB7A302EB94E8CDAAEDE1467D8BB931A42C31028EF9D6ABC24A235C7E34C31919D2A06D9E7715CF", "hash_sha512": "E7FF54076F9F9FAA8AC53DE228EFDF6684C5DD6ED16C73DAAEB8CFF1B18556609BAD0F5615D5BE230B278A6B6966F549D6442CD994CC681A31BE10EF864D1E11", "hash_ssdeep": "384:C/mo7K4hHCixhZd+NuAX5ERO7cot+rg/Mg/GdvaYzWYW4aWl:Cuo7K4FCeL+NfKa0gUg+sYia", "hash_imp": "15999B95AD28394287F092374BA3C64B", "hash_pesha1": "53CCB44E1023079E09C92BC3EEA7339A74BA3F62", "hash_pe256": "B1D24A1879911CCA615F8DEDEA0D413C6BE71D3818EAA95E8CB261CCE7F5BECA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Query or reset the computer's SPN attribute", "meta_original_filename": "setspn.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/8438388897dfb56415372c74aa23d7c39f6863c0146024ed94e331b50574221e/detection/", "output": "Usage: C:\\Windows\\SysWOW64\\setspn.exe [modifiers switch] [accountname] \r\n Where \"accountname\" can be the name or domain\\name\r\n of the target computer or user account\r\n\r\n Edit Mode Switches:\r\n -R = reset HOST ServicePrincipalName\r\n Usage: setspn -R accountname\r\n -S = add arbitrary SPN after verifying no duplicates exist\r\n Usage: setspn -S SPN accountname\r\n -D = delete arbitrary SPN\r\n Usage: setspn -D SPN accountname\r\n -L = list SPNs registered to target account\r\n Usage: setspn [-L] accountname \r\n\r\n Edit Mode Modifiers:\r\n -C = specify that accountname is a computer account\r\n -U = specify that accountname is a user account\r\n \r\n Note: -C and -U are exclusive. If neither is specified, the tool\r\n will interpret accountname as a computer name if such a computer\r\n exists, and a user name if it does not.\r\n\r\n Query Mode Switches:\r\n -Q = query for existence of SPN\r\n Usage: setspn -Q SPN \r\n -X = search for duplicate SPNs\r\n Usage: setspn -X \r\n\r\n Note: searching for duplicates, especially forestwide, can take\r\n a long period of time and a large amount of memory. -Q will execute\r\n on each target domain/forest. -X will return duplicates that exist\r\n across all targets. SPNs are not required to be unique across forests,\r\n but duplicates can cause authentication issues when authenticating\r\n cross-forest.\r\n\r\n Query Mode Modifiers:\r\n -P = suppresses progress to the console and can be used when redirecting\r\n output to a file or when used in an unattended script. There will be no\r\n output until the command is complete.\r\n -F = perform queries at the forest, rather than domain level\r\n -T = perform query on the speicified domain or forest (when -F is also used)\r\n Usage: setspn -T domain (switches and other parameters)\r\n \"\" or * can be used to indicate the current domain or forest.\r\n\r\n Note: these modifiers can be used with the -S switch in order to specify\r\n where the check for duplicates should be performed before adding the SPN.\r\n Note: -T can be specified multiple times.\r\n\r\nExamples: \r\nsetspn -R daserver1 \r\n It will register SPN \"HOST/daserver1\" and \"HOST/{DNS of daserver1}\" \r\nsetspn -S http/daserver daserver1 \r\n It will register SPN \"http/daserver\" for computer \"daserver1\" \r\n if no such SPN exists in the domain\r\nsetspn -D http/daserver daserver1 \r\n It will delete SPN \"http/daserver\" for computer \"daserver1\" \r\nsetspn -F -S http/daserver daserver1 \r\n It will register SPN \"http/daserver\" for computer \"daserver1\"\r\n if no such SPN exists in the forest\r\nsetspn -U -S http/daserver dauser \r\n It will register SPN \"http/daserver\" for user account \"dauser\" \r\n if no such SPN exists in the domain\r\nsetspn -T * -T bar -X\r\n It will report all duplicate registration of SPNs in this domain and bar\r\nsetspn -T bar -F -Q */daserver\r\n It will find all SPNs of the form */daserver registered in the forest to\r\n which bar belongs\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\setspn.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "FindDomainForAccount: Call to DsGetDcNameWithAccountW failed with return value 0x0000054B\r\nCould not find account help\r\n" }, "SettingSyncHost.exe-160669CA4DE30DFEB6D5AEFEE2A1EBA5": { "file_name": "SettingSyncHost.exe", "file_path": "C:\\Windows\\SysWOW64\\SettingSyncHost.exe", "hash_md5": "160669CA4DE30DFEB6D5AEFEE2A1EBA5", "hash_sha1": "9B136E60CE3D6A44171031AE783987778EC1B164", "hash_sha256": "020436DBAF8B73F2CA01EDF68F8098A38BC1FEF8551A51EF424B2C63F5DF3BB1", "hash_sha384": "963A22899B507AD69F0EA13F3FB51A59B6D3045900B0E3D9846B77434827F2FFB14B32041BC20BA06800FB8192C06E12", "hash_sha512": "226C7545B694933DB3D6BF97E573C9FBC65C18BB8036B87CD81ECD4D52CB247A3DD3DA56EA75F3ED39FD02BFA33C52ABF4D36B77CAA8E204CAE60D68832E9F89", "hash_ssdeep": "24576:r3TP5qU6KEtzaIsvdNCtCsDTlUDQp6IB+MZV9aF9Xqw:LTOt2IsVNC0sdUDaPkFEw", "hash_imp": "0AE2ABEE2FDDD74040A4859EE309463A", "hash_pesha1": "0A6C4EF8E1C78CFA0B6A9FAA98F66561A303D596", "hash_pe256": "706B1D97259D5EFCFB5ADCCB80B03A52B94193AC3F65872360E36A812C70D345", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Setting Synchronization", "meta_original_filename": "SettingSyncHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/020436dbaf8b73f2ca01edf68f8098a38bc1fef8551a51ef424b2c63f5df3bb1/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\SettingSyncHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "setup16.exe-13DBC931C358F6F28E7B4145D53C4F95": { "file_name": "setup16.exe", "file_path": "C:\\Windows\\SysWOW64\\setup16.exe", "hash_md5": "13DBC931C358F6F28E7B4145D53C4F95", "hash_sha1": "15760AC9EFAC39804A46AC1314FE8913E16D273A", "hash_sha256": "3D244E2BD05619FE4272E9E30C183E440CFF48BCDA8E24D62B12CAB68C9957E3", "hash_sha384": "FB2898250BAD1ACFBA1261DB72FF2B9368D08F2749942DB4F3F4242B1DF6A93A8ECDF245823EAE2631AAC41B3A8CEE20", "hash_sha512": "E06D2EB7C09939EE5B6680A280BE5CF70393DF546AE5E41A6DF74522B94F9BA80F19466E56DDD280C624E80402764A911D2FBD284139F494EB696E252167DF4D", "hash_ssdeep": "384:rFbbbTsT7N3sd4roLry/4lnoBnYZTG87g4I6B1LmRrVjsAq+FwWSpyW7E:ZyYNSsnEYZTG8eoLMRXqLk", "hash_imp": "4378AB751681DA98AB3B304461A9B42A", "hash_pesha1": "2659CA2D90C1EF8C24E97C8FACAB99B9672CB15A", "hash_pe256": "003752178CD1F844EC214B62B69170536BC299791EFFC4DCDBAFEEEE336283AB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "MS-Setup Setup Exe", "meta_original_filename": "SETUP.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "3.01 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright Microsoft Corp. 1991-1997", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/3d244e2bd05619fe4272e9e30c183e440cff48bcda8e24d62b12cab68c9957e3/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\setup16.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\setup16.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Setup Initialization Error" }, "setupugc.exe-DC9BE665123FE937A833BE9E427EF850": { "file_name": "setupugc.exe", "file_path": "C:\\Windows\\SysWOW64\\setupugc.exe", "hash_md5": "DC9BE665123FE937A833BE9E427EF850", "hash_sha1": "9A90B70DF7D36CB1122E8A98DA05DFA8F0956A2A", "hash_sha256": "D1075CEC07787200D3637F001FA7F2467C6601D41AFD2D2AA410282E1D479F71", "hash_sha384": "D8DB9625D96AA792DF466FBFC2A25C2D378D83DA17D2007D26431B72B115CFF1F050E89AF2AC580F50604EAD5904CC9C", "hash_sha512": "343582C30AA78714CC17274E0DA38F7ED5F8DBC5778CBE6E983CF06E553665E5D057388EC60AD9F00DEB7A83B089ACA8A3FEDC600750E6E61122DC2590D84C0B", "hash_ssdeep": "1536:s6bihsvnAmUD2ueu6hQekxbCU6t4xAj10Idi1Sk+ZdQFEqeRnybsSO:s+vAnDfeuJxZ6H0z1j+Zd2EVnybk", "hash_imp": "42249CB19BA34427F76E7A4CEACE1C81", "hash_pesha1": "86EFA609AA12E919224C8F5A00F0576D8BC4B2B4", "hash_pe256": "CDC040CB00B6A8C79E82B04AD937E45B6785892256700E9C8F953BEA089BC61E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Setup Unattend Generic Command Processor", "meta_original_filename": "SETUPUGC.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Windows\\SysWOW64\\setupugc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "setx.exe-CD05A95FE2D993EFB22EB27F6F0A1A68": { "file_name": "setx.exe", "file_path": "C:\\Windows\\SysWOW64\\setx.exe", "hash_md5": "CD05A95FE2D993EFB22EB27F6F0A1A68", "hash_sha1": "D4E03C8F5F782C93614F27ED4F36CDEA2ABBD8C2", "hash_sha256": "930EF8D553D8CDEE74724955431F13EFDB1BE212BC615E67A3CFD4D1A74D3497", "hash_sha384": "047A17D5DE15E34FEBE8460A62D954315107B98F8788263F01F65101E1B66B15532D1238B89D003B54D9CF90E716A06F", "hash_sha512": "8F811474EEB4AB95C59F9894CC5C53B287BD2C0290111DD451145639AA7657A99E3BD1683675915A79DE8077024575776140EF8977A7FF2C46F54CD5728F736C", "hash_ssdeep": "768:2mvk5lE6QawdkJZ+LI6/Q/vCHjvXOhB440jn1NjWTv+DN4GbsiIZJaP0+iEtujN+:LvkWa9JZMx/Q6vOj44cXirZGbsSP0+i+", "hash_imp": "9C2B9F65C9F5C2641E40D83FBA676576", "hash_pesha1": "367A695E3EF2958B2BF40D73D66B1029E5EAAB09", "hash_pe256": "19ED141CE4D1FC6A27D04E141F4A8292D443EBEA9D8A83D48444A3CC3CDEB453", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Setx - Sets environment variables", "meta_original_filename": "setx.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/930ef8d553d8cdee74724955431f13efdb1be212bc615e67a3cfd4d1a74d3497/detection/", "output": "\r\nSetX has three ways of working: \r\n\r\nSyntax 1:\r\n SETX [/S system [/U [domain\\]user [/P [password]]]] var value [/M]\r\n\r\nSyntax 2:\r\n SETX [/S system [/U [domain\\]user [/P [password]]]] var /K regpath [/M]\r\n\r\nSyntax 3:\r\n SETX [/S system [/U [domain\\]user [/P [password]]]]\r\n /F file {var {/A x,y | /R x,y string}[/M] | /X} [/D delimiters]\r\n\r\nDescription:\r\n Creates or modifies environment variables in the user or system\r\n environment. Can set variables based on arguments, regkeys or\r\n file input.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n var Specifies the environment variable to set.\r\n\r\n value Specifies a value to be assigned to the \r\n environment variable.\r\n\r\n /K regpath Specifies that the variable is set based\r\n on information from a registry key.\r\n Path should be specified in the format of\r\n hive\\key\\...\\value. For example,\r\n HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\\r\n Control\\TimeZoneInformation\\StandardName.\r\n\r\n /F file Specifies the filename of the text file\r\n to use.\r\n\r\n /A x,y Specifies absolute file coordinates\r\n (line X, item Y) as parameters to search \r\n within the file.\r\n\r\n /R x,y string Specifies relative file coordinates with\r\n respect to \"string\" as the search parameters.\r\n\r\n /M Specifies that the variable should be set in\r\n the system wide (HKEY_LOCAL_MACHINE)\r\n environment. The default is to set the\r\n variable under the HKEY_CURRENT_USER \r\n environment.\r\n\r\n /X Displays file contents with x,y coordinates.\r\n\r\n /D delimiters Specifies additional delimiters such as \",\"\r\n or \"\\\". The built-in delimiters are space,\r\n tab, carriage return, and linefeed. Any \r\n ASCII character can be used as an additional\r\n delimiter. The maximum number of delimiters,\r\n including the built-in delimiters, is 15.\r\n\r\n /? Displays this help message.\r\n\r\nNOTE: 1) SETX writes variables to the master environment in the registry.\r\n\r\n 2) On a local system, variables created or modified by this tool\r\n will be available in future command windows but not in the\r\n current CMD.exe command window.\r\n\r\n 3) On a remote system, variables created or modified by this tool\r\n will be available at the next logon session.\r\n\r\n 4) The valid Registry Key data types are REG_DWORD, REG_EXPAND_SZ,\r\n REG_SZ, REG_MULTI_SZ.\r\n\r\n 5) Supported hives: HKEY_LOCAL_MACHINE (HKLM),\r\n HKEY_CURRENT_USER (HKCU).\r\n\r\n 6) Delimiters are case sensitive.\r\n\r\n 7) REG_DWORD values are extracted from the registry in decimal \r\n format.\r\n\r\nExamples:\r\n SETX MACHINE COMPAQ \r\n SETX MACHINE \"COMPAQ COMPUTER\" /M\r\n SETX MYPATH \"%PATH%\"\r\n SETX MYPATH ~PATH~\r\n SETX /S system /U user /P password MACHINE COMPAQ \r\n SETX /S system /U user /P password MYPATH ^%PATH^% \r\n SETX TZONE /K HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\\r\n Control\\TimeZoneInformation\\StandardName\r\n SETX BUILD /K \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\r\n NT\\CurrentVersion\\CurrentBuildNumber\" /M\r\n SETX /S system /U user /P password TZONE /K HKEY_LOCAL_MACHINE\\\r\n System\\CurrentControlSet\\Control\\TimeZoneInformation\\\r\n StandardName\r\n SETX /S system /U user /P password BUILD /K \r\n \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\\r\n CurrentVersion\\CurrentBuildNumber\" /M\r\n SETX /F ipconfig.out /X \r\n SETX IPADDR /F ipconfig.out /A 5,11 \r\n SETX OCTET1 /F ipconfig.out /A 5,3 /D \"#$*.\" \r\n SETX IPGATEWAY /F ipconfig.out /R 0,7 Gateway\r\n SETX /S system /U user /P password /F c:\\ipconfig.out /X\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\setx.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "ERROR: Invalid syntax.\r\nType \"SETX /?\" for usage.\r\n" }, "sfc.exe-4A5EAB448C2CCC0FE104F3D2EAFA31E8": { "file_name": "sfc.exe", "file_path": "C:\\Windows\\SysWOW64\\sfc.exe", "hash_md5": "4A5EAB448C2CCC0FE104F3D2EAFA31E8", "hash_sha1": "6C8C046CF68396AF97D56870D576BD3E17EC5DFE", "hash_sha256": "9947DAF25487C97017038EFC3E19F6B8D7F3208BBAC05BD9C7DE2CD0A37C48C4", "hash_sha384": "81AFA8298A5ED212510C109B2AB1C49B7734CA4A80061DE999B65DE5C2106E1A50A07368B2DF440D0C425D8F82683487", "hash_sha512": "11F64F6B78595041EC4A4E5786B0F043F769D20A1BBED62CD90813A773BF6045E61DBFDDBB89503CACE1C0198CD9826A43AED8A8A3679FEDED6CCA677245CE4F", "hash_ssdeep": "768:4+r4pn+uvQ+4mAwOZIVDxK9E91dhU8lOjw4NUGEBk6a:4+uv/awrIGznbCUGEBk6a", "hash_imp": "CAC2B6353149BCC7390792522C3321BD", "hash_pesha1": "5789893F1A1E2C5C20C4DFC964D0FAF99646BD09", "hash_pe256": "6D2A22F45E5DE9AA8CC2A2D5F08936061094E6487FB2D02675BAF85C8C77709C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Integrity Check and Repair", "meta_original_filename": "sfc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/9947daf25487c97017038efc3e19f6b8d7f3208bbac05bd9c7de2cd0a37c48c4/detection/", "output": "\r\r\nMicrosoft (R) Windows (R) Resource Checker Version 6.0\r\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\r\n\r\r\nScans the integrity of all protected system files and replaces incorrect versions with \r\r\ncorrect Microsoft versions.\r\r\n\r\r\nSFC [/SCANNOW] [/VERIFYONLY] [/SCANFILE=<file>] [/VERIFYFILE=<file>]\r\r\n [/OFFWINDIR=<offline windows directory> /OFFBOOTDIR=<offline boot directory> [/OFFLOGFILE=<log file path>]]\r\r\n\r\r\n/SCANNOW Scans integrity of all protected system files and repairs files with\r\r\n problems when possible.\r\r\n/VERIFYONLY Scans integrity of all protected system files. No repair operation is\r\r\n performed.\r\r\n/SCANFILE Scans integrity of the referenced file, repairs file if problems are\r\r\n identified. Specify full path <file>\r\r\n/VERIFYFILE Verifies the integrity of the file with full path <file>. No repair\r\r\n operation is performed.\r\r\n/OFFBOOTDIR For offline repair, specify the location of the offline boot directory\r\r\n/OFFWINDIR For offline repair, specify the location of the offline windows directory\r\r\n/OFFLOGFILE For offline repair, optionally enable logging by specifying a log file path\r\r\n\r\r\ne.g.\r\r\n\r\r\n sfc /SCANNOW\r\r\n sfc /VERIFYFILE=c:\\windows\\system32\\kernel32.dll\r\r\n sfc /SCANFILE=d:\\windows\\system32\\kernel32.dll /OFFBOOTDIR=d:\\ /OFFWINDIR=d:\\windows\r\r\n sfc /SCANFILE=d:\\windows\\system32\\kernel32.dll /OFFBOOTDIR=d:\\ /OFFWINDIR=d:\\windows /OFFLOGFILE=c:\\log.txt\r\r\n sfc /VERIFYONLY\r\r\n" }, "shrpubw.exe-51311626D7D8EC313EF248FB60776F1A": { "file_name": "shrpubw.exe", "file_path": "C:\\Windows\\SysWOW64\\shrpubw.exe", "hash_md5": "51311626D7D8EC313EF248FB60776F1A", "hash_sha1": "8FF4CD1F1C069A86E3F48F5C715BDF8C51BE98F6", "hash_sha256": "6B4E6BB29538F24AFCF8B823383B846D2D483D83B38C3F74902995DE6E6679F8", "hash_sha384": "87974F31D79047D68456454AFC9C7EBB18F53FEC3131FE5E9A01252F2B0D7678A692DFFFD93E7187AC6805890F43AB1D", "hash_sha512": "6F68E57053C9146CBDB66AA5955065A7F5022AEA319F258A27498E7269ADCAF37279DF276A7A47D36A5AF6A1F003AB3B46C2F0901491440ACC9D8625697ADF4D", "hash_ssdeep": "1536:aXAWBTT7E7F3D0l4AuIDKBTxWJF51KsvhFsVqvCm:aQWBTT7EtptIcgJFWsvNvCm", "hash_imp": "1201946CACA3EB9F82F662E94886BB4C", "hash_pesha1": "35DACC9697FACD72507FE85CCC5493EB29C52B9B", "hash_pe256": "80F28D7DE71D1093CF841B36D590D0C3D131ED1AD6EF7D31AFB1F0D569318DB3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Share Creation Wizard", "meta_original_filename": "shrpubw.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/6b4e6bb29538f24afcf8b823383b846d2d483d83b38c3f74902995de6e6679f8/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\shrpubw.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\aclui.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\shrpubw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Create A Shared Folder Wizard" }, "shutdown.exe-1AABFB92B0F4C0D1531F72515848FD8A": { "file_name": "shutdown.exe", "file_path": "C:\\Windows\\SysWOW64\\shutdown.exe", "hash_md5": "1AABFB92B0F4C0D1531F72515848FD8A", "hash_sha1": "F446E7B7BBFB264DAB922614A748340640BE6DB4", "hash_sha256": "6219C1BC22930D17997DD21DEC663705ABA0B01FED1D11F73B6A9C721F894CB5", "hash_sha384": "A50F6D8A3EBC3D90AAFB099D3CCB03A0311F3E13BAB9643DA1179D4481C51DB8167A9461DC6272DA016E63373E2C5789", "hash_sha512": "B6269EE18F9F5746D7AC39488A33E9BD4D4452F7E2F4BC4CF7644D55FA3EF0AB2D6225551F101EB415F70264F191D731EF23A68138F9D92541E356318D5CBFCA", "hash_ssdeep": "384:Hk8ZkDFqPAkJ5b4EjIuUdo0XcM5VLAtjz+8Xp5Q/WK+SWk6R:HTsiv94EjIndo0X7AtjztXp5u+o6", "hash_imp": "8B92347E56758D2E293224C162867097", "hash_pesha1": "B453F501B57166123213A0B121D72C86735D92ED", "hash_pe256": "09C96798DE8C2786C91635C1FF3BF605680E3F0DC29301608D81361E5CB66384", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Shutdown and Annotation Tool", "meta_original_filename": "SHUTDOWN.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/6219c1bc22930d17997dd21dec663705aba0b01fed1d11f73b6a9c721f894cb5/detection/", "output": "Usage: C:\\Windows\\SysWOW64\\shutdown.exe [/i | /l | /s | /sg | /r | /g | /a | /p | /h | /e | /o] [/hybrid] [/soft] [/fw] [/f]\n [/m \\\\computer][/t xxx][/d [p|u:]xx:yy [/c \"comment\"]]\n\n No args Display help. This is the same as typing /?.\n /? Display help. This is the same as not typing any options.\n /i Display the graphical user interface (GUI).\n This must be the first option.\n /l Log off. This cannot be used with /m or /d options.\n /s Shutdown the computer.\n /sg Shutdown the computer. On the next boot,\n restart any registered applications.\n /r Full shutdown and restart the computer.\n /g Full shutdown and restart the computer. After the system is\n rebooted, restart any registered applications.\n /a Abort a system shutdown.\n This can only be used during the time-out period.\n Combine with /fw to clear any pending boots to firmware.\n /p Turn off the local computer with no time-out or warning.\n Can be used with /d and /f options.\n /h Hibernate the local computer.\n Can be used with the /f option.\n /hybrid Performs a shutdown of the computer and prepares it for fast startup.\n Must be used with /s option.\n /fw Combine with a shutdown option to cause the next boot to go to the\n firmware user interface.\n /e Document the reason for an unexpected shutdown of a computer.\n /o Go to the advanced boot options menu and restart the computer.\n Must be used with /r option.\n /m \\\\computer Specify the target computer.\n /t xxx Set the time-out period before shutdown to xxx seconds.\n The valid range is 0-315360000 (10 years), with a default of 30.\n If the timeout period is greater than 0, the /f parameter is\n implied.\n /c \"comment\" Comment on the reason for the restart or shutdown.\n Maximum of 512 characters allowed.\n /f Force running applications to close without forewarning users.\n The /f parameter is implied when a value greater than 0 is\n specified for the /t parameter.\n /d [p|u:]xx:yy Provide the reason for the restart or shutdown.\n p indicates that the restart or shutdown is planned.\n u indicates that the reason is user defined.\n If neither p nor u is specified the restart or shutdown is\n unplanned.\n xx is the major reason number (positive integer less than 256).\n yy is the minor reason number (positive integer less than 65536).\n\nReasons on this computer:\n(E = Expected U = Unexpected P = planned, C = customer defined)\nType\tMajor\tMinor\tTitle\n\n U \t0\t0\tOther (Unplanned)\nE \t0\t0\tOther (Unplanned)\nE P \t0\t0\tOther (Planned)\n U \t0\t5\tOther Failure: System Unresponsive\nE \t1\t1\tHardware: Maintenance (Unplanned)\nE P \t1\t1\tHardware: Maintenance (Planned)\nE \t1\t2\tHardware: Installation (Unplanned)\nE P \t1\t2\tHardware: Installation (Planned)\nE \t2\t2\tOperating System: Recovery (Unplanned)\nE P \t2\t2\tOperating System: Recovery (Planned)\n P \t2\t3\tOperating System: Upgrade (Planned)\nE \t2\t4\tOperating System: Reconfiguration (Unplanned)\nE P \t2\t4\tOperating System: Reconfiguration (Planned)\n P \t2\t16\tOperating System: Service pack (Planned)\n \t2\t17\tOperating System: Hot fix (Unplanned)\n P \t2\t17\tOperating System: Hot fix (Planned)\n \t2\t18\tOperating System: Security fix (Unplanned)\n P \t2\t18\tOperating System: Security fix (Planned)\nE \t4\t1\tApplication: Maintenance (Unplanned)\nE P \t4\t1\tApplication: Maintenance (Planned)\nE P \t4\t2\tApplication: Installation (Planned)\nE \t4\t5\tApplication: Unresponsive\nE \t4\t6\tApplication: Unstable\n U \t5\t15\tSystem Failure: Stop error\n U \t5\t19\tSecurity issue (Unplanned)\nE \t5\t19\tSecurity issue (Unplanned)\nE P \t5\t19\tSecurity issue (Planned)\nE \t5\t20\tLoss of network connectivity (Unplanned)\n U \t6\t11\tPower Failure: Cord Unplugged\n U \t6\t12\tPower Failure: Environment\n P \t7\t0\tLegacy API shutdown\n", "error": "Hibernation is not enabled on this system. You must enable hibernation in order to use the -h option.(126)\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\shutdown.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SndVol.exe-2A724F091A5C7329F41CE3B99D420EBD": { "file_name": "SndVol.exe", "file_path": "C:\\Windows\\SysWOW64\\SndVol.exe", "hash_md5": "2A724F091A5C7329F41CE3B99D420EBD", "hash_sha1": "F6720B46EA78D70162EB983AE8EE5EFE4F5AA9FA", "hash_sha256": "439997E510099CCD0D086DC1A99DF6651CED076B34DF2029A6CBBDAD6204B469", "hash_sha384": "386BC8928A60BCDF3FD7307D7BA0E3DD6703722E75F1D6C363C21106D7FABAA0D49EC2EAAC21C390DCB329517D5ABF03", "hash_sha512": "840C1D6794FE7A4222F479A5470336C45D9454F18981CE082FCA6F7D81BF0B50A6B03113DE0D57743A1689327F10AF4A833BD485AAB15794011D4799BCCC2105", "hash_ssdeep": "3072:kXdA52RxekzTkA5SKocHeKrEZAtOw+w//SfIBjbEyB7HbIdUAOo:k+yxeFA5SKPHeiP///qzy10dn", "hash_imp": "5F3F3778A963E0C44DCFB0F587F80B8A", "hash_pesha1": "B09B93235E33B199FB95E839C567E03D89A6C906", "hash_pe256": "CDB8BEA6F60AD50F0EA0B1AEA8DE074E6C8C08F480126F94F06A448DA4DCC290", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Volume Mixer", "meta_original_filename": "SndVol.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/439997e510099ccd0d086dc1a99df6651ced076b34df2029a6cbbdad6204b469/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_5706558cc25cc83b": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sndvol.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SndVol.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Volume Mixer" }, "sort.exe-1B8DE0D907DFF19D7C3623BC37BFC620": { "file_name": "sort.exe", "file_path": "C:\\Windows\\SysWOW64\\sort.exe", "hash_md5": "1B8DE0D907DFF19D7C3623BC37BFC620", "hash_sha1": "FBEF9032C1EA2065B6DF692629BFDCE0A189A5EF", "hash_sha256": "50A2F167CC31F53A9FBD23C5B9F0C28F72DB92AAE6D6638F25D41E9F5A30A4BD", "hash_sha384": "A7789ADB53EE1DDA92475851E9EFA147BA2E980B52CC4E1DD12287089C3C3D28E9319469304E8C4EA0F806A1789EAB61", "hash_sha512": "EDB77CFEE2FB41CF51E483B3D8F412C4AE05F3DBA10B6EE4F27ED649851521B48C579E186B94512BC9A0CDACB22D3BA672DD5E3EA8433EF12C34A740419B0C0A", "hash_ssdeep": "384:9katLqx6gT1M/EUCcQjo6+GHQO/R0eZeEqSCy0ThEmOfWXnWuju:9htAchQjmGweeVy0qXc7ju", "hash_imp": "C30764D4D528C7CFA9CAA068FBEFF18D", "hash_pesha1": "F8211E4A6599246B6C9F5B0D459805E9920B1D1A", "hash_pe256": "5DEFE2DE9C0C9D368E9A440CE6721ABA76AE023676131ED63C7A837CC51D7A82", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Sort Utility", "meta_original_filename": "Sort.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/50a2f167cc31f53a9fbd23c5b9f0c28f72db92aae6d6638f25d41e9f5a30a4bd/detection/", "output": "SORT [/R] [/+n] [/M kilobytes] [/L locale] [/REC recordbytes]\r\r\n [[drive1:][path1]filename1] [/T [drive2:][path2]]\r\r\n [/O [drive3:][path3]filename3]\r\r\n /+n Specifies the character number, n, to\r\r\n begin each comparison. /+3 indicates that\r\r\n each comparison should begin at the 3rd\r\r\n character in each line. Lines with fewer\r\r\n than n characters collate before other lines.\r\r\n By default comparisons start at the first\r\r\n character in each line.\r\r\n /L[OCALE] locale Overrides the system default locale with\r\r\n the specified one. The \"\"C\"\" locale yields\r\r\n the fastest collating sequence and is\r\r\n currently the only alternative. The sort\r\r\n is always case insensitive.\r\r\n /M[EMORY] kilobytes Specifies amount of main memory to use for\r\r\n the sort, in kilobytes. The memory size is\r\r\n always constrained to be a minimum of 160\r\r\n kilobytes. If the memory size is specified\r\r\n the exact amount will be used for the sort,\r\r\n regardless of how much main memory is\r\r\n available.\r\r\n\r\r\n The best performance is usually achieved by\r\r\n not specifying a memory size. By default the\r\r\n sort will be done with one pass (no temporary\r\r\n file) if it fits in the default maximum\r\r\n memory size, otherwise the sort will be done\r\r\n in two passes (with the partially sorted data\r\r\n being stored in a temporary file) such that\r\r\n the amounts of memory used for both the sort\r\r\n and merge passes are equal. The default\r\r\n maximum memory size is 90% of available main\r\r\n memory if both the input and output are\r\r\n files, and 45% of main memory otherwise.\r\r\n /REC[ORD_MAXIMUM] characters Specifies the maximum number of characters\r\r\n in a record (default 4096, maximum 65535).\r\r\n /R[EVERSE] Reverses the sort order; that is,\r\r\n sorts Z to A, then 9 to 0.\r\r\n [drive1:][path1]filename1 Specifies the file to be sorted. If not\r\r\n specified, the standard input is sorted.\r\r\n Specifying the input file is faster than\r\r\n redirecting the same file as standard input.\r\r\n /T[EMPORARY]\r\r\n [drive2:][path2] Specifies the path of the directory to hold\r\r\n the sort's working storage, in case the data\r\r\n does not fit in main memory. The default is\r\r\n to use the system temporary directory.\r\r\n /O[UTPUT]\r\r\n [drive3:][path3]filename3 Specifies the file where the sorted input is\r\r\n to be stored. If not specified, the data is\r\r\n written to the standard output. Specifying\r\r\n the output file is faster than redirecting\r\r\n standard output to the same file.\r\r\n\r\n", "error": "Invalid switch.\r\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\sort.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SpatialAudioLicenseSrv.exe-EAF509BCE23BB6D62F517E5DC569C682": { "file_name": "SpatialAudioLicenseSrv.exe", "file_path": "C:\\Windows\\SysWOW64\\SpatialAudioLicenseSrv.exe", "hash_md5": "EAF509BCE23BB6D62F517E5DC569C682", "hash_sha1": "831C70ECE1E878E9C626654579452F8858FE9233", "hash_sha256": "E17621CC0EA64AE63FF156C1AA34D64C3CE1C0C81AF4233A50DABC809F1AA264", "hash_sha384": "2D4A1793DF20039AD2652F01B6F76373F8514615A6C68C638A78BA981F2F89D21FBC49B774F089E74570AAB25B5CA395", "hash_sha512": "5621DF7085F25BB707006ED61D3A6BC0CD10A2BF017A1736D0D3F985DE6B1EAB6FEB7811E29106B815583E389CF27445E519E24F1455B947F9B68635667EC025", "hash_ssdeep": "3072:H5ssvkyH7qu400RzVj8zjMR3QgghCGzJ+iW4roAzuiGesThN+7b:HdrOu1WzxkV0woAzuhN1+b", "hash_imp": "0BD7721054C3E0114A408B0BF1B3528E", "hash_pesha1": "1791E6D8CF1CCA800B44C049439AC0AD4FE3A58D", "hash_pe256": "5F8913B5E82251ECD39FDA98AF6A605BBFA31770DD85C861F8A3A90744E26F38", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Spatial License AppService Broker", "meta_original_filename": "SpatialLicenseSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SpatialAudioLicenseSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "stordiag.exe-1F08AA1B4FB6EF5EFC219CC25A27C2E7": { "file_name": "stordiag.exe", "file_path": "C:\\Windows\\SysWOW64\\stordiag.exe", "hash_md5": "1F08AA1B4FB6EF5EFC219CC25A27C2E7", "hash_sha1": "C049D4B5AAC6C736ADEFB1FC243E7F9538D923A0", "hash_sha256": "D706DC037C51B48E412E6CA00129FC34F06830C27260A5D84F7D30D61237E980", "hash_sha384": "EEC1A09610AAF32BB8E2A5EA47294B9AD14F1723B912D125DED85FD4F5E65D9CA5814A185DD1CC4DCB891A849230494A", "hash_sha512": "47514CFDC13281FFE3FFBF3C53EC55BC53F3DACD96DEC6AFA58AC8B064FC2D144BBE4B744161E172A102FAD2C44CDB3B58962C0DAF7CF6F1A417F1B28660D05F", "hash_ssdeep": "1536:LSXiToaguRN2LT0SA6Tny2esoOCrcLbJWE4KWh+fbyJ:OXBagGA0SAGy8/bJWE4t2byJ", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "EF32A573149F3BFF31FA622A8D1771C250B4CA3F", "hash_pe256": "EFB192C80026823F3FE2A59C2BD9E3319CF03F68034FAEAC10816E6473940A6C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": " ", "meta_original_filename": "stordiag.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1", "meta_product_version": "10.0.17763.1", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/d706dc037c51b48e412e6ca00129fc34f06830c27260a5d84f7d30d61237e980/detection/", "output": "\r\nCollects storage and filesystem diagnostic logs and outputs them to a folder.\r\n\r\nStorDiag [-collectEtw] [-out <PATH>]\r\n-collectEtw Collect a 30-second long ETW trace if run from an elevated session\r\n-collectPerf Collect disk performance counters\r\n-checkFSConsistency Checks for the consistency of the NTFS file system\r\n-diagnostic outputs a storage diagnostic report\r\n-bootdiag output boot sectors of the disk\r\n-driverdiag output avaliable storport and storahci logs\r\n-out <PATH> Specify the output path. If not specified, logs are saved to %TEMP%\\StorDiag\r\n\r\n\r\n", "children": [ "conhost.exe", "systeminfo.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R--) C:\\Users\\user\\AppData\\Local\\Temp\\2\\StorDiag\\PSLogs.txt": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_2300": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\stordiag.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\5543cca0df435801e2303ff46a482ed5\\mscorlib.ni.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\6885802f40fd803e49150d8a2b43a09b\\System.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Management\\35d31e1630335aeb7e7cb2ed836e7230\\System.Management.ni.dll" ] }, "subst.exe-1CD4F787762A6A3688F02A346F6D5178": { "file_name": "subst.exe", "file_path": "C:\\Windows\\SysWOW64\\subst.exe", "hash_md5": "1CD4F787762A6A3688F02A346F6D5178", "hash_sha1": "EA9A28875EF01A07BDC95946305624B427786E7B", "hash_sha256": "7825146856DEFE9D7D240585117330A3D6B3BC8E4023FFA94C351CDE6FEB2F39", "hash_sha384": "206A561E12D11CC98537056C09689F64169423F7196EFECD54E3DD9EE72DBA73CA64C3F7C126B144D889906CA4BB4DE1", "hash_sha512": "C6AFCD8ACF0052BF1DAB22E5FD12FD6855C0E3A085B7484E932D2C1126785F4C222D60F8D0CDFC25B18B7577BD6D6117FFCBAEFABC34E8E52F9796B9E2277B86", "hash_ssdeep": "192:jGLQZcd/5MFs8B72LItJ6pkhEd3MtcnkxVRXkZWYGWju:rZc55MFbh2A6pkhm3oEuUZWYGWju", "hash_imp": "7DD76573763F447C2EF4E1C30B281996", "hash_pesha1": "09C3D7CF5CD6B26BA6A4D8D2ADB0F5025186C6E2", "hash_pe256": "9DC542AC72840F389EB0221778253301D6CC06DBAD38AEAEED746080CCB1D8B0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Subst Utility", "meta_original_filename": "Subst.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/7825146856defe9d7d240585117330a3d6b3bc8e4023ffa94c351cde6feb2f39/detection/", "output": "Associates a path with a drive letter.\r\n\r\nSUBST [drive1: [drive2:]path]\r\nSUBST drive1: /D\r\n\r\n drive1: Specifies a virtual drive to which you want to assign a path.\r\n [drive2:]path Specifies a physical drive and path you want to assign to\r\n a virtual drive.\r\n /D Deletes a substituted (virtual) drive.\r\n\r\nType SUBST with no parameters to display a list of current virtual drives.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\subst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "svchost.exe-23E47CE30CFC49F60A6E24B50AA83B9B": { "file_name": "svchost.exe", "file_path": "C:\\Windows\\SysWOW64\\svchost.exe", "hash_md5": "23E47CE30CFC49F60A6E24B50AA83B9B", "hash_sha1": "E8E2A9E05F117F5A03037CDABC21E453D777A8CA", "hash_sha256": "D8ECEAC9D02F7E8AAACA7BEEB8DC3FF28A0574E07FB34CA8E6720A6BC1126292", "hash_sha384": "C0EF72F60CAAC2A9D243116CC5782656F3BC0A33C7CE4895D62306598E03448D38262732D76CA0194E9710539E425221", "hash_sha512": "C86F077FEE11E732E05DD49F4AAA5CDA3CCC5BA1E3BF12E41E8C4830E99A8AC68DD1545A46FAE04504F2824D2462C9EB2AF640A4C7C54693535C6854F0050FBE", "hash_ssdeep": "768:asS9ve0lF/t7hl1IuwpPZCP8cVpmm6/oy1P7lA:a/lF/t7hlSuwpPZ16mm6FPJA", "hash_imp": "EC10F5BE711CB724C2D4D18A3C10AD6D", "hash_pesha1": "6F6983E1CE13F7E2DCFB76BFE65369143983AD45", "hash_pe256": "9C878AF3109C48E7685578A05D8532D45E95DA65ECCF138D26200FDC7401A2A2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Windows Services", "meta_original_filename": "svchost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/d8eceac9d02f7e8aaaca7beeb8dc3ff28a0574e07fb34ca8e6720a6bc1126292/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\svchost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "sxstrace.exe-B50DF715CD6FD0B92C660F2326B0181E": { "file_name": "sxstrace.exe", "file_path": "C:\\Windows\\SysWOW64\\sxstrace.exe", "hash_md5": "B50DF715CD6FD0B92C660F2326B0181E", "hash_sha1": "744C299AE16176C51685010BD913BD28748D2DE2", "hash_sha256": "3325883FD89108DD698638098CD9DFA14A2A75FD5FA812BDFD69BE23F5CA4C3D", "hash_sha384": "34B8350BAB5F1CE55D3149A80F4D76B112FBF317ABA974E373FBA318696565B23336106E9F99FD2A6DA09AC031D34C67", "hash_sha512": "B9096B067F0B34AF6C300F4BB572421257BCC593F75E39BC647B941F5AFE7059A8B43F6683548E16B03F6887A9C9B163A609B52B56F53DA8E9414F797EDE5D32", "hash_ssdeep": "384:Y16d1wFt+e2CAVOGfllyWabjxvFD5XgQ+0u8QzaoaMHcQwuKNVuF4mmSYTQtf/zl:+ISbtyKWctM0uJzaVtzmmS/f/zUPY", "hash_imp": "E5F700CF708ED01F967809EB3E520C38", "hash_pesha1": "D67B30CA79A48D5364FD7D690555104E42FD1793", "hash_pe256": "8944F699B413525AE3F38DCD1F7F040E5631853211CCE3230988FFC9C2872912", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Sxs Tracing Tool", "meta_original_filename": "sxstrace.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/3325883fd89108dd698638098cd9dfa14a2a75fd5fa812bdfd69be23f5ca4c3d/detection/", "output": "WinSxs Tracing Utility.\r\nUsage: SxsTrace [Options]\r\nOptions:\r\n Trace -logfile:FileName [-nostop]\r\n Enabling tracing for sxs.\r\n Tracing log is saved to FileName.\r\n If -nostop is specified, will not prompt to stop tracing.\r\n Parse -logfile:FileName -outfile:ParsedFile [-filter:AppName]\r\n Translate the raw trace file into a human readable format and save the result to ParsedFile.\r\n Use -filter option to filter the output.\r\n Stoptrace\r\n Stop the trace if it is not stopped before.\r\nExample: SxsTrace Trace -logfile:SxsTrace.etl\r\n SxsTrace Parse -logfile:SxsTrace.etl -outfile:SxsTrace.txt\r\n" }, "SyncHost.exe-B2716691D5F75F1F2A965923E180CE36": { "file_name": "SyncHost.exe", "file_path": "C:\\Windows\\SysWOW64\\SyncHost.exe", "hash_md5": "B2716691D5F75F1F2A965923E180CE36", "hash_sha1": "C4515C49AC4DEE3814458B115CAE6ADB41CC5080", "hash_sha256": "47EB6D62CC9B494EB451D19A84407A879B0A4A98A46301558F6DA66D5A3CEF84", "hash_sha384": "EBB55E23DF5C6879A19883155AEE5695026592FDE8C0B12EDA1FAE4BFCBAD7E57BB7F8909BE7C303A327234D574C9545", "hash_sha512": "8ECFF769DBFD5600D97054D89C61106EE2BDB4CFE9AFB31EAFF6E7106803B05091F87755BEE6C923D3BF6515209083F6D3097E863BE689006513BDC65AB4349C", "hash_ssdeep": "768:y5j1FMyTOzZHR5I3w6jJosfM6o3SEUu10+v2werM2HTON:yvqgM5I3w6jJo0do3SS6+GF6N", "hash_imp": "DA44A81E79B6C3BEC0D978860B3682DC", "hash_pesha1": "AB9B96272635A971F55E314B1320C0877C157E2B", "hash_pe256": "531863E09325AF7A8F1CF6757C301F2D9DE16BABF4C2B39040A1D7A0012F8F1A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for Windows Sync", "meta_original_filename": "SyncHost.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/47eb6d62cc9b494eb451d19a84407a879b0a4a98a46301558f6da66d5a3cef84/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1068": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SyncHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "systeminfo.exe-78B75864DDE70F270C72207926ECE380": { "file_name": "systeminfo.exe", "file_path": "C:\\Windows\\SysWOW64\\systeminfo.exe", "hash_md5": "78B75864DDE70F270C72207926ECE380", "hash_sha1": "1240BBE7589C2DDB4110C6506B659C3E3EBD3B12", "hash_sha256": "81E6D6CB7A0F50F5BC331FD2AF48A90F2DCEE9FF7EF4F1ABE0B87866F7837985", "hash_sha384": "D23B5DF4A1CF7EAB5BD70F7068D35AFBAD3DCFD3D91A2AAADC1D986EF112D2DBE9560E86C7498901F0ACED5644B5370C", "hash_sha512": "71FFB6E94E2258D6B3A488423AF0CFDC48C15B61CCF02DF584C1C81047F8048F2C732988500FB8B429CD18754006BED637B6F2717431194ADD465096F74E672B", "hash_ssdeep": "1536:BHJiQveHyrh8h1j7F9QBXh2H5uZcrePiokhkGzc1UxRh4:3cx9Qtha5uZc6PiXJIUxT", "hash_imp": "C0D1DE37ED694783E9A9D18EB4AA4342", "hash_pesha1": "5C8472C3BEF8987EC8F4B01D91E28246EA6033A4", "hash_pe256": "F532C8B8623A3BB8DDEDE630DC7AA5FCC98EA6A945338BC4173D5E48BED1C9AF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Displays system information", "meta_original_filename": "sysinfo.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/81e6d6cb7a0f50f5bc331fd2af48a90f2dcee9ff7ef4f1abe0b87866f7837985/detection/", "output": "\r\nSYSTEMINFO [/S system [/U username [/P [password]]]] [/FO format] [/NH]\r\n\r\nDescription:\r\n This tool displays operating system configuration information for\r\n a local or remote machine, including service pack levels.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /FO format Specifies the format in which the output\r\n is to be displayed.\r\n Valid values: \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" should\r\n not be displayed in the output.\r\n Valid only for \"TABLE\" and \"CSV\" formats.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n SYSTEMINFO\r\n SYSTEMINFO /?\r\n SYSTEMINFO /S system\r\n SYSTEMINFO /S system /U user\r\n SYSTEMINFO /S system /U domain\\user /P password /FO TABLE\r\n SYSTEMINFO /S system /FO LIST\r\n SYSTEMINFO /S system /FO CSV /NH\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"SYSTEMINFO /?\" for usage.\r\n" }, "SystemPropertiesAdvanced.exe-2C8585C9189C92A1B04A3F37D541C892": { "file_name": "SystemPropertiesAdvanced.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesAdvanced.exe", "hash_md5": "2C8585C9189C92A1B04A3F37D541C892", "hash_sha1": "74C2BE757661A8E2C0A8B44D2FE142575FE0003F", "hash_sha256": "86C7DB0E662CA65F8E5989A629E00B03354CC385A9AEE8BED7AAAE28672D0A5F", "hash_sha384": "334BFDAF9DE77F058BB7CB847776D246E3598BA36DF27E190CB08AEE86A901EB35D9A9B0A07330A9EEFA735E7D520955", "hash_sha512": "A0840031DB7883C79D06B5EB4E276E87A999B3FF71C86A331C41503C228EC9DBA6219F9F7903CA529419E3968F4F5542D325DBD39D08FE19A0B2746B4C17B83B", "hash_ssdeep": "1536:kELZERtREC/rMcgEPJV+G57ThjEC0kzJP+V5Jt:kACzECTMpuDhjRVJGX", "hash_imp": "B788892AE84BA86201A726810F01CB07", "hash_pesha1": "38963B418634499A8D4796CF7294002601B619AE", "hash_pe256": "E29A11E5513F2B8802FAAAF275C2016DB9568619B326A9E87962CE798C3DAFA8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Advanced System Settings", "meta_original_filename": "SystemPropertiesAdvanced.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/86c7db0e662ca65f8e5989a629e00b03354cc385a9aee8bed7aaae28672d0a5f/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesAdvanced.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesAdvanced.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemPropertiesComputerName.exe-8618B83B5ABEA87429E5FFFEA0F66A1D": { "file_name": "SystemPropertiesComputerName.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesComputerName.exe", "hash_md5": "8618B83B5ABEA87429E5FFFEA0F66A1D", "hash_sha1": "CCEB5DCF20DD4BB362CAD2F4C36F31137F07D32D", "hash_sha256": "1425D610BEB0E3CC092EBE55CA1817AD0AE703489A20BFCABE52E0E2473A8A54", "hash_sha384": "36CCB4D5719988A4E4682B9E142D358E2586EAD650ADEEC2C8DA9F46013EE942F21AE63CAEE04E1E767ACB840C197031", "hash_sha512": "D4AF7F1578EA27AE4CE1DF6413E5886E4A78E010C9FE2EDCE596C6580F3D3B4726300920BC006404868C9B7E3F11ED6AA271A2FBF3ADE8BC155A5554F1D33B94", "hash_ssdeep": "1536:cELZKtREC/rMcgEPJV+G57ThjEC0kzJP+V5Jx:cAKzECTMpuDhjRVJG7", "hash_imp": "B788892AE84BA86201A726810F01CB07", "hash_pesha1": "BB3EA64E377F7407B7F2641545E915A60BFCBF59", "hash_pe256": "2786D2AC99F5A3D2AA88E2A59404F70F7C6095B868CF38351DBB564F2CF794F2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Computer Settings", "meta_original_filename": "SystemPropertiesComputerName.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/1425d610beb0e3cc092ebe55ca1817ad0ae703489a20bfcabe52e0e2473a8a54/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesComputerName.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesComputerName.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemPropertiesDataExecutionPrevention.exe-0CF1C719CD88DA2E2D163CBB1AEFE06C": { "file_name": "SystemPropertiesDataExecutionPrevention.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesDataExecutionPrevention.exe", "hash_md5": "0CF1C719CD88DA2E2D163CBB1AEFE06C", "hash_sha1": "8881150E8B9A5492EB4C6BD1D2E0FB0204C83386", "hash_sha256": "51259F775BE738CE33C857B7777E88C8B6A9AFE0C3202E99D4C76F688F315424", "hash_sha384": "26052E4943DC40D68BE2CFCD7832846B20B94F4B90DC667DD88BD36FB7D78699E51337C9DDF0CF8F1B947662748D0E7C", "hash_sha512": "A7C31DFF653EE6180310349AE8EF63486F3CD1E03518DFB408553E1AAD3C3B0DD0A9DDBF681F7F23801FD6B2288FC19607BA1425E44E2165DF8752FC6DBF0A65", "hash_ssdeep": "1536:SzbZKtREC/rMcgEPJV+G57ThjEC0kzJP+V5J0:SJKzECTMpuDhjRVJGe", "hash_imp": "B788892AE84BA86201A726810F01CB07", "hash_pesha1": "BD480DA5144A194F1AFE00FE54CDCFE6B2A28F23", "hash_pe256": "20EEA9D7BBC2A7339ADCC110D1B08C5B6D7D2B1A8E9B4BF121B1CE57EF133117", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Data Execution Prevention Settings", "meta_original_filename": "SystemPropertiesDataExecutionPrevention.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/51259f775be738ce33c857b7777e88c8b6a9afe0c3202e99d4c76f688f315424/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesDataExecutionPrevention.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesDataExecutionPrevention.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemPropertiesHardware.exe-DFC9141799F2E8D40521D3C7A1177B9F": { "file_name": "SystemPropertiesHardware.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesHardware.exe", "hash_md5": "DFC9141799F2E8D40521D3C7A1177B9F", "hash_sha1": "AC50A941F0E77FFE400AE7D93EFF54B786E775E8", "hash_sha256": "EB71926B0F0F8B48F831C9589FAD0F355F4E2A311F034C951A39DE396FB552B9", "hash_sha384": "92382B4697157858BA0DA34060D0AF589E0F83DBBBDE360733E06E76C6DEA7E139E45464885E57443DD35C9AAB6FE99E", "hash_sha512": "4A9BA6434CF75835F54C4CF4454F15776B41642D7EB5362C936304CCCC61A7A4431675967622FF7029393AC8D95F8E6B0DEEBF9CA9D48C2630E22526FEA2F439", "hash_ssdeep": "1536:IELZUFtREC/rMcgEPJV+G57ThjEC0kzJP+V5Jk:IA2zECTMpuDhjRVJGu", "hash_imp": "B788892AE84BA86201A726810F01CB07", "hash_pesha1": "E474ED223256D39F70B9E7E89F0402027CF741CE", "hash_pe256": "F8BF23582F89FBB831C47D57FF6E814E20A3BC04EC3BB7E6997B7AC31E79F8A8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Hardware Settings", "meta_original_filename": "SystemPropertiesHardware.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/eb71926b0f0f8b48f831c9589fad0f355f4e2a311f034c951a39de396fb552b9/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesHardware.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesHardware.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemPropertiesPerformance.exe-8820127B5E5BACAE8A63E4F9AB0ADD83": { "file_name": "SystemPropertiesPerformance.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesPerformance.exe", "hash_md5": "8820127B5E5BACAE8A63E4F9AB0ADD83", "hash_sha1": "62BF997683EDA05F4541CF70083EA84B98D7C98A", "hash_sha256": "2348ACB60563CA0997DA7378E5454515937EF9D54000A5E2E7FB5C81495896AF", "hash_sha384": "BB74C2AE8D2AD6737EE73B18B6E4BD809D39A113220E32132CCC23CF39C76C34BFFFC7017D3BF9947BED5C60A3FD3E20", "hash_sha512": "22F3C97D08A159F836BEF06962346E1C248DCD33928190B4914D054A1057403F3553C6762E0CC6D57BDDF368BC3DC48EE072839B9FA5054245649C3D00E3A00A", "hash_ssdeep": "1536:mbZUtREC/rMcgEPJV+G57ThjEC0kzJP+V5JV:KUzECTMpuDhjRVJG/", "hash_imp": "0C021C23DE2070C3C89AA72CC7E919E9", "hash_pesha1": "DE2E909DD54B26C23162DCBE5BA6A7083C6E6B18", "hash_pe256": "CB122793BB1996557132FB88E21D1753ED6C18A8ABFB2AD08D51D96FA8AED5FB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Change Computer Performance Settings", "meta_original_filename": "SystemPropertiesPerformance.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/2348acb60563ca0997da7378e5454515937ef9d54000a5e2e7fb5c81495896af/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesPerformance.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\shell32.dll": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesPerformance.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemPropertiesProtection.exe-911AECBC7F23CD36C804AD113162D5AD": { "file_name": "SystemPropertiesProtection.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesProtection.exe", "hash_md5": "911AECBC7F23CD36C804AD113162D5AD", "hash_sha1": "5FDFCA0E053A84E43E4AA1E206DEE7D1E5CB8573", "hash_sha256": "A13C30DF2C1D6C82A068C207E4EA66B4614C272B733511D234827FBABE6F73F3", "hash_sha384": "49F3B439DA3E3A493BA7250ED6BB31738624D3BEEBE071EFB8C4D1D571BA0663C612D07BEF4DBD62CAD72EC83A984C00", "hash_sha512": "E9F71D6361C13FEE6DFB219FBF8EF550E1E005AD53B85D3CF26CADE361BD8DC6A9D0551168B6104DE4FF0F9F6359309A21644BF8C09A6B0A11DD0264C71CE85A", "hash_ssdeep": "1536:5ELZ2tREC/rMcgEPJV+G57ThjEC0kzJP+V5Js:5A2zECTMpuDhjRVJGy", "hash_imp": "B788892AE84BA86201A726810F01CB07", "hash_pesha1": "B62A1443AEA64BBDE850E13ED7946F0586ABF091", "hash_pe256": "73B2FDAE95D7B0346E41F9055634C8C58CD0AF450E5C0C4E68D8F0AE9C63D2BA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Protection Settings", "meta_original_filename": "SSystemPropertiesProtection.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/a13c30df2c1d6c82a068c207e4ea66b4614c272b733511d234827fbabe6f73f3/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesProtection.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesProtection.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemPropertiesRemote.exe-6068264C72837FF4741001B5FC4DE7A1": { "file_name": "SystemPropertiesRemote.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemPropertiesRemote.exe", "hash_md5": "6068264C72837FF4741001B5FC4DE7A1", "hash_sha1": "414F149EAA6654C3B71A89330F3D8EB9EA71CAF9", "hash_sha256": "76C62B0DC6D0EEC97CE4AF5DBF7658C6025147EF73653C8E0CE33C15CF4D8570", "hash_sha384": "FF39680AEEAC24B4C21F5CA0513E63F47224A7425175E30AE5FDB57E18A66672D5573210B54844997B53DE08EB24D56C", "hash_sha512": "85734370E920B46782E99335A7B070BE327565EE58D8F5260DC53CAC17BF1482654733D8A9FD723458F1156D7FA6733A769AB4445EEFCFC566FA03945E88FCDA", "hash_ssdeep": "1536:9ELZsztREC/rMcgEPJV+G57ThjEC0kzJP+V5Ju:9AAzECTMpuDhjRVJGc", "hash_imp": "B788892AE84BA86201A726810F01CB07", "hash_pesha1": "27129F762FDA536A7595EFCF7290301EF35451DE", "hash_pe256": "0C79076F9137C0C4256F7C2D83D2DB55451467C7CA93D722FFA22B4C10156D32", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "System Remote Settings", "meta_original_filename": "SystemPropertiesRemote.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/76c62b0dc6d0eec97ce4af5dbf7658c6025147ef73653c8e0ce33c15cf4d8570/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\SystemPropertiesRemote.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\sysdm.cpl.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\remotepg.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\netid.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemPropertiesRemote.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SystemUWPLauncher.exe-F21E3EC55C20093CE02E06CD8AECAB6D": { "file_name": "SystemUWPLauncher.exe", "file_path": "C:\\Windows\\SysWOW64\\SystemUWPLauncher.exe", "hash_md5": "F21E3EC55C20093CE02E06CD8AECAB6D", "hash_sha1": "49BD17751080125EA94799C1FC5EEF09E0972AB6", "hash_sha256": "2068B64AB16FF39ACDBAD5F7F3A86066CF80AC84DACEA84457370070B9C9A69F", "hash_sha384": "42169A9446A64C849B370C2138C382410DCA310905F886C634FAECB95BBAC9F30B55F2B16D54A0491FF9814E6D304E57", "hash_sha512": "F4A2F3EDC3D8B9D937E45154D10280CD16E7C3BFAC352B29ECB3DEE72F3FF3808F60F1658D690F4FA973CB515F98F6292BA640FFD9D2FF1D2ECBCA51813FB38F", "hash_ssdeep": "768:tO8PhJ/hjW2SJEmrIwXuzKLamOaBjC1w0D2CyM2GHgyU2QHOi1xvWh4zpMV5ri:tO853erIwpZMtBFOOiCh4tMVw", "hash_imp": "82B0EE266ABEACC560946D186FE378F8", "hash_pesha1": "432051292DAEE957D442408AF00D4269DD4FC92D", "hash_pe256": "40D4C1EF92531710285F405138A196717FDEAE49DA65B56FD21584D0A5348652", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SystemUWPLauncher", "meta_original_filename": "SystemUWPLauncher.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1339 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1339", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/2068b64ab16ff39acdbad5f7f3a86066cf80ac84dacea84457370070b9c9a69f/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\SystemUWPLauncher.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "systray.exe-6621A1811053A752B0DE76F8EEFEC12D": { "file_name": "systray.exe", "file_path": "C:\\Windows\\SysWOW64\\systray.exe", "hash_md5": "6621A1811053A752B0DE76F8EEFEC12D", "hash_sha1": "E1683B3E33E8F28B578A6A1EDAED7B881ED53215", "hash_sha256": "3386B848E8218274A91D56CFCF95CAA5A641ED9B82DB1A9C686E22CE0C42A649", "hash_sha384": "20D9FD1F9FF91DA82F5CB4C785AC6A9AF2BA45BC6419BB3A2E387EF137A6304E6600A9F91A8920202FFA2B16D12B3ADB", "hash_sha512": "B2F078E6B1F76EFAB96B673289E56DFFB3EEC8F8466C0712B818D918CD7F3EE5941DBEFA8A1ED46BEEDF25B023AA63E3149E9654BCE2521A7E3774D7BE26CD75", "hash_ssdeep": "96:qtku2zQw4ZP4p2R4YdsDGjsW+sHQxpTxpstoCfXWUSiDJdMs2bKveL4EWXGyWw0:qCu9wuinW1JtoCfXWZYN+WWyWX", "hash_imp": "BDEE2028E64A4C6E54156264705E7D10", "hash_pesha1": "7910B619A15E9777B2CA83E7EB0E4FB754DBBD21", "hash_pe256": "1AADF35FA70EBF38CECB05832BCBF2E02776FC513CC073C53780D8140B9F4E3A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Systray .exe stub", "meta_original_filename": "systray.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/3386b848e8218274a91d56cfcf95caa5a641ed9b82db1a9c686e22ce0c42a649/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\systray.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "takeown.exe-84002ADE46B79E59157EB8BA002AFED6": { "file_name": "takeown.exe", "file_path": "C:\\Windows\\SysWOW64\\takeown.exe", "hash_md5": "84002ADE46B79E59157EB8BA002AFED6", "hash_sha1": "293352BE936E3BFAA18DD9D5BFA779C8B1DC19EE", "hash_sha256": "5C865D2D1012EBF9F2503F06F2C4B8AFCCAE063D1E79421E0244E0CF627E5FF1", "hash_sha384": "D31413305D3411F81F062A9CCBC448AAF8ADE72BA6F0EA67A12F6F9BAA68495E4E15B0436B47072F87880D67ACD2CC2C", "hash_sha512": "21774ED290C644EE988F30BA65CDDC9CCF43905698519CFB6E991F7DB3E52F7DC77424A47292F402916BEB619F9958EE204469BE9A850F72774F2DB229083B24", "hash_ssdeep": "1536:W3W7Cpl/5zR3jkNT1Gf4jViqfPpWfJZaFf6:HUjm0YVi4PpOJZal", "hash_imp": "3EFF225872A4BFF594AF402A5BBCC6F4", "hash_pesha1": "6AB04561E19BA177F0EA23D3BAD23FCEA2E86DCB", "hash_pe256": "699C07704014D7115430F5FF347C719266113B08336E8CCD72704EE881A63B95", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Takes ownership of a file", "meta_original_filename": "takeown.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/5c865d2d1012ebf9f2503f06f2c4b8afccae063d1e79421e0244e0cf627e5ff1/detection/", "output": "\r\nTAKEOWN [/S system [/U username [/P [password]]]]\r\n /F filename [/A] [/R [/D prompt]]\r\n\r\nDescription:\r\n This tool allows an administrator to recover access to a file that\r\n was denied by re-assigning file ownership.\r\n\r\nParameter List: \r\n /S system Specifies the remote system to\r\n connect to.\r\n\r\n /U [domain\\]user Specifies the user context under\r\n which the command should execute.\r\n\r\n /P [password] Specifies the password for the\r\n given user context.\r\n Prompts for input if omitted.\r\n\r\n /F filename Specifies the filename or directory\r\n name pattern. Wildcard \"*\" can be used\r\n to specify the pattern. Allows\r\n sharename\\filename.\r\n\r\n /A Gives ownership to the administrators\r\n group instead of the current user.\r\n\r\n /R Recurse: instructs tool to operate on\r\n files in specified directory and all \r\n subdirectories.\r\n\r\n /D prompt Default answer used when the current user\r\n does not have the \"list folder\" permission\r\n on a directory. This occurs while operating\r\n recursively (/R) on sub-directories. Valid \r\n values \"Y\" to take ownership or \"N\" to skip.\r\n\r\n /SKIPSL Do not follow symbolic links.\r\n Only applicable with /R.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE: 1) If /A is not specified, file ownership will be given to the\r\n current logged on user.\r\n\r\n 2) Mixed patterns using \"?\" and \"*\" are not supported.\r\n\r\n 3) /D is used to suppress the confirmation prompt.\r\n\r\nExamples: \r\n TAKEOWN /?\r\n TAKEOWN /F lostfile\r\n TAKEOWN /F \\\\system\\share\\lostfile /A\r\n TAKEOWN /F directory /R /D N\r\n TAKEOWN /F directory /R /A\r\n TAKEOWN /F *\r\n TAKEOWN /F C:\\Windows\\System32\\acme.exe\r\n TAKEOWN /F %windir%\\*.txt\r\n TAKEOWN /S system /F MyShare\\Acme*.doc\r\n TAKEOWN /S system /U user /F MyShare\\MyBinary.dll\r\n TAKEOWN /S system /U domain\\user /P password /F share\\filename\r\n TAKEOWN /S system /U user /P password /F Doc\\Report.doc /A\r\n TAKEOWN /S system /U user /P password /F Myshare\\* \r\n TAKEOWN /S system /U user /P password /F Home\\Logon /R\r\n TAKEOWN /S system /U user /P password /F Myshare\\directory /R /A\r\n", "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"TAKEOWN /?\" for usage.\r\n" }, "TapiUnattend.exe-1ABCB8B7EFA840DC7C998AA57FA7B563": { "file_name": "TapiUnattend.exe", "file_path": "C:\\Windows\\SysWOW64\\TapiUnattend.exe", "hash_md5": "1ABCB8B7EFA840DC7C998AA57FA7B563", "hash_sha1": "E17D0442FDA8292D22D1266F37F2EE42A02C227D", "hash_sha256": "137892CC79F32BF5A94A86D86FF107DF006E77FD3F0215137DA978C6552CB73A", "hash_sha384": "4821C82BE7F74DF0647C66EEA1A67E083C6025788A37A6D9A1DF77D453CE503B810267BEF32874ED08E4404B619B5ED1", "hash_sha512": "35EFE706C4F9687A11CC54A084BE9503B09DCAB011DB3FDB5280D05DAB29F718B4FB92B7EA24B30C19D55174113F9D1C45DC63E023F26245DE46B8F57A21DF1B", "hash_ssdeep": "192:KSOadkYPdilaGPwrnR46TkBrTYreHCMrDTpHMhLVtmYGGW/BUWJx:jvPUYWk6BrT8eHCMTpshfDGGW/BUWJx", "hash_imp": "38D2F52A7BB6275BB518DEE25030D230", "hash_pesha1": "47FDEC72A0900B9C48FB1B9EA3DF0A07CF9CD067", "hash_pe256": "6AE41072B54DACA90CDD77963164972F63DB3EF0CA8C7A13006E2E679B0FCEF6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) Telephony Unattend Action", "meta_original_filename": "TapiUnattend.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/137892cc79f32bf5a94a86d86ff107df006e77fd3f0215137da978c6552cb73a/detection/" }, "tar.exe-8E49D76E21295D010FF0803D65928F5A": { "file_name": "tar.exe", "file_path": "C:\\Windows\\SysWOW64\\tar.exe", "hash_md5": "8E49D76E21295D010FF0803D65928F5A", "hash_sha1": "0E42D4159BC6AFD910D45D3042E8D89EC2DC884E", "hash_sha256": "9D3AB89E9AA2C2C3686F43C7C8FA312B9F80180CE86137151726D16966816C50", "hash_sha384": "F1A3185BD2CBA1CD1B36C834773E425BE98BFD910581747DB1C5B454DEF4C78843D0A1CFA01CCC2208F564329A1E35B7", "hash_sha512": "40D8DFFC5744EDB14920EAC3F4E029CB85F042E60CF9EEB2FEF9846498F2552E4A26DDA4FB055C868929667DA2534189612E4183DAEFCB577AC808A0A6FD5A94", "hash_ssdeep": "768:d1Bt3SDGP9WE1BfRO7zr9gCWUHtIU9HVweBraJmBKaK:ryiP9N1B5YsOnnNaABKaK", "hash_imp": "8221DA6584BCFA0E0B0414E1A45A1C55", "hash_pesha1": "8B4F0F250AAA97A85DC11CEA39A51916B9462DDC", "hash_pe256": "557721C7595EAE5DC50956B006016B033B1AF269D79727AF31DF66761206E563", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "bsdtar archive tool", "meta_original_filename": "bsdtar", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "3.3.2 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (c) libarchive authors", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/9d3ab89e9aa2c2c3686f43c7c8fa312b9f80180ce86137151726d16966816c50/detection/", "error": "Usage:\r\n List: tar.exe -tf <archive-filename>\r\n Extract: tar.exe -xf <archive-filename>\r\n Create: tar.exe -cf <archive-filename> [filenames...]\r\n Help: tar.exe --help\r\n", "output": "tar.exe(bsdtar): manipulate archive files\r\nFirst option must be a mode specifier:\r\n -c Create -r Add/Replace -t List -u Update -x Extract\r\nCommon Options:\r\n -b # Use # 512-byte records per I/O block\r\n -f <filename> Location of archive (default \\\\.\\tape0)\r\n -v Verbose\r\n -w Interactive\r\nCreate: tar.exe -c [options] [<file> | <dir> | @<archive> | -C <dir> ]\r\n <file>, <dir> add these items to archive\r\n -z, -j, -J, --lzma Compress archive with gzip/bzip2/xz/lzma\r\n --format {ustar|pax|cpio|shar} Select archive format\r\n --exclude <pattern> Skip files that match pattern\r\n -C <dir> Change to <dir> before processing remaining files\r\n @<archive> Add entries from <archive> to output\r\nList: tar.exe -t [options] [<patterns>]\r\n <patterns> If specified, list only entries that match\r\nExtract: tar.exe -x [options] [<patterns>]\r\n <patterns> If specified, extract only entries that match\r\n -k Keep (don't overwrite) existing files\r\n -m Don't restore modification times\r\n -O Write entries to stdout, don't restore to disk\r\n -p Restore permissions (including ACLs, owner, file flags)\r\nbsdtar 3.3.2 - libarchive 3.3.2 zlib/1.2.5.f-ipp\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\tar.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "taskkill.exe-1CC726A03B77DBEFC34491C8F7E2F4C3": { "file_name": "taskkill.exe", "file_path": "C:\\Windows\\SysWOW64\\taskkill.exe", "hash_md5": "1CC726A03B77DBEFC34491C8F7E2F4C3", "hash_sha1": "3C3942FD8534E0BAB9BEF34D90491FFFCC8C0A46", "hash_sha256": "942E94F84340FA275FECFE87BC1CAEC8F667E9EEA29E67F72E3F2E2546BB3197", "hash_sha384": "A3A4C8B1FEDA18230F29740E1AAEC6F616BC4FDE9E9BB9FE6BAB2B5C9BFF2C70DAD815BB9E3A4488B89ACACAE5F4D3C4", "hash_sha512": "3E2E89BC87C5A0AE94E6323786D5F73D2A27E4FC5EBD9BA9A9EE37776558318CF2ED3BA62FE0F89C681D0E7EA1C756602354BFA22D06828F4F2EF24218E0DCF3", "hash_ssdeep": "1536:vJYuKPT33R0i/7UaM0JrLveqf7+cQka45ui9JrUhxU1cGx1SB:mbnLQwtPf7+cQkauuifUhxLGxsB", "hash_imp": "0D3E23DCB6BF63A9EB90D5BED57B4F89", "hash_pesha1": "E3890C4CDA436E20A778CFF14F147B486CE22CD6", "hash_pe256": "5B5B0BF6E2DB4E9845BA34CB576569588365ACAAB71664DD0D1909752A6B3081", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Terminates Processes", "meta_original_filename": "taskkill.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/942e94f84340fa275fecfe87bc1caec8f667e9eea29e67f72e3f2e2546bb3197/detection/", "output": "\r\nTASKKILL [/S system [/U username [/P [password]]]]\r\n { [/FI filter] [/PID processid | /IM imagename] } [/T] [/F]\r\n\r\nDescription:\r\n This tool is used to terminate tasks by process id (PID) or image name.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which the\r\n command should execute.\r\n\r\n /P [password] Specifies the password for the given user\r\n context. Prompts for input if omitted.\r\n\r\n /FI filter Applies a filter to select a set of tasks.\r\n Allows \"*\" to be used. ex. imagename eq acme*\r\n\r\n /PID processid Specifies the PID of the process to be terminated.\r\n Use TaskList to get the PID.\r\n\r\n /IM imagename Specifies the image name of the process\r\n to be terminated. Wildcard '*' can be used\r\n to specify all tasks or image names.\r\n\r\n /T Terminates the specified process and any\r\n child processes which were started by it.\r\n\r\n /F Specifies to forcefully terminate the process(es).\r\n\r\n /? Displays this help message.\r\n\r\nFilters:\r\n Filter Name Valid Operators Valid Value(s)\r\n ----------- --------------- -------------------------\r\n STATUS eq, ne RUNNING |\r\n NOT RESPONDING | UNKNOWN\r\n IMAGENAME eq, ne Image name\r\n PID eq, ne, gt, lt, ge, le PID value\r\n SESSION eq, ne, gt, lt, ge, le Session number.\r\n CPUTIME eq, ne, gt, lt, ge, le CPU time in the format\r\n of hh:mm:ss.\r\n hh - hours,\r\n mm - minutes, ss - seconds\r\n MEMUSAGE eq, ne, gt, lt, ge, le Memory usage in KB\r\n USERNAME eq, ne User name in [domain\\]user\r\n format\r\n MODULES eq, ne DLL name\r\n SERVICES eq, ne Service name\r\n WINDOWTITLE eq, ne Window title\r\n\r\n NOTE\r\n ----\r\n 1) Wildcard '*' for /IM switch is accepted only when a filter is applied.\r\n 2) Termination of remote processes will always be done forcefully (/F).\r\n 3) \"WINDOWTITLE\" and \"STATUS\" filters are not considered when a remote\r\n machine is specified.\r\n\r\nExamples:\r\n TASKKILL /IM notepad.exe\r\n TASKKILL /PID 1230 /PID 1241 /PID 1253 /T\r\n TASKKILL /F /IM cmd.exe /T \r\n TASKKILL /F /FI \"PID ge 1000\" /FI \"WINDOWTITLE ne untitle*\"\r\n TASKKILL /F /FI \"USERNAME eq NT AUTHORITY\\SYSTEM\" /IM notepad.exe\r\n TASKKILL /S system /U domain\\username /FI \"USERNAME ne NT*\" /IM *\r\n TASKKILL /S system /U username /P password /FI \"IMAGENAME eq note*\"\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\taskkill.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"TASKKILL /?\" for usage.\r\n" }, "tasklist.exe-2185AD666AA7188AC9DB4E33DC6A2838": { "file_name": "tasklist.exe", "file_path": "C:\\Windows\\SysWOW64\\tasklist.exe", "hash_md5": "2185AD666AA7188AC9DB4E33DC6A2838", "hash_sha1": "514103BF51B9006D80D0D75018A56E3AF6D03428", "hash_sha256": "B4A874C5CCFA9A698E4A56D7453105CC7617802C385ABE1603760A9BB33D39ED", "hash_sha384": "1BDFEE0967B6130650AFA2B676CAF03190D6C2B3A1B3A64E9751967B5768C966AFC5B02F16B4444B214A8043C9AF0AE3", "hash_sha512": "139D7B47A2EF5BB3F3628B8D1BA3C6A1FEE8E7363C66D5478DA4ED702E61BB7CAA712C5AEC3291CF5C2FD83621B18D661463D28666564C78B7310D00B1766653", "hash_ssdeep": "1536:SAkPqUMKhUBmkv1/5csEStRcc6PHjYv/3YC/Segb1x1dcOES:0Mvb1xcmtRcc6PH0vfYneI1x/5E", "hash_imp": "D16A743355B243B7509AE74891F10F6B", "hash_pesha1": "BEA842A005C5DD023BF37B29742790AAEBFD9B78", "hash_pe256": "3CC19BC417DBAE1232C32DD105F3E02FD21C27594AB7614481CC98B3DDD0C768", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Lists the current running tasks", "meta_original_filename": "tasklist.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b4a874c5ccfa9a698e4a56d7453105cc7617802c385abe1603760a9bb33d39ed/detection/", "output": "\r\nTASKLIST [/S system [/U username [/P [password]]]]\r\n [/M [module] | /SVC | /V] [/FI filter] [/FO format] [/NH]\r\n\r\nDescription:\r\n This tool displays a list of currently running processes on\r\n either a local or remote machine.\r\n\r\nParameter List:\r\n /S system Specifies the remote system to connect to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given\r\n user context. Prompts for input if omitted.\r\n\r\n /M [module] Lists all tasks currently using the given\r\n exe/dll name. If the module name is not\r\n specified all loaded modules are displayed.\r\n\r\n /SVC Displays services hosted in each process.\r\n\r\n /APPS Displays Store Apps and their associated processes.\r\n\r\n /V Displays verbose task information.\r\n\r\n /FI filter Displays a set of tasks that match a\r\n given criteria specified by the filter.\r\n\r\n /FO format Specifies the output format.\r\n Valid values: \"TABLE\", \"LIST\", \"CSV\".\r\n\r\n /NH Specifies that the \"Column Header\" should\r\n not be displayed in the output.\r\n Valid only for \"TABLE\" and \"CSV\" formats.\r\n\r\n /? Displays this help message.\r\n\r\nFilters:\r\n Filter Name Valid Operators Valid Value(s)\r\n ----------- --------------- --------------------------\r\n STATUS eq, ne RUNNING | SUSPENDED\r\n NOT RESPONDING | UNKNOWN\r\n IMAGENAME eq, ne Image name\r\n PID eq, ne, gt, lt, ge, le PID value\r\n SESSION eq, ne, gt, lt, ge, le Session number\r\n SESSIONNAME eq, ne Session name\r\n CPUTIME eq, ne, gt, lt, ge, le CPU time in the format\r\n of hh:mm:ss.\r\n hh - hours,\r\n mm - minutes, ss - seconds\r\n MEMUSAGE eq, ne, gt, lt, ge, le Memory usage in KB\r\n USERNAME eq, ne User name in [domain\\]user\r\n format\r\n SERVICES eq, ne Service name\r\n WINDOWTITLE eq, ne Window title\r\n MODULES eq, ne DLL name\r\n\r\nNOTE: \"WINDOWTITLE\" and \"STATUS\" filters are not supported when querying\r\n a remote machine.\r\n\r\nExamples:\r\n TASKLIST\r\n TASKLIST /M\r\n TASKLIST /V /FO CSV\r\n TASKLIST /SVC /FO LIST\r\n TASKLIST /APPS /FI \"STATUS eq RUNNING\"\r\n TASKLIST /M wbem*\r\n TASKLIST /S system /FO LIST\r\n TASKLIST /S system /U domain\\username /FO CSV /NH\r\n TASKLIST /S system /U username /P password /FO TABLE /NH\r\n TASKLIST /FI \"USERNAME ne NT AUTHORITY\\SYSTEM\" /FI \"STATUS eq running\"\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\tasklist.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"TASKLIST /?\" for usage.\r\n" }, "Taskmgr.exe-ACA0D5EA1DF6DF1D3187777C2699F5C3": { "file_name": "Taskmgr.exe", "file_path": "C:\\Windows\\SysWOW64\\Taskmgr.exe", "hash_md5": "ACA0D5EA1DF6DF1D3187777C2699F5C3", "hash_sha1": "3C0DBAB7BAF66B518EF1DEAA230CD7F169815CC5", "hash_sha256": "B24F923D5A76B34B519F1065C6FBB533F2E52A372A2AEC2F844BC3F1540A1DD5", "hash_sha384": "6B91BBE618D618D753E1C081C8FC612EE1F819766E0F89255B48E067825FCEC30306B91FA4BB5227540CA6B0985B9702", "hash_sha512": "6C61908176E55F37F236D65CF8EA0F9B3F9C04EB3CC7D8318E987848C569902B6A39482522169D6C12A0A19C947DCCFC75A1DC4ACBE8B31C988DFDF22930F882", "hash_ssdeep": "24576:Qfq2LeRRFCqknb3yIKbmfqEzLGsw/xUxJm9ESCUa+Be7q4Dq+l:OCI6w0/xUxsLCUaMe7q4eK", "hash_imp": "920F3AEC5A928B966C39EE8CE6687BF6", "hash_pesha1": "38D303ACDC0CD3EAA4DDFB2D670DF697B4E29829", "hash_pe256": "397297B1FFC64304C466B0E52196C0F583984907DAC0C19F488934626B3CA537", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Task Manager", "meta_original_filename": "Taskmgr.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/b24f923d5a76b34b519f1065c6fbb533f2e52a372a2aec2f844bc3f1540a1dd5/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\Taskmgr.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\2\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\oleaccrc.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\RPC Control\\DSECF9C": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\propsys.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\C:*Users*Administrator*AppData*Local*Microsoft*Windows*Caches*{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\C:*Users*Administrator*AppData*Local*Microsoft*Windows*Caches*cversions.3.ro": "Section", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_16.db": "File", "(RWD) C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\Taskmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Task Manager" }, "tcmsetup.exe-8EC5D3BE26A23B88DF4DE0CC17931777": { "file_name": "tcmsetup.exe", "file_path": "C:\\Windows\\SysWOW64\\tcmsetup.exe", "hash_md5": "8EC5D3BE26A23B88DF4DE0CC17931777", "hash_sha1": "377D922B49542D57C8CFA172562AF778FB2CF079", "hash_sha256": "92D0DF82F636DBDF23926615682CB6183DE5E7504732AA8543E4D122E316A48E", "hash_sha384": "5A29A9BA2680D98B9475BBEA296217313D63E080B785CC716B4E6DA64932356D02464DE21A11ED92965AE10B9003003E", "hash_sha512": "640DAFEF9A04CFD549B2B595633B4329FB9BAA9F96B7D5358502A619A8B8D8ECEF4AF9E3CB02B2A52FF9B869550A28D1331E4CF083355084922D059FFBD3918D", "hash_ssdeep": "192:Fnr2RWY14Mcp3yb97Zc8DHK4wD1oad6V6WvgWGQoWMN:FnakY1awZcsK4wDG8WvgWGQoWM", "hash_imp": "EEFB875014ECDD920C8DA3D31E4C2FCB", "hash_pesha1": "DA11C26EA8662956C60B0B1772EC1DA0630333CA", "hash_pe256": "4560C0E3E740827EC6E3683B79DB5A325DDA1E7BD4222FDB5417142D4706D9DD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) Telephony Administration Setup", "meta_original_filename": "TCMSETUP.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/92d0df82f636dbdf23926615682cb6183de5e7504732aa8543e4d122e316a48e/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\tcmsetup.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\tcmsetup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Telephony Client Setup Help" }, "TCPSVCS.EXE-24299886198E801C7D428FC30C95E9C5": { "file_name": "TCPSVCS.EXE", "file_path": "C:\\Windows\\SysWOW64\\TCPSVCS.EXE", "hash_md5": "24299886198E801C7D428FC30C95E9C5", "hash_sha1": "E132698D6E20B41AD8F839094CD9DDA7370F4E00", "hash_sha256": "B2268460262B8587C8ACD530A5EDD7FB5D13CF41640D8BCF02A2EA213882FAB4", "hash_sha384": "B8070597F6926BFEC5206B1E2F1EF3B7FFF865A6F3B1C230145A946492F438C170B6C1A24A335B22AD33F9EA95540E65", "hash_sha512": "114D097595E3302B00698B8429F2758BDCBFC7F5DEB540C1C3A3134A89AAF8CCFC4C6AF8D19793E4ABC8B2459BC46C219110164FE2B3EA425BD8FAB61EFBED9D", "hash_ssdeep": "192:EF0o+tFS+H3I3Ou4vt2bvCpeXL6//1PKcW5/Wh:EF0oe4+XaR412DCM6//QcW5/Wh", "hash_imp": "7EC53FBE050A90703B67A98FCB8BCFCC", "hash_pesha1": "229A8CFDED64AC7D199E3C0C7283AD8C1BDD5409", "hash_pe256": "46D3D27ECEFF7F3027CED91C11663EF609AF3B816B926BFC2CDB9B1D6375FA31", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Services Application", "meta_original_filename": "TCPSVCS.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/b2268460262b8587c8acd530a5edd7fb5d13cf41640d8bcf02a2ea213882fab4/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\TCPSVCS.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ThumbnailExtractionHost.exe-3E2F28EE64E682BE567004F4265BD988": { "file_name": "ThumbnailExtractionHost.exe", "file_path": "C:\\Windows\\SysWOW64\\ThumbnailExtractionHost.exe", "hash_md5": "3E2F28EE64E682BE567004F4265BD988", "hash_sha1": "C9E03AFC026E7DBA1B9D2EFD0E0A118EE65FF9AD", "hash_sha256": "37ED1945A2BC2F4C53B0231BE12EFD84AD6D4568DAB2D0B4197BBBF847F0EC26", "hash_sha384": "5770F46F163F1513DCDF0ED2E9FFF8846D227B7E3008E111495E39B048B1EE21DCE781BECE387FD3E1A18BC07B925829", "hash_sha512": "B5CBE70FD37874C055757E16019A95ECBF3133EE4ADEC742877CDC1FF25FD4EEB4111E0BF8D10CBE878C703B4AC97B36BBACD614FA688A122B383C0E5A045E4E", "hash_ssdeep": "384:ID3OSLN9V42HU3yfc32kfj2tezP0+vkLe3oOrsmoqgf0yzSWccWc:ILOiQifc32kitezP0+NYgwV0yzo2", "hash_imp": "9424281BFA5BA01B75383423374BC258", "hash_pesha1": "E257017EFF3BC662B2DF9F05164CD7960BBEA981", "hash_pe256": "7ABAFB181BA4A1C26FC8FE1D3605CEF4B3B2A353AF34F8D6BA77933433B39DCD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Thumbnail Handler Extraction Host", "meta_original_filename": "ThumbnailExtractionHost.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/37ed1945a2bc2f4c53b0231be12efd84ad6d4568dab2d0b4197bbbf847f0ec26/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECFC4": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\ThumbnailExtractionHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "timeout.exe-98E377F190CC95851C1417B72921E83C": { "file_name": "timeout.exe", "file_path": "C:\\Windows\\SysWOW64\\timeout.exe", "hash_md5": "98E377F190CC95851C1417B72921E83C", "hash_sha1": "0DE83C74EF28ABAFC3380B34DD12C348E5C0A9B8", "hash_sha256": "496B42AAA7AAF0665E5EDD52D4348EC4105FB758DB674B110FA252DF247C91DC", "hash_sha384": "37463F0B1052A17318A0352226B6833DCAC5BD988C8982F303CDAF00A8D7DAC71EADF2A3939CB722C61E2EAD99C24E96", "hash_sha512": "F81FDA6E7F180D3500125E3B79A3636C71628399DD088E0D861FEEB0BD6F197F240D5AADDCB003A7762FEB0D3255F02433737EF57DFA2730DDE75AD8CC04791C", "hash_ssdeep": "384:SHPNPWHYMwZFzEbW1hn3PpREaH4cYCjdn/e35ikyXImnFHsTBx4viGhLI1whUWnN:SHP1zEKhhzjNGpikHmWBxYewhiC1", "hash_imp": "80CC4313933D9AFCC64EFD0255D4BD3C", "hash_pesha1": "E8EE7FB8537F99EE3EFF4540EEB4FAF35330224F", "hash_pe256": "0E3C4F9FC224B14E25484C4FCE39A887A2EE85456F4F4658C75B9574648C5744", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "timeout - pauses command processing", "meta_original_filename": "timeout.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/496b42aaa7aaf0665e5edd52d4348ec4105fb758db674b110fa252df247c91dc/detection/", "output": "\r\nTIMEOUT [/T] timeout [/NOBREAK] \r\n\r\nDescription:\r\n This utility accepts a timeout parameter to wait for the specified\r\n time period (in seconds) or until any key is pressed. It also \r\n accepts a parameter to ignore the key press. \r\n\r\nParameter List:\r\n /T timeout Specifies the number of seconds to wait.\r\n Valid range is -1 to 99999 seconds.\r\n\r\n /NOBREAK Ignore key presses and wait specified time.\r\n\r\n /? Displays this help message.\r\n\r\nNOTE: A timeout value of -1 means to wait indefinitely for a key press.\r\n\r\nExamples:\r\n TIMEOUT /?\r\n TIMEOUT /T 10\r\n TIMEOUT /T 300 /NOBREAK\r\n TIMEOUT /T -1\r\n", "error": "ERROR: Invalid value for timeout (/T) specified. Valid range is -1 to 99999.\r\n" }, "TokenBrokerCookies.exe-59FF42C66A71B04570887A727B4986DB": { "file_name": "TokenBrokerCookies.exe", "file_path": "C:\\Windows\\SysWOW64\\TokenBrokerCookies.exe", "hash_md5": "59FF42C66A71B04570887A727B4986DB", "hash_sha1": "7A287E8B0DCCE249A228F724BA70D415EA375438", "hash_sha256": "55006AD12E81756CE62630173FFC24CE8865B3AAF2B8497AF1FF6AB2E13FBD67", "hash_sha384": "7C49152FC90609BB88CF3C98C42CC572B9C34D08FBBA376A15410C2E828579B869EB1ED8D86A618DA5126BBCB7E9F7F6", "hash_sha512": "0E22BF452E96CC8006678F5919A7995BB198B2062FFF5F43685BF41BF59AAC3F8A12240859721BF50918C215470630ED07C5E7C45D38DABE09FAB4CA1B605075", "hash_ssdeep": "384:xWAuN/uTUaQcbo69bloEF5hIHQrvGlX6sxEmCVkxmwms8sDdxeGWuKWq:xWAI2nJoERoEF5tOMEEPixmwm5ExR", "hash_imp": "745F538A8F041CFDC4FB7F340DBD70A9", "hash_pesha1": "14118FF122B9295177938AE1606A3A430115904A", "hash_pe256": "CC1D68E1C55E37B17EF7319224D03E9427929CE1E43C8BAC102A9F5F79B8D6AA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Token Broker Cookie Helper", "meta_original_filename": "TokenBrokerCookies.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/55006ad12e81756ce62630173ffc24ce8865b3aaf2b8497af1ff6ab2e13fbd67/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\TokenBrokerCookies.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "TpmInit.exe-23E73EAD4C5304744E76E8ECE21273BC": { "file_name": "TpmInit.exe", "file_path": "C:\\Windows\\SysWOW64\\TpmInit.exe", "hash_md5": "23E73EAD4C5304744E76E8ECE21273BC", "hash_sha1": "6C1B56CB711D28DFC04929041E51D5F1BA6792E7", "hash_sha256": "2A7081195ACF53B272040BD4F232691B626B522123D3FE402FCA91B3FD64F158", "hash_sha384": "9A585D718B2150B9CC2EA5E613B397A8729567FAF8341AEEF757CCD0E2B55AD2F2483124586789B2E469EF4CC220C922", "hash_sha512": "7410638DB8B2D46B4E0520B53F3BED53F10B5A7EF1E246356D5D9B5570B020F434DF9463FB3D10DE08FE8F8845A8E280DE8718BA6ECA72F8C4E6569F19DFB761", "hash_ssdeep": "1536:OUeKzb+/P25nDmXSHuGiceY0lA3CJHkxUM:Le2b+/P25R+PYfSFkx1", "hash_imp": "80D512028EB708EE52E1A6F4BAB6259F", "hash_pesha1": "5E0A6F2AE28E92CC78CE737ED527B3AAB50DF7F4", "hash_pe256": "C1F8446BF067457EF6328118675A9ADC92E8101C9E96460471F02957AC49392C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TPM Initialization Wizard", "meta_original_filename": "TpmInit.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/2a7081195acf53b272040bd4f232691b626b522123d3fe402fca91b3fd64f158/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\TpmInit.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\oleaccrc.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECFAC": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\System32\\netmsg.dll": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\netmsg.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\TpmInit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Manage the TPM security hardware" }, "tracerpt.exe-B09F46CD5AEB2B771997B37C70E40F66": { "file_name": "tracerpt.exe", "file_path": "C:\\Windows\\SysWOW64\\tracerpt.exe", "hash_md5": "B09F46CD5AEB2B771997B37C70E40F66", "hash_sha1": "22EC2C5709301BC171D7A117956B7D2CAA2EF012", "hash_sha256": "18525850BA7B428AF5760E65E2CC384E7638CCE56365FD9ADF8075AFAF5E4379", "hash_sha384": "34E3D11E69CCDF6A3010EACE419FD85CEA662AA48FEB8914FB8C4B10792324A55986DDA3740B9012E910013C7AE8CAF5", "hash_sha512": "6BED1471CB289F8C287A2FDAF07B50A49F40CB2F7AFBA658F3869AEF7B114B5865D7B297A03890368042B53E11BD6AC65CC371F054C851478B7A95F32D4AEC05", "hash_ssdeep": "6144:3KyhVjVIN0aXJ17OG6cKVDOonKWUyUnY6i/WYI/4BU+:HrIN0GGDOSUbYcYI/4BU+", "hash_imp": "D60A359019760AA6264EF3A39C017D2E", "hash_pesha1": "E500F5ABF1231C6928C62CC7CB94E405250F58A0", "hash_pe256": "F02C47B14903FC5169A28035A84504E363B87AA484D48CD6118C876F300D7AC8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Trace Report Tool", "meta_original_filename": "TraceRpt.Exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "\r\nMicrosoft r TraceRpt.Exe (10.0.17763.1490)\r\n\r\nUsage:\r\n C:\\Windows\\SysWOW64\\tracerpt.exe <[-l] <value [value [...]]>|-rt <session_name [session_name [...]]>> [options]\r\n\r\nOptions:\r\n -? Displays context sensitive help.\r\n -config <filename> Settings file containing command options.\r\n -y Answer yes to all questions without prompting.\r\n -f <XML|HTML> Report format.\r\n -of <CSV|EVTX|XML> Dump format, the default is XML.\r\n -en <ANSI|Unicode> Output file encoding. Only allowed with CSV\n output format.\r\n -df <filename> Microsoft specific counting/reporting schema\n file.\r\n -import <filename [filename [...]]> Event Schema import file.\r\n -int <filename> Dump interpreted event structure into\n specified file.\r\n -rts Report raw timestamp in event trace header. \n Can only be used with -o, not -report or\n -summary.\r\n -tmf <filename> Trace Message Format definition file\r\n -tp <value> TMF file search path. Multiple paths can be\n used, separated with ';'.\r\n -i <value> Specifies the provider image path. The\n matching PDB will be located in the Symbol\n Server. Multiple paths can be used, separated\n with ';'.\r\n -pdb <value> Specifies the symbol server path. Multiple\n paths can be used, separated with ';'.\r\n -gmt Convert WPP payload timestamps to GMT time\r\n -rl <value> System Report Level from 1 to 5, the default\n value is 1.\r\n -summary [filename] Summary report text file. Default is\n summary.txt.\r\n -o [filename] Text output file. Default is dumpfile.xml.\r\n -report [filename] Text output report file. Default is\n workload.xml.\r\n -lr Less restrictive; use best effort for events\n not matching event schema.\r\n -export [filename] Event Schema export file. Default is\n schema.man.\r\n [-l] <value [value [...]]> Event Trace log file to process.\r\n -rt <session_name [session_name [...]]> Real-time Event Trace Session data\n source.\r\n\r\nExamples:\r\n tracerpt logfile1.etl logfile2.etl -o logdump.xml -of XML\n tracerpt logfile.etl -o logdmp.xml -of XML -lr -summary logdmp.txt -report logrpt.xml\n tracerpt logfile1.etl logfile2.etl -o -report\n tracerpt logfile.etl counterfile.blg -report logrpt.xml -df schema.xml\n tracerpt -rt \"NT Kernel Logger\" -o logfile.csv -of CSV\n\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\tracerpt.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "TRACERT.EXE-CFB60B65D971A9FFA8625B47E3ACD519": { "file_name": "TRACERT.EXE", "file_path": "C:\\Windows\\SysWOW64\\TRACERT.EXE", "hash_md5": "CFB60B65D971A9FFA8625B47E3ACD519", "hash_sha1": "C28199AE1F2100B973CCDAAAEE77D5CAD6A6EDAA", "hash_sha256": "9D950A12F26B79F07C7C44EDC1E0C6ED318F1CEEC677574AE866D83149A3E600", "hash_sha384": "62249F09C3090E207ED0F8C22F85AD896ADA8BB696241D83B869C8227B31D2BE1BA33C5F7A498EDA0C4797FAC3A28FDE", "hash_sha512": "254C7021CECE59AE7097CEE28D834DDCA7911A02E060AA96D80C401086565064D8C274E96A6E0AADE7FE1F6A86DF37E4672374691FCF6EA1ADA49B48ABD94DB9", "hash_ssdeep": "192:Ih1LWw7Ml1o1H461QZZW01QVYyWlzP2J/JCWrmofrL1bwG+WlaWkJ:IhNWyuq1H9QZZB1ryWKrmQL1biWlaW", "hash_imp": "531AE91619D780EE6780A8E52862643F", "hash_pesha1": "971730797ABB0D3302682F2D07B248C2E095857C", "hash_pe256": "636B9B385F79C4B36ABD40C4E52F90704C65315BC0FDA2CE1F7C66A6D88A3EB1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TCP/IP Traceroute Command", "meta_original_filename": "tracert.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/63", "filescan_vtlink": "https://www.virustotal.com/gui/file/9d950a12f26b79f07c7c44edc1e0c6ed318f1ceec677574ae866d83149a3e600/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\TRACERT.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "output": "--help is not a valid command option.\r\n\r\nUsage: tracert [-d] [-h maximum_hops] [-j host-list] [-w timeout] \r\n [-R] [-S srcaddr] [-4] [-6] target_name\r\n\r\nOptions:\r\n -d Do not resolve addresses to hostnames.\r\n -h maximum_hops Maximum number of hops to search for target.\r\n -j host-list Loose source route along host-list (IPv4-only).\r\n -w timeout Wait timeout milliseconds for each reply.\r\n -R Trace round-trip path (IPv6-only).\r\n -S srcaddr Source address to use (IPv6-only).\r\n -4 Force using IPv4.\r\n -6 Force using IPv6.\r\n" }, "tscon.exe-7E2A7CF189E59D638F22876593F5D194": { "file_name": "tscon.exe", "file_path": "C:\\Windows\\SysWOW64\\tscon.exe", "hash_md5": "7E2A7CF189E59D638F22876593F5D194", "hash_sha1": "0B407F6EE053903F0E76FB4E4A2404F4DA60C4A3", "hash_sha256": "B0837A65F983BF6C8D06E695AD60977F141066F1C8CB84753E75F96B9FAEE66C", "hash_sha384": "891E1A5FE872EAE25AB90DB88231CD5253315D3B4EED7D5248D867B476356EAD0B455C01BD208F7D0BA589B286BA2BEB", "hash_sha512": "C4AB2BEAFC90BF97A83F662E3CE1D09E41C8E59FC469E7F43019196599BA0B56D56B04E72D5C198AC007ADD65C7518C40F0854536BB5C39E73533A08E3761CEF", "hash_ssdeep": "384:0oai19OcbTqUcw/kWm9lSteKotZV5uY4x27v7WjigW7dT:0K9OczX/upVG2btD", "hash_imp": "A56882D0079E92DB91AA4874A2D331B8", "hash_pesha1": "206F9C4A690F43964B6F44A05D26341F53FCB60A", "hash_pe256": "720688F69AA8EB3B1BEC81775CE2ECC1F39C28B5B357E3CAE622316A0087597B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Session Connection Utility", "meta_original_filename": "tscon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/b0837a65f983bf6c8d06e695ad60977f141066f1c8cb84753e75f96b9faee66c/detection/", "output": "Attaches a user session to a remote desktop session.\r\n\r\nTSCON {sessionid | sessionname} [/DEST:sessionname]\r\n [/PASSWORD:pw | /PASSWORD:*] [/V]\r\n\r\n sessionid The ID of the session.\r\n sessionname The name of the session.\r\n /DEST:sessionname Connect the session to destination sessionname.\r\n /PASSWORD:pw Password of user owning identified session.\r\n /V Displays information about the actions performed.\r\n\r\n", "error": "Invalid parameter(s)\r\nAttaches a user session to a remote desktop session.\r\n\r\nTSCON {sessionid | sessionname} [/DEST:sessionname]\r\n [/PASSWORD:pw | /PASSWORD:*] [/V]\r\n\r\n sessionid The ID of the session.\r\n sessionname The name of the session.\r\n /DEST:sessionname Connect the session to destination sessionname.\r\n /PASSWORD:pw Password of user owning identified session.\r\n /V Displays information about the actions performed.\r\n\r\n" }, "tsdiscon.exe-1ABB99A7422F830E1B875281155A0E2A": { "file_name": "tsdiscon.exe", "file_path": "C:\\Windows\\SysWOW64\\tsdiscon.exe", "hash_md5": "1ABB99A7422F830E1B875281155A0E2A", "hash_sha1": "0965E581566F0BC654C5E694314DB347A4D66195", "hash_sha256": "C6F572841F362B549C9FACC377E280D09623873502EC1D02961BD4EDDC7D1E27", "hash_sha384": "B866BD70AE4A72BFBB6C99BACFFA7D1D2B0AA7C5E596E0FC39670015D2DF00EFF2EACECEF1F4A8D1310EDE8A63B15846", "hash_sha512": "549F27AF7A7A5FCB49161BF5831D619B9078A921B6CAD217098FD108116B90F082F3265C2057394355477EF7133524D553F9CBF1B41ECAC9230001F10C3693AB", "hash_ssdeep": "384:oOy3MZoSPbv+kcw/kWmsbSjUIZ10E47nx27V3WMqWWED:oOyioSPrX/uNw2p8M", "hash_imp": "76FB20C51F532D7D68559F39C04F6956", "hash_pesha1": "6122546118DF564EA444B9A5C4BA0E17A3297C0F", "hash_pe256": "4786328055DF425E237ED131E1D40FADD4E224B9DB24B4BA04CAF458196E8877", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Session Disconnection Utility", "meta_original_filename": "tsdiscon.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/c6f572841f362b549c9facc377e280d09623873502ec1d02961bd4eddc7d1e27/detection/", "output": "Disconnects a Remote Desktop Services session.\r\n\r\nTSDISCON [sessionid | sessionname] [/SERVER:servername] [/V] [/VM]\r\n\r\n sessionid The ID of the session.\r\n sessionname The name of the session.\r\n /SERVER:servername Specifies the Remote Desktop Session Host server (default is current).\r\n /V Displays information about the actions performed.\r\n /VM Disconnects session on server or within virtual machine. The unique ID of the session needs to be specified.\r\n\r\n", "error": "Invalid parameter(s)\r\nDisconnects a Remote Desktop Services session.\r\n\r\nTSDISCON [sessionid | sessionname] [/SERVER:servername] [/V] [/VM]\r\n\r\n sessionid The ID of the session.\r\n sessionname The name of the session.\r\n /SERVER:servername Specifies the Remote Desktop Session Host server (default is current).\r\n /V Displays information about the actions performed.\r\n /VM Disconnects session on server or within virtual machine. The unique ID of the session needs to be specified.\r\n\r\n" }, "tsecimp.exe-EC5A4DAF64E14473B03AA838E2CD5918": { "file_name": "tsecimp.exe", "file_path": "C:\\Windows\\SysWOW64\\tsecimp.exe", "hash_md5": "EC5A4DAF64E14473B03AA838E2CD5918", "hash_sha1": "E31D07B0CCD6B0A52D8B1DB44B47DF8674C226A7", "hash_sha256": "BC0986BF43BD5FEB6FFD5555648EF0ABA5CBE9648A57DB931644685717DF78CE", "hash_sha384": "C59D6B756E156DC8A0ECDD07582EF88041EAB4B0FB6520786DCFD68D1F0A3886D1DECED5051075992F8A11B870731C94", "hash_sha512": "86DDB852C7D1D186D328BB5C117E825AFA8C0F16E98C1FA696D6ED2F7D0BD04157E20481B7B6C7E56BEA9171CFBFD79D1724A0475A878FDE57CD7CFC88A2DD8A", "hash_ssdeep": "384:MYfkR8MvR3r5MfoesHnxrsFqj5W0bD/U/m9xY08RGdMFkup27FcGmWqr4WcKp8+3:MaGhr2PunxAMj5lmaDM27/k+KC", "hash_imp": "6BBF4D7D6545FC13C0082966BFFCBF35", "hash_pesha1": "DC7BFC32F985A51D07223DAAA918DD547FA87C69", "hash_pe256": "017AC3AD13D52416A333F063870D20D4342B5F6D0351DC3F05AB11AE7CE17490", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows(TM) TAPI Security File Importer", "meta_original_filename": "TSECIMP.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/bc0986bf43bd5feb6ffd5555648ef0aba5cbe9648a57db931644685717df78ce/detection/", "output": "Microsoft Windows(TM) TAPI Security File Importer\r\n\r\nThe syntax of this command is:\r\n\r\ntsecimp {-?|-h |-H} | { [ {-v|-V} | {-u|-U} ] -f filename} | {-d|-D}\r\n\r\n-?|-h|-H\tTo print this help page\r\n-v|-V\t\tValidate the input XML file only\r\n-u|-U\t\tValidate user accounts (slower)\r\n-f filename\tThe XML file to be processed\r\n-d|-D\t\tDisplay current configuration\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\tsecimp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "tskill.exe-82329DDD95460B91CFF76D777D1E58AE": { "file_name": "tskill.exe", "file_path": "C:\\Windows\\SysWOW64\\tskill.exe", "hash_md5": "82329DDD95460B91CFF76D777D1E58AE", "hash_sha1": "9AA945C68B86243F7B075DA3393016F721272D64", "hash_sha256": "7468A5DD894AD3B4EAB0CFB10ACF6347336356038EC9446ED3C15862088E4849", "hash_sha384": "5225BB3E6166F781206F42E3144733DB658CD6302052BF819807E00876A8CF765C35D9D855A08C8789F3E9549E0178E9", "hash_sha512": "F48DDBBA460BCB96987811EF6EAD67E4918B3254B9B2010CDA216A0A7F7D40B44F5356F7922E865BEEB4F88373BE8E29E1E4D94BB2DF1C7183839A47CAFA27F0", "hash_ssdeep": "384:gR2sOSALmDLzWsch/kWv3t9SDqBVEE9e4A/If27dSW4wQW:ToALmDP6/HwgB2Bx", "hash_imp": "82DB08E0613BAB949E41C09B91D85B62", "hash_pesha1": "8770B80B6947C091E883248C5E840FF8C3153682", "hash_pe256": "97193706ED6A0A496AD1184A45807D0463BA81713F8277093008262873E74059", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Remote Desktop Services End Process Utility", "meta_original_filename": "tskill.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/7468a5dd894ad3b4eab0cfb10acf6347336356038ec9446ed3c15862088e4849/detection/", "error": "Invalid parameter(s)\r\nEnds a process.\r\n\r\nTSKILL processid | processname [/SERVER:servername] [/ID:sessionid | /A] [/V]\r\n\r\n processid Process ID for the process to be terminated.\r\n processname Process name to be terminated.\r\n /SERVER:servername Server containing processID (default is current).\r\n /ID or /A must be specified when using processname\r\n and /SERVER\r\n /ID:sessionid End process running under the specified session.\r\n /A End process running under ALL sessions.\r\n /V Display information about actions being performed.\r\n\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\tskill.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "TSTheme.exe-8FDA1BE0C3C4DEE89774F0D09E67DFA9": { "file_name": "TSTheme.exe", "file_path": "C:\\Windows\\SysWOW64\\TSTheme.exe", "hash_md5": "8FDA1BE0C3C4DEE89774F0D09E67DFA9", "hash_sha1": "CADA3CFAF63258A28A5B17FB603A89F37F097E82", "hash_sha256": "E518E9415190BC504C9E4FE8B477006D9F8CA6901B9D4888A5B09C848C5C1246", "hash_sha384": "5C3AB79A4A5FED55E844638A2E889C566DF5F2E001728F521CC63ACCE655DC128BC9CAE28D3ED75549AA76A02E0E99BA", "hash_sha512": "BB329283227428591F6572CB176126E1483904E1EE26EA848C3B27AFA03EF85E4C41309C0D188465FBD00133365E9568F2FC17F4AA9633174ABAE15D7EF761B9", "hash_ssdeep": "768:Qg4kVzTa9BiS9MokYewhPEWFye8ahBLnIBkP5OWjark:QFkVzTa9BiS+okY1s2j55OWjar", "hash_imp": "D828BC7E8EC746DCF6700668A6129CF1", "hash_pesha1": "88101BC839483B93681924BEED04E43983750095", "hash_pe256": "98485539C5529F60F0F9BED05E39F795C47A9044B689837FCEC4648BB2BFE20B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "TSTheme Server Module", "meta_original_filename": "TSThemeS.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.771 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.771", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/e518e9415190bc504c9e4fe8b477006d9f8ca6901b9d4888a5b09c848c5c1246/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\TSTheme.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1318": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\TSTheme.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ttdinject.exe-B9269B78B1AEF3900F2864E98B766DE0": { "file_name": "ttdinject.exe", "file_path": "C:\\Windows\\SysWOW64\\ttdinject.exe", "hash_md5": "B9269B78B1AEF3900F2864E98B766DE0", "hash_sha1": "A276D84424F0AB97E888B024DA437F3F6334491B", "hash_sha256": "6D42E1981E0B9D704351705B3F14E7E982766775CEDA9D6A8EF15E9D7EC32F99", "hash_sha384": "DB25B8D526E75BC15695BE0EDA9304455AB240324C1EECB6854EBA154DE90074B03328D3016F75D204A09BDCB46B7BF8", "hash_sha512": "136304E147300B06B6556A3A694DBC1382A03E71DE484E7BF5F8D648AB5BF27A1E45D186BFF061BB53D053651950D9E3E33BC30520488919E3614E2D501E2068", "hash_ssdeep": "3072:lrM6awV1wYDyyn5j7z/sczZTENm2eK7mnoUSgpAY8ODcDcm7cIsW7WB8ANRaBK9d:lVLjLscz1ENm2eK7mnoUSgpAY8ODcDc9", "hash_imp": "4AC73D1C324B644A59D1D09C9A6241EA", "hash_pesha1": "386258219D4C67C06CC29B729D1CFB27C5E3AE27", "hash_pe256": "34BBDA0EC20FB0A2175D8114CE9E2B73E2CA96631CAE3881837347B51C44C4D8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Time Traver Debugger Application Launcher", "meta_original_filename": "TTDInject.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/6d42e1981e0b9d704351705b3f14e7e982766775ceda9d6a8ef15e9d7ec32f99/detection/", "output": "Microsoft (R) TTDInject Launcher 1.01.03\r\nRelease: 10.0.17763.1\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n\r\n", "error": "\b\b\b!!! Unexpected string 'help' after 'C:\\Windows\\SysWOW64\\ttdinject.exe'\r\n\r\n" }, "tttracer.exe-D6972207EACDB8AC6526A0624BD4FCF5": { "file_name": "tttracer.exe", "file_path": "C:\\Windows\\SysWOW64\\tttracer.exe", "hash_md5": "D6972207EACDB8AC6526A0624BD4FCF5", "hash_sha1": "EE8324C6932F1A52A74CA6B62DB0D19BD5E78211", "hash_sha256": "F501B18D8270CE7802E724C84D1EBA5C5D77ADB9113739605FB45E302EDF9C4C", "hash_sha384": "5C2AA92C40DAB06E2D0F5F25D08250BFEF78CF4ECA71774DA85EA202D97F74278E1CDC6B14615245C2E015B63ABB120C", "hash_sha512": "B9289CED19CEB996E8B6CD987FC12F725F2A9E74EF68207368FCD6030AAE793B2FAB17BD0B72E04875C866DD2A3C7CDC646815E12B70FD808524370D7A40A872", "hash_ssdeep": "3072:NqmrA6A5XVO/DNT/J7rnOoXAlXZ3ptkeuOwinfX9EJTJx4VniXOFZ9nkTvcx8MxB:AmrR0XVOhTBNwv3XkOYJHlOFZpevcx88", "hash_imp": "1399989C3CE962B011C51F54F5BD96A1", "hash_pesha1": "280067D88E2855B202458003BF509F861172D5AF", "hash_pe256": "CB0C6ADBC8EB0F5F6F715C5346FFDCDD0EA26B1B950A5DB3F631510ADAFB2B37", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Time Travel Tracing Tracer Tool", "meta_original_filename": "TTTracer.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/f501b18d8270ce7802e724c84d1eba5c5d77adb9113739605fb45e302edf9c4c/detection/", "output": "We have created EULA.TXT in the current folder. \r\nPlease review this file before agreeing.\r\nHave you read and do you accept the EULA? Y/N\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\tttracer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "typeperf.exe-99B1218099684D33D15582BBED966A94": { "file_name": "typeperf.exe", "file_path": "C:\\Windows\\SysWOW64\\typeperf.exe", "hash_md5": "99B1218099684D33D15582BBED966A94", "hash_sha1": "679453E755EAC97F39CA16CFE6F81BFCF8B27E46", "hash_sha256": "2747462E89FCDBF41AB73F46A8EFB67057792FD659D5AF9F54F1F8CF19F555D9", "hash_sha384": "1DA500B4E5180F902C1C14B8C94C386874E2A0CE1A6E90A1E45F69FE609158A33F4C972EA3697355A3D8F9E408D8B4B2", "hash_sha512": "1F5E8ED58D817E28436B6B553E909B1E0DBF574FC8F559F73C3C5964CE93395C41D6F1B38A420D2300CD610D2F424613CC26D1B3BE434DDA37940F1B06CA03AE", "hash_ssdeep": "768:Nrezwcfcj+r0V1xh+h1JnWd7ozrBSuZC1GNwtSqnw23j5roa5NjAJWHv0q:NoEjUQZSTWl5uEec3lMa5NkJ48", "hash_imp": "5DCDDB44A0DA4CD1D962C12AD1A2DA22", "hash_pesha1": "B43C1BBC974BCA075753FB76CF2CDDB99764CD4F", "hash_pe256": "F4F417A91B6F8CAF5B470027C01A69950E4D2BFC089A272F9C1A4A17D6D2E782", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Command line performance monitor", "meta_original_filename": "TypePerf.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/2747462e89fcdbf41ab73f46a8efb67057792fd659d5af9f54f1f8cf19f555d9/detection/", "output": "\r\nMicrosoft r TypePerf.exe (10.0.17763.1)\r\n\r\nTypeperf writes performance data to the command window or to a log file. To\r\nstop Typeperf, press CTRL+C.\r\n\r\nUsage:\r\nC:\\Windows\\SysWOW64\\typeperf.exe { <counter [counter ...]> \r\n | -cf <filename> \r\n | -q [object] \r\n | -qx [object] \r\n } [options]\r\n\r\nParameters:\r\n <counter [counter ...]> Performance counters to monitor.\r\n\nOptions:\r\n -? Displays context sensitive help.\r\n -f <CSV|TSV|BIN|SQL> Output file format. Default is CSV.\r\n -cf <filename> File containing performance counters to\r\n monitor, one per line.\r\n -si <[[hh:]mm:]ss> Time between samples. Default is 1 second.\r\n -o <filename> Path of output file or SQL database. Default\r\n is STDOUT.\r\n -q [object] List installed counters (no instances). To\r\n list counters for one object, include the\r\n object name, such as Processor.\r\n -qx [object] List installed counters with instances. To\r\n list counters for one object, include the\r\n object name, such as Processor.\r\n -sc <samples> Number of samples to collect. Default is to\r\n sample until CTRL+C.\r\n -config <filename> Settings file containing command options.\r\n -s <computer_name> Server to monitor if no server is specified\r\n in the counter path.\r\n -y Answer yes to all questions without prompting.\r\n\r\nNote:\r\n Counter is the full name of a performance counter in\r\n \"\\\\<Computer>\\<Object>(<Instance>)\\<Counter>\" format,\r\n such as \"\\\\Server1\\Processor(0)\\% User Time\".\r\n\r\nExamples:\r\n typeperf \"\\Processor(_Total)\\% Processor Time\"\r\n typeperf -cf counters.txt -si 5 -sc 50 -f TSV -o domain2.tsv\r\n typeperf -qx PhysicalDisk -o counters.txt\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\typeperf.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "tzutil.exe-DFED5044997A60C7C8909E3FC755240F": { "file_name": "tzutil.exe", "file_path": "C:\\Windows\\SysWOW64\\tzutil.exe", "hash_md5": "DFED5044997A60C7C8909E3FC755240F", "hash_sha1": "70FA72BBCE595D53D361BF0EA63C8B9EE332E4A9", "hash_sha256": "D0F640BA7DB3906AE5352EEE6989BDE941B51D20FC4A61BBEB83281112B1D28A", "hash_sha384": "45EC8D370E99C89CBC44F2C8BEF89E0362257A4BC4658E8DF1D31BDAD39C432E0FC23AAC88E5F17E3900C3B2C7513DCF", "hash_sha512": "00AD117B4C838271D0B6CC85AFFA5A233E09DB7B9D581373E2C026FDDC8B034F92B8CDCE4854AEC7309CBD03AF5D7412540DBD350F56BFB29FE042160F4F03D5", "hash_ssdeep": "768:sD21FKHTiPgnw0EJJvYxcc4DRf3IVBVx8I:si14HOonwlKec4Q7Vx8I", "hash_imp": "C705BC50B8CCB931FC1CB5042F3DF883", "hash_pesha1": "A003A3DFA64C7A590196C20B8ED602FD275D293C", "hash_pe256": "A6B9E4E009612A4F74C3BA91948ACC27AB249CFF2709222CB05BD823D2D4F74F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Time Zone Utility", "meta_original_filename": "tzutil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/65", "filescan_vtlink": "https://www.virustotal.com/gui/file/d0f640ba7db3906ae5352eee6989bde941b51d20fc4a61bbeb83281112b1d28a/detection/", "output": "Windows Time Zone Utility\r\n\r\nUsage:\r\nTZUTIL </? | /g | /s TimeZoneID[_dstoff] | /l>\r\n\r\nParameters:\r\n /? Displays usage information.\r\n\r\n /g Displays the current time zone ID.\r\n\r\n /s TimeZoneID[_dstoff]\r\n Sets the current time zone using the specified time zone ID.\r\n The _dstoff suffix disables Daylight Saving Time adjustments\r\n for the time zone (where applicable).\r\n\r\n /l Lists all valid time zone IDs and display names. The output will\r\n be: \r\n <display name>\r\n <time zone ID>\r\n\r\nExamples:\r\n TZUTIL /g\r\n TZUTIL /s \"Pacific Standard Time\"\r\n TZUTIL /s \"Pacific Standard Time_dstoff\"\r\n\r\nRemarks:\r\n An exit code of 0 indicates the command completed successfully.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\tzutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "unlodctr.exe-F27AEE2E93F96E6DF370C0D83CF31D97": { "file_name": "unlodctr.exe", "file_path": "C:\\Windows\\SysWOW64\\unlodctr.exe", "hash_md5": "F27AEE2E93F96E6DF370C0D83CF31D97", "hash_sha1": "0973E0BCB0CE3D7390953A21C5530AFD400C18AD", "hash_sha256": "47CF991CA0F91ADCD98AF1BADE9E2BCE82600D842237404BD6A5313A539B2E13", "hash_sha384": "D544A44EE41BBD2FEE5A75190AED821284F5DFBDE383E4AA61A02BE346EA3AA07DD5985582BA3F89276AF7A9B2FFDAFE", "hash_sha512": "8BCBD26F616D54441650DF2A83DBD20714F6674B83BB04B891C45C6F18600ABCB07371A852EAE8779FFB0AD22D376158337658F7E0F0033FD6F3507BA8C04111", "hash_ssdeep": "768:uZlM8QUUYOByqUZvtUPWVj9RjGd+QfHP:8lM81UrovtUPa9VG0QfHP", "hash_imp": "54DCED0AF2D07BD064A46424718177C1", "hash_pesha1": "B7836D58305BF46E088BC7B348ABE48EA69FF12C", "hash_pe256": "CC31630D72678D59FEF60C123846AFC9BDA754688A33E0F828777F69BCAF0579", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Unload PerfMon Counters", "meta_original_filename": "UNLODCTR.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/47cf991ca0f91adcd98af1bade9e2bce82600d842237404bd6a5313a539b2e13/detection/", "output": "\r\n\r\nUNLODCTR\r\n Removes counter names and explain text for the specified extensible counter.\r\n\r\nUsage:\r\n\r\n UNLODCTR <driver>\r\n driver is the name of the device driver which is to have its\r\n counter name definitions and explain text removed from the system's\r\n registry.\r\n\r\n UNLODCTR /m:<manifest>\r\n manifest is the name of the manifest file that contains performance\r\n counter definitions. These counters will be removed from local system.\r\n\r\n UNLODCTR /g:{ProviderGuid}\r\n ProviderGuid identifies the performance counter provider being unloaded.\r\n\r\n UNLODCTR /p:<ProviderName>\r\n ProviderName identifies the performance counter provider being unloaded.\r\n\r\nNote: any arguments with spaces in the names must be enclosed within\r\nDouble Quotation marks.\r\n" }, "unregmp2.exe-33A85B3DCFFEADA67C98EAC342B93DCB": { "file_name": "unregmp2.exe", "file_path": "C:\\Windows\\SysWOW64\\unregmp2.exe", "hash_md5": "33A85B3DCFFEADA67C98EAC342B93DCB", "hash_sha1": "33856AD378DB2ECEAEF0C7F4817995A277F25592", "hash_sha256": "1DF2F5FC3369F5901068AD9463D7A165FD8E7EE7A12CA6C1A88992BB1484632E", "hash_sha384": "E4DF469FCA2DBAAE1A69BC163519C8DD313E4B0AD2D8060FA98F30966B24432EC08D469F80CF896EF16E5274CCD2DA9E", "hash_sha512": "75F7633CA44E84D58203EF62373BB5911E95738B4D659269BFA3AD222F518AD98802225AB7461048CA9883B39DACCAF0C5C9749FE8AD9B6E434D52B93C3FED73", "hash_ssdeep": "3072:TI/3G2NOfAg0IezJCqk6SRaqprku+k5lzndAUmaH+b9s1:TIL5HeZlzdAkebA", "hash_imp": "567DEBB2A156B506ED421C435F1B2E33", "hash_pesha1": "34E5C7262181A1476F88271FA43385C7BAB7F6CD", "hash_pe256": "F78219179657C76950961DE298BE9A5875E7A643646F21DD533DDDA1FA319067", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Media Player Setup Utility", "meta_original_filename": "unregmp2.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/1df2f5fc3369f5901068ad9463d7a165fd8e7ee7a12ca6c1a88992bb1484632e/detection/", "children": "RdpSa.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\unregmp2.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "upnpcont.exe-710BE69006B074602546289497311CDD": { "file_name": "upnpcont.exe", "file_path": "C:\\Windows\\SysWOW64\\upnpcont.exe", "hash_md5": "710BE69006B074602546289497311CDD", "hash_sha1": "A4B2228082E5A57FFC07EC2D463BE578C572BA66", "hash_sha256": "8FC99D5AA8A124A217D12ADEBC52AC8A47F04E4A214A9D44CC125A70FFF58A85", "hash_sha384": "92780B9FCA5EB26593F189C03B2E63F863567B273A08B87DCD384C98FC3AC527280A0ACD282ED29E6EAB797F62455E23", "hash_sha512": "2A41260E381FB57B9DD1F899434074DDF4FE2B4A33B56997C862E0A205947C893B8FA85DB042827E99856E293709480EBB5FFB53D3A35C7D66D1C9D143CF7AB8", "hash_ssdeep": "768:u0ozid9Q9vaGQbLC1Czw7bNqZmAaMUhHgS:sovivoZmAa3A", "hash_imp": "7B6AE0B2821019CE4C865988D4D48C14", "hash_pesha1": "836EA3A5A13659CF52B3ABA3EF0E0764EC93A8AF", "hash_pe256": "75619F47C4EAB6F770496E52A9D53C6DBBBA41A0E0FCE77FBF55A88BA30B77E3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UPnP Device Host Container", "meta_original_filename": "upnpcont.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/8fc99d5aa8a124a217d12adebc52ac8a47f04e4a214a9d44cc125a70fff58a85/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC750": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\upnpcont.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "user.exe-D4D86D15435CC99BDF659FFF6784092D": { "file_name": "user.exe", "file_path": "C:\\Windows\\SysWOW64\\user.exe", "hash_md5": "D4D86D15435CC99BDF659FFF6784092D", "hash_sha1": "1CD2F1FC825F17D270C4BED851BE31A65AAE09F5", "hash_sha256": "4D2B4AA1114B342C4068E77EE063A4687C1D07CC1E51938CADAC364DF479C5B4", "hash_sha384": "0DB368EBA1C1E0C7D7CF62F614599DD52DCC2054E358D16859E311670A67E3D47D000A4AD980A700174A7DC0AA5727A1", "hash_sha512": "850C35B2BFAA3C089DF5BE24692F544EBC3B7BEB0E7FA07EF64E7D996FAAFE2AE93F4F90456C7FD894FD7ACFF35D82F76D7F6A41FB98D3673013E71950A48E31", "hash_ssdeep": "24:eNGS/glSH+q6ooD812UDGKDIILiIZW0gNNZl2Si35WWdPPYPNl:a/glScooDMxIlIZWjXZno5WwHg", "hash_imp": "n/a", "hash_pesha1": "0721B7F32EAD7BBE1135D0E7D95838728D443242", "hash_pe256": "91DECC042C0A76D51FF5EE1FF183713C9816667B74BD5ED92677E07721C41FB8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "User", "meta_original_filename": "User.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/4d2b4aa1114b342c4068e77ee063a4687c1d07cc1e51938cadac364df479c5b4/detection/" }, "UserAccountBroker.exe-21F28CA975F6ECEBDC2D82D48639E9CA": { "file_name": "UserAccountBroker.exe", "file_path": "C:\\Windows\\SysWOW64\\UserAccountBroker.exe", "hash_md5": "21F28CA975F6ECEBDC2D82D48639E9CA", "hash_sha1": "4650861A1984B99CE1BCB44D8E8B9D4FCEC1C3B0", "hash_sha256": "0E8430217B5215859DDB9B141649982B838538286334F309042FA614D5026D87", "hash_sha384": "64F7FCAF0C59362C50FD6D5A25FB4B85AE33D366696A6BF15F1953564DEC313AFD533BDC3DCC414235E015C089D2362C", "hash_sha512": "543AD318B0ACA7A6682DB909D681F2BDC2E7C0E5442F0245875C70B23F54384080671CA50E03C7E00FFFC7DC1E9295B0A2775B00C0F16C54C1AB788C861D87BE", "hash_ssdeep": "768:HKgmZIxjtwKgHQ4iFUQJRWswGEF/TW34B3PZWpoxOLh4Xj1PUd:HW6jt5gHQ4iFUQWssfZWpos8pPC", "hash_imp": "CAC43278DA3CE5795E99788B8ECFEDFF", "hash_pesha1": "2CC87DEF68836DD607F0423D1C0263136B22FA12", "hash_pe256": "727905ED8FEEADD49C7ACC87C68DD717B0C58FCD4FF152CEC5435C23C14267F9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "User Account Control Panel Host", "meta_original_filename": "UserAccountBroker.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/0e8430217b5215859ddb9b141649982b838538286334f309042fa614d5026d87/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECA5C": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\UserAccountBroker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "UserAccountControlSettings.exe-8BF5AC3EC558D69DC4B0E173E726F770": { "file_name": "UserAccountControlSettings.exe", "file_path": "C:\\Windows\\SysWOW64\\UserAccountControlSettings.exe", "hash_md5": "8BF5AC3EC558D69DC4B0E173E726F770", "hash_sha1": "D462B4F08BD1426E63F6FC0FCBCC61FE745EF9C8", "hash_sha256": "07ADA4F22B7A3CF3B56E3E687A9A03A6517ADA894911E398253DC8D36D84423E", "hash_sha384": "816403B7BAE22BF93FD820962C184BF9E6694D4A49BC46BFFBD39C6F0664920BE70DAE4D20E877817DCFEDDCD436B18F", "hash_sha512": "735C39F059DDFA696D059D19132F79DBB224FD8D6DC2E1E030DB3555DE11C1A7FF0C329166896A9D0D2B4CD1A37330275E0BF63940BD860F152720E9F72237C9", "hash_ssdeep": "1536:Y/C/IdmQkArTUJrePojh3vLyPST751sNz0UCdkV/L7:mCQLkAXG+635K", "hash_imp": "281B2F62B1066F5953A92A11BC46D367", "hash_pesha1": "908D653535D640F2E9F21B40F71B5960236D7BC5", "hash_pe256": "5105D24CC6B8027766793DFB4FE5B2E4ECE9C554D7EEA913756D2838505CE46F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "UserAccountControlSettings", "meta_original_filename": "UserAccountControlSettings.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/07ada4f22b7a3cf3b56e3e687a9a03a6517ada894911e398253dc8d36d84423e/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\UserAccountControlSettings.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "children": "RdpSa.exe" }, "userinit.exe-2FA05B1CFC52E590E090705EA56F5B02": { "file_name": "userinit.exe", "file_path": "C:\\Windows\\SysWOW64\\userinit.exe", "hash_md5": "2FA05B1CFC52E590E090705EA56F5B02", "hash_sha1": "FF0D462E86C10E3FA7BF327C500F19C531153E5A", "hash_sha256": "6F1C2FD98615B9B0427ABB5AF0DEF53E3205B4A9E5EEC008E2284E28E839B096", "hash_sha384": "56DCB11112C8E761D5AAF9B814EB16FB0AF9DCF301D15437A6BB5897F406D854595330D29FDC885AAA1E585E2428BA5D", "hash_sha512": "CCEBCAEA3051A05F11EBD0AF5422A43E15CD9469ADEA6BB46644154946234290A388940FA2F19A26774CD3D11E1E4D262ACD0FC5628F193CA8FCDBB14AC24985", "hash_ssdeep": "384:BU8ligOwpzLgHTZ4xBlwOHzuommB//QNmYMQnkvWxymW7:BbliwpLgHGvVXmk/QNmYn2", "hash_imp": "BCEBEA8627BDCA82019861C4F7DA1EC4", "hash_pesha1": "F98B391884DC3F0855097A09B61D18FA3B9EC629", "hash_pe256": "FBA15F653EA57340D3EF26EC9BCBAB47E8AB0DE18B0C169E4BA5AF428B3465A7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Userinit Logon Application", "meta_original_filename": "USERINIT.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/6f1c2fd98615b9b0427abb5af0def53e3205b4a9e5eec008e2284e28e839b096/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\userinit.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\userinit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Utilman.exe-4086253BB53A17F2BEAD669CCDFCB824": { "file_name": "Utilman.exe", "file_path": "C:\\Windows\\SysWOW64\\Utilman.exe", "hash_md5": "4086253BB53A17F2BEAD669CCDFCB824", "hash_sha1": "394100DE50E62E815A042EB1DB4EC0FC9C069129", "hash_sha256": "8A05A4990C0370142DDFEC7D489737CCC4B96FAFE0A80E06AF7AE04A1C7BE722", "hash_sha384": "97B2F0FEEBCA10E140F4E6B1165E5B776E44902445A5AF912402DFE28746DD41F005D310E4C963AE956A6172DECFBE41", "hash_sha512": "0CAE2C342E18096663DF919573031D48D34C0560C16297866E9064286B6362D9AB8B859BFE025304185A8F75AD9DCFD6A6214CE04621A5952FFA51F83AE7173A", "hash_ssdeep": "1536:tOCx1L46/n7zk1s2SxoZRM5RGye6NicH+LzPlliSPTcqgoLSbgvVoZtnBYMVGhZY:ECfLBzk1zFSGQefNwWc", "hash_imp": "3BD29D15021D65C6569F62BBCD68785C", "hash_pesha1": "A6CDC874E49E6A5ECD29D1583D658499E7C66161", "hash_pe256": "C64EB9AE42ACC9F00ED74AC7C1E5B590F266FAFA533ABF19054FAF0B36CAD8DB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Utility Manager", "meta_original_filename": "utilman2.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/8a05a4990c0370142ddfec7d489737ccc4b96fafe0a80e06af7ae04a1c7be722/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Utilman.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "verclsid.exe-FBBBBA89EFE4C6DD0CAC5CEAFC9342F0": { "file_name": "verclsid.exe", "file_path": "C:\\Windows\\SysWOW64\\verclsid.exe", "hash_md5": "FBBBBA89EFE4C6DD0CAC5CEAFC9342F0", "hash_sha1": "AD576D95E15E1DD55543A182DFF9452510D3E306", "hash_sha256": "50259658B30D267DB199A0805E0986798DD799E18700FD198B894CE9E04DB851", "hash_sha384": "40E9568C7C5C5EB1569C5216BFD44DBA8E89C784AE6A7F38D1B1F3A963198A7021A64FCE2E561113C7C9D85C154DC7CB", "hash_sha512": "4393D0FD1D12BCBCDFFDBC4973AC43823C68FB1F5BDDB77126E6D40479175670BB9F6AB94CD50FC918A2C2D5A5AEF6D8FCF4ABD757D4F5C20485E998D4F3161E", "hash_ssdeep": "192:N11qDr34PivAauMnDXD1MJVRaqXWNNW9w:PQjiivAauMzDWJeiWNNW", "hash_imp": "BDC7940F5DE0DB2F5978F34E0BD82FF0", "hash_pesha1": "1A628299620531687406291DE136973D58701419", "hash_pe256": "E4583FC03595147982CEBD97D0CE544948DE13E7822D034B8257F28E01110EE6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extension CLSID Verification Host", "meta_original_filename": "verclsid.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/50259658b30d267db199a0805e0986798dd799e18700fd198b894ce9e04db851/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\verclsid.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "verifiergui.exe-F61085E8A94C91AE6FF47F0D6FF449AF": { "file_name": "verifiergui.exe", "file_path": "C:\\Windows\\SysWOW64\\verifiergui.exe", "hash_md5": "F61085E8A94C91AE6FF47F0D6FF449AF", "hash_sha1": "5986573DEE53F421CBBFB3A8FBEA2BD32F81FCD6", "hash_sha256": "EC30A097830520B77A6BEFF40544271D01CB625CB29ECEE1E8AD6D4B9BA4E961", "hash_sha384": "B1C4B41BFBC8483F73F08DC5A4BB1B6727A46AD58FFC209E5E2C4CF03FF6D2B7ACEE3CA6B376A8EBD46BE0274D32C67E", "hash_sha512": "7AF23B01461DDA2BDFF5772E666FF1EECE9817C4C829E5430134CB6228033E09624039681BE99C948A16F45B091E073C368AC126CBC227C88E1F9EE893155B29", "hash_ssdeep": "3072:ZcJVIZen+Vcv2JBwwRBkBnRePnjA+z7zqB4nG0yYSQSvMA201qaIxP090tJJmNi+:OkG1kUg5qApW+nOU+KNU", "hash_imp": "88EF90B452C1D8A53DCAF4AB36A661C5", "hash_pesha1": "E70A2349664F2B34590AA5041216B264ECF307A1", "hash_pe256": "E77677EDB0B52FE1284E2EEF10420CDFFDE104E6042B237A24F5092F1645A411", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Driver Verifier Manager", "meta_original_filename": "verifiergui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/ec30a097830520b77a6beff40544271d01cb625cb29ecee1e8ad6d4b9ba4e961/detection/", "output": " \r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n \r\nCOMMON USAGE: \r\n verifier /?\r\n verifier /standard /all\r\n verifier /standard /driver NAME [NAME ...]\r\n verifier /flags FLAGS /all\r\n verifier /flags FLAGS /driver NAME [NAME ...]\r\n verifier /rules [OPTION ...]\r\n verifier /query\r\n verifier /querysettings\r\n verifier /bootmode [persistent|resetonbootfail|oneboot]\r\n verifier /reset\r\n verifier /faults [PROB [TAGS [APPS [MINS]]]]\r\n verifier /faultssystematic [OPTION ...]\r\n verifier /log LOG_FILE_NAME [/interval SECONDS]\r\n verifier /volatile /flags FLAGS\r\n verifier /volatile /adddriver NAME [NAME ...]\r\n verifier /volatile /removedriver NAME [NAME ...]\r\n verifier /volatile /faults [PROB [TAGS [APPS [MINS]]]]\r\n \r\n/?\r\n This help.\r\n \r\n/standard\r\n Enable the Driver Verifier standard flags. \r\n This is functionally equivalent to '/flags 0x209BB'\r\n \r\n/all\r\n Enable Driver Verifier on all drivers in a system.\r\n \r\n/driver NAME [NAME ...]\r\n Specify the driver or list of drivers that should be verified.\r\n NAME is the name and extension of the file to verify (example: driver.sys).\r\n To enable Driver Verifier on more than one driver, list all drivers using a\r\n space separated list. Wildcard values (such as n*.sys) are not supported.\r\n \r\n/flags FLAGS \r\n Specify which options are enabled for verification. \r\n FLAGS value must be a number in decimal or hex (with 0x prefix).\r\n Note: Flags are applied to all drivers being checked by Driver Verifier. \r\n \r\n STANDARD FLAGS:\r\n These flags are considered standard options for Driver Verifier and can be \r\n set using '/standard' or by the combination of the options: '/flags 0x209BB'\r\n bit 0 (0x00000001) - Special pool\r\n bit 1 (0x00000002) - Force IRQL checking\r\n bit 3 (0x00000008) - Pool tracking\r\n bit 4 (0x00000010) - I/O verification\r\n bit 5 (0x00000020) - Deadlock detection\r\n bit 7 (0x00000080) - DMA checking\r\n bit 8 (0x00000100) - Security checks\r\n bit 11 (0x00000800) - Miscellaneous checks\r\n bit 17 (0x00020000) - DDI compliance checking\r\n \r\n ADDITIONAL FLAGS:\r\n These flags are designed for specific scenario testing.\r\n Flags marked with a (*) require I/O Verification (bit 4) also be enabled.\r\n Flags marked with a (**) support disabling of individual rules.\r\n bit 2 (0x00000004) - Randomized low resources simulation\r\n bit 9 (0x00000200) - Force pending I/O requests (*)\r\n bit 10 (0x00000400) - IRP logging (*)\r\n bit 13 (0x00002000) - Invariant MDL checking for stack (*)\r\n bit 14 (0x00004000) - Invariant MDL checking for driver (*)\r\n bit 15 (0x00008000) - Power framework delay fuzzing\r\n bit 16 (0x00010000) - Port/miniport interface checking\r\n bit 18 (0x00040000) - Systematic low resources simulation\r\n bit 19 (0x00080000) - DDI compliance checking (additional)\r\n bit 21 (0x00200000) - NDIS/WIFI verification (**)\r\n bit 23 (0x00800000) - Kernel synchronization delay fuzzing\r\n bit 24 (0x01000000) - VM switch verification\r\n bit 25 (0x02000000) - Code integrity checks\r\n \r\n/rules [OPTION ...]\r\n Options for rules that can be disabled (advanced). \r\n query: shows current status of controllable rules.\r\n reset: resets all rules to their default state.\r\n default ID: sets rule ID to its default state.\r\n disable ID: disables specified rule ID.\r\n \r\n/query\r\n Display a summary of Driver Verifier's current activity.\r\n \r\n/querysettings\r\n Display a summary of the options and drivers that are currently enabled, \r\n or options and drivers that will be verified after the next boot. The \r\n display does not include drivers and options added using /volatile.\r\n \r\n/bootmode\r\n Sets the verifier boot mode. Requires reboot to take effect.\r\n persistent: Ensures that DV settings are persistent over many reboots.\r\n This is default.\r\n resetonbootfail: If OS fails to boot, reset verifier for subsequent boots.\r\n oneboot: Only enable verifier for next boot.\r\n \r\n/reset\r\n Clear Driver Verifier flag and driver settings. Does not clear bootmode.\r\n Requires reboot to take effect.\r\n \r\n/faults [PROB [TAGS [APPS [MINS]]]]\r\n Enable the Randomized low resources simulation bit and optionally control\r\n parameters for the Randomized low resources simulation.\r\n PROB: A number between 1 and 10000 specifying the fault injection \r\n probability. If this parameter is not specified, then the default \r\n value of 600 (6%) will be used.\r\n TAGS: A space separated list of the pool tags to be injected with faults.\r\n If this parameter is not specified, then any pool allocation can be\r\n injected with faults.\r\n APPS: A space separated list of the image filename of the applications that\r\n will be injected with faults. If this parameter is not specified then\r\n the Randomized low resources simulation can take place in any\r\n application.\r\n MINS: A positive number indicating the of minutes after rebooting during \r\n which no fault injection will occur. If this parameter is not \r\n specified, then the default length of 8 minutes will be used.\r\n \r\n/faultssystematic [OPTION ...]\r\n Options for controlling the Systematic low resources simulation.\r\n enableboottime: enables fault injections across reboots.\r\n disableboottime: disables fault injections across reboots (default).\r\n recordboottime: enables fault injections in 'what if' mode across\r\n reboots.\r\n resetboottime: disables fault injections across reboots and clears\r\n the stack exclusion list.\r\n enableruntime: dynamically enables fault injections.\r\n disableruntime: dynamically disables fault injections.\r\n recordruntime: dynamically enables fault injections in 'what if'\r\n mode.\r\n resetruntime: dynamically disables fault injections and clears the\r\n previosly faulted stack list.\r\n querystatistics: shows the current fault injection statistics.\r\n incrementcounter: increments the test pass counter used to identify\r\n when a fault was injected.\r\n getstackid COUNTER: retrieves the indicated injected stack id.\r\n excludestack STACKID: excludes the stack from fault injection.\r\n \r\n/log LOG_FILE_NAME [/interval SECONDS]\r\n Create a log file with the name LOG_FILE_NAME. \r\n If '/interval' option is not specified, the default 30 seconds is used. \r\n Note: If a 'verifier /log' command is typed at the command line, the command\r\n prompt does not return. Use CTRL+C to close the log and return.\r\n \r\n/volatile\r\n Change the verifier settings dynamically without rebooting the system.\r\n Volatile settings are in effect until the next system reboot. \r\n \r\n/volatile /adddriver NAME [NAME ...]\r\n Add the specified driver or drivers to the list of drivers that will be \r\n checked with volatile settings. \r\n \r\n/volatile /removedriver NAME [NAME ...]\r\n Remove the specified driver or drivers from the list of drivers that are\r\n being checked with volatile settings. \r\n \r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\verifiergui.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "VSSUIRUN.exe-743C6EAF570F5E54A822D6839C91F308": { "file_name": "VSSUIRUN.exe", "file_path": "C:\\Windows\\SysWOW64\\VSSUIRUN.exe", "hash_md5": "743C6EAF570F5E54A822D6839C91F308", "hash_sha1": "D35264F0AEA682835EEED84AEE0BCF2A724A09F4", "hash_sha256": "02E2F77451D995D053E0FD296A1CDEA7C3E3D24933C961987AE672A865A01D60", "hash_sha384": "F0ADBB4D8BAB2E4F10EAEBF1247D281A936D1565DE311127991840C28179D007861C255F5B979D4A2F929BD2F3CF220A", "hash_sha512": "86E19F3CA29871752DCEAD3A6E9A29F6FA9CEFF9C56110EAD0CC4AE6A9296C0E39D49E5945556AF59227D2787DEE8DA39C1D63C79D97231AE10D7BD33960EECA", "hash_ssdeep": "768:fo+ZPJz71JCgUvVOA8zHkqkQWeod/uUOu3jPewyszbkN4dppainbNnnnnnnnnnnZ:xn/Y8zHrYnb3C9sfk64inbsM", "hash_imp": "4A312608387D9665CC84921A5E9413F7", "hash_pesha1": "4E9B2800C7B393D0D59F4E4B3FD786DFD6F9C657", "hash_pe256": "E64277BB1D4F7EC4B34D549BBA315F4F4959FF0D6292B7C2615164897308CA81", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Configure Shadow Copies", "meta_original_filename": "VSSUIRUN.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/02e2f77451d995d053e0fd296a1cdea7c3e3d24933c961987ae672a865a01d60/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\VSSUI.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC13F8": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\VSSUIRUN.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Shadow Copies" }, "w32tm.exe-4FEC691AAA510DD9A3A783FBA5C52066": { "file_name": "w32tm.exe", "file_path": "C:\\Windows\\SysWOW64\\w32tm.exe", "hash_md5": "4FEC691AAA510DD9A3A783FBA5C52066", "hash_sha1": "BF777F445DE32A1DBD7762B272FDA14960A6AEC1", "hash_sha256": "52537A069C700F82683549DBA51BC73B66130385D726497C1728DC5A0B80987D", "hash_sha384": "66B74F43F72902A0D843CC26B2BD09FEFF02E7F514AD42314A2C6E8747BF8398998304F70AFF1DF4E9024A26AF3B7EE7", "hash_sha512": "0B247A05E78D2DBA77A81F2F4379B44177FDBAFD30873742C0ED71BF642FDA59E98E80B4DE776215C31589E1754664AD5B5B17172632BB7D0D610E91EDC47B4D", "hash_ssdeep": "3072:FJuUHqqL6hGKm/muGdxEtgdOgM/MIoPYtFJ4G7qAnclUs3q3T4wEi4LICX4KZ9jI:FKmMbfORA8TOUs3FiSI84kplZqfIu", "hash_imp": "CFD864E49D1D804AA17A5DB67CF74C08", "hash_pesha1": "D2C229B8F3CF303C6C0DB99A0E8D5A7E9C9802AD", "hash_pe256": "4AD4313AF61A52709EE84F067B7651A796DEE58A99D05BA740E38442722A9463", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Time Service Diagnostic Tool", "meta_original_filename": "w32time.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "w32tm [/? | /register | /unregister ]\r\n ? - this help screen.\r\n register - register to run as a service and add default\r\n configuration to the registry.\r\n unregister - unregister service and remove all configuration\r\n information from the registry.\r\n\r\nw32tm /monitor [/domain:<domain name>]\r\n [/computers:<name>[,<name>[,<name>...]]]\r\n [/threads:<num>] [/ipprotocol:<4|6>] [/nowarn]\r\n domain - specifies which domain to monitor. If no domain name\r\n is given, or neither the domain nor computers option is\r\n specified, the default domain is used. This option may be\r\n used more than once.\r\n computers - monitors the given list of computers. Computer\r\n names are separated by commas, with no spaces. If a name is\r\n prefixed with a '*', it is treated as an AD PDC. This option\r\n may be used more than once.\r\n threads - how many computers to analyze simultaneously. The\r\n default value is 3. Allowed range is 1-50.\r\n ipprotocol - specify the IP protocol to use. The default is\r\n to use whatever is available.\r\n nowarn - skip warning message.\r\n\r\nw32tm /ntte <NT time epoch>\r\n Convert a NT system time, in (10^-7)s intervals from 0h 1-Jan 1601,\r\n into a readable format.\r\n\r\nw32tm /ntpte <NTP time epoch>\r\n Convert an NTP time, in (2^-32)s intervals from 0h 1-Jan 1900, into\r\n a readable format.\r\n\r\nw32tm /resync [/computer:<computer>] [/nowait] [/rediscover] [/soft]\r\n Tell a computer that it should resynchronize its clock as soon\r\n as possible, throwing out all accumulated error statistics.\r\n computer:<computer> - computer that should resync. If not\r\n specified, the local computer will resync.\r\n nowait - do not wait for the resync to occur;\r\n return immediately. Otherwise, wait for the resync to\r\n complete before returning.\r\n rediscover - redetect the network configuration and rediscover\r\n network sources, then resynchronize.\r\n soft - resync utilizing existing error statistics. Not useful,\r\n provided for compatibility.\r\n\r\nw32tm /stripchart /computer:<target> [/period:<refresh>]\r\n [/dataonly] [/samples:<count>] [/packetinfo] [/ipprotocol:<4|6>] [/rdtsc]\r\n Display a strip chart of the offset between this computer and\r\n another computer.\r\n computer:<target> - the computer to measure the offset against.\r\n period:<refresh> - the time between samples, in seconds. The\r\n default is 2s\r\n dataonly - display only the data, no graphics.\r\n samples:<count> - collect <count> samples, then stop. If not\r\n specified, samples will be collected until Ctrl-C is pressed.\r\n packetinfo - print out NTP packet response message.\r\n ipprotocol - specify the IP protocol to use. The default is \r\n to use whatever is available.\r\n rdtsc - display the TSC values and time offset data in CSV format.\r\n The output displays TSC and FILETIME values captured before the \r\n NTP request is sent, TSC value after an NTP response is received\r\n along with NTP roundtrip and time offset values.\r\n\r\n\r\nw32tm /config [/computer:<target>] [/update]\r\n [/manualpeerlist:<peers>] [/syncfromflags:<source>]\r\n [/LocalClockDispersion:<seconds>]\r\n [/reliable:(YES|NO)]\r\n [/largephaseoffset:<milliseconds>]\r\n computer:<target> - adjusts the configuration of <target>. If not\r\n specified, the default is the local computer.\r\n update - notifies the time service that the configuration has\r\n changed, causing the changes to take effect.\r\n manualpeerlist:<peers> - sets the manual peer list to <peers>,\r\n which is a space-delimited list of DNS and/or IP addresses.\r\n When specifying multiple peers, this switch must be enclosed in\r\n quotes.\r\n syncfromflags:<source> - sets what sources the NTP client should\r\n sync from. <source> should be a comma separated list of\r\n these keywords (not case sensitive):\r\n MANUAL - sync from peers in the manual peer list\r\n DOMHIER - sync from an AD DC in the domain hierarchy\r\n NO - sync from none\r\n ALL - sync from both manual and domain peers \r\n LocalClockDispersion:<seconds> - configures the accuracy of the\r\n internal clock that w32time will assume when it can't acquire \r\n time from its configured sources. \r\n reliable:(YES|NO) - set whether this machine is a reliable time source.\r\n This setting is only meaningful on domain controllers. \r\n YES - this machine is a reliable time service\r\n NO - this machine is not a reliable time service\r\n largephaseoffset:<milliseconds> - sets the time difference between \r\n local and network time which w32time will consider a spike. \r\n\r\nw32tm /tz\r\n Display the current time zone settings.\r\n\r\nw32tm /dumpreg [/subkey:<key>] [/computer:<target>]\r\n Display the values associated with a given registry key.\r\n The default key is HKLM\\System\\CurrentControlSet\\Services\\W32Time\r\n (the root key for the time service).\r\n subkey:<key> - displays the values associated with subkey <key> \r\n of the default key.\r\n computer:<target> - queries registry settings for computer <target>.\r\n\r\nw32tm /query [/computer:<target>] \r\n {/source | /configuration | /peers | /status} \r\n [/verbose]\r\n Display a computer's windows time service information.\r\n computer:<target> - query the information of <target>. If not\r\n specified, the default is the local computer.\r\n source: display the time source.\r\n configuration: display the configuration of run-time and where \r\n the setting comes from. In verbose mode, display the undefined \r\n or unused setting too.\r\n peers: display a list of peers and their status.\r\n status: display windows time service status.\r\n verbose: set the verbose mode to display more information.\r\n\r\nw32tm /debug {/disable | {/enable /file:<name> /size:<bytes> /entries:<value>\r\n [/truncate]}} \r\n Enable or disable local computer windows time service private log.\r\n disable: disable the private log.\r\n enable: enable the private log.\r\n file:<name> - specify the absolute filename.\r\n size:<bytes> - specify the maximum size for circular logging.\r\n entries:<value> - contains a list of flags, specified by number and\r\n separated by commas, that specify the types of information that \r\n should be logged. Valid numbers are 0 to 300. A range of numbers \r\n is valid, in addition to single numbers, such as 0-100,103,106. \r\n Value 0-300 is for logging all information.\r\n truncate: truncate the file if it exists.\r\n\r\nw32tm /leapseconds /getstatus [/verbose]\r\n Display the status of leap seconds on the local machine.\r\n verbose: Set the verbose mode to display more information.\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\w32tm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "waitfor.exe-E76B70B02F292D98E8CBF33CD3DDF357": { "file_name": "waitfor.exe", "file_path": "C:\\Windows\\SysWOW64\\waitfor.exe", "hash_md5": "E76B70B02F292D98E8CBF33CD3DDF357", "hash_sha1": "E522CD636EE1C5AF3061031D3F29B3A96CD1B92D", "hash_sha256": "1B2EC8189777F5592A003C5AD8114848F0300590E034FACE6107D78E2EE8FB97", "hash_sha384": "C895EF8AA352EFF8C4FDFB89160F60DFF8A85478F15BF1606148CB833A582C7AE2A3A0EE0AE6BEB15DE48455DC211B9D", "hash_sha512": "EFBC53C57520DE531F1ADA9928E99AFCE89217C751F0F986E9A0C54EE0B8A2CD1DD29A64C0AA9E7B9D20A3DD49258F9827088183068727CD2893C3FB4A736A2B", "hash_ssdeep": "768:9SHaR2oWlwPzXapPr437iW8qdPwU+lHdKwi5xLApK:9SHaR2oVOpz437iAdl29KwWxQK", "hash_imp": "B03EDAA7CAD5E6CDC3A3B4CB4A721AD1", "hash_pesha1": "5D03826C2131FAAB1058CBEB53DC6517C4E41117", "hash_pe256": "3F7FDB71A382CEC4A1BA2433448426C2E933FC10ADFDC1A539FE044297C9CA1E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "waitfor - wait/send a signal over a network", "meta_original_filename": "waitfor.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/1b2ec8189777f5592a003c5ad8114848f0300590e034face6107d78e2ee8fb97/detection/", "output": "\r\nWaitFor has two ways of working: \r\n\r\nSyntax 1: to send a signal\r\n WAITFOR [/S system [/U user [/P [password]]]] /SI signal\r\n\r\nSyntax 2: to wait for a signal\r\n WAITFOR [/T timeout] signal \r\n\r\nDescription:\r\n This tool sends, or waits for, a signal on a system. When /S is not\r\n specified, the signal will be broadcasted to all the systems in a\r\n domain. If /S is specified, then the signal will be sent only\r\n to the specified system.\r\n\r\nParameter List:\r\n /S system Specifies remote system to send signal to.\r\n\r\n /U [domain\\]user Specifies the user context under which\r\n the command should execute.\r\n\r\n /P [password] Specifies the password for the given user context.\r\n\r\n /SI Sends the signal across the net to waiting machines\r\n\r\n /T timeout Number of seconds to wait for signal. Valid range\r\n is 1 - 99999. Default is to wait forever for signal.\r\n\r\n signal The name of the signal to wait for or to send.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE: A system can wait for multiple unique signal names.\r\n The signal name cannot exceed 225 characters and cannot\r\n contain characters other than a-z, A-Z, 0-9 and ASCII \r\n characters in the range 128-255.\r\n\r\nExamples:\r\n WAITFOR /?\r\n WAITFOR SetupReady \r\n WAITFOR CopyDone /T 100 \r\n WAITFOR /SI SetupReady \r\n WAITFOR /S system /U user /P password /SI CopyDone\r\n", "error": "ERROR: The signal cannot contain characters other than a-z, A-Z, 0-9 \r\nand ASCII characters in the range 128-255.\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\waitfor.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\waitfor.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wecutil.exe-D1DF41E659F60E05B0557293B4EE645C": { "file_name": "wecutil.exe", "file_path": "C:\\Windows\\SysWOW64\\wecutil.exe", "hash_md5": "D1DF41E659F60E05B0557293B4EE645C", "hash_sha1": "A98A3A75B40F9786EBF3DB21E5CCEF43E70351DE", "hash_sha256": "53B07AB9DAE0E58B06DAB40CF837DD9150A6125759B4D4A18D3C36A07042B9E7", "hash_sha384": "EAB9C9711DF660A713B1FD001BEAD2B6A10985DF5488E8ACD33A83EEF4FEC37ABB83F3CBEA61FCC2CAF93325599FF3FE", "hash_sha512": "007DF07229AA71524DFCF922F6B0A3E7033A24476798F6DFE1D89058F9247BFE6573DF0A57ED4ED604392E29E1964C26D818D9E8CFC86717E3311270D16BFF56", "hash_ssdeep": "1536:5h5mMvjC4F9XGgT4T59Jffp8WZ+rxNq3Qjg80wZD+k4:5zmMfFlI53ffaWZ+rxNIQcdwRL4", "hash_imp": "39A117F0BBDC6E58BDAB1DF5A22865F5", "hash_pesha1": "AB60EDF3B9FD3C9DCFB4AE20CA963B32810B4CF6", "hash_pe256": "F8A3A44FF881598F9DE8C6D2A6042D4745D8798BF916122A216BFE6794497A16", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Event Collector Command Line Utility", "meta_original_filename": "WECUTIL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/53b07ab9dae0e58b06dab40cf837dd9150a6125759b4d4a18d3c36a07042b9e7/detection/", "output": "Windows Event Collector Utility\r\n\r\nEnables you to create and manage subscriptions to events forwarded from remote\r\nevent sources that support WS-Management protocol.\r\n\r\nUsage:\r\n\r\nYou can use either the short (i.e. es, /f) or long (i.e. enum-subscription, /format)\r\nversion of the command and option names. Commands, options and option values are\r\ncase-insensitive.\r\n\r\n(ALL UPPER-CASE = VARIABLE)\r\n\r\nwecutil COMMAND [ARGUMENT [ARGUMENT] ...] [/OPTION:VALUE [/OPTION:VALUE] ...]\r\n\r\nCommands:\r\n\r\nes (enum-subscription) List existent subscriptions.\r\ngs (get-subscription) Get subscription configuration.\r\ngr (get-subscriptionruntimestatus) Get subscription runtime status.\r\nss (set-subscription) Set subscription configuration.\r\ncs (create-subscription) Create new subscription.\r\nds (delete-subscription) Delete subscription.\r\nrs (retry-subscription) Retry subscription.\r\nqc (quick-config) Configure Windows Event Collector service.\r\n\r\nCommon options:\r\n\r\n/h|? (help)\r\nGet general help for the wecutil program.\r\n\r\nwecutil { -help | -h | -? }\r\n\r\nFor arguments and options, see usage of specific commands:\r\n\r\nwecutil COMMAND -?\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wecutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "Command help is not supported. Error = 0x57.\r\nThe parameter is incorrect.\r\n" }, "WerFault.exe-E9862685F483002916436CDE77965076": { "file_name": "WerFault.exe", "file_path": "C:\\Windows\\SysWOW64\\WerFault.exe", "hash_md5": "E9862685F483002916436CDE77965076", "hash_sha1": "C9E03E349DEDE305A5E23E38101BF296EFE3B836", "hash_sha256": "4E87E4C2C71B519B402E1D6FBD818AB2EAAB712BFDC61AC741EA9ED8850E7C27", "hash_sha384": "83EC7BF54BDA63C2B48CBDD8B22EDF5FCD3D56707A4AA0E0DA73A775A2036AB924F7E4B203F3304FF55D4546AE2EF106", "hash_sha512": "703615810AAA4C9BAA5501628D844C4CC17C66FC0B45C398E24E6AD53FEF576357B6FE293473038BBFF12EBE9A75423EC4C32691C9676C5372EF5D5AAF9A0B90", "hash_ssdeep": "12288:wE2ecBg7D/qSvd889Oe5X+F/LexR1GOIn8Xc2Hyw4:fKBg7D/qSFf9Oe5yS/1GOIn8Xcyh4", "hash_imp": "DB2005AFC3C908C50B9371AF6F31CE8D", "hash_pesha1": "C9AE5E6F43196DB619489952D543F93ED317F7DF", "hash_pe256": "3205C8776E74751EF82975A2E2D718A791B34B0B10324C69D5041CE3B2E0A7E3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Problem Reporting", "meta_original_filename": "WerFault.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/61", "filescan_vtlink": "https://www.virustotal.com/gui/file/4e87e4c2c71b519b402e1d6fbd818ab2eaab712bfdc61ac741ea9ed8850e7c27/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\WerFault.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WerFaultSecure.exe-8629A5FC8B5A38E6BCA9160BCAE2B817": { "file_name": "WerFaultSecure.exe", "file_path": "C:\\Windows\\SysWOW64\\WerFaultSecure.exe", "hash_md5": "8629A5FC8B5A38E6BCA9160BCAE2B817", "hash_sha1": "6B47F84E5FCC721B8FDBCC8E4D876C811E68BF00", "hash_sha256": "D84F0A050159D0097C1ABEF7E815F1A2BE8C5365745DAABC6973B208E73A2AD1", "hash_sha384": "0215CB590A1CDE8BEDD6B1DCD3E3D458A7F8C92764889F24F1C0B39341147446FE0E3968A250004ECF0CA41123232165", "hash_sha512": "C7FFD600D7C0B92C414FB6B79A78B563F06D52889FC1685C92E00A5F244CA24EF0575D202E5E6957D6A7D5FC09F475D9559E6C68FD7A496C4D2A2ADD7562EADE", "hash_ssdeep": "3072:nDQquPKORsAsLqWt0wvaBaoFJ+yC3pwRb6JPqB604HHy7hRCd39vy3Ak:ncZVRHsLTpagVJyB60OHyLC7ve3", "hash_imp": "16258F58A6D7D262E9BE1902AD3FE046", "hash_pesha1": "BF2FEA9BFD5A92636BCC23E88F96950C9641E02F", "hash_pe256": "5F317B30BD152CB457005A7736287F16C821DA5D406D3D9329CD4C6BED9A2F47", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Fault Reporting", "meta_original_filename": "WerFaultSecure.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Windows": "File", "(R-D) C:\\Windows\\SysWOW64\\dbghelp.dll": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" } }, "wermgr.exe-555D0661B743C909A5BF0C2B27D220FA": { "file_name": "wermgr.exe", "file_path": "C:\\Windows\\SysWOW64\\wermgr.exe", "hash_md5": "555D0661B743C909A5BF0C2B27D220FA", "hash_sha1": "05B6BA6334666DB4D1FB62136EDD9DDB29397D8C", "hash_sha256": "ACBA1FA5F47D1777984DF28F0C30F70A2DF45EEAB0AFDA76AE09EAFCD3533281", "hash_sha384": "F3BD9D8338DED973B62F9AF477A9F81782A74244B1E96B6444B67AF2254A4A510A4F2F48E44991AAA7A1C17064ABC2AA", "hash_sha512": "72C055994159B57AC44BCE932A6CE98C5F011B0ABB5C367B50025B766EF496176FA5F3C9CE26009D0D4903D3C63720BEA9CC0DB02280B1E95204A381F5730F8B", "hash_ssdeep": "3072:gb7u+0mwitTGIgM1IOr4PeK+//VFtp5jwu0fGeNwOSFJ+yC3pwRb6JPqB604HHyn:gvu+0mwitThgMm1PeKc/ztpWqeNwOZVu", "hash_imp": "331C57EDE37E373B685F86CCD4B7EFF0", "hash_pesha1": "9C0FEA0D378E6A476948AABE1C3C7AEA5CD55778", "hash_pe256": "6DA12748B48C2BCD518DF728F547BB664416EE49D2E74A0522384C656DF8A742", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Problem Reporting", "meta_original_filename": "WerMgr", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/acba1fa5f47d1777984df28f0c30f70a2df45eeab0afda76ae09eafcd3533281/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wermgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wevtutil.exe-3C7F4C8D60835D7B636DAC97E8BD8E4C": { "file_name": "wevtutil.exe", "file_path": "C:\\Windows\\SysWOW64\\wevtutil.exe", "hash_md5": "3C7F4C8D60835D7B636DAC97E8BD8E4C", "hash_sha1": "9421FB4AE041F259A48471F0F29DAA062E1BC200", "hash_sha256": "0ADDECEB61359346C7D752F0FA3D1CE72E8A494CAE651A1DF2BF1E867E5DFC7C", "hash_sha384": "E61C619DDE606819610B50C82565798AC40B8122D9DA56770A4D2F1877B909FC2B69A38EC447C2B7537D0C6D32B3D241", "hash_sha512": "13E69E9B53703529B5459A7B1C4ECD8A8A521845305AB4F5EC0E2C8434192B7B91AB6C50EF703EE61069831747456B99776E7297DC26428E2CD36D13DE11FAF5", "hash_ssdeep": "3072:IDtDzFHGz9VYNksY3zsFgMveKKIbZ3lJnrMEAl+XQoJp/a8Y5iXpLutqYLq:iUziY3zvFKKI1V1jAAA8pLutJq", "hash_imp": "6CF8349084410DA14CC8D4F3BA0CAC78", "hash_pesha1": "EDE4E68D088D26D77FD3FF2519CFB78FBFC0162C", "hash_pe256": "9F63D27306037A9B84B58DD01B3F70DD01362873E4F3DF43D4784E6E55CEB3CE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Eventing Command Line Utility", "meta_original_filename": "wevtutil.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/0addeceb61359346c7d752f0fa3d1ce72e8a494cae651a1df2bf1e867e5dfc7c/detection/", "output": "Windows Events Command Line Utility.\r\n\r\nEnables you to retrieve information about event logs and publishers, install\r\nand uninstall event manifests, run queries, and export, archive, and clear logs.\r\n\r\nUsage:\r\n\r\nYou can use either the short (for example, ep /uni) or long (for example, \r\nenum-publishers /unicode) version of the command and option names. Commands, \r\noptions and option values are not case-sensitive.\r\n\r\nVariables are noted in all upper-case.\r\n\r\nwevtutil COMMAND [ARGUMENT [ARGUMENT] ...] [/OPTION:VALUE [/OPTION:VALUE] ...]\r\n\r\nCommands:\r\n\r\nel | enum-logs List log names.\r\ngl | get-log Get log configuration information.\r\nsl | set-log Modify configuration of a log.\r\nep | enum-publishers List event publishers.\r\ngp | get-publisher Get publisher configuration information.\r\nim | install-manifest Install event publishers and logs from manifest.\r\num | uninstall-manifest Uninstall event publishers and logs from manifest.\r\nqe | query-events Query events from a log or log file.\r\ngli | get-log-info Get log status information.\r\nepl | export-log Export a log.\r\nal | archive-log Archive an exported log.\r\ncl | clear-log Clear a log.\r\n\r\nCommon options:\r\n\r\n/{r | remote}:VALUE\r\nIf specified, run the command on a remote computer. VALUE is the remote computer \r\nname. Options /im and /um do not support remote operations.\r\n\r\n/{u | username}:VALUE\r\nSpecify a different user to log on to the remote computer. VALUE is a user name\r\nin the form domain\\user or user. Only applicable when option /r is specified.\r\n\r\n/{p | password}:VALUE\r\nPassword for the specified user. If not specified, or if VALUE is \"*\", the user \r\nwill be prompted to enter a password. Only applicable when the /u option is\r\nspecified.\r\n\r\n/{a | authentication}:[Default|Negotiate|Kerberos|NTLM]\r\nAuthentication type for connecting to remote computer. The default is Negotiate.\r\n\r\n/{uni | unicode}:[true|false]\r\nDisplay output in Unicode. If true, then output is in Unicode. \r\n\r\nTo learn more about a specific command, type the following:\r\n\r\nwevtutil COMMAND /?\r\n", "error": "Command help is not supported.\r\nThe parameter is incorrect.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wevtutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wextract.exe-7CD5F431EA58317F3B2E582F2D1DDFE9": { "file_name": "wextract.exe", "file_path": "C:\\Windows\\SysWOW64\\wextract.exe", "hash_md5": "7CD5F431EA58317F3B2E582F2D1DDFE9", "hash_sha1": "69F8EDC59857CE46821CED8342DA1C875CA05DA6", "hash_sha256": "64BC17D02D409B0EAE84DCCC71DD0C5115EF208EFC79A30281E60404A5632D91", "hash_sha384": "54882F879ED5203840DBFC08B85216DF2F793FBEB98615351DE84ABF9F3832B24723BA90F160B2C3E4EB32AD53DA6CE0", "hash_sha512": "E537056E3EA60BB918C0C8538445BE775B0B16775B2EC5FA92B9C2EAA394B3C425D47D5C0C7B9262A28BC42B5D76D03622758A058913AAC628841BBAE4B11566", "hash_ssdeep": "3072:KZy+bnr+O1m8Wp1icKAArDZz4N9GhbkUNEk951d:KZy+bnr+f9p0yN90vE", "hash_imp": "646167CCE332C1C252CDCB1839E0CF48", "hash_pesha1": "E0AABCB96934AE293FA44D93AC9F16F76B98D934", "hash_pe256": "3243E32D47F77684909956ED89B01473C14BCFBD8C444BBD6996838723820453", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Win32 Cabinet Self-Extractor ", "meta_original_filename": "WEXTRACT.EXE .MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/64bc17d02d409b0eae84dccc71dd0c5115ef208efc79a30281e60404a5632d91/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\wextract.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\wextract.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "where.exe-B9B75E18338D783CC01A215F8054AD26": { "file_name": "where.exe", "file_path": "C:\\Windows\\SysWOW64\\where.exe", "hash_md5": "B9B75E18338D783CC01A215F8054AD26", "hash_sha1": "6E837DC826A80F37D81B86971FED0EA1A073C5E9", "hash_sha256": "E4220435F20B966623B7646C247397DDAF5CE0D8A2A5EF2BC9915E6D111EA765", "hash_sha384": "1E865BAEEBC671A0F505342DB4E61C9E8E2F7C5B7D48A300B2742F9C65EE7AD81E5799F9DB40392026606DE7DA024F75", "hash_sha512": "1791CEDD57D8C3DE47DB2E41418BAF6185266C9EA70776D1C582746F3E4E4BD335AC2AD19BA5C229716C91A41E20E98E201819BA17A66D8EE41F96ED63F99E88", "hash_ssdeep": "768:JW9XPN2yhpD212KNJxFhwGkGp5Uqa/u9xufOBF:JaXPN2yhpS1lNvkCfVxhB", "hash_imp": "C6F8BF70A2BF252E595BCF3EB4236860", "hash_pesha1": "DCCBC628056C7FD94720C31A45B44B48EBA14454", "hash_pe256": "A8C0E500BB3D85A64C79A8033FA86DBCC27544E01942ED36E3BA6CF481792D76", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Where - Lists location of files", "meta_original_filename": "where.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/e4220435f20b966623b7646c247397ddaf5ce0d8a2a5ef2bc9915e6d111ea765/detection/", "output": "\r\nWHERE [/R dir] [/Q] [/F] [/T] pattern...\r\n\r\nDescription:\r\n Displays the location of files that match the search pattern.\r\n By default, the search is done along the current directory and\r\n in the paths specified by the PATH environment variable.\r\n\r\nParameter List:\r\n /R Recursively searches and displays the files that match the\r\n given pattern starting from the specified directory.\r\n\r\n /Q Returns only the exit code, without displaying the list\r\n of matched files. (Quiet mode)\r\n\r\n /F Displays the matched filename in double quotes.\r\n\r\n /T Displays the file size, last modified date and time for all\r\n matched files.\r\n\r\n pattern Specifies the search pattern for the files to match.\r\n Wildcards * and ? can be used in the pattern. The\r\n \"$env:pattern\" and \"path:pattern\" formats can also be\r\n specified, where \"env\" is an environment variable and\r\n the search is done in the specified paths of the \"env\"\r\n environment variable. These formats should not be used\r\n with /R. The search is also done by appending the\r\n extensions of the PATHEXT variable to the pattern.\r\n\r\n /? Displays this help message.\r\n\r\n NOTE: The tool returns an error level of 0 if the search is\r\n successful, of 1 if the search is unsuccessful and\r\n of 2 for failures or errors.\r\n\r\nExamples:\r\n WHERE /?\r\n WHERE myfilename1 myfile????.*\r\n WHERE $windir:*.* \r\n WHERE /R c:\\windows *.exe *.dll *.bat \r\n WHERE /Q ??.??? \r\n WHERE \"c:\\windows;c:\\windows\\system32:*.dll\"\r\n WHERE /F /T *.dll \r\n", "error": "ERROR: Invalid argument or option - '/h'.\r\nType \"WHERE /?\" for usage help.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\where.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "whoami.exe-B17EB327F33729DB69E97F0A09839EE7": { "file_name": "whoami.exe", "file_path": "C:\\Windows\\SysWOW64\\whoami.exe", "hash_md5": "B17EB327F33729DB69E97F0A09839EE7", "hash_sha1": "00569E99B388E3A170051CC93F94C6D0A5AFDE5C", "hash_sha256": "075FA41E449213910F6D45F5713FEF8ED71EA913C1EBE594407894141F103D64", "hash_sha384": "4E51F9BF007A04A7EFCF4691A43E1B0EE10BDCA3E3E50E329763458F6E9918D9EDA6324A05232BFC728391D05B543C1E", "hash_sha512": "31090A04BE6BF8DD6927C07E72C4722EC4C872C755C47A1B8D657A1A058F0D49FEF41F7306AF696641A89A911EB2EA9EC6BA9943FC10A3FC194AC3286DB80A1C", "hash_ssdeep": "1536:akt/IKd0QSml5AcK7r7OlQKzni++weTqnc+WrRcxLTGX:qjM5Q/OlvniNqnc+WrRcxHG", "hash_imp": "E91037BB26500603D5EE8666BA6C2510", "hash_pesha1": "A875DA03562F1D263786E47C7DEF3116F1E436F7", "hash_pe256": "DEE7160278E4CC68C6152C3B6107BAAF3B34DBB0971B6CB93DE10A839F3557DC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "whoami - displays logged on user information", "meta_original_filename": "whoami.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/075fa41e449213910f6d45f5713fef8ed71ea913c1ebe594407894141f103d64/detection/", "output": "\r\nWhoAmI has three ways of working: \r\n\r\nSyntax 1:\r\n WHOAMI [/UPN | /FQDN | /LOGONID]\r\n\r\nSyntax 2:\r\n WHOAMI { [/USER] [/GROUPS] [/CLAIMS] [/PRIV] } [/FO format] [/NH]\r\n\r\nSyntax 3:\r\n WHOAMI /ALL [/FO format] [/NH]\r\n\r\nDescription:\r\n This utility can be used to get user name and group information\r\n along with the respective security identifiers (SID), claims,\r\n privileges, logon identifier (logon ID) for the current user\r\n on the local system. I.e. who is the current logged on user?\r\n If no switch is specified, tool displays the user name in NTLM\r\n format (domain\\username).\r\n\r\nParameter List:\r\n /UPN Displays the user name in User Principal \r\n Name (UPN) format.\r\n\r\n /FQDN Displays the user name in Fully Qualified \r\n Distinguished Name (FQDN) format.\r\n\r\n /USER Displays information on the current user\r\n along with the security identifier (SID).\r\n\r\n /GROUPS Displays group membership for current user,\r\n type of account, security identifiers (SID)\r\n and attributes.\r\n\r\n /CLAIMS Displays claims for current user,\r\n including claim name, flags, type and values.\r\n\r\n /PRIV Displays security privileges of the current\r\n user.\r\n\r\n /LOGONID Displays the logon ID of the current user.\r\n\r\n /ALL Displays the current user name, groups \r\n belonged to along with the security \r\n identifiers (SID), claims and privileges for \r\n the current user access token.\r\n\r\n /FO format Specifies the output format to be displayed.\r\n Valid values are TABLE, LIST, CSV.\r\n Column headings are not displayed with CSV\r\n format. Default format is TABLE.\r\n\r\n /NH Specifies that the column header should not\r\n be displayed in the output. This is\r\n valid only for TABLE and CSV formats.\r\n\r\n /? Displays this help message.\r\n\r\nExamples:\r\n WHOAMI\r\n WHOAMI /UPN\r\n WHOAMI /FQDN \r\n WHOAMI /LOGONID\r\n WHOAMI /USER\r\n WHOAMI /USER /FO LIST\r\n WHOAMI /USER /FO CSV\r\n WHOAMI /GROUPS\r\n WHOAMI /GROUPS /FO CSV /NH\r\n WHOAMI /CLAIMS\r\n WHOAMI /CLAIMS /FO LIST\r\n WHOAMI /PRIV\r\n WHOAMI /PRIV /FO TABLE\r\n WHOAMI /USER /GROUPS\r\n WHOAMI /USER /GROUPS /CLAIMS /PRIV\r\n WHOAMI /ALL\r\n WHOAMI /ALL /FO LIST\r\n WHOAMI /ALL /FO CSV /NH\r\n WHOAMI /?\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\whoami.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "ERROR: Invalid argument/option - '--help'.\r\nType \"WHOAMI /?\" for usage.\r\n" }, "wiaacmgr.exe-C70D3C03ABE289C699D52D5C2F866FC9": { "file_name": "wiaacmgr.exe", "file_path": "C:\\Windows\\SysWOW64\\wiaacmgr.exe", "hash_md5": "C70D3C03ABE289C699D52D5C2F866FC9", "hash_sha1": "7E751752C3E44E8F718D9C5270923D50F3E64CF6", "hash_sha256": "90168783DBD9AC5CB2899297154B871FF50E218CD4C825FBB60668CAE4463144", "hash_sha384": "40E8A6C0D4E2F3648108DED1847DA881EDDB18914BFDCED00FD37460EB29E24ED60522F9765BCA906F8B5D6448A0DD87", "hash_sha512": "C6F7B837FD50230EC8E44D5F8778C46DCC689069CCE135C42EA6A7B7A2B1DBB49FE4C5414EAF747404E84DA858B415DB2855B9AC64A4A7A1DB93D1ACC572753D", "hash_ssdeep": "1536:ckXDC6ACeTd4446jzzzpyp+UmBo6AtfP/:cU7AFdPjzXpymBo6k/", "hash_imp": "1A1951DF009B708FE4E471176F4F890E", "hash_pesha1": "66D3CF2EA02AFE46F8BCAC0DF052DB9AE25EAB4A", "hash_pe256": "4415E5C5FA788DB461557CA4FBAC44AC14EC19075B677C47AAA632363AF0AA72", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Picture Acquisition Wizard", "meta_original_filename": "WIAACMGR.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/90168783dbd9ac5cb2899297154b871ff50e218cd4c825fbb60668cae4463144/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_5706558cc25cc83b": "File", "(R-D) C:\\Windows\\System32\\en-US\\wiaacmgr.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\scansetting.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1204": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\wiaacmgr.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "win32calc.exe-60390523A3CDFA370EC3B8EA22036827": { "file_name": "win32calc.exe", "file_path": "C:\\Windows\\SysWOW64\\win32calc.exe", "hash_md5": "60390523A3CDFA370EC3B8EA22036827", "hash_sha1": "36DFA2AAB49F1E9F430DA4568AD4AD6D716378D4", "hash_sha256": "4E0B5ADE22D9EFABA02635C2BACBDB942AECDBA9B017927B33900409712D852B", "hash_sha384": "4D872EEB38D05F65401CCC8C419F6E2A41EB003E3567BC8708E8094ED3C58A14D7C1B46E260D486C8CEF9C180E62BBBE", "hash_sha512": "0A690E9F06CCDBDF1B031EF890771D9970D6BCF828BBF77319864E1E03AC65CAF9DF7D1CDEF45F3BEB15198A175E9AF3BBF5D4C109BFB9A0340B3F9433CB70FD", "hash_ssdeep": "12288:7p5hDukHizi17kutVZuzs/Xj9TNoPph4l65HeeN7c6OhV:7pviziVkutVZuzs/Xj9aBql6Nehh", "hash_imp": "550229B8CA9B100CBA0AB24067A88FEC", "hash_pesha1": "273BF5FCBA6D5B77A17F8C6F92A81F2F6ADD6660", "hash_pe256": "57C6ED542FEAF8083D6DD56DDA068D7F53A25202C5CEA62B47CFFD9DFB18D5D7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Calculator", "meta_original_filename": "WIN32CALC.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.771 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.771", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/4e0b5ade22d9efaba02635c2bacbdb942aecdba9b017927b33900409712d852b/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_5706558cc25cc83b": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\win32calc.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\win32calc.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Calculator" }, "Windows.Media.BackgroundPlayback.exe-7E9CE7F806505ABB9C7B07C69F39DC17": { "file_name": "Windows.Media.BackgroundPlayback.exe", "file_path": "C:\\Windows\\SysWOW64\\Windows.Media.BackgroundPlayback.exe", "hash_md5": "7E9CE7F806505ABB9C7B07C69F39DC17", "hash_sha1": "B5B51C5C914B6F04AD689655E633D41E97C0FAAA", "hash_sha256": "3702851830630FA50AEAC479253B244781143C7E1419E4FB5014AE8963EC457A", "hash_sha384": "EA9C7A2B90E63879C5353FC24B38AC2E1ECEEDD47830CCA9D9535FCA7BFC5F4D0CBB2F3E6EC7B527CCF59DAF825697DC", "hash_sha512": "E1C24AAEE90845A1816C28FD4A5C662F232C6CFC4926EC54C614A2AC2B47920910BFE6825CC2564C4FFAA77B1153BE51A4D4656DDE3EF6DC76ACB784CC8D6BDD", "hash_ssdeep": "192:aACMfqJvX0ofTOrOkvOTSRM3qO4JD1hfX0H8WZ5WpxJE:8sqDgOkvOJwaH8WZ5WpxG", "hash_imp": "0378B911CA4B411C79AC0F70E4868A4E", "hash_pesha1": "D789FDE495B59B3F561242DD08430B83DBDB67B1", "hash_pe256": "B430C43A02EF9E2B7C5AE79D32D5CBAA213E4976906ACD81490F46B17C85F03D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Playback EXE", "meta_original_filename": "Windows.Media.Playback.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/3702851830630fa50aeac479253b244781143c7e1419e4fb5014ae8963ec457a/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Windows.Media.BackgroundPlayback.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "Windows.WARP.JITService.exe-F624D56D38A171191622EE186FA2B89F": { "file_name": "Windows.WARP.JITService.exe", "file_path": "C:\\Windows\\SysWOW64\\Windows.WARP.JITService.exe", "hash_md5": "F624D56D38A171191622EE186FA2B89F", "hash_sha1": "26A7ADBC043E67AD5ECF7AFB6221CCF562A81E84", "hash_sha256": "81B5BBAA76411A13187E12D7A4D7671A3479E328ED525C45583D856AB709C506", "hash_sha384": "DD93EA33A581A1559D527C3D17DA6F0E88EDC488D8D8A49D81E6BCB6FAB6A667E0E7E7334327A8D1BF32A84C919A6BC5", "hash_sha512": "DBD548E3B65D6506B620100A3E66DCAA87A39F6B8BDB255E7174332A6E8F1C78743A01167E737A8E7F659120D3FD4F6C269A9A214AA3D448AA991DE73B661CB4", "hash_ssdeep": "768:d1ueFgasxVGOc4bya7sS2l1idxFEf3j7:dQ4sxVca7mLWxF6P", "hash_imp": "245F746FCD1E900EBC5FD6E74CE04329", "hash_pesha1": "DA5E7DEA60C63CD09065B5010D868EB85668EBAA", "hash_pe256": "BA49B3D2AA3F6204F0AB586A42DE3207206C7B393F579F597C78BA3859A04C12", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/81b5bbaa76411a13187e12d7a4d7671a3479e328ed525c45583d856ab709c506/detection/" }, "winrs.exe-9688FF3435B814269DBE46079F175C79": { "file_name": "winrs.exe", "file_path": "C:\\Windows\\SysWOW64\\winrs.exe", "hash_md5": "9688FF3435B814269DBE46079F175C79", "hash_sha1": "66129D29C3B8CF5CF1CAB12FE01F6787545A29CA", "hash_sha256": "02ABC26A1F1FB25CB24992BF62EEAB05B570E1310F64AAA1CB1433F7BA77B3BB", "hash_sha384": "4BDAFB3835EA4DB71E6061908BAEC4207D9C8182538ED22CA934AAA886255DD3BDA2D3FCC3D04666FBD9B04D90DE0F82", "hash_sha512": "24E6F857AC65A7879195EF01CE89B359AB0EE990DC4192AA4E231555DFB27E682DD884D2A6509F52861CCC95D68858D02D2CBBC07CC472E9440422C4BE9581C4", "hash_ssdeep": "768:CY4DQSNQYzTbfi3IWSl57UBcLoVtfR6HwDEMLkBJPokB9Km:CDDlQmz80575LmfAHaLkfPdl", "hash_imp": "F0EE307FE96339D2235693E095EC19FE", "hash_pesha1": "3BB5F05547AA076E337E99235F1BDA7B08429F14", "hash_pe256": "2DB18C80BA3C111E592CEFCDDD0ABD2335BED11AE954E75207279D55C54E08A0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "winrs", "meta_original_filename": "winrs.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/02abc26a1f1fb25cb24992bf62eeab05b570e1310f64aaa1cb1433f7ba77b3bb/detection/", "output": "For more information on a specific command, type HELP command-name\r\nASSOC Displays or modifies file extension associations.\r\nATTRIB Displays or changes file attributes.\r\nBREAK Sets or clears extended CTRL+C checking.\r\nBCDEDIT Sets properties in boot database to control boot loading.\r\nCACLS Displays or modifies access control lists (ACLs) of files.\r\nCALL Calls one batch program from another.\r\nCD Displays the name of or changes the current directory.\r\nCHCP Displays or sets the active code page number.\r\nCHDIR Displays the name of or changes the current directory.\r\nCHKDSK Checks a disk and displays a status report.\r\nCHKNTFS Displays or modifies the checking of disk at boot time.\r\nCLS Clears the screen.\r\nCMD Starts a new instance of the Windows command interpreter.\r\nCOLOR Sets the default console foreground and background colors.\r\nCOMP Compares the contents of two files or sets of files.\r\nCOMPACT Displays or alters the compression of files on NTFS partitions.\r\nCONVERT Converts FAT volumes to NTFS. You cannot convert the\r\n current drive.\r\nCOPY Copies one or more files to another location.\r\nDATE Displays or sets the date.\r\nDEL Deletes one or more files.\r\nDIR Displays a list of files and subdirectories in a directory.\r\nDISKPART Displays or configures Disk Partition properties.\r\nDOSKEY Edits command lines, recalls Windows commands, and \r\n creates macros.\r\nDRIVERQUERY Displays current device driver status and properties.\r\nECHO Displays messages, or turns command echoing on or off.\r\nENDLOCAL Ends localization of environment changes in a batch file.\r\nERASE Deletes one or more files.\r\nEXIT Quits the CMD.EXE program (command interpreter).\r\nFC Compares two files or sets of files, and displays the \r\n differences between them.\r\nFIND Searches for a text string in a file or files.\r\nFINDSTR Searches for strings in files.\r\nFOR Runs a specified command for each file in a set of files.\r\nFORMAT Formats a disk for use with Windows.\r\nFSUTIL Displays or configures the file system properties.\r\nFTYPE Displays or modifies file types used in file extension \r\n associations.\r\nGOTO Directs the Windows command interpreter to a labeled line in \r\n a batch program.\r\nGPRESULT Displays Group Policy information for machine or user.\r\nGRAFTABL Enables Windows to display an extended character set in \r\n graphics mode.\r\nHELP Provides Help information for Windows commands.\r\nICACLS Display, modify, backup, or restore ACLs for files and \r\n directories.\r\nIF Performs conditional processing in batch programs.\r\nLABEL Creates, changes, or deletes the volume label of a disk.\r\nMD Creates a directory.\r\nMKDIR Creates a directory.\r\nMKLINK Creates Symbolic Links and Hard Links\r\nMODE Configures a system device.\r\nMORE Displays output one screen at a time.\r\nMOVE Moves one or more files from one directory to another \r\n directory.\r\nOPENFILES Displays files opened by remote users for a file share.\r\nPATH Displays or sets a search path for executable files.\r\nPAUSE Suspends processing of a batch file and displays a message.\r\nPOPD Restores the previous value of the current directory saved by \r\n PUSHD.\r\nPRINT Prints a text file.\r\nPROMPT Changes the Windows command prompt.\r\nPUSHD Saves the current directory then changes it.\r\nRD Removes a directory.\r\nRECOVER Recovers readable information from a bad or defective disk.\r\nREM Records comments (remarks) in batch files or CONFIG.SYS.\r\nREN Renames a file or files.\r\nRENAME Renames a file or files.\r\nREPLACE Replaces files.\r\nRMDIR Removes a directory.\r\nROBOCOPY Advanced utility to copy files and directory trees\r\nSET Displays, sets, or removes Windows environment variables.\r\nSETLOCAL Begins localization of environment changes in a batch file.\r\nSC Displays or configures services (background processes).\r\nSCHTASKS Schedules commands and programs to run on a computer.\r\nSHIFT Shifts the position of replaceable parameters in batch files.\r\nSHUTDOWN Allows proper local or remote shutdown of machine.\r\nSORT Sorts input.\r\nSTART Starts a separate window to run a specified program or command.\r\nSUBST Associates a path with a drive letter.\r\nSYSTEMINFO Displays machine specific properties and configuration.\r\nTASKLIST Displays all currently running tasks including services.\r\nTASKKILL Kill or stop a running process or application.\r\nTIME Displays or sets the system time.\r\nTITLE Sets the window title for a CMD.EXE session.\r\nTREE Graphically displays the directory structure of a drive or \r\n path.\r\nTYPE Displays the contents of a text file.\r\nVER Displays the Windows version.\r\nVERIFY Tells Windows whether to verify that your files are written\r\n correctly to a disk.\r\nVOL Displays a disk volume label and serial number.\r\nXCOPY Copies files and directory trees.\r\nWMIC Displays WMI information inside interactive command shell.\r\n\r\nFor more information on tools see the command-line reference in the online help.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\winrs.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "Winrs.exe: Unrecognized switch \"--help\"\r\nUse \"winrs -?\" to obtain the usage information" }, "winrshost.exe-06044E3942AB103B96307187BBD1ED93": { "file_name": "winrshost.exe", "file_path": "C:\\Windows\\SysWOW64\\winrshost.exe", "hash_md5": "06044E3942AB103B96307187BBD1ED93", "hash_sha1": "459432B5421F14A0EDFC1586C1AB416A6F625BF6", "hash_sha256": "9572884598BDB3C1A4B7D2E0E1B6945ED62F4172221E468EF53AA5A25E809691", "hash_sha384": "B6C277416C47D1E94EE97E5237A6F8591A5509CA378BF2ECAE96DC8C62CE57D91C892E9F7A2C4A3055D330F39E1169D7", "hash_sha512": "8F087E5B3D6EB827784350C41687FAB96EA9B971B28FC902765697A5F7E60D02155C2A7393AAD28DE6F59D52E01C41602D15419F9DB49EBCD278D0E29299FD9C", "hash_ssdeep": "384:gAQKb0LRGc5stCMg2uVYmfmknTTW3ap/Gh1WsnEW:ZTb0Yc5soMg2kHaKp/GhP", "hash_imp": "84E8D0734E85FF07FA62BE51BF7504A9", "hash_pesha1": "816C692BA83D9EE210022512A47CBB65E612C18F", "hash_pe256": "4AF30F1E5BBA5321F0FC307CB17C215EED2561F44627F651BDF406D17B3F50CD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host Process for WinRM's Remote Shell plugin", "meta_original_filename": "winrshost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/9572884598bdb3c1a4b7d2e0e1b6945ed62f4172221e468ef53aa5a25e809691/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECD40": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\winrshost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "winver.exe-D0CD7E799CC087F0F3630AF45F4CAB5A": { "file_name": "winver.exe", "file_path": "C:\\Windows\\SysWOW64\\winver.exe", "hash_md5": "D0CD7E799CC087F0F3630AF45F4CAB5A", "hash_sha1": "DF90A5AEA9FC189E55C5D9176F648A537CEF79DD", "hash_sha256": "97C23B8888FFE8F4A9D9A0DE8EDA27CBE029049CF07E1164C2E79C3623139E42", "hash_sha384": "46DE14EAD7FDCD59BE9C68E407C37B99FD4351E1E807BF9CE7A88B8FB636B4159D62623F404CCE7E70CEDA24907E1B06", "hash_sha512": "411DCB4E9D7D84CAC5F5145381D016AA04EFB0CDC9BE7A525AA4DED30B47412AB0ADEFBAB8F617CF0BA3024C88DC4166D8CE6BFC7A444C6F64301270E0BFFF15", "hash_ssdeep": "768:AqVcU4yi+GSkVhWakkbB5eT905WGnUKxHUe7n8jKBFFptX/7wUXj1:AZyi+xakkn6oYY0ewiP82", "hash_imp": "6F6011B78CCFE72E1E21C99F70873A70", "hash_pesha1": "241A5898FF2784205BFA6A3CA7AD8AF92364AA39", "hash_pe256": "E66F859D2BF020BFFCD202C4B1E6417ABAA01447C7797B6C7DAA52FD3D84D501", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Version Reporter Applet", "meta_original_filename": "WINVER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/97c23b8888ffe8f4a9d9a0de8eda27cbe029049cf07e1164c2e79c3623139e42/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\winver.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\shell32.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\winver.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "About Windows" }, "wowreg32.exe-4806AEA6060A7D3809A6BBA3C523668B": { "file_name": "wowreg32.exe", "file_path": "C:\\Windows\\SysWOW64\\wowreg32.exe", "hash_md5": "4806AEA6060A7D3809A6BBA3C523668B", "hash_sha1": "A8C92B2ECB761A3F3F266FC28E7699FEEE3B5D2B", "hash_sha256": "EB9048606C0CE6BE9F82F0B6B62A977133A6C43459E3DC6417F941D591FAB2A8", "hash_sha384": "DC4B4674E207DBD3B5CEA513642EF9150D3CF4807C7CB3352A201F127BF6FC7DC0C810C0E8D11790B11DB5E3646ED376", "hash_sha512": "FE58FBECEB4FAE6D25E0BBE2C3873527D127E3D2960600A4FB8D57E1DDB275B5829B08DC56EC481DF3334AC0E7EF8233ED2152AB01B75D55ED23A251A389EF66", "hash_ssdeep": "192:H6FOum/QeKudI7IUtTb/QDFQmQc6ynD4LtYE2m4XxWgxZjHW3:Zg7bRbqQhA4JarBWgxZjHW3", "hash_imp": "8B8A143002F5FC8DCA7CC0A0DC979CEF", "hash_pesha1": "540B95BAE84186B3242CBD8931882FCED28BFB60", "hash_pe256": "C899B0E6B19FDAB1FC0F1E1437434FFABB20C0F636C2F710C7806AA99EC8C223", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "SetupAPI 32-bit Surrogate", "meta_original_filename": "WOWREG32.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/eb9048606c0ce6be9f82f0b6b62a977133a6c43459e3dc6417f941d591fab2a8/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wowreg32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WPDShextAutoplay.exe-1D5CDAEBCC04D352776C0005C4C76EB6": { "file_name": "WPDShextAutoplay.exe", "file_path": "C:\\Windows\\SysWOW64\\WPDShextAutoplay.exe", "hash_md5": "1D5CDAEBCC04D352776C0005C4C76EB6", "hash_sha1": "03EDD0A896E1999DEE3F76D2B2A23CDD7E123C47", "hash_sha256": "0613C8CD54FDFB88868A7A8A379FDE648DAB69425B53F77F2B1B2C996CB8DB85", "hash_sha384": "DD1D4D85EC0767B4422EC5A96B48B053F5396D1159C638F6170D30CB6F49D39D1A393485497547EE668F7DA9BF78414E", "hash_sha512": "164776991823C27DBBD1ECFA129E175F1F840E92473E680E03AEED6F97ED2EBCC796271B83AD74DFC5B389BC768B47B16CC37A476930103B788CC93DEBD7E463", "hash_ssdeep": "384:9nH2DS09JCEaMVyrHmxmSadjJQMDmNAyOk0Cp0MqfdULDWbnWj4csR:9nH+9xVyrGxmxVgnqfdUQBcs", "hash_imp": "C26FA98179B5A82641E3913A19CB08AF", "hash_pesha1": "31A8DD37500C1E619DEC64357E69B312A4C6ECAC", "hash_pe256": "4F7560A66213BE46CE0FFC506590F445A633A8AF3A0FEDB4B2BBCB0D2FECC8D7", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Portable Device Shell Extension Autoplay Handler", "meta_original_filename": "WpdShExtAutoplay.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/0613c8cd54fdfb88868a7a8a379fde648dab69425b53f77f2b1b2c996cb8db85/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\WPDShextAutoplay.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC1164": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\WPDShextAutoplay.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "write.exe-55A288C36EBDFBA8F977307A8A2619D1": { "file_name": "write.exe", "file_path": "C:\\Windows\\SysWOW64\\write.exe", "hash_md5": "55A288C36EBDFBA8F977307A8A2619D1", "hash_sha1": "AB81F1C68543B79DA7B238DA39EB1A5149D751DF", "hash_sha256": "0FFCC65F70860F3961694BA64DBE7D69B09B5F0D6EB095DFF8349D6B2F1F0E96", "hash_sha384": "058FFB6E4F76DA5EE7F4A6BB46B810C10DEFEFBBDB7DB3F33846F30371B25D768FB521A98247D5FEE3B6638919D20320", "hash_sha512": "0AF74257FACA6B86DB29756E9895D85066867B5B507B9983C4D24A568C9E38A7CD8772350D3104123932E5AEDCB31FE00DBFD79E2A850D14FA820411A2BFE2AE", "hash_ssdeep": "192:y8bV0AQb/4HTbkqM6tmZPuxu/0WhOWIwN:yrpbwHTQf2+mxu/0WhOW/", "hash_imp": "B05C7142E6016FF931CDC4142BE82084", "hash_pesha1": "1A3B38BA2DDA5D4F0B18548A7235CB16785397F1", "hash_pe256": "B51996AE78FD0AA264B56BD979511DB883E886E96056E27EFC2CDFCF79416D0A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Write", "meta_original_filename": "write", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/0ffcc65f70860f3961694ba64dbe7d69b09b5f0d6eb095dff8349d6b2f1f0e96/detection/", "children": "wordpad.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\write.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wscript.exe-F2748908C6B873CB1970DF4C07223E72": { "file_name": "wscript.exe", "file_path": "C:\\Windows\\SysWOW64\\wscript.exe", "hash_md5": "F2748908C6B873CB1970DF4C07223E72", "hash_sha1": "5D7F2AFD2FF69D379B69DD94033B51EC537E8E52", "hash_sha256": "0FBB4F848D9FB14D7BF81B0454203810869C527C3435E8747A2213DD86F8129A", "hash_sha384": "128234C6B21A190B4E03ADEF4B33D73CA983AFB3DA764008032831DF3DE5B4EF966D6838544977F35FA07C585FE56A7B", "hash_sha512": "0E1B9102284131769BF960587D11F138948089130EE9366D643874A28013C573508AC2B65FE4BE5CD9608B5CDC4BE266A00CBDED6BA28560348B6E07B4D27E45", "hash_ssdeep": "3072:WunWMbPUr753/5oCjz1uJvXXrkpNUmGHruGTxt+G:nWMDUr7fclX7GoHrtT/", "hash_imp": "3602F3C025378F418F804C5D183603FE", "hash_pesha1": "6FED2A0A1CC9A1DB4705FE2A3F4F6B5289AA9F42", "hash_pe256": "3F6C650C991890B10829C6206EF6E58F34E3D1236E6C4FC584CC0E554A732057", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Based Script Host", "meta_original_filename": "wscript.exe", "meta_product_name": "Microsoft Windows Script Host", "meta_company_name": "Microsoft Corporation", "meta_file_version": "5.812.10240.16384", "meta_product_version": "5.812.10240.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/0fbb4f848d9fb14d7bf81b0454203810869c527c3435e8747a2213dd86f8129a/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\wscript.exe.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\wscript.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Script Host" }, "WSManHTTPConfig.exe-45D159A0E74A53762DF9948A66E1E40B": { "file_name": "WSManHTTPConfig.exe", "file_path": "C:\\Windows\\SysWOW64\\WSManHTTPConfig.exe", "hash_md5": "45D159A0E74A53762DF9948A66E1E40B", "hash_sha1": "D9D51A55C85E9329EBC4F5FF7687C096E35FF694", "hash_sha256": "AA19AB5F5C954583C46E2C4099A2765432C6CCCB5D20803167FCC1727AE5416C", "hash_sha384": "831B9C46A21C68BE899F7755FD6BD9271F830B36165EC4BFD4A99E6E3AC0FD21F2659E9575401368ED958E79699AD53C", "hash_sha512": "9D705E647325EB0F5162C5F0ECE52E3267F66A85CC50E7ECE79E90763E214E93BBC8681CE3A9F7216BBA9DDC8CF64E11511F1016615CD6C83A27B8C63213F151", "hash_ssdeep": "768:RjZPa/LdipG7U0KFtO2l948XZiIeDi//2GbO:hZPyUwEZiHDi/FbO", "hash_imp": "4C6861737F96AD89D00449DCA8039C8D", "hash_pesha1": "1D28B89CF6C2F567B028C456668BA6726E1A2F8D", "hash_pe256": "662B500056805850BF633524182464B8934BE2DD6C5D10F08472CD56696F5576", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WSMan HTTP Configuration File", "meta_original_filename": "WSManHTTPConfig.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.134 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.134", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/aa19ab5f5c954583c46e2c4099a2765432c6cccb5d20803167fcc1727ae5416c/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\WSManHTTPConfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "WSMan Generic Command ERROR: Unknown switch: --help\r\nWSMan Generic Command ERROR: Error in parsing input\r\n" }, "wsmprovhost.exe-6F2C7C4E86114D939A96EEB098E3A27C": { "file_name": "wsmprovhost.exe", "file_path": "C:\\Windows\\SysWOW64\\wsmprovhost.exe", "hash_md5": "6F2C7C4E86114D939A96EEB098E3A27C", "hash_sha1": "6F8F7E24F24BF1D911EBFB6C276CE5871A836FF4", "hash_sha256": "36A36855BED0F40D193F8DE0035C13C636C6CBD52E4F88759C4858FD0CDE08E3", "hash_sha384": "14B2DA8B70D43AB4D37846F9D9B535C153A8594647B290FFD7B6126216CF6925FB01CA2C992FF2FEE1ED1DB0C36489E3", "hash_sha512": "9D5CB891BFA21EA058F5021B98E4DDB4BA72AAA7562558815453014093D0111716523F2DDFF1EC09F90A5D89513720673996353157E5B2AE695466E39B4756F4", "hash_ssdeep": "384:RvbTjuromh33UjeUObqoqb4V7J5KDdPecvnSLXJMs2Fwmf2CSdZ9tn5TiGOaW7yT:pbTY5o4prgPecvSbE2CSdxnJi16Vr", "hash_imp": "0D771E3E9A15035B93E08ED3F8386DC4", "hash_pesha1": "98E96F9EA1685A7F361FBC1E4C66AD12E7215029", "hash_pe256": "DB4BB9923F3F722553AD14DA968134500F93CC87749DD6D02A3A631FD56743BC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Host process for WinRM plug-ins", "meta_original_filename": "wsmprovhost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/36a36855bed0f40d193f8de0035c13c636c6cbd52e4f88759c4858fd0cde08e3/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECF94": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\wsmprovhost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wusa.exe-6C81724C47077509C4CC874E34008FC3": { "file_name": "wusa.exe", "file_path": "C:\\Windows\\SysWOW64\\wusa.exe", "hash_md5": "6C81724C47077509C4CC874E34008FC3", "hash_sha1": "8927B37C0265394724D979D84EE1AA6E4F7D7E5A", "hash_sha256": "9A18550136D91FD0AF3D8D3E202A5A348DDEE9639498F2B5FC9630E83406D7E1", "hash_sha384": "D4BF20B3D3E3C3CB91DB85BEB54DF0F2AD2C4D0EE62F42CC949FA137E064244DF25F73C64B6515360AA778C5290C53C6", "hash_sha512": "7FC8E6A95BA3438F05A75DDA51BC125E2724A844EC91626360AC95585BAE7938A6E4A5D405A4C4B2B73B002F22DD310E2CD61D4F756EC09D0E2027CD2933B0E7", "hash_ssdeep": "6144:Kco8nRccME78lLeMeCWN8p09spxyN90vE:Kv8nRcAYdveCyMy90", "hash_imp": "43545885005F51C762261EDCD235042B", "hash_pesha1": "F723B6135D6E62967BB6018D6F3AC0A274A9B79F", "hash_pe256": "CA417504B971C5BDAA4BAFB414C8D6ADDD1BB44A8F0C508D487418C9ADEB2BE1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Update Standalone Installer", "meta_original_filename": "wusa.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/9a18550136d91fd0af3d8d3e202a5a348ddee9639498f2b5fc9630e83406d7e1/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\wusa.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\wusa.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Update Standalone Installer" }, "WWAHost.exe-776EE69BF2955CE384816C8BCCC02D41": { "file_name": "WWAHost.exe", "file_path": "C:\\Windows\\SysWOW64\\WWAHost.exe", "hash_md5": "776EE69BF2955CE384816C8BCCC02D41", "hash_sha1": "63971986949033109FE035BF9ACA1149367A6A49", "hash_sha256": "40BF206F8E55F3C01A920EE3932984E01517A6E7196BD2C57E12E413DA688448", "hash_sha384": "2BE11F7A5EDAAFDB43E045664DD4C29F79BA81247CB35D4E1F88BF4C091D4D403E55A272A78EE04B45A95B0E16FBB669", "hash_sha512": "B97AF8DA9B503CC3A19982F7FD98B13F4897A3AC3DEC4AE9CECA017119B39C65C878C0B02E737988A5D69629C5BF663D68FE456BAA48ECA0A76CF19663D3D26C", "hash_ssdeep": "12288:N0jLUorSvvHBLEGomLGLYLpLbLyKLgLSLqLlL6LvLOYeayWnv4ndboNoIozoMoXe:tvhkGjng9Ni5mvRb3g97zm", "hash_imp": "F9075D7FBE974B788215742C7A038E16", "hash_pesha1": "591335F37DB9BC8B0D06BED99E104D69A2D4261D", "hash_pe256": "C2DC29CB81C084545ACC3166A55D7C03A08FD828CFC156B25A7EDF0C92D2CBC6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft WWA Host", "meta_original_filename": "WWAHost.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/40bf206f8e55f3c01a920ee3932984e01517a6e7196bd2c57e12e413da688448/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\WWAHost.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "xcopy.exe-226EB744AF811DA693B08D79F52E5959": { "file_name": "xcopy.exe", "file_path": "C:\\Windows\\SysWOW64\\xcopy.exe", "hash_md5": "226EB744AF811DA693B08D79F52E5959", "hash_sha1": "F5C25B0801DB71F3F20AAE0D6CB16F4B74B060E6", "hash_sha256": "692C7A7A1A693AC5E49008292D2332CFA858C0AEBDC945B05068F51AF132C39B", "hash_sha384": "967FFA8392E8F31D8538EAFCEB9A330E2D802F310044A625768D8B96F7816E29821F08344FF020C4AF25C8C18C0789CE", "hash_sha512": "2966CD7DF4C127753395809928A5F4937F723C99C1BD624BE15224642151416EF4EBF27AB2338AC954C30DCA1915DA8EE4A24A9C8724C202B98F55BBC8CD4695", "hash_ssdeep": "768:000cnUoPee6EimPRDNg3al15ZduQhZE1RncdJEl7E:000OUnX2RDpVZAQhZoncdJk7E", "hash_imp": "052E5CB28770B24801BD790AB30830F2", "hash_pesha1": "977D7977D921056D4F14BD76095414842B624C9C", "hash_pe256": "3CB9AE691B8C7CFB046468A133B866A504E42D7E6C24E58FD79A2C86E0F6E851", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extended Copy Utility", "meta_original_filename": "XCOPY.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/58", "filescan_vtlink": "https://www.virustotal.com/gui/file/692c7a7a1a693ac5e49008292d2332cfa858c0aebdc945b05068f51af132c39b/detection/", "output": "Copies files and directory trees.\r\n\r\nXCOPY source [destination] [/A | /M] [/D[:date]] [/P] [/S [/E]] [/V] [/W]\r\n [/C] [/I] [/Q] [/F] [/L] [/G] [/H] [/R] [/T] [/U]\r\n [/K] [/N] [/O] [/X] [/Y] [/-Y] [/Z] [/B] [/J]\r\n [/EXCLUDE:file1[+file2][+file3]...]\r\n\r\n source Specifies the file(s) to copy.\r\n destination Specifies the location and/or name of new files.\r\n /A Copies only files with the archive attribute set,\r\n doesn't change the attribute.\r\n /M Copies only files with the archive attribute set,\r\n turns off the archive attribute.\r\n /D:m-d-y Copies files changed on or after the specified date.\r\n If no date is given, copies only those files whose\r\n source time is newer than the destination time.\r\n /EXCLUDE:file1[+file2][+file3]...\r\n Specifies a list of files containing strings. Each string\r\n should be in a separate line in the files. When any of the\r\n strings match any part of the absolute path of the file to be\r\n copied, that file will be excluded from being copied. For\r\n example, specifying a string like \\obj\\ or .obj will exclude\r\n all files underneath the directory obj or all files with the\r\n .obj extension respectively.\r\n /P Prompts you before creating each destination file.\r\n /S Copies directories and subdirectories except empty ones.\r\n /E Copies directories and subdirectories, including empty ones.\r\n Same as /S /E. May be used to modify /T.\r\n /V Verifies the size of each new file.\r\n /W Prompts you to press a key before copying.\r\n /C Continues copying even if errors occur.\r\n /I If destination does not exist and copying more than one file,\r\n assumes that destination must be a directory.\r\n /Q Does not display file names while copying.\r\n /F Displays full source and destination file names while copying.\r\n /L Displays files that would be copied.\r\n /G Allows the copying of encrypted files to destination that does\r\n not support encryption.\r\n /H Copies hidden and system files also.\r\n /R Overwrites read-only files.\r\n /T Creates directory structure, but does not copy files. Does not\r\n include empty directories or subdirectories. /T /E includes\r\n empty directories and subdirectories.\r\n /U Copies only files that already exist in destination.\r\n /K Copies attributes. Normal Xcopy will reset read-only attributes.\r\n /N Copies using the generated short names.\r\n /O Copies file ownership and ACL information.\r\n /X Copies file audit settings (implies /O).\r\n /Y Suppresses prompting to confirm you want to overwrite an\r\n existing destination file.\r\n /-Y Causes prompting to confirm you want to overwrite an\r\n existing destination file.\r\n /Z Copies networked files in restartable mode.\r\n /B Copies the Symbolic Link itself versus the target of the link.\r\n /J Copies using unbuffered I/O. Recommended for very large files.\r\n\r\nThe switch /Y may be preset in the COPYCMD environment variable.\r\nThis may be overridden with /-Y on the command line.\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\xcopy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "error": "File cannot be copied onto itself\r\n" }, "xpsrchvw.exe-05D5149C549F9CC0960204773DF34753": { "file_name": "xpsrchvw.exe", "file_path": "C:\\Windows\\SysWOW64\\xpsrchvw.exe", "hash_md5": "05D5149C549F9CC0960204773DF34753", "hash_sha1": "0645775F25AB3606CB816701D9ECBF534CFB7105", "hash_sha256": "9D38288014250DD0703C1CBB71C8022DAED0998CA8F6691827214FC8258B64A2", "hash_sha384": "BDB3171E8A32362878D2ACCA695C5EAA8F6CD8471643B2EF1B1C0378E0937006AB30BFE0E20DD4151F0BA7B3E006817A", "hash_sha512": "07AD11D07EBCDF5A7A38B77DD7ABC03EB41E7002A9D02DCC2D3DF81F5960D8FA48390CD30ED96746FBB76ABF1538B3824203D251162D9C07F6F7BBA089A45D13", "hash_ssdeep": "98304:fTCvVfatZNjerWYCSW2ktI/v54+XsUMBDtaQMwb:rcaHNje6uktI/v54+XsURnw", "hash_imp": "F45E0A0251CB5F958CCCD3056C2C4849", "hash_pesha1": "18C34A7553D359203569888E61A45411D387104A", "hash_pe256": "606C15CD224A87C008BAD035DEF044E15E519AF9AAAB38229DA20037115AEAFA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "XPS Viewer", "meta_original_filename": "xpsrchvw.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_5706558cc25cc83b": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\xpsrchvw.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\SysWOW64": "File", "\\RPC Control\\DSECFA4": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Users\\user\\help": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_window_title": "XPS Viewer", "runtime_modules": [ "C:\\Windows\\SysWOW64\\xpsrchvw.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "xwizard.exe-759CF84292251AB50E1791CBC0C4E8C5": { "file_name": "xwizard.exe", "file_path": "C:\\Windows\\SysWOW64\\xwizard.exe", "hash_md5": "759CF84292251AB50E1791CBC0C4E8C5", "hash_sha1": "A84C351137B8DC905CE737E8154DBD5D5BE4502D", "hash_sha256": "5CE0B07DBC12F4F9263376047A7A2F269958DF61E1510AC3B817796410CC2B00", "hash_sha384": "99B1F1E16E2F3EFF43D8199F67856F54812DCF879E0603F718103C2009D2DF44615B898A26ECE0DF36B0B3BC9D11F20B", "hash_sha512": "5B3E21D3EC0AC145AEEBE03911D7673CAEEBE6D51BA14C5CEA8E41A69738D1D4B5CDB8ECEAEDD987E2AEDE69C537DF0E78CD5A34A84D586914BB794D9CA79833", "hash_ssdeep": "1536:HdR9GlZLXAKaDiTThDURDoq4OZZZLlCIibT:9R9GlZLcDi3hoRD68wbT", "hash_imp": "878B18532266618387DC445E265148DD", "hash_pesha1": "826B0F962B039B5A32E01D8F061F72F05CC93CD9", "hash_pe256": "43DA55D1F2997B0D9FF4231173DCA39263A5DD70A93F5A05C2B2D4DF1F2A939E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Extensible Wizards Host Process", "meta_original_filename": "xwizard.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/5ce0b07dbc12f4f9263376047a7a2f269958df61e1510ac3b817796410cc2b00/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\xwizard.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\xwizard.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "comrepl.exe-2736F52E6FB1261EE6DFC0294ECD4F20": { "file_name": "comrepl.exe", "file_path": "C:\\Windows\\SysWOW64\\com\\comrepl.exe", "hash_md5": "2736F52E6FB1261EE6DFC0294ECD4F20", "hash_sha1": "69DE515236B74FC26D96FD5D14E37B19D3CA6BC9", "hash_sha256": "F7ABCB1234F29423664862B279B57D1D160AE50C749C3FB6DEA786E8EC8BC7CE", "hash_sha384": "F6A077DF234F78B157E944A81D4B38BE3768F992601FB97FAE1B16DB84769AD0840690F84D58803F787488ECBFE8FB60", "hash_sha512": "8261352F42EBA78BFD855EEFA809255C0A46EF40709F1C7DF6592E5841A823DE234F5F87F76199EE3BBF304E570850A39A0745433DC55E31B24361B7C596584C", "hash_ssdeep": "384:1zRB0QUkwhOyEcEmim348ZrVW5VuoWdS:1z1Uk1s348k4S", "hash_imp": "A1C21D02B295775CA1385E51D5DB789D", "hash_pesha1": "1ABCE15EBA7A09CF39269D4390DF40EED5950B3B", "hash_pe256": "A5A7866244A443626BD2B97E67400A2FFA2A2D010B17C7DCE0762F65CF5C0660", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+ Server Replication", "meta_original_filename": "COMREPL.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/f7abcb1234f29423664862b279b57d1d160ae50c749c3fb6dea786e8ec8bc7ce/detection/", "output": "ERROR: WriteConsole failed = 00000001\r\r\nERROR: WriteConsole failed = 00000001\r\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\com\\comrepl.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "children": "powershell.exe" }, "MigRegDB.exe-23153EE9486A95E9ACD996D65DD9C01F": { "file_name": "MigRegDB.exe", "file_path": "C:\\Windows\\SysWOW64\\com\\MigRegDB.exe", "hash_md5": "23153EE9486A95E9ACD996D65DD9C01F", "hash_sha1": "6B75F7DA3442BA97C287BB183C5115BE7C4770EC", "hash_sha256": "D356B8786F34A59B80A1170FAD8E942172073E6C0F9F014DA4064E332AE1ACE9", "hash_sha384": "B108B81883EBAF313C90625263AD51D764EE797452F0D39C8793D784F6D86A93494817BCF81533404104AD0E333733CB", "hash_sha512": "1731F662319A8B953625E32699DC55F9213137FC2CB5D34DAC5889181CF2E5552618DEF3343995A0B0B572FA2285D566A7F6A78A41502F780BC04FFBEA059555", "hash_ssdeep": "192:vFSc3shHvjTqKpDZbURK4h3Mktm+4oWYwWYSi:g3qKbbeK4Sgd4oWYwWY", "hash_imp": "D09A6E719E5E2339B3631F455943742B", "hash_pesha1": "DF00CAEEA0AE347FECB3B3B691BFD93AFE88036C", "hash_pe256": "80F20C9283BF2B026CCEEFD885CD53279C82C668FEFB07F48824C66D6C08669D", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "COM+", "meta_original_filename": "MIGREGDB.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2001.12.10941.16384 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/d356b8786f34a59b80a1170fad8e942172073e6c0f9f014da4064e332ae1ace9/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\com\\MigRegDB.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "DismHost.exe-37EA3E07F35A490F68C38D2F08344E12": { "file_name": "DismHost.exe", "file_path": "C:\\Windows\\SysWOW64\\Dism\\DismHost.exe", "hash_md5": "37EA3E07F35A490F68C38D2F08344E12", "hash_sha1": "B072D5E40A79204D2EF585CF748897F72A5BF370", "hash_sha256": "EA7E7D5045D32C114C030E85FB03925690F2FFFE93C5EB56209292C3C1154A8C", "hash_sha384": "2AB770158B63105CF7897BA9C3A2320AD002C2162B007047084CCEF857BFDA2E5F101DF325B8178F4976C49BF9189832", "hash_sha512": "F239A7A5EE155526ADFD7E5616DFC4C06EF705C5EA7AE548D637238B1E58495B830496D3900FF6F33890C6371E5BA3284FB97F27B0514878D4FC18F34B52DF28", "hash_ssdeep": "3072:A2PBxNV0a6pEIChuGkkZbD1Vh6LVYofclw:A2NdAChulWbD1Vh6LC4ca", "hash_imp": "D73721430C20D31544AEA558B6ECAA47", "hash_pesha1": "260215D0899792E3AF2D45A4AB76D7B8CBFA2F82", "hash_pe256": "E8F64708C38E9487B69E275C71254726873D9F52D2CFEF6488C6C4EBD0A95A69", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Dism Host Servicing Process", "meta_original_filename": "DismHost.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1518 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1518", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "IEChooser.exe-F48C76118C5E130F77028A09331AC772": { "file_name": "IEChooser.exe", "file_path": "C:\\Windows\\SysWOW64\\F12\\IEChooser.exe", "hash_md5": "F48C76118C5E130F77028A09331AC772", "hash_sha1": "086BD4681F625FEFFE3007F0D46567E757A29E65", "hash_sha256": "91DF9F47F5B6F1D81BE0F79C48FCE1CDA78D4ACAD95E938A8FD71E279ECF16D2", "hash_sha384": "61BA36F0AE7F565E7DDBF8EDCA1DE81A25EA3C8FD9AAF3E445C40D734D7AB619B2EA816CC6424133869D13C316CD5369", "hash_sha512": "69F3E24CA95A33AF8F15FF7448BD97968AAE0ABCB6571472717111C3F0A8C588934E67BE0CFCD3E305A1F962B95BB7D7F929DE923265C5C282BD896682E8753E", "hash_ssdeep": "3072:e8LMy55LTbOF99NgKym9y49RFQ+1DIC0yI2L:HM0bOF99NgKVA0TDIC0y", "hash_imp": "E73013DD16FE5239F8CEE7A7AF4F5244", "hash_pesha1": "36B70380BD01FA45CC46C00BD3A7410BCA01129F", "hash_pe256": "9CE40B4A7CA9529658AE0ED638808ACF8A37B5B20B8B75D8C60D6C1E948CFBC4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "F12 Attach Chooser executable", "meta_original_filename": "F12Chooser.exe.mui", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/91df9f47f5b6f1d81be0f79c48fce1cda78d4acad95e938a8fd71e279ecf16d2/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\F12\\IEChooser.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "IMJPDCT.EXE-65FAC431BB52952E4B5A8AA568971DB4": { "file_name": "IMJPDCT.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\IMEJP\\IMJPDCT.EXE", "hash_md5": "65FAC431BB52952E4B5A8AA568971DB4", "hash_sha1": "FB59BB83C225F908F6DFC41ED7A376C2CD00E8EC", "hash_sha256": "7495A02851E926A30E479454CB22950E1CFC382FE030D21E590B59FC329D5227", "hash_sha384": "E0F1E6D0A3E6F9C508430C9FDF7AEBE983106740F0E88B05E987F24BEB28B78F6A52E048B91F648A0402FD8B9FAE5C51", "hash_sha512": "E1F5D67636678E201CE5ED9BC63E81755BBF156170423FE1D51A51BCEBBAB0AD8CB47763EB00A284A50C2EB1327814A638491F82FBA711E86230AB0B2EFDD083", "hash_ssdeep": "12288:/3FaC+9z/dFm0aFqk0W13IJRFYDL1HXdAp8qrTbC:vFK/jaFqk0u3IrF6L1HXdAp8qj", "hash_imp": "1CFDDD1DC5470FFE2E2E801B4D490B48", "hash_pesha1": "10218F2B251A48A305F1ECAB93343428A7FE10BD", "hash_pe256": "12A056B5CAB60C2D4FC70E1809AF6FC46CB086C2DE9F1543A9D9129A28A97C43", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imjpdct.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/7495a02851e926a30e479454cb22950e1cfc382fe030d21e590b59fc329d5227/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\RPC Control\\DSEC5D0": "Section", "\\Sessions\\2\\BaseNamedObjects\\SatoriKnlDict_MemoryDictionary_IMJP_15__M_S-1-5-21-4075667164-670084373-454571106-500": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\2\\BaseNamedObjects\\5d0HWNDInterface:1e0682": "Section", "\\Sessions\\2\\BaseNamedObjects\\5d0HWNDInterface:18069a": "Section", "\\Sessions\\2\\BaseNamedObjects\\5d0HWNDInterface:1f069e": "Section", "\\Sessions\\2\\BaseNamedObjects\\_IMJP_15_UD_FileMapping_{b4f0aa5b-77d3-486f-b999-53049e87159e}_M_S-1-5-21-4075667164-670084373-454571106-500": "Section", "\\Sessions\\2\\BaseNamedObjects\\c:_users_user_appdata_roaming_microsoft_ime_15.0_imejp_userdict_imjp15cu.dic_IMJP_15_UD_ManagementBlock_{8bbff7b9-ccde-414f-96ed-936990babd2d}_M_S-1-5-21-4075667164-670084373-454571106-500": "Section", "\\Sessions\\2\\BaseNamedObjects\\mem_c:_users_user_appdata_roaming_microsoft_ime_15.0_imejp_userdict_imjp15cu.dic_M_S-1-5-21-4075667164-670084373-454571106-50000041000": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\IMEJP\\IMJPDCT.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Add Word" }, "IMJPSET.EXE-B3013D8C001264B02C08156A08F989C5": { "file_name": "IMJPSET.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\IMEJP\\IMJPSET.EXE", "hash_md5": "B3013D8C001264B02C08156A08F989C5", "hash_sha1": "49D4C8EAA6350AE5274E469CB5C2F58CC24F502F", "hash_sha256": "B4420A7DC8E158E69D0C944CC719B9136599A7AC89CA6F4BCFCB0DD294623AEF", "hash_sha384": "E4BC2C231A6045CF44BB910D8455BFF50A41F6D3A01A0516A5CC6B0DA048B3AE5EB8A39CB24E111CBF12A9CE7FFFBDD9", "hash_sha512": "0887A9A4380C4B9A1931F56C08F977D4E5ECAF1439A81EDED5281BD1F9DBB6AFE1F9C733551C010832B815A85998A5C38A9B545330A4BE888032349B64B0184F", "hash_ssdeep": "3072:7FM+PLmZPTAWFwymJVx+YhFWncWyy6aYYH67IkK2NLPcV2zu:hMxLbFwymr0YhsncWyy66mIkCP", "hash_imp": "4F6F430AABCB71CD016D423E32E517E1", "hash_pesha1": "106F163909B9146CEC0A443F3119A7D00B26BB87", "hash_pe256": "00DE135E79EC09A558FD6DCD17FA13D8CB7FE619BF6FF818684B52FA0600DF40", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "IMJPSET.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/b4420a7dc8e158e69d0c944cc719b9136599a7ac89ca6f4bcfcb0dd294623aef/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\_IMJP_15_UD_FileMapping_{b4f0aa5b-77d3-486f-b999-53049e87159e}_M_S-1-5-21-4075667164-670084373-454571106-500": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\IMEJP\\IMJPSET.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Settings for Microsoft IME" }, "IMJPUEX.EXE-F25AFE5F7458838756F205E18A800A3B": { "file_name": "IMJPUEX.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\IMEJP\\IMJPUEX.EXE", "hash_md5": "F25AFE5F7458838756F205E18A800A3B", "hash_sha1": "3AFCA2D8818EB987209285C0FEB2BFB989B1B0E2", "hash_sha256": "ADD9B3F88E55F55403022C946B1C4A8D7EEF597C524E766BAA751689DB4890C0", "hash_sha384": "2C0600491652B014B8BE3539C6E2AFE5C540A91A435FB26DB2F0BD5DF35D5B8752CD093B6ED86DF5F853544D8CEEB66E", "hash_sha512": "4AD5104D4A68A4CFDD9361273E3737CD28A8B3C5F9E77D19001ACBCF0B9243F27B08C5ED2CAC89DB1EFD966D8BAC54FEC739744E1FF04FD6F4D1DD27F142A8A9", "hash_ssdeep": "1536:o+DLziEvQS6oKL6x8oe4noCneHY3GBG3cYH67nIWDK2NLPcrIei:o+vziEoS6ovx/e4okWY3kGMYH67IkK2T", "hash_imp": "8EDC9357F22ADF7DB8B30C9166C360A7", "hash_pesha1": "850250E3028355654D7D4224213A4B364177CAAB", "hash_pe256": "7D4C57162128948F3A1FFC3A4EF29D6F40BDED64076979C48CF6A7552CBD2AE9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imjpuex.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/add9b3f88e55f55403022c946b1c4a8d7eef597c524e766baa751689db4890c0/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\_IMJP_15_UD_FileMapping_{b4f0aa5b-77d3-486f-b999-53049e87159e}_M_S-1-5-21-4075667164-670084373-454571106-500": "Section", "(R-D) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a\\comctl32.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_3c26ab8c9470805a": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\IMEJP\\IMJPUEX.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Advanced Settings for Microsoft IME" }, "imjpuexc.exe-E6B634A758B746492BB895CAA7886C65": { "file_name": "imjpuexc.exe", "file_path": "C:\\Windows\\SysWOW64\\IME\\IMEJP\\imjpuexc.exe", "hash_md5": "E6B634A758B746492BB895CAA7886C65", "hash_sha1": "A7012E9B792CD529BC9F31521762299CF0DEE831", "hash_sha256": "CCF5768E6A6E2D9C263DA61344D5348828B81DED7BD5135BF2B0C3A94BF7505A", "hash_sha384": "FD6B9A0347E2C982716533987EC0202268C4C43A16A7CAC75ECE0B3DCDE827CD86CCD57B3DD5DDAC00E7FE75935B0F52", "hash_sha512": "A82B2E1EB3029D38F72D94591BC1785575AEC1D6567F029C446029BABE4620DB1F5C32B9EC21A621B99BC7802F6B05F48713443FC6F3A0C0CA630F2B736CDEAF", "hash_ssdeep": "6144:uwgA+cttm94e5NIrnKXiqc5cY5OMS8gRTelaOrQTr3t7qs:uwgAHttm9X5OrGj3C0xr3R3", "hash_imp": "F200FB2F6E61D796EB8C963CED7E6E1F", "hash_pesha1": "8DA69A09CF29927271B82DBDFC6E0E426B98CEF7", "hash_pe256": "A10B9A2B3533A8C8040B07AC6CECA4EDC08C3FD0295810DEC9C0A89DDEFEE4F2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imjpuexc.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/ccf5768e6a6e2d9c263da61344d5348828b81ded7bd5135bf2b0c3a94bf7505a/detection/", "output": "Microsoft IME Property Command Line Tool (10.0.17763.1075)\r\nCopyright (c) Microsoft Corporation. All rights reserved.\r\n\r\nThe Syntax of this command is:\r\n\r\n IMJPUEXC HELP command\r\n\r\n Commands available are:\r\n \r\nIMJPUEXC ADDSYSDICT\t\tIMJPUEXC CHECKSYSDICT \r\nIMJPUEXC REMOVESYSDICT\t\tIMJPUEXC SETKANAINPUT \r\nIMJPUEXC GETKANAINPUT\t\tIMJPUEXC SETCUSTOMDICTPATH \r\nIMJPUEXC GETCUSTOMDICTPATH\tIMJPUEXC FIXCUSTOMDICT \r\nIMJPUEXC CODEAREAFORCONVERT\tIMJPUEXC SETOKURIGANAOPTION \r\nIMJPUEXC GETOKURIGANAOPTION\tIMJPUEXC SETKEYTEMPLATE \r\nIMJPUEXC SETKUTOUTEN\t\tIMJPUEXC RESET \r\nIMJPUEXC LOADAUTOTUNEDATA\tIMJPUEXC SAVEAUTOTUNEDATA \r\nIMJPUEXC REMOVEAUTOTUNEDATA\tIMJPUEXC SETFILTERDICT \r\nIMJPUEXC GETFILTERDICT\t\tIMJPUEXC REMOVEFILTERDICT\r\n" }, "IMTCLNWZ.EXE-8D216361F9E7024817739462D25FF190": { "file_name": "IMTCLNWZ.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\IMETC\\IMTCLNWZ.EXE", "hash_md5": "8D216361F9E7024817739462D25FF190", "hash_sha1": "785112A65BBCCD35FE22CA364C592ED2DB7A5372", "hash_sha256": "7ABFA126146C6C2D134529B9E8813FD97BB1C5562362FC47E66790F31A72B9D4", "hash_sha384": "62F8DAA8CEB786C828E8687A9F01AC9CF0B780396F8BA60A03E752AD3E489E0CC38BB1E999522BD7165CE1B639F9F9EA", "hash_sha512": "E9AD34AB278470F80A570193225D783C495A09DF18811730429CA7FDB26C3B56F97FB92279F84452C0AA8C83968EDB0197178715CBE9C960AE36856CC268AFF4", "hash_ssdeep": "3072:1+qm3EKu6acOD4JMK8m05CVtUo+siiWNqcH:1f0EKZu5m05CtUhsiNwcH", "hash_imp": "5D7B199BBE6443B3EFD7B4403BB617C2", "hash_pesha1": "F551E5D44D3F6D90AF60386AB77C75C6606C4E33", "hash_pe256": "16466EB0F4C8B2C793A850E8CB34FF09FC4E2D87DDE258AA22E289128ABDE7CC", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IMTCLNWZ.exe", "meta_original_filename": "IMTCLNWZ.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/7abfa126146c6c2d134529b9e8813fd97bb1c5562362fc47e66790f31a72b9d4/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_b4b635d36e735c2c": "File", "\\Windows\\Theme966197582": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\IMETC\\IMTCLNWZ.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "ANSI" }, "IMTCPROP.exe-03A7527713DFDC68221A62DD583341E7": { "file_name": "IMTCPROP.exe", "file_path": "C:\\Windows\\SysWOW64\\IME\\IMETC\\IMTCPROP.exe", "hash_md5": "03A7527713DFDC68221A62DD583341E7", "hash_sha1": "51EF0A74B3B4D5C827EF635A01A2FD429D92CF43", "hash_sha256": "40773A1B9C0B69CFEDBAADD7FCD8356B9D98C019CE76FC620CF35C148E956055", "hash_sha384": "0B0D42D9EDFFB109471B76AB800477BB5FCA216AA06858F88AEA475969E2CD86CA2820BC3509D3600F6D65E0393901B1", "hash_sha512": "7DA4FD9A2E86AE8E13D704604495539D281BC77BCF404B142F75195DE7BE2AB34F71237B4F4E9FC16005EEE90CC5782E386ECA7F7AB4027DD96D28AB6D2E47BA", "hash_ssdeep": "6144:7GijhMDTG5k/WCIPREiiejINmKKRiT7fJXCp:7Gire/WCIPRE7KwBCp", "hash_imp": "922A2D0EAA6DA5640AD5CC27428EE8A5", "hash_pesha1": "67C0D092F8EEDBAE4C4CCC067D20AA3F3DBADA3A", "hash_pe256": "2C280BAC429430A441D8C8D1CACD7EF489635739B177C6FBD77E28D540E22299", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IMTCPROP.exe", "meta_original_filename": "IMTCPROP.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/40773a1b9c0b69cfedbaadd7fcd8356b9d98c019ce76fc620cf35c148e956055/detection/", "children": "powershell.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\IMETC\\IMTCPROP.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Microsoft Bopomofo" }, "IMCCPHR.exe-5F460128535875F3B86AE6B7D9AB39F4": { "file_name": "IMCCPHR.exe", "file_path": "C:\\Windows\\SysWOW64\\IME\\shared\\IMCCPHR.exe", "hash_md5": "5F460128535875F3B86AE6B7D9AB39F4", "hash_sha1": "8D8EAE963BF9426E31B6091AED4CA3E934536913", "hash_sha256": "0AF80B99555749B2A43EF6480826F99B03F64A4B5073AA9C13A7056C163FCB0E", "hash_sha384": "D48462C19BF198A9FFD012910B14B65BB967279486F69FB737E96396329941CD48E284AFB18BC24883D1A5D8E8B822D2", "hash_sha512": "1ECD84E4550B554BE52695E9E2A6945731FEF71AB9E9DC9A78A9C27F1B0389E75CCC0F293AFA82E319D83DB59623895BF37F23337810A0A98877F96C010FF3A7", "hash_ssdeep": "6144:Vxo8/rDRDL0q7UVt6F/Sg5BxyOLvr8SjOj95qOlx8uSXmCPwP6k+kc8DZ5n4:VxNvWtSBxyWvr8SjOBSuSXmH6k+kcuv", "hash_imp": "1B0C9B064E59080F51121A478713F25A", "hash_pesha1": "2D411776CF888FB10A0C5D582239B6A55AC3A2DC", "hash_pe256": "961DE8B55C048A8B24E736FE0408E189EE665CE260ECA3D828BB6324E851FCBE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IMCCPHR.exe", "meta_original_filename": "IMCCPHR.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/0af80b99555749b2a43ef6480826f99b03f64a4b5073aa9c13a7056c163fcb0e/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\shared\\IMCCPHR.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "User-defined Phrase Tool for Microsoft Pinyin IME" }, "imecfmui.exe-C0C05DDCFB5489B02F27886C773B6EC2": { "file_name": "imecfmui.exe", "file_path": "C:\\Windows\\SysWOW64\\IME\\shared\\imecfmui.exe", "hash_md5": "C0C05DDCFB5489B02F27886C773B6EC2", "hash_sha1": "08E584C4B43527B10998DBF85967A8AE45AB4F06", "hash_sha256": "1A738F2F470DC27C3A32314895328A847B6AFE27BC6524D01727514C868A45A0", "hash_sha384": "2AE6324A0D484F3BCDFF907B2DC3F190625DE9BB14085392BBFC2F4990B13E7E4AE117DA663858BCEE805CF8EF87398E", "hash_sha512": "11D0A0BC87722A7414391E6F446CA342D75FC8D8A4995B6C747F9723A731828EC6057E30178EB0AA687D301AED3F0835A524F1C8CC74B04D66241DC5E0CDA466", "hash_ssdeep": "6144:pYOlmU1ZKkl4VT1yD+3t7LQcs/P/mn1V3CzQZgBk8SK0QO:pYOlmULK/14+mcs/P/mnvAS5", "hash_imp": "2D39A6D57D3B4041AEECD037739B6951", "hash_pesha1": "A68FCE4AF4B4FB3C97D1DBB7FE44ACBF3CAFA69B", "hash_pe256": "9EC66D6E1ECEBE49EC2B3C687CEE01849D22D53A0BAB1AB4F43B087953226EE0", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "imecfmui.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/1a738f2f470dc27c3a32314895328a847b6afe27bc6524d01727514c868a45a0/detection/" }, "IMEPADSV.EXE-B48A520DC5BB6B97E81849B9AA55692C": { "file_name": "IMEPADSV.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\shared\\IMEPADSV.EXE", "hash_md5": "B48A520DC5BB6B97E81849B9AA55692C", "hash_sha1": "6AB370EAD3E40E2EB53761C010E68D4B264AE855", "hash_sha256": "60C213702C2DE2C624DC1171748AFFAA6A948114A4B9BAE1E59067C0F650FBB9", "hash_sha384": "D987B459AA797820CFFA9D3D1AE7A3985FF2AC6F3C2BA0FF66C87B14856E58A5ACDD112F388BCCB730B072A7EAEDC106", "hash_sha512": "1DD4DC823B0E3E32F4878DE2748E8DF9DECC0F1F77849E6BA62F08F51617F0F2E2EEB4D19F105E51A3FD20533F5B76351D0E640D90D0170D42A303A510D1396B", "hash_ssdeep": "6144:P5wo3arm74fx1h5GwwldmLmMSZlbbUz13:xwo3ay74fz3DwldONiK", "hash_imp": "DBD22BB5C8E43B5CF495BCD15E726C8B", "hash_pesha1": "607C0BC19F22E56E55ACA028ABF32B8F8C26C819", "hash_pe256": "44A22C71D690E0E868C0F88827AB96B1FB85F80AF4BEE90593F53F262F26EABA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME", "meta_original_filename": "Microsoft IME", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/60c213702c2de2c624dc1171748affaa6a948114a4b9bae1e59067c0f650fbb9/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\shared\\IMEPADSV.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "IMESEARCH.EXE-93141C19451BA23CA72B66D9F001E909": { "file_name": "IMESEARCH.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\shared\\IMESEARCH.EXE", "hash_md5": "93141C19451BA23CA72B66D9F001E909", "hash_sha1": "587E14E9110C43CDAD92B5E7CE42C4CDAA0DCA40", "hash_sha256": "D0AE970CD194DF10DDE021DA975554B939E9AF85ADFFF46BAE6CF1D63F06C3C9", "hash_sha384": "B5E0FC185D276931790BD4743A00B147FE141937D5C55103727AD2F9FE2108DE1E84C171AD37F7F878B375D1229ACD9E", "hash_sha512": "84F44F5AA02A269D3260560873C7F13CAB5E34923D7AB2CAA98F183A136853A251644096E24ACE8DD4F3BDB6E1A3F9D04847E02E1D3A4A564D5551F504467549", "hash_ssdeep": "3072:Mi+9/GBa/KvfFYVQJKIAEaexgkCUWI0kPl:MiU+BaI+gKI1aeikCPI0e", "hash_imp": "7264C57C658C339A2C008A402DC9BAC4", "hash_pesha1": "F5EA18AAE73D2F0E052A3914B1213A60C422B9E8", "hash_pe256": "E961F83CFE2AECECEFCF00C79926825EEEA621976981789193642E881770F2DA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "IME search module", "meta_original_filename": "imesearch.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/d0ae970cd194df10dde021da975554b939e9af85adfff46bae6cf1d63f06c3c9/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\msxml6r.dll.mui": "File", "(R-D) C:\\Windows\\System32\\netmsg.dll": "File", "(R-D) C:\\Windows\\SysWOW64\\en-US\\netmsg.dll.mui": "File", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\shared\\IMESEARCH.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Microsoft IME Search Provider" }, "IMEWDBLD.EXE-0984D217E10D11B2DBB8CCD47CDF36BD": { "file_name": "IMEWDBLD.EXE", "file_path": "C:\\Windows\\SysWOW64\\IME\\shared\\IMEWDBLD.EXE", "hash_md5": "0984D217E10D11B2DBB8CCD47CDF36BD", "hash_sha1": "6BEBA2522259A3D06D21BA7B051C10F5BD42AD57", "hash_sha256": "C6CF94EE76F288CF59EDEBA4440CEDF08264EE1EA6F077DF654A0E9C5149F491", "hash_sha384": "B2BED978453E382510491B05274AD0759931273EB4151D6815BF3A413EF62872858882B2D710B985851CC6279165C9A8", "hash_sha512": "885060FBC753C4CE02BDF46671C70BDBA74E75584B14C5CC0826F3E184BA3ABB0FA279854121F9C5A7A6B75E64051DB57A38F88833B3A42530619A1FF11DA59A", "hash_ssdeep": "6144:sI9YzjicQ9utidKrVvI9p+hOHOty/sLRW3YolFqVQ7Gs/UEVTppNX+:rYzGcAGidKrVvI9p+MHOU/003FsQ7GsT", "hash_imp": "85CED23AC51CD18BBAAFE23E9D922D75", "hash_pesha1": "7BEEB221CD4C6AEB5536A18B258AF9D56693E715", "hash_pe256": "06CAFF4A8699D8EBED8CF7A0653D452AE3FCC5232E968CB7BE55E6B3C70F2BD9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft IME Open Extended Dictionary Module", "meta_original_filename": "imewdbld.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "Language Neutral", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/c6cf94ee76f288cf59edeba4440cedf08264ee1ea6f077df654a0e9c5149f491/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\IME\\shared\\IMEWDBLD.EXE", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Microsoft IME Open Extended Dictionary Error" }, "setup.exe-D3C5EB399AB4522ABF662EB72C23DB9B": { "file_name": "setup.exe", "file_path": "C:\\Windows\\SysWOW64\\InstallShield\\setup.exe", "hash_md5": "D3C5EB399AB4522ABF662EB72C23DB9B", "hash_sha1": "EF342E654624034D3A363D8EE0F62B0BA3141A95", "hash_sha256": "3F14C822BD440FEC8458FD11E950315E3D784908629B301526A57A3A623BF70C", "hash_sha384": "837EB427DD3E046D99C8B3E6ADE4FE4F583EB2793DF4331C703D627E781F01B2087E15E5976930B1038D1C1F028FA8C1", "hash_sha512": "4BAB306A87E9EF348D2C2F7051AF3E9ADC2BA0AADA6895CE3370DEF83E2A0A657E9DA9A8F9422093D1C274BFF9DDB0E52C9B7FE0D6D6FDAA85545DBDB2B2EE7B", "hash_ssdeep": "1536:I8wNfktLYUqSfzC8wATsq3CRJMdzzOi3d0eFKg:I80ct8dSfmXosgCRJMdfO6FKg", "hash_imp": "09B39D9CC248E77D59A084898ED73E6C", "hash_pesha1": "D759828F7F9C3CC9BAF19CD188D8A4F990AB2094", "hash_pe256": "D71B72FDAFADA48378D8F5E63A1B65A6EB16D8AFCDE65433C3B7FD7E25036933", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "32-bit Setup Launcher", "meta_product_name": "InstallShield", "meta_company_name": "InstallShield Software Corporation", "meta_file_version": "5, 54, 001, 0", "meta_product_version": "5, 54", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 1990-2000 InstallShield Software Corporation, Phone: (847) 240-9111", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/3f14c822bd440fec8458fd11e950315e3d784908629b301526a57a3a623bf70c/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_b4b635d36e735c2c": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\InstallShield\\setup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Setup Initialization Error" }, "_isdel.exe-9D4EC4B71FD189A0B2C4DBD6AADE16BF": { "file_name": "_isdel.exe", "file_path": "C:\\Windows\\SysWOW64\\InstallShield\\_isdel.exe", "hash_md5": "9D4EC4B71FD189A0B2C4DBD6AADE16BF", "hash_sha1": "0E7BB331D398BE694A92A823DE839FEFDF464DFD", "hash_sha256": "1E97ECA81395D1BD5E627DEBFDB02828BD3655D68C8F7296395D574781FAA32E", "hash_sha384": "4E7F088DD7D385E61DE22303A324671509767A5A11817922CC3FF9F3D032305746FA034861C575345578DBAF10BFF362", "hash_sha512": "765F8A531CC44FB241C577938C936506450D579F2005E32092B443423749F25F09C498B8A70179D37423082E8939EF4DB0B9AA82C10936922600EF2A2C936F65", "hash_ssdeep": "384:m3wIA7GjPE6nnP9TDWsKAkk/fG8+lmQP+0JSfgyz:QwIA7Q7tDUAdnemQVSfg", "hash_imp": "AF417A432744D25669A269C31C292485", "hash_pesha1": "FB5C09800C25B6498A54C4F0C638282CB01376E5", "hash_pe256": "499342A59AAFF1C1AC5F1BA1E0967C1EA21963505BAA43C841C16B02F5F3A186", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "32-bit InstallShield Deleter.", "meta_product_name": "InstallShield", "meta_company_name": "InstallShield Software Corporation", "meta_file_version": "5, 51, 138, 0", "meta_product_version": "5, 51", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 1990-1998 InstallShield Software Corporation, Phone: (847) 240-9111", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/1e97eca81395d1bd5e627debfdb02828bd3655d68c8f7296395d574781faa32e/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(R--) C:\\Windows\\SysWOW64\\InstallShield\\_isdel.exe": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_b4b635d36e735c2c": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\InstallShield\\_isdel.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "SpeechModelDownload.exe-258C6DE7D06FAB23AAD935E04629F562": { "file_name": "SpeechModelDownload.exe", "file_path": "C:\\Windows\\SysWOW64\\Speech_OneCore\\common\\SpeechModelDownload.exe", "hash_md5": "258C6DE7D06FAB23AAD935E04629F562", "hash_sha1": "5272B975A862FD809EAA9612B195001ED9E7A1A6", "hash_sha256": "7A6E9A6B0551052B74A74F789CA2BE13570757C326D10B212EDBEAA0E171A0A9", "hash_sha384": "507B2415AC78BDB56B6536C1A308D074DBE73E39CDDBC022C3B073C6625542F99850C614FB29A61630BC6258E874EE59", "hash_sha512": "DC82450530A22B7CDD8BB42E1FA838A8DA70C01014937D0552A5963148C67AA9A2F942B6A5C7CAB8AD844995DDCFB42BCF1924B077A0D5C1CABE362F79B7180E", "hash_ssdeep": "3072:Xs6DFenqmTJMFZokjH0loqB01UPw1FuVywSM6S6501KTTYf:cQFSqm4Z8GqBhaFu7S9Ao", "hash_imp": "9C5703517F234F035DCA7025FA10F7C0", "hash_pesha1": "CBBA84E0540491D16315531F853774EBD8F1EA15", "hash_pe256": "234C2BBDACCA66C85C375566F6AC14A636CB713C31DBD6B5CDE3750EE08E0DE9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Speech Model Download Executable", "meta_original_filename": "SpeechModelDownload.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1369 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1369", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/7a6e9a6b0551052b74a74f789ca2be13570757c326d10b212edbeaa0e171a0a9/detection/", "children": "RdpSa.exe", "runtime_modules": [ "C:\\Windows\\SysWOW64\\Speech_OneCore\\common\\SpeechModelDownload.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "mofcomp.exe-18132416C71D1B3A225D5BCC7F686381": { "file_name": "mofcomp.exe", "file_path": "C:\\Windows\\SysWOW64\\wbem\\mofcomp.exe", "hash_md5": "18132416C71D1B3A225D5BCC7F686381", "hash_sha1": "7BE07A001105BC39FB4C6828B9F50AEFADCCA476", "hash_sha256": "6B74BB2BFE0CDA5617EAC3A3EEFCCC9554186B098DC70DA573B153AF36525569", "hash_sha384": "DBA56541E2900942BFA78BBDEAC7944BA359B3A2C76C6FE605B4F219E9043F7B348047C5806C8F9C4CDA3C944F5980B0", "hash_sha512": "40BE189B8971BB968F013AD2CC769B4D14D966BB4F0C5F163E14048AA363ED5AD964E14596C5EAB1AC1C6355A0FC720F086D253156B45EBBBB5D55AAD560DA82", "hash_ssdeep": "384:Vt/0delwgfKrQwK79+14CkELZta4L+fyvoahl/liW1oWn1tV:VtMdcB5XfyvoaH/lxB1", "hash_imp": "3B603DD27AB650AF3F5B7F82AE17797D", "hash_pesha1": "F73F240758D2FDBD85A2C986559F4BD0FEADBDCE", "hash_pe256": "DA0D740311A8C64B8C7BE8743707DAEA640894FD410DACF3894EABF9655A2278", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "The Managed Object Format (MOF) Compiler ", "meta_original_filename": "mofcomp.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/6b74bb2bfe0cda5617eac3a3eefccc9554186b098dc70da573b153af36525569/detection/", "output": "Microsoft (R) MOF Compiler Version 10.0.17763.1\nCopyright (c) Microsoft Corp. 1997-2006. All rights reserved.\n\nusage: mofcomp [-check] [-N:<Path>]\n [-class:updateonly|-class:createonly]\n [-instance:updateonly|-instance:createonly]\n [-B:<filename>] [-P:<Password>] [-U:<UserName>]\n [-A:<Authority>] [-WMI] [-AUTORECOVER]\n [-MOF:<path>] [-MFL:<path>] [-AMENDMENT:<Locale>]\n [-ER:<ResourceName>] [-L:<ResourceLocale>] \n <MOF filename>\n\n -check Syntax check only\n -N:<path> Load into this namespace by default\n -class:updateonly Do not create new classes\n -class:safeupdate Update unless conflicts exist\n -class:forceupdate Update resolving conflicts if possible\n -class:createonly Do not change existing classes\n -instance:updateonly Do not create new instances\n -instance:createonly Do not change existing instances\n -U:<UserName> User Name\n -P:<Password> Login password\n -A:<Authority> Example: NTLMDOMAIN:Domain\n -B:<destination filename> Creates a binary MOF file, does not add to DB\n -WMI Do Windows Driver Model (WDM) checks, requires -B switch\n -AUTORECOVER Adds MOF to list of files compiled during DB recovery\n -Amendment:<LOCALE> splits MOF into language neutral and specific versions\n where locale is of the form \"MS_4??\"\n -MOF:<path> name of the language neutral output\n -MFL:<path> name of the language specific output\n -ER:<ResourceName> extracts binary mof from named resource\n -L:<ResourceLocale> optional specific locale number when using -ER switch\n\n Example c:>mofcomp -N:root\\default yourmof.mof\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wbem\\mofcomp.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WinMgmt.exe-3CCDE22442B58A5642B694F8157D0040": { "file_name": "WinMgmt.exe", "file_path": "C:\\Windows\\SysWOW64\\wbem\\WinMgmt.exe", "hash_md5": "3CCDE22442B58A5642B694F8157D0040", "hash_sha1": "1611D7029A2C287F8F6A46B2B068151EC4777913", "hash_sha256": "A733B3E7C718371FD75855B43D778710016E3545C9AC3705E26C080C43763140", "hash_sha384": "313CA1ECE44E43CC312F80C84F94EF8568994F86F048CD3AAFA9E11C61096A19AE3B0B1DF7B72FD8BA54F18D2B10B1BE", "hash_sha512": "C48991A41789032037A8AC01D34B80575EAF50FF0D4211F2C5B784BAC14496E4E7205EBDE667E5339A8418497E7E9ADD5D6E8C660FF7B47B12A749A80C644631", "hash_ssdeep": "1536:QIA/RMgNqRdShIPoANJLlAXuSXv+qSFEAeOFt:U/RcRshIPFJRAhP2EAeU", "hash_imp": "C3B140CA5A161C3F9BAB1E096049951D", "hash_pesha1": "655181DE9550F4E1EC68AC3BEE71B30D7143F671", "hash_pe256": "226D034141121C0ECAFA037FF81B5F097D873D4F9F77CACAE1ED793C2EF20DA4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Service Control Utility", "meta_original_filename": "winmgmt.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/a733b3e7c718371fd75855b43d778710016e3545c9ac3705e26c080c43763140/detection/", "output": "Invalid parameter\n\nWindows Management Instrumentation\n\nUsage: winmgmt\t[/backup <filename>] [/restore <filename> <flag>]\n\t\t[/resyncperf] [/standalonehost [<level>]] [/sharedhost]\n\t\t[/verifyrepository [<path>]] [/salvagerepository]\n\t\t[/resetrepository]\n\n/backup <filename>\n\tCauses WMI to back up the repository to the specified file name. The\n\tfilename argument should contain the full path to the file location.\n\tThis process requires a write lock on the repository so that write\n\toperations to the repository are suspended until the backup process is\n\tcompleted.\n\n/restore <filename> <flag>\n\tManually restores the WMI repository from the specified backup file.\n\tThe filename argument should contain the full path to the backup file\n\tlocation. To perform the restore operation, WMI saves the existing\n\trepository to write back if the operation fails. Then the repository is\n\trestored from the backup file that is specified in the filename\n\targument. If exclusive access to the repository cannot be achieved,\n\texisting clients are disconnected from WMI. The flag argument must be a\n\t1 (force - disconnect users and restore) or 0 (default - restore if no\n\tusers connected) and specifies the restore mode.\n\n/resyncperf\n\tRegisters the system performance libraries with WMI.\n\n/standalonehost [<level>]\n\tMoves the Winmgmt service to a standalone Svchost process that has a\n\tfixed DCOM endpoint. The default endpoint is \"ncacn_ip_tcp.0.24158\".\n\tHowever, the endpoint may be changed by running Dcomcnfg.exe. The level\n\targument is the authentication level for the Svchost process. If level\n\tis not specified, the default is 4 (RPC_C_AUTHN_LEVEL_PKT).\n\n/sharedhost\n\tMoves the Winmgmt service into the shared Svchost process.\n\n/verifyrepository [<path>]\n\tPerforms a consistency check on the WMI repository. When you add the\n\t/verifyrepository switch without the <path> argument, then the live\n\trepository currently used by WMI is verified. When you specify the path\n\targument, you can verify any saved copy of the repository. In this\n\tcase, the path argument should contain the full path to the saved\n\trepository copy. The saved repository should be a copy of the entire\n\trepository folder.\n\n/salvagerepository\n\tPerforms a consistency check on the WMI repository, and if an\n\tinconsistency is detected, rebuilds the repository. The content of the\n\tinconsistent repository is merged into the rebuilt repository, if it\n\tcan be read. The salvage operation always works with the repository\n\tthat the WMI service is currently using. MOF files that contain the\n\t#pragma autorecover preprocessor statement are restored to the\n\trepository.\n\n/resetrepository\n\tThe repository is reset to the initial state when the operating system\n\tis first installed. MOF files that contain the #pragma autorecover\n\tpreprocessor statement are restored to the repository.\n\n" }, "WMIADAP.exe-B6B42CA6C0271508321559B6D2901E95": { "file_name": "WMIADAP.exe", "file_path": "C:\\Windows\\SysWOW64\\wbem\\WMIADAP.exe", "hash_md5": "B6B42CA6C0271508321559B6D2901E95", "hash_sha1": "FF78F05E59E65E3E20C3DAED043EF8FE48577248", "hash_sha256": "999113AEE6783853D56F3AA40BD524FC567DF553AEC310C797193704219930D7", "hash_sha384": "08E35027B3181A3247C077EEF79E7DDE7013367CB8A3CBC12BAE3A46253FA3E7DDD303357A1444961625DE267786642E", "hash_sha512": "7CE5B9E93F80FEE2C8C694B5CC12103539675AF6B1FA12953E65123BA647E0B1C7E6B2121B57C1B19846C99DAC6B153E6E257BD92AFCA1913F633E206B6A5BA9", "hash_ssdeep": "3072:zp++AOVdnU7EEZ8+NNPyQ3fwyHSZ3du+LLC:zqOVMBrNP/33yZ3duEm", "hash_imp": "CF3EAAFDB564A5CFF2518D8921F5BC72", "hash_pesha1": "66FC617DD2612E02E76F58B2A186A2FCE45BED72", "hash_pe256": "08C171FA6CAC88FE38924FBC56DFEB144FF311F4FE6FECDE50475F74885B88DD", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Reverse Performance Adapter Maintenance Utility", "meta_original_filename": "wmicookr.dll", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/999113aee6783853d56f3aa40bd524fc567df553aec310c797193704219930d7/detection/", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wbem\\WMIADAP.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WMIC.exe-C0DB2C1BE17D7F3EE5805AD2B84DA59A": { "file_name": "WMIC.exe", "file_path": "C:\\Windows\\SysWOW64\\wbem\\WMIC.exe", "hash_md5": "C0DB2C1BE17D7F3EE5805AD2B84DA59A", "hash_sha1": "8BF4A74FDA8AC23C18D64AB3B93A3DD863739FE8", "hash_sha256": "F41A8470C4ECF503B576879A9043DF5781F4F08D688012E3DB391E04C8EB894A", "hash_sha384": "0D365F2EF487A1A395BE136B35E30F9B4B6ED43562854C9C73F2EDA234F7966173B26946091964E0CD6201DFE83F06FC", "hash_sha512": "106FF0B628BBA2D6FD3C55818F0874B75DD93102B351C4219773ED8409547B21C3834A5EC0181A06A8A32C1C83DD68019972F6422764F1A3FA0783414C956BE9", "hash_ssdeep": "6144:yCETqMqDmF4vgBiEv8iZv9KypcnIErF/lCE+/GH5enhZhHW:yC9MqCMgBDv8+Kypcnvg/GH0nhZhHW", "hash_imp": "B12619881D79C3ACADF45E752A58554A", "hash_pesha1": "881792E752F8D7307AD67D7A9CF0ED051AFC1506", "hash_pe256": "3A7726537240CF05BF40F10AA1AEF4912ACD8558F8BDE470E793F4E4FADB5888", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Commandline Utility", "meta_original_filename": "wmic.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/f41a8470c4ecf503b576879a9043df5781f4f08d688012e3db391e04c8eb894a/detection/", "output": "\r\r\nWMIC is deprecated.\r\r\n\r\r\n[global switches] <command>\r\r\n\r\r\nThe following global switches are available:\r\r\n/NAMESPACE Path for the namespace the alias operate against.\r\r\n/ROLE Path for the role containing the alias definitions.\r\r\n/NODE Servers the alias will operate against.\r\r\n/IMPLEVEL Client impersonation level.\r\r\n/AUTHLEVEL Client authentication level.\r\r\n/LOCALE Language id the client should use.\r\r\n/PRIVILEGES Enable or disable all privileges.\r\r\n/TRACE Outputs debugging information to stderr.\r\r\n/RECORD Logs all input commands and output.\r\r\n/INTERACTIVE Sets or resets the interactive mode.\r\r\n/FAILFAST Sets or resets the FailFast mode.\r\r\n/USER User to be used during the session.\r\r\n/PASSWORD Password to be used for session login.\r\r\n/OUTPUT Specifies the mode for output redirection.\r\r\n/APPEND Specifies the mode for output redirection.\r\r\n/AGGREGATE Sets or resets aggregate mode.\r\r\n/AUTHORITY Specifies the <authority type> for the connection.\r\r\n/?[:<BRIEF|FULL>] Usage information.\r\r\n\r\r\nFor more information on a specific global switch, type: switch-name /?\r\r\n\r\r\n\r\r\nThe following alias/es are available in the current role:\r\r\nALIAS - Access to the aliases available on the local system\r\r\nBASEBOARD - Base board (also known as a motherboard or system board) management.\r\r\nBIOS - Basic input/output services (BIOS) management.\r\r\nBOOTCONFIG - Boot configuration management.\r\r\nCDROM - CD-ROM management.\r\r\nCOMPUTERSYSTEM - Computer system management.\r\r\nCPU - CPU management.\r\r\nCSPRODUCT - Computer system product information from SMBIOS. \r\r\nDATAFILE - DataFile Management. \r\r\nDCOMAPP - DCOM Application management.\r\r\nDESKTOP - User's Desktop management.\r\r\nDESKTOPMONITOR - Desktop Monitor management.\r\r\nDEVICEMEMORYADDRESS - Device memory addresses management.\r\r\nDISKDRIVE - Physical disk drive management. \r\r\nDISKQUOTA - Disk space usage for NTFS volumes.\r\r\nDMACHANNEL - Direct memory access (DMA) channel management.\r\r\nENVIRONMENT - System environment settings management.\r\r\nFSDIR - Filesystem directory entry management. \r\r\nGROUP - Group account management. \r\r\nIDECONTROLLER - IDE Controller management. \r\r\nIRQ - Interrupt request line (IRQ) management. \r\r\nJOB - Provides access to the jobs scheduled using the schedule service. \r\r\nLOADORDER - Management of system services that define execution dependencies. \r\r\nLOGICALDISK - Local storage device management.\r\r\nLOGON - LOGON Sessions. \r\r\nMEMCACHE - Cache memory management.\r\r\nMEMORYCHIP - Memory chip information.\r\r\nMEMPHYSICAL - Computer system's physical memory management. \r\r\nNETCLIENT - Network Client management.\r\r\nNETLOGIN - Network login information (of a particular user) management. \r\r\nNETPROTOCOL - Protocols (and their network characteristics) management.\r\r\nNETUSE - Active network connection management.\r\r\nNIC - Network Interface Controller (NIC) management.\r\r\nNICCONFIG - Network adapter management. \r\r\nNTDOMAIN - NT Domain management. \r\r\nNTEVENT - Entries in the NT Event Log. \r\r\nNTEVENTLOG - NT eventlog file management. \r\r\nONBOARDDEVICE - Management of common adapter devices built into the motherboard (system board).\r\r\nOS - Installed Operating System/s management. \r\r\nPAGEFILE - Virtual memory file swapping management. \r\r\nPAGEFILESET - Page file settings management. \r\r\nPARTITION - Management of partitioned areas of a physical disk.\r\r\nPORT - I/O port management.\r\r\nPORTCONNECTOR - Physical connection ports management.\r\r\nPRINTER - Printer device management. \r\r\nPRINTERCONFIG - Printer device configuration management. \r\r\nPRINTJOB - Print job management. \r\r\nPROCESS - Process management. \r\r\nPRODUCT - Installation package task management. \r\r\nQFE - Quick Fix Engineering. \r\r\nQUOTASETTING - Setting information for disk quotas on a volume. \r\r\nRDACCOUNT - Remote Desktop connection permission management.\r\r\nRDNIC - Remote Desktop connection management on a specific network adapter.\r\r\nRDPERMISSIONS - Permissions to a specific Remote Desktop connection.\r\r\nRDTOGGLE - Turning Remote Desktop listener on or off remotely.\r\r\nRECOVEROS - Information that will be gathered from memory when the operating system fails. \r\r\nREGISTRY - Computer system registry management.\r\r\nSCSICONTROLLER - SCSI Controller management. \r\r\nSERVER - Server information management. \r\r\nSERVICE - Service application management. \r\r\nSHADOWCOPY - Shadow copy management.\r\r\nSHADOWSTORAGE - Shadow copy storage area management.\r\r\nSHARE - Shared resource management. \r\r\nSOFTWAREELEMENT - Management of the elements of a software product installed on a system.\r\r\nSOFTWAREFEATURE - Management of software product subsets of SoftwareElement. \r\r\nSOUNDDEV - Sound Device management.\r\r\nSTARTUP - Management of commands that run automatically when users log onto the computer system.\r\r\nSYSACCOUNT - System account management. \r\r\nSYSDRIVER - Management of the system driver for a base service.\r\r\nSYSTEMENCLOSURE - Physical system enclosure management.\r\r\nSYSTEMSLOT - Management of physical connection points including ports, slots and peripherals, and proprietary connections points.\r\r\nTAPEDRIVE - Tape drive management. \r\r\nTEMPERATURE - Data management of a temperature sensor (electronic thermometer).\r\r\nTIMEZONE - Time zone data management. \r\r\nUPS - Uninterruptible power supply (UPS) management. \r\r\nUSERACCOUNT - User account management.\r\r\nVOLTAGE - Voltage sensor (electronic voltmeter) data management.\r\r\nVOLUME - Local storage volume management.\r\r\nVOLUMEQUOTASETTING - Associates the disk quota setting with a specific disk volume. \r\r\nVOLUMEUSERQUOTA - Per user storage volume quota management.\r\r\nWMISET - WMI service operational parameters management. \r\r\n\r\r\nFor more information on a specific alias, type: alias /?\r\r\n\r\r\nCLASS - Escapes to full WMI schema.\r\r\nPATH - Escapes to full WMI object paths.\r\r\nCONTEXT - Displays the state of all the global switches.\r\r\nQUIT/EXIT - Exits the program.\r\r\n\r\r\nFor more information on CLASS/PATH/CONTEXT, type: (CLASS | PATH | CONTEXT) /?\r\r\n\r\r\n", "children": "conhost.exe", "error": "help - Alias not found.\r\r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\wbem\\WMIC.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "WmiPrvSE.exe-3FF0BB6EACC39958042B74CA04E202A6": { "file_name": "WmiPrvSE.exe", "file_path": "C:\\Windows\\SysWOW64\\wbem\\WmiPrvSE.exe", "hash_md5": "3FF0BB6EACC39958042B74CA04E202A6", "hash_sha1": "8CE4A111E7A2461CAA5FFE2E5F2670A58428A96B", "hash_sha256": "158075D730A7A6ACBE7739251EE9BEA4349268597CA576B3E0CB8442140865FD", "hash_sha384": "5B9E712A8206203CD51970A79EB1E76A51114AE5F71838DB40741CCE2A1CE16BFA36A0E5160E1883CEF11E4745EDDF5C", "hash_sha512": "24E893670872DA8688F6957975500C26B97DB41E7A3982BB2C475A1912453DB25E719FF22BEB1445A969248E3D7F6F39A97A4A8A9E7EBCFD47A7BD8B0C14D3F9", "hash_ssdeep": "6144:aSqTCo9s07xGgY8AqUb6BjZoXzj9yzhDePDXxRp:tqTCo9s07038AqUb6sXNcJ8DXxR", "hash_imp": "322419B2AF40F7FE09109E4C2F461902", "hash_pesha1": "AD05F43008A7B15B79CBBE95ACAE494991D8B50E", "hash_pe256": "5C683F78243472A859A1D912BFC4E0AF0647132A910B196F5E29F30F7AD573A9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "WMI Provider Host", "meta_original_filename": "Wmiprvse.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/158075d730a7a6acbe7739251ee9bea4349268597ca576b3e0cb8442140865fd/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\user32.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC64": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\wbem\\WmiPrvSE.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "powershell.exe-83767E18DB29B51A804A9E312D0ED99C": { "file_name": "powershell.exe", "file_path": "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe", "hash_md5": "83767E18DB29B51A804A9E312D0ED99C", "hash_sha1": "E6BCADE7272AFDF52D963D0626A1DD4D26B39A7E", "hash_sha256": "1EE3D7C80D075D64F97D04D036E558043F2F6BC959C87CD5B0A6D53B96B96A0F", "hash_sha384": "32E7AA7053BE685BAB5C77EBB02D9F19ACD5568A2799A71800DCF0852AAB0CF04632AF500A9BEBC23AA6F81034BAF6C9", "hash_sha512": "76CEF2E9FB6CF3DC10A25C783CDD92FC07DC567BD49DADC58E4FB3A8D40A233CB962A2C08E097227E56A80A8897A9747C9ED3A73E5F819202211A5B03880BF01", "hash_ssdeep": "6144:i0ye4FWwO9sV1yZywi/PzNKXzJ7BapCK5d3klRzULOnWyjLsPhAQzqOP:ixW2KXzJ4pdd3klnnWosPhnzqI", "hash_imp": "D1A922C94A1F407CB2BBCAD033C8ED7A", "hash_pesha1": "F78257284CDA8951D964F0980EC084C4F1BE6164", "hash_pe256": "E53B3A103E2FEF77A12AFCC519F94AA4E50FE81E88811210B54B1D82AB7815B1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows PowerShell", "meta_original_filename": "PowerShell.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/1ee3d7c80d075d64f97d04d036e558043f2f6bc959c87cd5b0a6d53b96b96a0f/detection/", "output": "\r\nPowerShell[.exe] [-PSConsoleFile <file> | -Version <version>]\r\n [-NoLogo] [-NoExit] [-Sta] [-Mta] [-NoProfile] [-NonInteractive]\r\n [-InputFormat {Text | XML}] [-OutputFormat {Text | XML}]\r\n [-WindowStyle <style>] [-EncodedCommand <Base64EncodedCommand>]\r\n [-ConfigurationName <string>]\r\n [-File <filePath> <args>] [-ExecutionPolicy <ExecutionPolicy>]\r\n [-Command { - | <script-block> [-args <arg-array>]\r\n | <string> [<CommandParameters>] } ]\r\n\r\nPowerShell[.exe] -Help | -? | /?\r\n\r\n-PSConsoleFile\r\n Loads the specified Windows PowerShell console file. To create a console\r\n file, use Export-Console in Windows PowerShell.\r\n\r\n-Version\r\n Starts the specified version of Windows PowerShell. \r\n Enter a version number with the parameter, such as \"-version 2.0\".\r\n\r\n-NoLogo\r\n Hides the copyright banner at startup.\r\n\r\n-NoExit\r\n Does not exit after running startup commands.\r\n\r\n-Sta\r\n Starts the shell using a single-threaded apartment.\r\n Single-threaded apartment (STA) is the default.\r\n\r\n-Mta\r\n Start the shell using a multithreaded apartment.\r\n\r\n-NoProfile\r\n Does not load the Windows PowerShell profile.\r\n\r\n-NonInteractive\r\n Does not present an interactive prompt to the user.\r\n\r\n-InputFormat\r\n Describes the format of data sent to Windows PowerShell. Valid values are\r\n \"Text\" (text strings) or \"XML\" (serialized CLIXML format).\r\n\r\n-OutputFormat\r\n Determines how output from Windows PowerShell is formatted. Valid values\r\n are \"Text\" (text strings) or \"XML\" (serialized CLIXML format).\r\n\r\n-WindowStyle\r\n Sets the window style to Normal, Minimized, Maximized or Hidden.\r\n\r\n-EncodedCommand\r\n Accepts a base-64-encoded string version of a command. Use this parameter \r\n to submit commands to Windows PowerShell that require complex quotation \r\n marks or curly braces.\r\n\r\n-ConfigurationName\r\n Specifies a configuration endpoint in which Windows PowerShell is run.\r\n This can be any endpoint registered on the local machine including the\r\n default Windows PowerShell remoting endpoints or a custom endpoint having\r\n specific user role capabilities.\r\n \r\n-File\r\n Runs the specified script in the local scope (\"dot-sourced\"), so that the \r\n functions and variables that the script creates are available in the \r\n current session. Enter the script file path and any parameters. \r\n File must be the last parameter in the command, because all characters \r\n typed after the File parameter name are interpreted \r\n as the script file path followed by the script parameters.\r\n\r\n-ExecutionPolicy\r\n Sets the default execution policy for the current session and saves it \r\n in the $env:PSExecutionPolicyPreference environment variable. \r\n This parameter does not change the Windows PowerShell execution policy \r\n that is set in the registry.\r\n\r\n-Command\r\n Executes the specified commands (and any parameters) as though they were\r\n typed at the Windows PowerShell command prompt, and then exits, unless \r\n NoExit is specified. The value of Command can be \"-\", a string. or a\r\n script block.\r\n\r\n If the value of Command is \"-\", the command text is read from standard\r\n input.\r\n\r\n If the value of Command is a script block, the script block must be enclosed\r\n in braces ({}). You can specify a script block only when running PowerShell.exe\r\n in Windows PowerShell. The results of the script block are returned to the\r\n parent shell as deserialized XML objects, not live objects.\r\n\r\n If the value of Command is a string, Command must be the last parameter\r\n in the command , because any characters typed after the command are \r\n interpreted as the command arguments.\r\n\r\n To write a string that runs a Windows PowerShell command, use the format:\r\n\t\"& {<command>}\"\r\n where the quotation marks indicate a string and the invoke operator (&)\r\n causes the command to be executed.\r\n\r\n-Help, -?, /?\r\n Shows this message. If you are typing a PowerShell.exe command in Windows\r\n PowerShell, prepend the command parameters with a hyphen (-), not a forward\r\n slash (/). You can use either a hyphen or forward slash in Cmd.exe.\r\n\r\nEXAMPLES\r\n PowerShell -PSConsoleFile SqlSnapIn.Psc1\r\n PowerShell -version 2.0 -NoLogo -InputFormat text -OutputFormat XML\r\n PowerShell -ConfigurationName AdminRoles\r\n PowerShell -Command {Get-EventLog -LogName security}\r\n PowerShell -Command \"& {Get-EventLog -LogName security}\"\r\n\r\n # To use the -EncodedCommand parameter:\r\n $command = 'dir \"c:\\program files\" '\r\n $bytes = [System.Text.Encoding]::Unicode.GetBytes($command)\r\n $encodedCommand = [Convert]::ToBase64String($bytes)\r\n powershell.exe -encodedCommand $encodedCommand\r\n", "error": "At line:1 char:3\r\n+ --help\r\n+ ~\r\nMissing expression after unary operator '--'.\r\nAt line:1 char:3\r\n+ --help\r\n+ ~~~~\r\nUnexpected token 'help' in expression or statement.\r\n + CategoryInfo : ParserError: (:) [], ParentContainsErrorRecordException\r\n + FullyQualifiedErrorId : MissingExpressionAfterOperator\r\n \r\n", "runtime_modules": [ "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "powershell_ise.exe-83B61B8AE3AE5CA669E1CBB191B4852D": { "file_name": "powershell_ise.exe", "file_path": "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell_ise.exe", "hash_md5": "83B61B8AE3AE5CA669E1CBB191B4852D", "hash_sha1": "1350ABFA1319526847102A08714D8159DC79FB64", "hash_sha256": "CD65AE1EBB2B8EE7DEA364729A14D3CF4221C0EA9156B55A84EAD138F5C146E3", "hash_sha384": "C9496564E48385EB4893442774D71DB39FDA2791FA59AF6A9920623900B982B099EEE4B0C8BDD67AFBD1D41A37698355", "hash_sha512": "2BA7211B7586D5C14602209B858F7ECBA42A901B1287C0B773118D62799E75CCF0618535EB600F959FBF81226060CCB6F83E89B08AF80795731FAECB440B0278", "hash_ssdeep": "3072:bwUkVjGPsw40vLkVjqP4w6U+ToIuWNXmmZTWl/jC7gDooMLa6:bfk+uZToIuUXmmZbgDooMz", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "B317AFABDD3B6D278D89E5552797B053483571CD", "hash_pe256": "7028F281E80D26C6451B7BB256EBF3D21E105C813B4C2B14A68487AFBD627183", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows PowerShell ISE", "meta_original_filename": "powershell_ise.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/cd65ae1ebb2b8ee7dea364729a14d3cf4221c0ea9156b55a84ead138f5c146e3/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4108": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell_ise.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows PowerShell ISE" }, "AWSAcpiSpcrReader.exe-1D3758741843A1750BB5D1B5AFDFB5FE": { "file_name": "AWSAcpiSpcrReader.exe", "file_path": "C:\\ProgramData\\Amazon\\EC2-Windows\\Launch\\Scripts\\AWSAcpiSpcrReader.exe", "hash_md5": "1D3758741843A1750BB5D1B5AFDFB5FE", "hash_sha1": "E96DDD10C77B494EA3D511A4CE04B22E5354898C", "hash_sha256": "269CB889D96E2F2741D66EF19552A94EC59DDAFF27A2FE28EF55516917375E57", "hash_sha384": "153CAE5129FC8114D6D088A6E83E6D5D06BD5267BA618D5760042FFB57F87CB9BAA75A654BC9A486330F7AF22B214C75", "hash_sha512": "D180B21CA08D0578EEF9F1AA8F0E9862F38E9DA1AA5114627E07CF48BF960262C16C166CFDFFD295514381495A51327F304D0521F3CB4483F39D48016E7D57E9", "hash_ssdeep": "3072:y3uMTsB0TUqlYXHC4crVc9c2dBZgXXe+lCIHyGqZt8QTALa:yeMLT9lYy4+VcO2ee2yG+8C", "hash_imp": "D47232778B4A8BEA428B253E687F92CB", "hash_pesha1": "3BA1680319175DC7FE21757F428EF79EABD05606", "hash_pe256": "47325FE7134084EA05C66792DBB7E7448F99495B0DE578AFD5D046F6F017F7C8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "0B6484A34E527CC2BC614568F961D353", "signature_thumbprint": "5E025F525F7CCDB57B9E0AD40C7022184536A52D", "signature_issuer": "CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US", "signature_subject": "CN=\"Amazon Web Services, Inc.\", O=\"Amazon Web Services, Inc.\", L=Seattle, S=Washington, C=US, PostalCode=98109, STREET=410 Terry Ave N, SERIALNUMBER=4152954, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US, OID.2.5.4.15=Private Organization", "meta_description": "AWS ACPI SPCR reader", "meta_original_filename": "AWSAcpiS.exe", "meta_product_name": "AWS ACPI SPCR reader", "meta_company_name": "Amazon Web Services, LLC", "meta_file_version": "1.0.0.1", "meta_product_version": "1.0.0.1", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 2017", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/269cb889d96e2f2741d66ef19552a94ec59ddaff27a2fe28ef55516917375e57/detection/", "output": "Result buffer size: 0\r\nSize of SPCR: 80\r\nException caught: GetSystemFirmwareTable() failed. LastError: Element not found.\r\n", "runtime_modules": [ "C:\\ProgramData\\Amazon\\EC2-Windows\\Launch\\Scripts\\AWSAcpiSpcrReader.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll" ] }, "Ec2LaunchSettings.exe-981D6BB8FEE39AF0D1760E1B84ED0EFA": { "file_name": "Ec2LaunchSettings.exe", "file_path": "C:\\ProgramData\\Amazon\\EC2-Windows\\Launch\\Settings\\Ec2LaunchSettings.exe", "hash_md5": "981D6BB8FEE39AF0D1760E1B84ED0EFA", "hash_sha1": "1EA583CEC654C222539E2A6A41FAA798164D7DEC", "hash_sha256": "DCA07840BD8B4F24F545C005865821B767393B6E1B0598E2DC6420802E067A22", "hash_sha384": "813737705FF4AE96D62397A07934C1952A1DCE7523D8197C7C5DCB56390DDBF6AE083C647DABE3AAFC2BBF42111E4855", "hash_sha512": "50B8990EF121C32A9F9A40A146853D432216E2B9471E43EC56A9CC2470775FFF5E982299DBBEB07081FE934CFCEF2388CFEF4FE29F4C1990E45DAF40B66985F2", "hash_ssdeep": "768:rryexlvbR9EgDpXz73kQfCFX2MpOXdDUkoMYKAnkzYc5tuTV7KYhJLJtKKQAUf2e:yexlvbR9NDpD73kNXvpOXdDUcWiCTV7g", "hash_imp": "n/a", "hash_pesha1": "3886D80DF93F15D8950BE189EDB10AFD0CCF8EB6", "hash_pe256": "7C7DAD55DD91C5ADC15C025B5D70DF2A07045B0989C78A9D33AAF813B91AC0E3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "060699CB065A7891D6EC94199F4A604B", "signature_thumbprint": "445F3553D886D857AA35528F4A298EECADEA1179", "signature_issuer": "CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US", "signature_subject": "CN=\"Amazon Web Services, Inc.\", OU=Amazon EC2, O=\"Amazon Web Services, Inc.\", L=Seattle, S=Washington, C=US, SERIALNUMBER=4152954, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US", "meta_description": "Ec2Launch.Settings", "meta_original_filename": "Ec2LaunchSettings.exe", "meta_product_name": "Ec2Launch.Settings", "meta_company_name": "Amazon.com", "meta_file_version": "1.0.0.0", "meta_product_version": "1.0.0.0", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright Amazon.com 2016", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/dca07840bd8b4f24f545c005865821b767393b6e1b0598e2dc6420802e067a22/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4536": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\ProgramData\\Amazon\\EC2-Windows\\Launch\\Settings\\Newtonsoft.Json.dll": "File", "\\RPC Control\\DSEC11B8": "Section", "(R-D) C:\\Windows\\Microsoft.NET\\assembly\\GAC_64\\System.Data\\v4.0_4.0.0.0__b77a5c561934e089\\System.Data.dll": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\Sessions\\2\\BaseNamedObjects\\11b8HWNDInterface:4b06c8": "Section", "(RWD) C:\\Windows\\Fonts\\segoeui.ttf": "File", "(R-D) C:\\Windows\\System32\\en-US\\msctfui.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\ProgramData\\Amazon\\EC2-Windows\\Launch\\Settings\\Ec2LaunchSettings.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\5543cca0df435801e2303ff46a482ed5\\mscorlib.ni.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\6885802f40fd803e49150d8a2b43a09b\\System.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Core\\f29b1120627489754c4b8dd317bbe950\\System.Core.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\WindowsBase\\7766b716f453669f6453022ce957c6ad\\WindowsBase.ni.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\PresentationCore\\8fad18d47be73b98845c53d0e6d3b964\\PresentationCore.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Presentatio5ae0f00f#\\d1101640429a2c3d8c6c257103ad22c1\\PresentationFramework.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Xaml\\12c01954752c224882de75b4418c8382\\System.Xaml.ni.dll", "C:\\Windows\\SYSTEM32\\dwrite.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\WPF\\wpfgfx_v0400.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\MSVCP120_CLR0400.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\WPF\\PresentationNative_v0400.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Configuration\\875dc3cfd53efc9f9a5c63016cd239d7\\System.Configuration.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Xml\\488d073901c2c0fb8ccbcbe182b6b160\\System.Xml.ni.dll", "C:\\Windows\\System32\\shell32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\SYSTEM32\\d3d9.dll", "C:\\Windows\\SYSTEM32\\d3d10warp.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Numerics\\65da063a028c3cfc846f5ddfffc32558\\System.Numerics.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Runteb92aa12#\\0a20c3e2769862d42803de9732fcf620\\System.Runtime.Serialization.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Xml.Linq\\1f8e15c27df619e8116461e283dac636\\System.Xml.Linq.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Data\\a39e284ddde9013349d1f350607766b8\\System.Data.ni.dll", "C:\\Windows\\Microsoft.Net\\assembly\\GAC_64\\System.Data\\v4.0_4.0.0.0__b77a5c561934e089\\System.Data.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Presentatioaec034ca#\\fc91c5553de4f5b4c206769962382b62\\PresentationFramework.Aero2.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Presentatio84a7b877#\\9b847af53f97de789af8b6c182043a67\\PresentationFramework-SystemData.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Presentatio4b37ff64#\\a518ad0e93e801a17388ac66da43fd46\\PresentationFramework-SystemXmlLinq.ni.dll", "C:\\Windows\\SYSTEM32\\wtsapi32.dll", "C:\\Windows\\SYSTEM32\\WINSTA.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\dataexchange.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\system32\\dcomp.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\system32\\twinapi.appcore.dll", "C:\\Windows\\system32\\RMCLIENT.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Presentatio49d6fefe#\\2765d5dfb05e889760491cc0e1f68a4e\\PresentationFramework-SystemXml.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\UIAutomationTypes\\f898d852ca0a3bf2329018f1997c623a\\UIAutomationTypes.ni.dll", "C:\\Windows\\SYSTEM32\\UIAutomationCore.dll", "C:\\Windows\\SYSTEM32\\Bcp47Langs.dll", "C:\\Windows\\system32\\msctfui.dll" ], "runtime_window_title": "Ec2 Launch Settings" }, "ebsnvme-id.exe-07D1CBA2721C23302A33FC8A67BA0800": { "file_name": "ebsnvme-id.exe", "file_path": "C:\\ProgramData\\Amazon\\Tools\\ebsnvme-id.exe", "hash_md5": "07D1CBA2721C23302A33FC8A67BA0800", "hash_sha1": "521EBA8A3ABBE1D75633877EC444C1DCCDC28BA8", "hash_sha256": "27A74549C4958B0FA767B62299A83A9BAD6E74512B65BA6C548A12E2B125E870", "hash_sha384": "A7DDEF971C50E63710B68BDB79B750FA3C41CEDC9AF193B1A6B8664BE405D3EC9524E21E9BB4821FF59577767DF5C8FE", "hash_sha512": "1083C4DA9208D5860785FAE76B401AD93DAC24D6B3D448B0D2AE29673997A2A7FA744FAFA3AAFDA975688FB8561CB6BE9FC06ECF474B947DC85356A2DF160BCF", "hash_ssdeep": "6144:tZcF50g9r2a3AQpcDxlAAcn83ShMhoh8GbGhFN:tJg9rxAccVlA8o2ZX", "hash_imp": "0249BFB49C7CB7ED8660CB7BC9407CDA", "hash_pesha1": "1D756C8EF819950F1A9435B102C8CA289DF70373", "hash_pe256": "798531F404DFB0A315515432FF94778B64BA73B39DC41FA70BDA0A5BE9C228DB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "015739DFC76C6256E7F4637282ACF160", "signature_thumbprint": "C21B73FB4E5B64D1AB23A6E4620E7780819446E9", "signature_issuer": "CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US", "signature_subject": "CN=\"Amazon Web Services, Inc.\", OU=EC2 Windows, O=\"Amazon Web Services, Inc.\", L=Seattle, S=Washington, C=US, PostalCode=98109, STREET=410 Terry Ave N, SERIALNUMBER=4152954, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US, OID.2.5.4.15=Private Organization", "meta_description": "EBS NVMe ID utility application", "meta_original_filename": "ebsnvme-id.exe", "meta_product_name": "ebsnvme-id", "meta_company_name": "Amazon Web Services, Inc.", "meta_file_version": "1.0.0.32", "meta_product_version": "1.0.0.32", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (C) 2018 Amazon Web Services, Inc.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/27a74549c4958b0fa767b62299a83a9bad6e74512b65ba6c548a12e2b125e870/detection/", "output": "\r\nError: Non-numeric input: --help\r\n\r\nEBS NVMe ID utility application ver 1.0.0.32\r\nUsage: ebsnvme-id <disknumber> ... <disknumberN>\r\n\r\n" }, "ConfigSecurityPolicy.exe-B5A3A34619717DB8486BCD0EE10D8791": { "file_name": "ConfigSecurityPolicy.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2007.8-0\\ConfigSecurityPolicy.exe", "hash_md5": "B5A3A34619717DB8486BCD0EE10D8791", "hash_sha1": "386A0B9561B2B5C63D07A15900B23BA41339112C", "hash_sha256": "6D9589A6DB768B9EB658215059B9848B9DE96DD8EA701BE8A11F28E062684E20", "hash_sha384": "87864E07B5CB2C789C6E5B5854C3CC30AA6CAA87C931BF37358C0D5E11747540620E82EAA4D3941871B1B15A1529DDF6", "hash_sha512": "7DA1AB11FB77FE3F5A2269C0DCD3DF50DB7DB400CD2F3F3948C31C2688F7446C9ED783D6FF43317D583E0559871EB31D1D5E87FB100EDF026979BEED8003D243", "hash_ssdeep": "3072:Kns2yL/4Vn+mFSGaToJqOMa1LFLK2gg6cEADk74t+fXa/QwKeGiSMV+T8rguIcmX:+s204t+cyoJ5M8LB3iqnXrgimGbw3", "hash_imp": "C87FC829E4403CB94530225A7ADC688A", "hash_pesha1": "D43B3033E281B2C2F061959FDB6C0487FE885724", "hash_pe256": "E2078CBD9582436DEE41FAF4069E24DA4F950AD6C65B14E42D4FDFECC3B1A119", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Security Client Policy Configuration Tool", "meta_original_filename": "ConfigSecurityPolicy.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.17763.1 (WinBuild.160101.0800)", "meta_product_version": "4.18.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/6d9589a6db768b9eb658215059b9848b9de96dd8ea701be8a11f28e062684e20/detection/", "error": "Microsoft Security Client failed to apply policy \"--help\". Error code: 0xC00CE225.\r\n", "runtime_modules": [ "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2007.8-0\\ConfigSecurityPolicy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\SYSTEM32\\WTSAPI32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\SYSTEM32\\gpapi.dll" ] }, "MpCmdRun.exe-73E18D56F42B16160008629E1C936311": { "file_name": "MpCmdRun.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2007.8-0\\MpCmdRun.exe", "hash_md5": "73E18D56F42B16160008629E1C936311", "hash_sha1": "CB69B237830F7C16F59B4CE276637260B6B61FC9", "hash_sha256": "F2C04FA5B0BCCD32F7B158C42D67B8242867E2C31058C68F13868035DBB09787", "hash_sha384": "8A4B54CF55DE53B357860352747149B0A5D50673F3219799908BBEC686A143B5BE7E2459DF21DAC1A805887624486D10", "hash_sha512": "EAF82A13A98FC2221B3FBA5B1D3783278741BA24793C1EAF89BE675B4B64B1DB842C2FC45063EBD38D99B25899E978C75B22C252E0B87D0FB04812C92E85DE26", "hash_ssdeep": "6144:I4gwwWtvGhP1yfKSMHlzztc17dUB8o0D/Zeh9BpIxenK/IfOnF:IIv4NySSMfcwB8o0D/EXq", "hash_imp": "25C9A89434BAA48C69401E0FBFDCEA84", "hash_pesha1": "C317FE3958452650A3217DF2BCF809826C07F0ED", "hash_pe256": "56D42EF5A9CA3F5732F7224D30A5D2F0451E6E009488D00A69A11B278792B844", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024BB2230A43CD03636200000000024B", "signature_thumbprint": "50AFF9A191126B5BAD57B29846F3B68D550758CA", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Malware Protection Command Line Utility", "meta_original_filename": "MpCmdRun.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2007.8 (WinBuild.160101.0800)", "meta_product_version": "4.18.2007.8", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/f2c04fa5b0bccd32f7b158c42d67b8242867e2c31058c68f13868035dbb09787/detection/", "output": "Microsoft Antimalware Service Command Line Utility (c) 2006-2018 Microsoft Corp\r\r\nUse this tool to automate and troubleshoot Microsoft Antimalware Service\r\r\n\r\r\nUsage:\r\r\nMpCmdRun.exe [command] [-options]\r\r\n\r\r\nCommand Description\r\r\n -? / -h Displays all available options\r\r\n for this tool\r\r\n -Scan [-ScanType #] [-File <path> [-DisableRemediation] [-BootSectorScan] [-CpuThrottling]]\r\r\n [-Timeout <days>]\r\r\n [-Cancel]\r\r\n [-ReturnHR]\r\r\n Scans for malicious software\r\r\n -Trace [-Grouping #] [-Level #] Starts diagnostic tracing\r\r\n -GetFiles [-SupportLogLocation <path>] Collects support information\r\r\n -GetFilesDiagTrack Same as Getfiles but outputs to \r\r\n temporary DiagTrack folder \r\r\n -RemoveDefinitions [-All] Restores the installed\r\r\n signature definitions\r\r\n to a previous backup copy or to\r\r\n the original default set of\r\r\n signatures\r\r\n [-Engine] Restore the installed engine to\r\r\n the previous version saved\r\r\n [-DynamicSignatures] Removes only the dynamically\r\r\n downloaded signatures\r\r\n -SignatureUpdate [-UNC | -MMPC] Checks for new definition updates\r\r\n -Restore [-ListAll | [[-Name <name>] [-All] | [-FilePath <filePath>]] [-Path <path>]] Restore or list\r\r\n quarantined item(s)\r\r\n -AddDynamicSignature [-Path] Loads a dynamic signature\r\r\n -ListAllDynamicSignatures List the loaded dynamic signatures\r\r\n -RemoveDynamicSignature [-SignatureSetID] Removes a dynamic signature\r\r\n -CheckExclusion -path <path> Checks whether path is excluded\r\r\n -DownloadFile -URL <url> -path <path> Downloads a file from the given URL\r\r\n to the location given in path. Path\r\r\n should also have the file name in it.\r\r\n\r\r\nAdditional Information:\r\r\n\r\r\nSupport information will be in the following directory:\r\r\nC:\\ProgramData\\Microsoft\\Windows Defender\\Support\r\r\n\r\r\n -Scan [-ScanType value]\r\r\n 0 Default, according to your configuration\r\r\n 1 Quick scan\r\r\n 2 Full system scan\r\r\n 3 File and directory custom scan\r\r\n\r\r\n [-File <path>]\r\r\n Indicates the file or directory to be scanned, only valid for custom scan.\r\r\n\r\r\n [-DisableRemediation]\r\r\n This option is valid only for custom scan.\r\r\n When specified:\r\r\n - File exclusions are ignored.\r\r\n - Archive files are scanned.\r\r\n - Actions are not applied after detection.\r\r\n - Event log entries are not written after detection.\r\r\n - Detections from the custom scan are not displayed in the user interface.\r\r\n - The console output will show the list of detections from the custom scan.\r\r\n\r\r\n [-BootSectorScan]\r\r\n Enables boot sector scanning; only valid for custom scan.\r\r\n\r\r\n [-Timeout <days>]\r\r\n Timeout in days; maximum value is 30.\r\r\n If this parameter is not specified, default value is 7 days for full scan and 1 day for all other scans.\r\r\n\r\r\n [-Cancel]\r\r\n Try to cancel any ongoing quick or full scan.\r\r\n\r\r\n [-CpuThrottling]\r\r\n When specified:\r\r\n - Will ensure that the scan obeys the CPU throttling as defined in the policy (Default 50).\r\r\n\r\r\n [-ReturnHR]\r\r\n Instead of returning the default 0 or 2 values, return the actual HRESULT of the scan command.\r\r\n\r\r\n [DEFAULT]Return code is\r\r\n 0 if no malware is found or malware is successfully remediated and no additional user action is required\r\r\n 2 if malware is found and not remediated or additional user action is required to complete remediation or there is error in scanning. Please check History for more information.\r\r\n OR\r\r\n HRESULT of the scan command if -ReturnHR was specified\r\r\n\r\r\n -Trace [-Grouping value] [-Level value]\r\r\n Begins tracing Microsoft Antimalware Service's actions.\r\r\n You can specify the components for which tracing is enabled and\r\r\n how much information is recorded.\r\r\n If no component is specified, all the components will be logged.\r\r\n If no level is specified, the Error, Warning and Informational levels\r\r\n will be logged. The data will be stored in the support directory\r\r\n as a file having the current timestamp in its name and bearing\r\r\n the extension BIN.\r\r\n\r\r\n [-Grouping]\r\r\n 0x1 Service\r\r\n 0x2 Malware Protection Engine\r\r\n 0x4 User Interface\r\r\n 0x8 Real-Time Protection\r\r\n 0x10 Scheduled actions\r\r\n 0x20 WMI\r\r\n 0x40 NIS/GAPA\r\r\n 0x80 Windows Security Center\r\r\n 0x100 DLP external\r\r\n\r\r\n [-Level]\r\r\n 0x1 Errors\r\r\n 0x2 Warnings\r\r\n 0x4 Informational messages\r\r\n 0x8 Function calls\r\r\n 0x10 Verbose\r\r\n 0x20 Performance\r\r\n\r\r\n -CaptureNetworkTrace -path <path>\r\r\n Captures all the network input into the Network Protection service and \r\r\n saves it to a file at <path>. Supply an empty path to stop tracing\r\r\n Note: The specified path must be writable by LocalService\r\r\n ex: C:\\Users\\Public\\Downloads \r\r\n\r\r\n -GetFiles\r\r\n Gathers the following log files and packages them together in a \r\r\n compressed file in the support directory\r\r\n\r\r\n - Any trace files from Microsoft Antimalware Service\r\r\n - The Windows Update history log\r\r\n - All Microsoft Antimalware Service events from the System event log\r\r\n - All relevant Microsoft Antimalware Service registry locations\r\r\n - The log file of this tool\r\r\n - The log file of the signature update helper tool\r\r\n\r\r\n [-SupportLogLocation <path>]\r\r\n Copies the support logs to the specified <path>. If <path> is not specified,\r\r\n support logs will be copied to the location specified in the SupportLogLocation Configuration.\r\r\n\r\r\n -GetFilesDiagTrack\r\r\n Same as GetFiles, but outputs the CAB file to the temp DiagTrack \r\r\n directory\r\r\n\r\r\n -RemoveDefinitions\r\r\n Restores the last set of signature definitions\r\r\n\r\r\n [-Engine]\r\r\n Restores the last saved engine\r\r\n Use this option to restore the previous engine.\r\r\n\r\r\n [-All]\r\r\n Removes any installed signature and engine files. Use this \r\r\n option if you have difficulties trying to update signatures.\r\r\n\r\r\n [-DynamicSignatures]\r\r\n Removes all Dynamic Signatures. \r\r\n\r\r\n -SignatureUpdate\r\r\n Checks for new definition updates\r\r\n\r\r\n [-UNC [-Path <path>]]\r\r\n Performs update directly from UNC file share specified in <path>\r\r\n If -Path is not specified, update will be performed directly from the\r\r\n preconfigured UNC location\r\r\n\r\r\n [-MMPC]\r\r\n Performs update directly from Microsoft Malware Protection Center\r\r\n\r\r\n -Restore\r\r\n [-ListAll]\r\r\n List all items that were quarantined\r\r\n\r\r\n [-Name <name>]\r\r\n Restores the most recently quarantined item based on threat name\r\r\n One Threat can map to more than one file\r\r\n\r\r\n [-All]\r\r\n Restores all the quarantined items based on name\r\r\n\r\r\n [-FilePath <filePath>]\r\r\n Restores quarantined item based on file path\r\r\n\r\r\n [-Path]\r\r\n Specify the path where the quarantined items will be restored.\r\r\n If not specified, the item will be restored to the original path.\r\r\n -AddDynamicSignature -Path <path> \r\r\n Adds a Dynamic Signature specified by <path>\r\r\n\r\r\n -ListAllDynamicSignatures\r\r\n Lists SignatureSet ID's of all Dynamic Signatures added to the client\r\r\n via MAPS and MPCMDRUN -AddDynamicSignature\r\r\n\r\r\n -RemoveDynamicSignature -SignatureSetID <SignatureSetID> \r\r\n Removes a Dynamic Signature specified by <SignatureSetID>\r\r\n\r\r\n -CheckExclusion -path <path>\r\r\n Checks whether <path> is excluded. It can be either a path, or a file.\r\r\n\r\r\n", "runtime_modules": [ "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2007.8-0\\MpCmdRun.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2007.8-0\\mpclient.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\version.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\SYSTEM32\\gpapi.dll" ] }, "MpDlpCmd.exe-C97B4BF420EB28F996FB2FC881D3864F": { "file_name": "MpDlpCmd.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2007.8-0\\MpDlpCmd.exe", "hash_md5": "C97B4BF420EB28F996FB2FC881D3864F", "hash_sha1": "26399AB0DCCC2DB8E3C656338B3EDDA1F344841F", "hash_sha256": "5144B12FC98F3E601225B4F3CB3545C6BB528E2FB8CBD166F1F3EC9ABCA459AD", "hash_sha384": "DAE8B0E1C4644A949E1841D904928C8FBA0D4F3A12CA3CE0BEFECD5B81980E5742F5B17EDEC93D1785AF056A86832F9B", "hash_sha512": "20DDD6D42B6C595D03F9650586452A981EC243B69BDFDDCD6F86E86B5F21DDE3F0B8DCBC941EC222BA6EB55F41DCEF5304DB44E7EEA59C83096ED211F43E0A94", "hash_ssdeep": "6144:sFBI/ZoNY3S6uQmiTVVmVVV8VVNVVVcVVVxVVVPVVlVVVRVVVtVVWV60jVLVVOVO:sFBI/ZoNY3juyB", "hash_imp": "02825D4A6921DDC8942786A47C533B8B", "hash_pesha1": "A2355846A2DC68978A9ED96F09205AA438EAD270", "hash_pe256": "65A3CE1C042A6A96C3A06B219C75756D8E33139340BA734B9C133AE59B947356", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024A0E8AFDF15C662D2B00000000024A", "signature_thumbprint": "96384A7F5F1C438F32E2454697DC6D312A74517B", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Malware Protection DLP Command Line Utility", "meta_original_filename": "MpDlpCmd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2007.8 (WinBuild.160101.0800)", "meta_product_version": "4.18.2007.8", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/5144b12fc98f3e601225b4f3cb3545c6bb528e2fb8cbd166f1f3ec9abca459ad/detection/", "runtime_modules": [ "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2007.8-0\\MpDlpCmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\SYSTEM32\\UxTheme.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll" ], "output": "MpDlpCmd: Failed with hr = 0x80070667.MpDlpCmd: Invalid command line argument\r\n\r\nUsage: MpDlpCmd -<Command>\r\n" }, "MsMpEng.exe-DBD746AC6FC4BD3A504AA2763BB6FDA8": { "file_name": "MsMpEng.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2007.8-0\\MsMpEng.exe", "hash_md5": "DBD746AC6FC4BD3A504AA2763BB6FDA8", "hash_sha1": "7C9D6E1335FE1AA4BCB0D246E58B2C8441192A0A", "hash_sha256": "35B450F1946D573A37F711CFB4D6DC0385778C71F7CA2A70657DD68C456C40CC", "hash_sha384": "1A40C10A89388C5743933271E12F337022DAC0C9C1BAA99869FB16E0A5122555A7A24104938EF538BA02A453BCCBE22B", "hash_sha512": "BDE122BF1E39BA82E676D0FE79F59D2E41479E602E954D48F68748ACDDEB26E3983896662477B4948E1F5C646764D4AFE757251AEAC66AEA170081304A24EFC9", "hash_ssdeep": "3072:EM8k0I8/TmWYVq/c326i7G1KTecmj1aaWiNb:EMA7mJVtqGZjAaJ", "hash_imp": "2DFE2B101E95D9803D7B3F7C3C2C42BE", "hash_pesha1": "545F9A95686AF0CEAE016B48D5BBC874E014683A", "hash_pe256": "0B1CDA9F73797367209F05C5E9627F8D4A33C0353187627F2828128DE177F0A3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024BB2230A43CD03636200000000024B", "signature_thumbprint": "50AFF9A191126B5BAD57B29846F3B68D550758CA", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Antimalware Service Executable", "meta_original_filename": "MsMpEng.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2007.8 (WinBuild.160101.0800)", "meta_product_version": "4.18.2007.8", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/35b450f1946d573a37f711cfb4d6dc0385778c71f7ca2a70657dd68c456c40cc/detection/" }, "NisSrv.exe-091538ABE1B2C0BEFE53EB5DB3BAED89": { "file_name": "NisSrv.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2007.8-0\\NisSrv.exe", "hash_md5": "091538ABE1B2C0BEFE53EB5DB3BAED89", "hash_sha1": "B45833242E79AFDBD77DA9FF01CCE001F9F8516B", "hash_sha256": "3AB68DDD04335ED4F5A69EC3ADB56CC80E2F2AB849394C07A21D66BDCBD67FF5", "hash_sha384": "C50347F203C0340F6659B679119CA2C7BFE9C58909B0103252AA31665F2E06C8288A528577F3A1F43CDD8183AB0D207F", "hash_sha512": "83449B31CEC68981B6000FB11171A47AB6381881596431B90E6177D3E319B8E9CB1D2E8F5120E5F6FBC307D5C99CA6F42A6828872800EC71E5CA17E9B0E7E8EA", "hash_ssdeep": "49152:mrWcaibdxQ1OHz8Z9SzZ1AAAyQolOM5JeeE2:tKb2Z/2", "hash_imp": "49CCF316E37B15E05F835D2FCF6BBE52", "hash_pesha1": "F3375886A77E6A0504FE6DA142E21A76C4A4CC79", "hash_pe256": "25995C4F9B21F202D580D58B556FB366A58DAB4B7386CC0900254F230E218FE2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024A0E8AFDF15C662D2B00000000024A", "signature_thumbprint": "96384A7F5F1C438F32E2454697DC6D312A74517B", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Network Realtime Inspection Service", "meta_original_filename": "NisSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2007.8 (WinBuild.160101.0800)", "meta_product_version": "4.18.2007.8", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/3ab68ddd04335ed4f5a69ec3adb56cc80e2f2ab849394c07a21d66bdcbd67ff5/detection/", "runtime_modules": [ "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2007.8-0\\NisSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "MpCmdRun.exe-3E41E1307F5ED17BAE3D2C8B23C6356D": { "file_name": "MpCmdRun.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2007.8-0\\X86\\MpCmdRun.exe", "hash_md5": "3E41E1307F5ED17BAE3D2C8B23C6356D", "hash_sha1": "C9FA045B45612B891BD1E9E150B96FBE550A8C1C", "hash_sha256": "3D9A2C370C77A665CED8AAB4864892300259081B3E0ACF5879A9B605F4A46A0B", "hash_sha384": "F22AD92EE0A129EC311EEA707C5BC54246B9BBDF0C6F81EA0BE79EEE563339512A178DC8891A73A0510FDE68FB73FE6F", "hash_sha512": "050E5AE852918A9A6402288E2E578AF73740B06B203F14D431779FEAC207A02E372611572D43B01127F6824A343EABFAE7931FE2E5544FBADB26708E28FBA862", "hash_ssdeep": "6144:Beh9Bp1xwfjxSbkoTUc8PgPoP9YZJD8wg8v4Bu6Mw4V1dNK//VK:vLxKkoTSVYnD8wg8vKu6MV1dm/Q", "hash_imp": "1EEDCE690720909485EC16A7AB6FAA87", "hash_pesha1": "DC01744B17FBCF97DFEDDAE7A05D382C97B3FBF3", "hash_pe256": "3E01ED4EBD62D0B52AE8D70E915354A9F93037F7F9937EF9DB88AA05DEC76315", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024BB2230A43CD03636200000000024B", "signature_thumbprint": "50AFF9A191126B5BAD57B29846F3B68D550758CA", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Malware Protection Command Line Utility", "meta_original_filename": "MpCmdRun.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2007.8 (WinBuild.160101.0800)", "meta_product_version": "4.18.2007.8", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/3d9a2c370c77a665ced8aab4864892300259081b3e0acf5879a9b605f4a46a0b/detection/", "output": "Microsoft Antimalware Service Command Line Utility (c) 2006-2018 Microsoft Corp\r\r\nUse this tool to automate and troubleshoot Microsoft Antimalware Service\r\r\n\r\r\nUsage:\r\r\nMpCmdRun.exe [command] [-options]\r\r\n\r\r\nCommand Description\r\r\n -? / -h Displays all available options\r\r\n for this tool\r\r\n -Scan [-ScanType #] [-File <path> [-DisableRemediation] [-BootSectorScan] [-CpuThrottling]]\r\r\n [-Timeout <days>]\r\r\n [-Cancel]\r\r\n [-ReturnHR]\r\r\n Scans for malicious software\r\r\n -Trace [-Grouping #] [-Level #] Starts diagnostic tracing\r\r\n -GetFiles [-SupportLogLocation <path>] Collects support information\r\r\n -GetFilesDiagTrack Same as Getfiles but outputs to \r\r\n temporary DiagTrack folder \r\r\n -RemoveDefinitions [-All] Restores the installed\r\r\n signature definitions\r\r\n to a previous backup copy or to\r\r\n the original default set of\r\r\n signatures\r\r\n [-Engine] Restore the installed engine to\r\r\n the previous version saved\r\r\n [-DynamicSignatures] Removes only the dynamically\r\r\n downloaded signatures\r\r\n -SignatureUpdate [-UNC | -MMPC] Checks for new definition updates\r\r\n -Restore [-ListAll | [[-Name <name>] [-All] | [-FilePath <filePath>]] [-Path <path>]] Restore or list\r\r\n quarantined item(s)\r\r\n -AddDynamicSignature [-Path] Loads a dynamic signature\r\r\n -ListAllDynamicSignatures List the loaded dynamic signatures\r\r\n -RemoveDynamicSignature [-SignatureSetID] Removes a dynamic signature\r\r\n -CheckExclusion -path <path> Checks whether path is excluded\r\r\n -DownloadFile -URL <url> -path <path> Downloads a file from the given URL\r\r\n to the location given in path. Path\r\r\n should also have the file name in it.\r\r\n\r\r\nAdditional Information:\r\r\n\r\r\nSupport information will be in the following directory:\r\r\nC:\\ProgramData\\Microsoft\\Windows Defender\\Support\r\r\n\r\r\n -Scan [-ScanType value]\r\r\n 0 Default, according to your configuration\r\r\n 1 Quick scan\r\r\n 2 Full system scan\r\r\n 3 File and directory custom scan\r\r\n\r\r\n [-File <path>]\r\r\n Indicates the file or directory to be scanned, only valid for custom scan.\r\r\n\r\r\n [-DisableRemediation]\r\r\n This option is valid only for custom scan.\r\r\n When specified:\r\r\n - File exclusions are ignored.\r\r\n - Archive files are scanned.\r\r\n - Actions are not applied after detection.\r\r\n - Event log entries are not written after detection.\r\r\n - Detections from the custom scan are not displayed in the user interface.\r\r\n - The console output will show the list of detections from the custom scan.\r\r\n\r\r\n [-BootSectorScan]\r\r\n Enables boot sector scanning; only valid for custom scan.\r\r\n\r\r\n [-Timeout <days>]\r\r\n Timeout in days; maximum value is 30.\r\r\n If this parameter is not specified, default value is 7 days for full scan and 1 day for all other scans.\r\r\n\r\r\n [-Cancel]\r\r\n Try to cancel any ongoing quick or full scan.\r\r\n\r\r\n [-CpuThrottling]\r\r\n When specified:\r\r\n - Will ensure that the scan obeys the CPU throttling as defined in the policy (Default 50).\r\r\n\r\r\n [-ReturnHR]\r\r\n Instead of returning the default 0 or 2 values, return the actual HRESULT of the scan command.\r\r\n\r\r\n [DEFAULT]Return code is\r\r\n 0 if no malware is found or malware is successfully remediated and no additional user action is required\r\r\n 2 if malware is found and not remediated or additional user action is required to complete remediation or there is error in scanning. Please check History for more information.\r\r\n OR\r\r\n HRESULT of the scan command if -ReturnHR was specified\r\r\n\r\r\n -Trace [-Grouping value] [-Level value]\r\r\n Begins tracing Microsoft Antimalware Service's actions.\r\r\n You can specify the components for which tracing is enabled and\r\r\n how much information is recorded.\r\r\n If no component is specified, all the components will be logged.\r\r\n If no level is specified, the Error, Warning and Informational levels\r\r\n will be logged. The data will be stored in the support directory\r\r\n as a file having the current timestamp in its name and bearing\r\r\n the extension BIN.\r\r\n\r\r\n [-Grouping]\r\r\n 0x1 Service\r\r\n 0x2 Malware Protection Engine\r\r\n 0x4 User Interface\r\r\n 0x8 Real-Time Protection\r\r\n 0x10 Scheduled actions\r\r\n 0x20 WMI\r\r\n 0x40 NIS/GAPA\r\r\n 0x80 Windows Security Center\r\r\n 0x100 DLP external\r\r\n\r\r\n [-Level]\r\r\n 0x1 Errors\r\r\n 0x2 Warnings\r\r\n 0x4 Informational messages\r\r\n 0x8 Function calls\r\r\n 0x10 Verbose\r\r\n 0x20 Performance\r\r\n\r\r\n -CaptureNetworkTrace -path <path>\r\r\n Captures all the network input into the Network Protection service and \r\r\n saves it to a file at <path>. Supply an empty path to stop tracing\r\r\n Note: The specified path must be writable by LocalService\r\r\n ex: C:\\Users\\Public\\Downloads \r\r\n\r\r\n -GetFiles\r\r\n Gathers the following log files and packages them together in a \r\r\n compressed file in the support directory\r\r\n\r\r\n - Any trace files from Microsoft Antimalware Service\r\r\n - The Windows Update history log\r\r\n - All Microsoft Antimalware Service events from the System event log\r\r\n - All relevant Microsoft Antimalware Service registry locations\r\r\n - The log file of this tool\r\r\n - The log file of the signature update helper tool\r\r\n\r\r\n [-SupportLogLocation <path>]\r\r\n Copies the support logs to the specified <path>. If <path> is not specified,\r\r\n support logs will be copied to the location specified in the SupportLogLocation Configuration.\r\r\n\r\r\n -GetFilesDiagTrack\r\r\n Same as GetFiles, but outputs the CAB file to the temp DiagTrack \r\r\n directory\r\r\n\r\r\n -RemoveDefinitions\r\r\n Restores the last set of signature definitions\r\r\n\r\r\n [-Engine]\r\r\n Restores the last saved engine\r\r\n Use this option to restore the previous engine.\r\r\n\r\r\n [-All]\r\r\n Removes any installed signature and engine files. Use this \r\r\n option if you have difficulties trying to update signatures.\r\r\n\r\r\n [-DynamicSignatures]\r\r\n Removes all Dynamic Signatures. \r\r\n\r\r\n -SignatureUpdate\r\r\n Checks for new definition updates\r\r\n\r\r\n [-UNC [-Path <path>]]\r\r\n Performs update directly from UNC file share specified in <path>\r\r\n If -Path is not specified, update will be performed directly from the\r\r\n preconfigured UNC location\r\r\n\r\r\n [-MMPC]\r\r\n Performs update directly from Microsoft Malware Protection Center\r\r\n\r\r\n -Restore\r\r\n [-ListAll]\r\r\n List all items that were quarantined\r\r\n\r\r\n [-Name <name>]\r\r\n Restores the most recently quarantined item based on threat name\r\r\n One Threat can map to more than one file\r\r\n\r\r\n [-All]\r\r\n Restores all the quarantined items based on name\r\r\n\r\r\n [-FilePath <filePath>]\r\r\n Restores quarantined item based on file path\r\r\n\r\r\n [-Path]\r\r\n Specify the path where the quarantined items will be restored.\r\r\n If not specified, the item will be restored to the original path.\r\r\n -AddDynamicSignature -Path <path> \r\r\n Adds a Dynamic Signature specified by <path>\r\r\n\r\r\n -ListAllDynamicSignatures\r\r\n Lists SignatureSet ID's of all Dynamic Signatures added to the client\r\r\n via MAPS and MPCMDRUN -AddDynamicSignature\r\r\n\r\r\n -RemoveDynamicSignature -SignatureSetID <SignatureSetID> \r\r\n Removes a Dynamic Signature specified by <SignatureSetID>\r\r\n\r\r\n -CheckExclusion -path <path>\r\r\n Checks whether <path> is excluded. It can be either a path, or a file.\r\r\n\r\r\n", "runtime_modules": [ "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2007.8-0\\X86\\MpCmdRun.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MpCmdRun.exe-8342BF358F6681A21B0CD38299034458": { "file_name": "MpCmdRun.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe", "hash_md5": "8342BF358F6681A21B0CD38299034458", "hash_sha1": "26B715999F463C82983D1DEE55CA1EBFA2ED7207", "hash_sha256": "F3A89B19AF1A084C6E827848BDC020C048B9ABCFB0F052DA50EACC37F6FDA1A6", "hash_sha384": "BDDE0A1EC389B668A3F1D4D83C52BF4156979FC09F6A03151578675D9C550D7C935B315C776EF053A8540AB9B9DBDEF4", "hash_sha512": "8F17410C98C4ABD0628D04654E38E6AEC72C47E75749A9FD6A33288CCA3C6512645071103081BC8EB241B8EEA8757BAC7229E68A891DF99EE98EDCE49D2F7A44", "hash_ssdeep": "6144:VnTkwGiumT1c5sygxBj5UUX7FuX2W/eh9BpYxU/Ku6u11CE:VQJXkMgrx7UXJsiuF1CE", "hash_imp": "3D48413FB45D6C25428587AF3E730CB5", "hash_pesha1": "9B6230D82E18A1217C27CFC3B07B18BB01EC3538", "hash_pe256": "A78E7CDFB844F21B90CB357E7695C62178E5B7D674049BCD4C8235483D6D88E2", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024A0E8AFDF15C662D2B00000000024A", "signature_thumbprint": "96384A7F5F1C438F32E2454697DC6D312A74517B", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Malware Protection Command Line Utility", "meta_original_filename": "MpCmdRun.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2008.9 (WinBuild.160101.0800)", "meta_product_version": "4.18.2008.9", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/f3a89b19af1a084c6e827848bdc020c048b9abcfb0f052da50eacc37f6fda1a6/detection/", "output": "Microsoft Antimalware Service Command Line Utility (c) 2006-2020 Microsoft Corp\r\r\nUse this tool to automate and troubleshoot Microsoft Antimalware Service\r\r\n\r\r\nUsage:\r\r\nMpCmdRun.exe [command] [-options]\r\r\n\r\r\nCommand Description\r\r\n -? / -h Displays all available options\r\r\n for this tool\r\r\n -Scan [-ScanType #] [-File <path> [-DisableRemediation] [-BootSectorScan] [-CpuThrottling]]\r\r\n [-Timeout <days>]\r\r\n [-Cancel]\r\r\n [-ReturnHR]\r\r\n Scans for malicious software\r\r\n -Trace [-Grouping #] [-Level #] Starts diagnostic tracing\r\r\n -GetFiles [-SupportLogLocation <path>] Collects support information\r\r\n -GetFilesDiagTrack Same as Getfiles but outputs to \r\r\n temporary DiagTrack folder \r\r\n -RemoveDefinitions [-All] Restores the installed\r\r\n signature definitions\r\r\n to a previous backup copy or to\r\r\n the original default set of\r\r\n signatures\r\r\n [-Engine] Restore the installed engine to\r\r\n the previous version saved\r\r\n [-DynamicSignatures] Removes only the dynamically\r\r\n downloaded signatures\r\r\n -SignatureUpdate [-UNC | -MMPC] Checks for new definition updates\r\r\n -Restore [-ListAll | [[-Name <name>] [-All] | [-FilePath <filePath>]] [-Path <path>]] Restore or list\r\r\n quarantined item(s)\r\r\n -AddDynamicSignature [-Path] Loads a dynamic signature\r\r\n -ListAllDynamicSignatures List the loaded dynamic signatures\r\r\n -RemoveDynamicSignature [-SignatureSetID] Removes a dynamic signature\r\r\n -CheckExclusion -path <path> Checks whether path is excluded\r\r\n -DownloadFile -URL <url> -path <path> Downloads a file from the given URL\r\r\n to the location given in path. Path\r\r\n should also have the file name in it.\r\r\n\r\r\nAdditional Information:\r\r\n\r\r\nSupport information will be in the following directory:\r\r\nC:\\ProgramData\\Microsoft\\Windows Defender\\Support\r\r\n\r\r\n -Scan [-ScanType value]\r\r\n 0 Default, according to your configuration\r\r\n 1 Quick scan\r\r\n 2 Full system scan\r\r\n 3 File and directory custom scan\r\r\n\r\r\n [-File <path>]\r\r\n Indicates the file or directory to be scanned, only valid for custom scan.\r\r\n\r\r\n [-DisableRemediation]\r\r\n This option is valid only for custom scan.\r\r\n When specified:\r\r\n - File exclusions are ignored.\r\r\n - Archive files are scanned.\r\r\n - Actions are not applied after detection.\r\r\n - Event log entries are not written after detection.\r\r\n - Detections from the custom scan are not displayed in the user interface.\r\r\n - The console output will show the list of detections from the custom scan.\r\r\n\r\r\n [-BootSectorScan]\r\r\n Enables boot sector scanning; only valid for custom scan.\r\r\n\r\r\n [-Timeout <days>]\r\r\n Timeout in days; maximum value is 30.\r\r\n If this parameter is not specified, default value is 7 days for full scan and 1 day for all other scans.\r\r\n\r\r\n [-Cancel]\r\r\n Try to cancel any ongoing quick or full scan.\r\r\n\r\r\n [-CpuThrottling]\r\r\n When specified:\r\r\n - Will ensure that the scan obeys the CPU throttling as defined in the policy (Default 50).\r\r\n\r\r\n [-ReturnHR]\r\r\n Instead of returning the default 0 or 2 values, return the actual HRESULT of the scan command.\r\r\n\r\r\n [DEFAULT]Return code is\r\r\n 0 if no malware is found or malware is successfully remediated and no additional user action is required\r\r\n 2 if malware is found and not remediated or additional user action is required to complete remediation or there is error in scanning. Please check History for more information.\r\r\n OR\r\r\n HRESULT of the scan command if -ReturnHR was specified\r\r\n\r\r\n -Trace [-Grouping value] [-Level value]\r\r\n Begins tracing Microsoft Antimalware Service's actions.\r\r\n You can specify the components for which tracing is enabled and\r\r\n how much information is recorded.\r\r\n If no component is specified, all the components will be logged.\r\r\n If no level is specified, the Error, Warning and Informational levels\r\r\n will be logged. The data will be stored in the support directory\r\r\n as a file having the current timestamp in its name and bearing\r\r\n the extension BIN.\r\r\n\r\r\n [-Grouping]\r\r\n 0x1 Service\r\r\n 0x2 Malware Protection Engine\r\r\n 0x4 User Interface\r\r\n 0x8 Real-Time Protection\r\r\n 0x10 Scheduled actions\r\r\n 0x20 WMI\r\r\n 0x40 NIS/GAPA\r\r\n 0x80 Windows Security Center\r\r\n 0x100 DLP external\r\r\n\r\r\n [-Level]\r\r\n 0x1 Errors\r\r\n 0x2 Warnings\r\r\n 0x4 Informational messages\r\r\n 0x8 Function calls\r\r\n 0x10 Verbose\r\r\n 0x20 Performance\r\r\n\r\r\n -CaptureNetworkTrace -path <path>\r\r\n Captures all the network input into the Network Protection service and \r\r\n saves it to a file at <path>. Supply an empty path to stop tracing\r\r\n Note: The specified path must be writable by LocalService\r\r\n ex: C:\\Users\\Public\\Downloads \r\r\n\r\r\n -GetFiles\r\r\n Gathers the following log files and packages them together in a \r\r\n compressed file in the support directory\r\r\n\r\r\n - Any trace files from Microsoft Antimalware Service\r\r\n - The Windows Update history log\r\r\n - All Microsoft Antimalware Service events from the System event log\r\r\n - All relevant Microsoft Antimalware Service registry locations\r\r\n - The log file of this tool\r\r\n - The log file of the signature update helper tool\r\r\n\r\r\n [-SupportLogLocation <path>]\r\r\n Copies the support logs to the specified <path>. If <path> is not specified,\r\r\n support logs will be copied to the location specified in the SupportLogLocation Configuration.\r\r\n\r\r\n -GetFilesDiagTrack\r\r\n Same as GetFiles, but outputs the CAB file to the temp DiagTrack \r\r\n directory\r\r\n\r\r\n -RemoveDefinitions\r\r\n Restores the last set of signature definitions\r\r\n\r\r\n [-Engine]\r\r\n Restores the last saved engine\r\r\n Use this option to restore the previous engine.\r\r\n\r\r\n [-All]\r\r\n Removes any installed signature and engine files. Use this \r\r\n option if you have difficulties trying to update signatures.\r\r\n\r\r\n [-DynamicSignatures]\r\r\n Removes all Dynamic Signatures. \r\r\n\r\r\n -SignatureUpdate\r\r\n Checks for new definition updates\r\r\n\r\r\n [-UNC [-Path <path>]]\r\r\n Performs update directly from UNC file share specified in <path>\r\r\n If -Path is not specified, update will be performed directly from the\r\r\n preconfigured UNC location\r\r\n\r\r\n [-MMPC]\r\r\n Performs update directly from Microsoft Malware Protection Center\r\r\n\r\r\n -Restore\r\r\n [-ListAll]\r\r\n List all items that were quarantined\r\r\n\r\r\n [-Name <name>]\r\r\n Restores the most recently quarantined item based on threat name\r\r\n One Threat can map to more than one file\r\r\n\r\r\n [-All]\r\r\n Restores all the quarantined items based on name\r\r\n\r\r\n [-FilePath <filePath>]\r\r\n Restores quarantined item based on file path\r\r\n\r\r\n [-Path]\r\r\n Specify the path where the quarantined items will be restored.\r\r\n If not specified, the item will be restored to the original path.\r\r\n -AddDynamicSignature -Path <path> \r\r\n Adds a Dynamic Signature specified by <path>\r\r\n\r\r\n -ListAllDynamicSignatures\r\r\n Lists SignatureSet ID's of all Dynamic Signatures added to the client\r\r\n via MAPS and MPCMDRUN -AddDynamicSignature\r\r\n\r\r\n -RemoveDynamicSignature -SignatureSetID <SignatureSetID> \r\r\n Removes a Dynamic Signature specified by <SignatureSetID>\r\r\n\r\r\n -CheckExclusion -path <path>\r\r\n Checks whether <path> is excluded. It can be either a path, or a file.\r\r\n\r\r\n", "runtime_modules": [ "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\mpclient.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\version.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "MpDlpCmd.exe-DB96C707FEBDFE8B5F6F11C2DD78073C": { "file_name": "MpDlpCmd.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpDlpCmd.exe", "hash_md5": "DB96C707FEBDFE8B5F6F11C2DD78073C", "hash_sha1": "5B497AB1EF4A769061951805A8EA183AA8961152", "hash_sha256": "9D5A5D804B4AD306F8F08F1D3CFD1DD80255CD8DB745F648643DC4BADDC5660E", "hash_sha384": "228E35671E195E1DD158AB6ED80ED0D9A9103CDFEC2A5ABA5E60B98B9CF4DAC3FBC81CEAE94CB80F38FE2FD41C827A0E", "hash_sha512": "557B380D0B8949D970E6987F4DBD96B51D6DE9571ADD1B6F4AC2B4CA1F35CED7808B2FCD7FB7DA0D04197DD8E4FC4710D1676834E73687CA16FFF8BACA179148", "hash_ssdeep": "6144:s6UjT4MJM3gOiu0miTVVmVVV8VVNVVVcVVVxVVVPVVlVVVRVVVtVVWV60jVLVVOk:sr4MJM3Diue1", "hash_imp": "1AE5F3EDF63DC3F39328634CE0A93C2B", "hash_pesha1": "0D91CD2C88BB212A818CB8F68599D5BD038AAB2B", "hash_pe256": "6F3B997EA130A313C9C9682B40AE5D9D848777EFA164AB168E7EF225C4B8B14C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024A0E8AFDF15C662D2B00000000024A", "signature_thumbprint": "96384A7F5F1C438F32E2454697DC6D312A74517B", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Malware Protection DLP Command Line Utility", "meta_original_filename": "MpDlpCmd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2008.9 (WinBuild.160101.0800)", "meta_product_version": "4.18.2008.9", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/9d5a5d804b4ad306f8f08f1d3cfd1dd80255cd8db745f648643dc4baddc5660e/detection/", "output": "MpDlpCmd: Failed with hr = 0x80070667.MpDlpCmd: Invalid command line argument\r\n\r\nUsage: MpDlpCmd -<Command>\r\n", "runtime_modules": [ "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpDlpCmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "MsMpEng.exe-134CAD0C9C405F644C7592701EE695A1": { "file_name": "MsMpEng.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MsMpEng.exe", "hash_md5": "134CAD0C9C405F644C7592701EE695A1", "hash_sha1": "9D014808CBA7A33B6FA58576734B1074D2301260", "hash_sha256": "98F2679F37260CDDBCE40CEFDC2A6F26450B1DD1271F2F43311D61A4A8229C96", "hash_sha384": "B84E85BE5D2F1ED5584C470ABE6260858FC67BE5F723713B57646392DF7E715AC8FAE066024258EC13D78A49C993CF7E", "hash_sha512": "7B2F5C72521047628C48C00D8B2AB46B657F0815288248A008180DA2967590B81FEFFB2547DC8C3A18FC2F2E127901016A666D7350F9B2D7CF17B37DB737843F", "hash_ssdeep": "3072:l9vYfT+Tb7MJx/iB+5KTeEr8kHhlqCwRF:lhYb+TbOo4+phPQ", "hash_imp": "2DFE2B101E95D9803D7B3F7C3C2C42BE", "hash_pesha1": "72A65AE6E168471B5934509A67D0411D39AAA6D7", "hash_pe256": "A671B51F49239EDB0A645F30B5036FD23D4D809237820576D5BAD6B0F49944EB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024A0E8AFDF15C662D2B00000000024A", "signature_thumbprint": "96384A7F5F1C438F32E2454697DC6D312A74517B", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Antimalware Service Executable", "meta_original_filename": "MsMpEng.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2008.9 (WinBuild.160101.0800)", "meta_product_version": "4.18.2008.9", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/98f2679f37260cddbce40cefdc2a6f26450b1dd1271f2f43311d61a4a8229c96/detection/" }, "NisSrv.exe-C519BE0369AA79BD30D744EBB54C296C": { "file_name": "NisSrv.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\NisSrv.exe", "hash_md5": "C519BE0369AA79BD30D744EBB54C296C", "hash_sha1": "4F73FA06D716DE090E7299B6B88BF9938B6479E3", "hash_sha256": "7771F332FFB71B2C9668DE3C5AA14617E26D00A21C931DEB2DCE0776CA3EE02A", "hash_sha384": "E54B61C87343A9D56AC3E3503E073BB049447DB325EC523D11157D334CC5068F78270E1792E668EE2F77ED9C7D0E1367", "hash_sha512": "D8BB374AB42799EED413B677AEEF2097B20A0DF5BA0FFEDB8632FD4E9095EADD0E3612AEB106D423193F770383F173FE1B1B376993BEB04D404B30DF154C4AA0", "hash_ssdeep": "49152:ehfaICkvvT4YAhYc+wjrMsunQrBTSSy7RcbMV3AMFSl09zhXgeHibn:eKNYs8ir", "hash_imp": "4DECE0E26698C1D6E3536B7EDD46D8F1", "hash_pesha1": "594C999E8704AA9461B1449A750C7A83C9745D4E", "hash_pe256": "F88F13FD89B82BA33A3E556BB3B4CB80F3B7351B1FDD44A80C187C20DCCB468F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024A0E8AFDF15C662D2B00000000024A", "signature_thumbprint": "96384A7F5F1C438F32E2454697DC6D312A74517B", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Network Realtime Inspection Service", "meta_original_filename": "NisSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2008.9 (WinBuild.160101.0800)", "meta_product_version": "4.18.2008.9", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/7771f332ffb71b2c9668de3c5aa14617e26d00a21c931deb2dce0776ca3ee02a/detection/" }, "MpCmdRun.exe-AC330E80331BE4EBE176AD976215F020": { "file_name": "MpCmdRun.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\X86\\MpCmdRun.exe", "hash_md5": "AC330E80331BE4EBE176AD976215F020", "hash_sha1": "2D4DC0B0CFCB25FFAAFE0F0951F7AE9B2E007361", "hash_sha256": "8AE272396DCA1EA6FE09E2982C3C4727A926371AB4B904C188B570D5D5D193E1", "hash_sha384": "F2B509415CE1110E0E3B8CD037D7C22D2FFAED9E7348F51C769237D88F2261DE84D15BDFBBA1FB7FFE42100BCF7768AA", "hash_sha512": "3E95A6F3A2FC81D7781CA61106F4220CFDBEF989406E1728984BB5687D9BE318847540D7CE37BD07F59B5B1CF3FE1D85AA95FBA208FA81E1DF248E37B87B0AEB", "hash_ssdeep": "6144:G1eh9BpFx+DqKE4wjna4290c3oWZhZ1ZDxoaHQpI9zBu4DaRO8XbcL4dUk:GlvE4wjanV1YaHQG9du4Da9XM4dn", "hash_imp": "2BBC7CF6F4B8F8DDD8763575A3FE5EBB", "hash_pesha1": "BF1F8FEBC5994270C1BD28E0EE38F5DEC89A8B2A", "hash_pe256": "0871DB68692BE5093DD9D54CAF50303617F6BA09DD32634566F37240EA084141", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024A0E8AFDF15C662D2B00000000024A", "signature_thumbprint": "96384A7F5F1C438F32E2454697DC6D312A74517B", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Malware Protection Command Line Utility", "meta_original_filename": "MpCmdRun.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2008.9 (WinBuild.160101.0800)", "meta_product_version": "4.18.2008.9", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/8ae272396dca1ea6fe09e2982c3c4727a926371ab4b904c188b570d5d5d193e1/detection/", "output": "Microsoft Antimalware Service Command Line Utility (c) 2006-2020 Microsoft Corp\r\r\nUse this tool to automate and troubleshoot Microsoft Antimalware Service\r\r\n\r\r\nUsage:\r\r\nMpCmdRun.exe [command] [-options]\r\r\n\r\r\nCommand Description\r\r\n -? / -h Displays all available options\r\r\n for this tool\r\r\n -Scan [-ScanType #] [-File <path> [-DisableRemediation] [-BootSectorScan] [-CpuThrottling]]\r\r\n [-Timeout <days>]\r\r\n [-Cancel]\r\r\n [-ReturnHR]\r\r\n Scans for malicious software\r\r\n -Trace [-Grouping #] [-Level #] Starts diagnostic tracing\r\r\n -GetFiles [-SupportLogLocation <path>] Collects support information\r\r\n -GetFilesDiagTrack Same as Getfiles but outputs to \r\r\n temporary DiagTrack folder \r\r\n -RemoveDefinitions [-All] Restores the installed\r\r\n signature definitions\r\r\n to a previous backup copy or to\r\r\n the original default set of\r\r\n signatures\r\r\n [-Engine] Restore the installed engine to\r\r\n the previous version saved\r\r\n [-DynamicSignatures] Removes only the dynamically\r\r\n downloaded signatures\r\r\n -SignatureUpdate [-UNC | -MMPC] Checks for new definition updates\r\r\n -Restore [-ListAll | [[-Name <name>] [-All] | [-FilePath <filePath>]] [-Path <path>]] Restore or list\r\r\n quarantined item(s)\r\r\n -AddDynamicSignature [-Path] Loads a dynamic signature\r\r\n -ListAllDynamicSignatures List the loaded dynamic signatures\r\r\n -RemoveDynamicSignature [-SignatureSetID] Removes a dynamic signature\r\r\n -CheckExclusion -path <path> Checks whether path is excluded\r\r\n -DownloadFile -URL <url> -path <path> Downloads a file from the given URL\r\r\n to the location given in path. Path\r\r\n should also have the file name in it.\r\r\n\r\r\nAdditional Information:\r\r\n\r\r\nSupport information will be in the following directory:\r\r\nC:\\ProgramData\\Microsoft\\Windows Defender\\Support\r\r\n\r\r\n -Scan [-ScanType value]\r\r\n 0 Default, according to your configuration\r\r\n 1 Quick scan\r\r\n 2 Full system scan\r\r\n 3 File and directory custom scan\r\r\n\r\r\n [-File <path>]\r\r\n Indicates the file or directory to be scanned, only valid for custom scan.\r\r\n\r\r\n [-DisableRemediation]\r\r\n This option is valid only for custom scan.\r\r\n When specified:\r\r\n - File exclusions are ignored.\r\r\n - Archive files are scanned.\r\r\n - Actions are not applied after detection.\r\r\n - Event log entries are not written after detection.\r\r\n - Detections from the custom scan are not displayed in the user interface.\r\r\n - The console output will show the list of detections from the custom scan.\r\r\n\r\r\n [-BootSectorScan]\r\r\n Enables boot sector scanning; only valid for custom scan.\r\r\n\r\r\n [-Timeout <days>]\r\r\n Timeout in days; maximum value is 30.\r\r\n If this parameter is not specified, default value is 7 days for full scan and 1 day for all other scans.\r\r\n\r\r\n [-Cancel]\r\r\n Try to cancel any ongoing quick or full scan.\r\r\n\r\r\n [-CpuThrottling]\r\r\n When specified:\r\r\n - Will ensure that the scan obeys the CPU throttling as defined in the policy (Default 50).\r\r\n\r\r\n [-ReturnHR]\r\r\n Instead of returning the default 0 or 2 values, return the actual HRESULT of the scan command.\r\r\n\r\r\n [DEFAULT]Return code is\r\r\n 0 if no malware is found or malware is successfully remediated and no additional user action is required\r\r\n 2 if malware is found and not remediated or additional user action is required to complete remediation or there is error in scanning. Please check History for more information.\r\r\n OR\r\r\n HRESULT of the scan command if -ReturnHR was specified\r\r\n\r\r\n -Trace [-Grouping value] [-Level value]\r\r\n Begins tracing Microsoft Antimalware Service's actions.\r\r\n You can specify the components for which tracing is enabled and\r\r\n how much information is recorded.\r\r\n If no component is specified, all the components will be logged.\r\r\n If no level is specified, the Error, Warning and Informational levels\r\r\n will be logged. The data will be stored in the support directory\r\r\n as a file having the current timestamp in its name and bearing\r\r\n the extension BIN.\r\r\n\r\r\n [-Grouping]\r\r\n 0x1 Service\r\r\n 0x2 Malware Protection Engine\r\r\n 0x4 User Interface\r\r\n 0x8 Real-Time Protection\r\r\n 0x10 Scheduled actions\r\r\n 0x20 WMI\r\r\n 0x40 NIS/GAPA\r\r\n 0x80 Windows Security Center\r\r\n 0x100 DLP external\r\r\n\r\r\n [-Level]\r\r\n 0x1 Errors\r\r\n 0x2 Warnings\r\r\n 0x4 Informational messages\r\r\n 0x8 Function calls\r\r\n 0x10 Verbose\r\r\n 0x20 Performance\r\r\n\r\r\n -CaptureNetworkTrace -path <path>\r\r\n Captures all the network input into the Network Protection service and \r\r\n saves it to a file at <path>. Supply an empty path to stop tracing\r\r\n Note: The specified path must be writable by LocalService\r\r\n ex: C:\\Users\\Public\\Downloads \r\r\n\r\r\n -GetFiles\r\r\n Gathers the following log files and packages them together in a \r\r\n compressed file in the support directory\r\r\n\r\r\n - Any trace files from Microsoft Antimalware Service\r\r\n - The Windows Update history log\r\r\n - All Microsoft Antimalware Service events from the System event log\r\r\n - All relevant Microsoft Antimalware Service registry locations\r\r\n - The log file of this tool\r\r\n - The log file of the signature update helper tool\r\r\n\r\r\n [-SupportLogLocation <path>]\r\r\n Copies the support logs to the specified <path>. If <path> is not specified,\r\r\n support logs will be copied to the location specified in the SupportLogLocation Configuration.\r\r\n\r\r\n -GetFilesDiagTrack\r\r\n Same as GetFiles, but outputs the CAB file to the temp DiagTrack \r\r\n directory\r\r\n\r\r\n -RemoveDefinitions\r\r\n Restores the last set of signature definitions\r\r\n\r\r\n [-Engine]\r\r\n Restores the last saved engine\r\r\n Use this option to restore the previous engine.\r\r\n\r\r\n [-All]\r\r\n Removes any installed signature and engine files. Use this \r\r\n option if you have difficulties trying to update signatures.\r\r\n\r\r\n [-DynamicSignatures]\r\r\n Removes all Dynamic Signatures. \r\r\n\r\r\n -SignatureUpdate\r\r\n Checks for new definition updates\r\r\n\r\r\n [-UNC [-Path <path>]]\r\r\n Performs update directly from UNC file share specified in <path>\r\r\n If -Path is not specified, update will be performed directly from the\r\r\n preconfigured UNC location\r\r\n\r\r\n [-MMPC]\r\r\n Performs update directly from Microsoft Malware Protection Center\r\r\n\r\r\n -Restore\r\r\n [-ListAll]\r\r\n List all items that were quarantined\r\r\n\r\r\n [-Name <name>]\r\r\n Restores the most recently quarantined item based on threat name\r\r\n One Threat can map to more than one file\r\r\n\r\r\n [-All]\r\r\n Restores all the quarantined items based on name\r\r\n\r\r\n [-FilePath <filePath>]\r\r\n Restores quarantined item based on file path\r\r\n\r\r\n [-Path]\r\r\n Specify the path where the quarantined items will be restored.\r\r\n If not specified, the item will be restored to the original path.\r\r\n -AddDynamicSignature -Path <path> \r\r\n Adds a Dynamic Signature specified by <path>\r\r\n\r\r\n -ListAllDynamicSignatures\r\r\n Lists SignatureSet ID's of all Dynamic Signatures added to the client\r\r\n via MAPS and MPCMDRUN -AddDynamicSignature\r\r\n\r\r\n -RemoveDynamicSignature -SignatureSetID <SignatureSetID> \r\r\n Removes a Dynamic Signature specified by <SignatureSetID>\r\r\n\r\r\n -CheckExclusion -path <path>\r\r\n Checks whether <path> is excluded. It can be either a path, or a file.\r\r\n\r\r\n", "runtime_modules": [ "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\X86\\MpCmdRun.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "MpCmdRun.exe-6A50F452AE086B197AB5DCDB36C93774": { "file_name": "MpCmdRun.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2009.7-0\\MpCmdRun.exe", "hash_md5": "6A50F452AE086B197AB5DCDB36C93774", "hash_sha1": "93737916061D4D98A48F8B4C14A568066EE99635", "hash_sha256": "AEC93378D5B4441FA8B813D62175575C056B6B88154E073F417A960CF844590A", "hash_sha384": "DB5FC5E377C9194C4784FD9C7B3363080DE7035CB639DABA2DBDF217881D256EB328BD00082074F1F85AFB519BD0D50B", "hash_sha512": "CAB1AC0F392612ECD1FC6F00B637EA1D4D69DFE9043C5BACDFACFB663F3B44921B49CA407E26C537B7A28E5DFD483CB9AA3C0A173269F6EF5D51E063744D7A2E", "hash_ssdeep": "6144:GPxYuEUYfGXxqSYTl6EIZOdUyqcYDH7nReI9Bp/xPle3OAdYBP6:GquEUNYh6ELdkDDbnXoNg6", "hash_imp": "05A2151F8131515608FDEEE284FC480E", "hash_pesha1": "E304DF2557CECF919544253EEE4A7D005BB9CFB2", "hash_pe256": "C98FA3D35F92B8852B1E94329A387DF8EB94CCC9FF7D4C01A6BE32123594DB66", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024A0E8AFDF15C662D2B00000000024A", "signature_thumbprint": "96384A7F5F1C438F32E2454697DC6D312A74517B", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Malware Protection Command Line Utility", "meta_original_filename": "MpCmdRun.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2009.7 (WinBuild.160101.0800)", "meta_product_version": "4.18.2009.7", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/aec93378d5b4441fa8b813d62175575c056b6b88154e073f417a960cf844590a/detection/", "output": "Microsoft Antimalware Service Command Line Utility (c) 2006-2020 Microsoft Corp\r\r\nUse this tool to automate and troubleshoot Microsoft Antimalware Service\r\r\n\r\r\nUsage:\r\r\nMpCmdRun.exe [command] [-options]\r\r\n\r\r\nCommand Description\r\r\n -? / -h Displays all available options\r\r\n for this tool\r\r\n -Scan [-ScanType #] [-File <path> [-DisableRemediation] [-BootSectorScan] [-CpuThrottling]]\r\r\n [-Timeout <days>]\r\r\n [-Cancel]\r\r\n [-ReturnHR]\r\r\n Scans for malicious software\r\r\n -Trace [-Grouping #] [-Level #] Starts diagnostic tracing\r\r\n -GetFiles [-SupportLogLocation <path>] Collects support information\r\r\n -GetFilesDiagTrack Same as Getfiles but outputs to \r\r\n temporary DiagTrack folder \r\r\n -RemoveDefinitions [-All] Restores the installed\r\r\n signature definitions\r\r\n to a previous backup copy or to\r\r\n the original default set of\r\r\n signatures\r\r\n [-Engine] Restore the installed engine to\r\r\n the previous version saved\r\r\n [-DynamicSignatures] Removes only the dynamically\r\r\n downloaded signatures\r\r\n -SignatureUpdate [-UNC | -MMPC] Checks for new definition updates\r\r\n -Restore [-ListAll | [[-Name <name>] [-All] | [-FilePath <filePath>]] [-Path <path>]] Restore or list\r\r\n quarantined item(s)\r\r\n -AddDynamicSignature [-Path] Loads a dynamic signature\r\r\n -ListAllDynamicSignatures List the loaded dynamic signatures\r\r\n -RemoveDynamicSignature [-SignatureSetID] Removes a dynamic signature\r\r\n -CheckExclusion -path <path> Checks whether path is excluded\r\r\n\r\r\nAdditional Information:\r\r\n\r\r\nSupport information will be in the following directory:\r\r\nC:\\ProgramData\\Microsoft\\Windows Defender\\Support\r\r\n\r\r\n -Scan [-ScanType value]\r\r\n 0 Default, according to your configuration\r\r\n 1 Quick scan\r\r\n 2 Full system scan\r\r\n 3 File and directory custom scan\r\r\n\r\r\n [-File <path>]\r\r\n Indicates the file or directory to be scanned, only valid for custom scan.\r\r\n\r\r\n [-DisableRemediation]\r\r\n This option is valid only for custom scan.\r\r\n When specified:\r\r\n - File exclusions are ignored.\r\r\n - Archive files are scanned.\r\r\n - Actions are not applied after detection.\r\r\n - Event log entries are not written after detection.\r\r\n - Detections from the custom scan are not displayed in the user interface.\r\r\n - The console output will show the list of detections from the custom scan.\r\r\n\r\r\n [-BootSectorScan]\r\r\n Enables boot sector scanning; only valid for custom scan.\r\r\n\r\r\n [-Timeout <days>]\r\r\n Timeout in days; maximum value is 30.\r\r\n If this parameter is not specified, default value is 7 days for full scan and 1 day for all other scans.\r\r\n\r\r\n [-Cancel]\r\r\n Try to cancel any ongoing quick or full scan.\r\r\n\r\r\n [-CpuThrottling]\r\r\n When specified:\r\r\n - Will ensure that the scan obeys the CPU throttling as defined in the policy (Default 50).\r\r\n\r\r\n [-ReturnHR]\r\r\n Instead of returning the default 0 or 2 values, return the actual HRESULT of the scan command.\r\r\n\r\r\n [DEFAULT]Return code is\r\r\n 0 if no malware is found or malware is successfully remediated and no additional user action is required\r\r\n 2 if malware is found and not remediated or additional user action is required to complete remediation or there is error in scanning. Please check History for more information.\r\r\n OR\r\r\n HRESULT of the scan command if -ReturnHR was specified\r\r\n\r\r\n -Trace [-Grouping value] [-Level value]\r\r\n Begins tracing Microsoft Antimalware Service's actions.\r\r\n You can specify the components for which tracing is enabled and\r\r\n how much information is recorded.\r\r\n If no component is specified, all the components will be logged.\r\r\n If no level is specified, the Error, Warning and Informational levels\r\r\n will be logged. The data will be stored in the support directory\r\r\n as a file having the current timestamp in its name and bearing\r\r\n the extension BIN.\r\r\n\r\r\n [-Grouping]\r\r\n 0x1 Service\r\r\n 0x2 Malware Protection Engine\r\r\n 0x4 User Interface\r\r\n 0x8 Real-Time Protection\r\r\n 0x10 Scheduled actions\r\r\n 0x20 WMI\r\r\n 0x40 NIS/GAPA\r\r\n 0x80 Windows Security Center\r\r\n 0x100 DLP external\r\r\n\r\r\n [-Level]\r\r\n 0x1 Errors\r\r\n 0x2 Warnings\r\r\n 0x4 Informational messages\r\r\n 0x8 Function calls\r\r\n 0x10 Verbose\r\r\n 0x20 Performance\r\r\n\r\r\n -CaptureNetworkTrace -path <path>\r\r\n Captures all the network input into the Network Protection service and \r\r\n saves it to a file at <path>. Supply an empty path to stop tracing\r\r\n Note: The specified path must be writable by LocalService\r\r\n ex: C:\\Users\\Public\\Downloads \r\r\n\r\r\n -GetFiles\r\r\n Gathers the following log files and packages them together in a \r\r\n compressed file in the support directory\r\r\n\r\r\n - Any trace files from Microsoft Antimalware Service\r\r\n - The Windows Update history log\r\r\n - All Microsoft Antimalware Service events from the System event log\r\r\n - All relevant Microsoft Antimalware Service registry locations\r\r\n - The log file of this tool\r\r\n - The log file of the signature update helper tool\r\r\n\r\r\n [-SupportLogLocation <path>]\r\r\n Copies the support logs to the specified <path>. If <path> is not specified,\r\r\n support logs will be copied to the location specified in the SupportLogLocation Configuration.\r\r\n\r\r\n -GetFilesDiagTrack\r\r\n Same as GetFiles, but outputs the CAB file to the temp DiagTrack \r\r\n directory\r\r\n\r\r\n -RemoveDefinitions\r\r\n Restores the last set of signature definitions\r\r\n\r\r\n [-Engine]\r\r\n Restores the last saved engine\r\r\n Use this option to restore the previous engine.\r\r\n\r\r\n [-All]\r\r\n Removes any installed signature and engine files. Use this \r\r\n option if you have difficulties trying to update signatures.\r\r\n\r\r\n [-DynamicSignatures]\r\r\n Removes all Dynamic Signatures. \r\r\n\r\r\n -SignatureUpdate\r\r\n Checks for new definition updates\r\r\n\r\r\n [-UNC [-Path <path>]]\r\r\n Performs update directly from UNC file share specified in <path>\r\r\n If -Path is not specified, update will be performed directly from the\r\r\n preconfigured UNC location\r\r\n\r\r\n [-MMPC]\r\r\n Performs update directly from Microsoft Malware Protection Center\r\r\n\r\r\n -Restore\r\r\n [-ListAll]\r\r\n List all items that were quarantined\r\r\n\r\r\n [-Name <name>]\r\r\n Restores the most recently quarantined item based on threat name\r\r\n One Threat can map to more than one file\r\r\n\r\r\n [-All]\r\r\n Restores all the quarantined items based on name\r\r\n\r\r\n [-FilePath <filePath>]\r\r\n Restores quarantined item based on file path\r\r\n\r\r\n [-Path]\r\r\n Specify the path where the quarantined items will be restored.\r\r\n If not specified, the item will be restored to the original path.\r\r\n -AddDynamicSignature -Path <path> \r\r\n Adds a Dynamic Signature specified by <path>\r\r\n\r\r\n -ListAllDynamicSignatures\r\r\n Lists SignatureSet ID's of all Dynamic Signatures added to the client\r\r\n via MAPS and MPCMDRUN -AddDynamicSignature\r\r\n\r\r\n -RemoveDynamicSignature -SignatureSetID <SignatureSetID> \r\r\n Removes a Dynamic Signature specified by <SignatureSetID>\r\r\n\r\r\n -CheckExclusion -path <path>\r\r\n Checks whether <path> is excluded. It can be either a path, or a file.\r\r\n\r\r\n", "runtime_modules": [ "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2009.7-0\\MpCmdRun.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2009.7-0\\mpclient.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\system32\\version.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\SYSTEM32\\gpapi.dll" ] }, "MpDlpCmd.exe-8552968F117AECCD72B5CCC5C092BD83": { "file_name": "MpDlpCmd.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2009.7-0\\MpDlpCmd.exe", "hash_md5": "8552968F117AECCD72B5CCC5C092BD83", "hash_sha1": "B6C44F4CC97594244BE4F412D186530836267F84", "hash_sha256": "65E60B3657B58AC9D61C67E7AA9160646E8D2FEEE3C998FEF943B365B902718B", "hash_sha384": "3F4393F76ADBA89E23676C2BA2BC12D105059109F9EB0F265A6B98BCAA7C37007EBC0D08B0542DFC55F400D8DEDD200B", "hash_sha512": "4429FF32905F857511984B29334B80C93BCAE1D3A6EE5DFB33BA70CF1E8DFD65C23755D6C9BE631F031FF763F30402B52D4A0063890833FB1C85EEDAF3BD7035", "hash_ssdeep": "6144:HyUbbAMV+L9OiuwmiTVVmVVV8VVNVVVcVVVxVVVPVVlVVVRVVVtVVWV60jVLVVO1:HDAMV+LgiuSk", "hash_imp": "F15B67A00B2CE6353DCB4070F8E5D10B", "hash_pesha1": "097ED9E8C4CCFA290F05D4FF6E2C136501F55A60", "hash_pe256": "4BA4EF91EBEBB830EFEC63E9FE48FA76F8DA2EA8FBEBEB5CD857018289DE2901", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024A0E8AFDF15C662D2B00000000024A", "signature_thumbprint": "96384A7F5F1C438F32E2454697DC6D312A74517B", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Malware Protection DLP Command Line Utility", "meta_original_filename": "MpDlpCmd.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2009.7 (WinBuild.160101.0800)", "meta_product_version": "4.18.2009.7", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/65e60b3657b58ac9d61c67e7aa9160646e8d2feee3c998fef943b365b902718b/detection/", "runtime_modules": [ "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2009.7-0\\MpDlpCmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "output": "MpDlpCmd: Failed with hr = 0x80070667.MpDlpCmd: Invalid command line argument\r\n\r\nUsage: MpDlpCmd -<Command>\r\n" }, "MsMpEng.exe-F54E7E584C472FFF2B741C05F8CDC766": { "file_name": "MsMpEng.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2009.7-0\\MsMpEng.exe", "hash_md5": "F54E7E584C472FFF2B741C05F8CDC766", "hash_sha1": "17AC1041F0AF35F7FF6823C326D0AA8F20CD71AA", "hash_sha256": "03D99B46FFF022D7B8BDCDF52D25AB21B30F2346E3B388E22804EF5D6E1AE08F", "hash_sha384": "BB607F2AD89EC0EAD9DEE8BDBB2357DBE722E7DB5724C9AA6015B7BE8EEBC795AD6DD78C451A49BEFB641A7C5FECE6DE", "hash_sha512": "4B7C88FADF7FC989F9C691220EB475C9959A70DA91BD6DE8B16836AB6A52E06A543104380D59B0004E365CB51C92A12846315022A2BCA2143271AD7E886BAB3F", "hash_ssdeep": "3072:x9vYfT+Tb7MJx/iB+uKTe4BkHhlqCTWaByo:xhYb+TbOo4qhPd", "hash_imp": "2DFE2B101E95D9803D7B3F7C3C2C42BE", "hash_pesha1": "D07319ECEB6750512972B52184717CB4A7250F35", "hash_pe256": "ACC2D1B7C10FA1ACFAAC9ABA4A808B4092B9E78BF232F3DA4B2AFB78A6719B97", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024A0E8AFDF15C662D2B00000000024A", "signature_thumbprint": "96384A7F5F1C438F32E2454697DC6D312A74517B", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Antimalware Service Executable", "meta_original_filename": "MsMpEng.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2009.7 (WinBuild.160101.0800)", "meta_product_version": "4.18.2009.7", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/03d99b46fff022d7b8bdcdf52d25ab21b30f2346e3b388e22804ef5d6e1ae08f/detection/" }, "NisSrv.exe-5260C83AD82BC4499D47706DCD0FE0CE": { "file_name": "NisSrv.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2009.7-0\\NisSrv.exe", "hash_md5": "5260C83AD82BC4499D47706DCD0FE0CE", "hash_sha1": "3164093FC90E35F91F22E0E13B9C61813DC9D0B9", "hash_sha256": "5B33BB9040F40E2D5022E37F725471F39F14DD4A63EE945537BC0B899B583CE5", "hash_sha384": "3A62D58B11A7755649CDCB82B222784607948813B321778E4DDEE07933501026F9B65DCFD567159250B35E58F29893D0", "hash_sha512": "54150654C24AD355EEC9EEE23E04A9FFB6E647E08B636428C0EAAB98C8146518E0DF6B8283555892A0AD00B3AFF15ED14ACFE0C3942805BB490225DB2FA9F1FE", "hash_ssdeep": "49152:mpPSQp/ZXI2JUfibdj3zWsGDAKn0krn9P4joNxsr:m8M/fOmH", "hash_imp": "4A88B4C7C53D9C798CC06288F26F45D5", "hash_pesha1": "76A3C4C679F215C7B0347E163719717CFC234062", "hash_pe256": "617D8F8CE8BC51685FF0C956C53CE64D901264A8C08E2F0D3329734351A4BAE3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024A0E8AFDF15C662D2B00000000024A", "signature_thumbprint": "96384A7F5F1C438F32E2454697DC6D312A74517B", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Network Realtime Inspection Service", "meta_original_filename": "NisSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2009.7 (WinBuild.160101.0800)", "meta_product_version": "4.18.2009.7", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/5b33bb9040f40e2d5022e37f725471f39f14dd4a63ee945537bc0b899b583ce5/detection/", "runtime_modules": [ "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2009.7-0\\NisSrv.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "MpCmdRun.exe-20B5E4B2BC01602D7F95076F7FD658B2": { "file_name": "MpCmdRun.exe", "file_path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2009.7-0\\X86\\MpCmdRun.exe", "hash_md5": "20B5E4B2BC01602D7F95076F7FD658B2", "hash_sha1": "A3860AA1EDD31C0A74C257CDB108EF6829E935BC", "hash_sha256": "7CDB1640FAB503F51B59EFD6EC634E52250FB440B95D420514E2F79F4C927A0D", "hash_sha384": "B9C7E5E0BE92FF2ED3714DAB02AADF03C015BBA266C46EEE99B527D557582B256FDA80AEC5C2F162FB321187E42A66D8", "hash_sha512": "AE4D96995615D6CA9C63831646103C38C5F178FAA1B24EC44F26390134F8C7A4332CAAA899748277259EFE7C55FC0C41B4820AE20800CF3195AE946625CF7002", "hash_ssdeep": "6144:Yfeo9BpKx508AxQn2owpxmdVYmfjQyn2q6hd9/nsW1u4tau6vDfn:YqdAxo2vOX+hd9/scu4twDf", "hash_imp": "17015118D89290BCAFBE0E36433C05C7", "hash_pesha1": "C58CDE0097DEAA44DB9FDB7F2E2FEE4D9A528208", "hash_pe256": "06D75556445165109CF67EA09B80714004D2A4F411B7AEF43F91F95AC128E275", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "330000024A0E8AFDF15C662D2B00000000024A", "signature_thumbprint": "96384A7F5F1C438F32E2454697DC6D312A74517B", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Malware Protection Command Line Utility", "meta_original_filename": "MpCmdRun.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.2009.7 (WinBuild.160101.0800)", "meta_product_version": "4.18.2009.7", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/7cdb1640fab503f51b59efd6ec634e52250fb440b95d420514e2f79f4c927a0d/detection/", "output": "Microsoft Antimalware Service Command Line Utility (c) 2006-2020 Microsoft Corp\r\r\nUse this tool to automate and troubleshoot Microsoft Antimalware Service\r\r\n\r\r\nUsage:\r\r\nMpCmdRun.exe [command] [-options]\r\r\n\r\r\nCommand Description\r\r\n -? / -h Displays all available options\r\r\n for this tool\r\r\n -Scan [-ScanType #] [-File <path> [-DisableRemediation] [-BootSectorScan] [-CpuThrottling]]\r\r\n [-Timeout <days>]\r\r\n [-Cancel]\r\r\n [-ReturnHR]\r\r\n Scans for malicious software\r\r\n -Trace [-Grouping #] [-Level #] Starts diagnostic tracing\r\r\n -GetFiles [-SupportLogLocation <path>] Collects support information\r\r\n -GetFilesDiagTrack Same as Getfiles but outputs to \r\r\n temporary DiagTrack folder \r\r\n -RemoveDefinitions [-All] Restores the installed\r\r\n signature definitions\r\r\n to a previous backup copy or to\r\r\n the original default set of\r\r\n signatures\r\r\n [-Engine] Restore the installed engine to\r\r\n the previous version saved\r\r\n [-DynamicSignatures] Removes only the dynamically\r\r\n downloaded signatures\r\r\n -SignatureUpdate [-UNC | -MMPC] Checks for new definition updates\r\r\n -Restore [-ListAll | [[-Name <name>] [-All] | [-FilePath <filePath>]] [-Path <path>]] Restore or list\r\r\n quarantined item(s)\r\r\n -AddDynamicSignature [-Path] Loads a dynamic signature\r\r\n -ListAllDynamicSignatures List the loaded dynamic signatures\r\r\n -RemoveDynamicSignature [-SignatureSetID] Removes a dynamic signature\r\r\n -CheckExclusion -path <path> Checks whether path is excluded\r\r\n\r\r\nAdditional Information:\r\r\n\r\r\nSupport information will be in the following directory:\r\r\nC:\\ProgramData\\Microsoft\\Windows Defender\\Support\r\r\n\r\r\n -Scan [-ScanType value]\r\r\n 0 Default, according to your configuration\r\r\n 1 Quick scan\r\r\n 2 Full system scan\r\r\n 3 File and directory custom scan\r\r\n\r\r\n [-File <path>]\r\r\n Indicates the file or directory to be scanned, only valid for custom scan.\r\r\n\r\r\n [-DisableRemediation]\r\r\n This option is valid only for custom scan.\r\r\n When specified:\r\r\n - File exclusions are ignored.\r\r\n - Archive files are scanned.\r\r\n - Actions are not applied after detection.\r\r\n - Event log entries are not written after detection.\r\r\n - Detections from the custom scan are not displayed in the user interface.\r\r\n - The console output will show the list of detections from the custom scan.\r\r\n\r\r\n [-BootSectorScan]\r\r\n Enables boot sector scanning; only valid for custom scan.\r\r\n\r\r\n [-Timeout <days>]\r\r\n Timeout in days; maximum value is 30.\r\r\n If this parameter is not specified, default value is 7 days for full scan and 1 day for all other scans.\r\r\n\r\r\n [-Cancel]\r\r\n Try to cancel any ongoing quick or full scan.\r\r\n\r\r\n [-CpuThrottling]\r\r\n When specified:\r\r\n - Will ensure that the scan obeys the CPU throttling as defined in the policy (Default 50).\r\r\n\r\r\n [-ReturnHR]\r\r\n Instead of returning the default 0 or 2 values, return the actual HRESULT of the scan command.\r\r\n\r\r\n [DEFAULT]Return code is\r\r\n 0 if no malware is found or malware is successfully remediated and no additional user action is required\r\r\n 2 if malware is found and not remediated or additional user action is required to complete remediation or there is error in scanning. Please check History for more information.\r\r\n OR\r\r\n HRESULT of the scan command if -ReturnHR was specified\r\r\n\r\r\n -Trace [-Grouping value] [-Level value]\r\r\n Begins tracing Microsoft Antimalware Service's actions.\r\r\n You can specify the components for which tracing is enabled and\r\r\n how much information is recorded.\r\r\n If no component is specified, all the components will be logged.\r\r\n If no level is specified, the Error, Warning and Informational levels\r\r\n will be logged. The data will be stored in the support directory\r\r\n as a file having the current timestamp in its name and bearing\r\r\n the extension BIN.\r\r\n\r\r\n [-Grouping]\r\r\n 0x1 Service\r\r\n 0x2 Malware Protection Engine\r\r\n 0x4 User Interface\r\r\n 0x8 Real-Time Protection\r\r\n 0x10 Scheduled actions\r\r\n 0x20 WMI\r\r\n 0x40 NIS/GAPA\r\r\n 0x80 Windows Security Center\r\r\n 0x100 DLP external\r\r\n\r\r\n [-Level]\r\r\n 0x1 Errors\r\r\n 0x2 Warnings\r\r\n 0x4 Informational messages\r\r\n 0x8 Function calls\r\r\n 0x10 Verbose\r\r\n 0x20 Performance\r\r\n\r\r\n -CaptureNetworkTrace -path <path>\r\r\n Captures all the network input into the Network Protection service and \r\r\n saves it to a file at <path>. Supply an empty path to stop tracing\r\r\n Note: The specified path must be writable by LocalService\r\r\n ex: C:\\Users\\Public\\Downloads \r\r\n\r\r\n -GetFiles\r\r\n Gathers the following log files and packages them together in a \r\r\n compressed file in the support directory\r\r\n\r\r\n - Any trace files from Microsoft Antimalware Service\r\r\n - The Windows Update history log\r\r\n - All Microsoft Antimalware Service events from the System event log\r\r\n - All relevant Microsoft Antimalware Service registry locations\r\r\n - The log file of this tool\r\r\n - The log file of the signature update helper tool\r\r\n\r\r\n [-SupportLogLocation <path>]\r\r\n Copies the support logs to the specified <path>. If <path> is not specified,\r\r\n support logs will be copied to the location specified in the SupportLogLocation Configuration.\r\r\n\r\r\n -GetFilesDiagTrack\r\r\n Same as GetFiles, but outputs the CAB file to the temp DiagTrack \r\r\n directory\r\r\n\r\r\n -RemoveDefinitions\r\r\n Restores the last set of signature definitions\r\r\n\r\r\n [-Engine]\r\r\n Restores the last saved engine\r\r\n Use this option to restore the previous engine.\r\r\n\r\r\n [-All]\r\r\n Removes any installed signature and engine files. Use this \r\r\n option if you have difficulties trying to update signatures.\r\r\n\r\r\n [-DynamicSignatures]\r\r\n Removes all Dynamic Signatures. \r\r\n\r\r\n -SignatureUpdate\r\r\n Checks for new definition updates\r\r\n\r\r\n [-UNC [-Path <path>]]\r\r\n Performs update directly from UNC file share specified in <path>\r\r\n If -Path is not specified, update will be performed directly from the\r\r\n preconfigured UNC location\r\r\n\r\r\n [-MMPC]\r\r\n Performs update directly from Microsoft Malware Protection Center\r\r\n\r\r\n -Restore\r\r\n [-ListAll]\r\r\n List all items that were quarantined\r\r\n\r\r\n [-Name <name>]\r\r\n Restores the most recently quarantined item based on threat name\r\r\n One Threat can map to more than one file\r\r\n\r\r\n [-All]\r\r\n Restores all the quarantined items based on name\r\r\n\r\r\n [-FilePath <filePath>]\r\r\n Restores quarantined item based on file path\r\r\n\r\r\n [-Path]\r\r\n Specify the path where the quarantined items will be restored.\r\r\n If not specified, the item will be restored to the original path.\r\r\n -AddDynamicSignature -Path <path> \r\r\n Adds a Dynamic Signature specified by <path>\r\r\n\r\r\n -ListAllDynamicSignatures\r\r\n Lists SignatureSet ID's of all Dynamic Signatures added to the client\r\r\n via MAPS and MPCMDRUN -AddDynamicSignature\r\r\n\r\r\n -RemoveDynamicSignature -SignatureSetID <SignatureSetID> \r\r\n Removes a Dynamic Signature specified by <SignatureSetID>\r\r\n\r\r\n -CheckExclusion -path <path>\r\r\n Checks whether <path> is excluded. It can be either a path, or a file.\r\r\n\r\r\n", "runtime_modules": [ "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2009.7-0\\X86\\MpCmdRun.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "AmazonSSMAgentSetup.exe-3CEF27949E14E0D0D06FD4313A9F76C6": { "file_name": "AmazonSSMAgentSetup.exe", "file_path": "C:\\ProgramData\\Package Cache\\{00df870a-cc28-4be9-941b-6a4679dd0ead}\\AmazonSSMAgentSetup.exe", "hash_md5": "3CEF27949E14E0D0D06FD4313A9F76C6", "hash_sha1": "6CF1CF72D76B8241F95FC8F87198A3216A4ED87F", "hash_sha256": "349A9E009CDF71E6E7C9781F71C1A1DE1473900DEF25DE9116FAFE3ED59F9AC3", "hash_sha384": "DD83D4275A3A6EA8108467203781788AC491C10E197CC2711A8A03DD2A26B8AD99C0E444690F0A65D426F64E274C6882", "hash_sha512": "AD4878250080E5D5181FB552473F10AB483B0516D0074AFB0229B7F93C669630F9E6E4A419021CC62683FC84C3EC5D355FA6E8A64D70B57EAF193258ED54E0BE", "hash_ssdeep": "12288:r79g/k9Ygb25zyaaEqrHqm/ARv7yKEkLGwPTO87:9gwYgb25FJsqIARzekLrPSE", "hash_imp": "945B38293D63DE197023E59F28A06BB8", "hash_pesha1": "20D0FDE3EF97607D603DFE78B2AC73C7A379E6AC", "hash_pe256": "F21A232D8FFD158D6F01D539577D3632F3756DF3897B0DBC068096456F6A4904", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "2F83C35B5136353D68CE9EB669FD1B0B", "signature_thumbprint": "4BAD227329ADEF18F215B6475FB7948E1629B505", "signature_issuer": "CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US", "signature_subject": "CN=Amazon.com Services LLC, OU=Software Services, O=Amazon.com Services LLC, L=Seattle, S=Washington, C=US", "meta_description": "Amazon SSM Agent", "meta_original_filename": "AmazonSSMAgentSetup.exe", "meta_product_name": "Amazon SSM Agent", "meta_company_name": "Amazon Web Services", "meta_file_version": "2.3.1319.0", "meta_product_version": "2.3.1319.0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (c) Amazon Web Services. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/349a9e009cdf71e6e7c9781f71c1a1de1473900def25de9116fafe3ed59f9ac3/detection/", "children": "AmazonSSMAgentSetup.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\ProgramData\\Package Cache\\{00df870a-cc28-4be9-941b-6a4679dd0ead}\\AmazonSSMAgentSetup.exe": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\ProgramData\\Package Cache\\{00df870a-cc28-4be9-941b-6a4679dd0ead}\\AmazonSSMAgentSetup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "cfn-elect-cmd-leader.exe-381A030E578E8285BF1F462CC036E4D0": { "file_name": "cfn-elect-cmd-leader.exe", "file_path": "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-elect-cmd-leader.exe", "hash_md5": "381A030E578E8285BF1F462CC036E4D0", "hash_sha1": "D6D51A5096A39A1D4BF34BA759248A82AEEBEDCD", "hash_sha256": "BD61C6FBD71679EB9BE6C2554F40262DDE0E5F69D3A51ED6C483541AB6425607", "hash_sha384": "6C436F903866C7E372527537B168273B6FB294421FC15DE6A621D74E6EF1F60BD84AF1CAB68B222D078744B5A0B966DC", "hash_sha512": "88C45DA414DE77B4E20EE87CC8D798D327DC45FAC0894607CECE170A9B0B571D002DB2C02EEE12DC91E1C966542210BD605D38E3CBB14907570A63BBA33107E3", "hash_ssdeep": "384:OytbeSasdkBKuZu/snjycBghtrYh8eknggMl4gKg67WhtrjHqC3V5ipeKCXosu5R:BvmBjHgTsfkngjjjHV5ipeXXosuQNO9V", "hash_imp": "8571CAA1C1E39E800CB623F4B1D233D9", "hash_pesha1": "2CB5D3724BC9D000B01FC925AE2A5CDDA0149D7A", "hash_pe256": "CF03DAE2348B0B633F5ABA4537F1ADA6783670CC5AA7CEFDC0AEA5315A936216", "signature_status": 2, "signature_status_message": "The file C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-elect-cmd-leader.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "An EC2 bootstrapper for CloudFormation", "meta_original_filename": "cfn-elect-cmd-leader.exe", "meta_product_name": "aws-cfn-bootstrap", "meta_file_version": "1.4", "meta_product_version": "1.4", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/bd61c6fbd71679eb9be6c2554f40262dde0e5f69d3a51ed6c483541ab6425607/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9518_none_08e07c8fa840efbe": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "error": "Error: You must specify StackName\r\nUsage: cfn-elect-cmd-leader.exe [options]\r\n\r\nOptions:\r\n -h, --help show this help message and exit\r\n -s STACK_NAME, --stack=STACK_NAME\r\n A CloudFormation stack\r\n -c COMMAND_NAME, --command-name=COMMAND_NAME\r\n The command name\r\n -i INVOCATION_ID, --invocation-id=INVOCATION_ID\r\n The invocation ID\r\n -l LISTENER_ID, --listener-id=LISTENER_ID\r\n The listener ID\r\n -u ENDPOINT, --url=ENDPOINT\r\n The CloudFormation service URL. The endpoint URL must\r\n match the region option. Use of this parameter is\r\n discouraged.\r\n --region=REGION The CloudFormation region. Default: us-east-1.\r\n -v, --verbose Enables verbose logging\r\n\r\n AWS Credentials:\r\n Options for specifying AWS Account Credentials.\r\n\r\n -f CREDENTIAL_FILE, --credential-file=CREDENTIAL_FILE\r\n A credential file, readable only by the owner, with\r\n keys 'AWSAccessKeyId' and 'AWSSecretKey'\r\n --role=IAM_ROLE An IAM Role\r\n --access-key=ACCESS_KEY\r\n An AWS Access Key\r\n --secret-key=SECRET_KEY\r\n An AWS Secret Key\r\n\r\n Proxy:\r\n Options for specifying proxies. Format:\r\n [scheme://][user:password@]host:port\r\n\r\n --http-proxy=HTTP_PROXY\r\n A (non-SSL) HTTP proxy\r\n --https-proxy=HTTPS_PROXY\r\n An HTTPS proxy\r\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-elect-cmd-leader.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9518_none_08e07c8fa840efbe\\MSVCR90.dll", "C:\\Program Files\\Amazon\\cfn-bootstrap\\PYTHON27.DLL", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Program Files\\Amazon\\cfn-bootstrap\\_socket.pyd", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Program Files\\Amazon\\cfn-bootstrap\\_ssl.pyd", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Program Files\\Amazon\\cfn-bootstrap\\select.pyd" ], "output": "Usage: cfn-elect-cmd-leader.exe [options]\r\n\r\nOptions:\r\n -h, --help show this help message and exit\r\n -s STACK_NAME, --stack=STACK_NAME\r\n A CloudFormation stack\r\n -c COMMAND_NAME, --command-name=COMMAND_NAME\r\n The command name\r\n -i INVOCATION_ID, --invocation-id=INVOCATION_ID\r\n The invocation ID\r\n -l LISTENER_ID, --listener-id=LISTENER_ID\r\n The listener ID\r\n -u ENDPOINT, --url=ENDPOINT\r\n The CloudFormation service URL. The endpoint URL must\r\n match the region option. Use of this parameter is\r\n discouraged.\r\n --region=REGION The CloudFormation region. Default: us-east-1.\r\n -v, --verbose Enables verbose logging\r\n\r\n AWS Credentials:\r\n Options for specifying AWS Account Credentials.\r\n\r\n -f CREDENTIAL_FILE, --credential-file=CREDENTIAL_FILE\r\n A credential file, readable only by the owner, with\r\n keys 'AWSAccessKeyId' and 'AWSSecretKey'\r\n --role=IAM_ROLE An IAM Role\r\n --access-key=ACCESS_KEY\r\n An AWS Access Key\r\n --secret-key=SECRET_KEY\r\n An AWS Secret Key\r\n\r\n Proxy:\r\n Options for specifying proxies. Format:\r\n [scheme://][user:password@]host:port\r\n\r\n --http-proxy=HTTP_PROXY\r\n A (non-SSL) HTTP proxy\r\n --https-proxy=HTTPS_PROXY\r\n An HTTPS proxy\r\n" }, "cfn-get-metadata.exe-AB00AE1FE4E4943F9CCB91C01E1C4F35": { "file_name": "cfn-get-metadata.exe", "file_path": "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-get-metadata.exe", "hash_md5": "AB00AE1FE4E4943F9CCB91C01E1C4F35", "hash_sha1": "DC028F5118DAC71FC7D7CB651270B40F181C935C", "hash_sha256": "00C060100872F0A5B6C920C9277F2EB31D21E1EEA437BE65679406751617B4CC", "hash_sha384": "FF3319B3A8D0067CA41AA6F0623881846F29E25A6C0C683F9FEEC29E2FA3EA8D6B82B9C4914A9085E870639C25588A7B", "hash_sha512": "057E8DA576E6E87CFD4C328F1614DEF92EC77525F58162962E9D5C7FAB193D5A8CD345B536990099E91849D64220C8FDFD60C824857695896023833674D69BC2", "hash_ssdeep": "384:+ytbeSasdkBKuZu/snjycBghtrYh8eknggMl4gKg67WhtrjHqC3V5ipeKMc/ZXIk:xvmBjHgTsfkngjjjHV5ipetc/ZXIxe", "hash_imp": "8571CAA1C1E39E800CB623F4B1D233D9", "hash_pesha1": "689BE2D483FE3742350EAD4ACF827A4860866BB7", "hash_pe256": "1CC740426E0D4280F1DF38F103052B43CEFE3C98E42EEF4FEA5C48DC107A8917", "signature_status": 2, "signature_status_message": "The file C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-get-metadata.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "An EC2 bootstrapper for CloudFormation", "meta_original_filename": "cfn-get-metadata.exe", "meta_product_name": "aws-cfn-bootstrap", "meta_file_version": "1.4", "meta_product_version": "1.4", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/00c060100872f0a5b6c920c9277f2eb31d21e1eea437be65679406751617b4cc/detection/", "error": "Error: You must specify both a stack name and logical resource id\r\nUsage: cfn-get-metadata.exe [options]\r\n\r\nOptions:\r\n -h, --help show this help message and exit\r\n -s STACK_NAME, --stack=STACK_NAME\r\n A CloudFormation stack\r\n -r LOGICAL_RESOURCE_ID, --resource=LOGICAL_RESOURCE_ID\r\n A CloudFormation logical resource ID\r\n -k KEY, --key=KEY Retrieve the value at <key> in the Metadata object;\r\n must be in dotted object notation (parent.child.leaf)\r\n -u ENDPOINT, --url=ENDPOINT\r\n The CloudFormation service URL. The endpoint URL must\r\n match the region option. Use of this parameter is\r\n discouraged.\r\n --region=REGION The CloudFormation region. Default: us-east-1.\r\n -v, --verbose Enables verbose logging\r\n\r\n AWS Credentials:\r\n Options for specifying AWS Account Credentials.\r\n\r\n -f CREDENTIAL_FILE, --credential-file=CREDENTIAL_FILE\r\n A credential file, readable only by the owner, with\r\n keys 'AWSAccessKeyId' and 'AWSSecretKey'\r\n --role=IAM_ROLE An IAM Role\r\n --access-key=ACCESS_KEY\r\n An AWS Access Key\r\n --secret-key=SECRET_KEY\r\n An AWS Secret Key\r\n\r\n Proxy:\r\n Options for specifying proxies. Format:\r\n [scheme://][user:password@]host:port\r\n\r\n --http-proxy=HTTP_PROXY\r\n A (non-SSL) HTTP proxy\r\n --https-proxy=HTTPS_PROXY\r\n An HTTPS proxy\r\n", "output": "Usage: cfn-get-metadata.exe [options]\r\n\r\nOptions:\r\n -h, --help show this help message and exit\r\n -s STACK_NAME, --stack=STACK_NAME\r\n A CloudFormation stack\r\n -r LOGICAL_RESOURCE_ID, --resource=LOGICAL_RESOURCE_ID\r\n A CloudFormation logical resource ID\r\n -k KEY, --key=KEY Retrieve the value at <key> in the Metadata object;\r\n must be in dotted object notation (parent.child.leaf)\r\n -u ENDPOINT, --url=ENDPOINT\r\n The CloudFormation service URL. The endpoint URL must\r\n match the region option. Use of this parameter is\r\n discouraged.\r\n --region=REGION The CloudFormation region. Default: us-east-1.\r\n -v, --verbose Enables verbose logging\r\n\r\n AWS Credentials:\r\n Options for specifying AWS Account Credentials.\r\n\r\n -f CREDENTIAL_FILE, --credential-file=CREDENTIAL_FILE\r\n A credential file, readable only by the owner, with\r\n keys 'AWSAccessKeyId' and 'AWSSecretKey'\r\n --role=IAM_ROLE An IAM Role\r\n --access-key=ACCESS_KEY\r\n An AWS Access Key\r\n --secret-key=SECRET_KEY\r\n An AWS Secret Key\r\n\r\n Proxy:\r\n Options for specifying proxies. Format:\r\n [scheme://][user:password@]host:port\r\n\r\n --http-proxy=HTTP_PROXY\r\n A (non-SSL) HTTP proxy\r\n --https-proxy=HTTPS_PROXY\r\n An HTTPS proxy\r\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-get-metadata.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9518_none_08e07c8fa840efbe\\MSVCR90.dll", "C:\\Program Files\\Amazon\\cfn-bootstrap\\PYTHON27.DLL", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Program Files\\Amazon\\cfn-bootstrap\\_socket.pyd", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Program Files\\Amazon\\cfn-bootstrap\\_ssl.pyd", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Program Files\\Amazon\\cfn-bootstrap\\select.pyd", "C:\\Program Files\\Amazon\\cfn-bootstrap\\_hashlib.pyd", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.dll" ] }, "cfn-hup.exe-FC05F4A7EA27BD5F73BE9016B8F70BD9": { "file_name": "cfn-hup.exe", "file_path": "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-hup.exe", "hash_md5": "FC05F4A7EA27BD5F73BE9016B8F70BD9", "hash_sha1": "22A7E09658613FA5F69CA5F6ACD34A5652AC735A", "hash_sha256": "7768DCA100497ED8ACA11310F5E5F6B4F70EFFDD13A824D5C5A9CE13F69E678A", "hash_sha384": "168A2DD1D0E082DFDF7485680BB29665D942ED9D0F84FEED164261AA541056D6B2BDB9E4513AB11EC837D1887FBFDC4C", "hash_sha512": "32E9B5FD11043133799C770232D0D838F0C7F0811E4E0B321E45EFCCD4BE0F73F5082A67F2DACCD4689F39BF3227EE9027B10B845DEB38AA521D9EA0D2B68013", "hash_ssdeep": "768:9vmBjHgTsfkngjjjHV5Speri8z8lP+Wtx0SEch:GLgTsfawh/ri8z8lP+WtxIch", "hash_imp": "8571CAA1C1E39E800CB623F4B1D233D9", "hash_pesha1": "9D3B062ABF6ACD8B807058DDA5C5A2EFD668CEA5", "hash_pe256": "4244A562A0A6AB45E7E956AC8090D658BED4013A854CE45E8D5F7FB24B2902A5", "signature_status": 2, "signature_status_message": "The file C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-hup.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "An EC2 bootstrapper for CloudFormation", "meta_original_filename": "cfn-hup.exe", "meta_product_name": "aws-cfn-bootstrap", "meta_file_version": "1.4", "meta_product_version": "1.4", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Usage: cfn-hup.exe [options]\r\n\r\nOptions:\r\n -h, --help show this help message and exit\r\n -c CONFIG_PATH, --config=CONFIG_PATH\r\n The configuration directory (default: C:\\cfn)\r\n --no-daemon Do not daemonize\r\n -v, --verbose Enables verbose logging\r\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-hup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "cfn-init.exe-5E0F3A7E9C8313FA6889B824EAB63614": { "file_name": "cfn-init.exe", "file_path": "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-init.exe", "hash_md5": "5E0F3A7E9C8313FA6889B824EAB63614", "hash_sha1": "E7A5B44B8CC5F681C549C97546F37A3F33170566", "hash_sha256": "CFBAB698F849F46D68C736AF3AA2BD1A27A16DE772F5A14AAD1A6D7E25475D21", "hash_sha384": "B9E858B2D7F64C802138E5149390BF3F7C775B165DC25DA53C5F3F3589B807667F51075EA7406AFC86A4403F5272CCE9", "hash_sha512": "D888447F6E65E7A01B3429479F214710D29ED91A8B2B2B2D13C3762455821C5E86211F9F0F9AC60499185D043E6DA2C92C41F2241DF91552A9968EE87A198086", "hash_ssdeep": "384:eytbeSasdkBKuZu/snjycBghtrYh8eknggMl4gKg67WhtrjHqC3V5/peK9/VNLOq:RvmBjHgTsfkngjjjHV5/pemrL8N8XPB", "hash_imp": "8571CAA1C1E39E800CB623F4B1D233D9", "hash_pesha1": "1C4B8E4500194D8DDFDF050AD17CE70526B1590C", "hash_pe256": "EDF656D354A1356200FFF432848827A93EF1C55ACEA184C07024C7F617324371", "signature_status": 2, "signature_status_message": "The file C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-init.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "An EC2 bootstrapper for CloudFormation", "meta_original_filename": "cfn-init.exe", "meta_product_name": "aws-cfn-bootstrap", "meta_file_version": "1.4", "meta_product_version": "1.4", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/cfbab698f849f46d68c736af3aa2bd1a27a16de772f5a14aad1a6d7e25475d21/detection/", "output": "Usage: cfn-init.exe [options]\r\n or: cfn-init.exe [options] <filename>\r\n or: cat <filename> | cfn-init.exe [options] -\r\n\r\nOptions:\r\n -h, --help show this help message and exit\r\n -s STACK_NAME, --stack=STACK_NAME\r\n A CloudFormation stack\r\n -r LOGICAL_RESOURCE_ID, --resource=LOGICAL_RESOURCE_ID\r\n A CloudFormation logical resource ID\r\n -c CONFIGSETS, --configsets=CONFIGSETS\r\n An optional list of configSets (default: \"default\")\r\n -u ENDPOINT, --url=ENDPOINT\r\n The CloudFormation service URL. The endpoint URL must\r\n match the region option. Use of this parameter is\r\n discouraged.\r\n --region=REGION The CloudFormation region. Default: us-east-1.\r\n -v, --verbose Enables verbose logging\r\n --resume Resume from a previous cfn-init run\r\n\r\n AWS Credentials:\r\n Options for specifying AWS Account Credentials.\r\n\r\n -f CREDENTIAL_FILE, --credential-file=CREDENTIAL_FILE\r\n A credential file, readable only by the owner, with\r\n keys 'AWSAccessKeyId' and 'AWSSecretKey'\r\n --role=IAM_ROLE An IAM Role\r\n --access-key=ACCESS_KEY\r\n An AWS Access Key\r\n --secret-key=SECRET_KEY\r\n An AWS Secret Key\r\n\r\n Proxy:\r\n Options for specifying proxies. Format:\r\n [scheme://][user:password@]host:port\r\n\r\n --http-proxy=HTTP_PROXY\r\n A (non-SSL) HTTP proxy\r\n --https-proxy=HTTPS_PROXY\r\n An HTTPS proxy\r\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-init.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9518_none_08e07c8fa840efbe\\MSVCR90.dll", "C:\\Program Files\\Amazon\\cfn-bootstrap\\PYTHON27.DLL", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Program Files\\Amazon\\cfn-bootstrap\\_socket.pyd", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Program Files\\Amazon\\cfn-bootstrap\\_ssl.pyd", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Program Files\\Amazon\\cfn-bootstrap\\select.pyd", "C:\\Program Files\\Amazon\\cfn-bootstrap\\_hashlib.pyd", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.dll" ], "error": "Unknown error reading from file help\r\n" }, "cfn-send-cmd-event.exe-6569521FE751E682B6AF18F84D544079": { "file_name": "cfn-send-cmd-event.exe", "file_path": "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-send-cmd-event.exe", "hash_md5": "6569521FE751E682B6AF18F84D544079", "hash_sha1": "57BFE6908B56B140DE4EAAEAD4CCD95F71273181", "hash_sha256": "320F6D6E4D3317CB7357D1C6315703FD9839D4FCB519C3932640E231DA88C3D5", "hash_sha384": "75FE378A41076911B63A78D25207C91FC4B1D9DCE44056E8E32688977A46829D9020A5E72E76656FCB45B6E81F1253BA", "hash_sha512": "6DDEB99C268D1BA51C1DB8B5B75677B2A6F88C5AFD3FC983549A524CE5D591A394B6182EA9FF47ACA7E3A6C59E27F4427C1DD7148977D2E86AEC2E5AF67D589B", "hash_ssdeep": "768:5vmBjHgTsfkngjjjHV5qpe5mUzmpOP4fTaq:KLgTsfawhf5mUzKOP47aq", "hash_imp": "8571CAA1C1E39E800CB623F4B1D233D9", "hash_pesha1": "BF61A4C06813759AF34B4984D41C499D7E4D012A", "hash_pe256": "663D37D4FC81D66E4031ECF9B0C4073333F91D8EE7CD30B6028D8A6F130D246C", "signature_status": 2, "signature_status_message": "The file C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-send-cmd-event.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "An EC2 bootstrapper for CloudFormation", "meta_original_filename": "cfn-send-cmd-event.exe", "meta_product_name": "aws-cfn-bootstrap", "meta_file_version": "1.4", "meta_product_version": "1.4", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/320f6d6e4d3317cb7357d1c6315703fd9839d4fcb519c3932640e231da88c3d5/detection/", "error": "Traceback (most recent call last):\r\n File \"cfn-send-cmd-event\", line 58, in <module>\r\n File \"re.pyc\", line 141, in match\r\nTypeError: expected string or buffer\r\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-send-cmd-event.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ], "output": "Usage: cfn-send-cmd-event.exe [options] [Command Event Message]\r\n\r\nOptions:\r\n -h, --help show this help message and exit\r\n --event-handle=EVENT_HANDLE\r\n Event Handle URL\r\n -e EVENT_ID, --event-id=EVENT_ID\r\n An id that uniquely identifies the event for this\r\n command and listener\r\n -t EVENT_TIMESTAMP, --event-timestamp=EVENT_TIMESTAMP\r\n The time the event occurred, in ISO 8601 form\r\n -d DISPATCHER_ID, --dispatcher-id=DISPATCHER_ID\r\n The dispatcher ID\r\n -c COMMAND_NAME, --command-name=COMMAND_NAME\r\n The command name\r\n -i INVOCATION_ID, --invocation-id=INVOCATION_ID\r\n The invocation ID\r\n -l LISTENER_ID, --listener-id=LISTENER_ID\r\n The listener ID\r\n\r\n Proxy:\r\n Options for specifying proxies. Format:\r\n [scheme://][user:password@]host:port\r\n\r\n --http-proxy=HTTP_PROXY\r\n A (non-SSL) HTTP proxy\r\n --https-proxy=HTTPS_PROXY\r\n An HTTPS proxy\r\n" }, "cfn-send-cmd-result.exe-3F9A3602A5CC3B5C8C8011A9DCB76006": { "file_name": "cfn-send-cmd-result.exe", "file_path": "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-send-cmd-result.exe", "hash_md5": "3F9A3602A5CC3B5C8C8011A9DCB76006", "hash_sha1": "5B28ED5CFC49F1C761DDF3CD4FCCC0B80C8A2720", "hash_sha256": "0500B21DA4072CE70F932B24DFE5422C1B120096E5DB1D9BD8376273D11943F1", "hash_sha384": "33206B00D68A5772CD3C0AB43BA822EA0FB6393A671851357005F1DE0BC055243DACDDCBBB96F36E0617F835D406FE04", "hash_sha512": "C24C4273BB8AE443F716C11214E67B73563D0E88005174837B71ED39974F0491A4CAE0DCF8A6DDFEB2EB65C94CB5EB624CB8C4088CFF82D8CC94A09141BE900E", "hash_ssdeep": "384:uytbeSasdkBKuZu/snjycBghtrYh8eknggMl4gKg67WhtrjHqC3V5lpeKn7DQx7F:hvmBjHgTsfkngjjjHV5lpeFx7Pp2Oaja", "hash_imp": "8571CAA1C1E39E800CB623F4B1D233D9", "hash_pesha1": "8563E2EE39BC6E708CF5982EA02D3BF325D810AF", "hash_pe256": "E96BE5365C98168B2D4E1582872BF8778999AEC55DE67BCF125C657E928CF5F2", "signature_status": 2, "signature_status_message": "The file C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-send-cmd-result.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "An EC2 bootstrapper for CloudFormation", "meta_original_filename": "cfn-send-cmd-result.exe", "meta_product_name": "aws-cfn-bootstrap", "meta_file_version": "1.4", "meta_product_version": "1.4", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/0500b21da4072ce70f932b24dfe5422c1b120096e5db1d9bd8376273d11943f1/detection/", "error": "Error: You must specify DispatcherId\r\nUsage: cfn-send-cmd-result.exe [options] [Command Result Data]\r\n\r\nOptions:\r\n -h, --help show this help message and exit\r\n --access-key=ACCESS_KEY\r\n An AWS Access Key\r\n --secret-key=SECRET_KEY\r\n An AWS Secret Key\r\n --token=SECURITY_TOKEN\r\n An AWS Session Token\r\n -q QUEUE_URL, --queue-url=QUEUE_URL\r\n SQS Queue URL for storing the command result\r\n -d DISPATCHER_ID, --dispatcher-id=DISPATCHER_ID\r\n The dispatcher ID\r\n -c COMMAND_NAME, --command-name=COMMAND_NAME\r\n The command name\r\n -i INVOCATION_ID, --invocation-id=INVOCATION_ID\r\n The invocation ID\r\n -l LISTENER_ID, --listener-id=LISTENER_ID\r\n The listener ID\r\n -s SUCCESS, --success=SUCCESS\r\n If true, signal success; if false, signal failure.\r\n Default: true\r\n -e EXIT_CODE, --exit-code=EXIT_CODE\r\n Derive success or failure from specified exit code.\r\n Note: This takes precedence over the success flag\r\n\r\n Proxy:\r\n Options for specifying proxies. Format:\r\n [scheme://][user:password@]host:port\r\n\r\n --http-proxy=HTTP_PROXY\r\n A (non-SSL) HTTP proxy\r\n --https-proxy=HTTPS_PROXY\r\n An HTTPS proxy\r\n", "output": "Usage: cfn-send-cmd-result.exe [options] [Command Result Data]\r\n\r\nOptions:\r\n -h, --help show this help message and exit\r\n --access-key=ACCESS_KEY\r\n An AWS Access Key\r\n --secret-key=SECRET_KEY\r\n An AWS Secret Key\r\n --token=SECURITY_TOKEN\r\n An AWS Session Token\r\n -q QUEUE_URL, --queue-url=QUEUE_URL\r\n SQS Queue URL for storing the command result\r\n -d DISPATCHER_ID, --dispatcher-id=DISPATCHER_ID\r\n The dispatcher ID\r\n -c COMMAND_NAME, --command-name=COMMAND_NAME\r\n The command name\r\n -i INVOCATION_ID, --invocation-id=INVOCATION_ID\r\n The invocation ID\r\n -l LISTENER_ID, --listener-id=LISTENER_ID\r\n The listener ID\r\n -s SUCCESS, --success=SUCCESS\r\n If true, signal success; if false, signal failure.\r\n Default: true\r\n -e EXIT_CODE, --exit-code=EXIT_CODE\r\n Derive success or failure from specified exit code.\r\n Note: This takes precedence over the success flag\r\n\r\n Proxy:\r\n Options for specifying proxies. Format:\r\n [scheme://][user:password@]host:port\r\n\r\n --http-proxy=HTTP_PROXY\r\n A (non-SSL) HTTP proxy\r\n --https-proxy=HTTPS_PROXY\r\n An HTTPS proxy\r\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-send-cmd-result.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "cfn-signal.exe-DDB912A9A7741BCFC2DB4C1DDE995AB1": { "file_name": "cfn-signal.exe", "file_path": "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-signal.exe", "hash_md5": "DDB912A9A7741BCFC2DB4C1DDE995AB1", "hash_sha1": "4FCAA47DEF52FFE798367EE55A4E0DBC7AAE6EC8", "hash_sha256": "3CF6F694067887C5A4CBE33B264C14611DC40A2C564236DD94FE051BB719FDC3", "hash_sha384": "8FCFBA181158F9BFF35E4F3A608055D591A60508E5A2A31360F4D2357BCF8B3B0E4FC84A62DAFD93B8D083F63149A4DC", "hash_sha512": "0433502B43E4405CF835534D2011ECBF47AF044DFC0D333823595038F54EEBECDF3E0B49BE30EA8F257F96C04ED70CF7824A3CC6BE76271DA5983EE6850A4928", "hash_ssdeep": "768:lvmBjHgTsfkngjjjHV5CpeUe4plNjUq29yj:eLgTsfawh/UXlNjgIj", "hash_imp": "8571CAA1C1E39E800CB623F4B1D233D9", "hash_pesha1": "35516F229CCE1E97218712C847FDA97448343D5A", "hash_pe256": "D83ADC2B2C55A74162C9D6E248F68C450C4F4EFBF9F5B4D2C51B019C14D309D7", "signature_status": 2, "signature_status_message": "The file C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-signal.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "An EC2 bootstrapper for CloudFormation", "meta_original_filename": "cfn-signal.exe", "meta_product_name": "aws-cfn-bootstrap", "meta_file_version": "1.4", "meta_product_version": "1.4", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/3cf6f694067887c5a4cbe33b264c14611dc40a2c564236dd94fe051bb719fdc3/detection/", "output": "Usage: cfn-signal.exe [options] [WaitConditionHandle URL]\r\n\r\nOptions:\r\n -h, --help show this help message and exit\r\n -s SUCCESS, --success=SUCCESS\r\n If true, signal success to CloudFormation; if false,\r\n signal failure. Default: true\r\n -i ID, --id=ID A unique ID to send with the signal\r\n -e EXIT_CODE, --exit-code=EXIT_CODE\r\n Derive success or failure from specified exit code\r\n\r\n AWS Credentials:\r\n Options for specifying AWS Account Credentials.\r\n\r\n -f CREDENTIAL_FILE, --credential-file=CREDENTIAL_FILE\r\n A credential file, readable only by the owner, with\r\n keys 'AWSAccessKeyId' and 'AWSSecretKey'\r\n --role=IAM_ROLE An IAM Role\r\n --access-key=ACCESS_KEY\r\n An AWS Access Key\r\n --secret-key=SECRET_KEY\r\n An AWS Secret Key\r\n\r\n Proxy:\r\n Options for specifying proxies. Format:\r\n [scheme://][user:password@]host:port\r\n\r\n --http-proxy=HTTP_PROXY\r\n A (non-SSL) HTTP proxy\r\n --https-proxy=HTTPS_PROXY\r\n An HTTPS proxy\r\n\r\n WaitConditionHandle Signal Options:\r\n -r REASON, --reason=REASON\r\n The reason for success/failure\r\n -d DATA, --data=DATA\r\n Data to include with the WaitCondition signal\r\n\r\n Resource Signal Options:\r\n --stack=STACK_NAME A CloudFormation stack\r\n --resource=LOGICAL_RESOURCE_ID\r\n A CloudFormation logical resource ID\r\n --url=ENDPOINT The CloudFormation service URL. The endpoint URL must\r\n match the region option. Use of this parameter is\r\n discouraged.\r\n --region=REGION The CloudFormation region. Default: us-east-1.\r\n", "error": "Error: Invalid WaitConditionHandle URL specified: help\r\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\cfn-bootstrap\\cfn-signal.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "winhup.exe-48FE04D8A6525EBF39345C41CE0D6842": { "file_name": "winhup.exe", "file_path": "C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe", "hash_md5": "48FE04D8A6525EBF39345C41CE0D6842", "hash_sha1": "6E7BA1E29BC808A746CCF11D447FA8BF1AE99A78", "hash_sha256": "9612C7D48A0806ACE6216CC69F3D0BC2A0CD16B9CEBDEDF5A0BAE1A007330D3E", "hash_sha384": "544476727EF7A908D3EF34C3B2053FF9C10B591F5419A473F9A8291B2F73423647D6B1600CAB1F9632BCEBFB46F00259", "hash_sha512": "4937468B19095EBB568D565263F890000D85FC24FC3A6A54F0B0510B5A16C218F67ADC88C16512FE76813409726BE7257B942E4C9997216D8779B821387BA13A", "hash_ssdeep": "384:aytbeSasdkBKuZu/snjycBghtrYh8eknggMl4gKg67WhtrjHqC3V57peKbQUE7eT:1vmBjHgTsfkngjjjHV57peUWX7knV/6A", "hash_imp": "8571CAA1C1E39E800CB623F4B1D233D9", "hash_pesha1": "7ED616869B4969DB0BE0A498822388AB9EB646AF", "hash_pe256": "82CEF25A25EA6184D30F7301D427EC84266128ACF9576B9717BF956453264BC8", "signature_status": 2, "signature_status_message": "The file C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "An EC2 bootstrapper for CloudFormation", "meta_original_filename": "winhup.exe", "meta_product_name": "aws-cfn-bootstrap", "meta_file_version": "1.4", "meta_product_version": "1.4", "meta_language": "English (United States)", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/9612c7d48a0806ace6216cc69f3d0bc2a0cd16b9cebdedf5a0bae1a007330d3e/detection/", "runtime_modules": [ "C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9518_none_08e07c8fa840efbe\\MSVCR90.dll", "C:\\Program Files\\Amazon\\cfn-bootstrap\\PYTHON27.DLL", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "output": "Services are supposed to be run by the system after they have been installed.\r\nThese command line options are available for (de)installation:\r\n\t-help\r\n\t-install\r\n\t-remove\r\n\t-auto\r\n\t-disabled\r\n\t-interactive\r\n\t-user: <arg>\r\n\t-password: <arg>\r\n\r\nConnecting to the Service Control Manager\r\n", "error": "Traceback (most recent call last):\r\n File \"boot_service.py\", line 173, in <module>\r\npywintypes.error: (1063, 'StartServiceCtrlDispatcher', 'The service process could not connect to the service controller.')\r\n" }, "EC2HibernateAgent.exe-BAF2DC4F2419BFC0DEA2BC2609DA5F5B": { "file_name": "EC2HibernateAgent.exe", "file_path": "C:\\Program Files\\Amazon\\Hibernate\\EC2HibernateAgent.exe", "hash_md5": "BAF2DC4F2419BFC0DEA2BC2609DA5F5B", "hash_sha1": "D8B1E277E419729FC177CF7F28D02339EFEC5766", "hash_sha256": "25C4F7BBC409CDEC1B144034C7E79F88AAE97C74E0ED72888F19817E47ACFBB5", "hash_sha384": "349C28BE361A913A1A7874D7661CEEC14DAD716BB873C7B323532C249EAAA4160A6395135FFAD3CD9889A13B97AE820E", "hash_sha512": "471A269E08D0025CBEDAA285038D3359D0EE412E2ACE1D6F993EC62C2A9AFB05CA11677561C8C96DF1F087C3D25C0CA8E5F3593707D1C0FD4552E7EFEF69EC91", "hash_ssdeep": "384:B8jcgHZevkMSZsHLPK6jTu7LwvZevkAZsHLsu1PnhY:e7kPKgOUfLhY", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "767D97913034939751E76BAF6EF3C110CC2B276F", "hash_pe256": "D238CAB89DAC82FFFAF96DBD0B63982F227793AA70D93608EFE89D78DABC2C28", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "0B6484A34E527CC2BC614568F961D353", "signature_thumbprint": "5E025F525F7CCDB57B9E0AD40C7022184536A52D", "signature_issuer": "CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US", "signature_subject": "CN=\"Amazon Web Services, Inc.\", O=\"Amazon Web Services, Inc.\", L=Seattle, S=Washington, C=US, PostalCode=98109, STREET=410 Terry Ave N, SERIALNUMBER=4152954, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US, OID.2.5.4.15=Private Organization", "meta_description": " ", "meta_original_filename": "EC2HibernateAgent.exe", "meta_file_version": "0.0.0.0", "meta_product_version": "0.0.0.0", "meta_language": "Language Neutral", "meta_legal_copyright": " ", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/64", "filescan_vtlink": "https://www.virustotal.com/gui/file/25c4f7bbc409cdec1b144034c7e79f88aae97c74e0ed72888f19817e47acfbb5/detection/", "children": [ "EC2HibernateAgent.exe", "WerFault.exe" ], "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4880": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "error": "\nUnhandled Exception: System.ArgumentException: Invalid parameter name: --help\r\n at EC2HibernateAgent.Main(String[] args)\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\Hibernate\\EC2HibernateAgent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\5543cca0df435801e2303ff46a482ed5\\mscorlib.ni.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\6885802f40fd803e49150d8a2b43a09b\\System.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Core\\f29b1120627489754c4b8dd317bbe950\\System.Core.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\bb0ca52db926eaec4a94a8b656f61a94\\System.Management.Automation.ni.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\diasymreader.dll" ] }, "amazon-ssm-agent.exe-D99D0B786003034B7255BA854D2750DF": { "file_name": "amazon-ssm-agent.exe", "file_path": "C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe", "hash_md5": "D99D0B786003034B7255BA854D2750DF", "hash_sha1": "63B5A7FD10E3F069E55CDE0589B164C4785D8013", "hash_sha256": "E59FC75594AA351583476F38E8C008C2AD2119C229D9C4540EFE17AFAEF7ED34", "hash_sha384": "A9FC7C39690F653E4E3609412D8343BD566793268AA788B1D45229B23FC7A36646BE4DA178B1414B80B6E2C7C9AE066F", "hash_sha512": "6E0782011AC8A1A75578E43BBEE155F247EC3271386721A2102D0D29E012D9D8AE3CADE0D3F07332AD1C109842F1321AD2A4365632A74E9A8B6648A01A5017CE", "hash_ssdeep": "196608:rmUGT/XfKfdJUxecpCzwznb1oTo75R/+sHzZtaP6F+M0:2ppCc+sHF6", "hash_imp": "F0070935B15A909B9DC00BE7997E6112", "hash_pesha1": "A1441DF045DBA2462AF9911688498B0D2DB3C2FA", "hash_pe256": "EF5A2FE4DF5B3AAFF14BB73317EFAE2EAB1D0045A4FFB930BC38DA1ED1A26037", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "2F83C35B5136353D68CE9EB669FD1B0B", "signature_thumbprint": "4BAD227329ADEF18F215B6475FB7948E1629B505", "signature_issuer": "CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US", "signature_subject": "CN=Amazon.com Services LLC, OU=Software Services, O=Amazon.com Services LLC, L=Seattle, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/e59fc75594aa351583476f38e8c008c2ad2119c229d9c4540efe17afaef7ed34/detection/", "output": "Initializing new seelog logger\nNew Seelog Logger Creation Complete\n2020-10-19 22:56:49 INFO Windows Only: Job object creation on SSM agent successful\n2020-10-19 22:56:49 INFO Getting IE proxy configuration for current user: The operation completed successfully.\n2020-10-19 22:56:49 INFO Getting WinHTTP proxy default configuration: The operation completed successfully.\n2020-10-19 22:56:49 INFO Proxy environment variables:\n2020-10-19 22:56:49 INFO http_proxy: \n2020-10-19 22:56:49 INFO https_proxy: \n2020-10-19 22:56:50 INFO Agent is in hibernate mode. Reducing logging. Logging will be reduced to one log per backoff period\n2020-10-19 22:56:49 INFO no_proxy: \n2020-10-19 22:56:50 INFO Entering SSM Agent hibernate - EC2RoleRequestError: no EC2 instance role found\ncaused by: EC2MetadataError: failed to make EC2Metadata request\n\tstatus code: 404, request id: \ncaused by: <?xml version=\"1.0\" encoding=\"iso-8859-1\"?>\n<!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Transitional//EN\"\n\t\"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd\">\n<html xmlns=\"http://www.w3.org/1999/xhtml\" xml:lang=\"en\" lang=\"en\">\n <head>\n <title>404 - Not Found\n \n \n

404 - Not Found

\n \n\n\n", "children": "conhost.exe", "error": "2020/10/19 22:56:58 Failed to load instance info from vault. RegistrationKey does not exist.\nUsage of C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe:\n -clear\n \t\n -code string\n \t\n -fingerprint\n \t\n -i string\n \tinstance id\n -id string\n \t\n -r string\n \tinstance region\n -region string\n \t\n -register\n \t\n -similarityThreshold int\n \t (default 40)\n -y\t\n", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RWD) C:\\Program Files\\Amazon\\SSM": "File", "(RW-) C:\\ProgramData\\Amazon\\SSM\\Logs\\amazon-ssm-agent.log": "File", "(RW-) C:\\Users\\user\\{{LOCALAPPDATA}}\\Amazon\\SSM\\Logs\\hibernate.log": "File", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.DLL", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\SYSTEM32\\winmm.dll", "C:\\Windows\\SYSTEM32\\WINMMBASE.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ws2_32.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\SYSTEM32\\dhcpcsvc6.DLL", "C:\\Windows\\SYSTEM32\\dhcpcsvc.DLL", "C:\\Windows\\SYSTEM32\\netapi32.dll", "C:\\Windows\\SYSTEM32\\SAMCLI.DLL", "C:\\Windows\\SYSTEM32\\SAMLIB.dll" ] }, "ssm-cli.exe-CCCADA29D93FF19CB13CC6CA59950ACF": { "file_name": "ssm-cli.exe", "file_path": "C:\\Program Files\\Amazon\\SSM\\ssm-cli.exe", "hash_md5": "CCCADA29D93FF19CB13CC6CA59950ACF", "hash_sha1": "B58B4D29EEF90928CF2E86ED5234398897920E26", "hash_sha256": "64FB39628A16560B783A71496EC7562944E92F125D36131384AD779783FA1F8D", "hash_sha384": "C8F8618875FA60BF7399E4B3EE29F0DE01E00429F41E76BF1980975031E5C13824AE57367B6AC422B20E8425D46A0068", "hash_sha512": "0CCB11B1354597127E1DF7D186C277F60E674E8195CD3A4DCFAD8DEAD1416F988BFF343C0C0D6774CA6F7544B80C1658976C6CD3217AF2A52B40722335BF4FA3", "hash_ssdeep": "196608:/DRf3d3JPlDm0ZXzUprVF7JHqwFErZOR7:P/DQjtQ0", "hash_imp": "F0070935B15A909B9DC00BE7997E6112", "hash_pesha1": "35646D36A77C586283B4724117F7F2003DED8AD7", "hash_pe256": "40FEB0B7E0AE52438463F67C4D699611F6D424F835D48D2FA75A149B16F94337", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "2F83C35B5136353D68CE9EB669FD1B0B", "signature_thumbprint": "4BAD227329ADEF18F215B6475FB7948E1629B505", "signature_issuer": "CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US", "signature_subject": "CN=Amazon.com Services LLC, OU=Software Services, O=Amazon.com Services LLC, L=Seattle, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "2020/10/19 22:57:47 Failed to load instance info from vault. RegistrationKey does not exist.\n", "output": "usage: ssm-cli [options] [subcommand1 subcommand2...] [parameters]\nTo see help text, you can run:\n\n ssm-cli help\n ssm-cli help\n ssm-cli help\n\nInvalid command -help. The following commands are supported:\n\nget-instance-information\nget-offline-command-invocation\nsend-offline-command\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\SSM\\ssm-cli.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ssm-document-worker.exe-F693CC0365167EF20EFE65C5F12ED9A6": { "file_name": "ssm-document-worker.exe", "file_path": "C:\\Program Files\\Amazon\\SSM\\ssm-document-worker.exe", "hash_md5": "F693CC0365167EF20EFE65C5F12ED9A6", "hash_sha1": "A6D40E0BF4DD6C8B30EA875AEE6434A5EEDC4024", "hash_sha256": "8DBB6FA1BEB4F206BD7A888FA684ED658793CE70568879B034F0FD0B24E61C38", "hash_sha384": "5372524BB390C861D599D70A78DAD59D025DAEFC64F384AC543CF0DFA589A69DA6149F9A44658D068A2401F3AF822EB8", "hash_sha512": "F49A4FB7879D65271E9C35EC599481B3D43AA203C516C4B4971667C4EE2078714C0A300A11F3B913DCF79022480AC5E72FF407225E1DEC6554EE3B2854661645", "hash_ssdeep": "196608:KMQqcOS+sylVOmRbbH9uaozhvk4aIgBkFFBFAx:vYeHDozhv+IbFm", "hash_imp": "F0070935B15A909B9DC00BE7997E6112", "hash_pesha1": "461B1973E295DADDE21C8221BADD2D8054C12B8B", "hash_pe256": "8B688AFDF79136CAA3A91CEEDC1FF49B821929399B0D0FF4EC57A79B747BAA4B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "2F83C35B5136353D68CE9EB669FD1B0B", "signature_thumbprint": "4BAD227329ADEF18F215B6475FB7948E1629B505", "signature_issuer": "CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US", "signature_subject": "CN=Amazon.com Services LLC, OU=Software Services, O=Amazon.com Services LLC, L=Seattle, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "2020/10/19 22:58:35 Failed to load instance info from vault. RegistrationKey does not exist.\n", "children": "conhost.exe", "output": "Initializing new seelog logger\nNew Seelog Logger Creation Complete\n2020-10-19 22:59:00 INFO parsing args: [C:\\Program Files\\Amazon\\SSM\\ssm-document-worker.exe --help]\n2020-10-19 22:59:00 INFO using channelName --help, instanceID: \n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] document: --help worker started\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] channel: --help not found, creating a new file channel...\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] Successfully loaded platform independent plugin aws:runPowerShellScript\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] Successfully loaded platform independent plugin aws:updateSsmAgent\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] Successfully loaded platform independent plugin aws:runDockerAction\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] Successfully loaded platform independent plugin aws:configurePackage\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] Successfully loaded platform independent plugin aws:downloadContent\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] Successfully loaded platform independent plugin aws:runDocument\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] Successfully loaded platform independent plugin aws:softwareInventory\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] Successfully loaded platform independent plugin aws:configureDocker\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] Successfully loaded platform independent plugin aws:refreshAssociation\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] Successfully loaded platform dependent plugin aws:psModule\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] Successfully loaded platform dependent plugin aws:applications\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] Successfully loaded platform dependent plugin aws:domainJoin\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] Successfully loaded platform dependent plugin aws:updateAgent\n2020-10-19 22:59:00 INFO [ssm-document-worker] [--help] inter process communication started\n2020-10-19 22:59:00 WARN [ssm-document-worker] [--help] IPC file not readable: tmp\n", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\ProgramData\\Amazon\\SSM\\Logs\\amazon-ssm-agent.log": "File", "(RWD) C:\\ProgramData\\Amazon\\SSM\\InstanceData\\i-0cb123bb7dbf3caae\\channels\\--help": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Amazon\\SSM\\ssm-document-worker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.DLL", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\SYSTEM32\\winmm.dll", "C:\\Windows\\SYSTEM32\\WINMMBASE.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ws2_32.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\mswsock.dll" ] }, "ssm-session-logger.exe-A5DF37E84A1F9C87B18CD01E1501F606": { "file_name": "ssm-session-logger.exe", "file_path": "C:\\Program Files\\Amazon\\SSM\\ssm-session-logger.exe", "hash_md5": "A5DF37E84A1F9C87B18CD01E1501F606", "hash_sha1": "F55F34AF68F748254F5E8A6715CB66DE38924826", "hash_sha256": "DF950B67BAA606DD29FB7D9745B49C296D82045901B544DD3A55080CBED5683A", "hash_sha384": "81328FBFA639F49C844A7556E31F4E4B4A2AD74545B2CCBD8A3E44FBC331C262F64DBB7E0DCF3C8E2A6F8000817A1934", "hash_sha512": "77699BBAE3889D2B1D282329E4843BB2FB8A0D40C75835643FD02C4C86FE7C4610CFF8E4D6E538292044B20BF7A340B76889ACCC9C8F24CD61B779F1EED9B0CA", "hash_ssdeep": "98304:lC26SKrdSYn0hZ1z+eRv6Q0TW6Z+r+WSGIeTw8XZ:Y26SKpSYnGV+eRvJx6UrJkS", "hash_imp": "F0070935B15A909B9DC00BE7997E6112", "hash_pesha1": "CBF70B2CA3462A084867372652C1CCA5850A4DCC", "hash_pe256": "635D793978DADC5BCC827CF0487F775B43E7AD67D24CBE20DDFEAF7177A12A24", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "2F83C35B5136353D68CE9EB669FD1B0B", "signature_thumbprint": "4BAD227329ADEF18F215B6475FB7948E1629B505", "signature_issuer": "CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US", "signature_subject": "CN=Amazon.com Services LLC, OU=Software Services, O=Amazon.com Services LLC, L=Seattle, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Initializing new seelog logger\nNew Seelog Logger Creation Complete\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\SSM\\ssm-session-logger.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "ssm-session-worker.exe-9AE44E45F061129AD0E54003553A7937": { "file_name": "ssm-session-worker.exe", "file_path": "C:\\Program Files\\Amazon\\SSM\\ssm-session-worker.exe", "hash_md5": "9AE44E45F061129AD0E54003553A7937", "hash_sha1": "180EF7BC5032BE080563E46F45A7A5DE15626AAA", "hash_sha256": "5C83F6681AEC35D9272DABD62DDA78AC7E8A46B69FDFF432041B6C31081810C4", "hash_sha384": "E6FCE37A707E440F5BC7A8AB715C3EC9FB1F8EA881A7CCCB47A847C1E97F6451FA69ABD787BD0CD37C8EC48D8FE8F093", "hash_sha512": "D8579819B3A350A059DD57F1A357E9DDF91FFB6A46A640A8E423D8CE4192817CC690D481FFF7430E2D99497F245571BB4753F28BAC2553A39E8E7218BC8D5D01", "hash_ssdeep": "196608:k3FEErsmQQMhwP1hlDDbtPBdYoPddAsaUfESaSCX9VY:CfhXlPdOfS2y", "hash_imp": "F0070935B15A909B9DC00BE7997E6112", "hash_pesha1": "D09780A13E65669C13F6D8EE97FABBA113AF6932", "hash_pe256": "DC7E2DF421CA7EB512C6F81B13AC1BE3F12FB21C7BE8951C6FCE742B95FED226", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "2F83C35B5136353D68CE9EB669FD1B0B", "signature_thumbprint": "4BAD227329ADEF18F215B6475FB7948E1629B505", "signature_issuer": "CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US", "signature_subject": "CN=Amazon.com Services LLC, OU=Software Services, O=Amazon.com Services LLC, L=Seattle, S=Washington, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Initializing new seelog logger\nNew Seelog Logger Creation Complete\n2020-10-19 23:00:06 INFO [ssm-session-worker] [/?] document: /? worker started\n2020-10-19 23:00:06 INFO [ssm-session-worker] [/?] channel: /? not found, creating a new file channel...\n2020-10-19 23:00:06 ERROR [ssm-session-worker] [/?] failed to create directory: CreateFile C:\\ProgramData\\Amazon\\SSM\\InstanceData/i-0cb123bb7dbf3caae/channels/?: The filename, directory name, or volume label syntax is incorrect.\n2020-10-19 23:00:06 ERROR [ssm-session-worker] [/?] failed to create channel: CreateFile C:\\ProgramData\\Amazon\\SSM\\InstanceData/i-0cb123bb7dbf3caae/channels/?: The filename, directory name, or volume label syntax is incorrect.\n2020-10-19 23:00:06 INFO [ssm-session-worker] [/?] Session worker closed\n", "error": "2020/10/19 23:00:06 Failed to load instance info from vault. RegistrationKey does not exist.\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\ProgramData\\Amazon\\SSM\\Logs\\amazon-ssm-agent.log": "File", "(RWD) C:\\ProgramData\\Amazon\\SSM\\InstanceData\\i-0cb123bb7dbf3caae\\channels\\--help": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Amazon\\SSM\\ssm-session-worker.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.DLL", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\SYSTEM32\\winmm.dll", "C:\\Windows\\SYSTEM32\\WINMMBASE.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ws2_32.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\system32\\mswsock.dll" ] }, "AWS.CloudWatch.exe-7F80573E534532FBE5D9C0515C5E2018": { "file_name": "AWS.CloudWatch.exe", "file_path": "C:\\Program Files\\Amazon\\SSM\\Plugins\\awsCloudWatch\\AWS.CloudWatch.exe", "hash_md5": "7F80573E534532FBE5D9C0515C5E2018", "hash_sha1": "069E5C5662E5D668D1A6C9906A39955C937444A2", "hash_sha256": "AFFF7C8923FC21CE8AE0325573873600E66381507A201E502EB0884F15B78DA2", "hash_sha384": "0A95359BB471B3C26272A5CC7E4F30068130913678422DC7DB728F08F4B7C4F6916624D5F13C4C3E91158B5681A73C65", "hash_sha512": "A8464A913B31249DF29ED1AC3C3763DBB757F536847D48424E8EE759DBE92E7207B3B90CF5130CD698144F1F28C0BFBACDAC4E1D6D237C2CAE8CBC09FC508D23", "hash_ssdeep": "192:F1MVIMiWdn+BzzT2QdFMzv6dOXTFtG1YL+nTGHHwhPu7bJWwcTVvFnkvtbu967:FmIMXp+BzzThvMz4SeScT9Fkvtbuo", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "9B3D7520D72F8A46118D778F53F838014A948D4A", "hash_pe256": "D948542DF633184B451151969F09A960266403151BC7F4B38BABBF610C7FE243", "signature_status": 2, "signature_status_message": "The file C:\\Program Files\\Amazon\\SSM\\Plugins\\awsCloudWatch\\AWS.CloudWatch.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "EC2Config.CloudWatch", "meta_original_filename": "AWS.CloudWatch.exe", "meta_company_name": "Amazon Web Services, Inc.", "meta_file_version": "4.9.4276", "meta_product_version": "4.9.4276", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Amazon Web Services, Inc. 2015", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Arguments 1\r\nArgument <--help>\r\nExpected parameters: instanceId instanceRegion config/path\r\nExample: i-00000000000000000 us-west-2 {\"EngineConfiguration\":{}}\r\nExample: i-00000000000000000 us-west-2 C:\\Amazon\\SSM\\Plugins\\awsCloudWatch\\AWS.EC2.Windows.CloudWatch.json\r\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\SSM\\Plugins\\awsCloudWatch\\AWS.CloudWatch.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "AWS.DomainJoin.exe-C9A2D48A263C2FDE3CE3449739C14087": { "file_name": "AWS.DomainJoin.exe", "file_path": "C:\\Program Files\\Amazon\\SSM\\Plugins\\awsDomainJoin\\AWS.DomainJoin.exe", "hash_md5": "C9A2D48A263C2FDE3CE3449739C14087", "hash_sha1": "EA56ECD4BB19794001BF10AF0E87EF9285F73D03", "hash_sha256": "97427335721A89356F7E495400755E256D8800DEF5656B594973D79B2934723E", "hash_sha384": "4ABA178AFC317602664F4B65A7A3CD9AE8CDD1E963DBB78F119D5709DDEC6BF8D9A5BE78CAD28D1CEF02C14A3CCD8586", "hash_sha512": "EAF0CF0D1B2406DDE7465CBE458B415336303A080CB4F2700455B99657BB31994799DC7608A78C8A9603E6B247ACB1AF88DE80B0A510FE96A3AEB5F0BAD545D6", "hash_ssdeep": "49152:Tz4YfI8ERt8i4Bapk930teXT892BIx8XBir1JohNXVXRmHpXs0:TEYwV4Bam9ktejdBbRWHohNXx", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "BC1B3876041833DCD07E720762568E8B8A897A88", "hash_pe256": "38E4B91AE54544150AA06879FC6ACD3BD40C75695D31D3A39C4F04A4325F77B2", "signature_status": 2, "signature_status_message": "The file C:\\Program Files\\Amazon\\SSM\\Plugins\\awsDomainJoin\\AWS.DomainJoin.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "Ec2Config.DomainJoin", "meta_original_filename": "AWS.DomainJoin.exe", "meta_company_name": "Amazon Web Services, Inc.", "meta_file_version": "4.9.4276", "meta_product_version": "4.9.4276", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Amazon Web Services, Inc. 2015", "meta_machinetype": "32-bit", "filescan_vtdetection": "1/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/97427335721a89356f7e495400755e256d8800def5656b594973d79b2934723e/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4808": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\winnlsres.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\UrlZonesSM_Administrator": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Amazon\\SSM\\Plugins\\awsDomainJoin\\AWS.DomainJoin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\5543cca0df435801e2303ff46a482ed5\\mscorlib.ni.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\6885802f40fd803e49150d8a2b43a09b\\System.ni.dll", "C:\\Windows\\SYSTEM32\\wldp.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Xml\\488d073901c2c0fb8ccbcbe182b6b160\\System.Xml.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Core\\f29b1120627489754c4b8dd317bbe950\\System.Core.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Configuration\\875dc3cfd53efc9f9a5c63016cd239d7\\System.Configuration.ni.dll", "C:\\Windows\\System32\\shell32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\ws2_32.dll", "C:\\Windows\\system32\\mswsock.dll", "C:\\Windows\\system32\\napinsp.dll", "C:\\Windows\\SYSTEM32\\DNSAPI.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\System32\\winrnr.dll", "C:\\Windows\\system32\\NLAapi.dll", "C:\\Windows\\system32\\wshbth.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Comp46f2b404#\\1c92eca48f2d96d558a0e489a3180648\\System.ComponentModel.DataAnnotations.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Runteb92aa12#\\0a20c3e2769862d42803de9732fcf620\\System.Runtime.Serialization.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Xml.Linq\\1f8e15c27df619e8116461e283dac636\\System.Xml.Linq.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Data\\a39e284ddde9013349d1f350607766b8\\System.Data.ni.dll", "C:\\Windows\\Microsoft.Net\\assembly\\GAC_64\\System.Data\\v4.0_4.0.0.0__b77a5c561934e089\\System.Data.dll" ] }, "winpty-agent.exe-4726115317D7B5750B9F82DE06356887": { "file_name": "winpty-agent.exe", "file_path": "C:\\Program Files\\Amazon\\SSM\\Plugins\\SessionManagerShell\\winpty-agent.exe", "hash_md5": "4726115317D7B5750B9F82DE06356887", "hash_sha1": "F6748E6BED353B807EA1AC8E438BEE409E6524E9", "hash_sha256": "2C4E65E18115FC0672E2B2E017073CC01E26735E2C93FC291C6875EBE19431B3", "hash_sha384": "BBAD60A2C082BFB0040E0E1E17C7EC6E8B3948BAA55672C98915DF350348FD6D84C8368270066154DCBE6BC5ACC5EF38", "hash_sha512": "2695A32BACCE41BD72B0DA29CFEFB4CE41631CD2262A9C12329F96B824C286849A0A89868D189E431D03927DA79DEFBFC9E158D67B9186820C2AA097CCFE4F5C", "hash_ssdeep": "6144:AdaLEz8bmoLLZE5u+seLXg4uT2UPRJicxn2ArfcSMxHcA:h1iuHUXsicEArLA", "hash_imp": "C5C2F7AF66B045BC3972B97B804DC21B", "hash_pesha1": "F091A295B51EF5CD0B50C444CEA37AD528115C5E", "hash_pe256": "EA0D6CFBF32E7DC463C693A9D984FF8EDD849A87473DB8C68007948DEAC9DCDB", "signature_status": 2, "signature_status_message": "The file C:\\Program Files\\Amazon\\SSM\\Plugins\\SessionManagerShell\\winpty-agent.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_machinetype": "64-bit", "filescan_vtdetection": "0/73", "filescan_vtlink": "https://www.virustotal.com/gui/file/2c4e65e18115fc0672e2b2e017073cc01e26735e2c93fc291c6875ebe19431b3/detection/", "error": "Usage: C:\\Program Files\\Amazon\\SSM\\Plugins\\SessionManagerShell\\winpty-agent.exe controlPipeName flags mouseMode cols rows\r\nUsage: C:\\Program Files\\Amazon\\SSM\\Plugins\\SessionManagerShell\\winpty-agent.exe controlPipeName --create-desktop\r\n\r\nOrdinarily, this program is launched by winpty.dll and is not directly\r\nuseful to winpty users. However, it also has options intended for\r\ndebugging winpty.\r\n\r\nUsage: C:\\Program Files\\Amazon\\SSM\\Plugins\\SessionManagerShell\\winpty-agent.exe [options]\r\n\r\nOptions:\r\n --show-input [--with-mouse] [--escape-input]\r\n Dump INPUT_RECORDs from the console input buffer\r\n --with-mouse: Include MOUSE_INPUT_RECORDs in the dump\r\n output\r\n --escape-input: Direct the new Windows 10 console to use\r\n escape sequences for input\r\n --version Print the winpty version\r\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\SSM\\Plugins\\SessionManagerShell\\winpty-agent.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dpinst.exe-B5F75FCCE7C32239378983A3A3C331D4": { "file_name": "dpinst.exe", "file_path": "C:\\Program Files\\Amazon\\XenTools\\dpinst.exe", "hash_md5": "B5F75FCCE7C32239378983A3A3C331D4", "hash_sha1": "6516BC2847EE96667477A6887C530DE9BC829255", "hash_sha256": "07ACBFF9A241CF67051807D261066DB56B159E3E25B26FEB8564A7ED1BC74E8B", "hash_sha384": "273F72FD49F60D5A11B48F9496F43FFB9A25D873F0B0CEFE2CF1AAE201A535E5830CA7B450694F6EE9522519BC25B083", "hash_sha512": "AC9B089F2DD1676ED7B9BB7C21A0D5A7D0C66DD1D2C3B5291ED07B17A4E5620A847537D826ECC7436234209D2305C35B869F69E7A6554A081AACA950D20E40B9", "hash_ssdeep": "6144:AsW7OzpPId26dQcEaUrPvwgwkRVagRoOQTiHaQsVIhVLpHf2mmP+8:cIId79EaUTvwieMowXzZ2tPh", "hash_imp": "3EACB9638877275335DA4B58E52824F8", "hash_pesha1": "0F333AD4E07C4244F7DDE4BEA333516CC18ED240", "hash_pe256": "5AAA3A94C85339984A86A21455B98A8A15913E4C52EE60C99125DB24ED3C4E42", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000000584C084C80A1C8D561000000000058", "signature_thumbprint": "580E5B74E4A43390FE113F7CAD3C138E21776F1E", "signature_issuer": "CN=Microsoft Windows Third Party Component CA 2012, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows Hardware Compatibility Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Driver Package Installer", "meta_original_filename": "DPInst.exe", "meta_product_name": "Driver Package Installer (DPInst)", "meta_company_name": "Microsoft Corporation", "meta_file_version": "2.1", "meta_product_version": "2.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/07acbff9a241cf67051807d261066db56b159e3e25b26feb8564a7ed1bc74e8b/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Windows\\DPINST.LOG": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Amazon\\XenTools\\dpinst.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\SYSTEM32\\AcLayers.DLL", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\sfc.dll", "C:\\Windows\\SYSTEM32\\WINSPOOL.DRV", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\SYSTEM32\\sfc_os.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\TextInputFramework.dll", "C:\\Windows\\System32\\CoreUIComponents.dll", "C:\\Windows\\System32\\CoreMessaging.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\SYSTEM32\\wintypes.dll" ], "runtime_window_title": "Device Driver Installation Wizard" }, "Installer.exe-A2482151B8383952231F9A08E18D5991": { "file_name": "Installer.exe", "file_path": "C:\\Program Files\\Amazon\\XenTools\\Installer.exe", "hash_md5": "A2482151B8383952231F9A08E18D5991", "hash_sha1": "82177C46189AD3A2DE0E982E1A8C93FFDF275AE7", "hash_sha256": "491DAEC01109E949162A2B97C550060F2C03C86C3F8B9ACDB8018FFC0B005A3E", "hash_sha384": "160B6FAD92EEE5151C06D3DAF53B15D517CB106D2FFC922BC25C78BCD8AC6E6D275B836CFD6836D8C449D2FF9581BE54", "hash_sha512": "EBA82F8A81F4A403EA845FFE9224B7FAB753EBD2067A4775B3BF3199290C5606B0268A211ED2606753B30CACAF21029B18270EF46BDA1F98757A96E667F8CFFB", "hash_ssdeep": "768:Rw3mF9n9Ahyqwr/txj3EXXtVtHmIssDUjpYClRZwWg8npULX+bTwvAuu4VtIfUpx:Rw3iqsWPtHma2YCzZz+c6Yp0PBUfGT", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "5A3465F0073B39997CFA96BA6280223DA08FD471", "hash_pe256": "8F8EACC9BA4B93643840F73DBA575CA73219ADFD91B475506FD03180F568D109", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "2F83C35B5136353D68CE9EB669FD1B0B", "signature_thumbprint": "4BAD227329ADEF18F215B6475FB7948E1629B505", "signature_issuer": "CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US", "signature_subject": "CN=Amazon.com Services LLC, OU=Software Services, O=Amazon.com Services LLC, L=Seattle, S=Washington, C=US", "meta_description": "Installer", "meta_original_filename": "Installer.exe", "meta_product_name": "Installer", "meta_company_name": "Amazon Web Services, Inc.", "meta_file_version": "8.3.4", "meta_product_version": "8.3.4", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Amazon Web Services, Inc. 2016", "meta_machinetype": "32-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "2020-10-19 23:02:26,307 [1] ERROR - Installing Drivers (8.3.4) failed.\r\n2020-10-19 23:02:26,924 [1] INFO - UninstallServiceIfExist: AWSPVDriverSchedulerService\r\n2020-10-19 23:02:27,045 [1] INFO - UninstallServiceIfExist: Service is already uninstalled, do nothing: AWSPVDriverSchedulerService\r\n2020-10-19 23:02:27,374 [1] INFO - Deleted directory: C:\\Program Files\\Amazon\\XenTools\\.Drivers\r\n2020-10-19 23:02:27,374 [1] INFO - Deleted - C:\\Program Files\\Amazon\\XenTools\\.Drivers\r\n2020-10-19 23:02:27,496 [1] INFO - Deleted directory: C:\\Program Files\\Amazon\\XenTools\\.Symbols\r\n2020-10-19 23:02:27,496 [1] INFO - Deleted - C:\\Program Files\\Amazon\\XenTools\\.Symbols\r\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\XenTools\\Installer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "LiteAgent.exe-3727559C2C2FE26EE668086FAF992815": { "file_name": "LiteAgent.exe", "file_path": "C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe", "hash_md5": "3727559C2C2FE26EE668086FAF992815", "hash_sha1": "75C96B1E5BFAA4875E737FA63455F813C9B591B4", "hash_sha256": "8130E7A850E0A088CB46F2595F7418CE9D73CE2F7750FC017ABC5CF3DED05F06", "hash_sha384": "59A78B0D8F361ED72AB62108967A8DEB394FD5AF1F83562B8C6EAF409365B14246C7350508EFE2307053C604BCC61116", "hash_sha512": "C105925D1CE7FCE608ED9ABBBC4D6AC251E6E14DB0AF62A0E1E34CFF6F4EF7B966844E22FF8F912DB8B3EAD0BDA3ED51ABF0C8A90FB3CFBFDEB8DA780C70DD1F", "hash_ssdeep": "6144:Qkh0os5hzTY9rTIr/EaV16VQHbcVY2CWNsvJKdyCD+n+sUqzK++S4PV9UJg5m2AH:Ph0RjPY9XI5bcVY2CksAs+SiPi2ATb", "hash_imp": "C8B18E9A517CB77EA7AB3E7295D84FE8", "hash_pesha1": "D790C4CA3A093C9ECE2900B0CDDB03F56D26C343", "hash_pe256": "E52F0BF126B314BEF3AFD843D6F9AAA68B700AF50121B607F26D015745FDF8CE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "015739DFC76C6256E7F4637282ACF160", "signature_thumbprint": "C21B73FB4E5B64D1AB23A6E4620E7780819446E9", "signature_issuer": "CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US", "signature_subject": "CN=\"Amazon Web Services, Inc.\", OU=EC2 Windows, O=\"Amazon Web Services, Inc.\", L=Seattle, S=Washington, C=US, PostalCode=98109, STREET=410 Terry Ave N, SERIALNUMBER=4152954, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US, OID.2.5.4.15=Private Organization", "meta_description": "xenagent", "meta_original_filename": "xenagent.exe", "meta_product_name": "XENIFACE", "meta_company_name": "Amazon Inc.", "meta_file_version": "1.0", "meta_product_version": "8.2.7.5", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright (c) Amazon Inc.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/8130e7a850e0a088cb46f2595f7418ce9d73ce2f7750fc017abc5cf3ded05f06/detection/" }, "XenStore_Client.exe-5FD3831D176CD3D8640832C5B66DE646": { "file_name": "XenStore_Client.exe", "file_path": "C:\\Program Files\\Amazon\\XenTools\\XenStore_Client.exe", "hash_md5": "5FD3831D176CD3D8640832C5B66DE646", "hash_sha1": "EE224C1D5FAB8E8ABC36847407F3FFA581100DF7", "hash_sha256": "D6EA866CDF346F5D77B25E2DEFC85039D6064A9F4110E1D6E93B2CEA5D1988FA", "hash_sha384": "83CA516DB4DA3D87F7161A002F1B3A9B7D9937EDA777E9FD9D240B38C5D3409941F3B4608CA4D02946088FACA178D2E0", "hash_sha512": "13006C08369D8780785E038BC44837044AFE81E424437CFDDDAFBECAC48FFEEEA11E8B4AEBAC2B7B4CC7ABC3047DA033868EB963F9F5DFD6D19E2E2D27FA1485", "hash_ssdeep": "3072:4Y+son9vKQgJ1TRNILfUnwTfOKsLmDF+XkxXtrTcaZ0F:4Y+sS9Cz3TsswTfOKrNFZ", "hash_imp": "7B022230051F87318BF767AC43EB68F8", "hash_pesha1": "8ADAF0C9E220D87B73574CB78AECE5EAC720A39F", "hash_pe256": "3CC9268102B1164458D5AC85F38E8C155C3DA21840A16B5A8A334E5BDDF706C8", "signature_status": 2, "signature_status_message": "The file C:\\Program Files\\Amazon\\XenTools\\XenStore_Client.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "XENSTORE_CLIENT", "meta_original_filename": "XENSTORE_CLIENT.EXE", "meta_product_name": "XENSTORE_CLIENT", "meta_company_name": "Amazon Inc.", "meta_file_version": "7.2.0.0", "meta_product_version": "7.2.0.0", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 2014 Amazon Inc.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/64", "filescan_vtlink": "https://www.virustotal.com/gui/file/d6ea866cdf346f5d77b25e2defc85039d6064a9f4110e1d6e93b2cea5d1988fa/detection/", "output": "xenstore_client -- access xenstore from the command line\r\n\r\nUsage:\r\n xenstore_client read {path} Read {path} and print contents\r\n xenstore_client write {path} {data} Set {path} to {data}\r\n xenstore_client dir {path} List subkeys of {path}\r\n xenstore_client remove {path} Remove key {path}\r\n", "runtime_modules": [ "C:\\Program Files\\Amazon\\XenTools\\XenStore_Client.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dpinst.exe-": { "file_name": "dpinst.exe", "file_path": "C:\\Program Files\\Amazon\\XenTools\\.Drivers\\xenbus\\dpinst.exe", "hash_md5": null, "hash_sha1": null, "hash_sha256": null, "hash_sha384": null, "hash_sha512": null, "signature_status": null, "signature_status_message": null, "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null }, "LiteAgent.exe-": { "file_name": "LiteAgent.exe", "file_path": "C:\\Program Files\\Amazon\\XenTools\\.Drivers\\xeniface\\LiteAgent.exe", "hash_md5": null, "hash_sha1": null, "hash_sha256": null, "hash_sha384": null, "hash_sha512": null, "signature_status": null, "signature_status_message": null, "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null }, "InputPersonalization.exe-331C85EB9BB158401BC36723595AC3A3": { "file_name": "InputPersonalization.exe", "file_path": "C:\\Program Files\\Common Files\\microsoft shared\\ink\\InputPersonalization.exe", "hash_md5": "331C85EB9BB158401BC36723595AC3A3", "hash_sha1": "C1EC3F69B863E509FE0D14A21D89FD853517439D", "hash_sha256": "249103E334745D187C729B73FED842E76D138333668D06747A8D170840E7013D", "hash_sha384": "414039C384FD25AE375571DEF97D31DFD63444429A5D26ACF9380361A3560CA3F1EBAA6D4E5367C104997237F58ECFE2", "hash_sha512": "3C2B74699019ABF1513A0DE8886279CCE73640BA056DD82D6977CC0F907AB32CB46A0F4555A3A84C578FCAEA0C0BAFEB45B5AAA604E9677B0FB90F5E0C01C0FB", "hash_ssdeep": "6144:IkaOXLzmunf+kaIWu5Bl6h5VWYnZr1jyG20HhjKm5b/6NBcKjX:uObzVnf+kaIWu5amAr1jPT1KQb/6Nt", "hash_imp": "615FE08745F46A3B1727DFA67336AC01", "hash_pesha1": "76DDF33183B91D0281F2DAB4E8B915100377EF28", "hash_pe256": "B4F5BED50CB0A38225E350565361025749EC7AAD7887993FB7539AA134871A50", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Input Personalization Server", "meta_original_filename": "InputPersonalization.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/249103e334745d187c729b73fed842e76d138333668d06747a8d170840e7013d/detection/", "runtime_modules": [ "C:\\Program Files\\Common Files\\microsoft shared\\ink\\InputPersonalization.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\IMM32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\XmlLite.dll", "C:\\Windows\\SYSTEM32\\elscore.dll" ] }, "mip.exe-259069D594D07D2E7EB064B3CC1A6DD5": { "file_name": "mip.exe", "file_path": "C:\\Program Files\\Common Files\\microsoft shared\\ink\\mip.exe", "hash_md5": "259069D594D07D2E7EB064B3CC1A6DD5", "hash_sha1": "703914BCD3C6CE24E93473E3F6F432538981C9B4", "hash_sha256": "FD5CC426FCDE9774005926003318EDE4099829BCE4B3C9886ACF41BF3165314C", "hash_sha384": "AA7404576CFDD4AC22C6A75324FCF741353FB9E975E9DD427D219E61781330B0E6746864E5D57A3768DB034273CC4468", "hash_sha512": "1C3FFDBE733150B6464348551479870742A0B02E385A80458DB923E8490F3D4910C9AF91E36A4AD4DBCAD0EA6E16413C0D37F2A43ECDAD4CA041ED430923A68A", "hash_ssdeep": "24576:mf2Yj8VYYfo3JobUJrc1JHIH5hCw29jg3Ov0zed0UaDKk4QBb3wsa20y:XM8VYYA5oMcfMCqUaDKZm3wf2d", "hash_imp": "5E36AF4CBB94E6119E2F99D0A20A9957", "hash_pesha1": "073D5DBC3B9915DA7C35486CA45427C7CED9BB03", "hash_pe256": "1638E46FC07CA56066E4C7A1A9F302A4B34CB0E4392A931DE13AAC7156A2DABF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Math Input Panel Accessory", "meta_original_filename": "mip.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/74", "filescan_vtlink": "https://www.virustotal.com/gui/file/fd5cc426fcde9774005926003318ede4099829bce4b3c9886acf41bf3165314c/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Program Files\\Common Files\\microsoft shared\\ink\\en-US\\mip.exe.mui": "File", "\\RPC Control\\DSEC9CC": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Sessions\\2\\BaseNamedObjects\\9ccHWNDInterface:8606d2": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Common Files\\microsoft shared\\ink\\mip.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\OLEACC.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\UxTheme.dll", "C:\\Windows\\SYSTEM32\\MSIMG32.dll", "C:\\Windows\\SYSTEM32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\system32\\dataexchange.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\system32\\dcomp.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\system32\\twinapi.appcore.dll", "C:\\Windows\\system32\\RMCLIENT.dll", "C:\\Windows\\SYSTEM32\\WindowsCodecs.dll", "C:\\Program Files\\Common Files\\Microsoft Shared\\Ink\\InkObj.dll", "C:\\Program Files\\Common Files\\Microsoft Shared\\Ink\\rtscom.dll", "C:\\Program Files\\Common Files\\Microsoft Shared\\Ink\\mshwgst.dll", "C:\\Windows\\System32\\wisp.dll", "C:\\Program Files\\Common Files\\Microsoft Shared\\Ink\\tpcps.dll", "C:\\Windows\\System32\\msxml6.dll", "C:\\Windows\\SYSTEM32\\avrt.dll" ] }, "ShapeCollector.exe-12E4B4C222C64376DDE03D9FBF93ED55": { "file_name": "ShapeCollector.exe", "file_path": "C:\\Program Files\\Common Files\\microsoft shared\\ink\\ShapeCollector.exe", "hash_md5": "12E4B4C222C64376DDE03D9FBF93ED55", "hash_sha1": "AAADD0CD3A5C9E92B2F5B7CA55A926B55BCE9923", "hash_sha256": "5718C40A309AAD4DB4F616EF89AF0C823948EE157A3F3E843533CFF4618A85F9", "hash_sha384": "8F001BE577CB422B83F7BC2950AFAE1B2B1579FC9F53F281808ADAC35FA44AC66B02FCC2AE064C9347E209389E504982", "hash_sha512": "72F5211D3ED1E2BA00856F649E3F3F0C3ECD8AB6383CA59CB8AF68D3E7C95F80DE939BE1E0346E93ED6C2E03A2455CE4C2BFD7883C77996F0123AC53DE5B313E", "hash_ssdeep": "6144:VCiw7TF1TwaXGA69XfNmrwGoQlXYKoAh7wUCV5SOmQEJpGgh1OuR9gpC1RjDksOh:VCCTDQlXYKoAMV5SPQEmgLlSo5Xw", "hash_imp": "CC88C9C4DDCBF9C9FB6CF2CEB3EA0A1D", "hash_pesha1": "4589D41BCB3B18489ADFA472AB797F94CE619375", "hash_pe256": "64692FABE8ED67761175459DBE117A1FAD21EF6C1052F2CF3ED8802681DBF4C3", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Personalize Handwriting Recognition UI", "meta_original_filename": "ShapeCollector.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/5718c40a309aad4db4f616ef89af0c823948ee157a3f3e843533cff4618a85f9/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Program Files\\Common Files\\microsoft shared\\ink\\en-US\\ShapeCollector.exe.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Common Files\\microsoft shared\\ink\\ShapeCollector.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\DUI70.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "runtime_window_title": "Handwriting Personalization" }, "TabTip.exe-FF1E1239ADDC318448E8F054CD72EBE6": { "file_name": "TabTip.exe", "file_path": "C:\\Program Files\\Common Files\\microsoft shared\\ink\\TabTip.exe", "hash_md5": "FF1E1239ADDC318448E8F054CD72EBE6", "hash_sha1": "BA2E29684874A0CDA65ECBF61EAB1547F2C7818D", "hash_sha256": "A834F4A957823F43656635026369C8ED537D4C3C29D4C8AA2473EA684DE8E767", "hash_sha384": "6F56626258E774C39D5F00E0ACF6AA5A0F0E45B1C5F6CCF9B45E63F426CCFA18354688E26259A9334526747D981A981E", "hash_sha512": "413E70F812E8E4B475977D64258AC581D79BC0AD2F940A556ED727BA97615C46DD68B8CC5AB3DA09629C5EB28F1E1C1E99042E671C61521B29FDFBD277F7D3EB", "hash_ssdeep": "12288:BclX+XV2/YnScN175uKlh02z7ivqmbf+hk4xKGa:BclXbYnSc/4KWlGkYKGa", "hash_imp": "9100AFE9AC7DE0573054B3791F4B1EA4", "hash_pesha1": "AFC09B12010DAC7DC31089AF2111CA57F2391A02", "hash_pe256": "B0263B551EB50DA6D746182848F064665D5D5C1C112502470A3322BAD07648DF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Touch Keyboard and Handwriting Panel", "meta_original_filename": "TabTip.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a834f4a957823f43656635026369c8ed537d4c3c29d4c8aa2473ea684de8e767/detection/" }, "ExtExport.exe-1D71EDDF5BC772FF5AAE7AD292A179D4": { "file_name": "ExtExport.exe", "file_path": "C:\\Program Files\\internet explorer\\ExtExport.exe", "hash_md5": "1D71EDDF5BC772FF5AAE7AD292A179D4", "hash_sha1": "092FE10D1B8DACBED9611F30CC82AF6978CC3818", "hash_sha256": "D3156EE400DDE48A9F7178CF5C8717A2553BF9ACD3C2322717A53BF207842D8C", "hash_sha384": "AF6C94E5AC7941269276B20DA75C93B792FE8ADA0473D6889A8367B3530B75BBE2BF54DC48EC2D048BC1C0F02953FAB2", "hash_sha512": "6C2EC4A4539DE31B01A25458B06266F981D749786AC3BDD593F50011F8A524461E6BDB00EEDF4553DF3EA7FE154D8A376FE4447B79067F9E27FF0A7108311E20", "hash_ssdeep": "1536:MdqbrEa+KYumBchwizRJxdWyfZdSgGjHVTfY2Mv3+3xbKZ/HMsQt1TZ/Iutz:MdqbrEZK+cS+0a8gyrMv3+3xbKZ/HMse", "hash_imp": "53D3D6675DF14EB40803104BF2C8993D", "hash_pesha1": "A1C08826220C653EB4D5BF79E5628172582C7891", "hash_pe256": "6E588FFE1C271454677CF91976389450453F0774507422C13042D7701FED2ED4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Internet Explorer ImpExp FF exporter", "meta_original_filename": "extexport.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/d3156ee400dde48a9f7178cf5c8717a2553bf9acd3c2322717a53bf207842d8c/detection/", "runtime_modules": [ "C:\\Program Files\\internet explorer\\ExtExport.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\iertutil.dll", "C:\\Windows\\System32\\IMM32.DLL" ] }, "iediagcmd.exe-458E8CE16FC3DBE56E8F374E61F77326": { "file_name": "iediagcmd.exe", "file_path": "C:\\Program Files\\internet explorer\\iediagcmd.exe", "hash_md5": "458E8CE16FC3DBE56E8F374E61F77326", "hash_sha1": "632C8512025BC80C23FB711208F656EF9DF00793", "hash_sha256": "A39A27B095053AC89717CC70650A432B2428785BBD9F7C9F1FFD8F96519D5E78", "hash_sha384": "BC4453F2960C0B2FE168ABA63E534AE4C7C564AC7E62B866A29234BFB57B520D0B288DB073CF9EA49DC1AF3B71519AA2", "hash_sha512": "68F9C973010D931B3C711671DF8D8C8AC39FC37D81B5873174DD9BED6DD231B3F858A80DE04471910C89060F0299FD8E8570ECD30864FF0CCF66F5071A270CA4", "hash_ssdeep": "12288:kLJCY57jTmPpq1Zi2HzQF5gIwgjxp21ZZ:kLJCY8R0zQF5gIww3K", "hash_imp": "8AD7D3F07924E8C2B7127391AFD2DA11", "hash_pesha1": "7316A71A24C65EB8212E420441C4A3F8CC497438", "hash_pe256": "139AC4487C798F4D89C76A9AE2F46893DC05341E67A0A2E222EE53B6ACAD2C8F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Diagnostics utility for Internet Explorer", "meta_original_filename": "IEDiagCmd.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1432 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1432", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "output": "Usage: iediagcmd \r\n\r\nOptions:\r\n /Out:value\r\n /Show\r\n /profile:value\r\n /TryAutoFix\r\n", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_4352": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\internet explorer\\iediagcmd.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\OLEACC.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\5543cca0df435801e2303ff46a482ed5\\mscorlib.ni.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\CRYPTSP.dll", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\6885802f40fd803e49150d8a2b43a09b\\System.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Drawing\\6c6bbae87386b6a33957366eae0e4470\\System.Drawing.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Windows.Forms\\23c1e20aa87eccaf2c33ba9f47d2319e\\System.Windows.Forms.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Core\\f29b1120627489754c4b8dd317bbe950\\System.Core.ni.dll" ], "error": "Arguments must start with /\r\n\r\n" }, "ieinstal.exe-58646B0C0417C0E01BECB6C922C0C10A": { "file_name": "ieinstal.exe", "file_path": "C:\\Program Files\\internet explorer\\ieinstal.exe", "hash_md5": "58646B0C0417C0E01BECB6C922C0C10A", "hash_sha1": "1B258676756A6594722C0C4F476A59F2E1B86646", "hash_sha256": "A57B027F6619281B920503C26A30FA3DAEFC874BE3FC31257F63106F7A434643", "hash_sha384": "D10D12BEED7FE277640B741A40C330182D1A2228B6A2B807C803090F1924AB8C46EB4BF34CFD5E2DC75C50A3D602B30D", "hash_sha512": "AA996AE19DA13FCDAA1F36D5B82A9A03AC793BE1726650D5771CD9319473C9FD0D2208A9AC42D19F23B1B12AB1604EF241ED4A6A7EEB4226075673C44E94BF93", "hash_ssdeep": "6144:ecaYwZJs+DsBwfw1rOt9pdYamXnrdbMKw7w1rOt9pdYamXnrdbMKw:ecaN6EFI5OLpdNIrd4Ds5OLpdNIrd4D", "hash_imp": "C5AC1A1FE6C548914C7DBCC2BC5DB3A9", "hash_pesha1": "BFF30A00A8BABFFD75140CA3AA8B9B38AA7AC840", "hash_pe256": "A077071369588656288A719F45ED975FD2821FA4F811A468D68F2291E56E76D5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Internet Explorer Add-on Installer", "meta_original_filename": "ieinstal.exe.mui", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/a57b027f6619281b920503c26a30fa3daefc874be3fc31257f63106f7a434643/detection/", "runtime_modules": [ "C:\\Program Files\\internet explorer\\ieinstal.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\SYSTEM32\\urlmon.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\iertutil.dll", "C:\\Windows\\SYSTEM32\\AUTHZ.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.DLL" ] }, "ielowutil.exe-97484E82D101785A7BE817FCF9C4CBD3": { "file_name": "ielowutil.exe", "file_path": "C:\\Program Files\\internet explorer\\ielowutil.exe", "hash_md5": "97484E82D101785A7BE817FCF9C4CBD3", "hash_sha1": "F33B0BB5499CDB6A4B5692C6668CB5CE4BA7150D", "hash_sha256": "A52B302AAA40A678BC61653F1271DEBDA2D6B1CEC6CC13972120D63A25D0CB12", "hash_sha384": "3899DE38876BFA568D13195C76A82D0EBDC838F0DFE55DFAC0FBD1E4C913194F0682DC100E093697098EF398D4322687", "hash_sha512": "EAD760C869D90DB4BB9D4856ECAFD506CEB93D6709E3B725A202222F65548C6580AE0B8E51C52F1AD6544F26533700FD83EDE0503EEA8226C426454A4E9812AB", "hash_ssdeep": "3072:AstD7trOt9pfslMYO9mXn9H0LeinObM6gZy5ChoTi3:Aw1rOt9pdYamXnrdbMKw", "hash_imp": "61AF1968F474A57E9628EA85799D5181", "hash_pesha1": "1FCF00D63CC219B8ABB871B0C5BF9A4922CB4C6E", "hash_pe256": "B98F7CA60426C964C20668281C94808E1C53A88057E7FB57C892C6AF8743B50A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Internet Low-Mic Utility Tool", "meta_original_filename": "ielowutil.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/61", "filescan_vtlink": "https://www.virustotal.com/gui/file/a52b302aaa40a678bc61653f1271debda2d6b1cec6cc13972120d63a25d0cb12/detection/" }, "iexplore.exe-F640445694FD65DEC07CA3A84F560534": { "file_name": "iexplore.exe", "file_path": "C:\\Program Files\\internet explorer\\iexplore.exe", "hash_md5": "F640445694FD65DEC07CA3A84F560534", "hash_sha1": "5D5586E4273110D48F2CD8B19A91E8853DE5E02C", "hash_sha256": "28FD5F83C7A2ED53C284BA791F0668C309E287576744530B6E9FC4C228D4B33B", "hash_sha384": "CABCDE4FD38229744066BD781BECACCA7727B250E6966AEFFD961147A9B77495B40D4ACC42D40F9E7090F910E68432B9", "hash_sha512": "9746AE0953377DBB6541D0DCC9CCB0DA1845C98CB167103C0B9F484D496BD659C7B9E5E5D244E527B30F9F04A736C5BD4043B8DC5E9BEFFA0C7AD879C2C1CE17", "hash_ssdeep": "24576:J4lGLbMMHMMMvMMZMMMKzb6XmMMMiMMMz8JMMHMMM6MMZMMMeXNMMzMMMUMMVMMr:3MMHMMMvMMZMMMlmMMMiMMMYJMMHMMMP", "hash_imp": "BF1B4238FCDBB117EDF39418CA0D205C", "hash_pesha1": "45B4E014D8BA963572F9BA85450D35B6C4B1717A", "hash_pe256": "E5D6E53256D536EBD6EE4568093D4B5E3965AFD6060C696E0D7DD1FC74B81AFA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Internet Explorer", "meta_original_filename": "IEXPLORE.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/28fd5f83c7a2ed53c284ba791f0668c309e287576744530b6e9fc4c228d4b33b/detection/", "children": "iexplore.exe", "runtime_handles": { "(R-D) C:\\Program Files\\internet explorer\\en-US\\iexplore.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\RPC Control\\DSEC558": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326": "File", "\\Sessions\\2\\BaseNamedObjects\\ie_ias_00000558-0000-0000-0000-000000000000": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_ie_global_counters": "Section", "\\Sessions\\2\\BaseNamedObjects\\IsoScope_558_IsoSpaceV2_ScopeTrusted": "Section", "\\Sessions\\2\\BaseNamedObjects\\IsoSpaceV2_LogonMediumx64": "Section", "\\Sessions\\2\\BaseNamedObjects\\VERMGMTSharedMemory": "Section", "\\Sessions\\2\\BaseNamedObjects\\IsoScope_558_IEFrame!GetAsyncKeyStateSharedMem": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Users\\user\\Desktop": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_webcache_counters_{9B6AB5B3-91BC-4097-835C-EA2DEC95E9CC}_S-1-5-21-4075667164-670084373-454571106-500": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\F932B6C7-3A20-46A0-B8A0-8894AA421973": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\ieframe.dll.mui": "File", "(---) C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{CB5585C4-1260-11EB-829E-0A8C8577B1EA}.dat": "File", "(RWD) C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2\\~DFA726461E236BAC58.TMP": "File", "\\Sessions\\2\\BaseNamedObjects\\UrlZonesSM_Administrator": "Section", "\\Sessions\\2\\BaseNamedObjects\\558HWNDInterface:70780": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Sessions\\2\\BaseNamedObjects\\558HWNDInterface:2076a": "Section", "\\Sessions\\2\\BaseNamedObjects\\558HWNDInterface:20750": "Section", "\\Sessions\\2\\BaseNamedObjects\\558HWNDInterface:607be": "Section", "\\Sessions\\2\\BaseNamedObjects\\IsoScope_558_IsoSpaceV2_ScopeTrusted_0:7_1": "Section", "(---) C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{CB5585C6-1260-11EB-829E-0A8C8577B1EA}.dat": "File", "(RWD) C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2\\~DF0DC33E760EC90AF6.TMP": "File", "\\Sessions\\2\\BaseNamedObjects\\IsoScope_558_IsoSpaceV2_ScopeTrusted_0:6_2": "Section", "\\Sessions\\2\\BaseNamedObjects\\558HWNDInterface:2074a": "Section", "\\Sessions\\2\\BaseNamedObjects\\558HWNDInterface:6079c": "Section", "\\Sessions\\2\\BaseNamedObjects\\IsoScope_558_IsoSpaceV2_ScopeTrusted_0:3_3": "Section", "\\Sessions\\2\\BaseNamedObjects\\IsoScope_558_IsoSpaceV2_ScopeTrusted_0:3_4": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\...\\!PrivacIE!SharedMem!Settings": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\internet explorer\\iexplore.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\SYSTEM32\\iertutil.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\msIso.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\IEFRAME.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\NETAPI32.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\SYSTEM32\\WINHTTP.dll", "C:\\Windows\\SYSTEM32\\NETUTILS.DLL", "C:\\Windows\\SYSTEM32\\WKSCLI.DLL", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Program Files\\internet explorer\\IEShims.dll", "C:\\Windows\\System32\\comdlg32.dll", "C:\\Windows\\SYSTEM32\\urlmon.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.DLL", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\SYSTEM32\\dhcpcsvc6.DLL", "C:\\Windows\\SYSTEM32\\dhcpcsvc.DLL", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\SYSTEM32\\ieapfltr.dll", "C:\\Windows\\SYSTEM32\\WININET.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\System32\\ieproxy.dll", "C:\\Windows\\SYSTEM32\\TOKENBINDING.dll", "C:\\Windows\\SYSTEM32\\ondemandconnroutehelper.dll", "C:\\Windows\\system32\\mswsock.dll", "C:\\Windows\\SYSTEM32\\WINNSI.DLL", "C:\\Windows\\system32\\rsaenh.dll", "C:\\Windows\\System32\\DPAPI.dll", "C:\\Windows\\SYSTEM32\\IEUI.dll", "C:\\Windows\\System32\\coml2.dll", "C:\\Windows\\system32\\windowscodecs.dll", "C:\\Windows\\System32\\oleacc.dll", "C:\\Windows\\system32\\dataexchange.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\system32\\dcomp.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\system32\\twinapi.appcore.dll", "C:\\Windows\\system32\\RMCLIENT.dll", "C:\\Windows\\system32\\explorerframe.dll", "C:\\Windows\\SYSTEM32\\MSIMG32.dll" ], "runtime_window_title": "http://--help/ - Internet Explorer" }, "MpCmdRun.exe-288D836B81E809EB33CDCCAA9D1AB395": { "file_name": "MpCmdRun.exe", "file_path": "C:\\Program Files\\Windows Defender\\MpCmdRun.exe", "hash_md5": "288D836B81E809EB33CDCCAA9D1AB395", "hash_sha1": "AB23FE8381B6D59F9D707E43C72270ABD6A0312B", "hash_sha256": "81F85A88DD1829663D5E748CA95709EFF5328444BBDB2C888F85124D939F6899", "hash_sha384": "A85379A0D80171212F0C7552566BE0D4F0A1065348EFA54F6CE0B92130447B2443304162ACD0B2B177BA158C34FC49DA", "hash_sha512": "D63334732FBB69B2290AABB3EC55B0D7F490E44FFE9B05F8C4CA9613A2BF8269B7EAC23C12E7F6460C0D6C5BA497E8A520A20336FC934F8E3D111E80C5688DE2", "hash_ssdeep": "6144:2eM+IYvdO7AePX4cikjqVg09BpapYu8EFpMEf/P:u+IjRPLiPsvdF", "hash_imp": "FFAEA1E2634A3119C40B178379C9863F", "hash_pesha1": "0BBAD52AEF2FEF17FE4395571EAB3A4D790ED280", "hash_pe256": "7235DCB5C5F73E506A4057112E8502E1DE94AC7AC15CF4C7A49DDD1BBFF6D57E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Malware Protection Command Line Utility", "meta_original_filename": "MpCmdRun.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.1807.18075 (GitEnlistment(winpbld).180719-0853)", "meta_product_version": "4.18.1807.18075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/81f85a88dd1829663d5e748ca95709eff5328444bbdb2c888f85124d939f6899/detection/", "output": "Microsoft Antimalware Service Command Line Utility (c) 2006-2018 Microsoft Corp\r\r\nUse this tool to automate and troubleshoot Microsoft Antimalware Service\r\r\n\r\r\nUsage:\r\r\nMpCmdRun.exe [command] [-options]\r\r\n\r\r\nCommand Description\r\r\n -? / -h Displays all available options\r\r\n for this tool\r\r\n -Scan [-ScanType #] [-File [-DisableRemediation] [-BootSectorScan]]\r\r\n [-Timeout ]\r\r\n [-Cancel]\r\r\n Scans for malicious software\r\r\n -Trace [-Grouping #] [-Level #] Starts diagnostic tracing\r\r\n -GetFiles Collects support information\r\r\n -GetFilesDiagTrack Same as Getfiles but outputs to \r\r\n temporary DiagTrack folder \r\r\n -RemoveDefinitions [-All] Restores the installed\r\r\n signature definitions\r\r\n to a previous backup copy or to\r\r\n the original default set of\r\r\n signatures\r\r\n [-DynamicSignatures] Removes only the dynamically\r\r\n downloaded signatures\r\r\n -SignatureUpdate [-UNC | -MMPC] Checks for new definition updates\r\r\n -Restore [-ListAll | [[-Name ] [-All] | [-FilePath ]] [-Path ]] Restore or list\r\r\n quarantined item(s)\r\r\n -AddDynamicSignature [-Path] Loads a dynamic signature\r\r\n -ListAllDynamicSignatures List the loaded dynamic signatures\r\r\n -RemoveDynamicSignature [-SignatureSetID] Removes a dynamic signature\r\r\n\r\r\nAdditional Information:\r\r\n\r\r\nSupport information will be in the following directory:\r\r\nC:\\ProgramData\\Microsoft\\Windows Defender\\Support\r\r\n\r\r\n -Scan [-ScanType value]\r\r\n 0 Default, according to your configuration\r\r\n 1 Quick scan\r\r\n 2 Full system scan\r\r\n 3 File and directory custom scan\r\r\n\r\r\n [-File ]\r\r\n Indicates the file or directory to be scanned, only valid for custom scan.\r\r\n\r\r\n [-DisableRemediation]\r\r\n This option is valid only for custom scan.\r\r\n When specified:\r\r\n - File exclusions are ignored.\r\r\n - Archive files are scanned.\r\r\n - Actions are not applied after detection.\r\r\n - Event log entries are not written after detection.\r\r\n - Detections from the custom scan are not displayed in the user interface.\r\r\n - The console output will show the list of detections from the custom scan.\r\r\n\r\r\n [-BootSectorScan]\r\r\n Enables boot sector scanning; only valid for custom scan.\r\r\n\r\r\n [-Timeout ]\r\r\n Timeout in days; maximum value is 30.\r\r\n If this parameter is not specified, default value is 7 days for full scan and 1 day for all other scans.\r\r\n\r\r\n [-Cancel]\r\r\n Try to cancel any ongoing quick or full scan.\r\r\n\r\r\n Return code is\r\r\n 0 if no malware is found or malware is successfully remediated and no additional user action is required\r\r\n 2 if malware is found and not remediated or additional user action is required to complete remediation or there is error in scanning. Please check History for more information.\r\r\n\r\r\n -Trace [-Grouping value] [-Level value]\r\r\n Begins tracing Microsoft Antimalware Service's actions.\r\r\n You can specify the components for which tracing is enabled and\r\r\n how much information is recorded.\r\r\n If no component is specified, all the components will be logged.\r\r\n If no level is specified, the Error, Warning and Informational levels\r\r\n will be logged. The data will be stored in the support directory\r\r\n as a file having the current timestamp in its name and bearing\r\r\n the extension BIN.\r\r\n\r\r\n [-Grouping]\r\r\n 0x1 Service\r\r\n 0x2 Malware Protection Engine\r\r\n 0x4 User Interface\r\r\n 0x8 Real-Time Protection\r\r\n 0x10 Scheduled actions\r\r\n 0x20 NIS/GAPA\r\r\n\r\r\n [-Level]\r\r\n 0x1 Errors\r\r\n 0x2 Warnings\r\r\n 0x4 Informational messages\r\r\n 0x8 Function calls\r\r\n 0x10 Verbose\r\r\n 0x20 Performance\r\r\n\r\r\n -GetFiles\r\r\n Gathers the following log files and packages them together in a \r\r\n compressed file in the support directory\r\r\n\r\r\n - Any trace files from Microsoft Antimalware Service\r\r\n - The Windows Update history log\r\r\n - All Microsoft Antimalware Service events from the System event log\r\r\n - All relevant Microsoft Antimalware Service registry locations\r\r\n - The log file of this tool\r\r\n - The log file of the signature update helper tool\r\r\n\r\r\n -GetFilesDiagTrack\r\r\n Same as GetFiles, but outputs the CAB file to the temp DiagTrack \r\r\n directory\r\r\n\r\r\n -RemoveDefinitions\r\r\n Restores the last set of signature definitions\r\r\n\r\r\n [-All]\r\r\n Removes any installed signature and engine files. Use this \r\r\n option if you have difficulties trying to update signatures.\r\r\n\r\r\n [-DynamicSignatures]\r\r\n Removes all Dynamic Signatures. \r\r\n\r\r\n -SignatureUpdate\r\r\n Checks for new definition updates\r\r\n\r\r\n [-UNC [-Path ]]\r\r\n Performs update directly from UNC file share specified in \r\r\n If -Path is not specified, update will be performed directly from the\r\r\n preconfigured UNC location\r\r\n\r\r\n [-MMPC]\r\r\n Performs update directly from Microsoft Malware Protection Center\r\r\n\r\r\n -Restore\r\r\n [-ListAll]\r\r\n List all items that were quarantined\r\r\n\r\r\n [-Name ]\r\r\n Restores the most recently quarantined item based on threat name\r\r\n One Threat can map to more than one file\r\r\n\r\r\n [-All]\r\r\n Restores all the quarantined items based on name\r\r\n\r\r\n [-FilePath ]\r\r\n Restores quarantined item based on file path\r\r\n\r\r\n [-Path]\r\r\n Specify the path where the quarantined items will be restored.\r\r\n If not specified, the item will be restored to the original path.\r\r\n -AddDynamicSignature -Path \r\r\n Adds a Dynamic Signature specified by \r\r\n\r\r\n -ListAllDynamicSignatures\r\r\n Lists SignatureSet ID's of all Dynamic Signatures added to the client\r\r\n via MAPS and MPCMDRUN -AddDynamicSignature\r\r\n\r\r\n -RemoveDynamicSignature -SignatureSetID \r\r\n Removes a Dynamic Signature specified by \r\r\n\r\r\n", "runtime_modules": [ "C:\\Program Files\\Windows Defender\\MpCmdRun.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Program Files\\Windows Defender\\mpclient.dll", "C:\\Windows\\SYSTEM32\\Secur32.dll", "C:\\Windows\\SYSTEM32\\SSPICLI.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\version.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\SYSTEM32\\gpapi.dll" ] }, "MsMpEng.exe-CEDC4E5155D9D48F2922C21EC02419B7": { "file_name": "MsMpEng.exe", "file_path": "C:\\Program Files\\Windows Defender\\MsMpEng.exe", "hash_md5": "CEDC4E5155D9D48F2922C21EC02419B7", "hash_sha1": "82E7FFB4E780BF16F3C42D52E2C6B0A4EF48732C", "hash_sha256": "B147CC9A14B92E224C7755D41E0453506F983E7874573F1DF79F3EBF27BED090", "hash_sha384": "2C228AF83455013F00172BDD6B3CAACC40BC85CAA37CFC81A2DCBBF4FB4B108348D08DDEC711455356EFA0937B194FC0", "hash_sha512": "9B4B23C5C8053526AAA4C85182B88E0CD8BFC8B4F09BBE264E6CD900061F10E77C339072116B6ECE87D2B6BFAC4CAE1211BC93143A766448F5913F12F9F2FFA4", "hash_ssdeep": "3072:GggdXEoTjiYxqS/Gn35KTen6tk5knppQslDt:GlZEgGYBoFVynpplDt", "hash_imp": "D3CAE088864F29A1BAAAC62FAD45C882", "hash_pesha1": "D959A2A519132A5B0F59ECE03761F8FF07B94EEE", "hash_pe256": "52AFDDDFF99112215DA2F99EC282948F0792753D760F9FE6D73EA6A9BEB01172", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Antimalware Service Executable", "meta_original_filename": "MsMpEng.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.1807.18075 (GitEnlistment(winpbld).180719-0853)", "meta_product_version": "4.18.1807.18075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/b147cc9a14b92e224c7755d41e0453506f983e7874573f1df79f3ebf27bed090/detection/" }, "NisSrv.exe-A19C36423BD32B1046781CC0B3B67F41": { "file_name": "NisSrv.exe", "file_path": "C:\\Program Files\\Windows Defender\\NisSrv.exe", "hash_md5": "A19C36423BD32B1046781CC0B3B67F41", "hash_sha1": "14E54A38697321A0547142F72192ADA6219E6160", "hash_sha256": "1FE1F4B5A65AEDBBD3676959E5B10D744FABA59727F6F58DC141B5211F1F6974", "hash_sha384": "B785960A4F2EE0854C582666E08428F72775D5F2B0B1CEBEF5AFAD6DD078F23586F5E109C565A25BD2311545B3BA06F3", "hash_sha512": "616CD2FA8E5367B0ED4475B2E942E59412F0CA750BE02BE0494D767B68586C0155F5D43BCA9A9629CCED0DC6952EA1A0446F56248FE634A39DF35F269EA8DCAE", "hash_ssdeep": "49152:zITOsROxWZ+q9KCKhvO7a0DMTNYuUn89KOArxm7Kb6KvySgYneeahv3nmS7yAqA:h6SiMRYI9urj6KvySznefhv3VWNA", "hash_imp": "CC8925537C6EFC7F7353A89069CF5178", "hash_pesha1": "9E57F35DFE7EA63D1DA6AC892F28FAAF0D6AF81E", "hash_pe256": "B69C31B2C847819C842858EA9765077CCDAA4EB79B2120AD0B1B29C6850BC814", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Network Realtime Inspection Service", "meta_original_filename": "NisSrv.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "4.18.1807.16384 (WinBuild.160101.0800)", "meta_product_version": "4.18.1807.16384", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/1fe1f4b5a65aedbbd3676959e5b10d744faba59727f6f58dc141b5211f1f6974/detection/" }, "MsSense.exe-6FEE3946D9194217B2F7B4D7E867CD0A": { "file_name": "MsSense.exe", "file_path": "C:\\Program Files\\Windows Defender Advanced Threat Protection\\MsSense.exe", "hash_md5": "6FEE3946D9194217B2F7B4D7E867CD0A", "hash_sha1": "31A35DF173BDD78F3E2E568272496504822C8B1F", "hash_sha256": "AF7115B5715618716E88FB62CC0548B2F5EAF751D0BA8320B99B285D956A4E87", "hash_sha384": "71A2A21EBEA62396305EE6686680A0B9E50BC153FED441C6C9047C1303BD3FFCFA78C73F3B7D211415A9B089D020A470", "hash_sha512": "238456AEC29057919A5C50F0DEA25B55CDC7243D492375EADF954F715679D9EB961CF23B03B687A14A5BDCB1EECDA1A781CD01B379B7B471098318352C96B533", "hash_ssdeep": "49152:HLLT2rKXH4W/myT9iQhnJcBsg9kcVyXykeXyy2/Don5YWzhUH7VW0zSMV2h0cElA:fyoqvKrIoRD+YfRX+x", "hash_imp": "8D60D67BAFAB47F6D5D23D2B10A665F8", "hash_pesha1": "26E85A87580DFC10F51C16E16A321C52F9354C69", "hash_pe256": "5641580983D7A7A4FA3F9BB7809F996900476CDE1292EBE901863B630960738E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Defender Advanced Threat Protection Service Executable", "meta_original_filename": "MsSense.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.7410.17763.1369 (WinBuild.160101.0800)", "meta_product_version": "10.7410.17763.1369", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/af7115b5715618716e88fb62cc0548b2f5eaf751d0ba8320b99b285d956a4e87/detection/", "runtime_modules": [ "C:\\Program Files\\Windows Defender Advanced Threat Protection\\MsSense.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\SYSTEM32\\Wldp.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\SYSTEM32\\TelLib.dll" ] }, "SenseCncProxy.exe-5EB0B91DF57713213DEEBC56C6930784": { "file_name": "SenseCncProxy.exe", "file_path": "C:\\Program Files\\Windows Defender Advanced Threat Protection\\SenseCncProxy.exe", "hash_md5": "5EB0B91DF57713213DEEBC56C6930784", "hash_sha1": "D0C8E9F8C8CE72007693504045BA730065CECF2C", "hash_sha256": "1F44CB03B35A5F994CF9B70D2399F8A6A3446DE3A85F0D88791045898742EEBD", "hash_sha384": "4E71C461858F232BA8D05D7ED98DD498644FEFE23F0F9421D292960102E28C5511ED99A5CF92C5EEB9D494FEF32E1BB9", "hash_sha512": "F42C05DE883DD033AA30AD899CA466A506AA4D920EF9BF8F73A10294B1B1AED55AA0F27E881A5816E1BB7701D5A3076D62397B3E048492136DB413B4D54440F5", "hash_ssdeep": "12288:Wvz3hf9Rz91gjgZnktQHZ8jBssS7D+upPVH:GVf9RR1gj4nzZYe7D+upPVH", "hash_imp": "19F8E1FDA45EBB2D9563E29E05522402", "hash_pesha1": "70A7FF04DC003BF3F26DAC57EE5E5B565C99E805", "hash_pe256": "A280858679D659981E2B26B9C715125A5D9D8EDFE8FDE6052CB4E7AB38EC6C7E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Defender Advanced Threat Protection Communications module", "meta_original_filename": "SenseCncProxy.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.7410.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.7410.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/1f44cb03b35a5f994cf9b70d2399f8a6a3446de3a85f0d88791045898742eebd/detection/", "runtime_modules": [ "C:\\Program Files\\Windows Defender Advanced Threat Protection\\SenseCncProxy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\WINHTTP.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\SYSTEM32\\DPAPI.DLL", "C:\\Windows\\System32\\IMM32.DLL" ] }, "SenseIR.exe-855B6185621E028D540FDC6F900F0721": { "file_name": "SenseIR.exe", "file_path": "C:\\Program Files\\Windows Defender Advanced Threat Protection\\SenseIR.exe", "hash_md5": "855B6185621E028D540FDC6F900F0721", "hash_sha1": "859140D28D79AF74CD9B36A2429CC55740F274CC", "hash_sha256": "6F839E0CABD582352403BF744AF6D550BCF7049039E8216E4F7E35B4B173E27A", "hash_sha384": "2ECD576FD76811A08E808C2828BF17BA383252B9D1AFD7D31BBDFE195AA1DA38B9D36A52A949FCD3470742099ABB770A", "hash_sha512": "DE769271C8317E8C42B935DD7DA0152B2A6DC04F6168F319B97E2DB654C382A2E06D0C6495E8BFA20C48245A91C69822A14DC18F748832B3D594C12B5C30BFF2", "hash_ssdeep": "49152:Im8Jh0bu0ZGAlcdVU8RXSmM39V3RZ0frSnWvUrThJtdpnbPm1:CjCWv6B3O1", "hash_imp": "075670EE6741C1E9AE301AE321C93986", "hash_pesha1": "87505E35188C9F78FC2C886D9574EAA2B4A01950", "hash_pe256": "7BA3963936696D7F26DA5B2AEBB25F002C883972F9A17BD34902E53C9AECB10A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Defender Advanced Threat Protection Sense IR module", "meta_original_filename": "SenseIR.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.7410.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.7410.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "runtime_modules": [ "C:\\Program Files\\Windows Defender Advanced Threat Protection\\SenseIR.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\SYSTEM32\\Cabinet.dll", "C:\\Windows\\SYSTEM32\\tdh.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\SYSTEM32\\WINHTTP.dll", "C:\\Windows\\SYSTEM32\\XmlLite.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\SYSTEM32\\urlmon.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\mintdh.dll", "C:\\Windows\\SYSTEM32\\iertutil.dll", "C:\\Windows\\SYSTEM32\\DPAPI.DLL", "C:\\Windows\\SYSTEM32\\CRYPTBASE.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\ntmarta.dll" ] }, "SenseSampleUploader.exe-732600C1D5BEDD4CB023601206AE0B13": { "file_name": "SenseSampleUploader.exe", "file_path": "C:\\Program Files\\Windows Defender Advanced Threat Protection\\SenseSampleUploader.exe", "hash_md5": "732600C1D5BEDD4CB023601206AE0B13", "hash_sha1": "D087034DB07B20DF4FBE3E457CFE4A97867F0107", "hash_sha256": "AA782115462AA5FB96B5D240D2057D1E825DB3CB8E38DD878A449209E9A7D7E8", "hash_sha384": "A2537BE9F43DB084E932CEF546DFAD0609CB481FB16E826143E382212ADBBC0DC8E38D2F6A642A8A46F7A90C5C4925BB", "hash_sha512": "B9E00AED2857DA91F590CA72C017BEAB51490C2DB81559421FA692A116A76C79B889E0D81F9F7722458A9D9FC2B337C77B9A434135EE694894E808178E11D016", "hash_ssdeep": "24576:sakQyJDa0CR0P0qA+F2bJYxieJMC9O+SbOvugA+4:sakLDa0U0P0qA+FsJYxieJMqW1", "hash_imp": "90230909037435116586A63780F751F8", "hash_pesha1": "32ECD63E9B43235A24BD60E11E950808B63B21BE", "hash_pe256": "849A83D1D3352D4D3F7D4AA160021CBCFD39B711B0DF71357ACAE3261C5504CE", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Defender Advanced Threat Protection Sample Upload module", "meta_original_filename": "SenseSampleUploader.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.7410.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.7410.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "SenseCE.exe-62834D204CA7A7BC3E5F94D428C0EFE9": { "file_name": "SenseCE.exe", "file_path": "C:\\Program Files\\Windows Defender Advanced Threat Protection\\Classification\\SenseCE.exe", "hash_md5": "62834D204CA7A7BC3E5F94D428C0EFE9", "hash_sha1": "AA7090BA4287C8C7AB6A8A3EE1E4A06A07EB9739", "hash_sha256": "24019735641D512CF8DFB175C6CF44CFDF00BD10079F61C99566FCCCED67D7E9", "hash_sha384": "75EF8563D3BAE22FD6250FF28329A7294B1358257DA5D93D6DD8D79576C1922A3F1FCF131E403F32612A17CECCAD529A", "hash_sha512": "6AB1EAEF32A47AC604E89932795BA486ACADB6B0D9916FBEC16CFEBB722D4A449DF3E15185EAF5A33FA48962856D86E9B57313AE077E756B0557E387BD59E0DB", "hash_ssdeep": "12288:djjo/fhUlnj+ySkCCXuiAK6xXHDJBIMQV2:i/pUln6ySkCCXuiA3XH8N2", "hash_imp": "C177F0580CBAD9FA33CAD7B95C7C570E", "hash_pesha1": "D7F6C22864D0CD2AF76D95D42EC1FDE652F43603", "hash_pe256": "8188BC6B38646276A51150E2597D00DFA2BA7466EDA10B7986DF22E27C9C9172", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Defender Advanced Threat Protection Sense CE module", "meta_original_filename": "SenseCE.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.7410.17763.1490 (WinBuild.160101.0800)", "meta_product_version": "10.7410.17763.1490", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a" }, "wab.exe-1763CB1756D4DF101F71DBC360C875E1": { "file_name": "wab.exe", "file_path": "C:\\Program Files\\Windows Mail\\wab.exe", "hash_md5": "1763CB1756D4DF101F71DBC360C875E1", "hash_sha1": "18C6BFD2A0A20B1C94546746FB316B0C7C2E39CD", "hash_sha256": "B0BDB7AF4B4E1C735791D5874691345D8D8F78149380E970B5F53F75C580FFEB", "hash_sha384": "858B8EF1423D219E5DBCFBBC37E30CA00AB5AC6552B71B92C416023B134CC4A85E112E343051E72E18C11CDCFF6778A7", "hash_sha512": "D0AD93FA8952A40D8708E3CB024606CC5C7B18092F67EFB1B1B1FE736D055C13A24EBFCB2AF6C7353C7459B0AD9710EBBC8E13795B8E2645843C724DF724824C", "hash_ssdeep": "12288:r4Tx5KRZ18xtSP+szdcIugOO50MMEMOkP:lmxtSP+sJ+O5FWPP", "hash_imp": "EBE0CE83B3C5863ACCA11795857482FC", "hash_pesha1": "6D179B8465A7C5F72A568E9261598A959FD889E3", "hash_pe256": "5647B1A3D21649258B0CDEE36D5B9056BAA599BF022C1D5768B26CCAC618D978", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Contacts", "meta_original_filename": "WAB.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/b0bdb7af4b4e1c735791d5874691345d8d8f78149380e970b5f53f75c580ffeb/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Program Files\\Common Files\\system\\en-US\\wab32res.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Windows Mail\\wab.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Program Files\\Common Files\\System\\wab32res.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Program Files\\Common Files\\System\\wab32.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\SYSTEM32\\CRYPTDLG.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\SYSTEM32\\MSOERT2.dll", "C:\\Windows\\SYSTEM32\\MSIMG32.dll", "C:\\Windows\\SYSTEM32\\WININET.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\SYSTEM32\\CRYPTUI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\SYSTEM32\\msftedit.dll" ] }, "wabmig.exe-8F064B7092BF681068EBEE51A7C7A9EB": { "file_name": "wabmig.exe", "file_path": "C:\\Program Files\\Windows Mail\\wabmig.exe", "hash_md5": "8F064B7092BF681068EBEE51A7C7A9EB", "hash_sha1": "C9F387D8C11F7075B7C6187E2AAE24C13674694D", "hash_sha256": "89500235E2416B8931F749E87E591B2661A3B31EB607CB654F89B5C0B84277B6", "hash_sha384": "FAD3D4BBC926B7269D083C03953704403A8DCFE53C41D735B347E342B9DE9574CF79D475CE6EB6453E8BC3446552CA20", "hash_sha512": "067F8B79027CF371FE1E1B90D2D79B153FD8EF92CF9B4FE68014E3A7AF58B562D83FAB4DC0C59FEBE08AC96FD74E2D650FD07C583D27810B6D1C70B3299BE766", "hash_ssdeep": "768:2ffRpAU9SPIS2Q4cdQMLgaRQW99VwhCnQeTF4Fs5p4+2KW0s20Uic:CJpP9G2bcdpgajRQeTF4A3WBVUF", "hash_imp": "29C9EB4BE844E75328AD3DCD8FD99253", "hash_pesha1": "212C30FE2235B600B3AD7FE2F7641F9C8A82C5A2", "hash_pe256": "E6FABD8472E2BB5F0C38531796E49E01517F22689BAA977BBCE233F8030BDB9C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) Contacts Import Tool", "meta_original_filename": "WABMIG.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/66", "filescan_vtlink": "https://www.virustotal.com/gui/file/89500235e2416b8931f749e87e591b2661a3b31eb607cb654f89b5c0b84277b6/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Program Files\\Common Files\\system\\en-US\\wab32res.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Windows Mail\\wabmig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Program Files\\Common Files\\System\\wab32res.dll", "C:\\Program Files\\Common Files\\System\\wab32.dll", "C:\\Windows\\System32\\imagehlp.dll", "C:\\Windows\\SYSTEM32\\CRYPTDLG.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\SYSTEM32\\MSOERT2.dll", "C:\\Windows\\SYSTEM32\\MSIMG32.dll", "C:\\Windows\\SYSTEM32\\WININET.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\SYSTEM32\\CRYPTUI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\msftedit.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll" ], "runtime_window_title": "Import to Windows Contacts" }, "setup_wm.exe-2598574253E2F749D1BCDF1975036E46": { "file_name": "setup_wm.exe", "file_path": "C:\\Program Files\\Windows Media Player\\setup_wm.exe", "hash_md5": "2598574253E2F749D1BCDF1975036E46", "hash_sha1": "374559BA7545BCC76823DEDD1B7BBFCF86B51D17", "hash_sha256": "7E1065BD659F3403D2655E5E5A459996F2EA742459A0CA6F866EDD3D90276802", "hash_sha384": "C289CAA2D6BEF57B51D395D00A2A05A1F1F6B7CAA33993F8368A819C6C55C4230B4E6273D0148DC47CE630F0923F8E75", "hash_sha512": "95CC97C64A51AE5819172D59F8FE4C5A7F546536C8CD212FD9C358C130D2099FE953591B5BF06995EF35D8F955CF6D9EB0CDD7E30C7DCAB498602FC3C5721FC4", "hash_ssdeep": "12288:vW9s7CMVCz3QpjrSVxsTBE/vRcvJYQqLWac0qpb0qD0xc:Be8p6J54JYJL1q2qDF", "hash_imp": "D675085E5D0206A2A6D6815816A64AFD", "hash_pesha1": "29F0FAE286FADC54B1E03C020CE9E5C649F3A518", "hash_pe256": "CD80473164ED07D5CF7349430385E99A3351D6FA8271B88CFE28A234157301E9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Media Configuration Utility", "meta_original_filename": "setup_wm.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/7e1065bd659f3403d2655e5e5a459996f2ea742459a0ca6f866edd3d90276802/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "(R-D) C:\\Program Files\\Windows Media Player\\en-US\\setup_wm.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R--) C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2\\wmsetup.log": "File", "(R-D) C:\\Windows\\System32\\en-US\\kernel32.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\Windows\\Theme966197582": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_webcache_counters_{9B6AB5B3-91BC-4097-835C-EA2DEC95E9CC}_S-1-5-21-4075667164-670084373-454571106-500": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\wininet.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\F932B6C7-3A20-46A0-B8A0-8894AA421973": "Section", "\\Sessions\\2\\BaseNamedObjects\\UrlZonesSM_Administrator": "Section", "(R-D) C:\\Windows\\System32\\en-US\\mswsock.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Windows Media Player\\setup_wm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\SYSTEM32\\ATL.DLL", "C:\\Windows\\SYSTEM32\\pdh.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\WININET.dll", "C:\\Windows\\SYSTEM32\\urlmon.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\SYSTEM32\\Secur32.dll", "C:\\Windows\\SYSTEM32\\MFPlat.DLL", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\SYSTEM32\\iertutil.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\SYSTEM32\\SSPICLI.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\RTWorkQ.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\SYSTEM32\\ondemandconnroutehelper.dll", "C:\\Windows\\SYSTEM32\\winhttp.dll", "C:\\Windows\\system32\\mswsock.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\SYSTEM32\\WINNSI.DLL", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\SYSTEM32\\DNSAPI.dll", "C:\\Windows\\System32\\fwpuclnt.dll", "C:\\Windows\\System32\\rasadhlp.dll" ], "runtime_window_title": "Windows Media Player" }, "wmlaunch.exe-0F9F6CA0723A86F110DE7B82E087C9FB": { "file_name": "wmlaunch.exe", "file_path": "C:\\Program Files\\Windows Media Player\\wmlaunch.exe", "hash_md5": "0F9F6CA0723A86F110DE7B82E087C9FB", "hash_sha1": "48F40200C36396C7DFA4FC56FBAEF0DE29268691", "hash_sha256": "E3912B625E6356F1F962CDEB2D4D6A2750CEFA90CEEAD7EE26CB5516A53EE041", "hash_sha384": "37B8C2C095A02F6C1557B93925A0EF6AFB9A7D61507C745683FB46EF4C7506669FF8B19528856D637BE09E78A43763D1", "hash_sha512": "ED702232753FDBD87913E37A560C0DE1A9178014C3C7CE15167F345DC595F818879EA5752A13FD4ED8EF78561C5985A031ACAFB566CCDC0EC38B7E07B1087650", "hash_ssdeep": "1536:o6t9eRp694ip728XJrw4XtzVilPb1aBHRGoDn6wJzpUUGFzcBOLlhK:o6twO4e22JrwsVilj1KRD6wsU0YwK", "hash_imp": "17BB20F989B0A254B1F05920AA008D6A", "hash_pesha1": "734DEB1A87CC92A067A2241BAA732A89FFBE913F", "hash_pe256": "EF09F3B0F787FA2764201A8F0384E9DA2EF92D455DC102DCA014EB4B6A3FE8D6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Launcher", "meta_original_filename": "wmlaunch.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/e3912b625e6356f1f962cdeb2d4d6a2750cefa90ceead7ee26cb5516a53ee041/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Program Files\\Windows Media Player\\en-US\\wmlaunch.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECB3C": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Windows Media Player\\wmlaunch.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\MPR.dll", "C:\\Windows\\SYSTEM32\\MFPlat.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\RTWorkQ.DLL", "C:\\Windows\\System32\\clbcatq.dll" ] }, "wmpconfig.exe-5607F957C0A4FF1B26F7D1A5F7D66814": { "file_name": "wmpconfig.exe", "file_path": "C:\\Program Files\\Windows Media Player\\wmpconfig.exe", "hash_md5": "5607F957C0A4FF1B26F7D1A5F7D66814", "hash_sha1": "8575C2D5A51E0276755D6E36FD4BEC24D29CA5F3", "hash_sha256": "3F47E9E6B84EF6B37B72FAA771A8068BFC8904CC30999A5268321233216940EC", "hash_sha384": "1A8A587EEC44D0C3EFC6C9C2352EF6B95D2875C7AA8EAF9F158A7A91395928F6641EBB397D54FE2C309B6AE921C03DF6", "hash_sha512": "27FE2D35AF48B3C904D431E25D190CAA6CD3CCBE9ADE8FF1B61C57FB411199D62E198A709C0727B5CDEFAE00C1FF54C007443BEA5899457074611D993B0CDEF1", "hash_ssdeep": "1536:iO4BfZ+hhuKL8lkQRrkcm464OBbYL53GJr95WAxJnolVz:mBfohYkQr0jeLwJr95rJo3", "hash_imp": "0FE27E5C660843E76910737378F61F5B", "hash_pesha1": "656ED1B5F4C77F3F2CAF10DF59465E145391C7C9", "hash_pe256": "D5F673ACD3AB3CA8CBF33B301830A1AD46A4A729FAFF4C3B40DCED3614A7261F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Configuration", "meta_original_filename": "wmpconfig.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/3f47e9e6b84ef6b37b72faa771a8068bfc8904cc30999a5268321233216940ec/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Windows Media Player\\wmpconfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\wmp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\SYSTEM32\\WMVCore.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\SYSTEM32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\mfperfhelper.dll", "C:\\Windows\\SYSTEM32\\WMASF.DLL", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\SYSTEM32\\wmploc.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Program Files\\Windows Media Player\\WMPMediaSharing.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\SYSTEM32\\NETAPI32.dll", "C:\\Windows\\SYSTEM32\\SAMCLI.DLL", "C:\\Windows\\SYSTEM32\\SAMLIB.dll", "C:\\Windows\\System32\\FirewallAPI.dll", "C:\\Windows\\System32\\DNSAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\NSI.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\System32\\fwbase.dll", "C:\\Windows\\System32\\FWPolicyIOMgr.dll", "C:\\Program Files\\Windows Media Player\\wmpnssci.dll" ] }, "wmplayer.exe-113719B2BC20764BE5D1F2E1679E149E": { "file_name": "wmplayer.exe", "file_path": "C:\\Program Files\\Windows Media Player\\wmplayer.exe", "hash_md5": "113719B2BC20764BE5D1F2E1679E149E", "hash_sha1": "E4CA0DCEA9A75B78CE11DD1CB05BDB32508ED278", "hash_sha256": "B3958D6FAD71FA64227F2B41F57DBF9BAB434746BA0D249E226408199C218F48", "hash_sha384": "C18D3630A024D6CD0892AF8CB1AD63D9A44385C09766A30DF3C9D9F9B78C7981B65F683CAA27841897AE5207D8AAB2E8", "hash_sha512": "C7FA2906D3EF4A80F130D40D4C9F257F789126CCACB15FB09BF02C78856336E53A136590E6508590F327B4B90E2DFA02563E6EA582FA47B90127992900105B8B", "hash_ssdeep": "3072:DAziiNohYkQr0jeLwJr95rJolNAzyP+msVK0Zh:DPYQqLwhHrWsOP+5VT", "hash_imp": "33E3BA3C576D003915CF7E8CEC099D86", "hash_pesha1": "80801622A250316607C59D889B87C570BDCC3800", "hash_pe256": "A9D9EF640DD10DE6C842257FA589632C2757B0C9FA55F14D2FB339A4176FB229", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player", "meta_original_filename": "wmplayer.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/b3958d6fad71fa64227f2b41f57dbf9bab434746ba0d249e226408199c218f48/detection/", "runtime_modules": [ "C:\\Program Files\\Windows Media Player\\wmplayer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "wmpnetwk.exe-DA094771C21F8FD92C4A68312A087A4D": { "file_name": "wmpnetwk.exe", "file_path": "C:\\Program Files\\Windows Media Player\\wmpnetwk.exe", "hash_md5": "DA094771C21F8FD92C4A68312A087A4D", "hash_sha1": "90E41A9A15318D64135CEED624D8345FB04929E7", "hash_sha256": "A9C8DC72B50C0DEAF09DB1EAE874D892082CDAA42A51B99A09E4F93C43D3D78E", "hash_sha384": "8771C36ACB283ADAEFFD55E5F0DF45CFF3BCC16159EA1C1FBE9AC9493977CAED567963C674B8AD58EB908B242F0364C9", "hash_sha512": "F73EE9C50D3E06AA40E8A0C5140A4D9D773D2902842BB02FE3DBC6DFD57FA346B0FB0FAA4A2FAEB14BB9660C51C53F8DFBE82D4A05C8E8BF74ACB6F17A6064FB", "hash_ssdeep": "24576:hvsnwi/wc5wv5WD9JrhUgRGjrn7VyhEKI:anwiIowv+rK3nByhEK", "hash_imp": "CE33293E11214B8162575CC0E318524F", "hash_pesha1": "65C7773AC102FF1D8BEC152C4812AA9AEB62B5D6", "hash_pe256": "34F457FBCDABD66E96A7851A19FC89556391BD8E46A8CF2BDBF4178943C4D022", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Network Sharing Service", "meta_original_filename": "WMPNetwk.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a9c8dc72b50c0deaf09db1eae874d892082cdaa42a51b99a09e4f93c43d3d78e/detection/" }, "wmpnscfg.exe-F34C107A55A199694CDBCEE26FC937B3": { "file_name": "wmpnscfg.exe", "file_path": "C:\\Program Files\\Windows Media Player\\wmpnscfg.exe", "hash_md5": "F34C107A55A199694CDBCEE26FC937B3", "hash_sha1": "249404593631EFA5AB1E843F91383CB25E1431BC", "hash_sha256": "E8E9E1C1384552E8A3E6CF6343118727221F115F348F72E6FDCA6FFC82A10620", "hash_sha384": "78D6FD9DF044760517D5300C8D65E949453D3E57551037007F28795A1B5AEFA8AF125FFDA482CD2556E908F56D950267", "hash_sha512": "4CA26226BB831044736A3A3C572BECBD5BC419C82729DA0FB6AE4469A5A8D52071126E4DF5072101766122B337D9D00DCED72FFA206AC39DDCC99F49C4F04C3C", "hash_ssdeep": "1536:e5P6tTc+Qox49M1GhKjMV4e3rsp5YYWUtCoOeTgqO5i4hTChhhh5:eV6tw+lBjbe3ooYWECoOeTgqO5i4hTCZ", "hash_imp": "10807BE6C556873C09952D20966D7581", "hash_pesha1": "ACB5CE91F4AFBE0ECD49100A9C9F872B06BA6EE0", "hash_pe256": "AFBEBF6FB2D1E5D43FB39FA5325B8275F047F305C996BCCC89F843C0AAC900FA", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Network Sharing Service Configuration Application", "meta_original_filename": "WMPNSCFG.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/e8e9e1c1384552e8a3e6cf6343118727221f115f348f72e6fdca6ffc82a10620/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Program Files\\Windows Media Player\\en-US\\wmpnscfg.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC12B8": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Windows Media Player\\wmpnscfg.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Program Files\\Windows Media Player\\wmpnssci.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll" ] }, "wmprph.exe-3246BF8676064ECD4E5033775202DC41": { "file_name": "wmprph.exe", "file_path": "C:\\Program Files\\Windows Media Player\\wmprph.exe", "hash_md5": "3246BF8676064ECD4E5033775202DC41", "hash_sha1": "16A1018FCB158A01DBFF47768295DE1310FBBCF2", "hash_sha256": "89FDDD93453D186FBD474A6ECF28CC4963F53650C7B45CCB239C64C69A87974B", "hash_sha384": "22D6AD2BFD0DE1FC541CEE998DB713B6C6D1A7BECD45120041AE54052ECF2756547CAEE52B320DBDD1FD099925F34F06", "hash_sha512": "AB8115FEA832FED36DFBB9F71A687AC60F1C5FE335D7833D72BAA2E3DE196694EF95FDDFB9637006269C778EFB5C6D7993AA4F9BE9A07BB864775BA5B47A317A", "hash_ssdeep": "1536:MR8gDCN6azM1vLA7RBCf9KKPsLBZuf9m1CGaQIeFdd9jf8TO8sRWjKS:W8JCvc7Rkf9KKPsFwg2QJzYOWG", "hash_imp": "842B9341196BC74EF2D7F5D061D8D10E", "hash_pesha1": "D1AC680A1061AF2FF6D87ECE2F44785C1C913C63", "hash_pe256": "993389523EA60C6A5C067DC77BD29CC38218C3C8FB70FBD5DEECB03A0F11D6F6", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Rich Preview Handler", "meta_original_filename": "wmprph.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1282 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1282", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/89fddd93453d186fbd474a6ecf28cc4963f53650c7b45ccb239c64c69a87974b/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSECA80": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Windows Media Player\\wmprph.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll" ] }, "wmpshare.exe-5E1E371446C859EB714A2C53BF9FAEC6": { "file_name": "wmpshare.exe", "file_path": "C:\\Program Files\\Windows Media Player\\wmpshare.exe", "hash_md5": "5E1E371446C859EB714A2C53BF9FAEC6", "hash_sha1": "8C86D5364D3B062EC7AD090A9BE688699162BB94", "hash_sha256": "84D445A0F798532435FE51177A43F541C0C928E194166083F85377B590969F30", "hash_sha384": "D5F1064812EFE1A95CB3185EF744C92CCAC3BC67E3C32D3D82032656FE5DF0957742E4C411DDB1BD1C603AFBB6ACCB7B", "hash_sha512": "8F705B5678B66F4FF70CACC4EB465919EED58435BE437200FDB7C1C8FB453AB90162936165473FA5AC9922DEE78CAF7AC1A0BF549746E6752C5D6E3DBA8F25DE", "hash_ssdeep": "1536:UGuanZ+hhuKL8lkQRrkcm464OBbYL53GJr95WAxJnolV3:nhohYkQr0jeLwJr95rJoz", "hash_imp": "131C7FE83E13DA0EA849431F5BEA3C8F", "hash_pesha1": "5291BE676C9A5429B56BAFE46715C4ECD476A62B", "hash_pe256": "76B44313313CC418CAEAC56DC097F39E1E09EFC739815A8088BAA980869EA6F1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Folder Sharing Executable", "meta_original_filename": "wmpshare.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/72", "filescan_vtlink": "https://www.virustotal.com/gui/file/84d445a0f798532435fe51177a43f541c0c928e194166083f85377b590969f30/detection/", "runtime_modules": [ "C:\\Program Files\\Windows Media Player\\wmpshare.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\SYSTEM32\\wmp.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\SYSTEM32\\WMVCore.DLL", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\SYSTEM32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\mfperfhelper.dll", "C:\\Windows\\SYSTEM32\\WMASF.DLL", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\SYSTEM32\\wmploc.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\SYSTEM32\\AUTHZ.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\SYSTEM32\\iertutil.dll", "C:\\Windows\\SYSTEM32\\XmlLite.dll", "C:\\Windows\\SYSTEM32\\LINKINFO.dll" ] }, "wordpad.exe-8C90572B1F8F341D72E5417DE7F4418F": { "file_name": "wordpad.exe", "file_path": "C:\\Program Files\\windows nt\\accessories\\wordpad.exe", "hash_md5": "8C90572B1F8F341D72E5417DE7F4418F", "hash_sha1": "00CC94610D30D7F022F63BF9E7D823B20AFA5F21", "hash_sha256": "657E99BDA5D2487F09F9302F661067B143F096C07C2AB64DD2ED24A2A51C8549", "hash_sha384": "7E1107505B276B4822D5A7D00691E98BD6D9FF95ED6600D463B29A194D6B57AEA483B249ABCB2680A8F0029498806988", "hash_sha512": "162495A2A40E0DD98F356DEBF276269153F2273611E150A3D05633E674CCD849F933D83B4A9CC0F5D458B1E5A21EEE726567EBF83EF5E1F00FC351BCFC7E72A5", "hash_ssdeep": "24576:5+CFswwI3HwOCzW295D8a5U6TOqUN2FxvNEtXcPCl9AuDF5zUPGLG5SvAMZAMg9:5+KL3Q8iU6TO2xvW9cPy9AuDzY", "hash_imp": "59D1F979AE3BD1A315954FF22001C99E", "hash_pesha1": "D182FC807EC8EB5BFBE15606D62DE89F8592B5A6", "hash_pe256": "D756D1FEB256659339897166F4D387643AF81D6506F2D729149FC50BE8D7B0E5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Wordpad Application", "meta_original_filename": "WORDPAD.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/657e99bda5d2487f09f9302f661067b143f096c07c2ab64dd2ed24a2a51c8549/detection/", "runtime_handles": { "(R-D) C:\\Program Files\\windows nt\\accessories\\en-US\\wordpad.exe.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\RPC Control\\DSECEB4": "Section", "\\Sessions\\2\\BaseNamedObjects\\eb4HWNDInterface:80750": "Section", "(R-D) C:\\Windows\\System32\\en-US\\UIRibbon.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\fms.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Users\\user\\Documents": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\windows nt\\accessories\\wordpad.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\SYSTEM32\\apphelp.dll", "C:\\Windows\\SYSTEM32\\AcGenral.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\SYSTEM32\\MPR.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\MFC42u.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\SYSTEM32\\WINMM.dll", "C:\\Windows\\SYSTEM32\\urlmon.dll", "C:\\Windows\\SYSTEM32\\XmlLite.dll", "C:\\Windows\\SYSTEM32\\WINMMBASE.dll", "C:\\Windows\\SYSTEM32\\iertutil.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.DLL", "C:\\Windows\\SYSTEM32\\ninput.dll", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\msxml3.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\MSFTEDIT.DLL", "C:\\Windows\\system32\\UIRibbon.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\Windows.Globalization.dll", "C:\\Windows\\System32\\Bcp47Langs.dll", "C:\\Windows\\System32\\bcp47mrm.dll", "C:\\Windows\\SYSTEM32\\globinputhost.dll", "C:\\Windows\\system32\\dataexchange.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\system32\\dcomp.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\system32\\twinapi.appcore.dll", "C:\\Windows\\system32\\RMCLIENT.dll", "C:\\Windows\\System32\\oleacc.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\system32\\windowscodecs.dll", "C:\\Windows\\System32\\Windows.UI.dll", "C:\\Windows\\System32\\TextInputFramework.dll", "C:\\Windows\\System32\\InputHost.dll", "C:\\Windows\\System32\\CoreUIComponents.dll", "C:\\Windows\\System32\\CoreMessaging.dll", "C:\\Windows\\System32\\d2d1.dll", "C:\\Windows\\SYSTEM32\\wintypes.dll", "C:\\Windows\\SYSTEM32\\ntmarta.dll", "C:\\Windows\\SYSTEM32\\WINSPOOL.DRV", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\SYSTEM32\\edputil.dll", "C:\\Windows\\System32\\DriverStore\\FileRepository\\prnms003.inf_amd64_513b04a5b0f1d094\\Amd64\\PrintConfig.dll", "C:\\Windows\\SYSTEM32\\prntvpt.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\system32\\fms.dll" ], "runtime_window_title": "Document - WordPad" }, "ImagingDevices.exe-D485B8D5ED55355F61365CB4F8C26C02": { "file_name": "ImagingDevices.exe", "file_path": "C:\\Program Files\\Windows Photo Viewer\\ImagingDevices.exe", "hash_md5": "D485B8D5ED55355F61365CB4F8C26C02", "hash_sha1": "A5E6696D437B4BEBD3E83BE6631851E9A8B3F770", "hash_sha256": "ACA461FD070D009740519FEFF8289FD1BE2BE3CC09011B28503FD535114ADB3C", "hash_sha384": "B960240652E3E733A84EFA04FB3294056D6FE3F5DC10AA622F52D0B713A7E2F84A0086F515AE742A17964CE0FD751837", "hash_sha512": "A7DF90E1B1FE50769A0C1E8FD766F61CC03A9615BD0837F5AD1721D27BC77811EEA121DF7FDDACCB10A94E97E9790E911AD6C0357DBAC91963134931D6B37829", "hash_ssdeep": "1536:8/sMCxtfTRVp/G/3W9hKBJjAqQCe1nwdsmZY5TThMKpqI1:8snRVJogh4ydDeuwY9ThMW1", "hash_imp": "B4335CA81995D66D816AD33073E6BAB0", "hash_pesha1": "B6102DAEA4BF615EE152B23151E38BBBCBFD2DAE", "hash_pe256": "7DD78D9594343C324A0D18AC4EFCFF4253C14574BC10BFE42E2C7659084201B1", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Imaging Devices Control Panel", "meta_original_filename": "ImagingDevices.cpl.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/aca461fd070d009740519feff8289fd1be2be3cc09011b28503fd535114adb3c/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Program Files\\Windows Photo Viewer\\en-US\\ImagingDevices.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Program Files\\Windows Photo Viewer\\en-US\\PhotoAcq.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\RPC Control\\DSEC138C": "Section", "(RW-) C:\\Windows\\debug\\WIA\\wiatrace.log": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Windows Photo Viewer\\ImagingDevices.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\SYSTEM32\\STI.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Program Files\\Windows Photo Viewer\\PhotoAcq.dll", "C:\\Windows\\System32\\SETUPAPI.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_0f591eb5ade09f35\\gdiplus.dll", "C:\\Windows\\SYSTEM32\\OLEACC.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\SYSTEM32\\WINMM.dll", "C:\\Program Files\\Windows Photo Viewer\\PhotoBase.dll", "C:\\Windows\\SYSTEM32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\SYSTEM32\\WINMMBASE.dll", "C:\\Windows\\SYSTEM32\\atlthunk.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\System32\\PortableDeviceApi.dll", "C:\\Windows\\System32\\DEVOBJ.dll", "C:\\Windows\\System32\\PortableDeviceTypes.dll", "C:\\Windows\\System32\\WINTRUST.dll", "C:\\Windows\\SYSTEM32\\wiatrace.dll", "C:\\Windows\\SYSTEM32\\WindowsCodecs.dll" ], "runtime_window_title": "Scanners and Cameras" }, "BrowserCore.exe-AF7748863FC9CEF22848CCD4DD383755": { "file_name": "BrowserCore.exe", "file_path": "C:\\Program Files\\Windows Security\\BrowserCore\\BrowserCore.exe", "hash_md5": "AF7748863FC9CEF22848CCD4DD383755", "hash_sha1": "7B80E6748C6E0A3EAC3B43EA0BA3B2D86B84B28E", "hash_sha256": "210513BC15A0DC19A74614C294B7B056D1BAF82C5A25B60D374AEE9CF59CAB07", "hash_sha384": "72C8635722BAC32A68C42D7265F9C0CAABA302CD31F0A0E4321D1C494BABAFB56D8EF15F22DD78648587F71A74F17CBB", "hash_sha512": "8399D2E2960658BC00E83CE5F34750B0129D0CB377BF4519E6AAA4EBCA3C06A8BF9B42346EBD334E980D6BB6F3C02F3A09A4399DF0F5AE6EC8AE49A813B31067", "hash_ssdeep": "1536:mNmPmquDsMP8BmqWGa3WhFhgG3PX4a3JwwYO3LuPyxmeFxzpPEn:mNm29Im6amhFhLQa3JwwYObuqx7xd", "hash_imp": "E1476BDCA1440DCD97BAEEB42AB355E0", "hash_pesha1": "73E5259DF1B00EF57BD0AA2D2E491B4264D449D5", "hash_pe256": "B1C25AB4608B017A8023ACAD1FCCAA669DF114DB782EC73ECDA68901C37ECCED", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "BrowserCore", "meta_original_filename": "BrowserCore.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/210513bc15a0dc19a74614c294b7b056d1baf82c5a25b60d374aee9cf59cab07/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Program Files\\Windows Security\\BrowserCore\\en-US\\BrowserCore.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files\\Windows Security\\BrowserCore\\BrowserCore.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\user32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll" ] }, "git-credential-AWSS4.exe-F9B8705F1BA1D9074C8C8B5279F5A861": { "file_name": "git-credential-AWSS4.exe", "file_path": "C:\\Program Files (x86)\\AWS Tools\\CodeCommit\\git-credential-AWSS4.exe", "hash_md5": "F9B8705F1BA1D9074C8C8B5279F5A861", "hash_sha1": "3ABC040E48CA6462EF2E19D39E9BD9AAF5A3F7F4", "hash_sha256": "35A66989B4F43D641B1D593DEF816B728F5B373EF787E967D7CA5A8CDBCCE317", "hash_sha384": "B16F3C2FA388E1461CF8103E9382E57A15583EA57679223BD6F144888E4347A64AFB1604061F821825A93C33E6777358", "hash_sha512": "FDA8A3C759FB7FA5695AF246C7864BA752EBA6C1334DB47279BDD7F54D34BA0F90FA05EE3C647A15035FDC6D621813A386B3D9880A7E47D150DF1B5A1D6AB207", "hash_ssdeep": "1536:tiSjuZXB4zBHNZeNmY9ijYkMfSMg9rWFvsxoiGZ/GbZ1O6:njuj4leNz8YkMSM+rWFvyFGBGbZ1O6", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "AA853BA1701995D43EC9068F44C77984589B9DF2", "hash_pe256": "62A43B2D76B0D003B773111CEB6E5360B2E7EE01A64598DEF575AF61E432C9E5", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\AWS Tools\\CodeCommit\\git-credential-AWSS4.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "git-credential-AWS4", "meta_original_filename": "git-credential-AWSS4.exe", "meta_product_name": "git-credential-AWS4", "meta_comments": "Git Credential Helper which generates AWS Signature Version 4 signed requests for use with AWS CodeCommit.", "meta_company_name": "Amazon.com, Inc", "meta_file_version": "1.0.2.0", "meta_product_version": "1.0.2.0", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright 2015-2016 Amazon.com, Inc. or its affiliates. All Rights Reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/35a66989b4f43d641b1d593def816b728f5b373ef787e967d7ca5a8cdbcce317/detection/", "children": "conhost.exe", "error": "Git AWSSV4 signature generation for Windows\r\n\r\nUsage: \r\n git-credential-AWSSV4.exe [-s] [-i ] [-t ] [-d ]\r\n git-credential-AWSSV4.exe -h\r\n\r\nOptions:\r\n -s Install silently (with no prompts or dialogs)\r\n -i Specifies the path to 'git.exe'\r\n -t Specifies the path in which to install this helper\r\n -p Specifies which profile to retreive AWS credentials from\r\n -h or -? Display this help message\r\n", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_3668": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\AWS Tools\\CodeCommit\\git-credential-AWSS4.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\SYSTEM32\\VERSION.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\SYSTEM32\\MSVCR120_CLR0400.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\5543cca0df435801e2303ff46a482ed5\\mscorlib.ni.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\6885802f40fd803e49150d8a2b43a09b\\System.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Core\\f29b1120627489754c4b8dd317bbe950\\System.Core.ni.dll" ] }, "awsdeploy.exe-AF8478E5A0A5814F8136FB0BADFFD9B2": { "file_name": "awsdeploy.exe", "file_path": "C:\\Program Files (x86)\\AWS Tools\\Deployment Tool\\awsdeploy.exe", "hash_md5": "AF8478E5A0A5814F8136FB0BADFFD9B2", "hash_sha1": "86486FF6876011530D2E988EA6EA914D20B0C891", "hash_sha256": "BB399F82B0EB8F9C337C8817568781762F6D19BAC0F63E83E8C0D48777BDAC02", "hash_sha384": "A7689D131047A390A94FE186A1320F0E78F411F25C7C02FA01416363F531418E83E696D94E17BB330FDCB49600EE4E1C", "hash_sha512": "039FEC310FF3F8A6063085DFC5261D1151C0338890E900EDF0F68E1870E4D30707E2275B4B841B624216013070BA01A36DB15BAE8A3D84060176A054AF7DA307", "hash_ssdeep": "192:LWQmRV59kKvBH+q2BfUZXWVE0DMsdTR4UAgAKBInl7Z:LWQmRV59fBeqf9WVVDMsd2zgAK+l", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "85A870392D8CF355054500A276CE3AFC5BC75C3D", "hash_pe256": "E5E10225A4E1C8AD4965F62B9C1B1FCD14A7E08C2120EFD9BF7CCDD4F2250084", "signature_status": 2, "signature_status_message": "The file C:\\Program Files (x86)\\AWS Tools\\Deployment Tool\\awsdeploy.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170", "signature_serial": null, "signature_thumbprint": null, "signature_issuer": null, "signature_subject": null, "meta_description": "AWSDeploymentTool", "meta_original_filename": "awsdeploy.exe", "meta_product_name": "AWS Toolkit for Visual Studio", "meta_company_name": "Amazon.com, Inc", "meta_file_version": "1.14.5.0", "meta_product_version": "1.14.5.0", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright 2011-2018 Amazon.com, Inc. or its affiliates. All Rights Reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/bb399f82b0eb8f9c337c8817568781762f6d19bac0f63e83e8c0d48777bdac02/detection/", "children": "conhost.exe", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\Cor_Private_IPCBlock_v4_3240": "Section", "\\...\\Cor_SxSPublic_IPCBlock": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "error": "Failed to parse deployment configuration file: No credential specified to do the deployment. Either AWSAccessKey and AWSSecretKey or AWSProfileName must be specified\r\n", "output": "[Warning]: Malformed configuration entry at line 1: ", "runtime_modules": [ "C:\\Program Files (x86)\\AWS Tools\\Deployment Tool\\awsdeploy.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "pipanel.exe-9EEF0FB0CBD2A760C6EACD29E7584E4D": { "file_name": "pipanel.exe", "file_path": "C:\\Program Files (x86)\\Common Files\\microsoft shared\\Ink\\pipanel.exe", "hash_md5": "9EEF0FB0CBD2A760C6EACD29E7584E4D", "hash_sha1": "1AC2482058C65E6966E6BA46551B37CD4495D565", "hash_sha256": "8DA6E35E2095F405DEBED1F4128717D035AC0E4888F49A9E6B5945D4C8BC2157", "hash_sha384": "B071318EA4A3937155A89E72A56F366DA1712D8971E634F5A7D4560380DC5D7F1A0025ADAE5B62F2BC46BD09FAF45FC9", "hash_sha512": "20612C3D7BCBA274A802F464F0D06F0A8042062D5B171BC7419DB45235DA2B0CE8217A98CB89E82C605C89F1C5C68C9681EB82B89AAE8D12E67A42C47AB3CE83", "hash_ssdeep": "96:bJgLvv1zzn9p9Ip2UcQVMDGjwi9HLrMOtmDEWeCfetnWwqWeL:bm3RzX817XMOtmIWeEetnW5", "hash_imp": "BCAA5893FCD6DD599299BC637B721E58", "hash_pesha1": "1A52ED5DD523A45F14C9EB6E717FCE6EB19C162A", "hash_pe256": "FD879A6FB35C747E76C3ED7112994F97FE6168574CEF1E3AC7A24322374EA05F", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Tablet PC Component", "meta_original_filename": "Dummy.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/8da6e35e2095f405debed1f4128717d035ac0e4888f49a9e6b5945d4c8bc2157/detection/" }, "TabTip32.exe-725AAEFD55B6DEA9663EEAA04E881C0E": { "file_name": "TabTip32.exe", "file_path": "C:\\Program Files (x86)\\Common Files\\microsoft shared\\Ink\\TabTip32.exe", "hash_md5": "725AAEFD55B6DEA9663EEAA04E881C0E", "hash_sha1": "D428BB759449A0E775C439B2739A7DEF7DE35381", "hash_sha256": "C9806C79056652EACE305C47C6BDEF9DEC73A1CB9A5CE149EB0AE4101F038057", "hash_sha384": "1A140FF8A8210C5E23F973CBA64FB13D3290EBCF8E111F4959768D782D517B55DCEAA27C7CC44A4CB6B18BA71F68661E", "hash_sha512": "72A1287CF4E7911E5EA24A25334FF1B40FBE3398D10A9C572B7D36C640B62D9EEFBC64CF80B95553F3C74549E0EC13154162B9A521336701395AEE05AC0E3C66", "hash_ssdeep": "384:dy7wospvZ4DSWN2Wr03qmXjDBRJ7vnHldl99u69w:HRZ4D5WXj1P7vbw", "hash_imp": "8D2575DF512BC4203633443E91FD24EF", "hash_pesha1": "6BD06E62DA177AC83F6326FEAA336DD3593CE5E2", "hash_pe256": "9C9CD79165691F00D30718B7B232A32650325AF30397EF31EB8C9206EFF2F3BB", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Touch Keyboard and Handwriting Panel Helper", "meta_original_filename": "TabTip32.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/c9806c79056652eace305c47c6bdef9dec73a1cb9a5ce149eb0ae4101f038057/detection/" }, "ExtExport.exe-72AC703193E2AD95FF112D3BF08DD4B2": { "file_name": "ExtExport.exe", "file_path": "C:\\Program Files (x86)\\Internet Explorer\\ExtExport.exe", "hash_md5": "72AC703193E2AD95FF112D3BF08DD4B2", "hash_sha1": "2244F6FE9D68A35ABF3B8A66EA85BAD3D3F787C6", "hash_sha256": "25063B72FEA5A86FE12073695F8A97E6BDC72A93417EFCC0D4156EF39BC6B46B", "hash_sha384": "3F5C94571B267030AA817C962C35CAC7106A532FB5C954CC091A69E8E481A10DF2ED81CC31A27811F0E9643AEE45DFD5", "hash_sha512": "CE50512E42BA07601AA73ECC9B66D2F9B94026E1D08A9FB14043A74104CFB2C5A792C648F2EF026AEA94ECCBB3CD19A4997E41C2684FFED5B1A0FA458DB24EF1", "hash_ssdeep": "768:ZAMBmP3+XxLKZ/XMsQt1TZPIR3fDUga9MWf7td7af75Ku7plyR8u4oCGkCs1iFg:HsP3+XxLKZ/XMsQt1TZPIR3fDUqWf5mT", "hash_imp": "EE9E4418B777C45B6741B9CE6DFC85B9", "hash_pesha1": "B892231AF7335001C9C7F70A6A4657B3D9B5BBCD", "hash_pe256": "BBDF39450FD9840CCC74F61E9B48B5F3DE522A2023AE0AEAA4B17BCCF97D39F4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Internet Explorer ImpExp FF exporter", "meta_original_filename": "extexport.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/25063b72fea5a86fe12073695f8a97e6bdc72a93417efcc0d4156ef39bc6b46b/detection/", "runtime_modules": [ "C:\\Program Files (x86)\\Internet Explorer\\ExtExport.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ieinstal.exe-22B06EAB26C89C0AD59071593442716E": { "file_name": "ieinstal.exe", "file_path": "C:\\Program Files (x86)\\Internet Explorer\\ieinstal.exe", "hash_md5": "22B06EAB26C89C0AD59071593442716E", "hash_sha1": "1DFE3E2B0BDAC0E4B8C62652D1749E0190058268", "hash_sha256": "AD5DCBE9F92C6DA4CA09226C93B570F918014D7FB596A7AE402459AB32EA3658", "hash_sha384": "5876754005614D54FF17C94B490074CCB4265732221341383E5F7213D6F149689930BE909C744199E48704796D22D4A3", "hash_sha512": "B7525FC23EF95F7F509F2C0558747497D7542E7385B01641AD2D24D41183EA567880848D9B9FB6ED13AD2F027ED3751203B23A64B9DB63E6FD7C49930A0C3CB2", "hash_ssdeep": "6144:WkzBUBwEw1rOt9pdYamXnrdbMKw7w1rOt9pdYamXnrdbMKww:WkNdn5OLpdNIrd4Ds5OLpdNIrd4Dw", "hash_imp": "9F36C0AED915A5B7F4A6DB6667FCB4C6", "hash_pesha1": "AE23A867503593DE30E163B0A2F7A3ECCBA52A1D", "hash_pe256": "D3E108BA141FB42BB59C6AEC4AE14B4CB924B1329CA8498088B6EBFABC2280B5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Internet Explorer Add-on Installer", "meta_original_filename": "ieinstal.exe.mui", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/ad5dcbe9f92c6da4ca09226c93b570f918014d7fb596a7ae402459ab32ea3658/detection/", "runtime_modules": [ "C:\\Program Files (x86)\\Internet Explorer\\ieinstal.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "ielowutil.exe-CE5D25E64B5CB96681659196EB6147E9": { "file_name": "ielowutil.exe", "file_path": "C:\\Program Files (x86)\\Internet Explorer\\ielowutil.exe", "hash_md5": "CE5D25E64B5CB96681659196EB6147E9", "hash_sha1": "073D140171D578D847EB6C518756183BE053F7FB", "hash_sha256": "D3FA76E0B2EDC355B2AE1F6F3BBF95AE3A314644F7CFFE9732A0B692341627B6", "hash_sha384": "E9C39DB10E5CA43259A3E36545AE9DCA7CB69174F111EF1D6425A6A274A994EA20C41E7B52D90FDFAEF981BD937E6DA0", "hash_sha512": "9E51AD02E640BE971B1E4B5323FC5D9B9844C807AAFE659CFAE329E5B59BD7FB2535F3980DD6F1658B2D8A310CAD9D7CA0D493ECDB53287D5D55D49AD40BA6BC", "hash_ssdeep": "3072:MJX2/stD7trOt9pfslMYO9mXn9H0LeinObM6gZy5ChoTi3:MA/w1rOt9pdYamXnrdbMKw", "hash_imp": "3CB0B3DC860A198C4B7291725FF7B90F", "hash_pesha1": "3C51B0D5D4AD844A4A9031D3355E63173F52B051", "hash_pe256": "77E0C4672F9B7AF2691BEC695FCFFF3EE467F6746F42B9704F06AA6933DAE638", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Internet Low-Mic Utility Tool", "meta_original_filename": "ielowutil.exe", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/d3fa76e0b2edc355b2ae1f6f3bbf95ae3a314644f7cffe9732a0b692341627b6/detection/", "runtime_modules": [ "C:\\Program Files (x86)\\Internet Explorer\\ielowutil.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "iexplore.exe-A2CD9CF67DEB267D7A2813F00D47245C": { "file_name": "iexplore.exe", "file_path": "C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe", "hash_md5": "A2CD9CF67DEB267D7A2813F00D47245C", "hash_sha1": "BB16D6876EB89343D31BEEA8DCFF56AD9BAD6DD5", "hash_sha256": "3BE1ABC6DAF27760A91413B77C4BA0A73EF92115FDA35FF6947B8AD937F54DF9", "hash_sha384": "2BC1FA5A0DB664923B6D8C7CF362478809AF169593638835DA6B1BE23C6C76232D53A9D08D2ED0E106E8A17AEBBE12E3", "hash_sha512": "FF49954A579274FDA687DFADDCE7A7522B62B30F88A2E0AD6A16AEAC456AD86B30FE69D6F8EA667B08DF237503867645CF3A722EB8BE168BB52F0D8EFDA21AFF", "hash_ssdeep": "24576:S3fqlGLbMMHMMMvMMZMMMKzb6XmMMMiMMMz8JMMHMMM6MMZMMMeXNMMzMMMUMMVG:S7MMHMMMvMMZMMMlmMMMiMMMYJMMHMMs", "hash_imp": "2C2E1D73CA9132FDC123B09EF74BD684", "hash_pesha1": "B89AA13656E8E297C93A12D13A9FE3D648B23193", "hash_pe256": "4CD57C1672446F40F9BEBE58293A738EAA5B8434E1381B1AB4744BF5F5C01B66", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Internet Explorer", "meta_original_filename": "IEXPLORE.EXE.MUI", "meta_product_name": "Internet Explorer", "meta_company_name": "Microsoft Corporation", "meta_file_version": "11.00.17763.1 (WinBuild.160101.0800)", "meta_product_version": "11.00.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/3be1abc6daf27760a91413b77c4ba0a73ef92115fda35ff6947b8ad937f54df9/detection/", "children": "iexplore.exe", "runtime_modules": [ "C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wab.exe-58CDC40AE57D2F2C6FC787BF66BAA1A6": { "file_name": "wab.exe", "file_path": "C:\\Program Files (x86)\\Windows Mail\\wab.exe", "hash_md5": "58CDC40AE57D2F2C6FC787BF66BAA1A6", "hash_sha1": "18DDC9D22EEFC841D98BCF261B0065285399E8DC", "hash_sha256": "079ED81718D31EF8303DF2350C72E452E6CE40CEF8E048EF46350C4DFD6A78D0", "hash_sha384": "A6AFDC81F0380F02CC5E0C70E490AE46AB3E5C38DA7965D78926E2F9069DCCAF786F4DDA96ECC90D2DD3B47976BED863", "hash_sha512": "3EC0530B8DFA46000879A2115450075F3AFBEB672D9F90172D98CF82418673B7FC5BD0682D439B17FD8DD820C24C783A0DEC7BD7DBA273EA37F07716AD9222B9", "hash_ssdeep": "12288:2Tx5KRZ18xtSP+szdcIugOO50MMEMOkP:TmxtSP+sJ+O5FWPP", "hash_imp": "0EF04699A47ECF41DF8E2B3DD1491D68", "hash_pesha1": "83E9D70BAE5B510A9B573A2C5F2B0F1E78E3D901", "hash_pe256": "11167B546AE827A288820902BE2A9A2E597D4CBC01069786AA28436E8C003D41", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Contacts", "meta_original_filename": "WAB.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/079ed81718d31ef8303df2350c72e452e6ce40cef8e048ef46350c4dfd6a78d0/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Program Files (x86)\\Common Files\\system\\en-US\\wab32res.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Mail\\wab.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wabmig.exe-DD1EDC212429385480C42542B58E024B": { "file_name": "wabmig.exe", "file_path": "C:\\Program Files (x86)\\Windows Mail\\wabmig.exe", "hash_md5": "DD1EDC212429385480C42542B58E024B", "hash_sha1": "F5F5AA5FB59C1C4C5A1A82AF0FD283C8C2EE41D3", "hash_sha256": "F6B817340614D938CCEC6C301AEF530E5D5C5F8742FCD747C6FE815A9ECDAFA6", "hash_sha384": "4C079F8CC820B1CA65CBE60990C026B061DA897EEE7F5737DF093DBDDB178D386189759E75093CD22B695E5ACF117217", "hash_sha512": "84B45DC743B1757565A91290E0EBEC9832381452001D1F47735625A2266A975A795367BD49FBD3DCD6B131110CB88327B39EA9F46AA248FC94AEA67FADE8DC6F", "hash_ssdeep": "768:fPLZso+cPd99VwhCnQeTF4Fs5p4+2KW0s20Uicn:fUqRQeTF4A3WBVUF", "hash_imp": "1CE988B2172FC734A17510C07D0EA9DD", "hash_pesha1": "3A1C6E890FA98EA07E8DB350D7CEB1CF8E7F8164", "hash_pe256": "DCBBDB7FD5B85B151CACE5986379494D36EF8BD42475EEB79C2FBC30E4F2B807", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft (R) Contacts Import Tool", "meta_original_filename": "WABMIG.EXE", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/f6b817340614d938ccec6c301aef530e5d5c5f8742fcd747c6fe815a9ecdafa6/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Program Files (x86)\\Common Files\\system\\en-US\\wab32res.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Mail\\wabmig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Import to Windows Contacts" }, "setup_wm.exe-D4A68AF9ABEECB326FC06AA17357C105": { "file_name": "setup_wm.exe", "file_path": "C:\\Program Files (x86)\\Windows Media Player\\setup_wm.exe", "hash_md5": "D4A68AF9ABEECB326FC06AA17357C105", "hash_sha1": "ECC1ECC51BD79ED51794B9D2C040CD0954537158", "hash_sha256": "6B98EA76457573D34C60E46BB72D3A2D007916F673D0B352877DCEFE8D1C598E", "hash_sha384": "AC37F8F1B3E5172F5F551F7D75DA1DE741A86CF5D68104EBAEE1975CBF99B83FEB062F0B9B46F7893E74D95988202626", "hash_sha512": "C1CD7247A1EF4506C10C0D9C7E7061AF47CFE06629058A92A2FE7A7D2B5D1257A062C7FBB58A5D24EFBDCB67A1B1F90D433AB060133AC38C88ED836FB4B0AB00", "hash_ssdeep": "12288:UWp8pCxIyG52CgOlYQqLWac0qpb0qD0xc1A:d6pCxIyZCgOlYJL1q2qDF", "hash_imp": "421A89D976B826E0CB5CCC2F5D8765C1", "hash_pesha1": "05EAC54FE568A08DA089DA33E27B5B26C2D2ED4A", "hash_pe256": "4995BF853F75EFE6FD6D1F217FC59A1645750A5BA631C2C4B96FF545EA69B1F5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Windows Media Configuration Utility", "meta_original_filename": "setup_wm.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/6b98ea76457573d34c60e46bb72d3a2d007916f673d0b352877dcefe8d1c598e/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_5706558cc25cc83b": "File", "(R-D) C:\\Program Files (x86)\\Windows Media Player\\en-US\\setup_wm.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Media Player\\setup_wm.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Windows Media Configuration Manager" }, "wmlaunch.exe-A94D52C2DDF833CB0886AF9C91E6A72B": { "file_name": "wmlaunch.exe", "file_path": "C:\\Program Files (x86)\\Windows Media Player\\wmlaunch.exe", "hash_md5": "A94D52C2DDF833CB0886AF9C91E6A72B", "hash_sha1": "6AB55E21EE71343806932ECDDF560FC9F0799C3E", "hash_sha256": "FE449FCE534F843C57FF95ACAFF7A9510DAFB37C0B384B91BEE9C8A2F203A27D", "hash_sha384": "FA2DBF490C2D38C5C965C4732001B35256899C358A6B1791F9E180E2903325B3929D5EB8B361EB797B727AF5490C260C", "hash_sha512": "F796D7C5909BB2AF7EFE9F89588AF4EE47A63747CFBCD6F425F82B7DD0E42DC0C9788F9AA84DF8EFC1B1C6C14BF1B1A85EACDE2672C0473E56DEC2F111660C85", "hash_ssdeep": "1536:/dIek2bpVKjMfV9l1vS/AlgKwkgGlZBw2:/dCCsjMDgAWrQBw", "hash_imp": "B038567086BD0DDB395DEB0D7D93BD13", "hash_pesha1": "3CAA8D46990DC45733BDDDE6EF045B69A3290417", "hash_pe256": "978FC676ECBFB723BBC29FBC3074ACD90EDC3FDA3A0BA1B8DABD6FF96A8604E5", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Launcher", "meta_original_filename": "wmlaunch.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/fe449fce534f843c57ff95acaff7a9510dafb37c0b384b91bee9c8a2f203a27d/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Program Files (x86)\\Windows Media Player\\en-US\\wmlaunch.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC484": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Media Player\\wmlaunch.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wmpconfig.exe-E173D6822FF7ACBBA5ADD79705D8DEB1": { "file_name": "wmpconfig.exe", "file_path": "C:\\Program Files (x86)\\Windows Media Player\\wmpconfig.exe", "hash_md5": "E173D6822FF7ACBBA5ADD79705D8DEB1", "hash_sha1": "39F9814EB20BA5945AC7E379E3A550F3298B0BFF", "hash_sha256": "B2B54120EC0632C731E27D4F2E0CB050A1BC6B58D85077D82F01FCEF25E7D8FB", "hash_sha384": "3DCB7DF34F27E1BE4E2B90037CF4D280BF026F69D6BFBDC7628D4013F4A4294D3D27D2A85C7E276CEDF0AC8961F223AB", "hash_sha512": "6F1B5AEAEC7F13A41E682758BCF7060C9D03D33B9D8C525A5C547F104E6ACB29D8D9D90EF8CF313627108832432B7A4AE73EDA9A242AA2400DAA23A64DE42B77", "hash_ssdeep": "1536:lTBfZ+hhuKL8lkQRrkcm464OBbYL53GJr95WAxJnolVz:VBfohYkQr0jeLwJr95rJo3", "hash_imp": "300A23DA66C9F482F62F9B9470336ACD", "hash_pesha1": "3C1FD7AC4B2A0AFBC2AEFFD43CAC072C1D91036C", "hash_pe256": "38677CEE86C33FB5D1B1A8CAC6EEE53B3412CF0F4146EAE93B7772FCC01A582B", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Configuration", "meta_original_filename": "wmpconfig.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/b2b54120ec0632c731e27d4f2e0cb050a1bc6b58d85077d82f01fcef25e7d8fb/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_5706558cc25cc83b": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Media Player\\wmpconfig.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wmplayer.exe-EEB987151A57294A024B8FBE323E8E94": { "file_name": "wmplayer.exe", "file_path": "C:\\Program Files (x86)\\Windows Media Player\\wmplayer.exe", "hash_md5": "EEB987151A57294A024B8FBE323E8E94", "hash_sha1": "29BF99CF79E6E43ABCF4C387B2426F1ED358BDE4", "hash_sha256": "E38036765FDDA1E24BC2DBBD83E3FE7726CD3BDA85FCA555CAE25520A200918C", "hash_sha384": "1886362E833B6A8A678B7A78A075D3B9C5572B1C59C1465A34EDDB4BB98478687A6DDDE24C074DF3C697E38EEDD271B2", "hash_sha512": "3DF32906E4AF61484F75DD4E624AC25B2812EDA0F23D8A498DC9B60B5BF8FC54A760D9D62DC7AE883A37A2DE02C8FE92B807F773EE5046CFBEF9C2BA4810E12C", "hash_ssdeep": "3072:8xdohYkQr0jeLwJr95rJolNAzyP+msVK0Zh:lYQqLwhHrWsOP+5VT", "hash_imp": "4C7D471D886B447BB6DF2D2962D0414C", "hash_pesha1": "F7C3E20D5234319A48A946BE51C4AB0BAFF738C8", "hash_pe256": "9918512D4E0DA6AFEE6418AE3FC8D9CAF23D257D661147488905F7F935A1405E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player", "meta_original_filename": "wmplayer.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e38036765fdda1e24bc2dbbd83e3fe7726cd3bda85fca555cae25520a200918c/detection/", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Media Player\\wmplayer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wmprph.exe-059CF1B78848862D366820C49CE7A168": { "file_name": "wmprph.exe", "file_path": "C:\\Program Files (x86)\\Windows Media Player\\wmprph.exe", "hash_md5": "059CF1B78848862D366820C49CE7A168", "hash_sha1": "C1E6F4586D53DFF8EF24CC12BB600379F9FECA75", "hash_sha256": "E881D9F2BF10C20F7B8869C09C0F0E7EE082B924AE1A5BBCE676556400FE5384", "hash_sha384": "0900EFF115B1F6C000472694166C7DCB8F65B5500CCB13A91660C479AFFF0A13724FBF3709B65366365E3BAEA4A8A3DA", "hash_sha512": "FB30F6B1E652A43A8BA7F0CBA718EE3A5B236911BEE490751BAA5300E922CEB0AC7DF558E4AAB238159DC74828745E466DE1D4A6ACBB740C9580FB4E9E602C6F", "hash_ssdeep": "768:CVqw4FhyDwxbHHlA2cNIGxQAiEGoQx50gMmAIEngn1soyrqujc1Z:/eiHFBcqGCA8MTgn1IqujcZ", "hash_imp": "E80BCC3A3EFBA6E5D42792769409FC2A", "hash_pesha1": "83D84818A68394DA43463344FEDCD9099DA0BD14", "hash_pe256": "D4A3A24CD635F63F720FB1AD8064E9BDFADF2B3B5D643F296C56064C3D08C905", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Rich Preview Handler", "meta_original_filename": "wmprph.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1282 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1282", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/e881d9f2bf10c20f7b8869c09c0f0e7ee082b924ae1a5bbce676556400fe5384/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\RPC Control\\DSEC6DC": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Media Player\\wmprph.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wmpshare.exe-1BA5B0F52DCD29859D8D3C5DB0F59410": { "file_name": "wmpshare.exe", "file_path": "C:\\Program Files (x86)\\Windows Media Player\\wmpshare.exe", "hash_md5": "1BA5B0F52DCD29859D8D3C5DB0F59410", "hash_sha1": "BDC658A7BCA222F21FEBB59B399C52AF4A302E43", "hash_sha256": "1AD541C9222C5E2BF09D09EE34C5E6256B71523D6E91F3F2E4FE642808452A9B", "hash_sha384": "37E65353DF125FE1C063AF6553D864B6B19B01561028C36B2710A42A7D18577E0614234CD3F8309131883C66B05867EE", "hash_sha512": "559B3B7C30FC7C77BC55685BD0C1435E470F33EE2D3D0DB5AECDF85537274A4843598C02263F6DC4554DC1C0F846B2EA7747C9739F883514462959AD7538B9FE", "hash_ssdeep": "1536:fO/Z+hhuKL8lkQRrkcm464OBbYL53GJr95WAxJnolV3N:f8ohYkQr0jeLwJr95rJozN", "hash_imp": "C0B0D05F05AB4E5E7AD7F26F321E9FB9", "hash_pesha1": "CEDE50B341CFE843CDAC036E79394695A3CEDC8A", "hash_pe256": "F9D29EF4F13F3D127248A6DC26633D66F18CE2F118BE3836F894217834142200", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Media Player Folder Sharing Executable", "meta_original_filename": "wmpshare.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "12.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "12.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/1ad541c9222c5e2bf09d09ee34c5e6256b71523d6e91f3f2e4fe642808452a9b/detection/", "runtime_modules": [ "C:\\Program Files (x86)\\Windows Media Player\\wmpshare.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "wordpad.exe-AD2FB3DA4D8AA9D8764E92E46CF2518D": { "file_name": "wordpad.exe", "file_path": "C:\\Program Files (x86)\\windows nt\\accessories\\wordpad.exe", "hash_md5": "AD2FB3DA4D8AA9D8764E92E46CF2518D", "hash_sha1": "AC4C000E0139DF03AC48CA261EDD41F6C5321D17", "hash_sha256": "C35624422AD35FEA2989387539908130CD9CEC17122AE9136C978DC91493EA9A", "hash_sha384": "FD2D9B20473DE40D2AE1726EDE0198F8595B0327DEA0EA70183E4174ADC45BD64DD95CF9C0EB9D2EAD67B4F35798337C", "hash_sha512": "40547C7DDD6EF429AADACCCCA85B5B6B10C122EC8E3010898614F4851824D501963EF60AECCBE07748CD072AA97C053D582282AF66CF959EFDC1D1C61A1ABB6B", "hash_ssdeep": "24576:I+mOVbV4AjtecTGbpigC2FxvNEtXcPCl9AuDF5zUPGLG5SvAMZAMg9ax:8OpqAjtecTohxvW9cPy9AuDzY4x", "hash_imp": "785E6D31910C9D8931D98C5E8B872F59", "hash_pesha1": "EE70BA13AAF34F85E5C5C71B8EE0F1966D8EA504", "hash_pe256": "CC86D3B658EDB75E6A77FD6D56A5BC94F07B41EB09A145199A130B5E66995308", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Wordpad Application", "meta_original_filename": "WORDPAD.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1075 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1075", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/67", "filescan_vtlink": "https://www.virustotal.com/gui/file/c35624422ad35fea2989387539908130cd9cec17122ae9136c978dc91493ea9a/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Program Files (x86)\\windows nt\\accessories\\en-US\\wordpad.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\MFC42u.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(R-D) C:\\Windows\\System32\\en-US\\KernelBase.dll.mui": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_5706558cc25cc83b": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\RPC Control\\DSECF14": "Section", "\\Sessions\\2\\BaseNamedObjects\\f14HWNDInterface:a09c8": "Section", "(R-D) C:\\Windows\\SysWOW64\\en-US\\UIRibbon.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\fms.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\SessionImmersiveColorPreference": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(RW-) C:\\Users\\user\\Documents": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\windows nt\\accessories\\wordpad.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Document - WordPad" }, "ImagingDevices.exe-3B6EE0E6F2C309F9535BDB71EF0EC9A1": { "file_name": "ImagingDevices.exe", "file_path": "C:\\Program Files (x86)\\Windows Photo Viewer\\ImagingDevices.exe", "hash_md5": "3B6EE0E6F2C309F9535BDB71EF0EC9A1", "hash_sha1": "61C88DEA8BC8049527CD6BC1426A16B2B65B6B17", "hash_sha256": "A21E5F3A91FFEEC54CDF5E8CDEF190083C1712EA5181435728B20F48566A7CDC", "hash_sha384": "D007163826FC92F594EE84BD893487B24343EC0262A0C4815FA06BA9A589D422273F0937BDCDA99C45D61A3EE16594FF", "hash_sha512": "1E83FA7D746474657CFE06A5E814C7EEC45FEBCA2C147438A3D8326A374490B0328DD2DAC1BA14041D5AA78F6A6521CC251EEC6F15C74282DC780BCCF7BB5B7E", "hash_ssdeep": "1536:HeaxNuACxtfTRVp/G/3W9hKBJjAqQCe1nwdsmZY5TTh1p1dlcQ:HeRnRVJogh4ydDeuwY9Thn7ld", "hash_imp": "6647780E00E5E0F11BA4FC61E5563764", "hash_pesha1": "69D00185C1866152AE11BE9A79413EC5CA42C53A", "hash_pe256": "97286E7B33A5AC05FD8078564EE645C8880AB91B8AEDD0A60F85D12F7EB3A40E", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Imaging Devices Control Panel", "meta_original_filename": "ImagingDevices.cpl.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a21e5f3a91ffeec54cdf5e8cdef190083c1712ea5181435728b20f48566a7cdc/detection/", "runtime_handles": { "(RW-) C:\\Windows": "File", "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_261b62a767ca4e6d": "File", "(R-D) C:\\Program Files (x86)\\Windows Photo Viewer\\en-US\\ImagingDevices.exe.mui": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RW-) C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.1518_none_5706558cc25cc83b": "File", "(R-D) C:\\Program Files (x86)\\Windows Photo Viewer\\en-US\\PhotoAcq.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\RPC Control\\DSEC12B0": "Section", "(RW-) C:\\Windows\\debug\\WIA\\wiatrace.log": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Program Files (x86)\\Windows Photo Viewer\\ImagingDevices.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ], "runtime_window_title": "Scanners and Cameras" }, "bfsvc.exe-C323E1D20F7C2AED759E5DC8FE56383A": { "file_name": "bfsvc.exe", "file_path": "C:\\Windows\\bfsvc.exe", "hash_md5": "C323E1D20F7C2AED759E5DC8FE56383A", "hash_sha1": "31CAD195FF4A6AC17B4B928FC257E5384010C614", "hash_sha256": "CF7CECABB289300D3EF6AF45D141C0524ABCA467076C0A98201BAD9A5CCE1195", "hash_sha384": "51F05DD0DB1A98874E6D6AE9E4258386B9A08425A187C6CD84BC5595F4D7B698A0FD054136CCA5A3EA0DACB4673C9E8F", "hash_sha512": "A1506F547225B3802E402ABA2300B70A8BEE08CA9C18BBE60C0B91834C0CCA33ED856CA1604633DC10649C56B4C2F703AA67D89A84F40ADA5B5BB04392A41BCE", "hash_ssdeep": "1536:ai37/D9/Z3EbkH7CR+1uHOWgcsFn6DghknGMLeJgDRNsk:99Z3bCg6OWgcC6EunHeJ4h", "hash_imp": "9CAC3C1F2A664256423DB5937B3166C1", "hash_pesha1": "1379508320A7132CA79608267D0952EEFEBC9A7C", "hash_pe256": "03339DFB8A58506CF44FD62A789FCF76DA1DD2F1175FC1617656128EE501C096", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Boot File Servicing Utility", "meta_original_filename": "bfsvc.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "Unknown", "filescan_vtlink": "n/a", "error": "BFSVC Warning: Failed to determine source OS version.\r\nBFSVC Error: Failed to validate boot manager checksum (help\\PCAT\\bootmgr)! Error code = 0xc1\r\nBFSVC Error: ServicingBootFiles failed. Error = 0xc1\r\n" }, "DfsrAdmin.exe-FDC25C48F19D2DBE817BAFFE16AEA267": { "file_name": "DfsrAdmin.exe", "file_path": "C:\\Windows\\DfsrAdmin.exe", "hash_md5": "FDC25C48F19D2DBE817BAFFE16AEA267", "hash_sha1": "6EB31915C6BA671C1C92247E6AA7B0B4A2D92581", "hash_sha256": "8AE6BDA2A754ADDD2F6F363F3597209DB39A75FE8461ED0B482DB33874C8D78F", "hash_sha384": "8662A68BEC653EEF084D4AB8734D49ED6CE9E780506834A67D4DDB0E16FD6A4D70EBBF59923853F996D3C366A77E3CB2", "hash_sha512": "AD88372CB73B533F960E9867E8873109C7EB20D55EAB280B851D00671CC39587DED388F22D236BDF5C37CD6D2D39339961BDB45A88AEE2FFED64150897CD560F", "hash_ssdeep": "3072:mDmwOBqkFplW0QBgXnCBfzBdYPZ23VDTGNpSVwICI+b:qvXkFpsxCgdYPZ23VDwICI", "hash_imp": "F34D5F2D4577ED6D9CEEC516C1F5A744", "hash_pesha1": "FAB3F6265A0CFF8D07475EC8C47891976B02FC25", "hash_pe256": "8572A6BF39C0E0B707120FA6E346BFC66A4A408C262A4AF202143FEA714AF01A", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "DFS Replication Command Line", "meta_original_filename": "DfsrAdmin.exe", "meta_product_name": "Microsoft (R) Windows (R) Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.529", "meta_product_version": "10.0.17763.529", "meta_language": "Language Neutral", "meta_legal_copyright": "Copyright (c) Microsoft Corporation. All rights reserved.", "meta_legal_trademarks": "Microsoft (R) Windows (R) Operating System", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/68", "filescan_vtlink": "https://www.virustotal.com/gui/file/8ae6bda2a754addd2f6f363f3597209db39a75fe8461ed0b482db33874c8d78f/detection/", "output": "\r\nHelp: \r\n=== Supported Objects ===\r\nYou can perform actions on the following objects:\r\n\r\n\r\nBulk Perform several actions by using a single input\r\n file \r\n \r\nConn Perform actions on connections between members of a replication \r\n group\r\n\r\nHealth Generate a health report for one or more members of a \r\n replication group\r\n \r\nMem Perform actions on a member of a replication group\r\n\r\nMembership Perform actions related to a member's participation in a \r\n replicated folder\r\n\r\nPropRep Generate propagation report for one or more propagation\r\n test files\r\n \r\nPropTest Generate and drop a propagation test file on a membership, \r\n used for testing replication\r\n\r\nRF Perform actions on a folder that is replicated between members\r\n of a replication group\r\n \r\nRG \t Perform actions on a group of computers that participates in\r\n replication\r\n\r\nSub Perform actions related to a member's subscription in \r\n replication groups\r\n\r\nType \"DfsrAdmin /?\" for detailed help.\r\n\r\nUsage: DfsrAdmin [] []\r\n ... [ ...]\r\n [/Domain:] [/DC:] [/CSV] [/Force]\r\n\r\n=== Optional Parameters Supported For All Commands ===\r\n/Domain: Specify the domain for the replication group\r\n/DC: Specify the domain controller to connect to in the replication \r\n group's domain\r\n/Force: Specify that a failed operation is skipped when an action causes a \r\n series of operations to be performed\r\n\r\n=== Optional Parameter Supported For All List Commands ===\r\n/CSV: Dumps the list output in CSV format\r\n", "runtime_modules": [ "C:\\Windows\\DfsrAdmin.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\SYSTEM32\\MSCOREE.DLL", "C:\\Windows\\System32\\KERNEL32.dll", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "error": "\r\nFailed: \r\nThe object --help is not a valid object.\r\n" }, "explorer.exe-47EA9E07B7DBFBEBA368BD95A3A2D25B": { "file_name": "explorer.exe", "file_path": "C:\\Windows\\explorer.exe", "hash_md5": "47EA9E07B7DBFBEBA368BD95A3A2D25B", "hash_sha1": "DA714F84A7BBAEE2BE9F1CA0262ACA649657CF3E", "hash_sha256": "F45557C0B57DEC4C000D8CB7D7068C8A4DCCF392DE740501B1046994460D77EA", "hash_sha384": "66BE6D55156B6458A156E5F8EEF8CFA54B9507D30DB236AB5208CF838ACA252C69650037A608673586C93ACFBB29F414", "hash_sha512": "F1CC3507592B2F79EC79209865F484743DD7B7BCEE66E26BD2C94BE2491660CA72932927CC543A675164640010E78B00AB0CC1143104941B5C623CF02CEC84B9", "hash_ssdeep": "49152:kBJWmpCqeSHfZy/dvEWZ+CEl4/UDX6xSk8g4mfQxHc+lQLGwtqRPLSo/hO5fw8AZ:upgCLgfw8a0cD", "hash_imp": "6D78CE65118DF73A9E7BEAC9366C186A", "hash_pesha1": "E450DBEC625AAEE0EC4A2DEE2735082034395AA2", "hash_pe256": "EC151D1D1902747A4B7271841F69D3201D642B2019D7406ECF83868A0F5AA009", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Explorer", "meta_original_filename": "EXPLORER.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/f45557c0b57dec4c000d8cb7d7068c8a4dccf392de740501b1046994460d77ea/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(R-D) C:\\Windows\\en-US\\explorer.exe.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\RPC Control\\DSEC91C": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\explorer.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\advapi32.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\SYSTEM32\\TWINAPI.dll", "C:\\Windows\\SYSTEM32\\dxgi.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\SYSTEM32\\winmm.dll", "C:\\Windows\\SYSTEM32\\settingsynccore.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\WININET.dll", "C:\\Windows\\SYSTEM32\\UxTheme.dll", "C:\\Windows\\SYSTEM32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\SYSTEM32\\USERENV.dll", "C:\\Windows\\SYSTEM32\\twinapi.appcore.dll", "C:\\Windows\\SYSTEM32\\WTSAPI32.dll", "C:\\Windows\\SYSTEM32\\WINMMBASE.dll", "C:\\Windows\\SYSTEM32\\RMCLIENT.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\SYSTEM32\\NInput.dll", "C:\\Windows\\system32\\explorerframe.dll", "C:\\Windows\\System32\\ActXPrxy.dll" ] }, "HelpPane.exe-CB8609764B0908853541EB4718ECE471": { "file_name": "HelpPane.exe", "file_path": "C:\\Windows\\HelpPane.exe", "hash_md5": "CB8609764B0908853541EB4718ECE471", "hash_sha1": "D8457897875FBB48A5510392EA2B913940E1F45D", "hash_sha256": "61A42C1904275294E6D1446F53275C64A752D0BFE362B03ED5F4ECC7DCBFA7B3", "hash_sha384": "25DCA0017E3884B81E8E33B48525F1BFED30CA4D69462954F41581A4C51E28837331A0A0E725D3CC05E24AE06C67972C", "hash_sha512": "E70D457D017D91CF1D171FEED4509EBDF2E59BF877DDB9F5D58325A3DAD757FDAC2954845BA3CF1BC04B639F0D47C081FCAA55C82D89CA40AE1CA8A182D995CC", "hash_ssdeep": "12288:CYQskmB4b43OYv/x+Pzr2PKlfs9W1W3MT3HOXKPXPiXuHNHGb6bH/zx/GCLW/nhf:lQlrYEzrWKlfs9WAe3H", "hash_imp": "6AD9191B348033E11321205D861CF898", "hash_pesha1": "26B5CAD3B210DACE272DBF1EE56A076A3E75400C", "hash_pe256": "60272855402205EC74C6B2090E3E22337743467FE33350498AD86337B93FC718", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft Help and Support", "meta_original_filename": "HelpPane.exe.mui", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/61a42c1904275294e6d1446f53275c64a752d0bfe362b03ed5f4ecc7dcbfa7b3/detection/" }, "hh.exe-1CECEE8D02A8E9B19D3A1A65C7A2B249": { "file_name": "hh.exe", "file_path": "C:\\Windows\\hh.exe", "hash_md5": "1CECEE8D02A8E9B19D3A1A65C7A2B249", "hash_sha1": "4B1E2F8EFBECB677080DBB26876311D9E06C5020", "hash_sha256": "8AB2F9A4CA87575F03F554AEED6C5E0D7692FA9B5D420008A1521F7F7BD2D0A5", "hash_sha384": "F4692DE1F5DDDAAAFAACF80D65B3CA91E37711EE1D358C2F4E29A57F650679C50B444B9BA5FAA8B279C42BD65AADB6A5", "hash_sha512": "B72A87C998BFF58C72241072BCDC682CDFC2154EF054F5F95B1CE87BDA44D9E9B16D1E43F708FBDB6BF37D73F8E7789D5226BCFFB96467383A14700E6C0600D0", "hash_ssdeep": "192:NZ4u99dac1vr3rS3N0MwfafE06YU/Shm5GJ1KDJD/4Wcg:NZ46Mc5vSCaE0TKI1KDWWcg", "hash_imp": "D3D9C3E81A404E7F5C5302429636F04C", "hash_pesha1": "DED222F89C89A23515854047634519A5E61E3F2B", "hash_pe256": "724A77AFB0A6C7F89D13CCC4AE1CBFC06D7D666A7A658A20782978BF871592E4", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Microsoft HTML Help Executable", "meta_original_filename": "HH.exe.mui", "meta_product_name": "HTML Help", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/8ab2f9a4ca87575f03f554aeed6c5e0d7692fa9b5d420008a1521f7f7bd2d0a5/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326": "File", "(R-D) C:\\Windows\\en-US\\hh.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\hhctrl.ocx.mui": "File", "\\Windows\\Theme966197582": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(R-D) C:\\Windows\\System32\\en-US\\user32.dll.mui": "File", "(R--) C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2\\~DF95187317C557A3BD.TMP": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "(RWD) C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2\\~DF36F096167D6F98FD.TMP": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "\\RPC Control\\DSECFE0": "Section", "\\Sessions\\2\\BaseNamedObjects\\fe0HWNDInterface:70a3a": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_ie_global_counters": "Section", "(R-D) C:\\Windows\\System32\\ieframe.dll": "File", "\\Sessions\\2\\BaseNamedObjects\\windows_shell_global_counters": "Section", "\\BaseNamedObjects\\windows_shell_global_counters": "Section", "(R-D) C:\\Windows\\System32\\en-US\\ieframe.dll.mui": "File", "\\Sessions\\2\\BaseNamedObjects\\UrlZonesSM_Administrator": "Section", "\\Sessions\\2\\BaseNamedObjects\\windows_webcache_counters_{9B6AB5B3-91BC-4097-835C-EA2DEC95E9CC}_S-1-5-21-4075667164-670084373-454571106-500": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "(R-D) C:\\Windows\\System32\\en-US\\urlmon.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\mshtml.dll.mui": "File", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\hh.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\hhctrl.ocx", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\shlwapi.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17763.1518_none_6d08fefc59f73326\\COMCTL32.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\system32\\uxtheme.dll", "C:\\Windows\\System32\\MSCTF.dll", "C:\\Windows\\system32\\dwmapi.dll", "C:\\Windows\\System32\\CRYPT32.dll", "C:\\Windows\\System32\\MSASN1.dll", "C:\\Windows\\System32\\coml2.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\System32\\ieframe.dll", "C:\\Windows\\System32\\iertutil.dll", "C:\\Windows\\System32\\NETAPI32.dll", "C:\\Windows\\System32\\VERSION.dll", "C:\\Windows\\System32\\USERENV.dll", "C:\\Windows\\System32\\WINHTTP.dll", "C:\\Windows\\System32\\NETUTILS.DLL", "C:\\Windows\\System32\\WKSCLI.DLL", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\comctl32.dll", "C:\\Windows\\system32\\dataexchange.dll", "C:\\Windows\\system32\\d3d11.dll", "C:\\Windows\\system32\\dcomp.dll", "C:\\Windows\\system32\\dxgi.dll", "C:\\Windows\\system32\\twinapi.appcore.dll", "C:\\Windows\\system32\\RMCLIENT.dll", "C:\\Windows\\SYSTEM32\\urlmon.dll", "C:\\Windows\\SYSTEM32\\CRYPTBASE.DLL", "C:\\Windows\\SYSTEM32\\sxs.dll", "C:\\Windows\\system32\\propsys.dll", "C:\\Windows\\SYSTEM32\\msIso.dll", "C:\\Windows\\SYSTEM32\\SspiCli.dll", "C:\\Windows\\SYSTEM32\\MSHTML.dll", "C:\\Windows\\SYSTEM32\\WindowsCodecs.dll" ], "runtime_window_title": "HTML Help" }, "regedit.exe-A3668018735B59050AD123A5A8CDC184": { "file_name": "regedit.exe", "file_path": "C:\\Windows\\regedit.exe", "hash_md5": "A3668018735B59050AD123A5A8CDC184", "hash_sha1": "1D72449F04F2287A31A91024FC3E3ADA33322E72", "hash_sha256": "FF3B56204F0CEA172AEFB178E05A32C3C3C0BE93F29DD4C2DF46A6DE07BB5152", "hash_sha384": "25096F9DDF40C883DEF467A2224EC2B739B74AEAE5B540F1CEFB37D5BEC31F885D4F3AC95642B8CC3579E22164C05AF4", "hash_sha512": "CB39E0A4F7C50A449DC113F4B61AB6EF2DCAEBA12170D04DA97A2644D8399CF51F217C84C608DEDD3F35B73F8BBAA1F3F7FDD1EA51AD293BF18BCE2FA38A2C0F", "hash_ssdeep": "6144:6qoAOc6qKhTsywE2KBiBQRZ66z+n4VZbd8g79pgrXNgRnVLjyzhbkidNN2:6qvOFhg5KIQRZ66z24VZbdrpgrXN2LWr", "hash_imp": "7FEBF576192E34BDF7D07877CBACC413", "hash_pesha1": "8A502B83863552735A48AFEBF00F967FA7F06CF8", "hash_pe256": "C09538DF5350AC6F798E8633280E353DFA3B06EB5E1FBF18A52F5F2A5E484FCF", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Registry Editor", "meta_original_filename": "REGEDIT.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/ff3b56204f0cea172aefb178e05a32c3c3c0be93f29dd4c2df46a6de07bb5152/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567": "File", "(R-D) C:\\Windows\\en-US\\regedit.exe.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\aclui.dll.mui": "File", "\\Windows\\Theme966197582": "Section", "(R-D) C:\\Windows\\System32\\en-US\\duser.dll.mui": "File", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\Sessions\\2\\Windows\\Theme2131664586": "Section", "(RW-) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754": "File", "(R-D) C:\\Windows\\WinSxS\\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.17763.1518_en-us_f47974b57ff45754\\comctl32.dll.mui": "File", "(R-D) C:\\Windows\\System32\\en-US\\imageres.dll.mui": "File", "(R-D) C:\\Windows\\Fonts\\StaticCache.dat": "File", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\regedit.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\SHLWAPI.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\System32\\COMDLG32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\System32\\SHELL32.dll", "C:\\Windows\\System32\\cfgmgr32.dll", "C:\\Windows\\System32\\windows.storage.dll", "C:\\Windows\\System32\\profapi.dll", "C:\\Windows\\System32\\powrprof.dll", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\cryptsp.dll", "C:\\Windows\\System32\\ole32.dll", "C:\\Windows\\SYSTEM32\\AUTHZ.dll", "C:\\Windows\\SYSTEM32\\ACLUI.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\SYSTEM32\\ulib.dll", "C:\\Windows\\SYSTEM32\\clb.dll", "C:\\Windows\\SYSTEM32\\UxTheme.dll", "C:\\Windows\\SYSTEM32\\NTDSAPI.dll", "C:\\Windows\\System32\\WS2_32.dll", "C:\\Windows\\SYSTEM32\\XmlLite.dll", "C:\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17763.1518_none_de6e2bd0534e2567\\COMCTL32.dll", "C:\\Windows\\System32\\IMM32.DLL" ], "runtime_window_title": "Registry Editor" }, "splwow64.exe-93A8D365CB20A105CB97FF41451B85D5": { "file_name": "splwow64.exe", "file_path": "C:\\Windows\\splwow64.exe", "hash_md5": "93A8D365CB20A105CB97FF41451B85D5", "hash_sha1": "91C6C820FAE580826E5C6D7783CDB7CEB131C298", "hash_sha256": "70AD0FE5B39719C3D0A5EDD2BEA742BC7AF35D6EF153D92FA1D011D34510E92C", "hash_sha384": "8CECD2835750C71AACCCFD96D3A7F5D573F0F8C19ADF9FE7A08169612EA05696D9B2FE1D01B1E684C53919F2CB4EF114", "hash_sha512": "2B004FF1C5841CE6B9F2BB290F8C74E67C5EDA4834331AF8F46BB7A544B3642F7842AB50954DC9073EE548D99C6F3F252C718C8D5951324A15F76A59DD96B0E0", "hash_ssdeep": "3072:JwTes+h9eRr6d/pGuWQ/Dc+vWCfZcxOeHQbPRyZ2pPTv:eis+hAuRpGFQ/rhCt8AZ2", "hash_imp": "A54B3197E11F3941F4E9261854E484BB", "hash_pesha1": "4F1F374CC854D664A53947D4091EB5E521F496BD", "hash_pe256": "23A933F5745F7F100F38A799B86EB8CED78E031FCCA066B176A02973F1EE813C", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "3300000266BD1580EFA75CD6D3000000000266", "signature_thumbprint": "A4341B9FD50FB9964283220A36A1EF6F6FAA7840", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Print driver host for applications", "meta_original_filename": "splwow64.exe", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1339 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1339", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/70ad0fe5b39719c3d0a5edd2bea742bc7af35d6ef153d92fa1d011d34510e92c/detection/", "runtime_handles": { "(RW-) C:\\Users\\user": "File", "\\BaseNamedObjects\\__ComCatalogCache__": "Section", "\\RPC Control\\DSEC12D8": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db": "Section", "\\BaseNamedObjects\\NLS_CodePage_437_3_2_0_0": "Section", "\\BaseNamedObjects\\NLS_CodePage_1252_3_2_0_0": "Section" }, "runtime_modules": [ "C:\\Windows\\splwow64.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll", "C:\\Windows\\System32\\ADVAPI32.dll", "C:\\Windows\\System32\\msvcrt.dll", "C:\\Windows\\System32\\sechost.dll", "C:\\Windows\\System32\\RPCRT4.dll", "C:\\Windows\\System32\\USER32.dll", "C:\\Windows\\System32\\win32u.dll", "C:\\Windows\\System32\\GDI32.dll", "C:\\Windows\\System32\\gdi32full.dll", "C:\\Windows\\System32\\msvcp_win.dll", "C:\\Windows\\System32\\ucrtbase.dll", "C:\\Windows\\System32\\combase.dll", "C:\\Windows\\System32\\bcryptPrimitives.dll", "C:\\Windows\\SYSTEM32\\WINSPOOL.DRV", "C:\\Windows\\System32\\kernel.appcore.dll", "C:\\Windows\\System32\\bcrypt.dll", "C:\\Windows\\SYSTEM32\\PROPSYS.dll", "C:\\Windows\\System32\\OLEAUT32.dll", "C:\\Windows\\System32\\shcore.dll", "C:\\Windows\\SYSTEM32\\IPHLPAPI.DLL", "C:\\Windows\\System32\\IMM32.DLL", "C:\\Windows\\SYSTEM32\\PrintIsolationProxy.dll", "C:\\Windows\\System32\\clbcatq.dll", "C:\\Windows\\SYSTEM32\\sspicli.dll" ] }, "winhlp32.exe-351FDCE5B7CDE5009C768FFDA64B5E57": { "file_name": "winhlp32.exe", "file_path": "C:\\Windows\\winhlp32.exe", "hash_md5": "351FDCE5B7CDE5009C768FFDA64B5E57", "hash_sha1": "1FAB1E89A86956A2281EE8364774BE307D81F689", "hash_sha256": "0AE37C1D7FC84E5E956874458508205F4DAD68D933BE6B801CFF2E42475664B5", "hash_sha384": "11F3469FF4D36905BAE955F9E0E7E713198950F9F8A9E101DFC6750DC99689D607FA27E9AFFF95FEC7538BD658CD2821", "hash_sha512": "71311CD7E0AD65C0B39AE1B8EA14E536E005090815527E2FA91811D238CFE33BB14DCBA34545F68D5A6BF7E8D7FD6255AE11425F7F318C014A360E2580029BF6", "hash_ssdeep": "192:PvR0uTw4mh2sKYHqWZxeqQ4t5tmXdkLWMeHWthh4jBrA:PiuTorHq8ZnCqLWMeHWthh49s", "hash_imp": "0DFDE2C713801A5C7E6DC0108384FB68", "hash_pesha1": "42A4AD10C35478AF05689EB0D648BD223D0F183D", "hash_pe256": "05BF298D57CB02F799ACFED77D7B44E4BEAEBD6E72203A7DC1EFC1633F0694B9", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "33000001C422B2F79B793DACB20000000001C4", "signature_thumbprint": "AE9C1AE54763822EEC42474983D8B635116C8452", "signature_issuer": "CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "signature_subject": "CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", "meta_description": "Windows Winhlp32 Stub", "meta_original_filename": "WINHLP32.EXE.MUI", "meta_product_name": "Microsoft Windows Operating System", "meta_company_name": "Microsoft Corporation", "meta_file_version": "10.0.17763.1 (WinBuild.160101.0800)", "meta_product_version": "10.0.17763.1", "meta_language": "English (United States)", "meta_legal_copyright": " Microsoft Corporation. All rights reserved.", "meta_machinetype": "32-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/0ae37c1d7fc84e5e956874458508205f4dad68d933be6b801cff2e42475664b5/detection/", "runtime_modules": [ "C:\\Windows\\winhlp32.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\wow64.dll", "C:\\Windows\\System32\\wow64win.dll", "C:\\Windows\\System32\\wow64cpu.dll" ] }, "capinfos.exe-D3682305FD039566EF3DD7470BA00AC0": { "file_name": "capinfos.exe", "file_path": "C:\\Program Files\\Wireshark\\capinfos.exe", "hash_md5": "D3682305FD039566EF3DD7470BA00AC0", "hash_sha1": "7D06AA941B98D3D244A639D9219085C23E5FF999", "hash_sha256": "A8CF4F8CB851B1C648FDFF18C8653833DCF7E35727D9C0321BB376DE09A11C96", "hash_sha384": "AD744CCC4F06845835D71928C53E9EBB7216F57B1105771573973F57AE28F78243CC2256319F2A25B48E87AABAFEAE14", "hash_sha512": "832389B1956322C232C8E2E20A6C9E9E29A5C783B56F259A405471F759916E022222E61711BF9CFD50DC4B7517B64585EF52AFE453DF323A8EEE5829C93E48E3", "hash_ssdeep": "1536:3ezrMNDYS8OGFP2UeaDUlZ9rj6ky7T7ODuYUg48o0VBgWHncnFPXavErjnCj2Wec:30rMNDYSWP2UeKGPjqyr2rFP0oBju/Z", "hash_imp": "6FB0FA337E36524E95E0106C09031255", "hash_pesha1": "7819E5B2434C83EC323E753E9B8C0AF7FD4C2CB1", "hash_pe256": "B6DCF864D78EF5279F519A5C589D5821FC0C693F316E47F51FD384C44F0B8457", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "02CCD99F7D556C13CE8710C69D09B31A", "signature_thumbprint": "E8EF7325044D018B0C0DCD8CBA4190B155857F3B", "signature_issuer": "CN=Sectigo RSA Code Signing CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB", "signature_subject": "CN=\"Wireshark Foundation, Inc.\", O=\"Wireshark Foundation, Inc.\", STREET=711 4th street, L=Davis, S=CA, PostalCode=95616, C=US", "meta_description": "Capinfos", "meta_original_filename": "capinfos.exe", "meta_product_name": "Capinfos", "meta_company_name": "The Wireshark developer community", "meta_file_version": "3.2.7", "meta_product_version": "3.2.7", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 2000 Gerald Combs , Gilbert Ramirez and many others", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/70", "filescan_vtlink": "https://www.virustotal.com/gui/file/a8cf4f8cb851b1c648fdff18c8653833dcf7e35727d9c0321bb376de09a11c96/detection/", "output": "Capinfos (Wireshark) 3.2.7 (v3.2.7-0-gfb6522d84a3a)\r\nPrint various information (infos) about capture files.\r\nSee https://www.wireshark.org for more information.\r\n\r\nUsage: capinfos [options] ...\r\n\r\nGeneral infos:\r\n -t display the capture file type\r\n -E display the capture file encapsulation\r\n -I display the capture file interface information\r\n -F display additional capture file information\r\n -H display the SHA256, RMD160, and SHA1 hashes of the file\r\n -k display the capture comment\r\n\r\nSize infos:\r\n -c display the number of packets\r\n -s display the size of the file (in bytes)\r\n -d display the total length of all packets (in bytes)\r\n -l display the packet size limit (snapshot length)\r\n\r\nTime infos:\r\n -u display the capture duration (in seconds)\r\n -a display the capture start time\r\n -e display the capture end time\r\n -o display the capture file chronological status (True/False)\r\n -S display start and end times as seconds\r\n\r\nStatistic infos:\r\n -y display average data rate (in bytes/sec)\r\n -i display average data rate (in bits/sec)\r\n -z display average packet size (in bytes)\r\n -x display average packet rate (in packets/sec)\r\n\r\nMetadata infos:\r\n -n display number of resolved IPv4 and IPv6 addresses\r\n -D display number of decryption secrets\r\n\r\nOutput format:\r\n -L generate long report (default)\r\n -T generate table report\r\n -M display machine-readable values in long reports\r\n\r\nTable report options:\r\n -R generate header record (default)\r\n -r do not generate header record\r\n\r\n -B separate infos with TAB character (default)\r\n -m separate infos with comma (,) character\r\n -b separate infos with SPACE character\r\n\r\n -N do not quote infos (default)\r\n -q quote infos with single quotes (')\r\n -Q quote infos with double quotes (\")\r\n\r\nMiscellaneous:\r\n -h display this help and exit\r\n -C cancel processing if file open fails (default is to continue)\r\n -A generate all infos (default)\r\n -K disable displaying the capture comment\r\n\r\nOptions are processed from left to right order with later options superseding\r\nor adding to earlier options.\r\n\r\nIf no options are given the default is to display all infos in long report\r\noutput format.\r\n", "error": "capinfos: The file \"C:\\temp\\strontic-xcyclopedia\\notepad.exe\" doesn't exist.\r\n", "runtime_modules": [ "C:\\Program Files\\Wireshark\\capinfos.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dftest.exe-049B4FA2F5ABEED3D65D516CE3BDC6FE": { "file_name": "dftest.exe", "file_path": "C:\\Program Files\\Wireshark\\dftest.exe", "hash_md5": "049B4FA2F5ABEED3D65D516CE3BDC6FE", "hash_sha1": "8358448EA1087F34956C38373683C2D47A8B2F15", "hash_sha256": "07F28305D10810B766683C5ACFC80DF985C3A9B51724B41D9027C9D684D0A943", "hash_sha384": "3A80109BDC76BA972471886B514223965383AF8F4ADC2B8E028D37E6D914BCC733486D12A46F7610E03C8960E2A0F50D", "hash_sha512": "107AEFCE1FD22324DCEA546E9E52B22123F1BCF910ECE6EFACB9DA7F74779F3A9486A5A1F120C474AA7F7EB68BCF68EFB2D67C17AB7896FDA904010DEAD42C99", "hash_ssdeep": "384:HaXxhII0V5zkEYU6aWIcAM+VvsqgxGfZ48JN77hhwt:yPIdorWMivsgb3hmt", "hash_imp": "0470AF7E1F79D9BC16920D3A59A88BE0", "hash_pesha1": "BE7FC33D164D098E74B3E14C4A731203D5228D37", "hash_pe256": "3A85F034D0C662A84A7CD84BC3AA7F276FA3CBFBBCA695AC39C1B0F0EFDE1724", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "02CCD99F7D556C13CE8710C69D09B31A", "signature_thumbprint": "E8EF7325044D018B0C0DCD8CBA4190B155857F3B", "signature_issuer": "CN=Sectigo RSA Code Signing CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB", "signature_subject": "CN=\"Wireshark Foundation, Inc.\", O=\"Wireshark Foundation, Inc.\", STREET=711 4th street, L=Davis, S=CA, PostalCode=95616, C=US", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/07f28305d10810b766683c5acfc80df985c3a9b51724b41d9027c9d684d0a943/detection/", "error": "dftest: \"--help\" is neither a field nor a protocol name.\r\n", "output": "Filter: \"C:\\temp\\strontic-xcyclopedia\\notepad.exe\"\r\n", "runtime_modules": [ "C:\\Program Files\\Wireshark\\dftest.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "dumpcap.exe-FA9F38700AA8216DDB89C544A3D388DB": { "file_name": "dumpcap.exe", "file_path": "C:\\Program Files\\Wireshark\\dumpcap.exe", "hash_md5": "FA9F38700AA8216DDB89C544A3D388DB", "hash_sha1": "69887913FCC3D840D0DAD0C1429F5BE5FC2305BE", "hash_sha256": "96702338BFC866FBEA133819697E992694E94D6D0AE32276728000D9B3ACE45B", "hash_sha384": "671508FEFF78108FB8FEFD3C06AA70357C7D985E5677EC5109D9F86C79BDA68F89ACDD3B4E6C218A318D4EA1712CD667", "hash_sha512": "2492046F4E78D8765F2BDFA3D907E2400EE790C653E821404C00478292F221334390BCFBEB426E3AE4067AD6678BEC6E6523E343D6159A15D91BA972665C31C6", "hash_ssdeep": "3072:vX0nLywFbVbXSypi9buQlZ6rGb4Z3KIUyr2rFP0oBjjZJ/:vkn2wVVb5aqQlUTKIUuSFP9FJ/", "hash_imp": "62C2ADC8A4D23E2D07B7EEB4235EEB0C", "hash_pesha1": "342E07693B6695A17138E42F7B01D7886A52CA50", "hash_pe256": "F43353775A17D79FDCF893DADF110DDC615B026096BB5132E81E2032B1DF0152", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "02CCD99F7D556C13CE8710C69D09B31A", "signature_thumbprint": "E8EF7325044D018B0C0DCD8CBA4190B155857F3B", "signature_issuer": "CN=Sectigo RSA Code Signing CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB", "signature_subject": "CN=\"Wireshark Foundation, Inc.\", O=\"Wireshark Foundation, Inc.\", STREET=711 4th street, L=Davis, S=CA, PostalCode=95616, C=US", "meta_description": "Dumpcap", "meta_original_filename": "Dumpcap.exe", "meta_product_name": "Dumpcap", "meta_company_name": "The Wireshark developer community", "meta_file_version": "3.2.7", "meta_product_version": "3.2.7", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 2000 Gerald Combs , Gilbert Ramirez and others", "meta_machinetype": "64-bit", "filescan_vtdetection": "0/69", "filescan_vtlink": "https://www.virustotal.com/gui/file/96702338bfc866fbea133819697e992694e94d6d0ae32276728000d9b3ace45b/detection/", "error": "dumpcap: Unable to load Npcap or WinPcap (wpcap.dll); you will not be able to\r\ncapture packets.\r\n\r\nIn order to capture packets Npcap or WinPcap must be installed. See\r\n\r\n https://nmap.org/npcap/\r\n\r\nfor a downloadable version of Npcap and for instructions on how to\r\ninstall it.\r\n", "output": "Dumpcap (Wireshark) 3.2.7 (v3.2.7-0-gfb6522d84a3a)\r\nCapture network packets and dump them into a pcapng or pcap file.\r\nSee https://www.wireshark.org for more information.\r\n\r\nUsage: dumpcap [options] ...\r\n\r\nCapture interface:\r\n -i , --interface \r\n name or idx of interface (def: first non-loopback),\r\n or for remote capturing, use one of these formats:\r\n rpcap:///\r\n TCP@:\r\n -f packet filter in libpcap filter syntax\r\n -s , --snapshot-length \r\n packet snapshot length (def: appropriate maximum)\r\n -p, --no-promiscuous-mode\r\n don't capture in promiscuous mode\r\n -I, --monitor-mode capture in monitor mode, if available\r\n -B , --buffer-size \r\n size of kernel buffer in MiB (def: 2MiB)\r\n -y , --linktype \r\n link layer type (def: first appropriate)\r\n --time-stamp-type timestamp method for interface\r\n -D, --list-interfaces print list of interfaces and exit\r\n -L, --list-data-link-types\r\n print list of link-layer types of iface and exit\r\n --list-time-stamp-types print list of timestamp types for iface and exit\r\n -d print generated BPF code for capture filter\r\n -k ,[],[],[]\r\n set channel on wifi interface\r\n -S print statistics for each interface once per second\r\n -M for -D, -L, and -S, produce machine-readable output\r\n\r\nRPCAP options:\r\n -r don't ignore own RPCAP traffic in capture\r\n -u use UDP for RPCAP data transfer\r\n -A : use RPCAP password authentication\r\n -m use packet sampling\r\n count:NUM - capture one packet of every NUM\r\n timer:NUM - capture no more than 1 packet in NUM ms\r\nStop conditions:\r\n -c stop after n packets (def: infinite)\r\n -a ..., --autostop ...\r\n duration:NUM - stop after NUM seconds\r\n filesize:NUM - stop this file after NUM kB\r\n files:NUM - stop after NUM files\r\n packets:NUM - stop after NUM packets\r\nOutput (files):\r\n -w name of file to save (def: tempfile)\r\n -g enable group read access on the output file(s)\r\n -b ..., --ring-buffer \r\n duration:NUM - switch to next file after NUM secs\r\n filesize:NUM - switch to next file after NUM kB\r\n files:NUM - ringbuffer: replace after NUM files\r\n packets:NUM - ringbuffer: replace after NUM packets\r\n interval:NUM - switch to next file when the time is\r\n an exact multiple of NUM secs\r\n -n use pcapng format instead of pcap (default)\r\n -P use libpcap format instead of pcapng\r\n --capture-comment \r\n add a capture comment to the output file\r\n (only for pcapng)\r\n\r\nMiscellaneous:\r\n -N maximum number of packets buffered within dumpcap\r\n -C maximum number of bytes used for buffering packets\r\n within dumpcap\r\n -t use a separate thread per interface\r\n -q don't report packet capture counts\r\n -v, --version print version information and exit\r\n -h, --help display this help and exit\r\n\r\nExample: dumpcap -i eth0 -a duration:60 -w output.pcapng\r\n\"Capture packets from interface eth0 until 60s passed into output.pcapng\"\r\n\r\nUse Ctrl-C to stop capturing at any time.\r\n", "runtime_modules": [ "C:\\Program Files\\Wireshark\\dumpcap.exe", "C:\\Windows\\SYSTEM32\\ntdll.dll", "C:\\Windows\\System32\\KERNEL32.DLL", "C:\\Windows\\System32\\KERNELBASE.dll" ] }, "editcap.exe-2DEF88D5CE21E9249550A3B44FB78DF3": { "file_name": "editcap.exe", "file_path": "C:\\Program Files\\Wireshark\\editcap.exe", "hash_md5": "2DEF88D5CE21E9249550A3B44FB78DF3", "hash_sha1": "B5D23FCB27CD0654E23B7FBCE740A0E91433DF74", "hash_sha256": "BD4E4E61AFD42D51D8CDB7B8F33590F7B2A30CA0A1CC19A0509A38ADF01E6383", "hash_sha384": "077558C3D3579E1104534D5E197E5A6E51E54AF791B3C867A369DF745C46A06D11367CD7562B1E27E9DEAADBCD22C107", "hash_sha512": "971EF67F44EF5D086496A4D1CF214B4378519D42FC99E9DA84C1670758B5A973AAB95DAE5AFD72D61310659452DDB713CD9DB2EB58D5654A693114ED154FBF35", "hash_ssdeep": "1536:WuN0ex0puy/u07kx87HpRxy7T7ODuYUg48o0VBgWHncnFPXavErjnCj2We2Vk4A2:WDOb07kx87Hpeyr2rFP0oBj7JGtb", "hash_imp": "FCE1A7709608524809C4CBDCCA73CDE6", "hash_pesha1": "59BC8835D3301B22B61CB543A8F4B9DEF9CBD7B1", "hash_pe256": "FE0CF661A9FC2C6F1C597C6B8DDC90682201D5EA14236DD0DE3D8347BAE963A8", "signature_status": 0, "signature_status_message": "Signature verified.", "signature_serial": "02CCD99F7D556C13CE8710C69D09B31A", "signature_thumbprint": "E8EF7325044D018B0C0DCD8CBA4190B155857F3B", "signature_issuer": "CN=Sectigo RSA Code Signing CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB", "signature_subject": "CN=\"Wireshark Foundation, Inc.\", O=\"Wireshark Foundation, Inc.\", STREET=711 4th street, L=Davis, S=CA, PostalCode=95616, C=US", "meta_description": "Editcap", "meta_original_filename": "editcap.exe", "meta_product_name": "Editcap", "meta_company_name": "The Wireshark developer community", "meta_file_version": "3.2.7", "meta_product_version": "3.2.7", "meta_language": "English (United States)", "meta_legal_copyright": "Copyright 2000 Gerald Combs , Gilbert Ramirez and many others", "meta_machinetype": "64-bit", "filescan_vtdetection": "1/71", "filescan_vtlink": "https://www.virustotal.com/gui/file/bd4e4e61afd42d51d8cdb7b8f33590f7b2a30ca0a1cc19a0509a38adf01e6383/detection/", "error": "\r\nUsage: editcap [options] ... [ [-] ... ]\r\n\r\n and must both be present.\r\nA single packet or a range of packets can be selected.\r\n\r\nPacket selection:\r\n -r keep the selected packets; default is to delete them.\r\n -A only output packets whose timestamp is after (or equal\r\n to) the given time (format as YYYY-MM-DD hh:mm:ss).\r\n -B only output packets whose timestamp is before the\r\n given time (format as YYYY-MM-DD hh:mm:ss).\r\n\r\nDuplicate packet removal:\r\n --novlan remove vlan info from packets before checking for duplicates.\r\n -d remove packet if duplicate (window == 5).\r\n -D remove packet if duplicate; configurable .\r\n Valid values are 0 to 1000000.\r\n NOTE: A of 0 with -v (verbose option) is\r\n useful to print MD5 hashes.\r\n -w remove packet if duplicate packet is found EQUAL TO OR\r\n LESS THAN prior to current packet.\r\n A is specified in relative seconds\r\n (e.g. 0.000001).\r\n NOTE: The use of the 'Duplicate packet removal' options with\r\n other editcap options except -v may not always work as expected.\r\n Specifically the -r, -t or -S options will very likely NOT have the\r\n desired effect if combined with the -d, -D or -w.\r\n --skip-radiotap-header skip radiotap header when checking for packet duplicates.\r\n Useful when processing packets captured by multiple radios\r\n on the same channel in the vicinity of each other.\r\n\r\nPacket manipulation:\r\n -s truncate each packet to max. bytes of data.\r\n -C [offset:] chop each packet by bytes. Positive values\r\n chop at the packet beginning, negative values at the\r\n packet end. If an optional offset precedes the length,\r\n then the bytes chopped will be offset from that value.\r\n Positive offsets are from the packet beginning,\r\n negative offsets are from the packet end. You can use\r\n this option more than once, allowing up to 2 chopping\r\n regions within a packet provided that at least 1\r\n choplen is positive and at least 1 is negative.\r\n -L adjust the frame (i.e. reported) length when chopping\r\n and/or snapping.\r\n -t